Identifying PROFIBUS FDL vs FMS on Siemens S5 CP5430/CP5431
Engineers maintaining legacy SIMATIC S5 installations frequently face an undocumented PROFIBUS network: the original project files are missing, the configuration tool floppy disks are lost, and the only available evidence is the communication processor (CP) seated in the S5-115U, S5-135U, or S5-155U rack. The central question becomes: Is this PROFIBUS segment running FDL (Fieldbus Data Link, layer 2), FMS (Fieldbus Message Specification, layer 7), or PROFIBUS-DP (Decentralised Periphery)? The answer is recoverable from the CP order number, the CP firmware version, and the configuration database inside SINEC NCM or the legacy COM5430/COM5431 commissioning tools. This reference documents the deterministic procedure for answering that question, including the SAP/service mappings, hardware order numbers, and migration paths to STEP 7 / TIA Portal.
1. S5 PROFIBUS Architecture Overview
The SIMATIC S5 family never integrated PROFIBUS into the CPU itself in the same way S7-300 CPUs (e.g., 6GK7 343-1) do. Instead, PROFIBUS communication was offloaded to dedicated communication processors that plug into the S5 backplane and present a dual-port RAM or I/O area to the CPU. The relevant CP families are:
| CP Model | Siemens Order Number (6GK1 …) | PROFIBUS Protocols Supported | Configuration Tool |
|---|---|---|---|
| CP5430 FMS | 6GK1 543-0AA01 / …AA02 | FMS only | COM5430 (DOS) / SINEC NCM |
| CP5431 FMS/FDL | 6GK1 543-1AA01 | FMS, FDL, DP (firmware-dependent) | COM5431 (DOS) / SINEC NCM |
| CP5432 | 6GK1 543-2AA00 | FDL with extended memory | SINEC NCM |
| CP5434 FMS | 6GK1 543-4AA00 | FMS, multi-segment | COM5431 / SINEC NCM |
| IM308C | 6ES7 308-3UCxx (S7) / S5 variant 6ES5 308-3UC11 | PROFIBUS-DP Master/Slave | COM PROFIBUS / STEP 5 DP |
| AG 95U CPU port | 6ES5 095-8MA… / …8ME… | FDL only (onboard) | STEP 5 COM 95U parameter block |
Three facts constrain every diagnostic:
- Only the CP5431 family natively supports FMS as a layer-7 service. CP5430 supports FMS as well; CP5430/CP5431/CP5432/CP5434 all support FDL. The onboard PROFIBUS of the AG 95U supports FDL only — never FMS.
- FMS is strictly a layer-7 protocol riding on FDL. It does not replace FDL; it consumes it. If FMS is in use, FDL is in use simultaneously.
- PROFIBUS-DP is a separate, optimised profile (EN 50170 / IEC 61158) that uses FDL only at layer 2, with DP-specific SAPs and cyclic MS0/MS1/MS2 communication. It cannot co-exist with FMS on the same CP without firmware restriction.
2. Physical Identification of the Installed CP
Before opening any software, perform the physical identification. Power down the S5 rack, locate the CP slot, and read the order number (MLFB) printed on the front panel. Cross-reference with the table above. Three patterns cover almost every field installation:
2.1 CP5430 in FDL Configuration
The CP5430 (6GK1 543-0AA02) was the most common S5 FDL CP. It exposes an MPI/PROFIBUS 9-pin D-sub on the front, has two status LEDs (red = PROFIBUS error, green = token), and the order number ends in …0AA02 or …0AA01. The CP5430 cannot run FMS even with firmware updates; the ASIC is fixed to layer-2 FDL with SEND/RECEIVE/BSEND/BRECV functions in the S5 user program.
2.2 CP5431 in FMS or FDL Configuration
The CP5431 (6GK1 543-1AA01) is physically similar but has a higher-position front connector (Profibus-DP female D-sub) and supports firmware variants. The order-number suffix is critical: …1AA01 is the FMS/FDL build; some later …1BA… variants add DP master capability. To identify which protocol is loaded, examine the front-panel LED pattern at power-up — FMS builds flash the red LED three times, FDL-only builds flash once. This is documented in the Siemens manual SIMATIC S5 CP5431 Manual (6GK1 543-1AA01) Edition 04/2002.
2.3 IM308C as DP Master/Slave
If the CP occupies a single slot and has a rotary address switch (1–99) on the front, it is an IM308C. The IM308C is a PROFIBUS-DP master or slave, never FMS. It was configured with COM PROFIBUS (Siemens order number 6ES5 895-3SE01) and produces a *.DP file rather than an NCM database. Discovering an IM308C immediately answers the question: the network is DP, not FMS.
3. Protocol Layer Model — FDL vs FMS vs DP
The three protocol families occupy different positions in the ISO/OSI reference model, and the configuration database inside SINEC NCM reflects this hierarchy.
| Layer | FDL (IEC 61158-3) | FMS (IEC 61158-7) | PROFIBUS-DP (IEC 61158-6) |
|---|---|---|---|
| 7 — Application | User SEND/RECEIVE | FMS services (Read, Write, Information Report) | DP user interface |
| 6 — Presentation | — | Object Dictionary | — |
| 5 — Session | — | Application Relationships (AR) | — |
| 4 — Transport | — | — | — |
| 3 — Network | — | — | — |
| 2 — Data Link | SDN/SDA/SRD services, SAP addressing | FDL (consumed transparently) | FDL with SRD, fixed SAPs |
| 1 — Physical | RS-485 (9.6 kbit/s – 12 Mbit/s) | RS-485 | RS-485 (typically 1.5/12 Mbit/s) |
FDL itself is the foundational layer-2 bus protocol. It offers three service primitives — SDA (Send Data with Acknowledge), SRD (Send and Request Data with Reply), and SDN (Send Data with No acknowledge) — addressed by SAPs in the range 0–126. FMS uses SRD exclusively at layer 2 and adds application relationships at layer 7 to manipulate named objects (variables, domain, program invocation, event). DP uses SRD with predefined SAPs 0 (DP Master Class 1), 1 (DP Master Class 2), and 0–126 for slaves (default 0).
4. Identifying the Protocol in SINEC NCM
SINEC NCM (Siemens Network and Communication Manager) was the Windows-based replacement for COM5430/COM5431. It stored the complete CP configuration in a binary project database with .ncm extension. To recover the protocol:
- Locate the project directory. The default path on Windows XP/7 era installations is
C:\SINEC\NCM\PROJECTS\<PROJECTNAME>\. Each project contains a*.ncmfile plus per-CP subdirectories. - Open the project in SINEC NCM (version 5.x supports S5 and S7 mixed projects; version 7.x is S7 only).
- Select the CP node in the network tree. The right-hand property pane shows the CP type, order number, and the loaded firmware version.
- Expand Connections. If FMS is active, you will see entries labelled Application Relationship with fields VFD index, CR name, Object list, and Index/Length pairs. These do not exist in pure FDL configurations.
- If only FDL is active, the connections list shows entries typed as AG-AG connection or Free Layer 2 connection. Each row exposes Local SAP, Remote SAP, and Service (SDA/SRD/SDN).
5. Identifying the Protocol in COM5430 / COM5431
COM5430 (for CP5430 FDL) and COM5431 (for CP5431 FMS/FDL) were DOS-based configuration tools distributed on 3.5" floppy disks. The default installation path is C:\COM5431\. To inspect a CP database:
- Boot into DOS or a Windows 9x DOS-prompt compatibility mode. COM5431 will not run on Windows NT/2000/XP natively; use
NTVDMor a virtual machine. - Run
COM5431.EXE. Select File → Open → CP5431 Database. - The opened database displays a hierarchical view: CP5431 → Bus Parameters → Connections.
- Expand Connections. FMS connections are stored under a sub-folder FMS-CR (Communication Relationship). FDL connections are stored under FDL-CR. The presence of an FMS-CR folder is the definitive proof that FMS is loaded.
5.1 CP5431 Firmware Identification
The CP5431 firmware EPROM is socketed. Reading the label cross-references to the loaded protocol set:
| EPROM Label | Firmware Version | Protocols Supported |
|---|---|---|
| 6ES5 873-1CC21 | V1.0 | FMS, FDL |
| 6ES5 873-1CD21 | V2.0 | FMS, FDL |
| 6ES5 873-1CE21 | V3.0 | FMS, FDL, DP-Master (limited) |
| 6ES5 873-1CF21 | V4.0 | FDL, DP-Master (FMS removed) |
Firmware V4.0 stripped FMS support to free ASIC resources for DP. If the EPROM reads …1CF21 the CP can only run FDL or DP, never FMS regardless of the project file.
6. Step-by-Step Protocol Identification Procedure
Use the following ordered procedure to converge on the protocol family in the field:
- Identify the CP order number from the front panel (Section 2). Record the full MLFB.
-
Read the EPROM label if accessible. Cross-reference with the firmware table (Section 5.1). If the firmware is
…1CF21or later, FMS is impossible; the answer is FDL or DP. - Inspect the SINEC NCM or COM5431 database. Presence of FMS-CR or Application Relationship rows confirms FMS. Presence of DP Master System rows in COM PROFIBUS confirms DP.
-
If the database is missing, connect a PROFIBUS analyser (e.g., Softing PROFIusb, Siemens BT200, or any class-2 master tool) and capture traffic. FMS frames have a fixed protocol ID byte
0xF1(FMS) at the FDL header; DP frames use0x80(Data Exchange) or0xF1for FMS, distinguished by the SAP and the FDL FC (Function Code) byte. - Use the S5 status word (Section 7) to read live protocol activity from the S5 CPU.
7. S5 Status Word and Diagnostics Block
The S5 user program exchanges control and status information with the CP through a defined handshake area in the CP dual-port RAM. Standard FB blocks expose status:
-
FB244 (SEND for CP5430) — status word
ANZWreports the last FDL service completion code. - FB245 (RECEIVE for CP5430) — same status mapping.
-
FB253 (BSEND for CP5431) — extended status includes FMS-specific
Error_ClassandError_Codeper IEC 61158-7. - FB254 (BRECV for CP5431) — same extended status.
If the S5 program references FB253/FB254 against a CP5431, the program is using FMS-aware blocks; FMS is therefore likely the active protocol (or at least configured). If the program uses FB244/FB245 against a CP5431, the program is using pure FDL even though the CP could do FMS.
8. SAP and Service Type Mapping Table
The SAP range is reserved by PROFIBUS standards and Siemens conventions. Cross-reference traffic captures against this table:
| SAP (Decimal) | SAP (Hex) | Reserved For |
|---|---|---|
| 0 | 0x00 | DP Master Class 1 default |
| 1 | 0x01 | DP Master Class 2 (diagnostics) |
| 2–35 | 0x02–0x23 | DP Slave default |
| 54 | 0x36 | Siemens-specific FMS (CP5431 default) |
| 55 | 0x37 | Siemens-specific FDL pass-through |
| 56 | 0x38 | FDL with S5-AG-AG standard |
| 62 | 0x3E | Siemens PG / S7 routing |
| 64 | 0x40 | Reserved (Siemens) |
| 127 | 0x7F | Default SAP for broadcast/no-station |
If the analyser captures traffic with SAP 54 (0x36), FMS is in use. If traffic is exclusively SAP 0–35, DP is in use. If traffic is on SAP 56 (0x38) with SDA/SRD services and no FMS object dictionary, FDL pass-through is in use.
9. Migration to STEP 7 and TIA Portal
When a project is migrated from S5 to S7, the protocol does not migrate automatically. The following mapping applies:
| S5 Protocol | S5 CP Block | S7 Equivalent | S7 Block Family |
|---|---|---|---|
| FDL AG-AG | FB244/FB245 | S7-300/400 CP343-1 / CP443-1 FDL | AG_SEND / AG_RECV (FB12/FB13) |
| FMS Client | FB253/FB254 | S7 CP with FMS license | FMS_AG_SEND / FMS_AG_RECV |
| FMS Server | FB253/FB254 (server side) | S7 CP + object dictionary file | FMS_IDENT / FMS_READ / FMS_WRITE |
| DP Master (IM308C) | STEP 5 DP / COM PROFIBUS | S7 CPU onboard / CP342-5 | Integrated in HW Config / TIA Portal |
10. TIA Portal PROFIBUS Line Configuration
Once the network is migrated to a STEP 7 or TIA Portal environment, the PROFIBUS subnet must be configured to match the cable plant. The TIA Portal V20 documentation "What you need to know about PROFIBUS line configuration" states: "You must select the 'Consider cable configuration' check box in the properties for the PROFIBUS subnet. The remaining information then depends on the type of …". Activate this checkbox in:
- Open the Devices & Networks editor in the TIA Portal project.
- Select the PROFIBUS subnet (the line between the master and slave devices).
- In the Properties > PROFIBUS subnet panel, expand Network settings.
- Tick Consider cable configuration. Then enter the cable type (e.g., PROFIBUS FC Standard Cable 6XV1 830-0EH10), segment lengths in metres, and the number of repeaters. TIA Portal will compute the maximum achievable baud rate (9.6 kbit/s to 12 Mbit/s) and refuse to assign an unsupported rate.
This is also where baud rate mismatches between legacy S5 CPs (typically 1.5 Mbit/s) and S7 hardware (12 Mbit/s) are detected and reported as Baud rate not supported by all nodes during compilation.
11. Verification Checklist
After identifying the protocol and confirming the configuration, perform the following verification checks before commissioning:
- CP order number matches the SINEC NCM/COM5431 project file (no firmware mismatch).
- Bus parameters: baud rate, HSA (Highest Station Address), and Tslot match across all nodes.
- FMS object dictionary (if FMS) is loaded into the server CP and the number of objects matches the client configuration.
- FDL SAPs do not collide between independent connections (each SAP may be used by only one connection at a time).
- Repeater diagnostic LEDs are all green; no PROFIBUS segment is longer than the calculated maximum for the configured baud rate.
- PG/PC online test with COM5431 or STEP 5 successfully reaches the CP with Online → CP Status returning
RUNnotSTOP.
12. Troubleshooting Matrix
| Symptom | Likely Root Cause | Diagnostic Step | Remediation |
|---|---|---|---|
| CP5431 RUN LED off | Wrong firmware EPROM | Read EPROM label, cross-reference Section 5.1 | Flash correct firmware via PG |
| SINEC NCM shows only FMS-CR but traffic is silent | Object dictionary not loaded into CP | Use Online → Download OD in COM5431 | Download OD to CP, restart CP |
| FDL SEND returns SF = 1, ANZW bit 7 set | Remote station not connected | Check PROFIBUS termination, cable continuity | Repair wiring, verify termination |
| DP slave not appearing in master diagnostic | Slave address mismatch | Compare rotary switch on slave with master config | Set address to match configuration |
| FMS Read returns Error_Class 0x0A | Object not in server OD | Inspect server OD via COM5431 | Add object to server, reload OD |
| Intermittent bus errors at 12 Mbit/s | Cable plant exceeds limit at 12 Mbit/s | Enable Consider cable configuration in TIA Portal | Reduce baud rate to 1.5 Mbit/s or replace cable |
13. Field-Proven Caveats
- The CP5431 EPROM socket is keyed; inserting the EPROM rotated 180° will not damage it but the CP will not boot. Verify notch orientation before re-seating.
- COM5431 generates a
*.CPfile that is platform-specific to the CP type. A*.CPgenerated for a CP5431 will be rejected by a CP5434 even with the same firmware version. - If the original S5 program calls FB253 (BSEND) with a subslot parameter, it is FMS. If it calls FB244/FB245 with a SSNR (interface number) parameter only, it is FDL — regardless of the CP hardware.
- Battery-backed RAM in the S5 CPU preserves the CP5430/5431 configuration only if the CP battery is also healthy. A dead CP battery silently reverts to factory defaults after power-cycle of more than ~30 days.
- The AG 95U onboard PROFIBUS port (X2) shares its address with the MPI port and cannot run FMS under any firmware version. If FMS is needed, a CP5431 in the rack is mandatory.
How can I tell if an S5 PROFIBUS network is FDL, FMS, or DP without the original project files?
Read the CP order number (MLFB) on the front panel and the EPROM label. A CP5430 is FDL only. A CP5431 with firmware EPROM 6ES5 873-1CE21 or earlier supports FMS/FDL; firmware …1CF21 is FDL/DP only. An IM308C is always DP. Capture live traffic with a PROFIBUS analyser — FMS frames use protocol ID 0xF1 with SAP 54 (0x36), DP uses SAP 0–35.
Which Siemens tool stores the S5 CP5431 FMS configuration?
FMS configurations for the CP5431 were created and stored in SINEC NCM (Windows, .ncm project files) or its DOS predecessor COM5431 (.CP files). Both tools store the Application Relationships (AR), Communication Relationships (CR), and the Object Dictionary (OD) for FMS servers. The CP5430-only FDL configuration tool is COM5430.
Can a CP5431 run FMS and DP simultaneously?
No. The CP5431 firmware loads a single protocol stack per boot. CP5431 firmware V3.0 (…1CE21) added DP-master capability but at the cost of FMS support being disabled when DP is selected. FMS and DP cannot coexist on the same CP instance.
What is the default SAP for a Siemens CP5431 FMS connection?
The Siemens default SAP for CP5431 FMS is 54 (0x36) on the FMS server side. FMS clients may use any free SAP in the user range 56–126 (0x38–0x7E). SAPs 0–35 are reserved for PROFIBUS-DP and must not be used for FMS to avoid collisions with DP masters on the same segment.
Why does TIA Portal refuse my migrated PROFIBUS baud rate?
Enable the Consider cable configuration checkbox in the PROFIBUS subnet properties under Devices & Networks. TIA Portal then computes the maximum supported baud rate from the entered cable type, segment length, and repeater count. If the S5 CP only supports 1.5 Mbit/s but TIA proposes 12 Mbit/s, the cable plant is too long; either reduce the baud rate or shorten/replace the segment with PROFIBUS FC Standard Cable 6XV1 830-0EH10.
Is FMS supported on S7-1200 or S7-1500 CPUs?
No. FMS is not supported on S7-1200 or S7-1500 hardware. FMS support ended with the S7-300/400 generation (CP343-1 and CP443-1 with FMS firmware option). New installations must use PROFINET, PROFIBUS-DP, or OPC UA as the replacement protocol.