S7-300 MPI Data Exchange: X_GET, X_PUT, and Global Data

David Krause17 min read
S7-300SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview: MPI Data Exchange Between S7-300 CPUs

The S7-300 CPU 313C (order number 6ES7313-5BF03-0AB0) and the CPU 315-2PN/DP (order number 6ES7 315-2EH14-0AB0) each integrate a multi-point interface (MPI) that supports both cyclic and acyclic data exchange with other S7 stations without additional hardware. The MPI is a token-passing, RS-485-based bus running at 19.2 kbit/s or 187.5 kbit/s by default, and up to 12 Mbit/s with newer CPUs. For two-CPU data sharing, Siemens provides three primary mechanisms, each with distinct trade-offs in configuration effort, data volume, and event model.

The available methods are:

  • Global Data (GD) communication — configured graphically in NetPro / STEP 7; cyclic broadcast of small data packets without explicit user programming.
  • X_GET / X_PUT SFCs — explicit acyclic read/write jobs initiated from the user program; preferred when a deterministic master/slave model is required.
  • BSEND / BRCV SFBs — large block-oriented, acknowledged data exchange over a configured S7 connection; required for transfers above 76 bytes per direction.

This reference covers the first two methods in depth because they are the most common answers to the question of how to share DB values between two S7-300 CPUs over MPI. The SFB-based approach is documented briefly as a fallback for larger payloads.

Naming convention. Siemens has migrated the older X_GET / X_PUT (SFC 67 / 68) to interrupt-driven versions I_GET / I_PUT (SFC 72 / 73) for newer firmware. S7-300 CPUs with firmware 2.x or later support both pairs. X_GET / X_PUT remain valid and are still the default selection in STEP 7 V5.5 for S7-300 stations. The I_GET / I_PUT pair uses an OB mask and is typically selected for S7-400 and S7-1500.

2. Hardware and Topology Prerequisites

Before configuring any of the methods above, confirm that the physical MPI network meets Siemens limits. The MPI segment must form a single, linear, terminated bus.

2.1 Hardware inventory

Component Order number Firmware Role
CPU 313C 6ES7313-5BF03-0AB0 V2.6 or higher Station A — typically the X_GET initiator
CPU 315-2PN/DP 6ES7315-2EH14-0AB0 V3.1 or higher Station B — provides the shared DB
PROFIBUS/MPI connector with PG socket 6ES7972-0BA12-0XA0 — 90° cable outlet, switchable 220 Ω termination
PROFIBUS cable 6XV1830-0EH10 — Two-core, shielded, twisted pair, violet jacket
Repeater (if required) 6GK1500-0AA10 — RS-485 repeater to extend segment or split into two segments

The two end stations of the segment must have terminating resistors switched ON. All intermediate nodes must have termination OFF. The CPU 313C ships with termination OFF on the supplied connector; the switch is located under the cable entry. Detailed pinning and termination information is provided in the S7-300 CPU 31xC and CPU 31x installation manual.

2.2 Address and baud-rate planning

Parameter Station A (CPU 313C) Station B (CPU 315-2PN/DP) Notes
MPI address 2 3 Avoid address 0 (reserved) and address 1 (typical PG/OP address)
Highest MPI address 31 31 Token-ring limit on a single segment
Baud rate 187.5 kbit/s 187.5 kbit/s Highest rate both CPUs share; 19.2 kbit/s fallback for legacy segments
OB82 / OB86 / OB122 Inserted in project Inserted in project Required for clean fault handling on link loss
Number of S7 connections 1 (reserved for partner) 1 (reserved for partner) Consumed from the connection resources of the CPU
Connection resources. Each S7-300 CPU has a fixed number of communication resources. The CPU 313C supports up to 4 S7 connections; the CPU 315-2PN/DP supports up to 16. The X_GET / X_PUT pair and the GD subscription each consume one resource on each station. Plan accordingly if PG/OP/HMI links already occupy slots.

3. Method Selection: GD vs. X_GET/X_PUT vs. SFB

Select the data-exchange method based on the payload size, determinism, and configuration effort required by the application.

Criterion Global Data (GD) X_GET / X_PUT (SFC 67/68) BSEND / BRCV (SFB 12/13)
Programming effort None (graphical) Medium (SFC call in OB1 or cyclic OB) Medium (SFB instance, request handling)
Max data per transfer 22 bytes per package 76 bytes per call (S7-300 user-data limit) 32 KB per call (configurable)
Max packages per CPU 16 packages, 4 GD circles Unlimited (sequential calls) Unlimited
Trigger Cyclic, scan-time driven Event-driven by user program Event-driven, streaming
Configuration site NetPro → GD table NetPro → S7 connection NetPro → S7 connection
Acknowledged No (broadcast) Yes (per job) Yes (segmented, with end marker)
Best fit Small setpoints/status Event-driven data, request/reply Large record transfer, recipes

For a typical S7-300-to-S7-300 point-to-point link where the master CPU 315-2PN/DP needs to read a 20-word array from a slave DB and write back a 10-word command, the X_GET / X_PUT pair is the cleanest fit. Reserve GD for low-rate, broadcast-style status sharing across three or more stations.

4. Configuring the MPI Network in STEP 7

Both methods require the MPI interface to be correctly parameterized in HW Config. Carry out the steps below in the S7 project that contains both CPU stations.

  1. Open the S7 project in SIMATIC Manager and select the station S7-300_1 (CPU 313C).
  2. Open HW Config and double-click the CPU 313C slot. Switch to the Interface tab of the MPI sub-module.
  3. Set Address = 2, Highest MPI address = 31, Baud rate = 187.5 kbit/s. Click Properties → Network Settings to verify the same profile appears on the bus.
  4. Repeat for the CPU 315-2PN/DP station, using Address = 3.
  5. Save, compile, and download to both stations. Verify the MPI link LED (SF/BF) on each CPU is off after a power cycle.

If the BF (bus fault) LED remains lit, re-check cable polarity (pin 3 = A, pin 8 = B on the D-sub connector), termination, and the baud rate consistency. A mismatch between the programmed and the actual profile is the most common cause of an MPI link that powers up but cannot establish token ring participation.

5. Global Data (GD) Communication

GD communication broadcasts small data packets from one CPU to one or more partner CPUs at the rate defined by the GD circle scan time. No user code is needed once the table is compiled and downloaded. The reference configuration in the Siemens support database is entry 25734677, "How do you configure global data communication (GD) between S7-300 CPUs?"

5.1 GD limits for the S7-300

Limit Value
GD circles per CPU 4
GD packages per CPU 16
GD packages per circle 16
User data per package 22 bytes
Number of CPUs per circle 1 sender + 1 receiver (paired) or 1 sender + N receivers (broadcast)
Scan-time multiples 1 to 255 × OB1 cycle

5.2 Building a GD table

  1. In NetPro, right-click the MPI subnet and choose Define as GD Subnet. The subnet line in the project tree becomes red instead of green.
  2. Open GD Table (right-click the MPI subnet → GD Table). The editor displays the stations on the subnet in columns.
  3. Drag a DB or a bit/byte/word/double-word address from the station symbol browser into the cells. The syntax follows the rule <DB number>.<data type>.<offset>, for example DB10.DBW0 for the first word of DB10.
  4. Right-click the cells to mark each entry as sender or receiver. Only one sender per line is allowed.
  5. Open the GD circle properties and set the Send cycle factor to control the broadcast rate. A factor of 5 with OB1 running at 50 ms means a 250 ms update.
  6. Compile (Ctrl+F9) and download the GD table to every station. STEP 7 stores it in the SDBs 20 and 21; the system diagnostic displays GD ok when the table is in sync.
Status word. STEP 7 inserts the GD_RDY bit in status word 1 of the user program. A 0 indicates a loss of one or more GD packages (a partner is missing or a length mismatch occurred). Ladder logic should monitor this bit and latch a fault for HMI display.

6. X_GET / X_PUT SFC Programming

The X_GET / X_PUT pair provides an explicit, programmatic read/write from one CPU to a partner. The complete Siemens reference for S7-300 / S7-400 standard SFCs is documented in the support entry 747743, "Which SFCs do you use to exchange data via MPI / PROFIBUS with S7-300?".

6.1 Required configuration

  1. In NetPro, right-click the CPU 313C station and choose Insert New Connection.
  2. Select S7 connection as the type and the CPU 315-2PN/DP as the partner. Confirm MPI as the network.
  3. Leave the connection resource locally at the default. STEP 7 will allocate a free slot and write the connection ID into the local and remote configuration. The connection ID is later required as the DEST_ID input is the partner's MPI address, not the connection ID — see Section 7.
  4. Compile and download the connection to both stations.

6.2 SCL call example for X_GET

The following Structured-Text block reads 76 bytes from the partner's DB10 starting at byte 0 into the local DB20. The SFC is instantiated as a multi-instance in FB100.

// FB100 — "MPI_Get_Data" multi-instance DB: "diMPI_Get"
DATA_BLOCK "diMPI_Get"
  FB100
BEGIN
END_DATA_BLOCK

FUNCTION_BLOCK FB100
VAR
    xTrigger   : BOOL;        // edge-triggered start request
    xBusy      : BOOL;
    wRetVal    : WORD;        // SFC67 RET_VAL in WORD form
    bStep      : BYTE;        // 0 = idle, 1 = request, 2 = wait
END_VAR
BEGIN
    // rising-edge trigger for one shot
    IF xTrigger AND bStep = 0 THEN
        bStep := 1;
    END_IF;

    // rising edge at REQ to start a new job
    "xGet".REQ    := (bStep = 1);
    "xGet".CONT   := TRUE;                            // keep connection after job
    "xGet".DEST_ID := W#16#3;                          // partner MPI address 3
    "xGet".VAR_ADDR := P#DB10.DBX0.0 BYTE 76;          // source in remote CPU
    "xGet".SD     := P#"DB_Remote".DBX0.0 BYTE 76;     // destination in local DB20

    SFC67("xGet")(
        REQ      := "xGet".REQ,
        CONT     := "xGet".CONT,
        DEST_ID  := "xGet".DEST_ID,
        VAR_ADDR := "xGet".VAR_ADDR,
        SD       := "xGet".SD,
        RET_VAL  := "xGet".wRetVal,
        BUSY     := "xGet".xBusy);

    IF bStep = 1 AND "xGet".xBusy THEN
        bStep := 2;
    END_IF;

    IF bStep = 2 AND NOT "xGet".xBusy THEN
        // job complete — evaluate wRetVal
        bStep := 0;
    END_IF;

    // map WORD to BOOL for HMI
    xBusy := "xGet".xBusy;
    wRetVal := "xGet".wRetVal;
END_FUNCTION_BLOCK

6.3 Ladder call example for X_PUT

For STEP 7 users programming in LAD/FBD, the SFC is called in OB1 and its formal parameters are wired to data in an instance DB.

  1. Place a call box in OB1 and select SFC 68 — X_PUT. STEP 7 creates the instance DB DB_SFC68 automatically.
  2. Wire the inputs:
    • REQ = a flag bit set every 100 ms in OB35 (e.g., M 10.0).
    • CONT = TRUE (keep connection open for subsequent jobs).
    • DEST_ID = W#16#3 (MPI address 3 of the partner CPU).
    • VAR_ADDR = P#DB100.DBX0.0 BYTE 76 (target area in the partner's CPU).
    • SD = P#DB200.DBX0.0 BYTE 76 (source area in the local CPU).
  3. Wire the outputs RET_VAL and BUSY to a diagnostic DB (e.g., DB99) and an HMI tag.
  4. Build, save, and download to both CPUs.

7. SFC Parameter Reference

The tables below are condensed from the STEP 7 V5.5 standard SFC reference manual and apply to S7-300 stations.

7.1 SFC 67 X_GET — input parameters

Parameter Declaration Type Meaning
REQ INPUT BOOL Rising edge starts a new read job
CONT INPUT BOOL TRUE = keep connection after job, FALSE = disconnect
DEST_ID INPUT WORD MPI address of the partner CPU
VAR_ADDR INPUT ANY Pointer to the data area in the partner CPU
SD OUTPUT ANY Pointer to the data area in the local CPU that receives the data
RET_VAL OUTPUT INT Error code; 0 = job accepted
BUSY OUTPUT BOOL TRUE while the job is in progress

7.2 SFC 68 X_PUT — input parameters

Parameter Declaration Type Meaning
REQ INPUT BOOL Rising edge starts a new write job
CONT INPUT BOOL TRUE = keep connection open
DEST_ID INPUT WORD MPI address of the partner CPU
VAR_ADDR INPUT ANY Pointer to the target data area in the partner CPU
SD INPUT ANY Pointer to the local data area to be sent
RET_VAL OUTPUT INT Error code
BUSY OUTPUT BOOL TRUE while the job is in progress

7.3 SFC 69 X_ABORT

X_ABORT forces a disconnect of the configured S7 connection. Use it when the application closes down or when an X_GET job is stuck in the BUSY state beyond a watchdog. Pass DEST_ID = partner MPI address and a rising edge on REQ to abort. The RET_VAL semantics are identical to X_GET / X_PUT.

8. SFB-based Large Data Exchange (BSEND / BRCV)

When the payload per direction exceeds 76 bytes — for example, a 244-byte recipe buffer — chain the X_PUT calls as separate jobs, or switch to SFB 12 BSEND / SFB 13 BRCV for acknowledged, segmented block transfer. The SFBs use the same S7 connection that X_GET / X_PUT use but support up to 32 KB per call. The user data are fragmented, transmitted, and reassembled by the partner; both sides must declare the same R_ID (DWORD) to bind the send and receive ends.

// SFB12 BSEND call skeleton (LAD)
SFB12 "BSEND", DB12
    REQ     := M 20.0         // rising edge starts a new send
    R       := M 20.1         // rising edge aborts in-progress job
    ID      := W#16#1         // S7 connection ID from NetPro
    R_ID    := DW#16#A1B2C3D4 // match on both stations
    DONE    := M 30.0         // 1 cycle: job complete with no error
    ERROR   := M 30.1         // 1 cycle: job complete with error
    STATUS  := MW 32          // SFB status word
    SD_1    := P#DB200.DBX0.0 BYTE 244
    LEN     := 244

Although the legacy SFC chains can move 244 bytes via three X_PUT calls (3 × 76 = 228 + 16 in a fourth call), the cleanest implementation above that limit is BSEND / BRCV. Reference: Siemens entry 18609206 on SFB 12 / SFB 13 configuration.

9. Diagnostics and Error Codes

RET_VAL from SFC 67 / 68 / 69 follows the SFC standard error schema. A 0 means the job is accepted; negative values are runtime errors; positive values are CPU-dependent protocol errors.

RET_VAL (hex) RET_VAL (dec) Class Meaning Remedy
W#16#0000 0 Info Job accepted; data valid on completion —
W#16#7000 28672 Info No job active (first call with REQ = 0) —
W#16#7001 28673 Info Job active; BUSY = 1 Wait for completion
W#16#7002 28674 Info Job active; new REQ ignored while BUSY = 1 Check trigger logic
W#16#8090 32912 Error Configured S7 connection was not found Verify NetPro S7 connection, rebuild, re-download
W#16#8092 32914 Error ANY pointer syntax error (length, DB number, area) Check SD / VAR_ADDR pointers
W#16#80A0 32928 Error Negative acknowledgement from partner Partner CPU in STOP, resource exhausted, or DB does not exist
W#16#80A1 32929 Error Partner rejected: DB not loaded or wrong length Check partner DB number, length, download status
W#16#80A2 32930 Error Data type cannot be processed by partner Align ANY pointer on byte boundary, reduce length
W#16#80B0 32944 Error S7 communication error (bus) Check MPI cable, termination, baud rate
W#16#80B1 32945 Error Length of transmitted data does not match the SD pointer Verify SD length on both ends
W#16#80C0 32960 Error Connection aborted by X_ABORT Restart X_GET / X_PUT
W#16#80C1 32961 Error Resources of the local CPU exhausted Increase OB1 priority, reduce parallel calls
W#16#80C2 32962 Error Partner not reachable; token-ring failure Check partner address and cable
W#16#80C3 32963 Error Partner CPU in STOP Bring partner to RUN; OB82/OB86 will fire
W#16#80D0 32976 Error SFB call in wrong OB context Move SFC call to OB1 / OB35

The complete error-code table is part of the STEP 7 V5.5 — Standard SFCs reference manual.

10. Commissioning and Verification

Use the following checklist to bring the MPI link into service. Each item can be verified on-line from the STEP 7 programming device.

  1. Online reachability. In SIMATIC Manager, choose PLC → Online → Accessible Nodes. Both CPUs must appear with the configured MPI address. If only one is visible, the wiring or the partner's MPI profile is wrong.
  2. Connection status. Open NetPro, right-click the S7 connection, and choose Connection Status. The states established and own ID confirm the link is live. If status reads not established, re-download the connection to both stations and verify the connection resource list in HW Config.
  3. GD check (if used). Open the GD table online; the green row colour confirms successful reception of each package. A red row indicates a mismatch — typically a DB number, offset, or data-type length difference.
  4. SFC check (if used). Add a VAT (Variable Table) and watch the RET_VAL and BUSY outputs. After triggering REQ once, BUSY should go TRUE for a few OB1 cycles, then drop. RET_VAL must read 0 on completion.
  5. Data integrity. Write a recognisable pattern (e.g., 0xA5A5) into the local source DB. In the partner's VAT, read the destination DB and verify the pattern appears.
  6. Fault injection. Pull the MPI cable from one CPU. The local CPU must call OB86 (link failure); the partner should call OB122 (data access error) if a job is in flight. Restore the cable and verify OB86 is exited without a STOP of either CPU.

11. Troubleshooting Matrix

Symptom Likely cause Diagnostic step Corrective action
BF LED steady on after power up Cable short, open, or wrong polarity Measure A-A / B-B continuity, check pins 3 and 8 Re-wire per Siemens topology rules
BF LED flashes Bus is active but no token with the partner Compare "Highest MPI address" and baud rate across both stations Equalize Highest MPI address and baud rate
RET_VAL = W#16#8090 S7 connection missing in NetPro Open NetPro and check the connection table Insert an S7 connection, download to both stations
RET_VAL = W#16#80A0 Partner CPU in STOP or has no resources Check partner's diagnostic buffer Bring partner to RUN, free a connection resource
RET_VAL = W#16#80A1 DB number or length mismatch Compare the ANY pointer length to the partner DB length Use the same length on both sides; verify DB length attribute
RET_VAL = W#16#80B0 MPI bus error during the job Check wiring and EMC; verify the segment has exactly two terminators Re-terminate, replace damaged cable
GD packages show red Mismatched DB or data-type Open GD table in NetPro and compare send/receive rows Re-align addresses; recompile and re-download
BUSY stays TRUE forever Partner lost power mid-job Inspect partner CPU SF/BF LEDs Cycle power on partner; the connection will reset
Job completes in tens of seconds, not milliseconds Too many SFCs called in one OB1 scan Count active SFC67/68/69 instances per scan Move lower-priority jobs to OB35; use CONT = TRUE
Error 80C2 — partner not reachable Duplicate MPI address Online → Accessible Nodes Assign a unique address to each station

12. Performance, Timing, and Throughput Notes

MPI is a deterministic token bus, so the worst-case transfer time is bounded by the token rotation time. At 187.5 kbit/s, a single 76-byte X_GET round-trip typically completes in 5 to 25 ms on a lightly loaded bus, dominated by the time the partner CPU needs to assemble the data and respond. With GD configured at a send-cycle factor of 5 and OB1 at 50 ms, the broadcast cycle is 250 ms, regardless of the OB1 scan time.

Throughput scales roughly linearly with baud rate. The CPU 315-2EH14-0AB0 supports 12 Mbit/s on the MPI/DP interface when the bus is rewired for PROFIBUS topology, but the partner CPU 313C tops out at 187.5 kbit/s on its MPI port. For higher throughput, the CPU 315-2PN/DP should be re-addressed on its PROFINET interface and the data path migrated to ISO-on-TCP (T-blocks T_SEND / T_RCV) or S7 connection over Industrial Ethernet — outside the scope of MPI but the usual upgrade path.

Practical limit. Field experience shows that a sustained X_GET rate higher than 20 jobs/s per connection on a 187.5 kbit/s MPI bus can starve the OB1 cycle. Restrict jobs to the rate the application actually requires; do not call X_GET in a fast cyclic OB if a 100-ms update is sufficient.

13. Frequently Asked Questions

What is the maximum data size per X_GET / X_PUT call on an S7-300?

The user-data limit per SFC 67 / 68 call is 76 bytes on an S7-300 station. For larger payloads, chain multiple calls in a sequence with distinct SD / VAR_ADDR pointers or switch to SFB 12 BSEND / SFB 13 BRCV over the same S7 connection.

Does X_GET / X_PUT require NetPro configuration?

Yes. An S7 connection must be created in NetPro and downloaded to both the local and the partner CPU. Without that connection, SFC 67 / 68 returns RET_VAL = W#16#8090 ("configured S7 connection was not found").

How do I choose between Global Data and X_GET / X_PUT?

Use Global Data when broadcasting up to 22 bytes per package to one or more partners cyclically without any user code. Use X_GET / X_PUT when the exchange must be event-driven, acknowledged, and triggered from the user program, or when a single source/single sink model fits the application.

What happens if the partner CPU is in STOP during a job?

The SFC completes with RET_VAL = W#16#80C3 ("partner CPU in STOP") and OB82 / OB86 will be called on the local CPU. Re-triggering the job after the partner returns to RUN is sufficient; the S7 connection is automatically re-established.

Can I share data between more than two CPUs over the same MPI segment?

Yes, but each S7 connection is point-to-point and consumes one connection resource on each endpoint. Global Data is the preferred method for n-way broadcast up to 16 packages per circle across the entire MPI subnet, subject to the 22-byte-per-package limit.

Why is my MPI link unreachable from the PG even though both CPUs run?

Check that the PG's MPI address is unique (typically 0 or 1) and that the bus profile in Set PG/PC Interface matches the bus profile programmed in the CPUs (187.5 kbit/s). A profile mismatch causes the PG to scan with the wrong baud rate and report "node not found".

Back to blog