Siemens PN/PN Coupler: Configuring Cross-Subnet S7-1500 Links

David Krause15 min read
Industrial NetworkingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Siemens PN/PN Coupler: Configuring Cross-Subnet S7-1500 Links

The Siemens PN/PN Coupler (article number 6ES7155-6AU01-0BN0, firmware V6.x) is a dedicated PROFINET gateway that links two physically and logically separated Ethernet subnets and exchanges data between them using configured input/output address areas. It is the correct device when two S7-1500 controllers must communicate but live on disjoint IP ranges - for example 192.168.1.1/24 on one plant and 10.0.0.100/24 on another - and routing through the CPU's IP routing table is undesirable or unsupported.

This guide walks through the hardware, TIA Portal V20 configuration, IP/subnet behavior, address mapping, status diagnostics, and verification steps required to put a PN/PN Coupler into service between two S7-1500 stations.

1. Functional Principle and Subnet Behavior

The PN/PN Coupler is not a router and does not perform Layer 3 forwarding. Each of its two PROFINET interfaces is bound to an independent PROFINET device network with its own IP subnet, device name, and IO controller. From the perspective of the left-side IO controller, the right subnet is invisible; the controller only sees the input/output byte areas configured on the local side of the coupler. Symmetrically, the right-side controller sees only the areas configured on its side.

Key consequence: The two PLCs never exchange IP packets directly. Data crosses the coupler as process image bytes copied between two isolated PROFINET realationships. The IP address of the PLC on the far side is therefore completely irrelevant to the controller on the near side - any RFC1918 range works on either side.

This is fundamentally different from the Siemens gateway / port-forwarding technique referenced in the field report. The port-forwarding approach relies on Layer 3 IP routing and requires a common subnet or a 0.0.0.0 default route; the PN/PN Coupler approach requires neither.

1.1 Galvanic and Logical Isolation

The two PROFINET ports are galvanically isolated. A fault, ground loop, or broadcast storm on subnet A cannot propagate into subnet B. This is the primary reason for selecting a coupler rather than a switch or router in redundant or segmented plants.

1.2 Supported Operating Modes

Per the PN/PN Coupler Hardware Installation and Operating Manual, the device supports:

Mode Use Case Max Data Volume
Non-isochronous coupling Standard cyclic IO data exchange Up to 1440 bytes input + 1440 bytes output per direction (firmware dependent)
Isochronous coupling Deterministic, time-synchronized exchange (IRT) Reduced payload; send clock 1 ms typical
MSI/MSO (Multiple Slot IO) Modular sub-slots for flexible addressing Per-slot configurable

2. Hardware Overview and Order Data

Parameter Value
Article number (current) 6ES7155-6AU01-0BN0
Firmware (current release) V6.0.x
Function PROFINET IO link between two PROFINET subnets
PROFINET interfaces 2 x RJ45, 100 Mbps, isolated
Power supply 24 V DC (19.2 - 28.8 V), typ. 200 mA
Max PN Controllers per subnet 4
PROFIsafe support Yes (V4.0+ firmware, F-host required on both sides)
Configuration GSD file imported into TIA Portal or STEP 7 V5.x
Dimensions (W x H x D) 40 x 125 x 117 mm

Source: Siemens Industry Mall - PN/PN Coupler.

2.1 Status and Diagnostic LEDs

LED Color State Meaning
SF (System Fault) Red Configuration error, firmware mismatch, or bus fault on either side
BF1 / BF2 (Bus Fault port 1 / 2) Red No PROFINET connection on the corresponding port (cable, device name, controller missing)
MT (Maintenance) Yellow Maintenance required (e.g., port error counter threshold exceeded)
ON / Power Green 24 V supply OK
LK1 / LK2 (Link) Green (flashing) Link established, traffic present on port 1 / port 2

3. Topology for Two S7-1500 Stations on Different Subnets

Consider the typical scenario: an automation cell on 192.168.1.0/24 must exchange a small amount of status and control data with a higher-level line controller on 10.0.0.0/24. Routing is disabled or undesirable because the two networks belong to different administrative zones.

+----------------------+           +-------------------+           +----------------------+
|   PROFINET Subnet A  |           |   PN/PN Coupler   |           |   PROFINET Subnet B  |
|   192.168.1.0 / 24   |           |  6ES7155-6AU01    |           |   10.0.0.0 / 24      |
|                      |  Port 1   |                   |  Port 2   |                      |
|   S7-1500 (IO Ctrl)  +-----------+  X1               |   X2      +----------------------+
|   192.168.1.1        |  RJ45     |       +---+       |  RJ45     |  S7-1500 (IO Ctrl)    |
|                      |           |       |CPU|       |           |  10.0.0.100           |
+----------------------+           +-------+---+-------+-----------+----------------------+
                                            24 V DC

The two PLCs are configured as IO controllers for their respective subnet. The PN/PN Coupler acts as an IO device on both sides simultaneously. Each controller sees only its local PROFINET line plus the coupler - never the other PLC.

The two PROFINET interfaces of the coupler cannot share a subnet. The device performs strict separation: if both ports are assigned overlapping addresses, the device generates a configuration error and reports SF + BF on the affected port.

4. Prerequisites

  1. TIA Portal V16 or later (V17 / V18 / V19 / V20 all supported; V20 recommended for current GSD).
  2. GSD file for PN/PN Coupler V6.x - install via Options > Manage General Station Description Files (GSD). The GSD is also available from the Hardware Manual support package.
  3. S7-1500 CPU with PROFINET interface (any standard CPU with firmware >= V2.0 supports PN controllers; check CPU-specific PROFINET IO controller count if your CPU is heavily loaded).
  4. Two physically separate Ethernet switches (or two VLANs) - one per subnet.
  5. 24 V DC power supply rated for at least 1 A continuous; the coupler draws ~200 mA nominal.
  6. PROFINET device names assigned to both ports of the coupler (e.g. pn-pn-coupler-p1 and pn-pn-coupler-p2) - either via TIA Portal topology editor or directly from the online & diagnostics view.

5. TIA Portal Configuration Procedure

5.1 Insert the PN/PN Coupler in the Network View

  1. Open the TIA Portal project that contains the S7-1500 station on Subnet A.
  2. Switch to Devices & Networks view.
  3. From the hardware catalog, navigate to Other field devices > PROFINET IO > Gateway > Siemens AG > PN/PN Coupler > 6ES7155-6AU01.
  4. Drag the device into Subnet A. Connect its X1 port to the S7-1500 PROFINET interface using the drag-to-port interaction.
  5. Right-click the coupler > Properties > General > PROFINET interface [X1] and set:
    • IP address: 192.168.1.200
    • Subnet mask: 255.255.255.0
    • PROFINET device name: pn-pn-coupler-p1

5.2 Connect the Second Subnet to Port X2

  1. Open the second project (or a multi-project) containing the S7-1500 station on Subnet B.
  2. Insert the same PN/PN Coupler instance (or reuse via inter-project routing) and place it into Subnet B at Devices & Networks.
  3. Set PROFINET interface [X2]:
    • IP address: 10.0.0.200
    • Subnet mask: 255.255.255.0
    • PROFINET device name: pn-pn-coupler-p2
  4. Connect X2 to the Subnet B S7-1500 PROFINET port.

5.3 Configure the Data Exchange Slots

The coupler exposes up to 16 input slots and 16 output slots on each side. Each slot can carry up to 64 bytes of process data (firmware V4+) or 128 bytes (V6.0+). Configured as a paired transfer area, each input slot on side A is mirrored to a corresponding output slot on side B and vice versa.

  1. In the device view of the coupler on the Subnet A side, open Device overview.
  2. Drag slot 1 (input) and slot 1 (output) into the configuration table.
  3. For each slot, click and set length (e.g., 16 bytes) and consistency. Default consistency is Total length for slot lengths ≤ 16 bytes - recommended for most applications.
  4. On the Subnet B side, perform the identical configuration. The slot-to-slot pairing is automatic: input slot 1 on side A appears as the source for output slot 1 on side B.

Example mapping table for a typical handshake (16 bytes per direction):

Slot Subnet A side Subnet B side Length Direction of payload
1 (In) A → B transfer area Mirrored 16 bytes S7-1500-A sends → S7-1500-B receives
1 (Out) Mirrored B → A transfer area 16 bytes S7-1500-B sends → S7-1500-A receives
2 (In) A → B status Mirrored 32 bytes Status word array A → B
2 (Out) Mirrored B → A status 32 bytes Status word array B → A

5.4 Assign the I/O Addresses

  1. In the Subnet A project, select the coupler, open Properties > IO tags (or Device overview > I/O addresses).
  2. TIA Portal will auto-assign input bytes IB 100 - IB 131 and output bytes QB 100 - QB 131 for the configured slots. Adjust to your project numbering convention.
  3. Repeat on Subnet B. The two CPUs have independent process image numbering - they do not need to match.

Within the S7-1500 program on PLC-A, read incoming bytes from the coupler via direct peripheral access or copy into a DB:

// SCL example - read incoming data from PN/PN coupler on PLC-A
"DB_Coupler_Input".Status_From_B := PEEK_WORD(area := 16#81, byteOffset := 0, length := 16);
// 16#81 = input process image, byteOffset 0 reads the 16 configured bytes

Or assign symbolic I/O tag names in the project and access normally via the default process image update at OB1.

6. IP Subnet and Address-Plan Best Practices

Because the two controllers never see each other's IP layer, you can use any RFC1918 range on either side, including overlapping addresses on the remote side that would normally be illegal under Layer 3. However, the following rules still apply locally:

  • The coupler X1 IP must be in the same subnet as the S7-1500 on Side A.
  • The coupler X2 IP must be in the same subnet as the S7-1500 on Side B.
  • The X1 IP and X2 IP may not be in the same subnet as each other.
  • The X1 and X2 ports must carry different PROFINET device names.

Sample address plan for the source scenario:

Device / Port IP Address Subnet PROFINET Name
S7-1500 Side A 192.168.1.1 255.255.255.0 plc-a-1500
PN/PN Coupler X1 192.168.1.200 255.255.255.0 pn-pn-coupler-p1
PN/PN Coupler X2 10.0.0.200 255.255.255.0 pn-pn-coupler-p2
S7-1500 Side B 10.0.0.100 255.255.255.0 plc-b-1500
Assign the PROFINET device names to the physical coupler ports using Online & diagnostics > Assign PROFINET device name. Many commissioning faults stem from assigning the wrong name (or no name) to X2 - the BF2 LED will light red and the Subnet B controller will report Station failure.

7. Comparison with Layer 3 Routing and Other Coupling Options

Criterion PN/PN Coupler S7-1500 IP Routing SCALANCE Layer 3 Switch
Subnet isolation Full galvanic + logical None (routed) VLAN / subnet boundaries
Data unit IO bytes, MSI/MSO, record data Any TCP/UDP, S7, Modbus, OPC UA Any IP-based protocol
Configuration effort Low - GSD + slot table Medium - routing table + firewall High - static routes, ACLs
Latency Sub-millisecond, deterministic via PROFINET IRT Variable, depends on stack Variable
Max payload per direction 1440 bytes (firmware V6.0) Unlimited (application) Unlimited
Cybersecurity exposure Very low - PROFINET only Direct - IP reachable Direct - IP reachable
Cost Low (single device) Free (CPU feature) Medium-high
Best for Deterministic, isolated handshakes HMI, programming, FTP, OPC UA Large mixed-protocol plants

For pure handshakes between zones (interlock signals, status words, recipe indices, small setpoints), the PN/PN Coupler is almost always preferred. Reserve Layer 3 routing for traffic that genuinely requires IP-level services (HMI panels, TIA Portal online access, OPC UA).

8. Diagnostics and Troubleshooting Matrix

Symptom LED State Likely Root Cause Remediation
No PROFINET connection from either side BF1 + BF2 solid red Coupler has no PROFINET device name on either port Assign device names to X1 and X2 individually
Only one side connects BF1 red, BF2 off (or vice versa) Wrong device name on that port, mismatched IP subnet, or cable fault Verify name, IP, mask; ping coupler IP from corresponding controller network; swap cable
Both controllers connect but no data updates SF red, BF off on both Slot length mismatch between side A and side B; different consistency settings Compare slot configuration on both projects; ensure identical lengths and consistency per slot
Intermittent data, occasional CRC errors MT yellow, LK green Cable near EMI source, marginal SFP/RJ45, broadcast storm on a side Check cable shielding; verify PROFINET diagnostics counter Discarded frames
PROFIsafe slots fail to go green SF red F-host not configured on one side, F-target address mismatch Enable F-host in CPU properties; assign matching F-source / F-destination addresses
Configuration download rejected SF red after TIA download Firmware on coupler older than required by GSD revision Update coupler firmware via TIA Portal (online > firmware update); current GSD requires V6.0
One CPU cannot browse the coupler in online view n/a (LED normal) The remote CPU was assigned a subnet that doesn't include the coupler's X1 IP Adjust the remote CPU's PROFINET interface IP to a member of the coupler's X1 subnet, or use a router in that network

8.1 Online Diagnostics in TIA Portal

Right-click the coupler in Devices & Networks, choose Online & diagnostics, then select:

  • Diagnostics > Status - shows module state and firmware version.
  • PROFINET diagnostics > Port statistics - frame counters, error counters per port.
  • I/O > Process image - live view of the configured slot bytes - invaluable when commissioning handshakes.

9. Verification Checklist After Commissioning

  1. All four LEDs (ON, LK1, LK2, SF off, BF1 off, BF2 off, MT off) show expected states for steady-state operation.
  2. From PLC-A, set a test pattern in the DB feeding the output bytes of slot 1.
  3. From PLC-B, observe the same pattern in the input bytes of slot 1.
  4. Reverse the test - PLC-B writes, PLC-A reads.
  5. Trigger a controlled disconnect on side A (unplug cable) and confirm PLC-B reports Station failure within one PROFINET update cycle (typically 1 ms - 4 ms).
  6. Restore the connection and verify automatic resumption without CPU restart.
  7. Capture a Wireshark trace on side B (with a TAP or mirror port) and confirm that no traffic from side A's subnet appears - only PROFINET RPC frames addressed to the coupler X2 IP.

10. Firmware and GSD Compatibility

When updating TIA Portal versions, the GSD revision for the PN/PN Coupler typically advances alongside. Older couplers in the field (V3.x, V4.x) are functionally compatible at the slot/data level but may lack MSI/MSO and PROFIsafe features.

Coupler Firmware Key Capabilities Compatible TIA Portal
V3.0 Basic IO, 240 bytes/dir V13 SP1+
V4.0 PROFIsafe, 1024 bytes/dir V15.1+
V5.0 MSI/MSO, 1440 bytes/dir V16+
V6.0 / V6.1 Enhanced diagnostics, extended record data V17 / V18 / V19 / V20

Per the TIA Portal V20 online help, the device is added by selecting PN/PN Coupler V6.0 for non-isochronous coupling and the corresponding V6.0 IRT variant for isochronous use.

11. Field-Proven Caveats

  • Two PROFINET device names. The coupler is treated as a separate IO device on each port. Many first-time users assign only one name and are puzzled when one side works and the other does not.
  • Slot pairing is positional. Input slot 1 on side A corresponds to output slot 1 on side B. Mismatched numbering silently swaps or duplicates data without raising a configuration error.
  • PROFINET update time. Default is 1 ms. If your application involves the S7-1500 motion control, leave it at 1 ms or align to the servo send clock.
  • CPU IO controller count. Each S7-1500 CPU has a maximum number of IO devices it can communicate with (commonly 128, but check the specific CPU manual). The coupler counts as one IO device per side for the local CPU.
  • TIA Portal multi-project. If the two PLC projects live in separate TIA projects, each project must contain the coupler as a PROFINET device. Inter-project cross-references are not required because the data exchange is via IO image, not symbolic linking.

12. When to Choose an Alternative

Despite its utility, the PN/PN Coupler is not always the right tool. Use a different approach when:

  • You need TCP/UDP socket communication between the PLCs.
  • You need to share large DBs (more than ~1.4 KB per direction) with high update rates.
  • You require S7 communication (PUT/GET) across the boundary for programming or HMI visibility - this requires Layer 3 routing.
  • One side must be a third-party PROFINET controller using a generic GSD.
  • OPC UA is needed - enable OPC UA server on each CPU and route, do not tunnel OPC UA through IO bytes.

For the specific problem in the field report - two S7-1500 stations on 192.168.1.0/24 and 10.0.0.0/24 - the PN/PN Coupler is exactly the right solution. It removes the need to set subnet 0.0.0.0 entirely, and it isolates the two zones while preserving deterministic data exchange.

Can the PN/PN Coupler connect two S7-1500 stations on different IP subnets?

Yes. Each side of the coupler uses an independent IP subnet (for example 192.168.1.0/24 and 10.0.0.0/24). The two controllers never see each other at the IP layer; data crosses as PROFINET IO bytes. Subnet 0.0.0.0 is not required.

Do both sides of the PN/PN Coupler need different PROFINET device names?

Yes. The two ports (X1 and X2) are separate PROFINET devices with their own device names, IP addresses, and subnets. Assign them individually via TIA Portal's Assign PROFINET device name function. If only one is named, BF on the unnamed port will light red.

What is the maximum data volume per direction?

With firmware V6.0, the PN/PN Coupler supports up to 1440 bytes of input and 1440 bytes of output per direction, distributed across up to 16 slots of up to 128 bytes each. Older firmware (V3.x) is limited to 240 bytes per direction.

Is the PN/PN Coupler a router or gateway?

Neither in the IP sense. It performs only Layer 2 PROFINET IO data exchange between two isolated subnets. There is no IP routing, no TCP/UDP forwarding, and no S7 communication passthrough. Use IP routing on the CPU or a SCALANCE Layer 3 switch if you need those services.

How do I troubleshoot a PN/PN Coupler showing BF red on one side?

Verify in order: (1) the PROFINET device name is assigned to that specific port, (2) the IP address of that port is in the same subnet as the local CPU, (3) the cable and switch port are functional, (4) the local CPU's IO controller is active and not in STOP, and (5) the GSD version matches the coupler firmware. TIA Portal's Online & diagnostics > PROFINET diagnostics view shows the exact cause.

Back to blog