Overview
This reference covers a complete Modbus RTU link between a Siemens SIMATIC S7-300 CPU (any 31x/31xC/31xT with a free serial port or expansion interface) and a Conzerv EM654 / EM6544 energy meter. The supported physical layer is RS-485 (2-wire half-duplex or 4-wire full-duplex depending on meter option), and the meter operates strictly as a Modbus slave. The S7-300 must therefore host a Modbus RTU master. Three hardware paths are viable on an S7-300:
-
CP 341 point-to-point module with the "Modbus master" loadable driver (license:
6ES7 341-1AH02-0AE0dongle, sometimes supplied with the driver). -
ET 200S Profibus-DP station with a 1SI 3964/ASCII module (
6ES7 138-4DF01-0AB0) running the free Modbus master example project. - ET 200SP with a CM PTP communication module using the same Modbus master function block library.
The CP 341 path is the most common and is documented in detail below.
Prerequisites
| Item | Specification | Notes |
|---|---|---|
| S7-300 CPU | CPU 31x-2DP or higher with free slot | Firmware ≥ V2.x for CP 341 on PROFIBUS |
| CP 341 module |
6ES7 341-1AH01-0AE0 (RS-485) or 6ES7 341-1BH01-0AE0 (RS-232) |
RS-485 variant recommended for multi-drop |
| Modbus master driver | SIMATIC Modbus master V3.x loadable driver | Delivered on the "CP PtP driver CD" part number 6ES7 858-2XX00-0AA0 family |
| Conzerv EM654x | RS-485 option card installed | Default slave address typically 1; jumpers configurable 1–247 |
| Cabling | Shielded twisted pair, 100 Ω characteristic impedance | Belden 3106A or equivalent; shield grounded at one end only |
| Termination | 120 Ω at each end of RS-485 bus | Most EM6xxx meters have DIP switches to enable terminator |
| STEP 7 (Classic) | V5.5 SP4 or later with HW Update | TIA Portal V15+ also supports CP 341 with Modbus PtP driver |
| Wiring topology | Daisy-chain, max 32 devices per segment | Use repeater for >32 nodes or >1200 m |
STEP 7 → Communication driver installation
On the programming PC, install the SIMATIC Modbus Master RTU loadable driver from the supplied CD or download it via the Siemens Support portal entry referenced below. The driver installs the CP 341 parameter assignment tool and a library of FB/FC/UDT blocks: FB80 MODB_MAST, FB81 MODB_3WAY, FC V24_STAT, plus the UDT for job configuration.
Hardware Configuration of the CP 341
- In HW Config (STEP 7 V5.5) or device configuration (TIA Portal), insert the CP 341 in the S7-300 rack. Double-click to open Properties → Parameter Assignment.
- Select the protocol "MODBUS Master (RTU)"; the rest of the driver is wired automatically.
- Set physical interface:
- Protocol = RTU
- Baud rate =
9600bit/s (default for EM654); 19200 and 38400 supported on most firmware revisions - Parity =
Even(EM6xxx default) - Data bits =
8; Stop bits =1 - Flow control =
None(RS-485 is hardware-directed)
- Set RS-485 transceiver mode to "Half-duplex (2-wire)" unless the meter is wired for full-duplex (4-wire).
- Save and rebuild the HW configuration, then download to the CPU.
RS-485 Pin Assignment (CP 341)
| Sub-D pin (CP 341 RS-485) | Signal | EM654x terminal |
|---|---|---|
| 1 / 6 | Shield | SHIELD |
| 11 / 13 | T(B) / R(B) | D− |
| 4 / 9 | T(A) / R(A) | D+ |
| 7 | RTS (for direction control) | Not used on EM654 |
| 2 | GND | 0V |
Wire the back of the 9-pin Sub-D to the EM654x terminal block using a shielded, twisted 2-wire pair. Connect the shield to earth ground at the PLC cabinet entry point only to avoid ground loops.
Modbus Register Map (EM654x Series)
The EM654/EM6544/EM6434 expose all instantaneous and accumulated quantities as 32-bit IEEE-754 floating-point registers or as 16-bit signed/unsigned integers. The most useful subset:
| Parameter | Modbus function | Address (hex) | Register count | Data type | Unit |
|---|---|---|---|---|---|
| Voltage VL-N avg | 03 Read Holding | 0x0000 | 2 | Float32 | V |
| Current avg | 03 Read Holding | 0x0006 | 2 | Float32 | A |
| Active power total | 03 Read Holding | 0x000C | 2 | Float32 | W |
| Reactive power total | 03 Read Holding | 0x000E | 2 | Float32 | VAr |
| Apparent power total | 03 Read Holding | 0x0010 | 2 | Float32 | VA |
| Power factor total | 03 Read Holding | 0x0012 | 2 | Float32 | – |
| Frequency | 03 Read Holding | 0x0014 | 2 | Float32 | Hz |
| Total active energy | 03 Read Holding | 0x0046 | 2 | Float32 | kWh |
| Total reactive energy | 03 Read Holding | 0x0048 | 2 | Float32 | kVArh |
| Total apparent energy | 03 Read Holding | 0x004A | 2 | Float32 | kVAh |
| Demand active power | 03 Read Holding | 0x00A0 | 2 | Float32 | W |
| Device address | 03/06/16 | 0x07D0 | 1 | UInt16 | 1–247 |
| Baud rate code | 03/06/16 | 0x07D1 | 1 | UInt16 | 1=9600, 2=19200, 3=38400 |
| Parity code | 03/06/16 | 0x07D2 | 1 | UInt16 | 0=None, 1=Odd, 2=Even |
Address 0x0000 returns the first parameter (multi-register read returns contiguous words). EM6xxx register addresses are 0-based; CP 341 Modbus master FB expects 1-based addresses—always add +1 in the job block.
PLC Program Structure
The CP 341 Modbus master driver supplies the MODB_MAST function block that must be called once per logical channel (one channel = one RS-485 line = one meter). A cyclic OB (OB1) invokes the block, while parameterization is done through an instance DB. Pseudocode in Structured Text:
// OB1 - cyclic poll of EM654 at slave address 1
// Read 12 holding registers starting at Modbus address 1 (hex 0x0000)
#JobDB.Slave := 1; // EM654 Modbus address
#JobDB.Function:= 3; // Read Holding Registers
#JobDB.ReadStart:= 1; // 1-based starting address (hex 0x0000 + 1)
#JobDB.ReadCount:= 12; // 6 consecutive floats: V, I, P, Q, S, PF
#JobDB.WriteStart:= 0;
#JobDB.WriteCount:= 0;
#JobDB.Done := 0; // reset done flags each cycle
#JobDB.Error := 0;
// Trigger handshake
IF "first_scan" THEN
#JobDB.Request := TRUE;
END_IF;
"MODB_MAST_DB"(REQ := #JobDB.Request,
LADDR := 256, // CP 341 base address in HW Config
DONE => #JobDB.Done,
ERROR => #JobDB.Error,
STATUS => #JobDB.Status,
JOB_DB := #JobDB);
The job data block exports the response as a byte array of length 2·N registers. Convert the bytes into S7 REAL values using area pointers or a temporary block of type REAL with byte-swap because Modbus transmits Float32 big-endian while S7 is little-endian. Sample conversion:
// Convert 2 × 16-bit words to REAL with byte swap
#raw_word_1 := WORD_TO_INT(#resp[0]);
#raw_word_2 := WORD_TO_INT(#resp[2]);
#Voltage := WORD_TO_REAL(SWAP_WORD(#raw_word_1, #raw_word_2));
FUNCTION FC_SWAP : REAL
VAR_INPUT
W1, W2 : WORD;
END_VAR
VAR_TEMP
b0, b1, b2, b3 : BYTE;
END_VAR
b0 := WORD_TO_BYTE(W2); // low byte of high word → lowest address
b1 := WORD_TO_BYTE(SHR(W2,8));
b2 := WORD_TO_BYTE(W1);
b3 := WORD_TO_BYTE(SHR(W1,8));
// Assemble little-endian REAL
FC_SWAP := DWORD_TO_REAL(BYTE_TO_DWORD(b0, b1, b2, b3));
END_FUNCTION
Step-by-Step Commissioning Procedure
- Verify wiring with a multimeter: resistance between D+ and D− should be ~120 Ω with both ends terminated, ~∞ if only one end terminated.
- Power the meter; check the LED pattern: green RUN, no red COM-ERROR.
- Set meter Modbus address using the front-panel keypad (Service menu → Address) or by writing to register
0x07D0from a separate Modbus master tool (e.g., Modbus Poll, Schneider EBO, or any RS-485 scanner). - Install SIMATIC Modbus master loadable driver on the PG/PC.
- In HW Config, insert CP 341 and parameterize for Modbus RTU master.
- Compile and download HW configuration.
- Generate the Modbus job DB and import the
MODB_MASTsource from the example project. - Insert the call into OB1; download the program.
- Go online with the CPU, open the CP 341 diagnostic buffer, and monitor the CP 341 "Send/Receive" indicators.
FB121 (Modbus_Master) and FB122 (Modbus_Slave) are in the Siemens "Point-to-Point Communication with ET 200S 1SI" example project.Verification Checklist
| Test | Procedure | Pass criterion |
|---|---|---|
| CP 341 online | Online → CP 341 Diagnostics | Status "Operating, mode Modbus Master" |
| First poll | Watch #JobDB.Done toggle TRUE | DONE = TRUE within ≤150 ms at 9600 baud |
| Error register | Monitor #JobDB.STATUS | STATUS = 0 (no error) |
| Voltage sanity | Compare #Voltage to meter display | Match within ±1% |
| Energy total | Force CPU STOP, run for 1 h, compare kWh | Δ matches display ±0.1 kWh |
| CRC check | Set a wrong slave address (e.g., 2) | STATUS = 0x0E02 (timeout) or 0x0E03 (CRC) |
CP 341 Modbus Master Status / Error Codes
| STATUS (hex) | Meaning | Typical cause | Corrective action |
|---|---|---|---|
| 0x0000 | No error | — | — |
| 0x0E01 | Parameter assignment error | Wrong protocol selected | Re-parameterize CP 341 with Modbus Master RTU |
| 0x0E02 | Timeout (no response) | Wiring, address, baud mismatch | Verify polarity A/B, check termination, set same baud on meter |
| 0x0E03 | CRC/frame error | Noise or wrong parity | Use shielded cable, check parity (Even default) |
| 0x0E06 | Illegal function code | Meter supports only FC 03/06/16 | Use FC 03 for read, FC 06 for single-word write |
| 0x0E07 | Illegal register address | Address out of range | Verify map; subtract 1 from Modbus 1-based address |
| 0x0E08 | Slave exception code 02 | Address not implemented on meter | Cross-check with firmware-specific register list |
| 0x0E09 | Slave exception code 03 | Read count wrong (e.g., odd for float pair) | Always read even number of words for Float32 |
| 0x0E0A | Buffer overrun | Response exceeds CP 341 buffer | Limit single read to ≤125 words per poll |
| 0x0E81 | CP 341 hardware fault | Module not properly seated | Re-seat module, check slot address in HW Config |
Troubleshooting Matrix
| Symptom | Likely root cause | Diagnostic step | Fix |
|---|---|---|---|
| STATUS always 0x0E02 (timeout) | Wrong polarity A/B on RS-485 | Swap D+/D− wires | If DONE toggles after swap, polarity was reversed |
| STATUS 0x0E03 (CRC) on every poll | Baud rate mismatch | Connect oscilloscope to A/B | Set meter and CP 341 to identical baud (default 9600/Even) |
| DONE toggles but values garbage | Word-swap missing in Float32 conversion | Trace raw response bytes | Apply SWAP_WORD conversion block shown above |
| DONE toggles, STATUS=0 but #Voltage=0.0 | EM6xxx uses 0-based addresses; you sent 1-based read of 0x0000 | Read holding from address 1 (not 0) | Confirm either via documentation or by polling address 1 and seeing voltage |
| CP 341 SF LED red | Driver not licensed / wrong firmware | Open CP 341 Properties in HW Config | Install licensed Modbus master driver on PG, re-download HW config |
| No communication at all | Meter is the EM6x3x variant with only Modbus ASCII (not RTU) | Check meter menu display for "RTU" or "ASCII" | Reconfigure driver for ASCII or swap to ASCII-supported meter |
| Intermittent dropouts during VFD switching | Common-mode noise on RS-485 | Monitor STATUS over 24 h | Install RS-485 isolator (Phoenix PSM-ME-RS485) near meter; tighten shield bonding |
| Multi-meter bus: only first meter responds | Missing termination at bus ends | Measure DC resistance across the bus | Enable 120 Ω termination on first and last meter only |
Alternative Hardware: ET 200S 1SI Path
For installations that already include an ET 200S Profibus-DP slave station, the cheaper path is a 1SI module (6ES7 138-4DF01-0AB0) plus the free "Modbus Master" example for ET 200S 1SI from Siemens. The block library is functionally identical: FB121 Modbus_Master cycles one job per call, and the device is addressed by slot number rather than a logical address. A typical poll cycle of eight quantities runs at ~250 ms at 9600 baud.
If migrating to a newer SIMATIC platform, the ET 200SP CM PtP module (6ES7 137-6AA01-0BA0) supports Modbus master natively and integrates with TIA Portal V17+ without the legacy CP 341 driver.
Concrete Floating-Point Readback — Sample Ladder Implementation
Using Function Block Diagram style, the same conversion in graphical form:
- Network 1: Call
MODB_MASTwith the job DB. - Network 2: When
DONE=TRUE, extract two 16-bit words from the response data block and feed them into the byte-swap FC. - Network 3: Move the REAL outputs into DB fields such as
DB100.Voltage_LN,DB100.kW_Tot, andDB100.kWh_Tot. - Network 4: Scale kW from W to kW with
DIV_Rby 1000.0.
For energy scaling the EM654 returns kWh directly; no scaling required.
Time and Watchdog Considerations
CP 341 Modbus master supports a configurable "response timeout" (default 3000 ms). At 9600 baud with 8N1 (here 8E1) framing, a request of 8 bytes + 0.25 char gap + slave turnaround + response of N·2 bytes takes roughly:
T ≈ (8 + N·2) × 10 / 9600 × 1.2 → ≈ 100 ms for a 20-word read
Cycle OB1 if your application is tight: invoke MODB_MAST in a time OB (e.g., OB35 at 100 ms) or use a self-resetting latch to prevent request retriggering faster than the slave can respond.
Reference Documents
- CP 341 manual and Modbus master RTU driver: see the Siemens "SIMATIC S7-300/S7-400 Loadable Driver for Point-to-Point CPs: MODBUS protocol, RTU format, S7 is master" entry in the Siemens Industry Online Support.
- Conzerv/Schneider EM6544 User Manual: see "Download User Manual - Schneider Electric" entry on the Schneider Electric product page for the PowerLogic EM-series meters.
- Siemens "Instructions for communication tasks (S7-300, S7-400, S7-1500)" reference: Siemens TIA documentation portal.
- ET 200S 1SI Modbus master example project: search "Modbus Master for ET 200S 1SI" in Siemens Industry Online Support.
Field-Proven Acceptance Test Procedure
- Verify all addresses return non-zero status flags.
- Compare 3-phase voltages against a calibrated reference meter; tolerance ±1%.
- Apply a known 100 % load; record time, run for 30 minutes, compare integrated kWh against meter display ±0.5 %.
- Disconnect and reconnect RS-485; verify automatic recovery within 5 s.
- Disconnect termination at one end; verify status indicates "Intermittent, CRC errors" rather than full timeout.
- Save diagnostic buffer from CP 341 and archive with the commissioning report.
Does the Conzerv EM654 support Profibus or Profinet, or only Modbus?
The EM6xxx family supports only Modbus RTU on RS-485 in its base configuration. Some higher-tier Conzerv/Schneider meters (PM5000/PM8000) add Profibus-DP or Modbus TCP modules, but the EM654/EM6544 is RS-485 only—use a CP 341 or ET 200S 1SI as the Modbus master on the S7-300.
What is the recommended default baud rate and parity?
9600 bit/s, Even parity, 1 stop bit (8E1) is the EM654x factory default. Both CP 341 parameterization and the meter menu must match exactly, otherwise STATUS 0x0E02 (timeout) or 0x0E03 (CRC error) is returned on every poll.
Do I need a license for the CP 341 Modbus master driver?
Yes. The Modbus master RTU driver is shipped as a licensed "loadable driver" on a CD, historically part number 6ES7 858-2XX00-0AA0. Without the dongle/license the CP 341 will refuse Modbus commands and report SF with diagnostic entry "Loadable driver not licensed."
Why are my read values 0.0 even though STATUS is 0?
Almost always a byte-order/word-swap issue. Modbus transmits Float32 in big-endian (high word first), while S7 REAL is little-endian. Apply the SWAP_WORD conversion shown in the program structure section, and remember that Modbus register addresses are typically 1-based on the S7-300 side while the EM654 documentation lists them 0-based.
Can I poll multiple EM654 meters from one CP 341?
Yes, the CP 341 RS-485 port supports multi-drop with up to 32 slave devices on one segment. Address each meter uniquely (1–247), enable 120 Ω termination on the first and last device only, and either poll cyclically or use FB81 MODB_3WAY for concurrent job buffering.
Is there a cheaper alternative to the CP 341?
If you already have an ET 200S Profibus-DP station, the 1SI serial module (6ES7 138-4DF01-0AB0) plus the free Modbus master example for ET 200S 1SI provides equivalent Modbus RTU master capability at lower cost. For new builds on TIA Portal V17+, the ET 200SP CM PtP is the recommended modern path.