1. Overview: Adding Ethernet to a Live S5-155U System
Retrofitting a SIMATIC S5-155U with a CP 1430 TCP communications processor is a common requirement when modern equipment must exchange data with an established S5 program over Industrial Ethernet. The mechanical challenge is that the central rack is usually full, while the logical challenge is that S5 has no HW Config equivalent to STEP 7 / TIA Portal — every address, every slot, and every multi-CPU relationship is determined by physical switches, the DB1 of each CPU, and any installed Coordinator card.
This reference walks through the complete mechanical and logical retrofit of a CP 1430 TCP into an S5-155U central rack whose last slot cannot accept the CP. The procedure assumes a single CPU S5-155U on STEP 5 with a Coordinator card already fitted (or to be fitted) for multi-CPU IPC flag coordination. The same logic applies to the S5-135U and S5-155U/155H families; consult the Siemens Industry Online Support portal for the specific 155U manual chapter on allowable slot populations.
2. Prerequisites
| Item | Requirement |
|---|---|
| CP 1430 TCP variant | 6GK1 143-0TA01 (standard) or 6GK1 143-0TA0x successor; verify against current Siemens catalog |
| Configuration software | COM 1430 Vx.x or NCM S5 (depending on firmware), running on MS-DOS / Windows PG |
| Programming tool | STEP 5 (PG 7xx, PG 720, PG 740, or PC with STEP 5 ≥ V6.x and appropriate cable) |
| S5-155U manuals | CPU 948 manual (if multi-CPU), Coordinator (Co) manual, S5-155U system manual chapter 4.1 "Slot assignments" |
| Network information | IP address, subnet mask, gateway for CP 1430; TSAPs or port numbers for peer; MAC if statically set |
| ESD protection | Wrist strap, grounded mat, original S5 packaging for module transport |
Before touching the rack, download and archive every CPU's complete project — program blocks, DB1, DB2 (if used for IPC), system data, and any EPROM contents. A corrupt DB1 is the single most common failure mode when an S5 module is moved or replaced, and a clean backup is the only safe rollback.
3. S5-155U Rack Architecture and Slot Topology
The S5-155U central rack (CR) and expansion racks (ER) follow fixed slot rules that are more rigid than S7-300/400. The CPU and Coordinator cards are restricted to specific slots, while digital and analog I/O may sit in any free slot except where the CPU occupies the row. Communication processors (CPs) and interface modules (IMs) are also restricted — they cannot occupy the slot reserved for the CPU, but they are also excluded from certain peripheral slots where their bus-master or interrupt behavior would clash with the I/O scan.
Three physical slot classes must be understood before any move:
| Class | Allowed modules | Typical slots |
|---|---|---|
| Power supply slot | PS 951 / 952 only | Slot 0 of every rack |
| CPU slot | CPU 9xx, plus optional Coordinator (Co) co-residency in dedicated position | Slot 1 (single CPU) or slots defined per multi-CPU configuration |
| Peripheral / CP / IM slots | DI/DO/AI/AQ, CP 1430, IM 304/305/308/314, IP xxx | Slots 2 through 21, with specific exclusions per card type |
The CP 1430 TCP draws power from the S5 backplane and uses the peripheral bus for its dual-port RAM interface to the CPU. Because the peripheral bus is scanned synchronously by the CPU cycle (OB1 cycle), the CP must be installed in a slot whose peripheral bus address is reachable by the CPU's I/O update. This is exactly the same mechanism used by every digital input card, which is why DIP switch addressing is consistent across module classes.
4. Slot Rules: Which Modules Can Be Moved Where
The S5-155U system manual chapter 4.1 contains the canonical table. The simplified rules that matter for a CP 1430 retrofit are:
- DI, DQ, AI, AQ cards can be installed in any peripheral slot of the central rack except the slot reserved for the CPU. Their P/Q byte addresses are set by DIP switch and travel with the card.
- CPs (including CP 1430), IPs (intelligent I/O such as IP 240, IP 252), and IMs (IM 304, IM 308, IM 314) are restricted to specific peripheral slots. The CP 1430 TCP is permitted in most peripheral slots of the central rack except the very last slot of certain rack variants (this is the documented limitation in the source scenario).
- The CPU itself must remain in its fixed slot. Moving the CPU is not a mechanical swap — it requires program reload and configuration validation.
- The Coordinator card (Co 135/155) is required for any multi-CPU configuration and must reside in a slot defined by the CPU manual for the specific CPU variant.
5. Identifying a Candidate Module to Relocate
To free a peripheral slot for the CP 1430 TCP, identify a module that:
- Currently occupies a mid-peripheral slot that the CP 1430 TCP can use.
- Is mechanically and electrically compatible with the target slot (i.e., a peripheral slot where I/O is allowed).
- Does not have firmware or jumpers tied to slot number (rare, but some IPs use slot-encoded interrupts).
The best candidates are almost always:
- An IM 304 / IM 308 / IM 314 used for an expansion rack. If the IM leads to an expansion rack, you cannot move the IM into the CP 1430's former slot without re-routing the expansion rack topology. However, if the expansion rack is fed by a different IM (one already in the middle of the rack), moving that IM into the last slot is rarely possible either — see the slot rule above.
- A DI or DQ card with low criticality. A digital card in the last slot can almost always be moved into the freed mid-rack slot. The address travels with the DIP switches, so STEP 5 program changes are not required.
- An unused or spare slot already fitted with a blanking plate. If a blank exists mid-rack, the move becomes trivial.
| Scenario | Easiest swap | Risk to program |
|---|---|---|
| Last slot has unused DI module (e.g., DI 32 with spare inputs) | Move DI from mid-slot to last slot (if last slot accepts it); install CP 1430 in freed mid-slot | Low — DIP switches carry the address; only confirm process wiring reaches the new slot or use terminal blocks |
| Last slot has IP 240 counter / IP 252 cam controller | Generally not movable to mid-slot; verify the IP accepts mid-slot addressing via DIP | Medium — verify DIP switch compatibility and any interrupt assignments |
| Last slot has IM 304 to ER1, and ER1 has another IM in slot 0 | Topology change required — not a swap, a reconfiguration | High — expansion rack addressing changes |
| Coordinator card occupies the slot you want | Cannot move Coordinator — it is locked to its slot | N/A |
6. DIP Switch Addressing: Why the Address Travels With the Card
Every S5 digital and analog I/O module carries a small DIP switch bank that selects the P (input) or Q (output) byte address. When the card is moved to a different slot, the address does not change — the CPU scans the slot, the card reports its DIP-encoded address, and the I/O image is updated at that address. This is a critical property: it means a card swap that does not alter the DIP switches produces no program change.
Typical DIP switch encodings for DI/DQ cards:
| Card | DIP switch group | Encoding | Example address |
|---|---|---|---|
| DI 32 (6ES5 430-xAAxx) | Byte address (P) + reserved | Binary, 0–127 byte range | DIP = 0000000 binary = P 0 |
| DQ 32 (6ES5 440-xAAxx) | Byte address (Q) + reserved | Binary, 0–127 byte range | DIP = 0000001 binary = Q 1 |
| AI 8 (6ES5 460-xAAxx) | Byte address (P) pair | Word-aligned pairs | Address pairs: PW 0, PW 2, … |
| AQ 8 (6ES5 470-xAAxx) | Byte address (Q) pair | Word-aligned pairs | QW 0, QW 2, … |
For the CP 1430 TCP, address selection is different: the CP uses a DIP switch to set its slot-related base address on the peripheral bus (so the CPU knows where to find the CP's dual-port RAM). The base address must not collide with any DI/DQ/AI/AQ address set by other cards. Typical CP 1430 DIP settings reserve a peripheral area starting at a chosen byte, conventionally placed at the high end of the address space (e.g., P/Q 252 onwards) to avoid user I/O overlap.
7. Coordinator Card and Multi-CPU IPC Flags
If the S5-155U runs a single CPU, no Coordinator is needed for I/O addressing. The Coordinator (Co) is required for multi-CPU coordination, in which case it provides the IPC (inter-CPU communication) flag area used to pass data between CPUs without going through I/O.
The Coordinator must be enabled per CPU in each CPU's DB1. The flags must be defined for the CPU that owns the CP 1430 so that it can pass data to other CPUs and vice versa. The CPU 948 manual is the authoritative reference; see also the Siemens FAQ 22535867 on CP 1430 TCP configuration for an end-to-end example.
| CPU flag area | Size | Purpose |
|---|---|---|
| IPC input flags | 8 bytes per CPU, configurable via DB1 | Data received FROM other CPUs |
| IPC output flags | 8 bytes per CPU, configurable via DB1 | Data sent TO other CPUs |
| Coordinator IPC mailbox | Hardware-defined on Co card | Backplane arbitration |
For the CP 1430 retrofit, the practical implication is: if your rack has only one CPU, the Coordinator is not required for the CP 1430 itself — the CP exchanges data with its host CPU via the standard dual-port RAM interface. The Coordinator only becomes mandatory when the CP 1430 must pass data to a second CPU on the same rack, which then requires IPC flags to be enabled in both CPUs' DB1.
8. DB1 and Per-CPU Address Assignment
DB1 is the system data block that the S5 CPU reads at restart to determine its own I/O addresses, the Coordinator's IPC flag area (if present), and certain restart behaviors. Unlike STEP 7's HW Config, there is no centralized I/O list — every CPU owns its own DB1 and its own view of the rack.
Typical DB1 entries for a S5-155U with one CPU and a CP 1430:
DB1 (System data, do not edit online without restart)
DW0 : KC 'DB1' ; DB identifier
DW2 : KF +0 ; Reserved
DW4 : KF +0 ; Coordinator base address (0 if no Co)
DW6 : KF +8 ; IPC flag area size (bytes per CPU)
DW8 : KF +252 ; CP 1430 base address (per DIP switch)
DW10 : KF +1 ; Number of CPs in this CPU's view
DW12 : KF +0 ; Reserved
DW14 : KF +0 ; Restart mode bits
DW16 : KF +0 ; Reserved
DW18 : KC 'CP1430' ; Symbolic CP name for documentation only
; ... additional DW for multi-CPU if applicable
When you move cards, DB1 does not normally need editing unless the Coordinator flag area is changing. For a single-CPU retrofit, the only DB1 change is typically the documentation-only DW entry showing the CP 1430's base address; the program itself continues to run unmodified.
9. CP 1430 TCP Hardware Installation
- Power down the rack at the PS 951/952. Do not hot-swap S5-155U modules.
- Remove the blank or DI card from the chosen mid-slot. Note its DIP setting (photograph it).
- Verify the slot against the manual's table — confirm CP 1430 is listed as supported in that slot.
- Set the CP 1430 DIP switches for the peripheral base address (e.g., 252) and the slot identification. Refer to the CP 1430 manual for switch banks S1, S2, S3.
- Insert the CP 1430 into the slot. Apply even pressure on the top and bottom latches simultaneously.
- Tighten the front-panel screws that lock the card to the rack. Vibration on a S5-155U is a common cause of intermittent peripheral faults.
- Connect the Ethernet cable to the CP 1430's front-panel RJ45. The CP 1430 supports 10BASE5 (AUI) on older variants and 10BASE-T on newer; verify the variant.
- Update the rack layout sheet with new slot, DIP addresses, and CP 1430 base address.
For the swapped-out card (e.g., DI 32 moving to the last slot), confirm that the last slot accepts that card type before insertion. If the last slot is mechanically incompatible (e.g., a slot width issue or a termination issue), you cannot move the card there and must find another solution.
10. CP 1430 TCP Software Configuration (COM 1430 / NCM S5)
Once the CP 1430 is seated, configure it from a PG using COM 1430 (or NCM S5 for newer firmware). The configuration is downloaded to the CP via the S5 backplane using the CP's initialization handshake; the CP then boots with the saved parameters.
| Parameter group | Example values |
|---|---|
| IP address | 192.168.1.50 (verify against site plan) |
| Subnet mask | 255.255.255.0 |
| Default router | 192.168.1.1 (omit if peer is on same subnet) |
| MAC address | Default Siemens prefix 08:00:06; override only if duplicate |
| Transport mode | TCP, ISO-on-TCP (RFC 1006), or UDP — choose ISO-on-TCP for S7 / S5 interop |
| TSAP / Port | Port 102 for ISO-on-TCP; TSAP e.g., "S5-CP01" ↔ "S7-CPU01" |
| Connection role | Active (S5 initiates) or Passive (S5 accepts) |
| Connection type | Send/Receive (PG-to-PLC), Fetch/Write (PG-to-PLC variable access), or job interface |
The configuration file generated by COM 1430 is a binary record loaded into the CP's flash. On boot, the CP performs a hardware self-test, initializes the Ethernet controller, and signals readiness on its front-panel LEDs (typical: LINK, RUN, STOP, FAULT). The RUN LED is the primary indicator that the loaded configuration is valid; FAULT indicates an invalid parameter or duplicate IP.
11. Connection Setup: TCP and ISO-on-TCP
For interop with a modern S7-1500 CPU or a third-party device, ISO-on-TCP (RFC 1006) on port 102 is the standard. The CP 1430 may also support raw TCP and UDP, but these require careful handling of segment boundaries — typically the application prepends a length header (P_LEN) so the receiver can reassemble. ISO-on-TCP transparently handles this.
; S5 side STL snippet - sending a 32-byte message via CP 1430
; using SEND-ALL / RECEIVE-ALL job interface
; (block numbers vary by CP 1430 firmware; consult manual)
L DB 100 ; application data DB
T IR ; source pointer
L +32 ; length
T LW 0 ; length word
L KB 1 ; connection ID 1
T LW 2 ; connection ID word
L KS 'S7-CPU01' ; destination TSAP
T LW 4 ; TSAP word 1
L KS 'ISO ' ; "ISO on TCP" tag
T LW 6 ; TSAP word 2
JU FB 244 ; SEND block (CP 1430)
; error handling on RET_VAL follows
For an end-to-end example of an S5-155U with CP 1430 establishing ISO-on-TCP to a S7-1500 CPU, see the Siemens application document "Communication S5-S71500". The same document shows the matching S7-1500 side connection configuration (TSAP, partner IP, active/passive role).
12. Risk Mitigation on a Live Production Line
Stopping the line is rarely permitted. The following sequence minimizes risk for a live S5-155U:
- Pre-stage the swap with the rack powered off briefly during a scheduled mini-stop. Verify all DIP settings and slot tables offline.
- Document the rollback: which card goes back to which slot, original DIP settings, and original DB1. Print and keep at the rack.
- Backup every CPU project including the EPROM image if the CPU uses one. Store on the engineering PC and on a separate USB drive.
- Add a watchdog rung that ignores the new CP's input bytes for the first 10 minutes after power-up, in case the CP is not yet initialized. This prevents nuisance faults.
- Apply power incrementally: PS first, observe P/B LED on the CPU, then perform a warm restart (OB21 / OB22) rather than a cold restart (OB20).
- Monitor the CPU STOP light during the first scan. If the CPU goes to STOP, the most likely cause is an address collision from the new CP 1430 DIP setting.
- Verify peripheral bus by reading a known DI word that was moved and confirming the value matches the field.
- Verify Ethernet by issuing a PING from a laptop on the same subnet (Industrial Ethernet hubs and unmanaged switches are typical on legacy S5 networks).
- Run a controlled test transaction from the new S5 program block through FB 244 SEND against the partner device. Compare with the partner's receive log.
13. Verification Checklist
| Check | Method | Pass criterion |
|---|---|---|
| CP 1430 RUN LED | Visual on front panel | Solid green, no FAULT |
| CPU in RUN | PG online status or front panel | RUN, not STOP; BASP off |
| Moved DI/DQ address | PG online, force field input, read PI/PQ bytes | Same byte number as before swap, value follows field |
| CP base address not colliding | PG online, status of CP region bytes | Bytes readable, no double assignment |
| Ethernet link | PING from engineering PC | Reply from CP 1430 IP |
| ISO-on-TCP connection | PG status display or partner device log | Connection established, last error zero |
| End-to-end data | Trigger SEND from S5 program, observe receive at partner | Data matches, retries < 3 |
| DB1 integrity | Compare DB1 before/after, checksum if tool supports | Unchanged except for any intended CP documentation entries |
14. Field-Proven Caveats
- CP 1430 firmware revisions matter. Older firmware does not support RFC 1006 plus the full TSAP length used by S7-1500/1200. Always cross-check the firmware version against the application document listed in section 11.
- Industrial Ethernet hubs are still common on S5 networks. Verify the CP variant supports 10BASE-T (most do) — older CP 1430 variants may ship with AUI only.
- Coordinator conflicts: if the rack has a second CPU, the Coordinator's IPC flags must be sized in every CPU's DB1 before the CP 1430 starts sending multi-CPU traffic. Skipping this produces silent data loss on inter-CPU messages.
- DO NOT assume hot-swap. S5-155U modules, especially older CPs, are not designed for live insertion. Plan a stop.
- Archive the CP's flash configuration separately from the CPU's STEP 5 project. If the CP fails and is replaced, you can restore parameters without re-commissioning from scratch.
15. Frequently Asked Questions
Can I install a CP 1430 TCP in the last slot of an S5-155U central rack?
Generally no. The last slot of many S5-155U central rack variants is mechanically or electrically restricted. The CP 1430 TCP must be installed in a mid-peripheral slot that the system manual chapter 4.1 explicitly lists as CP-allowed.
Does moving a digital I/O card require changing the STEP 5 program?
No. DIP switches on the card set its P/Q byte address, so the address travels with the card. As long as no two cards claim the same address, no program change is needed.
Do I need a Coordinator card for a single-CPU retrofit?
No. The Coordinator (Co) is only required for multi-CPU configurations and IPC flag management. A single-CPU rack can host a CP 1430 without a Coordinator.
What address does the CP 1430 use for its dual-port RAM?
The CP 1430's DIP switches set a peripheral base address (commonly in the high byte range, e.g., 252). It must not collide with any DI/DQ/AI/AQ address. Always list every card's DIP address before power-on.
Which transport should I use to talk to a S7-1500 — TCP or ISO-on-TCP?
Use ISO-on-TCP (RFC 1006) on port 102. It transparently handles segment boundaries and is the standard for S5-to-S7 communication as documented in the Siemens CP 1430 TCP product page and the S5-S71500 application document.
Why does my S5 CPU go to STOP after installing the CP 1430?
Most often the CP's DIP-encoded base address collides with a DI/DQ card's address, or DB1 has an inconsistent entry. Power off, re-check the rack layout sheet and DB1 against the manuals, then power up again. Verify the Siemens CP 1430 TCP configuration FAQ for the expected parameter set.