Configuring S7-1200 to S7-400H TCP and ISO-on-TCP in TIA Portal

David Krause18 min read
S7-1200SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Configuring S7-1200 CPU 1214C to S7-400H CPU 412-5H Open IE Communication

The SIMATIC S7-400H (S7-400H) redundancy PLC family was never integrated into the TIA Portal hardware catalog. As of TIA Portal V12 (and the later V13, V14, V15, V15.1, V16, V17, V18, and V19 releases), the CPU 412-5H PN/DP and CPU 414-5H PN/DP and CPU 417-5H PN/DP continue to be programmed exclusively with STEP 7 V5.5 / V5.6 and the optional S7-H Add-on package. When an S7-1200 (for example, CPU 1214C DC/DC/DC order number 6ES7214-1AG40-0XB0) must exchange process data with a CPU 412-5H, the standard S7 connection (PUT/GET via NetPro/connection configuration) cannot be built in a single engineering tool, and the DP/DP coupler + Y-Link path is unattractive when the two stations already share an Industrial Ethernet / PROFINET backbone.

The supported alternative is Open IE communication using the standard TCON / TSEND / TRCV / TDISCON instruction set on the S7-400H side (STEP 7 V5.5) and the TSEND_C / TRCV_C / TCON / TDISCON family on the S7-1200 side (TIA Portal V12). Both transports are configured independently on each controller — no NetPro cross-project, no PUT/GET access rights, no S7 connection partner definition. This article documents a field-proven configuration for a CPU 1214C ↔ CPU 412-5H link that is bridged by two SCALANCE W786-1PRO access points operating as a wireless bridge into a SCALANCE X108 managed switch on the stacker.

1. Scope and Applicability

Item Value
S7-1200 CPU CPU 1214C DC/DC/DC (6ES7214-1AG40-0XB0), firmware V4.2 or higher
S7-400H CPU CPU 412-5H PN/DP (6ES7412-5HK06-0AB0) with at least one PN interface
S7-400H firmware V6.0.x (for 5H; PN/DP variants 5HK06 and 5HM06)
Engineering S7-1200 SIMATIC STEP 7 Basic / Professional V12.0 + SP1 or later in the V12 line (V12 SP1, V12 SP2, V12 SP3)
Engineering S7-400H STEP 7 V5.5 + SP4 (or V5.5 + HF11 / later HFs) plus S7-H Add-on package
Wireless link SCALANCE W786-1PRO (6GK5786-1PRO-2AA1 or -3AA1) in client/bridge mode, both sides
Wired segment on stacker SCALANCE XC108 or X108 unmanaged/managed switch (8 × RJ45)
Transport protocols ISO-on-TCP (RFC 1006, connection type 12 = 0x0C) and/or TCP (connection type 11 = 0x0B)
Library on S7-1200 "Communication processors / Open User Communication" blocks shipped with TIA Portal V12
Library on S7-400H Standard library → Communication Blocks → Blocks for Open IE Communication (FB63–FB68, UDT65/UDT66)
Why TIA Portal V12 cannot see the CPU 412-5H: The S7-400H is a fault-tolerant system whose redundancy firmware, synchronization link, and rack configuration are described by GSD/SSD objects that the TIA Portal hardware catalog does not import. Siemens' position is to keep H-station engineering in STEP 7 V5.5. You can still place a "non-H" S7-400 CPU in the TIA Portal V12 catalog (for example, CPU 412-1 or CPU 414-3 PN/DP) just to expose the Open IE block set, but the block code is portable to the H station as long as the firmware supports the FB family (FB63 TCON, FB64 TSEND, FB65 TRCV, FB66 TDISCON, FB67 TUSEND, FB68 TURCV).

2. Network Architecture

The physical layer is two SCALANCE W786-1PRO devices configured as a point-to-point wireless bridge. The central control room end terminates on a SCALANCE X108 / XC108 switch together with the CPU 1214C; the movable stacker end terminates on a second SCALANCE X108 inside the stacker E-house, where the CPU 412-5H PN/DP's PROFINET port is wired. Both APs use the same SSID, channel, and WPA2/AES key in bridge mode (or iPCF mode if line-of-sight is intermittent).

Central Control Room CPU 1214C 192.168.0.10 PG / TIA V12 Switch X108 SCALANCE W786-1PRO 192.168.0.20 SCALANCE W786-1PRO 192.168.0.21 Stacker E-House CPU 412-5H PN/DP 192.168.0.30 (H-system) STEP 7 V5.5 + S7-H Switch X108 Cat6 / 100 m max 5 GHz WLAN bridge Cat6 / 100 m max

IP planning is critical because both S7-1200 and S7-400H are on the same Layer-2 broadcast domain. Use a private /24 such as 192.168.0.0/24 and reserve static addresses; SCALANCE W786-1PRO supports the “Bridge mode” (point-to-point) where both APs share a single IP subnet.

3. Protocol Selection: TCP vs ISO-on-TCP

Property ISO-on-TCP (RFC 1006) TCP (RFC 793)
T-block ID (UDT65) 12 (0x0C) — B#16#0C 11 (0x0B) — B#16#0B
Local / remote TSAP Required, max 16 bytes, ASCII or hex Not used, set to 0
Port number (S7-400H) Implicit, derived from TSAP Configurable (default 2000, 2500, 3000…)
Header overhead 4-byte TPDU header + RFC 1006 20-byte TCP + 20-byte IP
Data integrity Length field is explicit per send Length must be carried inside the payload
Suitability for 5H wireless Recommended — TSAP simplifies partner address Acceptable — slightly more bytes on the air
Number of S7-1200 connection resources (firmware V4.x) Up to 8 open IE connections for CPU 1214C Same as left

For a stacker with intermittent RF contact, ISO-on-TCP is the more deterministic choice: the TSAP (Transport Service Access Point) lets the S7-400H identify the partner without inspecting payload, and the S7-400H redundancy firmware treats the connection as a normal Open IE link that can be opened/closed by FB63/FB66. TCP is the only option if the partner is a non-Siemens device or a third-party SCADA node.

4. S7-400H Side Configuration (STEP 7 V5.5)

The S7-400H project must be created in STEP 7 V5.5 with the S7-H Add-on. Configure the CPU 412-5H PN/DP PROFINET interface with IP 192.168.0.30, subnet mask 255.255.255.0, no router. Open IE communication does not require a configured connection in NetPro — only an instance DB for the FBs.

4.1 Connection description UDT 65 (ISO-on-TCP)

Declare the connection description as a multi-instance or a stand-alone DB. UDT 65 is the standard structure used by FB63 TCON. The minimum fields for ISO-on-TCP are:

Offset Symbol Type Value (example) Comment
0.0 block_length WORD W#16#0040 (64 dec) Length of UDT 65 data area
2.0 id WORD W#16#0001 Connection ID, must match the ID at both ends
4.0 connection_type BYTE B#16#0C 12 = ISO-on-TCP
5.0 active_est BOOL TRUE TRUE = active (S7-400H opens), FALSE = passive
6.0 local_device_id BYTE B#16#00 0 = PN-IO interface of CPU 412-5H
7.0 local_tsap_id_len BYTE B#16#02 2 bytes TSAP for ASCII
8.0 local_tsap_id ARRAY[1..16] OF BYTE 'S' '4' = 0x53 0x34 Local TSAP, ASCII or hex
24.0 rem_subnet_id_len BYTE B#16#00 0 = no router
25.0 rem_staddr_len BYTE B#16#04 4 bytes IP
26.0 rem_staddr ARRAY[1..6] OF BYTE 192 168 0 10 0 0 Partner IP, 4 bytes used
32.0 rem_tsap_id_len BYTE B#16#02 2 bytes
33.0 rem_tsap_id ARRAY[1..16] OF BYTE 'S' '1' = 0x53 0x31 Remote TSAP (S7-1200 side)
Connection ID 1 is recommended for the first Open IE link on an S7-400H. The H-system itself reserves IDs 1, 2, 3 for redundancy synchronization (depending on S7-H Add-on version) and for the HMI/PG connection. Use ID 10, 11, 12… for Open IE so you can monitor the diagnostic buffers without conflict.

4.2 STL call sequence (S7-400H OB1)

//  FB63 TCON  - establish ISO-on-TCP connection
CALL  FB63,  DB100
       REQ   := M10.0                  // 1 = establish
       ID    := W#16#000A              // Connection ID 10
       DONE  := M10.1
       BUSY  := M10.2
       ERROR := M10.3
       STATUS:= MW12
       CONNECT := P#DB100.DBX0.0 BYTE 64   // UDT 65 in DB100
//  FB64 TSEND - send 100 bytes from DB200.DBX0.0
CALL  FB64,  DB101
       REQ   := M11.0                  // rising edge triggers send
       ID    := W#16#000A
       LEN   := 100                    // explicit length on ISO-on-TCP
       DONE  := M11.1
       BUSY  := M11.2
       ERROR := M11.3
       STATUS:= MW14
       DATA  := P#DB200.DBX0.0 BYTE 100
//  FB65 TRCV - receive into DB201 (must be 100+2 bytes for ISO-on-TCP header)
CALL  FB65,  DB102
       EN_R  := M12.0                  // 1 = enabled
       ID    := W#16#000A
       LEN   := 100                    // 0 = any length, or fixed
       NDR   := M12.1
       BUSY  := M12.2
       ERROR := M12.3
       STATUS:= MW16
       RCVD_LEN:= MW18
       DATA  := P#DB201.DBX0.0 BYTE 100
//  FB66 TDISCON - orderly close
CALL  FB66,  DB103
       REQ   := M13.0
       ID    := W#16#000A
       DONE  := M13.1
       BUSY  := M13.2
       ERROR := M13.3
       STATUS:= MW20

5. S7-1200 Side Configuration (TIA Portal V12)

The S7-1200 program is built in TIA Portal V12 against a CPU 1214C with firmware V4.2. Use the system library "Communication -> Open User Communication" which contains TSEND_C, TRCV_C, TCON, TDISCON, T_RESET, and T_DIAG FBs.

5.1 Configure the PROFINET interface

  1. Open the device view, select the CPU 1214C, switch to Properties > Ethernet addresses.
  2. Set IP address 192.168.0.10, subnet mask 255.255.255.0. Do not check "Use router" unless the SCALANCE W786-1PRO is in routed mode.
  3. If you need to enable secure PG/PC and HMI communication later, follow the steps for certificate handling in the S7-1200 manual collection: S7-1200 Communications CPU 1214C.
  4. Under "Connection mechanisms", enable "Permit access with PUT/GET from remote partner" only if you also need the legacy PUT/GET path; it is not required for Open IE communication.

5.2 Build a global DB of type "TCON_Param"

UDT "TCON_Param" is shipped with TIA Portal V12 in the system data types. Create a DB named iDB_H_Link of type TCON_Param for each connection. The fields required for an active ISO-on-TCP client targeting the S7-400H are:

Field Type Value Notes
InterfaceId HW_IO 64 (PN interface of CPU 1214C) 64 = onboard PROFINET
ID WORD W#16#000A Connection ID 10, must match S7-400H
ConnectionType BYTE B#16#0C 12 = ISO-on-TCP
ActiveEstablished BOOL TRUE S7-1200 is active
RemoteAddress ARRAY[1..4] OF BYTE 192, 168, 0, 30 CPU 412-5H IP
RemotePort UINT 0 Not used for ISO-on-TCP
LocalPort UINT 0 Auto-assign
LocalTSAP ARRAY[1..16] OF USINT 0,0,'S','1' (TSAP=2 bytes ASCII "S1") Two leading 0x00 bytes + ASCII
RemoteTSAP ARRAY[1..16] OF USINT 0,0,'S','4' (TSAP=2 bytes ASCII "S4") Matches S7-400H local TSAP
TSAP length encoding on S7-1200: The S7-1200 stores the TSAP length implicitly: the array is 16 bytes but only LengthOfTSAP bytes (derived from the first non-zero entry) are used. For 2-byte ASCII TSAPs such as S1, fill the array with [0,0,'S','1', 0,0,...]. For hex TSAPs use 0x53 0x31 directly.

5.3 SCL call sequence (S7-1200 OB1)

// TSEND_C: combined establish + send on rising edge of REQ
IF "M_Request_Send" THEN
   "iTSend_C_DB"(REQ   := "M_Request_Send",
                 ID    := 10,
                 CONT  := TRUE,                    // keep connection open
                 LEN   := 100,
                 DATA  := P#"DB_Send".DBX0.0 BYTE 100,
                 DONE  => "M_Send_Done",
                 BUSY  => "M_Send_Busy",
                 ERROR => "M_Send_Err",
                 STATUS=> "MW_Send_Status");
END_IF;

// TRCV_C: always enable after connection is up
"iTRcv_C_DB"(EN_R  := "M_Recv_Enable",
             ID    := 10,
             CONT  := TRUE,
             LEN   := 100,
             DATA  := P#"DB_Recv".DBX0.0 BYTE 100,
             NDR   => "M_Recv_NDR",
             BUSY  => "M_Recv_Busy",
             ERROR => "M_Recv_Err",
             STATUS=> "MW_Recv_Status",
             RCVD_LEN=> "MW_Recv_Len");

// Optional: T_DIAG for connection-state snapshot
"iTDiag_DB"(ID       := 10,
            MODE     := 0,                          // 0 = status only
            STATUS   := "DB_TDiag_Status",
            DIAG_OUT := "DB_TDiag_Result");

6. Connection Parameter Mapping Summary

Parameter S7-1200 (CPU 1214C, V4.2) S7-400H (CPU 412-5H, V6.0)
IP address 192.168.0.10 192.168.0.30
Subnet mask 255.255.255.0 255.255.255.0
Connection type 12 (ISO-on-TCP) 12 (ISO-on-TCP)
Active / Passive Active (TCON starts) Passive (waits for partner)
Local TSAP ASCII "S1" (0x00,0x00,'S','1') ASCII "S4" (0x53,0x34)
Remote TSAP ASCII "S4" (0x00,0x00,'S','4') ASCII "S1" (0x53,0x31)
Connection ID 10 (0x0A) 10 (0x0A)
Interface PN interface, slot 1 of CPU 1214C PN-IO X5 of CPU 412-5H, ID 0
Max payload per send 8192 bytes (S7-1200 limit) 8192 bytes (S7-400H limit, firmware ≥ V5.1)
Total Open IE connections on controller 8 (CPU 1214C, FW 4.x) Up to 64 depending on CPU type and work memory

7. SCALANCE W786-1PRO Wireless Bridge Settings

  1. Open the Web-Based Management of both W786-1PRO devices.
  2. Set Operating mode = Bridge mode (point-to-point). This is the default mode for the -PRO variant; do not select "Client" mode because the S7 stations need a transparent Layer-2 bridge.
  3. Configure both radios with the same SSID, channel (e.g., 5 GHz DFS channel 100), and WPA2/AES passphrase.
  4. Set the bridge partner MAC explicitly on both devices to avoid the 30-40 s scan delay during roam.
  5. Disable Spanning Tree on the W786 radios but leave it enabled on the SCALANCE X108 — the X108 will keep the loop-free path when the wireless side is recovering.
  6. Verify the link with the W786 "Diagnostics > WLAN > Signal" page; RSSI should be above -65 dBm for a 5H Open IE link to remain stable at 100 ms send cycle.
  7. Set the IP of the W786 for management only (192.168.0.20 / 192.168.0.21) — they are not part of the Open IE connection.
iPCF vs standard WLAN: On a moving stacker with a single access point at the control room, set the W786 to iPCF (Industrial Point Coordination Function) for deterministic handoff. iPCF requires the same firmware on both ends; mix-and-match with non-iPCF SCALANCE W devices is not supported. If the stacker only moves within a small radius (e.g., yard crane), standard bridge mode is sufficient.

8. Verification Procedure

  1. Download the S7-400H project to the H-station; check that both CPUs go to RUN with no diagnostic interrupt. The H-system status must show "System status: Redundant".
  2. Download the S7-1200 project to the CPU 1214C. Open the Online > Diagnostics > Connection diagnostics view; the connection with ID 10 should appear with state ESTABLISHED.
  3. On the S7-400H, force REQ = TRUE on FB64 TSEND. Verify in the partner DB that the data is non-zero and the S7-1200's RCVD_LEN reports 100.
  4. Reverse the test: trigger TSEND_C on the S7-1200 and read RCVD_LEN at the H-station. Both DONE flags must pulse once per REQ.
  5. Watch the W786 signal page for 60 s; packet loss must be 0 % for the 100 ms cycle.
  6. Issue a STOP/RUN on the standby CPU of the H-system to confirm that the Open IE connection survives a redundancy switchover. Status must remain ESTABLISHED within 2 s (typical 200-500 ms).
  7. Pull power on the wireless bridge for 5 s; verify that STATUS on the S7-1200 reads W#16#80C8 (connection terminated) and is followed by automatic re-establishment when the bridge comes back.

9. Diagnostics and Status Codes

Open IE communication on the S7-400H and S7-1200 use the same STATUS word layout (16-bit, 8-bit event class + 8-bit event number). Common codes that show up in the field:

STATUS Class / Number Meaning Field Action
W#16#0000 0/0 No error —
W#16#7000 7/0 FB not active (no REQ edge yet) Normal at start-up
W#16#7001 7/1 Job in progress (BUSY) Wait for DONE/NDR
W#16#7002 7/2 Internal job completed, awaiting next call Continue cyclic call
W#16#8085 8/5 LEN parameter = 0 and no data yet, or LEN too large for the DB Re-check LEN and DB size
W#16#80A1 8/161 Connection or port already occupied Lower ID, free a connection resource
W#16#80AB 8/171 TSAP already in use Use a different TSAP
W#16#80C3 8/195 All connection resources in use on this CPU Reduce number of Open IE links
W#16#80C4 8/196 Temporary communication error (TCP RST received) Auto-recovery within seconds
W#16#80C8 8/200 Partner actively closed the connection Auto-reconnect if REQ pulse is re-applied
W#16#8380 8/128 (S7-1200 only) Connection ID 0 not allowed Set ID ≥ 1
W#16#80B5 8/181 Local/remote IP identical Re-assign a unique IP

10. Security Considerations

Open IE communication is unencrypted by default. On a wireless link such as SCALANCE W, this is a known attack surface. The hardening sequence recommended for production:

  1. Enable WPA2/AES on the SCALANCE W786-1PRO radios (already documented in section 7) and use a 20+ character passphrase rotated quarterly.
  2. Restrict the S7-1200 firmware ≥ V4.2: enable "Access protection" with a password of at least 8 characters including a digit and a special character.
  3. For CPU 1214C firmware V4.4 and higher, switch the Open IE link to TLS using the TCON block with ConnectionType = 0x11 (17) and a CPU-side X.509 certificate. The S7-400H V6.0 firmware supports TLS for Open IE only with CP443-1 EX30 / GX30 modules, not on the CPU's onboard PN interface — keep Open IE unencrypted on the H-station CPU and rely on a CP for TLS.
  4. Apply all CISA-published Siemens advisories for the S7-1200 platform — see the CISA ICS advisory ICSA-25-044-01 for the most recent updates (note that CISA stopped updating this advisory line on 10 January 2023, but historical advisories still apply).
  5. Disable the Web server on the S7-1200 unless required; if it must remain on, restrict it to HTTPS with a CPU-side certificate.
  6. Apply the "Permit access with PUT/GET from remote partner" option in TIA Portal V12 only if legacy S7 partners exist; this option opens the CPU to known S7 read/write attacks and is the root cause of multiple S7-1200 advisories (e.g., CVE-2019-13945, CVE-2020-15782).

11. Troubleshooting Matrix

Symptom Most Likely Cause Diagnostic Step Resolution
FB63 TCON stays BUSY, no DONE Partner not reachable on IP Ping 192.168.0.30 from S7-400H PG; check SCALANCE W link state Fix IP / mask / bridge; re-trigger REQ
STATUS = W#16#80AB TSAP collision with another link List all UDT65 blocks in the S7-400H; check IDs and TSAPs Use a different TSAP string per link
S7-1200 reports W#16#80A1 ID already used by another TCON Cross-check DBs for duplicate ID values Re-assign ID; rebuild project
Connection goes up then drops after 30 s Keep-alive timeout; partner closes because no traffic Reduce cyclic send period to ≤ 5 s Send a 1-byte "heartbeat" with TSEND_C every 5 s
H-station redundancy switchover breaks the link Open IE uses the H-CPU's active interface; after switchover the binding is on the standby IP for a few cycles Use the H-system's redundant IP (192.168.0.30 is shared by both H-CPUs) Re-trigger TCON with rising edge; or use FB54 "DSND_INIT" pattern from the S7-H Add-on for IP re-bind
Data is shifted by 2 bytes ISO-on-TCP sender specified LEN=100 but receiver expects the 2-byte length prefix Check LEN at the sender and at the receiver Match the lengths; ISO-on-TCP does not include the length in the data on S7-1200 firmware ≥ V4.0 — it is a "data-only" transport
CPU 1214C online diagnostics shows the link but no data TSAP length encoding wrong (leading zeros in ASCII) Monitor TDiag output; STATUS = W#16#80A7 means TSAP format error For 2-byte ASCII TSAP, send [0,0,'S','1']; for 2-byte hex TSAP send [0x53, 0x31, 0,0,...]
After STOP/RUN of the S7-400H the S7-1200 sees W#16#80C8 S7-400H issued an active close; S7-1200 has not been told to reconnect Hold REQ on TSEND_C TRUE; the S7-1200 reconnects automatically when CONT=TRUE Ensure CONT is TRUE on TSEND_C / TRCV_C; never toggle REQ at every cycle

12. Why the DP/DP-Coupler + Y-Link Path Was Rejected

The original installation uses a SCALANCE W786-1PRO wireless link. The DP/DP coupler + Y-Link path requires the S7-400H to communicate over PROFIBUS, which would have meant adding a CP 443-5 Extended in the H-rack, a Y-Link (6ES7197-1LA12) and a DP/DP coupler (6ES7158-0AD01) in the stacker, plus a PROFIBUS cable routed back through the stacker cable reel. The wireless bridge already in place made the wireless Ethernet path the lower-cost and lower-maintenance alternative. Open IE over the existing SCALANCE W infrastructure reuses the same radio link, the same SCALANCE X108 switches, and the same grounding concept.

13. Migration to TIA Portal V15+ with PUT/GET

If the S7-400H is ever migrated to a non-H CPU (for example, on a non-redundant line), TIA Portal V15.1 and later support the legacy S7 PUT/GET path against the S7-1200. The same CPU 1214C then uses PUT / GET instructions in the "Communication -> S7 Communication" library, and the S7-400 side uses FB14 GET and FB15 PUT. For the S7-400H, however, the S7-H Add-on does not add PUT/GET support beyond the firmware already includes; the Open IE path remains the only standardized option across all firmware versions.

14. Frequently Asked Questions

Why does the CPU 412-5H not appear in the TIA Portal V12 hardware catalog?

The S7-400H is a fault-tolerant system programmed exclusively in STEP 7 V5.5 / V5.6 with the S7-H Add-on. TIA Portal does not import the H-CPU's GSD/SSD objects, and Siemens' policy is to keep H-station engineering in the classic STEP 7 tool. You can still use TIA Portal V12 for the S7-1200 side and STEP 7 V5.5 for the H side; Open IE communication (TCON / TSEND / TRCV) does not require cross-project NetPro coordination.

Can I use PUT/GET between a CPU 1214C and a CPU 412-5H directly?

PUT/GET is a Siemens S7 connection that needs to be defined in NetPro on the S7-400H side and in the device configuration on the S7-1200 side. On the H-station, the PUT/GET path is firmware-dependent and not always exposed through the S7-H Add-on. For H-system firmware V6.0.x the recommended and fully supported approach is Open IE communication with TCON / TSEND / TRCV / TDISCON, which is what this article documents.

How many Open IE connections can a CPU 1214C firmware V4.2 open simultaneously?

The CPU 1214C firmware V4.x supports up to 8 Open IE connections. Each active TCON, each TSEND_C / TRCV_C pair, and each TSEND / TRCV pair counts against this budget. If you need more than 8, move the S7-1200 to a CPU 1215C (up to 8 as well) or a CPU 1217C (firmware V4.x or V5.x), or add a CP 1242-7 / CP 1243-1 / CM 1243-5 module and use its additional connection resources.

What TSAP should I use on each side, and does it matter if I use ASCII or hex?

The TSAP is a free-form 1 to 16-byte string that identifies the partner application. ASCII is more readable in the diagnostic buffer (e.g., "S1" and "S4") and is recommended for human-troubleshootable links. Hex form (e.g., 0x53 0x31) yields the same bytes. On the S7-1200, prefix 2-byte ASCII TSAPs with [0,0,…] to mark the length as 2; on the S7-400H the UDT65 local_tsap_id_len and rem_tsap_id_len fields explicitly carry the length. The remote TSAP on side A must equal the local TSAP on side B, and vice versa.

What happens to the Open IE link when the H-system performs a redundancy switchover?

An H-system switchover moves the active role from one CPU to the other. Because both H-CPUs share the same IP (the H-system IP 192.168.0.30 in this article), the partner sees no IP change. The TCP / ISO-on-TCP socket survives if the switchover takes less than the OS keep-alive timeout of the partner (typically 30 s); S7-400H switchovers complete in 200-500 ms. If the link does drop, TSEND_C on the S7-1200 with CONT = TRUE will automatically re-establish the connection within a few seconds, and the S7-400H TCON block must be re-triggered with a rising edge on REQ.

Is Open IE communication secure on a wireless link?

Open IE is unencrypted on the S7-400H CPU onboard PN interface. On a wireless segment the link is exposed to anyone within radio range. Harden the wireless layer with WPA2/AES on the SCALANCE W786-1PRO, segment the S7 traffic into a separate VLAN, and apply the "Access protection" password on the S7-1200. For TLS on the Open IE link, use a CP443-1 EX30/GX30 on the H-station and firmware V4.4+ on the S7-1200 with ConnectionType = 0x11.

Back to blog