1. Overview: Migrating a Profibus-DP Line to S7-1500 While Retaining Legacy HMIs
Industrial revamping projects frequently encounter a mixed-vintage situation: a facility was originally automated with a SIMATIC S7-300 or S7-400 station driving an OP7, OP17, OP27, OP37, OP77A, or OP77B operator panel programmed with ProTool/Pro V6.0, and a modernization phase now requires the controller to be replaced with a SIMATIC S7-1500 (CPU 1511, 1513, 1515, 1516, 1517, or 1518). Budget pressure, downtime limits, and the customer's reluctance to retrain operators on a new HMI often create the engineering brief: replace the CPU, keep the panels.
ProTool/Pro is a long-discontinued HMI engineering tool. It was superseded by WinCC flexible (2004–2013) and then by the integrated TIA Portal WinCC (2010–present). TIA Portal is the only environment that supports the S7-1500 family. ProTool does not contain an S7-1500 device driver; you cannot simply add a CPU 1516 to a ProTool project. However, the Profibus-DP protocol used by the legacy OP7/OP77B is identical to the protocol the S7-1500 supports through the CM 1542-5 communications module (or through the integrated DP interface of the -3 PN/DP CPU variants). By configuring the S7-1500 as the DP master in the TIA Portal project and the OP7/OP77B with the S7-300/400 driver in the original ProTool project, a working communications path can be established — provided two critical settings are correct:
- The driver in the ProTool project must use the S7-300/400 protocol (not S7-1200 or S7-1500) and reference absolute DB addresses.
- The S7-1500 CPU must allow PUT/GET access from remote partners, and every data block used for HMI exchange must be non-optimized so the absolute addresses remain valid.
Field reports confirm that an OP77B configured as an S7-300/400 device on Profibus DP will communicate with an S7-1500 (and with the S7-1200 via CM 1243-5) when the CPU security settings permit remote PUT/GET and the data blocks are configured for standard (non-optimized) access. Siemens does not formally support this combination; the S7-300/400 driver is intended for the legacy S7-300/400 controllers, not the S7-1500. The functionality is therefore best-effort and must be validated on a bench test before production deployment. Treat the configuration as an unsupported engineering bridge, not a long-term design.
This reference documents the practical configuration procedure, the parameters that determine success, the verification methods, and the limitations to communicate to the customer before signing the modernization order.
2. Compatibility Matrix: ProTool Panels vs. S7-1500
The following matrix captures the panels, drivers, and S7-1500 CPU variants that have a realistic chance of working in this combination. The "Status" column is derived from the S7-1200 field tests and theoretical extension to the S7-1500 — it is not a Siemens product guarantee.
| Panel Model | ProTool Driver | Profibus DP | Tested with S7-1500 | Status |
|---|---|---|---|---|
| OP7 | S7-300/400 | Yes (with option module) | Not formally tested | Probable with slot = 1 |
| OP17 | S7-300/400 | Yes | Not formally tested | Probable with slot = 1 |
| OP27 | S7-300/400 | Yes | Not formally tested | Probable with slot = 1 |
| OP37 | S7-300/400 | Yes | Not formally tested | Probable with slot = 1 |
| OP77A | S7-300/400 | Yes | Not formally tested | Probable with slot = 1 |
| OP77B | S7-300/400 | Yes | Field-validated against S7-1200, expected with S7-1500 | Working with absolute DB access |
| TP170A (micro) | S7-300/400 | Yes | Not formally tested | Probable with slot = 1 |
| TP170B | S7-300/400 | Yes | Not formally tested | Probable with slot = 1 |
| S7-1500 CPU | MLFB (Article No.) | DP Master Source | Firmware (validated) | PG/HMI Connections |
|---|---|---|---|---|
| CPU 1511-1 PN | 6ES7511-1AK02-0AB0 | CM 1542-5 (6GK7542-5FX00-0XE0) | V2.9 and later | 32 |
| CPU 1513-1 PN | 6ES7513-1AL02-0AB0 | CM 1542-5 | V2.9 and later | 32 |
| CPU 1515-2 PN | 6ES7515-2AM02-0AB0 | CM 1542-5 | V2.9 and later | 64 |
| CPU 1516-3 PN/DP | 6ES7516-3AN02-0AB0 | Integrated DP + optional CM 1542-5 | V2.9 and later | 64 |
| CPU 1517-3 PN/DP | 6ES7517-3AP00-0AB0 | Integrated DP + optional CM 1542-5 | V3.0 and later | 128 |
| CPU 1518-4 PN/DP | 6ES7518-4AP00-0AB0 | Integrated DP + optional CM 1542-5 | V3.0 and later | 192 |
6GK7542-5FX00-0XE0. Firmware V2.0 or later is required to interoperate with S7-1500 firmware V2.9.x. If the CPU already has an integrated DP interface (1516-3 PN/DP, 1517-3 PN/DP, 1518-4 PN/DP) and you only have one DP master role to play, the integrated port is sufficient and the CM 1542-5 is not required.3. Required Hardware and Software Components
3.1 Controller side
- S7-1500 CPU (any of the variants listed above) with sufficient free connection resources. Each active HMI/PG connection consumes one resource.
- CM 1542-5 (6GK7542-5FX00-0XE0) if the CPU does not have an integrated DP master port, or as a second DP master if multiple DP lines must be supported.
- S7-1500 CPU firmware that supports PUT/GET. PUT/GET has been available since firmware V1.0 but is disabled by default. Firmware V2.9.x is the current long-term-service branch; V3.0.x is the latest released branch; V4.0 changes the security model and reorganises the access settings under "Connection mechanisms".
- TIA Portal V17, V18, V19, or V20 for project engineering. TIA Portal V15.1 or later is sufficient for the configuration described in this article.
3.2 HMI side
- Legacy ProTool/Pro panel: OP7, OP17, OP27, OP37, OP77A, OP77B, or the early TP170 variants.
- Original ProTool/Pro V6.0 SP3 project (file extension
*.pdb), or the WinCC flexible 2008 SP2 / SP5 project if the panel was migrated to WinCC flexible before. WinCC flexible is the recommended engineering tool for OP77B because it can import a ProTool V6.0 project and re-target the connection to an S7-300/400 driver. - Profibus DP connector on the panel side. For OP77B use 6GK1500-0FC00 (with PG socket) or 6GK1500-0EA02 (without PG socket), both with integrated terminating resistor switch.
- Profibus cable: Siemens 6XV1830-0EH10 (purple, shielded, twisted pair, 150 Ω nominal impedance). Maximum segment length: 200 m at 1.5 Mbps, 1000 m at 187.5 kbps.
3.3 Network side
- 9-pin D-sub Profibus connectors with integrated terminating resistor on the first and last physical station of the segment.
- 24 V DC power supply for the panel and any Profibus repeaters (6GK1716-1HB00-0AA0 or equivalent) if the bus must exceed the standard 32-station / 1000 m limit.
4. Profibus DP Topology and Bus Architecture
The topology is a linear RS-485 bus. The S7-1500 (via CM 1542-5 or its integrated DP port) is the DP master class 1; the legacy panel is a DP slave. Terminating resistors must be enabled at the two physical ends of the segment only. The OP77B GSD file presents the panel as a slave with a configurable slot layout; when the S7-300/400 driver is selected, the slot the master addresses becomes the parameter that determines whether the CPU responds.
5. Driver Selection: Why S7-300/400 and Not S7-1200/1500
In the ProTool/Pro V6.0 SP3 connection dialog, the legacy panels expose several controller options:
- SIMATIC S7-300/400 — uses MPI or Profibus DP, absolute addressing (DB number + byte offset + bit offset).
- SIMATIC S7-1200 — uses Profibus, symbolic addressing only.
- Other vendor drivers (Mitsubishi, Allen-Bradley DF1, Modbus RTU, etc.).
The S7-1500 is not on the list. The S7-1200 option exists in ProTool V6.0 SP3, but it requires symbolic addressing — the ProTool project would have to reference symbolic tag names that match the PLC's symbolic table, and the runtime in the panel firmware predates the S7-1200 symbolic protocol. The S7-1200 option is effectively non-functional in ProTool V6.0 SP3. The only viable option for a ProTool project talking to an S7-1500 is the S7-300/400 driver.
The internal logic is straightforward: the ProTool runtime on the panel sends Profibus-DP telegrams to the configured station using the slot number and the absolute addresses from the project. The S7-1500 CM 1542-5 (or the integrated DP port) is configured as a DP master, receives the request, and forwards the data access to the CPU. If the CPU's PUT/GET access setting is enabled and the target DB is non-optimized, the access succeeds because the absolute address resolves to a valid byte in the CPU's process image. The S7-1500 itself does not "see" that the request came from an OP77B; it simply sees a PUT/GET partner. The PUT/GET protocol on the Profibus/PROFINET boundary is opaque to the CPU model.
Therefore, the configuration rules are:
- Use the S7-300/400 driver in the ProTool or WinCC flexible project.
- Reference data blocks by absolute DB number and byte/bit offset (e.g.,
DB 100, DBW 0for the first word of DB 100). - Disable Optimized block access on every data block used by the HMI in TIA Portal.
- Enable PUT/GET access on the S7-1500 CPU security settings.
6. The Slot Parameter: The Most Common Failure Point
The ProTool S7-300/400 driver has a Slot parameter in the connection dialog. The default value is 2, which corresponds to the position of the CPU in a real S7-300/400 rack (slot 1 is the power supply, slot 2 is the CPU).
For an S7-1200 with CM 1243-5 Profibus DP master, the S7-1200 CPU occupies slot 1 of its rack; the DP master module sits beside it but is not the CPU from the partner's perspective. Field testing has confirmed that the ProTool project must be reconfigured with Slot = 1 to talk to an S7-1200 via the CM 1243-5. The S7-300/400 driver default of 2 fails because the partner requests slot 2, and the S7-1200 does not present a Profibus-visible slot 2.
For an S7-1500 with CM 1542-5, the S7-1500 CPU is in slot 1 of its rack; the CM 1542-5 is in slot 2 (or higher depending on the rack layout). From the Profibus-DP partner's perspective, the CPU's logical slot is therefore 1. The expected configuration is Slot = 1 in the ProTool project. However, this combination is not formally validated, and a bench test is required to confirm. If Slot = 1 fails, fall back to Slot = 2 and use the S7-1500 online diagnostics (TIA Portal → Online & Diagnostics → Profibus DP → Active Stations) to confirm which slot the panel reaches.
| Controller | DP Master Module | ProTool Driver | Slot Setting | Result |
|---|---|---|---|---|
| S7-300 / S7-400 | Integrated | S7-300/400 | 2 (default) | Works |
| S7-1200 | CM 1243-5 | S7-300/400 | 1 (override) | Works (field-validated) |
| S7-1500 | CM 1542-5 or integrated | S7-300/400 | 1 (expected), 2 (fallback) | Bench-validate |
7. S7-1500 TIA Portal Configuration
The TIA Portal project for the S7-1500 must be configured in the following sequence. All steps are written for TIA Portal V18/V19/V20; V15.1 and V17 differ only in menu placement.
7.1 Add the CPU and the DP master module
- Open the TIA Portal project and add the S7-1500 station.
- Drag the CPU (for example 6ES7516-3AN02-0AB0) into slot 1 of the rack.
- If the CPU has no integrated DP, drag the CM 1542-5 (6GK7542-5FX00-0XE0) into slot 2.
- Confirm the modules are recognised and the firmware version is current (V2.9.x or V3.0.x).
7.2 Configure the Profibus-DP master
- Open the device view of the CM 1542-5 (or the CPU's integrated DP port).
- Add a Profibus subnet. Assign the master address (default 2, configurable to 1–126).
- Set the baud rate to match the panel's Profibus connector. The OP77B supports 9.6 kbps to 12 Mbps; 1.5 Mbps is the typical production setting. Lower baud rates are more tolerant of long cable runs and noisy environments.
- Leave the bus timing parameters (
Tslot,Tset,Tqui) at their default values unless the bus is long, has many repeaters, or shows diagnostic errors in the S7-1500's online diagnostics.
7.3 Add the OP77B as a DP slave
- In the Profibus subnet, right-click → Add new device → browse to the OP77B GSD file.
- The GSD file is shipped with ProTool V6.0 SP3 (
SIEM81B0.gsdfor OP77B) or can be downloaded from the Siemens Industry Online Support portal. - Assign the slave's Profibus address (for example 3). Avoid address 0, 1, and 126 — these are reserved for class-2 masters and service tools.
- Configure the slave's slot 1 with the appropriate I/O or DB-access parameters. For PUT/GET-only operation, no cyclic I/O is required; the slot is a virtual placeholder that the partner's slot setting must match.
- Compile the hardware configuration and download it to the S7-1500.
7.4 Create the data blocks for HMI exchange
In the S7-1500 program, create one or more standard data blocks (for example DB 100, DB 200) as the HMI exchange area. Open the DB properties and uncheck Optimized block access. Declare variables with absolute addresses that the ProTool project can reference:
DATA_BLOCK "DB_HMI_Exchange"
{ S7_Optimized_Access := 'FALSE' }
VERSION : 0.1
NON_RETAIN
VAR
HMI_Start_Button : BOOL; // DB 100.DBX0.0
HMI_Stop_Button : BOOL; // DB 100.DBX0.1
HMI_Ack_Alarm : BOOL; // DB 100.DBX0.2
HMI_Setpoint_Speed : INT; // DB 100.DBW2
HMI_Actual_Speed : INT; // DB 100.DBW4
HMI_Actual_Temp : REAL; // DB 100.DBD6
HMI_Recipe_Number : INT; // DB 100.DBW10
END_VAR
BEGIN
END_DATA_BLOCK
S7_Optimized_Access := 'FALSE' is mandatory. Without it, the S7-1500 stores DB variables in symbolic-only format and the absolute addresses DB 100.DBW 2 configured in the ProTool project will not resolve correctly — the data access will return undefined values or trigger a Profibus diagnostic error.7.5 Enable PUT/GET access on the CPU
- Open the S7-1500 device properties.
- Navigate to Security → Connection mechanisms (firmware V2.x) or Security settings → Connection mechanisms (firmware V3.x and V4.x).
- Enable Permit access with PUT/GET communication from remote partner.
- Compile and download the hardware configuration.
7.6 Compile and download
- Compile the TIA Portal project (Project → Compile all).
- Download the hardware configuration to the S7-1500 (Online → Download to device).
- Restart the CPU in RUN mode if prompted. Confirm the CM 1542-5's
BF(bus fault) LED is off and theRUNLED is solid green.
8. Step-by-Step Commissioning Procedure
- Plan the change window. Block at least 4 hours for a single-panel swap, plus a 2-hour buffer for troubleshooting. Notify operations of the planned HMI blackout.
- Bench-test the configuration before the field cutover. Reproduce the wiring and the TIA Portal project on the test bench. Validate the ProTool / WinCC flexible project against the live S7-1500 station. Confirm all data points read and write correctly, including the alarm bits and recipe data.
- Wire the Profibus network. Install the Profibus cable between the CM 1542-5 and the OP77B connector. Use 6XV1830-0EH10 cable; route it in a dedicated cable tray at least 100 mm from VFD power cables.
- Configure the terminating resistors. Enable the resistor switch on the first and last physical station of the segment. Disable it on every station in between. The OP77B connector 6GK1500-0FC00 has a switch labelled "ON / OFF"; the CM 1542-5 has no on-board terminator and must use an external active terminator (6GK1500-0AB10) if it sits at the end of the segment.
-
Power up and verify the master. Apply 24 V DC to the panel. Confirm the CM 1542-5's
SF(system fault),BF(bus fault), andRUNLEDs. In TIA Portal, go to Online & Diagnostics → Profibus DP → Active Stations and confirm the panel's address appears in the list. - Configure the OP77B project in ProTool or WinCC flexible. Open the project, set the connection to S7-300/400, set the Profibus address to 3, set the slot to 1 (or 2 if the bench test indicated so), and verify all tag addresses match the DB layout from step 7.4.
- Download the OP77B project. Use ProSave (the ProTool / WinCC flexible transfer utility) to transfer the compiled runtime to the panel over Profibus, MPI, serial, or USB-PPI depending on the panel variant. Allow the panel to restart automatically.
- Test all data points. In TIA Portal, force values in DB 100 and confirm they appear on the OP77B screen. Trigger an input on the OP77B touch panel and confirm the corresponding bit in DB 100 toggles in the TIA Portal watch table.
- Document the configuration. Capture the Profibus address, the slot setting, the DB numbers, the PUT/GET setting, and the panel firmware version. File the document with the project records so the configuration can be reproduced by the next engineer.
- Commission. Hand the line back to operations with a written acceptance test record signed by the customer's representative.
9. Verification and Online Diagnostics
Use the following diagnostic chain when the panel fails to communicate.
| Symptom on Panel | Likely Cause | Diagnostic Action | Fix |
|---|---|---|---|
| "Connection Error" on screen | Wrong Profibus address or slot | TIA Portal → Online & Diagnostics → Profibus DP → Active Stations | Set slot to 1 (or 2) per bench test; verify address 3 matches the connector DIP switch |
| Values frozen at initial value | DB optimized, PUT/GET disabled | TIA Portal → DB properties → Optimized block access; CPU security settings | Uncheck optimized access; enable PUT/GET |
| CM 1542-5 BF LED solid red | Bus short, missing terminator, baud rate mismatch | Check cable continuity; check terminator switches; check baud rate | Replace cable segment; enable terminators; match baud rate |
| CM 1542-5 SF LED flashing | Slave not responding, GSD mismatch | TIA Portal → Online → Accessible nodes | Re-install GSD; verify slave address within 1–125 |
| Intermittent communication | EMI, bad connector, baud rate too high for cable length | Inspect cable shield; reduce baud rate to 500 kbps | Re-terminate connectors; lower baud rate; add repeater |
| Panel shows "???" on numeric fields | Address in ProTool project does not exist in DB | Cross-check DB layout in TIA Portal against ProTool tag list | Correct the tag address in the ProTool / WinCC flexible project |
For deeper diagnostics, the S7-1500's diagnostic buffer records every Profibus slave state change with a timestamp and an event ID. Open Online & Diagnostics → Diagnostic buffer and filter on "Profibus" to see whether the CM 1542-5 has logged station failure, station return, or configuration mismatch events. The CPU's event IDs for Profibus include (among others):
-
0x130A— Profibus station failure (slave went offline). -
0x130B— Profibus station return (slave came back online). -
0x130C— Profibus configuration error (slot mismatch, GSD mismatch). -
0x1310— Profibus bus error (parity, framing, baud rate).
Each event includes the slave's Profibus address and (for slot/configuration errors) the slot number the master attempted to address. Use the event ID and slot to pinpoint whether the slot setting in the ProTool project matches the slot the master expects.
10. Limitations, Risks, and Migration Path
The ProTool-to-S7-1500 configuration is a non-supported engineering bridge. Communicate the following limitations to the customer before signing the modernization order.
- No formal Siemens support. If the configuration fails, Siemens Industry Online Support will not log a support request against the combination. The configuration must be designed and validated by the integrator.
- Spare-parts risk. The OP7, OP17, OP27, OP37, OP77A, and OP77B are all in the SIMATIC HMI product-phase-out (PFO) lifecycle state. Repair and replacement parts are limited; lead times can be measured in months.
- Functional limitations. The S7-300/400 driver supports only absolute DB access. Symbolic tags, alarms with text references, and recipe data structures used by modern TIA Portal WinCC are not available. Any feature that requires symbolic addressing on the S7-1500 side will not work.
- Security implications. PUT/GET must be enabled. This is the same access model that allows an untrusted network partner to read and write CPU data. Restrict the Profibus segment to the panel and the CPU; do not expose it to the plant network without a Profibus firewall (Siemens Scalance S612 or similar).
- Migration path forward. Plan to replace the legacy panel with a Comfort Panel (TP700, TP900, TP1200, TP1500, TP1900, TP2200) or a Unified Panel within 2–3 years. The Comfort Panel is fully supported by the S7-1500 in TIA Portal and provides symbolic access, modern alarm logging, and recipe handling.
11. Frequently Asked Questions
Can I add a CPU 1516 to a ProTool/Pro V6.0 SP3 project?
No. ProTool/Pro does not list the S7-1500 family in its controller selection. Use the S7-300/400 driver with absolute DB addressing, configure the S7-1500 as the DP master in TIA Portal, and enable PUT/GET on the CPU. This combination is best-effort and not a Siemens-supported configuration.
What slot value should I configure in the ProTool S7-300/400 driver for an S7-1500?
Start with Slot = 1, which corresponds to the S7-1500 CPU's position in the rack. If communication fails, change to Slot = 2 and validate with the S7-1500 diagnostic buffer (event IDs 0x130A, 0x130B, 0x130C) and the TIA Portal Online & Diagnostics view.
Does the S7-1500 firmware version affect the PUT/GET configuration?
Yes. The setting has existed since firmware V1.0 but is relocated under Connection mechanisms from firmware V2.9 onward and re-grouped under Security settings in firmware V4.0. V2.9.x and V3.0.x are the widely deployed long-term-service branches. Confirm the option's location in the firmware-specific TIA Portal help.
Can I migrate the ProTool project to WinCC flexible 2008 and then to TIA Portal WinCC?
Yes. WinCC flexible 2008 SP2 or SP5 can import a ProTool V6.0 SP3 project. TIA Portal can then import a WinCC flexible project for migration to a Comfort Panel, but the migrated project targets the modern TIA Portal WinCC device, not the legacy OP77B. The OP77B remains a WinCC flexible endpoint; the S7-1500 connection works the same way as in ProTool.
Will Siemens support a Profibus-DP connection between a ProTool panel and an S7-1500?
No. The S7-300/400 driver is intended for the S7-300 and S7-400 controllers only. Siemens Industry Online Support will not register a support request for a ProTool panel against an S7-1500. Treat the configuration as an integrator-validated best-effort bridge, validate on a bench test, and document the configuration for the next engineer.
Why must the HMI data blocks be non-optimized on the S7-1500?
Optimized data blocks store variables in a symbolic-only format with the compiler free to reorder them in memory. The S7-300/400 driver in ProTool or WinCC flexible uses absolute addresses (DB number, byte offset, bit offset) and cannot resolve a symbolic layout. Uncheck Optimized block access on every DB used by the HMI; otherwise data access returns undefined values or triggers a Profibus diagnostic error.