Read S7-1500 CPU and HMI IP Address Programmatically in TIA

David Krause25 min read
SiemensTechnical ReferenceTIA Portal
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Read S7-1500 CPU and Comfort Panel HMI IP Address Programmatically in TIA Portal

Engineers commissioning SIMATIC S7-1500 systems frequently need to read the active IP address of the local CPU and the connected Comfort Panel HMI from inside the user program and display it on the HMI screen for service and diagnostics. The S7-1500 family does not expose the IP address as a simple system tag; you must use either a data record read (RDREC) on the local PROFINET interface, the Siemens LDP "Get_IP_Address" function block, the GetStationInfo system instruction, or a runtime-side query from the HMI. This reference documents all four approaches that work in TIA Portal V15.1 Update 3 and later, explains why error 8092 ("LADDR does not address a PROFINET IO device") appears when GetStationInfo or RDREC is misused, and provides a complete SCL implementation plus a WinCC VBScript for the HMI side.

1. Problem Statement and Approach

Reading the IP address of the local PLC and a Comfort Panel HMI is not a standard tag in TIA Portal. Most users first try one of the system libraries and fail, then fall back to hardware identifiers and data records. The selection of the right method depends on three constraints:

  1. What is being read: local CPU IP, HMI IP, or remote PROFINET device IP.
  2. The role of the HMI in the project topology: the HMI can be a PROFINET IO device (rare on Comfort Panels, more common on PC-based HMI systems with WinCC Professional) or an HMI panel connected via PROFINET/Industrial Ethernet without being an IO device.
  3. Where the read must run: from the CPU user program (SCL/LAD/FBD) or from the HMI runtime (VBScript, PowerShell, C-script on WinCC RT Professional).
Method Reads Where it runs Required instruction / library Limitations
RDREC on local PN interface, data record 0xFEF0 Local CPU IP / subnet / gateway CPU user program Standard RDREC instruction Reads only the local interface; no HMI support
Siemens LDP "Get_IP_Address" FB Local CPU or any PROFINET IO device CPU user program "Library of General Functions" (LDP) — entry ID 109753067 Device must be a PROFINET IO device with a hardware identifier
GetStationInfo Interface information of a local PN port CPU user program Built-in S7-1500 instruction Requires a valid HW identifier for a PROFINET interface
WinCC VBScript / PowerShell on HMI HMI's own IP address HMI runtime WinCC Professional / Comfort script environment HMI must have the script runtime enabled

For a typical machine with a CPU 1513 and a TP1200 Comfort Panel, the most robust approach is RDREC for the CPU and a WinCC VBScript for the HMI, with the LDP library as a fallback when a single FB must serve both devices. The HMI cannot be queried by the CPU via PROFINET data records because the Comfort Panel is not a PROFINET IO device in a standard HMI project; it is a supervisor on the network that exchanges tags with the CPU over S7 communication, not IO data.

2. Prerequisites: Hardware, Firmware, and Software

Component Recommended version Notes
CPU S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0) firmware V2.6 or later Single-port PN; HW identifier 64 = X1 interface
CPU (alternates) 1511-1 PN, 1515-2 PN, 1516-3 PN/DP, 1517-3 PN/DP, 1518-4 PN/DP X1 = HW 64, X2 = HW 65, X3 = HW 66, X4 = HW 67 (verify in Device View)
HMI SIMATIC TP1200 Comfort (6AV2124-1MC01-0AX0) or TP1500 / TP1900 / TP2200 WinCC Comfort V15.1 Update 3 or later
HMI (PC-based) WinCC Runtime Professional V15.1 Update 3 or later (IPC) Full VBScript and WMI available
TIA Portal V15.1 Update 3 (or V16, V17, V18 with same function blocks) STEP 7 Professional required for S7-1500
Siemens LDP Library "Library of General Functions" V15.1 or later Entry ID 109753067 in Siemens Industry Online Support

Verify the local PROFINET interface HW identifier before writing any code: in the TIA Portal project tree, open Devices & Networks, select the CPU, switch to Device View, click the PROFINET interface port, and read the System constants tab. The constant Local PROFINET interface_1 is HW 64 for the X1 port of a standard CPU 1513.

Note: The HW identifier is project-specific. If you added a CP 1543-1 communications processor or a second PROFINET interface, the numbering will not start at 64. Always confirm the constant name in the project before calling RDREC. A wrong LADDR is the most common cause of error 8092.

3. Network Topology Reference

The diagram below shows the typical reference topology. The CPU 1513 owns the local PROFINET interface (HW 64) on which RDREC operates. The TP1200 is a separate PROFINET node but is not a PROFINET IO device; tag data flows between the CPU and the HMI over S7 communication (PUT/GET or configured tag connections), not over cyclic IO data.

S7-1500 CPU 1513 X1 = HW 64 192.168.0.10 TP1200 Comfort No PROFINET IO 192.168.0.20 PROFINET / S7 192.168.0.0/24 S7 tag S7 tag

4. Method 1 — RDREC on the Local PROFINET Interface

The Siemens "Library of General Functions" (LDP) — entry ID 109753067 documents that the S7-1500 CPU exposes its PROFINET interface parameters through PROFINET data record 0xFEF0 ("IP Suite"). The data record is readable from the user program with the standard RDREC instruction; the LADDR must point to the local PROFINET interface, not a remote IO device. The same library entry also contains a pre-built "Get module information via PROFINET network" example (entry ID 98210758) that reads parameters from any reachable PROFINET device.

4.1 Data Record 0xFEF0 — IP Suite Structure

Offset (bytes) Length (bytes) Field Encoding
0 4 Interface ID Little-endian 32-bit interface selector
4 4 IP address Network byte order (big-endian)
8 4 Subnet mask Network byte order
12 4 Default router Network byte order
16 1 Status 0 = OK, 1 = not configured

Total declared length: 17 bytes. Allocate a byte array of at least MLEN = 18 to be safe; some firmware revisions append an extra padding byte. The IP field is stored in network byte order, so byte 4 = first octet (e.g. 192), byte 5 = second octet (168), and so on. Do not interpret the four bytes as a single DWORD in little-endian order — the resulting value will be the octets reversed.

4.2 SCL Implementation: Reading the CPU IP Address

The block below is a self-contained SCL FB that reads the local IP address on a rising edge of reqRead, parses the four octets, and exposes them as separate output bytes. Place the call in OB1 (cyclic) and create a single-instance DB; the values are persistent as long as the DB is not re-initialized.

FUNCTION_BLOCK "FB_IP_Read_Local"
VAR
    // Trigger control
    reqRead       : BOOL;          // rising edge triggers a new read
    busy          : BOOL;          // RDREC.BUSY
    done          : BOOL;          // RDREC.DONE
    error         : BOOL;          // RDREC.ERROR
    status        : WORD;          // RDREC.STATUS
    rdrecInst     : RDREC;         // RDREC instance
    // Output octets
    ipByte1       : BYTE;          // e.g. 192
    ipByte2       : BYTE;          // e.g. 168
    ipByte3       : BYTE;          // e.g. 0
    ipByte4       : BYTE;          // e.g. 10
    subByte1      : BYTE;
    subByte2      : BYTE;
    subByte3      : BYTE;
    subByte4      : BYTE;
    gwByte1       : BYTE;
    gwByte2       : BYTE;
    gwByte3       : BYTE;
    gwByte4       : BYTE;
    // Working buffer
    buffer        : ARRAY[0..31] OF BYTE;
    triggerEdge   : BOOL;          // edge memory
    pendingReq    : BOOL;          // request pending
END_VAR

BEGIN
    // 1) Detect rising edge of reqRead
    IF reqRead AND NOT triggerEdge THEN
        pendingReq := TRUE;
        busy       := FALSE;
        done       := FALSE;
        error      := FALSE;
    END_IF;
    triggerEdge := reqRead;

    // 2) Call RDREC on the local PN interface.
    //    LADDR = 64 is correct for the X1 port of a CPU 1511/1513/1515/1516/1517.
    //    INDEX 16#FEF0 = IP Suite data record.
    rdrecInst(
        req      := pendingReq AND NOT busy,
        ID       := 64,
        index    := 16#FEF0,
        MLEN     := 18,
        RECORD   := buffer,
        busy     => busy,
        done     => done,
        error    => error,
        status   => status
    );

    // 3) When RDREC finishes, parse the IP Suite fields.
    //    The IP address starts at offset 4, 4 bytes, big-endian.
    IF done AND NOT error THEN
        ipByte1 := buffer[4];
        ipByte2 := buffer[5];
        ipByte3 := buffer[6];
        ipByte4 := buffer[7];
        subByte1 := buffer[8];
        subByte2 := buffer[9];
        subByte3 := buffer[10];
        subByte4 := buffer[11];
        gwByte1 := buffer[12];
        gwByte2 := buffer[13];
        gwByte3 := buffer[14];
        gwByte4 := buffer[15];
        pendingReq := FALSE;
    ELSIF done AND error THEN
        pendingReq := FALSE;
    END_IF;
END_FUNCTION_BLOCK
Field tip: Use a one-shot rising edge detector, not a level-triggered reqRead. RDREC is edge-sensitive: if the REQ input is held high, only the first call transfers; subsequent calls return STATUS = 16#7000 (initial call) and never re-trigger the read. Reset pendingReq only when DONE becomes TRUE.

4.3 LAD/FBD Equivalent Trigger Logic

If you prefer to use LAD instead of SCL, the rising edge detector and the RDREC call can be wired as follows. The P_TRIG instruction captures the rising edge of the trigger button, and a SR flip-flop latches the REQ input until RDREC reports DONE.

// LAD network 1 — rising edge detection
//    reqRead ---| P_TRIG |-- reqPulse
//
// LAD network 2 — request latch
//    reqPulse --[S]   pendingReq
//    done     --[R]   pendingReq
//
// LAD network 3 — RDREC call
//    pendingReq --- RDREC.REQ
//    64          --- RDREC.ID
//    W#16#FEF0   --- RDREC.INDEX
//    18          --- RDREC.MLEN
//    buffer      --- RDREC.RECORD
//
// LAD network 4 — parse on DONE
//    done AND NOT error -- MOVE buffer[4]..[7] -> ipByte1..4
//                        -- MOVE buffer[8]..[11] -> subByte1..4
//                        -- MOVE buffer[12]..[15] -> gwByte1..4

5. HW Identifier 64 — The Local PROFINET Interface

The HW identifier is a system constant generated by TIA Portal during compilation. The table below lists the typical HW identifiers for the PROFINET/Industrial Ethernet interfaces of common S7-1500 CPUs. Always verify in the actual project, because the numbering depends on the device configuration and any inserted CPs (CP 1543-1, CP 1545-1, etc.).

CPU model Port / interface Typical HW identifier System constant name
CPU 1511-1 PN X1 64 Local PROFINET interface_1
CPU 1513-1 PN X1 64 Local PROFINET interface_1
CPU 1515-2 PN X1 64 Local PROFINET interface_1
CPU 1515-2 PN X2 65 Local PROFINET interface_2
CPU 1516-3 PN/DP X1 64 Local PROFINET interface_1
CPU 1516-3 PN/DP X2 65 Local PROFINET interface_2
CPU 1517-3 PN/DP X3 66 Local PROFINET interface_3
CPU 1518-4 PN/DP X4 67 Local PROFINET interface_4

To find the correct constant in your project: select the CPU in the project tree, switch to Device View, click the PROFINET port label (X1, X2, …), and read the value from the Properties > System constants tab. The value also appears in the watch table when you expand the System constants node.

6. RDREC State Machine Reference

RDREC is asynchronous. The call takes several scan cycles to complete. The diagram below shows the four states the FB above can be in, and the transitions driven by REQ, BUSY, DONE, and ERROR.

Idle Trigger REQ Read in flight DONE = TRUE ERROR = TRUE rising edge BUSY=1 no error parse IP capture STATUS

7. Method 2 — GetStationInfo System Function

The GetStationInfo instruction is part of the S7-1500 base instruction set and reads the interface information (MAC address, name, IP) of a local or remote PROFINET interface. Unlike RDREC, it does not require knowledge of the data record index; the instruction handles the index internally. However, it still requires a valid HW identifier for a PROFINET interface.

Parameter Direction Type Description
LADDR IN HW_IO Hardware identifier of the PN/IE interface
MODE IN UINT 1 = MAC + IP, 2 = name of station, 3 = full PROFINET name
STATION_INFO IN_OUT VARIANT Target structure (must be pre-allocated)
BUSY OUT BOOL Active transfer
DONE OUT BOOL Transfer complete
ERROR OUT BOOL Error flag
STATUS OUT WORD Error/status code

A working call for the local PN interface of a CPU 1513 with MODE = 1 looks like this in SCL:

VAR
    info : "typeStationInfo";   // predefined by the GetStationInfo instruction
END_VAR
GetStationInfo(
    LADDR        := 64,
    MODE         := 1,
    STATION_INFO := info,
    BUSY         => busy,
    DONE         => done,
    ERROR        => error,
    STATUS       => status
);
// info.IPAddress[] contains the four octets as USINT
ipByte1 := info.IPAddress[1];
ipByte2 := info.IPAddress[2];
ipByte3 := info.IPAddress[3];
ipByte4 := info.IPAddress[4];

7.1 Why GetStationInfo Returns Error 8092

Error 8092 is one of the PROFINET stack error codes returned by RDREC, GetStationInfo, and similar instructions when the LADDR parameter does not address a PROFINET IO device or PROFINET interface. The relevant status codes are:

STATUS (hex) STATUS (dec) Meaning Likely cause
0x8092 32914 LADDR does not address a PROFINET IO device / interface HW identifier points to a non-PROFINET module (display, backplane, central I/O)
0x8094 32916 IO device not connected / not accessible PROFINET cable disconnected or device powered off
0x80A0 32928 Negative acknowledgement from IO device Device does not support the requested data record
0x80A1 32929 Data record not supported Wrong INDEX; some devices return this for 0xFEF0
0x80C0 32960 Data record read incomplete MLEN too small or transfer aborted
0x80C1 32961 Data record read out of range INDEX not supported on this device

When GetStationInfo fails with 8092, the HW identifier being passed is either a central sub-module of the CPU (the display, backplane, central I/O) or a non-PROFINET object. Use the system constant Local PROFINET interface_1 (typically HW 64) — never a CPU sub-module identifier from the System constants tab that does not contain the words "PROFINET interface".

Important: Some users attempt to pass a hardware identifier obtained by right-clicking the CPU rack in the project tree and selecting Properties > System constants. The list there contains identifiers for every sub-module (the display, the backplane, the central I/O). Only the entries labeled "Local PROFINET interface" are valid LADDR values for RDREC and GetStationInfo.

8. Method 3 — Reading the Comfort Panel HMI IP Address

Reading the HMI's own IP address from a TP1200 Comfort (or any Comfort Panel) is fundamentally different from reading the CPU. The HMI does not expose a PROFINET IO device record that the PLC can read; the HMI is a separate runtime that owns its own network configuration. The HMI's IP address is stored in the Windows Embedded configuration of the panel and can be queried at runtime by:

  1. WinCC VBScript using a WMI query (recommended for WinCC RT Professional and supported on Comfort Panels with the VBScript runtime option enabled).
  2. PowerShell script triggered by a scheduled task or by a button event.
  3. The ipconfig command parsed from its output (the original approach in the field, but locale-fragile).
  4. A WinCC system tag (only available for some HMI types and TIA versions, with limited information).

8.1 Why the HMI Has No Hardware Identifier Like the CPU

A Comfort Panel connected via PROFINET is normally an HMI panel, not a PROFINET IO device. The HMI is a "supervisor" on the network; it exchanges data with the CPU via tag connections (S7 communication), not as an IO device. PROFINET IO data records such as 0xFEF0 are only defined for IO devices, so RDREC cannot be used to query the HMI from the PLC. The HMI's IP must be read from inside the HMI runtime using a script or system function, and then transferred to the PLC via a standard tag connection.

8.2 Approach A — VBScript with WMI (Recommended)

On WinCC Runtime Advanced (Comfort Panels with enabled script runtime) and WinCC Runtime Professional (PC-based), the VBScript environment can access Windows Management Instrumentation (WMI) through the GetObject("winmgmts:\\\\.\\root\\cimv2") call. The WMI class Win32_NetworkAdapterConfiguration returns the IP address of every enabled adapter. The script below should be triggered once on HMI startup (or behind a button) and writes the result to internal HMI tags that the PLC reads via the configured tag connection.

' WinCC VBScript - run on HMI startup or on a button click event
Dim objWMI, colAdapters, objAdapter
Dim sIP, sMask, sGateway

Set objWMI = GetObject("winmgmts:\\\\.\\root\\cimv2")
Set colAdapters = objWMI.ExecQuery( _
    "SELECT IPAddress, IPSubnet, DefaultIPGateway " & _
    "FROM Win32_NetworkAdapterConfiguration WHERE IPEnabled = True")

For Each objAdapter In colAdapters
    If IsArray(objAdapter.IPAddress) Then
        sIP = objAdapter.IPAddress(0)
        sMask = objAdapter.IPSubnet(0)
        If IsArray(objAdapter.DefaultIPGateway) Then
            sGateway = objAdapter.DefaultIPGateway(0)
        Else
            sGateway = "0.0.0.0"
        End If
        Exit For    ' take the first enabled adapter
    End If
Next

' Write to HMI tags (declare these as internal tags in the HMI project)
SmartTags("HMI_IP_String")      = sIP
SmartTags("HMI_Subnet_String")  = sMask
SmartTags("HMI_Gateway_String") = sGateway

' Parse the four octets into separate tags (PLC-friendly representation)
Dim parts
parts = Split(sIP, ".")
If UBound(parts) = 3 Then
    SmartTags("HMI_IP_octet1") = CInt(parts(0))
    SmartTags("HMI_IP_octet2") = CInt(parts(1))
    SmartTags("HMI_IP_octet3") = CInt(parts(2))
    SmartTags("HMI_IP_octet4") = CInt(parts(3))
End If

Create the HMI tags HMI_IP_String, HMI_Subnet_String, HMI_Gateway_String, and HMI_IP_octet1..4 in the HMI tag table, set the connection to the PLC, and configure the PLC to read these tags via standard tag connections (the HMI writes them to the PLC area on change).

8.3 Approach B — PowerShell on a Comfort Panel

On a Comfort Panel that runs Windows Embedded Compact 7 or WEC 2013 (not full Windows), VBScript with WMI is not always available. The most reliable approach on these panels is a scheduled script that writes the IP to a file, combined with an HMI tag that reads the file. The TIA Portal HMI supports file-based tag access on Comfort Panels.

# PowerShell - Save as C:\Temp\GetIP.ps1
$adapter = Get-NetIPAddress -InterfaceAlias "PROFINET" -AddressFamily IPv4 -ErrorAction SilentlyContinue | Select-Object -First 1
if ($adapter) {
    $adapter.IPAddress | Out-File -FilePath "C:\Temp\hmi_ip.txt" -Encoding ASCII
}

On the HMI, configure a tag with the File data source pointing to the file written by the script. The PLC reads the tag value after the script has run. Schedule the PowerShell script to run at startup via the HMI's Scheduler.

8.4 Approach C — Parsing ipconfig Output

The original workaround uses ipconfig redirected to a text file, with the HMI script reading specific lines. This works on all Windows-based HMIs and on Comfort Panels that ship with the Windows Embedded command shell, but it is fragile: locale changes (German vs. English) alter the output strings, and the index of the "IPv4 Address" line varies between Windows versions. Use it only as a last resort.

' WinCC VBScript - ipconfig parsing fallback
Dim oShell, oExec
Set oShell = CreateObject("WScript.Shell")
Set oExec  = oShell.Exec("cmd /c ipconfig > C:\Temp\ipconfig.txt")
WScript.Sleep 1000

Dim oFSO, oFile, sAll, sIP
Set oFSO  = CreateObject("Scripting.FileSystemObject")
Set oFile = oFSO.OpenTextFile("C:\Temp\ipconfig.txt", 1)
sAll = oFile.ReadAll
oFile.Close

' English locale: look for "IPv4 Address. . . . . . . . . . . : "
Dim iStart, iEnd
iStart = InStr(sAll, "IPv4 Address")
If iStart > 0 Then
    iStart = InStr(iStart, sAll, ":")
    iEnd   = InStr(iStart, vbCrLf)
    sIP    = Trim(Mid(sAll, iStart + 1, iEnd - iStart - 1))
End If
SmartTags("HMI_IP_String") = sIP

8.5 HMI Tag Configuration for PLC Visibility

For the PLC to read the HMI's IP octets, configure an S7 tag connection from the HMI to the PLC:

  1. Open the HMI's Connections editor and verify the connection to the CPU uses protocol S7ONLINE or PN/IE.
  2. Open the HMI tag table and add the four octet tags with the same names used in the script (HMI_IP_octet1..4). Set the PLC address to a data block range, e.g. DB100.DBX0.0 (BYTE) for the first octet, DB100.DBX1.0 for the second, and so on.
  3. Set the acquisition mode to Cyclic continuous (1 s) so the PLC always sees the current value.
  4. Compile and download the HMI project. After the HMI startup script runs, the four octets are visible in the PLC at the configured addresses.

9. Method 4 — T_CONFIG for IP Configuration

The T_CONFIG instruction is the counterpart to RDREC for writing IP parameters. It is used when the CPU needs to assign an IP address to a PROFINET device at runtime, for example a replacement device in a redundant topology. Siemens' TIA Portal documentation on assigning IP addresses lists three ways to assign an IP address: STEP 7 (TIA Portal), the SIMATIC Automation Tool, or the T_CONFIG instruction called from the user program.

Mechanism Direction Use case
STEP 7 / TIA Portal Configure at download time Initial commissioning, static IP
SIMATIC Automation Tool Bulk configure from a PC Series commissioning, IP reset across many CPUs
T_CONFIG instruction Configure at runtime from CPU Replacement device, dynamic IP assignment
DCP protocol directly (via FB) Configure at runtime from CPU Advanced use, requires the LDP "Set_IP_Address" FB

T_CONFIG is mentioned here only for completeness: it is a write operation, not a read, and it does not help when the goal is to display the active IP. The original requirement (display the current IP on the HMI) is best served by RDREC on the CPU side and a VBScript on the HMI side.

10. Siemens LDP Library: Get_IP_Address Function Block

The "Library of General Functions" (LDP) — entry ID 109753067 in the Siemens Industry Online Support ships a pre-built FB called Get_IP_Address (and a companion Get_Subnet_Mask, Get_Default_Gateway) that wraps the RDREC call described above. The library also includes a "Get module information via PROFINET network" example (entry ID 98210758) which is useful when the target is a remote IO device, not the local CPU.

To install the library:

  1. Open TIA Portal, switch to the Libraries task card on the right side.
  2. Click Open global library and navigate to the downloaded .zal15_1 file.
  3. Drag the Get_IP_Address FB into a project folder.
  4. Open the FB instance in a cyclic OB (e.g. OB1) and call it with the local PN interface HW identifier (64 for CPU 1513 X1).

The FB returns the IP address as an array of four USINT values plus a STRING representation. It is functionally equivalent to the SCL code in section 4, but tested and maintained by Siemens across TIA versions and CPU firmware generations.

Library update cadence: the LDP library is updated with each TIA Portal release. The V15.1 build of the library supports CPU firmware V2.6 and later. If you upgrade TIA Portal to V16, V17, or V18, also re-download the matching library build; older FBs may not compile against the new instruction set, and the internal data record index for the IP Suite was refined in later versions.

11. Displaying the IP Address on the HMI

With the IP octets stored in PLC tags (e.g. "DB_IP".IP_byte1..4) and the HMI tags (e.g. HMI_IP_octet1..4) populated, the HMI screen can display the values in two ways:

  1. As separate numeric tags: add four IO field controls to the screen, each connected to one of the eight octets. Format each as decimal (0–255). The customer sees "192 . 168 . 0 . 10".
  2. As a STRING tag: concatenate the octets into a single string in the PLC (CONCAT instruction or manual build), pass to the HMI, and display in a single Text/output field. The customer sees "192.168.0.10".

The second approach is more user-friendly but requires string handling on the PLC. Sample SCL code to build the string:

// Build a STRING from the four octets
"DB_IP".IP_String := '';
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String,
                            IN2 := UINT_TO_STRING("DB_IP".IP_byte1));
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String, IN2 := '.');
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String,
                            IN2 := UINT_TO_STRING("DB_IP".IP_byte2));
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String, IN2 := '.');
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String,
                            IN2 := UINT_TO_STRING("DB_IP".IP_byte3));
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String, IN2 := '.');
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String,
                            IN2 := UINT_TO_STRING("DB_IP".IP_byte4));

12. Verification and Commissioning Procedure

  1. Compile and download the user program to the CPU 1513.
  2. Open an online watch table on the instance DB of FB_IP_Read_Local. Force reqRead = TRUE, then immediately back to FALSE.
  3. Verify done = TRUE, error = FALSE, and that ipByte1..4 match the IP configured in TIA Portal's Device View > PROFINET interface > IP address.
  4. Cross-check with the CPU's physical display: from the CPU's main menu, navigate to Settings > Addresses > IP address and confirm the four octets match the watch table values.
  5. On the HMI, navigate to the screen that displays the IP. If the HMI octets are blank, open the HMI's Diagnostics > Runtime logs and check the VBScript error log; typically the WMI query fails on Comfort Panels if the script runtime is not enabled.
  6. Enable script runtime on the HMI: in TIA Portal, select the HMI device, open Properties > Runtime settings > Services, and check Enable VBScript. Recompile and download.
  7. Cycle power on the HMI to confirm the startup script runs and populates the tags.
  8. Cross-check the HMI's IP via the panel's Control Panel > Network & Dial-up Connections menu on Comfort Panels with the Windows Embedded shell.

12.1 Testing in PLCSIM

When using S7-PLCSIM (V15.1 Update 3 or later) for offline testing, the simulated PROFINET interface responds to RDREC just like a real CPU. The IP address is the one configured in the TIA Portal project; PLCSIM does not assign a different IP. The FB_IP_Read_Local block can be exercised end-to-end without physical hardware. Note that the HMI side cannot be tested in PLCSIM; for the HMI VBScript you need either the WinCC RT Simulator (ES) on a development PC or a physical Comfort Panel.

13. Troubleshooting Matrix

Symptom Most likely cause Fix
RDREC returns STATUS = 16#8092 Wrong LADDR; pointing at a CPU sub-module Use the system constant "Local PROFINET interface_1" (HW 64) for X1, HW 65 for X2
RDREC returns STATUS = 16#0000 with no data REQ held high; only the first call transfers Use rising edge detection on REQ; reset REQ after BUSY=1
RDREC returns STATUS = 16#7000 perpetually REQ not set or always high; pending request not cleared Set REQ once, wait for BUSY, do not reset REQ until DONE or ERROR
RDREC returns STATUS = 16#80C0 MLEN smaller than data record size (17 bytes) Set MLEN to 18 (or 20 to be safe)
Parsed IP shows 0.0.0.0 after a successful read Endianness assumption wrong; data record uses big-endian for the IP field Parse bytes [4..7] directly, not as a single DWORD in little-endian order
GetStationInfo returns BUSY=1 forever Calling on a non-existent or off-station HW identifier Verify the LADDR; CPU local interfaces are always available
HMI VBScript does not run on the TP1200 Script runtime disabled in the HMI project Enable VBScript under Properties > Runtime settings > Services, then re-download
HMI script returns empty string for IP WMI not available on Comfort Panel OS image Use the PowerShell or ipconfig fallback approach
HMI IP field does not update on the PLC PLC tag connection not configured for the HMI tags Open the HMI connection in TIA Portal and verify the direction is "Read/Write" with the right DB address
RDREC reads wrong IP after a topology change CPU is configured with a secondary IP or PROFINET device IP Use MODE 1 of GetStationInfo to confirm which IP is active
RDREC works in the project but not after compilation in a different TIA version HW identifier remapped after adding a CP module Re-read the system constants; renumber the LADDR
RDREC returns STATUS = 16#80A1 on a remote IO device The remote device does not support the IP Suite data record Use MODE 1 of GetStationInfo instead, or fall back to a vendor-specific data record
ipconfig parsing returns a non-IPv4 string Multiple IPv6 entries on the same line Search for "IPv4" specifically, not just any IP
GetStationInfo returns STATUS = 16#80B1 Index out of range; wrong MODE selected Use MODE = 1 for MAC + IP, MODE = 2 for name, MODE = 3 for full PROFINET name

14. Endianness and Parsing Caveats

One of the most common mistakes when reading PROFINET data records is endianness. The IP Suite data record (0xFEF0) uses network byte order (big-endian) for the IP address, subnet, and gateway fields. If you read the four bytes as a single DWORD in little-endian order (the default for S7-1500), the resulting IP will be the octets reversed. For example, the IP 192.168.0.10 stored in big-endian is C0 A8 00 0A; if you read it as a little-endian DWORD you get 0A 00 A8 C0 = 10.0.168.192, which is a different (and invalid) IP.

Always parse the four bytes individually:

ipByte1 := buffer[4];   // first octet (most significant in big-endian)
ipByte2 := buffer[5];
ipByte3 := buffer[6];
ipByte4 := buffer[7];   // last octet (least significant)

GetStationInfo already returns the octets in the correct order in its IPAddress[] array, so the endianness pitfall applies only to raw RDREC reads.

15. Security and Operational Notes

  • Read-only access: the IP address is read-only through RDREC and GetStationInfo. To change the IP at runtime, use T_CONFIG or the LDP "Set_IP_Address" FB.
  • Firewall rules on the HMI: WinCC VBScript with WMI does not require any firewall changes on the panel. PowerShell scripts that access the network may need outbound firewall rules if the panel's image is hardened.
  • Script execution policy: if you deploy a PowerShell script, the execution policy on the panel may block unsigned scripts. Use Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass in a wrapper or sign the script.
  • Network segmentation: when the HMI reports its IP back to the PLC, the tag connection uses the existing S7 connection — no additional port is opened. The IP read does not affect network security posture.

16. FAQ

What is the correct data record index to read the IP address of an S7-1500 CPU with RDREC?

Use INDEX = 16#FEF0 (IP Suite). Allocate at least 18 bytes of buffer space; the data record is 17 bytes (4-byte interface ID, 4-byte IP, 4-byte subnet, 4-byte gateway, 1-byte status) and some firmware versions append a padding byte. Pass the local PROFINET interface HW identifier (typically 64 for X1 of a CPU 1513) as the LADDR.

Why does GetStationInfo return error 8092 ("LADDR does not address a PROFINET IO device")?

Error 8092 means the LADDR points to a non-PROFINET object, usually a central sub-module of the CPU (the display, backplane, or central I/O). Only the entries labeled "Local PROFINET interface" in the system constants are valid LADDRs. On a CPU 1513-1 PN, the X1 interface is HW identifier 64.

Why does the HMI not have a hardware identifier in the same way as the CPU?

A Comfort Panel connected via PROFINET is normally an HMI panel, not a PROFINET IO device. The HMI is a supervisor on the network; it exchanges data with the CPU via S7 tag connections, not as an IO device. PROFINET IO data records (such as 0xFEF0) are only defined for IO devices, so RDREC cannot be used to query the HMI from the PLC. The HMI's IP must be read from inside the HMI runtime using VBScript, PowerShell, or the ipconfig fallback.

How do I read the IP address of a Comfort Panel TP1200 from a WinCC Comfort V15.1 runtime?

Create a VBScript in the HMI that queries Win32_NetworkAdapterConfiguration via WMI, parse the IPAddress string, and write the four octets to internal HMI tags. Configure a tag connection from those tags to the PLC. On the PLC, read the four octets from the configured DB range. If WMI is unavailable on the embedded OS, fall back to parsing the output of ipconfig redirected to a file, or use a PowerShell script with a file-based HMI tag.

Can I use T_CONFIG to read the IP address, or is T_CONFIG only for writing?

T_CONFIG writes IP parameters to a PROFINET device at runtime. It is the write counterpart of RDREC and does not return the current IP. For reading, use RDREC on the local PROFINET interface with data record 0xFEF0, or use GetStationInfo with MODE = 1.

Back to blog