Configuring CP 5611 A2 PROFIBUS with WinCC Flexible RT and S7-300

David Krause15 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Communication between a Panel PC running WinCC Flexible Runtime and a SIMATIC S7-300 CPU over PROFIBUS using the CP 5611 A2 PCI card (article number 6GK1-561-1AA01) is fully supported. The most common reason projects stall is that the CP 5611 A2 is not present as a separate catalog entry in the hardware catalog of older Step 7 versions (V5.3 and earlier) — the catalog only lists the original CP 5611 (6GK1-561-1AA00). A second, more disruptive class of failures shows up at runtime: the WinCC Flexible screen elements are visible, online monitoring of the PLC works through the same card, but the HMI tags do not change state, the colors do not switch, and forcing a bit in the PLC has no visible effect on the Panel PC. Both symptoms have the same root family — the wrong S7ONLINE access point assignment or a missing SIMATIC NET installation on the runtime PC — and both are fixable without changing hardware, replacing the card, or re-flashing firmware.

This reference covers the two valid communication architectures (S7ONLINE direct access and PC Station with SIMATIC NET), explains the Step 7 hardware catalog behavior, and walks through tag configuration, area pointer assignment, and field verification. It applies to the original CP 5611, the CP 5611 A2, and the A2 variant with article number 6GK1-561-1AA01 in particular, because the catalog gap is the symptom most often reported in the field.

Affected Components and Versions

Component Article / Version Role
CP 5611 A2 PCI card 6GK1-561-1AA01 PROFIBUS DP / MPI master or slave on the Panel PC
CP 5611 (predecessor) 6GK1-561-1AA00 Functionally equivalent for catalog use
Step 7 V5.3 SP3 and later (V5.4, V5.5) Project engineering, HWCN, NetPro
WinCC Flexible 2005, 2007, 2008 SP1, 2008 SP2 HMI engineering, integration in Step 7
WinCC Flexible Runtime 2005 or later Panel PC runtime for visualization
SIMATIC NET PC software, version 6.x or later Provides OPC / SAPI / soft-PB drivers
SIMATIC Softnet S7 for PROFIBUS License required Enables PC Station as PROFIBUS master on CP 5611 A2
SIMATIC Softnet S7 Lean (Ethernet) Bundled with WinCC Flex RT Ethernet only — does not cover PROFIBUS
S7-300 CPU CPU 312, CPU 312C, CPU 313, CPU 314, CPU 315-2 DP, CPU 317-2 DP Target PLC with integrated DP or CP 342-5
License caveat. The Ethernet Softnet Lean shipped with WinCC Flexible Runtime cannot be used to drive the CP 5611 A2 over PROFIBUS. For a PROFIBUS path through a PC Station you must purchase and install the SIMATIC Softnet S7 for PROFIBUS license.

Hardware Identification — CP 5611 vs. CP 5611 A2

The CP 5611 A2 is a low-cost PCI card for connecting a PG/PC to PROFIBUS DP and MPI networks. The "A2" suffix identifies a hardware revision with an updated ASIC and slightly lower power consumption, but the S7 firmware image, the PROFIBUS stack, and the driver interface are identical to the original CP 5611. Siemens publishes the A2 card in their catalog and manuals under the original "CP 5611" entry because no functional or configuration difference exists from the engineering point of view.

Parameter CP 5611 (6GK1-561-1AA00) CP 5611 A2 (6GK1-561-1AA01)
Bus system PROFIBUS DP, MPI PROFIBUS DP, MPI
Baud rate 9.6 kbit/s to 12 Mbit/s 9.6 kbit/s to 12 Mbit/s
Bus connector 9-pin D-sub female 9-pin D-sub female
Host interface PCI (5 V) PCI (universal 3.3 V / 5 V)
Driver / firmware SIMATIC NET DP Base Identical — backward compatible
Step 7 catalog entry "CP 5611" Same "CP 5611" entry (no A2 suffix)

Because the two cards share the same driver, the same firmware, and the same catalog representation, you do not need a separate GSD, HSP, or hardware update to use the A2 in a Step 7 V5.3 SP3 project. Inserting the original CP 5611 in the PC Station hardware configuration is correct and supported for the A2 card. Verify the article number in the device properties reads 6GK1-561-1AA01 to confirm the engineering station picked up the A2 hardware.

Root Cause Analysis

Two distinct root causes account for almost every reported failure of the form "WinCC Flexible Runtime shows static graphics / tags do not refresh". They can occur independently or together.

  1. Wrong S7ONLINE access point on the runtime PC. When the runtime PC uses the S7ONLINE access path (the default for direct connections from WinCC Flex RT to the PLC), the Windows tool "Set PG/PC Interface" (in German: PG/PC-Schnittstelle einstellen) decides which physical interface receives the S7 protocol traffic. If the access point is set to a different card (e.g. TCP/IP over the on-board Ethernet, a different CP, or "PC internal"), every WinCC Flex RT read/write attempts to reach the CPU through the wrong medium. The PLC remains reachable in Step 7 because Step 7 can be pointed at a different access point than the runtime, masking the problem.
  2. Missing or unlicensed SIMATIC NET on a PC Station. When the project is engineered as an integrated PC Station inside the Step 7 project (WinCC Flex RT configured as a "PC station" rather than a direct connection), the runtime loads its connection list from the Station Configurator, not from the S7ONLINE access point. If SIMATIC NET is not installed, or if only the Ethernet Softnet Lean license is present, the CP 5611 A2 is not bound to the PC Station's PROFIBUS slot and the connection silently fails. No tags update, but no error is raised in the WinCC Flex RT UI either.
Diagnostic clue. If a tag can be forced from Step 7 over the same CP 5611 A2 card (i.e. the same physical hardware), then the cabling, baud rate, bus terminator, PROFIBUS address, and S7-300 CPU are all proven good. The failure is therefore in software — access point or PC Station binding — not in the field wiring.

Communication Architecture: Two Valid Paths

There are exactly two supported communication architectures for a Panel PC running WinCC Flex RT to a SIMATIC S7-300 CPU over a CP 5611 A2. Choosing the right one is the first configuration decision.

Aspect Path A — S7ONLINE Direct Path B — PC Station with SIMATIC NET
Engineering model Standalone HMI project, runtime "HMI Runtime" with an S7 connection Integrated PC Station in Step 7 NetPro, runtime is one component of the station
Access point S7ONLINE → CP 5611 A2 (PROFIBUS) PC Station internal index — handled by Station Configurator
Required on PC WinCC Flexible Runtime only WinCC Flexible Runtime + SIMATIC NET PC Software + Softnet S7 PROFIBUS license
Configuration tool Set PG/PC Interface (Control Panel applet) Station Configurator + Step 7 HWCN / NetPro on engineering station
Typical use Single-PLC, small visualization, replacement of OP 370 / MP 370 Multi-PLC, redundant paths, OPC clients, archive server
Failure mode if misconfigured Tags do not update; PLC still online in Step 7 Runtime starts, station symbol blinks yellow, no tags update

Solution Path A — S7ONLINE Access Point (Direct)

Path A is the correct choice for a direct replacement of an OP/MP panel by a Panel PC running WinCC Flex RT, and for projects with a single S7-300 PLC. No SIMATIC NET license is required.

  1. Install WinCC Flexible Runtime 2005 or later on the Panel PC. The installer automatically deploys the CP 5611 / CP 5611 A2 driver (DP Base) and the "Set PG/PC Interface" tool.
  2. Open the Windows Control Panel, then "Set PG/PC Interface" (PG/PC-Schnittstelle einstellen). Select "S7ONLINE" as the access point of the application.
  3. For the interface parameter assignment, choose "CP 5611 A2 (PROFIBUS)" from the dropdown. If the entry shows only "CP 5611", that is the A2 — Windows displays only the marketing name without the A2 suffix.
  4. Click "Properties". Configure the PROFIBUS address of the CP 5611 A2 (typical: 0 for master, 1 for the engineering slot, 2 for the runtime slot if the PG and the Panel PC are on the same bus). The baud rate is auto-detected up to 12 Mbit/s.
  5. In the WinCC Flexible ES, open the HMI project, double-click "Connections" and verify the connection to the S7-300 CPU is type "S7" with the correct PLC PROFIBUS address, rack 0 / slot 2 for an S7-300 CPU 312.
  6. Compile the project and download to the runtime. The Panel PC should connect within a few seconds. Test by toggling a bit in the PLC and watching the WinCC Flex RT tag change.
Tip. If "S7ONLINE" is not present in the dropdown, you have not installed WinCC Flex Runtime or the access point was not registered. Reinstall Runtime with administrator rights so the access point is published to the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Siemens\S7ONLINE.

Solution Path B — PC Station with SIMATIC NET

Path B is mandatory when the WinCC Flex RT is part of an integrated Step 7 PC Station, when you need more than four PLC connections, or when you also need an OPC server. It requires the SIMATIC NET PC Software DVD and a Softnet S7 PROFIBUS license.

  1. Insert the SIMATIC NET PC Software DVD and install the "SIMATIC NET PC Software" component with PROFIBUS support. Reboot.
  2. Insert the SIMATIC Softnet S7 for PROFIBUS license key. Without this, the CP 5611 A2 runs in demo mode for 14 days only.
  3. On the engineering station, open the Step 7 project. Open HWCN for the PC Station, slot 1 should contain the "WinCC Flexible RT" application module. Slot 2 or 3 should contain the "CP 5611 A2" module. Drag the CP 5611 A2 from the catalog (path: SIMATIC PC Station → CP 5611 A2 or CP 5611) into the PC Station. Set the PROFIBUS address.
  4. Open NetPro. Add an S7 connection from the PC Station to the S7-300 CPU. Compile and download the PC Station configuration.
  5. On the runtime PC, open the "Station Configurator" desktop application. Click "Station Name" and assign the same computer name as in HWCN. The CP 5611 A2 should appear in the modules list with a green check; the WinCC Flex RT component should be in slot 1 with a green check.
  6. Start the SIMATIC NET "Configuration Console" (S7 Configuration Console for PROFIBUS). Verify the CP 5611 A2 is in "Configured and OK" state.
  7. Start WinCC Flex RT. The connection establishes through the SIMATIC NET path, not through the S7ONLINE access point.
Important. The S7ONLINE access point and the PC Station are mutually exclusive at runtime. If both are installed, S7ONLINE wins. Remove or disable the S7ONLINE access to the CP 5611 A2 if you are running Path B, to prevent intermittent failures.

Step 7 Hardware Catalog Behavior

Step 7 V5.3 SP3, V5.4, and V5.5 ship with a hardware catalog that does not list "CP 5611 A2" as a separate entry. The catalog lists the original "CP 5611" under SIMATIC PC Station → CP 5611. Hardware Support Packages (HSPs) released after Step 7 V5.3 do not add a new entry for the A2 — Siemens intentionally consolidated the entries to keep the catalog manageable.

This catalog gap is by design. The CP 5611 A2 is a drop-in replacement for the original CP 5611 from the configuration side, and the catalog entry "CP 5611" is correct for both. Do not copy entries from another project, install a third-party HSP, or rename the article number field — the SIMATIC PC Station validates the catalog entry against the installed driver and rejects mismatches at download time.

If you require the A2 to be displayed with its suffix in the station, you can rename the entry in HWCN (right-click → Object Properties → Name) without changing the article number field. The renaming is purely cosmetic and has no effect on the runtime connection. For an authoritative engineering reference, consult the Siemens Industry Online Support entry for the CP 5611 A2 under product family 6GK1 561, which documents the A2 as a catalog-compatible successor to the original CP 5611.

WinCC Flexible Runtime — Tag and Area Pointer Configuration

Tags in WinCC Flex RT update over the S7 protocol at the configured acquisition cycle (default 1 s for binary tags, 2 s for analog tags). The runtime does not subscribe to change-of-state events; it polls. If a tag does not update at runtime, the failure is therefore not in the polling rate but in one of three layers:

  1. Tag address mismatch. The tag points to a different DB or bit offset than the PLC program writes. Cross-check the tag's DB number, byte offset, and bit offset against the cross-reference in the S7 program.
  2. Connection not established. The WinCC Flex RT status line shows "Connection: Not established" or "Connection: Interrupted". This is the S7ONLINE / PC Station binding issue described above.
  3. Area pointer not configured. The WinCC Flex RT uses "area pointers" to exchange coordination and date/time data. If the area pointer is missing, certain functions (recipe transfer, alarm acknowledgment, screen selection) silently fail. Open the connection's "Area Pointers" tab and verify at minimum the "Coordination" pointer is enabled and points to a valid DB.
Area Pointer Direction Length Required For
Coordination Bidirectional 1 word Lifecycle, "Runtime is active" handshake
Date/Time PLC → HMI 8 bytes Time synchronization
Screen Number PLC → HMI 1 word PLC-driven screen selection
User Version HMI → PLC 1 word Project version ID
Job Mailbox Bidirectional 4 words Recipe transfer, password change

Verification and Commissioning Tests

  1. Open the S7 Configuration Console on the runtime PC. Verify the CP 5611 A2 shows status "OK" and the bus is "Online".
  2. Open the SIMATIC NET Diagnostics tool. Look for bus errors, repeated token, or slave diagnostics on the S7-300 CPU.
  3. From the Windows command line on the runtime PC, run the S7DOS / S7NETPG utility to test the S7 connection by issuing a single read to DB0.DBX0.0 of the target CPU. A successful read confirms Path A or Path B is correctly bound.
  4. In WinCC Flex RT, open the "Tools" menu → "Diagnostics". The status of all configured connections is listed with the last update time and error code.
  5. Force a known bit in the S7-300 PLC using the Step 7 Monitor/Modify tool. Verify the corresponding WinCC Flex RT tag changes within one acquisition cycle (1 s for binary tags).

Troubleshooting Matrix

Symptom Likely Cause Corrective Action
CP 5611 A2 not in Step 7 catalog Catalog behavior — A2 uses CP 5611 entry Insert "CP 5611" from SIMATIC PC Station; verify article number 6GK1-561-1AA01 in the device properties
Tags do not update, PLC online in Step 7 S7ONLINE access point set to wrong interface Open "Set PG/PC Interface" → assign S7ONLINE → CP 5611 A2 PROFIBUS
Runtime starts, Station Configurator status yellow SIMATIC NET not installed or license missing Install SIMATIC NET PC Software, install Softnet S7 PROFIBUS license
"Connection: Interrupted" in RT diagnostics PROFIBUS address mismatch, baud rate mismatch, or terminator off Compare addresses in HWCN vs. CPU front panel; enable terminator on first/last device
Tags update slowly or intermittently Too many tags on one acquisition cycle, or bus errors Stagger acquisition cycles; check PROFIBUS with diagnostic repeater
Runtime freezes on startup Area pointer DB does not exist or is too short Create the area pointer DB in the S7 program; recompile and download
Forced bit does not appear in RT Tag is on wrong DB / wrong offset Cross-reference the tag address against the S7 program symbol table
OPC client cannot read tags Softnet S7 license missing (demo mode expired) Install Softnet S7 PROFIBUS license key

Field-Proven Notes and Constraints

  • The CP 5611 A2 is functionally identical to the original CP 5611 from the Step 7 engineering and WinCC Flexible runtime perspective. Any project that worked with the predecessor will work with the A2 without re-engineering the catalog.
  • SIMATIC NET license keys are tied to the host SID. Moving the license to another PC requires deinstallation on the original and reactivation on the new one through the Automation License Manager.
  • For applications that require reading the CP 5611 A2 from a non-Siemens application (for example third-party SCADA, C# OPC clients, or test tools), use the SIMATIC NET OPC server or the documented SAPI / DLL interface that ships with SIMATIC NET. Direct DLL calls to the PROFIBUS driver are not officially documented and should be treated as a last resort.
  • Verify that the PROFIBUS cable is properly terminated at both ends. A common field fault is the integrated terminator on the PROFIBUS connector being switched off, which produces intermittent updates rather than a hard fault — exactly the symptom of "tags change when I change screen and come back".
  • For long-term stability, set the CP 5611 A2 PROFIBUS address to a value outside the range 0–2 (the convention is to reserve 0 for the engineering PG and 1–2 for the runtime or service PC). This avoids address conflicts when a service PG is connected to a live network.

FAQ

Why is the CP 5611 A2 not in my Step 7 hardware catalog?

Step 7 V5.3 SP3, V5.4, and V5.5 intentionally list the CP 5611 A2 under the original "CP 5611" catalog entry. The two cards share the same driver and firmware, so a single catalog entry covers both. Insert "CP 5611" from the SIMATIC PC Station catalog; verify the article number is 6GK1-561-1AA01 in the device properties.

Do I need SIMATIC NET to connect WinCC Flexible Runtime to an S7-300 over a CP 5611 A2?

Only if the runtime is part of an integrated PC Station (Path B). For a direct connection (Path A), WinCC Flexible Runtime and the Set PG/PC Interface tool are sufficient. The Softnet Ethernet Lean license bundled with WinCC Flex RT covers Ethernet only and cannot be used for the CP 5611 A2 PROFIBUS path.

What is the difference between the S7ONLINE access point and a PC Station configuration?

The S7ONLINE access point is a Windows-level setting that routes S7 protocol traffic to a single physical interface (in this case the CP 5611 A2). A PC Station configuration binds the S7 connections to modules inside a named PC station managed by the Station Configurator. They are mutually exclusive at runtime; choose one architecture per project.

Why are my WinCC Flexible Runtime tags not updating even though Step 7 can read the PLC?

Step 7 and WinCC Flex RT can use different access points. Verify in "Set PG/PC Interface" that S7ONLINE points to the CP 5611 A2 PROFIBUS, not to Ethernet or another card. If you are running as a PC Station, verify the Station Configurator shows the CP 5611 A2 in "Configured and OK" state.

Can I use the CP 5611 A2 without STEP 7 installed on the runtime PC?

Yes, for a direct connection from WinCC Flex RT you need only WinCC Flex Runtime and the Set PG/PC Interface tool. Step 7 is required only on the engineering station to configure the project. For a PC Station configuration, SIMATIC NET must be installed on the runtime PC, but Step 7 itself is still optional.

What PROFIBUS addresses are valid for the CP 5611 A2?

Valid addresses are 0 to 126. The card typically uses address 0 in master mode, 1 or 2 in slave mode, and must be unique on the bus. The S7-300 CPU PROFIBUS address is configured separately in the CPU properties (default 2) and must not collide with the PC card address.

Back to blog