A PLC can control a VFD by hardwired I/O, by a serial protocol (USS, Modbus RTU), or by a fieldbus or Industrial Ethernet telegram (PROFIBUS DP, PROFINET IO, Modbus TCP). Network methods exchange PZD process data — control word, setpoint, status word, actual value — every bus cycle. You do not need %IW and %QW addresses to reach that data: DPRD_DAT and DPWR_DAT exchange the whole telegram using the submodule's hardware identifier, library blocks such as SINA_SPEED take the same identifier, and USS or Modbus keep their data in data blocks with no I/Q addresses at all.
- Hardwired control carries a few signals; a telegram carries the whole drive.
- PZD is cyclic and belongs to run, stop and speed; parameters are acyclic and belong to commissioning values.
- The hardware identifier replaces the address and gives consistent access to the whole telegram.
- Whatever the path, the drive still sees the same STW1 and ZSW1 bits.
How to Network a Siemens PLC and a VFD
To network a Siemens PLC with a VFD you choose one of four methods: hardwired I/O, serial USS or Modbus RTU over RS-485, PROFIBUS DP, or PROFINET IO. For a SINAMICS drive on a new machine, PROFINET with Standard Telegram 1 is the default: the PLC writes a control word and a speed setpoint every bus cycle and reads a status word and the actual speed back. Everything below compares the methods, then shows how to reach that data in the program — including without %IW and %QW addresses.
Four Ways a PLC Talks to a VFD
Every method below ends at the same place — the drive's control and status information — but they differ enormously in how much they carry and what they cost to wire.
What Each Method Can and Cannot Do
| Method | What the PLC can do | What it cannot do | Wiring per drive |
|---|---|---|---|
| Hardwired DI/DO + analog | Start, stop, direction, speed setpoint, a few status signals | Read fault numbers, change parameters, see actual current | One pair per signal — typically 6 to 10 cores |
| Serial: USS | Start, stop, speed, status, actual values, parameter read/write | Fast updates; the bus is polled in sequence | One RS-485 pair for up to 16 drives on the bus |
| Serial: Modbus RTU | Same as USS, using holding registers | Vendor diagnostics; speed is limited | One RS-485 pair, multidrop |
| PROFIBUS DP | Full telegram: control word, setpoints, status, actual values, acyclic parameters | Share the cable with IT traffic | One DP drop per drive |
| PROFINET IO | Everything above, faster, with topology and device replacement | — | One Ethernet cable per drive, line or star |
| Modbus TCP / EtherNet/IP | Register or assembly based control over Ethernet | PROFIdrive telegram features on Siemens drives | One Ethernet cable per drive |
Protocol Comparison
Read the table by the row that matters for your machine: reaction time, number of drives, or what the PLC must be able to read back. For a deeper look at the two fieldbuses see PROFINET vs PROFIBUS.
| Hardwired | USS | Modbus RTU | PROFIBUS DP | PROFINET IO | |
|---|---|---|---|---|---|
| Medium | Copper per signal | RS-485 | RS-485 | RS-485 | Ethernet |
| Typical speed | Instant (analog) | Up to 187.5 kbit/s | 9.6 – 115.2 kbit/s | Up to 12 Mbit/s | 100 Mbit/s |
| Drives per line | 1 | Up to 16 | Up to about 30 | Up to 125 addresses | Limited by the controller |
| Cyclic data | Wired signals only | Control + status words | Holding registers | Telegram PZD | Telegram PZD |
| Parameter access | No | USS parameter jobs | Registers | PKW / acyclic | Acyclic (index 47) |
| PLC blocks needed | None | USS_Port_Scan, USS_Drive_Control | MB_COMM_LOAD, MB_MASTER | Standard FB or SINA blocks | Standard FB or SINA blocks |
| Diagnostics | Wired fault relay | Status word | Status register | Slave diagnostics | Device and network diagnostics |
| Best for | One simple drive | Small machines, low cost | Mixed-vendor drives | Existing PROFIBUS plants | New machines and plants |
Practise every method on real drives
Hardwired, USS, Modbus and PROFINET control of a SINAMICS drive from one PLC. Pune classroom or live online.
PZD and Parameters: Two Channels
Any network connection to a drive carries two kinds of traffic. Mixing them up is the most common design mistake in drive programs.
| PZD — cyclic | Parameter channel — acyclic | |
|---|---|---|
| Carries | Control word, speed setpoint, status word, actual values | Any drive parameter: ramp times, limits, fault buffer |
| Update | Every bus cycle, a few milliseconds | On request, over several cycles |
| Triggered by | Nothing — it runs continuously | A block call in the program |
| Blocks | None, or a mapping FB | WRREC / RDREC, SINA_PARA |
| Use for | Run, stop, speed, interlocks | Commissioning values, recipes, diagnostics |
| Never use for | Writing a parameter every scan | Start, stop or speed control |
The words inside PZD depend on the telegram — see G120 Telegram Selection in TIA Portal and STW1 and ZSW1 bit by bit.
PZD Without %IW and %QW
%IW and %QW are only one way into the process image. They are convenient for a two-word telegram, but they tie the program to addresses that move whenever the hardware configuration changes, and they read the telegram word by word. There are three routes to the same PZD data.
| Method | Block | Key input instead of an address | Where the data lives | When to use |
|---|---|---|---|---|
| Consistent telegram access | DPRD_DAT / DPWR_DAT | LADDR = hardware identifier of the telegram submodule | A DB structure you define | Telegrams longer than two words, or when you want no absolute addresses |
| Ready-made drive control | SINA_SPEED (DriveLib) | HWIDSTW and HWIDZSW hardware identifiers | The block's instance DB | Standard speed control on SINAMICS with telegram 1, 20 or 352 |
| Parameter read/write | SINA_PARA, or WRREC / RDREC | Hardware identifier plus record index 47 | A request/response DB | Ramp times, limits, reading the fault buffer |
| Serial USS | USS_Port_Scan + USS_Drive_Control | Port hardware identifier and drive number | Instance and buffer DBs | RS-485 drives — there are no I/Q addresses at all |
| Modbus RTU / TCP | MB_MASTER / MB_CLIENT | Register address in the drive | A DB array | Mixed-vendor drives |
Paths B and C also solve data consistency. A telegram longer than a couple of words should be exchanged in one operation so that every word comes from the same bus cycle — that is exactly what DPRD_DAT and DPWR_DAT do.
The Hardware Identifier
The hardware identifier is the key to all of this. TIA Portal creates one for every module and submodule, including each drive telegram, and lists them in the System constants tab of the device properties.
SINA_SPEED and Library Blocks
Siemens DriveLib blocks wrap the drive state machine so the program only supplies a run command and a speed. SINA_SPEED is the usual one for speed control; it takes the two hardware identifiers instead of telegram addresses.
| SINA_SPEED input | Meaning | Typical value |
|---|---|---|
EnableAxis | Run command | From the machine sequence |
AckError | Fault acknowledge — edge triggered | Reset pushbutton pulse |
SpeedSp | Speed setpoint in rpm | From the HMI |
RefSpeed | Reference speed, must equal p2000 | 1500.0 |
HWIDSTW | Hardware identifier of the setpoint (Q) submodule | From System constants |
HWIDZSW | Hardware identifier of the actual value (I) submodule | From System constants |
ActVelocity (output) | Actual speed in rpm | To the HMI |
Error / Status (outputs) | Block error and status word | To diagnostics |
A block of your own does the same job with less hidden behaviour and is easier to teach — see G120 PROFINET Standard FB, which maps the telegram bit by bit.
Serial Drives: USS and Modbus
On an RS-485 link there is no process image at all. The instruction blocks move the data between the communication port and data blocks, and the port itself is addressed by its hardware identifier. USS is the Siemens protocol and carries a control word and status word much like a telegram; Modbus RTU uses holding registers instead.
| Typical G120 Modbus RTU register | Direction | Content |
|---|---|---|
| 40100 | PLC → drive | Control word (STW1) |
| 40101 | PLC → drive | Speed setpoint, 16384 = 100 % of p2000 |
| 40110 | Drive → PLC | Status word (ZSW1) |
| 40111 | Drive → PLC | Actual speed |
| 4xxxx parameter registers | Both | Individual drive parameters |
Register numbers differ between drives and firmware versions, so always confirm them in the drive's Modbus register table before writing the program.
Acyclic Parameter Access
Ramp times, current limits and the fault buffer are parameters, not process data. They travel on the acyclic channel: the program sends a request, the drive answers over the next cycles.
Choosing a Method
Pitfalls
| Pitfall | What happens | Avoid it by |
|---|---|---|
| Reading a telegram word by word | Words can come from two different bus cycles | Using DPRD_DAT for the whole telegram, or a single consistent access |
| Writing parameters cyclically | The drive's memory wears and the bus load rises | Writing once on a change, through the acyclic channel |
| Holding the fault acknowledge bit high | A repeating fault is hidden and the motor keeps restarting | Sending a short pulse on the rising edge |
| Driving the HMI lamp from the run command | The lamp lies when the drive is not running | Using the status word bit for operation enabled |
| Mismatched reference speed | Setpoint and actual speed are scaled wrongly | Making RefSpeed or your scaling equal p2000 |
| Serial link too slow for the task | Speed updates lag, interlocks react late | Using a fieldbus where the reaction time matters |
Step-by-Step Lab: One Drive, Three Methods
Hands-on- An S7-1200 or S7-1500 with a SINAMICS G120 on PROFINET, Standard Telegram 1 configured, and a motor on a test bench.
- The DriveLib library installed if you want to try SINA_SPEED.
- Estimated time: 75 minutes.
Method A — absolute addresses
Write STW1 to the telegram Q word and read ZSW1 from the I word using PLC tags on those addresses.
Find the hardware identifiers
Open the drive properties, System constants tab, and note the identifiers of the two telegram submodules.
Method B — DPRD_DAT and DPWR_DAT
Create a DB with two words for send and two for receive, then exchange them with DPWR_DAT and DPRD_DAT using LADDR.
Method C — SINA_SPEED
Call SINA_SPEED, wire EnableAxis, SpeedSp, RefSpeed and the two hardware identifiers.
Change the address on purpose
In the Device overview, change the telegram start address and download again.
Read a parameter acyclically
Read the ramp-up time p1120 with SINA_PARA or RDREC, then write a new value.
You have understood PLC to VFD communication if the same motor ran through three different program paths, if you can say why methods B and C survived the address change, and if you can name which data belongs in PZD and which belongs in the parameter channel.
Frequently asked questions
How do I network a Siemens PLC with a VFD?
Pick the connection the drive supports and the machine needs: hardwired I/O for a single simple drive, USS or Modbus RTU over RS-485 for low-cost serial control, PROFIBUS DP on existing plants, or PROFINET IO on new ones. For a SINAMICS drive on PROFINET, configure Standard Telegram 1 in the hardware configuration, set p0922 to match in the drive, then exchange the control word, speed setpoint, status word and actual speed cyclically from the PLC program.
Can a PLC control a VFD without using %IW and %QW addresses?
Yes. DPRD_DAT and DPWR_DAT exchange the whole telegram using the hardware identifier of the submodule, and library blocks such as SINA_SPEED take the same identifier as HWIDSTW and HWIDZSW. Serial protocols like USS and Modbus never use I/Q addresses at all — their data sits in data blocks.
What is a hardware identifier?
It is a number TIA Portal assigns to every module and submodule, available as a system constant such as Drive_1~Standard_Telegram_1. Passing it to a block tells the block which device to talk to, so the program no longer depends on the absolute I/Q addresses.
What is the difference between PZD and parameter access?
PZD is the cyclic process data — control word, setpoint, status word and actual values — exchanged every bus cycle. Parameter access is acyclic: the program asks for or writes a single parameter, such as a ramp time, and the answer comes back over several cycles.
Should I use SINA_SPEED or write my own function block?
SINA_SPEED is quick to apply and handles the drive state machine for you. A block of your own is smaller, easier to follow in the classroom, and lets you decide exactly how each bit behaves. Both use the same telegram underneath.
Does USS or Modbus RTU need I/Q addresses?
No. The communication module is addressed through its own hardware identifier and the data is exchanged through data blocks. That is also why the update rate depends on the instruction call and the baud rate, not on the process image.
Is hardwired control still acceptable?
For a single drive with start, stop and a speed potentiometer, yes — it is cheap and needs no program. It stops being sensible as soon as you want fault numbers, actual current, parameter changes or more than a couple of drives.
Which method gives the fastest reaction?
A fieldbus or Industrial Ethernet telegram, because the data is exchanged automatically every cycle. Serial protocols depend on the instruction being called and on the baud rate, and hardwired analog is fast but carries almost no information.