Configuring S7-1200 CPU 1214C to S7-400H CPU 412-5H Open IE Communication
The SIMATIC S7-400H (S7-400H) redundancy PLC family was never integrated into the TIA Portal hardware catalog. As of TIA Portal V12 (and the later V13, V14, V15, V15.1, V16, V17, V18, and V19 releases), the CPU 412-5H PN/DP and CPU 414-5H PN/DP and CPU 417-5H PN/DP continue to be programmed exclusively with STEP 7 V5.5 / V5.6 and the optional S7-H Add-on package. When an S7-1200 (for example, CPU 1214C DC/DC/DC order number 6ES7214-1AG40-0XB0) must exchange process data with a CPU 412-5H, the standard S7 connection (PUT/GET via NetPro/connection configuration) cannot be built in a single engineering tool, and the DP/DP coupler + Y-Link path is unattractive when the two stations already share an Industrial Ethernet / PROFINET backbone.
The supported alternative is Open IE communication using the standard TCON / TSEND / TRCV / TDISCON instruction set on the S7-400H side (STEP 7 V5.5) and the TSEND_C / TRCV_C / TCON / TDISCON family on the S7-1200 side (TIA Portal V12). Both transports are configured independently on each controller — no NetPro cross-project, no PUT/GET access rights, no S7 connection partner definition. This article documents a field-proven configuration for a CPU 1214C ↔ CPU 412-5H link that is bridged by two SCALANCE W786-1PRO access points operating as a wireless bridge into a SCALANCE X108 managed switch on the stacker.
1. Scope and Applicability
| Item | Value |
|---|---|
| S7-1200 CPU | CPU 1214C DC/DC/DC (6ES7214-1AG40-0XB0), firmware V4.2 or higher |
| S7-400H CPU | CPU 412-5H PN/DP (6ES7412-5HK06-0AB0) with at least one PN interface |
| S7-400H firmware | V6.0.x (for 5H; PN/DP variants 5HK06 and 5HM06) |
| Engineering S7-1200 | SIMATIC STEP 7 Basic / Professional V12.0 + SP1 or later in the V12 line (V12 SP1, V12 SP2, V12 SP3) |
| Engineering S7-400H | STEP 7 V5.5 + SP4 (or V5.5 + HF11 / later HFs) plus S7-H Add-on package |
| Wireless link | SCALANCE W786-1PRO (6GK5786-1PRO-2AA1 or -3AA1) in client/bridge mode, both sides |
| Wired segment on stacker | SCALANCE XC108 or X108 unmanaged/managed switch (8 × RJ45) |
| Transport protocols | ISO-on-TCP (RFC 1006, connection type 12 = 0x0C) and/or TCP (connection type 11 = 0x0B) |
| Library on S7-1200 | "Communication processors / Open User Communication" blocks shipped with TIA Portal V12 |
| Library on S7-400H | Standard library → Communication Blocks → Blocks for Open IE Communication (FB63–FB68, UDT65/UDT66) |
2. Network Architecture
The physical layer is two SCALANCE W786-1PRO devices configured as a point-to-point wireless bridge. The central control room end terminates on a SCALANCE X108 / XC108 switch together with the CPU 1214C; the movable stacker end terminates on a second SCALANCE X108 inside the stacker E-house, where the CPU 412-5H PN/DP's PROFINET port is wired. Both APs use the same SSID, channel, and WPA2/AES key in bridge mode (or iPCF mode if line-of-sight is intermittent).
IP planning is critical because both S7-1200 and S7-400H are on the same Layer-2 broadcast domain. Use a private /24 such as 192.168.0.0/24 and reserve static addresses; SCALANCE W786-1PRO supports the “Bridge mode” (point-to-point) where both APs share a single IP subnet.
3. Protocol Selection: TCP vs ISO-on-TCP
| Property | ISO-on-TCP (RFC 1006) | TCP (RFC 793) |
|---|---|---|
| T-block ID (UDT65) | 12 (0x0C) — B#16#0C | 11 (0x0B) — B#16#0B |
| Local / remote TSAP | Required, max 16 bytes, ASCII or hex | Not used, set to 0 |
| Port number (S7-400H) | Implicit, derived from TSAP | Configurable (default 2000, 2500, 3000…) |
| Header overhead | 4-byte TPDU header + RFC 1006 | 20-byte TCP + 20-byte IP |
| Data integrity | Length field is explicit per send | Length must be carried inside the payload |
| Suitability for 5H wireless | Recommended — TSAP simplifies partner address | Acceptable — slightly more bytes on the air |
| Number of S7-1200 connection resources (firmware V4.x) | Up to 8 open IE connections for CPU 1214C | Same as left |
For a stacker with intermittent RF contact, ISO-on-TCP is the more deterministic choice: the TSAP (Transport Service Access Point) lets the S7-400H identify the partner without inspecting payload, and the S7-400H redundancy firmware treats the connection as a normal Open IE link that can be opened/closed by FB63/FB66. TCP is the only option if the partner is a non-Siemens device or a third-party SCADA node.
4. S7-400H Side Configuration (STEP 7 V5.5)
The S7-400H project must be created in STEP 7 V5.5 with the S7-H Add-on. Configure the CPU 412-5H PN/DP PROFINET interface with IP 192.168.0.30, subnet mask 255.255.255.0, no router. Open IE communication does not require a configured connection in NetPro — only an instance DB for the FBs.
4.1 Connection description UDT 65 (ISO-on-TCP)
Declare the connection description as a multi-instance or a stand-alone DB. UDT 65 is the standard structure used by FB63 TCON. The minimum fields for ISO-on-TCP are:
| Offset | Symbol | Type | Value (example) | Comment |
|---|---|---|---|---|
| 0.0 | block_length | WORD | W#16#0040 (64 dec) | Length of UDT 65 data area |
| 2.0 | id | WORD | W#16#0001 | Connection ID, must match the ID at both ends |
| 4.0 | connection_type | BYTE | B#16#0C | 12 = ISO-on-TCP |
| 5.0 | active_est | BOOL | TRUE | TRUE = active (S7-400H opens), FALSE = passive |
| 6.0 | local_device_id | BYTE | B#16#00 | 0 = PN-IO interface of CPU 412-5H |
| 7.0 | local_tsap_id_len | BYTE | B#16#02 | 2 bytes TSAP for ASCII |
| 8.0 | local_tsap_id | ARRAY[1..16] OF BYTE | 'S' '4' = 0x53 0x34 | Local TSAP, ASCII or hex |
| 24.0 | rem_subnet_id_len | BYTE | B#16#00 | 0 = no router |
| 25.0 | rem_staddr_len | BYTE | B#16#04 | 4 bytes IP |
| 26.0 | rem_staddr | ARRAY[1..6] OF BYTE | 192 168 0 10 0 0 | Partner IP, 4 bytes used |
| 32.0 | rem_tsap_id_len | BYTE | B#16#02 | 2 bytes |
| 33.0 | rem_tsap_id | ARRAY[1..16] OF BYTE | 'S' '1' = 0x53 0x31 | Remote TSAP (S7-1200 side) |
4.2 STL call sequence (S7-400H OB1)
// FB63 TCON - establish ISO-on-TCP connection
CALL FB63, DB100
REQ := M10.0 // 1 = establish
ID := W#16#000A // Connection ID 10
DONE := M10.1
BUSY := M10.2
ERROR := M10.3
STATUS:= MW12
CONNECT := P#DB100.DBX0.0 BYTE 64 // UDT 65 in DB100
// FB64 TSEND - send 100 bytes from DB200.DBX0.0
CALL FB64, DB101
REQ := M11.0 // rising edge triggers send
ID := W#16#000A
LEN := 100 // explicit length on ISO-on-TCP
DONE := M11.1
BUSY := M11.2
ERROR := M11.3
STATUS:= MW14
DATA := P#DB200.DBX0.0 BYTE 100
// FB65 TRCV - receive into DB201 (must be 100+2 bytes for ISO-on-TCP header)
CALL FB65, DB102
EN_R := M12.0 // 1 = enabled
ID := W#16#000A
LEN := 100 // 0 = any length, or fixed
NDR := M12.1
BUSY := M12.2
ERROR := M12.3
STATUS:= MW16
RCVD_LEN:= MW18
DATA := P#DB201.DBX0.0 BYTE 100
// FB66 TDISCON - orderly close
CALL FB66, DB103
REQ := M13.0
ID := W#16#000A
DONE := M13.1
BUSY := M13.2
ERROR := M13.3
STATUS:= MW20
5. S7-1200 Side Configuration (TIA Portal V12)
The S7-1200 program is built in TIA Portal V12 against a CPU 1214C with firmware V4.2. Use the system library "Communication -> Open User Communication" which contains TSEND_C, TRCV_C, TCON, TDISCON, T_RESET, and T_DIAG FBs.
5.1 Configure the PROFINET interface
- Open the device view, select the CPU 1214C, switch to Properties > Ethernet addresses.
- Set IP address
192.168.0.10, subnet mask255.255.255.0. Do not check "Use router" unless the SCALANCE W786-1PRO is in routed mode. - If you need to enable secure PG/PC and HMI communication later, follow the steps for certificate handling in the S7-1200 manual collection: S7-1200 Communications CPU 1214C.
- Under "Connection mechanisms", enable "Permit access with PUT/GET from remote partner" only if you also need the legacy PUT/GET path; it is not required for Open IE communication.
5.2 Build a global DB of type "TCON_Param"
UDT "TCON_Param" is shipped with TIA Portal V12 in the system data types. Create a DB named iDB_H_Link of type TCON_Param for each connection. The fields required for an active ISO-on-TCP client targeting the S7-400H are:
| Field | Type | Value | Notes |
|---|---|---|---|
| InterfaceId | HW_IO | 64 (PN interface of CPU 1214C) | 64 = onboard PROFINET |
| ID | WORD | W#16#000A | Connection ID 10, must match S7-400H |
| ConnectionType | BYTE | B#16#0C | 12 = ISO-on-TCP |
| ActiveEstablished | BOOL | TRUE | S7-1200 is active |
| RemoteAddress | ARRAY[1..4] OF BYTE | 192, 168, 0, 30 | CPU 412-5H IP |
| RemotePort | UINT | 0 | Not used for ISO-on-TCP |
| LocalPort | UINT | 0 | Auto-assign |
| LocalTSAP | ARRAY[1..16] OF USINT | 0,0,'S','1' (TSAP=2 bytes ASCII "S1") | Two leading 0x00 bytes + ASCII |
| RemoteTSAP | ARRAY[1..16] OF USINT | 0,0,'S','4' (TSAP=2 bytes ASCII "S4") | Matches S7-400H local TSAP |
LengthOfTSAP bytes (derived from the first non-zero entry) are used. For 2-byte ASCII TSAPs such as S1, fill the array with [0,0,'S','1', 0,0,...]. For hex TSAPs use 0x53 0x31 directly.5.3 SCL call sequence (S7-1200 OB1)
// TSEND_C: combined establish + send on rising edge of REQ
IF "M_Request_Send" THEN
"iTSend_C_DB"(REQ := "M_Request_Send",
ID := 10,
CONT := TRUE, // keep connection open
LEN := 100,
DATA := P#"DB_Send".DBX0.0 BYTE 100,
DONE => "M_Send_Done",
BUSY => "M_Send_Busy",
ERROR => "M_Send_Err",
STATUS=> "MW_Send_Status");
END_IF;
// TRCV_C: always enable after connection is up
"iTRcv_C_DB"(EN_R := "M_Recv_Enable",
ID := 10,
CONT := TRUE,
LEN := 100,
DATA := P#"DB_Recv".DBX0.0 BYTE 100,
NDR => "M_Recv_NDR",
BUSY => "M_Recv_Busy",
ERROR => "M_Recv_Err",
STATUS=> "MW_Recv_Status",
RCVD_LEN=> "MW_Recv_Len");
// Optional: T_DIAG for connection-state snapshot
"iTDiag_DB"(ID := 10,
MODE := 0, // 0 = status only
STATUS := "DB_TDiag_Status",
DIAG_OUT := "DB_TDiag_Result");
6. Connection Parameter Mapping Summary
| Parameter | S7-1200 (CPU 1214C, V4.2) | S7-400H (CPU 412-5H, V6.0) |
|---|---|---|
| IP address | 192.168.0.10 | 192.168.0.30 |
| Subnet mask | 255.255.255.0 | 255.255.255.0 |
| Connection type | 12 (ISO-on-TCP) | 12 (ISO-on-TCP) |
| Active / Passive | Active (TCON starts) | Passive (waits for partner) |
| Local TSAP | ASCII "S1" (0x00,0x00,'S','1') | ASCII "S4" (0x53,0x34) |
| Remote TSAP | ASCII "S4" (0x00,0x00,'S','4') | ASCII "S1" (0x53,0x31) |
| Connection ID | 10 (0x0A) | 10 (0x0A) |
| Interface | PN interface, slot 1 of CPU 1214C | PN-IO X5 of CPU 412-5H, ID 0 |
| Max payload per send | 8192 bytes (S7-1200 limit) | 8192 bytes (S7-400H limit, firmware ≥ V5.1) |
| Total Open IE connections on controller | 8 (CPU 1214C, FW 4.x) | Up to 64 depending on CPU type and work memory |
7. SCALANCE W786-1PRO Wireless Bridge Settings
- Open the Web-Based Management of both W786-1PRO devices.
- Set Operating mode = Bridge mode (point-to-point). This is the default mode for the -PRO variant; do not select "Client" mode because the S7 stations need a transparent Layer-2 bridge.
- Configure both radios with the same SSID, channel (e.g., 5 GHz DFS channel 100), and WPA2/AES passphrase.
- Set the bridge partner MAC explicitly on both devices to avoid the 30-40 s scan delay during roam.
- Disable Spanning Tree on the W786 radios but leave it enabled on the SCALANCE X108 — the X108 will keep the loop-free path when the wireless side is recovering.
- Verify the link with the W786 "Diagnostics > WLAN > Signal" page; RSSI should be above -65 dBm for a 5H Open IE link to remain stable at 100 ms send cycle.
- Set the IP of the W786 for management only (192.168.0.20 / 192.168.0.21) — they are not part of the Open IE connection.
8. Verification Procedure
- Download the S7-400H project to the H-station; check that both CPUs go to RUN with no diagnostic interrupt. The H-system status must show "System status: Redundant".
- Download the S7-1200 project to the CPU 1214C. Open the Online > Diagnostics > Connection diagnostics view; the connection with ID 10 should appear with state ESTABLISHED.
- On the S7-400H, force
REQ = TRUEon FB64 TSEND. Verify in the partner DB that the data is non-zero and the S7-1200'sRCVD_LENreports 100. - Reverse the test: trigger
TSEND_Con the S7-1200 and readRCVD_LENat the H-station. BothDONEflags must pulse once per REQ. - Watch the W786 signal page for 60 s; packet loss must be 0 % for the 100 ms cycle.
- Issue a STOP/RUN on the standby CPU of the H-system to confirm that the Open IE connection survives a redundancy switchover. Status must remain ESTABLISHED within 2 s (typical 200-500 ms).
- Pull power on the wireless bridge for 5 s; verify that
STATUSon the S7-1200 readsW#16#80C8(connection terminated) and is followed by automatic re-establishment when the bridge comes back.
9. Diagnostics and Status Codes
Open IE communication on the S7-400H and S7-1200 use the same STATUS word layout (16-bit, 8-bit event class + 8-bit event number). Common codes that show up in the field:
| STATUS | Class / Number | Meaning | Field Action |
|---|---|---|---|
| W#16#0000 | 0/0 | No error | — |
| W#16#7000 | 7/0 | FB not active (no REQ edge yet) | Normal at start-up |
| W#16#7001 | 7/1 | Job in progress (BUSY) | Wait for DONE/NDR |
| W#16#7002 | 7/2 | Internal job completed, awaiting next call | Continue cyclic call |
| W#16#8085 | 8/5 | LEN parameter = 0 and no data yet, or LEN too large for the DB | Re-check LEN and DB size |
| W#16#80A1 | 8/161 | Connection or port already occupied | Lower ID, free a connection resource |
| W#16#80AB | 8/171 | TSAP already in use | Use a different TSAP |
| W#16#80C3 | 8/195 | All connection resources in use on this CPU | Reduce number of Open IE links |
| W#16#80C4 | 8/196 | Temporary communication error (TCP RST received) | Auto-recovery within seconds |
| W#16#80C8 | 8/200 | Partner actively closed the connection | Auto-reconnect if REQ pulse is re-applied |
| W#16#8380 | 8/128 (S7-1200 only) | Connection ID 0 not allowed | Set ID ≥ 1 |
| W#16#80B5 | 8/181 | Local/remote IP identical | Re-assign a unique IP |
10. Security Considerations
Open IE communication is unencrypted by default. On a wireless link such as SCALANCE W, this is a known attack surface. The hardening sequence recommended for production:
- Enable WPA2/AES on the SCALANCE W786-1PRO radios (already documented in section 7) and use a 20+ character passphrase rotated quarterly.
- Restrict the S7-1200 firmware ≥ V4.2: enable "Access protection" with a password of at least 8 characters including a digit and a special character.
- For CPU 1214C firmware V4.4 and higher, switch the Open IE link to TLS using the
TCONblock withConnectionType = 0x11(17) and a CPU-side X.509 certificate. The S7-400H V6.0 firmware supports TLS for Open IE only with CP443-1 EX30 / GX30 modules, not on the CPU's onboard PN interface — keep Open IE unencrypted on the H-station CPU and rely on a CP for TLS. - Apply all CISA-published Siemens advisories for the S7-1200 platform — see the CISA ICS advisory ICSA-25-044-01 for the most recent updates (note that CISA stopped updating this advisory line on 10 January 2023, but historical advisories still apply).
- Disable the Web server on the S7-1200 unless required; if it must remain on, restrict it to HTTPS with a CPU-side certificate.
- Apply the "Permit access with PUT/GET from remote partner" option in TIA Portal V12 only if legacy S7 partners exist; this option opens the CPU to known S7 read/write attacks and is the root cause of multiple S7-1200 advisories (e.g., CVE-2019-13945, CVE-2020-15782).
11. Troubleshooting Matrix
| Symptom | Most Likely Cause | Diagnostic Step | Resolution |
|---|---|---|---|
| FB63 TCON stays BUSY, no DONE | Partner not reachable on IP | Ping 192.168.0.30 from S7-400H PG; check SCALANCE W link state | Fix IP / mask / bridge; re-trigger REQ |
| STATUS = W#16#80AB | TSAP collision with another link | List all UDT65 blocks in the S7-400H; check IDs and TSAPs | Use a different TSAP string per link |
| S7-1200 reports W#16#80A1 | ID already used by another TCON | Cross-check DBs for duplicate ID values | Re-assign ID; rebuild project |
| Connection goes up then drops after 30 s | Keep-alive timeout; partner closes because no traffic | Reduce cyclic send period to ≤ 5 s | Send a 1-byte "heartbeat" with TSEND_C every 5 s |
| H-station redundancy switchover breaks the link | Open IE uses the H-CPU's active interface; after switchover the binding is on the standby IP for a few cycles | Use the H-system's redundant IP (192.168.0.30 is shared by both H-CPUs) | Re-trigger TCON with rising edge; or use FB54 "DSND_INIT" pattern from the S7-H Add-on for IP re-bind |
| Data is shifted by 2 bytes | ISO-on-TCP sender specified LEN=100 but receiver expects the 2-byte length prefix | Check LEN at the sender and at the receiver | Match the lengths; ISO-on-TCP does not include the length in the data on S7-1200 firmware ≥ V4.0 — it is a "data-only" transport |
| CPU 1214C online diagnostics shows the link but no data | TSAP length encoding wrong (leading zeros in ASCII) | Monitor TDiag output; STATUS = W#16#80A7 means TSAP format error | For 2-byte ASCII TSAP, send [0,0,'S','1']; for 2-byte hex TSAP send [0x53, 0x31, 0,0,...] |
| After STOP/RUN of the S7-400H the S7-1200 sees W#16#80C8 | S7-400H issued an active close; S7-1200 has not been told to reconnect | Hold REQ on TSEND_C TRUE; the S7-1200 reconnects automatically when CONT=TRUE | Ensure CONT is TRUE on TSEND_C / TRCV_C; never toggle REQ at every cycle |
12. Why the DP/DP-Coupler + Y-Link Path Was Rejected
The original installation uses a SCALANCE W786-1PRO wireless link. The DP/DP coupler + Y-Link path requires the S7-400H to communicate over PROFIBUS, which would have meant adding a CP 443-5 Extended in the H-rack, a Y-Link (6ES7197-1LA12) and a DP/DP coupler (6ES7158-0AD01) in the stacker, plus a PROFIBUS cable routed back through the stacker cable reel. The wireless bridge already in place made the wireless Ethernet path the lower-cost and lower-maintenance alternative. Open IE over the existing SCALANCE W infrastructure reuses the same radio link, the same SCALANCE X108 switches, and the same grounding concept.
13. Migration to TIA Portal V15+ with PUT/GET
If the S7-400H is ever migrated to a non-H CPU (for example, on a non-redundant line), TIA Portal V15.1 and later support the legacy S7 PUT/GET path against the S7-1200. The same CPU 1214C then uses PUT / GET instructions in the "Communication -> S7 Communication" library, and the S7-400 side uses FB14 GET and FB15 PUT. For the S7-400H, however, the S7-H Add-on does not add PUT/GET support beyond the firmware already includes; the Open IE path remains the only standardized option across all firmware versions.
14. Frequently Asked Questions
Why does the CPU 412-5H not appear in the TIA Portal V12 hardware catalog?
The S7-400H is a fault-tolerant system programmed exclusively in STEP 7 V5.5 / V5.6 with the S7-H Add-on. TIA Portal does not import the H-CPU's GSD/SSD objects, and Siemens' policy is to keep H-station engineering in the classic STEP 7 tool. You can still use TIA Portal V12 for the S7-1200 side and STEP 7 V5.5 for the H side; Open IE communication (TCON / TSEND / TRCV) does not require cross-project NetPro coordination.
Can I use PUT/GET between a CPU 1214C and a CPU 412-5H directly?
PUT/GET is a Siemens S7 connection that needs to be defined in NetPro on the S7-400H side and in the device configuration on the S7-1200 side. On the H-station, the PUT/GET path is firmware-dependent and not always exposed through the S7-H Add-on. For H-system firmware V6.0.x the recommended and fully supported approach is Open IE communication with TCON / TSEND / TRCV / TDISCON, which is what this article documents.
How many Open IE connections can a CPU 1214C firmware V4.2 open simultaneously?
The CPU 1214C firmware V4.x supports up to 8 Open IE connections. Each active TCON, each TSEND_C / TRCV_C pair, and each TSEND / TRCV pair counts against this budget. If you need more than 8, move the S7-1200 to a CPU 1215C (up to 8 as well) or a CPU 1217C (firmware V4.x or V5.x), or add a CP 1242-7 / CP 1243-1 / CM 1243-5 module and use its additional connection resources.
What TSAP should I use on each side, and does it matter if I use ASCII or hex?
The TSAP is a free-form 1 to 16-byte string that identifies the partner application. ASCII is more readable in the diagnostic buffer (e.g., "S1" and "S4") and is recommended for human-troubleshootable links. Hex form (e.g., 0x53 0x31) yields the same bytes. On the S7-1200, prefix 2-byte ASCII TSAPs with [0,0,…] to mark the length as 2; on the S7-400H the UDT65 local_tsap_id_len and rem_tsap_id_len fields explicitly carry the length. The remote TSAP on side A must equal the local TSAP on side B, and vice versa.
What happens to the Open IE link when the H-system performs a redundancy switchover?
An H-system switchover moves the active role from one CPU to the other. Because both H-CPUs share the same IP (the H-system IP 192.168.0.30 in this article), the partner sees no IP change. The TCP / ISO-on-TCP socket survives if the switchover takes less than the OS keep-alive timeout of the partner (typically 30 s); S7-400H switchovers complete in 200-500 ms. If the link does drop, TSEND_C on the S7-1200 with CONT = TRUE will automatically re-establish the connection within a few seconds, and the S7-400H TCON block must be re-triggered with a rising edge on REQ.
Is Open IE communication secure on a wireless link?
Open IE is unencrypted on the S7-400H CPU onboard PN interface. On a wireless segment the link is exposed to anyone within radio range. Harden the wireless layer with WPA2/AES on the SCALANCE W786-1PRO, segment the S7 traffic into a separate VLAN, and apply the "Access protection" password on the S7-1200. For TLS on the Open IE link, use a CP443-1 EX30/GX30 on the H-station and firmware V4.4+ on the S7-1200 with ConnectionType = 0x11.