Connecting Siemens MP377 to S7-400 Stations via CP443-1 Industrial Ethernet
1. Problem Statement
A typical greenfield configuration consists of multiple S7-400 stations, each equipped with a CP443-1 communications processor (order number 6GK7 443-1EX20-0XE0 in the case discussed here), networked over Industrial Ethernet. Adding one or more MP377 Multi Panels for HMI visualization is required without modifying the STEP 7 / NetPro hardware configuration of the existing PLC stations. The challenge is twofold:
- Inserting the MP377 into the existing Ethernet subnet in NetPro would force a full project recompile, re-download of the S7-400 hardware configuration, and a CPU stop/start on every station.
- The CP443-1 EX20 variant exposes two physical RJ45 ports fed by an internal 2-port managed switch, which tempts the integrator to daisy-chain the HMI panels in series. While this topology is valid for PROFINET IO with device-level ring (DLR) or linear topology, it creates a different class of problems for the S7 communication protocol used by WinCC Flexible.
This article documents a method that bypasses the NetPro change, uses the CP443-1's IP stack directly, and avoids the failure modes introduced by a naive daisy chain.
2. Prerequisites
| Item | Specification | Notes |
|---|---|---|
| PLC | SIMATIC S7-400 (any CPU 412/414/416/417) | OP connection budget varies by CPU |
| Communications processor | CP443-1, 6GK7 443-1EX20-0XE0 (or EX30/GX20/GX30) | Firmware ≥ V2.5 recommended for 2-port switch |
| HMI | SIMATIC MP377 (12" or 15" TFT, Key or Touch) | WinCC Flexible 2008 SP5 runtime |
| Engineering | STEP 7 V5.5 + SP4 / SP5, WinCC Flexible 2008 SP5 | Same project not required |
| Ethernet switch | SCALANCE XC-200, XB-200, or XR-300 family | Managed switch with port statistics and SNMP preferred |
| Cabling | Cat5e / Cat6 STP, RJ45 | Industrial-graded (e.g., 6XV1 840-2AH10) |
| IP subnet | Class B/C private, e.g., 192.168.0.0/24 | All devices on same subnet for S7 routing |
3. CP443-1 (6GK7 443-1EX20-0XE0) Hardware Architecture
The CP443-1 integrates an ERtec 200-based Ethernet controller with an additional on-board 2-port real-time switch. The two RJ45 jacks (P1 and P2) are independent physical ports that share one MAC and one IP address assigned to the CP. The internal switch is a store-and-forward switch with cut-through optimization and supports:
- 10/100 Mbit/s, full or half duplex, auto-negotiation / auto-crossover
- PROFINET IO controller / device with linear topology
- PROFINET CBA (component-based automation)
- S7 communication, S5-compatible communication (SEND/RECEIVE), FETCH/WRITE, OPEN TCP/ISO
- PG/OP routing across subnets
- SNMPv1/v2, LLDP, Web diagnostics
Important: although the CP443-1 has an integrated switch, it is a managed switch that participates in PROFINET device discovery. The switch is configured through STEP 7 HW Config, not through WinCC Flexible. A CP443-1 can manage at most one IP address; therefore each S7-400 station is reachable through a single IP endpoint regardless of which physical port the Ethernet frame arrives on.
3.1 Diagnostic LED Map (EX20)
| LED | State | Meaning |
|---|---|---|
| SF (red) | On | Group error, diagnostic buffer has entry |
| BF (red) | On / flashing | Bus fault, no link or no S7 connection |
| LINK 1 / 2 (green) | On | 100 Mbit/s link established on P1 / P2 |
| RX/TX 1 / 2 (yellow) | Flashing | Activity on P1 / P2 |
| RUN (green) | Flashing | CP in STOP with configuration present |
| RUN (green) | On | CP running, S7 communication active |
4. Network Topology Options
Three physical topologies are feasible. The selection drives whether a NetPro change is mandatory.
4.1 Option A — Star with Managed SCALANCE Switch (Recommended)
Every CP443-1 and every MP377 lands on its own port of a central managed switch. The switch becomes the SPAN (single point of access) for diagnostics via Wireshark, SNMP, or the SCALANCE Web UI. This topology requires no change in the PLC project.
4.2 Option B — Linear / Daisy Chain using CP443-1 Port 2
Each PLC's Port 2 is wired to the next PLC's Port 1. The chain's end device is the only one connected to the central switch where the MP377 panels sit. The PROFINET linear topology would technically be valid, but S7 connection handling on the CP443-1 breaks down — see Section 5.
4.3 Option C — PG/OP Routing via Existing NetPro Entry
If the user is willing to add a single PC station with WinCC Flexible Runtime in NetPro, the routing is configured inside STEP 7 and the MP377 HMI tag database is built against that routing entry. This option is mentioned only for completeness; it is not aligned with the no-NetPro-change requirement of the original question.
5. Why Direct Daisy-Chain Fails for S7 Communication
Although PROFINET IO defines a physical linear topology with cut-through switching, S7 communication (the protocol used by WinCC Flexible) is a connection-oriented, TCP/IP-based protocol that uses the CP443-1's IP endpoint. The two ports are not a true layer-2 switch from the S7 communication viewpoint:
- Single TCP listener: The CP443-1 EX20 opens one S7 connection endpoint at ISO-on-TCP port 102 (TSAP). Both physical ports route into that same listener. If two switches/hubs upstream send an S7 packet through different paths, the listener is fine, but the CPU work-load for processing connection establishment is centralized on the CPU hosting the CP.
- TCP retransmission bursts: In a linear chain, a single cable break between PLC2 and PLC3 isolates PLC3 and PLC4 from any HMI connected to PLC1's Port 1. The remaining PLCs still have link on the adjacent CP, so the integrated switch keeps bridging MAC tables, but the S7 connection state is broken.
- CPU work-memory load on the chain's last device: The CP443-1 firmware passes every received S7 frame to the CPU via the SFB/SFC mechanism. The final CP in the chain has to forward all four stations' broadcast ARP traffic and any S7 broadcast (e.g., S7 search, programming request). This saturates the CPU's process image exchange. In practice, response times degrade by 30–60% when a 4-station chain is loaded with 3 OP connections per station.
- No redundancy protocol: CP443-1 EX20/EX30 do not support MRP (Media Redundancy Protocol) on the integrated switch. MRP requires a SCALANCE ring or MRP-capable devices. A linear chain therefore has zero redundancy.
- NetPro planning conflict: Even though the user wants to skip NetPro, daisy-chaining creates an implicit topology that NetPro would otherwise model. When the user later opens the project, the offline topology and the physical topology will not match, causing HW Config to issue a warning at every recompile.
6. Recommended Topology: Star with Managed SCALANCE Switch
A managed switch (SCALANCE XC-208, XB-208, or higher) provides:
- Electrical isolation between PLC and HMI segments (cable faults contained to one port)
- Port statistics (CRC errors, discards, late collisions) accessible via Web UI / SNMP
- LLDP topology auto-discovery visible in STEP 7
- Optional MRP ring when combined with a redundant SCALANCE
- VLAN support to separate PROFINET IO traffic from HMI traffic (e.g., VLAN 10 for S7, VLAN 20 for HMI)
The CP443-1 P1 connects to the SCALANCE. The MP377's PROFINET port (label "PN" on the rear) also connects to the SCALANCE. The CP443-1 P2 can be left unused or used to daisy-chain a single ET200S PN station on its own subnet.
7. IP Address Planning
Use a single subnet for the entire HMI/PLC network. The S7 protocol does not need routing across subnets if every device shares the same /24 subnet. A typical scheme for 4 PLCs + 4 MP377s:
| Device | IP | Subnet mask | Router | Role |
|---|---|---|---|---|
| CP443-1 (PLC1) | 192.168.0.11 | 255.255.255.0 | 0.0.0.0 | S7 server |
| CP443-1 (PLC2) | 192.168.0.12 | 255.255.255.0 | 0.0.0.0 | S7 server |
| CP443-1 (PLC3) | 192.168.0.13 | 255.255.255.0 | 0.0.0.0 | S7 server |
| CP443-1 (PLC4) | 192.168.0.14 | 255.255.255.0 | 0.0.0.0 | S7 server |
| MP377 #1 | 192.168.0.21 | 255.255.255.0 | 0.0.0.0 | Operator panel for PLC1 |
| MP377 #2 | 192.168.0.22 | 255.255.255.0 | 0.0.0.0 | Operator panel for PLC2 |
| MP377 #3 | 192.168.0.23 | 255.255.255.0 | 0.0.0.0 | Operator panel for PLC3 |
| MP377 #4 | 192.168.0.24 | 255.255.255.0 | 0.0.0.0 | Operator panel for PLC4 |
| SCALANCE XC-208 | 192.168.0.1 | 255.255.255.0 | 0.0.0.0 | Management |
Reserve 192.168.0.2 … 192.168.0.10 for engineering PG/PC access and for spare HMI stations. Avoid .255 (broadcast) and .0 (network address).
8. WinCC Flexible Connection Configuration (No NetPro)
WinCC Flexible 2008 SP5 can be configured to address the CP443-1 by IP address only. The S7 connection is established by the runtime without an entry in the PLC's NetPro, because S7 connections are negotiated dynamically by the active partner (the HMI) using the IP of the passive partner (the CP443-1).
8.1 Create the connection in WinCC Flexible
- Open WinCC Flexible ES, open the MP377 project.
- In the project tree, expand Connections → right-click → Add new connection.
- Set Communication driver =
SIMATIC S7 300/400. - Set HMI device = the local MP377 station.
- Disable Configured at the PLC end if the S7 connection is to be configured only at the HMI side.
- Fill in the connection parameters:
PLC name : PLC1 IP address : 192.168.0.11 IP port (default) : 102 (ISO-on-TCP) Rack : 0 Slot : 3 (slot of CP443-1 in the S7-400 UR2/UR1) Connection name : S7_HMI_PLC1 Connection type : S7 connection (TCP/IP) TSAP (local) : leave default TSAP (remote) : leave default (CP443-1 will accept any) - Repeat for PLC2/3/4, each with its own IP and the slot where the CP443-1 is inserted.
8.2 Why the connection works without NetPro
WinCC Flexible uses the S7 communication active partner role. When the MP377 boots and starts the configured connection, it opens a TCP socket to 192.168.0.11:102 and sends an S7 CR (Connection Request) PDU. The CP443-1 acts as a passive S7 server and accepts the CR provided the connection resources are not exhausted. The S7 connection is therefore instantiated entirely from the HMI side, and the PLC's NetPro database does not need an explicit S7 connection object referencing the HMI.
However, the connection does consume one of the CPU's OP connection resources. The CPU is the ultimate arbiter. The CP443-1 forwards the connection request to the CPU via the S7 backplane bus. The CPU checks its free OP resources and either accepts or rejects the connection.
9. S7-400 OP Connection Budget
Each S7-400 CPU has a fixed pool of communication resources divided into PG, OP, and S7 connection classes. The OP class is the one consumed by the HMI. Approximate budgets:
| CPU | Max OP connections | Max S7 connections (total) |
|---|---|---|
| CPU 412-1 / 412-2 | 8 | 16 |
| CPU 414-2 / 414-3 | 16 | 32 |
| CPU 416-2 / 416-3 | 24 | 48 |
| CPU 417-4 | 32 | 64 |
When more than one MP377 connects to a single PLC, every panel consumes one OP resource. Four MP377 panels talking to one CPU 414-2 would use 4 of the 16 OP connections. Always check CPU > Properties > Communication in STEP 7 to confirm the configuration. The resource counters are available in the CPU's diagnostic buffer and in the SFC51 (SSL_ID W#16#0131 / W#16#0132).
9.1 Diagnostic block to read OP connection state
// STL example in OB1 - read OP connection summary
CALL SFC 51 // RDSYSST
REQ := TRUE
SSL_ID := W#16#0132 // Communication status summary
INDEX := W#16#0000
RET_VAL := MW 100 // return code
BUSY := M 101.0
SZL_HEADER := DB10.DBD0
DATA := P#DB10.DBX8 BYTE 64
// In DB10:
// Byte 0..1 : SZL header
// Byte 2..3 : Number of communication connections (max)
// Byte 4..5 : Number of communication connections (established)
// Byte 6..7 : Number of OP connections (max)
// Byte 8..9 : Number of OP connections (established)
10. Area Pointers and Tag Configuration
Once the connection is up, WinCC Flexible exchanges data using area pointers and process tags mapped to S7 data blocks or peripheral areas. Typical area pointer types used by an MP377:
| Area pointer | Purpose | DB layout (S7) |
|---|---|---|
| Coordination | Coordination byte for HMI life-bit, screen number, etc. | DB-M 0.0 (1 byte), HMI writes status bits |
| Project ID | Verifies HMI project matches the S7 program | DB 1 from DBB 0 to DBB 7, configured at both ends |
| Date/Time | CPU pushes date/time to HMI | DB 2, 8 bytes BCD timestamp |
| Alarm / bit message | Bit-triggered alarms from S7 bit memory | DB 3 with n bytes of bit trigger words |
| Recipe | Recipe data block | Custom DB layout, see WinCC Flexible recipe editor |
The number of tags per connection is governed by the WinCC Flexible license. A 256-tag license is standard; larger applications need 1024, 2048, or 4096-tag licenses. Each process tag corresponds to a symbolic S7 address or an absolute address in a data block.
10.1 Configuring a process tag
- Open the WinCC Flexible project for the MP377.
- Right-click Tags → New tag.
- Choose connection =
S7_HMI_PLC1. - Address:
DB100.DBW0(Data Block 100, Word 0). - Acquisition cycle: 1 s (operator panel); 500 ms for fast process data.
- Limit values: define warning and alarm thresholds here to keep PLC scan time free of comparisons.
11. Commissioning and Verification
11.1 Power-on sequence
- Power the SCALANCE switch and verify all link LEDs are on for the CP443-1 ports and the MP377 ports.
- Power the S7-400 stations. The CP443-1 takes about 30 s to come up to RUN. Watch the LINK 1 LED and the RUN LED transition from slow-flash to steady-on.
- Power the MP377 panels. Allow 60 s for the Windows CE / WinCC Flexible runtime to boot.
11.2 Connectivity test from a PG/PC
- Connect an engineering PG to the SCALANCE.
- Open a command prompt and ping each CP443-1 and each MP377 IP address. A successful ping confirms layer-3 reachability; it does not confirm S7 connectivity.
C:\> ping 192.168.0.11
Reply from 192.168.0.11: bytes=32 time=3ms TTL=64
C:\> ping 192.168.0.21
Reply from 192.168.0.21: bytes=32 time=4ms TTL=64
- Open STEP 7 with the PLC project, go to Online > Accessible Nodes. The MP377 IP address should appear in the list because WinCC Flexible's S7 driver performs a station search on the same subnet.
- Open WinCC Flexible Runtime on the MP377. On the start screen, the Connections status should show all four S7 connections as Established.
11.3 Verification checklist
| Check | Expected | Method |
|---|---|---|
| CP443-1 RUN LED | Steady green | Visual |
| BF LED | Off | Visual |
| SCALANCE port status | All ports Up, 100 Mbit/s, full duplex | Web UI > Information > Port Statistics |
| OP connection count on CPU | +1 per MP377 connected | STEP 7 Online > Diagnostics > Communication |
| WinCC Flexible connection status | All connections green/established | Runtime screen |
| Tag update rate | Matches configured cycle (e.g., 1 s) | Cross-check with watch table in STEP 7 |
| CPU work memory | Stable, no growth in communication load | CPU diagnostic buffer |
12. Troubleshooting Matrix
| Symptom | Likely root cause | Action |
|---|---|---|
| MP377 displays "Connection interrupted" to all PLCs | SCALANCE not powered or wrong VLAN | Check SCALANCE power; verify port VLAN settings |
| MP377 connects to PLC1 but not to PLC2/3/4 | Duplicate IP, or CP443-1 BF LED on | Run ARP scan; check CP443-1 BF LED; check cable |
| CP443-1 BF LED on, no S7 connection possible | IP address conflict or wrong subnet | Verify CP443-1 IP via display; remove duplicate |
| Connection drops intermittently | Broadcast storm from daisy chain; CPU resource starvation | Migrate from daisy chain to star topology |
| "Project ID mismatch" alarm on HMI | Project ID area pointer configured differently on HMI vs. PLC | Match the 8-byte project ID string in both projects |
| Tags show quality BAD in WinCC Flexible | S7 connection not established or wrong DB number | Check connection status, verify DB exists in PLC |
| WinCC Flexible limits to 16 connections | Hard limit of the runtime version | Verify number of connections; some MP377 firmware versions cap simultaneous connections |
| PLC diagnostic buffer: "No resources for OP connection" | CPU OP resource budget exhausted | Free unused OP resources; check SFC51 diagnostics |
| High CPU scan time on the last PLC in the chain | Daisy chain forwarding all S7 broadcasts | Convert to star topology with SCALANCE |
| MP377 boots to "Transfer" mode after project download | Boot loader setting < Boot source | Set Control Panel > OP > Boot source > Local or Automatic |
13. Field-Proven Notes
- Always define the MP377 IP address in the Control Panel (Start > Settings > Control Panel > S7 Transfer Settings) before starting WinCC Flexible Runtime. Wrong settings cause the runtime to bind to 0.0.0.0 and miss all S7 connection attempts.
- If the user insists on daisy-chaining for cable-cost reasons, the smallest acceptable compromise is: one SCALANCE at the start of the line, daisy-chain ET200 stations (PROFINET IO) downstream of the SCALANCE, and connect the MP377s to the SCALANCE. This isolates the HMI traffic from the PROFINET chain.
- For projects with more than 8 MP377 panels, prefer a redundant SCALANCE ring (MRP) with two SCALANCE XC-200 switches. MRP is supported on CP443-1 EX30 and GX20/GX30 but not on EX20.
- PG/OP routing across subnets: if PLC1 must reach MP377 on a different subnet, configure PG/OP routing in NetPro. This is one of the few cases where a NetPro entry is unavoidable — but it can be added on the S7-400 station alone, without touching the HMI project.
- Watch out for duplicate IP detection: the CP443-1 EX20's integrated switch will shut down the port when it sees its own MAC on another port. This is the duplicate IP check feature. If two CP443-1 share an IP by mistake, all four stations go offline simultaneously.
- WinCC Flexible 2008 SP5 supports 16 connections in the standard license. Sufficient for 4 PLCs × 1 MP377 + 12 spare. The SP5 update is critical; earlier SPs cap at 8 connections.
14. Frequently Asked Questions
Do I really need to change the STEP 7 / NetPro project to add the MP377?
No. Configure the connection in WinCC Flexible using the IP address of the CP443-1 (e.g., 192.168.0.11) and the slot where the CP is inserted. The S7 connection is initiated by the HMI and accepted by the CP443-1 using the CPU's free OP resources, without requiring a NetPro entry.
Can I daisy-chain the four S7-400 stations using the CP443-1's two ports and put the MP377 on the end?
PROFINET IO linear topology supports it, but for S7 communication (used by WinCC Flexible) the practice is discouraged. The chain's last device becomes a broadcast sink, the CPU work memory on the last CP443-1 saturates, and a single cable break isolates half the network. Use a star topology with a SCALANCE switch instead.
How many MP377 panels can a single S7-400 CPU serve?
It depends on the CPU's OP connection budget. A CPU 414-2 supports 16 OP connections; a CPU 416-2 supports 24; a CPU 417-4 supports 32. Each MP377 consumes one OP connection. Verify the limit via STEP 7 > CPU Properties > Communication or by reading SSL W#16#0132 with SFC51.
What IP port does the S7 communication use on the CP443-1?
ISO-on-TCP port 102 (decimal). WinCC Flexible uses this port by default; do not change it unless you have a firewall that requires a custom port. ISO transport (RFC 1006) is the framing protocol on top of TCP 102.
What happens if I change the CP443-1's IP address after the MP377 is running?
The MP377's existing S7 connection drops. The runtime will retry every 10 s (default). When the retry succeeds, the connection is re-established. To avoid nuisance trips during commissioning, fix the IP of every CP443-1 and every MP377 in the SCALANCE's port configuration (port security) so they cannot be changed by accident.
Can the MP377 serve as a gateway to all four PLCs from a single panel?
Yes. Configure four S7 connections in WinCC Flexible, each pointing to a different CP443-1 IP. The MP377 can display data from all four PLCs on one screen. The limit is the WinCC Flexible connection count (16 with SP5) and the available tags on the panel's license.