Designing a 300-Node PROFIBUS Network with S7-300 and CP 342-5

David Krause14 min read
ProfibusSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Designing a 300-Node PROFIBUS Network with S7-300 and CP 342-5

A single PROFIBUS-DP segment is electrically limited to 32 nodes and the PROFIBUS standard caps any single bus at a maximum of 126 stations (address 0–125, with one slot reserved for the master). Hitting 300 slaves on one cable is therefore not a configuration problem you can solve by adding a different master — it is a topology problem you solve with multiple DP networks tied to a single S7-300 station. This reference walks through the architecture, hardware, segment math, TIA Portal configuration, and DP_SEND/DP_RECV programming required to build a 300-node PROFIBUS installation.

1. PROFIBUS Node Limits: Why 300 on One Cable Is Impossible

PROFIBUS-DP is built on RS-485. The physical layer of RS-485 places hard ceilings on every segment, and the PROFIBUS specification inherits those ceilings without exception.

PROFIBUS-DP segment and network limits per IEC 61158 / IEC 61784
Parameter Limit Reason
Nodes per electrical segment (no repeater) 32 RS-485 driver load (32 unit loads per segment)
Nodes per logical DP network 126 (0–125, but practical max 125 with HSA = 126) 7-bit PROFIBUS address field, address 126 reserved for broadcast
Repeaters cascaded in series 9 maximum between any two stations Signal jitter and token rotation timing budget
Segment length @ 1.5 Mbps 200 m RS-485 attenuation budget
Segment length @ 12 Mbps 100 m RS-485 attenuation budget
Baud rates supported 9.6 kbps to 12 Mbps Siemens S7-300 DP ports default to 1.5 Mbps

Address 126 is reserved as the global broadcast address; in practice that means a single DP network tops out at 125 usable slaves. To reach 300 slaves you must split the installation into a minimum of three logical PROFIBUS networks, each terminating at its own DP master. The good news: a single S7-300 CPU can host all three masters if you bolt on the right communication processors.

Field-proven rule: When sizing a DP network, leave the master address gap of 5–10 unused nodes below HSA so that future replacements (same model, same GSD) do not require a global address renumbering.

2. System Architecture for 300 Slaves

The recommended partition for 300 DP slaves is three DP networks, each carrying 100 slaves. This keeps every network under 125 stations, gives the operator meaningful engineering granularity (one production cell = one DP subnet), and minimizes the blast radius of a single cable fault.

Reference 300-node architecture
Network Master device on S7-300 backplane Slaves Repeaters Suggested baud
DP-Network_1 (Cell A) CPU 315-2 DP integrated port 100 4 (3 active + 1 terminating) 1.5 Mbps
DP-Network_2 (Cell B) CP 342-5 (6GK7 342-5DA02-0XE0) in slot 4 100 4 1.5 Mbps
DP-Network_3 (Cell C) CP 342-5 (6GK7 342-5DA02-0XE0) in slot 5 100 4 1.5 Mbps

Each network uses 4 repeaters to break the 100 slaves into 4 segments of 25 slaves (well under the 32-node electrical limit). The terminating repeater on the last segment also serves as the active bus terminator, eliminating the need for a separate termination resistor block at the very end of the cable.

2.1 Address Space Layout

PROFIBUS addresses are unique per network — not globally across the plant. You can therefore reuse address 3 in all three networks without collision, as long as the GSD file and slot configuration for that slave are identical.

Recommended address plan (HSA = 125 in all three subnets)
Subnet Master address Slave address range HSA Free gap
DP-Network_1 2 3–102 (100 slaves) 125 23 addresses (103–125)
DP-Network_2 2 3–102 (100 slaves) 125 23 addresses
DP-Network_3 2 3–102 (100 slaves) 125 23 addresses

Note that for the CP 342-5, address 2 is the recommended master default; the integrated CPU 315-2DP port also defaults to 2. Keeping the master address identical across all three subnets simplifies the GSD library and the operator HMI diagnostics.

3. Hardware Selection and Bill of Materials

Required hardware for a 300-node PROFIBUS installation
Component Siemens part number Quantity Function
CPU 315-2 DP 6ES7 315-2AH14-0AB0 (Firmware V3.3) 1 Master for DP-Network_1; PROFIBUS integrated port
CP 342-5 communications processor 6GK7 342-5DA02-0XE0 (FW V5.x) 2 Masters for DP-Network_2 and DP-Network_3
PROFIBUS Repeater 6GK1 500-0AB10 (RS-485 Repeater, diagnostic) 12 3 repeaters per network, 1 of which is the active terminator
PROFIBUS cable 6XV1 830-0EH10 (violet, fast-connect) Per plant layout Bus medium, RS-485 twisted pair
PROFIBUS connectors 6ES7 972-0BA52-0XA0 (90° with PG port) 1 per slave + spares Node termination and connection
Active RS-485 terminator 6ES7 972-0DA00-0AA0 3 (one per network) Last-segment termination with 24 V supervision
24 V power supply 6EP1 334-3BA10 (PS 305) 1 Backplane and CP power
SIMATIC MMC 6ES7 953-8LF20-0AA0 (8 MB) 1 Program and configuration storage for CPU 315-2DP
Connector rule: Every PROFIBUS segment needs termination ON at exactly two points: the physical first and physical last nodes (or the first repeater and the last repeater/terminator). All intermediate connectors must have termination OFF. Mis-terminating a single node is the single most common cause of intermittent bus faults in installations of this size.

4. TIA Portal Network Configuration

Configure all three subnets in the Devices & Networks editor of TIA Portal V17 (or V18/V19/V20 — the steps are identical). Start with the CPU 315-2DP integrated port, then add the two CP 342-5 modules.

4.1 Subnet Properties

  1. Open the project, then double-click Devices & Networks.
  2. Select the CPU 315-2DP port DP (X2) and choose Add new subnet → name it DP-Network_1.
  3. For each CP 342-5 in slot 4 and slot 5, select its DP port and create DP-Network_2 and DP-Network_3. The CPs and the CPU port must NOT share a single subnet.
  4. Open Properties > PROFIBUS interface > Address on every master:
    • Address: 2
    • Highest station address (HSA): 125
    • Transmission speed: 1.5 Mbps
    • Profile: DP

Per Siemens' TIA Portal V20 PROFIBUS line configuration guide, a maximum of 125 nodes are possible on the bus (No. 0 to 124). If the HSA is set to a value less than or equal to 125, addresses equal to or greater than the HSA are not used during the token rotation; the bus master skips them entirely. Always set HSA to the highest address you will ever use, then leave a safety gap.

4.2 Importing Slave GSD Files

  1. Download the GSD file for every slave type (ET200S, ET200MP, frequency inverter, valve island, etc.) from the manufacturer site.
  2. In TIA Portal: Options > Manage general station description files (GSD) → install the GSD.
  3. Drag the slave from the hardware catalog into the subnet, then assign it a unique address in the range 3–102 (100 slaves per subnet).
  4. Configure the slot-level I/O on each slave (input bytes, output bytes, diagnostic slot).

5. Programming the CP 342-5 as a DP Master

The integrated DP port of a CPU 315-2DP exposes its peripheral I/O directly in the process image — you read inputs with IW x and write outputs with QW x. The CP 342-5 does not. Data between the CPU user program and the CP 342-5 is exchanged over the S7-300 backplane using two function blocks: DP_SEND (CPU → CP → slaves) and DP_RECV (slaves → CP → CPU). The official Siemens reference for the integrated DP port vs. CP 342-5 DP port is Entry ID 21628388.

5.1 FC Declarations

Per-CP I/O layout (DP-Network_2 example, 100 slaves, mixed I/O)
Symbol Type Length Description
SEND_DATA_CP2 BYTE 256 Output image written by CPU, sent by CP
RECV_DATA_CP2 BYTE 256 Input image received by CP, read by CPU
DP_SEND_OK_CP2 BOOL 1 Last DP_SEND completed without error
DP_RECV_OK_CP2 BOOL 1 New data available from DP_RECV
DP_ERROR_CP2 WORD 1 CP 342-5 diagnostic word (DPRAM fault code)

5.2 OB1 Cyclic Block (SCL / Structured Text)

// OB1 - Cyclic main
// CP 342-5 in slot 4 = DP-Network_2 (100 slaves)

// 1. Always call DP_RECV first to refresh RECV_DATA_CP2
DP_RECV(
    CPLADDR     := 256,                  // Base address of CP 342-5 in slot 4 (typical W#16#100)
    RECV        := RECV_DATA_CP2,        // 256-byte input buffer
    NDR         := DP_RECV_OK_CP2,       // New data received
    ERROR       := DP_ERROR_CP2,         // 16-bit error word
    STATUS      := DP_STATUS_CP2         // 16-bit status word
);

// 2. User logic writes the output image
SEND_DATA_CP2[0]  := SHL(BYTE#16#01, motor_run_cmd_bit);   // example
// ... (rest of your 256 bytes of output image)

// 3. Push output image to CP, which then broadcasts on DP
DP_SEND(
    CPLADDR     := 256,
    SEND        := SEND_DATA_CP2,
    DONE        := DP_SEND_OK_CP2,
    ERROR       := DP_ERROR_CP2,
    STATUS      := DP_STATUS_CP2
);

The second CP 342-5 in slot 5 uses its own base address (e.g. W#16#108) and its own SEND/RECV buffers. The same two FBs are called twice per OB1 cycle. Detailed configuration steps for the CP 342-5 as a DP master are in Siemens Entry ID 109744374.

5.3 DP_SEND/DP_RECV Error Code Reference

Common DP_ERROR and DP_STATUS values on CP 342-5
STATUS (hex) Meaning Field action
0000 No error None
0A0A CP in STOP / not configured Check HW config, download to CP
0E0E Timeout on DPRAM access Backplane fault — reseat CP, check IM360/IM361
8181 DP slave diagnostic pending Read slave diagnostic with DP_DIAG, check GSD mismatch
8183 DP slave not reachable / not responding Check address, cable, repeater power, termination
8184 DP slave configuration mismatch Re-import GSD, check slot count vs. physical module
8185 DP slave parameterization error Slave rejected parameter telegram — verify GSD revision
8186 DP slave in CLEAR state, no process data Master is holding the slave in clear, or slave is reporting diagnostic
8187 DP watchdog expired Cable break or slave power off; check segment

6. Segment Length and Repeater Math

PROFIBUS segment length is baud-rate dependent. Use the table below to size your violet cable runs.

<>600 m
PROFIBUS segment length vs. baud rate (per IEC 61158)
Baud rate Max segment length (Type A cable) Max segment length (Type B)
9.6 kbps 1200 m 1200 m
19.2 kbps 1200 m 1200 m
93.75 kbps 1200 m 1200 m
187.5 kbps 1000 m
500 kbps 400 m 200 m
1.5 Mbps 200 m 70 m
3 Mbps 100 m —
6 Mbps 100 m —
12 Mbps 100 m —

For a 100-slave, 4-segment network at 1.5 Mbps, the maximum trunk distance is 4 × 200 m = 800 m from master to last slave, plus the drop-cable length per slave (typically < 0.5 m, must be kept short at >1.5 Mbps). If your plant exceeds 800 m total, drop one or more segments to 500 kbps (1600 m) or add a second-tier repeatered branch.

You may cascade up to 9 repeaters between any two stations. With 4 repeaters per network, 100 slaves, and 1.5 Mbps, you stay comfortably inside the token rotation timing budget (Ttr = 10,000 bit times at 1.5 Mbps ≈ 6.7 ms; a 100-slave token round fits in < 2 ms in practice).

7. Diagnostics and Verification

Once the system is wired and programmed, follow this verification sequence before handing the line to operations.

7.1 Power-Up Verification (per network)

  1. Power on repeaters in order from master outward; verify green PWR LED on each.
  2. Set the bus terminator ON at the first and last node only. Use a 9 V battery test: voltage between pins 5 and 6 of the first PROFIBUS connector should read ~5 V if termination is active.
  3. Switch CPU to RUN. SF (red) and BF (red, bus fault) LEDs on the master should extinguish within 5 seconds.
  4. Open TIA Portal Online & Diagnostics > PROFIBUS > Station Status — all 100 slaves should report Data Exchange.

7.2 Token Rotation Time Check

Use the master diagnostic buffer to read Trdy_actual (real token rotation time). For 100 slaves at 1.5 Mbps, Trdy_actual should be < 5 ms; values approaching 10 ms indicate an address gap (HSA too high) or a faulty repeater. Tighten HSA from 125 down to 110 to recover margin.

7.3 Cycle Time Test

Insert a TON timer in OB1 around the DP_SEND call. A healthy 100-slave network at 1.5 Mbps typically completes one full DP cycle in 3–8 ms. Sustained values > 15 ms require either a baud-rate drop (to 500 kbps) or network partition.

8. Troubleshooting Matrix

Field troubleshooting for 300-node installations
Symptom Likely root cause Diagnostic step Fix
BF LED on master, all slaves offline Cable break or termination missing Disconnect at master, measure 220 Ω across A–B; should read 110 Ω with both ends terminated Enable termination on end nodes; replace damaged cable
Random slaves drop and rejoin EMI or improper shield bonding Check shield clamp at every cable entry, verify 360° bonding Re-bond shields at cabinet entries; separate PROFIBUS from VFD power by > 200 mm
One segment of 25 slaves all show 8183 Repeater power loss or address clash Check repeater LEDs, scan with BT200/BT300 Restore 24 V, verify no two slaves share an address
DP_ERROR_CP2 toggles 8184 GSD revision mismatch after firmware update on a slave Compare slot count in TIA config vs. physical module Re-import matching GSD, re-download HW config
Trdy_actual drifts up over 24 h EMI from a VFD on shared tray Run BT200 scan during VFD ramp Use fiber-optic PROFIBUS OLM for VFD-adjacent segments
CP 342-5 unreachable after firmware update CP 342-5 firmware < V3.0 not compatible with newer S7-300 CPU FW Check IM/CP FW matrix Update CP 342-5 FW to V5.x via SIMATIC Manager
OB1 cycle time exceeds 50 ms DP_SEND/DP_RECV blocks too long, or backplane overloaded Cross-check STATUS, monitor OB1 runtime in PG Split I/O into two CP 342-5 modules; use DP cycle synchronization

9. Practical Commissioning Checklist

  1. Build one subnet at a time: commission DP-Network_1 with the integrated port first, then add DP-Network_2, then DP-Network_3.
  2. Lock the addresses physically: write the PROFIBUS address on the housing of every slave (vinyl label or paint pen). Address re-numbering during a hot fault is the #1 cause of 4 a.m. callbacks.
  3. Document the GSD file version used per slave type in the project comments. GSD drift is the second-biggest source of late-stage surprises.
  4. Configure DP cycle synchronization in the CPU properties to lock the DP cycle to the OB1 cycle — eliminates jitter when the OB1 time slice and the DP token pass overlap.
  5. Use a PROFIBUS diagnostic repeater (6GK1 500-0AB10) on at least one segment — it stores the last 100 bus events and identifies the segment at fault, which is invaluable when 300 nodes are spread across the plant.
  6. Train the maintenance crew on address-based diagnostic: teach them that a slave on DP-Network_2 address 17 is the same physical sensor as the one previously on DP-Network_1 address 17 only if the GSD matches — a network swap can mask itself as a hardware fault.
  7. Validate spare-parts strategy: keep one of every slave SKU on the shelf pre-addressed to its spare address (e.g. 110, 111, 112, 113, 114, 115 in every network) so a hot swap doesn't require a PG.

10. When to Use a Different Architecture

300 nodes is also a tipping point. Once the panel build exceeds 6 repeaters per network, consider:

  • PROFINET: replace DP entirely. A single S7-300 with CP 343-1 handles hundreds of PROFINET devices with no segment math, no termination, and standard Ethernet cabling. Migration path: keep the same PLC, swap the CPs.
  • PROFIBUS over fiber (OLM): use 6GK1 502-1/3/4 OLM modules to convert DP copper to fiber for plant-spanning runs > 800 m. Each OLM counts as a repeater in the cascaded chain (max 9 between any two stations).
  • Distributed intelligence: drop an ET200S with IM151-8 PN/DP coupler as a sub-master — it aggregates 12 PROFIBUS slaves onto one PROFINET node, flattening the topology and reducing the number of DP masters you need to host in the S7-300.

FAQ

Can I really not have 300 slaves on a single PROFIBUS network?

No. The PROFIBUS standard caps any single DP network at 126 addresses (0–125), with 126 reserved for broadcast — giving a practical maximum of 125 slaves. The RS-485 electrical layer further limits each segment to 32 nodes. You must split 300 slaves across at least three DP subnets, each driven by its own master.

What is the difference between the integrated DP port on a CPU 315-2DP and a CP 342-5?

The integrated port exchanges I/O directly with the CPU process image, so you read inputs and write outputs like any other S7-300 I/O. The CP 342-5 has no direct process image — data is moved between the CPU and the CP via the backplane using the DP_SEND and DP_RECV function blocks. See Siemens Entry ID 21628388 for the official comparison.

What does HSA (Highest Station Address) do, and what value should I set?

HSA tells the master the highest address it must poll during token rotation. Setting it to the highest address you will actually use (typically 125) keeps the master from wasting time polling empty address slots. Always leave a 5–10 address gap below HSA for future additions, and reference the TIA Portal line configuration guide for the version you are using (V20 documentation is at the Siemens TIA Portal V20 cloud docs).

How many repeaters do I need per subnet for 100 slaves?

At least 4 repeaters per 100-slave subnet — three to break the 100 nodes into 4 segments of 25 slaves (under the 32-node RS-485 limit), and the fourth repeater on the last segment to act as the active bus terminator. You can cascade up to 9 repeaters in series between any two stations, so headroom exists for longer runs.

Which baud rate should I use for a 300-node installation?

1.5 Mbps is the standard choice for S7-300 DP networks, giving 200 m segments and a token rotation time well under the 10 ms budget for 100 slaves per subnet. If a segment must exceed 200 m, drop to 500 kbps (400 m segments). Avoid 12 Mbps unless the entire 100-slave network fits in a single cabinet within 100 m total length — at that speed, even a 1 m drop cable can cause reflections.

Back to blog