Siemens S5 TTY Interface and AS511 Protocol Technical Reference

David Krause12 min read
Serial CommunicationSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview of Siemens S5 Communication Architecture

The SIMATIC S5 programmable controller family uses a layered communication model in which the physical layer (TTY current loop) is logically separated from the data link protocol (AS511 or 3964/R). This separation is fundamental: TTY defines only the electrical and mechanical coupling between two devices, while AS511 and 3964(R) define the framing, handshake, and supervisory character sequences that move user data across that coupling. Engineers approaching an S5 system for the first time often conflate the two layers, which leads to incorrect assumptions about cable length, address space, and partner integration.

SIMATIC S5 communication was historically built around dedicated Communication Processors (CPs) such as the CP 521, CP 524, CP 525-2, and CP 544. Each CP exposes a specific combination of physical interfaces (TTY, RS-232, RS-422) and supports a defined set of standard protocols. The CPU of an S5 (for example the AG 95U, AG 115U, AG 135U, AG 155U, or AG 155H) handles only the application program; all point-to-point traffic is delegated to the CP inserted in the S5 subrack.

Siemens officially discontinued the S5 line and its loadable protocol drivers years ago. Replacement parts, firmware updates, and engineering tools (COM 521, COM 525, COM 544) are no longer available through normal sales channels. Migrating to S7-1200/S7-1500 is the recommended path for new projects, but many S5 systems remain in service for 20-30 year life-cycle applications (rolling mills, power plants, water treatment).

TTY Physical Interface: 20 mA Current Loop

TTY (TeleType) on SIMATIC S5 is implemented as an optically isolated 20 mA current loop. The interface is current-driven rather than voltage-driven, which is what gives TTY its excellent noise immunity and long cable reach. A logical "1" (MARK) is represented by a current of nominally 20 mA flowing through the loop; a logical "0" (SPACE) is represented by the absence of current (0 mA). Because signalling depends on current rather than voltage drop, the loop tolerates voltage differences between the two ends of the cable and resists induced common-mode noise on long runs.

Parameter TTY Value (S5 CP modules)
Loop current (active) 20 mA nominal
Loop current (idle / SPACE) 0 mA
Compliance voltage typ. 24 V internal supply
Galvanic isolation Yes (optical)
Maximum cable length @ 9 600 bit/s up to 1 000 m (screened, high-quality cable)
Maximum cable length @ 19 200 bit/s
Connectors Sub-D 15-pin (active/passive) per Siemens S5 convention

Two operating modes exist for the S5 TTY port: active (the CP supplies the 20 mA) and passive (the partner supplies the loop current). The S5 CP can be configured for either role via hardware jumpers or COM parameter block, depending on module generation. Mismatching active-active on a single loop is the most common field failure mode and will result in no current flow at all.

AS511 Protocol (S5 CPU Programming Interface)

AS511 is the Siemens-proprietary protocol used by the programming device (PG) to communicate with an S5 CPU over the TTY port. It is not a general-purpose fieldbus protocol; it is a point-to-point, master-slave link where the PG is always master and the S5 CPU is always slave. The protocol is implemented in firmware on the CPU itself (or on the integrated TTY port of older AGs such as the AG 95U), so it does not require a separate CP.

AS511 frame structure follows a fixed character pattern based on STX/ETX and Siemens control characters. Field engineers typically need only the high-level characteristics:

  • Baud rates supported: 300, 600, 1 200, 2 400, 4 800, 9 600 bit/s. 9 600 bit/s is the practical maximum for stable long-distance TTY runs.
  • Addressing: The PG addresses an S5 station by its MPI/AS511 address (default 1, 2, or 3 depending on CPU type and rotary switch). The S5 CPU does not have a configurable address in the modern sense; the rotary switch on the CPU front panel selects one of the available PG slots.
  • Functions: Read/write PLC program blocks (OB, PB, FB, DB, SB), read/write process I/O image, start/stop CPU, status display, password handling.
  • Data integrity: AS511 uses a single-character checksum per telegram. It is suitable for engineering access but is not designed for high-integrity process data exchange.

For an interview or migration assessment, the key point to articulate is: AS511 is the protocol, TTY is the wire. Conflating the two is a common error that signals lack of field experience.

3964(R) Protocol

The 3964 protocol (and its acknowledged variant 3964R) is a point-to-point data link layer defined by Siemens for serial communication between two devices, typically a SIMATIC S5 CP and a partner device (printer, barcode scanner, scale, S7 controller, or third-party PLC). 3964(R) runs on top of RS-232, RS-422, or TTY depending on the CP variant installed.

Frame format and handshake sequence:

  1. Sender asserts the control line STX (0x02) to request the line.
  2. Receiver answers with DLE (0x10) within the configured acknowledgment delay (QVZ, default 2 s).
  3. Sender transmits the data telegram.
  4. Sender appends DLE + ETX (0x10 0x03) as the frame terminator.
  5. In 3964R, the receiver computes a checksum and replies with NAK (0x15) on error or DLE (0x10) on success.
  6. On NAK, the sender retries up to the configured retry count (default 3).
Parameter Typical default Notes
Baud rate 9 600 bit/s 300 to 19 200 bit/s selectable
Character frame 8 data, 1 stop, no parity 7E1 also common for legacy partners
QVZ (acknowledge delay) 2 000 ms Adjust for slow partner devices
Retries (3964R) 3 Increase on noisy links
Block check (3964R) 8-bit additive checksum Per Siemens standard
Max telegram length CP-dependent (typ. 1 024 bytes) CP 524/525/544 higher
If a third-party device uses plain ASCII without DLE/ETX framing, the S5 CP must be configured for a transparent driver or an XON/XOFF variant, not 3964(R). Selecting 3964R on a partner that does not implement the DLE handshake will hang the link and time out at QVZ.

S5 Communication Processors (CPs) and Their Protocols

Each S5 CP supports a defined set of loadable protocol drivers. The list below summarizes the four most common S5 CPs and the standard protocols they expose. Loadable protocol packages were officially discontinued years ago and are no longer available for new installations, but documentation can be obtained through legacy channels or Siemens Industry Online Support for already-licensed systems.

CP Physical interfaces Standard protocols Notes
CP 521 TTY (20 mA), RS-232, RS-422 AS511, 3964(R), ASCII, RK512 (subset) Basic point-to-point CP for AG 95U/100U
CP 521 SI TTY, RS-232 AS511, 3964(R), ASCII Variant for hazardous-area I/O
CP 523 TTY, RS-232 3964(R), ASCII, RK512 Drop-in for AG 115U/135U/155U
CP 524 TTY, RS-232, RS-422 3964(R), RK512, ASCII, Modbus master (loadable) Common in printer/scanner integrations
CP 525-2 TTY, RS-232, RS-422 3964(R), RK512, ASCII, Modbus, proprietary drivers High-end point-to-point CP for AG 155U/H
CP 544 TTY, RS-232, RS-422 3964(R), RK512, SINEC L1, SINEC L2 (PROFIBUS), Modbus Bridges S5 to PROFIBUS networks

RK512 deserves separate mention. RK512 is a Siemens standard for structured point-to-point data exchange with coordinated coordination flags. It runs on top of 3964(R) and adds data-block-oriented services (read DB, write DB, fetch, control) commonly used to exchange 256-word data blocks between two SIMATIC controllers. RK512 is also the basis of legacy S5/S7 cross-communication where the S5 side is the master and a contemporary S7-1200/1500 is the slave.

Cable Specifications and Maximum Length

The Siemens S5 TTY cable specification calls for a twisted-pair, screened (shielded) cable with characteristic impedance matched to the current loop. Standard off-the-shelf 24 AWG twisted pair with overall foil + braid shield (for example LiYCY or similar) is typically used. Each TTY channel uses two conductors (one for the active current source, one return), so a 2-pair or 4-pair shielded cable is common to support two channels plus spare.

Baud rate Maximum TTY cable length (screened, typical)
300 - 2 400 bit/s 1 000 m (often derated to 800 m for safety margin)
4 800 bit/s 1 000 m
9 600 bit/s 1 000 m (boundary case, requires high-quality cable)
19 200 bit/s 500 - 800 m, CP-dependent
38 400 bit/s Not recommended on TTY; switch to RS-422

Three factors dominate the practical cable length:

  1. Cable capacitance. Long cables exhibit capacitance that distorts the 20 mA loop edges. Specification should stay below the CP's published maximum (typically 100-150 pF/m for TTY).
  2. Shield bonding. Connect the shield at one end only (S5 side) to avoid ground loops. If both ends must be bonded, use a low-impedance equipotential bonding conductor between the two grounding points.
  3. Active/passive configuration. Only one device on the loop can be active. The second device must be wired passive (current sink only).

Sub-D 15 Pinout and Wiring Conventions

The standard S5 TTY connector is a 15-pin Sub-D. The pinout below reflects the convention used by CP 521/523/524 front connectors and is consistent with the original Siemens documentation. Always verify against the specific CP manual because pin assignments for the second channel differ between modules.

Pin Channel A Channel B
1 GND / shield GND / shield
2 +20 mA out (TX+) +20 mA out (TX+)
3 RX+ in RX+ in
4 +20 mA out (TX-) / shield —
5 RX- in RX- in
9-15 Reserved / second channel See CP manual

The two wires of a single TTY channel are commonly labelled T+ and T- (transmit pair) and R+ and R- (receive pair) in vendor wiring diagrams, although the actual signal flow is determined by which side of the loop is active.

Modern Integration: S5 TTY to S7-1500

Many legacy S5 systems must exchange data with a contemporary S7-1500 controller. The S7-1500 has no native TTY port, so a protocol converter or serial module is required. The official Siemens reference document "Serial communication between SIMATIC S5 and SIMATIC S7-1500" describes three supported paths:

  1. CM PtP (RS-232 / RS-422) modules on the S7-1500 with 3964(R) or RK512. The S5 CP (typically CP 524 or CP 525-2) terminates the link on the S5 side using 3964R; the S7-1500 uses its serial module configured for the same protocol. RK512 is preferred when structured DB-to-DB exchange is required.
  2. ET 200SP serial modules for distributed I/O installations where the S7-1500 head-end is remote from the S5.
  3. Third-party protocol converter (for example Helmholz, Prosoft, or Woodhead) translating 3964(R) to PROFINET or EtherNet/IP. Use only when Siemens-native conversion is not possible.

The official Siemens application document describing the first two paths is available at Serial communication between SIMATIC S5 and SIMATIC S7-1500. Reference this document in any interview discussion of brownfield integration.

When bridging TTY to RS-232 with a passive converter, verify the 20 mA loop is properly terminated. A common field error is to wire TTY directly into an RS-232 DB9 - the voltage-driven RS-232 receiver will not respond correctly to the current loop, and the link will appear dead even though the CP is transmitting.

Commissioning Procedure for an S5 TTY Link

  1. Identify the CP and its configured protocol. Read the CP front labels and the COM parameter block stored in the S5 program (e.g. FB 60 for CP 524).
  2. Verify the cable type. Screened, twisted pair; shield bonded at one end only.
  3. Check active/passive configuration. Exactly one device supplies the 20 mA.
  4. Measure loop current. With a clamp meter or in-line ammeter, verify 18-22 mA in MARK and <1 mA in SPACE.
  5. Verify protocol handshake. Use a serial analyzer (e.g. Wireshark with serial capture, or a dedicated protocol analyzer) to confirm STX/DLE exchange at startup.
  6. Send a test telegram. A short ASCII or 3964R test message from the partner and check the S5 CP status LEDs and the error word in the assigned data block.
  7. Document baud rate, character frame, QVZ, and retry count. These four parameters are the most common sources of mismatches during commissioning.

Troubleshooting Matrix

Symptom Most likely cause First check
No communication, CP LED off CP not seated, no backplane power, or CP fault Re-seat CP, check power supply
No communication, LED on, no current loop Both ends active, or open loop Measure loop current; verify active/passive jumpers
Garbled data, intermittent Baud rate mismatch or excessive capacitance Reduce baud, shorten cable, check shield
QVZ timeout (3964R) Partner not responding with DLE Verify partner protocol, increase QVZ
NAK storms (3964R) Checksum error, electrical noise Check shield bonding, swap cable
PG cannot online Wrong PG port selected, AS511 not enabled Verify PG COM port and S5 CPU address switch
Communication works, partner drops after N retries QVZ too short for slow partner Increase QVZ to 4-6 s, retries to 5

Field-Engineer Interview Talking Points

When discussing S5 communication in a technical interview, structure your answer around the four-layer model:

  1. Physical layer: TTY 20 mA current loop, 1 000 m maximum at 9 600 bit/s with screened cable.
  2. Data link layer: AS511 for PG-CPU, 3964(R) for general point-to-point, RK512 for structured S5-to-S5/S5-to-S7 exchange.
  3. Transport layer: Handled implicitly within RK512/3964R; no TCP/UDP equivalent exists for S5 TTY.
  4. Application layer: Read/write PLC blocks, process image, status, control.

Be explicit that TTY is a physical specification, not a protocol, and that the protocol (AS511, 3964R, RK512) is a separate decision. Citing a specific CP model number (for example CP 525-2 supporting Modbus master as a loadable driver) signals hands-on experience rather than textbook knowledge.

FAQ

Is TTY a protocol or a physical interface on Siemens S5?

TTY is a physical interface specification - a 20 mA optically-isolated current loop. It is not a protocol. The protocol that runs on TTY depends on the device, with AS511 (PG programming) and 3964(R) (point-to-point data) being the most common on S5 systems.

What is the maximum cable length for S5 TTY at 9 600 bit/s?

Up to 1 000 m using a screened, high-quality twisted-pair cable. The 1 000 m figure is a practical maximum and depends on cable capacitance staying below the CP's published limit (typically 100-150 pF/m). At higher baud rates, the maximum length is reduced.

What is the difference between AS511 and 3964(R)?

AS511 is the Siemens protocol used by a programming device to read and write S5 CPU program blocks, status, and process image. 3964(R) is a generic point-to-point data link protocol that frames arbitrary user data using STX/DLE/ETX and (in 3964R) an 8-bit checksum. 3964(R) is used between two S5 CPs or between an S5 CP and a partner (printer, scanner, S7-1500).

Which S5 communication processor supports Modbus?

The CP 524, CP 525-2, and CP 544 support Modbus as a loadable protocol driver. The CP 521 and CP 523 do not. Note that all S5 loadable protocol packages were officially discontinued years ago, so Modbus support on new S5 installations is typically achieved through a third-party converter.

How do I connect an S5 TTY port to a modern S7-1500 controller?

Use a Siemens CM PtP serial module on the S7-1500 configured for 3964(R) or RK512, and an S5 CP (typically CP 524 or CP 525-2) configured for the matching protocol on the TTY side. The official Siemens application document describing this integration is the "Serial communication between SIMATIC S5 and SIMATIC S7-1500" reference, available through Siemens Industry Online Support.

Back to blog