Overview
WinCC Industrial Data Bridge (IDB) is a Siemens option for WinCC V7.x and TIA Portal environments that enables bidirectional data exchange between SIMATIC controllers (S7-1200, S7-1500, S7-300/400) and external systems such as SQL databases, OPC servers, Office files, and TCP/IP peer devices. The Send/Receive provider in IDB is a TCP-based adapter that lets the IDB Runtime act as a passive partner to the S7-1200's open user communication blocks (TCON, TDISCON, TSEND, TRCV). This configuration pattern is the standard Siemens-recommended path for writing S7-1200 DB values into MySQL without writing custom OPC/DA logic.
This reference documents the configuration of WinCC IDB V7.3 (also applicable to V7.4/V7.5 with minor dialog differences) for the canonical case: S7-1200 DB tag → S7-1200 TSEND → IDB Send/Receive provider → IDB MySQL consumer → MySQL table. The approach uses only the IDB Configuration Studio wizard; no scripting is required for steady-state operation. For product background, refer to the official Siemens WinCC Industrial Data Bridge PDF which describes the data-connection model, licensing tiers, and runtime architecture.
For the official Siemens KB entry on this exact exchange, see "How do you exchange data between the SIMATIC WinCC Industrial Data Bridge (IDB) and a SIMATIC S7 Controller?" and the V7.4 reference manual at SIMATIC HMI WinCC V7.4 WinCC/IndustrialDataBridge. Office-file writing (a related, but distinct case) is documented at Writing data from SIMATIC WinCC or controllers in MS Office files.
Architecture and Data Flow
The communication path consists of three logical nodes:
-
S7-1200 PLC – Holds the source data in a global DB. Uses
TCONto establish a TCP connection to the IDB Runtime, thenTSENDto push the DB area on a positive edge ofREQ. The IDB Runtime listens on a configurable TCP port (default 5000 or operator-defined). - IDB Configuration Studio + IDB Runtime (Windows service) – The Configuration Studio (CS) is used offline to define the Send/Receive Provider (the TCP listener side) and one or more Consumers (MySQL, SQL Server, OPC, Excel, file). At runtime, the IDB Runtime service consumes the binary frame from the PLC, parses it according to the configured data layout, and writes the extracted values into the configured destination.
- MySQL Server – Receives the data via a standard ODBC connection (MySQL ODBC 8.0 Unicode driver or MySQL Connector/ODBC 5.x) defined in the IDB consumer.
Frame direction is unidirectional in the most common configuration: the PLC is the TCP active partner and pushes a defined byte payload; the IDB is the passive partner that receives, parses, and writes. Bidirectional exchange is possible by adding a Send/Receive consumer in IDB plus a TRCV block on the S7-1200 side, but this requires an additional TCON held in passive mode on the PLC and is outside the default V7.3 wizard templates.
Prerequisites
| Component | Required Version / Setting | Notes |
|---|---|---|
| WinCC | V7.3, V7.4, or V7.5 (this article focuses on V7.3) | IDB is a licensed option, activated via the WinCC License Manager |
| Industrial Data Bridge option license | Per RT-server tag count (e.g., 100/500/3000) | Tag count is sum of all tags across all provider/consumer connections |
| IndustrialDataBridge Configuration Studio | Installed as part of the IDB option setup | Can be installed stand-alone on a non-WinCC node |
| IndustrialDataBridge Runtime service | Matches the configuration studio version | Runs as a Windows service: "Siemens IndustrialDataBridge" |
| S7-1200 firmware | V4.0 or higher recommended (V4.2+ for optimized block access) | Firmware V4.0 introduced TSEND/TRCV enhancements; V4.4 added ISO-on-TCP keep-alive tuning |
| TIA Portal | V13 SP1 or higher (for V4.0+ PLC firmware) | Required to program the open user communication blocks |
| MySQL Server | 5.7, 8.0, or higher | Network reachable from the IDB Runtime host; port 3306 (or custom) open in firewall |
| MySQL ODBC driver | MySQL ODBC 8.0 Unicode Driver (recommended) or Connector/ODBC 5.3.4+ | Install 32-bit (ANSI or Unicode) if IDB Runtime is 32-bit; 64-bit Unicode for 64-bit IDB. Check via the IDB Runtime application properties. |
| Network | Ethernet between PLC ↔ IDB host; IDB host ↔ MySQL server | Disable Windows Firewall rules blocking the IDB listener port |
| User rights | Local Administrator on the IDB host for service install; MySQL user with INSERT/UPDATE on target table | IDB Runtime service account must have write access to its working directory |
MySQL Schema Preparation
Before configuring IDB, create the destination table in MySQL. The IDB consumer can either Insert (append) or Insert/Update rows. A typical logging table for sensor data:
CREATE DATABASE IF NOT EXISTS plant_data
CHARACTER SET utf8mb4
COLLATE utf8mb4_unicode_ci;
USE plant_data;
CREATE TABLE sensor_log (
id BIGINT NOT NULL AUTO_INCREMENT,
log_ts DATETIME(3) NOT NULL DEFAULT CURRENT_TIMESTAMP(3),
tag01 INT NULL,
tag02 FLOAT NULL,
tag03 DOUBLE NULL,
tag04 TINYINT NULL,
tag05 SMALLINT NULL,
quality TINYINT NULL,
PRIMARY KEY (id),
KEY idx_log_ts (log_ts)
) ENGINE=InnoDB;
CREATE USER 'idb_writer'@'%' IDENTIFIED BY 'StrongP@ssw0rd';
GRANT INSERT, SELECT ON plant_data.sensor_log TO 'idb_writer'@'%';
FLUSH PRIVILEGES;
Use a dedicated user with the minimum privileges required (INSERT and SELECT for log-only mode; UPDATE if you also use Insert/Update mode). Use a non-privileged account; do not use root.
PLC-Side Configuration (S7-1200 Open User Communication)
The S7-1200 side uses three blocks from the Communication → Open User Communication library in TIA Portal:
-
TCON– Establishes the TCP connection; called once at startup (or on reconnect) and held active. -
TDISCON– Tears down the connection; used on shutdown or for a controlled reconnect. -
TSEND– Sends a byte stream on a positive edge ofREQ.
All three blocks share a single connection description in a global DB of type TCON_IP_V4. Place one instance DB per connection. The instance DBs of TCON, TSEND, and TRCV all reference the same CONNECT parameter of type TCON_IP_V4.
Connection Parameters (TCON_IP_V4)
| Parameter | Value (Example) | Description |
|---|---|---|
| InterfaceId | 64#0A 0A 0B 04 01 00 00 00 (S7-1200 PROFINET port 1, IE_1) | HW identifier of the PROFINET interface from the device configuration; right-click port → Properties → System constants |
| ID | 1 (decimal) – must match the ID used in TSEND / TRCV
|
Local connection identifier, range 1..4095 |
| ConnectionType | 16#0B (TCP/IP, B#16#0B) | Use 16#0B for standard TCP. ISO-on-TCP (16#12) is not what the IDB Send/Receive provider uses |
| ActiveEstablished | TRUE | PLC is the active connection partner (initiates connect) |
| RemoteAddress | IP of IDB Runtime host, e.g. 192.168.0.50 | ADDR array of 4 bytes; IDB host IP |
| RemotePort | 5000 (or operator-defined IDB listener port) | Must match IDB Send/Receive provider port |
| LocalPort | 0 (auto-assign by firmware) | Set to 0 to let the CPU pick an ephemeral port |
SCL Example: TCON/TSEND Pattern
// Global data block "CommCfg"
DATA_BLOCK "CommCfg"
{ S7_Optimized_Access := 'FALSE' }
STRUCT
tcon_cfg : TCON_IP_V4; // populated in the watch table or by code below
payload : ARRAY[0..12] OF BYTE; // flat byte image of the data to send
payloadLen : UINT; // = 13 for the example below
END_STRUCT;
END_DATA_BLOCK
// OB1 / OB35
IF "FirstRun" THEN
"CommCfg".tcon_cfg.InterfaceId := 16#0A0A0B04_01000000;
"CommCfg".tcon_cfg.ID := 1;
"CommCfg".tcon_cfg.ConnectionType := 16#0B;
"CommCfg".tcon_cfg.ActiveEstablished := TRUE;
"CommCfg".tcon_cfg.RemoteAddress[1] := 192;
"CommCfg".tcon_cfg.RemoteAddress[2] := 168;
"CommCfg".tcon_cfg.RemoteAddress[3] := 0;
"CommCfg".tcon_cfg.RemoteAddress[4] := 50;
"CommCfg".tcon_cfg.RemotePort := 5000;
"CommCfg".tcon_cfg.LocalPort := 0;
"FirstRun" := FALSE;
END_IF;
// TCON: hold in startup, edge-triggered
IF NOT "tcDB".Established THEN
"tcDB"(REQ := "TCON_Trigger",
ID := 1,
CONNECT:= "CommCfg".tcon_cfg,
DONE => "TCON_Done",
BUSY => "TCON_Busy",
ERROR => "TCON_Error",
STATUS => "TCON_Status");
END_IF;
// TSEND on positive edge of "SendTrigger"
IF "SendTrigger" AND "tcDB".Established THEN
"tsDB"(REQ := "SendTrigger" AND NOT "tsDB".BUSY,
ID := 1,
LEN := "CommCfg".payloadLen,
DATA := "CommCfg".payload,
DONE => "TSEND_Done",
BUSY => "TSEND_Busy",
ERROR => "TSEND_Error",
STATUS=> "TSEND_Status");
"SendTrigger" := FALSE;
END_IF;
TSEND Trigger Logic
Key points on TSEND:
-
REQmust be a positive edge (one-shot). DrivingREQconstantly TRUE will flood the TCP buffer and is the leading cause ofSTATUS = 16#8085("Resource temporarily unavailable") returns. -
LENis the exact byte count of the payload. The IDB provider's field map must define the same total bytes. -
DATAis a slice of the source DB (e.g.,"MyData".Sensors) containing all fields to be mapped, packed contiguously in the order IDB will parse. - Check
DONEfor completion andERROR/STATUS. Common STATUS codes:-
16#7000– idle -
16#7001– first call active -
16#7002– follow-on call active -
16#8000– connection aborted by peer -
16#8085– resource temporarily unavailable (back-pressure on TCP send) -
16#8600–LEN/DATAlength mismatch
-
Data Layout and Byte Order
The S7-1200 stores data in little-endian format. IDB parses the byte stream as it arrives; the field list in the provider defines the byte offset and length for each item. For example, if the DB contains:
DATA_BLOCK "SourceDB"
{ S7_Optimized_Access := 'FALSE' } // non-optimized for direct byte access
STRUCT
Tag01 : INT; // 2 bytes
Tag02 : REAL; // 4 bytes
Tag03 : DINT; // 4 bytes
Tag04 : BOOL; // 1 byte (S7 pads BOOLs to 1 byte)
Tag05 : WORD; // 2 bytes
END_STRUCT;
END_DATA_BLOCK
Total payload is 13 bytes. The first byte IDB sees is the LSB of Tag01. Any DB restructuring after TCON is online requires a stop/start of the connection and an IDB Runtime reload.
"SourceDB".Tag01 works fine in TSEND, but you cannot rely on AT-via-offset views over an optimized block. Disable optimization for the data DB if you want guaranteed positional layout, or use the symbolic slice in the TSEND DATA parameter – the compiler will marshal the slice contiguously.IDB Configuration Studio – Project and Connection Setup
Open the IDB Configuration Studio (Start → Siemens Automation → IndustrialDataBridge → Configuration Studio). The left pane shows the project tree: Connections → Provider / Consumer → Field Lists.
Step 1: Create the Send/Receive Provider
- Right-click Provider → New Provider → Send/Receive.
- Name it (e.g.,
S71200_SendReceive). The name becomes the symbol in the runtime XML. - Open the provider's properties; the key parameters are:
-
Port: TCP port the IDB Runtime will listen on. Default 5000. Must match the PLC's
RemotePort. - Connection mode: Server (passive) is the correct selection for the S7-1200 active-initiator case. Selecting Client will cause IDB to attempt outbound connect and fail.
- Idle timeout: Set to 0 (disabled) or a value larger than the PLC's max send interval. If the PLC goes silent longer than the timeout, the provider will drop the connection and require a PLC re-TCON.
- Keep-alive: Enable to detect half-open sockets.
-
Frame delimiter / length: For raw TCP, set a fixed length matching the TSEND
LEN. If you use the wizard's "S7-1200 compatible" template, the wizard pre-fills the field list offsets from the DB definition you import.
-
Port: TCP port the IDB Runtime will listen on. Default 5000. Must match the PLC's
Step 2: Define the MySQL Consumer
- Right-click Consumer → New Consumer → Database (ODBC).
- Configure the ODBC data source first via Windows ODBC Data Source Administrator (32-bit or 64-bit to match IDB Runtime):
- DSN name (e.g.,
MySQL_IDB) - Server: MySQL host IP
- User / Password with INSERT/UPDATE on target schema
- Database: target schema
- Port: 3306 (or custom)
- DSN name (e.g.,
- In the IDB consumer properties, link the ODBC DSN. Set Write mode:
- Insert: every field list execution creates a new row. Use for time-series logging.
- Update: requires a defined key column to update an existing row.
- Insert/Update: hybrid; IDB attempts update first, falls back to insert.
Step 3: Connection Mapping
The Connection Mapping tab ties a Provider to one or more Consumers and defines the trigger / cycle. Open the provider, add a new mapping line:
- Source (Provider field list): to be defined next.
- Target (Consumer field list): to be defined next.
- Trigger: Cyclic with an interval (e.g., 1000 ms) is the safest for time-series; On change requires the provider to detect field changes and is unreliable on raw binary streams.
- Cycle time: 100–1000 ms typical. Below 50 ms is rarely productive due to MySQL write latency.
Defining the Send/Receive Provider Field List
This is the panel that the original problem identified as confusing: "First Byte, Requested Data Type". The field list maps byte offsets in the incoming TCP stream to named fields with a target data type.
Field List Parameters
| IDB Parameter | Meaning | Example |
|---|---|---|
| Field name | Symbolic name used downstream in the consumer mapping | Tag01 |
| First byte (offset) | 0-based byte offset into the TCP payload | 0 for the first INT, 2 for the next REAL, etc. |
| Requested data type | Target type after parsing | INT (2B), REAL (4B), DINT (4B), BOOL (1B), BYTE (1B), WORD (2B), DWORD (4B), STRING (nB) |
| Length (bytes) | Byte length; required for STRING | 2 for INT, 4 for REAL, n for STRING |
| Byte order (endianness) | Little-endian (S7 default) is implicit; for swapped, use big-endian or swap-words option | Leave at default for S7-1200 |
For the example DB, the field list rows are:
| Field name | First byte | Requested data type | Length (bytes) |
|---|---|---|---|
| Tag01 | 0 | INT | 2 |
| Tag02 | 2 | REAL | 4 |
| Tag03 | 6 | DINT | 4 |
| Tag04 | 10 | BOOL | 1 |
| Tag05 | 11 | WORD | 2 |
The sum of the field lengths (13) must equal the TSEND LEN. Common mistakes:
- Off-by-one on offsets (IDB is 0-based, not 1-based).
- BOOL sizing: S7 stores a BOOL in 1 byte (X bit + padding). Do not use length 0 or 1 bit.
- STRING with no length field: IDB expects a 2-byte header (max length) + 2-byte actual length + n bytes of characters. If you have a custom S7 STRING layout, define the byte layout explicitly in the field list.
Consumer Field List (MySQL Columns)
In the database consumer, define one row per target column:
- Field name: must exactly match a name from the provider field list (this is the link).
- Column: target MySQL column name.
- Data type: MySQL target type (INT, FLOAT, DOUBLE, DATETIME, VARCHAR).
IDB will coerce the provider value into the target column type. Numeric overflow is silently truncated unless the IDB log level is set to DEBUG.
Generating the Runtime XML and Activating
- In Configuration Studio, select File → Generate Runtime File. The output is an XML file (e.g.,
idb_project.xml) that the IDB Runtime loads. - Copy the XML to the IDB Runtime working directory (default:
C:\ProgramData\Siemens\Automation\IndustrialDataBridge\Runtime). - Open the IDB Runtime Manager (a separate utility, not the Configuration Studio). It shows the loaded project, the providers, and the consumers with their init state.
- Click Activate. The status indicator should transition: Provider: Initialized → Connected (when the PLC opens TCON) and Consumer: Initialized → Running.
- Click Start to begin the data flow.
Verifying Data in MySQL
- From any MySQL client, run
SELECT * FROM sensor_log ORDER BY id DESC LIMIT 10;to confirm rows are landing. - In the IDB Runtime Manager, observe the per-field "Last value" column – it must update at the configured cycle rate.
- Check the IDB log directory (
%ProgramData%\Siemens\Automation\IndustrialDataBridge\Log) for ERROR or WARNING entries. Set the log level to Info during commissioning; reduce to Warning in production. - Use a packet capture (Wireshark on port 5000) to confirm the PLC is sending the expected byte count. The IDB Runtime does not echo the payload by default.
Troubleshooting Matrix
| Symptom | Likely Cause | Action |
|---|---|---|
| Provider stays "Not Initialized" | XML file not loaded or has syntax error | Regenerate XML; check IDB Runtime log for parser errors |
| Provider "Initialized" but never "Connected" | PLC never opens TCON; firewall blocking port; port mismatch | Verify TCON.DONE in PLC; telnet from PLC subnet to IDB host:port; check Windows Firewall |
| Provider "Connected", Consumer "Running", no rows in MySQL | Field mapping mismatch, MySQL permissions, ODBC driver mismatch | Check consumer "Last value"; verify MySQL user has INSERT; confirm 32/64-bit ODBC matches IDB Runtime |
| Consumer shows "ODBC Error" | DSN missing, wrong driver, network unreachable | Test DSN via Windows ODBC admin; verify MySQL port reachable; check driver version |
| PLC TSEND returns STATUS 16#8600 | LEN inconsistent with DATA size | Cross-check LEN and sizeof("PayloadDB") in SCL |
| PLC TSEND returns STATUS 16#8085 | REQ held continuously TRUE; CPU sending faster than TCP can buffer | Convert REQ to a one-shot; add 50–100 ms gap between sends |
| Data values wrong / swapped | Byte order mismatch between DB layout and field list offsets | Reconcile offset list; consider endianness flag for big-endian consumers |
| First transfer works, then stops | Idle timeout closing the socket | Increase provider idle timeout or send periodic heartbeat from PLC |
| Connection drops during MySQL restart | Provider not configured to wait for consumer recovery | Enable Store-and-Forward on the consumer; IDB will spool to a local file |
| MySQL columns contain NULL on some rows | IDB encountered a parse error on a specific field; silent zero-fill in some templates | Set IDB log level to DEBUG; review per-field decode errors |
Performance and Sizing Notes
Throughput of the IDB Send/Receive pipeline is bounded by the slowest link – typically MySQL write latency. A single S7-1200 sending 100 bytes per cycle at 100 ms cycle time (10 frames/s, 1000 bytes/s) is trivial for MySQL. Bumping the cycle to 50 ms across 50 fields is also fine. Where IDB struggles:
- Cycles below 20 ms with non-batched insert – MySQL InnoDB commit overhead dominates.
- Payloads above 8 KB – IDB's internal buffer is sized for typical PLC frames; oversize frames can fragment.
- Multiple consumers per provider – IDB writes synchronously in the configured order; one slow consumer slows the chain.
For high-rate logging (>= 100 rows/s), consider:
- Use the Database Bulk consumer variant if available in your IDB version.
- Batch multiple TSEND frames into one IDB frame using a length-prefixed multi-tag array.
- Disable MySQL
innodb_flush_log_at_trx_commit(set to 2) on the MySQL side; you trade durability for throughput. - Add a covering index on the timestamp column only if your downstream queries filter on it.
Security Considerations
The Send/Receive provider in IDB V7.3 uses raw TCP without encryption. For production deployments on plant networks:
- Place the IDB host and the PLC on an isolated VLAN or behind an industrial firewall.
- Restrict the listener port to the PLC subnet only via Windows Firewall rules.
- Use a dedicated MySQL user with INSERT-only grants on the target schema; never use
root. - Disable anonymous ODBC tracing in production (it writes to a file in the user's profile).
- If TLS is required, move to the OPC UA provider (S7-1500 only) or the OPC UA server interface on the IDB side, which supports certificate-based auth.
Migration Notes (V7.3 → V7.4 / V7.5)
- The Configuration Studio UI in V7.4 re-arranged the Send/Receive provider wizard into multiple sub-tabs; the underlying XML structure is backward compatible.
- V7.5 added a 64-bit native IDB Runtime; existing 32-bit projects load unchanged but must be regenerated.
- Licenses purchased for V7.3 are upgrade-eligible to V7.4/V7.5 under the standard Siemens license trade-in terms.
- The MySQL ODBC driver recommendation is unchanged (8.0 Unicode).
Best Practices and Field-Proven Notes
- Keep the IDB host on a fixed IP and reserve it in DHCP; the PLC's
RemoteAddressis a static IP. - Log size: enable rolling logs (default 5 MB × 5 files) to avoid filling the disk.
- For audit / traceability, include a timestamp column in MySQL defined with
DEFAULT CURRENT_TIMESTAMPso you do not have to map a PLC clock to MySQL. - If you need guaranteed delivery (i.e., no row loss on a MySQL outage), enable IDB's Store-and-Forward on the consumer: IDB will spool to a local file and replay when MySQL returns.
- The IDB Send/Receive provider does not support multiple simultaneous PLC connections on the same port. For multiple S7-1200 devices, either use multiple providers on different ports or use a Send/Receive consumer on a single shared provider with field-list multiplexing (only feasible with fixed-size frames and known PLC IDs in the payload).
- On TIA Portal side, the
TCONinstance DB stores connection state; do not overwrite it from user logic. - Wrap
TCONin a watchdog: ifTCON.DONEis FALSE for > 5 s andTCON.BUSYis FALSE, callTDISCONand re-triggerTCONafter a 2 s backoff. This recovers from half-open sockets caused by switch reboots.
Verification Checklist
- ☐ PLC
TCON.DONE= TRUE within 5 s of startup. - ☐ IDB Runtime Manager shows Provider = Connected.
- ☐ IDB Runtime Manager shows Consumer = Running and field "Last value" updates at the cycle rate.
- ☐
SELECT COUNT(*) FROM sensor_logincreases over time. - ☐ No ERROR entries in the IDB log for 10 minutes of operation.
- ☐ Cycle time in IDB matches expected DB write volume (i.e., a 1 s cycle yields ≈60 rows/min).
- ☐ Simulated network drop: PLC reconnects within 10 s; IDB provider re-enters Connected state automatically.
- ☐ MySQL restart: IDB consumer logs error, recovers on next successful insert, and Store-and-Forward (if enabled) replays any spooled rows.
FAQ
What TCP port does the WinCC IDB Send/Receive provider use by default?
The default is port 5000, but it is freely configurable in the provider properties. The S7-1200's TCON.RemotePort must use the same value, and the Windows Firewall on the IDB host must allow inbound TCP on that port.
Do I need to install WinCC Runtime to use the Industrial Data Bridge?
No. The IDB Configuration Studio and IDB Runtime can be installed as standalone components on a Windows node without a full WinCC installation. A license for the IDB option is still required and is checked at runtime.
Why does the provider show "Connected" but no data appears in MySQL?
The most common cause is a mismatch between the TSEND LEN on the PLC and the sum of the field lengths in the IDB provider field list. Verify that every byte offset is correct (IDB uses 0-based offsets) and that the MySQL user has INSERT privilege on the target table.
Can the S7-1200 also receive data from MySQL via IDB?
Yes, but it requires a Send/Receive consumer in IDB plus an TRCV block on the S7-1200 side. The PLC must hold an additional TCON open in passive mode (PLC as server) for IDB to push to. This is a less common pattern and is not part of the default V7.3 wizard templates.
Which MySQL ODBC driver version is supported?
MySQL Connector/ODBC 8.0 (Unicode or ANSI) is the current recommendation and is compatible with MySQL Server 5.7 and 8.0. The 5.3.4 driver is also supported for legacy MySQL 5.6/5.7 servers. Match the driver bitness (32 or 64 bit) to the IDB Runtime executable.
What STATUS codes on TSEND indicate a real fault vs. a transient?
16#7000–16#7002 are normal in-progress codes. 16#8000 means the peer closed the socket (check IDB provider logs). 16#8085 is back-pressure (slow down REQ). 16#8600 is a length mismatch and must be fixed in code. Any other 16#8xxx is a hard fault that should halt the send until cleared.