Configuring MP277 HMI Connections to Two S7-300/400 CPUs
This engineering reference describes how to connect a single Siemens Multi Panel 277 (MP277) operator interface to two separate SIMATIC controllers — a CPU 414-3 DP (S7-400 family) and a CPU 315F-2PN/DP (S7-300 family, fail-safe) — so the panel can read process values from both CPUs and aggregate alarms into one common alarm log. The two CPUs are not redundant: they run independent user programs that control independent equipment. The HMI is the only shared visualization layer.
The configuration is based on the classic STEP 7 V5.5 engineering suite (with optional STEP 7 Professional add-ons) and WinCC Flexible 2008 SP5, both of which integrate into a single STEP 7 project so the HMI station, the S7-400 station, and the S7-300 station are configured and downloaded as one coordinated system.
1. Problem Definition and Architecture
The functional requirement is straightforward but has subtle consequences for the engineering design:
- CPU 414-3 DP (6ES7414-3EM05-0AB0 or 6ES7414-3EM06-0AB0) runs the main process program for plant area A.
- CPU 315F-2PN/DP (6ES7315-2FH13-0AB0 or 6ES7315-2EH13-0AB0) runs the fail-safe program for plant area B (e.g. a press or burner line).
- MP277 (typical 6AV6 643-0CD01-1AX1 10" Touch) provides common visualization, alarm logging, and operator control for both areas.
- The HMI is the only point where alarms from both CPUs are collected.
Three architectural questions must be answered up front:
- Physical medium — PROFIBUS DP (RS-485, purple cable) is the most common choice for MP277 and is supported on both CPUs' DP/MPI interfaces. PROFINET is supported by the CPU 315F-2PN/DP's PN port, but the CPU 414-3 DP variant does not have a PROFINET interface; only the 414-3 PN/DP variant does. The S7-400 must therefore reach the panel via PROFIBUS or via MPI.
- Connection type — Native S7 connections (configured in NetPro) are mandatory for full WinCC Flexible functionality including alarms, diagnostics, and direct tag access. Raw PROFIBUS DP slave I/O mapping is not a substitute.
- Redundancy expectation — Because the two CPUs are not redundant, a fault on one CPU does not cause the HMI to switch its data source; the surviving CPU simply remains visible, and the failed CPU's tags stop updating. The HMI itself is the lone point of failure unless an HMI redundancy scheme is implemented.
2. Prerequisites
| Item | Requirement | Notes |
|---|---|---|
| STEP 7 | V5.5 SP4 or later (V5.6 recommended) | Add-on "WinCC Flexible ES" is optional but simplifies integration |
| WinCC Flexible | 2008 SP5 (matches STEP 7 V5.5) | Required to configure the MP277; cannot be done in TIA Portal without migrating the S7-400 station |
| MP277 image | WinCC Flexible 2008 SP5 HSP or later HSP | Older panel images may be missing alarms/event log features |
| HMI license | WinCC Flexible Runtime license (e.g. 6AV6618-0BC01-3AB0 for 277) | Tag/license count must be sized for the total tag set of both CPUs |
| PROFIBUS cable | 6XV1830-0EH10 (FastConnect, purple, sold per metre) | Total length including spurs must respect 12 Mbit/s ≤ 100 m, 1.5 Mbit/s ≤ 200 m, 187.5 kbit/s ≤ 1000 m |
| PROFIBUS connectors | 6ES7972-0BA12-0XA0 (90°, with PG port) or 6ES7972-0BB12-0XA0 (35°) | Need one for each CPU, one for HMI; switchable terminating resistor on both ends |
| PG/PC adapter | USB MPI/DP adapter (6ES7972-0CB20-0XA0) or Ethernet CP | For commissioning and online diagnostics |
3. Hardware Topology and Bus Layout
The PROFIBUS DP network forms a single linear bus with three active nodes: CPU 414-3 DP, CPU 315F-2PN/DP, and MP277. Because the MP277 is a DP master class 2 in the WinCC Flexible sense (it initiates S7 connections), the network is logically a master/slave bus where both CPUs are DP slaves and the panel is the active connection initiator. For small installations the same physical DP cable is used; in larger plants, an OLM or repeater is inserted.
+-------------+ PROFIBUS DP (RS-485, purple) +-------------+
| CPU 414-3 |====(PROFIBUS addr 2)====(PROFIBUS addr 3)==| CPU 315F-2PN|
| DP (X1) | || || |DP (X2) |
+-------------+ || || +-------------+
|| ||
(PROFIBUS addr 4)=====================+
|
+-------------+
| MP277 (X2) |
| DP master |
+-------------+
|
(terminator ON at both bus ends only)
3.1 PROFIBUS addresses and baud rate
| Node | Default PROFIBUS address | Interface | Notes |
|---|---|---|---|
| CPU 414-3 DP | 2 | DP (X1) on the S7-400 backplane front connector | Configured via STEP 7 → Hardware → CPU properties → Interface → PROFIBUS |
| CPU 315F-2PN/DP | 3 | DP/MPI (X2) — second interface, the 315F has PN on X1 and DP/MPI on X2 | X1 (PN) is left unused for this HMI link; PN port is reserved for I/O or future PROFINET devices |
| MP277 | 4 | DP (X2 IF1B) on the back of the panel | Some MP277 variants have IF1A (MPI/DP) and IF1B (DP only); consult the panel nameplate |
Set the baud rate to 1.5 Mbit/s as a conservative default for mixed S7-300/S7-400 networks. The CPU 414-3 supports up to 12 Mbit/s on the DP interface; the MP277 supports up to 12 Mbit/s as well. 1.5 Mbit/s allows up to 200 m of bus segment, which fits the typical cabinet-to-panel distances of ≤ 50 m.
3.2 Cable and shielding
Use Siemens PROFIBUS FC Standard Cable (6XV1830-0EH10) with FC stripping tool (6GK1905-6AA00). Activate the terminating resistor on the connectors at the two physical ends of the bus only — typically on the connector at the first CPU and at the panel. Disable the resistor on all middle nodes. Failure to follow this rule is the single most common cause of intermittent PROFIBUS faults on commissioning day.
4. STEP 7 Project Setup
- Open the SIMATIC Manager and create a new project: File → New → Project. Name it e.g.
Plant_Area_AB_HMI. - Insert the S7-400 station: Insert → Station → SIMATIC 400 Station. Open HW Config and slot the rack (UR1/UR2), power supply (PS 405 10A or 20A), and the CPU 414-3 DP. The CPU slot is typically slot 3 on a UR2/UR1.
- Insert the S7-300 station: Insert → Station → SIMATIC 300 Station. Slot the rail, PS 307, and CPU 315F-2PN/DP. Remember that the PN port is X1 and the DP/MPI port is X2 — only X2 is used for the HMI link.
- Insert the HMI station: Insert → Station → SIMATIC HMI Station. From the catalog choose MP 277 10" Touch (or your exact variant).
- In each station's HW Config, configure the DP interface: Properties → PROFIBUS interface → Addresses. Disable DP master on both CPUs (they are slaves from the HMI's point of view). On the HMI, leave the DP interface set as a DP master if you intend to do direct I/O, or leave it as a passive participant if only S7 connections are used.
5. NetPro S7 Connection Configuration
NetPro is where the two S7 connections are defined. Each connection is a logical S7 channel that lets the HMI initiate read/write requests to one CPU.
- Open Options → NetPro in SIMATIC Manager. You should see the three stations on a single PROFIBUS subnet (PROFIBUS(1): DP master system).
- Right-click the MP277 station and select Insert New Connection.
- Choose the CPU 414-3 DP as the partner. Connection type: S7 connection. Confirm.
- Repeat: insert a second connection from MP277 to the CPU 315F-2PN/DP.
- Save and compile NetPro. The result is two S7 connections with local ID numbers (assigned automatically by NetPro) and the partner's PROFIBUS address filled in.
5.1 What NetPro generates
| Connection name | Local end (MP277) | Partner | Type | Use |
|---|---|---|---|---|
| Connection_1 | MP277 DP / addr 4 | CPU 414-3 DP / addr 2 | S7 connection | HMI tags for area A |
| Connection_2 | MP277 DP / addr 4 | CPU 315F-2PN/DP / addr 3 | S7 connection | HMI tags for area B |
Each connection carries an internal local ID (a 16-bit handle) that WinCC Flexible later references. The local IDs are visible in the NetPro connection table — write them down; they appear in the WinCC Flexible connection dialog as ID and must match exactly.
6. WinCC Flexible Connection Configuration
Open the MP277 in the project tree and double-click Connections. If WinCC Flexible was launched with the STEP 7 integration enabled, both S7 connections from NetPro are imported automatically. If not, they must be added manually.
6.1 Auto-import path (preferred)
- Select the MP277 station in the STEP 7 project tree.
- Right-click → Open with WinCC Flexible ES (or simply double-click if the file extension is bound).
- In the project view, open Connections. You should see two entries, one pointing to each CPU.
- Verify the ID field on each entry — these must equal the local IDs from NetPro. If the field is empty, the import failed; add the connections manually as in 6.2.
6.2 Manual configuration
If automatic import does not run, add connections as follows:
- In the WinCC Flexible Connections editor, double-click an empty row.
- Set Name to e.g.
CPU414_AreaAandCPU315F_AreaB. - Set Communication driver to
SIMATIC S7 300/400. - Set HMI device to
MP277and the appropriate interface (IF1B DP for example). - Set Station address (PROFIBUS partner address):
2for the 414 and3for the 315F. - Set Connection resource to the local ID reported by NetPro for that connection.
- Leave the rack/slot fields at the default
0 / 2for both CPUs (the S7-300/400 default slot 2 for the CPU). - Click OK. Repeat for the second CPU.
###### in runtime and alarms will silently fail to update.6.3 HMI tag structure
Tags are scoped per connection. Convention is to prefix the tag name with the connection/area identifier:
| Tag name | Connection | PLC address | Data type | Acquisition |
|---|---|---|---|---|
| AreaA_Motor1_Run | CPU414_AreaA | DB101.DBX0.0 | Bool | Cyclic 1 s |
| AreaA_TankLevel | CPU414_AreaA | DB101.DBD2 | Real | Cyclic 500 ms |
| AreaB_SafetyOK | CPU315F_AreaB | DB200.DBX10.0 | Bool | Cyclic 1 s |
| AreaB_EStopActive | CPU315F_AreaB | DB200.DBX10.1 | Bool | Cyclic 200 ms (alarms only) |
For alarm bits, set acquisition to On change or use the S7 alarm number (SFM/SF-discrete) approach so that the panel pulls a fresh status when the bit toggles. The MP277 supports up to 4 000 discrete alarms per project (verify in the panel's technical data).
7. Common Alarm Logging Configuration
This is the central reason for having a single HMI attached to two CPUs. The alarm log is configured at panel level, not at connection level; both connections feed the same log buffer.
- In WinCC Flexible, open Alarms → Settings on the MP277 project.
- Define alarm classes: Errors (red, must-acknowledge), Warnings (yellow, no ack), System (blue, info), Safety (orange, must-acknowledge, plays an audible pattern).
- For each alarm, select the Connection field — choose either
CPU414_AreaAorCPU315F_AreaBas appropriate. The same alarm class and trigger bit on the other connection must be a separate alarm entry; do not share alarm IDs across connections. - Define the Acknowledgement tag and the Status tag (optional) for S7-style alarms if you are using the S7 alarm number mechanism (SF-discrete). Otherwise use the bit-trigger method, which is simpler but offers no automatic fault time stamping from the CPU.
- Enable Alarm logging on the panel's Logs page. Choose a log size (e.g. 1 000 entries circular) and a path ("Storage Card") for persistent history.
- Add an Alarm View control to a screen and bind it to the alarm log.
ALARM_S / S7-Alarm-DB) require a "Message configuration" in STEP 7 and are more efficient, but they need an S7-300/S7-400 "Alarm-S" configuration in the CPU's HW Config. Bit-triggered alarms need no extra CPU work; the panel polls the configured bit. For mixed-vendor or legacy CPUs, bit alarms are usually simpler.8. Behaviour When a CPU Enters STOP or Fails
This is one of the most common operator questions. The expected behaviour depends on whether the panel is configured to detect the connection loss and how the tags are acquired.
| Scenario | Behaviour on MP277 | Recommended operator indication |
|---|---|---|
| CPU 414-3 goes to STOP | Tags under CPU414_AreaA keep their last value; new acquisitions return quality code bad. The connection status area pointer reports disconnected. |
Display a red "Connection lost" banner tied to the connection status area pointer of CPU414_AreaA. |
| CPU 315F goes to STOP (F-CPU) | Same as above; in addition, F-CPU STOP may raise a system-level diagnostic alarm on the panel's System events log if the F-driver is enabled in WinCC Flexible. | Use the F-status area pointer to colour a "Safety OK" indicator on the area overview screen. |
| PROFIBUS cable break | Both connections report disconnected. Tags hold last value with bad quality. | Distinct alarm class "Fieldbus fault" with the highest priority. |
| MP277 loses power | Both CPUs continue independently; the panel is invisible until it returns. The alarm log buffer is preserved on the storage card. | Add an HMI life-bit in each CPU that the operator can call up via the CPU's PG online view if the panel is dead. |
The panel does not automatically switch its data source to a surviving CPU. The two connections are independent; the HMI always tries to read both, and the operator simply sees "one side healthy, one side dead" until the faulty CPU returns.
8.1 Connection-status area pointer
Configure an area pointer in the connection settings:
- Pointer: Coordination (1 byte) — tells the panel whether the CPU is in run/stop and whether it is the master/follower in a redundancy group. Not used for diagnostic feedback on connection health.
- Pointer: Connection status (1 word per connection) — gives the panel a real-time picture of the S7 connection health for each configured connection. This is the one to use for the "Connection lost" banner.
- Pointer: Date/time (8 bytes) — synchronises the panel clock from the master CPU (pick one, typically the 414).
- Pointer: PLC ID (1 byte) — distinguishes which CPU sent the tag, useful for the alarm view.
The connection status pointer is configured in WinCC Flexible → Connections → [select connection] → Area Pointers. Tick Connection status and assign a DB / address in the partner CPU to hold the status word. The panel writes the current status to that address cyclically; the user program can use it to drive a faceplate.
9. Verification and Commissioning
Follow this sequence on commissioning day. Do not skip the bus diagnostics — most field faults are caught here.
- Power up the two CPUs and the MP277. Wait for the HMI to finish booting (about 30-45 s).
- Connect the PG to the first CPU via MPI. Open the online view; verify both CPUs are in RUN and that the user program is running.
- Open WinCC Flexible → Project → Transfer → Transfer. Compile the HMI project and transfer to the panel. Use Serial or Ethernet (preferred over MPI for the transfer).
- On the panel, open Start Center → Settings → System → Device → Network and Dial-up Connections. Verify the DP interface shows the correct PROFIBUS address (4) and that the bus is reporting OK.
- Open Start Center → Information → System Events and look for connection-related events. Two Connection established events should appear, one per CPU.
- Force a tag in CPU 414 (e.g. set DB101.DBX0.0 to TRUE from the PG) and watch the corresponding MP277 tag update on the faceplate.
- Repeat for CPU 315F.
- Trigger a discrete alarm on each CPU and verify the entry appears in the alarm view, with the correct connection source.
- Stop the CPU 414-3 (toggle the mode switch to STOP). Verify the panel's "Connection lost" banner appears for that connection only, and that CPU 315F tags continue updating.
- Use Start Center → Information → Connection Status to read the live state of both S7 connections.
10. Troubleshooting Matrix
| Symptom | Likely cause | Diagnostic step | Resolution |
|---|---|---|---|
| Tags show ###### in runtime | Wrong local ID, or the partner address does not match | WinCC Flexible → Connections → check ID and PROFIBUS address | Re-import the connection from NetPro, or correct the local ID manually |
| Panel says "Connection failed" for one CPU | Wrong rack/slot, or the CPU is in STOP, or PROFIBUS terminator missing | Open System Events log; check the CPU's operating mode and HW Config rack/slot | Set rack 0 / slot 2 in the WinCC Flexible connection; restart CPU; verify terminator at bus ends |
| Intermittent connection drops on the 315F | EMI on the DP cable near the VFD cabinet | Use a PROFIBUS diagnostic tool (e.g. Softing PROFINET/PROFIBUS Diagnostic Tester) to read bus quality | Re-route cable, add ferrite cores, increase shielding, lower baud rate to 500 kbit/s |
| Alarms do not appear | Alarm was created on the wrong connection, or alarm class is set to "no display" | Open Alarms editor; verify the connection name on the alarm's properties | Recreate the alarm pointing at the correct connection |
| One CPU blocks the other when in STOP | Misconfigured "Coordination" area pointer, or shared rack slot | Open Area Pointers; verify each connection has its own pointer set | Disable Coordination pointer if not needed; confirm rack 0 / slot 2 on both |
| PG can talk to both CPUs but panel cannot | Panel is not configured as DP master, or wrong interface (IF1A vs IF1B) is used | Check the panel's HMI device settings → Interfaces | Switch the connection from IF1A to IF1B (DP only) or set the IF1A mode to DP |
| Online view in STEP 7 shows the panel is connected but tags are stale | Acquisition cycle set to "On demand" instead of "Cyclic" | Open Tags editor; check the Acquisition column | Change to Cyclic 1 s (or shorter for safety-relevant tags) |
| Compile error "Connection resource already in use" | Two connections point to the same local ID | NetPro → Connection table → sort by ID and look for duplicates | Re-assign IDs; each connection must be unique |
11. Cross-Platform Notes and Edge Cases
11.1 Migration to TIA Portal
New installations are typically built in TIA Portal V17 / V18 with WinCC Comfort/Advanced. In that case the S7-400 CPU 414-3 DP (non-PN) cannot be migrated directly because TIA Portal does not support the S7-400 classic family as easily as it supports the S7-1500 family. The fallback options are:
- Stay on STEP 7 V5.x + WinCC Flexible for the HMI as described in this document.
- Replace the S7-400 with a S7-1500 and rebuild the project in TIA Portal (this is the direction Siemens recommends going forward).
- Replace the MP277 with a Comfort Panel (MTP / TP) and use TIA Portal from the start.
11.2 Mix of PROFIBUS and PROFINET
The CPU 315F-2PN/DP has both PROFINET and PROFIBUS. If the S7-400 is on PROFIBUS and the HMI is on PROFINET, a PROFINET/PROFIBUS gateway or an IE/PB Link (6GK1411-5BB00) is required. The IE/PB Link itself is a DP slave; the panel sees it as the partner. Most small plants avoid the gateway and keep all three nodes on a single PROFIBUS segment as shown in section 3.
11.3 Number of connections per panel
The MP277 family has a fixed budget. Refer to Siemens entry 15363798 for the exact numbers per variant:
- MP 277 8" keys: 4 S7 connections
- MP 277 10" touch: 6 S7 connections
- MP 277 10" keys: 6 S7 connections
- MP 277 12" touch: 8 S7 connections
Two connections are well within budget for any variant. The HMI becomes a problem only when many third-party PLCs are added.
11.4 HMI redundancy
If a true HMI-level redundancy is required (panel fails, backup panel takes over), a second MP277 with the same project and an HMI redundancy scheme in WinCC Flexible is needed. This is a separate engineering task and is outside the scope of the two-CPU single-panel configuration described here.
12. Field-Commissioning Checklist
Print and walk through this list on site:
- [ ] PROFIBUS cable continuous, shield bonded at both ends, terminating resistor ON at exactly two nodes.
- [ ] All three nodes have unique PROFIBUS addresses (2, 3, 4).
- [ ] STEP 7 project compiled and downloaded to both CPUs without errors.
- [ ] NetPro shows two S7 connections from MP277, with unique local IDs.
- [ ] WinCC Flexible connections match NetPro IDs.
- [ ] HMI project compiled and transferred to the panel.
- [ ] Panel boots, shows both connections established in System Events.
- [ ] Tag test passed for both CPUs (force/read).
- [ ] Alarm test passed for both CPUs (raise/acknowledge/clear).
- [ ] CPU STOP test: stopping one CPU does not affect the other's tags.
- [ ] Date/time area pointer configured on the master CPU.
- [ ] Connection-status area pointer wired to a faceplate indicator.
- [ ] Alarm log buffer size and path configured on the storage card.
- [ ] Project archive (STEP 7 + WinCC Flexible) saved to the project server.
With the points above verified, the MP277 will reliably read from both CPUs, display their tags side by side, aggregate their alarms into one common log, and survive a single CPU failure without crashing the visualization of the surviving one.
Can the MP277 show data from both CPUs at the same time?
Yes. The two S7 connections operate independently and the panel cycles through them. Tags from the CPU 414-3 DP and tags from the CPU 315F-2PN/DP are visible simultaneously on the same screens, with no need to switch connection context.
If one CPU goes to STOP, does the HMI switch to the other one?
No automatic switching occurs because the two CPUs are not redundant. The panel keeps trying to read the failed CPU; its tags hold their last value with a "bad connection" quality flag. The surviving CPU's tags continue to update normally. A user-configured "Connection lost" banner should be added via the connection-status area pointer.
How many connections does an MP277 support?
It depends on the variant. MP 277 8" keys supports 4 S7 connections; the 10" and 12" models support 6 to 8. The exact numbers are listed in Siemens support entry ID 15363798. Two connections (one to each CPU) is well within budget for any model.
What PROFIBUS baud rate should I use between the two CPUs and the MP277?
1.5 Mbit/s is a safe default that allows up to 200 m of cable per segment. Both CPU 414-3 DP and CPU 315F-2PN/DP support up to 12 Mbit/s, as does the MP277, but lower rates are more tolerant of cable quality and EMI. Avoid running PROFIBUS next to VFD power cables; keep at least 200 mm separation and cross at 90° if crossing is unavoidable.
Do I need STEP 7 Safety to read the CPU 315F from the MP277?
No. The F-signature and the F-program stay in the S7-300 station. The panel reads standard DBs and MBs as it would on any non-F CPU. STEP 7 Safety is only required if you want to edit the F-program online or passivate F-I/O from the panel, which is rarely useful and not recommended.
Why are my tags showing ###### on the panel?
The most common cause is a wrong local ID on the WinCC Flexible connection. Open the Connections editor, verify that the ID field matches the local ID in NetPro, and re-transfer the HMI project. Also confirm rack 0 / slot 2 on both CPUs — wrong slot values are the second most common cause.
Can I configure this in TIA Portal instead of STEP 7 V5.5?
Only if the S7-400 is a PROFINET variant (CPU 414-3 PN/DP). The DP-only CPU 414-3 is not natively supported in TIA Portal for new projects, so the classic STEP 7 V5.5 + WinCC Flexible 2008 path remains the practical choice. Long-term, plan a migration to a S7-1500 and TIA Portal.