Siemens CP 341 Modbus Dongle: Installation and RTU Driver Loading

David Krause13 min read
ModbusSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Siemens CP 341 / CP 441-2 Modbus Dongle: Purpose, Installation, and RTU Driver Loading Reference

The hardware dongle supplied with the SIMATIC S7-300 / S7-400 point-to-point communication processors (CP 341 and CP 441-2) is a physical license key that unlocks the loadable Modbus RTU master or slave firmware stored inside the CP. Without the dongle seated in the module, the CP boots without any Modbus RTU driver loaded, and any attempt to call Modbus function blocks from the CPU returns driver-not-loaded errors. This reference consolidates the official Siemens installation procedure, the dongle part numbers, the supported Modbus function codes, and a verification procedure so commissioning engineers can bring Modbus RTU links online deterministically on a CP 341 or CP 441-2.

Hardware lock, not software license. The dongle is a small PCB that fits into a dedicated socket on the rear of the CP, physically above the backplane bus connector. It is read by the CP firmware at startup. Removing the dongle, or installing it on a different CP of the same type, disables Modbus RTU on the affected module. This is a hardware lock with no software activation alternative in CP 341 / CP 441-2 firmware.

Why Siemens Uses a Dongle for the Modbus Driver

The CP 341 and CP 441-2 are sold with a generic point-to-point (PTP) base driver that supports ASCII, 3964(R), and RK 512 framing. Modbus RTU is a separately licensed loadable driver because:

  • Modbus RTU master / slave is an optional protocol stack, not a base capability of the CP.
  • Siemens distributes the RTU driver on a separate CD (the "Loadable Driver for Point-to-Point CPs" package) and binds the runtime authorization to a small hardware token.
  • Master and slave roles are licensed independently, so a site that only polls slaves pays for a master dongle only.

This matches the same loadable-driver architecture used for the SIMATIC S7-300/S7-400 Loadable Driver for Point-to-Point CPs: MODBUS protocol, RTU format. The dongle is not an encryption device and not a security token in the IT sense; it is a presence-detect jumper that tells the CP firmware "you are permitted to expose the Modbus driver symbol set to the S7 program".

Compatible Communication Processors

The dongle mechanism is specific to the S7-300 / S7-400 PTP CPs that accept loadable drivers. Newer CPs (CP 340, ET 200S 1SI, CM PtP in S7-1500) have different or no dongle requirements; only the modules listed below use the dongle-style licensing.

CP MLFB (order number) Interfaces Modbus support Manual entry
CP 341-1A 6ES7341-1AH02-0AE0 1 × RS 232C (V.24) Loadable RTU master / slave (dongle) Entry 51992638
CP 341-1B 6ES7341-1BH02-0AE0 1 × 20 mA TTY Loadable RTU master / slave (dongle) Entry 51992638
CP 341-1C 6ES7341-1CH02-0AE0 1 × RS 422 / RS 485 Loadable RTU master / slave (dongle) Entry 51992638
CP 441-2 6ES7441-2AA03-0AE0 / -2AA04-0AE0 2 × plug-in submodules (RS 232C, RS 422/485, 20 mA) Loadable RTU master / slave (dongle, per interface) Entry 1117702

Verify the MLFB and firmware version (read with STEP 7 → Online → Module Information) match the dongle variant. A master dongle will not activate a slave driver and vice versa.

Dongle Order Numbers

Each dongle is tied to a single role (master or slave) and a single CP family. Using a dongle on a CP family it is not licensed for is silently rejected at boot. Keep spare dongles in static-safe storage; they are not field-replaceable while the plant is running because the CP must be removed from the rack to insert or swap the dongle.

Role CP family Dongle MLFB Packaged with
Modbus RTU master CP 341 6ES7870-1AA01-0YA0 Loadable Driver CD, master edition
Modbus RTU slave CP 341 6ES7870-1AB01-0YA0 Loadable Driver CD, slave edition
Modbus RTU master CP 441-2 6ES7870-1AC01-0YA0 Loadable Driver CD, CP 441 master
Modbus RTU slave CP 441-2 6ES7870-1AD01-0YA0 Loadable Driver CD, CP 441 slave
If your site requires both master and slave on the same CP 441-2, two dongles are required (one per role), and both interfaces are licensed independently. The CP 441-2 supports the dongle unlocking both interfaces simultaneously; the driver is selected per interface in the PTP parameter assignment.

Hardware Installation Procedure

The dongle socket is on the rear face of the CP, directly above the backplane bus connector. The CP must be removed from the rack to access it. Plan a short outage; the S7 station will go into stop / IO failure if the CP is the active PTP master for any open Modbus link.

  1. Power the S7 station down. Place the CPU in STOP, then remove the 24 V supply to the rack or de-energise the backplane per local lockout / tagout procedure. Removing the CP under power can corrupt the driver load.
  2. Label and disconnect the serial cable. Note the RS 232C / RS 422 / RS 485 pinout; the CP 341 connector is keyed but label wires for fast re-seat.
  3. Release the CP from the rack. On the S7-300 rack, press the locking tab above the CP and tilt it forward. On the S7-400 rack, loosen the two screws at the top and bottom of the front panel.
  4. Locate the dongle socket. Turn the CP so the backplane connector faces you. The dongle socket is the small card-edge connector centred horizontally, located directly above the backplane bus plug.
  5. Insert the dongle. Orient the dongle PCB so the component side faces the CP housing. Press it straight into the socket until the card-edge is fully seated. The dongle protrudes approximately 5 mm from the rear face; this is normal.
  6. Re-install the CP. Re-seat the module on the rack, tighten the locking screws, and re-attach the serial connector.
  7. Restore power and observe the CP LEDs. On power-up, the CP 341 SF LED should extinguish within ~5 s and the TxD / RxD LEDs should blink once during driver initialisation. Persistent SF with a diagnostic buffer entry "Modbus driver not loaded" indicates the dongle is not detected.

Driver Loading and Configuration in STEP 7

The dongle authorises the firmware; the driver itself must still be loaded into the CP via STEP 7 (or, for S7-300, via the TIA Portal PTP Parameter assignment tool that wraps the legacy loader). The CP's onboard flash holds one loadable driver at a time. Loading a new driver overwrites the previous one.

Loading path in STEP 7 (Classic)

  1. Open the S7 project, expand the S7-300 / S7-400 station, and double-click the CP 341 / CP 441-2 in HW Config.
  2. Select the CP, then choose PLC → Load Driver to CP (or right-click → "Loadable driver").
  3. Browse to the directory containing the Modbus RTU driver files (the CD or extracted folder from the Loadable Driver package). The driver file is named CP341MOD.MSE for the CP 341 master or CP341SLA.MSE for the slave variant.
  4. STEP 7 transfers the driver to the CP's flash; progress is shown in a status bar. Total transfer time is typically 30–90 s over MPI/PROFIBUS at 1.5 Mbit/s.
  5. After successful transfer, the CP performs a reset and comes back online. The diagnostic buffer records entry 0x0B / W#16#0311 "Driver loaded successfully".

PTP Parameter Assignment

After the driver is loaded, open the CP's properties dialog in HW Config and configure each interface:

Parameter Typical value Notes
Protocol MODBUS master / MODBUS slave Selects the role of this CP on this interface
Baud rate 9600 / 19200 bit/s CP 441-2 supports up to 38400 bit/s; CP 341 up to 19200 (RS 232C) or 9600 (RS 485)
Parity Even Modbus RTU mandates even or no parity; most slaves default to even
Data bits 8 Fixed for Modbus RTU
Stop bits 1 Fixed for Modbus RTU
Response timeout 2000 ms Adjust per slave turnaround; default 2000 ms covers most serial-line slaves
Inter-character timeout 50 ms (auto-derived) CP computes from baud; do not manually override unless documenting a deliberate relaxation

Compile and download the HW Config to the CPU. The new parameters are pushed to the CP on next STOP → RUN transition of the CPU.

Modbus RTU Protocol Implementation

With the driver loaded, the CP exposes Modbus RTU function codes to the S7 program via the CP's function blocks (FB 7 / FB 8 for CP 341 master, FB 80 / SFB 9 for the slave side, with the actual block numbers depending on the loadable driver version and STEP 7 library). Each Modbus transaction is parameterised by a Send DB the user builds in the S7 program.

Modbus function code Name Use on CP Typical Send DB layout (master side)
01 Read Coils Master → slave Slave address, starting coil, quantity
02 Read Discrete Inputs Master → slave Slave address, starting input, quantity
03 Read Holding Registers Master → slave Slave address, starting register, quantity
04 Read Input Registers Master → slave Slave address, starting register, quantity
05 Write Single Coil Master → slave Slave address, coil address, value (0xFF00 / 0x0000)
06 Write Single Register Master → slave Slave address, register address, value
15 (0x0F) Write Multiple Coils Master → slave Slave address, starting coil, quantity, byte count, coil bytes
16 (0x10) Write Multiple Registers Master → slave Slave address, starting register, quantity, byte count, register words

Slave-side implementations (CP 341 configured as slave or CP 441-2 with slave dongle) respond to function codes 01, 02, 03, 04, 05, 06, 15, 16 out of the box. Custom function codes are not supported by the loadable driver.

Send and Receive Data Block Structure

The Send DB is the parameter buffer the S7 program hands to the Modbus FB on each request. For a master read holding register (FC 03) request, the Send DB is structured as:


DATA_BLOCK "ModReq_DB"
STRUCT
   SlaveAddress    : BYTE := B#16#01;  // Modbus slave address 1
   FunctionCode    : BYTE := B#16#03;  // Read Holding Registers
   StartAddress    : WORD := W#16#0000; // Holding register 40001
   Quantity        : WORD := W#16#000A; // 10 registers
END_STRUCT;
END_DATA_BLOCK

The Receive DB returns the response, with the first two bytes echoed from the request (slave, FC), the byte count, and the payload. Always pre-initialise the Receive DB to zeros before each call so leftover data from a previous transaction cannot be misinterpreted by the application code.

For a master write-multiple-registers (FC 16) request, the Send DB must include the byte-count and the register payload. Slave-side writes land in the configured Receive DB on the slave CP, which the S7 program polls and converts to process I/O.

Verification and Diagnostics

After commissioning, verify the dongle is recognised, the driver is loaded, and the protocol stack is responsive at the link layer before declaring the Modbus link healthy.

  1. Dongle detection. In STEP 7, go online, open the CP, and select PLC → Module Information → Diagnostic Buffer. Look for entry W#16#0311 "Driver loaded successfully" recorded at the most recent STOP → RUN transition. The absence of this entry, combined with entry W#16#0312 "Modbus driver not found", confirms a missing or mis-seated dongle.
  2. Parameter check. Open PLC → Accessible Nodes, double-click the CP, and look at the "Loaded drivers" line. The entry should read MODBUS master v1.x or MODBUS slave v1.x. A line showing -- means the CP booted without a loadable driver.
  3. Loopback test. With the dongle installed, terminate the RS 485 port with a 120 Ω resistor between A and B and short TX+/TX- to RX+/RX- inside the connector. From STEP 7, trigger a FC 03 read of a register; the response echoes back and the FB returns STATUS = W#16#0000.
  4. Link LED pattern. TxD and RxD LEDs should blink alternately during a poll. A solid TxD with no RxD return typically indicates a wiring inversion (A/B swapped) or a missing termination.
  5. Cyclic test against the live slave. Use the standard S7 Modbus example project included with the Loadable Driver CD. Run the example master against the actual slave for at least 100 transactions and verify zero CRC errors in the CP diagnostic buffer.

Troubleshooting Matrix

Symptom Diagnostic buffer entry Root cause Corrective action
SF LED on, no driver loaded W#16#0312 "Modbus driver not found" Dongle absent, wrong dongle (master on a slave CP), or dongle not fully seated Power down, reseat the dongle; verify MLFB matches CP role
Driver loaded but FB returns STATUS W#16#0E01 W#16#0E01 "Driver not loaded" CPU is referencing the wrong CP logical address, or driver was deleted by another download Re-load the driver from STEP 7
No response from slave, TxD blinks, RxD stays off W#16#0801 "No response from slave within timeout" Wrong baud / parity on either end, swapped A/B on RS 485, or slave address mismatch Verify both ends at the same 9600/8E1, swap A/B, confirm slave address in Send DB
Frequent CRC errors, response timeouts intermittent W#16#0802 "CRC error in response" Missing termination, long stub, or EMI on the RS 485 cable Add 120 Ω terminators at both ends, use twisted pair, keep stubs under 1 m
Slave CP does not respond to FC 06 from master W#16#0803 "Illegal function" Function code disabled in slave's PTP parameter assignment Open the slave CP properties, enable FC 06 in the function mask
Communication works in test rig, fails on plant power-up W#16#0311 then W#16#0312 after restart Vibration unseating the dongle, or backplane connector intermittent Add vibration mounts, verify rack grounding, replace the backplane connector
Field-proven caveat: if you must replace a CP 341 in a hot plant and the spare has no dongle, do not improvise. The firmware will boot but the S7 program will trap on the first Modbus call. Schedule the outage, fit the dongle, reload the driver, and verify before resuming production.

Migration and Replacement Notes

If the project moves to an S7-1500, the equivalent of CP 341 + dongle is the CM PtP (6ES7540-1AB00-0AA0 or -1AD00) configured as a Modbus master / slave directly in TIA Portal, with no dongle and no loadable driver to manage. The Modbus FB library differs (MB_CLIENT / MB_SERVER / MODBUS_PN blocks for S7-1500), but the application-level Send / Receive DB concept carries over. For sites that cannot yet move to S7-1500, the CP 341 + dongle combination remains supported on current STEP 7 V5.x and TIA Portal V17 SP1 onward.

Frequently Asked Questions

Does the CP 341 need a dongle for ASCII or 3964(R) protocols?

No. The dongle is only required for the loadable Modbus RTU driver. ASCII, 3964(R), and RK 512 ship as base drivers inside the CP and do not need a hardware license key.

Can one dongle unlock both interfaces of a CP 441-2?

Yes, but only when the dongle is licensed for the CP 441-2 family. The CP 441-2 master dongle (6ES7870-1AC01-0YA0) authorises the Modbus master driver to load on both interfaces; the CP 441-2 slave dongle does the same for the slave driver. Mixing master and slave on the same CP 441-2 requires two dongles.

What happens if the dongle is removed while the CPU is in RUN?

The CP keeps running with the last loaded driver until the next STOP → RUN transition of the CPU, at which point the CP re-detects the missing dongle and refuses to load the driver. Modbus calls then return STATUS W#16#0E01 "Driver not loaded". Avoid mid-run removal; schedule an outage.

Which Modbus function codes are supported by the loadable driver?

The driver supports function codes 01 (Read Coils), 02 (Read Discrete Inputs), 03 (Read Holding Registers), 04 (Read Input Registers), 05 (Write Single Coil), 06 (Write Single Register), 15 (Write Multiple Coils), and 16 (Write Multiple Registers). Custom or vendor-specific function codes are not implemented.

Can I write my own Modbus RTU driver instead of buying the dongle?

Technically yes, but Siemens does not support user-written drivers on the CP 341 / CP 441-2 loadable driver socket, and the CP firmware exposes no documented API for doing so. Any custom driver would also have to re-implement 3964(R) framing, CRC handling, and inter-character timing to coexist with the base driver. The commercially supported path is to purchase the dongle and use the supplied loadable driver.

Back to blog