S7-1200 TCP Port 49999 Configuration Beyond the 49151 UI Limit

David Krause12 min read
S7-1200SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem: S7-1200 Cannot Reach a TCP Server on Port 49999

When configuring an S7-1200 CPU to communicate with a third-party TCP device that listens on a fixed, non-standard port (for example a marquee display or status sign bound to port 49999), engineers hit a hard stop inside the TIA Portal configuration UI. The TCP connection dialog of TSEND_C, TRCV_C, and the TCON wizard validates the Local Port and Remote Port fields against a maximum of 49151. The dialog refuses any value greater than 49151 and the project will not compile while the value is out of range. The third-party device port cannot be changed on the field device side, so the controller must adapt.

Field condition: Port 49999 falls inside the IANA "dynamic/private" range (49152-65535). Devices that pick a "fixed" port in this range (marquees, signage controllers, weighing terminals, label printers, RFID readers) are a common source of this limitation.

Root Cause: Input Validation in the Connection Parameter UI

The 49151 ceiling is a TIA Portal front-end input check, not a CPU firmware limit. The underlying S7-1200 PROFINET/Industrial Ethernet stack supports the full TCP/UDP port range 1-65535 on the open user communication instructions (TCON, TSEND, TRCV, TUSEND, TURCV). The wizard exposes only the "registered" port band (1-49151) as selectable because the dynamic/private range is normally assigned by the OS to outbound sockets.

Because the dialog writes the port directly into the connection DB (data block of type TCON_Param), bypassing the dialog and editing the DB yourself unlocks the full range. Once the DB is compiled with a value > 49151, the CPU opens the socket on that exact port without complaint.

Affected Products and Firmware Versions

Component Affected Versions Notes
CPU S7-1200 (all DC/DC/DC, AC/DC/RLY, DC/DC/RLY variants) Firmware V4.0 - V4.7 Open user communication is supported on every S7-1200; TSEND_C/TRCV_C simplify TCON management.
CPU S7-1200 G2 (second generation, e.g. CPU 1212C G2, CPU 1215C G2, CPU 1217C G2) Firmware V5.0+ Same TCON/TSEND/TRCV instruction set; port range is also UI-limited in TIA Portal V20+.
TIA Portal V13 SP1 through V20 Input check is consistent across versions; the workaround applies to all of them.
CM 1243-1 / CP 1243-1 / CP 1243-7 / CP 1243-8 Firmware V3.x Used for external Ethernet interfaces; identical TCON data structure.

Reference: Communication protocols and ports used by Ethernet communication (Siemens SIMATIC S7-1200 Manual Collection, English).

Architecture: How TCON Allocates a Socket on the S7-1200

Every TCP connection on the S7-1200 is described by an instance DB of PLC data type TCON_Param (system UDT). The CPU uses this DB to allocate the socket via the internal PROFINET stack when TCON.REQ is triggered. The RemotePort and LocalPort fields are UINT (16-bit unsigned, 0-65535). Writing a value of 49999 (0xC34F) into either field is fully legal at the data type level - the restriction exists only in the HMI input mask that normally edits those fields.

Offset Name Type Meaning
0.0 BlockLength UINT Length of the connection description (64 bytes).
2.0 Id CONN_OUC (WORD) Connection reference (1-4095), referenced by TSEND/TRCV.
4.0 ConnectionType BYTE 16#0B = TCP, 16#13 = UDP, 16#11 = ISO-on-TCP.
5.0 ActiveEstablished BOOL TRUE = client (S7-1200 opens), FALSE = server (S7-1200 accepts).
6.0 LocalDeviceId BYTE Local interface module identifier (PROFINET interface = 1; CM/CP = its HW ID).
7.0 LocalTsapIdLen BYTE Length of local TSAP (TCP = 0, ISO-on-TCP = 1-16).
8.0 LocalTsapId ARRAY[1..16] of BYTE Local TSAP bytes (unused for plain TCP).
24.0 RemSubnetIdLen BYTE Remote subnet ID length.
25.0 RemSubnetId ARRAY[1..6] of BYTE Remote subnet ID (typically 0 for direct Ethernet).
31.0 RemStaddrLen BYTE Remote IP address length in bytes (4 for IPv4).
32.0 RemStaddr ARRAY[1..6] of BYTE Remote IPv4 address bytes 1-4 (bytes 5-6 = 0).
38.0 RemTsapIdLen BYTE Remote port length (2 for TCP - high byte first).
39.0 RemTsapId ARRAY[1..16] of BYTE Remote port, big-endian: byte 39 = high byte, byte 40 = low byte.
55.0 NextStaddrLen BYTE Local port length (2 for TCP).
56.0 NextStaddr ARRAY[1..6] of BYTE Local port, big-endian: byte 56 = high byte, byte 57 = low byte.
62.0 Spare WORD Reserved.
Big-endian caution: Siemens stores the 16-bit port in network byte order. Port 49999 = 0xC34F. Byte at offset 39 = 0xC3, byte at 40 = 0x4F (remote). For the local port, byte 56 = 0xC3, byte 57 = 0x4F.

Solution 1: Edit the TCON_Param Connection DB Directly

The cleanest method is to keep the standard TIA Portal connection wizard (so PROFINET diagnostics still recognize the connection) and only edit the raw byte values inside the generated instance DB.

  1. Insert a new TSEND_C or TRCV_C block in the program. In the configuration dialog, set Connection type = TCP, Active connection establishment = TRUE (S7-1200 initiates), and enter Remote Port = 49999 and Local Port = 0 (auto-assign) or any free port below 49151 for the initial compile.
  2. Click Generate to create the instance DB. Note the DB name (for example InstTSEND_C_DB).
  3. Open the generated DB, switch the view to All, and locate the static variable of type TCON_Param (typically named TCON_Param_1 or visible as the id, ConnectionType... structure starting at offset 0).
  4. Modify the port fields. For RemotePort (offset 39/40), enter 0xC3 at offset 39 and 0x4F at offset 40. For LocalPort (offset 56/57), enter 0xC3 / 0x4F to bind locally to 49999, or 0x00 / 0x00 to let the OS pick.
  5. Disable the watch tables for these bytes if needed - TIA Portal sometimes resets byte values to zero on re-edit. Lock the values with ATTR = "Read-only in HMI" or write them at runtime via a MOVE block (see Solution 2).
  6. Compile. TIA Portal will emit a non-fatal warning ("Port number outside the permissible range") but the project builds successfully because the type check on UINT accepts the value.
  7. Download to the CPU. Trigger TCON.REQ. The CPU opens the TCP socket on port 49999 and the marquee responds.

Solution 2: Runtime Override with a MOVE Block

If the engineer is not comfortable editing raw DB bytes, or if TIA Portal refuses the offline value at compile time on certain versions, force the port at runtime by copying a constant into the TCON DB before each TCON call.

Ladder logic - FB boundary:

Network 1 - Force remote port before TCON
      "InstTSEND_C".TCON_Param_1.RemTsapId[1]  :=  16#C3;   // high byte
      "InstTSEND_C".TCON_Param_1.RemTsapId[2]  :=  16#4F;   // low byte
      "InstTSEND_C".TCON_Param_1.RemTsapIdLen :=  B#16#2;

Network 2 - Trigger connection
      "Tag_TCON_REQ"  :=  TRUE;             // set for one scan via edge
      "InstTSEND_C".REQ   :=  "Tag_TCON_REQ";

SCL equivalent:

// Patch port 49999 (0xC34F) into the TCON DB before requesting the connection
"InstTSEND_C".TCON_Param_1.RemTsapId[1] := 16#C3;
"InstTSEND_C".TCON_Param_1.RemTsapId[2] := 16#4F;
"InstTSEND_C".TCON_Param_1.RemTsapIdLen := 2;
IF "FirstScan" THEN
  "InstTSEND_C".REQ := TRUE;
END_IF;

Place the MOVE (or direct byte assignment in SCL) immediately before TCON in every OB1 cycle. The byte write happens before the CPU reads the connection description, so the socket is always opened on the patched port.

Edge-trigger the REQ: TCON is edge-sensitive. A rising edge on REQ allocates the socket; a falling edge closes it. Drive REQ with a one-shot from R_TRIG or a startup tag to avoid tearing the connection down each cycle.

Solution 3: Manual TCON/TSEND/TRCV Split (No Wizard)

Engineers who want full control - or whose TIA Portal version refuses to compile any port above 49151 even as a DB value - can drop TSEND_C/TRCV_C entirely and call the legacy instructions directly.

Instruction Purpose Key inputs
TCON Open TCP connection on the configured port REQ (BOOL), ID (WORD, 1-4095), CONNECT (VARIANT pointing to TCON_Param DB)
TSEND Send a data buffer REQ, ID, LEN, DATA
TRCV Receive a data buffer EN_R, ID, LEN, DATA, ADHOC (TRUE = any length)
TDISCON Close TCP connection cleanly REQ, ID

Steps:

  1. Create a new global DB DB_Marquee with one variable of PLC data type TCON_Param named connParams. This bypasses the wizard entirely - no UI range check.
  2. Set BlockLength = 64, Id = 1, ConnectionType = 16#0B, ActiveEstablished = TRUE, LocalDeviceId = 1 (PROFINET interface), RemStaddrLen = 4.
  3. Fill RemStaddr[1..4] with the marquee IP (for example 192.168.0.50 becomes 192, 168, 0, 50).
  4. Fill RemTsapId: byte 1 = 16#C3, byte 2 = 16#4F (port 49999 big-endian). RemTsapIdLen = 2.
  5. Fill NextStaddr for the local port if you need a fixed source port: byte 1 = 16#C3, byte 2 = 16#4F. NextStaddrLen = 2. Use 0/0 to let the OS auto-assign.
  6. Call TCON(REQ := startPulse, ID := 1, CONNECT := "DB_Marquee".connParams).
  7. Once DONE = TRUE, send data via TSEND; receive via TRCV with ADHOC = TRUE for variable-length marquee responses.

Verification Procedure

  1. Open Online & Diagnostics on the S7-1200, navigate to Diagnostics > ProDiag / Connection overview or use a watch table on the TCON instance. Confirm DONE = TRUE and ERROR = FALSE / STATUS = 16#0000.
  2. From a Windows PC on the same subnet, run netstat -an | findstr 49999. The S7-1200 IP should appear with ESTABLISHED against port 49999 on the marquee IP. A SYN_SENT or CLOSE_WAIT state indicates the CPU opened the socket but the marquee never accepted - check firewall, IP, and that the device is in server mode.
  3. Send a known marquee payload (ASCII text or vendor protocol frame) via TSEND. Use a tap like Wireshark with port filter tcp.port == 49999 to confirm the bytes leave the CPU and the device acknowledges.
  4. Check STATUS after TSEND: 16#7000 = busy, 16#7002 = done, 16#8085 / 16#80A1 = connection fault. See the S7-1200 system manual, section "Status codes of TSEND/TRCV" for the full table.
  5. Use the marquee vendor's test utility (often a Windows TCP client) and point it at the S7-1200 IP on port 49999. If the CPU is the server side (ActiveEstablished = FALSE), the utility should see the listening socket immediately.

Troubleshooting Matrix

Symptom Likely cause Remedy
TCON ERROR = TRUE, STATUS = 16#8085 Local port already in use or invalid Set NextStaddrLen = 0 (auto) or pick a unique port; verify no other connection in the project uses 49999 as local.
STATUS = 16#80A1 Remote partner not responding (no SYN-ACK) Ping the marquee IP; check VLAN/subnet mask; confirm firewall rule on PC and any managed switch ACL.
STATUS = 16#80C3 / 16#80C4 Temporary resource shortage on CPU Reduce concurrent connections; S7-1200 supports up to 8 open user communication connections per PN interface.
TIA Portal refuses to compile, error "port out of range" Compiler validation on the wizard-managed DB Switch to the manual TCON/TSEND/TRCV split (Solution 3) - the global DB does not go through the wizard.
Connection opens but no data received TRCV ADHOC = FALSE and LEN mismatch, or no terminating character Set ADHOC = TRUE for variable-length frames; check marquee protocol - some require a poll/ACK handshake before streaming data.
Bytes overwritten on each download TIA Portal regenerates the TCON DB Always patch the bytes at runtime with MOVE (Solution 2) so they survive every recompile.
Port 49999 collides with Windows ephemeral assignment PC application grabs 49999 before the CPU does Bind the S7-1200 side with LocalPort = 49999 (NextStaddr = C3/4F) so the socket is reserved regardless of PC activity.

Design Considerations and Constraints

  • Connection count: The S7-1200 PROFINET interface supports up to 8 open user communication connections simultaneously. Each TSEND_C/TRCV_C consumes one. Above 8, the CPU returns STATUS 16#80C3.
  • Firmware floor: Open user communication has been available since the first S7-1200 firmware. TCON/TSEND/TRCV were extended with ADHOC receive and UDP variants in V4.0; the G2 generation (V5.0+) does not change the instruction semantics.
  • Watch out for collations: If the project also uses OPC UA on the CPU, mind the local port - OPC UA server default is 4840. Keep TCON local ports distinct from system services.
  • Security: Disabling the port ceiling in TIA Portal does not disable any runtime firewall. The S7-1200 CPU (V4.4+) supports a built-in firewall with connection rules; add a rule permitting remote IP/port 49999 if security is enabled.
  • Determinism: TCP retransmits and the marquee's server-side response time are non-deterministic. For sub-100 ms control loops, consider UDP (TUSEND/TURCV, ConnectionType = 16#13) on the same port range instead of TCP.
  • Diagnostic visibility: ProDiag in TIA Portal V17+ can supervise TCON/TSEND/TRCV status changes natively. Add a ProDiag FB to surface ERROR transitions in the HMI.

When to Use Which Instruction

Block pair Best for Notes
TSEND_C + TRCV_C One TCP partner, simple request/response Wizard-managed; one shared connection DB; easiest to patch the port bytes.
TCON + TSEND + TRCV (manual) Multiple parallel connections, full control, server mode No wizard validation; lets you set any port cleanly via a global DB.
TUSEND + TURCV Fire-and-forget broadcasts, low latency, no handshake ConnectionType = 16#13; same port-range issue applies but no server-side accept needed.
MB_CLIENT / MB_SERVER Modbus TCP devices Hardcoded port 502; not the right tool for port 49999.

Related Configuration: PROFINET Interface Diagnostics

If the marquee also exposes a web UI on another port (80, 443, 8080), use the CPU's Online & Diagnostics > PROFINET interface > Port statistics view to verify the physical link and check for CRC errors that would silently drop TCP segments. The official SIMATIC S7-1200 System Manual describes how to enable the Web server (default port 80) for diagnostics: S7-1200 Manual Collection - Communication.

Why does TIA Portal block port 49999 in the TCP configuration dialog?

The dialog validates user input against the IANA "registered" port band (1-49151). The S7-1200 CPU firmware itself supports the full 1-65535 range on TCON, TSEND, TRCV, TUSEND, and TURCV. Bypass the dialog by editing the connection DB directly or by writing the port bytes at runtime with a MOVE block.

Can I just enter 49999 and compile, ignoring the warning?

On TIA Portal V13 SP1 through V20 the wizard refuses values > 49151 and the project will not compile. The TCON_Param DB generated by the wizard does, however, accept UINT values up to 65535 - so the project compiles successfully if the wizard is bypassed (manual TCON/TSEND/TRCV with a global DB) or if the DB bytes are patched post-generation.

Does the workaround require a specific S7-1200 firmware version?

No. Open user communication has shipped since the first S7-1200 firmware. The MOVE-to-TCON_Param technique and the manual TCON/TSEND/TRCV split work on V4.0 through V5.x without changes. If you also need ProDiag supervision of the connection, use TIA Portal V17 or later.

How do I verify the S7-1200 actually opened port 49999?

Use Online & Diagnostics > Connection overview on the CPU, or run netstat -an | findstr 49999 from a Windows PC on the same subnet. The S7-1200 should appear with state ESTABLISHED against the marquee IP. Wireshark with filter tcp.port == 49999 shows the three-way handshake and payload.

What happens if another device on the network also binds port 49999?

TCON returns STATUS 16#8085 (port already in use or address parameter error) and the connection is not opened. Change the S7-1200 local port to a free value below 49151 (the dynamic range is fine on the local side) and keep the remote port at 49999 - that is the typical configuration for talking to a fixed-port server.

Back to blog