Is Siemens S7 Lockdown Possible

Join Date
Apr 2010
Location
India
Posts
4
Hi

I am trying to do data acquisition on an existing system which has an
S7 300 PLC connected to an HMI using ethernet.

The problem is that I am not able to ping any of the nodes on the network.

* I logged in on HMI and pinged on its own IP address. 192.168.1.151 ... no response.

* Disabled firewall...... Same. ... no response.

* Added a Linux machine on the LAN with IP address 192.168.1.153 ... and ran nmap -sP 192.168.1.0/24 ... no hosts detected.

* Added a WinXP machine on the LAN with Simatic manager ... PLC not detected.


Could someone tell me what could the problem be? Can a s7300 PLC be configured to accept requests from only a particular HMI through lock on mac id or some such means?
 
Last edited:
Hi

I am trying to do data acquisition on an existing system which has an
S7 300 PLC connected to an HMI using ethernet.

The problem is that I am not able to ping any of the nodes on the network.

* I logged in on HMI and pinged on its own IP address. 192.168.1.151 ... no response.

* Disabled firewall...... Same. ... no response.

* Added a Linux machine on the LAN with IP address 192.168.1.153 ... and ran nmap -sP 192.168.1.0/24 ... no hosts detected.

* Added a WinXP machine on the LAN with Simatic manager ... PLC not detected.


Could someone tell me what could the problem be? Can a s7300 PLC be configured to accept requests from only a particular HMI through lock on mac id or some such means?

Welcome to the Forum!

It sounds like you have bigger problems than just your S7 PLC. There is something not right on your Network. You should be able to Ping something on the Network. Normally you would be able to Ping the S7 PLC. I don't know if it is possible to disable ICMP, but I have Pinged S7 PLCs on Ethernet without a problem.

Put a Windows PC on the Network, and install Wireshark.

http://www.wireshark.org/

It is a Packet Sniffer and Analyzer Program.

Are you sure of your IP Addresses? You seem to have a good grasp of Network Topology.

Stu....
 
Unplug the network connection on the plc and plug your pc network connection into the same port and then ping the plc.
 
Unplug the network connection on the plc and plug your pc network connection into the same port and then ping the plc.

Wouldn't that require a Crossover Cable, or are the S7 Ethernet Ports Auto Sensing?

Maybe he has a bad Switch, but he said he couldn't Ping the HMI from itself. However, he didn't tell us what HMI he was using either.

Stu....
 
If it is an old S7, then maybe it uses ISO mode, and does not even have an IP address.
edit: New CP343-1 modules allow to disable TCP/IP and only use ISO mode.

Please state the exact type number of the CPU, and the exact type number of the CP343-1.

edit again: If the CP343-1 does use ISO mode, then you should still be able to scan for it with STEP7. The CP343-1 should be detectable by its MAC address.
 
Last edited:
Unlikely, but not impossible that the port has been configured to disable autonegotiation.
But if you try to ping from the HMI PC, then that cannot be the explanation.
 
Just to be sure that the laptop LAN configurations are correct, I connected second laptop in the network and successfully pinged to the second laptop.

The PLC model number is 315A and HMI is ESeries HMI.
 
Well.. to make this the easy way.

Put your PG in the switch of the network.

In Step 7 manager
Set your PC/PG interface to Ethernet card
Open menu PLC
Click Display accesible nodes

wait untill you see all nodes/hmi/plc and so on..

if nothing shows up, change your pc/pg interface if you have more then one ethernet based interface. repeat steps above.

If still nothing shows, look under your ethernetcard settings on your PG so you have the same IP area.

If problem still are there, check program so its on static IP based system and not DHCP and uses simatic names instead of IP adresses, if they run Profinet they should be using names to assign ID of nodes and so on. and not IP adresses.

I think you are on the wrong subnet.. but thats my best guess.
 
Well.. to make this the easy way.

Put your PG in the switch of the network.

In Step 7 manager
Set your PC/PG interface to Ethernet card
Open menu PLC
Click Display accesible nodes

wait untill you see all nodes/hmi/plc and so on..

if nothing shows up, change your pc/pg interface if you have more then one ethernet based interface. repeat steps above.

If still nothing shows, look under your ethernetcard settings on your PG so you have the same IP area.

If problem still are there, check program so its on static IP based system and not DHCP and uses simatic names instead of IP adresses, if they run Profinet they should be using names to assign ID of nodes and so on. and not IP adresses.

I think you are on the wrong subnet.. but thats my best guess.
> Put your PG in the switch of the network.
Done:

>In Step 7 manager
>Set your PC/PG interface to Ethernet card
>Open menu PLC
>Click Display accesible nodes
>wait untill you see all nodes/hmi/plc and so on..
Done... Img Attached
Shows only one node. checked its properties, they correspond to my laptop

>if nothing shows up, change your pc/pg interface if you have more then one >ethernet based interface. repeat steps above.
We have only one ethernet interface

>If still nothing shows, look under your ethernetcard settings on your PG so >you have the same IP area.
>If problem still are there, check program so its on static IP based system and >not DHCP and uses simatic names instead of IP adresses, if they run Profinet >they should be using names to assign ID of nodes and so on. and not IP >adresses.
>I think you are on the wrong subnet.. but thats my best guess.

Ip address is in the same range

PLC_test_result.jpg
 

Similar Topics

The past week we received a new piece of equipment from Germany which utilizes siemens controls. Typically in our company we use A.B. controls for...
Replies
11
Views
273
Hello I have a s7-1200 and I would like to read the tags present in this controller with my controllogix controller. The two controllers don't use...
Replies
5
Views
161
Hi need help why this “failure 5 emergency stop “ appears at every startup in the morning ? Have to shut off main switch at least 10 times on...
Replies
19
Views
311
i have two plc 1. s7-1212dc/dc/dc ip; 192.168.0.1 2. s7-1500 1513-1pn ip; 192.168.3.2 i need to get data from plc1 to plc2. any idea how to do...
Replies
5
Views
125
Hi everyone hope you'll well. Is it possible for me to download a Crack version of tia portal v13..sorry to say this but the software is very...
Replies
5
Views
200
Back
Top Bottom