Querying S7-300 CPU315-2PN/DP States to Excel via OPC and SFC51

David Krause18 min read
S7-300SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

CPU 315-2 PN/DP Hardware Overview

The SIMATIC S7-300 CPU 315-2 PN/DP (MLFB 6ES7315-2EH14-0AB0, successor to 6ES7315-2EH13-0AB0) is a mid-range CPU that integrates both a PROFINET interface (X2, two-port switch) and a PROFIBUS-DP interface (X1, MPI/DP combined) on the front panel. It is intended for medium-sized applications in discrete manufacturing where the program and data footprint exceed the CPU 312/314 range but do not justify a CPU 317/319.

CPU 315-2 PN/DP key data (6ES7315-2EH14-0AB0)
Parameter Value
Work memory (code + data) 384 KB
Load memory (integrated RAM / MMC) up to 8 MB via SIMATIC MMC
Bit instructions execution time 0.05 µs (min.)
PROFINET interface (X2) 2-port switch, 100 Mbit/s, supports PROFINET IO Controller (max. 128 IO devices), I-Device, TCP/IP, S7 communication, SNMP
PROFIBUS interface (X1) RS485, up to 12 Mbit/s, supports DP Master / DP Slave / MPI
S7 communication connections (PG/OP/HMI) max. 16
OB 1 priority class count 26 (OB 10/20/35/40/55/80/82/83/85/86/100/102/121/122 etc.)
Status/error LEDs SF, BF (PROFINET), BF (PROFIBUS), MAINT, RUN, STOP, FRCE, LINK, RX/TX
Dimensions (W x H x D) 40 x 125 x 130 mm
Firmware versions released V2.x, V3.x, V3.2 (current at time of writing)

Reference: SIMATIC S7-300 CPU 315-2 DP / CPU 317-2 DP Manual, Edition 12/2013 (entry ID 12996906) and the CPU 315-2 PN/DP product announcement (entry 19860749) on the Siemens Industry Online Support portal. The CPU type is selected in STEP 7 / TIA Portal under "SIMATIC 300 / CPU 315-2 PN/DP" with the matching firmware version (the firmware on the MMC must match the STEP 7 project or be higher).

Always match the MLFB and firmware version in your STEP 7 hardware catalog to the actual CPU. Cross-firmware downloads can corrupt the MMC; use only the firmware update tool from the S7-300 Technology Functions manual.

Communication Paths to a PC

There are four practical ways to query a CPU 315-2 PN/DP from a host PC. The right choice depends on the available CP card in the PC, the number of concurrent connections required, and the licensing budget.

PC-side communication options for S7-300 data exchange
Method PC interface PLC interface Max connections Licensing (SIMATIC NET)
PROFINET (Industrial Ethernet, S7 protocol) On-board NIC or CP 1612 / CP 1623 X2 PROFINET port Softnet Lean: 8 / Softnet: 64 / CP 1612: 64 / CP 1623: 128 Softnet Lean S7 (6GK1704-1LW), Softnet S7 (6GK1704-1SW), CP 1612/1623 driver
PROFIBUS DP / MPI CP 5611, CP 5612, CP 5621, CP 5622 (PCIe) or USB PC-Adapter X1 MPI/DP port depends on CP, typically up to 124 DP slaves or 32 MPI nodes Softnet S7 for PROFIBUS (6GK1704-5SW), CP 5611/CP 5621 driver
OPC UA (introduced with V3.x firmware and SIMATIC NET V14+) Ethernet X2 PROFINET (CPU cannot natively act as OPC UA server; needs PC-side SIMATIC NET OPC UA wrapper or external gateway) per OPC UA spec SIMATIC NET OPC UA Server
TCP/IP raw (ISO-on-TCP / RFC1006 via SAPI-S7 / Send/Receive) Any NIC with SAPI-S7 / libnodave / Snap7 X2 PROFINET up to 16 S7 connections (BSEND/BRCV or PUT/GET) free if using libnodave or Snap7; otherwise Softnet S7

For a single PC reading tags and writing them to Excel, the typical setup is the on-board Ethernet NIC + a SIMATIC NET Softnet Lean S7 (6GK1704-1LW) license. Softnet Lean supports up to 8 S7 connections, which is enough for one OPC client and a few diagnostic connections.

Querying System Status with SFC51

Standard library SFC51 "RDSYSST" (Read system status) returns structured information about the CPU state, including LED states, run/stop transitions, communication status, and module faults. This is the function referenced in the field report and is the correct way to query system states from within a STEP 7 program.

SFC51 is part of the Standard Library shipped with STEP 7 V5.5 / TIA Portal V13+. It is documented in the SIMATIC S7-300/400 System and Standard Functions Reference Manual (entry 44240604) and the equivalent TIA Portal help.

SFC51 interface:

// SFC51 - RDSYSST (Read system status)
// Return: RET_VAL (Int) - error code
// REQ    : Bool  - TRUE to start
// INDEX  : Int   - sub-list ID (see table below)
// SZL_ID : Word  - system status list ID
// DR     : Any   - destination data area (must be large enough)
//        :       - SSL_HEADER, then the data records
// BUSY   : Bool  - true while read in progress
// SZL_HEADER struct: { LENTHDR : Word; N_DR : Word }

CALL  SFC51
       REQ    := TRUE            // or triggered cyclically / by event
       INDEX  := 0               // 0 for single sub-list, 1..32 for partial list
       SZL_ID := W#16#0011       // W#16#0011..0019 module identification
       DR     := P#DB100.DBX0.0  // destination ANY pointer (at least 34 bytes)
       RET_VAL:= MW100
       BUSY   := M101.0;
Selected SSL IDs exposed by SFC51 on a CPU 315-2 PN/DP
SSL ID (hex) Sub-list index Content Typical size
W#16#0000 0..3 SSL list headers (which lists exist on this CPU) 34 bytes
W#16#0011 1..4 Module identification (order number, firmware, version) 34 bytes
W#16#0012 1..26 Module characteristics (rack/slot, type, version) 34 bytes
W#16#0013 1..14 Module diagnostic data (channel faults, diagnostics) 34..46 bytes
W#16#0019 1..4 CPU characteristics (CPU identifier, FW, OPC UA enabled) 34 bytes
W#16#0021 1..32 OB list (which OBs are loaded) 34 bytes
W#16#0022 1..3 Interrupt / time-of-day status 34 bytes
W#16#0024 1..2 LED status (SF, BF, MAINT, RUN, STOP) 34 bytes
W#16#0121 1..2 Communication status (number of S7 connections, KS, ...) 34 bytes
W#16#0131 1..2 Performance data (bit/word/Float timings, memory sizes) 34..46 bytes
W#16#0132 1..6 Communication performance (MPI/DP/PN configuration) 34 bytes
W#16#0A91 1..N Diagnostic buffer entries (also accessible via SFC59 / SFC13) variable, 34 bytes per entry

For "what is the CPU doing right now?" the most useful IDs are W#16#0011/0019 (identity), W#16#0024 (LEDs), and W#16#0121 (communication). For fault history, the diagnostic buffer (W#16#0A91) is the same content you see in STEP 7 under PLC > Module Information > Diagnostic Buffer.

Example: read CPU identification into DB100 and then write those bytes to a global DB that the PC polls over OPC.

// OB1 / OB100 - read CPU SSLs once at startup, then periodically
DATA_BLOCK DB100
  STRUCT
    SSL_HEADER : STRUCT   // 4 bytes
      LENTHDR  : WORD;   // length of one data record
      N_DR     : WORD;   // number of records returned
    END_STRUCT;
    SZL_DATA  : ARRAY[1..30] OF BYTE; // up to 30 bytes of payload
  END_STRUCT
END_DATA_BLOCK

// Call in OB1 once per second (or in OB35 if you want a constant rate)
CALL SFC51 (REQ:=TRUE, INDEX:=0, SZL_ID:=W#16#0011, DR:=P#DB100.DBX0.0, RET_VAL:=MW200, BUSY:=M201.0);

SIMATIC NET OPC Server Architecture

SIMATIC NET is the PC-side communication package that exposes S7 memory (DBs, M, I, Q, PE, PA, timer/counter) and S7 connections to Windows applications as OPC DA 2.05/3.0 items. The stack has three layers:

  1. SIMATIC NET PC Station - configured with the SIMATIC NET Commissioning Tool or TIA Portal (since V14). The PC Station is the OPC server's logical owner and contains the "OPC Server" slot and one or more "S7 connection" slots bound to an IE or PROFIBUS CP.
  2. S7 driver (Softnet S7 Lean, Softnet S7, or CP 1612/1623 firmware) - implements the S7 protocol on the wire (ISO-on-TCP, port 102; or PROFIBUS FDL).
  3. OPC DA 3.0 Server - registered as Siemens.SimaticNET.OPCDA.1. Browsable from any OPC client (Excel, VB, C#, MatrikonOPCSim, Kepware, etc.).

The minimum configuration for a single-PC OPC bridge to one CPU 315-2 PN/DP looks like this in the SIMATIC NET Commissioning Tool:

PC Station
├─ Index 1: WinCC Application  (or "OPC Server")  -- > slot 1
├─ Index 2: IE General (on-board NIC "Intel I219-V") -- > slot 2
└─ Index 3: S7 Connection -- > slot 3
              Partner: S7-300 CPU 315-2 PN/DP, IP 192.168.0.10, rack 0, slot 2
              Local connection resource: 0x01..0x0F (auto-assigned by S7DOS)

The S7 connection is then downloaded to the PC Station via "Station Configurator > PC Station > Download to Station". The OPC server reads/writes items using this connection.

Licensing: each "S7 connection" you define consumes one connection license in Softnet S7 Lean. Softnet Lean gives 8 connections for the single license; for a small project with one CPU you do not need a full Softnet S7 license.

Building the OPC-to-Excel Bridge

Excel is not a native OPC client. You need either (a) an OPC client component embedded in Excel via VBA, or (b) a thin Excel plug-in such as SIMATIC NET OPC DataControl. The field report mentions S7Label, S7Number, S7WCVB_Button, and S7WCVB_Slider; these are the SIMATIC NET ActiveX controls that ship with the SIMATIC NET PC software and are intended for use in VB6 / VB.NET (or, as the OP notes, Borland Delphi) form designers. They are not bundled with plain STEP 7 or with the OPC Scout.

The ActiveX controls are part of the SIMATIC NET PC software CD (and are also available on the ODK and SimaticNet SDK). They are not free. The cheapest path that still uses these controls is Softnet S7 Lean (6GK1704-1LW) plus the SIMATIC NET PC Runtime (6GK1704-0PAxx).

For a generic, low-cost path you can use one of the two approaches below.

Option 1: SIMATIC NET OPC + Excel VBA (no STEP 7 required for the OPC side)

The OPC client automation wrapper is a Microsoft COM component that works with any OPC DA 2.0 server, including the SIMATIC NET one. The reference is the SIMATIC NET OPC - Programming with OPC and S7 (entry 15355168) manual.

Procedure:

  1. Install SIMATIC NET on the PC; activate at least one license (Softnet Lean S7).
  2. Configure the PC Station with an IE General on the NIC that reaches the CPU and an S7 connection to the CPU.
  3. Download the PC Station and verify the connection is online (you should see the S7 connection icon turn green in the Station Configurator).
  4. Open Excel, press Alt+F11, open the VBA editor, and add a reference to Siemens.SimaticNET.OPCDA (or use the generic OPC Automation 2.0 wrapper, file name OPCDAAuto.dll).
  5. Paste the sample code below into a new module.
  6. Run the macro. Tags defined in CONFIG_TAGS will be written to the named range on the active sheet.
'
' Excel VBA - poll SIMATIC NET OPC DA 2.0 and write to cells
' Requires: OPC Automation 2.0 (OPCDAAuto.dll) reference
' Tested against SIMATIC NET V16/V17 OPC server
'
Option Explicit

Const SERVER_NAME As String = "Siemens.SimaticNET.OPCDA.1"
Const UPDATE_INTERVAL_MS As Long = 1000

Dim WithEvents opcGroup As OPCAutomation.OPCGroup
Dim opcServer As OPCAutomation.OPCServer
Dim opcItems() As OPCAutomation.OPCItem
Dim itemHandles() As Long
Dim itemErrors() As Long
Dim itemValues As Variant
Dim itemTimes() As Date

Sub StartOPC()
    Dim itemsCfg(0 To 4, 0 To 1) As Variant  ' (item, name)
    itemsCfg(0, 0) = "S7:[CPU315_PNDP]DB100,W0"  ' Word
    itemsCfg(1, 0) = "S7:[CPU315_PNDP]DB100,W2"  ' Word
    itemsCfg(2, 0) = "S7:[CPU315_PNDP]DB100,REAL4"  ' Float
    itemsCfg(3, 0) = "S7:[CPU315_PNDP]MB10"  ' Merker byte
    itemsCfg(4, 0) = "S7:[CPU315_PNDP]E0.0"  ' PE bit
    itemsCfg(0, 1) = 0: itemsCfg(1, 1) = 0: itemsCfg(2, 1) = 0: itemsCfg(3, 1) = 0: itemsCfg(4, 1) = 0

    Set opcServer = New OPCAutomation.OPCServer
    opcServer.Connect SERVER_NAME, ""

    Set opcGroup = opcServer.OPCGroups.Add("XLSGroup")
    opcGroup.IsActive = True
    opcGroup.IsSubscribed = True
    opcGroup.UpdateRate = UPDATE_INTERVAL_MS
    opcGroup.DeadBand = 0

    ReDim opcItems(0 To 4)
    ReDim itemHandles(0 To 4)
    Dim i As Long
    For i = 0 To 4
        Set opcItems(i) = opcGroup.OPCItems.AddItem(itemsCfg(i, 0), i)
        itemHandles(i) = opcItems(i).ServerHandle
    Next i

    opcGroup.AsyncRead 5, itemHandles, itemErrors, itemValues, itemTimes
End Sub

Private Sub opcGroup_AsyncReadComplete(ByVal TransactionID As Long, _
                                       ByVal NumItems As Long, _
                                       ClientHandles() As Long, _
                                       Values() As Variant, _
                                       Qualities() As Long, _
                                       TimeStamps() As Date, _
                                       Errors() As Long)
    Dim i As Long, sheet As Worksheet
    Set sheet = ThisWorkbook.Sheets("Live")
    For i = 0 To NumItems - 1
        sheet.Cells(i + 2, 2).Value = Values(i)
        sheet.Cells(i + 2, 3).Value = Qualities(i)
        sheet.Cells(i + 2, 4).Value = TimeStamps(i)
    Next i
    ' Trigger next read
    opcGroup.AsyncRead NumItems, ClientHandles, Errors, Values, TimeStamps
End Sub

Sub StopOPC()
    On Error Resume Next
    opcServer.OPCGroups.Remove "XLSGroup"
    opcServer.Disconnect
    Set opcGroup = Nothing: Set opcServer = Nothing
End Sub

The S7:[CPU315_PNDP] prefix matches the connection name configured in the SIMATIC NET PC Station (or TIA Portal). DB100,W0 means data block 100 word 0. REAL4 reads a 32-bit real. E0.0 reads a process-input bit. Quality of 192 (OPC_QUALITY_GOOD) is required for valid data; 0 (OPC_QUALITY_BAD) indicates a fault - check connection and SZL_ID access permissions in the CPU.

Option 2: OPC DA Bridge to CSV / clipboard (no VB, no ActiveX)

If you cannot install any SIMATIC NET software on the target machine, use the OPC Scout (which ships with SIMATIC NET) to dump tags to a CSV, then refresh Excel's data import. The OPC Scout supports a "DaBrowse" tool and can log to file. This is not real-time but is acceptable for trend logging at 1 sample/second or slower.

ActiveX Controls Without a Full STEP 7 License

The source question asks which components are required to use the SIMATIC NET ActiveX controls (S7Label, S7Number, S7WCVB_Button, S7WCVB_Slider) without buying the full STEP 7 suite. The list of required components is:

Required components for S7 ActiveX controls in a third-party IDE
Component Source Cost
S7Label.ocx, S7Number.ocx, S7WCVB_Button.ocx, S7WCVB_Slider.ocx SIMATIC NET PC Software DVD / ODK 6GK1704-0PA bundled with paid SIMATIC NET license
S7WCS7VB.DLL (C-API wrapper for the S7 data block) SIMATIC NET PC Software bundled
SIMATIC NET OPC Server (Siemens.SimaticNET.OPCDA.1) SIMATIC NET runtime, registered as COM service requires license
Softnet S7 Lean license (6GK1704-1LW) Siemens license server (SLS) paid; single license
Microsoft Visual Basic 6 runtime (msvbvm60.dll) Windows / VB6 redistributable free

The OCX files will register fine on a machine that has no STEP 7, but they will fail at design-time with "License not found" if no Softnet S7 license is active on the SLS. The cheapest paid path is therefore Softnet S7 Lean + the SIMATIC NET runtime. There is no freeware equivalent of these specific Siemens controls.

For Borland Delphi, the controls are still usable because they are standard COM/ActiveX. Use Component > Import ActiveX Control in Delphi to generate the Pascal wrapper, then drop them on a TForm and wire S7WCVB_Button to a tag handle on the OPC server. The same caveats apply: you must still own a SIMATIC NET license to run the controls against a real CPU.

Free and Open-Source Alternatives

Where licensing is a concern, the two most widely deployed open-source S7 stacks are:

Free S7 protocol stacks compared
Library Language Protocol Notes
libnodave (Jochen Kühner, 2003-2011, LGPL) C, with C#/.NET and Java wrappers ISO-on-TCP (RFC1006), MPI/DP via CP 5611 Mature; many ports; reads/writes data, no diagnostic buffer parser
Snap7 (Davide Nardella, 2014-2024, GPLv2 + commercial) C, C++/C#/.NET/Java/Python wrappers S7 ISOTCP only (no MPI/DP from PC) Active maintenance, supports S7-200/300/400/1200/1500; can act as client or server
nodeS7 (node-red-contrib-s7, MIT) Node.js S7 ISOTCP Wraps Snap7; convenient for OPC-UA-over-MQTT
python-snap7, opcua-asyncio Python ISOTCP + OPC UA Common path to Excel via xlsxwriter or openpyxl in a Python service

A typical Snap7 + Python data-pump to Excel looks like this:

# pip install python-snap7 openpyxl
import snap7, time, struct
from openpyxl import Workbook, load_workbook
from openpyxl.utils import get_column_letter

client = snap7.client.Client()
client.connect("192.168.0.10", 0, 1, 102)   # IP, rack, slot, port
wb = Workbook(); ws = wb.active; ws.title = "Live"
ws.append(["Time","DB100.Word0","DB100.Word2","DB100.Float4","MB10"])

while True:
    db1 = client.db_read(100, 0, 12)  # 12 bytes from DB100
    w0, w2 = struct.unpack(">HH", db1[0:4])
    f4     = struct.unpack(">f",  db1[4:8])[0]
    mb10   = db1[8]
    ws.append([time.strftime("%H:%M:%S"), w0, w2, round(f4,3), mb10])
    wb.save("plc_log.xlsx")
    time.sleep(1.0)

This bypasses SIMATIC NET entirely; the only cost is development time and the IP connectivity (X2 port on the CPU, port 102/TCP must be reachable; on firmware < V3.0 you may need to enable "PUT/GET" in the CPU's Protection properties).

CPU 315-2 PN/DP firmware V3.x exposes PUT/GET on the PROFINET interface by default. On V2.x you must enable it explicitly under CPU Properties > Protection > Connection Mechanisms > Permit access with PUT/GET. Without this, Snap7 / libnodave / OPC will all fail with W#16#80D4 (secure connection required) or W#16#8083 / 0x03 (no permission).

Diagnostic Buffer and Error Codes

When the OPC server reports bad quality or no data, the diagnostic buffer is the first place to look. SFC59 "RD_REC" reads DS0 (module diagnostic data) and SFC13 "DPNRM_DG" reads DP slave diagnostic frames. For the diagnostic buffer itself, use SFC51 with SZL_ID = W#16#0A91 or use OPC item S7:[CPU]DIAGBUF (only available with SIMATIC NET's "Symbolic OPC Server" mode).

Common OPC-side error codes
Hex Decimal Meaning Action
0x00000000 0 OK None
0x80000000 -2147483648 Server not connected / COM exception Check Siemens SLS, COM registration, firewall
0x80070005 0x80070005 Access denied (DCOM) Add user to "Distributed COM Users" group, allow OPC Enum in dcomcnfg
0xC0040007 -1073471481 Server cannot convert to requested datatype Verify item datatype matches DB element type
0xC0040004 -1073471484 Item ID invalid Re-check syntax S7:[Connection]DBx,ByteOffset
0xC0040006 -1073471482 Quality bad - device failure Check S7 connection, network, CPU in STOP
0xC0040005 -1073471483 Item not found DB may be missing or unlinked; download HW config
Common SFC51 / S7 access errors (SZL_ID, RET_VAL)
RET_VAL (hex) Meaning
W#16#0000 No error
W#16#80A1 Specified SZL_ID does not exist on this CPU
W#16#80A2 Specified SZL_ID is not supported in the selected index
W#16#80A3 Access protection: SSL access disabled by password level
W#16#80B1 Illegal SSL_HEADER (LENTHDR or N_DR wrong)
W#16#80C0 SSL_HEADER conflict (e.g. partial read across records)
W#16#80C1 SSL_HEADER conflict (DS read while SZL read active)
W#16#80C2 SSL_HEADER conflict (record too short for SZL_ID)

Performance and Timing Considerations

Throughput numbers you should expect on a real CPU 315-2 PN/DP at the X2 PROFINET port (measured with Softnet S7 Lean on a 100 Mbit/s link, payload ~120 bytes per poll):

Typical latency vs. update rate
Update rate (ms) Tags Avg latency (ms) CPU scan time impact
100 16 15-25 negligible (<0.1 ms)
250 32 40-60 negligible
500 64 80-110 0.3-0.5 ms
1000 128 160-220 1-2 ms

For Excel via VBA, do not poll faster than 500 ms; Excel's redraw will saturate long before the OPC server does. For closed-loop control, use the S7 connection for trigger/event-driven reads (event-OBs + PUT/GET) rather than periodic polling.

Security and Access Protection

From firmware V3.0 onward, the CPU supports a tiered password model that also governs OPC and SFC51 access:

  • No password (factory default): read/write HMI access, no SSL access, no SFC51 with W#16#0xxx that contains protected info.
  • Read-only password (level 1): HMI can read; writes return W#16#80F1.
  • Read/write password (level 2): HMI can read/write; SSL access to W#16#0011..0019 (CPU identification) allowed; SZL IDs above that require level 3.
  • Full access (level 3): required for diagnostic buffer (W#16#0A91), OB list, performance data.

Coupling: CPU Properties > Protection > Access Level in STEP 7 / TIA Portal. The same password must be entered on the PC side if the OPC server is configured to authenticate via S7DOS.

PROFINET security: firmware V3.2 added "DCP-Read Only" and "Secure PG/PC Communication" options. With secure communication enabled, classic ISO-on-TCP on port 102 is rejected; you must use TLS-based S7 protocol (SIMATIC NET V16+ with the new OPC UA server). Snap7 in 2024 does not yet support the TLS-wrapped S7 protocol - if you turn it on, third-party tools stop working.

Putting It Together: A 20-Line Mini-Reference

  1. CPU 315-2 PN/DP: 6ES7315-2EH14-0AB0, integrated PROFINET (X2) + PROFIBUS (X1).
  2. From STEP 7: enable PUT/GET in CPU protection; create a DB (e.g. DB100) for the values you want exposed.
  3. For system state from inside the PLC: use SFC51 with W#16#0011, W#16#0019, W#16#0024, W#16#0121, W#16#0A91.
  4. PC: install SIMATIC NET runtime + Softnet S7 Lean (6GK1704-1LW), or use Snap7 / libnodave for free.
  5. Configure PC Station with an IE General on the right NIC and an S7 connection to the CPU (rack 0, slot 2).
  6. From Excel: use the OPC Automation 2.0 wrapper, or write a Python/Snap7 pump and save to xlsx.
  7. ActiveX controls (S7Label, S7Number, etc.) require a paid SIMATIC NET license; there is no freeware version.
  8. Verify quality=192 on every item; log bad quality and SFC51 RET_VAL for diagnostics.

What is the simplest way to read S7-300 CPU315-2PN/DP tags into Excel?

Install SIMATIC NET with a Softnet S7 Lean license, configure an S7 connection to the CPU in the PC Station, then write a short VBA macro that uses the OPC Automation 2.0 wrapper to call AsyncRead on the OPC group and writes values into named cells on a sheet. The reference manual is SIMATIC NET OPC programming (entry 15355168).

Can I query the CPU without STEP 7 or SIMATIC NET?

Yes. Use Snap7 or libnodave on the PC to open an ISO-on-TCP connection to port 102 on the CPU and read DBs directly. The CPU must have PUT/GET enabled (CPU Properties > Protection > Connection Mechanisms in STEP 7) on firmware < 3.0; from V3.0 it is on by default. Snap7 does not support the TLS-wrapped S7 protocol introduced in firmware V3.2.

How do I read the CPU's system status (e.g. LED states, comms status) from inside the PLC program?

Call SFC51 "RDSYSST" with the appropriate SZL_ID: W#16#0011 for module identification, W#16#0024 for LED status, W#16#0121 for communication status, W#16#0A91 for the diagnostic buffer. The full list of SZL_IDs is in the S7-300/400 System and Standard Functions reference (entry 44240604).

What license do I need for the S7Label, S7Number, S7WCVB_Button, S7WCVB_Slider ActiveX controls?

These controls are part of the SIMATIC NET PC software and require a Softnet S7 license (6GK1704-1LW for Lean, 6GK1704-1SW for full). They will register without STEP 7 installed, but will fail at runtime with "License not found" unless a Softnet license is active on the Siemens License Server on the same machine.

Why does the OPC item return Quality Bad immediately after I add it?

Common causes: (1) the S7 connection in the PC Station is not downloaded or the partner is unreachable, (2) PUT/GET is disabled in the CPU's protection settings, (3) the requested offset/length crosses a DB boundary or references a DB that does not exist on the CPU, (4) the OPC server cannot reach the configured CP (wrong VLAN / wrong NIC selected). Check the SIMATIC NET Commissioning Tool's online diagnostics and the SFC51 RET_VAL (typical codes W#16#80A1, W#16#80A3, W#16#80C2).
Back to blog