Replacing CP443-1 Cards in S7-400: Successor Migration Guide

David Krause13 min read
Industrial NetworkingSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview: Why CP443 Modules Require Managed Replacement

SIMATIC S7-400 communication processors (CP 443) are field-replaceable modules, but unlike a like-for-like swap, migrating from an older CP443-1 or CP443-5DX to its successor is a controlled, multi-step procedure. The replacement affects STEP 7 hardware configuration, firmware revision handling, status code interpretation, and—in some cases—physical interface conversion (AUI to RJ45). A blind swap with the same catalog number reuses the same HW Config slot, while moving to a successor demands that the engineer accept the new module's type, re-validate application blocks, and re-verify network partners.

This reference covers migration of two specific modules within a S7-400 station built around a CPU 6ES7416-2XK04-0AB0 (S7-416F-2 / S7-416-2 family):

  • CP 443-1 6GK7443-1EX11-0XE0 (Industrial Ethernet / PROFINET)
  • CP 443-5DX 6GK7443-5DX04-0XE0 (PROFIBUS DP master)

It also documents the optional in-station CPU upgrade to 6ES7416-2XN05-0AB0, which can be performed concurrently without disturbing CP replacement.

Important: CP 443-1 (6GK7443-1EX20-0XE0) was declared a phased-out product in February 2013. The current successor is 6GK7443-1EX30-0XE0. Plan your spare-parts lifecycle accordingly; do not stock the EX20 for new projects.

2. Affected Modules and Their Successors

The table below maps the legacy modules referenced in the source application to their Siemens-published successors. Use the rightmost column when ordering replacement hardware.

Legacy Module Function Direct Successor Current/Long-Term Successor Phased-Out Status
6GK7443-1EX11-0XE0 CP 443-1 (Industrial Ethernet, TCP/UDP, S7/S5 communication, FETCH/WRITE) 6GK7443-1EX20-0XE0 6GK7443-1EX30-0XE0 EX11: discontinued; EX20: phased out 02/2013
6GK7443-5DX04-0XE0 CP 443-5DX (PROFIBUS DP master, S7-400 backplane) 6GK7443-5DX05-0XE0 — DX04: discontinued
6ES7416-2XK04-0AB0 CPU 416-2 (relevant if concurrent CPU migration) — 6ES7416-2XN05-0AB0 Check firmware compatibility for the target SIMATIC S7-400F CPU generation

3. Interface and Firmware Compatibility Matrix

The two CP families behave very differently in terms of physical ports, supported protocols, and firmware revision handling. The EX11 → EX20 → EX30 chain is not a transparent drop-in; each step introduces interface, status-code, and configuration changes.

Attribute CP 443-1 EX11 CP 443-1 EX20 CP 443-1 EX30 CP 443-5DX04 CP 443-5DX05
MLFB / Order No. 6GK7443-1EX11-0XE0 6GK7443-1EX20-0XE0 6GK7443-1EX30-0XE0 6GK7443-5DX04-0XE0 6GK7443-5DX05-0XE0
Ethernet ports 1 × RJ45 + 1 × AUI/ITP (combined) 1 × RJ45 (AUI removed) 1 × RJ45 (AUI removed) — —
PROFIBUS ports — — — 1 × DP master 1 × DP master
AG_CNTRL support No Yes (with differences) Yes N/A N/A
IP routing / iDevice No Limited (firmware dependent) Yes No No
STEP 7 V5.4 SP3 / SPx Supported Supported (with HW Config replace) Supported via HSP / GSD Supported Supported
Hardware revision compatibility 1 1 (with V1.0 firmware note) 1+ 1 1+
Critical observation: The EX11 module exposes an AUI/ITP interface alongside RJ45. If your plant cabling is still on 10Base5 (AUI/Thick Ethernet) or 10Base2, the EX20/EX30 cannot accept the AUI connector directly—an external AUI/RJ45 media converter is required. Failing to address this is the single most common field-installation error in CP443-1 migration.

4. Prerequisites

Before scheduling the replacement window, verify the following engineering and site prerequisites:

  1. Project archive of the current STEP 7 V5.4+ project, including HW Config and NetPro, taken immediately before shutdown.
  2. STEP 7 installation matching the project version (V5.4 SP3 minimum for EX20/EX30 and 6GK7443-5DX05-0XE0; install the latest available Service Pack and Hardware Support Package / HSP for the EX30 module).
  3. Sufficient slots in the S7-400 rack: the EX30 retains the same physical slot footprint as EX11/EX20, but verify mechanical fit if the station uses a UR2/UR2-H rack with adjacent wide modules.
  4. Network cabling readiness: pre-installed RJ45 patch cables with the correct pin-out (TIA-568A/B), and—if applicable—an AUI/RJ45 media converter (e.g., Siemens SIMATIC NET SCALANCE media converter or third-party 10Base5-to-10Base-TX).
  5. MAC and IP plan: document the EX11 module's MAC and IP configuration. The successor modules ship with different factory MAC addresses; the configured IP address is preserved in HW Config but must be re-applied via STEP 7 after the module is recognized as a new type.
  6. Spare modules on-site: at least one of each target module (6GK7443-1EX30-0XE0 and 6GK7443-5DX05-0XE0) plus a known-good memory card if the CPU is being replaced in parallel.
  7. Anti-static precautions: S7-400 modules are ESD-sensitive; use a grounded wrist strap and an ESD-safe surface.

5. CP 443-1 Migration: EX11 → EX20 → EX30

The CP 443-1 line is the more demanding migration because the successor modules are not pin-compatible at the Ethernet port. Apply the following workflow.

5.1 Mechanical removal of the EX11

  1. Power down the S7-400 station (PS 405/PS 407 power supply OFF, then remove the backup battery only if a memory card is being moved).
  2. Label and disconnect the RJ45 and AUI cables from the CP 443-1 EX11. Photograph the cable management.
  3. Loosen the module's two front screws, pivot the bottom release lever, and lift the module out of the rack. Place it in an ESD bag.

5.2 Adapter decision for the AUI port

If the existing plant cabling terminates on the AUI/DB-15 connector of the EX11, you have two options:

  • Option A — Media converter: install a SIMATIC NET media converter (e.g., 6GK1 161-1AA01 or equivalent third-party 10Base5/10Base2-to-10Base-TX) and run a short RJ45 patch to the new EX20/EX30.
  • Option B — Re-cable: re-pull twisted-pair cabling to the nearest Ethernet switch and terminate with RJ45.

5.3 STEP 7 HW Config replacement procedure

  1. Open the STEP 7 project, then open HW Config for the S7-400 station.
  2. Right-click the CP 443-1 (EX11) slot in the rack and choose Replace Object… (in German: Objekt austauschen). The HW Config catalog will offer the EX20 and (if the matching HSP is installed) the EX30 as compatible replacement types.
  3. Select 6GK7443-1EX30-0XE0 for the new deployment, or 6GK7443-1EX20-0XE0 if you are temporarily bridging to stock already on hand.
  4. Confirm the dialog. HW Config will inherit the slot, the network attachment in NetPro, and most of the connection configuration—but you must re-validate the IP address, subnet mask, and router.
  5. Save and recompile the station (Station > Save and Compile).
STEP 7 version note: When replacing EX11 with EX20 V1.0, the STEP 7 procedure documented in the official Siemens FAQ requires explicit HW Config changes (sections 7.3 and 7.4 of the CP 443-1 manual). The dialog-based Replace Object works in STEP 7 V5.4 SP3 and later; older Service Packs must be upgraded.

6. CP 443-5DX Migration: DX04 → DX05

The PROFIBUS CP migration is mechanically identical to the EX11 → EX30 swap but logically simpler because the DX05 is a near drop-in for the DX04 in STEP 7.

  1. Open HW Config, right-click the CP 443-5DX (DX04) slot, and select Replace Object….
  2. Select 6GK7443-5DX05-0XE0.
  3. Verify the PROFIBUS DP master parameters: baud rate, DP master system ID, and bus parameters (TSL, TSET, TTR, min TSDR) are retained.
  4. Re-compile and download the HW Config to the S7-400 CPU (online > download).

The DX05 retains the same PG/OP and S7 routing capabilities, and the diagnostic buffer interpretation for PROFIBUS station failure (SF/BSF) is consistent between DX04 and DX05 firmware revisions documented in the SIMATIC NET manual.

7. AUI-to-RJ45 Conversion: Field-Proven Procedure

When the AUI/ITP interface is the active network attachment, conversion is the highest-risk step. Use the following approach to minimize commissioning time:

  1. Document the existing AUI segment: transceiver type (e.g., MAU), cable type (10Base2/10Base5), segment length, and termination.
  2. Power down the segment at the AUI transceiver or hub.
  3. Disconnect the AUI drop cable from the EX11's DB-15 AUI port.
  4. Install the media converter in the same enclosure or a nearby DIN-rail location; connect the AUI side to the existing transceiver and the RJ45 side to the new EX20/EX30 via a short (< 3 m) shielded patch cord.
  5. Set the converter's link mode to auto-negotiate 10 Mbps full-duplex or force 10 Mbps half-duplex, depending on the legacy AUI segment's CSMA/CD behavior.
  6. Power the segment and verify link LEDs on both the converter and the new CP.
Common pitfall: AUI is a 10 Mbit/s shared medium; modern switches and the EX20/EX30 RJ45 ports auto-negotiate to 100/1000 Mbit/s. If the converter is forced to a higher speed or full-duplex on the AUI side, late collisions and CRC errors will appear in the S7 diagnostic buffer. Always force 10 Mbit/s half-duplex on the AUI-facing side of the media converter.

8. Concurrent CPU Replacement (6ES7416-2XK04-0AB0 → 6ES7416-2XN05-0AB0)

If the application requires upgrading the CPU in parallel with the CP replacement, the two operations are independent and can be sequenced as follows:

  1. Open HW Config, right-click the CPU slot, and select Replace Object….
  2. Choose 6ES7416-2XN05-0AB0 from the catalog (the catalog filters on the supported successor list).
  3. STEP 7 preserves the OB/FB/FC calls, the symbol table, and the CP slot configuration. No CP-side configuration edit is required by this operation alone.
  4. Save and re-compile the station. STEP 7 may warn about the new CPU's larger address space; review and accept.
  5. Replace the SIMATIC memory card if the new CPU's firmware requires a different card generation. For S7-400F CPUs, observe the safety-mode transfer rules; the S7-400F Manual Collection covers the memory-card swap procedure (see Replacing a defective SIMATIC memory card for the S7-1500R equivalent procedure and the S7-400F manual for the S7-400 variant).
  6. Insert the new CPU, apply power, and download the HW Config to the new CPU.
Safety systems: The S7-400F CPU family has fail-safe (F) variants. If your CPU carries an F-suffix, the safety program signature must be re-validated after the HW Config change, and the F-CPU may require a separate safety-mode password to accept the new HW Config.

9. AG_CNTRL and Status Code Behavior

When application code uses the AG_CNTRL / AG_LSEND / AG_LRECV / AG_RECV / AG_SEND blocks for industrial Ethernet communication, the successor CP returns different STATUS codes than the EX11. Engineers migrating from EX11 to EX20 or EX30 must:

  1. Re-read the CP 443-1 manual's section on STATUS code mapping for the target firmware revision.
  2. Update any user code that pattern-matches on specific status values (e.g., 0x0001, 0x7000, 0x8180, 0x8183, 0x8304) and that branches on the meaning of these codes.
  3. Build a STATUS-code translation table in the project documentation. The mapping is not 1:1 across EX11 → EX20 → EX30; documented differences exist in link-down, resource-busy, and partner-not-reachable indicators.

The official Siemens S7 Open Modbus TCP add-on documentation and the CP 443-1 manual (chapter 5 of the upgrade guide) describe the most prominent status-code deltas. Always cross-check the firmware revision listed in the module's Module Information > Firmware dialog after installation.

10. Verification and Commissioning

After the mechanical and STEP 7 work is complete, run the following verification sequence before handing the station back to operations.

10.1 Hardware-level verification

  1. Power up the S7-400 station and observe the CP front-panel LEDs: SF (red, group fault), BF (red, bus fault), LINK (green, physical link), and RX/TX (yellow, traffic). Expected state: SF off, BF off, LINK on, RX/TX flashing on legitimate traffic.
  2. Open Online > Accessible Nodes in STEP 7 and confirm the new CP responds with its configured IP address.

10.2 Configuration-level verification

  1. Open Online > Diagnose Hardware; verify the new MLFB appears and the firmware revision matches the expected one.
  2. In NetPro, right-click the new CP and select Connection Diagnostics; run a status check on every configured S7 / TCP / ISO-on-TCP connection.
  3. For PROFIBUS, run DP Slave Diagnosis on every slave and verify station-status-1 / station-status-2 / station-status-3 bytes match the baseline.

10.3 Application-level verification

  1. Trigger each AG_CNTRL or AG_SEND/AG_RECV pair from the application and confirm positive acknowledgments at the new CP's STATUS output.
  2. Cycle the application through its fault path (link down, partner offline) and confirm the new STATUS code reaches the HMI / alarm log correctly.

11. Troubleshooting Matrix

Symptom Likely Cause Diagnostic Step Corrective Action
CP front-panel SF LED on after replacement HW Config not re-downloaded; slot mismatch Online > Diagnose Hardware Save and re-download HW Config to CPU
BF LED on, no link Wrong media converter or RJ45 pin-out Check LINK LED; use a cable tester Replace cable; verify AUI/RJ45 converter is set to 10 Mbit/s HDX
CP reachable in STEP 7 but application STATUS = 0x8304 (partner not reachable) Partner IP or routing not preserved after replace NetPro > Connection Diagnostics Re-enter partner IP; re-establish connection
AG_CNTRL behaves differently from pre-replacement STATUS code map changed for new firmware Compare STATUS output before/after with the same trigger Update user-code branches per CP manual's STATUS code table
PROFIBUS slave diagnostics report station failure after DX05 swap Bus parameters were re-defaulted HW Config > DP master properties > Bus Parameters Restore TSL/TSET/min TSDR from the DX04 baseline
CPU replacement: PG cannot go online New CPU has different MPI/DP address or firmware boot state Check PG/PC interface assignment Set the new CPU's MPI address to match the previous one via the mode selector
PLC fault: "Module does not exist" or "Incorrect module in slot" HW Config still references old MLFB Compare HW Config slot vs. physically inserted module Re-run Replace Object and re-download

12. Field-Proven Notes and Lifecycle Caveats

  • Phased-out successor chain: Because the EX20 was phased out in 02/2013, do not use it for new installations. Use the EX30 directly. Treat any stock of EX20 as a bridge for a known spares shortage, not a long-term solution.
  • Firmware version pinning: When ordering, specify the firmware revision (e.g., V1.0, V2.0) that matches your STEP 7 HSP. Mixing an EX20 V1.0 with a STEP 7 V5.4 SP3 base install (no HSP) is a documented incompatibility source.
  • MAC address handling: The factory MAC address of the EX20/EX30 differs from the EX11. If you use MAC-based port security on managed switches, update the security ACL after the swap.
  • Spare-parts stocking rule of thumb: For a fleet of S7-400 stations, keep at least one EX30 and one DX05 on site per 10 stations, plus an AUI/RJ45 media converter if any AUI/ITP segments are still in service.
  • Documentation discipline: Update the station's wiring diagram and the plant's asset database with the new MLFB. The serial number on the module label is the new authoritative identity for warranty and firmware updates.
Documentation references: The CP 443-1 manual and the S7-400F Manual Collection (Siemens) are the authoritative sources for status-code maps, slot-compatibility rules, and CPU replacement procedures. Always verify against the current revision of the manual that matches the firmware you are deploying.

What is the current successor of the 6GK7443-1EX11-0XE0?

The 6GK7443-1EX11-0XE0 is replaced by 6GK7443-1EX20-0XE0 as a direct successor; the 6GK7443-1EX20-0XE0 is itself phased out as of February 2013, and the long-term successor is the 6GK7443-1EX30-0XE0. For new deployments, use the EX30.

What replaces the 6GK7443-5DX04-0XE0 PROFIBUS CP?

The 6GK7443-5DX04-0XE0 is replaced by the 6GK7443-5DX05-0XE0. The DX05 retains the same DP master footprint, STEP 7 hardware entry, and PROFIBUS diagnostic behavior; the migration is a HW Config Replace Object and re-compile.

Can I replace the CP 443-1 EX11 with an EX20 or EX30 without changing the wiring?

Only if your plant cabling terminates on RJ45. The EX11 has a combined RJ45 + AUI/DB-15 port; the EX20 and EX30 expose only RJ45. If the active connection uses the AUI port, install an AUI/RJ45 media converter (set to 10 Mbit/s half-duplex) or re-cable the segment.

Do I need to change the STEP 7 program when replacing the EX11 with an EX20 or EX30?

Yes. The HW Config slot must be re-typed via Replace Object in STEP 7 V5.4 SP3 or later, and any user code that pattern-matches on the AG_CNTRL / AG_SEND / AG_RECV STATUS codes must be reviewed against the new CP firmware's STATUS map. Re-validate all S7 and ISO-on-TCP connections in NetPro.

Can I replace the CPU 6ES7416-2XK04-0AB0 with 6ES7416-2XN05-0AB0 at the same time as the CP replacement?

Yes. Use Replace Object on the CPU slot in HW Config; this preserves the CP slot configuration and the program. The CP-side work is independent of the CPU replacement. For F-CPU variants, re-validate the safety program signature after the HW Config change.

Back to blog