Connecting an RS485 Temperature Controller to Siemens S7-313C-2DP
This technical reference explains the physical-layer and protocol-layer constraints that prevent a Siemens SIMATIC S7-313C-2DP CPU from reading an RS-485 ASCII temperature controller through its on-board MPI/Profibus port, and it documents the three viable integration paths using Siemens communications processors. The analysis is built around the CPU 31xC and CPU 31x Technical Specifications manual (order number 6ES7398-8FA10-8BA0) and the field-recommended CP 340 / CP 341 communications modules.
1. The Core Problem: RS-485 Is Not a Protocol
Engineers who encounter the question "can I use the MPI/Profibus port on my S7-313C-2DP as an RS-485 port?" almost always conflate two different layers of the ISO/OSI model:
- Physical layer (Layer 1): RS-485 specifies the electrical characteristics of a differential balanced line — driver output voltage, common-mode range, termination, and connector pinout. It does not define byte framing, addressing, or message structure.
- Data-link / application layer (Layers 2-7): This is where Profibus DP, Modbus RTU, ASCII, and vendor-specific protocols live. A cable that meets RS-485 simply carries bits; it does not guarantee that two devices on the bus can talk.
Because of this layering, the answer to the original question is: no, the MPI/Profibus port cannot be repurposed as a generic RS-485 ASCII port. The MPI/Profibus interface is a fixed-function ASIC that implements Siemens-proprietary MPI framing on top of Profibus DP-V0/V1 token-passing. It will not emit a free-form ASCII frame regardless of how the cable is wired.
2. S7-313C-2DP Hardware Architecture
The S7-313C-2DP (order number 6ES7 313-6CE00-0AB0, and successor variants 6ES7 313-6CG04-0AB0) is a compact CPU in the SIMATIC S7-300 family. Its integrated interfaces, per the CPU 31xC Technical Specifications, are:
| Interface | Function | Connector | Notes |
|---|---|---|---|
| X1 (MPI / PROFIBUS-DP) | MPI master/slave, DP-V0/V1 master | 9-pin sub-D female, RS-485 physical | Fixed protocol; not programmable as raw RS-485 |
| X2 (PtP / MPI) on -2DP variants | Point-to-point or second MPI | 9-pin sub-D | CPU 313C-2DP has only X1; PtP is on -2PtP variants |
| Onboard DI16 / DO16 / AI5 / AO2 | Process I/O | Front connector | Not relevant for serial comms |
| Technology counters | 3 channels, up to 30 kHz | Front connector | Not relevant for serial comms |
Key takeaway: the 9-pin sub-D connector at X1 is physically an RS-485 transceiver, but logically it is a Profibus ASIC. A user cannot load a different firmware image or change the framing engine to emit ASCII characters. This is the architectural reason the MPI/Profibus port cannot be a drop-in RS-485 terminal.
3. Why the On-Board Port Cannot Run ASCII
Three hard constraints prevent the on-board port from being used as a generic serial port:
- Protocol lockdown. The Profibus controller inside the CPU is a dedicated SPC3 / ASIC family device. It only generates Profibus telegrams (SD, DA, SA, FC, FCS, ED). It has no mode for free-running UART with start/stop bits.
- Bus arbitration. MPI/Profibus is a token-passing multi-drop bus. Devices share the medium and only the active token holder may transmit. An ASCII device that simply drops a frame on the line would corrupt token rotation.
- Timing and baud-rate lock. The MPI/Profibus port negotiates baud rates of 9.6 kbit/s up to 12 Mbit/s in discrete steps, with strict inter-frame timing. ASCII controllers typically use 9600/19200/38400 8N1 with 3-5 character inter-character timeouts that are incompatible with Profibus slot time.
4. The Three Viable Integration Paths
Once the on-board port is excluded, the engineering decision becomes: which Siemens communications processor matches the temperature controller's protocol?
4.1 Path A — RS-485 ASCII / 3964R via CP 340 or CP 341
If the temperature controller speaks a plain ASCII protocol (often documented in the controller manual as "Modbus ASCII" or a vendor-specific command set with start/stop characters and a CR/LF terminator), use a point-to-point module:
-
CP 340 — order number
6ES7340-1CH02-0AE0— single channel, ASCII and 3964R drivers in firmware, parameterisable up to 19.2 kbit/s on the RS-422/RS-485 variant. -
CP 341 — order number
6ES7341-1CH02-0AE0— single channel, supports higher baud rates (up to 76.8 kbit/s loadable drivers), loadable Modbus master, Modbus slave, and 3964R / ASCII drivers as separately orderable license dongles.
Both modules plug into the S7-300 backplane, are configured with the included "PtP Param" or "CP 341" parameter assignment tool in STEP 7 / TIA Portal, and exchange data with the CPU through the I/O area (PI/PQ) or via SFB/SFC calls. A typical ASCII loadable driver on CP 341 is order number 6ES7870-1AC01-0YA0 (Modbus master RTU/ASCII 2008 edition).
4.2 Path B — Modbus RTU / Modbus ASCII via CP 341 with Modbus Master
If the controller documents Modbus RTU over RS-485 (very common for industrial temperature controllers from Watlow, Omron E5CC, Delta DTB, Autonics TK, Honeywell DC1000, and similar), the CP 341 with the loadable Modbus master driver is the standard solution. The RS-485 variant of the CP 341 is 6ES7341-1CH02-0AE0; the corresponding loadable driver for Modbus master (RTU/ASCII) is 6ES7870-1AC01-0YA0.
Important hardware detail: the CP 341 RS-485 variant is half-duplex 2-wire. The controller must be wired to the A/A' and B/B' lines only — never to the RTS pin (which is for RS-232 flow control). For multi-drop Modbus RTU daisy-chains, bias resistors (typically 620 Ω to +5 V on A and 620 Ω to GND on B) are required if the controller does not provide them internally.
4.3 Path C — Profibus DP slave (only if the controller is genuinely Profibus-DP capable)
Some temperature controllers do have a true Profibus-DP slave option. In this case the on-board MPI/Profibus port can be used, but only because the controller is implementing the full Profibus protocol stack internally. The integration steps are:
- Obtain the controller manufacturer's GSD file (typically a *.gsd or *.gsg file).
- Copy the GSD file into the STEP 7 / TIA Portal hardware catalogue directory.
- Add the controller as a DP slave on the S7-313C-2DP's DP master port (X1).
- Configure the I/O slot mapping. Profibus slaves expose cyclic I/O; the temperature controller's process values (PV, setpoint, output) typically map to a few input words and a couple of output words.
- Assign a unique Profibus address on the controller's DIP switches or display menu (1-125, default 1 is not allowed for slaves if the master is at 2; verify in the controller manual).
The on-board port can support up to 32 DP slaves at 9.6 kbit/s, fewer at higher baud rates; refer to the segment repeater and segment current budget in the S7-300 manual.
5. Decision Matrix: Which Module Do I Need?
| Controller protocol | CP 340 | CP 341 + ASCII | CP 341 + Modbus | On-board X1 (DP) |
|---|---|---|---|---|
| ASCII (vendor-specific, no Modbus) | Yes (default driver) | Yes (default driver) | Yes | No |
| Modbus RTU over RS-485 | No | No (ASCII ≠ RTU) | Yes (loadable driver) | No |
| Modbus ASCII over RS-485 | Possible (manual frame building) | Yes (default driver) | Yes | No |
| 3964R (Siemens legacy) | Yes (default driver) | Yes (default driver) | Yes | No |
| Profibus DP slave | No | No | No | Yes (X1 as DP master) |
For an unknown temperature controller, the first verification step is to read the protocol chapter of its datasheet. Look for the words "Modbus RTU", "Modbus ASCII", "Profibus", "Profinet", or "ASCII protocol". The presence of an RS-485 connector alone is not diagnostic.
6. Step-by-Step: Connecting an ASCII RS-485 Controller via CP 341
The following procedure assumes a CP 341 with RS-422/RS-485 interface, order number 6ES7341-1CH02-0AE0, and a controller speaking ASCII frames terminated with CR/LF at 9600 8-N-1.
6.1 Prerequisites
- STEP 7 V5.5 / TIA Portal V15 or later installed.
- CP 341 parameter assignment tool (PtP-Param for STEP 7, "PtP interface" for TIA Portal).
- Loadable ASCII driver on the CP 341: bundled by default; no separate license required for plain ASCII.
- Shielded twisted-pair cable, characteristic impedance 100-120 Ω, terminated at both ends with 220 Ω in series with 120 Ω (per RS-485 / Profibus segment design).
6.2 Wiring
- Strip the back of the S7-300 rail to expose the CP 341's sub-D female connector on its front face.
- Connect controller terminal A' (or T/R+) to CP 341 pin 11 (T/R(A)+).
- Connect controller terminal B' (or T/R-) to CP 341 pin 9 (T/R(B)-).
- Connect the cable shield to the controller's ground terminal and to the CP 341's shield clamp at the sub-D hood. Ground the shield at one end only to avoid ground loops; for noisy industrial environments, ground both ends through a 100 nF ceramic capacitor.
- Enable termination on the CP 341 if it is the only device on the segment; otherwise place the termination at the far end of the bus. The CP 341 has an internal switch that must be physically set to ON when the module sits at a line end.
6.3 STEP 7 Configuration
- Open the SIMATIC Manager and the S7-300 station that contains the CPU.
- Insert the CP 341 from the hardware catalogue (SIMATIC 300 / CP-300 / PtP / CP 341 RS422/485).
- Double-click the CP 341 to open the parameter assignment tool.
- Set the protocol to ASCII, baud 9600, 8 data bits, no parity, 1 stop bit, XON/XOFF flow control disabled.
- Set the receive buffer and transmit buffer sizes; the ASCII driver supports up to 1024 bytes per direction.
- Set the end-of-frame delimiter to "on receipt of CR/LF" or "on character timeout = 4 ms".
- Compile and download the configuration.
6.4 STEP 7 Program — Reading a Temperature Setpoint
The CP 341 communicates with the CPU through two function blocks:
-
SFB 60— Send: triggered to push a request frame to the controller. -
SFB 61— Receive: triggered to fetch a frame that the CP 341 has already buffered.
For a vendor-specific ASCII protocol where the request is the byte sequence SP?\r\n and the response is SP=123.4\r\n, the structured text below calls SFB 60 with a static frame and uses SFB 61 to read the reply into a 32-byte buffer.
// S7-313C + CP 341, ASCII 9600 8N1
DATA_BLOCK DB100
STRUCT
reqFrame : ARRAY[0..7] OF BYTE := B#16#53, B#16#50, B#16#3F, B#16#0D, B#16#0A, 0, 0, 0; // "SP?\r\n" + pad
rspBuffer : ARRAY[0..63] OF BYTE;
rspLen : INT;
setpoint : REAL; // parsed from rspBuffer
ok : BOOL;
END_STRUCT
END_DATA_BLOCK
FUNCTION_BLOCK FB10_CP341_Ascii
VAR
SFCDone : BOOL;
SFCErr : WORD;
SFCStat : WORD;
rxLen : INT;
i : INT;
numStr : STRING[16];
END_VAR
BEGIN
// Trigger one transaction per scan if no transaction in flight
IF NOT SFCDone AND NOT SFCStat=16#8180 THEN
SFB60_IDB := 100; // instance DB
REQ := TRUE;
R := FALSE;
LADDR := W#16#100; // CP 341 base address (from HW config)
SD_1 := P#DB100.DBX0.0 BYTE 4; // send 4 bytes "SP?\r"
LEN := 4;
END_IF;
SFB60_DB(SFB60_instance);
// Poll for response
SFB61_DB(REQ := NOT SFCDone,
LADDR := W#16#100,
NDR := ok,
ERROR := SFCErr,
STATUS := SFCStat,
RD_1 := P#DB100.DBX8.0 BYTE 32,
LEN := rxLen);
IF ok AND rxLen > 4 THEN
// Crude parse: find '=' and copy numeric part
FOR i := 0 TO rxLen - 1 DO
IF DB100.rspBuffer[i] = B#16#3D THEN // '='
numStr := '';
WHILE (i + 1) < rxLen AND DB100.rspBuffer[i+1] <> B#16#0D DO
numStr := CONCAT(numStr, CHAR(DB100.rspBuffer[i+1]));
i := i + 1;
END_WHILE;
DB100.setpoint := STRING_TO_REAL(numStr);
END_IF;
END_FOR;
END_IF;
END_FUNCTION_BLOCK
This is illustrative — production code should add timeout handling, retry counters, frame-format checksums, and a watchdog that toggles the CP 341's RUN/STOP equivalent if the controller is silent for more than 5 seconds.
7. Step-by-Step: Modbus RTU via CP 341
For a Modbus-RTU temperature controller, the procedure is similar but the loadable Modbus master driver handles the CRC16 and inter-frame silence automatically. Required materials:
- CP 341 RS-422/RS-485 module:
6ES7341-1CH02-0AE0. - Modbus master loadable driver:
6ES7870-1AC01-0YA0(RTU/ASCII, 2008 edition). - CP 341 parameter assignment tool with the Modbus master profile selected.
Configuration in STEP 7:
- In the CP 341 parameter tool, set the protocol to "Modbus master" instead of "ASCII".
- Set the slave address of the temperature controller (1-247).
- Set the request: function code 03 (Read Holding Registers), starting address, register count. Many temperature controllers expose PV at holding register 0x0000 and setpoint at 0x0001.
- Set the response timeout (typically 1000 ms for 9600 baud over a short RS-485 bus).
- Compile and download.
Programmatic access uses SFB 60 / SFB 61 as before. The CP 341 stores the Modbus response bytes in the receive buffer; the application strips the slave address, function code, byte count, register data, and CRC16 to extract the actual values.
8. Diagnostics and Verification
After commissioning, validate each layer independently:
- Layer 1 — electrical: Measure A-to-B differential voltage with a multimeter. Idle line should be ≥ 200 mV (logical 1). Transmit bursts should toggle polarity cleanly. A stuck voltage at 0 V or 5 V indicates missing bias resistors.
- Layer 1 — termination: With the bus quiet, measure resistance across A and B at the far end. Expect ~120 Ω (one terminator on) or ~60 Ω (two terminators on, one at each end). Anything close to 0 Ω indicates a short.
- Layer 2 — frame integrity: Use a portable RS-485 line monitor or a USB-to-RS-485 dongle plus a free analyser (such as the on-board diagnostic in the CP 341 parameter tool) to capture one transaction. Verify the request matches the controller manual and the response is the documented length.
- Layer 7 — value sanity: Compare the parsed setpoint or process variable to the controller's local display. They should match to within the controller's resolution (typically ±0.1 °C).
-
Layer 7 — long-term stability: Run for 24 hours; check
SFCErrin the FB. A typical clean installation reports fewer than one retry per 1000 transactions.
9. Troubleshooting Matrix
| Symptom | Likely cause | Remedy |
|---|---|---|
CP 341 SF red, STATUS = 16#8183 |
Hardware fault — wrong module type or no loadable driver | Verify order number; reinstall loadable driver dongle |
No reply from controller, no NDR from SFB 61 |
Polarity swap on A/B or missing bias resistors | Swap T/R(A)+ and T/R(B)- leads; install 620 Ω bias pair at the master end |
| Garbled characters in response | Baud rate / parity mismatch | Check controller's serial settings; confirm 8-N-1 vs 8-E-1 |
CP 341 reports STATUS = 16#8180 (busy) |
Previous transaction still in flight | Trigger SFB 60 only when idle; add a 100 ms delay between calls |
| Frame received but CRC16 mismatch (Modbus RTU) | Inter-character timing violation > 1.5 char times | Shorten cable, lower baud rate, or switch to ASCII protocol |
| Intermittent timeouts after hours of operation | Ground loop or EMI | Use shielded cable, ground shield at one end, add 100 nF Y-cap to the line |
| Controller reports "communication error" on its display | Slave address collision or wrong function code | Confirm slave address in the controller menu matches the master config |
10. Common Pitfalls and Field-Notes
Engineers who have completed the integration report a recurring set of issues. The most frequent are:
-
Buying a CP 340 expecting Modbus RTU. The CP 340 ASCII driver does not generate Modbus RTU framing (the silent interval and CRC16 are not present). For Modbus RTU, use CP 341 with the loadable Modbus master driver (
6ES7870-1AC01-0YA0). - Forgetting the loadable driver license. The CP 341 ships with a default driver set that includes ASCII and 3964R but not Modbus. The Modbus driver is a separate licence, supplied on a floppy/USB stick and installed via the parameter tool.
- Confusing RS-422 and RS-485 pinout. The CP 341 RS-422/RS-485 variant has the same sub-D connector for both modes. RS-485 2-wire mode uses only pins 9 (T/R(B)-) and 11 (T/R(A)+). Pins 4, 7, 8, 12 (T(A)+, T(B)-, R(A)+, R(B)-) are RS-422 only and must be left unconnected.
- Over-driving the bus with bias resistors at every node. Only one pair of bias resistors per segment. Multiple bias pairs load the line and reduce noise margin.
- Exceeding the 32-node RS-485 limit. The standard allows up to 32 unit loads on a single segment. Some temperature controllers present a 1/8 UL (e.g. Maxim and TI transceivers) which means you can place up to 256 on paper, but bus capacitance and stub length will degrade the signal at high baud rates. A segment repeater (e.g. 6ES7 972-0AA02-0XA0) splits the bus into two physical segments when you exceed 32 nodes.
- Wiring the shield at both ends without a capacitor. A solid low-impedance ground loop will inject 50/60 Hz hum into the data signal. The accepted industrial practice is shield grounded at one end; if the cable run exceeds 30 m, ground both ends through 100 nF / 250 V Y2-class capacitors to break the DC loop while keeping the AC bond.
11. Sourcing the Correct CP 341 Order Numbers
For predictable commissioning, the standard order codes are:
- CP 341 RS-232C:
6ES7341-1AH02-0AE0— for point-to-point ASCII to a device with a true RS-232 port. - CP 341 RS-422/485:
6ES7341-1CH02-0AE0— for the typical industrial temperature controller use case. - CP 341 Modbus master RTU/ASCII loadable driver, 2008 edition:
6ES7870-1AC01-0YA0. - CP 341 Modbus slave loadable driver:
6ES7870-1AB01-0YA0(used when the S7-300 is a Modbus slave to a third-party master).
These codes are stable across STEP 7 V5.x and TIA Portal V13 and later. Always verify against the latest Siemens catalog before placing the order, because Siemens occasionally introduces firmware revisions that bundle the loadable driver in newer -0AE0 suffixes.
12. Summary and Field Recommendation
For a typical industrial scenario — a temperature controller with an RS-485 port speaking ASCII or Modbus RTU on a 9600/19200 baud bus, connected to a SIMATIC S7-313C-2DP CPU — the recommended integration is:
- Confirm the controller's protocol by reading its datasheet (look for "Modbus RTU", "Modbus ASCII", or a vendor-specific ASCII command set).
- Select a CP 341 RS-422/485 module (
6ES7341-1CH02-0AE0) and plug it into the S7-300 backplane next to the CPU. - For ASCII: use the default driver. For Modbus RTU/ASCII: install the loadable driver
6ES7870-1AC01-0YA0. - Wire A/A' and B/B' only. Do not use the RS-422 pins. Terminate at both ends if the CP 341 sits at one end of the segment.
- Configure with the CP 341 parameter assignment tool in STEP 7 / TIA Portal; download the configuration.
- Use
SFB 60 / SFB 61in the user program to send requests and receive responses; parse the data into REAL or INT tags and route to the rest of the application.
The MPI/Profibus port on the S7-313C-2DP remains available in parallel for HMI, programming, or Profibus-DP slave devices. It is not a substitute for a dedicated point-to-point module when the field device speaks anything other than Profibus.
Can I use the on-board MPI/Profibus port of an S7-313C-2DP as a generic RS-485 port to read an ASCII temperature controller?
No. The on-board X1 connector is a Profibus-DP / MPI ASIC and will only emit Profibus telegrams. It cannot be reprogrammed to send or receive free-running ASCII frames. Use a CP 340 (6ES7340-1CH02-0AE0) or CP 341 (6ES7341-1CH02-0AE0) for ASCII / 3964R, or a CP 341 with the loadable Modbus master driver (6ES7870-1AC01-0YA0) for Modbus RTU/ASCII.
What is the difference between RS-485, Modbus, and Profibus?
RS-485 is a physical-layer standard defining the electrical characteristics of a differential line. Modbus is a data-link / application protocol that can ride on RS-485 (RTU) or RS-232 (ASCII). Profibus is an entirely different protocol stack with its own framing, token passing, and master/slave arbitration, also on RS-485 physical media. A device that "has RS-485" may speak Modbus, Profibus, or a vendor-specific protocol; the connector alone does not reveal which.
My temperature controller has an RS-485 port. How do I confirm it is Modbus RTU versus vendor-specific ASCII?
Read the controller's protocol chapter and look for one of the following: the function code table 01/02/03/04/05/06/0F/10 indicates Modbus; a defined command set with explicit ASCII strings (for example SP?\r\n or READ PV\r\n) indicates a vendor-specific ASCII protocol. Some controllers allow you to select between Modbus RTU, Modbus ASCII, and a vendor protocol from the front panel.
Which order numbers do I need for a Modbus RTU connection to an RS-485 temperature controller?
Order a CP 341 with RS-422/485 interface (6ES7341-1CH02-0AE0) and the loadable Modbus master driver, 2008 edition (6ES7870-1AC01-0YA0). The CP 340 (6ES7340-1CH02-0AE0) does not support Modbus RTU; it is suitable only for ASCII and 3964R.
How do I bias and terminate an RS-485 segment with a CP 341?
Place 120 Ω termination resistors at the two physical ends of the segment, between T/R(A)+ and T/R(B)-. If the controller does not provide internal failsafe bias, add a single pair of bias resistors (620 Ω to +5 V on A and 620 Ω to GND on B) at the master end. Only one bias pair is allowed per segment. Ground the cable shield at one end; for runs above 30 m, ground both ends through 100 nF Y2 capacitors.