WinCC V7.4 Redundancy Hardware Selection with S7-400H and CP1623

David Krause13 min read
SiemensTechnical ReferenceWinCC
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

WinCC V7.4 Redundancy Hardware Selection with S7-400H PLC and CP1623

Overview

Designing a redundant WinCC V7.4 SCADA system in front of a SIMATIC S7-400H requires more than duplicating servers. Every layer — server, network adapter, license, switch — has its own redundancy model, and the parts must be ordered in a specific combination. A common design error is to specify the wrong S7 communication license (SOFTNET instead of HARDNET, or a missing REDCONNECT upgrade) when the workstation hosts a CP1623 PCIe Ethernet card. This reference consolidates the correct part topology, compares two agent proposals, and documents the license logic you must verify before issuing a purchase order.

The target architecture assumed in this article is a 2-server / 2-client WinCC V7.4 SP1 SCADA cluster with redundant S7-400H PLCs and one or two SCALANCE switches forming the PROFINET/S7 backbone. All WinCC V7.4 server licenses are 6AV6371-1CA07-4AX0; all RT client licenses are 6AV6381-2CA07-4AX0; the WinCC Redundancy package is 6AV6371-1CF07-4AX0. PowerTags are bounded by RC 2048 (6AV6381-2BP07-4AX0).

License rule of thumb: If the PC is fitted with a CP1623 (or any HARDNET-IE capable CP) and the controller on the other end is a redundant S7-400H, the only valid license pair is HARDNET-IE S7 (or Power Pack HARDNET-IE S7 REDCONNECT) — never SOFTNET-IE S7 REDCONNECT VM.

WinCC V7.4 Redundancy Architecture Fundamentals

WinCC V7.4 redundancy works as an active/standby server pair that shares a project and an internal redundancy tag structure. Each server independently holds a complete image of the process database. After every configurable update cycle, the standby server compares its internal process image to the partner server. If the partner fails to respond within the configured timeout (default 25 s, settable 5–65535 s in WinCC Explorer under Computer Properties > Redundancy), the standby takes ownership of the WinCC clients and alarms.

The redundancy handshake is implemented at the WinCC application layer (TCP port 6677 for the Redundancy Synchronization service by default), not at the S7 layer. This is critical: the S7 communication itself can fail over inside a single PC if the workstation has two CP1623 cards, but the WinCC redundancy peer check is independent of which CP is used.

For a redundant S7-400H PLC, the CP1623 on the WinCC side must use the S7-REDCONNECT protocol extension to subscribe to both H-CPUs simultaneously and tolerate a CPU switch-over. This extension is licensed separately from the base HARDNET-IE S7 license.

Required software layers per WinCC server

  1. Windows Server 2012 R2 / 2016 / 2019 (x64) — see WinCC V7.4 installation prerequisites in the SIMATIC WinCC V7.4 SP1 release notes.
  2. SIMATIC WinCC V7.4 SP1 (RT 2048) — 6AV6371-1CA07-4AX0.
  3. WinCC/Redundancy — 6AV6371-1CF07-4AX0 (one license per server, one floating license for the package itself).
  4. SIMATIC NET PC software containing HARDNET-IE S7 — installed once and bound to the CP1623 hardware.
  5. S7-REDCONNECT license — either as a stand-alone or as a Power Pack upgrade on top of HARDNET-IE S7.

HARDNET vs SOFTNET License Topology

Siemens S7 PC communication licenses are split into two families, and the choice is dictated entirely by the physical network adapter in the PC, not by the controller on the other end.

Family Binds to Use case Maximum connections
SOFTNET-IE S7 Software (any standard NIC) Engineering station, small RT station without Siemens CP Up to 64 S7 connections per license
HARDNET-IE S7 Specific CP (e.g. CP1623) by serial number Production RT server with CP1623, CP1616, CP1628 Up to 128 S7 connections, depends on CP
SOFTNET-IE S7 REDCONNECT Software, with virtual redundancy Non-CP PCs talking to S7-400H Typically used in VM environments
HARDNET-IE S7 REDCONNECT Specific CP by serial number CP1623/CP1628 PCs talking to S7-400H Pair of H-CPUs treated as one logical controller

The decisive line in the catalog: HARDNET-IE S7 REDCONNECT (e.g. 6GK1716-0HB13-0AA0) is the correct license for a CP1623-equipped WinCC server front-ending an S7-400H. The Power Pack variant 6GK1716-0HB13-0AC0 upgrades an existing HARDNET-IE S7 license to REDCONNECT capability in place.

IPC bundle exception: When a CP1623 is purchased as part of a Siemens SIMATIC IPC bundle (e.g. IPC547G, IPC647D, IPC847D), the HARDNET-IE S7 license is delivered pre-installed and pre-bound. In that case only the Power Pack HARDNET-IE S7 REDCONNECT (6GK1716-0HB13-0AC0) must be ordered additionally. If the CP1623 is retrofitted into a non-Siemens PC, the full HARDNET-IE S7 REDCONNECT license must be ordered.

CP1623 Hardware Reference

The CP1623 (6GK1162-3AA00) is a PCIe x1 Ethernet card for SIMATIC PCs and supports PROFINET IO controller/IO device plus S7 / open communication. For a WinCC redundancy server, the relevant features are:

Feature Specification
Article number 6GK1162-3AA00
Bus type PCI Express x1 (also available as PCI-X variant CP1613 — not interchangeable)
Number of ports 2 × RJ45 (integrated 2-port switch)
Transmission rate 10 / 100 Mbps (Fast Ethernet)
Supported protocols PROFINET IO RT/IRT, MRP, MRPD, S7 communication, open IE (TCP/UDP), SNMP
Supported redundancy MRP client, MRP master, S2 device redundancy
Max. S7 connections Up to 128, depends on installed HARDNET-IE S7 license
Driver SIMATIC NET PC Software V13 SP2 / V14 / V15 / V16 — see compatibility list for WinCC V7.4
Operating system Windows 7 SP1 / Server 2008 R2 SP1 and later

On a single physical CP1623 the integrated 2-port switch can be used either as an external MRP ring member (one port to the ring, one port free) or as a single direct connection. For redundancy to a S7-400H, only one CP1623 per server is sufficient from a pure protocol standpoint — both H-CPUs are reached through the same S7-REDCONNECT connection that internally handles the H-switchover.

Configuration Comparison: Original Agent Proposals

The original design phase produced two competing bills of material. Both used the same server and client licensing, but diverged on the PC-side communication license line and on the CP1623 count.

# Item Article number Config 1 qty Config 2 qty Verdict
1 CP1623 PCIe Ethernet card 6GK1162-3AA00 4 (2/server) 2 (1/server) Both valid; 1/server is sufficient
2 SOFTNET-IE S7 REDCONNECT VM V13 6GK1704-0HB13-0AA0 2 Wrong — SOFTNET binds to a software NIC, not to CP1623
2b HARDNET-IE S7 V8.2 SP1 6GK1716-1CB08-2AA0 2 Correct base license, but REDCONNECT missing
3 WinCC/Redundancy 6AV6371-1CF07-4AX0 1 1 Correct
4 WinCC/Server V7.4 RT 2048 6AV6371-1CA07-4AX0 2 2 Correct
5 WinCC V7.4 RC 2048 (PowerTags) 6AV6381-2BP07-4AX0 2 2 Correct
6 WinCC RT Client 6AV6381-2CA07-4AX0 2 2 Correct
7 SCALANCE switch (model to be defined) 1 1 Single point of failure — add a second switch

Configuration 1 fails because line item 2 specifies a SOFTNET license while the PC uses a HARDNET-class CP1623. SOFTNET-IE S7 REDCONNECT VM binds to a virtual adapter inside the OS, not to a CP1623 MAC/serial, so when SIMATIC NET starts it cannot find a matching license for the CP1623 and the S7 connection fails with licensing error.

Configuration 2 fails because line item 2b supplies the correct HARDNET base license but does not include the REDCONNECT upgrade. The server can talk to a non-redundant S7-400 but cannot track H-CPU switchover; alarms freeze after the first failover.

Corrected Bill of Materials

The corrected BoM uses one CP1623 per server, one HARDNET-IE S7 REDCONNECT license per server, and two SCALANCE switches in MRP. This is the minimum configuration that achieves both server-side and network-side redundancy without single points of failure.

# Item Article number Qty Function
1 CP1623 PCIe Ethernet card 6GK1162-3AA00 2 One per server; binds HARDNET-IE license to physical hardware
2 HARDNET-IE S7 REDCONNECT V13 6GK1716-0HB13-0AA0 2 One per CP1623; enables S7-400H connection with H-CPU tracking
3 WinCC/Redundancy 6AV6371-1CF07-4AX0 1 Activates WinCC Server/Server redundancy (floating)
4 WinCC/Server V7.4 RT 2048 6AV6371-1CA07-4AX0 2 Two redundant server licenses, RT 2048 PowerTags
5 WinCC V7.4 RC 2048 6AV6381-2BP07-4AX0 2 Two PowerTags expansion licenses
6 WinCC RT Client 6AV6381-2CA07-4AX0 2 Two client licenses
7 SCALANCE XC208 (or XC216/XR-500) e.g. 6GK5208-0BA00-2AC2 2 Two redundant managed switches in MRP ring

How Many CP1623 Cards per Server?

The original Config 1 specified two CP1623 per server. This is technically valid but almost never necessary when the entire server is already redundant.

Topology CP1623 per server Failure coverage Cost Verdict
Single CP per server 1 CP failure: the affected server drops connections, but the partner server takes over WinCC clients within ~25 s Lowest Recommended for most S7-400H plants
Dual CP per server 2 (each with its own HARDNET-IE license) CP failure: the affected server keeps operating via the second CP, partner takes over simultaneously Doubles CP and license cost Justified only if S7-400H is non-redundant or hot-process-uptime SLA requires sub-second failover

If dual CP1623 per server is chosen, the two cards must be on different PCIe buses (avoid shared upstream link) and the S7 connections must be split in WinCC so that primary variables are read through CP A and redundant variables through CP B. Otherwise both CPs will fail together on the same PCIe root complex fault.

SCALANCE Switch Selection and Network Redundancy

A single SCALANCE switch between the S7-400H and the two WinCC servers is the most common single point of failure in the proposed architecture. If that switch fails, both servers lose their S7 connections simultaneously and the entire HMI cluster goes dark — server redundancy cannot compensate because both servers are equally blind.

The minimum acceptable switch topology is two SCALANCE units configured as an MRP ring. Each WinCC server connects one CP1623 port to SCALANCE-A and the second port to SCALANCE-B. Each S7-400H CPU (H-CPU1 and H-CPU2) likewise connects to both switches through its PROFINET ports. The S7-REDCONNECT license tolerates one switch segment failure, the WinCC redundancy tolerates one server failure, and the union of the two tolerates any single hardware loss except simultaneous dual-server-plus-switch failure.

SCALANCE model Article number (typical) Ports Layer MRP support
SCALANCE XC208 6GK5208-0BA00-2AC2 8 × RJ45 2 Yes (MRP client)
SCALANCE XC216 6GK5216-0BA00-2AC2 16 × RJ45 2 Yes (MRP client)
SCALANCE XR528-6M 6GK5528-0AR00-2AR2 24-port managed 3 Yes (MRP + MRPD)
SCALANCE XC-200E (Enhanced) 6GK5226-2GS00-2AC2 26-port ring-capable 2 Yes (MRP manager)
MRP manager requirement: Only one device in the MRP ring may be the MRP manager. Designate one SCALANCE as manager (the higher model, typically XC-200E or XR-500) and the other as client to avoid ring flaps. Configure the manager priority under Layer 2 > Ring > MRP.

Logical Topology (Server, Switch, PLC)

The connection map below summarizes the validated topology. Each S7-400H CPU has its own PROFINET interface module (e.g. CP443-1) and is reachable through both SCALANCE switches. Each WinCC server has a single CP1623 with both ports connected to different SCALANCE units. WinCC redundancy peer traffic uses the same network but is logically separated by IP subnet and TCP port.

+-------------------+              +-------------------+
|   WinCC Server A  |              |   WinCC Server B  |
|   WinCC V7.4 SP1  |              |   WinCC V7.4 SP1  |
|   CP1623 [p1]-----+-------+      +----- CP1623 [p1]  |
|                   |       |      |                   |
|   CP1623 [p2]-----+   +---+--+---+-----+ CP1623 [p2] |
+-------------------+   |       |   |   +---------------+
                        |       |   |
                   +----+--+ +--+----+
                   |  SC-A | |  SC-B |
                   | SCAL. | | SCAL. |
                   +--+----+ +-+--+--+
                      |          |
                      +---+  +---+
                          |  |
                  +-------+--+-------+
                  |   S7-400H        |
                  |   CPU 410-5H     |
                  |   PN-H-CPU-1     |
                  |   PN-H-CPU-2     |
                  +-------------------+

S7-400H Connection Parameters

When WinCC connects to an S7-400H through HARDNET-IE S7 REDCONNECT, configure the S7 connection in the WinCC project with the following parameters under Tag Management > SIMATIC S7 PROTOCOL SUITE > New Connection:

Parameter Value Notes
Connection name e.g. S7_400H_A One logical connection per H-CPU pair (REDCONNECT collapses them)
Partner IP IP of H-CPU-1 (rack 0, slot 1) REDCONNECT auto-discovers H-CPU-2
Rack 0 S7-400H always rack 0
Slot 3 H-CPU logical slot
Connection type S7 Connection (TCP) ISO-on-TCP not required for IE
Active / Passive Active (WinCC initiates) WinCC always active when connecting to PLC
Cycle / scan time 1000–2000 ms (process dependent) Lower values increase load without benefit for HMI

Commissioning and Verification

  1. Power up both S7-400H CPUs, wait for H-link up and RUN-Redundant state (LEDs: RUN green, REDF off on both).
  2. Power up SCALANCE-A and SCALANCE-B. Verify the MRP ring closes within ~50 ms.
  3. Power up WinCC Server A first. Install HARDNET-IE S7 REDCONNECT license and bind it to the CP1623 serial number using SIMATIC NET > Commissioning PC Station.
  4. Confirm S7 connection establishes under WinCC Explorer > Tag Management; status icon must be green.
  5. Power up WinCC Server B. Repeat the license binding. Verify WinCC Redundancy Synchronization is OK in WinCC Explorer under Computer Properties > Redundancy > Status.
  6. From each server, force an H-system switchover in STEP 7 via H-CPU > Operating Mode > Switchover. Verify that the WinCC tag values continue to update on both servers without a single alarm freeze > 5 s.
  7. Pull the network cable from one SCALANCE; verify MRP reconverges and S7 stays connected on the surviving switch path.
  8. Stop the WinCC Runtime on Server A; verify Server B becomes Master within the configured redundancy timeout and clients reconnect automatically.

Common Fault Conditions

Symptom Root cause Remedy
WinCC channel diagnosis: License missing or invalid SOFTNET license used with CP1623, or HARDNET license bound to a different MAC/serial Replace SOFTNET with HARDNET-IE S7 REDCONNECT; rebind license to CP1623 in Commissioning PC Station
S7 connection stays Disconnected after H-CPU switchover REDCONNECT license missing; only base HARDNET-IE S7 installed Order Power Pack HARDNET-IE S7 REDCONNECT (6GK1716-0HB13-0AC0) and upgrade existing license
WinCC redundancy status: Not synchronized Redundancy Synchronization port (default 6677) blocked by Windows Firewall or wrong partner IP Open inbound TCP 6677 on both servers; verify partner IP in Computer Properties > Redundancy
Both servers lose HMI simultaneously after a single switch reboot Single SCALANCE switch used (single point of failure) Add second SCALANCE and split CP1623 port 1 / port 2 across both switches
CPU switchover freezes the tag update on WinCC for > 30 s MRP ring broken — switch is in blocking state Verify MRP manager priority; check that all ring ports are configured with the same MRP domain ID
License reports License not found after CP1623 swap HARDNET license is hardware-bound to the original CP1623 serial Use Siemens License Key Diskette re-hosting procedure or contact Siemens Industry Online Support for license re-binding

Reference Documentation

For deeper configuration of a redundancy-enabled WinCC HMI device (especially for WinCC Unified), see the official Siemens TIA Portal cloud documentation:

Refer to the SIMATIC WinCC V7.4 SP1 System Manual for the exact redundancy timeout default values, and to the SIMATIC NET PC Software Commissioning Manual for license binding procedures.

Do I need two CP1623 cards per WinCC server when the PLC is S7-400H?

No. A single CP1623 with the HARDNET-IE S7 REDCONNECT license is sufficient. The S7-REDCONNECT protocol internally tracks both H-CPUs and tolerates the H-switchover on one CP. A second CP1623 per server only adds value when the WinCC server itself must survive a CP failure without any partner-server takeover — which is rare when the server pair is already redundant.

Why is SOFTNET-IE S7 REDCONNECT wrong for a CP1623-equipped PC?

SOFTNET licenses bind to a software-defined NIC inside the OS, not to a physical CP1623 by serial number. When SIMATIC NET starts, the license manager cannot match the CP1623 hardware to the SOFTNET license and the S7 channel reports "License missing or invalid". The correct license for a CP1623 in front of an S7-400H is HARDNET-IE S7 REDCONNECT (6GK1716-0HB13-0AA0).

What is the difference between HARDNET-IE S7 and HARDNET-IE S7 REDCONNECT?

HARDNET-IE S7 (e.g. 6GK1716-1CB08-2AA0) provides the base S7 communication on a CP1623 and connects to a non-redundant S7-400/S7-1500 controller. HARDNET-IE S7 REDCONNECT adds the extension that keeps a single logical connection alive across an S7-400H H-switchover and reads the current master H-CPU transparently. Without REDCONNECT, the connection drops during the first H-switchover and freezes WinCC tags until the operator manually re-establishes the channel.

Can I get away with a single SCALANCE switch between the S7-400H and the two WinCC servers?

Technically yes, but operationally no. A single switch is a single point of failure that defeats both server redundancy and S7-400H redundancy — a switch failure blackouts the entire HMI cluster even though both servers and both PLCs are still healthy. Use two SCALANCE switches in MRP and connect each CP1623 port to a different switch, with each H-CPU likewise connected to both.

What SCALANCE models are recommended for WinCC V7.4 redundancy front-ending an S7-400H?

For small installations, SCALANCE XC208 or XC216 (Layer 2) in MRP is sufficient. For larger plants or where Layer 3 routing is also required, use SCALANCE XR-500 or XC-200E (Enhanced) series. Designate one switch as the MRP manager and the other as MRP client to prevent ring flaps during reconfiguration.

Back to blog