S7-1200 Remote Pumping Station: SCALANCE M876-4 VPN Setup

David Krause17 min read
S7-1200SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Remote pumping stations are typical industrial edge sites where a small Siemens S7-1200 PLC handles local pump control while a cellular router maintains an IPsec-secured VPN tunnel back to the central control room. This technical reference covers the complete commissioning path for a station built around the SIMATIC S7-1200 CPU 1212C DC/DC/Relay (MLFB 6ES7212-1HE40-0XB0), the SCALANCE M876-4 4G/LTE router, TIA Portal STEP 7 Basic V16, and the SINEMA Remote Connect virtual appliance. Each component is field-proven in unattended water and wastewater sites where only a cellular backhaul is available.

The architecture is deliberately compact. One PLC handles the discrete and analog I/O for pump run feedback, seal-leakage detection, wet-well level, and discharge pressure; the cellular router terminates a SINEMA Remote Connect (SINEMA RC) tunnel that the central engineering workstation can join without exposing the PLC directly to the public internet. The same channel carries TIA Portal project download, web-server pages, PUT/GET S7 communication, and remote firmware updates to the cellular router.

Three software entitlements are mandatory for this topology:

  1. A TIA Portal STEP 7 Basic license that authorizes the engineer to develop, compile, download, and commission the S7-1200 program. For V16 the floating download entitlement is 6ES7822-0AE06-0YA5.
  2. A SINEMA Remote Connect Server entitlement that runs the VPN concentrator in the central data center. For a 4-tunnel starter pack the entitlement is 6GK1720-1AH01-0BV0.
  3. Operator-side SINEMA RC Client software (free of charge) that allows individual engineering workstations to dial into the SINEMA RC server.

Bill of Materials and MLFB Decoding

Siemens part numbers encode the function, hardware variant, firmware, and packaging. Verify every digit against the official Siemens Industry Mall entry before ordering; a single letter often changes the I/O mix or the power-supply variant.

MLFB Description Role
6ES7212-1HE40-0XB0 S7-1200 CPU 1212C DC/DC/Relay, 150 KB work memory, 8 DI 24 V DC, 6 DO relay 2 A, 2 AI 0-10 V DC, 1 PROFINET port Station controller
6GK5876-4AA00-2BA2 SCALANCE M876-4 4G/LTE router, 1 WAN, 4 LAN, 2 SMA antenna ports, 2 SIM slots Cellular gateway and SINEMA RC client
6ES7822-0AE06-0YA5 SIMATIC STEP 7 Basic V16, floating license, software download Engineering software entitlement
6GK1720-1AH01-0BV0 SINEMA Remote Connect Virtual Appliance, Basic Package, 4 simultaneous VPN connections Central VPN concentrator entitlement
6ES7954-8LC03-0AA0 S7-1200 SIMATIC Memory Card, 4 MB Program and firmware storage (required for firmware update and CPU reset)
A used S7-1200 CPU 1212C is fully supported in new projects as long as the firmware version is at least V4.2 for TIA Portal V16. CPUs sold on the secondary market often ship with older firmware; plan an SD-card firmware update using a SIMATIC Memory Card and the TIA Portal "Online & Diagnostics" function before commissioning.

S7-1200 CPU 1212C Hardware Specifications

The 6ES7212-1HE40-0XB0 is the DC/DC/Relay variant of the CPU 1212C. The MLFB breaks down as 6ES7 212-1 HE 40-0XB0:

  • 212: CPU 1212C family (versus 211, 214, 215, 216 for the larger siblings).
  • 1: Single PROFINET interface on the bottom of the CPU body.
  • HE: DC/DC/Relay — 24 V DC power supply, 24 V DC digital inputs, relay outputs.
  • 40: Hardware functional state of the PCB; later codes denote newer revisions.
  • 0XB0: Packaging and documentation set.

Key specifications for this variant (verify against the latest datasheet at order time):

Parameter Value
Work memory (code + data) 150 KB
Load memory (internal) 4 MB
Retentive memory 14 KB
Bit memory (M) 8192 bytes (M0.0 through M1023.7)
Digital inputs 8 × 24 V DC, 4 of them usable as HSC up to 100 kHz
Digital outputs 6 × relay, 2 A, 250 V AC / 30 V DC max
Analog inputs 2 × 0-10 V DC, 10-bit resolution
PROFINET interface 1 × RJ45, 10/100 Mbps
Cycle time (bit operation) 0.085 µs
Counter / timer count Up to 1024 each
Web server Yes, with user-defined pages
Power supply 20.4 to 28.8 V DC, 1.5 A max
Operating temperature -20 to +60 °C horizontal mount
Real-time clock Yes, buffered by capacitor ~20 days typical

For full hardware details consult the official S7-1200 Programmable Controller System Manual and the S7-1200 entry on the Siemens Industry Mall catalog page.

SCALANCE M876-4 Cellular Router Specifications

The SCALANCE M876-4 is a 4G/LTE cellular router in the SCALANCE M family. It is intended for unattended outdoor and industrial cabinets, with an extended temperature range and ruggedized housing. Confirm the regional variant against the cellular bands licensed by the local carrier — for Canadian deployments choose a variant that includes B4 (AWS) and B12/B13 (lower 700 MHz) to cover Rogers, Bell, and Telus LTE deployments.

Parameter Value
Mobile network 4G/LTE (FDD and TDD), 3G/UMTS fallback, 2G/GSM fallback on selected variants
SIM slots 2 × Mini-SIM for redundancy or dual-carrier failover
Antenna connectors 2 × SMA female (MAIN + AUX) for LTE MIMO 2x2
WAN interface 1 × RJ45 10/100/1000 Mbps
LAN interfaces 4 × RJ45 10/100 Mbps
VPN support IPsec, OpenVPN, SINEMA Remote Connect client
Firewall Stateful inspection, MAC filter, NAT/NATP, 1:1 NAT
Power supply 9.6 to 28.8 V DC, max 7 W typical
Operating temperature -40 to +75 °C
Housing / IP DIN-rail mount, IP30
Configuration Web Based Management (WBM), CLI, TIA Portal HSP, SINEC NMS
The MLFB suffix -2BA2 designates a specific frequency band set. For North American deployments, order the matching North America variant that carries the AWS and lower-700 MHz bands used by Canadian operators. Verify the suffix on the Siemens Industry Mall page for the M876-4 before placing the order.

TIA Portal V16 — STEP 7 Basic Licensing

STEP 7 Basic V16 was released as part of the TIA Portal V16 update package in December 2020. It supports the S7-1200 family from firmware V4.2 onward and the S7-1500 family up to firmware V2.9. For projects that mix S7-1200 and S7-1500, upgrade to STEP 7 Professional. For a stand-alone S7-1200 station, STEP 7 Basic is the correct and most economical choice.

MLFB Description Notes
6ES7822-0AE06-0YA5 SIMATIC STEP 7 Basic V16, Floating License, software download (incl. license key download) License key delivered via OSD (Online Software Delivery) email
6ES7822-0AE06-0YG5 Same entitlement, Floating License, software + documentation on DVD Choose only if DVD media is required
6ES7822-1AA06-0YA5 STEP 7 Basic V16 trial, 21-day rental Cannot be activated as full license

A floating license means the license key can be assigned to any one engineering workstation at a time but can be moved to another workstation by returning it to the Automation License Manager (ALM). For teams that share a license, deploy the Automation License Server (a service that runs on a server-class machine and hands out licenses on demand).

Activation procedure (for the floating download entitlement):

  1. Install TIA Portal V16 from the Siemens Online Software Delivery (OSD) portal download.
  2. Open the Automation License Manager.
  3. Click Activate License and select Activate Floating License.
  4. Enter the License Key (a 20-character alphanumeric string supplied by Siemens by email once the OSD download is acknowledged).
  5. The license is now bound to that PC. To move it, right-click the license and choose Return Floating License on the source machine, then re-activate on the destination machine.

For larger engineering teams, install the Automation License Server (a separate Siemens download) on a Windows Server and use the ALM to borrow/return floating licenses. The server itself needs a license-key file generated from the purchased MLFB.

TIA Portal V16 remains usable on Windows 10 / Windows Server 2016/2019, but newer CPUs and HMIs that ship after 2023 may require TIA Portal V17 or later for project compatibility. Plan a portal upgrade path before deploying new devices at this station. New S7-1200 G2 hardware is documented on the SIMATIC S7-1200 G2 product page.

SINEMA Remote Connect Licensing

SINEMA Remote Connect is the Siemens VPN concentrator that terminates the tunnel initiated by the SCALANCE M876-4 and any SINEMA RC client. It is delivered as a virtual appliance (.ova for VMware ESXi and .vhd for Microsoft Hyper-V) and runs on a server in the central data center.

MLFB Description Capacity
6GK1720-1AH01-0BV0 SINEMA Remote Connect Virtual Appliance Basic Package 4 simultaneous VPN connections (tunnels)
Upgrade entitlements SINEMA RC tunnel capacity upgrades Contact Siemens Canada or an authorized distributor for current upgrade MLFBs and pricing

The Basic Package entitlement is suitable for a single pumping station with one SCALANCE M876-4 tunnel plus one or two engineering clients. Each tunnel consumes one connection credit regardless of the underlying device; SINEMA RC Client connections from engineers count the same as router-to-router tunnels. When the pool of four is exhausted, additional tunnel upgrade entitlements can be purchased and applied to the same appliance without redeploying the VM.

Procurement in Canada

Siemens sells its Canadian automation catalog through a mix of direct and authorized-distributor channels. For TIA Portal, SINEMA RC, and SCALANCE hardware the most common legitimate channels are:

  • Siemens Canada direct sales: The national office in Oakville, Ontario serves as the entry point for direct commercial offers, framework agreements, and project pricing. Contact details are listed on the Siemens Canada site and the Siemens Distributor Locator.
  • Authorized industrial automation distributors: Electrical wholesale houses that carry Siemens automation typically stock STEP 7 licenses, SCALANCE routers, and S7-1200 spare parts. They can also broker SINEMA RC entitlements.
  • Siemens Industry Mall: Online portal at mall.industry.siemens.com for direct purchase of software downloads (TIA Portal, SINEMA RC) and configured hardware MLFBs that are shipped from regional hubs.
When buying a used S7-1200 CPU, confirm the firmware version on the side label (it is printed as V + number, e.g. V4.4) and that the CPU does not show the ERROR LED at power-up. A used CPU can be returned to factory defaults by inserting an empty SIMATIC Memory Card and powering on — the CPU will then format itself and reload firmware from the card.

Network Architecture and IP Plan

The recommended topology is hub-and-spoke: one SINEMA RC server in the data center, one M876-4 router at each remote station, and any number of SINEMA RC clients on the engineering workstations.

Address plan example for one station:

Device Interface IP address Subnet
SINEMA RC Server LAN (eth0) 10.50.0.10 255.255.255.0
Engineering client #1 LAN 10.50.0.50 255.255.255.0
SCALANCE M876-4 (pumping station 1) WAN (public LTE) DHCP from carrier
SCALANCE M876-4 (pumping station 1) LAN (station network) 192.168.10.1 255.255.255.0
S7-1200 CPU 1212C PROFINET 192.168.10.10 255.255.255.0
HMI Comfort Panel (if used) PROFINET 192.168.10.20 255.255.255.0
Level transducer Analog output 4-20 mA to AI n/a n/a

All cellular-facing devices receive their WAN IP from the LTE carrier. The SINEMA RC server should be reachable from the public internet on UDP 500 and UDP 4500 (for IPsec NAT-traversal) and TCP 443 (for SINEMA RC client connections over TLS).

For multiple stations, increment the third octet on the station network: station 1 = 192.168.10.0/24, station 2 = 192.168.11.0/24, and so on. Avoid overlapping the LAN of the data center.

SCALANCE M876-4 Configuration

The M876-4 is configured through its Web Based Management (WBM) at https://192.168.1.1 on initial commissioning. Change the LAN IP to match the station plan before connecting it to the field network.

Required configuration steps:

  1. Connect a PC to the LAN port of the M876-4, set the PC to DHCP, browse to https://192.168.1.1, log in with admin / admin.
  2. Navigate to System > General, set the device name (e.g. PUMP01-M876), set the time zone, and configure NTP (pool.ntp.org or a local NTP source).
  3. Under Interfaces > WAN, select Mobile as the connection type, enter the APN supplied by the carrier (Bell, Rogers, and Telus typically use inet.bell.ca, internet.com, or isp.telus.com; confirm with the issued SIM card kit), and set the authentication credentials if required.
  4. Install both antenna leads to the SMA MAIN/AUX connectors and torque to 0.6 N·m to maintain the IP rating of the antenna bulkhead.
  5. Under Security > SINEMA RC, enable the SINEMA RC client, enter the FQDN or public IP of the SINEMA RC server, and paste the device-specific pre-shared key generated by the SINEMA RC server during device enrollment.
  6. Under Layer 3 > Firewall, create an inbound rule that allows IPsec IKE/ESP from the SINEMA RC server IP and a corresponding outbound rule for return traffic. Block all other inbound WAN traffic.
  7. Under Layer 3 > Static Routes, add a route to 10.50.0.0/24 with the SINEMA RC tunnel as the next-hop interface. The M876-4 sets this automatically once the SINEMA RC tunnel is up.

Test the cellular link by navigating to Information > Mobile and confirming that the SIM registers on the carrier (signal RSSI > -100 dBm is the minimum acceptable, RSRP > -110 dBm for LTE). A poor signal is the single biggest source of remote-site VPN instability — add an external MIMO antenna on the cabinet roof if the indoor RSSI is borderline.

SINEMA Remote Connect Server Configuration

The SINEMA RC Virtual Appliance is deployed on VMware ESXi or Microsoft Hyper-V. Minimum host requirements:

  • 2 vCPU, 4 GB RAM, 40 GB disk
  • 1 NIC bridged to the corporate LAN
  • Static IP address (e.g. 10.50.0.10)
  • DNS A-record pointing to sinema-rc.example.com

Initial setup procedure:

  1. Import the .ova (or .vhd) into the hypervisor, set the management IP, and power on.
  2. Browse to https://<sinema-rc-ip>, accept the self-signed certificate, and log in with admin / admin.
  3. Change the default password and upload the license key supplied with the Basic Package entitlement. The license count increments in the Licensing panel.
  4. Under User Accounts, create one account per engineering workstation. Generate a one-time password that the user changes at first login.
  5. Under Devices > Routers, create a device entry for the M876-4. The server generates a device-specific PSK; copy that PSK into the M876-4 SINEMA RC client configuration.
  6. Under Remote Connections > Connection Groups, create a group named Pumping Stations with the participating devices and user accounts. Save.

Once the configuration is saved, the SINEMA RC server sits and waits for inbound IPsec connections. To verify, watch the Connections panel as the M876-4 attempts its first dial-in.

S7-1200 Program Development

Open TIA Portal V16 and create a new project for the S7-1200 station.

  1. In Project Tree, add a new device S7-1200 > CPU 1212C DC/DC/Relay > 6ES7212-1HE40-0XB0 with firmware V4.4 (or higher, depending on what the CPU ships with).
  2. Open Device Configuration > PROFINET Interface, set the IP address to 192.168.10.10, subnet 255.255.255.0, and the router address to 192.168.10.1 (the M876-4 LAN IP).
  3. Open Device Configuration > Web Server, enable the web server, and tick Enable user-defined web pages.
  4. Under PLC Tags, create the following standard tag table for a pumping station:
Tag Type Address Comment
i_StartCmd Bool %I0.0 Remote start command from central
i_StopCmd Bool %I0.1 Remote stop command from central
i_Pump1Run Bool %I0.2 Pump 1 run feedback contact
i_Pump2Run Bool %I0.3 Pump 2 run feedback contact
i_SealLeak Bool %I0.4 Seal leakage sensor
i_HighLevel Bool %I0.5 High level float switch
i_LowLevel Bool %I0.6 Low level float switch
i_AutoMode Bool %I0.7 Auto / Manual selector
i_LevelAI Int %IW64 Wet-well level 0-10 V (0-100% scaled)
o_Pump1Run Bool %Q0.0 Pump 1 contactor
o_Pump2Run Bool %Q0.1 Pump 2 contactor
o_AlarmHorn Bool %Q0.2 Alarm horn
o_RunLight Bool %Q0.3 Cabinet run indicator
  1. Create an FC100 "Pump_Alternation" function block that implements duty rotation between the two pumps based on number of starts and elapsed run time. Use IEC timers (TP, TON) and counters (CTU) from the standard instruction library.
  2. Create an FC110 "Level_Control" that scales the AIW64 raw value (0-27648) to engineering units (0-100%) using the SCALE block from the "Convert" library.
  3. Build the OB1 cycle with the standard pattern: read inputs, evaluate alarms, run pump logic, write outputs.
  4. Configure a Watch Table with the most important tags and a Force Table for commissioning.
  5. Compile, download to the CPU over the VPN tunnel, and verify the green RUN LED.

Example ladder snippet for pump 1 run logic:


// Network 1: Auto run
A    "i_AutoMode"
A    "i_StartCmd"
AN   "i_StopCmd"
AN   "i_SealLeak"
=    "o_Pump1Run"

// Network 2: Manual run
AN   "i_AutoMode"
A    "i_StartCmd"
AN   "i_StopCmd"
=    "o_Pump1Run"

// Network 3: Seal-leak interlock (drops both pumps on alarm)
A    "i_SealLeak"
R    "o_Pump1Run"
R    "o_Pump2Run"
S    "o_AlarmHorn"

For project setup details refer to the Introducing the S7-1200 PLC chapter in the S7-1200 manual collection.

Commissioning Procedure

Commission in five stages, each gated by a sign-off:

  1. Bench test (off-site). Wire the CPU, M876-4, and a 24 V DC power supply on the bench. Update the CPU firmware via SD card to V4.4 or newer. Verify that the CPU reaches RUN, the M876-4 establishes the SINEMA RC tunnel, and that TIA Portal can download a project. Validate the pump logic with simulated inputs.
  2. Site installation. Mount the CPU and M876-4 in the cabinet, land the antenna cables outside, fit the SIM card, and apply 24 V DC. Power up.
  3. Cellular verification. From the M876-4 WBM, check the RSSI, RSRP, RSRQ, and SINR. Target: RSRP > -100 dBm, SINR > 5 dB. If the values are marginal, swap the antenna for a higher-gain MIMO external model.
  4. VPN tunnel test. From the central engineering workstation, launch the SINEMA RC client, connect to the server, and verify that the M876-4 endpoint shows online. Ping the PROFINET IP of the S7-1200 from the engineering workstation over the tunnel. A successful ping confirms routing and NAT-traversal.
  5. I/O loop check. With the pumps locked out, force each output individually and verify the contactor pulls in. Run each pump in manual mode for 10 seconds and verify the run feedback reaches the CPU.

Verification and Diagnostics

After the commissioning sign-off, the following diagnostics should be wired into the central SCADA or monitoring dashboard so remote faults are visible without dispatching a technician:

  • CPU diagnostic buffer download over the VPN tunnel (TIA Portal > Online > Diagnostics > Diagnostic Buffer). Look for Communication error events with error codes such as 0x02 0x03 (IP connection failed).
  • M876-4 event log via WBM or via the SINEC NMS server. Filter on VPN, Mobile, and Firewall events.
  • S7-1200 web server user-defined page showing current pump run state, level percentage, and runtime hours for each pump.
  • Cellular signal strength logged hourly into a data block and pushed to the central SCADA via S7 PUT/GET on the PROFINET interface.

Troubleshooting Matrix

Symptom Likely Cause Diagnostic Corrective Action
CPU MAINT LED flashes yellow Firmware mismatch or SD card error TIA Portal > Online > Diagnostics Insert SD card with correct firmware; perform firmware update
CPU ERROR LED steady red Programming error or hardware fault Diagnostic buffer Clear program; check for I/O wiring faults
M876-4 SINEMA RC tunnel down Wrong PSK, public IP changed, APN wrong M876-4 WBM > Information > SINEMA RC Re-enroll device; verify APN with carrier
M876-4 shows low RSSI Antenna location or cable length Information > Mobile Fit external MIMO antenna on roof
TIA Portal download fails over VPN Firewall blocks TIA ports (TCP 102) M876-4 WBM > Firewall log Allow TCP 102 between tunnel endpoints
SINEMA RC server shows "License exceeded" More than 4 simultaneous tunnels SINEMA RC > Licensing Purchase a tunnel capacity upgrade entitlement
Web server shows old data User-defined page not refreshed Browser cache Disable cache; reduce refresh interval in HTML
Pump does not start in Auto Seal-leak input active or stop latched Watch table force Inspect seal sensor; reset stop latch
AIW64 reads 32767 (overflow) Sensor input out of range Watch table Check transducer scaling; verify 24 V DC loop supply
TIA Portal V16 cannot open project on new PC License not activated Automation License Manager Activate floating license on new PC

Frequently Asked Questions

Can a used S7-1200 CPU 1212C be commissioned with TIA Portal V16?

Yes, as long as the firmware is V4.2 or later. Update firmware via SIMATIC Memory Card before connecting to TIA Portal V16 to avoid "online: not reachable" errors. Used CPUs can be returned to factory defaults by inserting an empty SD card at power-up.

Is STEP 7 Basic V16 enough for a stand-alone S7-1200 pumping station?

Yes. STEP 7 Basic V16 supports the full S7-1200 family and is the lowest-cost license tier. Upgrade to STEP 7 Professional only if the project also includes S7-1500 CPUs, S7-1500 motion, or PLC simulation.

How many VPN tunnels does the SINEMA Remote Connect Basic Package support?

The 6GK1720-1AH01-0BV0 entitlement covers 4 simultaneous VPN tunnels. Each SCALANCE M876-4 at a remote site consumes one tunnel; each SINEMA RC client on an engineering workstation consumes one tunnel. Tunnel capacity upgrade entitlements are available from Siemens Canada or an authorized distributor to raise the limit on the same virtual appliance.

Which SCALANCE M876-4 variant works in Canada?

Order the North America band variant whose MLFB suffix covers AWS-1 (Band 4) and 700 MHz (Bands 12/13/17) for Rogers, Bell, and Telus LTE. Confirm the exact MLFB suffix on the Siemens Industry Mall product page for the M876-4 before placing the order.

Can I move my TIA Portal V16 floating license between laptops?

Yes. Open Automation License Manager on the source PC, right-click the V16 license, and choose "Return Floating License". Activate the same license on the destination PC within the Siemens License Server visibility window. The license key itself can be re-used on any number of PCs as long as only one PC holds it at a time.

What minimum cellular signal is acceptable for the M876-4 in pumping-station service?

Target RSSI above -90 dBm and RSRP above -100 dBm with SINR above 5 dB. Below those thresholds the SINEMA RC tunnel becomes unstable and the engineering channel will drop intermittently. Add an external MIMO antenna if the indoor signal is borderline.

Specifications, firmware versions, and licensing terms are subject to change. Always confirm against the latest Siemens Industry Online Support entries, the S7-1200 system manual at S7-1200 System Manual, the S7-1200 G2 product page, and the S7-1200 manual collection.
Back to blog