Configuring WinCC v7.4 for S7-300 and S7-1200 Communication in the Same Project
WinCC V7.4 is a 32-bit SCADA/HMI runtime that natively supports multiple Siemens PLC families in a single project. The most common brownfield configuration pairs an existing SIMATIC S7-300 on MPI/ PROFIBUS with a newer SIMATIC S7-1200 on TCP/IP Ethernet. This article documents the channel architecture, the Set PG/PC Interface symbolic device model, and the field-proven procedure for running both drivers in parallel without bus contention or loss of one PLC's connection.
SIMATIC Protocol Suite (legacy MPI/PROFIBUS channel) for the S7-300, and SIMATIC S7-1200, S7-1500 Channel (the S7COM / TCP-IP channel) for the S7-1200. Because each channel selects its own access point in its connection properties, both can coexist on the same engineering station.1. Architecture Overview
WinCC V7.4 is a multichannel container. The Tag Management tree under "WinCC Explorer" allows multiple Channel Units (drivers) to be added, each maintaining its own:
- Connection table (logical PLCs)
- Process tag namespace
- Acquisition cycle, timeout, and retry behavior
- Access point reference resolved at runtime via Set PG/PC Interface
The two channels relevant to this scenario are summarized below.
| Channel | Driver DLL | Bus / Protocol | Typical S7 Use | Hardware Adapter |
|---|---|---|---|---|
| SIMATIC Protocol Suite → MPI | S7MCI / S7Proto | MPI 187.5 kbit/s to 12 Mbit/s | S7-300 / S7-400 CPU PN/DP | CP 5611, CP 5612, CP 5711, PC Adapter USB A2 |
| SIMATIC Protocol Suite → TCP/IP | S7Proto | ISO-on-TCP (RFC 1006), port 102 | S7-300/400 with CP or PN CPU | Standard Ethernet NIC |
| SIMATIC S7-1200, S7-1500 Channel → TCP/IP | S7Com | S7Comm (TCP port 102) | S7-1200 / S7-1500 | Standard Ethernet NIC |
For the S7-1200 path, the S7-1200/1500 Channel is the supported driver. The legacy SIMATIC Protocol Suite can technically be pointed at an S7-1200 with limited slot/rack options, but the modern S7-1200/1500 Channel is the documented, supported approach.
2. Prerequisites
- WinCC V7.4 SP1 or later (Update 14 / 15 recommended). Verify in WinCC Explorer → Help → About. The S7-1200/1500 Channel was first packaged with WinCC V7.3 and improved in V7.4.
- STEP 7 V5.5 SP4 / HF11 (for MPI configuration of the S7-300) or STEP 7 V13+ / TIA Portal (for S7-1200 / S7-1500).
- S7-1200 CPU firmware ≥ V4.0 if the Optimized Block Access is disabled or if symbolic access via DB is desired; firmware ≥ V4.2 is recommended for full S7-1200/1500 Channel compatibility.
-
Hardware:
- Siemens CP 5611 (PCIe), CP 5612, CP 5711 (USB), or PC Adapter USB A2 for MPI/PROFIBUS to the S7-300.
- Standard 100/1000 Mbit/s Ethernet NIC for the S7-1200 connection. Intel, Broadcom, and Realtek chipsets are validated.
-
S7-1200 firmware configuration: the Permit access with PUT/GET communication checkbox must be enabled in TIA Portal → Device Properties → Protection & Security → Connection mechanisms. Without this, the S7-1200 will reject WinCC reads/writes with
SF=0x31access errors. - Windows user rights: the WinCC Runtime must run as a user with Administrator privileges for Set PG/PC Interface modifications, or the access point must be pre-configured before runtime launch.
3. PG/PC Interface Model and Symbolic Access Points
Windows does not allow two applications (or two channels within one application) to bind to the same physical adapter using the same access point name unless they cooperate via shared access. Siemens solves this with the Set PG/PC Interface tool (start menu entry SIMATIC → Set PG/PC Interface), which maintains a registry of symbolic device names mapped to physical adapters.
Every WinCC channel connection parameter dialog has an Access Point dropdown. The dropdown does not list network cards — it lists these symbolic names. Behind each symbolic name, Set PG/PC Interface records which real device is used.
| Symbolic Name | Default Use | Physical Adapter Bound |
|---|---|---|
S7ONLINE |
STEP 7, legacy channels | Last selected (MPI/TCP/PROFIBUS) |
CP5611.MPI |
Direct CP 5611 access | CP 5611 (ASIX) — MPI |
CP_xxx_TCPIP |
S7-1200/1500 channel | Ethernet NIC — TCP/IP |
CP_H1_1: |
Industrial Ethernet (ISO) | Ethernet NIC — ISO protocol |
The trick that makes simultaneous S7-300 + S7-1200 access work is that two different symbolic access points are bound to two different physical adapters. The MPI access point can stay bound to the CP 5611, while a new TCP/IP access point is bound to the Ethernet NIC. The two channels then resolve these independently.
4. Step-by-Step Configuration
4.1 Open Set PG/PC Interface
- Close WinCC Explorer and the WinCC Runtime.
- Launch Start → SIMATIC → Set PG/PC Interface.
- Confirm the upper dropdown shows "S7ONLINE (STEP 7)" as the access point of the application.
4.2 Bind S7-300 / MPI Access Point
- For
S7ONLINEselect "CP5611(MPI)" (or your CP variant). Click Diagnostics to confirm the CP 5611 is reporting node 0/0/0 to 0/0/31. Click OK.
4.3 Create a New Symbolic Access Point for the S7-1200
- In Set PG/PC Interface, click "Add/Remove" or scroll to an unused entry.
- Create a new symbolic name, e.g.
S7_1200_ACCESSor use the built-inCP5611.TCPIPstyle entryCP_LAN_1. - Assign the standard Ethernet NIC (e.g. Intel(R) I210 Gigabit — TCP/IP). Click Diagnostics → Test to confirm the adapter pings the S7-1200 CPU IP address.
4.4 Verify the S7-300 Path Still Works
- Re-open WinCC Explorer, start the Runtime, and check WinCC Channel Diagnosis (start → WinCC → Channel Diagnosis). The MPI connection should still report "OK".
- You have not disturbed the S7-300 path — the access point
S7ONLINEstill resolves to CP 5611.
4.5 Add the S7-1200 Channel in WinCC
- In Tag Management, right-click and choose Add New Driver → SIMATIC S7-1200, S7-1500 Channel.
- Right-click OMS+ (or TCP/IP) and choose New Connection.
- In the connection dialog, set:
-
Name: descriptive (e.g.
S71200_Shopfloor). -
Access Point: select the symbolic name you created in 4.3 (e.g.
S7_1200_ACCESS). -
IP Address: the S7-1200 CPU IP (e.g.
192.168.0.10). - Connection Type: S7Comm (default).
- Slot / Rack: not required for S7-1200/1500.
-
Name: descriptive (e.g.
- Click OK.
4.6 Add the S7-300 Channel (if not already present)
- Tag Management → Add New Driver → SIMATIC Protocol Suite.
- Open MPI → right-click → New Connection.
- Set Access Point to
S7ONLINE(which is already bound to the CP 5611). - Set the MPI node address of the S7-300 CPU (e.g. MPI = 2).
- Set Rack 0, Slot 2 for an S7-300 CPU 31x PN/DP.
4.7 Define Tags
Tags reference address strings unique to the channel:
| PLC | Channel | Address Syntax | Example |
|---|---|---|---|
| S7-300 | SIMATIC Protocol Suite → MPI |
<DB><Byte.Bit> or M<Byte>
|
DB10,DBD0, MW20, I0.0
|
| S7-1200 | SIMATIC S7-1200, S7-1500 Channel | Same syntax; DB absolute only (no symbolic tag in WinCC < V7.5) |
DB20,DBW4, QB0
|
5. Verification Procedure
- Channel Diagnosis — Open Start → SIMATIC → WinCC → Channel Diagnosis. Both connections should show green status with active cycle counters.
- Tag Simulator — Use WinCC Explorer → Tools → Tag Simulation. Force a tag on each PLC and observe the runtime value.
-
APLog / WinCC Syslog — Inspect
C:\Program Files (x86)\Siemens\Automation\WinCC\Diagnose\WinCC_Sys_01.log. Look for channel-initialization lines and anyWCCRT:Channel:Errorentries. - S7-300 side — Use STEP 7 → PLC → Monitor/Modify or the CP 5611's MPI diagnostics to confirm bus load stays < 50%.
- S7-1200 side — TIA Portal → Online → Accessible Devices should list the CPU reachable from the engineering PC over the same Ethernet NIC.
- End-to-end — Toggle a discrete output on the S7-1200 and verify it appears in a WinCC screen value display. Toggle an S7-300 input and confirm the same in a separate screen widget.
6. Troubleshooting Matrix
| Symptom | Likely Cause | Diagnostic | Fix |
|---|---|---|---|
| S7-300 drops, S7-1200 works | Set PG/PC Interface S7ONLINE accidentally rebound to TCP/IP |
Set PG/PC Interface → highlight S7ONLINE | Rebind to CP 5611 MPI; click Test |
| S7-1200 drops, S7-300 works | Access point bound to wrong NIC (e.g. virtual VPN) |
ipconfig /all + Set PG/PC diagnostics |
Bind the symbolic access point to the physical Ethernet NIC |
| Both fail intermittently | NIC power management / Windows firewall | Device Manager → Power Management → uncheck "Allow PC to turn off"; wf.msc
|
Disable power saving; add firewall rules for TCP 102 |
S7-1200 channel returns 0x0310 access error |
PUT/GET not permitted on S7-1200 | TIA Portal → Device Properties → Protection | Enable Permit access with PUT/GET and re-download project |
S7-300 MPI STATUS: 0x0010
|
Wrong rack/slot or duplicate MPI address | STEP 7 → PG/PC → Diagnostics → Read | Set Rack 0, Slot 2 for CPU 31x; verify MPI = 2 unique |
| Runtime slow on both channels | Acquisition cycle set to 100 ms with thousands of tags | Channel Diagnosis → Cycle counter | Raise cycle to 500 ms for non-critical tags; use multiplexing |
| WinCC only loads S7-300 tags, S7-1200 tags greyed out | Wrong channel name in tag (e.g. "MPI" instead of "OMS+") | Tag properties → Channel unit dropdown | Re-enter tag address; verify connection assignment |
7. Performance & Cycle Tuning
WinCC's default acquisition cycle is 1 second. For each S7 connection, the channel DLL maintains a request queue sized by Request Buffer in the connection properties. Recommended baselines for a V7.4 SCADA on Windows 10 IoT LTSC x64:
| Parameter | S7-300 MPI | S7-1200 TCP |
|---|---|---|
| Acquisition cycle (slow tags) | 1000 ms | 1000 ms |
| Acquisition cycle (fast tags < 50) | 250 ms | 100 ms |
| Timeout | 3000 ms | 3000 ms |
| Max simultaneous requests | 4 | 8 |
| Bus load target | < 50% | N/A (TCP) |
8. Coexistence with STEP 7 and TIA Portal
Because the same physical Ethernet NIC may be used by the engineer for both STEP 7 V5.5 (S7-300) and TIA Portal (S7-1200), the access point S7ONLINE cannot be reliably bound to "the right" adapter. The recommended field practice is to always use a dedicated symbolic name for the S7-1200/1500 Channel and never assume S7ONLINE = TCP/IP. This avoids the classic "communication with S7-300 broke after I added the S7-1200" complaint.
9. Migration to TIA Portal and WinCC Unified
WinCC V7.4 is in maintenance phase. Newer deployments are encouraged to move to WinCC Unified in TIA Portal, which collapses the channel-DLL model into the project's device list. As a transition aid, Siemens documentation distinguishes three unified channel families; the equivalent of the V7.4 S7-300 + S7-1200 split is documented at Communicating with SIMATIC S7-300/400 (RT Unified). That page lists the permitted data areas, the connection resource budget per CPU, and the maximum number of simultaneous HMI connections — values that differ from the V7.4 limits and should be re-validated before a Unified migration.
10. Common Field Pitfalls
- Firewall blocking TCP 102. The Windows Defender Firewall is on by default. The S7-1200/1500 Channel needs inbound + outbound TCP 102 between the SCADA and the CPU. Create a rule once.
- Dual-stack IP conflict. If the NIC has both a 192.168.0.x (plant) and a 10.0.0.x (office) address, Set PG/PC may bind to the wrong subnet. Use the Advanced TCP/IP Settings to confirm metric order.
- S7-1200 with Optimized Block Access. Absolute DB access in WinCC V7.4 fails silently on optimized DBs with "Data consistency check failed". In TIA Portal, uncheck "Optimized Block Access" for DBs that WinCC reads.
- CP 5611 driver mismatch. The CP 5611 must use the Siemens SIMATIC NET driver, not a generic ASIX PCIe driver. If Windows Update replaced it, WinCC will fail to initialize. Reinstall SIMATIC NET from the WinCC DVD's "Tools" folder.
- Mixed firmware on S7-1200. CPUs at V4.0 allow PUT/GET only with the checkbox enabled. V4.2+ allows fine-grained DB-level access control. Match firmware to your security policy.
11. Commissioning Checklist
- [ ] S7-300 CPU MPI address verified with STEP 7 PG/PC Diagnostics.
- [ ] CP 5611 (or equivalent) installed; Siemens SIMATIC NET driver active.
- [ ]
S7ONLINEsymbolic access point bound to CP 5611 MPI. - [ ] S7-1200 CPU Permit access with PUT/GET enabled.
- [ ] Standard Ethernet NIC bound to a new symbolic name (e.g.
CP_LAN_1). - [ ] Windows Firewall rule for TCP 102 (inbound + outbound) created.
- [ ] Optimized Block Access disabled for any DB read by WinCC.
- [ ] Channel Diagnosis shows both connections green.
- [ ] Tag Simulator forces a value on each PLC and updates on the SCADA screen.
- [ ] Runtime & logging stable for 24 h soak test.
12. Frequently Asked Questions
Can I add the SIMATIC S7-1200, S7-1500 Channel to a WinCC V7.4 project that already uses SIMATIC Protocol Suite for an S7-300?
Yes. The two channel DLLs are independent. Add SIMATIC S7-1200, S7-1500 Channel under Tag Management, create a new connection, and assign it a distinct symbolic access point (e.g. CP_LAN_1) bound to the Ethernet NIC. The S7-300 path through S7ONLINE → CP 5611 remains untouched.
Will changing Set PG/PC Interface break the S7-300 MPI connection?
Not if the access point assigned to the SIMATIC Protocol Suite's MPI connection is not the one you are modifying. The S7ONLINE access point is just one entry in the registry. You can add a separate symbolic name (e.g. CP_5611_MPI) bound to the CP 5611, and a different symbolic name bound to the Ethernet NIC. The two channels resolve their access points independently.
What port does the S7-1200/1500 Channel use?
TCP 102 (S7Comm). The S7-1200/1500 Channel does not need S7-PCT or any additional licensing; the connection is opened directly by the channel DLL. Ensure the Windows Firewall has an inbound + outbound allow rule for TCP 102 between the WinCC host and the S7-1200 CPU.
Does WinCC V7.4 support symbolic tag names on the S7-1200?
No. V7.4 supports only absolute DB addressing (e.g. DB20,DBW4). Symbolic tag import was added in WinCC V7.5 via the TIA Portal Export to WinCC function. If you must stay on V7.4, export a CSV from the TIA Portal PLC tag table and import it into WinCC's tag database manually.
Why does my S7-1200 connection succeed in Channel Diagnosis but tags stay 0?
Three common causes: (1) Optimized Block Access is enabled on the DB, blocking absolute addressing; (2) the address range exceeds the DB size; (3) the S7-1200 firmware is V4.0 with Permit access with PUT/GET disabled. Check the TIA Portal project first, then re-download to the CPU.
What is the maximum number of WinCC connections to a single S7-1200?
An S7-1200 CPU V4.x supports up to 8 HMI/PG connections for S7Comm PUT/GET (connection resource 1). Higher connection counts require the S7-1200/1500 firmware's connection mechanisms setting to be expanded, or moving to an S7-1500 if more than 32 simultaneous connections are needed.