S7-300 to S7-300 Communication Setup with TIA Portal V13 SP1

David Krause12 min read
S7-300SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: Bridging Independent S7-300 Machines with a Link PLC

Brownfield factory cells based on SIMATIC S7-300 controllers typically evolve without a unified network plan. When a new machine is added that must exchange a defined I/O dataset with five pre-existing cells, pulling dedicated PROFIBUS cable runs is rarely practical. The field-proven alternative is to install a link PLC that sits on the same Industrial Ethernet subnet as the existing cells, and exposes a PROFIBUS segment terminated by DP/DP couplers to the new vendor machine.

This reference covers the full engineering of that bridge using TIA Portal V13 SP1, including:

  • Hardware selection between CP 343-1 Lean and a CPU 315-2 PN/DP as the link controller.
  • Why the CP 343-1 Lean is restricted to server role in S7 connections.
  • How to keep alterations to the existing cell programs to a minimum.
  • Configuring S7 connections with PUT/GET in TIA Portal V13 SP1.
  • Integrating DP/DP couplers (Siemens 6ES7158-0AD01-0XA0) on the new machine's PROFIBUS.
  • Commissioning, diagnostics, and verification steps.
Engineering assumption: The new vendor machine exposes 4 DP/DP couplers daisy-chained on a single PROFIBUS DP segment. Each existing cell has either a CPU 315-2 PN/DP or an S7-300 station with a CP 343-1 communications processor. All stations share one Industrial Ethernet subnet (10.10.0.0/16 in the example).

Prerequisites

Item Specification Notes
Engineering station TIA Portal V13 SP1 (Update 4 or later) with STEP 7 Professional Required for S7-300 hardware catalog V13 SP1
Link PLC CPU 315-2 PN/DP (6ES7315-2EH14-0AB0, firmware V3.3) Provides PN interface; acts as S7 client and server
Alternative link PLC CPU 315-2 DP (6ES7315-2AG10-0AB0) + CP 343-1 Lean (6GK7343-1CX10-0XE0) Lean acts only as server - see limitations below
DP/DP coupler 6ES7158-0AD01-0XA0 One per existing PROFIBUS segment to bridge
Existing cell PLCs CPU 315-2 PN/DP or CPU 31x with CP 343-1 Each must permit PUT/GET (allow-put-get = TRUE)
PROFIBUS cable 6XV1830-0EH10 (purple, 2-wire, shielded) Daisy-chain the 4 DP/DP couplers from the link PLC's DP port
Ethernet cable CAT6 / Industrial Ethernet FC TP Star or line topology to existing switches

Hardware Selection: Why CPU 315-2 PN/DP Beats CP 343-1 Lean as a Link

The original concept was to drop a CPU 315-2 DP with a CP 343-1 Lean into the new machine. The architecture is physically possible, but the CP 343-1 Lean has a hard functional restriction that determines where it can sit in the topology:

Property CP 343-1 Lean (6GK7343-1CX10-0XE0) CPU 315-2 PN/DP (6ES7315-2EH14-0AB0)
Role in configured S7 connection Server only Client or server
PUT/GET initiator No (cannot initiate PUT/GET) Yes
Number of S7 connections 4 maximum 14 (S7-300 CPU 315 PN/DP)
Integrated PROFINET interface No (separate CP) Yes (2-port switch)
Integrated PROFIBUS DP master No (CPU DP master only) Yes
Suitable as link PLC? Only if 4 incoming connections are acceptable and a separate master initiates all PUT/GET Yes - acts as initiator to all 5 partner CPUs

Because the link PLC must read signals from five partner cells and write consolidated tags to the DP/DP couplers, the link must be able to initiate PUT/GET transfers. A partner that holds a CP 343-1 Lean can only answer incoming requests, not start them. With one CP 343-1 Lean there is no way to drive the data exchange on its own.

Field result: After confirming this restriction, the engineering team sourced a CPU 315-2 PN/DP to replace the Lean/DP combination. The integrated PN interface replaced the CP entirely and provided 14 S7 connection resources, leaving 5 connections for the partner cells and 9 free for further expansion.

Network Topology

Industrial Ethernet Subnet 10.10.0.0/16 Cell ACPU 315-2 PN/DP10.10.0.11 Cell BCPU 315-2 PN/DP10.10.0.12 Cell CCPU + CP 343-110.10.0.13 Cell DCPU + CP 343-110.10.0.14 LINK PLCCPU 315-2 PN/DP10.10.0.10S7 client + server PROFIBUS DP Segment (1.5 Mbps, addresses 3-6) DP/DP #1Slave 3 DP/DP #2Slave 4 DP/DP #3Slave 5 DP/DP #4Slave 6

The link PLC is on the same Ethernet subnet as the four partner cells. Its PROFIBUS DP master port daisy-chains the four DP/DP couplers inside the new vendor machine. Each coupler passes a pre-defined slice of process data between the link PLC's PROFIBUS image and the new machine's own PROFIBUS master.

Step-by-Step: Configuring the Link PLC in TIA Portal V13 SP1

Step 1 - Create the project and add the link PLC

  1. Open TIA Portal V13 SP1 and select Create new project.
  2. In the project tree, choose Add new device > SIMATIC S7-300 > CPU > CPU 315-2 PN/DP > 6ES7315-2EH14-0AB0 V3.3.
  3. Open Device view and confirm the integrated PROFINET interface and PROFIBUS DP master appear in slot 2 (PN) and slot 2 (X2 DP).

Step 2 - Configure the PROFINET interface

  1. Select the PN interface and assign IP 10.10.0.10, subnet mask 255.255.0.0.
  2. Add the partner CPUs as Unspecified CPU 300 in Devices & Networks > Network view. Enter each partner's IP (10.10.0.11 through 10.10.0.14) under PROFINET interface > Ethernet addresses.
  3. Create a logical S7 connection from the link PLC to each partner. The endpoint on the partner side is left as unspecified; the partner IP is entered manually.

Step 3 - Configure the S7 connection properties

For each of the four S7 connections, set the following parameters in Properties > General > Connection mechanisms:

Parameter Link PLC (local) Partner PLC (remote)
Connection type S7 connection S7 connection
Local ID (hex) 1, 2, 3, 4 n/a (unspecified)
Active connection establishment Establish active Establish passive
One-way / Two-way Two-way Two-way
Max data length PUT/GET 160 bytes per call Partner must permit (see Step 4)

Step 4 - Enable PUT/GET access on the partner S7-300 CPUs

On every partner CPU that exposes its data, the PUT/GET access flag must be enabled. This is a CPU property in STEP 7 / TIA Portal:

  1. Open the partner's project (or online configuration if the original project is unavailable).
  2. Select the CPU and go to Properties > Protection & Security > Connection mechanisms.
  3. Tick Permit access with PUT/GET communication from remote partner.
  4. Compile and download to the partner CPU.
Minimal-impact change: Enabling PUT/GET is a single CPU property change and does not require touching the partner's user program. The existing S7 program continues to run unchanged; only the protection bit is flipped.

Step 5 - Program PUT/GET in the link PLC

Use the PUT and GET instructions from the Instructions > Communication > S7 Communication task card. The block interface for the link PLC program is:

// Data block DB100 - shared with vendor machine via PROFIBUS
DATA_BLOCK "DB_Vendor_Image"
  STRUCT
    From_CellA : WORD;     // status word from Cell A
    From_CellB : WORD;     // status word from Cell B
    From_CellC : WORD;     // status word from Cell C
    From_CellD : WORD;     // status word from Cell D
    To_All     : WORD;      // consolidated command broadcast
  END_STRUCT
END_DATA_BLOCK

OB1 cyclic call (SCL example):

// Read from Cell A (partner IP 10.10.0.11, connection ID 1)
"GET_DB".ID        := 1;                     // connection ID
"GET_DB".REQ       := %DB5.DBX0.0;           // 1 Hz trigger from cyclic OB
"GET_DB".DONE      := "CellA_Done";
"GET_DB".ERROR     := "CellA_Err";
"GET_DB".STATUS    := "CellA_Status";
"GET_DB".ADDR_1    := P#DB10.DBX0.0 BYTE 2;  // partner DB10, 2 bytes
"GET_DB".RD_1      := P#DB100.DBX0.0 BYTE 2; // local target

// Write to Cell A
"PUT_DB".ID        := 1;
"PUT_DB".REQ       := %DB5.DBX0.1;
"PUT_DB".ADDR_1    := P#DB11.DBX0.0 BYTE 2;
"PUT_DB".SD_1      := P#DB100.DBX10.0 BYTE 2;

Each GET/PUT call is fired once per cycle on a 100 ms tick from OB35 to avoid flooding the partner CPUs.

Step-by-Step: Integrating the DP/DP Couplers

  1. In the link PLC's device configuration, open the PROFIBUS subnet and set master address to 2 with transmission rate 1.5 Mbps.
  2. From the hardware catalog, drag the DP/DP coupler (6ES7158-0AD01-0XA0) four times onto the PROFIBUS subnet and assign PROFIBUS addresses 3, 4, 5, 6.
  3. For each coupler, open the device properties and define the I/O length on the link side (e.g. 4 words in / 4 words out per coupler). The vendor must mirror the same length on the opposite side.
  4. Add a global data block (DB200) on the link PLC with one slice per coupler, mapped symbolically to the vendor's image.

DP/DP coupler addressing table

PROFIBUS address Coupler ID Inputs (link → vendor) Outputs (vendor → link) Slot in link PLC image
3 DP/DP #1 IB 100-107 QB 100-107 Slot 0
4 DP/DP #2 IB 108-115 QB 108-115 Slot 1
5 DP/DP #3 IB 116-123 QB 116-123 Slot 2
6 DP/DP #4 IB 124-131 QB 124-131 Slot 3

Connection Resource Accounting

Both the link PLC's CPU and the partner CP/CPU modules have a hard limit on concurrent S7 connections. Crossing the limit raises SF on the partner and the connection is silently rejected.

Device Connection resources total Reserved for HMI / PG Available for link Used by this project
CPU 315-2 PN/DP (link) 14 2 (HMI panel + PG) 12 5 (4 partners + 1 spare)
CPU 315-2 PN/DP (cell) 14 2 12 1
CP 343-1 Lean (cell) 4 1 3 1
CP 343-1 (full, cell) 16 2 14 1
Watch-out: If a partner cell already has its own HMI panel, PG socket, and existing S7 connections to other cells, the link PLC's connection may be the one bumped when the partner's connection count saturates. Use Online & Diagnostics > Connection resources on the partner to check free resources before commissioning.

Commissioning Sequence

  1. Download the link PLC's hardware configuration. Verify the partner CPUs are reachable from Online & Diagnostics > Accessible nodes.
  2. Enable PUT/GET on each partner and recompile / download (or use online configuration if the project is not available).
  3. Download the link PLC's S7 program with PUT/GET blocks.
  4. Watch the STATUS output of each GET block. A status of 0000_0000 indicates success; common transient codes are 0001_0001 (job active) and 0001_0081 (partner rejected - check PUT/GET flag).
  5. Once the Ethernet side is stable, download the PROFIBUS configuration and verify the DP/DP couplers show green RUN on the diagnostic LEDs.
  6. Force one bit in DB100 from the link PLC and verify it appears in the vendor's input image, then verify a return bit in the opposite direction.

Diagnostics and Verification Matrix

Symptom Likely cause Check Corrective action
GET STATUS = 8183 hex Partner rejected PUT/GET Partner CPU protection Enable Permit access with PUT/GET
GET STATUS = 8304 hex Partner connection resources exhausted Online > Connection resources Free a connection or upgrade to a full CP
Connection established but data always 0 Partner DB wrong number or wrong length Partner DB attributes in STEP 7 Set partner DB to Non-optimized (classic) and confirm length
SF on partner CPU, BF blinks on link IP address / subnet mismatch Online > PN interface Align subnets; use ping from PG
DP/DP coupler BF on PROFIBUS address duplicate or wrong baud rate Diagnostic buffer Re-address coupler, align baud rate (1.5 Mbps)
Coupler RUN green, but data frozen I/O length mismatch between the two sides of the coupler Vendor's PROFIBUS master config Set identical length on both sides
PUT/GET works once, then stops after restart Partner CPU not retaining Permit PUT/GET because new project was loaded Partner's loaded project Recompile and reload partner with the flag set

Programming in SIMATIC Manager vs TIA Portal V13 SP1

Functionally, both STEP 7 V5.5 (SIMATIC Manager) and TIA Portal V13 SP1 generate the same S7 connection configuration. The differences relevant to this scenario are:

Aspect SIMATIC Manager V5.5 TIA Portal V13 SP1
Hardware catalog for older S7-300 CPUs Complete back to 6ES7315-2AG10 Limited on V13 SP1; better on V14/V15
NetPro / connection editor Standalone NetPro Integrated Devices & Networks
PUT/GET FB call FB15 PUT, FB14 GET PUT / GET instructions in task card
Block consistency check Manual Automatic compile warnings on type mismatch
Recommendation for this project Acceptable Preferred - same file contains link PLC + partner projects

If the existing cell projects are still in SIMATIC Manager and not migrated, it is possible to use TIA Portal V13 SP1 only for the link PLC and import the partner projects via Migration > Migrate project to step through the protection settings. Migrating is not strictly required; PUT/GET will work as long as the partner CPU has the runtime flag set in its loaded configuration, regardless of the engineering tool used to write that configuration.

Spare-Parts and Lifecycle Notes

  • CPU 315-2 PN/DP 6ES7315-2EH14-0AB0: shipped with firmware V3.3; remains in active sales per the Siemens product portfolio.
  • CP 343-1 Lean 6GK7343-1CX10-0XE0: phased out of catalog; replacements are the SCALANCE M series or a PROFINET interface on the CPU itself.
  • DP/DP coupler 6ES7158-0AD01-0XA0: still orderable, no functional successor required.
  • Always update to the latest hotfix of TIA Portal V13 SP1 (Update 9 at time of writing) before commissioning to avoid the PUT/GET status code display bug reported in early service packs.
Safety: The S7-300 link PLC and the DP/DP couplers described here carry no functional-safety (PROFIsafe) capability. If the new vendor machine requires SIL-rated communication, the link path must not be the only channel for safety signals; redundant hard-wired E-Stop remain mandatory.

Verification Checklist Before Hand-Over

  1. All four partner connections show STATUS = 0 for at least 10 minutes of OB35 cycles.
  2. Forced bits in the link PLC appear in the vendor machine's HMI within one PROFIBUS cycle (≤ 10 ms at 1.5 Mbps).
  3. Loss of one partner's Ethernet cable is detected by the link PLC (STATUS jumps to a non-zero value) and a vendor-side alarm is raised.
  4. Diagnostic buffer of the link PLC contains no SF events during a 1-hour soak test.
  5. Connection resource utilization on every partner is recorded in the hand-over document.

FAQ

Can a CP 343-1 Lean initiate PUT/GET to another S7-300?

No. The CP 343-1 Lean supports S7 connections only in server role. It can answer incoming PUT/GET from a client (such as a CPU 315-2 PN/DP) but cannot start a PUT/GET on its own. For a link PLC that must poll five partners, use a CPU with an integrated PROFINET interface.

How many bytes can a single PUT or GET transfer carry on an S7-300?

Up to 160 bytes per call (10 words of user data plus control overhead). For larger datasets, split into multiple calls or move to ISO-on-TCP with the full CP 343-1 (non-Lean) for 8 KB per call.

Do I need to modify the partner S7-300 program to enable PUT/GET?

No program change is required. Only the CPU property Permit access with PUT/GET communication from remote partner must be set, then the configuration recompiled and downloaded. The user OB code remains untouched.

Is TIA Portal V13 SP1 mandatory, or can I use SIMATIC Manager?

Either tool is acceptable. PUT/GET over S7 connections is unchanged between the two engineering platforms. TIA Portal V13 SP1 is preferred because the link PLC project, the partner connections, and the DP/DP coupler configuration can be edited in a single project tree.

What happens if I exceed the partner's connection-resource count?

The new connection is rejected with STATUS = 8304 hex on the GET/PUT block. The partner's diagnostic buffer logs a connection resources exhausted entry and the SF LED lights. Free a resource by removing an unused S7/HMI connection or replace the partner's CP with a model that has more resources (e.g., CP 343-1 6GK7343-1EX30 with 16 resources).

Back to blog