Configuring PROFINET Ring Topology with SCALANCE X-400

David Krause17 min read
Industrial NetworkingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Configuring a PROFINET Ring Topology with SCALANCE X-400 Switches and an S7-400H System

This reference describes how to engineer a redundant PROFINET ring built from three SCALANCE X408-2 switches, an S7-400H fault-tolerant controller, and an S7-300 station in SIMATIC Manager. The ring is closed through the third SCALANCE, redundancy is provided by Media Redundancy Protocol (MRP), and the two PROFINET interfaces of the S7-400H CPU are both attached to the same Ethernet/PROFINET subnet so that the H system can continue to communicate if one ring segment or one switch is lost.

All configuration steps use STEP 7 V5.5 + SPx with the SIMATIC NET configuration tools and the SCALANCE X-400 GSD package installed in HW Config. STEP 7 V13 / TIA Portal variants are not covered here; for those workflows use the SIMATIC PROFINET system description referenced below.

1. Topology Overview

The physical layout below shows a closed ring on port pairs 1 and 2 of every SCALANCE X408-2. The PROFINET interface of CPU 0 (rack 0) of the S7-400H is wired to SCALANCE 1, the PROFINET interface of CPU 1 (rack 1) of the S7-400H is wired to SCALANCE 2, and the S7-300 IM 151 / CP 343-1 is wired to SCALANCE 3. The fiber connections between switches are realized through two MM491-2 media modules per switch (one for the upstream, one for the downstream ring segment), so that the entire ring is multimode fiber 50/125 µm with SC connectors.

SCALANCE X408-2 #1 MRP Manager SCALANCE X408-2 #2 MRP Client SCALANCE X408-2 #3 MRP Client S7-400H CPU 0 (Rack 0) PN-IO #1 S7-400H CPU 1 (Rack 1) PN-IO #1 S7-300 (CP 343-1) PN-IO PROFINET MRP ring — closed through SCALANCE 3

The blue lines are the primary active path (data + ring closure), the orange dashed lines are the physical connections from the controllers and the S7-300 into the ring. In normal operation the MRP manager blocks one of its ring ports so the topology behaves as a logical line; on a fault the manager unblocks the port and the ring is re-established within the recovery time of the MRP manager.

2. Prerequisites and Component List

Item Article number / version Notes
SCALANCE X408-2 base module 6GK5 408-2GS00-2AM2 8 × RJ45 + 2 × media-module slots; Layer 2 managed
MM491-2 media module (fiber) 6GK5 491-2AB00-8AA2 2 × SC sockets, multimode 50/125 µm, 100 Mbps
S7-400H CPU CPU 414-4H (6ES7 414-4HM14-0AB0) or CPU 417-4H (6ES7 417-4HT14-0AB0) PROFINET interface onboard (X1 / X2)
S7-400H sync module / fiber 6ES7 960-1AA04-0XA0 + 6ES7 968-1AA00-0XA0 Required for the H system (not the ring)
S7-300 station CPU 31x PN/DP + CP 343-1 Lean / CP 343-1 Single PROFINET interface
STEP 7 V5.5 + SP4 + HF7 or later HW Config + NetPro
SIMATIC NET PC software included with STEP 7 Required for PROFINET IO diagnostics
GSD file SCALANCE X-400 Install via HW Config → Options → Install GSD File XML GSD for STEP 7 V5.5 SPx; GSDML-Vx.x-Siemens-SCALANCE_X408-xxxxxxxx.xml
SCALANCE X408-2 firmware V4.0 or later (V4.5 recommended) MRP manager capability is available from V3.0 onwards

Reference: SCALANCE X-400 Operating Instructions (Siemens Industry Online Support), SIMATIC PROFINET System Description.

Important: All three SCALANCE X408-2 units must be loaded with firmware that supports MRP manager and MRP client roles. The MM491-2 ports used for the ring must be configured as ring ports (port 1 of the module on one side, port 2 of the module on the other); the integrated RJ45 ports are not used for ring closure because the SC fiber transceivers are the field-proven choice for plant-floor fiber segments.

3. MRP Fundamentals and Ring Port Selection

MRP (IEC 62439-2) defines three roles that coexist in a single ring:

Role Function Quantity per ring
MRP Manager Actively monitors ring health via test frames; blocks one ring port in normal state; unblocks it within the configured recovery time when a topology change is detected. Exactly 1
MRP Client Forwards test frames and reacts to manager commands by blocking / forwarding its own ring ports. 0…n (rest of the ring)
MRP Auto-Manager Same as Manager, but elected automatically. Available since PROFINET specification V2.3. At most 1 in auto mode

For an S7-400H plant with an S7-300 attached, the recommended choice is:

  • SCALANCE #1 = MRP Manager (fixed role).
  • SCALANCE #2 and SCALANCE #3 = MRP Client.

For an 8-switch ring the standard IEC 62439-2 recovery time is 200 ms (default; the manager sets it via test frame); the SCALANCE X-400 default configuration is 200 ms and is suitable for most H systems. STEP 7 also offers a Prioritized startup option for the S7-400H where the H CPUs bring the ring up faster than other devices; this is configured in HW Config → Properties of the S7-400H PROFINET interface → Prioritized startup.

Reference: SIMATIC PROFINET System Description — Media Redundancy, SCALANCE X-400 Web Based Management (WBM) Manual.

4. Creating the S7-400H Station and a Shared PROFINET Network

The root cause of the most common configuration error in this topology is the duplication of the Ethernet subnet: STEP 7 will create a new Ethernet/PROFINET subnet for every CPU that has its PROFINET interface inserted, and if the H system is built by adding a second CPU afterwards, the second PROFINET interface is automatically attached to a brand-new subnet. The two H CPUs then end up on different subnets and the S7-300 cannot reach both, which is exactly the symptom reported in the field report ("both CPUs had the same network this time" — that is the success criterion).

  1. Open the SIMATIC Manager and create a new project.
  2. Insert a SIMATIC 400H Station from the right-mouse menu of the project. The HW Config of the H station opens.
  3. Insert the UR2-H or UR2 ALU rack (e.g. 6ES7 400-1TA01-0AA0) and place the PS 405 power supplies in slots 1 and 3 (Rack 0) and Rack 1 of the H system.
  4. Insert CPU 0 (e.g. 6ES7 414-4HM14-0AB0) into slot 3 of Rack 0. The CPU carries the PROFINET interface (X1 / X2). The slot for the CPU of Rack 1 is a slot that mirrors the same slot number (e.g. slot 3 of Rack 1) — STEP 7 will not place the second CPU in the same physical slot of the second rack; you must manually insert it.
  5. When the PROFINET interface of CPU 0 is inserted, STEP 7 displays the dialog Properties — Ethernet Interface. Click New… and create a PROFINET subnet. Configure:
    • Subnet name: PN-MRP-Ring (descriptive name)
    • IP address: e.g. 192.168.0.10
    • Subnet mask: 255.255.255.0
    • Router: leave empty unless routed networks are required
  6. Insert the CPU 1 (6ES7 414-4HM14-0AB0) into the matching slot of Rack 1. When its PROFINET interface is inserted, STEP 7 will again offer a subnet — do not create a new one; instead select the existing PN-MRP-Ring subnet. This is the critical step that binds both H CPUs to the same PROFINET subnet.
  7. Assign CPU 1 a unique IP address (e.g. 192.168.0.11). Both CPUs must be on the same subnet mask, otherwise the S7-300 cannot communicate with both.
Symptom & fix: If the second PROFINET interface is automatically placed on a different subnet, the cause is that the H system was built with the second CPU inserted after the PROFINET interface of the first CPU. Deleting both CPU PROFINET interface objects, re-inserting the first CPU's interface, then inserting the second CPU's interface on the same subnet, is the fastest fix. After the change, run Station → Save and Compile and re-check the Cross-reference tab in NetPro to confirm both PROFINET interfaces show the same S7 subnet identifier.

Reference: S7-400H System Manual — H Station configuration.

5. Adding the Three SCALANCE X-400 Switches to the PROFINET Subnet

From this point on, all work continues in HW Config of the S7-400H station, not in NetPro. NetPro is only used for cross-referencing networks; the PROFINET IO topology is owned by HW Config.

  1. In HW Config, open the PROFINET IO catalog (right side panel). Under PROFINET IO → Network Components → SCALANCE X-400 the installed GSD exposes the SCALANCE X408-2 module.
  2. Drag the SCALANCE X408-2 onto the PROFINET network line of the H station. STEP 7 prompts for an IP address; assign:
    • SCALANCE #1: 192.168.0.1
    • SCALANCE #2: 192.168.0.2
    • SCALANCE #3: 192.168.0.3
  3. Open the Properties dialog of each switch and confirm that the Device name is unique and matches the labelling in the cabinet (e.g. x400-1, x400-2, x400-3). The device name is the address used by PROFINET IO discovery; it must be lower case, no spaces, max. 240 characters, must start with a letter.
  4. Confirm that STEP 7 places every SCALANCE on the same PN-MRP-Ring subnet. The IO controller of this subnet is the S7-400H; the S7-300 is an IO device (or just a PN node, depending on what is wired to it).
Compile order: Compile after every change to the network (Station → Save and Compile → Check All). STEP 7 will display "no errors" only if all three SCALANCE devices are on the same S7 subnet. If a fourth PROFINET subnet appears in NetPro, it is a sign that one of the SCALANCE devices was accidentally inserted on a new subnet — delete the device from the network, drag it again, and confirm the subnet assignment.

6. Configuring MRP Roles and Ring Ports

The MRP configuration in STEP 7 is not done in the normal PROFINET interface properties; it is done in the PROFINET IO Domain Management dialog. This is a frequent point of confusion because the ring is invisible in the graphical network view.

  1. Right-click the PROFINET IO line in HW Config and select PROFINET IO Domain Management.
  2. The Domain Management dialog lists every PROFINET device in the project, its current MRP role, and the ring ports that will be used. Assign:
    Device MRP role Ring port 1 (P1) Ring port 2 (P2)
    SCALANCE #1 Manager MM491-2 — Port 1 (FX1) MM491-2 — Port 2 (FX2)
    SCALANCE #2 Client MM491-2 — Port 1 (FX1) MM491-2 — Port 2 (FX2)
    SCALANCE #3 Client MM491-2 — Port 1 (FX1) MM491-2 — Port 2 (FX2)
  3. Verify the MRP domain identifier is identical for all three devices; STEP 7 names it MRP-Domain_1 by default and it is the only domain an MRP manager can supervise.
  4. Select the Prioritized startup check-box for the S7-400H PROFINET interface if the S7-300 IO device should reach the H CPU faster after a ring break (typical when an S7-300 IO device must be served within 300 ms of a recovery).
  5. For the SCALANCE X408-2 you can also set the MRP role in the Web Based Management under Layer 2 → MRP, but the project is the source of truth — keep WBM consistent with the STEP 7 project.

Reference: SCALANCE X-400 WBM — MRP configuration.

7. Integrating the S7-300 Station on the Ring

The S7-300 can be attached to the ring in two ways. The recommended approach is a dedicated PROFINET IO device relationship with the S7-400H acting as IO controller.

  1. Insert a SIMATIC 300 Station into the project.
  2. Open HW Config of the S7-300, insert the rack, the PS 307, the CPU 31x PN/DP and a CP 343-1 Lean if the CPU is not a PN type.
  3. Select the PROFINET interface of the CPU (or CP) and choose the existing PN-MRP-Ring subnet — do not create a new subnet.
  4. Assign an IP address (e.g. 192.168.0.20) and a PROFINET device name (e.g. s7300-cp).
  5. In the S7-400H HW Config drag the S7-300 PROFINET interface into the PROFINET IO controller slot of the H CPU. STEP 7 will create the IO device relationship and assign a slot number for the S7-300 (slot 0 of the IO device is the head module / CPU interface).
  6. Run Save and Compile; the result must show the S7-400H as IO Controller and the S7-300 + 3 SCALANCE devices as IO Devices in the same domain.

Reference: SIMATIC PROFINET System Description — PROFINET IO, S7-400H — PROFINET IO with redundant interface.

8. PROFINET IO Domain Management and Compilation

After all three SCALANCE devices and the S7-300 are inserted, compile the S7-400H station. The compiler must report:

  • No errors and no warnings on the PROFINET subnet.
  • All IO devices show the same IO system number (e.g. PROFINET IO System (100)).
  • The S7-400H appears as IO Controller in two roles (one per CPU), and the IO system is the same on both PROFINET interfaces.

If a device shows the warning "Device is not part of any IO system", it is usually because the device was inserted by drag-and-drop from the catalog and the wrong IO controller was selected at insertion time. Delete the device, drag it from the catalog again, and drop it directly on the PROFINET line of the S7-400H.

9. Downloading the Configuration and Verification

  1. Connect the engineering PG to one of the SCALANCE X-400 ports (any RJ45).
  2. Set the PG/PC interface to TCP/IP → Intel Ethernet with a static IP in the same subnet (e.g. 192.168.0.100).
  3. Open PLC → Download to Target System → Selected CPU in HW Config of the S7-400H. The downloader will discover both H CPUs on the subnet; download the project to both.
  4. Download the S7-300 station (CPU 31x PN/DP) in the same way.
  5. Trigger a Topology Discovery via the WBM of SCALANCE #1 to confirm the ring is closed (Layer 2 → Topology → Accept). The expected result is a single MRP ring with three members.
  6. Open the Online & Diagnostics view of the S7-400H PROFINET interface. The IO Devices tab must show the three SCALANCE and the S7-300 as OK.
  7. Run a Ring test: pull one of the SCALANCE SFP/Glass fiber pairs. The MRP manager must re-establish the ring within 200 ms and no PROFINET IO device should go to Fail. The H system should not switch.

10. Troubleshooting Matrix

Symptom Likely cause Diagnostic Remediation
"To be able to position an IO device, either an IO controller with an IO system or an IO device has to be selected" Inserting the SCALANCE in NetPro (no IO controller context) Check window title bar: NetPro vs. HW Config Open HW Config of the S7-400H; drop the SCALANCE on the PROFINET line there
Each H CPU ends up on a separate PROFINET subnet Second CPU inserted after the first PROFINET interface NetPro → Ethernet shows two subnets Delete both PROFINET interface objects; re-insert; bind second CPU to the existing subnet
MRP manager / client role not visible in the graphical view Roles are configured in Domain Management, not in the network view Open PROFINET IO Domain Management Set role there; this dialog is the only one that drives the MRP state at runtime
Ring recovery time > 500 ms Wrong MRP domain or the manager is rebooting WBM of SCALANCE #1 → Information → MRP Confirm only one manager, increase manager priority, verify firmware
Single SCALANCE does not react to ring test Ring ports assigned to a non-MRP module (e.g. wrong MM491-2 slot) WBM → Information → Topology Reposition MM491-2 in the correct slot and re-download the project
S7-300 cannot be reached by either H CPU IP mismatch / wrong subnet ping from PG Re-verify IP / subnet mask; both H CPUs and the S7-300 must be in the same /24
H system does a switch-over on a single ring break PROFINET IO is configured as Single on the H CPU; the redundant PROFINET IO of the H system requires configuration of two PROFINET IO systems HW Config → Properties of the H-CPU PROFINET interface Switch to PROFINET IO redundant and configure the second PROFINET IO system on the second CPU's interface

Reference: SCALANCE X-400 Operating Instructions — Diagnostics, SCALANCE X-400 WBM Manual.

11. Performance, Timing, and Safety Considerations

  • MRP recovery time on a 3-switch ring is ≤ 200 ms; with up to 50 MRP nodes the IEC 62439-2 default is 200 ms. The H system tolerates a 200 ms ring break without switching.
  • PROFINET update time of the S7-300 IO device should be set to ≥ 1 ms. With three SCALANCE devices in the ring, the minimum is 250 µs; for IO devices that are not time-critical, 1 ms is the recommended starting point.
  • CPU 414-4H vs. CPU 417-4H: the 417-4H supports more PROFINET IO devices and a higher PROFINET update rate; the 414-4H is sufficient for a 3-switch ring with one S7-300 IO device.
  • Fiber segments with MM491-2: 50/125 µm multimode, 0–3000 m at 100 Mbps full duplex. Do not mix with single-mode MM491-1LD media modules on the same ring.
  • Redundancy vs. parallel operation: with PROFINET IO on the H system, both PROFINET interfaces of the H system are on the same subnet (this configuration). For the H system to keep IO communication after losing one CPU's PROFINET interface, configure PROFINET IO System 100 on the first CPU and PROFINET IO System 101 on the second CPU and assign the S7-300 to both IO systems; this is a more advanced setup outside the scope of the basic MRP ring.

Reference: S7-400H System Manual — H PROFINET IO redundancy, SIMATIC PROFINET System Description — Update time.

12. Operational Notes and Field-Proven Caveats

  1. When expanding the ring (adding a fourth or fifth SCALANCE), insert the new device on the same PN-MRP-Ring subnet. STEP 7 will then offer the existing PROFINET IO Domain Management; add the new device as Client and assign its ring ports. Re-compile and re-download to all CPUs.
  2. If the SCALANCE X408-2 is used with an S7-400H, the S7-400H should always be the IO controller of the subnet. The S7-300 is best configured as an IO device, not as a stand-alone PN node, so that the H system can supervise it.
  3. When commissioning, always check the MRP state via WBM before opening any PROFINET connection. The Information → MRP page shows the active manager, the recovery time and the ring port status.
  4. Always store the STEP 7 project on the engineering server and the as-built cabinet drawings should include the device name and the ring port label (e.g. x400-1 — ring ports: MM491-2/P1, MM491-2/P2).
  5. For an H system that has a SIMATIC PCS 7 operator station on the same ring, configure the ring with MRP and additionally enable the Passive listener role on the operator station switch (or use a dedicated PC switch, not part of the ring, to keep the ring pure).

FAQ

Why is the MRP ring not visible in the HW Config graphical view?

PROFINET IO rings are managed in the PROFINET IO Domain Management dialog, not in the network editor. Right-click the PROFINET line in HW Config of the S7-400H and open the Domain Management; that is where the MRP role (Manager / Client) and the ring ports of every SCALANCE X408-2 are assigned.

Can both H CPUs share the same PROFINET subnet for an MRP ring?

Yes. The S7-400H CPUs each have their own PROFINET interface, but both must be assigned to the same PROFINET subnet (e.g. PN-MRP-Ring) so that the SCALANCE switches see a single ring. Insert the second CPU's PROFINET interface and select the existing subnet — do not create a new one.

Which SCALANCE X408-2 should be the MRP manager?

Exactly one device per ring is the MRP manager. The convention is to place the manager at the head of the ring (SCALANCE #1 in this article) and the remaining devices as clients. The manager can also be any switch; STEP 7 only requires the Manager role to be assigned to exactly one device in the Domain Management.

What is the typical recovery time of a 3-switch MRP ring?

200 ms with the SCALANCE X408-2 default configuration (V4.0 and later). The H system tolerates this duration without switching. The recovery time is set by the MRP manager and is visible in WBM under Information → MRP.

Do the ring ports have to be the fiber ports of the MM491-2?

It is recommended. The MM491-2 fiber ports (FX1 / FX2) are the field-proven ring ports for SCALANCE X408-2 in plant-floor environments. The RJ45 ports can be used for the ring closure when a copper plant is preferred, but the configuration dialog is the same: select the appropriate ports as ring port 1 and ring port 2 in the PROFINET IO Domain Management.

Does the S7-300 count as an MRP participant?

No. The S7-300 is a PROFINET IO device attached to the ring but is not a ring participant; it does not carry ring ports and does not appear in the MRP list. The three SCALANCE X408-2 are the only MRP participants in this topology.

What firmware version is required on the SCALANCE X408-2?

MRP manager and client capability is available from firmware V3.0 onwards. V4.0 or later is recommended for current STEP 7 V5.5 SP4 projects; V4.5 includes the latest PROFINET conformance and security fixes. The firmware is loaded via the Web Based Management or via TIA Portal / SIMATIC Automation Tool.

Back to blog