Configuring Siemens CP341 as Modbus ASCII Slave in STEP 7

David Krause13 min read
ModbusSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

CP341 Modbus ASCII Slave Overview

The SIMATIC CP 341 is a point-to-point communications processor for the S7-300 automation system. It offloads serial communication from the CPU and supports RS-232C, RS-422, and RS-485 physical interfaces depending on the variant ordered. The module is configured through HW Config in STEP 7 (Classic, V5.x) and exchanges process data via loadable function blocks.

When a CP 341 is used as a Modbus slave, a separate loadable driver is required on top of the base firmware. The base "ASCII" driver only handles free-form 3964R / ASCII frames with no Modbus protocol awareness. The "Modbus ASCII Slave" driver, by contrast, parses incoming Modbus-PDU frames, validates the LRC, and dispatches function codes 01, 02, 03, 04, 05, 06, 07, 08, 11, 12, 15, and 16 to the user data area automatically.

This article documents the procedure for installing the Modbus ASCII Slave driver, applying the matching license dongle, and assigning the slave address inside the CP 341 parameter assignment tool. It is written for engineers commissioning the CP 341 with a SCADA master, a panel, or a third-party controller that speaks Modbus ASCII over RS-232 or RS-485.

Prerequisites and Hardware Requirements

Before configuring the CP 341 as a Modbus ASCII slave, verify the following items are on hand:

  • CP 341 module: 6ES7341-1AH02-0AE0 (RS-232C) or 6ES7341-1CH02-0AE0 (RS-422/RS-485). Earlier -1AH01 / -1CH01 versions are functionally equivalent for the Modbus ASCII slave driver.
  • S7-300 backplane with the CP 341 inserted and wired to the S7-300 CPU (a free slot is required; the CP 341 cannot occupy slot 0).
  • STEP 7 V5.5 + SPx or STEP 7 Professional (Classic) installed on the engineering station.
  • Modbus ASCII Slave driver for CP 341 (downloaded from the Siemens Industry Online Support portal, article ID 25356060).
  • Modbus ASCII Slave license dongle — a USB-bound license that unlocks the driver at runtime. Important: this is not the same hardware as the Modbus RTU slave dongle (6ES7870-1AB01-0YA1); the RTU dongle will not enable the ASCII slave driver.
  • License key floppy / USB transfer mechanism or the Automation License Manager (ALM) V6.x to install the license on a target station.
  • Shielded twisted-pair cable with the appropriate connector (DB-9 male for RS-232C or DB-9 / terminal block for RS-485).
Critical: The dongle 6ES7870-1AB01-0YA1 unlocks the Modbus RTU Slave driver only. Installing this dongle and selecting the Modbus ASCII Slave protocol will produce a license error at startup. A separate license must be ordered for the Modbus ASCII Slave driver.

ASCII vs. Modbus ASCII: Why the Distinction Matters

The CP 341 firmware exposes more than one ASCII-oriented protocol in the Parameter Assignment Tool. The two relevant entries are:

Protocol Entry Function Use Case
ASCII Transparent 3964R / free ASCII framing with no Modbus parsing Generic serial devices, weigh scales, barcode readers
Modbus ASCII Slave Modbus-IDA-conformant ASCII slave (10-bit frame, LRC, ':' start / CR-LF end) Modbus masters, SCADA, HMI panels speaking Modbus ASCII

Both entries appear under the CP 341's protocol selector, but only the Modbus ASCII Slave option is appropriate when a true Modbus master is polling the CP 341. The generic "ASCII" option is a byte-level transparent channel and will not respond to Modbus function codes.

Modbus ASCII differs from Modbus RTU in three measurable ways:

  • Framing: ASCII frames begin with the colon character ':' (0x3A) and end with CR-LF (0x0D 0x0A). RTU frames are delimited by 3.5 character times of silence.
  • Encoding: ASCII encodes every byte as two printable hex characters (1-9, A-F). RTU uses 8-bit binary with 11-bit frames.
  • Error check: ASCII uses an 8-bit Longitudinal Redundancy Check (LRC) computed in 2's complement. RTU uses a 16-bit Cyclical Redundancy Check (CRC-16).

These differences mean the CP 341 must be told the format expected by the master. Mismatched framing produces no slave response and no exception frame, which is the most common commissioning symptom reported on the topic.

Distinguishing the License Dongles

Siemens ships CP 341 drivers with hardware-bound activation. The most commonly confused pair is:

Order Number Drives Notes
6ES7870-1AB01-0YA1 Modbus RTU Slave 8-bit binary, CRC-16, 3.5-char inter-frame gap
Modbus ASCII Slave dongle (separate order) Modbus ASCII Slave 7-bit ASCII, LRC, ':' / CR-LF framing

The two licenses are not interchangeable. To find the current order number for the Modbus ASCII Slave dongle, refer to the Siemens support article ID 25356060, which lists the current license matrix and download package contents.

Field check: After installation, the license status can be confirmed in the Parameter Assignment Tool. Navigate to the CP 341's protocol tab and read the "License" line. A state of "Permanent" with the matching driver name confirms the dongle is recognized. A state of "Missing" or "Evaluation" indicates the wrong dongle is mounted or the 14-day trial period has expired.

Installing the Modbus ASCII Slave Driver in STEP 7

Follow the steps below to obtain and install the driver on the engineering PC:

  1. Open a browser and navigate to Siemens Industry Online Support.
  2. Search for article ID 25356060 ("CP 341 Modbus master / slave driver") or enter "CP341 Modbus ASCII" in the search bar.
  3. Download the ZIP archive Modbus_341.zip to a local directory.
  4. Extract the archive. The contents include a directory named Modbus_ASCII_Slave with files mod_ascii_sl.fmd, FB blocks, and a readme.
  5. Close all running instances of STEP 7 and SIMATIC Manager.
  6. Run the included setup executable (or manually copy the FMD file to %ProgramFiles%\Siemens\Automation\CP341\Driver).
  7. Re-launch STEP 7 / SIMATIC Manager. The "Modbus ASCII Slave" entry will now be available in the Parameter Assignment Tool's protocol selector for the CP 341.

If the entry remains absent, the FMD file was not registered with the Parameter Assignment Tool. Re-run the setup with administrator rights and confirm that the file cp341pa.exe (the parameter assignment tool) loads the new FMD at start-up.

Hardware Configuration in HW Config

Once the driver is registered, the CP 341 must be added to the S7-300 project:

  1. Open the S7 project in SIMATIC Manager and double-click Hardware.
  2. From the hardware catalog, browse to SIMATIC 300 > CP-300 > Point-to-Point > CP 341.
  3. Select the variant matching the physical module: 6ES7 341-1AH02-0AE0 (RS-232C) or 6ES7 341-1CH02-0AE0 (RS-422/485).
  4. Drag the CP 341 into a free slot of the S7-300 rack. Slots 4-11 are valid on a standard 18-slot rack.
  5. Double-click the CP 341 to open the Properties - CP 341 dialog and assign it within the same subnet as the CPU (or any logical address, the CP supports direct backplane access).
  6. Click Parameters... to launch the dedicated Parameter Assignment Tool.

Configuring the Modbus ASCII Slave Protocol

The Parameter Assignment Tool is a separate executable (cp341pa.exe) that builds the protocol database. Inside the tool:

  1. Select the Protocol tab. The selector now shows the entries: ASCII, 3964R, Modbus Master, Modbus Slave, Modbus ASCII Slave, and RK 512.
  2. Choose Modbus ASCII Slave.
  3. Configure the physical layer on the Interface tab:
    • Baud rate: 1200, 2400, 4800, 9600 (default), or 19200 bit/s
    • Data bits: 7 (fixed for Modbus ASCII)
    • Stop bits: 1 or 2 (master must match)
    • Parity: Even, Odd, or None (master must match)
    • Half-duplex / full-duplex: matches the wiring scheme
  4. Switch to the Modbus Slave tab.
  5. Enter the Slave Address in decimal (range 1-247, default 1). This is the address the master uses to address the CP 341. Address 0 is the Modbus broadcast address and is reserved.
  6. Map the data areas. Each Modbus function code is bound to a contiguous data block region. The default mapping is:
    • Function 01/05/15 → Output Coils (DB or process image bit area)
    • Function 02 → Input Coils (DB or input area)
    • Function 03/06/16 → Holding Registers (DB or MW area)
    • Function 04 → Input Registers (DB or PEW area)
  7. Enable Diagnostic Interrupts if the application requires OB82 / OB87 to be triggered on comms errors.
  8. Click OK to save the database, then Download to Target in HW Config.
Address range note: Modbus register addresses are 0-based in the protocol layer, but the CP 341 parameter tool accepts the values you will load in the application. The mapping function in the tool offsets the user-visible DB-word address by 1 when forming the Modbus PDU. Always verify with a Modbus master poll (e.g. function 03 on register 0) before assuming the data block word 0 is register 1.

Where the Slave Address Is Stored

The slave address is a single parameter inside the protocol database created by the Parameter Assignment Tool. It is not stored in the user program and not in a function block input. To change the slave address after initial commissioning:

  1. Open HW Config and double-click the CP 341.
  2. Click Parameters... to launch the Parameter Assignment Tool.
  3. On the Modbus Slave tab, change the address field.
  4. Click OK twice and re-download the hardware configuration to the S7-300 station.

The new address becomes effective on the next CP 341 start-up (cold restart) or when the parameter assignment is reloaded via the diagnostic interface. Hot-swapping the slave address at runtime is not supported on the CP 341.

Wiring and Physical Layer

Pin assignments for the CP 341 front connector follow the Siemens standard:

Signal RS-232C Pin (DB-9) RS-485 Pin (DB-9 / terminal)
TxD / T(R) 2 3 (R/T+ on terminal block)
RxD / R(T) 3 8 (R/T- on terminal block)
RTS 4 —
CTS 5 —
Signal GND 5 5 (GND on terminal block)
Shield Housing Housing

For RS-485 multi-drop Modbus networks, terminate the bus at both ends with 120 Ω resistors, set the CP 341 to "Half-duplex (RS-485 2-wire)", and enable the bus-termination DIP switch on the front of the CP 341 if the module is the end node. Always tie the cable shield to ground at one end only to avoid ground loops.

Programming the Slave Interface

After the protocol database is downloaded, the user program exchanges process data with the CP 341 through two function blocks supplied with the driver:

  • FB 7 ("P_RCV_RK") — receives data from the CP 341 (Modbus response frames and unsolicited event frames)
  • FB 8 ("P_SND_RK") — sends data to the CP 341 (rarely used in pure slave mode, but required during startup to initialize the CP 341)

Typical call in OB 1 (STL syntax) for the Modbus ASCII Slave driver:

CALL FB 7, DB 107
  EN  := TRUE
  REQ :=    // not used in slave
  R   := FALSE
  LADDR:= 256               // logical base address of CP 341
  DB_NO:= 200               // data block containing the protocol data
  DBB_NO:= 0                // start byte within DB
  LEN  := 100               // length of process data in bytes
  NDR  := M 100.0           // new data received
  ERROR:= M 100.1           // receive error
  STATUS:= MW 102           // status / error code

The driver's instance DB (DB 107 in the example) is generated automatically when the FBs are inserted into the project from the Modbus ASCII Slave library. The data block DB 200 holds the Modbus process image: holding registers, input registers, and coils. Tie the offset of the data block to the offsets configured in the Parameter Assignment Tool.

Commissioning and Verification

Run the following checks after download:

  1. Open CP 341 Online Diagnostics from STEP 7 (right-click CP 341 → Module Information). Confirm:
    • Module state: OK
    • Protocol loaded: Modbus ASCII Slave
    • License: Permanent
    • Slave address: matches the configured value
  2. From a Modbus master tool (e.g. Modbus Poll, CAS Modbus Scanner, or a WinCC channel), issue function code 03 starting at register 0 with a length of 10 words. The CP 341 should return the contents of the configured DB.
  3. Toggle a coil via function code 05 and verify that the corresponding bit in the DB changes.
  4. Force a deliberate parity error on the master side. The CP 341 should return a Modbus exception 02 (Illegal Data Address) or, if the LRC fails, exception 08 (LRC Error) and increment the diagnostic counter.

Troubleshooting Matrix

Symptom Likely Cause Corrective Action
Master times out, no response from CP 341 Wrong license dongle (RTU dongle mounted for ASCII driver) Verify license in Parameter Assignment Tool; install the Modbus ASCII Slave dongle
Protocol selector does not list "Modbus ASCII Slave" Driver FMD not installed Reinstall from the article 25356060 download package
CP 341 returns exception 02 (Illegal Data Address) DB offset outside configured data area Check the Modbus tab mapping in the Parameter Assignment Tool
Frames are visible on the wire but no slave response Baud rate, parity, or data bits mismatched Match master parameters to CP 341 settings; ASCII requires 7 data bits
License error LED on CP 341 front panel Dongle missing, wrong dongle, or license not transferred to ALM Transfer license with Automation License Manager; reseat the dongle
Data values returned are off by one word Modbus 0-based vs. application 1-based addressing Adjust the application data block offset by 1 or re-map in the parameter tool
Intermittent response, frames truncated RS-485 termination missing or excessive bus length Add 120 Ω at both ends; keep cable under 1200 m at 9600 bit/s
SF LED on after parameter download Diagnostic interrupt active, no OB82 loaded Load OB82 in the CPU, or disable diagnostic interrupts in the parameter tool

Status and Error Codes Returned by the Driver

The status word returned on the LEN / STATUS output of FB 7 and FB 8 carries driver-specific codes. The most relevant for the ASCII slave are:

STATUS (hex) Meaning Recommended Action
0000 No error —
0x7001 Receive in progress Wait for NDR or ERROR
0x7002 Send in progress Wait for DONE or ERROR
0x8081 Receive buffer overflow Increase LEN or slow the master poll
0x8085 Framing error (parity, stop bit, or LRC) Check master / slave parameter match
0x8090 License missing or invalid Verify Modbus ASCII Slave dongle installed
0x80A1 Function code not supported Verify the FC is in the supported list (01-16 except 09, 10, 13, 14)

Differences From CP 441 and ET 200S 1SI

The CP 341 shares much of its driver architecture with the higher-end CP 441 and the distributed ET 200S 1SI serial interface module. Engineers migrating projects between these should note:

  • The CP 441 supports a different set of FBs (FB 9-12) and uses a separate order-number matrix for licenses.
  • The ET 200S 1SI (6ES7138-4DF01-0AB0) accepts the same Modbus ASCII Slave FMD but assigns the slave address through the GSD file configuration, not the classic parameter tool.
  • Function block call signatures differ. Code that targets the CP 341 cannot be reused verbatim on the 1SI without adjustment of LADDR, LEN, and DB number fields.

Frequently Asked Questions

Can the Modbus RTU slave dongle 6ES7870-1AB01-0YA1 be used with the Modbus ASCII slave driver?

No. The RTU slave dongle 6ES7870-1AB01-0YA1 only enables the Modbus RTU Slave driver. The Modbus ASCII Slave driver requires its own dedicated license dongle, and the license status can be verified in the CP 341 Parameter Assignment Tool under the Protocol tab.

Where is the Modbus ASCII slave address configured on the CP 341?

The slave address (1-247) is set inside the CP 341 Parameter Assignment Tool on the Modbus Slave tab, not in the user program. After changing the address, re-download the hardware configuration and restart the CP 341 for the new value to take effect.

Why does the CP 341 not respond to a Modbus ASCII master poll?

Most "no response" issues are caused by a missing or wrong license dongle, mismatched serial parameters (ASCII requires 7 data bits), or an unloaded driver FMD. Verify the license status, ensure the master uses 7E1 or 7N2 framing, and confirm the Modbus ASCII Slave driver appears in the parameter tool's protocol selector.

Which function codes does the CP 341 Modbus ASCII slave support?

The driver supports function codes 01, 02, 03, 04, 05, 06, 07, 08, 11, 12, 15, and 16. Function code 08 sub-code 00 (return query) is supported for loopback testing. Function codes 09, 10, 13, and 14 are not implemented and will return exception code 01 (Illegal Function).

What is the maximum Modbus RTU/ASCII frame size on the CP 341?

The Modbus ASCII slave driver accepts PDUs up to 255 bytes of payload, limited by the LRC computation and the receive buffer of 1024 bytes per FB 7 call. For typical register polls (function 03 with up to 125 registers per request) the CP 341 is more than capable. For bulk coil access (function 15) keep the bit count at 1968 bits per request as recommended by the Modbus-IDA specification.

Back to blog