Modbus TCP S7-1500 TIA Portal: MB_CLIENT Setup for LabVIEW
Siemens S7-1500 CPUs expose Modbus TCP as a standard instruction set inside TIA Portal, enabling direct register-level exchange with any Modbus TCP client or server such as National Instruments LabVIEW. This reference walks through a complete MB_CLIENT configuration on a CPU 1516F-3 PN/PD, including the TCON_IP_V4 connection parameter block, data block mapping, status/error code interpretation, and a paired LabVIEW client implementation on TCP/502.
MB_CLIENT and MB_SERVER instructions (instruction library, no extra package). TIA Portal V13 uses a separately installed "ModbusTCP" library with different FB names; a compatibility summary appears in §11. Verify CPU firmware is V2.0 or later (V2.5+ recommended for stable multi-connection behavior).1. Overview and System Architecture
Modbus TCP is an application-layer protocol riding on standard TCP/IP, registered on port 502. The S7-1500 PN/PD CPU acts as a Modbus TCP server (slave) by default in this configuration, exposing a 16-bit register and bit-addressable data image to any client. LabVIEW on a Windows PC plays the role of the Modbus TCP client (master) and issues read/write requests against the CPU's IP and port 502.
| Component | Role | IP address | Port | Submask / GW |
|---|---|---|---|---|
| CPU 1516F-3 PN/PD | Modbus TCP server | 192.168.0.10 | 502 | 255.255.255.0 / 192.168.0.1 |
| LabVIEW host PC | Modbus TCP client | 192.168.0.20 | 0 (ephemeral) | 255.255.255.0 / 192.168.0.1 |
| Ethernet | PN/PN coupler or switch | — | — | 100 Mbit/s full duplex minimum |
The S7-1500 supports up to 64 simultaneously established Modbus TCP connections on the integrated PROFINET interface, with a configurable maximum server connection count (default 1, extend via the CPU's webserver or MB_SERVER multi-instance). The LabVIEW client only needs one connection.
2. Prerequisites
-
CPU: S7-1500 1516F-3 PN/PD, firmware V2.0 or later. V2.5+ recommended for
MB_CLIENTbug fixes related to multi-instance and connection-loss recovery. - Engineering: TIA Portal V15.1 / V16 / V17 / V18 with the matching S7-1500 HSP installed.
- LabVIEW: LabVIEW 2018 or later (2020+ recommended) plus the NI Modbus Library (free add-on from NI) or NI OPC Server with Modbus TCP driver.
- Network: Managed or unmanaged Ethernet switch, both devices on the same subnet, TCP/502 reachable end-to-end. Disable Windows Firewall on the LabVIEW PC during commissioning or explicitly allow the LabVIEW executable inbound/outbound on TCP/502.
-
Program memory: Approximately 2 KB of load memory for the
MB_CLIENT/MB_SERVERFBs and the connection parameter DB.
3. S7-1500 Program Structure
The standard Modbus TCP implementation on S7-1500 requires three blocks:
-
MB_SERVER(FB) — implemented as a multi-instance inside a parent FB. The server is normally started once in OB1 (or OB100 for cold start) and runs continuously. -
MB_CLIENT(FB) — used when the S7-1500 itself initiates requests to another Modbus device. In this scenario, the client is on the LabVIEW side, so the S7-1500 only needsMB_SERVER. - A user data DB (e.g.,
"ModbusData") where the Modbus register image is mirrored. TheMB_DATA_PTRofMB_SERVERpoints to the start of this DB.
Optional supporting blocks:
-
TCON_IP_V4(UDT) — connection parameter structure, instantiated inside a global DB. -
MODBUS_PARAMor "Modbus_Comm_Load"-style setup — not required when using the integrated instructions; the parameter DB replaces it.
4. MB_SERVER Instruction Configuration
Drop MB_SERVER from Instructions > Communication > Modbus TCP into OB1. In a production deployment, wrap it in a parent FB and call it via a multi-instance DB so you can run several independent Modbus servers with different connection parameter DBs.
| Pin | Direction | Type | Value / Description |
|---|---|---|---|
DISCONNECT |
IN | BOOL | FALSE (kept connected). Pulse TRUE to drop a connection. |
CONNECT |
IN/OUT | VARIANT (TCON_IP_V4) | Pointer to the connection parameter DB instance |
MB_HOLD_REG |
IN/OUT | VARIANT | Pointer to the holding-register DB (e.g., P#DB100.DBX0.0 WORD 100) |
NDR |
OUT | BOOL | New data indication (one-shot pulse after a write that changes data) |
DR |
OUT | BOOL | Data read (pulses after a successful client read) |
ERROR |
OUT | BOOL | TRUE on protocol or connection error |
STATUS |
OUT | WORD | Detailed status/error code (see §10) |
The S7-1500 is passive in Modbus TCP server mode — it waits for the client to open the connection. The CONNECT structure must specify ActiveEstablished = FALSE and LocalPort = 502 for an MB_SERVER.
5. Connection Parameter Data Block (TCON_IP_V4)
Create a global DB named "Modbus_Conn_Server" with the data type TCON_IP_V4. The structure definition is:
TYPE TCON_IP_V4
STRUCT
InterfaceId : HW_ANY; // local PN interface HW ID
ID : CONN_OUC; // connection ID 1..4095
ConnectionType : BYTE; // 16#0B = TCP
ActiveEstablished : BOOL; // FALSE = server
RemoteAddress : ARRAY[1..4] OF BYTE; // ignored when server
RemotePort : UINT; // ignored when server
LocalPort : UINT; // 502
END_STRUCT;
END_TYPE
| Field | Value (example) | Notes |
|---|---|---|
InterfaceId |
64 | HW identifier of the CPU's PROFINET interface_1. Find via CPU properties > System constants or by going online and reading the constant table. |
ID |
1 | Must be unique on the CPU. Range 1..4095. |
ConnectionType |
B#16#0B | TCP/IP. UDP is not used by Modbus TCP. |
ActiveEstablished |
FALSE | Server passively accepts the connection from LabVIEW. |
RemoteAddress |
[0,0,0,0] | Don't care for server. |
RemotePort |
0 | Don't care for server. |
LocalPort |
502 | IANA-registered Modbus TCP port. Do not change unless you also adjust the client. |
If you need to expose the same S7-1500 to multiple LabVIEW clients simultaneously, instantiate one TCON_IP_V4 DB per connection and use multiple MB_SERVER multi-instances. The CPU's connection resource count is visible in Device properties > Communication > Connection resources.
6. Modbus Data Block Mapping
Create a global DB named "ModbusData". The block must be non-optimized (disable "Optimized block access" in DB properties) so that MB_SERVER can address it with absolute byte offsets. Standard access is required for direct Modbus register mapping.
| Modbus address (1-based, client view) | DB offset | Type | Symbol | Notes |
|---|---|---|---|---|
| 40001 | DBW0 | WORD | HR_Setpoint_Speed |
First holding register |
| 40002 | DBW2 | WORD | HR_Actual_Speed |
— |
| 40003..40010 | DBW4..DBW18 | ARRAY[1..8] OF WORD | HR_Process_Data |
8-word array |
| 40011..40050 | DBW20..DBW98 | ARRAY[1..40] OF WORD | HR_Recipe |
Recipe block (40 registers) |
| 00001..00016 | DBX100.0..DBX101.7 | ARRAY[1..16] OF BOOL | Coil_Status |
First 16 coils mapped at byte 100 |
The Modbus standard uses 1-based logical addresses (40001 for the first holding register, 00001 for the first coil). Internally, MB_SERVER references the DB at byte 0 for holding register 40001. The CPU automatically handles the +1 offset between the Modbus address from the wire and the zero-based DB offset.
For 32-bit floating-point values, two adjacent 16-bit holding registers must be used. LabVIEW clients must be configured to read two registers and interpret the result as REAL. The byte/word order follows the Modbus specification (big-endian per register, but the order of the two registers can be swapped on the client side based on word swap and byte swap settings).
7. LabVIEW Client Configuration
The NI Modbus Library provides native Modbus TCP master VIs for LabVIEW. The minimum VIs to use are:
- MB TCP Open Connection.vi — establishes the TCP/502 session to 192.168.0.10.
- MB TCP Read Holding Registers.vi — FC 03 reads.
- MB TCP Write Multiple Holding Registers.vi — FC 16 writes.
- MB TCP Write Single Register.vi — FC 06 single-word writes.
- MB TCP Close Connection.vi — clean teardown.
| Control | Value | Notes |
|---|---|---|
| Server IP address | 192.168.0.10 | S7-1500 PN interface address |
| Server port | 502 | IANA standard |
| Unit ID (slave ID) | 255 (or 1) | Modbus unit identifier. S7-1500 ignores this byte on TCP, but the LabVIEW library still requires a value. |
| Starting address | 1 | 1-based Modbus address (40001) |
| Quantity of registers | 50 | Maps to 40001..40050 |
| Timeout (ms) | 3000 | Adjust for network latency; default 1000 ms is often too short for the first poll after a download. |
| Poll rate (ms) | 100..500 | Cycle time; do not exceed the S7-1500 OB1 cycle time × 3 to avoid backlog. |
The connection state and Modbus exception codes (0x01 Illegal Function, 0x02 Illegal Data Address, 0x03 Illegal Data Value, 0x04 Slave Device Failure) are exposed on the error cluster of each VI. Wire the error cluster to a simple error handler VI for the first commissioning pass.
8. Function Code and Register Reference
| FC | Function | Address range (Modbus) | DB element type | Access from LabVIEW |
|---|---|---|---|---|
| 01 | Read Coils | 00001..0xxxx | BOOL bits inside DB | MB TCP Read Coils.vi |
| 02 | Read Discrete Inputs | 10001..1xxxx | BOOL bits inside DB (separate area) | MB TCP Read Discrete Inputs.vi |
| 03 | Read Holding Registers | 40001..4xxxx | WORD inside DB | MB TCP Read Holding Registers.vi |
| 04 | Read Input Registers | 30001..3xxxx | WORD inside DB (separate area) | MB TCP Read Input Registers.vi |
| 05 | Write Single Coil | 00001..0xxxx | BOOL inside DB | MB TCP Write Single Coil.vi |
| 06 | Write Single Register | 40001..4xxxx | WORD inside DB | MB TCP Write Single Register.vi |
| 15 | Write Multiple Coils | 00001..0xxxx | BOOL array inside DB | MB TCP Write Multiple Coils.vi |
| 16 | Write Multiple Registers | 40001..4xxxx | WORD array inside DB | MB TCP Write Multiple Holding Registers.vi |
The S7-1500 MB_SERVER accepts all eight function codes above by default. The maximum PDU size is 253 bytes, which translates to 125 holding registers or 2000 coils per single transaction. A 50-register read (100 bytes) is well within limits and completes in roughly one OB1 cycle on a 1516F.
9. Verification and Diagnostics
-
Go online in TIA Portal. Open the
MB_SERVERinstance DB. ConfirmERROR = FALSEandSTATUS = 16#0000after the first call from LabVIEW. -
Watch
DR/NDR— both pulse TRUE for one OB1 cycle when a Modbus read or write completes successfully. -
Monitor the connection in the CPU webserver under Diagnostics > Connections. Look for the
ID = 1connection in state "Established". -
Run a Modbus poll from LabVIEW on FC 03 starting at register 1 for 50 words. Verify each WORD lands in the correct
DBWoffset ofModbusData. The first read should return zeroed data if the DB is uninitialized — that is the expected state. -
Write back from LabVIEW using FC 16, register 1, length 10. Add a watch table to
ModbusData. EachDBW0..18 should reflect the value written. -
Use Wireshark on the LabVIEW PC to capture port 502 traffic. Decode the Modbus TCP MBAP header: Transaction ID, Protocol ID 0x0000, Length, Unit ID, Function Code. The expected FC 03 reply starts with
00 00 00 00 00 06 01 03 ....
DB100.DBW0..DBW98) and the coil range (DB100.DBX100.0). Right-click and enable "Monitor all" to refresh the view at each OB1 cycle during commissioning.10. Troubleshooting Matrix
| STATUS (hex) | Meaning | Likely cause | Corrective action |
|---|---|---|---|
| 0x0000 | No error, idle | — | — |
| 0x7000 | No active request, server listening | Normal state before first client call | No action |
| 0x7001 | First call after server start | Normal initialization | No action |
| 0x7002 | Intermediate call, request in progress | Client request is being processed | Wait for completion |
| 0x8380 | Received parameter error | Wrong CONNECT structure or DB is optimized | Verify TCON_IP_V4 fields; switch DB to non-optimized access |
| 0x8381 | Illegal Modbus function | Client sent a function code not in {01,02,03,04,05,06,15,16} | Check client configuration; some SCADA packages default to FC 22 — disable |
| 0x8382 | Illegal data address | Client requested address outside DB size | Extend the ModbusData DB or reduce the request length |
| 0x8383 | Illegal data value | Length field in request invalid | Verify quantity-of-registers value on the client |
| 0x80C8 | No resources | CPU connection resources exhausted | Reduce active connection count, or check for stale client connections |
| 0x80C9 | TCP connection error | Switch port down, VLAN mismatch, or firewall | Verify physical link and switch port; temporarily disable Windows Firewall on the PC |
| 0x80CA | Connection aborted by peer | LabVIEW VI closed the socket unexpectedly | Check LabVIEW error cluster; ensure the VI closes the connection only on shutdown |
| 0x80CB | Connection timeout | Client did not send any data within the keep-alive window | Configure LabVIEW for periodic reads or send a "no-op" poll every 30 s |
Field-proven gotchas
-
Optimized DB access breaks Modbus mapping. If
ModbusDatais set to optimized access, MB_SERVER returns 0x8380. The pointer still compiles, but the address arithmetic is invalid. Always disable optimized access for any DB thatMB_DATA_PTRreferences. -
Local port 0 vs 502. Some older Modbus clients reject port 502 if the server's
LocalPortis set to 0 ("any"). Always setLocalPort = 502explicitly. - InterfaceId wrong constant. The HW ID for the PN interface is shown in the CPU's system constants. On a 1516F-3 PN/PD the first PN interface typically has ID 64. Do not hard-code this from a different CPU model — verify per device.
-
Connection ID collision. If another part of the program (e.g., a PUT/GET or open user communication) is already using
ID = 1, the Modbus server will fail to start with 0x80C8. Audit the connection table under Device > Properties > Communication > Connection resources. - LabVIEW firewall block. Windows Defender Firewall blocks unsolicited inbound traffic, but for an outbound client like LabVIEW it usually allows. If the S7-1500 side shows 0x80C9, the issue is the S7-1500 side not the PC. Ping the CPU from the PC first; if ping fails, the Modbus session will also fail.
11. Notes on TIA Portal V13 Compatibility
For users still on TIA Portal V13, the integrated MB_CLIENT / MB_SERVER instructions are not present. Modbus TCP support was distributed as a separate library called ModbusTCP, installable from the TIA Portal media or the Siemens support download portal. The library contains:
- FB blocks (typically named
ModbusTCP_Client/ModbusTCP_Serveror similar) — drop into the program as standard FBs with their own instance DB. - Accompanying UDTs for connection parameters.
- Documentation in the TIA Portal information system under Using Modbus TCP.
Functionally the V13 library covers the same Modbus function codes (FC 01..16). The configuration workflow is the same: create a connection DB, instantiate the FB in OB1, point the data pointer to a non-optimized user DB. Migrating a V13 project to V15.1+ requires deleting the legacy library blocks and inserting the new MB_CLIENT / MB_SERVER instructions, with corresponding renames of the data pointers.
Siemens maintains the dedicated application example at Entry ID 94766380 — Modbus/TCP communication between two S7-1500 CPUs which applies the same principles to a peer-to-peer S7-1500 ↔ S7-1500 setup and is a good reference for the data block layout and connection DB conventions. The PDF "Modbus/TCP with instructions MB_CLIENT and MB_SERVER" at net_modbus_tcp_s7-1500_s7-1200_en.pdf documents the function-code / MB_MODE mapping in detail. The TIA Portal V21 reference for MODBUS (TCP) is at docs.tia.siemens.cloud — MODBUS (TCP) S7-1200/S7-1500.
12. Performance and Sizing Notes
The MB_SERVER is non-blocking — it consumes essentially zero CPU time on a 1516F when no client is connected. Each Modbus transaction is dispatched inside the OB1 cycle that the call occurs in, and the round-trip time on a 100 Mbit/s network is typically under 5 ms for a 50-register read.
For high-throughput polling (e.g., 100 reads/s from LabVIEW), observe the following:
- The S7-1500 PN interface can sustain roughly 5000 Modbus TCP transactions per second under ideal conditions. Real-world load is shared with HMI, S7 communication, and PROFINET IO.
- Limit the LabVIEW poll rate to the minimum that satisfies the application. A 100 ms poll = 10 reads/s is a sensible default.
- If the application requires more than 200 reads/s, consider OPC UA instead of Modbus TCP — the S7-1500 OPC UA server has a higher transaction ceiling and is the recommended long-term Siemens path.
CPU program size impact is minimal: MB_SERVER alone is about 12 KB of code, MB_CLIENT another 12 KB. The connection parameter DB is a few hundred bytes of data. No additional communication loaders (the older CP/CM module pattern) are required — the PN interface is built into the CPU.
13. FAQ
What TCP port does Modbus TCP use on the S7-1500, and can I change it?
Modbus TCP uses IANA-registered port 502. Set TCON_IP_V4.LocalPort = 502 for the MB_SERVER connection DB. Non-standard ports are technically possible, but most client tools and firewalls expect 502, so changing it is not recommended.
How many simultaneous Modbus TCP connections does the S7-1500 support?
Up to 64 simultaneously established TCP connections on the integrated PN interface, shared with all other TCP-based services (OPC UA, S7 communication, etc.). A single LabVIEW client needs only one connection; multi-client deployments should add an MB_SERVER instance per active client.
Why does MB_SERVER report STATUS 0x8380 immediately on startup?
STATUS 0x8380 indicates a parameter error. The most common cause is a non-optimized access issue on the data DB — switch "Optimized block access" off in the DB properties. The second most common cause is a wrong InterfaceId in the TCON_IP_V4 structure; verify the HW ID via CPU properties > System constants.
Can the S7-1500 be both Modbus TCP client and server at the same time?
Yes. Add MB_CLIENT in addition to MB_SERVER, each with its own connection parameter DB and unique connection ID. The client is used to poll downstream Modbus devices (e.g., a SENTRON PAC3200 meter) while the server accepts requests from LabVIEW. Use distinct MB_MODE values to avoid protocol confusion on a shared DB.
How do I read a 32-bit REAL value from LabVIEW on the S7-1500 via Modbus TCP?
Allocate two adjacent 16-bit holding registers in the data DB (e.g., DBW20 and DBW22 for the first REAL). In LabVIEW, perform a FC 03 read with quantity = 2, then combine the two 16-bit words into a 32-bit REAL using the Modbus library's word-swap and byte-swap settings to match the S7-1500 big-endian word order.
Why does my LabVIEW poll succeed for the first 10 registers but fail at 40011?
The data DB ModbusData is smaller than the requested address range. The S7-1500 returns Modbus exception code 0x02 (Illegal Data Address), which MB_SERVER translates to STATUS 0x8382. Extend the DB to at least the highest requested register offset plus one word, or reduce the LabVIEW read length to stay within the DB size.