S7-1200 Real-Time WLAN Communication with SCALANCE iWLAN Setup

David Krause14 min read
Industrial NetworkingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Application Overview

Real-time PROFINET communication between two SIMATIC S7-1200 CPUs separated by approximately 200 m of free space (aisle, yard, hall, or between buildings) is a common industrial requirement for conveyor bridges, rotating platforms, AGV transfer stations, and inter-building process links. Standard Wi-Fi consumer hardware cannot deliver the deterministic update times PROFINET IO demands. Siemens addresses this with the SCALANCE W industrial WLAN (iWLAN) family, which supports features such as iPCF (industrial Point Coordination Function), iPCF-MC (with controller handover for moving nodes), and iREF (industrial Radio Ethernet Frequency) extensions that bound latency and jitter on the wireless segment.

For a fixed 200 m point-to-point link where both nodes are stationary, the typical architecture is:

  • Each S7-1200 CPU is connected over its integrated PROFINET interface to a SCALANCE W access point (one end) and a SCALANCE W client (the other end).
  • The two SCALANCE devices form a transparent Layer-2 bridge, so PROFINET frames and S7 communication traverse the wireless link as if the two controllers were on the same switch.
  • One end is configured as Access Point (AP), the other as Client (Station). In iPCF mode the AP controls the channel access and the timing of every transmission, which is the mechanism that gives the link its deterministic behaviour.
Important: A consumer Wi-Fi router, even one that supports 802.11ac/ax, will not give you bounded PROFINET cycle times. Use SCALANCE W (or an equivalent industrial WLAN product) whenever PROFINET IO, S7 communication, or fail-safe (PROFIsafe) traffic must run over the wireless link.

2. Prerequisites and Topology

Before commissioning, confirm the following:

  • Two S7-1200 CPUs with functional PROFINET interface (X1). For the newer S7-1200 G2 generation, the CPU provides a built-in 2-port Ethernet switch, so the SCALANCE device can be daisy-chained off the same CPU. Refer to the S7-1200 G2 Communication Manual on the TIA Portal documentation cloud for the exact port assignments and pin-out of the X1/X2 sockets.
  • Both CPUs are loaded with a TIA Portal project at compatible firmware (V14 or higher recommended for iWLAN configuration under the SCALANCE W add-on).
  • Clear or near-clear Fresnel zone along the 200 m path. With 5 GHz carriers and standard 6 dBi antennas, the first Fresnel zone radius at 100 m distance is approximately 2.6 m. Trim foliage and avoid metal obstructions in the beam path.
  • 24 V DC power available at each mounting point (SCALANCE W devices accept 19.2 to 28.8 V DC on the M12 power socket).
  • PG/PC with TIA Portal (V16 or later) and Ethernet port for initial SCALANCE configuration via Web Based Management (WBM).

Logical topology reference:

CPU_1 (S7-1200) --[PROFINET]-- SCALANCE W_AP )))) ((((( SCALANCE W_CL --[PROFINET]-- CPU_2 (S7-1200)
                          |  200 m iWLAN  |  |                                 |
                          |   (5 GHz)     |  |                                 |
                       ANT795- ANT795-
                       4MA    4MA

3. SCALANCE W Family Selection Guide

The SCALANCE W portfolio is split into access points, client modules, and controllers. For a stationary 200 m point-to-point link, the typical choice is one AP and one Client, both from the same radio generation, so that the proprietary iPCF/iPCF-MC modes are available on both ends.

Article number Model Function Radio Notes
6GK5778-1GY00-0AA0 SCALANCE W778-1 M12 Access Point 1 radio, 2.4/5 GHz, 802.11ac M12 power/data, IP65, iPCF capable
6GK5788-1GY00-0AA0 SCALANCE W788-1 M12 Access Point with RCoax 1 radio, 802.11ac Use when radiating along a track/aisle
6GK5748-1GY00-0AA0 SCALANCE W748-1 M12 Client Module 1 radio, 802.11ac Stationary client, IP65, iPCF client
6GK5786-2FE00-0AA0 SCALANCE W786-2 SFP Dual-radio AP 2 radios, 802.11ac Wave 2 Redundancy with two independent iWLAN links
6GK5795-4MA00-0AA0 ANT795-4MA Directional antenna 5 GHz, ~14 dBi Recommended for 200 m directional link
6GK5795-4MN00-0AA0 ANT795-4MN Dual-band omnidirectional 2.4/5 GHz, ~6 dBi Use only if both ends have clear 360° LOS
6GK5793-6DG00-0AA0 ANT793-6DG Wide-angle directional 2.4 GHz, ~9 dBi Shorter range, not recommended at 200 m

For a 200 m fixed point-to-point application with a clear line of sight, the recommended combination is:

  • AP: SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0)
  • Client: SCALANCE W748-1 M12 (6GK5748-1GY00-0AA0)
  • Antennas: Two ANT795-4MA (6GK5795-4MA00-0AA0) panel antennas with low-loss N-connector pigtails (e.g., 6XV1875-5AH10 or 6XV1875-5CH10).
Why directional antennas matter at 200 m: Free-space path loss at 5 GHz over 200 m is approximately 106 dB. With 14 dBi directional antennas and 20 dBm transmit power, the received signal strength indicator (RSSI) typically lands between -55 dBm and -65 dBm, which is well within the iPCF operating range. With omnidirectional 6 dBi antennas, RSSI often drops to -75 dBm or lower, which still works for non-real-time TCP traffic but is borderline for the deterministic iPCF cycle times that PROFINET IO requires.

4. RF and Antenna Planning for 200 m Links

Use the standard free-space path loss (FSPL) formula to validate the link budget before installation:

FSPL (dB) = 20 * log10(d_m) + 20 * log10(f_MHz) + 32.44

For d = 200 m, f = 5180 MHz (UNII-1 lower edge, often used by iWLAN in EU/US):

FSPL = 20 * log10(200) + 20 * log10(5180) + 32.44
     = 46.0 + 74.3 + 32.44
     = 102.7 dB (round up to 103 dB)

Resulting link budget with ANT795-4MA at both ends:

Parameter Value
Tx power (configurable, typical 17 dBm) 17 dBm
Tx antenna gain 14 dBi
Rx antenna gain 14 dBi
Cable + connector loss (3 m N-connector pigtail) -2 dB
FSPL @ 200 m, 5.18 GHz -103 dB
Expected RSSI -60 dBm
SCALANCE W receiver sensitivity (MCS7, 802.11ac, 40 MHz) -67 dBm typical
Link margin ~7 dB

A 7 dB margin is acceptable for a clean outdoor aisle; if the line of sight passes through metal grating, perforated cable trays, or partial obstructions, add a 6 dB fade margin and consider a higher-gain antenna or a lower carrier frequency (2.4 GHz UNII band) to recover another 6–8 dB of path loss advantage.

5. Hardware Installation and Cabling

  1. Mount each SCALANCE W on a metal backplane or wall bracket. Maintain a minimum 30 cm clearance from large steel surfaces and switching power supplies to limit multipath and EMI.
  2. Install the ANT795-4MA antennas on weatherproof N-connector bulkheads (or use the SCALANCE W M12 connector housing). Aim the panels at each other with a maximum azimuth error of ±5°; at 200 m, a 5° error displaces the beam centre by 17 m on the far end.
  3. Use low-loss coax (e.g., 6XV1875-5AH10, LMR-400 equivalent) to keep loss below 1 dB/m at 5 GHz. Cable length should be kept under 5 m total per end.
  4. Apply 24 V DC to the M12 power socket (A-coded 4-pin). The SCALANCE W boot sequence takes approximately 30 seconds; the "A1/A2" LED turns solid green when the device is ready.
  5. Connect SCALANCE W port P1 (or P2) to the S7-1200 PROFINET X1 socket using a standard Cat 6 M12 D-coded Ethernet cordset (6XV1870-3QH20 or similar). If using the S7-1200 G2 with the integrated 2-port switch, the second port on the CPU can be used for a parallel HMI panel while still feeding the SCALANCE device.

6. Initial IP Configuration and Web Based Management

The default SCALANCE W is delivered with DHCP client enabled and an LLDP-friendly fallback address of 192.168.0.1 on VLAN 1. For deterministic commissioning, set static IPs on both devices.

  1. Connect a PG/PC directly to SCALANCE port P1 (use an M12-D-to-RJ45 adapter, e.g., 6GK1901-1BB10-2AA0).
  2. Set the PG/PC address to 192.168.0.10/24.
  3. Browse to https://192.168.0.1. The WBM login is admin / admin on first boot; you will be forced to change the password.
  4. Navigate to Layer 3 > Subnets, deactivate DHCP, and assign a static IP. Recommended scheme:
Device IP address Subnet PROFINET device name
SCALANCE W778-1 (AP) 192.168.1.11 255.255.255.0 iwlan-ap
SCALANCE W748-1 (Client) 192.168.1.12 255.255.255.0 iwlan-cl
S7-1200 CPU #1 192.168.1.1 255.255.255.0 cpu-1
S7-1200 CPU #2 192.168.1.2 255.255.255.0 cpu-2
  1. Set the system time under System > Time using SNTP, otherwise PROFINET device-name resolution and TLS handshakes will fail on reboot.
  2. Repeat the same procedure on the client SCALANCE W748-1.

7. iWLAN Parameter Configuration

On the AP (WLAN > iWLAN > AP tab):

Parameter Value
Country code Set to deployment country (drives allowed channel list)
Channel 36 (5180 MHz) or 100 (5500 MHz), DFS-aware
Channel bandwidth 20 MHz (iPCF only supports 20 MHz)
Mode iPCF (deterministic) or iPCF-MC if a moving client is added later
Max. number of clients 2 (one is the W748)
Tx power 17 dBm (adjust to satisfy regulatory EIRP)
SSID iWLAN-P2P
Security WPA2-Enterprise (802.1X) or WPA2-PSK with AES

On the client (WLAN > iWLAN > Client tab):

  • Set Operating mode to "Client" with iPCF client enabled.
  • Enter the AP MAC address in the Preferred AP field for fast roaming.
  • Enable Background scan at intervals of 30 s to detect link-quality degradation.

After saving, the WBM Information > WLAN > iWLAN page should show a green "iWLAN-Status: Connected" indicator and a measured round-trip time of 5–8 ms for 64-byte PROFINET frames.

8. TIA Portal Project Configuration

  1. Open the TIA Portal project containing both S7-1200 stations.
  2. In the project tree, install the SCALANCE W778/W748 HSP (Hardware Support Package) so the AP and client are recognized as catalog devices: Options > Support Packages > Install HSP.
  3. Add the SCALANCE W778-1 and W748-1 as IO devices under the same PROFINET subnet used by the CPUs. Assign device names iwlan-ap and iwlan-cl matching the WBM configuration.
  4. Right-click each SCALANCE device, choose Assign PROFINET device name, and confirm using the MAC address (printed on the device label). Use the Topology editor to map the wireless link as an "iWLAN" connection between the two SCALANCE ports; this allows the TIA Portal diagnostics to colour-code the wireless link separately from the wired PROFINET.
  5. Compile and download. Verify that both SCALANCE devices report "No fault" under Online > Diagnostics.

9. S7-1200 PROFINET Communication Setup

For simple S7 data exchange (e.g., a few bytes per cycle), the cleanest method is to add a PN/PN coupler on the PROFINET line and configure the S7-1200 CPUs to exchange IO data through it. The PN/PN coupler appears as an IO device on both PROFINET subnets, so PROFINET IO frames transit it transparently while keeping the S7-1200 G2 CPUs unaware of the wireless layer.

For larger payloads (kilobytes per cycle) or record-based S7 communication, use the standard S7 connection with PUT/GET instructions:

// CPU_1 - periodic send of a 100-byte data block to CPU_2
// Trigger: cyclic OB1
// Done in SCL
IF "send_trigger" THEN
  "req_put"(REQ := TRUE,
            ID   := W#16#1,           // connection ID from NetPro
            DONE => "put_done",
            BUSY => "put_busy",
            ERROR => "put_error",
            STATUS => "put_status");
  IF "put_done" OR "put_error" THEN
    "send_trigger" := FALSE;
    "req_put"(REQ := FALSE, ID := W#16#1);
  END_IF;
END_IF;

Recommended PROFINET update times when crossing the iWLAN link:

Application Recommended update time iPCF cycle
Standard I/O (digital in/out) 4 ms 4 ms
Drive telegrams (PROFIdrive 1) 4 ms 4 ms
S7 PUT/GET block transfer 32 ms or 64 ms Match to update time
PROFIsafe over iWLAN 8 ms 8 ms (special PROFIsafe profile required)
Watchdog settings: PROFINET IO uses three watchdogs (slot, device, and AR). With iWLAN, set the AR watchdog to at least 3 × the update time. With a 4 ms update time, configure a 12 ms AR watchdog; otherwise transient RF fades will be misinterpreted as a station failure.

10. Security Hardening

  • Disable all unused services on the SCALANCE W (Telnet, TFTP, HTTP). Use HTTPS only.
  • Replace the default admin/admin credentials on first boot.
  • Use WPA2-Enterprise (802.1X) with a RADIUS server if more than two SCALANCE devices share the same SSID. For a single AP/Client pair, WPA2-PSK with a 63-character random key is acceptable and is simpler to operate.
  • Place the iWLAN segment in a dedicated VLAN (e.g., VLAN 100). Block inter-VLAN routing at the plant firewall to limit the blast radius of a compromised radio.
  • Enable the SCALANCE W built-in firewall with default-deny inbound rules; allow only PROFINET-RT (UDP 34964), PROFINET-RT class 2/3, and ARP.
  • Activate SNMPv3 with read-only access for the SCALANCE device and a unique Engine ID, so that SINEC NMS or a network management system can poll link quality.

11. Verification, Diagnostics, and KPIs

After loading the project and assigning PROFINET device names, validate the link in this order:

  1. Layer 1/Layer 2 test: In the SCALANCE WBM, navigate to Information > WLAN > iWLAN. Verify RSSI > -70 dBm and an "iPCF-Status: Connected" entry.
  2. ICMP test: From CPU_1, issue a PING to CPU_2. Latency should be < 10 ms for 64-byte frames in iPCF mode, with no packet loss over 60 seconds.
  3. PROFINET diagnostic: In TIA Portal Online > Accessible devices, both CPUs should appear with a green check and live update time stamps.
  4. Cyclic IO test: Toggle a digital output on CPU_1 and read it back on CPU_2 using a PN/PN coupler. Confirm the round-trip latency using the system clock tags in each CPU.
  5. Long-term monitoring: Enable SCALANCE W Syslog forwarding to a central server. Watch for the messages iWLAN: link quality degraded and iWLAN: iPCF cycle violation — both indicate RF health issues that precede visible PROFINET errors.

Acceptance KPIs for a 200 m iWLAN link in PROFINET IO operation:

KPI Target Warning Fault
RSSI ≥ -65 dBm -65 to -75 dBm < -75 dBm
iPCF round-trip (64 B) ≤ 8 ms 8–12 ms > 12 ms
PROFINET CRC errors / hour 0 1–5 > 5
Connection uptime ≥ 99.9% 99.0–99.9% < 99.0%

12. Troubleshooting Matrix

Symptom Likely cause Diagnostic Corrective action
AP and Client never associate Channel mismatch, country code, antenna aim WBM Information > WLAN: "scan results" empty Verify same country code, set AP to a non-DFS channel, realign antennas within ±3°
Associates but PROFINET AR fails PROFINET device name not assigned TIA Portal Online > Accessible devices shows the SCALANCE in red Use Assign PROFINET device name with the correct MAC
PROFINET runs, intermittent IO faults Watchdog too tight, multipath, fade margin too low Increase AR watchdog to 3 × update time; check SCALANCE syslog for "iPCF cycle violation" Reduce update time to 8 ms, raise Tx power, or switch to 2.4 GHz
High latency, no errors iPCF disabled, falling back to CSMA/CA WBM Information > iWLAN: "iPCF status: off" Enable iPCF on both AP and Client, save and reboot
One-way communication only Asymmetric RSSI, half duplex on client antenna port Compare RSSI in WBM on both ends Replace coax pigtail with matched-length pair, verify antenna polarization alignment
WBM inaccessible after firmware update IP address changed or HTTPS reconfigured Ping default IP 192.168.0.1; ARP table Reset via the recessed "SET" button for 10 s, reconfigure
PROFIsafe diagnostics over iWLAN PROFIsafe profile mismatch CPU diagnostic buffer: "PROFIsafe parameter set invalid" Use the iWLAN-specific PROFIsafe profile from the TIA Portal library; do not use the default wired profile

Do I need PROFINET IO on the wireless link, or can I use S7 PUT/GET over standard TCP?

For pure data exchange (bytes, words, blocks) without hard real-time guarantees, S7 PUT/GET or TCON/TSEND/TRCV over the iWLAN link is sufficient and easier to configure. PROFINET IO is required only when you need deterministic update times (typically 1–8 ms), drives, or PROFIsafe. The iPCF mode of SCALANCE W still bounds latency for both, but PROFINET IO enforces the timing contract that iPCF provides.

Is Bluetooth a viable alternative for 200 m S7-1200 communication?

Yes, products such as the DATAEAGLE X-Treme (2.4 GHz Bluetooth with 869 MHz option) provide a transparent Ethernet bridge over 200–300 m line-of-sight and have been used to link S7 controllers, including S7-1200. The trade-off is throughput: typical net wireless throughput is 200–300 kbit/s, which is acceptable for S7 communication but inadequate for PROFINET IO with sub-10 ms update times or for any application with video or large file transfer.

Which channel bandwidth should I choose for a 200 m point-to-point link?

For iPCF operation, use 20 MHz channel width. iPCF does not support 40/80/160 MHz bonded channels because the timing engine relies on a fixed airtime per slot. The 20 MHz choice also improves link margin by approximately 3 dB compared to a 40 MHz channel at the same transmit power.

Can I daisy-chain a SCALANCE W off an S7-1200 G2 CPU using the integrated 2-port switch?

Yes. The S7-1200 G2 CPUs expose a built-in 2-port Ethernet switch on X1/X2 (or equivalent labelling on the G2 housing). Connect the SCALANCE W to one port and an HMI panel to the other, then configure both as PROFINET nodes on the same subnet. The CPU will switch frames between the two ports internally, eliminating the need for an external switch.

How do I migrate from a wired PROFINET to iWLAN without changing the S7-1200 program?

Insert a PN/PN coupler on each side of the wireless link, or use SCALANCE W in transparent bridge mode (default). Because the wireless link is a Layer-2 bridge, the S7-1200 application code is unaware that the path traverses RF. Only the PROFINET device name, IP address, and watchdog configuration need to be reviewed during commissioning; the user program in OB1 and elsewhere remains unchanged.

Back to blog