Overview: Bridging Independent S7-300 Machines with a Link PLC
Brownfield factory cells based on SIMATIC S7-300 controllers typically evolve without a unified network plan. When a new machine is added that must exchange a defined I/O dataset with five pre-existing cells, pulling dedicated PROFIBUS cable runs is rarely practical. The field-proven alternative is to install a link PLC that sits on the same Industrial Ethernet subnet as the existing cells, and exposes a PROFIBUS segment terminated by DP/DP couplers to the new vendor machine.
This reference covers the full engineering of that bridge using TIA Portal V13 SP1, including:
- Hardware selection between CP 343-1 Lean and a CPU 315-2 PN/DP as the link controller.
- Why the CP 343-1 Lean is restricted to server role in S7 connections.
- How to keep alterations to the existing cell programs to a minimum.
- Configuring S7 connections with PUT/GET in TIA Portal V13 SP1.
- Integrating DP/DP couplers (Siemens 6ES7158-0AD01-0XA0) on the new machine's PROFIBUS.
- Commissioning, diagnostics, and verification steps.
Prerequisites
| Item | Specification | Notes |
|---|---|---|
| Engineering station | TIA Portal V13 SP1 (Update 4 or later) with STEP 7 Professional | Required for S7-300 hardware catalog V13 SP1 |
| Link PLC | CPU 315-2 PN/DP (6ES7315-2EH14-0AB0, firmware V3.3) | Provides PN interface; acts as S7 client and server |
| Alternative link PLC | CPU 315-2 DP (6ES7315-2AG10-0AB0) + CP 343-1 Lean (6GK7343-1CX10-0XE0) | Lean acts only as server - see limitations below |
| DP/DP coupler | 6ES7158-0AD01-0XA0 | One per existing PROFIBUS segment to bridge |
| Existing cell PLCs | CPU 315-2 PN/DP or CPU 31x with CP 343-1 | Each must permit PUT/GET (allow-put-get = TRUE) |
| PROFIBUS cable | 6XV1830-0EH10 (purple, 2-wire, shielded) | Daisy-chain the 4 DP/DP couplers from the link PLC's DP port |
| Ethernet cable | CAT6 / Industrial Ethernet FC TP | Star or line topology to existing switches |
Hardware Selection: Why CPU 315-2 PN/DP Beats CP 343-1 Lean as a Link
The original concept was to drop a CPU 315-2 DP with a CP 343-1 Lean into the new machine. The architecture is physically possible, but the CP 343-1 Lean has a hard functional restriction that determines where it can sit in the topology:
| Property | CP 343-1 Lean (6GK7343-1CX10-0XE0) | CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) |
|---|---|---|
| Role in configured S7 connection | Server only | Client or server |
| PUT/GET initiator | No (cannot initiate PUT/GET) | Yes |
| Number of S7 connections | 4 maximum | 14 (S7-300 CPU 315 PN/DP) |
| Integrated PROFINET interface | No (separate CP) | Yes (2-port switch) |
| Integrated PROFIBUS DP master | No (CPU DP master only) | Yes |
| Suitable as link PLC? | Only if 4 incoming connections are acceptable and a separate master initiates all PUT/GET | Yes - acts as initiator to all 5 partner CPUs |
Because the link PLC must read signals from five partner cells and write consolidated tags to the DP/DP couplers, the link must be able to initiate PUT/GET transfers. A partner that holds a CP 343-1 Lean can only answer incoming requests, not start them. With one CP 343-1 Lean there is no way to drive the data exchange on its own.
Network Topology
The link PLC is on the same Ethernet subnet as the four partner cells. Its PROFIBUS DP master port daisy-chains the four DP/DP couplers inside the new vendor machine. Each coupler passes a pre-defined slice of process data between the link PLC's PROFIBUS image and the new machine's own PROFIBUS master.
Step-by-Step: Configuring the Link PLC in TIA Portal V13 SP1
Step 1 - Create the project and add the link PLC
- Open TIA Portal V13 SP1 and select Create new project.
- In the project tree, choose Add new device > SIMATIC S7-300 > CPU > CPU 315-2 PN/DP > 6ES7315-2EH14-0AB0 V3.3.
- Open Device view and confirm the integrated PROFINET interface and PROFIBUS DP master appear in slot 2 (PN) and slot 2 (X2 DP).
Step 2 - Configure the PROFINET interface
- Select the PN interface and assign IP
10.10.0.10, subnet mask255.255.0.0. - Add the partner CPUs as Unspecified CPU 300 in Devices & Networks > Network view. Enter each partner's IP (
10.10.0.11through10.10.0.14) under PROFINET interface > Ethernet addresses. - Create a logical S7 connection from the link PLC to each partner. The endpoint on the partner side is left as unspecified; the partner IP is entered manually.
Step 3 - Configure the S7 connection properties
For each of the four S7 connections, set the following parameters in Properties > General > Connection mechanisms:
| Parameter | Link PLC (local) | Partner PLC (remote) |
|---|---|---|
| Connection type | S7 connection | S7 connection |
| Local ID (hex) | 1, 2, 3, 4 | n/a (unspecified) |
| Active connection establishment | Establish active | Establish passive |
| One-way / Two-way | Two-way | Two-way |
| Max data length PUT/GET | 160 bytes per call | Partner must permit (see Step 4) |
Step 4 - Enable PUT/GET access on the partner S7-300 CPUs
On every partner CPU that exposes its data, the PUT/GET access flag must be enabled. This is a CPU property in STEP 7 / TIA Portal:
- Open the partner's project (or online configuration if the original project is unavailable).
- Select the CPU and go to Properties > Protection & Security > Connection mechanisms.
- Tick Permit access with PUT/GET communication from remote partner.
- Compile and download to the partner CPU.
Step 5 - Program PUT/GET in the link PLC
Use the PUT and GET instructions from the Instructions > Communication > S7 Communication task card. The block interface for the link PLC program is:
// Data block DB100 - shared with vendor machine via PROFIBUS
DATA_BLOCK "DB_Vendor_Image"
STRUCT
From_CellA : WORD; // status word from Cell A
From_CellB : WORD; // status word from Cell B
From_CellC : WORD; // status word from Cell C
From_CellD : WORD; // status word from Cell D
To_All : WORD; // consolidated command broadcast
END_STRUCT
END_DATA_BLOCK
OB1 cyclic call (SCL example):
// Read from Cell A (partner IP 10.10.0.11, connection ID 1)
"GET_DB".ID := 1; // connection ID
"GET_DB".REQ := %DB5.DBX0.0; // 1 Hz trigger from cyclic OB
"GET_DB".DONE := "CellA_Done";
"GET_DB".ERROR := "CellA_Err";
"GET_DB".STATUS := "CellA_Status";
"GET_DB".ADDR_1 := P#DB10.DBX0.0 BYTE 2; // partner DB10, 2 bytes
"GET_DB".RD_1 := P#DB100.DBX0.0 BYTE 2; // local target
// Write to Cell A
"PUT_DB".ID := 1;
"PUT_DB".REQ := %DB5.DBX0.1;
"PUT_DB".ADDR_1 := P#DB11.DBX0.0 BYTE 2;
"PUT_DB".SD_1 := P#DB100.DBX10.0 BYTE 2;
Each GET/PUT call is fired once per cycle on a 100 ms tick from OB35 to avoid flooding the partner CPUs.
Step-by-Step: Integrating the DP/DP Couplers
- In the link PLC's device configuration, open the PROFIBUS subnet and set master address to
2with transmission rate1.5 Mbps. - From the hardware catalog, drag the DP/DP coupler (6ES7158-0AD01-0XA0) four times onto the PROFIBUS subnet and assign PROFIBUS addresses
3, 4, 5, 6. - For each coupler, open the device properties and define the I/O length on the link side (e.g. 4 words in / 4 words out per coupler). The vendor must mirror the same length on the opposite side.
- Add a global data block (DB200) on the link PLC with one slice per coupler, mapped symbolically to the vendor's image.
DP/DP coupler addressing table
| PROFIBUS address | Coupler ID | Inputs (link → vendor) | Outputs (vendor → link) | Slot in link PLC image |
|---|---|---|---|---|
| 3 | DP/DP #1 | IB 100-107 | QB 100-107 | Slot 0 |
| 4 | DP/DP #2 | IB 108-115 | QB 108-115 | Slot 1 |
| 5 | DP/DP #3 | IB 116-123 | QB 116-123 | Slot 2 |
| 6 | DP/DP #4 | IB 124-131 | QB 124-131 | Slot 3 |
Connection Resource Accounting
Both the link PLC's CPU and the partner CP/CPU modules have a hard limit on concurrent S7 connections. Crossing the limit raises SF on the partner and the connection is silently rejected.
| Device | Connection resources total | Reserved for HMI / PG | Available for link | Used by this project |
|---|---|---|---|---|
| CPU 315-2 PN/DP (link) | 14 | 2 (HMI panel + PG) | 12 | 5 (4 partners + 1 spare) |
| CPU 315-2 PN/DP (cell) | 14 | 2 | 12 | 1 |
| CP 343-1 Lean (cell) | 4 | 1 | 3 | 1 |
| CP 343-1 (full, cell) | 16 | 2 | 14 | 1 |
Commissioning Sequence
- Download the link PLC's hardware configuration. Verify the partner CPUs are reachable from Online & Diagnostics > Accessible nodes.
- Enable PUT/GET on each partner and recompile / download (or use online configuration if the project is not available).
- Download the link PLC's S7 program with PUT/GET blocks.
- Watch the STATUS output of each GET block. A status of
0000_0000indicates success; common transient codes are0001_0001(job active) and0001_0081(partner rejected - check PUT/GET flag). - Once the Ethernet side is stable, download the PROFIBUS configuration and verify the DP/DP couplers show green RUN on the diagnostic LEDs.
- Force one bit in DB100 from the link PLC and verify it appears in the vendor's input image, then verify a return bit in the opposite direction.
Diagnostics and Verification Matrix
| Symptom | Likely cause | Check | Corrective action |
|---|---|---|---|
| GET STATUS = 8183 hex | Partner rejected PUT/GET | Partner CPU protection | Enable Permit access with PUT/GET |
| GET STATUS = 8304 hex | Partner connection resources exhausted | Online > Connection resources | Free a connection or upgrade to a full CP |
| Connection established but data always 0 | Partner DB wrong number or wrong length | Partner DB attributes in STEP 7 | Set partner DB to Non-optimized (classic) and confirm length |
| SF on partner CPU, BF blinks on link | IP address / subnet mismatch | Online > PN interface | Align subnets; use ping from PG |
| DP/DP coupler BF on | PROFIBUS address duplicate or wrong baud rate | Diagnostic buffer | Re-address coupler, align baud rate (1.5 Mbps) |
| Coupler RUN green, but data frozen | I/O length mismatch between the two sides of the coupler | Vendor's PROFIBUS master config | Set identical length on both sides |
| PUT/GET works once, then stops after restart | Partner CPU not retaining Permit PUT/GET because new project was loaded | Partner's loaded project | Recompile and reload partner with the flag set |
Programming in SIMATIC Manager vs TIA Portal V13 SP1
Functionally, both STEP 7 V5.5 (SIMATIC Manager) and TIA Portal V13 SP1 generate the same S7 connection configuration. The differences relevant to this scenario are:
| Aspect | SIMATIC Manager V5.5 | TIA Portal V13 SP1 |
|---|---|---|
| Hardware catalog for older S7-300 CPUs | Complete back to 6ES7315-2AG10 | Limited on V13 SP1; better on V14/V15 |
| NetPro / connection editor | Standalone NetPro | Integrated Devices & Networks |
| PUT/GET FB call | FB15 PUT, FB14 GET | PUT / GET instructions in task card |
| Block consistency check | Manual | Automatic compile warnings on type mismatch |
| Recommendation for this project | Acceptable | Preferred - same file contains link PLC + partner projects |
If the existing cell projects are still in SIMATIC Manager and not migrated, it is possible to use TIA Portal V13 SP1 only for the link PLC and import the partner projects via Migration > Migrate project to step through the protection settings. Migrating is not strictly required; PUT/GET will work as long as the partner CPU has the runtime flag set in its loaded configuration, regardless of the engineering tool used to write that configuration.
Spare-Parts and Lifecycle Notes
- CPU 315-2 PN/DP 6ES7315-2EH14-0AB0: shipped with firmware V3.3; remains in active sales per the Siemens product portfolio.
- CP 343-1 Lean 6GK7343-1CX10-0XE0: phased out of catalog; replacements are the SCALANCE M series or a PROFINET interface on the CPU itself.
- DP/DP coupler 6ES7158-0AD01-0XA0: still orderable, no functional successor required.
- Always update to the latest hotfix of TIA Portal V13 SP1 (Update 9 at time of writing) before commissioning to avoid the PUT/GET status code display bug reported in early service packs.
Verification Checklist Before Hand-Over
- All four partner connections show STATUS = 0 for at least 10 minutes of OB35 cycles.
- Forced bits in the link PLC appear in the vendor machine's HMI within one PROFIBUS cycle (≤ 10 ms at 1.5 Mbps).
- Loss of one partner's Ethernet cable is detected by the link PLC (STATUS jumps to a non-zero value) and a vendor-side alarm is raised.
- Diagnostic buffer of the link PLC contains no SF events during a 1-hour soak test.
- Connection resource utilization on every partner is recorded in the hand-over document.
FAQ
Can a CP 343-1 Lean initiate PUT/GET to another S7-300?
No. The CP 343-1 Lean supports S7 connections only in server role. It can answer incoming PUT/GET from a client (such as a CPU 315-2 PN/DP) but cannot start a PUT/GET on its own. For a link PLC that must poll five partners, use a CPU with an integrated PROFINET interface.
How many bytes can a single PUT or GET transfer carry on an S7-300?
Up to 160 bytes per call (10 words of user data plus control overhead). For larger datasets, split into multiple calls or move to ISO-on-TCP with the full CP 343-1 (non-Lean) for 8 KB per call.
Do I need to modify the partner S7-300 program to enable PUT/GET?
No program change is required. Only the CPU property Permit access with PUT/GET communication from remote partner must be set, then the configuration recompiled and downloaded. The user OB code remains untouched.
Is TIA Portal V13 SP1 mandatory, or can I use SIMATIC Manager?
Either tool is acceptable. PUT/GET over S7 connections is unchanged between the two engineering platforms. TIA Portal V13 SP1 is preferred because the link PLC project, the partner connections, and the DP/DP coupler configuration can be edited in a single project tree.
What happens if I exceed the partner's connection-resource count?
The new connection is rejected with STATUS = 8304 hex on the GET/PUT block. The partner's diagnostic buffer logs a connection resources exhausted entry and the SF LED lights. Free a resource by removing an unused S7/HMI connection or replace the partner's CP with a model that has more resources (e.g., CP 343-1 6GK7343-1EX30 with 16 resources).