S7-300 OPC Communication: S7 Online vs ISO on TCP with CP343-1

David Krause15 min read
OPC / OPC UASiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Engineers integrating a SIMATIC S7-300 controller with an OPC server routinely ask whether a dedicated CP343-1 communications processor is mandatory and whether the "S7 Online" channel that STEP 7 uses for programming can be re-used for production OPC traffic. The short, field-proven answer: the same S7 Communication transport used by the STEP 7 "S7 Online" interface is fully supported by SIMATIC NET OPC servers (DA) and by the integrated OPC UA server of the S7-1500 family. The choice between S7 Communication, ISO on TCP, and TCP/IP native is therefore a question of available CPU/PROFINET interfaces, connection-resource budgets, and project standards — not a fundamental capability gap.

This reference walks through the three communication paths a SIMATIC S7-300 controller can take to an OPC DA or OPC UA client, the precise role of CP343-1, and the configuration sequence required to bring the channel up reliably. The content applies to S7-300 firmware V2.x and later, with notes on the S7-1500 transition path where the same engineering rules apply. Where configuration steps differ between STEP 7 V5.x and TIA Portal, both are referenced.

Important nomenclature: "S7 Online" in STEP 7 is not a separate protocol — it is the PG/OP channel carried over the S7 Communication stack. SIMATIC NET OPC servers, WinCC, and HMI panels reuse the exact same S7 Communication services (PUT/GET, BSEND/BRCV, USEND/URCV) that PG/OP routing uses. If "S7 Online" can read and write tags from your engineering station, OPC DA via SIMATIC NET will work over the identical transport.

Communication Paths from S7-300 to OPC

Three Siemens transport options terminate on the same S7 Communication stack in the CPU. Choosing between them is governed by the available physical interface, the number of OPC clients, and whether the path must traverse routers or firewalls.

Transport Standard / Port Physical Interface OPC Compatibility Typical Use
S7 Communication (S7-Kommunikation) over ISO on TCP RFC 1006 / TCP port 102 CPU PROFINET, CP343-1, CP343-1 Lean/Advanced/IT SIMATIC NET OPC DA, WinCC, OPC UA via SIMATIC NET Default path for STEP 7 PG/OP and OPC DA on S7-300
S7 Communication over native TCP/IP TCP port 102 (no RFC 1006 wrapper) CP343-1 IT, CP343-1 Advanced SIMATIC NET OPC DA/UA Routed networks, WAN links, third-party OPC brokers
OPC UA binary (TCP) OPC UA / TCP port 4840 (default), discovery on 4840 S7-1500 CPU (integrated), S7-300 via SIMATIC NET OPC UA server Any OPC UA client Modern greenfield projects, cross-vendor integration

For the S7-300, the practical question collapses to: does my CPU have an integrated PROFINET port that supports S7 Communication, or do I need a CP343-1?

S7 Online vs. ISO on TCP — Clearing the Confusion

Many documentation sets and training material state that "ISO on TCP" is the only sanctioned way to read/write S7-300 tags from an OPC server. The statement is technically true but often misinterpreted. ISO on TCP is the transport that carries the S7 Communication application protocol; the OPC server does not care which lower-layer transport the S7 stack is wrapped in, as long as the CPU terminates the S7 Communication service correctly.

When STEP 7's "S7 Online" connects, it:

  1. Opens an ISO-on-TCP connection (TPKT length header + RFC 1006) to the CPU on TCP port 102.
  2. Negotiates an S7 Communication session (S7COMM protocol).
  3. Performs PUT/GET, cyclic services, or programming functions over that session.

The SIMATIC NET OPC DA server performs the identical sequence. There is no separate "S7 Online channel" and "OPC channel" — they share the same CPU connection resources. The visible difference is the project-side configuration: STEP 7 uses the "PG/PC interface" assignment; SIMATIC NET uses the "S7-ONLINE" access point or a custom access point that points to the same network adapter.

Rule of thumb: if you can download the project to the CPU from your engineering station, the OPC DA server can read/write tags over the same network adapter without any new wiring or CP changes.

When CP343-1 Is Required

CP343-1 is a communications processor that adds an Ethernet/PROFINET interface to S7-300 CPUs that either lack a port or have an exhausted interface. The decision tree is straightforward:

CPU Family Integrated Ethernet? S7 Comm. Support? CP343-1 Needed?
CPU 312, 314, 315-2 DP, 316-2 DP (no PN/PN-IO suffix) None or MPI/DP only N/A Yes — add CP343-1 Lean/Standard/Advanced
CPU 314C-2 PN/DP, 315-2 PN/DP, 317-2 PN/DP, 319-3 PN/DP 2-port PROFINET switch Yes, on the PN interface No — use the integrated PN port
CPU 31xT/F (technology / failsafe) PN on most variants Yes No
ET 200S IM151-8 PN/DP CPU PN Yes No

Common CP343-1 variants and their relevance to OPC:

  • CP343-1 Lean (6GK7343-1CX10-0XE0) — 1 × RJ45, 10/100 Mb, supports S7 Communication and PG/OP routing; adequate for low-volume OPC DA polling.
  • CP343-1 (6GK7343-1EX30-0XE0) — 2-port switch, S7 Communication, PG/OP, routing; typical for OPC DA and small WinCC stations.
  • CP343-1 Advanced (6GK7343-1GX30-0XE0) — adds IT functions (HTTP, FTP, email) and is the typical choice when SIMATIC NET OPC UA forwarding is required on the S7-300 line.

The CP does not need a separate IP from the CPU — both appear in the S7 project as Ethernet nodes. The CP must be connected and configured (IP, subnet, S7 connection resource) in the STEP 7 / TIA Portal hardware configuration, otherwise the S7 Communication stack will not bind to the port and the OPC server will report "connection refused" on TCP 102.

Hardware and Software Prerequisites

Bring the following into scope before commissioning the OPC link:

  • CPU firmware: S7-300 firmware V2.x or later for full PUT/GET. CPU 31x PN/DP with FW V3.x recommended for OPC UA bridging via SIMATIC NET.
  • CP343-1 firmware: keep current; field issues with early FW V2.x caused OPC timeouts under load.
  • STEP 7 V5.5 / V5.6 (for S7-300 in the classic project) or TIA Portal V16+ for the S7-1500 path.
  • SIMATIC NET v8.x or v16+ (matches STEP 7 / TIA Portal major) — provides the OPC DA server and (since 2008) the OPC UA server wrapper. S7-1500 firmware V2.0+ embeds an OPC UA server directly, eliminating SIMATIC NET for native UA.
  • PC adapter: a standard Ethernet NIC bound to the "S7-ONLINE" access point. Industrial managed switches are recommended for determinism.
  • Connection resources: every PG/OP, HMI, and OPC client consumes a connection resource on the CPU. Verify the CPU's published "max connections" count against the project total.
Connection-resource budgeting: the S7-300 CPU maintains a counter of open S7 Communication connections. A CPU 315-2 PN/DP allows 16 connections by default; of these, one is consumed by each PG/OP, each HMI, and each OPC DA group. If "max number of S7 connections reached" appears in the diagnostic buffer, the OPC link is not at fault — the project exceeds the CPU's connection budget and a CP must be added or connection multiplexing must be enabled in the OPC server.

Configuring an OPC DA Server for S7-300 (SIMATIC NET)

The standard, vendor-supported route on S7-300 is the SIMATIC NET OPC Scout V10 (DA) or the SIMATIC NET OPC UA Server configured via TIA Portal / Station Configurator. The sequence below is the field-proven commissioning procedure.

  1. Open SIMATIC Manager / TIA Portal and ensure the S7-300 station compiles without errors. The hardware configuration must include the CPU and any CP343-1 with valid IP, subnet mask, and a defined Ethernet subnet.
  2. Configure the PG/PC interface on the engineering station: Control Panel → Set PG/PC Interface → S7-ONLINE (TCP/IP) → <your NIC>. This is the same access point OPC will use.
  3. Download the hardware configuration to the CPU and CP. Confirm the CP's LINK LED is solid and that PING to the CP IP from the engineering station succeeds.
  4. Open the SIMATIC NET Station Configurator and add an OPC server slot. Choose OPC.SimaticNET (DA 2.0/3.0) and confirm the station loads without error icons.
  5. Launch OPC Scout V10. In the server tree, navigate to OPC.SimaticNET → DA view → 3 (the local server). Add an S7 connection by right-clicking → New Connection → S7.
  6. Set the connection parameters: enter the CPU's or CP's IP address, leave the S7 connection name at default, and set the Access Point to "S7-ONLINE". Tick Single Write/Read if the OPC client will perform acyclic writes; leave unchecked for cyclic-only HMI traffic.
  7. Add items by browsing the tag browser (S7 symbols or absolute DB addresses, e.g. DB1,REAL0 for a REAL at byte 0 of DB1). The browser parses the S7 project and exposes the configured symbols.
  8. Test with OPC Scout's DA view: drag the item into a watch window and confirm the value updates and that a write operation forces the tag to a new value visible in the CPU's VAT table.
  9. Set update rate and dead band: cyclic groups default to 1000 ms. For analog tags, configure a 0.5% dead band to suppress noise; for digital status, set dead band to 0 to capture every transition.

If the S7 connection establishes, OPC reads work, and writes from the DA test client change values that STEP 7 can monitor, the OPC server is healthy. Pointing a third-party HMI/SCADA (WinCC, Ignition, iFIX, Citect) at OPC.SimaticNET is then a matter of creating a DA client channel with the host running the SIMATIC NET station.

Modern OPC UA Path (S7-1500 and SIMATIC NET for S7-300)

Newer projects increasingly standardize on OPC UA. Two paths are valid for a Siemens fleet:

Path A — Native OPC UA on S7-1500 CPUs

From firmware V2.0 onward, every S7-1500 CPU ships with an integrated OPC UA server that runs on the PROFINET interface, default TCP port 4840. No additional module is required. Configuration is done in TIA Portal under Device configuration → OPC UA → Server: enable the server, generate or import a server certificate, define security policies (None, Basic128Rsa15, Basic256Sha256), and grant runtime tag read/write permissions.

The connection setup for OPC UA is two-stage, as documented in the TIA Portal help: "the client establishes a connection for the discovery process, only then the productive connection." See the official reference Details about OPC UA client/server connections (S7-1500) — TIA Portal help. This means a client must first read /discovery endpoints on port 4840, choose a security policy, and then open a session using that endpoint URL.

Path B — SIMATIC NET OPC UA forwarding an S7-300 station

When the controller is an S7-300, the OPC UA server is provided by SIMATIC NET running on a PC station. The PC station acts as a UA server; internally it reads the S7-300 over the S7 Communication path (S7 Online) and exposes those tags as UA nodes. Configuration is similar to the DA path, but the Station Configurator now hosts an OPC UA Server slot in addition to (or instead of) the DA server. Security is configured by importing the SIMATIC NET server certificate into the UA client trust store.

Aspect DA over SIMATIC NET (S7-300) UA on S7-1500 (native) UA via SIMATIC NET (S7-300)
Port 102 (S7), DCOM dynamic 4840 4840 (server) + 102 (S7 backplane)
Security DCOM ACL, no transport crypto Certificates, AES, signing Certificates, AES, signing
Cross-vendor clients Windows-only (DCOM) Any OPC UA client Any OPC UA client
Module required on PLC CP343-1 (if no PN) None (CPU only) CP343-1 (if no PN)

Connection Resources and Limits

The S7-300 CPU maintains an S7-connection resource counter. Each of the following consumes one resource:

  • STEP 7 online session (PG)
  • WinCC / HMI panel (each HMI station = 1)
  • SIMATIC NET OPC DA connection (1 per configured S7 connection in OPC Scout)
  • PUT/GET partner (1 per configured PUT/GET)
  • Open user communication via BSEND/BRCV (1 per configured UDT connection)

Typical published limits (verify against the CPU's manual in the hardware catalog):

CPU Total S7 Connections Reserved for PG/OP Available for OPC/HMI
CPU 312 6 2 4
CPU 314 8 2 6
CPU 315-2 PN/DP 16 2 14
CPU 317-2 PN/DP 32 2 30
CPU 319-3 PN/DP 32 2 30

For larger OPC deployments (>16 clients, e.g. multi-station SCADA), the project must either consolidate clients through a single OPC DA bridge or add a CP343-1 Advanced to provide an additional 16–48 connection resources on a separate interface.

Verification and Diagnostics

After configuration, validate the path end-to-end with the following checks:

  1. Link layer: PING the CPU's or CP's IP from the OPC server PC. 0% loss at 100 packets.
  2. S7 Online test: in STEP 7, go Online → Accessible Nodes. The CPU must appear at the configured IP. If not, the OPC server will not see it either.
  3. OPC Scout Read: drag a known tag (e.g. DB1.DBD0) into a watch window. The value must equal the value shown in a STEP 7 VAT or online monitor on the same tag.
  4. OPC Scout Write: force a digital output via the OPC server; verify the physical output transitions using a multimeter or by reading the process image in STEP 7.
  5. CPU diagnostic buffer: Online → Diagnostic Buffer. Look for events "Connection established / terminated" with source "S7 Communication". Each OPC connection establishment must be logged here; if not, the connection is failing at the transport layer.
  6. Connection counter: Online → Module Information → Communication → Connection Resources. Confirm used ≤ max.

For OPC UA on S7-1500, repeat with the UA client: open the discovery endpoint, accept the certificate, navigate to ns=4;s="DB1"."Real0" (or your configured namespace), and read/write the same tag.

Troubleshooting Matrix

Symptom Likely Cause Diagnostic Resolution
OPC Scout shows "Cannot connect to server" SIMATIC NET Station Configurator error; PC station not loaded Check Station Configurator for red icon Restart SIMATIC NET service; reload PC station from configuration
Accessible Nodes does not see the CPU PG/PC interface bound to wrong NIC, firewall blocking TCP 102 PING test, telnet <ip> 102 from server PC Rebind S7-ONLINE access point; open inbound TCP 102 on Windows Firewall
Connection establishes, tags read as "OPC Quality Bad" DB not optimized, wrong offset, or symbol not released for OPC STEP 7 DB properties → Attributes → check "Accessible via OPC" Mark the DB as not optimized (S7-300), correct the offset, or export the symbol to OPC Scout
Diagnostic buffer: "Maximum number of S7 connections reached" Connection-resource budget exhausted Module Information → Communication Close redundant PG/OP sessions; consolidate OPC clients; add CP343-1 for more resources
OPC UA discovery returns 0 endpoints on S7-1500 OPC UA server disabled, certificate not generated, or port 4840 blocked TIA Portal → OPC UA Server settings; telnet <ip> 4840 Enable server, generate self-signed cert, open TCP 4840 in firewall
UA client reports "BadCertificateUntrusted" Server certificate not in client trust store Client log file Export the CPU's OPC UA server certificate and import into the UA client's trusted certificates store
Reads succeed, writes silently fail CPU protection level 3 set, PUT/GET disabled in CPU properties CPU properties → Protection → "Permit access with PUT/GET" Enable PUT/GET communication from the partner (OPC); configure a password if protection level 2/3 is required
Intermittent timeout under load CP343-1 firmware bug, undersized update group, broadcast storm Diagnostic buffer for comm. errors; Wireshark on TCP 102 Update CP343-1 firmware; split OPC groups by update rate; isolate OT VLAN

Field-Proven Engineering Notes

  • PUT/GET permission is the silent killer. A CPU at protection level 3 with PUT/GET disabled will accept PG/OP (because the password is supplied) but reject OPC writes. Always verify CPU Properties → Protection → Permit access with PUT/GET from remote partner before commissioning OPC.
  • Do not double-tag in the OPC browser. When the same DB variable is exported both as an S7 symbol and as an absolute address, OPC Scout may add two items. Reads from both will return the same value, but writing to the absolute address while the symbol is being read can race.
  • Symbolic vs. absolute addressing. S7-300 / STEP 7 V5.5 supports symbolic access to non-optimized DBs only. TIA Portal defaults DBs to "optimized"; for S7-300 with DA, change the DB attribute Optimized block access → No before downloading, or the OPC browser will not enumerate the symbols.
  • DCOM is still the DA Achilles' heel. OPC DA over SIMATIC NET uses DCOM, which requires named ACLs and open RPC ports. On a hardened Windows Server 2019/2022, expect to spend 30–60 minutes configuring Windows Firewall rules and DCOMCNFG. OPC UA eliminates this entirely.
  • Watch the broadcast domain. A CP343-1 Lean has a single port; loop the engineering station and the SCADA server through a managed switch, not a hub. PROFINET real-time traffic and S7 Communication can coexist on the same wire but should be on separate VLANs if the switch supports QoS.
  • OPC UA namespaces. The S7-1500 default namespace index 4 maps to the project symbols; index 3 holds the system diagnostics. Always confirm with the UA client tool that the namespace URI matches what the TIA Portal project generated — a re-download of the hardware configuration regenerates the namespace and breaks running client subscriptions until the client imports the new companion spec.

Do I need a CP343-1 to use an OPC server with an S7-300?

Only if the CPU lacks a PROFINET (PN) interface. S7-300 CPUs with a PN suffix (e.g. 315-2 PN/DP, 317-2 PN/DP) expose S7 Communication natively on the integrated port. CPUs without PN must use a CP343-1 (Lean, standard, or Advanced) to provide the Ethernet interface and the S7 Communication stack.

Can I use the same S7 Online connection that STEP 7 uses for programming to carry OPC traffic?

Yes. "S7 Online" is the PG/OP channel carried by the S7 Communication stack on TCP port 102. The SIMATIC NET OPC DA server uses the identical S7 Communication services, so the existing Ethernet wiring and PG/PC access point work for OPC without reconfiguration — provided the CPU has free S7 connection resources.

Is ISO on TCP the only transport allowed for OPC on S7-300?

No. ISO on TCP (RFC 1006 on port 102) is the default because it matches the PG/OP path and the S7-300 Ethernet driver, but native TCP and OPC UA binary are equally supported. For S7-300, the OPC UA server is provided by SIMATIC NET; for S7-1500, it is integrated and uses TCP 4840.

Why do my OPC writes fail even though the connection is established?

The most common cause is the CPU's protection level disabling PUT/GET access. Open the CPU properties in STEP 7 / TIA Portal, go to Protection, and enable Permit access with PUT/GET from remote partner. After re-downloading the hardware configuration, OPC writes will succeed without restarting the OPC server.

How do I get an OPC UA server on an S7-300?

Install SIMATIC NET on a PC station and configure the OPC UA Server slot in the Station Configurator. The PC station reads the S7-300 over S7 Communication and exposes the tags as OPC UA nodes on port 4840. This is the only vendor-supported OPC UA path for S7-300; the S7-1500 line carries the OPC UA server natively from firmware V2.0 onward.

Back to blog