1. Problem Overview
A field-recovered Siemens SIMATIC S7-300 CPU 313C-2 DP (MLFB 6ES7313-6CE00-0AB0) returns the error "The connection partner is not responding" when targeted over both integrated interfaces. STEP 7 V5.3 (Windows NT) on a PG with a CP5611 PCI card, and STEP 7 V5.5 (Windows XP) on a laptop with a CP5711 USB adapter, both fail to attach. The same PG/laptop pair successfully communicates with other S7-300 / S7-400 CPUs, which isolates the fault to the target CPU hardware rather than the programming device.
The PG/PC interface self-test passes, which confirms the bus physics layer of the CP5611/CP5711 is functional. Both the MPI port and the PROFIBUS DP port on the CPU fail to enumerate as live nodes. Physical inspection after opening the housing reveals localized burn damage on the PCB immediately behind the combined MPI/DP Sub-D connector. This pattern is consistent with a sustained over-voltage or reverse-polarity event on the bus connector (typical causes: 24 V DC injected onto the PROFIBUS cable shield or pins, hot-plug of a charged cable, or lightning-induced surge on a field-run PROFIBUS segment).
2. Affected Hardware Identification
The MLFB 6ES7313-6CE00-0AB0 decodes as follows:
| MLFB Segment | Meaning |
|---|---|
| 6ES7 | SIMATIC S7 family |
| 313 | CPU class 313 (mid-range S7-300) |
| C | Compact CPU with integrated I/O |
| 2 | Second interface present |
| DP | PROFIBUS-DP master/slave on second port |
| 6 | Integrated 16 DI / 16 DO + 4 AI / 2 AO |
| CE00 | Internal ordering code (compact, German/English documentation set) |
| 0AB0 | Original release, no firmware suffix |
Key specifications of the failed unit:
| Parameter | Value |
|---|---|
| Work memory (integrated) | 32 KB |
| Load memory | Via MMC (not present at fault time) |
| Bit instruction time | 0.1 µs |
| Integrated digital I/O | 16 DI / 16 DO (24 V DC) |
| Integrated analog I/O | 4 AI (0–10 V, ±10 V, 0/4–20 mA) / 2 AO |
| Integrated counters | 3 channels (up to 30 kHz) |
| Integrated PWM/frequency outputs | 2 channels |
| Port 1 (X1) | MPI, 187.5 kbit/s default |
| Port 2 (X2) | PROFIBUS-DP master/slave, up to 12 Mbit/s |
| Supply voltage | 24 V DC (via backplane) |
| Operating temperature | 0 °C to +60 °C horizontal mounting |
Both X1 (MPI) and X2 (PROFIBUS-DP) are physically combined on a single 9-pin Sub-D female connector block on the bottom edge of the CPU front panel. Burn damage localized to the PCB copper immediately behind this connector typically destroys the RS-485 transceiver (Siemens part designation often marked as a small 8- or 14-pin SOIC near the connector) and supporting ESD/termination components.
3. Initial Diagnostic Procedure
-
Verify the PG/PC interface assignment. Open SIMATIC Manager > Options > Set PG/PC Interface. Confirm the active access point is
S7ONLINEpointing toCP5611(MPI)orCP5711(MPI). The interface diagnostic button must report "OK" — if it does, the CP hardware and driver stack are sound. - Test against a known-good CPU. Connect the same cable to any other S7-300 on the bench. A successful online view proves the cable, CP, and STEP 7 installation are not contributing to the fault.
-
Try both ports independently. The X1/MPI and X2/DP interfaces share the physical connector but are addressed through separate PG/PC interface assignments (
CP5611(MPI)vs.CP5611(PROFIBUS)). If only one side responds and the other is silent, the fault is localized to that interface's transceiver channel. - Perform MRES. Cycle the mode selector to MRES and hold for >3 s. The CPU should perform a full reset. If even the SF (system fault) LED refuses to cycle through its reset pattern, the base firmware is not executing.
- Check LED state. A healthy CPU with no project shows: SF off, BF (bus fault) flashing briefly then off, DC5V on, RUN off, STOP on solid. A continuously lit BF1 or BF2 LED indicates the corresponding interface cannot synchronize to the bus — a strong indicator of transceiver damage.
4. Bus Node Scan Procedure
With the CPU powered and the CP assigned, run SIMATIC Manager > PLC > Edit Ethernet Node / PROFIBUS Node (or the legacy PG/PC Interface Diagnostics with bus node scan). Expected outcome on a damaged port: zero nodes appear despite the CPU being physically connected.
Scan limits to set before test:
- MPI: address range 0–31, baud 187.5 kbit/s
- PROFIBUS: address range 0–126, baud 9.6 kbit/s up to 12 Mbit/s (start at lowest baud and step up; damaged transceivers sometimes respond at low baud but fail at high baud)
- Maximum repeaters: 0
If the scan reports "no active nodes found" on a known good cable and a known good CP, the fault lies downstream of the CP.
5. Port Isolation Methodology
Because X1 (MPI) and X2 (DP) share a connector block but use separate transceiver channels, isolating them is straightforward with a custom test harness. Cut a PROFIBUS cable at the CPU end and bring only the X2 pin subset to the CP at low baud. The pinout of the 9-pin Sub-D is:
| Pin | MPI (X1) | PROFIBUS-DP (X2) | Wire color (typical) |
|---|---|---|---|
| 1 | NC | NC | — |
| 2 | NC | NC | — |
| 3 | Data line B (RxD/TxD-P) | Data line B (RxD/TxD-P) | Red |
| 4 | RTS | RTS | — |
| 5 | DGND (5 V reference) | DGND (5 V reference) | Black |
| 6 | +5 V (terminator power, ≤90 mA) | +5 V (terminator power) | Green |
| 7 | NC | NC | — |
| 8 | Data line A (RxD/TxD-N) | Data line A (RxD/TxD-N) | Yellow |
| 9 | NC | NC | — |
| Shield | Cable shield (bonded to connector housing) | Cable shield | Bare |
Measuring between pins 3 and 8 with a multimeter on a powered CPU should show roughly 1 V DC of differential bias on a functional transceiver; an open circuit (>5 MΩ) indicates destroyed line-side components. Measuring 0 V with the supply on is also consistent with a shorted transceiver.
6. PCB Visual Inspection Indicators
Once the housing is opened, document the following on the PCB immediately around the MPI/DP Sub-D connector:
- Discoloration on the FR4 substrate — brown or black scorching localized to the area behind the connector pins
- Lifted pads on the transceiver IC footprint (8- or 14-pin SOIC, often labeled Siemens-internal part numbers such as 6SE7090 or similar)
- Carbon tracking between adjacent traces — appears as fine black lines that may continue to conduct after the burnout, creating leakage paths
- Cracked SMD resistors in the bus termination / bias network (typically 390 Ω, 220 Ω, 1 kΩ combinations)
- Bulged tantalum or electrolytic capacitors on the 5 V rail near the connector
If any of these are present, the CPU has sustained a destructive electrical overstress. There is no firmware or parameter recovery path.
7. Repair vs. Replacement Decision Matrix
| Option | Indicative cost (EUR) | Lead time | Outcome |
|---|---|---|---|
| Siemens factory repair / exchange | €450–€900 (flat-rate repair or exchange) | 2–6 weeks | Tested unit with 12-month warranty; functional replacement may be a later -0AB0 variant |
| Authorized Siemens partner local repair | €300–€600 | 1–3 weeks | Component-level repair; warranty varies by partner (typically 6 months) |
| New CPU 313C-2 DP (current MLFB 6ES7313-6CF03-0AB0) | €1,200–€1,800 list | Stock / 2–4 weeks | Newest firmware, form-fit-function compatible, full warranty |
| Refurbished broker stock (6ES7313-6CE00-0AB0 or -0AD0) | €250–€500 | 1–7 days | Cost-effective; verify testing report and return policy |
| Retire the unit (salvage MMC, front connector, label set) | €0 (parts only) | Immediate | Documented decommission |
Repair becomes economically attractive when the CPU holds a unique program whose source is lost, when the firmware version is mandated by the system integrator, or when the rack has no spare slot for a different CPU class.
8. Siemens RMA / Repair Process
- Locate the regional Siemens representative through the official Siemens contact directory.
- Request an SRS — Service Request System number, or open a ticket via the Siemens Industry Online Support portal.
- Provide the MLFB, serial number, firmware version (read from the side label), and a fault description. Attach photos of the PCB burn damage to accelerate triage.
- Receive a flat-rate repair quote or an exchange offer. Exchange units are typically tested replacements that may carry a later firmware release; this is acceptable as long as the project contains no version-locked blocks.
- Ship the unit in ESD-safe packaging with the SRS number written on the shipping label.
- Receive a tested return unit or exchange with a test certificate.
9. Replacement CPU Cross-Reference
The 313C-2 DP family has been re-released several times; the following MLFBs are form-fit-function compatible and can replace 6ES7313-6CE00-0AB0 without modifying the STEP 7 hardware configuration beyond updating the MLFB in HW Config:
| MLFB | Release | Firmware | Notes |
|---|---|---|---|
| 6ES7313-6CE00-0AB0 | Original | V2.0 | Failed unit in this case |
| 6ES7313-6CE00-0AD0 | Revision | V2.6 | Same PCB, revised components |
| 6ES7313-6CF03-0AB0 | Current | V3.3 | RoHS-compliant, latest variant |
| 6ES7313-6CG04-0AB0 | Conformal-coated | V3.3 | For harsh environments |
STEP 7 V5.5 SP4 or later is required to configure the V3.3 firmware. STEP 7 V5.3 will not see a V3.3 CPU as an online target; it can still host the project offline and download through a CP5711 once the firmware is set in HW Config.
10. Serial-to-USB Workaround (Limited Scope)
If only the MPI port is damaged and the DP port is functional, the program can be offloaded via PROFIBUS at low baud using a CP5711 in DP-master mode. If both ports are damaged, an external RS-485 to USB converter wired to the connector's pin 3/8 pair may still recover the CPU if the transceiver IC is blown but the secondary protection network is intact — this is a low-probability outcome because the burn damage typically propagates beyond the primary transceiver.
The procedure, attempted only as a last resort before RMA:
- Power down the rack.
- Wire an FTDI USB-to-RS485 adapter (e.g., FTDI USB-485) to pins 3, 5, 8 of the CPU's combined MPI/DP connector.
- Set the FTDI driver to 187.5 kbit/s, even parity, no flow control.
- Open a terminal session to the COM port and attempt to capture the MPI token-passing telegrams during boot.
- If no telegrams appear within 30 s, declare both ports failed and proceed to RMA.
11. Preventive Measures for Working Racks
- Install PROFIBUS surge protectors (e.g., Siemens 6ES7972-0DA00-0AA0 or Phoenix Contact PLUGTRAB) at every cable transition between buildings or between buildings and field cabling.
- Bond shield drain wires to a clean ground bar at every cabinet entry — never use shield as a current-carrying conductor.
- Power down the rack before inserting or removing the MPI/DP connector. Hot-plug is not supported and is the most common cause of transceiver destruction.
- Verify 24 V DC polarity and absence of AC ripple on the backplane supply before commissioning; reverse polarity during a hot swap is the second most common cause.
- Document the MPI/DP connector type on every machine schematic so a replacement CPU with the same connector pinout can be swapped without rewiring.
12. Verification Checklist After Repair or Replacement
- Re-seat the CPU on the rack and apply 24 V DC.
- Confirm the LED pattern: SF off, DC5V on, STOP solid.
- Insert the project MMC (or download the project through MPI/DP).
- Switch to RUN; verify the RUN LED is solid and the SF/BF LEDs remain off.
- From STEP 7, run PLC > Monitor/Modify on a known tag to confirm bidirectional communication.
- Force the bus node scan; the CPU must appear at its configured MPI/DP address.
- Log the new CPU's serial number and firmware version for the asset register.
FAQ
Can a CPU 313C-2 DP with both MPI and PROFIBUS ports damaged be repaired in-house?
No — Siemens does not publish board schematics for the CPU 313C-2 DP mainboard, and the burned area typically destroys proprietary transceiver ICs that are not stocked as service parts. Repair must be done by Siemens factory service or an authorized partner with controlled documentation access.
What STEP 7 version is needed to go online with a replacement CPU 313C-2 DP?
For the current -0AB0 release (firmware V3.3), use STEP 7 V5.5 SP4 or later. Older V5.3 and V5.4 SP3 will not see a V3.3 CPU as an online target. The hardware configuration can be edited offline in any V5.x version and then downloaded through a CP5711 once the project is opened on a supported version.
Will a USB-to-MPI PC adapter recover a CPU with a dead MPI transceiver?
No. The PC Adapter (6ES7972-0CB20-0XA0) implements the Siemens MPI protocol at the bus level. If the CPU's RS-485 transceiver is destroyed, no adapter can complete token handshaking. The only communications that remain possible are through the unaffected DP port, if any.
How can both MPI and PROFIBUS ports fail simultaneously on one CPU?
The two interfaces share a single 9-pin Sub-D connector on the CPU 313C-2 DP front panel. A voltage surge or reverse polarity injected into that connector propagates through the shared ground and bias network, destroying both transceivers in the same event. This is a documented failure pattern on S7-300 CPUs without surge protection on the bus cable entry.
Is a CPU 313C-2 DP still orderable from Siemens in 2025/2026?
The current MLFB is 6ES7313-6CF03-0AB0 (firmware V3.3, RoHS-compliant) and is in active distribution. The original 6ES7313-6CE00-0AB0 is in the "classic" lifecycle phase and available only while stocks last. Always confirm availability through the Siemens Industry Mall or your regional representative before issuing a purchase order.