Siemens S7-300 Remote Programming Teleservice, Ewon, and 3G Setup

David Krause16 min read
S7-300SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Siemens S7-300 Remote Programming: Teleservice, Ewon, and 3G Setup

Remote programming of a Siemens SIMATIC S7-300 CPU is a routine commissioning and service requirement when the controller is installed at a customer site that restricts inbound VPN access, refuses direct plant-network exposure, or operates in a regulated environment with strict change-control procedures. This reference consolidates the field-proven paths - Siemens Teleservice adapters, Ewon Cosy+/Flexy cellular routers from HMS Networks, and direct STEP 7 PG/PC interface routing - into a single technical document, with commissioning steps, parameter tables, and a verification matrix for each approach. The intended reader is a control engineer who must deliver, configure, and sign off a remote connection without relying on the customer's IT infrastructure beyond an analog line or a cellular signal.

1. Remote Programming Architecture Overview

A remote programming session consists of three logical segments:

  1. Engineering workstation running STEP 7 V5.5 SP2/SP3 (or TIA Portal V16+ for S7-300 CPUs that support the modern toolchain, e.g., CPU 31x PN/DP). The PG/PC interface is set to the local remote-access client (for example, "Modem", "TCP/IP", or "Ewon").
  2. WAN transport (PSTN, cellular 3G/4G LTE, or the customer's outbound Ethernet) terminating at a remote-access gateway installed inside the cabinet.
  3. Field-bus transport (MPI, PROFIBUS DP, or PROFINET) carrying the S7 protocol between the gateway and the CPU's programming port.

Selection criteria for the WAN transport are:

  • Site policy on VPN, firewall traversal, and external connections.
  • Available CPU port on the S7-300 (MPI/DP, PN, or both).
  • Required bandwidth and session latency.
  • Cost ceiling (cellular data, PSTN tariffs, subscription).
  • Regulatory environment (pharma, food, automotive often restrict remote IP access).

For most field retrofits where the customer refuses any VPN into the plant network, a vendor-managed cellular teleservice router (Ewon Cosy+ / Flexy) or a Siemens Teleservice adapter (TS Adapter II or TS Module) provides an air gap at the IP layer: the customer's LAN never receives a routable packet from the engineering workstation, and the connection is initiated outbound from the plant.

2. S7-300 Interface Inventory and Protocol Selection

Before choosing a remote gateway, confirm which physical interfaces the target CPU exposes. The standard S7-300 CPU family is summarised below; refer to the official S7-300 CPU Parameter Manual for the exact ordering data of a specific CPU.

CPU class PROFINET (PN) MPI/DP port (X1) DP port (X2) Typical use for remote programming
CPU 312, 312C No MPI (default) None TS Adapter II on MPI, or Cosy+ via MPI pass-through
CPU 314 No MPI/DP switchable None Same as 312; configurable as MPI or DP master
CPU 315-2 DP No MPI/DP DP master TS Adapter II on MPI, or PROFIBUS tap on X2
CPU 315-2 PN/DP Yes (X2 PN) MPI/DP (X1) DP master (X1 in DP mode) Cosy+ or VPN directly to PN; MPI used as fallback
CPU 317-2 PN/DP Yes (X2 PN) MPI/DP (X1) DP master (X1 in DP mode) Preferred path is PN; bandwidth supports full project upload/download
CPU 319-3 PN/DP Yes (X2 PN, X3 PN) MPI/DP (X1) DP master (X1 in DP mode) Dual-port PN enables segmentation; ideal for service VLAN

Physical layer rules-of-thumb per the S7-300 Hardware and Installation Manual:

  • MPI default baud rate is 187.5 kbit/s; supported rates up to 12 Mbit/s on CPUs released after 2002. Most Teleservice adapters auto-baud to 187.5 kbit/s or 1.5 Mbit/s.
  • PROFIBUS DP segment with a TS Adapter II tap is terminated at both ends with 220 ohm to 390 ohm; the adapter sits as a slave on the segment.
  • PROFINET cable runs are limited to 100 m (copper) per segment. The PN port of a CPU 31x-2 PN/DP can be reached directly by a Cosy+ on the same switch if the customer's IT permits; otherwise route through a maintenance router.

3. Siemens Teleservice Adapters (TS Adapter II / TS Module)

The Siemens Teleservice family consists of two products with overlapping function:

  • TS Adapter II (catalog family 6ES7972-0CA34-0XA0 and variants). A standalone box with an MPI/PROFIBUS port (D-sub 9) on the field side and either an analog PSTN RJ-11 port, an ISDN port, or an Ethernet variant on the WAN side. Connects to STEP 7 via the proprietary "Modem" PG/PC interface.
  • TS Module (catalog family 6ES7137, designed for ET 200S and S7-300 racks). A slide-in module that occupies one slot in the ET 200S or in a free slot of an S7-300 sub-rack; uses an internal backplane connection, no separate MPI cable needed for programming.

Functional differences relevant to remote programming:

Property TS Adapter II (6ES7972-0CA34-0XA0 family) TS Module (6ES7137 family)
Field port MPI/PROFIBUS via RS-485 D-sub 9 Backplane to host S7-300/ET 200S
WAN options PSTN (analog), ISDN, or Ethernet variant Analog PSTN only (RJ-11)
STEP 7 support Modem driver, S7 Teleservice wizard Same
Typical baud Up to 1.5 Mbit/s MPI/PB 187.5 kbit/s / 1.5 Mbit/s (depends on host CPU)
Security Callback option, password, PIN Callback option, password, PIN
Status Active but largely superseded by IP routers Active, used in legacy cabinets

The Teleservice Wizard in STEP 7 V5.5 SP2 (Start > SIMATIC > STEP 7 > Teleservice) configures the dial-up number, MPI address, and target CPU. The wizard writes a "Teleservice" object into the STEP 7 project that, when opened, automatically dials the TS Adapter II and brings up an "online" view of the target CPU.

Note: Siemens has reduced formal support for new Teleservice installations since the introduction of industrial cellular routers. For greenfield sites prefer Ewon Cosy+/Flexy or comparable industrial routers from HMS Networks, Moxa, or Cisco IC3000. The TS Adapter II remains the right answer when the customer refuses any IP device on the plant network and only permits an analog line.

4. Ewon Cosy+ and Flexy Cellular Routers (HMS Networks)

The Ewon Cosy+ (EW24500A-EU and the EW24420 EU/NA models) is the most widely deployed cellular teleservice router for S7-300 service work. It uses the Talk2M cloud broker so the engineering workstation never opens a direct inbound connection to the plant - outbound TCP/UDP from the Cosy+ traverses the cellular modem to Talk2M, and the eCatcher client on the engineering workstation terminates a VPN tunnel into Talk2M. Functionally the customer sees no inbound traffic on their firewall, which satisfies pharma, food, and automotive audit requirements.

The Flexy (FLX3101, FLX3201, FLX3401 base units) is a modular platform that accepts the same WAN extension cards as the Cosy+ but adds slots for MPI/PROFIBUS pass-through cards (FLB3202 for MPI, FLB3204 for PROFIBUS). Use the Flexy on multi-protocol plants where the service laptop is expected to connect to PROFIBUS DP devices, HMI panels, and S7-300 CPUs over the same tunnel.

4.1 Hardware Variants

Model WAN Field interface Talk2M licence
Ewon Cosy+ EW24500A-EU 4G LTE Cat-4 EU + Ethernet WAN fallback Ethernet LAN (4-port switch) to PLC PN port Free tier with Connect subscription
Ewon Cosy+ EW24420 4G LTE EU/NA Ethernet LAN Same
Ewon Flexy FLX3101 + FLB3202 Cellular or Ethernet WAN card MPI/PROFIBUS via FLB3202 Same; requires MPI/PB card option
Ewon Flexy FLX3401 + FLB3204 4G card PROFIBUS pass-through Same

4.2 Logical Path

  1. Cosy+ powers up, registers to Talk2M broker using device ID + OTP key (printed on the unit and recoverable via the manufacturer's secure provisioning flow).
  2. Engineering workstation runs eCatcher, authenticates against Talk2M, and selects the Cosy+ as the destination.
  3. eCatcher brings up a TUN/TAP interface (or IPSec on Windows) and assigns a private IP from the Ewon VPN pool (default 10.8.x.x).
  4. STEP 7 PG/PC interface is set to "TCP/IP" with target IP equal to the S7-300 CPU's PN IP (for example 192.168.10.10), routed through the eCatcher TUN. S7 frames pass transparently.

5. STEP 7 PG/PC Interface Configuration for Remote Access

All remote paths ultimately present themselves to STEP 7 as one of three PG/PC interface assignments. The configuration is performed in Start > SIMATIC > STEP 7 > Set PG/PC Interface.

PG/PC interface Used with Typical driver
Modem (Teleservice) TS Adapter II / TS Module Siemens Teleservice driver (STEP 7 V5.5 SP2+)
TCP/IP → Auto Ewon tunnel → CPU PN port RFC1006 / ISO-on-TCP via TCP/IP
TCP/IP → S7Online (STEP 7 V5) Direct Ethernet access (in-plant or routed VPN) Same
PC Adapter (MPI/PROFIBUS USB) Local service laptop with Cosy+ MPI pass-through PC Adapter USB driver
Ethernet → MPI/DP router (NetLink) Ewon Cosy+ with MPI/PB pass-through card NetLink PRO or comparable driver

5.1 Setting up the TCP/IP path for an Ewon Cosy+ tunnel

  1. Open Set PG/PC Interface, select "TCP/IP → <your LAN adapter>" as the interface used by STEP 7. Confirm with OK.
  2. Launch eCatcher, connect to Talk2M, and bring the Cosy+ online. Verify the TUN interface receives an address from the 10.8.0.0/16 pool.
  3. In STEP 7, choose PLC → Accessible Nodes. The S7-300 CPU should appear with its configured PROFINET IP (e.g., 192.168.10.10). If a Windows route does not auto-install, add a static route: route ADD 192.168.10.0 MASK 255.255.255.0 10.8.0.5 METRIC 1 (where 10.8.0.5 is the TUN gateway).
  4. Open the project, select the target CPU in the project tree, and click "Go Online". STEP 7 establishes an S7 connection via TCP port 102 (ISO-on-TCP/RFC1006) and downloads the project.
Tip: When the customer permits Ethernet to the cabinet but blocks VPN, the Ewon Cosy+ in LAN-to-LAN mode (bridged to the plant network) is acceptable. In that mode the Cosy+ is just another device on the plant LAN, but Talk2M still terminates the inbound tunnel at the broker - not at the plant.

6. Commissioning Procedure: TS Adapter II over Analog PSTN

Use this procedure when the customer mandates an air-gap dial-up solution and the only available WAN is an analog line.

  1. Mount and wire. Place the TS Adapter II in the cabinet within 5 m of the S7-300 CPU. Connect the MPI/PROFIBUS D-sub 9 directly to the CPU's X1 port using a pre-fabricated PROFIBUS cable (6XV1830-0AH10, or equivalent) terminated according to the S7-300 Hardware and Installation Manual chapter "MPI/PROFIBUS Network".
  2. Configure the TS Adapter II. Open its WebConfig (browse to 192.168.1.1 default, login admin/admin on first power-up) and set:
  • Field bus: MPI or PROFIBUS, baud auto.
  • Highest MPI address: 31.
  • Own MPI address: 0 (default).
  • PSTN dial-in enabled; callback number programmed.
  • PIN: 6-digit numeric.
  1. Configure STEP 7. In Set PG/PC Interface choose "Modem (Teleservice)" and create a new dial-up entry with the customer's site number, the TS Adapter II PIN, and the callback number. Activate "Use callback" to force the adapter to dial back the engineering workstation - eliminates direct inbound exposure.
  2. Test the dial-up. From STEP 7 use PLC → Teleservice → Connect to Target System. The wizard dials, the TS Adapter II answers, requests the PIN, calls back, and STEP 7 displays the online view. Time-to-online is typically 45-90 s on PSTN.
  3. Program. Download the project, perform online/compare, and document the change in the customer's change log.
PSTN caveat: Modern PSTN is being decommissioned in many regions. Confirm with the customer whether the line is true POTS or a VoIP ATA; the TS Adapter II is sensitive to ATA digit timing and may fail to handshake on a poor VoIP translation.

7. Commissioning Procedure: Ewon Cosy+ over 3G/4G LTE

This is the most common greenfield path. Allow approximately 60 min per site including SIM provisioning.

  1. SIM provisioning. Order an industrial IoT SIM (1NCE, Wireless Logic, or operator equivalent). For most Talk2M deployments a private SIM is sufficient because Talk2M brokers the tunnel - a public static IP is optional. Store the SIM PIN and PUK in the customer's cell-router access register.
  2. Mechanical install. DIN-rail mount the Cosy+ on the cabinet sub-panel. Antenna on top of the cabinet, routed away from VFD cables. Power 24 VDC from the cabinet 24 V bus, fused at 1 A.
  3. Field network wiring. Patch cable from Cosy+ LAN port 1 to the S7-300 CPU's PROFINET port (X2 on a 31x-2 PN/DP). If the PN port is already used for an HMI, add an unmanaged switch (e.g., Scalance XB005) so the Cosy+ sits in parallel.
  4. Cosy+ first power-up. Connect a service laptop to LAN port 2 of the Cosy+. Browse to http://10.0.0.53 (default) and run the Quick Launch wizard. Verify IMEI, IMSI, signal strength RSSI > -85 dBm, and registration to Talk2M.
  5. eCatcher enrollment. In eCatcher on the engineering workstation, add the device using its serial number and the OTP recovery key. Synchronize and confirm the Cosy+ icon turns green.
  6. STEP 7 tunnel test. With eCatcher connected, run PLC → Accessible Nodes. The CPU should appear within 10-30 s depending on cellular RTT.
  7. Acceptance test. Document the session: timestamp, RSSI, RTT, project revision downloaded, user ID. Capture a screenshot of the STEP 7 "Online → Accessible Nodes" view and store it in the site quality file.

7.1 Cellular signal quality thresholds

RSSI RSRP (LTE) Effect on remote programming
> -75 dBm > -90 dBm Full project upload/download acceptable; expected tunnel RTT < 250 ms.
-85 to -75 dBm -100 to -90 dBm Online/compare works; full upload > 5 MB may time out, prefer block-by-block download.
< -85 dBm < -100 dBm Not reliable; relocate antenna, add external antenna, or fall back to MPI local.

8. MPI / PROFIBUS / TCP Pass-Through Selection

If the S7-300 CPU only exposes MPI (CPU 312/314 without PN option) and the customer refuses any IP device in the cabinet, the only viable WAN choices are PSTN (TS Adapter II) or cellular with an MPI pass-through adapter. The Flexy + FLB3202 MPI card emulates a master on the MPI segment and proxies S7 frames to Talk2M.

Field bus CPU required Remote gateway Effective STEP 7 online speed
MPI 187.5 kbit/s Any TS Adapter II (PSTN) or Flexy+FLB3202 Project upload roughly 3-8 kbit/s effective, slow but reliable.
MPI 1.5 Mbit/s CPU ≥ 314 Flexy+FLB3202 Effective about 120 kbit/s.
PROFIBUS DP 1.5 Mbit/s CPU with DP port Flexy+FLB3204 or NetLink Comparable to MPI 1.5 Mbit/s.
PROFINET 100 Mbit/s CPU 31x-2 PN/DP Cosy+ Ethernet Project upload saturates at cellular RTT.
Selection rule: If the S7-300 has a PN port, prefer PROFINET for remote programming even when the bus is shared with an HMI. The S7 protocol is light; the bottleneck is cellular RTT, not bandwidth. A session at 250 ms RTT will download a 2 MB project in roughly 70 s.

9. Security Architecture Without Site VPN

Cellular teleservice routers and dial-up Teleservice adapters provide implicit network segmentation. The principles to enforce on site:

  • Outbound only. The plant-side device (Cosy+, TS Adapter II) opens the connection outbound to a broker (Talk2M) or accepts a callback from the engineering workstation. The plant firewall never accepts inbound connections from the public Internet.
  • Device identity. Use the Ewon OTP key provisioning or the TS Adapter II PIN + callback number. Do not share PINs across sites.
  • Two-factor on the broker. Talk2M supports MFA on the eCatcher account. Enable it.
  • Session logging. Talk2M records every tunnel establishment with timestamp and user. Export logs monthly for the customer's IT audit.
  • VLAN separation. If the Cosy+ sits on the same physical switch as the HMI, place the Cosy+ on a separate VLAN with inter-VLAN routing disabled. The Cosy+ only needs to reach the CPU's IP, not the rest of the plant.

10. Verification and Diagnostics

After commissioning, perform the following verification on every remote session:

  1. Identity check. Confirm the CPU order number and firmware version via PLC → Accessible Nodes → Object Properties. Match against the project's hardware configuration.
  2. Online compare. Run PLC → Compare Online/Offline. The result must be "Identical" before downloading any change.
  3. Diagnostic buffer. Open PLC → Diagnostics/Settings → Diagnostic Buffer. Confirm there are no active errors. The buffer must show a clean power-on or clean run-up event.
  4. Cycle time. Read OB1 cycle time and compare to the project's expected OB1 scan time. A sudden doubling indicates a stuck or new I/O fault that may have nothing to do with the remote link.
  5. Time sync. On remote sessions, the engineering workstation may be in a different time zone. Verify the CPU clock via PLC → Set Time of Day and choose "Take from PG/PC" only after the user has confirmed the workstation clock is correct.

10.1 STEP 7 diagnostic buffer codes relevant to remote sessions

Event ID (hex) Meaning Remote-link implication
0x1381 Online: connection established Normal on each session open.
0x1382 Online: connection terminated Normal on session close.
0x3942 Communication error on MPI/PB Check TS Adapter II / Flexy wiring.
0x4304 STOP due to communication failure Possibly caused by loss of MPI/PB partner; investigate.
0xA180 Time sync error Re-set time after session.

11. Troubleshooting Matrix

Symptom Likely cause First check Fix
STEP 7: "Online: cannot reach partner" PG/PC interface set to wrong adapter Open Set PG/PC Interface Select TCP/IP → correct LAN adapter.
eCatcher: Cosy+ shows red SIM not registered, or Talk2M blocked Cosy+ status page; check APN Re-enter APN; confirm SIM active.
Teleservice wizard hangs at "Dialing" PSTN line is VoIP ATA with poor DTMF Test line with analog handset Replace with cellular path or ask for true POTS.
TS Adapter II answers but STEP 7 cannot find CPU Wrong MPI address or wrong bus Check CPU's MPI address with HMI Set correct MPI address in Teleservice entry.
Flexy MPI card shows RUN, but STEP 7 cannot go online CPU is in RUN with password, or MPI address conflict Try "Accessible Nodes" instead of project go-online Resolve address conflict; check password.
Cellular RSSI < -100 dBm Antenna inside shielded cabinet Move antenna outside cabinet Use external antenna on top of cabinet.
Project upload times out at 2 MB Cellular RTT > 500 ms Ping the CPU through tunnel Reduce block size in STEP 7; download FC/DB individually.
CPU stops after remote session CPU was in STOP before session, or remote download triggered reload Read diagnostic buffer Investigate original STOP cause before restarting.

12. Frequently Asked Questions

Which remote programming method should I choose for a new S7-300 site in a regulated (pharma or food) environment?

Use an Ewon Cosy+ (EW24500A-EU) on 4G LTE through the Talk2M broker. The customer's network never accepts an inbound connection, the connection is outbound-initiated by the plant, and Talk2M logs every session for audit. Pair with MFA on the eCatcher account and a dedicated industrial SIM with a monthly data cap.

Can I program an S7-300 over MPI remotely using a cellular router?

Yes, with an Ewon Flexy fitted with the FLB3202 MPI card, or with a NetLink PRO LAN-to-MPI gateway behind an Ewon Cosy+. The effective programming speed is roughly 120 kbit/s at 1.5 Mbit/s MPI. Use this path only when the CPU has no PROFINET port.

Is the Siemens TS Adapter II still supported for new installations?

Siemens continues to ship and repair the TS Adapter II, but new installations are rare because PSTN is being decommissioned and the Ewon path is operationally simpler. Prefer the cellular path unless the customer mandates a true analog air gap and refuses any IP device in the cabinet.

How do I avoid the CPU going into STOP after a remote download?

Open the project's hardware configuration and confirm that the CPU's startup behavior is set to "Warm restart" rather than "Cold restart". Also disable "Reset outputs on STOP" unless process safety requires it. Document the change in the change log so the customer can audit it.

What cellular antenna setup is acceptable inside a steel cabinet?

Place the antenna on top of the cabinet with a short (< 3 m) low-loss coax to the Ewon Cosy+. If RSSI remains below -90 dBm, mount a high-gain (5 dBi) external antenna on the cabinet roof or through the wall. Avoid mounting inside the cabinet; the steel attenuates the LTE signal by 15-25 dB.

Back to blog