Skip to main content
Siemens · Technical Blog

SINAMICS G120 PROFINET Standard FB: Create, Call in OB1 and Map to I/Q Addresses

Create one standard FB for a SINAMICS G120 on PROFINET, call it in OB1 with an instance DB, and map it to the telegram's I and Q addresses.

2,500+ engineers trained 4.9/5 Google rating 21+ years, Chinchwad, Pune Next batch: contact for dates
Quick answer

Create one function block, FB_VFD, whose inputs are the 16 STW1 bits, Set_RPM, SW_01 and SW_02, and whose outputs are CW_01, CW_02, the 16 ZSW1 bits and Act_RPM. Inside, 34 Ladder networks map the bits and scale the speed. Call it in OB1 with an instance DB per drive, then connect CW_01 → %QW256, CW_02 → %QW258, %IW256 → SW_01 and %IW258 → SW_02, using the addresses from the G120's Device overview.

  • One FB, one instance DB per drive. A second drive needs a new call and new addresses — no new code.
  • Give the "held at 1" bits a default of TRUE, so OB1 only wires what actually changes.
  • Take the I and Q addresses from the Device overview of the G120, never from memory.
  • Read "running" from Oper_En (ZSW1 bit 2), never from the ON_OFF1 command.

Why One Standard FB for Every G120

A plant with ten G120 drives can have ten copies of the same bit mapping scattered through OB1 — or one tested function block called ten times. The second approach is what "standard FB" means: the drive logic is written and verified once, and each drive only differs in its instance DB and its I/Q addresses.

This guide builds that block for Standard Telegram 1 (PZD-2/2) on an S7-1200 or S7-1500, in four steps: create the interface, write the networks, call it in OB1, and map it to the telegram's I and Q addresses. The meaning of every individual bit is covered in SINAMICS G120 STW1 and ZSW1: Every Control and Status Bit; this page focuses on the block itself.

Block Diagram: OB1, FB, I/Q Addresses and Drive

Data passes through four stages. OB1 supplies machine tags to the FB; the FB packs them into words; the words sit in the PLC's process image at the telegram's addresses; and PROFINET carries them to and from the drive every cycle.

Standard FB data flow: OB1 tags, FB_VFD, PLC I/O addresses and SINAMICS G120 Telegram 1 OB1 passes machine tags into FB_VFD. The FB writes CW_01 and CW_02 to QW256 and QW258, which the drive receives as STW1 and NSOLL_A. The drive sends ZSW1 and NIST_A to IW256 and IW258, which the FB reads as SW_01 and SW_02. OB1Machine tagsTO DRIVEFROM DRIVE"Motor1_Run"to ON_OFF1"HMI_Set_RPM"to Set_RPM"Motor1_Running"from Oper_En"HMI_Act_RPM"from Act_RPMFB_VFDInstance DB_VFD_01TO DRIVEFROM DRIVECW_01WordOutput · STW1CW_02WordOutput · NSOLL_ASW_01WordInput · ZSW1SW_02WordInput · NIST_APLC I/OProcess imageTO DRIVEFROM DRIVE%QW256Q"G120_1_CW_01"%QW258Q"G120_1_CW_02"%IW256I"G120_1_SW_01"%IW258I"G120_1_SW_02"SINAMICS G120Telegram 1 · PZD-2/2TO DRIVEFROM DRIVEPZD1STW1Receive r2050[0]PZD2NSOLL_AReceive r2050[1]PZD1ZSW1Send r0052PZD2NIST_ASend r0063 Addresses are examples — take them from the Device overview of the G120 in TIA Portal.
Orange: commands from OB1 through FB_VFD and %QW256/%QW258 to the drive. Teal: status from the drive through %IW256/%IW258 and FB_VFD back to OB1.

Step 1 — Create the FB Interface

In the project tree open Program blocks → Add new block, choose Function block, name it FB_VFD, set the language to LAD and click OK. Then fill in the block interface as below. The seven bits marked TRUE must be held at 1 for the drive to run, so they get TRUE as their default value — the OB1 call can then leave them unconnected.

SectionNameData typeDefault valueComment
InputON_OFF1BoolFALSESTW1 bit 0 — ON / OFF1
InputOFF2BoolTRUESTW1 bit 1 — No coast stop
InputOFF3BoolTRUESTW1 bit 2 — No quick stop
InputEn_OperBoolTRUESTW1 bit 3 — Enable operation
InputEn_RFGBoolTRUESTW1 bit 4 — Enable ramp generator
InputCont_RFGBoolTRUESTW1 bit 5 — Continue ramp generator
InputEn_SPBoolTRUESTW1 bit 6 — Enable setpoint
InputAck_FltBoolFALSESTW1 bit 7 — Fault acknowledge - pulse only
InputRes_08BoolFALSESTW1 bit 8 — Reserved
InputRes_09BoolFALSESTW1 bit 9 — Reserved
InputCtrl_PLCBoolTRUESTW1 bit 10 — Control by PLC
InputRevBoolFALSESTW1 bit 11 — Reverse
InputRes_12BoolFALSESTW1 bit 12 — Reserved
InputMOP_UpBoolFALSESTW1 bit 13 — MOP raise
InputMOP_DnBoolFALSESTW1 bit 14 — MOP lower
InputCDSBoolFALSESTW1 bit 15 — CDS select
InputSet_RPMReal0.0Speed setpoint in rpm
InputSW_01Word16#0ZSW1 status word from drive
InputSW_02Word16#0NIST_A actual speed from drive
OutputCW_01Word16#0STW1 control word to drive
OutputCW_02Word16#0NSOLL_A speed setpoint to drive
OutputRdy_SwOnBoolFALSEZSW1 bit 0 — Ready to switch on
OutputRdy_OperBoolFALSEZSW1 bit 1 — Ready to operate
OutputOper_EnBoolFALSEZSW1 bit 2 — Operation enabled - real running signal
OutputFaultBoolFALSEZSW1 bit 3 — Fault active
OutputNo_OFF2BoolFALSEZSW1 bit 4 — No coast stop active
OutputNo_OFF3BoolFALSEZSW1 bit 5 — No quick stop active
OutputSwOn_InhBoolFALSEZSW1 bit 6 — Switching on inhibited
OutputWarningBoolFALSEZSW1 bit 7 — Warning active
OutputSpd_OKBoolFALSEZSW1 bit 8 — Speed within tolerance
OutputCtrl_ReqBoolFALSEZSW1 bit 9 — Control requested
OutputSpd_CmpBoolFALSEZSW1 bit 10 — Comparison speed reached
OutputNo_LimitBoolFALSEZSW1 bit 11 — Setpoint reached
OutputApp_12BoolFALSEZSW1 bit 12 — Application specific
OutputApp_13BoolFALSEZSW1 bit 13 — Application specific
OutputApp_14BoolFALSEZSW1 bit 14 — Application specific
OutputApp_15BoolFALSEZSW1 bit 15 — Application specific
OutputAct_RPMReal0.0Actual speed in rpm
TempNorm_SPReal—Normalised setpoint, network 33
TempNorm_ActReal—Normalised actual speed, network 34

With these defaults and ON_OFF1 at FALSE, the FB writes 16#047E to CW_01 from the first scan — the ready state. Setting ON_OFF1 changes it to 16#047F and the drive starts.

Step 2 — Write the FB Networks

The FB body is 34 Ladder networks: 16 for the control word, 16 for the status word and 2 for speed scaling. The operand names match the interface above.

Control word — Networks 1 to 16

Network 1: STW1 bit 0 — ON / OFF1
#ON_OFF1#CW_01.%X0
Network 2: STW1 bit 1 — No coast stop
#OFF2#CW_01.%X1
Network 3: STW1 bit 2 — No quick stop
#OFF3#CW_01.%X2
Network 4: STW1 bit 3 — Enable operation
#En_Oper#CW_01.%X3
Network 5: STW1 bit 4 — Enable ramp generator
#En_RFG#CW_01.%X4
Network 6: STW1 bit 5 — Continue ramp generator
#Cont_RFG#CW_01.%X5
Network 7: STW1 bit 6 — Enable setpoint
#En_SP#CW_01.%X6
Network 8: STW1 bit 7 — Fault acknowledge
#Ack_Flt#CW_01.%X7
Network 9: STW1 bit 8 — Reserved
#Res_08#CW_01.%X8
Network 10: STW1 bit 9 — Reserved
#Res_09#CW_01.%X9
Network 11: STW1 bit 10 — Control by PLC
#Ctrl_PLC#CW_01.%X10
Network 12: STW1 bit 11 — Reverse
#Rev#CW_01.%X11
Network 13: STW1 bit 12 — Reserved
#Res_12#CW_01.%X12
Network 14: STW1 bit 13 — MOP raise
#MOP_Up#CW_01.%X13
Network 15: STW1 bit 14 — MOP lower
#MOP_Dn#CW_01.%X14
Network 16: STW1 bit 15 — CDS select
#CDS#CW_01.%X15

Status word — Networks 17 to 32

Network 17: ZSW1 bit 0 — Ready to switch on
#SW_01.%X0#Rdy_SwOn
Network 18: ZSW1 bit 1 — Ready to operate
#SW_01.%X1#Rdy_Oper
Network 19: ZSW1 bit 2 — Operation enabled
#SW_01.%X2#Oper_En
Network 20: ZSW1 bit 3 — Fault active
#SW_01.%X3#Fault
Network 21: ZSW1 bit 4 — No coast stop active
#SW_01.%X4#No_OFF2
Network 22: ZSW1 bit 5 — No quick stop active
#SW_01.%X5#No_OFF3
Network 23: ZSW1 bit 6 — Switching on inhibited
#SW_01.%X6#SwOn_Inh
Network 24: ZSW1 bit 7 — Warning active
#SW_01.%X7#Warning
Network 25: ZSW1 bit 8 — Speed within tolerance
#SW_01.%X8#Spd_OK
Network 26: ZSW1 bit 9 — Control requested
#SW_01.%X9#Ctrl_Req
Network 27: ZSW1 bit 10 — Comparison speed reached
#SW_01.%X10#Spd_Cmp
Network 28: ZSW1 bit 11 — Setpoint reached
#SW_01.%X11#No_Limit
Network 29: ZSW1 bit 12 — Application specific
#SW_01.%X12#App_12
Network 30: ZSW1 bit 13 — Application specific
#SW_01.%X13#App_13
Network 31: ZSW1 bit 14 — Application specific
#SW_01.%X14#App_14
Network 32: ZSW1 bit 15 — Application specific
#SW_01.%X15#App_15

Speed scaling — Networks 33 and 34

16#4000 (16384) equals 100 % of p2000. Replace 1500.0 with your drive's p2000 reference speed in rpm.

Network 33: Scale speed setpoint rpm → CW_02 (NSOLL_A)
NORM_XReal to RealENENOMINOUTVALUEMAX0.0#Set_RPM1500.0#Norm_SPSCALE_XReal to IntENENOMINOUTVALUEMAX0#Norm_SP16384#CW_02
Network 34: Scale actual speed SW_02 (NIST_A) → rpm
NORM_XInt to RealENENOMINOUTVALUEMAX0#SW_0216384#Norm_ActSCALE_XReal to RealENENOMINOUTVALUEMAX0.0#Norm_Act1500.0#Act_RPM

Build this block on real SINAMICS hardware

Create the FB, call it in OB1 and run a G120 over PROFINET in a guided session. Pune classroom or live online.

Book a Free Demo Class

Step 3 — Call the FB in OB1

Open Main [OB1] and drag FB_VFD from the project tree into network 1. TIA Portal asks for an instance data block: name it DB_VFD_01 and click OK. Then connect the pins as shown. Pins showing ... are left unconnected and use their default value from the interface.

Main [OB1] — Network 1: Conveyor drive 1
%DB1"DB_VFD_01"%FB1"FB_VFD"ENENOON_OFF1%M10.0 "Motor1_Run"OFF2...OFF3...En_Oper...En_RFG...Cont_RFG...En_SP...Ack_Flt%M10.1 "Motor1_Ack_Pulse"Res_08...Res_09...Ctrl_PLC...Rev...Res_12...MOP_Up...MOP_Dn...CDS...Set_RPM%MD20 "HMI_Set_RPM"SW_01%IW256 "G120_1_SW_01"SW_02%IW258 "G120_1_SW_02"CW_01%QW256 "G120_1_CW_01"CW_02%QW258 "G120_1_CW_02"Rdy_SwOn...Rdy_Oper...Oper_En%M10.2 "Motor1_Running"Fault%M10.3 "Motor1_Fault"No_OFF2...No_OFF3...SwOn_Inh...Warning%M10.4 "Motor1_Warning"Spd_OK...Ctrl_Req...Spd_Cmp...No_Limit...App_12...App_13...App_14...App_15...Act_RPM%MD24 "HMI_Act_RPM"

Motor1_Ack_Pulse must be a short pulse of around 200 ms — for example from a TP timer triggered by the reset button — never a held signal, because fault acknowledge works on the rising edge.

Step 4 — Map to I and Q Addresses

The addresses come from the hardware configuration, not from the program. In Devices & networks, double-click the G120, open the Device view and look at the Device overview table. The row Standard telegram 1, PZD-2/2 shows an I address range and a Q address range — for example 256…259 for both.

FB pinPLC tagAddressBytesDrive word
CW_01G120_1_CW_01%QW256%QB256 (bits 8–15), %QB257 (bits 0–7)PZD1 out — STW1
CW_02G120_1_CW_02%QW258%QB258, %QB259PZD2 out — NSOLL_A
SW_01G120_1_SW_01%IW256%IB256 (bits 8–15), %IB257 (bits 0–7)PZD1 in — ZSW1
SW_02G120_1_SW_02%IW258%IB258, %IB259PZD2 in — NIST_A

Create the tags in a PLC tag table with these names, types and addresses. The list below includes the machine tags used in the OB1 call.

PLC tags — drive 1 and OB1 machine tags
// PLC tag table - drive 1 (addresses from the G120 Device overview)
G120_1_CW_01        Word  %QW256   // PZD1 out - STW1 control word
G120_1_CW_02        Word  %QW258   // PZD2 out - NSOLL_A speed setpoint
G120_1_SW_01        Word  %IW256   // PZD1 in  - ZSW1 status word
G120_1_SW_02        Word  %IW258   // PZD2 in  - NIST_A actual speed
// Machine tags used in the OB1 call
Motor1_Run          Bool  %M10.0   // Run command to ON_OFF1
Motor1_Ack_Pulse    Bool  %M10.1   // 200 ms reset pulse to Ack_Flt
Motor1_Running      Bool  %M10.2   // From Oper_En - HMI lamp and interlocks
Motor1_Fault        Bool  %M10.3   // From Fault
Motor1_Warning      Bool  %M10.4   // From Warning
HMI_Set_RPM         Real  %MD20    // Speed setpoint in rpm to Set_RPM
HMI_Act_RPM         Real  %MD24    // Actual speed in rpm from Act_RPM

If the hardware address ever changes, edit only the four G120_1_ tags. The FB and the OB1 call stay untouched.

Adding a Second Drive

Add a second network in OB1, drag in FB_VFD again and create a new instance DB, DB_VFD_02. Connect it to the second drive's telegram addresses and its own machine tags. The FB code is not copied or changed.

DriveInstance DBCW_01CW_02SW_01SW_02
Conveyor 1DB_VFD_01%QW256%QW258%IW256%IW258
Conveyor 2DB_VFD_02%QW260%QW262%IW260%IW262

The second drive's addresses above are examples. TIA Portal assigns them when the drive is added, so always read them from that drive's own Device overview.

Safety note: Clearing OFF2 or OFF3 gives an operational stop sent over the network. It is not a safety function. Emergency stop must be implemented through the drive's STO input or a safety-rated PLC and drive configuration, never through the control word alone.

Step-by-Step Lab: Standard FB on Live Hardware

Hands-on
Before you start
  • An S7-1200 or S7-1500 and a G120 with a PROFINET control unit, both in the same TIA Portal project, with Standard Telegram 1 selected and device names assigned.
  • A motor on a test bench or uncoupled, and p2000 known (this lab assumes 1500 rpm).
  • Estimated time: 60 minutes.
1

Read the telegram addresses

Open the G120 Device overview and note the I and Q address ranges of Standard telegram 1, PZD-2/2.

On screen: the Device overview table with the telegram row selected.
Both ranges are four bytes long, for example I 256…259 and Q 256…259.
2

Create FB_VFD and its interface

Add a new LAD function block and enter the interface from Step 1, including the TRUE defaults.

The interface shows 19 inputs, 19 outputs and 2 temps, with seven inputs defaulted to TRUE.
3

Enter the 34 networks and compile

Build networks 1–34 and compile the block.

The block compiles without errors. A type error in network 33 or 34 usually means CW_02 or SW_02 was declared with the wrong type.
4

Call the FB in OB1 and create the tags

Drag FB_VFD into OB1, create DB_VFD_01, add the PLC tags and connect the pins.

The call shows the instance DB above the box and the tag names on every connected pin.
5

Download and check the ready state

Download, go online and put G120_1_CW_01 and G120_1_SW_01 in a watch table in hexadecimal.

G120_1_CW_01 shows 16#047E and the Rdy_SwOn output of the FB is TRUE, without any command being given.
6

Run the motor

Set HMI_Set_RPM to 750.0, then set Motor1_Run to TRUE.

G120_1_CW_01 changes to 16#047F, Motor1_Running goes TRUE and HMI_Act_RPM settles close to 750.
Checkpoint — how to know you did it right

You have a working standard FB if the drive reaches 16#047E on its own after download, runs on one command bit, and reports its real speed in rpm. Adding a second drive should now take one new OB1 network, one instance DB and four tags.

This block is the PROFINET route. For the other options in Siemens PLC and VFD networking, including USS, Modbus and hardwired control, see the overview.

Frequently asked questions

What is a standard FB for a SINAMICS G120?

It is one function block that holds all the logic for a G120 on Standard Telegram 1: mapping the 16 control word bits into CW_01, splitting the 16 status word bits out of SW_01, and scaling the speed in CW_02 and SW_02. Every drive in the project uses the same FB with its own instance DB.

Why does every drive need its own instance DB?

The instance DB stores the FB's inputs, outputs and defaults for one drive. Calling FB_VFD twice with the same instance DB would make two drives share one set of data. Create DB_VFD_01 for drive 1, DB_VFD_02 for drive 2, and so on.

Where do I find the I and Q addresses of the G120 telegram?

Open the G120 in the Device view and look at the Device overview. The row for Standard telegram 1, PZD-2/2 shows the I address and Q address ranges, for example 256…259. The first word is STW1 or ZSW1, the second is the speed.

Why are OFF2, OFF3, En_Oper, En_RFG, Cont_RFG, En_SP and Ctrl_PLC defaulted to TRUE?

These bits must be held at 1 for the drive to run. With TRUE as the default value in the FB interface, the OB1 call can leave them unconnected and the control word still starts from 16#047E. Only ON_OFF1, Ack_Flt and the speed need wiring.

Can I wire %IW256 and %QW256 directly to the FB pins?

Yes, TIA Portal accepts absolute addresses on FB pins. Using named PLC tags such as G120_1_SW_01 on those addresses is better: the OB1 call reads clearly, and if the hardware address changes you edit only the tag table.

Why does Act_RPM show the wrong speed?

The value 1500.0 in networks 33 and 34 must equal the drive's reference speed p2000. If p2000 is 3000 rpm and the FB still uses 1500.0, both the setpoint and the actual speed are scaled by a factor of two.

Reviewed by Bhawesh Kumar Singh Industrial Automation Trainer and Industry 4.0 Consultant · Softwell Automation · 21+ years industry experience

Get the full syllabus + free demo class

Share your details — a Softwell training advisor will call you within 24 hours with batch dates, fees and hardware access options.

No spam. Used only to share course details for this enquiry.

Learn with practical industrial examples

Join live online, Pune classroom or corporate in-plant automation training.

Request Course Details
Verified learning pathway

Discuss Your Automation Requirement

Get guidance for training, corporate programs, projects or technical resources.

Content reviewed: 22 September 2026

☎ Call WhatsApp ✉ Email Enquire Now