1. Overview: Why CP443 Modules Require Managed Replacement
SIMATIC S7-400 communication processors (CP 443) are field-replaceable modules, but unlike a like-for-like swap, migrating from an older CP443-1 or CP443-5DX to its successor is a controlled, multi-step procedure. The replacement affects STEP 7 hardware configuration, firmware revision handling, status code interpretation, and—in some cases—physical interface conversion (AUI to RJ45). A blind swap with the same catalog number reuses the same HW Config slot, while moving to a successor demands that the engineer accept the new module's type, re-validate application blocks, and re-verify network partners.
This reference covers migration of two specific modules within a S7-400 station built around a CPU 6ES7416-2XK04-0AB0 (S7-416F-2 / S7-416-2 family):
- CP 443-1 6GK7443-1EX11-0XE0 (Industrial Ethernet / PROFINET)
- CP 443-5DX 6GK7443-5DX04-0XE0 (PROFIBUS DP master)
It also documents the optional in-station CPU upgrade to 6ES7416-2XN05-0AB0, which can be performed concurrently without disturbing CP replacement.
2. Affected Modules and Their Successors
The table below maps the legacy modules referenced in the source application to their Siemens-published successors. Use the rightmost column when ordering replacement hardware.
| Legacy Module | Function | Direct Successor | Current/Long-Term Successor | Phased-Out Status |
|---|---|---|---|---|
| 6GK7443-1EX11-0XE0 | CP 443-1 (Industrial Ethernet, TCP/UDP, S7/S5 communication, FETCH/WRITE) | 6GK7443-1EX20-0XE0 | 6GK7443-1EX30-0XE0 | EX11: discontinued; EX20: phased out 02/2013 |
| 6GK7443-5DX04-0XE0 | CP 443-5DX (PROFIBUS DP master, S7-400 backplane) | 6GK7443-5DX05-0XE0 | — | DX04: discontinued |
| 6ES7416-2XK04-0AB0 | CPU 416-2 (relevant if concurrent CPU migration) | — | 6ES7416-2XN05-0AB0 | Check firmware compatibility for the target SIMATIC S7-400F CPU generation |
3. Interface and Firmware Compatibility Matrix
The two CP families behave very differently in terms of physical ports, supported protocols, and firmware revision handling. The EX11 → EX20 → EX30 chain is not a transparent drop-in; each step introduces interface, status-code, and configuration changes.
| Attribute | CP 443-1 EX11 | CP 443-1 EX20 | CP 443-1 EX30 | CP 443-5DX04 | CP 443-5DX05 |
|---|---|---|---|---|---|
| MLFB / Order No. | 6GK7443-1EX11-0XE0 | 6GK7443-1EX20-0XE0 | 6GK7443-1EX30-0XE0 | 6GK7443-5DX04-0XE0 | 6GK7443-5DX05-0XE0 |
| Ethernet ports | 1 × RJ45 + 1 × AUI/ITP (combined) | 1 × RJ45 (AUI removed) | 1 × RJ45 (AUI removed) | — | — |
| PROFIBUS ports | — | — | — | 1 × DP master | 1 × DP master |
| AG_CNTRL support | No | Yes (with differences) | Yes | N/A | N/A |
| IP routing / iDevice | No | Limited (firmware dependent) | Yes | No | No |
| STEP 7 V5.4 SP3 / SPx | Supported | Supported (with HW Config replace) | Supported via HSP / GSD | Supported | Supported |
| Hardware revision compatibility | 1 | 1 (with V1.0 firmware note) | 1+ | 1 | 1+ |
4. Prerequisites
Before scheduling the replacement window, verify the following engineering and site prerequisites:
- Project archive of the current STEP 7 V5.4+ project, including HW Config and NetPro, taken immediately before shutdown.
- STEP 7 installation matching the project version (V5.4 SP3 minimum for EX20/EX30 and 6GK7443-5DX05-0XE0; install the latest available Service Pack and Hardware Support Package / HSP for the EX30 module).
- Sufficient slots in the S7-400 rack: the EX30 retains the same physical slot footprint as EX11/EX20, but verify mechanical fit if the station uses a UR2/UR2-H rack with adjacent wide modules.
- Network cabling readiness: pre-installed RJ45 patch cables with the correct pin-out (TIA-568A/B), and—if applicable—an AUI/RJ45 media converter (e.g., Siemens SIMATIC NET SCALANCE media converter or third-party 10Base5-to-10Base-TX).
- MAC and IP plan: document the EX11 module's MAC and IP configuration. The successor modules ship with different factory MAC addresses; the configured IP address is preserved in HW Config but must be re-applied via STEP 7 after the module is recognized as a new type.
- Spare modules on-site: at least one of each target module (6GK7443-1EX30-0XE0 and 6GK7443-5DX05-0XE0) plus a known-good memory card if the CPU is being replaced in parallel.
- Anti-static precautions: S7-400 modules are ESD-sensitive; use a grounded wrist strap and an ESD-safe surface.
5. CP 443-1 Migration: EX11 → EX20 → EX30
The CP 443-1 line is the more demanding migration because the successor modules are not pin-compatible at the Ethernet port. Apply the following workflow.
5.1 Mechanical removal of the EX11
- Power down the S7-400 station (PS 405/PS 407 power supply OFF, then remove the backup battery only if a memory card is being moved).
- Label and disconnect the RJ45 and AUI cables from the CP 443-1 EX11. Photograph the cable management.
- Loosen the module's two front screws, pivot the bottom release lever, and lift the module out of the rack. Place it in an ESD bag.
5.2 Adapter decision for the AUI port
If the existing plant cabling terminates on the AUI/DB-15 connector of the EX11, you have two options:
- Option A — Media converter: install a SIMATIC NET media converter (e.g., 6GK1 161-1AA01 or equivalent third-party 10Base5/10Base2-to-10Base-TX) and run a short RJ45 patch to the new EX20/EX30.
- Option B — Re-cable: re-pull twisted-pair cabling to the nearest Ethernet switch and terminate with RJ45.
5.3 STEP 7 HW Config replacement procedure
- Open the STEP 7 project, then open HW Config for the S7-400 station.
- Right-click the CP 443-1 (EX11) slot in the rack and choose Replace Object… (in German: Objekt austauschen). The HW Config catalog will offer the EX20 and (if the matching HSP is installed) the EX30 as compatible replacement types.
- Select 6GK7443-1EX30-0XE0 for the new deployment, or 6GK7443-1EX20-0XE0 if you are temporarily bridging to stock already on hand.
- Confirm the dialog. HW Config will inherit the slot, the network attachment in NetPro, and most of the connection configuration—but you must re-validate the IP address, subnet mask, and router.
- Save and recompile the station (Station > Save and Compile).
6. CP 443-5DX Migration: DX04 → DX05
The PROFIBUS CP migration is mechanically identical to the EX11 → EX30 swap but logically simpler because the DX05 is a near drop-in for the DX04 in STEP 7.
- Open HW Config, right-click the CP 443-5DX (DX04) slot, and select Replace Object….
- Select 6GK7443-5DX05-0XE0.
- Verify the PROFIBUS DP master parameters: baud rate, DP master system ID, and bus parameters (TSL, TSET, TTR, min TSDR) are retained.
- Re-compile and download the HW Config to the S7-400 CPU (online > download).
The DX05 retains the same PG/OP and S7 routing capabilities, and the diagnostic buffer interpretation for PROFIBUS station failure (SF/BSF) is consistent between DX04 and DX05 firmware revisions documented in the SIMATIC NET manual.
7. AUI-to-RJ45 Conversion: Field-Proven Procedure
When the AUI/ITP interface is the active network attachment, conversion is the highest-risk step. Use the following approach to minimize commissioning time:
- Document the existing AUI segment: transceiver type (e.g., MAU), cable type (10Base2/10Base5), segment length, and termination.
- Power down the segment at the AUI transceiver or hub.
- Disconnect the AUI drop cable from the EX11's DB-15 AUI port.
- Install the media converter in the same enclosure or a nearby DIN-rail location; connect the AUI side to the existing transceiver and the RJ45 side to the new EX20/EX30 via a short (< 3 m) shielded patch cord.
- Set the converter's link mode to auto-negotiate 10 Mbps full-duplex or force 10 Mbps half-duplex, depending on the legacy AUI segment's CSMA/CD behavior.
- Power the segment and verify link LEDs on both the converter and the new CP.
8. Concurrent CPU Replacement (6ES7416-2XK04-0AB0 → 6ES7416-2XN05-0AB0)
If the application requires upgrading the CPU in parallel with the CP replacement, the two operations are independent and can be sequenced as follows:
- Open HW Config, right-click the CPU slot, and select Replace Object….
- Choose 6ES7416-2XN05-0AB0 from the catalog (the catalog filters on the supported successor list).
- STEP 7 preserves the OB/FB/FC calls, the symbol table, and the CP slot configuration. No CP-side configuration edit is required by this operation alone.
- Save and re-compile the station. STEP 7 may warn about the new CPU's larger address space; review and accept.
- Replace the SIMATIC memory card if the new CPU's firmware requires a different card generation. For S7-400F CPUs, observe the safety-mode transfer rules; the S7-400F Manual Collection covers the memory-card swap procedure (see Replacing a defective SIMATIC memory card for the S7-1500R equivalent procedure and the S7-400F manual for the S7-400 variant).
- Insert the new CPU, apply power, and download the HW Config to the new CPU.
9. AG_CNTRL and Status Code Behavior
When application code uses the AG_CNTRL / AG_LSEND / AG_LRECV / AG_RECV / AG_SEND blocks for industrial Ethernet communication, the successor CP returns different STATUS codes than the EX11. Engineers migrating from EX11 to EX20 or EX30 must:
- Re-read the CP 443-1 manual's section on STATUS code mapping for the target firmware revision.
- Update any user code that pattern-matches on specific status values (e.g., 0x0001, 0x7000, 0x8180, 0x8183, 0x8304) and that branches on the meaning of these codes.
- Build a STATUS-code translation table in the project documentation. The mapping is not 1:1 across EX11 → EX20 → EX30; documented differences exist in link-down, resource-busy, and partner-not-reachable indicators.
The official Siemens S7 Open Modbus TCP add-on documentation and the CP 443-1 manual (chapter 5 of the upgrade guide) describe the most prominent status-code deltas. Always cross-check the firmware revision listed in the module's Module Information > Firmware dialog after installation.
10. Verification and Commissioning
After the mechanical and STEP 7 work is complete, run the following verification sequence before handing the station back to operations.
10.1 Hardware-level verification
- Power up the S7-400 station and observe the CP front-panel LEDs: SF (red, group fault), BF (red, bus fault), LINK (green, physical link), and RX/TX (yellow, traffic). Expected state: SF off, BF off, LINK on, RX/TX flashing on legitimate traffic.
- Open Online > Accessible Nodes in STEP 7 and confirm the new CP responds with its configured IP address.
10.2 Configuration-level verification
- Open Online > Diagnose Hardware; verify the new MLFB appears and the firmware revision matches the expected one.
- In NetPro, right-click the new CP and select Connection Diagnostics; run a status check on every configured S7 / TCP / ISO-on-TCP connection.
- For PROFIBUS, run DP Slave Diagnosis on every slave and verify station-status-1 / station-status-2 / station-status-3 bytes match the baseline.
10.3 Application-level verification
- Trigger each AG_CNTRL or AG_SEND/AG_RECV pair from the application and confirm positive acknowledgments at the new CP's STATUS output.
- Cycle the application through its fault path (link down, partner offline) and confirm the new STATUS code reaches the HMI / alarm log correctly.
11. Troubleshooting Matrix
| Symptom | Likely Cause | Diagnostic Step | Corrective Action |
|---|---|---|---|
| CP front-panel SF LED on after replacement | HW Config not re-downloaded; slot mismatch | Online > Diagnose Hardware | Save and re-download HW Config to CPU |
| BF LED on, no link | Wrong media converter or RJ45 pin-out | Check LINK LED; use a cable tester | Replace cable; verify AUI/RJ45 converter is set to 10 Mbit/s HDX |
| CP reachable in STEP 7 but application STATUS = 0x8304 (partner not reachable) | Partner IP or routing not preserved after replace | NetPro > Connection Diagnostics | Re-enter partner IP; re-establish connection |
| AG_CNTRL behaves differently from pre-replacement | STATUS code map changed for new firmware | Compare STATUS output before/after with the same trigger | Update user-code branches per CP manual's STATUS code table |
| PROFIBUS slave diagnostics report station failure after DX05 swap | Bus parameters were re-defaulted | HW Config > DP master properties > Bus Parameters | Restore TSL/TSET/min TSDR from the DX04 baseline |
| CPU replacement: PG cannot go online | New CPU has different MPI/DP address or firmware boot state | Check PG/PC interface assignment | Set the new CPU's MPI address to match the previous one via the mode selector |
| PLC fault: "Module does not exist" or "Incorrect module in slot" | HW Config still references old MLFB | Compare HW Config slot vs. physically inserted module | Re-run Replace Object and re-download |
12. Field-Proven Notes and Lifecycle Caveats
- Phased-out successor chain: Because the EX20 was phased out in 02/2013, do not use it for new installations. Use the EX30 directly. Treat any stock of EX20 as a bridge for a known spares shortage, not a long-term solution.
- Firmware version pinning: When ordering, specify the firmware revision (e.g., V1.0, V2.0) that matches your STEP 7 HSP. Mixing an EX20 V1.0 with a STEP 7 V5.4 SP3 base install (no HSP) is a documented incompatibility source.
- MAC address handling: The factory MAC address of the EX20/EX30 differs from the EX11. If you use MAC-based port security on managed switches, update the security ACL after the swap.
- Spare-parts stocking rule of thumb: For a fleet of S7-400 stations, keep at least one EX30 and one DX05 on site per 10 stations, plus an AUI/RJ45 media converter if any AUI/ITP segments are still in service.
- Documentation discipline: Update the station's wiring diagram and the plant's asset database with the new MLFB. The serial number on the module label is the new authoritative identity for warranty and firmware updates.
What is the current successor of the 6GK7443-1EX11-0XE0?
The 6GK7443-1EX11-0XE0 is replaced by 6GK7443-1EX20-0XE0 as a direct successor; the 6GK7443-1EX20-0XE0 is itself phased out as of February 2013, and the long-term successor is the 6GK7443-1EX30-0XE0. For new deployments, use the EX30.
What replaces the 6GK7443-5DX04-0XE0 PROFIBUS CP?
The 6GK7443-5DX04-0XE0 is replaced by the 6GK7443-5DX05-0XE0. The DX05 retains the same DP master footprint, STEP 7 hardware entry, and PROFIBUS diagnostic behavior; the migration is a HW Config Replace Object and re-compile.
Can I replace the CP 443-1 EX11 with an EX20 or EX30 without changing the wiring?
Only if your plant cabling terminates on RJ45. The EX11 has a combined RJ45 + AUI/DB-15 port; the EX20 and EX30 expose only RJ45. If the active connection uses the AUI port, install an AUI/RJ45 media converter (set to 10 Mbit/s half-duplex) or re-cable the segment.
Do I need to change the STEP 7 program when replacing the EX11 with an EX20 or EX30?
Yes. The HW Config slot must be re-typed via Replace Object in STEP 7 V5.4 SP3 or later, and any user code that pattern-matches on the AG_CNTRL / AG_SEND / AG_RECV STATUS codes must be reviewed against the new CP firmware's STATUS map. Re-validate all S7 and ISO-on-TCP connections in NetPro.
Can I replace the CPU 6ES7416-2XK04-0AB0 with 6ES7416-2XN05-0AB0 at the same time as the CP replacement?
Yes. Use Replace Object on the CPU slot in HW Config; this preserves the CP slot configuration and the program. The CP-side work is independent of the CPU replacement. For F-CPU variants, re-validate the safety program signature after the HW Config change.