1. System Requirement Analysis and I/O Inventory
The target system specification is a mid-range factory automation project requiring 155 active digital inputs with 30% spare (200 DI total), 85 active digital outputs with 30% spare (120 DO total), 8 analog inputs, and 8 analog outputs. A single maintenance engineering workstation must connect to the PLC over Ethernet TCP/IP, and a single HMI panel must connect over Profibus DP. The challenge is to size a controller, signal modules (SM), communication processors (CP), and power supplies that meet the channel count with the requested spare, while keeping the OB1 cycle time short enough for the controlled process.
Begin by formalising the requirement into an I/O inventory. The 30% spare on digital I/O is critical: it is the most common source of under-engineering in greenfield projects. Skimping on spare channels forces a controller re-spin and a panel re-cut the first time a new sensor or actuator is added. Treat the 200 DI / 120 DO values as the design floor, not the design target. Where possible, leave a further 10-15% free slots in each rack for future SM modules (relays, counters, fast inputs, fail-safe modules) without re-wiring the backplane.
Classify the I/O by signal type and switching voltage. The default for a discrete factory floor is 24 V DC sourcing inputs and 24 V DC transistor outputs rated at 0.5 A per channel. If any of the 120 DO are 230 V AC solenoids or motor contactors, plan at least one SM 322 DO 8×230VAC/2A (6ES7322-1HF01-0AA0) or use interposing relays. Group high-speed counters (for example encoder feedback) into SM 321 DI 24×24 V DC with hardware interrupt capability (6ES7321-7BH01-0AB0).
2. I/O Module Selection and Channel Mapping
Siemens signal modules for the S7-300 / S7-400 platform are 8, 16, or 32 channels wide. For purely economic reasons, prefer 32-channel modules on digital I/O so the rack slot count (and the IM 460/461 or ET 200M station width) stays low. For analog I/O, 8-channel modules are the sweet spot between cost-per-channel and wiring density.
| I/O Type | Channels Required | Recommended SM Module | Order Number | Modules Needed | Total Channels | Spare Channels |
|---|---|---|---|---|---|---|
| DI 24 V DC | 200 | SM 321, 32×24 V DC | 6ES7321-1BL00-0AA0 | 7 | 224 | 24 |
| DO 24 V DC / 0.5 A | 120 | SM 322, 32×24 V DC / 0.5 A | 6ES7322-1BL00-0AA0 | 4 | 128 | 8 |
| AI universal | 8 | SM 331, 8×12 bit | 6ES7331-7KF02-0AB0 | 1 | 8 | 0 |
| AO universal | 8 | SM 332, 8×12 bit | 6ES7332-5HF00-0AB0 | 1 | 8 | 0 |
Total SM modules: 7 + 4 + 1 + 1 = 13. The 12% spare on DI (24/200) and 6.7% spare on DO (8/120) come from the next-channel-up multiple; the user-requested 30% spare is already absorbed because the requirement was specified as 155 DI / 85 DO active. If the requirement had been 200 active DI with 30% spare on top, the channel count would be 260, requiring 9 SM 321 modules.
Verify the analog module accuracy is sufficient. The 7KF02 variant is 12-bit + sign (effective ~11-bit plus sign, ~0.098% of full scale). For pressure, level, or flow applications requiring 0.05% accuracy or better, step up to the SM 331 7PF01 (16-bit, 0.05% FS) at higher per-channel cost. The 12-bit AO (5HF00) is fine for proportional valves and variable-speed drive references; upgrade to 8×16-bit (6ES7332-5ND01-0AB0) only if 0.05% setpoint resolution is required.
3. CPU Selection: S7-400 vs S7-300
For 200 DI / 120 DO / 8 AI / 8 AO, both the S7-400 and the S7-300 will fit. The decision is about headroom, lifecycle, and the communication interfaces you need today and five years from now.
| Parameter | S7-400 CPU 412-2 PN/DP (6ES7412-2EK06-0AB0) | S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) |
|---|---|---|
| Work memory (code + data) | 1 MB | 512 KB |
| Load memory | 4 MB RAM, expandable with MMC | MMC up to 8 MB |
| Bit memory (M) | 8 KB | 4 KB |
| S7 timers / counters | 2 048 / 2 048 | 2 048 / 2 048 |
| Max DI / DO (addressable) | 32 768 / 32 768 | 16 384 / 16 384 |
| Max AI / AO (addressable) | 2 048 / 2 048 | 1 024 / 1 024 |
| Max SM modules in central rack | up to 18 (UR1) plus 21 expansion racks via IM 460/461 | 8 per rack, up to 4 racks via IM 360/361 = 32 SM |
| Profinet interface | 2-port switch, Profinet IO controller | 2-port switch, Profinet IO controller |
| Profibus DP master | Yes, integrated DP master | Yes, integrated DP master |
| Number of Profinet IO devices | 256 | 128 |
| Number of DP slaves | 32 per DP line, 125 with repeaters | 32 per DP line, 125 with repeaters |
| OB1 typical cycle with 13 SM | 5-15 ms | 10-25 ms |
The S7-400 CPU 412-2 is the recommended choice when:
- The site standard is S7-400 (common in legacy plants, automotive, water/wastewater, power).
- The expected growth is 50-100% additional I/O over 5 years.
- Fail-safe (F) CPUs may be required later (CPU 412F / 414F / 416F).
- The application includes CPs for Profinet IRT, Profibus, Modbus TCP, or OPC UA server (S7-400 supports more CP options).
- Hot-swap and high availability (S7-400H) is in the roadmap.
The S7-300 CPU 315-2 PN/DP is the recommended choice when:
- The site standard is S7-300 and the panel builder is comfortable with distributed I/O via Profinet.
- The application is cost-sensitive and the I/O is unlikely to grow by more than 25%.
- The HMI connects via Profibus DP (a built-in DP port on the CPU handles up to 32 slaves without any CP).
For the stated requirement (200 DI / 120 DO / 8 AI / 8 AO + Ethernet maintenance PC + Profibus HMI), the S7-400 CPU 412-2 EK06 is the smallest-fit, conservative option. The S7-300 CPU 315-2 EH14 is the smallest-fit, cost-optimised option. Either is a sound engineering choice; the S7-400 simply carries more memory and rack slots for future expansion.
4. Rack Configuration and Power Supply Sizing
Compute the 24 V backplane power budget before picking the power supply module. Add the typical power dissipation values of every module; do not rely on the "max" ratings, which include short-circuit currents.
| Module | Quantity | Dissipation (typ) per module | Total |
|---|---|---|---|
| CPU 412-2 PN/DP | 1 | 3.5 W | 3.5 W |
| SM 321 32×24 V DC | 7 | 6.5 W | 45.5 W |
| SM 322 32×24 V DC / 0.5 A | 4 | 6.8 W | 27.2 W |
| SM 331 8×AI 12-bit | 1 | 1.8 W | 1.8 W |
| SM 332 8×AO 12-bit | 1 | 3.5 W | 3.5 W |
| CP 443-1 (Ethernet, optional) | 1 | 5.0 W | 5.0 W |
| Total backplane power | 86.5 W | ||
Power supply selection:
- S7-400: Use PS 405 10 A (6ES7405-0KA02-0AB0) for the UR1 rack. Rated 24 V DC / 10 A = 240 W available to the backplane. Operating margin = 240 - 86.5 = 153.5 W (64% headroom). Add a second PS 405 in redundant mode only for high-availability plants.
- S7-300: Use PS 307 5 A (6ES7307-1EA01-0AA0) for both the main rack and any expansion rack. Rated 24 V / 5 A = 120 W. Operating margin = 120 - 78 = 42 W (35% headroom). The PS 307 2 A (6ES7307-1BA01-0AA0) is too small (60 W) for a rack with 7×SM 321 + 4×SM 322.
Rack layout (S7-300 main rack, slots numbered left to right as installed):
- Slot 1: PS 307 5 A
- Slot 2: CPU 315-2 PN/DP
- Slot 3: IM 360 (send) - only if expansion rack is required
- Slots 4-11: 8× SM (4×SM 321 + 3×SM 322 + 1×SM 331, leaving 1 slot free)
Remaining 4 SM modules (3×SM 322 + 1×SM 332) fit in expansion rack 1 with IM 361 (receive) at slot 3. The 8-channel limit per rack is then met. If slot utilisation is the concern, swap to the S7-400 UR1 (18 slots) and place all 13 SM modules plus CP in a single rack.
Sensor supply current check: each SM 321 32×24 V DC can source up to 30 mA per channel for a 3-wire sensor, total 32 × 30 mA = 960 mA per module. With 7 SM 321 = 6.72 A. The PS 307 5 A can only supply 5 A to the sensor bus. If all 200 DI are PNP 3-wire devices, plan an external 24 V DC power supply (for example SITOP 6EP1334-3BA10) sized for 8 A. Otherwise switch to 4-wire (separate sensor power) or use 2-wire NAMUR inputs.
5. Communication Architecture: Profinet, Profibus, and Ethernet
The application defines two parallel networks: a Profibus DP line for the HMI panel and an Ethernet TCP/IP line for the maintenance PC. Both are present on the S7-300 and S7-400 CPUs as built-in interfaces - no extra CP is required if you accept Profinet on the Ethernet side and Profibus DP master on the HMI side.
For the maintenance PC link, two architectures are common:
- Direct Profinet on the CPU port. The CPU 315-2 PN/DP or 412-2 PN/DP has a 2-port managed switch. Connect the engineering PC with a standard patch cord. TIA Portal / STEP 7 talks to the PLC over the S7 protocol, port 102. This is the cheapest solution and works for projects under ~10 000 tags.
- Dedicated Ethernet CP (CP 343-1 / CP 443-1). If the engineering PC is in a plant network, place a CP on the backplane to isolate the field network from the corporate LAN. The CP 443-1 (6GK7443-1EX30-0XE0) supports 32 S7 connections, IP routing, and basic IT diagnostics. The CP 343-1 Lean (6GK7343-1CX10-0XE0) supports 8 connections and is the budget pick for S7-300.
For the HMI Profibus connection, the CPU's integrated DP master port is the cheapest path. A 12 Mbaud Profibus segment with 32 slaves, total segment length up to 1 000 m without repeaters, easily carries a KTP1200 Basic DP panel. The HMI becomes Profibus slave 1, and the maintenance PC becomes Profinet station 2 on the same CPU. Set the DP parameters in HW Config: 1.5 Mbps to 12 Mbps supported, 244-byte I/O per slot, 32 slots.
Profibus termination: install active RS-485 terminators at both physical ends of every segment. The connector 6ES7972-0BA12-0XA0 has an integrated terminator that switches on when the connector is the last on the segment. A repeater (6ES7972-0AA01-0XA0) is required if the segment exceeds 32 nodes or the cable length is over 1 000 m.
| Network | Master | Slave / Device | Cable | Max Length |
|---|---|---|---|---|
| Profinet (Ethernet) | CPU PN port | Maintenance PC, future ET 200 stations | Cat 5e / Cat 6, SF/UTP | 100 m per segment |
| Profibus DP | CPU DP port | HMI panel (e.g. KTP1200 Basic DP) | Profibus purple cable 6XV1830-0EH10 | 1 000 m at 1.5 Mbps, 100 m at 12 Mbps |
Refer to the Profinet user organisation for cable qualification, and the Profibus user organisation for segment layout, baud rate tables, and connector selection.
6. Distributed I/O Alternative with ET 200SP / ET 200M
If the controller needs to be located in an MCC room while the field I/O is split across multiple field junction boxes, replace the central SM modules with ET 200SP (Profinet) or ET 200M (Profinet or Profibus) stations. This is the dominant pattern in modern Siemens plants and decouples the controller hardware from the field wiring.
For the same I/O count using ET 200SP:
- ET 200SP head module: IM 155-6 PN (6ES7155-6AA01-0BN0) or IM 155-6 PN HF (6ES7155-6AU01-0BN0) - 1 per field station.
- DI 32 module: 6ES7131-6BL01-0BA0 with BaseUnit 6ES7193-6BP00-0DA0.
- DO 32 module: 6ES7132-6BL01-0BA0 with BaseUnit 6ES7193-6BP00-0DA0.
- AI 8 module: 6ES7134-6GF00-0AA1 with BaseUnit 6ES7193-6BP00-0DA0.
- AO 8 module: 6ES7135-6HD00-0BA1 with BaseUnit 6ES7193-6BP00-0DA0.
Cycle times: Profinet IO is typically 1-2 ms update for distributed I/O at 100 Mbit/s, faster than a 1.5 Mbps Profibus segment (4-8 ms). Use Profinet for new plants; reserve Profibus for brownfield integration with existing HMI panels.
The Profinet device count limit for the CPU 412-2 is 256; for the CPU 315-2 it is 128. Even a 20-station ET 200SP plant only uses 20 IO devices, leaving 108-236 free IO device slots for future expansion.
7. HMI and Engineering Station Integration
The HMI is a Profibus DP slave on the CPU's integrated DP port. The maintenance PC is a Profinet device (or pure TCP station) on the CPU's integrated PN port. Configure both as separate logical devices in HW Config or TIA Portal - they have different GSD files, different IP / Profibus addresses, and different PG/PC interfaces.
Recommended HMI for a small panel mount installation:
- KTP1200 Basic DP (6AV2 124-1MC01-0AX0): 12" touch, Profibus DP slave, WinCC Basic / Comfort V16. 1 000 tags is more than enough for 8 AI / 8 AO trends.
- Comfort Panel TP1500 (6AV2 124-1QC13-0AX0): 15" if you need recipe handling, audit trail, or OPC UA server.
For the maintenance PC, install TIA Portal V16 / V17 with STEP 7 Professional and WinCC Professional. The PG/PC interface must point to the right Ethernet adapter and the right Profinet or TCP protocol. Typical PG/PC interface assignment: TCP/IP (Auto) for Profinet / Ethernet, PC Adapter (MPI/Profibus) for legacy MPI programming.
8. Bill of Materials (BOM) and Sizing References
The Siemens Industry Mall configurator generates a complete BOM, including screw-type or push-in front connectors, labelling strips, and SIMATIC memory cards. The S7 Configurator exports the BOM as a CSV for direct order upload.
| Item | Order Number | Qty | Description |
|---|---|---|---|
| CPU 412-2 PN/DP | 6ES7412-2EK06-0AB0 | 1 | S7-400 CPU 412, 1 MB, 2 PN, 1 DP |
| PS 405 10 A | 6ES7405-0KA02-0AB0 | 1 | 24 V DC, 10 A, S7-400 PS |
| UR1 rack (18 slots) | 6ES7400-1TA11-0AA0 | 1 | Universal rack for S7-400 |
| SM 321 32×24 V DC | 6ES7321-1BL00-0AA0 | 7 | 32 DI 24 V DC |
| SM 322 32×24 V DC / 0.5 A | 6ES7322-1BL00-0AA0 | 4 | 32 DO 24 V DC / 0.5 A |
| SM 331 8×AI 12 bit | 6ES7331-7KF02-0AB0 | 1 | 8 AI universal |
| SM 332 8×AO 12 bit | 6ES7332-5HF00-0AB0 | 1 | 8 AO universal |
| Front connector 40-pin | 6ES7392-1AM00-0AA0 | 13 | Screw-type front connector for SM |
| MMC 4 MB (for S7-400) | 6ES7952-1AM00-0AA0 | 1 | Micro Memory Card |
| HMI KTP1200 Basic DP | 6AV2 124-1MC01-0AX0 | 1 | 12" touch, Profibus DP slave |
| Profibus connector | 6ES7972-0BA12-0XA0 | 2 | 90° outlet, with PG port, terminating |
For the S7-300 alternative BOM, swap the CPU 412 / PS 405 / UR1 for:
- CPU 315-2 PN/DP 6ES7315-2EH14-0AB0
- PS 307 5 A 6ES7307-1EA01-0AA0 (×2 if using expansion rack)
- UR1 (S7-300) 6ES7300-1BP10-0AA0 (slot count for 11 modules)
- IM 360 (send) 6ES7360-3AA01-0AA0 (in main rack slot 3)
- IM 361 (receive) 6ES7361-3CA01-0AA0 (in expansion rack slot 3)
For pricing and order uploads, use the Siemens Industry Mall or contact the local Siemens rep. For product manuals, firmware updates, and FAQs, use the Siemens Industry Online Support portal.
9. Engineering and Commissioning Workflow
Follow the standard V-model: P&ID → I/O list → hardware design → software design (HMI + PLC) → FAT → site install → SAT → production.
- Build the I/O list. Export from Excel as a CSV. Each row is one signal: tag, P&ID reference, area, rack, slot, channel, type (DI / DO / AI / AO), signal range, sensor / actuator description, cable number, terminal number, ATEX zone (if any).
- Configure the hardware in TIA Portal (or STEP 7 + HW Config). Drag the CPU, PS, IM, SM, CP from the catalog. HW Config / TIA Portal will warn if you exceed the CPU's max I/O count, rack limit, or Profinet / Profibus slave count.
- Assign device names and IP addresses. Profinet devices must be assigned a unique device name via the "Assign device name" wizard (right-click PLC → Online → accessible nodes). Profibus slaves are addressed via DIP switches or rotary switches on the slave.
- Compile and download the project. Use the "Extended download to device" option in TIA Portal, with PG/PC interface set to "TCP/IP (Auto)" for Profinet or "PC Adapter" for Profibus. Verify the "Compile" output has no warnings; warnings usually indicate missing GSD files or parameter conflicts.
- Force and test. Use the Watch table in TIA Portal to set forces, monitor values, and validate the wiring before energising any actuator. Always remove forces before handing the system over - a forced DO can become a hazard after the HMI assumes control.
- Back up the project. Save the TIA Portal project to the engineering PC, the MMC card, and a network share. Generate a PDF of the I/O list and the HW configuration for the documentation package.
Documentation references for design guidelines:
- TIA Portal - Guidelines for designing a PLC system (Siemens official)
- PLC, DCS & PAC design resources - Texas Instruments
- Programmable logic controller - Wikipedia
10. Verification Checklist and Acceptance Test
Before energising any actuator in production, complete this checklist:
- Wiring continuity test. Disconnect the field side. Megger the loop at 500 V DC for 1 s; expect ≥ 100 MΩ.
- Module diagnostic scan. In TIA Portal, go Online → Online & Diagnostics → Diagnostic buffer. The buffer must show no "IO fault", "channel fault", or "parameter error" entries.
- Channel test. For every DI: stimulate the sensor (or short the terminal) and verify the corresponding I bit toggles in the Watch table. For every DO: drive the output from the Watch table, measure the voltage at the field terminal, verify the actuator responds.
- Cycle time test. Use OB1's run time information in the system status list (SSL) - "Cycle time of OB1" (SSL ID 0x0132). Expect 10-25 ms for S7-300, 5-15 ms for S7-400. Cycle time must be below the longest process time constant in the plant.
- Communication test. From the maintenance PC, ping the PLC's IP address. Open TIA Portal Online → Accessible nodes, confirm the PLC appears. From the HMI, verify a tag read (e.g. AI 0) shows the correct engineering value.
- Fault test. Pull a Profibus connector. The CPU's diagnostic buffer must log "DP slave failure" with the slave number, and the HMI must show the configured "slave not reachable" message.
- Backup the final project. Upload the project from the PLC back to TIA Portal ("Upload from device"). Save the result as the "as-built" archive. Store on the engineering PC, the MMC card, and the network share.
If any of the seven steps fails, return to engineering and resolve. Do not sign the SAT (Site Acceptance Test) until every step passes.
1. Which Siemens CPU is the smallest-fit for 200 DI, 120 DO, 8 AI, 8 AO?
Both the S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) and the S7-400 CPU 412-2 PN/DP (6ES7412-2EK06-0AB0) fit the I/O count. The S7-300 is the cost-optimised choice with one expansion rack for the 13 SM modules; the S7-400 is the conservative choice with all SMs in a single UR1 rack and more memory for future expansion.
2. How many SM 321 digital-input modules are required for 200 DI?
200 ÷ 32 = 6.25, rounded up to 7 SM 321 6ES7321-1BL00-0AA0 (32 DI 24 V DC each). The seventh module gives 224 channels, leaving 24 spare DI for field additions and absorbing the operator-requested 30% spare.
3. Does the maintenance PC need a CP 343-1 / CP 443-1 if the CPU has a Profinet port?
No. The CPU 315-2 PN/DP and 412-2 PN/DP have an integrated 2-port Profinet switch that supports S7 communication (port 102) for engineering and HMI traffic. A CP is only required if you need to physically isolate the field network from the corporate LAN, support more than 16 S7 connections, or add IT diagnostics (SNMP, port mirroring, firewall).
4. How long can the Profibus segment be between the CPU and the HMI?
Up to 1 000 m at 1.5 Mbps, 400 m at 3 Mbps, 200 m at 6 Mbps, or 100 m at 12 Mbps. The Profibus purple cable 6XV1830-0EH10 supports the full length. Active terminators (6ES7972-0BA12-0XA0) are required at both physical ends of every segment.
5. What power supply size is needed for the S7-300 rack with 13 SM modules?
Use the PS 307 5 A (6ES7307-1EA01-0AA0) for both the main and the expansion rack. With 13 SM modules the typical backplane dissipation is ~78 W, well under the 120 W available from the 5 A supply. The PS 307 2 A (60 W) is insufficient because the SM 322 32×DO alone draws 6.8 W each, and four of them already exceed the 2 A capacity margin.
6. Can the system be migrated to a TIA Portal V17 project later?
Yes, but the CPU firmware must be compatible. S7-300 CPU 315-2 EH14 firmware V3.3 or higher, and S7-400 CPU 412-2 EK06 firmware V6.0 or higher, are the minimum versions supported by TIA Portal V17 Update 2. STEP 7 V5.5 SP2 projects migrate to TIA Portal via the "Migrate project" wizard with manual touch-up on the hardware catalog.