Overview
Engineers frequently attempt to establish an S7 connection between two SIMATIC S7-1200 CPUs over PROFIBUS using the PUT and GET instructions in TIA Portal V13. The portal blocks the configuration, and the resulting error is not a configuration mistake: S7 communication is not supported on the PROFIBUS interface of an S7-1200. The Siemens TIA Portal documentation for configuring PROFIBUS DP with S7-1200 states that the PROFIBUS CM on an S7-1200 acts strictly as a DP master (CM 1243-5) or DP slave (CM 1242-5) for distributed I/O, and the S7 connection resources exposed by the CPU are bound to the PROFINET interface, not the PROFIBUS CM.
The correct method to exchange data between two S7-1200 stations over PROFIBUS is the I-Slave/Master model with configured transfer areas, polled by the master CPU using the DPRD_DAT (read) and DPWR_DAT (write) instructions. This article walks through hardware selection, project configuration in TIA Portal V13, transfer-area setup, and the program code required to read a value (for example, the constant 100) from a slave CPU to a master CPU.
Why S7 PUT/GET Fails Over PROFIBUS on the S7-1200
The S7-1200 connection resources are managed by the CPU firmware. With the default firmware delivered for a 1214C, the CPU exposes a fixed number of communication connections (typically 16 for the 1214C/1215C/1217C variants), but those connections are PROFINET-only. When you add a CM 1242-5 (slave) or CM 1243-5 (master) to the S7-1200, the module does not extend the S7 connection table; it only adds a DP master or DP slave interface for cyclic I/O data exchange.
Symptoms engineers see in TIA Portal V13:
- The "Add new connection" dialog only allows PROFINET partners when the local interface is a PROFIBUS CM.
-
PUTandGETblocks either refuse to compile, or compile but never transition fromBUSYtoDONEat runtime because no S7 connection is bound. - Online diagnostics on the CM show the DP bus is operational, but no S7 connection is listed in "Connection resources".
PUT/GET communication between two S7-1200 stations.
Prerequisites
Confirm the following before configuring the project:
| Item | Specification | Notes |
|---|---|---|
| Master CPU | S7-1200 (e.g., 1214C DC/DC/DC, 6ES7214-1AG40-0XB0) | Firmware V4.x recommended for full DP master capability |
| Master PROFIBUS CM | CM 1243-5 (6GK7243-5DX30-0XE0) | Acts as DP master for distributed I/O |
| Slave CPU | S7-1200 (e.g., 1214C) | Same family as master; CPU firmware V4.x or later |
| Slave PROFIBUS CM | CM 1242-5 (6GK7242-5DX30-0XE0) | Acts as DP slave; supports I-Slave mode |
| Engineering software | TIA Portal V13 (or V13 SP1 / V14 / V15.1 for newer firmware) | Must include HSP for the CM 1242-5/1243-5 |
| PROFIBUS cable | 2-wire shielded, terminated at both ends | Use PROFIBUS connectors with terminating resistor switched ON at end nodes |
| PROFIBUS address | Master = 1, Slave = 2 (typical) | Each address must be unique on the segment |
Hardware and Module Pinout Reference
The CM 1242-5 (slave) and CM 1243-5 (master) plug into the left-side bay of the S7-1200 CPU. The PROFIBUS connector is a 9-pin D-sub female. Pin assignment is identical to the standard PROFIBUS DP connector:
| Pin | Signal | Description |
|---|---|---|
| 3 | B / RxD/TxD-P | Data line B (positive) |
| 5 | DGND | Data ground (reference for 5 V) |
| 6 | VP | +5 V supply (termination only) |
| 8 | A / RxD/TxD-N | Data line A (negative) |
Project Setup in TIA Portal V13
- Create a new project and add both S7-1200 CPUs. Name them clearly, e.g.,
CPU_MasterandCPU_Slave. - In the device configuration of the master, drag a CM 1243-5 from the hardware catalog onto the left of the CPU. TIA Portal auto-assigns a PROFIBUS interface with subnet
PROFIBUS_1. - In the device configuration of the slave, drag a CM 1242-5. Connect its PROFIBUS interface to
PROFIBUS_1. - Open the master CM's properties → PROFIBUS address: set to
1, transmission rate1.5 Mbps(or whatever the segment requires). - Open the slave CM's properties → PROFIBUS address: set to
2. - From the device view of the slave CM, switch the operating mode to DP slave. In the I-Slave communication tab, the transfer areas are configured in the next step.
Configuring the DP Slave (I-Slave Mode) and Transfer Areas
The I-Slave mode is what enables peer-to-peer data exchange between two S7-1200 stations. The slave publishes one or more transfer areas to the bus, and the master reads/writes those areas as if they were remote I/O.
- Select the CM 1242-5 in the slave station.
- Open Properties → I-Slave communication.
- Add a new transfer area:
- Type: Input (data the slave provides to the master)
- Length: e.g., 4 bytes
-
Address in slave process image: e.g.,
%IW100
- Optionally add an output transfer area for data the master sends back to the slave (length 4 bytes, e.g.,
%QW100). - Compile and download the slave configuration.
100) to avoid overlap with the default process image range 0..1023.
Configuring the DP Master and Assigning the Slave
- Switch to network view and connect the master CM 1243-5 to the slave CM 1242-5 on the same PROFIBUS subnet.
- Right-click the master CM → Assign master system, then drag the slave CM into the master system.
- Open the slave device in the device view of the master project. TIA Portal lists the transfer areas as slot 0 with input/output subslots, matching the I-Slave configuration on the slave.
- The slave's transfer areas appear in the master's device view at I addresses (e.g.,
IW0) and Q addresses (e.g.,QW0). These are the addresses the master program uses withDPRD_DAT/DPWR_DAT.
Programming: Reading a Value from the Slave with DPRD_DAT
The DPRD_DAT instruction reads a consistent block of data from a DP slave. The DPWR_DAT instruction writes a consistent block of data. Both are available in the Instructions task card under Communication → PROFIBUS DP.
Example: read 4 bytes from slave PROFIBUS address 2, slot 0, and place the result in a tag called SlaveData.
// Master CPU - program block OB1 (ladder / FBD / ST)
// Read 4 bytes from DP slave at PROFIBUS address 2, slot 0
// RECORD = target tag; LADDR = configured I address of the slave
// Ladder equivalent:
// [ DPRD_DAT_EN ]----[ ENO ]
// LADDR := 0 // I/O start address from device view
// RECORD := P#DB1.DBX0.0 BYTE 4 // 4-byte destination
// RET_VAL:= MW100 // return value (16-bit status)
// Structured Text:
IF "FirstScan" THEN
"DPRD_DB".REQ := TRUE;
END_IF;
"DPRD_DB"(REQ := "FirstScan",
LADDR := 0,
RECORD := P#"SlaveData".InputWord BYTE 4,
RET_VAL := "DPRD_Status");
IF "DPRD_DB".DONE THEN
"ValueFromSlave" := "SlaveData".InputWord;
"DPRD_DB".REQ := FALSE;
END_IF;
IF "DPRD_DB".ERROR THEN
"ProfibusError" := "DPRD_DB".STATUS;
END_IF;
To send a value (e.g., 100) from the master to the slave, mirror the configuration with a write transfer area on the slave and use DPWR_DAT on the master:
// Structured Text - master program
"ValueToSlave" := 100;
"DPWR_DB"(REQ := TRUE,
LADDR := 4, // Q start address of output transfer area
RECORD := P#"MasterData".OutputWord BYTE 4,
RET_VAL := "DPWR_Status");
IF "DPWR_DB".DONE THEN
"DPWR_DB".REQ := FALSE;
END_IF;
On the slave CPU, map the input transfer area into a tag (e.g., %IW100) and copy it into a data block. The slave can also react to changes in %IW100 to drive outputs, store values, etc.
Reading Data on the Slave CPU
The slave CPU sees its own transfer area as a normal input area in the process image. To expose the data received from the master (the value 100 in the example) as a tag, simply read %IW100 in the slave program. To make the tag available for the master, store it in the input transfer area region (e.g., %QW100 of the slave, which is mapped to the master as an input).
// Slave CPU - OB1 (Structured Text)
// Push a constant 100 into the transfer area so the master can read it.
"ValueToMaster" := 100;
// Tag "ValueToMaster" must be at the address configured as the input transfer area,
// e.g., %QW100 (4 bytes), in the CM 1242-5 I-Slave configuration.
On the master, the previously written DPRD_DAT will read this 4-byte region and the value 100 will appear in SlaveData.InputWord.
Diagnostic and Status Codes
The STATUS output of DPRD_DAT/DPWR_DAT returns a 16-bit value. The most common codes you will see on S7-1200:
| STATUS (hex) | Meaning | Corrective action |
|---|---|---|
| 0000 | Job completed without error | None |
| 7000 | No job active | Trigger REQ to start a new read/write |
| 7001 | First read/write job in progress | Wait for DONE or ERROR
|
| 7002 | Subsequent job in progress | Wait |
| 8090 | LADDR invalid or slave not configured | Check the I/O start address in the master device view |
| 8092 | RECORD pointer exceeds process image | Reduce the data length or move the destination DB |
| 80A1 | DP slave not reachable / bus fault | Check PROFIBUS cable, termination, addresses |
| 80A2 | DP slave not ready / configuration mismatch | Re-download the I-Slave configuration to the slave |
| 80B0 | DP slave reports diagnostics | Read slave diagnostics in online view |
| 80B1 | Configuration data differs from the slave | Recompile and download both stations |
| 80C0 | DP slave not in data exchange | Slave has not yet started cyclic communication; check DP LEDs |
| 80D0 | DP master not in RUN | Place master CPU in RUN; check OB82/OB86 handling |
PROFIBUS module LEDs provide additional clues:
- BF (red, steady): bus fault — cable/termination/addressing issue.
- BF (red, flashing): slave configuration mismatch.
- SF (red): system fault on the CM; check online diagnostics.
- ON (green): the CM is in data exchange with the master.
Troubleshooting Matrix
| Symptom | Likely cause | Fix |
|---|---|---|
| TIA Portal refuses to create S7 connection on PROFIBUS | CM does not support S7 connections | Use I-Slave transfer areas + DPRD_DAT/DPWR_DAT
|
DPRD_DAT STATUS = 80A1 |
Bus fault or wrong address | Verify both ends are terminated, addresses unique, cable polarity |
| STATUS = 80A2 / 80B1 | Configuration mismatch | Re-download the slave's I-Slave configuration; ensure transfer area length matches |
| STATUS = 80B0 | Slave sent diagnostic interrupt | Open "Online & Diagnostics" → DP diagnostics on the slave |
| STATUS = 8090 | LADDR not the configured I/Q start | Use the address shown in the master's device view for the slave slot |
| Value in master is always 0 | Transfer area not written on the slave side | Confirm the slave program writes the tag at the transfer area address |
| PROFIBUS LED BF steady on master | Slave not powered or cable broken | Power the slave, check the bus cable, check terminating resistor |
Alternative: Switch to PROFINET for S7 Communication
If the project permits, replacing the PROFIBUS CMs with a direct PROFINET connection between the two S7-1200 CPUs unlocks the standard PUT/GET/TSEND/TRCV instruction set. In that scenario:
- The S7-1200 PROFINET interface is used for S7 communication.
- No CM is required.
-
PUTandGETare configured via the "Connections" editor against the partner CPU's PROFINET IP address.
For installations with existing PROFIBUS infrastructure (cable, connectors, SCADA interfaces) staying on PROFIBUS and using the I-Slave / DPRD_DAT/DPWR_DAT method is usually the lowest-impact change.
Verification
- Compile and download both stations. The master CPU must be in RUN.
- Open "Online & Diagnostics" on the master CM 1243-5. The "DP master system" view should list the slave at PROFIBUS address 2 with state Data exchange.
- Force
REQon theDPRD_DATinstance. WatchSTATUStransition from7001→0000withDONE= TRUE. - Watch table on the master:
SlaveData.InputWordshould display the value100within one DP cycle. - On the slave, watch table: writing to the output transfer area tag (e.g.,
QW100) should be reflected on the master at the corresponding input address within one cycle. - Disconnect the PROFIBUS cable at one end: the master should report STATUS =
80A1and the CM's BF LED should light. Reconnect: communication resumes within the configured reaction time.
Why does TIA Portal V13 refuse to create an S7 connection on the PROFIBUS CM?
The S7-1200 connection resources are bound to the PROFINET interface of the CPU. The CM 1242-5/CM 1243-5 only provide a DP slave or DP master interface for cyclic I/O, not S7 communication. Use the I-Slave/Master model and DPRD_DAT/DPWR_DAT instead of PUT/GET.
Which Siemens CM module do I need for the master and for the slave?
For the master side, use the CM 1243-5 (article number 6GK7243-5DX30-0XE0). For the slave side, use the CM 1242-5 (6GK7242-5DX30-0XE0). The CM 1243-5 cannot be used as a slave and the CM 1242-5 cannot be used as a master.
How much data can be exchanged per transfer area on the CM 1242-5?
Each I-Slave transfer area on the CM 1242-5 supports up to 32 bytes for inputs and 32 bytes for outputs. If you need more, add additional transfer areas in the I-Slave configuration. The aggregate data must fit within the DP slave's configured slot.
Can I use PUT/GET between two S7-1200 CPUs without changing the hardware?
Yes, but only if both CPUs are connected via PROFINET. The CPUs' built-in PROFINET interface supports S7 connections. If the bus must remain PROFIBUS, you must switch to the DPRD_DAT/DPWR_DAT method described above.
What does STATUS 80A1 mean on DPRD_DAT, and how do I fix it?
STATUS 80A1 indicates that the DP slave is not reachable on the bus. Check the PROFIBUS cable for breaks or swapped A/B wires, confirm the terminating resistor is ON at both ends and OFF in the middle, and verify the slave's PROFIBUS address matches the one assigned in the master's device view.