1. Engineering Problem Statement
A typical brownfield plant segment bundles a moderate I/O footprint (≈385 process signals: 300 DI, 25 AI, 50 DO, 10 AO), three operator workstations displaying geographically separate production units, three S7-300 CPU 315-2 DP controllers running in a software-redundant arrangement, and serial Modbus RTU slaves polled by the CPUs in master mode. The selection question that follows is not which Siemens SCADA product is the most modern, but which one matches the controller generation, the I/O scale, the redundancy model, and the operator-station topology that the plant already has in place.
This reference consolidates the decision matrix between SIMATIC WinCC V7.x (the "classic" SCADA), SIMATIC WinCC in the TIA Portal (Advanced and Professional variants), and SIMATIC PCS 7, then walks through the server-client architecture, Windows operating-system requirements, software-redundancy mechanics, and Modbus RTU integration for an S7-300 CPU 315-2 DP fleet.
2. Selection Matrix: WinCC vs WinCC TIA Portal vs PCS 7
| Criterion | WinCC V7.x (Classic) | WinCC TIA Portal (Advanced) | WinCC TIA Portal (Professional) | PCS 7 V9.x |
|---|---|---|---|---|
| Supported controllers | S7-300, S7-400, S7-1200/1500 (via OPC), third-party | S7-1200, S7-1500, ET 200SP, S7-300/400 limited | S7-1200, S7-1500, S7-300/400, WinCC Runtime Advanced targets | S7-400, S7-400H, AS 410 only |
| Typical I/O scale | 10k–250k tags per server | Up to ~3,200 power-tags (RT Advanced) | Up to 16k tags / 64k archives | Process-cell to plant-wide (DCM, route control) |
| Redundant server pair | Yes, WinCC Redundancy (option) | No (single-server model) | Yes (option package) | Yes (CAS, redundant AS, redundant OS server) |
| Client-server architecture | Native multi-client / web client | Limited (RT Advanced is local panel) | Native WinCC Professional client-server | Native OS-Server / OS-Client pair |
| Add-ons | Web Navigator, Telecontrol, ProAgent, Energy Manager, Connectivity Pack | Smaller: Sm@rtServer, Recipes, Logging, Audit | Sm@rtServer, OPC UA, Recipes, Logging, MindSphere connector | Route Control, BATCH, Safety Integrated, SIMATIC Logon |
| Software-redundant S7-300 connection | Yes via S7-REDCONNECT | Limited / not certified | Yes via "S7-300/400 redundancy" channel | Not the target use case |
| Engineering tool | SIMATIC Manager / WinCC Explorer | TIA Portal (single project) | TIA Portal (unified PLC + HMI) | PCS 7 Engineering Toolset (CFC, SFC, SCL) |
| Typical use case | Plant-wide SCADA, multi-server, archives | Stand-alone machine panels, mid-size lines | Plant-wide SCADA in TIA Portal project | Continuous process / pharma / power |
For an S7-300 fleet of three CPUs with software redundancy and ≈385 process signals, the practical candidates are WinCC V7.x and WinCC Professional (TIA Portal). WinCC V7.x remains the canonical Siemens SCADA for server-client architectures with a redundant server pair; WinCC Professional is the modern replacement when the engineering workflow must remain inside a single TIA Portal project.
3. WinCC V7.x — Server-Client Architecture for S7-300
SIMATIC WinCC V7.x is the classic SCADA that runs natively on Windows Server, supports the largest tag counts, and provides the deepest set of add-ons. It is engineered for projects that need a redundant server pair, several operator clients, a long-term archive (SQL Server backed), and remote access via Web Navigator.
3.1 Logical components
- WinCC Server: data manager, archive manager, alarm logging, user administrator; connects to the AS via S7-REDCONNECT for redundant pairs.
- WinCC Client: read-only operator station that subscribes to the server via TCP/UDP (default port 0x0102 / 258). It can be configured with read-only or read/write privileges.
- WinCC Web Navigator Server / Client: serves screens over IIS for browser-based operation.
- WinCC Connectivity Pack / OPC UA Server: publishes WinCC tags to higher-level MES / ERP systems.
3.2 S7-REDCONNECT channel
The connection to three CPU 315-2 DP controllers in software redundancy uses the S7-REDCONNECT channel unit. Each redundant pair is represented by one logical connection (two physical S7 connections, one primary, one standby). On a server fault, the standby server takes over within a configurable switchover time, typically 1–5 seconds.
Channel: SIMATIC S7-1200/1500 (or S7-REDCONNECT)
Connection name: AS_UNIT1_RED
Partner IP (primary) : 192.168.10.11 rack 0 slot 2
Partner IP (standby) : 192.168.10.12 rack 0 slot 2
Switchover time : 3000 ms
Connection mode : SOFTRED (S7-300 SW redundancy)
4. WinCC in the TIA Portal — Advanced vs Professional
The TIA Portal bundles the HMI configuration in two distinct products:
| Property | WinCC Advanced | WinCC Professional |
|---|---|---|
| Runtime target | Comfort Panels, RT Advanced on PC (max 3,200 power-tags) | RT Professional on PC (max ~16k tags / 64k archive values) |
| Server-client model | Single station; Sm@rtServer access | Native client-server with optional redundancy |
| Redundant AS integration | Limited (single partner) | Yes, supports S7-300/400 SW redundancy channel |
| Archive back-end | SQLite / file-based (small) | Microsoft SQL Server (segmentable) |
| Licensing | RT Advanced 128 / 512 / 2048 / 4096 / 8192 power-tags | RT Professional 512 / 2k / 4k / 8k / 16k tags |
| Typical use | Single machine, small line | Multi-station plant SCADA inside TIA Portal |
For three operator workstations plus a server, the correct TIA Portal choice is WinCC Professional. WinCC Advanced is a single-station runtime and cannot natively implement the required client-server topology, although each client can be a "WinCC Runtime Advanced with Sm@rtServer access". For ≈385 process signals the licensing threshold (Professional 512 power-tags) is more than adequate.
5. Why PCS 7 Is Not Selected
SIMATIC PCS 7 is a process-control system (DCS) that tightly integrates the engineering of automation, HMI, alarm, and batch/recipe functions with the AS 410 / S7-400 / S7-400H controllers. It requires CFC (Continuous Function Chart) and SFC (Sequential Function Chart) engineering and licenses the OS-Server / OS-Client runtime pair.
Keep PCS 7 in the matrix as a candidate only when the user is prepared to upgrade the controller layer to S7-400H or AS 410. Otherwise the SCADA choice is constrained to WinCC V7.x or WinCC Professional.
6. Tag and I/O Sizing for 385 Process Signals
| Signal type | Count | Internal/external tag ratio | Derived internal tags (1:1.2) | Derived internal tags (1:1.5, with structure) |
|---|---|---|---|---|
| DI (300) | 300 | 1:1 | 300 | 300 |
| AI (25) | 25 | 1:2 (raw + scaled + EU) | 50 | 75 |
| DO (50) | 50 | 1:1.1 (cmd + feedback) | 55 | 75 |
| AO (10) | 10 | 1:2.5 (cmd + scaled + feedback) | 25 | 25 |
| Derived tags (motors, valves, PID faceplates) | ~50 faceplates | 1:8 per faceplate | 400 | 400 |
| Totals | 385 I/O | — | ~830 internal | ~875 internal |
Even with the standard Siemens faceplate-template expansion (≈8 internal tags per motor or valve faceplate), the project stays well below the 512-power-tag licensing threshold of WinCC Professional 512. Conclusion: the 512-tag license is the minimum cost-efficient option; WinCC Professional 2048 covers any future expansion up to ≈1,500 I/O without re-licensing.
7. Operating-System Requirements
For a redundant WinCC V7.x server pair the canonical operating system is Windows Server. Always verify the specific combination against the Siemens compatibility tool (Kompatool) before commissioning.
| Runtime role | WinCC V7.x | WinCC Professional (TIA Portal) |
|---|---|---|
| Redundant server | Windows Server 2012 R2 / 2016 / 2019 (64-bit, Standard or Datacenter edition) | Windows Server 2012 R2 / 2016 / 2019 (64-bit, Standard or Datacenter) |
| Operator client | Windows 10 Pro / Enterprise (64-bit) or Windows Server with desktop experience | Windows 10 Pro / Enterprise (64-bit) or Windows Server |
| Archive back-end | Microsoft SQL Server 2014 / 2016 / 2017 / 2019 (version must match WinCC release) | Microsoft SQL Server 2014 / 2016 / 2017 / 2019 |
| Domain | Active Directory recommended for SIMATIC Logon | Active Directory recommended for SIMATIC Logon |
SQL Server is the back-end for the alarm, tag, and long-term archives. The SQL Server instance must be reachable from both redundant WinCC servers in the cluster; configure the client network protocol in SQL Server Configuration Manager as documented in Microsoft SQL Server client network configuration.
8. Network Topology
The reference plant topology consists of three Ethernet subnets stitched through Industrial Ethernet switches and a server backbone:
[AS Unit 1] CPU 315-2 DP PN 192.168.10.11/24
[AS Unit 1] CPU 315-2 DP PN 192.168.10.12/24 (redundant partner)
[AS Unit 2] CPU 315-2 DP PN 192.168.20.11/24
[AS Unit 2] CPU 315-2 DP PN 192.168.20.12/24
[AS Unit 3] CPU 315-2 DP PN 192.168.30.11/24
[AS Unit 3] CPU 315-2 DP PN 192.168.30.12/24
│
┌────────┴────────┐
│ IE Switch (managed) │
└────────┬────────┘
│ Server VLAN 192.168.100.0/24
[WinCC Server A] 192.168.100.11
[WinCC Server B] 192.168.100.12 (redundant)
[Client WS-1] 192.168.100.21
[Client WS-2] 192.168.100.22
[Client WS-3] 192.168.100.23
[SQL Server] 192.168.100.30
8.1 Recommended separation
- AS-VLAN (192.168.10/16) carries PROFINET or Industrial Ethernet to the controllers; segment with a Layer-2 managed switch (SCALANCE XB/XC/XR or comparable).
- Server-VLAN (192.168.100.0/24) carries WinCC and SQL traffic; isolate from the AS-VLAN by routing only the S7-REDCONNECT channel addresses through a firewall rule.
- Time synchronization via NTP from a single source (S7-300 has an integrated NTP client from firmware V3.3) to keep the redundant pair synchronized.
9. Software Redundancy on CPU 315-2 DP
Three CPU 315-2 DP controllers in software redundancy implement the redundancy at the application level (FB PROGRAM, FB SEND, FB RECV library). The HMI layer communicates through the S7-REDCONNECT channel unit that hides the partner switchover from the SCADA.
9.1 Library blocks required
- FB 101 "PROGRAM" — wraps the user OB 1 / OB 35 cyclic program.
- FB 102 "SEND" — copies the redundancy-relevant data areas to the partner.
- FB 103 "RECV" — accepts mirrored data from the partner.
- FB 104 "SWR_AG" — diagnostics block, exposes redundancy status to the HMI.
9.2 HMI tag exposure
The faceplate of every motor and valve exposes at least the redundancy-relevant diagnostic tags:
| Tag name (WinCC) | DB address | Meaning |
|---|---|---|
| AS1_STATE | DB100.DBW0 | 0=standby, 1=primary, 2=fault |
| AS1_PARTNER_STATE | DB100.DBW2 | Mirror of partner |
| AS1_LAST_SWITCHOVER | DB100.DBD4 | Timestamp of last switchover (DATE_AND_TIME) |
| AS1_LINK_STATUS | DB100.DBX8.0 | TRUE = link to partner OK |
10. Modbus RTU Integration
The CPU 315-2 DP exposes an RS-485 port (X27) that is used as a Modbus RTU master polling slave devices such as weigh scales, energy meters, or VFDs. Two distinct physical RS-485 trunks (redundant) are typical:
- Trunk A (CPU 315-2 DP #A primary): function code 03/06/16 polling slaves 1..32 at 19200 bps, 8E1.
- Trunk B (CPU 315-2 DP #B standby): identical poll list; only the active CPU drives the bus, the standby listens.
10.1 Modbus master library (example)
Siemens supplies the "Modbus Master" library for S7-300/400 in the form of the ModbusPN / MODB_341 / MODB_TCP function blocks. For pure RTU on the onboard PtP port, the blocks are FB 7 "MB_MASTER" / FB 8 "MB_SLAVE" (legacy) or FB 108/109 from the modern "MODBUS PN" package. Sample call in STL:
CALL FB 108, DB108
REQ := M 100.0
LADDR := 304 // PtP port base address
MODE := B#16#1 // RTU master
DATA_PTR := P#DB120.DBX0 BYTE 200
DONE := M 200.0
ERROR := M 200.1
STATUS := MW 202
10.2 HMI-side polling
The polled values land in DB 120 (e.g., slave 1 register 40001–40032). The WinCC tags read the DB through the S7-REDCONNECT channel; no separate Modbus-to-WinCC gateway is needed because the CPU already aggregates the data into its own DB.
11. Commissioning Step-by-Step
- Verify the compatibility tool. Confirm the WinCC V7.x SP version against the SQL Server release, Windows Server build, and S7-300 CPU firmware at Siemens compatibility tool.
- Install Windows Server on the two server nodes, join the domain, configure static IPv4 addresses, and apply all critical updates. Enable the SNMP service for SCALANCE diagnostics.
- Install SQL Server with mixed-mode authentication. Open SQL Server Configuration Manager and enable the TCP/IP protocol on port 1433. Confirm the protocol with Microsoft SQL Server client network configuration guidance.
- Install WinCC V7.x Server on both server nodes. License with the WinCC Redundancy option and the appropriate power-tag count.
-
Configure the S7-REDCONNECT channel for the three CPU 315-2 DP pairs. Verify partner reachability with
pingandSIMATIC Manager → Accessible Nodes. - Configure the server project: tag management, alarm logging, tag logging (fast and slow archives), user administrator (SIMATIC Logon).
- Activate redundancy in WinCC Explorer → Server → Redundancy. Set the partner server, switchover time (default 3000 ms), and verify with the redundancy diagnostic screen.
- Install WinCC Client on the three operator workstations. Configure the preferred server (auto-failover enabled). Distribute the user roles per area.
- Validate Modbus RTU on the CPU 315-2 DP pair: loopback test on a single slave, then progressive multi-slave test, then a forced master switchover to confirm the standby CPU continues polling without interruption.
- Perform a network switchover test: disconnect the primary server's Ethernet to confirm the secondary takes over and the operator clients reconnect within the configured switchover window.
- Document the architecture in the project quality folder: server pair IPs, AS pair IPs, VLAN IDs, license file paths, redundancy passwords (DP master system), and SQL maintenance plan.
12. Verification Checklist
| Check | Expected result | Method |
|---|---|---|
| Server A ↔ Server B | Redundancy state = OK, partner reachable | WinCC Redundancy diagnostic screen |
| AS unit 1 — primary link | Established, status 0x0004 (RUN) | WinCC channel diagnosis |
| AS unit 1 — standby link | Established, status 0x0004 (RUN) | WinCC channel diagnosis |
| Operator client WS-1 | Connected to preferred server, all process values update ≤ 1 s | Visual check + trace |
| Alarm simulation | Alarm appears on all three clients within 1 s | Forced tag in AS |
| Modbus RTU polling | Cycle time ≤ 500 ms on slave 1, no CRC errors | Port monitor + FB 108 STATUS |
| Archive write | SQL Server records written, no missing segments | SQL query on dbo.MS_Archive |
| Forced switchover | Operators see ≤ 3 s interruption, no archive gap | Pull primary server Ethernet |
13. Troubleshooting Matrix
| Symptom | Likely root cause | Corrective action |
|---|---|---|
| Operator clients show "No connection to server" after server reboot | WinCC service not yet started; client retries immediately | Set client timeout ≥ 30 s; verify WinCC.exe service started before user login |
| Redundancy state = "Partner not reachable" | UDP broadcast blocked by switch VLAN filter | Allow UDP 0x0102 between server VLAN; disable IGMP snooping on the server VLAN |
| Server cannot login to SQL back-end | SQL Server using Windows-only auth, S7 account not in sysadmin | Switch to mixed-mode or grant NTFS rights per the SQL client-network config guide |
| AI values stuck at 0 after partner switchover | Redundant DB not mirrored through FB SEND/RECV | Verify FB 101/102/103 pair called in OB 35; extend SEND area to cover AI DB |
| Modbus RTU CRC errors | Termination missing, double termination, or wrong bias | Add 120 Ω termination at both ends, 680 Ω bias to +5 V / GND at one end only |
| WinCC TIA Portal cannot connect to S7-300 SW redundancy | WinCC Advanced / older SP used | Upgrade to WinCC Professional ≥ V16 SP2 and use the "S7-300/400 SW redundancy" channel unit |
| Compatibility tool rejects the OS combination | Mixing unsupported SQL Server build with WinCC SP | Adopt the exact matrix version recommended by Siemens (Kompatool) |
14. Frequently Asked Questions
Which WinCC is the right choice for three CPU 315-2 DP controllers with software redundancy?
Use WinCC V7.x with the Redundancy option or WinCC Professional (TIA Portal) ≥ V16 SP2. Both expose the S7-REDCONNECT channel and accept the S7-300 software-redundant partner pair. WinCC Advanced cannot host a server-client architecture.
Can PCS 7 be used with S7-300 controllers?
No. PCS 7 is engineered exclusively for S7-400 / S7-400H / AS 410 automation stations. Installing PCS 7 against a CPU 315-2 DP will fail during AS-OS compilation and is not a supported configuration.
Does the WinCC server need Windows Server 2008 specifically?
The historical guidance was Windows Server 2008, but current WinCC V7.x releases support Windows Server 2012 R2 / 2016 / 2019. Always validate the exact SP combination against the Siemens compatibility tool before commissioning.
How do the operator clients authenticate to the server?
Configure SIMATIC Logon against the Windows Active Directory and assign each user to a role (operator, supervisor, engineer). The WinCC client reads the role on connect and applies the permission set per area. Local accounts are possible but not recommended in regulated plants.
How is the Modbus RTU link kept alive across a CPU switchover?
Only the active CPU drives the RS-485 bus; the standby listens. The SEND/RECV redundancy blocks mirror the polled register area (DB 120) to the standby, so the HMI never sees a discontinuity even when the standby takes over the master role. Use FB 108 "MODBUS_PN" or FB 7 "MB_MASTER" plus a 120 Ω termination and a single 680 Ω bias to keep CRC errors at zero.