SCALANCE XC216 vs XC116: Managed vs Unmanaged PROFINET Switch

David Krause21 min read
Industrial NetworkingSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

When commissioning must start before the ordered managed switch has been delivered, an unmanaged SCALANCE XC116 (6GK5116-0BA00-2AC2) or XB116 (6GK5116-0BA00-2AB2) is sometimes used to bring up an S7-1517TF controller, ET200SP stations, and ET200AL field I/O over PROFINET RT. This reference documents what is gained, what is lost, and what must be re-validated when the unmanaged switch is later replaced by the managed SCALANCE XC216 (6GK5216-0BA00-2AC2).

Overview: Managed XC216 vs Unmanaged XC116 / XB116

All three candidates are Siemens SCALANCE industrial Ethernet switches designed for cabinet mounting in an S7-1500 environment. Each has 16 fixed 10/100 Mbit/s RJ45 copper ports and a redundant 24 V power input. The XC216 is the only Layer 2 managed device in the group; the XC116 and XB116 are plug-and-play store-and-forward switches that build their MAC address table automatically and have no user-accessible configuration interface.

The single most consequential difference for a PROFINET application is that the XC216 is itself a PROFINET IO Device. It speaks DCP (Discovery and Configuration Protocol) and LLDP (Link Layer Discovery Protocol) on every port, reports its own diagnostics to the IO controller, and can be inserted into the TIA Portal device and topology view. The XC116 and XB116 are transparent bridges. They appear in no PROFINET project view, contribute no diagnostics to the controller, and have no GSD file.

For a first-pass test where the goal is to confirm the S7-1517TF can see every ET200SP and ET200AL station and read/write process data, the unmanaged switch is functionally adequate. The PROFINET RT frame path (real-time class 1, unscheduled, priority-tagged) does not require any switch management plane to be active. What is lost is everything the managed plane enables: topology configuration in TIA Portal, device replacement without exchangeable medium, port interconnection diagnostics, per-port statistics, redundancy protocols, security, and remote management.

Hardware and Ordering Comparison

Feature SCALANCE XC216
6GK5216-0BA00-2AC2
SCALANCE XC116
6GK5116-0BA00-2AC2
SCALANCE XB116
6GK5116-0BA00-2AB2
Switch type Managed Layer 2 IE switch Unmanaged IE switch Unmanaged IE switch
Copper ports 16x 10/100 Mbit/s RJ45 16x 10/100 Mbit/s RJ45 16x 10/100 Mbit/s RJ45
Console port 1x serial (RJ11 / RS-232) None None
Management interfaces Web (HTTPS), CLI, SNMP v1/v2/v3, PROFINET, EtherNet/IP None (LED only) None (LED only)
PROFINET IO Device Yes (PROFINET conformance class B) No (transparent bridge) No (transparent bridge)
LLDP agent / DCP responder Yes (per port) No No
Redundancy protocols RSTP, MRP client, MRP manager, standby, passive listening None None
Security IEC 62443-4-2 certified; user roles, ACL, 802.1X, broadcast limiter, syslog None None
Error-signaling contact Yes (with SET button) Yes (with SET button) No
C-PLUG slot Yes (exchangeable configuration medium) No No
Power supply 2x 24 V DC, redundant 2x 24 V DC, redundant 2x 24 V AC/DC, redundant
Operating temperature -40 °C to +70 °C -40 °C to +70 °C -40 °C to +60 °C
Mounting DIN rail, S7 mounting rail, wall DIN rail, S7 mounting rail, wall DIN rail, S7 mounting rail, wall
Protection class IP20 IP20 IP20
802.1Q priority handling Yes (tag-aware, configurable queues) Yes (priority bits honored, untagged) Yes (priority bits honored, untagged)

Source: Siemens SCALANCE XC-200 product support and the SCALANCE XC-100 / XB-100 operating instructions on the Siemens Industry Online Support portal.

PROFINET Conformance Classes, RT, and the Limits of the Unmanaged Switch

PROFINET devices are categorized into Conformance Classes (CC) that describe which PROFINET services the device supports:

  • CC-A — Basic PROFINET functionality: real-time RT communication, identification, basic network diagnostics via SNMP.
  • CC-B — Extended diagnostics: adds system redundancy (MRP), neighborhood detection (LLDP), and diagnostic data to the controller.
  • CC-C — Adds IRT (Isochronous Real-Time) with scheduled traffic, bandwidth reservation, and synchronization down to 1 µs jitter.
  • CC-D — Highest performance, full IRT with cut-through switching and 31.25 µs cycle.

The SCALANCE XC216 is implemented as a PROFINET IO Device at Conformance Class B. It can be diagnosed by the S7-1517TF as a node in the PROFINET IO system. The XC116 and XB116 are not PROFINET devices at all — they are transparent Ethernet bridges — so they implement none of the conformance classes and are simply not visible to the IO controller.

PROFINET RT (Real-Time) class 1 uses standard Ethernet with a transmission cycle of 1 ms or longer. Each RT frame is a standard IEEE 802.3 Ethernet frame with a VLAN priority tag (PCP value 6) so that the switch can prefer RT traffic over background traffic. The frame is forwarded by store-and-forward, exactly the mechanism an unmanaged switch uses. Both the XC116 and XB116 honor 802.1Q priority on the forwarding decision and do not strip VLAN tags.

For an S7-1517TF talking PROFINET RT to ET200SP and ET200AL stations, the network requirements are:

  1. Cut-through forwarding is not required — store-and-forward latency on the XC116/XB116 is well under 100 µs per port.
  2. Priority handling on the switch must not be disabled — both unmanaged SCALANCE variants honor 802.1Q priority.
  3. The IO controller must receive its own PROFINET frames back within the configured send clock (1 ms by default for an S7-1500); a single store-and-forward hop easily meets this.
  4. No broadcast storm protection is strictly required for a small star, but a broadcast storm caused by a miswired cable will impact the entire network regardless of switch class.

Result: PROFINET RT communication with cycle times of 1 ms and 2 ms will work through XC116 or XB116 with no functional difference from XC216, as long as network load is light. The controller will complete IO data exchange, the ET200SP and ET200AL modules will report "OK" in TIA Portal online diagnostics, and the user program will read and write process data.

Important: Transparency does not mean incompatibility. PROFINET RT frames are standard IEEE 802.3 Ethernet frames with VLAN priority bits set to 6 (RT class 1) or 7 (RT class 2). Any unmanaged switch that forwards these priority-tagged frames unmodified will pass PROFINET RT traffic.

TIA Portal Topology Editor and Port Interconnection Diagnostics

PROFINET defines a "neighborhood" relationship between two directly connected devices. When two PROFINET devices are linked, they exchange LLDP TLVs that include the local port number and the remote device's PROFINET name and chassis ID. The IO controller can use this to build a model of the physical network — the "topology".

In TIA Portal, the topology view (Devices & Networks > Topology) is populated automatically by LLDP exchange. The engineer can then:

  • Visually verify which port of switch A connects to which port of switch B.
  • Lock the topology to detect any later unauthorized reconnections.
  • Enable "device replacement without exchangeable medium" for every station in the project.
  • Enable port interconnection diagnostics (errors raised when the live topology differs from the configured topology).
  • Configure IRT bandwidth reservation (only relevant for IRT projects).

None of this is possible for the XC116 or XB116. The switches have no PROFINET stack, no LLDP agent, and no DCP responder. They cannot be added as a device in the TIA Portal project, and they cannot participate in neighborhood detection. The TIA Portal device tree will simply have the S7-1517TF, the ET200SP, and the ET200AL — the switches are not nodes, they are wires.

The XC216, by contrast, is added to the project as a PROFINET device. Its 16 ports appear as drag-and-drop endpoints in the topology view, and you can connect the ET200SP and ET200AL stations to specific ports of the XC216 in the project. This forms the "configured topology" that is later compared against the actual topology detected at runtime.

When the topology is configured and downloaded, the IO controller continuously checks that the actual LLDP-reported topology matches the configured topology. If a cable is plugged into the wrong port — for example, two ET200SP stations are swapped during cabinet wiring — the controller raises a "port interconnection mismatch" diagnostic on the relevant port of the affected device. With an unmanaged switch in the path, no such check is possible: the PROFINET devices on either side of the switch see each other as neighbors directly, with no port number information. A wiring error can therefore be detected only by manual inspection of the LED state on the IO device, or by failure of the IO device to come up at all.

Key consequence: Without the managed switch in the project, the topology view shows direct CPU-to-IO connections. The physical reality (CPU — XC116 — ET200SP) does not match the logical model, and any topology-based feature will silently fail or produce misleading diagnostics.

Device Replacement Without Exchangeable Medium

"Device replacement without exchangeable medium" is the PROFINET feature that allows an engineer to swap a defective IO device with a new, unconfigured spare of the same catalog number, without having to load the device name and IP address from an SD card, C-PLUG, or SIMATIC Memory Card. It is enabled per-device in the TIA Portal device properties, and it relies on:

  1. The PROFINET name of the device being stored in the controller's topology model, keyed by the port number that the device is reachable through.
  2. The defective device being detected as missing (no LLDP, no DCP response from that station).
  3. The replacement device being assigned the stored name and IP address automatically by the controller once it sees the new device at that port.

Step 1 requires the topology to be known. The controller must know that "ET200SP station 1 is reachable via port 7 of the switch in slot 0 of the network". If the switch is the XC116, the controller has no path information beyond "ET200SP station 1 is somewhere on the same Ethernet segment as the controller", and the automatic name assignment cannot be performed.

For first-time commissioning, this is not a problem — the engineer configures the IO devices manually once and they stay. For a machine that is shipped to a customer and maintained for ten years, however, the absence of "device replacement without exchangeable medium" turns a 30-second field replacement into a 10-minute TIA Portal download (or a service engineer callout).

To work around this during a pre-shipment bench test on the unmanaged switch, the engineer can pre-assign PROFINET device names and IP addresses to the spare IO devices using the SIMATIC Automation Tool before sending the spares to the field, or use the PRONETA tool to scan and configure the spare from a service laptop. Neither tool requires the XC216 to be in the topology.

Diagnostic and Management Feature Comparison

Diagnostic / management function XC216 XC116 XB116
Per-port link state visible to controller Yes (per port, in PROFINET diagnostic records) No No
Per-port frame counters (RX/TX, errors, discards) Yes (PROFINET record & web interface) No (LED only) No (LED only)
SNMPv1/v2/v3 Yes No No
Web server for management Yes (HTTP/HTTPS) No No
Log file / syslog export Yes (volatile, downloadable) No No
Error-signaling contact on hardware fault Yes (with SET button) Yes (with SET button) No
Cable diagnostics (length, short, open) Yes (per port) No No
Port mirroring (SPAN) Yes (ingress, egress, both) No No
VLAN (802.1Q) segmentation Yes (tag-based, configurable) No (priority bits forwarded, no segmentation) No (priority bits forwarded, no segmentation)
QoS priority queues 4 queues per port, configurable Strict priority on bit pattern Strict priority on bit pattern
IGMP snooping Yes No No
RSTP (IEEE 802.1D-2004) Yes No No
MRP (Media Redundancy Protocol) Yes (manager + client) No No
Standby redundancy Yes No No
Link aggregation (LACP / static) Yes No No
Broadcast / multicast rate limiter Yes (per port) No No

Source: Siemens SCALANCE XC-200 product support and the operating instructions for each switch.

Network Security: IEC 62443-4-2 on the XC216

The XC216 (6GK5216-0BA00-2AC2) is certified to IEC 62443-4-2, the "Technical Security Requirements for IACS Components" standard. In the Siemens catalog, this certification is what makes the device "Security Integrated" and eligible for use in defense-in-depth architectures that satisfy the requirements of IEC 62443-3-3 system-level security. Specific security capabilities enabled on the XC216 include:

  • User administration with role-based access (admin, user, guest)
  • HTTPS web interface with self-signed or CA-issued certificate
  • SSH and SNMPv3 for management plane
  • Port-based 802.1X authentication (supplicant mode)
  • MAC-based access control lists (ACL)
  • Broadcast, multicast, and unknown unicast rate limiting
  • Configurable password policy and account lockout
  • Audit log of administrative actions

The XC116 and XB116 have none of these. The unmanaged switches should not be exposed to a network that carries traffic from outside the machine — they are intended as a closed segment. For first-pass testing on a development bench with no external connectivity, this is acceptable. For factory-floor or remote-access commissioning, the managed switch is mandatory from a security perspective.

Reference: Cisco: Managed vs Unmanaged Switches for a vendor-independent overview of the security and management gap.

Redundancy: RSTP, MRP, and Standby

The XC216 supports three redundancy protocols that the XC116 and XB116 do not:

  1. RSTP (IEEE 802.1w, 802.1D-2004) — rapid spanning tree. Sub-second failover on ring or meshed topologies. Topology-independent, works with any IEEE 802.1Q-compliant switch.
  2. MRP (Media Redundancy Protocol, IEC 62439-2) — PROFINET-specific ring redundancy. One MRP manager per ring, all other switches as MRP clients. Failover time < 200 ms with default configuration.
  3. Standby redundancy — two parallel links to the same partner device, one active, one standby. Sub-100 ms failover. Used in PROFINET System Redundancy (S2) configurations with an S7-1500R/H redundant controller.

For first-pass testing of a single XC216 in a star with three to five ET200 stations, no redundancy is configured and no failover is expected. For the final machine, the redundancy plan (if any) is implemented on the XC216 once it is installed. The S7-1517TF (technology CPU) used here is a single-CPU variant and does not support PROFINET S2 system redundancy; only the S7-1517F or S7-1518F in a redundant pair (S7-1500R/H) supports S2.

First-Pass Testing Strategy with XC116 or XB116

The most common reason to substitute an unmanaged switch in a Siemens PROFINET project is to start IO bring-up at the cabinet level before the ordered managed switch has been delivered. The following procedure assumes the goal is "every ET200SP and ET200AL comes up green, every channel is exercised once". It is not a long-term architecture plan.

  1. Wire the network in a star. The S7-1517TF PROFINET port X2 (or X1, depending on configuration) is the central point. All ET200SP and ET200AL stations connect directly to the XC116 or XB116. No ring, no daisy chain.
  2. Leave the topology view in TIA Portal empty. Because the unmanaged switch is not a PROFINET device, do not attempt to add it to the topology. Do not enable "device replacement without exchangeable medium" or "port interconnection diagnostics" — they will silently fail.
  3. Assign PROFINET device names and IP addresses manually using the TIA Portal "Assign device name" function, or via the SIMATIC Automation Tool. With no DCP responder on the switch, the discovery and assignment process touches only the IO devices and the controller.
  4. Download the project to the controller. The IO system will go into RUN. Expect a single "device replacement" warning on the first run if "device replacement without exchangeable medium" was inadvertently enabled — clear it and proceed.
  5. Verify IO data exchange. In TIA Portal, go online and check that every ET200SP and ET200AL slot reports "OK" in the Devices > Online > Diagnostics view. Check the cyclic IO data in a watch table or with a forcing table on a non-critical signal.
  6. Capture a baseline. Save a screenshot of the online diagnostics, a topology export, and the project's hardware configuration. These will be reused when the XC216 is installed.
  7. Use PRONETA to validate the network. PRONETA is a free Siemens tool that can scan the network, list all PROFINET devices, verify device names and IP addresses, and measure basic network parameters. With the unmanaged switch in the path, PRONETA will see all the IO devices and the CPU; it will not see the switch itself. This is expected.
Do not use the unmanaged switch for safety-related PROFINET communication. PROFINET Safety (PROFIsafe) over the XC116/XB116 is not officially qualified and cannot provide the diagnostic coverage that PROFIsafe requires. Safety IO must be on a network segment with a managed switch, or directly on the F-CPU's PROFINET port.

Migration from XC116/XB116 to the Managed XC216

Once the XC216 arrives, the migration to the managed topology is a controlled process. The following steps assume the original project was commissioned on the unmanaged switch and a baseline exists.

  1. Receive and power up the XC216 on the bench. Connect a single PC to a free port. Open the web interface (https://192.168.1.1 by default) or use the SINEC NMS or PRONETA tool to assign an initial IP address, PROFINET device name, and administrator password. Document the IP and name on the project sheet.
  2. Insert the XC216 into the TIA Portal project. Use "Add new device" in the device tree, select SCALANCE XC216, and place it at the appropriate position. Assign a PROFINET name (e.g. "switch-xc216") and IP address consistent with the plant scheme.
  3. Reconnect the IO stations in the topology view. In Devices & Networks, switch to Topology view. Connect each ET200SP and ET200AL station to the specific XC216 port that it will be wired to. Save and download the project to the controller.
  4. Physically swap the switch. Schedule a short downtime. Disconnect the field cabling from the XC116/XB116 in sequence, label each cable, and reconnect to the same-numbered port on the XC216. Power up the XC216. The C-PLUG slot on the XC216 can be left empty for first-time use; the configuration is loaded from the controller's PROFINET download.
  5. Download the new configuration to the controller and the switch. The XC216 will reboot. After the reboot, the controller will see the XC216 as a PROFINET device, see all 16 ports in the topology, and the LLDP-detected topology should match the configured topology.
  6. Verify port interconnection diagnostics. If the wiring is correct, the topology status will be "OK". If a cable has been moved to a different port, the relevant port will raise a diagnostic alarm that surfaces in TIA Portal's online diagnostics view.
  7. Enable "device replacement without exchangeable medium" per device. With the topology now configured, this feature can be enabled and will operate correctly.
  8. Configure security per plant policy. Change the default password, set the password policy, configure the user roles, enable HTTPS and SSH, and disable unused services. The exact configuration depends on the plant's IEC 62443-3-3 system-level security plan.

Source: TIA Portal online help, section "Configuring topology", available via Siemens Industry Online Support.

Verification Checklist and Field-Proven Caveats

Item Pass criterion Method
Controller-to-switch link Link LED green on both controller port and switch port Visual inspection
Switch-to-ET200SP link Link LED green; PROFINET status LED green on ET200SP Visual inspection
PROFINET IO system starts All ET200 stations reach "OK" state within 30 s of controller RUN TIA Portal online > diagnostics
No port faults No "link down" or "no partner" diagnostic on any port Online diagnostics
IO data exchange Cyclic IO updates visible in watch table Watch table / force table
No excess bus load Send clock 1 ms achieved, no "life sign" failures PROFINET diagnostics > statistics
Cable lengths All patch cables < 100 m (copper limit per IEEE 802.3u) Visual / TDR (when XC216 is installed)
Error-signaling contact (XC116 only) Open when powered and healthy, closed on fault PLC input / multimeter
Power redundancy Both 24 V feeds present; switch survives removal of one Test with redundant PSU
VLAN priority not stripped PROFINET RT frames pass with 802.1Q PCP=6 intact Wireshark capture on a port-mirrored XC216 port

Field-proven caveats from PROFINET commissioning practice:

  • Do not mix XC116 and XB116 in the same network unless intentional. The XB116 supports AC supply (up to 24 V AC) and is intended for installation in non-DCS cabinets, while the XC116 is a DC-only industrial switch. Mixing them does not break PROFINET but complicates the spare parts list.
  • The XC116 error-signaling contact is not a PROFINET diagnostic. It is a hardware signal that follows the "device is healthy and configuration is loaded" bit. It will not trigger a PROFINET alarm on the controller. The XC216's error-signaling contact is also a hardware signal, but the equivalent PROFINET diagnostic is reported by the device's PROFINET stack and surfaces in the TIA Portal diagnostics view.
  • "Device replacement without exchangeable medium" requires the device to have been previously seen on that port. A first-time installation of a brand-new spare part with the same catalog number will work, but only if the topology was configured before the original device failed.
  • The XC216's PROFINET IO Device interface is on a single port pair. In the default configuration, the first PROFINET port of the XC216 is the management/IO port. The remaining 15 ports are pure Layer 2 forwarding ports. Do not connect PROFINET IO devices to port 1 by accident if the IO Device interface is in use.
  • Firmware version matters. SCALANCE XC-200 firmware 4.x and later introduced Security Integrated features. Confirm the firmware level before assuming IEC 62443-4-2 features are present. Use the latest firmware available on the Siemens Industry Online Support portal.
  • The PROFINET conformance class of the IO device is independent of the switch. An ET200SP station is PROFINET CC-B regardless of whether the switch in the path is a managed XC216 or an unmanaged XC116. The switch class affects what the controller can learn about the network, not what the IO device can do.
  • The C-PLUG is a configuration backup, not a license. Swapping a C-PLUG into a new XC216 transfers the configuration (IP, name, security settings) so the device boots with the same identity. It does not transfer firmware; firmware is loaded separately.

When the Unmanaged Switch Is the Correct Choice

The unmanaged SCALANCE XC116 and XB116 are not "wrong" products — they are designed for a different application profile. The following use cases are appropriate:

  • Standalone machine with no network connection beyond the HMI and one or two PROFINET IO stations.
  • Engineering test bench with no remote access.
  • Pre-commissioning bring-up of a controller and IO when the managed switch is on back-order.
  • Low-cost redundant segment where the IO stations are on a separate, isolated subnetwork with no safety devices.

For any of the following, the managed XC216 is the correct choice:

  • Connection to a plant network (even read-only).
  • PROFIsafe over PROFINET (F-CPU + F-IO).
  • Need for "device replacement without exchangeable medium" in the field.
  • Need for port interconnection diagnostics during cabinet wiring validation.
  • Need for any form of media redundancy (MRP, RSTP, standby).
  • Security requirements per IEC 62443-3-3.
  • More than 8-10 PROFINET devices on a single segment (broadcast storm risk).

For further information on the SCALANCE XC-200 family and the SCALANCE XC-100 / XB-100 unmanaged series, see the operating instructions on the Siemens Industry Online Support portal at support.industry.siemens.com. For an independent overview of the managed vs unmanaged switch distinction, see the Cisco networking primer at Cisco: Managed vs Unmanaged Switches. For PROFINET conformance classes, IRT/RT behavior, and the role of LLDP/DCP in topology discovery, refer to the PROFINET specification maintained by PROFIBUS & PROFINET International (PI).

Frequently Asked Questions

Can I use the SCALANCE XC116 or XB116 for initial PROFINET RT testing with an S7-1517TF and ET200SP/AL?

Yes, for first-pass bring-up. PROFINET RT class 1 frames are standard Ethernet frames with VLAN priority 6, and the XC116 and XB116 forward them unmodified. The S7-1517TF will see every ET200SP and ET200AL station and exchange cyclic IO at send clock 1 ms. Features that require a PROFINET-aware switch in the topology — "device replacement without exchangeable medium", "port interconnection diagnostics", per-port PROFINET statistics — will not work until the managed XC216 is installed.

Why does TIA Portal not let me add the XC116 to the topology view?

The topology view only displays devices that have a PROFINET interface and a GSD file. The XC116 and XB116 are transparent Ethernet bridges with no PROFINET stack, no DCP responder, and no GSD file. They are not nodes in the PROFINET project — they are simply wires. The topology view will show the IO devices connected directly to the CPU port, ignoring the unmanaged switch.

Will "device replacement without exchangeable medium" work through an XC116?

No. The feature depends on the controller knowing the port number that the device is reachable through. The controller derives this from the LLDP topology, which requires a PROFINET-aware switch at every hop. With the XC116 in the path, the controller sees the IO device as a direct neighbor and cannot determine the port number. The automatic name assignment will not be attempted; the engineer must use the SIMATIC Automation Tool or a TIA Portal download to re-assign the new device.

What is the difference between the XC116 and the XB116?

The XC116 belongs to the SCALANCE XC-100 industrial switch family, designed for cabinet mounting alongside S7-1500 stations, with 24 V DC redundant supply. The XB116 belongs to the SCALANCE XB-100 series, intended for smaller star and line topologies and supporting 24 V AC or DC supply. The XC116 has a hardware error-signaling contact with a SET button to acknowledge faults; the XB116 does not. Both are unmanaged and both honor 802.1Q priority on PROFINET RT frames.

When must the managed XC216 be installed before shipping the machine?

Install the XC216 before the machine is connected to any plant network, before any PROFIsafe IO is wired to the controller, and before "device replacement without exchangeable medium" is required for field maintenance. For a self-contained standalone machine with no remote access, no plant network, and manual device replacement, the unmanaged switch can remain in service for the lifetime of the machine.

Back to blog