CP341 Modbus ASCII Slave Overview
The SIMATIC CP 341 is a point-to-point communications processor for the S7-300 automation system. It offloads serial communication from the CPU and supports RS-232C, RS-422, and RS-485 physical interfaces depending on the variant ordered. The module is configured through HW Config in STEP 7 (Classic, V5.x) and exchanges process data via loadable function blocks.
When a CP 341 is used as a Modbus slave, a separate loadable driver is required on top of the base firmware. The base "ASCII" driver only handles free-form 3964R / ASCII frames with no Modbus protocol awareness. The "Modbus ASCII Slave" driver, by contrast, parses incoming Modbus-PDU frames, validates the LRC, and dispatches function codes 01, 02, 03, 04, 05, 06, 07, 08, 11, 12, 15, and 16 to the user data area automatically.
This article documents the procedure for installing the Modbus ASCII Slave driver, applying the matching license dongle, and assigning the slave address inside the CP 341 parameter assignment tool. It is written for engineers commissioning the CP 341 with a SCADA master, a panel, or a third-party controller that speaks Modbus ASCII over RS-232 or RS-485.
Prerequisites and Hardware Requirements
Before configuring the CP 341 as a Modbus ASCII slave, verify the following items are on hand:
- CP 341 module: 6ES7341-1AH02-0AE0 (RS-232C) or 6ES7341-1CH02-0AE0 (RS-422/RS-485). Earlier -1AH01 / -1CH01 versions are functionally equivalent for the Modbus ASCII slave driver.
- S7-300 backplane with the CP 341 inserted and wired to the S7-300 CPU (a free slot is required; the CP 341 cannot occupy slot 0).
- STEP 7 V5.5 + SPx or STEP 7 Professional (Classic) installed on the engineering station.
- Modbus ASCII Slave driver for CP 341 (downloaded from the Siemens Industry Online Support portal, article ID 25356060).
- Modbus ASCII Slave license dongle — a USB-bound license that unlocks the driver at runtime. Important: this is not the same hardware as the Modbus RTU slave dongle (6ES7870-1AB01-0YA1); the RTU dongle will not enable the ASCII slave driver.
- License key floppy / USB transfer mechanism or the Automation License Manager (ALM) V6.x to install the license on a target station.
- Shielded twisted-pair cable with the appropriate connector (DB-9 male for RS-232C or DB-9 / terminal block for RS-485).
ASCII vs. Modbus ASCII: Why the Distinction Matters
The CP 341 firmware exposes more than one ASCII-oriented protocol in the Parameter Assignment Tool. The two relevant entries are:
| Protocol Entry | Function | Use Case |
|---|---|---|
| ASCII | Transparent 3964R / free ASCII framing with no Modbus parsing | Generic serial devices, weigh scales, barcode readers |
| Modbus ASCII Slave | Modbus-IDA-conformant ASCII slave (10-bit frame, LRC, ':' start / CR-LF end) | Modbus masters, SCADA, HMI panels speaking Modbus ASCII |
Both entries appear under the CP 341's protocol selector, but only the Modbus ASCII Slave option is appropriate when a true Modbus master is polling the CP 341. The generic "ASCII" option is a byte-level transparent channel and will not respond to Modbus function codes.
Modbus ASCII differs from Modbus RTU in three measurable ways:
- Framing: ASCII frames begin with the colon character ':' (0x3A) and end with CR-LF (0x0D 0x0A). RTU frames are delimited by 3.5 character times of silence.
- Encoding: ASCII encodes every byte as two printable hex characters (1-9, A-F). RTU uses 8-bit binary with 11-bit frames.
- Error check: ASCII uses an 8-bit Longitudinal Redundancy Check (LRC) computed in 2's complement. RTU uses a 16-bit Cyclical Redundancy Check (CRC-16).
These differences mean the CP 341 must be told the format expected by the master. Mismatched framing produces no slave response and no exception frame, which is the most common commissioning symptom reported on the topic.
Distinguishing the License Dongles
Siemens ships CP 341 drivers with hardware-bound activation. The most commonly confused pair is:
| Order Number | Drives | Notes |
|---|---|---|
| 6ES7870-1AB01-0YA1 | Modbus RTU Slave | 8-bit binary, CRC-16, 3.5-char inter-frame gap |
| Modbus ASCII Slave dongle (separate order) | Modbus ASCII Slave | 7-bit ASCII, LRC, ':' / CR-LF framing |
The two licenses are not interchangeable. To find the current order number for the Modbus ASCII Slave dongle, refer to the Siemens support article ID 25356060, which lists the current license matrix and download package contents.
Installing the Modbus ASCII Slave Driver in STEP 7
Follow the steps below to obtain and install the driver on the engineering PC:
- Open a browser and navigate to Siemens Industry Online Support.
- Search for article ID 25356060 ("CP 341 Modbus master / slave driver") or enter "CP341 Modbus ASCII" in the search bar.
- Download the ZIP archive Modbus_341.zip to a local directory.
- Extract the archive. The contents include a directory named
Modbus_ASCII_Slavewith filesmod_ascii_sl.fmd, FB blocks, and a readme. - Close all running instances of STEP 7 and SIMATIC Manager.
- Run the included setup executable (or manually copy the FMD file to
%ProgramFiles%\Siemens\Automation\CP341\Driver). - Re-launch STEP 7 / SIMATIC Manager. The "Modbus ASCII Slave" entry will now be available in the Parameter Assignment Tool's protocol selector for the CP 341.
If the entry remains absent, the FMD file was not registered with the Parameter Assignment Tool. Re-run the setup with administrator rights and confirm that the file cp341pa.exe (the parameter assignment tool) loads the new FMD at start-up.
Hardware Configuration in HW Config
Once the driver is registered, the CP 341 must be added to the S7-300 project:
- Open the S7 project in SIMATIC Manager and double-click Hardware.
- From the hardware catalog, browse to SIMATIC 300 > CP-300 > Point-to-Point > CP 341.
- Select the variant matching the physical module: 6ES7 341-1AH02-0AE0 (RS-232C) or 6ES7 341-1CH02-0AE0 (RS-422/485).
- Drag the CP 341 into a free slot of the S7-300 rack. Slots 4-11 are valid on a standard 18-slot rack.
- Double-click the CP 341 to open the Properties - CP 341 dialog and assign it within the same subnet as the CPU (or any logical address, the CP supports direct backplane access).
- Click Parameters... to launch the dedicated Parameter Assignment Tool.
Configuring the Modbus ASCII Slave Protocol
The Parameter Assignment Tool is a separate executable (cp341pa.exe) that builds the protocol database. Inside the tool:
- Select the Protocol tab. The selector now shows the entries: ASCII, 3964R, Modbus Master, Modbus Slave, Modbus ASCII Slave, and RK 512.
- Choose Modbus ASCII Slave.
- Configure the physical layer on the Interface tab:
- Baud rate: 1200, 2400, 4800, 9600 (default), or 19200 bit/s
- Data bits: 7 (fixed for Modbus ASCII)
- Stop bits: 1 or 2 (master must match)
- Parity: Even, Odd, or None (master must match)
- Half-duplex / full-duplex: matches the wiring scheme
- Switch to the Modbus Slave tab.
- Enter the Slave Address in decimal (range 1-247, default 1). This is the address the master uses to address the CP 341. Address 0 is the Modbus broadcast address and is reserved.
- Map the data areas. Each Modbus function code is bound to a contiguous data block region. The default mapping is:
- Function 01/05/15 → Output Coils (DB or process image bit area)
- Function 02 → Input Coils (DB or input area)
- Function 03/06/16 → Holding Registers (DB or MW area)
- Function 04 → Input Registers (DB or PEW area)
- Enable Diagnostic Interrupts if the application requires OB82 / OB87 to be triggered on comms errors.
- Click OK to save the database, then Download to Target in HW Config.
Where the Slave Address Is Stored
The slave address is a single parameter inside the protocol database created by the Parameter Assignment Tool. It is not stored in the user program and not in a function block input. To change the slave address after initial commissioning:
- Open HW Config and double-click the CP 341.
- Click Parameters... to launch the Parameter Assignment Tool.
- On the Modbus Slave tab, change the address field.
- Click OK twice and re-download the hardware configuration to the S7-300 station.
The new address becomes effective on the next CP 341 start-up (cold restart) or when the parameter assignment is reloaded via the diagnostic interface. Hot-swapping the slave address at runtime is not supported on the CP 341.
Wiring and Physical Layer
Pin assignments for the CP 341 front connector follow the Siemens standard:
| Signal | RS-232C Pin (DB-9) | RS-485 Pin (DB-9 / terminal) |
|---|---|---|
| TxD / T(R) | 2 | 3 (R/T+ on terminal block) |
| RxD / R(T) | 3 | 8 (R/T- on terminal block) |
| RTS | 4 | — |
| CTS | 5 | — |
| Signal GND | 5 | 5 (GND on terminal block) |
| Shield | Housing | Housing |
For RS-485 multi-drop Modbus networks, terminate the bus at both ends with 120 Ω resistors, set the CP 341 to "Half-duplex (RS-485 2-wire)", and enable the bus-termination DIP switch on the front of the CP 341 if the module is the end node. Always tie the cable shield to ground at one end only to avoid ground loops.
Programming the Slave Interface
After the protocol database is downloaded, the user program exchanges process data with the CP 341 through two function blocks supplied with the driver:
- FB 7 ("P_RCV_RK") — receives data from the CP 341 (Modbus response frames and unsolicited event frames)
- FB 8 ("P_SND_RK") — sends data to the CP 341 (rarely used in pure slave mode, but required during startup to initialize the CP 341)
Typical call in OB 1 (STL syntax) for the Modbus ASCII Slave driver:
CALL FB 7, DB 107
EN := TRUE
REQ := // not used in slave
R := FALSE
LADDR:= 256 // logical base address of CP 341
DB_NO:= 200 // data block containing the protocol data
DBB_NO:= 0 // start byte within DB
LEN := 100 // length of process data in bytes
NDR := M 100.0 // new data received
ERROR:= M 100.1 // receive error
STATUS:= MW 102 // status / error code
The driver's instance DB (DB 107 in the example) is generated automatically when the FBs are inserted into the project from the Modbus ASCII Slave library. The data block DB 200 holds the Modbus process image: holding registers, input registers, and coils. Tie the offset of the data block to the offsets configured in the Parameter Assignment Tool.
Commissioning and Verification
Run the following checks after download:
- Open CP 341 Online Diagnostics from STEP 7 (right-click CP 341 → Module Information). Confirm:
- Module state: OK
- Protocol loaded: Modbus ASCII Slave
- License: Permanent
- Slave address: matches the configured value
- From a Modbus master tool (e.g. Modbus Poll, CAS Modbus Scanner, or a WinCC channel), issue function code 03 starting at register 0 with a length of 10 words. The CP 341 should return the contents of the configured DB.
- Toggle a coil via function code 05 and verify that the corresponding bit in the DB changes.
- Force a deliberate parity error on the master side. The CP 341 should return a Modbus exception 02 (Illegal Data Address) or, if the LRC fails, exception 08 (LRC Error) and increment the diagnostic counter.
Troubleshooting Matrix
| Symptom | Likely Cause | Corrective Action |
|---|---|---|
| Master times out, no response from CP 341 | Wrong license dongle (RTU dongle mounted for ASCII driver) | Verify license in Parameter Assignment Tool; install the Modbus ASCII Slave dongle |
| Protocol selector does not list "Modbus ASCII Slave" | Driver FMD not installed | Reinstall from the article 25356060 download package |
| CP 341 returns exception 02 (Illegal Data Address) | DB offset outside configured data area | Check the Modbus tab mapping in the Parameter Assignment Tool |
| Frames are visible on the wire but no slave response | Baud rate, parity, or data bits mismatched | Match master parameters to CP 341 settings; ASCII requires 7 data bits |
| License error LED on CP 341 front panel | Dongle missing, wrong dongle, or license not transferred to ALM | Transfer license with Automation License Manager; reseat the dongle |
| Data values returned are off by one word | Modbus 0-based vs. application 1-based addressing | Adjust the application data block offset by 1 or re-map in the parameter tool |
| Intermittent response, frames truncated | RS-485 termination missing or excessive bus length | Add 120 Ω at both ends; keep cable under 1200 m at 9600 bit/s |
| SF LED on after parameter download | Diagnostic interrupt active, no OB82 loaded | Load OB82 in the CPU, or disable diagnostic interrupts in the parameter tool |
Status and Error Codes Returned by the Driver
The status word returned on the LEN / STATUS output of FB 7 and FB 8 carries driver-specific codes. The most relevant for the ASCII slave are:
| STATUS (hex) | Meaning | Recommended Action |
|---|---|---|
| 0000 | No error | — |
| 0x7001 | Receive in progress | Wait for NDR or ERROR |
| 0x7002 | Send in progress | Wait for DONE or ERROR |
| 0x8081 | Receive buffer overflow | Increase LEN or slow the master poll |
| 0x8085 | Framing error (parity, stop bit, or LRC) | Check master / slave parameter match |
| 0x8090 | License missing or invalid | Verify Modbus ASCII Slave dongle installed |
| 0x80A1 | Function code not supported | Verify the FC is in the supported list (01-16 except 09, 10, 13, 14) |
Differences From CP 441 and ET 200S 1SI
The CP 341 shares much of its driver architecture with the higher-end CP 441 and the distributed ET 200S 1SI serial interface module. Engineers migrating projects between these should note:
- The CP 441 supports a different set of FBs (FB 9-12) and uses a separate order-number matrix for licenses.
- The ET 200S 1SI (6ES7138-4DF01-0AB0) accepts the same Modbus ASCII Slave FMD but assigns the slave address through the GSD file configuration, not the classic parameter tool.
- Function block call signatures differ. Code that targets the CP 341 cannot be reused verbatim on the 1SI without adjustment of LADDR, LEN, and DB number fields.
Frequently Asked Questions
Can the Modbus RTU slave dongle 6ES7870-1AB01-0YA1 be used with the Modbus ASCII slave driver?
No. The RTU slave dongle 6ES7870-1AB01-0YA1 only enables the Modbus RTU Slave driver. The Modbus ASCII Slave driver requires its own dedicated license dongle, and the license status can be verified in the CP 341 Parameter Assignment Tool under the Protocol tab.
Where is the Modbus ASCII slave address configured on the CP 341?
The slave address (1-247) is set inside the CP 341 Parameter Assignment Tool on the Modbus Slave tab, not in the user program. After changing the address, re-download the hardware configuration and restart the CP 341 for the new value to take effect.
Why does the CP 341 not respond to a Modbus ASCII master poll?
Most "no response" issues are caused by a missing or wrong license dongle, mismatched serial parameters (ASCII requires 7 data bits), or an unloaded driver FMD. Verify the license status, ensure the master uses 7E1 or 7N2 framing, and confirm the Modbus ASCII Slave driver appears in the parameter tool's protocol selector.
Which function codes does the CP 341 Modbus ASCII slave support?
The driver supports function codes 01, 02, 03, 04, 05, 06, 07, 08, 11, 12, 15, and 16. Function code 08 sub-code 00 (return query) is supported for loopback testing. Function codes 09, 10, 13, and 14 are not implemented and will return exception code 01 (Illegal Function).
What is the maximum Modbus RTU/ASCII frame size on the CP 341?
The Modbus ASCII slave driver accepts PDUs up to 255 bytes of payload, limited by the LRC computation and the receive buffer of 1024 bytes per FB 7 call. For typical register polls (function 03 with up to 125 registers per request) the CP 341 is more than capable. For bulk coil access (function 15) keep the bit count at 1968 bits per request as recommended by the Modbus-IDA specification.