S7-300 Modbus RTU CP 341 Selection, Driver Setup

David Krause14 min read
S7-300SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

The SIMATIC S7-300 does not support Modbus RTU natively on a standard CPU. Modbus RTU is a serial protocol carried over RS-232, RS-422, or RS-485, and the S7-300 CPU itself has no serial interface capable of running the Modbus RTU framing. A dedicated point-to-point communication processor (PtP CP) must be installed in the S7-300 rack to terminate the Modbus RTU traffic, run the master or slave state machine, and exchange process data with the CPU over the backplane.

A frequent mis-specification is to select the Ethernet CP 343-1 (catalog number 6GK7 343-1EX11-0XE0 or its successors 6GK7 343-1CX00-0XE0 / 6GK7 343-1EX30-0XE0) and expect Modbus RTU functionality. The CP 343-1 family terminates Industrial Ethernet and PROFINET only. It has no UART, no RS-485 transceiver, and no Modbus RTU firmware. Selecting it for an RTU link is a hardware error that surfaces as a missing interface in the TIA Portal device catalog and as "No driver for protocol" messages in STEP 7.

The correct hardware path is one of three:

  1. CP 341 serial CP with the Modbus RTU loadable driver (most common, recommended for new designs).
  2. CP 340 legacy serial CP with the Modbus RTU loadable driver (still supported, older footprint).
  3. Modbus TCP gateway approach: keep the CP 343-1, expose the field device as a Modbus TCP slave, and place an external TCP-to-RTU converter (for example, Lantronix XPress-DR-IAP or any compliant industrial gateway) between the PLC subnet and the RTU device.

Hardware Identification: CP 343-1 vs. CP 341

Before purchasing or installing, verify the order number stamped on the front panel of the module. The catalog number uniquely identifies the protocol capability.

Module Order Number (MLFB) Interface Modbus RTU Capable Modbus TCP Capable
CP 343-1 Lean 6GK7 343-1EX11-0XE0 (legacy) 1 x RJ45 (10/100 Mbit) No No (TCP socket only, not Modbus)
CP 343-1 6GK7 343-1CX00-0XE0 1 x RJ45 (10/100 Mbit) No No (TCP socket only, not Modbus)
CP 343-1 Advanced 6GK7 343-1GX20-0XE0 2 x RJ45 (switch) No No (TCP socket only, not Modbus)
CP 341 RS-232C 6ES7 341-1AH01-0AE0 1 x RS-232C (15-pin sub-D) Yes (with driver) No
CP 341 RS-232C + modem 6ES7 341-1BH01-0AE0 1 x RS-232C Yes (with driver) No
CP 341 RS-422/485 6ES7 341-1CH01-0AE0 1 x RS-422/485 (15-pin sub-D) Yes (with driver) No

If the front-panel label reads "CP 343-1" with a 6GK7 343-1 prefix, the module is unsuitable for Modbus RTU. Order a 6ES7 341-1CH01-0AE0 (RS-422/485) for typical 2-wire RTU multidrop buses, or 6ES7 341-1AH01-0AE0 (RS-232C) for point-to-point links to a single instrument.

Field tip: Some third-party vendors sell labeled "CP 343-1 Modbus" variants. These are not Siemens MLFBs. Confirm the 6ES7 341-1 prefix and the Siemens logo on the front bezel. Counterfeit modules report the wrong module type in TIA Portal and brick during firmware update.

CP 341 Variant Selection

Three CP 341 variants exist, and the selection is driven by the physical layer of the Modbus RTU bus.

RS-485 / RS-422 (6ES7 341-1CH01-0AE0)

The default choice for Modbus RTU. RS-485 supports up to 32 unit loads on a single twisted pair, half-duplex, with cable lengths up to 1200 m at reduced baud. The CP 341 exposes a 15-pin sub-D female connector; the Siemens 6ES7 972-0BA12-0XA0 RS-485 termination plug is used at the end of the segment to bias the bus.

Pinout (CP 341 end):

  • Pin 11: T/R+ (Data A)
  • Pin 4 / 9: T/R- (Data B)
  • Pin 6 / 7: +5 V (isolated, for termination bias only)
  • Pin 5: functional ground

RS-232C (6ES7 341-1AH01-0AE0)

Use for point-to-point links to a single instrument, typically a panel meter, scale indicator, or laboratory device. Maximum cable length 15 m. The CP 341 acts as DCE; if the device is also DCE, a null-modem crossover is required.

RS-232C with Modem (6ES7 341-1BH01-0AE0)

Adds a Hayes-compatible AT command interface for dial-up or radio-modem links. Rarely used in modern Modbus RTU designs; choose the plain RS-232C variant unless the application explicitly requires a dial-up SCADA RTU.

Modbus RTU Loadable Driver

The CP 341 / CP 340 ships with ASCII and 3964(R) drivers pre-installed. Modbus RTU is licensed separately and is delivered as a "loadable driver" on a separate CD or download package. Without the driver license, the Modbus RTU FB blocks (FB 7, FB 8 for master; FB 80, FB 81 for the new generation in TIA) will return error code 0x0001 (license missing) and the CP will report protocol 0x00 (no protocol loaded).

Driver Package Order Number Role STEP 7 / TIA
Modbus Master RTU, CP 341/340 6ES7 870-1AA01-0YA0 CP acts as Modbus RTU master (poll slaves) STEP 7 V5.x; TIA V13+ via compatibility block
Modbus Slave RTU, CP 341/340 6ES7 870-1AB01-0YA0 CP acts as Modbus RTU slave (responds to master) STEP 7 V5.x; TIA V13+ via compatibility block
Modbus Master RTU, CP 341/340 (TIA V15+) 6ES7 870-1AA01-0YA1 Updated master driver with TIA integration TIA V15 and later
Modbus Slave RTU, CP 341/340 (TIA V15+) 6ES7 870-1AB01-0YA1 Updated slave driver with TIA integration TIA V15 and later

Reference documentation:

STEP 7 / TIA Portal Configuration Procedure

  1. Install hardware. Insert the CP 341 in an S7-300 slot (slot 4–11 in the central rack, or any free slot in an expansion rack). Power down the CPU, slot the module, and apply power.
  2. Open the project in TIA Portal (V15 or later recommended) or STEP 7 V5.6.
  3. Add the CP 341 to the device configuration. In the hardware catalog, navigate to SIMATIC S7-300 > Communication > CP 340/341 and drag the exact MLFB (for example 6ES7 341-1CH01-0AE0) onto the rack. Confirm the firmware version matches the physical module (readable via online diagnostics).
  4. Configure the serial interface. Double-click the CP 341 to open the properties. Set the protocol to Modbus Master or Modbus Slave, baud rate (1200, 2400, 4800, 9600, 19200, 38400, 57600, 115200), parity (None / Even / Odd), data bits (8), and stop bits (1 or 2). For Modbus RTU the default is 8E1; the 11-bit frame is mandatory per the Modbus specification.
  5. Load the licensed driver to the CP. The first time the project is downloaded, TIA Portal will prompt to load the Modbus driver firmware to the CP 341's flash. Accept the prompt; this takes 30–90 seconds. Verify in the CP online diagnostics: Diagnostic buffer > Module information > Protocol loaded = Modbus Master RTU.
  6. Call the Modbus function block in the user program. The TIA Portal library "Modbus_RTU_CP341" provides FB blocks. Wire the instance DB, supply the slave address, function code (01–06, 15, 16), start address, and data buffer. Trigger with a positive edge on the REQ input.
  7. Download and test. Use a Modbus RTU slave simulator on a laptop (for example, Modbus Poll or the free QModMaster tool) wired to the CP 341's RS-485 port to verify the request/response cycle before connecting the real field device.

Sample call (structured text, TIA Portal)

// Modbus RTU master read holding registers (FC 03)
// instance: "ModbusMaster_DB" from library Modbus_RTU_CP341
// CP341 slot address: 4 (rack 0, slot 4)

IF "Tag_Start_Read" AND NOT "Busy" THEN
    "ModbusMaster_DB".REQ := TRUE;
    "ModbusMaster_DB".SLAVE_ADDR := 1;            // Slave ID 1
    "ModbusMaster_DB".FUNCTION_CODE := 3;          // FC 03 read holding regs
    "ModbusMaster_DB".START_ADDRESS := 0;          // Start at 40001
    "ModbusMaster_DB".QUANTITY := 10;              // Read 10 registers
    "ModbusMaster_DB".DATA_PTR := "HoldingRegs";  // Pointer to DB area
    "ModbusMaster_DB".LADDR := 256;                // I/O start address from HW config
END_IF;

"ModbusMaster_DB".REQ := FALSE;  // Self-reset after one scan

Wiring, Termination, and Serial Parameters

Modbus RTU over RS-485 is half-duplex on a single shielded twisted pair. Cabling practices determine reliability more than any software setting.

  • Cable type: Belden 3106A or equivalent, 24 AWG, 120 ohm characteristic impedance, overall shield.
  • Maximum segment length: 1200 m at 9600 baud; 500 m at 19200; 200 m at 115200. Reduce by 50% if the route passes near VFD power cables.
  • Termination: 120 ohm resistor at both ends of the segment, between A and B. The Siemens 6ES7 972-0BA12-0XA0 termination plug inserts between pins 11 and 4 of the CP 341's sub-D and provides the bias resistors as well.
  • Shield grounding: Ground the shield at one end only, typically at the panel entry, to avoid ground loops. Use a cable gland that contacts 360 degrees.
  • Stubs: Avoid T-branches. Multi-drop must be a true daisy chain. Stub length < 0.3 m.

Timing budget: at 9600 baud, 8E1, a 1-register read (FC 03) takes approximately 25 ms (3.5 char turnaround + 8 char request + 1 char delay + 7 char response). Plan your OB1 cycle and the Modbus master's inter-frame delay (default 50 ms in the CP 341) accordingly.

Alternative Path: Modbus TCP via CP 343-1 + External Gateway

If the project already has a CP 343-1 in the rack, or if the field device is more than 15 m away and an RS-485 run is impractical, a Modbus TCP-to-RTU gateway is often simpler and faster to commission than re-racking a CP 341. The architecture is:

  1. The S7-300 uses the CP 343-1 to open TCP socket connections (FB 65 "TCON", FB 66 "TRECV", FB 67 "TSEND" in STEP 7; the open Modbus/TCP library from IT4Industry wraps these into FC 03 / FC 16 calls).
  2. An external industrial gateway terminates the Modbus TCP socket on the Ethernet side and presents a Modbus RTU master port on the RS-485 side.
  3. The field device connects to the gateway's RS-485 port as a Modbus RTU slave.

Common gateway products:

Device Mode Notes
Lantronix XPress-DR-IAP TCP slave ↔ RTU master Single RS-232/422/485 port, web config, 10/100 Ethernet, 24 VDC, industrial temp range
Moxa MGate MB3180 TCP master/slave ↔ RTU master/slave 1 port, 2 kV isolation, IEC 61850-3 option
Anybus X-gateway Modbus TCP TCP slave ↔ RTU master/slave Fieldbus-style gateway for cabinet mounting

This architecture is also the right answer when the Modbus RTU device is remote (cellular, radio, or across a plant LAN) and only the SCADA sees a TCP front-end.

Integration with HMI and WinCC

For an S7-300 reading a Modbus RTU device and presenting the values on an HMI, the typical data path is:

  1. CP 341 reads Modbus RTU → CPU DB (for example DB100).
  2. CPU DB → PROFINET or MPI to the HMI (TP, Comfort Panel, or WinCC Runtime).
  3. HMI tag points at the DB100 word, displays the value.

For a central SCADA on WinCC 7.0 (or WinCC Professional in TIA), the same DB100 is exposed via the S7 driver in WinCC. No Modbus-specific configuration is required on the SCADA side; the S7-300 abstracts the RTU into a standard S7 tag.

Common mistake: Trying to run a Modbus RTU driver directly on WinCC and connect to the RS-485 bus. WinCC does not have native Modbus RTU master support for S7-300 CPs. The S7-300 CPU must own the RTU master and the SCADA must read S7 tags.

Troubleshooting Matrix

Symptom Likely Cause Verification Corrective Action
CP 343-1 in slot, no RS-485 port visible Wrong module selected; CP 343-1 is Ethernet only Read MLFB on the front bezel; check that it begins with 6GK7 343 Replace with 6ES7 341-1CH01-0AE0 (RS-485) or 6ES7 341-1AH01-0AE0 (RS-232C)
TIA Portal device catalog shows CP 341 grayed out Module not licensed in the project, or HSP not installed Check Options > Manage HSP; confirm a valid S7-300 license Install latest TIA HSP for CP 341 from the Siemens Online Software Delivery portal
FB returns error 0x0001 "License missing" Modbus RTU loadable driver not present on the CP flash Online > CP 341 > Module information > Protocol Re-download the project with "Load protocol driver" checked; the driver file is shipped with the 6ES7 870-1AA01-0YA0 / -1AB01-0YA0 package
CP LEDs: SF red, RX/TX not toggling Wiring error: A/B swapped, termination missing, or shield not grounded Measure 0.3–5 V differential across A-B at the CP with bus idle Correct A/B polarity, add 120 ohm terminators at both ends, ground shield at one end
CP responds to FB call with timeout (error 0x7000 / 0x7005) Slave address mismatch, wrong baud, or no slave on the bus Connect Modbus Poll as master, set slave to the expected address; if it responds, the bus is healthy Adjust slave address in the FB call; verify baud / parity / data bits match the slave's Modbus map
Intermittent CRC errors (error 0x8081) Electromagnetic interference from VFD, or missing termination, or excessive stub length Run a long oscilloscope capture on A-B; look for ringing at the bit transitions Re-route cable, add ferrite cores, terminate at both ends, shorten stubs to < 0.3 m
CP 341 and DP master in the same rack, CPU stops during DP startup CP 341 inserted in a slot that conflicts with the IM/DP interface Check the S7-300 mounting manual for allowed slot positions per rack Move the CP 341 to a free slot in slots 4–11 of the central rack
Modbus TCP gateway: TCP socket opens, RTU response never arrives Gateway is configured as TCP slave + RTU slave (wrong direction) Read gateway's active mode from its web interface Reconfigure the gateway to TCP slave + RTU master (most Lantronix/Moxa defaults) and ensure the field device is set as RTU slave address 1–247

Verification Procedure

  1. Loopback test. Wire the CP 341 RS-485 port to itself (T/R+ to RX+, T/R- to RX-). Send a Modbus FC 03 read to slave 1; the CP should echo its own response with no error.
  2. Slave simulator test. Connect a Windows laptop running Modbus Poll or QModMaster to the bus. Verify that the laptop can read and write the field device's registers directly.
  3. Online diagnostic check. In TIA Portal, go online with the CP 341 and inspect the diagnostic buffer. The last entry should show the last Modbus transaction with status 0x0000 (no error) and the byte count echoed back.
  4. HMI tag monitor. Force the FB to read continuously with a 200 ms OB1 tick. Add a watch table on the destination DB and confirm the data updates.
  5. Long-run stability test. Leave the system running for 24 hours. Count CRC error increments in the CP's diagnostic buffer; the count must remain zero.

Field-Proven Caveats

  • One Modbus master per bus. If the CP 341 is the master, do not connect another master (SCADA, HMI, gateway) to the same RS-485 segment. Two masters produce colliding frames and CRC errors that are impossible to recover at the protocol level.
  • Ground potential differences. A 0 V to 24 V supply on the CP and a 0 V to 24 V supply at a remote panel can produce several volts of ground potential. RS-485 survives this only if the galvanic isolation on the CP 341 is intact (check that the 24 V supply and the serial shield are referenced to the same PE). If not, install an RS-485 isolator such as a Phoenix Contact PSM-ME-RS485.
  • Inter-frame delay. Modbus RTU requires a 3.5 character silent gap between frames. The CP 341 implements this internally; do not back-to-back trigger Modbus FBs in OB1 without respecting the FB's DONE/NDR handshake, or the CP will drop requests silently.
  • Float / Double in Modbus. Modbus RTU only carries 16-bit registers. To exchange a 32-bit REAL, you must read two consecutive registers and byte-swap in the CPU (or use the CP 341's "Byte swap" flag in the protocol configuration). Endian mismatch between the field device and the S7-300 is the single most common "my number is wrong" complaint on commissioning day.
  • Firmware version pinning. If you upgrade the CP 341 firmware to match a TIA V17 project, the Modbus driver may need to be re-loaded. The driver is paired with the firmware. Do not assume the driver persists across a firmware update.

FAQ

Can a CP 343-1 (6GK7 343-1EX11-0XE0) run Modbus RTU?

No. The CP 343-1 family is Industrial Ethernet and PROFINET only. It has no serial port, no UART, and no Modbus RTU firmware. Use a CP 341 (6ES7 341-1CH01-0AE0 for RS-485) with the loadable Modbus RTU driver 6ES7 870-1AA01-0YA0 (master) or 6ES7 870-1AB01-0YA0 (slave).

Which CP 341 variant should I order for a 2-wire Modbus RTU bus?

Order 6ES7 341-1CH01-0AE0 (RS-422/485). Wire T/R+ (pin 11) to Data A and T/R- (pin 4/9) to Data B. Place a 120 ohm termination at both ends of the segment using the 6ES7 972-0BA12-0XA0 termination plug on the CP end.

Do I need a separate license for the Modbus RTU driver on the CP 341?

Yes. Modbus RTU is delivered as a loadable driver on the 6ES7 870-1AA01-0YA0 (master) or 6ES7 870-1AB01-0YA0 (slave) package. The driver is downloaded to the CP 341's flash on the first project download. Without it, the Modbus FB returns error 0x0001 "license missing" and the CP reports no protocol loaded.

What is the maximum cable length for Modbus RTU over RS-485 on a CP 341?

Up to 1200 m at 9600 baud, 500 m at 19200 baud, and 200 m at 115200 baud. Use Belden 3106A or equivalent 120 ohm shielded twisted pair, terminate both ends with 120 ohm resistors, and ground the shield at one end only to avoid ground loops.

Can I use a Modbus TCP gateway with the existing CP 343-1 instead of adding a CP 341?

Yes. The S7-300 opens a TCP socket to a Lantronix XPress-DR-IAP (or Moxa MGate MB3180) gateway using FB 65/66/67 or the IT4Industry Modbus/TCP library. The gateway converts the TCP requests to Modbus RTU on its RS-485 port to the field device. This is the right approach when the field device is remote, the bus is hard to wire, or the existing rack already has a CP 343-1.

Back to blog