Connecting Siemens V90 PN to S7-300 with STEP 7 V5.6 and FB283

David Krause15 min read
S7-300SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. System Overview and Hardware Topology

The classic S7-300 + SINAMICS V90 PN position-control architecture has no equivalent to the TIA Portal "SinaPos" FB284 library entry point that most engineers learn first. A CPU 317F-2DP cannot run FB284 because the block is part of the TIA Portal SinaPos / Motion Control library, which is compiled for S7-1200 and S7-1500 target systems only. The drop-in substitute for STEP 7 V5.x is FB283, supplied with the Siemens entry SINAMICS V90 PN: Communication with SIMATIC S7-300/400 on Siemens Industry Online Support. The block accepts the same telegrams and exposes the same I/O interface as FB284 once the matching UDT is loaded.

The reference hardware topology used throughout this document is:

  • 1 x S7-300 CPU 317F-2DP (6ES7317-6FF04-0AB0 or compatible firmware V3.x).
  • 1 x CP 343-1 Lean / CP 343-1 on slot 4 of the central rack. The CPU's integrated PN interface of the 317F-2DP is present but the F-CPU variants in many TIA replacement projects use the CP path for IO controller separation.
  • 1 x SINAMICS V90 PN (6SL3210-5FB10-xUAx, FW ≥ V1.04 for full telegram 111 support).
  • PROFINET cable, copper, Cat5e minimum, with the V90 PN port 1 → CP 343-1 port (line topology) or via an external switch.
S7-300 Station CPU 317F-2DP CP 343-1 PROFINET IO SINAMICS V90 PN PN Port 1 / Port 2 Telegram 111 Position Control (EPOS)

Configuration of the CP 343-1 within STEP 7 V5.6 follows the standard procedure documented in How To Configure S7-300/400 Connections in STEP 7; the CP is added in HW Config with its PROFINET interface enabled, and the V90 PN is dragged from the device catalog as a PROFINET IO device under the CP subnet.

2. Why FB283 (Not FB284) on STEP 7 V5.x

Engineers moving from TIA Portal to STEP 7 V5.6 expect to call FB284 "SINA_POS", but FB284 is not part of the STEP 7 V5.x standard library and cannot be retrofitted without recreating it as a stand-alone FC. The platform-native block on STEP 7 V5.x is:

Platform Function Block Library Source Target CPU
TIA Portal V14+ FB284 (SINA_POS) SinaPos V60 / V70 S7-1200 / S7-1500
STEP 7 V5.5 / V5.6 / V5.7 FB283 (SINA_POS) SinaPos STEP 7 V5.x entry 25166781 S7-300 / S7-400 / WinAC

FB283 implements the same PROFIdrive state machine and the same parameter channel (PKW) handling as FB284. The interface differs only in the names of a few input pins and the calling convention of ModePos. There is no functional loss when porting a TIA V15 motion routine to STEP 7 V5.6; the I/O mapping rules are identical.

Do not attempt to recompile FB284 for STEP 7 V5.x. The block uses SCL syntax (multi-instance arrays, slice access "dbName".STW1.%X10) that STEP 7 V5.6 KOP/FUP/AWL will reject. The supported workflow is to install the SinaPos V5.x package, drop FB283 into the S7 program, and write user logic around it.

3. Installing the V90 PN GSD and FB283 Library

  1. Download the latest SINAMICS V90 PN GSDML (file pattern GSDML-V2.3x-Siemens-Sinamics_V90_PN-xxxxxx.xml) from Siemens Product Support under entry 109745287 (V90 PN Operating Instructions, "GSD files" appendix).
  2. Close any running STEP 7 instances. From the Windows Start menu, run SIMATIC Manager → Options → Install GSD File and select the downloaded GSDML.
  3. Install the SinaPos STEP 7 V5.x archive (SinaPos_V5x_Vxxxx.zip) referenced inside entry 25166781 by opening it from STEP 7 → Options → Install Library / Function Block. The package installs FB283 plus the following UDTs in the standard library SinaPos_STEP7:
UDT Telegram Use Case
UDT1 1 Speed setpoint, 32-bit
UDT3 3 Speed + 2 encoder channels
UDT7 7 Basic positioner, 16-bit setpoint
UDT9 9 Basic positioner, 32-bit setpoint
UDT102 102 Speed + torque reduction
UDT105 105 Speed with DSC
UDT110 110 Basic positioner with MDI / DSC, 32-bit
UDT111 111 Position with DSC, 32-bit, encoder feedback ch1+ch2
UDT116 116 V90 PN with EPOS and torque data

For the V90 PN in position control with full DSC and encoder feedback the binding UDT is UDT111. UDT110 is acceptable if DSC is disabled, but most V90 PN applications use DSC to compensate dead-time in the position loop, so UDT111 is preferred.

4. PROFINET Network Configuration in STEP 7 V5.6

  1. Open the S7-300 station in HW Config, insert the CP 343-1 in slot 4, and create a PROFINET subnet with IP 192.168.0.1 / mask 255.255.255.0 on the CP.
  2. From the device catalog, expand PROFINET IO → Drives → SINAMICS → V90 PN, and drag the device onto the PROFINET subnet. Assign IP 192.168.0.10 and the device name v90pn.
  3. Open the slot configuration of the V90 PN. Insert the DO Standard Telegram 111 in slot 1 of the drive. The HW Config now displays the input and output address ranges (typical default 256..271 inputs and 256..271 outputs). Note these addresses — they become the LADDR of SFC14 / SFC15.
  4. Compile and download the HW Config. The drive should appear online in HW Config with a green check on every slot. If the V90 reports F30001 or F08501, the device name has not been assigned; use Target system → Ethernet → Assign device name to push v90pn onto the drive.

For CP 343-1 Lean (6GK7342-1) the maximum PROFINET IO slot count is 32; for CP 343-1 (6GK7343-1) it is 128. Either is sufficient for one V90 PN. Do not mix the CPU integrated PROFINET interface and the CP PROFINET subnet as two IO controllers on the same drive — the drive will only accept one AR.

5. Telegram 111 Structure for V90 PN Position Control

Telegram 111 is a 16-word cyclic frame (12 PZD + 4 PZD depending on encoder mapping) defined by PROFIdrive application class 4. The word layout, with the S7 byte order applied (low byte first, high byte second), is shown below. This mapping must match UDT111 exactly — a one-word shift in either direction will surface as fault F08501 in the drive.

Telegram 111 — Cyclic PZD Layout PLC → Drive (Outputs) PZD1 STW1 PZD2 NSOLL_B PZD3 STW2 PZD4 MOMRED PZD5 G1_STW PZD6 G2_STW PZD7 G3_STW Drive → PLC (Inputs) PZD1 ZSW1 PZD2 NIST_B PZD3 ZSW2 PZD4 MELDW PZD5 G1_ZSW PZD6 G2_ZSW PZD7 G3_ZSW Follow-up words for encoder feedback PZD8 G1_XIST1 PZD9 G1_XIST2 PZD10 spare Bit-10 trap: STW1 sits in DBW0 → low byte DBX0, high byte DBX1. Bit 10 = DBX1.2.

The default word count is 10 PZD (20 bytes per direction) for the V90 PN firmware that ships with telegram 111 enabled. The exact count is visible in V-ASSISTANT → Telegram configuration; it must equal the value passed into SFC14/15.

6. Building the I/O Interface DB and UDT Mapping

Create a shared data block (e.g. DB257) and declare its structure as a copy of UDT111. Open DB257 in Declaration view, type UDT111 in the Type column of the first line, and let the editor expand the full member tree:

DATA_BLOCK DB257
TITLE = 'V90 PN Interface for Telegram 111'
AUTHOR : AUTOMATION
VERSION : 0.1
  STRUCT
    STW1     : WORD;    // Control word 1, PZD1 output
    NSOLL_B  : DWORD;   // Position setpoint, PZD2..3
    STW2     : WORD;    // Control word 2, PZD4
    MOMRED   : WORD;    // Torque reduction, PZD5
    G1_STW   : WORD;    // Encoder 1 control word, PZD6
    G2_STW   : WORD;    // Encoder 2 control word, PZD7
    G3_STW   : WORD;    // Encoder 3 control word, PZD8
    ZSW1     : WORD;    // Status word 1, PZD1 input
    NIST_B   : DWORD;   // Position actual value, PZD2..3
    ZSW2     : WORD;    // Status word 2, PZD4
    MELDW    : WORD;    // Message word, PZD5
    G1_ZSW   : WORD;    // Encoder 1 status word, PZD6
    G2_ZSW   : WORD;    // Encoder 2 status word, PZD7
    G3_ZSW   : WORD;    // Encoder 3 status word, PZD8
    G1_XIST1 : DWORD;   // Encoder 1 actual pos 1, PZD9..10
    G1_XIST2 : DWORD;   // Encoder 1 actual pos 2, PZD11..12
  END_STRUCT;
END_DATA_BLOCK

The byte offsets generated automatically are critical for the SFC calls:

Member Offset (bytes) Type
STW1 0..1 WORD
NSOLL_B 2..5 DWORD
STW2 6..7 WORD
ZSW1 16..17 WORD
NIST_B 18..21 DWORD
ZSW2 22..23 WORD
Consistency warning: Because Telegram 111 spans 12 words (24 bytes) per direction, the DB must be at least 24 bytes per direction. STEP 7 will truncate it silently if too short, and the drive will display Cyclic data length mismatch. The standard practice is to size the DB to 32 bytes per direction for headroom.

7. Cyclic Data Exchange with SFC14 and SFC15

For the S7-300 + CP 343-1 path, PROFINET IO cyclic data is exchanged with SFC14 DPRD_DAT and SFC15 DPWR_DAT. These are mandatory — direct I/O area reads (PEW256) will not return consistent data across telegram boundaries, which leads to torn values in NIST_B (32-bit position).

Standard call pattern in OB1 / OB35:

CALL  SFC 14   // DPRD_DAT — read inputs from V90
      LADDR  := W#16#100       // base I address from HW Config (256 dec = 0x100)
      RET_VAL:= MW100          // any error code
      RECORD := P#DB257.DBX16 BYTE 24   // destination: ZSW1 region of DB257

CALL  SFC 15   // DPWR_DAT — write outputs to V90
      LADDR  := W#16#100       // base Q address from HW Config
      RECORD := P#DB257.DBX0  BYTE 24   // source: STW1 region of DB257
      RET_VAL:= MW102

The LADDR must match the base address in HW Config; with the default 256 the value is W#16#100. RET_VAL returns 0 on success, 0x8xxx on SFC-level fault, and 0xExxx on data-record fault. Common codes:

RET_VAL Cause Remedy
W#16#0000 No error —
W#16#8085 LADDR invalid (slot not configured) Verify HW Config slot assignment
W#16#80A1 Negative acknowledge, slot busy Re-download HW Config; check CP RUN
W#16#80A3 PROFINET IO AR down Check cable, device name, IP
W#16#80B0 Slot not configured Reinsert telegram 111 in slot 1
W#16#80B1 Record length mismatch Match RECORD length to telegram PZD count

8. PROFIdrive Control Word 1 Bit Map and the Bit 10 Trap

STW1 is the most error-prone word in the entire Telegram 111 frame. The bit assignments are fixed by the PROFIdrive profile and applied identically across SINAMICS G120, S120, V90, and S210:

Bit Name Meaning (when set)
0 ON / OFF1 Edge: 0 → 1 powers the drive on
1 OFF2 1 = no coast stop, 0 = coast to stop
2 OFF3 1 = no quick stop, 0 = quick stop
3 Enable operation 1 = enable inverter pulses
4 Enable ramp generator 1 = enable ramp (RFC only)
5 Unfreeze ramp 1 = continue ramp
6 Enable setpoint 1 = apply setpoint
7 Fault acknowledge 0→1 edge resets drive faults
8 Reserved / jog1 (vendor) Keep 0 on V90
9 Reserved / jog2 (vendor) Keep 0 on V90
10 Control by PLC 1 = PLC has authority, 0 = local/encoder
11 Reserved / direction reversal 0 on V90
12..15 Reserved 0

The two reference patterns used during commissioning are 16#047E (Switch-on disabled) and 16#047F (Switched on / Ready):

// STW1 = 16#047E (binary 0000 0100 0111 1110)
// Bit 10 set, OFF2 / OFF3 inactive, enable not armed
//  → drive transitions to "Switch-on disabled"
//
// STW1 = 16#047F (binary 0000 0100 0111 1111)
// Bit 0 added (ON / OFF1)
//  → drive transitions to "Switched on"
//
// Next state: 16#047F + bit 3 already set
//  → drive transitions to "Operation enabled"

8.1 The Bit-10 Addressing Trap

The most common failure during commissioning is correctly placing the value 16#047E into DBW0 (STW1) but failing to assert bit 10 because of byte-order confusion. The S7 word at DBW0 spans bytes DBX0 (low) and DBX1 (high):

DBW0 = 16#047E
  DBX0 (low byte)  = 16#7E = bits 0..7 = 0111 1110
  DBX1 (high byte) = 16#04 = bits 8..15 = 0000 0100

Bit 0  (ON/OFF1)    = DBX0.0
Bit 6  (En. setpt)  = DBX0.6
Bit 10 (PLC control)= DBX1.2    ← correct address
Bit 15              = DBX1.7

A common mistake is to write the bit as DB257.DBX0.2. That bit is bit 2 of the 16-bit value (the OFF3 line), not bit 10. With DB257.DBX0.2 unset, bit 10 of the word coming out of the DB stays 0, and the drive stays in Local control. The result: ZSW1 reports 0xEB31 (Operation enabled in status word, but bit 9 = control requested NOT met). The classic symptom is that the drive refuses every command, returns 0x0131 in ZSW1, and the run LED on V-ASSISTANT stays grey.

Correction snippet: Always toggle bit 10 with the high-byte address:
SET
= DB257.DBX1.2   // bit 10 of STW1 — PLC takes control
Never use DB257.DBX0.2 for the control-requested bit.

An equivalent safe path is to set the entire STW1 as a word and let SFC15 move it as a consistent block:

L   W#16#047F      // Operation enabled
T   DB257.DBW0     // STW1
// STW2 must contain bit 9 = 1 for DSC activation in telegram 111
L   W#16#0100
T   DB257.DBW6     // STW2

9. Step-by-Step Commissioning Sequence

  1. Wire PROFINET, power up the V90 PN, set the drive's node address via V-ASSISTANT or the BOP.
  2. Open SIMATIC Manager, load the project, double-click Hardware. Verify the V90 PN is reachable (online view, slot diagnostics green).
  3. Open V-ASSISTANT → Online → Telegram configuration and confirm Telegram 111 is selected with the same word count you set in HW Config.
  4. In the S7 project, create DB257 with the UDT111 structure from section 6.
  5. Insert SFC14 (read) and SFC15 (write) calls in OB1. Pass LADDR = W#16#100 and a 24-byte RECORD.
  6. Set DB257.DBW0 = W#16#047E and DB257.DBW6 = W#16#0000. Observe ZSW1 in DB257.DBW16 in VAT view.
  7. Toggle DB257.DBX1.2 to assert bit 10 (PLC control). Watch ZSW1 bit 9 come on.
  8. Sequence the standard PROFIdrive transitions: 047E → 047F → 047F (the third word is identical but the edge on bit 0 has already triggered). ZSW1 should walk through 0xC031 → 0xC237 → 0xC337.
  9. Insert a traversing block call: load a target position into DB257.DBD2 (NSOLL_B, increments of 1000 LU per V90 scaling) and trigger a relative jog from V-ASSISTANT or FB283.
  10. Monitor DB257.DBD18 (NIST_B) — the actual position should track the setpoint with the configured following-error window.
  11. Run a 10 000-pulse test move, log ZSW1/NIST_B to a data log, and confirm the loop is stable.

10. Troubleshooting Matrix

Symptom Likely Cause Diagnostic Fix
V90 LED "BF" solid red PROFINET physical layer down CP 343-1 diagnostics → port status Replace cable; verify port 1 on V90
V90 fault F08501 Telegram mismatch V-ASSISTANT → Telegram Match word count in DB / SFC to HW Config
V90 fault F30001 Device name not assigned HW Config online view Assign v90pn device name
ZSW1 stays 0x0131 STW1 bit 10 not set (PLC control not granted) Monitor DBX1.2 Set bit 10 in high byte of STW1
SFC15 RET_VAL = W#16#80B1 RECORD length ≠ telegram length Compare P#bytes to telegram Use 24 bytes for 12-PZD telegram 111
ZSW1 = 0xC331 but motor does not move STW2 DSC enable missing DB257.DBW6 = 0 Set DB257.DBW6 = W#16#0100 (bit 9 = DSC on)
Motor vibrates at high speed NSOLL_B scaling mismatch V-ASSISTANT axis config → LU/rev Match NSOLL_B units to p29247 / p29248
Frequent F07491 after motion Following error window too tight p2546 value Increase window or tune Kv (p29120)
CPU goes SF after CPU restart CP 343-1 not in RUN after reboot CP diagnostic buffer Power-cycle CP separately; check firmware ≥ V2.x
NIST_B increments in wrong direction Encoder polarity inverted Compare direction with EPOS reference Invert p29004 or swap phase in DB257.DBD2 sign

11. Verification and Acceptance Test

Before signing off, run a four-stage acceptance check and log every result to a CSV file. The four stages mirror the structure of the PROFIdrive state machine plus a motion step:

  1. Communication check. Cycle power on the drive; ZSW1 must reach 0x0131 within 2 s. Record SFC14/15 RET_VAL every 100 ms.
  2. Control-requested handshake. With STW1 = 0x047E, monitor ZSW1 bit 9 for transition 0 → 1 within 200 ms of setting DB257.DBX1.2.
  3. State walk. Send the sequence 047E → 047F → 047F and capture ZSW1 every 20 ms. Expected transitions 0xC031 → 0xC237 → 0xC337.
  4. Motion step. Write NSOLL_B = 100 000 LU, send STW1 = 0x4F7F (set jog bits). Monitor NIST_B, ZSW1 bit 10 (target reached), and following error over 5 s.

Record the captured curves to a project directory \project\commissioning\v90pn\acceptance\. Any deviation from the expected ZSW1 transitions indicates a state-machine deviation; fall back to section 10 before resuming.

Safety precondition: The drive must be in Safe Torque Off (STO) via the dedicated terminals during commissioning. PROFINET STO can be wired through the CP 343-1 F-capability or via PROFIsafe — confirm the STO source before energizing any axis.

Can I copy FB284 from a TIA Portal project and paste it into STEP 7 V5.6?

No. FB284 uses SCL syntax (slice access, multi-instance arrays) that the STEP 7 V5.6 compiler rejects. Use the STEP 7 V5.x SinaPos package and call FB283 with the matching UDT (UDT111 for Telegram 111).

Why does the drive ignore every command, even though ZSW1 reports "Operation enabled"?

Almost always bit 10 of STW1 is not set. The bit lives at DBX1.2 (high byte), not DBX0.2. Setting DB257.DBX0.2 only asserts OFF3, which is usually already 1 and tells the drive nothing new. Toggle DBX1.2 and the ZSW1 bit 9 (control requested) comes on within one PROFINET cycle.

Which SFC is correct for cyclic PROFINET IO with CP 343-1?

Use SFC14 (DPRD_DAT) to read consistent inputs and SFC15 (DPWR_DAT) to write consistent outputs. Direct I/O access (PEW / PAW) reads partial values and corrupts the 32-bit fields such as NIST_B and NSOLL_B. Pass LADDR = W#16#100 for the default address range 256..271.

What is the minimum V90 PN firmware for Telegram 111?

Firmware V1.04 supports Telegram 111. Earlier V1.00 firmware only supports Telegram 1 (speed control). Upgrade with V-ASSISTANT or a Siemens MMC card before commissioning.

Does the drive support encoder feedback in Telegram 111?

Yes. PZD8/9 carry G1_XIST1 (encoder 1 actual position 1) and G1_XIST2 (encoder 1 actual position 2). The corresponding UDT111 members G1_XIST1 and G1_XIST2 in DB257 are populated automatically by SFC14. Use G1_XIST1 for the position loop and G1_XIST2 for diagnostics or dual-channel verification.

Back to blog