Configuring WinCC v7.4 for S7-300 and S7-1200 Communication

David Krause12 min read
SiemensTutorial / How-toWinCC
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Configuring WinCC v7.4 for S7-300 and S7-1200 Communication in the Same Project

WinCC V7.4 is a 32-bit SCADA/HMI runtime that natively supports multiple Siemens PLC families in a single project. The most common brownfield configuration pairs an existing SIMATIC S7-300 on MPI/ PROFIBUS with a newer SIMATIC S7-1200 on TCP/IP Ethernet. This article documents the channel architecture, the Set PG/PC Interface symbolic device model, and the field-proven procedure for running both drivers in parallel without bus contention or loss of one PLC's connection.

Engineering intent. Two different WinCC channel DLLs are used: SIMATIC Protocol Suite (legacy MPI/PROFIBUS channel) for the S7-300, and SIMATIC S7-1200, S7-1500 Channel (the S7COM / TCP-IP channel) for the S7-1200. Because each channel selects its own access point in its connection properties, both can coexist on the same engineering station.

1. Architecture Overview

WinCC V7.4 is a multichannel container. The Tag Management tree under "WinCC Explorer" allows multiple Channel Units (drivers) to be added, each maintaining its own:

  • Connection table (logical PLCs)
  • Process tag namespace
  • Acquisition cycle, timeout, and retry behavior
  • Access point reference resolved at runtime via Set PG/PC Interface

The two channels relevant to this scenario are summarized below.

Channel Driver DLL Bus / Protocol Typical S7 Use Hardware Adapter
SIMATIC Protocol Suite → MPI S7MCI / S7Proto MPI 187.5 kbit/s to 12 Mbit/s S7-300 / S7-400 CPU PN/DP CP 5611, CP 5612, CP 5711, PC Adapter USB A2
SIMATIC Protocol Suite → TCP/IP S7Proto ISO-on-TCP (RFC 1006), port 102 S7-300/400 with CP or PN CPU Standard Ethernet NIC
SIMATIC S7-1200, S7-1500 Channel → TCP/IP S7Com S7Comm (TCP port 102) S7-1200 / S7-1500 Standard Ethernet NIC

For the S7-1200 path, the S7-1200/1500 Channel is the supported driver. The legacy SIMATIC Protocol Suite can technically be pointed at an S7-1200 with limited slot/rack options, but the modern S7-1200/1500 Channel is the documented, supported approach.

2. Prerequisites

  1. WinCC V7.4 SP1 or later (Update 14 / 15 recommended). Verify in WinCC Explorer → Help → About. The S7-1200/1500 Channel was first packaged with WinCC V7.3 and improved in V7.4.
  2. STEP 7 V5.5 SP4 / HF11 (for MPI configuration of the S7-300) or STEP 7 V13+ / TIA Portal (for S7-1200 / S7-1500).
  3. S7-1200 CPU firmware ≥ V4.0 if the Optimized Block Access is disabled or if symbolic access via DB is desired; firmware ≥ V4.2 is recommended for full S7-1200/1500 Channel compatibility.
  4. Hardware:
    • Siemens CP 5611 (PCIe), CP 5612, CP 5711 (USB), or PC Adapter USB A2 for MPI/PROFIBUS to the S7-300.
    • Standard 100/1000 Mbit/s Ethernet NIC for the S7-1200 connection. Intel, Broadcom, and Realtek chipsets are validated.
  5. S7-1200 firmware configuration: the Permit access with PUT/GET communication checkbox must be enabled in TIA Portal → Device Properties → Protection & Security → Connection mechanisms. Without this, the S7-1200 will reject WinCC reads/writes with SF=0x31 access errors.
  6. Windows user rights: the WinCC Runtime must run as a user with Administrator privileges for Set PG/PC Interface modifications, or the access point must be pre-configured before runtime launch.
Critical S7-1200 step. TIA Portal default projects starting with firmware V4.x have Permit access with PUT/GET disabled. This is the single most common reason for "cannot connect" faults on a freshly deployed S7-1200. Always verify the checkbox state before commissioning.

3. PG/PC Interface Model and Symbolic Access Points

Windows does not allow two applications (or two channels within one application) to bind to the same physical adapter using the same access point name unless they cooperate via shared access. Siemens solves this with the Set PG/PC Interface tool (start menu entry SIMATIC → Set PG/PC Interface), which maintains a registry of symbolic device names mapped to physical adapters.

Every WinCC channel connection parameter dialog has an Access Point dropdown. The dropdown does not list network cards — it lists these symbolic names. Behind each symbolic name, Set PG/PC Interface records which real device is used.

Symbolic Name Default Use Physical Adapter Bound
S7ONLINE STEP 7, legacy channels Last selected (MPI/TCP/PROFIBUS)
CP5611.MPI Direct CP 5611 access CP 5611 (ASIX) — MPI
CP_xxx_TCPIP S7-1200/1500 channel Ethernet NIC — TCP/IP
CP_H1_1: Industrial Ethernet (ISO) Ethernet NIC — ISO protocol

The trick that makes simultaneous S7-300 + S7-1200 access work is that two different symbolic access points are bound to two different physical adapters. The MPI access point can stay bound to the CP 5611, while a new TCP/IP access point is bound to the Ethernet NIC. The two channels then resolve these independently.

4. Step-by-Step Configuration

4.1 Open Set PG/PC Interface

  1. Close WinCC Explorer and the WinCC Runtime.
  2. Launch Start → SIMATIC → Set PG/PC Interface.
  3. Confirm the upper dropdown shows "S7ONLINE (STEP 7)" as the access point of the application.

4.2 Bind S7-300 / MPI Access Point

  1. For S7ONLINE select "CP5611(MPI)" (or your CP variant). Click Diagnostics to confirm the CP 5611 is reporting node 0/0/0 to 0/0/31. Click OK.
Note on PC Adapter USB A2. If the field station uses a PC Adapter USB A2 instead of a CP card, select "PC Adapter (MPI)" or "PC Adapter (Auto)". Auto mode negotiates MPI/PROFIBUS/TCP from the cable, which is convenient when the bus type changes during commissioning.

4.3 Create a New Symbolic Access Point for the S7-1200

  1. In Set PG/PC Interface, click "Add/Remove" or scroll to an unused entry.
  2. Create a new symbolic name, e.g. S7_1200_ACCESS or use the built-in CP5611.TCPIP style entry CP_LAN_1.
  3. Assign the standard Ethernet NIC (e.g. Intel(R) I210 Gigabit — TCP/IP). Click Diagnostics → Test to confirm the adapter pings the S7-1200 CPU IP address.

4.4 Verify the S7-300 Path Still Works

  1. Re-open WinCC Explorer, start the Runtime, and check WinCC Channel Diagnosis (start → WinCC → Channel Diagnosis). The MPI connection should still report "OK".
  2. You have not disturbed the S7-300 path — the access point S7ONLINE still resolves to CP 5611.

4.5 Add the S7-1200 Channel in WinCC

  1. In Tag Management, right-click and choose Add New Driver → SIMATIC S7-1200, S7-1500 Channel.
  2. Right-click OMS+ (or TCP/IP) and choose New Connection.
  3. In the connection dialog, set:
    • Name: descriptive (e.g. S71200_Shopfloor).
    • Access Point: select the symbolic name you created in 4.3 (e.g. S7_1200_ACCESS).
    • IP Address: the S7-1200 CPU IP (e.g. 192.168.0.10).
    • Connection Type: S7Comm (default).
    • Slot / Rack: not required for S7-1200/1500.
  4. Click OK.

4.6 Add the S7-300 Channel (if not already present)

  1. Tag Management → Add New Driver → SIMATIC Protocol Suite.
  2. Open MPI → right-click → New Connection.
  3. Set Access Point to S7ONLINE (which is already bound to the CP 5611).
  4. Set the MPI node address of the S7-300 CPU (e.g. MPI = 2).
  5. Set Rack 0, Slot 2 for an S7-300 CPU 31x PN/DP.

4.7 Define Tags

Tags reference address strings unique to the channel:

PLC Channel Address Syntax Example
S7-300 SIMATIC Protocol Suite → MPI <DB><Byte.Bit> or M<Byte> DB10,DBD0, MW20, I0.0
S7-1200 SIMATIC S7-1200, S7-1500 Channel Same syntax; DB absolute only (no symbolic tag in WinCC < V7.5) DB20,DBW4, QB0
Symbolic vs. absolute on S7-1200. WinCC V7.4 supports only absolute addressing on the S7-1200/1500 channel. The symbolic tag list export feature arrived in WinCC V7.5. For V7.4, you must re-enter tag addresses manually or import a CSV. TIA Portal's PLC tag table → Export → WinCC V7.4 compatible CSV can speed this up.

5. Verification Procedure

  1. Channel Diagnosis — Open Start → SIMATIC → WinCC → Channel Diagnosis. Both connections should show green status with active cycle counters.
  2. Tag Simulator — Use WinCC Explorer → Tools → Tag Simulation. Force a tag on each PLC and observe the runtime value.
  3. APLog / WinCC Syslog — Inspect C:\Program Files (x86)\Siemens\Automation\WinCC\Diagnose\WinCC_Sys_01.log. Look for channel-initialization lines and any WCCRT:Channel:Error entries.
  4. S7-300 side — Use STEP 7 → PLC → Monitor/Modify or the CP 5611's MPI diagnostics to confirm bus load stays < 50%.
  5. S7-1200 side — TIA Portal → Online → Accessible Devices should list the CPU reachable from the engineering PC over the same Ethernet NIC.
  6. End-to-end — Toggle a discrete output on the S7-1200 and verify it appears in a WinCC screen value display. Toggle an S7-300 input and confirm the same in a separate screen widget.

6. Troubleshooting Matrix

Symptom Likely Cause Diagnostic Fix
S7-300 drops, S7-1200 works Set PG/PC Interface S7ONLINE accidentally rebound to TCP/IP Set PG/PC Interface → highlight S7ONLINE Rebind to CP 5611 MPI; click Test
S7-1200 drops, S7-300 works Access point bound to wrong NIC (e.g. virtual VPN) ipconfig /all + Set PG/PC diagnostics Bind the symbolic access point to the physical Ethernet NIC
Both fail intermittently NIC power management / Windows firewall Device Manager → Power Management → uncheck "Allow PC to turn off"; wf.msc Disable power saving; add firewall rules for TCP 102
S7-1200 channel returns 0x0310 access error PUT/GET not permitted on S7-1200 TIA Portal → Device Properties → Protection Enable Permit access with PUT/GET and re-download project
S7-300 MPI STATUS: 0x0010 Wrong rack/slot or duplicate MPI address STEP 7 → PG/PC → Diagnostics → Read Set Rack 0, Slot 2 for CPU 31x; verify MPI = 2 unique
Runtime slow on both channels Acquisition cycle set to 100 ms with thousands of tags Channel Diagnosis → Cycle counter Raise cycle to 500 ms for non-critical tags; use multiplexing
WinCC only loads S7-300 tags, S7-1200 tags greyed out Wrong channel name in tag (e.g. "MPI" instead of "OMS+") Tag properties → Channel unit dropdown Re-enter tag address; verify connection assignment

7. Performance & Cycle Tuning

WinCC's default acquisition cycle is 1 second. For each S7 connection, the channel DLL maintains a request queue sized by Request Buffer in the connection properties. Recommended baselines for a V7.4 SCADA on Windows 10 IoT LTSC x64:

Parameter S7-300 MPI S7-1200 TCP
Acquisition cycle (slow tags) 1000 ms 1000 ms
Acquisition cycle (fast tags < 50) 250 ms 100 ms
Timeout 3000 ms 3000 ms
Max simultaneous requests 4 8
Bus load target < 50% N/A (TCP)
CPU load. The S7-1200/1500 Channel uses approximately 4–6 % of a single CPU core per 1000 tags at 1 s cycle on WinCC V7.4. Cores < 4 on the SCADA host will become the bottleneck before the bus does. Confirm at least 8 GB RAM and a quad-core CPU for projects with 5000+ tags across both PLCs.

8. Coexistence with STEP 7 and TIA Portal

Because the same physical Ethernet NIC may be used by the engineer for both STEP 7 V5.5 (S7-300) and TIA Portal (S7-1200), the access point S7ONLINE cannot be reliably bound to "the right" adapter. The recommended field practice is to always use a dedicated symbolic name for the S7-1200/1500 Channel and never assume S7ONLINE = TCP/IP. This avoids the classic "communication with S7-300 broke after I added the S7-1200" complaint.

9. Migration to TIA Portal and WinCC Unified

WinCC V7.4 is in maintenance phase. Newer deployments are encouraged to move to WinCC Unified in TIA Portal, which collapses the channel-DLL model into the project's device list. As a transition aid, Siemens documentation distinguishes three unified channel families; the equivalent of the V7.4 S7-300 + S7-1200 split is documented at Communicating with SIMATIC S7-300/400 (RT Unified). That page lists the permitted data areas, the connection resource budget per CPU, and the maximum number of simultaneous HMI connections — values that differ from the V7.4 limits and should be re-validated before a Unified migration.

10. Common Field Pitfalls

  1. Firewall blocking TCP 102. The Windows Defender Firewall is on by default. The S7-1200/1500 Channel needs inbound + outbound TCP 102 between the SCADA and the CPU. Create a rule once.
  2. Dual-stack IP conflict. If the NIC has both a 192.168.0.x (plant) and a 10.0.0.x (office) address, Set PG/PC may bind to the wrong subnet. Use the Advanced TCP/IP Settings to confirm metric order.
  3. S7-1200 with Optimized Block Access. Absolute DB access in WinCC V7.4 fails silently on optimized DBs with "Data consistency check failed". In TIA Portal, uncheck "Optimized Block Access" for DBs that WinCC reads.
  4. CP 5611 driver mismatch. The CP 5611 must use the Siemens SIMATIC NET driver, not a generic ASIX PCIe driver. If Windows Update replaced it, WinCC will fail to initialize. Reinstall SIMATIC NET from the WinCC DVD's "Tools" folder.
  5. Mixed firmware on S7-1200. CPUs at V4.0 allow PUT/GET only with the checkbox enabled. V4.2+ allows fine-grained DB-level access control. Match firmware to your security policy.

11. Commissioning Checklist

  • [ ] S7-300 CPU MPI address verified with STEP 7 PG/PC Diagnostics.
  • [ ] CP 5611 (or equivalent) installed; Siemens SIMATIC NET driver active.
  • [ ] S7ONLINE symbolic access point bound to CP 5611 MPI.
  • [ ] S7-1200 CPU Permit access with PUT/GET enabled.
  • [ ] Standard Ethernet NIC bound to a new symbolic name (e.g. CP_LAN_1).
  • [ ] Windows Firewall rule for TCP 102 (inbound + outbound) created.
  • [ ] Optimized Block Access disabled for any DB read by WinCC.
  • [ ] Channel Diagnosis shows both connections green.
  • [ ] Tag Simulator forces a value on each PLC and updates on the SCADA screen.
  • [ ] Runtime & logging stable for 24 h soak test.

12. Frequently Asked Questions

Can I add the SIMATIC S7-1200, S7-1500 Channel to a WinCC V7.4 project that already uses SIMATIC Protocol Suite for an S7-300?

Yes. The two channel DLLs are independent. Add SIMATIC S7-1200, S7-1500 Channel under Tag Management, create a new connection, and assign it a distinct symbolic access point (e.g. CP_LAN_1) bound to the Ethernet NIC. The S7-300 path through S7ONLINE → CP 5611 remains untouched.

Will changing Set PG/PC Interface break the S7-300 MPI connection?

Not if the access point assigned to the SIMATIC Protocol Suite's MPI connection is not the one you are modifying. The S7ONLINE access point is just one entry in the registry. You can add a separate symbolic name (e.g. CP_5611_MPI) bound to the CP 5611, and a different symbolic name bound to the Ethernet NIC. The two channels resolve their access points independently.

What port does the S7-1200/1500 Channel use?

TCP 102 (S7Comm). The S7-1200/1500 Channel does not need S7-PCT or any additional licensing; the connection is opened directly by the channel DLL. Ensure the Windows Firewall has an inbound + outbound allow rule for TCP 102 between the WinCC host and the S7-1200 CPU.

Does WinCC V7.4 support symbolic tag names on the S7-1200?

No. V7.4 supports only absolute DB addressing (e.g. DB20,DBW4). Symbolic tag import was added in WinCC V7.5 via the TIA Portal Export to WinCC function. If you must stay on V7.4, export a CSV from the TIA Portal PLC tag table and import it into WinCC's tag database manually.

Why does my S7-1200 connection succeed in Channel Diagnosis but tags stay 0?

Three common causes: (1) Optimized Block Access is enabled on the DB, blocking absolute addressing; (2) the address range exceeds the DB size; (3) the S7-1200 firmware is V4.0 with Permit access with PUT/GET disabled. Check the TIA Portal project first, then re-download to the CPU.

What is the maximum number of WinCC connections to a single S7-1200?

An S7-1200 CPU V4.x supports up to 8 HMI/PG connections for S7Comm PUT/GET (connection resource 1). Higher connection counts require the S7-1200/1500 firmware's connection mechanisms setting to be expanded, or moving to an S7-1500 if more than 32 simultaneous connections are needed.

Back to blog