Resolving CPU 315-2 PN/DP Detection After MMC Swap

David Krause12 min read
S7-300SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

After swapping a 128 kB SIMATIC Micro Memory Card (MMC) for a 512 kB MMC in a CPU 315-2 PN/DP (typical order number 6ES7315-2EH14-0AB0), the engineering station running SIMATIC Manager (STEP 7 V5.x) can no longer discover the CPU on the PROFINET network. The previous project, online connection, and download all worked before the card change. The diagnostic state of the CPU (SF/BF/MAINT LEDs) appears normal, and the network cable, switch, and PG/PC interface assignment have all been verified. The problem persists across SIMATIC Manager restarts and even after the original 128 kB MMC is reinserted.

The failure mode is consistent and reproducible: the CPU is reachable only as a passive Ethernet node, not as a S7 target. This is a configuration-loss condition, not a hardware fault. The root cause lies in how the S7-300 CPU family persists its PROFINET interface parameters.

Critical: The S7-300 CPU 31x series cannot operate without an MMC. Unlike the S7-400, the MMC is not optional - it is the load memory. Removing or blanking the card puts the CPU into a "no project" state, which strips any previously assigned IP address, subnet mask, and router configuration from the PROFINET interface.

Root Cause Analysis

When a new (factory-blank) MMC is inserted, the CPU performs a cold initialization. The hardware PROFINET interface itself is still active at Layer 1 and Layer 2 - the link LED on the RJ45 port lights up and the CPU continues to send LLDP frames. However, the IP protocol stack only comes up after STEP 7 has assigned an IP address via the MAC-address discovery method. Until that assignment is made, the CPU has:

  • No IPv4 address on the PROFINET interface X2 (PN interface)
  • No S7 communication connection
  • No project, no symbol table, no S7 connections to download to

The MAC address is hardware-fused and printed on the front cover of the CPU. It survives MMC changes and power cycles. This is the anchor used to recover the device.

The 512 kB MMC itself is fully supported by the CPU 315-2 PN/DP - the device accepts MMCs in the 64 kB to 8 MB range (MMC 64K, 128K, 512K, 2M, 4M, 8M). The capacity is not the problem. The replacement card is functionally identical except for the fact that it contains no STEP 7 project.

Per the CPU 315-2 DP / CPU 317-2 DP device manual, the SIMATIC Micro Memory Card is mandatory load memory. The CPU 31xC and 31x series, including the 315-2 PN/DP, will not enter RUN and cannot retain any configuration when no MMC is present or when the MMC has never been written.

Symptoms Checklist

Confirm the following before proceeding with recovery:

Symptom Expected on failed CPU Check
Link LED on X2 (PN port) ON (green) Cable, switch port, patch lead
SF / BF LEDs OFF or briefly flashing at startup No bus fault expected
CPU STOP/RUN state STOP (no project loaded) Mode switch position
MAC address visible via ARP Yes - read from CPU front arp -a after ping broadcast
Accessible via S7 protocol No - until IP is assigned Accessible Nodes / Online > Accessible Nodes
PG/PC interface TCP/IP Configured to local NIC Control Panel > Set PG/PC Interface

Prerequisites

  1. STEP 7 V5.4 SP5 or later (V5.5 SPx recommended) installed on the engineering station.
  2. SIMATIC Manager with the project for the CPU 315-2 PN/DP available locally (or ready to be re-built).
  3. Physical access to the CPU's front panel to read the MAC address(es) - PROFINET MAC and, if used, PROFIBUS MAC.
  4. PG/PC Ethernet adapter on the same physical subnet (or a direct crossover/straight cable to the CPU's X2 port).
  5. Known target IP address, subnet mask, and (if used) router address for the PROFINET interface.
The original S7 project is the authoritative source for the IP address. If the project has been lost, the IP must be chosen from the same subnet as the engineering station, and a re-download of hardware configuration will be required.

Step-by-Step Recovery via Edit Ethernet Node

This is the canonical Siemens procedure for re-commissioning an S7-300 PN/DP CPU whose project (and therefore IP configuration) resides on a missing or blank MMC. It uses the MAC address as the lookup key and assigns a fresh IP address to the PROFINET interface without requiring a project download first.

  1. Read the MAC address. Power off the CPU, flip open the front cover. The PROFINET interface MAC is printed on a label inside the door, prefixed "Ethernet address" or "MAC:". Note all 12 hex characters.
  2. Verify the PG/PC interface assignment. Open Control Panel > Set PG/PC Interface. Select S7ONLINE (STEP 7) -> TCP/IP -> <your NIC>. The local NIC must be on the same subnet you plan to use for the CPU. Click OK.
  3. Launch SIMATIC Manager. Open (or create) any project. From the menu bar select PLC > Edit Ethernet Node. The Edit Ethernet Node dialog opens.
  4. Click "Browse". The dialog sends a DCP (Discovery and Configuration Protocol) identification request across the local subnet. After a few seconds, the reachable PROFINET devices appear in the list with their MAC addresses and current IP (if any).
  5. Select the CPU by MAC. Highlight the row matching the MAC address noted in step 1. If the CPU does not appear, confirm the patch cable, switch port VLAN, and that no firewall on the engineering station is blocking UDP port 34964 (PROFINET DCP).
  6. Click "OK" or "Assign IP". Enter the desired IPv4 address, subnet mask, and (optionally) router address. The dialog writes the values to the CPU's non-volatile memory area. The CPU stores the IP even when the MMC is blank.
  7. Confirm assignment. Re-browse the network - the CPU should now report the assigned IP next to its MAC address.
  8. Establish an online connection. In SIMATIC Manager select PLC > Accessible Nodes. The CPU should appear with its new IP as an S7 target.

Alternative Recovery via PROFIBUS DP

If the PROFINET interface is unreachable (e.g., a PROFINET stack fault) but the X1 PROFIBUS interface and its partner are healthy, the configuration can be reloaded through DP and then PROFINET re-enabled:

  1. Connect the engineering station to the CPU's X1 PROFIBUS port via a PROFIBUS cable and a CP 5611 / CP 5612 / CP 5711 / PC Adapter USB A2.
  2. Set the PG/PC interface to S7ONLINE (STEP 7) -> PROFIBUS.
  3. In SIMATIC Manager open the original project, right-click the CPU and select Download > Hardware and Software (only differences).
  4. STEP 7 will reach the CPU over DP, re-load the project (including the IP configuration for X2), and restart the CPU. The PROFINET stack comes up with the IP from the project.

This method is also useful as a permanent fallback for installations where PROFINET commissioning tools are not available on the service laptop.

PG/PC Interface Selection: ISO vs TCP/IP

For the PROFINET interface of an S7-300, only TCP/IP is supported. ISO Industrial Ethernet is a legacy transport used with the older CP 343-1 / CP 343-1 Lean modules and is not applicable to the integrated PN port of the CPU 315-2 PN/DP. If the Set PG/PC Interface dialog shows the assignment as ISO Ind. Ethernet, change it to TCP/IP for the correct network adapter. Mixing the two is a common cause of "CPU not found" even when the IP is correct.

Interface Type Use Case Applicable to X2 PN
TCP/IP <-> <NIC> Native PROFINET IO and S7 communication Yes
ISO Ind. Ethernet Legacy CP 343-1 / CP 443-1 No
PROFIBUS (DP) DP master / DP slave via X1 No (different port)

MMC Compatibility and Sizing

The CPU 315-2 PN/DP supports the SIMATIC Micro Memory Card in the following sizes. Using a larger card is fully supported; the CPU simply uses the additional space for retentive data, project history, or larger data blocks.

MMC Order Number Capacity Use Case
6ES7953-8LF11-0AA0 64 KB Small STEP 7 projects, no HMI
6ES7953-8LG11-0AA0 128 KB Typical S7-300 program (source of original card)
6ES7953-8LJ11-0AA0 512 KB Recommended for projects with HMI tags and recipes (target card)
6ES7953-8LL11-0AA0 2 MB Projects with many DBs or long trace buffers
6ES7953-8LM11-0AA0 4 MB Large STEP 7 projects, CPU 317 typically
6ES7953-8LP11-0AA0 8 MB Largest available for S7-300 family

Note that the MMC has a limited write endurance (typically 100,000 to 1,000,000 erase cycles per sector). Replacing a card periodically is acceptable; wearing out a card through constant recipe logging is not. Use the CPU's diagnostic buffer (CPU > CPU Diagnostics) to monitor for MMC-related diagnostic events.

Verification

After assigning the IP via Edit Ethernet Node, run the following checks:

  1. Accessible Nodes in SIMATIC Manager: the CPU appears with the assigned IP and is listed as an S7 device.
  2. Online > Online and Diagnostics: STEP 7 reports CPU type, firmware version, and operating mode. SF/BF LEDs should be off on the physical CPU.
  3. Download the project: right-click the CPU in the project tree and select Download to Target System. The STEP 7 project (blocks, hardware configuration, IP/subnet, PROFINET device assignments) is written to the new MMC. The MMC is now committed to this CPU; do not insert it in another CPU without first doing PLC > Copy RAM to ROM in reverse, or the IP will not match the new CPU's MAC.
  4. Cycle test: place the CPU in RUN, verify process I/O, and check the diagnostic buffer for any new entries.

Why the Old MMC Behavior Was Different

The original 128 kB MMC contained the STEP 7 project, including the IP configuration. On every restart, the CPU loaded the project from the MMC and applied the IP from the hardware configuration to its PN interface. As long as the IP was defined in the project, the CPU was reachable on PROFINET without any manual assignment.

Re-inserting the original 128 kB MMC should also restore the IP - assuming the project is intact and the IP was defined in the hardware configuration. If the original card was reinserted and the CPU is still not visible, the card itself may be defective (frequent cause: hot-swap of a powered CPU) or the project may not have included the IP parameter. Note that hot-swapping the MMC is not supported by Siemens; the CPU must be in STOP or power-off, and removing the MMC while the CPU is in RUN is a documented fault condition.

Preventive Measures

  • Always export the STEP 7 project to a versioned archive (Step7 V5.5: File > Archive) before touching the MMC.
  • Document the PROFINET device name, IP, subnet mask, and router for every CPU in the plant's network register.
  • Use a unique MMC per CPU. Marking the card with the CPU's serial number prevents accidental swap between machines.
  • Avoid MMC swap while the CPU is in RUN. Use the mode switch to STOP, swap, then return to RUN-P.
  • When provisioning a spare CPU, use PLC > Edit Ethernet Node to assign a unique IP and PROFINET device name before commissioning.

Diagnostic Buffer Reference

Useful entries to look for in the CPU's diagnostic buffer during this scenario:

Event ID Meaning Action
0x4501 STOP due to missing or defective MMC Insert or replace MMC, perform MRES
0x4541 MMC write error during download Replace MMC; check write protection slider
0x4301 MMC type incompatible with firmware Update firmware or use approved MMC order number
0x4947 PROFINET interface restart Informational; expected after MRES or download
0x4380 IP address conflict on PROFINET Reassign IP via Edit Ethernet Node

Troubleshooting Matrix

Symptom Likely Cause Resolution
CPU not in Accessible Nodes; link LED on No IP assigned after MMC swap Use PLC > Edit Ethernet Node
CPU not in Accessible Nodes; link LED off Cable/switch/VLAN issue Swap cable, check switch port, disable firewall
CPU visible but download fails PG/PC interface set to ISO not TCP/IP Change to TCP/IP <-> <NIC>
MAC not found in Browse dialog Different subnet or DCP blocked Use direct crossover cable, allow UDP 34964
IP assigned but S7 connection aborts IP conflict with another device Check ARP table, reassign unique IP
Original MMC restored, still not found MMC corruption from hot-swap Reformat MMC in CPU (MRES) and reload project
A crossover patch cable between the PG/PC and the CPU's X2 port is supported for point-to-point commissioning. Most modern NICs auto-negotiate MDI/MDIX, so a straight-through cable is also acceptable on PCs built after approximately 2005. The key requirement is that both devices share the same subnet, and that the PG/PC firewall is disabled or specifically allows STEP 7 ports (102 for ISO/TCP S7, 34964 for DCP).

FAQ

Why does my CPU 315-2 PN/DP disappear from the network after I install a new MMC?

The IP address, subnet mask, and PROFINET device name are stored in the STEP 7 project on the MMC. A blank MMC means the CPU has no IP configuration, so although the link LED stays on, the CPU is not reachable on TCP/IP. Reassign the IP via SIMATIC Manager: PLC > Edit Ethernet Node > Browse > select by MAC > assign IP.

Can I hot-swap the SIMATIC MMC while the CPU is in RUN?

No. Siemens documents that the MMC must only be inserted or removed when the CPU is de-energized or in STOP. Hot-swap can corrupt the card, trigger a STOP with diagnostic event 0x4501, and in some cases damage the MMC holder. Always bring the mode switch to STOP, power down if practical, and then swap the card.

Does the Edit Ethernet Node function require a STEP 7 project to be open?

No. The Edit Ethernet Node dialog is a standalone tool in SIMATIC Manager and writes directly to the CPU's non-volatile IP storage. You do not need a project, although you will need the project afterward to download the hardware configuration and user program to the new MMC.

Is a 512 kB MMC compatible with the CPU 315-2 PN/DP?

Yes. The CPU 315-2 PN/DP accepts all MMC sizes from 64 kB to 8 MB (order numbers 6ES7953-8Lxx1-0AA0). The 512 kB variant 6ES7953-8LJ11-0AA0 is well within the supported range. The size of the card has no effect on PROFINET commissioning.

The MAC address does not appear in the Browse dialog. What should I check?

Verify that the PG/PC Ethernet adapter is on the same subnet as the CPU, that the patch cable is functional, and that no Windows firewall or network security policy is blocking UDP port 34964 (PROFINET DCP). A direct point-to-point cable to the CPU's X2 port, with the PC set to a static address in the 192.168.0.x range, is the most reliable test.

Back to blog