1. Problem Overview
When a WinCC SCADA runtime on a PC equipped with a SIMATIC CP5611 communications processor suddenly stops displaying live process values from one or more SIMATIC S7-300 (CPU 313) stations on a Profibus DP network, every I/O field, output, and trend tag in the WinCC graphics is replaced by six hash characters (#######). The substitution indicates that the runtime database has lost the channel connection to the AS (automation system) and therefore cannot return a valid value for the configured tag — the WinCC Variable Manager has either timed out the connection or has not received a single successful read response after the configured update/poll interval.
The symptom is identical whether the cause is a wrong bus speed, a missing or doubled termination resistor, a defective bus cable, an unplugged connector, a configuration mismatch between STEP 7 and WinCC, or a hung DP master. Because the display itself is non-specific, the engineer must follow a structured diagnostic path. This reference documents a real field case in which three CPU 313 stations are arranged in a Profibus DP network together with three HMI panels, supervised by one PC running WinCC via CP5611, and produces the ####### symptom on all tags. The root cause was a frozen DP master, and the recovery action was a hard power-cycle of the master PLC for 30 minutes. The full diagnostic chain that leads to that conclusion is reproduced below so that the same approach can be applied to any S7-300 + CP5611 + WinCC installation showing the same behavior.
The engineering task is fundamentally one of layer isolation: physical layer (cable, connector, termination), data link layer (bus address, baud rate, master arbitration), application layer (WinCC channel, STEP 7 project integration), and AS state (CPU run/stop/fault). Each layer must be verified in turn before changing anything else.
2. Network Topology and Components
The reference installation consists of the following nodes, all on a single Profibus DP segment:
| Node | Type | Profibus Address | Role |
|---|---|---|---|
| S7-300 CPU 313 (master) | DP master class 1 | 2 | Owns the DP cycle, exchanges data with slaves and with CP5611 |
| S7-300 CPU 313 (slave #1) | DP slave | 3 | Provides process data to master |
| S7-300 CPU 313 (slave #2) | DP slave | 4 | Provides process data to master |
| PC + CP5611 (WinCC station) | DP master class 2 (active) | 0 or 1 (per PG/PC settings) | WinCC runtime, online diagnostics |
| Three HMI panels (e.g. OP/TP/Comfort) | DP slaves | 5, 6, 7 | Local HMI on each station |
All nodes are wired in a linear bus topology with Profibus cable (typically 6XV1 830-0EH10 violet, characteristic impedance 150 Ω). Bus segments are joined through 6ES7 972-0BB12-0XA0-style 90° bus connectors or the older 6ES7 972-0BA12-0XA0 axial connectors. The DP couplers mentioned in the source are repeater/branch nodes (e.g. 6GK1 500-0AB00 or 6ES7 972-0AA01-0XA0) used to extend the segment or to decouple galvanically isolated sub-segments.
Inline SVG — physical bus layout with termination:
3. Root Cause Analysis
Six families of defect produce the ####### symptom in WinCC on a Profibus DP network. They are listed below in descending order of frequency observed on S7-300 + CP5611 installations.
| # | Layer | Fault | Distinguishing evidence |
|---|---|---|---|
| 1 | Physical | Termination ON in the middle of the segment (doubles the bus impedance → signal collapse) | Bus activity LED on CP5611 red, BF (bus fault) LED on master |
| 2 | Physical | Termination OFF at one or both physical ends | Intermittent #######, frequent rediagnostic cycles |
| 3 | Physical | Damaged cable, broken shield, kinked segment, missing 150 Ω impedance match | Bus faults appear only with vibration or movement |
| 4 | Data link | Different baud rate between WinCC/CP5611 and the rest of the bus (e.g. 1.5 Mbps vs 187.5 kbps) | STEP 7 "Online → Accessible Nodes" returns 33:17075 and the same address is listed as "not reachable" |
| 5 | Data link | Duplicate Profibus address on two nodes (incl. duplicate between CP5611 and an HMI) | Diagnostic buffer of master lists "Station failure" repeating with same address |
| 6 | AS / Master | DP master CPU is in STOP, fault, or hung in RUN with no DP cycle (defective firmware, watchdog, OB122 storm) | Master SF/BF on, but slave station diagnostics are missing; CP5611 cannot obtain a live list |
The decisive clue in the reference case is error 33:17075 appearing in SIMATIC Manager's Accessible Nodes view. This is a SIMATIC S7 diagnostic code returned by the CP5611 firmware when the host requests an active node list and the master either does not respond to token-passing frames within the configured time-out, or the segment is electrically silent at the configured baud rate. The error alone is not specific — but combined with the fact that the installation had been running for ten days, that the cabling had not been touched, and that the master PLC's behavior was the only changed element after a power event, the diagnosis narrows to the master layer rather than the cable.
4. Error Code 33:17075 Diagnostic
Error 33:17075 is reported by SIMATIC Manager / STEP 7 when the S7DOS / S7DBE connection layer cannot establish a Profibus connection to the target address requested by the operator. The number is structured as error class : error code:
- Class 33 — connection layer internal status (often "no resource / timeout").
- Code 17075 — operation did not complete within the configured time-out. On CP5611 Profibus this typically maps to a token-passing failure or a bus-silent segment at the configured baud rate.
The error is not an SFC/SFB user program error (those carry codes in the 8xxx / Fxxx range in the diagnostic buffer). It is a CP5611 driver-level status, surfaced by SIMATIC Manager when it polls "Accessible Nodes" and no token is observed at the configured baud rate within the time-out window.
Recommended diagnostic sequence when 33:17075 appears:
- Open Start → SIMATIC → STEP 7 → Set PG/PC Interface.
- Select the
S7ONLINE (CP5611.PROFIBUS.1)access point, not the MPI variant. - Open Properties → PROFIBUS and note the configured transmission rate.
- Compare the configured rate with the rate set in the STEP 7 HW Config of the master PLC. They must match exactly.
- From the STEP 7 project, run PLC → Accessible Nodes. The reachable nodes list is built from token-passing replies, so a complete empty list with 33:17075 indicates that the master is silent or the segment is electrically broken.
- If the list is empty but the master CPU is in RUN (mode switch in RUN, SF/BF LEDs behave as expected), observe the master's diagnostic buffer (PLC → Diagnostic/Setting → Diagnostic Buffer) for station-failure entries.
5. Profibus DP Termination Configuration
Profibus DP is a 2-wire RS-485 segment running at half-duplex. The cable has a characteristic impedance of 150 Ω. To prevent signal reflection at the ends, each physical end of every segment must be terminated with 220 Ω pull-up and 390 Ω pull-down resistors that synthesize the 150 Ω match and bias the line to a defined idle voltage. The termination is implemented inside every Profibus bus connector by a 4-position DIP switch (often labeled SW1).
| DIP position | Meaning | When to set |
|---|---|---|
| ON (1) | Termination active | Only at the two physical ends of a segment |
| OFF (0) | Termination inactive | At every intermediate node |
The connector itself has two Profibus ports: IN (cable coming from previous node) and OUT (cable going to next node). The termination switch only biases the IN segment. The standard 6ES7 972-0BA12-0XA0 connector ships with a switch that has four positions: OFF OFF OFF ON means "terminated". A common field mistake is to interpret the same switch as "ON" because of the printed silkscreen — always follow the silkscreen of the specific part number.
Inline SVG — bus connector DIP switch detail:
####### within seconds. Doubled termination lowers the bus impedance from 150 Ω to about 75 Ω and biases the line aggressively, destroying the differential waveform.6. CP5611 Interface Configuration in PG/PC
The CP5611 (order number 6GK1 561-1AA01) is a PCI-card Profibus/MPI interface for PCs. It is recognised by Windows as a Siemens communications processor and is configured through the Set PG/PC Interface control-panel applet that ships with STEP 7 / SIMATIC NET. The configured access point is read by both STEP 7 and WinCC.
Two key parameters must be correct:
-
Access point — select
S7ONLINE (CP5611.PROFIBUS.1)for STEP 7 diagnostics and for WinCC when the channel is "SIMATIC S7 Protocol Suite → PROFIBUS". Do not use the(Auto)alias unless every device in the project has been verified to share the same parameters. - Transmission rate — set the same baud rate as the master PLC's Profibus subnet. Typical values for a CPU 313 Profibus DP network are 1.5 Mbps, 500 kbps, 187.5 kbps, 45.45 kbps, 19.2 kbps, 9.6 kbps. Field experience with mixed cable lengths and CP5611 cards consistently shows that 1.5 Mbps requires high-quality cable, short distances, and good termination; if a single node is reporting errors, dropping to 187.5 kbps or 500 kbps dramatically improves robustness at the cost of bus cycle time.
| Baud rate | Max segment length (Type A cable) | Typical cycle headroom | Recommended use |
|---|---|---|---|
| 9.6 kbps | 1200 m | Very high | Long cable, very slow I/O |
| 19.2 kbps | 1200 m | Very high | Diagnostic only |
| 45.45 kbps | 1200 m | High | Legacy systems |
| 93.75 kbps | 1200 m | High | HMI-heavy systems |
| 187.5 kbps | 1000 m | Good | Default for HMI + WinCC mixed networks |
| 500 kbps | 400 m | Good | Higher speed, controlled environment |
| 1.5 Mbps | 200 m | Low | Short cable, premium quality, otherwise unstable |
| 3 / 6 / 12 Mbps | ≤ 100 m | Marginal | Requires Profibus DP cable spec v1.0+ and repeater |
#######, fixing the baud rate explicitly is the more diagnostic-friendly choice.Property screenshot of the CP5611 in Set PG/PC Interface (text representation):
S7ONLINE → CP5611.PROFIBUS.1 → [Properties]
Transmission Rate : 187.5 kbps (or 1.5 Mbps to match master)
Highest Station Address : 126
Profile : Standard
Bus Timing : Default
PG/PC is the only master on the bus : OFF
7. WinCC Connection Configuration
WinCC reads from the S7-300 stations through the SIMATIC S7 Protocol Suite channel. The channel unit PROFIBUS (not MPI, not TCP/IP) is the unit that talks to a Profibus master such as CP5611. Each WinCC connection is bound to:
- The Profibus address of the target S7 CPU.
- The application slot in STEP 7 — by default S7 connection uses slot 2 of the S7-300 CPU (rack 0, slot 2 for CPU 313).
- The rack and slot of the CPU on the STEP 7 project — these must match the physical placement of the CPU module on the rail.
- The communication partner (CP5611) configured in WinCC Explorer under Tag Management → SIMATIC S7 Protocol Suite → PROFIBUS → Connection Properties.
Inline SVG — WinCC tag manager path to the Profibus connection:
When a WinCC I/O field is grayed out or shows #######, the runtime is not consulting the field's configured format or value table — it is signalling that the underlying tag's last read returned a quality code of "Bad / No Communication". The fix is therefore not in the graphics designer but in the connection layer and the physical layer.
8. STEP 7 Project Configuration
All Profibus partners should be in a single STEP 7 project. The advantages are:
- STEP 7 verifies that no Profibus address is assigned twice in the project.
- STEP 7 verifies that the bus profile (baud rate, Tslot, max Tsdr, quiet time, Tset, Tqui) is the same on every node.
- STEP 7 generates a consistent GSD-based master configuration that is downloaded to the DP master.
- When a new station is added, STEP 7 automatically assigns the next free address from the project pool.
If the partners are not in a single project, the engineer must manually check the following on every node:
| Parameter | Where set on CPU 313 | Where set on CP5611 |
|---|---|---|
| Profibus address | HW Config → CPU → Properties → PROFIBUS interface | Set PG/PC Interface → CP5611 Properties → Address |
| Transmission rate | HW Config → Subnet → Properties → Network Settings | Set PG/PC Interface → CP5611 Properties → Transmission Rate |
| Highest station address (HSA) | HW Config → Subnet → Properties | Set PG/PC Interface → CP5611 Properties → HSA |
| Profile | HW Config → Subnet → Properties | Set PG/PC Interface → CP5611 Properties → Profile |
####### symptom implies that no valid response is being received, not a slow cycle.9. Step-by-Step Resolution Procedure
The following ordered procedure is the fastest path from "all WinCC tags show #######" to a healthy running system. It is written to be carried out in a single maintenance window, with the WinCC runtime stopped before any physical changes are made.
- Stop the WinCC runtime. Open WinCC Explorer on the SCADA PC, run Stop Runtime in the Computer properties, and wait for the red dot in the title bar to disappear. This prevents the Variable Manager from spamming connection-failure entries during diagnostics.
- Verify CP5611 is healthy in Windows. Open Device Manager. The CP5611 must be listed under SIMATIC NET or Siemens Communications with no yellow or red warning glyph. If the device is marked with a code 10 / 28, reinstall the SIMATIC NET driver package that matches the STEP 7 / WinCC version.
-
Verify the Set PG/PC Interface assignment.
Set the access point
S7ONLINEtoCP5611.PROFIBUS.1. Open Properties and confirm:- Address unique on the bus and not shared with an HMI or the master.
- Transmission rate identical to the master CPU's HW Config value (e.g. 1.5 Mbps, 500 kbps, 187.5 kbps).
- Highest station address ≥ max address actually used.
- Profile "Standard" or "User-defined" consistent with the rest of the bus.
-
Run STEP 7 → Accessible Nodes.
If the reachable list is empty and you get
33:17075, do not assume a dead PC. Move to step 5. - Verify Profibus termination on every connector. Physically walk the bus from one end to the other. The two physical end connectors must have their termination switch in the ON (terminated) position. Every connector in between must be OFF. A common audit uses a multimeter on the bus core: with the segment powered, the resistance measured between pins 3 and 8 at any point should be approximately 110 Ω (220 Ω // 390 Ω // 220 Ω // 390 Ω combined through the powered bus, with both ends terminated). An open circuit indicates both ends are off; a reading below 70 Ω indicates a doubled or triple termination.
- Verify the cable. Check for kinks, crushed sections, or cuts at the strain-relief glands. Re-seat every connector and torque the screws to 0.4 N·m. If you have a Profibus cable tester (e.g. Softing BC-700-PB, Indu-Sol PROFINET-INspektor PB, or any device that measures cable impedance and reflection), run a single-segment test from one end. A healthy segment reports no significant reflection at the configured baud rate.
- Verify the DP master CPU is alive. Look at the master PLC. The mode switch should be in RUN. The SF LED should be off, the BF LED should be off, and the DC5V LED should be on. The RUN LED should be steady green (not flashing). If the SF/BF LEDs indicate a bus fault, the master is trying to poll a slave that does not reply — go back to step 5.
- Power-cycle the DP master CPU. If the master CPU appears alive but the bus is silent, the master may be hung in a state where it does not transmit token frames. Place the mode switch in STOP, then power the entire S7-300 rack off (CPU, PS, IM, all SMs). Wait 30 minutes for internal capacitors in the CPU firmware to bleed down. Reapply power, place the switch in RUN, and observe the BF LED. If the BF LED is off and the SF LED is off, the master is now generating token frames and the bus cycle has resumed.
- Re-run Accessible Nodes from STEP 7. Confirm that the master, the slaves, the HMIs, and the CP5611 are now visible. If you can read the master CPU online, the Profibus layer is healthy.
-
Restart the WinCC runtime.
Start the project, open the process screens, and confirm that the I/O fields display live values. Look at the tag diagnostics in WinCC Explorer → Tools → Tag Diagnosis; the connection quality should be "Good". If a single tag still shows
#######, the problem is a wrong address or wrong data type in that tag's configuration, not in the connection. - Document the change. Record the CP5611 parameters, the master CPU firmware version, the STEP 7 version, the WinCC version, and the bus baud rate. Save a backup of the STEP 7 project and the WinCC project after the fix.
10. Verification and Acceptance Test
After the recovery action, run the following acceptance checks before returning the system to production:
| Check | Expected result | Tool |
|---|---|---|
| Master RUN LED | Steady green | Visual |
| Master BF LED | Off | Visual |
| Master SF LED | Off | Visual |
| CP5611 status in Device Manager | Healthy, no warning glyph | Windows Device Manager |
| Accessible Nodes from STEP 7 | All expected nodes listed with correct addresses | STEP 7 → PLC → Accessible Nodes |
| WinCC process screens | Live values, no ####### on any I/O field |
WinCC runtime |
| Tag quality in WinCC Tag Diagnosis | Good for every connection | WinCC Tag Diagnosis |
| Bus diagnostic buffer of master | No station failure, no bus error entries | STEP 7 → PLC → Diagnostic Buffer |
| Master DP slave list | All configured slaves reported as "OK" | STEP 7 → HW Config → DP master diagnostics |
A practical stress test is to read the same tag from two different SCADA clients connected to the same CP5611 (or from the STEP 7 force table) and confirm that the value updates at the expected update time. A secondary stress test is to trigger an emergency stop (or a deliberate stop of one of the slaves) and confirm that the diagnostic buffer of the master records the expected "Station failure" event and that WinCC reports the corresponding tag as ####### only for that slave's tags while the rest of the system continues to update — this proves that the failure isolation is per-station rather than per-system.
11. Preventive Maintenance and Field Lessons
The following practices are field-proven to reduce the probability of a repeat of the ####### symptom.
- Single bus speed for the whole segment. The reference case is a network that has been running for ten days at 1.5 Mbps. If 1.5 Mbps is not strictly required (cycle time, I/O count), drop the entire network to 500 kbps or 187.5 kbps. Lower speeds are dramatically more tolerant of cable quality, connector quality, and EMI.
- Lock the CP5611 profile. Use a fixed profile ("Standard" or "User-defined") in Set PG/PC Interface rather than Auto. Field experience with mixed HMIs and CP5611 cards shows that Auto occasionally fails to find a healthy bus after a CP5611 cold start and forces the operator to switch the profile manually.
- Use only the official Profibus violet cable (6XV1 830-0EH10 or 6XV1 830-3EH10). Generic RS-485 cable has a 120 Ω impedance, not 150 Ω, and creates the same reflection pattern as a missing termination.
- Mark the two physical end connectors. A red dot sticker on each end connector is the cheapest possible termination audit. It eliminates the most common field mistake: an electrician who extends the bus by adding a new station in the middle and accidentally activates the new middle connector's termination switch.
-
Configure OB82, OB86, OB122 in the master CPU. Diagnostic OBs catch a missing slave or a defective bus without taking the master into STOP. Without OB86, the master will fall into STOP as soon as a slave drops out, and the entire SCADA layer will show
#######for what is in reality a single missing slave. - Keep the master CPU firmware current within the same major version. Older CPU 313 firmware has known DP-cycle lockup issues when the bus experiences short bursts of errors. The recovery is always a power-cycle, but upgrading the firmware (e.g. from V2.x to V3.x within the same hardware) reduces the frequency of the lockup.
- Use a UPS on the master PLC. Brownouts and fast power restorations are a common cause of the master entering a state where the BF LED is off but the master is not generating a token. A UPS that provides clean ramp-down and ramp-up prevents the lockup in the first place.
12. Related Siemens Documentation
For a deeper understanding of the items above, the official Siemens references that match the CPU 313 / CP5611 / Profibus DP subject are:
- SIMATIC S7-300 CPU 31xC and CPU 31x — Installation and Operating Instructions
- SIMATIC NET CP 5611 — Manual
- PROFIBUS Network Configuration — Wiring and Assembly
- SIMATIC S7-300 DP Master / DP Slave — Configuring and Commissioning
- SIMATIC WinCC V7 — Communication Manual (S7 Protocol Suite)
- SIMATIC WinCC — Diagnostics of Channel Connections
- PROFIBUS Installation Guideline (PI)
Frequently Asked Questions
What does the ####### symbol in a WinCC I/O field actually mean?
It means the WinCC runtime could not obtain a valid value for the tag within the configured update/poll cycle. The runtime substitutes ####### whenever the underlying channel returns a quality code of "Bad / No Communication" — the value displayed by the field is intentionally overwritten to draw the operator's attention to the loss of comms. The fix is in the connection, not in the field's formatting.
Is error 33:17075 the same on every STEP 7 / CP5611 version?
The numeric code 33:17075 has been reported on STEP 7 V5.4, V5.5, and V5.6 with CP5611 firmware 5.x and 6.x. The meaning is consistent: the host's connection request to the CP5611 did not complete within the configured time-out, almost always because the bus is silent or the master is hung. Always cross-check with the master CPU's diagnostic buffer and the CP5611 status in Set PG/PC Interface.
Should the Profibus termination switch be ON at every node or only at the ends?
Only at the two physical ends of each Profibus DP segment. The Profibus bus connector integrates a 220 Ω / 390 Ω network that synthesises the 150 Ω line impedance and biases the bus to a defined idle state. The resistor network is activated by a 4-position DIP switch. Setting the switch to ON at any middle node halves the bus impedance and corrupts the signal for the entire segment.
What is the recommended baud rate for an S7-300 + CP5611 + WinCC network with cable runs around 50 m?
1.5 Mbps works for short, well-terminated, premium-cable segments, but field experience shows 500 kbps or 187.5 kbps is more robust. A bus running at 187.5 kbps with eight active nodes has a cycle time of about 10–20 ms, which is more than fast enough for the typical WinCC update time of 1 s. The lower speed buys you tolerance to cable quality and EMI, which is the typical field variable that drifts over time.
Why did a 30-minute power-off of the master PLC fix the ####### symptom?
Modern S7-300 CPU firmware retains a small amount of internal state (token-passing timing, error counters, configuration revision) across a short power interruption. A 30-minute power-off allows the on-board supercapacitors and bypass capacitors to bleed down to a guaranteed state and forces a full cold start of the Profibus DP subsystem. The same outcome is occasionally possible with a mode-switch transition RUN→STOP→MRES→RUN, but a hard power-off is the most reliable reset when the master is in a soft-hung state.
Can I mix MPI and Profibus devices on the same physical cable?
Yes, but only at a baud rate supported by both — the most common compromise is 187.5 kbps. The MPI and Profibus protocols are distinct at the data-link layer and coexist on the same RS-485 wire; a Profibus master will not pass token to an MPI-only station, but a CP5611 that supports both profiles can talk to either kind of device on the same physical bus. Termination rules are identical because both protocols use RS-485 at the physical layer.
How do I tell whether the problem is a cable break or a master lockup?
Disconnect the master from the bus and power it off. Connect a single healthy Profibus slave (or a second CP5611 configured as a diagnostic tool) to the bus. If the slave / diagnostic tool can be detected from STEP 7 → Accessible Nodes, the cable and the rest of the segment are healthy and the master is the suspect. If the diagnostic tool cannot be detected either, the cable, termination, or a passive slave is the suspect and you should test the bus at one node at a time until the bus returns to healthy.