What S7 Routing Is and What It Is Not
S7 routing is the transfer of data beyond a single S7 subnet boundary. It allows a programming device (PG/PC), HMI engineering station, or Web client to reach a target station that sits on a different subnet, by traversing a SIMATIC CPU that has physical connections to both subnets. The traversing CPU is referred to as the gateway CPU, the router CPU, or simply the bridge.
For a mixed PROFINET/PROFIBUS network, S7 routing is the standard mechanism STEP 7 (TIA Portal) and WinCC use to download projects, run online diagnostics, refresh HMI tags on a remote panel, and access Web servers of a CPU on another subnet.
For the topology described in this article, the only viable routing path is:
- PG/PC (engineering station) → PROFINET subnet A → S7-317F PN/DP (gateway) → PROFIBUS subnet B → HMI TP700 Comfort (DP master) or other DP device
Reference: Overview of the routing mechanisms of S7-1500 CPUs (Siemens TIA documentation cloud)
Reference Topology: S7-1511, S7-317F, and TP700 Comfort
The configuration discussed in this article uses three devices. Only the S7-317F PN/DP has a physical interface in both subnets and is therefore the only module that can act as a routing gateway.
| Position | Module | Typical Order Number | Interface | Subnet |
|---|---|---|---|---|
| Controller 1 | SIMATIC S7-1511-1 PN | 6ES7511-1AK02-0AB0 | X1 (PN/IE) | PROFINET subnet A |
| Gateway CPU | SIMATIC S7-317F-2 PN/DP | 6ES7317-2EK14-0AB0 | X1 (PN), X2 (DP) | Subnets A and B |
| Operator panel | SIMATIC TP700 Comfort | 6AV2124-1GC01-0AX0 | X1 (PN), X2 (DP) | Subnet A or subnet B |
Inline topology diagram (logical view):
The S7-1511-1 PN has a single PROFINET port (X1). The TP700 Comfort has one PROFINET (X1) and one PROFIBUS (X2) port. The S7-317F PN/DP is the only module that bridges the two physical media. Routing only works through the S7-317F.
Hardware and Software Requirements
- STEP 7 (TIA Portal) V16 minimum. V17 or V18 recommended for current firmware support and for working with the SIMATIC S7-1500 CPU 1511-1 PN V2.9 firmware.
- S7-1500 CPU firmware V2.6 minimum. V2.9 recommended for the 6ES7511-1AK02-0AB0 variant.
- S7-300F CPU firmware V3.3 minimum (for the 6ES7317-2EK14-0AB0 variant). Older firmware revisions of the 6ES7317-2EK13-0AB0 also support S7 routing but are limited to V3.2 features.
- TP700 Comfort firmware V14.0.1 minimum; V16 or higher recommended for use with TIA Portal V17/V18.
- PG/PC interface: standard PROFINET-capable Ethernet adapter.
- PROFIBUS cable with proper termination on both ends. The DP master port of the S7-317F (X2) is not terminated internally; the connector at the start and end of the segment must have terminating resistors switched ON.
Reference: S7 Routing FAQ (Siemens Support entry 59192925)
Subnet ID: The Core Constraint
Every S7 subnet in a STEP 7 project has a unique 32-bit subnet identifier (subnet ID), expressed in hexadecimal form, for example 0000_0001 for the first PROFINET subnet, 0000_0002 for the second, and so on. The subnet ID is assigned automatically when STEP 7 creates the subnet, but it can be edited manually in the subnet properties.
When STEP 7 builds the SDB (System Data Block) and downloads it to a CPU, the CPU stores the subnet IDs of all subnets it can physically reach. When a routed request arrives, the CPU looks up the destination subnet ID and forwards the request on the matching interface.
For S7 routing to work end-to-end, the gateway CPU must have been downloaded with a project that already contains the destination subnet ID. In single-project engineering (one TIA Portal project containing all three devices), this is automatic: every device is downloaded with the same set of subnet IDs.
Step-by-Step Configuration in TIA Portal
Follow this sequence to make the S7-317F act as a routing gateway between the PROFINET subnet (S7-1500 side) and the PROFIBUS subnet (HMI/field side).
- Create a new TIA Portal project. Switch to Devices & Networks and add the three devices: S7-1511-1 PN (6ES7511-1AK02-0AB0), S7-317F PN/DP (6ES7317-2EK14-0AB0), and TP700 Comfort (6AV2124-1GC01-0AX0).
- Define two subnets. Right-click the PROFINET interface of the S7-1511-1 PN, select Add new subnet, name it
PN_HMI. Right-click the PROFIBUS interface of the S7-317F, select Add new subnet, name itDP_Field. - Connect the S7-317F PN/DP's X1 (PN/IE) port to subnet
PN_HMI. Set the IP to192.168.0.20/24. The S7-1500's X1 stays on the same subnet with IP192.168.0.10/24. The TP700 Comfort's X1 (if used on PROFINET) joins the same subnet with IP192.168.0.30/24. - Connect the S7-317F PN/DP's X2 (DP) port to subnet
DP_Field. Set the PROFIBUS address of the CPU to2. Connect the TP700 Comfort's X2 (DP) port to the same PROFIBUS subnet, address3. Disable the terminating resistor on the CPU's DP connector (the CPU is in the middle of the segment, not at the end). - Open the device view of the S7-317F PN/DP. STEP 7 will show the CPU as a routing candidate because it has interfaces in two different subnets. There is no separate "Enable routing" checkbox to set; routing is implicit in the topology once the project is downloaded.
- Compile the project. In the project tree, right-click the project root and select Compile > Hardware (rebuild all). Resolve any compile errors before continuing.
- Download the project to the S7-317F PN/DP first. Use a direct Ethernet cable from the PG/PC to the S7-317F's X1 port to perform the initial download, then reconnect to the network switch for subsequent downloads.
- Download the project to the S7-1511-1 PN and the TP700 Comfort. All three devices now share identical subnet IDs because they were downloaded from the same project.
- From the PG/PC, run Online > Accessible Devices. STEP 7 should list the S7-317F, the S7-1500, and the TP700 Comfort, even though the HMI sits on a different physical medium.
HMI Integration: What S7 Routing Can and Cannot Do
A common misconception is that S7 routing lets the TP700 Comfort talk to the S7-1500 by traversing the S7-317F. It does not. S7 routing only carries engineering and operator traffic that originates from a PG/PC, not runtime HMI-to-PLC tag traffic.
HMI-to-PLC connections are direct S7 connections, configured in the HMI device's Connections editor. The HMI must reach the target CPU on the configured subnet. Three options are available for the TP700 Comfort to access S7-1500 tags:
- Connect the TP700 Comfort's X1 (PROFINET) port to subnet
PN_HMIand configure a direct S7 connection to the S7-1500. The HMI can then read and write tags without any S7 routing. This is the simplest and recommended topology. - Configure the HMI to talk to the S7-317F on PROFIBUS, and use S7-317F PUT/GET to the S7-1500 to mirror the required tags. The HMI then reads the mirrored tags from the S7-317F. This works but adds engineering effort and an extra hop.
- Use PROFINET on the HMI for the S7-1500 connection, and reserve the HMI's DP port for a remote I/O station or a third-party DP device. This keeps the HMI runtime traffic on PROFINET and limits DP to the field.
S7 routing remains valuable even when option 1 is used: the PG/PC can still download the HMI project, refresh HMI tags in WinCC, and run online diagnostics on the S7-1500 across the S7-317F gateway.
Cross-Project Routing
If the S7-1500 and S7-317F live in different TIA Portal projects (multi-project or inter-departmental engineering), S7 routing only works when the subnet ID of the connecting subnet is identical in both projects. STEP 7 does not synchronize subnet IDs across separate projects; the engineer must align them manually.
- Open the first project, navigate to Devices & Networks > Network view > Subnets, right-click the connecting PROFINET subnet (for example,
PN_HMI), and read the subnet ID. It is a 32-bit hexadecimal value displayed in the properties dialog under Subnet ID. - Open the second project, navigate to the same PROFINET subnet, and overwrite the subnet ID with the value copied from the first project.
- Re-compile both projects and re-download all affected CPUs.
- From the engineering PG/PC, run Online > Accessible Devices across the network. Both subnets should now resolve correctly.
Reference: Siemens S7 Routing FAQ (entry 59192925)
Commissioning and Verification Procedure
- Power up the S7-317F first, then the S7-1511-1 PN, then the TP700 Comfort. Verify the SF and BF LEDs on the S7-317F are OFF after the boot cycle.
- From the PG/PC, ping
192.168.0.10(S7-1500) and192.168.0.20(S7-317F PN side) to confirm layer-2/IP connectivity on subnet A. - Open TIA Portal, select the project, and choose Online > Accessible Devices. STEP 7 will scan subnet A. The S7-1500 and S7-317F should both appear.
- Right-click the S7-317F and select Go online. The online diagnostics view should load. Check the diagnostic buffer for any boot-time errors. The S7-317F should report a clean boot.
- With the S7-317F online, right-click the TP700 Comfort in the project tree and select Go online. STEP 7 will attempt a routed connection through the S7-317F. A successful connection proves S7 routing is working end-to-end. If the connection fails, the diagnostic buffer of the S7-317F will contain the routing error code (see the troubleshooting matrix below).
- Repeat for the S7-1500. If the S7-1500 is reachable across the S7-317F from a PG/PC that is on a different subnet, S7 routing is fully functional.
- Open the HMI runtime on the TP700 Comfort. Verify that all configured tags show current values. The HMI runtime connection is a separate path from the engineering routing, so both must be validated.
Troubleshooting Matrix
| Symptom | Likely Cause | Remediation |
|---|---|---|
| Online diagnostic: "Subnet ID does not match" | Gateway CPU was downloaded with a project that does not include the destination subnet ID | Re-download the S7-317F with the current project; verify subnet IDs are identical across all participating projects |
| Accessible Devices does not list the TP700 Comfort across the S7-317F | S7-317F firmware too old, or DP master not active on the subnet | Upgrade S7-317F firmware to V3.3 or higher; verify the DP master (X2) is configured and the bus is terminated |
| HMI runtime shows "Connection partner not reached" on S7-1500 | HMI connection misconfigured to a remote CPU that requires S7 routing | Add a direct PROFINET connection from the HMI's X1 port to the S7-1500, or use the S7-317F as a data hub with PUT/GET |
| BF (bus fault) LED lit on S7-317F X2 (DP) | PROFIBUS termination missing or duplicate address | Enable terminating resistors on the first and last DP connectors only; verify all PROFIBUS addresses are unique in the segment |
| PG/PC can ping both CPUs but Accessible Devices shows only the local subnet | PC/PG interface is set to a single subnet; routing table on the engineering station not aware of the second subnet | In Set PG/PC Interface, select the S7ONLINE access point and the network adapter; check that the routing path is enabled in Online > Accessible Devices > Options |
| Step 7 reports "Routing not possible" for the S7-1500 across the S7-317F | Cross-project subnet ID mismatch | Open both projects, copy the subnet ID from the connecting subnet in the first project to the second, recompile, redownload |
| HMI tags stay greyed out in WinCC online | HMI is online through routed path but the S7 connection is to the wrong CPU | Verify the HMI connection target IP/address matches the actual CPU; the HMI may be reaching a different CPU on the routed path |
Field-Proven Notes and Edge Cases
PROFINET and PROFIBUS cannot share a single routing entry. The S7-317F must be on both physical media. If the S7-317F is replaced by an S7-300 CPU without an integrated DP port, you must add a CP 343-5 or an IM 153 to bridge PROFIBUS, and the S7 routing configuration grows accordingly.
Safety-relevant routing (S7-300F) has the same topology requirements as standard S7 routing. The S7-317F is a fail-safe CPU, but the S7 routing function is not safety-relevant. Routing S7-300F does not affect the F-runtime group; it is a standard communication service.
S7 routing is bound to the project that the gateway CPU was downloaded from. If you change the subnet structure in the project (rename a subnet, change an IP, add a station), you must re-download the gateway CPU. Downloading only the affected station is not enough for routed access; the gateway CPU's SDB must be regenerated.
Web server access across the gateway works the same as PG/PC access. The S7-1500's integrated Web server can be opened in a browser by addressing http://192.168.0.10 from the PG/PC; the S7 routing mechanism does not interfere with Web traffic because the Web request uses the same routed S7 connection.
PROFINET IO and S7 routing share the same physical interface on the S7-317F. PROFINET IO devices on subnet A will continue to communicate with the S7-317F as a PROFINET IO controller (or device) even while S7 routing is active. Routing is a separate logical channel and does not consume PROFINET IO bandwidth.
Multiple engineering stations can route through the same gateway. Any PG/PC on subnet A can use the S7-317F to reach stations on subnet B. The gateway CPU does not enforce a single-engineering-station limit. However, only one engineering station can have a write session to a given CPU at a time.
FAQ
Does S7 routing work between PROFINET and PROFIBUS?
Yes. Any S7-300/400 or S7-1500 CPU that has physical interfaces in both subnets can act as a routing gateway. The S7-317F-2 PN/DP is the standard module for mixed PN/DP routing and supports firmware V3.3 or higher.
Can the TP700 Comfort route through the S7-317F to talk to the S7-1500?
No. S7 routing only carries PG/PC, Web, and engineering traffic. HMI runtime tag traffic is a direct S7 connection between the HMI and a single CPU. Connect the TP700 Comfort's PROFINET port to the same subnet as the S7-1500, or use PUT/GET on the S7-317F to mirror tags from the S7-1500 to the HMI.
What firmware version of the S7-317F is required for S7 routing?
Firmware V3.3 or higher is required for the 6ES7317-2EK14-0AB0 variant. Older firmware revisions of the 6ES7317-2EK13-0AB0 also support S7 routing but only up to the feature set of V3.2.
Do subnet IDs need to match in cross-project routing?
Yes. When the gateway CPU lives in a different TIA Portal project from the engineering station, the subnet ID of the connecting subnet must be set to the same 32-bit hexadecimal value in both projects. STEP 7 will not synchronize this automatically.
Why is the PG/PC online connection failing even though ping works?
Ping uses ICMP and does not exercise S7 routing. Use TIA Portal's Online > Accessible Devices function to scan the entire routed network. A successful accessible device scan that returns the S7-1500 or TP700 Comfort across the S7-317F confirms S7 routing is working.