Connecting an HMI Operator Panel to ET 200S CPU 6ES7151-7AA20-0AB

David Krause14 min read
HMI / SCADASiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Connecting an HMI Operator Panel to the ET 200S CPU 6ES7151-7AA20-0AB0

This reference documents how to select, wire, configure, and commission a Siemens SIMATIC operator panel (HMI) against the ET 200S CPU module with order number 6ES7 151-7AA20-0AB0. The same workflow applies to variants of the IM151-7 (6ES7151-7AA21-0AB0, 6ES7151-7AB00-0AB0, 6ES7151-7AB01-0AB0) and to the IM151-8 PN/DP (6ES7151-8AB00-0AB0) when its PROFIBUS interface is used. The objective is threefold: (1) read and acknowledge process faults, (2) monitor the online status of digital and analog inputs/outputs, and (3) display the live value of a position encoder connected to the ET 200S I/O.

Identification note: The order number 6ES7 151-7AA20-0AB0 is an ET 200S IM151-7 CPU, not a classic S7-300 CPU. The IM151-7 implements a CPU 314-class instruction set and is programmed with STEP 7 V5.x or TIA Portal. It exposes a single 9-pin D-sub MPI/PROFIBUS DP interface; a second PROFINET port is only present on the IM151-8 PN/DP variants (6ES7151-8AB0x-0AB0). All HMI communication must traverse the MPI/DP port unless an external PROFINET/PROFIBUS coupler is added.

1. CPU Interface and Communication Capabilities

The integrated X1 interface of the 6ES7151-7AA20-0AB0 supports the following modes, selectable in HW Config:

  • MPI – default after factory reset; up to 32 nodes, default baud rate 187.5 kbit/s, max 12 Mbit/s on the 6ES7151-7AA20-0AB0 with firmware V3.x.
  • PROFIBUS DP master – up to 125 slaves; 9.6 kbit/s to 12 Mbit/s.
  • PROFIBUS DP slave – to a higher-level DP master (typical for PCS 7 AS stations).

Default MPI address out of the box is 2. HMI panels and the programming PG/PC must occupy addresses on the same bus segment; the CPU reserves addresses 0 (PG), 1 (PG/OP reserved), and 2 (CPU) by Siemens convention. Free usable addresses for HMI: 3 through 31 (and higher when bus repeaters are added).

The CPU operator panel referenced in TIA Portal online & diagnostic tools is a software view of the online CPU's mode, error state, and value-forcing status. It is not a physical HMI. The HMI selection and wiring discussed below are independent of that software feature.

2. Communication Protocol Decision Matrix

Criterion MPI PROFIBUS DP
Maximum number of HMI stations per segment 32 (CPU + 31 nodes) 32 per segment, 125 with repeaters
Baud rate supported by 6ES7151-7AA20-0AB0 19.2 kbit/s – 187.5 kbit/s (firmware ≤ V2.x); up to 12 Mbit/s on V3.x 9.6 kbit/s – 12 Mbit/s
Available HMI catalog All SIMATIC Panels with MPI option: OP7, OP17, OP27, OP37, TP27, TP170A/B, TP177A/B, KTP, MP177, MP277, MP377, Comfort panels Same panels with PROFIBUS option; the "DP" suffix is required on Comfort and Mobile panels
Configuration tool ProTool, ProTool/Pro, WinCC Flexible 2004/2008, TIA Portal (WinCC) WinCC Flexible 2004/2008, TIA Portal (WinCC Comfort/Advanced/Professional)
Typical use Single panel, retrofit, no other DP slaves Multiple panels, mixed with drives/remote I/O, high-speed data
Diagnostics depth Standard S7 diagnostic, no slave diagnostics Full DP slave diagnostics, station failure alarms, diagnostic interrupts routed to OB82

Recommendation: for a single operator panel that reads faults, I/O state, and a position encoder, MPI at 187.5 kbit/s is sufficient and avoids the need for GSD files or DP master configuration. Switch to PROFIBUS DP only if a second HMI, an ET 200 remote station, or a drive is also on the bus.

3. Compatible Operator Panel Catalog

Selection must satisfy three constraints simultaneously: (a) MPI or PROFIBUS physical interface on the panel, (b) WinCC Flexible / TIA Portal configuration project must be available for that panel, and (c) the panel must not be in the "Product Cancellation" phase if long-term spare-part availability matters.

Panel (MLFB example) Display Interface Config tool Lifecycle status
OP7 (6AV3607-1JC20-0AX1) 4 × 20 text LCD MPI (RS-485) ProTool / ProTool Lite Product Cancellation (announcement 2008); spares only
OP17 (6AV3617-1JC20-0AX1) 4 × 20 text LCD MPI ProTool / WinCC Flexible 2004 Product Cancellation
TP177A 6" mono (6AV6642-0BA01-1AX1) 5.7" STN 320 × 240 MPI/PROFIBUS DP WinCC Flexible 2004/2008 SP5 Discontinued; check phase on Siemens Product Lifecycle portal
TP177B 4" color (6AV6642-0BC01-1AX1) 4" TFT 320 × 240 MPI/PROFIBUS DP WinCC Flexible 2004/2008 / TIA Portal (limited) Discontinued
TP177micro (6AV6640-0CA01-0AX1) 5.7" STN MPI WinCC Flexible 2004 Micro Discontinued
KTP400 Basic mono PN (6AV2123-2DB03-0AX0) 3.8" mono 320 × 240 PROFINET only – not compatible with this CPU unless you add a PN/DP coupler TIA Portal WinCC Basic Active
KTP700 Basic PN 7" TFT PROFINET only TIA Portal WinCC Basic Active
Comfort Panel TP700 / TP900 / TP1200 (6AV2 124-1/2/3) 7" – 12" color touch PROFINET + optional PROFIBUS plug-in module TIA Portal WinCC Comfort/Advanced Active
MP277 8" / 10" (6AV6643-0CB01-1AX1) 8"/10" TFT MPI/PROFIBUS DP WinCC Flexible 2008 / TIA Portal Discontinued; transition to Comfort panels

Verdict for the 6ES7151-7AA20-0AB0: the TP177B 4" or 6" or the TP177A 6" remain the most widely available MPI/PROFIBUS panels that work directly with this CPU. A Comfort Panel (TP700/TP1200) with the optional PROFIBUS plug-in card (6GK1162-1AA01) is the long-term-repair / lifecycle-stable choice.

OP7 suitability: the OP7 is technically compatible (MPI 187.5 kbit/s, ProTool project with S7-300/400 driver). It is, however, a 4-line text display, lacks touch/colour, has been in Product Cancellation since 2008, and configuration software (ProTool) is no longer maintained. Use it only for like-for-like spare replacement on an existing machine.

4. Hardware Wiring

Both MPI and PROFIBUS DP share the same 9-pin D-sub pinout on the CPU. Terminating resistors must be enabled at the two physical ends of the bus segment only.

Pin Signal Wire colour (6XV1830-0EH10)
1 SHIELD braid / foil
2 n.c. —
3 RxD/TxD-P (line B) red
4 RTS (CNTR-P) —
5 DGND (data ground) —
6 VP (+5 V termination) —
7 n.c. —
8 RxD/TxD-N (line A) green
9 n.c. —

Use the pre-assembled PROFIBUS cable with 9-pin D-sub and integrated terminating resistor (6XV1830-0EH10 plus connector 6ES7972-0BA12-0XA0). Insert the connector with the terminating switch in the ON position at the CPU and at the panel end only; the middle nodes must have it OFF. Maximum segment length at 187.5 kbit/s is 1000 m; at 1.5 Mbit/s 200 m; at 12 Mbit/s 100 m.

5. STEP 7 / TIA Portal CPU Side Configuration

  1. Open the SIMATIC Manager project that contains the ET 200S station; right-click IM151-7 CPU → Object Properties → tab Interface.
  2. Set Interface: MPI or PROFIBUS DP. Set MPI address = 2 (CPU default) and Highest MPI address: = 31. Transmission rate 187.5 kbit/s is the safe default for a single HMI.
  3. If DP is used, add the HMI as a DP slave with the panel's GSD file: Options → Install GSD File. Siemens panels ship with their GSD pre-installed in the HW catalog under PROFIBUS DP → HMI → Siemens AG.
  4. Download the HW Config to the CPU. The MPI/DP LED on the CPU should change from steady to flashing (active token passing).
  5. Compile and download the S7 program; ensure OB1, OB82 (diagnostic interrupt), OB100 (restart), and OB122 (I/O access error) are present to prevent the CPU from going STOP on first error.

6. HMI Configuration in WinCC Flexible / TIA Portal

  1. Create a WinCC Flexible project for the chosen TP/MP panel. In TIA Portal, add a new device → HMI → select the MLFB of the panel.
  2. On the panel's Connections editor, add an S7-300/400 connection. Set Interface: MPI or PROFIBUS, address = 3 (or any free address 3–31), Slot: 2 (CPU), Rack: 0. Leave the default rack/slot; the IM151-7 occupies slot 2 of its virtual rack.
  3. Set the same baud rate on the HMI side as on the CPU side (187.5 kbit/s for MPI; matched DP rate for PROFIBUS).
  4. For PROFIBUS DP panels, set the panel's PROFIBUS address to a unique value 3–31. The Highest station address on the bus must be ≥ the highest assigned address.
  5. Compile the HMI project. Transfer the runtime over Ethernet (TP Ethernet port) or via MPI/PROFIBUS using the "Transfer" mode on the panel (hold the Transfer button or set Settings → Transfer → enable MPI/DP transfer).

7. Tag, Alarm, and Encoder Value Configuration

7.1 Digital I/O status (online monitoring)

Declare the I/O as Process tags in WinCC Flexible with the same absolute addresses used in the STEP 7 symbol table. Example for byte 0 of the ET 200S digital input module (1st slot of the IM151-7):

Symbol:    DI_byte_0
Datatype:  BYTE  (or USINT for TIA WinCC)
Address:   E 0     (German)  /  I 0     (international)
Acquisition: Cyclic, 1 s

Place a numeric / bit-pattern output field on the screen bound to DI_byte_0 or individual bits E0.0…E0.7 for one-line state. Enable Display Leading Zeros in the panel's screen layout for readability.

7.2 Position encoder value (online monitoring)

For an SSI / incremental encoder wired to an ET 200S 1SSI module (e.g. 6ES7 138-4DB03-0AB0) or a 1Count24V counter module, the encoder value lands in input words IW x and IW x+1. Configure:

Symbol:   EncoderPos
Datatype: DINT  (32-bit signed) or DWORD
Address:  ID  x        (I area, double-word aligned)
Length:   4 bytes
Scaling:  user units per increment / engineering units in the PLC

Use an I/O Field on the panel with display format Decimal and the proper scaling (counts → mm, deg, pulses). For 32-bit encoders, declare a DINT tag; the panel will display signed integer values directly.

7.3 Fault reading and acknowledgement

For bit faults mapped to a word (e.g. MW 100) use WinCC Flexible's Bit messages with acknowledgement. For S7 diagnostic alarms (drive, slave, module faults) generated by the CPU, the operator panel will receive them through the standard S7 diagnostic mechanism if you tick Use S7 diagnostics in the connection settings and define a Message number assignment in the CPU (STEP 7 → CPU properties → Diagnostics). Each diagnostic event creates an entry in the panel's Message view with the Acknowledge button, and the acknowledgement bit is set in the corresponding Acknowledge tag.

For S7 user-defined alarms (SFC17 / SFC18 / SFC107 / SFC108) that you trigger from OB1, declare alarm numbers 1–999 in the CPU's Alarm_S / Alarm_D configuration and the matching message text in WinCC Flexible's Bit messages or Alarm messages. The acknowledgement tag and the Acknowledge HMI button reset the alarm bit in the PLC.

8. Online / Diagnostic Tools (TIA Portal "CPU Operator Panel")

In TIA Portal with the PG connected to the 6ES7151-7AA20-0AB0 over MPI/DP, the Online & Diagnostics → CPU operator panel view reports the operating mode (STOP / RUN / STARTUP / HOLD), the presence of an error, the value-forcing status, and the online/Offline comparison state. This is a software-only view; it does not replace a physical HMI. Use it during commissioning to confirm the bus is alive before fault-tracing the panel connection.

9. Commissioning Verification (Field Procedure)

  1. Power up the ET 200S station with the HMI connector unpowered first; measure 24 V at the panel.
  2. Power the panel. Enter Transfer mode and download the compiled HMI runtime. Restart the panel.
  3. Verify the panel changes from Connection error to Online; the diagnostic LED on the panel turns green.
  4. In TIA Portal / STEP 7 Online → Accessible Nodes the panel's MPI/DP address must appear.
  5. Toggle a digital input and verify the bit-pattern changes on the HMI screen within 2 s (default acquisition).
  6. Move the encoder and verify the I/O field value changes by the expected scaling factor.
  7. Trigger a test fault (e.g. force a wire break on an analog input) and confirm the panel raises a message and that the Acknowledge button clears it.

10. Troubleshooting Matrix

Symptom on panel Likely root cause Corrective action
"Connection to PLC failed" / panel shows Offline Wrong bus address, mismatched baud rate, terminating resistor left on a middle node, or shielding/ground loop Verify CPU MPI address = 2 and panel address is unique; force both to 187.5 kbit/s; verify 220 Ω terminators at exactly two ends; check shield is bonded at one end only
Panel boots, but all tags show "####" Datatype mismatch (e.g. tag declared INT, PLC symbol is DINT) or address alignment (DINT must be on word boundary) Re-declare tag with matching datatype; verify IW is even-numbered for 16-bit INT and ID is divisible by 4 for DINT
Some I/O update, some are static Acquisition cycle set too long, or wrong connection partner (slot 2 of the wrong CPU) Reduce acquisition cycle to 500 ms; set Slot = 2 / Rack = 0 in the HMI connection
Fault messages arrive but cannot be acknowledged Ack tag declared read-only, or OB82 missing so the CPU re-raises the diagnostic every cycle Mark the ack tag as "read/write"; load OB82 (and OB100, OB121, OB122) into the CPU
Encoder value jumps by ±1 LSB Counter module not initialised, scaling wrong, or encoder in Gray code Check 1Count24V / 1SSI configuration bits; declare the tag as DWORD and apply the unit conversion in WinCC
Panel reset every few minutes Bus error from missing terminator causing CPU to drop and re-join the bus Install PROFIBUS connector with terminator ON at the two physical ends; verify shield continuity
"Transfer" not possible over MPI/DP Panel's Transfer setting disabled in Control Panel → Transfer → enable MPI/DP channel Enable the channel in the panel's Control Panel, set station address, restart panel

11. Migration to Active Components

The OP7, OP17, OP27, OP37, TP170A/B, TP177A/B, TP177micro, and MP177/MP277 are all in Discontinued or Product Cancellation phase. For new installations, choose one of the following to guarantee spares for 10+ years:

  • Comfort Panel TP700 / TP900 / TP1200 with the PROFIBUS plug-in module 6GK1162-1AA01 – active product, full TIA Portal support, PROFIBUS DP 12 Mbit/s.
  • Basic Panel KTP400 / KTP700 / KTP900 / KTP1200 with PROFINET – requires a IE/PB Link PN IO (6GK1411-5AB10) or a PN/DP coupler between the ET 200S CPU's MPI/DP port and the PROFINET panel.
  • For PCS 7 plants, the panel is typically an OS client, see Integration of S7-300 Package Units in SIMATIC PCS 7 for the recommended OS route.
Lifecycle advice: if you have only one spare TP177B in the cabinet, do not install it on a new line. Keep it as a like-for-like emergency spare for an existing machine where the user is already trained. For new lines, stock a Comfort Panel and the PROFIBUS plug-in card instead.

12. Field-Proven Cautions

  • Never enable the PROFIBUS terminating resistor on more than two nodes per segment. A common field error is enabling the terminator on the CPU, the panel, and a third ET 200 station that happens to sit at the end of the cable run.
  • The IM151-7 CPU's MPI/DP port and the IM151-8 PN/DP's PROFINET port are mutually exclusive for HMI traffic if you only have one cable run. Use a PN/DP coupler (e.g. 6GK1411-5AB10) if the panel is PROFINET-only.
  • When the panel is in Transfer mode, it briefly drops its S7 connection. This is normal and does not indicate a fault.
  • If a TIA Portal project is compiled against a Comfort Panel using "S7-300/400" as the connection, the bus address on the panel and the slot of the CPU must match exactly. Mismatches cause a non-deterministic connection failure that only shows up after a panel restart.
  • Encoder values from a 1SSI module arrive as a right-justified 16- or 32-bit integer in IW; apply bit-shifting and zero-adjustment in the PLC's user program (FC/FB) before exposing the scaled value to the HMI as a DINT tag.

Which operator panel is the best fit for the ET 200S CPU 6ES7151-7AA20-0AB0?

For a single panel on MPI at 187.5 kbit/s, use the TP177B 4" (6AV6642-0BC01-1AX1) or TP177A 6" (6AV6642-0BA01-1AX1). For a long-term-stable installation, choose a Comfort Panel TP700/TP900/TP1200 (6AV2 124-…) with the PROFIBUS plug-in module 6GK1162-1AA01. The OP7 is technically compatible but is in Product Cancellation and should only be used as a like-for-like spare.

Is the OP7 suitable for the 6ES7151-7AA20-0AB0?

Yes, the OP7 supports MPI 187.5 kbit/s and is configured with ProTool. The driver for S7-300/400 in ProTool is fully compatible with the ET 200S IM151-7 CPU. However, the OP7 was placed in Product Cancellation in 2008 and ProTool is no longer maintained, so it should only be installed for like-for-like spare replacement, not for new machines.

Do I have to use PROFIBUS DP, or is MPI sufficient?

MPI at 187.5 kbit/s is sufficient to read faults, I/O status, and a position encoder value on a single HMI. Switch to PROFIBUS DP only when you need a second HMI, a drive, an ET 200 remote station, or higher update rates above 1.5 Mbit/s on the same bus segment.

How do I acknowledge a fault from the HMI?

Configure the alarm as a "Bit message with acknowledgement" or use S7 diagnostic alarms. In both cases the panel raises a message and sets the corresponding acknowledgement bit in the PLC when the operator presses the Acknowledge button. The CPU must contain OB82 (diagnostic interrupt) and OB100 / OB122 for the alarm system to behave deterministically.

What MPI/DP address should the HMI use?

Reserve address 0 (PG), 1 (reserved), and 2 (CPU). Assign the HMI any free address in the range 3–31 within the same segment. Make sure the "Highest station address" in the CPU's MPI/DP interface properties is set to a value greater than or equal to the highest assigned HMI address (typically 31).

Back to blog