indicates that death or severe personal injury will result if proper precautions are not taken.
WARNING
indicates that death or severe personal injury may result if proper precautions are not taken.
CAUTION
indicates that minor personal injury can result if proper precautions are not taken.
NOTICE
indicates that property damage can result if proper precautions are not taken.
Qualified Personnel
personnel qualified
Proper use of Siemens products
WARNING
Siemens products may only be used for the applications described in the catalog and in the relevant technical
maintenance are required to ensure that the products operate safely and without any problems. The permissible
ambient conditions must be complied with. The information in the relevant documentation must be observed.
Trademarks
Disclaimer of Liability
This manual contains notices you have to observe in order to ensure your personal safety, as well as to prevent
damage to property. The notices referring to your personal safety are highlighted in the manual by a safety alert
symbol, notices referring only to property damage have no safety alert symbol. These notices shown below are
graded according to the degree of danger.
If more than one degree of danger is present, the warning notice representing the highest degree of danger will
be used. A notice warning of injury to persons with a safety alert symbol may also include a warning relating to
property damage.
The product/system described in this documentation may be operated only by
task in accordance with the relevant documentation, in particular its warning notices and safety instructions.
Qualified personnel are those who, based on their training and experience, are capable of identifying risks and
avoiding potential hazards when working with these products/systems.
Note the following:
documentation. If products and components from other manufacturers are used, these must be recommended
or approved by Siemens. Proper transport, storage, installation, assembly, commissioning, operation and
All names identified by ® are registered trademarks of Siemens AG. The remaining trademarks in this publication
may be trademarks whose use by third parties for their own purposes could violate the rights of the owner.
We have reviewed the contents of this publication to ensure consistency with the hardware and software
described. Since variance cannot be precluded entirely, we cannot guarantee full consistency. However, the
information in this publication is reviewed regularly and any necessary corrections are included in subsequent
editions.
for the specific
12/2016 Subject to change
Preface
Validity of this manual
CP 1243-1
This document contains information on the following telecontrol product:
●
Article number 6GK7 243-1BX30-0XE0
Hardware product version 2
Firmware version V2.1.77
The CP 1243-1 is the communications processor for connecting the SIMATIC S7-1200 to
a control center with TeleControl Server Basic (V3) via the public infrastructure (e.g.
DSL).
With the help of VPN technology and the firewall, the CP allows protected access to the
S7-1200.
The CP can also be used as an additional interface of the CPU for S7 communication.
Behind the top hinged cover of the module housing, you will see the hardware product
version to the right of the article number printed as a placeholder "X". If the printed text is, for
example, "X 2 3 4", "X" would be the placeholder for hardware product version 1.
You will find the firmware version of the CP as supplied behind the top hinged cover of the
housing to the left below the LED field.
You will find the MAC address under the lower hinged cover of the housing.
● CP
The term "CP" is used below instead of the full product name CP 1243-1.
●
This abbreviation ill be used below for the "TeleControl Server Basic", version V3.
●
This short form will be used below for the STEP 7 Basic / Professional configuration tool.
●
PC with the STEP 7 project
This manual describes the properties of this module and supports you when installing and
commissioning it.
The required configuration steps are described as an overview and there are explanations of
the relationship between firmware functions and configuration.
You will also find information about the diagnostics options of the device.
● New functions in the firmware version named above:
– Changed behavior during time-of-day synchronization, see section Time-of-day
– Changed selection of supported data types, see section Datapoint types (Page 71).
– Changing the IP address during runtime, see section Address and authentication data
– Support of S7 routing
● Functional improvement of data point configuration as of STEP 7 V13 + SP1. see section
Configuring data points and messages (Page 65).
To install, commission and operate the CP, you require experience in the following areas:
● Automation engineering
● Setting up the SIMATIC S7-1200
● SIMATIC STEP 7 Basic / Professional
In this manual there are often cross references to other sections.
To be able to return to the initial page after jumping to a cross reference, some PDF readers
support the command <Alt>+<Left arrow>.
You will find an overview of further reading and references in the Appendix of this manual.
You will find license conditions in the following document on the supplied data medium:
● OSS-CP1243-1_86.pdf
The firmware is signed and encrypted. This ensures that only firmware created by Siemens
can be downloaded to the device.
e
Siemens provides products and solutions with industrial security functions that support the
secure operation of plants, systems, machines and networks.
In order to protect plants, systems, machines and networks against cyber threats, it is
necessary to implement – and continuously maintain – a holistic, state-of-the-art industrial
security concept. Siemens’ products and solutions only form one element of such a concept.
Customer is responsible to prevent unauthorized access to its plants, systems, machines
and networks. Systems, machines and components should only be connected to the
enterprise network or the internet if and to the extent necessary and with appropriate security
measures (e.g. use of firewalls and network segmentation) in place.
Additionally, Siemens’ guidance on appropriate security measures should be taken into
account. For more information about industrial security, please visit
Link: (http://www.siemens.com/industrialsecurity)
Siemens’ products and solutions undergo continuous development to make them more
secure. Siemens strongly recommends to apply product updates as soon as available and to
always use the latest product versions. Use of product versions that are no longer supported,
and failure to apply latest updates may increase customer’s exposure to cyber threats.
To stay informed about product updates, subscribe to the Siemens Industrial Security RSS
Feed under
Link: (http://www.siemens.com/industrialsecurity).
Explanations of many of the specialist terms used in this documentation can be found in the
SIMATIC NET glossary.
You will find the SIMATIC NET glossary on the Internet at the following address:
You will find information on Training, Service & Support in the multi--language document
"DC_support_99.pdf" on the data medium supplied with the documentation.
The product is low in pollutants, can be recycled and meets the requirements of the WEEE
directive 2012/19/EU "Waste Electrical and Electronic Equipment".
Do not dispose of the product at public disposal sites. For environmentally friendly recycling
and the disposal of your old device contact a certified disposal company for electronic scrap
or your Siemens contact.
Keep to the local regulations.
You will find information on returning the product on the Internet pages of Siemens Industry
Online Support:
Link: (https://support.industry.siemens.com/cs/ww/en/view/109479891)
6 Technical data .................................................................................................................................... 101
A Approvals ............................................................................................................................................ 103
B Dimension drawings ............................................................................................................................ 107
C Documentation references .................................................................................................................. 109
S7 communication and PG/OP communication with the following functions:
The CP is intended for operation in an S7-1200 automation system. The CP allows
connection of the S7-1200 to Industrial Ethernet or via the Internet to a control center with
TELECONTROL SERVER BASIC (TCSB version V3).
With the combination of different security functions such as firewall and protocols for data
encryption, the CP protects the station and even entire automation cells from unauthorized
access and protects the communication between the remote S7 station and the master
station (TCSB) from espionage and manipulation.
The following communications services are supported:
●
The CP is a communications processor of the SIMATIC S7-1200 for system connection to
control centers with the OPC server application TCSB.
The communications protocol used allows IP-based data transmission for telecontrol
applications. As an integrated (unconfigurable) Security function, the telecontrol protocol
encrypts the data for transfer between the CP and telecontrol server.
For a description of the configurable Security functions, refer to the section Industrial
Ethernet Security (Page 13).
●
– PUT/GET as client and server for data exchange with remote stations (S7-
Due to the data point configuration in STEP 7, programming program blocks in order to
transfer the process data is unnecessary. The individual data points are processed oneto-one in the control system.
●
– IPv4 / IPv6
The CP supports IP addresses according to IPv4 and IPv6.
For telecontrol applications in IPv6 networks, an IPv6 address can be used in addition
to an IPv4 address.
– Address assignment
The IP address, the subnet mask and the address of a gateway can be set manually
in the configuration.
As an alternative, the IP address can be obtained from a DHCP server or by other
means outside the configuration.
●
– When telecontrol communication is enabled, the CP obtains its local time of day as
UTC time from the partner (TCSB). The time of day can be read from the CPU. The
mechanisms are described in the STEP 7 information system.
For information on the format of the time stamp, refer to the section Datapoint types
(Page 71).
– If telecontrol communication is disabled, the time of day can be obtained from an NTP
server or from the CPU.
– If the security functions are enabled, the secure method NTP (secure) can be used.
For more information, refer to the section Time-of-day synchronization (Page 50).
●
The CP can communicate with a redundant installation of TCSB.
●
The CP can store events of different classes chronologically and transfer them
spontaneously or together to the telecontrol server.
●
The telecontrol communication with TCSB is triggered in two ways:
– After a request by TCSB or an OPC client connected to TCSB
With configured events in the process image of the CPU, the CP can send messages as
e-mails. The data sent by e-mail is configured using PLC tags.
●
Analog values can be preprocessed on the CP according to various methods.
●
From the engineering station you can access the station via the CP with the online
functions of STEP 7.
The following online functions are available:
– Downloading project or program data from the STEP 7 project to the station
– Querying diagnostics data on the station
– Downloading firmware files to the CP
For information on the online functions, refer to the section Online functions and
TeleService (Page 93).
●
As an SNMP agent, the CP supports data queries using SNMP (Simple Network
Management Protocol).
For more detailed information, refer to section SNMP (Page 94).
With Industrial Ethernet Security, individual devices, automation cells or network segments
of an Ethernet network can be protected. The data transfer via the CP can be protected from
the following attacks by a combination of different security measures:
● Data espionage
● Data manipulation
● Unauthorized access
Secure underlying networks can be operated via additional Ethernet/PROFINET interfaces of
the CPU.
The security functions can be used independently of telecontrol communication.
Note
Plants with security requirements - recommendation
Use the following options:
•
•
See also section
1.4 Industrial Ethernet Security
As a result of using the CP, as a security module, the following security functions are
accessible to the S7-1200 station on the interface to the external network:
●
– IP firewall with stateful packet inspection (layer 3 and 4)
– Firewall also for "non-IP" Ethernet frames according to IEEE 802.3 (layer 2)
– Limitation of the transmission speed ("Bandwidth limitation")
– Global firewall rules
●
VPN tunnel communication allows the establishment of secure IPsec tunnels for
communication with one or more security modules.
The CP can be put together with other modules to form VPN groups during configuration.
IPsec tunnels (VPN) are created between all security modules of a VPN group. All
internal nodes of these security modules can communicate securely with each other
through these tunnels.
●
To allow monitoring, events can be stored in log files that can be read out using the
configuration tool or can be sent automatically to a Syslog server.
●
For secure transfer during time-of-day synchronization
●
For secure transmission of network analysis information safe from eavesdropping
●
The protection provided by the firewall can cover individual devices, several devices or
even entire network segments.
If you have systems with high security requirements, use the secure protocols
NTP (secure), HTTPS and SNMPv3.
If you connect to public networks, you should use the firewall. Think about the services
you want to allow access to the station via public networks. By using the "bandwidth
limitation" of the firewall, you can restrict the possibility of flooding and DoS attacks.
Security recommendations (Page 33).
For configuring the security functions refer to the section Security (Page 47).
You will find further information on the functionality and configuration of the security functions
in the information system of STEP 7 and in the manual /4/ (Page 110).
Number of data points for the data point configuration
User data
1.5 Configuration limits and performance data
In each S7-1200 station, up to three CMs/CPs can be plugged in and configured; this allows
three CP 1243-1 modules.
To use telecontrol communication, three CP 1243-1 modules can be plugged in per station
that communicate with three telecontrol servers.
●
The CP can establish corrections to non-redundant or redundant telecontrol servers
(TCSB).
In addition to this, inter-station communication with up to 4 S7 stations with a CP 1243-1
can be operated via the telecontrol server.
●
The CP can establish connections to up to 4 communications partners (S7 stations).
●
1 connection resource is reserved for online functions.
●
8 connection resources for S7 connections (PUT/GET)
●
– 1 connection resource for PG connections
– 3 connection resources for OP connections
The maximum number of configurable data points is 200.
The data to be transferred by the CP is assigned to various data points in the STEP 7
configuration.
The size of the user data per data point depends on the data type of the relevant data point.
You will find details in the section Datapoint types (Page 71).
The CP has a frame memory (send buffer) for the values of data points configured as an
event.
The send buffer has a maximum size of 64000 events divided into equal parts for all
configured communications partners. The size of the frame memory can be set in STEP 7,
refer to the section SNMP (Page 42).
Up to 10 messages can be configured in STEP 7 and sent as e-mails.
Up to 8 IPsec terminals can be established for secure communication with other security
modules.
The maximum number of firewall rules in advanced firewall mode is limited to 256.
The firewall rules are divided up as follows:
● Maximum 226 rules with individual addresses
● Maximum 30 rules with address ranges or network addresses
(e.g. 140.90.120.1 - 140.90.120.20 or 140.90.120.0/16)
● Maximum 128 rules with limitation of the transmission speed ("Bandwidth limitation")
Telecontrol with a non-redundant master station (TCSB)
Communication between S7 stations and a master station (TCSB)
1.6 Configuration examples
Figure 1-1
In the telecontrol applications of the example shown, SIMATIC S7 stations communicate with
a non-redundant telecontrol server (TCSB) in the master station.
● Telecontrol communication between stations and master station
The communication is via the following paths and communications modules:
– Communication via the Internet: S7-1200 with CP 1243-1
– Communication via the GSM network and the Internet: S7-1200 with CP 1242-7 or
The establishment of terminal connections with encryption is initiated automatically by the
telecontrol protocol used by the various communications modules.
The creation of VPN connections between the CP 1243-1 and telecontrol server is
optional.
The telecontrol server monitors the connections established by the remote stations.
● Inter-station communication
Stations of the same type, for example S7-1200 with CP 1243-1, can communicate with
each other by sending the frames via the telecontrol server.
Location of the display elements and the electrical connectors
Opening the covers of the housing
The LEDs for the detailed display of the module statuses are located behind the upper cover
of the module housing.
The Ethernet connector is located behind the lower hinged cover of the module.
Open the upper or lower cover of the housing by pulling it down or up as shown by the
arrows in the illustration. The covers extend beyond the housing to give you a grip.
Note the following safety notices when setting up and operating the device and during all
associated work such as installation, connecting up or replacing the device.
If power is supplied to the module or station over longer power cables or networks, the
coupling in of strong electromagnetic pulses onto the power supply cables is possible. This
can be caused, for example by lightning strikes or switching of higher loads.
The connector of the external power supply is not protected from strong electromagnetic
pulses. To protect it, an external overvoltage protection module is necessary. The
requirements of EN61000-4-5, surge immunity tests on power supply lines, are met only
when a suitable protective element is used. A suitable device is, for example, the Dehn
Blitzductor BVT AVD 24, article number 918 422 or a comparable protective element.
Notices on use in hazardous areas according to IECEx / ATEX
WARNING
Requirements for the cabinet/enclosure
WARNING
3.1 Important notes on using the device
The equipment is designed for operation with Safety Extra-Low Voltage (SELV) by a
Limited Power Source (LPS).
This means that only SELV / LPS complying with IEC 60950-1 / EN 60950-1 / VDE 0805-1
must be connected to the power supply terminals. The power supply unit for the equipment
power supply must comply with NEC Class 2, as described by the National Electrical Code
(r) (ANSI / NFPA 70).
If the equipment is connected to a redundant power supply (two separate power supplies),
both must meet these requirements.
DO NOT CONNECT OR DISCONNECT EQUIPMENT WHEN A FLAMMABLE OR
COMBUSTIBLE ATMOSPHERE IS PRESENT.
SUBSTITUTION OF COMPONENTS MAY IMPAIR SUITABILITY FOR CLASS I, DIVISION
2 OR ZONE 2.
When used in hazardous environments corresponding to Class I, Division 2 or Class I,
Zone 2, the device must be installed in a cabinet or a suitable enclosure.
To comply with EU Directive 94/9 (ATEX95), the enclosure or cabinet must meet the
requirements of at least IP54 in compliance with EN 60529.
If the cable or conduit entry point exceeds 70 °C or the branching point of conductors
exceeds 80 °C, special precautions must be taken. If the equipment is operated in an air
ambient in excess of 50 °C, only use cables with admitted maximum operating temperature
of at least 80 °C.
Notices regarding use in hazardous areas according to UL HazLoc
WARNING
EXPLOSION HAZARD
3.1.4
Notices on use in hazardous areas according to FM
WARNING
EXPLOSION HAZARD
WARNING
EXPLOSION HAZARD
3.1 Important notes on using the device
Take measures to prevent transient voltage surges of more than 40% of the rated voltage.
This is the case if you only operate devices with SELV (safety extra-low voltage).
DO NOT DISCONNECT WHILE CIRCUIT IS LIVE UNLESS AREA IS KNOWN TO BE
NON-HAZARDOUS.
This equipment is suitable for use in Class I, Division 2, Groups A, B, C and D or nonhazardous locations only.
This equipment is suitable for use in Class I, Zone 2, Group IIC or non-hazardous locations
only.
Do not connect or disconnect while the circuit is live or unless the area is known to be free
of ignitible concentrations.
This equipment is suitable for use in Class I, Division 2, Groups A, B, C and D or nonhazardous locations only.
This equipment is suitable for use in Class I, Zone 2, Group IIC or non-hazardous locations
only.
The equipment is intended to be installed within an ultimate enclosure. The inner service
temperature of the enclosure corresponds to the ambient temperature of the module. Use
installation wiring connections with admitted maximum operating temperature of at least
30 ºC higher than maximum ambient temperature.
Read the system manual "S7-1200 Programmable Controller"
Pulling/plugging the module
NOTICE
Turning off the station when plugging/pulling the module
Dimensions for installation
3.2 Installing, connecting up and commissioning
Prior to installation, connecting up and commissioning, read the relevant sections in the
system manual "S7-1200 Programmable Controller", refer to the documentation in the
Appendix.
When installing and connecting up, keep to the procedures described in the system manual
"S7-1200 Programmable Controller".
Before pulling or plugging the module, always turn off the power supply to the station.
Figure 3-1 Dimensions for installation of the S7-1200