S7-1200 PROFIBUS DP Configuration with CM 1243-5 and CM 1242-5
The SIMATIC S7-1200 CPU family does not include an onboard PROFIBUS interface. PROFIBUS DP connectivity is added to the S7-1200 system through dedicated communication modules (CM/CP) that mount on the left side of the CPU. Two modules cover the entire DP role spectrum:
- CM 1242-5 — PROFIBUS DP Slave (CPV 1242-5 in legacy naming)
- CM 1243-5 — PROFIBUS DP Master (CPV 1243-5 in legacy naming)
With these modules an S7-1200 can act as a DP master on a PROFIBUS segment, a DP slave to a higher-level master, or both simultaneously when two slots are populated. This reference covers the hardware, TIA Portal configuration, ET200M integration, diagnostics, and field-proven constraints for S7-1200 PROFIBUS DP projects.
1. S7-1200 PROFIBUS Module Family
The S7-1200 supports PROFIBUS DP exclusively through the CM 1242-5 and CM 1243-5 communications modules. There is no PROFIBUS interface built into the CPU backplane and no signal-module (SM) variant that exposes PROFIBUS. Each module occupies one slot on the left bus of the S7-1200 CPU, in the same left-side expansion chain used by the CM/CP for point-to-point (RS232/RS485), AS-i, and Telecontrol.
| Module | MLFB (Article No.) | PROFIBUS Role | Firmware | Max. DP Slaves | Power from S7-1200 Bus |
|---|---|---|---|---|---|
| CM 1242-5 | 6GK7 242-5DX30-0XE0 | DP Slave | V1.0 and higher | n/a (slave device) | Yes |
| CM 1243-5 | 6GK7 243-5DX30-0XE0 | DP Master (Class 1) | V1.0 and higher | 16 DP slaves per module | Yes |
| CM 1243-5 (new revision) | 6GK7 243-5DX30-0XE1 | DP Master (Class 1) — supports S7 routing + extended diagnostics | V2.0 and higher | 16 DP slaves per module | Yes |
2. Functional Differences Between CM 1242-5 and CM 1243-5
2.1 CM 1242-5 — PROFIBUS DP Slave
The CM 1242-5 exposes the S7-1200 CPU as a DP-V0/V1 slave to an external PROFIBUS master (typically a S7-300/S7-400 CPU with integrated DP interface, an ET200S/station, or a third-party master). The host CPU exchanges process data with the CM 1242-5 over the internal backplane; the CM forwards those data to the DP master through the PROFIBUS segment.
- 32-byte maximum I/O data per direction (DP-V0); extended to 122 bytes input and 122 bytes output for DP-V1 with suitable master configuration
- Automatic baud rate detection (9.6 kbit/s to 12 Mbit/s)
- 9-pin D-sub PROFIBUS connector, female
- Diagnostic LEDs: BF (Bus Fault), SF (System Fault), ON (Power), MAINT
2.2 CM 1243-5 — PROFIBUS DP Master
The CM 1243-5 acts as a DP-V0/V1 Class 1 master. It owns the PROFIBUS token and polls configured slaves cyclically. The CM 1243-5 handles bus arbitration, slave diagnostics, and acyclic DP-V1 services. The host CPU is not burdened with the PROFIBUS stack — the CM communicates with the CPU over the left-side bus using internal process-image mirroring.
- Up to 16 DP slaves per CM 1243-5
- Maximum 32-byte input and 32-byte output per slave (DP-V0); DP-V1 expands this to 244 bytes per slot
- Supported baud rates: 9.6 kbit/s, 19.2 kbit/s, 45.45 kbit/s, 93.75 kbit/s, 187.5 kbit/s, 500 kbit/s, 1.5 Mbit/s, 3 Mbit/s, 6 Mbit/s, 12 Mbit/s
- Diagnostic LEDs: BF1/BF2, SF, ON, MAINT
3. S7-1200 CPU Selection for PROFIBUS Projects
Because the PROFIBUS stack is offloaded to the CM 1243-5/CM 1242-5, the CPU selection is driven by I/O count, program memory, and onboard I/O type — not PROFIBUS performance. The CM 1243-5 can be added to any S7-1200 CPU from CPU 1211C up to CPU 1217C/DC/DC/DC (Firmware V4.0 or higher; CPU 1211C/1212C with FW V4.x supports the CMs but limits central I/O expansion). PROFIBUS configuration was originally introduced in TIA Portal V11 and is available in all subsequent TIA Portal versions including V15, V16, V17, V18, V19, and V20.
3.1 CPU Family Overview
| CPU | Work Memory (Program/Data) | Load Memory | Bit Memory | Onboard DI/DO/AI | Signal Modules (SM) Max | CM/CP Max |
|---|---|---|---|---|---|---|
| CPU 1211C | 50 KB / 50 KB | 1 MB (V4.x) / 2 MB (V4.4+) | 4 KB | 6 DI / 4 DO / 2 AI | 0 (board-locked) / 1 (some FW) | 3 |
| CPU 1212C | 75 KB / 75 KB | 1 MB / 4 MB | 4 KB | 8 DI / 6 DO / 2 AI | 1 | 3 |
| CPU 1214C | 100 KB / 100 KB | 1.5 MB / 4 MB | 8 KB | 14 DI / 10 DO / 2 AI | 8 | 3 |
| CPU 1215C | 125 KB / 125 KB | 4 MB | 8 KB | 14 DI / 10 DO / 2 AI / 2 AO | 8 | 3 |
| CPU 1217C | 150 KB / 150 KB | 4 MB | 8 KB | 14 DI / 10 DO / 2 AI / 2 AO | 8 | 3 |
3.2 Recommended CPU for the Reference Network
The sample network cited in the source — three ET200M slaves totaling 64+32+16 = 112 DI, 32+16+32 = 80 DO, 8+8 = 16 AI, 0+0+8 = 8 AO — places the project firmly in the CPU 1214C or CPU 1215C range. The CPU 1214C with up to 8 signal modules covers the central I/O requirement; the CPU 1215C adds two onboard analog outputs and is preferable if onboard AO is required.
Selection checklist:
- Central I/O — Total DI/DO/AI/AO count after PROFIBUS I/O is subtracted.
- Work memory — DP-V1 acyclic blocks (e.g., RDREC/WRREC on the CM 1243-5 process image) add 4–8 KB to the program.
- Load memory — TIA Portal auto-allocates; the CPU 1214C V4.4 4 MB load memory is the practical minimum for any non-trivial project.
- Onboard I/O type — DC/DC/DC for solid-state outputs, AC/DC/Relay for mixed-voltage installations, DC/DC/Relay for discrete load handling.
- Future expansion — Reserve at least one free CM/CP slot for diagnostics or an additional RS232/RS485 module.
Use the Siemens SIMATIC Selection Tool (TIA Selection Tool) for an automated BOM and validation pass.
4. S7-1200 Backplane Topology and Slot Rules
The S7-1200 left-side expansion bus is the physical path for the CM 1242-5 and CM 1243-5. Critical rules:
- Maximum three CMs/CPs per CPU. This includes the CM 1242-5, CM 1243-5, CM 1241 (RS232/RS485), CP 1242-7 (GPRS), CP 1243-1 (Industrial Ethernet), CP 1243-7 LTE, and AS-i master CM 1243-2.
- CMs/CPs are placed to the left of the CPU in TIA Portal > Device view. The CPU is always slot 1 of the station; CMs occupy logical slots 100, 101, 102 (or higher, with V4.x firmware allowing up to slot 103 in some CPU variants).
- Slot order is significant only for bus addressing; PROFIBUS CMs may be placed in any order. The TIA Portal hardware catalog enforces maximum-count rules.
- No PROFIBUS connection to ET200S / ET200pro as a distributed sub-rack from the S7-1200 backplane — that is an S7-300/S7-400 architecture. For the S7-1200, PROFIBUS DP slaves (including ET200M) hang off the CM 1243-5 over the fieldbus, not the backplane.
5. PROFIBUS Topology, Cabling, and Connectors
Use the standard Siemens PROFIBUS cable (6XV1830-0EH10, violet sheath) terminated with 9-pin D-sub connectors. The CM 1243-5 exposes a 9-pin female D-sub with the standard PROFIBUS pinout:
| Pin | Signal | Function |
|---|---|---|
| 1 | Shield | Cable shield (optional bonding) |
| 2 | M24 | 24 V common (only on active terminators) |
| 3 | RxD/TxD-P | Data line B (red conductor) |
| 4 | RTS | Request To Send (direction control) |
| 5 | DGND | Data ground (5 V reference) |
| 6 | VP | +5 V supply (only on active terminators) |
| 7 | P24 | +24 V (only on active terminators) |
| 8 | RxD/TxD-N | Data line A (green conductor) |
| 9 | DGNDA | Data ground (repeater/signal) |
5.1 Termination
Each end of a PROFIBUS segment must be terminated with 220 Ω between pin 3 and pin 8, plus 390 Ω pull-up to +5 V (pin 6) and 390 Ω pull-down to ground (pin 5). The termination is typically built into the 9-pin connector with a switch (e.g., 6GK1 500-0FC10). The CM 1243-5 itself does not provide termination — fit the bus terminator on the connector of the first and last device.
5.2 Baud Rate vs. Segment Length
| Baud Rate | Max Segment Length (Type A cable) |
|---|---|
| 9.6 kbit/s – 187.5 kbit/s | 1000 m |
| 500 kbit/s | 400 m |
| 1.5 Mbit/s | 200 m |
| 3 Mbit/s – 12 Mbit/s | 100 m |
For typical 1.5 Mbit/s ET200M networks, 200 m per segment is the working ceiling. Repeaters (RS 485 Repeater, e.g., 6GK1 500-3AA10) extend the bus and provide segment-to-segment galvanic isolation.
6. TIA Portal Configuration — S7-1200 as DP Master
Configuration is performed in TIA Portal under Devices & Networks > Network view. The procedure below corresponds to TIA Portal V16/V17/V18/V19/V20; older TIA versions V11–V15 follow the same path with minor dialog changes.
6.1 Prerequisites
- TIA Portal with STEP 7 Professional installed (Basic edition does not include PROFIBUS configuration)
- Installed HSP (Hardware Support Package) for the S7-1200 CPU and the CM 1243-5 in the current TIA Portal version
- Project created with the target S7-1200 CPU (e.g., 6ES7214-1AG40-0XB0 for CPU 1214C DC/DC/DC V4.4)
6.2 Step-by-Step Configuration
- Open the project and switch to Project view > Devices & Networks.
- Open Device view on the S7-1200 CPU.
- In the Hardware catalog on the right, navigate to Communication modules > PROFIBUS > CM 1243-5.
- Drag the CM 1243-5 into the slot left of the CPU (slot 100 or the first free left-side slot). The module is now part of the S7-1200 station.
- Select the CM 1243-5 and open Properties > PROFIBUS interface. Set:
-
Interface type= PROFIBUS -
Address= the desired master PROFIBUS address (default 2) -
Highest PROFIBUS address= 126 (HSA — must be ≥ the highest slave address) -
Transmission speed= matches the slaves' configured speed (e.g., 1.5 Mbit/s) -
Profile= DP
-
- From the network view, drag each PROFIBUS slave (e.g., ET200M with IM 153-1, IM 153-2, or IM 153-4 PN) onto the CM 1243-5 PROFIBUS subnet.
- For each slave, open Properties > PROFIBUS interface and set a unique PROFIBUS address (1, 3, 4 in the sample network — note that 1 is not always recommended; many projects leave 1 for a PG/service device).
- For each slave, open Device view and slot the signal modules (SM 321 DI, SM 322 DO, SM 331 AI, SM 332 AO) to match the physical hardware configuration in the ET200M rack.
- TIA Portal automatically generates the I/O address mapping. Verify it in Device view > I/O addresses. The process image is split:
- Inputs: I0.0 – I
(cyclic I/O from the slaves is mirrored into the CPU input image) - Outputs: Q0.0 – Q
- Inputs: I0.0 – I
- Compile the configuration (Project > Compile > Hardware configuration) and download to the CPU.
7. TIA Portal Configuration — S7-1200 as DP Slave
When the S7-1200 must report to a higher-level master, the CM 1242-5 is added to the station and configured as a slave:
- Drag CM 1242-5 into the left-side slot in Device view.
- Open Properties > PROFIBUS interface > Operating mode and select DP slave.
- In I/O addresses, set the cyclic input and output slot sizes. TIA Portal adds the I/O areas to the CPU process image automatically.
- On the master side (e.g., S7-1500 with CM 1542-5, or a third-party PLC), the GSD file is not required for the S7-1200 — Siemens devices are part of the TIA Portal hardware catalog. For non-Siemens masters, export the GSD from the S7-1200 station by right-clicking the CM 1242-5 and selecting Export GSD.
8. Integrating ET200M Slaves on the CM 1243-5
The ET200M uses the IM 153-x interface module to connect to PROFIBUS DP. Compatibility with the CM 1243-5 is full because the ET200M is a standard DP-V0/V1 slave. The IM 153-1 supports DP-V0, IM 153-2 adds DP-V1 acyclic services, and IM 153-4 PN is for PROFINET (not applicable here).
8.1 Reference Network Mapping
| ET200M Station | IM Module | PROFIBUS Address | Slots Configured | Total I/O |
|---|---|---|---|---|
| Slave 1 | IM 153-1 (6ES7153-1AA03-0XB0) | 3 | SM 321 32DI, SM 322 32DO | 32 DI / 32 DO |
| Slave 2 | IM 153-1 (6ES7153-1AA03-0XB0) | 4 | SM 321 16DI, SM 322 16DO, SM 331 8AI | 16 DI / 16 DO / 8 AI |
| Slave 3 | IM 153-2 (6ES7153-2BA02-0XB0) | 5 | SM 321 64DI, SM 322 32DO, SM 331 8AI, SM 332 8AO | 64 DI / 32 DO / 8 AI / 8 AO |
Total PROFIBUS I/O across the three slaves: 112 DI, 80 DO, 16 AI, 8 AO. This is well within the 16-slave limit of a single CM 1243-5, and within the I/O image budget of any S7-1200 CPU from the 1214C upward.
8.2 Hot-Swap and Diagnostics
The IM 153-2 supports module hot-swap; the IM 153-1 only supports module replacement with the station powered down. Diagnostic interrupts generated by SM 331/SM 332 modules (e.g., wire break, over-range) are propagated through the CM 1243-5 to the S7-1200 CPU and appear in the diagnostic buffer. The CM 1243-5 also generates a station failure event if a slave drops off the bus, addressable in the CPU via the diagnostic interrupt OB (OB 82) and the status of the slave's DP fault bit in the I/O image.
9. CPU-Side Programming Interface
The PROFIBUS I/O from the CM 1243-5 is mapped into the standard process image and accessed in the same way as onboard I/O. Cyclic I/O uses direct I/O access (e.g., %IW64, %QW32 in SCL, or IW 64, QW 32 in ladder). Acyclic DP-V1 services (read/write record) use the following instruction set:
| Instruction | Library | Purpose |
|---|---|---|
| RDREC | Standard | Read data record from a DP-V1 slave |
| WRREC | Standard | Write data record to a DP-V1 slave |
| RALRM | Standard | Receive interrupt from a DP slave |
| DP_PRAL | SFB 75 / SFC 7 | Trigger a DP-V1 process alarm |
9.1 Sample SCL — Reading an Analog Value via RDREC
// Acyclic read of data record 0 from ET200M slave 3 (PROFIBUS address 5)
// Returns the calibrated 16-bit value of the first AI channel
#statRequest := RDREC(
REQ := TRUE,
ID := 5, // DP master ID for slave at address 5
INDEX := 0, // Data record number 0
LEN := 4, // 4 bytes expected
DONE => #statDone,
BUSY => #statBusy,
ERROR => #statError,
STATUS => #statStatus,
RECORD := #statRecord
);
IF #statDone AND NOT #statError THEN
// First 2 bytes of record contain the AI value
#iValue := WORD_TO_INT(#statRecord[0]);
END_IF;
ID input on RDREC/WRREC is the Hardware Identifier of the slave in the device configuration, not the PROFIBUS address. The HW identifier is visible in Device view > Properties > System constants. Using the PROFIBUS address is a common commissioning error that returns status 0xDE80 (80B0 hex) — "Hardware fault, wrong identifier".10. Diagnostics and Troubleshooting Matrix
| LED on CM 1243-5 / CM 1242-5 | ON | BF (Bus Fault) | SF (System Fault) | MAINT | Meaning / Action |
|---|---|---|---|---|---|
| Power-up normal | green | off | off | off | Module OK, bus OK |
| No PROFIBUS connection | green | red flashing | off | off | Cable/connector or slave power — check termination and 24 V supply on slave |
| Slave failure | green | red solid | off | off | One or more configured slaves are not responding; inspect slave address and baud rate |
| Configuration mismatch | green | red solid | red solid | off | ET200M module inserted in wrong slot or wrong module type — match the slot configuration in TIA Portal to the physical rack |
| Firmware update pending | green | off | off | yellow | Update the CM via TIA Portal Online > Accessible devices > Firmware update |
| PROFIBUS diagnostic interrupt | green | off | red flashing | off | Slave raised a diagnostic interrupt (e.g., wire break on SM 331) — read record 0 with RDREC and check CPU diagnostic buffer |
10.1 Common Error Codes from RDREC/WRREC
| STATUS (hex) | Cause | Remediation |
|---|---|---|
| 0000 0000 | No error | — |
| DE80 / 80B0 | Hardware identifier (ID) invalid | Replace the ID with the HW identifier from System constants, not the PROFIBUS address |
| DE80 / 80C0 | Index / data record not supported by slave | Verify the data record number against the slave GSD/module manual |
| DE80 / 80C3 | Access denied — module is in protected state | Check IM 153 parameter assignment for write protection |
| DE80 / 80D0 | Length error — LEN mismatch with slave | Set LEN to the exact data record length declared in the GSD |
| DE80 / 80FF | Slave not in cyclic data exchange | Wait for BF to clear; check physical connection and slave diagnostics |
10.2 Field-Proven Diagnostic Steps
- Online > Accessible devices in TIA Portal to confirm the CM is visible on the left-side bus.
- Online > Diagnostics > PROFIBUS diagnostics — read the live bus statistics, including per-slave diagnostics, retransmission counters, and cycle time.
- CPU diagnostic buffer — the S7-1200 CPU logs every PROFIBUS module insertion/removal and bus fault with timestamp.
- PROFIBUS cable test with a Siemens BT200 cable tester or equivalent — open/short/reflection check.
11. Cycle Time and Performance
The CM 1243-5 cycle time on the PROFIBUS segment is calculated from the number of configured slaves and the per-slave I/O. The order-of-magnitude rule:
T_cycle ≈ N_slaves × T_bit × 11 + N_diagnostics × 100 µs
For the reference network (3 slaves at 1.5 Mbit/s, 30 DI/DO bytes total per slave on average, no DP-V1 acyclic traffic):
- T_bit at 1.5 Mbit/s = 0.667 µs
- Per-bit time × 11 (start, 8 data, parity, stop) = 7.3 µs per byte
- 30 bytes × 3 slaves × 7.3 µs ≈ 660 µs pure transmission
- Add 100–200 µs per slave for token passing and turn-around
- Estimated cycle time: 1–2 ms
This is well within the 1 ms to 10 ms typical application scan of an S7-1200. For high-speed applications requiring sub-millisecond PROFIBUS, the S7-1500 with CM 1542-5 is the appropriate platform.
12. Migration and Replacement Notes
12.1 CM 1243-5 / CM 1242-5 Obsolescence
The first-generation CM 1243-5 (6GK7 243-5DX00-0XE0) and CM 1242-5 (6GK7 242-5DX00-0XE0) were discontinued. The current production article numbers (6GK7 243-5DX30-0XE1 for the master, 6GK7 242-5DX30-0XE0 for the slave) are drop-in compatible at the PROFIBUS level but require TIA Portal V13 SP1 or higher for configuration. Existing projects with the old MLFBs open cleanly in TIA Portal V17/V18/V19/V20 with the appropriate HSP installed.
12.2 Migration to PROFINET
New installations are recommended to use PROFINET (the S7-1200 has a PROFINET interface on the CPU itself) and the SIMATIC ET200 distributed I/O on PROFINET. The S7-1200 PROFINET interface is more capable, eliminates the CM slot, and provides higher throughput. PROFIBUS remains fully supported by the S7-1200 hardware through the CM 1243-5/CM 1242-5 modules, and the choice between the two is project-specific.
13. Standards Compliance
The CM 1243-5 and CM 1242-5 implement PROFIBUS DP per IEC 61158/61784. The conformance certificate is held by Siemens AG; the modules comply with the PROFIBUS Nutzerorganisation e.V. (PNO) certification for DP-V0 and DP-V1 Class 1 master/slave roles. Verify installation against:
- IEC 61158 — Digital data communications for measurement and control — Fieldbus for use in industrial control systems
- IEC 61784 — Industrial communication networks — Profiles
- PROFIBUS Installation Guideline (PNO order no. 8.042)
14. References
- Siemens Support: PROFIBUS — SIMATIC S7 S7-1200 Programmable controller — official Siemens support entry for CM 1243-5 master integration on the S7-1200.
- TIA Portal Help (V20): Configuring PROFIBUS DP (S7-1200) — STEP 7 — official TIA Portal V20 configuration procedure for the S7-1200 as a PROFIBUS master or slave.
Does the S7-1200 have a built-in PROFIBUS interface?
No. The S7-1200 CPU has no onboard PROFIBUS port. PROFIBUS DP is added by mounting a CM 1242-5 (slave) or CM 1243-5 (master) module on the left side of the CPU. Each CPU supports up to 3 communication modules total.
How many PROFIBUS slaves can a CM 1243-5 connect?
The CM 1243-5 supports up to 16 DP slaves per module. For the reference network with three ET200M stations (one IM 153-1 with 32DI/32DO, one IM 153-1 with 16DI/16DO/8AI, and one IM 153-2 with 64DI/32DO/8AI/8AO), any S7-1200 CPU from the CPU 1214C up is sufficient.
Can the S7-1200 act as both a DP master and a DP slave?
Yes. Add a CM 1243-5 (master) and a CM 1242-5 (slave) to the same CPU. Each occupies a separate left-side slot. The two modules run independent PROFIBUS stacks and the CPU exchanges data with both through the backplane process image.
What baud rate is recommended for S7-1200 PROFIBUS networks with ET200M?
1.5 Mbit/s is the most common working baud rate for ET200M networks and supports up to 200 m of cable per segment. The CM 1243-5 auto-detects from 9.6 kbit/s up to 12 Mbit/s. For mixed-vendor installations, set the baud rate explicitly in TIA Portal and the slave configuration to avoid auto-detect failures during startup.
Why does RDREC return STATUS 0xDE80 / 80B0?
This is the "invalid hardware identifier" error. The ID input to RDREC must be the Hardware Identifier of the slave (visible in TIA Portal > System constants), not the PROFIBUS address. Replacing the address with the HW identifier clears the error.