A Sinumerik 828D or 840D sl doesn’t ship with a FOCAS-style API or an MTConnect agent. What it has instead is an embedded PLC, built on the same architecture as a standalone Siemens S7 controller, that exchanges signals with the NC kernel through a fixed set of data blocks. That PLC talks standard S7 communication on TCP port 102, the exact protocol Spall already reads on a plain S7-300/400 PLC. Point Spall at it and it reads real machine state. But it reads the PLC’s data blocks, not the CNC’s part program world, and which data block carries what is not standardized the way a FOCAS parameter number is. This guide states that difference plainly before it gets to the setup.
Before you start This covers Sinumerik 828D and 840D sl (NCU-based) controls. You’ll need network access to the right Ethernet interface (below, this matters more on a Sinumerik than on most controls), a fixed IP for that interface, S7 communication (TCP 102) reachable from the Spall gateway, and, most importantly, your machine builder’s PLC interface documentation, sometimes called a signal list or Signalliste. That document is what turns a generic S7 connection into actual spindle speed and run state. Spall reads. It never writes to the control.
1. Pick the right Ethernet interface
A Sinumerik NCU exposes up to three separate Ethernet interfaces, and they are not interchangeable:
- X120, the system network, links the NCU to its own HMI and operator panel. S7 communication is open here by default, but it’s the control’s internal network, not something you generally want a plant network device sharing.
- X130, the company network interface, is the one meant for a device like the Spall gateway. S7 (port 102) is firewalled off here by default and has to be explicitly allowed in SINUMERIK Operate’s network settings before anything outside the control can reach it.
- X127, the service port, is for engineering access (STEP 7, commissioning tools) on its own fixed subnet. It’s not the one to wire the gateway into for ongoing data collection.
2. Open S7 communication on X130
By default, the X130 interface blocks S7 (TCP 102) at the NCU’s own firewall. Someone with access to SINUMERIK Operate’s network configuration needs to allow it, alongside setting a static IP for X130 in the same range as the Spall gateway. The exact screen name has moved around across Operate software versions, so treat this as a five minute task for whoever commissioned the control (your machine builder, or your own controls engineer) rather than something to guess at from a generic screenshot. Siemens publishes its own networking application note for exactly this task if you want the primary source.
3. Get the actual DB map from your machine builder
This is the part that’s different from every other guide in this series, and worth being direct about. FOCAS has a fixed PARTS COUNT parameter. MTConnect standardizes an Execution data item. Sinumerik’s NC-PLC interface is a real, Siemens-documented boundary too, a fixed range of data blocks (DB10 through DB1900 in Siemens’s own interface signal list, with per-axis data starting at DB31) carries the signals the NC kernel and PLC exchange. But every machine builder writes their own sequence program on top of that base interface, and it’s the builder’s program, not Siemens’s base layer, that usually decides what ends up easy to read: which DB and byte offset reflects spindle load, which bit means “in cycle,” whether there’s a running part counter at all.
That means there’s no universal “the run state is always at DB2600.DBX4.2” the way there is for a FOCAS parameter number. Ask your machine builder for their PLC interface documentation, sometimes called a signal list or Signalliste, it’s a normal request and most builders have one on file. It’ll tell you exactly which data blocks carry what on your specific machine.
4. Test the connection
Before pointing Spall at it, confirm the control is actually answering on port 102 from the network Spall’s gateway sits on:
# from a PC on the same network as the X130 interface
Test-NetConnection 10.20.4.15 -Port 102
-> TcpTestSucceeded : True
A closed connection here almost always means the X130 firewall exception from step 2 hasn’t been applied yet, not a wiring problem. If the port answers, a generic S7 read tool (or Spall’s own connection test when you add the machine) confirming a specific known DB, like an axis position in the DB31 range, reads back a sane value is the real proof the addressing lines up.
5. Point Spall at the machine
In Spall, add the machine, choose Siemens S7 as the source, and enter the control’s X130 address and port:
10.20.4.15:102
Set the rack and slot for the connection, most single-CPU S7 stations use rack 0, slot 2, but confirm the right value with your machine builder if the connection test doesn’t come back clean, Sinumerik’s embedded PLC doesn’t always match a standalone S7-300/400’s defaults. Then add a tag per signal you want, each one addressed by memory area (DB), the DB number, and the byte offset from your builder’s signal list, plus a bit offset for anything boolean like a run/stop flag. Assign the Spall gateway and save.
What Spall does with this data
Whatever you mapped, exactly. Unlike FOCAS or MTConnect, there’s no automatic “run state” or “part count” tag waiting on a Sinumerik, because there’s no standard address for either across machine builders. Once your DB map is entered as tags, though, it works the same way as every other protocol from there.
Availability. A tag mapped to a run/cycle-active bit splits every hour into running, idle, and down, no clipboards.
Downtime and reasons. Each stop is caught the instant the mapped state bit flips. Operators tag the reason, and Spall ranks them into a Pareto.
Production. If your builder’s PLC program maintains a part counter in a DB, mapping it gives target-vs-actual by shift and job the same way a FOCAS or MTConnect part count would.
Quality and OEE. Availability, performance, and quality still roll into one OEE view, each loss ranked in dollars, whatever the source protocol underneath. Siemens shops tend to be the ones already asking whether that view needs to sit inside a full MES, see what MES actually is and whether you need one before signing anything bigger than this.
One thing worth repeating An S7 PLC can technically be written to over the same protocol Spall uses to read it. Spall never does. The gateway issues read requests only, on your network, and sends what it reads outbound over encrypted MQTT. There’s no inbound port opened on your firewall, no VPN, and nothing is ever written back to the control’s PLC or NC program. Worst case if it can’t reach the machine is a gap in the chart. The spindle keeps running.
Quick recap
- Connect on X130 (company network), not X120 (system network) or X127 (service port)
- Enable the X130 firewall exception for S7 (TCP 102) in SINUMERIK Operate
- Get the real DB map from your machine builder’s signal list, there’s no universal address
- Test port 102 first, then a known DB value, before trusting the connection
- Add the machine in Spall with rack, slot, and a tag per DB/byte offset from that map
Once you have your machine builder’s signal list in hand, the Spall side is five minutes. Bring us that document and your machine list and we’ll map it with you.