Configuring S7-1500 to S7-300 Communication via PUT/GET Blocks

David Krause13 min read
SiemensTIA PortalTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview: Cross-Generation SIMATIC S7 Communication

Linking a SIMATIC S7-1500 controller (programmed in TIA Portal) with a SIMATIC S7-300 controller (programmed in STEP 7 Classic / SIMATIC Manager) is a routine retrofit and migration task. Because the two CPUs are engineered in different project environments, the link is configured as an unspecific S7 connection in which one CPU owns the connection and references the other as an "Unknown" partner. Data exchange is then performed with the S7 Communication service using PUT and GET blocks.

The reference topology in this article uses a CPU 1515-2 PN (article number 6ES7515-2AM02-0AB0) on the S7-1500 side and a CPU 315-2 DP (6ES7315-2AH14-0AB0) with a CP 343-1 (6GK7343-1EX30-0XE0) on the S7-300 side, communicating over PROFINET/Ethernet.

S7-1500 Station (TIA Portal) CPU 1515-2 PN (6ES7515-2AM02-0AB0) IP: 192.168.0.10 PUT/GET client + server S7-300 Station (STEP 7 Classic) CPU 315-2 DP + CP 343-1 IP: 192.168.0.20 PUT/GET client + server PROFINET / Industrial Ethernet Unspecific S7 Connection (PUT/GET) Switch / LAN segment

The configuration shown above can be completed in roughly twenty minutes per station when the IP plan and DB layout are agreed in advance. The full Siemens application example is documented in the official entry: S7 Communication between SIMATIC S7-1500 and SIMATIC S7-300.

2. Prerequisites

Item Requirement Notes
S7-1500 engineering TIA Portal V16 or later (V18 / V19 / V20 supported) PUT/GET access must be enabled in the CPU properties
S7-300 engineering STEP 7 V5.5 + SPx or STEP 7 Classic in TIA Portal Use SIMATIC Manager for native "Unknown" partner support
S7-1500 CPU Firmware V2.5 or higher for full PUT/GET area support CPU 1515-2 PN supports up to 16 S7 connections
S7-300 CPU CPU 315-2 DP (6ES7315-2AH14-0AB0) Two PN/DP interfaces require CP 343-1 for S7 Communication in older projects
CP 343-1 6GK7343-1EX30-0XE0 (or compatible) Provides the Ethernet interface; max 16 S7 connections
Network TCP/IP reachable, no firewall on PG side Use ping from the PG to validate L3 reachability first
User rights Local administrator on PG, project edit rights on both projects Compiling and downloading requires full access
Connection count quick check: S7-1500 CPUs expose a "Maximum number of S7 connections" in the device properties. The default for CPU 1515-2 PN is 16, of which "PG communication", "HMI communication" and "S7 communication" share the pool. Plan headroom for online diagnostics, HMI, and other S7 partners.

3. S7 Connection vs. TCP Connection - Which One to Use

For the use case described here, the S7-1500 ↔ S7-300 link must be implemented as an S7 connection, not a raw TCP connection. The reasons are operational, not merely conventional:

  • S7 connection uses the SIMATIC S7 Communication protocol on top of ISO-on-TCP (RFC 1006, port 102). It is connection-oriented, password-protected, and supported natively by the PUT/GET blocks of every S7-300/400/1500 CPU.
  • TCP connection (T-block family: TSEND/TRCV on S7-1500, FB186/FB187-style on S7-300) requires custom packaging of every payload. It is the right tool only when the partner is a non-Siemens device or when explicit message framing is required.
  • The official Siemens catalog of communication instructions is described in Instructions for communication tasks (S7-300, S7-400, S7-1500).

PUT/GET is the lower-overhead option for cyclic DB-to-DB mirroring and does not require a configured connection on the partner side - it is sufficient to configure the S7 connection on the CPU that issues the request (the "active" partner) and declare the remote as unspecific on that one station.

4. TIA Portal Configuration on the S7-1500 Side

4.1 Create the S7 connection

  1. Open the S7-1500 project in TIA Portal.
  2. Select the CPU 1515-2 PN in the project tree, then open Properties → Communication → S7 connections.
  3. Click Add new S7 connection. The partner type defaults to "Unspecific"; leave it on that value because the S7-300 is not part of this TIA project.
  4. Set the Local ID (e.g. 1). This is the connection handle you will pass to the PUT/GET block.
  5. Enter the partner IP address (192.168.0.20) and the partner's Rack/Slot for the S7-300 side. For a CPU 315-2 DP with CP 343-1, the S7 partner address is the CP's Ethernet interface: rack 0, slot 0 is conventional for the CP, or the configured slot from the S7-300 project's hardware configuration. The CP 343-1 is normally projected in slot 4 of the S7-300 rack when set as the default.
  6. Enable Active connection establishment on the local (S7-1500) side if this CPU will own the connection, or leave it passive if the S7-300 will own it.
  7. Compile the project and download the connection configuration to the CPU 1515-2 PN.

4.2 Connection ID handling

The Local ID configured above is the value that the S7-1500 PUT/GET instruction expects on its ID input. It must match the ID parameter the S7-300 will use on its PUT/GET block when it owns the connection. Adopt a project-wide convention: S7-1500 always uses odd local IDs (1, 3, 5…) and S7-300 always uses the mirrored even IDs (2, 4, 6…).

5. STEP 7 Classic Configuration on the S7-300 Side

5.1 Create the S7 connection in NetPro

  1. Open the S7-300 project in SIMATIC Manager.
  2. Launch NetPro from the project view.
  3. Right-click the CP 343-1 in the S7-300 station and choose Insert New Connection.
  4. In the connection partner dialog select "Unspecified" / "S7 Connection (unspecific)" from the partner dropdown. The partner's IP is then entered manually.
  5. Choose S7 connection as the connection type, then enter the partner IP 192.168.0.10 and the S7-1500 rack/slot (rack 0, slot 1 for CPU 1515-2 PN).
  6. Set the Local ID on this side (e.g. 2 if the TIA project uses 1).
  7. Save, compile, and download NetPro to the CP 343-1.

5.2 Cross-check

When correctly configured, opening Monitor/Modify on the S7 connection in NetPro will show the connection in ESTABLISHED state after a few seconds of CPU run time, even before the PUT/GET blocks are loaded. If the status is PARTNER-ABORT or OWN-ABORT, jump to the troubleshooting matrix at the end of this article.

6. Enabling PUT/GET Access on the S7-1500 CPU

Mandatory step. By default the S7-1500 access protection blocks remote PUT/GET calls. The connection may establish successfully while PUT/GET still returns STATUS = 0x0001_FFFF ("operation not permitted") if this setting is not changed.
  1. In TIA Portal select the CPU 1515-2 PN and open Properties → Protection & Security → Access level.
  2. Scroll to the Connection mechanisms section.
  3. Tick the checkbox "Permit access with PUT/GET communication from remote partner".
  4. Confirm with OK, recompile, and download the hardware configuration to the S7-1500.

The S7-300 does not have an equivalent global access toggle - the connection in NetPro, combined with the S7 user program using PUT/GET, is sufficient. The CP 343-1 firmware V3.x and higher are required for S7 communication as a server.

7. Programming PUT/GET on the S7-300 Side (FB14 / FB15)

7.1 Block sources

Insert FB14 "GET" and FB15 "PUT" into the S7-300 program from the standard library path Communication Blocks → Blocks. A dedicated instance DB is created for each call (e.g. DB100 for the GET instance and DB101 for the PUT instance). The official Siemens FAQ for these blocks is the entry "Sample Program: S7 Communication with blocks FB14 (GET) and FB15 (PUT) of the CPU 317-2PN/DP".

7.2 GET interface (S7-300 reads from S7-1500)

// FB14 "GET" - read data from the S7-1500 partner
CALL  "GET" , "DB_GET_Inst"
  REQ    :=M0.0                // 1 = start read
  ID      :=W#16#2              // Local ID of the S7 connection (NetPro)
  NDR     :=M10.0               // 1 = new data received
  ERROR   :=M10.1               // 1 = error, see STATUS
  STATUS  :=MW12                // Detailed status word
  ADDR_1  :=P#DB200.DBX0.0 BYTE 100   // Source area in S7-1500 partner
  RD_1    :=P#DB50.DBX0.0 BYTE 100    // Destination in this S7-300 CPU

7.3 PUT interface (S7-300 writes into S7-1500)

// FB15 "PUT" - write data to the S7-1500 partner
CALL  "PUT" , "DB_PUT_Inst"
  REQ    :=M0.1                // 1 = start write
  ID      :=W#16#2              // Same Local ID
  DONE    :=M10.2               // 1 = write completed without error
  ERROR   :=M10.3               // 1 = error, see STATUS
  STATUS  :=MW14
  ADDR_1  :=P#DB201.DBX0.0 BYTE 50    // Destination area in S7-1500
  SD_1    :=P#DB60.DBX0.0 BYTE 50     // Source in this S7-300 CPU

7.4 Multi-area variants

FB14 and FB15 support up to four address pairs (ADDR_1..ADDR_4, RD_1..RD_4, SD_1..SD_4). For each pair the length must be a multiple of one byte and a maximum of 160 bytes; total payload per call is bounded by the partner's connection resources. If more than 160 bytes must be transferred, segment the transfer into multiple calls or use a single ANY pointer of up to 462 bytes - both block variants are valid; segmenting is more portable across firmware versions.

8. Programming PUT/GET on the S7-1500 Side

The S7-1500 provides the same service via the instructions GET and PUT from the Instructions → Communication → S7 Communication palette. Drop the instruction into a cyclically executed OB (typically OB1 or OB35).

8.1 GET instance on S7-1500 (reads from S7-300)

// S7-1500 GET - read 80 bytes from S7-300 DB20
%I0.0  "Trigger_GET"  // positive edge = start
"Inst_GET"(
  REQ    :=  "Trigger_GET",
  ID     :=  1,                       // Local ID from TIA connection
  NDR    =>  "GET_Done",
  ERROR  =>  "GET_Error",
  STATUS =>  "GET_Status",
  ADDR_1 :=  P#DB20.DBX0.0 BYTE 80,   // Area in the S7-300 partner
  RD_1   :=  P#DB120.DBX0.0 BYTE 80   // Destination in this CPU
);

8.2 PUT instance on S7-1500 (writes to S7-300)

// S7-1500 PUT - write 32 bytes to S7-300 DB21
%I0.1  "Trigger_PUT"
"Inst_PUT"(
  REQ    :=  "Trigger_PUT",
  ID     :=  1,
  DONE   =>  "PUT_Done",
  ERROR  =>  "PUT_Error",
  STATUS =>  "PUT_Status",
  ADDR_1 :=  P#DB21.DBX0.0 BYTE 32,   // Destination in S7-300
  SD_1   :=  P#DB130.DBX0.0 BYTE 32   // Source in S7-1500
);

8.3 Data limits on S7-1500 PUT/GET

Parameter S7-1500 PUT/GET Notes
Bytes per call (single area) up to 462 bytes Larger DBs must be segmented
Total connection payload subject to CPU-specific connection resources See CPU datasheet for "max user data per S7 connection"
Allowed remote areas Inputs (I), Outputs (Q), Merkers (M), DBs DB must be "unoptimized" access on S7-300 side
Bit/byte boundary Byte aligned Bit-granular pointers are accepted by FB14/FB15 but not by S7-1500 PUT/GET; segment at byte boundaries

9. Common STATUS Codes

STATUS (hex) Meaning Corrective action
0000_0000 Job completed without error None
0000_0001 Job in progress Wait for NDR/DONE
0000_81xx Local connection resource error Check Local ID matches NetPro/TIA connection
0000_82xx Partner rejects the request Verify PUT/GET access permitted on S7-1500
0001_FFFF Operation not permitted by access protection Enable PUT/GET in S7-1500 protection settings
000A_0A01 Address error in ADDR_1 / SD_1 Re-check ANY pointer syntax; check DB number exists on the partner
0080_0000 At least one job in progress, no new REQ accepted Wait for prior job to finish
80A1_xxxx Connection aborted by partner Check CP 343-1 diagnostics, partner CPU run state
80C3_0000 Connection resource exhausted Reduce active connections or upgrade CPU

10. Verification and Online Diagnostics

  1. Open the S7-1500 online view in TIA Portal. Navigate to Online & Diagnostics → Communication → S7 connections. The new connection should display state ESTABLISHED with the partner IP shown.
  2. On the S7-300 side open NetPro, select the CP 343-1, and use PLC → Monitor/Modify on the S7 connection. State should read ESTABLISHED as well.
  3. Force the trigger tag on one side and observe the destination area on the other using a watch table. Update time is typically 50-150 ms for a 100-byte payload on PROFINET, depending on connection scan cycle and partner CPU load.
  4. Use the S7-1500 web server (CPU properties → Web server → Activate) for a browser-based cross-check of the connection state and DB contents without installing TIA Portal on every service laptop.
  5. For a structured status display, instantiate DIAG_INF (S7-300) or read the S7 connection's STATUS from the SZL partial list 0x0132 in OB82/OB100.

11. Troubleshooting Matrix

Symptom Likely cause Remediation
Connection never reaches ESTABLISHED IP mismatch, subnet mask, or CP 343-1 not downloaded ping both directions, re-download NetPro, confirm CP firmware ≥ V3.0
Connection ESTABLISHED but STATUS = 0001_FFFF PUT/GET access disabled on S7-1500 Tick the "Permit access with PUT/GET" checkbox in CPU properties
STATUS = 000A_0A01 on every call Bad ANY pointer or non-existent DB on the partner Verify DB number and length on the partner; use Watch Table with absolute addressing
STATUS = 80A1_xxxx after a few hours of operation CP 343-1 partner-aborted; IP conflict or PG port 102 blocked Check ARP table, disable Windows firewall or any anti-virus on the PG side
Data goes one direction only PUT/GET client side installed but server side missing Add the reciprocal call (PUT ↔ GET) on the partner station; one CPU cannot serve a request it did not own
Data arrives only after PLC restart Connection configured on the wrong side; PUT/GET call issued before connection completes Configure connection on the active side, gate REQ with ESTABLISHED status
CPU STOP on S7-1500 with SF LED Optimized DB access mismatch when reading from S7-300 Uncheck "Optimized block access" on the destination DB on S7-1500, or expose a non-optimized DB copy
Intermittent data loss under high load Trigger rate exceeds partner cycle; call collisions Use a one-shot REQ gated by NDR/DONE; do not call PUT/GET every OB1 cycle

12. Field-Proven Best Practices

  • Configure on one side only. Whether TIA or STEP 7 Classic owns the connection is a project decision - pick the side where the engineer is more likely to maintain the project and keep the partner "Unspecific" everywhere else.
  • Match access levels. If the S7-1500 project uses password-protected access levels, store the password in the TIA project; otherwise the S7-300 PUT/GET will be denied even with the security flag enabled.
  • Watch DB block consistency. Mark both source and destination DBs as non-optimized to avoid byte-alignment gaps in S7-300. Optimized DBs on the S7-1500 must be addressed using symbolic names, but the partner still receives raw byte data.
  • Plan the connection count. Each S7-1500 and each CP 343-1 has a finite S7 connection pool. Reserve at least 4 free S7 connections for online, HMI, and one future expansion.
  • Use a single trigger source. A Clock_Byte or a slow OB35 task is a more reliable trigger than every-cycle OB1, especially for larger payloads.
  • Document the Local ID map. Mirror the Local ID in a project header comment so a future engineer can correlate the TIA connection ID with the STEP 7 NetPro ID.
  • Validate endianness and length. Both CPUs are little-endian, but mixing INT and WORD views of the same bytes will produce misleading values; agree on a "byte layout table" before commissioning.

FAQ

Must I use an S7 connection or a TCP connection between S7-1500 and S7-300?

Use an S7 connection. It rides on ISO-on-TCP (RFC 1006, port 102) and is supported by the PUT/GET blocks of every S7-300/400/1500 CPU. Use raw TCP (TSEND/TRCV) only when the partner is a non-Siemens device or when explicit framing is required.

Do I have to configure the connection on both CPUs?

No. Configure the S7 connection on the active side only and set the partner to "Unspecific" / "Unknown". The S7-300 references the S7-1500 by IP, rack, and slot; the S7-1500 then answers all PUT/GET requests that target its DBs, M, I, or Q areas.

Why does the connection establish but PUT/GET return error STATUS = 0001_FFFF?

The S7-1500 access protection is blocking remote PUT/GET. Open CPU properties → Protection & Security → Access level and tick "Permit access with PUT/GET communication from remote partner". Recompile and download.

What is the maximum payload per PUT/GET call?

FB14/FB15 on the S7-300 handle up to 160 bytes per address pair (4 pairs per call). The S7-1500 PUT/GET instructions accept up to 462 bytes per area. For larger transfers, segment into multiple calls and avoid overlapping triggers.

Which DB attributes are required on the S7-1500 when accessed from the S7-300?

The DB exposed to the S7-300 must be "non-optimized" (the "Optimized block access" checkbox cleared) or you must use a non-optimized "proxy" DB. The S7-300 PUT/GET blocks address bytes absolutely and do not know the symbolic slot layout of optimized S7-1500 blocks.

How do I check the connection state from a running plant without TIA Portal?

Activate the S7-1500 web server, browse to the CPU's IP, and open the connection overview; the S7-300 side can be read with a CP 343-1 diagnostic buffer dump (PLC → Module Information → Diagnostic Buffer).

Back to blog