Overview
The SIMATIC S7-300 family does not have an integrated Ethernet port on the standard CPU. To participate in industrial Ethernet, a S7-300 station needs a CP 343-1 communications processor mounted in the central rack (or, for distributed I/O, in an ET 200M). The CP is configured inside the STEP 7 V5.x engineering suite using HW Config for the hardware slot and NetPro for the logical connection. This reference walks through a complete first-time commissioning: from part-number selection and rack planning, through IP address assignment, all the way to the call interface in the user program (LAD/FBD/STL).
The article is written for an engineer who is new to the S7-300 platform but already familiar with industrial control and basic TCP/IP networking. The default engineering tool is STEP 7 V5.5 + SP2 (or newer SP/HF) with the optional NCM S7 add-on, which is normally installed alongside STEP 7 from the same media. TIA Portal also supports the S7-300, but the workflow, catalog paths, and block names differ; the V5.x path is documented here because the source material targets STEP 7.
Prerequisites
| Item | Requirement |
|---|---|
| Engineering software | STEP 7 V5.5 with SP2 or later, including NCM S7 for PROFIBUS/Industrial Ethernet |
| Hardware | S7-300 PS 307 power supply, CPU 31x, CP 343-1 communications processor, Ethernet patch cable (RJ45, Cat 5e or better) |
| Firmware | CP firmware matching STEP 7 catalog (typically the catalog ships the latest GSD/EDDL; mismatches cause SF LED + diagnostic buffer entry 0xE001) |
| IP plan | Reserved IP address, subnet mask, optional router/gateway for the CP |
| Operator rights | Windows user with full rights to install CP drivers (NDIS) and to bind Siemens service protocols |
| Manuals | SIMATIC NET CP 343-1 Manual (entry ID 26100711), S7-300 CPU 31x/31xC Manual |
CP 343-1 Hardware Family and Selection
The CP 343-1 family has several variants; choosing the right one avoids over-spending and avoids missing features the application requires.
| Article number | Variant | Ports | Key capabilities |
|---|---|---|---|
| 6GK7343-1EX30-0XE0 | CP 343-1 Lean | 1 × RJ45 10/100 | S7 Communication, ISO-on-TCP, TCP, UDP, PG/OP communication, time sync |
| 6GK7343-1EX21-0XE0 | CP 343-1 | 1 × RJ45 10/100 | Adds fetch/write (file/DB access), FTP server, S7 routing |
| 6GK7343-1GX31-0XE0 | CP 343-1 Advanced | 2 × RJ45 (switch) | PROFINET IO Controller / IO Device, web server, IP routing, FTP, SNMP, security/firewall (later GSD) |
| 6GK7343-1CX10-0XE0 | CP 343-1 ERPC | 1 × RJ45 | Replacement/ERPC variant; functionally similar to the standard CP 343-1 |
For a beginner doing first-time S7-300 Ethernet, the CP 343-1 Lean (6GK7343-1EX30-0XE0) is the lowest-cost option and is fully supported by STEP 7 V5.5. If you need to connect a remote S7 station through this CP (S7 routing), the standard CP 343-1 is required; the Lean variant does not route S7 connections across subnets.
Step 1 — Create the Station in STEP 7
- Launch SIMATIC Manager. File → New → Project. Name the project (e.g.
PlantLine1_S7-300). - Right-click the project, choose Insert New Object → SIMATIC 300 Station. A new station icon appears in the project tree.
- Open the station. Double-click Hardware to launch HW Config.
- Insert a rail (RACK-300, article 6ES7 390-1AF30-0AA0) from the catalog: drag RACK-300 onto the empty rack frame.
- Slot 1: PS 307 (e.g. 6ES7 307-1EA01-0AA0, 5 A).
- Slot 2: CPU 315-2 PN/DP (6ES7 315-2EH14-0AB0) or any CPU 31x. When using a CPU 31x-2 PN/DP the second PROFINET interface is on the CPU, not the CP; the CP is a separate network path.
- Slot 4: CP 343-1 Lean (6GK7 343-1EX30-0XE0). Drag from SIMATIC 300 → CP-300 → Industrial Ethernet → CP 343-1 Lean.
- Double-click the CP to open its properties. Set the IP address (e.g.
192.168.0.10), Subnet mask (255.255.255.0), and optional Router address if the plant has a backbone. - Save and compile the station. Station → Save and Compile. Address assignment is written to the CP at download time.
Step 2 — Set the CP as a PROFINET/IE Node
The CP 343-1 (Ethernet) appears in HW Config as an Ethernet node. In the Properties dialog, switch to the Properties → Ethernet Interface → General tab and verify the following:
| Field | Recommended value for first-time setup |
|---|---|
| MAC address | Read-only (factory assigned) |
| IP address | 192.168.0.10 |
| Subnet mask | 255.255.255.0 |
| Use router | Activated only if the CP must talk to another subnet |
| PROFINET IO Device / Controller | Not used for CP 343-1 Lean; only on the Advanced variant |
| Time-of-day synchronization | Activate if the plant NTP server is reachable; the CP becomes an NTP client |
The CP can be assigned its IP address from three sources, in order of priority: (1) configuration in STEP 7, (2) DHCP, (3) factory default (0.0.0.0). For a fixed plant, always assign from STEP 7 so the configuration is reproducible.
Step 3 — Build the Logical Connection in NetPro
After hardware compile, open NetPro (menu Options → NetPro). The S7-300 station appears with its CP 343-1 as an Ethernet node. To add a partner:
- Insert a second S7 station, an HMI station, or a third-party node that uses the same Ethernet subnet.
- Select the CP 343-1 of the S7-300, right-click the connection table, Insert New Connection.
- In the dialog choose the partner node (e.g. an S7-1200 CPU on the same subnet, or a CPU 317 in another S7-300 station).
- Select the connection type:
| Connection type | Typical use | TSAP / Port |
|---|---|---|
| S7 Connection | PG functions, HMI, S7 routing, PUT/GET to another S7 | TSAP 01.01 (server) / 02.01 (PG) |
| ISO-on-TCP Connection | Open, vendor-neutral, reliable byte stream between S7 and PC/3rd party | TSAP, e.g. 10.01 hex |
| TCP Connection | Free-form byte stream to a PC socket (port number) | Local + remote port, e.g. 2000 |
| UDP Connection | Lightweight, broadcast-friendly, no handshake | Local + remote port |
After confirming, NetPro shows the connection with a green/yellow line. Save and compile NetPro (Network → Save and Compile) so the connection ID, partner IP, and local/remote TSAP/port are written into the S7-300 station data.
Step 4 — Download the Configuration to the CPU and CP
- In HW Config, click Download to Target → Selected Target Device. The download dialog appears.
- If this is the first download, Select Target System → Accessible Nodes must find the CPU on MPI/Profibus. If you only have Ethernet, plug your PC into the same switch as the CP and target the CP's IP directly; the CP will then route the download to the CPU via the backplane.
- Select the interface: Ethernet → TCP/IP → Network card of PG/PC.
- Enter the CP's IP (
192.168.0.10) and press Display. The CP replies with its MAC. - Confirm download. STEP 7 writes the hardware configuration first, then the connection data, then the user program (blocks).
http://192.168.0.10) that can confirm the IP is alive without STEP 7.Step 5 — Call the Communication Blocks in the User Program
The connection made in NetPro exposes an ID (local connection ID) used by the CP blocks in the user program. The three most common S7-300 user-program patterns are listed below.
5.1 S7 Communication: PUT / GET (with partner S7)
Use FB 15 (PUT) and FB 14 (GET) from the Standard Library. These are integrated in every S7-300 CPU and do not require a CP — the CP is just a transport. They are easiest when both sides are Siemens S7.
// STL excerpt: read 10 bytes from partner DB20 starting at byte 0
CALL "PUT"
REQ :=M0.0 // rising edge triggers send
ID :=W#16#0001 // must match NetPro connection ID
DONE :=M10.0
ERROR :=M10.1
STATUS :=MW12
ADDR_1 :=P#DB20.DBX0.0 BYTE 10
SD_1 :=P#M100.0 BYTE 10
LEN :=10
5.2 ISO-on-TCP / TCP with CP 343-1 (lean variants)
The CP requires its own AG_SEND / AG_RECV function blocks (FC 5 / FC 6) for open TCP/ISO transport when no S7 partner is involved. Both are part of the SIMATIC_NET_CP library that ships with STEP 7.
// STL: send 50 bytes to a partner socket
CALL "AG_SEND"
AG :=W#16#0001 // CP 343-1 logical address from HW Config
ID :=1 // connection ID from NetPro
LEN :=50
DONE :=M20.0
ERROR :=M20.1
STATUS:=MW22
SEND :=P#DB100.DBX0.0 BYTE 50
On the receive side, AG_RECV (FC 6) pulls bytes from the receive buffer. Always allocate the receive buffer with adequate length (a few hundred bytes is safe for short protocols).
5.3 UDP with CP 343-1
UDP uses AG_SEND (FC 5) and AG_RECV (FC 6) with a connection configured as UDP in NetPro. UDP has no DONE handshake; the receive is edge-driven by the LEN output of AG_RECV transitioning from 0 to a non-zero value.
Step 6 — Configure Time Synchronization (Optional)
The CP 343-1 supports SIMATIC time-of-day and NTP (NTP only on the Advanced variant). To enable NTP on the Advanced CP:
- Open HW Config and double-click the CP 343-1 Advanced.
- Properties → Time-of-Day Synchronization → NTP mode.
- Enter the NTP server address (e.g.
192.168.0.250) and the synchronization interval (default 10 minutes, range 1-1440). - Set the time zone offset. Save and download.
Step 7 — Verify the Connection
| Check | How to verify | Pass criterion |
|---|---|---|
| CP firmware/online | Online → Accessible Nodes → flash LED of CP | CP reachable, SF LED off |
| CP IP | Online → Diagnostics of CP → General | IP shows the configured value, MAC matches label |
| Connection status | NetPro → right-click CP → Connection Status | Connection "Established" |
| User program | Online → Monitor/Modify → STATUS word of AG_SEND/GET | STATUS = W#16#0000 (no error) |
| PG/OP | Online → Accessible Nodes → browse online from second node | Partner station visible |
LED Diagnosis and Buffer Entries
The CP 343-1 has four status LEDs. Their meaning is identical across the Lean/standard/Advanced variants.
| LED | Off | On (steady) | Flashing |
|---|---|---|---|
| SF (red) | No fault | Group fault (see diagnostic buffer) | Boot/firmware update active |
| BF (red) | Link present, no bus fault | Physical link down or no partner | No Ethernet cable plugged in |
| RUN (green) | No power or CP stopped | CP running, connections OK | CP startup phase |
| STOP (yellow) | CP running | CP stopped; connections refused | Hold-down/reset phase |
If SF is on, open the S7-300 diagnostic buffer (online) and look for CP entries. Common diagnostic event IDs:
| Event ID | Meaning | Remedy |
|---|---|---|
| 0xE001 | Firmware/HW mismatch (catalog older than CP FW) | Update STEP 7 catalog or downgrade CP FW |
| 0xE002 | IP address conflict (duplicate IP on the LAN) | Change CP IP, audit network |
| 0xE003 | No subnet / mask invalid | Re-enter mask in HW Config |
| 0xE004 | Duplicate station name (PROFINET only) | Rename station |
| 0xE005 | Connection error (TSAP/port mismatch) | Compare NetPro entries to partner |
| 0xE006 | Authentication/security block | Re-enter password or disable secure_odp if not needed |
Common STATUS Words for AG_SEND / AG_RECV
| STATUS (hex) | Source | Meaning |
|---|---|---|
| 0000 | Both | Job completed without error |
| 7000 | Both | No job active, waiting for REQ trigger |
| 8180 | AG_SEND | Connection ID/AG number does not exist |
| 8183 | AG_SEND | AG_SEND and AG_RECV are in the wrong order, or REQ edge lost |
| 8184 | AG_SEND | System error (memory/CP internal) |
| 8185 | AG_SEND | LEN > max user data (e.g. > 8192 bytes for Lean) |
| 80A1 | AG_RECV | Connection aborted by partner |
| 80A4 | AG_RECV | Connection ID / AG number does not exist |
| 80A7 | AG_RECV | Receive buffer too small; reduce LEN or enlarge buffer |
| 80B4 | AG_SEND | Connection is being established; wait |
Troubleshooting Matrix
| Symptom | Most likely cause | Action |
|---|---|---|
| BF LED on, no link | Cable/Switch port, wrong port speed (10 vs 100) | Swap cable, try another switch port, set CP to auto-negotiate (default) |
| BF flashing | TCP/IP ARP not getting reply | Check switch VLAN, ping CP from PC |
| SF LED on | Configuration mismatch | Read diagnostic buffer, compare HW Config to online |
| STATUS 8180 on AG_SEND | Connection not in NetPro, or wrong ID | Recompile NetPro, check ID |
| STATUS 80A1 | Partner closed the TCP socket | Confirm partner PLC/PC application is running |
| PUT/GET works from HMI but not from PC | No S7 license (CP 343-1 standard uses write-protected S7 routes) | Use the standard CP 343-1 (not Lean) or buy a routing license |
| PG cannot find CP | PG/PC interface set to MPI/Profibus | Set PG/PC interface to TCP/IP, retry |
| Time jumps after reboot | CP not configured as NTP client | Enable NTP in CP properties, save, download |
Security and Modern Considerations
Firmware on the CP 343-1 family is mature; do not expose an S7-300 CP directly to the public internet or a hostile subnet. Mitigations to apply at commissioning:
- Use a dedicated plant VLAN with private RFC 1918 addressing.
- Disable unused services on the CP (e.g. FTP, web server) in HW Config → Properties → Services.
- Activate the Access Protection password so unauthorized S7 partners cannot be defined.
- On the Advanced CP, enable the integrated firewall with allow-list of partner IPs.
- Use S7-1200/1500 or SCALANCE SFPs at the plant boundary; do not terminate the S7-300 CP at the WAN edge.
Field-Commissioning Short List
- Verify rack order, slot occupancy, and PS 307 sizing (5 A standard, 10 A for many I/O + CP).
- Confirm CP MAC sticker matches HW Config.
- Pre-stage IP plan; reserve DHCP exclusions for the CP block.
- Compile HW Config → Compile NetPro → Download both.
- Check the four CP LEDs, then read CPU diagnostic buffer for any new entries.
- Run a test S7 connection (e.g. an HMI tag polling) and watch NetPro Connection Status.
- Document the connection IDs, partner IPs, and TSAPs in the cabinet drawing.
- Hand off to operations with a network diagram, including switch, VLAN, and the CP's IP.
Where do I find the official CP 343-1 manual?
The current CP 343-1 manual is on the Siemens support portal as entry ID 26100711. Search "CP 343-1 Manual" at support.industry.siemens.com. The S7-300 CPU manual is entry ID 45531122.
Why does the CP 343-1 Lean not show up in the STEP 7 catalog?
Older STEP 7 versions (V5.3 and below) do not include the 6GK7343-1EX30-0XE0 GSD. Install STEP 7 V5.5 SP2 or later, or install the HSP (Hardware Support Package) for the CP from the Siemens online updates.
Can I use TIA Portal instead of STEP 7 V5.x for the S7-300?
Yes. TIA Portal (V13 and newer) supports the S7-300 family for configuration, online diagnostics, and the same communication blocks. The S7-300 PROFINET CPUs (31x-2 PN/DP) work directly; the CP 343-1 family is also cataloged, though Siemens recommends newer S7-1200/1500 for new projects.
What is the difference between an S7 connection and an ISO-on-TCP connection?
S7 connections are Siemens-proprietary, work only between S7 stations, and ride on top of ISO-on-TCP (TSAP addressing). ISO-on-TCP is the open RFC 1006 transport; any device that speaks TCP can talk to a CP 343-1 ISO-on-TCP partner if it knows the TSAP and byte layout. Use S7 for HMI and S7-S7, use ISO-on-TCP for cross-vendor integration.
My AG_SEND STATUS reads 8185 (LEN too big) — what is the maximum user data length?
For the CP 343-1 Lean and standard, AG_SEND/AG_RECV support up to 8192 bytes per call. The CP 343-1 Advanced allows up to 32767 bytes. For larger payloads, use BSEND/BRCV (FB 12/FB 13) on the S7-400 or, for S7-300, segment manually with multiple AG_SEND calls.