Configuring TI505 CP1434 to S7-300 Communication via IE/PB Link

David Krause17 min read
Industrial NetworkingSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Definition and Operational Constraints

The integration target is data exchange between a legacy SIMATIC TI505 PLC (CPU TI545-1102, fitted with a CP1434 H1 communications module) and a Siemens S7-300 station (CPU 317-2DP) that is already running in production. A Siemens IE/PB Link (catalog number 6GK1 411-5AA0) has been installed as the bridge between Industrial Ethernet and the PROFIBUS DP subnet. The operational constraint that drives every decision in this article is hard-frozen by the field engineer: the S7-300 CPU cannot be stopped, restarted, or have its hardware reconfigured because the plant is live. This single rule disqualifies any architecture that requires adding a new PROFIBUS master, swapping the CPU, or rebuilding the STEP 7 hardware configuration online in a way that would force a STOP-to-RUN transition of the S7-300.

Two facts must be reconciled before any hardware is ordered or any cable is run:

  1. The CP1434 H1 speaks ISO-on-TCP (RFC 1006), ISO Transport, and TCP/IP natively. It does not speak PROFIBUS DP.
  2. The CPU 317-2DP has a built-in PROFIBUS DP master interface. It can also host a CP 343-1 Lean / CP 343-1 / CP 343-1 IT / CP 343-1 PN on the backplane and use ISO-on-TCP (RFC 1006) connections from STEP 7.

Those two facts are the hinge of the entire design. From them, three viable architectures emerge, plus one that looks viable but is not. Each is dissected below with part numbers, configuration steps, byte/word budgets, and the operational risk attached to it.

Constraint reminder: Any architecture that requires a STOP of the S7-300 to bind a new PROFIBUS master, an additional CP, or to change HW Config in a way that triggers a re-download must be rejected outright.

2. Protocol and Hardware Inventory

Before selecting an architecture, lock down the actual catalog numbers, firmware classes, and protocol stacks present in the system. The following table is the baseline reference and should be reconciled with the physical hardware on site.

Item Catalog / Order Number Protocol Stack(s) Role
TI505 CPU TI545-1102 505 serial / CTI Workbench Legacy controller, runs user logic
TI505 Ethernet CP CP1434 H1 ISO Transport, ISO-on-TCP (RFC 1006), TCP/IP, UDP Ethernet attachment on the 505 backplane
S7-300 CPU CPU 317-2DP (6ES7 317-2AJ10-0AB0 or later) MPI, PROFIBUS DP master Existing controller, cannot be stopped
IE/PB Link 6GK1 411-5AA0 (IE/PB Link PN IO) PROFINET IO device ↔ PROFIBUS DP master/slave Installed bridge hardware
Ethernet side of IE/PB Link PROFINET IO device, S7 communication optional PROFINET, optional S7 routing
PROFIBUS side of IE/PB Link DP master or DP slave (configurable) PROFIBUS DP-V0/V1

The CP1434 H1 occupies one slot in the TI505 chassis and exposes an AUI/10BASE-T/100BASE-TX Ethernet interface. Its configuration is performed using the SIMATIC TI505 Workbench (or, for older units, COM PROFIBUS / NCM S7 for TI505) where the transport connections are bound to port numbers and ISO TSAPs. The CP1434 H1 firmware understands passive ISO Transport partners, FETCH/WRITEs initiated from the S7 side, and SEND/RECEIVE jobs initiated from the 505 side.

The CPU 317-2DP firmware class must be checked in the online diagnostics of STEP 7 (PLC → Module Information → Firmware). Any firmware of V2.x or higher supports the CP 343-1 family in the backplane and S7 communication over ISO-on-TCP. The CPU 317-2DP itself does not support ISO-on-TCP on its integrated DP interface; an additional CP in the backplane is required if ISO Transport is chosen.

If you intend to use ISO-on-TCP between CP1434 H1 and an S7 CP 343-1, verify that an unused slot exists in the S7-300 rack and that the STEP 7 hardware configuration already declares that slot (or can be downloaded without stopping the CPU). If neither slot is free nor declared, fall back to the PROFIBUS-based options.

3. Architecture Path A — Native ISO Transport, Bypass the IE/PB Link

This is the architecturally cleanest path. The CP1434 H1 and a Siemens CP 343-1 / CP 343-1 IT / CP 343-1 PN already share the same wire-level protocol: ISO-on-TCP (RFC 1006). The IE/PB Link becomes irrelevant for the actual data path and can be removed from the topology or left in place as a passive node.

Topology:

  • TI545-1102 + CP1434 H1 (Ethernet port) → Industrial Ethernet switch → CP 343-1 (or CP 343-1 IT / CP 343-1 PN) on the S7-300 backplane.
  • Data flows over a single ISO-on-TCP connection configured with PUT/GET on the S7 side and a matching transport connection on the 505 side.

Data budget: a CP 343-1 Lean supports PUT/GET up to 76 bytes per call. A CP 343-1 (full) supports up to 212 bytes per PUT or GET job. The CP 343-1 IT and CP 343-1 PN raise the limit to 212 bytes per call as well but allow multiple simultaneous jobs (up to 16 active connections on the IT variant).

This path is the only one that does not require PROFIBUS at all. If the S7-300 already has a CP 343-1 mounted (or one can be added without stopping the CPU, see Section 8), this is the recommended solution.

4. Architecture Path B — CTI 2577 PROFIBUS DP Slave Adapter

Control Technology Inc. (CTI) manufactures the 2577 PROFIBUS DP Slave Adapter for the TI505 series. The 2577 occupies one slot in the TI505 chassis alongside the CPU and the CP1434 H1, and it presents a standard PROFIBUS DP slave interface to the network. From the S7-300's perspective, the 2577 looks like any other DP slave with a GSD file.

Data budget:

  • Up to 110 words (220 bytes) input from the 505 to the S7-300.
  • Up to 110 words (220 bytes) output from the S7-300 to the 505.
  • Total cyclic I/O is configured in the S7 HW Config by selecting the appropriate slots in the slave's GSD.

Topology:

  • TI545-1102 + CP1434 H1 + CTI 2577 → PROFIBUS DP segment → CPU 317-2DP (integrated DP master interface).
  • The IE/PB Link can be removed from the PROFIBUS path entirely. Its only function in Path B would be as a passive DP slave or as a router, neither of which is needed.

This path keeps the S7-300 CPU untouched and uses its already-declared DP master interface. If the 2577 is added to the existing HW Config of the S7-300, the CPU may need to be briefly stopped for the new GSD to be installed in HW Config, depending on whether STEP 7 allows the change online. Check this with the plant operator before committing to Path B.

5. Architecture Path C — DP/DP Coupler

The Siemens DP/DP Coupler (6GK1 572-1AA00 or the current 6GK1 572-1AM00) is a gateway between two physically separate PROFIBUS DP networks. Each side of the coupler is a DP slave, and the coupler copies I/O data from one side to the other with a configurable offset.

Data budget:

  • Up to 244 bytes per direction, per scan (the practical maximum given the coupler's internal buffer).
  • Total of 16 input slots and 16 output slots per side, each slot configurable from 1 byte up to 16 bytes.

Topology for this case:

  • Side A: TI505 with CTI 2577 on PROFIBUS segment A.
  • Side B: S7-300 CPU 317-2DP on PROFIBUS segment B.
  • The DP/DP Coupler sits on both segments and shuttles data between them.

The DP/DP coupler is only useful when the TI505 is on a separate PROFIBUS segment from the S7-300, which is unusual if both are in the same cabinet. In the source application, the S7-300 already owns the PROFIBUS master, so a DP/DP coupler adds cost without value over Path B. Path C is included here only for completeness in case the TI505 must remain electrically isolated from the S7-300's segment.

6. Architecture Path D — IE/PB Link as PROFINET/DP Gateway (and Why It Does Not Solve This Problem)

The 6GK1 411-5AA0 is an IE/PB Link PN IO. Its design purpose is to attach a PROFIBUS DP master (such as the CPU 317-2DP) to a PROFINET IO controller, or to attach a PROFINET IO controller to PROFIBUS DP slaves. It is fundamentally a PROFINET/PROFIBUS bridge.

The original question asked whether the IE/PB Link could be used to forward data from the CP1434 H1 across to the S7-300. The IE/PB Link does not speak ISO-on-TCP as an end station for S7 connections. Its PROFINET side is configured as a PROFINET IO device with a fixed slot model; it cannot be addressed as a peer ISO Transport partner by the CP1434 H1.

Therefore, the IE/PB Link, in isolation, cannot translate between the CP1434 H1's ISO protocol and the S7-300's PROFIBUS DP master. The unit can still be retained in the cabinet if it is required for other nodes (for example, to attach ET 200S stations to a PROFINET controller elsewhere in the plant), but it is not the path that connects the TI505 to the S7-300.

7. Architecture Comparison Matrix

Criterion Path A: ISO-on-TCP Path B: CTI 2577 Path C: DP/DP Coupler Path D: IE/PB Link
Required new HW on TI505 side None CTI 2577 + PROFIBUS connector CTI 2577 + PROFIBUS connector None
Required new HW on S7-300 side CP 343-1 (free slot) None if DP master port free None None
S7-300 CPU stop required Only if CP slot must be added online Only if HW Config must be rebuilt for new GSD Only if HW Config must be rebuilt No
Max data per scan (cyclic) 212 B/job (CP 343-1 full) 110 W in / 110 W out 244 B/direction PROFINET slot model only
IE/PB Link still used? No No No Yes (but does not solve CP1434 problem)
Engineering tool — TI505 side Workbench / NCM S7 for TI505 Workbench + CTI 2577 config tool Workbench + CTI 2577 config tool —
Engineering tool — S7-300 side STEP 7 V5.x or TIA Portal STEP 7 V5.x or TIA Portal (GSD import) STEP 7 V5.x or TIA Portal STEP 7 / TIA Portal

Recommendation priority: Path A → Path B → Path C → Path D. Path D is documented only because the installed hardware prompts the question.

8. Configuration Procedure — Path A (ISO-on-TCP) in Detail

Path A is the leanest solution when the S7-300 already has (or can host without stopping) a CP 343-1. The following steps assume STEP 7 V5.5 or TIA Portal V15 or later on the engineering station.

8.1 Prerequisites

  • Free slot in the S7-300 rack OR an already-installed CP 343-1 (Lean, full, IT, or PN).
  • CP1434 H1 firmware that supports ISO Transport. Confirm via HW Config → CP1434 H1 → Module Information in the 505 Workbench.
  • Industrial Ethernet switch reachable by both stations, with both stations in the same IP subnet (e.g. 192.168.10.x/24).
  • Firewall/VLAN rules opened for TCP port 102 (ISO Transport) between the two nodes.

8.2 Configure CP1434 H1 Transport Connection

  1. Open the TI505 Workbench and select the CP1434 H1 in the rack view.
  2. Create a new Transport Connection of type ISO Transport (also called ISO-on-TCP or RFC 1006 in the Siemens nomenclature).
  3. Bind it to a free TSAP on the local side, for example TSAP-L = 10.00 (the convention for Siemens is two-byte TSAP: first byte = device, second byte = slot/connection).
  4. Set the remote TSAP to the one declared by the CP 343-1, for example TSAP-R = 10.02.
  5. Set the remote IP address to the CP 343-1's Ethernet IP, for example 192.168.10.20.
  6. Define the data areas: input word file (V-memory words to be sent) and output word file (V-memory words to be received). Each area can be up to 64 words in the CP1434 H1's classical firmware.

8.3 Configure CP 343-1 PUT/GET Connection

  1. In STEP 7 HW Config, place a CP 343-1 (full or IT) in an available slot. If the slot is already declared in the existing project, simply add the connection configuration.
  2. Open NetPro (STEP 7 V5.x) or Devices & Networks → Connections (TIA Portal).
  3. Insert a new S7 connection with type S7 connection (PUT/GET-capable). The local endpoint is the CP 343-1, the partner is the CP1434 H1 (enter its IP address).
  4. Activate the PUT/GET checkbox on the connection properties. Without this, only operator communication is permitted.
  5. Download the connection configuration to the S7-300. If the CP was already in HW Config, the download runs as a delta and does not require a CPU STOP. If the CP was just added to a previously unused slot, a STOP is required.

8.4 Ladder Logic on the S7-300 Side

The PUT/GET blocks are FB15 (PUT) and FB14 (GET) in the standard STEP 7 library. Example call structure (illustrative STL excerpt):

CALL  "PUT" , %DB15
     REQ    := TRUE              // Trigger on rising edge
     ID     := W#16#1            // Connection ID from NetPro
     ADDR_1 := P#DB20.DBX0.0 BYTE 32   // Send: 32 bytes from DB20
     ADDR_2 := P#DB21.DBX0.0 BYTE 32   // Send: 32 bytes from DB21
     SD_1   := P#DB30.DBX0.0 BYTE 32   // Local source area
     SD_2   := P#DB31.DBX0.0 BYTE 32   // Local source area
     LEN    := 64                // Total 64 bytes
     DONE   := M50.0
     ERROR  := M50.1
     STATUS := MW52

Mirror the call with FB14 (GET) to receive the 505's data. Each scan must trigger the blocks with a rising-edge bit to avoid duplicate transmissions.

8.5 Verification (Path A)

  • Open Online → Accessible Nodes in STEP 7 and confirm the CP 343-1 can ping the CP1434 H1 (or use the diagnostics page to view the ISO connection state).
  • Force a known value into the 505's outgoing word file and verify it appears in the S7-300's destination DB.
  • Write a known value from the S7-300 into the source DB and verify it appears in the 505's incoming word file.
  • Check FB15/FB14 STATUS word for return codes: 0000 = DONE, 8x7F = job active, 8x0A = partner not reachable.

9. Configuration Procedure — Path B (CTI 2577) in Detail

9.1 Prerequisites

  • CTI 2577 installed in the TI505 chassis, with PROFIBUS cable routed to the S7-300's DP port.
  • CTI 2577 GSD file (e.g. CTI2577.GSD) imported into STEP 7 or TIA Portal.
  • The S7-300's DP master port must have enough bus address space and must be configured with a free slot for the new slave.
  • Termination enabled at both ends of the PROFIBUS segment; shield grounded at the cabinet entry.

9.2 Configure CTI 2577 DIP Switches / Workbench

  1. Set the PROFIBUS node address on the 2577 with the rotary switches (default 3 is conventional; avoid 0, 1, 2, 126 which are reserved for masters or diagnostics).
  2. Using CTI's 2577 configuration tool (or the equivalent dialog in the TI505 Workbench), define the I/O word count and the mapping into the TI505 V-memory area.
  3. Save and activate the configuration; the 2577 will power up as a DP-V0 slave.

9.3 Configure S7-300 as DP Master for the 2577

  1. In HW Config (STEP 7 V5.x) or Devices & Networks (TIA Portal), open the CPU 317-2DP's DP interface properties.
  2. Add a new PROFIBUS slave from the catalog (after GSD import) and assign it the node address set on the 2577.
  3. Drag the desired I/O modules into the slave's slot table. The 2577 typically supports modules from 1 word up to 110 words in each direction, packaged as Universal modules in the GSD.
  4. Download HW Config. If the CPU 317-2DP is in RUN, STEP 7 will attempt a delta download. If a STOP is required by the system, you cannot use this path without scheduling a plant outage.

9.4 Ladder Logic on the S7-300 Side

The 2577's input and output areas appear as I/O addresses directly under the slave's configured slots, e.g. IW 256 through IW 365 for 110 input words. Wrap them into DBs with simple BTI/ITB byte-swap blocks if integer word order matters. No PUT/GET blocks are required — data is exchanged cyclically by the DP master.

9.5 Verification (Path B)

  • Inspect the slave's diagnostic buffer in STEP 7: PLC → Module Information → Diagnostic Buffer on the slave icon. Expected: no diagnostic interrupts, slave in data exchange.
  • LED indicators on the 2577: green BF off, green SF off indicates healthy cyclic exchange.
  • Force a value into the 2577's input area from the 505 (via CTI Workbench) and observe the corresponding IW/DB on the S7-300.
  • Watch the PROFIBUS bus monitor (BT200, Softing PROFIBUS Inspector, or similar) for error-free telegrams on the slave's address.

10. Configuration Procedure — Path C (DP/DP Coupler) in Detail

  1. Mount the DP/DP Coupler on a DIN rail close to both PROFIBUS segments.
  2. Connect segment A (TI505 + CTI 2577) to one DB9 port and segment B (CPU 317-2DP) to the other.
  3. Set the PROFIBUS address on each side of the coupler (rotary switches, range 1–125).
  4. Configure the slot table on each side using the DIP switch / configuration tool; mirror the byte layout from one side to the other.
  5. Import the DP/DP coupler GSD into both STEP 7 projects (TI505 side uses CTI's master-side GSD; S7-300 side uses Siemens' coupler GSD).
  6. Download both HW Configs. The S7-300 side requires the same online-change considerations as Path B.

Data verification is identical to Path B — cyclic I/O appears at fixed input/output addresses on each side.

11. Diagnostics and Field Troubleshooting Matrix

Symptom Likely Cause Path Corrective Action
STATUS = 8x0A on FB15/FB14 Partner unreachable A Verify IP and TSAP settings; check switch VLAN/firewall on TCP/102
STATUS = 8x03 PUT/GET not permitted on connection A Re-check PUT/GET flag in NetPro connection properties
2577 BF LED steady on No PROFIBUS baud rate negotiation B Match baud rate; check termination; verify slave address not duplicated
2577 SF LED blinking Configuration mismatch B Reconcile slot table in HW Config with 2577 actual config
DP/DP coupler DIA LED red One side offline C Power-cycle coupler; verify both masters running
CPU 317-2DP SF after HW Config download New GSD requires STOP B/C Schedule outage OR revert to Path A which avoids HW Config change
CP1434 H1 not visible from STEP 7 Routing/PG function disabled A Enable PG/OP routing or use a separate Ethernet engineering interface
Field-proven caveat: On CPU 317-2DP with early firmware (V2.0), attempting a delta HW Config download that adds a new DP slave may still force a STOP. Verify the firmware version with PLC → Module Information → Firmware. Firmware V3.3 and later on the 6ES7 317-2AJ10 generally accept the addition without a STOP, but this is not guaranteed. Always validate on a test bench before committing to Path B or C on a live plant.

12. References to Official Documentation

Can the IE/PB Link alone translate between the CP1434 H1 (ISO) and the S7-300?

No. The IE/PB Link (6GK1 411-5AA0) is a PROFINET IO device / PROFIBUS DP master-or-slave bridge. It does not terminate ISO-on-TCP transport connections on its PROFINET port and therefore cannot act as an ISO Transport partner for the CP1434 H1. Use a CP 343-1 on the S7-300 side (Path A) or a CTI 2577 on the TI505 side (Path B).

What is the largest payload I can move between the TI505 and the S7-300?

With a CP 343-1 full/IT/PN on the S7-300, PUT/GET jobs of up to 212 bytes per call are supported. With a CTI 2577, up to 110 words (220 bytes) input and 110 words output are available per DP cycle. With a DP/DP coupler, the practical limit is 244 bytes per direction, per scan.

Do I have to stop the S7-300 CPU to add the CTI 2577 to its HW Config?

It depends on the CPU 317-2DP firmware revision. Firmware V3.3 and later generally accept online addition of a new DP slave without a STOP. Earlier firmware, or a slot rearrangement that changes the CPU's own configuration, can force a STOP. Always confirm on a test bench before booking Path B against a live plant.

Which Siemens CP on the S7-300 supports ISO-on-TCP with the CP1434 H1?

CP 343-1 Lean (limited), CP 343-1 (full), CP 343-1 IT, and CP 343-1 PN. The Lean variant restricts PUT/GET to 76 bytes per job; the full, IT, and PN variants allow 212 bytes. The integrated DP interface on the CPU 317-2DP does not support ISO-on-TCP directly.

Is the IE/PB Link useful if I keep the CP1434 H1 path?

Yes, but only for other PROFIBUS or PROFINET traffic in the plant. It plays no role in carrying data between the CP1434 H1 and the S7-300 once Path A is selected. Leave it powered and configured for its existing downstream slaves; do not rely on it for the TI505 ↔ S7-300 data path.

Back to blog