Siemens · S7

How to Connect a Siemens S7-1200 or S7-1500 PLC to Spall

The plain PLC path, not a Sinumerik's embedded one. Rack and slot, why optimized block access breaks a byte-offset read, and DB addressing that works.

~15 min · Last reviewed September 12, 2026

This guide is about a standalone S7-1200 or S7-1500 PLC, a packaging line, a conveyor, a press, running its own program with no CNC control layered on top. If you’re chasing a Sinumerik’s embedded PLC instead, that’s a different starting point (three Ethernet interfaces, a machine builder’s signal list) covered in its own guide. A plain S7-1200/1500 is simpler in one real way and harder in another: there’s no machine builder’s documentation to hunt down, but TIA Portal’s default project settings will stop an outside reader like Spall from seeing your data blocks at all until you turn one setting off.

Before you start You’ll need the PLC’s IP address, S7 communication (TCP port 102) reachable from the Spall gateway, the rack and slot the CPU sits in, and a DB you’re allowed to read with optimized block access turned off (step 2 covers exactly what that means and how to check it). Spall reads. It never writes to the controller.

1. Rack and slot

S7 communication addresses a CPU by its position in a rack, in addition to its IP address. A single S7-1200 or S7-1500 CPU almost always answers to rack 0, slot 1, the common starting point and Spall’s own default. If the connection test in step 5 doesn’t come back clean, check the hardware configuration in TIA Portal. A CPU behind a routed connection or an unusual rack layout can sit on a different slot, and the wrong one fails the connection outright rather than reading garbage.

Rack 0, slot 1: the common S7-1200/1500 layout One CPU, one rack, the default slot CPU slot 1 slot 2 slot 3 rack 0
A single-CPU S7-1200/1500 station usually looks like this. Confirm against your actual hardware config if the connection test fails.

2. Turn off optimized block access on the DB you want to read

TIA Portal defaults every new data block to optimized block access, which lets the compiler assign each variable’s memory address on its own and reshuffle it on a recompile, with no fixed byte offset a program (or an outside S7comm reader) can count on. That’s fine for the PLC’s own program, which addresses everything by symbol name, but it’s exactly what S7comm-based reads like Spall’s can’t work with: they read a byte offset into a DB, and an optimized DB doesn’t have one to give.

The fix is a property on the DB itself, not a global project setting. In TIA Portal, right click the data block in the project tree, open Properties > Attributes, and uncheck Optimized block access. The DB now gets fixed byte offsets again, viewable in its own view, and that’s what you address a tag by. This only affects the specific DB you change it on. Existing optimized DBs elsewhere in the program are untouched, and the PLC’s own logic keeps running exactly as before, unaffected by how an outside device happens to address the block.

Optimized versus standard data block access Optimized (TIA default) RunState : Bool PartCount : DInt Compiler assigns the address. No byte offset to read by. Standard (unchecked) RunState : DBX0.0 PartCount : DBD2 Fixed byte offset, every compile. This is what Spall addresses.
Uncheck Optimized block access on the specific DB you're reading. The PLC's own program is unaffected either way.

3. Reading DB addressing notation

Once a DB’s view shows fixed offsets, the notation on that view is what you’ll be typing into Spall’s tag fields. Know what each letter means before you start. DBX is a single bit, DBX0.2 reads byte 0, bit 2. DBB is a whole byte, DBW is a 16-bit word (two bytes), and DBD is a 32-bit double word (four bytes), covering an int32 or a float. A tag that says DBD4 in the program view is byte offset 4 in Spall’s own Offset field, with the data type set to match, int32 or float32 depending on what the program declares it as. Get the width wrong, and the read succeeds but the number is nonsense. A float read as an int prints a value nobody recognizes, not an error.

DB notation widths: bit, byte, word, double word Same DB, four widths, four notations DBX0.2 1 bit DBB1 1 byte DBW2 2 bytes (word) DBD4 4 bytes (double word: int32 or float32) Spall's Offset field takes the byte number, DBD4 becomes Offset 4 with the data type set to int32 or float32. A width mismatch still reads back a number, just the wrong one, so match the type to what the program declares.
DBX, DBB, DBW, DBD are widths on the same byte-offset scale, not four separate addressing schemes.

4. Check PUT/GET communication is allowed

TIA Portal also gates outside S7comm access at the CPU level, separately from any one DB’s optimized setting. Under the CPU’s Properties > Protection & Security > Connection mechanisms, confirm Permit access with PUT/GET communication from remote partner is checked. If it isn’t, every read request from Spall (or any other external S7comm client) is refused at the CPU, regardless of how the target DB is configured. This is a one-time setting per CPU, not per DB.

5. Test the connection

Before pointing Spall at the PLC, confirm it answers on port 102 from the network the gateway sits on:

nc -vz 10.0.5.20 102
   -> Connection to 10.0.5.20 102 succeeded!

A refused connection here usually means PUT/GET communication is still disabled from step 4, or a firewall sits between the gateway and the PLC, not a wiring problem. This test doesn’t touch Spall’s own configuration yet.

6. Point Spall at the PLC

In Spall, add the machine, choose Siemens S7 as the source, and enter the PLC’s address:

10.0.5.20:102

Set rack 0 and slot 1 (step 1) unless your hardware configuration says otherwise. Then add a tag per value, each one addressed by memory area, I or Q for the CPU’s own onboard digital inputs and outputs, M for bit or flag memory, or DB with the data block number for anything living in the DB you unoptimized in step 2, plus the byte offset and, for a boolean tag, the bit position. Assign the Spall gateway and save.

S7 PLC to gateway to cloud, read only S7-1200/1500 rack 0, slot 1 :102 reads DBs, I/Q/M Spall Gateway read-only DIN-rail, on-site MQTT / TLS outbound only Spall Cloud dashboards & loss board No inbound ports. No VPN. The gateway only ever issues S7 read requests.
The data path. The gateway reads specific bytes over S7comm and pushes outbound to Spall.

What Spall does with this data

Availability. A tag mapped to a run or cycle-active bit splits every hour into running, idle, and down, no clipboards.

Downtime and reasons. Each stop is caught the instant the mapped bit flips. Operators tag the reason, and Spall ranks them into a Pareto.

Production. A DB tag maintaining a part count drives target-vs-actual by shift and job, the same as a native CNC part count.

Quality and OEE. Availability, performance, and quality still roll into one OEE view, each loss ranked in dollars, whatever the source underneath.

One thing worth repeating An S7 PLC can technically be written to over the same protocol Spall uses to read it. Spall never does. The gateway issues read requests only, on your network, and sends what it reads outbound over encrypted MQTT. There’s no inbound port opened on your firewall, no VPN, and nothing is ever written back to the program. Worst case if it can’t reach the PLC is a gap in the chart. The line keeps running.

Quick recap

  • This is the plain PLC path, a standalone S7-1200/1500 running its own program, not a Sinumerik’s embedded one
  • Rack 0, slot 1 is the common default, confirm against your hardware config if the connection test fails
  • Uncheck Optimized block access on the specific DB you want to read, since TIA Portal defaults every new DB to optimized with no fixed byte offset to address
  • Confirm Permit access with PUT/GET communication is checked on the CPU, a separate setting from any one DB
  • Test port 102, then add the PLC with rack, slot, and a tag per memory area, DB number, and byte offset

If a DB’s optimized setting is locked down by a controls standard at your site, bring that constraint to a pilot call. We’ll tell you what’s realistically readable before anyone touches the program.

Related guides

From the Help Center

$200/machine/mo · pilots from $4,500 · hardware included

See full pricing →

See your Siemens machines live

30 days, hardware included, line pilot $4,500 or plant pilot $8,500, fully credited when you expand.