indicates that death or severe personal injury will result if proper precautions are not taken.
WARNING
indicates that death or severe personal injury may result if proper precautions are not taken.
CAUTION
indicates that minor personal injury can result if proper precautions are not taken.
NOTICE
indicates that property damage can result if proper precautions are not taken.
Qualified Personnel
personnel qualified
Proper use of Siemens products
WARNING
Siemens products may only be used for the applications described in the catalog and in the relevant technical
maintenance are required to ensure that the products operate safely and without any problems. The permissible
ambient conditions must be complied with. The information in the relevant documentation must be observed.
Trademarks
Disclaimer of Liability
This manual contains notices you have to observe in order to ensure your personal safety, as well as to prevent
damage to property. The notices referring to your personal safety are highlighted in the manual by a safety alert
symbol, notices referring only to property damage have no safety alert symbol. These notices shown below are
graded according to the degree of danger.
If more than one degree of danger is present, the warning notice representing the highest degree of danger will
be used. A notice warning of injury to persons with a safety alert symbol may also include a warning relating to
property damage.
The product/system described in this documentation may be operated only by
task in accordance with the relevant documentation, in particular its warning notices and safety instructions.
Qualified personnel are those who, based on their training and experience, are capable of identifying risks and
avoiding potential hazards when working with these products/systems.
Note the following:
documentation. If products and components from other manufacturers are used, these must be recommended
or approved by Siemens. Proper transport, storage, installation, assembly, commissioning, operation and
All names identified by ® are registered trademarks of Siemens AG. The remaining trademarks in this publication
may be trademarks whose use by third parties for their own purposes could violate the rights of the owner.
We have reviewed the contents of this publication to ensure consistency with the hardware and software
described. Since variance cannot be precluded entirely, we cannot guarantee full consistency. However, the
information in this publication is reviewed regularly and any necessary corrections are included in subsequent
editions.
for the specific
02/2018 Subject to change
Preface
Validity of this manual
CP 1243-8 IRC
Purpose of the manual
This document contains information on the following product:
●
Article number 6GK7 243-8RX30-0XE0
Hardware product version 2
Firmware version V3.1
The CP is the communications processor for connection of the SIMATIC S7-1200 via
public or private infrastructures to a telecontrol master station. For information on the
telecontrol protocols used refer to the section Properties of the CP (Page 11).
With the help of VPN technology and the firewall, the CP allows protected access to the
S7-1200.
The CP can also be used as an additional Ethernet interface of the CPU for S7
communication.
Behind the top hinged cover of the module housing, you will see the hardware product
version to the right of the article number printed as a placeholder "X". If the printed text is, for
example, "X 2 3 4", "X" would be the placeholder for hardware product version 1.
You will find the MAC address under the lower hinged cover of the housing.
This manual describes the properties of this module and supports you when installing and
commissioning it.
The required configuration steps are described as an overview and there are explanations of
the relationship between firmware functions and configuration.
3
Preface
Product names and abbreviations
CP
IRC
STEP 7
Proxy
ST7
New in this issue
Replaced manual issue
Current manual release on the Internet
Required experience
You will also find information about the diagnostics options of the device.
The following short forms are used in this document:
●
The short form is used instead of the full product name "CP 1243-8 IRC".
●
Industrial Remote Communication
●
Short form for the following versions of the configuration tool STEP 7:
– STEP 7 V5
– STEP 7 Basic
The short form "STEP 7" is only used when the product is self-explanatory in the
particular context.
For information on the product versions, refer to the section Requirements for operation
(Page 23).
●
"PROXY CP1243-8 IRC", substitute module for the CP 1243-8 IRC in the catalog of
STEP 7 V5 / HW Config.
●
Short form for the telecontrol protocol "SINAUT ST7"
Connection to SINEMA Remote Connect of the above firmware version
Edition 07/2017
You will also find the current version of this manual on the Internet pages of Siemens
Industry Online Support at the following address:
The product contains open source software. Read the license conditions for open source
software carefully before using the product.
Security information
You will find the requirements for using the module in the section Requirements for operation
(Page 23).
In this manual there are often cross references to other sections.
To be able to return to the initial page after jumping to a cross reference, some PDF readers
support the command <Alt>+<left arrow>.
You will find an overview of further reading and references in the Appendix of this manual.
You will find the license conditions on the supplied data medium:
● OSS_CP1243-8_99.pdf
Siemens provides products and solutions with industrial security functions that support the
secure operation of plants, systems, machines and networks.
In order to protect plants, systems, machines and networks against cyber threats, it is
necessary to implement – and continuously maintain – a holistic, state-of-the-art industrial
security concept. Siemens’ products and solutions constitute one element of such a concept.
Customers are responsible for preventing unauthorized access to their plants, systems,
machines and networks. Such systems, machines and components should only be
connected to an enterprise network or the internet if and to the extent such a connection is
necessary and only when appropriate security measures (e.g. firewalls and/or network
segmentation) are in place.
Additionally, Siemens’ guidance on appropriate security measures should be taken into
account. For additional information on industrial security measures that may be
implemented, please visit
Link: (http://www.siemens.com/industrialsecurity)
Siemens’ products and solutions undergo continuous development to make them more
secure. Siemens strongly recommends that product updates are applied as soon as they are
available and that the latest product versions are used. Use of product versions that are no
longer supported, and failure to apply the latest updates may increase customers’ exposure
to cyber threats.
You will find information on Training, Service & Support in the multi--language document
"DC_support_99.pdf" on the data medium supplied with the documentation.
The product is low in pollutants, can be recycled and meets the requirements of the WEEE
directive 2012/19/EU "Waste Electrical and Electronic Equipment".
Do not dispose of the product at public disposal sites. For environmentally friendly recycling
and the disposal of your old device contact a certified disposal company for electronic scrap
or your Siemens contact.
Keep to the local regulations.
You will find information on returning the product on the Internet pages of Siemens Industry
Online Support:
Link: (https://support.industry.siemens.com/cs/ww/en/view/109479891)
5 Program blocks ................................................................................................................................... 167
6 Diagnostics and upkeep ...................................................................................................................... 171
4.16.4.2 Firewall settings for configured connection connections via a VPN tunnel .......................... 108
4.16.4.3 Settings for online security diagnostics and downloading to station with the firewall
7 Technical data ..................................................................................................................................... 183
A Approvals ............................................................................................................................................ 187
B Dimension drawings ............................................................................................................................. 191
C Accessories ......................................................................................................................................... 193
D STEP 7 V5 configuration of the proxy ................................................................................................... 215
E Documentation references ................................................................................................................... 225
Index ................................................................................................................................................... 229
6.5 Processing status of messages ........................................................................................... 177
The CP is intended for operation in a SIMATIC S7-1200 automation system. The CP is the
communications processor for connection of the S7-1200 via public or private infrastructures
to a telecontrol master station.
11
Application and functions
Supported telecontrol protocols
Firmware version V2.1
Firmware version V3
Application
SINAUT ST7 system
New ST7 systems
Existing DNP3 or IEC systems
Communications partners
Firmware version V2.1
1.2 Properties of the CP
Depending on the firmware version the CP supports the following protocols.
●
– SINAUT ST7
●
– SINAUT ST7
– DNP3
– IEC 60870-5
You will find the supported transmission protocols and network types in the section
Communications services (Page 14).
The CP can be used in the following systems:
●
In existing SINAUT systems in which the ST7 protocol is used, the CP can be used with
the functions of TIM 3V-IE Advanced.
If used for this purpose note the instructions below on configuration.
●
New systems with S7-1200 stations in which the ST7 protocol is used.
●
In existing systems in which the DNP3 or the IEC protocol is used, the CP can be used
as the communications processor of the SIMATIC S7-1200.
The interfaces of the CP support the network node type "station". A master station can be
connected as the communications partner of the CP. When using the ST7 protocol, a master
station or node station can be connected.
Depending on the firmware version of the CP, a master station with one of the following
applications can be connected.
●
The following master station applications are possible:
To configure the CP in new systems with one of the telecontrol protocols named above
use STEP 7 Basic.
In these systems use a CP with firmware version V3.
● Existing ST7 systems
In existing SINAUT systems with SIMATIC stations of the families S7-300/400 and the
TIM modules for remote transfer, the CP can be used for expansions by S7-1200
stations.
In these systems that were configured with STEP 7 V5, use a CP with firmware version
V2.1.
To configure the CP, you require the two following STEP 7 products:
– STEP 7 V5
and
– STEP 7 Basic
For information on the required STEP 7 versions, see section Requirements for operation
(Page 23).
Functions and services of the telecontrol protocol
Communication with the control center
SMS / E-mail
Inter-station communication
Direct communication
1.3 Communications services
The following communications services are supported:
The CP is the communications processor for connection of the SIMATIC S7-1200 via public
or private infrastructures to a telecontrol master station. You will find the possible application
of the telecontrol master station in the section Properties of the CP (Page 11).
For telecontrol communication, the CP uses the ST7 protocol on the application layer (OSI
layer 7) for communication via different telecontrol networks.
●
An S7-1200 station with a CP 1243-8 IRC communicates via LAN/WAN with the master
station.
●
Event-driven, the CP can send SMS messages to mobile telephones and e-mails to PCs
with an Internet connection.
– SMS messages can be sent if the CP is connected to a mobile wireless network via
the RS-232 interface.
– If the CP is connected, e-mails can be sent via the Ethernet interface.
Both types of messages are configured in telecontrol communication in STEP 7 Basic.
The use of program blocks is not necessary here. For information on the configuration,
see section Message configuration (Page 163).
●
In dedicated line networks and with communication via the mobile wireless network and
the Internet (GSM/MSC), the CP supports inter-station communication between S7-1200
stations via the master station.
With inter-station communication, the CP establishes a connection to the master station.
The master station forwards the frames to the destination station.
The partners for inter-station communication must already have been created in the
STEP 7 V5 project.
●
In dial-up networks and Ethernet networks, there is direct communication between the
subscribers.
Simple communication via the mobile wireless network (GSM) and the Internet can be
achieved with the MSC transmission protocol. If the security requirements are higher, the
transmission protocols (OSI layer 3) listed below can be used.
●
Can be used with S7 communication
Simple Internet communication via the Internet (DSL)
The MSC protocol supports authentication of the communications partners and simple
encryption of data. A user name and a password are included in the encryption. An MSC
tunnel is established between the MSC station and MSC master station.
●
Can be used with S7 communication
Secure Internet communication using:
– Internet (DSL)
or
– Mobile wireless network (GSM) + Internet (DSL)
MSCsec supports authentication of the communications partners and data encryption
with a user name and password. In addition to this, the shared automatically generated
key is renewed between the communications partners at configurable intervals.
●
Highly secure communication via mobile wireless and the Internet (DSL).
Communication via a mobile wireless network combined with the Internet is made
possible by the router SCALANCE M. The SCALANCE M product series provides various
VPN routers with IPsec and encryption software and their own firewall.
For a description of the configurable Security functions, refer to the section Security
(Page 104).
You will find an overview of the possible transmission options in the section Overview:
Connection to LAN / WAN (Page 59).
Communication is based on the DNP3 SPECIFICATION Version 2.x (2007/2009).
The CP is a communications processor of the SIMATIC S7-1200 for system connection to
control centers using the DNP3 protocol for telecontrol applications.
An S7-1200 with a CP functions as a DNP3 station (Outstation).
The CP supports implementation level 1 - 4 (DNP3 Application Layer protocol Level). You
will find a description of the other functions in the section Partners (DNP3 / IEC) (Page 91).
The communication is based on the specification IEC 60870-5 Part 1 - 5 (1990 - 1995) and
Part 104 (2000).
The CP is a communications processor of the SIMATIC S7-1200 for system connection to
control centers using the IEC 60870-5 protocol for telecontrol applications.
An S7-1200 with a CP functions as a substation (slave).
Supported as of firmware version V3.1. See section Connection to SINEMA RC (Page 17).
The CP makes telecontrol communication possible via the following network types:
● Industrial Ethernet
● Dedicated line / wireless network
● Analog dial-up network, ISDN network
● Mobile wireless networks
– GSM/GPRS (2G)
With 2.5G router SCALANCE M874-2
– UMTS (3G)
With 3G router SCALANCE M874-3
– LTE
With router SCALANCE M876-4
● IP-based wireless networks
For information on connecting the CP to various network types, refer to the section
Overview: Connection to LAN / WAN (Page 59).
The CP with the firmware version described here (see Preface) and configured in STEP 7
V14.0 SP1 supports the following network node types:
● Station
● Node station
Depending on the transmission protocol being used, one of the following transmission
modes can be configured in STEP 7 V5:
Communication via SINEMA Remote Connect (SINEMA RC)
1.4 Connection to SINEMA RC
Reading / writing data from / to a CPU via the mobile wireless network is possible if S7
communication is enabled in the configuration of the CP.
The CP supports the following functions:
●
The CP supports the function as client (program blocks) and server for data exchange
with remote stations (S7-300/400/1200/1500).
●
Communication between stations via S7 connections
●
●
You will find details on the program blocks in the information system of STEP 7 Basic.
For S7 communication, the CP requires a fixed IP address.
Via the Ethernet interface of the CP and the program blocks of the Open User
Communication on the CPU the CP has the following communication options:
● Communication with SIMATIC stations via S7 connections
● Sending e-mails
In contrast to the corresponding service of telecontrol communication (see above), to
transfer e-mails via OUC, the TMAIL_C program block needs to be used, see section
Program blocks (Page 167).
The "SINEMA RC Server" application provides end-to-end connection management of
distributed networks via the Internet. This also includes secure remote access to lower-level
stations. Communication between SINEMA RC Server and the remote devices takes place
via a VPN tunnel with consideration of the stored access rights.
SINEMA RC uses OpenVPN for encryption of the data. The center of the communication is
SINEMA RC Server via which communication runs between the subscribers and that
manages the configuration of the communications system.
SCALANCE M routers, which you can use for the connection, also support OpenVPN and
connection to SINEMA Remote Connect.
For the CP firmware version required for communication via SINEMA RC see section
Communications services (Page 14).
The CP can also handle telecontrol communication via the SINEMA RC server.
Due to the data point configuration in STEP 7 Basic, programming program blocks in
order to transfer the process data is unnecessary. The process data is configured as
individual data points and transferred one-to-1 to the master station.
●
Characteristics of the IP configuration of the Ethernet interface of the CP:
– The CP supports IP addresses according to IPv4.
– Address assignment:
The IP address, the subnet mask and the address of a gateway can be set manually
in the configuration.
As an alternative, the IP address can be obtained from a DHCP server or by other
means outside the configuration.
●
For information on the method and configuration, refer to the section Time-of-day
synchronization (Page 100).
For information on the format of the time stamp of the frames, refer to the section
Datapoint types (Page 135).
●
With the aid of the Web server of the CPU, you can read out module data from the
station.
●
The CP saves the values of data points configured as an event in the send buffer.
The data is not saved retentively. It is lost in case of a power outage.
●
The CP transmits the data from the send buffer individually or bundled to the
communication partner. The transfer can be triggered by various triggers.
●
Analog values can be preprocessed on the CP according to various methods.
Security functions of the telecontrol and transmission protocols
ST7
MSC
MSCsec
DNP3
1.6 Security functions
●
From an engineering station (ES) on which STEP 7 is installed, you can use the online
functions of STEP 7 via the Ethernet interface of the CP to access the S7-1200 CPU if
the station is located in the same IP subnet.
The following online functions are available:
– Downloading project or program data from the STEP 7 project to the station
– Querying diagnostics data on the station
– Downloading firmware files to the CP
For a remote station located in a different IP subnet or that can be reached via the
Internet, these functions can only be used if the ES (with CP 1628 or via SCALANCE S)
is connected to the station via a VPN tunnel.
●
As an SNMP agent, the CP supports data queries using SNMP (Simple Network
Management Protocol).
For more detailed information, refer to section SNMP (Page 175).
With Industrial Ethernet Security, individual devices, automation cells or network segments
of an Ethernet network can be protected.
Read the information in the section Security recommendations (Page 55) for planning and
configuring your networks.
For the telecontrol communication, the following Security functions can be activated:
●
The transmission protocols that can be used by the CP for telecontrol communication via
the ST7 protocol support the following Security functions:
–
The MSC protocol supports authentication of the communications partners and simple
encryption of data. A user name and a password are included in the encryption. An
MSC tunnel is established between the MSC station and MSC master station.
–
MSCsec supports authentication of the communications partners and data encryption
with a user name and password. In addition to this, the shared automatically
generated key is renewed between the communications partners at configurable
intervals.
The security functions specific to DNP3 can be used.
Application and functions
Further configurable security functions of the CP
Firewall
VPN
Logging
NTP (secure)
STARTTLS / SMTPS
HTTPS
SNMPv3
1.6 Security functions
The following security functions can be used independently of telecontrol communication.
Due to the activation of the security functions of the CP in the configuration, the following
functions are accessible to the S7-1200 station on the interface to the external network:
●
– IP firewall with stateful packet inspection (layer 3 and 4)
– Firewall also for "non-IP" Ethernet frames according to IEEE 802.3 (layer 2)
– Limitation of the transmission speed to restrict flooding and DoS attacks ("Define IP
packet filter rules")
– Global firewall rule sets
The protection provided by the firewall can cover individual devices, several devices or
even entire network segments.
●
The following alternatives can be used:
– Secured communication via IPsec tunnels
VPN communication allows the establishment of secure IPsec tunnels for
communication with one or more security modules. The CP can be grouped together
with other modules to form VPN groups during configuration. IPsec tunnels are
created between all security modules of a VPN group.
– Remote maintenance via SINEMA Remote Connect
It is not necessary and not possible to create a VPN group for communication via a
SINEMA RC server. The SINEMA RC Server manages the communication between
the devices and the security mechanisms (OpenVPN).
●
To allow monitoring, events can be stored in log files that can be read out using the
configuration tool or can be sent automatically to a Syslog server.
●
For secure transfer during time-of-day synchronization (with telecontrol communication
disabled)
●
For secure sending of e-mails
●
For secure access to the Web server of the CPU
●
Foe secure transfer of network diagnostic information
For the range of performance of the security functions refer to the section Performance data
and configuration limits (Page 22).
For a description of the configuration, refer to the section Security (Page 104).
Number of data points for the data point configuration
Frame memory (send buffer)
1.7 Performance data and configuration limits
You will find further information on the functionality and configuration of the security functions
in the information system of STEP 7 and in the manual /11/ (Page 227).
In each S7-1200 station, up to three CMs/CPs can be plugged in and configured, of which a
maximum of one CP 1243-8 IRC.
●
The CP can establish connections to up to 4 communications partners.
The partners can be linked redundantly.
When using the ST7 protocol, in addition to this, inter-station communication with up to 4
S7 stations can be operated via the master station.
●
The CP can establish connections to up to 4 communications partners (S7 stations).
●
1 connection resource is reserved for online functions.
●
8 connection resources for S7 connections (BSEND/BRCV)
These connections are used for SINAUT ST7 communication.
●
Max. 4 connections at the same time
●
– 2 connection resources for PG connections
– 1 connection resource for OP connections
The maximum number of configurable data points is 200.
The CP has a frame memory (send buffer) for the values of data points configured as an
event.
The send buffer has a maximum size of 16000 frames. The size of the frame memory is
divided equally among all configured communications partners. It can be set in STEP 7
Basic, refer to the section Communication with the CPU (Page 95).
You will find details of how the send buffer works (storing and sending events) as well as the
options for transferring data in the section Process image, type of transmission, event
classes (Page 144).
Up to 10 messages can be configured in STEP 7 and sent as e-mails or SMS messages.
● Maximum number of characters that can be transferred per SMS message: 160 ASCII
characters including any value sent at the same time
● Maximum number of characters that can be transferred per e-mail: 256 ASCII characters
including any value sent at the same time
Up to 8 IPsec terminals can be established for secure communication with other security
modules.
The maximum number of firewall rules in advanced firewall mode is limited to 256.
The firewall rules are divided up as follows:
● Maximum 226 rules with individual addresses
● Maximum 30 rules with address ranges or network addresses
(e.g. 140.90.120.1 - 140.90.120.20 or 140.90.120.0/16)
● Maximum 128 rules with limitation of the transmission speed ("Bandwidth limitation")
Apart from the CP, in the remote S7-1200, the following hardware is also required:
● A CPU with firmware version as of V4.1
● For communication via WAN networks (dedicated line, dial-up / GSM / wireless network):
A TS module
You will find the TS modules in the telecontrol accessories program, refer to the appendix
TS modules (Page 193).
Program blocks for Open User Communication and S7 communication
Requirements for using mobile wireless services
1.8 Requirements for operation
● When using the TS Module RS232: The suitable modem
For information on modems, refer also to the appendix Modems and routers (Page 202).
● When using the TS Module GSM: An external antenna for the CP
Only use antennas from the telecontrol accessories program, refer to the appendix
Antennas (Page 208).
To configure the CP completely, you require the following products as configuration tools:
● STEP 7 Basic V15
In addition when using the CP to expand SINAUT projects that were configured in STEP 7
V5:
● STEP 7 V5.5
● SINAUT Engineering Software V5.5
The use of the two STEP 7 products is described in the section Configuration (Page 55).
For Open User Communication and S7 communication, program blocks are required, see
section Program blocks (Page 167).
● A contract with a suitable mobile wireless network provider
The contract must allow the transfer of data.
● IP address:
For communication with the master station, a private (fixed) or public (dynamic) IP
address assigned by the mobile wireless network provider can be used.
● The SIM card and PIN belonging to the mobile wireless contract
The SIM card is inserted in the TS module GSM.
With mobile wireless contracts in which the network provider does not assign a PIN, no
PIN is configured for the CP in STEP 7 V5.
● Local availability of a mobile wireless network in the range of the station.
Below, you will find configuration examples for stations with a CP 1243-8 IRC.
In telecontrol communication the station communicates via the CP with a master station.
Communication can take place via various interfaces of the CP and via various network
types.
In the sample configuration shown, stations communicate with a master station TIM that in
turn is connected to a master station of the type SINAUT ST7sc:
● An S7-300 that only communicates via the Internet.
● An S7-300 that communicates via the mobile wireless network and the Internet.
● An S7-1200 with CP 1243-8 IRC that communicates via the mobile wireless network and
the Internet.
All three stations use the transport protocol MSC (or MSCsec).
Figure 1-1 Communication with the MSC protocol via mobile wireless and Internet
Inter-station communication is possible for stations connected to the same master station.
For the inter-station communication between stations, the master station forwards the
messages of the sending station to the receiving station.
In the sample configuration shown, an S7-300 and two S7-1200 stations communicate with a
master station SINAUT ST7cc/ST7sc.
The CPs are connected via their Ethernet interface.
The connection to the Ethernet network, in this example a fiber-optic cable, is implemented
using SCALANCE X switches. Copper cable is also possible as the medium.
Figure 1-2 Communication via an Ethernet network (optical medium)
In this example, the S7 stations communicate with the master station via an IP-based private
wireless network. For this application, suitable IP-based wireless devices must be used.
The CPs are connected via their Ethernet interface. In this configuration as well, an Ethernet
network needs to be configured in STEP 7 V5.
Figure 1-5 Communication via an IP-based private wireless network
Communication via an analog wireless network with communication according to the RS-232
standard is also possible. In this case, the CP 1243-8 would need to be connected to the
wireless device via a TS module RS-232. In this configuration a dedicated line network
would need to be configured in STEP 7 V5.
Figure 1-6 Sending messages by SMS from an S7-1200 station
The CP can send SMS messages to a mobile phone. SMS messages are generated and
sent due to events. You will find the description of the configuration in the following sections:
Data point configuration (Page 128)
Message configuration (Page 163)
The CP can send e-mails to a PC with an Internet connection or a mobile phone. The
mechanisms for this are as follows:
● E-mails that are generated by the telecontrol application.
E-mails are generated and sent due to events. You will find the description of the
configuration in the following sections:
Data point configuration (Page 128)
Message configuration (Page 163)
TheE-mail configuration (Page 110)
● E-mails sent as a result of calling the program block TMAIL_C.
You will find information on the blocks in the section Program blocks (Page 167). You will
find the description of the programming in the STEP 7 information system.