Weintek HMI to Siemens S7-1200: S7 and Modbus TCP Setup Guide

David Krause12 min read
S7-1200SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Weintek HMI to Siemens S7-1200: S7 and Modbus TCP Setup Guide

This technical reference covers the two production-grade paths used to connect a Weintek cMT/iE-series HMI to a Siemens SIMATIC S7-1200 CPU (example: 6ES7212-1AE40-0XB0, article number 1212 DC/DC/RLY). It is written for engineers commissioning TIA Portal V16 projects where the available CPU firmware ranges from V2.x through V4.x and where both S7 symbolic (PUT/GET) and Modbus TCP integration must be supported. The guide resolves a common confusion: the "Permit access with PUT/GET communication from remote partner" option that appears in TIA Portal under Properties > Protection & Security is only meaningful for the S7 communication path; Modbus TCP does not use PUT/GET at all and behaves as an independent transport on TCP port 502.

Critical distinction: The PUT/GET permission toggle exists only because, beginning with S7-1200 firmware V4.0, Siemens introduced a security default that disables the legacy PUT/GET remote-partner mechanism. CPUs below V4.0 (e.g., the 1212 DC/DC/RLY V2.2 in the source scenario) ship with PUT/GET already enabled and the property is therefore hidden. Modbus TCP does not depend on this toggle; it depends on the user program instantiating MB_SERVER in the S7-1200.

1. Connectivity Matrix and Protocol Selection

Weintek EasyBuilder Pro supports three PLC driver families for the S7-1200 platform. The driver you select in EasyBuilder Pro must match both the S7-1200 firmware version and the addressing model you configure in TIA Portal.

EasyBuilder Pro driver CPU firmware TIA Portal addressing Underlying transport PUT/GET required?
Siemens S7-1200 (Ethernet) – absolute V1.x – V3.x DB absolute (%DB1.DBX0.0) S7Comm (PUT/GET), TCP port 102 No (always on pre-V4)
Siemens S7-1200/S7-1500 (Symbolic) – S7CommPlus V4.0 and later Symbolic tags (optimized or standard) S7CommPlus, TCP port 102 Yes (firmware V4+ default blocks it)
Siemens S7-1200 Modbus TCP Any firmware that supports MB_SERVER Modbus Holding/Input register map Modbus TCP, port 502 No
Siemens S7-1200/S7-1500 (Absolute) – newer EasyBuilder V4.0 and later DB absolute (standard access) S7Comm (PUT/GET), TCP port 102 Yes

The CPU in the original question is firmware V2.2 (1212 DC/DC/RLY). On this hardware, the legacy Siemens S7-1200 (Ethernet) driver in EasyBuilder Pro is the correct selection, the DB must use standard access (optimized = FALSE), and PUT/GET is implicitly enabled. If the same project later migrates to a V4.x or V5.x CPU, you must switch drivers and explicitly enable PUT/GET in TIA Portal.

2. Prerequisites

  1. SIMATIC S7-1200 CPU with a PROFINET interface (all 1212/1214/1215 DC/DC/RLY variants qualify).
  2. TIA Portal V16 with the matching CPU support package installed (HSP for the 1212 DC/DC/RLY 6ES7212-1AE40-0XB0).
  3. Weintek EasyBuilder Pro V6.x or later, installed with the Siemens S7-1200 / S7-1500 PLC plug-in. Refer to the Weintek EasyBuilder Pro download portal for the current build.
  4. Patch cable (or switch) between the S7-1200 PROFINET port and the Weintek HMI LAN port.
  5. A DB whose access mode is standard (not optimized) when using S7 absolute or Modbus TCP data buffers.
  6. An offline/online test workstation running Wireshark (optional, recommended for commissioning) so that S7Comm and Modbus/TCP frames can be captured on TCP ports 102 and 502.
TIA Portal V16 is the last release that provides a full hardware catalog for the legacy 1212 DC/DC/RLY V2.2 CPU. Newer TIA Portal versions (V17/V18) may show the device but block the firmware downgrade; plan migrations carefully.

3. Method A – S7 Symbolic / Absolute (PUT/GET) Path

This path is the path that triggers the "I cannot find PUT/GET" question. The reason it is hidden on firmware V2.2 is that PUT/GET cannot be disabled on those firmware revisions. The reason it must be enabled on V4.0+ is that Siemens hardened the default security posture.

3.1 CPU Protection Settings

  1. In the TIA Portal project tree, right-click the S7-1200 CPU and choose Properties.
  2. Navigate to Protection & Security.
  3. In the Connection mechanisms group, tick Permit access with PUT/GET communication from remote partner. The full procedure is documented in the Weintek Siemens S7-1200 (Symbolic Addressing) Ethernet PLC Connection Guide.
  4. For S7-1200/S7-1500 V4.0+ projects, also confirm Permit access with PUT/GET communication from remote partner under Properties > Protection & Security > Connection mechanisms and verify that the access level (full / read-only / HMI) is set to allow read/write for the HMI role.
On firmware V2.2 (such as the original 1212 DC/DC/RLY CPU), this option does not exist in the dialog because it is implicitly enabled. If the option is missing, that is the expected behavior, not a configuration defect.

3.2 Data Block Configuration

For the absolute-addressing path (firmware < V4), follow these rules in TIA Portal V16:

  1. Create a new DB (e.g., HMI_Data).
  2. Open DB Properties > Attributes and uncheck Optimized block access. The block must use standard access.
  3. Define tags with explicit offsets. Example structure:
DATA_BLOCK "HMI_Data"
{ S7_Optimized_Access := 'FALSE' }
VERSION : 0.1
NON_RETAIN
VAR
  Start_Cmd        : BOOL;     // DBX0.0
  Stop_Cmd         : BOOL;     // DBX0.1
  Motor_Running    : BOOL;     // DBX0.2
  Spare_Bits       : BOOL;     // DBX0.3
  Process_Value    : INT;      // DBW2
  Setpoint         : INT;      // DBW4
  Batch_Counter    : DINT;     // DBD6
  Recipe_Number    : INT;      // DBW10
  Recipe_Name      : STRING[32]; // DBB12..DBB43
END_VAR

Symbolic tags (M-memory and DB tags) are both readable by the Weintek driver. For higher-V4 firmware using the S7CommPlus driver in EasyBuilder Pro, optimized DBs and fully symbolic tag names are supported.

3.3 EasyBuilder Pro – S7-1200 (Ethernet) Driver Setup

  1. Open EasyBuilder Pro and create or open the project for the target Weintek panel.
  2. Click Home > System Parameters > New PLC.
  3. Select Siemens S7-1200 (Ethernet) as the device type.
  4. Set the IP address to match the S7-1200 PROFINET interface. Default is 192.168.0.1.
  5. Port stays at 102.
  6. On the Tag tab, click Import Tags and either pull symbols via the TIA Portal export or enter addresses manually using DB1.DBX0.0 syntax for bits and DB1.DBW2 for words.

For the V4+ firmware path, repeat the procedure but choose Siemens S7-1200/S7-1500 (Symbolic) – S7CommPlus instead. The detailed driver behavior is described in the Weintek S7-1200/S7-1500 S7CommPlus Symbolic Addressing PLC Connection Guide.

4. Method B – Modbus TCP Path

Modbus TCP is the cleaner path when the user explicitly wants to use a vendor-neutral protocol or when third-party devices (other than the Weintek HMI) must also read the same data. The S7-1200 firmware revision is irrelevant; only the availability of the MB_SERVER instruction in the CPU firmware matters (present in all S7-1200 firmware versions that the 1212 DC/DC/RLY ships with from V1.x onward).

4.1 TIA Portal MB_SERVER Configuration

Add the following SCL code to the S7-1200 OB1 or to a cyclic OB:

// Modbus TCP server (HMI as client)
IF "First_Scan" THEN
  // Connection 0 reserved for Weintek HMI
  "MB_SERVER_DB".ID := 0;
  "MB_SERVER_DB".CONNECT_IP_ENABLE := TRUE;
  // Permit any remote client; tighten with CONNECT_REM_IP if needed
END_IF;

"MB_SERVER_DB".MB_HOLD_REG[0]   := "HMI_Data".Process_Value;   // MW0
"MB_SERVER_DB".MB_HOLD_REG[1]   := "HMI_Data".Setpoint;
"MB_SERVER_DB".MB_COILS[0]      := "HMI_Data".Start_Cmd;        // M10.0
"MB_SERVER_DB".MB_COILS[1]      := "HMI_Data".Stop_Cmd;

"MB_SERVER_DB"(REQ := TRUE,
               DISCONNECT := FALSE,
               CONNECT_ID := 0,
               IP_PORT := 502);

Alternatively, instantiate MB_SERVER from the Instructions > Communication > MODBUS TCP catalog and let TIA Portal auto-generate the instance DB. Use the MB_SERVER dialog to enable "Permit Modbus access with TCP". Confirm that the connection ID matches what is later declared in EasyBuilder Pro. Standard Siemens-published parameter ranges (MB_SERVER instructions manual, entry ID 109748536) are:

Parameter Data type Meaning
REQ BOOL Edge-triggered to start listening
DISCONNECT BOOL 1 = close the TCP connection
CONNECT_ID UINT Local identifier; HMI must use the same value
IP_PORT UINT Default 502 (Modbus TCP standard)
MB_HOLD_REG ARRAY[0..n] Holding registers exposed as 4xxxx
MB_COILS ARRAY[0..n] Coils exposed as 0xxxx

4.2 EasyBuilder Pro – Modbus TCP Client Setup

  1. System Parameters > New PLC.
  2. Select Modbus TCP/IP Server (Siemens S7-1200/S7-1500) from the Modbus family, or the generic Modbus TCP/IP Client.
  3. \li>Set the S7-1200 IP and port 502.
  4. Map each Weintek tag to a Modbus address. Example mapping for the previous DB:
Weintek tag Modbus address Function
Process_Value 4x 1 (offset 0) Read Holding Register
Setpoint 4x 2 (offset 1) Read/Write Holding Register
Batch_Counter 4x 3 (offset 2) – word count 2 Read Holding Register (DINT)
Start_Cmd 0x 1 (offset 0) Write Single Coil
Stop_Cmd 0x 2 (offset 1) Write Single Coil

5. Network and IP Configuration

Both S7 communication and Modbus TCP use the S7-1200 PROFINET interface. TIA Portal defaults the CPU to IP 192.168.0.1 with subnet mask 255.255.255.0. Configure the Weintek panel's LAN port to a sibling address (e.g., 192.168.0.10). Recommended practice:

  • Place the HMI and PLC in the same IP subnet; no router required for a point-to-point link.
  • Disable the Windows firewall or open inbound TCP 102 (S7) and TCP 502 (Modbus) on the engineering station during commissioning.
  • If the S7-1200 has multiple connections, verify that no more than eight MB_SERVER connections are open simultaneously. TIA Portal will report resource errors if the limit is exceeded.

6. Verification

Use the following acceptance test before handing the panel over to operations:

  1. From the Weintek project, click Project > Compile > Online Simulation. The simulator should display live values from the CPU within one poll cycle.
  2. Verify S7 path: open TIA Portal Online > Accessible Devices; the HMI should appear in the participant list with its MAC address.
  3. Verify Modbus TCP path: use Wireshark with a display filter tcp.port == 502; you should see Modbus/TCP frames containing function codes 0x03 (Read Holding Registers) and 0x06 (Write Single Register) from the HMI to the CPU.
  4. Toggle a bit from the HMI and confirm the change in the DB on the S7-1200 via TIA Portal Monitor & Force.
  5. Force a CPU STOP and confirm the Weintek panel reports the comm loss indicator (driver-status tag turns red) within the configured timeout.

7. Troubleshooting Matrix

Symptom Likely root cause Corrective action
HMI shows "PLC No Response" on a V4.x CPU PUT/GET not enabled Enable Permit access with PUT/GET communication from remote partner under CPU properties, or migrate to the S7CommPlus symbolic driver.
Tags read 0 on a V2.x CPU DB set to optimized access Set DB attribute S7_Optimized_Access := 'FALSE' and recompile.
Modbus TCP reads return exception code 0x02 (ILLEGAL DATA ADDRESS) Address offset off by one; Modbus is 1-based in EasyBuilder but 0-based in the S7-1200 Add 1 to the holding-register offset shown in EasyBuilder when mapping to MB_HOLD_REG[].
HMI connects once and then stops polling MB_SERVER instance not cyclically called Move the MB_SERVER call into a cyclic OB (OB1) and confirm REQ is edge-triggered.
EasyBuilder driver list does not contain the S7-1200 symbolic option EasyBuilder Pro version too old for S7-1200 firmware V4 Update EasyBuilder Pro to the latest V6.x build that includes the S7CommPlus driver; refer to the Weintek S7-1200/S7-1500 Absolute Addressing connection guide.
Comm link drops every 60 s Port 502 collision with a second Modbus server Change IP_PORT in the MB_SERVER call to a free port and update the EasyBuilder port accordingly.
PUT/GET option missing in TIA Portal CPU firmware below V4.0 No action required; PUT/GET is implicitly enabled on V2.x/V3.x CPUs.
HMI displays values but cannot write HMI access level set to read-only In TIA Portal, set the HMI access level to Full or assign a password for the HMI role.

8. Best Practices for Production Roll-Out

  • Always use a standard-access DB when the project will be commissioned on legacy firmware. Reserve optimized blocks for symbolic-only V4+ deployments.
  • Document the driver family, CPU firmware, and EasyBuilder version on the project cover sheet. The combination locks the design to a reproducible configuration.
  • For redundant HMI panels (e.g., cMT + iE backup), open two MB_SERVER connections using CONNECT_ID 0 and 1, both pointing to port 502.
  • When migrating a V2.x project to a V4.x CPU, plan for a TIA Portal rebuild. Tag offsets may shift because optimized-block packing differs from standard-block packing.
  • Place the Weintek panel and S7-1200 on a managed switch when integrating with other PROFINET devices to avoid broadcast storms that can disrupt TCP sessions.

9. Field-Commissioning Checklist

  1. CPU firmware version recorded on the backplane label (e.g., V2.2 for the 1212 DC/DC/RLY in the source scenario).
  2. TIA Portal V16 project compiled and downloaded; Online > Accessible Devices confirms the CPU IP.
  3. If V4+: PUT/GET permission enabled and shown in the project documentation.
  4. DBs used for HMI traffic marked as standard access.
  5. EasyBuilder Pro project compiles offline and downloads to the panel without errors.
  6. Wireshark capture of the first 30 s shows valid frames on TCP 102 (S7) or TCP 502 (Modbus).
  7. Operator-acceptance test sign-off with bit/word toggles logged.

10. Standards and Reference Documentation

  • Siemens SIMATIC S7-1200 Programmable Controller System Manual – refer to Siemens Industry Online Support entry ID 109772793.
  • MODBUS Application Protocol Specification V1.1b3 – Modbus Organization.
  • PROFINET Installation Guideline – PROFIBUS Nutzerorganisation e.V.
  • Weintek EasyBuilder Pro Software User Manual – current revision on the Weintek support site.

Why is the "Permit access with PUT/GET" option missing on my S7-1212 DC/DC/RLY firmware V2.2?

Because PUT/GET remote-partner access is implicitly enabled on all S7-1200 CPUs with firmware below V4.0. The toggle only appears beginning with firmware V4.0 because Siemens hardened the default security posture; on V2.2 you do not need to enable anything for S7 communication from a Weintek HMI.

Can I use Modbus TCP instead of S7 symbolic and skip the PUT/GET setting entirely?

Yes. Modbus TCP uses TCP port 502 and the S7-1200 MB_SERVER instruction. The PUT/GET toggle has no effect on Modbus TCP. Instantiate MB_SERVER in OB1, expose your data via MB_HOLD_REG and MB_COILS, and configure the Weintek panel as a Modbus TCP client on port 502.

Which EasyBuilder Pro driver should I select for a 1212 DC/DC/RLY V2.2 CPU?

Use the legacy Siemens S7-1200 (Ethernet) driver with absolute DB addressing. The S7CommPlus symbolic driver in EasyBuilder Pro is intended for firmware V4.0 and later and is not compatible with V2.2 CPUs.

My DB tags read zero on the HMI but show correct values in TIA Portal. What is wrong?

The DB is set to optimized block access. Disable Optimized block access in the DB attributes (set S7_Optimized_Access := 'FALSE'), recompile, and re-download the project. Symbolic addressing on a V4+ CPU is the only path that allows optimized blocks.

What is the maximum number of Modbus TCP clients that can connect to one S7-1200?

The S7-1200 supports up to eight concurrent Modbus TCP connections using the MB_SERVER instruction. Each HMI panel should be assigned a unique CONNECT_ID value to avoid session collisions.

Do I need a special EasyBuilder Pro version for V4.x S7-1200 CPUs?

Yes. EasyBuilder Pro introduced a dedicated S7CommPlus symbolic driver for S7-1200/S7-1500 firmware V4.0 and later. Download the latest EasyBuilder Pro V6.x build from Weintek support so the symbolic tag import and the S7CommPlus transport are available.

Back to blog