Siemens S7 Nodes
A suite of nodes for reading, writing, and monitoring data on Siemens S7 PLCs, from S7-300 and S7-400 to S7-1200, S7-1500 and LOGO!, using the S7 communication protocol (S7comm).
Overview
The Siemens S7 nodes connect FlowFuse flows to Siemens PLCs over Ethernet. They read and write data blocks, markers, inputs, outputs, counters and timers, watch addresses for changes, discover the data blocks on a PLC, and import tag lists exported from TIA Portal and STEP 7, so you can work with named tags rather than raw addresses.
Each connection can use one of three backends:
- nodes7 (default): pure JavaScript, nothing to compile, works anywhere Node-RED runs.
- snap7: the native Snap7 library. Adds block listing, CPU status and CPU control, and a few data types nodes7 does not support.
- sim: a built-in simulated PLC, for building and testing flows without hardware.
This is a FlowFuse Certified Node. Unlike community nodes, which vary in quality and can go unmaintained without warning, FlowFuse vets Certified Nodes for quality, security, and support, and maintains them on an ongoing basis. Read more about Certified Nodes.
What is S7 communication?
S7 communication (S7comm) is the protocol Siemens SIMATIC PLCs use to exchange data with HMIs, SCADA systems, engineering tools and other PLCs. It runs over ISO-on-TCP (RFC 1006) on TCP port 102 typically, so an Ethernet-connected PLC needs no extra gateway or OPC server.
S7comm reads and writes by absolute address: a data block number and byte offset (DB1,REAL0, or DB1.DBD0 in TIA Portal notation), or a memory area such as markers (MW10), inputs (I0.1) and outputs (QW2). It does not use the symbolic tag names of TIA Portal, which is why S7-1200 and S7-1500 PLCs need a couple of settings changed before they can be reached this way (see Requirements).
Supported Hardware
| PLC family | Default rack / slot | Notes |
|---|---|---|
| S7-1500 | 0 / 1 | Enable PUT/GET access; use non-optimized data blocks |
| S7-1200 | 0 / 1 | Enable PUT/GET access; use non-optimized data blocks |
| S7-300 | 0 / 2 | |
| S7-400 | 0 / 3 | Use the slot of the CPU in the rack |
| S7-200 | 0 / 1 | Ethernet-connected models |
| LOGO! | - | Connects by TSAP instead of rack and slot, e.g. local 01.00 and remote 02.00 |
Requirements
- Node.js 18 or later
- Node-RED 2.0 or later
- Access to the FlowFuse Edge Certified Nodes catalogue (part of the FlowFuse Edge offering)
- Network access from your FlowFuse instance or device to the PLC on TCP port 102
Preparing an S7-1200 or S7-1500
These PLCs block external S7 access by default. In TIA Portal:
- In the PLC's device configuration, under Protection & Security > Connection mechanisms, tick Permit access with PUT/GET communication from remote partner.
- For each data block you want to read or write, open its Properties > Attributes and untick Optimized block access, then compile. Markers, inputs and outputs do not need this.
- Download the changes to the PLC.
The snap7 backend
The default nodes7 backend needs nothing extra. The optional snap7 backend uses the native node-snap7 module, which is installed alongside the nodes where it can be built for your platform. If it is not available, the snap7 option reports that it is missing and the nodes7 backend continues to work.
Installation
Because these nodes are part of the FlowFuse Edge Certified Nodes catalogue, which is part of the FlowFuse Edge offering, make sure your account has access before installing. Contact our sales team if you don't.
Install via the Palette Manager (recommended)
- Open the Palette Manager from the top-right menu in the FlowFuse editor.
- Switch to the Install tab.
- Search for the FlowFuse Edge Certified Nodes collection.
- Locate
@flowfuse-certified-nodes/s7and click Install.
After installation, the nodes appear under the S7 Suite category in the palette, and the connection is set up in an s7-config configuration node.
Nodes in the Suite
| Node | Type | Description |
|---|---|---|
| s7-config | Config | The connection to one PLC: host, port, rack and slot (or TSAPs), backend, timeouts and automatic reconnection. Connection settings can come from environment variables, and flows can connect, disconnect, reconnect or ask for the connection status. |
| s7-read | In/Out | Read one or many addresses as a single value, an object keyed by address or label, a raw buffer, a structure defined by a schema, or an array of bits. Addresses can be set in the node or taken from the message, flow, global context or an environment variable. Import tag lists from TIA Portal (.xlsx, .xml, .sdf) or STEP 7 (.csv, .cfg). |
| s7-write | In/Out | Write single values, arrays, strings, several addresses at once, or a whole structure. |
| s7-trigger | Out | Poll addresses at an interval and send a message when a value changes, with rising and falling edge detection for bits and a deadband for analog values. |
| s7-browse | In/Out | Discover the data blocks and memory areas on a PLC, or read them from a STEP 7 .cfg export without a live connection. |
| s7-control | In/Out | Start, stop or cold-start the PLC CPU. snap7 backend only, and many S7-1200 and S7-1500 PLCs refuse these commands over PUT/GET. |
Variable addressing
Addresses use the nodes7 format, which differs a little from TIA Portal and STEP 7. The TIA Portal form is accepted too, so DB1.DBD8 and DB1,DWORD8 read the same value, and both forms can be mixed in one node.
Data blocks
| Address | TIA Portal equivalent | Value in Node-RED | Description |
|---|---|---|---|
DB5,X0.1 | DB5.DBX0.1 | boolean | Bit 1 of byte 0 of DB 5 |
DB23,BYTE1 | DB23.DBB1 | number | Byte 1 of DB 23 (0 to 255) |
DB100,CHAR2 | DB100.DBB2 | string | Byte 2 of DB 100 as a character |
DB42,INT4 | DB42.DBW4 | number | Signed 16-bit integer at byte 4 of DB 42 |
DB57,WORD4 | DB57.DBW4 | number | Unsigned 16-bit integer at byte 4 of DB 57 |
DB13,DINT6 | DB13.DBD6 | number | Signed 32-bit integer at byte 6 of DB 13 |
DB19,DWORD6 | DB19.DBD6 | number | Unsigned 32-bit integer at byte 6 of DB 19 |
DB21,REAL8 | DB21.DBD8 | number | 32-bit floating point number at byte 8 of DB 21 |
DB21,LREAL12 | - | number | 64-bit floating point number at byte 12 of DB 21 |
DB2,STRING10.20 | - | string | STRING[20] starting at byte 10 of DB 2 |
DB1,DTL0 | - | Date | DTL at byte 0 of DB 1, as server local time. Use DTLZ if the PLC keeps UTC |
DB1,DT12 | - | Date | DATE_AND_TIME at byte 12 of DB 1, as server local time. Use DTZ if the PLC keeps UTC |
The TIA Portal column shows where the value lives. Typed in that form, DBW always reads as an unsigned WORD and DBD as an unsigned DWORD, so use the nodes7 form for INT, DINT and REAL.
A string takes 2 bytes more than its length: the first byte holds the maximum length and the second the current length. When writing to a string that is already declared in the PLC, the length can be left off (DB2,STRING10).
Inputs, outputs and markers
| Address | TIA Portal equivalent | Value in Node-RED | Description |
|---|---|---|---|
I1.0 | I1.0 | boolean | Bit 0 of byte 1 of the inputs |
Q2.1 | Q2.1 | boolean | Bit 1 of byte 2 of the outputs |
M3.2 | M3.2 | boolean | Bit 2 of byte 3 of the markers |
IB4 | IB4 | number | Byte 4 of the inputs (0 to 255) |
QB5 | QB5 | number | Byte 5 of the outputs (0 to 255) |
MB6 | MB6 | number | Byte 6 of the markers (0 to 255) |
IW10 | IW10 | number | Unsigned 16-bit integer at byte 10 of the inputs |
QW12 | QW12 | number | Unsigned 16-bit integer at byte 12 of the outputs |
MW14 | MW14 | number | Unsigned 16-bit integer at byte 14 of the markers |
ID16 | ID16 | number | Unsigned 32-bit integer at byte 16 of the inputs |
QD20 | QD20 | number | Unsigned 32-bit integer at byte 20 of the outputs |
MD24 | MD24 | number | Unsigned 32-bit integer at byte 24 of the markers |
C1 | C1 | number | Counter 1 (snap7 backend only) |
T2 | T2 | number | Timer 2 (snap7 backend only) |
Arrays
A number after the offset reads that many values as an array, and a write takes an array of exactly that many values. For a bit, the second number is the count.
| Address | Description |
|---|---|
DB1,INT20.3 | 3 INT values starting at byte 20 of DB 1, an Array[0..2] of Int |
DB1,REAL40.10 | 10 REAL values starting at byte 40 of DB 1 |
DB1,X10.3.8 | 8 consecutive bits starting at bit 3 of byte 10 of DB 1, an Array[0..7] of Bool |
MB20.4 | 4 bytes starting at byte 20 of the markers |
M10.0.16 | 16 consecutive bits starting at bit 0 of byte 10 of the markers |
Data types and backends
The nodes7 backend reads and writes BOOL, BYTE, CHAR, WORD, INT, DWORD, DINT, REAL, LREAL, STRING, DT, DTZ, DTL and DTLZ. These types need the snap7 backend:
USINT,UINT,UDINT,LINTandULINTDATE,TIME,TIME_OF_DAY,S5TIMEandDATE_AND_TIME- reading
WSTRING(nodes7 can write it) - counters and timers
The sim backend supports every type. If the nodes7 backend is given a type it does not support, the node reports an error that names the address.