Siemens S5 Integration Guide
Read and write Siemens SIMATIC S5 PLCs by S5 address. The S5 connector reaches a PLC the two ways S5 plants are on Ethernet: through a gateway on the programming port that answers as an S7-300, or through a CP 1430 TCP card speaking Siemens FETCH/WRITE.
Overview
The S5 connector provides:
- S5 addresses, with the German or the English letters:
E3.1orI3.1,AW4orQW4,MW10orFW10,DB10.DW4,T5,Z3orC3 - S5 data types: the S5 floating-point format (KG), timers in milliseconds and BCD counters, read as numbers
- Many points in the fewest reads: neighbouring points in the same area or data block share a read
- Writes to data words, flags and outputs
Connection Configuration
Two ways to reach an S5
| Via a gateway | Via a CP 1430 (FETCH/WRITE) | |
|---|---|---|
| Hardware | An S5-to-S7 gateway on the PLC's programming port: IBH Link S5++, S5-LAN++ and similar | A CP 1430 TCP (or S5-TCP/IP 100) card in the PLC rack. IBH Link S5++ and S5-LAN++ also speak FETCH/WRITE. |
| What it speaks | S7 on port 102; the S5 answers as an S7-300 | FETCH/WRITE on two TCP ports: one for reading (FETCH), one for writing (WRITE) |
| What to set up on the device | Nothing beyond the gateway's IP address | Two passive connections on the CP: Fetch passive and Write passive, each on its own port |
Creating an S5 Connection
Navigate to Connections → New Connection → Siemens S5.
| Field | Default | Description |
|---|---|---|
| Connect via | gateway | gateway (S7 through an S5-to-S7 gateway) or fetchwrite (FETCH/WRITE to a CP 1430) |
| Address | — | The gateway's or the CP's IP address or host name (required) |
| S7 Port | 102 | Via a gateway: the S7 port |
| Rack | 0 | Via a gateway: the rack it answers as (0 for IBH Link S5++ and S5-LAN++) |
| Slot | 2 | Via a gateway: the slot it answers as (2 for IBH Link S5++ and S5-LAN++) |
| Fetch Port | — | Via FETCH/WRITE: the port of the CP's FETCH connection (required for FETCH/WRITE) |
| Write Port | — | Via FETCH/WRITE: the port of the CP's WRITE connection. Leave empty to only read. |
| Timeout | 5s | Maximum time to connect, and to wait for each answer |
Testing the Connection
Test Connection opens the connection (the S7 connection, or both FETCH/WRITE connections) and reads flag byte MB0.
S5 Addresses
| Address | What it is | Type | Written |
|---|---|---|---|
E3.1 / I3.1, EB3, EW4, ED4 | Inputs (bytes 0–127): bit, byte, word, double word | BIT, BYTE, WORD, DWORD | No |
A4.0 / Q4.0, AB4, AW4, AD4 | Outputs (bytes 0–127) | as above | Yes |
M10.2 / F10.2, MB10, MW10, MD10 | Flags (bytes 0–255) | as above | Yes |
DB10.DW4 | Data word 4 of DB10 | WORD | Yes |
DB10.DL4, DB10.DR4 | The left (high) and right (low) byte of a data word | BYTE | Yes |
DB10.DD4 | Data words 4 and 5 as a double word | DWORD | Yes |
DB10.D4.15 | Bit 15 of data word 4 (bit 0 is the lowest) | BIT | Yes |
T5 | Timer 5, in milliseconds | number | No |
Z3 / C3 | Counter 3 | number (0–999) | No |
Data blocks are DB1–DB255, data words DW0–DW2047. A data block is word-addressed, as in STEP 5: DW4 is the fifth word, not byte 4.
Typing a word or double word
A word reads as an unsigned WORD and a double word as an unsigned DWORD unless typed with a suffix:
| Suffix | On | Reads as |
|---|---|---|
:INT | a word (MW10:INT, DB10.DW4:INT) | 16-bit signed |
:DINT | a double word (DB10.DD4:DINT) | 32-bit signed |
:KG | a double word (DB10.DD4:KG, MD20:KG) | the S5 floating-point format |
An S5 stores a floating-point number in its own format, not IEEE 754 as an S7 does: an 8-bit exponent and a 24-bit mantissa, both in two's complement. Read and write such a value with :KG; reading it as :DINT shows the raw bits.
A timer is read in milliseconds: its BCD value multiplied by its time base (10 ms, 100 ms, 1 s or 10 s).
The CPU reads its inputs in on every cycle, so a value written there is overwritten. Timers and counters run in the S5 program. To command an S5, write a flag or a data word the program reads.
Function Builder
Read Points (s5.read)
Read a set of named points, each by S5 address, in the fewest reads.
| Field | Required | Description |
|---|---|---|
| Points | Yes | One or more {name, address}: the name is the key in the result, the address an S5 address |
Example: speed = DB10.DD4:KG, pump = A4.0, parts = Z3 returns { "speed": 100.0, "pump": true, "parts": 42 } under values.
A point name may not repeat, and an address that is not an S5 address (such as DB0.DW1 or E128.0) is refused when the function is saved.
Write Point (s5.write)
Write one value to a data block item, a flag or an output.
| Field | Required | Description |
|---|---|---|
| Address | Yes | A data block item (DB10.DW4, DB10.DD4:KG, DB10.D4.15), a flag (M10.2, MW10) or an output (A4.0, AW4). Supports ((paramName)). |
| Value | Yes | true/false (also on/off, 1/0) for a bit, a number otherwise. Supports ((paramName)). |
A single bit, or one byte of a data word (DL, DR), is written by reading its byte or word, changing it and writing it back. If the program writes other bits of the same byte or word at the same moment, the write can race with it.
Testing Functions
Use Test Function on the function form to run a read or write against the live S5 before saving it.
Pipeline Integration
Each operation has its own node: S5 Read and S5 Write. See Siemens S5 Nodes for their parameters and results.
Troubleshooting
| Symptom | Possible cause | Solution |
|---|---|---|
| Test Connection fails via a gateway | Wrong address, or the gateway expects another rack/slot | Check the gateway's IP address; IBH Link S5++ and S5-LAN++ answer at rack 0, slot 2 |
| Test Connection fails via FETCH/WRITE | A port is not the CP's FETCH or WRITE connection, or the connection is not configured passive | Check the CP's connections: a Fetch passive and a Write passive connection, on the ports set here |
error 2, the requested block does not exist | The data block is not loaded in the S5 | Check the DB number; the block must exist in the PLC program |
error 3, the requested block is too small | The address runs past the end of the area or data block | Check the data word number against the block's length |
this connection has no write port | A FETCH/WRITE connection without a write port | Set the Write Port to the CP's WRITE connection |
| A floating-point value reads as a huge or tiny number | It was read without :KG, or the value is IEEE (written by newer equipment) | Add :KG for S5 floating point; an IEEE value reads correctly as :DINT bits only |