Remote Accessing S7-300 and S7-300 / S7-200: Engineering Reference
Remote service for SIMATIC S7-300 stations (CPU 314, CPU 315-2DP) and S7-200 stations (CPU 226) over hundreds of kilometers is a routine field requirement. This reference consolidates the three industrial-grade access topologies: site-to-site VPN, cellular (GPRS/3G/EDGE) gateway, and ISDN/analog TeleService. It also resolves the recurring CP343-1 Lean vs. CP343-1 IT selection, defines the S7-200 Ethernet bring-up path, and gives the S7 connection configuration parameters required to program both sides of the link.
1. Network Topology Overview
Three topologies meet the requirement. Selection is driven by the on-site Ethernet capability of each CPU, the customer's existing WAN infrastructure, and the acceptable OPEX (recurring SIM/data costs) versus CAPEX (router hardware).
| Topology | On-Site Ethernet Required | WAN Reach | OPEX Driver | Typical Latency |
|---|---|---|---|---|
| Customer-site VPN + Static IP | Yes (CP 343-1 or PN-CPU) | Internet, customer firewall | None beyond ISP | 20-80 ms |
| Cellular gateway (GPRS/3G) | Yes | Mobile network | SIM data plan | 150-600 ms |
| TeleService (TS Adapter / TS Module) | No (uses MPI/PROFIBUS) | ISDN or analog dial-in | Telco line rental | Dial-up |
2. Option 1 — Site VPN with Static Public IP (Recommended Default)
2.1 Hardware Prerequisites
- S7-300 CPU 315-2DP: already has an MPI/DP interface; add CP 343-1 Lean or CP 343-1 IT for Ethernet. The CPU 315-2DP does not embed PROFINET.
- S7-300 CPU 314 (6ES7 314-1AG14-0AB0 and similar): no integrated Ethernet, requires CP 343-1 Lean (6GK7 343-1CX10-0XE0) minimum.
- S7-200 CPU 226 (6ES7 216-2AD23-0XB0): no integrated Ethernet. Add CP 243-1 IT (6GK7 243-1GX00-0XE0) or CP 243-1 (6GK7 243-1EX00-0XE0) Ethernet module.
- Industrial 5-port unmanaged switch (e.g., Westermo SDW-550 or equivalent DIN-rail switch).
- Customer firewall / SOHO router capable of site-to-site IPsec or OpenVPN.
- Static public IPv4 address (or a DynDNS hostname pointing at a near-static IP).
2.2 IP Addressing Plan
| Device | IP Address | Subnet Mask | Default Gateway |
|---|---|---|---|
| S7-300 #1 (CP 343-1) | 192.168.10.11 | 255.255.255.0 | 192.168.10.1 |
| S7-300 #2 (CP 343-1) | 192.168.10.12 | 255.255.255.0 | 192.168.10.1 |
| S7-300 #3 (CP 343-1) | 192.168.10.13 | 255.255.255.0 | 192.168.10.1 |
| S7-200 CPU 226 (CP 243-1) | 192.168.10.21 | 255.255.255.0 | 192.168.10.1 |
| Customer router (LAN side) | 192.168.10.1 | 255.255.255.0 | — |
| Customer router (WAN side) | 203.0.113.50 (example) | ISP-provided | ISP GW |
2.3 Firewall / Port Forwarding
The customer router must forward TCP 102 (ISO-on-TCP / RFC 1006) to the engineering VLAN. Siemens S7 communication uses ISO Transport over TCP port 102 exclusively.
- TCP 102 — S7 communication (STEP 7 ↔ PLC, HMI ↔ PLC, S7 PUT/GET).
- UDP 161/162 — optional, only if SNMP-based network management is in use.
- TCP 500, UDP 500, UDP 4500 (IPsec NAT-T) — required for the IPsec tunnel to the engineering office.
2.4 STEP 7 (TIA Portal / STEP 7 V5.x) Configuration
- Open the project in STEP 7 (or TIA Portal).
- In HW Config, double-click the CP 343-1 and assign the IP address from the table above. Set the subnet mask and router address.
- In NetPro, create an S7 connection for each remote CPU. The S7 connection is configured on both sides (client and server) — see Siemens application note "S7 Communication over Industrial Ethernet".
- Set the partner IP to the public (WAN) address of the remote site for the engineering interface, or to the LAN address of the target PLC if accessing from inside the same routed domain.
- Download the hardware configuration to the CP 343-1.
3. Option 2 — Cellular (GPRS / 3G / EDGE) Gateway
Use this topology when the customer has no wired internet at the machine site (rural plant, mobile skid, or shared building without IT infrastructure). A rugged industrial cellular router with Ethernet LAN bridges into the CP 343-1 and the CP 243-1 (on the S7-200).
3.1 Hardware Selection
| Capability | Minimum Spec | Notes |
|---|---|---|
| Cellular bands | Quad-band GSM/GPRS/EDGE; UMTS/HSPA preferred | EDGE is the fallback when 3G is unavailable |
| Ethernet ports | 1× RJ45 LAN minimum, 2-4× preferred | Must support 10/100 Mbit/s full duplex |
| Power input | 12-24 V DC, ±20 % | Industrial cabinet power |
| Operating temperature | -25 °C to +70 °C | Cabinet interior acceptable; verify for unventilated panels |
| VPN client | IPsec, OpenVPN, or L2TP | IPsec is preferred for IT department acceptance |
| SIM holder | Standard SIM (or eSIM via industrial SKU) | Use a multi-network M2M SIM for best coverage |
3.2 Engineering-Office End
The engineering office must run a VPN concentrator (a second router, a software endpoint such as OpenVPN Access Server, or the firewall's built-in IPsec server). The cellular router initiates the IPsec tunnel outbound to the concentrator, which means no inbound public IP is needed at either end and the firewall posture is the same as Option 1 from the inside.
3.3 Bandwidth and Latency Notes
- GPRS typical downlink: 30-50 kbit/s; EDGE: 100-200 kbit/s; HSPA: 1-5 Mbit/s.
- S7-300 online services over TCP 102 function reliably on EDGE and above. GPRS is acceptable for short PUT/GET data blocks (≤ 200 bytes) and for STEP 7 online diagnostics, but program download over GPRS is not recommended.
- Add an IP-filter on the cellular router to drop unsolicited inbound traffic; allow only the IPsec UDP 500 / UDP 4500 and ICMP to the engineering peer.
4. Option 3 — TeleService (TS Adapter / TS Module)
SIMATIC TeleService predates the wide availability of broadband internet and remains a valid option where the customer cannot or will not expose Ethernet, or where the existing CPU has no CP module.
4.1 Components
- TS Adapter II (6ES7 972-0CA00-0XA0) — for S7-300 stations on MPI/PROFIBUS.
- TS Module for S7-200 (6ES7 240-1AA00) — connects to the PPI/MPI port of the CPU 226.
- Modem — ISDN terminal adapter (most common in EU installations) or analog PSTN modem. The TS Adapter supports both ISDN and analog interfaces; the TS Module for S7-200 supports analog only.
4.2 Configuration
- Install the TeleService software component (add-on to STEP 7 V5.x).
- Create a TeleService object in the project; assign the phone number of the engineering office and the callback number of the customer site.
- Configure the TS Adapter via its integrated web interface: set MPI address, MPI baud rate (default 187.5 kbit/s), and the dial-in parameters.
- From the engineering office, the engineer dials in; the TS Adapter auto-answers and bridges the call to the S7-300 MPI bus.
5. CP 343-1 Lean vs. CP 343-1 IT — Decision Matrix
This is the most common selection question for S7-300 Ethernet. Both modules are physically similar and plug into the S7-300 backplane. The decision is driven by the protocols the application requires.
| Feature | CP 343-1 Lean (6GK7 343-1CX10-0XE0) | CP 343-1 IT (6GK7 343-1GX11-0XE0) |
|---|---|---|
| S7 communication (PUT/GET, client+server) | Yes | Yes |
| PG / STEP 7 online over Ethernet | Yes | Yes |
| HMI communication (WinCC flexible, TIA Portal HMI) | Yes | Yes |
| Open IE communication (TCP/UDP, ISO-on-TCP) via SEND/RECV / TCON | Yes (max 8 connections) | Yes (max 16 connections) |
| Web server (S7-300 station pages) | No | Yes |
| FTP client (send data files) | No | Yes |
| E-mail via SMTP (alarm dispatch) | No | Yes |
| Number of IT/PG/HMI/S7 connections | 8 total | 16 total |
| PROFINET IO Controller / IO Device | No (Lean variant) | No (basic IT variant) — use CP 343-1 PN for PROFINET |
| Firmware updates via STEP 7 | Yes | Yes |
Selection rule for this customer: If the requirement is only S7 communication and STEP 7 remote access, the CP 343-1 Lean is sufficient and lower cost. The CP 343-1 IT adds value when the customer wants the S7-300 to send e-mail on alarm, host a small diagnostic web page, or push archive files by FTP — features that materially improve 24/7 serviceability.
6. S7-200 Ethernet Bring-Up
The S7-200 CPU 226 does not have an integrated Ethernet port. The CP 243-1 (or CP 243-1 IT) is required. The CP 243-1 IT is the more capable variant; the CP 243-1 is the basic S7-communication module.
6.1 S7-200 + CP 243-1 IT Configuration with STEP 7-Micro/WIN
- In STEP 7-Micro/WIN, open the Ethernet Wizard.
- Select module position (slot 0 of the S7-200 expansion bus).
- Assign the IP address 192.168.10.21, mask 255.255.255.0, gateway 192.168.10.1.
- Configure the number of S7 connections (max 8 for CP 243-1, max 16 for CP 243-1 IT). Each connection is either a client (PUT/GET initiated by the S7-200) or a server (partner initiates).
- Select the connection to TSAP (Transport Service Access Point) partner; this is the same hex TSAP used by the S7-300 NetPro S7 connection.
- Generate the program blocks the wizard creates (ETHx_CTRL, ETHx_CFG) and download them with the project.
PG connection mode is supported; STEP 7-Micro/WIN can program the S7-200 across the Ethernet by using the CP 243-1 as the PG interface. See the S7-200 device communication parameters reference for connection and TSAP mapping.
7. S7 Connection Configuration (Client ↔ Server)
An S7 connection is configured on both partners; the parameters on both sides must match exactly or the connection refuses to come up.
7.1 Parameter Mapping (CPU 315-2DP client → CPU 226 / CP 243-1 server)
| Parameter | Client (S7-300, NetPro) | Server (S7-200, Ethernet Wizard) |
|---|---|---|
| Connection type | S7 connection | S7 connection (server) |
| Local end point | CP 343-1, local IP | CP 243-1, local IP |
| Partner end point | Remote IP 192.168.10.21 | Partner IP 192.168.10.11 (or unspecified) |
| Local TSAP | 03.01 (rack 0, slot 1 — example) | Matches partner's partner TSAP |
| Partner TSAP | 03.00 (S7-200 default slot 0) | 03.00 (S7-200 default slot 0) |
| Establishment | Active (client initiates) | Passive (server accepts) |
For a CPU 226, the default TSAP is 03.00. The S7-300 side is configured as the active partner; the S7-200 side is passive. Both sides must reference the same rack/slot TSAPs. Refer to the Siemens S7 Communication over Industrial Ethernet application note for the complete TSAP rules and the PUT/GET block parameter layout.
8. PG Mode for Online Access
For STEP 7 V5.x and STEP 7-Micro/WIN to program the PLCs over the remote link, the engineering PG needs a route to the public IP (or VPN virtual IP) of the customer site. The route is automatic if the engineering office is the IPsec peer.
- In STEP 7, choose Options → Set PG/PC Interface; select TCP/IP with the office's Ethernet adapter.
- Use Accessible Nodes to scan; the three S7-300 stations and the S7-200 (via CP 243-1) should appear in the list.
- Double-click to open online; the same diagnostics view is available as on-site.
9. Commissioning and Verification
After installing the hardware, perform the following sequence before declaring the link in service.
- Layer 1/2 check: link LEDs on switch, CP 343-1, CP 243-1, and router. Pings between the PG, the office firewall, and the LAN side of the customer router succeed.
- IPsec tunnel up: on the customer router's status page, confirm the tunnel is established and the negotiated SA lifetime is non-zero.
- PG online scan: all four PLCs appear in Accessible Nodes.
- S7 connection status: in NetPro, right-click the S7 connection and check status. A green check indicates the connection is established; a red X with diagnostic buffer entry 0x4A, 0x4B, or 0x4C indicates a parameter mismatch (TSAP / IP), a connection refused, or a partner unreachable.
- PUT/GET smoke test: from the S7-300 trigger a small block PUT to the S7-200 and verify the data on the S7-200 side using a status table in Micro/WIN.
- Latency check: ping the remote PLC 100 times; median should be under 100 ms on a VPN, under 500 ms on EDGE.
- Failover test: disconnect the WAN link and confirm the engineering office is notified (e.g., via a watchdog e-mail from the CP 343-1 IT).
10. Troubleshooting Matrix
| Symptom | Likely Root Cause | Diagnostic Step | Resolution |
|---|---|---|---|
| PG cannot see any PLC in Accessible Nodes | IPsec tunnel down or port 102 blocked | Ping remote router; check firewall logs for TCP 102 | Re-establish IPsec; open TCP 102 inbound on customer firewall |
| S7-300 visible, S7-200 not | CP 243-1 not configured or wrong IP | Ping 192.168.10.21 from a station on the same LAN | Re-run Ethernet Wizard, re-download blocks |
| S7 connection refused, NetPro status red | TSAP mismatch between S7-300 and S7-200 | Check diagnostic buffer for S7 connection error 0x4A/0x4B | Set both partners to the same TSAP (S7-200 default 03.00) |
| Connection cycles up and down | Wrong subnet mask; broadcast storms on switch | Check SZL 0x0131 (CP status) and SZL 0x0132 (port status) | Re-check IP/subnet; replace unmanaged switch with managed switch and disable broadcast storm |
| Online works, program download fails | Bandwidth too low / latency too high on GPRS | Measure round-trip latency | Schedule downloads on HSPA/3G coverage; use cellular router external antenna |
| TeleService dials in but no MPI traffic | TS Adapter MPI address conflict | Check MPI bus with STEP 7 online Accessible Nodes MPI | Set TS Adapter to a free MPI address; ensure highest MPI address on bus |
| CP 343-1 IT sends no e-mail | SMTP port 25 blocked by customer firewall | Check CP 343-1 IT diagnostic buffer for SEND MAIL errors | Open TCP 25 outbound or use authenticated SMTP on TCP 587 |
11. Security Hardening Checklist
- Restrict the IPsec peer list to the engineering office's static IP; reject dynamic peers.
- Enable the S7 CP's "Access protection" (password / CPU protect) on every S7-300 and the S7-200.
- Disable the S7-200's PPI/MPI port if remote access is the only path (CP 243-1 keeps the bus active via Ethernet).
- Set the cellular router to firewall-off all inbound ports; allow only IPsec.
- Rotate the STEP 7 project password at every service contract renewal.
- Log every engineering access (VPN concentrator log + STEP 7 audit trail if enabled).
12. FAQ
Do I need a CP 343-1, or can a CPU 315-2PN/DP connect directly to Ethernet?
The CPU 315-2DP (6ES7 315-2AH14-0AB0) has no integrated PROFINET interface; it requires a CP 343-1 family module for Ethernet. Only the CPU 315-2PN/DP and CPU 317-2PN/DP have an on-board PROFINET port that can be used for S7 communication and STEP 7 online access.
Is the CP 343-1 Lean enough for STEP 7 remote programming and S7 PUT/GET?
Yes. The CP 343-1 Lean supports S7 communication (PUT/GET, both client and server), PG/STEP 7 online over Ethernet, and HMI communication. The CP 343-1 IT is only required if you need the S7-300 to act as an e-mail client, host a web server, or push files via FTP.
How do I give the S7-200 CPU 226 Ethernet connectivity?
Add a CP 243-1 (6GK7 243-1EX00-0XE0) for S7 communication only, or a CP 243-1 IT (6GK7 243-1GX00-0XE0) if you also need e-mail or web diagnostic features. Configure the IP and S7 connections in STEP 7-Micro/WIN's Ethernet Wizard and download the generated program blocks.
What TCP port does STEP 7 use to reach a remote S7-300 or S7-200?
TCP 102 (ISO Transport over TCP, RFC 1006). This is the only port used by S7 communication and STEP 7 online. Your firewall or IPsec tunnel must allow TCP 102 between the engineering PG and the remote PLC subnet.
Can the S7-300 and the S7-200 exchange data directly over the same remote link?
Yes. Configure an S7 connection in NetPro on the S7-300 (active partner) pointing to the S7-200 (passive server, TSAP 03.00). Use SFB/FB PUT and GET to exchange data blocks. The S7-200 partner IP is the LAN IP of the CP 243-1; the S7-300 sees the S7-200 through the same VPN tunnel that the PG uses for online access.
Is TeleService still recommended for 24/7 service?
For 24/7 remote service, VPN (Option 1) is the modern default. TeleService (Option 3) is best reserved for legacy installations with no Ethernet and for occasional diagnostic dial-in. Cellular gateway (Option 2) is the fallback when the customer has no wired internet and a SIM is acceptable.