S7-1200 PROFINET Communication with KUKA KRC4 Robot Controllers

David Krause18 min read
Industrial NetworkingSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: S7-1200 to KUKA Robot Communication Architecture

Integrating a Siemens SIMATIC S7-1200 programmable logic controller with a KUKA robot controller requires a deliberate choice of physical layer, protocol, and program block family. The wrong combination produces a working TIA Portal project that never exchanges a single process byte, which is the most common failure pattern observed when migrating from a PROFIBUS-based KRC4 cell to a PROFINET-based S7-1200 machine.

Three legitimate communication paths exist between an S7-1200 and a KUKA KRC4 (or KR C4 compact / extended) robot controller:

  1. Cyclic PROFINET IO via the CPU's integrated PROFINET interface and a KUKA GSDML file.
  2. Acyclic PROFINET record-data exchange using the RDREC and WRREC instructions.
  3. PROFIBUS DP via the CM 1243-5 communication module, using DPRD_DAT and DPWR_DAT for slot-based I/O.

Additionally, if the KUKA application exposes a TCP/IP server (KUKA.EthernetKRL XML or OPC UA), the S7-1200 can use TCON, TSEND, TRCV, and TDISCON for open user communication. Each path is valid; the selection is driven by the robot's available option slot, the existing cabinet wiring, and the data volume.

KUKA Controller Capability Matrix: PROFINET and PROFIBUS Support

KUKA robot controllers distinguish themselves by option package. The base KR C4 (and the later KR C5) controllers do not always ship with PROFINET enabled; the relevant add-on options are KUKA.PROFINET MS (manufacturer-specific, supports the KUKA message channel) and KUKA.PROFINET SN (standard PROFINET IO device). For PROFIBUS, the relevant option is KUKA.PROFIBUS. The following table summarises the support matrix based on KUKA controller documentation and KR C4 option package manuals.

KUKA Controller Built-in PROFINET PROFIBUS DP slave Required Option Package
KR C2 (legacy) Optional via CP1616 Yes (standard) KUKA.PROFIBUS / KUKA.PROFINET MS
KR C4 (standard) Yes (on-board) Yes (on-board) PROFINET IO Device, KUKA.PROFINET MS for acyclic
KR C4 compact Yes (on-board) Yes (on-board) Same as KR C4
KR C4 extended Yes (on-board) Yes (on-board) Same as KR C4
KR C5 Yes (on-board) Yes (on-board) KUKA.PROFINET SN or MS, KUKA.PROFIBUS
If a KRC2 cell is being integrated (for example a cell with an installed CP1616 PCIe card), confirm that the KUKA.WorkVisual project has the PROFINET device stack activated. The CP1616 must be configured as a PROFINET IO Device, not as a controller.

The point of this matrix is straightforward: the KRC4 supports both PROFINET and PROFIBUS natively, which means the choice of S7-1200 hardware (CPU-integrated PROFINET versus a CM 1243-5 PROFIBUS module) is driven by the cabinet, the existing field devices, and the engineering team's familiarity — not by a capability limitation of the robot. Confirm the active option packages on the KRC4 by entering $option at the KUKA smartHMI command line; the list must include the protocol option you intend to use.

Hardware Selection: S7-1200 CPU and CM 1243-5 Decision Path

The S7-1200 family (CPU 1211C, 1212C, 1214C, 1215C, 1217C) has an integrated PROFINET interface on the CPU itself. The interface supports PROFINET IO Controller mode with up to 16 IO Devices, depending on firmware. Refer to the S7-1200 Programmable Controller System Manual for the device count and cycle limits of your specific firmware. Common catalog numbers include:

  • 6ES7211-1AE40-0XB0 (CPU 1211C DC/DC/DC)
  • 6ES7214-1AG40-0XB0 (CPU 1214C DC/DC/DC)
  • 6ES7215-1AG40-0XB0 (CPU 1215C DC/DC/DC)
  • 6ES7217-1AG40-0XB0 (CPU 1217C DC/DC/DC)

The CM 1243-5 (catalog number 6GK7243-5DX30-0XE0) is a PROFIBUS DP master module that plugs into the left-side communication bus of the S7-1200. It supports DP-V0, DP-V1, and DP-V2, with up to 32 DP slaves per the CM 1243-5 operating instructions. If the cabinet has a PROFIBUS DP backbone and the KUKA robot is on the same segment, the CM 1243-5 is the correct module. If the robot is on PROFINET, the CM 1243-5 is unnecessary hardware.

A common field failure pattern: an S7-1200 cabinet is delivered with a CM 1243-5 populated and the robot is wired PROFINET. The CM 1243-5 ends up unused, but the S7-1200 PROFINET interface is correctly used for the robot. The two are not exclusive — the S7-1200 can simultaneously use its PROFINET interface and a CM 1243-5 if the cell genuinely mixes both networks. They simply should not be confused as alternatives to the same job.

The decision rule:

  • If the robot is on PROFINET, use the CPU's PROFINET port. CM 1243-5 is not required.
  • If the robot is on PROFIBUS DP, install CM 1243-5 and configure the KUKA GSD on the DP master.
  • If both networks coexist (e.g., legacy PROFIBUS drives plus a newer PROFINET robot), install CM 1243-5 and use the PROFINET port in parallel.

TIA Portal Project Setup and GSDML File Installation

For PROFINET integration, the KUKA robot is configured as a PROFINET IO Device in the S7-1200's Device Configuration. The required step is to import the KUKA GSDML file into TIA Portal. The GSDML is provided by KUKA with the PROFINET option package, typically named something like GSDML-Vx.x-KUKA-KRCPN-yyyymmdd.xml. GSDML versions must match the KRC4 firmware major release; a mismatched GSDML produces slot/length inconsistencies at runtime.

  1. In the TIA Portal project tree, select Options → Manage general station description files (GSD).
  2. Browse to the directory containing the GSDML file and install it.
  3. Restart TIA Portal if prompted.
  4. Open Devices & Networks and add the KUKA device from the Hardware Catalog (PROFINET IO → ... → KUKA → PROFINET IO Device).
  5. Drag the KUKA device into the PROFINET subnet and connect it to the S7-1200 CPU's PROFINET interface.
  6. Assign a unique device name and IP address consistent with the KUKA.WorkVisual project (e.g., 192.168.1.50 for the robot, 192.168.1.10 for the S7-1200).

For PROFIBUS integration, the equivalent file is a PROFIBUS GSD, typically KUKAxxxx.GSD, imported via the same dialog. The KUKA device is then placed under PROFIBUS DP → ... → KUKA in the Hardware Catalog and connected to the CM 1243-5's DP master subnet.

TIA Portal V13 is end-of-life. Modern TIA Portal versions (V16 and later) are recommended for new projects. The device configuration steps remain conceptually identical, but the menu paths in V13 differ from V18+. If upgrading, also re-import the GSDML into the new TIA Portal version.

PROFINET Cyclic I/O Configuration (Recommended Primary Path)

Once the KUKA device is in the project, TIA Portal exposes its slots and submodules. For a KRC4 with the standard PROFINET IO Device option, the typical slot layout is:

Slot Submodule Direction Default Length
0 Device access point (DAP) — 0 bytes
1 Digital inputs (KRC4 → PLC) Input 16 / 32 bytes (configurable)
2 Digital outputs (PLC → KRC4) Output 16 / 32 bytes (configurable)
3+ Optional: KUKA message channel (PROFINET MS only) Bidirectional Configurable

After dragging the input and output submodules into the device, TIA Portal automatically creates the I/O addresses in the process image. For a CPU 1214C, the default addresses are typically the first available input and output words (e.g., %IW0 through %IWn for inputs, %QW0 through %QWn for outputs). The addresses can be reassigned in the device properties.

No additional program blocks are required for cyclic PROFINET I/O. The CPU's PROFINET interface handles the data exchange autonomously. The PLC program simply reads the input words and writes the output words as if they were local I/O:

// Ladder example: start robot program when HMI button is pressed
// "RobotStart" is an HMI tag, %I0.0 is a KRC4 input (e.g., User-Safety-OK)
A  "RobotStart"
AN %I0.0        // KRC4 input: user safety OK
S  %Q0.0        // KRC4 output: program select bit 0
S  %Q0.1        // KRC4 output: program select bit 1

On the KUKA side, the I/O mapping is configured in KUKA.WorkVisual under PROFINET → I/O Mapping. Each PROFINET byte must be mapped to a KRL (KUKA Robot Language) variable or system variable, for example $IN[1]..$IN[32] and $OUT[1]..$OUT[32].

Acyclic PROFINET Data Exchange with RDREC and WRREC

Some applications require read/write of KUKA parameters outside the cyclic refresh — for example, retrieving the current robot position, reading fault counters, or writing production counters. PROFINET record-data exchange handles this via the RDREC and WRREC instructions as documented in the S7-1200 communication function manual.

The instruction signatures for S7-1200 (TIA Portal):

RDREC(
    REQ     := bStartRead,            // BOOL: trigger read
    ID      := dwIoDeviceId,         // DWORD: hardware identifier of the KUKA device
    INDEX   := dwRecordIndex,        // DWORD: record index (KUKA-specific)
    MLEN    := iMaxLen,              // INT: max record length
    VALID   => bValid,               // BOOL: new data valid
    BUSY    => bBusy,                // BOOL: operation in progress
    ERROR   => bError,               // BOOL: error occurred
    STATUS  => wStatus,              // WORD: error/status code
    RECORD  := pRecordBuffer         // VARIANT: destination buffer
);

WRREC(
    REQ     := bStartWrite,          // BOOL: trigger write
    ID      := dwIoDeviceId,         // DWORD: hardware identifier
    INDEX   := dwRecordIndex,        // DWORD: record index
    LEN     := iDataLen,             // INT: length to write
    DONE    => bDone,                // BOOL: write complete
    BUSY    => bBusy,                // BOOL: operation in progress
    ERROR   => bError,               // BOOL: error
    STATUS  => wStatus,              // WORD: error/status code
    RECORD  := pRecordBuffer         // VARIANT: source buffer
);

The hardware identifier is found in the device properties of the KUKA PROFINET device (System constants tab in TIA Portal, prefix Local~PROFINET_interface_...). The record index is KUKA-specific and must be obtained from the KUKA PROFINET option package documentation — typical KUKA record indices include 0x4000..0x4FFF for the message channel when KUKA.PROFINET MS is enabled.

RDREC and WRREC are not interchangeable with DPRD_DAT/DPWR_DAT. The record-data instructions operate on PROFINET slot/index addressing and use a different error model. Mixing them with PROFIBUS DP blocks produces a build error in TIA Portal or a runtime error 0x80C3 (record not available).

Typical status codes for RDREC/WRREC with a KUKA device:

STATUS (hex) Meaning Recommended Action
0000 No error Continue
7000 No job active Trigger REQ to start
7001 First call / job running Wait, do not retrigger
7002 Subsequent call / job running Wait
80A0 Negative acknowledgment, slot invalid Check INDEX parameter against KUKA record table
80A1 Negative acknowledgment, type invalid Verify MLEN/LEN matches KUKA record length
80A2 Negative acknowledgment, access denied KUKA option package not licensed or record protected
80A7 DP slave / IO Device not in data exchange Check PROFINET connection, device name, cable
80B1 Index not supported Wrong record index for this KUKA firmware version
80C3 Resource unavailable Reduce concurrent record jobs; check MLEN
80C4 Communication fault Check PROFINET diagnostics; verify device is reachable

PROFIBUS DP Path with CM 1243-5 and DPRD_DAT/DPWR_DAT

If the KUKA robot is on PROFIBUS DP, the CM 1243-5 acts as the DP master and the KUKA controller acts as the DP slave. The integration steps mirror the PROFINET case, but the data exchange uses the slot-based DP instructions DPRD_DAT and DPWR_DAT per the S7-1200 Communication function manual.

Instruction signatures for S7-1200 (PROFIBUS DP, the S7-1200 supports these instructions only when a CM 1243-5 or CP 1242-7 is configured):

DPRD_DAT(
    LADDR   := wHwAddress,           // WORD: hardware address of the KUKA DP slave
    RET_VAL := iRetVal,              // INT: function return value
    RECORD  := pReadBuffer           // VARIANT: destination
);

DPWR_DAT(
    LADDR   := wHwAddress,           // WORD: hardware address
    RECORD  := pWriteBuffer,         // VARIANT: source
    RET_VAL := iRetVal               // INT: function return value
);

The hardware address is the PROFIBUS station address (1..125) configured on the CM 1243-5's DP master subnet in TIA Portal. Each DP slave slot configured in the device view produces a contiguous I/O area; the user program accesses it either via the process image (if the slot is configured as direct I/O) or via the DP instructions (if the slot is configured as a slot-based I/O with consistency > 1 byte).

For consistent data blocks larger than 4 bytes (typical for KUKA status words or motion commands), always use DPRD_DAT and DPWR_DAT. The process image is not coherent across more than 4 bytes in PROFIBUS DP and produces data tearing on an S7-1200.

DPRD_DAT and DPWR_DAT are PROFIBUS-DP-specific. On PROFINET, cyclic data goes through the process image and acyclic data goes through RDREC/WRREC. Using the DP instructions on a PROFINET device produces a compile error in TIA Portal.

PROFIBUS DP return value (RET_VAL) error codes, abbreviated:

RET_VAL (hex) Meaning Recommended Action
0000 OK Continue
7000 No job Trigger request
7001 First call, job active Wait
7002 Subsequent call, job active Wait
8090 Configured hardware address invalid Verify LADDR against the configured DP slave station
8092 Any-pointer / variant error Check RECORD variant length and type
80A0 Negative acknowledgment, slot invalid Check KUKA GSD slot layout
80A1 Negative acknowledgment, type invalid Check RECORD length matches KUKA slot length
80A2 Negative acknowledgment, access denied Check KUKA DP access rights
80A3 Negative acknowledgment, DP slave out of memory Check KUKA option package resources
80A7 DP slave not in data exchange Check PROFIBUS wiring, slave address, baud rate
80B0 DP slave not configured Check CM 1243-5 configuration, slave must be assigned
80B1 Slot/index not supported Check KUKA GSD version

Open TCP/IP Communication via TCON, TSEND, TRCV, TDISCON

If the KUKA controller exposes a TCP server (for example KUKA.EthernetKRL on port 6000 or an OPC UA server on port 4840), the S7-1200 can communicate as a TCP client using the open user communication instructions. This is the most flexible path but requires application-level protocol handling on the PLC side.

Setup sequence in TIA Portal:

  1. Open the S7-1200 CPU's properties and add a new connection under Communication → Open User Communication → TCP/IP.
  2. Configure the local port and the remote port and IP address of the KUKA controller.
  3. Note the connection ID generated by TIA Portal (e.g., 1).
  4. Insert TCON in the program to establish the connection.
  5. Use TSEND to send a command string (e.g., KRL XML command) and TRCV to receive the response.
  6. Use TDISCON to release the connection on shutdown.

Minimal ST example (illustrative — validate against the actual KUKA.EthernetKRL documentation):

// Establish connection
TCON(
    REQ        := bConnectRequest,
    ID         := 1,                 // connection ID from TIA Portal
    CONNECT    := tConnectParams,    // TCON_IP_v4 structure
    DONE       => bConnected,
    BUSY       => bConnectBusy,
    ERROR      => bConnectError,
    STATUS     => wConnectStatus
);

// Send a KRL XML command (read current position)
TSEND(
    REQ        := bSendRequest,
    ID         := 1,
    LEN        := uiSendLen,
    DATA       := sKukaCommand,      // STRING, e.g. '<Request ... />'
    DONE       => bSendDone,
    BUSY       => bSendBusy,
    ERROR      => bSendError,
    STATUS     => wSendStatus
);

// Receive the response
TRCV(
    EN_R       := bReceiveEnable,
    ID         := 1,
    LEN        := uiRcvMaxLen,
    DATA       := sKukaResponse,
    DONE       => bRcvDone,
    BUSY       => bRcvBusy,
    ERROR      => bRcvError,
    STATUS     => wRcvStatus,
    RCVD_LEN   => uiRcvLen
);

Status codes for TCON/TSEND/TRCV are documented in the S7-1200 Communication Function Manual. The most common field failure is a STATUS of 80C4 (connection error) when the KUKA.EthernetKRL server is not started on the robot, or the KUKA firewall blocks the S7-1200's IP. Verify by pinging the robot from a Windows machine on the same subnet before launching the PLC program.

Open user communication is a poor choice if the cell requires deterministic cycle times. The PROFIBUS DP and PROFINET IO paths guarantee deterministic refresh based on the configured send clock (PROFINET) or baud rate (PROFIBUS). TCP/IP is best effort and not suitable for safety-critical motion interlocks. Use PROFINET for cycle work and reserve TCP/IP for diagnostics or recipe download.

Legacy Reference: S7-300 KUKA Function Blocks FB197 and FB199

Parallel S7-300 projects sometimes use FB197 and FB199 to talk to a KUKA. These blocks are KUKA-provided, not Siemens library blocks. They are shipped as part of the KUKA.PLC Multiprog project template or the KUKA.EthernetKRL sample code, and they wrap the KRL XML protocol on top of the S7-300's open communication instructions (AG_SEND/AG_RECV or TCON/TSEND/TRCV depending on firmware).

The blocks appear with the names KukaSendReceive (FB197) and KUKA_AUTO_EXT (FB199) in the original S7-300 sample projects distributed by KUKA. They are not present in the S7-1200 TIA Portal library — the S7-1200 project must reimplement the protocol directly, or import the S7-300 source as a migration template. The block signatures and the underlying protocol do not change, but the call interface in TIA Portal does change because the S7-1200 uses the OUC instruction family rather than the AG_SEND/AG_RECV family used on S7-300.

Use them only as a protocol reference, not as drop-in code. The correct path on S7-1200 is to use TCON/TSEND/TRCV as shown above, with the same XML command set on the wire.

HMI Integration: KTP600 Basic Program Number Selection

The KTP600 Basic (catalog 6AV2 123-2MB03-0AX0, with PROFINET interface) connects to the S7-1200 PROFINET port. HMI tags are read/written into the PLC tags, and the S7-1200 program then writes the KUKA's output bytes accordingly. A typical "select program 1..12" sequence:

  1. Map a WinCC tag HMI_ProgramSelect (INT, 1..12) to a PLC tag "HMI_ProgramSelect".
  2. In the S7-1200 program, convert the integer to a 4-bit binary code (programs 1..12 fit in 4 bits) and write it to a 2-byte output area mapped to KUKA inputs $IN[17]..$IN[20] (example only; verify against the KUKA mapping table).
  3. Use a separate bit (e.g., $IN[21] from KRC4) as a "request accepted" acknowledgement and a third bit as a "running" flag from the robot.

Configure the WinCC tag in the HMI configuration as a "Mode" IO field with limits 1..12, and connect it to the WinCC tag list. The data flow is HMI → S7-1200 process image → PROFINET output to KUKA → KRL.

Troubleshooting Matrix: Symptoms, Root Causes, Corrections

Symptom Probable Root Cause Diagnostic Correction
PROFINET device shows "Not reachable" in TIA Portal online Wrong device name assigned to the KUKA Use the KUKA.PROFINET MS configuration to confirm device name, or read the device's PROFINET name via Primary Setup Tool (PST) Assign the correct PROFINET device name from the KUKA.WorkVisual project
Inputs are always 0, outputs are not echoed by the robot Wrong slot configuration in TIA Portal Compare TIA Portal slot layout with KUKA.WorkVisual I/O mapping Match submodules exactly; verify the slot length
DP slave goes to "Station failure" on CM 1243-5 Address conflict, wiring error, or terminator missing Use PROFIBUS diagnostic repeater or oscilloscope; check bus termination Enable bus terminator on the KRC4 PROFIBUS connector; verify station address 1..125 unique
DPRD_DAT/DPWR_DAT returns 80A2 (access denied) KUKA PROFIBUS option not licensed or record protected Check KUKA controller for active option packages Activate the relevant KUKA PROFIBUS option; license with KUKA.Option Key
RDREC returns 80B1 (index not supported) Record index does not exist on the KUKA firmware version Verify with KUKA PROFINET option manual for the installed firmware Update KUKA firmware or use the index documented for the installed version
TCON returns 80C4 (connection error) KUKA.EthernetKRL server not started, or firewall blocks S7-1200 Telnet to the KUKA controller on the configured port; check KUKA firewall rules Start KUKA.EthernetKRL on the robot; open the port in the KUKA firewall
Inputs flickering or showing "1" intermittently when no signal is present Process image update without KUKA option package enabled Check KUKA option package list with $option in the KUKA smartHMI Enable the PROFINET IO Device option on the KRC4
PROFINET IO Device shows "Maintenance required" warning Diagnostic from KUKA (e.g., warm restart pending) Read the KUKA PROFINET diagnostic record Acknowledge on robot side; clear via RDREC index 0x8000 if supported

Field Commissioning Checklist

  1. Verify the KUKA option package list with $option in the KUKA smartHMI. KUKA.PROFINET SN (or MS) and KUKA.PROFIBUS must be listed as active.
  2. Confirm the physical network. PROFINET uses RJ45 Cat5e or better; PROFIBUS uses 9-pin D-sub with shielded twisted pair (purple cable) and bus terminators at both ends.
  3. Install the latest GSDML/GSD file from the KUKA option package on a USB stick or shared drive.
  4. In TIA Portal, import the GSD file, add the KUKA device, configure the IP/device name (PROFINET) or station address (PROFIBUS), and assign the desired submodules/slots.
  5. Download the hardware configuration to the S7-1200.
  6. Verify the connection status in TIA Portal online → Devices & Networks → PROFINET/DP diagnostics.
  7. In the S7-1200 program, add a watch table for the input/output words to confirm data exchange.
  8. On the KUKA side, configure the I/O mapping in KUKA.WorkVisual and map each PROFINET/DP byte to a KRL variable (e.g., $IN, $OUT, or $FLAG).
  9. Run a manual jog test in KUKA mode T1 with the cell interlocks enabled, confirming that the I/O bits toggle as expected.
  10. Document the configured slot layout, the record indices used (if acyclic), and the IP/address plan in the project README.

PROFINET and PROFIBUS specifications are maintained by PROFIBUS Nutzerorganisation (PNO). The relevant IEC standards are IEC 61784-2 (PROFINET) and IEC 61158 (PROFIBUS DP). The canonical Siemens platform reference is the S7-1200 Programmable Controller System Manual, and the canonical KUKA reference is the option package manual delivered with KUKA.PROFINET SN/MS or KUKA.PROFIBUS.

FAQ

Does KUKA support PROFINET?

Yes. KRC4 and KR C5 controllers support PROFINET natively. The PROFINET IO Device option (KUKA.PROFINET SN) is required for cyclic I/O; KUKA.PROFINET MS is required for acyclic message-channel access. Both options can coexist on a single KRC4.

Do I need DPRD_DAT and DPWR_DAT to talk to a KUKA on PROFINET?

No. Those instructions are PROFIBUS DP only. For PROFINET, cyclic data goes through the process image (no extra blocks) and acyclic data goes through RDREC and WRREC. Using the DP instructions on a PROFINET device produces a compile error in TIA Portal.

Is the CM 1243-5 required for an S7-1200 to PROFINET robot?

No. The CM 1243-5 (6GK7243-5DX30-0XE0) is a PROFIBUS DP master module. If the KUKA robot is on PROFINET, the S7-1200 CPU's integrated PROFINET port is sufficient. CM 1243-5 is only needed if a PROFIBUS DP segment is present in the same cell.

What is the difference between RDREC and DPRD_DAT?

RDREC is the PROFINET acyclic record-data read instruction; it uses a hardware identifier and a record index. DPRD_DAT is the PROFIBUS DP consistent-data read instruction; it uses a hardware address. They are not interchangeable and address different protocol layers.

Why does an S7-300 KUKA project use FB197 and FB199?

FB197 (KukaSendReceive) and FB199 (KUKA_AUTO_EXT) are KUKA-provided, not Siemens library blocks. They wrap the KUKA.EthernetKRL XML protocol over the S7-300's open communication instructions. The S7-1200 does not include these blocks; reimplement the protocol with TCON/TSEND/TRCV or use the S7-300 source as a migration reference.

Back to blog