Configuring Modbus on Siemens S7 CP 340/341/441: Setup Guide

David Krause13 min read
ModbusSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Configuring Modbus RTU on Siemens S7 CP 340, CP 341, and CP 441 Modules

Modbus RTU integration on a Siemens S7 PLC requires a serial communications processor (CP) and the dedicated PTP Param parameterization tool. The CP modules themselves do not expose a Modbus tab directly in STEP 7 Hardware Configuration; instead, the protocol-specific parameters are loaded into the CP via the PTP Param utility after the module has been inserted into the hardware catalog. This article details the full commissioning path for the CP 340, CP 341, and CP 441-1 / CP 441-2 modules, including module selection, software installation, register mapping, FB programming, and on-line verification.

1. Overview of Modbus on Siemens Serial CPs

The Siemens serial communication processors implement Modbus through a loadable driver on the CP firmware. The driver is selected in the PTP Param tool and downloaded into the CP's flash memory. Once loaded, the CP autonomously handles the Modbus frame, CRC, and timing — leaving the CPU free to issue request jobs and parse responses via standardized function blocks.

CP Module Order Number (MLFB) Max Baud Rate Protocols Supported Typical PLC
CP 340 6ES7 340-1xxx-xAxx 19.2 kbit/s (RS-232/422/485) ASCII, 3964(R), Modbus RTU (loadable) S7-300, ET 200M
CP 341 6ES7 341-1xxx-xAxx 76.8 kbit/s (RS-232/422/485) ASCII, 3964(R), Modbus RTU Master/Slave (loadable) S7-300, ET 200M
CP 441-1 6ES7 441-1xxx-xx0x 38.4 kbit/s per interface ASCII, 3964(R), Modbus RTU (loadable) S7-400
CP 441-2 6ES7 441-2xxx-xx0x 115.2 kbit/s per interface ASCII, 3964(R), Modbus RTU Master/Slave (loadable) S7-400
Important: Modbus RTU is not a built-in feature of the CP firmware shipped from the factory. The protocol driver is a separately loadable piece of firmware, distributed with the PTP Param CD and re-distributed via the Siemens Support entry ID 27013524. Without this driver installed on the CP, the Modbus option will not appear in any configuration dialog.

2. Prerequisites

Confirm the following before commissioning:

  1. STEP 7 version compatibility: STEP 7 V5.4 SP5 or higher for CP 340/341, STEP 7 V5.5 SP4 or higher for CP 441. TIA Portal does not natively configure these legacy CP modules — use the legacy STEP 7 (SIMATIC Manager) for parameterization even when the CPU is a newer S7-300/S7-400.
  2. PTP Param tool installed on the engineering station. The installer is delivered on the CD bundled with every CP, and the latest revision is available on the Siemens Industry Online Support portal.
  3. Appropriate hardware configuration with the CP inserted on a compatible slot. CP 340 and CP 341 occupy one slot each in the S7-300 rack. CP 441 occupies one slot in the S7-400 rack.
  4. Licensed driver image for the Modbus protocol loaded into the CP's flash memory.
  5. Modbus slave devices with known station addresses (1–247 per the Modbus standard), register maps, and supported function codes.

3. Installing the PTP Param Parameterization Software

The PTP Param tool is the only Siemens-licensed utility that writes Modbus driver images and protocol parameters into the CP. Installation is straightforward but must be completed before opening Hardware Configuration.

  1. Insert the CD shipped with the CP. If the CD is missing, download the current package from Siemens Support entry ID 27013524 — "CP PTP Parameter assignment tool".
  2. Run setup.exe and select the appropriate CP family (CP 340/341 or CP 441). The installer copies the executable (ptpparam.exe), driver images, and the corresponding Hardware Configuration support packages into the STEP 7 directory tree.
  3. Restart SIMATIC Manager to register the new hardware catalog entries.
  4. Open the CP in Hardware Configuration and confirm that the Protocol dropdown in the CP properties dialog now lists Modbus Master and Modbus Slave. If the entries are absent, the PTP Param install was not detected by STEP 7 — re-run the setup and verify the destination folder.

4. Selecting the Correct CP for Your Application

Selection Criterion CP 340 CP 341 CP 441-1 CP 441-2
Single master / few slaves, low speed Recommended OK Over-spec Over-spec
Master and slave role on same port Not supported Yes Not supported Yes
High baud rate (> 38.4 kbit/s) No Up to 76.8 Up to 38.4 Up to 115.2
Multiple simultaneous ports 1 1 1 2
Redundant CP architecture No No No Yes (with CPU 41x-H)

If you need both Modbus master and slave on a single port of an S7-300, the CP 341 (or the CP 441-2) is mandatory. The CP 340 only supports master mode.

5. STEP 7 Hardware Configuration

Open the S7 project in SIMATIC Manager and edit the station in Hardware Configuration (HW Config).

  1. Insert the CP from the catalog. For an S7-300, drag CP 341 > RS-485/422 onto a free slot (slot 4–11 typical). For an S7-400, drag CP 441 onto slot 4–15.
  2. Open the CP's object properties by double-clicking the module. The default tab is General; switch to the Parameters tab.
  3. Select the interface (IF1 / IF2 on CP 441-2) and the physical layer: RS-485 2-wire, RS-485 4-wire, or RS-232. Match the wiring of the bus.
  4. Activate the Modbus protocol: from the protocol dropdown, select Modbus Master or Modbus Slave. The previously installed PTP Param tool binds this selection to the loadable driver.
  5. Set baud rate, parity, and stop bits to match the slave device. Common values: 9600, 19200, 38400; parity even, 1 stop bit (8E1). Modbus RTU requires 11 bits per character (1 start + 8 data + 1 parity + 1 stop); 10-bit formats are not RTU-compliant.
  6. Configure the response timeout: typical default is 2000 ms for slaves, 500 ms for adjacent masters. Adjust to (slave processing time) × (number of polled stations) + inter-frame gap.
  7. Save and compile the hardware configuration and download it to the PLC.
Verification step: After download, switch the CP online in HW Config. The Diagnostic Buffer and the CP's Operating Mode indicators should report RUN with no parameter errors. If the CP reports SF (group fault) and BF (bus fault) immediately, the protocol image is missing — re-run the PTP Param download.

6. Modbus Master Configuration Detail

For a CP 341 / CP 441-2 in master mode, define each polled slave as a logical connection. Each connection stores the slave address, scan rate, and the register to read/write.

Field Setting
Slave Address 1–247 (255 inclusive address space in some tools, but 247 is the Modbus standard limit)
Function Code 01 (Read Coils), 02 (Read Discrete Inputs), 03 (Read Holding Regs), 04 (Read Input Regs), 05 (Write Single Coil), 06 (Write Single Reg), 15 (Write Multiple Coils), 16 (Write Multiple Regs)
Register Range 0–65535 (Modbus address space; +40001 offset common for holding registers)
Polling Interval Defined by user program via SEND/RECEIVE cycle time
Max. Registers per Request 125 (function code 03/04), 2000 (function code 16)

The master is polled from the CPU via the standard Siemens function blocks. For CP 341 with Modbus master driver, use FB 7 "P_RCV_RK" and FB 8 "P_SND_RK" from the Modbus master library, or the integrated block FB 80 "MB_MASTER" available with newer driver versions. For CP 441-2, use FB 9 "RECV_441" and FB 10 "SEND_441".

7. Modbus Slave Configuration Detail

In slave mode, the CP answers requests from external masters. Configure the CP's slave address (1–247), then map the four standard Modbus areas to DB blocks in the CPU:

Modbus Area FC Source in CPU Default Mapping
Coils (output) 01 / 05 / 15 Bit memory or DB DB 100, starting at offset 0.0
Discrete Inputs 02 Process input image / DB DB 101, starting at offset 0.0
Holding Registers 03 / 06 / 16 DB (word-aligned) DB 102, starting at offset 0.0
Input Registers 04 DB (read-only) DB 103, starting at offset 0.0

The starting DB number is configurable in PTP Param. Each register occupies 2 bytes; coil 0 = DBxx.DBX0.0, coil 1 = DBxx.DBX0.1, etc. Holding register 0 = DBxx.DBW0, register 1 = DBxx.DBW2. Modbus masters typically address these as 40001, 40002, etc., with the offset of 40001 added externally by the master. The Siemens CP does not apply any offset — register 0 in the master request always points to DBB0.

8. Register and Coil Mapping Reference

The following table summarizes the bit- and byte-level mapping inside the configured DB. This is the most frequent source of field errors:

Modbus Address CP 341/441 DB Mapping (Big-Endian word order)
Coil 0–15 DB 100 DBW0 (low byte = coils 0–7, high byte = coils 8–15)
Coil 16–31 DB 100 DBW2
Holding Reg 0 DB 102 DBW0 (low byte first if using Modicon convention, high byte first if Siemens convention)
Holding Reg 1 DB 102 DBW2
Input Reg 0 DB 103 DBW0
Byte-order warning: Modbus is big-endian on the wire; the CP preserves that order inside the DB. If your CPU program interprets the word in little-endian (as S7 does natively), use TAH/TAL byte-swap instructions or swap in the FB layer. Several field failures with power meters and drives have been traced to mismatched byte order; always verify with a known reference value (e.g., write 0x1234 to register 0 and read back from the master).

9. Programming the Modbus Master in the CPU

Use the Modbus master library function blocks in the OB 1 cycle. The call interface for CP 341 with the loadable Modbus master driver:

// Master request: read 10 holding regs from slave 5, start reg 100
CALL  FB 80 "MB_MASTER"
  REQ    := M 10.0          // Trigger request, set for one cycle
  ID     := W#16#100        // Logical address from HW Config (CP slot address + 1)
  MODE   := B#16#4          // 4 = Read holding registers (FC 03)
  SLAVE  := B#16#5          // Slave address 5
  ADDR   := W#16#100        // Start register address
  LEN    := B#16#A          // Number of registers = 10
  DATA   := P#DB 50.DBX 0.0 BYTE 20 // 10 words = 20 bytes
  DONE   := M 10.1
  ERROR  := M 10.2
  STATUS := MW 12
  NDR    := M 10.3

Parameters to verify during commissioning:

  • ID: the logical base address of the CP. For CP 341 in slot 4 of an S7-300, the input address is typically 256 and the output address 256 — the ID is the input address for receive-oriented blocks and the output address for send-oriented blocks; with bidirectional Modbus, use the output address.
  • STATUS = 16#DF80 indicates "request in progress"; 16#0000 = success. Common error codes: 16#DF81 (response timeout), 16#DF82 (CRC error), 16#DF83 (illegal FC), 16#DF84 (illegal data address), 16#DF85 (illegal data value).

10. Verifying the Bus

After hardware configuration, driver download, and CPU programming, validate communication end-to-end:

  1. LED check: CP 341/441 LEDs should be solid green on the SF and TXD/RXD indicators after a successful slave response. The CP 341 has dedicated LEDs: SF (group fault), BF (bus fault), TD (transmit data), RD (receive data).
  2. Hardware Configuration online diagnostic buffer: Select the CP in HW Config and view PLC > Module Information > Diagnostic Buffer. Look for entries of type Communication error with timestamp — these correspond to corrupted frames or timeouts.
  3. Modbus diagnostic counters: In PTP Param, the online view exposes counters: Frames sent OK, Frames received OK, CRC errors, Timeouts, Overrun errors. Watch the ratio of CRC errors to total frames — should be 0% on a healthy bus.
  4. Slave-side confirmation: From a Modbus master on a laptop (e.g., using Modbus Poll for testing, not as a production tool), poll the CP in slave mode and verify the coils and registers match the expected DB values.
  5. Function-code round-trip: Use FC 03 to read back a value written by FC 06 — this tests both directions and verifies byte order.

11. Troubleshooting Matrix

Symptom Likely Root Cause Diagnostic Step Remedy
Modbus option missing in HW Config PTP Param not installed Check C:\Program Files\Siemens\Automation\PTP_Param Install PTP Param, restart SIMATIC Manager
CP reports SF + BF immediately Driver image not loaded Open PTP Param, connect online, check firmware version Re-download Modbus driver image to CP
All requests return timeout Wiring / baud / parity mismatch Verify with oscilloscope on the bus; confirm 8E1 Match slave settings; check A/B polarity on RS-485
Intermittent CRC errors Cable too long / no termination / EMC Inspect cable length < 1200 m; termination at bus ends only Add 120 Ω termination; use shielded twisted pair
Single register read returns wrong value Byte-order mismatch Write 0x1234, read back, compare byte order Swap bytes in CPU program before/after transfer
Some slaves respond, others don't Duplicate address or broadcast on RS-485 Disconnect slaves one at a time Re-number addresses; ensure unique 1–247 per bus
FB 80 returns 16#DF81 repeatedly Slave processing time exceeded Increase response timeout in HW Config Set timeout ≥ 2 × slave response time
Hold register write succeeds, coil write fails Coils mapped to read-only DB Check PTP Param coil mapping Use DB 100 with write access; verify DB attributes

12. Compatibility and Migration Notes

  • STEP 7 V5.x only: These CPs and the PTP Param tool are not supported in TIA Portal. Projects with newer TIA CPUs that need Modbus RTU must use an ET 200SP PTP module or a CM PtP, configured from TIA Portal with native Modbus blocks (MB_MASTER, MB_SLAVE V3+).
  • Modbus TCP alternative: If a serial RS-485 link is not mandatory, prefer Modbus TCP on a CP 343-1 Lean / CP 443-1 via the open Modbus/TCP library (Siemens entry ID 62830447 — "Modbus TCP PN-CPU"). Configuration is via TIA Portal block calls and avoids the PTP Param tool entirely.
  • Replacement modules: For new S7-300 builds, the CP 341 is end-of-life but the recommended replacement is the CM PtP in ET 200S or CM 1241 on S7-1200/1500. Existing installations with CP 341 remain supportable via the latest PTP Param revision.

13. Field-Proven Best Practices

  1. Always place the Modbus slave's holding-register DB in non-optimized access mode (DB attribute Standard, not Optimized) — the CP accesses the DB via absolute offsets and optimized symbolic access breaks the mapping.
  2. Reserve one DB per Modbus area; do not interleave coils, inputs, and holding registers in a single DB. Some third-party masters assume Modicon-style addressing (40001 offset) and the layout discipline prevents confusion.
  3. Use a small (< 200 ms) inter-frame gap. The Siemens CP adds its own turn-around delay; overlapping requests will trigger an "already busy" status (16#DF88).
  4. For CP 341 with the loadable Modbus master driver, the maximum number of logical connections per CP is 16; plan the polling list accordingly.
  5. Always wire RS-485 with a common ground reference (signal ground or shield). Floating shields cause CRC errors that appear random but correlate with plant switching events.
  6. Document the Modbus register map in a separate sheet inside the project documentation. Map both the PLC DB offset and the Modbus address the external master uses.
Safety notice: Modbus RTU has no built-in authentication or integrity check beyond the 16-bit CRC. Do not use Modbus RTU for safety-critical signaling. For safety-relevant communication, use PROFIsafe on PROFINET or PROFIBUS — never substitute Modbus RTU.

FAQ

Why doesn't my CP 341 show the Modbus option in Hardware Configuration?

The Modbus RTU driver is a loadable firmware image, not a built-in feature. Install the PTP Param tool from entry ID 27013524, restart SIMATIC Manager, then re-open the CP properties — the Modbus Master/Slave entries will appear in the protocol dropdown.

Can the CP 340 run as a Modbus master and slave simultaneously?

No. The CP 340 supports Modbus master only. For combined master/slave operation on a single port, use the CP 341 (S7-300) or CP 441-2 (S7-400). Both can load the Modbus master/slave driver and serve either role on one physical interface.

Which FB should I call for Modbus master on a CP 341?

With the loadable Modbus master driver, use FB 80 MB_MASTER from the Modbus library shipped with the driver CD, or FB 7 P_RCV_RK / FB 8 P_SND_RK from the standard CP 341 library. For CP 441-2, use FB 9 RECV_441 and FB 10 SEND_441 from the CP 441 library.

How do I map Modbus holding registers into an S7 DB?

In PTP Param, assign a DB number (default DB 102) to the holding-register area. The CP then writes the register value into the DB as a word at the byte offset equal to the register number × 2. Holding register 100 lands at DB 102 DBW 200. The mapping is big-endian — apply byte swap if your CPU program expects little-endian.

What does Modbus error status 16#DF81 mean on a CP 341?

Status 16#DF81 indicates a response timeout — the slave did not reply within the configured timeout window. Verify the slave address, baud rate (default 9600, 8E1), and physical wiring. If the slave is slow, increase the response timeout in the CP's hardware parameters to at least twice the slave's processing time.

Back to blog