S7-200 GPS Tuner Setup via PC/PPI Cable and MAS 41 Library

David Krause19 min read
S7-200SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Connecting a GPS receiver to a SIMATIC S7-200 CPU through the PC/PPI programming cable is a recurring integration task in mobile machinery, marine automation, fleet telemetry, and time-synchronized control. Siemens packages the canonical reference wiring and code as Micro Automation Set 41 (MAS 41) — "GPS Synchronization of SIMATIC S7-200" (order code 6ES7841-0AA00-0YA0), a free library of function blocks that parses NMEA 0183 sentences on the S7-200's freeport UART. The physical layer, however, is where most field failures originate: a typical GPS tuner (e.g. NL303P, u-blox-class) emits RS-232-level NMEA strings that cannot be read by the S7-200's RS-485 PPI port directly, and the legacy RS-232 PC/PPI cable (6ES7 901-3BF20-0XA0) draws its transceiver power from a host PC's PS/2 keyboard port — a source that delivers roughly 3.3 V on modern machines and zero volts on machines without a PS/2 connector. This reference documents the exact cable pinout, the missing 5 V problem, dip-switch selection, NL303P wiring, and the Set 41 parameter block configuration required to recover from a fault where the S7-200 status table shows all zeros for every NMEA field.

Prerequisites

Verify the following components before commissioning:

  • SIMATIC S7-200 CPU — any CPU 21x or 22x. The reference build uses CPU 224XP DC/DC/DC 6ES7 214-2AD23-0XB0, which exposes two RS-485 ports (Port 0 = PPI/freeport, Port 1 = freeport/USS).
  • Siemens PC/PPI cable — RS-232 variant 6ES7 901-3BF20-0XA0 (with the PS/2 tap) or USB variant 6ES7 901-3DB30-0XA0 (USB-powered, no PS/2 power problem).
  • GPS tuner with NMEA 0183 RS-232 output — e.g. Navilock NL-303P (u-blox 6 engine), or any module defaulting to 4800 bps, 8 data bits, no parity, 1 stop bit.
  • Siemens Set 41 library — "GPS Synchronization of SIMATIC S7-200", order code 6ES7841-0AA00-0YA0, available from the Siemens Industry Online Support portal. Delivered as a self-extracting archive containing GPS_SYNC.LIB and a STEP 7 Micro/WIN example project.
  • STEP 7 Micro/WIN V4.0 or later (matching the CPU 22x firmware family).
  • 5 V DC source — e.g. a Siemens LOGO! Power 5 V/3 A (6EP3310-1SH03) or a 7805 linear regulator fed from the S7-200 backplane 24 V DC.
  • PS/2 power injector (a short custom harness) or a 5 V tap soldered to pin 4 of the PS/2 connector on the PC/PPI cable.
The RS-232 PC/PPI cable includes a permanently-attached 6-pin mini-DIN (PS/2) plug on the DB9 housing. The original design drew +5 V from a PC keyboard port to power the cable's isolated DC/DC converter and RS-485 transceiver. Modern PCs supply approximately +3.3 V on the PS/2 +5 V line, and machines without a PS/2 port supply 0 V. In both cases the PPI/Freeport transceiver is starved, the PPI LED stays dark, and the S7-200 receives no NMEA characters.

Hardware Architecture and PC/PPI Cable Pinout

The PC/PPI cable is a passive RS-232 to RS-485 translator built around an isolated DC/DC converter and a Siemens-specific PPI ASIC. Three connector faces are relevant to the integrator:

  • PC side — DB9 female (RS-232): TXD on pin 3, RXD on pin 2, RTS on pin 7, CTS on pin 8, signal ground on pin 5. The cable does not draw operating power from the RS-232 port; it is self-powered from the PS/2 tap.
  • PS/2 tap — 6-pin mini-DIN male: pin 1 = keyboard data, pin 3 = ground, pin 4 = +5 V VCC, pin 5 = mouse data, pins 2 and 6 unused. The cable only uses pin 4 (+5 V) and pin 3 (GND); the data lines are mechanically present but not bonded.
  • PLC side — DB9 male (RS-485 PPI): pin 3 = Data B, pin 8 = Data A, pin 5 = signal ground, pin 2 and pin 7 = +24 V (carried through from the S7-200 sensor power, not used by the cable). Pins 4 and 9 are shield/termination in some cable revisions.

The PC/PPI cable presents an RS-485 differential pair on the PLC side; it does not accept RS-232 levels. A GPS tuner's NMEA output (typically ±5 V to ±9 V swing on a DB9 or 3-wire pigtail) must therefore be converted to RS-485 before it can be presented to the cable. Three integration topologies are accepted by Set 41:

  1. External RS-232 → RS-485 converter (e.g. Phoenix Contact PSM-ME-RS232/RS485-P, Advantech ADAM-4520, or Moxa TCC-80) inserted between the GPS tuner and the PC/PPI cable. This is the standard MAS 41 reference topology and provides 2 kV isolation between the GPS module and the PLC port.
  2. Direct differential wiring using a passive level shifter (e.g. MAX3232 + MAX485 pair) integrated into a custom OEM harness. The integrator is responsible for EMI, ground loops, and surge protection.
  3. USB PC/PPI cable (6ES7 901-3DB30-0XA0) connected to a USB-to-RS232 adapter at the GPS tuner end, removing the PS/2 power problem entirely and presenting a standard COM port to the S7-200 side via a 9-wire null-modem. This is the recommended path for new installations.
Topology PS/2 Power Required Isolation Field-Proven Use Case
External RS-232→RS-485 converter + RS-232 PC/PPI cable Yes (5 V tap required) Converter-dependent (typ. 2 kV) Reference MAS 41 design
Custom MAX3232/MAX485 harness + RS-232 PC/PPI cable Yes (5 V tap required) None unless added OEM embedded
USB PC/PPI cable + USB-RS232 adapter on GPS No (USB-powered) USB-side only New installations, retrofit

The 5 V PS/2 Power Problem

The PC/PPI cable's PS/2 tap is its only source of operating power. When the host PC's PS/2 port delivers 5 V (legacy desktop), the cable's isolated DC/DC converter starts, the RS-485 transceiver comes up, and the PPI LED illuminates green. When the host PC supplies less than approximately 4.5 V (modern desktops with 3.3 V PS/2 rails, laptops with no PS/2 port, USB-PS/2 adapters that omit the +5 V wire), the converter either fails to start or runs in a marginal brown-out region. The symptoms are consistent:

  • PPI LED on the cable does not illuminate or pulses weakly.
  • No TX/RX flash on the cable's diagnostic LED when the S7-200 polls the GPS tuner.
  • The S7-200 variable table reports all zeros for every NMEA field that Set 41 exposes (latitude, longitude, UTC time, fix quality, satellite count).
  • STEP 7 Micro/WIN's "Information → PPI/Modbus Error Counters" register shows zero good frames, but this is because Set 41 uses freeport mode (transparent ASCII) and does not increment the standard PPI counters.

To confirm the diagnosis, measure the voltage between pin 4 (+5 V) and pin 3 (GND) of the PS/2 plug with the cable plugged into the PC. A reading of 4.75 V to 5.25 V indicates a healthy PS/2 source. A reading of 3.0 V to 3.6 V indicates a modern PC with a 3.3 V PS/2 rail. A reading near 0 V indicates no PS/2 port or a USB-PS/2 adapter that drops the +5 V wire.

A common field error is to test the cable with a multimeter across the PS/2 +5 V pin and conclude that the cable is faulty when the host PC is the actual cause. Always measure with the PS/2 plug fully inserted into the PC and the PC powered on.

PS/2 5 V Fix Circuits

Three proven remedies restore the 5 V rail. Choose the one that matches your mechanical constraints.

Option A — Tap the S7-200 backplane 24 V and regulate with 7805

The S7-200 backplane supplies +24 V DC at the sensor power terminals (e.g. CPU 224 XP sensor outputs 1M / 2L). Feed this 24 V through a 7805 linear regulator with the standard input capacitor (0.33 µF) and output capacitor (0.1 µF) to produce a stable 5 V. The reference circuit:

24 V DC ---[ 0.33 uF ]--- 7805 Vin --- 7805 Vout ---[ 0.1 uF ]--- +5 V to PS/2 pin 4
                                  |                                |
                                  +----------- PS/2 pin 3 (GND) ----+

Add a 1N4001 flyback diode across the 7805 input-to-output if the cable is hot-plugged, and a small heatsink if the 24 V source is at the upper end of the tolerance band (the 7805 will dissipate approximately 1.4 W at 24 V → 5 V at 75 mA load).

Option B — Siemens LOGO! Power 5 V module

The Siemens LOGO! Power 5 V/3 A (6EP3310-1SH03) is a DIN-rail switching power supply designed for the LOGO! logic module, and its 5 V output can be wired directly to the PS/2 +5 V pin. Use a regulated cable with a 2-pin Dupont or JST-PH connector to land the +5 V and GND on the PS/2 plug. This is the approach the source installation used, with a 7805 stabilizer providing the secondary regulation.

Option C — USB-to-PS/2 adapter with active +5 V

Some industrial PS/2-to-USB adapters include an active +5 V regulator on the PS/2 side and can be used as a 5 V source in their own right. Verify with a multimeter before relying on this in production.

Do not back-feed +5 V from the S7-200's logic-power rail into the PS/2 tap. The PC/PPI cable's isolated DC/DC converter and the S7-200's 5 V rail are not designed to share a common return through the PS/2 cable shield, and ground loops will inject noise into the NMEA reception.

PC/PPI Cable DIP-Switch Configuration for Freeport 4800 bps

The PC/PPI cable carries a 5-position DIP switch behind the DB9 housing. Switches 1 and 2 select the operating mode; switches 3, 4, and 5 select the baud rate. The default factory setting is PPI mode at 19.2 kbps (1 = ON, 2 = OFF, 3 = OFF, 4 = ON, 5 = OFF). For Set 41 GPS reception at 4800 bps, freeport mode is required because NMEA 0183 is a transparent ASCII stream, not a PPI frame.

Switch Function Position for Set 41 GPS
1 Mode select ON (PPI) for programming the CPU; OFF (freeport) for the GPS side
2 Local/Remote echo OFF (echo disabled)
3 Baud rate, bit 0 ON
4 Baud rate, bit 1 OFF
5 Baud rate, bit 2 ON

The switch 3/4/5 combination above yields 4800 bps, the de-facto default for u-blox 6 and most NMEA 0183 GPS tuners. If the GPS module is configured for 9600 bps (a common u-blox 7 default), set switches 3 = ON, 4 = OFF, 5 = OFF for 9600 bps. For 38400 bps (u-blox 8 / 9 high-speed), use 3 = OFF, 4 = ON, 5 = OFF. Always cross-check the baud rate against the active PRT message emitted by the GPS module before commissioning.

The DIP switches set the baud rate of the RS-485 side of the cable (the PLC side). The RS-232 side of the cable (the PC side) is not affected by the DIP switches when the cable is connected to STEP 7 Micro/WIN, which auto-detects the cable's PPI rate from the firmware. Always match the DIP-switch baud rate to the GPS tuner's NMEA output rate, not to the STEP 7 Micro/WIN programming rate.

MAS 41 Set 41 Library Architecture

Set 41 (MAS 41 GPS Synchronization) ships a single library, GPS_SYNC.LIB, with four primary function blocks and a configuration data block. The blocks operate entirely in freeport mode; they do not require PPI masters or slaves. The block set (per the MAS 41 documentation, chapter 5.3.2 table 5-5):

Block Type Purpose
GPS_INIT FB Initializes the S7-200 freeport UART, configures baud rate, parity, and interrupt vectors. Called once on first scan.
GPS_RECV FB Receives characters via the freeport receive interrupt (interrupt event 8 for Port 0, event 25 for Port 1) and assembles a complete NMEA sentence into a buffer.
GPS_PARSE FB Parses the NMEA sentence in the buffer, validates the checksum, and extracts fields into a structured data block (GGA, RMC, GSA, GST, ZDA).
GPS_TIME FB Optional block that synchronizes the S7-200 clock (READ_RTC / SET_RTC) to the GPS UTC time at a configurable interval.
GPS_DATA DB Shared data block containing the parsed position, fix, and time fields exposed to user code.

The default data block exposes the following user-visible fields (offsets relative to DB base). Specific offsets should be verified against the active library build:

Symbol Type Description
FixValid BOOL 1 = valid GPS fix, 0 = no fix or invalid checksum
Latitude REAL Decimal degrees, positive = North
Longitude REAL Decimal degrees, positive = East
Altitude REAL Meters above mean sea level
UTC_Time DWORD Seconds since 00:00:00 UTC
UTC_Date DWORD Days since 1980-01-01 (DOS epoch)
SatCount INT Number of satellites in the fix
HDOP REAL Horizontal dilution of precision

The example project in MAS 41 initializes FixValid = 0 by default and all numerical fields to 0.0. A persistent all-zero state in the user variable table is the canonical symptom of either (a) the PS/2 power fault, (b) a baud-rate mismatch between the GPS tuner and the freeport UART, or (c) a TX/RX wiring swap. The "0" symptom reported in the field is therefore expected on a healthy download; the diagnostic task is to identify which of the three causes is in effect by watching whether the values change over time.

NL303P and u-blox-Class GPS Tuner Wiring

The Navilock NL-303P is a representative u-blox 6-class active antenna module. It exposes a 6-pin JST-PH connector with the following pinout:

JST-PH Pin Signal Direction Notes
1 VCC Input 3.3 V to 5.0 V DC; the NL-303P has an on-board LDO that accepts either
2 TX (NMEA out) Output RS-232 levels (±5 V minimum) on modules that include the on-board level translator; TTL (0/VCC) on bare u-blox modules
3 RX (NMEA in) Input RS-232 input, used to send configuration commands (e.g. u-blox u-center)
4 GND — Common return for VCC and signal
5 1PPS Output 1 pulse per second, 3.3 V CMOS, 100 ms wide — can be routed to a digital input on the S7-200 for time synchronization if SET_RTC is not used
6 n/c — Reserved

On the NL-303P specifically, the on-board MAX3232 RS-232 transceiver is present, so the TX line swings between approximately +5.5 V and −5.5 V. This is incompatible with the S7-200's RS-485 PPI port on Port 0/1; it must be converted through an external RS-232 → RS-485 converter as described in the topology table above. Connecting the NL-303P TX line directly to the S7-200 Port 0 pin 3 (Data B) or pin 8 (Data A) will damage neither device but will produce all zeros in the variable table because the level is not differential.

u-center configuration commands for a default NL-303P at 4800 bps, 8N1, GGA+RMC output once per second (sent over the JST-PH RX pin from a u-blox u-center host):

PRT (Port):     Protocol = NMEA, Baudrate = 4800, Databits = 8, Parity = None, Stopbits = 1
MSG (Messages): Enable 01-01 (GGA), 01-03 (GSA), 01-05 (VTG), 01-07 (ZDA) for Set 41
RATE:           Measurement period = 1000 ms, Navigation rate = 1 Hz

Send the configuration to the NL-303P over the JST-PH RX pin and SAVE it to BBR (battery-backed RAM) or FLASH with the CFG-CFG message so the module powers up in the desired state after a cold start.

Step-by-Step Commissioning

  1. Confirm the PS/2 voltage on the host PC with a multimeter between pin 4 and pin 3 of the PS/2 plug, with the plug inserted and the PC powered on. A reading below 4.5 V confirms the power fault; install the 5 V fix circuit from the previous section.
  2. Set the PC/PPI DIP switches to freeport mode at 4800 bps per the table above. Re-insert the cable into the PLC port. The PPI LED should now illuminate green.
  3. Power the NL-303P from a 3.3 V or 5 V source on the S7-200 backplane (or an external supply). Verify the PPS LED on the NL-303P is blinking once per second — this confirms the GPS engine is running and the antenna has a clear view of the sky.
  4. Route the NL-303P TX line through the RS-232 → RS-485 converter. Connect the converter's RS-485 A/B outputs to the S7-200 Port 0 pins 8 and 3 respectively. Connect the converter's RS-232 input to the NL-303P TX pin.
  5. Install the Set 41 library in STEP 7 Micro/WIN: File → Library Add/Remove → locate GPS_SYNC.LIB from the MAS 41 archive. Open the example project GPS_SYNC_EXAMPLE.mwp and download it to the CPU.
  6. Configure GPS_INIT for the correct port and baud rate. The default is Port 0, 4800 bps, 8N1. If you have a single S7-200 port, use Port 0 and program via the USB PC/PPI cable. If you use Port 1, configure accordingly.
  7. Watch the variable table in STEP 7 Micro/WIN: open VAT_1 (or the example project's default VAT) and add FixValid, Latitude, Longitude, SatCount. After approximately 5 to 30 seconds under open sky, SatCount should rise from 0 to 4 or higher and FixValid should toggle to 1.
  8. Verify the PPS path (optional): if the S7-200 is using GPS_TIME to synchronize its internal RTC, watch the SET_RTC_OK flag flip to 1 within 1 second of the next PPS edge.

Troubleshooting Matrix

Symptom Likely Cause Diagnostic Fix
All NMEA fields = 0, PPI LED off PS/2 +5 V missing or below 4.5 V Measure PS/2 pin 4 vs pin 3 with cable inserted Install 5 V fix circuit (7805, LOGO! Power, or active USB-PS/2)
All NMEA fields = 0, PPI LED green Baud rate mismatch between PC/PPI DIP switch and GPS tuner Check PC/PPI DIP 3/4/5 against GPS PRT message Re-set DIP switches; or re-configure GPS with u-center
All NMEA fields = 0, PPI LED green, garbage on hyperterminal TX/RX swap on RS-232 → RS-485 converter Swap A/B on the RS-485 side of the converter Verify A → pin 8, B → pin 3 of S7-200 Port 0
Variable table reads $GPGGA,$GPRMC,... as ASCII but parsed fields = 0 Set 41 GPS_PARSE not called, or called before sentence is complete Place GPS_PARSE in the receive-interrupt OB or in a 100 ms cyclic OB Wire GPS_PARSE to GPS_RECV's "SentenceReady" output
FixValid = 1 but Latitude/Longitude are 0.0 Wrong datum in GPS (e.g. Tokyo vs WGS84) or empty NMEA fields Hyperterminal the raw NMEA stream; verify comma-delimited fields are not blank Re-configure GPS to WGS84; verify the active antenna is connected
FixValid toggles 0/1/0/1 every second Checksum errors — RS-485 termination missing on long runs Inspect the GPS_PARSE error byte for checksum mismatch count Add 120 Ω termination at the S7-200 end of the RS-485 run
Variable table shows N/A or "Object does not exist" GPS_DATA DB not downloaded, or symbol table not loaded Cross-reference GPS_DATA in the project tree Download the DB separately; refresh the symbol table

Verification

Acceptance criteria for a healthy Set 41 GPS link:

  • FixValid = 1 for at least 30 consecutive seconds.
  • SatCount ≥ 4 in an open-sky installation.
  • Latitude / Longitude within 0.0001° of a known reference (handheld GPS, smartphone GPS, or a known survey marker).
  • UTC_Time matches an NTP-disciplined reference within 1 second.
  • 1PPS rising edges on the S7-200 digital input correlate with the seconds-rollover of UTC_Time in the data block.
  • No checksum error counter incrementing in GPS_DATA over a 10-minute observation window.

For long-term verification, log Latitude, Longitude, and SatCount to the S7-200's recipe or data-log area and download the archive via STEP 7 Micro/WIN or a custom Modbus poll. Position drift greater than 10 meters static in a fixed installation indicates a faulty active antenna, a damaged antenna cable, or multipath from a metallic mounting surface.

Notes on Modernization and Replacement

Set 41 was last updated in 2009 and targets the S7-200 platform, which Siemens has declared out of mainstream support. For new projects the migration targets are:

  • S7-1200 / S7-1500: replace the PC/PPI cable with a CP 1243-1 or CM 1241 RS-232/RS-485 module and use the Open User Communication (OUC) library to parse NMEA 0183 directly. The "GPS" application example is published on Siemens Industry Online Support.
  • LOGO! 8 with LOGO! CMK2000 communication module: GPS time synchronization is supported natively via the LOGO! Soft Comfort V8.4 function block set.
  • Third-party telemetry RTUs: most modern fleet-management RTUs (Sierra Wireless, CalAmp, Queclink) integrate a u-blox GPS engine directly and expose NMEA or NMEA-compatible data over an IP backhaul, removing the S7-200 from the GPS path entirely.

When the S7-200 remains in service, the USB PC/PPI cable (6ES7 901-3DB30-0XA0) eliminates the PS/2 power fault and is the recommended replacement for the legacy RS-232 cable on any new Set 41 integration.

Why does the S7-200 variable table show all zeros for every NMEA field, even though the GPS tuner LED is blinking?

The most common cause is the missing 5 V supply on the PC/PPI cable's PS/2 tap. Modern PCs supply 3.3 V or 0 V on the PS/2 +5 V line, which is below the cable's isolated DC/DC converter start voltage. The cable's RS-485 transceiver is starved, the PPI LED stays dark or pulses weakly, and the freeport UART on the S7-200 never sees a NMEA character. Measure the PS/2 pin 4 voltage; if it is below 4.5 V, install a 5 V tap from a 7805 regulator fed from the S7-200 backplane 24 V, or from a Siemens LOGO! Power 5 V module (6EP3310-1SH03).

Which DIP-switch positions on the PC/PPI cable select freeport mode at 4800 bps for Set 41 GPS?

Set switch 1 to ON for PPI/freeport select, switch 2 to OFF for echo disabled, and switches 3 = ON, 4 = OFF, 5 = ON for 4800 bps. This matches the default NMEA 0183 baud rate of u-blox 6 and most NL303P-class GPS tuners. For 9600 bps (u-blox 7 default) use 3 = ON, 4 = OFF, 5 = OFF. For 38400 bps use 3 = OFF, 4 = ON, 5 = OFF.

Can I connect the NL303P GPS tuner directly to S7-200 Port 0 without a converter?

No. The NL-303P's TX line outputs RS-232 levels (±5.5 V swing) which are not RS-485 differential. The S7-200 Port 0/1 PPI port expects a differential pair on pins 3 (B) and 8 (A). Direct connection will not damage the modules but will produce all zeros in the variable table. Use an external RS-232 → RS-485 converter (e.g. Phoenix Contact PSM-ME-RS232/RS485-P or Moxa TCC-80) between the GPS tuner and the S7-200 port.

What is the order number for the Siemens Set 41 GPS library?

Set 41 is published under order code 6ES7841-0AA00-0YA0 ("GPS Synchronization of SIMATIC S7-200") and is available as a free download from the Siemens Industry Online Support portal. The archive contains the library GPS_SYNC.LIB and an example STEP 7 Micro/WIN project that pre-configures GPS_INIT, GPS_RECV, GPS_PARSE, and the GPS_DATA shared data block. Specific block names and data-block offsets should be verified against the active library build before commissioning.

My variable table shows the raw NMEA sentence ($GPGGA,...) but the parsed fields are all zero. What is wrong?

Set 41's GPS_PARSE function block is either not being called, is being called before the receive interrupt has assembled a complete sentence, or the GPS_PARSE is wired to the wrong done flag. Place GPS_PARSE in a 100 ms cyclic OB or directly in the receive-interrupt routine and connect its enable input to GPS_RECV's "SentenceReady" output. After this, FixValid should toggle to 1 within a few seconds of a healthy GPS fix.

Back to blog