Resolving S7-313C-2DP SIMOTION D445 PROFIBUS Master-Master Issues

David Krause12 min read
ProfibusSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving S7-313C-2DP to SIMOTION D445 PROFIBUS Master-Master Communication Failures

1. Problem Statement

A master-master link between a SIMATIC S7-313C-2DP and a SIMOTION D445 is partially operational: data flows from the SIMOTION to the PLC, but the reverse path (PLC → SIMOTION) returns nothing. The application uses SFC65 (XSEND) / SFC66 (XRCV) on the S7-300 side and the system functions _Xsend / _Xreceive on the SIMOTION side. The asymmetry is not a wiring fault: it is a fundamental capability restriction in the S7-300 firmware that the SFC pair exposes only on the MPI/ISO transport layer, not on the integrated PROFIBUS-DP interface.

Engineering note: SFC65 / SFC66 are part of the SIMATIC "basic communication" or ISO-on-TCP transport block family. On the CPU 313C-2DP (and on the S7-300 family in general) these blocks route exclusively through the MPI/DP combined port when that port is configured as MPI. They do not open a separate PROFIBUS-DP class-1 data link on the integrated DP master. The user-visible symptom is one-way traffic that "looks like PROFIBUS" but is actually a stub of MPI traffic terminated on the SIMOTION side.

2. Affected Components and Firmware

Component Order Number (MLFB) Role Relevant Firmware
SIMATIC S7-313C-2DP 6ES7313-6CF00-0AB0 / 6ES7313-6CG00-0AB0 DP master, MPI node, SFC65/66 host Firmware V2.6 / V3.0 / V3.3 (firmware ≥V3.0 required for full DP-V1)
SIMOTION D445 6AU1445-0AA00-0AA0 (D445-1) or 6AU1445-0AD00-0AA0 (D445-2) DP master / slave, _Xsend / _Xreceive host SIMOTION V4.1 / V4.2 / V4.4 (Scout ≥ V4.1)
ET 200M stations 6ES7153-1AA03-0XB0 (IM153-1) DP slaves Firmware ≥ V4.0
TP 177B (DP) 6AV6642-0BA01-1AX1 DP slave, HMI ProTool / WinCC flexible ≥ 2007
SIMOTION CU320 6SL3040-0MA00-0AA0 Drive controller, DP slave Firmware ≥ V2.5

The failure described in the field report is independent of the SIMOTION D445 sub-variant (D445-1 vs. D445-2). It is determined entirely by the S7-300 firmware behaviour of SFC65/SFC66.

3. Root Cause Analysis

The S7-300 system blocks SFC65 X_SEND and SFC66 X_RCV implement the SIMATIC basic communication (SBC) service. This service is bound to the MPI / ISO transport layer and is only available when the CPU port is configured for the MPI profile. Although the CPU 313C-2DP has an integrated DP master on the same physical port, the SBC service cannot be routed through a DP-master-configured port. When the port is set to PROFIBUS-DP, the CPU does not respond to MPI FDL calls, and SFC65/66 requests to a remote MPI address (the SIMOTION) are rejected at the FDL layer.

Why one-way "appears" to work:

  • The SIMOTION D445 _Xsend function uses a different internal transport that can reach an MPI-configured S7-300 port. It is therefore not symmetric to SFC65/66 on the S7-300.
  • As soon as the PLC tries to push data back with SFC65, the call either returns error code W#16#8001 (communications error, partner not reachable) or W#16#8085 (negative acknowledgement from partner) and the receive call on SIMOTION never sees a frame.

Per the SIMOTION SCOUT Communication System Manual, the master-master mode documented in the publication is implemented as DP class-1 I/O data exchange, not as SFC65/66 transport. The field report flags this exactly: "S7-300 doesn't support SFC65 for PROFIBUS, only for MPI." The manual page that raises expectations on the user side is describing Xsend / Xreceive on the SIMOTION side against an MPI-configured S7-300, not a true DP master-master transport pair.

4. Diagnostic Steps

  1. Capture the active bus configuration with STEP 7 HW Config → DP Interface Properties → Operating Mode on the S7-313C-2DP. Confirm whether the port is set to DP Master or MPI.
  2. Open the SIMOTION D445 project in Scout and inspect Project Navigator → Communication → Xsend/Xreceive. Note the configured MPI address of the partner.
  3. In the S7-300 program, place a status block on the RET_VAL of SFC65. Expect:
    • W#16#0000 – sent OK (data may or may not arrive depending on partner port mode)
    • W#16#8001 – communications error
    • W#16#8085 – partner NACK
  4. On the SIMOTION side, evaluate the Status output of _Xreceive. Expect STATUS := FALSE with CMDSTATUS indicating "no data pending" indefinitely.
  5. Use a PROFIBUS tracer (e.g. PROFIBUS Diagnoser in Scout, or a Softing PROFINET/PROFIBUS analyser) to verify that the S7-300 does not emit an FDL SDA request with source address = its DP master address. The absence of such a frame is the definitive evidence of the SFC65/66 limitation.

5. Solution A — MPI Mode at 187.5 kbit/s (Minimum Common Denominator)

The minimal-change workaround is to set the physical port of the S7-313C-2DP to MPI and operate the link at 187.5 kbit/s, the lowest baud rate that the SIMOTION D445 reliably auto-negotiates as a DP/MPI hybrid node. The SFC65/66 SBC stack on the S7-300 will then push frames to the SIMOTION at the MPI address configured in HW Config, and the SIMOTION _Xreceive block will accept them.

5.1 HW Config — S7-313C-2DP

  1. Open the S7 project in STEP 7 (V5.5 or TIA V13+).
  2. Open the device view of the CPU 313C-2DP and select the DP/X2 port (the second port).
  3. In Properties → Operating Mode, select MPI.
  4. Set the MPI address (default 2 is acceptable, do not collide with the SIMOTION's address).
  5. Set the transmission rate to 187.5 kbit/s.
  6. Compile and download the hardware configuration.

5.2 HW Config — SIMOTION D445

  1. In Scout, navigate to the D445 device and open the PROFIBUS interface properties.
  2. Set the PROFIBUS address distinct from the S7-300 (e.g. PLC = 2, D445 = 4).
  3. Set the baud rate to 187.5 kbit/s.
  4. Disable DP-master class-1 services on the SIMOTION port if only MPI/ISO transport is used; otherwise leave DP master active to support routing into slaves.

5.3 Baud Rate Constraint

The 187.5 kbit/s rate is the lowest PROFIBUS segment rate that the D445 firmware auto-negotiates reliably. The S7-313C-2DP allows it on the MPI profile; newer S7-300 CPUs (CPU 319, CPU 317) can use higher rates, but the SBC stack on the older 313C-2DP is most stable at 187.5 kbit/s. Field reports show that pushing the link to 1.5 Mbit/s on the 313C-2DP SBC stack frequently produces intermittent W#16#8001 returns even when wiring is correct.

6. Solution B — I-Slave Topology

Where higher bandwidth or coexistence with multiple slaves is required, the link should be re-architected as a DP master – DP slave (i-slave) relationship. The SIMOTION D445 supports both directions: it can be the master and the S7-300 the i-slave, or vice versa. In the field report this is the recommended path because it preserves the higher DP baud rates and integrates cleanly with the existing ET 200M and TP 177B devices.

6.1 Option B.1 — SIMOTION as I-Slave to S7-300

  1. In the STEP 7 project, insert the SIMOTION D445 as a DP slave on the S7-300's DP master line. Use the GSD file SIEM811F.GSD (for the D445-1) or the appropriate Scout-exported GSD for the D445-2.
  2. Define the slot configuration: one input slot and one output slot, each with 16 bytes (128 bits) by default. Adjust the byte count to match the application data width.
  3. Compile and download to the S7-300.
  4. In Scout, configure the SIMOTION D445's DP interface as a DP slave and select the slot mapping generated by STEP 7.
  5. On the SIMOTION program, use the _receive / _send I/O accessors or the configured process image to expose the data to the application.

6.2 Option B.2 — S7-300 as I-Slave to SIMOTION D445

  1. In Scout, add the S7-300 as a slave of the SIMOTION master. Export the SIMOTION-side GSD if the SIMOTION is the master, and import it into STEP 7 to mark the CPU 313C-2DP as an i-slave.
  2. On the S7-300, configure the DP port to operate as a DP slave and define the I/O slot sizes.
  3. Use SFC14 (DPRD_DAT) and SFC15 (DPWR_DAT) on the S7-300 to read/write the i-slave process image, replacing the failed SFC65/66 calls.

6.3 Trade-off Matrix

Criterion Option A: MPI 187.5 kbit/s Option B.1: D445 as i-slave Option B.2: 313C as i-slave
Maximum baud rate 187.5 kbit/s 12 Mbit/s (DP) 12 Mbit/s (DP)
Code change in PLC None (SFC65/66 unchanged) None Replace SFC65/66 with SFC14/15
Code change in SIMOTION None (use _Xsend/_Xreceive) Replace _Xsend/_Xreceive with I/O image None
Coexistence with ET 200M, TP 177B, CU320 Yes (single master, mixed slaves) Yes (S7-300 remains master) Yes (SIMOTION becomes master)
Diagnostic depth Low (SBC only) High (DP-V0/V1 diagnostics) High (DP-V0/V1 diagnostics)
Best for Small payloads, debug, legacy retrofit New projects, large payloads, motion-heavy Symmetric data where SIMOTION must drive

7. Network Configuration with ET 200M, TP 177B and CU320

The source application shares the PROFIBUS segment with two ET 200M stations (IM 153-1), a TP 177B (DP) HMI, and a CU320 drive controller. All of these are DP slaves and must be addressed by a single DP master on the segment. Putting the SIMOTION D445 in i-slave mode (Option B.1) keeps the S7-313C-2DP as the sole master; the existing slaves do not need to be reconfigured. Putting the S7-300 in i-slave mode (Option B.2) requires moving the master role to the SIMOTION D445 — the existing slaves remain attached but the master-of-master relationship inverts. Either topology is supported by all five device types; the master-role change is the only difference.

Bus termination and topology: When the baud rate is dropped to 187.5 kbit/s (Solution A), the maximum stub length and segment length are dominated by the DP cable specification (EN 50170). At 187.5 kbit/s a single segment can reach 1 200 m, so most retrofit segments fit without repeaters. At 12 Mbit/s (Solution B), segment length is capped at 100 m and termination must be active at both ends. The SIMOTION D445 provides internal termination that can be enabled in HW Config if the D445 sits at the end of the line.

8. XSEND / XRCV Usage on the S7-300

For the record, the SFC65/66 invocation on the S7-313C-2DP is:

// S7-300 side, STL excerpt
CALL  SFC 65 // X_SEND
 REQ    := M 10.0           // start trigger (rising edge)
 CONT   := TRUE              // keep connection open
 DEST_ID:= W#16#0004         // SIMOTION MPI address (example 4)
 REQ_ID := DW#16#0000_0001   // user-defined transaction ID
 SD     := P#DB20.DBX0.0     // any-pointer to send data (e.g. 32 bytes)
 RET_VAL:= MW 12             // status word, evaluate per §4

The companion receive call:

CALL  SFC 66 // X_RCV
 EN_DT := M 11.0             // enable data receipt
 RET_VAL:= MW 14             // status word
 REQ_ID := MW 16             // echoed ID of last successful receipt
 NDA    := M 18.0            // TRUE = new data available
 RD     := P#DB21.DBX0.0     // receive buffer (must match SD size)

The same call syntax will work in the MPI workaround (Solution A) without code change. In Option B.2, replace this pair with SFC14 (DPRD_DAT) and SFC15 (DPWR_DAT), which address the i-slave I/O image directly and do not depend on the MPI/ISO transport.

9. SIMOTION Side: _Xsend / _Xreceive

On the SIMOTION D445, the symmetric blocks are declared as system function calls within an MCC chart or a ST unit:

// SIMOTION ST, send direction (PLC <- SIMOTION)
_Xsend(REQ := send_request,
       CONT := TRUE,
       DEST_ID := 2,            // S7-300 MPI address
       REQ_ID := 1,
       SD := send_data,         // BYTE array or struct
       RET_VAL := send_status);

// SIMOTION ST, receive direction (PLC -> SIMOTION)
_Xreceive(EN_DT := receive_enable,
          RET_VAL := recv_status,
          REQ_ID := recv_id,
          NDA := new_data_available,
          RD := recv_data);

After switching to the i-slave topology (Solution B.1), the SIMOTION accesses the same data through its process image of the DP slave, removing the need for the _Xsend / _Xreceive pair entirely. Application code that referenced those blocks must be rewritten to read/write the mapped I/O variables directly.

10. Verification Procedures

  1. Cyclic data check: Force a toggle in the S7-300 send area (e.g. DB20.DBB0) and observe the same byte in the SIMOTION receive image. Latency should be one DP cycle (≤ 1 ms at 12 Mbit/s, ≤ 10 ms at 187.5 kbit/s).
  2. Bidirectional check: Toggle in the SIMOTION send area and verify in the S7-300 receive DB. With Solution A this is the only direction that was already working; with Solutions B the directionality is symmetric.
  3. SFC65 RET_VAL inspection: Place a watch table on the RET_VAL tag of SFC65. Expect W#16#0000 at the trigger edge and no W#16#8001 or W#16#8085 over a 10-minute soak.
  4. Bus diagnostic counters: In Scout → Project Navigator → Commissioning → PROFIBUS Diagnostics, confirm zero CRC errors, zero retry events, and zero station-loss events on the segment.
  5. Slave presence test: Power-cycle each ET 200M and the TP 177B; the master must re-include them within the configured watchdog time without affecting the SIMOTION link.

11. Troubleshooting Matrix

Symptom Likely Cause Action
SIMOTION → PLC works, PLC → SIMOTION silent SFC65/66 misrouted to a DP-configured port Apply Solution A (MPI 187.5 kbit/s) or Solution B (i-slave)
Both directions fail, SFC65 RET_VAL = W#16#8001 Wrong MPI address, wrong baud rate, or wrong terminating resistor Verify addresses, set both ends to 187.5 kbit/s, enable terminators
Both directions fail, RET_VAL = W#16#8085 Partner not in correct SBC mode Check SIMOTION _Xreceive enable and address
Intermittent failure at 1.5 Mbit/s SBC stack on 313C-2DP unstable at higher rates Drop to 187.5 kbit/s, or migrate to i-slave topology
ET 200M drops after enabling SIMOTION link Bus termination introduced/removed incorrectly Verify active terminators only at segment ends, not in the middle
TP 177B goes blank during PLC reset TP 177B expects continuous cyclic master Confirm the S7-300 remains the master (Solution B.1 preferred)

12. Reference Material

For further configuration of PROFIBUS-DP master systems in TIA Portal — including the device view, slot population, and DP identifier parameterization referenced in this article — consult the official TIA Portal documentation at: The basics of configuring a DP master system (S7-300, S7-400, S7-1500).

Why does the SIMOTION D445 receive data from the S7-313C-2DP only in one direction?

Because the S7-300 firmware restricts SFC65 (XSEND) and SFC66 (XRCV) to the MPI/ISO transport layer, not to the integrated PROFIBUS-DP master. When the S7-300's DP port is configured as DP master, SFC65/66 cannot open an FDL connection to the SIMOTION. The reverse path uses SIMOTION _Xsend, which is not subject to the same restriction, so traffic flows from SIMOTION to PLC.

Is there any S7-300 firmware that supports SFC65/66 over PROFIBUS-DP?

No. The SBC stack on the S7-300 family is bound to MPI/ISO transport across all firmware versions. To carry user data over PROFIBUS-DP from the S7-300 to a remote partner, use the DP i-slave mechanism with SFC14 (DPRD_DAT) and SFC15 (DPWR_DAT), or use the MPI workaround at 187.5 kbit/s with SFC65/66.

Can the SIMOTION D445 be an i-slave to the S7-313C-2DP and still master the CU320?

Yes, in the sense that a single D445 has only one PROFIBUS interface. If it is configured as a slave of the S7-300, the CU320 must be addressed by the S7-300. If the D445 must remain master of the CU320, then the S7-300 should be the i-slave of the D445 instead (Solution B.2).

What baud rate should I pick if I keep the MPI workaround?

Set both ends to 187.5 kbit/s. The S7-313C-2DP SBC stack is most stable at that rate, and 187.5 kbit/s is the lowest baud the SIMOTION D445 reliably auto-negotiates as a hybrid DP/MPI node. Higher rates on the 313C-2DP SBC stack frequently return intermittent W#16#8001 errors.

Do I need to reconfigure the ET 200M and TP 177B when I switch to i-slave topology?

No. The ET 200M stations and the TP 177B remain attached to the DP master of the segment. Only the master role changes: in Solution B.1 the S7-313C-2DP remains the master; in Solution B.2 the SIMOTION D445 becomes the master. The slave GSD files and I/O slot mappings on the ET 200M and TP 177B are unchanged.

Back to blog