Configuring Rockwell E1plus Profibus Slaves on an S7-1500 Master: Resolving the Default Address 126 Conflict
This technical reference covers the integration of Rockwell Automation E1plus intelligent overload relays equipped with 160-PD1 Profibus-DP communication modules as DP slaves on a Siemens SIMATIC S7-1500 Profibus master. The article addresses the specific commissioning obstacle where E1plus relays ship from the factory with Profibus node address 126, while TIA Portal restricts configurable DP addresses to the range 1-125. The supported remedy is to change the node address directly on the E1plus relay before adding the device to the TIA Portal hardware configuration; the S7-1500 master cannot assign the service address and TIA Portal will not accept address 126 as a runtime address. The procedure, hardware prerequisites, and diagnostic flow documented here apply to TIA Portal V17 through V20, S7-1500 CPUs (6ES751x-1xx02 through 6ES751x-1xx06 firmware), and E1plus relays with 160-PD1 modules at PROFIBUS module firmware revision 1.001 or later.
1. Profibus DP Address Space and the Meaning of 126
PROFIBUS DP (IEC 61158 Type 3) uses a 7-bit station address space. The master and each slave occupy one address from 0 to 127, but the address space is partitioned:
| Address | Allocation | Runtime Use |
|---|---|---|
| 0 | Reserved | Not used for runtime DP nodes on Class 1 masters |
| 1-125 | Valid DP node addresses | Masters and slaves at runtime |
| 126 | Default service address | Unconfigured (factory-default) slave address; used for Set_Slave_Add service |
| 127 | Broadcast | Not assignable to any physical device |
When a DP slave is delivered from the factory, it powers up with address 126 so that a commissioning tool (a Siemens COM PROFIBUS, TIA Portal, or a Rockwell Studio 5000 Logix Designer with the appropriate AOP) can detect and re-address it. After a unique address in 1-125 is assigned, the device stores it in non-volatile memory and stops responding to the service address. Address 126 is not assignable on the S7-1500 master because the master itself occupies one address in the 1-125 range and a slave permanently at 126 would conflict with the service function used for device replacement without programming device.
2. Hardware Architecture: S7-1500 Master and E1plus Slaves
The integration combines a Siemens Profibus DP master with Rockwell Profibus DP slaves on one RS-485 segment. Understanding both sides is necessary to avoid timing and GSD mismatches.
2.1 Siemens S7-1500 DP Master
The S7-1500 CPU does not include an onboard Profibus interface on most part numbers. A Profibus master is added through one of the following communications processors:
- CP 1542-5 (6GK7542-5FX10-0XE0): plugs into the S7-1500 backplane, supports DP master or DP slave, baud rates 9.6 kbit/s to 12 Mbit/s. Compatible with TIA Portal V15.1 and later. Module firmware V2.0 or higher is recommended for V18/V19/V20 projects.
- CM 1542-5 (6GK7542-5FX00-0XE0): older module, supports DP master only, baud rates 9.6 kbit/s to 12 Mbit/s. Used with S7-1500 ET 200MP stations when the CPU does not require Profibus master capability.
Both modules are configured as a Profinet-to-Profibus gateway or as a pure DP master in the TIA Portal device view. The CP 1542-5 owns its own DP master interface and uses a separate PROFIBUS address from the CPU's PROFINET interface; the DP master address is typically 1 or 2, leaving 3-125 for slaves.
2.2 Rockwell E1plus with 160-PD1 Communication Module
The Allen-Bradley E1plus electronic overload relay (Bulletin 193/592) is a microprocessor-based motor protection relay. It is shipped as a stand-alone overload, and Profibus-DP connectivity is provided by a snap-on 160-PD1 communication module that mounts on top of the E1plus control module. The 160-PD1 provides a 9-pin D-sub PROFIBUS DP port and supports baud rates from 9.6 kbit/s to 12 Mbit/s with auto-detect.
Key 160-PD1 parameters relevant to this integration (per the 160-PD1 Profibus-DP Communication Module User Manual, publication 160PD1-UM011):
- Factory default node address: 126 (decimal)
- Configurable range: 1-125
- Power supply: drawn from the E1plus control module; no separate 24 VDC required for the bus electronics
- Baud rate: auto-detect; no DIP switch setting required
- Termination: internal, switchable from the module cover
- GSD file: ROCK0913.GSD, revision 1.1 or later
- Supported I/O slots: typically 2 word input and 2 word output cyclic data, plus a diagnostics slot
The 160-PD1 stores the node address in non-volatile memory on the E1plus control module base unit. The address is retained through power cycles. There is no "Set_Slave_Add" service supported from the S7-1500 side; the 160-PD1 is re-addressed by manually editing it on the device before placing the device into the segment that contains the S7-1500 master, or by isolating the slave on a small service segment and using a Profibus commissioning tool.
3. Why TIA Portal Refuses Address 126
When the E1plus is brought online in the Profibus segment with its default address 126, the CP 1542-5 master will poll the slave at address 126. The slave responds with a diagnostic indicating "Slave present at service address; awaiting parameter assignment". TIA Portal's online "Accessible nodes" function may list the device, but the device properties dialog enforces the 1-125 range and refuses to commit a hardware configuration containing 126.
This is by design. Address 126 is reserved in PROFIBUS DP for:
- Initial commissioning of unconfigured slaves via the Set_Slave_Add service.
- Device replacement on systems where the replacement device ships at 126 and is re-addressed automatically by the master when the configured slot assignment is uploaded from the master using PROFIBUS DP-V1 parameter assignment.
The S7-1500's TIA Portal implementation does not include the Set_Slave_Add flow as part of standard DP master operation. Device replacement without a programming device is therefore not supported for slaves that arrive at 126; the address must be set locally on the device.
0x0B ("Invalid slave configuration"). The only correct path is to change the slave's address before going online.4. Prerequisites for Integration
Before starting, verify the following items. The list is the minimum set; missing any item is the most common cause of "no communication" faults on first try.
| # | Item | Specification |
|---|---|---|
| 1 | TIA Portal | V17, V18, V19, or V20 with HSP 0365 (CP 1542-5) installed |
| 2 | S7-1500 CPU | Firmware V2.9 or higher (V3.0+ recommended for V20 projects) |
| 3 | CP 1542-5 | Firmware V2.0 or higher |
| 4 | 160-PD1 GSD file | ROCK0913.GSD, revision 1.1 or later, installed in TIA Portal under Options > Manage device description files (GSD) |
| 5 | E1plus with 160-PD1 | 160-PD1 module firmware 1.001 or later; relay firmware compatible with the motor full-load current range |
| 6 | Profibus cable | Belden 3079A or equivalent, purple, twisted pair, 150 ohm characteristic impedance |
| 7 | Connectors | 9-pin D-sub with switchable termination; 2 connectors required for a bus segment with more than one device |
| 8 | Termination | Active termination at both ends of the segment, ON at the two physical end devices, OFF on all intermediate devices |
| 9 | Shield grounding | 360-degree bonding at every entry/exit point to a low-impedance ground bar |
| 10 | Baud rate | All devices on the segment must auto-detect to the same rate; 1.5 Mbit/s is the practical maximum for longer cable runs |
| 11 | Power | E1plus control module powered from the contactor coil or external 24 VDC; 160-PD1 is powered from the E1plus base |
| 12 | Commissioning tool | Handheld addressing tool (e.g., Profibus tester from Softing or Indu-Sol) or a dedicated service segment with a master and 160-PD1 manual address procedure |
5. Changing the Node Address on the E1plus Relay (160-PD1)
The 160-PD1 provides an address-setting procedure that does not require a Profibus master. The procedure writes the new address to the non-volatile memory of the E1plus base unit. There are two common methods; use Method A when you have a Profibus handheld tester, and Method B when only the 160-PD1 module itself is available.
5.1 Method A: Handheld Profibus Tester (recommended)
- Disconnect the 160-PD1 from the operational Profibus segment that includes the S7-1500. This isolates the slave so that no master is contending for the bus at the moment of re-addressing.
- Power the E1plus control module from its normal supply (contactor coil or 24 VDC).
- Connect the handheld tester to the 160-PD1's 9-pin D-sub port using a Profibus drop cable. Activate the bus termination on the tester if it is the only device on the segment.
- From the tester's main menu, select Slave diagnostics > Set slave address.
- Enter the new Profibus address in the range 1-125. Choose a number that is not in use by the CP 1542-5 master (commonly 2 if the master is at 1) and not reserved for other slaves in the segment. Document the assignment in the network address map.
- Confirm the write operation. The 160-PD1 stores the new address in non-volatile memory and resets its Profibus stack. The tester reports
Set_Slave_Add successfulat the new address. - Power-cycle the E1plus control module (remove and reapply control power) to confirm the address is retained after a cold start.
5.2 Method B: Service Segment with a Temporary Master
- Build a small service segment consisting of a Profibus master (any DP master will work, including a laptop with a Profibus card such as a Siemens CP 5512 or a Softing PROFIBUS Master) and the E1plus with 160-PD1. Keep this segment physically separate from the operational Profibus network that includes the S7-1500.
- Set the temporary master to a non-conflicting address (commonly 1). Activate termination at the master end of the service segment only.
- Power up the E1plus. The master should detect the slave at address 126 (factory default) and report it in the live list as a slave "present at service address".
- Open the master's configuration tool. For a Siemens laptop with COM PROFIBUS or TIA Portal in online mode, navigate to Online > Accessible nodes. The 160-PD1 should appear at address 126. Right-click the device and select Assign PROFIBUS address. Enter the target address (1-125) and confirm.
- For a Rockwell environment with Studio 5000 Logix Designer, the 160-PD1 must first be added to the I/O tree from the AOP. The 160-PD1 will be detected at 126 and the AOP includes a Change Node Address button on the Connection tab that drives the Set_Slave_Add service on the temporary master.
- After the write, power-cycle the E1plus and confirm that the temporary master now sees the slave at the new address and no longer responds to 126.
6. Installing the GSD and Adding the E1plus to TIA Portal
After the address is set, install the Rockwell GSD file into TIA Portal and add the 160-PD1 as a DP slave.
- Download
ROCK0913.GSDfrom the Rockwell Automation Product Compatibility Download Center (PCDC) or the included media. Confirm the file revision matches the 160-PD1 module firmware. - Open the TIA Portal project. From the menu, choose Options > Manage device description files (GSD).
- Set the source path to the folder containing the
ROCK0913.GSDfile. Click Install. Wait for the "Installation of device description files was successful" message. TIA Portal indexes the new GSD under Other field devices > PROFIBUS DP > General > Rockwell Automation in the hardware catalog. - Open the Devices & Networks editor. Drag a CP 1542-5 from the catalog onto the S7-1500 CPU rack slot. The CP appears as a sub-module of the CPU.
- On the CP 1542-5, click the PROFIBUS interface sub-module and, in the Properties pane under PROFIBUS address, set the master address (commonly 1 or 2) and the baud rate. Select "Automatic" for baud rate detection unless the segment has a fixed rate requirement.
- Switch to the Network view. From the hardware catalog, navigate to Other field devices > PROFIBUS DP > General > Rockwell Automation > 160-PD1. Drag the 160-PD1 device into the network pane.
- Click the new 160-PD1 device. In the Properties pane, set the PROFIBUS address to the same value assigned to the physical device in Section 5. TIA Portal accepts any value in 1-125; values outside this range are rejected with a validation error.
- Click the Not assigned placeholder on the 160-PD1 device and select the CP 1542-5 PROFIBUS interface as the master. TIA Portal draws the Profibus connection between the master and slave.
- Open the device view for the 160-PD1. Configure the cyclic I/O slots to match the E1plus data layout. The default slot mapping for the 160-PD1 is:
| Slot | Type | Length | Content |
|---|---|---|---|
| 0 | Input | 2 words (4 bytes) | Status word 0, Status word 1 (motor state, currents, thermal capacity) |
| 1 | Input | 2 words (4 bytes) | Status word 2, Status word 3 (phase currents L1/L2/L3, ground fault) |
| 2 | Output | 2 words (4 bytes) | Command word 0, Command word 1 (remote trip/reset, parameter set select) |
| 3 | Output | 1 word (2 bytes) | Auxiliary output commands (e.g., trip relay override) |
- Compile the project. TIA Portal generates a hardware configuration that is downloaded to the S7-1500 CPU along with the CP 1542-5 firmware configuration.
7. Commissioning and Verification
With the address set on the E1plus and the slave added to TIA Portal, proceed with the online commissioning checks. Run the steps in order; do not skip the bus diagnostics step even if everything appears to work, because intermittent faults at higher baud rates (3 Mbit/s and 12 Mbit/s) often hide in the signal quality.
7.1 Download the Configuration
- Connect the TIA Portal engineering station to the S7-1500 CPU over PROFINET (the CPU's PROFINET interface) or over the CP 1542-5's Profibus interface if the CPU is reachable that way.
- Right-click the S7-1500 device and select Download to device > Hardware configuration. Confirm the target device fingerprint.
- After the download completes, the CPU restarts the CP 1542-5. The CP brings the Profibus master online with the configured baud rate.
7.2 Online Diagnostics in TIA Portal
- In the Devices & Networks editor, select the CP 1542-5 and switch to Online & Diagnostics.
- Open the PROFIBUS diagnostics entry. Confirm the CP reports the segment as "Running" and shows the live list of detected slaves.
- For each 160-PD1, expand the diagnostic entry and confirm:
| Check | Expected Result | Fault if Not |
|---|---|---|
| Master sees slave at configured address | Yes | Wrong address, bad cable, or termination issue |
Slave diagnostics 0x00 (no error) |
Yes | See Section 9 fault table |
| Cyclic input data refreshing | Yes, input words update at the configured update time | Wrong slot configuration; check GSD module selection |
| Cyclic output data accepted | Yes, no 0x0B invalid configuration |
Slot length mismatch; check GSD slot configuration |
| Slave baud rate matches master | Yes | Manual baud rate override on the 160-PD1; re-enable auto-detect |
7.3 Bus Signal Quality Verification
Connect a Profibus signal analyzer (Indu-Sol PROFIBUS-INspektor, Softing Profibus Tester, or similar) at one end of the segment and verify:
- Signal amplitude at both ends is at least 2.5 V peak-to-peak at 1.5 Mbit/s and 12 Mbit/s.
- Number of telegram repetitions per 1,000 telegrams is below 1.
- No illegal bus idle voltage (must be 1.0 V +/- 0.1 V on the differential pair).
- Number of CRC errors per minute is zero.
8. Multi-Master and Multi-Slave Segment Considerations
When the E1plus relays are placed on a Profibus segment that also carries one or more additional DP masters (for example, a second S7-1500 with its own CP 1542-5, or a Rockwell ControlLogix 1756-DHRIO module acting as a Profibus master), the address plan must be coordinated across the entire segment. The CP 1542-5 master only addresses its own configured slaves but shares the bus with the other master; the masters arbitrate the token between them according to the lowest-address and highest-address parameters in the bus parameters dialog.
For multi-master configurations on S7-1500, the recommended approach is documented in the TIA Portal help under "Configurations involving several DP master systems (S7-300, S7-400, S7-1500)", available at the official TIA Portal V20 documentation. Key rules:
- Each master occupies a unique address in 1-125. The TIA Portal hardware configuration validates that no two masters on the same segment share an address.
- The highest station address (HSA) of the segment must be set to the largest configured address, not the default 126. This reduces the token rotation time and improves bus efficiency.
- Cross-master direct data exchange (DP-DX) between slaves of different masters is possible but requires the slaves to be configured as "publisher" on one master and "subscriber" on the other in TIA Portal.
- Repeaters do not extend the bus address space; the address 1-125 applies to the entire physical Profibus network across repeaters.
9. Common Faults and Diagnostic Codes
Below is a troubleshooting matrix for the most common faults observed when integrating 160-PD1 modules on an S7-1500 DP master. The Profibus diagnostic codes follow the IEC 61158 standard.
| Code (hex) | Meaning | Probable Cause | Action |
|---|---|---|---|
| 0x00 | No error | Normal operation | No action |
| 0x02 | Slave not reachable | Cable break, terminator off, address conflict, no power to 160-PD1 | Check 24 VDC to E1plus, check termination at both ends, confirm address with handheld tester |
| 0x05 | Invalid slave response | GSD revision mismatch with module firmware, baud rate mismatch | Update GSD to match 160-PD1 module firmware; confirm auto-baud detect has locked at the configured rate |
| 0x0A | Parameter assignment error | Slot configuration in TIA Portal does not match the GSD module selection | Re-import the GSD and rebuild the device configuration; check slot lengths |
| 0x0B | Invalid slave configuration | Address 126 used as runtime address; module does not support the requested I/O length | Re-address the slave to 1-125; reduce I/O to match GSD module selection |
| 0x0C | Diagnostic from station not present | Slave lost power or was disconnected from the segment during operation | Restore power, check connector seating |
| 0x0F | Watchdog timeout | Cyclic data exchange interrupted; bus error or master CPU stopped | Check CPU run state, check bus signal quality, check for excessive retries |
| 0x15 | Invalid slot | A configured slot is not supported by the GSD | Re-check the slot configuration against the GSD file |
| 0x16 | Manufacturer-specific diagnostic | E1plus trip state, ground fault, phase loss, thermal overload | Read the 160-PD1 status words and clear the trip condition at the relay |
9.1 TIA Portal Specific Diagnostic Indicators
In TIA Portal's Online & Diagnostics view, the CP 1542-5 surfaces bus-level diagnostics under the "PROFIBUS" entry. If the bus shows "Bus fault, slave not found at address X" repeatedly, the most likely causes are:
- The 160-PD1 has reverted to address 126 (some firmware versions revert after a factory reset of the E1plus base unit).
- The 160-PD1 is not powered (check the green status LED on the module; if the LED is off, the E1plus base has no control power).
- The Profibus connector is reversed (pin 3 and pin 8 swapped). The 160-PD1 uses standard 9-pin D-sub pinout with pin 3 = B-line and pin 8 = A-line.
- The baud rate is locked to a rate the master does not support (very rare, but check the 160-PD1 module if it has a baud rate switch under the cover).
10. Safety, Best Practices, and Long-Term Maintainability
- Document the address map. Maintain a spreadsheet with one row per E1plus, listing the Profibus address, the motor it protects, the motor tag name, the S7-1500 input/output byte offset, and the last date the address was verified.
- Label the device. Print a label with the Profibus address and affix it to the 160-PD1 module. Field engineers will not have the commissioning tool when troubleshooting a year from now.
- Use a single baud rate. Auto-detect works, but a fixed baud rate eliminates one variable during commissioning. The practical maximum cable length is 200 m at 1.5 Mbit/s; 1,000 m at 93.75 kbit/s; 1,200 m at 9.6 kbit/s. Choose the slowest rate that meets the application cycle time requirement.
- Do not run Profibus next to VFD output cables. The high dV/dt from a VFD output cable couples noise into the Profibus cable and causes intermittent CRC errors. Maintain at least 200 mm of separation and cross at 90 degrees when separation is not possible.
- Verify ground bonding. The shield must be bonded at the cabinet entry to a clean ground bar. Floating shields are the single most common cause of intermittent Profibus faults in industrial environments.
- Use the E1plus diagnostic slot. Enable the 160-PD1 manufacturer-specific diagnostic in TIA Portal (GSD parameter "Diag_Enable"). This brings the manufacturer-specific diagnostic (0x16) into the CPU's diagnostic buffer, including phase loss and thermal overload events.
- Plan for spare parts. A spare E1plus with a 160-PD1 arrives at address 126. If the spare is to be hot-swapped, the technician must set the address on the spare to match the unit it replaces before commissioning. The Set_Slave_Add flow from the master is not used in this integration.
11. Frequently Asked Questions
Why does my E1plus show up at Profibus address 126 in TIA Portal's "Accessible nodes" but refuse to add to the hardware configuration?
Address 126 is the factory default service address for unconfigured Profibus DP slaves. TIA Portal only accepts addresses 1-125 in the hardware catalog because 126 is reserved for the Set_Slave_Add service. The slave must be re-addressed to a value in 1-125 using a handheld Profibus tester or a temporary DP master; TIA Portal cannot perform the re-addressing step.
Can the S7-1500 master re-address the E1plus automatically when the device is replaced in the field?
No. The S7-1500 with CP 1542-5 does not implement the Set_Slave_Add service as part of standard DP master operation, and the 160-PD1 does not support being re-addressed from the master in a hot-swap scenario. Every replacement E1plus must be addressed locally with a handheld tester before being placed on the segment.
What TIA Portal version supports the 160-PD1 GSD file?
The 160-PD1 GSD (ROCK0913.GSD) is imported through Options > Manage device description files and is supported from TIA Portal V14 SP1 onward. TIA Portal V17, V18, V19, and V20 have all been verified to import the current GSD revision and compile a working configuration against the CP 1542-5.
What baud rate should I use for a segment with multiple E1plus relays on an S7-1500 master?
1.5 Mbit/s is the practical maximum for a 200 m segment and is the recommended default for new installations. Lower baud rates (187.5 kbit/s, 93.75 kbit/s) extend the cable length and are more tolerant of marginal cable installations, but they reduce the cyclic update rate. Auto-detect works on the 160-PD1, but fixing the baud rate in TIA Portal removes a variable from the commissioning checklist.
How do I confirm the 160-PD1 is at the address I assigned rather than the factory default?
Power-cycle the E1plus (remove and reapply control power) and then connect a Profibus handheld tester to the 160-PD1's 9-pin D-sub port. The tester will list the slave at its current address; if the device still appears at 126, the address write did not complete or was overwritten by a factory reset of the E1plus base. Repeat the address-setting procedure and verify the non-volatile write before returning the device to service.