1. System Architecture Overview
A bidirectional S7-1200 telecontrol link over GPRS involves five distinct software and hardware elements that must agree on addressing, buffer geometry, and trigger semantics before a single value can move in either direction. The CP1242-7 GPRS module sits in the S7-1200 backplane and terminates the GPRS tunnel, the Telecontrol Server Basic (TCSB) OPC server terminates the TCP session in the control center, and a WinCC Advanced Runtime (or any OPC DA client) consumes or produces data on top of the TCSB namespace.
The data path for a read (PLC to HMI) is straightforward: the S7-1200 user program calls TC_SEND, copying a slice of a process DB to the CP1242-7 internal send buffer; the CP1242-7 frames the data, applies the configured GPRS APN, and transmits it to the TCSB via the GSM/GPRS network; TCSB validates the frame and writes the payload into its internal mirror DB1 at the offset configured in the CP station definition; the embedded OPC DA server then exposes the mirror DB1 region as browseable items, and WinCC reads them using AsyncIO2 subscription or synchronous Read calls.
The write path (HMI to PLC) is the mirror image, and is the part that often breaks on the first integration: WinCC writes an item (or set of items) to the TCSB OPC server; TCSB stages the write into a send buffer associated with the CP station; on the next polling cycle (or upon explicit trigger) TCSB opens a frame and pushes it to the CP1242-7 over the existing GPRS tunnel; the CP1242-7 receives the frame, validates the sequence number and the partner ID, and signals TC_RECV in the S7-1200 user program; TC_RECV copies the payload from the CP receive buffer into a process DB that the application logic can read.
The first three steps in the write path are entirely on the TCSB/OPC side; the last two are entirely on the PLC side. The configuration split that confuses new integrators is that TCSB does not know your DB structure; it only knows an opaque byte buffer that the CP and the user program agree upon. The WinCC client therefore does not write to DB1.DBX0.0 on the S7-1200; it writes to a TCSB mirror offset, and the user program is responsible for mapping that offset back to a real PLC tag.
2. CP1242-7 GPRS Hardware Variants and Firmware Constraints
The CP1242-7 exists in two hardware revisions that behave very differently with respect to the data point configuration concept introduced with TIA Portal V15.1.
| Article Number | Designation | Data Point Config | TCSB Required | Typical Firmware |
|---|---|---|---|---|
| 6GK7242-7KX30-0XE0 | CP 1242-7 GPRS V1 | No | Yes (TCSB V2 / V3) | V1.1.x |
| 6GK7242-7KX31-0XE0 | CP 1242-7 GPRS V2 | Yes (TIA V15.1+) | Optional (TCSB still supported) | V2.1.x |
The variant in this discussion is the V1 module. Because the V1 CP has no internal data point configuration editor, the only supported way to expose PLC data to TCSB is by using the TC_SEND / TC_RECV instruction pair from the "Telecontrol" library and accepting that TCSB will see the data as a flat byte buffer. The CP itself does not parse tag names; it transports raw octets and a small header containing the connection ID, sequence number, and a one-byte command code that distinguishes spontaneous frames from polled frames.
Physical constraints that must be respected regardless of firmware:
- Supply voltage: 24 V DC (19.2 to 28.8 V), current draw typically 100 mA plus peaks to 1.2 A during GPRS attach.
- Antenna: SMA female, 50 ohm, omni-directional, gain ≤ 2.5 dBi for Quad Band GSM 850/900/1800/1900 MHz.
- SIM: Mini-SIM (2FF), 3 V logic. PIN-protected SIMs are supported but the PIN must be entered into the CP configuration; the CP does not support entering a PIN from a HMI panel.
- Operating temperature: -20 to +70 °C. The CP must be mounted to the left of the CPU with one slot separation at minimum to keep the backplane bus noise within Siemens limits.
LED behavior that matters for write diagnostics:
| LED | State | Meaning for Write Path |
|---|---|---|
| SF (red) | On | CP group or system fault. Write frames are discarded. Check diagnostics buffer in TIA Portal. |
| BS (green) | On | Backplane link to CPU is up; TC_SEND/TC_RECV can run. |
| TX (yellow) | Flashing | CP is sending a frame to TCSB. If it never flashes when TC_SEND triggers, the backplane handshake is broken. |
| RX (green) | Flashing | CP received a frame from TCSB (i.e. an incoming write). Absence of RX flash on a TCSB-initiated write indicates a routing or APN problem. |
| DIAG (red) | On | Maintenance event, e.g. SIM locked, APN rejected, GPRS not attached. |
The CP1242-7 V1 manual is published under Siemens entry ID 109749944. The V2 manual, which contains the data point configuration model that is not available on V1, is entry ID 109973859. Always confirm your article number on the front plate of the module before assuming V2 features are usable.
3. Telecontrol Server Basic (TCSB) OPC Interface
TCSB ships with an embedded OPC DA 2.05a / 3.0 server. The ProgID varies by version:
- TCSB V2.x:
TCSB.OPCServer - TCSB V3.0.0 to V3.0.3:
TCSB.OPCServer.1 - TCSB V3.0.4 and later:
TelecontrolServerBasic.OPCServer
When adding the OPC channel in WinCC Advanced, browse the local or remote machine for the CLSID {52D7B9C9-E229-4CD4-A0A0-1C5F45A3B6D6} (TCSB OPC DA wrapper) or pick the ProgID from the dropdown. The CLSID is documented in the TCSB manual 109749948.
Item naming for the mirror DB1 of a CP station follows a fixed convention:
S7:[<StationName>]DB1,<ByteOffset>[,<DataType>][.<BitOffset>]
Worked examples (StationName = CP_PUMP_01):
| Item ID | PLC Type | Bytes | Bit-level Addressable |
|---|---|---|---|
S7:[CP_PUMP_01]DB1,0,S7.BYTE |
BYTE | 1 | Yes (.0 to .7) |
S7:[CP_PUMP_01]DB1,2,S7.WORD |
WORD (little-endian) | 2 | Yes (.0 to .15) |
S7:[CP_PUMP_01]DB1,4,S7.DWORD |
DWORD (little-endian) | 4 | Yes (.0 to .31) |
S7:[CP_PUMP_01]DB1,8,S7.REAL |
REAL (IEEE 754 float) | 4 | No |
S7:[CP_PUMP_01]DB1,12,X4 |
BOOL (bit 4 of byte 12) | 0 | Single bit |
The mirror DB1 is conceptually split into two halves. The lower half (offsets 0 to 999 by default) is the send image populated by TC_SEND on the S7-1200; the upper half (offsets 1000 to 1999 by default) is the receive image that TC_RECV copies out of on the S7-1200. The split is configurable per CP station in TCSB under Station Properties → Data Direction, and the S7-1200 program must match that split by pointing SD_1 (send area) and RD_1 (receive area) at the same offsets.
4. Prerequisites and Software Versions
The following software baseline has been validated for CP1242-7 V1 with TCSB V3.0.4 and WinCC Advanced V14 SP1 on a Windows 7 SP1 / Windows Server 2008 R2 control room PC. Newer combinations (TIA V15.1, V16, WinCC V15.1, V16) are supported but require the matching TCSB V3 maintenance release.
- TIA Portal V14 SP1 Update 6 or later (V15, V15.1, V16 supported for engineering; TIA V16 is required if you want to add an OPC UA server on the S7-1200 side as a parallel channel).
- STEP 7 Basic V14 SP1 (bundled with the above).
- WinCC Advanced V14 SP1 (or WinCC Comfort / Professional V14 SP1).
- Telecontrol Server Basic V3.0.4 or later; TCSB V2.1 is end of life and no longer recommended for new projects.
- S7-1200 CPU firmware V4.2 minimum; V4.4 required for the embedded OPC UA server option discussed in Section 9.
- CP 1242-7 firmware V1.1.10 minimum. Earlier V1.0.x firmware has a known bug with fragmented receive frames that corrupts payloads above 480 bytes.
- .NET Framework 4.7.2 on the TCSB host.
- A SIM card with public APN, a fixed public IP from the M2M provider (or a hostname that resolves to one), and an inbound port 55097 / TCP forwarded to the TCSB host. The default TCSB port is 55097 and is configurable in the registry under
HKLM\SOFTWARE\Siemens\TelecontrolServerBasic\TCSB\ListenPort.
5. S7-1200 User Program: TC_CON, TC_SEND, TC_RECV
The Telecontrol library is installed in TIA Portal under Options → Support Packages → Telecontrol_S7_1200_1500. After installation, three FBs and their associated UDTs become available in the Libraries → Telecontrol folder:
| Block | FB Number | Function | Instance DB Allocation |
|---|---|---|---|
TC_CON |
FB 840 | Establishes and monitors the connection to TCSB | One instance per CP station |
TC_SEND |
FB 841 | Pushes a byte range to TCSB on a rising edge of REQ | One instance per send area |
TC_RECV |
FB 842 | Copies the most recent received frame from CP to a DB on rising edge of EN_R | One instance per receive area |
5.1 DB100 — Send Buffer (TC_SEND source)
Declare DB100 as a non-optimized (i.e. classic, "with absolute addressing") DB. The data direction is from PLC to TCSB. A typical layout for a small pump station:
DATA_BLOCK "DB_Telecontrol_Send"
{ S7_Optimize_Access := 'FALSE' }
VERSION : 0.1
NON_RETAIN
STRUCT
Heartbeat : WORD; // byte 0, increments every TC_SEND cycle
Pump1_Run : BOOL; // byte 2.0
Pump1_Fault : BOOL; // byte 2.1
Pump1_Speed : INT; // bytes 4..5, RPM feedback
Pump1_Current : REAL; // bytes 8..11, ampere
TankLevel_pct : REAL; // bytes 12..15, 0..100
Spare_1 : ARRAY[0..83] OF BYTE; // bytes 16..99, reserved
END_STRUCT;
END_DATA_BLOCK
5.2 DB110 — Receive Buffer (TC_RECV destination)
Same rules: non-optimized, classic addressing. This DB is written by TC_RECV and read by the application logic. It is the mirror image of the WinCC write area.
DATA_BLOCK "DB_Telecontrol_Recv"
{ S7_Optimize_Access := 'FALSE' }
VERSION : 0.1
NON_RETAIN
STRUCT
Cmd_Heartbeat : WORD; // byte 0, echoes back the HMI command counter
Cmd_Pump1_Start : BOOL; // byte 2.0
Cmd_Pump1_Stop : BOOL; // byte 2.1
Cmd_Pump1_Speed : INT; // bytes 4..5, RPM setpoint
Cmd_Valve1_Target: REAL; // bytes 8..11, % open
Spare_2 : ARRAY[0..87] OF BYTE; // bytes 12..99, reserved
END_STRUCT;
END_DATA_BLOCK
5.3 TC_CON Call (OB1, first scan)
// SCL
"iDB_TC_CON"( // instance DB name
REQ := TRUE,
ID := 1,
PARTNER_IP := 'tcserver.plant.local',
PARTNER_PORT := 55097,
LOCAL_PORT := 0, // 0 = any free port
ACTIVE_ESTAB := TRUE, // CP initiates; works through most NATs
STATUS := "DB_Telecontrol_Diag".ConStatus,
ERROR => "DB_Telecontrol_Diag".ConError,
CONNECTED => "DB_Telecontrol_Diag".ConEstablished
);
5.4 TC_SEND Call (cyclic, OB1)
// SCL — call every 100 ms is fine for a heartbeat, but TC_SEND is
// edge-triggered. Use a 1 Hz edge from a clock flag.
"iDB_TC_SEND"(
REQ := "Clock_1Hz",
ID := 1,
SD_1 := P#DB100.DBX0.0 BYTE 100, // first 100 bytes of DB100
LEN := 100,
DONE => "DB_Telecontrol_Diag".SendDone,
BUSY => "DB_Telecontrol_Diag".SendBusy,
ERROR => "DB_Telecontrol_Diag".SendError,
STATUS=> "DB_Telecontrol_Diag".SendStatus
);
5.5 TC_RECV Call (cyclic, OB1)
// SCL — EN_R is level-triggered; the FB evaluates the CP receive
// buffer on every call and latches NDR on a new frame arrival.
"iDB_TC_RECV"(
EN_R := TRUE,
ID := 1,
RD_1 := P#DB110.DBX0.0 BYTE 100, // first 100 bytes of DB110
LEN := 100,
NDR => "DB_Telecontrol_Diag".RecvNDR,
BUSY => "DB_Telecontrol_Diag".RecvBusy,
ERROR => "DB_Telecontrol_Diag".RecvError,
STATUS=> "DB_Telecontrol_Diag".RecvStatus
);
The STATUS word of each FB follows the standard Siemens SFB STATUS layout. The lower byte is the event class, the upper byte is the event number. Common values to expect on a healthy link:
| STATUS (hex) | Block | Meaning |
|---|---|---|
| 0x0000 | TC_SEND / TC_RECV | No error, no active job |
| 0x0001 | TC_SEND | Job completed successfully (DONE pulse) |
| 0x0002 | TC_RECV | New data received (NDR pulse) |
| 0x7000 | TC_SEND / TC_RECV | No job active, ready |
| 0x7001 | TC_SEND / TC_RECV | Job active, first call |
| 0x7002 | TC_SEND / TC_RECV | Job active, follow-up call |
| 0x80A1 | TC_CON | Connection terminated by partner (TCSB) |
| 0x80B1 | TC_CON | Connection establishment failed (timeout, DNS, APN) |
| 0x80C1 | TC_SEND | Send buffer DB does not exist or is optimized (must be classic) |
| 0x80C3 | TC_RECV | RD_1 length exceeds 480 bytes (CP1242-7 V1 fragmentation limit) |
SD_1 and RD_1 must be classic (non-optimized) DBs, and the address must be byte-aligned. Word and DWord types inside the DB must be on even or quad-byte boundaries respectively if you intend to use typed OPC items such as S7.WORD; the OPC DA bridge in TCSB does not byte-swap.6. TCSB Configuration for Bidirectional Data
After installing TCSB V3, perform the following steps to enable write-back on a CP1242-7 V1 station. The default install path is C:\Program Files\Siemens\Telecontrol Server Basic and the engineering front-end is started from the Windows start menu under Siemens Automation → Telecontrol Server Basic Config.
- Open TCSB Config and add a new CP station with the same Station Name that the CP1242-7 sends in its Partner field. Station names are case-sensitive and limited to 24 ASCII characters; do not include spaces or hyphens.
- Set the Station Type to S7-1200 with CP 1242-7 V1. The dropdown changes the data point editor to the legacy buffer view; selecting V2 by accident will grey out the receive direction on the lower offsets.
- On the Connection tab, enter the public IP / hostname that the CP can reach, the TCP port (default 55097), and set Telecontrol Direction to Bidirectional. Setting this to Read Only is a frequent cause of "I can read every item but I cannot write".
- On the Data tab, configure the mirror DB1 geometry. For the example in Section 5, enter:
- Send area: byte offset 0, length 100 (matches
SD_1on TC_SEND). - Receive area: byte offset 100, length 100 (matches
RD_1on TC_RECV on the S7-1200 side; TCSB does not require the S7-1200 to start the receive buffer at offset 100, but the convention avoids overlap).
- Send area: byte offset 0, length 100 (matches
- Tick Allow OPC write access on the receive area. Without this tick, TCSB rejects every OPC write to offsets 100..199 with HRESULT 0x80070005 (E_ACCESSDENIED) at the WinCC side.
- Click Apply and Activate Configuration. The TCSB runtime service picks up the change within 5 seconds.
Win32_Servicename is Siemens Telecontrol Server Basic, default startup Automatic (Delayed Start). - Verify the OPC namespace with a third-party client such as Matrikon OPC Explorer or Kepware OPC Quick Client. Connect to the ProgID, browse to the station, and try a synchronous Write of a single byte at offset 100. If the write returns
S_OKand TCSB logs a WRITEFORWARD entry inC:\ProgramData\Siemens\Telecontrol Server Basic\Logs\trace.log, the server side is correctly configured.
HKLM\SOFTWARE\Siemens\TelecontrolServerBasic\LogLevel = 5 to see the frame-level hex dumps of every incoming and outgoing frame. Reset to Information (3) for production; the verbose log can grow several MB per minute on a busy station.7. WinCC Advanced Configuration for OPC Write Access
Open the WinCC Advanced project that hosts the HMI tags, then proceed as follows.
- In the project tree, right-click HMI Tags and select Add New Driver → OPC → WinCC OPC DA Client. The driver registers as OPC in the tag administration.
- Open the OPC driver connection, click OPC Server, and pick the TCSB ProgID from the dropdown. If the TCSB host is remote, type the hostname in the Server Computer field and the user must have DCOM access to the TCSB machine. See TCSB manual 109749948 for the DCOM hardening checklist.
- Click Browse. The OPC browser shows the full mirror DB1 of the CP station as items
S7:[StationName]DB1,offset,type. Add only the items you actually need; WinCC allocates a tag subscription per item and a CP station with 200 items will saturate the GPRS downlink on a Class 10 SIM. - For each write tag, open the tag properties and set Acquisition Mode to Cyclic continuous and Update to 1 s. The Write Permission box on the Options tab must remain checked; this is the bit that allows WinCC to push the tag value to the OPC server when the operator changes it on a screen. Uncheck Read-only; by default WinCC tags imported via the OPC browser are read-only because the OPC DA 3.0 specification lets the server tag items as read-only in the browser metadata.
- Wire the tag to an I/O field or a button on a screen. To verify write direction without disturbing the real process, point a button to a tag bound to a spare offset in the receive area, for example offset 150 (a byte inside the
Spare_2area). A successful click increments the value seen at the PLC side within one GPRS round trip (typically 800 ms to 4 s on Class 10 GPRS). - Save the project, transfer to the runtime, and start Runtime. The status bar at the bottom of Runtime shows the OPC connection state; a green bar means the TCSB OPC DA server has accepted the subscription.
7.1 Why a "writable" item is not enough
OPC DA defines write-ability at the item level, but the WinCC tag editor shows it as a property of the WinCC tag, not the OPC item. The combination of factors that must all be true for a write to reach the S7-1200 is:
- The TCSB station definition has Bidirectional telecontrol direction.
- The mirror offset being written is in the receive half of DB1.
- The receive area has Allow OPC write access ticked.
- The CP station has not exceeded the operator-defined Max writes per minute quota (default 60). The quota prevents a runaway HMI script from saturating the GPRS uplink.
- The WinCC tag has Write Permission enabled in the tag properties.
- The HMI screen object bound to the tag has its Operating mode set to Switch or Output rather than Display.
8. OPC Item Addressing and DB Offset Mapping
The mapping from a WinCC tag to a byte in the S7-1200 receive DB is the most error-prone step on first integration. The rule set is straightforward but the byte order can confuse engineers who are used to S7 big-endian conventions.
| WinCC Tag (TCSB Item) | TSCB Byte Offset | S7-1200 Byte in DB110 | S7-1200 Type |
|---|---|---|---|
S7:[CP_PUMP_01]DB1,100,S7.BYTE |
100 | DB110.DBB0 | BYTE |
S7:[CP_PUMP_01]DB1,102,S7.WORD |
102 | DB110.DBB2..3 | WORD (little-endian) |
S7:[CP_PUMP_01]DB1,104,S7.INT |
104 | DB110.DBB4..5 | INT (little-endian) |
S7:[CP_PUMP_01]DB1,108,S7.REAL |
108 | DB110.DBB8..11 | REAL (IEEE 754, little-endian) |
S7:[CP_PUMP_01]DB1,102,X0 |
102, bit 0 | DB110.DBX2.0 | BOOL |
Note the offset math: the TCSB item byte offset is an absolute offset into the global mirror DB1, while the S7-1200 byte in DB110 is relative to the start of DB110. The mapping only coincides when the TCSB receive area starts at offset 0 of the global mirror; the example in Section 6 deliberately starts the receive area at offset 100 to keep send and receive halves disjoint.
S7.WORD, TCSB will not byte-swap; the value displayed in WinCC will be the S7-native value. Mismatched display values typically indicate a wrong type specifier (e.g. S7.DWORD on a REAL) or a mis-aligned offset that picks up adjacent bytes.To avoid overlap, draw a layout grid like the following on a whiteboard before declaring a project ready. The offsets shown are in the global mirror DB1 of TCSB:
0x0000 ┌────────────────────────────────────┐
│ Send area: DB100 mirrored by TCSB │
│ 100 bytes (heartbeat, telemetry) │
0x0064 ├────────────────────────────────────┤
│ Receive area: DB110 from WinCC │
│ 100 bytes (commands, setpoints) │
0x00C8 ├────────────────────────────────────┤
│ Reserved (spare / future use) │
0xFFFF └────────────────────────────────────┘
9. Alternative Architectures: OPC UA on S7-1200
The S7-1200 CPU firmware V4.4 and later (released 2018) includes an embedded OPC UA server that can be configured directly in TIA Portal V15.1 and later. With the OPC UA server enabled, the S7-1200 can expose DB tags with full read/write access over a standard TCP connection on port 4840, with certificate-based authentication, subscription support, and optional encryption. This is a viable alternative to the CP1242-7 V1 + TCSB architecture for new projects, but it does not solve the GPRS transport problem: the OPC UA server still has to reach the control room over a mobile network, and the CP1242-7's GPRS tunnel is one of the few mechanisms Siemens provides for S7-1200 stations to traverse a mobile APN with a stable partner IP and firewall-friendly single port.
For green-field projects, the recommended architecture is:
- Use the CP 1243-1 for wired / Internet connections and put the OPC UA server directly on the S7-1200 (TIA V16+). WinCC Advanced V16 can consume the OPC UA server using the OPC UA Client channel with no TCSB in the path.
- Use the CP 1242-7 GPRS V2 (article 6GK7242-7KX31-0XE0) for mobile connections and configure data points natively in TIA V15.1+. TCSB is still supported as an alternative path, but the data point configuration reduces the engineering effort for simple read/write mirroring.
- For legacy CP 1242-7 V1 stations already in the field, the TCSB + TC_SEND/TC_RECV pattern described in this article is the only viable bidirectional GPRS solution.
Security note: OPC UA on the S7-1200 supports certificates, but the CPU is shipped with a self-signed certificate that must be replaced and distributed to the WinCC OPC UA client. TCSB uses DCOM and Windows credentials; if your control room is hardened to DCOM lockdown, OPC UA is significantly easier to firewall correctly.
10. Verification and Diagnostics
A working write path should be confirmed with at least three independent checks before being handed over to operations.
10.1 Online CP1242-7 diagnostics (TIA Portal)
- Connect the engineering PG to the S7-1200 either over the same backplane or via the CP1242-7's remote tunnel (TIA V14 SP1 supports online diagnostics over a telecontrol connection, but the GPRS round-trip latency is significant).
- In the project tree, right-click the CP1242-7 → Online & Diagnostics → Diagnostics Buffer. Look for entries with Event ID 0xE0 (connection establishment) and 0xE1 (connection termination). A repeating 0xE1 every 30 s means the CP is dropping and re-establishing the tunnel, usually an APN or DNS issue.
- Expand Telecontrol Service → Connection Status. The status word
STSshould be 0x0004 (Connected) whenTC_CONhas established the link, and 0x0006 (Data Active) immediately after a TC_SEND or TC_RECV completes.
10.2 TCSB runtime logs
- Open
C:\ProgramData\Siemens\Telecontrol Server Basic\Logs\trace.login the configured log viewer. The file rolls at midnight; the current day is intrace.logand the previous day is intrace.log.1. - Search for
WRITEFORWARD. Each line shows the station name, the byte offset, the byte count, the sequence number, and the timestamp in ISO 8601 format. AWRITEFORWARDfollowed within 5 s by aWRITEACKfrom the CP confirms a successful round trip. - Search for
WRITEREJECT. Common rejection reasons and their remedies are listed in the troubleshooting matrix below.
10.3 WinCC Advanced Runtime diagnostics
- Open the Runtime window, press Ctrl+D to bring up the diagnostics page, and click Connections → OPC. The connection status icon should be green; a yellow icon means the OPC subscription is in error and a red icon means the WinCC tag cannot reach the server.
- Open a tag table that contains the write tag, right-click the value column, and select Modify/Force. Enter a value, click Set, then check the PLC variable in DB110 within 5 s. If the value changed, the write path is end-to-end functional.
10.4 Round-trip timing
A typical end-to-end write latency budget is:
| Stage | Typical Duration | |
|---|---|---|
| Notes | ||
| WinCC tag change to OPC write request | 20 to 50 ms | Includes WinCC tag update cycle |
| TCSB write staging | < 10 ms | TCSB writes to internal buffer immediately |
| TCSB polling cycle to CP | 100 ms to 10 s | Configurable per station; default 1 s |
| GPRS uplink | 300 ms to 2 s | Class 10 GPRS, dependent on RSSI and cell load |
| CP1242-7 receive and trigger TC_RECV | 20 to 80 ms | Includes backplane handshake to CPU |
| TC_RECV copy to DB110 | 10 to 30 ms | Direct memcpy on S7-1200 firmware |
| Total | ~500 ms to 12 s | Median around 1.5 s on a healthy Class 10 link |
11. Troubleshooting Matrix
| Symptom | Probable Cause | First Check | Remedy |
|---|---|---|---|
| WinCC reads OK but write returns HRESULT 0x80070005 | Receive area "Allow OPC write access" not ticked in TCSB | TCSB Config → Station → Data tab | Tick the checkbox, click Apply, Activate Configuration |
| Write returns S_OK but PLC value does not change | WinCC tag is read-only, or HMI object is in Display mode | Tag properties → Options → Write Permission; screen object Properties → Operating mode | Enable Write Permission; change screen object to Output or Switch |
| TC_RECV STATUS = 0x80C3 | RD_1 length > 480 bytes on CP1242-7 V1 | Watch table on STATUS | Split the receive area into two TC_RECV instances or upgrade to CP1242-7 V2 |
| TC_SEND STATUS = 0x80C1 | Send DB is optimized (S7-1200 symbolic-only) access | DB properties → Attributes → Optimized block access | Uncheck "Optimized block access", recompile, download |
| TCSB log shows WRITEREJECT with reason "OUT_OF_RANGE" | WinCC wrote to an offset outside the configured receive area | TCSB Config → Station → Data tab → Receive area geometry | Align the WinCC tag offset with the receive area, or extend the receive area |
| TCSB log shows WRITEREJECT with reason "QUOTA_EXCEEDED" | Operator script is writing faster than the per-station quota | TCSB Config → Station → Limits → Max writes per minute | Raise the quota or fix the runaway script; default is 60 writes/min |
| CP LED DIAG red, no TX/RX activity | GPRS attach failure, wrong APN, or PIN lock | CP1242-7 Web server (if enabled) or TIA Diagnostics Buffer | Confirm APN string, clear SIM PIN, verify SIM has GPRS service active |
| CP LED TX flashes, RX never flashes on a WinCC write | CGNAT or firewall blocking the inbound TCP from TCSB | External port scan on the public IP from a 3rd-party host | Order an M2M SIM with a public IP, or set up a VPN |
| WinCC reads OK, writes work once, then stop | Sequence number mismatch; CP rejected the second frame | TCSB log, search for SEQERR | Reset CP1242-7 power or trigger TC_CON REQ edge; persistent mismatch indicates a firmware bug — upgrade CP firmware to V1.1.12 or later |
| TC_RECV NDR fires but value in DB110 is constant | RD_1 overlaps SD_1, or DB110 is optimized | Cross-check the offset arithmetic in Section 8 | Disable Optimized block access; remap the offsets so the send and receive halves are disjoint |
FAQ
Why does the WinCC OPC browser show every TCSB item as read-only on a CP1242-7 V1?
TCSB v3 marks items in the send half of the mirror DB1 as read-only because they are populated by the S7-1200 via TC_SEND, and the server enforces the direction defined in the CP station's Data tab. The receive half is writable only if the station's Telecontrol Direction is set to Bidirectional and the Allow OPC write access box is ticked on the receive area. Configure the station accordingly and refresh the OPC browser.
What is the maximum payload per TC_SEND / TC_RECV call on a CP1242-7 V1?
The CP1242-7 V1 firmware supports a single send or receive area of up to 480 bytes per call. If your receive area is larger, declare two TC_RECV instances with disjoint RD_1 ranges (for example 0..479 and 480..959). The CP1242-7 V2 and the S7-1500 CP modules raise this limit to 8192 bytes per call.
Can I drop TCSB entirely if I upgrade the S7-1200 to firmware V4.4 with OPC UA?
For a wired network and a stable public IP, yes — TIA Portal V16 can configure the S7-1200 OPC UA server directly and WinCC Advanced V16 can connect to it as an OPC UA client. For GPRS, you still need either the CP1242-7 GPRS module (which terminates the mobile tunnel) or an external cellular router; the OPC UA server on the S7-1200 does not include a GPRS stack.
How can I tell a TCSB connection drop apart from a GPRS APN problem?
Open the CP1242-7 diagnostics buffer in TIA Portal. Event ID 0xE1 with reason code 0x0001 (TCP socket closed by partner) is a TCSB-side drop. Event ID 0xE1 with reason code 0x0003 (DNS resolution failed) or 0x0004 (no PDP context) is an APN or SIM problem. The TCSB trace log will show a CONNLOST in the first case and no WRITEFORWARD activity at all in the second case.
Why does TC_RECV STATUS show 0x80C3 even though the receive DB exists?
STATUS 0x80C3 indicates that RD_1 extends beyond the CP1242-7 V1's 480-byte fragmentation limit, not that the DB is missing. Reduce the LEN parameter to 480 or less, or split the receive area into multiple TC_RECV instances. STATUS 0x80C1 is the one that indicates a missing or optimized DB.
Do I need a static public IP on the TCSB host, or can I put TCSB behind a NAT?
The CP1242-7 initiates the TCP connection outbound to the TCSB and keeps it open, so a 1:1 NAT with port forwarding from a public IP to the TCSB host is sufficient. You cannot use dynamic DNS alone — the CP caches the resolved IP for up to 10 minutes and will not re-resolve during a transient outage, so plan a TTL of 60 s or less for the DNS A record if you use a hostname.