This guide is about a standalone S7-1200 or S7-1500 PLC, a packaging line, a conveyor, a press, running its own program with no CNC control layered on top. If you’re chasing a Sinumerik’s embedded PLC instead, that’s a different starting point (three Ethernet interfaces, a machine builder’s signal list) covered in its own guide. A plain S7-1200/1500 is simpler in one real way and harder in another: there’s no machine builder’s documentation to hunt down, but TIA Portal’s default project settings will stop an outside reader like Spall from seeing your data blocks at all until you turn one setting off.
Before you start You’ll need the PLC’s IP address, S7 communication (TCP port 102) reachable from the Spall gateway, the rack and slot the CPU sits in, and a DB you’re allowed to read with optimized block access turned off (step 2 covers exactly what that means and how to check it). Spall reads. It never writes to the controller.
1. Rack and slot
S7 communication addresses a CPU by its position in a rack, in addition to its IP address. A single S7-1200 or S7-1500 CPU almost always answers to rack 0, slot 1, the common starting point and Spall’s own default. If the connection test in step 5 doesn’t come back clean, check the hardware configuration in TIA Portal. A CPU behind a routed connection or an unusual rack layout can sit on a different slot, and the wrong one fails the connection outright rather than reading garbage.
2. Turn off optimized block access on the DB you want to read
TIA Portal defaults every new data block to optimized block access, which lets the compiler assign each variable’s memory address on its own and reshuffle it on a recompile, with no fixed byte offset a program (or an outside S7comm reader) can count on. That’s fine for the PLC’s own program, which addresses everything by symbol name, but it’s exactly what S7comm-based reads like Spall’s can’t work with: they read a byte offset into a DB, and an optimized DB doesn’t have one to give.
The fix is a property on the DB itself, not a global project setting. In TIA Portal, right click the data block in the project tree, open Properties > Attributes, and uncheck Optimized block access. The DB now gets fixed byte offsets again, viewable in its own view, and that’s what you address a tag by. This only affects the specific DB you change it on. Existing optimized DBs elsewhere in the program are untouched, and the PLC’s own logic keeps running exactly as before, unaffected by how an outside device happens to address the block.
3. Reading DB addressing notation
Once a DB’s view shows fixed offsets, the notation on that view is what you’ll be typing into Spall’s tag fields. Know what each letter means before you start. DBX is a single bit, DBX0.2 reads byte 0, bit 2. DBB is a whole byte, DBW is a 16-bit word (two bytes), and DBD is a 32-bit double word (four bytes), covering an int32 or a float. A tag that says DBD4 in the program view is byte offset 4 in Spall’s own Offset field, with the data type set to match, int32 or float32 depending on what the program declares it as. Get the width wrong, and the read succeeds but the number is nonsense. A float read as an int prints a value nobody recognizes, not an error.
4. Check PUT/GET communication is allowed
TIA Portal also gates outside S7comm access at the CPU level, separately from any one DB’s optimized setting. Under the CPU’s Properties > Protection & Security > Connection mechanisms, confirm Permit access with PUT/GET communication from remote partner is checked. If it isn’t, every read request from Spall (or any other external S7comm client) is refused at the CPU, regardless of how the target DB is configured. This is a one-time setting per CPU, not per DB.
5. Test the connection
Before pointing Spall at the PLC, confirm it answers on port 102 from the network the gateway sits on:
nc -vz 10.0.5.20 102
-> Connection to 10.0.5.20 102 succeeded!
A refused connection here usually means PUT/GET communication is still disabled from step 4, or a firewall sits between the gateway and the PLC, not a wiring problem. This test doesn’t touch Spall’s own configuration yet.
6. Point Spall at the PLC
In Spall, add the machine, choose Siemens S7 as the source, and enter the PLC’s address:
10.0.5.20:102
Set rack 0 and slot 1 (step 1) unless your hardware configuration says otherwise. Then add a tag per value, each one addressed by memory area, I or Q for the CPU’s own onboard digital inputs and outputs, M for bit or flag memory, or DB with the data block number for anything living in the DB you unoptimized in step 2, plus the byte offset and, for a boolean tag, the bit position. Assign the Spall gateway and save.
What Spall does with this data
Availability. A tag mapped to a run or cycle-active bit splits every hour into running, idle, and down, no clipboards.
Downtime and reasons. Each stop is caught the instant the mapped bit flips. Operators tag the reason, and Spall ranks them into a Pareto.
Production. A DB tag maintaining a part count drives target-vs-actual by shift and job, the same as a native CNC part count.
Quality and OEE. Availability, performance, and quality still roll into one OEE view, each loss ranked in dollars, whatever the source underneath.
One thing worth repeating An S7 PLC can technically be written to over the same protocol Spall uses to read it. Spall never does. The gateway issues read requests only, on your network, and sends what it reads outbound over encrypted MQTT. There’s no inbound port opened on your firewall, no VPN, and nothing is ever written back to the program. Worst case if it can’t reach the PLC is a gap in the chart. The line keeps running.
Quick recap
- This is the plain PLC path, a standalone S7-1200/1500 running its own program, not a Sinumerik’s embedded one
- Rack 0, slot 1 is the common default, confirm against your hardware config if the connection test fails
- Uncheck Optimized block access on the specific DB you want to read, since TIA Portal defaults every new DB to optimized with no fixed byte offset to address
- Confirm Permit access with PUT/GET communication is checked on the CPU, a separate setting from any one DB
- Test port 102, then add the PLC with rack, slot, and a tag per memory area, DB number, and byte offset
If a DB’s optimized setting is locked down by a controls standard at your site, bring that constraint to a pilot call. We’ll tell you what’s realistically readable before anyone touches the program.