1. Overview
The S7-300 platform is built around a modular backplane that mechanically and electrically links the CPU, signal modules (SM), communication processors (CP), function modules (FM), and interface modules (IM) on a single mounting rail. The backplane is not a passive PCB inside the rail; it is implemented through pre-installed U-shaped bus connectors on the rear of every module that mate with the adjacent module as the installer slides the next device into position and tightens its single bottom fixing screw.
This reference covers three common field tasks on the S7-300:
- Mechanically mounting (or dismounting) a CPU 314 or CPU 315, a CP 341, two digital input (DI) modules, and two digital output (DO) modules on a single S7-300 rail.
- Replacing an in-service CPU 314 with a CPU 315 in the same HW Config project to recover from a "memory full on download" condition.
- Preserving the user program, hardware configuration, and symbolic table during the swap.
The procedure applies to STEP 7 V5.5 / V5.6 with the optional S7-PCT or TIA Portal migration path, and is consistent with the official SIMATIC S7-300 CPU 31xC and CPU 31x: Installation manual and the S7-300 Automation System / Module Specifications reference.
2. Prerequisites
2.1 Hardware
- S7-300 mounting rail (6ES7390-1AJ30-0AA0 = 530 mm, 6ES7390-1BC00-0AA0 = 830 mm, or 6ES7390-1AE80-0AA0 = 2000 mm). Cut to length with a hacksaw and de-burr the cut end.
- CPU 315 module (e.g. 6ES7315-1AH14-0AB0 for CPU 315-2 DP, or 6ES7315-2EH14-0AB0 for CPU 315-2 PN/DP). Confirm the firmware (FW) version with STEP 7 HW catalog; firmware upgrades use the SIMATIC MMC and a Siemens Field PG or memory card programmer.
- MMC sized for the new CPU's load memory. CPU 315 typically requires a 4 MB MMC minimum (6ES7953-8LM20-0AA0). The program size grows when system data is regenerated.
- One PS 305/307 power supply sized for the sum of the module backplane currents (see Section 9).
- Spare bus connectors if any are missing or damaged: 6ES7390-0AA00-0AA0 (each module ships with one; CPUs and IMs ship with two).
- Flat-blade screwdriver 1.0 x 5.5 mm for module screws, 0.6 x 3.5 mm for the front connector cages.
2.2 Software
- STEP 7 V5.5 SP4 or later, or V5.6 with the matching HW Config update. Confirm the HW catalog entry of the new CPU is installed; otherwise run HW Config catalog update from the support site.
- STEP 7 online interface drivers: PC-Adapter USB (6ES7972-0CB20-0XA0) or CP 5711 / CP 5512 for MPI/ PROFIBUS.
- The current STEP 7 project archive (.zip) and a signed-off PLC program listing.
2.3 Safety and Site Preparation
- Bring the process to a safe state. CPU swaps in a running system will cause an OB 100 (restart) or warm restart.
- Open the line disconnector or pull the PS 307 circuit breaker. Verify zero potential on the 24 V backplane and field-side terminals with a calibrated DMM.
- Document the wiring of the front connectors with a label printer or photograph each connector; CPU 315 and CPU 314 share the same front connector pinout for the MPI/DP port, but the secondary interface differs (PROFIBUS DP on CPU 315-2 DP, PROFINET on CPU 315-2 PN/DP).
- Export the PLC to the PG (PLC → Upload Station to PG) as a fallback even if you have the source archive.
3. S7-300 Rail Layout and Slot Numbering
The S7-300 rack is divided into numbered slots. The slot count is fixed regardless of physical module size and is required by HW Config.
| Slot | Module (typical S7-300 single-rack configuration) |
|---|---|
| 1 | Power supply (PS 305/307). Slot 1 may be left empty if 24 V DC is fed directly and the PS is omitted (only permitted in some configurations; refer to the manual). |
| 2 | CPU (314 or 315). Always the first logical module after the PS. |
| 3 | IM 360/361 (only if a second rack is connected, e.g. ER 161/162). |
| 3-8 (single rack) or 4-11 (expansion rack) | Signal modules, CPs, FMs in any order. The first four slots of the expansion rack (4-7) have an address limit that depends on the CPU; see Section 6. |
Slot addresses are physical and they determine the default I/O address area. The user can override the I address (inputs) and Q address (outputs) start in HW Config; keep them consistent with the existing wiring to avoid an OB 85 "I/O access error" at startup.
4. Mechanical Mounting of CPU, CP 341, DI, DO Modules
4.1 Rail Preparation
- Mount the rail horizontally on a flat, vibration-free surface with the grounding screw at the bottom-left when the cabinet door is on the right (DIN 43835 reference).
- Torque each rail fixing screw to 2.5 Nm on M5 or 1.2 Nm on M4 hardware to ensure a low-impedance PE bond.
- Connect the rail's protective earth (PE) to the cabinet's PE bar with a 4 mm² green/yellow conductor. S7-300 modules rely on the rail for chassis ground via the spring contacts on the bus connector shroud.
4.2 Module Installation Order
Install from left to right. The CPU is always the second physical device on the rail. To install a module:
- Hang the module on the rail's upper edge. The metal clamp on the rear of the housing seats on the top of the rail.
- Rotate the module downward until the bus connector at the rear of the previous module is fully inserted into the rear of the new module. A short mechanical detent indicates correct engagement.
- Tighten the bottom fixing screw to 0.8-1.1 Nm. This action also locks the bus connector in place; never carry the rail with the modules loose.
- Verify the bus connector on the CPU and on the last SM: the U-shaped sliding piece at the bottom rear of every module must be pushed into the module's housing when the module is the rightmost device. If the connector sticks out after mounting, it will short the backplane.
4.3 Removing a Module
- Loosen the bottom screw two full turns.
- Push the release lever at the front underside upward with a flat-blade screwdriver. The module will swing out from the rail.
- Lift the module off the rail.
- Immediately slide the next module to the left until the bus connector is fully mated, then re-tighten its screw. Never leave a gap on the rail without a module or a blank cover (6ES7390-0AA00-0AA0) for longer than a few minutes; the bus connector on the exposed module will be damaged if the rail is tilted.
4.4 Backplane Bus Connector Reference
| Module position | Bus connectors supplied on rear | Comment |
|---|---|---|
| CPU, IM | 2 | One is left for the module on the right; one is the spare. |
| SM, CP, FM, PS | 1 | Single connection to the module on the right. |
| Right-most module | 0 (push connector fully in) | Terminates the backplane. |
5. Wiring the PS, CPU, CP 341, DI, DO
5.1 Power Supply Sizing
The S7-300 backplane is fed by the PS through a fixed connector that also passes 24 V DC to the module electronics. Use the rated backplane currents from the module data sheets:
| Module | Typical order number | Backplane current (5 V) | Backplane current (24 V) |
|---|---|---|---|
| CPU 314 (e.g. 6ES7314-1AG14-0AB0) | Refer to catalog | ~ 1.0 A | ~ 0.2 A (sensors, no load) |
| CPU 315-2 DP (e.g. 6ES7315-1AH14-0AB0) | Refer to catalog | ~ 1.2 A | ~ 0.3 A |
| CP 341 (e.g. 6ES7341-1AH02-0AE0) | Refer to catalog | ~ 0.2 A | ~ 0.04 A |
| SM 321 DI 16x24 V DC (6ES7321-1BH02-0AA0) | Refer to catalog | ~ 0.03 A | ~ 0.07 A (sensor supply) |
| SM 322 DO 16x24 V DC / 0.5 A (6ES7322-1BH01-0AA0) | Refer to catalog | ~ 0.08 A | ~ 0.08 A (load supply, no load current) |
Sum the 5 V backplane currents and compare to the PS 307 rated output (5 V / 5 A for 6ES7307-1EA01-0AA0; 5 V / 10 A for 6ES7307-1KA02-0AA0). Sum the 24 V sensor / load currents to size the 24 V branch circuit; S7-300 PS modules have a separate 24 V output current rating of 2 A or 5 A depending on the variant.
5.2 Front Connectors and Wiring
Each SM, the CP 341, and the CPU use 20-pin front connectors (6ES7392-1AJ00-0AA0 for screw-type, 6ES7392-1BJ00-0AA0 for spring-loaded). Wire assignments for the relevant modules:
SM 321 DI 16x24 V DC (front connector X10)
- Pins 1-16: I0.0 to I1.7 (slot-dependent address prefix)
- Pin 17: 24 V sensor supply, jumpered internally to pin 20
- Pin 18: 24 V sensor supply
- Pin 19: 24 V sensor supply
- Pin 20: 24 V sensor supply (typ. terminal 1L+)
SM 322 DO 16x24 V DC (front connector X11)
- Pins 1-16: Q0.0 to Q1.7 (slot-dependent address prefix)
- Pins 17-19: 24 V load (1L+, jumpered)
- Pin 20: 0 V load (1M)
CP 341 Front Connector (X27, sub-D 9-pin female)
- Pin 2: TxD (RS-232C variant), or T(A) on RS-422/485
- Pin 3: RxD (RS-232C), or R(A) on RS-422/485
- Pin 4: RTS / T(B)
- Pin 5: GND
- Pin 6: +5 V (only on TTY variant)
- Pin 7: +24 V (only on TTY variant)
- Pins 8-9: R(B), shield ground
Shield continuity is critical for RS-485 networks terminating at field devices. Use a sub-D metal hood with a 360° shield clamp (e.g. Siemens 6ES5792-2BA00-0AA0) and tie the shield to cabinet PE at the entry point only.
5.3 First Power-Up Checks (CPU 314 or 315)
- Apply 24 V DC only to the PS. Measure 5 V on the backplane at a spare module test point (any backplane connector pin 2 = 5 V, pin 1 = GND on the diagnostic interface).
- Insert the MMC (if used) and switch the CPU selector to MRES briefly to verify it boots.
- Watch the LED sequence:
SF(red) off,BF(red) off,DC5V(green) on,RUN(green) flashing at 2 Hz,STOP(yellow) on steady. The flashing RUN with steady STOP indicates "module startup" pending configuration.
6. CPU 314 vs CPU 315 Functional Comparison
Confirm the migration target before ordering hardware. The functional differences between the two CPU classes relevant to a "memory full" swap are summarized below; refer to the latest S7-300 module data reference for the production build of each order number.
| Characteristic | CPU 314 (6ES7314-1AG14-0AB0) | CPU 315 (6ES7315-1AH14-0AB0) | CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) |
|---|---|---|---|
| Work memory (code + data) | 128 KB | 256 KB | 384 KB |
| Load memory (MMC) | 8 MB max | 8 MB max | 8 MB max |
| Bit memory (M) | 2048 byte | 4096 byte | 4096 byte |
| Counters (C) | 256 | 256 | 256 |
| Timers (T) | 256 | 256 | 256 |
| Digital I/O max (central + distributed) | 1024 / 1024 | 1024 / 1024 | 1024 / 1024 |
| OBs supported | OB 1, 10, 20, 35, 40, 80, 82, 85, 86, 100, 121, 122 | Adds OB 35 (already in 314), more priority classes | Same as 315, plus F-programming OBs if F-library is licensed |
| FB / FC / DB max | FB: 128, FC: 128, DB: 127 | FB: 192, FC: 192, DB: 255 | FB: 256, FC: 256, DB: 511 |
| Communication connections (max) | 12 | 16 | 16 (plus integrated PN: 16 more) |
| Integrated interfaces | 1 x MPI (187.5 kbps) | 1 x MPI/DP switchable, 1 x DP | 1 x MPI/DP, 1 x PROFINET (2-port switch) |
| Bit operations, typical execution | 0.06 µs | 0.05 µs | 0.05 µs |
| Number of racks / max modules | 4 / 32 | 4 / 32 | 4 / 32 |
The work memory jump from 128 KB to 256 KB (CPU 315) is the main justification for the swap when a download fails with diagnostic buffer entry "No memory available for user program" (event ID 0x13F0 / 0x13F1 in the diagnostic buffer).
7. Replacing the CPU 314 with CPU 315 in HW Config
7.1 Replace-Object Method (recommended)
- Open the STEP 7 project on the PG. Open the SIMATIC 300 Station and double-click Hardware.
- Right-click the CPU 314 icon in the station window. Choose Replace Object → CPU 31x → select the target CPU 315 (and FW version).
- STEP 7 will prompt: "The system data will be recompiled; user program is preserved." Click OK.
- Verify the address area is identical (default: I 0.0..127.7, Q 0.0..127.7). If the existing program reads M 2000.0 and the new CPU only has 2048 bytes of M (MB 0..MB 2047), the move works as-is.
- Click Station → Save and Compile (Ctrl+S). The new system data blocks (SDB) are written into the offline project.
7.2 Delete-and-Insert Method (use when replace-object is greyed out)
- Right-click the CPU 314 and choose Delete. Do not choose "Delete and remove from project" for the sub-elements; the user program (S7 Program → Blocks) must remain intact.
- Drag the new CPU 315 from the catalog (right pane, SIMATIC 300 → CPU 31x) into Slot 2.
- STEP 7 will recreate the system data. The user program, symbol table, and source files remain in S7 Program → Blocks, Symbols, and Sources untouched.
- Re-enter any CPU properties that were set on the old CPU: MPI address (default 2), PROFIBUS address (default 2), protection level, OB 1 cycle time, OB 35 interval, time-of-day interrupt settings, etc. STEP 7 does not copy these from the deleted object.
- Save and compile.
7.3 Download to the New CPU
- Connect the PC Adapter to the MPI port of the CPU 315. Set the adapter to MPI / 187.5 kbps / PC USB.
- In HW Config, click PLC → Download to Target CPU (or right-click the CPU and choose PLC → Download). Confirm the target CPU's order number and FW version in the dialog.
- When prompted "Stop the CPU?" choose Yes. The CPU will go from RUN to STOP and remain there during download.
- After successful download, switch the mode selector to RUN. The CPU executes OB 100 (restart) and the cycle begins.
8. CP 341 and DI/DO Module Reuse
8.1 CP 341 Configuration
The CP 341 (e.g. 6ES7341-1AH02-0AE0) keeps its slot address when the CPU changes. Configuration lives in the CP 341 object: right-click → Object Properties. After the CPU swap:
- Re-open the CP 341 dialog. Verify the protocol is still set to ASCII, 3964(R), or Modbus master/slave as required.
- Recompile and re-download the CP 341's protocol data. The CP has its own MMC slot and stores the protocol configuration; an MRES on the CPU does not clear it.
- If the CP was already configured and the wiring is intact, no further action is required. The CP starts in standalone mode once the CPU powers up the backplane.
8.2 DI/DO Module Address Mapping
Signal module addresses follow the slot position:
| Slot | Module (example) | Default input byte range | Default output byte range |
|---|---|---|---|
| 4 | SM 321 DI 16x24 V DC | IB 0 - IB 1 | - |
| 5 | SM 321 DI 16x24 V DC | IB 2 - IB 3 | - |
| 6 | SM 322 DO 16x24 V DC | - | QB 0 - QB 1 |
| 7 | SM 322 DO 16x24 V DC | - | QB 2 - QB 3 |
| 8 | (empty / spare) | - | - |
If the user program addresses I 0.0..I 3.7 and Q 0.0..Q 3.7, the address plan is preserved. If the program uses symbolic names only, the symbol table entries are unaffected by the CPU swap and the wiring remains valid.
9. Commissioning and Verification
9.1 Pre-Power Checklist
- All module screws torqued to 0.8-1.1 Nm.
- Bus connectors flush with the housing on the right-most module.
- PS output voltage 24 V DC ± 5% on the backplane test points.
- Front connectors seated, latch levers closed.
- Shield clamps tightened, shields bonded to PE at the cabinet entry only.
9.2 First Power-Up Procedure
- Energize the PS. Watch the CPU LED sequence: STOP (yellow) on, DC5V (green) on, SF/BF off.
- After 5-10 s the CPU performs a self-test and reads MMC. STOP remains on if no program is present.
- Use a PG to connect over MPI. In STEP 7 choose PLC → Accessible Nodes; the new CPU appears with its MPI address (default 2).
- Download the HW Config and program as described in Section 7.3.
- Switch selector to RUN. The RUN LED should be on steady and STOP off within 1-2 OB 1 cycles.
- Check PLC → Diagnostic Buffer for startup events. A clean restart lists OB 100 followed by OB 1. Any OB 85 / OB 86 / OB 122 entries indicate a wiring, address, or module mismatch.
- Force each DI bit from the field (e.g. close the limit switch) and confirm the corresponding input bit in the VAT or HMI.
- Use the VAT table to set each DO bit; verify the field device (contactor, solenoid) energises and the voltage on the output terminal matches expectation.
- Run the CP 341 in loopback mode if no partner device is online. For ASCII protocol, set "Send receive with end-of-frame timeout" and check that received bytes match the transmitted string in the CP's diagnostic buffer.
- Monitor the CPU's scan time with PLC → Module Information → Scan Time. A CPU 315 should execute the existing program in less time than the same program on the CPU 314, with the same cycle clock settings.
- Order the correct CPU 315 variant (DP, PN/DP, F-capable) and FW version.
- Order a 4 MB or larger MMC if the new CPU does not ship with one.
- Back up the STEP 7 project (File → Archive) and upload the current PLC to PG.
- Record the wiring of every front connector with a label or photo.
- Bring the process to a safe state, isolate the cabinet, verify zero potential.
- Swap the CPU on the rail; reuse the same bus connector positions.
- Open HW Config; use Replace Object to swap the CPU; save and compile.
- Re-apply any CPU-specific properties (MPI address, OB 35 interval, time-of-day interrupt, protection level).
- Download the new configuration to the new CPU.
- Verify SF / BF / DC5V / RUN LEDs; check the diagnostic buffer.
- Force each DI/DO in turn; check CP 341 loopback.
- Hand the system back to operations with the project archive and the commissioning record.
9.3 Functional Verification
10. Troubleshooting Matrix
| Symptom | Likely cause | Action |
|---|---|---|
| CPU SF LED steady red after download | HW Config mismatch, missing module, or duplicate address. | Open PLC → Module Information. The first event in the diagnostic buffer points to the offending slot. |
| CPU BF LED on steady | Bus fault on PROFIBUS / MPI / PROFINET. Wiring or termination. | Check bus connector pin engagement; verify terminator resistor is on at both ends of the segment only (PROFIBUS). |
| CPU SF + BF flashing in alternation | Module pulled during RUN, or a CP 341 has not completed startup. | Re-seat the offending module. CP 341 with no protocol loaded will report BF until configured. |
| Download fails: "Insufficient work memory" | MMC too small or work memory of the new CPU is still too small. | Upgrade MMC size; compress DBs with the "Reuse DB" option in STEP 7; check for orphaned DBs from deleted sources. |
| OB 85 "I/O access error" at startup | User program reads / writes an address not in the new module's image. | Open PLC → Diagnostic Buffer → OB 85 start info. The byte address and slot are reported. Adjust the program or remap the module in HW Config. |
| RUN LED flashes at 2 Hz, STOP steady | CPU in startup; expecting configuration download or module update. | Wait 30 s. If the pattern persists, check for a pending firmware update marker on the MMC. |
| Field I/O bit does not track the input | Wiring break, sensor supply missing, or address offset in the program. | Verify 24 V on terminal 1L+ of the SM 321. Force the input from the VAT and watch the symbol table. |
| CP 341 "No protocol loaded" | Protocol not downloaded to the CP's own memory. | Open the CP 341 object in HW Config, click "Protocol" and re-download with "Download protocol to module". |
| Mode selector does not latch in RUN | Mode selector worn or firmware in update mode. | Pull and re-insert the selector; if the CPU returns to "Update mode" automatically, the MMC has a pending firmware update. Erase the MMC and re-load. |
11. Migration Checklist
12. Related Notes
For dual-rack configurations (CPU + IM 360 in rack 0, IM 361 in rack 1, and up to two more ER 161/162 racks), the S7-300 backplane address area is split: slots 0-7 of rack 0 use I/Q bytes 0-127 by default; expansion racks start at 128. The CPU 315 supports up to four racks. If your existing system uses an expansion rack, the new CPU 315 may allow a larger default address range without re-mapping, but verify against the HW Config "Address Overview" before commissioning.
The CP 341 will be the next likely replacement target if your serial network is being modernised. Modern equivalents include the CM PtP modules on the S7-1500 ET 200MP station (6ES7540-1AB00-0AA0 series). A migration of the CP 341 to a CM PtP requires a protocol recompile but preserves the electrical interface (RS-232C / RS-422 / RS-485) and most application-level telegram structures.
13. Frequently Asked Questions
Does removing the CPU 314 from HW Config also delete the user program?
No. The user program (OB, FB, FC, DB, SFB, SFC) is stored in the S7 Program → Blocks container, not on the CPU icon. Deleting the CPU object in HW Config only removes the system data (SDBs); the application blocks are retained and rebound to the new CPU. Always archive the project and upload the station to PG before the swap to guarantee recovery.
Do I need a new MMC when migrating from CPU 314 to CPU 315?
Yes. CPU 31xC and CPU 315 require an MMC; the CPU 314 (6ES7314-1AG14-0AB0) also uses one. Use an MMC rated for the new CPU's load memory (a 4 MB Siemens MMC, 6ES7953-8LM20-0AA0, is sufficient for most projects). The MMC content is not automatically transferred by STEP 7; the program is downloaded to the MMC during the standard download to target.
Can I keep the bus connectors when I swap the CPU on the rail?
Yes. The bus connectors are clipped to the rear of every module and remain with the module they are physically attached to. The CPU ships with two bus connectors (one for the module on the right, one spare). When you remove the old CPU, slide the bus connector off and attach it to the new CPU before mounting, or use the spare that ships with the new CPU.
What happens to the diagnostic buffer when the CPU is replaced?
The diagnostic buffer is non-volatile on the MMC for CPU 31xC and CPU 315. After the swap, the new CPU starts with an empty buffer. The events from the previous CPU are not transferred, even if the MMC is reused. Always export the diagnostic buffer from the old CPU (PLC → Module Information → Diagnostic Buffer → Save As) before the swap if you need the historical record for the maintenance file.
Will the CP 341 continue to work after the CPU swap?
Yes, provided the CP 341 remains in the same slot, the wiring is intact, and the CP's protocol is still loaded. The CP 341 has its own non-volatile memory (Flash) and does not lose its protocol configuration when the CPU is replaced. If the protocol is not loaded (e.g. a brand-new CP 341), re-configure it in HW Config and download the protocol to the CP after the CPU swap.
Do I have to re-terminate PROFIBUS connectors after removing the CPU?
No. PROFIBUS terminations live on the D-sub connectors at the ends of the segment, not on the CPU. The CPU 315-2 DP is one node on the segment; its on-board DP interface has no internal termination. If the CPU is the physical end of the segment, leave the terminator on the bus connector; otherwise, leave it off.