Problem Overview
The SCALANCE XC216 (Siemens part number 6GK5216-0BA00-2AC2 and related variants in the XC-200 family) is an industrial Ethernet switch with Layer 3 functionality, including NAT, static routing, and subnet management. When Layer 3 NAT is enabled and a default gateway is configured under Layer 3 > Subnets > Default Gateway, the gateway IP is lost and reverts to 0.0.0.0 after a complete power cycle. The internal real-time clock simultaneously resets to 2000-01-01 00:00:00, indicating that the device is reverting to factory-state configuration.
This condition affects SCALANCE XC-200, XB-200, XF-200BA, XP-200, and XR-300WG models running older firmware, where persistent storage of Layer 3 parameters may be overwritten by an attached S7 PLC or DHCP server. Confirm the symptom with both a Web-Based Management (WBM) page refresh and a PING from a downstream node once the gateway disappears.
Affected Hardware and Firmware
| Device Family | Order Number (example) | Affected Firmware | Recommended Firmware |
|---|---|---|---|
| SCALANCE XC216 | 6GK5216-0BA00-2AC2 | FW 4.0.0.0 (2018) | FW 4.5.x (current) |
| SCALANCE XC224 | 6GK5224-0BA00-2AC2 | FW 4.0.x | FW 4.5.x |
| SCALANCE XC206-2SFP | 6GK5206-2BS00-2AC2 | FW 4.0.x | FW 4.5.x |
| SCALANCE XB-200 | 6GK5x2x-x | FW 4.0.x | FW 4.5.x |
| SCALANCE XR-300WG | 6GK5x04-x | FW 4.0.x | FW 4.5.x |
Root Cause Analysis
Three independent mechanisms can force the default gateway back to 0.0.0.0 after a power cycle on a SCALANCE XC-200 device. Identify which one applies before changing configuration.
Cause 1 - DHCP client overrides static gateway
If the DHCP client is enabled in System > Configuration, the device requests its IP, subnet mask, and default gateway from a DHCP server on power-up. Any preconfigured static gateway is discarded once the lease is applied, even when the DHCP server returns no router information. The default gateway field will display 0.0.0.0 if no router option (option 3) is provided.
Check the configuration flag DHCP Client = Enabled under System > DHCP > DHCP Client. On current firmware, the WBM disables this option automatically when a static IP is committed. Firmware V4.0 may fail to retain that state.
Cause 2 - S7 / PROFINET PLC forces network parameters
When the SCALANCE XC216 is connected to a SIMATIC S7-1200, S7-1500, or ET 200SP CPU as a PROFINET device, the PLC's startup configuration may include IP-suite assignment via PROFINET device > PROFINET interface > IP Suite. The CPU pushes its IP, subnet mask, and router value to the switch on every PROFINET AR (Application Relationship) establishment, overwriting any value set in the WBM.
This behavior is by design in PROFINET conformance class B/C and is implemented through record-data write operations during AR establishment. The PLC's IP Suite block becomes the source of truth; the WBM gateway is treated as a non-persistent display value.
Cause 3 - RTC battery / capacitor discharged (time = 2000-01-01)
The simultaneous reset of system time to 2000-01-01 00:00:00 strongly suggests the SCALANCE has reverted to factory defaults rather than merely losing one parameter. Time-only loss with preserved configuration usually points to a discharged RTC backup capacitor or missing SNTP/NTP server reachability after reboot. Full reset (gateway + time + other volatile state) is consistent with a startup configuration reload because the stored configuration was marked invalid or was overwritten on a previous save.
Diagnostic Steps
-
Capture WBM state before power cycle. Log in to
https://<IP>, navigate to Layer 3 > Subnets > Default Gateway and record the value, then to System > Information and record firmware version, serial number, and uptime. - Power-cycle the device by removing both power inputs (L1/M and L2/M on the terminal block) for at least 30 seconds, then reapply.
-
Re-open WBM and confirm: (a) gateway reverts to
0.0.0.0, (b) system time is2000-01-01 00:00:00, (c) NAT rule and static routes are still present. - Disconnect the PLC uplink from port P1 (the designated PROFINET port on XC-200) and repeat the power cycle. If the gateway is now retained, the PLC is forcing the parameter (Cause 2).
- Enable DHCP Client check in System > DHCP. Toggle to Disabled, click Set Values, then perform a power cycle and re-check.
-
Check event log under Information > Log Table > System Log. Look for entries containing
Configuration loaded,Factory defaults restored, orIP suite received from PROFINET IO controller.
Resolution Procedure
Apply the corrective sequence in order. Stop and verify at each step before proceeding.
Step 1 - Disable DHCP client
From WBM, navigate to System > DHCP > DHCP Client. Uncheck DHCP Client enabled. Click Set Values. The dialog must show the checkbox cleared and the assigned IP type must read static. If the checkbox reappears after Set Values, the configuration commit has failed; reload the page and retry.
Step 2 - Remove PLC IP-Suite forcing
Open the TIA Portal project that owns the SCALANCE XC216 device. In the device properties of the SCALANCE, navigate to PROFINET interface > Ethernet addresses and clear the IP Suite assignment so the PLC does not push network parameters. Alternatively, change the SCALANCE device role in TIA Portal from PROFINET IO Device to Standard Ethernet Node by removing the PROFINET device configuration from the project entirely. Recompile and download to the PLC.
If the SCALANCE is intended to be a managed switch (not a PROFINET IO device), the correct TIA Portal configuration is to add it under Devices & networks as an unmanaged or managed switch without placing it under a PROFINET IO controller.
Step 3 - Re-enter the default gateway
Reconnect to the SCALANCE WBM. Navigate to Layer 3 > Subnets > Default Gateway. Enter the router IP (for example 192.168.10.1). Click Set Values, then Commit. On firmware V4.5 and later, the gateway is written to non-volatile storage immediately.
Step 4 - Configure NTP / SNTP time source
Navigate to System > Time > SNTP Client. Enter an NTP server address (for example the PLC at 192.168.10.10 if it acts as an NTP server, or a plant NTP source). Click Set Values. Verify System > Information > Current System Time updates within 60 seconds. If the plant has no NTP source, manually set the time once after every power cycle until the firmware update is applied.
Step 5 - Save configuration to non-volatile memory
Navigate to System > Configuration > Save. Click Save. The dialog returns Configuration saved successfully when the write to internal flash completes. Without this step, parameters set via the WBM are kept in RAM only and are lost on the next power cycle regardless of firmware version.
Step 6 - Power-cycle verification
Remove power for 30 seconds, restore, and verify:
- Default gateway still equals the configured value.
- System time is within 1 second of the NTP source.
- NAT rule still translates traffic between the two IP domains.
- Event log shows Configuration loaded with no Factory defaults restored entry.
Firmware Update Procedure
Updating to the current V4.5.x firmware eliminates the V4.0 volatile-storage behavior. Obtain the signed firmware from the Siemens Industry Online Support portal entry listed below. The image includes SCALANCE_XC200_V04_05_00_xx.sfw and a release note describing corrected defects.
- Download the firmware package and verify the SHA-256 checksum against the value published on the Siemens support page.
- Open WBM, navigate to System > Firmware > Firmware Update.
- Click Select File and choose the
.sfwimage. Confirm the displayed version matches the expected target (for example4.5.0.x). - Click Load. The device restarts automatically once the upload completes. Do not interrupt power during this step.
- After restart, re-verify gateway, NAT rule, and time. The first restart after firmware update always resets Layer 3 parameters and time to defaults; restore them and click Save.
Configuration Reference
| Menu Path (WBM) | Parameter | Recommended Value | Notes |
|---|---|---|---|
| System > DHCP > DHCP Client | DHCP Client | Disabled | Required for static gateway persistence |
| Layer 3 > Subnets > Default Gateway | Default Gateway | Plant router IP (e.g., 192.168.10.1) | Written to NVRAM only on explicit Save |
| Layer 3 > NAT > NAT Rules | NAT mapping | Per site | Survives reboot if Commit & Save performed |
| System > Time > SNTP Client | NTP Server | 192.168.10.10 (or plant source) | Eliminates time reset on reboot |
| System > Configuration > Save | Save current configuration | Click after every change | RAM-only until Save is invoked |
| System > Restart > Restart | Restart device | Used after firmware update | Volatile state cleared on restart |
NAT Layer-3 Behavior on SCALANCE XC-200
The XC-200 family supports both 1:1 NAT and NAPT (Network Address Port Translation) under Layer 3 > NAT. NAT rules reference the configured subnet entries under Layer 3 > Subnets. The default gateway must be reachable from the source interface for return traffic to be accepted by upstream routers; a 0.0.0.0 gateway causes NAT sessions to fail silently and shows as no route in the diagnostic trace.
When the gateway is missing, NAT-translated packets still leave the device but with no return path, producing one-way communication. Confirm with a downstream tracert (Windows) or traceroute (Linux) from a node behind the NAT. A * at the first hop indicates the SCALANCE is not advertising a route because its default gateway is unset.
Interaction with PROFINET IO Controller
SCALANCE XC-200 switches used as PROFINET devices receive configuration records during AR establishment per the PROFINET specification. The IO controller (PLC) writes the IP suite record to the device's PROFINET interface. Even when WBM is used to set the gateway, the IO controller's record write overrides it at the next AR restart, which occurs at every PLC restart, network reconfiguration, or AR break-and-rebuild.
To preserve the WBM-set gateway, either:
- Remove the IP Suite assignment from the PLC project (TIA Portal > Device properties > PROFINET interface > Ethernet addresses > IP Suite > clear values).
- Remove the SCALANCE from the PLC's PROFINET topology and manage it as a stand-alone managed switch with its own IP address.
- Use a SCALANCE in PROFINET conformance class A mode where the IO controller does not push IP parameters.
Verification Checklist
- WBM shows default gateway equal to the configured value after power cycle.
- System time updates from NTP and remains correct after power cycle.
- NAT rule still translates traffic between subnet A and subnet B.
- Static routes under Layer 3 > Static Routes are intact.
- Event log contains no Factory defaults restored or Configuration invalid entries after reboot.
- Downstream node successfully reaches a host on the far side of the NAT with
ping -tstable for 5 minutes. - PROFINET diagnostic in TIA Portal > Online > Diagnostics shows the SCALANCE with status No fault.
Troubleshooting Matrix
| Symptom | Likely Cause | Corrective Action |
|---|---|---|
| Gateway = 0.0.0.0 only when PLC is connected | PLC IP Suite forcing | Clear IP Suite in TIA Portal or remove SCALANCE from PROFINET topology |
| Gateway = 0.0.0.0 after every power cycle regardless of PLC | DHCP client enabled or NVRAM commit missed | Disable DHCP client, click Save, update firmware |
| Time resets to 2000-01-01 after reboot | No NTP source or volatile NVRAM | Configure NTP and update firmware to V4.5 |
| NAT rules present but no traffic flows | Gateway missing; return route absent | Set default gateway; verify with traceroute |
| Configuration disappears on every reboot | Save not invoked, or firmware < V4.3 | Invoke Save, then update firmware to V4.5 |
| WBM shows configuration commit error | Internal flash wear or pending firmware update | Update firmware; if persistent, replace device |
Documentation References
- SCALANCE XB-200/XC-200/XF-200BA/XP-200/XR-300WG Web Based Management manual
- SCALANCE XC-200 firmware download V4.5 (Siemens Support entry 109825818)
- SIMATIC NET: Restart behavior of SCALANCE X devices (TIA Portal Cloud docs)
Why does my SCALANCE XC216 lose the default gateway after every power cycle?
Three causes are typical on firmware V4.0: (1) the DHCP client is enabled and overrides the static gateway on boot, (2) a connected S7 PLC pushes its IP Suite via PROFINET and overwrites the gateway, or (3) the WBM change was never committed with System > Save. Disable DHCP, clear the PLC's IP Suite assignment in TIA Portal, and click Save after every WBM change.
How do I stop the S7 PLC from forcing network parameters on the SCALANCE?
In TIA Portal open the SCALANCE device properties, navigate to PROFINET interface > Ethernet addresses > IP Suite, clear all values, recompile, and download to the PLC. Alternatively, remove the SCALANCE from the PLC's PROFINET topology so it is managed as a stand-alone switch.
Which firmware version fixes the gateway-reset bug on SCALANCE XC-200?
Siemens firmware V4.5.x is the current release and corrects the volatile-storage behavior of the default gateway, NTP state, and several Layer 3 parameters. The signed image is available from Siemens Support entry 109825818.
Why does the system time reset to 2000-01-01 00:00:00 after reboot?
The SCALANCE has no battery-backed RTC. If no NTP or SNTP server is reachable at boot, time defaults to 2000-01-01. Configure an SNTP server under System > Time pointing to a plant NTP source or to the PLC itself.
Do I have to click Save in WBM to make configuration persistent?
Yes. Every change made through the Web Based Management interface is held in RAM until System > Configuration > Save is invoked. Without Save, all settings revert on power cycle or restart, including the default gateway, NAT rules, and static routes.