SCALANCE W746-1 Not Recovering Link to S7-300 CPU315-2PN: Field Troubleshooting Guide
1. Problem Statement
A SCALANCE W746-1 IWLAN client module connected to a SIMATIC CPU 315-2 PN/DP (V2.6) via a hybrid connector cable periodically loses the Ethernet link to the CPU. The radio link itself (W788 access point ↔ W746-1 client) remains up, but the wired Ethernet segment between the W746-1 and the CPU's PROFINET port freezes. Symptoms include:
- BF2 LED of the CPU 315-2 PN lit red, indicating a bus fault on the PROFINET interface.
- Link LED of the W746-1 Ethernet port dark (off).
- Web UI of the W746-1 reachable over the radio; the "Ethernet" interface shows operational status
Down. - Log file shows alternating
Link Down/Link Upentries prior to the freeze. - Recovery only possible via power-cycle of the W746-1 or a soft restart from its Web UI.
After a restart, the link returns without any intervention on the cable, the connectors, or the CPU. The problem is reproducible on a period of 1–5 days, never on a fixed schedule.
2. System Architecture
The reference installation consists of three CPU 315-2 PN/DP controllers. Two of them communicate over a wired PROFINET ring, the third is mounted on a moving carriage and bridges to the network over an IWLAN segment:
- W788-1 M12 (6GK5788-1AA60-2AA0) — IWLAN access point, mounted on the fixed infrastructure.
- W746-1 M12 (6GK5746-1AA60-4AB0) — IWLAN client, mounted on the moving carriage.
- CPU 315-2 PN/DP (6ES7315-2EH14-0AB0, firmware V2.6) — on the carriage, connected to the W746-1 through the PROFINET port X1.
- Hybrid connector cable — single M12 Hybrid connector carrying 100 Mbit/s Ethernet plus 24 V supply from a power source, terminating in an M12 Hybrid plug at the W746-1 and a free wire end / RJ45 at the CPU side.
- Linear travel — approximately 20 m; client must hand over within the coverage cell.
Communication is implemented with S7 connections, PUT/GET, and ISO-on-TCP transport. No PROFINET IO device is bound to the radio segment; PROFINET IO has been explicitly disabled in the HW Config of the affected CPU.
3. Affected Hardware and Firmware Versions
| Component | Order number / firmware | Relevance to this fault |
|---|---|---|
| SCALANCE W746-1 M12 client | 6GK5746-1AA60-4AB0 | Host of the freezing Ethernet port |
| SCALANCE W788-1 M12 access point | 6GK5788-1AA60-2AA0 | Counterpart; check symmetric configuration |
| Firmware 4.1.11 (W700 family) | Released 2014–2015 era | Recommended baseline, stable 802.11h behavior |
| Firmware 4.1.18 (W700 family) | Released late 2015 | Known regression: 802.11h channels blocked |
| CPU 315-2 PN/DP firmware V2.6 | 6ES7315-2EH14-0AB0 | PN interface supports 100 Mbit full-duplex; check duplex/auto-negotiation |
Always verify the exact article number and firmware with the device's Web UI under Information > Versions before applying any of the recommendations below.
4. Symptom Pattern Analysis
The failure has a specific fingerprint that distinguishes it from a true radio outage:
- The radio path remains usable: the W746-1 Web UI continues to respond over the wireless link from the W788-1.
- Only the wired Ethernet segment between the W746-1 and the CPU's PROFINET port drops.
- The W746-1 logs show several
Link Down / Link Upsequences before the link eventually freezes in theDownstate. - The BF2 LED of the CPU is solid red — the CPU sees no link partner on its PROFINET port.
- A W746-1 restart restores the link without any physical intervention on the cable, connectors, or CPU.
This pattern rules out pure radio coverage problems. It points to one of: the Ethernet PHY in the W746-1, the Ethernet PHY in the CPU, the cable assembly, the connector pin assignment, or a W746-1 software state machine that fails to re-arm the link supervision after a certain number of bounces.
5. Root-Cause Hypotheses
Work the list top-down — fastest and cheapest checks first.
| # | Hypothesis | Why it fits | How to verify |
|---|---|---|---|
| H1 | Mechanical / contact issue on the hybrid connector or its termination | Link bounces precede the freeze, BF2 red, M12 hybrid connectors are sensitive to torque and pin alignment | Visual inspection; replace the entire hybrid lead with a known-good spare; log link bounces after swap |
| H2 | 802.11h channel blocked or temporarily denied by DFS | Firmware 4.1.18 blocks 802.11h channels; DFS radar hits cause channel change with possible reassociation storm | Check Information > WLAN > Radio for channel changes; downgrade firmware or change channel |
| H3 | W746-1 link-supervision state machine stuck | Wired port goes Down and does not re-arm; only a W746-1 restart recovers |
Check for firmware 4.1.x patches; enable Layer2Tunnel MAC mode; observe after firmware change |
| H4 | CPU PROFINET port / duplex mismatch | BF2 solid red, no link LED on the partner; CPU port may be defaulting to 10 Mbit/half or auto-negotiation failure | Force 100 Mbit/full-duplex on both sides; check CPU diagnostic buffer |
| H5 | Excessive multicast / broadcast load on the radio cell | Many Link Up/Down events can be triggered by the CPU re-ARPing or PROFINET DCP chatter when the wired link is being lost repeatedly |
Disable PROFINET discovery on the radio segment; filter non-S7 traffic |
| H6 | Defective W746-1 Ethernet PHY | Power-on works, but after temperature cycles or hours of operation the PHY latches in Down
|
RMA / replace W746-1; observe fault frequency before and after |
| H7 | CPU 315-2 PN/DP internal PN controller fault | Same fault signature has been reproduced with swapped CPUs in the field | Swap CPU; record results in a fault log |
6. Diagnostic Procedure
Perform the following steps in order. Document the result of each step before moving to the next.
6.1 Capture the current configuration and logs
- On the W746-1, open the Web UI (
https://<IP of W746>). - Navigate to System > Load & Save and download the configuration file (CPL).
- Download the log file from Information > Log Table > Save.
- From the W788-1 access point, repeat step 2 and 3.
- From the CPU, read the diagnostic buffer with STEP 7 / TIA Portal: CPU > Diagnostic Buffer.
6.2 Inspect the hybrid connector and cable
- Power down the W746-1 and the CPU.
- Disconnect the hybrid connector at the W746-1 end.
- Inspect the pins under a magnifier: look for bent or recessed pins, contamination, and proper seating of the contact carrier.
- Check the recommended torque (M12 hybrid typically 0.6 Nm) — over- and under-torque both cause intermittent contact.
- Inspect the cable run for kinks, abrasion, oil ingress, and minimum-bend-radius violations.
- Re-seat the connector, torque to spec, power up, and observe for 24 h.
6.3 Validate the radio segment
- On the W788-1: Information > WLAN > Clients; confirm the W746-1 is associated and the signal level is stable.
- On the W746-1: Information > WLAN > Radio; note the current channel, channel changes, and TX power.
- Cross-check the channel against your local regulatory domain. With 802.11h (5 GHz outdoor) the device must support DFS (Dynamic Frequency Selection) and TPC (Transmit Power Control).
6.4 Reproduce the fault deterministically
Before changing any configuration, prove that the fault is reproducible and that you have a baseline:
- Connect a managed switch or a tap between the W746-1 and the CPU to capture Ethernet frames (e.g., a SPAN port with Wireshark).
- Run a continuous S7 PUT/GET traffic generator between the master CPU and the moving CPU.
- Let the system run until a freeze occurs. Note the time of the freeze and the last 100 frames on the wired side.
- Trigger a W746-1 restart and capture the re-arm sequence.
This data set becomes the baseline against which every fix is measured.
7. Configuration Optimization
7.1 Channel selection
802.11h is a 5 GHz regulatory domain for outdoor use and requires DFS. DFS radar hits force the radio to vacate the channel for 30 minutes, which can cause repeated client re-associations and link bounces. To reduce churn:
- Use DFS-free channels where the regulatory domain permits. In Europe, channels 36, 40, 44, 48, 149, 153, 157, 161, 165 are typically DFS-free. Channel 140 is often the first 5 GHz choice for industrial outdoor use in Europe because it balances availability and bandwidth.
- If 802.11h is not required by local regulation, prefer 802.11a/n on a DFS-free channel instead.
- Disable automatic channel selection; pin both AP and client to the same channel.
7.2 MAC Mode = Layer2Tunnel
For radio segments that carry only S7 / PUT/GET traffic — and no PROFINET IO — set the MAC mode of the W746-1 to Layer2Tunnel. This mode transports Layer 2 frames transparently across the radio link without performing PROFINET DCP or LLDP forwarding. In the W746-1 Web UI:
- Layer 2 > MAC Mode.
- Set MAC Mode to
Layer2Tunnel. - Save and activate.
Layer2Tunnel reduces broadcast / multicast load on the radio cell and avoids spurious DCP discovery frames, which directly addresses hypothesis H5.
7.3 Link supervision and port settings
- On the W746-1: Layer 2 > Ethernet > Port. Disable Auto-Negotiation and force
100 Mbit/s Full-Duplexon the port that connects to the CPU. - On the CPU 315-2 PN/DP, in HW Config / device configuration, set the PROFINET port to
100 Mbit/s Full-Duplex, auto-negotiation off, autocrossing on. - Disable Energy Efficient Ethernet (EEE / 802.3az) on both sides if it is available; EEE can interact poorly with industrial real-time stacks.
- Enable Link Aggregation only if the CPU supports it; do not aggregate on a single cable.
7.4 Disable PROFINET IO and DCP forwarding on the radio segment
Because the radio segment carries only S7 / PUT/GET:
- In HW Config of the affected CPU, remove any PROFINET IO device assignment on the PROFINET interface that traverses the radio.
- On the W788-1 and W746-1, disable the PROFINET device role and DCP forwarding so DCP discovery frames do not leak across the radio cell.
- Verify with a filtered port mirror that no PROFINET DCP multicast frames are crossing the radio after the change.
8. Firmware Update Procedure
- Download the firmware 4.1.11 image for the W700 family from the Siemens Industry Online Support (entry point: Siemens Industry Online Support; search for the article "SCALANCE W700 firmware 4.1.11").
- Verify the SHA / MD5 of the download against the value published on the Siemens entry page.
- On the W788-1, update first: System > Load & Save > Firmware. Activate, then reboot.
- Update the W746-1 the same way.
- Restore your configuration from the CPL backup you made in §6.1, or re-import via the configuration file.
- Re-apply the changes from §7 (Layer2Tunnel, fixed 100 Mbit/FD, channel 140, DCP off).
- Run a 72 h soak test with the link monitor described in §6.4.
9. Hardware & Cabling Verification
If the software changes do not eliminate the fault, escalate to the hardware layer.
9.1 Replace the hybrid cable end-to-end
- Pull a known-good hybrid cable from stock.
- Verify pinout against the W746-1 wiring diagram (M12 Hybrid: 8 pins, 100 Mbit Ethernet on pins 1, 2, 3, 6; 24 V on pins 4, 5; GND on pin 7; PE on pin 8).
- Use a cable tester suitable for M12 hybrid: check each Ethernet pair, each power pin, and the shield.
- Re-install, torque, and observe.
9.2 Bypass the hybrid connector temporarily
- Power the W746-1 from an external 24 V supply (separate from the hybrid cable).
- Connect the W746-1 to the CPU with a standard Cat 5e / Cat 6 RJ45 patch cord, using an M12-to-RJ45 media converter if required.
- Run the system for 24–48 h.
- If the fault does not reproduce, the hybrid cable / connector is the cause. If it reproduces, the fault is in the W746-1 or the CPU.
9.3 Swap the W746-1
- Replace the W746-1 with a known-good spare.
- Apply the same configuration (CPL).
- Run a 72 h soak test.
- If the fault disappears, RMA the original W746-1.
9.4 Swap the CPU
- Replace the CPU 315-2 PN/DP with a spare of the same article number.
- Restore the STEP 7 project.
- Observe for one full fault cycle (typically 1–5 days in this installation).
10. Long-Term Stability Improvements
10.1 Watchdog S7 connection
Add an application-level watchdog on top of the S7 connection so the moving PLC can detect a frozen link even if BF2 is latched:
- A separate S7 connection per pair of CPUs carries a 1-Hz counter.
- The receiving CPU checks that the counter is incrementing; if it stalls for more than 3 s the application enters a safe state.
- This does not fix the root cause, but it contains the impact and gives the maintenance team time to roll a truck.
10.2 Scheduled W746-1 maintenance reboot
If after firmware update and cable replacement the fault is rare (one cycle per 30 days), a scheduled nightly reboot of the W746-1 is an acceptable mitigation. Schedule via the Web UI under System > Restart or via SNMP/NTP-based scripts.
10.3 Antenna placement review
- Verify line-of-sight along the 20 m of linear travel.
- Use directional antennas at both ends to reduce multi-path and DFS radar false-positives.
- Document RSSI and SNR at the extremes of the travel; a target of ≥ 50 dB SNR at the worst point is a useful industrial guideline.
10.4 Log and trend
- Configure the W746-1 to send its log to a syslog server (PRONETA, SINEC NMS, or any standard syslog collector).
- Trend
Link Down/Link Upcounts. A sudden increase is an early warning. - Trend CPU diagnostic buffer for PROFINET port events. STEP 7's diagnostic buffer is the canonical source of truth for the CPU side.
11. Verification Matrix
| Fix applied | What to measure | Pass criterion |
|---|---|---|
| Firmware 4.1.11 on W788-1 and W746-1 | 802.11h channel stability over 72 h | No channel change events |
| Layer2Tunnel MAC mode | Multicast / broadcast rate on radio | < 50 frames/s sustained |
| 100 Mbit/Full-Duplex, no autoneg | Wired port up-time | 0 link drops in 7 days |
| DCP forwarding off on radio segment | PROFINET DCP frames crossing radio | 0 DCP frames observed |
| Hybrid cable replaced | Continuity, shield resistance | All pairs pass; shield < 1 Ω |
| W746-1 swapped | Fault recurrence | 0 freezes in 14 days |
| CPU swapped | Fault recurrence | 0 freezes in 14 days |
12. Field-Commissioning Checklist
- Confirm article numbers of W788-1, W746-1, CPU, and hybrid cable against the bill of materials.
- Confirm firmware of W788-1, W746-1, and CPU matches the project specification.
- Pin the radio channel on both ends (recommended: 140 in EU, or a DFS-free channel in your domain).
- Force 100 Mbit/Full-Duplex on the W746-1 wired port and on the CPU's PROFINET port.
- Set MAC mode to
Layer2Tunnelon the W746-1. - Disable PROFINET DCP forwarding on the radio segment.
- Configure syslog to a central collector.
- Run a 72 h soak test with continuous PUT/GET traffic.
- Document the as-built configuration, antenna positions, and signal levels.
- Schedule a 6-monthly review of the trend logs.
Why does the W746-1 log show Link Down / Link Up repeatedly before it freezes?
The most common cause is mechanical: a hybrid connector with marginal contact, incorrect torque, or contamination. The radio logs the bounce, the PHY re-negotiates, and after a number of cycles the W746-1's link-supervision state machine fails to re-arm. Inspect and replace the hybrid lead first.
Which SCALANCE W700 firmware should I use and which should I avoid?
Use firmware 4.1.11 for the W788-1 and W746-1. Avoid firmware 4.1.18 — it temporarily blocks 802.11h channels. After every firmware update, re-apply your configuration (channel, MAC mode, port speed) and re-test for at least 72 h.
Which channel should I pick for 802.11h outdoor use?
For most EU outdoor installations, channel 140 is a good industrial default. Always pick a DFS-free channel where your regulatory domain allows it and pin it on both the W788-1 and the W746-1 to avoid automatic channel changes.
Should I set the W746-1 MAC mode to Layer2Tunnel when I only use PUT/GET?
Yes. Layer2Tunnel transports Layer 2 frames transparently without PROFINET DCP or LLDP forwarding, which lowers broadcast and multicast load on the radio cell and removes a class of spurious DCP discovery frames that can destabilise the radio link.
The fault is rare after the fixes — can I just schedule a nightly reboot of the W746-1?
It is acceptable as a last-resort mitigation, not as a fix. Schedule it under System > Restart or via SNMP, and keep trending the log so the underlying fault does not get worse while the reboot masks it.