1. Overview
The SINAMICS S120 drive family uses the PROFIdrive profile on PROFIBUS DP (and PROFINET IO) to exchange setpoints, actual values, control words, and status words between the SIMATIC S7 controller and the drive. On the controller side, the standard SIMATIC mechanism for cyclic PZD (Process Data) exchange is SFC14 (DPRD_DAT) for reading consistent data from the drive and SFC15 (DPWR_DAT) for writing consistent data to the drive. For parameter handling outside the fast cyclic channel, the DPV1 acyclic services are available through SFC58 (WR_REC) and SFC59 (RD_REC) (and the older SFC55 / SFC56 / SFC57 on S7-300/400).
This reference covers the canonical commissioning path for a CU320-2 DP (or CU320 DP) controlled SINAMICS S120 on PROFIBUS DP with an S7-300/400 CPU. It addresses the four questions typical to a first-time integrator:
- Whether the SFCs are appropriate and how the telegram is wired on the PLC side.
- Which control-word / status-word bits (STW1 / ZSW1) and which SINAMICS parameters (P2050 / P2051 / P2061 / r2050 / r2090…) must be configured.
- Which blocks perform cyclic vs. acyclic data transfer.
- Field-proven caveats that prevent first-start-up from failing.
A ready-made S7 sample project that already includes FB283 for basic positioning can be downloaded from Siemens support under entry ID 25166781. FB283 encapsulates the SFC14 / SFC15 handshake for the standard positioning telegrams and is the recommended starting block whenever the drive runs a positioning telegram (Telegram 7 / 9 / 110).
2. Prerequisites
- Firmware: SINAMICS S120 with CU320-2 DP firmware ≥ 4.4 (for full FB283 compatibility) or matching S120 List Manual for the firmware on site. STARTER ≥ V4.4 or Startdrive ≥ V15 for commissioning.
- SIMATIC side: STEP 7 V5.5 SP2 (or TIA Portal V13+ for S7-300/400 projects), S7-CPU with PROFIBUS DP master interface (e.g., CPU 315-2 DP, CPU 317-2 DP, CPU 319-3 PN/DP, or an S7-400 CPU with CP443-5).
- GSD file: Siemens GSD file "SIEM811F.gsd" (or the most recent SI0xxxxx.GSD) for the SINAMICS S120 drive. Available from the Siemens support entry 49216293.
- Hardware: PROFIBUS DP cable (purple, shielded), bus terminator on both ends, two connectors at the drive (CBC10/CBC11 communication board on the CU320).
3. Hardware Topology and Telegram Selection
The PROFIdrive profile defines standard telegrams that map STW1 / ZSW1, NSOLL / NIST, and additional process data into a fixed set of PZD words. The PLC and the drive must agree on the same telegram for consistent decoding.
| PROFIdrive Telegram | Direction (PLC → Drive) | Direction (Drive → PLC) | Typical Use |
|---|---|---|---|
| Telegram 1 | STW1, NSOLL | ZSW1, NIST, IAIST, MIST, WARN, FAULT | Speed control |
| Telegram 2 | STW1, NSOLL | ZSW1, NIST, IAIST, MIST, WARN, FAULT | Speed control (no encoder) |
| Telegram 3 | STW1, NSOLL | ZSW1, NIST, IAIST, MIST, WARN, FAULT | Speed control, 4 PZD each direction |
| Telegram 4 | STW1, NSOLL | ZSW1, NIST, IAIST, MIST, WARN, FAULT | Speed control, 6 PZD each direction |
| Telegram 7 | STW1, STW2, NSOLL | ZSW1, ZSW2, NIST | Basic positioning |
| Telegram 9 | STW1, STW2, NSOLL | ZSW1, ZSW2, NIST | Basic positioning (extended) |
| Telegram 110 | STW1, STW2, NSOLL, MIST | ZSW1, ZSW2, NIST, IAIST | Positioning with torque limit |
| Telegram 999 | Free (user-defined) | Free (user-defined) | Custom via P2051 / P2061 |
Telegram selection on the drive:
- Set
P0922 = 1for PROFIdrive Telegram 1, or the appropriate number for the chosen telegram. - Set
P2038 = 0for PROFIdrive profile (default).
Telegram selection on the PLC: In HW Config, after inserting the SINAMICS S120 from the GSD catalog, double-click the drive slot and assign the same telegram number on the "PROFIBUS message frame" drop-down. The I and Q addresses start at the configured base address (e.g., PE 256 / PA 256).
4. SINAMICS S120 PROFIBUS Parameter Layout
The S120 routes PROFIBUS PZD through BICO interconnections. The most frequently misconfigured pair is P2051 (length of received PZD) vs. r2050 / r2090 (source of sent PZD).
| Parameter | Direction | Purpose | Default for Telegram 1 |
|---|---|---|---|
| P2051[0..15] | PLC → Drive (input PZD word count) | CI: PZD received (BICO source for each word) | 4 entries: STW1 (r2090.0), NSOLL_B (r2090.1), free, free |
| P2061[0..15] | PLC → Drive (BICO sink) | BICO default mapping for received PZD | Defaults to control word / setpoint slots |
| r2050[0..15] | Drive → PLC (output PZD word count) | CO: PZD sent (status / actual values) | 4 entries: ZSW1, NIST_B, IAIST, MIST |
| r2090.0…r2094.15 | Drive internal | Bit-wise access to received PZD | Used by BICO to route individual bits of STW1 to lower-level drive functions |
| r2053[0..15] | Drive internal | Diagnostic: BICO source actually used | Read-only |
| r2054 | Drive internal | PROFIBUS diagnosis / fault buffer | Read-only |
Step-by-step drive commissioning (PROFIBUS portion):
- Run quick commissioning in STARTER to set motor data, encoder data, current / speed limits, and ramp-function generator timings (P1120, P1121).
- Open Communication → PROFIBUS and set
P0922to the desired telegram. - Open Configuration → Process data. Verify that
P2051entries match the telegram definition. For Telegram 1 you should see:
P2051[0] = r2090.0(STW1 source)
P2051[1] = r2090.1(NSOLL_B source) - Verify
r2050[0..3]values:ZSW1,NIST_B,IAIST,MISTfor Telegram 1. - Save and Copy RAM to ROM. Power-cycle to load.
5. Cyclic Communication with SFC14 (DPRD_DAT) and SFC15 (DPWR_DAT)
On the SIMATIC S7-300/400, SFC14 and SFC15 read and write the consistent PZD area of a DP slave in a single call. They bypass the I/O image so the transfer is not fragmented across OB1 scan boundaries.
| SFC | Function | Inputs | Outputs |
|---|---|---|---|
| SFC14 (DPRD_DAT) | Read consistent data from DP slave | LADDR (WORD), RET_VAL (INT) | RECORD (ANY-pointer to DB), RET_VAL |
| SFC15 (DPWR_DAT) | Write consistent data to DP slave | LADDR (WORD), RECORD (ANY-pointer), RET_VAL (INT) | RET_VAL, BUSY |
Typical data block layout for Telegram 1:
DATA_BLOCK DB100
STRUCT
STW1 : WORD; // offset 0 - Control Word 1 (output)
NSOLL : INT; // offset 2 - Speed setpoint (output)
unused1 : WORD; // offset 4
unused2 : WORD; // offset 6
ZSW1 : WORD; // offset 8 - Status Word 1 (input)
NIST : INT; // offset 10 - Speed actual (input)
IAIST : INT; // offset 12 - Current actual
MIST : INT; // offset 14 - Torque actual
END_STRUCT
END_DATA_BLOCK
SFC call in OB1 (cyclic exchange):
// --- Output direction: PLC → drive ---
CALL "DPWR_DAT" // SFC15
LADDR := W#16#100; // base address of output area (PE 256 in example)
RECORD := P#DB100.DBX 0.0 WORD 8; // 8 bytes = 4 words
RET_VAL := MW100;
// --- Input direction: drive → PLC ---
CALL "DPRD_DAT" // SFC14
LADDR := W#16#100; // same base address; SFC14 reads input area
RET_VAL := MW102;
RECORD := P#DB100.DBX 8.0 WORD 8; // store at offset 8
For Telegram 7 / 110 with 5–6 PZD words each direction, the RECORD length must equal 2 × number of PZD. For Telegram 999 (free) the length follows P2051 on the drive.
DBX 0.0, DBX 8.0, DBX 16.0 as offsets. Byte offsets other than multiples of 8 cause SFC15 to return error code 0x80B0 or 0x80B1.
6. Control Word 1 (STW1) Encoding
STW1 is the master enable word. The bits follow the PROFIdrive AC1 profile. For a speed-controlled drive, only six bits are typically toggled in normal operation.
| Bit | Meaning | State to Run |
|---|---|---|
| 0 | ON / OFF1 | 1 = drive energized |
| 1 | Coast stop (OFF2) | 1 = no coast; 0 = coast to 0 |
| 2 | Quick stop (OFF3) | 1 = no quick stop; 0 = ramp P1135 |
| 3 | Enable operation | 1 = enable pulses |
| 4 | Enable ramp generator | 1 = ramp output active |
| 5 | Unfreeze ramp generator | 1 = ramp proceeds |
| 6 | Enable speed setpoint | 1 = setpoint applied |
| 7 | Acknowledge fault | 0→1 edge clears faults |
| 8 | Jogging 1 | Optional |
| 9 | Jogging 2 | Optional |
| 10 | Control by PLC | 1 = PLC is active source |
| 11-15 | Reserved / vendor | Per drive profile |
Standard control words referenced in the source conversation:
// 0x047F = 0000 0100 0111 1111b
// bit0 = 1 ON
// bit1 = 1 OFF2 inactive
// bit2 = 1 OFF3 inactive
// bit3 = 1 Enable operation
// bit4 = 1 Enable ramp generator
// bit5 = 1 Unfreeze ramp generator
// bit6 = 1 Enable setpoint
// bit10 = 1 Control by PLC
STW_RUN := WORD#16#047F;
// 0x047E = same but bit0 = 0 → controlled OFF1 ramp to zero, then pulse inhibit
STW_OFF1 := WORD#16#047E;
The OFF2 command is 0x047D (bit 1 cleared). The OFF3 command is 0x047B (bit 2 cleared). Inhibit operation / coast is 0x047C (bit 0 cleared, bit 1 cleared, bit 2 cleared).
7. Status Word 1 (ZSW1) Decoding
ZSW1 mirrors the drive state. Read it from DB100.ZSW1 after SFC14 has executed.
| Bit | Meaning |
|---|---|
| 0 | Ready to switch on |
| 1 | Ready to operate (pulses off, link charged) |
| 2 | Operation enabled (pulses on) |
| 3 | Fault present |
| 4 | OFF2 inactive |
| 5 | OFF3 inactive |
| 6 | Switching on inhibited |
| 7 | Alarm present |
| 8 | Speed setpoint / actual deviation within tolerance |
| 9 | Control requested (PLC has control) |
| 10 | f or n reached |
| 11 | I, M, or P limit reached |
| 12-15 | Reserved / vendor |
For the controller to issue run commands, the PLC must first set P3981 = 1 on the drive (Control Unit priority from PROFIBUS) and the fieldbus option module must be in control priority mode (P3985). On the S120 this is typically done automatically when Telegram 1 (or higher) is active and the drive is in PROFIdrive profile mode.
8. Acyclic Parameter Access via DPV1 (SFC58 / SFC59)
Beyond the cyclic PZD, SINAMICS S120 exposes the full parameter set (~ 8000 parameters) over PROFIBUS DPV1 record 47 (read) / 48 (write). The SIMATIC S7 side uses SFC59 (RD_REC) to read and SFC58 (WR_REC) to write.
| SFC | Function | Key Parameters |
|---|---|---|
| SFC58 (WR_REC) | Write DPV1 record | REQ, IOID, LADDR, RECNUM, RECORD (ANY), RET_VAL, BUSY |
| SFC59 (RD_REC) | Read DPV1 record | REQ, IOID, LADDR, RECNUM, RET_VAL, BUSY, RECORD |
| SFC55 (WR_PARM) | Legacy write parameter | Older style, do not mix with DPV1 |
| SFC56 (RD_PARM) | Legacy read parameter | Older style |
| SFC57 (PARM_MOD) | Modify parameter (toggle) | Older style |
DPV1 request / response payload layout (PROFIdrive parameter channel, hex):
// Request header (4 words):
// Word 0: Reference = 0x01
// Word 1: Request ID (0x01 = read, 0x02 = write)
// Word 2: Parameter number (e.g. 0x1019 = P1019)
// Word 3: Parameter index (e.g. 0x0001 for index 1 of array parameter)
// Word 4+: parameter value(s) for write
Example: read parameter P21 (drive reference speed) via DPV1:
DATA_BLOCK DB200
STRUCT
req_header : ARRAY[0..3] OF WORD; // reference, ID, PNU, index
resp_value : WORD; // response word
END_STRUCT
END_DATA_BLOCK
CALL "RD_REC" // SFC59
REQ := TRUE;
IOID := B#16#54; // input ID
LADDR := W#16#100; // diagnostic address of drive
RECNUM := B#16#47; // record number 47 (DPV1 read)
RET_VAL := MW200;
BUSY := M201.0;
RECORD := P#DB200.DBX 0.0 WORD 8;
// After BUSY=0: DB200.resp_value holds the parameter content (Word 4 of response).
9. Using FB283 for Basic Positioning
FB283 (formerly part of the "SIMATIC S7 FB283" library, supplied with the SINAMICS S120 Function Block description) implements the SFC14 / SFC15 handshake and adds the positioning state machine defined by PROFIdrive Telegram 7 / 110. It is the Siemens-recommended block when the drive runs the EPOS basic positioner.
Inputs / outputs of FB283 (selected):
| Port | Direction | Description |
|---|---|---|
| AxisNo | IN | Drive axis number (1..N) |
| LADDR | IN | PROFIBUS base address (HW Config) |
| JOGPos / JOGNeg | IN | Jog commands |
| ModeSelect | IN | Operating mode (1 = pos, 2 = homing, 3 = jog, …) |
| TargetPos | IN | DINT absolute target position |
| Velocity | IN | REAL velocity (LU/min) |
| Execute | IN | Edge-triggered start of motion block |
| Done | OUT | Motion finished |
| Fault | OUT | Drive fault latched |
| ActPos | OUT | Actual position DINT |
| DiagId / ErrorNum | OUT | Internal FB283 diagnostic |
FB283 hides the manual toggling of STW1 / STW2 bits and the write of NSOLL. Internally it constructs the standard Telegram 7 word sequence (STW1, STW2, NSOLL, ModePos2, ModePos3) and decodes ZSW1 / ZSW2 / NIST / ActPos / ModePosStat back into BOOL/DINT outputs.
The full sample program ("SINAMICS S120 with S7-300/400 Basic Positioning") and FB283 documentation are published as Siemens support entry 25166781.
10. Verification and Diagnostics
-
Bus status: Check
SFandBFLEDs on the CPU.BFsolid red = PROFIBUS cable break or slave not in project; flashing red = intermittent. -
Drive LED: The CU320
RDYgreen +COMMgreen = cyclic traffic active. -
Drive parameter
r2054: Contains the cyclic telegram diagnostics.r2054[0]= number of configured PZD in,r2054[1]= number of configured PZD out. -
SFC return codes: If
RET_VAL ≠ 0after SFC14 / SFC15, decode per the table below.
| RET_VAL | Cause | Remedy |
|---|---|---|
| 0x0000 | No error | — |
| 0x80A0 | Negative acknowledgement from slave | Check r0947 on drive; check telegram number match |
| 0x80A1 | DP slave is offline | Check PROFIBUS address / cable / termination |
| 0x80A2 | Master system not configured | Re-run HW Config download |
| 0x80B0 | Length / type conflict at SFC14/15 | Confirm consistent access, ANY-pointer length matches telegram length |
| 0x80B1 | Length of RECORD too long | Reduce number of PZD or split into two calls |
| 0x80C0 | DPV1 protocol error (record number) | Verify RECNUM = 47 for read, 48 for write |
| 0x80C1 | DPV1 access: parameter does not exist | Check parameter number in List Manual |
| 0x80C2 | DPV1: parameter access denied (read-only) | Use correct access type or drive password (P3978) |
| 0x80C3 | DPV1: parameter access temporarily not possible | Wait for "operational" state, retry |
| 0x80C4 | DPV1: parameter value invalid | Check value range in List Manual |
Drive-side faults to watch for:
-
F08501 (PN/COMM fault) — telegram timeout, increase
P2047cycle time monitoring or check cable. - F08502 (sign-of-life) — telegram time-slot violation; reduce bus load or shorten OB1 cycle.
-
F08504 (PZD configuration) —
P0922telegram number mismatch between HW Config and STARTER. - A08511 (PZD configuration warning) — sent / received length inconsistent with telegram.
11. Common Pitfalls and Field-Proven Caveats
- Wrong GSD revision. Use the GSD that matches the S120 firmware family. Mixing SIEM811F (old) with CU320-2 V4.4+ leaves some BICO defaults invisible in STARTER.
- Inconsistent access not set. HW Config default is "Byte access". Without "Whole length consistent" the SFC14/15 data is corrupted every other OB1 cycle.
- Bit 10 of STW1 cleared. With bit 10 = 0 the drive ignores the PLC setpoint and does not accept run commands. Default STW1 = 0x0000, which leaves the drive in "switch-on inhibit" — exactly the symptom seen during first commissioning.
-
Wrong PROFIBUS address on the drive. Address is set via
P0918on the CU320 DIP switches or via the rotary switch on the CBC10 / CBC11 board. Confirm withSTARTER → Online → PROFIBUS diagnostics. - Checksum mismatch after telegram change. When switching from Telegram 1 to Telegram 7 the offsets of NSOLL and NIST change. Verify DB layout in STEP 7 and rerun HW Config download.
- Mixing legacy SFC55/56/57 with modern SFC58/59. SFC55/56 use slot 0; SFC58/59 use slot 0 too, but the request/response header differs. Pick one family per project.
-
CU240S DP question. If you later migrate to a G120 (CU240S DP), the parameter layout differs (
r2050,p0922,p1001quick commissioning). The PLC-side SFC14/15 code does not change, but you must re-map every parameter. -
Without FB283, manual toggling is fragile. Always sequence STW1 transitions: OFF (0x047E) → ON inhibited (0x0401) → wait for ZSW1 bit 0=1 → ON (0x0407) → enable (0x047F) — inserting
0x047Eonly between states.
12. Quick Commissioning Checklist
- [ ] Drive quick commissioning complete (motor data, encoder, ramp, limits).
- [ ]
P0922telegram selected. - [ ]
P2038 = 0PROFIdrive profile active. - [ ]
P2051[0..n-1]matches Telegram direction (STW1 at index 0, NSOLL at index 1). - [ ]
P3981 = 1Control Unit priority = PLC. - [ ] GSD installed in STEP 7; drive inserted in HW Config at correct PROFIBUS address.
- [ ] "Whole length consistent" set on I/O area.
- [ ] DB layout matches Telegram offsets (Word boundaries).
- [ ] SFC14 / SFC15 called every OB1 scan.
- [ ] STW1 = 0x047F in run; 0x047E for controlled OFF1; 0x047C for coast.
- [ ] ZSW1.bit2 = 1 indicates operation enabled.
- [ ] Fault F08501 / F08502 / F08504 not active in
r0947.
FAQ
Which SFCs are used for cyclic data exchange between S7-300/400 and SINAMICS S120 over PROFIBUS?
Use SFC15 (DPWR_DAT) to write consistent PZD data to the drive and SFC14 (DPRD_DAT) to read consistent PZD data from the drive. Both are called from OB1 with LADDR set to the configured PROFIBUS base address and RECORD pointing to a DB with the proper Telegram layout.
What control word value starts the drive (Telegram 1, speed control)?
STW1 = 0x047F enables the drive: bit 0 ON, bits 1–3 OFF2/OFF3/enable cleared, bit 4 ramp enable, bit 5 unfreeze, bit 6 enable setpoint, bit 10 control-by-PLC. For controlled OFF1 ramp stop use 0x047E; for coast stop (OFF2) use 0x047D; for quick stop (OFF3) use 0x047B.
Which drive parameters configure the PROFIBUS process data on SINAMICS S120?
The key parameters are P0922 (telegram selection), P2051 / P2061 (received PZD BICO mapping), r2050 (sent PZD BICO mapping), and P3981 (control priority). Defaults for Telegram 1 place STW1 in r2090.0, NSOLL_B in r2090.1, ZSW1 in r2050[0], NIST_B in r2050[1], IAIST in r2050[2], MIST in r2050[3].
How do I read a non-cyclic parameter (e.g., P21) from the S120 over PROFIBUS?
Use SFC59 (RD_REC) with LADDR = drive diagnostic address, RECNUM = B#16#47, and a RECORD ANY-pointer with the PROFIdrive parameter channel header (reference 0x01, request ID 0x01, parameter number, parameter index). The response word at offset 8 contains the parameter value. Use SFC58 (WR_REC) with RECNUM = B#16#48 to write parameters.
Can I use FB283 with a CU240S DP instead of CU320?
No — CU240S DP belongs to the SINAMICS G120 family and is not controlled by FB283 (which targets SINAMICS S120 positioning telegrams). For G120 you use either the SFC14/15 manual path with PROFIdrive Telegram 1, or the G120-specific FB block from the SINAMICS G120 library. The SFC14/15 PLC code itself works identically.
Why does SFC15 return 0x80B0 even though the drive is online?
0x80B0 indicates a length or access-type mismatch. Verify two things: (1) the I/O area in HW Config is set to "Whole length consistent"; (2) the RECORD ANY-pointer length in bytes equals 2 × number of PZD (e.g., 8 bytes for 4 PZD). Byte-aligned but not word-aligned offsets also trigger 0x80B0/B1.
Where can I download the SINAMICS S120 PROFIBUS GSD file and a sample project?
The GSD file "SIEM811F.gsd" (and newer revisions) is available from Siemens support entry 49216293. A complete S7 sample project with FB283 for basic positioning is published as entry 25166781. The functional description "Speed Control of a SINAMICS S120 with SIMATIC S7-300/400F" is attached to entry 68624711.