Skip to main content
Version: 3.0 (next)

Siemens S5 Siemens S5 Integration Guide

Read and write Siemens SIMATIC S5 PLCs by S5 address. The S5 connector reaches a PLC the two ways S5 plants are on Ethernet: through a gateway on the programming port that answers as an S7-300, or through a CP 1430 TCP card speaking Siemens FETCH/WRITE.

Overview​

The S5 connector provides:

  • S5 addresses, with the German or the English letters: E3.1 or I3.1, AW4 or QW4, MW10 or FW10, DB10.DW4, T5, Z3 or C3
  • S5 data types: the S5 floating-point format (KG), timers in milliseconds and BCD counters, read as numbers
  • Many points in the fewest reads: neighbouring points in the same area or data block share a read
  • Writes to data words, flags and outputs

Connection Configuration​

Two ways to reach an S5​

Via a gatewayVia a CP 1430 (FETCH/WRITE)
HardwareAn S5-to-S7 gateway on the PLC's programming port: IBH Link S5++, S5-LAN++ and similarA CP 1430 TCP (or S5-TCP/IP 100) card in the PLC rack. IBH Link S5++ and S5-LAN++ also speak FETCH/WRITE.
What it speaksS7 on port 102; the S5 answers as an S7-300FETCH/WRITE on two TCP ports: one for reading (FETCH), one for writing (WRITE)
What to set up on the deviceNothing beyond the gateway's IP addressTwo passive connections on the CP: Fetch passive and Write passive, each on its own port

Creating an S5 Connection​

Navigate to Connections → New Connection → Siemens S5.

FieldDefaultDescription
Connect viagatewaygateway (S7 through an S5-to-S7 gateway) or fetchwrite (FETCH/WRITE to a CP 1430)
Address—The gateway's or the CP's IP address or host name (required)
S7 Port102Via a gateway: the S7 port
Rack0Via a gateway: the rack it answers as (0 for IBH Link S5++ and S5-LAN++)
Slot2Via a gateway: the slot it answers as (2 for IBH Link S5++ and S5-LAN++)
Fetch Port—Via FETCH/WRITE: the port of the CP's FETCH connection (required for FETCH/WRITE)
Write Port—Via FETCH/WRITE: the port of the CP's WRITE connection. Leave empty to only read.
Timeout5sMaximum time to connect, and to wait for each answer

Testing the Connection​

Test Connection opens the connection (the S7 connection, or both FETCH/WRITE connections) and reads flag byte MB0.

S5 Addresses​

AddressWhat it isTypeWritten
E3.1 / I3.1, EB3, EW4, ED4Inputs (bytes 0–127): bit, byte, word, double wordBIT, BYTE, WORD, DWORDNo
A4.0 / Q4.0, AB4, AW4, AD4Outputs (bytes 0–127)as aboveYes
M10.2 / F10.2, MB10, MW10, MD10Flags (bytes 0–255)as aboveYes
DB10.DW4Data word 4 of DB10WORDYes
DB10.DL4, DB10.DR4The left (high) and right (low) byte of a data wordBYTEYes
DB10.DD4Data words 4 and 5 as a double wordDWORDYes
DB10.D4.15Bit 15 of data word 4 (bit 0 is the lowest)BITYes
T5Timer 5, in millisecondsnumberNo
Z3 / C3Counter 3number (0–999)No

Data blocks are DB1–DB255, data words DW0–DW2047. A data block is word-addressed, as in STEP 5: DW4 is the fifth word, not byte 4.

Typing a word or double word​

A word reads as an unsigned WORD and a double word as an unsigned DWORD unless typed with a suffix:

SuffixOnReads as
:INTa word (MW10:INT, DB10.DW4:INT)16-bit signed
:DINTa double word (DB10.DD4:DINT)32-bit signed
:KGa double word (DB10.DD4:KG, MD20:KG)the S5 floating-point format
The S5 floating-point format (KG)

An S5 stores a floating-point number in its own format, not IEEE 754 as an S7 does: an 8-bit exponent and a 24-bit mantissa, both in two's complement. Read and write such a value with :KG; reading it as :DINT shows the raw bits.

A timer is read in milliseconds: its BCD value multiplied by its time base (10 ms, 100 ms, 1 s or 10 s).

Why inputs, timers and counters are not written

The CPU reads its inputs in on every cycle, so a value written there is overwritten. Timers and counters run in the S5 program. To command an S5, write a flag or a data word the program reads.

Function Builder​

Read Points (s5.read)​

Read a set of named points, each by S5 address, in the fewest reads.

FieldRequiredDescription
PointsYesOne or more {name, address}: the name is the key in the result, the address an S5 address

Example: speed = DB10.DD4:KG, pump = A4.0, parts = Z3 returns { "speed": 100.0, "pump": true, "parts": 42 } under values.

A point name may not repeat, and an address that is not an S5 address (such as DB0.DW1 or E128.0) is refused when the function is saved.

Write Point (s5.write)​

Write one value to a data block item, a flag or an output.

FieldRequiredDescription
AddressYesA data block item (DB10.DW4, DB10.DD4:KG, DB10.D4.15), a flag (M10.2, MW10) or an output (A4.0, AW4). Supports ((paramName)).
ValueYestrue/false (also on/off, 1/0) for a bit, a number otherwise. Supports ((paramName)).

A single bit, or one byte of a data word (DL, DR), is written by reading its byte or word, changing it and writing it back. If the program writes other bits of the same byte or word at the same moment, the write can race with it.

Testing Functions​

Use Test Function on the function form to run a read or write against the live S5 before saving it.

Pipeline Integration​

Each operation has its own node: S5 Read and S5 Write. See Siemens S5 Nodes for their parameters and results.

Troubleshooting​

SymptomPossible causeSolution
Test Connection fails via a gatewayWrong address, or the gateway expects another rack/slotCheck the gateway's IP address; IBH Link S5++ and S5-LAN++ answer at rack 0, slot 2
Test Connection fails via FETCH/WRITEA port is not the CP's FETCH or WRITE connection, or the connection is not configured passiveCheck the CP's connections: a Fetch passive and a Write passive connection, on the ports set here
error 2, the requested block does not existThe data block is not loaded in the S5Check the DB number; the block must exist in the PLC program
error 3, the requested block is too smallThe address runs past the end of the area or data blockCheck the data word number against the block's length
this connection has no write portA FETCH/WRITE connection without a write portSet the Write Port to the CP's WRITE connection
A floating-point value reads as a huge or tiny numberIt was read without :KG, or the value is IEEE (written by newer equipment)Add :KG for S5 floating point; an IEEE value reads correctly as :DINT bits only