Configuring SINAMICS S120 PROFIBUS Communication via SFC14/15

David Krause16 min read
ProfibusSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview

The SINAMICS S120 drive family uses the PROFIdrive profile on PROFIBUS DP (and PROFINET IO) to exchange setpoints, actual values, control words, and status words between the SIMATIC S7 controller and the drive. On the controller side, the standard SIMATIC mechanism for cyclic PZD (Process Data) exchange is SFC14 (DPRD_DAT) for reading consistent data from the drive and SFC15 (DPWR_DAT) for writing consistent data to the drive. For parameter handling outside the fast cyclic channel, the DPV1 acyclic services are available through SFC58 (WR_REC) and SFC59 (RD_REC) (and the older SFC55 / SFC56 / SFC57 on S7-300/400).

This reference covers the canonical commissioning path for a CU320-2 DP (or CU320 DP) controlled SINAMICS S120 on PROFIBUS DP with an S7-300/400 CPU. It addresses the four questions typical to a first-time integrator:

  1. Whether the SFCs are appropriate and how the telegram is wired on the PLC side.
  2. Which control-word / status-word bits (STW1 / ZSW1) and which SINAMICS parameters (P2050 / P2051 / P2061 / r2050 / r2090…) must be configured.
  3. Which blocks perform cyclic vs. acyclic data transfer.
  4. Field-proven caveats that prevent first-start-up from failing.

A ready-made S7 sample project that already includes FB283 for basic positioning can be downloaded from Siemens support under entry ID 25166781. FB283 encapsulates the SFC14 / SFC15 handshake for the standard positioning telegrams and is the recommended starting block whenever the drive runs a positioning telegram (Telegram 7 / 9 / 110).

Hardware scope: This document focuses on SINAMICS S120 with CU320 / CU320-2 DP. The CU240S DP belongs to the SINAMICS G120 family and uses a different parameter set (e.g., r2050, p0922 telegram select, p1001 quick commissioning). If you migrate logic from G120 to S120, re-map all PROFIdrive parameters on the drive side and verify the telegram selection on the PLC hardware configuration.

2. Prerequisites

  • Firmware: SINAMICS S120 with CU320-2 DP firmware ≥ 4.4 (for full FB283 compatibility) or matching S120 List Manual for the firmware on site. STARTER ≥ V4.4 or Startdrive ≥ V15 for commissioning.
  • SIMATIC side: STEP 7 V5.5 SP2 (or TIA Portal V13+ for S7-300/400 projects), S7-CPU with PROFIBUS DP master interface (e.g., CPU 315-2 DP, CPU 317-2 DP, CPU 319-3 PN/DP, or an S7-400 CPU with CP443-5).
  • GSD file: Siemens GSD file "SIEM811F.gsd" (or the most recent SI0xxxxx.GSD) for the SINAMICS S120 drive. Available from the Siemens support entry 49216293.
  • Hardware: PROFIBUS DP cable (purple, shielded), bus terminator on both ends, two connectors at the drive (CBC10/CBC11 communication board on the CU320).

3. Hardware Topology and Telegram Selection

The PROFIdrive profile defines standard telegrams that map STW1 / ZSW1, NSOLL / NIST, and additional process data into a fixed set of PZD words. The PLC and the drive must agree on the same telegram for consistent decoding.

PROFIdrive Telegram Direction (PLC → Drive) Direction (Drive → PLC) Typical Use
Telegram 1 STW1, NSOLL ZSW1, NIST, IAIST, MIST, WARN, FAULT Speed control
Telegram 2 STW1, NSOLL ZSW1, NIST, IAIST, MIST, WARN, FAULT Speed control (no encoder)
Telegram 3 STW1, NSOLL ZSW1, NIST, IAIST, MIST, WARN, FAULT Speed control, 4 PZD each direction
Telegram 4 STW1, NSOLL ZSW1, NIST, IAIST, MIST, WARN, FAULT Speed control, 6 PZD each direction
Telegram 7 STW1, STW2, NSOLL ZSW1, ZSW2, NIST Basic positioning
Telegram 9 STW1, STW2, NSOLL ZSW1, ZSW2, NIST Basic positioning (extended)
Telegram 110 STW1, STW2, NSOLL, MIST ZSW1, ZSW2, NIST, IAIST Positioning with torque limit
Telegram 999 Free (user-defined) Free (user-defined) Custom via P2051 / P2061

Telegram selection on the drive:

  • Set P0922 = 1 for PROFIdrive Telegram 1, or the appropriate number for the chosen telegram.
  • Set P2038 = 0 for PROFIdrive profile (default).

Telegram selection on the PLC: In HW Config, after inserting the SINAMICS S120 from the GSD catalog, double-click the drive slot and assign the same telegram number on the "PROFIBUS message frame" drop-down. The I and Q addresses start at the configured base address (e.g., PE 256 / PA 256).

Consistency rule: Telegram 1 = 4 words input + 4 words output. Telegram 7 = 5/6 words. Always set the access type to "Whole length consistent" on the PLC hardware configuration, otherwise SFC14 / SFC15 will fault with 80C4 (length error) or 80C1 (parameter assignment error) because the CPU cannot guarantee consistent access to sub-word data.

4. SINAMICS S120 PROFIBUS Parameter Layout

The S120 routes PROFIBUS PZD through BICO interconnections. The most frequently misconfigured pair is P2051 (length of received PZD) vs. r2050 / r2090 (source of sent PZD).

Parameter Direction Purpose Default for Telegram 1
P2051[0..15] PLC → Drive (input PZD word count) CI: PZD received (BICO source for each word) 4 entries: STW1 (r2090.0), NSOLL_B (r2090.1), free, free
P2061[0..15] PLC → Drive (BICO sink) BICO default mapping for received PZD Defaults to control word / setpoint slots
r2050[0..15] Drive → PLC (output PZD word count) CO: PZD sent (status / actual values) 4 entries: ZSW1, NIST_B, IAIST, MIST
r2090.0…r2094.15 Drive internal Bit-wise access to received PZD Used by BICO to route individual bits of STW1 to lower-level drive functions
r2053[0..15] Drive internal Diagnostic: BICO source actually used Read-only
r2054 Drive internal PROFIBUS diagnosis / fault buffer Read-only

Step-by-step drive commissioning (PROFIBUS portion):

  1. Run quick commissioning in STARTER to set motor data, encoder data, current / speed limits, and ramp-function generator timings (P1120, P1121).
  2. Open Communication → PROFIBUS and set P0922 to the desired telegram.
  3. Open Configuration → Process data. Verify that P2051 entries match the telegram definition. For Telegram 1 you should see:
    P2051[0] = r2090.0 (STW1 source)
    P2051[1] = r2090.1 (NSOLL_B source)
  4. Verify r2050[0..3] values: ZSW1, NIST_B, IAIST, MIST for Telegram 1.
  5. Save and Copy RAM to ROM. Power-cycle to load.

5. Cyclic Communication with SFC14 (DPRD_DAT) and SFC15 (DPWR_DAT)

On the SIMATIC S7-300/400, SFC14 and SFC15 read and write the consistent PZD area of a DP slave in a single call. They bypass the I/O image so the transfer is not fragmented across OB1 scan boundaries.

SFC Function Inputs Outputs
SFC14 (DPRD_DAT) Read consistent data from DP slave LADDR (WORD), RET_VAL (INT) RECORD (ANY-pointer to DB), RET_VAL
SFC15 (DPWR_DAT) Write consistent data to DP slave LADDR (WORD), RECORD (ANY-pointer), RET_VAL (INT) RET_VAL, BUSY

Typical data block layout for Telegram 1:

DATA_BLOCK DB100
STRUCT
    STW1       : WORD;  // offset 0  - Control Word 1 (output)
    NSOLL      : INT;   // offset 2  - Speed setpoint (output)
    unused1    : WORD;  // offset 4
    unused2    : WORD;  // offset 6
    ZSW1       : WORD;  // offset 8  - Status Word 1  (input)
    NIST       : INT;   // offset 10 - Speed actual  (input)
    IAIST      : INT;   // offset 12 - Current actual
    MIST       : INT;   // offset 14 - Torque actual
END_STRUCT
END_DATA_BLOCK

SFC call in OB1 (cyclic exchange):

// --- Output direction: PLC → drive ---
CALL "DPWR_DAT"     // SFC15
   LADDR   := W#16#100;       // base address of output area (PE 256 in example)
   RECORD  := P#DB100.DBX 0.0 WORD 8;   // 8 bytes = 4 words
   RET_VAL := MW100;

// --- Input direction: drive → PLC ---
CALL "DPRD_DAT"     // SFC14
   LADDR   := W#16#100;       // same base address; SFC14 reads input area
   RET_VAL := MW102;
   RECORD  := P#DB100.DBX 8.0 WORD 8;   // store at offset 8

For Telegram 7 / 110 with 5–6 PZD words each direction, the RECORD length must equal 2 × number of PZD. For Telegram 999 (free) the length follows P2051 on the drive.

Alignment: Some STEP 7 V5.x releases complain when the RECORD ANY-pointer is not word-aligned. Always use DBX 0.0, DBX 8.0, DBX 16.0 as offsets. Byte offsets other than multiples of 8 cause SFC15 to return error code 0x80B0 or 0x80B1.

6. Control Word 1 (STW1) Encoding

STW1 is the master enable word. The bits follow the PROFIdrive AC1 profile. For a speed-controlled drive, only six bits are typically toggled in normal operation.

Bit Meaning State to Run
0 ON / OFF1 1 = drive energized
1 Coast stop (OFF2) 1 = no coast; 0 = coast to 0
2 Quick stop (OFF3) 1 = no quick stop; 0 = ramp P1135
3 Enable operation 1 = enable pulses
4 Enable ramp generator 1 = ramp output active
5 Unfreeze ramp generator 1 = ramp proceeds
6 Enable speed setpoint 1 = setpoint applied
7 Acknowledge fault 0→1 edge clears faults
8 Jogging 1 Optional
9 Jogging 2 Optional
10 Control by PLC 1 = PLC is active source
11-15 Reserved / vendor Per drive profile

Standard control words referenced in the source conversation:

// 0x047F = 0000 0100 0111 1111b
//   bit0  = 1  ON
//   bit1  = 1  OFF2 inactive
//   bit2  = 1  OFF3 inactive
//   bit3  = 1  Enable operation
//   bit4  = 1  Enable ramp generator
//   bit5  = 1  Unfreeze ramp generator
//   bit6  = 1  Enable setpoint
//   bit10 = 1  Control by PLC
STW_RUN  := WORD#16#047F;

// 0x047E = same but bit0 = 0 → controlled OFF1 ramp to zero, then pulse inhibit
STW_OFF1 := WORD#16#047E;

The OFF2 command is 0x047D (bit 1 cleared). The OFF3 command is 0x047B (bit 2 cleared). Inhibit operation / coast is 0x047C (bit 0 cleared, bit 1 cleared, bit 2 cleared).

7. Status Word 1 (ZSW1) Decoding

ZSW1 mirrors the drive state. Read it from DB100.ZSW1 after SFC14 has executed.

Bit Meaning
0 Ready to switch on
1 Ready to operate (pulses off, link charged)
2 Operation enabled (pulses on)
3 Fault present
4 OFF2 inactive
5 OFF3 inactive
6 Switching on inhibited
7 Alarm present
8 Speed setpoint / actual deviation within tolerance
9 Control requested (PLC has control)
10 f or n reached
11 I, M, or P limit reached
12-15 Reserved / vendor

For the controller to issue run commands, the PLC must first set P3981 = 1 on the drive (Control Unit priority from PROFIBUS) and the fieldbus option module must be in control priority mode (P3985). On the S120 this is typically done automatically when Telegram 1 (or higher) is active and the drive is in PROFIdrive profile mode.

8. Acyclic Parameter Access via DPV1 (SFC58 / SFC59)

Beyond the cyclic PZD, SINAMICS S120 exposes the full parameter set (~ 8000 parameters) over PROFIBUS DPV1 record 47 (read) / 48 (write). The SIMATIC S7 side uses SFC59 (RD_REC) to read and SFC58 (WR_REC) to write.

SFC Function Key Parameters
SFC58 (WR_REC) Write DPV1 record REQ, IOID, LADDR, RECNUM, RECORD (ANY), RET_VAL, BUSY
SFC59 (RD_REC) Read DPV1 record REQ, IOID, LADDR, RECNUM, RET_VAL, BUSY, RECORD
SFC55 (WR_PARM) Legacy write parameter Older style, do not mix with DPV1
SFC56 (RD_PARM) Legacy read parameter Older style
SFC57 (PARM_MOD) Modify parameter (toggle) Older style

DPV1 request / response payload layout (PROFIdrive parameter channel, hex):

// Request header (4 words):
// Word 0: Reference = 0x01
// Word 1: Request ID  (0x01 = read, 0x02 = write)
// Word 2: Parameter number (e.g. 0x1019 = P1019)
// Word 3: Parameter index (e.g. 0x0001 for index 1 of array parameter)
// Word 4+: parameter value(s) for write

Example: read parameter P21 (drive reference speed) via DPV1:

DATA_BLOCK DB200
STRUCT
    req_header : ARRAY[0..3] OF WORD;  // reference, ID, PNU, index
    resp_value : WORD;                 // response word
END_STRUCT
END_DATA_BLOCK

CALL "RD_REC"   // SFC59
   REQ    := TRUE;
   IOID   := B#16#54;            // input ID
   LADDR  := W#16#100;           // diagnostic address of drive
   RECNUM := B#16#47;            // record number 47 (DPV1 read)
   RET_VAL := MW200;
   BUSY   := M201.0;
   RECORD := P#DB200.DBX 0.0 WORD 8;

// After BUSY=0: DB200.resp_value holds the parameter content (Word 4 of response).
Multi-word parameters: Parameters that span multiple words (e.g., string parameters, ramp times P1120 / P1121 represented as floating-point, or 32-bit diagnostics) need the full payload length. Add 4 words to the payload for every parameter value word. The maximum payload length per call is 240 bytes (120 words).

9. Using FB283 for Basic Positioning

FB283 (formerly part of the "SIMATIC S7 FB283" library, supplied with the SINAMICS S120 Function Block description) implements the SFC14 / SFC15 handshake and adds the positioning state machine defined by PROFIdrive Telegram 7 / 110. It is the Siemens-recommended block when the drive runs the EPOS basic positioner.

Inputs / outputs of FB283 (selected):

Port Direction Description
AxisNo IN Drive axis number (1..N)
LADDR IN PROFIBUS base address (HW Config)
JOGPos / JOGNeg IN Jog commands
ModeSelect IN Operating mode (1 = pos, 2 = homing, 3 = jog, …)
TargetPos IN DINT absolute target position
Velocity IN REAL velocity (LU/min)
Execute IN Edge-triggered start of motion block
Done OUT Motion finished
Fault OUT Drive fault latched
ActPos OUT Actual position DINT
DiagId / ErrorNum OUT Internal FB283 diagnostic

FB283 hides the manual toggling of STW1 / STW2 bits and the write of NSOLL. Internally it constructs the standard Telegram 7 word sequence (STW1, STW2, NSOLL, ModePos2, ModePos3) and decodes ZSW1 / ZSW2 / NIST / ActPos / ModePosStat back into BOOL/DINT outputs.

The full sample program ("SINAMICS S120 with S7-300/400 Basic Positioning") and FB283 documentation are published as Siemens support entry 25166781.

10. Verification and Diagnostics

  1. Bus status: Check SF and BF LEDs on the CPU. BF solid red = PROFIBUS cable break or slave not in project; flashing red = intermittent.
  2. Drive LED: The CU320 RDY green + COMM green = cyclic traffic active.
  3. Drive parameter r2054: Contains the cyclic telegram diagnostics. r2054[0] = number of configured PZD in, r2054[1] = number of configured PZD out.
  4. SFC return codes: If RET_VAL ≠ 0 after SFC14 / SFC15, decode per the table below.
RET_VAL Cause Remedy
0x0000 No error —
0x80A0 Negative acknowledgement from slave Check r0947 on drive; check telegram number match
0x80A1 DP slave is offline Check PROFIBUS address / cable / termination
0x80A2 Master system not configured Re-run HW Config download
0x80B0 Length / type conflict at SFC14/15 Confirm consistent access, ANY-pointer length matches telegram length
0x80B1 Length of RECORD too long Reduce number of PZD or split into two calls
0x80C0 DPV1 protocol error (record number) Verify RECNUM = 47 for read, 48 for write
0x80C1 DPV1 access: parameter does not exist Check parameter number in List Manual
0x80C2 DPV1: parameter access denied (read-only) Use correct access type or drive password (P3978)
0x80C3 DPV1: parameter access temporarily not possible Wait for "operational" state, retry
0x80C4 DPV1: parameter value invalid Check value range in List Manual

Drive-side faults to watch for:

  • F08501 (PN/COMM fault) — telegram timeout, increase P2047 cycle time monitoring or check cable.
  • F08502 (sign-of-life) — telegram time-slot violation; reduce bus load or shorten OB1 cycle.
  • F08504 (PZD configuration) — P0922 telegram number mismatch between HW Config and STARTER.
  • A08511 (PZD configuration warning) — sent / received length inconsistent with telegram.

11. Common Pitfalls and Field-Proven Caveats

  1. Wrong GSD revision. Use the GSD that matches the S120 firmware family. Mixing SIEM811F (old) with CU320-2 V4.4+ leaves some BICO defaults invisible in STARTER.
  2. Inconsistent access not set. HW Config default is "Byte access". Without "Whole length consistent" the SFC14/15 data is corrupted every other OB1 cycle.
  3. Bit 10 of STW1 cleared. With bit 10 = 0 the drive ignores the PLC setpoint and does not accept run commands. Default STW1 = 0x0000, which leaves the drive in "switch-on inhibit" — exactly the symptom seen during first commissioning.
  4. Wrong PROFIBUS address on the drive. Address is set via P0918 on the CU320 DIP switches or via the rotary switch on the CBC10 / CBC11 board. Confirm with STARTER → Online → PROFIBUS diagnostics.
  5. Checksum mismatch after telegram change. When switching from Telegram 1 to Telegram 7 the offsets of NSOLL and NIST change. Verify DB layout in STEP 7 and rerun HW Config download.
  6. Mixing legacy SFC55/56/57 with modern SFC58/59. SFC55/56 use slot 0; SFC58/59 use slot 0 too, but the request/response header differs. Pick one family per project.
  7. CU240S DP question. If you later migrate to a G120 (CU240S DP), the parameter layout differs (r2050, p0922, p1001 quick commissioning). The PLC-side SFC14/15 code does not change, but you must re-map every parameter.
  8. Without FB283, manual toggling is fragile. Always sequence STW1 transitions: OFF (0x047E) → ON inhibited (0x0401) → wait for ZSW1 bit 0=1 → ON (0x0407) → enable (0x047F) — inserting 0x047E only between states.

12. Quick Commissioning Checklist

  • [ ] Drive quick commissioning complete (motor data, encoder, ramp, limits).
  • [ ] P0922 telegram selected.
  • [ ] P2038 = 0 PROFIdrive profile active.
  • [ ] P2051[0..n-1] matches Telegram direction (STW1 at index 0, NSOLL at index 1).
  • [ ] P3981 = 1 Control Unit priority = PLC.
  • [ ] GSD installed in STEP 7; drive inserted in HW Config at correct PROFIBUS address.
  • [ ] "Whole length consistent" set on I/O area.
  • [ ] DB layout matches Telegram offsets (Word boundaries).
  • [ ] SFC14 / SFC15 called every OB1 scan.
  • [ ] STW1 = 0x047F in run; 0x047E for controlled OFF1; 0x047C for coast.
  • [ ] ZSW1.bit2 = 1 indicates operation enabled.
  • [ ] Fault F08501 / F08502 / F08504 not active in r0947.

FAQ

Which SFCs are used for cyclic data exchange between S7-300/400 and SINAMICS S120 over PROFIBUS?

Use SFC15 (DPWR_DAT) to write consistent PZD data to the drive and SFC14 (DPRD_DAT) to read consistent PZD data from the drive. Both are called from OB1 with LADDR set to the configured PROFIBUS base address and RECORD pointing to a DB with the proper Telegram layout.

What control word value starts the drive (Telegram 1, speed control)?

STW1 = 0x047F enables the drive: bit 0 ON, bits 1–3 OFF2/OFF3/enable cleared, bit 4 ramp enable, bit 5 unfreeze, bit 6 enable setpoint, bit 10 control-by-PLC. For controlled OFF1 ramp stop use 0x047E; for coast stop (OFF2) use 0x047D; for quick stop (OFF3) use 0x047B.

Which drive parameters configure the PROFIBUS process data on SINAMICS S120?

The key parameters are P0922 (telegram selection), P2051 / P2061 (received PZD BICO mapping), r2050 (sent PZD BICO mapping), and P3981 (control priority). Defaults for Telegram 1 place STW1 in r2090.0, NSOLL_B in r2090.1, ZSW1 in r2050[0], NIST_B in r2050[1], IAIST in r2050[2], MIST in r2050[3].

How do I read a non-cyclic parameter (e.g., P21) from the S120 over PROFIBUS?

Use SFC59 (RD_REC) with LADDR = drive diagnostic address, RECNUM = B#16#47, and a RECORD ANY-pointer with the PROFIdrive parameter channel header (reference 0x01, request ID 0x01, parameter number, parameter index). The response word at offset 8 contains the parameter value. Use SFC58 (WR_REC) with RECNUM = B#16#48 to write parameters.

Can I use FB283 with a CU240S DP instead of CU320?

No — CU240S DP belongs to the SINAMICS G120 family and is not controlled by FB283 (which targets SINAMICS S120 positioning telegrams). For G120 you use either the SFC14/15 manual path with PROFIdrive Telegram 1, or the G120-specific FB block from the SINAMICS G120 library. The SFC14/15 PLC code itself works identically.

Why does SFC15 return 0x80B0 even though the drive is online?

0x80B0 indicates a length or access-type mismatch. Verify two things: (1) the I/O area in HW Config is set to "Whole length consistent"; (2) the RECORD ANY-pointer length in bytes equals 2 × number of PZD (e.g., 8 bytes for 4 PZD). Byte-aligned but not word-aligned offsets also trigger 0x80B0/B1.

Where can I download the SINAMICS S120 PROFIBUS GSD file and a sample project?

The GSD file "SIEM811F.gsd" (and newer revisions) is available from Siemens support entry 49216293. A complete S7 sample project with FB283 for basic positioning is published as entry 25166781. The functional description "Speed Control of a SINAMICS S120 with SIMATIC S7-300/400F" is attached to entry 68624711.

Back to blog