S7-300 Interarea Pointers: Accessing ET200S Peripheral I/O

David Krause15 min read
S7-300SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

S7-300 Interarea Pointers: Accessing ET200S Peripheral I/O

This reference explains how to access distributed I/O on an ET200S station from a Siemens SIMATIC S7-300 CPU 314-2DP over Profibus DP using 32-bit area-cross (interarea) pointers in STL. It consolidates the pointer structure, the difference between process image and direct peripheral access, the HW Config slot addressing rules, and field-proven STL snippets for digital and analog I/O.

Scope: CPU 314-2DP (6ES7314-6BF01-0AB0 or comparable variants) with STEP 7 V5.5 / TIA Portal. ET200S with IM151-1 interface module on Profibus DP. Master-slave integration is assumed; peer-to-peer coupling is out of scope.

1. Prerequisites

  • SIMATIC S7-300 CPU 314-2DP (6ES7314-6BF01-0AB0) with at least one DP master port active.
  • ET200S distributed station, interface module IM151-1 (e.g., 6ES7151-1BA02-0AB0) or IM151-1 HF.
  • Digital I/O modules 4/8/16-channel (e.g., 6ES7131-4BD01-0AA0 inputs, 6ES7132-4BD01-0AA0 outputs).
  • Analog I/O modules (e.g., 6ES7134-4FB01-0AB0 2AI, 6ES7135-4FB01-0AB0 2AO).
  • Profibus DP cable, bus connector (6ES7972-0BA12-0XA0), terminating resistors enabled at both ends.
  • STEP 7 V5.5 SP2 (or TIA Portal V15.1 or higher) with HW Config installed.
  • GSD file of the ET200S IM (ET200S.GSD, supplied with STEP 7).

2. The 32-Bit Area-Cross Pointer Format

The S7-300 family uses 32-bit internal pointers to dereference any memory area. When the high byte carries an area identifier, the pointer is called an interarea (area-cross) pointer because it can target any area in one instruction.

Bit Position 31..24 23..16 15..8 7..3 2..0
Content Area ID Byte address high Byte address low Reserved Bit address 0..7
Example input 0.0 0x81 0x00 0x00 0x00 0x00
Example output 0.0 0x82 0x00 0x00 0x00 0x00
Example PEW 0 0x80 0x00 0x00 0x00 0x00

2.1 Area Identifier Table

Area ID (hex) Area Mnemonic Pointer Prefix
0x80 Peripheral I/O (direct) PE / PQ P
0x81 Process image inputs I / IE E
0x82 Process image outputs Q / QA A
0x83 Bit memory M M
0x84 Data block (DB) DBX / DBB / DBW / DBD DB
0x85 Instance data block DIX / DIB / DIW / DID DI
0x86 Local data (L stack) L / LB / LW / LD L
0x87 Previous L stack (V) V / VB / VW / VD V

For digital bit access the complete pointer is built as DW#16#8yBB000n where y is the area digit, BB is the byte address in hex, and n is the bit position 0..7. For example, the source's DW#16#81000000 points to I 0.0 and DW#16#82000000 to Q 0.0.

3. Process Image vs. Direct Peripheral Access

Two physically different paths exist between the CPU and the ET200S modules:

  1. Process image (PI / PIP1) — the I/O image is refreshed once per OB1 cycle (or as configured). The I and Q areas are copies of the physical state at the OB1 start.
  2. Direct peripheral (P area) — a single load/store triggers a Profibus cycle that reads or writes the actual value at the moment of execution. No snapshot is used.

3.1 When to Use Direct Peripheral Access

Use case Recommended area Reason
Fast interrupt-driven input (OB30..OB38) P (peripheral) Read latest value without OB1 lag
Safety-related reads where age matters P Deterministic cycle
Standard OB1 logic, comfortable timing I / Q (PI) Faster instruction, no extra Profibus traffic
Outputs driven by a function block triggered asynchronously PQ Avoids output lock-up in OB1-skip cases

If the ET200S module property is set to "Process image update" (default), the area appears under I and Q. If you change the property to "PIP1 (peripheral, update once per cycle)" or "PIP2" in HW Config, the same byte can be read by the P-area pointer as well. Modules configured as "no PI" can only be accessed by the P area.

4. ET200S Address Mapping in HW Config

When the ET200S station is inserted in HW Config and linked via Profibus DP, the address assignment follows the slot order of the IM151-1 head. For a typical configuration the mapping looks like:

Slot Module Digital I/O Address Analog I/O Address
1 IM151-1 (head) 0 0
2 Power module PM-E 0 0
3 8 DI 24 V DC (6ES7131-4BF00-0AA0) I 0.0..0.7 (PI) or PE 0 (P) —
4 8 DO 24 V DC (6ES7132-4BF00-0AA0) Q 0.0..0.7 (PI) or PQ 0 (P) —
5 4 DI 24 V DC I 1.0..1.3 —
6 4 DO 24 V DC Q 1.0..1.3 —
7 2 AI (6ES7134-4FB01-0AB0) — PIW 256 / 258 (PI) or PEW 256 / 258 (P)
8 2 AO (6ES7135-4FB01-0AB0) — PQW 256 / 258 (PI) or PQW 256 / 258 (P)

For the CPU 314-2DP the analog I/O area starts at PIW 256 by default for the first Profibus master system. The exact starting address can be shifted in HW Config by editing the module properties ("Addresses" tab). The first free PIW/PQW after the CPU's local I/O is typically 256 for a Profibus master system — check with the Address Overview tool in HW Config to confirm.

Overlap warning: The same byte number can exist in both the PI and P areas. A pointer built with 0x80 (peripheral) and a byte offset of 0 will read PE 0, not PI 0 or I 0. Mixing the two areas in the same FB without explicit documentation is a common field failure cause.

5. Building a 32-Bit Pointer in STL

5.1 Construction Pattern

The standard formula is:

  1. Load the byte number (0..65535) into a temporary.
  2. Convert to DINT (ITD).
  3. Shift left by 3 to make room for the bit field (SLD 3).
  4. OR-in the area identifier (0x80..0x87) in the high byte.
  5. OR-in the bit number 0..7 in the low 3 bits.
  6. Transfer to AR1 (LAR1) and dereference with A [AR1,P#0.0] or L DBB [AR1,P#0.0].

5.2 STL Snippet: Bit Read of a Logical Input

// Source-variable examples in STEP 7 V5.5
// Input: #i_LogNo  (INT, 0..255  logical input number)
// Output: #RET_VAL (BOOL)

      L     #i_LogNo           // logical input number 0..N
      ITD                       // convert to DINT
      SLD   3                   // shift byte addr by 3 to make room for bit pos
      L     DW#16#81000000      // area id 0x81 = process image input
      OD                        // OR area id into high byte
      TAR1                      // use AR1 (or LAR1 if not preset)
      AD    DW#16#0             // mask off low bits if needed
      LAR1
      A     [AR1, P#0.0]        // read bit
      =     #RET_VAL            // return

Reading directly from the peripheral area (PE) is identical except for the area identifier:

      L     DW#16#80000000      // area id 0x80 = peripheral input
      OD
      LAR1
      A     [AR1, P#0.0]

5.3 STL Snippet: Byte / Word / Dword Access

// Read a peripheral byte (PEB 0) using interarea pointer
      L     0                   // byte number 0
      ITD
      SLD   3
      L     DW#16#80000000      // area id 0x80 = peripheral
      OD
      LAR1
      L     B [AR1, P#0.0]      // L PEB 0
      T     MB   10

// Read a peripheral word (PEW 256) for first analog input
      L     256
      ITD
      SLD   3
      L     DW#16#80000000
      OD
      LAR1
      L     W [AR1, P#0.0]      // L PEW 256
      T     MW   12

// Read a peripheral dword (PED 0)  (longer analog value, or two adjacent words)
      L     0
      ITD
      SLD   3
      L     DW#16#80000000
      OD
      LAR1
      L     D [AR1, P#0.0]      // L PED 0

5.4 STL Snippet: Logical-to-Physical Map via a DB

This is the pattern that matches the source's application: a DB is filled with one DINT per logical I/O. Each DINT is a prebuilt interarea pointer that is dereferenced by a generic FC.

// DB "IO_Ptrs" — DINT array
//   DBW 0  -> pointer for logical input #0
//   DBW 4  -> pointer for logical input #1
//   ...

FUNCTION FC 100 : VOID
VAR_INPUT
   i_LogNo  : INT;     // logical I/O number 0..N
END_VAR
VAR_TEMP
   t_Offset : INT;
   t_Ptr    : DWORD;
   t_AR1    : DWORD;
END_VAR

BEGIN
      L     #i_LogNo
      L     4
      *D                       // offset = i_LogNo * 4
      T     #t_Offset

      OPN   "IO_Ptrs"
      L     DBB [#t_Offset]    // load DINT pointer from DB (one of 4 bytes)
      ...
      L     DBD [#t_Offset]    // load full DINT
      T     #t_Ptr

      LAR1  #t_Ptr             // load into AR1
      A     [AR1, P#0.0]
      =     M 0.1              // forwarded result
END_FUNCTION
Bit-address note: If the DB stores full 32-bit pointers such as DW#16#81000000, you cannot simply LAR1 directly from DBD on older CPUs. Use the explicit pattern L DBD[…]; LAR1 to load the DINT into AR1, then dereference. Always re-load AR1 before every use; do not assume AR1 retains its value across blocks.

6. Step-by-Step Commissioning

  1. Wire the ET200S station. Connect the IM151-1 Profibus port, enable terminating resistors on the first and last device only.
  2. Open HW Config in STEP 7. Insert a Profibus DP master system and place an ET200S station (HW Catalog > PROFIBUS DP > ET200S).
  3. Add modules to the ET200S slots. Drag digital input, digital output, analog input, analog output modules. STEP 7 auto-assigns addresses starting at the next free range (commonly 0.0 for digital, 256 for analog on master system 1).
  4. Edit module properties. For inputs that need real-time access, set the digital input module to "Process image: PIP1" or "no PI" depending on whether you want OB1-time reads or direct reads.
  5. Configure the analog input range. For 6ES7134-4FB01-0AB0 select "0..10 V" or "4..20 mA" in module properties > Inputs. STEP 7 will encode 0..27648 integer units across the selected range.
  6. Download HW Config to the CPU and the IM151-1. Verify the IM151-1 has its SF/ BF LED off.
  7. Create the IO_Ptrs DB. Populate with 32-bit interarea pointers, e.g. DW#16#81000000 for I 0.0, DW#16#81000020 for I 0.2, DW#16#80000000 for PE 0, etc.
  8. Implement the FC in STL following the pattern in section 5.4. Place a call in OB1 with the logical input number as input.
  9. Monitor online in STEP 7: open the FC, click Monitor, change the input number, and confirm the dereferenced bit follows the physical signal at the terminal.

7. Verification

After commissioning, perform the following checks before sign-off:

Check Procedure Pass Criterion
PI read Force 24 V on terminal of slot 3 input 0.0; monitor I 0.0 in VAT. I 0.0 = 1
P read Same input 0.0; monitor PE 0 bit 0 with a VAT on the P area. PE 0.0 = 1
PI write Set Q 0.0 = 1 in VAT; measure voltage at output terminal. 24 V present at output
P write Set PQ 0.0 = 1 via P area VAT; measure. 24 V present
Pointer read Run FC100 with i_LogNo=0; result reflects PE 0.0. RET_VAL follows physical input
Pointer write Use analogous FC to set Q 0.0 via pointer. Output energised
OB1 time lag Apply 5 Hz square wave to input 0.0; observe I 0.0 and PE 0.0 on scope. PE follows input; I is delayed by OB1 cycle
Force vs. pointer test: When you force a bit in the process image via VAT, the CPU is not driving the Profibus slave line per cycle; force is local to the image. Always test the pointer against a real signal on the terminal block before assuming the dereference works.

8. Analog I/O Specifics

Analog modules on ET200S return integer values normalised to the configured range:

Range Integer Units (decimal) Resolution
0..10 V 0..27648 ~0.36 mV / bit
±10 V -27648..27648 ~0.36 mV / bit
4..20 mA 0..27648 ~0.578 µA / bit
0..20 mA 0..27648 ~0.723 µA / bit
Pt100 (standard) multiplied by 10 0.1 °C / bit

Read the first AI (PEW 256) with a 32-bit interarea pointer as shown in section 5.3. The next channel is at PEW 258. The 2-wire / 4-wire mode of the AI module is configured in HW Config > module properties > Inputs.

9. Troubleshooting Matrix

Symptom Likely Cause Resolution
Bit always 0, even with 24 V on terminal Pointer built with wrong area ID (e.g., 0x82 instead of 0x80 for direct read of an input) Re-check area ID; use 0x80 for PE, 0x81 for I
Bit always 0; PI read works fine Module set to "Process image" only; no P access Open module properties and switch to PIP1 or "no PI"
Bit always 1 from PI but real signal 0 Wrong byte address in pointer (overlapping with output image) Cross-check with HW Config address overview
SF LED on IM151-1 Slave diagnostic alarm; module removed or wrong type Run "Module Information" on the DP slave; replace module
BF LED on IM151-1 Profibus cable break, wrong baud rate, missing terminator Check cable, terminating resistor, baud rate (45.45 kbit/s to 12 Mbit/s)
PEW always 0, even with 4 mA on AI Module in 2-wire mode but wired as 4-wire, or wrong input range Verify module properties > Inputs > range and wiring
Pointer FB returns 0 sporadically AR1 destroyed by another block between calls Always re-load AR1 from the stored DINT pointer before dereference
SF on CPU and "Peripheral access error" OB Address not present in HW Config (typo in pointer) Check HW Config; verify the byte address is allocated
Output bit flips back after OB1 Written to PI output that is overwritten by peripheral write elsewhere Use P area (PQ) for the actual write, or remove the duplicate source
Interarea pointer in DB returns status word 0x80xx Bit 15 (SFB) was set by accident — 0x80000000 used for write of input Use 0x80 for PE read; never OR with 0x80000000 for input

10. Field Commissioning Notes

  • Profibus baud rate is auto-detected by the IM151-1. New slaves may take up to 5 s to enter data exchange. With OB82 (diagnostic interrupt) enabled, the CPU logs the transition.
  • OB1 cycle time on a CPU 314-2DP with 200 byte Profibus I/O is typically 5…15 ms. A direct peripheral read inside an OB30 (5 ms interrupt) returns the value at that instant, not at OB1 start.
  • AR1 / AR2 usage — both address registers are shared. If the called FC uses AR1 internally, save and restore AR1 around the dereference; otherwise the caller's pointer is corrupted.
  • Bit memory vs. peripheral read — reading a peripheral input does not update M memory. A latching operator must copy the bit to M if persistence across OB1 cycles is required.
  • Pointers in SCL — SCL abstracts pointers with the POINTER and ANY data types. The compile target STL generated by SCL is functionally equivalent to the explicit patterns above; STL gives finer control for bit access.
  • Process image size on a CPU 314-2DP defaults to 128 byte for inputs and 128 byte for outputs. Profibus I/O can exceed this if "no PI" is selected on a module. With OB1, only the configured PI range is refreshed; bytes outside the range require direct peripheral access.
  • Wiring rule for digital output — ET200S 24 V DO modules source 500 mA per channel. When using a relay coil, install a flyback diode (1N4007) reverse-biased across the coil to protect the output against inductive kickback.
  • Watchdog / time-out — if the IM151-1 loses Profibus communication for longer than the configured DP watchdog (default 10 s), the ET200S outputs go to the configured substitute value (typically 0). Set this in HW Config > ET200S properties > Parameter Assignment.

11. Edge Cases and Caveats

  1. Pointer arithmetic overflow — if i_LogNo is negative, ITD sign-extends and the resulting byte address becomes a very large unsigned value, which causes a peripheral access error in OB121. Always check i_LogNo >= 0 and i_LogNo < Max before loading the pointer.
  2. Byte-aligned only — the P area cannot be read below the byte boundary. If your logical map has bit granularity, the source must still load the entire byte and extract the bit via A [AR1, P#0.x].
  3. AR1/P#0.0 sum — when you write [AR1, P#0.0], the S7 firmware adds the bit offset P#x.x to the pointer's bit address. Use this for indirect bit access without reloading AR1.
  4. Byte vs. word address interpretation — the same DINT can mean "byte 256 of the P area" or "word 128 of the P area", depending on whether you dereference with L W[AR1,P#0.0] or L B[AR1,P#0.0]. Always confirm the dereference width.
  5. PI update partial refresh — if the ET200S module is set to PIP1, the image is updated at the start of OB1, but only for the configured PIP1 range. Bytes outside that range stay at the previous value if read with I; use PE instead.

12. Related S7-300 Resources

For verification of standard wiring and rating limits, cross-check against the project-specific installation guidelines in the S7-300 manual and the module-specific datasheets. Permissible overload values, derating curves, and ambient temperature limits are not in scope of this article and must be confirmed against the latest edition of the relevant Siemens datasheet before deployment.

What is the difference between area ID 0x80, 0x81, and 0x82 in an S7-300 interarea pointer?

0x80 points to the direct peripheral area (PE/PQ) which is read or written at the moment of the instruction. 0x81 points to the process image input (I), and 0x82 to the process image output (Q), both of which are snapshots refreshed once per OB1 cycle.

Can I read an ET200S digital input through pointer 0x80 if the module is configured as process image?

Yes. Setting the module to PIP1 keeps it accessible through both PE (direct) and I (process image). If it is set to "no PI", only the PE (0x80) pointer works for the module.

Why does my pointer dereference return 0 even though the input is at 24 V?

Common causes: wrong area ID, wrong byte address, the module is configured as PI only while you are dereferencing PE, or AR1 was overwritten between loading and dereference. Cross-check with the VAT in HW Config > Address Overview and reload AR1 from the stored DINT immediately before use.

Where do the analog addresses PEW 256, 258, 260, 262 come from on a CPU 314-2DP?

By default, the first analog range of the first Profibus master system starts at PIW 256 / PQW 256. The 2-AI module at slot 7 occupies PEW 256 (channel 0) and PEW 258 (channel 1). The 2-AO module at slot 8 occupies PQW 256 and PQW 258. The exact base can be shifted in HW Config.

Is it safe to mix process image and peripheral access in the same FC?

Yes, but document the area ID clearly. Use a structured DB where each entry pairs the pointer with a tag (e.g. "PI:PEW 256" or "PE:PIW 256") and avoid reusing the same local pointer variable for both areas. Always reload AR1 from the DINT pointer before dereference to prevent stale-pointer bugs.

Back to blog