Running Modbus TCP and PROFINET I/O on a Siemens S7-300 CPU 315 PN/DP Integrated Port
The integrated PROFINET (PN) interface of a Siemens SIMATIC S7-300 CPU 315 PN/DP is not a single-purpose channel. The same physical Ethernet port can simultaneously carry PROFINET IO real-time traffic to distributed ET 200 stations and standard TCP/IP traffic for a Modbus TCP client or server role. This article documents the architectural basis, the exact software package required, and a deterministic configuration procedure to deploy both protocols on the on-board PN interface of a CPU 31x PN/DP without adding a separate CP card.
1. Problem Statement
A typical machine builder faces a brownfield integration problem: the existing machine uses an S7-300 with a PROFINET ring of ET 200S / ET 200SP / ET 200MP stations for distributed I/O, and a third-party device (variable frequency drive, weigh scale, energy meter, or a SCADA gateway) must be reached via Modbus TCP on the same machine. Adding a dedicated CP 343-1 or CP 343-1 Advanced for Modbus is the textbook solution, but it consumes a backplane slot, requires a separate IP address, an additional device in the PROFINET topology, and a longer project lead time.
The question is whether the single on-board PROFINET port of the CPU 315 PN/DP can handle both PROFINET RT/IRT IO and Modbus TCP in parallel, with no communication conflicts, and without any additional communication processor hardware.
2. PROFINET Interface Architecture
Every S7-300 CPU 31x PN/DP exposes a PROFINET device that is itself a 2-port switch. The on-board interface has two RJ45 sockets labelled Port 1 and Port 2, internally connected by a managed 2-port switch. This is documented in the Helmholz PROFINET-Switch FAQ, Version 2 (PDF), which states that “PROFINET participants mostly have 2 ports for the PROFINET cabling. The two ports are connected with one another by an internal 2-port switch component.”
Architectural consequences:
- Linear topology by default. Wiring Port 1 to the next PROFINET device and Port 2 to the previous one forms a line; no external switch is required to chain ET 200 stations.
- Star topology with an external switch. Inserting a managed PROFINET switch (Scalance XB-004, XC-100, etc.) at either port turns the topology into a star. The TIA Portal topology documentation confirms: “If you connect communication devices to a switch with more than two PROFINET ports, you automatically create a star network topology.”
- Ethernet frames coexist. The 2-port switch forwards both PROFINET RT frames (Ethernet type 0x8892) and standard TCP/IP frames (0x0800) on the same physical medium. PROFINET prioritises its own real-time frames via IEEE 802.1Q VLAN tagging, but the underlying silicon does not reject TCP/IP traffic.
The same silicon that drives the PROFINET channel is fully capable of transporting TCP/IP sockets for the user program. The Modbus TCP application is therefore not a "second protocol" competing for hardware; it is a standard TCP socket that is software-handled in parallel with the PROFINET stack.
3. Protocol Coexistence Model
The CPU 315 PN/DP runs the PROFINET stack as part of the firmware. The stack owns the port for PROFINET RT or IRT, with the configured update time, watchdog, and IRT top-down scheduling. The TCP/IP stack (used by the Modbus TCP FBs) is a second, independent software path that opens connections on the same IP address and MAC address. The two stacks do not exchange buffers; they only share the physical port and the IP address.
| Property | PROFINET IO | Modbus TCP |
|---|---|---|
| Transport layer | Real-time Ethernet (RT/IRT) on top of Layer 2 | TCP/IP, port 502 |
| EtherType | 0x8892 (PROFINET RT) | 0x0800 (IPv4) |
| Cycle model | Cyclic, deterministic, configured update time | Acyclic, request/response, on demand |
| Configuration | HW Config / TIA Portal device configuration | FB calls in user program (OB1/OB35) |
| Diagnostics | PN stack diagnostics, FB125 / PNIO_ALARM | FB return codes (status / error) |
| Conflict risk | None, if IP/subnet are consistent and PROFINET device name is unique | |
Because Modbus TCP and PROFINET use different EtherType fields and different transport layers, there is no protocol-level collision. The only shared resources are:
- The CPU's PN interface IP address (used by both PROFINET AR and the TCP socket).
- The MAC address table inside the integrated 2-port switch.
- The PN port's transmit bandwidth (typically 100 Mbit/s full duplex; 1 Gbit/s on the CPU 319-3 PN/DP X1 interface).
Field reports and the technical experience of integrators confirm that a correctly configured CPU 315 PN/DP runs PROFINET IO and Modbus TCP on the same integrated port with no communication conflicts. The Modbus TCP traffic is best-effort and is automatically throttled by the PROFINET priority handling of the switch silicon.
4. Required Software Package
To run Modbus TCP on a SIMATIC S7-300 PN CPU, you must install the optional software package ModbusTCP PN CPU, order number 2XV9450-1MB02. This is a separately licensed block library shipped by Siemens that contains the function blocks (FBs) and the UDTs required to build a Modbus TCP client or server in STEP 7 V5.x or TIA Portal (with S7-300 targets).
| Item | Value |
|---|---|
| Package name | ModbusTCP PN CPU |
| Siemens order number (MLFB) | 2XV9450-1MB02 |
| Target CPUs | S7-300 PN CPUs (CPU 31x PN/DP) |
| Engineering tool | STEP 7 V5.5 SP4+ or TIA Portal V13+ with S7-300 add-on |
| Role supported | Modbus TCP Client (master) and Modbus TCP Server (slave) |
| Connection count | Up to 16 concurrent Modbus TCP connections (CPU-firmware dependent) |
| Transport | RFC 1006 / ISO-on-TCP or native TCP, port 502 (configurable) |
The package must be installed on the engineering station (PG/PC) so that the FBs and the documentation PDF appear in the STEP 7 / TIA Portal library. The CPU firmware itself already contains the TCP/IP stack and the Open Communication FBs (FB63 TCON, FB64 TDISCON, FB65 TSEND, FB66 TRCV, FB67 TUSEND, FB68 TURCV) that the Modbus library calls internally. No CPU firmware update is required for the on-board PN port to act as a Modbus TCP peer; the library adds the application-layer protocol parsing and the data-base handling on top of the open TCP socket.
2XV9450-1MB02 is the runtime/engineering license and is required per project. There is no per-instance runtime royalty; one license covers all Modbus TCP connections on the licensed CPU. Always verify the latest release notes in the Siemens Industry Online Support portal before commissioning, as Siemens has issued version updates (for example 2XV9450-1MB02 with V3.x library) that add new FBs or fix edge cases with TCP keep-alive behaviour.5. Prerequisites
- CPU: S7-300 CPU 315 PN/DP (6ES7 315-2EH14-0AB0) or any 31x PN/DP variant with firmware supporting open communication (typically V2.6 or higher). Verify the firmware version in HW Config → CPU → Module Information → Firmware.
- Engineering tool: STEP 7 V5.5 SP4 (or higher) with the HSP for the CPU installed, or TIA Portal V13 SP1+ with the S7-300 add-on.
- Modbus library: ModbusTCP PN CPU 2XV9450-1MB02, installed in the same STEP 7 / TIA Portal version as the project.
- Network cabling: Two PROFINET patch cables (Cat 5e or higher) for the linear topology, or a managed switch (Scalance XC-100, XB-004, etc.) for star topology with the Modbus TCP device on a separate port.
- IP plan: One free IPv4 address for the CPU PN interface (default 192.168.0.1 is acceptable for prototyping), one address per ET 200 station, and one address for the Modbus TCP peer. All on the same subnet.
- PROFINET device name: Each PROFINET device (CPU and every ET 200) must have a unique device name assigned via the topology editor or via PRONETA.
6. Step-by-Step Configuration
6.1 Configure the PROFINET interface
- Open the S7 project in STEP 7 V5.5 or TIA Portal.
- Open HW Config and select the CPU 315 PN/DP.
- Double-click the PN-IO sub-module to open the PROFINET interface properties.
- Assign the IP address, subnet mask, and (optionally) router address. Example:
192.168.0.1/255.255.255.0. - In Properties → PROFINET, leave the integrated 2-port switch in Automatic mode; do not disable the switch.
- Add ET 200S / ET 200SP / ET 200MP stations from the catalog and connect them to Port 1 or Port 2 of the CPU. STEP 7 / TIA Portal will create a linear topology in the topology editor.
- Compile and download the hardware configuration. Assign the PROFINET device name to every IO device using the Assign PROFINET device name dialog (or use PRONETA for bulk assignment).
6.2 Install the ModbusTCP PN CPU library
- Run the ModbusTCP PN CPU setup from the Siemens installation media or from the Industry Online Support download for order number 2XV9450-1MB02.
- Restart STEP 7 / TIA Portal. The library appears under Libraries → ModbusPN (STEP 7) or as a global library in TIA Portal.
- Open the library documentation PDF to read the FB descriptions, instance DB requirements, and connection parameter UDTs.
6.3 Build the Modbus TCP client program
The library exposes FBs for client and server roles. The exact FB numbers depend on the library version (V2.x, V3.x). The typical structure is:
- Create a data block (instance DB) for the Modbus client FB call (for example,
DB100as the instance for FB100 "ModbusTCP_Client"). - Create a connection DB that defines the TCP connection parameters: remote IP, remote port (default 502), local port (0 = auto), and connection ID.
- Declare an instance of the
TCONparameter UDT (UDT65 in classic STEP 7) with the connection description; this is the structure the open-communication FBs require. - Call
FB63 TCONonce in OB100 (startup) or first scan to establish the TCP connection to the Modbus server. - Call the Modbus client FB in OB1 (or in a cyclic OB such as OB35 at 100 ms) with the request data and a read/write trigger.
- Poll the FB status and error outputs to drive the next request or to signal a fault to the HMI.
Minimal client call (illustrative, matches the ModbusTCP PN CPU V3.x signature):
// OB1 — Modbus TCP client cyclic call
// Read holding registers 40001..40010 from slave 192.168.0.50
CALL "ModbusTCP_Client", DB100
REQ := TRUE // rising edge triggers one request
UNIT := 1 // Modbus unit ID (typically 255 for TCP)
FUNCTION := 4 // 3=Read Holding, 4=Read Input, 6=Write Single, 16=Write Multiple
READ_START := 1 // start address in Modbus numbering
READ_QUANT := 10 // number of registers
WRITE_START:= 0
WRITE_QUANT:= 0
READ_DATA := P#DB200.DBX0.0 WORD 10 // target buffer for received registers
WRITE_DATA := // not used for read
BUSY := M100.0
DONE := M100.1
ERROR := M100.2
STATUS := MW102
CON_ID := 1 // matches CON_ID in TCON config
The CON_ID value must match the id field in the TCON parameter description (UDT65). The TCON is started once in OB100:
// OB100 — Establish TCP connection to Modbus server
CALL "TCON", DB120
REQ := TRUE
ID := 1 // connection ID = 1
CONNECT := P#DB121.DBX0.0 BYTE 64 // pointer to TCON_PAR UDT65
DONE := M110.0
BUSY := M110.1
ERROR := M110.2
STATUS := MW112
6.4 Compile, download, and go online
- Compile the S7 program and download to the CPU.
- Switch the CPU to RUN. The PROFINET ARs come up; the ET 200 stations are reachable in the diagnostic buffer.
- Open a watch table on the Modbus instance DB and verify that
BUSYtoggles,DONEis set, andERRORstays 0. - Trigger a single read and confirm the buffer in DB200 contains the expected values from the Modbus server.
7. Network Topology and Port Behaviour
Two valid physical topologies are common in the field:
7.1 Linear topology (recommended for small cells)
CPU 315 PN/DP Port 1 → ET 200 #1 Port 1 → ET 200 #1 Port 2 → ET 200 #2 Port 1 → ... → last ET 200 Port 2. The Modbus TCP device is connected to the spare Port 2 of the last ET 200 station, or to the spare Port 1 / Port 2 of the CPU. Because ET 200 PN stations are also 2-port switches, the linear line naturally extends and the Modbus TCP device sits at the end of the line. PROFINET RT update times of 1 ms to 4 ms are supported across 8 to 16 stations in this topology.
7.2 Star topology (recommended when scaling)
CPU 315 PN/DP Port 1 → Scalance XC-100 (or any managed PROFINET switch) → ET 200 stations + Modbus TCP device. The TIA Portal topology editor will show the star with the switch as a central node. Star topology is preferred when the Modbus TCP device generates a lot of broadcast traffic, because the switch isolates the broadcast domain and the PROFINET diagnostics remain clean.
8. Performance and Timing
Modbus TCP on the S7-300 PN CPU is implemented on top of the Open Communication (T-Block) firmware path. Each request/response cycle is non-deterministic by design; it is bounded by the OB1 cycle time, the TCP stack processing, and the switch port latency. Typical measured values on a CPU 315-2 PN/DP (firmware V3.3):
| Operation | Round-trip time, local switch | Round-trip time, 3-hop star |
|---|---|---|
| Read 1 register (FC03) | 3–6 ms | 5–10 ms |
| Read 100 registers (FC03) | 8–15 ms | 12–25 ms |
| Write 1 register (FC06) | 3–6 ms | 5–10 ms |
| Write 100 registers (FC16) | 10–18 ms | 15–30 ms |
These values are field-typical and should be confirmed with a Wireshark capture and a stopwatch in the commissioning phase. The PROFINET update time does not directly impact Modbus TCP round-trip time, but a very short PROFINET update (250 µs with IRT) can starve the OB1 cycle if the OB1 has heavy TCP processing; in that case move the Modbus FBs into OB35 (100 ms cyclic) to keep the IRT phase free.
9. Diagnostics and Verification
- PROFINET diagnostics: In HW Config, go online with the CPU and open the online view of the PROFINET IO system. All ET 200 stations must show green "OK". Use Module Information → IO Device Diagnostics to read the per-port link state, frame errors, and discard counters.
-
Modbus TCP diagnostics: Use the
STATUSandERRORoutputs of the Modbus client FB. The Siemens library maps Modbus exception codes (0x01 illegal function, 0x02 illegal data address, 0x03 illegal data value, 0x04 slave device failure) to status words. Cross-reference with the library documentation. - Wire-level check: Mirror the CPU port on a managed switch (Scalance XC-200 mirror port), connect a laptop with Wireshark, and capture the traffic. PROFINET RT frames will appear as EtherType 0x8892, Modbus TCP as TCP port 502 traffic.
-
CPU diagnostic buffer: PLC → Diagnostic Buffer in STEP 7 / TIA Portal. Look for PNIO events (link up/down, AR established, watchdog expired) and Open Communication events (TCP connection established/closed, TCON errors with status
W#16#80A1for remote partner not reachable, etc.).
10. Troubleshooting Matrix
| Symptom | Likely cause | Action |
|---|---|---|
| PROFINET stations go into station failure after the Modbus FB is downloaded | Duplicate IP address between the CPU and the Modbus server | Re-IP the Modbus server to a free address in the same subnet; verify with ARP ping |
| TCON returns status W#16#80A1 / W#16#80A7 | Modbus server is offline, wrong port, or firewall on the server | Test with a Modbus poll tool (e.g. Modbus Poll, CAS Modbus Scanner) from a PG on the same subnet; verify port 502 is open |
| PROFINET runs, Modbus returns error 0x04 (slave device failure) | Modbus server is overloaded or the requested quantity exceeds the server's holding/input range | Reduce READ_QUANT / WRITE_QUANT; confirm register map with the device vendor |
| Modbus data updates only on every second or third OB1 scan | REQ is held high instead of being a one-shot pulse | Use a rising-edge detector on REQ; the library processes one transaction per REQ pulse |
| CPU goes into STOP with SF LED on after enabling the Modbus FB | Library version mismatch with the CPU firmware; FBs require a newer firmware | Check the compatibility matrix in the library PDF; update the CPU firmware if required |
| Wireshark shows TCP retransmissions on port 502 | Switch or cable saturating; PROFINET IRT starving TCP | Move Modbus polling to OB35 with 100–500 ms period; check for broadcast storms from the Modbus device |
| Modbus client works, then stops after a few hours | TCP keep-alive is not enabled; intermediate switch ages the ARP entry | Enable keep-alive in the TCON UDT; set local and partner keep-alive to 30 s |
| PROFINET diagnostic: "Device name assignment error" on a station downstream of the Modbus device | The Modbus device is a non-PNIO switch and is forwarding DCP with the wrong device name | Replace the unmanaged switch with a PNO-certified switch, or place the Modbus device on a separate branch with its own switch |
11. Best-Practice Checklist
- Plan the IP plan first: CPU PN, every ET 200, and the Modbus peer all on the same subnet, no overlap.
- Keep PROFINET device names unique and meaningful (for example
cpu315-pn,et200s-line1-station03). - Use a managed PROFINET switch (Scalance XC-100 or higher) at any branch point to isolate broadcast and to enable port mirroring for Wireshark.
- Place the Modbus FBs in a cyclic OB (OB35 at 100–500 ms) to keep OB1 free for PROFINET diagnostics.
- Document the Modbus register map (function code, start address, quantity, units) in the project functional specification.
- Enable TCP keep-alive in the TCON UDT to recover from silent partner drop-outs.
- Cross-check the installed library version (ModbusTCP PN CPU 2XV9450-1MB02 Vx.x) against the CPU firmware version in the compatibility matrix shipped with the library.
12. Frequently Asked Questions
Can the S7-300 CPU 315 PN/DP run PROFINET I/O and Modbus TCP on the same integrated port at the same time?
Yes. The on-board PROFINET interface is a managed 2-port switch that forwards both PROFINET RT frames (EtherType 0x8892) and standard IPv4 TCP traffic. The PROFINET stack and the Open Communication TCP stack share the silicon but use independent software paths, so there is no protocol-level conflict.
Do I need an extra CP 343-1 communication processor for Modbus TCP?
No, not for typical 1–4 connection Modbus TCP workloads. You do need the optional software package ModbusTCP PN CPU (Siemens order number 2XV9450-1MB02) installed on the engineering station and the FBs from that library in the S7 program. The TCP/IP stack is already in the CPU firmware.
How many Modbus TCP connections can the CPU 315 PN/DP handle in parallel?
Up to 16 Open Communication connections, depending on CPU firmware version and OB cycle load. The practical limit is usually driven by the OB1/OB35 cycle time and the number of PROFINET IO devices, not by the Modbus connection count. If you need more than 8–10 concurrent Modbus peers with short cycle times, evaluate moving Modbus to a CP 343-1 Advanced.
Does the Modbus TCP library add CPU scan time?
Yes, proportionally to the number of Modbus transactions per OB cycle. A single Modbus read/write inside OB1 typically adds 0.3–1.5 ms. To protect the PROFINET update time, place the Modbus FBs in a slower cyclic OB (OB35 at 100 ms or 200 ms).
What happens if the Modbus TCP server is offline when the CPU starts?
The TCON call will return status W#16#80A1 or W#16#80A7 (remote partner not reachable). The Modbus client FB will report ERROR and STATUS, and the application should implement a retry / fallback strategy (for example, hold last good value, raise an HMI alarm, and retry every 5 s). PROFINET IO is not affected by the Modbus server state.
Is the same approach valid for S7-1500 or ET 200SP CPUs?
The principle is identical, but the library differs. S7-1500 uses the "Modbus TCP" library supplied with TIA Portal (LCom_Modbus or MB_CLIENT / MB_SERVER from the "MODBUS TCP" palette) and does not require order number 2XV9450-1MB02. The package 2XV9450-1MB02 is specific to the S7-300 PN CPU line.