Overview: S7-1200 to KUKA Robot Communication Architecture
Integrating a Siemens SIMATIC S7-1200 programmable logic controller with a KUKA robot controller requires a deliberate choice of physical layer, protocol, and program block family. The wrong combination produces a working TIA Portal project that never exchanges a single process byte, which is the most common failure pattern observed when migrating from a PROFIBUS-based KRC4 cell to a PROFINET-based S7-1200 machine.
Three legitimate communication paths exist between an S7-1200 and a KUKA KRC4 (or KR C4 compact / extended) robot controller:
- Cyclic PROFINET IO via the CPU's integrated PROFINET interface and a KUKA GSDML file.
- Acyclic PROFINET record-data exchange using the RDREC and WRREC instructions.
- PROFIBUS DP via the CM 1243-5 communication module, using DPRD_DAT and DPWR_DAT for slot-based I/O.
Additionally, if the KUKA application exposes a TCP/IP server (KUKA.EthernetKRL XML or OPC UA), the S7-1200 can use TCON, TSEND, TRCV, and TDISCON for open user communication. Each path is valid; the selection is driven by the robot's available option slot, the existing cabinet wiring, and the data volume.
KUKA Controller Capability Matrix: PROFINET and PROFIBUS Support
KUKA robot controllers distinguish themselves by option package. The base KR C4 (and the later KR C5) controllers do not always ship with PROFINET enabled; the relevant add-on options are KUKA.PROFINET MS (manufacturer-specific, supports the KUKA message channel) and KUKA.PROFINET SN (standard PROFINET IO device). For PROFIBUS, the relevant option is KUKA.PROFIBUS. The following table summarises the support matrix based on KUKA controller documentation and KR C4 option package manuals.
| KUKA Controller | Built-in PROFINET | PROFIBUS DP slave | Required Option Package |
|---|---|---|---|
| KR C2 (legacy) | Optional via CP1616 | Yes (standard) | KUKA.PROFIBUS / KUKA.PROFINET MS |
| KR C4 (standard) | Yes (on-board) | Yes (on-board) | PROFINET IO Device, KUKA.PROFINET MS for acyclic |
| KR C4 compact | Yes (on-board) | Yes (on-board) | Same as KR C4 |
| KR C4 extended | Yes (on-board) | Yes (on-board) | Same as KR C4 |
| KR C5 | Yes (on-board) | Yes (on-board) | KUKA.PROFINET SN or MS, KUKA.PROFIBUS |
The point of this matrix is straightforward: the KRC4 supports both PROFINET and PROFIBUS natively, which means the choice of S7-1200 hardware (CPU-integrated PROFINET versus a CM 1243-5 PROFIBUS module) is driven by the cabinet, the existing field devices, and the engineering team's familiarity — not by a capability limitation of the robot. Confirm the active option packages on the KRC4 by entering $option at the KUKA smartHMI command line; the list must include the protocol option you intend to use.
Hardware Selection: S7-1200 CPU and CM 1243-5 Decision Path
The S7-1200 family (CPU 1211C, 1212C, 1214C, 1215C, 1217C) has an integrated PROFINET interface on the CPU itself. The interface supports PROFINET IO Controller mode with up to 16 IO Devices, depending on firmware. Refer to the S7-1200 Programmable Controller System Manual for the device count and cycle limits of your specific firmware. Common catalog numbers include:
- 6ES7211-1AE40-0XB0 (CPU 1211C DC/DC/DC)
- 6ES7214-1AG40-0XB0 (CPU 1214C DC/DC/DC)
- 6ES7215-1AG40-0XB0 (CPU 1215C DC/DC/DC)
- 6ES7217-1AG40-0XB0 (CPU 1217C DC/DC/DC)
The CM 1243-5 (catalog number 6GK7243-5DX30-0XE0) is a PROFIBUS DP master module that plugs into the left-side communication bus of the S7-1200. It supports DP-V0, DP-V1, and DP-V2, with up to 32 DP slaves per the CM 1243-5 operating instructions. If the cabinet has a PROFIBUS DP backbone and the KUKA robot is on the same segment, the CM 1243-5 is the correct module. If the robot is on PROFINET, the CM 1243-5 is unnecessary hardware.
The decision rule:
- If the robot is on PROFINET, use the CPU's PROFINET port. CM 1243-5 is not required.
- If the robot is on PROFIBUS DP, install CM 1243-5 and configure the KUKA GSD on the DP master.
- If both networks coexist (e.g., legacy PROFIBUS drives plus a newer PROFINET robot), install CM 1243-5 and use the PROFINET port in parallel.
TIA Portal Project Setup and GSDML File Installation
For PROFINET integration, the KUKA robot is configured as a PROFINET IO Device in the S7-1200's Device Configuration. The required step is to import the KUKA GSDML file into TIA Portal. The GSDML is provided by KUKA with the PROFINET option package, typically named something like GSDML-Vx.x-KUKA-KRCPN-yyyymmdd.xml. GSDML versions must match the KRC4 firmware major release; a mismatched GSDML produces slot/length inconsistencies at runtime.
- In the TIA Portal project tree, select Options → Manage general station description files (GSD).
- Browse to the directory containing the GSDML file and install it.
- Restart TIA Portal if prompted.
- Open Devices & Networks and add the KUKA device from the Hardware Catalog (PROFINET IO → ... → KUKA → PROFINET IO Device).
- Drag the KUKA device into the PROFINET subnet and connect it to the S7-1200 CPU's PROFINET interface.
- Assign a unique device name and IP address consistent with the KUKA.WorkVisual project (e.g.,
192.168.1.50for the robot,192.168.1.10for the S7-1200).
For PROFIBUS integration, the equivalent file is a PROFIBUS GSD, typically KUKAxxxx.GSD, imported via the same dialog. The KUKA device is then placed under PROFIBUS DP → ... → KUKA in the Hardware Catalog and connected to the CM 1243-5's DP master subnet.
PROFINET Cyclic I/O Configuration (Recommended Primary Path)
Once the KUKA device is in the project, TIA Portal exposes its slots and submodules. For a KRC4 with the standard PROFINET IO Device option, the typical slot layout is:
| Slot | Submodule | Direction | Default Length |
|---|---|---|---|
| 0 | Device access point (DAP) | — | 0 bytes |
| 1 | Digital inputs (KRC4 → PLC) | Input | 16 / 32 bytes (configurable) |
| 2 | Digital outputs (PLC → KRC4) | Output | 16 / 32 bytes (configurable) |
| 3+ | Optional: KUKA message channel (PROFINET MS only) | Bidirectional | Configurable |
After dragging the input and output submodules into the device, TIA Portal automatically creates the I/O addresses in the process image. For a CPU 1214C, the default addresses are typically the first available input and output words (e.g., %IW0 through %IWn for inputs, %QW0 through %QWn for outputs). The addresses can be reassigned in the device properties.
No additional program blocks are required for cyclic PROFINET I/O. The CPU's PROFINET interface handles the data exchange autonomously. The PLC program simply reads the input words and writes the output words as if they were local I/O:
// Ladder example: start robot program when HMI button is pressed
// "RobotStart" is an HMI tag, %I0.0 is a KRC4 input (e.g., User-Safety-OK)
A "RobotStart"
AN %I0.0 // KRC4 input: user safety OK
S %Q0.0 // KRC4 output: program select bit 0
S %Q0.1 // KRC4 output: program select bit 1
On the KUKA side, the I/O mapping is configured in KUKA.WorkVisual under PROFINET → I/O Mapping. Each PROFINET byte must be mapped to a KRL (KUKA Robot Language) variable or system variable, for example $IN[1]..$IN[32] and $OUT[1]..$OUT[32].
Acyclic PROFINET Data Exchange with RDREC and WRREC
Some applications require read/write of KUKA parameters outside the cyclic refresh — for example, retrieving the current robot position, reading fault counters, or writing production counters. PROFINET record-data exchange handles this via the RDREC and WRREC instructions as documented in the S7-1200 communication function manual.
The instruction signatures for S7-1200 (TIA Portal):
RDREC(
REQ := bStartRead, // BOOL: trigger read
ID := dwIoDeviceId, // DWORD: hardware identifier of the KUKA device
INDEX := dwRecordIndex, // DWORD: record index (KUKA-specific)
MLEN := iMaxLen, // INT: max record length
VALID => bValid, // BOOL: new data valid
BUSY => bBusy, // BOOL: operation in progress
ERROR => bError, // BOOL: error occurred
STATUS => wStatus, // WORD: error/status code
RECORD := pRecordBuffer // VARIANT: destination buffer
);
WRREC(
REQ := bStartWrite, // BOOL: trigger write
ID := dwIoDeviceId, // DWORD: hardware identifier
INDEX := dwRecordIndex, // DWORD: record index
LEN := iDataLen, // INT: length to write
DONE => bDone, // BOOL: write complete
BUSY => bBusy, // BOOL: operation in progress
ERROR => bError, // BOOL: error
STATUS => wStatus, // WORD: error/status code
RECORD := pRecordBuffer // VARIANT: source buffer
);
The hardware identifier is found in the device properties of the KUKA PROFINET device (System constants tab in TIA Portal, prefix Local~PROFINET_interface_...). The record index is KUKA-specific and must be obtained from the KUKA PROFINET option package documentation — typical KUKA record indices include 0x4000..0x4FFF for the message channel when KUKA.PROFINET MS is enabled.
Typical status codes for RDREC/WRREC with a KUKA device:
| STATUS (hex) | Meaning | Recommended Action |
|---|---|---|
| 0000 | No error | Continue |
| 7000 | No job active | Trigger REQ to start |
| 7001 | First call / job running | Wait, do not retrigger |
| 7002 | Subsequent call / job running | Wait |
| 80A0 | Negative acknowledgment, slot invalid | Check INDEX parameter against KUKA record table |
| 80A1 | Negative acknowledgment, type invalid | Verify MLEN/LEN matches KUKA record length |
| 80A2 | Negative acknowledgment, access denied | KUKA option package not licensed or record protected |
| 80A7 | DP slave / IO Device not in data exchange | Check PROFINET connection, device name, cable |
| 80B1 | Index not supported | Wrong record index for this KUKA firmware version |
| 80C3 | Resource unavailable | Reduce concurrent record jobs; check MLEN |
| 80C4 | Communication fault | Check PROFINET diagnostics; verify device is reachable |
PROFIBUS DP Path with CM 1243-5 and DPRD_DAT/DPWR_DAT
If the KUKA robot is on PROFIBUS DP, the CM 1243-5 acts as the DP master and the KUKA controller acts as the DP slave. The integration steps mirror the PROFINET case, but the data exchange uses the slot-based DP instructions DPRD_DAT and DPWR_DAT per the S7-1200 Communication function manual.
Instruction signatures for S7-1200 (PROFIBUS DP, the S7-1200 supports these instructions only when a CM 1243-5 or CP 1242-7 is configured):
DPRD_DAT(
LADDR := wHwAddress, // WORD: hardware address of the KUKA DP slave
RET_VAL := iRetVal, // INT: function return value
RECORD := pReadBuffer // VARIANT: destination
);
DPWR_DAT(
LADDR := wHwAddress, // WORD: hardware address
RECORD := pWriteBuffer, // VARIANT: source
RET_VAL := iRetVal // INT: function return value
);
The hardware address is the PROFIBUS station address (1..125) configured on the CM 1243-5's DP master subnet in TIA Portal. Each DP slave slot configured in the device view produces a contiguous I/O area; the user program accesses it either via the process image (if the slot is configured as direct I/O) or via the DP instructions (if the slot is configured as a slot-based I/O with consistency > 1 byte).
For consistent data blocks larger than 4 bytes (typical for KUKA status words or motion commands), always use DPRD_DAT and DPWR_DAT. The process image is not coherent across more than 4 bytes in PROFIBUS DP and produces data tearing on an S7-1200.
RDREC/WRREC. Using the DP instructions on a PROFINET device produces a compile error in TIA Portal.PROFIBUS DP return value (RET_VAL) error codes, abbreviated:
| RET_VAL (hex) | Meaning | Recommended Action |
|---|---|---|
| 0000 | OK | Continue |
| 7000 | No job | Trigger request |
| 7001 | First call, job active | Wait |
| 7002 | Subsequent call, job active | Wait |
| 8090 | Configured hardware address invalid | Verify LADDR against the configured DP slave station |
| 8092 | Any-pointer / variant error | Check RECORD variant length and type |
| 80A0 | Negative acknowledgment, slot invalid | Check KUKA GSD slot layout |
| 80A1 | Negative acknowledgment, type invalid | Check RECORD length matches KUKA slot length |
| 80A2 | Negative acknowledgment, access denied | Check KUKA DP access rights |
| 80A3 | Negative acknowledgment, DP slave out of memory | Check KUKA option package resources |
| 80A7 | DP slave not in data exchange | Check PROFIBUS wiring, slave address, baud rate |
| 80B0 | DP slave not configured | Check CM 1243-5 configuration, slave must be assigned |
| 80B1 | Slot/index not supported | Check KUKA GSD version |
Open TCP/IP Communication via TCON, TSEND, TRCV, TDISCON
If the KUKA controller exposes a TCP server (for example KUKA.EthernetKRL on port 6000 or an OPC UA server on port 4840), the S7-1200 can communicate as a TCP client using the open user communication instructions. This is the most flexible path but requires application-level protocol handling on the PLC side.
Setup sequence in TIA Portal:
- Open the S7-1200 CPU's properties and add a new connection under Communication → Open User Communication → TCP/IP.
- Configure the local port and the remote port and IP address of the KUKA controller.
- Note the connection ID generated by TIA Portal (e.g., 1).
- Insert
TCONin the program to establish the connection. - Use
TSENDto send a command string (e.g., KRL XML command) andTRCVto receive the response. - Use
TDISCONto release the connection on shutdown.
Minimal ST example (illustrative — validate against the actual KUKA.EthernetKRL documentation):
// Establish connection
TCON(
REQ := bConnectRequest,
ID := 1, // connection ID from TIA Portal
CONNECT := tConnectParams, // TCON_IP_v4 structure
DONE => bConnected,
BUSY => bConnectBusy,
ERROR => bConnectError,
STATUS => wConnectStatus
);
// Send a KRL XML command (read current position)
TSEND(
REQ := bSendRequest,
ID := 1,
LEN := uiSendLen,
DATA := sKukaCommand, // STRING, e.g. '<Request ... />'
DONE => bSendDone,
BUSY => bSendBusy,
ERROR => bSendError,
STATUS => wSendStatus
);
// Receive the response
TRCV(
EN_R := bReceiveEnable,
ID := 1,
LEN := uiRcvMaxLen,
DATA := sKukaResponse,
DONE => bRcvDone,
BUSY => bRcvBusy,
ERROR => bRcvError,
STATUS => wRcvStatus,
RCVD_LEN => uiRcvLen
);
Status codes for TCON/TSEND/TRCV are documented in the S7-1200 Communication Function Manual. The most common field failure is a STATUS of 80C4 (connection error) when the KUKA.EthernetKRL server is not started on the robot, or the KUKA firewall blocks the S7-1200's IP. Verify by pinging the robot from a Windows machine on the same subnet before launching the PLC program.
Legacy Reference: S7-300 KUKA Function Blocks FB197 and FB199
Parallel S7-300 projects sometimes use FB197 and FB199 to talk to a KUKA. These blocks are KUKA-provided, not Siemens library blocks. They are shipped as part of the KUKA.PLC Multiprog project template or the KUKA.EthernetKRL sample code, and they wrap the KRL XML protocol on top of the S7-300's open communication instructions (AG_SEND/AG_RECV or TCON/TSEND/TRCV depending on firmware).
The blocks appear with the names KukaSendReceive (FB197) and KUKA_AUTO_EXT (FB199) in the original S7-300 sample projects distributed by KUKA. They are not present in the S7-1200 TIA Portal library — the S7-1200 project must reimplement the protocol directly, or import the S7-300 source as a migration template. The block signatures and the underlying protocol do not change, but the call interface in TIA Portal does change because the S7-1200 uses the OUC instruction family rather than the AG_SEND/AG_RECV family used on S7-300.
Use them only as a protocol reference, not as drop-in code. The correct path on S7-1200 is to use TCON/TSEND/TRCV as shown above, with the same XML command set on the wire.
HMI Integration: KTP600 Basic Program Number Selection
The KTP600 Basic (catalog 6AV2 123-2MB03-0AX0, with PROFINET interface) connects to the S7-1200 PROFINET port. HMI tags are read/written into the PLC tags, and the S7-1200 program then writes the KUKA's output bytes accordingly. A typical "select program 1..12" sequence:
- Map a WinCC tag
HMI_ProgramSelect(INT, 1..12) to a PLC tag"HMI_ProgramSelect". - In the S7-1200 program, convert the integer to a 4-bit binary code (programs 1..12 fit in 4 bits) and write it to a 2-byte output area mapped to KUKA inputs
$IN[17]..$IN[20](example only; verify against the KUKA mapping table). - Use a separate bit (e.g., $IN[21] from KRC4) as a "request accepted" acknowledgement and a third bit as a "running" flag from the robot.
Configure the WinCC tag in the HMI configuration as a "Mode" IO field with limits 1..12, and connect it to the WinCC tag list. The data flow is HMI → S7-1200 process image → PROFINET output to KUKA → KRL.
Troubleshooting Matrix: Symptoms, Root Causes, Corrections
| Symptom | Probable Root Cause | Diagnostic | Correction |
|---|---|---|---|
| PROFINET device shows "Not reachable" in TIA Portal online | Wrong device name assigned to the KUKA | Use the KUKA.PROFINET MS configuration to confirm device name, or read the device's PROFINET name via Primary Setup Tool (PST) | Assign the correct PROFINET device name from the KUKA.WorkVisual project |
| Inputs are always 0, outputs are not echoed by the robot | Wrong slot configuration in TIA Portal | Compare TIA Portal slot layout with KUKA.WorkVisual I/O mapping | Match submodules exactly; verify the slot length |
| DP slave goes to "Station failure" on CM 1243-5 | Address conflict, wiring error, or terminator missing | Use PROFIBUS diagnostic repeater or oscilloscope; check bus termination | Enable bus terminator on the KRC4 PROFIBUS connector; verify station address 1..125 unique |
| DPRD_DAT/DPWR_DAT returns 80A2 (access denied) | KUKA PROFIBUS option not licensed or record protected | Check KUKA controller for active option packages | Activate the relevant KUKA PROFIBUS option; license with KUKA.Option Key |
| RDREC returns 80B1 (index not supported) | Record index does not exist on the KUKA firmware version | Verify with KUKA PROFINET option manual for the installed firmware | Update KUKA firmware or use the index documented for the installed version |
| TCON returns 80C4 (connection error) | KUKA.EthernetKRL server not started, or firewall blocks S7-1200 | Telnet to the KUKA controller on the configured port; check KUKA firewall rules | Start KUKA.EthernetKRL on the robot; open the port in the KUKA firewall |
| Inputs flickering or showing "1" intermittently when no signal is present | Process image update without KUKA option package enabled | Check KUKA option package list with $option in the KUKA smartHMI | Enable the PROFINET IO Device option on the KRC4 |
| PROFINET IO Device shows "Maintenance required" warning | Diagnostic from KUKA (e.g., warm restart pending) | Read the KUKA PROFINET diagnostic record | Acknowledge on robot side; clear via RDREC index 0x8000 if supported |
Field Commissioning Checklist
- Verify the KUKA option package list with
$optionin the KUKA smartHMI. KUKA.PROFINET SN (or MS) and KUKA.PROFIBUS must be listed as active. - Confirm the physical network. PROFINET uses RJ45 Cat5e or better; PROFIBUS uses 9-pin D-sub with shielded twisted pair (purple cable) and bus terminators at both ends.
- Install the latest GSDML/GSD file from the KUKA option package on a USB stick or shared drive.
- In TIA Portal, import the GSD file, add the KUKA device, configure the IP/device name (PROFINET) or station address (PROFIBUS), and assign the desired submodules/slots.
- Download the hardware configuration to the S7-1200.
- Verify the connection status in TIA Portal online → Devices & Networks → PROFINET/DP diagnostics.
- In the S7-1200 program, add a watch table for the input/output words to confirm data exchange.
- On the KUKA side, configure the I/O mapping in KUKA.WorkVisual and map each PROFINET/DP byte to a KRL variable (e.g., $IN, $OUT, or $FLAG).
- Run a manual jog test in KUKA mode T1 with the cell interlocks enabled, confirming that the I/O bits toggle as expected.
- Document the configured slot layout, the record indices used (if acyclic), and the IP/address plan in the project README.
PROFINET and PROFIBUS specifications are maintained by PROFIBUS Nutzerorganisation (PNO). The relevant IEC standards are IEC 61784-2 (PROFINET) and IEC 61158 (PROFIBUS DP). The canonical Siemens platform reference is the S7-1200 Programmable Controller System Manual, and the canonical KUKA reference is the option package manual delivered with KUKA.PROFINET SN/MS or KUKA.PROFIBUS.
FAQ
Does KUKA support PROFINET?
Yes. KRC4 and KR C5 controllers support PROFINET natively. The PROFINET IO Device option (KUKA.PROFINET SN) is required for cyclic I/O; KUKA.PROFINET MS is required for acyclic message-channel access. Both options can coexist on a single KRC4.
Do I need DPRD_DAT and DPWR_DAT to talk to a KUKA on PROFINET?
No. Those instructions are PROFIBUS DP only. For PROFINET, cyclic data goes through the process image (no extra blocks) and acyclic data goes through RDREC and WRREC. Using the DP instructions on a PROFINET device produces a compile error in TIA Portal.
Is the CM 1243-5 required for an S7-1200 to PROFINET robot?
No. The CM 1243-5 (6GK7243-5DX30-0XE0) is a PROFIBUS DP master module. If the KUKA robot is on PROFINET, the S7-1200 CPU's integrated PROFINET port is sufficient. CM 1243-5 is only needed if a PROFIBUS DP segment is present in the same cell.
What is the difference between RDREC and DPRD_DAT?
RDREC is the PROFINET acyclic record-data read instruction; it uses a hardware identifier and a record index. DPRD_DAT is the PROFIBUS DP consistent-data read instruction; it uses a hardware address. They are not interchangeable and address different protocol layers.
Why does an S7-300 KUKA project use FB197 and FB199?
FB197 (KukaSendReceive) and FB199 (KUKA_AUTO_EXT) are KUKA-provided, not Siemens library blocks. They wrap the KUKA.EthernetKRL XML protocol over the S7-300's open communication instructions. The S7-1200 does not include these blocks; reimplement the protocol with TCON/TSEND/TRCV or use the S7-300 source as a migration reference.