--- title: "Schneider - How to bring your PLC online" slug: "schneider-how-to-bring-your-plc-online" description: "This page describes how to use an INSYS router, here the MIRO model, to establish a remote access connection (cellular radio) via the icom Connectivity Suite - VPN to a Schneider Electric PLC, here the M221 model." updated: 2026-03-17T14:42:11Z published: 2026-03-17T14:42:11Z canonical: "docs.insys-icom.com/schneider-how-to-bring-your-plc-online" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.insys-icom.com/llms.txt > Use this file to discover all available pages before exploring further. # Schneider - How to bring your PLC online ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(255).png) ## What do I want to achieve? I have a PLC (programmable logic controller) of the type Schneider M221 and would like to be able to access it remotely via cellular radio. > [!NOTE] > Other WAGO controllers? > > The procedure described here was verified with a Schneider M221 controller. The procedure for other Siemens controllers is identical or very similar. ## **How do I accomplish this?** With an INSYS router, a SIM card and the VPN service icom Connectivity Suite, remote access to the control system via cellular radio is possible. ### **Required hardware** **You will need the following in addition to your controller to be able to access it remotely.** - 1 INSYS router, e. g. [MIRO L-200](https://www.insys-icom.com/en/products/router-gateways/router/miro-router/) - 1 suitable [cellular antenna](https://www.insys-icom.com/en/accessories/antenna/) - 1 [M2M SIM card](https://www.insys-icom.com/en/products/managed-services/m2m-sim-service/) in industrial quality - 1 Ethernet cable - 1 [power supply unit](https://www.insys-icom.com/en/accessories/power-supplies/) or-power supply (12-24 V DC) - 1 Configuration PC with browser (for initial setup, can also be the remote access PC) - 1 Remote access PC with browser and PLC-specific software, such as e. g. EcoStruxure Machine Expert Basic ### Preparation In our exemplary configuration, which is described in the following steps, we use a typical installation as a basis for the IP address of the controller. We give the router an IP address in the same network. [Netmapping](/kb/docs/en/icom-connectivity-suite-vpn-addressing-en) is used to create a virtual IP network via which the controller and the router (or other devices) in the network behind the router can be accessed remotely. - IP address of the Schneider controller: 10.10.1.26/24 - IP address of the INSYS router: 10.10.1.1/24 - IP network accessible from remote: 192.168.22.0/24 ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(256).png) #### icom Connectivity Suite **How to log in to the icom Connectivity Suite and add a remote access PC and router.** 1. If you do not already have an account for the **icom Connectivity Suite**, register on the portal. See this [Configuration Guide](https://docs.insys-icom.com/docs/en/registration-with-the-icom-connectivity-suite-en). 2. Sign in to the [portal](https://connectivity.insys-icom.de). 3. Add the PC, from which you want to access the controller, to the VPN network. See this [Configuration Guide](https://docs.insys-icom.com/docs/en/adding-a-third-party-device-pc-to-the-icom-connectivity-suite-vpn-en). > [!NOTE] > Please note! > > You do not have to set an *accessible IP* for the remote access PC, since access to the PC from the VPN network is not necessary. 4. Add the router, which you want to use to access the controller, to the VPN network. See this [Configuration Guide](https://docs.insys-icom.com/docs/en/adding-an-insys-router-with-icom-os-to-the-icom-connectivity-suite-vpn-en). > [!NOTE] > Please note! > > - If you assign a device code here, keep it in mind for the subsequent configuration of the router. > - Enter as *accessible IP* the IP address, which the router should get in the network accessible from remote, in this case **192.168.22.1**. > - Check *Netmapping*. > - Enter as *Router/LAN IP* the IP address, which the router should get in the local network, which also contains the controller, in this case **10.10.1.1**. > > ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(259).png) #### Configuration PC **How to prepare your configuration PC.** You will need a PC with a free Ethernet socket. A DHCP client should be activated on the PC; otherwise you must set up a static IP address in the address range 192.168.1.0/24. The IP address 192.168.1.1 is already occupied by the router. #### Router **How to commission your router.** > [!NOTE] > The router should be in default settings for this configuration! > > Reset the router to [default settings](/kb/docs/en/resetting-to-defaults-en) in case it has already been used. 1. Insert the SIM card into the router (for routers with two SIM card slots, make sure that you insert the SIM card into SIM1). 2. Install the router on the DIN rail (installation notes are available in the [Installation and User Manual](https://docs.insys-icom.com/docs/en/miro-info-en)). 3. Connect the antenna (when using an antenna on routers with two antenna sockets, make sure that you connect the antenna to LTE1). 4. Connect the configuration PC to the router to socket ETH1 using an Ethernet cable. 5. Connect the power supply to terminals V+ (or VIN, positive) and V- (or GND, negative). The uppermost LED **PWR (Power)** should light now and signal that the router is supplied with power. **How to configure your router using the Startup wizard** 1. Open a new browser window or tab - keep the browser window with the **icom Connectivity Suite - VPN** open. 2. Enter https://insys.icom into the address bar of the browser. 3. Click on the welcome screen on To Startup wizard. > [!NOTE] > Please note! > > If the welcome screen is not displayed, you may also start the Startup wizard in the *Wizards* → *Startup wizard* menu. 4. Click in step 1 - System time - on NEXT - this takes over the system time from the configuration PC and configures a regular update of the time. 5. Enter in step 2 - Authentication - a user name and a safe password for future access to the router and click on NEXT . 6. Select in step 3 - Internet connection - the interface you want to use to establish the connection, here **LTE - SIM1**, enter a PIN for the SIM cad if required, select the APN and click on NEXT . ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(149).png) 7. Enable in step 4 - VPN connection - the *Configure VPN* switch, select as *Type of VPN connection* the **icom Connectivity Suite**, select *Download configuration automatically* and enter *Customer name* as well as *Device code* or *Default code*. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(150).png) If you did not specify a device code when registering the router, the default code will be used here. Customer name and default code can be found in the **icom Connectivity Suite - VPN** on the *System* → *My VPN Hub* page in the *Account Information* field. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(152).png) Click on NEXT . 8. Click in step 5 - LAN connection - on NEXT - the LAN connection will be configured automatically by the **icom Connectivity Suite - VPN**. 9. Step 6 - icom Router Management - allows to configure your router for the [icom Router Management](https://www.insys-icom.com/en/products/managed-services/device-management/). For this purpose, the router must first be set up as described [here](/kb/docs/adding-routers-to-icom-router-management). 10. Click on RUN WIZARD. The Startup wizard is executed and displays the progress of the configurations it has made. The Ethernet interface of the router will be reconfigured. After clicking on EXIT WIZARD, the router can not be accessed via the Ethernet connection from the configuration PC any more, as it gets above configured *Router/LAN IP* in the network of the controller. From now on, the router can only be accessed from the remote access PC via the **icom Connectivity Suite - VPN**. The router should be indicated as **Online** in the device list in the portal of the **icom Connectivity Suite - VPN** (*VPN* > *Devices* menu) after a few minutes. #### PLC **How to check the IP settings of your Schneider controller.** > [!NOTE] > Compatibility of the controller with the PLC software! > > Make sure that the controller firmware is up-to-date and works with the PLC-specific software used (in this case EcoStruxure Machine Expert Basic V1.3). Establish a local direct connection to the controller, open a command prompt or terminal window and send a Ping to the IP address of the controller (in our example **10.10.1.94**): `> ping 10.10.1.94` If the ping is received successfully, you have verified the IP address of the controller. #### Remote access PC **How to configure the PC with which you want to access your controller remotely for a connection with the **icom Connectivity Suite - VPN**. The installation and configuration of the PLC-specific EcoStruxure Machine Expert Basic V1.3 software is not part of these instructions.** Use this [Configuration Guide](/kb/docs/en/configuring-a-windows-pc-for-a-connection-to-the-icom-connectivity-suite-vpn-en) to set up a Windows PC for a connection to the **icom Connectivity Suite - VPN**. Proceed in the same way for a computer with a Linux operating system. It is important to download the OpenVPN configuration file generated by the **icom Connectivity Suite - VPN** and import this configuration file into the OpenVPN software. Instructions for iOS and Android are available [here](https://docs.insys-icom.com/docs/en/configuring-third-party-devices-for-a-connection-to-the-icom-connectivity-suite-vpn-en). ## How do I establish the remote access? 1. To connect the router, proceed as described [above](/kb/docs/en/how-to-bring-a-wago-plc-online#router) and connect the controller to the router via Ethernet. 2. On the remote access PC, establish the OpenVPN connection as described [here](https://docs.insys-icom.com/docs/en/configuring-a-windows-pc-for-a-connection-to-the-icom-connectivity-suite-vpn-en#establishing-the-openvpn-connection). **How to establish remote access to the user interface of the controller.** Open a command prompt or terminal window and send a Ping to the remote access address of the controller (in our example **192.168.22.26**): `> ping 192.168.22.26` If the ping is received successfully, you have verified the access to the controller. > [!NOTE] > Access to other devices in the network! > > If there are other devices in the local network on the router, you can also access them via the IP network **192.168.22.0/24** that can be reached for remote access. For example, if another controller in the local network has the IP address **10.10.1.23**, you can access it via the remote access address **192.168.22.23**. **How to establish remote access from EcoStruxure Machine Expert Basic to the controller.** In order to program the controller, it is necessary that the PC on which the required EcoStruxure Machine Expert Basic is installed is located in the local network of the controller or has remote access to this network. In the following, we describe remote access to the controller in this network. 1. Start Machine Expert and open the project of the controller to which you want to establish remote access. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(260).png) 2. Change to *ETH1* to verify the settings for IP address and Gateway of the controller and adjust it if necessary. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(261).png) 3. Add the connection to the controller by opening *Commissioning*, enter under *Remote Lookup* the IP address **192.168.22.26** and confirm with a click on *Add*. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(262).png) 4. Select the newly added controller and start the connection by clicking on *Login*. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(263).png) When the connection has been established, the message *Connection is established* is displayed. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(264).png) You can now monitor the controller and make changes to its programming. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(265).png) The connection can be terminated again with a click on *Logout* under *Commissioning*. ## How do I set up a web proxy access to the controller? **How to set up a web proxy access to the controller** A [Web-Proxy](/kb/docs/icom-connectivity-suite-vpn-endpoints-webproxies) enables access to the user interface of the controller also from a device that is not in the VPN network of the **icom Connectivity Suite - VPN**. > [!WARNING] > Security risk! > > The controller is accessible via the Internet when using a web proxy. > > The encrypted connection is only protected against Internet access by a password. This is either the device code of the INSYS routers or, if the password has been deactivated in the web proxy, the password of your application. Obey the security of your application and the rules for strong passwords. We do not recommend this function for applications that are relevant to security. To access the user interface of your controller via a web proxy, the web server must be activated on your controller. 1. Log in to the [Portal](https://connectivity.insys-icom.de) of the **icom Connectivity Suite - VPN**. 2. Click on the *VPN* → *Endpoints (Webproxies)* page on + ADD ENDPOINT. 3. Select the *Device* network of your router that you previously added in **icom Connectivity Suite - VPN**. 4. Select **HTTPS** as the *Protocol* for accessing the endpoint. 5. Enter the IP address that is accessible from remote under *IP in VPN*, in our example **192.168.22.26**. 6. Enter the *Port* that is used for access to the device, this is for HTTPS **443**. 7. Enter an *Endpoint name* that uniquely describes the endpoint so that it can be distinguished from others. 8. Activate the *Add webproxy* switch and click NEXT. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(481).png) 9. Change the randomly generated string in *Name in URL* to a ‘descriptive’ address. The resulting URL is displayed as a preview below the field. 10. For *Basic Authentication*, optionally select **No Authentication** to disable the password request by the **icom Connectivity Suite - VPN**. Please note the information above! 11. Click on CREATE to add the endpoint. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(482).png) You can now access the user interface of your controller directly via the link in the *Webproxy call* column, even if the device used is not in the VPN network of the **icom Connectivity Suite - VPN** or the VPN connection does not exist. ## What to do if it doesn't work? **If remote access to the controller does not work, you can troubleshoot the fault using the following methods:** - Are remote access PC and router indicated as **Online** in the device list of the **icom Connectivity Suite - VPN** (*VPN* > *Devices* menu)? - Does remote access to the router work via the address [**https://192.168.22.1**](https://192.168.22.1)? - Is it possible to ping the controller in the local network of the router? To do this, go to the *Administration* → *Debugging* menu and enter for the **Ping** *Tool* the local address of the controller **10.10.1.26** as *Parameter*. - Does local access to the controller work via the local address **10.10.1.26** from a PC in the local network of the controller? - Open the *Status* → *Dashboard* page and check the necessary connections. ![](https://cdn.document360.io/c690fe99-a3eb-474c-a449-c2c75e5df119/Images/Documentation/image(154).png) ## Further configuration options In this [Configuration Guide](/kb/docs/en/establishing-a-connection-using-a-key-switch-signal-en), you will learn how to configure the router so that it can be enabled locally with a key switch for an Internet connection - and thus for a connection to the **icom Connectivity Suite - VPN** - in order to be able to authorize remote access locally, for example. Standard IP address: https://192.168.1.1; login depending on configuration; default for earlier firmware versions: *User name*: **insys**, *Password*: **icom**