Connecting an HMI Operator Panel to the ET 200S CPU 6ES7151-7AA20-0AB0
This reference documents how to select, wire, configure, and commission a Siemens SIMATIC operator panel (HMI) against the ET 200S CPU module with order number 6ES7 151-7AA20-0AB0. The same workflow applies to variants of the IM151-7 (6ES7151-7AA21-0AB0, 6ES7151-7AB00-0AB0, 6ES7151-7AB01-0AB0) and to the IM151-8 PN/DP (6ES7151-8AB00-0AB0) when its PROFIBUS interface is used. The objective is threefold: (1) read and acknowledge process faults, (2) monitor the online status of digital and analog inputs/outputs, and (3) display the live value of a position encoder connected to the ET 200S I/O.
1. CPU Interface and Communication Capabilities
The integrated X1 interface of the 6ES7151-7AA20-0AB0 supports the following modes, selectable in HW Config:
- MPI – default after factory reset; up to 32 nodes, default baud rate 187.5 kbit/s, max 12 Mbit/s on the 6ES7151-7AA20-0AB0 with firmware V3.x.
- PROFIBUS DP master – up to 125 slaves; 9.6 kbit/s to 12 Mbit/s.
- PROFIBUS DP slave – to a higher-level DP master (typical for PCS 7 AS stations).
Default MPI address out of the box is 2. HMI panels and the programming PG/PC must occupy addresses on the same bus segment; the CPU reserves addresses 0 (PG), 1 (PG/OP reserved), and 2 (CPU) by Siemens convention. Free usable addresses for HMI: 3 through 31 (and higher when bus repeaters are added).
The CPU operator panel referenced in TIA Portal online & diagnostic tools is a software view of the online CPU's mode, error state, and value-forcing status. It is not a physical HMI. The HMI selection and wiring discussed below are independent of that software feature.
2. Communication Protocol Decision Matrix
| Criterion | MPI | PROFIBUS DP |
|---|---|---|
| Maximum number of HMI stations per segment | 32 (CPU + 31 nodes) | 32 per segment, 125 with repeaters |
| Baud rate supported by 6ES7151-7AA20-0AB0 | 19.2 kbit/s – 187.5 kbit/s (firmware ≤ V2.x); up to 12 Mbit/s on V3.x | 9.6 kbit/s – 12 Mbit/s |
| Available HMI catalog | All SIMATIC Panels with MPI option: OP7, OP17, OP27, OP37, TP27, TP170A/B, TP177A/B, KTP, MP177, MP277, MP377, Comfort panels | Same panels with PROFIBUS option; the "DP" suffix is required on Comfort and Mobile panels |
| Configuration tool | ProTool, ProTool/Pro, WinCC Flexible 2004/2008, TIA Portal (WinCC) | WinCC Flexible 2004/2008, TIA Portal (WinCC Comfort/Advanced/Professional) |
| Typical use | Single panel, retrofit, no other DP slaves | Multiple panels, mixed with drives/remote I/O, high-speed data |
| Diagnostics depth | Standard S7 diagnostic, no slave diagnostics | Full DP slave diagnostics, station failure alarms, diagnostic interrupts routed to OB82 |
Recommendation: for a single operator panel that reads faults, I/O state, and a position encoder, MPI at 187.5 kbit/s is sufficient and avoids the need for GSD files or DP master configuration. Switch to PROFIBUS DP only if a second HMI, an ET 200 remote station, or a drive is also on the bus.
3. Compatible Operator Panel Catalog
Selection must satisfy three constraints simultaneously: (a) MPI or PROFIBUS physical interface on the panel, (b) WinCC Flexible / TIA Portal configuration project must be available for that panel, and (c) the panel must not be in the "Product Cancellation" phase if long-term spare-part availability matters.
| Panel (MLFB example) | Display | Interface | Config tool | Lifecycle status |
|---|---|---|---|---|
| OP7 (6AV3607-1JC20-0AX1) | 4 × 20 text LCD | MPI (RS-485) | ProTool / ProTool Lite | Product Cancellation (announcement 2008); spares only |
| OP17 (6AV3617-1JC20-0AX1) | 4 × 20 text LCD | MPI | ProTool / WinCC Flexible 2004 | Product Cancellation |
| TP177A 6" mono (6AV6642-0BA01-1AX1) | 5.7" STN 320 × 240 | MPI/PROFIBUS DP | WinCC Flexible 2004/2008 SP5 | Discontinued; check phase on Siemens Product Lifecycle portal |
| TP177B 4" color (6AV6642-0BC01-1AX1) | 4" TFT 320 × 240 | MPI/PROFIBUS DP | WinCC Flexible 2004/2008 / TIA Portal (limited) | Discontinued |
| TP177micro (6AV6640-0CA01-0AX1) | 5.7" STN | MPI | WinCC Flexible 2004 Micro | Discontinued |
| KTP400 Basic mono PN (6AV2123-2DB03-0AX0) | 3.8" mono 320 × 240 | PROFINET only – not compatible with this CPU unless you add a PN/DP coupler | TIA Portal WinCC Basic | Active |
| KTP700 Basic PN | 7" TFT | PROFINET only | TIA Portal WinCC Basic | Active |
| Comfort Panel TP700 / TP900 / TP1200 (6AV2 124-1/2/3) | 7" – 12" color touch | PROFINET + optional PROFIBUS plug-in module | TIA Portal WinCC Comfort/Advanced | Active |
| MP277 8" / 10" (6AV6643-0CB01-1AX1) | 8"/10" TFT | MPI/PROFIBUS DP | WinCC Flexible 2008 / TIA Portal | Discontinued; transition to Comfort panels |
Verdict for the 6ES7151-7AA20-0AB0: the TP177B 4" or 6" or the TP177A 6" remain the most widely available MPI/PROFIBUS panels that work directly with this CPU. A Comfort Panel (TP700/TP1200) with the optional PROFIBUS plug-in card (6GK1162-1AA01) is the long-term-repair / lifecycle-stable choice.
4. Hardware Wiring
Both MPI and PROFIBUS DP share the same 9-pin D-sub pinout on the CPU. Terminating resistors must be enabled at the two physical ends of the bus segment only.
| Pin | Signal | Wire colour (6XV1830-0EH10) |
|---|---|---|
| 1 | SHIELD | braid / foil |
| 2 | n.c. | — |
| 3 | RxD/TxD-P (line B) | red |
| 4 | RTS (CNTR-P) | — |
| 5 | DGND (data ground) | — |
| 6 | VP (+5 V termination) | — |
| 7 | n.c. | — |
| 8 | RxD/TxD-N (line A) | green |
| 9 | n.c. | — |
Use the pre-assembled PROFIBUS cable with 9-pin D-sub and integrated terminating resistor (6XV1830-0EH10 plus connector 6ES7972-0BA12-0XA0). Insert the connector with the terminating switch in the ON position at the CPU and at the panel end only; the middle nodes must have it OFF. Maximum segment length at 187.5 kbit/s is 1000 m; at 1.5 Mbit/s 200 m; at 12 Mbit/s 100 m.
5. STEP 7 / TIA Portal CPU Side Configuration
- Open the SIMATIC Manager project that contains the ET 200S station; right-click IM151-7 CPU → Object Properties → tab Interface.
- Set Interface: MPI or PROFIBUS DP. Set MPI address = 2 (CPU default) and Highest MPI address: = 31. Transmission rate 187.5 kbit/s is the safe default for a single HMI.
- If DP is used, add the HMI as a DP slave with the panel's GSD file: Options → Install GSD File. Siemens panels ship with their GSD pre-installed in the HW catalog under PROFIBUS DP → HMI → Siemens AG.
- Download the HW Config to the CPU. The MPI/DP LED on the CPU should change from steady to flashing (active token passing).
- Compile and download the S7 program; ensure OB1, OB82 (diagnostic interrupt), OB100 (restart), and OB122 (I/O access error) are present to prevent the CPU from going STOP on first error.
6. HMI Configuration in WinCC Flexible / TIA Portal
- Create a WinCC Flexible project for the chosen TP/MP panel. In TIA Portal, add a new device → HMI → select the MLFB of the panel.
- On the panel's Connections editor, add an S7-300/400 connection. Set Interface: MPI or PROFIBUS, address = 3 (or any free address 3–31), Slot: 2 (CPU), Rack: 0. Leave the default rack/slot; the IM151-7 occupies slot 2 of its virtual rack.
- Set the same baud rate on the HMI side as on the CPU side (187.5 kbit/s for MPI; matched DP rate for PROFIBUS).
- For PROFIBUS DP panels, set the panel's PROFIBUS address to a unique value 3–31. The Highest station address on the bus must be ≥ the highest assigned address.
- Compile the HMI project. Transfer the runtime over Ethernet (TP Ethernet port) or via MPI/PROFIBUS using the "Transfer" mode on the panel (hold the Transfer button or set Settings → Transfer → enable MPI/DP transfer).
7. Tag, Alarm, and Encoder Value Configuration
7.1 Digital I/O status (online monitoring)
Declare the I/O as Process tags in WinCC Flexible with the same absolute addresses used in the STEP 7 symbol table. Example for byte 0 of the ET 200S digital input module (1st slot of the IM151-7):
Symbol: DI_byte_0
Datatype: BYTE (or USINT for TIA WinCC)
Address: E 0 (German) / I 0 (international)
Acquisition: Cyclic, 1 s
Place a numeric / bit-pattern output field on the screen bound to DI_byte_0 or individual bits E0.0…E0.7 for one-line state. Enable Display Leading Zeros in the panel's screen layout for readability.
7.2 Position encoder value (online monitoring)
For an SSI / incremental encoder wired to an ET 200S 1SSI module (e.g. 6ES7 138-4DB03-0AB0) or a 1Count24V counter module, the encoder value lands in input words IW x and IW x+1. Configure:
Symbol: EncoderPos
Datatype: DINT (32-bit signed) or DWORD
Address: ID x (I area, double-word aligned)
Length: 4 bytes
Scaling: user units per increment / engineering units in the PLC
Use an I/O Field on the panel with display format Decimal and the proper scaling (counts → mm, deg, pulses). For 32-bit encoders, declare a DINT tag; the panel will display signed integer values directly.
7.3 Fault reading and acknowledgement
For bit faults mapped to a word (e.g. MW 100) use WinCC Flexible's Bit messages with acknowledgement. For S7 diagnostic alarms (drive, slave, module faults) generated by the CPU, the operator panel will receive them through the standard S7 diagnostic mechanism if you tick Use S7 diagnostics in the connection settings and define a Message number assignment in the CPU (STEP 7 → CPU properties → Diagnostics). Each diagnostic event creates an entry in the panel's Message view with the Acknowledge button, and the acknowledgement bit is set in the corresponding Acknowledge tag.
For S7 user-defined alarms (SFC17 / SFC18 / SFC107 / SFC108) that you trigger from OB1, declare alarm numbers 1–999 in the CPU's Alarm_S / Alarm_D configuration and the matching message text in WinCC Flexible's Bit messages or Alarm messages. The acknowledgement tag and the Acknowledge HMI button reset the alarm bit in the PLC.
8. Online / Diagnostic Tools (TIA Portal "CPU Operator Panel")
In TIA Portal with the PG connected to the 6ES7151-7AA20-0AB0 over MPI/DP, the Online & Diagnostics → CPU operator panel view reports the operating mode (STOP / RUN / STARTUP / HOLD), the presence of an error, the value-forcing status, and the online/Offline comparison state. This is a software-only view; it does not replace a physical HMI. Use it during commissioning to confirm the bus is alive before fault-tracing the panel connection.
9. Commissioning Verification (Field Procedure)
- Power up the ET 200S station with the HMI connector unpowered first; measure 24 V at the panel.
- Power the panel. Enter Transfer mode and download the compiled HMI runtime. Restart the panel.
- Verify the panel changes from Connection error to Online; the diagnostic LED on the panel turns green.
- In TIA Portal / STEP 7 Online → Accessible Nodes the panel's MPI/DP address must appear.
- Toggle a digital input and verify the bit-pattern changes on the HMI screen within 2 s (default acquisition).
- Move the encoder and verify the I/O field value changes by the expected scaling factor.
- Trigger a test fault (e.g. force a wire break on an analog input) and confirm the panel raises a message and that the Acknowledge button clears it.
10. Troubleshooting Matrix
| Symptom on panel | Likely root cause | Corrective action |
|---|---|---|
| "Connection to PLC failed" / panel shows Offline | Wrong bus address, mismatched baud rate, terminating resistor left on a middle node, or shielding/ground loop | Verify CPU MPI address = 2 and panel address is unique; force both to 187.5 kbit/s; verify 220 Ω terminators at exactly two ends; check shield is bonded at one end only |
| Panel boots, but all tags show "####" | Datatype mismatch (e.g. tag declared INT, PLC symbol is DINT) or address alignment (DINT must be on word boundary) | Re-declare tag with matching datatype; verify IW is even-numbered for 16-bit INT and ID is divisible by 4 for DINT |
| Some I/O update, some are static | Acquisition cycle set too long, or wrong connection partner (slot 2 of the wrong CPU) | Reduce acquisition cycle to 500 ms; set Slot = 2 / Rack = 0 in the HMI connection |
| Fault messages arrive but cannot be acknowledged | Ack tag declared read-only, or OB82 missing so the CPU re-raises the diagnostic every cycle | Mark the ack tag as "read/write"; load OB82 (and OB100, OB121, OB122) into the CPU |
| Encoder value jumps by ±1 LSB | Counter module not initialised, scaling wrong, or encoder in Gray code | Check 1Count24V / 1SSI configuration bits; declare the tag as DWORD and apply the unit conversion in WinCC |
| Panel reset every few minutes | Bus error from missing terminator causing CPU to drop and re-join the bus | Install PROFIBUS connector with terminator ON at the two physical ends; verify shield continuity |
| "Transfer" not possible over MPI/DP | Panel's Transfer setting disabled in Control Panel → Transfer → enable MPI/DP channel | Enable the channel in the panel's Control Panel, set station address, restart panel |
11. Migration to Active Components
The OP7, OP17, OP27, OP37, TP170A/B, TP177A/B, TP177micro, and MP177/MP277 are all in Discontinued or Product Cancellation phase. For new installations, choose one of the following to guarantee spares for 10+ years:
-
Comfort Panel TP700 / TP900 / TP1200 with the PROFIBUS plug-in module
6GK1162-1AA01– active product, full TIA Portal support, PROFIBUS DP 12 Mbit/s. - Basic Panel KTP400 / KTP700 / KTP900 / KTP1200 with PROFINET – requires a IE/PB Link PN IO (6GK1411-5AB10) or a PN/DP coupler between the ET 200S CPU's MPI/DP port and the PROFINET panel.
- For PCS 7 plants, the panel is typically an OS client, see Integration of S7-300 Package Units in SIMATIC PCS 7 for the recommended OS route.
12. Field-Proven Cautions
- Never enable the PROFIBUS terminating resistor on more than two nodes per segment. A common field error is enabling the terminator on the CPU, the panel, and a third ET 200 station that happens to sit at the end of the cable run.
- The IM151-7 CPU's MPI/DP port and the IM151-8 PN/DP's PROFINET port are mutually exclusive for HMI traffic if you only have one cable run. Use a PN/DP coupler (e.g.
6GK1411-5AB10) if the panel is PROFINET-only. - When the panel is in Transfer mode, it briefly drops its S7 connection. This is normal and does not indicate a fault.
- If a TIA Portal project is compiled against a Comfort Panel using "S7-300/400" as the connection, the bus address on the panel and the slot of the CPU must match exactly. Mismatches cause a non-deterministic connection failure that only shows up after a panel restart.
- Encoder values from a 1SSI module arrive as a right-justified 16- or 32-bit integer in IW; apply bit-shifting and zero-adjustment in the PLC's user program (FC/FB) before exposing the scaled value to the HMI as a DINT tag.
Which operator panel is the best fit for the ET 200S CPU 6ES7151-7AA20-0AB0?
For a single panel on MPI at 187.5 kbit/s, use the TP177B 4" (6AV6642-0BC01-1AX1) or TP177A 6" (6AV6642-0BA01-1AX1). For a long-term-stable installation, choose a Comfort Panel TP700/TP900/TP1200 (6AV2 124-…) with the PROFIBUS plug-in module 6GK1162-1AA01. The OP7 is technically compatible but is in Product Cancellation and should only be used as a like-for-like spare.
Is the OP7 suitable for the 6ES7151-7AA20-0AB0?
Yes, the OP7 supports MPI 187.5 kbit/s and is configured with ProTool. The driver for S7-300/400 in ProTool is fully compatible with the ET 200S IM151-7 CPU. However, the OP7 was placed in Product Cancellation in 2008 and ProTool is no longer maintained, so it should only be installed for like-for-like spare replacement, not for new machines.
Do I have to use PROFIBUS DP, or is MPI sufficient?
MPI at 187.5 kbit/s is sufficient to read faults, I/O status, and a position encoder value on a single HMI. Switch to PROFIBUS DP only when you need a second HMI, a drive, an ET 200 remote station, or higher update rates above 1.5 Mbit/s on the same bus segment.
How do I acknowledge a fault from the HMI?
Configure the alarm as a "Bit message with acknowledgement" or use S7 diagnostic alarms. In both cases the panel raises a message and sets the corresponding acknowledgement bit in the PLC when the operator presses the Acknowledge button. The CPU must contain OB82 (diagnostic interrupt) and OB100 / OB122 for the alarm system to behave deterministically.
What MPI/DP address should the HMI use?
Reserve address 0 (PG), 1 (reserved), and 2 (CPU). Assign the HMI any free address in the range 3–31 within the same segment. Make sure the "Highest station address" in the CPU's MPI/DP interface properties is set to a value greater than or equal to the highest assigned HMI address (typically 31).