S7-1200 PROFIBUS Master-Slave Data Exchange in TIA Portal V13

David Krause11 min read
S7-1200SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Engineers frequently attempt to establish an S7 connection between two SIMATIC S7-1200 CPUs over PROFIBUS using the PUT and GET instructions in TIA Portal V13. The portal blocks the configuration, and the resulting error is not a configuration mistake: S7 communication is not supported on the PROFIBUS interface of an S7-1200. The Siemens TIA Portal documentation for configuring PROFIBUS DP with S7-1200 states that the PROFIBUS CM on an S7-1200 acts strictly as a DP master (CM 1243-5) or DP slave (CM 1242-5) for distributed I/O, and the S7 connection resources exposed by the CPU are bound to the PROFINET interface, not the PROFIBUS CM.

The correct method to exchange data between two S7-1200 stations over PROFIBUS is the I-Slave/Master model with configured transfer areas, polled by the master CPU using the DPRD_DAT (read) and DPWR_DAT (write) instructions. This article walks through hardware selection, project configuration in TIA Portal V13, transfer-area setup, and the program code required to read a value (for example, the constant 100) from a slave CPU to a master CPU.

Why S7 PUT/GET Fails Over PROFIBUS on the S7-1200

The S7-1200 connection resources are managed by the CPU firmware. With the default firmware delivered for a 1214C, the CPU exposes a fixed number of communication connections (typically 16 for the 1214C/1215C/1217C variants), but those connections are PROFINET-only. When you add a CM 1242-5 (slave) or CM 1243-5 (master) to the S7-1200, the module does not extend the S7 connection table; it only adds a DP master or DP slave interface for cyclic I/O data exchange.

Symptoms engineers see in TIA Portal V13:

  • The "Add new connection" dialog only allows PROFINET partners when the local interface is a PROFIBUS CM.
  • PUT and GET blocks either refuse to compile, or compile but never transition from BUSY to DONE at runtime because no S7 connection is bound.
  • Online diagnostics on the CM show the DP bus is operational, but no S7 connection is listed in "Connection resources".
Root cause: S7 connection resources on the S7-1200 are anchored to the PROFINET interface of the CPU. The PROFIBUS CMs do not participate in S7 routing or in PUT/GET communication between two S7-1200 stations.

Prerequisites

Confirm the following before configuring the project:

Item Specification Notes
Master CPU S7-1200 (e.g., 1214C DC/DC/DC, 6ES7214-1AG40-0XB0) Firmware V4.x recommended for full DP master capability
Master PROFIBUS CM CM 1243-5 (6GK7243-5DX30-0XE0) Acts as DP master for distributed I/O
Slave CPU S7-1200 (e.g., 1214C) Same family as master; CPU firmware V4.x or later
Slave PROFIBUS CM CM 1242-5 (6GK7242-5DX30-0XE0) Acts as DP slave; supports I-Slave mode
Engineering software TIA Portal V13 (or V13 SP1 / V14 / V15.1 for newer firmware) Must include HSP for the CM 1242-5/1243-5
PROFIBUS cable 2-wire shielded, terminated at both ends Use PROFIBUS connectors with terminating resistor switched ON at end nodes
PROFIBUS address Master = 1, Slave = 2 (typical) Each address must be unique on the segment

Hardware and Module Pinout Reference

The CM 1242-5 (slave) and CM 1243-5 (master) plug into the left-side bay of the S7-1200 CPU. The PROFIBUS connector is a 9-pin D-sub female. Pin assignment is identical to the standard PROFIBUS DP connector:

Pin Signal Description
3 B / RxD/TxD-P Data line B (positive)
5 DGND Data ground (reference for 5 V)
6 VP +5 V supply (termination only)
8 A / RxD/TxD-N Data line A (negative)
Always enable the terminating resistor on the connector at each end of the PROFIBUS segment and switch it OFF on all intermediate nodes. The CM 1243-5/1242-5 modules themselves do not provide bus termination; the connector does.

Project Setup in TIA Portal V13

  1. Create a new project and add both S7-1200 CPUs. Name them clearly, e.g., CPU_Master and CPU_Slave.
  2. In the device configuration of the master, drag a CM 1243-5 from the hardware catalog onto the left of the CPU. TIA Portal auto-assigns a PROFIBUS interface with subnet PROFIBUS_1.
  3. In the device configuration of the slave, drag a CM 1242-5. Connect its PROFIBUS interface to PROFIBUS_1.
  4. Open the master CM's properties → PROFIBUS address: set to 1, transmission rate 1.5 Mbps (or whatever the segment requires).
  5. Open the slave CM's properties → PROFIBUS address: set to 2.
  6. From the device view of the slave CM, switch the operating mode to DP slave. In the I-Slave communication tab, the transfer areas are configured in the next step.

Configuring the DP Slave (I-Slave Mode) and Transfer Areas

The I-Slave mode is what enables peer-to-peer data exchange between two S7-1200 stations. The slave publishes one or more transfer areas to the bus, and the master reads/writes those areas as if they were remote I/O.

  1. Select the CM 1242-5 in the slave station.
  2. Open Properties → I-Slave communication.
  3. Add a new transfer area:
    • Type: Input (data the slave provides to the master)
    • Length: e.g., 4 bytes
    • Address in slave process image: e.g., %IW100
  4. Optionally add an output transfer area for data the master sends back to the slave (length 4 bytes, e.g., %QW100).
  5. Compile and download the slave configuration.
Transfer areas on the CM 1242-5 must not collide with the I/O addresses used by signal modules. Use a free area (e.g., starting at 100) to avoid overlap with the default process image range 0..1023.

Configuring the DP Master and Assigning the Slave

  1. Switch to network view and connect the master CM 1243-5 to the slave CM 1242-5 on the same PROFIBUS subnet.
  2. Right-click the master CM → Assign master system, then drag the slave CM into the master system.
  3. Open the slave device in the device view of the master project. TIA Portal lists the transfer areas as slot 0 with input/output subslots, matching the I-Slave configuration on the slave.
  4. The slave's transfer areas appear in the master's device view at I addresses (e.g., IW0) and Q addresses (e.g., QW0). These are the addresses the master program uses with DPRD_DAT/DPWR_DAT.

Programming: Reading a Value from the Slave with DPRD_DAT

The DPRD_DAT instruction reads a consistent block of data from a DP slave. The DPWR_DAT instruction writes a consistent block of data. Both are available in the Instructions task card under Communication → PROFIBUS DP.

Example: read 4 bytes from slave PROFIBUS address 2, slot 0, and place the result in a tag called SlaveData.

// Master CPU - program block OB1 (ladder / FBD / ST)
// Read 4 bytes from DP slave at PROFIBUS address 2, slot 0
// RECORD = target tag; LADDR = configured I address of the slave

// Ladder equivalent:
// [ DPRD_DAT_EN ]----[ ENO ]
//     LADDR  := 0          // I/O start address from device view
//     RECORD := P#DB1.DBX0.0 BYTE 4   // 4-byte destination
//     RET_VAL:= MW100       // return value (16-bit status)

// Structured Text:
IF "FirstScan" THEN
    "DPRD_DB".REQ := TRUE;
END_IF;

"DPRD_DB"(REQ := "FirstScan",
         LADDR := 0,
         RECORD := P#"SlaveData".InputWord BYTE 4,
         RET_VAL := "DPRD_Status");

IF "DPRD_DB".DONE THEN
    "ValueFromSlave" := "SlaveData".InputWord;
    "DPRD_DB".REQ := FALSE;
END_IF;

IF "DPRD_DB".ERROR THEN
    "ProfibusError" := "DPRD_DB".STATUS;
END_IF;

To send a value (e.g., 100) from the master to the slave, mirror the configuration with a write transfer area on the slave and use DPWR_DAT on the master:

// Structured Text - master program
"ValueToSlave" := 100;

"DPWR_DB"(REQ := TRUE,
         LADDR := 4,                       // Q start address of output transfer area
         RECORD := P#"MasterData".OutputWord BYTE 4,
         RET_VAL := "DPWR_Status");

IF "DPWR_DB".DONE THEN
    "DPWR_DB".REQ := FALSE;
END_IF;

On the slave CPU, map the input transfer area into a tag (e.g., %IW100) and copy it into a data block. The slave can also react to changes in %IW100 to drive outputs, store values, etc.

Reading Data on the Slave CPU

The slave CPU sees its own transfer area as a normal input area in the process image. To expose the data received from the master (the value 100 in the example) as a tag, simply read %IW100 in the slave program. To make the tag available for the master, store it in the input transfer area region (e.g., %QW100 of the slave, which is mapped to the master as an input).

// Slave CPU - OB1 (Structured Text)
// Push a constant 100 into the transfer area so the master can read it.
"ValueToMaster" := 100;
// Tag "ValueToMaster" must be at the address configured as the input transfer area,
// e.g., %QW100 (4 bytes), in the CM 1242-5 I-Slave configuration.

On the master, the previously written DPRD_DAT will read this 4-byte region and the value 100 will appear in SlaveData.InputWord.

Diagnostic and Status Codes

The STATUS output of DPRD_DAT/DPWR_DAT returns a 16-bit value. The most common codes you will see on S7-1200:

STATUS (hex) Meaning Corrective action
0000 Job completed without error None
7000 No job active Trigger REQ to start a new read/write
7001 First read/write job in progress Wait for DONE or ERROR
7002 Subsequent job in progress Wait
8090 LADDR invalid or slave not configured Check the I/O start address in the master device view
8092 RECORD pointer exceeds process image Reduce the data length or move the destination DB
80A1 DP slave not reachable / bus fault Check PROFIBUS cable, termination, addresses
80A2 DP slave not ready / configuration mismatch Re-download the I-Slave configuration to the slave
80B0 DP slave reports diagnostics Read slave diagnostics in online view
80B1 Configuration data differs from the slave Recompile and download both stations
80C0 DP slave not in data exchange Slave has not yet started cyclic communication; check DP LEDs
80D0 DP master not in RUN Place master CPU in RUN; check OB82/OB86 handling

PROFIBUS module LEDs provide additional clues:

  • BF (red, steady): bus fault — cable/termination/addressing issue.
  • BF (red, flashing): slave configuration mismatch.
  • SF (red): system fault on the CM; check online diagnostics.
  • ON (green): the CM is in data exchange with the master.

Troubleshooting Matrix

Symptom Likely cause Fix
TIA Portal refuses to create S7 connection on PROFIBUS CM does not support S7 connections Use I-Slave transfer areas + DPRD_DAT/DPWR_DAT
DPRD_DAT STATUS = 80A1 Bus fault or wrong address Verify both ends are terminated, addresses unique, cable polarity
STATUS = 80A2 / 80B1 Configuration mismatch Re-download the slave's I-Slave configuration; ensure transfer area length matches
STATUS = 80B0 Slave sent diagnostic interrupt Open "Online & Diagnostics" → DP diagnostics on the slave
STATUS = 8090 LADDR not the configured I/Q start Use the address shown in the master's device view for the slave slot
Value in master is always 0 Transfer area not written on the slave side Confirm the slave program writes the tag at the transfer area address
PROFIBUS LED BF steady on master Slave not powered or cable broken Power the slave, check the bus cable, check terminating resistor

Alternative: Switch to PROFINET for S7 Communication

If the project permits, replacing the PROFIBUS CMs with a direct PROFINET connection between the two S7-1200 CPUs unlocks the standard PUT/GET/TSEND/TRCV instruction set. In that scenario:

  • The S7-1200 PROFINET interface is used for S7 communication.
  • No CM is required.
  • PUT and GET are configured via the "Connections" editor against the partner CPU's PROFINET IP address.

For installations with existing PROFIBUS infrastructure (cable, connectors, SCADA interfaces) staying on PROFIBUS and using the I-Slave / DPRD_DAT/DPWR_DAT method is usually the lowest-impact change.

Verification

  1. Compile and download both stations. The master CPU must be in RUN.
  2. Open "Online & Diagnostics" on the master CM 1243-5. The "DP master system" view should list the slave at PROFIBUS address 2 with state Data exchange.
  3. Force REQ on the DPRD_DAT instance. Watch STATUS transition from 7001 → 0000 with DONE = TRUE.
  4. Watch table on the master: SlaveData.InputWord should display the value 100 within one DP cycle.
  5. On the slave, watch table: writing to the output transfer area tag (e.g., QW100) should be reflected on the master at the corresponding input address within one cycle.
  6. Disconnect the PROFIBUS cable at one end: the master should report STATUS = 80A1 and the CM's BF LED should light. Reconnect: communication resumes within the configured reaction time.

Why does TIA Portal V13 refuse to create an S7 connection on the PROFIBUS CM?

The S7-1200 connection resources are bound to the PROFINET interface of the CPU. The CM 1242-5/CM 1243-5 only provide a DP slave or DP master interface for cyclic I/O, not S7 communication. Use the I-Slave/Master model and DPRD_DAT/DPWR_DAT instead of PUT/GET.

Which Siemens CM module do I need for the master and for the slave?

For the master side, use the CM 1243-5 (article number 6GK7243-5DX30-0XE0). For the slave side, use the CM 1242-5 (6GK7242-5DX30-0XE0). The CM 1243-5 cannot be used as a slave and the CM 1242-5 cannot be used as a master.

How much data can be exchanged per transfer area on the CM 1242-5?

Each I-Slave transfer area on the CM 1242-5 supports up to 32 bytes for inputs and 32 bytes for outputs. If you need more, add additional transfer areas in the I-Slave configuration. The aggregate data must fit within the DP slave's configured slot.

Can I use PUT/GET between two S7-1200 CPUs without changing the hardware?

Yes, but only if both CPUs are connected via PROFINET. The CPUs' built-in PROFINET interface supports S7 connections. If the bus must remain PROFIBUS, you must switch to the DPRD_DAT/DPWR_DAT method described above.

What does STATUS 80A1 mean on DPRD_DAT, and how do I fix it?

STATUS 80A1 indicates that the DP slave is not reachable on the bus. Check the PROFIBUS cable for breaks or swapped A/B wires, confirm the terminating resistor is ON at both ends and OFF in the middle, and verify the slave's PROFIBUS address matches the one assigned in the master's device view.

Back to blog