Resolving S7-300 I-Device PROFINET Faults: CP343-1 and CPU 315

David Krause18 min read
Industrial NetworkingSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Symptom Overview

PROFINET communication does not establish between an S7-300 I-device (CPU 314 + CP 343-1) configured in STEP 7 V5.x Classic and an S7-300 IO controller (CPU 315) configured in TIA Portal V13. The I-device GSD is exported from STEP 7 and imported into the TIA project, but no cyclic process data is exchanged. Both stations report bus fault (BF) LEDs, and on the controller side the system fault (SF) LED is also latched. No diagnostic interrupts clear, and the program blocks FC11 / FC12 (PNIO_SEND / PNIO_RECV) called on the I-device do not produce any application-level handshake.

This failure mode is typical of mixed STEP 7 Classic / TIA Portal installations where an S7-300 with CP 343-1 acts as a lower-level "intelligent device" (I-device) and reports process data back to a higher-level controller. Two independent faults usually coexist in such a setup: the PROFINET connection itself is broken (BF / SF LEDs) and the application program calls the wrong data-exchange mechanism. The PROFINET connection must be repaired first; otherwise no block call can succeed regardless of which FBs / FCs are used.

Hardware and Software Topology

Reference installation:

  • I-device station: SIMATIC S7-300 with CPU 314 (for example 6ES7 314-1AG14-0AB0) and CP 343-1 (for example 6GK7 343-1EX30-0XE0, 6GK7 343-1CX10-0XE0, or 6GK7 343-1GX30-0XE0). Engineering: STEP 7 V5.5 SP4 or later with HSP for the CP 343-1 firmware present.
  • IO controller station: SIMATIC S7-300 with CPU 315 (for example 6ES7 315-2EH14-0AB0 with integrated PROFINET interface) or CPU 315-2 PN/DP. Engineering: TIA Portal V13, V13 SP1, V13 SP2, or V14.
  • Physical media: PROFINET copper cable (RJ45) on the PN port of CP 343-1 and on the integrated PN port of the CPU 315. No managed switch required for a point-to-point link, but a switch (scalance XB-005, XB-008, or XC-206) is recommended for commissioning visibility.
  • Engineering data exchange: I-device is exported as a PROFINET GSD (GSDML-Vx.x-...) file from STEP 7 Classic and imported into the TIA Portal project of the CPU 315.

LED Diagnostic Reference

LED Location State observed Meaning
BF (Bus Fault) CP 343-1 (I-device) Flashing at ~2 Hz PROFINET connection is not established: no link, IP/NameOfStation mismatch, GSD slot mismatch, or partner not in RUN. Flashes during AR establishment; solid red once a permanent fault is latched.
BF (Bus Fault) CPU 314 (I-device) Solid red PROFINET IO subsystem on the CP 343-1 reports an AR (Application Relationship) fault. Typically the controller has not yet opened an AR toward the I-device slot, or the slot configuration on the controller does not match the configured transfer areas on the I-device.
BF (Bus Fault) CPU 315C / CPU 315 PN (controller) Flashing at ~2 Hz Controller cannot reach the I-device over PROFINET: physical link down, IP not reachable, NameOfStation assignment via DCP not received, or partner CPU is in STOP / fault.
SF (System Fault) CPU 315C / CPU 315 PN (controller) Solid red A diagnostic interrupt from the PROFINET IO subsystem has been queued; the cause is in the diagnostic buffer. SF is set whenever a configured but non-reachable IO device produces a station failure.
LINK / RX/TX CP 343-1, CPU 315 Must be green / flickering Physical layer OK. If LINK is off, the cable, switch port, or auto-negotiation is at fault; PROFINET will never come up.
MAINT CP 343-1 (firmware-dependent) Yellow if maintenance demanded Maintenance event pending. Resolve the underlying diagnostic event first; this is rarely the cause of a complete AR failure.
Rule: Any BF LED - whether flashing or solid - means the PROFINET Application Relationship (AR) has not been established or has been aborted. Application-level blocks (FC11, FC12, FC5, FC6, MOVE, BLKMOV) cannot succeed until the AR is up. Always clear the BF/SF LEDs first.

Root Cause Hierarchy

In the observed fault, four causes can occur independently and must be eliminated in the order listed below. The order is chosen because each layer depends on the previous one being correct.

  1. Physical layer fault - cable, RJ45 termination, switch port, autonegotiation mismatch.
  2. IP / subnet / NameOfStation fault - the CP 343-1 and CPU 315 are on different IP subnets, the IP has not been assigned, or the PROFINET device name (NameOfStation) of the I-device is missing / wrong on the controller side.
  3. GSD slot / transfer area mismatch - the I-device GSD is imported but the slot configuration on the controller does not match the transfer areas defined on the I-device in HW Config (STEP 7 Classic). Length, type, or consistency (input vs. output) mismatch causes the controller to refuse the AR.
  4. Wrong data-exchange mechanism - the I-device program calls FC11 PNIO_SEND and FC12 PNIO_RECV, which are PN-IO-controller toward lower IO-device blocks. For I-device data exchange, the transfer areas are mapped into the CPU process image and are read/written with normal I/Q access, BLKMOV, or MOVE - not with the PNIO blocks.

PROFINET Connection Establishment Prerequisites

Before any data block can exchange a single byte, the controller must successfully complete a DCP identify / name assignment and open a PROFINET IO AR toward the I-device. The following parameters must match on both ends.

Parameter CP 343-1 (I-device) CPU 315 PN (Controller) Verification method
IP address Set in HW Config of CP 343-1 (Properties > PROFINET interface > Ethernet addresses). Default: 0.0.0.0 (DCP only). Set in Device view > PROFINET interface > Ethernet addresses of the CPU 315 PN. Ping from TIA project > "Online > Accessible nodes" or via PRONETA / Topology editor.
Subnet mask 255.255.255.0 (typical) 255.255.255.0 Must match. PROFINET does not route across subnet boundaries without a router.
PROFINET device name (NameOfStation) Configured in HW Config > PROFINET IO > Properties. This is the name the controller uses in its AR. Bound to the I-device slot under "PROFINET device name" or assigned via the topology editor / PRONETA. PRONETA / Topology discovery / Online > Accessible nodes / STEP 7 "Assign PROFINET device name".
GSD slot configuration Transfer areas configured in CP 343-1 properties > "I-device / I-slave" tab: address, length, consistency, slot. Imported GSD appears in the device catalog. Drag into the PROFINET IO system; verify that the slot and length match the I-device transfer area definition. Open both HW Configs side by side and confirm byte-for-byte parity of slot, length, direction.
Firmware / HSP support CP 343-1 firmware must be V2.x or V3.x compatible with I-device functionality. Refer to the CP 343-1 manual, section "I-device function". TIA Portal V13 / V14 GSD importer must accept the GSDML file revision. Older GSDML revisions may need re-export. Step 7 menu > Options > Install HW Updates; TIA Portal > Options > Manage General Station Description (GSD) files.
Critical: The PROFINET device name is case-sensitive. "Idevice1" and "idevice1" are different stations. DCP name assignment must be performed by the controller (CPU 315 PN) toward the CP 343-1 after every factory reset of the I-device. Use PRONETA or "Online > Accessible nodes > Assign PROFINET device name" in TIA Portal.

STEP 7 Classic I-Device Configuration on the CP 343-1

On the I-device side the CP 343-1 must be configured as an I-device, not as a plain PROFINET IO device. The configuration steps in STEP 7 V5.5 / V5.6 are:

  1. Open the S7-300 station in HW Config and double-click the CP 343-1.
  2. Switch to the "PROFINET IO" tab and tick "Operate as I-device".
  3. In the "Transfer areas" sub-tab, define one or more areas:
    • Direction: Input (data the controller writes to the I-device, so the I-device reads these as inputs) or Output (data the I-device provides to the controller).
    • Length: any value up to the maximum transfer area size supported by the CP 343-1 firmware (typically 256 bytes per area; refer to the CP manual for firmware-specific limits).
    • Consistency: Total length is recommended for areas greater than 4 bytes if the controller needs to read/write them atomically with BLKMOV / DPRD_DAT / DPWR_DAT.
    • Slot: a free slot number, typically 0, 1, or higher; must be unique within the I-device.
  4. Assign a PROFINET device name under "PROFINET IO > Properties > Ethernet addresses". Example: i-dev-314.
  5. Assign an IP address on the same subnet as the controller.
  6. Compile and download to the CPU 314 and CP 343-1.
  7. Export the I-device: menu > Options > "Export I-device / PN station as GSD" creates a GSDML file (e.g., GSDML-V2.31-Siemens-S7_CP343-1-...).

For a detailed procedure refer to the Siemens application document "I-Device Function in Standard PN Communication" and the CP 343-1 manual section on the I-device role.

GSD Export and TIA Portal V13 Import

After the GSDML export from STEP 7:

  1. Copy the GSD file and the accompanying image / text files to a folder accessible by TIA Portal.
  2. In TIA Portal V13: Options > Manage General Station Description (GSD) files > Source path > Install.
  3. After installation, the I-device appears in the hardware catalog under "PROFINET IO > Other field devices > ...". Drag it into the PROFINET IO system of the CPU 315.
  4. Open the I-device slot and verify that the configured input / output slots match exactly the transfer areas exported from STEP 7 (length, type, slot).
  5. Click on the PROFINET interface of the I-device, set the device name (must equal the NameOfStation programmed on the CP 343-1, e.g., i-dev-314), and verify the IP.
  6. Compile the S7-315 station and download.
Watch for GSDML version: If TIA Portal reports "The GSD file is not compatible with the current TIA Portal version", re-export the I-device from STEP 7 using a GSDML revision supported by the installed TIA version. STEP 7 V5.5 SP4+ can export GSDML V2.31 which is compatible with TIA V13 SP1 and later.

Controller-Side Data Access on the CPU 315

The CPU 315 acting as IO controller has an integrated PROFINET interface; no CP is required to communicate with the I-device. The data appears at the input / output addresses configured in the device view of TIA Portal. Two valid access patterns exist on the controller:

  1. Direct I/O access - the simplest method. Read inputs via L IW x / L IB x and write outputs via T QW x / T QB x. For consistency > 4 bytes, use load / transfer of word / double-word directly and accept that non-atomic access can produce torn values during updates. Sufficient for most bit / analog applications.
  2. Consistent read / write with BLKMOV / DPRD_DAT / DPWR_DAT - use BLKMOV (SFC20) for whole data blocks, or for PROFINET use the system blocks that the controller's PN interface provides:
    • DPRD_DAT (SFC14) - reads consistent data from a DP / PN slave / I-device input area.
    • DPWR_DAT (SFC15) - writes consistent data to a DP / PN slave / I-device output area.
    Both expect a hardware ID (HW identifier) obtained from the device view of the I-device slot in TIA Portal (right-click > Properties > System constants).

Example - read 10 bytes of consistent input from the I-device:

CALL SFC 14 // DPRD_DAT
LADDR  := W#16#100   // HW identifier of the I-device input area
RET_VAL:= MW 100     // return code
RECORD := P#DB20.DBX0.0 BYTE 10
NOP 0;

Example - write 10 bytes of consistent output to the I-device:

CALL SFC 15 // DPWR_DAT
LADDR  := W#16#110   // HW identifier of the I-device output area
RECORD := P#DB21.DBX0.0 BYTE 10
RET_VAL:= MW 102
NOP 0;

I-Device Side Data Access on the CPU 314

On the I-device, the CP 343-1 internally handles the PROFINET IO AR and exchanges the configured transfer areas with the controller. The CPU 314 sees the data in its process image. The access pattern on the I-device side is identical to local I/O:

  • Outputs received from the controller (controller writes, I-device reads): L IW x, L ID x, etc.
  • Inputs sent to the controller (I-device writes, controller reads): T QW x, T QD x, etc.
  • For atomic transfer: BLKMOV (SFC20) between the process-image area and a data block.

No FC, FB, or SFB is required on the I-device to publish its transfer areas. The CP 343-1 firmware performs the data exchange autonomously based on the configuration downloaded from HW Config.

Why PNIO_SEND / PNIO_RECV Are Not the Correct Block Pair

FC11 "PNIO_SEND" and FC12 "PNIO_RECV" (sometimes referenced as "PNIO_Send" / "PNIO_Receive" in STEP 7 libraries) are part of the SIMATIC NET block set for the CP 343-1 when the CP operates as a PROFINET IO controller toward subordinate IO devices. They are designed for the use case "the CP and the CPU together control a PN subnet with several real IO devices, exchanging their cyclic data with the CPU user program".

When the CP 343-1 is configured as an I-device, the role is reversed: the CP is the IO device on the higher-level controller's PROFINET subnet. The CP itself receives and publishes the transfer areas. The CPU user program does not need to call PNIO_SEND / PNIO_RECV; doing so on an I-device station will at best produce a return code that is discarded, at worst interfere with the CP's internal AR handling. Either way, the application-level data will not move.

The fix is to remove FC11 / FC12 from the I-device program and replace them with direct I/Q access (or BLKMOV). If S7 communication between the two CPUs is required in addition to PROFINET IO - for example, for acyclic record read / write or operator-authority flags - use FC5 "AG_SEND" and FC6 "AG_RECV" configured against an S7 connection on the CP 343-1, not the PNIO blocks.

Field-proven caveat: Some older STEP 7 libraries ship PNIO_SEND / PNIO_RECV under the names "FC11 / FC12" but with different semantics on different CP firmware versions. Always open the block interface and confirm the symbol "PNIO_SEND" / "PNIO_RECV" in the symbol table before deletion, especially if the program was copied from another project.

Diagnostic Buffer Evaluation

The diagnostic buffer of each station must be read in this order. In STEP 7 Classic (CPU 314 / CP 343-1): PLC > Diagnostic/Setting > Diagnostic Buffer. In TIA Portal (CPU 315): Online > Online & Diagnostics > Diagnostic buffer.

Buffer entry (typical) Station Interpretation
"IO device failure" with station number = I-device number CPU 315 Controller cannot reach the I-device. Confirm physical link, IP, NameOfStation.
"Parameter assignment error" / "Configuration error" CP 343-1 The controller sent a configuration that does not match the transfer areas. Confirm slot / length / type parity.
"AR establishment error" / "DCP timeout" CP 343-1 NameOfStation not assigned or wrong. Use PRONETA to assign / verify.
"Module / submodule not reachable" CPU 315 Slot in the I-device GSD does not exist on the real CP 343-1 transfer-area configuration.
"PNIO_SEND: busy" / "PNIO_RECV: resource error" CPU 314 PNIO blocks called on an I-device configuration. Remove them.

Step-by-Step Resolution Procedure

  1. Verify the physical layer. LINK LEDs on CP 343-1 and CPU 315 must be green. Replace cable, swap switch port, or cross-connect directly with a known-good patch cable if the link is down.
  2. Verify IP reachability. From a maintenance PG with PRONETA installed, browse "Accessible nodes". Both the CP 343-1 and the CPU 315 PN must appear with the configured IPs. If a device appears with IP 0.0.0.0, the device name must be assigned by DCP before IP can be set.
  3. Assign the PROFINET device name. In TIA Portal: Online > Accessible nodes > select the CP 343-1 (identified by MAC) > "Assign PROFINET device name" > use the exact name configured on the CP, e.g., i-dev-314. Wait until the assignment is acknowledged; the BF LED should stop flashing once the AR opens.
  4. Verify the GSD slot / length. Open HW Config of the I-device station and the TIA device view of the controller side by side. Confirm that every transfer area on the I-device has a slot of identical length and direction on the controller. If even one slot differs, the AR fails.
  5. Delete FC11 / FC12 from the I-device program. Open the OB1 of the CPU 314 (and any other OB calling them). Remove the CALL instructions. Replace any references to PNIO data with direct I/Q access or BLKMOV to / from the configured transfer-area addresses.
  6. Download the corrected I-device program and re-download the HW Config. Use "Download to target device" and select both the CPU and the CP. Stop and restart the CPU if required by the CP firmware.
  7. Re-download the controller project. In TIA Portal, download the S7-315 station. Watch the BF LED on the CPU 315 PN. It should extinguish within a few seconds if the AR opens cleanly. The SF LED should clear after the next diagnostic-buffer poll.
  8. Read the diagnostic buffer again. Confirm no fresh "IO device failure" or "parameter assignment error" entries have appeared.
  9. Force a test value. On the I-device, write a fixed pattern (e.g., 16#AAAA) to the first word of an output transfer area and verify with a watch table on the controller. On the controller, write a fixed pattern to an output transfer area and verify on the I-device.

Verification

The I-device link is healthy when all of the following are simultaneously true:

  • BF LED off on CP 343-1.
  • BF LED off on CPU 314.
  • BF and SF LEDs off on CPU 315.
  • Diagnostic buffer of CPU 315 contains no IO-device-failure entry for the I-device station number.
  • Diagnostic buffer of CP 343-1 contains no parameter-assignment error or AR-establishment error after the controller has been in RUN for at least 30 seconds.
  • In TIA Portal, online view of the I-device shows green "OK" status on every configured slot.
  • A test value written on either side appears on the other within one PROFINET update cycle (default 1 ms, configurable up to 512 ms in the device properties).

Common Edge Cases and Field Notes

  • Watchdog time mismatch. If the controller's PROFINET watchdog time is shorter than the configured transfer-area update time on the I-device, the controller will drop the AR intermittently. Set the watchdog to at least 3x the update time on the I-device properties.
  • Shared PROFINET subnet with other devices. When the CP 343-1 is on a switch with additional controllers, an unintended second controller may issue an AR with the same device name. Check the AR originator with PRONETA's "Network analysis".
  • CP 343-1 firmware older than V2.x. Some early CP 343-1 firmware revisions do not support I-device. Refer to the CP manual "Firmware version / functions" table; V2.0 or higher is typically required.
  • GSDML re-export after configuration change. Any change to the transfer areas in HW Config of the I-device requires a fresh GSDML export and re-import in TIA Portal. Otherwise the controller uses stale slot data and the BF / SF LEDs return.
  • Replacement of CP 343-1 hardware. A new CP 343-1 has empty PROFINET device name storage. Re-assign the NameOfStation before the controller can open an AR.
  • S7 connection vs. PROFINET IO. The CP 343-1 supports S7 connections on top of PROFINET IO. These are independent of the I-device AR; they require their own connection configuration (FC5 / FC6). Do not confuse AR-establishment faults (BF LED) with S7-connection faults (only visible in the diagnostic buffer / connection status).
  • Replacement CPU 315. A replacement CPU 315 PN must receive the PROFINET device name from TIA Portal before it can be the IO controller. Use "Assign PROFINET device name" via the project tree or PRONETA.

Troubleshooting Matrix

Symptom Most likely cause Action
BF solid on CPU 314, BF flashing on CP 343-1 Controller has not opened AR Check IP / NameOfStation / GSD slot match
BF solid on CPU 315, SF solid I-device not reachable or GSD slot mismatch Verify I-device GSD slot length on controller
BF clears for < 1 s then returns AR aborted, watchdog / consistency mismatch Increase controller watchdog; check consistency = "Total length" for > 4 byte areas
AR opens, but data is always zero CPU 314 program calls PNIO_SEND / PNIO_RECV; transfer areas not actually written Replace PNIO blocks with direct I/Q access
AR opens, but data is intermittent / torn Non-atomic read / write of > 4 byte area Use BLKMOV / DPRD_DAT / DPWR_DAT with "Total length" consistency
AR opens, but PRONETA shows two controllers on same device NameOfStation is non-unique or assigned twice Reset the I-device to factory defaults and re-assign the name
BF on CP 343-1, LINK LED off Physical layer Replace cable / switch port; verify autonegotiation

FAQ

Which Siemens block should I use to access I-device data on the CPU 315 PN controller?

Use direct I/Q access (e.g., L IW, T QW) for areas ≤ 4 bytes, or SFC14 DPRD_DAT and SFC15 DPWR_DAT with the hardware ID from the TIA device view for consistent areas. The CPU 315 PN does not need a CP and does not need PNIO_SEND / PNIO_RECV for I-device communication.

Why are FC11 / FC12 (PNIO_SEND / PNIO_RECV) producing no data on my I-device?

FC11 / FC12 are designed for the CP 343-1 acting as a PROFINET IO controller toward subordinate IO devices. When the CP 343-1 is configured as an I-device, the cyclic transfer areas are exchanged automatically by the CP firmware and appear in the CPU process image. Remove FC11 / FC12 and use direct I/Q access (or BLKMOV / MOVE) instead.

The BF LED on the CP 343-1 keeps flashing even though the controller is in RUN. What is wrong?

Check the PROFINET device name assignment first: use TIA Portal "Online > Accessible nodes" or PRONETA to confirm the CP 343-1 carries the exact NameOfStation configured in HW Config (case-sensitive). If the name matches, verify that the GSD slot / length on the controller matches the transfer areas defined on the I-device. Also confirm both stations share the same IP subnet.

How do I find the hardware ID for SFC14 / SFC15 in TIA Portal V13?

Open the device view of the CPU 315, select the I-device input or output slot, open Properties > System constants. The hardware identifier (e.g., HW_ID_1 or a raw hex value such as W#16#100) is listed there. Use that value for the LADDR parameter of SFC14 / SFC15.

Does the CP 343-1 require a specific firmware version for I-device functionality?

Yes. Most CP 343-1 variants support I-device starting with firmware V2.x. Refer to the CP 343-1 manual "Functions" table for the specific article number; firmware below V2.0 may reject the "Operate as I-device" tick box in HW Config. Update the firmware via the SIMATIC Automation Tool or the Web-based management of the CP if required.

Back to blog