Resolving SIMATIC OP7 Communication Failures with S5-95U PLC
The SIMATIC OP7 operator panel paired with an S5-95U CPU is a classic automation combination that remains in service across many manufacturing facilities. When the original OP7 fails and a replacement unit is installed, the panel frequently refuses to communicate with the S5 controller despite a correct ProTool configuration transfer. The root cause almost always lies in a mismatch between the S5 program's communication function block and the revision expected by the OP7 firmware. This reference documents the full diagnostic path, firmware management, and the FB51 / FB151 replacement procedure that resolves the failure, plus cabling and electrical checks frequently overlooked after a panel swap.
1. Hardware Identification: OP7-PP vs OP7-DP
The SIMATIC OP7 was offered in two interface variants that are not interchangeable. Confirming the model before any software work avoids days of misdirected troubleshooting. The faceplate label and the MLFB (order number) are the only reliable identifiers because both variants look identical from the front.
| Variant | MLFB Order Number | On-board Interface | Protocol | Compatible S5 CPUs |
|---|---|---|---|---|
| OP7-PP (Point-to-Point) | 6AV3 607-1JC00-0AX2 | TTY / 20 mA current loop | AS511 | S5-90U, S5-95U, S5-100U, S5-115U, S5-135U, S5-155U |
| OP7-DP | 6AV3 607-1JC10-0AX0 | RS-485 PROFIBUS | PROFIBUS-DP | S5-95U/DP, S5-115U with DP-CP, ET 200U |
The OP7-DP does not implement AS511. Replacing an OP7-PP with a DP variant will never establish communication with an S5-95U CPU that is not configured as a DP slave. The label "Operator Panel OP7-PP" and the order number 6AV3 607-1JC00-0AX2 identify the correct replacement for an AS511 link.
2. AS511 Protocol Fundamentals
AS511 is a serial point-to-point protocol operating over a 20 mA current loop at 9600 bit/s. The S5-95U exposes the AS511 interface on the front X2 connector (15-pin sub-D) and the OP7-PP terminates the link on its 15-pin sub-D port. Both devices must be configured for matching active/passive current-loop roles. The S5-95U is typically wired as the active source; the OP7-PP is passive. Reversing this assignment is a common cabling error after a panel swap and will not be flagged by ProTool transfer mode.
| Parameter | Value |
|---|---|
| Physical layer | 20 mA current loop (active / passive) |
| Baud rate | 9600 bit/s |
| Data bits | 8 |
| Parity | Even |
| Stop bits | 1 |
| Max cable length | 1000 m (depending on cable type) |
3. The Communication Function Block: FB51 / FB151
The S5 user program must contain a function block that handles the OP7 ↔ S5 handshake, data exchange, and error reporting. The standard block distributed with ProTool V6 is FB51. Earlier ProTool releases distributed a different revision of the same logic under the same FB number, and many machine builders copied the block into a higher number (commonly FB151) to keep their numbering convention intact. The OP7 firmware checks the revision of the block it is talking to during the initial handshake; an old revision completes ProTool transfer mode but fails in run mode because the run-mode data exchange is rejected.
Symptoms of a block-level mismatch:
- OP7 displays "Communication Error" or "No Connection" at startup.
- OP7 passes the ProTool transfer but the process screen does not load.
- S5 diagnostic buffer contains stop codes 0x3F22 (interface error) or 0x3F23 (handshake timeout).
- Replacing the OP7 with a second identical OP7 still fails to establish communication, ruling out a hardware fault in the panel.
4. Step-by-Step Recovery Procedure
4.1 Prerequisites
- STEP 5 programming software (V6.x or V7.x) with an online upload license.
- PG cable for the S5-95U (e.g., 6ES5 734-1BD20).
- ProTool V6.0 SP3 or later configuration software.
- ProSave V9.0.3.0 (or later) for panel backup and firmware management.
- Original ProTool *.pdb or archived project file.
- Known-good OP7-PP (6AV3 607-1JC00-0AX2).
- OP7-PP / S5-95U TTY cable (6AV3 671-1JC00-0AX0) or wired equivalent.
4.2 Upload the S5 User Program
- Connect the PG to the S5-95U serial port.
- Open STEP 5 and select
File → Upload to PG → All Blocks. - Save the complete program archive (
.S5D) to a working directory before any modification. - Open the cross-reference (
REF) for OB1, OB21, OB22, and every PB/FB that calls external blocks.
4.3 Identify the Communication Function Block
- In the cross-reference, search for calls to
FB51,FB151,FB251, or any FB with a name indicating operator-panel handling. - Open the candidate FB in the STEP 5 editor. Compare the segment structure against the standard FB51 description in the ProTool V6 help file (
Help → Communication Blocks → FB51 Description). - Note the FB number used in the calls. Many OEM programs call a renamed copy of FB51 stored under FB151 or another free number.
- Confirm the DB number passed into the FB call (commonly DB51 or DB151) and the data length expected by the OP7.
4.4 Replace the Communication Function Block
- Obtain the current FB51 source from the ProTool V6 installation:
C:\Siemens\ProTool\Library\S5\FB51.S5Dor from the ProTool CD underFB_S5\FB51. - In STEP 5, open the OEM program archive and select
Block → Insertfor FB51. - If the OEM program used a non-standard number (for example FB151), copy the new FB51 logic into the program under that same number. Do not renumber the call sites; copy the new logic into the existing FB151 address.
- Generate the FB and verify the parameter list at the call site in OB1: DB number, OP address, and length of user-data area must match what the OP7 expects.
- Download the modified program to the S5-95U with
Block → Download to AG. - Save the updated archive as the new machine reference.
4.5 Verify OP7 Communication
- Cycle power on the S5-95U and the OP7.
- Observe the OP7 startup screen. A successful handshake is indicated by the configured process screen appearing within 5-8 seconds after the boot banner.
- If the panel remains in "Connecting…" status, re-check cabling and current-loop direction (see Section 6).
5. Firmware Management
ProTool V6 SP3 embeds firmware V5.22 (or a later patch) for the OP7/OP17. When a configuration is transferred to the panel, the firmware version reported by the OP7 may increment compared to the original unit. Older ProTool releases (V4.x, V5.x) integrate firmware V5.22 specifically, as documented in Siemens support article 2976597 ("Firmware V 5.22 for OP7/17 for installation in ProTool V4.x / V5.x for improvement in the case of bus faults"). The article confirms that V5.22 is automatically integrated when a configuration is transferred.
| ProTool Version | Embedded OP7 Firmware |
|---|---|
| V4.x / V5.x | V5.22 |
| V6.0 SP3 | V5.22 (or later patch) |
Use ProSave V9.0.3.0 to back up the panel image before any firmware change and to restore the panel if a downgrade is required. ProSave is available on the ProTool / STEP 7 installation media or via the Siemens SiePortal thread "Need software for OP7" for license request.
5.1 Firmware Inspection
- On the OP7, enter the system menu and select
Information → Version. Record the firmware build string. - Compare the build string with the firmware embedded in the ProTool version used to compile the project.
- If the panel firmware is older than the embedded firmware, the ProTool transfer will upgrade it automatically.
- If the panel firmware is newer, ProTool will refuse to transfer without an explicit reset.
5.2 Firmware Downgrade Procedure
- Back up the current panel image:
ProSave → OP7 → Backup → Serial (TTY). - Select the older firmware file (for example, the V5.22 PROTOOL firmware from the ProTool V5 CD).
- Transfer with:
ProSave → OP7 → Restore → Firmware. - Re-transfer the ProTool project to refresh the configuration.
6. Cabling and Electrical Verification
The OP7-PP ↔ S5-95U link uses a 1:1 TTY cable, not a crossed RS-232 cable. A replacement unit installed with the wrong cable type will appear to transfer the ProTool project successfully (ProTool transfer uses its own protocol on the same pins) yet fail in run mode. This is the second most common root cause after the FB mismatch.
| Signal | OP7-PP Pin (15-pin D-sub) | S5-95U X2 Pin (15-pin D-sub) |
|---|---|---|
| TX+ (panel input) | 3 | 14 |
| TX- (panel input return) | 10 | 15 |
| RX+ (panel output) | 11 | 3 |
| RX- (panel output return) | 7 | 10 |
| Shield | 1 | 1 |
Use a Siemens 6AV3 671-1JC00-0AX0 OP7-PP / S5 cable or wire a shielded 4-wire cable with twisted pairs. Verify with a multimeter that current flows in the loop (typically 20 mA) when both devices are powered. If no current is present, the active/passive assignment is reversed or the loop is open. The S5-95U side is normally active (current source); the OP7-PP side is normally passive (current sink).
7. Verification and Acceptance
- Power-cycle both the S5-95U and OP7.
- Confirm the process screen loads within 10 s of the OP7 boot banner.
- Trigger at least three operator actions (setpoint entry, mode change, screen change) and verify the corresponding S5 inputs and outputs respond.
- Read the S5 diagnostic buffer and confirm no OB1, OB13, or OB22 stop events with interface-error stop codes.
- Run the OP7 self-test:
Menu → Diagnosis → Interface Test; the result must show "OK" with no CRC errors. - Document the active FB number (FB51 or the OEM number), the firmware version, and the cable part number for the maintenance record.
8. Troubleshooting Matrix
| Symptom | Most Likely Cause | First Check |
|---|---|---|
| OP7 stuck on "Connecting" after ProTool transfer | Wrong or inactive FB in S5 program | Cross-reference search for FB51 / FB151 |
| ProTool transfer works, run mode fails | TTY cable wired for RS-232 | Verify pin mapping and current loop |
| OP7 shows "Communication Error" with random S5 stop codes | FB revision mismatch | Compare FB source to current ProTool FB51 |
| OP7-DP installed in place of OP7-PP | Wrong panel variant | Check faceplate label and MLFB |
| S5-95U outputs remain in safe state, no operator input | Active / passive current loop reversed | Measure 20 mA in the loop |
| Panel firmware newer than ProTool project expects | ProTool version mismatch | Match ProTool to panel firmware |
9. Field-Proven Caveats
- Always upload the S5 program before modifying it. The OB1 and the communication FB are the only way to restore the machine if a wrong block is downloaded.
- The S5-95U has limited free FB numbers. Reuse the OEM's existing FB number for the new communication block; renumbering requires updating every call site and is error-prone.
- The OP7 retains its firmware in flash. A cold boot does not downgrade firmware. Use ProSave to roll back if needed.
- ProTool V6 SP3 is the last release that supports the OP7. Newer WinCC flexible and TIA Portal versions cannot configure this panel.
- ProTool transfer mode uses a different handshake than run mode. A successful transfer is not a guarantee of run-mode communication.
- The 20 mA current loop is polarity-sensitive at the loop level. Reversing TX+ / TX- is a common fault after a field re-termination.
FAQ
What is the difference between OP7-PP and OP7-DP?
The OP7-PP (6AV3 607-1JC00-0AX2) uses the AS511 protocol over a 20 mA current loop and connects directly to an S5 CPU. The OP7-DP uses PROFIBUS-DP and cannot be used with a non-DP S5-95U. The OP7-DP does not perform AS511 communication.
Why does my replacement OP7 not communicate even though the ProTool project transfers successfully?
ProTool transfer uses a dedicated protocol on the same physical port and succeeds even when the S5 communication function block is missing or incorrect. Verify the S5 program contains a current revision of FB51, copied under the FB number originally used by the OEM (commonly FB151).
Can I downgrade the OP7 firmware to a version lower than V5.22?
Yes, using ProSave V9.0.3.0 you can restore an older firmware image to the panel. However, the dominant root cause of communication failure is the S5 communication function block, not the panel firmware. Replace FB51 first before downgrading firmware.
Do I need FB51 in the S5 program for OP7 communication?
Yes. The S5 program must contain a communication function block (FB51 standard, or a copy under a different number such as FB151). Without it, the OP7 cannot exchange data with the S5 CPU. The block must match the revision expected by the OP7 firmware; older revisions of the same block will not initialize the link reliably in run mode.
What cable do I need between the OP7-PP and S5-95U?
Use a Siemens 6AV3 671-1JC00-0AX0 OP7-PP-to-S5 cable or a shielded 4-wire cable wired for a 20 mA current loop on the 15-pin D-sub ports (OP7 pin 3/10 to S5 pin 14/15 and OP7 pin 11/7 to S5 pin 3/10). A standard RS-232 crossover cable will not establish AS511 communication in run mode.