Problem Overview: Error 8188 on MB_MASTER
When the legacy MB_MASTER instruction is called on a Siemens SIMATIC S7-1200 CPU (for example the S7-1215C) paired with a CM1241 (RS422/485) communications module in TIA Portal V15 or later, configuring MB_MODE = 106 returns error code 8188 in the STATUS output ("Invalid Mode specified for broadcast request"), while MB_MODE = 104 executes without raising the error. The same symptom appears on any CPU firmware that still resolves MB_MASTER from the legacy Modbus RTU library (V3.x or earlier). It also surfaces after migrating an older program to TIA Portal V18, V19, or V20 if the master block signature has not been re-linked to the current Modbus library.
The root cause is a documented discrepancy in the MB_MODE validation table: the Modbus RTU library distributed before V4.0 only accepts Modes 0 to 6, while the Modbus library V4.0 and later exposes Modes 100 to 116 that map one-to-one to standard Modbus function codes (FC 01 through FC 16). When the legacy block receives a Mode value it does not recognize, the validation logic inside FB 1105 fails the request and sets STATUS = 16#2004 (8188 decimal). The trigger condition is the combination of an unrecognized MB_MODE and the implicit broadcast address range (slave ID = 0 or address inside the 0xxxx coil space).
MB_MASTER — never a wiring, termination, or physical-layer problem. Treat it as a configuration error before swapping cables or RS485 terminators.Affected Hardware, Firmware, and Library Versions
| Component | Specification / Order Number | Behavior Notes |
|---|---|---|
| CPU | S7-1215C DC/DC/DC (6ES7215-1AG40-0XB0) or AC/DC/RLY (6ES7215-1BG40-0XB0) | Master block availability depends on CPU firmware |
| Communications module | CM1241 RS422/485 (6ES7241-1CH32-0XB0) | Provides Modbus RTU master/slave on the front-panel D-sub |
| TIA Portal | V15, V15.1, V16, V17, V18, V19, V20 | Modbus library catalog differs per release |
| CPU firmware observed | V2.2 (legacy MB_MASTER only) | Modes 104/106 are unrecognized values |
| CPU firmware | V4.0 – V4.6 (Modbus_Master) | Modes 101–116 supported |
| CPU firmware | V5.0+ (current Modbus_Master) | Recommended for new projects |
| Modbus library | "MODBUS" / "Modbus_RTU" V3.x or earlier | Contains MB_COMM_LOAD + MB_MASTER |
| Modbus library | "Modbus" V4.0 or later | Contains Modbus_Comm_Load + Modbus_Master |
On CPU firmware V2.2 the only available master is the legacy MB_MASTER (FB 1105). Starting with firmware V4.0, Siemens replaced it with the DB-based Modbus_Master (FB 1090). The two blocks coexist in a TIA Portal project library but cannot be cross-compiled without re-mapping the instance DB and the parameter list.
MB_MASTER vs. Modbus_Master: Block Comparison
| Attribute | MB_MASTER (legacy) | Modbus_Master (current) |
|---|---|---|
| Library source | "MODBUS" / "Modbus_RTU" V3.x or earlier | "Modbus" V4.0 or later |
| Companion block | MB_COMM_LOAD (FB 1106) | Modbus_Comm_Load (FB 1089) |
| Instance | Single multi-instance DB (CALL MB_MASTER, DBn) | One instance DB per connection (Modbus_Master_DB) |
| CPU firmware required | V1.0 – V3.x | V4.0 – V5.x |
| Read MB_MODE values | 0 (covers FC 01/02/03/04 by address class) | 0, 101, 102, 103, 104 |
| Write MB_MODE values | 5, 6, 15, 16 | 1, 2, 105, 106, 115, 116 |
| Mode 0 broadcast flag | Supported | Supported only with FC 01/02 read modes |
| STATUS = 8188 trigger | Unknown MB_MODE or write to broadcast range | Same root cause |
The mixed behavior reported in the source thread — Mode 104 working while Mode 106 fails — is the classic fingerprint of the V4.x+ Modbus_Master block sitting next to a CPU still running firmware V2.2 documentation. The user is most likely reading the TIA Portal V20 MB_MODE documentation while executing the legacy FB 1105.
MB_MODE, MB_DATA_ADDR, and MB_DATA_LEN Parameters
Per the TIA Portal V20 documentation for the Modbus TCP library versions V4.0 and later (applies structurally to Modbus RTU on the same firmware generation), MB_MODE carries both the read/write direction and the function-code mapping:
| MB_MODE | Direction | Modbus FC | Description |
|---|---|---|---|
| 0 | Read | 01 | Read Coils (address range 0xxxx) |
| 1 | Write | 05 | Write Single Coil |
| 2 | Write | 15 (0x0F) | Write Multiple Coils |
| 101 | Read | 02 | Read Discrete Inputs |
| 102 | Read | 03 | Read Holding Registers |
| 103 | Read | 04 | Read Input Registers |
| 104 | Read | 04 | Read Input Registers (alias) |
| 105 | Write | 06 | Write Single Register |
| 106 | Write | 06 | Write Single Register (alias) |
| 115 | Write | 16 (0x10) | Write Multiple Registers |
| 116 | Write | 16 (0x10) | Write Multiple Registers (alias) |
The TIA Portal redundant MB_RED_CLIENT documentation confirms the same Mode set for the V5.0+ library: "Read: MB_MODE = 0, 101, 102, 103 and 104. Write: MB_MODE = 1, 2, 105, 106, 115 and 116."
MB_MASTER 0/1/2/3/4/5/6 numbering while exposing the Modbus-native function codes to Modbus_Master. The library author chose 104/106/116 because they sit adjacent to the legacy 0/1/2 read codes and to the 1-series write codes.MB_DATA_ADDR: How the Address-Class Trick Works
Legacy MB_MASTER uses the Modbus address-class convention to infer the function code:
- 0xxxx → FC 01 (Read Coils)
- 1xxxx → FC 02 (Read Discrete Inputs)
- 3xxxx → FC 04 (Read Input Registers)
- 4xxxx → FC 03 (Read Holding Registers) and FC 06/16 writes
The block subtracts the address-class prefix before transmitting, so MB_DATA_ADDR = 30023 with MB_MODE = 0 sends FC 04 at Modbus register 22. This is the exact behavior reported in the source thread: 30023 + Mode 0 = function 04, address 22 on the wire.
Current Modbus_Master abandons the address-class trick and forces the user to specify MB_MODE explicitly. MB_DATA_ADDR is now the literal Modbus register address (1-based) with no prefix offset.
Root Cause Analysis
Three independent causes can produce STATUS 8188 with Modes 104 and 106:
-
Library/block mismatch. The legacy
MB_MASTER(FB 1105) shipped with library V3.x does not recognize Modes 101–116. The block's internal switch table only contains values 0–6 and a few reserved codes. When the call resolves to FB 1105 withMB_MODE= 106, the validation rejects the mode and returns 8188. Mode 104 may pass in some builds only because the validation includes an FC 04 escape through the address-class decoder when the function code is implied by the address prefix. - CPU firmware vs. library version skew. The S7-1200 System Manual specifies a minimum CPU firmware for each Modbus library version. Library V4.0 requires CPU firmware V4.0+; library V3.x is paired with firmware V2.2 – V3.x. If you compile a V15/V16/V17 project with library V4.x but download to a V2.2 CPU, the block signature and mode table diverge and 8188 appears.
-
Broadcast bit collision. For legacy
MB_MASTER, slave ID = 0 is the broadcast address. IfMB_DATA_ADDRevaluates inside the broadcast segment together with a write function code, the block returns 8188 to prevent accidental writes to all slaves. Mode 106 (FC 06) is a single-register write — it is legal, but only outside the broadcast address space (slave IDs 1–247).
Resolution Path Selection
Use the decision tree below to choose the correct fix.
Resolution Steps for Legacy MB_MASTER (Firmware V2.2)
- Open TIA Portal → project tree → "Program blocks". Locate the
MB_MASTERcall. - Read
MB_DATA_ADDRon the wire (capture with a Modbus sniffer if necessary). Identify the Modbus register the third-party slave expects. - Add the appropriate Modbus address-class prefix:
- FC 04 (Read Input Registers):
MB_DATA_ADDR= slave_register + 30000 - FC 03 (Read Holding Registers):
MB_DATA_ADDR= slave_register + 40000 - FC 06 (Write Single Register):
MB_DATA_ADDR= slave_register + 40000,MB_MODE= 6 - FC 16 (Write Multiple Registers):
MB_DATA_ADDR= slave_register + 40000,MB_MODE= 16
- FC 04 (Read Input Registers):
- Set
MB_MODE= 0 for reads and 5, 6, 15, or 16 for writes — never 101–116. - Compile and download. Watch
STATUSreturn 0.
Resolution Steps for Modbus_Master (Firmware V4.0+)
- Right-click "PLC → Program blocks → System blocks → Library". Confirm the "Modbus" library version is V4.0 or later and matches the CPU firmware generation.
- Delete the calls to
MB_COMM_LOADandMB_MASTER. - From "Libraries → Modbus → Master/Client", drag
Modbus_Comm_Load(FB 1089) andModbus_Master(FB 1090) into OB1. The library auto-creates an instance DB "Modbus_Master_DB". - Wire the parameters:
-
REQ: rising-edge trigger (e.g.,%M0.0from a 100 ms clock or a one-shot) -
MB_DB: connect to theModbus_Master_DBdata block -
MB_MODE: use 102 (FC 03), 104 (FC 04), 106 (FC 06), 116 (FC 16) -
MB_DATA_ADDR: literal slave register (no 3xxxx/4xxxx offset) -
MB_DATA_LEN: number of registers or coils to transfer (max 125 words per FC 03/04 request) -
MB_DATA_PTR: anyARRAY OF WORD,BOOL, orINTtag in a global DB
-
- Wire the
DONE,BUSY,ERROR, andSTATUSoutputs to your HMI or status DB. - Compile, download, and run online. Verify
STATUS= 0 on the first successful exchange.
Address-to-Function-Code Mapping Reference
| MB_DATA_ADDR range (legacy) | MB_MODE (legacy) | MB_MODE (current) | Modbus FC transmitted |
|---|---|---|---|
| 00001 – 09999 (read) | 0 | 0 | 01 Read Coils |
| 10001 – 19999 (read) | 0 | 101 | 02 Read Discrete Inputs |
| 30001 – 39999 (read) | 0 or 3 | 103 or 104 | 04 Read Input Registers |
| 40001 – 49999 (read) | 0 or 4 | 102 | 03 Read Holding Registers |
| 00001 – 09999 (write single) | 5 | 1 | 05 Write Single Coil |
| 00001 – 09999 (write multi) | 15 | 2 | 15 Write Multiple Coils |
| 40001 – 49999 (write single) | 6 | 105 or 106 | 06 Write Single Register |
| 40001 – 49999 (write multi) | 16 | 115 or 116 | 16 Write Multiple Registers |
Verification
- Trigger
REQonModbus_Masteronce for eachMB_MODEin use. ConfirmSTATUS= 0 and thatDONEpulses true for one scan. - Check the CM1241 diagnostic LEDs. The TX and RX LEDs must flicker at the expected polling rate; sustained OFF means the slave is not responding.
- Open "Online → Diagnostics → Diagnostic buffer" on the S7-1200. Confirm no entry references error W#16#2004 (8188) or W#16#80C8 (timeout).
- Capture the bus with a Modbus sniffer (e.g., a USB RS485 tap and Wireshark with the Modbus dissector). Validate that the transmitted packet shows the expected FC byte (04 for Mode 104, 06 for Mode 106) at the expected register.
- Force a write to a single register (Mode 106, register 1, value = 16#1234). Read back the same register with Mode 102. If the value matches, the round-trip is correct.
Compatibility Matrix: Library vs. CPU Firmware
| Modbus Library | S7-1200 CPU Firmware | Master Block | Supports Mode 104 | Supports Mode 106 |
|---|---|---|---|---|
| V3.x | V2.2 – V3.x | MB_MASTER (FB 1105) | No — use Mode 0 + 3xxxx | No — use Mode 6 + 4xxxx |
| V4.0 | V4.0 – V4.1 | Modbus_Master (FB 1090) | Yes | Yes |
| V4.1 | V4.2 | Modbus_Master | Yes | Yes |
| V5.0 | V4.4 – V4.6 | Modbus_Master | Yes | Yes |
| V6.0 | V5.0+ | Modbus_Master | Yes | Yes |
Troubleshooting Matrix
| Symptom | Likely Cause | Remediation |
|---|---|---|
| Mode 104 always returns 8188 | Legacy MB_MASTER on firmware V3.x or earlier | Switch to Modbus_Master on V4.x+ or use address-class trick |
| Mode 106 always returns 8188 | Legacy block, or write to broadcast range | Switch blocks; ensure slave ID is not 0 |
| 8188 only on first call after download | MB_COMM_LOAD / Modbus_Comm_Load not yet complete | Poll DONE of the load block before first master call |
| 8188 every cycle after first | Instance DB disconnected from MB_DB
|
Reconnect the instance DB; recompile |
| STATUS = 16#80C8 (timeout) | No response within Response Timeout | Increase timeout in MB_COMM_LOAD, check RS485 termination, validate slave ID |
| STATUS = 16#8380 (CRC) | Bus collision or parity mismatch | Match baud rate, parity, stop bits; add 120 Ω termination |
| STATUS = 16#8187 (invalid pointer) |
MB_DATA_PTR not a typed ARRAY
|
Declare a typed ARRAY OF WORD in a global DB |
Notes on Third-Party Devices
Many third-party Modbus slaves (variable-frequency drives, energy meters, environmental sensors) do not strictly follow the Modbus address-class convention. They expose input registers at low addresses (for example register 22) and require FC 04 regardless of the address. Two clean fixes exist:
-
Legacy firmware (V3.x or earlier): Specify
MB_DATA_ADDR= 30023 withMB_MODE= 0. The block subtracts the 3xxxx prefix and transmits FC 04 at Modbus register 22. This is the workaround observed in the source thread. -
Current firmware (V4.0+): Specify
MB_MODE= 104 withMB_DATA_ADDR= 22 (literal). The block transmits FC 04 at register 22 without any offset trick.
Both approaches send the identical byte sequence on the wire. Pick the one that matches your CPU firmware to avoid STATUS 8188.
Why does MB_MODE 106 give error 8188 on legacy MB_MASTER?
The legacy MB_MASTER (FB 1105) shipped with Modbus library V3.x only validates Modes 0–6 and rejects Modes 101–116. Mode 106 (FC 06 Write Single Register) is recognized only by the newer Modbus_Master (FB 1090) in library V4.0 and later. Mixing the block signature with the wrong library version causes 8188.
Can I use MB_MODE 104 and 106 on an S7-1215C with firmware V2.2?
No. Firmware V2.2 contains only the legacy MB_MASTER, which does not implement Modes 101–116. Either upgrade the CPU firmware to V4.0+ and switch to Modbus_Master, or use the address-prefix workaround (Mode 0 with a 3xxxx or 4xxxx range) to transmit FC 04 or FC 06.
What does STATUS 8188 mean?
STATUS 8188 = W#16#2004, "Invalid Mode specified for broadcast request". It indicates that MB_MODE is incompatible with the current MB_DATA_ADDR range (broadcast) or with the block firmware. Treat it as a configuration error, not a wiring or termination fault.
Is MB_MASTER still supported in TIA Portal V20?
MB_MASTER is retained for backward compatibility but Siemens recommends Modbus_Master on CPU firmware V4.0 and higher. TIA Portal V20 documentation covers Modbus TCP library versions V4.0 onward; the same Modes 102, 104, 106, and 116 apply. For a CPU still running V2.2 firmware, MB_MASTER remains the only option.
How do I read input register 22 from a third-party slave using MB_MASTER on firmware V2.2?
Use MB_MODE = 0 and MB_DATA_ADDR = 30023. The block strips the 3 prefix and transmits function code 04 at Modbus address 22, matching the third-party device mapping without needing Mode 104.