Configuring S7-300 Ethernet with CP 343-1 in STEP 7 V5.x

David Krause12 min read
S7-300SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

The SIMATIC S7-300 family does not have an integrated Ethernet port on the standard CPU. To participate in industrial Ethernet, a S7-300 station needs a CP 343-1 communications processor mounted in the central rack (or, for distributed I/O, in an ET 200M). The CP is configured inside the STEP 7 V5.x engineering suite using HW Config for the hardware slot and NetPro for the logical connection. This reference walks through a complete first-time commissioning: from part-number selection and rack planning, through IP address assignment, all the way to the call interface in the user program (LAD/FBD/STL).

The article is written for an engineer who is new to the S7-300 platform but already familiar with industrial control and basic TCP/IP networking. The default engineering tool is STEP 7 V5.5 + SP2 (or newer SP/HF) with the optional NCM S7 add-on, which is normally installed alongside STEP 7 from the same media. TIA Portal also supports the S7-300, but the workflow, catalog paths, and block names differ; the V5.x path is documented here because the source material targets STEP 7.

Document scope: This reference covers ISO-on-TCP, TCP, UDP, and S7 Communication over the CP 343-1. PROFINET IO Controller/IO Device operation on a CP 343-1 Advanced (6GK7343-1GX31-0XE0) is summarized in a separate section because the configuration shifts into a PROFINET view inside HW Config.

Prerequisites

Item Requirement
Engineering software STEP 7 V5.5 with SP2 or later, including NCM S7 for PROFIBUS/Industrial Ethernet
Hardware S7-300 PS 307 power supply, CPU 31x, CP 343-1 communications processor, Ethernet patch cable (RJ45, Cat 5e or better)
Firmware CP firmware matching STEP 7 catalog (typically the catalog ships the latest GSD/EDDL; mismatches cause SF LED + diagnostic buffer entry 0xE001)
IP plan Reserved IP address, subnet mask, optional router/gateway for the CP
Operator rights Windows user with full rights to install CP drivers (NDIS) and to bind Siemens service protocols
Manuals SIMATIC NET CP 343-1 Manual (entry ID 26100711), S7-300 CPU 31x/31xC Manual

CP 343-1 Hardware Family and Selection

The CP 343-1 family has several variants; choosing the right one avoids over-spending and avoids missing features the application requires.

Article number Variant Ports Key capabilities
6GK7343-1EX30-0XE0 CP 343-1 Lean 1 × RJ45 10/100 S7 Communication, ISO-on-TCP, TCP, UDP, PG/OP communication, time sync
6GK7343-1EX21-0XE0 CP 343-1 1 × RJ45 10/100 Adds fetch/write (file/DB access), FTP server, S7 routing
6GK7343-1GX31-0XE0 CP 343-1 Advanced 2 × RJ45 (switch) PROFINET IO Controller / IO Device, web server, IP routing, FTP, SNMP, security/firewall (later GSD)
6GK7343-1CX10-0XE0 CP 343-1 ERPC 1 × RJ45 Replacement/ERPC variant; functionally similar to the standard CP 343-1

For a beginner doing first-time S7-300 Ethernet, the CP 343-1 Lean (6GK7343-1EX30-0XE0) is the lowest-cost option and is fully supported by STEP 7 V5.5. If you need to connect a remote S7 station through this CP (S7 routing), the standard CP 343-1 is required; the Lean variant does not route S7 connections across subnets.

Slot rules: A CP 343-1 occupies one slot in the S7-300 rack (slot 4 to 11). It can sit in slot 4 only if the CPU does not need a free slot for its own expansion. The CP cannot be plugged into slot 1-3. With a CPU 31xC, multi-computing (more than one CPU in one rack) is supported, but the CP must be assigned to a CPU in HW Config.

Step 1 — Create the Station in STEP 7

  1. Launch SIMATIC Manager. File → New → Project. Name the project (e.g. PlantLine1_S7-300).
  2. Right-click the project, choose Insert New Object → SIMATIC 300 Station. A new station icon appears in the project tree.
  3. Open the station. Double-click Hardware to launch HW Config.
  4. Insert a rail (RACK-300, article 6ES7 390-1AF30-0AA0) from the catalog: drag RACK-300 onto the empty rack frame.
  5. Slot 1: PS 307 (e.g. 6ES7 307-1EA01-0AA0, 5 A).
  6. Slot 2: CPU 315-2 PN/DP (6ES7 315-2EH14-0AB0) or any CPU 31x. When using a CPU 31x-2 PN/DP the second PROFINET interface is on the CPU, not the CP; the CP is a separate network path.
  7. Slot 4: CP 343-1 Lean (6GK7 343-1EX30-0XE0). Drag from SIMATIC 300 → CP-300 → Industrial Ethernet → CP 343-1 Lean.
  8. Double-click the CP to open its properties. Set the IP address (e.g. 192.168.0.10), Subnet mask (255.255.255.0), and optional Router address if the plant has a backbone.
  9. Save and compile the station. Station → Save and Compile. Address assignment is written to the CP at download time.

Step 2 — Set the CP as a PROFINET/IE Node

The CP 343-1 (Ethernet) appears in HW Config as an Ethernet node. In the Properties dialog, switch to the Properties → Ethernet Interface → General tab and verify the following:

Field Recommended value for first-time setup
MAC address Read-only (factory assigned)
IP address 192.168.0.10
Subnet mask 255.255.255.0
Use router Activated only if the CP must talk to another subnet
PROFINET IO Device / Controller Not used for CP 343-1 Lean; only on the Advanced variant
Time-of-day synchronization Activate if the plant NTP server is reachable; the CP becomes an NTP client

The CP can be assigned its IP address from three sources, in order of priority: (1) configuration in STEP 7, (2) DHCP, (3) factory default (0.0.0.0). For a fixed plant, always assign from STEP 7 so the configuration is reproducible.

Step 3 — Build the Logical Connection in NetPro

After hardware compile, open NetPro (menu Options → NetPro). The S7-300 station appears with its CP 343-1 as an Ethernet node. To add a partner:

  1. Insert a second S7 station, an HMI station, or a third-party node that uses the same Ethernet subnet.
  2. Select the CP 343-1 of the S7-300, right-click the connection table, Insert New Connection.
  3. In the dialog choose the partner node (e.g. an S7-1200 CPU on the same subnet, or a CPU 317 in another S7-300 station).
  4. Select the connection type:
Connection type Typical use TSAP / Port
S7 Connection PG functions, HMI, S7 routing, PUT/GET to another S7 TSAP 01.01 (server) / 02.01 (PG)
ISO-on-TCP Connection Open, vendor-neutral, reliable byte stream between S7 and PC/3rd party TSAP, e.g. 10.01 hex
TCP Connection Free-form byte stream to a PC socket (port number) Local + remote port, e.g. 2000
UDP Connection Lightweight, broadcast-friendly, no handshake Local + remote port

After confirming, NetPro shows the connection with a green/yellow line. Save and compile NetPro (Network → Save and Compile) so the connection ID, partner IP, and local/remote TSAP/port are written into the S7-300 station data.

Step 4 — Download the Configuration to the CPU and CP

  1. In HW Config, click Download to Target → Selected Target Device. The download dialog appears.
  2. If this is the first download, Select Target System → Accessible Nodes must find the CPU on MPI/Profibus. If you only have Ethernet, plug your PC into the same switch as the CP and target the CP's IP directly; the CP will then route the download to the CPU via the backplane.
  3. Select the interface: Ethernet → TCP/IP → Network card of PG/PC.
  4. Enter the CP's IP (192.168.0.10) and press Display. The CP replies with its MAC.
  5. Confirm download. STEP 7 writes the hardware configuration first, then the connection data, then the user program (blocks).
First-time download trap: If the PC cannot reach the CP, check that the firewall on the PC is not blocking TCP/102 (S7) and TCP/34962/34964 (Siemens Discovery). The CP has a small bootstrap web page (Lean: not available, Advanced: yes at http://192.168.0.10) that can confirm the IP is alive without STEP 7.

Step 5 — Call the Communication Blocks in the User Program

The connection made in NetPro exposes an ID (local connection ID) used by the CP blocks in the user program. The three most common S7-300 user-program patterns are listed below.

5.1 S7 Communication: PUT / GET (with partner S7)

Use FB 15 (PUT) and FB 14 (GET) from the Standard Library. These are integrated in every S7-300 CPU and do not require a CP — the CP is just a transport. They are easiest when both sides are Siemens S7.

// STL excerpt: read 10 bytes from partner DB20 starting at byte 0
      CALL  "PUT"
           REQ    :=M0.0        // rising edge triggers send
           ID     :=W#16#0001   // must match NetPro connection ID
           DONE   :=M10.0
           ERROR  :=M10.1
           STATUS :=MW12
           ADDR_1 :=P#DB20.DBX0.0 BYTE 10
           SD_1   :=P#M100.0 BYTE 10
           LEN    :=10

5.2 ISO-on-TCP / TCP with CP 343-1 (lean variants)

The CP requires its own AG_SEND / AG_RECV function blocks (FC 5 / FC 6) for open TCP/ISO transport when no S7 partner is involved. Both are part of the SIMATIC_NET_CP library that ships with STEP 7.

// STL: send 50 bytes to a partner socket
      CALL  "AG_SEND"
           AG    :=W#16#0001   // CP 343-1 logical address from HW Config
           ID    :=1            // connection ID from NetPro
           LEN   :=50
           DONE  :=M20.0
           ERROR :=M20.1
           STATUS:=MW22
           SEND  :=P#DB100.DBX0.0 BYTE 50

On the receive side, AG_RECV (FC 6) pulls bytes from the receive buffer. Always allocate the receive buffer with adequate length (a few hundred bytes is safe for short protocols).

5.3 UDP with CP 343-1

UDP uses AG_SEND (FC 5) and AG_RECV (FC 6) with a connection configured as UDP in NetPro. UDP has no DONE handshake; the receive is edge-driven by the LEN output of AG_RECV transitioning from 0 to a non-zero value.

Step 6 — Configure Time Synchronization (Optional)

The CP 343-1 supports SIMATIC time-of-day and NTP (NTP only on the Advanced variant). To enable NTP on the Advanced CP:

  1. Open HW Config and double-click the CP 343-1 Advanced.
  2. Properties → Time-of-Day Synchronization → NTP mode.
  3. Enter the NTP server address (e.g. 192.168.0.250) and the synchronization interval (default 10 minutes, range 1-1440).
  4. Set the time zone offset. Save and download.

Step 7 — Verify the Connection

Check How to verify Pass criterion
CP firmware/online Online → Accessible Nodes → flash LED of CP CP reachable, SF LED off
CP IP Online → Diagnostics of CP → General IP shows the configured value, MAC matches label
Connection status NetPro → right-click CP → Connection Status Connection "Established"
User program Online → Monitor/Modify → STATUS word of AG_SEND/GET STATUS = W#16#0000 (no error)
PG/OP Online → Accessible Nodes → browse online from second node Partner station visible

LED Diagnosis and Buffer Entries

The CP 343-1 has four status LEDs. Their meaning is identical across the Lean/standard/Advanced variants.

LED Off On (steady) Flashing
SF (red) No fault Group fault (see diagnostic buffer) Boot/firmware update active
BF (red) Link present, no bus fault Physical link down or no partner No Ethernet cable plugged in
RUN (green) No power or CP stopped CP running, connections OK CP startup phase
STOP (yellow) CP running CP stopped; connections refused Hold-down/reset phase

If SF is on, open the S7-300 diagnostic buffer (online) and look for CP entries. Common diagnostic event IDs:

Event ID Meaning Remedy
0xE001 Firmware/HW mismatch (catalog older than CP FW) Update STEP 7 catalog or downgrade CP FW
0xE002 IP address conflict (duplicate IP on the LAN) Change CP IP, audit network
0xE003 No subnet / mask invalid Re-enter mask in HW Config
0xE004 Duplicate station name (PROFINET only) Rename station
0xE005 Connection error (TSAP/port mismatch) Compare NetPro entries to partner
0xE006 Authentication/security block Re-enter password or disable secure_odp if not needed

Common STATUS Words for AG_SEND / AG_RECV

STATUS (hex) Source Meaning
0000 Both Job completed without error
7000 Both No job active, waiting for REQ trigger
8180 AG_SEND Connection ID/AG number does not exist
8183 AG_SEND AG_SEND and AG_RECV are in the wrong order, or REQ edge lost
8184 AG_SEND System error (memory/CP internal)
8185 AG_SEND LEN > max user data (e.g. > 8192 bytes for Lean)
80A1 AG_RECV Connection aborted by partner
80A4 AG_RECV Connection ID / AG number does not exist
80A7 AG_RECV Receive buffer too small; reduce LEN or enlarge buffer
80B4 AG_SEND Connection is being established; wait

Troubleshooting Matrix

Symptom Most likely cause Action
BF LED on, no link Cable/Switch port, wrong port speed (10 vs 100) Swap cable, try another switch port, set CP to auto-negotiate (default)
BF flashing TCP/IP ARP not getting reply Check switch VLAN, ping CP from PC
SF LED on Configuration mismatch Read diagnostic buffer, compare HW Config to online
STATUS 8180 on AG_SEND Connection not in NetPro, or wrong ID Recompile NetPro, check ID
STATUS 80A1 Partner closed the TCP socket Confirm partner PLC/PC application is running
PUT/GET works from HMI but not from PC No S7 license (CP 343-1 standard uses write-protected S7 routes) Use the standard CP 343-1 (not Lean) or buy a routing license
PG cannot find CP PG/PC interface set to MPI/Profibus Set PG/PC interface to TCP/IP, retry
Time jumps after reboot CP not configured as NTP client Enable NTP in CP properties, save, download

Security and Modern Considerations

Firmware on the CP 343-1 family is mature; do not expose an S7-300 CP directly to the public internet or a hostile subnet. Mitigations to apply at commissioning:

  • Use a dedicated plant VLAN with private RFC 1918 addressing.
  • Disable unused services on the CP (e.g. FTP, web server) in HW Config → Properties → Services.
  • Activate the Access Protection password so unauthorized S7 partners cannot be defined.
  • On the Advanced CP, enable the integrated firewall with allow-list of partner IPs.
  • Use S7-1200/1500 or SCALANCE SFPs at the plant boundary; do not terminate the S7-300 CP at the WAN edge.

Field-Commissioning Short List

  1. Verify rack order, slot occupancy, and PS 307 sizing (5 A standard, 10 A for many I/O + CP).
  2. Confirm CP MAC sticker matches HW Config.
  3. Pre-stage IP plan; reserve DHCP exclusions for the CP block.
  4. Compile HW Config → Compile NetPro → Download both.
  5. Check the four CP LEDs, then read CPU diagnostic buffer for any new entries.
  6. Run a test S7 connection (e.g. an HMI tag polling) and watch NetPro Connection Status.
  7. Document the connection IDs, partner IPs, and TSAPs in the cabinet drawing.
  8. Hand off to operations with a network diagram, including switch, VLAN, and the CP's IP.

Where do I find the official CP 343-1 manual?

The current CP 343-1 manual is on the Siemens support portal as entry ID 26100711. Search "CP 343-1 Manual" at support.industry.siemens.com. The S7-300 CPU manual is entry ID 45531122.

Why does the CP 343-1 Lean not show up in the STEP 7 catalog?

Older STEP 7 versions (V5.3 and below) do not include the 6GK7343-1EX30-0XE0 GSD. Install STEP 7 V5.5 SP2 or later, or install the HSP (Hardware Support Package) for the CP from the Siemens online updates.

Can I use TIA Portal instead of STEP 7 V5.x for the S7-300?

Yes. TIA Portal (V13 and newer) supports the S7-300 family for configuration, online diagnostics, and the same communication blocks. The S7-300 PROFINET CPUs (31x-2 PN/DP) work directly; the CP 343-1 family is also cataloged, though Siemens recommends newer S7-1200/1500 for new projects.

What is the difference between an S7 connection and an ISO-on-TCP connection?

S7 connections are Siemens-proprietary, work only between S7 stations, and ride on top of ISO-on-TCP (TSAP addressing). ISO-on-TCP is the open RFC 1006 transport; any device that speaks TCP can talk to a CP 343-1 ISO-on-TCP partner if it knows the TSAP and byte layout. Use S7 for HMI and S7-S7, use ISO-on-TCP for cross-vendor integration.

My AG_SEND STATUS reads 8185 (LEN too big) — what is the maximum user data length?

For the CP 343-1 Lean and standard, AG_SEND/AG_RECV support up to 8192 bytes per call. The CP 343-1 Advanced allows up to 32767 bytes. For larger payloads, use BSEND/BRCV (FB 12/FB 13) on the S7-400 or, for S7-300, segment manually with multiple AG_SEND calls.

Back to blog