S7-300 to S7-1200 PUT/GET Communication Setup in STEP 7 and TIA

David Krause13 min read
Industrial NetworkingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview: Mixing S7-300 and S7-1200 on a Single Ethernet Subnet

Engineers often inherit brownfield systems where an S7-300 CPU 317-2 PN/DP programmed in SIMATIC Manager (STEP 7 V5.x) must exchange cyclic or event-driven data with an S7-1200 CPU 1214 DC/DC/Rly configured in TIA Portal V13. Both controllers carry a PROFINET interface, so they can sit on the same physical Ethernet segment, but the two engineering tools and two firmware generations impose constraints on which transport mechanism is viable.

Three transport families are normally considered:

  1. S7 Communication (PUT/GET) – single-sided, connection-oriented, optimal for small-to-medium peer-to-peer data exchange. Works between S7-300 and S7-1200 provided that optimized data access on the S7-1200 side is disabled and the S7-1200 is configured as a PUT/GET server.
  2. Native TCP via ISO-on-TCP (RFC 1006) – implemented with FB 63 TSEND, FB 64 TRCV on S7-300 (or legacy FC 5 AG_SEND / FC 6 AG_RCV) and TCON / TSEND / TRCV / TDISCON on S7-1200. Useful when peer-to-peer payload does not map cleanly to S7 data areas.
  3. Profinet IO – not applicable here, because the S7-300 and S7-1200 are peers, not IO controllers/devices in this scenario.

For the typical "read a few hundred bytes from a remote DB and write a few bytes back" requirement, PUT/GET is the shortest path and is the recommended first option. TCP is the fallback when PUT/GET block sizes, partner counts, or DB access rules get in the way.

2. Hardware and Firmware Prerequisites

2.1 S7-300 Side – 6ES7 317-2EK14-0AB0 (CPU 317-2 PN/DP)

Parameter Value
Order number (typical variant) 6ES7 317-2EK14-0AB0 (Firmware V3.x)
PROFINET interface X2, two-port switch (so daisy-chaining is supported)
S7 connection resources Up to 16 (firmware-dependent; V3.x supports 16 S7 connections)
Engineering tool STEP 7 V5.5 + SP4/HF or STEP 7 V5.6
Required blocks FB 14 (PUT) and FB 15 (GET) from the "Standard Library > Communication Blocks"

Older CPU 317-2 PN/DP variants (6ES7 317-2AJ10-0AB0, firmware V2.x) ship with a reduced connection count (8 S7 connections). Verify the firmware release with PLC > Module Information > Firmware in STEP 7 before allocating resources.

2.2 S7-1200 Side – CPU 1214 DC/DC/Rly

The CPU 1214C DC/DC/Rly is identified by order number 6ES7 214-1HE30-0XB0 (or later revisions). Its on-board Ethernet port is a single PROFINET interface with the following published limits:

Item Value
Ethernet ports 1 (PROFINET, 10/100 Mbit/s)
HMI connections (reserved / max) 4 / 12 (firmware V4.x)
PG connections (reserved / max) 1 / 1
S7 / PUT-GET server connections (reserved / max) 3 / 8
Open User Communication (TCP/UDP) connections (reserved / max) 0 / 8
Total connections (reserved / max) 34 / 68 (firmware V4.x; V1/V2 firmwares have lower ceilings)

Source: Siemens S7-1200 Manual Collection – CPU 1214C Communications Specifications.

Planning pitfall: the S7-1200 reserves 4 HMI and 1 PG connection by default, leaving a maximum of 8 S7 server slots for PUT/GET partners. If a single S7-1200 must talk to many S7-300 stations, you must reduce the reserved HMI count or migrate to TCP.

2.3 Engineering Tools

  • STEP 7 V5.5 SP4 (or V5.6) for the S7-300 project. TIA Portal V13 cannot configure the S7-300 in this scenario unless the project is migrated.
  • TIA Portal V13 SP1 (Update 5) or later for the S7-1200 project. Update 7 or newer is recommended to avoid TCON wizard bugs in early V13 releases.
  • NCM S7 Industrial Ethernet (optional, ships with STEP 7) for editing the S7-300 connection table.

3. Choosing the Communication Mechanism

Criterion PUT/GET (S7 Comm) TCP (Open User Comm)
Block on S7-300 FB 14 / FB 15 FB 63 TSEND / FB 64 TRCV (or FC 5/6)
Block on S7-1200 Extended instruction "PUT" / "GET" TCON, TSEND, TRCV, TDISCON
Max payload per call 160 bytes (PUT) / 160 bytes (GET) on S7-300 classic; up to 400 bytes on S7-1200 V4 8192 bytes (TSEND/TRCV)
Trigger model One-shot per REQ edge; CPU schedules transport Application-driven, requires DONE/NERROR polling
Optimized DBs on S7-1200 NOT supported – DB must be "non-optimized" (standard access) Supported (S7-1200 sends/receives raw bytes)
Connection consumption Consumes 1 S7 connection on each side Consumes 1 OUC connection on S7-1200, 1 ISO-on-TCP connection on S7-300
Configuration effort Low – connection table + block call Medium – TSAP/port pairing, LEN/ID matching

The official Siemens FAQ Entry ID 92269951 confirms that PUT/GET between a STEP 7-configured S7-300 and a TIA-configured S7-1200 is fully supported when the S7-1200 side uses non-optimized data blocks and the S7-1200 is configured to act as a PUT/GET server.

4. Step-by-Step: PUT/GET Configuration (Recommended Path)

4.1 STEP 7 (S7-300) Project Setup

  1. Open the S7-300 project in STEP 7 V5.5.
  2. In HW Config, double-click the CPU 317-2 PN/DP and open the "Properties > PROFINET Interface" dialog. Set a fixed IP address (e.g., 192.168.0.10), subnet mask 255.255.255.0, and confirm that the PROFINET interface is enabled. Do not assign a PROFINET IO device role here.
  3. Save and recompile the hardware (Station > Save and Compile).
  4. Open NetPro (or use NCM S7 Industrial Ethernet). Right-click the S7-300 CPU icon and choose Insert New Connection.
  5. In the connection wizard, set Partner = "Unspecified" and Type = "S7 Connection". Click OK.
  6. In the connection properties:
    • Enter the Partner IP Address of the S7-1200 (e.g., 192.168.0.20).
    • Leave Partner Rack/Slot = 0 / 1 (slot 1 is the CPU slot on S7-1200).
    • Confirm that the local connection endpoint (TSAP) is auto-assigned, e.g., 10.01. The partner TSAP is also left at default 10.01 – both sides match.
  7. Note the local Connection ID shown in the connection table (e.g., 1). You will reference this ID when calling FB 14/FB 15.
  8. Download the hardware and connection configuration to the S7-300.

4.2 TIA Portal (S7-1200) Project Setup

  1. Open the S7-1200 project in TIA Portal V13.
  2. In Device Configuration, select the CPU and open Properties > PROFINET Interface > Ethernet addresses. Assign 192.168.0.20 with mask 255.255.255.0.
  3. In Properties > General > Protection & Security (or "Connection Mechanisms" on earlier V13 revisions), ensure the option "Permit access with PUT/GET communication from remote partner (PLC, HMI, OPC, …)" is enabled. Without this checkbox, PUT/GET partners cannot open an S7 connection to the S7-1200.
  4. Open the DB that you want the S7-300 to read or write. Right-click the DB in the project tree and select Properties > Attributes. Uncheck "Optimized block access". Set the Retain attribute as required.
  5. Compile and download the hardware and program to the S7-1200.
Why optimized access must be off: the S7-300 PUT/GET block can address the S7-1200 only with absolute byte offsets inside the DB (e.g., DB200.DBX0.0 BYTE 100). Optimized DBs hide the absolute offset behind symbolic names and re-pack variables at compile time, so the partner cannot form a valid byte-level address list.

4.3 Calling FB 14 (PUT) and FB 15 (GET) on the S7-300

Both FBs are part of the CPU operating system; they live in the "Standard Library > Communication Blocks" and are not installed as separate source files.

FB 14 PUT – request to write data to the S7-1200

Input Type Meaning Example value
REQ BOOL Rising edge starts the transfer M10.0
ID WORD Connection ID from NetPro W#16#0001
DONE BOOL Transfer complete (status) M11.0
ERROR BOOL Error flag M11.1
STATUS WORD Error/detail status code MW12
ADDR_1 ANY Partner area to write to P#DB200.DBX 0.0 BYTE 100
SD_1 ANY Local source area P#DB100.DBX 0.0 BYTE 100

FB 15 GET – request to read data from the S7-1200

Input Type Meaning Example value
REQ BOOL Rising edge starts the read M10.1
ID WORD Connection ID W#16#0001
ADDR_1 ANY Partner area to read from P#DB200.DBX 0.0 BYTE 50
RD_1 ANY Local destination area P#DB110.DBX 0.0 BYTE 50

Calling ladder example (FB 14 PUT):

// OB1 cycle – S7-300
// Trigger PUT every 1 s via clock bit
A   M10.0
=   L 0.0
A   L 0.0
FP  M10.2
=   "put_trigger"      // rising edge flag
CALL  FB 14, DB14
 REQ  := "put_trigger"
 ID   := W#16#0001
 DONE := M11.0
 ERROR:= M11.1
 STATUS:=MW12
 ADDR_1:=P#DB200.DBX 0.0 BYTE 100
 SD_1 :=P#DB100.DBX 0.0 BYTE 100

4.4 Calling PUT/GET on the S7-1200 Side

The S7-1200 is the passive partner in PUT/GET. No client code is required on the S7-1200: the firmware answers incoming PUT/GET requests automatically once the checkbox described in §4.2 is enabled. Programmers only need to ensure that the data blocks used as partners are present, non-optimized, and downloaded.

For test purposes, an optional ladder snippet can confirm the data exchange by mirroring the received bytes into a flag word or visible HMI tag.

5. Alternative Path – TCP / ISO-on-TCP with AG_SEND / AG_RCV and TCON

If the application payload exceeds PUT/GET limits, or if multiple S7-300 stations must share a single S7-1200 connection budget, switch to Open User Communication.

5.1 S7-300 Side – Legacy FC 5 / FC 6 or FB 63 / FB 64

Legacy programs still use FC 5 AG_SEND and FC 6 AG_RCV from the "Standard Library > Communication Blocks". Both reference a connection descriptor (a 12-byte ANY pointing at a UDT-style DB built by NetPro). Newer projects should migrate to FB 63 TSEND / FB 64 TRCV with an explicit connection DB built by the TCON wizard or manually written to the "Standard Library > Communication Blocks > Blocks for Open User Communication" templates.

5.2 S7-1200 Side – TCON / TSEND / TRCV / TDISCON

  1. In TIA Portal, drag TCON from the "Communications" palette into a function block. A wizard opens.
  2. Choose TCP (not ISO-on-TCP) for the simplest case; choose ISO-on-TCP if you must interoperate with an existing AG_SEND/AG_RCV or FB 63/64 project on the S7-300.
  3. Enter the partner IP address (192.168.0.10) and the partner port/TSAP. Default TCP port is 2000; default ISO-on-TCP TSAPs are 10.00 on each side.
  4. Connect TSEND and TRCV to the connection ID returned by TCON. Use DONE, BUSY, and ERROR for handshake. LEN is the number of bytes to send; on TRCV, leave LEN = 0 to accept whatever arrives.
  5. Call TDISCON at CPU restart or shutdown to release the socket.

TCP bypasses the optimized-access restriction: you can send a tagged UDT, SCL STRUCT, or even raw byte slices, and the partner decodes them. Trade-off: you must implement length, sequence, and timeout handling in user code.

6. Connection Resource Budgeting

Resource S7-300 CPU 317-2 PN/DP (FW 3.3) S7-1200 CPU 1214C (FW 4.x)
Total configurable connections 16 (8 S7 + 8 OUC depending on CPU) 68 max (34 reserved)
Default reserved for PG/HMI 1 PG / 0 HMI 1 PG / 4 HMI
S7 connections used by PUT/GET per partner 1 1 (server role)
Recommended headroom Keep 2 free for online commissioning Keep 4 free for HMIs and Web server
Diagnostic command on the S7-1200: in the Online & Diagnostics view, open "Diagnostics > Connection Information" to see live connection state, partner IP, and which connections are still free.

7. Verification and Commissioning Checklist

  1. Physical layer – confirm PROFINET link LEDs on both CPUs. ping 192.168.0.20 from the PG must succeed before STEP 7 can establish any S7 connection.
  2. S7 connection state – in STEP 7, right-click the S7-300 CPU in NetPro and choose Connection Status. The state should read Established. If it shows Not connected, check that the S7-1200 PUT/GET server checkbox is enabled and that the S7-1200 program is running (not in STOP).
  3. Single-shot PUT test – write a known pattern (e.g., W#16#AA55) into the S7-300 source DB, trigger PUT, and watch the S7-1200 DB on a watch table.
  4. Single-shot GET test – toggle a bit in the S7-1200 DB from a watch table, trigger GET on the S7-300, and verify the byte at the destination.
  5. Cyclic PUT/GET – route the REQ edges from a clock bit (e.g., CPU clock flag MB0 bit 7) and observe DONE toggling every cycle.
  6. STATUS evaluation – any non-zero STATUS (e.g., W#16#001F, W#16#8085) should be captured in the cross-reference HMI page for live troubleshooting.

8. Troubleshooting Matrix

Symptom Most likely root cause Corrective action
Connection status: "Not connected" on S7-300, no log entry S7-1200 PUT/GET server checkbox disabled Enable "Permit access with PUT/GET communication" in TIA Portal, recompile, download
STATUS = 8085 (object access error) Optimized access on the partner DB Uncheck "Optimized block access" on the S7-1200 DB
STATUS = 001F (partner not reachable) Wrong IP or firewall on switch port Ping from PG; verify subnet mask; clear any VLAN ACL
Connection established, but no data appears in DB ANY pointer length mismatch (SD_1 vs ADDR_1) Match BYTE counts and ensure DB number exists on S7-1200
DONE toggles once then ERROR stays low but no further updates Missing rising edge on REQ Use edge bit (FP) instead of a level signal
S7-1200 reports "No resources" on connection attempt All S7 connection slots used Reduce reserved HMI count or migrate some links to TCP
Intermittent timeouts after 30 s Watchdog in TCP mode too short Increase keep-alive interval on both sides

9. Migration and Lifecycle Notes

  • The CPU 317-2 PN/DP has been announced for discontinuation of marketing (legacy spare-part phase). For new installations, migrate to a CPU 31x PN/DP current revision or a S7-1500 with PROFINET 2-port switch.
  • TIA Portal V13 itself has reached its end-of-life mainstream support. Plan to migrate the S7-1200 project to TIA Portal V16 or later so that future firmware updates remain installable.
  • When migrating from PUT/GET to TCP, keep the same DB offsets on the S7-300 side so the partner application logic remains unchanged.
  • If you ever need S7 communication between an S7-1200 (firmware V4.0 or later) acting as the client and an S7-300, the S7-1200 must be configured to run the PUT/GET extended instructions with the partner set to "Unspecified" or to a partner CPU on the same subnet.

10. Field-Proven Recommendations

  1. Document every PUT/GET connection in a single table: Connection ID, partner IP, partner TSAP, source DB, partner DB, length, and trigger source. This avoids hunting through NetPro and watch tables during a hot call.
  2. Always allocate non-overlapping DB areas on the S7-1200 when multiple S7-300 stations read/write the same DB. PUT/GET does not arbitrate conflicts.
  3. For deterministic cycle times, drive PUT/GET from a timed interrupt (e.g., OB35 at 100 ms) rather than from OB1. OB1 cycle jitter can stretch the effective cycle to several hundred milliseconds.
  4. Mirror critical PUT/GET data into a second DB and verify it via HMI alarms. The 317-2 PN/DP and 1214C both support DB-driven HMI tags without additional code.
  5. Capture FB 14 / FB 15 STATUS into an array of words and expose them to the HMI. This is faster than going online with STEP 7 during a plant incident.

11. Glossary

Term Meaning
TSAP Transport Service Access Point – local/partner identifier inside an S7 connection
Optimized block access S7-1200/1500 attribute that hides absolute byte offsets and uses symbolic addressing only
OUC Open User Communication – TCP/UDP/ISO-on-TCP via TCON
REQ Block input that initiates a transfer on its rising edge
ANY pointer S7 data type that encapsulates an address + length for block parameters

FAQ

Can an S7-300 (STEP 7) and an S7-1200 (TIA Portal V13) really use PUT/GET together?

Yes. Siemens Entry ID 92269951 confirms that S7 communication between an S7-300 programmed in STEP 7 V5.x and an S7-1200 programmed in TIA Portal works, provided the S7-1200 has "Permit access with PUT/GET communication" enabled and the partner data blocks are non-optimized.

Why does PUT/GET fail when the S7-1200 DB uses optimized access?

PUT/GET on the S7-300 side addresses remote data by absolute byte offset (e.g., DB200.DBX 0.0 BYTE 100). Optimized DBs hide absolute offsets behind symbolic names, so the S7-300 cannot form a valid address list. Uncheck "Optimized block access" in the DB properties to fix this.

How many PUT/GET partners can a CPU 1214C serve?

Up to 8 active S7 connections per firmware V4.x CPU 1214C (3 reserved, 8 max), as documented in the S7-1200 Manual Collection. Each partner consumes one slot. Reduce the reserved HMI count if more partner slots are required.

What is the largest payload per PUT/GET call?

S7-300 FB 14 / FB 15 transfers up to 160 bytes per call (single ADDR_1/SD_1 pair) on classic CPUs. The S7-1200 PUT/GET server accepts the same range; on firmware V4.x the upper limit is documented at 400 bytes per request.

When should I choose TCP instead of PUT/GET?

Switch to TCP (FB 63/FB 64 on S7-300 plus TCON/TSEND/TRCV on S7-1200) when payload exceeds the PUT/GET limit, when the S7-1200 connection budget is exhausted, or when the application requires mixed endianness, multi-frame buffering, or data that does not map cleanly to a DB area.

Back to blog