CM 1241 RS485 Modbus RTU: S7-1200 to DCS Configuration Guide

David Krause13 min read
S7-1200SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

The SIMATIC CM 1241 RS422/485 communication module (order number 6ES7241-1CH30-1XB0) extends an S7-1200 CPU with a serial interface that supports Modbus RTU master/slave, USS, and free-port (3964(R)) protocols. In a typical brownfield integration, an S7-1200 already exchanges Modbus RTU data with an HMI through a CM 1241, and the engineering team must then expose the same process values to a Distributed Control System (DCS) that also speaks RS485 Modbus RTU. The two most reliable approaches are:

  1. Install a second CM 1241 in the same S7-1200 and dedicate it to the DCS bus (recommended for plants where the HMI bus and DCS bus are physically or logically separate).
  2. Reuse the existing PROFINET port of the S7-1200 CPU and expose the same data to the DCS as a Modbus TCP server, eliminating the second CM entirely.

This reference walks through the hardware, the topology decision, the TIA Portal configuration, the program blocks (MB_MASTER / MB_SLAVE), and field verification steps for both routes. Specifications are anchored to the official CM 1241 RS422/485 specifications page in the TIA Portal manual collection.

Important: A single CM 1241 can act as only one Modbus RTU node on one bus. Two independent Modbus RTU masters (the HMI and the DCS) on the same physical pair will collide. If the DCS and the HMI must each poll the PLC over RS485, either use two CM 1241 modules on two isolated buses, or move one of the two clients to Modbus TCP on the PROFINET port.

Prerequisites

  • SIMATIC S7-1200 CPU (any firmware version that matches TIA Portal V16 or later; the Modbus library shipped with TIA V16 SP1 / V17 / V18 supports the modern MB_MASTER / MB_SLAVE v4.x instruction set).
  • CM 1241 RS422/485 module (6ES7241-1CH30-1XB0). One module for the HMI bus, an additional identical module if the DCS will be served over RS485 RTU.
  • TIA Portal V16 or higher with the "S7-1200 Modbus/TCP" or "PtP" library installed.
  • RS485 bus topology with shielded twisted pair, 120 Ω termination at both physical ends, and a defined baud rate / parity / stop-bit set common to all slaves.
  • DCS engineering station or Modbus master tool (e.g. Siemens PCS 7 Modbus driver, ABB 800xA Modbus TCP/RTU link, Emerson DeltaV Modbus interface) configured with the PLC's Modbus slave address.
  • 24 V DC supply for the CM 1241 from the S7-1200 system power or a separate SITOP line.

CM 1241 RS422/485 Hardware Specifications

The values below are taken from the official CM 1241 datasheet. Always verify against the device label and the current TIA Portal hardware catalog because Siemens has revised the module several times (6ES7241-1CH30-0XB0 → 6ES7241-1CH30-1XB0).

Parameter Value
Order number (current) 6ES7241-1CH30-1XB0
Order number (legacy) 6ES7241-1CH30-0XB0
Interface RS422 or RS485, 9-pin sub-D male (X31)
Mode switch RS422 (4-wire full duplex) or RS485 (2-wire half duplex)
Baud rates 300, 600, 1200, 2400, 4800, 9600, 19200, 38400, 57600, 76800, 115200 bit/s
Max nodes per RS485 bus 32 (1 unit load per node assumed)
Max cable length (RS485) 1 000 m at ≤ 93.75 kbit/s; 15 m at 1 Mbit/s (not supported on this module)
Supported protocols Modbus RTU master, Modbus RTU slave, USS, ASCII, 3964(R)
Modbus library instructions MB_COMM_LOAD, MB_MASTER, MB_SLAVE (TiaPortal library "Modbus" v4.x)
Power consumption from backplane 5 V DC, 220 mA typical
Galvanic isolation 500 V AC between bus and backplane
Approvals CE, UL, cULus, FM, ATEX (see module label)

For the complete electrical and timing envelope, see the CM 1241 RS422/485 specifications page.

Network Topology: One vs Two CM 1241 Modules

Option A — One CM 1241, shared RS485 bus

If the DCS acts as a Modbus RTU master and the HMI as a Modbus RTU slave (or vice versa) on the same physical RS485 pair, both masters will generate requests simultaneously and corrupt frames. This topology is not supported in a deterministic process. Either:

  • configure one device as the single master and the other as a transparent Modbus gateway, or
  • use request/response discipline enforced by a token scheduler in the user program (fragile, not recommended for DCS-grade monitoring).

Option B — Two CM 1241 modules, two isolated buses

The S7-1200 CPU 1215C, 1217C, and 1214C (with CB/CM mounting slots) support up to three CMs. Each CM occupies an independent slot in the device configuration, an independent hardware identifier, and an independent instance of MB_COMM_LOAD. This is the cleanest answer for a brownfield plant:

  • CM 1241 #1 (slot 101): serves the HMI bus at, for example, 19200 bit/s, 8E1.
  • CM 1241 #2 (slot 102): serves the DCS bus at 9600 bit/s, 8N1.
  • The user program holds two MB_SLAVE instances with different MODBUS_ADDR and one MB_MASTER if the S7-1200 must also poll remote RTU slaves on the DCS bus.
Wiring caution: The two RS485 buses must remain galvanically isolated. Do not tie their shield grounds together inside the cabinet; run each shield to its own grounding bar at the cabinet entry. Failure to isolate will inject CM 1241 bus currents into the DCS earth and create a ground loop.

Option C — Modbus TCP on the PROFINET port (preferred when the DCS supports it)

Most modern DCS platforms (PCS 7, ABB 800xA, Emerson DeltaV, Honeywell Experion) have a Modbus TCP/IPA driver. The S7-1200 CPU already exposes a PROFINET interface. By adding the "Modbus TCP" library to the S7-1200 project you get a MB_SERVER instruction that listens on TCP port 502 by default. The DCS polls the PLC over the plant Ethernet, and the existing CM 1241 continues to serve the HMI bus unchanged. This removes the second CM, the second termination, the second cable run, and the galvanic isolation question.

Modbus Register Map Planning

Decide the register layout before writing code. A typical S7-1200 to DCS register map for a process cell:

DCS Tag Function Code Modbus Address PLC DB offset (byte) Data type
AI_01_TankLevel 03 (Read Holding) 40001 DB100.DBW0 INT (0–27648 scaled)
AI_02_TankTemp 03 40003 DB100.DBW2 INT
AI_03_FlowRate 03 40005 DB100.DBW4 REAL (modbus32)
DI_04_PumpRun 02 (Read Input) 10001 DB100.DBX6.0 BOOL
DO_05_PumpCmd 05 (Write Coil) 00001 DB100.DBX7.0 BOOL

Many DCS engineers prefer Read Holding (FC03) for analog values and Read Coil (FC01) / Write Coil (FC05) for digitals. The MB_SLAVE v4.x instruction supports FC01, FC02, FC03, FC04, FC05, FC06, FC15, and FC16 simultaneously without a separate instance per function code.

Step-by-Step TIA Portal Configuration (Modbus RTU route)

  1. Add the second CM 1241. In the project tree, open Devices & Networks → PLC_1 → Device view. Drag a second CM 1241 (RS422/RS485) from the catalog and snap it to the right of the first CM. TIA assigns hardware identifiers automatically (typically 270 and 271 for slot 101/102).
  2. Set port parameters. Click each CM → Properties → RS422/485 interface and select RS485 half-duplex, baud rate, parity, and stop bits to match the bus it serves. Enable Termination and biasing only on the physical end nodes.
  3. Add the Modbus library. Options → Manage general station description files (GSD) / Library is not required; the Modbus RTU blocks ship with TIA. In the program editor, right-click Program blocks → External source files and add Modbus → PtP from the global library. Drop MB_COMM_LOAD, MB_MASTER, and MB_SLAVE from the instructions tree (Communication → Modbus).
  4. Wire MB_COMM_LOAD for each port. Create a separate MB_COMM_LOAD instance for every CM 1241. The HW_ID input is the hardware identifier from step 1. MODE = 0 for RTU, BAUD matches step 2, PARITY = 0 (none), 1 (odd), 2 (even), MB_DB points to a shared instance DB that MB_MASTER / MB_SLAVE will read.
  5. Call MB_SLAVE. Insert MB_SLAVE in OB1 (cyclical). The MB_ADDR input is the Modbus slave address of the S7-1200 on the DCS bus, e.g. 17. MB_DATA_PTR points to a data block (e.g. DB100) that is at least 1 000 bytes long to cover all holding, input, coil, and discrete ranges. The NDR, DR, ERROR, and STATUS outputs expose diagnostic codes.
  6. Compile and download. Build the hardware and software, then download to the CPU. Use Online → Go online to confirm the CM 1241 is reachable and the MB_COMM_LOAD DONE output rises to TRUE.
  7. Configure the DCS. In the DCS, define a Modbus RTU channel with the same baud / parity / stop bits, slave address = 17, and the register map from the table above. Set the scan class to 1 s (slow monitoring) or 250 ms if the DCS is configured to handle that rate.

Step-by-Step TIA Portal Configuration (Modbus TCP route)

  1. Confirm the DCS supports Modbus TCP. The S7-1200 CPU acts as a Modbus TCP server on port 502.
  2. Add the Modbus TCP library. From the instructions tree pick Communication → Modbus TCP and drop MB_SERVER into a cyclic OB. CONNECT uses an TCON_IP_V4 connection block; leave LOCAL_PORT = 502.
  3. Map the same DB100 holding and coil ranges to the TCP server. The DCS connects to the PLC IP, port 502, and reads the same addresses the RTU slaves would have used.
  4. Compile, download, then from the DCS test the link with a Modbus poll tool (e.g. mbpoll, Modbus Poll, or the vendor diagnostic page).

Sample Program Skeleton (Modbus RTU)

// MB_COMM_LOAD for CM 1241 #1 (HMI bus, hardware ID 270)
MB_COMM_LOAD_DB1(
  REQ      := TRUE,
  MODE     := 0,           // RTU
  BAUD     := 19200,
  PARITY   := 2,           // even
  PORT     := 0,           // not used by S7-1200 CM
  MB_DB    := "modbus_master_DB",
  HW_ID    := 270,
  DONE     => commload1_done,
  ERROR    => commload1_err,
  STATUS   => commload1_status
);

// MB_SLAVE for CM 1241 #2 (DCS bus, hardware ID 271)
MB_SLAVE_DB1(
  MB_ADDR   := 17,         // S7-1200 slave address on DCS bus
  MB_DATA_PTR := "DB100",
  NDR       => dcs_ndr,
  DR        => dcs_dr,
  ERROR     => dcs_error,
  STATUS    => dcs_status
);
Status code 0x0001 on MB_SLAVE.STATUS means the port is initializing; 0x0002 means a frame error; 0x0003 means a CRC error. 0x8380 indicates an invalid Modbus address. Refer to the CM 1241 RS422/485 specifications page and the Modbus library help for the full list.

Verification

  1. Online diagnostics in TIA Portal. Right-click the CM 1241 → Online & Diagnostics → Diagnostics buffer. A clean connection shows no bus errors. Open the Watch table on DB100 and force a value (e.g. DB100.DBW0 := 12345); the DCS read of register 40001 must return 12345 within the configured scan class.
  2. Bus health from a Modbus master tool. Connect a laptop running a Modbus RTU master to the same RS485 bus (T-connector with switchable termination). Poll FC03 @ 40001 and verify the response. If the laptop sees values but the DCS does not, the problem is the DCS configuration, not the PLC.
  3. Frame integrity with an oscilloscope or protocol analyzer. Capture the A/B lines with a differential probe. A healthy 9600 bit/s RTU frame shows 1 start bit, 8 data bits, parity, 1 stop bit, and 16-bit CRC. Runt frames or missing CRCs point to baud rate, termination, or shielding issues.
  4. Long-run stability. Leave the test running for at least 24 h. Check the MB_SLAVE.ERROR counter in a counter tag. Any non-zero count in this period indicates intermittent noise and warrants shield re-termination or replacement of the bus cable.

Troubleshooting Matrix

Symptom Likely Cause Action
No response on the DCS bus, but HMI communication works Second CM 1241 hardware identifier wrong, or slave address mismatch Verify HW_ID in MB_COMM_LOAD; confirm the DCS slave address equals MB_ADDR
Periodic CRC errors (status 0x0003) Missing or double termination, baud rate too high for cable length Place 120 Ω at both physical ends only; reduce baud to 9600 if cable > 500 m
Intermittent failure correlated with VFD start Common-mode noise on shield Re-terminate shield to cabinet ground at one end only; separate RS485 from VFD power cables by ≥ 200 mm
All frames NAK with status 0x8380 Requested address outside DB100 range Enlarge the holding/input DB or remap the DCS to addresses the DB actually covers
Both HMI and DCS see data, but values are stale Scan class too long, or MB_SLAVE dropped because the OB1 cycle was too long Move MB_SLAVE to a fast OB (e.g. OB35) and check CPU cycle time
Modbus TCP: DCS can connect but reads return illegal data address Modbus register base in DCS set to 1 while PLC expects 0 (or vice versa) Verify the DCS Modbus driver addressing convention; some drivers add +1 to the configured address
No GO online with the CM 1241 after adding the second module Firmware mismatch on the CM, or TIA Portal version older than the CM's catalog entry Upgrade TIA Portal to the latest HSP for the new CM 1241 order number; update CPU firmware if required

Field-Proven Caveats

  • The S7-1200 CPU has a limited number of Modbus connections. Each MB_SLAVE consumes one. On CPUs with limited work memory, two slaves plus a master may force you to raise the CPU to 1215C or 1217C.
  • The CM 1241 RS422/485 module is half-duplex for RS485 mode. The 9-pin sub-D assignment for RS485 is pin 3 (T/R+, B), pin 8 (T/R-, A), pin 5 (GND). Pins 1, 2, 4, 6, 7, 9 are reserved for RS422 mode.
  • The S7-1200 does not support simultaneous Modbus master and slave on the same CM 1241 port. The second CM is therefore mandatory if the S7-1200 must be polled by the HMI and the DCS and must also poll field devices such as power meters or weigh scales.
  • If the DCS requires signed 32-bit values (common for energy meters), configure the MB_DATA_PTR DB with the correct byte order. Modbus is big-endian; S7-1200 is little-endian, so a REAL or DINT read as two 16-bit words may need byte swapping in the user program.

Summary Recommendation

For a greenfield design where the DCS supports Modbus TCP, run the DCS on the S7-1200 PROFINET port and keep a single CM 1241 for the HMI bus. For a brownfield upgrade where the DCS only speaks Modbus RTU over RS485, install a second CM 1241 in the S7-1200, run the HMI bus and the DCS bus as two isolated RS485 segments, and dedicate one MB_COMM_LOAD / MB_SLAVE pair per CM. Always confirm the bus topology, register map, and diagnostic counters with a 24-hour stability run before handing the link to operations. For full electrical and protocol specifications, refer to the CM 1241 RS422/485 specifications in the TIA Portal manual collection.

FAQ

How many CM 1241 modules can I install in one S7-1200 CPU?

The S7-1200 supports up to three CM 1241 modules in total, limited by the slot count of the CPU (CPU 1214C: 2 slots, CPU 1215C: 3 slots, CPU 1217C: 3 slots). Each CM gets an independent hardware identifier and must be initialized with its own MB_COMM_LOAD call.

Can the same CM 1241 act as a Modbus RTU slave for the HMI and the DCS simultaneously?

Yes, the CM can answer requests from any Modbus RTU master on the bus, but two masters on the same physical RS485 pair will collide. Either use two CMs on two isolated buses, or move one client to Modbus TCP on the PROFINET port.

Which Modbus library blocks do I need for RTU on a CM 1241?

Use MB_COMM_LOAD to configure the port, MB_SLAVE if the S7-1200 is polled, and MB_MASTER if the S7-1200 polls other RTU devices. All three ship with the TIA Portal Modbus RTU library; the current version targets library v4.x for TIA V16 and later.

What is the default Modbus TCP port on the S7-1200?

Port 502. The MB_SERVER instruction uses the TCON connection block; leave LOCAL_PORT = 502 unless your plant firewall requires a different port. Confirm the DCS driver can be configured to match.

My MB_SLAVE returns status 0x0003 with periodic CRC errors. What is the cause?

Status 0x0003 is a Modbus CRC error, which on RS485 usually means a baud rate mismatch, a missing or double 120 Ω termination, or a shield that is not grounded correctly. Verify termination only at the two physical ends, confirm both sides use identical parity and stop bits, and check the shield is bonded to cabinet ground at one end only.

Back to blog