Problem Definition: ET200S Profinet I/O on a PCS 7 V7.0 SP1 Backbone
A Process Control System based on SIMATIC PCS 7 V7.0 SP1 with an S7 416-3 DP automation station (AS) and an existing CP 443-1 for the plant bus must integrate approximately sixteen distributed ET 200S Profinet stations that perform local monitoring and control. The standard PCS 7 V7.0 SP1 hardware catalog does not provide a native Profinet IO controller port on the CPU, and the system does not load Profinet IO device descriptions in the same way as Profibus DP slave GSD files. Engineers face three concrete constraints:
- The S7 416-3 DP CPU has no integrated Profinet interface; only MPI/DP and, depending on the order number, an additional DP interface.
- PCS 7 V7.0 SP1 (and the related SIMATIC S7-400 firmware packages) was released before universal Profinet IO controller support was qualified for the AS library blocks.
- ET 200S Profinet head modules (IM 151-3 PN) require a Profinet IO controller (not an IO device relationship) to exchange process data cyclically.
Root Cause Analysis: Why Direct Integration Fails
Three independent obstacles prevent a direct connection:
- CPU capability. The S7 416-3 DP carries order number 6ES7 416-3XR05-0AB0 (or earlier -3XL00/-3XR00 variants). None of these -3DP revisions expose a Profinet port on the CPU itself. Only the -3PN/DP variants (e.g. 6ES7 416-3ER05-0AB0, firmware V5.0 and above) provide two integrated PN interfaces.
-
PCS 7 V7.0 SP1 release scope. The V7.0 SP1 engineering system ships the HW Catalog under profile
PCS7_V7.0. Profinet IO stations are not enumerated as standard AS IO in this catalog. Inserting an IM 151-3 PN into HW Config under that profile returns an unsupported module or a missing GSDML file error. - CP 443-1 role. In a stock PCS 7 AS, the CP 443-1 (e.g. 6GK7 443-1EX10/-1EX11) is configured as a plant-bus node (Layer 3 routing or S7 communication). It does not act as a Profinet IO controller unless the order number, firmware version, and CPU partner all satisfy the PROFINET IO controller release matrix.
Affected Components and Order Numbers
| Component | Order Number (MLFB) | Firmware / Version | Relevance |
|---|---|---|---|
| S7 416-3 DP (existing) | 6ES7 416-3XR05-0AB0 | V4.x / V5.x | No integrated PN port; DP only |
| S7 414-3 PN/DP | 6ES7 414-3EM05-0AB0 | V5.0+ | Upgrade path target for smaller AS |
| S7 416-3 PN/DP | 6ES7 416-3ER05-0AB0 | V5.0+ | Direct replacement for -3DP; adds 2 PN ports |
| CP 443-1 (plant bus) | 6GK7 443-1EX40-0XE0 | FW V2.1 | Standard Ethernet, not IO controller capable in PCS 7 |
| CP 443-1 Advanced | 6GK7 443-1EX41-0XE0 | FW V2.1+ | PN IO controller capable only with PN-CPU, NOT PCS 7 / S7-400H |
| ET 200S IM 151-3 PN HF | 6ES7 151-3BA20-0AB0 | FW V6.0+ | Profinet IO device head module |
| ET 200S IM 151-3 PN ST | 6ES7 151-3AA20-0AB0 | FW V3.0+ | Standard Profinet IO device head module |
| S7-300 CPU 317-2 PN/DP | 6ES7 317-2EK14-0AB0 | FW V3.3+ | Gateway CPU option |
Solution Architecture Overview
Three viable architectural patterns resolve the integration. Each is documented with its data-flow topology, hardware delta, and operational caveats.
Solution Option A: Replace S7 416-3 DP with S7 416-3 PN/DP
The cleanest path is to replace the existing CPU with a Profinet-capable variant that shares the same slot footprint in the S7-400 rack.
- Order 6ES7 416-3ER05-0AB0 (S7 416-3 PN/DP) with firmware V5.0 or higher.
- Migrate the STEP 7 / PCS 7 project: open the S7 program in HW Config, swap the CPU order number, and let HW Config re-assign the MPI/DP and integrated PN interfaces (PN interface 1 = X1 P1, PN interface 2 = X1 P2).
- Insert the ET 200S PN head modules from the HW Catalog (path:
PROFINET IO > ET 200S > IM 151-3 PN). The GSDML file ships with PCS 7 V7.0 SP1's installation media underSIEMENS\Automation\HWConfig\GSDML. - Re-load the AS program and run a PCS 7 commissioning download to synchronize the OS server.
Advantages: Native Profinet IO controller, no additional hardware, fastest cyclic update (typically 1 ms minimum for ET 200S PN).
Disadvantages: Hardware cost (the -3PN/DP carries a significant price premium), requires full CPU memory-card migration, and forces a planned PCS 7 downtime of typically 2-4 hours per AS for program reload and OS reconnection.
Solution Option B: CP 443-1 EX41 as Profinet IO Controller
CP 443-1 communications processors can act as a Profinet IO controller, but only under strict firmware and CPU pairing rules.
| CP 443-1 Order Number | Firmware | PN IO Controller | Required CPU Partner | PCS 7 Compatibility |
|---|---|---|---|---|
| 6GK7 443-1EX40-0XE0 | V2.1 | No (S7 communication only) | Any S7-400 | Yes |
| 6GK7 443-1EX41-0XE0 | V2.1+ | Yes (max 32 PN devices) | S7 414-3 PN/DP or S7 416-3 PN/DP (FW V5.0+) | NOT supported |
| 6GK7 443-1EX50-0XE0 | V3.0+ | Yes | S7-400 PN-CPU | NOT supported |
PCS7_V7.0 profile.If the engineer is willing to operate the CP outside PCS 7's AS library (e.g. as a stand-alone PN controller in a non-redundant cabinet), the EX41 supports up to 32 Profinet IO devices with a maximum of 1024 bytes of cyclic input and 1024 bytes of cyclic output per CP.
Solution Option C: S7-300 Gateway over Profibus DP
The most economical architecture uses an S7-317-2 PN/DP (order number 6ES7 317-2EK14-0AB0, firmware V3.3 or higher) as a subordinated PN controller that exchanges data with the S7 416-3 DP over Profibus DP master-slave communication.
- Mount an S7-300 station (PS 307, CPU 317-2 PN/DP, IM 365 if needed) in the same cabinet or adjacent cabinet.
- Configure the S7 317 as Profinet IO controller for the 16 ET 200S PN stations in its own STEP 7 project (NOT the PCS 7 project — this is a subordinate controller).
- Configure the Profibus DP interface of the S7 317 as a DP slave; configure the S7 416-3 DP as DP master. Use S7 communication (PUT/GET or BSEND/BRCV) to mirror the ET 200S process image into the PCS 7 AS.
- In PCS 7 CFC, map the mirrored tags to the standard AS block I/O. The ET 200S I/O is no longer in the PCS 7 HW Config and therefore cannot use the standard PCS 7 driver blocks (CH_AI, CH_DI, etc.) without a custom channel block.
Advantages: Lowest hardware cost (an S7-317-2 PN/DP is a fraction of the price of an S7-416 PN/DP), preserves the existing CPU investment, and avoids PCS 7 program recompilation.
Disadvantages: Loss of native PCS 7 diagnostics (no automatic channel-level fault display in the OS), additional Profibus DP segment required, additional engineering effort to maintain tag mirroring, and longer update times due to the DP cycle (typically 5-10 ms added).
Engineering Comparison Matrix
| Criterion | Option A (CPU swap) | Option B (CP 443-1 EX41) | Option C (S7-317 gateway) |
|---|---|---|---|
| Hardware cost (relative) | High | Medium | Low |
| Engineering effort | Medium (program migration) | Low (HW Config + GSDML) | High (two projects, mirroring logic) |
| PCS 7 V7.0 SP1 compatibility | Yes (with FW V5.0 CPU) | No | Partial (subordinate controller) |
| OS diagnostics integration | Native | N/A | Custom only |
| Update time (typ.) | 1 ms | 1 ms | 5-15 ms (DP + mirror) |
| Failure risk to existing plant bus | High (full AS swap) | Low (additive CP) | Low (additive gateway) |
| Recommended use | Greenfield / planned outage | Not permitted in PCS 7 | Brownfield, cost-sensitive |
Configuration Procedure for Option A (Recommended Path)
Prerequisites
- PCS 7 V7.0 SP1 engineering station with STEP 7 V5.4 SP5 or higher.
- S7 416-3 PN/DP CPU (6ES7 416-3ER05-0AB0), firmware V5.0 or later, with matching memory card (MMC, 8 MB minimum).
- ET 200S PN GSDML files installed:
GSDML-Vx.x-Siemens-ET200S-IM151-3PN-YYYYMMDD.xml. - Plant bus topology documentation and an outage window of at least 2 hours per AS.
Step-by-Step Configuration
-
Backup the existing AS project. In PCS 7 ES, select the AS and choose
AS > Save to Memory Card, then archive the S7 program withFile > Archive. - Swap hardware. Power down the S7-400 rack, replace the CPU, transfer the MMC if the part number is compatible (MMC is keyed to the CPU order number on V5.x firmware).
-
Update HW Config. In STEP 7, open the S7 program, double-click the CPU, and change the order number to
6ES7 416-3ER05-0AB0. Accept the prompt to update the module. -
Assign Profinet parameters. Open
Properties > PN Interface > Ethernet. Assign an IP address, subnet mask, and a Profinet device name (e.g.as410-pn1) consistent with the PCS 7 naming convention. Disable router if the AS is on the same subnet as the field devices. -
Insert ET 200S PN stations. Drag IM 151-3 PN HF (6ES7 151-3BA20-0AB0) from the catalog to the Profinet IO line. Repeat 16 times. Assign each station a unique device name (e.g.
et200s-pn-01...et200s-pn-16) and a unique IP address in the same subnet. - Configure slots. For each IM 151-3 PN, add power modules, digital/analog I/O modules as required. Assign symbolic names matching the PCS 7 tag database.
-
Compile and download. Run
Station > Check Consistency, thenPLC > Download to Target System. UseDownload to Target System > Entire Stationfor the first load. -
OS download. In the OS project, run
Compile OSand download the runtime to the OS server. Confirm the new AS IO appears in the process picture.
Configuration Procedure for Option C (Gateway Path)
Hardware Build-Out
- S7-300 rack with PS 307 (e.g. 6ES7 307-1EA01-0AA0) and CPU 317-2 PN/DP (6ES7 317-2EK14-0AB0), firmware V3.3+.
- Profibus DP cable between the S7-317 (DP master or slave port) and the S7-416 (DP master port). Terminate both ends with 220 Ω / 390 Ω / 390 Ω connector (6ES7 972-0BA12-0XA0).
- Managed industrial Ethernet switch for the PN subnet (e.g. SCALANCE XB208, 6GK5 208-0BA10-2AA3).
Programming Steps
- In the S7-317 STEP 7 project, configure PN IO with all 16 ET 200S PN head modules. Compile and download.
- Configure the S7-317 DP port as a DP slave with a consistent data area matching the process image size (e.g. 64 bytes IN / 64 bytes OUT).
- In the S7-416 STEP 7 / PCS 7 project, configure the S7-317 as a DP slave using a GSD file (
SIEM806D.GSDfor the 317-2 PN/DP). Map the slave's I/O to PCS 7 DB tags. - Implement a cross-CPU consistency check using SFC14 / SFC15 (
DPRD_DAT/DPWR_DAT) on both sides to ensure data consistency across the Profibus DP boundary. - In PCS 7 CFC, use the
CH_AI/CH_DIblocks only for I/O that is physically wired to the S7-416. For I/O behind the gateway, use a custom block (e.g.GAIN_PN) that reads the mirrored DB and applies scaling. Configure PCS 7's signal-status handling manually because the automatic channel diagnostics will not be populated.
Verification and Diagnostics
Profinet Diagnostics (Option A)
- Open the online view in HW Config and confirm all 16 ET 200S PN stations show a green check mark.
- Open
Diagnostics > PROFINET IO Diagnosticsin STEP 7 and verify device names, IP addresses, and port interconnections. - Check the CPU diagnostic buffer (
PLC > Diagnostic/Setting > Diagnostic Buffer) for PROFINET IO station failure events (event IDs 0x001E, 0x001F). - In the OS runtime, navigate to the standard
@PCS7_PN_Diagfaceplate or the area-specific picture to verify the new I/O appears with valid signal status (Q_BAD = 0).
Profibus DP Diagnostics (Option C)
- Use the S7-416 online DP slave diagnostics (
PLC > PROFIBUS > Diagnose) to confirm the S7-317 slave reportsStation OK. - Verify the S7-317 DP slave diagnostic data with SFC13 (
DPNRM_DG) in the S7-416 program. - Check the mirrored DB in the S7-416 with a VAT table; values must update within the configured OB1 cycle and must show
B#16#00in the first byte when the S7-317 is offline.
Functional Test Checklist
-
All 16 ET 200S PN stations respond to cyclic IO exchange (verify with
PNIO_CTRLSFB or vendor-supplied test block). - PCS 7 OS process picture updates I/O values within the operator-perceived latency (typically < 1 s).
- Disconnecting one ET 200S PN station triggers a diagnostic alarm visible in the PCS 7 OS message system.
- Hot-swapping a Profinet cable on one ET 200S does not disturb the other 15 stations.
-
PCS 7 CFC compile is free of warnings related to the new IO (specifically
Warning: Driver block not assigned).
Limitations, Caveats, and Field-Proven Notes
- PCS 7 V7.0 SP1 release window. This article covers PCS 7 V7.0 SP1 (released 2008) and the S7-400 CPU firmware V5.x. Later PCS 7 versions (V8.0+, V9.0) provide full Profinet IO controller support in the AS library and remove many of the constraints described above. Plan a PCS 7 version upgrade if multiple AS need Profinet integration.
- CP 443-1 PN controller in PCS 7. As documented in the PCS 7 V7.0 SP1 engineering manual SIMATIC Process Control System PCS 7 V7.0 SP1 Engineering System, only CPs explicitly listed in the PCS 7 catalog are permitted as AS components. The CP 443-1 EX41 PN IO controller mode is not in that list.
- S7-400H exclusion. The CP 443-1 EX41 / EX50 PN IO controller function is explicitly excluded from redundant S7-400H systems. For H-system Profinet IO controller, an external PC station running SIMATIC NET OPC or a PCS 7 V8.x AS is required.
- GSDML version drift. ET 200S GSDML files are versioned against the IM 151-3 PN firmware. Mixing a V5.0 IM with a V7.0 GSDML produces inconsistent slot configuration errors. Always match the GSDML version to the head module firmware.
-
Profinet device naming. Unlike Profibus DP addresses, Profinet device names are case-sensitive and must be assigned before the device can be discovered by the IO controller. Use the
PRONETAtool or STEP 7'sAssign Profinet Device Namefunction during commissioning. - Subnet size. PCS 7 plant-bus practice typically segments Profinet field devices on a separate subnet from the plant bus to avoid broadcast storms. Use a dedicated SCALANCE switch or VLAN.
When to Escalate Beyond PCS 7 V7.0 SP1
If more than two AS require Profinet IO controller integration, or if the application requires Profinet IRT (isochronous real-time) for motion or high-speed interlocking, escalate the project to PCS 7 V8.2 or later. From V8.0 onward, the S7-400 PN CPUs and the ET 200SP/ET 200MP PN stations are first-class citizens of the AS IO model, with native driver blocks and OS-level diagnostics. A brownfield migration from V7.0 SP1 to V8.2 can be staged one AS at a time, but it requires a complete re-validation of the safety lifecycle (if the plant is SIS-classified).
FAQ
Does PCS 7 V7.0 SP1 support any Profinet IO controller natively on the S7-400 AS?
No. PCS 7 V7.0 SP1 does not include Profinet IO controller support in the AS hardware catalog. Only S7 400 CPUs with integrated Profinet ports (S7 414-3 PN/DP, S7 416-3 PN/DP) operating outside the PCS 7 AS profile, or an external PC-based controller, can serve as a Profinet IO controller. See the PCS 7 V7.0 SP1 Engineering System manual for the supported component list.
Can the existing CP 443-1 (6GK7 443-1EX40-0XE0) be reused as a Profinet IO controller?
No. The CP 443-1 EX40 with firmware V2.1 supports S7 communication and plant-bus routing only. Profinet IO controller capability requires the CP 443-1 EX41 (6GK7 443-1EX41-0XE0) or EX50, and even those are not approved for use inside a PCS 7 AS.
What is the cheapest way to connect 16 ET 200S Profinet stations to a PCS 7 AS without replacing the CPU?
Use an S7-300 CPU 317-2 PN/DP (6ES7 317-2EK14-0AB0) as a Profinet IO controller and gateway, exchanging data with the S7 416-3 DP over Profibus DP master-slave with SFC14/SFC15 for consistency. The gateway CPU must run outside the PCS 7 AS profile, and the mirrored I/O must be mapped into the PCS 7 CFC with custom driver blocks.
Is the S7 416-3 PN/DP a drop-in replacement for the S7 416-3 DP?
Physically yes — the -3PN/DP occupies the same slot and uses the same rack. Functionally the program must be recompiled because the integrated PN interface replaces the slot for the optional CP 443-1, and the order number change triggers a STEP 7 hardware update. Memory-card content is keyed to the CPU order number on firmware V5.x and must be reloaded.
Which firmware version of the S7 416-3 PN/DP is required for 16 ET 200S PN stations?
Firmware V5.0 or higher on the S7 416-3 PN/DP (6ES7 416-3ER05-0AB0) is required. Earlier PN-CPU firmware versions limit the number of Profinet IO devices and the maximum cyclic payload. Always check the CPU's manual for the exact limits of the firmware revision deployed.