Resolving S7-313C-2DP to SIMOTION D445 PROFIBUS Master-Master Communication Failures
1. Problem Statement
A master-master link between a SIMATIC S7-313C-2DP and a SIMOTION D445 is partially operational: data flows from the SIMOTION to the PLC, but the reverse path (PLC → SIMOTION) returns nothing. The application uses SFC65 (XSEND) / SFC66 (XRCV) on the S7-300 side and the system functions _Xsend / _Xreceive on the SIMOTION side. The asymmetry is not a wiring fault: it is a fundamental capability restriction in the S7-300 firmware that the SFC pair exposes only on the MPI/ISO transport layer, not on the integrated PROFIBUS-DP interface.
2. Affected Components and Firmware
| Component | Order Number (MLFB) | Role | Relevant Firmware |
|---|---|---|---|
| SIMATIC S7-313C-2DP | 6ES7313-6CF00-0AB0 / 6ES7313-6CG00-0AB0 | DP master, MPI node, SFC65/66 host | Firmware V2.6 / V3.0 / V3.3 (firmware ≥V3.0 required for full DP-V1) |
| SIMOTION D445 | 6AU1445-0AA00-0AA0 (D445-1) or 6AU1445-0AD00-0AA0 (D445-2) | DP master / slave, _Xsend / _Xreceive host | SIMOTION V4.1 / V4.2 / V4.4 (Scout ≥ V4.1) |
| ET 200M stations | 6ES7153-1AA03-0XB0 (IM153-1) | DP slaves | Firmware ≥ V4.0 |
| TP 177B (DP) | 6AV6642-0BA01-1AX1 | DP slave, HMI | ProTool / WinCC flexible ≥ 2007 |
| SIMOTION CU320 | 6SL3040-0MA00-0AA0 | Drive controller, DP slave | Firmware ≥ V2.5 |
The failure described in the field report is independent of the SIMOTION D445 sub-variant (D445-1 vs. D445-2). It is determined entirely by the S7-300 firmware behaviour of SFC65/SFC66.
3. Root Cause Analysis
The S7-300 system blocks SFC65 X_SEND and SFC66 X_RCV implement the SIMATIC basic communication (SBC) service. This service is bound to the MPI / ISO transport layer and is only available when the CPU port is configured for the MPI profile. Although the CPU 313C-2DP has an integrated DP master on the same physical port, the SBC service cannot be routed through a DP-master-configured port. When the port is set to PROFIBUS-DP, the CPU does not respond to MPI FDL calls, and SFC65/66 requests to a remote MPI address (the SIMOTION) are rejected at the FDL layer.
Why one-way "appears" to work:
- The SIMOTION D445
_Xsendfunction uses a different internal transport that can reach an MPI-configured S7-300 port. It is therefore not symmetric to SFC65/66 on the S7-300. - As soon as the PLC tries to push data back with SFC65, the call either returns error code
W#16#8001(communications error, partner not reachable) orW#16#8085(negative acknowledgement from partner) and the receive call on SIMOTION never sees a frame.
Per the SIMOTION SCOUT Communication System Manual, the master-master mode documented in the publication is implemented as DP class-1 I/O data exchange, not as SFC65/66 transport. The field report flags this exactly: "S7-300 doesn't support SFC65 for PROFIBUS, only for MPI." The manual page that raises expectations on the user side is describing Xsend / Xreceive on the SIMOTION side against an MPI-configured S7-300, not a true DP master-master transport pair.
4. Diagnostic Steps
- Capture the active bus configuration with STEP 7 HW Config → DP Interface Properties → Operating Mode on the S7-313C-2DP. Confirm whether the port is set to DP Master or MPI.
- Open the SIMOTION D445 project in Scout and inspect Project Navigator → Communication → Xsend/Xreceive. Note the configured MPI address of the partner.
- In the S7-300 program, place a status block on the
RET_VALof SFC65. Expect:-
W#16#0000– sent OK (data may or may not arrive depending on partner port mode) -
W#16#8001– communications error -
W#16#8085– partner NACK
-
- On the SIMOTION side, evaluate the Status output of
_Xreceive. ExpectSTATUS := FALSEwithCMDSTATUSindicating "no data pending" indefinitely. - Use a PROFIBUS tracer (e.g. PROFIBUS Diagnoser in Scout, or a Softing PROFINET/PROFIBUS analyser) to verify that the S7-300 does not emit an FDL
SDArequest with source address = its DP master address. The absence of such a frame is the definitive evidence of the SFC65/66 limitation.
5. Solution A — MPI Mode at 187.5 kbit/s (Minimum Common Denominator)
The minimal-change workaround is to set the physical port of the S7-313C-2DP to MPI and operate the link at 187.5 kbit/s, the lowest baud rate that the SIMOTION D445 reliably auto-negotiates as a DP/MPI hybrid node. The SFC65/66 SBC stack on the S7-300 will then push frames to the SIMOTION at the MPI address configured in HW Config, and the SIMOTION _Xreceive block will accept them.
5.1 HW Config — S7-313C-2DP
- Open the S7 project in STEP 7 (V5.5 or TIA V13+).
- Open the device view of the CPU 313C-2DP and select the DP/X2 port (the second port).
- In Properties → Operating Mode, select MPI.
- Set the MPI address (default 2 is acceptable, do not collide with the SIMOTION's address).
- Set the transmission rate to 187.5 kbit/s.
- Compile and download the hardware configuration.
5.2 HW Config — SIMOTION D445
- In Scout, navigate to the D445 device and open the PROFIBUS interface properties.
- Set the PROFIBUS address distinct from the S7-300 (e.g. PLC = 2, D445 = 4).
- Set the baud rate to 187.5 kbit/s.
- Disable DP-master class-1 services on the SIMOTION port if only MPI/ISO transport is used; otherwise leave DP master active to support routing into slaves.
5.3 Baud Rate Constraint
The 187.5 kbit/s rate is the lowest PROFIBUS segment rate that the D445 firmware auto-negotiates reliably. The S7-313C-2DP allows it on the MPI profile; newer S7-300 CPUs (CPU 319, CPU 317) can use higher rates, but the SBC stack on the older 313C-2DP is most stable at 187.5 kbit/s. Field reports show that pushing the link to 1.5 Mbit/s on the 313C-2DP SBC stack frequently produces intermittent W#16#8001 returns even when wiring is correct.
6. Solution B — I-Slave Topology
Where higher bandwidth or coexistence with multiple slaves is required, the link should be re-architected as a DP master – DP slave (i-slave) relationship. The SIMOTION D445 supports both directions: it can be the master and the S7-300 the i-slave, or vice versa. In the field report this is the recommended path because it preserves the higher DP baud rates and integrates cleanly with the existing ET 200M and TP 177B devices.
6.1 Option B.1 — SIMOTION as I-Slave to S7-300
- In the STEP 7 project, insert the SIMOTION D445 as a DP slave on the S7-300's DP master line. Use the GSD file SIEM811F.GSD (for the D445-1) or the appropriate Scout-exported GSD for the D445-2.
- Define the slot configuration: one input slot and one output slot, each with 16 bytes (128 bits) by default. Adjust the byte count to match the application data width.
- Compile and download to the S7-300.
- In Scout, configure the SIMOTION D445's DP interface as a DP slave and select the slot mapping generated by STEP 7.
- On the SIMOTION program, use the
_receive/_sendI/O accessors or the configured process image to expose the data to the application.
6.2 Option B.2 — S7-300 as I-Slave to SIMOTION D445
- In Scout, add the S7-300 as a slave of the SIMOTION master. Export the SIMOTION-side GSD if the SIMOTION is the master, and import it into STEP 7 to mark the CPU 313C-2DP as an i-slave.
- On the S7-300, configure the DP port to operate as a DP slave and define the I/O slot sizes.
- Use
SFC14 (DPRD_DAT)andSFC15 (DPWR_DAT)on the S7-300 to read/write the i-slave process image, replacing the failed SFC65/66 calls.
6.3 Trade-off Matrix
| Criterion | Option A: MPI 187.5 kbit/s | Option B.1: D445 as i-slave | Option B.2: 313C as i-slave |
|---|---|---|---|
| Maximum baud rate | 187.5 kbit/s | 12 Mbit/s (DP) | 12 Mbit/s (DP) |
| Code change in PLC | None (SFC65/66 unchanged) | None | Replace SFC65/66 with SFC14/15 |
| Code change in SIMOTION | None (use _Xsend/_Xreceive) | Replace _Xsend/_Xreceive with I/O image | None |
| Coexistence with ET 200M, TP 177B, CU320 | Yes (single master, mixed slaves) | Yes (S7-300 remains master) | Yes (SIMOTION becomes master) |
| Diagnostic depth | Low (SBC only) | High (DP-V0/V1 diagnostics) | High (DP-V0/V1 diagnostics) |
| Best for | Small payloads, debug, legacy retrofit | New projects, large payloads, motion-heavy | Symmetric data where SIMOTION must drive |
7. Network Configuration with ET 200M, TP 177B and CU320
The source application shares the PROFIBUS segment with two ET 200M stations (IM 153-1), a TP 177B (DP) HMI, and a CU320 drive controller. All of these are DP slaves and must be addressed by a single DP master on the segment. Putting the SIMOTION D445 in i-slave mode (Option B.1) keeps the S7-313C-2DP as the sole master; the existing slaves do not need to be reconfigured. Putting the S7-300 in i-slave mode (Option B.2) requires moving the master role to the SIMOTION D445 — the existing slaves remain attached but the master-of-master relationship inverts. Either topology is supported by all five device types; the master-role change is the only difference.
8. XSEND / XRCV Usage on the S7-300
For the record, the SFC65/66 invocation on the S7-313C-2DP is:
// S7-300 side, STL excerpt
CALL SFC 65 // X_SEND
REQ := M 10.0 // start trigger (rising edge)
CONT := TRUE // keep connection open
DEST_ID:= W#16#0004 // SIMOTION MPI address (example 4)
REQ_ID := DW#16#0000_0001 // user-defined transaction ID
SD := P#DB20.DBX0.0 // any-pointer to send data (e.g. 32 bytes)
RET_VAL:= MW 12 // status word, evaluate per §4
The companion receive call:
CALL SFC 66 // X_RCV
EN_DT := M 11.0 // enable data receipt
RET_VAL:= MW 14 // status word
REQ_ID := MW 16 // echoed ID of last successful receipt
NDA := M 18.0 // TRUE = new data available
RD := P#DB21.DBX0.0 // receive buffer (must match SD size)
The same call syntax will work in the MPI workaround (Solution A) without code change. In Option B.2, replace this pair with SFC14 (DPRD_DAT) and SFC15 (DPWR_DAT), which address the i-slave I/O image directly and do not depend on the MPI/ISO transport.
9. SIMOTION Side: _Xsend / _Xreceive
On the SIMOTION D445, the symmetric blocks are declared as system function calls within an MCC chart or a ST unit:
// SIMOTION ST, send direction (PLC <- SIMOTION)
_Xsend(REQ := send_request,
CONT := TRUE,
DEST_ID := 2, // S7-300 MPI address
REQ_ID := 1,
SD := send_data, // BYTE array or struct
RET_VAL := send_status);
// SIMOTION ST, receive direction (PLC -> SIMOTION)
_Xreceive(EN_DT := receive_enable,
RET_VAL := recv_status,
REQ_ID := recv_id,
NDA := new_data_available,
RD := recv_data);
After switching to the i-slave topology (Solution B.1), the SIMOTION accesses the same data through its process image of the DP slave, removing the need for the _Xsend / _Xreceive pair entirely. Application code that referenced those blocks must be rewritten to read/write the mapped I/O variables directly.
10. Verification Procedures
- Cyclic data check: Force a toggle in the S7-300 send area (e.g. DB20.DBB0) and observe the same byte in the SIMOTION receive image. Latency should be one DP cycle (≤ 1 ms at 12 Mbit/s, ≤ 10 ms at 187.5 kbit/s).
- Bidirectional check: Toggle in the SIMOTION send area and verify in the S7-300 receive DB. With Solution A this is the only direction that was already working; with Solutions B the directionality is symmetric.
-
SFC65 RET_VAL inspection: Place a watch table on the
RET_VALtag of SFC65. ExpectW#16#0000at the trigger edge and noW#16#8001orW#16#8085over a 10-minute soak. - Bus diagnostic counters: In Scout → Project Navigator → Commissioning → PROFIBUS Diagnostics, confirm zero CRC errors, zero retry events, and zero station-loss events on the segment.
- Slave presence test: Power-cycle each ET 200M and the TP 177B; the master must re-include them within the configured watchdog time without affecting the SIMOTION link.
11. Troubleshooting Matrix
| Symptom | Likely Cause | Action |
|---|---|---|
| SIMOTION → PLC works, PLC → SIMOTION silent | SFC65/66 misrouted to a DP-configured port | Apply Solution A (MPI 187.5 kbit/s) or Solution B (i-slave) |
| Both directions fail, SFC65 RET_VAL = W#16#8001 | Wrong MPI address, wrong baud rate, or wrong terminating resistor | Verify addresses, set both ends to 187.5 kbit/s, enable terminators |
| Both directions fail, RET_VAL = W#16#8085 | Partner not in correct SBC mode | Check SIMOTION _Xreceive enable and address |
| Intermittent failure at 1.5 Mbit/s | SBC stack on 313C-2DP unstable at higher rates | Drop to 187.5 kbit/s, or migrate to i-slave topology |
| ET 200M drops after enabling SIMOTION link | Bus termination introduced/removed incorrectly | Verify active terminators only at segment ends, not in the middle |
| TP 177B goes blank during PLC reset | TP 177B expects continuous cyclic master | Confirm the S7-300 remains the master (Solution B.1 preferred) |
12. Reference Material
For further configuration of PROFIBUS-DP master systems in TIA Portal — including the device view, slot population, and DP identifier parameterization referenced in this article — consult the official TIA Portal documentation at: The basics of configuring a DP master system (S7-300, S7-400, S7-1500).
Why does the SIMOTION D445 receive data from the S7-313C-2DP only in one direction?
Because the S7-300 firmware restricts SFC65 (XSEND) and SFC66 (XRCV) to the MPI/ISO transport layer, not to the integrated PROFIBUS-DP master. When the S7-300's DP port is configured as DP master, SFC65/66 cannot open an FDL connection to the SIMOTION. The reverse path uses SIMOTION _Xsend, which is not subject to the same restriction, so traffic flows from SIMOTION to PLC.
Is there any S7-300 firmware that supports SFC65/66 over PROFIBUS-DP?
No. The SBC stack on the S7-300 family is bound to MPI/ISO transport across all firmware versions. To carry user data over PROFIBUS-DP from the S7-300 to a remote partner, use the DP i-slave mechanism with SFC14 (DPRD_DAT) and SFC15 (DPWR_DAT), or use the MPI workaround at 187.5 kbit/s with SFC65/66.
Can the SIMOTION D445 be an i-slave to the S7-313C-2DP and still master the CU320?
Yes, in the sense that a single D445 has only one PROFIBUS interface. If it is configured as a slave of the S7-300, the CU320 must be addressed by the S7-300. If the D445 must remain master of the CU320, then the S7-300 should be the i-slave of the D445 instead (Solution B.2).
What baud rate should I pick if I keep the MPI workaround?
Set both ends to 187.5 kbit/s. The S7-313C-2DP SBC stack is most stable at that rate, and 187.5 kbit/s is the lowest baud the SIMOTION D445 reliably auto-negotiates as a hybrid DP/MPI node. Higher rates on the 313C-2DP SBC stack frequently return intermittent W#16#8001 errors.
Do I need to reconfigure the ET 200M and TP 177B when I switch to i-slave topology?
No. The ET 200M stations and the TP 177B remain attached to the DP master of the segment. Only the master role changes: in Solution B.1 the S7-313C-2DP remains the master; in Solution B.2 the SIMOTION D445 becomes the master. The slave GSD files and I/O slot mappings on the ET 200M and TP 177B are unchanged.