S7-300 Modbus Communication: CP 341 and CP 343-1 Reference

David Krause16 min read
ModbusSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Integrating an S7-300 PLC into a brownfield multi-vendor network is a recurring problem in plant engineering. A typical topology pairs a Siemens SIMATIC S7-300 CPU (such as the CPU 313C, 314, 315-2 DP, or 317-2) with a Rockwell Automation ControlLogix 5555 master and Schneider Electric Modicon M340 or Premium stations. Each vendor uses its own fieldbus heritage: Siemens relies on PROFIBUS and PROFINET, Rockwell on EtherNet/IP, ControlNet, and DeviceNet, and Schneider on Modbus RTU/TCP, plus legacy Fipway/Unitelway.

When a Siemens controller must appear as a Modbus RTU slave on RS-485, a Modbus/TCP server on Ethernet, or a Modbus master polling third-party devices, the selection of communication processor (CP), interface module (IM), or serial submodule is dictated by the bus, the protocol role, and the licensing of the loadable driver. This reference consolidates the hardware catalog numbers, driver licenses, STEP 7 V4.2 (and later) configuration steps, and diagnostic utilities required to plan, commission, and troubleshoot a Siemens S7-300 node on a mixed-bus plant network that also includes a ControlLogix 5555 acting as a multi-protocol gateway.

Multi-Vendor Network Architecture

The reference architecture is a layered industrial network where the ControlLogix 5555 (1756-L55) hosts a 1756-ENBT EtherNet/IP module, a 1756-DHRIO Data Highway Plus / Remote I/O module, and a 1756-DNB DeviceNet scanner. To bridge into the Siemens segment, the ControlLogix uses either a 1756-EN2T plus an external Modbus/TCP-to-PROFINET gateway (e.g., a ProSoft or HMS Anybus X-gateway), or communicates to the S7-300 over an explicit EtherNet/IP-to-Modbus/TCP path.

On the Siemens side, the S7-300 is the Modbus peer. Three hardware paths exist for Modbus connectivity, each with a different cost and footprint:

  • CP 341 serial communication processor for Modbus RTU or ASCII on RS-232C, TTY, or RS-485.
  • CP 343-1 Ethernet communication processor for Modbus/TCP on the plant LAN.
  • ET 200S 1SI (6ES7138-4DF11-0AB0) serial interface submodule when the S7-300 is deployed on PROFIBUS-DP or PROFINET and a distributed ET 200S station is already in place.

An additional path not covered in the field report is the IM 151-1 PROFIBUS interface module referenced in some legacy deployments, but it is limited to PROFIBUS and does not natively carry a Modbus profile, so it is excluded from the Modbus-focused selection.

CP 341 Modbus RTU Hardware Selection

The CP 341 is the standard S7-300 serial communication processor for point-to-point and multi-drop protocols including Modbus RTU, Modbus ASCII, RK512, 3964(R), and ASCII driver. Three variants exist, selected by physical interface and not by protocol. The protocol is licensed separately through a loadable driver on a hardware dongle.

MLFB Description Interface Typical Use
6ES7341-0AH01-0AE0 CP 341 RS-232C variant RS-232C (D-sub 9) Modbus RTU to a single device, short cable, point-to-point
6ES7341-1BH01-0AE0 CP 341 TTY variant TTY (20 mA current loop) Legacy panel meters and drives, noise-immune, isolated
6ES7341-1CH01-0AE0 CP 341 RS-485/RS-422 variant RS-485/RS-422 (D-sub 15) Modbus RTU multi-drop, up to 32 nodes, half- or full-duplex

For a multi-vendor network where the S7-300 acts as either Modbus master or slave on a 2-wire RS-485 trunk, the 6ES7341-1CH01-0AE0 is the correct selection. For an RS-232C connection to a single VFD or weigh scale, choose 6ES7341-0AH01-0AE0. The TTY variant is rarely used in greenfield Modbus work but is still required for some legacy Telemechanique and Modicon devices.

The CP 341 occupies one slot in the S7-300 rack. It supports up to 1.5 Mbaud on the RS-232C and RS-485/RS-422 variants; Modbus RTU is typically operated at 9600, 19200, or 38400 baud with even parity, 8 data bits, 1 stop bit (8E1). A diagnostic LED strip on the front of the module indicates SF (group fault), BF (bus fault), and TX/RX activity for fault isolation.

CP 343-1 Modbus/TCP Hardware

For Modbus/TCP, the S7-300 requires an Ethernet CP. The CP 343-1 Lean (6GK7343-1CX00-0XE0) is a cost-optimized variant for small projects, providing 4-port switch functionality and a single MAC/IP. The full-feature CP 343-1 (6GK7343-1EX30-0XE0 in later revisions) supports multiple IP connections, ISO-on-TCP, and S7 communication, which is the right pick when the S7-300 also needs to communicate with HMI panels and a ControlLogix via the EtherNet/IP to Modbus/TCP gateway.

  • 2XV9450-1MB00 – S7-OPEN MODBUS/TCP, single license on CD.

Modern alternatives include the SIMATIC Modbus/TCP PN coupler (6AV7260-1xx) for S7-300/400, or the Modbus/TCP CPx42 gateway family from Helmholz and HMS. The Modbus/TCP driver presents a function block interface (FB) inside STEP 7 that wraps the open Modbus/TCP client/server primitives (FC 3, 4, 6, 16, 23) into standard DB calls.

ET 200S 1SI Serial Interface Module

The ET 200S 1SI (6ES7138-4DF11-0AB0) is a serial interface submodule that slides into an ET 200S station. It supports RS-232C, RS-422, and RS-485 modes, and carries Modbus RTU master and slave capability natively, without an additional driver license. It is approximately half the price of a CP 341 + driver combination, but its applicability is conditional on three prerequisites:

  1. An ET 200S station must already exist on PROFIBUS-DP or PROFINET with available slot width (15 mm) for the 1SI submodule.
  2. The host CPU must be a DP (6ES7313-6CE01-0AB0) or PN/DP variant; the basic CPU 312 IFM without PROFIBUS cannot reach the 1SI.
  3. Configuration is done inside the ET 200S head module's slot, not in the S7-300 hardware catalog directly, which adds one level of indirection for new users.

For a greenfield S7-300 node that is already on PROFINET to a SIMATIC ET 200MP or ET 200SP, the modern equivalent is the CM PtP (6ES7137-6AA00-0BA0) on an ET 200SP station, which is the recommended path for new deployments per the Siemens Migration Guide.

Modbus Driver Software and Licensing

The CP 341 does not speak Modbus out of the box. Modbus is licensed separately and delivered as a dongle-protected software loadable driver that must be installed on the CP 341 itself, not on the S7-300 CPU. Two license packages are relevant:

MLFB Product Role Reference Hardware STEP 7
6ES7870-1AA01-0YA0 SIMATIC S7 MODBUS MASTER V3.1, single license, CD + HW dongle Master CP 341, CP 441-2 V4.2 or later
6ES7870-1AB01-0YA0 SIMATIC S7 MODBUS SLAVE V3.1, single license, CD + HW dongle Slave CP 341, CP 441-2 V4.2 or later

The dongle is keyed to the CP's serial number, so the license is non-transferable. For ASCII variants (non-Modbus) such as 3964R or RK512, the CP 341 ships with a base ASCII driver pre-installed and no additional license is required. For Modbus ASCII specifically, refer to the Siemens Support entry ID 25356060 for the configuration recipe.

When sizing licenses, count the number of CP 341 modules that will run Modbus, not the number of end devices. Each CP 341 that participates in Modbus traffic requires its own driver and dongle.

STEP 7 V4.2 Configuration Procedure

The following procedure integrates a CP 341 with the Modbus Master V3.1 driver into an S7-300 station. STEP 7 V4.2 is the minimum; later versions (V5.4, V5.5) are backward compatible.

  1. Install the dongle driver. Run the setup from the CD 6ES7870-1AA01-0YA0, which installs the licensing service and the Modbus FB library (FB 7, FB 8, FB 110, FB 111, FC 80). The dongle must be physically present on the PG/PC USB port during configuration download; runtime does not require the dongle on the PLC.
  2. Open the SIMATIC Manager and double-click Hardware on the S7-300 station.
  3. Insert the CP 341 from the catalog under SIMATIC 300 > CP-300 > PtP, choosing the variant that matches the physical interface (RS-485 = 6ES7341-1CH01-0AE0).
  4. Set the Modbus address base in the CP properties dialog. The default mapping places Modbus holding registers 40001-49999 into DB offsets 0-9999 of a project DB. Document the offset; it is the single most common cause of "we are reading the wrong register" commissioning errors.
  5. Configure the protocol by selecting Modbus Master in the protocol dropdown. Define baud (typically 19200), parity (Even), data bits (8), stop bits (1), and inter-character timeout (3.5 character times, i.e., ~2 ms at 19200 baud for the Modbus RTU silent interval).
  6. Compile and download the hardware configuration. The CP will reboot and come up as the configured interface.
  7. Place the Modbus FBs (FB 80 for master polling) in OB 1 with instance DBs. Wire the LADDR input to the CP's I/O base address (for example, 256 decimal = 100 hex).

For Modbus/TCP, the procedure differs: the Modbus/TCP driver (2XV9450-1MB00) installs a different FB library, and the LADDR points to the CP 343-1's IP connection handle rather than a hex I/O base.

ControlLogix 5555 Multi-Protocol Bridge

The 1756-L55 ControlLogix processor supports a backplane populated with multiple 1756 communication modules. The catalog matrix for the most common protocol gateways is:

Module Protocol Topology Max Nodes Notes
1756-ENBT / 1756-EN2T EtherNet/IP 100 Mbps star or ring (DLR) 128 connections Bridges to Modbus/TCP via third-party gateway
1756-DHRIO Data Highway Plus / Remote I/O DH+ trunk, 3 Mbaud 32 per channel 2 channels per module, scanner or adapter
1756-DNB DeviceNet DeviceNet trunk, 500 kbaud 63 nodes Scanner mode required for master
1756-CNB / 1756-CN2 ControlNet ControlNet coax, 5 Mbaud 99 nodes Scheduled or unscheduled
1756-MODULE (generic) n/a n/a For vendor-specific backplane modules

To bridge a ControlLogix 5555 to an S7-300 Modbus/TCP node, the typical path is: 1756-ENBT → plant Ethernet LAN → CP 343-1 (S7-300). The ControlLogix side uses an explicit MSG instruction of CIP Generic type with an Embedded Modbus/TCP path, or a third-party add-on (ProSoft PLX31-EIP-MBTCP, HMS Anybus X-gateway AB7648) that appears as a rack-mounted EtherNet/IP device and converts to Modbus/TCP transparently.

Modicon M340 and Modbus Integration

The Schneider Electric Modicon M340 uses BMX NOM 0200 (RS-485 Modbus RTU) or BMX NOE 0100 (Ethernet, Modbus/TCP) modules. For legacy Modbus Plus, the TSX PBY 100 or BMX NOC 0401 modules are required. The M340's Ethernet module supports up to 16 simultaneous Modbus/TCP client or server connections. For a Modicon Premium line (TSX P57), the ETY 110 or ETY 4103 modules with PL7 Pro V4.5 or later manage Modbus/TCP server roles, while the SCP 111 / SCP 114 handle RS-485 Modbus RTU.

When the M340 acts as master and the S7-300 acts as Modbus RTU slave, the S7-300 site requires the 6ES7870-1AB01-0YA0 Slave driver. The M340 uses function block READ_VAR for Modbus/TCP and OUT_IN_MBUS for RTU. Polling intervals should be staggered across the network to avoid broadcast storms on the RS-485 bus.

Diagnostic and Protocol Analysis Tools

Diagnosing a multi-vendor network requires one tool per protocol layer, plus a cross-protocol traffic analyzer. The recommended baseline toolkit is:

  • Wireshark with the Modbus/TCP dissector and EtherNet/IP CIP dissector enabled. Capture on a managed switch SPAN/mirror port. Wireshark 3.6 and later interpret Modbus register names from .csv map files.
  • Modbus Poll (modbus tools, by WinTech) for Modbus RTU and TCP master/slave simulation. Use it to verify that a third-party slave is responsive before blaming the S7-300.
  • Siemens STEP 7 Diagnose HW for CP 341 and CP 343-1 module diagnostics: SF, BF, frame error counters, and Modbus job log are all available online.
  • ProSoft Discovery Service (for AB / Rockwell) and Schneider Modbus Diagnostic (Unity Loader) for the foreign-vendor modules.
  • Wireshark → Statistics → IO Graph for bandwidth verification. Modbus/TCP on a 10 Mbps half-duplex legacy plant network should not exceed 30% sustained load.

For DeviceNet, the RSNetWorx for DeviceNet tool is mandatory; for ControlNet, RSNetWorx for ControlNet; for DH+, the legacy DH+ Network Analyzer or RSWho in RSLinx. The ControlLogix 5555 backplane can be inspected with RSLogix 5000 (now Studio 5000 Logix Designer) by going online with the controller and reading the I/O tree.

Bandwidth and Collision Considerations

Ethernet is permissive: Modbus/TCP, PROFINET, EtherNet/IP, and S7 communication can coexist on a single switch fabric, provided the switch supports QoS, IGMP snooping for multicast PROFINET, and is managed. Half-duplex hubs are not acceptable for multi-protocol Ethernet: collisions between an EtherNet/IP I/O multicast and a Modbus/TCP request will manifest as occasional Modbus timeouts that the S7-300 logs as 0xE0 to 0xE5 events in the CP 343-1 diagnostic buffer. Use full-duplex switches only.

RS-485 Modbus RTU has a 32-node electrical limit per segment and a single terminating resistor at each end. The CP 341's RS-485 variant includes internal termination that is enabled by a DIP switch on the rear of the module. Termination must be enabled only at the two physical ends of the trunk; enabling it in the middle of the bus causes reflections and CRC errors.

Commissioning and Verification Procedure

Use this checklist to bring up an S7-300 Modbus node on a multi-vendor plant network.

  1. Verify the CP 341 or CP 343-1 module is seated in the rack and the SF LED is off after power-up. A constant SF indicates the dongle is missing or the driver load failed.
  2. Set the IP address on the CP 343-1 (default 0.0.0.0) and verify ping from the engineering station.
  3. On the Modbus RTU RS-485 bus, measure DC bias with a multimeter between A and B; a healthy idle line shows > 200 mV differential with the driver chip not enabled.
  4. Start a Modbus Poll session against the S7-300 slave. Read holding register 1 (function code 3) and confirm a non-zero response.
  5. From the ControlLogix 5555, execute a CIP Generic MSG with a Modbus/TCP service path; verify success on the first transaction.
  6. Open Wireshark on a SPAN port. Filter on tcp.port == 502 and confirm the S7-300 is responding within 100 ms per request.
  7. Force a fault by stopping the Modbus/TCP driver service on the S7-300. Verify that the ControlLogix MSG instruction times out after the configured retry window, and that the S7-300 records a CP diagnostic event.
  8. Restore the service, clear the diagnostic buffer, and re-verify the polling cycle.

Troubleshooting Matrix

Symptom Likely Root Cause Diagnostic Step Resolution
CP 341 SF LED steady red Modbus driver not loaded, dongle missing Online > CP 341 > Module Information Reinstall driver from CD 6ES7870-1xx01-0YA0; verify dongle serial number matches CP
CP 341 BF LED flashing, no Modbus response RS-485 termination wrong, A/B reversed, or baud mismatch Measure A-B with scope; verify with Modbus Poll as master Enable termination only at trunk ends; correct polarity (A is inverting, B is non-inverting on TIA-485)
Modbus/TCP requests time out sporadically Half-duplex hub, switch QoS disabled, broadcast storm Wireshark capture on SPAN port; check switch port duplex Replace hub with managed full-duplex switch; enable QoS with Modbus/TCP at low priority
Modbus returns swapped registers (e.g., 40001 returns value of 40002) Offset misalignment in CP 341 mapping dialog Inspect CP 341 protocol properties → Modbus mapping Recompute the base offset; verify against device's Modbus map documentation
ControlLogix MSG to Modbus/TCP returns error code 0x0001 Path string invalid or Modbus/TCP port not 502 RSLogix MSG path editor; netstat -an on S7-300 Correct path to LocalENBT,2,IP_of_CP343-1,1,0,502
ET 200S 1SI not visible in HW Config ET 200S station not configured first; submodule catalog path wrong Open ET 200S head module first, then insert 1SI under "submodules" Add 1SI under the IM 151 head, not under the S7-300 directly
DeviceNet scanner reports 77 (Node Offline) on every poll No terminating resistor on DeviceNet trunk; or baud auto-baud failed Measure resistance across CAN-H and CAN-L (should be ~60 ohms with both ends terminated) Install 121-ohm resistor at each trunk end; set baud with RSNetWorx auto-detect
DH+ RSLinx sees ControlLogix but cannot go online DH+ node address conflict; coax broken DH+ network analyzer; visual inspection of taps Set unique node addresses 0-77 octal; replace damaged coax segments

Functional Block Reference (Modbus Master on CP 341)

The Modbus Master V3.1 driver exposes the following FBs in STEP 7. The instance DB carries the request queue.

// OB1 cyclic section
CALL "MODB_MAST" , DB120  // FB 80 instance
  REQ    := TRUE            // Trigger on rising edge
  LADDR  := W#16#100        // I/O base of CP 341
  DB_NO  := 201             // Project DB holding the request
  DBB_NO := 0               // Byte offset in DB 201
  LEN    := 8               // 8 bytes = 4 holding registers
  SLAVE  := 2               // Modbus slave address 2
  RW     := TRUE            // TRUE = write, FALSE = read
  FUNC   := 16              // Function code 16 = Preset Multiple Registers
  DONE   := M100.0          // Job complete
  ERROR  := M100.1          // Job failed; STATUS holds code
  STATUS := MW102           // 16-bit diagnostic word
  DATA   := P#DB201.DBX0 BYTE 8

STATUS codes from the Modbus Master driver include 0x0000 (success), 0x8001 (timeout), 0x8002 (CRC error from slave), 0x8003 (illegal function), 0x8004 (illegal data address), 0x8005 (illegal data value), and 0x8006 (slave device failure). Cross-reference these against the slave device's Modbus register map to isolate the failure.

Migration Path to PROFINET

For new deployments, Siemens has formally discontinued the CP 341 in favor of the CM PtP (6ES7137-6AA00-0BA0) on an ET 200SP station, which supports Modbus RTU master and slave out of the box, without a separate driver license. The S7-300 CPU 315-2 PN/DP or CPU 317-2 PN/DP plus an IM 155-6 PN ST interface module is the recommended 2024-2025 reference architecture. The CP 341 remains in service for legacy spares, but planning for migration is recommended because end-of-life notices have been published for the RS-232C and TTY variants.

Safety notice. The Dongle-protected Modbus driver (6ES7870-1AA01-0YA0 and -1AB01-0YA0) must be present on the engineering station during the initial download to the CP 341. After commissioning, the dongle may be removed; the CP retains the driver in its internal flash. Hot-swapping the CP 341 requires re-downloading the driver. Always retain the dongle in a labeled location for future replacement.

What is the difference between the CP 341 and the CP 441-2?

The CP 341 is a single-channel serial module for the S7-300 rack, supporting up to 1.5 Mbaud on RS-232C, TTY, or RS-485. The CP 441-2 is a two-channel module for the S7-400 (with S7-300 support via specific variants) that supports up to 19.2 kbaud on its two independent channels and uses the same Modbus driver license (6ES7870-1AA01-0YA0 master, -1AB01-0YA0 slave). Choose the CP 341 for S7-300 projects; the CP 441-2 only when the host is an S7-400 or you need two independent Modbus masters from a single slot.

Can the S7-300 act as both a Modbus master and a Modbus slave at the same time?

Yes, but it requires two CP 341 modules with separate driver licenses (one with 6ES7870-1AA01-0YA0, one with 6ES7870-1AB01-0YA0). A single CP 341 can only run one Modbus profile at a time. Alternatively, use one CP 341 as RTU and the CP 343-1 as Modbus/TCP, which keeps the roles on different physical media and avoids dongle conflicts.

How do I check the Modbus driver version installed on a CP 341?

Open STEP 7, go online with the S7-300 station, right-click the CP 341, and select Module Information → Diagnostic Buffer. The driver version is reported in event ID 0x1381 with a timestamp of the last driver load. Cross-reference this with the CD version (V3.1 in the cited MLFBs) to confirm compatibility with STEP 7 V4.2 or later.

Is the ET 200S 1SI a drop-in replacement for the CP 341?

No. The 1SI is a distributed I/O submodule inside an ET 200S station on PROFIBUS or PROFINET, not a central module in the S7-300 rack. It does not require a loadable driver or dongle for Modbus RTU, which is its key advantage, but it adds a PROFIBUS or PROFINET dependency and one network hop between the CPU and the Modbus bus. For a single Modbus segment with no PROFIBUS backbone, the CP 341 + driver remains the simpler choice.

Why does my Modbus/TCP poll work from Modbus Poll but fail from the ControlLogix 5555?

Almost always a CIP path or service-code mismatch. In RSLogix 5000, the MSG instruction's path must include the CP 343-1 IP and the standard Modbus/TCP port 502 in the form LocalENBT,2,IP,1,0,502. The service code for a Modbus register read is 0x4B (read holding registers, embedded in CIP). Verify the path string with Wireshark: a correctly formatted request will show a CIP SendRRData encapsulated Modbus/TCP frame on TCP port 502.

Back to blog