Forcing PG/PC S7 Routing via CP343-1 to MPI on S7-300

David Krause13 min read
S7-300SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: Why PG/PC Picks the Wrong CP343-1

When a S7-300 station carries more than one communication processor, the PG/PC interface selection in STEP 7 / TIA Portal becomes the deciding factor for which physical port the engineering station uses to reach the target CPU. The classic field problem is a CPU 317 with a CP 343-1 in an Ethernet subnet, an MPI cable linking it to a CPU 313, and a brand-new CP 343-1 just installed on the CPU 313. The moment a second Ethernet CP appears, the S7ONLINE access point can resolve the target CPU through either CP 343-1, and the PG/PC will normally pick the one that is reachable on the same subnet as the engineering station. This bypasses the MPI bridge and breaks the original route that was used for years.

The correct Siemens mechanism for reaching the CPU 313 through the CPU 317's CP 343-1 and then across the MPI backbone is called S7 Routing. Routing is a function of the S7-300 / S7-400 CPU firmware and the PG/PC interface; it is not a property of the CP 343-1 itself. Once it is enabled and the right access point is selected, the engineering station uploads, downloads, and goes online with the target CPU transparently across two subnets.

Network Topology Used in This Scenario

The reference topology is a three-segment network with two S7-300 stations and one PG/PC:

  • Segment 1 - Engineering LAN (Ethernet/Industrial Ethernet): PG/PC, CP 343-1 of CPU 317, CP 343-1 of CPU 313. Same IP subnet (for example 192.168.0.0/24).
  • Segment 2 - MPI backbone: CP 343-1 of CPU 317 routes to CPU 317, CPU 317 MPI port links to CPU 313 MPI port. MPI address of CPU 317 = 2, CPU 313 = 3, PG reserved for future use = 0.
  • Segment 3 - S7-300 station 2: CPU 313 (6ES7313-...) with optional CP 343-1 (6GK7343-1...) installed in slot 4.
Reserve MPI address 0 for a programming device and allocate the remaining MPI addresses in ascending order without gaps. Up to 126 addressable devices may share one MPI subnet, but only 32 may be repeaters, and bus terminators are required at both physical ends of the segment.

Prerequisites

  1. STEP 7 V5.5 + SP2 or higher, or TIA Portal V13 SP1 or higher. TIA Portal V16 or later is recommended for current S7-300 CPU firmware (see How do you configure and enable S7 Routing in STEP 7 (TIA Portal)?).
  2. CPU 317 (6ES7317-...) firmware V2.x or higher; CPU 313 (6ES7313-...) firmware V2.x or higher. The S7 Routing entry ID 584459 lists every CPU and CP that supports S7 routing. Both CPUs and the CP 343-1 used as the gateway must appear in that compatibility matrix.
  3. CP 343-1 (6GK7343-1CX10-0XE0 or later EX-series variant) on the CPU 317, with a configured IP address and a correctly wired MPI bus between the two CPUs.
  4. The STEP 7 project on the PG/PC must contain both stations, the Ethernet subnet, the MPI subnet, and the S7 connections; otherwise the NetPro / devices & networks view will not offer routing.
  5. Administrator rights on Windows to set the PG/PC interface (S7ONLINE access point), because the access point is a computer-wide setting in the Set PG/PC Interface tool.

Step 1 - Verify S7 Routing Hardware Capability

Before touching any configuration, confirm that the S7-300 CPUs and the CP 343-1 in question actually support the routing function. Siemens documents the exact combination in Which modules support the "S7 Routing" function in S7 subnets? (entry ID 584459). As a rule of thumb, all standard CPUs of the S7-300 (CPU 312 / 313 / 314 / 315 / 317 / 319) and S7-400 families that ship with firmware V2.x or higher support S7 routing when used with a CP from the compatibility list. CP 343-1 variants EX11 and later (6GK7343-1EX11-0XE0 and 6GK7343-1EX30-0XE0) are the typical industrial variants used as a routing gateway.

Step 2 - Configure the Subnets in STEP 7 (SIMATIC Manager)

  1. Open the STEP 7 project that contains both stations. If the new CP 343-1 on the CPU 313 was added recently, run PLC > Upload Station to PG so the hardware is mirrored in the offline project.
  2. Open NetPro (Options > Configure Network). The Ethernet subnet and the MPI subnet must each appear as a single object on the network view, with both stations connected to the correct subnet.
  3. Drag the CP 343-1 of CPU 317 to the Ethernet subnet and to the MPI subnet (or to the backplane of CPU 317 - STEP 7 attaches the CP to the Ethernet subnet and the CPU's integrated MPI port stays on the MPI subnet).
  4. Drag the CPU 317 to the MPI subnet only; its MPI port is the physical connector that reaches CPU 313.
  5. Drag the CPU 313 to the MPI subnet. If the new CP 343-1 is on the CPU 313, drag that CP to the Ethernet subnet as well, but do not put a S7 connection from the PG/PC to that CP - that is the route you want to suppress.
  6. Save and compile (Network > Save and Compile). The project is now physically consistent with the real wiring.

Step 3 - Configure the Subnets in TIA Portal

  1. In the project tree open Devices & Networks.
  2. Select the CP 343-1 on CPU 317. In Properties > Ethernet addresses, confirm the IP, subnet mask, and the assignment to the Ethernet subnet. Select the Use router option only if a layer-3 device is in the path - for a single flat subnet, leave it empty.
  3. Select the CPU 317 itself. In Properties > MPI/DP interface, set MPI address 2, bus profile MPI, and the transmission rate 187.5 kbps (default) or 1.5 Mbps for short segments.
  4. For the CPU 313, set MPI address 3 on its MPI/DP interface.
  5. For the new CP 343-1 on CPU 313, set its IP address on the same Ethernet subnet as the engineering station.
  6. Compile the project (Project tree > right-click the project > Compile > Hardware and software (only changes)). TIA Portal implicitly generates the routing information from the topology.

Step 4 - Force the PG/PC to Use the S7ONLINE Access Point over Ethernet

Routing is triggered by the access point of the engineering software, not by the project. The PG/PC must use the Ethernet card (or the Intel / Realtek / Siemens network interface installed) under the S7ONLINE access point, and STEP 7 / TIA Portal must reach the target CPU through the gateway on that subnet, which is the CP 343-1 of CPU 317.

  1. Open the Windows control panel entry Set PG/PC Interface (32-bit) or start the same tool from Start > Siemens Automation > Set PG/PC Interface.
  2. In the Access Point of the Application drop-down, select S7ONLINE.
  3. In the Interface Parameterization Used list, select the TCP/IP network card bound to the engineering LAN, for example TCP/IP > Intel(R) I210 Gigabit Network Connection. Do not select AGP/MPI links, do not select any auto-detect entry.
  4. Click Properties. On the TCP/IP tab the system uses the Windows IP configuration; the card must have a fixed IP on the same subnet as CP 343-1 of CPU 317 (e.g. 192.168.0.100 / 255.255.255.0).
  5. Click OK and confirm. The tool writes the assignment to the registry under HKLM\SOFTWARE\Wow6432Node\Siemens\SINEC\LogDevices.
A single PC cannot bind two different physical interfaces to the S7ONLINE access point at the same time. If a second engineering tool (PLCSIM, a second instance of TIA Portal, or a WinCC runtime) is open on the same S7ONLINE, the routing path is undefined and downloads can silently fail. Close all other engineering tools before going online.

Step 5 - Go Online Through the Router CPU

  1. Open the project in STEP 7 / TIA Portal and select the CPU 313 in the project tree.
  2. Right-click and choose Go online > Online & Diagnostics (TIA Portal) or PLC > Go Online (SIMATIC Manager). TIA Portal opens a dialog and lets you choose the target subnet; pick PN/IE and type the IP address of the CP 343-1 on CPU 317 as the gateway (e.g. 192.168.0.10). TIA Portal will then route through the CPU 317's MPI port to the CPU 313 on MPI.
  3. SIMATIC Manager: choose PLC > Go Online > Accessible Nodes, type the MPI address of CPU 313 (3). STEP 7 will resolve that address through the configured gateway and the online view opens on the routed CPU.
  4. Run PLC > Download. The blocks travel: PG/PC Ethernet card > engineering LAN > CP 343-1 (CPU 317) > backplane > CPU 317 MPI port > MPI cable > CPU 313 MPI port > backplane > CPU 313 work memory.

Step 6 - Why the Engineering System "Prefers" the New CP 343-1

Routing is an explicit choice. When the PG/PC sends a S7 connection request, the engineering software looks for a partner whose IP/MPI/Profibus address matches the address in the dialog box. If you type the IP of the CPU 313's CP 343-1, the request is delivered directly and the MPI bridge is never traversed. If you type the IP of the CPU 317's CP 343-1 plus the MPI address of CPU 313, the engineering software appends a routing header and the gateway CPU forwards the request across the MPI subnet. The first path is faster and is the default the OS / engineering tool will pick; the second path requires a configured routing entry, which is what the project provides in Step 3.

Verification Checklist

Check Expected result Where to verify
S7ONLINE points to TCP/IP of engineering LAN Selected interface is the LAN NIC, not a virtual AGP Set PG/PC Interface dialog
Routing entry exists in project CPU 317 is connected to both Ethernet and MPI subnet NetPro / Devices & Networks
Online status of CPU 313 Online & Diagnostics shows green "Connected" with router path indicated TIA Portal online view
MPI bus health No SF/BF on CPU 313 MPI port, no bus termination errors CPU 313 diagnostic buffer
CP 343-1 link state on CPU 317 Link LED green, no diagnostic buffer entries with code 0x0001 / 0x0002 CP 343-1 online diagnostics

Troubleshooting Matrix

Symptom Likely root cause Corrective action
TIA Portal opens CPU 313 directly, ignoring CPU 317 Wrong IP entered in the Go Online dialog; PG/PC picked the new CP 343-1 Re-enter the IP of the CP 343-1 on CPU 317 and select the MPI address of CPU 313 as the destination
Online returns "Router not found" CPU 317 not connected to the Ethernet subnet in the offline project, or no routing license Re-attach CP 343-1 to the Ethernet subnet in NetPro / Devices & Networks, recompile, and re-download the hardware configuration to CPU 317
Online hangs at "Establishing connection" MPI bus terminator missing, MPI cable swapped, transmission rate mismatch (CPU 187.5 kbps, CP 1.5 Mbps) Install 120 ohm terminators at the physical ends, set identical MPI bus profile on both CPUs, check pinout per TIA Portal MPI network configuration
Download aborts with SF on CPU 313, BF on MPI MPI address conflict; PG/PC holds an MPI address that collides with CPU 313 Reserve MPI address 0 for the PG, keep CPU 317 = 2, CPU 313 = 3, no duplicates
Only one of two engineering tools can be online Both tools share the same S7ONLINE access point Close the second tool or assign a second access point (e.g. S7ONLINE_2) for a parallel session

Special Case: Third-Party HMI Scanned as AGP/MPI

Some HMI panels, for example Pro-face GP-Pro EX projects, expose MPI pass-through to their engineering software via a virtual AGP MPI Link. The TCP/IP block driver and the AGP MPI Link cannot share the S7ONLINE access point on the same PC. The Pro-face driver manual (entry reference SIMATIC S7 MPI Direct Driver Pass-Through Function Guide) describes the order in which the panel and STEP 7 compete for the access point. In mixed-vendor plants, install the HMI engineering software on a separate workstation or switch the S7ONLINE binding per session.

Safety and Production Considerations

Routing downloads require a STOP on the target CPU only if the blocks are reorganized or if the hardware configuration is being reloaded. Pure program-block downloads in RUN are supported on S7-300 CPUs that have the corresponding firmware and enough work memory, but the route through the gateway CPU is not transparent to the CPU 317: the routing function temporarily buffers the S7 telegrams, which adds a few hundred milliseconds of latency on the MPI segment. During a download to the CPU 313, do not assume deterministic MPI response times for the gateway CPU 317. For process-critical MPI traffic, schedule the download in a maintenance window or set the CPU 313 to STOP first.

Migrating from SIMATIC Manager to TIA Portal

Projects created in STEP 7 V5.5 can be migrated to TIA Portal using Project > Migrate project. After migration, re-check the S7 routing configuration because the offline configuration is recomputed and the gateway relationship between CPU 317 and CPU 313 must be regenerated from the new topology. The TIA Portal-specific configuration steps are documented in How do you configure and enable S7 Routing in STEP 7 (TIA Portal)? (entry ID 109736340). The S7-300 hardware catalog in TIA Portal V16 and later retains the classic CPU and CP 343-1 article numbers; the legacy V5.5 project migrates without losing the routing capability as long as the original hardware is preserved.

FAQ

Why does the PG/PC connect directly to the new CP 343-1 on the CPU 313 instead of routing through CPU 317?

Because the S7ONLINE access point on the PG/PC is bound to TCP/IP, and the engineering software resolves the target CPU by its reachable address. Once the new CP 343-1 sits on the same Ethernet subnet as the PG/PC, that address is reachable and the request is delivered directly. To force routing, point the Go Online dialog to the IP of the CP 343-1 on CPU 317 and use the MPI address of CPU 313 as the destination, then make sure both CPUs and the CP appear in the offline project on the correct subnets (see Routing requirements entry ID 2383206).

Do I need a special license or hardware option for S7 routing on a CPU 317?

No. S7 routing is a firmware feature of the CPU and the CP listed in the compatibility table at entry ID 584459. Standard CPU 317 and CP 343-1 EX-series hardware supports it without an additional license.

What is the difference between S7 routing and S7 bridging in STEP 7?

Routing is a CPU function that forwards S7 telegrams between two subnets (e.g. Ethernet to MPI). Bridging is a CP function that converts a protocol at the transport layer. For the CPU 317 to MPI scenario described here, only routing is required; the CP 343-1 on CPU 317 does not need to be configured as a bridge.

Can I keep a parallel TCP/IP route to the new CP 343-1 and still use the MPI bridge?

Yes. Routing is enabled per project. The S7 connections defined in NetPro / Devices & Networks determine which path is used for which partner. As long as the new CP 343-1 on CPU 313 has no S7 connection to the engineering project that points to the PG/PC, the routing through CPU 317 stays active. Adding such a connection later will give the PG/PC a choice, and the explicit Go Online dialog will decide which path is used.

What MPI addresses should I assign when two S7-300 CPUs share a backbone?

Reserve MPI address 0 for a PG. Assign the lowest addresses to the gateway CPUs first, e.g. CPU 317 = 2, CPU 313 = 3, and avoid gaps. The MPI subnet accepts up to 126 addressable devices with at most 32 repeaters, and every segment must be terminated with 120 ohm resistors at both ends. Full topology rules are in the TIA Portal MPI network configuration guide.

Back to blog