S7-300 STEP 7 to TIA Portal Migration: Symbols, HMI, Round-Trip

David Krause15 min read
SiemensTIA PortalTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

S7-300 STEP 7 to TIA Portal Migration: Symbols, HMI Connections, and Round-Trip Compatibility

1. Overview

When a shop acquires a used machine built around a SIMATIC S7-300 CPU 313C with documentation but without the original engineering software, the most common recovery path is to read the existing STEP 7 V5.x project from the PLC, archive the offline/online blocks, and migrate the project to STEP 7 in the TIA Portal. The migration raises three recurring engineering questions:

  1. Why does DB1 show absolute addresses (DB1.DBX0.0) instead of the assigned symbolic name (MAN_OTO) inside the program code?
  2. After a download from TIA Portal, can the same program still be downloaded again from the original STEP 7 V5.x project?
  3. Will a third-party HMI (in this case an Esa panel) lose its S7 connection when the PLC project is migrated and reloaded?

This reference walks through each issue with the engineering depth required to recover a complete, supportable program archive and a working HMI link, then re-load the PLC safely from either tool.

2. Hardware and Software Prerequisites

Component Specification / Article Number Notes
CPU SIMATIC S7-300 CPU 313C, e.g. 6ES7313-5BG04-0AB0 32 KB work memory, 16 DI / 16 DO integrated, integrated counters
Firmware (CPU 313C) V3.3 (latest in family) Earlier variants 5BF03 / 5BG04 / 5BH04 with FW V2.x / V3.0 also supported
Source engineering tool STEP 7 V5.4 or V5.5 (Classic) Required to open the original *.S7P project
Target engineering tool STEP 7 in TIA Portal V13 SP1 or higher (V15 / V16 / V17 / V18 / V19 / V20 supported) Older TIA Portal versions have a smaller device catalog for S7-300
PC adapter PC-Adapter USB A2 (6GK1571-1AA00) or CP 5711 / CP 5512 For MPI/ PROFIBUS online read of the CPU
Ethernet (if used) CP 343-1 Lean / Standard / Advanced, or onboard PROFINET of the CPU (313C-2 PtP / PN versions) For TCP/IP download and HMI traffic
HMI (third party) Esa panel (e.g. SCADA / eTOP series) with Esa project using the Siemens S7 MPI/TCP driver Communication configured in the Esa software, not in STEP 7
CPU 313C variants – confirm before migrating. Three sub-families exist: 313C (integrated I/O, no PN), 313C-2 PtP (with second serial interface), and 313C-2 PN/DP (with PROFINET). The exact MLFB must match the device in the TIA Portal hardware catalog or the migration tool will fail to map the configuration. TIA Portal V18+ supports FW 3.3 of the 313C; earlier FW may require an older TIA Portal version or a GSD-based substitution.

3. Issue 1 — DB1 Shows Absolute Addresses Instead of Symbolic Names

3.1 Symptom

The program code displays references like:

DB1.DBX0.0 // bit 0 of byte 0

instead of the assigned symbolic name:

MAN_OTO // expected symbolic reference

3.2 Root Cause

In STEP 7 V5.x, the symbolic name shown in the LAD/FBD/STL editor is taken from the DB's own property "Symbolic name" field, not the global Symbol Table. There are two places where the text MAN_OTO can live:

  1. Symbol Table (S7-Program > Symbols) — assigns a symbol to a global address (e.g. DB1 MAN_OTO DB 1).
  2. DB Properties > General > Symbolic Name — assigns a name to the data block itself. When the DB is opened, the elements (STAT) can also be given individual symbolic names inside the declaration table.

If only the Symbol Table entry exists, the global reference works, but inside the DB's own declaration view the elements still show as DB1.DBX0.0. To make the element's symbolic name visible inside the program code (in the STL/LAD editor's Symbol Information column), the DB must be opened, the element renamed in the declaration, and the DB recompiled.

3.3 Step-by-Step Fix in STEP 7 V5.x

  1. Open the S7 project in SIMATIC Manager.
  2. In the project tree, right-click DB1 → Object Properties.
  3. On the General > General Part 1 tab, populate the field "Symbolic Name" (e.g. MAN_OTO) and "Symbol Comment".
  4. Open DB1 by double-clicking. In the declaration table, the column Name holds the per-element symbolic name. Edit STAT 0 and enter the name MAN_OTO.
  5. Save and close the DB. STEP 7 recompiles the block and updates the Symbol Information shown in the program editor.
  6. Re-open the calling block (e.g. OB1 or FC10). The address DB1.DBX0.0 should now display the symbolic name MAN_OTO in the Symbol column of the LAD/FBD/STL editor.
Watch the address table. Renaming a STAT in the declaration is purely a symbolic change — the absolute address (here DBX0.0) is preserved, so no logic is altered. However, adding or re-ordering elements before the renamed element will shift the byte offset. Do that only if a full retest is possible.

3.4 Verification

  • Right-click in the program editor and enable View → Display → Symbol Information (or press Ctrl+Q in some configurations). The name MAN_OTO must appear next to the absolute address.
  • Open Options → Symbol Table and check that the row MAN_OTO   DB1   DB 1 exists and is not marked red (a red triangle indicates an unresolved or duplicate symbol).

3.5 Behavior After Migration to TIA Portal

The TIA Portal STEP 7 project migration tool transfers both the global Symbol Table and the DB-internal declarations. After a successful migration, the project is converted to an *.ap20 (TIA V20) archive, and the symbolic name MAN_OTO will be visible in the TIA Portal's PLC tags & watch tables view and inside the program editor without further changes.

4. Issue 2 — Round-Trip Download Between TIA Portal and STEP 7 V5.x

4.1 Short Answer

Yes. After migration, a project can be downloaded from the TIA Portal to the S7-300 CPU and, in the future, the same program can be downloaded back from the original STEP 7 V5.x project — provided the blocks are byte-identical. The PLC stores the compiled program in its load memory; whichever tool most recently downloaded wins.

4.2 Pre-Requisites for a Clean Round-Trip

  1. Keep the STEP 7 V5.x source project unaltered after the first migration. Do not let TIA Portal re-save it — TIA Portal writes a separate *.ap20 file; the original *.S7P stays intact.
  2. After any TIA Portal download, run PLC → Upload from device in STEP 7 V5.x to refresh the offline blocks, or use the STEP 7 Upload Station to PG function to capture the current online program.
  3. Avoid block compare inconsistencies. The STEP 7 V5.x compiler produces a slightly different MC7 code stream than TIA Portal for the same source, so a strict block comparison between the two archives can show false mismatches even when the logic is identical. Use the Timestamp and CRC columns to confirm functional equivalence.

4.3 Step-by-Step Migration Procedure

  1. Back up the STEP 7 V5.x project. Use File → Archive in SIMATIC Manager to produce a *.zip containing the *.S7P file and all sub-projects. Store this on a read-only medium or external drive.
  2. Read the online program from the CPU (if the offline project is missing or out-of-date): PLC → Upload Station to PG. Compare block timestamps with the running machine to confirm parity.
  3. Compact the project: File → Save As and use Save with reorganization to remove deleted blocks. This is the file the TIA Portal migration tool should open.
  4. Open the TIA Portal and select Project → Migrate project → STEP 7 V5.x project. Choose the *.S7P file and a target folder. TIA Portal writes a new *.ap20 TIA Portal project.
  5. Review the Migration log. Warnings about unsupported blocks (e.g. SFB/SFCs older than V2, GRAPH, HiGraph, S7-PDIAG) must be resolved before compiling.
  6. Open the new project in TIA Portal, switch to the project view, and compile the entire S7 program (right-click the PLC_1 → Compile → Software (rebuild all blocks)).
  7. Download to the CPU: select the PLC_1 device, click Download to device, choose the PG/PC interface (e.g. PC Adapter USB A2 — MPI), and start the transfer.
  8. Switch the CPU to RUN only after verifying that the existing machine state allows it. Use Monitor & force in TIA Portal to confirm critical tags before the first RUN.

4.4 What TIA Portal Will Refuse to Migrate

STEP 7 V5.x Element Migration Status Workaround
Standard LAD/FBD/STL blocks (OB, FB, FC, DB, UDT) Full migration None
System data (hardware configuration) Full migration to Devices & Networks Re-check rack layout; some CPs may need a manual substitute
NetPro S7 connections Full migration to Devices & Networks → Connections Verify connection IDs — TIA Portal may renumber
S7-GRAPH, S7-HiGraph, S7-PDIAG Requires optional TIA Portal packages Install the matching add-on package; older FB versions may not be portable
S7-SCL V5.x source Migrated if SCL add-on is installed in TIA Portal Re-compile; minor syntax differences exist between V5.3 and TIA V13+
Old SFB/SFCs (FW < 2.0) Replaced by current versions Re-test affected logic

4.5 Round-Trip Caveats

  • Once you modify, recompile, and download from TIA Portal, the running program on the CPU is the TIA Portal-compiled version. You must upload from device into the original STEP 7 V5.x project (or a fresh project) to keep the archives in sync.
  • If you only use TIA Portal going forward, keep the STEP 7 V5.x archive as a read-only master. Do not let TIA Portal convert and overwrite the source files.
  • Avoid editing the same block simultaneously in both tools. Pick one as the master; the other is the recovery option.

5. Issue 3 — HMI Communication With a Third-Party Esa Panel

5.1 Where the HMI Lives in the Engineering World

The reason the HMI does not appear in the Hardware Configuration (HW Config) of STEP 7 V5.x is that Siemens HMIs are configured in NetPro, not HW Config. A Siemens HMI such as a TP/OP/MP or Comfort panel is added as a station in NetPro, given an MPI/PROFIBUS/Ethernet node, and the S7 connection is established there. Esa, however, is a third-party vendor and uses its own configuration utility (typically Esa Project Editor or EsaCAD). The S7 link on the Esa side is a single S7-MPI / S7-TCP driver entry that points to the PLC's MPI address or IP/port (default TCP 102 for S7 communication).

5.2 What the Migration Will and Will Not Break

  • What survives untouched: the Esa project on the HMI itself (stored on the panel's internal flash or compact flash). The Esa panel continues to poll the same DB areas as long as the PLC data layout (offsets, lengths) is unchanged.
  • What must be re-validated after any download to the CPU: the MPI address, the baud rate, the rack/slot of the CPU, and (for TCP) the IP address, subnet mask, and the S7 connection resource. If TIA Portal assigned a new connection ID or shifted the S7 connection to a different CP, the Esa side still works — Esa talks to the CPU directly, not to a named STEP 7 connection.

5.3 Checklist Before Downloading From TIA Portal

  1. Capture the current CPU's MPI / IP configuration using PLC → Ethernet / MPI Properties in STEP 7 V5.x or the Online & Diagnostics view in TIA Portal.
  2. Verify the same address is configured in the Esa project (e.g. MPI address 2, baud 187.5 kbps; or IP 192.168.0.10, port 102).
  3. Do not change the CPU's MPI or IP address in the new TIA Portal project. If you must, update the Esa project at the same time and plan a brief HMI outage.
  4. After download, test one or two tags from the Esa panel to confirm bidirectional communication. A quick force in TIA Portal on a tag read by the HMI is the fastest end-to-end check.
PUT/GET access rights. Modern S7-300 firmware defaults the CPU to no PUT/GET access from foreign partners. If the Esa panel only reads/writes via raw S7 functions and you see a SF LED on the CPU with diagnostic buffer entry "Security function: connection refused - no PUT/GET access", enable Permit access with PUT/GET from remote partner in the CPU's protection properties. Re-test after enabling.

6. NetPro vs TIA Portal Device & Networks

STEP 7 V5.x separates hardware (HW Config — modules in racks) from networking (NetPro — S7 connections, MPI/PROFIBUS subnet configuration). TIA Portal collapses these into a single Devices & Networks editor:

STEP 7 V5.x TIA Portal Equivalent Notes
HW Config (rack, modules) Device view — PLC_1 → Device configuration Drag modules from the hardware catalog
NetPro (S7 connections) Network view — Connections Drag a connection line between two devices
Set MPI/PROFIBUS address on a station Properties of the station → PROFIBUS address / MPI address Same field semantics, but on a per-port basis
PG/PC assignment table Online & Diagnostics → Assign PG/PC Inline dropdown in TIA Portal

For a third-party Esa HMI, neither HW Config nor NetPro will show the panel. The migration therefore introduces no HMI entry to delete or to reconfigure — the Esa project is the sole source of truth for HMI-side parameters.

7. Recommended Workflow for a Second-Hand S7-313C Machine

  1. Document the current machine state (mode selector, E-Stop, safety circuits).
  2. Read the existing project from the CPU with STEP 7 V5.5: PLC → Upload Station to PG. Save and archive.
  3. Resolve DB1 symbolic names (Section 3) and any other unresolved symbols before migration.
  4. Install TIA Portal V18 or V20 (matching the CPU's FW). Migrate the archived *.S7P to *.ap20.
  5. Compile, then perform a dry-run block compare: open Online → Compare offline/online in TIA Portal. The compiled blocks must match the CPU's running program before any field download.
  6. Schedule a short machine stop. Save the current process values to a recipe or DB snapshot. Switch the CPU to STOP.
  7. Download from TIA Portal. Switch back to RUN. Verify the machine's safety circuits and primary I/O.
  8. Validate Esa HMI tags end-to-end. Confirm trends, alarms, and write-back commands.
  9. Archive both the *.S7P (STEP 7 V5.x) and the *.ap20 (TIA Portal) on redundant media.

8. Verification & Commissioning Checklist

Item Pass Criterion Tool
Block consistency All OBs, FBs, FCs, DBs, UDTs compile without warnings TIA Portal → Compile
Symbol resolution No red triangles in the Symbol Table; MAN_OTO visible in editor Symbol Table / program editor
Hardware match Online ↔ offline hardware comparison shows no difference Online → Compare
CPU diagnostic buffer No IO/Configuration error, Security function, or Time-of-day faults after first RUN Online & Diagnostics
HMI tag exchange Read and write a value from the Esa panel; observe update in TIA Portal watch table Esa runtime + TIA Portal watch table
Round-trip integrity Download from TIA Portal, then upload to a fresh STEP 7 V5.x project — blocks should match Both tools
Safety chain E-Stop, light curtain, guard door respond within one PLC scan Functional test per machine PHA

9. Troubleshooting Matrix

Symptom Likely Cause Fix
Only DB1.DBX0.0 shows; MAN_OTO missing Symbolic name not set in DB properties or in the declaration table Edit DB1 → Properties → Symbolic Name; edit the Name column of the declaration; recompile
Migration tool reports "The project uses a CPU that is not installed in the device catalog" TIA Portal version does not contain the CPU's MLFB or FW Update TIA Portal to a version that includes the CPU FW; or install the HSP (Hardware Support Package)
Esa panel shows "No connection" after TIA Portal download PUT/GET access disabled in CPU protection Enable Permit access with PUT/GET from remote partner in the CPU properties
Esa panel shows "No connection" — PUT/GET is enabled, but the IP changed TIA Portal project assigned a new IP to the CPU or to a CP Restore the original IP or update the Esa project to the new IP
Block compare shows differences after TIA Portal → STEP 7 round-trip MC7 / compiler differences between the two tools Compare timestamps and CRC; if logic is identical, treat the compare warning as cosmetic
CPU stays in STOP with "OB not loaded" OB1 or an error OB (OB82/OB85/OB86/OB121) is missing in the new project Add the missing OBs or copy them from the STEP 7 V5.x project before download
Comment text disappears after migration Comments stored in the offline project only and not in the system data Enable Comments in the PLC in TIA Portal download options

10. Long-Term Maintenance Recommendation

Once the migration is complete, establish a single-source-of-truth policy:

  • Use TIA Portal as the primary engineering tool. The current TIA Portal versions (V18 / V19 / V20) support the full S7-300 / S7-400 family, including the 313C with FW 3.3, and integrate the HMI configuration if you ever switch to a Siemens panel.
  • Archive both the original STEP 7 V5.x project and the migrated TIA Portal project in version-controlled media. Tag the archive with the CPU's serial number and FW version.
  • After any future hardware change (CPU replacement, CP swap), re-run the migration wizard only if you need to re-baseline the project. The TIA Portal archive is self-contained and portable between engineering PCs.
  • Keep the PG/PC interface drivers up to date. TIA Portal V20 ships with newer PC-Adapter USB A2 drivers that improve the MPI connection stability on Windows 10 / 11 22H2 and later.

11. FAQ

Why does DB1 only show DB1.DBX0.0 and not the symbolic name MAN_OTO inside the program?

The symbolic name must be set in the DB's own properties (Symbolic Name field) and the element must be renamed in the declaration table. An entry in the global Symbol Table alone is not enough — open DB1, edit the Name column for STAT 0 to MAN_OTO, save, and reopen the calling block.

After I download the program from TIA Portal, can I still download from STEP 7 V5.x later?

Yes. Keep the original STEP 7 V5.x project untouched (TIA Portal writes a separate *.ap20). If you modify the program in TIA Portal and download, the CPU holds the latest compiled version; you can re-upload to the STEP 7 V5.x project or simply load the older STEP 7 V5.x project back into the CPU at any time, provided the block logic is intact.

Will my Esa HMI lose communication when I switch to TIA Portal?

No — the Esa project lives on the panel itself and uses a direct S7-MPI / S7-TCP driver. The migration does not delete or change the Esa project. Just make sure the CPU's MPI address or IP address remains the same and that PUT/GET access is permitted in the CPU's protection settings.

The CPU goes into SF and the diagnostic buffer shows a security violation after the migration. What happened?

Modern S7-300 firmware defaults to blocking remote PUT/GET access. Esa panels that use raw S7 read/write functions need this option enabled: in TIA Portal, open the CPU → Properties → Protection & Security → Connection mechanisms and tick Permit access with PUT/GET from remote partner, then re-download the hardware configuration.

Does the migration tool keep all comments and symbol names?

Yes, when the TIA Portal option Comments in the PLC is enabled at download time. Both network comments (NW Kommentar) and block/segment comments are transferred. Ensure the source STEP 7 V5.x project contains the comments in the *.S7P archive, not only in the documentation files.
Back to blog