S7-400 DP Slave Free Addressing: Resolving 4-Byte Alignment Limit

David Krause11 min read
ProfibusSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Statement

The Siemens SIMATIC S7-400 CPU 416-2 with MLFB 6ES7 416-2XL01-0AB0 enforces a hard constraint when PROFIBUS DP slave I/O addresses are configured in STEP 7 Classic (SIMATIC Manager): every input and output byte assigned to a DP slave must fall on a 4-byte (32-bit) boundary. The only addresses accepted by the configuration tool are therefore 0, 4, 8, 12, 16, 20, 24, 28, 32... and any address of the form 4·n for n ≥ 0.

This rules out the natural "random" placement engineers expect when they want to free address — e.g. starting an ET 200S DI module at IB 5, an AI module at IW 90, or an AO module at QW 45. The hardware configuration window rejects the input with the error "The address must be a multiple of 4". The same restriction applies to process image partition mapping for those addresses.

This is not a defect of the DP slave or the PROFIBUS cable: it is a CPU firmware / CPU revision restriction. Newer S7-400 CPUs (firmware V4.x and higher, MLFB generation 416-3) accept arbitrary byte and word addresses. The challenge for the field engineer is to either:

  • confirm whether the installed CPU can be firmware-upgraded to a revision that supports free addressing, or
  • deploy a documented workaround that produces a working application without replacing the CPU.

2. Affected Hardware and Firmware Matrix

MLFB CPU Designation Firmware Free DP Addressing Notes
6ES7 416-2XL01-0AB0 CPU 416-2 DP V3.1 No Original target hardware for this article; 4-byte alignment mandatory
6ES7 416-2XL02-0AB0 CPU 416-2 DP V3.1 No Same constraint; same workaround path
6ES7 416-2FK02-0AB0 CPU 416-2 F V3.1 No F-variant, same DP alignment restriction
6ES7 416-3XL04-0AB0 CPU 416-3 PN/DP V4.5 Yes Free byte/word addressing enabled
6ES7 416-3XS07-0AB0 CPU 416-3 PN/DP V7.0 Yes Latest-generation free addressing + PROFINET
6ES7 416-3XR05-0AB0 CPU 416-3 PN/DP V5.4 Yes Recommended minimum upgrade target for STEP 7 V5.6

The decisive attribute is the firmware (operating system) version reported by PLC > Module Information > Diagnostic Buffer in STEP 7. The same MLFB stamped with a newer firmware supports free addressing. Always cross-check the firmware string on the physical module label against the entry in HW Config > CPU Properties > Diagnostic/Clock.

3. Root Cause: CPU Revision and DP Address Alignment

S7-400 CPUs configure PROFIBUS DP slaves through system data blocks (SDB) downloaded to the master interface. For each DP slave slot, STEP 7 generates a logical address (input or output byte) and a length (number of consistent bytes). Older S7-400 firmware generations implement the DP data exchange with the master on 32-bit word granularity — the internal data buffer is processed in 32-bit chunks. The configuration tool therefore refuses any slave address that crosses a 4-byte boundary (e.g. an 8-byte slave cannot start at byte 2, because the buffer would then span bytes 2..9 instead of a clean 4-byte-aligned range).

When the firmware version pre-dates the "free addressing" capability introduced in the V4.x generation, the diagnostic system data layout forces the configuration editor to round any user-entered start address down to the nearest multiple of 4. Subsequent slots automatically inherit a 4-byte-stepped offset. The DP slave itself is functionally capable of supporting any byte address; the limitation is purely on the master-side configuration.

Engineering implication. The same ET 200S, ET 200M, ET 200pro, or third-party DP slave placed on the bus will accept IW 90 as input start address on a CPU 416-3 (V5.4). The DP slave hardware does not change — the master CPU does.

4. Diagnosing the CPU Revision

Before attempting any workaround, confirm the firmware revision on the installed module:

  1. Open STEP 7 (SIMATIC Manager) and connect online to the CPU via PROFIBUS or MPI.
  2. Navigate to PLC > Accessible Nodes; select the CPU.
  3. Open PLC > Module Information; record the value of the Firmware entry on the General tab.
  4. Cross-reference against the S7-400 CPU data sheet in the SIMATIC S7-400 / S7-400H CPU Data Manual for the corresponding feature set.

If the reported firmware is V3.1.x and the MLFB is the original 6ES7 416-2XL01-0AB0, the CPU is at the boundary of the available upgrade window. Reference the official Firmware update entry 2774118 for the SIMATIC Micro Memory Card image. Most hardware revisions of this MLFB shipped with V3.1; later revisions of the same MLFB can take V4.x firmware. If the MLFB on the front plate ends in -0AB0 with a hardware revision index of 3 or lower, firmware migration is not possible and only the workarounds in §5–§8 apply.

5. Workaround Options

Four field-proven options exist when the CPU cannot be upgraded. They are listed in order of preference for typical discrete and process applications.

# Option Engineering Cost Runtime Cost Best For
1 Upgrade CPU MLFB to 416-3 (V5.4+) High (hardware, retest) None Greenfield / overhaul
2 Firmware upgrade in place (if HW permits) Low (download via SIMATIC Manager) None Existing installed base on supported HW
3 Use 4-byte-aligned logical addresses + offset index in user program Low Negligible Read-only I/O, simple process image
4 I-slave configuration with decoupled address areas Medium Medium (extra SFC14/SFC15 calls) Modular plants, mix of slaves

Option 4 in particular benefits from the TIA Portal documented procedure to add an I-slave to a DP master system, which configures an S7-300/400/1500 as an intelligent DP slave with its own free address area.

6. Workaround: 4-Byte-Aligned Logical Addresses Plus Programmatic Re-Mapping

The simplest workaround keeps the CPU, the configuration, and the PROFIBUS topology unchanged. The user accepts the 4-byte alignment constraint and rebuilds the address map around it. The application program then re-indexes every access through a pointer or by direct symbolic access.

Configuration example for three DP slaves on a CPU 416-2 (V3.1):

DP Slave Module Start Address (input) Start Address (output) Length
ET 200S #1 (slot 4) DI 8x24VDC IB 0 — 1 byte
ET 200S #1 (slot 5) DO 4x24VDC — QB 4 1 byte
ET 200S #2 (slot 4) AI 2x12Bit IW 8 — 4 bytes (aligned)
ET 200S #2 (slot 5) AO 2x12Bit — QW 12 4 bytes (aligned)

In STL the program reads the symbolic slot symbol only; no manual offset is required because STEP 7 handles the byte-wise distribution inside the 4-byte word. If a downstream HMI expects IW 90 but the DP input actually lives at IW 8, expose the alias through a DB pointer:

// IEC 61131-3 ST — input pointer alias (DB instance)
FUNCTION FC100 : INT
VAR_INPUT
  iSourceStartAddr : INT;   // e.g. 8
  iTargetOffset    : INT;   // e.g. 90
END_VAR
VAR_TEMP
  tSlotByte AT IB 0: ARRAY[0..31] OF BYTE;
END_VAR
BEGIN
  // copy one word from aligned source to aligned target
  WORD_TO_INT(tSlotByte[iTargetOffset]) := INT_TO_WORD(tSlotByte[iSourceStartAddr]);
  FC100 := tSlotByte[iSourceStartAddr];
END_FUNCTION
Note. The target offset must also be a multiple of 2 for a WORD access. STEP 7 will reject IW 91 in hardware configuration for the same reason. For byte-level mis-alignment, use PEB / PAB peripheral access in OB1 or a cyclic interrupt OB.

7. Workaround: I-Slave (Intelligent DP Slave) Configuration

Configure a downstream S7-300 / ET 200S as an I-slave to take advantage of free addressing on its side. The master S7-400 (V3.1) sees only the I-slave as a single DP slave with one 4-byte-aligned slot; the I-slave CPU then provides free addressing to its own distributed I/O. This is the documented Siemens pattern for cases where the master CPU is constrained but the slave side is more modern.

Procedure (STEP 7 V5.6, TIA Portal V20 documentation mirrored for S7-300/400):

  1. Insert a second DP-capable device in the project (e.g. IM 151 / CPU 315-2 DP / CPU 1511-1 PN as I-slave).
  2. On the I-slave device, open Properties > PROFIBUS Interface > Operating Mode and tick DP Slave.
  3. Configure the I-slave's free-address area (this side does support free addressing from V4.x).
  4. On the master CPU 416-2 (V3.1), add the I-slave as a DP slave on the same PROFIBUS subnet. STEP 7 will display the I-slave's transferred data area as a single block, which is itself 4-byte-aligned by the master's constraint.
  5. Use SFC15 DPRD_DAT / SFC14 DPWR_DAT in the master to copy the consistent block between process image and the data block used for application logic.

The same construction pattern is the basis of the official Siemens application example "Reading the input data of a DP slave configured by a different DP master", where a CPU 416-2 DP reads ET 200S input modules via direct data exchange — i.e. without taking ownership of the slave.

8. Workaround: SFC14 / SFC15 for Consistent Data Exchange

Where consistent data over the entire DP slave slot is required (essential for analog modules with more than 4 bytes or for compact slaves that bundle status bytes), use the standard SFCs:

// SFC14 "DPRD_DAT" — read consistent data of a DP slave
// LADDR  = logical address of the slave (4-byte aligned)
// RET_VAL = error code (0 = OK)
// RECORD  = destination area
CALL SFC14
  LADDR  := W#16#0100          // IW 256  (start address, 4-byte aligned)
  RET_VAL := MW 200
  RECORD := P#DB20.DBX 0.0 BYTE 16
// SFC15 "DPWR_DAT" — write consistent data
CALL SFC15
  LADDR  := W#16#0100
  RET_VAL := MW 202
  RECORD := P#DB21.DBX 0.0 BYTE 16

Diagnostic error codes from SFC14 / SFC15 on the CPU 416-2 (V3.1) include:

RET_VAL (hex) Meaning Remedy
0000 No error —
80A0 Negative acknowledgement at the slave Check slave power and bus connector
80A1 Slave removed / not reachable Check PROFIBUS termination
80A2 Memory error at SFC instance Increase RECORD area / correct length
80A3 DP protocol error (single error) Check GSD, baud rate, repeater
80B0 Slave does not support the function Verify slave GSD revision supports the slot
80B2 Length of RECORD inconsistent Align RECORD length to SDB slot length

Use SFC14/SFC15 instead of direct process-image access whenever the slave exceeds 4 bytes consistent data or whenever the engineer wants the free address area to be inside an application DB rather than in the I/O area.

9. Configuration in STEP 7 Classic (SIMATIC Manager)

For CPUs that support the upgrade path (the same MLFB family with newer firmware), the upgrade sequence is:

  1. Insert a SIMATIC Micro Memory Card of size matching the CPU (typically 2 MB or 4 MB for CPU 416-2).
  2. Download the firmware file via SIMATIC Manager > PLC > Update Firmware; the firmware must be unpacked on the memory card using the Siemens SIMATIC Manager > Options > Firmware Update wizard.
  3. Power-cycle the CPU; the front panel will display UPDATE during the firmware load.
  4. After the CPU comes back to RUN, re-download the hardware configuration (HW Config) — the addressing constraint dialog will accept non-4-byte addresses from this point onward.

The official Siemens entry for the firmware image is SIOS entry 2774118. The operational product manual for the family is the SIMATIC S7-400 / S7-400H CPU Data Manual. The FAQ that originally motivated the user's question is the legacy entry 5362481, mirrored in the Siemens Knowledge Base.

10. Verification and Diagnostics

After the configuration has been downloaded, validate the addressing scheme in the following sequence:

  1. PLC > Module Information > Diagnostic Buffer: confirm no SDB errors, no event W#16#35B1 (inconsistent hardware configuration).
  2. PLC > Accessible Nodes > PROFIBUS Node Status: every DP slave reports OK with the configured diagnostic address.
  3. Monitor/Modify on the configured start address: values must toggle with physical signals.
  4. Trigger a force on each output byte; observe the corresponding output module LED.
  5. Disconnect a slave intentionally; verify the CPU goes to STOP with diagnostic buffer event "Station failure" on the correct slave diagnostic address.

If the user program is using SFC14/SFC15 against a slave that has been re-aligned, the RET_VAL must be W#16#0000 on every call. A persistent non-zero return triggers a slot-length mismatch and is the most common commissioning error after the address remap.

11. Migration to S7-1500 — Long-Term Option

For plants where the S7-400 hardware is reaching end-of-life (the S7-400 / S7-400H product family has been in phase-down since 2023), the most future-proof resolution is a CPU migration to S7-1500. In STEP 7 (TIA Portal), the modern CPU 1516-3 PN/DP or CPU 1517-3 PN/DP supports free PROFIBUS DP addressing natively (no 4-byte alignment) and additionally offers PROFINET IO. The migration tool S7-1500 Migration > Migrate S7-400 program in TIA Portal carries over the program logic, while the I/O configuration is regenerated with free addresses from a fresh project.

Verification step after migration. Use the TIA Portal "Compile > Software (rebuild all blocks)" with the Strict I/O address check disabled, and then re-enable it to catch any unaddressed slots. The error list will report the byte index of any slot that was not migrated.

12. Frequently Asked Questions

Why does the CPU 416-2 (6ES7 416-2XL01-0AB0) only accept 4-byte aligned DP addresses?

Because the V3.1 firmware implements PROFIBUS DP data exchange with the master buffer on 32-bit word granularity; STEP 7 enforces the constraint in the hardware configuration editor. CPUs with V4.x firmware and newer accept free byte and word start addresses.

Can the firmware on a CPU 416-2 be upgraded to remove the 4-byte limit?

It depends on the hardware revision index stamped on the front plate. Hardware revisions 3 or higher can usually be upgraded to V4.5; revision 1 or 2 cannot. Always cross-check the MLFB and revision against the Siemens SIOS entry 2774118 before attempting an update.

What is the simplest workaround without replacing the CPU?

Keep the 4-byte-aligned logical addresses in HW Config and re-map the values to the application data block through a copy block or through SFC14/SFC15 consistent read/write. The free "random" appearance is then recreated in user data, while the configuration remains valid.

How do I configure an S7-300 as an I-slave to bypass the master CPU limitation?

Mark the S7-300 PROFIBUS interface as a DP Slave in its properties, assign its own free address area on that side, and treat it from the S7-400 as a single DP slave with 4-byte-aligned transfer slots. The TIA Portal documentation describes the same pattern under Adding an I-slave to a DP master system S7-300/S7-400/S7-1500.

Does the same 4-byte rule apply to PROFINET IO on an S7-1500 successor?

No. PROFINET IO on S7-1500 (and on S7-400 CPUs with PROFINET interface, V4.x+) uses free byte addressing by default. There is no 4-byte alignment constraint for PROFINET slots.

Back to blog