1. System Architecture Overview
Designing a SIMATIC S7-1200 station with four 6ES7 221-1BH30-0XB0 (SM 1221, 16 digital inputs @ 24 V DC) modules, three 6ES7 222-1BH30-0XB0 (SM 1222, 16 digital outputs @ 24 V DC) modules, and a CP 1243-7 LTE communications processor requires a CPU that supports at least eight signal-module (SM) slots. The CPU 1214C DC/DC/DC (or DC/DC/Rly) supports exactly one signal board (SB) plus eight signal modules, which is the smallest CPU that fits the seven SMs plus one CP 1243-7 LTE combination requested.
The station is intended for unattended remote operation, so a cellular backhaul is used in place of a fixed LAN. The CP 1243-7 LTE provides an IP-based tunnel that the engineering workstation can use to load STEP 7 projects, run online diagnostics, reach the Web server, and poll the S7 program as if the CPU were on the local network. Refer to the S7-1200 Programmable Controller System Manual (PDF) for the full module catalog and configuration rules.
1.1 Topology Diagram
Figure 1: rack layout from left to right. CPU 1214C occupies slot 0; SM 1221 modules occupy slots 1-4; SM 1222 modules occupy slots 5-7; the CP 1243-7 LTE occupies slot 8. The CP terminates on an LTE/UMTS/GPRS cellular network and exposes the S7-1200 station to a remote engineering station through an OpenVPN or TeleControl Server Basic tunnel.
2. CPU 1214C Selection and Slot Rules
The S7-1200 family defines a strict maximum number of signal modules per CPU. A CPU smaller than 1214C cannot host seven SMs plus a communications processor.
| CPU | Order number (DC/DC/DC variant) | Onboard DI / DO / AI | Signal Board slots | Signal Module slots | Work memory |
|---|---|---|---|---|---|
| CPU 1211C | 6ES7 211-1AE40-0XB0 | 6 DI / 4 DO / 2 AI | 1 | 0 | 50 KB |
| CPU 1212C | 6ES7 212-1AE40-0XB0 | 8 DI / 6 DO / 2 AI | 1 | 2 | 50 KB |
| CPU 1214C | 6ES7 214-1AG40-0XB0 | 14 DI / 10 DO / 2 AI | 1 | 8 | 75 KB |
| CPU 1215C | 6ES7 215-1AG40-0XB0 | 14 DI / 10 DO / 2 AI | 1 | 8 | 100 KB |
| CPU 1217C | 6ES7 217-1AG40-0XB0 | 14 DI / 10 DO / 2 AI | 1 | 8 | 125 KB |
For the requested four SM 1221 plus three SM 1222 plus CP 1243-7 LTE, eight SM slots are required. The CPU 1214C is the lowest-cost CPU that meets the requirement, and 75 KB of work memory is more than enough for typical remote-telemetry programs (count, scale, alarm, log, S7 communication). The 1214C is also available with a relay output variant (6ES7 214-1BG40-0XB0); choose the DC/DC/DC transistor variant when interfacing to 24 V DC loads.
For the new S7-1200 G2 platform, see the SIMATIC S7-1200 G2 product page. G2 CPUs expose different SM limits and firmware; the slot and tunnel rules in this article apply to the classic S7-1200 (firmware V4.x).
3. SM 1221 DI 16x24VDC (6ES7 221-1BH30-0XB0)
The SM 1221 digital input module with order number 6ES7 221-1BH30-0XB0 provides 16 sinking/sourcing 24 V DC inputs organized in two groups of eight. The four modules requested therefore contribute 64 isolated digital inputs.
| Parameter | Value |
|---|---|
| Number of inputs | 16 (2 groups of 8) |
| Rated input voltage | 24 V DC at 7 mA (typ.) |
| Logic "1" range | 15 V DC to 30 V DC |
| Logic "0" range | 0 V DC to 5 V DC |
| Input delay (selectable per group) | 0.2 / 0.4 / 0.8 / 1.6 / 3.2 / 6.4 / 12.8 / 20 ms |
| Isolation (group to logic) | 500 V AC for 1 minute |
| Cable length, shielded | 500 m |
| Cable length, unshielded | 300 m |
| Current consumption (5 V backplane) | 130 mA |
| Power dissipation | 2.5 W typ. |
| Dimensions (W x H x D) | 70 x 100 x 75 mm |
| Operating temperature | -20 to +60 °C horizontal mount |
Each input requires a 24 V source; the module's two groups can be wired either as PNP (sourcing) sensors to a common 24 V return or as NPN sensors with a 0 V common. The default project setting in TIA Portal is PNP (type 1 according to IEC 61131-2). To toggle, open Device view > SM 1221 properties > Digital inputs > Input filter.
4. SM 1222 DQ 16x24VDC (6ES7 222-1BH30-0XB0)
The SM 1222 transistor output module with order number 6ES7 222-1BH30-0XB0 delivers 16 sourcing 24 V DC outputs rated at 0.5 A each, organized in two groups of eight. Three modules therefore contribute 48 outputs, 24 A of switched load capacity in total per module group, and 1 A continuous per output.
| Parameter | Value |
|---|---|
| Number of outputs | 16 (2 groups of 8) |
| Output type | Solid-state, PNP (sourcing) |
| Rated output voltage | 24 V DC (permissive 20.4 - 28.8 V) |
| Rated output current per channel | 0.5 A |
| Maximum current per group | 8 A |
| On-state voltage drop | < 0.5 V at 0.5 A |
| Switching frequency, resistive | 100 Hz |
| Switching frequency, inductive | 0.5 Hz (with external free-wheeling diode) |
| Leakage current in OFF state | < 10 µA |
| Short-circuit / overload | Electronic, latching per group; diagnostic interrupt supported |
| Current consumption (5 V backplane) | 140 mA |
| Power dissipation | 3.0 W typ. |
SM1222_Diag flags populate in the diagnostic buffer. Cycle 24 V on the affected group, or power-cycle the module, to clear.For inductive loads such as solenoid valves or DC contactors, install a flyback diode (1N4007 or equivalent) directly across the coil, reverse-biased with respect to the 24 V supply. This both protects the output transistor and extends its life.
5. I/O Address Map and Process Image
The S7-1200 allocates I/O addresses automatically when modules are placed in the device view of TIA Portal, but the engineer should understand the address map for program design, HMI tag mapping, and process-image optimization.
| Slot | Module | Inputs (default) | Outputs (default) |
|---|---|---|---|
| 0 (CPU onboard) | CPU 1214C | IB 0 / IB 1 (14 DI) | QB 0 / QB 1 (10 DO) |
| 0 (SB, optional) | SB 1221 / SB 1222 / SB 1231 | IB 2 / QB 2 (per SB) | IB 2 / QB 2 (per SB) |
| 1 | SM 1221 (DI 16) | I 3.0 - I 4.7 | - |
| 2 | SM 1221 (DI 16) | I 5.0 - I 6.7 | - |
| 3 | SM 1221 (DI 16) | I 7.0 - I 8.7 | - |
| 4 | SM 1221 (DI 16) | I 9.0 - I 10.7 | - |
| 5 | SM 1222 (DQ 16) | - | Q 3.0 - Q 4.7 |
| 6 | SM 1222 (DQ 16) | - | Q 5.0 - Q 6.7 |
| 7 | SM 1222 (DQ 16) | - | Q 7.0 - Q 8.7 |
| 8 | CP 1243-7 LTE | (diagnostic only, no PI) | (diagnostic only, no PI) |
Total points used:
- Digital inputs: 14 onboard + 64 SM = 78 DI (8 DI reserved in process image for SM slot alignment)
- Digital outputs: 10 onboard + 48 SM = 58 DO
The CPU 1214C supports a process image of 1024 bytes for inputs and 1024 bytes for outputs. The configuration above uses 11 bytes of inputs and 9 bytes of outputs, leaving substantial headroom. The CP 1243-7 LTE does not consume process-image space; it reports diagnostics only via the standard diagnostic buffer and the web server.
6. Power Budget Calculation
Each S7-1200 SM draws its internal logic current from the 5 V backplane that the CPU supplies. The CPU 1214C budget is 1600 mA on 5 V. The 24 V sensor and actuator current comes from the user's 24 V supply, not from the CPU.
| Module | Qty | 5 V consumption per module | Total 5 V |
|---|---|---|---|
| CPU 1214C internal use | 1 | ~ 250 mA (system reserve) | 250 mA |
| SM 1221 (6ES7 221-1BH30-0XB0) | 4 | 130 mA | 520 mA |
| SM 1222 (6ES7 222-1BH30-0XB0) | 3 | 140 mA | 420 mA |
| CP 1243-7 LTE | 1 | 0 mA (powered from external 24 V) | 0 mA |
| Total | 1190 mA | ||
| CPU 1214C budget | 1600 mA | ||
| Margin | 410 mA (25 %) |
The 5 V budget is satisfied. The 24 V supply that feeds the inputs and the loads must be sized separately. As a worst case for 24 V sizing, with all 64 inputs energized at 7 mA each and all 48 outputs at 0.5 A each (24 A continuous total - which exceeds practical duty), the field current dominates by an order of magnitude. Specify a 24 V, 10 A SITOP or equivalent and verify the inrush of any DC loads.
6.1 24 V Sensor and Load Supply
Formulae for sizing the 24 V supply:
- Input hold current:
I_in_total = N_DI * 7 mA - Output load current:
I_out_total = sum(I_load_i) - Sensor supply margin:
I_margin = 1.25 * (I_in_total + I_out_total)
For the worst case of 64 inputs and 48 outputs at average 0.2 A per output, the field-side requirement is roughly 1.25 * (0.45 A + 9.6 A) = 12.6 A. A 10 A supply is acceptable if real load duty is below 0.18 A per output; otherwise step to 20 A. Confirm by reading the connected device datasheets.
7. CP 1243-7 LTE Communication Processor
The CP 1243-7 LTE (order number 6GK7 243-7FX30-0XE0) is the S7-1200 communications processor that provides IP connectivity over LTE / UMTS / GSM / GPRS. It is inserted as a standard signal module in any open SM slot, but it does not occupy a process-image area; instead it acts as a router on the CPU's PROFINET interface.
| Parameter | Value |
|---|---|
| Order number | 6GK7 243-7FX30-0XE0 |
| Mobile networks | LTE (4G), UMTS (3G), GSM/GPRS (2G) |
| Frequency bands | B1 (2100), B3 (1800), B7 (2600), B8 (900), B20 (800) MHz |
| Antenna connector | SMA female, 50 ohm |
| SIM card format | Mini-SIM (2FF), 1.8 V / 3 V |
| Supply voltage | 24 V DC (19.2 - 28.8 V) |
| Current consumption at 24 V | 230 mA typ. |
| Power loss | 5.5 W typ. |
| IP services | OpenVPN client, IPsec, S7 routing, TeleControl Server Basic (TCSB), FTP, HTTP/HTTPS, NTP, DynDNS, SMTP |
| Firewall | Stateful, configurable inbound / outbound rules |
| Diagnostics | Web server, diagnostic buffer, SNMP v1/v3 |
Reference the S7-1200 device configuration documentation for slot rules, and the CP 1243-7 LTE operating instructions for SIM handling, APN setup, and security policy guidance.
8. Remote Programming and Diagnostics over LTE
The question "can I access the CPU program, diagnostic and everything like using a local LAN connection?" is answered yes, but the path is the cellular tunnel, not a direct Ethernet cable. The CP 1243-7 LTE supports two main remote-access patterns.
8.1 Pattern A: OpenVPN Tunnel (recommended)
The CP 1243-7 LTE runs an OpenVPN client that connects to an OpenVPN server on the engineering side - typically a SCALANCE M876 or any Linux/Windows host running OpenVPN 2.4+. Once the tunnel is up, the S7-1200 station is reachable on a virtual subnet, and TIA Portal can use the CPU's PROFINET interface as if it were local.
- Generate a static.key or PKI certificates for the OpenVPN server and client.
- In TIA Portal, drag the CP 1243-7 into the device view at slot 8.
- Open CP 1243-7 properties > VPN > OpenVPN and set the role to Client.
- Import the .ovpn profile or paste the static.key contents into the configuration.
- Enter the OpenVPN server's public DNS or fixed IP and the listening UDP/TCP port (default 1194/TCP).
- Assign a virtual IP to the CP (e.g. 10.8.0.2) and to the engineering station (10.8.0.1).
- Compile and download. The CP dials the APN, establishes the OpenVPN session, and the CPU becomes reachable at its PROFINET IP over the tunnel.
From the engineering station, the following tools work over the tunnel:
- TIA Portal Online > Go online against the CPU's IP - full program read/write, force table, watch table, trace, online diagnostics.
- Web browser to the CPU's Web server (default 80 / 443) and the CP's Web server (port 80 / 443, separate IP).
- SIMATIC Automation Tool for firmware update and project push.
- WinCC Unified / HMI panel remote commissioning.
- PUTTY / SSH into the CP's management interface (when enabled).
8.2 Pattern B: TeleControl Server Basic
Siemens TeleControl Server Basic (TCSB) is a Windows-based OPC UA server that aggregates remote S7-1200 stations. Each CP 1243-7 LTE acts as a TCSB agent and reports tags on a schedule or on change. TCSB is more appropriate for SCADA telemetry than for full program downloads; it is best deployed when the application primarily reads process values and writes set points.
- Install TCSB on a Windows server reachable from the public internet.
- In the CP's TIA Portal configuration, enable Telecontrol > TeleControl Server Basic.
- Enter the TCSB server address, project number, station number, and a 32-byte PSK.
- Define the data points (process tags) and their send cycle / trigger conditions.
- Compile and download the CP. The CP dials the APN, opens a TLS-protected session to TCSB, and pushes the configured tags.
8.3 What Works Locally vs. What Works Remotely
| Function | Local LAN | OpenVPN tunnel | TCSB |
|---|---|---|---|
| Program download / upload (TIA Portal) | Yes | Yes | No |
| Online watch / force table | Yes | Yes | No |
| CPU Web server | Yes | Yes | No |
| CP Web server / diagnostics | Yes | Yes | Yes (subset) |
| HMI panel remote update | Yes | Yes | No |
| Firmware update via SIMATIC Automation Tool | Yes | Yes (slow) | No |
| SCADA tag polling (OPC UA) | Yes | Yes | Yes (primary use) |
| Trace recording / download | Yes | Yes | No |
9. TIA Portal Project Configuration
The following steps assume TIA Portal V16 / V17 / V18 with HSP 0286 or later installed so the SM 1221 -1BH30-, SM 1222 -1BH30-, and CP 1243-7 LTE -7FX30- are present in the hardware catalog.
9.1 Create the Project and Add the CPU
- Launch TIA Portal and select Create new project. Name it (e.g. RTU_S7_1200_v01).
- Open Add new device > SIMATIC S7-1200 > CPU > CPU 1214C DC/DC/DC > 6ES7 214-1AG40-0XB0. Pick the firmware version that matches the physical CPU (e.g. V4.4 or V4.5).
- In Device view, confirm that the PROFINET interface is configured with an IP, e.g. 192.168.0.10 / 255.255.255.0, and that the CPU is the IO controller.
9.2 Insert the Signal Modules
- Open the hardware catalog and navigate to SM 1221 > DI 16x24V (6ES7 221-1BH30-0XB0). Drag four instances into slots 1 through 4 of the device view.
- Open the catalog under SM 1222 > DQ 16x24V (6ES7 222-1BH30-0XB0) and drag three instances into slots 5 through 7.
- For each module, set the input filter (SM 1221) and the output reaction to CPU stop (SM 1222: Keep last value or Substitute a value).
9.3 Insert the CP 1243-7 LTE
- Navigate to Communication modules > CP 1243-7 LTE and place it in slot 8.
- Open CP 1243-7 properties and configure the following tabs:
- Ethernet interface: assign a separate subnet IP for the CP, e.g. 192.168.1.10, or leave IP routing through the CPU interface.
- Mobile network: enter the APN provided by the M2M SIM operator, the SIM PIN, and the authentication method (PAP/CHAP/none).
- Time: enable NTP and point to a public NTP server (or the engineering station).
- Security > Firewall: restrict inbound traffic to OpenVPN UDP 1194 and S7 102 by default. Drop everything else.
- VPN: choose OpenVPN, import the client profile, and set the keep-alive interval to 30 s.
- Telecontrol (optional): if TCSB is used, fill the server address, project, and PSK.
9.4 Define the S7 Routing Path
For TIA Portal to reach the CPU over the OpenVPN tunnel, the S7 route must pass through the CP. In Online > Accessible nodes, TIA Portal will list both the CPU PROFINET IP and the CP virtual IP. Right-click the CPU and select Assign PG/PC interface, then use the OpenVPN virtual NIC as the S7 route.
10. Commissioning and Verification
Before energizing the field wiring, perform a staged verification.
- Mechanical check: confirm the CPU, four SM 1221, three SM 1222, and CP 1243-7 are latched into the DIN rail and the bus connectors are fully seated. The maximum station width is roughly 600 mm for this layout.
- Wiring check: torque every terminal to 0.6 Nm. Verify shield continuity and that no 230 V runs in the same duct as the 24 V signal cable.
- Power-on, no load: apply 24 V to the CPU and observe the LEDs. CPU: STOP (yellow), ERROR (off). CP: RN (off until SIM inserted). All SM LEDs: PWR (green), ERROR (off).
- SIM and APN: insert a working M2M SIM into the CP. After ~30 s the CP's RN LED should go green solid, indicating LTE/UMTS attached. The SIG LEDs indicate signal strength: 1 LED marginal, 4 LEDs excellent.
-
OpenVPN bring-up: check the CP's Web server at
https://<CP-IP>. The VPN status page should show Connected with the assigned virtual IP. - Online connection: from the engineering station, open TIA Portal and run Online > Accessible nodes. The CPU should appear with its PROFINET IP. Click Go online and verify the project name and the cycle time.
- Force table test: write a single DI bit and verify the input LED on the corresponding SM 1221. Then force a single DO bit and verify the output LED on the corresponding SM 1222 and the actual load.
- Diagnostic buffer: empty the buffer, then re-run the test sequence. The buffer should be clean of hardware faults.
- Watch table: add a tag from each SM and a tag for the CP's online status. Leave the watch table open for 24 h and verify the CP keeps the tunnel up through any APN dropouts (the CP will redial within ~30 s).
11. Troubleshooting Matrix
| Symptom | Likely cause | Diagnostic step | Remedy |
|---|---|---|---|
| CPU ERROR LED red, MAINT flashing | Module missing or wrong firmware on SM | TIA Portal online > Diagnostics > Device status | Update SM firmware or replace the module |
| SM 1221 inputs read 0 with 24 V applied | Input filter set too slow, or wrong PNP/NPN type | Watch table with raw input bit; check Properties > Input filter | Reduce input filter; verify wiring polarity |
| SM 1222 output stays off, ERROR red on module | Output group in electronic short-circuit latch | Diagnostic buffer entry "Short circuit on DO group 0/1" | Remove the load, cycle 24 V on the affected group |
| CP 1243-7 RN LED off | SIM not recognized, APN incorrect, no network | CP Web server > Mobile network > Status | Check SIM PIN, APN, antenna, and signal level |
| CP 1243-7 RN green, but no TIA Portal connection | OpenVPN tunnel not up; firewall block | CP Web server > VPN status | Check OpenVPN server, certificates, and UDP 1194 reachability |
| OpenVPN drops every 5-10 minutes | Carrier NAT keep-alive interval too long | CP log file via Web server | Reduce OpenVPN keep-alive to 25 s; enable ping-restart |
| TIA Portal sees CPU only as "unidentified" | Wrong PG/PC interface or S7 route | Online > Accessible nodes > Show all | Bind TIA Portal to the OpenVPN virtual NIC |
| Web server returns 404 on the CPU | Web server disabled or wrong port | CPU properties > Web server | Enable Web server, allow port 80/443, set user rights |
12. Field-Proven Caveats
- Slot numbering in TIA Portal is rigid: dragging a module into slot 8 forces a renumbering of all later slots. Always start the layout with the CPU in slot 0, then add SMs left to right.
- The CP 1243-7 LTE does not pass LLDP; if the PROFINET topology view shows the CP as a "neighbor" rather than a "device," that is expected. The CP sits behind the CPU's PROFINET interface and acts as an IP router.
- Firmware V4.2 of the S7-1200 CPU has known issues with certain OpenVPN key lengths; upgrade to V4.4 or later to avoid intermittent tunnel re-key failures.
- If you co-locate the LTE antenna next to a 24 V switching power supply, expect VSWR drift under load. Move the antenna at least 50 cm from the supply's switching magnetics.
- The CP 1243-7 LTE does not support NAT loopback. Test the OpenVPN server from a separate internet connection before commissioning the remote site.
- For S7 routing through the CP, enable the S7 communication load on the CPU: CPU properties > Communication > S7 communication > Permit. Without this, the S7 PUT/GET traffic is blocked by default on firmware V4.x.
FAQ
Can a CPU 1212C be used with four SM 1221, three SM 1222, and one CP 1243-7 LTE?
No. The CPU 1212C supports a maximum of two signal-module slots, which is fewer than the seven SMs and one CP required. Step up to the CPU 1214C, which provides eight SM slots, or to the 1215C / 1217C for additional work memory.
How many digital inputs and outputs are available with the four SM 1221 plus three SM 1222 layout?
You get 14 onboard DI and 64 SM DI (78 DI total), and 10 onboard DO and 48 SM DO (58 DO total). The 1214C process image allows up to 1024 bytes for inputs and 1024 bytes for outputs, so this layout uses less than 2 % of the available image.
Does the CP 1243-7 LTE replace a wired PROFINET connection for programming?
Functionally yes, performance no. The CP 1243-7 LTE establishes an IP tunnel (OpenVPN or TeleControl) over LTE/UMTS/GPRS. TIA Portal can run Go online, force tables, and download projects through this tunnel, but download times scale with the cellular uplink bandwidth (typically 1-10 Mbit/s on LTE).
What is the order number of the CP 1243-7 LTE?
The CP 1243-7 LTE is 6GK7 243-7FX30-0XE0. It supports LTE / UMTS / GSM / GPRS, accepts a Mini-SIM (2FF) with 1.8 V or 3 V logic, draws 230 mA at 24 V, and exposes an SMA antenna connector.
Can I add a SIMATIC HMI panel to the S7-1200 and reach it remotely through the CP 1243-7 LTE?
Yes. The HMI panel connects to the S7-1200 PROFINET interface as usual; from the engineering side, the OpenVPN tunnel makes the panel and the CPU appear on the same subnet. You can run HMI commissioning, change the project, and update firmware remotely through TIA Portal.
What happens when the cellular network drops briefly?
The CP 1243-7 LTE continues to buffer outgoing telecontrol messages (when TCSB is configured) and the OpenVPN client will redial within ~30 s. The CPU program runs unaffected because the S7-1200 is autonomous; the cellular link is purely for remote access and SCADA reporting.
Do I need a static public IP for the OpenVPN server?
It is highly recommended. If the server has a dynamic IP, configure a Dynamic DNS hostname on the CP and enable DynDNS updates. The CP 1243-7 LTE supports the major DynDNS providers natively; see the S7-1200 device configuration documentation for the supported list.