Siemens SIMATIC S7 ISO on TCP
Siemens SIMATIC S7 ISO on TCP communication protocol
Supported device types and versions
Communication line configuration
Line protocol parameters
Communication station configuration
I/O tag configuration
Note on Siemens TIA Portal version 12 and above
Note on Siemens S7 1200/1500
Literature
Changes and modifications
Document revisions
Supported device types and versions
This protocol supports a data reading/writing from the control PLC machines Siemens SIMATIC:
types S7-300 and S7-400 equipped by an ethernet interface for the communication S7 ISO over TCP.
types S7-1200, S7-1500
Siemens LOGO
Siemens Microbox
Note: communication via Profinet/Profibus adapter ACCON-NetLink-PRO compact produced by company DELTALOGIC has been verified. Communication with multiple S-300 series PLCs on Profibus worked after firmware upgrade of adapter to version V2.54 (31. march 2015) with adapter's BIOS version V2.39 (7. June 2011). When the adapter's firmware was version V2.37 (8.august 2011), communication could not be correctly established.
Note: communication with PLC Siemens LOGO was tested. A part of memory that is accessible for reading/writing is the V area that is seen as DB1.
Note: the protocol has a "big endian" data representation.
Communication line configuration
Communication line category: TCP/IP-TCP, TCP Redundant.
IP address (addresses) is set according to a network configuration of a specific Siemens SIMATIC device.
The port number is 102 (according to specification RFC 1006).
The line number is not used, set on 1.
When the communication line is set as TCP Redundant you can configure an IP address and port of a backup device. If a communication process lost the connection or is unable to connect to the device, it will switch periodically between the configured devices. KOM process tries to connect to a primary device at first.
Note: Multiple IP addresses of primary/backup device can also be configured (separated by commas or semicolons).
Line protocol parameters
A dialog window of communication line configuration - Protocol parameters tab.
They influence some optional protocol parameters.
The following line protocol parameters are defined:
Parameter | Meaning | Unit / size | Default value |
|---|---|---|---|
Rack | Siemens Simatic rack number. Rack 0 is most often used. | 0 to 7 | 0 |
Slot | Siemens Simatic slot number. Slot 2 is most often used. | 0 to 31 | 0 |
S7 Subnet ID-part 1 (hex) | S7 subnet address sent as a part of Remote TSAP if parameter Use long TSAP is set to True | 0x0 to 0xFFFF | 0 |
S7 Subnet ID-part 2 (hex) | S7 subnet address sent as a part of Remote TSAP if parameter Use long TSAP is set to True | 0x0 to 0xFFFF | 0 |
Use Secondary | The parameter allows the use of redundant PLCs, which may differ in the settings of some parameters (Rack, Slot, S7 Subnet ID). If its value is True, the primary and secondary parameters are used alternately when connecting to the PLC using the specified IP addresses. | - | False |
Connection Resource (hex) | Connection resource, it enters as MSB byte to the calculation of the value of Remote TSAP at initialization of ISO Connection-request. /TSK1/Sending CR-TPDU: CLASS=0, SRC-REF=0x0001, TPDU size=1024, SRC-TSAP=10-00, DST-TSAP=03-02 After changing the Connection resource from 3 to 2, the communication started working. | 0x0 to 0xFF | 3 |
Local TSAP (hex) | ISO Local TSAP (Transport Service Local Point). Source TSAP value during the initialization of ISO Connection-request. | 0x0 to 0xFFFF | 0x1000 |
Source Reference | ISO Source Reference. Value of SRC-REF during the initialization of ISO Connection-request. | 0 to 65535 | 1 |
Use long TSAP | Enables a long format of local and remote TSAP which is sent during the connection setup phase.
Short remote TSAP has the following format:
Long local TSAP is 28 bytes long. Last 2 bytes are higher and lower byte of parameter Local TSAP
| - | False |
MPI/Profibus Address | MPI/Profibus address sent as a part of Remote TSAP, if parameter Use long TSAP is set to True | 0 to 126 | 1 |
ISO TPDU Size Variable Parameter | The maximum required size of ISO TPDU. The parameter value the initialization of ISO Connection-request. | 8192, 4096, 2048, 1024, 512, 256 or 128 bytes | 1024 bytes |
Nr. of Parallel Network Threads | Maximum parallel communication threads. Increase the value if there is a request on more data read from the device in a shorter time. | 1 to 4 | 1 |
Cycle Time | The required time of one data reading cycle. | ms | 1000 ms |
Message Timeout | Maximal wait time on a reply from the device. | ms | 2500 ms |
Inter Message Delay | Delay which is used before sending a data request. When a high data transfer rate is required, set 0 ms. | sec.ms | 20 ms |
Reconnect Delay | Delay before reconnection to the device if the connection has failed or some communication error has occurred. | sec.ms | 2 sec |
Connection Error Timeout | When Timeout passes and communication error occurs in all threads, a communication error status is set on the stations. FALSE state is set on the communication line. | sec.ms | 20 sec |
S7 PDU Size | Maximum PDU in bytes at S7 communication with the device. | 240, 480, 960 bytes | 480 bytes |
Tcp No Delay | Setting Tcp No Delay parameter causes low-level socket option TCP_NODELAY to be set, thus turning off the default packet coalesce feature. | - | False |
Debug Values | Activates a debug info about the loaded values of I/O tags. Use this parameter only when communication must be debugged because it highly uses CPU and slows down the communication. | YES/NO | NO |
Debug I/O Binary Packets Info | Activates a debug info about a binary content of packets. Use this parameter only when communication must be debugged because it highly uses CPU and slows down the communication. | YES/NO | NO |
Debug Requests Info | Activates a basic debug info about requested data. | YES/NO | YES |
Debug Answers Info | Activates a basic debug info about received packets. | YES/NO | YES |