Resolving MB_MASTER Error 8188: S7-1200 Modbus Mode 104/106

David Krause11 min read
ModbusSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview: Error 8188 on MB_MASTER

When the legacy MB_MASTER instruction is called on a Siemens SIMATIC S7-1200 CPU (for example the S7-1215C) paired with a CM1241 (RS422/485) communications module in TIA Portal V15 or later, configuring MB_MODE = 106 returns error code 8188 in the STATUS output ("Invalid Mode specified for broadcast request"), while MB_MODE = 104 executes without raising the error. The same symptom appears on any CPU firmware that still resolves MB_MASTER from the legacy Modbus RTU library (V3.x or earlier). It also surfaces after migrating an older program to TIA Portal V18, V19, or V20 if the master block signature has not been re-linked to the current Modbus library.

The root cause is a documented discrepancy in the MB_MODE validation table: the Modbus RTU library distributed before V4.0 only accepts Modes 0 to 6, while the Modbus library V4.0 and later exposes Modes 100 to 116 that map one-to-one to standard Modbus function codes (FC 01 through FC 16). When the legacy block receives a Mode value it does not recognize, the validation logic inside FB 1105 fails the request and sets STATUS = 16#2004 (8188 decimal). The trigger condition is the combination of an unrecognized MB_MODE and the implicit broadcast address range (slave ID = 0 or address inside the 0xxxx coil space).

Critical: STATUS 8188 always indicates a parameter-level fault inside MB_MASTER — never a wiring, termination, or physical-layer problem. Treat it as a configuration error before swapping cables or RS485 terminators.

Affected Hardware, Firmware, and Library Versions

Component Specification / Order Number Behavior Notes
CPU S7-1215C DC/DC/DC (6ES7215-1AG40-0XB0) or AC/DC/RLY (6ES7215-1BG40-0XB0) Master block availability depends on CPU firmware
Communications module CM1241 RS422/485 (6ES7241-1CH32-0XB0) Provides Modbus RTU master/slave on the front-panel D-sub
TIA Portal V15, V15.1, V16, V17, V18, V19, V20 Modbus library catalog differs per release
CPU firmware observed V2.2 (legacy MB_MASTER only) Modes 104/106 are unrecognized values
CPU firmware V4.0 – V4.6 (Modbus_Master) Modes 101–116 supported
CPU firmware V5.0+ (current Modbus_Master) Recommended for new projects
Modbus library "MODBUS" / "Modbus_RTU" V3.x or earlier Contains MB_COMM_LOAD + MB_MASTER
Modbus library "Modbus" V4.0 or later Contains Modbus_Comm_Load + Modbus_Master

On CPU firmware V2.2 the only available master is the legacy MB_MASTER (FB 1105). Starting with firmware V4.0, Siemens replaced it with the DB-based Modbus_Master (FB 1090). The two blocks coexist in a TIA Portal project library but cannot be cross-compiled without re-mapping the instance DB and the parameter list.

MB_MASTER vs. Modbus_Master: Block Comparison

Attribute MB_MASTER (legacy) Modbus_Master (current)
Library source "MODBUS" / "Modbus_RTU" V3.x or earlier "Modbus" V4.0 or later
Companion block MB_COMM_LOAD (FB 1106) Modbus_Comm_Load (FB 1089)
Instance Single multi-instance DB (CALL MB_MASTER, DBn) One instance DB per connection (Modbus_Master_DB)
CPU firmware required V1.0 – V3.x V4.0 – V5.x
Read MB_MODE values 0 (covers FC 01/02/03/04 by address class) 0, 101, 102, 103, 104
Write MB_MODE values 5, 6, 15, 16 1, 2, 105, 106, 115, 116
Mode 0 broadcast flag Supported Supported only with FC 01/02 read modes
STATUS = 8188 trigger Unknown MB_MODE or write to broadcast range Same root cause

The mixed behavior reported in the source thread — Mode 104 working while Mode 106 fails — is the classic fingerprint of the V4.x+ Modbus_Master block sitting next to a CPU still running firmware V2.2 documentation. The user is most likely reading the TIA Portal V20 MB_MODE documentation while executing the legacy FB 1105.

MB_MODE, MB_DATA_ADDR, and MB_DATA_LEN Parameters

Per the TIA Portal V20 documentation for the Modbus TCP library versions V4.0 and later (applies structurally to Modbus RTU on the same firmware generation), MB_MODE carries both the read/write direction and the function-code mapping:

MB_MODE Direction Modbus FC Description
0 Read 01 Read Coils (address range 0xxxx)
1 Write 05 Write Single Coil
2 Write 15 (0x0F) Write Multiple Coils
101 Read 02 Read Discrete Inputs
102 Read 03 Read Holding Registers
103 Read 04 Read Input Registers
104 Read 04 Read Input Registers (alias)
105 Write 06 Write Single Register
106 Write 06 Write Single Register (alias)
115 Write 16 (0x10) Write Multiple Registers
116 Write 16 (0x10) Write Multiple Registers (alias)

The TIA Portal redundant MB_RED_CLIENT documentation confirms the same Mode set for the V5.0+ library: "Read: MB_MODE = 0, 101, 102, 103 and 104. Write: MB_MODE = 1, 2, 105, 106, 115 and 116."

Key observation: Modes 103 and 104 both map to FC 04; Modes 105 and 106 both map to FC 06; Modes 115 and 116 both map to FC 16. The duplicate modes preserve the legacy MB_MASTER 0/1/2/3/4/5/6 numbering while exposing the Modbus-native function codes to Modbus_Master. The library author chose 104/106/116 because they sit adjacent to the legacy 0/1/2 read codes and to the 1-series write codes.

MB_DATA_ADDR: How the Address-Class Trick Works

Legacy MB_MASTER uses the Modbus address-class convention to infer the function code:

  • 0xxxx → FC 01 (Read Coils)
  • 1xxxx → FC 02 (Read Discrete Inputs)
  • 3xxxx → FC 04 (Read Input Registers)
  • 4xxxx → FC 03 (Read Holding Registers) and FC 06/16 writes

The block subtracts the address-class prefix before transmitting, so MB_DATA_ADDR = 30023 with MB_MODE = 0 sends FC 04 at Modbus register 22. This is the exact behavior reported in the source thread: 30023 + Mode 0 = function 04, address 22 on the wire.

Current Modbus_Master abandons the address-class trick and forces the user to specify MB_MODE explicitly. MB_DATA_ADDR is now the literal Modbus register address (1-based) with no prefix offset.

Root Cause Analysis

Three independent causes can produce STATUS 8188 with Modes 104 and 106:

  1. Library/block mismatch. The legacy MB_MASTER (FB 1105) shipped with library V3.x does not recognize Modes 101–116. The block's internal switch table only contains values 0–6 and a few reserved codes. When the call resolves to FB 1105 with MB_MODE = 106, the validation rejects the mode and returns 8188. Mode 104 may pass in some builds only because the validation includes an FC 04 escape through the address-class decoder when the function code is implied by the address prefix.
  2. CPU firmware vs. library version skew. The S7-1200 System Manual specifies a minimum CPU firmware for each Modbus library version. Library V4.0 requires CPU firmware V4.0+; library V3.x is paired with firmware V2.2 – V3.x. If you compile a V15/V16/V17 project with library V4.x but download to a V2.2 CPU, the block signature and mode table diverge and 8188 appears.
  3. Broadcast bit collision. For legacy MB_MASTER, slave ID = 0 is the broadcast address. If MB_DATA_ADDR evaluates inside the broadcast segment together with a write function code, the block returns 8188 to prevent accidental writes to all slaves. Mode 106 (FC 06) is a single-register write — it is legal, but only outside the broadcast address space (slave IDs 1–247).

Resolution Path Selection

Use the decision tree below to choose the correct fix.

MB_MASTER returns 8188? CPU firmware < V4.0? Use legacy MB_MASTER with address-class trick (Mode 0 + 3xxxx / 4xxxx) Library = V4.0 or higher? Switch to Modbus_Master FB 1090, Modes 102/104/106 Confirm: STATUS = 0, DONE = 1

Resolution Steps for Legacy MB_MASTER (Firmware V2.2)

  1. Open TIA Portal → project tree → "Program blocks". Locate the MB_MASTER call.
  2. Read MB_DATA_ADDR on the wire (capture with a Modbus sniffer if necessary). Identify the Modbus register the third-party slave expects.
  3. Add the appropriate Modbus address-class prefix:
    • FC 04 (Read Input Registers): MB_DATA_ADDR = slave_register + 30000
    • FC 03 (Read Holding Registers): MB_DATA_ADDR = slave_register + 40000
    • FC 06 (Write Single Register): MB_DATA_ADDR = slave_register + 40000, MB_MODE = 6
    • FC 16 (Write Multiple Registers): MB_DATA_ADDR = slave_register + 40000, MB_MODE = 16
  4. Set MB_MODE = 0 for reads and 5, 6, 15, or 16 for writes — never 101–116.
  5. Compile and download. Watch STATUS return 0.

Resolution Steps for Modbus_Master (Firmware V4.0+)

  1. Right-click "PLC → Program blocks → System blocks → Library". Confirm the "Modbus" library version is V4.0 or later and matches the CPU firmware generation.
  2. Delete the calls to MB_COMM_LOAD and MB_MASTER.
  3. From "Libraries → Modbus → Master/Client", drag Modbus_Comm_Load (FB 1089) and Modbus_Master (FB 1090) into OB1. The library auto-creates an instance DB "Modbus_Master_DB".
  4. Wire the parameters:
    • REQ: rising-edge trigger (e.g., %M0.0 from a 100 ms clock or a one-shot)
    • MB_DB: connect to the Modbus_Master_DB data block
    • MB_MODE: use 102 (FC 03), 104 (FC 04), 106 (FC 06), 116 (FC 16)
    • MB_DATA_ADDR: literal slave register (no 3xxxx/4xxxx offset)
    • MB_DATA_LEN: number of registers or coils to transfer (max 125 words per FC 03/04 request)
    • MB_DATA_PTR: any ARRAY OF WORD, BOOL, or INT tag in a global DB
  5. Wire the DONE, BUSY, ERROR, and STATUS outputs to your HMI or status DB.
  6. Compile, download, and run online. Verify STATUS = 0 on the first successful exchange.

Address-to-Function-Code Mapping Reference

MB_DATA_ADDR range (legacy) MB_MODE (legacy) MB_MODE (current) Modbus FC transmitted
00001 – 09999 (read) 0 0 01 Read Coils
10001 – 19999 (read) 0 101 02 Read Discrete Inputs
30001 – 39999 (read) 0 or 3 103 or 104 04 Read Input Registers
40001 – 49999 (read) 0 or 4 102 03 Read Holding Registers
00001 – 09999 (write single) 5 1 05 Write Single Coil
00001 – 09999 (write multi) 15 2 15 Write Multiple Coils
40001 – 49999 (write single) 6 105 or 106 06 Write Single Register
40001 – 49999 (write multi) 16 115 or 116 16 Write Multiple Registers

Verification

  1. Trigger REQ on Modbus_Master once for each MB_MODE in use. Confirm STATUS = 0 and that DONE pulses true for one scan.
  2. Check the CM1241 diagnostic LEDs. The TX and RX LEDs must flicker at the expected polling rate; sustained OFF means the slave is not responding.
  3. Open "Online → Diagnostics → Diagnostic buffer" on the S7-1200. Confirm no entry references error W#16#2004 (8188) or W#16#80C8 (timeout).
  4. Capture the bus with a Modbus sniffer (e.g., a USB RS485 tap and Wireshark with the Modbus dissector). Validate that the transmitted packet shows the expected FC byte (04 for Mode 104, 06 for Mode 106) at the expected register.
  5. Force a write to a single register (Mode 106, register 1, value = 16#1234). Read back the same register with Mode 102. If the value matches, the round-trip is correct.

Compatibility Matrix: Library vs. CPU Firmware

Modbus Library S7-1200 CPU Firmware Master Block Supports Mode 104 Supports Mode 106
V3.x V2.2 – V3.x MB_MASTER (FB 1105) No — use Mode 0 + 3xxxx No — use Mode 6 + 4xxxx
V4.0 V4.0 – V4.1 Modbus_Master (FB 1090) Yes Yes
V4.1 V4.2 Modbus_Master Yes Yes
V5.0 V4.4 – V4.6 Modbus_Master Yes Yes
V6.0 V5.0+ Modbus_Master Yes Yes
Matching rule: The Modbus library minor version (e.g., V5.0) and the CPU firmware major (e.g., V4.x for S7-1200) must align. Mismatches cause silent parameter-table divergences that surface as 8188 only after several thousand scan cycles.

Troubleshooting Matrix

Symptom Likely Cause Remediation
Mode 104 always returns 8188 Legacy MB_MASTER on firmware V3.x or earlier Switch to Modbus_Master on V4.x+ or use address-class trick
Mode 106 always returns 8188 Legacy block, or write to broadcast range Switch blocks; ensure slave ID is not 0
8188 only on first call after download MB_COMM_LOAD / Modbus_Comm_Load not yet complete Poll DONE of the load block before first master call
8188 every cycle after first Instance DB disconnected from MB_DB Reconnect the instance DB; recompile
STATUS = 16#80C8 (timeout) No response within Response Timeout Increase timeout in MB_COMM_LOAD, check RS485 termination, validate slave ID
STATUS = 16#8380 (CRC) Bus collision or parity mismatch Match baud rate, parity, stop bits; add 120 Ω termination
STATUS = 16#8187 (invalid pointer) MB_DATA_PTR not a typed ARRAY Declare a typed ARRAY OF WORD in a global DB

Notes on Third-Party Devices

Many third-party Modbus slaves (variable-frequency drives, energy meters, environmental sensors) do not strictly follow the Modbus address-class convention. They expose input registers at low addresses (for example register 22) and require FC 04 regardless of the address. Two clean fixes exist:

  • Legacy firmware (V3.x or earlier): Specify MB_DATA_ADDR = 30023 with MB_MODE = 0. The block subtracts the 3xxxx prefix and transmits FC 04 at Modbus register 22. This is the workaround observed in the source thread.
  • Current firmware (V4.0+): Specify MB_MODE = 104 with MB_DATA_ADDR = 22 (literal). The block transmits FC 04 at register 22 without any offset trick.

Both approaches send the identical byte sequence on the wire. Pick the one that matches your CPU firmware to avoid STATUS 8188.

Why does MB_MODE 106 give error 8188 on legacy MB_MASTER?

The legacy MB_MASTER (FB 1105) shipped with Modbus library V3.x only validates Modes 0–6 and rejects Modes 101–116. Mode 106 (FC 06 Write Single Register) is recognized only by the newer Modbus_Master (FB 1090) in library V4.0 and later. Mixing the block signature with the wrong library version causes 8188.

Can I use MB_MODE 104 and 106 on an S7-1215C with firmware V2.2?

No. Firmware V2.2 contains only the legacy MB_MASTER, which does not implement Modes 101–116. Either upgrade the CPU firmware to V4.0+ and switch to Modbus_Master, or use the address-prefix workaround (Mode 0 with a 3xxxx or 4xxxx range) to transmit FC 04 or FC 06.

What does STATUS 8188 mean?

STATUS 8188 = W#16#2004, "Invalid Mode specified for broadcast request". It indicates that MB_MODE is incompatible with the current MB_DATA_ADDR range (broadcast) or with the block firmware. Treat it as a configuration error, not a wiring or termination fault.

Is MB_MASTER still supported in TIA Portal V20?

MB_MASTER is retained for backward compatibility but Siemens recommends Modbus_Master on CPU firmware V4.0 and higher. TIA Portal V20 documentation covers Modbus TCP library versions V4.0 onward; the same Modes 102, 104, 106, and 116 apply. For a CPU still running V2.2 firmware, MB_MASTER remains the only option.

How do I read input register 22 from a third-party slave using MB_MASTER on firmware V2.2?

Use MB_MODE = 0 and MB_DATA_ADDR = 30023. The block strips the 3 prefix and transmits function code 04 at Modbus address 22, matching the third-party device mapping without needing Mode 104.

Back to blog