Connecting Siemens MP277 HMI to Omron CQM1 via RS232 Hostlink

David Krause13 min read
HMI / SCADASiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Replacing a legacy desktop HMI with a Siemens SIMATIC MP277 multi-panel while keeping an installed Omron SYSMAC CQM1 PLC requires a properly configured RS232 link running the Omron SYSMAC Way (Hostlink/Multilink) protocol. The Siemens HMI acts as the master on a serial point-to-point or RS422 multi-drop network. WinCC flexible 2008 SP3 and later releases the MP277 for direct SYSMAC Way communication to Omron controllers of the SYSMAC C, SYSMAC CV, SYSMAC CS1, SYSMAC alpha, and CP series, provided the CQM1 CPU is not in the excluded list.

This reference covers the CQM1-CPU45-V (and compatible CQM1-CPU4x variants), the recommended RS232 cable wiring between the MP277 sub-D male and the CQM1 peripheral port, the correct serial parameters (9600 7E2 baseline, 19200 7E2 high speed), the WinCC flexible connection editor configuration, the CQM1 PLC Setup word that must be changed to free Channel 1 from remote ladder transfer, and a verification procedure that confirms end-to-end tag polling before commissioning.

Compatibility Matrix: MP277 to Omron CQM1 CPUs

Siemens AG tested and released Hostlink/Multilink communication for the controllers in the table below. The CQM1 family is partially supported: every CQM1 CPU except the CQM1-CPU11 and CQM1-CPU21 (which lack the full Hostlink frame set) is released.

Omron PLC Series Released CPU Types Excluded CPU Types Physical Layer
SYSMAC C (CQM1) CQM1-CPU41/42/43/44/45 (all -EV / -V variants) CQM1-CPU11, CQM1-CPU21 RS232 to peripheral port, RS422 multidrop via adapter
SYSMAC CV CV500 / CV1000 / CV2000 / CVM1 None RS232 / RS422
SYSMAC CS1 CS1G / CS1H / CS1D None RS232 / RS422
SYSMAC alpha AL-*** (all) None RS232 / RS422
CP series CP1E / CP1L / CP1H None (toolbus variants require mode change) RS232 / RS422 / RS485
Critical: The CQM1-CPU11 and CQM1-CPU21 implement a reduced Hostlink command subset. The MP277 will fail to read IR/SR/HR areas and will timeout on any C-mode command. Always verify the CPU suffix before commissioning.

Identifying the CQM1 CPU Model

Confirm the exact CPU type before wiring. CQM1 modules carry a four-line nameplate on the right-hand side of the unit. For the MP277 ↔ Hostlink path the device must be a CPU4x:

  1. Power the rack and open the CQM1 front cover.
  2. Read the model code printed above the battery holder. Typical strings: CQM1-CPU45-EV1, CQM1-CPU45-V1, CQM1-CPU44-EV1.
  3. Cross-check against the Omron CQM1 Operation Manual (W227-E1) part number list. The -EV1 suffix denotes the enhanced instruction set including floating point, the -V1 suffix denotes a value-line variant with reduced features.
  4. If the label reads CPU11 or CPU21 the MP277 cannot establish Hostlink. Replace the CPU or use an Omron CP1L with a serial option board as an alternative.

Hardware: Physical RS232 Connection

The MP277 8-inch and 10-inch variants expose a single 9-pin sub-D male (IF1B) labelled RS422/RS485 on the rear. For Hostlink the port is wired as RS232 using the standard Siemens cable 6XV1440-1K... series or a hand-built crossover conforming to the pinout below.

Siemens MP277 (IF1B) 9-pin sub-D male, RS232 mode 2 TXD 3 RXD 5 GND Omron CQM1 peripheral port 9-pin sub-D male, RS232 2 RXD 3 TXD 5 GND TXD ↔ RXD (crossover) RXD ↔ TXD (crossover) GND ↔ GND
MP277 IF1B pin Signal Direction (HMI→PLC) CQM1 peripheral port pin Signal
2 TXD (RD−) Out 2 SD (TXD)
3 RXD (RD+) In 3 RD (RXD)
5 SG (signal ground) — 5 SG
4 / 6 DTR / DSR (linked) — 4 / 6 RTS / CTS (linked)
7 / 8 RTS / CTS (linked) — 7 / 8 —
Shell Shield — Shell Shield (one end only)

Connect the shield to ground at one end only to avoid ground-loop noise. Maximum RS232 cable length at 9600 baud is 15 m per the EIA-232-F specification; at 19200 baud reduce to 7.5 m to keep the CQM1 peripheral port receiver within its 3 kΩ input impedance budget.

Protocol: SYSMAC Way Hostlink Frame Structure

Hostlink is a master/slave ASCII protocol on top of RS232 or RS422. The MP277 always originates the request; the CQM1 always replies. Every frame is bracketed by an STX/ETX pair, terminated with FCS (two-hex Frame Check Sum) and CR.

Request:  @ [unit-no] [header-2-chars] [text] FCS CR LF
Reply:    @ [unit-no] [header-2-chars] [text] FCS CR LF
           |   2 BCD   | RH/WR/RL/WL  |  cmd/data   |
FCS calc: XOR of every byte from @ through the last text byte, take low 8 bits, return ASCII hex.

Typical read command used by WinCC flexible to poll IR0 from a unit-00 CQM1:

Master → @00RR00000001 (FCS) CR
Slave  ← @00RR00 (FCS) CR           ← success, data block follows
Master → @00RD00000001 (FCS) CR    ← for DM area, RD command
Slave  ← @00RD1234 (FCS) CR        ← DM0000 = 0x1234
Header Function Operand Area CQM1 Range
RR IR / SR area read Bit / word I/O, internal relays, special relays IR000–IR243 (word), HR00–HR99, AR00–AR27, SR244–SR255
RL IR / SR area write Same as RR —
RD DM area read Data memory (16-bit words) DM0000–DM6143
WD DM area write DM —
RH HR area read Holding relays HR00–HR99
WH HR area write HR —
SC Status write (RUN/MON/PRG) — —
MF Error clear — —
KS Force set / reset Bit-level —

The unit number is BCD 00–31. The default CQM1 unit number is 00. For multidrop with multiple CQM1s, set each CPU to a unique unit number via DM6651 (channel 1 unit number, two BCD digits).

CQM1 Communication Port Setup (Channel 1)

The CQM1 peripheral port (Channel 1) has PLC Setup words DM6650 through DM6653 that control its Hostlink behaviour. Out of the box the port defaults to remote ladder transfer mode, which conflicts with the MP277 polling cycle. Channel 1 must be reconfigured for Hostlink master/slave with the HMI acting as the master.

PLC Setup Word Default Value Required Setting for MP277 Hostlink Meaning
DM6650 bits 00–07 00 hex 00 hex Port mode: 00 = Hostlink master/slave (HMI is master)
DM6650 bits 08–11 0 hex 0 hex Data bits: 0 = 7 bits, 1 = 8 bits (Hostlink mandates 7)
DM6650 bits 12 0 0 Stop bits: 0 = 2 stops, 1 = 1 stop (Hostlink mandates 2)
DM6650 bits 13 0 0 Parity: 0 = even, 1 = odd, 2 = none (Hostlink mandates even)
DM6650 bits 14–15 00 00 Baud: 00 = 9600, 01 = 300, 10 = 1200, 11 = 19200
DM6651 0000 0000 (or any two-BCD unit 00–31) Hostlink unit number, BCD
DM6652 0000 0000 CTS control: 0000 = always transmit (no flow control)
DM6653 0000 0000 Delay before response in 10 ms units (0–99). 0 = 0 ms recommended for HMI scan.
Critical: Before changing DM6650 set the CQM1 to PROGRAM mode using the mode key on the front panel, or write SC02 via Hostlink first. Writing DM6650 in RUN mode is permitted but the new mode becomes active only after a power cycle or after executing the STUP(237) instruction.

Procedure using Omron CX-Programmer or a handheld programmer:

  1. Connect the programming console to the CQM1 peripheral port (CX-Programmer can use the same port in Hostlink mode if you leave the existing laptop attached to a different port or temporarily disconnect the MP277).
  2. Open the PLC Setup and navigate to the Hostlink / Peripheral Port section.
  3. Set DM6650 to 0000 (Hostlink master/slave, 9600, 7E2, unit number follows).
  4. Set DM6651 to 0000 for a single PLC network, or a unique BCD value (e.g. 0001, 0002) for each additional node in an RS422 multidrop.
  5. Set DM6652 and DM6653 to 0000 for no RTS/CTS gating and minimum response delay.
  6. Transfer the setup to the PLC. Cycle power to the CQM1 to activate the new mode if CX-Programmer does not send the STUP(237) automatically.
  7. Verify with a HyperTerminal / PuTTY session: send @00RR0000000158*\r (where 58 is the FCS for that header) and confirm the CQM1 echoes the IR word 0000.

WinCC flexible 2008 HMI Configuration

After loading the project in WinCC flexible 2008 SP3 (or WinCC Comfort/Professional V11+ for migration), open the Connections editor and add a new connection with the parameters in the table below.

Field Value Notes
Name CQM1_Hostlink Free-form identifier
Communication driver Omron Hostlink/Multilink Listed under Omron SYSMAC in the driver catalogue
HMI device MP277 10" Touch Project must match the panel variant
Interface IF1B, RS232 MP277 IF1B operates as RS232 when set to RS232 mode (DIP switch on rear, position 1 = OFF)
Baud rate 9600 Use 19200 only after verifying signal integrity on long cables
Data bits / parity / stop 7 / even / 2 (7E2) Fixed by Hostlink specification
PLC unit number 0 Must match DM6651 BCD value
Server / client HMI = client (master) CQM1 only supports slave role on Hostlink
Update time 1000 ms Lower values (e.g. 250 ms) accelerate tag updates but increase CPU scan load

Tag mapping example for reading a process value from DM0100 and a bit from IR010.00:

Tag:    PV_Flowrate
Type:   INT (16-bit, signed)
Address (WinCC flexible): DM 100
Access: cyclic read, 1 s

Tag:    Pump1_Run
Type:   BOOL
Address (WinCC flexible): IR 010.00
Access: cyclic read, 500 ms
WinCC flexible uses the prefix DM for the CQM1 data memory area and the prefix IR / SR / HR / AR for the corresponding bit/word areas. For bit addresses always include a dot separator and a two-digit bit index (e.g. IR 200.07). Omron DM numbering is decimal; do not prefix with a leading zero except when matching the underlying PLC area exactly.

Recommended Serial Parameters

The baseline Hostlink profile for CQM1 ↔ MP277 is fixed by the protocol but the optional high-speed variant is permitted when both sides support it. A third-party panel-vendor compatibility reference (Weintek EasyBuilder PLC connection guide for CQM1) confirms the 7E2 / 9600 / 19200 envelope and lists the same RS232 pinout used here:

Parameter Required (Hostlink) Optional High-Speed Variant
Baud rate 9600 19200
Data bits 7 7
Parity Even Even
Stop bits 2 2
Flow control None (RTS/CTS jumpered) None
Response timeout ≥ 1 s (HMI scan) ≥ 0.5 s
Inter-character timeout ≤ 50 ms ≤ 25 ms

The protocol mandates 7 data bits, even parity, and 2 stop bits. Any deviation causes every FCS byte to mismatch and the CQM1 will respond with @00IC00 (format error) instead of the requested data.

Multi-Drop Networks (RS422 with Adapters)

Up to four Omron controllers may share one MP277 IF1B port using an RS422 four-wire multidrop topology. Each CQM1 is fitted with a CQM1-CIF11 or NS-AL002 RS232↔RS422 adapter on its peripheral port; the adapter converts TXD/RXD to SDA/SDB/RDA/RDB differential pairs and tri-states when not selected. The MP277 IF1B port must be reconfigured to RS422 mode using the rear-panel DIP switch block (DIP-1 = ON, DIP-2 = OFF for RS422 four-wire) and the WinCC flexible connection must specify the same unit number configured in each PLC's DM6651.

MP277 IF1B RS422 mode (DIP-1 ON) SDA / SDB RDA / RDB SG CQM1 #0 (unit 00) + CIF11 / NS-AL002 CQM1 #1 (unit 01) + CIF11 / NS-AL002 CQM1 #2 (unit 02) + CIF11 / NS-AL002 120 Ω termination (last node) differential bus

Termination: place a 120 Ω resistor across RDA/RDB at the farthest node only. Each CQM1 unit number must be unique (00–31) and must match the unit number configured in the WinCC flexible connection properties.

Verification Procedure

After physical wiring and project transfer, validate end-to-end communication before handing over to operations:

  1. Power the MP277 and the CQM1, then start WinCC flexible Runtime on the panel (or simulate via the WinCC flexible Loader on the engineering PC).
  2. Open the Diagnostics → Connection Status view on the MP277. The Omron Hostlink driver should report Connected within one scan cycle.
  3. Force a known value into a DM word from CX-Programmer (e.g. write 1234 hex to DM0000). Watch the value appear on the configured MP277 numeric I/O field.
  4. Toggle an output bit (e.g. IR100.00) from a button on the HMI. Verify the CQM1 output LED reacts within the configured update time.
  5. Disconnect the cable and confirm the MP277 raises an alarm with error code 130002 (communication error, Omron Hostlink). Re-connect and confirm automatic recovery within two scan cycles.
  6. Capture a logic-analyser trace of one polling cycle and decode the FCS to confirm both sides agree on the parity and stop bits.
Field tip: If the HMI shows 130002 immediately after project start but recovers when you reset the CQM1, the CQM1 still has remote ladder transfer enabled. Re-check DM6650 bits 00–07 and confirm they are set to 00 hex (Hostlink master/slave), not 01 hex (peripheral bus, remote ladder transfer).

Troubleshooting Matrix

Symptom Likely Root Cause Diagnostic Action Corrective Action
HMI shows 130002 immediately Channel 1 in remote transfer mode Read DM6650 via CX-Programmer Set DM6650 = 0000 hex, cycle power
HMI shows 130002 intermittently Baud mismatch or noise on shield Inspect shield termination, check DIP switch on rear of MP277 Tie shield to ground at one end only; verify 7E2 on both sides
All tags read 0 Unit number mismatch Send @00RR00000001 with PuTTY on the cable to verify the unit number Adjust DM6651 (BCD) or the WinCC flexible unit number to match
Some tags read 0, others valid Out-of-range DM or HR index Check CQM1 DM/HR area size in the project configuration Clip address to the area size of the installed CPU (CPU45 has DM0000–DM6143)
Connection drops every 30 s CQM1 response timeout too short Trace frames with logic analyser; measure inter-frame gap Increase DM6653 to 10 (= 100 ms response delay) or reduce HMI scan count
CQM1 returns IC instead of data FCS or framing error (wrong parity, wrong stop) Check parity on MP277 connection properties Set 7 / even / 2 explicitly; do not let Windows select 8-N-1
CQM1 returns !E followed by error code Command not supported by CPU (e.g. CPU11) Read model label Replace CPU with a CPU4x or migrate to a CP1L
Update time stretches to > 2 s Too many tags polled at 100 ms Open the WinCC flexible tag log Distribute tags across 500 ms and 1000 ms update groups

Documentation References

The complete Hostlink driver configuration (Omron chapter) is documented in the Siemens WinCC flexible 2008 Communication Part 2 manual, available through the Siemens Industry Online Support portal under entry ID 18796066. The CQM1 peripheral port pinout and PLC Setup word map are documented in the Omron CQM1 Operation Manual (W227-E1-1) and the CQM1 Programming Manual (W228-E1-1).

A consolidated parameter reference for the CQM1 series, including the 9600 / 19200 baud envelope and RS232 / RS422 / RS485 options, is published by Weintek as a third-party panel compatibility note: OMRON C/CQM1 Series PLC connection guide (Weintek, PDF). Use it as a cross-check on baud and data-bit limits; the protocol behaviour remains defined by Omron and Siemens.

Does the Siemens MP277 support every Omron CQM1 CPU?

No. The Hostlink/Multilink driver was tested and released by Siemens AG for SYSMAC C (excluding CQM1-CPU11 and CQM1-CPU21), SYSMAC CV, SYSMAC CS1, SYSMAC alpha, and CP series. Any CQM1-CPU4x (CPU41, CPU42, CPU43, CPU44, CPU45 — including the -V and -EV variants) is supported.

What baud rate and frame format should I configure for CQM1 Hostlink?

The protocol mandates 7 data bits, even parity, and 2 stop bits (7E2). The baud rate is 9600 by default. DM6650 bits 14–15 may be set to 11 to enable 19200 baud only after verifying cable length and signal integrity; the parity and stop-bit fields must remain 7E2.

Why does the MP277 report communication error 130002 immediately after power-up?

The CQM1 Channel 1 defaults to peripheral bus / remote ladder transfer mode, which blocks Hostlink polling. Program DM6650 to 0000 hex (Hostlink master/slave) and either cycle power or execute STUP(237) in the ladder program to activate the new mode.

Can I connect more than one CQM1 to a single MP277?

Yes. Up to four CQM1 CPUs may share one MP277 IF1B port using an RS422 four-wire multidrop. Each CQM1 must have a unique Hostlink unit number (DM6651, BCD 00–31) and a CIF11 or NS-AL002 RS232↔RS422 adapter on its peripheral port. Terminate the bus with 120 Ω at the farthest node.

Which PLC Setup word controls the CQM1 unit number?

DM6651 holds the Hostlink unit number as two BCD digits (00–31). The WinCC flexible connection property "PLC unit number" must match this value exactly, otherwise the CQM1 will not respond and the HMI will report communication error 130002.

Back to blog