Reading PROFINET Data Records with the LPNDR Library in TIA

David Krause17 min read
Industrial NetworkingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview of PROFINET Diagnostics via Data Records

PROFINET exchanges diagnostics and configuration data between an IO controller and IO devices through standardized PROFINET data records transported as acyclic record read/write services. Every record is addressed by an Application Process Identifier (API), slot, and subslot, and the payload follows the record index rules of IEC 61784-2 / PROFINET specification. Siemens S7-1200 and S7-1500 controllers expose this mechanism through the RDREC and WRREC system function blocks. The S7-1500 also supports an implicit record mechanism that copies record data into a process image without explicit user calls.

Typical items an automation engineer wants to read from the user program include:

  • Interface descriptors: IP address, subnet mask, MAC address, port name, medium
  • Per-port link status (link up, link down, speed, duplex, autonegotiation result)
  • MRP (Media Redundancy Protocol) role, current ring state, manager/client port assignment
  • Port statistics: frames received, frames discarded, CRC errors, late collisions
  • Channel diagnostics enable/disable on modular I/O such as ET 200SP AI modules

Because each PROFINET device interprets records differently and the slot/subslot map is project-specific, Siemens publishes a curated function block library that hides the record indices and error-code handling. The library is delivered as the LPNDR (Library PROFINET Data Record) entry in Siemens Online Support (entry ID 109753067). The entry contains the TIA Portal library, an example project, and a description of every block interface.

Compatibility scope. The LPNDR library is designed for SIMATIC S7-1200 and S7-1500 stations programmed with TIA Portal. S7-300/400 stations programmed with STEP 7 V5.5 or classic STEP 7 cannot use the library. For those systems, the equivalent information is read through System Status Lists (SSL) using SFC 51 RDSYSST or, where applicable, the DPRD_DAT / DPWR_DAT SFCs with PROFINET record indices.

LPNDR Library: Function Block Reference

The library wraps the acyclic PROFINET record services into ready-to-use function blocks (FBs). Each FB publishes a single, well-defined capability. The block symbols follow the LPNDR_* prefix and accept the PROFINET interface hardware identifier (HID) plus a slot/subslot reference where applicable. The exact symbol names and the latest revision are documented in the entry itself; engineers should always open the supplied PDF first to confirm the FB type for their TIA Portal version.

Function block Purpose Record family used
LPNDR_ReadDeviceInfo Reads IP, subnet mask, MAC, port name, medium, and default gateway of a PROFINET device API 0 record set (device identification)
LPNDR_ReadLinkStatus Reads the link state of every physical port: link up/down, speed, duplex, autonegotiation result PD Port Data Real (record 0x802A family)
LPNDR_ReadMRPStatus Reads MRP role (manager/client/not-member), ring state (open/closed), and blocked port PD MRP Data Real (record 0x802B family)
LPNDR_ReadPortStatistics Reads per-port counters: bytes received, frames discarded, CRC errors, late collisions PD Port Statistics (record 0x802C family)
LPNDR_ReadInterfaceInfo Reads the local PROFINET interface of the controller: own IP, MAC, port name Local interface records (API 0, slot 0)
LPNDR_WriteParameter Writes a record to a subslot; used to enable/disable channel diagnostics on ET 200SP AI modules User-defined record index (e.g. 0x2F00 series for channel diagnostics)

All blocks return a STATUS output of type DWORD that carries the standard PROFINET record error classes. A non-zero status starts with 0x80 (PN IO error) or 0xDE (busy / partial). The library maps common status codes to symbolic constants so the user program can branch on human-readable names.

Prerequisites and Installation

  1. Controller. SIMATIC S7-1200 (firmware V4.0 or later) or S7-1500 (firmware V1.8 or later recommended for full block set). Older firmware may lack implicit record support or specific sub-records.
  2. Engineering station. TIA Portal V15.1 or later, with the matching HSP (Hardware Support Package) for the IO devices used in the project.
  3. Library package. Download the LPNDR zip archive from Siemens Online Support entry 109753067. The package contains a TIA Portal library (.zal15 / .zal16 / .zal17 depending on the TIA version) and a sample project.
  4. Hardware identifier. The PROFINET interface of the IO device must be configured in the device view, and its Hardware Identifier (HID) must be available. The HID is visible in the device properties under "System constants" and is also returned by DeviceStates and ModuleStates in OB 100 / OB 82 startup.
  5. Slot/subslot map. For subslot-level records (e.g. channel diagnostics), the slot and subslot numbers come from the device configuration. In TIA Portal open the device view and select the module: the slot number is shown in the rack, the subslot is shown on the channel list.

Install the library by opening TIA Portal, choosing Options → Global libraries → Open library, and selecting the supplied archive. Drag the LPNDR master copies into the project under "Program blocks → Library blocks". The library is then available in every program block call.

Reading Device Information (IP, MAC, Port Name, Medium)

Use the device information FB to query identification data of a remote IO device. The example below is for TIA Portal SCL and follows the documented block interface.

// Instance of the device info FB
iLPNDR_DevInfo : LPNDR_ReadDeviceInfo;

// Trigger rising edge
IF #bStart THEN
    iLPNDR_DevInfo(REQ := TRUE,
                   HW_ID := 268,                  // hardware identifier of the PN interface
                   DONE => #bDone,
                   BUSY => #bBusy,
                   ERROR => #bError,
                   STATUS => #dwStatus,
                   IP   => #sIP,                  // WSTRING or STRING, e.g. '192.168.0.10'
                   MAC  => #abMAC,                // ARRAY[0..5] of BYTE
                   PORT => #sPortName,            // e.g. 'Port 1 X1 P1'
                   MEDIUM=> #sMedium);            // e.g. 'Copper', 'Fiber'
    #bStart := FALSE;
END_IF;

When BUSY falls and DONE rises, the outputs contain the requested values. The IP output is normally a WSTRING or STRING in dotted notation. The MAC is exposed as a six-byte array; convert it to a string with a helper routine if you want a colon-separated display in HMI.

Read consistency. Acyclic records are not time-coherent with the cyclic process image. If the network address is changed by another station between the request and the response, the values may be inconsistent. In redundant networks always re-read after MRP ring closure.

Reading Link Status per Port

Link status records are per port. The block returns an array of port descriptors; each element carries Link, Speed (Mbps), Duplex, and Autoneg. The index in the array corresponds to the physical port number visible on the device label.

iLPNDR_Link(REQ := #bTrg,
            HW_ID := 268,
            DONE => #bDone,
            BUSY => #bBusy,
            ERROR => #bError,
            STATUS => #dwStatus,
            PORTS => #aPortStatus);  // ARRAY[1..n] of LPNDR_typePortStatus

A typical structure element is:

TYPE LPNDR_typePortStatus
    STRUCT
        PortNumber : UINT;    // 1..n
        Link       : BOOL;    // TRUE if link is up
        Speed      : UINT;    // 10, 100, 1000, 10000 (Mbps)
        Duplex     : USINT;   // 0 = half, 1 = full, 2 = unknown
        AutoNeg    : BOOL;    // autonegotiation result
        PortName   : STRING[32];
    END_STRUCT
END_TYPE

Use the link status in supervision code to raise an alarm on a single-link failure that has not yet triggered MRP swap. In ring topologies a link drop on a non-blocked port is the first indication that the ring is about to open.

Reading MRP Role and Current Ring Status

MRP operates with one manager and one or more clients. The manager sends test frames on both ring ports; if it stops receiving its own frames, the ring is open and it unblocks the backup port. The data record exposes the device's role, the current ring state, and the port that is currently blocked.

Output Meaning Typical values
MRPRole Configured role 0 = disabled, 1 = client, 2 = manager, 3 = manager (auto)
RingState Current ring topology 0 = undefined, 1 = ring open, 2 = ring closed, 3 = not connected
BlockedPort Port currently blocked by the manager 0 = none, 1 = port 1, 2 = port 2
ManagerMAC MAC of the active MRP manager 6-byte array

Field acceptance: a healthy closed ring shows RingState = 2 and BlockedPort = 1 or 2. After disconnecting one cable, RingState must transition to 1 (ring open) within the MRP topology change timeout (default 500 ms). Reconnecting must close the ring within the same window.

Reading Port Statistics

Port statistics are counter-based. The block returns per-port counters. The counters are 32-bit unsigned and roll over to zero. To detect slowly increasing error rates, sample the counters periodically and store the previous value in a static DB.

Counter Description Engineering use
InOctets Bytes received Bandwidth trending
OutOctets Bytes sent Bandwidth trending
InDiscards Frames discarded on ingress Buffer overruns, QoS issues
InErrors Frames received with errors CRC, alignment, FIFO overrun
OutErrors Frames sent with errors Late collisions, carrier sense
SingleCollisions Frames that collided once Half-duplex warning
MultipleCollisions Frames that collided more than once Persistent half-duplex issue
Deferred Delayed first transmission Busy medium

Sample the counters in OB 35 (cyclic interrupt, e.g. every 1 s) and compute the delta to a previous snapshot. Persist long-term counters in a retentive DB if you need to survive a controller restart.

Modifying Parameters at Runtime (ET 200SP Example)

The same record mechanism is used for writing parameters to a subslot. The reference example in the LPNDR entry enables and disables channel diagnostics on an ET 200SP analog input module (e.g. AI 4xU/I/RTD/TC ST). The procedure is:

  1. Identify the slot of the AI module (visible in the device view).
  2. Identify the subslot of the channel (channel 0 = subslot 1, channel 1 = subslot 2, etc.).
  3. Build the record payload in the user program. The record index for channel diagnostics is module-specific; consult the device manual (e.g. Diagnostics and configuration data records).
  4. Call the write FB with the slot, subslot, record index, and payload.
// Build the record payload for AI channel diagnostics disable
#aRecord[0] := 16#00;   // block header
#aRecord[1] := 16#01;   // length
#aRecord[2] := 16#00;
#aRecord[3] := 16#00;
#aRecord[4] := 16#00;   // channel diagnostics: 0 = off, 1 = on

iLPNDR_WriteParam(REQ := #bWriteTrg,
                   HW_ID := 268,
                   SLOT := 1,           // AI module slot
                   SUBSLOT := 1,        // channel 0
                   INDEX := 16#2F00,    // channel diagnostics record (module-specific)
                   LEN := 5,
                   RECORD := #aRecord,
                   DONE => #bDone,
                   BUSY => #bBusy,
                   ERROR => #bError,
                   STATUS => #dwStatus);
Record index source of truth. The record index above is generic. The exact index for channel diagnostics is documented in the ET 200SP AI module manual and varies between module order numbers (e.g. 6ES7134-6GD01-0BA1 vs. -0BD0). Always check the module manual before writing; writing to the wrong index can put the channel into an undefined state.

Legacy S7-300/400 Approach Using System Status Lists

STEP 7 V5.5 and the S7-300/400 system software expose many of the same values through System Status Lists (SSL). The function SFC 51 RDSYSST reads partial lists or complete lists of SSL data. The result is a pre-formatted buffer that the user program parses.

SSL_ID (W#16#) Meaning Use
0131 IP parameters of an interface Local IP, subnet, router, DNS
0132 MAC address of an interface Local MAC
0174 Status of the PROFINET interface Interface ready / not ready / error
0222 Status of the PROFINET IO system IO controller status
0F31 Status of PROFINET interfaces Detailed PN status
// Read SSL partial list: SZL_ID = W#16#0131 (IP parameters)
CALL "RDSYSST" (
    REQ      := TRUE,
    SZL_ID   := W#16#0131,
    INDEX    := 1,             // interface number
    RET_VAL  := #iRetVal,
    BUSY     := #bBusy,
            SZL_HEADER := #szlHeader,
    DR       := #abDataRecord);

For PROFINET-specific items (link status, MRP, port statistics), the S7-300/400 family does not provide the same standardized record access that S7-1500 does. The historical workaround is to use the DPWR_DAT / DPRD_DAT SFCs with the IO device's hardware identifier and a known record index, or to read the data with a separate PROFINET IO supervisor such as PRONETA.

S7-1200/1500 Approach Using RDREC and WRREC

The generic acyclic record blocks RDREC and WRREC are available in every TIA Portal installation. They require the engineer to assemble the record index, slot, and subslot manually, and to evaluate the STATUS output.

// RDREC - read a PROFINET record
iRDREC(REQ   := #bTrg,
       ID    := 268,                 // hardware identifier
       INDEX := 16#802A,             // PD Port Data Real
       MLEN  := 32,
       VALID => #bValid,
       BUSY  => #bBusy,
       ERROR => #bError,
       STATUS=> #dwStatus,
       LEN   => #iLen,
       RECORD=> #abBuf);

Common status codes that RDREC / WRREC return:

STATUS (hex) Meaning Action
0000 0000 No error Process RECORD
0070 0000 First successful read after REQ Process RECORD
80A1 0000 Record not supported Check INDEX against device manual
80A1 0001 Invalid slot / subslot Verify module is plugged and configured
80A1 0007 Access denied (write protection) Check device protection level in TIA
80B0 0000 Resource busy Re-issue after next cycle or wait for BUSY = FALSE
DE80 0000 Module not ready Wait for OB 82 / OB 100 startup completion

WRREC uses the same interface; MLEN becomes LEN (length of the record to write) and RECORD is the source buffer.

Implicit Read/Write Records on S7-1500

The S7-1500 firmware introduced an implicit record mechanism: instead of calling RDREC / WRREC in the user program, the controller automatically mirrors the record payload into a configured data block at the configured update interval. This removes the need to manage BUSY / DONE state machines in the application.

The mechanism is configured per record in the device properties of the IO device. Steps:

  1. Open the device view of the IO device.
  2. Select the interface.
  3. Open the Properties → PROFINET interface → Record handling (or equivalent) tab.
  4. Click Add record, enter the API, slot, subslot, and record index, and bind the record to a data block in the project.
  5. Compile and download.

For detailed behavior and the firmware versions that introduced the feature, see the Siemens article Implicit reading and writing of PROFINET data records (entry ID 109810980).

Implicit access is recommended for records that are read on every cycle (e.g. link status) and for records that are written once at startup (e.g. configuration of an I/O module). For low-priority records polled on demand, the explicit RDREC / WRREC path is more efficient because it does not consume permanent bus bandwidth.

Data Record Addressing Model

PROFINET records are addressed with a four-coordinate tuple. The full path is required to read or write a record.

Coordinate Type Range / meaning Where to find it
API UINT (32 bits in spec) 0 = PROFINET default, higher values = sub-APIs used by some device families Device manual / GSD file
Slot UINT 0 = head module, 1..n = plug-in modules in device view Device view in TIA Portal
Subslot UINT 0 = sub-module, 1..m = channel or sub-submodule Channel list of the module
Index UINT Record index; 0x8000-0xFFFF = PROFINET standard records, 0x0000-0x7FFF = vendor specific Device manual / GSD file

Standard record indices used in this article:

  • 0x802A — PD Port Data Real (link / port status snapshot)
  • 0x802B — PD MRP Data Real (MRP runtime data)
  • 0x802C — PD Port Statistics (per-port counters)
  • 0xF000…0xFFFF — Identification & Maintenance (I&M) records
Note on record indices. The values above are the indices defined in the PROFINET specification. Device-specific extensions use the lower range (0x0000–0x7FFF). Always verify the exact index in the device's manual and GSD file before sending an acyclic read.

Troubleshooting Matrix

Symptom Likely root cause Where to look Fix
STATUS = 0x80A10000 on every call Record not supported by the IO device Device manual, GSD file Use the correct record index for that device family
STATUS = 0x80A10001 after slot change Wrong slot or subslot Device view in TIA Portal Re-read the slot from the device configuration; the slot index of a module changes when the station order is edited
STATUS = 0x80A10007 Access protection is enabled in TIA Device properties → Protection Set the protection level to "full access" for the engineering account or supply the right password
Block returns zeros with no error Module is in PROFIenergy pause or replacement mode Device LEDs, PRONETA online diagnostics Wake the device or remove the replacement marker
Link always reads "down" while the LED is on Wrong hardware identifier passed to the FB System constants in TIA Portal Use the HID of the IO device's PROFINET interface, not the controller's local interface
MRP role reads "undefined" MRP is disabled in the project Interface properties → MRP Enable MRP and assign manager / client roles
Port statistics never increase Counters are read on the wrong port number Device label / manual Match the array index to the physical port number printed on the housing
Implicit record stays at 0 even though the device is healthy API / slot / subslot mismatch in the implicit record configuration TIA Portal → Record handling Re-enter the coordinates; download hardware configuration
Channel diagnostics write returns 0x80B00000 Another record transaction is already in progress User program Serialize writes; never call WRREC twice in parallel on the same module

Verification and Field Acceptance

After commissioning, perform the following verification steps. The checklist applies to both the LPNDR library path and the explicit RDREC / WRREC path.

  1. Compile and download without errors. The TIA Portal offline build must finish with status "Done". Any remaining warning about record access is treated as an error in production projects.
  2. Watch table test. Open a watch table, force the REQ input of each FB, and check that DONE rises within two OB 1 cycles. The STATUS must be zero.
  3. Cross-check with PRONETA. The free Siemens tool PRONETA reads the same records over the network. The values it reports must match the values the user program reads. A delta indicates a wrong hardware identifier or a wrong slot/subslot.
  4. MRP ring test. With MRP active, pull one cable. The library must report RingState = 1 within the topology change timeout (default 500 ms). Reconnect; the value must return to 2.
  5. Link loss test. Disconnect the patch cable of one port. The link status must drop to FALSE for that port. Reconnect; the value must return to TRUE after autonegotiation completes (typical 2–5 s).
  6. Channel diagnostics write test. For an ET 200SP AI module, disable channel diagnostics, simulate a wire break, and confirm that the diagnostic interrupt does not appear. Re-enable, simulate again, and confirm the interrupt does appear.
  7. Retention check. Cycle power to the controller. The implicit record configuration must reload automatically. The LPNDR block instances keep their last values from the previous session if the instance DB is marked as retentive.

Performance and Timing Notes

An acyclic PROFINET record request is a UDP frame on the PROFINET real-time channel. The round-trip time is bounded by the configured update time of the IO device:

  • Typical RT class 1 update time: 1 ms
  • Record read latency: 1–2 update cycles (1–2 ms) under light load
  • Record read latency with MRP swap in progress: up to 500 ms (MRP topology change timeout)

For periodic polling, set the polling interval to at least 100 ms. Polling faster than the update time wastes bus bandwidth without producing new data. If the value never changes, the block is reading from a cached record; reset the block instance and re-issue.

Security and Access Protection

PROFINET record access can be protected by access levels configured in TIA Portal. With the default protection level, a record write to a protected device returns 0x80A10007 (access denied). To allow writes:

  1. Open the device properties in TIA Portal.
  2. Select Protection & Security.
  3. Set the access level for the engineering account to "Full access (no protection)" or assign a password.
  4. Download the new configuration.

For production networks, use a dedicated HMI account with write access limited to the records that the application needs. Do not disable protection in the field unless the project security policy requires it.

FAQ

Can I use the LPNDR library on an S7-300 or S7-400 station?

No. The LPNDR library targets TIA Portal projects with S7-1200 and S7-1500 controllers. On S7-300/400 systems, read the same information via System Status Lists using SFC 51 (RDSYSST) with SSL_ID W#16#0131, W#16#0132, or W#16#0174, depending on the value needed.

What is the difference between explicit (RDREC / WRREC) and implicit record access on the S7-1500?

Explicit access is triggered by the user program; the application manages the REQ / BUSY / DONE state machine. Implicit access is configured in the device properties; the controller automatically copies the record payload into a configured DB at a fixed update interval without any user code. See Siemens entry 109810980 for the firmware versions that introduced implicit access.

Where do I find the hardware identifier (HID) of a PROFINET interface?

Open the device view in TIA Portal, select the IO device, and read the value from the system constants list (path: Properties → System constants → PN interface). The HID is also exposed at runtime in the input area of the RDREC / WRREC system blocks.

How do I check the MRP ring state from the user program?

Call the LPNDR Read MRP status block (or the equivalent RDREC call with record index 0x802B on the device's hardware identifier). The block returns the role, the ring state (open / closed / not connected), and the port that is currently blocked by the manager.

Why does my WRREC call return 0x80A10007?

The IO device is access-protected. Open the device properties in TIA Portal, navigate to Protection & Security, and either set the access level to "Full access" for the engineering account or supply the correct password. Re-download the configuration and re-issue the write.

What is the maximum length of a PROFINET data record?

The PROFINET specification allows records up to 65 535 bytes. The practical limit on the S7-1500 is determined by the available work memory and by the MLEN input of RDREC; in most field applications records are well below 1 kB.

Back to blog