1. Overview: MPI Data Exchange Between S7-300 CPUs
The S7-300 CPU 313C (order number 6ES7313-5BF03-0AB0) and the CPU 315-2PN/DP (order number 6ES7 315-2EH14-0AB0) each integrate a multi-point interface (MPI) that supports both cyclic and acyclic data exchange with other S7 stations without additional hardware. The MPI is a token-passing, RS-485-based bus running at 19.2 kbit/s or 187.5 kbit/s by default, and up to 12 Mbit/s with newer CPUs. For two-CPU data sharing, Siemens provides three primary mechanisms, each with distinct trade-offs in configuration effort, data volume, and event model.
The available methods are:
- Global Data (GD) communication — configured graphically in NetPro / STEP 7; cyclic broadcast of small data packets without explicit user programming.
- X_GET / X_PUT SFCs — explicit acyclic read/write jobs initiated from the user program; preferred when a deterministic master/slave model is required.
- BSEND / BRCV SFBs — large block-oriented, acknowledged data exchange over a configured S7 connection; required for transfers above 76 bytes per direction.
This reference covers the first two methods in depth because they are the most common answers to the question of how to share DB values between two S7-300 CPUs over MPI. The SFB-based approach is documented briefly as a fallback for larger payloads.
2. Hardware and Topology Prerequisites
Before configuring any of the methods above, confirm that the physical MPI network meets Siemens limits. The MPI segment must form a single, linear, terminated bus.
2.1 Hardware inventory
| Component | Order number | Firmware | Role |
|---|---|---|---|
| CPU 313C | 6ES7313-5BF03-0AB0 | V2.6 or higher | Station A — typically the X_GET initiator |
| CPU 315-2PN/DP | 6ES7315-2EH14-0AB0 | V3.1 or higher | Station B — provides the shared DB |
| PROFIBUS/MPI connector with PG socket | 6ES7972-0BA12-0XA0 | — | 90° cable outlet, switchable 220 Ω termination |
| PROFIBUS cable | 6XV1830-0EH10 | — | Two-core, shielded, twisted pair, violet jacket |
| Repeater (if required) | 6GK1500-0AA10 | — | RS-485 repeater to extend segment or split into two segments |
The two end stations of the segment must have terminating resistors switched ON. All intermediate nodes must have termination OFF. The CPU 313C ships with termination OFF on the supplied connector; the switch is located under the cable entry. Detailed pinning and termination information is provided in the S7-300 CPU 31xC and CPU 31x installation manual.
2.2 Address and baud-rate planning
| Parameter | Station A (CPU 313C) | Station B (CPU 315-2PN/DP) | Notes |
|---|---|---|---|
| MPI address | 2 | 3 | Avoid address 0 (reserved) and address 1 (typical PG/OP address) |
| Highest MPI address | 31 | 31 | Token-ring limit on a single segment |
| Baud rate | 187.5 kbit/s | 187.5 kbit/s | Highest rate both CPUs share; 19.2 kbit/s fallback for legacy segments |
| OB82 / OB86 / OB122 | Inserted in project | Inserted in project | Required for clean fault handling on link loss |
| Number of S7 connections | 1 (reserved for partner) | 1 (reserved for partner) | Consumed from the connection resources of the CPU |
3. Method Selection: GD vs. X_GET/X_PUT vs. SFB
Select the data-exchange method based on the payload size, determinism, and configuration effort required by the application.
| Criterion | Global Data (GD) | X_GET / X_PUT (SFC 67/68) | BSEND / BRCV (SFB 12/13) |
|---|---|---|---|
| Programming effort | None (graphical) | Medium (SFC call in OB1 or cyclic OB) | Medium (SFB instance, request handling) |
| Max data per transfer | 22 bytes per package | 76 bytes per call (S7-300 user-data limit) | 32 KB per call (configurable) |
| Max packages per CPU | 16 packages, 4 GD circles | Unlimited (sequential calls) | Unlimited |
| Trigger | Cyclic, scan-time driven | Event-driven by user program | Event-driven, streaming |
| Configuration site | NetPro → GD table | NetPro → S7 connection | NetPro → S7 connection |
| Acknowledged | No (broadcast) | Yes (per job) | Yes (segmented, with end marker) |
| Best fit | Small setpoints/status | Event-driven data, request/reply | Large record transfer, recipes |
For a typical S7-300-to-S7-300 point-to-point link where the master CPU 315-2PN/DP needs to read a 20-word array from a slave DB and write back a 10-word command, the X_GET / X_PUT pair is the cleanest fit. Reserve GD for low-rate, broadcast-style status sharing across three or more stations.
4. Configuring the MPI Network in STEP 7
Both methods require the MPI interface to be correctly parameterized in HW Config. Carry out the steps below in the S7 project that contains both CPU stations.
- Open the S7 project in SIMATIC Manager and select the station S7-300_1 (CPU 313C).
- Open HW Config and double-click the CPU 313C slot. Switch to the Interface tab of the MPI sub-module.
- Set Address = 2, Highest MPI address = 31, Baud rate = 187.5 kbit/s. Click Properties → Network Settings to verify the same profile appears on the bus.
- Repeat for the CPU 315-2PN/DP station, using Address = 3.
- Save, compile, and download to both stations. Verify the MPI link LED (SF/BF) on each CPU is off after a power cycle.
If the BF (bus fault) LED remains lit, re-check cable polarity (pin 3 = A, pin 8 = B on the D-sub connector), termination, and the baud rate consistency. A mismatch between the programmed and the actual profile is the most common cause of an MPI link that powers up but cannot establish token ring participation.
5. Global Data (GD) Communication
GD communication broadcasts small data packets from one CPU to one or more partner CPUs at the rate defined by the GD circle scan time. No user code is needed once the table is compiled and downloaded. The reference configuration in the Siemens support database is entry 25734677, "How do you configure global data communication (GD) between S7-300 CPUs?"
5.1 GD limits for the S7-300
| Limit | Value |
|---|---|
| GD circles per CPU | 4 |
| GD packages per CPU | 16 |
| GD packages per circle | 16 |
| User data per package | 22 bytes |
| Number of CPUs per circle | 1 sender + 1 receiver (paired) or 1 sender + N receivers (broadcast) |
| Scan-time multiples | 1 to 255 × OB1 cycle |
5.2 Building a GD table
- In NetPro, right-click the MPI subnet and choose Define as GD Subnet. The subnet line in the project tree becomes red instead of green.
- Open GD Table (right-click the MPI subnet → GD Table). The editor displays the stations on the subnet in columns.
- Drag a DB or a bit/byte/word/double-word address from the station symbol browser into the cells. The syntax follows the rule
<DB number>.<data type>.<offset>, for exampleDB10.DBW0for the first word of DB10. - Right-click the cells to mark each entry as sender or receiver. Only one sender per line is allowed.
- Open the GD circle properties and set the Send cycle factor to control the broadcast rate. A factor of 5 with OB1 running at 50 ms means a 250 ms update.
- Compile (Ctrl+F9) and download the GD table to every station. STEP 7 stores it in the SDBs 20 and 21; the system diagnostic displays GD ok when the table is in sync.
GD_RDY bit in status word 1 of the user program. A 0 indicates a loss of one or more GD packages (a partner is missing or a length mismatch occurred). Ladder logic should monitor this bit and latch a fault for HMI display.6. X_GET / X_PUT SFC Programming
The X_GET / X_PUT pair provides an explicit, programmatic read/write from one CPU to a partner. The complete Siemens reference for S7-300 / S7-400 standard SFCs is documented in the support entry 747743, "Which SFCs do you use to exchange data via MPI / PROFIBUS with S7-300?".
6.1 Required configuration
- In NetPro, right-click the CPU 313C station and choose Insert New Connection.
- Select S7 connection as the type and the CPU 315-2PN/DP as the partner. Confirm MPI as the network.
- Leave the connection resource locally at the default. STEP 7 will allocate a free slot and write the connection ID into the local and remote configuration. The connection ID is later required as the
DEST_IDinput is the partner's MPI address, not the connection ID — see Section 7. - Compile and download the connection to both stations.
6.2 SCL call example for X_GET
The following Structured-Text block reads 76 bytes from the partner's DB10 starting at byte 0 into the local DB20. The SFC is instantiated as a multi-instance in FB100.
// FB100 — "MPI_Get_Data" multi-instance DB: "diMPI_Get"
DATA_BLOCK "diMPI_Get"
FB100
BEGIN
END_DATA_BLOCK
FUNCTION_BLOCK FB100
VAR
xTrigger : BOOL; // edge-triggered start request
xBusy : BOOL;
wRetVal : WORD; // SFC67 RET_VAL in WORD form
bStep : BYTE; // 0 = idle, 1 = request, 2 = wait
END_VAR
BEGIN
// rising-edge trigger for one shot
IF xTrigger AND bStep = 0 THEN
bStep := 1;
END_IF;
// rising edge at REQ to start a new job
"xGet".REQ := (bStep = 1);
"xGet".CONT := TRUE; // keep connection after job
"xGet".DEST_ID := W#16#3; // partner MPI address 3
"xGet".VAR_ADDR := P#DB10.DBX0.0 BYTE 76; // source in remote CPU
"xGet".SD := P#"DB_Remote".DBX0.0 BYTE 76; // destination in local DB20
SFC67("xGet")(
REQ := "xGet".REQ,
CONT := "xGet".CONT,
DEST_ID := "xGet".DEST_ID,
VAR_ADDR := "xGet".VAR_ADDR,
SD := "xGet".SD,
RET_VAL := "xGet".wRetVal,
BUSY := "xGet".xBusy);
IF bStep = 1 AND "xGet".xBusy THEN
bStep := 2;
END_IF;
IF bStep = 2 AND NOT "xGet".xBusy THEN
// job complete — evaluate wRetVal
bStep := 0;
END_IF;
// map WORD to BOOL for HMI
xBusy := "xGet".xBusy;
wRetVal := "xGet".wRetVal;
END_FUNCTION_BLOCK
6.3 Ladder call example for X_PUT
For STEP 7 users programming in LAD/FBD, the SFC is called in OB1 and its formal parameters are wired to data in an instance DB.
- Place a call box in OB1 and select SFC 68 — X_PUT. STEP 7 creates the instance DB DB_SFC68 automatically.
- Wire the inputs:
-
REQ= a flag bit set every 100 ms in OB35 (e.g.,M 10.0). -
CONT= TRUE (keep connection open for subsequent jobs). -
DEST_ID= W#16#3 (MPI address 3 of the partner CPU). -
VAR_ADDR= P#DB100.DBX0.0 BYTE 76 (target area in the partner's CPU). -
SD= P#DB200.DBX0.0 BYTE 76 (source area in the local CPU).
-
- Wire the outputs
RET_VALandBUSYto a diagnostic DB (e.g.,DB99) and an HMI tag. - Build, save, and download to both CPUs.
7. SFC Parameter Reference
The tables below are condensed from the STEP 7 V5.5 standard SFC reference manual and apply to S7-300 stations.
7.1 SFC 67 X_GET — input parameters
| Parameter | Declaration | Type | Meaning |
|---|---|---|---|
| REQ | INPUT | BOOL | Rising edge starts a new read job |
| CONT | INPUT | BOOL | TRUE = keep connection after job, FALSE = disconnect |
| DEST_ID | INPUT | WORD | MPI address of the partner CPU |
| VAR_ADDR | INPUT | ANY | Pointer to the data area in the partner CPU |
| SD | OUTPUT | ANY | Pointer to the data area in the local CPU that receives the data |
| RET_VAL | OUTPUT | INT | Error code; 0 = job accepted |
| BUSY | OUTPUT | BOOL | TRUE while the job is in progress |
7.2 SFC 68 X_PUT — input parameters
| Parameter | Declaration | Type | Meaning |
|---|---|---|---|
| REQ | INPUT | BOOL | Rising edge starts a new write job |
| CONT | INPUT | BOOL | TRUE = keep connection open |
| DEST_ID | INPUT | WORD | MPI address of the partner CPU |
| VAR_ADDR | INPUT | ANY | Pointer to the target data area in the partner CPU |
| SD | INPUT | ANY | Pointer to the local data area to be sent |
| RET_VAL | OUTPUT | INT | Error code |
| BUSY | OUTPUT | BOOL | TRUE while the job is in progress |
7.3 SFC 69 X_ABORT
X_ABORT forces a disconnect of the configured S7 connection. Use it when the application closes down or when an X_GET job is stuck in the BUSY state beyond a watchdog. Pass DEST_ID = partner MPI address and a rising edge on REQ to abort. The RET_VAL semantics are identical to X_GET / X_PUT.
8. SFB-based Large Data Exchange (BSEND / BRCV)
When the payload per direction exceeds 76 bytes — for example, a 244-byte recipe buffer — chain the X_PUT calls as separate jobs, or switch to SFB 12 BSEND / SFB 13 BRCV for acknowledged, segmented block transfer. The SFBs use the same S7 connection that X_GET / X_PUT use but support up to 32 KB per call. The user data are fragmented, transmitted, and reassembled by the partner; both sides must declare the same R_ID (DWORD) to bind the send and receive ends.
// SFB12 BSEND call skeleton (LAD)
SFB12 "BSEND", DB12
REQ := M 20.0 // rising edge starts a new send
R := M 20.1 // rising edge aborts in-progress job
ID := W#16#1 // S7 connection ID from NetPro
R_ID := DW#16#A1B2C3D4 // match on both stations
DONE := M 30.0 // 1 cycle: job complete with no error
ERROR := M 30.1 // 1 cycle: job complete with error
STATUS := MW 32 // SFB status word
SD_1 := P#DB200.DBX0.0 BYTE 244
LEN := 244
Although the legacy SFC chains can move 244 bytes via three X_PUT calls (3 × 76 = 228 + 16 in a fourth call), the cleanest implementation above that limit is BSEND / BRCV. Reference: Siemens entry 18609206 on SFB 12 / SFB 13 configuration.
9. Diagnostics and Error Codes
RET_VAL from SFC 67 / 68 / 69 follows the SFC standard error schema. A 0 means the job is accepted; negative values are runtime errors; positive values are CPU-dependent protocol errors.
| RET_VAL (hex) | RET_VAL (dec) | Class | Meaning | Remedy |
|---|---|---|---|---|
| W#16#0000 | 0 | Info | Job accepted; data valid on completion | — |
| W#16#7000 | 28672 | Info | No job active (first call with REQ = 0) | — |
| W#16#7001 | 28673 | Info | Job active; BUSY = 1 | Wait for completion |
| W#16#7002 | 28674 | Info | Job active; new REQ ignored while BUSY = 1 | Check trigger logic |
| W#16#8090 | 32912 | Error | Configured S7 connection was not found | Verify NetPro S7 connection, rebuild, re-download |
| W#16#8092 | 32914 | Error | ANY pointer syntax error (length, DB number, area) | Check SD / VAR_ADDR pointers |
| W#16#80A0 | 32928 | Error | Negative acknowledgement from partner | Partner CPU in STOP, resource exhausted, or DB does not exist |
| W#16#80A1 | 32929 | Error | Partner rejected: DB not loaded or wrong length | Check partner DB number, length, download status |
| W#16#80A2 | 32930 | Error | Data type cannot be processed by partner | Align ANY pointer on byte boundary, reduce length |
| W#16#80B0 | 32944 | Error | S7 communication error (bus) | Check MPI cable, termination, baud rate |
| W#16#80B1 | 32945 | Error | Length of transmitted data does not match the SD pointer | Verify SD length on both ends |
| W#16#80C0 | 32960 | Error | Connection aborted by X_ABORT | Restart X_GET / X_PUT |
| W#16#80C1 | 32961 | Error | Resources of the local CPU exhausted | Increase OB1 priority, reduce parallel calls |
| W#16#80C2 | 32962 | Error | Partner not reachable; token-ring failure | Check partner address and cable |
| W#16#80C3 | 32963 | Error | Partner CPU in STOP | Bring partner to RUN; OB82/OB86 will fire |
| W#16#80D0 | 32976 | Error | SFB call in wrong OB context | Move SFC call to OB1 / OB35 |
The complete error-code table is part of the STEP 7 V5.5 — Standard SFCs reference manual.
10. Commissioning and Verification
Use the following checklist to bring the MPI link into service. Each item can be verified on-line from the STEP 7 programming device.
- Online reachability. In SIMATIC Manager, choose PLC → Online → Accessible Nodes. Both CPUs must appear with the configured MPI address. If only one is visible, the wiring or the partner's MPI profile is wrong.
- Connection status. Open NetPro, right-click the S7 connection, and choose Connection Status. The states established and own ID confirm the link is live. If status reads not established, re-download the connection to both stations and verify the connection resource list in HW Config.
- GD check (if used). Open the GD table online; the green row colour confirms successful reception of each package. A red row indicates a mismatch — typically a DB number, offset, or data-type length difference.
- SFC check (if used). Add a VAT (Variable Table) and watch the RET_VAL and BUSY outputs. After triggering REQ once, BUSY should go TRUE for a few OB1 cycles, then drop. RET_VAL must read 0 on completion.
- Data integrity. Write a recognisable pattern (e.g., 0xA5A5) into the local source DB. In the partner's VAT, read the destination DB and verify the pattern appears.
- Fault injection. Pull the MPI cable from one CPU. The local CPU must call OB86 (link failure); the partner should call OB122 (data access error) if a job is in flight. Restore the cable and verify OB86 is exited without a STOP of either CPU.
11. Troubleshooting Matrix
| Symptom | Likely cause | Diagnostic step | Corrective action |
|---|---|---|---|
| BF LED steady on after power up | Cable short, open, or wrong polarity | Measure A-A / B-B continuity, check pins 3 and 8 | Re-wire per Siemens topology rules |
| BF LED flashes | Bus is active but no token with the partner | Compare "Highest MPI address" and baud rate across both stations | Equalize Highest MPI address and baud rate |
| RET_VAL = W#16#8090 | S7 connection missing in NetPro | Open NetPro and check the connection table | Insert an S7 connection, download to both stations |
| RET_VAL = W#16#80A0 | Partner CPU in STOP or has no resources | Check partner's diagnostic buffer | Bring partner to RUN, free a connection resource |
| RET_VAL = W#16#80A1 | DB number or length mismatch | Compare the ANY pointer length to the partner DB length | Use the same length on both sides; verify DB length attribute |
| RET_VAL = W#16#80B0 | MPI bus error during the job | Check wiring and EMC; verify the segment has exactly two terminators | Re-terminate, replace damaged cable |
| GD packages show red | Mismatched DB or data-type | Open GD table in NetPro and compare send/receive rows | Re-align addresses; recompile and re-download |
| BUSY stays TRUE forever | Partner lost power mid-job | Inspect partner CPU SF/BF LEDs | Cycle power on partner; the connection will reset |
| Job completes in tens of seconds, not milliseconds | Too many SFCs called in one OB1 scan | Count active SFC67/68/69 instances per scan | Move lower-priority jobs to OB35; use CONT = TRUE |
| Error 80C2 — partner not reachable | Duplicate MPI address | Online → Accessible Nodes | Assign a unique address to each station |
12. Performance, Timing, and Throughput Notes
MPI is a deterministic token bus, so the worst-case transfer time is bounded by the token rotation time. At 187.5 kbit/s, a single 76-byte X_GET round-trip typically completes in 5 to 25 ms on a lightly loaded bus, dominated by the time the partner CPU needs to assemble the data and respond. With GD configured at a send-cycle factor of 5 and OB1 at 50 ms, the broadcast cycle is 250 ms, regardless of the OB1 scan time.
Throughput scales roughly linearly with baud rate. The CPU 315-2EH14-0AB0 supports 12 Mbit/s on the MPI/DP interface when the bus is rewired for PROFIBUS topology, but the partner CPU 313C tops out at 187.5 kbit/s on its MPI port. For higher throughput, the CPU 315-2PN/DP should be re-addressed on its PROFINET interface and the data path migrated to ISO-on-TCP (T-blocks T_SEND / T_RCV) or S7 connection over Industrial Ethernet — outside the scope of MPI but the usual upgrade path.
13. Frequently Asked Questions
What is the maximum data size per X_GET / X_PUT call on an S7-300?
The user-data limit per SFC 67 / 68 call is 76 bytes on an S7-300 station. For larger payloads, chain multiple calls in a sequence with distinct SD / VAR_ADDR pointers or switch to SFB 12 BSEND / SFB 13 BRCV over the same S7 connection.
Does X_GET / X_PUT require NetPro configuration?
Yes. An S7 connection must be created in NetPro and downloaded to both the local and the partner CPU. Without that connection, SFC 67 / 68 returns RET_VAL = W#16#8090 ("configured S7 connection was not found").
How do I choose between Global Data and X_GET / X_PUT?
Use Global Data when broadcasting up to 22 bytes per package to one or more partners cyclically without any user code. Use X_GET / X_PUT when the exchange must be event-driven, acknowledged, and triggered from the user program, or when a single source/single sink model fits the application.
What happens if the partner CPU is in STOP during a job?
The SFC completes with RET_VAL = W#16#80C3 ("partner CPU in STOP") and OB82 / OB86 will be called on the local CPU. Re-triggering the job after the partner returns to RUN is sufficient; the S7 connection is automatically re-established.
Can I share data between more than two CPUs over the same MPI segment?
Yes, but each S7 connection is point-to-point and consumes one connection resource on each endpoint. Global Data is the preferred method for n-way broadcast up to 16 packages per circle across the entire MPI subnet, subject to the 22-byte-per-package limit.
Why is my MPI link unreachable from the PG even though both CPUs run?
Check that the PG's MPI address is unique (typically 0 or 1) and that the bus profile in Set PG/PC Interface matches the bus profile programmed in the CPUs (187.5 kbit/s). A profile mismatch causes the PG to scan with the wrong baud rate and report "node not found".