Symptom Overview
PROFINET communication does not establish between an S7-300 I-device (CPU 314 + CP 343-1) configured in STEP 7 V5.x Classic and an S7-300 IO controller (CPU 315) configured in TIA Portal V13. The I-device GSD is exported from STEP 7 and imported into the TIA project, but no cyclic process data is exchanged. Both stations report bus fault (BF) LEDs, and on the controller side the system fault (SF) LED is also latched. No diagnostic interrupts clear, and the program blocks FC11 / FC12 (PNIO_SEND / PNIO_RECV) called on the I-device do not produce any application-level handshake.
This failure mode is typical of mixed STEP 7 Classic / TIA Portal installations where an S7-300 with CP 343-1 acts as a lower-level "intelligent device" (I-device) and reports process data back to a higher-level controller. Two independent faults usually coexist in such a setup: the PROFINET connection itself is broken (BF / SF LEDs) and the application program calls the wrong data-exchange mechanism. The PROFINET connection must be repaired first; otherwise no block call can succeed regardless of which FBs / FCs are used.
Hardware and Software Topology
Reference installation:
- I-device station: SIMATIC S7-300 with CPU 314 (for example 6ES7 314-1AG14-0AB0) and CP 343-1 (for example 6GK7 343-1EX30-0XE0, 6GK7 343-1CX10-0XE0, or 6GK7 343-1GX30-0XE0). Engineering: STEP 7 V5.5 SP4 or later with HSP for the CP 343-1 firmware present.
- IO controller station: SIMATIC S7-300 with CPU 315 (for example 6ES7 315-2EH14-0AB0 with integrated PROFINET interface) or CPU 315-2 PN/DP. Engineering: TIA Portal V13, V13 SP1, V13 SP2, or V14.
- Physical media: PROFINET copper cable (RJ45) on the PN port of CP 343-1 and on the integrated PN port of the CPU 315. No managed switch required for a point-to-point link, but a switch (scalance XB-005, XB-008, or XC-206) is recommended for commissioning visibility.
- Engineering data exchange: I-device is exported as a PROFINET GSD (GSDML-Vx.x-...) file from STEP 7 Classic and imported into the TIA Portal project of the CPU 315.
LED Diagnostic Reference
| LED | Location | State observed | Meaning |
|---|---|---|---|
| BF (Bus Fault) | CP 343-1 (I-device) | Flashing at ~2 Hz | PROFINET connection is not established: no link, IP/NameOfStation mismatch, GSD slot mismatch, or partner not in RUN. Flashes during AR establishment; solid red once a permanent fault is latched. |
| BF (Bus Fault) | CPU 314 (I-device) | Solid red | PROFINET IO subsystem on the CP 343-1 reports an AR (Application Relationship) fault. Typically the controller has not yet opened an AR toward the I-device slot, or the slot configuration on the controller does not match the configured transfer areas on the I-device. |
| BF (Bus Fault) | CPU 315C / CPU 315 PN (controller) | Flashing at ~2 Hz | Controller cannot reach the I-device over PROFINET: physical link down, IP not reachable, NameOfStation assignment via DCP not received, or partner CPU is in STOP / fault. |
| SF (System Fault) | CPU 315C / CPU 315 PN (controller) | Solid red | A diagnostic interrupt from the PROFINET IO subsystem has been queued; the cause is in the diagnostic buffer. SF is set whenever a configured but non-reachable IO device produces a station failure. |
| LINK / RX/TX | CP 343-1, CPU 315 | Must be green / flickering | Physical layer OK. If LINK is off, the cable, switch port, or auto-negotiation is at fault; PROFINET will never come up. |
| MAINT | CP 343-1 (firmware-dependent) | Yellow if maintenance demanded | Maintenance event pending. Resolve the underlying diagnostic event first; this is rarely the cause of a complete AR failure. |
Root Cause Hierarchy
In the observed fault, four causes can occur independently and must be eliminated in the order listed below. The order is chosen because each layer depends on the previous one being correct.
- Physical layer fault - cable, RJ45 termination, switch port, autonegotiation mismatch.
- IP / subnet / NameOfStation fault - the CP 343-1 and CPU 315 are on different IP subnets, the IP has not been assigned, or the PROFINET device name (NameOfStation) of the I-device is missing / wrong on the controller side.
- GSD slot / transfer area mismatch - the I-device GSD is imported but the slot configuration on the controller does not match the transfer areas defined on the I-device in HW Config (STEP 7 Classic). Length, type, or consistency (input vs. output) mismatch causes the controller to refuse the AR.
- Wrong data-exchange mechanism - the I-device program calls FC11 PNIO_SEND and FC12 PNIO_RECV, which are PN-IO-controller toward lower IO-device blocks. For I-device data exchange, the transfer areas are mapped into the CPU process image and are read/written with normal I/Q access, BLKMOV, or MOVE - not with the PNIO blocks.
PROFINET Connection Establishment Prerequisites
Before any data block can exchange a single byte, the controller must successfully complete a DCP identify / name assignment and open a PROFINET IO AR toward the I-device. The following parameters must match on both ends.
| Parameter | CP 343-1 (I-device) | CPU 315 PN (Controller) | Verification method |
|---|---|---|---|
| IP address | Set in HW Config of CP 343-1 (Properties > PROFINET interface > Ethernet addresses). Default: 0.0.0.0 (DCP only). | Set in Device view > PROFINET interface > Ethernet addresses of the CPU 315 PN. | Ping from TIA project > "Online > Accessible nodes" or via PRONETA / Topology editor. |
| Subnet mask | 255.255.255.0 (typical) | 255.255.255.0 | Must match. PROFINET does not route across subnet boundaries without a router. |
| PROFINET device name (NameOfStation) | Configured in HW Config > PROFINET IO > Properties. This is the name the controller uses in its AR. | Bound to the I-device slot under "PROFINET device name" or assigned via the topology editor / PRONETA. | PRONETA / Topology discovery / Online > Accessible nodes / STEP 7 "Assign PROFINET device name". |
| GSD slot configuration | Transfer areas configured in CP 343-1 properties > "I-device / I-slave" tab: address, length, consistency, slot. | Imported GSD appears in the device catalog. Drag into the PROFINET IO system; verify that the slot and length match the I-device transfer area definition. | Open both HW Configs side by side and confirm byte-for-byte parity of slot, length, direction. |
| Firmware / HSP support | CP 343-1 firmware must be V2.x or V3.x compatible with I-device functionality. Refer to the CP 343-1 manual, section "I-device function". | TIA Portal V13 / V14 GSD importer must accept the GSDML file revision. Older GSDML revisions may need re-export. | Step 7 menu > Options > Install HW Updates; TIA Portal > Options > Manage General Station Description (GSD) files. |
STEP 7 Classic I-Device Configuration on the CP 343-1
On the I-device side the CP 343-1 must be configured as an I-device, not as a plain PROFINET IO device. The configuration steps in STEP 7 V5.5 / V5.6 are:
- Open the S7-300 station in HW Config and double-click the CP 343-1.
- Switch to the "PROFINET IO" tab and tick "Operate as I-device".
- In the "Transfer areas" sub-tab, define one or more areas:
- Direction: Input (data the controller writes to the I-device, so the I-device reads these as inputs) or Output (data the I-device provides to the controller).
- Length: any value up to the maximum transfer area size supported by the CP 343-1 firmware (typically 256 bytes per area; refer to the CP manual for firmware-specific limits).
- Consistency: Total length is recommended for areas greater than 4 bytes if the controller needs to read/write them atomically with BLKMOV / DPRD_DAT / DPWR_DAT.
- Slot: a free slot number, typically 0, 1, or higher; must be unique within the I-device.
- Assign a PROFINET device name under "PROFINET IO > Properties > Ethernet addresses". Example:
i-dev-314. - Assign an IP address on the same subnet as the controller.
- Compile and download to the CPU 314 and CP 343-1.
- Export the I-device: menu > Options > "Export I-device / PN station as GSD" creates a GSDML file (e.g.,
GSDML-V2.31-Siemens-S7_CP343-1-...).
For a detailed procedure refer to the Siemens application document "I-Device Function in Standard PN Communication" and the CP 343-1 manual section on the I-device role.
GSD Export and TIA Portal V13 Import
After the GSDML export from STEP 7:
- Copy the GSD file and the accompanying image / text files to a folder accessible by TIA Portal.
- In TIA Portal V13:
Options > Manage General Station Description (GSD) files > Source path > Install. - After installation, the I-device appears in the hardware catalog under "PROFINET IO > Other field devices > ...". Drag it into the PROFINET IO system of the CPU 315.
- Open the I-device slot and verify that the configured input / output slots match exactly the transfer areas exported from STEP 7 (length, type, slot).
- Click on the PROFINET interface of the I-device, set the device name (must equal the NameOfStation programmed on the CP 343-1, e.g.,
i-dev-314), and verify the IP. - Compile the S7-315 station and download.
Controller-Side Data Access on the CPU 315
The CPU 315 acting as IO controller has an integrated PROFINET interface; no CP is required to communicate with the I-device. The data appears at the input / output addresses configured in the device view of TIA Portal. Two valid access patterns exist on the controller:
-
Direct I/O access - the simplest method. Read inputs via
L IW x/L IB xand write outputs viaT QW x/T QB x. For consistency > 4 bytes, use load / transfer of word / double-word directly and accept that non-atomic access can produce torn values during updates. Sufficient for most bit / analog applications. -
Consistent read / write with BLKMOV / DPRD_DAT / DPWR_DAT - use BLKMOV (SFC20) for whole data blocks, or for PROFINET use the system blocks that the controller's PN interface provides:
-
DPRD_DAT(SFC14) - reads consistent data from a DP / PN slave / I-device input area. -
DPWR_DAT(SFC15) - writes consistent data to a DP / PN slave / I-device output area.
-
Example - read 10 bytes of consistent input from the I-device:
CALL SFC 14 // DPRD_DAT
LADDR := W#16#100 // HW identifier of the I-device input area
RET_VAL:= MW 100 // return code
RECORD := P#DB20.DBX0.0 BYTE 10
NOP 0;
Example - write 10 bytes of consistent output to the I-device:
CALL SFC 15 // DPWR_DAT
LADDR := W#16#110 // HW identifier of the I-device output area
RECORD := P#DB21.DBX0.0 BYTE 10
RET_VAL:= MW 102
NOP 0;
I-Device Side Data Access on the CPU 314
On the I-device, the CP 343-1 internally handles the PROFINET IO AR and exchanges the configured transfer areas with the controller. The CPU 314 sees the data in its process image. The access pattern on the I-device side is identical to local I/O:
- Outputs received from the controller (controller writes, I-device reads):
L IW x,L ID x, etc. - Inputs sent to the controller (I-device writes, controller reads):
T QW x,T QD x, etc. - For atomic transfer:
BLKMOV(SFC20) between the process-image area and a data block.
No FC, FB, or SFB is required on the I-device to publish its transfer areas. The CP 343-1 firmware performs the data exchange autonomously based on the configuration downloaded from HW Config.
Why PNIO_SEND / PNIO_RECV Are Not the Correct Block Pair
FC11 "PNIO_SEND" and FC12 "PNIO_RECV" (sometimes referenced as "PNIO_Send" / "PNIO_Receive" in STEP 7 libraries) are part of the SIMATIC NET block set for the CP 343-1 when the CP operates as a PROFINET IO controller toward subordinate IO devices. They are designed for the use case "the CP and the CPU together control a PN subnet with several real IO devices, exchanging their cyclic data with the CPU user program".
When the CP 343-1 is configured as an I-device, the role is reversed: the CP is the IO device on the higher-level controller's PROFINET subnet. The CP itself receives and publishes the transfer areas. The CPU user program does not need to call PNIO_SEND / PNIO_RECV; doing so on an I-device station will at best produce a return code that is discarded, at worst interfere with the CP's internal AR handling. Either way, the application-level data will not move.
The fix is to remove FC11 / FC12 from the I-device program and replace them with direct I/Q access (or BLKMOV). If S7 communication between the two CPUs is required in addition to PROFINET IO - for example, for acyclic record read / write or operator-authority flags - use FC5 "AG_SEND" and FC6 "AG_RECV" configured against an S7 connection on the CP 343-1, not the PNIO blocks.
Diagnostic Buffer Evaluation
The diagnostic buffer of each station must be read in this order. In STEP 7 Classic (CPU 314 / CP 343-1): PLC > Diagnostic/Setting > Diagnostic Buffer. In TIA Portal (CPU 315): Online > Online & Diagnostics > Diagnostic buffer.
| Buffer entry (typical) | Station | Interpretation |
|---|---|---|
| "IO device failure" with station number = I-device number | CPU 315 | Controller cannot reach the I-device. Confirm physical link, IP, NameOfStation. |
| "Parameter assignment error" / "Configuration error" | CP 343-1 | The controller sent a configuration that does not match the transfer areas. Confirm slot / length / type parity. |
| "AR establishment error" / "DCP timeout" | CP 343-1 | NameOfStation not assigned or wrong. Use PRONETA to assign / verify. |
| "Module / submodule not reachable" | CPU 315 | Slot in the I-device GSD does not exist on the real CP 343-1 transfer-area configuration. |
| "PNIO_SEND: busy" / "PNIO_RECV: resource error" | CPU 314 | PNIO blocks called on an I-device configuration. Remove them. |
Step-by-Step Resolution Procedure
- Verify the physical layer. LINK LEDs on CP 343-1 and CPU 315 must be green. Replace cable, swap switch port, or cross-connect directly with a known-good patch cable if the link is down.
- Verify IP reachability. From a maintenance PG with PRONETA installed, browse "Accessible nodes". Both the CP 343-1 and the CPU 315 PN must appear with the configured IPs. If a device appears with IP 0.0.0.0, the device name must be assigned by DCP before IP can be set.
-
Assign the PROFINET device name. In TIA Portal:
Online > Accessible nodes > select the CP 343-1 (identified by MAC) > "Assign PROFINET device name" > use the exact name configured on the CP, e.g.,. Wait until the assignment is acknowledged; the BF LED should stop flashing once the AR opens.i-dev-314 - Verify the GSD slot / length. Open HW Config of the I-device station and the TIA device view of the controller side by side. Confirm that every transfer area on the I-device has a slot of identical length and direction on the controller. If even one slot differs, the AR fails.
- Delete FC11 / FC12 from the I-device program. Open the OB1 of the CPU 314 (and any other OB calling them). Remove the CALL instructions. Replace any references to PNIO data with direct I/Q access or BLKMOV to / from the configured transfer-area addresses.
- Download the corrected I-device program and re-download the HW Config. Use "Download to target device" and select both the CPU and the CP. Stop and restart the CPU if required by the CP firmware.
- Re-download the controller project. In TIA Portal, download the S7-315 station. Watch the BF LED on the CPU 315 PN. It should extinguish within a few seconds if the AR opens cleanly. The SF LED should clear after the next diagnostic-buffer poll.
- Read the diagnostic buffer again. Confirm no fresh "IO device failure" or "parameter assignment error" entries have appeared.
- Force a test value. On the I-device, write a fixed pattern (e.g., 16#AAAA) to the first word of an output transfer area and verify with a watch table on the controller. On the controller, write a fixed pattern to an output transfer area and verify on the I-device.
Verification
The I-device link is healthy when all of the following are simultaneously true:
- BF LED off on CP 343-1.
- BF LED off on CPU 314.
- BF and SF LEDs off on CPU 315.
- Diagnostic buffer of CPU 315 contains no IO-device-failure entry for the I-device station number.
- Diagnostic buffer of CP 343-1 contains no parameter-assignment error or AR-establishment error after the controller has been in RUN for at least 30 seconds.
- In TIA Portal, online view of the I-device shows green "OK" status on every configured slot.
- A test value written on either side appears on the other within one PROFINET update cycle (default 1 ms, configurable up to 512 ms in the device properties).
Common Edge Cases and Field Notes
- Watchdog time mismatch. If the controller's PROFINET watchdog time is shorter than the configured transfer-area update time on the I-device, the controller will drop the AR intermittently. Set the watchdog to at least 3x the update time on the I-device properties.
- Shared PROFINET subnet with other devices. When the CP 343-1 is on a switch with additional controllers, an unintended second controller may issue an AR with the same device name. Check the AR originator with PRONETA's "Network analysis".
- CP 343-1 firmware older than V2.x. Some early CP 343-1 firmware revisions do not support I-device. Refer to the CP manual "Firmware version / functions" table; V2.0 or higher is typically required.
- GSDML re-export after configuration change. Any change to the transfer areas in HW Config of the I-device requires a fresh GSDML export and re-import in TIA Portal. Otherwise the controller uses stale slot data and the BF / SF LEDs return.
- Replacement of CP 343-1 hardware. A new CP 343-1 has empty PROFINET device name storage. Re-assign the NameOfStation before the controller can open an AR.
- S7 connection vs. PROFINET IO. The CP 343-1 supports S7 connections on top of PROFINET IO. These are independent of the I-device AR; they require their own connection configuration (FC5 / FC6). Do not confuse AR-establishment faults (BF LED) with S7-connection faults (only visible in the diagnostic buffer / connection status).
- Replacement CPU 315. A replacement CPU 315 PN must receive the PROFINET device name from TIA Portal before it can be the IO controller. Use "Assign PROFINET device name" via the project tree or PRONETA.
Troubleshooting Matrix
| Symptom | Most likely cause | Action |
|---|---|---|
| BF solid on CPU 314, BF flashing on CP 343-1 | Controller has not opened AR | Check IP / NameOfStation / GSD slot match |
| BF solid on CPU 315, SF solid | I-device not reachable or GSD slot mismatch | Verify I-device GSD slot length on controller |
| BF clears for < 1 s then returns | AR aborted, watchdog / consistency mismatch | Increase controller watchdog; check consistency = "Total length" for > 4 byte areas |
| AR opens, but data is always zero | CPU 314 program calls PNIO_SEND / PNIO_RECV; transfer areas not actually written | Replace PNIO blocks with direct I/Q access |
| AR opens, but data is intermittent / torn | Non-atomic read / write of > 4 byte area | Use BLKMOV / DPRD_DAT / DPWR_DAT with "Total length" consistency |
| AR opens, but PRONETA shows two controllers on same device | NameOfStation is non-unique or assigned twice | Reset the I-device to factory defaults and re-assign the name |
| BF on CP 343-1, LINK LED off | Physical layer | Replace cable / switch port; verify autonegotiation |
FAQ
Which Siemens block should I use to access I-device data on the CPU 315 PN controller?
Use direct I/Q access (e.g., L IW, T QW) for areas ≤ 4 bytes, or SFC14 DPRD_DAT and SFC15 DPWR_DAT with the hardware ID from the TIA device view for consistent areas. The CPU 315 PN does not need a CP and does not need PNIO_SEND / PNIO_RECV for I-device communication.
Why are FC11 / FC12 (PNIO_SEND / PNIO_RECV) producing no data on my I-device?
FC11 / FC12 are designed for the CP 343-1 acting as a PROFINET IO controller toward subordinate IO devices. When the CP 343-1 is configured as an I-device, the cyclic transfer areas are exchanged automatically by the CP firmware and appear in the CPU process image. Remove FC11 / FC12 and use direct I/Q access (or BLKMOV / MOVE) instead.
The BF LED on the CP 343-1 keeps flashing even though the controller is in RUN. What is wrong?
Check the PROFINET device name assignment first: use TIA Portal "Online > Accessible nodes" or PRONETA to confirm the CP 343-1 carries the exact NameOfStation configured in HW Config (case-sensitive). If the name matches, verify that the GSD slot / length on the controller matches the transfer areas defined on the I-device. Also confirm both stations share the same IP subnet.
How do I find the hardware ID for SFC14 / SFC15 in TIA Portal V13?
Open the device view of the CPU 315, select the I-device input or output slot, open Properties > System constants. The hardware identifier (e.g., HW_ID_1 or a raw hex value such as W#16#100) is listed there. Use that value for the LADDR parameter of SFC14 / SFC15.
Does the CP 343-1 require a specific firmware version for I-device functionality?
Yes. Most CP 343-1 variants support I-device starting with firmware V2.x. Refer to the CP 343-1 manual "Functions" table for the specific article number; firmware below V2.0 may reject the "Operate as I-device" tick box in HW Config. Update the firmware via the SIMATIC Automation Tool or the Web-based management of the CP if required.