Identifying PROFIBUS FDL vs FMS on Siemens S5 CP5430/CP5431

David Krause14 min read
ProfibusSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Identifying PROFIBUS FDL vs FMS on Siemens S5 CP5430/CP5431

Engineers maintaining legacy SIMATIC S5 installations frequently face an undocumented PROFIBUS network: the original project files are missing, the configuration tool floppy disks are lost, and the only available evidence is the communication processor (CP) seated in the S5-115U, S5-135U, or S5-155U rack. The central question becomes: Is this PROFIBUS segment running FDL (Fieldbus Data Link, layer 2), FMS (Fieldbus Message Specification, layer 7), or PROFIBUS-DP (Decentralised Periphery)? The answer is recoverable from the CP order number, the CP firmware version, and the configuration database inside SINEC NCM or the legacy COM5430/COM5431 commissioning tools. This reference documents the deterministic procedure for answering that question, including the SAP/service mappings, hardware order numbers, and migration paths to STEP 7 / TIA Portal.

1. S5 PROFIBUS Architecture Overview

The SIMATIC S5 family never integrated PROFIBUS into the CPU itself in the same way S7-300 CPUs (e.g., 6GK7 343-1) do. Instead, PROFIBUS communication was offloaded to dedicated communication processors that plug into the S5 backplane and present a dual-port RAM or I/O area to the CPU. The relevant CP families are:

CP Model Siemens Order Number (6GK1 …) PROFIBUS Protocols Supported Configuration Tool
CP5430 FMS 6GK1 543-0AA01 / …AA02 FMS only COM5430 (DOS) / SINEC NCM
CP5431 FMS/FDL 6GK1 543-1AA01 FMS, FDL, DP (firmware-dependent) COM5431 (DOS) / SINEC NCM
CP5432 6GK1 543-2AA00 FDL with extended memory SINEC NCM
CP5434 FMS 6GK1 543-4AA00 FMS, multi-segment COM5431 / SINEC NCM
IM308C 6ES7 308-3UCxx (S7) / S5 variant 6ES5 308-3UC11 PROFIBUS-DP Master/Slave COM PROFIBUS / STEP 5 DP
AG 95U CPU port 6ES5 095-8MA… / …8ME… FDL only (onboard) STEP 5 COM 95U parameter block

Three facts constrain every diagnostic:

  1. Only the CP5431 family natively supports FMS as a layer-7 service. CP5430 supports FMS as well; CP5430/CP5431/CP5432/CP5434 all support FDL. The onboard PROFIBUS of the AG 95U supports FDL only — never FMS.
  2. FMS is strictly a layer-7 protocol riding on FDL. It does not replace FDL; it consumes it. If FMS is in use, FDL is in use simultaneously.
  3. PROFIBUS-DP is a separate, optimised profile (EN 50170 / IEC 61158) that uses FDL only at layer 2, with DP-specific SAPs and cyclic MS0/MS1/MS2 communication. It cannot co-exist with FMS on the same CP without firmware restriction.

2. Physical Identification of the Installed CP

Before opening any software, perform the physical identification. Power down the S5 rack, locate the CP slot, and read the order number (MLFB) printed on the front panel. Cross-reference with the table above. Three patterns cover almost every field installation:

2.1 CP5430 in FDL Configuration

The CP5430 (6GK1 543-0AA02) was the most common S5 FDL CP. It exposes an MPI/PROFIBUS 9-pin D-sub on the front, has two status LEDs (red = PROFIBUS error, green = token), and the order number ends in …0AA02 or …0AA01. The CP5430 cannot run FMS even with firmware updates; the ASIC is fixed to layer-2 FDL with SEND/RECEIVE/BSEND/BRECV functions in the S5 user program.

2.2 CP5431 in FMS or FDL Configuration

The CP5431 (6GK1 543-1AA01) is physically similar but has a higher-position front connector (Profibus-DP female D-sub) and supports firmware variants. The order-number suffix is critical: …1AA01 is the FMS/FDL build; some later …1BA… variants add DP master capability. To identify which protocol is loaded, examine the front-panel LED pattern at power-up — FMS builds flash the red LED three times, FDL-only builds flash once. This is documented in the Siemens manual SIMATIC S5 CP5431 Manual (6GK1 543-1AA01) Edition 04/2002.

2.3 IM308C as DP Master/Slave

If the CP occupies a single slot and has a rotary address switch (1–99) on the front, it is an IM308C. The IM308C is a PROFIBUS-DP master or slave, never FMS. It was configured with COM PROFIBUS (Siemens order number 6ES5 895-3SE01) and produces a *.DP file rather than an NCM database. Discovering an IM308C immediately answers the question: the network is DP, not FMS.

3. Protocol Layer Model — FDL vs FMS vs DP

The three protocol families occupy different positions in the ISO/OSI reference model, and the configuration database inside SINEC NCM reflects this hierarchy.

Layer FDL (IEC 61158-3) FMS (IEC 61158-7) PROFIBUS-DP (IEC 61158-6)
7 — Application User SEND/RECEIVE FMS services (Read, Write, Information Report) DP user interface
6 — Presentation — Object Dictionary —
5 — Session — Application Relationships (AR) —
4 — Transport — — —
3 — Network — — —
2 — Data Link SDN/SDA/SRD services, SAP addressing FDL (consumed transparently) FDL with SRD, fixed SAPs
1 — Physical RS-485 (9.6 kbit/s – 12 Mbit/s) RS-485 RS-485 (typically 1.5/12 Mbit/s)

FDL itself is the foundational layer-2 bus protocol. It offers three service primitives — SDA (Send Data with Acknowledge), SRD (Send and Request Data with Reply), and SDN (Send Data with No acknowledge) — addressed by SAPs in the range 0–126. FMS uses SRD exclusively at layer 2 and adds application relationships at layer 7 to manipulate named objects (variables, domain, program invocation, event). DP uses SRD with predefined SAPs 0 (DP Master Class 1), 1 (DP Master Class 2), and 0–126 for slaves (default 0).

4. Identifying the Protocol in SINEC NCM

SINEC NCM (Siemens Network and Communication Manager) was the Windows-based replacement for COM5430/COM5431. It stored the complete CP configuration in a binary project database with .ncm extension. To recover the protocol:

  1. Locate the project directory. The default path on Windows XP/7 era installations is C:\SINEC\NCM\PROJECTS\<PROJECTNAME>\. Each project contains a *.ncm file plus per-CP subdirectories.
  2. Open the project in SINEC NCM (version 5.x supports S5 and S7 mixed projects; version 7.x is S7 only).
  3. Select the CP node in the network tree. The right-hand property pane shows the CP type, order number, and the loaded firmware version.
  4. Expand Connections. If FMS is active, you will see entries labelled Application Relationship with fields VFD index, CR name, Object list, and Index/Length pairs. These do not exist in pure FDL configurations.
  5. If only FDL is active, the connections list shows entries typed as AG-AG connection or Free Layer 2 connection. Each row exposes Local SAP, Remote SAP, and Service (SDA/SRD/SDN).
Diagnostic Tip: A pure FMS configuration will have at least one Server AR row and one Client AR row. If only client ARs are present, the local CP is FMS-client and the partner is FMS-server. If only server ARs are present, the local CP is server.

5. Identifying the Protocol in COM5430 / COM5431

COM5430 (for CP5430 FDL) and COM5431 (for CP5431 FMS/FDL) were DOS-based configuration tools distributed on 3.5" floppy disks. The default installation path is C:\COM5431\. To inspect a CP database:

  1. Boot into DOS or a Windows 9x DOS-prompt compatibility mode. COM5431 will not run on Windows NT/2000/XP natively; use NTVDM or a virtual machine.
  2. Run COM5431.EXE. Select File → Open → CP5431 Database.
  3. The opened database displays a hierarchical view: CP5431 → Bus Parameters → Connections.
  4. Expand Connections. FMS connections are stored under a sub-folder FMS-CR (Communication Relationship). FDL connections are stored under FDL-CR. The presence of an FMS-CR folder is the definitive proof that FMS is loaded.

5.1 CP5431 Firmware Identification

The CP5431 firmware EPROM is socketed. Reading the label cross-references to the loaded protocol set:

EPROM Label Firmware Version Protocols Supported
6ES5 873-1CC21 V1.0 FMS, FDL
6ES5 873-1CD21 V2.0 FMS, FDL
6ES5 873-1CE21 V3.0 FMS, FDL, DP-Master (limited)
6ES5 873-1CF21 V4.0 FDL, DP-Master (FMS removed)

Firmware V4.0 stripped FMS support to free ASIC resources for DP. If the EPROM reads …1CF21 the CP can only run FDL or DP, never FMS regardless of the project file.

6. Step-by-Step Protocol Identification Procedure

Use the following ordered procedure to converge on the protocol family in the field:

  1. Identify the CP order number from the front panel (Section 2). Record the full MLFB.
  2. Read the EPROM label if accessible. Cross-reference with the firmware table (Section 5.1). If the firmware is …1CF21 or later, FMS is impossible; the answer is FDL or DP.
  3. Inspect the SINEC NCM or COM5431 database. Presence of FMS-CR or Application Relationship rows confirms FMS. Presence of DP Master System rows in COM PROFIBUS confirms DP.
  4. If the database is missing, connect a PROFIBUS analyser (e.g., Softing PROFIusb, Siemens BT200, or any class-2 master tool) and capture traffic. FMS frames have a fixed protocol ID byte 0xF1 (FMS) at the FDL header; DP frames use 0x80 (Data Exchange) or 0xF1 for FMS, distinguished by the SAP and the FDL FC (Function Code) byte.
  5. Use the S5 status word (Section 7) to read live protocol activity from the S5 CPU.

7. S5 Status Word and Diagnostics Block

The S5 user program exchanges control and status information with the CP through a defined handshake area in the CP dual-port RAM. Standard FB blocks expose status:

  • FB244 (SEND for CP5430) — status word ANZW reports the last FDL service completion code.
  • FB245 (RECEIVE for CP5430) — same status mapping.
  • FB253 (BSEND for CP5431) — extended status includes FMS-specific Error_Class and Error_Code per IEC 61158-7.
  • FB254 (BRECV for CP5431) — same extended status.

If the S5 program references FB253/FB254 against a CP5431, the program is using FMS-aware blocks; FMS is therefore likely the active protocol (or at least configured). If the program uses FB244/FB245 against a CP5431, the program is using pure FDL even though the CP could do FMS.

8. SAP and Service Type Mapping Table

The SAP range is reserved by PROFIBUS standards and Siemens conventions. Cross-reference traffic captures against this table:

SAP (Decimal) SAP (Hex) Reserved For
0 0x00 DP Master Class 1 default
1 0x01 DP Master Class 2 (diagnostics)
2–35 0x02–0x23 DP Slave default
54 0x36 Siemens-specific FMS (CP5431 default)
55 0x37 Siemens-specific FDL pass-through
56 0x38 FDL with S5-AG-AG standard
62 0x3E Siemens PG / S7 routing
64 0x40 Reserved (Siemens)
127 0x7F Default SAP for broadcast/no-station

If the analyser captures traffic with SAP 54 (0x36), FMS is in use. If traffic is exclusively SAP 0–35, DP is in use. If traffic is on SAP 56 (0x38) with SDA/SRD services and no FMS object dictionary, FDL pass-through is in use.

9. Migration to STEP 7 and TIA Portal

When a project is migrated from S5 to S7, the protocol does not migrate automatically. The following mapping applies:

S5 Protocol S5 CP Block S7 Equivalent S7 Block Family
FDL AG-AG FB244/FB245 S7-300/400 CP343-1 / CP443-1 FDL AG_SEND / AG_RECV (FB12/FB13)
FMS Client FB253/FB254 S7 CP with FMS license FMS_AG_SEND / FMS_AG_RECV
FMS Server FB253/FB254 (server side) S7 CP + object dictionary file FMS_IDENT / FMS_READ / FMS_WRITE
DP Master (IM308C) STEP 5 DP / COM PROFIBUS S7 CPU onboard / CP342-5 Integrated in HW Config / TIA Portal
Compatibility Warning: FMS is end-of-life on S7 hardware; S7-1200 and S7-1500 do not support FMS at all. If the S5 network runs FMS, plan a protocol conversion at the gateway level (e.g., a CP343-1 FMS-to-S7-communication bridge, or a third-party PROFINET/PROFIBUS gateway) before retiring the S5.

10. TIA Portal PROFIBUS Line Configuration

Once the network is migrated to a STEP 7 or TIA Portal environment, the PROFIBUS subnet must be configured to match the cable plant. The TIA Portal V20 documentation "What you need to know about PROFIBUS line configuration" states: "You must select the 'Consider cable configuration' check box in the properties for the PROFIBUS subnet. The remaining information then depends on the type of …". Activate this checkbox in:

  1. Open the Devices & Networks editor in the TIA Portal project.
  2. Select the PROFIBUS subnet (the line between the master and slave devices).
  3. In the Properties > PROFIBUS subnet panel, expand Network settings.
  4. Tick Consider cable configuration. Then enter the cable type (e.g., PROFIBUS FC Standard Cable 6XV1 830-0EH10), segment lengths in metres, and the number of repeaters. TIA Portal will compute the maximum achievable baud rate (9.6 kbit/s to 12 Mbit/s) and refuse to assign an unsupported rate.

This is also where baud rate mismatches between legacy S5 CPs (typically 1.5 Mbit/s) and S7 hardware (12 Mbit/s) are detected and reported as Baud rate not supported by all nodes during compilation.

11. Verification Checklist

After identifying the protocol and confirming the configuration, perform the following verification checks before commissioning:

  • CP order number matches the SINEC NCM/COM5431 project file (no firmware mismatch).
  • Bus parameters: baud rate, HSA (Highest Station Address), and Tslot match across all nodes.
  • FMS object dictionary (if FMS) is loaded into the server CP and the number of objects matches the client configuration.
  • FDL SAPs do not collide between independent connections (each SAP may be used by only one connection at a time).
  • Repeater diagnostic LEDs are all green; no PROFIBUS segment is longer than the calculated maximum for the configured baud rate.
  • PG/PC online test with COM5431 or STEP 5 successfully reaches the CP with Online → CP Status returning RUN not STOP.

12. Troubleshooting Matrix

Symptom Likely Root Cause Diagnostic Step Remediation
CP5431 RUN LED off Wrong firmware EPROM Read EPROM label, cross-reference Section 5.1 Flash correct firmware via PG
SINEC NCM shows only FMS-CR but traffic is silent Object dictionary not loaded into CP Use Online → Download OD in COM5431 Download OD to CP, restart CP
FDL SEND returns SF = 1, ANZW bit 7 set Remote station not connected Check PROFIBUS termination, cable continuity Repair wiring, verify termination
DP slave not appearing in master diagnostic Slave address mismatch Compare rotary switch on slave with master config Set address to match configuration
FMS Read returns Error_Class 0x0A Object not in server OD Inspect server OD via COM5431 Add object to server, reload OD
Intermittent bus errors at 12 Mbit/s Cable plant exceeds limit at 12 Mbit/s Enable Consider cable configuration in TIA Portal Reduce baud rate to 1.5 Mbit/s or replace cable

13. Field-Proven Caveats

  • The CP5431 EPROM socket is keyed; inserting the EPROM rotated 180° will not damage it but the CP will not boot. Verify notch orientation before re-seating.
  • COM5431 generates a *.CP file that is platform-specific to the CP type. A *.CP generated for a CP5431 will be rejected by a CP5434 even with the same firmware version.
  • If the original S5 program calls FB253 (BSEND) with a subslot parameter, it is FMS. If it calls FB244/FB245 with a SSNR (interface number) parameter only, it is FDL — regardless of the CP hardware.
  • Battery-backed RAM in the S5 CPU preserves the CP5430/5431 configuration only if the CP battery is also healthy. A dead CP battery silently reverts to factory defaults after power-cycle of more than ~30 days.
  • The AG 95U onboard PROFIBUS port (X2) shares its address with the MPI port and cannot run FMS under any firmware version. If FMS is needed, a CP5431 in the rack is mandatory.

How can I tell if an S5 PROFIBUS network is FDL, FMS, or DP without the original project files?

Read the CP order number (MLFB) on the front panel and the EPROM label. A CP5430 is FDL only. A CP5431 with firmware EPROM 6ES5 873-1CE21 or earlier supports FMS/FDL; firmware …1CF21 is FDL/DP only. An IM308C is always DP. Capture live traffic with a PROFIBUS analyser — FMS frames use protocol ID 0xF1 with SAP 54 (0x36), DP uses SAP 0–35.

Which Siemens tool stores the S5 CP5431 FMS configuration?

FMS configurations for the CP5431 were created and stored in SINEC NCM (Windows, .ncm project files) or its DOS predecessor COM5431 (.CP files). Both tools store the Application Relationships (AR), Communication Relationships (CR), and the Object Dictionary (OD) for FMS servers. The CP5430-only FDL configuration tool is COM5430.

Can a CP5431 run FMS and DP simultaneously?

No. The CP5431 firmware loads a single protocol stack per boot. CP5431 firmware V3.0 (…1CE21) added DP-master capability but at the cost of FMS support being disabled when DP is selected. FMS and DP cannot coexist on the same CP instance.

What is the default SAP for a Siemens CP5431 FMS connection?

The Siemens default SAP for CP5431 FMS is 54 (0x36) on the FMS server side. FMS clients may use any free SAP in the user range 56–126 (0x38–0x7E). SAPs 0–35 are reserved for PROFIBUS-DP and must not be used for FMS to avoid collisions with DP masters on the same segment.

Why does TIA Portal refuse my migrated PROFIBUS baud rate?

Enable the Consider cable configuration checkbox in the PROFIBUS subnet properties under Devices & Networks. TIA Portal then computes the maximum supported baud rate from the entered cable type, segment length, and repeater count. If the S5 CP only supports 1.5 Mbit/s but TIA proposes 12 Mbit/s, the cable plant is too long; either reduce the baud rate or shorten/replace the segment with PROFIBUS FC Standard Cable 6XV1 830-0EH10.

Is FMS supported on S7-1200 or S7-1500 CPUs?

No. FMS is not supported on S7-1200 or S7-1500 hardware. FMS support ended with the S7-300/400 generation (CP343-1 and CP443-1 with FMS firmware option). New installations must use PROFINET, PROFIBUS-DP, or OPC UA as the replacement protocol.

Back to blog