Configuring MP277 HMI Connections to Two S7-300/400 CPUs

David Krause20 min read
HMI ProgrammingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Configuring MP277 HMI Connections to Two S7-300/400 CPUs

This engineering reference describes how to connect a single Siemens Multi Panel 277 (MP277) operator interface to two separate SIMATIC controllers — a CPU 414-3 DP (S7-400 family) and a CPU 315F-2PN/DP (S7-300 family, fail-safe) — so the panel can read process values from both CPUs and aggregate alarms into one common alarm log. The two CPUs are not redundant: they run independent user programs that control independent equipment. The HMI is the only shared visualization layer.

The configuration is based on the classic STEP 7 V5.5 engineering suite (with optional STEP 7 Professional add-ons) and WinCC Flexible 2008 SP5, both of which integrate into a single STEP 7 project so the HMI station, the S7-400 station, and the S7-300 station are configured and downloaded as one coordinated system.

Critical constraint: The number of simultaneously usable controller connections on a SIMATIC panel is a hardware- and firmware-limited parameter. Always confirm the connection budget of the specific MP277 variant (10"/12" touch, 8"/10" keys) before ordering hardware. See the official Siemens entry ID 15363798 for the per-panel connection matrix.

1. Problem Definition and Architecture

The functional requirement is straightforward but has subtle consequences for the engineering design:

  • CPU 414-3 DP (6ES7414-3EM05-0AB0 or 6ES7414-3EM06-0AB0) runs the main process program for plant area A.
  • CPU 315F-2PN/DP (6ES7315-2FH13-0AB0 or 6ES7315-2EH13-0AB0) runs the fail-safe program for plant area B (e.g. a press or burner line).
  • MP277 (typical 6AV6 643-0CD01-1AX1 10" Touch) provides common visualization, alarm logging, and operator control for both areas.
  • The HMI is the only point where alarms from both CPUs are collected.

Three architectural questions must be answered up front:

  1. Physical medium — PROFIBUS DP (RS-485, purple cable) is the most common choice for MP277 and is supported on both CPUs' DP/MPI interfaces. PROFINET is supported by the CPU 315F-2PN/DP's PN port, but the CPU 414-3 DP variant does not have a PROFINET interface; only the 414-3 PN/DP variant does. The S7-400 must therefore reach the panel via PROFIBUS or via MPI.
  2. Connection type — Native S7 connections (configured in NetPro) are mandatory for full WinCC Flexible functionality including alarms, diagnostics, and direct tag access. Raw PROFIBUS DP slave I/O mapping is not a substitute.
  3. Redundancy expectation — Because the two CPUs are not redundant, a fault on one CPU does not cause the HMI to switch its data source; the surviving CPU simply remains visible, and the failed CPU's tags stop updating. The HMI itself is the lone point of failure unless an HMI redundancy scheme is implemented.

2. Prerequisites

Item Requirement Notes
STEP 7 V5.5 SP4 or later (V5.6 recommended) Add-on "WinCC Flexible ES" is optional but simplifies integration
WinCC Flexible 2008 SP5 (matches STEP 7 V5.5) Required to configure the MP277; cannot be done in TIA Portal without migrating the S7-400 station
MP277 image WinCC Flexible 2008 SP5 HSP or later HSP Older panel images may be missing alarms/event log features
HMI license WinCC Flexible Runtime license (e.g. 6AV6618-0BC01-3AB0 for 277) Tag/license count must be sized for the total tag set of both CPUs
PROFIBUS cable 6XV1830-0EH10 (FastConnect, purple, sold per metre) Total length including spurs must respect 12 Mbit/s ≤ 100 m, 1.5 Mbit/s ≤ 200 m, 187.5 kbit/s ≤ 1000 m
PROFIBUS connectors 6ES7972-0BA12-0XA0 (90°, with PG port) or 6ES7972-0BB12-0XA0 (35°) Need one for each CPU, one for HMI; switchable terminating resistor on both ends
PG/PC adapter USB MPI/DP adapter (6ES7972-0CB20-0XA0) or Ethernet CP For commissioning and online diagnostics
STEP 7 / WinCC Flexible integration: Install WinCC Flexible after STEP 7 on the same engineering PC. The "WinCC Flexible ES" add-on enables the Start → SIMATIC → WinCC Flexible launch from inside STEP 7 and lets NetPro import HMI stations automatically.

3. Hardware Topology and Bus Layout

The PROFIBUS DP network forms a single linear bus with three active nodes: CPU 414-3 DP, CPU 315F-2PN/DP, and MP277. Because the MP277 is a DP master class 2 in the WinCC Flexible sense (it initiates S7 connections), the network is logically a master/slave bus where both CPUs are DP slaves and the panel is the active connection initiator. For small installations the same physical DP cable is used; in larger plants, an OLM or repeater is inserted.

   +-------------+        PROFIBUS DP (RS-485, purple)        +-------------+
   | CPU 414-3   |====(PROFIBUS addr 2)====(PROFIBUS addr 3)==| CPU 315F-2PN|
   | DP  (X1)    |   ||                                    ||  |DP  (X2)   |
   +-------------+   ||                                    ||  +-------------+
                      ||                                    ||
                      (PROFIBUS addr 4)=====================+
                            |
                       +-------------+
                       | MP277 (X2)  |
                       | DP master   |
                       +-------------+
                            |
                       (terminator ON at both bus ends only)

3.1 PROFIBUS addresses and baud rate

Node Default PROFIBUS address Interface Notes
CPU 414-3 DP 2 DP (X1) on the S7-400 backplane front connector Configured via STEP 7 → Hardware → CPU properties → Interface → PROFIBUS
CPU 315F-2PN/DP 3 DP/MPI (X2) — second interface, the 315F has PN on X1 and DP/MPI on X2 X1 (PN) is left unused for this HMI link; PN port is reserved for I/O or future PROFINET devices
MP277 4 DP (X2 IF1B) on the back of the panel Some MP277 variants have IF1A (MPI/DP) and IF1B (DP only); consult the panel nameplate

Set the baud rate to 1.5 Mbit/s as a conservative default for mixed S7-300/S7-400 networks. The CPU 414-3 supports up to 12 Mbit/s on the DP interface; the MP277 supports up to 12 Mbit/s as well. 1.5 Mbit/s allows up to 200 m of bus segment, which fits the typical cabinet-to-panel distances of ≤ 50 m.

3.2 Cable and shielding

Use Siemens PROFIBUS FC Standard Cable (6XV1830-0EH10) with FC stripping tool (6GK1905-6AA00). Activate the terminating resistor on the connectors at the two physical ends of the bus only — typically on the connector at the first CPU and at the panel. Disable the resistor on all middle nodes. Failure to follow this rule is the single most common cause of intermittent PROFIBUS faults on commissioning day.

4. STEP 7 Project Setup

  1. Open the SIMATIC Manager and create a new project: File → New → Project. Name it e.g. Plant_Area_AB_HMI.
  2. Insert the S7-400 station: Insert → Station → SIMATIC 400 Station. Open HW Config and slot the rack (UR1/UR2), power supply (PS 405 10A or 20A), and the CPU 414-3 DP. The CPU slot is typically slot 3 on a UR2/UR1.
  3. Insert the S7-300 station: Insert → Station → SIMATIC 300 Station. Slot the rail, PS 307, and CPU 315F-2PN/DP. Remember that the PN port is X1 and the DP/MPI port is X2 — only X2 is used for the HMI link.
  4. Insert the HMI station: Insert → Station → SIMATIC HMI Station. From the catalog choose MP 277 10" Touch (or your exact variant).
  5. In each station's HW Config, configure the DP interface: Properties → PROFIBUS interface → Addresses. Disable DP master on both CPUs (they are slaves from the HMI's point of view). On the HMI, leave the DP interface set as a DP master if you intend to do direct I/O, or leave it as a passive participant if only S7 connections are used.
CPU 315F safety considerations: Because the 315F is a fail-safe CPU, the F-signature is generated automatically by STEP 7 Safety. The F-program does not affect HMI access — the panel reads standard DBs/MBs as usual — but F-blocks cannot be edited online from a non-F-aware tool, including the HMI.

5. NetPro S7 Connection Configuration

NetPro is where the two S7 connections are defined. Each connection is a logical S7 channel that lets the HMI initiate read/write requests to one CPU.

  1. Open Options → NetPro in SIMATIC Manager. You should see the three stations on a single PROFIBUS subnet (PROFIBUS(1): DP master system).
  2. Right-click the MP277 station and select Insert New Connection.
  3. Choose the CPU 414-3 DP as the partner. Connection type: S7 connection. Confirm.
  4. Repeat: insert a second connection from MP277 to the CPU 315F-2PN/DP.
  5. Save and compile NetPro. The result is two S7 connections with local ID numbers (assigned automatically by NetPro) and the partner's PROFIBUS address filled in.

5.1 What NetPro generates

Connection name Local end (MP277) Partner Type Use
Connection_1 MP277 DP / addr 4 CPU 414-3 DP / addr 2 S7 connection HMI tags for area A
Connection_2 MP277 DP / addr 4 CPU 315F-2PN/DP / addr 3 S7 connection HMI tags for area B

Each connection carries an internal local ID (a 16-bit handle) that WinCC Flexible later references. The local IDs are visible in the NetPro connection table — write them down; they appear in the WinCC Flexible connection dialog as ID and must match exactly.

6. WinCC Flexible Connection Configuration

Open the MP277 in the project tree and double-click Connections. If WinCC Flexible was launched with the STEP 7 integration enabled, both S7 connections from NetPro are imported automatically. If not, they must be added manually.

6.1 Auto-import path (preferred)

  1. Select the MP277 station in the STEP 7 project tree.
  2. Right-click → Open with WinCC Flexible ES (or simply double-click if the file extension is bound).
  3. In the project view, open Connections. You should see two entries, one pointing to each CPU.
  4. Verify the ID field on each entry — these must equal the local IDs from NetPro. If the field is empty, the import failed; add the connections manually as in 6.2.

6.2 Manual configuration

If automatic import does not run, add connections as follows:

  1. In the WinCC Flexible Connections editor, double-click an empty row.
  2. Set Name to e.g. CPU414_AreaA and CPU315F_AreaB.
  3. Set Communication driver to SIMATIC S7 300/400.
  4. Set HMI device to MP277 and the appropriate interface (IF1B DP for example).
  5. Set Station address (PROFIBUS partner address): 2 for the 414 and 3 for the 315F.
  6. Set Connection resource to the local ID reported by NetPro for that connection.
  7. Leave the rack/slot fields at the default 0 / 2 for both CPUs (the S7-300/400 default slot 2 for the CPU).
  8. Click OK. Repeat for the second CPU.
Why the local ID matters: The local ID is the handle that all HMI tags, alarm logs, and area pointers use to route data through the connection. If the ID is wrong, tags will display ###### in runtime and alarms will silently fail to update.

6.3 HMI tag structure

Tags are scoped per connection. Convention is to prefix the tag name with the connection/area identifier:

Tag name Connection PLC address Data type Acquisition
AreaA_Motor1_Run CPU414_AreaA DB101.DBX0.0 Bool Cyclic 1 s
AreaA_TankLevel CPU414_AreaA DB101.DBD2 Real Cyclic 500 ms
AreaB_SafetyOK CPU315F_AreaB DB200.DBX10.0 Bool Cyclic 1 s
AreaB_EStopActive CPU315F_AreaB DB200.DBX10.1 Bool Cyclic 200 ms (alarms only)

For alarm bits, set acquisition to On change or use the S7 alarm number (SFM/SF-discrete) approach so that the panel pulls a fresh status when the bit toggles. The MP277 supports up to 4 000 discrete alarms per project (verify in the panel's technical data).

7. Common Alarm Logging Configuration

This is the central reason for having a single HMI attached to two CPUs. The alarm log is configured at panel level, not at connection level; both connections feed the same log buffer.

  1. In WinCC Flexible, open Alarms → Settings on the MP277 project.
  2. Define alarm classes: Errors (red, must-acknowledge), Warnings (yellow, no ack), System (blue, info), Safety (orange, must-acknowledge, plays an audible pattern).
  3. For each alarm, select the Connection field — choose either CPU414_AreaA or CPU315F_AreaB as appropriate. The same alarm class and trigger bit on the other connection must be a separate alarm entry; do not share alarm IDs across connections.
  4. Define the Acknowledgement tag and the Status tag (optional) for S7-style alarms if you are using the S7 alarm number mechanism (SF-discrete). Otherwise use the bit-trigger method, which is simpler but offers no automatic fault time stamping from the CPU.
  5. Enable Alarm logging on the panel's Logs page. Choose a log size (e.g. 1 000 entries circular) and a path ("Storage Card") for persistent history.
  6. Add an Alarm View control to a screen and bind it to the alarm log.
S7 alarms vs. bit alarms: S7-numbered alarms (ALARM_S / S7-Alarm-DB) require a "Message configuration" in STEP 7 and are more efficient, but they need an S7-300/S7-400 "Alarm-S" configuration in the CPU's HW Config. Bit-triggered alarms need no extra CPU work; the panel polls the configured bit. For mixed-vendor or legacy CPUs, bit alarms are usually simpler.

8. Behaviour When a CPU Enters STOP or Fails

This is one of the most common operator questions. The expected behaviour depends on whether the panel is configured to detect the connection loss and how the tags are acquired.

Scenario Behaviour on MP277 Recommended operator indication
CPU 414-3 goes to STOP Tags under CPU414_AreaA keep their last value; new acquisitions return quality code bad. The connection status area pointer reports disconnected. Display a red "Connection lost" banner tied to the connection status area pointer of CPU414_AreaA.
CPU 315F goes to STOP (F-CPU) Same as above; in addition, F-CPU STOP may raise a system-level diagnostic alarm on the panel's System events log if the F-driver is enabled in WinCC Flexible. Use the F-status area pointer to colour a "Safety OK" indicator on the area overview screen.
PROFIBUS cable break Both connections report disconnected. Tags hold last value with bad quality. Distinct alarm class "Fieldbus fault" with the highest priority.
MP277 loses power Both CPUs continue independently; the panel is invisible until it returns. The alarm log buffer is preserved on the storage card. Add an HMI life-bit in each CPU that the operator can call up via the CPU's PG online view if the panel is dead.

The panel does not automatically switch its data source to a surviving CPU. The two connections are independent; the HMI always tries to read both, and the operator simply sees "one side healthy, one side dead" until the faulty CPU returns.

8.1 Connection-status area pointer

Configure an area pointer in the connection settings:

  • Pointer: Coordination (1 byte) — tells the panel whether the CPU is in run/stop and whether it is the master/follower in a redundancy group. Not used for diagnostic feedback on connection health.
  • Pointer: Connection status (1 word per connection) — gives the panel a real-time picture of the S7 connection health for each configured connection. This is the one to use for the "Connection lost" banner.
  • Pointer: Date/time (8 bytes) — synchronises the panel clock from the master CPU (pick one, typically the 414).
  • Pointer: PLC ID (1 byte) — distinguishes which CPU sent the tag, useful for the alarm view.

The connection status pointer is configured in WinCC Flexible → Connections → [select connection] → Area Pointers. Tick Connection status and assign a DB / address in the partner CPU to hold the status word. The panel writes the current status to that address cyclically; the user program can use it to drive a faceplate.

9. Verification and Commissioning

Follow this sequence on commissioning day. Do not skip the bus diagnostics — most field faults are caught here.

  1. Power up the two CPUs and the MP277. Wait for the HMI to finish booting (about 30-45 s).
  2. Connect the PG to the first CPU via MPI. Open the online view; verify both CPUs are in RUN and that the user program is running.
  3. Open WinCC Flexible → Project → Transfer → Transfer. Compile the HMI project and transfer to the panel. Use Serial or Ethernet (preferred over MPI for the transfer).
  4. On the panel, open Start Center → Settings → System → Device → Network and Dial-up Connections. Verify the DP interface shows the correct PROFIBUS address (4) and that the bus is reporting OK.
  5. Open Start Center → Information → System Events and look for connection-related events. Two Connection established events should appear, one per CPU.
  6. Force a tag in CPU 414 (e.g. set DB101.DBX0.0 to TRUE from the PG) and watch the corresponding MP277 tag update on the faceplate.
  7. Repeat for CPU 315F.
  8. Trigger a discrete alarm on each CPU and verify the entry appears in the alarm view, with the correct connection source.
  9. Stop the CPU 414-3 (toggle the mode switch to STOP). Verify the panel's "Connection lost" banner appears for that connection only, and that CPU 315F tags continue updating.
  10. Use Start Center → Information → Connection Status to read the live state of both S7 connections.

10. Troubleshooting Matrix

Symptom Likely cause Diagnostic step Resolution
Tags show ###### in runtime Wrong local ID, or the partner address does not match WinCC Flexible → Connections → check ID and PROFIBUS address Re-import the connection from NetPro, or correct the local ID manually
Panel says "Connection failed" for one CPU Wrong rack/slot, or the CPU is in STOP, or PROFIBUS terminator missing Open System Events log; check the CPU's operating mode and HW Config rack/slot Set rack 0 / slot 2 in the WinCC Flexible connection; restart CPU; verify terminator at bus ends
Intermittent connection drops on the 315F EMI on the DP cable near the VFD cabinet Use a PROFIBUS diagnostic tool (e.g. Softing PROFINET/PROFIBUS Diagnostic Tester) to read bus quality Re-route cable, add ferrite cores, increase shielding, lower baud rate to 500 kbit/s
Alarms do not appear Alarm was created on the wrong connection, or alarm class is set to "no display" Open Alarms editor; verify the connection name on the alarm's properties Recreate the alarm pointing at the correct connection
One CPU blocks the other when in STOP Misconfigured "Coordination" area pointer, or shared rack slot Open Area Pointers; verify each connection has its own pointer set Disable Coordination pointer if not needed; confirm rack 0 / slot 2 on both
PG can talk to both CPUs but panel cannot Panel is not configured as DP master, or wrong interface (IF1A vs IF1B) is used Check the panel's HMI device settings → Interfaces Switch the connection from IF1A to IF1B (DP only) or set the IF1A mode to DP
Online view in STEP 7 shows the panel is connected but tags are stale Acquisition cycle set to "On demand" instead of "Cyclic" Open Tags editor; check the Acquisition column Change to Cyclic 1 s (or shorter for safety-relevant tags)
Compile error "Connection resource already in use" Two connections point to the same local ID NetPro → Connection table → sort by ID and look for duplicates Re-assign IDs; each connection must be unique

11. Cross-Platform Notes and Edge Cases

11.1 Migration to TIA Portal

New installations are typically built in TIA Portal V17 / V18 with WinCC Comfort/Advanced. In that case the S7-400 CPU 414-3 DP (non-PN) cannot be migrated directly because TIA Portal does not support the S7-400 classic family as easily as it supports the S7-1500 family. The fallback options are:

  • Stay on STEP 7 V5.x + WinCC Flexible for the HMI as described in this document.
  • Replace the S7-400 with a S7-1500 and rebuild the project in TIA Portal (this is the direction Siemens recommends going forward).
  • Replace the MP277 with a Comfort Panel (MTP / TP) and use TIA Portal from the start.

11.2 Mix of PROFIBUS and PROFINET

The CPU 315F-2PN/DP has both PROFINET and PROFIBUS. If the S7-400 is on PROFIBUS and the HMI is on PROFINET, a PROFINET/PROFIBUS gateway or an IE/PB Link (6GK1411-5BB00) is required. The IE/PB Link itself is a DP slave; the panel sees it as the partner. Most small plants avoid the gateway and keep all three nodes on a single PROFIBUS segment as shown in section 3.

11.3 Number of connections per panel

The MP277 family has a fixed budget. Refer to Siemens entry 15363798 for the exact numbers per variant:

  • MP 277 8" keys: 4 S7 connections
  • MP 277 10" touch: 6 S7 connections
  • MP 277 10" keys: 6 S7 connections
  • MP 277 12" touch: 8 S7 connections

Two connections are well within budget for any variant. The HMI becomes a problem only when many third-party PLCs are added.

11.4 HMI redundancy

If a true HMI-level redundancy is required (panel fails, backup panel takes over), a second MP277 with the same project and an HMI redundancy scheme in WinCC Flexible is needed. This is a separate engineering task and is outside the scope of the two-CPU single-panel configuration described here.

12. Field-Commissioning Checklist

Print and walk through this list on site:

  • [ ] PROFIBUS cable continuous, shield bonded at both ends, terminating resistor ON at exactly two nodes.
  • [ ] All three nodes have unique PROFIBUS addresses (2, 3, 4).
  • [ ] STEP 7 project compiled and downloaded to both CPUs without errors.
  • [ ] NetPro shows two S7 connections from MP277, with unique local IDs.
  • [ ] WinCC Flexible connections match NetPro IDs.
  • [ ] HMI project compiled and transferred to the panel.
  • [ ] Panel boots, shows both connections established in System Events.
  • [ ] Tag test passed for both CPUs (force/read).
  • [ ] Alarm test passed for both CPUs (raise/acknowledge/clear).
  • [ ] CPU STOP test: stopping one CPU does not affect the other's tags.
  • [ ] Date/time area pointer configured on the master CPU.
  • [ ] Connection-status area pointer wired to a faceplate indicator.
  • [ ] Alarm log buffer size and path configured on the storage card.
  • [ ] Project archive (STEP 7 + WinCC Flexible) saved to the project server.

With the points above verified, the MP277 will reliably read from both CPUs, display their tags side by side, aggregate their alarms into one common log, and survive a single CPU failure without crashing the visualization of the surviving one.

Can the MP277 show data from both CPUs at the same time?

Yes. The two S7 connections operate independently and the panel cycles through them. Tags from the CPU 414-3 DP and tags from the CPU 315F-2PN/DP are visible simultaneously on the same screens, with no need to switch connection context.

If one CPU goes to STOP, does the HMI switch to the other one?

No automatic switching occurs because the two CPUs are not redundant. The panel keeps trying to read the failed CPU; its tags hold their last value with a "bad connection" quality flag. The surviving CPU's tags continue to update normally. A user-configured "Connection lost" banner should be added via the connection-status area pointer.

How many connections does an MP277 support?

It depends on the variant. MP 277 8" keys supports 4 S7 connections; the 10" and 12" models support 6 to 8. The exact numbers are listed in Siemens support entry ID 15363798. Two connections (one to each CPU) is well within budget for any model.

What PROFIBUS baud rate should I use between the two CPUs and the MP277?

1.5 Mbit/s is a safe default that allows up to 200 m of cable per segment. Both CPU 414-3 DP and CPU 315F-2PN/DP support up to 12 Mbit/s, as does the MP277, but lower rates are more tolerant of cable quality and EMI. Avoid running PROFIBUS next to VFD power cables; keep at least 200 mm separation and cross at 90° if crossing is unavoidable.

Do I need STEP 7 Safety to read the CPU 315F from the MP277?

No. The F-signature and the F-program stay in the S7-300 station. The panel reads standard DBs and MBs as it would on any non-F CPU. STEP 7 Safety is only required if you want to edit the F-program online or passivate F-I/O from the panel, which is rarely useful and not recommended.

Why are my tags showing ###### on the panel?

The most common cause is a wrong local ID on the WinCC Flexible connection. Open the Connections editor, verify that the ID field matches the local ID in NetPro, and re-transfer the HMI project. Also confirm rack 0 / slot 2 on both CPUs — wrong slot values are the second most common cause.

Can I configure this in TIA Portal instead of STEP 7 V5.5?

Only if the S7-400 is a PROFINET variant (CPU 414-3 PN/DP). The DP-only CPU 414-3 is not natively supported in TIA Portal for new projects, so the classic STEP 7 V5.5 + WinCC Flexible 2008 path remains the practical choice. Long-term, plan a migration to a S7-1500 and TIA Portal.

Back to blog