Read S7-1500 CPU and Comfort Panel HMI IP Address Programmatically in TIA Portal
Engineers commissioning SIMATIC S7-1500 systems frequently need to read the active IP address of the local CPU and the connected Comfort Panel HMI from inside the user program and display it on the HMI screen for service and diagnostics. The S7-1500 family does not expose the IP address as a simple system tag; you must use either a data record read (RDREC) on the local PROFINET interface, the Siemens LDP "Get_IP_Address" function block, the GetStationInfo system instruction, or a runtime-side query from the HMI. This reference documents all four approaches that work in TIA Portal V15.1 Update 3 and later, explains why error 8092 ("LADDR does not address a PROFINET IO device") appears when GetStationInfo or RDREC is misused, and provides a complete SCL implementation plus a WinCC VBScript for the HMI side.
1. Problem Statement and Approach
Reading the IP address of the local PLC and a Comfort Panel HMI is not a standard tag in TIA Portal. Most users first try one of the system libraries and fail, then fall back to hardware identifiers and data records. The selection of the right method depends on three constraints:
- What is being read: local CPU IP, HMI IP, or remote PROFINET device IP.
- The role of the HMI in the project topology: the HMI can be a PROFINET IO device (rare on Comfort Panels, more common on PC-based HMI systems with WinCC Professional) or an HMI panel connected via PROFINET/Industrial Ethernet without being an IO device.
- Where the read must run: from the CPU user program (SCL/LAD/FBD) or from the HMI runtime (VBScript, PowerShell, C-script on WinCC RT Professional).
| Method | Reads | Where it runs | Required instruction / library | Limitations |
|---|---|---|---|---|
| RDREC on local PN interface, data record 0xFEF0 | Local CPU IP / subnet / gateway | CPU user program | Standard RDREC instruction | Reads only the local interface; no HMI support |
| Siemens LDP "Get_IP_Address" FB | Local CPU or any PROFINET IO device | CPU user program | "Library of General Functions" (LDP) — entry ID 109753067 | Device must be a PROFINET IO device with a hardware identifier |
| GetStationInfo | Interface information of a local PN port | CPU user program | Built-in S7-1500 instruction | Requires a valid HW identifier for a PROFINET interface |
| WinCC VBScript / PowerShell on HMI | HMI's own IP address | HMI runtime | WinCC Professional / Comfort script environment | HMI must have the script runtime enabled |
For a typical machine with a CPU 1513 and a TP1200 Comfort Panel, the most robust approach is RDREC for the CPU and a WinCC VBScript for the HMI, with the LDP library as a fallback when a single FB must serve both devices. The HMI cannot be queried by the CPU via PROFINET data records because the Comfort Panel is not a PROFINET IO device in a standard HMI project; it is a supervisor on the network that exchanges tags with the CPU over S7 communication, not IO data.
2. Prerequisites: Hardware, Firmware, and Software
| Component | Recommended version | Notes |
|---|---|---|
| CPU | S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0) firmware V2.6 or later | Single-port PN; HW identifier 64 = X1 interface |
| CPU (alternates) | 1511-1 PN, 1515-2 PN, 1516-3 PN/DP, 1517-3 PN/DP, 1518-4 PN/DP | X1 = HW 64, X2 = HW 65, X3 = HW 66, X4 = HW 67 (verify in Device View) |
| HMI | SIMATIC TP1200 Comfort (6AV2124-1MC01-0AX0) or TP1500 / TP1900 / TP2200 | WinCC Comfort V15.1 Update 3 or later |
| HMI (PC-based) | WinCC Runtime Professional V15.1 Update 3 or later (IPC) | Full VBScript and WMI available |
| TIA Portal | V15.1 Update 3 (or V16, V17, V18 with same function blocks) | STEP 7 Professional required for S7-1500 |
| Siemens LDP Library | "Library of General Functions" V15.1 or later | Entry ID 109753067 in Siemens Industry Online Support |
Verify the local PROFINET interface HW identifier before writing any code: in the TIA Portal project tree, open Devices & Networks, select the CPU, switch to Device View, click the PROFINET interface port, and read the System constants tab. The constant Local PROFINET interface_1 is HW 64 for the X1 port of a standard CPU 1513.
3. Network Topology Reference
The diagram below shows the typical reference topology. The CPU 1513 owns the local PROFINET interface (HW 64) on which RDREC operates. The TP1200 is a separate PROFINET node but is not a PROFINET IO device; tag data flows between the CPU and the HMI over S7 communication (PUT/GET or configured tag connections), not over cyclic IO data.
4. Method 1 — RDREC on the Local PROFINET Interface
The Siemens "Library of General Functions" (LDP) — entry ID 109753067 documents that the S7-1500 CPU exposes its PROFINET interface parameters through PROFINET data record 0xFEF0 ("IP Suite"). The data record is readable from the user program with the standard RDREC instruction; the LADDR must point to the local PROFINET interface, not a remote IO device. The same library entry also contains a pre-built "Get module information via PROFINET network" example (entry ID 98210758) that reads parameters from any reachable PROFINET device.
4.1 Data Record 0xFEF0 — IP Suite Structure
| Offset (bytes) | Length (bytes) | Field | Encoding |
|---|---|---|---|
| 0 | 4 | Interface ID | Little-endian 32-bit interface selector |
| 4 | 4 | IP address | Network byte order (big-endian) |
| 8 | 4 | Subnet mask | Network byte order |
| 12 | 4 | Default router | Network byte order |
| 16 | 1 | Status | 0 = OK, 1 = not configured |
Total declared length: 17 bytes. Allocate a byte array of at least MLEN = 18 to be safe; some firmware revisions append an extra padding byte. The IP field is stored in network byte order, so byte 4 = first octet (e.g. 192), byte 5 = second octet (168), and so on. Do not interpret the four bytes as a single DWORD in little-endian order — the resulting value will be the octets reversed.
4.2 SCL Implementation: Reading the CPU IP Address
The block below is a self-contained SCL FB that reads the local IP address on a rising edge of reqRead, parses the four octets, and exposes them as separate output bytes. Place the call in OB1 (cyclic) and create a single-instance DB; the values are persistent as long as the DB is not re-initialized.
FUNCTION_BLOCK "FB_IP_Read_Local"
VAR
// Trigger control
reqRead : BOOL; // rising edge triggers a new read
busy : BOOL; // RDREC.BUSY
done : BOOL; // RDREC.DONE
error : BOOL; // RDREC.ERROR
status : WORD; // RDREC.STATUS
rdrecInst : RDREC; // RDREC instance
// Output octets
ipByte1 : BYTE; // e.g. 192
ipByte2 : BYTE; // e.g. 168
ipByte3 : BYTE; // e.g. 0
ipByte4 : BYTE; // e.g. 10
subByte1 : BYTE;
subByte2 : BYTE;
subByte3 : BYTE;
subByte4 : BYTE;
gwByte1 : BYTE;
gwByte2 : BYTE;
gwByte3 : BYTE;
gwByte4 : BYTE;
// Working buffer
buffer : ARRAY[0..31] OF BYTE;
triggerEdge : BOOL; // edge memory
pendingReq : BOOL; // request pending
END_VAR
BEGIN
// 1) Detect rising edge of reqRead
IF reqRead AND NOT triggerEdge THEN
pendingReq := TRUE;
busy := FALSE;
done := FALSE;
error := FALSE;
END_IF;
triggerEdge := reqRead;
// 2) Call RDREC on the local PN interface.
// LADDR = 64 is correct for the X1 port of a CPU 1511/1513/1515/1516/1517.
// INDEX 16#FEF0 = IP Suite data record.
rdrecInst(
req := pendingReq AND NOT busy,
ID := 64,
index := 16#FEF0,
MLEN := 18,
RECORD := buffer,
busy => busy,
done => done,
error => error,
status => status
);
// 3) When RDREC finishes, parse the IP Suite fields.
// The IP address starts at offset 4, 4 bytes, big-endian.
IF done AND NOT error THEN
ipByte1 := buffer[4];
ipByte2 := buffer[5];
ipByte3 := buffer[6];
ipByte4 := buffer[7];
subByte1 := buffer[8];
subByte2 := buffer[9];
subByte3 := buffer[10];
subByte4 := buffer[11];
gwByte1 := buffer[12];
gwByte2 := buffer[13];
gwByte3 := buffer[14];
gwByte4 := buffer[15];
pendingReq := FALSE;
ELSIF done AND error THEN
pendingReq := FALSE;
END_IF;
END_FUNCTION_BLOCK
reqRead. RDREC is edge-sensitive: if the REQ input is held high, only the first call transfers; subsequent calls return STATUS = 16#7000 (initial call) and never re-trigger the read. Reset pendingReq only when DONE becomes TRUE.4.3 LAD/FBD Equivalent Trigger Logic
If you prefer to use LAD instead of SCL, the rising edge detector and the RDREC call can be wired as follows. The P_TRIG instruction captures the rising edge of the trigger button, and a SR flip-flop latches the REQ input until RDREC reports DONE.
// LAD network 1 — rising edge detection
// reqRead ---| P_TRIG |-- reqPulse
//
// LAD network 2 — request latch
// reqPulse --[S] pendingReq
// done --[R] pendingReq
//
// LAD network 3 — RDREC call
// pendingReq --- RDREC.REQ
// 64 --- RDREC.ID
// W#16#FEF0 --- RDREC.INDEX
// 18 --- RDREC.MLEN
// buffer --- RDREC.RECORD
//
// LAD network 4 — parse on DONE
// done AND NOT error -- MOVE buffer[4]..[7] -> ipByte1..4
// -- MOVE buffer[8]..[11] -> subByte1..4
// -- MOVE buffer[12]..[15] -> gwByte1..4
5. HW Identifier 64 — The Local PROFINET Interface
The HW identifier is a system constant generated by TIA Portal during compilation. The table below lists the typical HW identifiers for the PROFINET/Industrial Ethernet interfaces of common S7-1500 CPUs. Always verify in the actual project, because the numbering depends on the device configuration and any inserted CPs (CP 1543-1, CP 1545-1, etc.).
| CPU model | Port / interface | Typical HW identifier | System constant name |
|---|---|---|---|
| CPU 1511-1 PN | X1 | 64 | Local PROFINET interface_1 |
| CPU 1513-1 PN | X1 | 64 | Local PROFINET interface_1 |
| CPU 1515-2 PN | X1 | 64 | Local PROFINET interface_1 |
| CPU 1515-2 PN | X2 | 65 | Local PROFINET interface_2 |
| CPU 1516-3 PN/DP | X1 | 64 | Local PROFINET interface_1 |
| CPU 1516-3 PN/DP | X2 | 65 | Local PROFINET interface_2 |
| CPU 1517-3 PN/DP | X3 | 66 | Local PROFINET interface_3 |
| CPU 1518-4 PN/DP | X4 | 67 | Local PROFINET interface_4 |
To find the correct constant in your project: select the CPU in the project tree, switch to Device View, click the PROFINET port label (X1, X2, …), and read the value from the Properties > System constants tab. The value also appears in the watch table when you expand the System constants node.
6. RDREC State Machine Reference
RDREC is asynchronous. The call takes several scan cycles to complete. The diagram below shows the four states the FB above can be in, and the transitions driven by REQ, BUSY, DONE, and ERROR.
7. Method 2 — GetStationInfo System Function
The GetStationInfo instruction is part of the S7-1500 base instruction set and reads the interface information (MAC address, name, IP) of a local or remote PROFINET interface. Unlike RDREC, it does not require knowledge of the data record index; the instruction handles the index internally. However, it still requires a valid HW identifier for a PROFINET interface.
| Parameter | Direction | Type | Description |
|---|---|---|---|
| LADDR | IN | HW_IO | Hardware identifier of the PN/IE interface |
| MODE | IN | UINT | 1 = MAC + IP, 2 = name of station, 3 = full PROFINET name |
| STATION_INFO | IN_OUT | VARIANT | Target structure (must be pre-allocated) |
| BUSY | OUT | BOOL | Active transfer |
| DONE | OUT | BOOL | Transfer complete |
| ERROR | OUT | BOOL | Error flag |
| STATUS | OUT | WORD | Error/status code |
A working call for the local PN interface of a CPU 1513 with MODE = 1 looks like this in SCL:
VAR
info : "typeStationInfo"; // predefined by the GetStationInfo instruction
END_VAR
GetStationInfo(
LADDR := 64,
MODE := 1,
STATION_INFO := info,
BUSY => busy,
DONE => done,
ERROR => error,
STATUS => status
);
// info.IPAddress[] contains the four octets as USINT
ipByte1 := info.IPAddress[1];
ipByte2 := info.IPAddress[2];
ipByte3 := info.IPAddress[3];
ipByte4 := info.IPAddress[4];
7.1 Why GetStationInfo Returns Error 8092
Error 8092 is one of the PROFINET stack error codes returned by RDREC, GetStationInfo, and similar instructions when the LADDR parameter does not address a PROFINET IO device or PROFINET interface. The relevant status codes are:
| STATUS (hex) | STATUS (dec) | Meaning | Likely cause |
|---|---|---|---|
| 0x8092 | 32914 | LADDR does not address a PROFINET IO device / interface | HW identifier points to a non-PROFINET module (display, backplane, central I/O) |
| 0x8094 | 32916 | IO device not connected / not accessible | PROFINET cable disconnected or device powered off |
| 0x80A0 | 32928 | Negative acknowledgement from IO device | Device does not support the requested data record |
| 0x80A1 | 32929 | Data record not supported | Wrong INDEX; some devices return this for 0xFEF0 |
| 0x80C0 | 32960 | Data record read incomplete | MLEN too small or transfer aborted |
| 0x80C1 | 32961 | Data record read out of range | INDEX not supported on this device |
When GetStationInfo fails with 8092, the HW identifier being passed is either a central sub-module of the CPU (the display, backplane, central I/O) or a non-PROFINET object. Use the system constant Local PROFINET interface_1 (typically HW 64) — never a CPU sub-module identifier from the System constants tab that does not contain the words "PROFINET interface".
8. Method 3 — Reading the Comfort Panel HMI IP Address
Reading the HMI's own IP address from a TP1200 Comfort (or any Comfort Panel) is fundamentally different from reading the CPU. The HMI does not expose a PROFINET IO device record that the PLC can read; the HMI is a separate runtime that owns its own network configuration. The HMI's IP address is stored in the Windows Embedded configuration of the panel and can be queried at runtime by:
- WinCC VBScript using a WMI query (recommended for WinCC RT Professional and supported on Comfort Panels with the VBScript runtime option enabled).
- PowerShell script triggered by a scheduled task or by a button event.
- The
ipconfigcommand parsed from its output (the original approach in the field, but locale-fragile). - A WinCC system tag (only available for some HMI types and TIA versions, with limited information).
8.1 Why the HMI Has No Hardware Identifier Like the CPU
A Comfort Panel connected via PROFINET is normally an HMI panel, not a PROFINET IO device. The HMI is a "supervisor" on the network; it exchanges data with the CPU via tag connections (S7 communication), not as an IO device. PROFINET IO data records such as 0xFEF0 are only defined for IO devices, so RDREC cannot be used to query the HMI from the PLC. The HMI's IP must be read from inside the HMI runtime using a script or system function, and then transferred to the PLC via a standard tag connection.
8.2 Approach A — VBScript with WMI (Recommended)
On WinCC Runtime Advanced (Comfort Panels with enabled script runtime) and WinCC Runtime Professional (PC-based), the VBScript environment can access Windows Management Instrumentation (WMI) through the GetObject("winmgmts:\\\\.\\root\\cimv2") call. The WMI class Win32_NetworkAdapterConfiguration returns the IP address of every enabled adapter. The script below should be triggered once on HMI startup (or behind a button) and writes the result to internal HMI tags that the PLC reads via the configured tag connection.
' WinCC VBScript - run on HMI startup or on a button click event
Dim objWMI, colAdapters, objAdapter
Dim sIP, sMask, sGateway
Set objWMI = GetObject("winmgmts:\\\\.\\root\\cimv2")
Set colAdapters = objWMI.ExecQuery( _
"SELECT IPAddress, IPSubnet, DefaultIPGateway " & _
"FROM Win32_NetworkAdapterConfiguration WHERE IPEnabled = True")
For Each objAdapter In colAdapters
If IsArray(objAdapter.IPAddress) Then
sIP = objAdapter.IPAddress(0)
sMask = objAdapter.IPSubnet(0)
If IsArray(objAdapter.DefaultIPGateway) Then
sGateway = objAdapter.DefaultIPGateway(0)
Else
sGateway = "0.0.0.0"
End If
Exit For ' take the first enabled adapter
End If
Next
' Write to HMI tags (declare these as internal tags in the HMI project)
SmartTags("HMI_IP_String") = sIP
SmartTags("HMI_Subnet_String") = sMask
SmartTags("HMI_Gateway_String") = sGateway
' Parse the four octets into separate tags (PLC-friendly representation)
Dim parts
parts = Split(sIP, ".")
If UBound(parts) = 3 Then
SmartTags("HMI_IP_octet1") = CInt(parts(0))
SmartTags("HMI_IP_octet2") = CInt(parts(1))
SmartTags("HMI_IP_octet3") = CInt(parts(2))
SmartTags("HMI_IP_octet4") = CInt(parts(3))
End If
Create the HMI tags HMI_IP_String, HMI_Subnet_String, HMI_Gateway_String, and HMI_IP_octet1..4 in the HMI tag table, set the connection to the PLC, and configure the PLC to read these tags via standard tag connections (the HMI writes them to the PLC area on change).
8.3 Approach B — PowerShell on a Comfort Panel
On a Comfort Panel that runs Windows Embedded Compact 7 or WEC 2013 (not full Windows), VBScript with WMI is not always available. The most reliable approach on these panels is a scheduled script that writes the IP to a file, combined with an HMI tag that reads the file. The TIA Portal HMI supports file-based tag access on Comfort Panels.
# PowerShell - Save as C:\Temp\GetIP.ps1
$adapter = Get-NetIPAddress -InterfaceAlias "PROFINET" -AddressFamily IPv4 -ErrorAction SilentlyContinue | Select-Object -First 1
if ($adapter) {
$adapter.IPAddress | Out-File -FilePath "C:\Temp\hmi_ip.txt" -Encoding ASCII
}
On the HMI, configure a tag with the File data source pointing to the file written by the script. The PLC reads the tag value after the script has run. Schedule the PowerShell script to run at startup via the HMI's Scheduler.
8.4 Approach C — Parsing ipconfig Output
The original workaround uses ipconfig redirected to a text file, with the HMI script reading specific lines. This works on all Windows-based HMIs and on Comfort Panels that ship with the Windows Embedded command shell, but it is fragile: locale changes (German vs. English) alter the output strings, and the index of the "IPv4 Address" line varies between Windows versions. Use it only as a last resort.
' WinCC VBScript - ipconfig parsing fallback
Dim oShell, oExec
Set oShell = CreateObject("WScript.Shell")
Set oExec = oShell.Exec("cmd /c ipconfig > C:\Temp\ipconfig.txt")
WScript.Sleep 1000
Dim oFSO, oFile, sAll, sIP
Set oFSO = CreateObject("Scripting.FileSystemObject")
Set oFile = oFSO.OpenTextFile("C:\Temp\ipconfig.txt", 1)
sAll = oFile.ReadAll
oFile.Close
' English locale: look for "IPv4 Address. . . . . . . . . . . : "
Dim iStart, iEnd
iStart = InStr(sAll, "IPv4 Address")
If iStart > 0 Then
iStart = InStr(iStart, sAll, ":")
iEnd = InStr(iStart, vbCrLf)
sIP = Trim(Mid(sAll, iStart + 1, iEnd - iStart - 1))
End If
SmartTags("HMI_IP_String") = sIP
8.5 HMI Tag Configuration for PLC Visibility
For the PLC to read the HMI's IP octets, configure an S7 tag connection from the HMI to the PLC:
- Open the HMI's Connections editor and verify the connection to the CPU uses protocol S7ONLINE or PN/IE.
- Open the HMI tag table and add the four octet tags with the same names used in the script (
HMI_IP_octet1..4). Set the PLC address to a data block range, e.g.DB100.DBX0.0(BYTE) for the first octet,DB100.DBX1.0for the second, and so on. - Set the acquisition mode to Cyclic continuous (1 s) so the PLC always sees the current value.
- Compile and download the HMI project. After the HMI startup script runs, the four octets are visible in the PLC at the configured addresses.
9. Method 4 — T_CONFIG for IP Configuration
The T_CONFIG instruction is the counterpart to RDREC for writing IP parameters. It is used when the CPU needs to assign an IP address to a PROFINET device at runtime, for example a replacement device in a redundant topology. Siemens' TIA Portal documentation on assigning IP addresses lists three ways to assign an IP address: STEP 7 (TIA Portal), the SIMATIC Automation Tool, or the T_CONFIG instruction called from the user program.
| Mechanism | Direction | Use case |
|---|---|---|
| STEP 7 / TIA Portal | Configure at download time | Initial commissioning, static IP |
| SIMATIC Automation Tool | Bulk configure from a PC | Series commissioning, IP reset across many CPUs |
| T_CONFIG instruction | Configure at runtime from CPU | Replacement device, dynamic IP assignment |
| DCP protocol directly (via FB) | Configure at runtime from CPU | Advanced use, requires the LDP "Set_IP_Address" FB |
T_CONFIG is mentioned here only for completeness: it is a write operation, not a read, and it does not help when the goal is to display the active IP. The original requirement (display the current IP on the HMI) is best served by RDREC on the CPU side and a VBScript on the HMI side.
10. Siemens LDP Library: Get_IP_Address Function Block
The "Library of General Functions" (LDP) — entry ID 109753067 in the Siemens Industry Online Support ships a pre-built FB called Get_IP_Address (and a companion Get_Subnet_Mask, Get_Default_Gateway) that wraps the RDREC call described above. The library also includes a "Get module information via PROFINET network" example (entry ID 98210758) which is useful when the target is a remote IO device, not the local CPU.
To install the library:
- Open TIA Portal, switch to the Libraries task card on the right side.
- Click Open global library and navigate to the downloaded
.zal15_1file. - Drag the Get_IP_Address FB into a project folder.
- Open the FB instance in a cyclic OB (e.g. OB1) and call it with the local PN interface HW identifier (64 for CPU 1513 X1).
The FB returns the IP address as an array of four USINT values plus a STRING representation. It is functionally equivalent to the SCL code in section 4, but tested and maintained by Siemens across TIA versions and CPU firmware generations.
11. Displaying the IP Address on the HMI
With the IP octets stored in PLC tags (e.g. "DB_IP".IP_byte1..4) and the HMI tags (e.g. HMI_IP_octet1..4) populated, the HMI screen can display the values in two ways:
- As separate numeric tags: add four IO field controls to the screen, each connected to one of the eight octets. Format each as decimal (0–255). The customer sees "192 . 168 . 0 . 10".
-
As a STRING tag: concatenate the octets into a single string in the PLC (
CONCATinstruction or manual build), pass to the HMI, and display in a single Text/output field. The customer sees "192.168.0.10".
The second approach is more user-friendly but requires string handling on the PLC. Sample SCL code to build the string:
// Build a STRING from the four octets
"DB_IP".IP_String := '';
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String,
IN2 := UINT_TO_STRING("DB_IP".IP_byte1));
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String, IN2 := '.');
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String,
IN2 := UINT_TO_STRING("DB_IP".IP_byte2));
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String, IN2 := '.');
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String,
IN2 := UINT_TO_STRING("DB_IP".IP_byte3));
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String, IN2 := '.');
"DB_IP".IP_String := CONCAT(IN1 := "DB_IP".IP_String,
IN2 := UINT_TO_STRING("DB_IP".IP_byte4));
12. Verification and Commissioning Procedure
- Compile and download the user program to the CPU 1513.
- Open an online watch table on the instance DB of
FB_IP_Read_Local. ForcereqRead = TRUE, then immediately back to FALSE. - Verify
done = TRUE,error = FALSE, and thatipByte1..4match the IP configured in TIA Portal's Device View > PROFINET interface > IP address. - Cross-check with the CPU's physical display: from the CPU's main menu, navigate to Settings > Addresses > IP address and confirm the four octets match the watch table values.
- On the HMI, navigate to the screen that displays the IP. If the HMI octets are blank, open the HMI's Diagnostics > Runtime logs and check the VBScript error log; typically the WMI query fails on Comfort Panels if the script runtime is not enabled.
- Enable script runtime on the HMI: in TIA Portal, select the HMI device, open Properties > Runtime settings > Services, and check Enable VBScript. Recompile and download.
- Cycle power on the HMI to confirm the startup script runs and populates the tags.
- Cross-check the HMI's IP via the panel's Control Panel > Network & Dial-up Connections menu on Comfort Panels with the Windows Embedded shell.
12.1 Testing in PLCSIM
When using S7-PLCSIM (V15.1 Update 3 or later) for offline testing, the simulated PROFINET interface responds to RDREC just like a real CPU. The IP address is the one configured in the TIA Portal project; PLCSIM does not assign a different IP. The FB_IP_Read_Local block can be exercised end-to-end without physical hardware. Note that the HMI side cannot be tested in PLCSIM; for the HMI VBScript you need either the WinCC RT Simulator (ES) on a development PC or a physical Comfort Panel.
13. Troubleshooting Matrix
| Symptom | Most likely cause | Fix |
|---|---|---|
| RDREC returns STATUS = 16#8092 | Wrong LADDR; pointing at a CPU sub-module | Use the system constant "Local PROFINET interface_1" (HW 64) for X1, HW 65 for X2 |
| RDREC returns STATUS = 16#0000 with no data | REQ held high; only the first call transfers | Use rising edge detection on REQ; reset REQ after BUSY=1 |
| RDREC returns STATUS = 16#7000 perpetually | REQ not set or always high; pending request not cleared | Set REQ once, wait for BUSY, do not reset REQ until DONE or ERROR |
| RDREC returns STATUS = 16#80C0 | MLEN smaller than data record size (17 bytes) | Set MLEN to 18 (or 20 to be safe) |
| Parsed IP shows 0.0.0.0 after a successful read | Endianness assumption wrong; data record uses big-endian for the IP field | Parse bytes [4..7] directly, not as a single DWORD in little-endian order |
| GetStationInfo returns BUSY=1 forever | Calling on a non-existent or off-station HW identifier | Verify the LADDR; CPU local interfaces are always available |
| HMI VBScript does not run on the TP1200 | Script runtime disabled in the HMI project | Enable VBScript under Properties > Runtime settings > Services, then re-download |
| HMI script returns empty string for IP | WMI not available on Comfort Panel OS image | Use the PowerShell or ipconfig fallback approach |
| HMI IP field does not update on the PLC | PLC tag connection not configured for the HMI tags | Open the HMI connection in TIA Portal and verify the direction is "Read/Write" with the right DB address |
| RDREC reads wrong IP after a topology change | CPU is configured with a secondary IP or PROFINET device IP | Use MODE 1 of GetStationInfo to confirm which IP is active |
| RDREC works in the project but not after compilation in a different TIA version | HW identifier remapped after adding a CP module | Re-read the system constants; renumber the LADDR |
| RDREC returns STATUS = 16#80A1 on a remote IO device | The remote device does not support the IP Suite data record | Use MODE 1 of GetStationInfo instead, or fall back to a vendor-specific data record |
| ipconfig parsing returns a non-IPv4 string | Multiple IPv6 entries on the same line | Search for "IPv4" specifically, not just any IP |
| GetStationInfo returns STATUS = 16#80B1 | Index out of range; wrong MODE selected | Use MODE = 1 for MAC + IP, MODE = 2 for name, MODE = 3 for full PROFINET name |
14. Endianness and Parsing Caveats
One of the most common mistakes when reading PROFINET data records is endianness. The IP Suite data record (0xFEF0) uses network byte order (big-endian) for the IP address, subnet, and gateway fields. If you read the four bytes as a single DWORD in little-endian order (the default for S7-1500), the resulting IP will be the octets reversed. For example, the IP 192.168.0.10 stored in big-endian is C0 A8 00 0A; if you read it as a little-endian DWORD you get 0A 00 A8 C0 = 10.0.168.192, which is a different (and invalid) IP.
Always parse the four bytes individually:
ipByte1 := buffer[4]; // first octet (most significant in big-endian)
ipByte2 := buffer[5];
ipByte3 := buffer[6];
ipByte4 := buffer[7]; // last octet (least significant)
GetStationInfo already returns the octets in the correct order in its IPAddress[] array, so the endianness pitfall applies only to raw RDREC reads.
15. Security and Operational Notes
- Read-only access: the IP address is read-only through RDREC and GetStationInfo. To change the IP at runtime, use T_CONFIG or the LDP "Set_IP_Address" FB.
- Firewall rules on the HMI: WinCC VBScript with WMI does not require any firewall changes on the panel. PowerShell scripts that access the network may need outbound firewall rules if the panel's image is hardened.
-
Script execution policy: if you deploy a PowerShell script, the execution policy on the panel may block unsigned scripts. Use
Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypassin a wrapper or sign the script. - Network segmentation: when the HMI reports its IP back to the PLC, the tag connection uses the existing S7 connection — no additional port is opened. The IP read does not affect network security posture.
16. FAQ
What is the correct data record index to read the IP address of an S7-1500 CPU with RDREC?
Use INDEX = 16#FEF0 (IP Suite). Allocate at least 18 bytes of buffer space; the data record is 17 bytes (4-byte interface ID, 4-byte IP, 4-byte subnet, 4-byte gateway, 1-byte status) and some firmware versions append a padding byte. Pass the local PROFINET interface HW identifier (typically 64 for X1 of a CPU 1513) as the LADDR.
Why does GetStationInfo return error 8092 ("LADDR does not address a PROFINET IO device")?
Error 8092 means the LADDR points to a non-PROFINET object, usually a central sub-module of the CPU (the display, backplane, or central I/O). Only the entries labeled "Local PROFINET interface" in the system constants are valid LADDRs. On a CPU 1513-1 PN, the X1 interface is HW identifier 64.
Why does the HMI not have a hardware identifier in the same way as the CPU?
A Comfort Panel connected via PROFINET is normally an HMI panel, not a PROFINET IO device. The HMI is a supervisor on the network; it exchanges data with the CPU via S7 tag connections, not as an IO device. PROFINET IO data records (such as 0xFEF0) are only defined for IO devices, so RDREC cannot be used to query the HMI from the PLC. The HMI's IP must be read from inside the HMI runtime using VBScript, PowerShell, or the ipconfig fallback.
How do I read the IP address of a Comfort Panel TP1200 from a WinCC Comfort V15.1 runtime?
Create a VBScript in the HMI that queries Win32_NetworkAdapterConfiguration via WMI, parse the IPAddress string, and write the four octets to internal HMI tags. Configure a tag connection from those tags to the PLC. On the PLC, read the four octets from the configured DB range. If WMI is unavailable on the embedded OS, fall back to parsing the output of ipconfig redirected to a file, or use a PowerShell script with a file-based HMI tag.
Can I use T_CONFIG to read the IP address, or is T_CONFIG only for writing?
T_CONFIG writes IP parameters to a PROFINET device at runtime. It is the write counterpart of RDREC and does not return the current IP. For reading, use RDREC on the local PROFINET interface with data record 0xFEF0, or use GetStationInfo with MODE = 1.