Overview
The SINAUT MD720-3 (Siemens order number 6NH9720-3AA00) is a GSM/GPRS modem used as the telecontrol link in SINAUT ST1 and SINAUT ST7 systems. Firmware updates are applied locally through the modem's front-panel RS-232 service port using a PC running the Siemens MD720-3 firmware update tool. Connection problems during the update are almost always traceable to the serial cable, the DB-9/DB-25 adapter, or the PC COM port selection; the modem hardware itself is rarely at fault when the symptom is a generic "hardware failure" message at the handshake stage.
This article documents the cable requirements, the official Siemens firmware update procedure (firmware V1.7.7 was the target in the originating service case), and the diagnostic steps used to isolate a hardware-failure error encountered during a live update. The case study is built around a damaged 9-pin contact in a generic 25-to-9 pin adapter, which is one of the most common failure modes observed in field service.
Prerequisites
Verify the following hardware, software, and documentation items are on the bench before the update window starts.
- SINAUT MD720-3 modem (6NH9720-3AA00) with a known-good 24 V DC supply.
- Target firmware file (for example, MD720-3 V1.7.7) downloaded from Siemens Product Support.
- PC with a free RS-232 (COM) port, or a proven USB-to-RS-232 converter based on FTDI or similar industrial-grade silicon.
- Siemens MD720-3 firmware update utility as referenced in Siemens Support Entry 23067682.
- Straight-through (1:1) RS-232 serial modem cable. Do not use a null-modem (crossover) cable.
- DB-9 female to DB-25 male adapter only if the PC end is a legacy DB-25 connector.
- Multimeter with continuity mode for cable and adapter verification.
- Loopback connector (DB-9 female with pins 2-3 bridged) for PC COM port self-test.
Identifying the Modem and Service Port
The MD720-3 has two DB-9 male connectors on the front face. The lower connector is the service port used for firmware updates and AT-command diagnostics. The upper connector (when fitted) is the data interface to the SINAUT ST1/ST7 station. Both are wired identically as RS-232 DCE ports; only the service port is used for firmware update.
| Front-Panel Item | Function |
|---|---|
| Lower DB-9 male | RS-232 service / firmware update / AT command port |
| Upper DB-9 male (option) | PPP/AT data interface to the SINAUT station |
| SMA female | GSM antenna connector |
| SIM holder | Standard 3 V GSM SIM |
| Power LED (green) | 24 V supply and internal DC-DC OK |
| Service LED (yellow) | Bootloader and firmware transfer activity |
Cable Candidates: What Works and What Does Not
The originating service case listed four Siemens cables plus a standard serial cable plus a generic 25-to-9 pin adapter. None of the Siemens MPI/PC adapter cables is suitable for the MD720-3 service port; they are designed for S7 MPI/PROFIBUS programming and will not perform an MD720-3 firmware update. The 25-to-9 pin adapter is acceptable in principle, but its pin integrity must be verified before use.
| Siemens Order Number | Designation | Intended Use | Suitable for MD720-3 Service Update? |
|---|---|---|---|
| 6ES7 901-3CB30-0XA0 | PC/MPI cable (USB) | S7 MPI/PROFIBUS programming | No |
| 6ES7 902-1AB00-0AA0 | PC/MPI cable (RS-232) | S7 MPI/PROFIBUS programming | No |
| 6ES7 705-0AA00-7BA0 | TS Adapter II | Modem-to-CPU telecontrol link | No |
| 6ES7 901-0BF00-0AA0 | RS-232 null-modem cable | DTE-to-DTE crossover | No (crossover pinout) |
| Generic DB-9 1:1 serial cable | Standard serial extension | DTE-to-DCE | Yes (verify pinout) |
| Generic DB-25-to-DB-9 adapter | Mechanical adapter | Connector format change only | Conditional (verify pinout) |
RS-232 Pinout Reference
The MD720-3 service interface uses the standard IBM-PC AT RS-232 DTE pinout on a DB-9 male connector. A straight-through cable to a PC COM port (also DB-9 male DTE) provides the correct DTE-to-DCE crossover for serial communication.
| DB-9 Pin | Signal | Direction (Modem = DCE) | PC DB-9 Pin (DTE) |
|---|---|---|---|
| 1 | DCD | Modem → PC | 1 |
| 2 | RXD | Modem → PC | 2 |
| 3 | TXD | PC → Modem | 3 |
| 4 | DTR | PC → Modem | 4 |
| 5 | GND | — | 5 |
| 6 | DSR | Modem → PC | 6 |
| 7 | RTS | PC → Modem | 7 |
| 8 | CTS | Modem → PC | 8 |
| 9 | RI | Modem → PC | 9 |
Step-by-Step Firmware Update Procedure
The following procedure is aligned with the official Siemens support entry for the MD720-3 firmware update. Refer to Siemens Support Entry 23067682 for the latest revision and any firmware-specific notes.
- Power down the MD720-3 and disconnect the 24 V supply at the terminals.
- Insert a valid SIM card if a GSM connection will be tested after the update.
- Connect the PC COM port to the lower DB-9 service port of the MD720-3 using a verified 1:1 serial cable. If the PC end is DB-25, attach a continuity-tested DB-25-to-DB-9 adapter.
- Launch the Siemens MD720-3 firmware update tool. Select the COM port and the firmware file (for example, V1.7.7).
- Apply 24 V DC to the modem. Watch the front-panel LEDs. The Power LED should illuminate solid; the Service LED should follow the bootloader pattern.
- Within the boot window defined by the update tool (typically 5-10 s after power-up), the tool sends the boot command and begins downloading the firmware image.
- Wait for the tool to display "Update successful" or equivalent. Do not power-cycle the modem during the update; an interrupted write can corrupt the bootloader.
- Reboot the modem and verify the firmware revision using the AT command
AT+CGMRvia a terminal emulator.
Hardware-Failure Error: Root Cause Analysis
The "hardware failure" or "connection error" returned by the firmware update tool at step 6 is a generic RS-232 layer failure indicator. The tool could not complete the bootloader handshake. The most frequent root causes, in descending order of probability observed in the field:
- Damaged pin in the DB-9/DB-25 adapter (the case described in the originating service report). Symptoms include intermittent connection, an error that appears only after the cable has been moved, or the PC seeing the port as open with no data exchange.
- Crossover (null-modem) cable in use instead of a 1:1 cable. RXD and TXD are crossed, so the modem never sees the boot command.
- Incorrect COM port selected in the update tool. Check Device Manager for the COM number assigned to the USB-to-RS-232 converter.
- Insufficient or unstable 24 V supply. The MD720-3 draws significant inrush current; a weak bench supply can cause the bootloader to reset mid-handshake.
- Modem already in data mode from a previous session. Power-cycle the modem with at least 10 s off time before retrying.
- USB-to-RS-232 converter that does not buffer or that maps non-standard pins. Industrial-grade converters based on FTDI or similar proven parts are recommended.
- Modem is in a state requiring a recovery boot that the update tool's default timeout does not support. Hold the reset line or reapply power within the boot window.
Field-Proven Diagnostic: The 25-to-9 Pin Adapter Failure
The originating service case was resolved by opening the 25-to-9 pin adapter, finding a damaged pin, and re-soldering the joint. The following diagnostic sequence is recommended before assuming the cable or the modem is at fault.
- Disconnect the cable from the PC and the modem.
- Set a digital multimeter to continuity mode (beep on short).
- Probe each of the nine DB-9 pins on the modem end of the cable to the corresponding pin on the PC end. All nine should show continuity.
- If an adapter is in the path, repeat the continuity test across the adapter. Verify each of the 25 pins on the DB-25 side maps to the correct DB-9 pin per the standard PC AT pinout.
- Inspect each pin under a magnifier for bent, recessed, or oxidized contacts. Female DB-9 sockets are particularly prone to opening up after repeated insertions; male DB-25 pins are prone to bending if the adapter is mis-mated.
- Re-tension or replace any loose socket. A bent male pin can usually be straightened with fine-tip pliers; a damaged female socket requires replacement of the adapter.
- Apply power to the modem without the cable connected and confirm the Power and Service LEDs behave as expected (see LED reference below). This isolates a defective modem from a defective cable.
PC COM Port Self-Test with Loopback
Before pointing the finger at the modem, confirm the PC COM port itself is healthy. A shorted or open port will produce the same "hardware failure" symptom as a bad cable.
- Insert a DB-9 loopback connector (pins 2 and 3 bridged) into the PC COM port.
- Open a terminal emulator such as PuTTY or Tera Term at 115,200 bit/s, 8N1, no flow control.
- Type characters. They should be echoed back to the screen if the port is functional and the loopback is wired correctly.
- Repeat with pins 4 and 6 bridged plus pins 7 and 8 bridged to verify hardware handshaking if the firmware update tool uses RTS/CTS or DTR/DSR.
- If the loopback test fails, the PC COM port (or its USB converter driver) is defective. Replace the converter or use a different PC port before retrying the update.
LED Behavior Reference
| LED | State | Indicates |
|---|---|---|
| Power (green) | Solid on | 24 V supply present, internal DC-DC OK |
| Power (green) | Off | No supply, reversed polarity, or blown internal fuse |
| Service (yellow) | Rapid flashing during transfer | Active firmware transfer in progress |
| Service (yellow) | Solid on for > 30 s after power-up | Bootloader stalled; check cable and supply |
| Service (yellow) | Off | Service port not active or no traffic |
| GSM signal LEDs | Off or cycling | Modem has not yet registered on the GSM network |
Post-Update Verification with AT Commands
After the update tool reports success, perform the following checks before returning the modem to service. Connect a terminal emulator to the service port at 115,200 bit/s, 8N1, no flow control.
- Power-cycle the modem. Confirm the Power LED returns to solid on within 2 s of 24 V application.
- Send
AT. The modem should respondOKwithin 1 s. - Send
AT+CGMRto read the firmware version. Confirm the version string matches the target (for example, 1.7.7). - Send
AT+CPIN?to confirm SIM PIN status. The modem should respond+CPIN: READYif the SIM is unlocked, or+CPIN: SIM PINif a PIN must be entered. - Send
AT+CSQto read signal strength. A value above 10 (out of 31) is generally required for reliable SINAUT ST1/ST7 communication; below 5 the link is unreliable. - Send
AT+CREG?to confirm GSM network registration. A response of+CREG: 0,1or+CREG: 0,5indicates successful registration on the home or roaming network. - Restore the original wiring and trigger a SINAUT test frame from the connected S7 station to confirm end-to-end operation.
Troubleshooting Matrix
| Symptom | Likely Cause | Action |
|---|---|---|
| "Hardware failure" at handshake | Damaged adapter pin, crossover cable, wrong COM port | Continuity check all nine pins, swap to known-good 1:1 cable, verify COM number in Device Manager |
| Tool starts update then fails partway | Weak 24 V supply, USB converter glitch, loose terminal | Use bench supply with current margin, replace USB converter, secure 24 V terminals |
| Modem not detected at all | Cable wired backwards, dead modem, wrong service port | Verify pinout with multimeter, try alternate MD720-3 unit, confirm lower DB-9 is the service port |
| Update appears to succeed, version is unchanged | Wrong firmware file, partial write, bootloader mismatch | Re-download firmware from Siemens support, repeat the full procedure, confirm file checksum |
| Modem reboots during update | Loose power connection, brown-out, ESD event | Secure 24 V terminals, check supply current capability, observe ESD practices |
| Update completes but modem does not register on GSM | Antenna disconnected, SIM locked or missing, APN misconfigured | Reconnect antenna, unlock SIM, verify APN in SINAUT configuration |
Alternative Update Paths
The MD720-3 service port is the only documented path to recover a bricked modem or to perform a firmware downgrade. If the service port is physically damaged, the modem must be returned to a Siemens service center. There is no over-the-air firmware update path for the MD720-3 from the GSM network; firmware is always applied locally via the RS-232 service interface.
If the modem is in normal data mode and the connected S7 station is running a SINAUT ST7 application, firmware can be pushed from the engineering station via the SINAUT STARTTOOL or the SINAUT diagnostics. This path updates the modem's active firmware image but does not replace the bootloader; a service-port update is still required to upgrade the bootloader itself, which is the case in V1.7.7 and later revisions where the bootloader may be revised alongside the application firmware.
Field Service Recommendations
- Label and dedicate a known-good 1:1 DB-9 cable to MD720-3 service work. Generic cables drift in and out of the service kit and become the most common point of failure.
- Always run the loopback test on the PC COM port at the start of a service call. A failing port will produce the same symptom as a bad cable and waste an hour of diagnostics.
- Carry a spare DB-25-to-DB-9 metal-shell adapter. The plastic-shell adapters that ship with consumer serial cards fail within a handful of insertions.
- Document the firmware version, signal strength (
AT+CSQ), and registration state (AT+CREG?) in the service report. A baseline of these values makes future diagnostics significantly faster. - When a firmware update is part of a planned outage, schedule at least 30 minutes of bench time including bench supply, PC, and known-good cable. The actual transfer takes only a few minutes; the diagnostic overhead dominates when the first attempt fails.
FAQ
Which Siemens cable works for a SINAUT MD720-3 firmware update?
None of the standard Siemens MPI/PC adapter cables (6ES7 901-3CB30-0XA0, 6ES7 902-1AB00-0AA0, 6ES7 705-0AA00-7BA0, 6ES7 901-0BF00-0AA0) is suitable. Use a straight-through (1:1) DB-9 RS-232 cable between the PC COM port and the modem's lower service DB-9. The official procedure is documented in Siemens Support Entry 23067682.
What causes a "hardware failure" error during the MD720-3 firmware update?
The most common cause is a damaged pin in the DB-25/DB-9 adapter, followed by a crossover (null-modem) cable or the wrong COM port selected in the update tool. Verify continuity on all nine pins of the cable and adapter with a multimeter, and confirm the cable is wired 1:1, not crossed.
Can the MD720-3 firmware be updated over the GSM network?
No. The MD720-3 service port is the only documented path for a local firmware update. Over-the-air updates are not supported by the modem. If the service port is inaccessible, the modem must be returned to a Siemens service center.
How do I verify the new firmware version after the update?
Connect a terminal to the service port at 115,200 bit/s, 8N1, and send AT+CGMR. The modem replies with the firmware version string; confirm the major and minor version match the target (for example, 1.7.7).
What is the recommended RS-232 pinout between the PC and the MD720-3 service port?
Use a 1:1 (straight-through) DB-9 male-to-female cable. Pins 2 (RXD), 3 (TXD), and 5 (GND) must pass directly through. All other control lines (RTS, CTS, DTR, DSR, DCD, RI) are also passed 1:1; the modem's bootloader relies on the standard DTE-to-DCE crossover provided by the cable.
What signal strength is required for reliable SINAUT ST1/ST7 operation?
An AT+CSQ reading above 10 (out of 31) is generally required. Below 5 the link is unreliable, and the firmware update tool may also surface intermittent handshake failures at low signal levels if the modem's radio subsystem shares the supply with the serial interface.