Overview
The Pfeiffer Vacuum TPG366 is a MaxiGauge vacuum measurement controller that exposes only RS-232 and RS-485 serial interfaces. It does not implement PROFINET, EtherNet/IP, Modbus/TCP, or any other industrial Ethernet protocol natively. To bring the device onto the plant LAN and into a Siemens S7-300 CPU 315, you must place a transparent serial-to-Ethernet converter (also called a device server or terminal server) between the controller and the gauge.
This article documents the field-proven approach:
- Wire the TPG366 RS-232 port to a serial device server (Moxa NPort, Brainboxes, Phoenix Contact, or compatible).
- Configure the device server in raw TCP Server (or Real COM) mode and bind it to a known TCP port.
- On the S7-300, use the integrated PROFINET interface of the CPU 315-2 PN/DP (or a CP 343-1 Lean) with the
TCON,TSEND, andTRCVinstructions to open a TCP connection, transmit the TPG366 ASCII query, and parse the response. - Parse the ASCII frame in the S7-300 and store pressure values in a DB for the HMI/PLC program.
The result is a deterministic vacuum data path without the need for a custom GSD file, a PROFINET coupler, or a third-party OPC server on a PC.
Prerequisites
| Item | Specification |
|---|---|
| Vacuum controller | Pfeiffer TPG366 (Pfeiffer MaxiGauge), firmware ≥ 1.4.0 |
| Serial cable | DB9 female to DB9 male, null-modem (crossover) for RS-232, 3 m max |
| Serial-to-Ethernet converter | Moxa NPort 5150 (or 5110/5130), Brainboxes ES-257, Phoenix Contact FL COMSERVER, or any device supporting raw TCP server mode |
| Siemens CPU | S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) with integrated PROFINET interface, or CPU 315-2 DP (6ES7315-2AH14-0AB0) plus CP 343-1 Lean (6GK7343-1CX10-0XE0) |
| Engineering software | SIMATIC Manager V5.6 SP2 or TIA Portal V18+ |
| Library | Standard STEP 7 IEC library (TCON, TSEND, TRCV, T_DISCON); no add-on package required |
| Network | IPv4 subnet with no firewalls blocking the chosen TCP port (default 4001 for Moxa) |
TPG366 Serial Protocol Fundamentals
The TPG366 implements the Pfeiffer Vacuum Vacuum Protocol, a request/response ASCII protocol where the host sends a 3-character command terminated by CR LF (\r\n, hex 0D 0A) and the gauge replies with the value, also terminated by CR LF. The protocol is documented in the Pfeiffer Vacuum Communication Protocol for TPG300 / TPG366 document, distributed with the gauge and also available from the official product page.
Link parameters
| Parameter | Value | Notes |
|---|---|---|
| Baud rate | 9600 / 19200 / 38400 / 115200 | Default 9600; 115200 is stable on short cables |
| Data bits | 8 | Fixed |
| Parity | None | Fixed |
| Stop bits | 1 | Fixed |
| Flow control | None (XON/XOFF optional) | Disabled recommended when using a converter |
| Terminator | CR LF (0x0D 0x0A) | Sent and received |
| Address | 1 to 31 (RS-485 multi-drop) | Use address 1 for point-to-point |
These values must match on the TPG366 (configure via the front panel under Parameters → Interface) and on the serial device server's Serial Settings page.
Key ASCII commands
| Command | Function | Typical response (ASCII) |
|---|---|---|
PVR |
Read all active pressure values | 1,+1.2345E-09,cr,lf 2,+0.0000E+00,cr,lf ... |
PR1 |
Read pressure of channel 1 | +1.2345E-09 |
PR2 |
Read pressure of channel 2 | +2.0010E-07 |
PRx |
Read pressure of channel x (1–6) | Scientific notation in mbar |
TID |
Read transducer identification | TPG366,1234567,1.4.0 |
ERR |
Read error register |
0 (no error) |
SP1 |
Set setpoint 1 threshold (write) | Acknowledges with new value |
PVR response frame for 6 channels is typically 60–90 bytes. Always size the S7-300 receive buffer at the maximum expected length (recommend 256 bytes) and parse the actual length from the connection status word of TRCV.Hardware Wiring
RS-232 point-to-point
- Connect TPG366 DB9 pinout to the converter DB9:
| TPG366 DB9 (RS-232 DCE) | Signal | Converter DB9 (DTE) |
|---|---|---|
| 2 | TXD → RXD | 2 |
| 3 | RXD → TXD | 3 |
| 5 | GND | 5 |
| 7 | RTS → CTS | 7 |
| 8 | CTS → RTS | 8 |
Use a shielded cable, ground the shield at the converter end only, and keep length ≤ 3 m for 115200 baud.
Ethernet side
- Assign the converter a fixed IPv4 address on the same subnet as the CPU 315-2 PN/DP (for example, 192.168.1.50/24).
- Configure the CPU's PROFINET interface with a fixed address in the same subnet (for example, 192.168.1.10/24).
- Reserve a TCP port on the converter; 4001 is the Moxa default and is a safe choice.
Serial-to-Ethernet Converter Configuration
The exact menu names vary by vendor, but the following four parameters are universal:
| Parameter | Recommended value |
|---|---|
| Operation mode | TCP Server (not Real COM, not UDP) |
| Local TCP port | 4001 |
| Serial settings | 9600, 8, N, 1, no flow control |
| Delimiter handling | Disabled (do not insert extra characters; pass CR/LF transparently) |
| Max connection | 1 (one S7 connection only) |
| Inactivity timeout | 0 (never auto-disconnect) |
TCON with Active connection establishment fits this model and avoids firewall/NAT issues that arise when the PLC is a server.S7-300 Software Configuration (STEP 7 V5.6)
Hardware configuration
- Open the SIMATIC Manager project and place the CPU 315-2 PN/DP in HW Config.
- Double-click the PROFINET interface PN-IO and assign IP 192.168.1.10, subnet mask 255.255.255.0.
- Add a new Ethernet connection in NetPro:
- Local end: CPU 315-2 PN/DP, PN-IO interface.
- Partner: unspecified, IP 192.168.1.50.
- Connection type: TCP connection (not ISO-on-TCP — the converter does not implement RFC 1006).
- Connection ID: 1 (used by
TCON).
Connection DB (UDT for TCON)
STEP 7 will generate a DB from the NetPro connection (for example, DB100). It contains the 64-byte TCON_PAR structure. Verify the key fields:
DB100.DBB0 = 11 // Block ID (TCP, hex 0x11)
DB100.DBB1 = 1 // Length of the parameter block (low byte)
DB100.DBB2 = 0 // High byte
DB100.DBB3 = 1 // Connection ID
DB100.DBB4 = 0 // Local TSAP length (0 for TCP)
DB100.DBB5 = 0
DB100.DBB6 = 0 // Remote TSAP length (0 for TCP)
DB100.DBB7 = 0
DB100.DBB8 = 0 // Next Staddr length (4 = IPv4)
DB100.DBB9 = 0
DB100.DBB10..13 = C0 A8 01 0A // Local IP: 192.168.1.10 (unused, set to local CPU IP)
DB100.DBB14..17 = C0 A8 01 32 // Remote IP: 192.168.1.50
DB100.DBB18..19 = 0A 0A // Remote port: 4001 (hex 0A 0A 0A 0A — 4001 = 0x0FA1)
DB100.DBB20..21 = 00 00 // Local port: 0 (any)
ST code — poll cycle (OB1)
Call sequence per scan: TCON once at startup, TSEND the ASCII command, wait, TRCV the response, parse, repeat every 500 ms.
FUNCTION_BLOCK FB100 "TPG366_Poll"
VAR
sSend : STRING := 'PVR\r\n'; // 5 bytes
sRecv : STRING[256];
iState : INT; // 0=idle, 1=connected, 2=sent, 3=rcv, 4=parse
tPoll : TON; // 500 ms period
END_VAR
BEGIN
// --- Establish TCP connection on first call ---
IF iState = 0 THEN
UDT_TCON.DB := 100; // Connection parameter DB
TCON(req := TRUE, ID := 1, DONE => , BUSY => , ERROR => ,
STATUS => );
iState := 1;
END_IF;
// --- Periodic polling ---
tPoll(IN := (iState = 1) OR (iState = 4), PT := T#500MS);
IF tPoll.Q AND iState = 1 THEN
TSEND(req := TRUE, ID := 1, LEN := LEN(sSend),
DATA := sSend, DONE => , BUSY => , ERROR => , STATUS => );
iState := 2;
END_IF;
IF iState = 2 AND NOT TSEND.BUSY THEN
TRCV(req := TRUE, ID := 1, LEN := 256,
DATA := sRecv, NDR => , BUSY => , ERROR => , STATUS => ,
RCVD_LEN => wRecLen); // WORD, actual bytes received
iState := 3;
END_IF;
IF iState = 3 AND NOT TRCV.BUSY AND TRCV.NDR THEN
// Parse sRecv and write to DB200 (pressure values as REAL)
// Example: DB200.DBD0 = pressure channel 1 in mbar (REAL)
// DB200.DBD4 = pressure channel 2 in mbar
// (parsing logic shown in next section)
iState := 4;
END_IF;
IF iState = 4 THEN
iState := 1; // wait for next tPoll
END_IF;
END_FUNCTION_BLOCK
Parsing the ASCII response
The PVR response has the form 1,+1.2345E-09,2,+0.0000E+00,3,---,4,---,5,---,6,---<CR><LF>. --- indicates an inactive channel. A simple finite-state parser in Structured Text extracts the floating-point value per channel:
// Simplified parser - locates commas and converts ASCII to REAL
FOR i := 1 TO 6 DO
nPosCh := FIND(sRecv, INT_TO_STRING(i) + ','); // channel tag
nPosEnd := FIND(sRecv, ',', nPosCh + 2);
sField := MID(sRecv, nPosCh + 2, nPosEnd - nPosCh - 2);
IF sField = '---' THEN
DB200.Channel[i] := -1.0; // -1 = invalid/no gauge
ELSE
DB200.Channel[i] := STRING_TO_REAL(sField);
END_IF;
END_FOR;
S7-300 Software Configuration (TIA Portal V18)
- Add the CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) in Devices & Networks.
- Open Properties → PROFINET interface → Ethernet addresses and set IP 192.168.1.10 / 255.255.255.0.
- Use the Open User Communication instructions from the basic program library:
-
TSEND_C(FB 1900 / block 317 in classic) orTSEND+TRCVfrom Communication → Open User Communication. - Configure a new connection of type TCP to the partner IP 192.168.1.50, port 4001.
- Drop
TSEND_CandTRCVinto a cyclic OB (OB1) or a time-of-day OB (OB35 at 100 ms). Trigger the send on a 500 ms interval using a clock bit or IEC timer.
Verification
-
Link test with PuTTY or similar: connect to 192.168.1.50:4001 from a PC, type
PVR+ Enter, confirm a multi-line ASCII response. This isolates the converter and TPG366 from the PLC. -
Online monitoring: in STEP 7 or TIA Portal, watch
TCONSTATUS = 0x0000 after a few seconds. STATUS = 0x7000 means "connection establishment active"; STATUS = 0xFFFF means error. - Force a known value: vent the chamber to atmosphere and verify DB200.Channel[1] converges to a pressure value near 1.0E+03 mbar (or whatever the active gauge measures at atmospheric pressure for the installed sensor type).
-
Disconnect test: unplug the Ethernet cable at the converter.
TRCVshould return STATUS = 0x80C4 (resource permanently unavailable) andTCONshould auto-re-establish the link when the cable is restored.
Troubleshooting Matrix
| Symptom | Likely cause | Corrective action |
|---|---|---|
TCON STATUS = 0x80C3 (job still active) |
Multiple TCON calls without reset |
Ensure TCON is called once and then never again until the connection drops |
TCON STATUS = 0x80C4 (no resources) |
Converter unreachable; wrong IP or port | Ping 192.168.1.50; verify firewall; check port with Wireshark |
TSEND STATUS = 0x80A1 (connection fault) |
Converter closed socket due to inactivity | Set converter inactivity timeout to 0; add periodic keep-alive (empty TSEND) |
| No response, but link is up | TX/RX swap, parity mismatch, or terminator wrong | Loopback test converter DB9; verify 9600,8,N,1 on both ends; ensure TPG366 expects CR LF
|
Garbled response (e.g. ?+?1.2E-09) |
Baud rate mismatch | Set TPG366 and converter to the same baud rate; factory default is 9600 |
PR1 returns 000
|
No sensor connected to that channel | Check BNC cabling; verify gauge is recognized in TPG366 Sensor menu |
Frame split across multiple TRCV calls |
TCP does not preserve message boundaries | Use delimiter-based TRCV (configure to stop on 0x0A); or accumulate in a buffer until LF received |
| DB200 stays at 0.0 | Parser unable to find channel tag | Capture raw sRecv in VAT; confirm TPG366 Display is set to send the full PVR frame, not a single channel |
Performance and Timing
At 9600 baud, the TPG366 reply to PVR is approximately 80 bytes, which is 83 ms of serial transmit time. Add 5 ms command time and 1–3 ms for converter/PLC latency, giving a round-trip of roughly 100–120 ms. Polling every 500 ms leaves ample headroom. At 115200 baud the round-trip drops below 20 ms, allowing a 100 ms poll cycle if the application requires faster vacuum updates.
Alternative Topologies
RS-485 multi-drop
The TPG366 RS-485 terminal block supports up to 32 addressable units on a single bus. Each converter RS-485 port can be wired to a chain of TPG36x controllers, each with a unique address (1…31). The S7-300 code adds an address prefix in front of every command, for example 01 PVR for unit 1, 02 PVR for unit 2. The Pfeiffer protocol prefix is the two-digit decimal ASCII address followed by a space.
EPICS / StreamDevice path
If a Linux soft-IOC is acceptable in front of the S7-300, the Paul Scherrer Institute has published a StreamDevice support module for the TPG366 that exposes every gauge parameter as a PV over Ethernet or RS-485. The IOC then bridges to the S7-300 via PROFINET or OPC UA. This is useful when vacuum read-back must also feed an EPICS control system used by an accelerator or beamline.
Native PROFINET alternative
The Pfeiffer TPG36x family does not implement PROFINET. The matching PR-series gauges that support IO-Link can be combined with a Siemens IO-Link master to bring some Pfeiffer data natively to PROFINET, but the TPG366 controller itself must still be polled serially or excluded from the PROFINET segment.
Documentation References
- Pfeiffer Vacuum, MaxiGauge TPG366 Operating Instructions — TPG366 product page
- Pfeiffer Vacuum, Vacuum Communication Protocol (TPG300 / TPG366) — available from the Pfeiffer document download center
- Siemens, S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) Manual — Siemens Industry Online Support
- Siemens, S7-300 CP 343-1 Lean (6GK7343-1CX10-0XE0) Manual — Siemens Industry Online Support
- Siemens, STEP 7 V5.6 - Open Communication with TCP — Siemens Industry Online Support
- Moxa, NPort 5100 Series User's Manual — Moxa technical documents
Does the Pfeiffer TPG366 support PROFINET or a Siemens GSD file?
No. The TPG366 only provides RS-232 and RS-485 interfaces and uses the Pfeiffer ASCII vacuum protocol. A PROFINET GSD file does not exist for this device; you must use a serial-to-Ethernet converter and poll the gauge with ASCII commands over TCP.
Which serial-to-Ethernet converter is recommended for a TPG366 link?
Any industrial device server that supports transparent TCP server mode at the configured baud rate works. The Moxa NPort 5150, Brainboxes ES-257, and Phoenix Contact FL COMSERVER are common field choices. Configure the converter in TCP server mode (not Real COM, not UDP) on a fixed port such as 4001.
What TCP port should the S7-300 use to reach the converter?
Use the port you bind on the converter, commonly 4001 for Moxa NPort defaults, 23 for raw Telnet-style converters, or 9000 for Brainboxes. Pick a port that is not used by the CPU 315-2 PN/DP web server (80, 443) or by PROFINET (34962, 34963, 34964).
Why does TRCV return partial frames when polling PVR?
TCP is a stream protocol and does not preserve message boundaries. A single TRCV call may return a partial PVR reply. Configure TRCV to terminate on the 0x0A (LF) delimiter, or accumulate received bytes in a buffer until both CR and LF are detected, then pass the complete frame to the parser.
How fast can the S7-300 poll the TPG366 over Ethernet?
At 9600 baud the round-trip is approximately 100–120 ms, supporting a 200–500 ms poll cycle. At 115200 baud the round-trip drops to about 20 ms, allowing a 100 ms poll cycle. Do not poll faster than 50 ms; the TPG366 internal measurement rate is 10–25 Hz depending on sensor type, so faster polling yields no new data.