Siemens TP1500 Comfort: Driving Recipes from PLC via Job Mailbox

David Krause12 min read
HMI / SCADASiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

On WinCC Comfort / Advanced / Professional Panels (Basic Panels, Panels, and Comfort Panels) the Job Mailbox area pointer is the canonical mechanism for a Siemens S7-1500 (or S7-1200) CPU to command an HMI to switch recipes and data records at runtime. Two design paths exist and they must not be mixed up:

  1. Recipe Control view – a screen-level Recipe view object bound to PLC tags for RecipeNumber and DataRecordName.
  2. Global Recipe system functions / Job Mailbox – area-pointer driven, decoupled from the on-screen Recipe view. Functions such as SetDataRecordToPLC, GetDataRecordFromPLC, SaveDataRecord, LoadDataRecord and the area-pointer jobs 69/70/71/72 operate against the recipe database independently of any visible Recipe view.

Symptom patterns reported on the field match the original case exactly: a user writes 69 or 70 into the Job Mailbox word, observes the mailbox request being cleared by the panel (job acknowledged), yet the drop-down in the Recipe view does not change. The root cause is that the on-screen Recipe Control is bound to its own interface tags, not to the Job Mailbox result. The mailbox job is executed by the recipe subsystem, but the Recipe view is not subscribed to that update.

Prerequisites

  • Engineering station: TIA Portal V19 Update 2 (V19.0.2) with installed SIMATIC WinCC Comfort V19.
  • Controller: SIMATIC S7-1512 (e.g. 6ES7512-1DK02-0AB0, firmware ≥ V2.9) on PROFINET to the HMI.
  • HMI: SIMATIC TP1500 Comfort (6AV2 124-1QC02-0AX0 or current equivalent) on PROFINET, firmware matching the TIA Portal version.
  • Configured HMI connection of type S7-1500 using the integrated PROFINET interface of the CPU.
  • A recipe project with at least one recipe containing multiple data records (e.g. Recipe_Color with records RED, GREEN, BLUE).
Important – Runtime / Firmware compatibility: The TIA Portal project version and the HMI image version must match. Mismatched versions cause the Job Mailbox to be acknowledged without executing the requested job, with no HMI log entry. See the Siemens Industry Online Support portal for the V19 compatibility list.

Understanding the Job Mailbox Area Pointer

The Job Mailbox is an unidirectional area pointer of length 4 words that the HMI polls cyclically. The CPU writes a job number, the HMI picks it up, executes the action, and overwrites the mailbox with 0 to acknowledge completion. Recipe-relevant jobs are listed below.

Job No. Action Argument 1 (Word 2) Argument 2 (Word 3) Word 4
69 Set recipe number (select active recipe by index) Recipe number (1..n) 0 0
70 Set data record name (select data record by name) Pointer index (DBW) of name string DB number of string 0
71 Get current recipe number → returned in Word 2 of mailbox 0 0 0
72 Save data record to recipe database on HMI 0 0 0
73 Read data record (HMI → tags) Pointer to record name DB number 0
74 Write data record (tags → HMI) Pointer to record name DB number 0

The pointer is configured under HMI tags → Connections → Area pointer. The default DB location is in the HMI-side data block; on the PLC side the pointer is read from the configured DBW / MW area. The TIA Portal configuration screen accepts the same four-word structure.

Critical – Acknowledge semantics: When you write 69 and the HMI sets the mailbox back to 0, the recipe subsystem has accepted the request. The fact that the Recipe view drop-down does not update is not a Job Mailbox problem – it is a binding problem on the Recipe view object.

Recipe View Tag Binding vs. Job Mailbox – Why the Drop-down Does Not Update

The on-screen Recipe view (recipe/screen object) exposes its own Configuration → General interface tags, which the discussion in the source thread identified as the actual drivers of the drop-down:

  • RecipeNumber – INT tag. Writing a value here updates the active recipe in the view.
  • DataRecordName – WSTRING / STRING tag. Writing the record name here updates the selected data record in the view.

These two tags are the only elements that change the on-screen Recipe view content. The Job Mailbox (jobs 69 / 70) and the global recipe system functions update the underlying recipe database, but they do not write back into the Recipe view's RecipeNumber / DataRecordName tags. Hence the visible drop-down stays unchanged.

Design rule of thumb: Pick one of the two strategies and stick to it. Mixing both will produce inconsistent UI state.

Strategy A – PLC Writes Directly to the Recipe View Tags (recommended for TP1500)

This is the cleanest method when the operator should see the PLC's selection reflected in the Recipe view drop-down.

Step-by-step

  1. In the HMI project, open the screen that contains the Recipe view.
  2. Select the Recipe view object, then open Properties → General → Tags.
  3. Bind the two interface tags to PLC tags of the matching data type:
    • RecipeNumber → DB_HMI.HMI_RecipeNumber (INT)
    • DataRecordName → DB_HMI.HMI_RecipeRecordName (WSTRING[80])
  4. From the PLC, write the desired recipe number and record name to those tags. The Recipe view drop-down updates immediately because the acquisition cycle on the panel pulls the new value.
  5. If you also want the change to be persisted on the HMI, follow up by writing job 72 (Save data record) to the Job Mailbox so the panel flushes the current tag values into the recipe database.

Sample SCL code on the S7-1512 (function block FB_SelectRecipe):

// Inputs
//  i_RecipeIdx : INT  // 1..n, recipe index
//  i_RecName   : WSTRING[80]
// Outputs
//  q_Done      : BOOL
//  q_Busy      : BOOL
// InOut
//  io_RecipeNumber : INT
//  io_RecName      : WSTRING[80]
//  io_Mailbox      : ARRAY[0..3] OF WORD   // 4-word job mailbox area pointer

IF i_RecipeIdx > 0 AND i_RecipeIdx <= i_RecipeIdx.MaxRecipe THEN
    io_RecipeNumber := i_RecipeIdx;
    io_RecName      := i_RecName;
    q_Done := TRUE;
    q_Busy := FALSE;
ELSE
    q_Done := FALSE;
    q_Busy := FALSE;
END_IF;

This approach produces the behaviour the source user expected: the drop-down in the Recipe view reflects the value coming from the PLC. It also avoids the long-standing pitfall of relying on the Job Mailbox for UI binding.

Strategy B – Use the Global Recipe System Functions (no on-screen Recipe view)

If the application does not need a Recipe view on the HMI – the operator just needs the HMI to feed recipe data to the PLC – the Job Mailbox / system function path is the correct one.

Step-by-step

  1. Define the recipe under Recipes in the HMI project and synchronize it.
  2. Configure the Job Mailbox area pointer on the HMI connection. Default location: first word of an INT array. Map it to a PLC DB (e.g. DB_JobMailbox.Mailbox[0..3]).
  3. From the PLC, write a recipe number into the recipe view tags and trigger the Job Mailbox job 70 with the data record name pointer to actually push the value into the recipe database and notify the HMI recipe subsystem.
  4. To load the recipe data back to the PLC, call the system function SetDataRecordToPLC from the HMI scheduler, or write job 73 (Read data record) to the Job Mailbox.

System Functions Reference (WinCC Comfort V19)

System function Direction Use case Typical trigger
LoadDataRecord Recipe DB → HMI tags Reflect current recipe values into PLC tags Operator press / PLC tag change
SaveDataRecord HMI tags → Recipe DB Persist current values into the selected record Operator press / PLC tag change
SetDataRecordToPLC Recipe DB → HMI tags Same as LoadDataRecord, useful from global script Change-of-value event on selection tag
GetDataRecordFromPLC HMI tags → Recipe DB Save from PLC side to recipe DB Change-of-value event
DeleteDataRecord — Delete a record from the HMI recipe DB Operator action
ExportDataRecords / ImportDataRecords Recipe DB ↔ file/USB Back-up / restore Operator action / scheduled

All system functions are accessible from a function list on the screen, a global script, or a scheduled task. Acquisition type for the trigger tag should be set to Cyclic continuous with a sensible update cycle (200–500 ms is typical).

Downloading a Recipe from PLC to HMI

The follow-up requirement from the field report – download the chosen recipe from the PLC to the HMI – maps to one of the two system functions above. Procedure:

  1. In the HMI tags, create the recipe elements as HMI tags, each bound to a PLC tag of the same data type and length.
  2. On the HMI, attach GetDataRecordFromPLC to a trigger (e.g. a boolean PLC tag PLC_Cmd_PushToHMI with Change value event).
  3. From the PLC, set the active recipe and record (Strategy A or B), set all element values in the corresponding HMI tags, then pulse PLC_Cmd_PushToHMI for one PLC cycle. The panel writes the values into the recipe database under the currently selected record.
  4. Confirm with job 72 if you want the values to remain persisted on the panel after a power cycle.
WSTRING length: WSTRING tags default to 80 characters. Increase the length on the PLC side if your record names are longer, and verify the HMI tag size matches exactly – mismatched lengths are the most common cause of partial string updates on the panel.

Verifying Correct Operation

  1. Place the project on the TP1500 Comfort and download the S7-1512 program. Both must be in RUN with no diagnostic alarms (online → Diagnostics → Diagnostic buffer should be empty for recipe errors).
  2. On the HMI, open the recipe screen. Use the panel's Recipes view (Control Panel → Recipes) to confirm the active recipe and record are listed.
  3. From the PLC, write a value to io_RecipeNumber and observe the Recipe view drop-down updating within one acquisition cycle.
  4. Trigger GetDataRecordFromPLC from the HMI and verify in Recipes → Show values that the HMI-side element values match what the PLC placed in the HMI tags.
  5. Power-cycle the TP1500 and reload the recipe to confirm persistence.

Troubleshooting Matrix

Symptom Likely cause Fix
Mailbox job acknowledged (mailbox = 0) but drop-down does not change Recipe view bound to its own tags, not to the Job Mailbox result Bind RecipeNumber and DataRecordName of the Recipe view to PLC tags (Strategy A)
Mailbox stays at 69 / 70, never acknowledged Area pointer mis-sized, wrong DB, or wrong offset Re-check 4-word length, DB number, byte offset on both PLC and HMI sides; confirm connection is RUN
Mailbox job executed, Recipe view updates, but HMI recipe DB still has the old record Job 72 (save) was not issued Trigger SaveDataRecord or write job 72 after the change
GetDataRecordFromPLC writes only the first element WSTRING length too short, recipe element list truncated Match all element lengths in HMI and PLC; check the recipe definition length in TIA Portal
Recipe view shows records out of order Recipe record names are case-sensitive; RED ≠ Red Standardize record names in the engineering project, regenerate the recipe DB
HMI log shows Error 200007 / Recipe status not OK Recipe DB on the panel is read-only or path missing Check storage location, file system permissions on the SD card
Mailbox job is processed but the HMI does not change the active recipe The recipe number being written is out of range ( > number of defined recipes ) Clamp the value to 1..n on the PLC side

Field-Proven Tips

  • Keep the Job Mailbox area pointer on its own DB in the PLC so it is easy to monitor in the online watch table. Read the mailbox as a 4-element WORD array.
  • Always bracket recipe changes with a Busy / Done handshake on the PLC side; recipe operations on the HMI are not instantaneous (typ. 200 ms – 1 s depending on record size and panel load).
  • On the TP1500 Comfort, prefer WSTRING over STRING for record names – WSTRING is what the TIA Portal recipe system emits by default and avoids an extra conversion step.
  • If the application loads recipes at machine start-up, issue job 73 from a HMI Scheduler task at Runtime start rather than from the PLC – the panel may not yet have fully established the area pointer handshake when the PLC writes job 70 immediately after power-on.
  • When using the global recipe system functions in VBS / C scripts, do not run them inside a tight loop. WinCC Comfort executes them in the scripting thread; calling them faster than 50 ms apart may stall the recipe subsystem.

Security and Persistence Notes

The recipe database on a Comfort Panel is stored under /home/automation/recipes/ on the panel's internal storage or external SD card. With firmware ≥ V17 the storage is encrypted only if panel access protection is enabled (under Control Panel → Security). For GMP / FDA-regulated environments, enable access protection, route the storage to the SD card, and use ExportDataRecords as part of the daily back-up job.

ESD / hot-swapping: Do not remove the SD card while a recipe is being saved (job 72 active). The recipe file is opened with a temporary .tmp extension and is renamed atomically only on completion. Removing the card mid-write will leave the recipe DB in an inconsistent state on the next panel boot.

FAQ

Why does my WinCC TP1500 drop-down not update when I write job 69 or 70 to the Job Mailbox?

The Job Mailbox updates the recipe database, not the Recipe view's interface tags. Bind the Recipe view's RecipeNumber and DataRecordName to PLC tags and write those instead – or issue job 70 followed by a SaveDataRecord / job 72 if you specifically need the database side updated.

What is the correct data type for the Recipe view's record name tag on a TP1500 Comfort?

Use WSTRING[80] (default) on both the HMI and the PLC side. Match the exact length; partial updates on the panel are usually a length mismatch.

How do I download a recipe from the S7-1512 PLC to the TP1500 Comfort?

Bind all recipe element tags to PLC tags, then trigger the system function GetDataRecordFromPLC from the HMI on a change-of-value event. The panel writes the live tag values into the active record. Persist the change with SaveDataRecord or job 72.

Why is my Job Mailbox word not being cleared after I write 69 or 70?

Check that the area pointer length is 4 words, the DB number and byte offset match on both PLC and HMI, and the HMI connection is in RUN. A mismatched length is the most common reason the HMI never acks the job.

Can I use both the Recipe view drop-down and the Job Mailbox at the same time?

Yes, but treat the Recipe view tags as the UI source of truth. Use the Job Mailbox / system functions only for database persistence and for loading data into the PLC; do not expect jobs 69/70 to drive the drop-down itself.

Back to blog