Troubleshooting CPU 313C-2 DP MPI/PROFIBUS Port Failure

David Krause11 min read
S7-300SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Overview

A field-recovered Siemens SIMATIC S7-300 CPU 313C-2 DP (MLFB 6ES7313-6CE00-0AB0) returns the error "The connection partner is not responding" when targeted over both integrated interfaces. STEP 7 V5.3 (Windows NT) on a PG with a CP5611 PCI card, and STEP 7 V5.5 (Windows XP) on a laptop with a CP5711 USB adapter, both fail to attach. The same PG/laptop pair successfully communicates with other S7-300 / S7-400 CPUs, which isolates the fault to the target CPU hardware rather than the programming device.

The PG/PC interface self-test passes, which confirms the bus physics layer of the CP5611/CP5711 is functional. Both the MPI port and the PROFIBUS DP port on the CPU fail to enumerate as live nodes. Physical inspection after opening the housing reveals localized burn damage on the PCB immediately behind the combined MPI/DP Sub-D connector. This pattern is consistent with a sustained over-voltage or reverse-polarity event on the bus connector (typical causes: 24 V DC injected onto the PROFIBUS cable shield or pins, hot-plug of a charged cable, or lightning-induced surge on a field-run PROFIBUS segment).

Safety: Before any further diagnostic, de-energize the S7-300 rack, lock out the 24 V DC supply, and verify zero energy with a calibrated meter. Burned PCB areas may retain charge in filter capacitors; allow 60 s discharge time before contact.

2. Affected Hardware Identification

The MLFB 6ES7313-6CE00-0AB0 decodes as follows:

MLFB Segment Meaning
6ES7 SIMATIC S7 family
313 CPU class 313 (mid-range S7-300)
C Compact CPU with integrated I/O
2 Second interface present
DP PROFIBUS-DP master/slave on second port
6 Integrated 16 DI / 16 DO + 4 AI / 2 AO
CE00 Internal ordering code (compact, German/English documentation set)
0AB0 Original release, no firmware suffix

Key specifications of the failed unit:

Parameter Value
Work memory (integrated) 32 KB
Load memory Via MMC (not present at fault time)
Bit instruction time 0.1 µs
Integrated digital I/O 16 DI / 16 DO (24 V DC)
Integrated analog I/O 4 AI (0–10 V, ±10 V, 0/4–20 mA) / 2 AO
Integrated counters 3 channels (up to 30 kHz)
Integrated PWM/frequency outputs 2 channels
Port 1 (X1) MPI, 187.5 kbit/s default
Port 2 (X2) PROFIBUS-DP master/slave, up to 12 Mbit/s
Supply voltage 24 V DC (via backplane)
Operating temperature 0 °C to +60 °C horizontal mounting

Both X1 (MPI) and X2 (PROFIBUS-DP) are physically combined on a single 9-pin Sub-D female connector block on the bottom edge of the CPU front panel. Burn damage localized to the PCB copper immediately behind this connector typically destroys the RS-485 transceiver (Siemens part designation often marked as a small 8- or 14-pin SOIC near the connector) and supporting ESD/termination components.

3. Initial Diagnostic Procedure

  1. Verify the PG/PC interface assignment. Open SIMATIC Manager > Options > Set PG/PC Interface. Confirm the active access point is S7ONLINE pointing to CP5611(MPI) or CP5711(MPI). The interface diagnostic button must report "OK" — if it does, the CP hardware and driver stack are sound.
  2. Test against a known-good CPU. Connect the same cable to any other S7-300 on the bench. A successful online view proves the cable, CP, and STEP 7 installation are not contributing to the fault.
  3. Try both ports independently. The X1/MPI and X2/DP interfaces share the physical connector but are addressed through separate PG/PC interface assignments (CP5611(MPI) vs. CP5611(PROFIBUS)). If only one side responds and the other is silent, the fault is localized to that interface's transceiver channel.
  4. Perform MRES. Cycle the mode selector to MRES and hold for >3 s. The CPU should perform a full reset. If even the SF (system fault) LED refuses to cycle through its reset pattern, the base firmware is not executing.
  5. Check LED state. A healthy CPU with no project shows: SF off, BF (bus fault) flashing briefly then off, DC5V on, RUN off, STOP on solid. A continuously lit BF1 or BF2 LED indicates the corresponding interface cannot synchronize to the bus — a strong indicator of transceiver damage.

4. Bus Node Scan Procedure

With the CPU powered and the CP assigned, run SIMATIC Manager > PLC > Edit Ethernet Node / PROFIBUS Node (or the legacy PG/PC Interface Diagnostics with bus node scan). Expected outcome on a damaged port: zero nodes appear despite the CPU being physically connected.

Scan limits to set before test:

  • MPI: address range 0–31, baud 187.5 kbit/s
  • PROFIBUS: address range 0–126, baud 9.6 kbit/s up to 12 Mbit/s (start at lowest baud and step up; damaged transceivers sometimes respond at low baud but fail at high baud)
  • Maximum repeaters: 0

If the scan reports "no active nodes found" on a known good cable and a known good CP, the fault lies downstream of the CP.

5. Port Isolation Methodology

Because X1 (MPI) and X2 (DP) share a connector block but use separate transceiver channels, isolating them is straightforward with a custom test harness. Cut a PROFIBUS cable at the CPU end and bring only the X2 pin subset to the CP at low baud. The pinout of the 9-pin Sub-D is:

Pin MPI (X1) PROFIBUS-DP (X2) Wire color (typical)
1 NC NC
2 NC NC
3 Data line B (RxD/TxD-P) Data line B (RxD/TxD-P) Red
4 RTS RTS
5 DGND (5 V reference) DGND (5 V reference) Black
6 +5 V (terminator power, ≤90 mA) +5 V (terminator power) Green
7 NC NC
8 Data line A (RxD/TxD-N) Data line A (RxD/TxD-N) Yellow
9 NC NC
Shield Cable shield (bonded to connector housing) Cable shield Bare

Measuring between pins 3 and 8 with a multimeter on a powered CPU should show roughly 1 V DC of differential bias on a functional transceiver; an open circuit (>5 MΩ) indicates destroyed line-side components. Measuring 0 V with the supply on is also consistent with a shorted transceiver.

6. PCB Visual Inspection Indicators

Once the housing is opened, document the following on the PCB immediately around the MPI/DP Sub-D connector:

  • Discoloration on the FR4 substrate — brown or black scorching localized to the area behind the connector pins
  • Lifted pads on the transceiver IC footprint (8- or 14-pin SOIC, often labeled Siemens-internal part numbers such as 6SE7090 or similar)
  • Carbon tracking between adjacent traces — appears as fine black lines that may continue to conduct after the burnout, creating leakage paths
  • Cracked SMD resistors in the bus termination / bias network (typically 390 Ω, 220 Ω, 1 kΩ combinations)
  • Bulged tantalum or electrolytic capacitors on the 5 V rail near the connector

If any of these are present, the CPU has sustained a destructive electrical overstress. There is no firmware or parameter recovery path.

Component-level repairability: Siemens does not publish schematics for the CPU 313C-2 DP mainboard. Repair at the component level is therefore impractical without the proprietary circuit diagram, which is not available even to most third-party repair shops.

7. Repair vs. Replacement Decision Matrix

Option Indicative cost (EUR) Lead time Outcome
Siemens factory repair / exchange €450–€900 (flat-rate repair or exchange) 2–6 weeks Tested unit with 12-month warranty; functional replacement may be a later -0AB0 variant
Authorized Siemens partner local repair €300–€600 1–3 weeks Component-level repair; warranty varies by partner (typically 6 months)
New CPU 313C-2 DP (current MLFB 6ES7313-6CF03-0AB0) €1,200–€1,800 list Stock / 2–4 weeks Newest firmware, form-fit-function compatible, full warranty
Refurbished broker stock (6ES7313-6CE00-0AB0 or -0AD0) €250–€500 1–7 days Cost-effective; verify testing report and return policy
Retire the unit (salvage MMC, front connector, label set) €0 (parts only) Immediate Documented decommission

Repair becomes economically attractive when the CPU holds a unique program whose source is lost, when the firmware version is mandated by the system integrator, or when the rack has no spare slot for a different CPU class.

8. Siemens RMA / Repair Process

  1. Locate the regional Siemens representative through the official Siemens contact directory.
  2. Request an SRS — Service Request System number, or open a ticket via the Siemens Industry Online Support portal.
  3. Provide the MLFB, serial number, firmware version (read from the side label), and a fault description. Attach photos of the PCB burn damage to accelerate triage.
  4. Receive a flat-rate repair quote or an exchange offer. Exchange units are typically tested replacements that may carry a later firmware release; this is acceptable as long as the project contains no version-locked blocks.
  5. Ship the unit in ESD-safe packaging with the SRS number written on the shipping label.
  6. Receive a tested return unit or exchange with a test certificate.
Siemens warranty on repair or exchange is typically 12 months from the date of return shipment. Confirm in writing before issuing the purchase order.

9. Replacement CPU Cross-Reference

The 313C-2 DP family has been re-released several times; the following MLFBs are form-fit-function compatible and can replace 6ES7313-6CE00-0AB0 without modifying the STEP 7 hardware configuration beyond updating the MLFB in HW Config:

MLFB Release Firmware Notes
6ES7313-6CE00-0AB0 Original V2.0 Failed unit in this case
6ES7313-6CE00-0AD0 Revision V2.6 Same PCB, revised components
6ES7313-6CF03-0AB0 Current V3.3 RoHS-compliant, latest variant
6ES7313-6CG04-0AB0 Conformal-coated V3.3 For harsh environments

STEP 7 V5.5 SP4 or later is required to configure the V3.3 firmware. STEP 7 V5.3 will not see a V3.3 CPU as an online target; it can still host the project offline and download through a CP5711 once the firmware is set in HW Config.

10. Serial-to-USB Workaround (Limited Scope)

If only the MPI port is damaged and the DP port is functional, the program can be offloaded via PROFIBUS at low baud using a CP5711 in DP-master mode. If both ports are damaged, an external RS-485 to USB converter wired to the connector's pin 3/8 pair may still recover the CPU if the transceiver IC is blown but the secondary protection network is intact — this is a low-probability outcome because the burn damage typically propagates beyond the primary transceiver.

The procedure, attempted only as a last resort before RMA:

  1. Power down the rack.
  2. Wire an FTDI USB-to-RS485 adapter (e.g., FTDI USB-485) to pins 3, 5, 8 of the CPU's combined MPI/DP connector.
  3. Set the FTDI driver to 187.5 kbit/s, even parity, no flow control.
  4. Open a terminal session to the COM port and attempt to capture the MPI token-passing telegrams during boot.
  5. If no telegrams appear within 30 s, declare both ports failed and proceed to RMA.
Standard USB-to-MPI cables (PC-Adapter USB A2, 6ES7972-0CB20-0XA0) will not help here because they present themselves as a Siemens MPI device at the bus protocol level — if the CPU's MPI transceiver is dead, the adapter cannot complete token handshaking regardless of cable integrity.

11. Preventive Measures for Working Racks

  • Install PROFIBUS surge protectors (e.g., Siemens 6ES7972-0DA00-0AA0 or Phoenix Contact PLUGTRAB) at every cable transition between buildings or between buildings and field cabling.
  • Bond shield drain wires to a clean ground bar at every cabinet entry — never use shield as a current-carrying conductor.
  • Power down the rack before inserting or removing the MPI/DP connector. Hot-plug is not supported and is the most common cause of transceiver destruction.
  • Verify 24 V DC polarity and absence of AC ripple on the backplane supply before commissioning; reverse polarity during a hot swap is the second most common cause.
  • Document the MPI/DP connector type on every machine schematic so a replacement CPU with the same connector pinout can be swapped without rewiring.

12. Verification Checklist After Repair or Replacement

  1. Re-seat the CPU on the rack and apply 24 V DC.
  2. Confirm the LED pattern: SF off, DC5V on, STOP solid.
  3. Insert the project MMC (or download the project through MPI/DP).
  4. Switch to RUN; verify the RUN LED is solid and the SF/BF LEDs remain off.
  5. From STEP 7, run PLC > Monitor/Modify on a known tag to confirm bidirectional communication.
  6. Force the bus node scan; the CPU must appear at its configured MPI/DP address.
  7. Log the new CPU's serial number and firmware version for the asset register.

FAQ

Can a CPU 313C-2 DP with both MPI and PROFIBUS ports damaged be repaired in-house?

No — Siemens does not publish board schematics for the CPU 313C-2 DP mainboard, and the burned area typically destroys proprietary transceiver ICs that are not stocked as service parts. Repair must be done by Siemens factory service or an authorized partner with controlled documentation access.

What STEP 7 version is needed to go online with a replacement CPU 313C-2 DP?

For the current -0AB0 release (firmware V3.3), use STEP 7 V5.5 SP4 or later. Older V5.3 and V5.4 SP3 will not see a V3.3 CPU as an online target. The hardware configuration can be edited offline in any V5.x version and then downloaded through a CP5711 once the project is opened on a supported version.

Will a USB-to-MPI PC adapter recover a CPU with a dead MPI transceiver?

No. The PC Adapter (6ES7972-0CB20-0XA0) implements the Siemens MPI protocol at the bus level. If the CPU's RS-485 transceiver is destroyed, no adapter can complete token handshaking. The only communications that remain possible are through the unaffected DP port, if any.

How can both MPI and PROFIBUS ports fail simultaneously on one CPU?

The two interfaces share a single 9-pin Sub-D connector on the CPU 313C-2 DP front panel. A voltage surge or reverse polarity injected into that connector propagates through the shared ground and bias network, destroying both transceivers in the same event. This is a documented failure pattern on S7-300 CPUs without surge protection on the bus cable entry.

Is a CPU 313C-2 DP still orderable from Siemens in 2025/2026?

The current MLFB is 6ES7313-6CF03-0AB0 (firmware V3.3, RoHS-compliant) and is in active distribution. The original 6ES7313-6CE00-0AB0 is in the "classic" lifecycle phase and available only while stocks last. Always confirm availability through the Siemens Industry Mall or your regional representative before issuing a purchase order.

Back to blog