S7-1200 CPU 1214C Configuration: 4 DI/DQ SMs with CP 1243-7 LTE

David Krause19 min read
S7-1200SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. System Architecture Overview

Designing a SIMATIC S7-1200 station with four 6ES7 221-1BH30-0XB0 (SM 1221, 16 digital inputs @ 24 V DC) modules, three 6ES7 222-1BH30-0XB0 (SM 1222, 16 digital outputs @ 24 V DC) modules, and a CP 1243-7 LTE communications processor requires a CPU that supports at least eight signal-module (SM) slots. The CPU 1214C DC/DC/DC (or DC/DC/Rly) supports exactly one signal board (SB) plus eight signal modules, which is the smallest CPU that fits the seven SMs plus one CP 1243-7 LTE combination requested.

The station is intended for unattended remote operation, so a cellular backhaul is used in place of a fixed LAN. The CP 1243-7 LTE provides an IP-based tunnel that the engineering workstation can use to load STEP 7 projects, run online diagnostics, reach the Web server, and poll the S7 program as if the CPU were on the local network. Refer to the S7-1200 Programmable Controller System Manual (PDF) for the full module catalog and configuration rules.

1.1 Topology Diagram

CPU 1214C DC/DC/DC SM 1221DI 16x24V (Slot 1) SM 1221DI 16x24V (Slot 2) SM 1221DI 16x24V (Slot 3) SM 1221DI 16x24V (Slot 4) SM 1222DQ 16x24V (Slot 5) SM 1222DQ 16x24V (Slot 6) SM 1222DQ 16x24V (Slot 7) CP 1243-7 LTE6GK7243-7FX30-0XE0 (Slot 8) LTE/UMTS/GPRSCellular Network OpenVPN Server / TCSBSCALANCE M876 / TCSB TIA PortalPG/PC Remote PROFINET

Figure 1: rack layout from left to right. CPU 1214C occupies slot 0; SM 1221 modules occupy slots 1-4; SM 1222 modules occupy slots 5-7; the CP 1243-7 LTE occupies slot 8. The CP terminates on an LTE/UMTS/GPRS cellular network and exposes the S7-1200 station to a remote engineering station through an OpenVPN or TeleControl Server Basic tunnel.

2. CPU 1214C Selection and Slot Rules

The S7-1200 family defines a strict maximum number of signal modules per CPU. A CPU smaller than 1214C cannot host seven SMs plus a communications processor.

CPU Order number (DC/DC/DC variant) Onboard DI / DO / AI Signal Board slots Signal Module slots Work memory
CPU 1211C 6ES7 211-1AE40-0XB0 6 DI / 4 DO / 2 AI 1 0 50 KB
CPU 1212C 6ES7 212-1AE40-0XB0 8 DI / 6 DO / 2 AI 1 2 50 KB
CPU 1214C 6ES7 214-1AG40-0XB0 14 DI / 10 DO / 2 AI 1 8 75 KB
CPU 1215C 6ES7 215-1AG40-0XB0 14 DI / 10 DO / 2 AI 1 8 100 KB
CPU 1217C 6ES7 217-1AG40-0XB0 14 DI / 10 DO / 2 AI 1 8 125 KB

For the requested four SM 1221 plus three SM 1222 plus CP 1243-7 LTE, eight SM slots are required. The CPU 1214C is the lowest-cost CPU that meets the requirement, and 75 KB of work memory is more than enough for typical remote-telemetry programs (count, scale, alarm, log, S7 communication). The 1214C is also available with a relay output variant (6ES7 214-1BG40-0XB0); choose the DC/DC/DC transistor variant when interfacing to 24 V DC loads.

Note: An SB (signal board) installs in the CPU itself, not on the DIN rail, and does not consume an SM slot. If you also need an analog SB or a battery SB, it does not displace an SM.

For the new S7-1200 G2 platform, see the SIMATIC S7-1200 G2 product page. G2 CPUs expose different SM limits and firmware; the slot and tunnel rules in this article apply to the classic S7-1200 (firmware V4.x).

3. SM 1221 DI 16x24VDC (6ES7 221-1BH30-0XB0)

The SM 1221 digital input module with order number 6ES7 221-1BH30-0XB0 provides 16 sinking/sourcing 24 V DC inputs organized in two groups of eight. The four modules requested therefore contribute 64 isolated digital inputs.

Parameter Value
Number of inputs 16 (2 groups of 8)
Rated input voltage 24 V DC at 7 mA (typ.)
Logic "1" range 15 V DC to 30 V DC
Logic "0" range 0 V DC to 5 V DC
Input delay (selectable per group) 0.2 / 0.4 / 0.8 / 1.6 / 3.2 / 6.4 / 12.8 / 20 ms
Isolation (group to logic) 500 V AC for 1 minute
Cable length, shielded 500 m
Cable length, unshielded 300 m
Current consumption (5 V backplane) 130 mA
Power dissipation 2.5 W typ.
Dimensions (W x H x D) 70 x 100 x 75 mm
Operating temperature -20 to +60 °C horizontal mount

Each input requires a 24 V source; the module's two groups can be wired either as PNP (sourcing) sensors to a common 24 V return or as NPN sensors with a 0 V common. The default project setting in TIA Portal is PNP (type 1 according to IEC 61131-2). To toggle, open Device view > SM 1221 properties > Digital inputs > Input filter.

Field tip: When a long shielded cable runs through a noisy plant, increase the input filter to 3.2 ms or 6.4 ms to reject conducted interference. Faster cycle applications should stay at 0.8 ms or below.

4. SM 1222 DQ 16x24VDC (6ES7 222-1BH30-0XB0)

The SM 1222 transistor output module with order number 6ES7 222-1BH30-0XB0 delivers 16 sourcing 24 V DC outputs rated at 0.5 A each, organized in two groups of eight. Three modules therefore contribute 48 outputs, 24 A of switched load capacity in total per module group, and 1 A continuous per output.

Parameter Value
Number of outputs 16 (2 groups of 8)
Output type Solid-state, PNP (sourcing)
Rated output voltage 24 V DC (permissive 20.4 - 28.8 V)
Rated output current per channel 0.5 A
Maximum current per group 8 A
On-state voltage drop < 0.5 V at 0.5 A
Switching frequency, resistive 100 Hz
Switching frequency, inductive 0.5 Hz (with external free-wheeling diode)
Leakage current in OFF state < 10 µA
Short-circuit / overload Electronic, latching per group; diagnostic interrupt supported
Current consumption (5 V backplane) 140 mA
Power dissipation 3.0 W typ.
Warning: A short-circuited output will latch the affected group off and raise a diagnostic interrupt. The CPU's error LED (ERROR) lights and SM1222_Diag flags populate in the diagnostic buffer. Cycle 24 V on the affected group, or power-cycle the module, to clear.

For inductive loads such as solenoid valves or DC contactors, install a flyback diode (1N4007 or equivalent) directly across the coil, reverse-biased with respect to the 24 V supply. This both protects the output transistor and extends its life.

5. I/O Address Map and Process Image

The S7-1200 allocates I/O addresses automatically when modules are placed in the device view of TIA Portal, but the engineer should understand the address map for program design, HMI tag mapping, and process-image optimization.

Slot Module Inputs (default) Outputs (default)
0 (CPU onboard) CPU 1214C IB 0 / IB 1 (14 DI) QB 0 / QB 1 (10 DO)
0 (SB, optional) SB 1221 / SB 1222 / SB 1231 IB 2 / QB 2 (per SB) IB 2 / QB 2 (per SB)
1 SM 1221 (DI 16) I 3.0 - I 4.7 -
2 SM 1221 (DI 16) I 5.0 - I 6.7 -
3 SM 1221 (DI 16) I 7.0 - I 8.7 -
4 SM 1221 (DI 16) I 9.0 - I 10.7 -
5 SM 1222 (DQ 16) - Q 3.0 - Q 4.7
6 SM 1222 (DQ 16) - Q 5.0 - Q 6.7
7 SM 1222 (DQ 16) - Q 7.0 - Q 8.7
8 CP 1243-7 LTE (diagnostic only, no PI) (diagnostic only, no PI)

Total points used:

  • Digital inputs: 14 onboard + 64 SM = 78 DI (8 DI reserved in process image for SM slot alignment)
  • Digital outputs: 10 onboard + 48 SM = 58 DO

The CPU 1214C supports a process image of 1024 bytes for inputs and 1024 bytes for outputs. The configuration above uses 11 bytes of inputs and 9 bytes of outputs, leaving substantial headroom. The CP 1243-7 LTE does not consume process-image space; it reports diagnostics only via the standard diagnostic buffer and the web server.

Engineering tip: If a future expansion adds a second CP 1243-7 LTE for redundancy, or a CM 1241 for RS-232/RS-485, the diagnostic-only address assignment means you can place the CP at any open SM slot without re-mapping the application program.

6. Power Budget Calculation

Each S7-1200 SM draws its internal logic current from the 5 V backplane that the CPU supplies. The CPU 1214C budget is 1600 mA on 5 V. The 24 V sensor and actuator current comes from the user's 24 V supply, not from the CPU.

Module Qty 5 V consumption per module Total 5 V
CPU 1214C internal use 1 ~ 250 mA (system reserve) 250 mA
SM 1221 (6ES7 221-1BH30-0XB0) 4 130 mA 520 mA
SM 1222 (6ES7 222-1BH30-0XB0) 3 140 mA 420 mA
CP 1243-7 LTE 1 0 mA (powered from external 24 V) 0 mA
Total 1190 mA
CPU 1214C budget 1600 mA
Margin 410 mA (25 %)

The 5 V budget is satisfied. The 24 V supply that feeds the inputs and the loads must be sized separately. As a worst case for 24 V sizing, with all 64 inputs energized at 7 mA each and all 48 outputs at 0.5 A each (24 A continuous total - which exceeds practical duty), the field current dominates by an order of magnitude. Specify a 24 V, 10 A SITOP or equivalent and verify the inrush of any DC loads.

6.1 24 V Sensor and Load Supply

Formulae for sizing the 24 V supply:

  • Input hold current: I_in_total = N_DI * 7 mA
  • Output load current: I_out_total = sum(I_load_i)
  • Sensor supply margin: I_margin = 1.25 * (I_in_total + I_out_total)

For the worst case of 64 inputs and 48 outputs at average 0.2 A per output, the field-side requirement is roughly 1.25 * (0.45 A + 9.6 A) = 12.6 A. A 10 A supply is acceptable if real load duty is below 0.18 A per output; otherwise step to 20 A. Confirm by reading the connected device datasheets.

7. CP 1243-7 LTE Communication Processor

The CP 1243-7 LTE (order number 6GK7 243-7FX30-0XE0) is the S7-1200 communications processor that provides IP connectivity over LTE / UMTS / GSM / GPRS. It is inserted as a standard signal module in any open SM slot, but it does not occupy a process-image area; instead it acts as a router on the CPU's PROFINET interface.

Parameter Value
Order number 6GK7 243-7FX30-0XE0
Mobile networks LTE (4G), UMTS (3G), GSM/GPRS (2G)
Frequency bands B1 (2100), B3 (1800), B7 (2600), B8 (900), B20 (800) MHz
Antenna connector SMA female, 50 ohm
SIM card format Mini-SIM (2FF), 1.8 V / 3 V
Supply voltage 24 V DC (19.2 - 28.8 V)
Current consumption at 24 V 230 mA typ.
Power loss 5.5 W typ.
IP services OpenVPN client, IPsec, S7 routing, TeleControl Server Basic (TCSB), FTP, HTTP/HTTPS, NTP, DynDNS, SMTP
Firewall Stateful, configurable inbound / outbound rules
Diagnostics Web server, diagnostic buffer, SNMP v1/v3

Reference the S7-1200 device configuration documentation for slot rules, and the CP 1243-7 LTE operating instructions for SIM handling, APN setup, and security policy guidance.

Field tip: Place an LTE antenna at least 30 cm away from the CPU and the SM backplane bus connector. Route the SMA pigtail through a 90-degree bend, not a sharp loop, to keep the VSWR below 1.5:1.

8. Remote Programming and Diagnostics over LTE

The question "can I access the CPU program, diagnostic and everything like using a local LAN connection?" is answered yes, but the path is the cellular tunnel, not a direct Ethernet cable. The CP 1243-7 LTE supports two main remote-access patterns.

8.1 Pattern A: OpenVPN Tunnel (recommended)

The CP 1243-7 LTE runs an OpenVPN client that connects to an OpenVPN server on the engineering side - typically a SCALANCE M876 or any Linux/Windows host running OpenVPN 2.4+. Once the tunnel is up, the S7-1200 station is reachable on a virtual subnet, and TIA Portal can use the CPU's PROFINET interface as if it were local.

  1. Generate a static.key or PKI certificates for the OpenVPN server and client.
  2. In TIA Portal, drag the CP 1243-7 into the device view at slot 8.
  3. Open CP 1243-7 properties > VPN > OpenVPN and set the role to Client.
  4. Import the .ovpn profile or paste the static.key contents into the configuration.
  5. Enter the OpenVPN server's public DNS or fixed IP and the listening UDP/TCP port (default 1194/TCP).
  6. Assign a virtual IP to the CP (e.g. 10.8.0.2) and to the engineering station (10.8.0.1).
  7. Compile and download. The CP dials the APN, establishes the OpenVPN session, and the CPU becomes reachable at its PROFINET IP over the tunnel.

From the engineering station, the following tools work over the tunnel:

  • TIA Portal Online > Go online against the CPU's IP - full program read/write, force table, watch table, trace, online diagnostics.
  • Web browser to the CPU's Web server (default 80 / 443) and the CP's Web server (port 80 / 443, separate IP).
  • SIMATIC Automation Tool for firmware update and project push.
  • WinCC Unified / HMI panel remote commissioning.
  • PUTTY / SSH into the CP's management interface (when enabled).

8.2 Pattern B: TeleControl Server Basic

Siemens TeleControl Server Basic (TCSB) is a Windows-based OPC UA server that aggregates remote S7-1200 stations. Each CP 1243-7 LTE acts as a TCSB agent and reports tags on a schedule or on change. TCSB is more appropriate for SCADA telemetry than for full program downloads; it is best deployed when the application primarily reads process values and writes set points.

  1. Install TCSB on a Windows server reachable from the public internet.
  2. In the CP's TIA Portal configuration, enable Telecontrol > TeleControl Server Basic.
  3. Enter the TCSB server address, project number, station number, and a 32-byte PSK.
  4. Define the data points (process tags) and their send cycle / trigger conditions.
  5. Compile and download the CP. The CP dials the APN, opens a TLS-protected session to TCSB, and pushes the configured tags.
Note: Full STEP 7 program download over TCSB is not supported. To load a new project to the S7-1200 from a TCSB-managed site, use the OpenVPN pattern or schedule an on-site visit.

8.3 What Works Locally vs. What Works Remotely

Function Local LAN OpenVPN tunnel TCSB
Program download / upload (TIA Portal) Yes Yes No
Online watch / force table Yes Yes No
CPU Web server Yes Yes No
CP Web server / diagnostics Yes Yes Yes (subset)
HMI panel remote update Yes Yes No
Firmware update via SIMATIC Automation Tool Yes Yes (slow) No
SCADA tag polling (OPC UA) Yes Yes Yes (primary use)
Trace recording / download Yes Yes No

9. TIA Portal Project Configuration

The following steps assume TIA Portal V16 / V17 / V18 with HSP 0286 or later installed so the SM 1221 -1BH30-, SM 1222 -1BH30-, and CP 1243-7 LTE -7FX30- are present in the hardware catalog.

9.1 Create the Project and Add the CPU

  1. Launch TIA Portal and select Create new project. Name it (e.g. RTU_S7_1200_v01).
  2. Open Add new device > SIMATIC S7-1200 > CPU > CPU 1214C DC/DC/DC > 6ES7 214-1AG40-0XB0. Pick the firmware version that matches the physical CPU (e.g. V4.4 or V4.5).
  3. In Device view, confirm that the PROFINET interface is configured with an IP, e.g. 192.168.0.10 / 255.255.255.0, and that the CPU is the IO controller.

9.2 Insert the Signal Modules

  1. Open the hardware catalog and navigate to SM 1221 > DI 16x24V (6ES7 221-1BH30-0XB0). Drag four instances into slots 1 through 4 of the device view.
  2. Open the catalog under SM 1222 > DQ 16x24V (6ES7 222-1BH30-0XB0) and drag three instances into slots 5 through 7.
  3. For each module, set the input filter (SM 1221) and the output reaction to CPU stop (SM 1222: Keep last value or Substitute a value).

9.3 Insert the CP 1243-7 LTE

  1. Navigate to Communication modules > CP 1243-7 LTE and place it in slot 8.
  2. Open CP 1243-7 properties and configure the following tabs:
  • Ethernet interface: assign a separate subnet IP for the CP, e.g. 192.168.1.10, or leave IP routing through the CPU interface.
  • Mobile network: enter the APN provided by the M2M SIM operator, the SIM PIN, and the authentication method (PAP/CHAP/none).
  • Time: enable NTP and point to a public NTP server (or the engineering station).
  • Security > Firewall: restrict inbound traffic to OpenVPN UDP 1194 and S7 102 by default. Drop everything else.
  • VPN: choose OpenVPN, import the client profile, and set the keep-alive interval to 30 s.
  • Telecontrol (optional): if TCSB is used, fill the server address, project, and PSK.

9.4 Define the S7 Routing Path

For TIA Portal to reach the CPU over the OpenVPN tunnel, the S7 route must pass through the CP. In Online > Accessible nodes, TIA Portal will list both the CPU PROFINET IP and the CP virtual IP. Right-click the CPU and select Assign PG/PC interface, then use the OpenVPN virtual NIC as the S7 route.

10. Commissioning and Verification

Before energizing the field wiring, perform a staged verification.

  1. Mechanical check: confirm the CPU, four SM 1221, three SM 1222, and CP 1243-7 are latched into the DIN rail and the bus connectors are fully seated. The maximum station width is roughly 600 mm for this layout.
  2. Wiring check: torque every terminal to 0.6 Nm. Verify shield continuity and that no 230 V runs in the same duct as the 24 V signal cable.
  3. Power-on, no load: apply 24 V to the CPU and observe the LEDs. CPU: STOP (yellow), ERROR (off). CP: RN (off until SIM inserted). All SM LEDs: PWR (green), ERROR (off).
  4. SIM and APN: insert a working M2M SIM into the CP. After ~30 s the CP's RN LED should go green solid, indicating LTE/UMTS attached. The SIG LEDs indicate signal strength: 1 LED marginal, 4 LEDs excellent.
  5. OpenVPN bring-up: check the CP's Web server at https://<CP-IP>. The VPN status page should show Connected with the assigned virtual IP.
  6. Online connection: from the engineering station, open TIA Portal and run Online > Accessible nodes. The CPU should appear with its PROFINET IP. Click Go online and verify the project name and the cycle time.
  7. Force table test: write a single DI bit and verify the input LED on the corresponding SM 1221. Then force a single DO bit and verify the output LED on the corresponding SM 1222 and the actual load.
  8. Diagnostic buffer: empty the buffer, then re-run the test sequence. The buffer should be clean of hardware faults.
  9. Watch table: add a tag from each SM and a tag for the CP's online status. Leave the watch table open for 24 h and verify the CP keeps the tunnel up through any APN dropouts (the CP will redial within ~30 s).

11. Troubleshooting Matrix

Symptom Likely cause Diagnostic step Remedy
CPU ERROR LED red, MAINT flashing Module missing or wrong firmware on SM TIA Portal online > Diagnostics > Device status Update SM firmware or replace the module
SM 1221 inputs read 0 with 24 V applied Input filter set too slow, or wrong PNP/NPN type Watch table with raw input bit; check Properties > Input filter Reduce input filter; verify wiring polarity
SM 1222 output stays off, ERROR red on module Output group in electronic short-circuit latch Diagnostic buffer entry "Short circuit on DO group 0/1" Remove the load, cycle 24 V on the affected group
CP 1243-7 RN LED off SIM not recognized, APN incorrect, no network CP Web server > Mobile network > Status Check SIM PIN, APN, antenna, and signal level
CP 1243-7 RN green, but no TIA Portal connection OpenVPN tunnel not up; firewall block CP Web server > VPN status Check OpenVPN server, certificates, and UDP 1194 reachability
OpenVPN drops every 5-10 minutes Carrier NAT keep-alive interval too long CP log file via Web server Reduce OpenVPN keep-alive to 25 s; enable ping-restart
TIA Portal sees CPU only as "unidentified" Wrong PG/PC interface or S7 route Online > Accessible nodes > Show all Bind TIA Portal to the OpenVPN virtual NIC
Web server returns 404 on the CPU Web server disabled or wrong port CPU properties > Web server Enable Web server, allow port 80/443, set user rights

12. Field-Proven Caveats

  • Slot numbering in TIA Portal is rigid: dragging a module into slot 8 forces a renumbering of all later slots. Always start the layout with the CPU in slot 0, then add SMs left to right.
  • The CP 1243-7 LTE does not pass LLDP; if the PROFINET topology view shows the CP as a "neighbor" rather than a "device," that is expected. The CP sits behind the CPU's PROFINET interface and acts as an IP router.
  • Firmware V4.2 of the S7-1200 CPU has known issues with certain OpenVPN key lengths; upgrade to V4.4 or later to avoid intermittent tunnel re-key failures.
  • If you co-locate the LTE antenna next to a 24 V switching power supply, expect VSWR drift under load. Move the antenna at least 50 cm from the supply's switching magnetics.
  • The CP 1243-7 LTE does not support NAT loopback. Test the OpenVPN server from a separate internet connection before commissioning the remote site.
  • For S7 routing through the CP, enable the S7 communication load on the CPU: CPU properties > Communication > S7 communication > Permit. Without this, the S7 PUT/GET traffic is blocked by default on firmware V4.x.

FAQ

Can a CPU 1212C be used with four SM 1221, three SM 1222, and one CP 1243-7 LTE?

No. The CPU 1212C supports a maximum of two signal-module slots, which is fewer than the seven SMs and one CP required. Step up to the CPU 1214C, which provides eight SM slots, or to the 1215C / 1217C for additional work memory.

How many digital inputs and outputs are available with the four SM 1221 plus three SM 1222 layout?

You get 14 onboard DI and 64 SM DI (78 DI total), and 10 onboard DO and 48 SM DO (58 DO total). The 1214C process image allows up to 1024 bytes for inputs and 1024 bytes for outputs, so this layout uses less than 2 % of the available image.

Does the CP 1243-7 LTE replace a wired PROFINET connection for programming?

Functionally yes, performance no. The CP 1243-7 LTE establishes an IP tunnel (OpenVPN or TeleControl) over LTE/UMTS/GPRS. TIA Portal can run Go online, force tables, and download projects through this tunnel, but download times scale with the cellular uplink bandwidth (typically 1-10 Mbit/s on LTE).

What is the order number of the CP 1243-7 LTE?

The CP 1243-7 LTE is 6GK7 243-7FX30-0XE0. It supports LTE / UMTS / GSM / GPRS, accepts a Mini-SIM (2FF) with 1.8 V or 3 V logic, draws 230 mA at 24 V, and exposes an SMA antenna connector.

Can I add a SIMATIC HMI panel to the S7-1200 and reach it remotely through the CP 1243-7 LTE?

Yes. The HMI panel connects to the S7-1200 PROFINET interface as usual; from the engineering side, the OpenVPN tunnel makes the panel and the CPU appear on the same subnet. You can run HMI commissioning, change the project, and update firmware remotely through TIA Portal.

What happens when the cellular network drops briefly?

The CP 1243-7 LTE continues to buffer outgoing telecontrol messages (when TCSB is configured) and the OpenVPN client will redial within ~30 s. The CPU program runs unaffected because the S7-1200 is autonomous; the cellular link is purely for remote access and SCADA reporting.

Do I need a static public IP for the OpenVPN server?

It is highly recommended. If the server has a dynamic IP, configure a Dynamic DNS hostname on the CP and enable DynDNS updates. The CP 1243-7 LTE supports the major DynDNS providers natively; see the S7-1200 device configuration documentation for the supported list.

Back to blog