Overview: Modbus TCP Library Access for S7 PLCs
Siemens distributes officially tested Modbus TCP libraries for the S7-1200 and S7-1500 families that contain pre-built program blocks (FB, FC, DB, UDT) implementing Modbus TCP client and server functionality on top of the integrated PROFINET interface of the CPU. The most widely deployed package is the "Modbus/TCP CP" library, current revision V4.3, which exposes the MB_CLIENT and MB_SERVER function blocks for use inside TIA Portal projects. The library is shipped as a global library archive (.al14, .al15, or .al18) and as a zipped bundle that includes worked example projects, release notes, and bilingual documentation.
Because Siemens distributes the demo version through the IT4INDUSTRY license-tracking backend rather than the standard support.industry.siemens.com download area, engineers routinely hit a dead link or an "email not found" error when trying to retrieve the package. This reference consolidates the working retrieval path, documents the required registration on the IT4INDUSTRY portal, lists the TIA Portal integration sequence, and provides drop-in alternatives when the official channel is offline.
Prerequisites for Obtaining Modbus TCP Demo Blocks
Before retrieving the library, verify the following items are in place:
- Siemens Industry Online Support account: A registered user at support.industry.siemens.com. Note that the IT4INDUSTRY portal credentials are independent from this account; do not assume single sign-on.
- IT4INDUSTRY downloads account: A separate registration is required on the IT4INDUSTRY distribution site that hosts the licensed demo material. Re-use of the standard support credentials returns "The email-address was not found or password was wrong."
- TIA Portal installation: V15, V15.1, V16, V17, or V18 installed locally. Modbus/TCP CP V4.3 is compatible with all of these; older revisions V3.x are required for TIA V13/V14 environments.
- S7-1200 or S7-1500 CPU firmware: Firmware 4.2 or higher for S7-1200 (CPU 1211C/1212C/1214C/1215C/1217C and 1212FC/1214FC/1215FC) and firmware 2.0 or higher for S7-1500 to use the integrated PROFINET interface for Modbus TCP without an additional CP module.
- Working email address: The IT4INDUSTRY portal sends an activation link that must be confirmed before any download is enabled.
- Outbound HTTPS to extranet.is.industry.siemens.com: Corporate firewalls that block the extranet domain prevent the Accept page from loading.
Locating the Official Modbus TCP Library on Siemens Support
The canonical entry point for the Modbus/TCP CP library on the Siemens Industry Online Support portal is reached via the search term "Modbus TCP S7-1200" or the direct article number 67293086. The article carries the library ZIP, release notes, and a German/English PDF describing the MB_CLIENT/MB_SERVER block interfaces.
For TIA Portal cloud documentation and worked examples, refer to the TIA Portal help portal at docs.tia.siemens.cloud – Modbus TCP examples. The cloud collection covers example projects for both client and server roles, instruction instance DB creation, and download behavior when blocks are still in compile-error state.
| Article ID | Title | Library | TIA Portal |
|---|---|---|---|
| 67293086 | Modbus/TCP CP library for S7-1200/S7-1500 | V4.3 (current) | V15–V18 |
| 22660304 | Modbus/TCP CP V3.x legacy | V3.4.5 | V13 SP1–V14 |
| 109751826 | Modbus RTU via CM PtP | V2.x | V15–V18 |
| 109766507 | S7-1500 Modbus TCP sample project | V4.3 example | V16–V18 |
Registering on the IT4INDUSTRY Portal
The demo version of the Modbus/TCP CP library is distributed under the IT4INDUSTRY license-tracking system rather than the public Siemens support area. IT4INDUSTRY is a separate authentication domain — a Siemens Industry Online Support login will not be recognized. The decision tree below illustrates the correct path through the Accept and authentication flow.
Follow the steps below to obtain working credentials:
- Open the library entry on Siemens Support and click the Download link. When the Accept EULA screen appears, click Accept.
- The browser redirects to the IT4INDUSTRY login form. If you have not registered, click the Register link — not Login.
- Provide a valid corporate email address, first/last name, company, and country. A confirmation email is dispatched within minutes; click the embedded activation URL to complete the registration.
- Return to the original library entry, click Accept again, and authenticate with the freshly activated IT4INDUSTRY credentials. The download initiates immediately.
Downloading the Modbus TCP V4.x Demo Package
The download package ships as a ZIP archive (typically 67293086_Modbus_TCP_CP_V4_3.zip) containing the following structure:
/
├── Library/
│ ├── Modbus_TCP_CP_V4_3.al14 (TIA V14 SP1–V15 library)
│ ├── Modbus_TCP_CP_V4_3.al15 (TIA V15.1–V16 library)
│ └── Modbus_TCP_CP_V4_3.al18 (TIA V17–V18 library)
├── Examples/
│ ├── Modbus_TCP_Client_S7-1200.zap14
│ ├── Modbus_TCP_Server_S7-1200.zap14
│ └── Modbus_TCP_Client_S7-1500.zap16
├── Documentation/
│ ├── Modbus_TCP_CP_V4_3_en.pdf
│ └── Modbus_TCP_CP_V4_3_de.pdf
└── Release_Notes.txt
The library exposes the following function blocks in the Modbus_TCP_CP program folder:
| Block | Type | Number | Role |
|---|---|---|---|
| MB_CLIENT | FB | 1100 | Modbus TCP client (master) |
| MB_SERVER | FB | 1101 | Modbus TCP server (slave) |
| MB_RED_CLIENT | FB | 1102 | Redundant client wrapper |
| MB_HAL_DB | DB | 1103 | Hardware abstraction DB |
| MODBUS_PNIODATA | UDT | 1104 | I/O data structure for CP 343-1 / CP 443-1 path |
Modbus TCP reserves TCP port 502 per IANA assignment. All connections opened by MB_CLIENT and MB_SERVER use port 502 as the server-side listen port and as the destination port for outgoing client requests. The library additionally reserves 16 connection identifiers (CONNECT_ID 1..16) per CPU instance; CONNECT_ID collisions between two MB_CLIENT instances cause STATUS 16#80C9 at runtime.
MB_CLIENT and MB_SERVER Parameter Reference
The V4.3 library publishes the following input and output parameters on MB_CLIENT. The structure of MB_SERVER is a subset (no partner IP, fixed listen port).
| Parameter | Direction | Type | Description |
|---|---|---|---|
| REQ | IN | Bool | Rising edge initiates a new transaction |
| DISCONNECT | IN | Bool | Edge 0→1 closes the TCP connection |
| MB_MODE | IN | USInt | 1 = read, 2 = write |
| MB_DATA_ADDR | IN | UInt | Modbus register address (1-based by default) |
| MB_DATA_LEN | IN | UInt | Number of registers or coils per transaction |
| MB_DATA_PTR | IN | Variant | Pointer to source/destination data block |
| CONNECT_ID | IN | UInt | Connection identifier (1..16), must be unique per CPU |
| IP_OCTET_1..4 | IN | USInt[4] | Target server IP address octets |
| PORT | IN | UInt | Modbus TCP port (default 502) |
| DONE | OUT | Bool | TRUE for one cycle when transaction completes without error |
| BUSY | OUT | Bool | TRUE while a transaction is in progress |
| ERROR | OUT | Bool | TRUE for one cycle when transaction completes with error |
| STATUS | OUT | Word | Detailed status or error code (hex) |
Modbus Address Mapping and Register Conventions
Modbus function codes are paired with four logical address spaces. The library accepts the 1-based address as written in the device documentation; conversion to the 0-based PDU offset happens inside the block.
| FC | Name | Logical Space | Typical Address | MB_DATA_PTR Type |
|---|---|---|---|---|
| FC1 | Read Coils | 0xxxx | 00001–09999 | Bool / Byte array |
| FC2 | Read Discrete Inputs | 1xxxx | 10001–19999 | Bool / Byte array |
| FC3 | Read Holding Registers | 4xxxx | 40001–49999 | Word / Int / Real array |
| FC4 | Read Input Registers | 3xxxx | 30001–39999 | Word / Int / Real array |
| FC5 | Write Single Coil | 0xxxx | 00001–09999 | Bool |
| FC6 | Write Single Register | 4xxxx | 40001–49999 | Word / Int / Real |
| FC15 | Write Multiple Coils | 0xxxx | 00001–09999 | Bool array |
| FC16 | Write Multiple Registers | 4xxxx | 40001–49999 | Word / Int / Real array |
MB_DATA_ADDR = 40001 in V4.3 (1-based). Older V3.x libraries expected 0-based and required MB_DATA_ADDR = 0 for the same register. Migrating projects from V3.x to V4.3 requires subtracting 1 from the address or shifting the partner documentation convention.Integrating the Library into TIA Portal V15–V18
- Open TIA Portal and the target project.
- Right-click the project node and choose Global libraries > Open library...
- Browse to
Modbus_TCP_CP_V4_3.al15(or.al18for V17/V18) and confirm. - In the library palette, navigate to Master copies > Modbus_TCP_CP. Drag the MB_CLIENT or MB_SERVER FB into the project Program blocks folder.
- Provide an instance DB when prompted (TIA auto-numbers DB1100 onward). Use a fixed DB number for traceability:
idb_MB_CLIENTas DB1100. - Create a standard-access data DB (un-optimized) to hold the Modbus payload. A 10-register holding-register example:
DATA_BLOCK "dbModbusData"
{ S7_Optimize_Access := 'FALSE' }
AUTHOR : ENG
FAMILY : MODBUS
NAME : dbModbusData
VERSION : 0.1
STRUCT
HoldingReg : ARRAY[0..9] OF WORD; // 10 registers, FC3/FC6/FC16
CoilState : ARRAY[0..15] OF BOOL; // 16 coils, FC1/FC5/FC15
END_STRUCT;
END_DATA_BLOCK
- Insert a CALL MB_CLIENT, "idb_MB_CLIENT" ladder/network in OB1. Wire the inputs:
REQ := bStartRequest // Bool — rising edge initiates transaction
DISCONNECT := bDisconnect // Bool — close TCP connection on demand
MB_MODE := 1 // USInt — 1 = read, 2 = write
MB_DATA_ADDR:= 40001 // UInt — 1-based Modbus register address
MB_DATA_LEN := 10 // UInt — number of registers/coils
MB_DATA_PTR := "dbModbusData".HoldingReg // Variant — must point to a standard DB
CONNECT_ID := 1 // UInt — unique per CPU
IP_OCTET_1 := 192 // USInt
IP_OCTET_2 := 168
IP_OCTET_3 := 0
IP_OCTET_4 := 50
PORT := 502 // UInt — Modbus TCP standard port
- Compile the project (Build > Compile all). Resolve any "Instance DB must be non-optimized" warnings by un-checking Optimized block access on the data DB.
- Download to the CPU in STOP, then RUN. Watch the
STATUSword on the instance DB to confirm clean operation.
MB_DATA_PTR must have Optimized block access disabled. Optimized DBs use symbolic-only addressing which the library cannot resolve at runtime. Mark the DB as "Standard" compatible in the DB properties and ensure S7_Optimize_Access := 'FALSE' is set in the source.Alternative Open-Source Modbus TCP Libraries
When the IT4INDUSTRY portal is offline or the demo download cannot be retrieved, third-party libraries are usable for non-safety, non-validated applications. The Modbus Organization maintains a public resource list at modbus.org/other-sites tracking open-source implementations. For .NET integration, the EasyModbusTCP/UDP/RTU .NET library implements function codes FC1 (Read Coils), FC2 (Read Discrete Inputs), FC3 (Read Holding Registers), FC4 (Read Input Registers), FC5 (Write Single Coil), FC6 (Write Single Register), FC15 (Write Multiple Coils), and FC16 (Write Multiple Registers) for client and server roles.
| Library | Language | RTU | TCP | UDP | License |
|---|---|---|---|---|---|
| EasyModbusTCP/UDP/RTU .NET | C# | Yes | Yes | Yes | LGPL |
| libmodbus | C | Yes | Yes | No | LGPL 2.1 |
| pymodbus | Python | Yes | Yes | No | BSD |
| Modbus Tools Kit | Python | Yes | Yes | No | Apache 2.0 |
| NModbus4 | C# | Yes | Yes | No | MIT |
| jamod | Java | Yes | Yes | No | BSD |
Verifying the Library Installation
After integration, verify the library loads correctly using the following checks:
- Compile clean: Project compiles with zero warnings and zero errors referencing Modbus blocks. Watch specifically for "Instance DB must be non-optimized" and "Variant pointer type mismatch".
- Block inventory: The library FBs (MB_CLIENT = FB1100, MB_SERVER = FB1101) appear in Program blocks > System blocks > Library blocks.
-
Watch table: Open a watch table on the MB_CLIENT instance DB. The
DONE,BUSY,ERROR, andSTATUSoutputs must be visible (Word type for STATUS). - Live connection test: Use a Modbus poll tool (such as the Modbus Tools Kit client) to read the same register range the CPU is configured to serve. The tool must return values without "Illegal Data Address" (exception code 02) or "Illegal Function" (exception code 01).
- STATUS = 16#0000: No transaction error. STATUS = 16#80C8 indicates the configured partner is not reachable; verify IP, subnet, and firewall on TCP/502.
- Cycle-time budget: A single FC3 read of 10 registers should add < 5 ms to the OB1 cycle time on S7-1214C/DC/DC and < 2 ms on S7-1516-3 PN/DP.
Diagnostic STATUS Code Reference
The MB_CLIENT/MB_SERVER STATUS word returns hex codes that map to specific protocol or local faults. The most common values are listed below; refer to the bundled PDF in the library ZIP for the full table.
| STATUS (hex) | Meaning | Likely Cause |
|---|---|---|
| 0000 | No error | Normal completion |
| 7000 | No active call | REQ has not been pulsed |
| 7001 | First call, waiting | Transaction initializing |
| 7002 | Subsequent call, waiting | Transaction in progress |
| 80C8 | Partner not reachable | Wrong IP, wrong subnet, firewall blocks 502, server offline |
| 80C9 | Connection rejected | Duplicate CONNECT_ID, server reached refused |
| 8183 | MB_DATA_PTR type mismatch | Source DB optimized or wrong data type |
| 8187 | MB_DATA_LEN exceeds DB size | Resize data DB or shorten transaction |
| 8188 | Invalid MB_DATA_ADDR for FC | Address outside the supported range for the chosen function code |
| 80D1 | Modbus exception 01 (illegal function) | Partner does not implement requested FC |
| 80D2 | Modbus exception 02 (illegal data address) | Address not mapped in partner |
| 80D3 | Modbus exception 03 (illegal data value) | Quantity outside partner limits |
| 80D4 | Modbus exception 04 (server device failure) | Partner internal error |
Field Commissioning Checklist and Security Notes
Run through the following checks before declaring a Modbus TCP link production-ready:
- Network isolation: Modbus TCP has no authentication or encryption (per the Modbus Organization specification at modbus.org). Place the link on a separate VLAN or behind an industrial firewall.
- Write protection: Restrict MB_MODE = 2 (write) to clearly identified instances; accidental writes to a partner holding register can rewrite process setpoints.
-
Watchdog: Implement an OB1 cycle-counter that drops the connection if
DONEdoes not toggle within N cycles; useDISCONNECT= TRUE to force re-handshake. - Time synchronization: Use the same NTP source for the S7 CPU and partner SCADA so that transaction logs can be correlated during incident review.
-
Port scan verification: From a laptop on the same VLAN, run
nmap -p 502 <cpu-ip>to confirm only TCP/502 is open and no extraneous ports are exposed by the library. - Spare CONNECT_IDs: Reserve CONNECT_ID 1–4 for production, 5–8 for commissioning, 9–16 for test/diagnostics. Document in the project README.
- Backup project: Store the integrated TIA project and the global library in the same versioned repository. Re-downloading the demo at the next migration can be cumbersome if the IT4INDUSTRY portal is unavailable.
Troubleshooting Common Download and Integration Issues
| Symptom | Root Cause | Resolution |
|---|---|---|
| Accept-link returns 404 or page does not load | Siemens portal deeplink drift | Search Siemens Support for article 67293086 directly; use the latest canonical URL |
| "Email not found or password wrong" on EULA Accept page | Siemens Support credentials reused on IT4INDUSTRY | Register a new IT4INDUSTRY account, confirm the activation email, then retry |
| Library opens as TIA V14 but project is V17 | Mismatched library revision | Use .al15 for V15.1–V16, .al18 for V17–V18 |
| Compile error: "Instance DB must not be optimized" | DB passed to MB_DATA_PTR has optimized access | Uncheck Optimized block access on the data DB; set S7_Optimize_Access := 'FALSE'
|
| STATUS = 16#80C8 at runtime | Partner not reachable on TCP/502 | Ping partner IP, verify firewall, confirm Modbus server bound to 0.0.0.0:502 |
| STATUS = 16#8187 | MB_DATA_LEN exceeds DB size | Resize data DB or reduce MB_DATA_LEN |
| STATUS = 16#80C9 | Connection rejected by partner | Verify CONNECT_ID unique, check partner expects MB_CLIENT role, increase partner listen backlog |
| STATUS = 16#80D2 | Partner returns Illegal Data Address | Verify the 40001-range map in the partner; subtract 1 if migrating from V3.x library |
| Browser blocks the Accept URL | HTTP referrer mismatch in intranet | Copy the full extranet URL into a private-browsing window; disable corporate URL rewriting |
| Partner sees connection drops every ~50 minutes | TCP keepalive timeout | Reduce DISCONNECT toggling or set keepalive interval in partner stack |
Where can I download the official Siemens Modbus TCP demo blocks?
From the Siemens Industry Online Support entry article 67293086 for Modbus/TCP CP V4.3. The download is gated behind the IT4INDUSTRY portal — separate registration is required because the demo is licensed material, not a public document.
Why does the IT4INDUSTRY portal reject my Siemens Support login?
IT4INDUSTRY uses an independent user database. A valid Siemens Industry Online Support account does not authenticate against the IT4INDUSTRY downloads system. Register a fresh IT4INDUSTRY account using the link on the EULA page, confirm the activation email, then retry the Accept flow.
Which TIA Portal version supports Modbus/TCP CP V4.3?
TIA Portal V15.1 through V18. The package includes .al14, .al15, and .al18 global library variants. For older TIA V13/V14 environments, use the legacy V3.4.5 package (article 22660304).
Can I use MB_CLIENT and MB_SERVER on a CPU without a separate CP module?
Yes — S7-1200 CPUs with firmware 4.2 or higher and S7-1500 CPUs with firmware 2.0 or higher support Modbus TCP directly on the integrated PROFINET interface. The library detects the hardware and routes through the on-board interface; no CM/CP is required unless you need a second physical port or routing through a CP 343-1 / CP 443-1.
What is the default Modbus TCP port and how do I change it?
Port 502 is the IANA-assigned standard and is the default for both MB_CLIENT destination port and MB_SERVER listen port. The library allows override of the listen port by setting the PORT input on MB_SERVER (for example to 5002 or 5502). The client destination port is fixed at 502 in V4.x; use a port-forwarding NAT if the partner expects a non-standard port.
Why does the partner return Illegal Data Address (exception 02) on read?
The address passed in MB_DATA_ADDR is either outside the partner's mapped range, or it conflicts with a 0-based versus 1-based convention. Confirm the address against the partner documentation, then check whether the project was migrated from V3.x (where the address was 0-based) without subtracting 1 from each entry.