Overview
The SIMATIC S7-400 CPU 416-3 PN/DP (MLFB 6ES7416-3ER05-0AB0) is a high-end central processing unit that integrates three independent communication interfaces on a single module: PROFIBUS-DP, PROFINET (Industrial Ethernet), and a slot for an additional IF964-DP or similar submodule. Because the PROFINET interface is built directly into the CPU front panel, no additional Ethernet CP (Communications Processor) is required for connection to a SCADA workstation, engineering station, or HMI panel. The CPU's integrated PROFINET port is a 10/100 Mbit/s RJ-45 interface (X1P1) supporting TCP/IP, ISO-on-TCP (RFC1006), UDP, PROFINET IO, and S7 communication.
This reference documents the field-proven procedure for connecting a single PC (such as an HP Compaq 600 Pro Micro Tower running WinCC, PCS 7, or a third-party SCADA) to the CPU's PROFINET port. It also addresses the recurring field question of whether a hub, switch, or cross-over cable should be used, and what Ethernet CPs can be deployed in the S7-400 backplane if the built-in port is unavailable (damaged, occupied, or assigned to a different subnet).
CPU 416-3 PN/DP Hardware Identification
Before commissioning, verify the CPU's MLFB and firmware version. The ordering data and successor parts are documented in the Siemens Industry Online Support product tree.
| MLFB | Description | Firmware | Status |
|---|---|---|---|
| 6ES7416-3ER05-0AB0 | CPU 416-3 PN/DP, work memory 5.6 MB code / 5.6 MB data (subject to FW), 3 interfaces (PN, DP, IF slot) | V5.3 and higher | Discontinued; replaced by 6ES7416-3ES06-0AB0 |
| 6ES7416-3ES06-0AB0 | CPU 416-3 PN/DP, 16 MB work memory (8 MB code, 8 MB data), 3 interfaces | V6.0 and higher | Current successor product |
| 6ES7416-3XR05-0AB0 | CPU 416-3 PN/DP, failsafe / variant | V5.3 | See S7-400 CPU Specifications manual |
The successor MLFB 6ES7416-3ES06-0AB0 is fully pin-compatible at the backplane connector level and preserves the PROFINET and PROFIBUS port assignments, so the cabling instructions below apply to both the E-series (-ER05-) and the newer ES06- hardware.
Built-in PROFINET Interface Specifications
The integrated PROFINET interface of the CPU 416-3 PN/DP occupies the left-most RJ-45 socket on the CPU front panel, labelled X1P1 (PROFINET port 1) and X1P2 (PROFINET port 2) on later ES06- variants. Key parameters:
| Parameter | Value |
|---|---|
| Physical layer | 10BASE-T / 100BASE-TX, full and half duplex, auto-negotiation / auto-crossover |
| Connector | RJ-45, 8P8C, shielded |
| Supported protocols | TCP/IP, ISO-on-TCP (RFC1006), UDP, PROFINET IO Controller/Device, S7 Communication, PG/OP communication, SNMP, LLDP |
| Number of S7 connections (PG/OP reserved) | Up to 16; check CPU-specific maximum in the manual |
| Default IP address | 0.0.0.0 (must be assigned before first use) |
| MAC address | Printed on the front-panel label (8 hex characters) |
Network Topology Options
Selection of the correct physical topology is the most common commissioning question for an S7-400 CPU 416-3 PN/DP connected to a single SCADA PC. Three topologies are valid:
Option A — Direct PC-to-CPU Connection (Recommended for One PC)
Use a standard patch cable (TIA-568A on both ends) when the PC's Ethernet NIC supports Auto-MDIX (virtually all post-2005 NICs do, including the Broadcom NIC in the HP Compaq 600 Pro Micro Tower). If the NIC does not auto-negotiate, use a crossover cable (TIA-568A on one end, TIA-568B on the other). No hub, switch, or CP module is required.
- CPU X1P1 ↔ patch/crossover cable ↔ PC RJ-45
- Maximum cable length: 100 m (Cat 5e or higher)
- Assign a fixed IP address (e.g., 192.168.0.1 / 24) to the CPU and a same-subnet address to the PC (e.g., 192.168.0.2 / 24)
Option B — SCALANCE Switch (Recommended for One or More PCs)
Use a Siemens SCALANCE XC/XB/XR series switch when:
- More than one PC needs access to the CPU (e.g., engineering station + SCADA server + thin client)
- PROFINET IO devices are also connected to the same CPU port
- Network diagnostics, port mirroring, or SNMP monitoring are required
A 10/100 unmanaged switch (e.g., SCALANCE XC206-2SFP) is sufficient when the network is exclusively used for SCADA polling. Configure VLANs and managed features only if PROFINET IO is mixed in the same switch — PROFINET requires priority tagging (VLAN 0, PCP 6) and LLDP, which unmanaged switches do not respect.
Option C — Legacy Ethernet Hub
A 10/100 Mbit/s hub (repeater) is electrically valid for a single SCADA PC because the integrated CPU port supports half-duplex 10/100 Mbit/s. However, hubs are obsolete and introduce collision-domain contention; a managed or unmanaged switch is always preferred. A hub must never be used if PROFINET IO devices share the segment, as the timing jitter of CSMA/CD collisions violates the PROFINET real-time requirements.
Ethernet CP Alternatives (When the Built-in Port Is Unavailable)
If the integrated PROFINET port is damaged, fully occupied by a PROFINET IO controller assignment, or the application requires additional isolated subnets, an Ethernet CP can be inserted in the S7-400 backplane. The supported CP modules are documented in entry 59187251 of the Siemens Industry Online Support.
| CP Module | MLFB | Interface | Typical Use |
|---|---|---|---|
| CP 443-1 | 6GK7443-1EX11-0XE0 / -1GX11-0XE0 | 10/100 Mbit/s or 1 Gbit/s RJ-45 | Standard TCP/IP + S7 communication to SCADA / IT network |
| CP 443-1 Advanced | 6GK7443-1EX30-0XE0 / -1GX30-0XE0 | 1 Gbit/s, 4 ports, IT integration | Multiple SCADA subnets, firewall, IP routing |
| CP 443-1 PN | 6GK7443-1EX20-0XE0 | PROFINET IO Controller + IO Device | When the CPU port is reserved for PROFINET IO and a separate SCADA subnet is required |
The CP occupies a free slot in the S7-400 rack. Configuration is performed in HW Config (STEP 7 V5.5 / V5.6) or in the TIA Portal (V13 SP1 and higher, via GSD or HSP). The CP's MAC address is printed on the front panel and is required when the network administrator assigns a fixed IP outside of the S7 project.
IP Address Configuration Procedure (STEP 7 V5.x)
- Open SIMATIC Manager and the S7 project containing the CPU 416-3 PN/DP hardware configuration.
- Open HW Config and double-click the CPU 416-3 PN/DP slot. Select the PROFINET Interface tab.
- Click Ethernet Addresses → Properties. The dialog is shown in the S7-400 CPU manual entry 23904550.
- Click New and enter the IP address, subnet mask, and (if applicable) router address. Example values for an isolated SCADA subnet:
IP address: 192.168.0.1 Subnet mask: 255.255.255.0 Router: 0.0.0.0 (none) - Compile and download the hardware configuration to the CPU. After the restart, the CPU's PROFINET port is reachable on the assigned IP.
- Configure the PC's NIC with a same-subnet fixed IP (e.g., 192.168.0.2 / 255.255.255.0). Disable any other active NICs (Wi-Fi, VPN) to avoid routing conflicts.
SCADA / OPC Configuration
For a SIMATIC WinCC or PCS 7 OS, add the S7-400 station via the SIMATIC S7 PROTOCOL SUITE channel and select the TCP/IP driver. Enter the CPU's PROFINET IP address and the rack/slot (always rack 0, slot 3 for the CPU in an S7-400).
For third-party SCADA packages (Ignition, iFIX, Citect, WinCC OA), use either:
- Siemens S7 driver / libnodave / Snap7 over ISO-on-TCP (port 102), or
- OPC UA via the S7-400 OPC UA server (requires CP 443-1 with firmware supporting OPC UA, or an external edge gateway such as the SIMATIC IOT2050)
The default port 102 (ISO-on-TCP / RFC1006) is the standard S7 communication port. The PROFINET port also accepts PG/OP communication on the same port. No additional firewall opening is required if the SCADA PC and the CPU are on the same isolated subnet.
Cable and Wiring Requirements
| Scenario | Cable Type | Max Length | Notes |
|---|---|---|---|
| Direct CPU ↔ PC, modern NIC with Auto-MDIX | Cat 5e UTP patch (straight-through) | 100 m | Simplest, most reliable |
| Direct CPU ↔ PC, old NIC without Auto-MDIX | Cat 5e crossover | 100 m | Verify with link LED on CPU port |
| CPU ↔ SCALANCE ↔ multiple PCs | Cat 5e / Cat 6 UTP/STP patch | 100 m per segment | Use STP (S/FTP) in EMC-noisy cabinets |
| CPU ↔ hub (legacy) | Cat 5e UTP | 100 m | Not recommended; switch preferred |
Verification and Diagnostics
- From the PC, open a command prompt and run
ping 192.168.0.1. A reply with TTL < 64 confirms IP-level connectivity to the CPU's PROFINET port. - In STEP 7, select PLC → Accessible Nodes. The CPU 416-3 PN/DP should appear with its MAC address and the assigned IP. If the CPU is not visible, verify that the firewall on the PC allows ISO-on-TCP port 102 and that the PC and CPU share the same subnet.
- Open the CPU's online diagnostic buffer (PLC → Diagnostic Buffer in SIMATIC Manager) and confirm that the PROFINET interface has reached the RUN state and that no link-down events are logged after the cable was connected.
- Use the CPU's front-panel LED indicators:
LINK(green, link up) andRX/TX(yellow, flashing on traffic). Both LEDs must be active when the SCADA is polling. - From the SCADA, perform a single read of a known tag (e.g., a marker in MB0) and confirm the value updates at the configured poll interval.
Troubleshooting Matrix
| Symptom | Likely Root Cause | Corrective Action |
|---|---|---|
| CPU's LINK LED off | Cable fault, wrong cable type, or port damage | Replace with known-good patch cable; try a SCALANCE switch between PC and CPU to rule out NIC issues |
| Ping fails, LINK LED on | IP/subnet mismatch or PC firewall | Verify IP and subnet mask; temporarily disable Windows Firewall; try arp -d and re-ping |
| SCADA reports "Connection refused" on port 102 | PG/OP or S7 communication disabled in CPU properties | In HW Config → CPU Properties → Protection tab, enable Permit access with PUT/GET if the SCADA uses PUT/GET |
| CPU not visible in Accessible Nodes | PG/OP communication on PROFINET disabled | HW Config → CPU → PROFINET Interface → Enable PG/OP Communication must be checked |
| Intermittent timeouts with PROFINET IO devices on the same port | Hub in the line (collision domain) or excessive broadcast traffic from IT side | Replace hub with SCALANCE switch; isolate SCADA traffic in a separate VLAN |
| SF / BF LEDs on the PROFINET port illuminated | Duplicate IP address in the subnet | Run arp -a on the PC and identify the conflicting device; reassign a unique IP |
Field-Proven Notes
- For a single SCADA PC, the direct CPU-to-PC patch cable is the most reliable configuration. A switch adds only one extra failure point with no benefit in a one-to-one link.
- For PROFINET IO line topology and SCADA on the same physical port, use a SCALANCE switch in the line. The CPU 416-3 PN/DP supports PROFINET Conformance Class B and can act as a PROFINET IO controller while simultaneously serving PG/OP and S7 communication on the same interface.
- If the application is safety-related (F-CPU), the integrated PROFINET interface of the CPU 416-3 PN/DP is the safety bus interface; do not connect a non-safety SCADA on the same port without a SCALANCE S-series security module in front of the SCADA side.
- The HUB question is best answered in 2024+ by saying: use a switch, not a hub. Hubs are no longer manufactured in industrial grade and are not supported in any new PROFINET installation.
FAQ
Does the S7-400 CPU 416-3 PN/DP need a separate Ethernet CP module to talk to a SCADA PC?
No. The CPU has an integrated PROFINET (Ethernet) port on the front panel labelled X1P1 (and X1P2 on later ES06- variants). For a single SCADA PC, connect a patch cable directly between the PC's NIC and the CPU's PROFINET port. An Ethernet CP such as the CP 443-1 is only required if the built-in port is damaged, fully occupied by a PROFINET IO controller role, or you need an additional isolated SCADA subnet.
Can I use a hub (not a switch) between the PC and the CPU 416-3 PN/DP?
Electrically, a 10/100 Mbit/s hub works for a single SCADA PC because the CPU's PROFINET port supports half-duplex. However, a hub must never be used if PROFINET IO devices share the segment — the CSMA/CD collisions violate PROFINET real-time timing. In practice, always use a SCALANCE or any 10/100 unmanaged switch instead.
What is the default IP address of the CPU 416-3 PN/DP out of the box?
0.0.0.0. The CPU ships without an IP address; you must assign one in HW Config (STEP 7 V5.x) or in the TIA Portal device view and download the configuration. A unique IP must be on the same subnet as the SCADA PC's NIC, e.g., CPU 192.168.0.1 / 24 and PC 192.168.0.2 / 24.
Which Ethernet CP can be installed in the S7-400 rack for additional SCADA subnets?
The supported modules are the CP 443-1 (6GK7443-1EX11-0XE0, 10/100 Mbit/s), the CP 443-1 Advanced (6GK7443-1EX30-0XE0, 1 Gbit/s, 4 ports, with IT integration and IP routing), and the CP 443-1 PN (6GK7443-1EX20-0XE0) when a dedicated PROFINET interface is needed. The full list is in Siemens entry 59187251.
Which firmware and STEP 7 version are required for the 6ES7416-3ER05-0AB0?
The CPU 416-3 PN/DP MLFB 6ES7416-3ER05-0AB0 is designed for STEP 7 V5.3 SP2 or higher with the matching hardware support package (HSP). The successor MLFB 6ES7416-3ES06-0AB0 (16 MB work memory) is supported by TIA Portal V13 SP1 and STEP 7 V5.5 with the latest HSP. Refer to the S7-400 CPU product page for the exact HSP and firmware matrix.