Configuring Modbus RTU on Siemens S7 CP 340, CP 341, and CP 441 Modules
Modbus RTU integration on a Siemens S7 PLC requires a serial communications processor (CP) and the dedicated PTP Param parameterization tool. The CP modules themselves do not expose a Modbus tab directly in STEP 7 Hardware Configuration; instead, the protocol-specific parameters are loaded into the CP via the PTP Param utility after the module has been inserted into the hardware catalog. This article details the full commissioning path for the CP 340, CP 341, and CP 441-1 / CP 441-2 modules, including module selection, software installation, register mapping, FB programming, and on-line verification.
1. Overview of Modbus on Siemens Serial CPs
The Siemens serial communication processors implement Modbus through a loadable driver on the CP firmware. The driver is selected in the PTP Param tool and downloaded into the CP's flash memory. Once loaded, the CP autonomously handles the Modbus frame, CRC, and timing — leaving the CPU free to issue request jobs and parse responses via standardized function blocks.
| CP Module | Order Number (MLFB) | Max Baud Rate | Protocols Supported | Typical PLC |
|---|---|---|---|---|
| CP 340 | 6ES7 340-1xxx-xAxx | 19.2 kbit/s (RS-232/422/485) | ASCII, 3964(R), Modbus RTU (loadable) | S7-300, ET 200M |
| CP 341 | 6ES7 341-1xxx-xAxx | 76.8 kbit/s (RS-232/422/485) | ASCII, 3964(R), Modbus RTU Master/Slave (loadable) | S7-300, ET 200M |
| CP 441-1 | 6ES7 441-1xxx-xx0x | 38.4 kbit/s per interface | ASCII, 3964(R), Modbus RTU (loadable) | S7-400 |
| CP 441-2 | 6ES7 441-2xxx-xx0x | 115.2 kbit/s per interface | ASCII, 3964(R), Modbus RTU Master/Slave (loadable) | S7-400 |
2. Prerequisites
Confirm the following before commissioning:
- STEP 7 version compatibility: STEP 7 V5.4 SP5 or higher for CP 340/341, STEP 7 V5.5 SP4 or higher for CP 441. TIA Portal does not natively configure these legacy CP modules — use the legacy STEP 7 (SIMATIC Manager) for parameterization even when the CPU is a newer S7-300/S7-400.
- PTP Param tool installed on the engineering station. The installer is delivered on the CD bundled with every CP, and the latest revision is available on the Siemens Industry Online Support portal.
- Appropriate hardware configuration with the CP inserted on a compatible slot. CP 340 and CP 341 occupy one slot each in the S7-300 rack. CP 441 occupies one slot in the S7-400 rack.
- Licensed driver image for the Modbus protocol loaded into the CP's flash memory.
- Modbus slave devices with known station addresses (1–247 per the Modbus standard), register maps, and supported function codes.
3. Installing the PTP Param Parameterization Software
The PTP Param tool is the only Siemens-licensed utility that writes Modbus driver images and protocol parameters into the CP. Installation is straightforward but must be completed before opening Hardware Configuration.
- Insert the CD shipped with the CP. If the CD is missing, download the current package from Siemens Support entry ID 27013524 — "CP PTP Parameter assignment tool".
- Run
setup.exeand select the appropriate CP family (CP 340/341 or CP 441). The installer copies the executable (ptpparam.exe), driver images, and the corresponding Hardware Configuration support packages into the STEP 7 directory tree. - Restart SIMATIC Manager to register the new hardware catalog entries.
- Open the CP in Hardware Configuration and confirm that the Protocol dropdown in the CP properties dialog now lists
Modbus MasterandModbus Slave. If the entries are absent, the PTP Param install was not detected by STEP 7 — re-run the setup and verify the destination folder.
4. Selecting the Correct CP for Your Application
| Selection Criterion | CP 340 | CP 341 | CP 441-1 | CP 441-2 |
|---|---|---|---|---|
| Single master / few slaves, low speed | Recommended | OK | Over-spec | Over-spec |
| Master and slave role on same port | Not supported | Yes | Not supported | Yes |
| High baud rate (> 38.4 kbit/s) | No | Up to 76.8 | Up to 38.4 | Up to 115.2 |
| Multiple simultaneous ports | 1 | 1 | 1 | 2 |
| Redundant CP architecture | No | No | No | Yes (with CPU 41x-H) |
If you need both Modbus master and slave on a single port of an S7-300, the CP 341 (or the CP 441-2) is mandatory. The CP 340 only supports master mode.
5. STEP 7 Hardware Configuration
Open the S7 project in SIMATIC Manager and edit the station in Hardware Configuration (HW Config).
-
Insert the CP from the catalog. For an S7-300, drag
CP 341 > RS-485/422onto a free slot (slot 4–11 typical). For an S7-400, dragCP 441onto slot 4–15. - Open the CP's object properties by double-clicking the module. The default tab is General; switch to the Parameters tab.
-
Select the interface (IF1 / IF2 on CP 441-2) and the physical layer:
RS-485 2-wire,RS-485 4-wire, orRS-232. Match the wiring of the bus. -
Activate the Modbus protocol: from the protocol dropdown, select
Modbus MasterorModbus Slave. The previously installed PTP Param tool binds this selection to the loadable driver. - Set baud rate, parity, and stop bits to match the slave device. Common values: 9600, 19200, 38400; parity even, 1 stop bit (8E1). Modbus RTU requires 11 bits per character (1 start + 8 data + 1 parity + 1 stop); 10-bit formats are not RTU-compliant.
- Configure the response timeout: typical default is 2000 ms for slaves, 500 ms for adjacent masters. Adjust to (slave processing time) × (number of polled stations) + inter-frame gap.
- Save and compile the hardware configuration and download it to the PLC.
RUN with no parameter errors. If the CP reports SF (group fault) and BF (bus fault) immediately, the protocol image is missing — re-run the PTP Param download.6. Modbus Master Configuration Detail
For a CP 341 / CP 441-2 in master mode, define each polled slave as a logical connection. Each connection stores the slave address, scan rate, and the register to read/write.
| Field | Setting |
|---|---|
| Slave Address | 1–247 (255 inclusive address space in some tools, but 247 is the Modbus standard limit) |
| Function Code | 01 (Read Coils), 02 (Read Discrete Inputs), 03 (Read Holding Regs), 04 (Read Input Regs), 05 (Write Single Coil), 06 (Write Single Reg), 15 (Write Multiple Coils), 16 (Write Multiple Regs) |
| Register Range | 0–65535 (Modbus address space; +40001 offset common for holding registers) |
| Polling Interval | Defined by user program via SEND/RECEIVE cycle time |
| Max. Registers per Request | 125 (function code 03/04), 2000 (function code 16) |
The master is polled from the CPU via the standard Siemens function blocks. For CP 341 with Modbus master driver, use FB 7 "P_RCV_RK" and FB 8 "P_SND_RK" from the Modbus master library, or the integrated block FB 80 "MB_MASTER" available with newer driver versions. For CP 441-2, use FB 9 "RECV_441" and FB 10 "SEND_441".
7. Modbus Slave Configuration Detail
In slave mode, the CP answers requests from external masters. Configure the CP's slave address (1–247), then map the four standard Modbus areas to DB blocks in the CPU:
| Modbus Area | FC | Source in CPU | Default Mapping |
|---|---|---|---|
| Coils (output) | 01 / 05 / 15 | Bit memory or DB | DB 100, starting at offset 0.0 |
| Discrete Inputs | 02 | Process input image / DB | DB 101, starting at offset 0.0 |
| Holding Registers | 03 / 06 / 16 | DB (word-aligned) | DB 102, starting at offset 0.0 |
| Input Registers | 04 | DB (read-only) | DB 103, starting at offset 0.0 |
The starting DB number is configurable in PTP Param. Each register occupies 2 bytes; coil 0 = DBxx.DBX0.0, coil 1 = DBxx.DBX0.1, etc. Holding register 0 = DBxx.DBW0, register 1 = DBxx.DBW2. Modbus masters typically address these as 40001, 40002, etc., with the offset of 40001 added externally by the master. The Siemens CP does not apply any offset — register 0 in the master request always points to DBB0.
8. Register and Coil Mapping Reference
The following table summarizes the bit- and byte-level mapping inside the configured DB. This is the most frequent source of field errors:
| Modbus Address | CP 341/441 DB Mapping (Big-Endian word order) |
|---|---|
| Coil 0–15 | DB 100 DBW0 (low byte = coils 0–7, high byte = coils 8–15) |
| Coil 16–31 | DB 100 DBW2 |
| Holding Reg 0 | DB 102 DBW0 (low byte first if using Modicon convention, high byte first if Siemens convention) |
| Holding Reg 1 | DB 102 DBW2 |
| Input Reg 0 | DB 103 DBW0 |
TAH/TAL byte-swap instructions or swap in the FB layer. Several field failures with power meters and drives have been traced to mismatched byte order; always verify with a known reference value (e.g., write 0x1234 to register 0 and read back from the master).9. Programming the Modbus Master in the CPU
Use the Modbus master library function blocks in the OB 1 cycle. The call interface for CP 341 with the loadable Modbus master driver:
// Master request: read 10 holding regs from slave 5, start reg 100
CALL FB 80 "MB_MASTER"
REQ := M 10.0 // Trigger request, set for one cycle
ID := W#16#100 // Logical address from HW Config (CP slot address + 1)
MODE := B#16#4 // 4 = Read holding registers (FC 03)
SLAVE := B#16#5 // Slave address 5
ADDR := W#16#100 // Start register address
LEN := B#16#A // Number of registers = 10
DATA := P#DB 50.DBX 0.0 BYTE 20 // 10 words = 20 bytes
DONE := M 10.1
ERROR := M 10.2
STATUS := MW 12
NDR := M 10.3
Parameters to verify during commissioning:
-
ID: the logical base address of the CP. For CP 341 in slot 4 of an S7-300, the input address is typically 256 and the output address 256 — theIDis the input address for receive-oriented blocks and the output address for send-oriented blocks; with bidirectional Modbus, use the output address. -
STATUS=16#DF80indicates "request in progress";16#0000= success. Common error codes:16#DF81(response timeout),16#DF82(CRC error),16#DF83(illegal FC),16#DF84(illegal data address),16#DF85(illegal data value).
10. Verifying the Bus
After hardware configuration, driver download, and CPU programming, validate communication end-to-end:
-
LED check: CP 341/441 LEDs should be solid green on the SF and TXD/RXD indicators after a successful slave response. The CP 341 has dedicated LEDs:
SF(group fault),BF(bus fault),TD(transmit data),RD(receive data). - Hardware Configuration online diagnostic buffer: Select the CP in HW Config and view PLC > Module Information > Diagnostic Buffer. Look for entries of type Communication error with timestamp — these correspond to corrupted frames or timeouts.
- Modbus diagnostic counters: In PTP Param, the online view exposes counters: Frames sent OK, Frames received OK, CRC errors, Timeouts, Overrun errors. Watch the ratio of CRC errors to total frames — should be 0% on a healthy bus.
- Slave-side confirmation: From a Modbus master on a laptop (e.g., using Modbus Poll for testing, not as a production tool), poll the CP in slave mode and verify the coils and registers match the expected DB values.
- Function-code round-trip: Use FC 03 to read back a value written by FC 06 — this tests both directions and verifies byte order.
11. Troubleshooting Matrix
| Symptom | Likely Root Cause | Diagnostic Step | Remedy |
|---|---|---|---|
| Modbus option missing in HW Config | PTP Param not installed | Check C:\Program Files\Siemens\Automation\PTP_Param
|
Install PTP Param, restart SIMATIC Manager |
| CP reports SF + BF immediately | Driver image not loaded | Open PTP Param, connect online, check firmware version | Re-download Modbus driver image to CP |
| All requests return timeout | Wiring / baud / parity mismatch | Verify with oscilloscope on the bus; confirm 8E1 | Match slave settings; check A/B polarity on RS-485 |
| Intermittent CRC errors | Cable too long / no termination / EMC | Inspect cable length < 1200 m; termination at bus ends only | Add 120 Ω termination; use shielded twisted pair |
| Single register read returns wrong value | Byte-order mismatch | Write 0x1234, read back, compare byte order | Swap bytes in CPU program before/after transfer |
| Some slaves respond, others don't | Duplicate address or broadcast on RS-485 | Disconnect slaves one at a time | Re-number addresses; ensure unique 1–247 per bus |
FB 80 returns 16#DF81 repeatedly |
Slave processing time exceeded | Increase response timeout in HW Config | Set timeout ≥ 2 × slave response time |
| Hold register write succeeds, coil write fails | Coils mapped to read-only DB | Check PTP Param coil mapping | Use DB 100 with write access; verify DB attributes |
12. Compatibility and Migration Notes
- STEP 7 V5.x only: These CPs and the PTP Param tool are not supported in TIA Portal. Projects with newer TIA CPUs that need Modbus RTU must use an ET 200SP PTP module or a CM PtP, configured from TIA Portal with native Modbus blocks (MB_MASTER, MB_SLAVE V3+).
- Modbus TCP alternative: If a serial RS-485 link is not mandatory, prefer Modbus TCP on a CP 343-1 Lean / CP 443-1 via the open Modbus/TCP library (Siemens entry ID 62830447 — "Modbus TCP PN-CPU"). Configuration is via TIA Portal block calls and avoids the PTP Param tool entirely.
- Replacement modules: For new S7-300 builds, the CP 341 is end-of-life but the recommended replacement is the CM PtP in ET 200S or CM 1241 on S7-1200/1500. Existing installations with CP 341 remain supportable via the latest PTP Param revision.
13. Field-Proven Best Practices
- Always place the Modbus slave's holding-register DB in non-optimized access mode (DB attribute Standard, not Optimized) — the CP accesses the DB via absolute offsets and optimized symbolic access breaks the mapping.
- Reserve one DB per Modbus area; do not interleave coils, inputs, and holding registers in a single DB. Some third-party masters assume Modicon-style addressing (40001 offset) and the layout discipline prevents confusion.
- Use a small (< 200 ms) inter-frame gap. The Siemens CP adds its own turn-around delay; overlapping requests will trigger an "already busy" status (
16#DF88). - For CP 341 with the loadable Modbus master driver, the maximum number of logical connections per CP is 16; plan the polling list accordingly.
- Always wire RS-485 with a common ground reference (signal ground or shield). Floating shields cause CRC errors that appear random but correlate with plant switching events.
- Document the Modbus register map in a separate sheet inside the project documentation. Map both the PLC DB offset and the Modbus address the external master uses.
FAQ
Why doesn't my CP 341 show the Modbus option in Hardware Configuration?
The Modbus RTU driver is a loadable firmware image, not a built-in feature. Install the PTP Param tool from entry ID 27013524, restart SIMATIC Manager, then re-open the CP properties — the Modbus Master/Slave entries will appear in the protocol dropdown.
Can the CP 340 run as a Modbus master and slave simultaneously?
No. The CP 340 supports Modbus master only. For combined master/slave operation on a single port, use the CP 341 (S7-300) or CP 441-2 (S7-400). Both can load the Modbus master/slave driver and serve either role on one physical interface.
Which FB should I call for Modbus master on a CP 341?
With the loadable Modbus master driver, use FB 80 MB_MASTER from the Modbus library shipped with the driver CD, or FB 7 P_RCV_RK / FB 8 P_SND_RK from the standard CP 341 library. For CP 441-2, use FB 9 RECV_441 and FB 10 SEND_441 from the CP 441 library.
How do I map Modbus holding registers into an S7 DB?
In PTP Param, assign a DB number (default DB 102) to the holding-register area. The CP then writes the register value into the DB as a word at the byte offset equal to the register number × 2. Holding register 100 lands at DB 102 DBW 200. The mapping is big-endian — apply byte swap if your CPU program expects little-endian.
What does Modbus error status 16#DF81 mean on a CP 341?
Status 16#DF81 indicates a response timeout — the slave did not reply within the configured timeout window. Verify the slave address, baud rate (default 9600, 8E1), and physical wiring. If the slave is slow, increase the response timeout in the CP's hardware parameters to at least twice the slave's processing time.