Resolving SIMATIC OP7 Communication Failures with S5-95U PLC

David Krause10 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving SIMATIC OP7 Communication Failures with S5-95U PLC

The SIMATIC OP7 operator panel paired with an S5-95U CPU is a classic automation combination that remains in service across many manufacturing facilities. When the original OP7 fails and a replacement unit is installed, the panel frequently refuses to communicate with the S5 controller despite a correct ProTool configuration transfer. The root cause almost always lies in a mismatch between the S5 program's communication function block and the revision expected by the OP7 firmware. This reference documents the full diagnostic path, firmware management, and the FB51 / FB151 replacement procedure that resolves the failure, plus cabling and electrical checks frequently overlooked after a panel swap.

1. Hardware Identification: OP7-PP vs OP7-DP

The SIMATIC OP7 was offered in two interface variants that are not interchangeable. Confirming the model before any software work avoids days of misdirected troubleshooting. The faceplate label and the MLFB (order number) are the only reliable identifiers because both variants look identical from the front.

Variant MLFB Order Number On-board Interface Protocol Compatible S5 CPUs
OP7-PP (Point-to-Point) 6AV3 607-1JC00-0AX2 TTY / 20 mA current loop AS511 S5-90U, S5-95U, S5-100U, S5-115U, S5-135U, S5-155U
OP7-DP 6AV3 607-1JC10-0AX0 RS-485 PROFIBUS PROFIBUS-DP S5-95U/DP, S5-115U with DP-CP, ET 200U

The OP7-DP does not implement AS511. Replacing an OP7-PP with a DP variant will never establish communication with an S5-95U CPU that is not configured as a DP slave. The label "Operator Panel OP7-PP" and the order number 6AV3 607-1JC00-0AX2 identify the correct replacement for an AS511 link.

2. AS511 Protocol Fundamentals

AS511 is a serial point-to-point protocol operating over a 20 mA current loop at 9600 bit/s. The S5-95U exposes the AS511 interface on the front X2 connector (15-pin sub-D) and the OP7-PP terminates the link on its 15-pin sub-D port. Both devices must be configured for matching active/passive current-loop roles. The S5-95U is typically wired as the active source; the OP7-PP is passive. Reversing this assignment is a common cabling error after a panel swap and will not be flagged by ProTool transfer mode.

Parameter Value
Physical layer 20 mA current loop (active / passive)
Baud rate 9600 bit/s
Data bits 8
Parity Even
Stop bits 1
Max cable length 1000 m (depending on cable type)

3. The Communication Function Block: FB51 / FB151

The S5 user program must contain a function block that handles the OP7 ↔ S5 handshake, data exchange, and error reporting. The standard block distributed with ProTool V6 is FB51. Earlier ProTool releases distributed a different revision of the same logic under the same FB number, and many machine builders copied the block into a higher number (commonly FB151) to keep their numbering convention intact. The OP7 firmware checks the revision of the block it is talking to during the initial handshake; an old revision completes ProTool transfer mode but fails in run mode because the run-mode data exchange is rejected.

Symptoms of a block-level mismatch:

  • OP7 displays "Communication Error" or "No Connection" at startup.
  • OP7 passes the ProTool transfer but the process screen does not load.
  • S5 diagnostic buffer contains stop codes 0x3F22 (interface error) or 0x3F23 (handshake timeout).
  • Replacing the OP7 with a second identical OP7 still fails to establish communication, ruling out a hardware fault in the panel.

If the S5 program works with one OP7 and not with another identical OP7, the panel is functioning. The S5 program is the suspect and the FB number used by the OEM is the key to the fix.

4. Step-by-Step Recovery Procedure

4.1 Prerequisites

  • STEP 5 programming software (V6.x or V7.x) with an online upload license.
  • PG cable for the S5-95U (e.g., 6ES5 734-1BD20).
  • ProTool V6.0 SP3 or later configuration software.
  • ProSave V9.0.3.0 (or later) for panel backup and firmware management.
  • Original ProTool *.pdb or archived project file.
  • Known-good OP7-PP (6AV3 607-1JC00-0AX2).
  • OP7-PP / S5-95U TTY cable (6AV3 671-1JC00-0AX0) or wired equivalent.

4.2 Upload the S5 User Program

  1. Connect the PG to the S5-95U serial port.
  2. Open STEP 5 and select File → Upload to PG → All Blocks.
  3. Save the complete program archive (.S5D) to a working directory before any modification.
  4. Open the cross-reference (REF) for OB1, OB21, OB22, and every PB/FB that calls external blocks.

4.3 Identify the Communication Function Block

  1. In the cross-reference, search for calls to FB51, FB151, FB251, or any FB with a name indicating operator-panel handling.
  2. Open the candidate FB in the STEP 5 editor. Compare the segment structure against the standard FB51 description in the ProTool V6 help file (Help → Communication Blocks → FB51 Description).
  3. Note the FB number used in the calls. Many OEM programs call a renamed copy of FB51 stored under FB151 or another free number.
  4. Confirm the DB number passed into the FB call (commonly DB51 or DB151) and the data length expected by the OP7.

4.4 Replace the Communication Function Block

  1. Obtain the current FB51 source from the ProTool V6 installation: C:\Siemens\ProTool\Library\S5\FB51.S5D or from the ProTool CD under FB_S5\FB51.
  2. In STEP 5, open the OEM program archive and select Block → Insert for FB51.
  3. If the OEM program used a non-standard number (for example FB151), copy the new FB51 logic into the program under that same number. Do not renumber the call sites; copy the new logic into the existing FB151 address.
  4. Generate the FB and verify the parameter list at the call site in OB1: DB number, OP address, and length of user-data area must match what the OP7 expects.
  5. Download the modified program to the S5-95U with Block → Download to AG.
  6. Save the updated archive as the new machine reference.

4.5 Verify OP7 Communication

  1. Cycle power on the S5-95U and the OP7.
  2. Observe the OP7 startup screen. A successful handshake is indicated by the configured process screen appearing within 5-8 seconds after the boot banner.
  3. If the panel remains in "Connecting…" status, re-check cabling and current-loop direction (see Section 6).

5. Firmware Management

ProTool V6 SP3 embeds firmware V5.22 (or a later patch) for the OP7/OP17. When a configuration is transferred to the panel, the firmware version reported by the OP7 may increment compared to the original unit. Older ProTool releases (V4.x, V5.x) integrate firmware V5.22 specifically, as documented in Siemens support article 2976597 ("Firmware V 5.22 for OP7/17 for installation in ProTool V4.x / V5.x for improvement in the case of bus faults"). The article confirms that V5.22 is automatically integrated when a configuration is transferred.

ProTool Version Embedded OP7 Firmware
V4.x / V5.x V5.22
V6.0 SP3 V5.22 (or later patch)

Use ProSave V9.0.3.0 to back up the panel image before any firmware change and to restore the panel if a downgrade is required. ProSave is available on the ProTool / STEP 7 installation media or via the Siemens SiePortal thread "Need software for OP7" for license request.

5.1 Firmware Inspection

  1. On the OP7, enter the system menu and select Information → Version. Record the firmware build string.
  2. Compare the build string with the firmware embedded in the ProTool version used to compile the project.
  3. If the panel firmware is older than the embedded firmware, the ProTool transfer will upgrade it automatically.
  4. If the panel firmware is newer, ProTool will refuse to transfer without an explicit reset.

5.2 Firmware Downgrade Procedure

  1. Back up the current panel image: ProSave → OP7 → Backup → Serial (TTY).
  2. Select the older firmware file (for example, the V5.22 PROTOOL firmware from the ProTool V5 CD).
  3. Transfer with: ProSave → OP7 → Restore → Firmware.
  4. Re-transfer the ProTool project to refresh the configuration.

Firmware downgrade is rarely the correct remedy. The block-level incompatibility (Section 3) is the dominant root cause. Treat firmware as the last resort, after FB51 replacement and cabling verification.

6. Cabling and Electrical Verification

The OP7-PP ↔ S5-95U link uses a 1:1 TTY cable, not a crossed RS-232 cable. A replacement unit installed with the wrong cable type will appear to transfer the ProTool project successfully (ProTool transfer uses its own protocol on the same pins) yet fail in run mode. This is the second most common root cause after the FB mismatch.

Signal OP7-PP Pin (15-pin D-sub) S5-95U X2 Pin (15-pin D-sub)
TX+ (panel input) 3 14
TX- (panel input return) 10 15
RX+ (panel output) 11 3
RX- (panel output return) 7 10
Shield 1 1

Use a Siemens 6AV3 671-1JC00-0AX0 OP7-PP / S5 cable or wire a shielded 4-wire cable with twisted pairs. Verify with a multimeter that current flows in the loop (typically 20 mA) when both devices are powered. If no current is present, the active/passive assignment is reversed or the loop is open. The S5-95U side is normally active (current source); the OP7-PP side is normally passive (current sink).

7. Verification and Acceptance

  1. Power-cycle both the S5-95U and OP7.
  2. Confirm the process screen loads within 10 s of the OP7 boot banner.
  3. Trigger at least three operator actions (setpoint entry, mode change, screen change) and verify the corresponding S5 inputs and outputs respond.
  4. Read the S5 diagnostic buffer and confirm no OB1, OB13, or OB22 stop events with interface-error stop codes.
  5. Run the OP7 self-test: Menu → Diagnosis → Interface Test; the result must show "OK" with no CRC errors.
  6. Document the active FB number (FB51 or the OEM number), the firmware version, and the cable part number for the maintenance record.

8. Troubleshooting Matrix

Symptom Most Likely Cause First Check
OP7 stuck on "Connecting" after ProTool transfer Wrong or inactive FB in S5 program Cross-reference search for FB51 / FB151
ProTool transfer works, run mode fails TTY cable wired for RS-232 Verify pin mapping and current loop
OP7 shows "Communication Error" with random S5 stop codes FB revision mismatch Compare FB source to current ProTool FB51
OP7-DP installed in place of OP7-PP Wrong panel variant Check faceplate label and MLFB
S5-95U outputs remain in safe state, no operator input Active / passive current loop reversed Measure 20 mA in the loop
Panel firmware newer than ProTool project expects ProTool version mismatch Match ProTool to panel firmware

9. Field-Proven Caveats

  • Always upload the S5 program before modifying it. The OB1 and the communication FB are the only way to restore the machine if a wrong block is downloaded.
  • The S5-95U has limited free FB numbers. Reuse the OEM's existing FB number for the new communication block; renumbering requires updating every call site and is error-prone.
  • The OP7 retains its firmware in flash. A cold boot does not downgrade firmware. Use ProSave to roll back if needed.
  • ProTool V6 SP3 is the last release that supports the OP7. Newer WinCC flexible and TIA Portal versions cannot configure this panel.
  • ProTool transfer mode uses a different handshake than run mode. A successful transfer is not a guarantee of run-mode communication.
  • The 20 mA current loop is polarity-sensitive at the loop level. Reversing TX+ / TX- is a common fault after a field re-termination.

FAQ

What is the difference between OP7-PP and OP7-DP?

The OP7-PP (6AV3 607-1JC00-0AX2) uses the AS511 protocol over a 20 mA current loop and connects directly to an S5 CPU. The OP7-DP uses PROFIBUS-DP and cannot be used with a non-DP S5-95U. The OP7-DP does not perform AS511 communication.

Why does my replacement OP7 not communicate even though the ProTool project transfers successfully?

ProTool transfer uses a dedicated protocol on the same physical port and succeeds even when the S5 communication function block is missing or incorrect. Verify the S5 program contains a current revision of FB51, copied under the FB number originally used by the OEM (commonly FB151).

Can I downgrade the OP7 firmware to a version lower than V5.22?

Yes, using ProSave V9.0.3.0 you can restore an older firmware image to the panel. However, the dominant root cause of communication failure is the S5 communication function block, not the panel firmware. Replace FB51 first before downgrading firmware.

Do I need FB51 in the S5 program for OP7 communication?

Yes. The S5 program must contain a communication function block (FB51 standard, or a copy under a different number such as FB151). Without it, the OP7 cannot exchange data with the S5 CPU. The block must match the revision expected by the OP7 firmware; older revisions of the same block will not initialize the link reliably in run mode.

What cable do I need between the OP7-PP and S5-95U?

Use a Siemens 6AV3 671-1JC00-0AX0 OP7-PP-to-S5 cable or a shielded 4-wire cable wired for a 20 mA current loop on the 15-pin D-sub ports (OP7 pin 3/10 to S5 pin 14/15 and OP7 pin 11/7 to S5 pin 3/10). A standard RS-232 crossover cable will not establish AS511 communication in run mode.

Back to blog