Configuring PROFIBUS FDL SAPs for S5 to WinCC Communication via CP5611 A2
This reference documents the end-to-end configuration of the Service Access Point (SAP) parameters required to establish FDL (Fieldbus Data Link) communication between a SIMATIC S5 PLC and a WinCC HMI/SCADA station using a CP 5611 A2 PROFIBUS interface and a CP 5430/CP 5431 in the S5 rack. The article consolidates the original field configuration notes with the official Siemens SIMATIC NET, STEP 5, and WinCC V5 documentation to provide a deterministic procedure for assigning the Own SAP, Foreign SAP, SSNR, and ANR values that WinCC demands during FDL tag management.
1. Communication Architecture Overview
The S5↔WinCC link is a classic two-layer PROFIBUS FDL configuration:
- PC side: CP 5611 A2 PROFIBUS interface card, configured by SIMATIC NET software (COM 5611, later NCM PC). The card exposes PROFIBUS to the WinCC channel DLL "PROFIBUS FDL".
- PLC side: CP 5430 or CP 5431 in the S5 central/expansion rack. The CP is loaded with a connection database that defines SSAP, DSAP, SSNR, and ANR for every active FDL connection.
- STEP 5 program: Provides the application data plus a thin "driver shell" consisting of FB9 (L2STARTUP) and FB10 (L2SNDRCV) plus their work-DBs. The FBs encapsulate the request/response framing to the CP and are the only place in the S5 program where the SAP numbers are physically referenced.
| Layer | Component | Order Number | Function |
|---|---|---|---|
| PC | CP 5611 A2 | 6GK1 561-1AA01 | PCI PROFIBUS master, 12 Mbaud |
| PC | SIMATIC NET NCM PC / COM 5611 | 6GK1 708-0AC00 | CP 5611 configuration and diagnostics |
| PC | WinCC V5/V6/V7 PROFIBUS FDL channel | — | Tag management, alarms, archive |
| PLC | CP 5430 (master) / CP 5431 (slave) | 6ES5 430 / 6ES5 431 | PROFIBUS interface to S5 backplane |
| PLC | COM 5430 / COM 5431 | — | CP connection database editor on PG |
| PLC | STEP 5 function blocks FB9 / FB10 | — | L2STARTUP / L2SNDRCV transport interface |
The CP 5611 A2 is the PROFIBUS DP/FDL/FMS interface card documented in the SIMATIC NET manual collection on the Siemens Industry Online Support portal (support.industry.siemens.com). Its PROFIBUS address and the bus parameters (baud rate, HSA, Tslot, max Tdr, min Ttrd, etc.) must match the CP 5430/CP 5431 profile exactly, otherwise the FDL handshake will fail at SYNC/FDL_REPLY timeouts rather than at the SAP layer.
2. Understanding the SAP Number in PROFIBUS FDL
A SAP (Service Access Point) is the addressing mechanism that lets a Layer 2 device multiplex multiple independent logical connections over a single physical PROFIBUS link. Each SAP is identified by a number between 0 and 126 (in practice, 0 is reserved for the Layer 2 management, and 64 onwards is normally reserved for DP). For FDL user data exchange the usable range is typically 1–62.
Every FDL connection is defined by four addressing tuples:
| Field | Meaning | Set in | Direction |
|---|---|---|---|
| Own SAP (SSAP) | The local SAP on which this station listens | WinCC channel and CP 5430/31 DB | Receive |
| Foreign SAP (DSAP) | The remote SAP that the partner listens on | WinCC channel and CP 5430/31 DB | Send |
| SSNR | Interface number on the S5 (always 0 for the first CP 5430) | COM 5430 / STEP 5 FBs | — |
| ANR | Connection/job number in the CP's connection DB | COM 5430 | — |
The Own SAP and the Foreign SAP must be swapped on the two sides. A WinCC tag configured with Own SAP 35 and Foreign SAP 35 means: WinCC listens on 35, and it transmits to the S5's SAP 35. The CP 5430 must therefore have a connection entry where DSAP = 35 and the local S5's SSAP is 35 as well, completing the loop.
3. Prerequisites
-
SIMATIC NET installed on the engineering station. Required components:
- CP 5611 A2 driver (part of SIMATIC NET PC software).
- NCM PC / COM 5611 configuration tool.
- PROFIBUS FDL channel for WinCC.
- STEP 5 programming package (≥ STEP 5 V6.6 or S5-DOS / S5 for Windows) on a PG connected to the S5 CPU.
- COM 5430 configuration tool (provided on the CP 5430/5431 product CD) for the S5-side connection DB.
- Function blocks FB9 (L2STARTUP) and FB10 (L2SNDRCV) loaded into the S5 program. These are part of the standard STEP 5 library "L2 Functions" and are documented in the CP 5430/CP 5431 manual.
- Free SAPs in the S5 CP. List the SSAPs already consumed by DP slaves or other FDL connections; do not overlap.
- PROFIBUS bus parameters matched: baud rate (typically 1.5 Mbaud for a WinCC↔S5 single-master setup), HSA, Tslot, max Tdr, min Ttrd, quiet time, setup time. Use the SIMATIC NET "Busprofile" export from NCM PC and import the same values into COM 5430.
- At least 250 bytes of free DB area on the S5 for the work-DBs of the read and write functions.
4. Verified SAP Assignment for S5-115U / CP 5430 / WinCC FDL
The configuration below is the standard pattern used in WinCC V5 examples and reproduced in the WinCC Communication Manual chapter on S5-FDL coupling. It uses one SAP per direction (read and write) and is the minimum viable configuration for cyclic tag exchange.
| Function | WinCC Own SAP | WinCC Foreign SAP | S5 SSAP | S5 SSNR | S5 ANR | Work-DB | FB Parameter Index |
|---|---|---|---|---|---|---|---|
| WinCC ← S5 (read) | 35 | 35 | 35 | 0 | 135 | DB12 | 5 (RCV5, A-NR5, DBX5) |
| WinCC → S5 (write) | 34 | 34 | 34 | 0 | 134 | DB11 | 4 (RCV4, A-NR4, DBX4) |
This 34/35 split is conventional rather than mandatory. Any free SAP in the 1–62 range can be used as long as it is unique on the segment and not reserved by a DP slave. The two SAPs are required because WinCC opens a dedicated FDL connection per read/write channel direction; sharing a single SAP for both directions is technically possible with the FDM primitive but is not exposed in the WinCC V5 channel DLL, so the 34/35 pattern is the documented one.
4.1 WinCC Side Configuration (Tag Management → PROFIBUS FDL)
- Open the WinCC project, then in the WinCC Explorer navigate to Tag Management → PROFIBUS FDL.
- Right-click and choose New Connection; select the system "CP 5611 A2 (PROFIBUS)".
- In the Connection Properties dialog set:
- Station Address: PROFIBUS address of the CP 5430 (typical 3).
- Local Station: PROFIBUS address of the CP 5611 A2 (typical 0 or 1).
- Read function → Own SAP 35, Foreign SAP 35
- Write function → Own SAP 34, Foreign SAP 34
- Add tags under the connection: for each tag, choose either the read or write direction and assign a byte offset in the corresponding S5 DB.
- Activate the project and watch the WinCC channel diagnostics for FDL OK.
4.2 SIMATIC NET / NCM PC Side Configuration
- Start Configuration Console for the CP 5611 A2; assign a PROFIBUS address and confirm the bus profile is loaded.
- Start NCM PC and create two free Layer 2 connections (German: freie Layer-2-Verbindungen), one per direction:
- Read connection: Prio L, SSAP 35, SSNR 0, ANR 135
- Write connection: Prio L, SSAP 34, SSNR 0, ANR 134
- Download the connection configuration to the CP 5611 A2.
4.3 S5 Side Configuration (COM 5430 / STEP 5)
- On the PG, start COM 5430 and open the connection DB for the CP 5430.
- Add two "free layer 2" connection entries with the parameters from Table 3 (SSAP 34/35, DSAP = same value, SSNR 0, ANR 134/135).
- Transfer the connection DB to the CP 5430 (online → CP).
- Download the STEP 5 program containing FB9 and FB10 and the work-DBs DB11 and DB12 to the S5 CPU.
5. STEP 5 L2STARTUP / L2SNDRCV Programming
FB9 (L2STARTUP) is called once during startup to bring up the CP 5430's Layer 2 services. FB10 (L2SNDRCV) is called cyclically in OB1 to drive each individual FDL connection. The function blocks take their parameters from a work-DB and from the inputs in the call. The relevant parameter layout for the two connections (write = index 4, read = index 5) is shown in Table 4.
| FB10 formal parameter | Write connection (index 4) | Read connection (index 5) | Comment |
|---|---|---|---|
| RADR | 3 | 3 | PROFIBUS address of the CP 5611 A2 in WinCC PC |
| RCV4 / RCV5 | RCV4 = 34 | RCV5 = 35 | SAP number of the FDL job (write / read) |
| A-NR4 / A-NR5 | A-NR4 = 134 | A-NR5 = 135 | ANR in the CP 5430 connection DB |
| DBX4 / DBX5 | DBX4 = 11 | DBX5 = 12 | Number of the work-DB that holds the request/response buffer |
The work-DBs must be long enough to hold the Layer 2 request header plus the user data. A minimum length of 250 bytes is recommended; WinCC tags with large data blocks (e.g. 1 kB recipe transfers) may require up to 1024 bytes. The structure inside each work-DB is:
- Request header (16 bytes): SSAP, DSAP, ANR, SSNR, length, type, status, …
- Data area: the payload written by FB10 (send) or read by FB10 (receive).
5.1 Calling FB9 in OB21 and OB22 (Cold/Restart)
FB9 must be called in both OB21 (cold restart) and OB22 (warm restart) so that the CP 5430 is parameterised with the connection DB after every startup class. The typical call is:
FB 9
RADR := 3 // PROFIBUS address of the CP 5611 A2 in the PC
DBNO := 10 // connection-DB number for the CP 5430
SSNR := 0 // interface number on the S5
5.2 Calling FB10 in OB1 (Cyclic)
FB10 is called once per cycle and services all configured indices (typically indices 4 and 5 for the two FDL connections). Each call passes the SAP and the work-DB:
FB 10
RADR := 3 // PROFIBUS address of the WinCC PC
RCV4 := 34 // write SAP
RCV5 := 35 // read SAP
A-NR4 := 134 // write ANR
A-NR5 := 135 // read ANR
DBX4 := DB11 // work-DB for write
DBX5 := DB12 // work-DB for read
Inside the work-DBs, the application updates the data area with the process values it wants to publish (DB11 for write, DB12 for read) and the same data bytes become the WinCC tag address. The byte offset in the work-DB is the "offset" parameter in the WinCC tag definition.
6. Connection Database in the CP 5430/31 (COM 5430)
The CP 5430/5431 stores its connections in a binary DB that COM 5430 generates. Each connection row has the columns listed in Table 5.
| Column | Value (Write) | Value (Read) | Meaning |
|---|---|---|---|
| ANR | 134 | 135 | Connection number within the CP |
| SSAP | 34 | 35 | Local SAP on which the CP listens |
| DSAP | 34 | 35 | Remote SAP (WinCC Own SAP) |
| SSNR | 0 | 0 | Interface number (= 0 for the first CP) |
| Typ | FDL | FDL | Service type, must be FDL for WinCC coupling |
| Prio | L | L | Low priority is sufficient for cyclic data |
| Adresse | 0/1 | 0/1 | PROFIBUS address of the WinCC PC (CP 5611 A2) |
The "Adresse" field is the PROFIBUS address of the remote partner, i.e. the CP 5611 A2 in the WinCC PC. If WinCC and the CP 5430 are the only active stations on the bus, address 0 is acceptable for the PC.
7. WinCC Tag Definition
Once the FDL connection is in place, tags are added under the PROFIBUS FDL channel. Each tag has the fields listed in Table 6.
| WinCC tag field | Source value | Comment |
|---|---|---|
| Name | Tag_LvlTank | Free text |
| Connection | PROFIBUS FDL: S5_Station_3 | The FDL connection created in §4.1 |
| Direction | Read or Write | Selects the SAP pair (35 or 34) |
| Data type | Word, Byte, Bool, Float, … | Matches S5 data type |
| DB number | 11 (write) / 12 (read) | Matches FB10 DBX4 / DBX5 |
| Byte offset | e.g. 0 | Start of the value in the work-DB |
| Bit offset | 0–7 | For Bool tags |
8. Verification Procedure
- Physical layer: confirm the PROFIBUS connector is in, the terminator is ON at the two ends, and the bus is running (CP 5611 A2 LED "PROFIBUS" steady green).
- Bus configuration: launch SIMATIC NET diagnostics and verify that the CP 5430 is listed at the expected PROFIBUS address and is in OPERATE state.
- FDL handshake: open the WinCC Channel Diagnosis tool (ApDiag.exe / WinCC Channel Diagnostics). The PROFIBUS FDL channel should report FDL OK and a live update on a read tag.
- Cyclic data: set a value in the S5 work-DB DB12 (e.g. data word DW 0), confirm it appears in the WinCC tag within the configured acquisition cycle (default 1 s).
- Write path: change a WinCC write tag and confirm the corresponding data word changes in DB11 of the S5.
- Error counters: in the CP 5430 diagnostics (COM 5430 online) verify Send retries and Receive CRC errors are zero.
9. Troubleshooting Matrix
| Symptom | Likely root cause | Action |
|---|---|---|
| WinCC: FDL: no partner | SAP mismatch (WinCC Foreign SAP differs from CP 5430 DSAP) | Re-check Table 3 — both numbers must be identical across the two sides |
| WinCC: FDL: timeout after SYNC | Bus profile mismatch (HSA, Tslot, Ttrd) | Export bus profile from NCM PC and import into COM 5430 |
| S5: FB9 returns error 0x0E | Connection DB not loaded to CP 5430 | Online → CP in COM 5430, transfer DB |
| S5: FB10 returns error 0x14 | Work-DB too small | Extend DB11/DB12 to 250+ bytes |
| PROFIBUS LED blinks red on CP 5611 | No bus terminator, or duplicate PROFIBUS address | Enable terminator; verify all addresses unique |
| Tags update slowly / jittery | Prio H not used, scan time too long | Set connection Prio to H; reduce acquisition cycle |
| WinCC reads only zeroes | Wrong DBX / offset | Compare WinCC tag DB/offset with FB10 DBX4/DBX5 |
| CRC errors on CP 5430 | Shielding or cable length violation | Check shielding, baud rate / segment length rule (1.5 Mbaud ≤ 200 m) |
| FB9 not called in OB21/OB22 | CP 5430 not initialised | Insert FB9 call in both restart OBs |
| One direction works, the other fails | Wrong SAP pair (e.g. 34 used for read, 35 for write) | Verify Table 3 direction → SAP mapping |
10. Common Pitfalls and Field-Proven Cautions
- SSNR confusion. The SSNR is always 0 for the first CP 5430/31 in the S5 rack. If a second CP 5430 is installed (e.g. for a second bus segment), its SSNR is 1. The ANR namespace is per-SSNR, so SSNR 0/ANR 134 and SSNR 1/ANR 134 are two distinct connections.
- DP SAP reservation. PROFIBUS DP slaves commonly use SAP 62 (DP class 1) and 63 (DP class 2). Avoid using 62/63 for FDL user data exchange.
- FDL Prio. The "Prio" column in the CP 5430 connection DB selects between Low and High priority token handling. For WinCC tag exchange, Prio L is fine; Prio H is reserved for isochronous, deterministic loops.
- COM 5430 vs NCM PC version. COM 5430 is the S5-side tool. NCM PC / Configuration Console is the PC-side tool. They share the bus profile but are separate executables; do not run COM 5430 on the PC unless the S5 PG is the same machine.
- WinCC V5 channel DLL naming. The PROFIBUS FDL channel is FDLPMC.dll in WinCC V5/V6. In WinCC V7 it was renamed to a different channel driver but the parameter set remained compatible.
- S5-95U FDL. The S5-95U has an integrated PROFIBUS interface (no separate CP) — the configuration is then done in the CPU's system data (SDBs), and the FB9/FB10 parameter layout is identical but loaded directly into the S5-95U. See the manual S5-95U FDL for the SD-layout difference.
- No "read" loop without CP 5430 acknowledge. FB10 on the S5 is "send or receive" — the cyclic call services both directions. There is no separate "read" FB; the same FB10 polls the CP for incoming frames and submits outgoing frames in the same call.
11. Migration Path to Modern Architectures
Although FDL over CP 5611 A2 is still encountered in long-running brownfield S5 plants, the modern migration paths are:
- PROFINET / Industrial Ethernet with a CP 343-1 Lean / CP 343-1 on the S7 replacement or with an S5-to-S7 gateway.
- OPC UA tunneling with a Softing gateway that exposes the FDL connection as an OPC UA server.
- S5 LAN/Ethernet using the CP 1430 (10 Mbit) for direct TCP/IP and a WinCC V7 Industrial Ethernet channel.
- TIA Portal migration when the S5 is replaced with an S7-1200/S7-1500 and a PROFIBUS CP (CM 1542-1) bridges the S5 PROFIBUS to PROFINET.
For new installations, prefer Industrial Ethernet and OPC UA over PROFIBUS FDL. The FDL path described in this document is the deterministic solution for service contracts on existing S5 installations.
12. Reference Parameter Sheet (Printable)
| Item | Value | Configured in |
|---|---|---|
| PROFIBUS baud rate | 1.5 Mbaud | NCM PC + COM 5430 |
| CP 5611 A2 address | 0 | Configuration Console |
| CP 5430 address | 3 | COM 5430 |
| Read Own SAP / Foreign SAP | 35 / 35 | WinCC Tag Management |
| Write Own SAP / Foreign SAP | 34 / 34 | WinCC Tag Management |
| SSNR | 0 | FB9 / FB10 parameter |
| ANR (read) | 135 | COM 5430 + FB10 |
| ANR (write) | 134 | COM 5430 + FB10 |
| Work-DB (read) | DB12, ≥ 250 bytes | STEP 5 |
| Work-DB (write) | DB11, ≥ 250 bytes | STEP 5 |
| FB9 call location | OB21 + OB22 | STEP 5 |
| FB10 call location | OB1 (cycle) | STEP 5 |
Where is the SAP number physically stored in the S5 program?
The SAP number is stored in two places: the CP 5430/5431 connection database (configured with COM 5430/5431) and as input parameters of FB9 (L2STARTUP) and FB10 (L2SNDRCV) in the STEP 5 program. There is no global variable in the S5 CPU; the CPU forwards the SAP to the CP via the function block calls.
Can I use the same SAP for read and write?
Technically yes — the FDL protocol supports full-duplex traffic on a single SAP — but the WinCC V5/V6/V7 PROFIBUS FDL channel DLL opens one FDL connection per direction and assigns separate SAP pairs. The conventional and documented pattern is 34 for write and 35 for read, which is the only configuration verified end-to-end in the WinCC V5 manual chapter 9.
What happens if the SAP is already used by a DP slave?
The CP 5430/31 will reject the connection during start-up with error code 0x0E ("SAP already in use") and WinCC will report FDL: no partner. Reserve SAP 62 and 63 for DP master/slave and choose 34/35 (or any other free pair) for the WinCC FDL user data exchange.
Do I need COM 5430 in addition to NCM PC?
Yes. NCM PC configures the CP 5611 A2 on the PC side and is shipped with SIMATIC NET. COM 5430 configures the CP 5430/5431 on the PLC side and is shipped with the CP 5430/5431 product CD. Both must be used to keep the bus profile consistent across the segment.
Is this configuration still supported on Windows 10/11 with WinCC V7.5?
CP 5611 A2 is end-of-life hardware; for new projects use CP 5612 A2 (PCI) or CP 5622 (PCIe). The CP 5611 A2 driver is no longer signed for Windows 10 64-bit in SIMATIC NET V15 and later, so the FDL path is effectively limited to WinCC V7.4 on Windows 7 32-bit for the original CP 5611 A2 hardware.