Setting Up S7-400 to S7-300 PUT/GET Communication via CP 343-1

David Krause18 min read
S7-300SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview: Mixed S7-400 and S7-300 Communication on Industrial Ethernet

When a CPU 414-2 DP is paired with a CP 443-1 and a CPU 315-2 DP is paired with a CP 343-1 Lean, classic PUT/GET communication over Industrial Ethernet must be configured with explicit attention to the role limitation of the CP 343-1 Lean. Unlike the full CP 343-1, the Lean variant is restricted to S7 server behavior, which means the S7-400 must always be the client that initiates the PUT/GET requests. Misreading this role and attempting to configure two fully specified S7 connections, or attempting PUT/GET from the S7-300, results in connection establishment failures, error code 0x80B1 (area does not exist) or 0x80B5 (partner not reachable) on SFB14/SFB15, and a stalled data exchange.

This article details the supported configuration for a CPU 414-2 DP (firmware V5.x or V6.x) exchanging data with a CPU 315-2 DP (firmware V3.x or later) using a CP 443-1 on the S7-400 side and a CP 343-1 Lean on the S7-300 side. It also covers the BSEND/BRCV alternative when bidirectional data exchange is required, CPU access protection settings, and the diagnostic checks that confirm correct operation.

Critical role limitation. The CP 343-1 Lean is an S7 server only. It cannot establish an S7 connection as a client. If the S7-300 must actively push data, the CP 343-1 Lean must be replaced with a CP 343-1 (full variant). The Lean CP is an architectural choice, not a STEP 7 configuration choice; no NetPro option changes the role.

Hardware and Software Prerequisites

Confirm the following before beginning configuration.

Hardware

  • S7-400 station. CPU 414-2 DP. Order numbers include 6ES7414-2XG03-0AB0, 6ES7414-2XK05-0AB0, and 6ES7414-2XL05-0AB0. Firmware V5.1 or higher is required to interpret all PUT/GET STATUS codes correctly.
  • S7-400 Ethernet CP. CP 443-1. Order numbers include 6GK7443-1EX11-0XE0, 6GK7443-1EX20-0XE0, and 6GK7443-1EX30-0XE0. The EX30 supports ISO, TCP, and UDP and is the recommended choice for new projects. Confirm the CP firmware is at least V2.6 for the EX20 and V3.0 for the EX30; older firmware can cause connection establishment failures that are not visible in the SFB STATUS output.
  • S7-300 station. CPU 315-2 DP. Order numbers include 6ES7315-2AG10-0AB0 and 6ES7315-2AH14-0AB0. Firmware V3.3 or higher is recommended. Firmware V2.x has restrictions on DB access from remote partners and may not honor all PUT/GET error semantics.
  • S7-300 Ethernet CP. CP 343-1 Lean. Two part numbers are relevant: 6GK7343-1CX00-0XE0 (4 S7 connections, single RJ45) and 6GK7343-1CX10-0XE0 (8 S7 connections, integrated 2-port switch, ISO/TCP/UDP). The CX10 is the recommended choice for new installations. Firmware V1.0 or higher is required for S7 communication as server with PUT/GET.

Software

  • STEP 7 V5.5 + SP4 or later. Includes NetPro, the standard library with FB14/FB15, SFB14/SFB15, and FB12/FB13.
  • SIMATIC NET PC software V12 or later if NCM diagnostics are used to verify CP 443-1 connections from a service PC.
  • SIMATIC NET HSP (current revision) to obtain current CP firmware and STEP 7 hardware catalog updates.

See the CP 343-1 Lean device manual and the CP 443-1 device manual on the Siemens Industry Online Support portal for the supported firmware matrix per order number.

CP 343-1 Lean Capability Boundaries

The CP 343-1 Lean is a low-cost Ethernet CP for the S7-300. The "Lean" suffix indicates that the PROFINET IO controller, PROFINET IO device, and open communication (SEND/RECEIVE) functions are removed. S7 communication capability is preserved for server scenarios only.

Capability CP 343-1 (full) CP 343-1 Lean
S7 communication as server (PUT/GET/FETCH/WRITE) Supported Supported
S7 communication as client (PUT/GET/BSEND/BRCV as client) Supported Not supported
Maximum S7 connections Up to 32 (variant dependent) 4 (CX00) or 8 (CX10)
BSEND/BRCV (FB12/FB13) as server on Lean Supported Limited: works on CX10 firmware V2.0+; not guaranteed on all CX00 variants
Open TCP/UDP SEND/RECEIVE Supported Not supported
PROFINET IO controller Variant dependent Not supported
ISO-on-TCP (RFC1006) Supported Supported (CX10 only)
Integrated 2-port switch No (except EX40 GX30) Yes on CX10; no on CX00

The consequence for a project with a CP 343-1 Lean is that the S7-300 cannot be the client in any S7 communication. All PUT/GET or BSEND/BRCV calls must be issued from the S7-400 side, and the S7-300 must hold a non-optimized DB that the S7-400 reads or writes via the CP 343-1 Lean acting as server.

Field note. The S7-300 cannot dynamically be made a client by changing NetPro options. The limitation is in the CP firmware, not in STEP 7. If the application requires the S7-300 to push data on event (for example, a status change), the only clean solution with a CP 343-1 Lean is to poll from the S7-400 using a periodic GET, or to upgrade the S7-300 to a CP 343-1 (full) or a CPU with integrated PROFINET interface.

Network Topology and IP Planning

Place both stations on the same IP subnet. The following example is used throughout the rest of this article.

S7-400 Station CPU 414-2 DP CP 443-1 (slot 4) IP 192.168.10.40 Mask 255.255.255.0 S7 client (PUT/GET) S7-300 Station CPU 315-2 DP CP 343-1 Lean (slot 4) IP 192.168.10.30 Mask 255.255.255.0 S7 server only Switch Industrial Ethernet 10/100 Mbit/s

Figure 1 — Network topology for S7-400↔S7-300 PUT/GET. Both CPs are connected to a single industrial switch on subnet 192.168.10.0/24.

Station Module IP address Subnet mask Router
S7-400 CP 443-1 (slot 4) 192.168.10.40 255.255.255.0 0.0.0.0
S7-300 CP 343-1 Lean (slot 4) 192.168.10.30 255.255.255.0 0.0.0.0

Set the IP address in the CP configuration under Properties > Ethernet interface > IP Parameters. On the CP 343-1 Lean, the address can also be assigned via the SIMATIC Manager using the PLC > Ethernet > Assign Ethernet Address menu when the CP is in factory state. Always confirm the address with a ping from a service PC connected to the same physical switch.

The physical layer is straightforward: both CPs are connected to a 10/100 Mbit/s industrial switch using standard RJ45 patch cables (Cat 5e or higher). If the CP 343-1 Lean is the CX10 variant with the integrated 2-port switch, a downstream PROFINET device can be daisy-chained, but for S7-400↔S7-300 communication, the standard star topology is recommended for predictability.

NetPro Connection Configuration

The S7 connection is configured in NetPro. The configuration direction depends on which side is the client.

Connection configuration on the S7-400 side

  1. Open the S7-400 station in NetPro.
  2. Select the CP 443-1 (not the CPU).
  3. Right-click the CP row and select Insert New Connection.
  4. Choose S7 connection as the connection type.
  5. For the partner, select (unspecified) and enter the CP 343-1 Lean's IP address (192.168.10.30) in the Address field of the partner dialog. Using "unspecified" forces STEP 7 to generate a one-sided connection definition that is sufficient when the partner CP is a Lean server.
  6. Set the Local ID to a free value, for example 1. This ID is later referenced by the PUT/GET blocks (input ID on SFB14/SFB15).
  7. Set the Active connection establishment checkbox — the S7-400 must establish the connection because the CP 343-1 Lean cannot.
  8. Confirm with OK and compile/download the NetPro configuration to the S7-400 station.

Connection configuration on the S7-300 side

For a server-only CP 343-1 Lean, the S7-300 does not need an outgoing connection. The CP 343-1 Lean will accept incoming connection requests from the S7-400 on the configured port (ISO port 102 / TCP port 102). However, two practical configurations are common in the field:

  1. Unconfigured partner. No S7 connection is added on the S7-300 side. The CP 343-1 Lean accepts incoming requests from any S7 client on the subnet. This is the minimum viable configuration and is appropriate for very small projects.
  2. Mirror one-sided connection. In NetPro on the S7-300 station, add an S7 connection to the S7-400 with Active connection establishment = unchecked. This produces a matching connection entry on the S7-300 side. The advantage is that the S7-300's connection diagnostics will report specific errors and partner status, which is useful for commissioning and ongoing troubleshooting.

Download the configuration to the S7-300 station. Without the configuration download, the CP 343-1 Lean will not service any S7 requests, even if the S7-400 has a fully configured connection. The download path is: SIMATIC Manager > select the S7-300 station > right-click the CP > Download to Target System.

Common pitfall. A frequent commissioning error is configuring the S7 connection with the S7-300 as the active partner. With a CP 343-1 Lean, this connection will never establish. Symptom: STATUS = 0x80B5 (partner not reachable) on the S7-400 SFB14/SFB15 call. Fix: set Active connection establishment on the S7-400 side only and recompile NetPro on both stations.

CPU Access Protection on the S7-300

Since STEP 7 V5.4, the S7-300 CPU has a configurable access protection that blocks write access from a remote partner to a CPU password-protected DB unless explicitly allowed. This setting is the second most common reason PUT/GET fails after NetPro role errors.

Open the CPU 315-2 DP properties in HW Config, go to the Protection tab, and confirm the following:

  • Protection level: 1 (No protection) or 2 (Write protection). If level 3 (Read/write protection) is set, the CPU will reject PUT requests from the S7-400; GET will still return data — this asymmetry is a common source of confusion during commissioning.
  • Permit access with PUT/GET communication from remote partner (PLC, HMI, OPC, ...): Checked. This is the critical checkbox. It is independent of the protection level and must be explicitly enabled. On a fresh project with a CPU that has been memory-reset, the default state is unchecked.
Symptom mapping. If PUT only fails with STATUS = 0x80B3 or 0x80B5, and GET succeeds, the PUT/GET access flag is the most likely cause. The setting survives a CPU STOP/RUN transition and a memory reset only if Reset to factory settings is not performed; after a factory reset, the flag returns to the default unchecked state on CPUs with firmware V3.x.

Programming PUT/GET (SFB14/SFB15)

The S7-400 has PUT and GET available as system function blocks SFB14 (PUT) and SFB15 (GET). The S7-300 has the same functions available as FB14 and FB15 in the Standard Library > Communication Blocks. Because the CP 343-1 Lean only supports the server role, only the S7-400 side is programmed with PUT/GET. The S7-300 merely makes a DB available; the DB must be non-optimized and large enough to cover the read/write range declared in the PUT/GET pointer.

Block parameters on the S7-400

Parameter Type Description Example value
REQ INPUT BOOL Start PUT/GET on rising edge M0.0 (pulse from OB35 or timer)
ID INPUT WORD Local connection ID from NetPro W#16#1
ADDR_1 INPUT ANY Pointer to partner area 1 (PUT: write target, GET: read source) P#DB10.DBX 0.0 BYTE 2
ADDR_2 ... ADDR_4 INPUT ANY Additional partner areas (PUT/GET support up to 4 areas per call) —
SD_1 ... SD_4 INPUT ANY (PUT only) Local source area to send P#DB20.DBX 0.0 BYTE 2
RD_1 ... RD_4 INPUT ANY (GET only) Local destination area to receive P#DB20.DBX 0.0 BYTE 2
DONE OUTPUT BOOL 1 for one cycle when the job finished successfully —
ERROR OUTPUT BOOL 1 when the job finished with an error —
STATUS OUTPUT WORD Status/error code; 0 = no error —

STL example: 2-byte GET from S7-300 DB10 to S7-400 DB20

// Periodic call in OB35 (e.g., 100 ms)
A M0.0                          // 1 Hz pulse from clock memory
FP M0.1
= M0.2                          // Edge flag

A M0.2
JCN end_call

CALL "GET", DB15                // Background DB instance
REQ :=M0.2
ID :=W#16#1
ADDR_1:=P#DB10.DBX 0.0 BYTE 2  // Partner (S7-300) DB10, 2 bytes
RD_1 :=P#DB20.DBX 0.0 BYTE 2   // Local (S7-400) DB20, 2 bytes
DONE :=M10.0
ERROR:=M10.1
STATUS:=MW12

end_call: NOP 0

STL example: 2-byte PUT to S7-300 DB11 from S7-400 DB21

CALL "PUT", DB14                // Background DB instance
REQ :=M0.2
ID :=W#16#1
ADDR_1:=P#DB11.DBX 0.0 BYTE 2  // Partner (S7-300) DB11, 2 bytes
SD_1 :=P#DB21.DBX 0.0 BYTE 2   // Local (S7-400) DB21, 2 bytes
DONE :=M10.2
ERROR:=M10.3
STATUS:=MW14

Each call may define up to four partner areas, but every area must lie in the same partner DB. Mixing DB11 and DB12 within the same PUT/GET call is not permitted. The partner DB on the S7-300 must be non-optimized; on S7-300, all DBs are non-optimized by default, so this is not a concern in this configuration, but the same is not true if the S7-300 is later replaced with an ET 200S CPU or an S7-1500 module.

Polling and timing considerations

PUT and GET are call-bound operations; the actual data transfer happens asynchronously in the CP 443-1 firmware. The DONE bit is set for one cycle on success. To avoid CPU scan time degradation, do not call PUT/GET every OB1 cycle. A 100 ms cycle (OB35) is a common production setting. A GET cycle of 500 ms is sufficient for most non-time-critical monitoring tasks. The minimum recommended cycle is 50 ms; below this, the CP 443-1 firmware can saturate and reject jobs with STATUS = 0x0070.

BSEND/BRCV Alternative for Bidirectional Exchange

When both directions of data transfer are required, BSEND (FB12) and BRCV (FB13) from the standard library are an alternative. The S7-400 calls BSEND to push data; the S7-300 calls BRCV to receive it. The reverse direction would require BSEND on the S7-300, which requires the S7-300 to be the S7 client — not possible with a CP 343-1 Lean.

The conclusion: with a CP 343-1 Lean, full bidirectional BSEND/BRCV is not possible. For 2-byte exchanges, PUT/GET from the S7-400 remains the supported solution. If bidirectional data is required, replace the CP 343-1 Lean with a CP 343-1 (full), for example 6GK7343-1EX30-0XE0.

Parameter set for BSEND on the S7-400

Parameter Description Example
REQ Start on rising edge M1.0
R Cancel active job M1.1
ID Local connection ID W#16#2
R_ID Relationship ID — must match BRCV's R_ID on the partner DW#16#1
SD_1 ... SD_4 Local data area to send (pointer + length) P#DB22.DBX 0.0 BYTE 32
DONE, ERROR, STATUS Job result —

Diagnostics, STATUS Codes, and Connection Tests

When the connection does not establish, or PUT/GET returns a STATUS other than 0, the following diagnostics should be performed in order.

REQ rising edge STATUS=7001 CP transfer DONE=1 ERROR=1 STATUS = code success error

Figure 2 — SFB14/SFB15 call state machine. STATUS = 0x7000 means call without active job; 0x7001 is the first call with a job pending; 0x7002 is a follow-up call with the job still pending. Done and error are mutually exclusive terminal states for each job.

1. Test the physical layer

  • Verify the link LED on the CP 443-1 and the CP 343-1 Lean.
  • Ping the partner IP from a service PC on the same subnet. If ping fails, the issue is IP, subnet, switch, or cabling. PUT/GET cannot succeed if ping fails.

2. Test the ISO/TCP layer (CP 443-1 diagnostics)

  • Open the CP 443-1 online diagnostics in STEP 7 (CP right-click > Diagnostics).
  • Check Connection list. The configured S7 connection should appear with state "established" within 10 seconds of CPU RUN on both stations.
  • Check Statistics for rejected or reset frames.

3. Read the SFB STATUS

The most relevant STATUS values on SFB14/SFB15 are:

STATUS Meaning Typical cause
0x0000 No error —
0x0010 Partner not reachable (initial) Connection not yet established, partner in STOP, or wrong IP
0x0020 Partner rejected the connection Partner PUT/GET access disabled; wrong local ID; partner DB does not exist
0x0030 Local resource issue Local ID already in use; PUT/GET block instance missing
0x0070 Local SFB instance cancelled Repeated REQ without waiting for DONE
0x7000 Call without active job —
0x7001 First call with job pending —
0x7002 Follow-up call with job pending —
0x80A1 Negative acknowledgement from partner CPU Partner DB does not exist or is too short
0x80B1 Requested data area exceeds partner DB size Pointer length > partner DB length
0x80B2 Partner DB is write-protected Open DB properties and clear DB write-protected
0x80B3 Partner DB does not exist or access protection blocks PUT Enable "Permit access with PUT/GET" on S7-300 CPU
0x80B4 Partner memory error Check partner CPU diagnostics buffer
0x80B5 Partner not reachable Wrong partner IP; CP 343-1 Lean firmware issue; subnet mismatch
0x80C3 Requested data type not supported by partner CPU Partner CPU firmware < V3.x or old CP 343-1 Lean firmware

4. Read the partner CPU's diagnostic buffer

On the S7-300 CPU 315-2 DP, open the online diagnostics buffer in STEP 7. The most common event after a failed PUT/GET is "Communication error: PUT/GET access rejected" with the partner connection ID logged. This is the most direct indicator that the access protection checkbox is the cause. See the STEP 7 V5.5 System and Standard Functions reference for the complete STATUS code list for SFB14/SFB15.

Troubleshooting Matrix

Symptom First-place check Fix
CP 343-1 Lean never appears in NetPro "Insert New Connection" list CP is configured but the project was compiled before the CP was added Run Station > Consistency Check and recompile
S7 connection established but PUT/GET always returns 0x80B3 CPU access protection Enable "Permit access with PUT/GET" on CPU 315-2 DP
S7 connection established but PUT/GET always returns 0x80B5 CP 443-1 firmware too old, or partner IP is wrong Update CP 443-1 firmware to V3.0+ and verify the IP in NetPro partner properties
S7 connection not establishing at all "Active connection establishment" set on the S7-300 side Set active flag on the S7-400 side only
DONE never comes, ERROR comes immediately with 0x0020 CP 343-1 Lean not configured (NetPro not downloaded) Download the S7-300 NetPro configuration to the CP
PUT works from S7-400, but S7-300 cannot call PUT CP 343-1 Lean server-only By design — do not use PUT/GET on S7-300 side
Connection drops every few minutes Keep-alive time mismatch between the two CPs Match keep-alive time on both CPs in the connection properties; default is 30 s
STATUS = 0x80B1 on GET only ADDR_1 length too large for the partner DB Verify the partner DB has the declared length in the S7-300 project
DONE comes, but data is wrong Different byte order interpretation between PUT and GET blocks Confirm SWAP logic; on S7-400, both PUT and GET respect the partner's byte order (little-endian) automatically
STATUS 0x0070 intermittent REQ pulse rate exceeds CP capability Increase OB35 cycle time to at least 100 ms

Verification and Commissioning

Use the following steps to confirm a working configuration.

  1. On the S7-400, open Online > Monitor/Modify on the local DB (e.g., DB20) and write a recognizable pattern (for example, W#16#5A5A in DBW0).
  2. On the S7-300, monitor DB10.DB0 and confirm the same value appears after the GET cycle.
  3. Reverse the test: change a value in the S7-300 DB11 and confirm it arrives in the S7-400 DB21 after the PUT cycle.
  4. In the CP 443-1 connection list, confirm the connection is "established" and the counters for sent/received bytes are incrementing.
  5. Run a 24-hour soak test. With PUT/GET on a CP 343-1 Lean, intermittent dropouts after a few hours are a known symptom when the CP firmware is older than V2.0 (CX10) or V1.0 (CX00). Updating to the latest firmware available on Siemens support typically resolves it.
Firmware update caveat. The CP 443-1 and CP 343-1 Lean firmware files are distributed as HSP (Hardware Support Package) files for STEP 7. Apply the HSP to STEP 7 first, then download the new firmware via the CP's online functions. The update is non-disruptive to the S7-400 CPU runtime but interrupts the connection for a few seconds. Always perform the firmware update during a planned maintenance window.

For a deeper review of the S7 connection setup philosophy, see the "Communication with SIMATIC" system manual on Siemens Industry Online Support, which includes a connection selection aid that confirms the role asymmetry between the S7-400 as client and the CP 343-1 Lean as server for PUT/GET.

FAQ

Can the CPU 315-2 DP with a CP 343-1 Lean act as an S7 client for PUT/GET?

No. The CP 343-1 Lean is an S7 server only. PUT/GET calls (FB14/FB15 on the S7-300) require a fully configured S7 client connection, which the Lean CP does not support. The S7-400 must be the client in this configuration. Replace the CP 343-1 Lean with a CP 343-1 (full) to enable client behavior on the S7-300.

What STATUS code on SFB14/SFB15 means the partner rejected the connection because of access protection?

STATUS = 0x80B3 indicates that the partner CPU's "Permit access with PUT/GET communication from remote partner" checkbox is disabled in the CPU 315-2 DP's Protection tab. Enable the checkbox and download the new CPU configuration. The SFB14/SFB15 call will then succeed without code changes.

How many S7 connections does a CP 343-1 Lean support?

The 6GK7343-1CX00-0XE0 supports up to 4 S7 connections, and the 6GK7343-1CX10-0XE0 supports up to 8 S7 connections. All of them can be used for PUT/GET server access. If the project requires more S7 connections, switch to the full CP 343-1 (for example, 6GK7343-1EX30-0XE0 with 32 S7 connections).

Is BSEND/BRCV (FB12/FB13) supported between a CPU 414-2 DP and a CPU 315-2 DP with a CP 343-1 Lean?

Limited. BSEND from the S7-400 with BRCV on the S7-300 (CP 343-1 Lean acting as server) generally works on a CX10 with firmware V2.0 or later. The reverse direction (BSEND from the S7-300) does not work, because the Lean CP cannot be an S7 client. For full bidirectional exchange with BSEND/BRCV, replace the CP 343-1 Lean with a CP 343-1 (full).

Why does my S7 connection show as "established" in the CP 443-1 diagnostics but PUT/GET still returns 0x80A1?

0x80A1 means the S7-300 partner CPU has rejected the data area request. The most common cause is that the partner DB number declared in the PUT/GET block does not exist in the S7-300, or the partner DB is shorter than the pointer length in the call (for example, ADDR_1 = P#DB10.DBX 0.0 BYTE 32 but the S7-300 DB10 is only 10 bytes long). Verify the partner DB length in the S7-300 project and shorten the pointer if needed.

Back to blog