S7-300 CPU-to-CPU Ethernet Communication with CP 343-1 Lean

David Krause16 min read
S7-300SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: Four-Station S7-300 Network Architecture

Multi-station S7-300 networks with CPU 317-2DP controllers and CP 343-1 Lean communication processors are common in water/wastewater, building automation, and small process plants. The challenge is implementing deterministic CPU-to-CPU data exchange on Ethernet while keeping the same CP available for SCADA polling, leaving the PROFIBUS-DP master port free for distributed I/O.

The reference configuration discussed in this guide is:

  • 4x SIMATIC S7-300 stations, each with a CPU 317-2DP (6ES7317-2AK14-0AB0, firmware V3.x)
  • 1x CP 343-1 Lean (6GK7343-1CX10-0XE0) per station in the Ethernet subnet
  • 1x SCADA/operator station on the same switched Ethernet segment
  • TCP/IP-based cyclic data exchange between all four CPUs

Each CPU must read data published by the other three and publish its own data, with a typical exchange budget of 50 to 400 bytes per station. Because the application is non-time-critical (wastewater treatment), latency in the 100 ms range is acceptable.

Clarification: Global Data (GD) vs. Ethernet Communication

A frequent source of confusion is the term "Global Data." In SIMATIC vocabulary, Global Data is a Siemens-specific broadcast mechanism for exchanging small amounts of data over MPI or the backplane bus, not over Ethernet. CPU 317-2DP supports GD communication with the following hard limits:

Parameter Limit for CPU 317-2DP
Maximum number of GD circles up to 8
Maximum number of GD packets per circle up to 8
Maximum data length per packet 22 bytes (16 data + 4 status + 2 spare)
Total maximum data per CPU ~ 256 bytes
Transport medium MPI bus only

For an Ethernet-based four-station project with a SCADA client, Global Data is the wrong tool. The correct family of solutions is the Open Communication Services (ISO-on-TCP, TCP, UDP) or S7 Communication (PUT/GET) carried over the CP 343-1 Lean. The remaining sections of this guide focus on those mechanisms.

Do not attempt to configure GD circles in NETPRO over the Ethernet CP. The CP 343-1 Lean transports GD only as a router, and the CPU's GD table still binds to MPI. The data budget (22 B/packet) is also far too small for typical multi-station process sharing.

Connection Type Selection: ISO-on-TCP, TCP, UDP, S7

SIMATIC S7-300 / CP 343-1 Lean supports four transport protocols for user-controlled data exchange. Selection depends on data size, partner type, and diagnostic needs.

Protocol Block (send/receive) Max payload per call Connection type Recommended use
ISO-on-TCP (RFC 1006) FC5 AG_SEND / FC6 AG_RECV 8 192 bytes (8 KB) Connection-oriented, full-duplex Default for CPU-to-CPU on CP 343-1 Lean
TCP native FC5 / FC6 with TCP 8 192 bytes Connection-oriented, full-duplex Non-Siemens partners, simple firewalls
UDP FC5 / FC6 with UDP 2 048 bytes per datagram Connectionless Pub/sub-style broadcast (no ack)
S7 Communication SFB12 BSEND / SFB13 BRCV, or FB14 PUT / FB15 GET 64 KB (BSEND/BRCV), 160/462 bytes (PUT/GET) Connection-oriented, S7-only Large blocks, server-only model

For the four-station wastewater reference plant, ISO-on-TCP with FC5/FC6 is the canonical choice: every CPU is a Siemens device, the 8 KB ceiling per call is far beyond the data requirement, and ISO-on-TCP gives clean per-job acknowledgment and orderly close behavior. The remainder of this guide uses ISO-on-TCP exclusively.

Hardware and Topology Prerequisites

  1. Four CPU 317-2DP mounted on a common rack profile with PS 307 power supply, SM 321/SM 322/SM 331/SM 332 as required.
  2. One CP 343-1 Lean (6GK7343-1CX10-0XE0) per station. The Lean variant is part number 6GK7343-1CX10-0XE0; the EX11 firmware is current. Note: CP 343-1 Lean does not support routing to other subnets and has no integrated switch (single RJ45 port). An external managed switch (e.g., SCALANCE XB005 or XB208) is required to build the Ethernet segment.
  3. Ethernet patch cabling, Cat 5e or better, maximum segment length 100 m.
  4. SCADA station (WinCC, Citect, iFIX, or a third-party SCADA) with Ethernet interface and the same subnet. SCADA talks to each CPU over the same CP 343-1 Lean used for CPU-to-CPU traffic.
  5. STEP 7 V5.5 SP4 (or V5.6) project with the four stations inserted, CP 343-1 Lean hardware catalog (HSP) installed.
The CP 343-1 Lean is a single-port device. A 4-port unmanaged switch is mandatory for any plant with two or more Ethernet peers. For PROFINET-converged traffic, use a SCALANCE switch with PROFINET diagnostics enabled.

STEP 7 Project Structure and IP Plan

Assign fixed IP addresses. The CP 343-1 Lean acts as a separate Ethernet node from the CPU, even though it sits in the same S7 station. CPU 317-2DP has an integrated PN/DP port, but the Lean CP is typically used for the SCADA-coupled traffic to keep that path isolated from distributed I/O on PROFIBUS-DP.

Station CPU IP / Subnet CP 343-1 Lean IP / Subnet CP MAC (example)
Station A (PLC-1) 192.168.0.11 / 24 (PROFIBUS-DP side) 192.168.1.11 / 24 08-00-06-01-00-11
Station B (PLC-2) 192.168.0.12 / 24 192.168.1.12 / 24 08-00-06-01-00-12
Station C (PLC-3) 192.168.0.13 / 24 192.168.1.13 / 24 08-00-06-01-00-13
Station D (PLC-4) 192.168.0.14 / 24 192.168.1.14 / 24 08-00-06-01-00-14
SCADA N/A 192.168.1.20 / 24 PC NIC

Use subnet mask 255.255.255.0 and keep the SCADA station on the same /24 as the CPs. Avoid duplicate IP addresses; the CP 343-1 Lean will refuse to come online with a duplicate and report SF/BF on the front panel.

NETPRO Connection Configuration

Open SIMATIC Manager > Options > Configure Network (NETPRO). Each CPU needs three outgoing ISO-on-TCP connections, one to each of the other three CPUs. On the partner CPU you create the matching receive-end connection. This is the standard "configured connection" model: every connection has a local ID, a partner IP, a TSAP, and an active/passive role assignment.

  1. Right-click the CP 343-1 Lean of Station A in NETPRO and choose "Insert New Connection." Pick "ISO-on-TCP connection" and select the CP of Station B as the partner. The CP offers to create the partner side automatically; accept.
  2. In the connection properties, give the local connection an ID, for example ID 1. The partner receives a mirrored ID automatically. Assign TSAPs: the active end is typically the one whose CP connects, so on Station A assign TSAP "PLC1.01" (or simply "01.01") and on Station B the passive TSAP "PLC2.01" / "02.01". The TSAP must be identical on both sides for the connection to establish.
  3. Repeat to create connections A ↔ C (ID 2) and A ↔ D (ID 3) on Station A. Each partner station gains the corresponding mirror connections.
  4. On Station B, add connections to C (ID 4) and D (ID 5) - the A-link was created in step 1.
  5. On Station C, add connection to D (ID 6) - A and B links are already there.
  6. Save and compile NETPRO, then download the connection configuration (Connections button on the CP properties, or the entire station) to each PLC.
Total connections configured: 4 CPUs * 3 partners / 2 = 6 unique connections, but each CPU has 3 local connection IDs. The CP 343-1 Lean supports a maximum of 8 ISO/TCP/UDP connections simultaneously. Four CPUs * 3 = 12 connections total in the subnet. Verify this against the CP manual: CP 343-1 Lean (6GK7343-1CX10-0XE0) supports up to 8 connections for Open Communication. If exceeded, switch to CP 343-1 (6GK7343-1EX30-0XE0) which supports 32.

Connection Budget on the CP 343-1 Lean

This is the single most common stumbling block on this topology. The Lean CP is limited:

Resource CP 343-1 Lean (CX10) CP 343-1 (EX30)
Total open communication connections (ISO/TCP/UDP) 8 32
S7 connections (PUT/GET, S7 server) 4 (or 8, firmware dependent) 16
SCADA connections counted against the budget? Yes - each HMI/SCADA partner occupies one S7 connection Yes

For a four-station ISO-on-TCP design with a SCADA server, the budget is:

  • 3 ISO-on-TCP CPU-to-CPU connections per CP = 3
  • 1 S7 connection (or ISO) to SCADA per CP = 1
  • Total per CP = 4 connections, well within the 8-connection ceiling.

If the SCADA polls via ISO-on-TCP and the engineering team also wants one diagnostic connection per CP (e.g., a laptop for online viewing), plan the connection matrix carefully and document it in NETPRO. The CP 343-1 Lean does not allow the budget to be exceeded at runtime; new connection attempts are rejected with status word W#16#80A1 in the AG_SEND / AG_RECV blocks.

Programming FC5 AG_SEND and FC6 AG_RECV

The Open Communication interface is a pair of function blocks shipped with STEP 7. For ISO-on-TCP, the classic pair is FC5 (AG_SEND) and FC6 (AG_RECV) from the "Standard Library > Communication Blocks" catalog. Place the calls in OB1 (cyclic) or in a watch-dog OB (e.g., OB35 at 100 ms) for deterministic cycling.

FC5 AG_SEND interface (STEP 7 V5.5)

Parameter Declaration Type Description
ACT INPUT BOOL Trigger to start send (rising edge)
ID INPUT INT Connection ID from NETPRO (1, 2, 3 on Station A)
LADDR INPUT WORD Logical base address of the CP (default W#16#0100 for slot 4)
SEND INPUT ANY Pointer to send data, e.g. P#DB100.DBX0.0 BYTE 200
LEN INPUT INT Number of bytes to send (1-8192)
DONE OUTPUT BOOL 1 = send completed without error
ERROR OUTPUT BOOL 1 = error pending
STATUS OUTPUT WORD Status / error code (W#16#...)

FC6 AG_RECV interface

Parameter Declaration Type Description
ID INPUT INT Connection ID (same as partner send ID)
LADDR INPUT WORD Logical base address of the CP
RECV INPUT ANY Pointer to receive buffer, e.g. P#DB200.DBX0.0 BYTE 200
NDR OUTPUT BOOL 1 = new data received
ERROR OUTPUT BOOL 1 = error pending
STATUS OUTPUT WORD Status / error code
LEN OUTPUT INT Number of bytes actually received

Sample LAD / FBD call pattern (per CPU, 3 partners)

For each of the three connection IDs, instantiate a send call and a receive call. The send calls may be triggered by a cycle clock (e.g., OB35 at 1 s for slow process data) while the receive calls are evaluated every OB1 scan. Keep the receive buffer slightly larger than the send length to tolerate future growth:

// Station A - send to Station B (ID=1)
CALL FC5 // AG_SEND
  ACT := M100.0 // 1-second cycle pulse from OB35
  ID  := 1
  LADDR := W#16#100 // CP 343-1 Lean in slot 4
  SEND := P#DB100.DBX0.0 BYTE 200
  LEN  := 200
  DONE := M110.0
  ERROR:= M110.1
  STATUS:= MW112

// Station A - receive from Station B (ID=1)
CALL FC6 // AG_RECV
  ID  := 1
  LADDR := W#16#100
  RECV := P#DB201.DBX0.0 BYTE 200
  NDR  := M120.0
  ERROR:= M120.1
  STATUS:= MW122
  LEN  := MW124

Repeat for IDs 2 and 3 (Station C and Station D). For each CPU, three DBs are typical:

  • DB100 - "MyData": local data published to all three partners
  • DB201, DB202, DB203 - received data from partners B, C, D

Synchronize send cadence so that all four stations trigger FC5 within a 100-200 ms window of each other. Use a global enable bit distributed via the SCADA or a small dedicated "heartbeat" byte that each station broadcasts and increments in the send DB. This makes timeouts in NDR/DONE much easier to diagnose.

Status Word Diagnostics (FC5/FC6)

The STATUS output of FC5/FC6 follows the SIMATIC communication status convention. Critical codes for this topology:

STATUS (hex) Meaning Cause / Fix
0000 Job completed, no error Normal
7000 Job in progress, wait Normal during transmission
7001 Job accepted, executing Normal during transmission
7002 Job rejected - send too early, FC5 still busy Trigger ACT only after DONE/ERROR of the previous job
8085 LADDR wrong, or FC version mismatch Verify CP slot, FC5/FC6 from correct library
80A1 Connection not configured / unknown ID Re-download NETPRO to both partners, verify ID matches
80A2 Send/receive buffer too small for partner data Increase the ANY pointer length, regenerate
80A3 Connection being established Wait for 1-3 s after CPU RUN, or after CP restart
80A4 Connection not yet established by remote Partner CPU not in RUN, or TSAP mismatch
80A7 Receive buffer overflow, LEN > ANY length Increase receive buffer size
80B1 User data length error (LEN = 0 or > 8192) Check LEN input
80C3 Resources exhausted on CP CP 343-1 Lean connection budget exceeded
80D0 Send: partner terminated connection Partner in STOP, or partner received bad data
80F6 CP not in RUN / CP fault Check CP SF/BF LEDs, physical link

See the official SIMATIC Communication DOKU v21 for the complete status table.

SCADA Integration on the Same CP 343-1 Lean

Running SCADA on the same CP as CPU-to-CPU traffic is fully supported and is the default plant architecture for small systems. Two technical points to enforce:

  1. Define SCADA as one additional connection on each CP. The total cost is one connection per CP (the SCADA polls the CPU, the CPU is server). The CPU-to-CPU connections are unchanged.
  2. Disable the CP 343-1 Lean "Write protection" and "Read protection" for the SCADA connection, or set the CPU's protection level to "No protection" / "Write-protection for HMI" so the SCADA can read consistently.

For the SCADA-side protocol, two common options exist:

  • S7 communication (recommended): The SCADA driver (e.g., WinCC with "SIMATIC S7 PROTOCOL SUITE" channel, KEPware, or LibNoDave) opens a single S7 connection to the CP, then uses PUT/GET semantics. Configuration in NETPRO: one unspecified S7 connection per CPU pointing at the SCADA PC.
  • ISO-on-TCP to SCADA: The SCADA acts as a passive ISO-on-TCP partner. Used when the SCADA vendor does not have a native S7 driver. Connection count is the same.

WinCC typically uses S7 communication and consumes one S7 connection per CPU, leaving the four CPU-to-CPU ISO-on-TCP links untouched. The 8-connection budget is then 3 (CPU) + 1 (SCADA) + 1 (engineering, optional) = 5 per CP.

Commissioning Procedure

  1. Wire the panel, install the CP 343-1 Lean, and connect all four PLCs to a managed switch. Verify the SF/BF LED pattern: SF off, BF off, LINK LED green = healthy link.
  2. Open the STEP 7 project, perform a full download of each station (hardware, connections, program). Wait for the SF LED to extinguish on each CP.
  3. From a programming PC, use the menu "PLC > Ethernet Node > Edit Ethernet Node" or the Web diagnostics of the CP (http://192.168.1.11 if reachable) to confirm the assigned IP and firmware. CP 343-1 Lean supports Web diagnostics from firmware V2.0 onward.
  4. Go online with each CPU. In OB1, evaluate the STATUS word of the first FC5/FC6 pair. Expect 7000/7001 transitioning to 0000 within 3-5 seconds of CPU RUN.
  5. Use a VAT (Variable Table) to monitor M110.0, M110.1, MW112. A persistent 80A4 status indicates that the partner CPU has not established the connection, most often because of TSAP mismatch or because the partner CPU is still in STOP.
  6. Force a small value (e.g., a counter in DB100) from Station A. Verify that the same counter appears in DB201 of Station B within one cycle clock (1 s if OB35 is configured at 1 s).
  7. Bring SCADA online. Add the four PLCs as S7 connections in the SCADA project, and confirm tag polling at the configured update rate (250 ms - 1 s is typical).
  8. Test failure modes: stop one CPU, confirm that the partner stations report 80D0 or 80A4 in the receive side, and that the SCADA driver marks the stopped CPU as "not reachable" but keeps the other three online.

Alternatives: S7 Communication with PUT/GET

If the data volume is asymmetric (e.g., one master CPU pulls from three slaves) and the data fits inside the 160-byte single PUT limit, the S7 Communication blocks (FB14 PUT, FB15 GET) offer a leaner implementation. The downside is that PUT/GET require both partners to be active or configured, and they count against the S7-connection budget on the CP, which on the Lean is even tighter than the open-communication budget.

For symmetric "all stations publish and consume" topologies, ISO-on-TCP with FC5/FC6 is the right call. For star topologies with a clear master, PUT/GET may be simpler.

Common Pitfalls and Field-Proven Caveats

Symptom Likely cause Fix
All connections report 80A4 after CPU RUN TSAP mismatch or wrong slot of CP Verify TSAP on both sides, recompile NETPRO and download
One CPU works, others get 80C3 Connection budget exceeded on a specific CP Audit configured connections; upgrade to CP 343-1 (EX30)
Intermittent 80A2 after program change Receive ANY pointer smaller than the new send LEN Match ANY lengths across the link
SCADA cannot browse CPU tags CPU protection level 3 (write-protect) and read-protect Set protection level to "No protection" or "HMI write protection"
BF LED flashes on one CP Duplicate IP or switch port issue Ping from PC, check MAC table, replace patch cable
FC5 never reports DONE ACT triggered every scan - the CP can only process one job at a time per ID Trigger ACT on a clock pulse; latch DONE/ERROR
Data arrives but is old / frozen Receive call only in OB1, but send cycle is OB35; clock skew Match OB priorities and cycle times; verify heartbeat byte increments

Verification Checklist

  • All four CPs show SF off, BF off, LINK green.
  • FC5 DONE pulses once per send cycle for all three connections on every CPU.
  • STATUS words read 0000 in steady state.
  • Receive DBs on each CPU update at the configured cycle time.
  • SCADA online diagnosis shows all four PLCs "Connected."
  • Stopping one CPU does not crash the others; the partner STATUS words degrade gracefully to 80D0.
  • Connection count per CP = 3 (CPU-to-CPU) + 1 (SCADA) + 1 (engineering) = 5, within the 8-connection budget of the CP 343-1 Lean.

FAQ

What is the maximum data size per ISO-on-TCP send call on a CP 343-1 Lean?

Up to 8 192 bytes per call using FC5 AG_SEND / FC6 AG_RECV, with the call split into multiple jobs if more is needed. For the four-station wastewater case, 200-400 bytes per partner is typical and fits in one call.

How many ISO-on-TCP connections does a CP 343-1 Lean support?

8 Open Communication connections in total. Three CPU-to-CPU links plus one SCADA connection fits comfortably; the budget is tight if you also need an engineering or Web-diagnostics connection. The full-feature CP 343-1 (6GK7343-1EX30-0XE0) supports 32 Open Communication connections.

Can I use Global Data (GD) on the CP 343-1 Lean instead?

No. Global Data is an MPI-only mechanism, hard-limited to 22 bytes per packet on the CPU 317-2DP. For Ethernet traffic on the CP 343-1 Lean you must use ISO-on-TCP, TCP, UDP, or S7 Communication blocks (FC5/FC6, FB14/FB15, or SFB12/SFB13).

Why does my FC5 STATUS read 80A4 even though NETPRO is downloaded?

STATUS 80A4 means the connection is not yet established, typically because of a TSAP mismatch between the two CPs or because the partner CPU is in STOP. Re-check the connection properties: the local TSAP and the partner TSAP on the active side must match the partner's passive TSAP. Recompile NETPRO and download both stations.

Can SCADA share the same CP 343-1 Lean with the CPU-to-CPU traffic?

Yes. Add one S7 connection (for the SCADA driver) per CP. The total connection count per CP is 3 (CPU-to-CPU) + 1 (SCADA) + 1 (engineering, optional) = 5, within the 8-connection budget. CPU protection level must be set to "No protection" or "HMI write protection" so the SCADA can read tags.

Do I need to change the program if I switch to TCP native instead of ISO-on-TCP?

The FC5/FC6 call signature is identical. The only difference is the connection type in NETPRO: pick "TCP connection" instead of "ISO-on-TCP connection" and assign the same IP, port (2000-2999 range, free choice), and ID. ISO-on-TCP is preferred for Siemens-to-Siemens because TSAP-based addressing is more explicit and easier to audit.

Back to blog