Connecting a SIMATIC S7-300 to a PROFINET HMI/PC via CP 343-1
Many legacy SIMATIC S7-300 stations were built around CPUs that only expose a PROFIBUS-DP interface (for example CPU 315-2 DP, CPU 316-2 DP, or older CPU 31x variants). When the project later needs a PROFINET-based Panel PC, Comfort Panel, or a WinCC Runtime station, the missing PROFINET interface is solved by adding a SIMATIC NET CP 343-1 communications processor in the S7-300 rack. The CP 343-1 acts as a PROFINET IO controller / IO device and provides the Ethernet/PROFINET port that the HMI connects to.
This reference covers hardware selection, slot rules, STEP 7 / TIA Portal configuration, the critical distinction between an OP connection and a standard S7 connection, and a verification / troubleshooting matrix. It also covers the direct-key PROFINET/PROFIBUS IO slave path, which is the only case in which an HMI panel acts as a PROFINET IO device.
1. Problem Statement and Network Architecture
The S7-300 CPU in scope has a single PROFIBUS-DP interface (MPI/DP combined port set to DP master) and no onboard PROFINET port. The HMI side (PC Runtime or Panel) is PROFINET-capable and must reach the S7 program tags for acyclic read/write of operator data, alarms, recipes, and diagnostics.
Inserting a CP 343-1 closes that gap. The CP sits in the S7-300 backplane as a standard FM/CP slot (slots 4–11 on a single rack, depending on the CPU and PS), occupies a PROFINET interface of its own, and the CPU continues to execute the user program. The HMI only sees a single IP endpoint on PROFINET; the tag reads/writes are routed by the CPU through the backplane (K-bus) to the CP and out on Ethernet.
Two important architectural facts that drive the rest of this guide:
- The CP 343-1 is only a communications adapter. The S7 program, the connection data, and the HMI tag handling all run in the CPU. Losing the CP does not affect program execution, only external HMI/PG communication.
- The HMI does not connect to the CP as if the CP were a CPU. The destination IP address is the CP's IP, but the connection partner (rack/slot) in the WinCC connection configuration must be set to the CPU (rack 0, slot of the CPU, typically slot 2 or 3). The HMI opens an OP connection that is asynchronous to the standard S7 PUT/GET connections; it is not a standard S7 client/server relationship in the S7-comm sense.
2. CP 343-1 Family: Selecting the Right Variant
Siemens offers three CP 343-1 variants. All three can bridge a PROFIBUS-only S7-300 to a PROFINET HMI; the difference is the number of connections, IT/web functions, and PROFINET IO controller/device capability. Choose the smallest variant that meets the connection count and the PROFINET IO role you need.
| Feature | CP 343-1 Lean | CP 343-1 | CP 343-1 Advanced |
|---|---|---|---|
| Typical order number (6GK7 343-1...) | ...CX10-0XE0 / ...CX30-0XE0 | ...EX21-0XE0 / ...EX30-0XE0 | ...GX21-0XE0 / ...GX31-0XE0 |
| PROFINET interfaces | 1 × PROFINET (2-port switch) | 1 × PROFINET + 1 × GbE (varies by FW) | 1 × PROFINET + 1 × GbE |
| PROFINET IO controller | Yes (limited IO devices) | Yes | Yes |
| PROFINET IO device | Yes | Yes | Yes |
| S7 / PG / OP / S7-HMI connections | Limited (4 total typical) | More (8–16 typical) | Many (up to 32+ depending on FW) |
| IT functions (HTTP, FTP, email, web server) | No | Limited / none | Yes (FTP, HTTP, email, SNMP) |
| Security / firewall | Basic | Basic | Stateful firewall (CP FW) |
| Recommended for | Single PROFINET HMI, small machines | Multi-HMI, multi-PG, IO controller use | Plant networks, IT integration, many connections |
For a single Panel PC acting as an HMI to a single S7-300, the CP 343-1 Lean is sufficient and is the most cost-effective choice. The CP 343-1 Advanced is only justified if you also need the IT/web/email functions or a stateful firewall between the plant network and the office network.
3. Hardware Installation Prerequisites
- Slot rules. The CP 343-1 occupies a slot in the S7-300 rack. It must be placed in a free slot (slot 4–11 on rack 0) to the right of the CPU. The slot is configured in STEP 7 / TIA Portal hardware configuration and must match the physical slot.
- Backplane power. The CP draws 5 V from the backplane. Check the S7-300 / PS 305/307 budget; a typical CP 343-1 draws ~200 mA at 5 V. Add this to the segment total and confirm the PS can supply it. The CPU will not start if the PS is undersized.
- PROFINET cabling. Use Cat 5e or better for PROFINET copper runs up to 100 m. The CP 343-1 Lean has an integrated 2-port switch, so a daisy-chained topology is supported without an external switch for small line topologies.
- IP plan. Reserve a fixed IP for the CP (e.g., 192.168.0.10/24) and a fixed IP for the HMI/PC (e.g., 192.168.0.20/24). PROFINET devices must be in the same subnet. The CPU's MPI/PROFIBUS address and PROFINET IP are independent; the S7 program does not need a PROFINET IP on the CPU itself.
- Engineering tool. TIA Portal (V15.1 or later recommended for current CP 343-1 firmware) for new projects, or STEP 7 V5.5 + SPx with the matching SIMATIC NET CP library for legacy projects. The CP's GSD file is not required for in-project configuration but is required if a third-party controller must talk to the CP as a PROFINET IO device.
- Firmware. Confirm the CP's firmware against the TIA Portal HSP (Hardware Support Package) list. Older CP 343-1 Lean units shipped with firmware V1.x; these are supported in STEP 7 V5.5 but may require an HSP or firmware update to be visible in current TIA Portal versions.
4. TIA Portal Configuration: Step-by-Step
The procedure below covers TIA Portal (recommended for greenfield projects). STEP 7 V5.5 is functionally equivalent; menu paths differ.
4.1 Insert the CP 343-1 in the device configuration
- Open the project and double-click the S7-300 station Devices & Networks.
- In the hardware catalog, navigate to SIMATIC S7-300 > Communication modules > CP 343-1 and drag the selected variant onto the rack at the desired free slot.
- Double-click the inserted CP to open its properties.
- Assign the PROFINET interface a fixed IP address, subnet mask, and (if used) router address. Disable the Set IP address from a different configuration tool option if you want a permanent static address.
- Optionally enable PROFINET IO controller mode and add PROFINET IO devices. The CP can act as the IO controller for distributed I/O, independent of the CPU's own PROFIBUS IO system.
4.2 Compile and download the hardware configuration
- Right-click the S7-300 station → Compile > Hardware (rebuild all). Resolve any slot / type errors.
- Connect the PG to the CP's PROFINET port (or to the CPU's MPI/DP port with the CP reachable via the backplane's K-bus for routing).
- Download the HW configuration to the station. The CP will reset briefly and come up with the new IP.
- Use Online & Diagnostics → PROFINET diagnostics to verify the CP's port status and link state.
4.3 Configure the HMI connection in the HMI device
Add a WinCC HMI device (or open the existing one) and configure the connection to the S7-300:
- In the HMI device's Connections editor, create a new connection. Choose the connection type that matches your runtime: S7-300/400 for WinCC Comfort/Advanced RT, or SIMATIC S7-300/400 for WinCC Professional.
- Partner (endpoint): the S7-300 station.
- Interface: PROFINET (the HMI's PROFINET interface).
- Partner address: enter the CP 343-1's IP address (e.g., 192.168.0.10).
- Partner rack/slot: enter the CPU's rack and slot, e.g., Rack 0, Slot 2. Do not enter the CP's slot here. The CP is transparent for the connection's logical partner.
- Connection type: leave as default OP connection for an HMI tag polling project. Only change to a standard S7 connection if the HMI explicitly uses S7 PUT/GET blocks.
- Compile the HMI project and download to the Panel / RT PC.
ping to the CP succeeds.5. OP Connection vs S7 Connection — What the HMI Actually Uses
WinCC (Comfort, Advanced, Professional) does not use a pure S7-comm PUT/GET when communicating with an HMI tag polling project. It opens an OP connection that uses the S7-comm transport but adds the WinCC-licensed protocol extensions for tag subscription, alarm/event subscription, and recipe handling. The OP connection:
- Is established by the HMI (the HMI is the OP client / S7 client in S7-comm terms).
- Is asynchronous to user-program S7 connections — user PUT/GET blocks running on the CPU do not block, and are not blocked by, the OP connection.
- Consumes one S7-comm connection resource on the CPU. S7-300 CPUs typically have 8, 12, or 16 S7-comm resources depending on the CPU type; track total connection usage (PG, OP, S7, route, HTTP) to avoid 0x0001 / no resources errors.
Verify the connection resource in the CPU's online diagnostics under Connection overview. The HMI's OP connection should appear with the HMI's IP, an OP type, and Established state once the runtime starts.
6. PROFINET Direct Keys: HMI as IO Device
If you need to wire physical keys on a Comfort Panel directly into the CPU's process image (e.g., for fast hand/auto jog keys that must be read even if the HMI tag polling connection is down), Comfort Panels support PROFINET direct keys and can be added to the CPU's or the CP's PROFINET IO system as an IO device. In this case:
- The HMI is no longer just a client — it has a PROFINET device interface.
- The HMI's slots/IO are mapped to bits in the CPU's process image via PROFINET IO.
- Tag polling still uses the OP connection described in §5; the direct keys are a separate IO channel.
Enable in TIA Portal under the HMI device → PROFINET interface → Operating mode → IO device. The PROFINET IO system must be assigned to either the CPU's PN port (only on PN-capable CPUs) or to a CP 343-1 configured as PROFINET IO controller.
7. Network Topology Diagram
The CP sits in the rack, the HMI/PC and PG sit on the PROFINET segment, the CPU remains reachable via MPI/DP for legacy PROFIBUS devices. The HMI's partner IP is the CP; the partner rack/slot is the CPU.
8. Verification and Commissioning Checks
- Link/LED check. CP 343-1 port LEDs show LINK and DATA activity when the PROFINET cable is connected to an active partner. No link = cabling/port fault.
-
Ping test. From the HMI/PC,
ping 192.168.0.10(the CP). A successful ping only proves L3 reachability — it does not prove the OP connection. - CPU online connection overview. In TIA Portal, go Online & Diagnostics > CPU > Connection overview. The HMI's IP should appear with type OP and state Established. If it shows Establishing or no entry, the OP connection failed.
- WinCC connection diagnostics. On the HMI, in the runtime, open System > System Information > Connections. The configured connection should be Online. Clicking it shows last error code and timestamp.
- Tag test. Create a temporary tag mapped to a known process value (e.g., a Merker word). Force the value in the CPU and verify the HMI updates within the configured polling cycle. A '#########' or No connection indication confirms the data path is broken.
- PROFINET diagnostics. TIA Portal → Online & Diagnostics > PROFINET diagnostics on the CP. Port statistics should show no excessive CRC, late collisions, or discards.
9. Troubleshooting Matrix
| Symptom | Probable Cause | Diagnostic | Fix |
|---|---|---|---|
| CP not reachable, ping fails | Wrong IP, wrong subnet, cable fault | LED off; arp -a; check IP config in TIA Portal | Assign correct IP via TIA Portal; check cable; check VLAN |
| Ping works, OP connection fails | Partner rack/slot set to CP slot, or connection resource exhausted | Connection overview in CPU; check partner address in WinCC | Set partner rack/slot to CPU slot (e.g., 0/2); free CPU connections |
| Connection establishes, no tag updates | Wrong DB / offset, area pointer not configured, tag has no acquisition cycle | Watch table on tag address; WinCC tag status | Correct address; enable cyclic acquisition on tag |
| Intermittent connection drops | PROFINET storm, broadcast, IGMP, keep-alive too low | Wireshark on PROFINET port; CPU diag buffer | Isolate PROFINET; tune TCP keep-alive; replace switch |
| CP SF/BF LED on | Duplicate IP, IO device failure, config mismatch | CPU diag buffer; PROFINET online diagnostics | Resolve duplicate IP; recommission IO devices |
| CPU STOP after CP download | Slot conflict or HW config error | CPU diag buffer code | Verify slot assignment; check CP version vs HW catalog |
| Only one HMI works, second cannot connect | CP 343-1 Lean OP connection limit reached | Connection overview | Upgrade to CP 343-1 Standard/Advanced or reduce connection count |
10. Connection Limits and Sizing
CP 343-1 variants have a fixed connection budget. S7-300 CPUs also have an S7-comm resource count. The HMI OP connection counts against the CPU S7-comm budget, not the CP's, because the S7 program is the logical partner.
| CPU family | Typical S7-comm resources | Notes |
|---|---|---|
| CPU 312 / 314 | 4–8 | One PG + one OP leaves little headroom |
| CPU 315-2 DP / 316-2 DP | 8–12 | Suitable for 1 HMI + 1 PG + a few S7 routes |
| CPU 317-2 DP / PN/DP | 12–16 | Multiple HMI panels feasible |
| CPU 319-3 PN/DP | 16–32 | Plant-scale HMI counts |
For sizing, the formula is:
Total_Connections = PG_count + OP_count + S7_route_count + HTTP_admin (if used) <= CPU_Comm_Budget
If the budget is exceeded, the CPU rejects new connections and the HMI shows Connection failure (0x0001) in WinCC diagnostics.
11. Security and Network Hardening
- Place the PROFINET segment in a separate VLAN from the office network. The CP 343-1 has no Layer-3 firewall.
- If plant/office separation is required, use the CP 343-1 Advanced, which has a stateful firewall. Configure rules in TIA Portal → CP → Security → Firewall.
- Disable unused services on the CP (FTP, HTTP, SNMP) if the Advanced variant is used and those services are not required.
- Lock the CP's PROFINET port with the port-security / port-restriction features in the managed switch.
- Use dedicated S7-comm user/passwords in the CPU's protection settings (CPU → Properties → Access protection). The HMI/CP must be configured with matching credentials.
12. References to Official Documentation
Configuration of HMI connections between WinCC Runtime and S7-300/400 over PROFINET is documented in the TIA Portal Help and in the Siemens documentation portal:
CP 343-1 device manuals, GSD files, and firmware updates are available in the Siemens Industry Online Support under product tree → Automation technology → Industrial communication → SIMATIC NET → CP 343-1.
Do I need a CP 343-1 if my S7-300 CPU already has a PROFINET port?
No. CPUs with an onboard PROFINET port (e.g., CPU 315-2 PN/DP, CPU 317-2 PN/DP, CPU 319-3 PN/DP) can host the HMI OP connection directly. The CP 343-1 is only required for PROFIBUS-only S7-300 CPUs (CPU 31x-2 DP variants without the PN suffix).
Is the CP 343-1 Lean enough for a single PROFINET HMI?
Yes. The Lean variant supports the OP connection from a single WinCC Runtime or Comfort Panel and provides a 2-port PROFINET switch. Use the Standard variant if you need more than 4 simultaneous connections, and the Advanced variant if you also need IT functions (FTP, HTTP, email) or a stateful firewall.
What rack and slot do I enter as the HMI's connection partner?
Enter the CPU's rack and slot, e.g., Rack 0 / Slot 2 for a CPU 315-2 DP. The CP's IP is the partner IP; the CP's slot is not used for the connection partner. Setting the partner slot to the CP's slot is the most common configuration error and causes a connection that pings but never establishes.
Can I also use the CP 343-1 as a PROFINET IO controller for distributed I/O?
Yes. The CP 343-1 (all three variants) can act as a PROFINET IO controller and supervise its own PROFINET IO system, independent of the CPU's PROFIBUS IO system. This is useful when you want to keep the CPU's PROFIBUS for legacy field devices and run a parallel PROFINET I/O line through the CP.
Why does my HMI show 'Connection failure' even though ping to the CP succeeds?
Almost always a partner rack/slot mismatch in the WinCC connection (set to the CP's slot instead of the CPU's slot), an exhausted CPU S7-comm resource pool, or a CPU access-protection password that the HMI was not configured with. Check the CPU's Online > Connection overview first — if the HMI is not listed there at all, the OP connection was never accepted by the CPU.