Siemens · S7

How to Read a Siemens Sinumerik over S7, and What You Actually Get

A Sinumerik 828D or 840D sl exposes its embedded PLC over standard S7 (port 102). What that gets you, what it doesn't, and how to connect it to Spall.

~20 min · Last reviewed August 13, 2026

A Sinumerik 828D or 840D sl doesn’t ship with a FOCAS-style API or an MTConnect agent. What it has instead is an embedded PLC, built on the same architecture as a standalone Siemens S7 controller, that exchanges signals with the NC kernel through a fixed set of data blocks. That PLC talks standard S7 communication on TCP port 102, the exact protocol Spall already reads on a plain S7-300/400 PLC. Point Spall at it and it reads real machine state. But it reads the PLC’s data blocks, not the CNC’s part program world, and which data block carries what is not standardized the way a FOCAS parameter number is. This guide states that difference plainly before it gets to the setup.

Before you start This covers Sinumerik 828D and 840D sl (NCU-based) controls. You’ll need network access to the right Ethernet interface (below, this matters more on a Sinumerik than on most controls), a fixed IP for that interface, S7 communication (TCP 102) reachable from the Spall gateway, and, most importantly, your machine builder’s PLC interface documentation, sometimes called a signal list or Signalliste. That document is what turns a generic S7 connection into actual spindle speed and run state. Spall reads. It never writes to the control.

1. Pick the right Ethernet interface

A Sinumerik NCU exposes up to three separate Ethernet interfaces, and they are not interchangeable:

  • X120, the system network, links the NCU to its own HMI and operator panel. S7 communication is open here by default, but it’s the control’s internal network, not something you generally want a plant network device sharing.
  • X130, the company network interface, is the one meant for a device like the Spall gateway. S7 (port 102) is firewalled off here by default and has to be explicitly allowed in SINUMERIK Operate’s network settings before anything outside the control can reach it.
  • X127, the service port, is for engineering access (STEP 7, commissioning tools) on its own fixed subnet. It’s not the one to wire the gateway into for ongoing data collection.
One NCU, three Ethernet ports, only one is for you X120 System network (HMI, panel) not this one X130 Company network S7 firewalled by default connect Spall here X127 Service port (STEP 7, commissioning) not this one X130 needs its TCP/102 firewall exception turned on in SINUMERIK Operate before Spall can reach it, the exact screen depends on your software version, Siemens's own networking documentation and your machine builder both cover it for your specific control.
X130 is the company-network interface. X120 and X127 exist for the machine's own HMI and for engineering tools, not for a floor-monitoring device.

2. Open S7 communication on X130

By default, the X130 interface blocks S7 (TCP 102) at the NCU’s own firewall. Someone with access to SINUMERIK Operate’s network configuration needs to allow it, alongside setting a static IP for X130 in the same range as the Spall gateway. The exact screen name has moved around across Operate software versions, so treat this as a five minute task for whoever commissioned the control (your machine builder, or your own controls engineer) rather than something to guess at from a generic screenshot. Siemens publishes its own networking application note for exactly this task if you want the primary source.

3. Get the actual DB map from your machine builder

This is the part that’s different from every other guide in this series, and worth being direct about. FOCAS has a fixed PARTS COUNT parameter. MTConnect standardizes an Execution data item. Sinumerik’s NC-PLC interface is a real, Siemens-documented boundary too, a fixed range of data blocks (DB10 through DB1900 in Siemens’s own interface signal list, with per-axis data starting at DB31) carries the signals the NC kernel and PLC exchange. But every machine builder writes their own sequence program on top of that base interface, and it’s the builder’s program, not Siemens’s base layer, that usually decides what ends up easy to read: which DB and byte offset reflects spindle load, which bit means “in cycle,” whether there’s a running part counter at all.

That means there’s no universal “the run state is always at DB2600.DBX4.2” the way there is for a FOCAS parameter number. Ask your machine builder for their PLC interface documentation, sometimes called a signal list or Signalliste, it’s a normal request and most builders have one on file. It’ll tell you exactly which data blocks carry what on your specific machine.

4. Test the connection

Before pointing Spall at it, confirm the control is actually answering on port 102 from the network Spall’s gateway sits on:

# from a PC on the same network as the X130 interface
Test-NetConnection 10.20.4.15 -Port 102
   -> TcpTestSucceeded : True

A closed connection here almost always means the X130 firewall exception from step 2 hasn’t been applied yet, not a wiring problem. If the port answers, a generic S7 read tool (or Spall’s own connection test when you add the machine) confirming a specific known DB, like an axis position in the DB31 range, reads back a sane value is the real proof the addressing lines up.

5. Point Spall at the machine

In Spall, add the machine, choose Siemens S7 as the source, and enter the control’s X130 address and port:

10.20.4.15:102

Set the rack and slot for the connection, most single-CPU S7 stations use rack 0, slot 2, but confirm the right value with your machine builder if the connection test doesn’t come back clean, Sinumerik’s embedded PLC doesn’t always match a standalone S7-300/400’s defaults. Then add a tag per signal you want, each one addressed by memory area (DB), the DB number, and the byte offset from your builder’s signal list, plus a bit offset for anything boolean like a run/stop flag. Assign the Spall gateway and save.

Sinumerik embedded PLC X130 :102 reads DBs Spall Gateway read-only DIN-rail, on-site MQTT / TLS outbound only Spall Cloud dashboards & loss board No inbound ports. No VPN. No public IP. The gateway only ever issues S7 read requests.
The data path. The gateway reads specific data blocks over S7 on your network and pushes outbound to Spall.

What Spall does with this data

Whatever you mapped, exactly. Unlike FOCAS or MTConnect, there’s no automatic “run state” or “part count” tag waiting on a Sinumerik, because there’s no standard address for either across machine builders. Once your DB map is entered as tags, though, it works the same way as every other protocol from there.

Availability. A tag mapped to a run/cycle-active bit splits every hour into running, idle, and down, no clipboards.

Downtime and reasons. Each stop is caught the instant the mapped state bit flips. Operators tag the reason, and Spall ranks them into a Pareto.

Production. If your builder’s PLC program maintains a part counter in a DB, mapping it gives target-vs-actual by shift and job the same way a FOCAS or MTConnect part count would.

Quality and OEE. Availability, performance, and quality still roll into one OEE view, each loss ranked in dollars, whatever the source protocol underneath. Siemens shops tend to be the ones already asking whether that view needs to sit inside a full MES, see what MES actually is and whether you need one before signing anything bigger than this.

One thing worth repeating An S7 PLC can technically be written to over the same protocol Spall uses to read it. Spall never does. The gateway issues read requests only, on your network, and sends what it reads outbound over encrypted MQTT. There’s no inbound port opened on your firewall, no VPN, and nothing is ever written back to the control’s PLC or NC program. Worst case if it can’t reach the machine is a gap in the chart. The spindle keeps running.

Quick recap

  • Connect on X130 (company network), not X120 (system network) or X127 (service port)
  • Enable the X130 firewall exception for S7 (TCP 102) in SINUMERIK Operate
  • Get the real DB map from your machine builder’s signal list, there’s no universal address
  • Test port 102 first, then a known DB value, before trusting the connection
  • Add the machine in Spall with rack, slot, and a tag per DB/byte offset from that map

Once you have your machine builder’s signal list in hand, the Spall side is five minutes. Bring us that document and your machine list and we’ll map it with you.

Related guides

From the Help Center

$200/machine/mo · pilots from $4,500 · hardware included

See full pricing →

See your Siemens machines live

30 days, hardware included, line pilot $4,500 or plant pilot $8,500, fully credited when you expand.