WinCC V7.4 Redundancy Hardware Selection with S7-400H PLC and CP1623
Overview
Designing a redundant WinCC V7.4 SCADA system in front of a SIMATIC S7-400H requires more than duplicating servers. Every layer — server, network adapter, license, switch — has its own redundancy model, and the parts must be ordered in a specific combination. A common design error is to specify the wrong S7 communication license (SOFTNET instead of HARDNET, or a missing REDCONNECT upgrade) when the workstation hosts a CP1623 PCIe Ethernet card. This reference consolidates the correct part topology, compares two agent proposals, and documents the license logic you must verify before issuing a purchase order.
The target architecture assumed in this article is a 2-server / 2-client WinCC V7.4 SP1 SCADA cluster with redundant S7-400H PLCs and one or two SCALANCE switches forming the PROFINET/S7 backbone. All WinCC V7.4 server licenses are 6AV6371-1CA07-4AX0; all RT client licenses are 6AV6381-2CA07-4AX0; the WinCC Redundancy package is 6AV6371-1CF07-4AX0. PowerTags are bounded by RC 2048 (6AV6381-2BP07-4AX0).
WinCC V7.4 Redundancy Architecture Fundamentals
WinCC V7.4 redundancy works as an active/standby server pair that shares a project and an internal redundancy tag structure. Each server independently holds a complete image of the process database. After every configurable update cycle, the standby server compares its internal process image to the partner server. If the partner fails to respond within the configured timeout (default 25 s, settable 5–65535 s in WinCC Explorer under Computer Properties > Redundancy), the standby takes ownership of the WinCC clients and alarms.
The redundancy handshake is implemented at the WinCC application layer (TCP port 6677 for the Redundancy Synchronization service by default), not at the S7 layer. This is critical: the S7 communication itself can fail over inside a single PC if the workstation has two CP1623 cards, but the WinCC redundancy peer check is independent of which CP is used.
For a redundant S7-400H PLC, the CP1623 on the WinCC side must use the S7-REDCONNECT protocol extension to subscribe to both H-CPUs simultaneously and tolerate a CPU switch-over. This extension is licensed separately from the base HARDNET-IE S7 license.
Required software layers per WinCC server
- Windows Server 2012 R2 / 2016 / 2019 (x64) — see WinCC V7.4 installation prerequisites in the SIMATIC WinCC V7.4 SP1 release notes.
- SIMATIC WinCC V7.4 SP1 (RT 2048) — 6AV6371-1CA07-4AX0.
- WinCC/Redundancy — 6AV6371-1CF07-4AX0 (one license per server, one floating license for the package itself).
- SIMATIC NET PC software containing HARDNET-IE S7 — installed once and bound to the CP1623 hardware.
- S7-REDCONNECT license — either as a stand-alone or as a Power Pack upgrade on top of HARDNET-IE S7.
HARDNET vs SOFTNET License Topology
Siemens S7 PC communication licenses are split into two families, and the choice is dictated entirely by the physical network adapter in the PC, not by the controller on the other end.
| Family | Binds to | Use case | Maximum connections |
|---|---|---|---|
| SOFTNET-IE S7 | Software (any standard NIC) | Engineering station, small RT station without Siemens CP | Up to 64 S7 connections per license |
| HARDNET-IE S7 | Specific CP (e.g. CP1623) by serial number | Production RT server with CP1623, CP1616, CP1628 | Up to 128 S7 connections, depends on CP |
| SOFTNET-IE S7 REDCONNECT | Software, with virtual redundancy | Non-CP PCs talking to S7-400H | Typically used in VM environments |
| HARDNET-IE S7 REDCONNECT | Specific CP by serial number | CP1623/CP1628 PCs talking to S7-400H | Pair of H-CPUs treated as one logical controller |
The decisive line in the catalog: HARDNET-IE S7 REDCONNECT (e.g. 6GK1716-0HB13-0AA0) is the correct license for a CP1623-equipped WinCC server front-ending an S7-400H. The Power Pack variant 6GK1716-0HB13-0AC0 upgrades an existing HARDNET-IE S7 license to REDCONNECT capability in place.
CP1623 Hardware Reference
The CP1623 (6GK1162-3AA00) is a PCIe x1 Ethernet card for SIMATIC PCs and supports PROFINET IO controller/IO device plus S7 / open communication. For a WinCC redundancy server, the relevant features are:
| Feature | Specification |
|---|---|
| Article number | 6GK1162-3AA00 |
| Bus type | PCI Express x1 (also available as PCI-X variant CP1613 — not interchangeable) |
| Number of ports | 2 × RJ45 (integrated 2-port switch) |
| Transmission rate | 10 / 100 Mbps (Fast Ethernet) |
| Supported protocols | PROFINET IO RT/IRT, MRP, MRPD, S7 communication, open IE (TCP/UDP), SNMP |
| Supported redundancy | MRP client, MRP master, S2 device redundancy |
| Max. S7 connections | Up to 128, depends on installed HARDNET-IE S7 license |
| Driver | SIMATIC NET PC Software V13 SP2 / V14 / V15 / V16 — see compatibility list for WinCC V7.4 |
| Operating system | Windows 7 SP1 / Server 2008 R2 SP1 and later |
On a single physical CP1623 the integrated 2-port switch can be used either as an external MRP ring member (one port to the ring, one port free) or as a single direct connection. For redundancy to a S7-400H, only one CP1623 per server is sufficient from a pure protocol standpoint — both H-CPUs are reached through the same S7-REDCONNECT connection that internally handles the H-switchover.
Configuration Comparison: Original Agent Proposals
The original design phase produced two competing bills of material. Both used the same server and client licensing, but diverged on the PC-side communication license line and on the CP1623 count.
| # | Item | Article number | Config 1 qty | Config 2 qty | Verdict |
|---|---|---|---|---|---|
| 1 | CP1623 PCIe Ethernet card | 6GK1162-3AA00 | 4 (2/server) | 2 (1/server) | Both valid; 1/server is sufficient |
| 2 | SOFTNET-IE S7 REDCONNECT VM V13 | 6GK1704-0HB13-0AA0 | 2 | — | Wrong — SOFTNET binds to a software NIC, not to CP1623 |
| 2b | HARDNET-IE S7 V8.2 SP1 | 6GK1716-1CB08-2AA0 | — | 2 | Correct base license, but REDCONNECT missing |
| 3 | WinCC/Redundancy | 6AV6371-1CF07-4AX0 | 1 | 1 | Correct |
| 4 | WinCC/Server V7.4 RT 2048 | 6AV6371-1CA07-4AX0 | 2 | 2 | Correct |
| 5 | WinCC V7.4 RC 2048 (PowerTags) | 6AV6381-2BP07-4AX0 | 2 | 2 | Correct |
| 6 | WinCC RT Client | 6AV6381-2CA07-4AX0 | 2 | 2 | Correct |
| 7 | SCALANCE switch | (model to be defined) | 1 | 1 | Single point of failure — add a second switch |
Configuration 1 fails because line item 2 specifies a SOFTNET license while the PC uses a HARDNET-class CP1623. SOFTNET-IE S7 REDCONNECT VM binds to a virtual adapter inside the OS, not to a CP1623 MAC/serial, so when SIMATIC NET starts it cannot find a matching license for the CP1623 and the S7 connection fails with licensing error.
Configuration 2 fails because line item 2b supplies the correct HARDNET base license but does not include the REDCONNECT upgrade. The server can talk to a non-redundant S7-400 but cannot track H-CPU switchover; alarms freeze after the first failover.
Corrected Bill of Materials
The corrected BoM uses one CP1623 per server, one HARDNET-IE S7 REDCONNECT license per server, and two SCALANCE switches in MRP. This is the minimum configuration that achieves both server-side and network-side redundancy without single points of failure.
| # | Item | Article number | Qty | Function |
|---|---|---|---|---|
| 1 | CP1623 PCIe Ethernet card | 6GK1162-3AA00 | 2 | One per server; binds HARDNET-IE license to physical hardware |
| 2 | HARDNET-IE S7 REDCONNECT V13 | 6GK1716-0HB13-0AA0 | 2 | One per CP1623; enables S7-400H connection with H-CPU tracking |
| 3 | WinCC/Redundancy | 6AV6371-1CF07-4AX0 | 1 | Activates WinCC Server/Server redundancy (floating) |
| 4 | WinCC/Server V7.4 RT 2048 | 6AV6371-1CA07-4AX0 | 2 | Two redundant server licenses, RT 2048 PowerTags |
| 5 | WinCC V7.4 RC 2048 | 6AV6381-2BP07-4AX0 | 2 | Two PowerTags expansion licenses |
| 6 | WinCC RT Client | 6AV6381-2CA07-4AX0 | 2 | Two client licenses |
| 7 | SCALANCE XC208 (or XC216/XR-500) | e.g. 6GK5208-0BA00-2AC2 | 2 | Two redundant managed switches in MRP ring |
How Many CP1623 Cards per Server?
The original Config 1 specified two CP1623 per server. This is technically valid but almost never necessary when the entire server is already redundant.
| Topology | CP1623 per server | Failure coverage | Cost | Verdict |
|---|---|---|---|---|
| Single CP per server | 1 | CP failure: the affected server drops connections, but the partner server takes over WinCC clients within ~25 s | Lowest | Recommended for most S7-400H plants |
| Dual CP per server | 2 (each with its own HARDNET-IE license) | CP failure: the affected server keeps operating via the second CP, partner takes over simultaneously | Doubles CP and license cost | Justified only if S7-400H is non-redundant or hot-process-uptime SLA requires sub-second failover |
If dual CP1623 per server is chosen, the two cards must be on different PCIe buses (avoid shared upstream link) and the S7 connections must be split in WinCC so that primary variables are read through CP A and redundant variables through CP B. Otherwise both CPs will fail together on the same PCIe root complex fault.
SCALANCE Switch Selection and Network Redundancy
A single SCALANCE switch between the S7-400H and the two WinCC servers is the most common single point of failure in the proposed architecture. If that switch fails, both servers lose their S7 connections simultaneously and the entire HMI cluster goes dark — server redundancy cannot compensate because both servers are equally blind.
The minimum acceptable switch topology is two SCALANCE units configured as an MRP ring. Each WinCC server connects one CP1623 port to SCALANCE-A and the second port to SCALANCE-B. Each S7-400H CPU (H-CPU1 and H-CPU2) likewise connects to both switches through its PROFINET ports. The S7-REDCONNECT license tolerates one switch segment failure, the WinCC redundancy tolerates one server failure, and the union of the two tolerates any single hardware loss except simultaneous dual-server-plus-switch failure.
| SCALANCE model | Article number (typical) | Ports | Layer | MRP support |
|---|---|---|---|---|
| SCALANCE XC208 | 6GK5208-0BA00-2AC2 | 8 × RJ45 | 2 | Yes (MRP client) |
| SCALANCE XC216 | 6GK5216-0BA00-2AC2 | 16 × RJ45 | 2 | Yes (MRP client) |
| SCALANCE XR528-6M | 6GK5528-0AR00-2AR2 | 24-port managed | 3 | Yes (MRP + MRPD) |
| SCALANCE XC-200E (Enhanced) | 6GK5226-2GS00-2AC2 | 26-port ring-capable | 2 | Yes (MRP manager) |
Logical Topology (Server, Switch, PLC)
The connection map below summarizes the validated topology. Each S7-400H CPU has its own PROFINET interface module (e.g. CP443-1) and is reachable through both SCALANCE switches. Each WinCC server has a single CP1623 with both ports connected to different SCALANCE units. WinCC redundancy peer traffic uses the same network but is logically separated by IP subnet and TCP port.
+-------------------+ +-------------------+
| WinCC Server A | | WinCC Server B |
| WinCC V7.4 SP1 | | WinCC V7.4 SP1 |
| CP1623 [p1]-----+-------+ +----- CP1623 [p1] |
| | | | |
| CP1623 [p2]-----+ +---+--+---+-----+ CP1623 [p2] |
+-------------------+ | | | +---------------+
| | |
+----+--+ +--+----+
| SC-A | | SC-B |
| SCAL. | | SCAL. |
+--+----+ +-+--+--+
| |
+---+ +---+
| |
+-------+--+-------+
| S7-400H |
| CPU 410-5H |
| PN-H-CPU-1 |
| PN-H-CPU-2 |
+-------------------+
S7-400H Connection Parameters
When WinCC connects to an S7-400H through HARDNET-IE S7 REDCONNECT, configure the S7 connection in the WinCC project with the following parameters under Tag Management > SIMATIC S7 PROTOCOL SUITE > New Connection:
| Parameter | Value | Notes |
|---|---|---|
| Connection name | e.g. S7_400H_A
|
One logical connection per H-CPU pair (REDCONNECT collapses them) |
| Partner IP | IP of H-CPU-1 (rack 0, slot 1) | REDCONNECT auto-discovers H-CPU-2 |
| Rack | 0 | S7-400H always rack 0 |
| Slot | 3 | H-CPU logical slot |
| Connection type | S7 Connection (TCP) | ISO-on-TCP not required for IE |
| Active / Passive | Active (WinCC initiates) | WinCC always active when connecting to PLC |
| Cycle / scan time | 1000–2000 ms (process dependent) | Lower values increase load without benefit for HMI |
Commissioning and Verification
- Power up both S7-400H CPUs, wait for H-link up and RUN-Redundant state (LEDs: RUN green, REDF off on both).
- Power up SCALANCE-A and SCALANCE-B. Verify the MRP ring closes within ~50 ms.
- Power up WinCC Server A first. Install HARDNET-IE S7 REDCONNECT license and bind it to the CP1623 serial number using SIMATIC NET > Commissioning PC Station.
- Confirm S7 connection establishes under WinCC Explorer > Tag Management; status icon must be green.
- Power up WinCC Server B. Repeat the license binding. Verify WinCC Redundancy Synchronization is OK in WinCC Explorer under Computer Properties > Redundancy > Status.
- From each server, force an H-system switchover in STEP 7 via H-CPU > Operating Mode > Switchover. Verify that the WinCC tag values continue to update on both servers without a single alarm freeze > 5 s.
- Pull the network cable from one SCALANCE; verify MRP reconverges and S7 stays connected on the surviving switch path.
- Stop the WinCC Runtime on Server A; verify Server B becomes Master within the configured redundancy timeout and clients reconnect automatically.
Common Fault Conditions
| Symptom | Root cause | Remedy |
|---|---|---|
| WinCC channel diagnosis: License missing or invalid | SOFTNET license used with CP1623, or HARDNET license bound to a different MAC/serial | Replace SOFTNET with HARDNET-IE S7 REDCONNECT; rebind license to CP1623 in Commissioning PC Station |
| S7 connection stays Disconnected after H-CPU switchover | REDCONNECT license missing; only base HARDNET-IE S7 installed | Order Power Pack HARDNET-IE S7 REDCONNECT (6GK1716-0HB13-0AC0) and upgrade existing license |
| WinCC redundancy status: Not synchronized | Redundancy Synchronization port (default 6677) blocked by Windows Firewall or wrong partner IP | Open inbound TCP 6677 on both servers; verify partner IP in Computer Properties > Redundancy |
| Both servers lose HMI simultaneously after a single switch reboot | Single SCALANCE switch used (single point of failure) | Add second SCALANCE and split CP1623 port 1 / port 2 across both switches |
| CPU switchover freezes the tag update on WinCC for > 30 s | MRP ring broken — switch is in blocking state | Verify MRP manager priority; check that all ring ports are configured with the same MRP domain ID |
| License reports License not found after CP1623 swap | HARDNET license is hardware-bound to the original CP1623 serial | Use Siemens License Key Diskette re-hosting procedure or contact Siemens Industry Online Support for license re-binding |
Reference Documentation
For deeper configuration of a redundancy-enabled WinCC HMI device (especially for WinCC Unified), see the official Siemens TIA Portal cloud documentation:
Refer to the SIMATIC WinCC V7.4 SP1 System Manual for the exact redundancy timeout default values, and to the SIMATIC NET PC Software Commissioning Manual for license binding procedures.
Do I need two CP1623 cards per WinCC server when the PLC is S7-400H?
No. A single CP1623 with the HARDNET-IE S7 REDCONNECT license is sufficient. The S7-REDCONNECT protocol internally tracks both H-CPUs and tolerates the H-switchover on one CP. A second CP1623 per server only adds value when the WinCC server itself must survive a CP failure without any partner-server takeover — which is rare when the server pair is already redundant.
Why is SOFTNET-IE S7 REDCONNECT wrong for a CP1623-equipped PC?
SOFTNET licenses bind to a software-defined NIC inside the OS, not to a physical CP1623 by serial number. When SIMATIC NET starts, the license manager cannot match the CP1623 hardware to the SOFTNET license and the S7 channel reports "License missing or invalid". The correct license for a CP1623 in front of an S7-400H is HARDNET-IE S7 REDCONNECT (6GK1716-0HB13-0AA0).
What is the difference between HARDNET-IE S7 and HARDNET-IE S7 REDCONNECT?
HARDNET-IE S7 (e.g. 6GK1716-1CB08-2AA0) provides the base S7 communication on a CP1623 and connects to a non-redundant S7-400/S7-1500 controller. HARDNET-IE S7 REDCONNECT adds the extension that keeps a single logical connection alive across an S7-400H H-switchover and reads the current master H-CPU transparently. Without REDCONNECT, the connection drops during the first H-switchover and freezes WinCC tags until the operator manually re-establishes the channel.
Can I get away with a single SCALANCE switch between the S7-400H and the two WinCC servers?
Technically yes, but operationally no. A single switch is a single point of failure that defeats both server redundancy and S7-400H redundancy — a switch failure blackouts the entire HMI cluster even though both servers and both PLCs are still healthy. Use two SCALANCE switches in MRP and connect each CP1623 port to a different switch, with each H-CPU likewise connected to both.
What SCALANCE models are recommended for WinCC V7.4 redundancy front-ending an S7-400H?
For small installations, SCALANCE XC208 or XC216 (Layer 2) in MRP is sufficient. For larger plants or where Layer 3 routing is also required, use SCALANCE XR-500 or XC-200E (Enhanced) series. Designate one switch as the MRP manager and the other as MRP client to prevent ring flaps during reconfiguration.