Overview: The SIMATIC NET OPC Routing Problem
Engineers frequently attempt to deploy a single Siemens SIMATIC PC Station with SIMATIC NET OPC Server to read data tags from multiple S7 controllers on the same Industrial Ethernet subnet, especially when one CPU (for example, an S7-400) already terminates the backbone and a second CPU (for example, an S7-300) sits one PROFINET/Industrial Ethernet hop away. The intuitive idea is to use the S7-400 as an application-level router — the OPC client sends an S7 read request to the S7-400, which then forwards the request to the S7-300 over an S7 connection that the CPU-400 has already established. STEP 7 supports this concept for engineering stations via PG routing, but SIMATIC NET OPC Server does not implement the same routing primitive for S7 user-data connections. This technical reference explains why that limitation exists, maps the supported and unsupported communication topologies, and documents working alternatives using direct Ethernet attachment, the S7 protocol suite, and S7 routes defined in the station configuration.
Architecture: SIMATIC PC Station and SIMATIC NET Components
The SIMATIC PC Station is a software-defined controller participant in an S7 network. The relevant components are:
- SIMATIC NET OPC Server – the OPC DA / OPC UA server process that exposes S7 variables to OPC clients. It uses the S7 communication protocol over ISO-on-TCP (RFC1006, port 102) or ISO (ISO 8073).
- SIMATIC NET PC Station Configuration Editor – the "Station Configuration" tool that assigns the PC station's S7 address, slot number (typically Slot 1), and the CP module index.
- CP 1613 / CP 1623 / CP 1612 A2 – the Industrial Ethernet communication processor installed in the PC. The CP presents itself to the S7 network as an S7 station in its own right and is what the OPC Server binds to.
- Softnet IE / Softnet PROFINET – the S7 communication software installed on the PC.
Because the PC station presents itself as a peer on the Ethernet bus, the OPC Server can only read tags from S7 stations to which it has an end-to-end ISO-on-TCP or S7 connection. It cannot stitch multi-hop S7 paths the way STEP 7 does for engineering access.
Why STEP 7 Routes but SIMATIC NET OPC Does Not
STEP 7 Routing Model
STEP 7 V5.5 and TIA Portal both support PG routing and S7 routing when the network is configured with the appropriate route tables. A route is defined in the project's NetPro (STEP 7 V5.x) or in the Devices & Networks editor (TIA Portal). When a programming device (PG) or another S7 station wants to communicate with a remote station, the PG/PC sends the first packet addressed to an intermediate router CPU; the router CPU forwards the packet based on its routing table to the next hop. This works because STEP 7 implements the S7 routing extension described in the Siemens S7 communication manuals.
SIMATIC NET OPC Server Model
SIMATIC NET OPC Server exposes tags via the OPC DA 2.0/3.0 interface. To read a tag, the OPC Server invokes an S7 Read / Write service on a single ISO-on-TCP connection that terminates directly at the target CPU. The server therefore expects:
- A configured single-hop Ethernet path to the target S7 CPU, and
- An OPCP connection object bound to a CP on the PC station.
The S7 routing primitive used by STEP 7 (PG routing via router CPU) is not exposed as an OPC item access service by SIMATIC NET. The OPC Server has no concept of "read tag at S7-300 by going through S7-400." Each S7 read/write must terminate on the same CPU as the OPC connection.
Hardware and Software Versions Referenced
| Component | Catalog Number / Order Number | Version / Firmware | Notes |
|---|---|---|---|
| CP 1613 A2 | 6GK1 161-3AA01 | Hardnet IE, FW ≥ V2.6 | PCI card, supports ISO, TCP, and UDP simultaneously. |
| CP 1623 | 6GK1 162-3AA00 | FW ≥ V1.0 | PCIe, used as OPC server interface in PC stations. |
| CP 1612 A2 | 6GK1 161-2AA01 | Softnet IE compatible | Lower-cost option, only one protocol active at a time. |
| SIMATIC NET IE Software | 6GK1 704-1LW64 | V6.2 SP1 (legacy) | The PC software package referenced in the source. |
| SIMATIC NET V14 | 6GK1 704-1CW14 | V14 (TIA Portal era) | Required for OPC UA on newer PCs. |
| S7-300 CP 343-1 PN | 6GK7 343-1HX0x-0XE0 | FW V3.x | PROFINET-capable CP for S7-300, ISO on TCP supported. |
| S7-400 CP 443-1 | 6GK7 443-1EX30-0XE0 | FW V3.x | PROFINET CP for S7-400. |
Topology: What the Source Picture Describes
- SIMATIC PC Station – host of SIMATIC NET OPC Server, equipped with CP 1613 (FW V6.2 SP1 driver stack).
- SIMATIC 400 (1) – S7-400 CPU with CP 443-1 on the same Ethernet subnet.
- SIMATIC 300 (1) / 400 (2) – additional S7 station(s) intended to be reached through SIMATIC 400 (1).
The direct, supported path of communication is PC Station ↔ 400(1) and PC Station ↔ 300(1) independently. The dashed line shows the desired but unsupported indirect path.
Why Reading Through the S7-400 "Works" but OPC Cannot Reach It
The S7-400 CPU does support PUT/GET, BSEND/BRCV, and USEND/URCV on S7 connections programmed between CPUs. An S7-300 connected to the same subnet can publish its tags via a configured S7 connection to the S7-400. The S7-400 in turn exposes those tags through its own DB / process image. From STEP 7's perspective, the S7-400 looks like a single S7 station containing consolidated data.
However, the OPC Server is bound to a single OPC connection on the PC's CP 1613. That connection terminates at one Ethernet address — the S7-400. From the OPC Server's namespace, the S7-400's DB is opaque; the OPC Server has no mechanism to read across the S7 connection it owns. Therefore, even though the engineering data exists at the S7-400, the OPC Server cannot pull it without either:
- A second, direct Ethernet connection from the PC station to the S7-300, or
- An S7 program in the S7-400 that copies the required tags into a DB accessible to the OPC Server, or
- An OPC UA aggregation server (or middleware) sitting on top of two separate SIMATIC NET OPC Servers.
Step-by-Step: Validating the OPC Connection Inventory
- Open Station Configuration Editor on the PC station and confirm the CP 1613 is online and indexed in Slot 1, Index 1 (or per project).
- Open SIMATIC NET OPC Scout V10 (or S7-OPC Configurator) and add a new OPC group.
- For each S7 CPU that the OPC Server must read, add an OPC item using the syntax
S7:[<connection>]<DB>.,<ByteOffset>,<ElementType>. The<connection>must reference anS7 connectionobject in the station configuration that points to the target CPU's Ethernet IP address. - Click Activate. Each active item establishes its own S7 connection. Items that cannot establish a connection return Quality = BAD with
E_CPCiServerCom.
Diagnostic Error Codes and Quality Flags
| OPC Quality | Typical Hex Code | Meaning | Corrective Action |
|---|---|---|---|
| BAD / Configuration error | 0x80040000 + 0x00000001 | S7 connection object missing in PC station | Re-export station from STEP 7 / TIA and re-import. |
| BAD / Not Connected | 0x80040000 + 0x00000004 | No TCP/IP connection to target | Ping the IP, check VLAN, check CP module index. |
| BAD / Out of Service | 0x80040000 + 0x00000002 | OPC group not active | Activate group; verify license. |
| BAD / Device Failure | 0x80040000 + 0x00000005 | CP rejected TPDU | Check S7 connection resource (max 16/32 per CP). |
| UNCERTAIN / Last usable value | 0x40000000 + 0x00000004 | Watchdog timeout | Increase CP timeout in OPC Configurator. |
Working Alternative 1: Programmatic Tag Replication in the S7-400
The most common work-around when the PC station only has one CP and cannot reach the S7-300 directly is to write a small S7 program in the S7-400 that PUTs/GETs the required tags from the S7-300 into a local DB on the S7-400. The OPC Server then reads the local DB.
Implementation pattern (LAD/FBD-style summary):
- Configure an S7 connection in NetPro between S7-400 (local) and S7-300 (remote), type S7 connection.
- In the S7-400, call GET (SFB 14 / FB 14 equivalent in classic S7) on a cyclic OB (typically OB35 with 100 ms cycle) to pull selected DBs from the S7-300 into the S7-400's local DB.
- Configure the OPC Server connection to the S7-400's local DB.
Example SCL snippet for the periodic GET in the S7-400:
IF "Pulse_1s" THEN
"REQ_300_DB" := TRUE;
END_IF;
// SFB 14 GET on rising edge of REQ
IF "REQ_300_DB" THEN
// IDB from NetPro / S7 connection to S7-300
GET(
REQ := "REQ_300_DB",
ID := W#16#1, // S7 connection ID
NDR := "NDR_done",
ERROR := "GET_err",
STATUS := "GET_status",
ADDR_1 := P#DB300.DBX 0.0 BYTE 100,
RD_1 := P#"LocalMirror".DBX 0.0 BYTE 100
);
"REQ_300_DB" := FALSE;
END_IF;
Working Alternative 2: Direct Ethernet / PROFINET Connection
If the application can be re-cabled, run a second Industrial Ethernet drop from the PC station's CP 1613 (or add a second CP 1612 / CP 1623) directly to the S7-300's CP 343-1. The PC station then holds two independent S7 connections, each with its own OPC connection object. This is the textbook Siemens-recommended topology and avoids CPU coupling entirely.
Working Alternative 3: OPC UA Aggregation via Middleware
Where direct cabling is impossible, an OPC UA aggregation server (such as the OPC Router Data Integration Platform or Siemens OPC UA Companion Specification stack on a WinCC / PCS 7 host) can be placed in the cell. Two SIMATIC NET OPC Server instances, each bound to its own S7 connection, feed the aggregator; SCADA clients then read merged tag sets via OPC UA. This keeps the PC station topology simple but introduces additional engineering effort.
PG Routing vs OPC Routing: When Each Is Used
| Use Case | Mechanism | Tool | Multi-hop via S7-400? |
|---|---|---|---|
| Online programming of remote S7-300 | PG routing | STEP 7 / TIA Portal | Yes |
| HMI panel debugging | PG routing | WinCC flexible / TIA Portal | Yes (with configured route) |
| OPC DA / UA read of remote S7-300 | S7 OPC connection | SIMATIC NET OPC Server | No |
| OPC UA Pub/Sub of remote S7-300 | OPC UA Pub/Sub broker | Siemens OPC UA Server | No (still single-hop S7) |
| S7-400 as a "gateway" for OPC tags | S7 PUT/GET + OPC Server | STEP 7 + SIMATIC NET | Yes, through S7-400 program |
Configuration Reference: Station Import from TIA Portal
- In TIA Portal, open the PC station and add the CP 1613/1623 with the correct order number.
- Configure an S7 connection per target CPU. Set Active connection establishment = yes if the PC initiates the connection.
- Compile the PC station and export the XDB / station configuration.
- On the PC, open Station Configuration Editor → Import Station, select the XDB.
- Restart the SIMATIC NET service.
Verification Checklist After Configuration
- CP 1613 / CP 1623 diagnostic LEDs: LINK green steady, RX/TX flickering under load.
- OPC Scout: Quality = Good on at least one item from each S7 CPU.
-
pingon the PC command line successfully reaches every target CPU IP. - Siemens SIMATIC NET Diagnostic Tool (PC station) shows each connection Established.
- No entries in
Siemens.SimaticNet.EventsWindows log with Error severity.
Edge Cases and Field Notes
- VLAN segmentation: If the S7-300 sits behind a managed switch on a separate VLAN, even direct Ethernet access from the PC requires inter-VLAN routing. SIMATIC NET does not support L3 routing above ISO-on-TCP.
- CP 343-1 firmware mismatch: Older CP 343-1 (6GK7 343-1EX10, FW V1.x) cannot act as an S7 connection partner in parallel with PROFINET. Upgrade to FW V2.x or V3.x.
- OPC license: SIMATIC NET V6.2 SP1 historically shipped with a 30-day demo; subsequent reads fail with Quality = BAD / License missing. Apply a valid Hardnet IE S7-1613 or Softnet IE S7 license key.
- S7 connection count: S7-300 CPUs have a hard limit of 16 S7 connection resources for BSEND/BRCV/PUT/GET. Heavy use of CPU-to-CPU GETs in addition to OPC consumes this budget.
- OPC UA vs OPC DA: Newer SIMATIC NET releases (V14 and later) expose OPC UA on port 4840; S7 routing restrictions still apply to OPC UA read services, because the same S7 connection limitation exists underneath.
Safety and Operational Considerations
Related Siemens Documentation
- SIMATIC NET PC Software: Manual Collection
- SIMATIC S7-300 / S7-400: Communication Functions
- STEP 7 Professional: Routing Functions
- CP 1613 / CP 1623: Communications Processor Manual
- Siemens Industry Online Support Knowledge Base
FAQ
Can SIMATIC NET OPC Server route through an S7-400 to read a remote S7-300?
No. The SIMATIC NET OPC Server establishes a single S7 connection per OPC connection object and cannot chain S7 hops. Only direct Ethernet/IP reachability between the PC's CP and the target CPU is supported; indirect read-through via a router CPU is not implemented in any standard SIMATIC NET release.
What is the recommended way to expose S7-300 tags via SIMATIC NET when the PC station is single-subnet?
Run a periodic GET in the S7-400 (SFB 14 / equivalent) that mirrors the required S7-300 data into a local DB, then let the OPC Server read that local DB on the S7-400 directly. Typical cycle time on OB35 is 100 ms.
Which CP should be used on the PC station for SIMATIC NET V6.2 SP1?
The CP 1613 A2 (6GK1 161-3AA01) with Hardnet IE S7 OPC license is the legacy reference. For new designs use the CP 1623 (6GK1 162-3AA00) on PCIe with SIMATIC NET V14 or later.
Does OPC UA in newer SIMATIC NET versions lift the routing restriction?
No. OPC UA uses the same S7-on-TCP transport underneath; multi-hop routing through an S7-400 is still not supported. OPC UA only changes the client-server wire format, not the underlying S7 connection model.
How do I confirm whether the PC station has end-to-end Ethernet to a target CPU?
Open a Windows command prompt on the PC, run ping <target-IP>, and from OPC Scout add a one-item group pointing to that CPU. A successful read with Quality = GOOD indicates end-to-end reachability; Quality = BAD / Not Connected indicates a wiring, VLAN, or CP-index issue to resolve before any routing scheme is considered.