Configuring S7-1500 ET 200SP with DNP3 for Wastewater Pumps
Wastewater lift stations and pump stations are geographically distributed sites that report to a central SCADA master over cellular, fiber, or radio links. The DNP3 (Distributed Network Protocol version 3.0) protocol, defined in IEEE Std 1815-2012 and maintained by the DNP Users Group at dnp.org, is the dominant SCADA protocol in the water/wastewater, electric power, and oil & gas sectors. The configuration in this reference covers a Siemens SIMATIC ET 200SP station with CPU 1510SP-1 PN, an I/O slice set, a CP 1542SP-1 IRC communications processor running the DNP3 device stack, and an eWON Flexy for remote VPN engineering access.
1. Application Overview and DNP3 in Wastewater Pumping
A pump station's RTU must reliably send motor status, level, flow, power, alarm, and run-time data to the central master, and accept start/stop commands back to the local pumps. Key DNP3 features relevant to this use case:
- Report-by-exception (RBE) and unsolicited reporting to minimize cellular bandwidth
- Time-stamped events with class 0/1/2/3 scan priorities (static, class 1, class 2, class 3)
- Integrity poll (function code 1) and event poll (function code 2)
- Select-before-operate (SBO) binary output control via group 12 variations (CROB)
- Time synchronization (function code 24) for accurate event time-stamping
- Cold restart (function code 15) and warm restart (function code 14) for master-driven recovery
- File transfer (group 70) for firmware and configuration upload/download
The DNP3 data set for a pump station typically maps to: binary inputs (group 1) for pump run/fault/hand-off-auto, binary output status (group 10), analog inputs (group 30) for level/flow/voltage, analog output status (group 40), and counters (group 20) for run-hours and starts. Conformance level 2 with selected level 3 features is the typical capability baseline. Reference: Software Toolbox: What is DNP3?.
2. System Architecture
The architecture comprises four functional layers:
- Field layer: submersible level transmitter (hydrostatic or ultrasonic), flowmeter, pump thermal/overload contacts, door switches, and surge protection
- Control layer: ET 200SP station with CPU 1510SP-1 PN, AI/DI/DO modules, and CP 1542SP-1 IRC running DNP3
- Communications layer: eWON Flexy VPN router over LTE/UMTS (or fiber), then the DNP3 master over Talk2M or dedicated IPsec tunnel
- Supervisory layer: SCADA master (WinCC, Geo SCADA Expert, Ignition, or third-party) with DNP3 master stack
The ET 200SP station operates as an IO Controller with CPU 1510SP-1 PN. The CP 1542SP-1 IRC handles all DNP3 traffic independently of the CPU scan, so protocol load does not impact the PLC cycle time. Communication between CPU and CP is via the backplane bus, not the LAN.
3. Hardware Selection: S7-1500 ET 200SP and CP Modules
For DNP3 over IP on S7-1500, Siemens requires a SIMATIC NET communications processor (CP). The CPU itself cannot serve DNP3 directly; the DNP3 stack is loaded on the CP and exchanges data with the CPU via PUT/GET or via the S7-1500 backplane bus.
| Component | Article Number | Function | Notes |
|---|---|---|---|
| CPU 1510SP-1 PN | 6ES7510-1DJ02-0AB0 | ET 200SP CPU, PROFINET IO Controller | FW V2.8 recommended |
| CP 1542SP-1 | 6GK7542-1AX00-0XE0 | ET 200SP comm processor, 1× RJ45 | Basic TCP/UDP only — no DNP3 |
| CP 1542SP-1 IRC | 6GK7542-1AX10-0XE0 | ET 200SP comm processor with DNP3, IEC 61850, IEC 60870-5-104 | Required for DNP3 |
| CP 1543-1 | 6GK7543-1MX00-0XE0 | S7-1500 CP, 2× RJ45, security/firewall | For S7-1500 standalone PLCs |
| IM 155-6 PN ST | 6ES7155-6AA01-0BN0 | ET 200SP PROFINET interface module | For distributed I/O only (no CPU) |
| AI 4xU/I/RTD/TC ST | 6ES7531-7QD00-0AB0 | 4-ch analog input | Level/flow 4-20 mA |
| DI 8x24VDC ST | 6ES7131-6BF00-0BA0 | 8-ch digital input | Pump run/fault/HOA |
| DQ 8x24VDC/0.5A ST | 6ES7132-6BF00-0BA0 | 8-ch digital output | Pump start/stop commands |
The CP 1542SP-1 IRC (Industrial Remote Communication) is the correct choice for distributed ET 200SP stations where the DNP3 stack runs directly on the communications processor. The plain CP 1542SP-1 (without IRC) does not have the DNP3 firmware option. If the project uses a standalone S7-1500 (e.g., CPU 1515-2 PN in an S7-1500 rack) instead of ET 200SP, the CP 1543-1 is the equivalent part for DNP3.
Reference: Siemens: CP 1542SP-1 IRC manual and Siemens: CP 1543-1 manual.
4. Siemens Compact RTU Alternative: SIMATIC RTU3030C
For unmanned pump stations where the full S7-1500 PLC capability is not required, Siemens offers the SIMATIC RTU3030C. This is a hardened cellular RTU with DNP3 firmware pre-installed.
| Specification | Value |
|---|---|
| Article number | 6NH3112-0BA00-0XX0 |
| Power supply | 12-24 V DC nominal (9-36 V DC operating) |
| CPU / protocol stack | DNP3, IEC 60870-5-104, MQTT, TeleControl Basic |
| Cellular modem | LTE Cat 1 (B1/B3/B7/B8/B20/B28), UMTS, GSM fallback |
| Antenna | ANT794-4MR (6NH9860-1AA00) recommended |
| SIM | Mini-SIM, 1.8 / 3 V |
| Digital inputs | 4 (24 V DC, type 3 per IEC 61131-2) |
| Digital outputs | 2 (relay, 5 A 250 V AC / 30 V DC) |
| Analog inputs | 4 (0-10 V or 0/4-20 mA, 16-bit) |
| Counter inputs | 2 (up to 1 kHz) |
| Temperature input | 1 (PT1000) |
| Protocols | DNP3, IEC 60870-5-104, MQTT, OpenVPN, IPsec |
| Configuration tool | SINEC NMS, SCS, or web UI (port 8443) |
| Operating temperature | -40 °C to +70 °C |
| Protection | IP65 with sealing plugs |
| Approvals | CE, FCC, RCM, ATEX Zone 2 (variant) |
The RTU3030C is the recommended RTU for greenfield pump stations where the controller must be compact, rugged, and cellular-native. It is wired directly to the pump contactor, level transducer, and power monitor; no separate CP is required. The S7-1500 ET 200SP is preferred when the station also has process control (chemical dosing, multi-pump alternation, VFD coordination) beyond pure monitoring. Reference: Siemens: SIMATIC RTU3030C manual.
5. I/O Sizing for a Wastewater Pump Station
A typical duplex submersible pump station with two 18.5 kW (25 hp) pumps on a 400 V three-phase supply has the following I/O list. The sizing is used to plan the ET 200SP slice count and AI/DI/DO module selection.
5.1 Power calculation
For three-phase apparent power:
kVA = sqrt(3) × V_LL × I_line / 1000
For single-phase apparent power:
kVA = V × I / 1000
Example 1: line current 36 A at 400 V three-phase → kVA = sqrt(3) × 400 × 36 / 1000 = 24.94 kVA
Example 2: 360 A three-phase line current at 400 V → kVA = sqrt(3) × 400 × 360 / 1000 = 249.4 kVA
Example 3: 360 A single-phase current at 230 V → kVA = 230 × 360 / 1000 = 82.8 kVA
Always confirm whether the current is three-phase line current, single-phase, RMS, or peak before sizing conductors and transformers. The pump station I/O list below assumes 36 A line current per pump at 400 V three-phase.
5.2 I/O list (duplex pump station)
| Signal | Type | Module | Range / Spec |
|---|---|---|---|
| Wet well level | AI | 1× AI 4xU/I | 4-20 mA from hydrostatic level, 0-10 m H2O |
| Flow (magmeter) | AI | 1× AI 4xU/I | 4-20 mA, 0-200 L/s |
| Pump 1 running | DI | DI 8x24VDC | 24 V from contactor aux contact |
| Pump 1 fault | DI | DI 8x24VDC | 24 V from overload relay |
| Pump 1 HOA in AUTO | DI | DI 8x24VDC | 24 V from selector switch |
| Pump 1 thermal | DI | DI 8x24VDC | PTC via thermistor relay |
| Pump 2 running | DI | DI 8x24VDC | 24 V from contactor aux contact |
| Pump 2 fault | DI | DI 8x24VDC | 24 V from overload relay |
| Pump 2 HOA in AUTO | DI | DI 8x24VDC | 24 V from selector switch |
| Pump 2 thermal | DI | DI 8x24VDC | PTC via thermistor relay |
| Intrusion / door | DI | DI 8x24VDC | 24 V from door switch |
| Power fail | DI | DI 8x24VDC | 24 V from UPS alarm relay |
| Pump 1 start | DO | DQ 8x24VDC/0.5A | 24 V to contactor coil via interposing relay |
| Pump 1 stop | DO | DQ 8x24VDC/0.5A | 24 V to latching contactor stop |
| Pump 2 start | DO | DQ 8x24VDC/0.5A | 24 V to contactor coil via interposing relay |
| Pump 2 stop | DO | DQ 8x24VDC/0.5A | 24 V to latching contactor stop |
| Beacon / horn | DO | DQ 8x24VDC/0.5A | 24 V to high-level alarm device |
| VFD speed ref 1 (optional) | AO | AQ 4xU/I ST | 4-20 mA, 0-100% to VFD |
Minimum ET 200SP configuration: 1× CPU 1510SP-1 PN, 1× CP 1542SP-1 IRC, 1× AI 4xU/I, 2× DI 8x24VDC, 1× DQ 8x24VDC/0.5A, plus server module and BaseUnit. With spares, the typical ordering is 1× AI 8xU/I, 2× DI 16x24VDC, 1× DQ 8x24VDC/0.5A to allow room for future expansion.
6. TIA Portal DNP3 Library Configuration
The DNP3 stack on the CP 1542SP-1 IRC is configured from TIA Portal using the DNP3 device library. This library is part of the "DNP3 device" option package installed alongside STEP 7 Professional.
6.1 Minimum software stack
- TIA Portal V16 SP1 Update 4 or later (V17 / V18 / V19 / V20 all supported)
- STEP 7 Professional
- "DNP3 device" option package
- CPU 1510SP-1 PN firmware V2.8 or later
- CP 1542SP-1 IRC firmware V1.1 or later
6.2 Project structure
- Create a TIA Portal project with the CPU 1510SP-1 PN in slot 1 of the ET 200SP station.
- Add the CP 1542SP-1 IRC to slot 2.
- Drag the AI, DI, and DO modules into slots 3-5.
- Drag the "DNP3" application from the library onto the CP 1542SP-1 IRC.
- Open the DNP3 configuration editor and define data points.
The DNP3 configuration is split into four tabs:
- Device Configuration: master IP addresses, port (default 20000 TCP), authentication, unsolicited reporting mode, keep-alive timer, master-allow-list.
- Data Point Configuration: each DNP3 point has an object group, variation, index, deadband (analogs), event class (0/1/2/3), and SBO attributes.
- Event Configuration: class 1/2/3 scan periods, integrity poll period, event buffer size (recommended 1000 events minimum).
- Diagnostics: buffer enable, syslog target, web diagnostics.
6.3 Sample DNP3 point configuration
In the PLC program, the DNP3 stack exchanges data with the CPU via a data block. The default is DB 100 for inputs and DB 101 for outputs. Example tag mapping:
| Tag | Type | DNP3 Object | Group/Variant | Event Class |
|---|---|---|---|---|
| Pump1_Running | Bool | Binary Input | 1:0 | 1 |
| Pump1_Fault | Bool | Binary Input | 1:0 | 2 |
| Pump1_HOA_Auto | Bool | Binary Input | 1:0 | 1 |
| WetWell_Level_m | Real | Analog Input | 30:6 (float) | 2 |
| Flow_Lps | Real | Analog Input | 30:6 (float) | 3 |
| Pump1_Run_Hours | DWord | Counter | 20:0 (32-bit) | 0 |
| Pump1_Start | Bool | Binary Output (CROB) | 12:1 | n/a |
| Pump1_Stop | Bool | Binary Output (CROB) | 12:1 | n/a |
Configuration example for a binary input (pump 1 running):
Point index : 0
Object group : 1 (Binary Input)
Variation : 0 (g1v0, packed format)
Static class : 0 (returned on integrity poll)
Event class : 1
Deadband : n/a
DB mapping : DB100.DBX0.0
Configuration example for an analog input (wet well level):
Point index : 0
Object group : 30 (Analog Input)
Variation : 6 (g30v6, 32-bit float)
Static class : 0
Event class : 2
Deadband : 0.05 m
DB mapping : DB100.DBD4
For binary outputs (CROB):
Point index : 0
Object group : 12 (CROB)
Variation : 1 (g12v1)
Control mode : SBO (select-before-operate, control code 0x40)
DB mapping : DB101.DBX0.0
7. DNP3 Data Point Mapping
DNP3 conformance levels per IEEE Std 1815-2012 define which objects are supported. The CP 1542SP-1 IRC typically supports conformance level 2 with selected level 3 features. The mapping table below shows the recommended object mapping for a pump station.
| Function | DNP3 Object | Group | Variant | PLC Tag Prefix |
|---|---|---|---|---|
| Pump run / fault / HOA | Binary Input | 1 | 0 | Pump1_Status |
| Pump trip (CROB echo) | Binary Output Status | 10 | 2 | Pump1_BO_Echo |
| Run-hours counter | Counter | 20 | 0 | Pump1_RH |
| Starts counter | Counter | 20 | 0 | Pump1_Starts |
| Level (m) | Analog Input | 30 | 6 | Level_m |
| Flow (L/s) | Analog Input | 30 | 6 | Flow_Lps |
| Power (kW) | Analog Input | 30 | 6 | Power_kW |
| Pump 1 trip alarm | Binary Input Event | 2 | 0 | Pump1_Fault_Ev |
| Level high-high | Binary Input Event | 2 | 0 | Level_HH_Ev |
| Time sync | Time | 50 | 1 | SystemTime |
| Pump start command | CROB | 12 | 1 | Pump1_StartCmd |
| Pump stop command | CROB | 12 | 1 | Pump1_StopCmd |
| Setpoint (e.g., set level) | Analog Output | 40 | 2 | SetLevel_m |
For unsolicited reporting, configure the CP with:
- Mode: "Enabled — on class 1/2/3 events"
- Hold time after event: 500 ms
- Number of events before send: 5
- Max events per unsolicited response: 10
- Retry count: 3
- Retry timeout: 5 s
7.1 SBO control timing
8. eWON Remote Access and DNP3 Gateway
For remote engineering, cellular backhaul, and DNP3 master concentration, the eWON Flexy family is a common choice. The Flexy establishes an IPsec or OpenVPN tunnel to the Talk2M cloud, and the engineering workstation connects via eCatcher. The eWON does not include a DNP3 master stack; it acts only as a VPN router. The DNP3 master is on the central SCADA host and connects to the CP 1542SP-1 IRC via the VPN.
8.1 Typical eWON configuration
| Setting | Value |
|---|---|
| Article number | eWON Flexy 201 (base) + FLB 3202 (cellular) + FLB 3601 (WiFi, optional) |
| VPN protocol | OpenVPN over Talk2M |
| Outbound | UDP 1194 to Talk2M relay |
| Authentication | eWON ID + activation key |
| Local PLC subnet | 192.168.0.0/24 |
| eWON LAN IP | 192.168.0.1 |
| CPU 1510SP-1 PN IP | 192.168.0.10 |
| CP 1542SP-1 IRC IP | 192.168.0.20 |
| TIA Portal access | PG/PC routes through VPN, target CPU |
eWON Cosy+ is a smaller, dedicated remote-access router without I/O expansion slots. eWON Flexy supports up to 8 I/O expansion cards for local monitoring if needed. If a DNP3-to-DNP3 gateway is required (e.g., to aggregate multiple cellular RTUs to a single SCADA master), the eWON is not the right device. Use a dedicated DNP3 concentrator (e.g., Siemens SICAM A8000, or a PLC-based aggregator running the DNP3 master stack) instead. Reference: eWON Flexy specifications.
9. Self-Diagnostics and Web Server
The S7-1500 CPU and the CP 1542SP-1 IRC both provide diagnostics accessible via the integrated web server.
9.1 CPU diagnostics
- Standard web pages at
http://<CPU_IP>/(default port 80, redirect 443) - Diagnostic buffer viewable in the web UI (read-only) and in TIA Portal (online → diagnostics)
- Watch tables and force tables via web page (read-only)
- OPC UA server (firmware V2.6+ exposes diagnostic tags)
- CPU status LEDs: RUN (green), ERROR (red), MAINT (yellow), LINK (green on PROFINET port)
9.2 CP diagnostics
- DNP3 statistics page: counters for transmissions, receptions, parse errors, authentication failures
- Per-master connection state
- Time sync source / status
- Active alarms
- License status (valid / expired)
The PLC self-diagnostic function is built-in. To expose diagnostics to the SCADA master as DNP3 points:
- DNP3 object 80 (device attributes) for firmware version
- DNP3 object 81 (device status) for restart count, battery, time sync flag
- User-defined binary inputs for diagnostic flags
- Analog input for CP uptime (in hours)
| Tag | DNP3 Object | Source |
|---|---|---|
| CP_Online | g1v0 index 100 | CP online state |
| VPN_Connected | g1v0 index 101 | eWON VPN tunnel up |
| CPU_Battery_OK | g1v0 index 102 | CPU battery status |
| Time_Sync_OK | g1v0 index 103 | DNP3 time sync from master |
| CPU_Load_pct | g30v6 index 100 | CPU utilization 0-100% |
| CP_Temp_C | g30v6 index 101 | CP internal temperature |
| Comm_Errors_LastHour | g20v0 index 100 | Rolling counter |
10. Network Architecture and Security
DNP3 over IP is routed over the same network infrastructure as the engineering VPN. The recommended segmentation is:
- OT DMZ (zone 3): eWON Flexy, CP 1542SP-1 IRC, CPU
- IT/Cloud zone: Talk2M relay, SCADA master
- Office network (zone 4): engineering workstations
10.1 Security baseline
- Enable IPsec between eWON and Talk2M (default)
- Enable CP 1543-1 / CP 1542SP-1 IRC firewall
- Restrict DNP3 master IP allow-list to the SCADA master public IP
- Disable unused services on the CP (FTP, telnet, HTTP)
- Use DNP3 Secure Authentication v5 (SAv5) for master-to-RTU authentication. S7-1500 CP supports SAv2 by default; SAv5 requires CP firmware V2.9+
- Disable public DNS entries for the RTU
- Use cellular private APN where available
- Patch CPU and CP firmware at every planned shutdown
11. Commissioning Procedure
- Pre-power checks: verify ET 200SP BaseUnit wiring, shield terminations, and 24 V DC polarity. Use a multimeter to confirm 24 V ±10% at the power feed module.
- Apply power: power up the ET 200SP station. The CPU RDY LED should turn solid green within 30 s. The CP RDY LED should turn solid green within 60 s.
- CPU online: connect TIA Portal, assign IP 192.168.0.10 to the CPU via the Online & Diagnostics wizard. Online go-online and download the project. Verify CPU RUN.
- CP configuration: assign IP 192.168.0.20 to the CP 1542SP-1 IRC. Download the DNP3 configuration. Verify the CP shows "DNP3 active" in its web diagnostics.
- I/O check: force each DI/DO and verify via watch table. For each AI, inject 4 mA / 12 mA / 20 mA and verify the scaled value in the process image.
- DNP3 master connectivity: from the SCADA master, ping the CP IP via the VPN. Add the RTU as a DNP3 outstation. Run integrity poll (FC=1) and verify all class 0 points return. Run event poll (FC=2) and verify class 1/2/3 points.
- Control check: issue a SBO + OPERATE to the pump start CROB. Verify the DO turns on. Issue SBO + OPERATE to the pump stop CROB. Verify the DO turns off. Capture the sequence of events in the master log.
- Alarm test: open the wet well level door (simulate high level). Verify the level-HH event appears in the master. Acknowledge the alarm and confirm the event clears from the class queue.
- Time sync: enable time sync (FC=24) from the master. Verify the CP's time-stamp on incoming events matches master time within 1 s.
- Failover test: disconnect the cellular link for 60 s. Verify the buffer of events is held and re-transmitted on reconnect.
- Cybersecurity: scan the CP from Nmap; verify only TCP 20000 (DNP3) and 443 (web) are open. Verify all other ports are filtered.
- Documentation handover: export the TIA Portal project archive, the DNP3 configuration file, the IP allocation table, and the master configuration file. Hand over to the SCADA integrator.
12. Troubleshooting Matrix
| Symptom | Likely Cause | Diagnostic Step | Fix |
|---|---|---|---|
| CP RDY LED red, all 4 RUN/STOP/COMM LEDs off | CP 1542SP-1 IRC firmware mismatch with CPU FW | Open TIA Portal online → CP → "Firmware version" | Upgrade CP firmware to the version bundled with the TIA Portal version |
| DNP3 master receives no response | DNP3 license not loaded | CP web diagnostics → "License" tab | Re-install DNP3 option card using the CoL |
| Integrity poll returns no class 0 points | DB mapping wrong | TIA Portal watch table on DB100, verify bit states | Re-map data points to DB100/DB101 |
| CROB operate returns "unsupported" | SBO mode not enabled in point config | CP DNP3 config → point → control mode | Change to SBO enabled (control code 0x40) |
| Time-stamps off by hours | Time sync disabled | CP diagnostics → time source | Enable FC24 (record current time) from master |
| Latency spikes every 5 min | Integrity poll too frequent | Master polling settings | Increase integrity poll to 5-15 min, use RBE for change events |
| Cellular link drops daily | Antenna placement / RSSI | eWON web → cellular diagnostics | Move antenna outside enclosure, target RSSI > -90 dBm |
| Event buffer overflows | RBE not enabled | CP DNP3 config → unsolicited | Enable unsolicited reporting, class 1+2+3 |
| Auth failure log entries | Master and RTU pre-shared key mismatch | CP DNP3 config → security | Re-enter SAv2 pre-shared key, save and restart CP |
| Pump start command received but DO not closing | Interposing relay coil polarity | Field check at DO terminal | Reverse 24 V polarity, verify common is tied to GND |
| Analog value clipped at 0 or 32767 | 4-20 mA wire break or overrange | TIA Portal watch table on AI | Check loop power, transducer, scaling in AI module config |
| PLC battery alarm | CPU battery low | CPU web → battery | Replace battery (article number 6ES7971-0BA00) within 2 weeks |
13. Frequently Asked Questions
Can the CPU 1510SP-1 PN run DNP3 directly without a CP module?
No. DNP3 on the S7-1500/ET 200SP platform requires a SIMATIC NET communications processor (CP 1542SP-1 IRC for ET 200SP, CP 1543-1 for S7-1500) running the DNP3 firmware option. The CPU executes the application program; the CP executes the protocol stack independently, with the option of running a separate IP firewall.
Which TIA Portal version is required for the DNP3 device library?
TIA Portal V16 SP1 Update 4 or later with the DNP3 device option package installed. The library is enabled once the option package is installed, but the CP firmware requires a separate DNP3 option card license to enable the protocol on the hardware.
Does DNP3 support report-by-exception (RBE) on the CP 1542SP-1 IRC?
Yes. The CP supports unsolicited reporting with configurable class 1/2/3 events, hold time, retry count, and maximum events per response. RBE is recommended for cellular links to minimize data transfer costs.
How does the eWON integrate with the DNP3 master?
The eWON Flexy is a VPN router. It does not act as a DNP3 master. The remote SCADA engineer connects to the eWON over Talk2M and the DNP3 master establishes a direct TCP connection to the CP 1542SP-1 IRC through the VPN tunnel on port 20000.
What is the difference between the SIMATIC RTU3030C and the ET 200SP DNP3 solution?
The RTU3030C is a compact, cellular-native RTU with 4 AI / 4 DI / 2 DO / 2 counter and integrated DNP3 firmware. The ET 200SP with CP 1542SP-1 IRC is a full PLC with expandable I/O, advanced control (PID, motion, dosing), and DNP3. Use the RTU for pure monitoring; use the ET 200SP when control logic exceeds simple start/stop alternation.