S7-400 CPU 416-3 PN/DP Ethernet Connection to SCADA via PROFINET

David Krause11 min read
Industrial NetworkingSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

The SIMATIC S7-400 CPU 416-3 PN/DP (MLFB 6ES7416-3ER05-0AB0) is a high-end central processing unit that integrates three independent communication interfaces on a single module: PROFIBUS-DP, PROFINET (Industrial Ethernet), and a slot for an additional IF964-DP or similar submodule. Because the PROFINET interface is built directly into the CPU front panel, no additional Ethernet CP (Communications Processor) is required for connection to a SCADA workstation, engineering station, or HMI panel. The CPU's integrated PROFINET port is a 10/100 Mbit/s RJ-45 interface (X1P1) supporting TCP/IP, ISO-on-TCP (RFC1006), UDP, PROFINET IO, and S7 communication.

This reference documents the field-proven procedure for connecting a single PC (such as an HP Compaq 600 Pro Micro Tower running WinCC, PCS 7, or a third-party SCADA) to the CPU's PROFINET port. It also addresses the recurring field question of whether a hub, switch, or cross-over cable should be used, and what Ethernet CPs can be deployed in the S7-400 backplane if the built-in port is unavailable (damaged, occupied, or assigned to a different subnet).

CPU 416-3 PN/DP Hardware Identification

Before commissioning, verify the CPU's MLFB and firmware version. The ordering data and successor parts are documented in the Siemens Industry Online Support product tree.

MLFB Description Firmware Status
6ES7416-3ER05-0AB0 CPU 416-3 PN/DP, work memory 5.6 MB code / 5.6 MB data (subject to FW), 3 interfaces (PN, DP, IF slot) V5.3 and higher Discontinued; replaced by 6ES7416-3ES06-0AB0
6ES7416-3ES06-0AB0 CPU 416-3 PN/DP, 16 MB work memory (8 MB code, 8 MB data), 3 interfaces V6.0 and higher Current successor product
6ES7416-3XR05-0AB0 CPU 416-3 PN/DP, failsafe / variant V5.3 See S7-400 CPU Specifications manual

The successor MLFB 6ES7416-3ES06-0AB0 is fully pin-compatible at the backplane connector level and preserves the PROFINET and PROFIBUS port assignments, so the cabling instructions below apply to both the E-series (-ER05-) and the newer ES06- hardware.

Built-in PROFINET Interface Specifications

The integrated PROFINET interface of the CPU 416-3 PN/DP occupies the left-most RJ-45 socket on the CPU front panel, labelled X1P1 (PROFINET port 1) and X1P2 (PROFINET port 2) on later ES06- variants. Key parameters:

Parameter Value
Physical layer 10BASE-T / 100BASE-TX, full and half duplex, auto-negotiation / auto-crossover
Connector RJ-45, 8P8C, shielded
Supported protocols TCP/IP, ISO-on-TCP (RFC1006), UDP, PROFINET IO Controller/Device, S7 Communication, PG/OP communication, SNMP, LLDP
Number of S7 connections (PG/OP reserved) Up to 16; check CPU-specific maximum in the manual
Default IP address 0.0.0.0 (must be assigned before first use)
MAC address Printed on the front-panel label (8 hex characters)
Important: The integrated PROFINET port is not a switch port pair. To form a line topology you must use the two ports on the same physical switch or use a SCALANCE switch inserted in the line. Daisy-chaining the two PROFINET ports of the CPU (X1P1 to X1P2) is permitted for PROFINET Conformance Class B line topologies but not for SCADA traffic where you want a star topology.

Network Topology Options

Selection of the correct physical topology is the most common commissioning question for an S7-400 CPU 416-3 PN/DP connected to a single SCADA PC. Three topologies are valid:

Option A — Direct PC-to-CPU Connection (Recommended for One PC)

Use a standard patch cable (TIA-568A on both ends) when the PC's Ethernet NIC supports Auto-MDIX (virtually all post-2005 NICs do, including the Broadcom NIC in the HP Compaq 600 Pro Micro Tower). If the NIC does not auto-negotiate, use a crossover cable (TIA-568A on one end, TIA-568B on the other). No hub, switch, or CP module is required.

  • CPU X1P1 ↔ patch/crossover cable ↔ PC RJ-45
  • Maximum cable length: 100 m (Cat 5e or higher)
  • Assign a fixed IP address (e.g., 192.168.0.1 / 24) to the CPU and a same-subnet address to the PC (e.g., 192.168.0.2 / 24)

Option B — SCALANCE Switch (Recommended for One or More PCs)

Use a Siemens SCALANCE XC/XB/XR series switch when:

  • More than one PC needs access to the CPU (e.g., engineering station + SCADA server + thin client)
  • PROFINET IO devices are also connected to the same CPU port
  • Network diagnostics, port mirroring, or SNMP monitoring are required

A 10/100 unmanaged switch (e.g., SCALANCE XC206-2SFP) is sufficient when the network is exclusively used for SCADA polling. Configure VLANs and managed features only if PROFINET IO is mixed in the same switch — PROFINET requires priority tagging (VLAN 0, PCP 6) and LLDP, which unmanaged switches do not respect.

Option C — Legacy Ethernet Hub

A 10/100 Mbit/s hub (repeater) is electrically valid for a single SCADA PC because the integrated CPU port supports half-duplex 10/100 Mbit/s. However, hubs are obsolete and introduce collision-domain contention; a managed or unmanaged switch is always preferred. A hub must never be used if PROFINET IO devices share the segment, as the timing jitter of CSMA/CD collisions violates the PROFINET real-time requirements.

Ethernet CP Alternatives (When the Built-in Port Is Unavailable)

If the integrated PROFINET port is damaged, fully occupied by a PROFINET IO controller assignment, or the application requires additional isolated subnets, an Ethernet CP can be inserted in the S7-400 backplane. The supported CP modules are documented in entry 59187251 of the Siemens Industry Online Support.

CP Module MLFB Interface Typical Use
CP 443-1 6GK7443-1EX11-0XE0 / -1GX11-0XE0 10/100 Mbit/s or 1 Gbit/s RJ-45 Standard TCP/IP + S7 communication to SCADA / IT network
CP 443-1 Advanced 6GK7443-1EX30-0XE0 / -1GX30-0XE0 1 Gbit/s, 4 ports, IT integration Multiple SCADA subnets, firewall, IP routing
CP 443-1 PN 6GK7443-1EX20-0XE0 PROFINET IO Controller + IO Device When the CPU port is reserved for PROFINET IO and a separate SCADA subnet is required

The CP occupies a free slot in the S7-400 rack. Configuration is performed in HW Config (STEP 7 V5.5 / V5.6) or in the TIA Portal (V13 SP1 and higher, via GSD or HSP). The CP's MAC address is printed on the front panel and is required when the network administrator assigns a fixed IP outside of the S7 project.

IP Address Configuration Procedure (STEP 7 V5.x)

  1. Open SIMATIC Manager and the S7 project containing the CPU 416-3 PN/DP hardware configuration.
  2. Open HW Config and double-click the CPU 416-3 PN/DP slot. Select the PROFINET Interface tab.
  3. Click Ethernet Addresses → Properties. The dialog is shown in the S7-400 CPU manual entry 23904550.
  4. Click New and enter the IP address, subnet mask, and (if applicable) router address. Example values for an isolated SCADA subnet:
    IP address:    192.168.0.1
    Subnet mask:   255.255.255.0
    Router:        0.0.0.0 (none)
  5. Compile and download the hardware configuration to the CPU. After the restart, the CPU's PROFINET port is reachable on the assigned IP.
  6. Configure the PC's NIC with a same-subnet fixed IP (e.g., 192.168.0.2 / 255.255.255.0). Disable any other active NICs (Wi-Fi, VPN) to avoid routing conflicts.

SCADA / OPC Configuration

For a SIMATIC WinCC or PCS 7 OS, add the S7-400 station via the SIMATIC S7 PROTOCOL SUITE channel and select the TCP/IP driver. Enter the CPU's PROFINET IP address and the rack/slot (always rack 0, slot 3 for the CPU in an S7-400).

For third-party SCADA packages (Ignition, iFIX, Citect, WinCC OA), use either:

  • Siemens S7 driver / libnodave / Snap7 over ISO-on-TCP (port 102), or
  • OPC UA via the S7-400 OPC UA server (requires CP 443-1 with firmware supporting OPC UA, or an external edge gateway such as the SIMATIC IOT2050)

The default port 102 (ISO-on-TCP / RFC1006) is the standard S7 communication port. The PROFINET port also accepts PG/OP communication on the same port. No additional firewall opening is required if the SCADA PC and the CPU are on the same isolated subnet.

Cable and Wiring Requirements

Scenario Cable Type Max Length Notes
Direct CPU ↔ PC, modern NIC with Auto-MDIX Cat 5e UTP patch (straight-through) 100 m Simplest, most reliable
Direct CPU ↔ PC, old NIC without Auto-MDIX Cat 5e crossover 100 m Verify with link LED on CPU port
CPU ↔ SCALANCE ↔ multiple PCs Cat 5e / Cat 6 UTP/STP patch 100 m per segment Use STP (S/FTP) in EMC-noisy cabinets
CPU ↔ hub (legacy) Cat 5e UTP 100 m Not recommended; switch preferred
EMC: In cabinet installations, route the PROFINET cable at least 200 mm away from VFD motor cables and 100 mm from 24 VDC power conductors. Use grounded metal cable ducts and the PROFINET cable shield clamp on the CPU's strain-relief bracket.

Verification and Diagnostics

  1. From the PC, open a command prompt and run ping 192.168.0.1. A reply with TTL < 64 confirms IP-level connectivity to the CPU's PROFINET port.
  2. In STEP 7, select PLC → Accessible Nodes. The CPU 416-3 PN/DP should appear with its MAC address and the assigned IP. If the CPU is not visible, verify that the firewall on the PC allows ISO-on-TCP port 102 and that the PC and CPU share the same subnet.
  3. Open the CPU's online diagnostic buffer (PLC → Diagnostic Buffer in SIMATIC Manager) and confirm that the PROFINET interface has reached the RUN state and that no link-down events are logged after the cable was connected.
  4. Use the CPU's front-panel LED indicators: LINK (green, link up) and RX/TX (yellow, flashing on traffic). Both LEDs must be active when the SCADA is polling.
  5. From the SCADA, perform a single read of a known tag (e.g., a marker in MB0) and confirm the value updates at the configured poll interval.

Troubleshooting Matrix

Symptom Likely Root Cause Corrective Action
CPU's LINK LED off Cable fault, wrong cable type, or port damage Replace with known-good patch cable; try a SCALANCE switch between PC and CPU to rule out NIC issues
Ping fails, LINK LED on IP/subnet mismatch or PC firewall Verify IP and subnet mask; temporarily disable Windows Firewall; try arp -d and re-ping
SCADA reports "Connection refused" on port 102 PG/OP or S7 communication disabled in CPU properties In HW Config → CPU Properties → Protection tab, enable Permit access with PUT/GET if the SCADA uses PUT/GET
CPU not visible in Accessible Nodes PG/OP communication on PROFINET disabled HW Config → CPU → PROFINET Interface → Enable PG/OP Communication must be checked
Intermittent timeouts with PROFINET IO devices on the same port Hub in the line (collision domain) or excessive broadcast traffic from IT side Replace hub with SCALANCE switch; isolate SCADA traffic in a separate VLAN
SF / BF LEDs on the PROFINET port illuminated Duplicate IP address in the subnet Run arp -a on the PC and identify the conflicting device; reassign a unique IP

Field-Proven Notes

  • For a single SCADA PC, the direct CPU-to-PC patch cable is the most reliable configuration. A switch adds only one extra failure point with no benefit in a one-to-one link.
  • For PROFINET IO line topology and SCADA on the same physical port, use a SCALANCE switch in the line. The CPU 416-3 PN/DP supports PROFINET Conformance Class B and can act as a PROFINET IO controller while simultaneously serving PG/OP and S7 communication on the same interface.
  • If the application is safety-related (F-CPU), the integrated PROFINET interface of the CPU 416-3 PN/DP is the safety bus interface; do not connect a non-safety SCADA on the same port without a SCALANCE S-series security module in front of the SCADA side.
  • The HUB question is best answered in 2024+ by saying: use a switch, not a hub. Hubs are no longer manufactured in industrial grade and are not supported in any new PROFINET installation.

FAQ

Does the S7-400 CPU 416-3 PN/DP need a separate Ethernet CP module to talk to a SCADA PC?

No. The CPU has an integrated PROFINET (Ethernet) port on the front panel labelled X1P1 (and X1P2 on later ES06- variants). For a single SCADA PC, connect a patch cable directly between the PC's NIC and the CPU's PROFINET port. An Ethernet CP such as the CP 443-1 is only required if the built-in port is damaged, fully occupied by a PROFINET IO controller role, or you need an additional isolated SCADA subnet.

Can I use a hub (not a switch) between the PC and the CPU 416-3 PN/DP?

Electrically, a 10/100 Mbit/s hub works for a single SCADA PC because the CPU's PROFINET port supports half-duplex. However, a hub must never be used if PROFINET IO devices share the segment — the CSMA/CD collisions violate PROFINET real-time timing. In practice, always use a SCALANCE or any 10/100 unmanaged switch instead.

What is the default IP address of the CPU 416-3 PN/DP out of the box?

0.0.0.0. The CPU ships without an IP address; you must assign one in HW Config (STEP 7 V5.x) or in the TIA Portal device view and download the configuration. A unique IP must be on the same subnet as the SCADA PC's NIC, e.g., CPU 192.168.0.1 / 24 and PC 192.168.0.2 / 24.

Which Ethernet CP can be installed in the S7-400 rack for additional SCADA subnets?

The supported modules are the CP 443-1 (6GK7443-1EX11-0XE0, 10/100 Mbit/s), the CP 443-1 Advanced (6GK7443-1EX30-0XE0, 1 Gbit/s, 4 ports, with IT integration and IP routing), and the CP 443-1 PN (6GK7443-1EX20-0XE0) when a dedicated PROFINET interface is needed. The full list is in Siemens entry 59187251.

Which firmware and STEP 7 version are required for the 6ES7416-3ER05-0AB0?

The CPU 416-3 PN/DP MLFB 6ES7416-3ER05-0AB0 is designed for STEP 7 V5.3 SP2 or higher with the matching hardware support package (HSP). The successor MLFB 6ES7416-3ES06-0AB0 (16 MB work memory) is supported by TIA Portal V13 SP1 and STEP 7 V5.5 with the latest HSP. Refer to the S7-400 CPU product page for the exact HSP and firmware matrix.

Back to blog