Siemens S7 Nodes

A suite of nodes for reading, writing, and monitoring data on Siemens S7 PLCs, from S7-300 and S7-400 to S7-1200, S7-1500 and LOGO!, using the S7 communication protocol (S7comm).

Overview

The Siemens S7 nodes connect FlowFuse flows to Siemens PLCs over Ethernet. They read and write data blocks, markers, inputs, outputs, counters and timers, watch addresses for changes, discover the data blocks on a PLC, and import tag lists exported from TIA Portal and STEP 7, so you can work with named tags rather than raw addresses.

Each connection can use one of three backends:

  • nodes7 (default): pure JavaScript, nothing to compile, works anywhere Node-RED runs.
  • snap7: the native Snap7 library. Adds block listing, CPU status and CPU control, and a few data types nodes7 does not support.
  • sim: a built-in simulated PLC, for building and testing flows without hardware.

This is a FlowFuse Certified Node. Unlike community nodes, which vary in quality and can go unmaintained without warning, FlowFuse vets Certified Nodes for quality, security, and support, and maintains them on an ongoing basis. Read more about Certified Nodes.

The Siemens S7 nodes are not available by default. They are part of the FlowFuse Edge Certified Nodes catalogue, which is part of the FlowFuse Edge offering. Please contact our sales team at Contact us to learn more or to request access.

What is S7 communication?

S7 communication (S7comm) is the protocol Siemens SIMATIC PLCs use to exchange data with HMIs, SCADA systems, engineering tools and other PLCs. It runs over ISO-on-TCP (RFC 1006) on TCP port 102 typically, so an Ethernet-connected PLC needs no extra gateway or OPC server.

S7comm reads and writes by absolute address: a data block number and byte offset (DB1,REAL0, or DB1.DBD0 in TIA Portal notation), or a memory area such as markers (MW10), inputs (I0.1) and outputs (QW2). It does not use the symbolic tag names of TIA Portal, which is why S7-1200 and S7-1500 PLCs need a couple of settings changed before they can be reached this way (see Requirements).

Supported Hardware

PLC familyDefault rack / slotNotes
S7-15000 / 1Enable PUT/GET access; use non-optimized data blocks
S7-12000 / 1Enable PUT/GET access; use non-optimized data blocks
S7-3000 / 2
S7-4000 / 3Use the slot of the CPU in the rack
S7-2000 / 1Ethernet-connected models
LOGO!-Connects by TSAP instead of rack and slot, e.g. local 01.00 and remote 02.00

Requirements

  • Node.js 18 or later
  • Node-RED 2.0 or later
  • Access to the FlowFuse Edge Certified Nodes catalogue (part of the FlowFuse Edge offering)
  • Network access from your FlowFuse instance or device to the PLC on TCP port 102

Preparing an S7-1200 or S7-1500

These PLCs block external S7 access by default. In TIA Portal:

  1. In the PLC's device configuration, under Protection & Security > Connection mechanisms, tick Permit access with PUT/GET communication from remote partner.
  2. For each data block you want to read or write, open its Properties > Attributes and untick Optimized block access, then compile. Markers, inputs and outputs do not need this.
  3. Download the changes to the PLC.

The snap7 backend

The default nodes7 backend needs nothing extra. The optional snap7 backend uses the native node-snap7 module, which is installed alongside the nodes where it can be built for your platform. If it is not available, the snap7 option reports that it is missing and the nodes7 backend continues to work.

Installation

Because these nodes are part of the FlowFuse Edge Certified Nodes catalogue, which is part of the FlowFuse Edge offering, make sure your account has access before installing. Contact our sales team if you don't.

Newly installed nodes are picked up automatically, no restart needed. Restart is only required when you update a node that's already installed: restart any remote instance or hosted instance running the previous version.
  1. Open the Palette Manager from the top-right menu in the FlowFuse editor.
  2. Switch to the Install tab.
  3. Search for the FlowFuse Edge Certified Nodes collection.
  4. Locate @flowfuse-certified-nodes/s7 and click Install.

After installation, the nodes appear under the S7 Suite category in the palette, and the connection is set up in an s7-config configuration node.

Nodes in the Suite

NodeTypeDescription
s7-configConfigThe connection to one PLC: host, port, rack and slot (or TSAPs), backend, timeouts and automatic reconnection. Connection settings can come from environment variables, and flows can connect, disconnect, reconnect or ask for the connection status.
s7-readIn/OutRead one or many addresses as a single value, an object keyed by address or label, a raw buffer, a structure defined by a schema, or an array of bits. Addresses can be set in the node or taken from the message, flow, global context or an environment variable. Import tag lists from TIA Portal (.xlsx, .xml, .sdf) or STEP 7 (.csv, .cfg).
s7-writeIn/OutWrite single values, arrays, strings, several addresses at once, or a whole structure.
s7-triggerOutPoll addresses at an interval and send a message when a value changes, with rising and falling edge detection for bits and a deadband for analog values.
s7-browseIn/OutDiscover the data blocks and memory areas on a PLC, or read them from a STEP 7 .cfg export without a live connection.
s7-controlIn/OutStart, stop or cold-start the PLC CPU. snap7 backend only, and many S7-1200 and S7-1500 PLCs refuse these commands over PUT/GET.

Variable addressing

Addresses use the nodes7 format, which differs a little from TIA Portal and STEP 7. The TIA Portal form is accepted too, so DB1.DBD8 and DB1,DWORD8 read the same value, and both forms can be mixed in one node.

Data blocks

AddressTIA Portal equivalentValue in Node-REDDescription
DB5,X0.1DB5.DBX0.1booleanBit 1 of byte 0 of DB 5
DB23,BYTE1DB23.DBB1numberByte 1 of DB 23 (0 to 255)
DB100,CHAR2DB100.DBB2stringByte 2 of DB 100 as a character
DB42,INT4DB42.DBW4numberSigned 16-bit integer at byte 4 of DB 42
DB57,WORD4DB57.DBW4numberUnsigned 16-bit integer at byte 4 of DB 57
DB13,DINT6DB13.DBD6numberSigned 32-bit integer at byte 6 of DB 13
DB19,DWORD6DB19.DBD6numberUnsigned 32-bit integer at byte 6 of DB 19
DB21,REAL8DB21.DBD8number32-bit floating point number at byte 8 of DB 21
DB21,LREAL12-number64-bit floating point number at byte 12 of DB 21
DB2,STRING10.20-stringSTRING[20] starting at byte 10 of DB 2
DB1,DTL0-DateDTL at byte 0 of DB 1, as server local time. Use DTLZ if the PLC keeps UTC
DB1,DT12-DateDATE_AND_TIME at byte 12 of DB 1, as server local time. Use DTZ if the PLC keeps UTC

The TIA Portal column shows where the value lives. Typed in that form, DBW always reads as an unsigned WORD and DBD as an unsigned DWORD, so use the nodes7 form for INT, DINT and REAL.

A string takes 2 bytes more than its length: the first byte holds the maximum length and the second the current length. When writing to a string that is already declared in the PLC, the length can be left off (DB2,STRING10).

Inputs, outputs and markers

AddressTIA Portal equivalentValue in Node-REDDescription
I1.0I1.0booleanBit 0 of byte 1 of the inputs
Q2.1Q2.1booleanBit 1 of byte 2 of the outputs
M3.2M3.2booleanBit 2 of byte 3 of the markers
IB4IB4numberByte 4 of the inputs (0 to 255)
QB5QB5numberByte 5 of the outputs (0 to 255)
MB6MB6numberByte 6 of the markers (0 to 255)
IW10IW10numberUnsigned 16-bit integer at byte 10 of the inputs
QW12QW12numberUnsigned 16-bit integer at byte 12 of the outputs
MW14MW14numberUnsigned 16-bit integer at byte 14 of the markers
ID16ID16numberUnsigned 32-bit integer at byte 16 of the inputs
QD20QD20numberUnsigned 32-bit integer at byte 20 of the outputs
MD24MD24numberUnsigned 32-bit integer at byte 24 of the markers
C1C1numberCounter 1 (snap7 backend only)
T2T2numberTimer 2 (snap7 backend only)

Arrays

A number after the offset reads that many values as an array, and a write takes an array of exactly that many values. For a bit, the second number is the count.

AddressDescription
DB1,INT20.33 INT values starting at byte 20 of DB 1, an Array[0..2] of Int
DB1,REAL40.1010 REAL values starting at byte 40 of DB 1
DB1,X10.3.88 consecutive bits starting at bit 3 of byte 10 of DB 1, an Array[0..7] of Bool
MB20.44 bytes starting at byte 20 of the markers
M10.0.1616 consecutive bits starting at bit 0 of byte 10 of the markers

Data types and backends

The nodes7 backend reads and writes BOOL, BYTE, CHAR, WORD, INT, DWORD, DINT, REAL, LREAL, STRING, DT, DTZ, DTL and DTLZ. These types need the snap7 backend:

  • USINT, UINT, UDINT, LINT and ULINT
  • DATE, TIME, TIME_OF_DAY, S5TIME and DATE_AND_TIME
  • reading WSTRING (nodes7 can write it)
  • counters and timers

The sim backend supports every type. If the nodes7 backend is given a type it does not support, the node reports an error that names the address.