Troubleshooting CP 343-5 WinCC FMS Communication Errors

David Krause13 min read
Industrial NetworkingSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview: '?' Status on WinCC Tags

The classic symptom of a CP 343-5 / WinCC communication failure is a question mark "?" rendered in the value field of every HMI tag that is supposed to read from a SIMATIC S7-300 PLC over PROFIBUS FMS. The "?" is not a fault of the HMI display, the S7 program, or the PLC CPU; it is WinCC's generic indicator that the channel DLL did not return a valid value because the connection to the S7 station could not be established, or the configured logical address does not match the physical hardware layout. In most field cases the CPU is reachable from STEP 7 / SIMATIC Manager and from Set PG/PC Interface online diagnostics, yet WinCC still shows "?" on every tag. This isolation is the key clue: the problem is between the WinCC channel driver and the CP 343-5, not between the CP 343-5 and the CPU.

This article addresses the configuration layer of the failure, where the most common root causes live:

  • Wrong or missing access point name in the SIMATIC NET / PG/PC interface (most frequent cause).
  • WinCC S7 Protocol Suite channel parameter mismatches the CP inserted in the SCADA PC.
  • FMS connection not defined in the S7 program (no global DB, no CR / AR relationship).
  • Profibus Logical Device Name not set to "Profibus".
  • CP 343-5 firmware mismatch with the version of SIMATIC NET installed on the PC station.

CP 343-5 Hardware Reference and Variants

The CP 343-5 is a communications processor for the S7-300 family that connects the CPU to PROFIBUS networks, supporting both DP slave / master and FMS (Fieldbus Message Specification) services. Multiple firmware revisions exist, and each is bound to a specific STEP 7 / SIMATIC NET release. Using an unsupported combination is a common source of intermittent failures or persistent "?" on WinCC tags.

MLFB (Order No.) Function Firmware STEP 7 / SIMATIC NET
6GK7 343-5FA00-0XE0 CP 343-5 (DP/FMS) V1.0 STEP 7 V5.x / Net V6.x
6GK7 343-5FA01-0XE0 CP 343-5 (DP/FMS) V2.0 STEP 7 V5.2+ / Net V6.2+
6GK7 343-5FA02-0XE0 CP 343-5 (DP/FMS) V3.0 STEP 7 V5.3+ / Net V7.0+
6GK7 343-5FX00-0XE0 CP 343-5 (FMS only, OEM) V1.x Legacy

Before any WinCC configuration, confirm that the CP 343-5 is recognized by HW Config of STEP 7 and that the FMS tab is visible in the CP properties. If the FMS tab is missing, the firmware revision of the inserted CP object does not match the real hardware, or the SIMATIC NET version installed on the PG/PC cannot read the GSD of the CP. The CP manual is published in the Siemens Industry Online Support under entry ID CP 343-5 product support.

FMS vs PROFIBUS DP: Protocol Differences

PROFIBUS DP and PROFIBUS FMS are separate protocol layers that share the same physical media (RS-485 on copper, or fiber with OLM) but expose different services to the application. WinCC supports both, but the channel configuration is fundamentally different.

Attribute PROFIBUS DP PROFIBUS FMS
Application layer EN 50170 / IEC 61158-2 DP-V0/V1 IEC 61158-2 FMS
Service model Cyclic I/O data exchange (PZD) Client/server, acyclic read/write by name
Connection setup Implicit by slot Explicit CR (Communication Reference) and AR (Application Relationship)
Data block Process image, I/O addresses Named variables inside an FMS-mapped DB (typically a global DB)
Number of connections per CP Up to 32 (master) Limited by the FMS-Engine license and CP RAM
WinCC channel name PROFIBUS DP (under SIMATIC S7 Protocol Suite) PROFIBUS FMS (older releases) / PROFIBUS with FMS option

When the question is "why is WinCC not seeing the S7 data" the first branch is to identify which service the application is using. DP is plug-and-play once the GSD is in the catalog; FMS requires an Application Relationship to be programmed on both sides of the bus. The remainder of this article targets the FMS path because that is the path that consistently produces "?" tags when one detail of the configuration is wrong.

Root Cause Analysis

Each of the following conditions will leave WinCC showing "?" on every tag while STEP 7 online functions still operate normally. The key is that STEP 7 talks to the CPU directly over the MPI / PROFIBUS interface using the S7 protocol, while WinCC talks to the CP 343-5 using the FMS channel, so the two paths can fail independently.

  1. Access point name formatting – In the Set PG/PC Interface dialog, the Access Point of the FMS application must be entered exactly as CP_L2_1: including the trailing colon. Omitting the colon causes the configuration to be silently rejected; the CP-Layer-2 service cannot bind to the access point and WinCC times out on every read.
  2. Wrong CP referenced in the channel – The WinCC S7 Protocol Suite → PROFIBUS → System Parameter must reference the same CP that is physically inserted in the SCADA PC (e.g., CP 5611, CP 5613, CP 5621). Referencing an onboard CP that does not exist produces the same "?" pattern.
  3. Logical Device Name not set to "Profibus" – The Logical Device Name for the FMS channel must be the literal string Profibus. Some installations rename it to the access point; that breaks the FMS-DLL lookup.
  4. FMS CR not defined in the S7 program – Without a Communication Reference and a corresponding Application Relationship in the FMS connection editor of the CP 343-5, the FMS engine in the CP has nothing to publish, and WinCC reads return empty data.
  5. Global DB not allocated to FMS – The variables that WinCC should display must live in a global DB that is registered as an FMS object in the CP properties. Pointing to an instance DB or to a non-FMS global DB is invalid.
  6. Firmware / SIMATIC NET version mismatch – A CP 343-5 with newer firmware and a SIMATIC NET release older than the supported matrix entry will not complete the FMS-AR handshake.

Access Point Configuration (CP_L2_1:)

The access point is the symbolic name that binds a Windows application to a specific PROFIBUS interface DLL. For FMS communication the access point must be CP_L2_1: – a name that is set by default when the SIMATIC NET PC software is installed. The trailing colon is not a typo; it is part of the registered name in the registry. Field experience has shown that the most common WinCC "?" is caused by this colon being absent. Because the access point configuration dialog does not warn about a missing colon, the operator is led to believe the configuration is correct when in fact no DLL will bind to the malformed name.

Critical: The access point name in Set PG/PC Interface must be CP_L2_1: with the colon. Without the colon the FMS layer-2 service is not bound and every WinCC read returns "?".

Verification path:

  1. Open the Windows Control Panel and launch Set PG/PC Interface (part of SIMATIC NET).
  2. Select the Access Point of the Application dropdown and choose CP_L2_1:.
  3. In the Interface Parameter Assignment Used field, choose the CP inserted in the PC, e.g. CP5611(PROFIBUS) or CP5621(PROFIBUS).
  4. Click Diagnostics → Read to confirm the bus can be reached. A successful bus scan displays the station addresses of all active PROFIBUS nodes.

WinCC S7 Protocol Suite Channel Setup

Once the access point is correct, the WinCC channel must be pointed at the same CP. The default WinCC S7 Protocol Suite creates a tree entry called PROFIBUS under Tag Management; it is this entry that must be reconfigured for FMS.

  1. Open WinCC Explorer and expand Tag Management → SIMATIC S7 PROTOCOL SUITE.
  2. Right-click the PROFIBUS entry and select System Parameter.
  3. In the Unit tab, set the Logical Device Name to the literal value Profibus. Do not rename it to the CP model number; the FMS DLL looks up the name "Profibus" by default.
  4. Switch to the Connection tab and verify that the Access Point field reads CP_L2_1: for the active PROFIBUS row.
  5. Click Properties on the connection row. Under Station Address enter the PROFIBUS address of the CP 343-5 in the S7-300 station (e.g., 3). Under Slot enter 2 for the CP 343-5. Confirm the rack matches the hardware configuration (rack 0).
  6. Click OK twice and restart the WinCC Runtime to apply the new channel parameter set.

SIMATIC NET Set PG/PC Interface Configuration

The PC station that runs WinCC must also have its PROFIBUS interface registered in the SIMATIC NET configuration console. If the CP card is recognized by Windows but is not registered with the SIMATIC NET PC station, the S7 Protocol Suite will refuse to start the channel.

  1. Open the Configuration Console (Start → SIMATIC → SIMATIC NET → Configuration Console).
  2. Select the PROFIBUS module from the tree, e.g. CP 5611 or CP 5621.
  3. Right-click and choose Properties. Set the PROFIBUS address of the PC station (typically 0 for master-capable interfaces and the highest number on the bus for slaves). Confirm the baud rate (e.g., 1.5 Mbit/s, 12 Mbit/s).
  4. Open the Station Configuration editor and ensure the CP appears in the PC station with index 1 (or the next free index if multiple modules are present).
  5. Apply and re-import the XDB or PC station configuration into the WinCC project. In WinCC Explorer, Tag Management → right-click the WinCC project node → Load Online Connections to refresh the channel definitions.

S7 Program Preparation: FMS Object and Global DB

WinCC cannot read arbitrary memory areas over FMS. Only variables that are members of an FMS-mapped global DB can be exposed to the FMS channel. The S7 program must therefore contain the following three artefacts:

  1. A global DB (e.g., DB 100) with all WinCC-relevant variables declared as named UDT instances or named elementary types.
  2. The CP 343-5 FMS connection configuration in HW Config: right-click the CP → Properties → FMS tab → add a new FMS connection, assign a unique Connection Name, and add the global DB as a Domain (read) or Variable Collection.
  3. An Application Relationship (AR) in the FMS connection editor with the SCADA PC station referenced by its PROFIBUS address and the CP's CR (Communication Reference) identifier.

The official Siemens entry that walks through the FMS channel configuration between an S7 station and WinCC is published in Industry Online Support under entry ID 14761448 – "How do you configure the PROFIBUS FMS channel between a SIMATIC S7 station and WinCC?". The procedure there is the reference for the FMS connection definition in the S7 program.

Verification and Status Checks

After applying the configuration changes, verify the link end-to-end before going into Runtime. Three independent verifications are recommended; all three should pass before any tag is considered healthy.

Step Tool Pass Criterion
1. Bus scan Set PG/PC Interface → Diagnostics → Read All PROFIBUS nodes visible, CP 343-5 appears at expected address
2. FMS-AR handshake CP 343-5 online diagnostics in STEP 7 Connection State = Established, FMS-CR active
3. WinCC driver status WinCC Explorer → Tools → Status of Driver Connections PROFIBUS row shows "OK" or "Connected" for the active connection

If the bus scan and the FMS-AR handshake both pass but the WinCC driver status still reports Disconnected, return to the access point verification: the most common remaining cause is the missing colon on CP_L2_1:.

Common Configuration Errors and Fixes

Symptom Likely Cause Fix
All tags "?"; CPU reachable from STEP 7 Access point CP_L2_1 without colon Add the colon, rebind access point, restart WinCC
Tags "?" after CP swap (e.g. CP 5611 → CP 5621) Channel System Parameter still references old CP Open PROFIBUS System Parameter, select new CP, restart Runtime
Tags "?" only for some variables Variables not in the FMS-mapped global DB Move the variable into the FMS-registered DB, recompile and download
Tags "?" after STEP 7 upgrade FMS GSD / object catalog regeneration required Re-import the FMS connection in HW Config and download the CP 343-5
Tags "?" on secondary SCADA PC only PC station FMS license missing Install FMS license on the second PC; FMS is a separately licensed option of SIMATIC NET
Tags "?" after CP firmware update SIMATIC NET version not on compatibility matrix Update SIMATIC NET to a release that supports the new CP firmware

Best Practices and Field Notes

  • Treat the access point name as case- and punctuation-sensitive. Document the exact spelling in the project quality plan. CP_L2_1: and CP_L2_1 are not the same string to the FMS layer.
  • Keep the S7 FMS connection object catalog under source control. When the CP 343-5 firmware is upgraded, the catalog must be regenerated, otherwise the GSD version seen by the SCADA PC will drift from the one in the CP.
  • Reserve PROFIBUS address 0 for the SCADA PC master, and assign the CP 343-5 of the S7 station a unique high address (e.g., 3) to keep bus scan output unambiguous.
  • Disable any second SIMATIC NET configuration tool running on the SCADA PC (e.g., an old PC Station from a previous project). Two active stations on the same CP will fight for the bus and WinCC tags will oscillate between "?" and valid values.
  • Plan an orderly migration path: CP 343-5 is a legacy product and FMS is being superseded by PROFINET and S7 communication over Industrial Ethernet. If greenfield work is in scope, prefer CP 343-1 Lean / CP 343-1 Advanced modules and the S7 Protocol Suite TCP/IP channel rather than FMS. For existing FMS installations, capture the configuration described above as a baseline and pin the SIMATIC NET version to avoid silent regressions.
  • When commissioning, always use Set PG/PC Interface → Diagnostics → Test to read the bus statistics (repeat count, bus errors). A high repeat count is the first sign of a cabling or termination problem that will show up in WinCC as occasional "?" values before the link drops entirely.
Safety note: PROFIBUS FMS is a process communication service. Do not apply configuration changes to a live plant while the SCADA is supervising safety-critical interlocks. Take the affected WinCC screens out of service, apply the change, validate the link with the verification procedure above, and put the screens back into service only after the driver status reads OK.

What does the "?" symbol on a WinCC tag mean for a CP 343-5 link?

The "?" means the WinCC channel could not read a value at the last poll cycle. The most common cause when STEP 7 online is still working is that the access point in the SIMATIC NET Set PG/PC Interface is not bound to the same CP, or the access point name is missing the trailing colon. Verify that the access point is CP_L2_1: and that the WinCC S7 Protocol Suite → PROFIBUS System Parameter points at the CP that is physically installed in the SCADA PC.

Why does my CP 343-5 show the FMS tab missing in HW Config?

The FMS tab appears only when the CP object in HW Config matches a firmware revision that supports FMS and the SIMATIC NET version installed on the PG/PC is on the compatibility matrix. Confirm the MLFB (6GK7 343-5FA0x-0XE0), the firmware in Module Information, and that the installed STEP 7 / SIMATIC NET release includes the FMS option. Update the CP object in HW Config to the latest firmware and redownload the station.

Can WinCC use DP and FMS over the same CP 343-5 at the same time?

Yes, the CP 343-5 supports simultaneous DP and FMS operation when the firmware is V2.0 or higher and the CP is configured as a DP master. Define the DP slaves under the DP tab and the FMS connections under the FMS tab of the CP properties. WinCC can then read DP process data over the DP channel and named variables from the FMS-mapped global DB over the FMS channel.

How do I confirm the FMS Application Relationship is established?

Open the S7 project in STEP 7, go online with the S7-300 station, and open the Module Information for the CP 343-5. Under the FMS diagnostics, the active ARs are listed with their partner PROFIBUS address. If the SCADA PC is not listed, the AR is not programmed on the CP side; right-click the FMS connection in HW Config, add the partner by PROFIBUS address, save, compile, and download the CP configuration.

Is there a successor to CP 343-5 / PROFIBUS FMS I should plan for?

Yes. PROFIBUS FMS has been deprecated for new projects; Siemens recommends PROFINET IO with CP 343-1 Lean (6GK7 343-1CX10-0XE0) or CP 343-1 Advanced (6GK7 343-1GX30-0XE0) and the WinCC S7 Protocol Suite over Industrial Ethernet. Existing FMS installations can be kept running with the configuration described above, but new work should use the S7 / PROFINET path to avoid the licensing and compatibility constraints of FMS.

Back to blog