Configuring P3000 for SMC EX250 EtherNet/IP Valve Manifolds

Brian Holt9 min read
AutomationDirectEtherNet/IPTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Skip These Quick Fixes

An SMC EX250 valve manifold on EtherNet/IP runs fine under a CompactLogix. It stays silent under a Productivity3000 (P3000) or a DL205 with a DL260 CPU. Most people try the fixes below first. Each one fails for a specific reason.

Quick fix tried Why it fails
Plug the EX250 into the P3000 Ethernet port and point a Modbus TCP read at it "Ethernet" is only the physical and transport layer. EtherNet/IP is CIP (Common Industrial Protocol) carried over TCP/UDP. Modbus TCP is a separate application protocol on port 502. The EX250 EtherNet/IP module does not answer Modbus requests.
Add a DL205 PROFIBUS or DeviceNet module and switch the EX250 to that bus Both DL205 fieldbus modules are slave only. The EX250 is also a slave, so neither end starts the I/O exchange.
Use ECOM or ECOM100 Modbus TCP client mode ECOM and ECOM100 act as Modbus TCP client or server only. Same protocol mismatch as the P3000 Modbus client.
Build a "custom protocol" with the P3000/DL205 ASCII instructions ASCII instructions format character strings for serial or raw devices. The EX250 does not use ASCII-code communication. You cannot hand-build a CIP connection this way.

What does restore production is one of two paths. Either the CPU speaks EtherNet/IP natively, or a protocol gateway sits between Modbus TCP on the PLC side and EtherNet/IP on the valve side. Work through the checks below to pick the path.

Check 1: Read the EX250 Communication Module Protocol

Reading: the part number and label on the EX250 SI (serial interface) unit, cross-checked against the SMC catalog.

The EX250 family comes in these protocol variants:

  • DeviceNet
  • PROFIBUS
  • CC-Link
  • AS-i
  • CANopen
  • ControlNet
  • EtherNet/IP

Modbus TCP is not in the list.

  • EtherNet/IP module installed: go to Check 2.
  • Another fieldbus module installed: you need a master for that bus. The DL205 fieldbus modules are slaves, so go straight to Check 4 and size a gateway for that fieldbus.
  • Module not yet purchased: ask SMC whether a Modbus-capable interface exists and what it costs. A native Modbus TCP slave on the valve side removes the gateway entirely.

Check 2: Identify the Controller and Its Firmware

Reading: CPU catalog number and installed firmware in the Productivity Suite hardware configuration, plus the programming software version.

  • P3-550 CPU: EtherNet/IP was later added as a native protocol. You enable it by upgrading both the CPU module firmware and the Productivity Suite software. Upgrade, then open the release notes for your firmware. Confirm the CPU can act as an EtherNet/IP scanner (originator) to an adapter device. If it can, add the EX250 as an adapter using the assembly instances and sizes from the SMC manual, and skip the gateway. If the release notes only describe adapter or explicit-message functions, go to Check 4.
  • P3-550 on older firmware you cannot upgrade (validated system, spares policy): treat it as Modbus TCP only and go to Check 3.
  • DL260 CPU in a DL205 rack: go to Check 3.

Stop here if the upgraded P3-550 lists EtherNet/IP scanning. A native connection beats a gateway on wiring, spares, and diagnostics.

Check 3: Confirm Who Is Master

The EX250 is always the slave (adapter). It waits for a scanner to open an I/O connection and send outputs at a requested packet interval. On your side, something must be the master or client.

Controller option Role available Can it drive an EX250 directly?
DL205 PROFIBUS module Slave only No
DL205 DeviceNet module Slave only No
DL205 ECOM / ECOM100 Modbus TCP client or server Only through a Modbus TCP to EtherNet/IP gateway
P3000 Ethernet port (Modbus TCP) Modbus TCP client or server Only through a gateway
P3-550 with EtherNet/IP firmware Per release notes Yes, if scanner function is listed

If your controller can only be a Modbus TCP client, go to Check 4.

Check 4: Pick the Bridge

Three options work. Pick the one that matches the parts you have and the risk you can accept.

Bridge How it works Trade-off
HMS Anybus X-Gateway (Modbus TCP ↔ EtherNet/IP) The gateway scans the EX250 as an EtherNet/IP scanner. It exposes the I/O as Modbus registers to the P3000, which acts as the Modbus TCP client. Proven on this exact pairing. Gateway-side configuration is not intuitive, and bit order needs mapping.
Small A-B controller as translator The P3000/DL205 drives hardwired outputs into a MicroLogix-class controller. That controller talks to the EX250. Adds a second program, a second spare, and I/O wiring. Before buying, confirm the chosen model can own I/O connections to an adapter.
Modbus interface from SMC The valve-side interface speaks Modbus TCP natively. Not in the standard EX250 protocol list. Only viable if SMC supplies it at acceptable cost.

A note on determinism: the Modbus TCP leg is polled. Update timing depends on the P3000 poll interval, how fast the gateway turns requests around, and network load. The EtherNet/IP leg runs on a scheduled I/O connection. For valve sequencing where milliseconds matter, measure the round trip (Verification, below) before committing a large job to the gateway path.

Configure the Gateway Path

Get it running with a laptop first, then bring in the PLC. Isolating each leg saves hours.

  1. Set IP addresses for the EX250, the gateway's EtherNet/IP side, and the gateway's Modbus TCP side. Use the SMC and HMS tools. Keep everything on one subnet for the first test.
  2. In the gateway configuration, add the EX250 as an EtherNet/IP adapter. Enter the input and output assembly instances and sizes from the SMC EX250 manual. A size mismatch is the usual reason the I/O connection never opens.
  3. Map the EtherNet/IP input and output data to Modbus register areas on the gateway. Write down the exact register offsets. You will need them in the P3000.
  4. From a laptop, poll the gateway with a Modbus TCP test master such as ModScan32. Read the input area and confirm status bits change when manifold inputs or diagnostics change. Stop here if reads fail. The fault is in the gateway or EX250 configuration, not the PLC.
  5. Still from the test master, write the output registers and confirm solenoids actuate. If reads work but writes do not, the output mapping or the gateway's EtherNet/IP output connection is wrong. Stay on the gateway side until writes work from the laptop.
  6. In the P3000, configure an MRX (Modbus Read) instruction to the gateway IP and the input register offsets. Pair it with a Modbus write instruction for the output registers.
  7. Parse the input words with UPKB (Unpack Bits). MRX moves 16-bit words, not individual bits. Build output words from bit tags with the matching pack function before the write executes.

Map the Bits: Reversed Order and Gaps

Reads working and writes working does not mean the right valve fires. Expect the solenoid order to look scrambled until you map it by testing.

On one working P3000 + Anybus + EX250 installation, the valve bit order came out as follows:

  • Solenoids 8 down to 1
  • Then 16 down to 9
  • Then a gap
  • Then 24 down to 21

Two mechanisms produce patterns like this:

  • Bit numbering direction within a byte. One side counts bit 0 as the least significant bit. The other maps the first solenoid to the most significant bit.
  • Byte packing into 16-bit Modbus registers. Gateways move EtherNet/IP data as a byte array. How two bytes land in one register (byte swap) depends on the gateway setting. Some Modbus devices expose a byte-swap configuration bit. If a replacement unit ships with that bit in the other state, data arrives jumbled after a swap-out.
Symptom Likely cause Check
No I/O at all from test master Gateway not connected to EX250; wrong assembly size or IP Gateway EtherNet/IP connection status; EX250 network LEDs
Status reads OK, outputs never actuate Output area not mapped, or written to wrong register offset Write from ModScan32 to each output register
Wrong solenoid fires, pattern mirrored within each 8 Bit order reversed within bytes Fire one bit at a time; record the actual solenoid
Wrong group of 8 fires Byte swap within the 16-bit register Gateway byte-order setting; swap in logic if needed
Some solenoid numbers have no bit Gap or reserved space in the EX250 data layout SMC manual data map vs. installed valve stations
Everything scrambled after replacing the gateway Byte-order or config setting not restored Compare against the saved gateway configuration file

Build the map empirically:

  1. Remove air, or lock out the actuators, so a wrong valve cannot move the machine.
  2. Write a single bit from the test master, one bit at a time.
  3. Record which solenoid LED lights on the manifold.
  4. Enter the result in a mapping table.
  5. Name the P3000 bit tags after the physical solenoid, not after the register bit. The ladder then reads correctly regardless of order.
  6. Save the gateway configuration file with the PLC project.

Verify Before Handing Back

  1. Every solenoid: toggle each output tag from the P3000 and confirm the matching solenoid LED. Check both coils on double-solenoid valves.
  2. Every status bit: force or simulate each EX250 diagnostic or input condition and confirm the correct UPKB output bit changes.
  3. Timing: run a fast handshake. Set an output, read back a related status, and log the round trip in the P3000 over several hundred cycles. Compare the worst case against what the machine sequence can tolerate.
  4. Comm loss: pull the cable between the gateway and the EX250, then between the PLC and the gateway. Confirm the valves go to the state your safety review requires. Confirm the P3000 flags the Modbus error so logic stops sequencing.
  5. Power cycle: cycle the gateway alone and the whole panel. Confirm the connection re-establishes without a manual reset.
  6. Documentation: file the bit map, gateway config, IP plan, and firmware versions with the drawings for the next person on nights.

FAQ

Can a Productivity3000 talk directly to an SMC EX250 over EtherNet/IP?

Yes, on a P3-550 CPU upgraded with firmware and Productivity Suite software that add native EtherNet/IP; confirm scanner support in the release notes. On other CPUs or older firmware, use a Modbus TCP to EtherNet/IP gateway with the P3000 as Modbus TCP client.

Does the DL205 DeviceNet or PROFIBUS module work as a master for an EX250?

No. Both DL205 fieldbus modules are slave only, and the EX250 is also a slave. For a DL260 system, use ECOM or ECOM100 as a Modbus TCP client into a protocol gateway.

Can I keep troubleshooting the gateway myself, or when do I call support?

Stop and call HMS support if the gateway will not open an I/O connection to the EX250 after you have verified assembly instances, sizes, and IPs from a laptop test master. Call SMC support for EX250 data layout, gap, or diagnostic questions, and AutomationDirect support if a P3-550 upgraded for EtherNet/IP will not connect. Do not return valves to air until every solenoid has been bit-mapped and verified.

Back to blog