Replacing CP341 v1 with CP341 v2: Migration & Block Update Guide

David Krause14 min read
S7-300SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: CP341 v1 vs CP341 v2 Hardware Replacement

The SIMATIC CP341 is the Siemens S7-300 point-to-point (Ptp) communication processor used for RS232C, 20 mA/TTY, and RS422/RS485 serial links on ASCII, 3964(R), and RK 512 protocols. Field-installed CP341 v1 modules can be replaced with CP341 v2 modules using the same backplane slot, front connector, and peripheral address space, but the replacement is not a drop-in firmware-only swap: the v2 hardware is a later revision of the same MLFB family that ships with updated firmware (typically v2.1.x), corrected point-to-point FBs (FB7 P_RCV_RK and FB8 P_SND_RK blocks raised to V3.1 and later), and updated HSP support that requires both the SIMATIC HSP s7h2011x.hsp and the Configuration Package for Point to Point Communication V5.1 + SP9 (or newer) installed in your engineering tool.

If the v1 card failed electrically (no module diagnostic, OK LED off, SF/FRCE LEDs blinking), the v2 replacement requires re-parameterizing the CP via HW Config (or TIA Portal device configuration), recompiling any user program that calls CP341 function blocks, and rewriting/importing any FB7/FB8 instances whose instance DB was generated from a pre-V3.1 block source. This article documents the exact migration steps, block versions, parameter differences, and the verification procedure that confirms the new CP341 is operational.

Prerequisites

Before you pull the v1 module out of the rack, confirm the following items are available. Each one is mandatory for a successful migration.

  1. CP341 v2 module, matched to the original interface:
    • 6ES7341-1AH02-0AE0 - RS232C (replaces v1: 6ES7341-1AH01-0AE0)
    • 6ES7341-1BH02-0AE0 - 20 mA/TTY (replaces v1: 6ES7341-1BH01-0AE0)
    • 6ES7341-1CH02-0AE0 - RS422/RS485 (replaces v1: 6ES7341-1CH01-0AE0)
  2. STEP 7 V5.5 + SP4 or later, or TIA Portal V13 SP2 / V14 / V15 or later with the CP341 V2 device support installed.
  3. HSP s7h2011x.hsp (newer HSPs bundle this module into the base catalog - verify with Hardware Catalog → SIMATIC 300 → Communication → CP 341).
  4. Configuration Package for Point to Point Communication V5.1 incl. SP9 (provides FB7/FB8 V3.1 and the project example zXX21_01). For newer engineering suites the package is named “Point-to-Point Communication CP 341 / CP 441”.
  5. Latest Siemens Support firmware update if the v2 module reports a firmware lower than V2.1.x. The example block ships compatible with CP341 v2.1.6 firmware.
  6. The original S7-300 project archive (STEP 7 .s7p / TIA Portal .ap14) and a clean working copy for the migration.
  7. Serial cable / 20 mA / RS422 wiring that is not changed - CP341 v2 uses the same front-connector pin-out and the same serial parameters selected in HW Config.

Hardware & Firmware Comparison

Both revisions are pin-compatible and use the same S7-300 peripheral address area. The differences that matter for the project are listed below.

Attribute CP341 v1 (6ES7 341-1xH01) CP341 v2 (6ES7 341-1xH02)
Hardware MLFB family 341-1AH01 / BH01 / CH01 341-1AH02 / BH02 / CH02
Shipped firmware V1.x V2.0.x default, upgradable to V2.1.6
HSP required Older s7h20xxx.hsp s7h2011x.hsp (or HSP-bundled baseline)
Configuration Package PtP CP 340/341 ≤ V5.0 PtP CP 340/341/441 V5.1 + SP9 (or newer)
FB7 (P_RCV_RK) version V2.x / V3.0 V3.1 mandatory; TIA Portal: V3.2 (min) / V3.3
FB8 (P_SND_RK) version V2.x / V3.0 V3.1 mandatory; TIA Portal: V3.2 (min) / V3.3
Diagnostic buffer Original Expanded event classes, identical SFC59 calls
Module footprint / front connector Identical (same MLFB physical design)
Peripheral address area Selected in HW Config Same - reuse original address slots

Function Block Versions Used with CP341 v2

The point-to-point function blocks used to drive the CP341 are part of the Standard Library → Communication Blocks in STEP 7, and Libraries → Communication → Point-to-Point in TIA Portal. The migration requires replacing older FB7/FB8 instances with the updated blocks.

Engineering tool Minimum FB7 / FB8 version Recommended version Source location
STEP 7 V5.5 SP4+ V3.1 (P_RCV_RK / P_SND_RK) V3.1 latest patch s7libs block library + project example zXX21_01
TIA Portal V13 SP2 V3.2 V3.3 “Point-to-Point Communication CP 340/CP 341/CP 441” configuration package
TIA Portal V14 / V15 V3.2 V3.3 Same package, install under “Options → Support Packages”

FB7 V3.1 and FB8 V3.1 carry corrected internal handling of the CP341 startup phase and tightened timing for RK 512 frame control. Older V2.x block versions that worked with CP341 v1 will compile but produce intermittent timeout faults (SFB / SFC error code W#16#0802) on CP341 v2.1.x because the firmware boots slightly faster.

Critical: Do not keep FB7/FB8 V2.x block code in your program simply because “it compiled.” The CP341 V2.1.x firmware expects the V3.1 (or newer) handshake; the older blocks will not fully handshake the initial “module ready” sequence and the CP will appear busy on every SS/SR trigger. Pull the new blocks from the configuration package and recompile every OB/FC/FB that references the CP341 instance DB.

Step-by-Step Migration Procedure (STEP 7 Classic)

Step 1 - Back up the existing project

  1. Open the STEP 7 project that targets the S7-300 station with the failed CP341 v1.
  2. Use File → Archive to create a .zip or .arc backup. Do not edit the working project until the migration is verified.
  3. Save under a new name (e.g. proj_v2_migration.s7p).

Step 2 - Install the HSP and configuration package

  1. Close STEP 7.
  2. Run s7h2011x.hsp from the HSP folder. Confirm CP 341 → 6ES7 341-1AH02 / 1BH02 / 1CH02 appears in the HW Catalog.
  3. Install the Configuration Package for Point to Point Communication V5.1 + SP9 (or newer). Accept all defaults.
  4. Restart STEP 7.

Step 3 - Swap the module in HW Config

  1. Open HW Config in the working copy of the project.
  2. Right-click the slot occupied by the CP341 v1 → Replace Object → select the v2 catalog entry that matches the original interface (RS232C / 20 mA / RS485).
  3. Confirm the same peripheral address (PI/PQ area) and same logical CP identifier (default: CP 341 (RS232C)) are kept. The CP identifier must match the LADDR input of FB7/FB8.
  4. Open Properties → Interface on the v2 module and re-apply the serial parameters exactly as they were set on v1 (baud, parity, data bits, stop bits, protocol type: ASCII / 3964 / 3964R / RK 512).
  5. Save and compile HW Config (Station → Save and Compile).

Step 4 - Update FB7 and FB8 instances

  1. Open Libraries → Standard Library → Communication Blocks (or the installed s7libs folder from the configuration package).
  2. Locate FB7 — > confirm the version stamp column reads V3.1 (or newer). If the column shows V2.x or V3.0, you are viewing the old library; re-check the configuration package installation.
  3. Locate FB8 — confirm V3.1 (or newer).
  4. In the project navigator, delete the old FB7 and FB8 instances from the program (do not delete the instance DB - you will overwrite it).
  5. Copy FB7 V3.1 and FB8 V3.1 from the library into your Blocks container. STEP 7 will either reuse the existing instance DBs or prompt you to regenerate them - accept regeneration; the new block initializes more status fields.
  6. Open each OB/FC/FB that calls FB7 or FB8 and verify the call interface matches the V3.1 signature:
    • REQ / ID / R / LADDR / DB_NO / DBB_NO / LEN / DONE / ERROR / STATUS
    • For P_SND_RK additionally SD_1 ... SD_4 and SENDLEN need values; if STATUS flags W#16#0A on the first call it means the CP has not yet finished startup - the V3.1 block handles this internally with a 1.5 s grace window.

Step 5 - Download to the CPU

  1. Connect the MPI/Profibus/Profinet programming cable.
  2. Power the S7-300 rack. Confirm the CP341 v2 OK and SF LEDs behavior after insertion: OK should be solid green within ~30 s; SF may flash during HW Config download.
  3. In STEP 7: PLC → Download to push the updated HW Config and the new FB7/FB8 + instance DBs to the CPU.
  4. Stop and restart the CPU so CP341 firmware re-initializes against the new project configuration.

Step-by-Step Migration Procedure (TIA Portal)

  1. Open the TIA Portal project. If the original was STEP 7, use File → Migration… to convert the project before editing.
  2. Open Options → Support Packages and install the “Point-to-Point Communication CP 340/CP 341/CP 441” package. Required FB version: V3.2 minimum, V3.3 recommended.
  3. Open Devices & Networks, delete the v1 CP341, and insert the v2 module on the same slot. Match the interface sub-module to the original protocol port (RS232C / RS485 / TTY).
  4. Re-apply the same protocol and interface parameters under Properties → Interface.
  5. In the project library, replace the CP341 instance blocks: drop new FB_PtP_Rcv / FB_PtP_Snd instances (TIA-side FBs that wrap FB7/FB8) or expose the underlying FB7/FB8 calls with V3.3 stamps.
  6. Compile (Hardware + Software), then Download to device.
  7. Restart the CPU; check the CP341 diagnostic buffer via Online & Diagnostics → Diagnostics Buffer. Expect one Module information: Module OK entry after power-up.

Block Interface Reference (FB7 V3.1 / FB8 V3.1)

Parameter (input/output) Direction Description
REQ IN Trigger pulse to start receive (FB7) or send (FB8)
ID / R IN Connection ID; R cancels an active job
LADDR IN Logical base address of the CP341 slot (decimal, e.g. 256)
DB_NO IN Data block number holding the user payload
DBB_NO IN Start byte offset within the data DB
LEN IN/OUT Length of data area (byte)
DONE OUT Job complete without error (TRUE pulse)
ERROR OUT Job terminated with error
STATUS OUT Word; carries W#16#xxxx status / error code
SENDLEN OUT (FB8 only) Actual bytes transmitted

CP341 Status / Error Code Reference

STATUS (hex) Meaning Action
0000 Job finished, no error None
0Axx CP startup phase, transparent transient V3.1+ block buffers it; do not R-trigger
0802 Timeout waiting for CP handshake Verify LADDR matches HW Config; update FB to V3.1 if pre-V3.1
0835 CP not in CP-STOP / no project data Re-download HW Config
0E81 Frame error on serial line Check baud, parity, cable
0E82 Parity / overrun on receive Check grounding, cable length
0E91 - 0E9F 3964(R) protocol violation Partner device timing out of CC gap
0F31 Internal firmware buffer overrun Reduce polling rate; switch to RK 512 if ASCII

Verification

  1. Diagnostic buffer: Online → CP341 → Diagnostic Buffer. The newest entry must read “Module OK”. Any “Parameter error” / “Wrong module in slot” entry means the HW Config replacement was not downloaded correctly.
  2. SF LED: Must be off after the CPU restart. If SF blinks at ~2 Hz, the FB versions in the program are older than V3.1 even though the catalog shows v2 hardware - delete the FB7/FB8 instances again and re-copy them from the library.
  3. Loopback test: Connect the TX and RX pins on the front connector (RS232: pins 2 ↔ 3 for CP end, with RTS/CTS strapped as needed for hardware flow control) and call FB8 with a test string. Call FB7 to read the echo. Done=TRUE on FB7 confirms the Ptp stack is fully operational.
  4. Live protocol test: With a partner device or a terminal emulator running on the same parameters, monitor traffic with Commissioning → Trace (STEP 7 V5.5+ Trace) or the Online Watch Table watching the CP341's send/receive DB area.
  5. Latency check: Time from REQ = 1 to DONE = 1 at 9600/8/N/1 ASCII should be < 100 ms per 100 bytes. Higher latency indicates a hardware flow-control misconfiguration (CTS/RTS) rather than a migration issue.

Field-Proven Caveats and Edge Cases

  • Same MLFB family, different revision digit. When ordering the v2 replacement, the MLFB differs only in the -xH02 digit (vs -xH01) - the catalog description is identical, which is why the v1 module is not auto-replaced by HW Config. Confirm the exact revision digit on the side label before insertion.
  • Firmware below V2.1.6. If the new module is supplied with firmware below V2.1.6, update via STEP 7 PLC → Module Information → Firmware Update with the latest CP341 firmware package. Older v2 firmware (≤ V2.0.5) is incompatible with FB7/FB8 V3.1 and will return STATUS = W#16#0A81 on the first job.
  • Instance DBs from V2.x blocks. Do not reuse the old instance DBs with V3.1 blocks. The V3.1 block reads new internal flags (e.g. internal_state, last_R_LENGTH) and will leave them in an undefined state.
  • TIA Portal project example zXX21_01. This project ships with FB7/FB8 V3.1 and is the reference for the parameter set used by the new CP341. Use it as a sanity baseline if your migration misbehaves: import the example, replace the CP identifier, and confirm the example program runs against your rack before diagnosing your migrated code.
  • STEP 7 vs TIA version skew. When the same physical CP341 v2 is addressed by both a STEP 7 V5.5 program and a TIA Portal project, the FB versions that physically run on the module are both valid (the block version is checked at CPU start-up, not at the CP). However, do not mix V3.1 (STEP 7) and V3.3 (TIA) blocks in the same project - the status word semantics differ in the 0Axx family.
  • Serial cable impedance. The physical wiring is unchanged, but if the original installation had an unusually long RS422 run (> 1200 m at low baud), the v2 firmware's tighter receiver threshold can surface ghost characters. Lower the baud rate or add a 120 Ω termination on the RS422 line.
Safety / Functional note: If the CP341 is part of a safety-relevant link (F-CPU-attached Ptp to a safety PLC via 3964R for example), do not hot-swap the v1 → v2 module without first putting the F-system into passivation and re-validating against the safety program. The FB version change (V2.x → V3.1) is not a SIL change, but the CRC over the instance DB will invalidate safety signatures.

Troubleshooting Matrix

Symptom on the v2 module Most Likely Root Cause Remediation
SF LED steady on after CPU restart FB7/FB8 still V2.x; or HSP not installed Recopy FB7/FB8 V3.1; reinstall s7h2011x.hsp
SF blinking 2 Hz Configuration package not installed Install PtP Configuration Package V5.1 SP9+
STATUS = 0A81 on first call CP firmware below V2.1.6 Perform firmware update
STATUS = 0802 on every call LADDR mismatch Cross-check LADDR against HW Config base address
Rx bytes present in trace, partner does not see Tx RTS/CTS jumpering on RS232C not restored Verify RTS-CTS and DTR-DSR/DSR jumpers per original wiring
Random 0E82 errors Cable impedance / ground differential Add 120 Ω termination or use shielded twisted pair
Done pulses never appear Old instance DB reused Regenerate the instance DB with V3.1 block initialization
TIA Portal: “device not in catalog” Wrong HSP for the TIA version Use the TIA Portal equivalent HSP bundled with the PtP configuration package

Standards & Reference Documentation

The replacement procedure is anchored in the following Siemens manuals and reference works. Each is the authoritative source for the section cited.

Do I have to replace FB7 and FB8 when I swap CP341 v1 for CP341 v2?

Yes. CP341 v2 firmware (V2.0.x and later) requires FB7 P_RCV_RK and FB8 P_SND_RK at version V3.1 in STEP 7 V5.5, or V3.2 / V3.3 in TIA Portal. Older V2.x blocks compile but they do not properly handshake the CP341 v2 startup, which causes intermittent STATUS = W#16#0802 timeouts.

Will the new CP341 v2 use the same LADDR and CP identifier as the v1 module?

Yes - if you keep the same slot and the same peripheral address in HW Config, the new module uses the same LADDR parameter in your program. The CP identifier shown under module properties (typically “CP 341 (RS232C)”) also carries over and does not need to be edited.

Which Configuration Package for Point-to-Point should I install?

Install the “Configuration Package for Point to Point Communication” V5.1 inclusive of SP9 (or newer) for STEP 7 V5.5. For TIA Portal V13 SP2, V14 and V15, install the “Point-to-Point Communication CP 340/CP 341/CP 441” package via Options → Support Packages. Both packages contain the corrected FB7/FB8 V3.1+ blocks and the example project zXX21_01.

Can I keep the same serial cable when I swap CP341 v1 for v2?

Yes. The front-connector pin-out, electrical characteristics (RS232C, 20 mA/TTY, RS422/RS485), and baud-rate range are unchanged between v1 (-xH01) and v2 (-xH02) modules. Power down the rack, swap the module, restore the front connector with the same wiring, then re-download HW Config and the program.

Do I need to update CP341 v2 firmware after installation?

Only if the module is supplied with firmware below V2.1.6. Use STEP 7 PLC → Module Information → Firmware Update with the latest CP341 firmware package. FB7/FB8 V3.1 expects at least V2.1.6 - older v2 firmware returns STATUS = W#16#0A81 on the first job.

Back to blog