Cannot connect to siemens HMI through eWon Flexy


#1

Hello
I have a Siemens S71200 PLC and a TP900 comfort HMI connected to a eWon Flexy fw13.0. I can communicate with both the PLC and the HMI using TIA 13 sp1 when I am connected to the LAN side of the eWon but when connected through the VPN I can only communicate with the PLC. I can ping the HMI through the VPN however, is there a way to fix this?


#2

@Confused

By default you are only able to download to the ComfortPanel HMIs. In order to locate the HMI, TIA portal uses a combination of an ARP message and a Siemens specific protocol (PN-DCP). Neither of the previously mentioned protocols are routeable and are only usable locally.

Now this will not stop you from downloading to the HMI as that should work just fine.

If you would like to go online with the HMI however a newer feature in the eWON may be able to make this happen. In firmware revision 11.0 we introduced a broadcast forwarding option. Basically this will allow the broadcast messaging to go through the VPN tunnel allowing you to auto-discover your devices and go online.

See pages 7-8 in the below document for setup.


#4

Thank you Jordan for your reply, how do I turn on broadcast
forwarding on the Flexy firmware version 13?


#5

#6

@Confused

It is quite easy to enable.

First and foremost, ensure to follow the eCatcher setup information found in that PDF I linked previously. As for the Flexy simply do the following:


  1. Load the eWON webpage

  2. Select Setup from the left

  3. Select System -> Storage -> Tabular Edition -> Edit COM Cfg

  4. In the searchbar enter: BroadcastForwarder

  5. Update the value to a 1 and save the value.

  6. Reboot your device.



#8

Hi jseanor,

yours post helped me a lot, but didnt solved my problem completly. I can now see all acessible nodes on my VPN network but i cant go to online. TIA portal v15 can show diagnostic info, blocks stored in PLC and so on. Maybe i can download the program, but i cant try it at the moment, because the machine is in use.

So do you have any sugesstions why i cant “go online” ?

For early response advance thanks!
Sincerely Mr.Collor


#9

Hi Mr. Collor,

Are you trying to go online with a device on the LAN side of the Flexy? By default, traffic on the LAN is only allowed through the VPN (for security reasons), but the Flexy can be configured to allow WAN access to LAN devices, if that is what you require.

Am I understanding your question correctly?

Kyle


#11

I am trying to go online using eCatcher (VPN).
Devices are on LAN side (IP range 200.0.0.x)
WAN port is connected to internet trough customers network (172.x.x.x)
My PC is connected to internet using our company network and virtual driver used by eCatcher have IP 10.237.x.x.

Yesterday I had experienced with strange situation. I had turned on BroadcastForwarder and i saw devices on accessible nodes, i was able diagnose them and so on, except going online. In few hours I was again only be able to download program to HMI and I couldn’t see any accessible nodes. I didn’t changed any other parameters. (I was always able to ping HMI and PLC)

Today is situation same, I can only download program to HMI (using eCatcher VPN).

For early response advance thanks!
Sincerely Mr.Collor


#12

Mr. Collor,

I have to transfer this conversation back to board- (and fyi, even if the posts haven’t been approved, it doesn’t mean we haven’t seen them and are working on them. you will get quicker/better response on the board than PM.)

I think the best course of action is a Teamviewer session so you can show me what you are experiencing, because I’m still not completely clear. Is there a time that you are available to work on this with me?

Thank you,
Kyle

M>
I had posted replay, but it takes again few hours to get approved, so I am writing you message.

I realized, that the original question is about Flexy, but for clarity I have eWon Cosy.

I am trying to go online on HMI (LAN) using eCatcher. I can ping the HMI through the VPN, I can download program, but I can’t go online and I can’t see any accessible devices.

Yesterday I was able to see accessible devices after enabling Broadcast Forwarder, but after few hours, it stop working. Today I get step by step trough this PDF and nothing changed. ( aug-070-0-en-plc_discovery_through_talk2m.pdf)

I can ping HMI(PLC and so on), I can download program to HMI, but I can’t see any accusable devices and I can go online (TIA portal v15).

So do you have any suggestions?

For early response advance thanks!

Sincerely Mr.Collor

K> Hi Mr. Collor, Are you trying to go online with a device on the LAN side of the Flexy? By default, traffic on the LAN is only allowed through the VPN (for security reasons), but the Flexy can be configured to allow WAN access to LAN devices, if that is what you require. Am I understanding your question correctly? Kyle

M>
I made some mistakes, this is the correct text:

I can ping HMI(PLC and so on), I can download program to HMI, but I can’t see any accessible devices and I can’t go online (TIA portal v15).

K>
You need to check some settings: First, in the menu, Go to Setup - System - Storage - Tabular edition - Edit COM cfg. Change/confirm these settings 1) NatItf=2 2) FwrdToWAN=1 3) VPNRedirect=0 4) All of the device on the eWONs LAN MUST use the eWON LAN address for their default gateway. Thats it! Should work.

M>
I have changed that parameters.
NatItf 3=>2
FwrdToWAN 0=>1
VPNRedirect0=>4

In eCatcher is firewall set to High, HMI and PLC addresses are added in LAN devices list, “PLC discovery” function is ENABLED. eCatcher version: 6.3.6

In TIA project of HMI is set IP to 200.0.0.3. and gateway (router) is 200.0.0.31 (eWon LAN address).
Default interface in TIA is set to “TAP-Windows Adapter V9”. Transfer option in HMI settings is set to “PN/IE”.

Problem is same, I can ping devices, I can download program to HMI, I can´t go online and I can´t see any accessible devices.

K>
VPNRedirect needs to be 0, and make sure to reboot device after making changes

M>
VPNRedirect 4=>0; rebooted, reconnected in eCatcher, restarted TIA
portal.
Any changes.

K>
Can you test another device, like a laptop, to see if that device gets connection with same settings? That will determine if the problem is with the eWON or the HMI.

M>
I have tested 2 other laptops from our company and one other eWon. It is possible to go online on PLC or dignose devices. But i still cant see accessable devices and i can´t go online with HMI.


#13

Ty for yours time and help, I have been moved to another project, so I can´t now use that eWon. If I will have some time, I will write you message / replay.

In general, I still can´t see any accessible devices (I can´t explore devices on network). But I can ping them and for example I can download program to PLC/HMI if I have that devices configured in project and I know their IP addresses.