S7 Routing with S7-300 and TP177A: HMI Download Limitations

David Krause13 min read
Industrial NetworkingSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

S7 Routing with S7-300 and TP177A: HMI Download Limitations

S7 routing enables a programming device (PG/PC) or HMI engineering station to cross subnet boundaries and reach a target CPU that is not directly attached to the same physical network. For an installation built around a CPU 315-2DP, a CP343-1 Lean communications processor, and a TP177A basic panel on PROFIBUS, the question is whether the panel project can be downloaded from an Ethernet-attached PG/PC through the S7-300 station acting as a router.

This reference documents the topology, the required CP firmware and STEP 7 / WinCC flexible options, and the panel-specific limitations that determine whether HMI transfer via S7 routing actually succeeds on a TP177A. It also documents the supported workarounds when the basic panel cannot act as the routing endpoint.

1. S7 Routing Fundamentals

S7 routing is the transport of PG/PC and HMI telegrams beyond a single S7 subnet boundary. A gateway CPU or communications processor forwards the telegram from the entry subnet to the exit subnet using configured S7 connections and route information stored in the project's S7 subnet topology.

Per the Siemens function manual, S7 routing allows the transfer of data "from a transmitter to a receiver across several S7 subnets." Routing is possible over Ethernet, PROFIBUS, and MPI subnets, with the PG/PC reaching devices beyond subnet limits without a direct physical connection to every subnet.

Key routing characteristics that affect the S7-300 + TP177A case:

  • Routing requires a station that physically sits on both subnets and is configured as a router. In the topology above, only the S7-300 station (CPU 315-2DP plus CP343-1 Lean) bridges Ethernet and PROFIBUS.
  • The routing function must be enabled on the gateway module. On CP343-1 Lean this is a license-free firmware feature; it does not require the routing plug-in or "S7-Routing" add-on that legacy MPI/CP cards once required.
  • Both the source and target S7 stations must be assigned to their respective subnets in the STEP 7 or TIA Portal project. A floating station that is not assigned to a subnet cannot be reached by a routed telegram.
  • The PG/PC interface must be assigned to the entry subnet (Ethernet in this case) and the target station must be in a downstream subnet (PROFIBUS).

2. Reference Topology

The installation addressed by this article is summarized in the diagram below.

PG / PC Ethernet CPU 315-2DP 6ES7 315-2AG10 CP 343-1 Lean 6GK7 343-1CX10 TP177A PROFIBUS Ethern DP backplane

The S7-300 station is the only router in this topology. There is no Ethernet-attached HMI; the TP177A connects only to PROFIBUS.

3. Hardware and Firmware Prerequisites

Component Order Number Minimum Firmware Routing Capable
CPU 315-2DP 6ES7 315-2AG10-0AB0 (or -2AH14) V2.0+ Yes (DP port)
CP 343-1 Lean 6GK7 343-1CX10-0XE0 V1.0+ Yes (Ethernet)
TP177A 6" mono 6AV6 642-0AA11-0AX0 — Limited (see §6)
TP177B 6" color 6AV6 642-0DC11-0AX0 — Yes (2-port)

The CP343-1 Lean supports S7 routing by default; no additional configuration flag or routing license is required in STEP 7 V5.x or TIA Portal. The "Use router" or "Activate routing" option in the CP properties is enabled by default on firmware V2.0 and later.

The TP177A is a single-port basic panel. It has only one PROFIBUS / MPI combined interface; it cannot terminate Ethernet. This hardware limitation is the root cause of the routing behavior described in §6.

4. STEP 7 V5.x Project Configuration

For a STEP 7 V5.x + WinCC flexible 2008 SP2/SP3 project, configure routing as follows.

4.1 Assign the PG/PC to the Ethernet subnet

  1. Open SIMATIC Manager and select Options → Set PG/PC Interface.
  2. Choose TCP/IP → <your NIC> for the Ethernet subnet that contains the CP343-1 Lean.
  3. In Options → PG/PC Station → Properties, ensure the Ethernet subnet is the access point assigned to the project.

4.2 Build the subnet topology

  1. Insert an Industrial Ethernet subnet and a PROFIBUS subnet in the project.
  2. Place the CP343-1 Lean onto the Ethernet subnet and the CPU 315-2DP's DP port onto the PROFIBUS subnet. The CP is automatically linked to the CPU via the backplane.
  3. Place the TP177A onto the PROFIBUS subnet at a free PROFIBUS address (default 1).
  4. Configure a unique PROFIBUS address for the CPU 315-2DP's DP master (default 2).

4.3 Enable routing on the gateway CP

  1. Open the CP343-1 Lean properties.
  2. Confirm the IP address, subnet mask, and router address (if any) are correct.
  3. In older STEP 7 versions, a checkbox labeled "Activate router / Use router" may appear under Properties → Options. Enable it. If the option is absent, routing is implicitly active.

4.4 Configure the WinCC flexible transfer channel

  1. In WinCC flexible 2008, open the TP177A project and choose Project → Transfer → Transfer settings.
  2. Set the channel to S7 Ethernet and enter the CP343-1 Lean's IP address as the access point.
  3. Tick Enable routing. WinCC flexible will populate the PG/PC station and HMI station route information from the STEP 7 project.
  4. Save and close the transfer dialog.

The "Enable routing" tick is only available when the HMI station is on a different subnet than the PG/PC station. If the option is greyed out, the project is missing the subnet assignment for either the TP177A or the CP343-1 Lean.

5. TIA Portal Configuration

In TIA Portal V13 SP1 and later, S7 routing is configured differently than in STEP 7 V5.x.

  1. Add the CPU 315-2DP and CP343-1 Lean to the device configuration. TIA Portal automatically creates the S7 connection between the CPU and CP.
  2. In Devices & Networks, assign the CP to an Ethernet subnet (PROFINET subnet) and the CPU's DP port to a PROFIBUS subnet.
  3. Add the HMI to the PROFIBUS subnet. For a TP177A, choose SIMATIC HMI → 170/177 → TP177A 6" mono PN/DP from the catalog.
  4. Open the HMI's Properties → Transfer and select S7 Ethernet as the transfer channel. TIA Portal will offer to use the CP343-1 Lean as the access point of the HMI when the panel is on PROFIBUS only.
  5. Compile the project and download to the CPU. The HMI transfer settings are downloaded with the project; the panel stores the routing path at next transfer.
Note: TIA Portal does not require a separate "Enable routing" checkbox. The router is implicit in the topology. However, the HMI transfer settings must still list the Ethernet access point explicitly; otherwise the transfer will only work when the PG/PC is on PROFIBUS.

6. TP177A-Specific Routing Limitation

This is the central technical question of the original inquiry. Siemens' official WinCC flexible 2008 documentation (entry ID 32235096, FAQ note 4) explicitly lists the panels that support S7 routing for HMI download. The TP177A is not on that list. Supported basic panels in the relevant Siemens list include the OP77B and TP177B.

The functional reason: S7 routing requires the receiving device to participate as an S7 station on the source subnet. The TP177A has only a PROFIBUS interface. For the PG/PC to route an HMI download through the TP177A (i.e. with the TP177A as the final destination on PROFIBUS), the panel itself must accept the S7 routing telegram on its PROFIBUS interface. WinCC flexible 2008 exposes a "S7 Ethernet → Enable routing" option in the transfer dialog for the TP177A, but the panel firmware does not complete the routing handshake in the same way the TP177B or OP277 does.

The observable behavior when the option is exercised on a TP177A:

  • WinCC flexible reports "Transfer started" and may even show a progress bar.
  • The CP343-1 Lean accepts the routed telegram on its Ethernet interface and forwards it to PROFIBUS.
  • The TP177A does not acknowledge the routing telegram and the transfer eventually fails with a timeout or "Panel not responding" error.
Engineering decision path:
  • If the HMI must be downloaded over Ethernet via S7 routing: replace the TP177A with a TP177B (or larger 2-port panel). The TP177B has the same form factor and project compatibility but accepts routed transfers.
  • If the TP177A must be retained: do the HMI transfer over PROFIBUS directly from a PG/PC attached to the PROFIBUS segment, or use a PROFIBUS-to-USB CP (e.g. 6GK1 571-1AA00) on the engineering station.
  • Alternatively, configure a remote-PROFIBUS gateway (e.g. IE/PB Link PN IO) on Ethernet and use it to bridge into the PROFIBUS segment from the PG/PC; this is plain bridging, not S7 routing, but achieves the same result for HMI transfer.

7. WinCC flexible 2008 Transfer Options Mapped to Hardware

Panel Interfaces "S7 Ethernet → Enable routing" visible Routed download works
OP77B PROFIBUS/MPI Yes Yes
TP177A PROFIBUS/MPI Yes (UI only) No (per Siemens note 4)
TP177B PROFIBUS/MPI Yes Yes
KTP600 Basic PROFINET Yes Yes (PROFINET native)
MP277 PROFINET + PROFIBUS Yes Yes

The "visible" column reflects the WinCC flexible 2008 transfer dialog behavior. The "works" column reflects what Siemens officially supports. The asymmetry is what creates confusion during commissioning.

8. Step-by-Step: Download TP177A from Ethernet-Attached PG/PC

The following sequence produces a successful HMI transfer to the TP177A when the PG/PC is on Ethernet.

  1. Confirm PG/PC Ethernet reachability. From the engineering station, ping the CP343-1 Lean's IP address. A reply confirms the Ethernet subnet and routing prerequisites are in place.
  2. Confirm CPU PROFIBUS reachability via routed path. In SIMATIC Manager choose PLC → Display Accessible Nodes. The CPU 315-2DP should appear in the list with the CP343-1 Lean's IP address as the access point.
  3. Open WinCC flexible and load the TP177A project. Confirm the HMI station is bound to the PROFIBUS subnet and the S7 connection points to the CPU 315-2DP.
  4. Open the transfer dialog. Set channel = S7 Ethernet, Access Point = CP343-1 Lean's IP address, tick Enable routing.
  5. Attempt transfer. On the TP177A, set Transfer mode via the control panel (the panel must be in transfer/ready mode).
  6. Capture the result. Record whether the transfer completes, hangs, or errors. If it hangs and ultimately times out, the TP177A routing limitation applies; switch to the workaround below.

8.1 Workaround for the TP177A Limitation

  1. Disconnect the engineering station from Ethernet and connect it to the PROFIBUS segment using a USB-PROFIBUS adapter (CP 5711, order number 6GK1 571-1AA00) or a PC adapter (PC Adapter USB A2, 6GK1 571-2AA00).
  2. In SIMATIC Manager set the PG/PC interface to PROFIBUS.
  3. Open WinCC flexible, point the transfer channel at PROFIBUS, untick Enable routing (the option will grey out anyway).
  4. Initiate transfer. The TP177A accepts the project directly over PROFIBUS without S7 routing.

9. IE/PB Link as an Alternative to S7 Routing

When the TP177A must be reached over Ethernet but cannot act as the routed endpoint, an IE/PB Link PN IO (6GK1 411-5AB00) acts as a transparent PROFIBUS master on the PROFIBUS side and an Ethernet/PROFINET node on the other. It is configured as a PROFINET device on the same Ethernet subnet as the CP343-1 Lean, and as a PROFIBUS master in front of the TP177A.

Configuration in TIA Portal:

  1. Add the IE/PB Link from the catalog: Network components → IE/PB Link PN IO.
  2. Assign it to the same PROFINET subnet as the CP343-1 Lean.
  3. Configure its PROFIBUS master interface with a free master address (e.g. 3) and assign the TP177A as a PROFIBUS slave at address 1.
  4. The PG/PC now uses the IE/PB Link's PROFINET interface as the access point for the TP177A. No S7 routing is involved; the IE/PB Link is a media converter.

This topology also works with STEP 7 V5.x and WinCC flexible 2008 if the IE/PB Link is added via GSD file import. The IE/PB Link PN IO GSD file is available from Siemens support (entry ID 23624770 at the time of writing).

10. Diagnostic and Verification

After configuration, verify the routing path with the following checks.

Check Tool Expected Result
Ethernet connectivity PG → CP343-1 Lean ping Reply < 1 ms LAN
CPU accessible over routed path SIMATIC Manager → Accessible Nodes CPU 315-2DP listed with CP IP as access point
CP routing flag CP properties → Options Routing enabled
WinCC flexible transfer Transfer dialog Channel = S7 Ethernet, routing tick present
HMI transfer completes WinCC flexible 100% with no errors

10.1 Online diagnostics on the CP343-1 Lean

Open the CP online diagnostic in STEP 7. The connection list should show the S7 connections the CP has established with both the PG/PC and the CPU. If the routed connection to the CPU is absent, the CP routing flag or the subnet assignment is misconfigured.

10.2 PROFIBUS diagnostics

On the CPU 315-2DP, open PLC → Module Information → Diagnostic Buffer. Look for DP slave diagnostic events corresponding to the TP177A's PROFIBUS address. "Slave not found" indicates the PROFIBUS wiring or address is at fault rather than the routing configuration.

11. Troubleshooting Matrix

Symptom Likely Cause Corrective Action
"Enable routing" greyed out in WinCC flexible HMI and PG/PC on same subnet, or HMI subnet not assigned Assign TP177A to PROFIBUS subnet in SIMATIC Manager
CPU not visible from Ethernet in Accessible Nodes CP routing flag off, or CP IP misconfigured Enable routing on CP343-1 Lean; verify IP/subnet
Transfer starts, then times out on TP177A TP177A firmware does not support S7 routing for HMI transfer Use PROFIBUS-direct transfer or replace with TP177B
Transfer starts, panel restarts, project not loaded Incompatible WinCC flexible image / panel firmware Update panel firmware to match project; check ProTool/WinCC flexible compatibility list
CP343-1 Lean returns SF (red LED) Ethernet link or duplicate IP Check Ethernet cable; verify unique IP on the subnet
PROFIBUS BF on CPU 315-2DP Wiring, termination, or address conflict Verify PROFIBUS connectors, terminating resistors, address uniqueness

12. Field-Commissioning Notes

  • Document the CP343-1 Lean's MAC and IP address in the project sheet. Field engineers need both to re-establish Ethernet routing after a CP replacement.
  • If the CP is replaced, the new CP must be assigned the same IP address before the project is downloaded; otherwise the HMI's stored transfer target becomes invalid.
  • WinCC flexible 2008 SP3 is the last version with TP177A support. WinCC flexible 2008 SP5 and TIA Portal maintain TP177A as a legacy device via HSP. Plan firmware and project migration accordingly.
  • For remote service over a VPN or cellular router, the Ethernet side of the topology behaves identically. S7 routing is independent of the WAN medium.
  • Timeouts in S7-routed HMI transfer are typically 60 s by default in WinCC flexible. Increase Options → Settings → Transfer → Timeout to 180 s when transferring over a high-latency link.

13. Reference Standards and Siemens Documentation

Can I download a TP177A HMI project over Ethernet through an S7-300 station?

No, not reliably. WinCC flexible 2008 exposes an "Enable routing" option for the TP177A, but the panel does not complete the routing handshake. Use a direct PROFIBUS connection, an IE/PB Link PN IO as a media converter, or replace the panel with a TP177B which supports S7-routed transfer.

Does the CP343-1 Lean need a routing license?

No. The CP343-1 Lean (6GK7 343-1CX10-0XE0) supports S7 routing by default on firmware V1.0 and later. Confirm the "Activate router" property is enabled in STEP 7 or TIA Portal, and ensure both subnets (Ethernet and PROFIBUS) are defined in the project.

Which basic panels support S7 routing for HMI transfer?

Per Siemens support entry 32235096, supported basic panels include the OP77B and TP177B. The TP177A is explicitly excluded despite showing the option in the WinCC flexible 2008 transfer dialog.

How can I reach the TP177A remotely without changing the panel?

Add an IE/PB Link PN IO (6GK1 411-5AB00) on the Ethernet side as a PROFIBUS master in front of the TP177A. The engineering station then reaches the panel through the IE/PB Link without using S7 routing at the panel itself.

Why is "Enable routing" greyed out in the WinCC flexible transfer dialog?

The option is only available when the HMI station is on a different subnet than the PG/PC station. If both are on PROFIBUS or the TP177A is not assigned to any subnet in SIMATIC Manager, the checkbox is disabled. Re-assign the panel's subnet first.

Back to blog