Overview: Reading S7-300 Data Blocks from an S7-1200
When retrofitting a machine with an S7-1200 (for example, a CPU 1215C) next to an existing S7-300 (for example, a CPU 315-2 PN/DP or a CPU 315-2 DP plus CP 343-1), the cleanest path for the S7-1200 to read two words from a data block (DB) inside the S7-300 is the S7 communication protocol running over the PROFINET interface. The S7-1200 acts as the active client and uses the GET instruction (formerly FB14 in classic STEP 7, integrated as a system instruction in TIA Portal) to pull data from the S7-300 partner.
This approach is preferred over Ethernet ISO-on-TCP (Open User Communication) or PROFIBUS DP slave coupling when the existing SIMATIC Manager (STEP 7 V5.x) project must remain untouched, because the entire configuration is performed on the S7-1200 side. The S7-300 requires no program changes and, in most cases, no recompile. Only one toggle on the CPU properties is required to authorize the remote PUT/GET access.
The procedure below assumes TIA Portal V13 (as specified in the source scenario) and covers S7-300 CPUs with an integrated PROFINET interface or an external CP 343-1. It can be adapted to newer TIA Portal versions, but the connection- and instruction-IDs differ slightly.
Prerequisites and Hardware Selection
| Component | Recommended Selection | Notes |
|---|---|---|
| S7-1200 CPU | CPU 1215C DC/DC/DC, order number 6ES7215-1AG40-0XB0 (firmware V4.2 or higher recommended) | Integrated PROFINET interface, supports S7 connection as client and server. |
| S7-300 CPU | CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) or CPU 315-2 DP (6ES7315-2AH14-0AB0) with CP 343-1 (6GK7343-1EX30-0XE0) | PN interface required for S7 communication; CP 343-1 can be added later if the CPU has no integrated PN. |
| Firmware S7-300 | V3.x or higher (CPU 31x PN/DP family) | Required for full S7 connection support. |
| Engineering tool S7-1200 | TIA Portal V13 SP1 (or V14/V15 if updating project) | Allows configuration of S7 connection and placement of GET instruction. |
| Engineering tool S7-300 | STEP 7 V5.5 SP2+ (Simatic Manager) for HW Config access | Used once only to enable PUT/GET access; project is not otherwise modified. |
| Network | PROFINET switch, CAT5e or higher, 100 Mbit/s full duplex | Direct cross-over cable is also valid for a 1:1 link. |
Before starting, confirm the S7-300 IP address, subnet mask, rack/slot location of the PN interface or CP, the DB number where the two words reside, and the byte offset within that DB. The original SIMATIC project contains all of this information; the S7-1200 only needs to read, not to import, the S7-300 project.
Network Architecture
The S7-1200 only requires an Ethernet link to the S7-300. The existing PROFIBUS ring with the ET200 stations is unaffected. The S7 connection is logical, not physical; it is multiplexed over the same PROFINET cable or switch that the S7-300 PN interface uses.
Enabling PUT/GET Access on the S7-300 CPU
This is the only configuration change required on the S7-300 side. By default, S7-300 CPUs in modern firmware versions block remote PUT/GET for write protection reasons.
- Open the existing SIMATIC Manager project on the engineering station.
- Open HW Config and select the CPU 315.
- Open Object Properties on the CPU, then navigate to the Protection tab (STEP 7 V5.5) or Communication tab (older versions).
- Check the box "Permit access with PUT/GET communication from remote partner" (German: "Bausteinoptimierter Zugriff" in some versions: "Zulassen der PUT/GET-Kommunikation").
- Download the hardware configuration to the CPU (online > Download to Target Station).
Configuring the S7 Connection in TIA Portal V13
- Open the S7-1200 project in TIA Portal V13. Add a CPU 1215C device if you have not already done so.
- Open the Devices & Networks view, then the Network view.
- From the right-hand catalog, drag an S7 connection (under Other Ethernet devices if you do not have the S7-300 in the project) onto the S7-1200's PROFINET interface. Alternatively, use the menu Options > Configure a new S7 connection.
- Double-click the connection line to open its properties.
- On the General tab, set:
- Local endpoint: S7-1200 PROFINET interface, address 192.168.0.10 (adjust to your network).
- Partner: Choose Unspecified and enter the S7-300 IP (192.168.0.20), rack 0, slot 2 (CPU 315-2 PN/DP). If using CP 343-1, the slot is 4 (rack 0, slot 4).
- Connection type: S7 connection.
- Connection resource: Pick a free ID (e.g., 1) and record the resulting Connection ID. The GET instruction will use this ID.
- On the Address details tab, confirm the TSAPs: the local TSAP is auto-assigned, the partner TSAP is 03.02 for a CPU on rack 0 slot 2 (or 03.04 for a CP on rack 0 slot 4). For an S7-300 with an integrated PN interface, the TSAP is
03.02by default. - Compile and download the hardware configuration to the S7-1200.
Programming the GET Instruction
Open the main OB (OB1) of the S7-1200. Drag the GET instruction from the task card under Instructions > Communication > S7 Communication into a network. TIA Portal prompts you to create an instance DB; accept the default name (e.g., GET_DB).
A typical two-word read is wired as follows:
// Network 1: read 2 words from DB100 starting at byte 0
// of the S7-300 into a local DB on the S7-1200
//
// S7 connection ID: 1 (from Devices & Networks)
// Remote DB: DB100
// Remote offset: 0.0 (byte.bit; S7-300 uses byte offset only)
// Length: 4 bytes (= 2 words)
// Local target: DB200.DBD0 (any data block of sufficient size)
"GET_DB".REQ := %I0.0; // trigger one-shot, e.g. from a positive edge
"GET_DB".ID := W#16#1; // connection ID = 1
"GET_DB".ADDR_1 := P#DB100.DBX 0.0 WORD 2; // remote: 2 words from DB100
"GET_DB".RD_1 := P#DB200.DBX 0.0 WORD 2; // local: 2 words into DB200
"GET_DB".LEN := 4; // 2 words = 4 bytes
// Status outputs
"GET_DB".NDR := %M10.0; // 1 cycle: new data received
"GET_DB".ERROR := %M10.1; // 1 = error occurred
"GET_DB".STATUS := %MW12; // detailed error/status code
"GET_DB".BUSY := %M10.3; // job in progress
Because GET is asynchronous, wrap the REQ with an edge-detect pattern and trigger it cyclically (every 100 ms) or by an event. Poll NDR to latch the successful read or ERROR for diagnostics.
GET Instruction Interface Reference
| Parameter | Direction | Type | Meaning |
|---|---|---|---|
| REQ | IN | BOOL | Rising edge starts a new read job. |
| ID | IN | WORD | Connection ID from the S7 connection configuration. |
| ADDR_1 (…ADDR_4) | IN | VARIANT (POINTER in V13) | Remote address. Use P#DB<n>.DBX <byte>.0 WORD <count>. |
| RD_1 (…RD_4) | OUT/IN-OUT | VARIANT | Local receive area; must match the size implied by ADDR_1. |
| LEN | OUT/IN-OUT | DINT or UINT | Total length in bytes (sum of all ADDR_x areas). |
| NDR | OUT | BOOL | One-cycle TRUE when new data has been received without error. |
| ERROR | OUT | BOOL | One-cycle TRUE when the job terminated with an error. |
| STATUS | OUT | WORD | Detailed status (see table below). 0x0000 if the job is queued. |
| BUSY | OUT | BOOL | TRUE while the job is in progress. |
Multiple ADDR/RD pairs let you read up to four separate areas with a single GET. The sum of their byte lengths must equal LEN. For two words from one DB, ADDR_1 alone with WORD 2 is sufficient.
STATUS and ERROR Code Interpretation
| STATUS (hex) | Meaning |
|---|---|
| 0x0000 | Job queued or completed without error. |
| 0x0001 / 0x0002 | Connection established, data read successfully (informational). |
| 0x7000 | No job active (idle state). |
| 0x7001 | Job starting (first call). |
| 0x7002 | Job running (intermediate call). |
| 0x8085 / 0x8185 | Connection error (partner unreachable, wrong TSAP, wrong IP, or wrong slot). |
| 0x80A1 / 0x80A3 | Connection aborted by partner or by network timeout. |
| 0x80B1 / 0x80B4 | Illegal pointer specification in ADDR_x or RD_x. |
| 0x80C3 | Data length mismatch between LEN and the sum of ADDR_x areas. |
| 0x80C4 | Data type conflict; check that ADDR_1's element type matches RD_1. |
| 0x8x22 | DB number too high or does not exist on the partner CPU. |
| 0x8x24 | Area length error on the partner CPU (offset + length exceeds DB size). |
| 0x8x32 | DB does not exist on the partner (typo, DB uninitialized, or DB deleted in RUN). |
| 0xDF31 / 0xCF31 | PUT/GET access denied: the S7-300 CPU has not enabled remote PUT/GET. |
31, the partner CPU is rejecting PUT/GET. The single most common cause is the unchecked "Permit access with PUT/GET" box on the S7-300.Verification and Commissioning
- Online connect to the S7-1200. Monitor the GET instance DB.
- Force
REQto TRUE. WatchBUSYgo TRUE for one or two OB1 cycles (typical on a healthy 100 Mbit link: 1 cycle ≈ 10–30 ms for 2 words). - Confirm
NDRpulses TRUE andSTATUSreturns 0x0002 (or 0x0001 first time, then 0x0002 on success). - Open the target DB200 on the S7-1200 in the watch table and confirm the two words match the values in DB100 of the S7-300. Use Monitor / Modify on the S7-300 to write a known pattern and observe it propagating within one OB1 cycle.
- Disconnect the PROFINET cable and verify
ERRORsets within the configured connection timeout (default 10 s) with STATUS = 0x8185. Reconnect and confirm the S7-1200 re-establishes the connection automatically without restart.
Troubleshooting Matrix
| Symptom | Likely Root Cause | Corrective Action |
|---|---|---|
| STATUS = 0x8185 immediately on REQ | Wrong partner IP, wrong rack/slot, or TSAP mismatch | Verify the partner address details in Devices & Networks > S7 connection > Address details. Ping the S7-300 from the TIA engineering PC. |
| STATUS = 0xDF31 or 0xCF31 | PUT/GET disabled on S7-300 | Open the S7-300 hardware configuration, check Permit access with PUT/GET communication from remote partner, recompile and download HW Config. |
| STATUS = 0x8x22 / 0x8x32 | DB number does not exist on S7-300 | Cross-check the DB number against the SIMATIC project. Confirm the DB has been generated and downloaded. |
| STATUS = 0x8x24 | Offset + length exceeds DB size | Reduce WORD count or adjust the starting byte offset. |
| STATUS = 0x80C4 | Type mismatch between ADDR_1 and RD_1 | Match element count and data type (WORD 2 ↔ DBD area, or ARRAY[0..1] OF WORD). |
| NDR never sets, BUSY stays TRUE | Connection resource on S7-300 exhausted (S7-300 has max 16 S7 connections per CPU/CP) | Reduce concurrent connections, or upgrade to a CPU/CP with more S7 connection resources. |
| Read works online, fails after restart | Connection not yet established at startup | Trigger GET only after the connection is up (status bit from connection diagnostics, or delay REQ by 2 s in OB100/startup OB). |
| Values arrive scrambled or zeroed | Byte-swap because S7-300 is big-endian and S7-1200 is little-endian on the wire | S7 communication handles byte order automatically; if you still see swapped bytes, check that the target area in DB200 is a WORD array and not a STRING or user-defined type with mixed length. |
Performance, Cycle, and Optimization Notes
- Throughput: a single GET of 2 words (4 bytes) consumes approximately 8 to 30 ms round-trip on a 100 Mbit PROFINET link, dominated by the S7 connection's request/acknowledge handshake. Increasing the read length to fetch the entire DB in one shot (e.g., 100 bytes) does not change the per-job latency meaningfully but reduces the number of connection requests per second.
- Polling cadence: 100 ms to 500 ms is typical for HMI/monitoring scenarios. Faster polling (< 50 ms) generates unnecessary traffic on the S7-300's connection resource pool.
- Connection budget: a CPU 315-2 PN/DP supports up to 16 S7 connections; an external CP 343-1 supports 16. If HMI panels, drives, and other controllers already use most of these, add a second CP 343-1 or consolidate via an S7 router.
- Edge triggering: a one-shot REQ edge prevents multiple jobs from queuing; without edge detection, BUSY can latch.
- Read-only: GET is the only instruction needed. PUT (the write counterpart) is not required and should not be configured for this retrofit.
FAQ
Do I need to modify the S7-300 program to expose the data block to the S7-1200?
No program change is needed. The S7-300 must have the "Permit access with PUT/GET communication from remote partner" checkbox enabled in HW Config (Protection / Communication tab). That single toggle authorizes the S7-1200's GET instruction to read any DB directly.
What hardware do I need on the S7-300 to get PROFINET?
Use a CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) which has an integrated PROFINET interface, or add a CP 343-1 (6GK7343-1EX30-0XE0) to a CPU 315-2 DP. The PN interface becomes the S7 connection endpoint; rack 0, slot 2 for the integrated PN or rack 0, slot 4 for the CP.
Which TIA Portal version is required on the S7-1200 side?
TIA Portal V13 supports S7-1200 CPUs with firmware V4.0 or higher. V13 SP1 adds S7-1500 support. V14/V15 use a different GET block ID, so when migrating projects, recompile the GET and update the connection ID.
How many words can a single GET transfer?
Up to 462 bytes in a single GET (this is the S7-300 partner's maximum PDU size for a passive read). For two words (4 bytes) the job completes in a single handshake, so no fragmentation logic is required.
Why does STATUS return 0xDF31 even though the network is reachable?
Status 0xDF31 indicates the partner CPU has refused the PUT/GET access. The cause is almost always the disabled "Permit access with PUT/GET communication" option on the S7-300. Re-check HW Config, recompile, and download only the hardware configuration back to the S7-300.