Connecting MP377 HMI to S7-300 via CP 343-1 Lean Ethernet

David Krause14 min read
HMI / SCADASiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

The Siemens SIMATIC MP377 12-inch Touch HMI (6AV6 644-0AA01-2AX0) exchanges process data with a SIMATIC S7-300 CPU 313C (6ES7 313-5BF03-0AB0) through the CP 343-1 Lean (6GK7 343-1CX10-0XE0) communications processor over PROFINET. Although the panel's port is labeled PROFINET and the CP is also a PROFINET/Industrial Ethernet device, the practical HMI path is the S7 protocol carried on ISO-on-TCP (RFC 1006, TCP port 102). PROFINET and Industrial Ethernet share the same physical layer (IEEE 802.3, 10/100 Mbit/s, RJ45). An MP377 plus a CPU 313C plus a CP 343-1 Lean therefore form a small, deterministic Ethernet cell that does not require a PROFINET IO controller or PROFINET device names — only IP addresses and a single S7 connection. This reference compiles the engineering workflow in STEP 7 V5.x plus WinCC flexible 2008 Standard, which is the minimum tool combination that resolves the project compatibility issue where WinCC flexible 2007 Compact fails to integrate the MP377 12" Touch with the CP 343-1 Lean configuration package.

Hardware Identification and Catalog Numbers

Component MLFB / Order Number Function Firmware Floor
MP377 12" Touch HMI 6AV6 644-0AA01-2AX0 Operator panel, 12.1" TFT, 800x600, PROFINET WinCC flexible 2008 SP2 image
SIMATIC S7-300 CPU 313C 6ES7 313-5BF03-0AB0 Compact CPU, 64 KB work memory, DI16/DO16 + AI5/AO2 onboard Firmware V2.6 minimum
CP 343-1 Lean 6GK7 343-1CX10-0XE0 Ethernet/PROFINET comms processor, 8 S7 connections Firmware V2.4 minimum
Power supply PS 307 5 A 6ES7 307-1BA01-0AA0 120/230 VAC -> 24 VDC, 5 A —
Front connector 40-pin 6ES7 392-1AM00-0AA0 Wiring the CPU onboard I/O —

The MP377 12" Touch is part of the Multi Panel 377 family. Its PROFINET interface is a single 10/100 Mbit/s RJ45 jack supporting S7-MPI/DP, S7 Ethernet, and PROFINET RT. The CP 343-1 Lean supplies one PROFINET interface plus diagnostics over standard Ethernet services (Web, SNMP, FTP).

Protocol Selection: PROFINET vs S7 over Ethernet

The CP 343-1 Lean can be operated in three modes from STEP 7 V5.5 NetPro:

  • S7 communication (PUT/GET, USEND/URCV, BSEND/BRCV) on ISO-on-TCP port 102.
  • PROFINET IO Device — the CP presents itself as an IO device to an external PROFINET IO controller.
  • Standard Ethernet services (FTP, HTTP, SNMP) for diagnostics and firmware updates.

For HMI/messaging traffic with WinCC flexible the most reliable path is S7 communication on ISO-on-TCP. The CP does not act as a PROFINET IO controller, so the MP377 cannot be a PROFINET IO device on a controller hosted by this CP. The HMI is treated as a passive S7 partner that initiates the connection to the CP. PROFINET RT and S7-TCP share the same physical cabling but use independent protocol stacks, so the two can coexist if ET 200 PN I/O is later added.

Design rule: When the HMI is the only PROFINET-class device on the network and no distributed I/O is attached, prefer S7 communication. Reserve PROFINET IO controller/IO device pairs for distributed I/O such as ET 200S, ET 200SP, or ET 200pro PN. Using PROFINET IO for the HMI adds cycle-time overhead without functional benefit.

Firmware Compatibility Matrix

Engineering Tool CP 343-1 Lean HSP MP377 HSP Compile Outcome
STEP 7 V5.4 SP5 + WinCC flexible 2007 Compact HSP for 6GK7 343-1CX10-0XE0 Not bundled Compile error: no panel image for 12" Touch
STEP 7 V5.5 + WinCC flexible 2008 Standard SP2 Bundled Bundled Clean compile
STEP 7 V5.5 SP4 + WinCC flexible 2008 SP3 Bundled Bundled Clean compile
TIA Portal V13 SP1 Update 9 HSP for S7-300 family HMI HSP for MP377 Clean compile, mixed device limits apply
TIA Portal V14 / V15.1 / V16 HSP for S7-300 family HMI HSP for MP377 Recommended for new projects

The 6AV6 644-0AA01-2AX0 panel is supported only by WinCC flexible 2008 SP2 or later. The CP 343-1 Lean 6GK7 343-1CX10-0XE0 ships with STEP 7 V5.5 and later HSP bundles; for STEP 7 V5.4 you must install the CP 343-1 Lean HSP for STEP 7 V5.4 separately.

Software Prerequisites

Select the engineering software before touching hardware. WinCC flexible 2007 Compact is not a valid engineering tool for the MP377 12" Touch when paired with the CP 343-1 Lean 6GK7 343-1CX10-0XE0 because:

  • It does not bundle a configuration package for the MP377 12" Touch revision required by the runtime image.
  • It cannot generate a panel image for the 12" Touch target when the CP 343-1 Lean is selected as the partner (the partner catalog references a higher configuration package revision).
  • It reports "Configuration package not found" or "The selected PLC connection is not supported in this version of WinCC flexible" at compile time.

Use WinCC flexible 2008 Standard SP2 (or later) as the engineering tool, with the matching MP377 and CP 343-1 Lean support packages installed. For new projects, migrate to TIA Portal V13 SP1 Update 9 or later with the S7-300 family HSP and the HMI HSP for MP377. TIA Portal supports the CP 343-1 Lean 6GK7 343-1CX10-0XE0 directly through the S7-300 device library and the MP377 as a Comfort Panel target in compatibility mode.

STEP 7 V5.x Hardware Configuration

  1. Open the STEP 7 V5.5 project (or create a new one) and insert a SIMATIC 300 station.
  2. Place the rail (UR / ER) and slot the power supply in slot 1: PS 307 5 A (6ES7 307-1BA01-0AA0).
  3. Slot 2: leave empty for one-slot IM gap if used, or place the IM 365 for split racks.
  4. Slot 3: CPU 313C (6ES7 313-5BF03-0AB0). The CP 343-1 Lean must be installed in slots 4–11 only.
  5. Insert the CP 343-1 Lean (6GK7 343-1CX10-0XE0) in slot 4. Do not place the CP in slot 3 — the CPU occupies slot 3 and a CP in slot 3 is rejected by HW Config.
  6. Double-click the CP and assign:
    • Ethernet interface IP: 192.168.0.10, subnet mask 255.255.255.0, no router.
    • PROFINET device name: optional, e.g., cp343-lean-1 — only required if PROFINET IO mode is enabled.
    • In Properties > Options, enable "Use ISO-on-TCP for S7 communication" (default) and "Use TCP/IP".
    • In Properties > Connection, enable "Active connection establishment" if the CP initiates the connection, or leave it disabled if the HMI is the active partner. For an MP377 driving the link, leave the CP passive.
  7. Compile and download the hardware configuration (HW Config > PLC > Download to Target) to the CPU.

NetPro Connection Setup

Open NetPro (menu Options > NetPro) and create a new S7 connection. Choose the CP 343-1 Lean as the local endpoint and select "Unspecified" as the partner (WinCC flexible partners cannot be selected from the S7-300 catalog because they are not STEP 7 stations). Define:

  • Connection name: e.g., HMI_Connection_1.
  • Local ID (hex): a free connection resource on the CP, e.g., 0001.
  • Partner IP address: 192.168.0.20 (the MP377).
  • Partner rack/slot: 0 / 0 for the MP377 (the HMI is not rack-mounted, but the field is required and ignored by WinCC flexible).
  • Connection type: S7 connection.

Compile NetPro (Network > Compile and Check All) and download the connection table to the CPU. The CP 343-1 Lean stores the connection configuration in non-volatile memory and survives power cycles.

WinCC Flexible 2008 Project Setup

  1. Launch WinCC flexible 2008 Standard.
  2. Create a new project and select the device MP377 12" Touch (6AV6 644-0AA01-2AX0). The image shows a 12.1" 800x600 panel.
  3. In Project > Device Properties, verify that the panel reports PROFINET as the interface. Do not select MPI/DP — the panel ships with PROFINET only on this MLFB.
  4. Open Communication > Connections and create a new connection.

Connection Parameters

Parameter Value Notes
Communication driver S7 Ethernet (ISO-on-TCP) Do not use S7 MPI/DP
PLC IP address 192.168.0.10 CP 343-1 Lean IP
PLC rack 0 S7-300 rack 0
PLC slot 4 Slot of the CP 343-1 Lean (not the CPU)
Connection name HMI_Connection_1 Must match the NetPro entry name for clarity
Cycle time 500 ms (default) Tune only if HMI latency is observed
Number of retries 3 (default) Increase to 5 in noisy environments

WinCC flexible expects the PLC slot to point at the head module that owns the Ethernet interface. Slot 4 (CP 343-1 Lean) is the correct choice. Pointing at the CPU slot (3) will produce a connection error because the CPU 313C variant used here (313-5BF03-0AB0) has no PN/IE port.

Slot rule: For S7-300 with external CP, the HMI's PLC slot must reference the CP slot, not the CPU slot. This is the most common commissioning error on first-time projects.

Panel Network Settings

Configure the MP377 itself through the Control Panel (reachable after first download via Start Center > Settings > Control Panel):

  1. Control Panel > Network and Dial-up Connections > PN-IO (labeled "PROFINET" on the 6AV6 644-0AA01-2AX0).
  2. Set IP address to 192.168.0.20, subnet mask 255.255.255.0.
  3. Set PROFINET device name to mp377-hmi (used only if PROFINET IO is later added; harmless otherwise).
  4. Save and reboot the panel.

If the panel is reached for the first time over Ethernet from a programming PG, use ProSave (bundled with WinCC flexible) and set the PG/PC interface to TCP/IP > your Ethernet adapter. ProSave transfers the panel image and runtime by default over Ethernet once the panel is reachable.

Area Pointers and Tag Areas

WinCC flexible uses area pointers to coordinate with the S7-300 firmware. Configure the following pointers in Communication > Area Pointers:

Area Pointer DB on S7-300 Length Purpose
Coordination DB 999 (default) 1 byte Coordination bits for HMI life/ready
Date/Time — — Synchronizes panel clock to CPU
Job mailbox DB 998 (default) 4 words Trigger control jobs (set screen, logon, etc.)
Project ID DB 997 1 word Project version stamping
Recipe pointer DB 996 (optional) — Recipe view

Create the corresponding DBs in STEP 7 with attribute "Non-optimized" (so that WinCC flexible can access them via S7 absolute address) and write a startup OB100 that initializes the coordination byte to B#16#FF to indicate HMI-ready after restart.

// OB100 startup
CALL "SET_PIO" / FC105
   PIW := 0
   RET_VAL := DB999.DBX0.0   // Coordination byte
   ...

Cabling, Topology, and Switch Sizing

  • Use Cat 5e or higher UTP/STP cable, max 100 m per segment (TIA-EIA 568 standard).
  • For point-to-point link between MP377 and CP 343-1 Lean, both ports are auto-MDI/MDIX — a crossover cable is not required.
  • For multi-device networks, use a managed switch (e.g., SCALANCE XC-208 or XB-208) with PROFINET compliance if PROFINET IO is later added. Disable EEE (Energy Efficient Ethernet) on the switch port to prevent PROFINET IRT jitter.
  • Ensure the panel and PLC are on the same subnet. Mismatched subnet masks (e.g., /24 on the panel, /16 on the CP) are the most common commissioning failure and are not detected until the HMI tries to establish the S7 connection.
  • Use a separate VLAN for HMI traffic if the cell shares a corporate network. The CP 343-1 Lean supports a single Ethernet interface, so the VLAN is configured on the switch side and the CP is unaware of the VLAN tag.

Cycle Time, Update Rate, and Performance

The default WinCC flexible cycle time of 500 ms is conservative. The CP 343-1 Lean can sustain 100 ms cycles for up to 32 polled tags; below 100 ms use event-driven acquisition (configured per tag in WinCC flexible). Practical sizing:

  • Up to 250 tags per cycle at 500 ms without dropped frames on a clean network.
  • Up to 64 tags per cycle at 100 ms.
  • Avoid polling the entire DB at sub-second cycle — split into event-driven acquisition for status bits.

The MP377 internal tag database holds up to 4096 tags. Limit external pointers to the union of HMI screen variables plus 10% margin to keep panel RAM consumption predictable.

Verification and Diagnostics

  1. Download the WinCC flexible project to the MP377 using Ethernet (ProSave) or USB. Confirm the runtime version matches the configuration package.
  2. Watch the CP 343-1 Lean LEDs during startup:
    • SF (red) — system fault; off in healthy state.
    • BF (red) — bus fault; off when at least one S7 connection is established.
    • LINK/ACT (green/yellow) — link status; blinking = traffic.
    • RX/TX (per-port) — link partner traffic.
  3. On the MP377 Start Center, open System > Logs > Connection; the S7 connection should report "Established".
  4. From the CPU side, use PLC > Diagnostics/Settings > Module Information > Communication in STEP 7 to inspect the connection status, status bytes, and rejection counters (word STAT1 / STAT2 of the SFB/SFC diagnostics).
  5. Ping the CP from a PG on the same subnet: ping 192.168.0.10 -t. Successful echo confirms Layer 3 reachability.

Diagnostic Codes and LED Patterns

Symptom Likely Cause Remedy
BF LED solid on CP 343-1 Lean No TCP partner reachable; subnet mismatch Ping from PG to CP IP; verify subnet; check VLAN tagging
BF LED blinks, SF off S7 connection rejected by CPU Check NetPro connection; verify rack/slot match
SF LED steady on CP CP firmware does not match HSP Update CP firmware to V2.4 or later via Web UI
HMI shows "Connection failed" Wrong slot in WinCC flexible Set PLC slot = 4 (CP slot), not 3 (CPU slot)
Compile error: "Configuration package not found" WinCC flexible 2007 Compact used Upgrade to WinCC flexible 2008 Standard SP2 or later
HMI displays project but values are "####" DB uninitialized or wrong DB number Create the DB referenced by the HMI tag
Intermittent loss after switch reboot CP does not auto-reconnect in time Enable "Active connection establishment" on CP, or shorten retry interval
Status word STAT1 = 0x0001 Connection resource exhausted CP 343-1 Lean supports max 8 S7 connections; reduce count
Status word STAT1 = 0x0003 Wrong TSAP or rack/slot Re-enter partner rack/slot; check TSAP for ISO-on-TCP
Status word STAT1 = 0x001A Timeout — partner not responding Check CP partner IP and switch port

Failure Modes and Recovery

Plan the recovery procedure for each failure mode so that production restarts in seconds, not minutes.

  • Loss of panel IP: re-enter via Control Panel on the panel directly (keyboard input not required, the panel retains touch).
  • Loss of CP IP: re-enter via the CP's Web UI (https://192.168.0.10) or use the STEP 7 "Assign Ethernet Address" tool.
  • Panel firmware corruption: ProSave reset to factory, then retransfer the runtime image (5-10 min).
  • Connection resource exhaustion: track the 8-connection budget — CPU programming PG, MP377, drive, peer PLC — and document each in NetPro. The CP rejects new connections with status 0x0001 once the budget is met.

Migration Path to TIA Portal

For new projects Siemens recommends engineering both the HMI and the PLC in TIA Portal V16 or later. The migration steps are:

  1. Use Project > Migrate project in TIA Portal to convert the STEP 7 V5.x + WinCC flexible 2008 project. TIA Portal accepts both .s7p and .hmi source files.
  2. Replace the MP377 target with the TIA Portal device entry (the MP377 maps to a Comfort Panel target; physical device remains the same — TIA Portal uses a software compatibility layer to support older Multi Panels).
  3. Re-import tags from the S7-300 DBs (DB1, DB2, etc.) using the PLC tag table import and re-bind them to HMI tags.
  4. Compile, then download HMI and PLC as a unit from TIA Portal.

The CP 343-1 Lean (6GK7 343-1CX10-0XE0) is fully supported in TIA Portal V14+ under the S7-300 device family. The PROFINET interface is exposed as an Ethernet interface of the S7-300 station and the connection is configured via Devices & Networks > Connections.

Power Budget and Wiring Notes

The MP377 12" Touch draws up to 1.2 A at 24 VDC. The CPU 313C onboard I/O draws up to 0.6 A at 24 VDC. The CP 343-1 Lean draws up to 0.2 A at 24 VDC. Total panel-side load is approximately 2.0 A. Use a PS 307 5 A (6ES7 307-1BA01-0AA0) for the S7-300 rack to keep ample margin for sensor and actuator supply current on the backplane bus.

Frequently Asked Questions

Why does WinCC flexible 2007 Compact fail to compile the MP377 12" Touch project?

WinCC flexible 2007 Compact does not bundle a configuration package for the MP377 12" Touch (6AV6 644-0AA01-2AX0) at the firmware revision required by the panel runtime. Upgrade to WinCC flexible 2008 Standard SP2 or later — the configuration packages for MP377 and CP 343-1 Lean (6GK7 343-1CX10-0XE0) are bundled together and the project compiles cleanly.

Does the CP 343-1 Lean support PROFINET IO with the MP377?

No. The CP 343-1 Lean operates as a PROFINET IO Device for distributed I/O, not as an IO Controller. The MP377 is a passive PROFINET device that uses S7 communication on TCP/IP, so HMI traffic does not require PROFINET IO. Configure an S7 connection in NetPro and on the panel — no PROFINET IO controller/IO device handshake is needed for HMI traffic.

Which slot do I select in WinCC flexible for the PLC partner?

Select the slot of the CP 343-1 Lean in the S7-300 rack (typically slot 4). The CPU 313C in slot 3 has no Ethernet port on variant 313-5BF03-0AB0; pointing the HMI at slot 3 fails with a connection error. The CP owns the IP stack that the HMI talks to.

Can I use WinCC flexible 2007 Compact with an MP370 or smaller panel and the CP 343-1 Lean?

WinCC flexible 2007 Compact supports the MP370 12" Touch and earlier Multi Panels, but only with their original firmware revisions. For mixed fleets using the CP 343-1 Lean and an MP377, standardize on WinCC flexible 2008 Standard or TIA Portal to eliminate the matrix of per-panel compatibility packages.

What is the maximum number of S7 connections the CP 343-1 Lean supports?

The CP 343-1 Lean (6GK7 343-1CX10-0XE0) provides 8 S7 connections total (BSEND/BRCV, PUT/GET, HMI). With one MP377 and one programming PG using two connections, six remain for additional HMIs, drives, or peer PLCs. Track connection IDs in NetPro — duplicate IDs cause "Connection already configured" errors at compile time and status word STAT1 = 0x0001 at runtime.

Back to blog