Problem: S7-1200 Cannot Reach a TCP Server on Port 49999
When configuring an S7-1200 CPU to communicate with a third-party TCP device that listens on a fixed, non-standard port (for example a marquee display or status sign bound to port 49999), engineers hit a hard stop inside the TIA Portal configuration UI. The TCP connection dialog of TSEND_C, TRCV_C, and the TCON wizard validates the Local Port and Remote Port fields against a maximum of 49151. The dialog refuses any value greater than 49151 and the project will not compile while the value is out of range. The third-party device port cannot be changed on the field device side, so the controller must adapt.
Root Cause: Input Validation in the Connection Parameter UI
The 49151 ceiling is a TIA Portal front-end input check, not a CPU firmware limit. The underlying S7-1200 PROFINET/Industrial Ethernet stack supports the full TCP/UDP port range 1-65535 on the open user communication instructions (TCON, TSEND, TRCV, TUSEND, TURCV). The wizard exposes only the "registered" port band (1-49151) as selectable because the dynamic/private range is normally assigned by the OS to outbound sockets.
Because the dialog writes the port directly into the connection DB (data block of type TCON_Param), bypassing the dialog and editing the DB yourself unlocks the full range. Once the DB is compiled with a value > 49151, the CPU opens the socket on that exact port without complaint.
Affected Products and Firmware Versions
| Component | Affected Versions | Notes |
|---|---|---|
| CPU S7-1200 (all DC/DC/DC, AC/DC/RLY, DC/DC/RLY variants) | Firmware V4.0 - V4.7 | Open user communication is supported on every S7-1200; TSEND_C/TRCV_C simplify TCON management. |
| CPU S7-1200 G2 (second generation, e.g. CPU 1212C G2, CPU 1215C G2, CPU 1217C G2) | Firmware V5.0+ | Same TCON/TSEND/TRCV instruction set; port range is also UI-limited in TIA Portal V20+. |
| TIA Portal | V13 SP1 through V20 | Input check is consistent across versions; the workaround applies to all of them. |
| CM 1243-1 / CP 1243-1 / CP 1243-7 / CP 1243-8 | Firmware V3.x | Used for external Ethernet interfaces; identical TCON data structure. |
Reference: Communication protocols and ports used by Ethernet communication (Siemens SIMATIC S7-1200 Manual Collection, English).
Architecture: How TCON Allocates a Socket on the S7-1200
Every TCP connection on the S7-1200 is described by an instance DB of PLC data type TCON_Param (system UDT). The CPU uses this DB to allocate the socket via the internal PROFINET stack when TCON.REQ is triggered. The RemotePort and LocalPort fields are UINT (16-bit unsigned, 0-65535). Writing a value of 49999 (0xC34F) into either field is fully legal at the data type level - the restriction exists only in the HMI input mask that normally edits those fields.
| Offset | Name | Type | Meaning |
|---|---|---|---|
| 0.0 | BlockLength | UINT | Length of the connection description (64 bytes). |
| 2.0 | Id | CONN_OUC (WORD) | Connection reference (1-4095), referenced by TSEND/TRCV. |
| 4.0 | ConnectionType | BYTE | 16#0B = TCP, 16#13 = UDP, 16#11 = ISO-on-TCP. |
| 5.0 | ActiveEstablished | BOOL | TRUE = client (S7-1200 opens), FALSE = server (S7-1200 accepts). |
| 6.0 | LocalDeviceId | BYTE | Local interface module identifier (PROFINET interface = 1; CM/CP = its HW ID). |
| 7.0 | LocalTsapIdLen | BYTE | Length of local TSAP (TCP = 0, ISO-on-TCP = 1-16). |
| 8.0 | LocalTsapId | ARRAY[1..16] of BYTE | Local TSAP bytes (unused for plain TCP). |
| 24.0 | RemSubnetIdLen | BYTE | Remote subnet ID length. |
| 25.0 | RemSubnetId | ARRAY[1..6] of BYTE | Remote subnet ID (typically 0 for direct Ethernet). |
| 31.0 | RemStaddrLen | BYTE | Remote IP address length in bytes (4 for IPv4). |
| 32.0 | RemStaddr | ARRAY[1..6] of BYTE | Remote IPv4 address bytes 1-4 (bytes 5-6 = 0). |
| 38.0 | RemTsapIdLen | BYTE | Remote port length (2 for TCP - high byte first). |
| 39.0 | RemTsapId | ARRAY[1..16] of BYTE | Remote port, big-endian: byte 39 = high byte, byte 40 = low byte. |
| 55.0 | NextStaddrLen | BYTE | Local port length (2 for TCP). |
| 56.0 | NextStaddr | ARRAY[1..6] of BYTE | Local port, big-endian: byte 56 = high byte, byte 57 = low byte. |
| 62.0 | Spare | WORD | Reserved. |
Solution 1: Edit the TCON_Param Connection DB Directly
The cleanest method is to keep the standard TIA Portal connection wizard (so PROFINET diagnostics still recognize the connection) and only edit the raw byte values inside the generated instance DB.
- Insert a new TSEND_C or TRCV_C block in the program. In the configuration dialog, set Connection type = TCP, Active connection establishment = TRUE (S7-1200 initiates), and enter Remote Port = 49999 and Local Port = 0 (auto-assign) or any free port below 49151 for the initial compile.
- Click Generate to create the instance DB. Note the DB name (for example
InstTSEND_C_DB). - Open the generated DB, switch the view to All, and locate the static variable of type
TCON_Param(typically namedTCON_Param_1or visible as the id, ConnectionType... structure starting at offset 0). - Modify the port fields. For RemotePort (offset 39/40), enter 0xC3 at offset 39 and 0x4F at offset 40. For LocalPort (offset 56/57), enter 0xC3 / 0x4F to bind locally to 49999, or 0x00 / 0x00 to let the OS pick.
- Disable the watch tables for these bytes if needed - TIA Portal sometimes resets byte values to zero on re-edit. Lock the values with
ATTR= "Read-only in HMI" or write them at runtime via aMOVEblock (see Solution 2). - Compile. TIA Portal will emit a non-fatal warning ("Port number outside the permissible range") but the project builds successfully because the type check on
UINTaccepts the value. - Download to the CPU. Trigger
TCON.REQ. The CPU opens the TCP socket on port 49999 and the marquee responds.
Solution 2: Runtime Override with a MOVE Block
If the engineer is not comfortable editing raw DB bytes, or if TIA Portal refuses the offline value at compile time on certain versions, force the port at runtime by copying a constant into the TCON DB before each TCON call.
Ladder logic - FB boundary:
Network 1 - Force remote port before TCON
"InstTSEND_C".TCON_Param_1.RemTsapId[1] := 16#C3; // high byte
"InstTSEND_C".TCON_Param_1.RemTsapId[2] := 16#4F; // low byte
"InstTSEND_C".TCON_Param_1.RemTsapIdLen := B#16#2;
Network 2 - Trigger connection
"Tag_TCON_REQ" := TRUE; // set for one scan via edge
"InstTSEND_C".REQ := "Tag_TCON_REQ";
SCL equivalent:
// Patch port 49999 (0xC34F) into the TCON DB before requesting the connection
"InstTSEND_C".TCON_Param_1.RemTsapId[1] := 16#C3;
"InstTSEND_C".TCON_Param_1.RemTsapId[2] := 16#4F;
"InstTSEND_C".TCON_Param_1.RemTsapIdLen := 2;
IF "FirstScan" THEN
"InstTSEND_C".REQ := TRUE;
END_IF;
Place the MOVE (or direct byte assignment in SCL) immediately before TCON in every OB1 cycle. The byte write happens before the CPU reads the connection description, so the socket is always opened on the patched port.
TCON is edge-sensitive. A rising edge on REQ allocates the socket; a falling edge closes it. Drive REQ with a one-shot from R_TRIG or a startup tag to avoid tearing the connection down each cycle.Solution 3: Manual TCON/TSEND/TRCV Split (No Wizard)
Engineers who want full control - or whose TIA Portal version refuses to compile any port above 49151 even as a DB value - can drop TSEND_C/TRCV_C entirely and call the legacy instructions directly.
| Instruction | Purpose | Key inputs |
|---|---|---|
TCON |
Open TCP connection on the configured port | REQ (BOOL), ID (WORD, 1-4095), CONNECT (VARIANT pointing to TCON_Param DB) |
TSEND |
Send a data buffer | REQ, ID, LEN, DATA |
TRCV |
Receive a data buffer | EN_R, ID, LEN, DATA, ADHOC (TRUE = any length) |
TDISCON |
Close TCP connection cleanly | REQ, ID |
Steps:
- Create a new global DB
DB_Marqueewith one variable of PLC data typeTCON_ParamnamedconnParams. This bypasses the wizard entirely - no UI range check. - Set
BlockLength= 64,Id= 1,ConnectionType= 16#0B,ActiveEstablished= TRUE,LocalDeviceId= 1 (PROFINET interface),RemStaddrLen= 4. - Fill
RemStaddr[1..4]with the marquee IP (for example 192.168.0.50 becomes 192, 168, 0, 50). - Fill
RemTsapId: byte 1 = 16#C3, byte 2 = 16#4F (port 49999 big-endian).RemTsapIdLen= 2. - Fill
NextStaddrfor the local port if you need a fixed source port: byte 1 = 16#C3, byte 2 = 16#4F.NextStaddrLen= 2. Use 0/0 to let the OS auto-assign. - Call
TCON(REQ := startPulse, ID := 1, CONNECT := "DB_Marquee".connParams). - Once
DONE= TRUE, send data viaTSEND; receive viaTRCVwithADHOC= TRUE for variable-length marquee responses.
Verification Procedure
- Open Online & Diagnostics on the S7-1200, navigate to Diagnostics > ProDiag / Connection overview or use a watch table on the
TCONinstance. ConfirmDONE= TRUE andERROR= FALSE /STATUS= 16#0000. - From a Windows PC on the same subnet, run
netstat -an | findstr 49999. The S7-1200 IP should appear withESTABLISHEDagainst port 49999 on the marquee IP. ASYN_SENTorCLOSE_WAITstate indicates the CPU opened the socket but the marquee never accepted - check firewall, IP, and that the device is in server mode. - Send a known marquee payload (ASCII text or vendor protocol frame) via
TSEND. Use a tap like Wireshark with port filtertcp.port == 49999to confirm the bytes leave the CPU and the device acknowledges. - Check
STATUSafterTSEND: 16#7000 = busy, 16#7002 = done, 16#8085 / 16#80A1 = connection fault. See the S7-1200 system manual, section "Status codes of TSEND/TRCV" for the full table. - Use the marquee vendor's test utility (often a Windows TCP client) and point it at the S7-1200 IP on port 49999. If the CPU is the server side (
ActiveEstablished= FALSE), the utility should see the listening socket immediately.
Troubleshooting Matrix
| Symptom | Likely cause | Remedy |
|---|---|---|
| TCON ERROR = TRUE, STATUS = 16#8085 | Local port already in use or invalid | Set NextStaddrLen = 0 (auto) or pick a unique port; verify no other connection in the project uses 49999 as local. |
| STATUS = 16#80A1 | Remote partner not responding (no SYN-ACK) | Ping the marquee IP; check VLAN/subnet mask; confirm firewall rule on PC and any managed switch ACL. |
| STATUS = 16#80C3 / 16#80C4 | Temporary resource shortage on CPU | Reduce concurrent connections; S7-1200 supports up to 8 open user communication connections per PN interface. |
| TIA Portal refuses to compile, error "port out of range" | Compiler validation on the wizard-managed DB | Switch to the manual TCON/TSEND/TRCV split (Solution 3) - the global DB does not go through the wizard. |
| Connection opens but no data received | TRCV ADHOC = FALSE and LEN mismatch, or no terminating character | Set ADHOC = TRUE for variable-length frames; check marquee protocol - some require a poll/ACK handshake before streaming data. |
| Bytes overwritten on each download | TIA Portal regenerates the TCON DB | Always patch the bytes at runtime with MOVE (Solution 2) so they survive every recompile. |
| Port 49999 collides with Windows ephemeral assignment | PC application grabs 49999 before the CPU does | Bind the S7-1200 side with LocalPort = 49999 (NextStaddr = C3/4F) so the socket is reserved regardless of PC activity. |
Design Considerations and Constraints
- Connection count: The S7-1200 PROFINET interface supports up to 8 open user communication connections simultaneously. Each TSEND_C/TRCV_C consumes one. Above 8, the CPU returns STATUS 16#80C3.
- Firmware floor: Open user communication has been available since the first S7-1200 firmware. TCON/TSEND/TRCV were extended with ADHOC receive and UDP variants in V4.0; the G2 generation (V5.0+) does not change the instruction semantics.
- Watch out for collations: If the project also uses OPC UA on the CPU, mind the local port - OPC UA server default is 4840. Keep TCON local ports distinct from system services.
- Security: Disabling the port ceiling in TIA Portal does not disable any runtime firewall. The S7-1200 CPU (V4.4+) supports a built-in firewall with connection rules; add a rule permitting remote IP/port 49999 if security is enabled.
-
Determinism: TCP retransmits and the marquee's server-side response time are non-deterministic. For sub-100 ms control loops, consider UDP (
TUSEND/TURCV, ConnectionType = 16#13) on the same port range instead of TCP. - Diagnostic visibility: ProDiag in TIA Portal V17+ can supervise TCON/TSEND/TRCV status changes natively. Add a ProDiag FB to surface ERROR transitions in the HMI.
When to Use Which Instruction
| Block pair | Best for | Notes |
|---|---|---|
| TSEND_C + TRCV_C | One TCP partner, simple request/response | Wizard-managed; one shared connection DB; easiest to patch the port bytes. |
| TCON + TSEND + TRCV (manual) | Multiple parallel connections, full control, server mode | No wizard validation; lets you set any port cleanly via a global DB. |
| TUSEND + TURCV | Fire-and-forget broadcasts, low latency, no handshake | ConnectionType = 16#13; same port-range issue applies but no server-side accept needed. |
| MB_CLIENT / MB_SERVER | Modbus TCP devices | Hardcoded port 502; not the right tool for port 49999. |
Related Configuration: PROFINET Interface Diagnostics
If the marquee also exposes a web UI on another port (80, 443, 8080), use the CPU's Online & Diagnostics > PROFINET interface > Port statistics view to verify the physical link and check for CRC errors that would silently drop TCP segments. The official SIMATIC S7-1200 System Manual describes how to enable the Web server (default port 80) for diagnostics: S7-1200 Manual Collection - Communication.
Why does TIA Portal block port 49999 in the TCP configuration dialog?
The dialog validates user input against the IANA "registered" port band (1-49151). The S7-1200 CPU firmware itself supports the full 1-65535 range on TCON, TSEND, TRCV, TUSEND, and TURCV. Bypass the dialog by editing the connection DB directly or by writing the port bytes at runtime with a MOVE block.
Can I just enter 49999 and compile, ignoring the warning?
On TIA Portal V13 SP1 through V20 the wizard refuses values > 49151 and the project will not compile. The TCON_Param DB generated by the wizard does, however, accept UINT values up to 65535 - so the project compiles successfully if the wizard is bypassed (manual TCON/TSEND/TRCV with a global DB) or if the DB bytes are patched post-generation.
Does the workaround require a specific S7-1200 firmware version?
No. Open user communication has shipped since the first S7-1200 firmware. The MOVE-to-TCON_Param technique and the manual TCON/TSEND/TRCV split work on V4.0 through V5.x without changes. If you also need ProDiag supervision of the connection, use TIA Portal V17 or later.
How do I verify the S7-1200 actually opened port 49999?
Use Online & Diagnostics > Connection overview on the CPU, or run netstat -an | findstr 49999 from a Windows PC on the same subnet. The S7-1200 should appear with state ESTABLISHED against the marquee IP. Wireshark with filter tcp.port == 49999 shows the three-way handshake and payload.
What happens if another device on the network also binds port 49999?
TCON returns STATUS 16#8085 (port already in use or address parameter error) and the connection is not opened. Change the S7-1200 local port to a free value below 49151 (the dynamic range is fine on the local side) and keep the remote port at 49999 - that is the typical configuration for talking to a fixed-port server.