Know-How von unseren Helmholz Experten
Do you have questions about Helmholz products? Here you will find answers to the most frequently asked questions that have been put to the Helmholz customer service team over many years.
How much data volume does a REX with GSM modem consume?
Assuming that a REX is connected to the myREX24 portal server 24/7, our tests have shown that up to 80 MB of data volume can be consumed per month (also depending on the ISP, 80 MB is the highest value found in our tests).
As soon as a user connects to the REX via VPN or data values are logged via the REX, the data volume will be higher.
After a device replacement USBoverIP does not work anymore
After transferring the configuration to the new device a synchronization with the portal has to be done again (In the portal click on Configuration-->Force Synchronization - see picture). After that USBoverIP works again and a connected device is recognized.
The reason:
When replacing a device the information "Firmware version" and "Hardware version" of the old device are deleted in the portal. But this information is needed for the new device to create the complete configuration (including USBoverIP). For this a new synchronization is necessary.
After a device exchange USBoverIP does not work any moreAfter a device exchange USBoverIP does not work any moreThe connection to the myREX24 portal or the REX device is slow or unstable.
shDIALUP is affected by another software/application. This could be an antivirus program installed on your Internet PC or another VPN client software already installed. As far as possible, always use current browser versions and the latest version of shDIALUP Software.
The hardware of your dial-up computer and the Internet connection should generally provide good performance. A firewall and/or proxy server in your internal network structure may also affect the connection.
Which firewall settings are necessary to reach the myREX24 server?
The shDIALUP software and the REX routers establish an outbound TCP connection to the address https://v2.myrex24.net (5.39.123.21). To establish a secure connection to the myREX24 server, at least one of the following TCP ports (80, 1194 or 443) must be enabled for the VPN tunnel. If MAC address filtering is enabled in your firewall, it must be disabled or adjusted.
In the default setting, only the openVPN port 1194 is used. If this is blocked, the REX/shDIALUP configurations must be changed accordingly. There is no automatism, which polls all three ports cyclically and switches to a free one!
With the shDIALUP software (dial-in client) it is no longer possible to log in to the myREX24 V1 portal. The following message appears: The Authentification failed. Please make sure you have the right username and password.
For security reasons (patched in portal version 1.7.2) a login via server authentication method "1" is no longer possible. Please set the "Server Authentication Method" in shDIALUP to 2.

When I set the NETLink to Auto Baud in the PG/PC interface and try to go online, the active LED flashes briefly before the message appears that the bus parameters could not be determined.
Either the CPU used does not support the cyclic sending of the bus parameters (switched off by parameterisation or function not available), or the CPU is so busy with general communication tasks that the low-priority bus parameter telegram is sent too infrequently and thus cannot be detected by the NET Link®. Please switch off the autobaud functionality in the NETLink-S7-NET driver (PG/PC interface) and set the baud rate used by the CPU and the corresponding profile manually.
Is there a hidden button on the NETLink housing to perform a factory reset?
Resetting all parameters is only possible via the web interface. The http login data is also required for this. Using the button 'Restore Factory Defaults' it is then possible to restore the NETLink® to its factory settings.
The web interface of a new NETLink cannot be reached via the standard IP address. The PC's network card has been set to the appropriate address space, but the ping command does not work either.
In the event that the IP address stored in the NETLink (with subnet mask) is not permissible or no IP address was assigned via DHCP, the NETLink uses the "autoip" functionality to arrive at a valid local IP address!
The address space 169.254.x.x is available for AUTOIP addresses (random values are used for the last two octets of the IP address). The subnet mask is set to 255.255.0.0 and the gateway to the IP address 0.0.0.0.
Which operating systems are supported?
Prerequisites are a Microsoft operating system with administrative rights and the system control element "Set PG/PC interface". The functionality has been successfully tested under Windows* XP/2003R2/7/2008R2/8.1/2012 R2/10.
* Windows is a registered trademark of Microsoft Corporation
My computer has a firewall. Which ports do I have to release?
The NETLink-S7-NET driver communicates with the NETLink via TCP port 7777. Furthermore the UDP ports 25342 and 25343 are used to search the NETLink devices. Please enable at least port 7777, so that the basic functionality of the driver is available to you.
If you use the RFC1006 functionality (also known as S7-TCP/IP), port 102 must be enabled additionally.
If I mix RFC1006 connections and connections via the STEP*7 driver, there are occasionally connection aborts or error messages stating that it is not possible to establish a connection.
When communicating with S7-300** modules, the communication resources may have to be parameterized. The user may influence the distribution of the available 'connection resources' in the hardware configuration at object properties of the CPU.
* STEP is a registered trademark of Siemens AG.
** S7-300 is a registered trademark of Siemens AG.
We can no longer log in to the web interface because the password is not accepted. How can the login data be reset?
We can generate an unlock code for you to reset the password for this device.
To do this, we need a copy of the delivery note/invoice and the serial number of the NETLink adapter for verification, in which we can see that you or your company have purchased this device.
This is the only way we can generate a ticket for you to reset the NETLink. For this you need our free parameterization software SHTools. You can find the latest version on our homepage at helmholz.de > Download > NETLink.
If you are unable to send us a verification or no longer have one, please return the NETLink to our head office in Großenseebach. We will then reset the adapter to the factory settings for you in return for a flat-rate inspection fee.
I have connected the NETLink USB Compact to my PC/notebook, but it always seems to reboot.
It is possible that the power supply from the USB interface cannot provide enough power to operate the NETLink USB Compact.
In most cases the problem can be solved by connecting a USB hub with its own power supply.
The webinterface of a new NETLink is not reachable via the standard IP address. The network card of the PC was set to the appropriate address space, but the ping command does not work either.
In case the IP address stored in the NETLink (with subnet mask) is not valid, or no IP address was assigned via DHCP, the NETLink uses the "autoip" functionality to get a valid local IP address!
For AUTOIP addresses the address space 169.254.x.x is available (random values are used for the last two octets of the IP address). The subnet mask is set to 255.255.0.0 and the gateway to the IP address 0.0.0.0.
Although I already have a NETLink USB Compact running on my PC, I am prompted to install a USB- driver if I want to use another NETL ink® USB Compact or another USB- interface of my PC.
USB- devices are generally provided with a serial number. This number is used to identify already known devices. If you use two USB devices of the same type, two driver instances for this device type will be installed on your computer.
The USB driver is located on the supplied CD in the directory 'CD- Verzeichnis:\Driver'. You can also download the latest driver version.
When using the NETLink USB Compact with an external hub or a USB- plug-in card, errors often occur. Even plugging and unplugging the NETLink USB Compact does not help.
For example, if the power supply of the hub is not sufficient for the NETL ink® USB Compact, some hubs report an error to the upstream host (the PC). This now leads to the fact that the hub is logged off from the host system. The hub is therefore no longer ready for operation. If the hub is disconnected and then reconnected, it is reinitialized on the USB bus and should be available again.
The setting dialogs do not appear in the Simatic Manager.
Note that after the first installation the NETLink-S7-NET driver still has to be added to the PG/PC interfaces.
Make sure that you have administrator rights during the installation. Restart your computer after the first installation if you were prompted to do so.
The Starter program has problems accessing a Micromaster* drive.
When requesting 'control authority' for the Micromaster* drive, please make sure to increase the failure monitoring from 20ms to 200ms and the application monitoring from 2000ms to 5000ms, so that the starter software remains operable.
*MICROMASTER is a registered trademark of Siemens AG.
If I set the NETLink USB Compact to Auto Baud in the PG/PC interface and try to go online, the orange LED flashes shortly before the message appears that the bus parameters could not be determined.
Either the used CPU does not support the cyclic sending of the bus parameters (switched off by parameterization or function not available), or the CPU is so busy with general communication tasks that the low-priority bus parameter telegram is sent too seldom and thus cannot be detected by the NETLink USB Compact.
Please switch off the autobaud functionality in the NETLink-S7-NET driver (PG/PC interface) and set the correct baud rate and profile.
When I open several connections via the STEP*7 driver, there are occasionally connection aborts or error messages stating that it is not possible to establish a connection.
When communicating with S7-300** modules, the communication resources may have to be parameterized. The user may influence the distribution of the available 'connection resources' in the hardware configuration at object properties of the CPU.
* STEP is a registered trademark of Siemens AG.
** S7-300 is a registered trademark of Siemens AG.
As soon as the configured PROFIBUS slaves are added to my CPU, the communication between NETLink USB Compact and STEP*7 becomes significantly slower.
The user can influence the 'Cycle load by communication [%]' in the hardware configuration under object properties of the CPU. The default value is 20 %.
* STEP is a registered trademark of Siemens AG.
Can the PROFINET switch also be operated with 10 Mbit?
Why do you need "Port Mirroring"?
PROFINET is a complex communication protocol. In some situations it may be necessary to read and interpret the telegram traffic with a protocol analyzer.
In order to be able to read in an Ethernet network, expensive coupling hardware is used, which is looped into the line or a free port in a switch is configured as a "mirror port". The mirror port sends out all telegrams of another port of the switch as a copy. A device or PC with appropriate analysis software can then run on the mirror port.
Why do you need MRP (Media Redundancy Protocol)? What happens to a PROFINET device if the power supply fails?
PROFINET devices usually have 2 ports for PROFINET cabling. The two ports are connected to each other by an internal 2-port switch module. If the power supply of a PROFINET device fails, communication in a network line is interrupted at this point. This problem can be avoided by using ring cabling with MRP technology.
If the power supply of a PROFINET switch fails, communication with all nodes connected to this switch is no longer possible.
This behavior is a very important difference to PROFIBUS networks!
Can I use the PROFINET switch in other industrial networks?
PROFINET is based on the Ethernet standard and the PROFINET switch can be used as a managed switch in normal TCP/IP networks, especially in industrial networks. In this case the PROFINET specific functions of the PROFINET switch are not addressed.
General Ethernet functions can be read out and parameterized via the web page of the PROFINET switch.
What is I&M data?
For PROFINET and also PROFIBUS, I&M stands for "Identification and Maintenance". The I&M data contains information about the PROFINET node. These are partly from the manufacturer (order number, serial number, etc.) but can also be described by the user (location, service contact, etc.).
The I&M data of all PROFINET nodes can be read out and evaluated with standard functions in the automation network.
The PROFINET switch has corresponding I&M data sets.
Why does the PROFINET switch have its own IP address and PROFINET name?
The PROFINET switch is a managed switch. The IP address is necessary to be able to address the switch as an active infrastructure component. You can reach the web page of the PROFINET switch via the IP address and PROFINET participants (e.g. a CPU or a programming device) can configure the switch and read information from the switch.
In PROFINET a device name can be used for the IP address for simplification, which is then synonymous with the IP address in a project.
Can PROFIsafe be transmitted via the PROFINET switch?
Yes, the PROFIsafe protocol considers all components between the PROFIsafe controller (CPU) and the PROFIsafe device as a "black channel", so any network devices and components can be used in the link. If transmission disturbances occur, the PROFIsafe components go into the safe state.
Which Ethernet cable types can be used for PROFINET?
Why do I need a PROFINET switch for a PROFINET network?
A PROFINET switch treats PROFINET telegrams with the highest priority and ensures that there are no telegram losses and that the jitter in the transmission remains low. This secures the PROFINET transmission and allows precise control in PROFINET systems.
A PROFINET switch supports mechanisms for neighbor detection (LLDP protocol) to detect and check the topology of the network. This ensures that the structure and network cabling of the plant are correct.
A PROFINET switch enables the device replacement of PROFINET components during operation. If a PROFINET device fails during operation, a replacement device is detected after installation based on its position in the topology (by the PROFINET neighbors) and automatically assigned its IP address and PROFINET name. Then the CPU can parameterize and restart the replacement device.
Since in automation systems often many similar devices are installed, the function "Find devices via LED display" supports the simple search for a station.
To increase the reliability of networks, PROFINET switches support the ring redundancy technology MRP (Media Redundancy Protocol).
The operation of a PROFINET network is also possible with unmanaged switches.
Can the PROFINET switch also transmit 1 GBit?
What is behind the PROFINET conformance classes A, B, C?
PROFINET is divided into conformance classes (CC). The conformance classes define meaningful functional scopes and are therefore decision criteria for system operators when using PROFINET components.
By previously defining an application in a CC, the user can make a selection of components that have clearly defined minimum properties.
For more information on the conformance classes, please refer to the PNO document "The PROFINET IO Conformance Classes - Guideline for PROFINET IO (Order No.: 7.041)".
Why should PROFINET devices have a PROFINET certification?
What is "device replacement during operation" and what role does the PROFINET switch play here?
If a PROFINET device fails during operation, a replacement device is detected after installation based on its position in the topology (by the PROFINET neighbors) and automatically assigned its IP address and PROFINET name. Thereupon the CPU can parameterize and restart the exchange device. The neighboring PROFINET devices, e.g. the switch, must support PROFINET to enable this function.
What do the LEDs BF and SF mean?
The "BF" LED indicates logical "bus errors", e.g. that the device has not received a configuration, the configuration is faulty or no PROFINET communication is possible at all (network error).
The "SF" LED indicates "collective errors". This can be e.g. a present PROFINET diagnosis.
Is the PROFINET switch "real-time capable"?
The PROFINET switch is "real-time capable" and supports PROFINET real-time class 2 for cyclic data exchange. PROFINET generally distinguishes between two main realtime classes: RT and IRT.
The "real-time capability" of an industrial bus system generally refers to the temporal accuracy of the cyclic IO transmission. For complex and distributed automation tasks, especially in the field of drive control, it is important that the cyclic data transmission always runs uniformly. Prolonged interruptions caused by other Ethernet traffic, such as video cameras or project transmissions, must not affect the behavior of the PROFINET IO cycle as far as possible.
PROFINET RT (Realtime) uses the standard technologies of managed switches (e.g. QoS) to always prioritize the important Ethernet telegrams of the bus communication over telegrams that are not time-critical.
PROFINET IRT (Isochronous Realtime) uses special PROFINET switches to keep the jitter and the clock of the IO cycle as accurate as possible in the network and to ensure a clock-synchronous and highly performant transmission.
The Helmholz PROFINET switch supports PROFINET RT, but not IRT.
Background
Under certain circumstances, if an attacker with direct (physical) access to the PROFINET network attacks the devices using the DCP services of the PROFINET protocol, this can lead to a permanent loss of communication capability between the PROFINET controller and the PROFINET device. The reason for this lies in the nature of the DCP service provided by the PROFINET protocol. This DCP service can be used to change or reset device parameters via DCP command. Examples of this are DCP-Set (NameOfStation) or DCP-Set (Reset-to-Factory). No safety functions are provided for the use of DCP in the existing PROFINET specification.
Impact
Under certain conditions, an attacker - with direct access to the OT network - can prevent the PROFINET controller from establishing communication with a PROFINET device and thus disrupt the operation of the device. Manual intervention by the user is required. The device is not destroyed by an attack, it is simply no longer accessible to the CPU. A new assignment of the PROFINET name or IP address can restore device operation.
Measures
Helmholz recommends that its customers introduce or review a strict access policy for the network. Access from other zones to the PROFINET network must be restricted, in particular DCP services must be blocked. This can be achieved using a firewall or a suitable VLAN configuration.
Newer versions of the PROFINET specification address this problem by introducing PROFINET security in security class 1. Helmholz will successively implement PROFINET security class 1 for all active PROFINET components and make new firmware versions available.
Further Information
PROFINET Security Advisory: Improper Access Control for DCP Services (PNO Identifier: PISA-001).
Where can the transmitter supply voltage be obtained from and how must a two-wire transmitter be connected?
Due to the design, the supply voltage of the transmitters to be connected must be provided separately.
As can be seen in the picture, this is possible, for example, with a TB20 potential distributor.

Error messages are generated during the configuration of my TB20 components. What is the best way to perform a quick diagnosis?
Which software is required?
To log in to the remote maintenance portal, you need our openVPN dial-in software shDIALUP or a web browser. Preferably use "Mozilla Firefox*" or "Google Chrome**" to establish a direct connection via the URL https://v2.myrex24.net. Only with shDIALUP you can realize a VPN connection to your REX routers in order to access your machines/equipment afterwards via the remote maintenance portal.
* Firefox is a registered trademark of the Mozilla Foundation.
** Chrome is a trademark of Google Inc.
The connection to the myREX24 portal or the REX device is slow or unstable.
shDIALUP is affected by another software/application. This could be an antivirus program installed on your Internet PC or another VPN client software already installed. As far as possible, always use current browser versions and the latest version of shDIALUP software.
The hardware of your dial-up computer and the Internet connection should generally provide good performance. A firewall and/or proxy server in your internal network structure may also affect the connection.
Which firewall settings are necessary to reach the myREX24 server?
The shDIALUP software and the REX routers establish an outbound TCP connection to the address https://v2.myrex24.net (5.39.123.21). To establish a secure connection to the myREX24 server, at least one of the following TCP ports (80, 1194 or 443) must be enabled for the VPN tunnel. If MAC address filtering is enabled in your firewall, it must be disabled or adjusted.
In the default setting, only the openVPN port 1194 is used. If this is blocked, the REX/shDIALUP configurations must be changed accordingly. There is no automatism, which polls all three ports cyclically and switches to a free one!
The "TAP-Windows Adapter V9" is missing or I get the message "No VPN Network Adapter was found in your computer...".
Get the Windows message: "No VPN Network Adapter was found in your computer. Typically there should be a Network Adapter called "TAP-Windows Adapter V9" showing in your Networksettings. Please reinstall this Software!", the "TAP-Windows Adapter V9" for shDIALUP is missing in your "Adapter Settings" in the "Network and Sharing Center". If your virus scanner did not allow the installation of this virtual TCP/IP interface or another software for VPN connections already occupies this interface, you may have to reinstall this adapter manually.
This is possible as follows:
- Navigate to the directory "C:\Program Files (x86)\Systems Helmholz\shDIALUP\ovpn".
- Execute the file "addtap.bat" with administration rights.
- After the installation the TAP adapter appears in the "Network and Sharing Center" under the "Adapter Settings". The TAP adapter must still be renamed to "shDIALUP".
With the shDIALUP software (dial-up client) it is no longer possible to log on to the myREX24 V1 portal. The following message appears: The Authentification failed. Please make sure you have the right username and password.
For security reasons (patched in portal version 1.7.2) a login via server authentication method "1" is no longer possible. Please set the "Server Authentication Method" in shDIALUP to 2.

Which modules must be selected on the PROFINET side, if in PROFIBUS 1. universal modules and/or 2. consistency are configured?
Answer 1:
When using universal modules, please note that these are only available on the PROFIBUS side. In the excerpt of the DP/PN Coupler web interface you can see in red that in the 5 universal modules at the first 3 slots no regular sizes have been parameterized, which are conform with the PN configuration. At the DP/PN coupler the SF LEDs are on in this case and a data transfer is not possible. The number of configured input or output bytes must correspond exactly with the other side.

Answer 2:
Depending on the application, consistent data transmission can also be selected for PROFIBUS.
On PROFINET side all modules are always consistent, so that here only the corresponding sequences and sizes (matching to the opposite side) have to be kept.
Where do I find the GSD-file for the DP/DP coupler?
What is the Ethernet Cable Guard?
What is the determined "cable status"?
How does the measurement of the cable status work?
The output of the "cable status" is based on an algorithm - developed by the company LAPP - which collects, converts and continuously evaluates measured values from various physical transmission parameters. The measured values consist, for example, of protocol-related transmission parameters and/or a quality indicator, which can be calculated from statistics of the level values.
The "user data" (data transmission) is neither influenced nor evaluated. If a teach-in is carried out, the line is calibrated and limit values are set according to the parameters. If these limit values are violated during operation, correction values are incorporated into the algorithm. It is important that the algorithm takes historical values into account. This leads to the following consequence: If a cable is subjected to such a mechanical load (far above the specifications) that it cannot physically "age", the "prediction" may be delayed. Example: if the data cable is cut with a side cutter, the cable "ages" abruptly; logically, no "prediction" can be made in advance.
What exactly does the "cable status" indicate?
How do customers benefit from using Ethernet Cable Guard?
What can the Ethernet Cable Guard do?
For which industries is the Ethernet Cable Guard suitable?
The Ethernet Cable Guard can be used wherever data cables are used. Especially in moving applications with high speeds and strong torsion. Such applications are often found in (intra-)logistics, the automotive sector and medical technology. In principle, however, it is suitable for a wide range of industries. Where is the Ethernet Cable Guard used?
The Ethernet Cable Guard is particularly suitable for data cables that are constantly exposed to "stress", such as
- Movements with high speeds and accelerations
- Changing motion sequences
- Rotations with very high axial torsion angles
- Fast cycle times
- small bending radii
The monitored data cable is also used in critical processes where high to extremely high downtime costs or even personal injury would occur in the event of a standstill.
The Ethernet Cable Guard is suitable
- for use in Ethernet-based automation technology networks.
- for monitoring data cables in dynamic applications.
- for EtherCAT, EtherNET/IP, PROFINET and many other Ethernet-based applications.
- for use in the control cabinet.
Where is the Ethernet Cable Guard used?
The Ethernet Cable Guard is particularly suitable for data cables that are constantly exposed to “stress,” such as:
- movements with high speeds and accelerations
- changing motion sequences
- rotations with very high axial torsion angles
- fast cycle times
- small bending radii
The monitored data line is also used in critical processes where, in the event of downtime, high to extremely high failure costs or even personal injury could occur. The Ethernet Cable Guard is suitable:
- for use in Ethernet-based automation networks.
- for monitoring data cables in dynamic applications.
- for EtherCAT, EtherNet/IP, PROFINET, and many other Ethernet-based applications.
- for use in control cabinets.
Which cables can be monitored with the Ethernet Cable Guard?
Can the Ethernet Cable Guard monitor any type of data cable?
Can the Ethernet Cable Guard be used on multi-axis kinematics / robots?
Does Ethernet Cable Guard also work across multiple connection points?
Can Ethernet Cable Guard only monitor one data cable?
How can costs be saved with the Ethernet Cable Guard?
How high are the cost savings by using the Ethernet Cable Guard?
This depends, for example, on the previous maintenance cycles, the size of the machinery, the number of critical connection points, the expected costs in the event of a production shutdown and much more. It also depends on the respective scenario in which the customer operates, the goods produced, their critical failure forecast and many other factors.
By using predictive maintenance solutions, maintenance operations can be optimized and costs reduced by using fewer personnel resources. In addition, planned downtimes can prevent unforeseen machine failures and thus downtime costs.
Does the Ethernet Cable Guard affect the data transmission?
How long can the cable to be monitored be?
What happens if the Ethernet Cable Guard has no power supply?
Subscribe to our newsletter now!
Receive regular news on products, promotions and solutions from the world of Helmholz.