Skip These Quick Fixes
An SMC EX250 valve manifold on EtherNet/IP runs fine under a CompactLogix. It stays silent under a Productivity3000 (P3000) or a DL205 with a DL260 CPU. Most people try the fixes below first. Each one fails for a specific reason.
| Quick fix tried | Why it fails |
|---|---|
| Plug the EX250 into the P3000 Ethernet port and point a Modbus TCP read at it | "Ethernet" is only the physical and transport layer. EtherNet/IP is CIP (Common Industrial Protocol) carried over TCP/UDP. Modbus TCP is a separate application protocol on port 502. The EX250 EtherNet/IP module does not answer Modbus requests. |
| Add a DL205 PROFIBUS or DeviceNet module and switch the EX250 to that bus | Both DL205 fieldbus modules are slave only. The EX250 is also a slave, so neither end starts the I/O exchange. |
| Use ECOM or ECOM100 Modbus TCP client mode | ECOM and ECOM100 act as Modbus TCP client or server only. Same protocol mismatch as the P3000 Modbus client. |
| Build a "custom protocol" with the P3000/DL205 ASCII instructions | ASCII instructions format character strings for serial or raw devices. The EX250 does not use ASCII-code communication. You cannot hand-build a CIP connection this way. |
What does restore production is one of two paths. Either the CPU speaks EtherNet/IP natively, or a protocol gateway sits between Modbus TCP on the PLC side and EtherNet/IP on the valve side. Work through the checks below to pick the path.
Check 1: Read the EX250 Communication Module Protocol
Reading: the part number and label on the EX250 SI (serial interface) unit, cross-checked against the SMC catalog.
The EX250 family comes in these protocol variants:
- DeviceNet
- PROFIBUS
- CC-Link
- AS-i
- CANopen
- ControlNet
- EtherNet/IP
Modbus TCP is not in the list.
- EtherNet/IP module installed: go to Check 2.
- Another fieldbus module installed: you need a master for that bus. The DL205 fieldbus modules are slaves, so go straight to Check 4 and size a gateway for that fieldbus.
- Module not yet purchased: ask SMC whether a Modbus-capable interface exists and what it costs. A native Modbus TCP slave on the valve side removes the gateway entirely.
Check 2: Identify the Controller and Its Firmware
Reading: CPU catalog number and installed firmware in the Productivity Suite hardware configuration, plus the programming software version.
- P3-550 CPU: EtherNet/IP was later added as a native protocol. You enable it by upgrading both the CPU module firmware and the Productivity Suite software. Upgrade, then open the release notes for your firmware. Confirm the CPU can act as an EtherNet/IP scanner (originator) to an adapter device. If it can, add the EX250 as an adapter using the assembly instances and sizes from the SMC manual, and skip the gateway. If the release notes only describe adapter or explicit-message functions, go to Check 4.
- P3-550 on older firmware you cannot upgrade (validated system, spares policy): treat it as Modbus TCP only and go to Check 3.
- DL260 CPU in a DL205 rack: go to Check 3.
Stop here if the upgraded P3-550 lists EtherNet/IP scanning. A native connection beats a gateway on wiring, spares, and diagnostics.
Check 3: Confirm Who Is Master
The EX250 is always the slave (adapter). It waits for a scanner to open an I/O connection and send outputs at a requested packet interval. On your side, something must be the master or client.
| Controller option | Role available | Can it drive an EX250 directly? |
|---|---|---|
| DL205 PROFIBUS module | Slave only | No |
| DL205 DeviceNet module | Slave only | No |
| DL205 ECOM / ECOM100 | Modbus TCP client or server | Only through a Modbus TCP to EtherNet/IP gateway |
| P3000 Ethernet port (Modbus TCP) | Modbus TCP client or server | Only through a gateway |
| P3-550 with EtherNet/IP firmware | Per release notes | Yes, if scanner function is listed |
If your controller can only be a Modbus TCP client, go to Check 4.
Check 4: Pick the Bridge
Three options work. Pick the one that matches the parts you have and the risk you can accept.
| Bridge | How it works | Trade-off |
|---|---|---|
| HMS Anybus X-Gateway (Modbus TCP ↔ EtherNet/IP) | The gateway scans the EX250 as an EtherNet/IP scanner. It exposes the I/O as Modbus registers to the P3000, which acts as the Modbus TCP client. | Proven on this exact pairing. Gateway-side configuration is not intuitive, and bit order needs mapping. |
| Small A-B controller as translator | The P3000/DL205 drives hardwired outputs into a MicroLogix-class controller. That controller talks to the EX250. | Adds a second program, a second spare, and I/O wiring. Before buying, confirm the chosen model can own I/O connections to an adapter. |
| Modbus interface from SMC | The valve-side interface speaks Modbus TCP natively. | Not in the standard EX250 protocol list. Only viable if SMC supplies it at acceptable cost. |
A note on determinism: the Modbus TCP leg is polled. Update timing depends on the P3000 poll interval, how fast the gateway turns requests around, and network load. The EtherNet/IP leg runs on a scheduled I/O connection. For valve sequencing where milliseconds matter, measure the round trip (Verification, below) before committing a large job to the gateway path.
Configure the Gateway Path
Get it running with a laptop first, then bring in the PLC. Isolating each leg saves hours.
- Set IP addresses for the EX250, the gateway's EtherNet/IP side, and the gateway's Modbus TCP side. Use the SMC and HMS tools. Keep everything on one subnet for the first test.
- In the gateway configuration, add the EX250 as an EtherNet/IP adapter. Enter the input and output assembly instances and sizes from the SMC EX250 manual. A size mismatch is the usual reason the I/O connection never opens.
- Map the EtherNet/IP input and output data to Modbus register areas on the gateway. Write down the exact register offsets. You will need them in the P3000.
- From a laptop, poll the gateway with a Modbus TCP test master such as ModScan32. Read the input area and confirm status bits change when manifold inputs or diagnostics change. Stop here if reads fail. The fault is in the gateway or EX250 configuration, not the PLC.
- Still from the test master, write the output registers and confirm solenoids actuate. If reads work but writes do not, the output mapping or the gateway's EtherNet/IP output connection is wrong. Stay on the gateway side until writes work from the laptop.
- In the P3000, configure an
MRX(Modbus Read) instruction to the gateway IP and the input register offsets. Pair it with a Modbus write instruction for the output registers. - Parse the input words with
UPKB(Unpack Bits).MRXmoves 16-bit words, not individual bits. Build output words from bit tags with the matching pack function before the write executes.
Map the Bits: Reversed Order and Gaps
Reads working and writes working does not mean the right valve fires. Expect the solenoid order to look scrambled until you map it by testing.
On one working P3000 + Anybus + EX250 installation, the valve bit order came out as follows:
- Solenoids 8 down to 1
- Then 16 down to 9
- Then a gap
- Then 24 down to 21
Two mechanisms produce patterns like this:
- Bit numbering direction within a byte. One side counts bit 0 as the least significant bit. The other maps the first solenoid to the most significant bit.
- Byte packing into 16-bit Modbus registers. Gateways move EtherNet/IP data as a byte array. How two bytes land in one register (byte swap) depends on the gateway setting. Some Modbus devices expose a byte-swap configuration bit. If a replacement unit ships with that bit in the other state, data arrives jumbled after a swap-out.
| Symptom | Likely cause | Check |
|---|---|---|
| No I/O at all from test master | Gateway not connected to EX250; wrong assembly size or IP | Gateway EtherNet/IP connection status; EX250 network LEDs |
| Status reads OK, outputs never actuate | Output area not mapped, or written to wrong register offset | Write from ModScan32 to each output register |
| Wrong solenoid fires, pattern mirrored within each 8 | Bit order reversed within bytes | Fire one bit at a time; record the actual solenoid |
| Wrong group of 8 fires | Byte swap within the 16-bit register | Gateway byte-order setting; swap in logic if needed |
| Some solenoid numbers have no bit | Gap or reserved space in the EX250 data layout | SMC manual data map vs. installed valve stations |
| Everything scrambled after replacing the gateway | Byte-order or config setting not restored | Compare against the saved gateway configuration file |
Build the map empirically:
- Remove air, or lock out the actuators, so a wrong valve cannot move the machine.
- Write a single bit from the test master, one bit at a time.
- Record which solenoid LED lights on the manifold.
- Enter the result in a mapping table.
- Name the P3000 bit tags after the physical solenoid, not after the register bit. The ladder then reads correctly regardless of order.
- Save the gateway configuration file with the PLC project.
Verify Before Handing Back
- Every solenoid: toggle each output tag from the P3000 and confirm the matching solenoid LED. Check both coils on double-solenoid valves.
-
Every status bit: force or simulate each EX250 diagnostic or input condition and confirm the correct
UPKBoutput bit changes. - Timing: run a fast handshake. Set an output, read back a related status, and log the round trip in the P3000 over several hundred cycles. Compare the worst case against what the machine sequence can tolerate.
- Comm loss: pull the cable between the gateway and the EX250, then between the PLC and the gateway. Confirm the valves go to the state your safety review requires. Confirm the P3000 flags the Modbus error so logic stops sequencing.
- Power cycle: cycle the gateway alone and the whole panel. Confirm the connection re-establishes without a manual reset.
- Documentation: file the bit map, gateway config, IP plan, and firmware versions with the drawings for the next person on nights.
FAQ
Can a Productivity3000 talk directly to an SMC EX250 over EtherNet/IP?
Yes, on a P3-550 CPU upgraded with firmware and Productivity Suite software that add native EtherNet/IP; confirm scanner support in the release notes. On other CPUs or older firmware, use a Modbus TCP to EtherNet/IP gateway with the P3000 as Modbus TCP client.
Does the DL205 DeviceNet or PROFIBUS module work as a master for an EX250?
No. Both DL205 fieldbus modules are slave only, and the EX250 is also a slave. For a DL260 system, use ECOM or ECOM100 as a Modbus TCP client into a protocol gateway.
Can I keep troubleshooting the gateway myself, or when do I call support?
Stop and call HMS support if the gateway will not open an I/O connection to the EX250 after you have verified assembly instances, sizes, and IPs from a laptop test master. Call SMC support for EX250 data layout, gap, or diagnostic questions, and AutomationDirect support if a P3-550 upgraded for EtherNet/IP will not connect. Do not return valves to air until every solenoid has been bit-mapped and verified.