indicates that death or severe personal injury will result if proper precautions are not taken.
WARNING
indicates that death or severe personal injury may result if proper precautions are not taken.
CAUTION
indicates that minor personal injury can result if proper precautions are not taken.
NOTICE
indicates that property damage can result if proper precautions are not taken.
Qualified Personnel
personnel qualified
Proper use of Siemens products
WARNING
Siemens products may only be used for the applications described in the catalog and in the relevant technical
ambient conditions must be complied with. The information in the relevant documentation must be observed.
Trademarks
Disclaimer of Liability
This manual contains notices you have to observe in order to ensure your personal safety, as well as to prevent
damage to property. The notices referring to your personal safety are highlighted in the manual by a safety alert
symbol, notices referring only to property damage have no safety alert symbol. These notices shown below are
graded according to the degree of danger.
If more than one degree of danger is present, the warning notice representing the highest degree of danger will
be used. A notice warning of injury to persons with a safety alert symbol may also include a warning relating to
property damage.
The product/system described in this documentation may be operated only by
task in accordance with the relevant documentation, in particular its warning notices and safety instructions.
Qualified personnel are those who, based on their training and experience, are capable of identifying risks and
avoiding potential hazards when working with these products/systems.
Note the following:
documentation. If products and components from other manufacturers are used, these must be recommended
or approved by Siemens. Proper transport, storage, installation, assembly, commissioning, operation and
maintenance are required to ensure that the products operate safely and without any problems. The permissible
All names identified by ® are registered trademarks of Siemens AG. The remaining trademarks in this publication
may be trademarks whose use by third parties for their own purposes could violate the rights of the owner.
We have reviewed the contents of this publication to ensure consistency with the hardware and software
described. Since variance cannot be precluded entirely, we cannot guarantee full consistency. However, the
information in this publication is reviewed regularly and any necessary corrections are included in subsequent
editions.
for the specific
05/2016 Subject to change
Preface
Purpose of the Operating Instructions
Validity of the Operating Instructions
Names of the devices in these operating instructions
Classification
Description
Product line (X-300)
Product group
For all devices and variants of a product group, only the product group is used.
Device
For a device, only the device name is used.
Variant
name.
These Operating Instructions describe the design and functions of the compact and modular
Industrial Ethernet Switches of the SCALANCE X-300 product line and support you during
installation, commissioning, and troubleshooting on site.
These Operating Instructions are valid for the following product groups of the SCALANCE X300 product line, see also section Product overview (Page 27).
● X-300
● X-300M
● XR-300M
● X-300EEC
● XR-300M EEC
● X-300M PoE
● XR-300M PoE
● MM900 media modules
● SFP transceiver
Within the SCALANCE X-300 product line, there are product groups, devices and variants.
For all devices and variants of all product groups within the SCALANCE X-300 product
line, the term "IE Switch X-300" is used.
A variant of a device represents a particular design version. They are identified by a
separate order number.
When all variants of a device are meant in the text, "(all)" is often added after the device
If you have questions on the use of SIMATIC NET products, please contact your Siemens
sales partner.
The devices of the SCALANCE X-300 product line meet the requirements for the CE mark.
For more detailed information, refer to section Approvals, certificates, standards (Page 223).
The current GSDML file must be used for integration in STEP 7 V5.4 SP5 projects. This
applies to all products covered by these operating instructions.
)
)
You can obtain the relevant GSD file from the Internet at:
Siemens provides products and solutions with industrial security functions that support the
secure operation of plants, solutions, machines, equipment and/or networks. They are
important components in a holistic industrial security concept. With this in mind, Siemens’
products and solutions undergo continuous development. Siemens recommends strongly
that you regularly check for product updates.
For the secure operation of Siemens products and solutions, it is necessary to take suitable
preventive action (e.g. cell protection concept) and integrate each component into a holistic,
state-of-the-art industrial security concept. Third-party products that may be in use should
also be considered. For more information about industrial security, visit
http://www.siemens.com/industrialsecurity.
To stay informed about product updates as they occur, sign up for a product-specific
newsletter. For more information, visit http://support.automation.siemens.com.
A Appendix ............................................................................................................................................. 311
9.5 XR-300M EEC product group .............................................................................................. 249
Safety extra low voltage (only devices with 24 VDC power supply)
WARNING
For use in an environment with pollution level 2
The following safety notices must be adhered to when setting up and operating the device
and during all associated work such as installation, connecting up, replacing or opening the
device.
DO NOT OPEN WHEN ENERGIZED.
The equipment is designed for operation with Safety Extra-Low Voltage (SELV) by a
Limited Power Source (LPS).
This means that only SELV / LPS (Limited Power Source) complying with IEC 60950-1 / EN
60950-1 / VDE 0805-1 must be connected to the power supply terminals. The power supply
unit for the equipment power supply must comply with NEC Class 2, as described by the
National Electrical Code (r) (ANSI / NFPA 70).
If the equipment is connected to a redundant power supply (two separate power supplies),
both must meet these requirements.
A power source that supplies safety extra low voltage combined with a following NEC Class
2 power limiter also meets the requirements according to IEC 60950-1 / EN 60950-1 / VDE
0805-1 or NEC Class 2. A suitable power limiter is for example the redundancy module
SITOP PSE202U NEC Class 2 (article number 6EP1962-2BA00).
Safety notice for connectors with LAN (Local Area Network) marking
General notices about use in hazardous areas
WARNING
Risk of explosion when connecting or disconnecting the device
WARNING
Replacing components
WARNING
Requirements for the cabinet/enclosure
WARNING
Opening the device
1.1 Important notes on using the device
A LAN or LAN segment, with all its associated interconnected equipment, shall be entirely
contained within a single low-voltage power distribution and within a single building. The
LAN is considered to be in an "environment A" according to IEEE802.3 or "environment 0"
according to IEC TR 62102, respectively. Never connect directly to TNV-circuits (Telephone
Network) or WAN (Wide Area Network).
EXPLOSION HAZARD
DO NOT CONNECT OR DISCONNECT EQUIPMENT WHEN A FLAMMABLE OR
COMBUSTIBLE ATMOSPHERE IS PRESENT.
EXPLOSION HAZARD
SUBSTITUTION OF COMPONENTS MAY IMPAIR SUITABILITY FOR CLASS I, DIVISION
2 OR ZONE 2.
When used in hazardous environments corresponding to Class I, Division 2 or Class I,
Zone 2, the device must be installed in a cabinet or a suitable enclosure.
DO NOT OPEN WHEN ENERGIZED.
SCALANCE X-300
16Operating Instructions, 05/2016, A5E01113043-20
Safety instructions
Safety notices on use in hazardous areas according to ATEX and IECEx
WARNING
Requirements for the cabinet/enclosure
WARNING
Suitable cables for temperatures in excess of 70 °C
WARNING
Protection against transient voltage surges
1.2
PELV
Note
Safety extra-low voltage
The supply of the devices by PELV (Protective Extra Low Voltage) according to DIN VDE
0100
exceed the voltage limits 25 VAC or 60 VDC.
1.2 PELV
To comply with EC Directive 94/9 (ATEX95) or the conditions of IECEx, this enclosure must
meet the requirements of at least IP54 in compliance with EN 60529.
The fiber-optic bus connections labeled SCALANCE MM900 (see type plate) may also be
led through a hazardous area zone1 (see also Auto-Hotspot, section "Explosion Protection
Directive (ATEX)").
If the cable or conduit entry point exceeds 70°C or the branching point of conductors
exceeds 80°C, special precautions must be taken.
If the equipment is operated in an air ambient in excess of 50 °C, only use cables with
admitted maximum operating temperature of at least 80 °C.
Provisions shall be made to prevent the rated voltage from being exceeded by transient
voltage surges of more than 40%. This criterion is fulfilled, if supplies are derived from
SELV (Safety Extra-Low Voltage) only.
-410 or IEC 60364-4-41 is permitted when the generated nominal voltage does not
Important notes on using the device in hazardous areas
WARNING
WARNING - EXPLOSION HAZARD -
WARNING
Restricted area of application
WARNING
Restricted area of application
Note on devices with power supply 100 to 240 V AC
WARNING
Danger from line voltage
WARNING
Devices with a 100 to 240 V AC power supply do not have an ATEX or IECEx approval.
NOTICE
Securing cables with dangerous voltage
1.3 Important notes on using the device in hazardous areas
DO NOT DISCONNECT WHILE CIRCUIT IS LIVE UNLESS AREA IS KNOWN TO BE
NON-HAZARDOUS.
This equipment is suitable for use in Class I, Division 2, Groups A, B, C and D or nonhazardous locations only.
This equipment is suitable for use in Class I, Zone 2, Group IIC or non-hazardous locations
only.
The supply voltage for the devices listed is 100 to 240 VAC.
This device can only function correctly and safely if it is transported, stored, set up, and
installed correctly, and operated and maintained as recommended.
Connecting and disconnecting may only be performed by an electrical specialist.
Connect or disconnect power supply cables only when the power is turned off.
Devices with a 100 to 240 V AC power supply are not approved for use in hazardous areas
according to EC-RL-94/9 ATEX or IECEx.
Make sure that the connector cannot be released accidentally by pulling on the connecting
cable. Lay the cables in cable ducts or cable channels and secure the cables, where
necessary, with cable ties.
SCALANCE X-300
18Operating Instructions, 05/2016, A5E01113043-20
Safety instructions
Safety requirements for installation
1.4
Security recommendations
General
Physical access
1.4 Security recommendations
According to the IEC 61131-2 standard and therefore in accordance with the EU directive
2006/95/EC (Low Voltage Directive), the devices are "open equipment" and in accordance
with UL/CSA certification, they are an "open type".
To fulfill requirements for safe operation with regard to mechanical stability, flame
retardation, stability, and shock-hazard protection, the following alternative types of
installation are specified:
● Installation in a suitable cabinet.
● Installation in a suitable enclosure.
● Installation in a suitably equipped, enclosed control room.
To prevent unauthorized access, note the following security recommendations.
● You should make regular checks to make sure that the device meets these
recommendations and/or other security guidelines.
● Evaluate your plant as a whole in terms of security. Use a cell protection concept with
suitable products.
● When confidential zones are used, the internal and external network are disconnected, an
attacker cannot access the data from the outside.
● Operate the device only within a protected network area.
● Use VPN to encrypt and authenticate communication from and to the devices.
● For data transmission via a non-secure network use an encrypted VPN tunnel (IPsec).
● For operation of the device in a non-secure infrastructure no product liability will be
accepted.
● Separate connections correctly (WBM. Telnet, SSH etc.).
● Limit physical access to the device to qualified personnel.
The memory card or the C-PLUG contains sensitive data such as certificates, keys etc.
that can be read out and modified.
● Lock unused physical ports on the device. Unused ports can be used to gain forbidden
access to the plant.
● Keep the software up to date. Check regularly for security updates of the product.
You will find information on this on the Internet pages "Industrial Security"
● Inform yourself regularly about security advisories and bulletins published by Siemens
productCERT.
● Only activate protocols that you really require to use the device.
● Restrict access to the device with a firewall or rules in an access control list (ACL -
Access Control List).
● Restrict access to the management of the device with rules in an access control list
(ACL).
● The option of VLAN structuring provides good protection against DoS attacks and
unauthorized access. Check whether this is practical or useful in your environment.
● Enable logging functions. Use the central logging function to log changes and access
attempts centrally. Check the logging information regularly.
● Configure a Syslog server to forward all logs to a central location.
● Define rules for the use of devices and assignment of passwords.
● Regularly update passwords and keys to increase security.
● Change all default passwords for users before you operate the device.
● Only use passwords with a high password strength. Avoid weak passwords for example
● Make sure that all passwords are protected and inaccessible to unauthorized personnel.
● Do not use the same password for different users and systems or after it has expired.
This section deals with the security keys and certificates you require to set up SSL.
● We strongly recommend that you create your own SSL certificates and make them
password1, 123456789, abcdefgh.
available.
There are preset certificates and keys on the device. The preset and automatically
created SSL certificates are self-signed. We recommend that you use SSL certificates
signed either by a reliable external or by an internal certification authority.
The device has an interface via which you can import the certificates and keys.
● Use the certification authority including key revocation and management to sign the
certificates.
SCALANCE X-300
20Operating Instructions, 05/2016, A5E01113043-20
Safety instructions
Secure/non-secure protocols
1.4 Security recommendations
● Handle user-defined private keys with great caution if you use user-defined SSH or SSL
keys.
● Verify certificates and fingerprints on the server and client to avoid "man in the middle"
attacks.
● We recommend that you use certificates with a key length of 2048 bits.
● Change keys and certificates immediately, if there is a suspicion of compromise.
● Avoid or disable non-secure protocols, for example Telnet and TFTP. For historical
reasons, these protocols are still available, however not intended for secure applications.
Use non-secure protocols on the device with caution.
● Avoid or disable non-secure protocols. Check whether use of the following protocols is
necessary:
– PNIO
– Broadcast pings
– Non authenticated and unencrypted interfaces
– ICMP (redirect)
– MRP, HRP
– GMRP and IGMP
– LLDP
– Syslog
– RADIUS
– DHCP Options 66/67
– TFTP
– GMRP and GVRP
– Multicast routing
● The following protocols provide secure alternatives:
– SNMPv1/v2 → SNMPv3
Check whether use of SNMPv1 is necessary. SNMPv1 is classified as non-secure.
Use the option of preventing write access. The product provides you with suitable
setting options.
If SNMP is enabled, change the community names. If no unrestricted access is
necessary, restrict access with SNMP.
Ethernet switches forward data packets directly from the input port to the appropriate output
port during data exchange based on the address information. Ethernet switches operate on a
direct delivery basis.
Essentially, switches have the following functions:
● Connecting collision domains / subnets
Since repeaters and star couplers (hubs) operate at the physical level, their use is
restricted to the span of a collision domain. Switches connect collision domains. Their use
is therefore not restricted to the maximum span of a repeater network. On the contrary,
extremely large networks with very large spans are possible with switches. The distances
achieved depend on the fiber-optic interfaces used in the devices and the FO fibers used
(see technical specifications).
● Load containment
By filtering the data traffic based on the Ethernet (MAC) addresses, local data traffic
remains local. In contrast to repeaters or hubs, which distribute data unfiltered to all ports
/ network nodes, switches operate selectively. Only data intended for nodes in other
subnets is switched from the input port to the appropriate output port of the switch. To
make this possible, a table assigning Ethernet (MAC) addresses to output ports is
created by the switch in a "teach-in" mode.
● Limiting the propagation of errors to the subnet involved.
By checking the validity of a data packet on the basis of the checksum which each data
packet contains, the switch ensures that bad data packets are not transported further.
Collisions in one network segment are not passed on to other segments.
With over 95% of LANs based on Ethernet, this is the most commonly used technology. The
use of switches is particularly important: They allow extensive networks with large numbers
of nodes to be set up, increase the data throughput, and simplify network expansion.
The IE Switches X-300 from SIMATIC NET are designed for use in high-speed plant
networks that will also meet future requirements. With the HRP redundancy function and
standby linking of rings, high network availability can be achieved. HRP and standby link
reconfigures the network within 300 ms. Support of IT standards such as VLAN, RSTP,
IGMP, and GARP makes seamless integration of automation networks in existing office
networks possible.
The IE Switches X-300 are designed for use in switching cubicles and cabinets.
The IE Switches X-300 simplify the expansion of a network regardless of the network
topology.
You can use an IE Switch X-300 in the following network topologies:
● Linear structure
● Star/tree structure
● Ring with redundancy manager
The maximum cable length is 70 km for single mode gigabit transmission. A mixed topology
consisting of IE Switch X-300 devices and OSMs/ESMs is possible at the electrical ports. A
mixed topology consisting of IE Switch X-300 devices and an OSM via the optical ports is not
possible.
Using an IE Switch X-300 as the redundancy manager in a ring with redundancy manager
provides greater availability. If there is an interruption on the connection between these
switches, the IE Switch X-300 used as redundancy manager acts like a switch and in a very
short time creates a line from the ring. As a result, a functional, end-to-end structure is
restored. For information on this topic, refer to the Configuration Manual "SIMATIC NET Industrial Ethernet Switches SCALANCE X-300 SCALANCE X-400."
SCALANCE X-300
26Operating Instructions, 05/2016, A5E01113043-20
Introduction
2.2
Product overview
2.2.1
Type designations
Structure of the type designation
Interface
Property
FE
Electrical RJ-45 port for 10/100 Mbps.
[-]
Electrical RJ-45 port for 10/100 Mbps or 10/100/1000 Mbps.
Interface
Property
FE
SC port 100 Mbps multimode FO cable (up to max. 5 km).
LD FE
SC port 100 Mbps single mode FO cable (up to max. 26 km).
[-]
SC port 1000 Mbps multimode FO cable (up to max. 750 m).
LD
SC port 1000 Mbps single mode FO cable (up to max. 10 km).
LH+
SC port 1000 Mbps single mode FO cable (up to max. 70 km).
2.2 Product overview
The type designation of an IE Switch X-300 is made up of several parts that have the
following meaning:
Interfaces of devices without optical ports:
Interfaces of devices with optical ports:
LH SC port 1000 Mbps single mode FO cable (up to max. 40 km).
If information applies to all devices, the term "IE Switches X-300" is used. If information
applies to only a particular product group, the relevant names will be used without extra
information on the type or number of interfaces. Examples: "X-300" stands for non-modular
devices with a compact housing, "XR-300" means all rack devices, "X-300M" means all
modular devices etc.
-3LD FE deviates from the type designation in that it has an SC port
-optic cable up to a maximum of 5 km in length and two SC ports for
-optic cable up to a maximum of 26 km in length.
Port 21: Multimode
Port 22: LD (long distance, single mode)
Port 23: LD (long distance, single mode)
The IE switches of the SCALANCE X-300 product line can have the following designs and
variants:
Table 2- 1
Modular devices (M) are intended to accommodate media modules.
• Partially modular devices: Some of the ports (slots) are intended to accommodate media modules.
Example: X308-2M
• Fully modular devices: All ports (slots) are intended to accommodate media modules.
SCALANCE X-300
28Operating Instructions, 05/2016, A5E01113043-20
Introduction
2.2.3
X-300 product group
Device
Properties
Order number
X304-2FE
to max. 750 m
X306-1LD FE
X307-3
to max. 750 m
X307-3LD
up to max. 10 km
X308-2
to max. 750 m
2.2 Product overview
Image 2-1 Designs of the X-300 IE switches, example of plugging media modules into the media module slots
of the XR324-12M
7 x 10/100 Mbps RJ-45 ports electrical
1 x 10/100/1000 Mbps, RJ-45 ports electrical
4 x 10/100 Mbps RJ-45 ports electrical
2 x 1000 Mbps, SC ports optical, for glass FO cable (multimode), up
6 x 10/100 Mbps RJ-45 ports electrical
1 x 100 Mbps, SC port optical, for glass FO cable (single mode), up
to max. 26 km
3 x 1000 Mbps, SC ports optical, for glass FO cable (multimode), up
7 x 10/100 Mbps RJ-45 ports electrical
3 x 1000 Mbps, SC ports optical, for glass FO cable (single mode),
7 x 10/100 Mbps RJ-45 ports electrical
2 x 1000 Mbps, SC ports optical, for glass FO cable (multimode), up