Overview: IEC 60870-5-104 to S7-300 Integration
IEC 60870-5-104 (commonly written IEC 104 or IEC 870-5-104) is the TCP/IP profile of the IEC 60870-5 series used by substation RTUs, protection equipment, and SCADA outstations in the energy and water/wastewater industries. A frequent engineering requirement is to exchange single-point indications (digital status), double-point indications, step position information, measured values (analogs), and setpoint commands between a remote RTU and a Siemens SIMATIC S7-300 controller acting as either a master (control center) or slave (outstation) on the same substation LAN.
This reference covers the hardware options that Siemens offers, the discontinued parts you may still find installed, the SIPLUS RIC replacement bundle, and the procedure to bring up an end-to-end IEC 104 link with STEP 7 V5.x or TIA Portal. It also lists the field-proven caveats (port 2404, t0/t1/t2/t3 timers, STARTDT/STOPDT handshake) and a troubleshooting matrix for the most common commissioning failures.
IEC 60870-5-104 Protocol Fundamentals
IEC 104 encapsulates the IEC 60870-5-101 application layer (ASDU – Application Service Data Unit) inside a TCP transport. A field engineer should be familiar with the following constants because they are required inputs in the S7-300 configuration blocks:
| Parameter | Standard value | Meaning |
|---|---|---|
| TCP port | 2404 | Default IEC 104 port; must be identical on both endpoints and opened in any firewall |
| t0 (connection establishment) | 30 s | Time allowed for TCP connect attempt |
| t1 (send/ack timeout) | 15 s | Maximum time the sender waits for an S-frame acknowledgment of the last I-frame |
| t2 (S-frame acknowledgment) | 10 s | Maximum time before sending an S-frame if no new I-frame is queued |
| t3 (test frame) | 20 s | Idle-time after which the station sends a U-test frame (TESTFR) |
| k (max unacknowledged I-frames) | 12 | Maximum number of outstanding I-frames before the sender must stop |
| w (latest ack) | 8 | Number of received I-frames before an S-frame is mandatory |
| Common address (CA) | 1…65 534 | Station address of the slave RTU (per ASDU header byte 6/7, low/high octet) |
The link starts with the controlling station sending STARTDT act (start data transfer, activate). The controlled station confirms with STARTDT con. From that point I-frames carrying ASDUs may be exchanged. STOPDT act / STOPDT con halts the transfer but keeps the TCP socket open. TESTFR act/con (U-format) is the keep-alive when t3 elapses without traffic.
ASDU type identifiers you will typically map to S7-300 data blocks:
| Type ID | Name | Direction (M→S / S→M) | Typical S7 tag type |
|---|---|---|---|
| 1 | M_SP_NA_1 – single-point information | S→M | BOOL (DBx.DBXy.0) |
| 3 | M_DP_NA_1 – double-point information | S→M | BOOL (2 bits) |
| 5 | M_ST_NA_1 – step position | S→M | BYTE / INT |
| 7 | M_BO_NA_1 – bitstring 32 bits | S→M | DWORD |
| 9 | M_ME_NA_1 – measured value, normalized | S→M | INT / REAL (scaled) |
| 11 | M_ME_NB_1 – measured value, scaled | S→M | INT |
| 13 | M_ME_NC_1 – measured value, short float | S→M | REAL |
| 15 | M_IT_NA_1 – integrated totals | S→M | DINT / counter |
| 30 | M_SP_TB_1 – single-point with time tag CP56Time2a | S→M | BOOL + DT |
| 36 | M_ME_TF_1 – short-float meas. with time tag | S→M | REAL + DT |
| 45 | C_SC_NA_1 – single command | M→S | BOOL pulse |
| 46 | C_DC_NA_1 – double command | M→S | BOOL (2 bits) |
| 50 | C_SE_NC_1 – setpoint, short float | M→S | REAL |
| 100 | C_IC_NA_1 – interrogation command (general) | M→S | Trigger OB100 / flag |
| 102 | C_CS_NA_1 – clock synchronization | M→S / S→M | SFC 0 / SFC 1 |
Hardware Options for S7-300 IEC 104 Communication
Siemens has offered three different paths over the years. Field engineers must identify which path applies to the installed base before quoting spare parts or firmware upgrades.
| Solution | Order number (MLFB) | Status (as documented) | Where it runs | Notes |
|---|---|---|---|---|
| TIM 3V-IE (Telecontrol Interface Module) | 6NH7808-3BA00 | Discontinued (PMD – product phase discontinued) | Standalone, behind the S7-300 CPU, communicates via MPI/PROFINET backplane | Older installations only. Replacement is the SIPLUS RIC bundle below. |
| SIPLUS RIC EXT BUNDLE T104 M/S CPU 315 (master/slave, IEC 104) | 6AG6003-2BB03-0DA7 | Active SIPLUS product bundle | CPU 315-2 PN/DP with the RIC library, 2 MB flash memory card | Current path. Master and slave role selectable per instance. Reference: Siemens Product Support 6AG6003-2BB03-0DA7. |
| CP 343-1 Lean / CP 343-1 Advanced + IEC 104 library | 6GK7343-1… (CP family) + regional IEC 104 FB library | Library is region- and project-specific; ordered from Siemens local office | Runs in user OB1 on the CPU, CP 343-1 owns the TCP socket | Used when the customer already has a CPU 313C/314C/315-2 PN/DP and wants to avoid the RIC bundle. Library must be purchased through Siemens regional support and is licensed per CPU. |
Software and Library Requirements
For a current implementation using the SIPLUS RIC bundle (6AG6003-2BB03-0DA7) on a CPU 315-2 PN/DP, the engineering station must have:
- STEP 7 V5.5 SP4 or later (for the legacy S7-300 workbench) or TIA Portal V15.1 / V16 / V17 with the S7-300 CPU 315-2 PN/DP HSP installed.
- The "SIPLUS RIC Library" delivered with the bundle (FBs for the IEC 104 master/slave, DBs for the ASDU buffer, UDTs for CP56Time2a, alarm handling, etc.).
- The S7-300 CPU 315-2 PN/DP firmware version that matches the RIC library release notes (the bundle's product support entry lists the tested combinations).
- A 2 MB SIMATIC Memory Card (SMC) for the CPU 315-2 PN/DP – the bundle ships with the SMC pre-flashed, but field replacements require a 6ES7953-8LM20-0AA0 (or newer 6ES7953-8LP20-0AA0) sized for the project.
- A working Ethernet switch between the S7-300 and the RTU/MTU.
For the CP 343-1 path on a CPU 313C, the IEC 104 FB library must be ordered from the local Siemens office. The library is a project-specific set of FBs (commonly named FB104_MASTER / FB104_SLAVE in customer examples) plus accompanying UDTs and DBs. Because the FB source is not publicly downloadable, it cannot be inventoried generically – obtain the exact FB number, version, and licensing scope from the Siemens regional contact before ordering the CP.
Prerequisites
- One S7-300 station with the chosen CPU (CPU 313C + CP 343-1, or CPU 315-2 PN/DP per the RIC bundle).
- IEC 60870-5-104 RTU/MTU on the same IP subnet, default TCP port 2404 reachable in both directions (verify with a telnet or
Test-NetConnection). - Static IP addressing on both ends; DHCP is not acceptable for an IEC 104 outstation.
- STEP 7 / TIA Portal project with the S7-300 hardware configured and compiled without errors.
- Point list from the RTU side: for every data point the IOA (Information Object Address, 3 octets) in the RTU, the ASDU type ID, the COT (Cause of Transmission), and the engineering range/scaling must be defined.
- Time source: the IEC 104 clock synchronization (
C_CS_NA_1, type 102) requires the S7-300 to callSFC 0 SET_CLKfrom the CP56Time2a data. Decide which side is the time master.
Step-by-Step Configuration
1. Hardware configuration in STEP 7 / TIA Portal
- Open the S7-300 project and insert the CPU. If using the SIPLUS RIC bundle, select the CPU 315-2 PN/DP with order number 6AG1315-2AH13-2AB0 (or the exact MLFB listed in the bundle's product support entry).
- Insert the CP 343-1 (Lean or Advanced) in the rack if you are on the CPU 313C path. Configure the CP's Ethernet interface with the station IP, subnet mask, and the S7 connection on the same subnet.
- Disable any unused services on the CP/PN interface (e.g., S7 routing, web server) to reduce the surface area; enable only the TCP connections needed for IEC 104.
2. Install the RIC library (or IEC 104 FB library)
- Extract the supplied archive to a known path. The archive contains the master FBs, slave FBs, sample S7 program, and a README with the tested STEP 7 / TIA Portal version.
- Open the library in STEP 7 / TIA Portal and copy the FBs, UDTs, and DBs into the S7-300 program. Do not rename the FBs – the documentation links FBs by number to the configuration tool.
- Compile the program. The library typically creates the following blocks: one DB per active IEC 104 connection, one DB per monitored data point, and a UDT for the ASDU header.
3. Configure the IEC 104 connection
Open the configuration DB (commonly DB104 in customer projects) and fill in the parameters that mirror the protocol constants from Protocol Fundamentals above:
// Sample configuration values – verify against the FB documentation in the library
DB104.DBW0 := 2404; // TCP port
DB104.DBW2 := 30; // t0 [s] connection establishment
DB104.DBW4 := 15; // t1 [s] send/ack timeout
DB104.DBW6 := 10; // t2 [s] S-frame ack
DB104.DBW8 := 20; // t3 [s] test frame
DB104.DBW10 := 12; // k max outstanding I-frames
DB104.DBW12 := 8; // w latest ack
DB104.DBW14 := 1; // Common address of the controlled station
DB104.DBX16.0 := TRUE; // 1 = controlling station (master), 0 = controlled (slave)
DB104.DBD18 := 'C0A8010B'; // IP of partner (192.168.1.11) – hex, network order
4. Map data points to PLC tags
For every IOA in the RTU point list, create one entry in the IEC 104 data-point DB. Typical fields per entry:
| Field | Type | Example (analogue input) | Example (digital input) |
|---|---|---|---|
| IOA (3 octets) | DWORD | 16#000001 (point 1) | 16#000065 (point 101) |
| ASDU type ID | BYTE | 13 (M_ME_NC_1 short float) | 1 (M_SP_NA_1 single point) |
| COT (cause of transmission) | BYTE | 2 (background), 3 (spontaneous), 20 (interrogated by station) | 3 (spontaneous) / 20 (general interrogation) |
| Engineering range low | REAL | 0.0 | 0 |
| Engineering range high | REAL | 400.0 (bar) | 1 |
| Tag in S7 user program | DB pointer | DB100.DBD0 (REAL) | DB100.DBX100.0 (BOOL) |
| Quality descriptor | BOOL | DB100.DBX104.0 (good = 1) | DB100.DBX105.0 |
For commands coming from the master to the S7-300 (e.g., a circuit-breaker close), the same structure is used in reverse: the library writes the received command value into the S7 tag and sets a command-pending flag. The user program must clear the flag once the command has been executed and the result reported back as M_SP_NA_1 with COT 12 (operation completed).
5. General interrogation and clock sync
- Configure the library so that on
STARTDT conthe slave responds to aC_IC_NA_1general interrogation by cycling through all data points and returning the current values with COT 20 (interrogated by station) or 36 (interrogated by group 1…16). - Decide who is the time master. If the S7-300 should accept time from the RTU, enable the
C_CS_NA_1handler in the library and route the received CP56Time2a toSFC 0 SET_CLK. If the S7-300 is the time master (common in substations with a GPS clock feeding the RTU), triggerSFC 1 READ_CLKon a slow cycle and transmit type 102 with COT 6 (activation) followed by type 103 (C_CS_TA_1 time-tagged command).
6. Download and cold start
- Compile the project (STEP 7: Station > Compile and Download Objects; TIA Portal: Download to device > Hardware and Software).
- Perform a CPU stop→run transition with a memory reset (MRES) to clear any residual connection table.
- Watch the diagnostic buffer (STEP 7: PLC > Diagnostic/Setting > Diagnostic Buffer) for the IEC 104 FB start-up events: "IEC104: TCP open," "IEC104: STARTDT received," and "IEC104: GD cycle started."
Verification and Commissioning
After the download, validate the link from both sides:
-
TCP connectivity: From the engineering station, open a TCP socket to the S7-300 IP on port 2404 (for example with
Test-NetConnection 192.168.1.10 -Port 2404on Windows, ornc -vz 192.168.1.10 2404on Linux). The socket should accept the connection immediately, confirming that the S7-300 is in TCP listen. - STARTDT handshake: On the RTU/master, force an "Initialize" command. The diagnostic buffer on the S7-300 should record "STARTDT act received" followed by "STARTDT con sent."
- General interrogation: Trigger a station interrogation from the master. The S7-300 must respond with all configured data points within t1. A missing point indicates an IOA mismatch; a wrong value indicates a scaling or endianness problem.
- Spontaneous reports: Toggle a digital input wired to the S7-300. The RTU should receive a type-1 ASDU with COT 3 (spontaneous) and the new value within 1 s.
-
Clock sync: Watch the CPU clock; after one
C_CS_NA_1exchange the CPU time should match the master's reference within ±1 s. - Keep-alive: With all data quiet for t3 = 20 s, the diagnostic buffer should show a "TESTFR sent" / "TESTFR received" pair every 20 s. Absence of these events is the most common symptom of a partner that has a firewall dropping idle TCP sessions.
Troubleshooting Matrix
| Symptom | Likely cause | Diagnostic | Remedy |
|---|---|---|---|
| TCP connection refused on port 2404 | CP not loaded, or wrong port | Diagnostic buffer, netstat -an on the S7 side |
Confirm CP 343-1 is in RUN with no SF LED, re-check port number in DB104 |
| TCP connects but no STARTDT in the buffer | Master not sending, or firewall dropping U-frames | Wireshark on port 2404 | Open inbound 2404; some firewalls need an explicit rule for U-format (control field octet = 0x07 / 0x0B) |
| STARTDT con seen, but no ASDUs | IOA or type ID mismatch in the point DB | Enable "trace" in the IEC 104 FB and capture the first 10 frames | Cross-check IOA list between RTU config and S7 DB104 entries |
| Values received but always zero | Endianness / byte-swap on the IP or on the 32-bit analog | Compare a known constant in the diagnostic buffer | Reverse byte order in the configuration, or activate the library's "byte-swap on write" flag |
| Analog values random / noisy | Scaling range or wrong ASDU type (e.g., type 9 normalized vs type 11 scaled vs type 13 short float) | Decode a captured frame with an IEC 104 analyzer | Match the ASDU type ID with the RTU engineering; for type 11 (scaled) enter the correct engineering range |
| Connection drops every few minutes | t1 too short for the round-trip, or TCP keep-alive on the switch kills the session | Diag buffer "connection closed by partner" | Increase t1 to 30 s; disable "aggressive" TCP keep-alive on the managed switch; configure the CP for "keep-alive enabled" |
| General interrogation returns values once, never updates | Spontaneous report blocked by COT filter | Decode frames; COT should be 3 (spontaneous) | Enable COT 1 (periodic) or COT 3 (spontaneous) for the relevant data points in the point DB |
| Commands from master have no effect on the plant | Select-before-operate handshake (SBO) not handled | Check whether the master sends type 58/59 (C_SE_TA_1 etc.) instead of 45/50 | Enable SBO handling in the library, or change the master to "direct execute" (S/E bit = 0) |
| S7 CPU goes into STOP after first ASDU | OB121 not loaded; library reads a non-existent DB | Diag buffer "OB not loaded" / "DB not found" | Insert OB121, OB122, OB85 in the S7 program, then re-download |
| Time jumps by 1 hour after sync | Daylight-saving handling in CP56Time2a differs from CPU time | Compare CPU clock before and after sync | Disable DST in the master, or use only the first 5 bytes (time-of-day + date) and ignore the "summer time" bit in the IEC 104 library configuration |
Field-Proven Caveats
- Do not use TIM 3V-IE for new projects. 6NH7808-3BA00 is in the discontinued phase. Spares are limited; firmware updates and cybersecurity patches are no longer issued. New builds should use the SIPLUS RIC bundle (6AG6003-2BB03-0DA7) or the CP 343-1 + IEC 104 library combination.
- CP 343-1 + IEC 104 library path is not plug-and-play. The library is a regional, project-specific deliverable. It must be ordered through the local Siemens office and licensed for the specific CPU; do not assume an "IEC 104 starter kit" is on the price list.
- One CPU 313C is rarely the only station. A typical substation has multiple S7-300 outstations. The IEC 104 master can handle this – each station gets its own common address (CA) and a unique DB104 instance on the master CPU – but the configuration is per station. Build a point list per station and version it in the engineering tool.
- Cybersecurity. IEC 104 has no built-in authentication. Apply IEC 62351 (TLS-AH profile, NERC CIP) at the network layer if the RTU is reachable from a routed network. Inside the substation, segregate the IEC 104 VLAN from the office VLAN and from the protection network.
- Documentation drift. The bundle's manual is published under entry 6AG60032BB030DA7 on the Siemens Product Support portal. Always check the current "Product support" → "Manuals" → "Firmware/Software" section of that entry for the latest library revision, sample project, and release notes before commissioning.
Standards and References
- IEC 60870-5-104:2010 – Networked IEC 60870-5-101, transport over TCP/IP (t0, t1, t2, t3, k, w defined in §6.2 of the standard).
- IEC 60870-5-101:2003 – Companion standard for basic telecontrol, ASDU definitions and state/quality descriptors.
- IEC 62351 – Security for power system communication, applied to IEC 104 in part 3 / 5 / 6.
- Siemens Product Support entry 6AG6003-2BB03-0DA7 – SIPLUS RIC EXT BUNDLE T104 M/S CPU315 – product manual, firmware notes, and library download.
- Siemens TIA Portal documentation: Modbus RTU communication (S7-300, S7-400) – provided here for context; Modbus RTU is a different protocol from IEC 104 and uses CP 341/CP 441/CM PtP.
Which Siemens module do I use today to connect an S7-300 to an IEC 60870-5-104 RTU?
Use the SIPLUS RIC EXT BUNDLE T104 M/S CPU315, order number 6AG6003-2BB03-0DA7, on a CPU 315-2 PN/DP. The legacy TIM 3V-IE (6NH7808-3BA00) is discontinued. For a CPU 313C, add a CP 343-1 and obtain the IEC 104 FB library from your local Siemens office.
What TCP port does IEC 60870-5-104 use, and is it configurable?
Default port is 2404 on both sides. The port is configurable in the S7-300 configuration DB but must match the RTU/MTU exactly. The value must also be opened bidirectionally in any firewall between the two stations.
What is the difference between IEC 60870-5-104 and Modbus RTU for S7-300?
IEC 104 runs over TCP/IP on port 2404 with a structured ASDU layer (types 1, 3, 9/11/13, 45/50, 100, 102, etc.) and uses U-format (STARTDT/STOPDT/TESTFR) plus S-format frames. Modbus RTU is a serial or TCP master/slave protocol with function codes 1, 2, 3, 4, 5, 6, 15, 16 and no ASDU model. They are not interchangeable. Modbus RTU on S7-300/S7-400 uses CP 341/CP 441/CM PtP or the Modbus TCP CP and is documented at the Siemens TIA portal page for Modbus RTU.
Why does the IEC 104 link open but no data ever arrives?
Almost always a point-list mismatch – the Information Object Address (IOA) configured in the S7-300 DB104 does not match the IOA sent by the RTU, or the ASDU type ID (e.g., 9 vs 11 vs 13 for analogs) is wrong. Capture the first few frames with Wireshark on port 2404 and decode the IOA and type ID against the point DB. A byte-order error on the partner IP can also produce a silent "no route to host" – verify the IP in the configuration is stored big-endian.
Which timers (t0, t1, t2, t3) should I leave at default?
For most substation LANs the IEC standard defaults (t0=30 s, t1=15 s, t2=10 s, t3=20 s, k=12, w=8) work without modification. Increase t1 to 30 s only if the round-trip is high (slow radio link, congested network) or if the master is intermittently slow to acknowledge. Lower t3 below 20 s only if your firewall is aggressively dropping idle TCP sessions – and prefer to fix the firewall instead.
Is the IEC 104 FB library for CP 343-1 free with the CP?
No. The IEC 104 FB library for CP 343-1 is a project-specific deliverable ordered from the local Siemens office. It is licensed per CPU and includes the FBs, UDTs, sample program, and release notes. Confirm the FB numbers, version, and licensing terms with Siemens regional support before purchasing the CP.