1. Problem Definition and Operational Constraints
The integration target is data exchange between a legacy SIMATIC TI505 PLC (CPU TI545-1102, fitted with a CP1434 H1 communications module) and a Siemens S7-300 station (CPU 317-2DP) that is already running in production. A Siemens IE/PB Link (catalog number 6GK1 411-5AA0) has been installed as the bridge between Industrial Ethernet and the PROFIBUS DP subnet. The operational constraint that drives every decision in this article is hard-frozen by the field engineer: the S7-300 CPU cannot be stopped, restarted, or have its hardware reconfigured because the plant is live. This single rule disqualifies any architecture that requires adding a new PROFIBUS master, swapping the CPU, or rebuilding the STEP 7 hardware configuration online in a way that would force a STOP-to-RUN transition of the S7-300.
Two facts must be reconciled before any hardware is ordered or any cable is run:
- The CP1434 H1 speaks ISO-on-TCP (RFC 1006), ISO Transport, and TCP/IP natively. It does not speak PROFIBUS DP.
- The CPU 317-2DP has a built-in PROFIBUS DP master interface. It can also host a CP 343-1 Lean / CP 343-1 / CP 343-1 IT / CP 343-1 PN on the backplane and use ISO-on-TCP (RFC 1006) connections from STEP 7.
Those two facts are the hinge of the entire design. From them, three viable architectures emerge, plus one that looks viable but is not. Each is dissected below with part numbers, configuration steps, byte/word budgets, and the operational risk attached to it.
2. Protocol and Hardware Inventory
Before selecting an architecture, lock down the actual catalog numbers, firmware classes, and protocol stacks present in the system. The following table is the baseline reference and should be reconciled with the physical hardware on site.
| Item | Catalog / Order Number | Protocol Stack(s) | Role |
|---|---|---|---|
| TI505 CPU | TI545-1102 | 505 serial / CTI Workbench | Legacy controller, runs user logic |
| TI505 Ethernet CP | CP1434 H1 | ISO Transport, ISO-on-TCP (RFC 1006), TCP/IP, UDP | Ethernet attachment on the 505 backplane |
| S7-300 CPU | CPU 317-2DP (6ES7 317-2AJ10-0AB0 or later) | MPI, PROFIBUS DP master | Existing controller, cannot be stopped |
| IE/PB Link | 6GK1 411-5AA0 (IE/PB Link PN IO) | PROFINET IO device ↔ PROFIBUS DP master/slave | Installed bridge hardware |
| Ethernet side of IE/PB Link | PROFINET IO device, S7 communication optional | PROFINET, optional S7 routing | |
| PROFIBUS side of IE/PB Link | DP master or DP slave (configurable) | PROFIBUS DP-V0/V1 |
The CP1434 H1 occupies one slot in the TI505 chassis and exposes an AUI/10BASE-T/100BASE-TX Ethernet interface. Its configuration is performed using the SIMATIC TI505 Workbench (or, for older units, COM PROFIBUS / NCM S7 for TI505) where the transport connections are bound to port numbers and ISO TSAPs. The CP1434 H1 firmware understands passive ISO Transport partners, FETCH/WRITEs initiated from the S7 side, and SEND/RECEIVE jobs initiated from the 505 side.
The CPU 317-2DP firmware class must be checked in the online diagnostics of STEP 7 (PLC → Module Information → Firmware). Any firmware of V2.x or higher supports the CP 343-1 family in the backplane and S7 communication over ISO-on-TCP. The CPU 317-2DP itself does not support ISO-on-TCP on its integrated DP interface; an additional CP in the backplane is required if ISO Transport is chosen.
3. Architecture Path A — Native ISO Transport, Bypass the IE/PB Link
This is the architecturally cleanest path. The CP1434 H1 and a Siemens CP 343-1 / CP 343-1 IT / CP 343-1 PN already share the same wire-level protocol: ISO-on-TCP (RFC 1006). The IE/PB Link becomes irrelevant for the actual data path and can be removed from the topology or left in place as a passive node.
Topology:
- TI545-1102 + CP1434 H1 (Ethernet port) → Industrial Ethernet switch → CP 343-1 (or CP 343-1 IT / CP 343-1 PN) on the S7-300 backplane.
- Data flows over a single ISO-on-TCP connection configured with PUT/GET on the S7 side and a matching transport connection on the 505 side.
Data budget: a CP 343-1 Lean supports PUT/GET up to 76 bytes per call. A CP 343-1 (full) supports up to 212 bytes per PUT or GET job. The CP 343-1 IT and CP 343-1 PN raise the limit to 212 bytes per call as well but allow multiple simultaneous jobs (up to 16 active connections on the IT variant).
This path is the only one that does not require PROFIBUS at all. If the S7-300 already has a CP 343-1 mounted (or one can be added without stopping the CPU, see Section 8), this is the recommended solution.
4. Architecture Path B — CTI 2577 PROFIBUS DP Slave Adapter
Control Technology Inc. (CTI) manufactures the 2577 PROFIBUS DP Slave Adapter for the TI505 series. The 2577 occupies one slot in the TI505 chassis alongside the CPU and the CP1434 H1, and it presents a standard PROFIBUS DP slave interface to the network. From the S7-300's perspective, the 2577 looks like any other DP slave with a GSD file.
Data budget:
- Up to 110 words (220 bytes) input from the 505 to the S7-300.
- Up to 110 words (220 bytes) output from the S7-300 to the 505.
- Total cyclic I/O is configured in the S7 HW Config by selecting the appropriate slots in the slave's GSD.
Topology:
- TI545-1102 + CP1434 H1 + CTI 2577 → PROFIBUS DP segment → CPU 317-2DP (integrated DP master interface).
- The IE/PB Link can be removed from the PROFIBUS path entirely. Its only function in Path B would be as a passive DP slave or as a router, neither of which is needed.
This path keeps the S7-300 CPU untouched and uses its already-declared DP master interface. If the 2577 is added to the existing HW Config of the S7-300, the CPU may need to be briefly stopped for the new GSD to be installed in HW Config, depending on whether STEP 7 allows the change online. Check this with the plant operator before committing to Path B.
5. Architecture Path C — DP/DP Coupler
The Siemens DP/DP Coupler (6GK1 572-1AA00 or the current 6GK1 572-1AM00) is a gateway between two physically separate PROFIBUS DP networks. Each side of the coupler is a DP slave, and the coupler copies I/O data from one side to the other with a configurable offset.
Data budget:
- Up to 244 bytes per direction, per scan (the practical maximum given the coupler's internal buffer).
- Total of 16 input slots and 16 output slots per side, each slot configurable from 1 byte up to 16 bytes.
Topology for this case:
- Side A: TI505 with CTI 2577 on PROFIBUS segment A.
- Side B: S7-300 CPU 317-2DP on PROFIBUS segment B.
- The DP/DP Coupler sits on both segments and shuttles data between them.
The DP/DP coupler is only useful when the TI505 is on a separate PROFIBUS segment from the S7-300, which is unusual if both are in the same cabinet. In the source application, the S7-300 already owns the PROFIBUS master, so a DP/DP coupler adds cost without value over Path B. Path C is included here only for completeness in case the TI505 must remain electrically isolated from the S7-300's segment.
6. Architecture Path D — IE/PB Link as PROFINET/DP Gateway (and Why It Does Not Solve This Problem)
The 6GK1 411-5AA0 is an IE/PB Link PN IO. Its design purpose is to attach a PROFIBUS DP master (such as the CPU 317-2DP) to a PROFINET IO controller, or to attach a PROFINET IO controller to PROFIBUS DP slaves. It is fundamentally a PROFINET/PROFIBUS bridge.
The original question asked whether the IE/PB Link could be used to forward data from the CP1434 H1 across to the S7-300. The IE/PB Link does not speak ISO-on-TCP as an end station for S7 connections. Its PROFINET side is configured as a PROFINET IO device with a fixed slot model; it cannot be addressed as a peer ISO Transport partner by the CP1434 H1.
Therefore, the IE/PB Link, in isolation, cannot translate between the CP1434 H1's ISO protocol and the S7-300's PROFIBUS DP master. The unit can still be retained in the cabinet if it is required for other nodes (for example, to attach ET 200S stations to a PROFINET controller elsewhere in the plant), but it is not the path that connects the TI505 to the S7-300.
7. Architecture Comparison Matrix
| Criterion | Path A: ISO-on-TCP | Path B: CTI 2577 | Path C: DP/DP Coupler | Path D: IE/PB Link |
|---|---|---|---|---|
| Required new HW on TI505 side | None | CTI 2577 + PROFIBUS connector | CTI 2577 + PROFIBUS connector | None |
| Required new HW on S7-300 side | CP 343-1 (free slot) | None if DP master port free | None | None |
| S7-300 CPU stop required | Only if CP slot must be added online | Only if HW Config must be rebuilt for new GSD | Only if HW Config must be rebuilt | No |
| Max data per scan (cyclic) | 212 B/job (CP 343-1 full) | 110 W in / 110 W out | 244 B/direction | PROFINET slot model only |
| IE/PB Link still used? | No | No | No | Yes (but does not solve CP1434 problem) |
| Engineering tool — TI505 side | Workbench / NCM S7 for TI505 | Workbench + CTI 2577 config tool | Workbench + CTI 2577 config tool | — |
| Engineering tool — S7-300 side | STEP 7 V5.x or TIA Portal | STEP 7 V5.x or TIA Portal (GSD import) | STEP 7 V5.x or TIA Portal | STEP 7 / TIA Portal |
Recommendation priority: Path A → Path B → Path C → Path D. Path D is documented only because the installed hardware prompts the question.
8. Configuration Procedure — Path A (ISO-on-TCP) in Detail
Path A is the leanest solution when the S7-300 already has (or can host without stopping) a CP 343-1. The following steps assume STEP 7 V5.5 or TIA Portal V15 or later on the engineering station.
8.1 Prerequisites
- Free slot in the S7-300 rack OR an already-installed CP 343-1 (Lean, full, IT, or PN).
- CP1434 H1 firmware that supports ISO Transport. Confirm via
HW Config → CP1434 H1 → Module Informationin the 505 Workbench. - Industrial Ethernet switch reachable by both stations, with both stations in the same IP subnet (e.g. 192.168.10.x/24).
- Firewall/VLAN rules opened for TCP port 102 (ISO Transport) between the two nodes.
8.2 Configure CP1434 H1 Transport Connection
- Open the TI505 Workbench and select the CP1434 H1 in the rack view.
- Create a new Transport Connection of type ISO Transport (also called ISO-on-TCP or RFC 1006 in the Siemens nomenclature).
- Bind it to a free TSAP on the local side, for example
TSAP-L = 10.00(the convention for Siemens is two-byte TSAP: first byte = device, second byte = slot/connection). - Set the remote TSAP to the one declared by the CP 343-1, for example
TSAP-R = 10.02. - Set the remote IP address to the CP 343-1's Ethernet IP, for example
192.168.10.20. - Define the data areas: input word file (V-memory words to be sent) and output word file (V-memory words to be received). Each area can be up to 64 words in the CP1434 H1's classical firmware.
8.3 Configure CP 343-1 PUT/GET Connection
- In STEP 7 HW Config, place a CP 343-1 (full or IT) in an available slot. If the slot is already declared in the existing project, simply add the connection configuration.
- Open NetPro (STEP 7 V5.x) or Devices & Networks → Connections (TIA Portal).
- Insert a new S7 connection with type S7 connection (PUT/GET-capable). The local endpoint is the CP 343-1, the partner is the CP1434 H1 (enter its IP address).
- Activate the PUT/GET checkbox on the connection properties. Without this, only operator communication is permitted.
- Download the connection configuration to the S7-300. If the CP was already in HW Config, the download runs as a delta and does not require a CPU STOP. If the CP was just added to a previously unused slot, a STOP is required.
8.4 Ladder Logic on the S7-300 Side
The PUT/GET blocks are FB15 (PUT) and FB14 (GET) in the standard STEP 7 library. Example call structure (illustrative STL excerpt):
CALL "PUT" , %DB15
REQ := TRUE // Trigger on rising edge
ID := W#16#1 // Connection ID from NetPro
ADDR_1 := P#DB20.DBX0.0 BYTE 32 // Send: 32 bytes from DB20
ADDR_2 := P#DB21.DBX0.0 BYTE 32 // Send: 32 bytes from DB21
SD_1 := P#DB30.DBX0.0 BYTE 32 // Local source area
SD_2 := P#DB31.DBX0.0 BYTE 32 // Local source area
LEN := 64 // Total 64 bytes
DONE := M50.0
ERROR := M50.1
STATUS := MW52
Mirror the call with FB14 (GET) to receive the 505's data. Each scan must trigger the blocks with a rising-edge bit to avoid duplicate transmissions.
8.5 Verification (Path A)
- Open Online → Accessible Nodes in STEP 7 and confirm the CP 343-1 can ping the CP1434 H1 (or use the diagnostics page to view the ISO connection state).
- Force a known value into the 505's outgoing word file and verify it appears in the S7-300's destination DB.
- Write a known value from the S7-300 into the source DB and verify it appears in the 505's incoming word file.
- Check FB15/FB14
STATUSword for return codes:0000= DONE,8x7F= job active,8x0A= partner not reachable.
9. Configuration Procedure — Path B (CTI 2577) in Detail
9.1 Prerequisites
- CTI 2577 installed in the TI505 chassis, with PROFIBUS cable routed to the S7-300's DP port.
- CTI 2577 GSD file (e.g.
CTI2577.GSD) imported into STEP 7 or TIA Portal. - The S7-300's DP master port must have enough bus address space and must be configured with a free slot for the new slave.
- Termination enabled at both ends of the PROFIBUS segment; shield grounded at the cabinet entry.
9.2 Configure CTI 2577 DIP Switches / Workbench
- Set the PROFIBUS node address on the 2577 with the rotary switches (default 3 is conventional; avoid 0, 1, 2, 126 which are reserved for masters or diagnostics).
- Using CTI's 2577 configuration tool (or the equivalent dialog in the TI505 Workbench), define the I/O word count and the mapping into the TI505 V-memory area.
- Save and activate the configuration; the 2577 will power up as a DP-V0 slave.
9.3 Configure S7-300 as DP Master for the 2577
- In HW Config (STEP 7 V5.x) or Devices & Networks (TIA Portal), open the CPU 317-2DP's DP interface properties.
- Add a new PROFIBUS slave from the catalog (after GSD import) and assign it the node address set on the 2577.
- Drag the desired I/O modules into the slave's slot table. The 2577 typically supports modules from 1 word up to 110 words in each direction, packaged as Universal modules in the GSD.
- Download HW Config. If the CPU 317-2DP is in RUN, STEP 7 will attempt a delta download. If a STOP is required by the system, you cannot use this path without scheduling a plant outage.
9.4 Ladder Logic on the S7-300 Side
The 2577's input and output areas appear as I/O addresses directly under the slave's configured slots, e.g. IW 256 through IW 365 for 110 input words. Wrap them into DBs with simple BTI/ITB byte-swap blocks if integer word order matters. No PUT/GET blocks are required — data is exchanged cyclically by the DP master.
9.5 Verification (Path B)
- Inspect the slave's diagnostic buffer in STEP 7: PLC → Module Information → Diagnostic Buffer on the slave icon. Expected: no diagnostic interrupts, slave in data exchange.
- LED indicators on the 2577: green BF off, green SF off indicates healthy cyclic exchange.
- Force a value into the 2577's input area from the 505 (via CTI Workbench) and observe the corresponding IW/DB on the S7-300.
- Watch the PROFIBUS bus monitor (BT200, Softing PROFIBUS Inspector, or similar) for error-free telegrams on the slave's address.
10. Configuration Procedure — Path C (DP/DP Coupler) in Detail
- Mount the DP/DP Coupler on a DIN rail close to both PROFIBUS segments.
- Connect segment A (TI505 + CTI 2577) to one DB9 port and segment B (CPU 317-2DP) to the other.
- Set the PROFIBUS address on each side of the coupler (rotary switches, range 1–125).
- Configure the slot table on each side using the DIP switch / configuration tool; mirror the byte layout from one side to the other.
- Import the DP/DP coupler GSD into both STEP 7 projects (TI505 side uses CTI's master-side GSD; S7-300 side uses Siemens' coupler GSD).
- Download both HW Configs. The S7-300 side requires the same online-change considerations as Path B.
Data verification is identical to Path B — cyclic I/O appears at fixed input/output addresses on each side.
11. Diagnostics and Field Troubleshooting Matrix
| Symptom | Likely Cause | Path | Corrective Action |
|---|---|---|---|
| STATUS = 8x0A on FB15/FB14 | Partner unreachable | A | Verify IP and TSAP settings; check switch VLAN/firewall on TCP/102 |
| STATUS = 8x03 | PUT/GET not permitted on connection | A | Re-check PUT/GET flag in NetPro connection properties |
| 2577 BF LED steady on | No PROFIBUS baud rate negotiation | B | Match baud rate; check termination; verify slave address not duplicated |
| 2577 SF LED blinking | Configuration mismatch | B | Reconcile slot table in HW Config with 2577 actual config |
| DP/DP coupler DIA LED red | One side offline | C | Power-cycle coupler; verify both masters running |
| CPU 317-2DP SF after HW Config download | New GSD requires STOP | B/C | Schedule outage OR revert to Path A which avoids HW Config change |
| CP1434 H1 not visible from STEP 7 | Routing/PG function disabled | A | Enable PG/OP routing or use a separate Ethernet engineering interface |
12. References to Official Documentation
- Siemens S7-300/S7-400 ISO Ethernet Communication Guide — protocol, ISO-on-TCP transport, and CP 343-1 connection setup.
- TIA Portal: Point-to-Point Link S7-300/S7-400/S7-1500 — connection topology rules and IE/PB Link usage notes.
- Siemens Support Entry 24708615: Hardware Components for S7-300/S7-400 Communication Modules — catalog numbers and approved interfaces for PROFIBUS DP master, PROFINET IO, and IE/PB Link integration.
- Siemens manual CP 343-1 / CP 343-1 PN — PUT/GET limits and connection budget per firmware release.
- CTI 2577 PROFIBUS DP Slave Adapter User Manual — slot counts, GSD revision, DIP switch definitions.
Can the IE/PB Link alone translate between the CP1434 H1 (ISO) and the S7-300?
No. The IE/PB Link (6GK1 411-5AA0) is a PROFINET IO device / PROFIBUS DP master-or-slave bridge. It does not terminate ISO-on-TCP transport connections on its PROFINET port and therefore cannot act as an ISO Transport partner for the CP1434 H1. Use a CP 343-1 on the S7-300 side (Path A) or a CTI 2577 on the TI505 side (Path B).
What is the largest payload I can move between the TI505 and the S7-300?
With a CP 343-1 full/IT/PN on the S7-300, PUT/GET jobs of up to 212 bytes per call are supported. With a CTI 2577, up to 110 words (220 bytes) input and 110 words output are available per DP cycle. With a DP/DP coupler, the practical limit is 244 bytes per direction, per scan.
Do I have to stop the S7-300 CPU to add the CTI 2577 to its HW Config?
It depends on the CPU 317-2DP firmware revision. Firmware V3.3 and later generally accept online addition of a new DP slave without a STOP. Earlier firmware, or a slot rearrangement that changes the CPU's own configuration, can force a STOP. Always confirm on a test bench before booking Path B against a live plant.
Which Siemens CP on the S7-300 supports ISO-on-TCP with the CP1434 H1?
CP 343-1 Lean (limited), CP 343-1 (full), CP 343-1 IT, and CP 343-1 PN. The Lean variant restricts PUT/GET to 76 bytes per job; the full, IT, and PN variants allow 212 bytes. The integrated DP interface on the CPU 317-2DP does not support ISO-on-TCP directly.
Is the IE/PB Link useful if I keep the CP1434 H1 path?
Yes, but only for other PROFIBUS or PROFINET traffic in the plant. It plays no role in carrying data between the CP1434 H1 and the S7-300 once Path A is selected. Leave it powered and configured for its existing downstream slaves; do not rely on it for the TI505 ↔ S7-300 data path.