S7-1200 GET Instruction: Reading S7-300 Data Blocks via PROFINET

David Krause11 min read
S7-1200SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: Reading S7-300 Data Blocks from an S7-1200

When retrofitting a machine with an S7-1200 (for example, a CPU 1215C) next to an existing S7-300 (for example, a CPU 315-2 PN/DP or a CPU 315-2 DP plus CP 343-1), the cleanest path for the S7-1200 to read two words from a data block (DB) inside the S7-300 is the S7 communication protocol running over the PROFINET interface. The S7-1200 acts as the active client and uses the GET instruction (formerly FB14 in classic STEP 7, integrated as a system instruction in TIA Portal) to pull data from the S7-300 partner.

This approach is preferred over Ethernet ISO-on-TCP (Open User Communication) or PROFIBUS DP slave coupling when the existing SIMATIC Manager (STEP 7 V5.x) project must remain untouched, because the entire configuration is performed on the S7-1200 side. The S7-300 requires no program changes and, in most cases, no recompile. Only one toggle on the CPU properties is required to authorize the remote PUT/GET access.

The procedure below assumes TIA Portal V13 (as specified in the source scenario) and covers S7-300 CPUs with an integrated PROFINET interface or an external CP 343-1. It can be adapted to newer TIA Portal versions, but the connection- and instruction-IDs differ slightly.

Reference documentation: Siemens application note S7 Communication between SIMATIC S7-1200 and SIMATIC S7-300 and the TIA Portal online help topic GET and PUT (Read and write from a remote CPU).

Prerequisites and Hardware Selection

Component Recommended Selection Notes
S7-1200 CPU CPU 1215C DC/DC/DC, order number 6ES7215-1AG40-0XB0 (firmware V4.2 or higher recommended) Integrated PROFINET interface, supports S7 connection as client and server.
S7-300 CPU CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) or CPU 315-2 DP (6ES7315-2AH14-0AB0) with CP 343-1 (6GK7343-1EX30-0XE0) PN interface required for S7 communication; CP 343-1 can be added later if the CPU has no integrated PN.
Firmware S7-300 V3.x or higher (CPU 31x PN/DP family) Required for full S7 connection support.
Engineering tool S7-1200 TIA Portal V13 SP1 (or V14/V15 if updating project) Allows configuration of S7 connection and placement of GET instruction.
Engineering tool S7-300 STEP 7 V5.5 SP2+ (Simatic Manager) for HW Config access Used once only to enable PUT/GET access; project is not otherwise modified.
Network PROFINET switch, CAT5e or higher, 100 Mbit/s full duplex Direct cross-over cable is also valid for a 1:1 link.

Before starting, confirm the S7-300 IP address, subnet mask, rack/slot location of the PN interface or CP, the DB number where the two words reside, and the byte offset within that DB. The original SIMATIC project contains all of this information; the S7-1200 only needs to read, not to import, the S7-300 project.

Network Architecture

S7-1200 CPU 1215C 192.168.0.10 TIA Portal V13 GET instruction (active) S7 connection (TCP/ISO) PROFINET Switch Managed or unmanaged PROFINET S7-300 CPU 315-2 PN/DP 192.168.0.20 Existing Simatic project Server (no program change) PROFIBUS DP ET200S ET200M ET200M Existing PROFIBUS outstations (untouched)

The S7-1200 only requires an Ethernet link to the S7-300. The existing PROFIBUS ring with the ET200 stations is unaffected. The S7 connection is logical, not physical; it is multiplexed over the same PROFINET cable or switch that the S7-300 PN interface uses.

Enabling PUT/GET Access on the S7-300 CPU

This is the only configuration change required on the S7-300 side. By default, S7-300 CPUs in modern firmware versions block remote PUT/GET for write protection reasons.

  1. Open the existing SIMATIC Manager project on the engineering station.
  2. Open HW Config and select the CPU 315.
  3. Open Object Properties on the CPU, then navigate to the Protection tab (STEP 7 V5.5) or Communication tab (older versions).
  4. Check the box "Permit access with PUT/GET communication from remote partner" (German: "Bausteinoptimierter Zugriff" in some versions: "Zulassen der PUT/GET-Kommunikation").
  5. Download the hardware configuration to the CPU (online > Download to Target Station).
No program change is required. You do not need to add an FB14, FB15, or any data block on the S7-300. The GET instruction on the S7-1200 reaches directly into the S7-300's data blocks by number and offset; the CPU's operating system handles the read.

Configuring the S7 Connection in TIA Portal V13

  1. Open the S7-1200 project in TIA Portal V13. Add a CPU 1215C device if you have not already done so.
  2. Open the Devices & Networks view, then the Network view.
  3. From the right-hand catalog, drag an S7 connection (under Other Ethernet devices if you do not have the S7-300 in the project) onto the S7-1200's PROFINET interface. Alternatively, use the menu Options > Configure a new S7 connection.
  4. Double-click the connection line to open its properties.
  5. On the General tab, set:
    • Local endpoint: S7-1200 PROFINET interface, address 192.168.0.10 (adjust to your network).
    • Partner: Choose Unspecified and enter the S7-300 IP (192.168.0.20), rack 0, slot 2 (CPU 315-2 PN/DP). If using CP 343-1, the slot is 4 (rack 0, slot 4).
    • Connection type: S7 connection.
    • Connection resource: Pick a free ID (e.g., 1) and record the resulting Connection ID. The GET instruction will use this ID.
  6. On the Address details tab, confirm the TSAPs: the local TSAP is auto-assigned, the partner TSAP is 03.02 for a CPU on rack 0 slot 2 (or 03.04 for a CP on rack 0 slot 4). For an S7-300 with an integrated PN interface, the TSAP is 03.02 by default.
  7. Compile and download the hardware configuration to the S7-1200.

Programming the GET Instruction

Open the main OB (OB1) of the S7-1200. Drag the GET instruction from the task card under Instructions > Communication > S7 Communication into a network. TIA Portal prompts you to create an instance DB; accept the default name (e.g., GET_DB).

A typical two-word read is wired as follows:

//  Network 1: read 2 words from DB100 starting at byte 0
//  of the S7-300 into a local DB on the S7-1200
//
//  S7 connection ID: 1  (from Devices & Networks)
//  Remote DB:        DB100
//  Remote offset:    0.0  (byte.bit; S7-300 uses byte offset only)
//  Length:           4 bytes (= 2 words)
//  Local target:     DB200.DBD0  (any data block of sufficient size)

      "GET_DB".REQ   :=   %I0.0;            // trigger one-shot, e.g. from a positive edge
      "GET_DB".ID    :=   W#16#1;            // connection ID = 1
      "GET_DB".ADDR_1 :=   P#DB100.DBX 0.0 WORD 2;  // remote: 2 words from DB100
      "GET_DB".RD_1   :=   P#DB200.DBX 0.0 WORD 2;  // local:  2 words into DB200
      "GET_DB".LEN   :=   4;                 // 2 words = 4 bytes

//  Status outputs
      "GET_DB".NDR    :=   %M10.0;           // 1 cycle: new data received
      "GET_DB".ERROR  :=   %M10.1;           // 1 = error occurred
      "GET_DB".STATUS :=   %MW12;            // detailed error/status code
      "GET_DB".BUSY   :=   %M10.3;           // job in progress

Because GET is asynchronous, wrap the REQ with an edge-detect pattern and trigger it cyclically (every 100 ms) or by an event. Poll NDR to latch the successful read or ERROR for diagnostics.

GET Instruction Interface Reference

Parameter Direction Type Meaning
REQ IN BOOL Rising edge starts a new read job.
ID IN WORD Connection ID from the S7 connection configuration.
ADDR_1 (…ADDR_4) IN VARIANT (POINTER in V13) Remote address. Use P#DB<n>.DBX <byte>.0 WORD <count>.
RD_1 (…RD_4) OUT/IN-OUT VARIANT Local receive area; must match the size implied by ADDR_1.
LEN OUT/IN-OUT DINT or UINT Total length in bytes (sum of all ADDR_x areas).
NDR OUT BOOL One-cycle TRUE when new data has been received without error.
ERROR OUT BOOL One-cycle TRUE when the job terminated with an error.
STATUS OUT WORD Detailed status (see table below). 0x0000 if the job is queued.
BUSY OUT BOOL TRUE while the job is in progress.

Multiple ADDR/RD pairs let you read up to four separate areas with a single GET. The sum of their byte lengths must equal LEN. For two words from one DB, ADDR_1 alone with WORD 2 is sufficient.

STATUS and ERROR Code Interpretation

STATUS (hex) Meaning
0x0000 Job queued or completed without error.
0x0001 / 0x0002 Connection established, data read successfully (informational).
0x7000 No job active (idle state).
0x7001 Job starting (first call).
0x7002 Job running (intermediate call).
0x8085 / 0x8185 Connection error (partner unreachable, wrong TSAP, wrong IP, or wrong slot).
0x80A1 / 0x80A3 Connection aborted by partner or by network timeout.
0x80B1 / 0x80B4 Illegal pointer specification in ADDR_x or RD_x.
0x80C3 Data length mismatch between LEN and the sum of ADDR_x areas.
0x80C4 Data type conflict; check that ADDR_1's element type matches RD_1.
0x8x22 DB number too high or does not exist on the partner CPU.
0x8x24 Area length error on the partner CPU (offset + length exceeds DB size).
0x8x32 DB does not exist on the partner (typo, DB uninitialized, or DB deleted in RUN).
0xDF31 / 0xCF31 PUT/GET access denied: the S7-300 CPU has not enabled remote PUT/GET.
Field tip: If STATUS ends in 31, the partner CPU is rejecting PUT/GET. The single most common cause is the unchecked "Permit access with PUT/GET" box on the S7-300.

Verification and Commissioning

  1. Online connect to the S7-1200. Monitor the GET instance DB.
  2. Force REQ to TRUE. Watch BUSY go TRUE for one or two OB1 cycles (typical on a healthy 100 Mbit link: 1 cycle ≈ 10–30 ms for 2 words).
  3. Confirm NDR pulses TRUE and STATUS returns 0x0002 (or 0x0001 first time, then 0x0002 on success).
  4. Open the target DB200 on the S7-1200 in the watch table and confirm the two words match the values in DB100 of the S7-300. Use Monitor / Modify on the S7-300 to write a known pattern and observe it propagating within one OB1 cycle.
  5. Disconnect the PROFINET cable and verify ERROR sets within the configured connection timeout (default 10 s) with STATUS = 0x8185. Reconnect and confirm the S7-1200 re-establishes the connection automatically without restart.

Troubleshooting Matrix

Symptom Likely Root Cause Corrective Action
STATUS = 0x8185 immediately on REQ Wrong partner IP, wrong rack/slot, or TSAP mismatch Verify the partner address details in Devices & Networks > S7 connection > Address details. Ping the S7-300 from the TIA engineering PC.
STATUS = 0xDF31 or 0xCF31 PUT/GET disabled on S7-300 Open the S7-300 hardware configuration, check Permit access with PUT/GET communication from remote partner, recompile and download HW Config.
STATUS = 0x8x22 / 0x8x32 DB number does not exist on S7-300 Cross-check the DB number against the SIMATIC project. Confirm the DB has been generated and downloaded.
STATUS = 0x8x24 Offset + length exceeds DB size Reduce WORD count or adjust the starting byte offset.
STATUS = 0x80C4 Type mismatch between ADDR_1 and RD_1 Match element count and data type (WORD 2 ↔ DBD area, or ARRAY[0..1] OF WORD).
NDR never sets, BUSY stays TRUE Connection resource on S7-300 exhausted (S7-300 has max 16 S7 connections per CPU/CP) Reduce concurrent connections, or upgrade to a CPU/CP with more S7 connection resources.
Read works online, fails after restart Connection not yet established at startup Trigger GET only after the connection is up (status bit from connection diagnostics, or delay REQ by 2 s in OB100/startup OB).
Values arrive scrambled or zeroed Byte-swap because S7-300 is big-endian and S7-1200 is little-endian on the wire S7 communication handles byte order automatically; if you still see swapped bytes, check that the target area in DB200 is a WORD array and not a STRING or user-defined type with mixed length.

Performance, Cycle, and Optimization Notes

  • Throughput: a single GET of 2 words (4 bytes) consumes approximately 8 to 30 ms round-trip on a 100 Mbit PROFINET link, dominated by the S7 connection's request/acknowledge handshake. Increasing the read length to fetch the entire DB in one shot (e.g., 100 bytes) does not change the per-job latency meaningfully but reduces the number of connection requests per second.
  • Polling cadence: 100 ms to 500 ms is typical for HMI/monitoring scenarios. Faster polling (< 50 ms) generates unnecessary traffic on the S7-300's connection resource pool.
  • Connection budget: a CPU 315-2 PN/DP supports up to 16 S7 connections; an external CP 343-1 supports 16. If HMI panels, drives, and other controllers already use most of these, add a second CP 343-1 or consolidate via an S7 router.
  • Edge triggering: a one-shot REQ edge prevents multiple jobs from queuing; without edge detection, BUSY can latch.
  • Read-only: GET is the only instruction needed. PUT (the write counterpart) is not required and should not be configured for this retrofit.

FAQ

Do I need to modify the S7-300 program to expose the data block to the S7-1200?

No program change is needed. The S7-300 must have the "Permit access with PUT/GET communication from remote partner" checkbox enabled in HW Config (Protection / Communication tab). That single toggle authorizes the S7-1200's GET instruction to read any DB directly.

What hardware do I need on the S7-300 to get PROFINET?

Use a CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) which has an integrated PROFINET interface, or add a CP 343-1 (6GK7343-1EX30-0XE0) to a CPU 315-2 DP. The PN interface becomes the S7 connection endpoint; rack 0, slot 2 for the integrated PN or rack 0, slot 4 for the CP.

Which TIA Portal version is required on the S7-1200 side?

TIA Portal V13 supports S7-1200 CPUs with firmware V4.0 or higher. V13 SP1 adds S7-1500 support. V14/V15 use a different GET block ID, so when migrating projects, recompile the GET and update the connection ID.

How many words can a single GET transfer?

Up to 462 bytes in a single GET (this is the S7-300 partner's maximum PDU size for a passive read). For two words (4 bytes) the job completes in a single handshake, so no fragmentation logic is required.

Why does STATUS return 0xDF31 even though the network is reachable?

Status 0xDF31 indicates the partner CPU has refused the PUT/GET access. The cause is almost always the disabled "Permit access with PUT/GET communication" option on the S7-300. Re-check HW Config, recompile, and download only the hardware configuration back to the S7-300.

Back to blog