Overview of PROFINET Diagnostics via Data Records
PROFINET exchanges diagnostics and configuration data between an IO controller and IO devices through standardized PROFINET data records transported as acyclic record read/write services. Every record is addressed by an Application Process Identifier (API), slot, and subslot, and the payload follows the record index rules of IEC 61784-2 / PROFINET specification. Siemens S7-1200 and S7-1500 controllers expose this mechanism through the RDREC and WRREC system function blocks. The S7-1500 also supports an implicit record mechanism that copies record data into a process image without explicit user calls.
Typical items an automation engineer wants to read from the user program include:
- Interface descriptors: IP address, subnet mask, MAC address, port name, medium
- Per-port link status (link up, link down, speed, duplex, autonegotiation result)
- MRP (Media Redundancy Protocol) role, current ring state, manager/client port assignment
- Port statistics: frames received, frames discarded, CRC errors, late collisions
- Channel diagnostics enable/disable on modular I/O such as ET 200SP AI modules
Because each PROFINET device interprets records differently and the slot/subslot map is project-specific, Siemens publishes a curated function block library that hides the record indices and error-code handling. The library is delivered as the LPNDR (Library PROFINET Data Record) entry in Siemens Online Support (entry ID 109753067). The entry contains the TIA Portal library, an example project, and a description of every block interface.
SFC 51 RDSYSST or, where applicable, the DPRD_DAT / DPWR_DAT SFCs with PROFINET record indices.LPNDR Library: Function Block Reference
The library wraps the acyclic PROFINET record services into ready-to-use function blocks (FBs). Each FB publishes a single, well-defined capability. The block symbols follow the LPNDR_* prefix and accept the PROFINET interface hardware identifier (HID) plus a slot/subslot reference where applicable. The exact symbol names and the latest revision are documented in the entry itself; engineers should always open the supplied PDF first to confirm the FB type for their TIA Portal version.
| Function block | Purpose | Record family used |
|---|---|---|
LPNDR_ReadDeviceInfo |
Reads IP, subnet mask, MAC, port name, medium, and default gateway of a PROFINET device | API 0 record set (device identification) |
LPNDR_ReadLinkStatus |
Reads the link state of every physical port: link up/down, speed, duplex, autonegotiation result | PD Port Data Real (record 0x802A family) |
LPNDR_ReadMRPStatus |
Reads MRP role (manager/client/not-member), ring state (open/closed), and blocked port | PD MRP Data Real (record 0x802B family) |
LPNDR_ReadPortStatistics |
Reads per-port counters: bytes received, frames discarded, CRC errors, late collisions | PD Port Statistics (record 0x802C family) |
LPNDR_ReadInterfaceInfo |
Reads the local PROFINET interface of the controller: own IP, MAC, port name | Local interface records (API 0, slot 0) |
LPNDR_WriteParameter |
Writes a record to a subslot; used to enable/disable channel diagnostics on ET 200SP AI modules | User-defined record index (e.g. 0x2F00 series for channel diagnostics) |
All blocks return a STATUS output of type DWORD that carries the standard PROFINET record error classes. A non-zero status starts with 0x80 (PN IO error) or 0xDE (busy / partial). The library maps common status codes to symbolic constants so the user program can branch on human-readable names.
Prerequisites and Installation
- Controller. SIMATIC S7-1200 (firmware V4.0 or later) or S7-1500 (firmware V1.8 or later recommended for full block set). Older firmware may lack implicit record support or specific sub-records.
- Engineering station. TIA Portal V15.1 or later, with the matching HSP (Hardware Support Package) for the IO devices used in the project.
- Library package. Download the LPNDR zip archive from Siemens Online Support entry 109753067. The package contains a TIA Portal library (.zal15 / .zal16 / .zal17 depending on the TIA version) and a sample project.
-
Hardware identifier. The PROFINET interface of the IO device must be configured in the device view, and its Hardware Identifier (HID) must be available. The HID is visible in the device properties under "System constants" and is also returned by
DeviceStatesandModuleStatesin OB 100 / OB 82 startup. - Slot/subslot map. For subslot-level records (e.g. channel diagnostics), the slot and subslot numbers come from the device configuration. In TIA Portal open the device view and select the module: the slot number is shown in the rack, the subslot is shown on the channel list.
Install the library by opening TIA Portal, choosing Options → Global libraries → Open library, and selecting the supplied archive. Drag the LPNDR master copies into the project under "Program blocks → Library blocks". The library is then available in every program block call.
Reading Device Information (IP, MAC, Port Name, Medium)
Use the device information FB to query identification data of a remote IO device. The example below is for TIA Portal SCL and follows the documented block interface.
// Instance of the device info FB
iLPNDR_DevInfo : LPNDR_ReadDeviceInfo;
// Trigger rising edge
IF #bStart THEN
iLPNDR_DevInfo(REQ := TRUE,
HW_ID := 268, // hardware identifier of the PN interface
DONE => #bDone,
BUSY => #bBusy,
ERROR => #bError,
STATUS => #dwStatus,
IP => #sIP, // WSTRING or STRING, e.g. '192.168.0.10'
MAC => #abMAC, // ARRAY[0..5] of BYTE
PORT => #sPortName, // e.g. 'Port 1 X1 P1'
MEDIUM=> #sMedium); // e.g. 'Copper', 'Fiber'
#bStart := FALSE;
END_IF;
When BUSY falls and DONE rises, the outputs contain the requested values. The IP output is normally a WSTRING or STRING in dotted notation. The MAC is exposed as a six-byte array; convert it to a string with a helper routine if you want a colon-separated display in HMI.
Reading Link Status per Port
Link status records are per port. The block returns an array of port descriptors; each element carries Link, Speed (Mbps), Duplex, and Autoneg. The index in the array corresponds to the physical port number visible on the device label.
iLPNDR_Link(REQ := #bTrg,
HW_ID := 268,
DONE => #bDone,
BUSY => #bBusy,
ERROR => #bError,
STATUS => #dwStatus,
PORTS => #aPortStatus); // ARRAY[1..n] of LPNDR_typePortStatus
A typical structure element is:
TYPE LPNDR_typePortStatus
STRUCT
PortNumber : UINT; // 1..n
Link : BOOL; // TRUE if link is up
Speed : UINT; // 10, 100, 1000, 10000 (Mbps)
Duplex : USINT; // 0 = half, 1 = full, 2 = unknown
AutoNeg : BOOL; // autonegotiation result
PortName : STRING[32];
END_STRUCT
END_TYPE
Use the link status in supervision code to raise an alarm on a single-link failure that has not yet triggered MRP swap. In ring topologies a link drop on a non-blocked port is the first indication that the ring is about to open.
Reading MRP Role and Current Ring Status
MRP operates with one manager and one or more clients. The manager sends test frames on both ring ports; if it stops receiving its own frames, the ring is open and it unblocks the backup port. The data record exposes the device's role, the current ring state, and the port that is currently blocked.
| Output | Meaning | Typical values |
|---|---|---|
MRPRole |
Configured role | 0 = disabled, 1 = client, 2 = manager, 3 = manager (auto) |
RingState |
Current ring topology | 0 = undefined, 1 = ring open, 2 = ring closed, 3 = not connected |
BlockedPort |
Port currently blocked by the manager | 0 = none, 1 = port 1, 2 = port 2 |
ManagerMAC |
MAC of the active MRP manager | 6-byte array |
Field acceptance: a healthy closed ring shows RingState = 2 and BlockedPort = 1 or 2. After disconnecting one cable, RingState must transition to 1 (ring open) within the MRP topology change timeout (default 500 ms). Reconnecting must close the ring within the same window.
Reading Port Statistics
Port statistics are counter-based. The block returns per-port counters. The counters are 32-bit unsigned and roll over to zero. To detect slowly increasing error rates, sample the counters periodically and store the previous value in a static DB.
| Counter | Description | Engineering use |
|---|---|---|
InOctets |
Bytes received | Bandwidth trending |
OutOctets |
Bytes sent | Bandwidth trending |
InDiscards |
Frames discarded on ingress | Buffer overruns, QoS issues |
InErrors |
Frames received with errors | CRC, alignment, FIFO overrun |
OutErrors |
Frames sent with errors | Late collisions, carrier sense |
SingleCollisions |
Frames that collided once | Half-duplex warning |
MultipleCollisions |
Frames that collided more than once | Persistent half-duplex issue |
Deferred |
Delayed first transmission | Busy medium |
Sample the counters in OB 35 (cyclic interrupt, e.g. every 1 s) and compute the delta to a previous snapshot. Persist long-term counters in a retentive DB if you need to survive a controller restart.
Modifying Parameters at Runtime (ET 200SP Example)
The same record mechanism is used for writing parameters to a subslot. The reference example in the LPNDR entry enables and disables channel diagnostics on an ET 200SP analog input module (e.g. AI 4xU/I/RTD/TC ST). The procedure is:
- Identify the slot of the AI module (visible in the device view).
- Identify the subslot of the channel (channel 0 = subslot 1, channel 1 = subslot 2, etc.).
- Build the record payload in the user program. The record index for channel diagnostics is module-specific; consult the device manual (e.g. Diagnostics and configuration data records).
- Call the write FB with the slot, subslot, record index, and payload.
// Build the record payload for AI channel diagnostics disable
#aRecord[0] := 16#00; // block header
#aRecord[1] := 16#01; // length
#aRecord[2] := 16#00;
#aRecord[3] := 16#00;
#aRecord[4] := 16#00; // channel diagnostics: 0 = off, 1 = on
iLPNDR_WriteParam(REQ := #bWriteTrg,
HW_ID := 268,
SLOT := 1, // AI module slot
SUBSLOT := 1, // channel 0
INDEX := 16#2F00, // channel diagnostics record (module-specific)
LEN := 5,
RECORD := #aRecord,
DONE => #bDone,
BUSY => #bBusy,
ERROR => #bError,
STATUS => #dwStatus);
Legacy S7-300/400 Approach Using System Status Lists
STEP 7 V5.5 and the S7-300/400 system software expose many of the same values through System Status Lists (SSL). The function SFC 51 RDSYSST reads partial lists or complete lists of SSL data. The result is a pre-formatted buffer that the user program parses.
| SSL_ID (W#16#) | Meaning | Use |
|---|---|---|
| 0131 | IP parameters of an interface | Local IP, subnet, router, DNS |
| 0132 | MAC address of an interface | Local MAC |
| 0174 | Status of the PROFINET interface | Interface ready / not ready / error |
| 0222 | Status of the PROFINET IO system | IO controller status |
| 0F31 | Status of PROFINET interfaces | Detailed PN status |
// Read SSL partial list: SZL_ID = W#16#0131 (IP parameters)
CALL "RDSYSST" (
REQ := TRUE,
SZL_ID := W#16#0131,
INDEX := 1, // interface number
RET_VAL := #iRetVal,
BUSY := #bBusy,
SZL_HEADER := #szlHeader,
DR := #abDataRecord);
For PROFINET-specific items (link status, MRP, port statistics), the S7-300/400 family does not provide the same standardized record access that S7-1500 does. The historical workaround is to use the DPWR_DAT / DPRD_DAT SFCs with the IO device's hardware identifier and a known record index, or to read the data with a separate PROFINET IO supervisor such as PRONETA.
S7-1200/1500 Approach Using RDREC and WRREC
The generic acyclic record blocks RDREC and WRREC are available in every TIA Portal installation. They require the engineer to assemble the record index, slot, and subslot manually, and to evaluate the STATUS output.
// RDREC - read a PROFINET record
iRDREC(REQ := #bTrg,
ID := 268, // hardware identifier
INDEX := 16#802A, // PD Port Data Real
MLEN := 32,
VALID => #bValid,
BUSY => #bBusy,
ERROR => #bError,
STATUS=> #dwStatus,
LEN => #iLen,
RECORD=> #abBuf);
Common status codes that RDREC / WRREC return:
| STATUS (hex) | Meaning | Action |
|---|---|---|
| 0000 0000 | No error | Process RECORD
|
| 0070 0000 | First successful read after REQ
|
Process RECORD
|
| 80A1 0000 | Record not supported | Check INDEX against device manual |
| 80A1 0001 | Invalid slot / subslot | Verify module is plugged and configured |
| 80A1 0007 | Access denied (write protection) | Check device protection level in TIA |
| 80B0 0000 | Resource busy | Re-issue after next cycle or wait for BUSY = FALSE |
| DE80 0000 | Module not ready | Wait for OB 82 / OB 100 startup completion |
WRREC uses the same interface; MLEN becomes LEN (length of the record to write) and RECORD is the source buffer.
Implicit Read/Write Records on S7-1500
The S7-1500 firmware introduced an implicit record mechanism: instead of calling RDREC / WRREC in the user program, the controller automatically mirrors the record payload into a configured data block at the configured update interval. This removes the need to manage BUSY / DONE state machines in the application.
The mechanism is configured per record in the device properties of the IO device. Steps:
- Open the device view of the IO device.
- Select the interface.
- Open the Properties → PROFINET interface → Record handling (or equivalent) tab.
- Click Add record, enter the API, slot, subslot, and record index, and bind the record to a data block in the project.
- Compile and download.
For detailed behavior and the firmware versions that introduced the feature, see the Siemens article Implicit reading and writing of PROFINET data records (entry ID 109810980).
Implicit access is recommended for records that are read on every cycle (e.g. link status) and for records that are written once at startup (e.g. configuration of an I/O module). For low-priority records polled on demand, the explicit RDREC / WRREC path is more efficient because it does not consume permanent bus bandwidth.
Data Record Addressing Model
PROFINET records are addressed with a four-coordinate tuple. The full path is required to read or write a record.
| Coordinate | Type | Range / meaning | Where to find it |
|---|---|---|---|
| API | UINT (32 bits in spec) | 0 = PROFINET default, higher values = sub-APIs used by some device families | Device manual / GSD file |
| Slot | UINT | 0 = head module, 1..n = plug-in modules in device view | Device view in TIA Portal |
| Subslot | UINT | 0 = sub-module, 1..m = channel or sub-submodule | Channel list of the module |
| Index | UINT | Record index; 0x8000-0xFFFF = PROFINET standard records, 0x0000-0x7FFF = vendor specific | Device manual / GSD file |
Standard record indices used in this article:
- 0x802A — PD Port Data Real (link / port status snapshot)
- 0x802B — PD MRP Data Real (MRP runtime data)
- 0x802C — PD Port Statistics (per-port counters)
- 0xF000…0xFFFF — Identification & Maintenance (I&M) records
Troubleshooting Matrix
| Symptom | Likely root cause | Where to look | Fix |
|---|---|---|---|
STATUS = 0x80A10000 on every call |
Record not supported by the IO device | Device manual, GSD file | Use the correct record index for that device family |
STATUS = 0x80A10001 after slot change |
Wrong slot or subslot | Device view in TIA Portal | Re-read the slot from the device configuration; the slot index of a module changes when the station order is edited |
STATUS = 0x80A10007 |
Access protection is enabled in TIA | Device properties → Protection | Set the protection level to "full access" for the engineering account or supply the right password |
| Block returns zeros with no error | Module is in PROFIenergy pause or replacement mode | Device LEDs, PRONETA online diagnostics | Wake the device or remove the replacement marker |
| Link always reads "down" while the LED is on | Wrong hardware identifier passed to the FB | System constants in TIA Portal | Use the HID of the IO device's PROFINET interface, not the controller's local interface |
| MRP role reads "undefined" | MRP is disabled in the project | Interface properties → MRP | Enable MRP and assign manager / client roles |
| Port statistics never increase | Counters are read on the wrong port number | Device label / manual | Match the array index to the physical port number printed on the housing |
| Implicit record stays at 0 even though the device is healthy | API / slot / subslot mismatch in the implicit record configuration | TIA Portal → Record handling | Re-enter the coordinates; download hardware configuration |
| Channel diagnostics write returns 0x80B00000 | Another record transaction is already in progress | User program | Serialize writes; never call WRREC twice in parallel on the same module |
Verification and Field Acceptance
After commissioning, perform the following verification steps. The checklist applies to both the LPNDR library path and the explicit RDREC / WRREC path.
- Compile and download without errors. The TIA Portal offline build must finish with status "Done". Any remaining warning about record access is treated as an error in production projects.
-
Watch table test. Open a watch table, force the
REQinput of each FB, and check thatDONErises within two OB 1 cycles. TheSTATUSmust be zero. - Cross-check with PRONETA. The free Siemens tool PRONETA reads the same records over the network. The values it reports must match the values the user program reads. A delta indicates a wrong hardware identifier or a wrong slot/subslot.
-
MRP ring test. With MRP active, pull one cable. The library must report
RingState = 1within the topology change timeout (default 500 ms). Reconnect; the value must return to2. -
Link loss test. Disconnect the patch cable of one port. The link status must drop to
FALSEfor that port. Reconnect; the value must return toTRUEafter autonegotiation completes (typical 2–5 s). - Channel diagnostics write test. For an ET 200SP AI module, disable channel diagnostics, simulate a wire break, and confirm that the diagnostic interrupt does not appear. Re-enable, simulate again, and confirm the interrupt does appear.
- Retention check. Cycle power to the controller. The implicit record configuration must reload automatically. The LPNDR block instances keep their last values from the previous session if the instance DB is marked as retentive.
Performance and Timing Notes
An acyclic PROFINET record request is a UDP frame on the PROFINET real-time channel. The round-trip time is bounded by the configured update time of the IO device:
- Typical RT class 1 update time: 1 ms
- Record read latency: 1–2 update cycles (1–2 ms) under light load
- Record read latency with MRP swap in progress: up to 500 ms (MRP topology change timeout)
For periodic polling, set the polling interval to at least 100 ms. Polling faster than the update time wastes bus bandwidth without producing new data. If the value never changes, the block is reading from a cached record; reset the block instance and re-issue.
Security and Access Protection
PROFINET record access can be protected by access levels configured in TIA Portal. With the default protection level, a record write to a protected device returns 0x80A10007 (access denied). To allow writes:
- Open the device properties in TIA Portal.
- Select Protection & Security.
- Set the access level for the engineering account to "Full access (no protection)" or assign a password.
- Download the new configuration.
For production networks, use a dedicated HMI account with write access limited to the records that the application needs. Do not disable protection in the field unless the project security policy requires it.
FAQ
Can I use the LPNDR library on an S7-300 or S7-400 station?
No. The LPNDR library targets TIA Portal projects with S7-1200 and S7-1500 controllers. On S7-300/400 systems, read the same information via System Status Lists using SFC 51 (RDSYSST) with SSL_ID W#16#0131, W#16#0132, or W#16#0174, depending on the value needed.
What is the difference between explicit (RDREC / WRREC) and implicit record access on the S7-1500?
Explicit access is triggered by the user program; the application manages the REQ / BUSY / DONE state machine. Implicit access is configured in the device properties; the controller automatically copies the record payload into a configured DB at a fixed update interval without any user code. See Siemens entry 109810980 for the firmware versions that introduced implicit access.
Where do I find the hardware identifier (HID) of a PROFINET interface?
Open the device view in TIA Portal, select the IO device, and read the value from the system constants list (path: Properties → System constants → PN interface). The HID is also exposed at runtime in the input area of the RDREC / WRREC system blocks.
How do I check the MRP ring state from the user program?
Call the LPNDR Read MRP status block (or the equivalent RDREC call with record index 0x802B on the device's hardware identifier). The block returns the role, the ring state (open / closed / not connected), and the port that is currently blocked by the manager.
Why does my WRREC call return 0x80A10007?
The IO device is access-protected. Open the device properties in TIA Portal, navigate to Protection & Security, and either set the access level to "Full access" for the engineering account or supply the correct password. Re-download the configuration and re-issue the write.
What is the maximum length of a PROFINET data record?
The PROFINET specification allows records up to 65 535 bytes. The practical limit on the S7-1500 is determined by the available work memory and by the MLEN input of RDREC; in most field applications records are well below 1 kB.