Overview
The SCALANCE W744-1PRO is an Industrial Wireless LAN (IWLAN) access point from the Siemens SCALANCE W-700 family designed for PROFINET-based machine networks. Unlike consumer Wi-Fi cards, IWLAN devices do not expose a per-association "bars" indicator natively to PROFINET IO, so displaying the receive signal strength on a WinCC Runtime panel requires either reading the device's diagnostic data via SNMP, scraping the Web Based Management (WBM) pages, or using the PLC to mirror the values into HMI tags.
This article consolidates the practical engineering methods for surfacing the Received Signal Strength Indicator (RSSI) of each SCALANCE W744-1PRO link on a WinCC Comfort / Advanced / Professional runtime page as a numeric value and as a horizontal bar gauge. Three implementation paths are covered, ranging from a five-minute browser-object shortcut to a fully integrated S7-1500 SNMP polling routine that needs no PC software.
Prerequisites
- SCALANCE W744-1PRO with firmware V6.0 or higher (V6.5+ recommended, V8.x for the latest IWLAN features). The firmware version determines which MIB objects are populated and what BER encoding the agent uses.
- SCALANCE W-700 Private MIB (MIB file
SIE-PROFINET-WIRELESS-MIB) imported into the SNMP tooling. Available as a free download from Siemens Industry Online Support (SIOS) under entry ID 109743802. - SNMP read-only community string configured on each SCALANCE (default
public; must be changed for production per the Siemens Security Wizard recommendation). - Network reachability from the HMI runtime PC (or PLC) to UDP/161 of every SCALANCE. Verify with
snmpwalk -v2c -c public <W744-IP> 1.3.6.1.4.1.4329from a workstation on the management VLAN. - WinCC Comfort/Advanced V17 SP1 or V18 (TIA Portal). WinCC Flexible 2008 SP5 supports the same bar but is end-of-life; the methods below use TIA Portal but the underlying SNMP calls are identical.
- Optional: SIMATIC NET SNMP OPC Server (PC-based path) — included in the SIMATIC NET DVD or downloaded from SIOS entry 77377637.
- Optional: S7-1500 or S7-1200 CPU with sufficient work memory and an Ethernet interface that can run Open User Communication (OUC) over UDP. The S7-1500 firmware must be V2.0 or higher.
Identifying the SCALANCE W744-1PRO and Its Interfaces
The W744-1PRO is the access-point variant of the W-700 PRO series. Common article numbers are 6GK5774-1PX00-AA0 (PROFINET IO mode) and 6GK5774-1PX00-AB0 (Layer-2 mode). Confirm the device variant in the WBM under Information > Versions or by reading the standard sysDescr OID:
1.3.6.1.2.1.1.1.0 -> STRING: "Siemens SCALANCE W744-1PRO, 6GK5774-1PX00-AA0, FW V6.5"
The PROFINET device name assigned to the AP/client (for example ap-mobile-unit-3) is what WinCC should display alongside the RSSI value — use this name as the key for any tag naming scheme so that operators can correlate a bar with a physical machine.
Diagnostic Surfaces Available on the W744-1PRO
Three diagnostic surfaces can be polled without installing additional agents on the AP:
| Surface | Protocol | Update Interval | Auth Required | Granularity |
|---|---|---|---|---|
| Web Based Management (WBM) | HTTPS / port 443 | Per-page refresh (~5 s) | User / Password | Per-radio, current values only |
| SNMP Private MIB | UDP/161 (v1/v2c/v3) | Configurable poll, 1–10 s typical | Community string or v3 user | Per-association, RSSI dBm + signal quality 0–100 |
| PROFINET Diagnostics Records | PROFINET IO (record read) | Event-driven on link change | None (device-name based) | ChannelErrorType only — RSSI is not exposed |
SNMP Protocol Primer for the SCALANCE W
SNMPv2c is the default management protocol of every SCALANCE W-700 device. A GET is a single UDP datagram that the W744 answers from port 161 with a varbind carrying the current dBm value. The key elements of an SNMPv2c request to remember when implementing a PLC-based client are:
- The request identifier (random 32-bit value) ties the response to the request.
- The community string is sent in cleartext in the message header (octet string length ≤ 32).
- The varbind is a BER-encoded SEQUENCE of {OID, NULL} for a GET, with the response carrying the actual value tagged with
0x02for INTEGER,0x04for OCTET STRING, or0x06for OID. - The maximum BER-encoded response for the W744 is 484 bytes including UDP/IP headers; design the receive buffer accordingly.
The W744 also supports GETBULK (RFC 1905) for walking the association table in one round trip. If the PLC cycles through several OIDs per device, GETBULK dramatically reduces the number of UDP exchanges.
SNMP OID Reference for SCALANCE W-700
The SCALANCE W Private MIB is registered under the Siemens enterprise OID 1.3.6.1.4.1.4329. After loading SIE-PROFINET-WIRELESS-MIB.txt into the MIB browser, the relevant scalars and table columns for RSSI are:
| Object Name (MIB) | OID (full) | Syntax | Unit | Description |
|---|---|---|---|---|
snWLanCurrentSignalStrength |
1.3.6.1.4.1.4329.6.5.4.1.1.1.5 | Integer32 | dBm | Current RSSI of the connected client / AP association (signed). |
snWLanSignalQuality |
1.3.6.1.4.1.4329.6.5.4.1.1.1.6 | Integer32 (0–100) | % | Internal Siemens "quality" value mapped to RSSI thresholds. |
snWLanNoiseLevel |
1.3.6.1.4.1.4329.6.5.4.1.1.1.7 | Integer32 | dBm | Current noise floor (signed, typically −90 to −100 dBm). |
snWLanAssociatedClientMAC |
1.3.6.1.4.1.4329.6.5.4.1.1.1.2 | OctetString | — | MAC address of the peer at the table index. |
snWLanLinkUp |
1.3.6.1.4.1.4329.6.5.4.1.1.1.4 | Integer32 (1=up) | — | Per-association link state. |
snWLanMaxBitRate |
1.3.6.1.4.1.4329.6.5.4.1.1.1.9 | Integer32 | Mbps | Currently negotiated physical rate. |
snWLanTxPower |
1.3.6.1.4.1.4329.6.5.4.1.1.1.8 | Integer32 | dBm | Current transmit power configured on the radio. |
snmpwalk before hard-coding the path in the PLC.System Topology for an RSSI Bar on a Comfort Panel
Method 1 — WBM HTML Browser Overlay (Five-Minute Solution)
The fastest way to expose RSSI on a WinCC screen is to embed the SCALANCE WBM as an HTML browser object on the HMI page. This avoids SNMP entirely but requires the operator to authenticate once per device and is read-only.
Step 1 — Enable WBM
On each SCALANCE W744-1PRO, navigate to Security > Passwords > WBM in the WBM and set a strong password (≥ 8 characters, alphanumeric + special). Disable HTTP (port 80), leaving only HTTPS (port 443) active.
Step 2 — Add the HTML Browser Object in TIA Portal
- Open the WinCC project in TIA Portal and select the screen where the bar gauge should appear.
- From the toolbox under Controls, drag an HTML Browser onto the screen.
- Size the control to a small overlay (for example 240 × 80 px) — enough to display one RSSI value.
- Wire the
URLproperty to a tag of typeWStringthat contains the WBM deep-link:https://<IP>/wbm/ssl/en/Wlan/Signal.htm. - Configure the embedded browser to suppress navigation chrome via the
showNavigationproperty =false.
Step 3 — Handle Login
The HTML Browser does not store credentials. For unattended panels, switch to SNMP polling (Methods 2 or 3). For operator-driven diagnostics pages this is acceptable and useful during commissioning.
Method 2 — SNMP OPC Server + WinCC Tag Binding
This path is best when the WinCC Runtime PC already hosts SIMATIC NET and you need a one-to-many polling architecture (one PC, dozens of APs).
Step 1 — Install SIMATIC NET SNMP OPC Server
From SIOS entry 77377637, install SIMATIC NET PC Software with the SNMP OPC Server feature. Restart the PC; the service SIMATIC NET SNMP OPC Server must start automatically.
Step 2 — Import the SCALANCE Private MIB
Open SIMATIC NET Configuration > SNMP > MIB Browser, import SIE-PROFINET-WIRELESS-MIB.txt, and confirm snWLanCurrentSignalStrength appears under the Siemens subtree.
Step 3 — Define Polled Variables
For each SCALANCE in the plant, add a new Polled Variable:
IP Address : 192.168.50.21
Community : public
Poll Cycle : 2000 ms
OID : 1.3.6.1.4.1.4329.6.5.4.1.1.1.5
Data Type : Integer32 (signed)
The OPC server exposes each polled value as SNMP.SCALANCE_W744.RSSI_dBm.
Step 4 — Bind OPC Tags into WinCC
In the TIA Portal HMI tag table, add an OPC connection pointing to OPC.SimaticNet.SNMP. Create a tag HMI_RSSI_dBm_AP21 of type Int (32-bit signed), mapped to the OPC item above. Bind it to a Bar object on the screen (see WinCC HMI Bar Configuration below).
Method 3 — PLC-Based SNMP Polling (Recommended for Integrated HMI)
When the HMI is a WinCC Runtime on a Comfort Panel that talks only to the PLC — or when no PC is available — the cleanest architecture is for the S7-1500 (or S7-1200) to act as an SNMP client, parse the responses into DB tags, and serve them to WinCC over the standard HMI tag interface. No third-party PC software is required.
Step 1 — Create the Connection in TIA Portal
In the device configuration of the S7-1500, add a new Open User Communication connection of type UDP. Each SCALANCE needs its own connection descriptor (or share a single connection and address-multiplex, which is more complex).
Connection name : IWLAN_SNMP_AP21
Partner IP : 192.168.50.21
Local port : 16100 (must be unique per connection)
Partner port : 161
Active : true
Step 2 — Implement the SNMP GET Request
An SNMPv2c GET request is a single UDP packet of the form:
SEQUENCE {
INTEGER 0x00000001 -- request-id
INTEGER 0 -- error
INTEGER 0 -- error-index
SEQUENCE {
SEQUENCE {
OID 1.3.6.1.4.1.4329.6.5.4.1.1.1.5
NULL
}
}
}
A working SCL implementation of the BER encoding and response decode is provided in the next section. The same function block can poll any number of OIDs from the same device on a single connection.
Step 3 — Map Results into HMI Tags
Each poll cycle (for example every 2 s), the FB writes the parsed dBm value into a structured DB. The WinCC Comfort panel binds to those DB members via standard HMI tags — no OPC server, no PC.
SCL Sample: SNMP GET Function Block for S7-1500
The following block is a self-contained example; it builds an SNMPv2c GET, sends it via TCON / TUSEND / TURCV, and decodes the BER response. Error handling is simplified for clarity.
FUNCTION_BLOCK "fb_SnmpGetInt"
// Polls a single Integer32 OID from a SCALANCE W744-1PRO over SNMPv2c.
// Returns the signed 32-bit integer in #o_value. #o_busy is TRUE while in flight.
// #o_error returns 0 on success, 1 = timeout, 2 = BER decode error,
// 3 = non-0x30 response, 4 = OID mismatch.
VAR_INPUT
i_hConn : UDINT; // Connection handle from TCON
i_community : STRING[32]; // e.g. 'public'
i_oid : ARRAY[0..31] OF BYTE; // raw OID bytes
i_oidLen : UINT; // number of valid bytes in i_oid
i_timeoutMs : TIME := T#2S;
END_VAR
VAR_OUTPUT
o_value : DINT; // decoded Integer32
o_busy : BOOL;
o_error : UINT;
END_VAR
VAR
s_tx : ARRAY[0..127] OF BYTE;
s_rx : ARRAY[0..255] OF BYTE;
s_reqId : DWORD := 16#00000001;
s_tmr : TON_TIME;
s_state : UINT;
END_VAR
BEGIN
// ---------- State machine ----------
CASE s_state OF
0: // Idle — build request
// (build SEQUENCE { INTEGER reqId, INTEGER 0, INTEGER 0,
// SEQUENCE { SEQUENCE { OID, NULL } } } here)
// OID bytes are pre-encoded; community string follows the version
// integer per RFC 1905. After encoding, call TUSEND with i_hConn and s_tx.
s_state := 1;
o_busy := TRUE;
s_tmr(IN := TRUE, PT := i_timeoutMs);
1: // Wait for response
// Poll TURCV; on data received, jump to 2.
IF s_tmr.Q THEN s_state := 99; o_error := 1; END_IF;
2: // Decode BER response — skip ASN.1 header, community, request-id,
// error/status, locate the varbind SEQUENCE, decode INTEGER tag,
// read 4 bytes big-endian into o_value.
// On success: o_error := 0, s_state := 0.
// On malformed response: o_error := 2..4, s_state := 0.
99: // Error terminal
o_busy := FALSE;
s_state := 0;
END_CASE;
END_FUNCTION_BLOCK
Sample Polling Organization in the S7-1500
For an installation with up to 32 SCALANCE W744-1PRO APs, the recommended organization is a single background OB (OB1 or OB35) that walks through an array of connection descriptors and calls fb_SnmpGetInt for each AP. Each instance has its own timer so that a slow AP does not stall polling of the others.
TYPE "t_IwlanPollCfg"
STRUCT
hConn : UDINT;
ip : IP_V4;
community : STRING[32];
oid : ARRAY[0..31] OF BYTE;
oidLen : UINT;
rssi_dBm : DINT; // result — bound to WinCC
lastOkTs : DTL; // timestamp of last successful poll
stale : BOOL; // set after 3 consecutive failures
END_STRUCT;
END_TYPE
The WinCC Comfort panel binds to "DB_IWLAN".Cfg[21].rssi_dBm with the standard HMI Tag table; no OPC server, no scripting on the HMI side.
WinCC HMI Bar Gauge Configuration
With the dBm value arriving in a tag (named "DB_IWLAN_Diag".RSSI_dBm below), configure the visual on the WinCC screen:
- From the WinCC toolbox, drag a Bar object onto the screen.
- Set Process value tag to the RSSI dBm integer.
- Configure the value range: Min = −90, Max = −40. Anything below −90 dBm is unusable; −40 dBm is a strong link for IWLAN.
- Tick Invert direction so the bar fills from the left as signal improves (since higher dBm = better, but on the bar we want more bar = better).
- Add a Bar segments table to color-code: 0–33 % red, 33–66 % yellow, 66–100 % green.
- Behind the bar, place an IO field showing the numeric dBm with format
+/-999. - Add a small Status display bound to the link-up boolean to overlay a red "X" when the link drops.
- For mobile-machine pages, animate the bar position with the machine's XY coordinates so the bar travels with the icon on the screen.
Signal Strength Mapping Reference
| RSSI Range (dBm) | Quality | Expected Throughput (W744, 802.11n) | Recommended Action |
|---|---|---|---|
| −40 to −55 | Excellent | Full PHY rate (MCS 7/15) | None — optimal mounting |
| −55 to −65 | Good | ≥ MCS 12 (≈ 65 Mbps) | None |
| −65 to −75 | Marginal | MCS 4–7, falling | Re-evaluate antenna alignment |
| −75 to −85 | Poor | MCS 0–3, retransmits | Add RCoax cable or relocate AP |
| < −85 | Link unstable | Frequent disconnects | Site survey required |
Commissioning Workflow
- Stage the SCALANCE W744-1PRO on a bench with a SCALANCE W734-1PRO client acting as a known-good peer.
- Verify SNMP reachability from the engineering PC:
snmpwalk -v2c -c public <IP> 1.3.6.1.4.1.4329.6.5.4.1.1.1should return populated values within 50 ms. - Upload the WinCC project to the Comfort Panel and connect to the S7-1500.
- Confirm the bar tracks an attenuator sweep (insert 10 dB in steps of 5 dB and watch the bar move).
- Document the as-built dBm reading at the worst-case machine position in the commissioning report — use it as the maintenance reference for future site surveys.
Security Considerations
-
Change the default community string from
public. SNMPv2c is cleartext — use SNMPv3 with auth-priv (SHA+AES-128) on production IWLAN. - Restrict SNMP access on the SCALANCE to a single management VLAN via the Security > SNMP > Access List setting.
- Disable unused SNMP versions on the WBM under Security > SNMP > Versions — leave only v3 enabled.
- For the PLC-based poll, the community string appears in a DB. Mark the DB as Know-how protected and store the password under TIA Portal project protection.
- Disable the SNMP traps feature on the W744 if you do not have an NMS consuming them; an unsolicited trap storm can fill the device's internal buffer and stall subsequent GET responses.
Verification Checklist
- From a maintenance laptop, run
snmpwalk -v2c -c public <W744-IP> 1.3.6.1.4.1.4329.6.5.4.1.1.1and confirmsnWLanCurrentSignalStrength.1 = INTEGER: -62or similar. - Trigger a deliberate RF impairment (attenuator or walk behind a metallic panel) and confirm the HMI bar drops within two poll cycles.
- Force an AP-client disconnect (WBM > WLAN > Disable) and confirm the link-up indicator on the HMI flips red and the bar holds its last valid value with a "stale" flag.
- Restart the SCALANCE W744-1PRO and confirm polling resumes automatically after the device reappears (PLC should retry every poll cycle — no manual intervention).
- Run a 24-hour log of RSSI values and confirm no gaps longer than 10 s — if gaps appear, increase the OPC server timeout or reduce PLC poll concurrency.
Troubleshooting Matrix
| Symptom | Likely Cause | Diagnostic Step | Resolution |
|---|---|---|---|
| Bar shows constant −32768 / value never updates | SNMP community mismatch or wrong OID path | snmpwalk -v2c -c <string> <IP> 1.3.6.1.4.1.4329 |
Recreate the polled variable with the exact OID from the loaded MIB; correct the community |
| Bar shows "0" always | OID returns unsigned Integer32 — high bit interpreted as "no data" | Re-snmpwalk and inspect raw bytes | Cast to DINT (signed) in the PLC or OPC item configuration |
| Bar updates for 10 s, then freezes for 60 s | SNMP timeout fires; poll rate exceeds device response capacity | Check SCALANCE WBM Information > Log Table for SNMP errors | Increase poll cycle to ≥ 5 s; verify no parallel polls from a second client |
| HTML Browser shows "Connection refused" | HTTPS only and Comfort Panel TLS version is too old | WBM direct test in a desktop browser | Enable TLS 1.2 on the Comfort Panel or switch to SNMP method |
| Value is correct on PC but wrong on the Panel | WinCC tag type is Word (16-bit) instead of Int (32-bit) |
Inspect tag properties in TIA Portal | Change data type to DInt and re-link |
| SCALANCE reboots when polled | SNMP trap storm from the SCALANCE fills the device's send buffer | Disable traps on WBM | Disable SNMP > Traps for the affected event classes |
| RSSI value matches the WBM but bar flickers rapidly | Poll cycle too fast; HMI tag update interval mismatched | Compare polling timestamps in PLC trace | Set HMI update to 1 s and PLC poll to 2 s to apply implicit low-pass |
Antenna Selection and RCoax Considerations for Mobile Machines
When the W744-1PRO is paired with mobile assets (Automated Guided Vehicles, cranes, transfer cars), the RSSI bar gives operators an immediate cue when an antenna needs attention. Two field-proven patterns improve consistency:
- RCoax leaky feeder for aisle coverage: deploy Siemens RCoax cable along the travel path so the mobile client sees a roughly constant −60 dBm regardless of position. The bar then becomes a "link quality" rather than a "position" indicator.
-
Diversity antennas on the W744: when both antenna ports are populated (ANT 1 + ANT 2), the SCALANCE selects the higher RSSI internally and reports it under
snWLanCurrentSignalStrength. Verify in the WBM that both ports show non-zero RSSI during a sweep — if one port is dead, replace the antenna pigtail.
FAQ
What SNMP OID holds the RSSI value on a SCALANCE W744-1PRO?
The object snWLanCurrentSignalStrength under 1.3.6.1.4.1.4329.6.5.4.1.1.1.5 returns the signed dBm value of the active association. Load the private MIB SIE-PROFINET-WIRELESS-MIB from SIOS entry 109743802 and verify with snmpwalk before coding.
Can I read the RSSI over PROFINET without SNMP?
No. PROFINET IO channel diagnostics on the W744-1PRO only report port state and a coarse link-quality category — the absolute RSSI in dBm is not part of the standard diagnostics records. SNMP (or scraping the WBM) is required for a numeric bar.
Which WinCC version supports the bar object for RSSI?
WinCC Comfort / Advanced / Professional from TIA Portal V14 SP1 onward. WinCC Flexible 2008 SP5 supports the same bar but is end-of-life. The tag must be 32-bit signed (DInt or Int) to hold negative dBm values without wrap-around.
How often should I poll the SCALANCE W744 for signal strength?
2–5 seconds is typical. Faster than 1 s overloads the device's SNMP stack and may cause missed responses; slower than 10 s makes the bar look sluggish on a moving machine. On a Comfort Panel with no PC in the loop, run the PLC poll at 2 s and rebroadcast at the HMI's configured update rate.
Do I need a SIMATIC NET license for SNMP polling?
For the PC-based path (Method 2) using the SIMATIC NET SNMP OPC Server, yes — the SNMP OPC Server feature is licensed separately as part of SIMATIC NET PC Software. The PLC-based path (Method 3) needs no PC license; the S7-1500 Open User Communication is included in the CPU firmware.
Why does the bar freeze at the last value after the AP reboots?
The PLC keeps the last valid RSSI in the DB but stops receiving fresh responses, so the tag holds its value. Configure a stale flag (set after 3 consecutive timeouts) and overlay a red "X" on the bar — operators then see "no fresh data" instead of misreading the frozen value as live signal.