Resolving CP 443-1 EX11 Fatal Configuration Error in STEP 7 V5.x

David Krause13 min read
S7-400SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving CP 443-1 EX11 Fatal Configuration Error in STEP 7 V5.x

Overview

The Siemens CP 443-1 (catalog number 6GK7 443-1EX30-0XE0, variant EX11) is the industrial Ethernet communications processor for the SIMATIC S7-400 / PCS 7 AS 400 stations. When the module is inserted into the S7-400 rack and the project is downloaded from STEP 7 HW Config, two related symptoms can occur that stop the CP from entering RUN:

  1. The CP does not appear in the HW Config catalog under SIMATIC 400 > CP-400 > Industrial Ethernet, so the engineer cannot place the module.
  2. After the module is placed and the project is downloaded, the CP reports a "Fatal Configuration Error" or "Critical Configuration Fault" on the diagnostic display and on the module's SF/EXTF LEDs, and the CP leaves RUN mode.

Both symptoms have the same underlying cause: a mismatch between the firmware version flashed on the CP 443-1 EX11, the GSD/HSP entry inside HW Config, and the version of the NCM S7 configuration database installed in the engineering station. This reference walks through the failure modes, the firmware/HSP compatibility matrix, and the field-proven recovery sequence for STEP 7 V5.2, V5.3 (SP1, SP2, SP3) and PCS 7 V6.0.

Affected Components and Versions

Component Identifier Versions Observed in the Field
CP 443-1 module variant 6GK7 443-1EX30-0XE0 (EX11) Firmware V2.0, V2.3, V2.4, V2.5, V2.6.7
STEP 7 (without PCS 7) STEP 7 V5.2 / V5.3 V5.2 SP1 HF1, V5.3 SP1
STEP 7 inside PCS 7 PCS 7 V6.0 Bundled STEP 7 V5.3 SP1 + HF1
NCM S7 for Industrial Ethernet Optional add-on Last known update: V5.2 SP1 HF1 (do NOT install standalone)
CP firmware package Siemens Entry ID 21835974 FW V2.6.7 for EX11
CP firmware V2.4 release notes Siemens Entry ID 17504794 Error corrections only, no new function
Critical: The standalone NCM S7 update (last release V5.2 SP1 HF1) is not compatible with PCS 7 V6.0. Installing it on top of PCS 7 corrupts the integrated NCM database. Always update the CP firmware and HW Config catalog through the Siemens support portal, not by patching NCM S7 separately on a PCS 7 workstation.

Problem 1: CP 443-1 EX11 Is Missing from the HW Config Catalog

Symptom Description

When the engineer opens HW Config and expands SIMATIC 400 > CP-400 > Industrial Ethernet, the EX11 order number 6GK7 443-1EX30-0XE0 is not listed, even though the physical module in the rack is an EX11. Older EX10 modules may be present, but the EX11 selection either does not exist or appears with an older firmware revision (typically V2.0) that does not match the physical module's actual FW.

Root Cause

The HW Config catalog is fed by an internal HSP (Hardware Support Package) database. Each release of STEP 7 / PCS 7 ships with a frozen snapshot of CP entries. STEP 7 V5.2 was released before the EX11 was added; STEP 7 V5.3 SP1 and PCS 7 V6.0 (which bundles STEP 7 V5.3 SP1) include EX11 entries that may be older than the firmware actually on the module. When the project is downloaded, the CP compares the configuration block it receives against its own firmware; a non-matching revision triggers the configuration error described in Problem 2.

Diagnostic Check

  1. Read the order number printed on the module's front panel (top-left).
  2. Open the module's Online > Module Information in HW Config to read the actual firmware version reported by the CP.
  3. Cross-check the catalog entry placed in the rack slot: right-click the CP > Object Properties > Order Number / Firmware.

If the catalog version is below the actual firmware, HW Config will still allow the download, but the CP will reject the resulting configuration block.

Problem 2: "Fatal Configuration Error" / "Critical Configuration Fault" After Download

Symptom Description

After a successful project download, the CP 443-1 EX11 refuses to enter RUN. The diagnostic display cycles through the message FATAL CONFIGURATION ERROR or, on newer firmware builds, CRITICAL CONFIGURATION FAULT. The SF LED is lit steady, the EXTF LED may blink, and the module is shown as "not available" or "faulted" in the online view of the AS.

Root Cause

The CP stores a fixed-format configuration block describing the Ethernet interface, the ISO/TCP connections, the MAC/IP parameters, and the S7 connection routes. If the FW on the CP does not recognise the structure produced by the engineering tool (for example, a field, an option bit, or a connection parameter that the FW build predates), it flags the block as fatally corrupt and stays in STOP. The user-visible triggers are:

  • Placing the CP with a catalog entry that is older than the FW flashed on the module (e.g., placing a V2.0 entry against a V2.4 module).
  • Placing the CP with a catalog entry that is newer than the FW (e.g., placing a V2.5 entry against a V2.4 module after a failed FW flash).
  • An interrupted or partial FW update that leaves the CP in a mixed V2.x state. This is the classic source of FATAL CONFIGURATION ERROR when the engineer can read the module's FW as V2.4 from the display but HW Config still sees V2.3 / V2.5.
Important: CP firmware V2.4 contains error corrections only. The official release notes (Siemens Entry ID 17504794) state that V2.4 introduces no new functional fields, which means a V2.3 HW Config entry is fully compatible with a V2.4 module. Do not force a V2.5 or V2.6 entry onto a V2.4 module: the CP will interpret it as a future-looking configuration and reject it.

Recovery Procedure

The recovery has three ordered steps. Always run them in this sequence; re-flashing FW before updating the catalog typically makes the symptom worse.

Step 1 — Install the Latest HW Updates for STEP 7 / PCS 7

  1. Open SIMATIC Manager and open the project.
  2. Open HW Config for the affected AS 400 station.
  3. From the menu, choose Options > Install HW Updates ...
  4. Accept the default path to the Siemens Internet HSP server. STEP 7 will download and merge all available CP 443-1 HSPs, including EX10 and EX11 revisions, into the local catalog.
  5. Close and re-open HW Config. The CP 443-1 EX11 entry should now be present, with the highest available FW revision selectable.

If the engineering station has no Internet access, the HSP can be downloaded as a self-extracting .exe from the Siemens support portal under entry ID 21835974 and installed offline. The same package contains both the FW files and the matching HSP.

Step 2 — Flash the CP 443-1 EX11 Firmware to V2.6.7

  1. Open SIMATIC Manager > Options > Set PG/PC Interface and select the TCP/IP (Auto) or ISO Ind. Ethernet access point, depending on the existing AS network.
  2. From HW Config, right-click the CP 443-1 in the rack and choose PLC > Update Firmware. STEP 7 will offer the FW files in the package downloaded in Step 1.
  3. Select V2.6.7 for the EX11. Do not downgrade to V2.3 / V2.4 unless Siemens support explicitly requests it.
  4. Confirm the update. The CP performs two automatic reboots: first to erase the FW partition, then to write and verify the new image. Do not power off the AS during this window — a bricked FW image is recoverable only through Siemens repair.
  5. After the second reboot, verify with Online > Module Information > Firmware that the module reports V2.6.7.
Warning: On a V2.0 module, the update to V2.6.7 is a one-way upgrade. V2.6.7 cannot be downgraded back below V2.4. Make sure the spare-parts inventory and the documentation reflect this before performing the flash on production hardware.

Step 3 — Re-place the CP in the Rack with the Matching Catalog Entry

  1. Delete the existing CP 443-1 from the rack slot.
  2. Drag the new EX11 entry from SIMATIC 400 > CP-400 > Industrial Ethernet into the slot. The order number should read 6GK7 443-1EX30-0XE0 and the FW should read V2.6.7.
  3. Re-enter the Ethernet parameters (IP address, subnet mask, MAC if manually set), the ISO transport connections, the S7 connections, and any TCP connections previously configured.
  4. Compile and save the HW Config. The consistency check must report zero errors.
  5. Download the HW Config to the AS. The CP should now enter RUN within 5-10 seconds and the SF / EXTF LEDs should extinguish.

Compatibility Matrix: FW x Catalog Entry

CP Firmware (actual) Catalog FW to use in HW Config Expected result
V2.0 V2.0 (legacy HSP, STEP 7 V5.1 SP3 / V5.2) Runs
V2.3 V2.3 Runs
V2.4 V2.3 or V2.4 (functionally identical for configuration) Runs
V2.5 V2.5 Runs only if HSP for V2.5 is installed
V2.6.7 V2.6.7 Runs; recommended baseline
V2.6.7 (after failed flash) V2.5 or V2.6.7 Fatal Configuration Error — repeat Step 2 and 3

Edge Case: PCS 7 V6.0 Bundles STEP 7 V5.3 SP1 + HF1

On a PCS 7 V6.0 engineering station, the bundled STEP 7 is V5.3 SP1 with Hotfix 1. A standalone NCM S7 update downloaded from the Internet will refuse to install with a message of the form "Main S7 software CD must be installed first". This is by design — Siemens does not allow mixing the bundled PCS 7 NCM database with a separately updated NCM S7 from the regular STEP 7 stream. The supported path is:

  1. Install the HSP via Options > Install HW Updates while running inside PCS 7 (this does not touch NCM S7).
  2. Use SIMATIC Manager > Options > Firmware Update on the CP directly; this uses the FW files delivered with the HSP, not NCM S7.
  3. If the CP still misbehaves, upgrade the entire PCS 7 package rather than patching components individually.

Edge Case: Archived Project Shows Different Firmware

A common confusion is that an archived project retrieved from a different engineering station shows the EX11 entry at FW V2.0 even though the physical module and the live project are at V2.4. This is because the archive was built with an older HSP that froze the V2.0 entry as the EX11 baseline. Re-opening the project on a station with updated HSPs will refresh the entry, but until the project is re-saved and re-downloaded, the CP on the rack will receive the V2.0-shaped configuration block. The fix is to:

  1. Open the archived project on an engineering station with current HSPs.
  2. Re-place the CP 443-1 in HW Config (drag, drop, confirm dialog) so the entry picks up the latest FW.
  3. Save, compile, download.

Diagnostic Tools and LED Patterns

LED State Meaning Action
SF (red) Steady on Group fault; configuration rejected Check FW vs. catalog entry; re-do Step 2 and 3
EXTF (red) Steady on External fault (link down, duplicate IP) Verify physical Ethernet; check ARP for duplicate IP
RUN (green) Flashing 2 Hz CP starting / self-test Wait 10 s; if persistent, power cycle AS
RUN (green) Steady on CP in RUN, configuration accepted None — normal operation
STOP (yellow) Steady on CP in STOP after fatal config error Follow recovery procedure in this article
Diagnostic display FATAL CONFIGURATION ERROR Config block rejected Match FW and HSP; reflash if needed
Diagnostic display CRITICAL CONFIGURATION FAULT Same root cause, newer FW wording Same as above

When the Recovery Fails

If the CP still reports FATAL CONFIGURATION ERROR after a clean V2.6.7 flash and a re-placed, re-compiled HW Config:

  1. Open Online > Accessible Nodes and read the CP's diagnostic buffer via PLC > Module Information > Diagnostic Buffer. The first entry usually identifies the offending configuration field (e.g., a malformed S7 connection with conflicting slot references).
  2. Check the S7 connection table: every connection's local partner must reference a slot that exists in the current HW Config. After a rack re-design, leftover connections from a deleted CP can trigger the fault.
  3. Power-cycle the entire AS 400 station, not just the CP. The S7-400 backplane resets configuration pointers only on full power-down.
  4. If the diagnostic buffer is empty or unreadable, open a support ticket with Siemens SIMATIC NET at [email protected], attaching the STEP 7 project archive and the diagnostic buffer dump.

Best-Practice Baseline Configuration

For new installations on STEP 7 V5.3 SP2 or later, or on PCS 7 V7.0+:

  • CP 443-1 EX11 firmware: V2.6.7 (latest available, from Siemens Entry ID 21835974).
  • HW Config entry: V2.6.7 (match the FW exactly).
  • STEP 7 minimum version: V5.3 SP2 for plain S7-400 projects; PCS 7 V7.0+ for PCS 7 projects.
  • Avoid the standalone NCM S7 V5.2 SP1 HF1 update on any machine that hosts PCS 7 — it has been pulled from the public support site for that reason.
  • Document the FW version on the front panel of the AS cabinet door. This avoids the "archived project says V2.0" confusion during commissioning.

Verification Checklist

After the recovery procedure, confirm the following before signing off the work order:

  1. Online > Module Information > Firmware reports V2.6.7 on the CP 443-1.
  2. SF LED is off; RUN LED is steady green; STOP LED is off.
  3. Diagnostic display reads the slot number (e.g., 4) instead of an error string.
  4. From a separate engineering station, Online > Accessible Nodes lists the CP at its configured IP address.
  5. An existing S7 connection (e.g., to a WinCC station or a partner CPU) reports Established in the connection diagnostics.
  6. The diagnostic buffer contains no entries dated later than the FW update event.

Related References

  • Siemens Entry ID 21835974 — CP 443-1 EX11 firmware update package (V2.6.7).
  • Siemens Entry ID 17504794 — CP 443-1 firmware V2.4 release notes (error corrections only).
  • SIMATIC NET S7-400 Industrial Ethernet CP manual on the Siemens Industry Online Support portal.

Why does my CP 443-1 EX11 not appear in the HW Config catalog after installing STEP 7 V5.3?

The EX11 was added to the HW Config catalog after the initial release of STEP 7 V5.3. Open HW Config, choose Options > Install HW Updates, and let STEP 7 download the latest HSPs from the Siemens Internet server. After re-opening HW Config, the EX11 entry (6GK7 443-1EX30-0XE0) will be available under SIMATIC 400 > CP-400 > Industrial Ethernet.

What does "Fatal Configuration Error" on the CP 443-1 mean?

The configuration block the CP received from HW Config does not match what its current firmware can interpret. This usually happens when the catalog entry placed in the rack has a firmware revision that differs from the one flashed on the module. Match the FW on the CP (read via Online > Module Information > Firmware) with the FW selected in the catalog entry, then re-download HW Config.

Can I use the V2.3 HW Config entry on a V2.4 module?

Yes. Siemens Entry ID 17504794 states that firmware V2.4 contains error corrections only and no new functional fields. A V2.3 catalog entry produces a configuration block that a V2.4 module accepts without complaint. Do not, however, use a V2.5 or V2.6 entry on a V2.4 module, as the module will reject the future-looking fields.

Is the standalone NCM S7 V5.2 SP1 HF1 update safe to install on PCS 7 V6.0?

No. The V5.2 SP1 HF1 NCM S7 update is intended for plain STEP 7 V5.2 installations. On a PCS 7 V6.0 workstation, which bundles STEP 7 V5.3 SP1 with its own NCM database, installing the standalone update corrupts the integrated NCM. Use Options > Install HW Updates inside the PCS 7 SIMATIC Manager instead, and update the entire PCS 7 package if a feature requires a newer NCM revision.

What is the latest firmware for the CP 443-1 EX11 and where do I get it?

The latest firmware available for the EX11 (6GK7 443-1EX30-0XE0) is V2.6.7. It is distributed as part of the Siemens support package referenced by Entry ID 21835974, which contains both the firmware image and the matching HSP for HW Config. The same package supports the offline installation path on stations without Internet access.

Back to blog