S7400, CP443-1 & MP270 Network Isolation

shamusdb

Member
Join Date
Jul 2012
Location
UK
Posts
12
Hi

I have a system where essentially i am connecting an HMI via a switch to the CP443 card. I've set an IP address in the PLC end and an IP address in the HMI and all works fine. The customer is now asking that the HMI is a different level of network i.e. PLC = Level 2 and HMI will be Level 0. The Level 2 network is a factory network and IP addresses are supplied to us. Level 0 is our network and needs to be IP addresses configured by us. Is there a way i can either configure or install hardware so that i can have the PLC - HMI communication but be on 2 levels of network. My first thoughts are making the switch a managed switch and creating some kind of bridge from one to the other but i'm not to familiar with this side of things.

Any help or pointers is much appreciated

Shaun
 
A managed switch or Router between the two levels is the way to go.
In all the SIMATIC components that must be reached from the other level, the ethernet option "use Router" must be set, and the Router IP must be specified.

In stead of a "normal" Router, you can also use two ethernet cards in the PLC. One connected to level 0 and the other to level 2. The PLC will then act as a Router between the levels. It is a different kind of routing, and you need some instructions on how to implement it. But it is not difficult.
 
Thanks Jesper

If i did plonk something in between the PLC & HMI would they still be happy talking to each other if the IP addresses were (potentially) in different ranges?

Regards
Shaun
 
Yes. You may have to tell the HMI how to reach the PLC, but it is definitely possible.

One thing though. IMHO opinion, the HMI is part of the machine or plant it is controlling. So HMI and PLC are normally not to be separated from each other.
When I see sometimes that there is a need to separate networks from each other, then it is typically in connection with integration to the higher level (i.e. production database, statistics, that sort of things) that goes via a separate conenction.

If IT decides it is time to do maintenance on the higher level network, will it cut off the HMI from the PLC ? Would that be acceptable ?
 
The PLC tags will be accessed from the main SCADA system and other than that there is no real problem to me if the factory LAN was down in terms of the machine running on. There are 5 of these PLC/HMI arrangements and its a redundant system so if they want a separate card for the HMI your talking 10 new cards which is a fortune. It would just be easier all round if they gave me five extra IP addresses for the HMI's instead!! I think there main concern is accessing the network from the HMI and using the internet or downloading 3rd party software which will be unlikely using the MP270.

Thanks Again
 

Similar Topics

Hi guys, I'm having problems converting WinAC (WinLC RTF F application) to S7 300 project based on CPU 319F-3PN or S7 400/416F-3PN. The problem is...
Replies
0
Views
615
Hello All I hope you are well and safe. I have a problem that I could use your appreciated input for: SW: SIMATIC MANAGER v5.5 SP3 HW1...
Replies
2
Views
1,228
Hello, does anyone know the best connection method between an S71500R/H profinet MRP ring (2 x S7 1500R controllers in redundant profinet ring)...
Replies
12
Views
2,864
Hi all, I have PCS7 project where I need to link Zebra scanners. The Zebra scanners are equiped with serial->ethernet converters also from the...
Replies
7
Views
3,141
Hi All, Long time gap between visits again, but this is the only place to come for PLC advice. So I am here. I have come up against a problem...
Replies
11
Views
3,884
Back
Top Bottom