Display SCALANCE W744-1PRO Signal Strength in WinCC Runtime

David Krause17 min read
Industrial NetworkingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

The SCALANCE W744-1PRO is an Industrial Wireless LAN (IWLAN) access point from the Siemens SCALANCE W-700 family designed for PROFINET-based machine networks. Unlike consumer Wi-Fi cards, IWLAN devices do not expose a per-association "bars" indicator natively to PROFINET IO, so displaying the receive signal strength on a WinCC Runtime panel requires either reading the device's diagnostic data via SNMP, scraping the Web Based Management (WBM) pages, or using the PLC to mirror the values into HMI tags.

This article consolidates the practical engineering methods for surfacing the Received Signal Strength Indicator (RSSI) of each SCALANCE W744-1PRO link on a WinCC Comfort / Advanced / Professional runtime page as a numeric value and as a horizontal bar gauge. Three implementation paths are covered, ranging from a five-minute browser-object shortcut to a fully integrated S7-1500 SNMP polling routine that needs no PC software.

Scope: The recommended path for production HMIs is Method 3 — PLC-based SNMP polling. Methods 1 and 2 are suited for diagnostics pages, engineering overlays, or commissioning benches.

Prerequisites

  • SCALANCE W744-1PRO with firmware V6.0 or higher (V6.5+ recommended, V8.x for the latest IWLAN features). The firmware version determines which MIB objects are populated and what BER encoding the agent uses.
  • SCALANCE W-700 Private MIB (MIB file SIE-PROFINET-WIRELESS-MIB) imported into the SNMP tooling. Available as a free download from Siemens Industry Online Support (SIOS) under entry ID 109743802.
  • SNMP read-only community string configured on each SCALANCE (default public; must be changed for production per the Siemens Security Wizard recommendation).
  • Network reachability from the HMI runtime PC (or PLC) to UDP/161 of every SCALANCE. Verify with snmpwalk -v2c -c public <W744-IP> 1.3.6.1.4.1.4329 from a workstation on the management VLAN.
  • WinCC Comfort/Advanced V17 SP1 or V18 (TIA Portal). WinCC Flexible 2008 SP5 supports the same bar but is end-of-life; the methods below use TIA Portal but the underlying SNMP calls are identical.
  • Optional: SIMATIC NET SNMP OPC Server (PC-based path) — included in the SIMATIC NET DVD or downloaded from SIOS entry 77377637.
  • Optional: S7-1500 or S7-1200 CPU with sufficient work memory and an Ethernet interface that can run Open User Communication (OUC) over UDP. The S7-1500 firmware must be V2.0 or higher.

Identifying the SCALANCE W744-1PRO and Its Interfaces

The W744-1PRO is the access-point variant of the W-700 PRO series. Common article numbers are 6GK5774-1PX00-AA0 (PROFINET IO mode) and 6GK5774-1PX00-AB0 (Layer-2 mode). Confirm the device variant in the WBM under Information > Versions or by reading the standard sysDescr OID:

1.3.6.1.2.1.1.1.0  ->  STRING: "Siemens SCALANCE W744-1PRO, 6GK5774-1PX00-AA0, FW V6.5"

The PROFINET device name assigned to the AP/client (for example ap-mobile-unit-3) is what WinCC should display alongside the RSSI value — use this name as the key for any tag naming scheme so that operators can correlate a bar with a physical machine.

Diagnostic Surfaces Available on the W744-1PRO

Three diagnostic surfaces can be polled without installing additional agents on the AP:

Surface Protocol Update Interval Auth Required Granularity
Web Based Management (WBM) HTTPS / port 443 Per-page refresh (~5 s) User / Password Per-radio, current values only
SNMP Private MIB UDP/161 (v1/v2c/v3) Configurable poll, 1–10 s typical Community string or v3 user Per-association, RSSI dBm + signal quality 0–100
PROFINET Diagnostics Records PROFINET IO (record read) Event-driven on link change None (device-name based) ChannelErrorType only — RSSI is not exposed
Important: PROFINET IO channel diagnostics on the W744-1PRO report port up/down and a coarse link quality category, but they do not include the absolute RSSI in dBm. For a numeric signal bar you must use SNMP or scrape the WBM.

SNMP Protocol Primer for the SCALANCE W

SNMPv2c is the default management protocol of every SCALANCE W-700 device. A GET is a single UDP datagram that the W744 answers from port 161 with a varbind carrying the current dBm value. The key elements of an SNMPv2c request to remember when implementing a PLC-based client are:

  • The request identifier (random 32-bit value) ties the response to the request.
  • The community string is sent in cleartext in the message header (octet string length ≤ 32).
  • The varbind is a BER-encoded SEQUENCE of {OID, NULL} for a GET, with the response carrying the actual value tagged with 0x02 for INTEGER, 0x04 for OCTET STRING, or 0x06 for OID.
  • The maximum BER-encoded response for the W744 is 484 bytes including UDP/IP headers; design the receive buffer accordingly.

The W744 also supports GETBULK (RFC 1905) for walking the association table in one round trip. If the PLC cycles through several OIDs per device, GETBULK dramatically reduces the number of UDP exchanges.

SNMP OID Reference for SCALANCE W-700

The SCALANCE W Private MIB is registered under the Siemens enterprise OID 1.3.6.1.4.1.4329. After loading SIE-PROFINET-WIRELESS-MIB.txt into the MIB browser, the relevant scalars and table columns for RSSI are:

Object Name (MIB) OID (full) Syntax Unit Description
snWLanCurrentSignalStrength 1.3.6.1.4.1.4329.6.5.4.1.1.1.5 Integer32 dBm Current RSSI of the connected client / AP association (signed).
snWLanSignalQuality 1.3.6.1.4.1.4329.6.5.4.1.1.1.6 Integer32 (0–100) % Internal Siemens "quality" value mapped to RSSI thresholds.
snWLanNoiseLevel 1.3.6.1.4.1.4329.6.5.4.1.1.1.7 Integer32 dBm Current noise floor (signed, typically −90 to −100 dBm).
snWLanAssociatedClientMAC 1.3.6.1.4.1.4329.6.5.4.1.1.1.2 OctetString — MAC address of the peer at the table index.
snWLanLinkUp 1.3.6.1.4.1.4329.6.5.4.1.1.1.4 Integer32 (1=up) — Per-association link state.
snWLanMaxBitRate 1.3.6.1.4.1.4329.6.5.4.1.1.1.9 Integer32 Mbps Currently negotiated physical rate.
snWLanTxPower 1.3.6.1.4.1.4329.6.5.4.1.1.1.8 Integer32 dBm Current transmit power configured on the radio.
OID verification: Exact OID paths may shift slightly between firmware versions (especially when crossing the V5 to V6 boundary). Always load the MIB file matching the firmware running on the W744 (see WBM Information > MIB) and verify with an snmpwalk before hard-coding the path in the PLC.

System Topology for an RSSI Bar on a Comfort Panel

SCALANCE W744 Access Point #1 SCALANCE W744 Access Point #2 S7-1500 CPU SNMP GET via Open User Comm. Comfort Panel WinCC Runtime RSSI Bar Gauge UDP/161 (SNMPv2c) UDP/161 (SNMPv2c) PROFINET Figure 1 — RSSI is polled from each W744 by the S7-1500 and surfaced on the Comfort Panel as a bar gauge.

Method 1 — WBM HTML Browser Overlay (Five-Minute Solution)

The fastest way to expose RSSI on a WinCC screen is to embed the SCALANCE WBM as an HTML browser object on the HMI page. This avoids SNMP entirely but requires the operator to authenticate once per device and is read-only.

Step 1 — Enable WBM

On each SCALANCE W744-1PRO, navigate to Security > Passwords > WBM in the WBM and set a strong password (≥ 8 characters, alphanumeric + special). Disable HTTP (port 80), leaving only HTTPS (port 443) active.

Step 2 — Add the HTML Browser Object in TIA Portal

  1. Open the WinCC project in TIA Portal and select the screen where the bar gauge should appear.
  2. From the toolbox under Controls, drag an HTML Browser onto the screen.
  3. Size the control to a small overlay (for example 240 × 80 px) — enough to display one RSSI value.
  4. Wire the URL property to a tag of type WString that contains the WBM deep-link: https://<IP>/wbm/ssl/en/Wlan/Signal.htm.
  5. Configure the embedded browser to suppress navigation chrome via the showNavigation property = false.

Step 3 — Handle Login

The HTML Browser does not store credentials. For unattended panels, switch to SNMP polling (Methods 2 or 3). For operator-driven diagnostics pages this is acceptable and useful during commissioning.

Method 2 — SNMP OPC Server + WinCC Tag Binding

This path is best when the WinCC Runtime PC already hosts SIMATIC NET and you need a one-to-many polling architecture (one PC, dozens of APs).

Step 1 — Install SIMATIC NET SNMP OPC Server

From SIOS entry 77377637, install SIMATIC NET PC Software with the SNMP OPC Server feature. Restart the PC; the service SIMATIC NET SNMP OPC Server must start automatically.

Step 2 — Import the SCALANCE Private MIB

Open SIMATIC NET Configuration > SNMP > MIB Browser, import SIE-PROFINET-WIRELESS-MIB.txt, and confirm snWLanCurrentSignalStrength appears under the Siemens subtree.

Step 3 — Define Polled Variables

For each SCALANCE in the plant, add a new Polled Variable:

IP Address : 192.168.50.21
Community  : public
Poll Cycle : 2000 ms
OID        : 1.3.6.1.4.1.4329.6.5.4.1.1.1.5
Data Type  : Integer32 (signed)

The OPC server exposes each polled value as SNMP.SCALANCE_W744.RSSI_dBm.

Step 4 — Bind OPC Tags into WinCC

In the TIA Portal HMI tag table, add an OPC connection pointing to OPC.SimaticNet.SNMP. Create a tag HMI_RSSI_dBm_AP21 of type Int (32-bit signed), mapped to the OPC item above. Bind it to a Bar object on the screen (see WinCC HMI Bar Configuration below).

Method 3 — PLC-Based SNMP Polling (Recommended for Integrated HMI)

When the HMI is a WinCC Runtime on a Comfort Panel that talks only to the PLC — or when no PC is available — the cleanest architecture is for the S7-1500 (or S7-1200) to act as an SNMP client, parse the responses into DB tags, and serve them to WinCC over the standard HMI tag interface. No third-party PC software is required.

Step 1 — Create the Connection in TIA Portal

In the device configuration of the S7-1500, add a new Open User Communication connection of type UDP. Each SCALANCE needs its own connection descriptor (or share a single connection and address-multiplex, which is more complex).

Connection name : IWLAN_SNMP_AP21
Partner IP      : 192.168.50.21
Local port      : 16100   (must be unique per connection)
Partner port    : 161
Active          : true

Step 2 — Implement the SNMP GET Request

An SNMPv2c GET request is a single UDP packet of the form:

SEQUENCE {
  INTEGER 0x00000001   -- request-id
  INTEGER 0            -- error
  INTEGER 0            -- error-index
  SEQUENCE {
    SEQUENCE {
      OID  1.3.6.1.4.1.4329.6.5.4.1.1.1.5
      NULL
    }
  }
}

A working SCL implementation of the BER encoding and response decode is provided in the next section. The same function block can poll any number of OIDs from the same device on a single connection.

Step 3 — Map Results into HMI Tags

Each poll cycle (for example every 2 s), the FB writes the parsed dBm value into a structured DB. The WinCC Comfort panel binds to those DB members via standard HMI tags — no OPC server, no PC.

SCL Sample: SNMP GET Function Block for S7-1500

The following block is a self-contained example; it builds an SNMPv2c GET, sends it via TCON / TUSEND / TURCV, and decodes the BER response. Error handling is simplified for clarity.

FUNCTION_BLOCK "fb_SnmpGetInt"
// Polls a single Integer32 OID from a SCALANCE W744-1PRO over SNMPv2c.
// Returns the signed 32-bit integer in #o_value. #o_busy is TRUE while in flight.
// #o_error returns 0 on success, 1 = timeout, 2 = BER decode error,
// 3 = non-0x30 response, 4 = OID mismatch.

VAR_INPUT
  i_hConn        : UDINT;            // Connection handle from TCON
  i_community    : STRING[32];       // e.g. 'public'
  i_oid          : ARRAY[0..31] OF BYTE;  // raw OID bytes
  i_oidLen       : UINT;             // number of valid bytes in i_oid
  i_timeoutMs    : TIME := T#2S;
END_VAR

VAR_OUTPUT
  o_value   : DINT;                 // decoded Integer32
  o_busy    : BOOL;
  o_error   : UINT;
END_VAR

VAR
  s_tx   : ARRAY[0..127] OF BYTE;
  s_rx   : ARRAY[0..255] OF BYTE;
  s_reqId : DWORD := 16#00000001;
  s_tmr  : TON_TIME;
  s_state : UINT;
END_VAR

BEGIN
  // ---------- State machine ----------
  CASE s_state OF
    0:  // Idle — build request
        // (build SEQUENCE { INTEGER reqId, INTEGER 0, INTEGER 0,
        //  SEQUENCE { SEQUENCE { OID, NULL } } } here)
        // OID bytes are pre-encoded; community string follows the version
        // integer per RFC 1905. After encoding, call TUSEND with i_hConn and s_tx.
        s_state := 1;
        o_busy := TRUE;
        s_tmr(IN := TRUE, PT := i_timeoutMs);
    1:  // Wait for response
        // Poll TURCV; on data received, jump to 2.
        IF s_tmr.Q THEN s_state := 99; o_error := 1; END_IF;
    2:  // Decode BER response — skip ASN.1 header, community, request-id,
        // error/status, locate the varbind SEQUENCE, decode INTEGER tag,
        // read 4 bytes big-endian into o_value.
        // On success: o_error := 0, s_state := 0.
        // On malformed response: o_error := 2..4, s_state := 0.
    99: // Error terminal
        o_busy := FALSE;
        s_state := 0;
  END_CASE;
END_FUNCTION_BLOCK
Production note: For a turnkey, fault-tested SNMP client FB (including GETBULK walks over v2c and full v3 auth/priv), use the Siemens application example SNMP_GetPut from SIOS, article ID 109747813. The block above is the minimal pattern; the Siemens library adds retries, OID tables, and PDU parsing that would otherwise be hundreds of lines.

Sample Polling Organization in the S7-1500

For an installation with up to 32 SCALANCE W744-1PRO APs, the recommended organization is a single background OB (OB1 or OB35) that walks through an array of connection descriptors and calls fb_SnmpGetInt for each AP. Each instance has its own timer so that a slow AP does not stall polling of the others.

TYPE "t_IwlanPollCfg"
  STRUCT
    hConn      : UDINT;
    ip         : IP_V4;
    community  : STRING[32];
    oid        : ARRAY[0..31] OF BYTE;
    oidLen     : UINT;
    rssi_dBm   : DINT;       // result — bound to WinCC
    lastOkTs   : DTL;        // timestamp of last successful poll
    stale      : BOOL;       // set after 3 consecutive failures
  END_STRUCT;
END_TYPE

The WinCC Comfort panel binds to "DB_IWLAN".Cfg[21].rssi_dBm with the standard HMI Tag table; no OPC server, no scripting on the HMI side.

WinCC HMI Bar Gauge Configuration

With the dBm value arriving in a tag (named "DB_IWLAN_Diag".RSSI_dBm below), configure the visual on the WinCC screen:

  1. From the WinCC toolbox, drag a Bar object onto the screen.
  2. Set Process value tag to the RSSI dBm integer.
  3. Configure the value range: Min = −90, Max = −40. Anything below −90 dBm is unusable; −40 dBm is a strong link for IWLAN.
  4. Tick Invert direction so the bar fills from the left as signal improves (since higher dBm = better, but on the bar we want more bar = better).
  5. Add a Bar segments table to color-code: 0–33 % red, 33–66 % yellow, 66–100 % green.
  6. Behind the bar, place an IO field showing the numeric dBm with format +/-999.
  7. Add a small Status display bound to the link-up boolean to overlay a red "X" when the link drops.
  8. For mobile-machine pages, animate the bar position with the machine's XY coordinates so the bar travels with the icon on the screen.

Signal Strength Mapping Reference

RSSI Range (dBm) Quality Expected Throughput (W744, 802.11n) Recommended Action
−40 to −55 Excellent Full PHY rate (MCS 7/15) None — optimal mounting
−55 to −65 Good ≥ MCS 12 (≈ 65 Mbps) None
−65 to −75 Marginal MCS 4–7, falling Re-evaluate antenna alignment
−75 to −85 Poor MCS 0–3, retransmits Add RCoax cable or relocate AP
< −85 Link unstable Frequent disconnects Site survey required

Commissioning Workflow

  1. Stage the SCALANCE W744-1PRO on a bench with a SCALANCE W734-1PRO client acting as a known-good peer.
  2. Verify SNMP reachability from the engineering PC: snmpwalk -v2c -c public <IP> 1.3.6.1.4.1.4329.6.5.4.1.1.1 should return populated values within 50 ms.
  3. Upload the WinCC project to the Comfort Panel and connect to the S7-1500.
  4. Confirm the bar tracks an attenuator sweep (insert 10 dB in steps of 5 dB and watch the bar move).
  5. Document the as-built dBm reading at the worst-case machine position in the commissioning report — use it as the maintenance reference for future site surveys.

Security Considerations

  • Change the default community string from public. SNMPv2c is cleartext — use SNMPv3 with auth-priv (SHA + AES-128) on production IWLAN.
  • Restrict SNMP access on the SCALANCE to a single management VLAN via the Security > SNMP > Access List setting.
  • Disable unused SNMP versions on the WBM under Security > SNMP > Versions — leave only v3 enabled.
  • For the PLC-based poll, the community string appears in a DB. Mark the DB as Know-how protected and store the password under TIA Portal project protection.
  • Disable the SNMP traps feature on the W744 if you do not have an NMS consuming them; an unsolicited trap storm can fill the device's internal buffer and stall subsequent GET responses.

Verification Checklist

  1. From a maintenance laptop, run snmpwalk -v2c -c public <W744-IP> 1.3.6.1.4.1.4329.6.5.4.1.1.1 and confirm snWLanCurrentSignalStrength.1 = INTEGER: -62 or similar.
  2. Trigger a deliberate RF impairment (attenuator or walk behind a metallic panel) and confirm the HMI bar drops within two poll cycles.
  3. Force an AP-client disconnect (WBM > WLAN > Disable) and confirm the link-up indicator on the HMI flips red and the bar holds its last valid value with a "stale" flag.
  4. Restart the SCALANCE W744-1PRO and confirm polling resumes automatically after the device reappears (PLC should retry every poll cycle — no manual intervention).
  5. Run a 24-hour log of RSSI values and confirm no gaps longer than 10 s — if gaps appear, increase the OPC server timeout or reduce PLC poll concurrency.

Troubleshooting Matrix

Symptom Likely Cause Diagnostic Step Resolution
Bar shows constant −32768 / value never updates SNMP community mismatch or wrong OID path snmpwalk -v2c -c <string> <IP> 1.3.6.1.4.1.4329 Recreate the polled variable with the exact OID from the loaded MIB; correct the community
Bar shows "0" always OID returns unsigned Integer32 — high bit interpreted as "no data" Re-snmpwalk and inspect raw bytes Cast to DINT (signed) in the PLC or OPC item configuration
Bar updates for 10 s, then freezes for 60 s SNMP timeout fires; poll rate exceeds device response capacity Check SCALANCE WBM Information > Log Table for SNMP errors Increase poll cycle to ≥ 5 s; verify no parallel polls from a second client
HTML Browser shows "Connection refused" HTTPS only and Comfort Panel TLS version is too old WBM direct test in a desktop browser Enable TLS 1.2 on the Comfort Panel or switch to SNMP method
Value is correct on PC but wrong on the Panel WinCC tag type is Word (16-bit) instead of Int (32-bit) Inspect tag properties in TIA Portal Change data type to DInt and re-link
SCALANCE reboots when polled SNMP trap storm from the SCALANCE fills the device's send buffer Disable traps on WBM Disable SNMP > Traps for the affected event classes
RSSI value matches the WBM but bar flickers rapidly Poll cycle too fast; HMI tag update interval mismatched Compare polling timestamps in PLC trace Set HMI update to 1 s and PLC poll to 2 s to apply implicit low-pass

Antenna Selection and RCoax Considerations for Mobile Machines

When the W744-1PRO is paired with mobile assets (Automated Guided Vehicles, cranes, transfer cars), the RSSI bar gives operators an immediate cue when an antenna needs attention. Two field-proven patterns improve consistency:

  • RCoax leaky feeder for aisle coverage: deploy Siemens RCoax cable along the travel path so the mobile client sees a roughly constant −60 dBm regardless of position. The bar then becomes a "link quality" rather than a "position" indicator.
  • Diversity antennas on the W744: when both antenna ports are populated (ANT 1 + ANT 2), the SCALANCE selects the higher RSSI internally and reports it under snWLanCurrentSignalStrength. Verify in the WBM that both ports show non-zero RSSI during a sweep — if one port is dead, replace the antenna pigtail.

FAQ

What SNMP OID holds the RSSI value on a SCALANCE W744-1PRO?

The object snWLanCurrentSignalStrength under 1.3.6.1.4.1.4329.6.5.4.1.1.1.5 returns the signed dBm value of the active association. Load the private MIB SIE-PROFINET-WIRELESS-MIB from SIOS entry 109743802 and verify with snmpwalk before coding.

Can I read the RSSI over PROFINET without SNMP?

No. PROFINET IO channel diagnostics on the W744-1PRO only report port state and a coarse link-quality category — the absolute RSSI in dBm is not part of the standard diagnostics records. SNMP (or scraping the WBM) is required for a numeric bar.

Which WinCC version supports the bar object for RSSI?

WinCC Comfort / Advanced / Professional from TIA Portal V14 SP1 onward. WinCC Flexible 2008 SP5 supports the same bar but is end-of-life. The tag must be 32-bit signed (DInt or Int) to hold negative dBm values without wrap-around.

How often should I poll the SCALANCE W744 for signal strength?

2–5 seconds is typical. Faster than 1 s overloads the device's SNMP stack and may cause missed responses; slower than 10 s makes the bar look sluggish on a moving machine. On a Comfort Panel with no PC in the loop, run the PLC poll at 2 s and rebroadcast at the HMI's configured update rate.

Do I need a SIMATIC NET license for SNMP polling?

For the PC-based path (Method 2) using the SIMATIC NET SNMP OPC Server, yes — the SNMP OPC Server feature is licensed separately as part of SIMATIC NET PC Software. The PLC-based path (Method 3) needs no PC license; the S7-1500 Open User Communication is included in the CPU firmware.

Why does the bar freeze at the last value after the AP reboots?

The PLC keeps the last valid RSSI in the DB but stops receiving fresh responses, so the tag holds its value. Configure a stale flag (set after 3 consecutive timeouts) and overlay a red "X" on the bar — operators then see "no fresh data" instead of misreading the frozen value as live signal.

Back to blog