CPU 315-2 PN/DP Hardware Overview
The SIMATIC S7-300 CPU 315-2 PN/DP (MLFB 6ES7315-2EH14-0AB0, successor to 6ES7315-2EH13-0AB0) is a mid-range CPU that integrates both a PROFINET interface (X2, two-port switch) and a PROFIBUS-DP interface (X1, MPI/DP combined) on the front panel. It is intended for medium-sized applications in discrete manufacturing where the program and data footprint exceed the CPU 312/314 range but do not justify a CPU 317/319.
| Parameter | Value |
|---|---|
| Work memory (code + data) | 384 KB |
| Load memory (integrated RAM / MMC) | up to 8 MB via SIMATIC MMC |
| Bit instructions execution time | 0.05 µs (min.) |
| PROFINET interface (X2) | 2-port switch, 100 Mbit/s, supports PROFINET IO Controller (max. 128 IO devices), I-Device, TCP/IP, S7 communication, SNMP |
| PROFIBUS interface (X1) | RS485, up to 12 Mbit/s, supports DP Master / DP Slave / MPI |
| S7 communication connections (PG/OP/HMI) | max. 16 |
| OB 1 priority class count | 26 (OB 10/20/35/40/55/80/82/83/85/86/100/102/121/122 etc.) |
| Status/error LEDs | SF, BF (PROFINET), BF (PROFIBUS), MAINT, RUN, STOP, FRCE, LINK, RX/TX |
| Dimensions (W x H x D) | 40 x 125 x 130 mm |
| Firmware versions released | V2.x, V3.x, V3.2 (current at time of writing) |
Reference: SIMATIC S7-300 CPU 315-2 DP / CPU 317-2 DP Manual, Edition 12/2013 (entry ID 12996906) and the CPU 315-2 PN/DP product announcement (entry 19860749) on the Siemens Industry Online Support portal. The CPU type is selected in STEP 7 / TIA Portal under "SIMATIC 300 / CPU 315-2 PN/DP" with the matching firmware version (the firmware on the MMC must match the STEP 7 project or be higher).
Communication Paths to a PC
There are four practical ways to query a CPU 315-2 PN/DP from a host PC. The right choice depends on the available CP card in the PC, the number of concurrent connections required, and the licensing budget.
| Method | PC interface | PLC interface | Max connections | Licensing (SIMATIC NET) |
|---|---|---|---|---|
| PROFINET (Industrial Ethernet, S7 protocol) | On-board NIC or CP 1612 / CP 1623 | X2 PROFINET port | Softnet Lean: 8 / Softnet: 64 / CP 1612: 64 / CP 1623: 128 | Softnet Lean S7 (6GK1704-1LW), Softnet S7 (6GK1704-1SW), CP 1612/1623 driver |
| PROFIBUS DP / MPI | CP 5611, CP 5612, CP 5621, CP 5622 (PCIe) or USB PC-Adapter | X1 MPI/DP port | depends on CP, typically up to 124 DP slaves or 32 MPI nodes | Softnet S7 for PROFIBUS (6GK1704-5SW), CP 5611/CP 5621 driver |
| OPC UA (introduced with V3.x firmware and SIMATIC NET V14+) | Ethernet | X2 PROFINET (CPU cannot natively act as OPC UA server; needs PC-side SIMATIC NET OPC UA wrapper or external gateway) | per OPC UA spec | SIMATIC NET OPC UA Server |
| TCP/IP raw (ISO-on-TCP / RFC1006 via SAPI-S7 / Send/Receive) | Any NIC with SAPI-S7 / libnodave / Snap7 | X2 PROFINET | up to 16 S7 connections (BSEND/BRCV or PUT/GET) | free if using libnodave or Snap7; otherwise Softnet S7 |
For a single PC reading tags and writing them to Excel, the typical setup is the on-board Ethernet NIC + a SIMATIC NET Softnet Lean S7 (6GK1704-1LW) license. Softnet Lean supports up to 8 S7 connections, which is enough for one OPC client and a few diagnostic connections.
Querying System Status with SFC51
Standard library SFC51 "RDSYSST" (Read system status) returns structured information about the CPU state, including LED states, run/stop transitions, communication status, and module faults. This is the function referenced in the field report and is the correct way to query system states from within a STEP 7 program.
SFC51 is part of the Standard Library shipped with STEP 7 V5.5 / TIA Portal V13+. It is documented in the SIMATIC S7-300/400 System and Standard Functions Reference Manual (entry 44240604) and the equivalent TIA Portal help.
SFC51 interface:
// SFC51 - RDSYSST (Read system status)
// Return: RET_VAL (Int) - error code
// REQ : Bool - TRUE to start
// INDEX : Int - sub-list ID (see table below)
// SZL_ID : Word - system status list ID
// DR : Any - destination data area (must be large enough)
// : - SSL_HEADER, then the data records
// BUSY : Bool - true while read in progress
// SZL_HEADER struct: { LENTHDR : Word; N_DR : Word }
CALL SFC51
REQ := TRUE // or triggered cyclically / by event
INDEX := 0 // 0 for single sub-list, 1..32 for partial list
SZL_ID := W#16#0011 // W#16#0011..0019 module identification
DR := P#DB100.DBX0.0 // destination ANY pointer (at least 34 bytes)
RET_VAL:= MW100
BUSY := M101.0;
| SSL ID (hex) | Sub-list index | Content | Typical size |
|---|---|---|---|
| W#16#0000 | 0..3 | SSL list headers (which lists exist on this CPU) | 34 bytes |
| W#16#0011 | 1..4 | Module identification (order number, firmware, version) | 34 bytes |
| W#16#0012 | 1..26 | Module characteristics (rack/slot, type, version) | 34 bytes |
| W#16#0013 | 1..14 | Module diagnostic data (channel faults, diagnostics) | 34..46 bytes |
| W#16#0019 | 1..4 | CPU characteristics (CPU identifier, FW, OPC UA enabled) | 34 bytes |
| W#16#0021 | 1..32 | OB list (which OBs are loaded) | 34 bytes |
| W#16#0022 | 1..3 | Interrupt / time-of-day status | 34 bytes |
| W#16#0024 | 1..2 | LED status (SF, BF, MAINT, RUN, STOP) | 34 bytes |
| W#16#0121 | 1..2 | Communication status (number of S7 connections, KS, ...) | 34 bytes |
| W#16#0131 | 1..2 | Performance data (bit/word/Float timings, memory sizes) | 34..46 bytes |
| W#16#0132 | 1..6 | Communication performance (MPI/DP/PN configuration) | 34 bytes |
| W#16#0A91 | 1..N | Diagnostic buffer entries (also accessible via SFC59 / SFC13) | variable, 34 bytes per entry |
For "what is the CPU doing right now?" the most useful IDs are W#16#0011/0019 (identity), W#16#0024 (LEDs), and W#16#0121 (communication). For fault history, the diagnostic buffer (W#16#0A91) is the same content you see in STEP 7 under PLC > Module Information > Diagnostic Buffer.
Example: read CPU identification into DB100 and then write those bytes to a global DB that the PC polls over OPC.
// OB1 / OB100 - read CPU SSLs once at startup, then periodically
DATA_BLOCK DB100
STRUCT
SSL_HEADER : STRUCT // 4 bytes
LENTHDR : WORD; // length of one data record
N_DR : WORD; // number of records returned
END_STRUCT;
SZL_DATA : ARRAY[1..30] OF BYTE; // up to 30 bytes of payload
END_STRUCT
END_DATA_BLOCK
// Call in OB1 once per second (or in OB35 if you want a constant rate)
CALL SFC51 (REQ:=TRUE, INDEX:=0, SZL_ID:=W#16#0011, DR:=P#DB100.DBX0.0, RET_VAL:=MW200, BUSY:=M201.0);
SIMATIC NET OPC Server Architecture
SIMATIC NET is the PC-side communication package that exposes S7 memory (DBs, M, I, Q, PE, PA, timer/counter) and S7 connections to Windows applications as OPC DA 2.05/3.0 items. The stack has three layers:
- SIMATIC NET PC Station - configured with the SIMATIC NET Commissioning Tool or TIA Portal (since V14). The PC Station is the OPC server's logical owner and contains the "OPC Server" slot and one or more "S7 connection" slots bound to an IE or PROFIBUS CP.
- S7 driver (Softnet S7 Lean, Softnet S7, or CP 1612/1623 firmware) - implements the S7 protocol on the wire (ISO-on-TCP, port 102; or PROFIBUS FDL).
-
OPC DA 3.0 Server - registered as
Siemens.SimaticNET.OPCDA.1. Browsable from any OPC client (Excel, VB, C#, MatrikonOPCSim, Kepware, etc.).
The minimum configuration for a single-PC OPC bridge to one CPU 315-2 PN/DP looks like this in the SIMATIC NET Commissioning Tool:
PC Station
├─ Index 1: WinCC Application (or "OPC Server") -- > slot 1
├─ Index 2: IE General (on-board NIC "Intel I219-V") -- > slot 2
└─ Index 3: S7 Connection -- > slot 3
Partner: S7-300 CPU 315-2 PN/DP, IP 192.168.0.10, rack 0, slot 2
Local connection resource: 0x01..0x0F (auto-assigned by S7DOS)
The S7 connection is then downloaded to the PC Station via "Station Configurator > PC Station > Download to Station". The OPC server reads/writes items using this connection.
Licensing: each "S7 connection" you define consumes one connection license in Softnet S7 Lean. Softnet Lean gives 8 connections for the single license; for a small project with one CPU you do not need a full Softnet S7 license.
Building the OPC-to-Excel Bridge
Excel is not a native OPC client. You need either (a) an OPC client component embedded in Excel via VBA, or (b) a thin Excel plug-in such as SIMATIC NET OPC DataControl. The field report mentions S7Label, S7Number, S7WCVB_Button, and S7WCVB_Slider; these are the SIMATIC NET ActiveX controls that ship with the SIMATIC NET PC software and are intended for use in VB6 / VB.NET (or, as the OP notes, Borland Delphi) form designers. They are not bundled with plain STEP 7 or with the OPC Scout.
For a generic, low-cost path you can use one of the two approaches below.
Option 1: SIMATIC NET OPC + Excel VBA (no STEP 7 required for the OPC side)
The OPC client automation wrapper is a Microsoft COM component that works with any OPC DA 2.0 server, including the SIMATIC NET one. The reference is the SIMATIC NET OPC - Programming with OPC and S7 (entry 15355168) manual.
Procedure:
- Install SIMATIC NET on the PC; activate at least one license (Softnet Lean S7).
- Configure the PC Station with an IE General on the NIC that reaches the CPU and an S7 connection to the CPU.
- Download the PC Station and verify the connection is online (you should see the S7 connection icon turn green in the Station Configurator).
- Open Excel, press Alt+F11, open the VBA editor, and add a reference to Siemens.SimaticNET.OPCDA (or use the generic
OPC Automation 2.0wrapper, file nameOPCDAAuto.dll). - Paste the sample code below into a new module.
- Run the macro. Tags defined in
CONFIG_TAGSwill be written to the named range on the active sheet.
'
' Excel VBA - poll SIMATIC NET OPC DA 2.0 and write to cells
' Requires: OPC Automation 2.0 (OPCDAAuto.dll) reference
' Tested against SIMATIC NET V16/V17 OPC server
'
Option Explicit
Const SERVER_NAME As String = "Siemens.SimaticNET.OPCDA.1"
Const UPDATE_INTERVAL_MS As Long = 1000
Dim WithEvents opcGroup As OPCAutomation.OPCGroup
Dim opcServer As OPCAutomation.OPCServer
Dim opcItems() As OPCAutomation.OPCItem
Dim itemHandles() As Long
Dim itemErrors() As Long
Dim itemValues As Variant
Dim itemTimes() As Date
Sub StartOPC()
Dim itemsCfg(0 To 4, 0 To 1) As Variant ' (item, name)
itemsCfg(0, 0) = "S7:[CPU315_PNDP]DB100,W0" ' Word
itemsCfg(1, 0) = "S7:[CPU315_PNDP]DB100,W2" ' Word
itemsCfg(2, 0) = "S7:[CPU315_PNDP]DB100,REAL4" ' Float
itemsCfg(3, 0) = "S7:[CPU315_PNDP]MB10" ' Merker byte
itemsCfg(4, 0) = "S7:[CPU315_PNDP]E0.0" ' PE bit
itemsCfg(0, 1) = 0: itemsCfg(1, 1) = 0: itemsCfg(2, 1) = 0: itemsCfg(3, 1) = 0: itemsCfg(4, 1) = 0
Set opcServer = New OPCAutomation.OPCServer
opcServer.Connect SERVER_NAME, ""
Set opcGroup = opcServer.OPCGroups.Add("XLSGroup")
opcGroup.IsActive = True
opcGroup.IsSubscribed = True
opcGroup.UpdateRate = UPDATE_INTERVAL_MS
opcGroup.DeadBand = 0
ReDim opcItems(0 To 4)
ReDim itemHandles(0 To 4)
Dim i As Long
For i = 0 To 4
Set opcItems(i) = opcGroup.OPCItems.AddItem(itemsCfg(i, 0), i)
itemHandles(i) = opcItems(i).ServerHandle
Next i
opcGroup.AsyncRead 5, itemHandles, itemErrors, itemValues, itemTimes
End Sub
Private Sub opcGroup_AsyncReadComplete(ByVal TransactionID As Long, _
ByVal NumItems As Long, _
ClientHandles() As Long, _
Values() As Variant, _
Qualities() As Long, _
TimeStamps() As Date, _
Errors() As Long)
Dim i As Long, sheet As Worksheet
Set sheet = ThisWorkbook.Sheets("Live")
For i = 0 To NumItems - 1
sheet.Cells(i + 2, 2).Value = Values(i)
sheet.Cells(i + 2, 3).Value = Qualities(i)
sheet.Cells(i + 2, 4).Value = TimeStamps(i)
Next i
' Trigger next read
opcGroup.AsyncRead NumItems, ClientHandles, Errors, Values, TimeStamps
End Sub
Sub StopOPC()
On Error Resume Next
opcServer.OPCGroups.Remove "XLSGroup"
opcServer.Disconnect
Set opcGroup = Nothing: Set opcServer = Nothing
End Sub
The S7:[CPU315_PNDP] prefix matches the connection name configured in the SIMATIC NET PC Station (or TIA Portal). DB100,W0 means data block 100 word 0. REAL4 reads a 32-bit real. E0.0 reads a process-input bit. Quality of 192 (OPC_QUALITY_GOOD) is required for valid data; 0 (OPC_QUALITY_BAD) indicates a fault - check connection and SZL_ID access permissions in the CPU.
Option 2: OPC DA Bridge to CSV / clipboard (no VB, no ActiveX)
If you cannot install any SIMATIC NET software on the target machine, use the OPC Scout (which ships with SIMATIC NET) to dump tags to a CSV, then refresh Excel's data import. The OPC Scout supports a "DaBrowse" tool and can log to file. This is not real-time but is acceptable for trend logging at 1 sample/second or slower.
ActiveX Controls Without a Full STEP 7 License
The source question asks which components are required to use the SIMATIC NET ActiveX controls (S7Label, S7Number, S7WCVB_Button, S7WCVB_Slider) without buying the full STEP 7 suite. The list of required components is:
| Component | Source | Cost |
|---|---|---|
| S7Label.ocx, S7Number.ocx, S7WCVB_Button.ocx, S7WCVB_Slider.ocx | SIMATIC NET PC Software DVD / ODK 6GK1704-0PA | bundled with paid SIMATIC NET license |
| S7WCS7VB.DLL (C-API wrapper for the S7 data block) | SIMATIC NET PC Software | bundled |
| SIMATIC NET OPC Server (Siemens.SimaticNET.OPCDA.1) | SIMATIC NET runtime, registered as COM service | requires license |
| Softnet S7 Lean license (6GK1704-1LW) | Siemens license server (SLS) | paid; single license |
| Microsoft Visual Basic 6 runtime (msvbvm60.dll) | Windows / VB6 redistributable | free |
The OCX files will register fine on a machine that has no STEP 7, but they will fail at design-time with "License not found" if no Softnet S7 license is active on the SLS. The cheapest paid path is therefore Softnet S7 Lean + the SIMATIC NET runtime. There is no freeware equivalent of these specific Siemens controls.
For Borland Delphi, the controls are still usable because they are standard COM/ActiveX. Use Component > Import ActiveX Control in Delphi to generate the Pascal wrapper, then drop them on a TForm and wire S7WCVB_Button to a tag handle on the OPC server. The same caveats apply: you must still own a SIMATIC NET license to run the controls against a real CPU.
Free and Open-Source Alternatives
Where licensing is a concern, the two most widely deployed open-source S7 stacks are:
| Library | Language | Protocol | Notes |
|---|---|---|---|
| libnodave (Jochen Kühner, 2003-2011, LGPL) | C, with C#/.NET and Java wrappers | ISO-on-TCP (RFC1006), MPI/DP via CP 5611 | Mature; many ports; reads/writes data, no diagnostic buffer parser |
| Snap7 (Davide Nardella, 2014-2024, GPLv2 + commercial) | C, C++/C#/.NET/Java/Python wrappers | S7 ISOTCP only (no MPI/DP from PC) | Active maintenance, supports S7-200/300/400/1200/1500; can act as client or server |
| nodeS7 (node-red-contrib-s7, MIT) | Node.js | S7 ISOTCP | Wraps Snap7; convenient for OPC-UA-over-MQTT |
| python-snap7, opcua-asyncio | Python | ISOTCP + OPC UA | Common path to Excel via xlsxwriter or openpyxl in a Python service |
A typical Snap7 + Python data-pump to Excel looks like this:
# pip install python-snap7 openpyxl
import snap7, time, struct
from openpyxl import Workbook, load_workbook
from openpyxl.utils import get_column_letter
client = snap7.client.Client()
client.connect("192.168.0.10", 0, 1, 102) # IP, rack, slot, port
wb = Workbook(); ws = wb.active; ws.title = "Live"
ws.append(["Time","DB100.Word0","DB100.Word2","DB100.Float4","MB10"])
while True:
db1 = client.db_read(100, 0, 12) # 12 bytes from DB100
w0, w2 = struct.unpack(">HH", db1[0:4])
f4 = struct.unpack(">f", db1[4:8])[0]
mb10 = db1[8]
ws.append([time.strftime("%H:%M:%S"), w0, w2, round(f4,3), mb10])
wb.save("plc_log.xlsx")
time.sleep(1.0)
This bypasses SIMATIC NET entirely; the only cost is development time and the IP connectivity (X2 port on the CPU, port 102/TCP must be reachable; on firmware < V3.0 you may need to enable "PUT/GET" in the CPU's Protection properties).
Diagnostic Buffer and Error Codes
When the OPC server reports bad quality or no data, the diagnostic buffer is the first place to look. SFC59 "RD_REC" reads DS0 (module diagnostic data) and SFC13 "DPNRM_DG" reads DP slave diagnostic frames. For the diagnostic buffer itself, use SFC51 with SZL_ID = W#16#0A91 or use OPC item S7:[CPU]DIAGBUF (only available with SIMATIC NET's "Symbolic OPC Server" mode).
| Hex | Decimal | Meaning | Action |
|---|---|---|---|
| 0x00000000 | 0 | OK | None |
| 0x80000000 | -2147483648 | Server not connected / COM exception | Check Siemens SLS, COM registration, firewall |
| 0x80070005 | 0x80070005 | Access denied (DCOM) | Add user to "Distributed COM Users" group, allow OPC Enum in dcomcnfg |
| 0xC0040007 | -1073471481 | Server cannot convert to requested datatype | Verify item datatype matches DB element type |
| 0xC0040004 | -1073471484 | Item ID invalid | Re-check syntax S7:[Connection]DBx,ByteOffset
|
| 0xC0040006 | -1073471482 | Quality bad - device failure | Check S7 connection, network, CPU in STOP |
| 0xC0040005 | -1073471483 | Item not found | DB may be missing or unlinked; download HW config |
| RET_VAL (hex) | Meaning |
|---|---|
| W#16#0000 | No error |
| W#16#80A1 | Specified SZL_ID does not exist on this CPU |
| W#16#80A2 | Specified SZL_ID is not supported in the selected index |
| W#16#80A3 | Access protection: SSL access disabled by password level |
| W#16#80B1 | Illegal SSL_HEADER (LENTHDR or N_DR wrong) |
| W#16#80C0 | SSL_HEADER conflict (e.g. partial read across records) |
| W#16#80C1 | SSL_HEADER conflict (DS read while SZL read active) |
| W#16#80C2 | SSL_HEADER conflict (record too short for SZL_ID) |
Performance and Timing Considerations
Throughput numbers you should expect on a real CPU 315-2 PN/DP at the X2 PROFINET port (measured with Softnet S7 Lean on a 100 Mbit/s link, payload ~120 bytes per poll):
| Update rate (ms) | Tags | Avg latency (ms) | CPU scan time impact |
|---|---|---|---|
| 100 | 16 | 15-25 | negligible (<0.1 ms) |
| 250 | 32 | 40-60 | negligible |
| 500 | 64 | 80-110 | 0.3-0.5 ms |
| 1000 | 128 | 160-220 | 1-2 ms |
For Excel via VBA, do not poll faster than 500 ms; Excel's redraw will saturate long before the OPC server does. For closed-loop control, use the S7 connection for trigger/event-driven reads (event-OBs + PUT/GET) rather than periodic polling.
Security and Access Protection
From firmware V3.0 onward, the CPU supports a tiered password model that also governs OPC and SFC51 access:
- No password (factory default): read/write HMI access, no SSL access, no SFC51 with W#16#0xxx that contains protected info.
- Read-only password (level 1): HMI can read; writes return W#16#80F1.
- Read/write password (level 2): HMI can read/write; SSL access to W#16#0011..0019 (CPU identification) allowed; SZL IDs above that require level 3.
- Full access (level 3): required for diagnostic buffer (W#16#0A91), OB list, performance data.
Coupling: CPU Properties > Protection > Access Level in STEP 7 / TIA Portal. The same password must be entered on the PC side if the OPC server is configured to authenticate via S7DOS.
Putting It Together: A 20-Line Mini-Reference
- CPU 315-2 PN/DP: 6ES7315-2EH14-0AB0, integrated PROFINET (X2) + PROFIBUS (X1).
- From STEP 7: enable PUT/GET in CPU protection; create a DB (e.g. DB100) for the values you want exposed.
- For system state from inside the PLC: use SFC51 with W#16#0011, W#16#0019, W#16#0024, W#16#0121, W#16#0A91.
- PC: install SIMATIC NET runtime + Softnet S7 Lean (6GK1704-1LW), or use Snap7 / libnodave for free.
- Configure PC Station with an IE General on the right NIC and an S7 connection to the CPU (rack 0, slot 2).
- From Excel: use the OPC Automation 2.0 wrapper, or write a Python/Snap7 pump and save to xlsx.
- ActiveX controls (S7Label, S7Number, etc.) require a paid SIMATIC NET license; there is no freeware version.
- Verify quality=192 on every item; log bad quality and SFC51 RET_VAL for diagnostics.
What is the simplest way to read S7-300 CPU315-2PN/DP tags into Excel?
Install SIMATIC NET with a Softnet S7 Lean license, configure an S7 connection to the CPU in the PC Station, then write a short VBA macro that uses the OPC Automation 2.0 wrapper to call AsyncRead on the OPC group and writes values into named cells on a sheet. The reference manual is SIMATIC NET OPC programming (entry 15355168).
Can I query the CPU without STEP 7 or SIMATIC NET?
Yes. Use Snap7 or libnodave on the PC to open an ISO-on-TCP connection to port 102 on the CPU and read DBs directly. The CPU must have PUT/GET enabled (CPU Properties > Protection > Connection Mechanisms in STEP 7) on firmware < 3.0; from V3.0 it is on by default. Snap7 does not support the TLS-wrapped S7 protocol introduced in firmware V3.2.
How do I read the CPU's system status (e.g. LED states, comms status) from inside the PLC program?
Call SFC51 "RDSYSST" with the appropriate SZL_ID: W#16#0011 for module identification, W#16#0024 for LED status, W#16#0121 for communication status, W#16#0A91 for the diagnostic buffer. The full list of SZL_IDs is in the S7-300/400 System and Standard Functions reference (entry 44240604).
What license do I need for the S7Label, S7Number, S7WCVB_Button, S7WCVB_Slider ActiveX controls?
These controls are part of the SIMATIC NET PC software and require a Softnet S7 license (6GK1704-1LW for Lean, 6GK1704-1SW for full). They will register without STEP 7 installed, but will fail at runtime with "License not found" unless a Softnet license is active on the Siemens License Server on the same machine.