Extending S7-1200 I/O Modules PROFINET and PROFIBUS Remote

David Krause11 min read
S7-1200SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Definition: Separating S7-1200 CPU from I/O Modules

When a control cabinet is physically too small to host both an S7-1200 CPU and its expansion modules (SM 1221 DI, SM 1222 DQ, SM 1231 AI, SM 1232 AQ, SM 1234 AI/AQ), the engineer must relocate the I/O away from the CPU while preserving deterministic, real-time communication. The original query is unambiguous: keep the CPU inside the operator console and place the SM signal modules near the field devices to shorten analog wiring runs and reduce noise pickup.

The S7-1200 system was designed for a compact, single-row architecture. There is no official Siemens bus extension cable that allows the standard local I/O backplane to span more than approximately 2 meters. Any attempt to extend the proprietary backplane ribbon beyond that distance is unsupported and may fail EMC and timing tests. The practical answer is to abandon the local I/O bus and migrate to a fieldbus-distributed topology.

2. S7-1200 Local I/O Backplane Limits

The S7-1200 communication bus between the CPU and SM/CM/CP modules uses a proprietary side-connector ribbon. According to the S7-1200 Programmable Controller System Manual (06/2021 edition):

  • Maximum 1 signal module (SM) per CPU row in compact configurations.
  • CPU 1211C: 0 SMs (no local expansion).
  • CPU 1212C: up to 2 SMs.
  • CPU 1214C: up to 8 SMs.
  • CPU 1215C / 1217C: up to 8 SMs plus 3 CM/CP modules.
  • Maximum physical row length: limited by the 1 m dual-pin ribbon that ships with each SM. Total mechanical stretch must remain below 2 m of cumulative ribbon length to keep the integrated logic within timing budget.
Note: Siemens does not publish a 5 m, 10 m, or longer S7-1200 backplane ribbon as a catalog part number. Any custom ribbon assembly constructed from third-party connectors is not warranted and will fail in environments with high electrical noise or vibration.

3. Solution Matrix: Three Architectures for Remote I/O

The following table summarizes the three proven architectures available on the S7-1200 platform. Selection depends on existing hardware, required update time, and cable distance.

Architecture Required Hardware Max Distance Min TIA Portal Update Time
I-Device (2nd S7-1200) 2x CPU 1212C/1214C/1215C + 1x PROFINET port per CPU 100 m (copper) V13 SP1 1–32 ms
ET200S over PROFINET IM151-3 PN + ET200S modules 100 m V11 SP2 1–32 ms
ET200SP over PROFINET IM155-6 PN + BaseUnit + ET200SP modules 100 m (copper), 3 km (fiber via BFOC) V13 SP1 0.25–32 ms
ET200S over PROFIBUS CPU + CM 1243-5 (master) + IM151-1 (slave) 1.2 km at 9.6 kbps; 100 m at 12 Mbps V11 1–10 ms
ET200SP over PROFIBUS CM 1243-5 + IM155-6 DP 1.2 km V13 SP1 1–10 ms

4. Solution 1: I-Device (Second S7-1200 as Remote I/O)

The I-Device (intelligent IO-Device) configuration turns a slave S7-1200 into a distributed I/O station while exposing its process data to the master S7-1200 through a defined PROFINET interface. TIA Portal V13 SP1 or higher is required.

Hardware required

  • Master CPU: any S7-1200 firmware V4.0+ with on-board PROFINET port.
  • I-Device CPU: any S7-1200 (1212C/1214C/1215C/1217C), firmware V4.1+ recommended.
  • PROFINET cable: Siemens IE FC TP Standard Cable (6XV1840-2AH10) or IE FC TP Trailing Cable (6XV1870-2B) for moving installations.
  • RJ45 connectors: IE FC RJ45 Plug 180 (6GK1901-1BB10-2AA0), 4-core.

Configuration procedure

  1. Insert the I-Device CPU in the TIA Portal project, add the required SM signal modules.
  2. In the I-Device CPU device configuration, open Properties → PROFINET interface → Operating mode and select IO Device.
  3. Configure the transfer areas: define input and output slots for the PROFINET interface. Each slot can hold up to 244 bytes of input data and 244 bytes of output data.
  4. Compile the I-Device project and export the GSD file of the I-Device.
  5. In the master CPU project, install the GSD under Options → Manage device description files (GSD).
  6. Drag the I-Device from the catalog onto the master PROFINET subnet, assign device name and IP address.
  7. Download both projects and verify the device name assignment through PRONETA or the master CPU online diagnostics.
Tip: Use Siemens PRONETA (free tool) to scan the network, assign PROFINET device names, and verify topology before commissioning.

5. Solution 2: ET200S over PROFINET

The ET200S family uses an interface module (IM) that hosts standard ST or HS plug-in I/O modules. With firmware V11 SP2 and a CPU 1215C, the IM151-3 PN can be added directly through the catalog. The IM151-3 PN (6ES7151-3BA23-0AB0) supports up to 63 I/O modules and exposes the standard PROFINET diagnostics.

Maximum topology

  • Copper (100BASE-TX): 100 m segment length between two devices.
  • Fiber (100BASE-FX) using IE FC Media Converter: up to 3 km.
  • Maximum of 255 devices per subnet, 8 stations in a line topology.

Configuration follows the standard PROFINET device-installation workflow. The IM151-3 PN GSD file is part of TIA Portal V11 SP2 HSP0080 or higher.

6. Solution 3: ET200SP over PROFINET (Recommended for New Designs)

The ET200SP is the current generation of distributed I/O. The interface module IM155-6 PN (6ES7155-6AU01-0BN0 or newer -6BA01) combined with BaseUnit type A0/B0 provides a compact, hot-swappable I/O rack that can be expanded up to 32 or 64 modules depending on variant.

Interface Module Order Number Max I/O Modules PROFINET Ports Update Time
IM155-6 PN ST 6ES7155-6AU01-0BN0 32 2 (switched) 1 ms minimum
IM155-6 PN HF 6ES7155-6BA01-0BN0 64 2 (switched, MRP) 0.25 ms minimum
IM155-6 PN HS 6ES7155-6AU30-0BN0 32 2 0.125 ms minimum
IM155-6 DP HF (PROFIBUS) 6ES7155-6BU01-0BN0 32 n/a (DP) 1 ms minimum

The HF variants support Media Redundancy Protocol (MRP) for ring topologies, which is critical in motion or high-availability applications.

7. Solution 4: PROFIBUS DP with CM 1243-5

If the installation already has a PROFIBUS infrastructure or the distance exceeds 100 m and copper PROFINET is not feasible, the CM 1243-5 (6GK7243-5DX30-0XE0) can be installed on the S7-1200 to act as a PROFIBUS DP master. The CM 1243-5 sits in the leftmost CM/CP slot of the CPU row.

Configuration parameters

  • Baud rate: 9.6 kbps to 12 Mbps.
  • Maximum PROFIBUS segment length depends on baud rate: 1200 m at 9.6 kbps / 187.5 kbps; 400 m at 500 kbps; 200 m at 1.5 Mbps; 100 m at 3 Mbps / 6 Mbps / 12 Mbps.
  • Maximum stations per segment: 32 (including repeaters), 126 total per PROFIBUS network.
  • Connector: PROFIBUS connector with 35° cable outlet (6ES7972-0BA52-0XA0) or 90° outlet.
  • Termination: switch ON at both physical ends of the segment, OFF at intermediate stations.

On the ET200S side use IM151-1 (6ES7151-1BA02-0AB0) for standard DP or IM151-1 HF (6ES7151-1CA00-0AB0) for high-feature. On the ET200SP side use IM155-6 DP HF.

8. Cable, Connector, and Distance Reference

Bus Cable Type Order Number Max Segment Connector
PROFINET Cu IE FC TP Standard 6XV1840-2AH10 100 m IE FC RJ45 Plug 180 (6GK1901-1BB10-2AA0)
PROFINET Trailing IE FC TP Trailing 6XV1870-2B 85 m IE FC RJ45 Plug 180
PROFINET Fiber (POF) IE POF Standard 6XV2001-1A 50 m SC RJ45 POF Plug (6GK1901-0LB01-0AA0)
PROFINET Fiber (HCS) IE HCS 6XV2001-1C 100 m SC RJ45 HCS Plug
PROFINET Fiber (Glass) IE FC Glass 6XV2001-1G 3000 m (multimode) BFOC connector
PROFIBUS PROFIBUS FC Standard 6XV1830-0EH10 per baud rate PROFIBUS connector (6ES7972-0BA52)
Important: PROFINET copper cable total length between two devices must remain ≤ 100 m regardless of baud rate (100 Mbps fixed). For distances of 10 m or less, a generic CAT5e/CAT6 patch cable is acceptable; for industrial environments use only IE FC TP cables.

9. TIA Portal Configuration: Step-by-Step

The example below uses an S7-1215C master CPU (192.168.0.1) and an ET200SP HF station (192.168.0.2) on PROFINET.

  1. Open TIA Portal V16 or higher and create a new project.
  2. Insert a CPU 1215C DC/DC/DC (6ES7215-1AG40-0XB0). Add the rack-mounted CM 1243-5 only if PROFIBUS is required.
  3. Open Devices & Networks, drag an IM155-6 PN HF from the catalog to the PROFINET subnet.
  4. Connect the master CPU port to the IM155-6 PN HF port with a drag line.
  5. Assign IP addresses: master 192.168.0.1 / 255.255.255.0, ET200SP 192.168.0.2 / 255.255.255.0.
  6. Assign a PROFINET device name: et200sp-station1. Note: PROFINET device name is mandatory; IP alone is insufficient.
  7. Insert ET200SP modules into the IM155-6 HF station: DQ 16x24VDC/0.5A (6ES7132-6BH01-0BA0), DI 16x24VDC (6ES7131-6BH01-0BA0), AI 4xU/I/RTD (6ES7134-6HD01-0BA1), AQ 2xU/I (6ES7135-6HB00-0CA1).
  8. Configure IO cycle: in PROFINET interface → Real-time settings → IO cycle time, set 1.0 ms for HF stations, 4.0 ms for ST.
  9. Assign symbolic IO tags in the master program: "ET200SP".DI16_1.IW0, etc.
  10. Compile, download to CPU, and use Online & Diagnostics → PROFINET device name assignment for the ET200SP.

10. Verification and Commissioning

After download, perform the following verification sequence:

  1. In Online & Diagnostics → Diagnostics, confirm the ET200SP shows Station OK and no diagnostic interrupts.
  2. Use PRONETA or Topology Editor to confirm the cable plant. Verify that the PROFINET device name matches the configuration.
  3. Force a sample input: monitor %IW0 on the master CPU and toggle a field input. Confirm the value updates within one PROFINET update cycle.
  4. Write a sample output: set %QW0 and confirm the field device energizes within one PROFINET update cycle.
  5. Check bus load with Wireshark or PRONETA: PROFINET bus load should remain below 50% under normal operation. If it exceeds 70%, increase the update time.
  6. Verify EMC: confirm shield bonding at both ends of the PROFINET cable through the IE FC RJ45 Plug's shield clamp.

11. Troubleshooting Matrix

Symptom Likely Cause Diagnostic Step Corrective Action
ET200SP shows "Station Failure" PROFINET device name mismatch Compare assigned name in TIA Portal vs. PRONETA Reassign name with PRONETA or download device name
Diagnostic interrupt "Channel Fault" Wire break, overload, or missing BaseUnit Open online diagnostics on the module Re-pull wire, replace module, ensure correct BU type
Intermittent communication dropouts Total PROFINET cable > 100 m, or cable routed next to VFD Measure cable length with TDR or count connectors Insert IE FC Media Converter and switch to fiber
No I/O update after CPU restart IP address OK but device name not assigned Check PROFINET diagnostics buffer Assign device name through the CPU's online tools
PROFIBUS station appears but data is FFh Wrong GSD version or DP slave not configured Compare HW revision with TIA Portal device list Update GSD, recompile, redownload
SF LED lit on IM155-6 PN HF Configuration error or low supply voltage Read diagnostic buffer, measure 24V at BaseUnit Verify CPU power budget ≥ ET200SP load
Update time too long for motion axis ST IM used instead of HF, or too many devices Open Real-time settings Switch to IM155-6 PN HF, reduce send clock

12. Choosing the Right Architecture

Pick I-Device (2nd S7-1200) when the user already owns two S7-1200 CPUs and wants a low-cost, fast-commissioning solution with PROFINET at 100 m. It is the closest equivalent to keeping the original "single PLC" feel because both controllers run TIA Portal projects.

Pick ET200SP over PROFINET for any new design. It is the current Siemens generation, has the highest density per mm of DIN rail, supports hot-swap, and offers HF variants with sub-millisecond update times. HF modules also support MRP rings, which is mandatory in many modern automotive and packaging lines.

Pick ET200S over PROFINET only if the cabinet already has ET200S ST or HS modules that must be retained. ET200S is in phase-out.

Pick PROFIBUS with CM 1243-5 when the plant already has PROFIBUS infrastructure, the distance is between 100 m and 1.2 km, or when the installation environment is so electrically noisy that copper PROFINET is impractical without fiber converters. The CM 1243-5 supports up to 16 PROFIBUS slaves in the S7-1200 master configuration.

13. Field-Proven Caveats

  • PROFINET requires a device name in addition to an IP address. Forgetting the device name is the single most common reason an ET200 station shows "Station Failure" even when the IP is correct.
  • The IE FC RJ45 Plug must be crimped with the Siemens IE FC Stripping Tool (6GK1901-1GA00). Standard RJ45 crimps will damage the cable geometry and degrade return loss.
  • The shield of PROFINET copper cable must be bonded at both ends through the connector shield clamp, not at a single point. Failure to bond both ends is the most common cause of EMC-related diagnostic interrupts.
  • The CM 1243-5 occupies a CM/CP slot. On a CPU 1215C you have three slots; on a CPU 1214C you have only one. Plan accordingly.
  • Update time must be ≥ 4× the send clock. TIA Portal will reject update times below the bus cycle limit.

Can I extend an S7-1200 local I/O bus with a longer ribbon cable to 10 m?

No. Siemens does not sell a 10 m backplane ribbon for the S7-1200. The proprietary side-connector ribbon must remain under 2 m total mechanical stretch. To move I/O 10 m away, use PROFINET (100 m) or PROFIBUS (up to 1.2 km) instead.

Which is the cheapest way to add remote I/O to an S7-1200?

Use a second S7-1200 CPU as an I-Device over PROFINET. No additional master module is required because both CPUs have on-board PROFINET ports. TIA Portal V13 SP1 or higher is needed to configure the I-Device transfer areas.

What is the maximum PROFINET cable distance between an S7-1200 and an ET200SP?

100 m with copper IE FC TP Standard Cable (6XV1840-2AH10). For longer distances, use an IE FC Media Converter or SC RJ45 POF/HCS fiber cables, which extend to 50 m (POF), 100 m (HCS), or 3 km (multimode glass) per segment.

Do I need a CM 1243-5 to use PROFIBUS on an S7-1200?

Yes. The on-board PROFINET port cannot be switched to PROFIBUS. The CM 1243-5 (6GK7243-5DX30-0XE0) plugs into the leftmost CM/CP slot and acts as a DP master for up to 16 slaves.

Why does my ET200SP station show "Station Failure" even though the IP address is correct?

PROFINET uses both an IP address and a device name. The IP is only used for engineering access; the device name is what the master uses for cyclic data exchange. Assign the device name using PRONETA or TIA Portal's online & diagnostics tools, then the station will go to "Station OK".

Back to blog