S7-300 Modbus RTU Communication with Conzerv EM654 Energy Meter

David Krause12 min read
S7-300SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer
Field clarification: Schneider Electric acquired the Conzerv power-meter product line; the model referenced as "EM654" is most commonly the EM6544 (or the closely related EM6434/EM3360 family). Verify the exact MLFB/part number on the meter nameplate before commissioning—protocol availability differs across firmware revisions of the EM6xxx series.

Overview

This reference covers a complete Modbus RTU link between a Siemens SIMATIC S7-300 CPU (any 31x/31xC/31xT with a free serial port or expansion interface) and a Conzerv EM654 / EM6544 energy meter. The supported physical layer is RS-485 (2-wire half-duplex or 4-wire full-duplex depending on meter option), and the meter operates strictly as a Modbus slave. The S7-300 must therefore host a Modbus RTU master. Three hardware paths are viable on an S7-300:

  1. CP 341 point-to-point module with the "Modbus master" loadable driver (license: 6ES7 341-1AH02-0AE0 dongle, sometimes supplied with the driver).
  2. ET 200S Profibus-DP station with a 1SI 3964/ASCII module (6ES7 138-4DF01-0AB0) running the free Modbus master example project.
  3. ET 200SP with a CM PTP communication module using the same Modbus master function block library.

The CP 341 path is the most common and is documented in detail below.

Prerequisites

Item Specification Notes
S7-300 CPU CPU 31x-2DP or higher with free slot Firmware ≥ V2.x for CP 341 on PROFIBUS
CP 341 module 6ES7 341-1AH01-0AE0 (RS-485) or 6ES7 341-1BH01-0AE0 (RS-232) RS-485 variant recommended for multi-drop
Modbus master driver SIMATIC Modbus master V3.x loadable driver Delivered on the "CP PtP driver CD" part number 6ES7 858-2XX00-0AA0 family
Conzerv EM654x RS-485 option card installed Default slave address typically 1; jumpers configurable 1–247
Cabling Shielded twisted pair, 100 Ω characteristic impedance Belden 3106A or equivalent; shield grounded at one end only
Termination 120 Ω at each end of RS-485 bus Most EM6xxx meters have DIP switches to enable terminator
STEP 7 (Classic) V5.5 SP4 or later with HW Update TIA Portal V15+ also supports CP 341 with Modbus PtP driver
Wiring topology Daisy-chain, max 32 devices per segment Use repeater for >32 nodes or >1200 m

STEP 7 → Communication driver installation

On the programming PC, install the SIMATIC Modbus Master RTU loadable driver from the supplied CD or download it via the Siemens Support portal entry referenced below. The driver installs the CP 341 parameter assignment tool and a library of FB/FC/UDT blocks: FB80 MODB_MAST, FB81 MODB_3WAY, FC V24_STAT, plus the UDT for job configuration.

Hardware Configuration of the CP 341

  1. In HW Config (STEP 7 V5.5) or device configuration (TIA Portal), insert the CP 341 in the S7-300 rack. Double-click to open Properties → Parameter Assignment.
  2. Select the protocol "MODBUS Master (RTU)"; the rest of the driver is wired automatically.
  3. Set physical interface:
    • Protocol = RTU
    • Baud rate = 9600 bit/s (default for EM654); 19200 and 38400 supported on most firmware revisions
    • Parity = Even (EM6xxx default)
    • Data bits = 8; Stop bits = 1
    • Flow control = None (RS-485 is hardware-directed)
  4. Set RS-485 transceiver mode to "Half-duplex (2-wire)" unless the meter is wired for full-duplex (4-wire).
  5. Save and rebuild the HW configuration, then download to the CPU.

RS-485 Pin Assignment (CP 341)

Sub-D pin (CP 341 RS-485) Signal EM654x terminal
1 / 6 Shield SHIELD
11 / 13 T(B) / R(B) D−
4 / 9 T(A) / R(A) D+
7 RTS (for direction control) Not used on EM654
2 GND 0V

Wire the back of the 9-pin Sub-D to the EM654x terminal block using a shielded, twisted 2-wire pair. Connect the shield to earth ground at the PLC cabinet entry point only to avoid ground loops.

Modbus Register Map (EM654x Series)

The EM654/EM6544/EM6434 expose all instantaneous and accumulated quantities as 32-bit IEEE-754 floating-point registers or as 16-bit signed/unsigned integers. The most useful subset:

Parameter Modbus function Address (hex) Register count Data type Unit
Voltage VL-N avg 03 Read Holding 0x0000 2 Float32 V
Current avg 03 Read Holding 0x0006 2 Float32 A
Active power total 03 Read Holding 0x000C 2 Float32 W
Reactive power total 03 Read Holding 0x000E 2 Float32 VAr
Apparent power total 03 Read Holding 0x0010 2 Float32 VA
Power factor total 03 Read Holding 0x0012 2 Float32 –
Frequency 03 Read Holding 0x0014 2 Float32 Hz
Total active energy 03 Read Holding 0x0046 2 Float32 kWh
Total reactive energy 03 Read Holding 0x0048 2 Float32 kVArh
Total apparent energy 03 Read Holding 0x004A 2 Float32 kVAh
Demand active power 03 Read Holding 0x00A0 2 Float32 W
Device address 03/06/16 0x07D0 1 UInt16 1–247
Baud rate code 03/06/16 0x07D1 1 UInt16 1=9600, 2=19200, 3=38400
Parity code 03/06/16 0x07D2 1 UInt16 0=None, 1=Odd, 2=Even

Address 0x0000 returns the first parameter (multi-register read returns contiguous words). EM6xxx register addresses are 0-based; CP 341 Modbus master FB expects 1-based addresses—always add +1 in the job block.

PLC Program Structure

The CP 341 Modbus master driver supplies the MODB_MAST function block that must be called once per logical channel (one channel = one RS-485 line = one meter). A cyclic OB (OB1) invokes the block, while parameterization is done through an instance DB. Pseudocode in Structured Text:

// OB1 - cyclic poll of EM654 at slave address 1
// Read 12 holding registers starting at Modbus address 1 (hex 0x0000)
#JobDB.Slave   := 1;            // EM654 Modbus address
#JobDB.Function:= 3;            // Read Holding Registers
#JobDB.ReadStart:= 1;           // 1-based starting address (hex 0x0000 + 1)
#JobDB.ReadCount:= 12;          // 6 consecutive floats: V, I, P, Q, S, PF
#JobDB.WriteStart:= 0;
#JobDB.WriteCount:= 0;
#JobDB.Done    := 0;            // reset done flags each cycle
#JobDB.Error   := 0;

// Trigger handshake
IF "first_scan" THEN
    #JobDB.Request := TRUE;
END_IF;

"MODB_MAST_DB"(REQ      := #JobDB.Request,
              LADDR    := 256,             // CP 341 base address in HW Config
              DONE     => #JobDB.Done,
              ERROR    => #JobDB.Error,
              STATUS   => #JobDB.Status,
              JOB_DB   := #JobDB);

The job data block exports the response as a byte array of length 2·N registers. Convert the bytes into S7 REAL values using area pointers or a temporary block of type REAL with byte-swap because Modbus transmits Float32 big-endian while S7 is little-endian. Sample conversion:

// Convert 2 × 16-bit words to REAL with byte swap
#raw_word_1 := WORD_TO_INT(#resp[0]);
#raw_word_2 := WORD_TO_INT(#resp[2]);
#Voltage   := WORD_TO_REAL(SWAP_WORD(#raw_word_1, #raw_word_2));

FUNCTION FC_SWAP : REAL
VAR_INPUT
    W1, W2 : WORD;
END_VAR
VAR_TEMP
    b0, b1, b2, b3 : BYTE;
END_VAR
b0 := WORD_TO_BYTE(W2);  // low byte of high word → lowest address
b1 := WORD_TO_BYTE(SHR(W2,8));
b2 := WORD_TO_BYTE(W1);
b3 := WORD_TO_BYTE(SHR(W1,8));
// Assemble little-endian REAL
FC_SWAP := DWORD_TO_REAL(BYTE_TO_DWORD(b0, b1, b2, b3));
END_FUNCTION

Step-by-Step Commissioning Procedure

  1. Verify wiring with a multimeter: resistance between D+ and D− should be ~120 Ω with both ends terminated, ~∞ if only one end terminated.
  2. Power the meter; check the LED pattern: green RUN, no red COM-ERROR.
  3. Set meter Modbus address using the front-panel keypad (Service menu → Address) or by writing to register 0x07D0 from a separate Modbus master tool (e.g., Modbus Poll, Schneider EBO, or any RS-485 scanner).
  4. Install SIMATIC Modbus master loadable driver on the PG/PC.
  5. In HW Config, insert CP 341 and parameterize for Modbus RTU master.
  6. Compile and download HW configuration.
  7. Generate the Modbus job DB and import the MODB_MAST source from the example project.
  8. Insert the call into OB1; download the program.
  9. Go online with the CPU, open the CP 341 diagnostic buffer, and monitor the CP 341 "Send/Receive" indicators.
If you have an ET 200S station already on PROFIBUS, use the 1SI module with the free "Modbus_Master" example for STEP 7. Function blocks FB121 (Modbus_Master) and FB122 (Modbus_Slave) are in the Siemens "Point-to-Point Communication with ET 200S 1SI" example project.

Verification Checklist

Test Procedure Pass criterion
CP 341 online Online → CP 341 Diagnostics Status "Operating, mode Modbus Master"
First poll Watch #JobDB.Done toggle TRUE DONE = TRUE within ≤150 ms at 9600 baud
Error register Monitor #JobDB.STATUS STATUS = 0 (no error)
Voltage sanity Compare #Voltage to meter display Match within ±1%
Energy total Force CPU STOP, run for 1 h, compare kWh Δ matches display ±0.1 kWh
CRC check Set a wrong slave address (e.g., 2) STATUS = 0x0E02 (timeout) or 0x0E03 (CRC)

CP 341 Modbus Master Status / Error Codes

STATUS (hex) Meaning Typical cause Corrective action
0x0000 No error — —
0x0E01 Parameter assignment error Wrong protocol selected Re-parameterize CP 341 with Modbus Master RTU
0x0E02 Timeout (no response) Wiring, address, baud mismatch Verify polarity A/B, check termination, set same baud on meter
0x0E03 CRC/frame error Noise or wrong parity Use shielded cable, check parity (Even default)
0x0E06 Illegal function code Meter supports only FC 03/06/16 Use FC 03 for read, FC 06 for single-word write
0x0E07 Illegal register address Address out of range Verify map; subtract 1 from Modbus 1-based address
0x0E08 Slave exception code 02 Address not implemented on meter Cross-check with firmware-specific register list
0x0E09 Slave exception code 03 Read count wrong (e.g., odd for float pair) Always read even number of words for Float32
0x0E0A Buffer overrun Response exceeds CP 341 buffer Limit single read to ≤125 words per poll
0x0E81 CP 341 hardware fault Module not properly seated Re-seat module, check slot address in HW Config

Troubleshooting Matrix

Symptom Likely root cause Diagnostic step Fix
STATUS always 0x0E02 (timeout) Wrong polarity A/B on RS-485 Swap D+/D− wires If DONE toggles after swap, polarity was reversed
STATUS 0x0E03 (CRC) on every poll Baud rate mismatch Connect oscilloscope to A/B Set meter and CP 341 to identical baud (default 9600/Even)
DONE toggles but values garbage Word-swap missing in Float32 conversion Trace raw response bytes Apply SWAP_WORD conversion block shown above
DONE toggles, STATUS=0 but #Voltage=0.0 EM6xxx uses 0-based addresses; you sent 1-based read of 0x0000 Read holding from address 1 (not 0) Confirm either via documentation or by polling address 1 and seeing voltage
CP 341 SF LED red Driver not licensed / wrong firmware Open CP 341 Properties in HW Config Install licensed Modbus master driver on PG, re-download HW config
No communication at all Meter is the EM6x3x variant with only Modbus ASCII (not RTU) Check meter menu display for "RTU" or "ASCII" Reconfigure driver for ASCII or swap to ASCII-supported meter
Intermittent dropouts during VFD switching Common-mode noise on RS-485 Monitor STATUS over 24 h Install RS-485 isolator (Phoenix PSM-ME-RS485) near meter; tighten shield bonding
Multi-meter bus: only first meter responds Missing termination at bus ends Measure DC resistance across the bus Enable 120 Ω termination on first and last meter only

Alternative Hardware: ET 200S 1SI Path

For installations that already include an ET 200S Profibus-DP slave station, the cheaper path is a 1SI module (6ES7 138-4DF01-0AB0) plus the free "Modbus Master" example for ET 200S 1SI from Siemens. The block library is functionally identical: FB121 Modbus_Master cycles one job per call, and the device is addressed by slot number rather than a logical address. A typical poll cycle of eight quantities runs at ~250 ms at 9600 baud.

If migrating to a newer SIMATIC platform, the ET 200SP CM PtP module (6ES7 137-6AA01-0BA0) supports Modbus master natively and integrates with TIA Portal V17+ without the legacy CP 341 driver.

Concrete Floating-Point Readback — Sample Ladder Implementation

Using Function Block Diagram style, the same conversion in graphical form:

  • Network 1: Call MODB_MAST with the job DB.
  • Network 2: When DONE=TRUE, extract two 16-bit words from the response data block and feed them into the byte-swap FC.
  • Network 3: Move the REAL outputs into DB fields such as DB100.Voltage_LN, DB100.kW_Tot, and DB100.kWh_Tot.
  • Network 4: Scale kW from W to kW with DIV_R by 1000.0.

For energy scaling the EM654 returns kWh directly; no scaling required.

Time and Watchdog Considerations

CP 341 Modbus master supports a configurable "response timeout" (default 3000 ms). At 9600 baud with 8N1 (here 8E1) framing, a request of 8 bytes + 0.25 char gap + slave turnaround + response of N·2 bytes takes roughly:

T ≈ (8 + N·2) × 10 / 9600 × 1.2 → ≈ 100 ms for a 20-word read

Cycle OB1 if your application is tight: invoke MODB_MAST in a time OB (e.g., OB35 at 100 ms) or use a self-resetting latch to prevent request retriggering faster than the slave can respond.

Reference Documents

  • CP 341 manual and Modbus master RTU driver: see the Siemens "SIMATIC S7-300/S7-400 Loadable Driver for Point-to-Point CPs: MODBUS protocol, RTU format, S7 is master" entry in the Siemens Industry Online Support.
  • Conzerv/Schneider EM6544 User Manual: see "Download User Manual - Schneider Electric" entry on the Schneider Electric product page for the PowerLogic EM-series meters.
  • Siemens "Instructions for communication tasks (S7-300, S7-400, S7-1500)" reference: Siemens TIA documentation portal.
  • ET 200S 1SI Modbus master example project: search "Modbus Master for ET 200S 1SI" in Siemens Industry Online Support.

Field-Proven Acceptance Test Procedure

  1. Verify all addresses return non-zero status flags.
  2. Compare 3-phase voltages against a calibrated reference meter; tolerance ±1%.
  3. Apply a known 100 % load; record time, run for 30 minutes, compare integrated kWh against meter display ±0.5 %.
  4. Disconnect and reconnect RS-485; verify automatic recovery within 5 s.
  5. Disconnect termination at one end; verify status indicates "Intermittent, CRC errors" rather than full timeout.
  6. Save diagnostic buffer from CP 341 and archive with the commissioning report.

Does the Conzerv EM654 support Profibus or Profinet, or only Modbus?

The EM6xxx family supports only Modbus RTU on RS-485 in its base configuration. Some higher-tier Conzerv/Schneider meters (PM5000/PM8000) add Profibus-DP or Modbus TCP modules, but the EM654/EM6544 is RS-485 only—use a CP 341 or ET 200S 1SI as the Modbus master on the S7-300.

What is the recommended default baud rate and parity?

9600 bit/s, Even parity, 1 stop bit (8E1) is the EM654x factory default. Both CP 341 parameterization and the meter menu must match exactly, otherwise STATUS 0x0E02 (timeout) or 0x0E03 (CRC error) is returned on every poll.

Do I need a license for the CP 341 Modbus master driver?

Yes. The Modbus master RTU driver is shipped as a licensed "loadable driver" on a CD, historically part number 6ES7 858-2XX00-0AA0. Without the dongle/license the CP 341 will refuse Modbus commands and report SF with diagnostic entry "Loadable driver not licensed."

Why are my read values 0.0 even though STATUS is 0?

Almost always a byte-order/word-swap issue. Modbus transmits Float32 in big-endian (high word first), while S7 REAL is little-endian. Apply the SWAP_WORD conversion shown in the program structure section, and remember that Modbus register addresses are typically 1-based on the S7-300 side while the EM654 documentation lists them 0-based.

Can I poll multiple EM654 meters from one CP 341?

Yes, the CP 341 RS-485 port supports multi-drop with up to 32 slave devices on one segment. Address each meter uniquely (1–247), enable 120 Ω termination on the first and last device only, and either poll cyclically or use FB81 MODB_3WAY for concurrent job buffering.

Is there a cheaper alternative to the CP 341?

If you already have an ET 200S Profibus-DP station, the 1SI serial module (6ES7 138-4DF01-0AB0) plus the free Modbus master example for ET 200S 1SI provides equivalent Modbus RTU master capability at lower cost. For new builds on TIA Portal V17+, the ET 200SP CM PtP is the recommended modern path.

Back to blog