Troubleshooting SCALANCE W788 and W744 PROFINET Wireless Failures

David Krause12 min read
Industrial NetworkingSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Details: SCALANCE W788/W744 PROFINET IO Failure

After commissioning a SCALANCE W788 (access point) and SCALANCE W744 (client) pair on a 2.4 GHz radio link carrying a single ET200S distributed I/O station, the Web Based Management (WBM) shows that the wireless link is established (signal LEDs active, association table populated) but PROFINET IO cyclic data exchange with the ET200S never comes up. The PLC reports the IO device as "not accessible" or "station failure", and the diagnostic buffer of the IO controller logs AR (Application Relationship) aborts even though the W788/W744 radio layer appears healthy.

This is one of the most common SCALANCE W7xx commissioning faults: the radio side looks fine, but the layer-2 PROFINET frame forwarding is silently broken because of a missing or uncommitted client-side parameter, a country regulation mismatch, or a PN IO update time that is too aggressive for the wireless medium.

Affected Products and Firmware Branches

Component Order Number (example) Role Recommended Firmware
SCALANCE W788-1 RR 6GK5788-1AA60-2AA0 Access Point V6.5.x or newer (IWLAN family)
SCALANCE W788-2 RR 6GK5788-2AA60-2AA0 Access Point, dual radio V6.5.x or newer
SCALANCE W744-1 6GK5744-1AA60-2AA0 Client module V6.5.x or newer
SCALANCE W744-1 RR 6GK5744-1AA60-4AA0 Client, robust rail V6.5.x or newer
ET200S (IM151-3 PN) 6ES7151-3BA23-0AB0 PROFINET IO device Matching STEP 7 HW catalog

Firmware downloads and release notes are available from the Siemens Industry Online Support (SIOS) portal under product tree "Industrial Communication / IWLAN / SCALANCE W". Always read the release notes for known PROFINET issues before assuming a hardware fault.

Reference Architecture: AP – Switch – Client – IO Device

The validated reference topology for this failure mode is:

  1. PROFINET IO controller (e.g. S7-1500) on the plant network.
  2. SCALANCE W788 Access Point connected via SCALANCE X switch (X208, XC208, XC216, etc.).
  3. Radio link on 2.4 GHz or 5 GHz between W788 and W744.
  4. SCALANCE W744 Client connected downstream of the AP via PROFINET.
  5. One (and only one) PROFINET IO device — typically an ET200S IM151-3 PN — connected to the W744 client port.
Hard limit: A SCALANCE W744 client port supports exactly one downstream PROFINET IO device in standard IWLAN deployments. Multiple IO devices behind a single client require a SCALANCE W748 client with bridging/routing features and PROFINET-aware switch behaviour, or an IWLAN/PB link instead. Treat "1 client = 1 IO device" as a commissioning rule until firmware-specific exceptions are verified.

Root Cause Analysis: Why the Radio Is Up but PN IO Is Down

There are five independent root causes that produce this exact symptom. Each must be verified in turn before changing hardware or swapping antennas.

1. MAC Mode Not Set to "Adopt MAC Manually"

The W744 client must spoof the MAC address of the downstream ET200S so that the PROFINET AR is terminated at the IO device, not at the W744 itself. The relevant WBM page is Layer 2 >> MAC Mode or the Basic Wizard. The valid selections are:

  • Automatic — W744 uses a random MAC. PROFINET ARs will fail because the controller cannot address the IO device.
  • Adopt MAC Manually — operator enters the MAC of the ET200S (printed on the IM151-3 PN front module, format 00-0A-... or similar). This is the required mode for PROFINET IO behind a client.
  • Adopt MAC Automatically — W744 learns the MAC of the first device seen on its LAN port. Acceptable for commissioning but not for production because the learned MAC is volatile across reboots on older firmware.

If the WBM shows MAC 00-00-00-00-00-00 in the client configuration, the manual MAC has never been written or — more commonly — the device has not been rebooted to activate the change.

2. Configuration Change Committed Without Software Reboot

SCALANCE W7xx devices do not apply all parameter changes live. MAC mode, country, channel, SSID, security mode, and PROFINET-related settings require a Save & Load operation plus a software reboot. A "disconnect and reconnect" of the Web session is not enough. Symptoms of an uncommitted change:

  • WBM shows the new value (e.g. ET200S MAC entered) but the device continues to operate with the previous (default 00-00-00-00-00-00) MAC.
  • After reboot the value reverts to default because the change was never written to the Startup Configuration.

This is the most frequent cause in the field and matches the symptom set described in the source case.

3. Country Mode Mismatch Producing Channel Blackout

The W788 and W744 each have a Country setting in WLAN >> Basic. The set of legal channels differs by country:

Country 2.4 GHz Channels Allowed DFS Channels (5 GHz)
USA / FCC 1 – 11 UNII-1, UNII-3, DFS on UNII-2
Europe / ETSI 1 – 13 UNII-1, UNII-2, UNII-2-Extended, UNII-3 (DFS required)
Spain 1 – 13 (with restrictions) Restricted sub-bands
Japan 1 – 13 (14 in legacy 802.11b) W52, W53, W56

If the AP is set to "Auto" country and the client is set to "USA", the AP may select channel 13 (legal in ETSI but illegal under FCC rules) and the client will simply not associate. Conversely, if the AP is locked to a US channel and the client is in ETSI mode, the client will scan channels 12-13 that the AP never uses.

Best practice for industrial sites: set both devices to the correct country and lock the channel manually. Auto-channel selection in IWLAN is convenient but it can shift the AP to a channel the client cannot use after a power cycle.

4. PROFINET IO Update Time Too Aggressive for Wireless

IWLAN radio links are not equivalent to copper. Packet loss, retransmissions, and roaming latencies must be absorbed by the PROFINET update time. Siemens' engineering guideline (and the default recommendation in STEP 7 / TIA Portal for IWLAN devices) is:

Update Time Watchdog Retries Use Case
1 ms 3 3 NOT supported over IWLAN
4 ms 3 3 NOT supported over IWLAN
16 ms 3 3 Minimum recommended for IWLAN
32 ms 3 3 Default for many IWLAN PROFINET devices
64 – 128 ms 3 3 Marginal radio, congested 2.4 GHz band
256 ms – 1 s 3 3 Long-range, high-interference sites
Hard limit: A PROFINET IO update time below 16 ms on an IWLAN segment is a configuration error. STEP 7 / TIA Portal will accept it in the project, the controller will try to honour it, and the AR will collapse under the first retransmission. Always force 16 ms minimum for IWLAN PROFINET devices and verify with a 128 ms / 3-retry fallback test if the radio environment is unknown.

5. 2.4 GHz Co-Channel Interference at University / Plant Sites

Many non-industrial WLANs (campus Wi-Fi, lab access points, microwave ovens, Bluetooth) crowd the 2.4 GHz band. With the W788 set to "Auto Channel", the AP may hop to a channel that overlaps a neighbour's 40 MHz HT network, causing intermittent loss of the PN IO AR. Diagnostic actions:

  • Run a Wi-Fi survey with a tool such as Acrylic Wi-Fi, inSSIDer, or a spectrum analyser.
  • Identify the three cleanest 2.4 GHz channels at the AP mounting location (typically 1, 6, 11 in the US).
  • Lock the AP and the client to one of these clean channels.
  • Alternatively, switch the IWLAN link to 5 GHz (UNII-1 channels 36/40/44/48 are usually free and do not require DFS in many regulatory domains) — verify with the country profile.

Step-by-Step Resolution Procedure

  1. Confirm reachability of the W744 client. From the AP side, ping the client IP. If the ping fails, the issue is layer-2/3 forwarding, not PROFINET. Fix the IP plan (WBM >> Layer 3) and re-test before touching PROFINET parameters.
  2. Download the configuration of both devices for offline analysis: WBM >> Save & Load >> HTTP. Save the config file and the running configuration. Diff them — they must match. Any setting that differs is a candidate.
  3. Set the MAC mode on the W744 to "Adopt MAC Manually" in the Basic Wizard or under Layer 2 >> MAC Mode. Enter the MAC of the downstream ET200S, including the dashes. Verify the entry visually — single-character typos here are silent and produce AR aborts.
  4. Click "Set Values", then "Commit" (or "Save") and trigger a software reboot: System >> Restart >> Software Restart. Wait for the W744 to come back online (~60-90 s) and verify the LED pattern: power LED green, link LED on the LAN port showing the ET200S MAC as the connected peer.
  5. Align the country setting on both AP and client. Use the actual country of installation, not "Automatic". For training labs and university sites, this is usually the country where the hardware is physically installed.
  6. Lock the radio channel manually. In WLAN >> Radio, disable "Auto Channel" and select a 2.4 GHz channel that is not occupied by a neighbour AP, or move the link to 5 GHz if the antennas and antennas cables support it.
  7. Verify PROFINET update time and watchdog in STEP 7 / TIA Portal: open the properties of the ET200S station, tab "PROFINET interface", set update time to 16 ms and number of retries to 3. Compile and download the project.
  8. Watch the diagnostic buffer of the IO controller during the next AR establishment. A clean "AR established, IO device OK" message confirms the fix.
  9. If the AR still aborts, temporarily increase the update time to 128 ms / 3 retries to rule out transient RF loss. If 128 ms works and 16 ms does not, the radio environment is the limiting factor, not the configuration.

Verification: Confirming the Link Is Healthy

Check Where Expected Result
W744 power LED Front of device Solid green
W744 LAN LED ET200S port Solid green (link up, no flashing)
W744 WLAN LED (R1) Front of device Solid green when AR active
WBM >> Information >> Log Table W744 WBM No "MAC mode invalid" or "AR abort" entries
STEP 7 / TIA Online >> Diagnostics IO controller ET200S = "OK", no station failure
PROFINET update time STEP 7 device properties ≥ 16 ms, 3 retries
WBM >> WLAN >> AP Table W788 WBM W744 listed with correct MAC and signal strength > -75 dBm

Diagnostic Matrix: Symptoms vs Probable Cause

Symptom Most Likely Root Cause First Action
WBM shows MAC 00-00-00-00-00-00 MAC mode not set, or set without reboot Set "Adopt MAC Manually" and software-reboot
Client associates, then disassociates every few seconds Channel/country mismatch, or security key mismatch Match country on AP and client, verify WPA2 key
AR established, then aborted within seconds Update time too low for radio Raise to 16 ms, then 32 ms / 128 ms for test
WBM inaccessible on client IP IP plan wrong, or no route from AP subnet Re-assign static IP, ping from AP subnet
RSSI good but AR still fails Hidden interfering AP on same channel Spectrum scan, manual channel change
Multiple IO devices behind W744 Topology exceeds client capability Replace W744 with W748 or add managed switch

Web Based Management Pages Used in This Procedure

  • Information >> Start Page — device model, firmware, MAC of the device itself.
  • Layer 2 >> MAC Mode — Adopt MAC Manually entry for the client.
  • WLAN >> Basic — country, channel, SSID, radio mode (802.11 a/b/g/n).
  • WLAN >> Security — WPA2/AES key, key management.
  • System >> Restart — software reboot (required after parameter commit).
  • Save & Load >> HTTP — download configuration for offline diff.
  • Information >> Log Table — events, AR aborts, association failures.

For a guided configuration sequence, refer to the SIMATIC NET online help page Editing properties and parameters — SCALANCE W in the TIA Portal documentation set. That page documents the parameter editing flow inside TIA Portal, which is the recommended commissioning environment for new installations.

Field-Proven Caveats

  • Save & Load behaviour: on older firmware branches the W744 will accept parameter changes in the WBM and only persist them on the next "Save & Load >> Commit". Forgetting to commit is functionally identical to forgetting to reboot — the value is in volatile memory only.
  • Static vs DHCP IP: for PROFINET diagnostics, always assign a static IP to the W744 from the same subnet as the IO controller. DHCP-rescued IPs will change after power cycles and the controller will lose the AR.
  • Time sources: PROFINET diagnostics timestamps are only meaningful if the SCALANCE W clock is synchronised (SNTP or SIMATIC time). Skewed clocks make log table correlation impossible.
  • One IO device per W744: the W744 in client mode is designed for a single PROFINET IO device. Adding a second device behind it will work in some firmware versions for non-PROFINET traffic but will break PROFINET ARs because the W744 cannot multiplex the controller's AR with two device MACs.
  • Security profile: "Key security" (legacy WPA-PSK TKIP) is supported but discouraged in favour of WPA2/AES. If the AP is set to WPA2/AES-only and the client to mixed mode, association will succeed at low rates but PROFINET jitter can rise because the radios fall back to legacy rates for management frames.

Standards Reference

The PROFINET update time and watchdog behaviour is defined in IEC 61784-2 (PROFINET profiles) and the PROFINET Installation Guideline (PNO document 8.062). The wireless physical layer is governed by IEEE 802.11 a/b/g/n depending on the SCALANCE W7xx variant. Always cross-check the configured update time against the profile selected in STEP 7 / TIA Portal (e.g. "PROFINET IO profile 4" for IWLAN applications).

Frequently Asked Questions

Why does my SCALANCE W744 show MAC 00-00-00-00-00-00 in the WBM?

Either the MAC mode is set to "Automatic" and no downstream device has been learned yet, or the manual MAC was entered but the device was not software-rebooted to commit the change. Set Layer 2 >> MAC Mode to "Adopt MAC Manually", enter the ET200S MAC, click "Set Values", and trigger a software restart from System >> Restart.

What is the minimum PROFINET update time over an IWLAN link?

16 ms with 3 retries is the minimum Siemens-recommended setting for SCALANCE W7xx PROFINET IO. Update times of 1 ms, 2 ms, 4 ms, or 8 ms are technically accepted by STEP 7 / TIA Portal but will not survive the first wireless retransmission. If the link is marginal, raise to 32 ms or 128 ms for commissioning and tune downward once the radio environment is verified.

Can I connect more than one PROFINET IO device behind a SCALANCE W744 client?

No — a SCALANCE W744 client supports exactly one PROFINET IO device. To connect multiple devices behind a wireless client, use a SCALANCE W748 (client with bridge) plus a downstream managed switch, or replace the topology with an IWLAN/PB link and PROFIBUS DP behind it. Always plan the topology for one IO device per W744.

How do I fix a country/channel mismatch between SCALANCE W788 and W744?

Set WLAN >> Basic >> Country on both devices to the actual installation country (not "Automatic"), and lock the radio channel manually to a known-good 2.4 GHz channel such as 1, 6, or 11 in the US. Verify that both devices list the same channel in the WBM AP table. If interference is high, migrate the link to a 5 GHz UNII-1 channel (36/40/44/48) where the regulatory and DFS constraints are simpler.

Where do I download the configuration files of a SCALANCE W device?

Open the Web Based Management of the device, navigate to Save & Load >> HTTP, and download both the "Startup Configuration" and the "Running Configuration" as .conf files. Compare them offline; any difference indicates a setting that was changed in the WBM but not committed. Always download both files before opening a support case with Siemens Industry Online Support.

Back to blog