Siemens CP 341 / CP 441-2 Modbus Dongle: Purpose, Installation, and RTU Driver Loading Reference
The hardware dongle supplied with the SIMATIC S7-300 / S7-400 point-to-point communication processors (CP 341 and CP 441-2) is a physical license key that unlocks the loadable Modbus RTU master or slave firmware stored inside the CP. Without the dongle seated in the module, the CP boots without any Modbus RTU driver loaded, and any attempt to call Modbus function blocks from the CPU returns driver-not-loaded errors. This reference consolidates the official Siemens installation procedure, the dongle part numbers, the supported Modbus function codes, and a verification procedure so commissioning engineers can bring Modbus RTU links online deterministically on a CP 341 or CP 441-2.
Why Siemens Uses a Dongle for the Modbus Driver
The CP 341 and CP 441-2 are sold with a generic point-to-point (PTP) base driver that supports ASCII, 3964(R), and RK 512 framing. Modbus RTU is a separately licensed loadable driver because:
- Modbus RTU master / slave is an optional protocol stack, not a base capability of the CP.
- Siemens distributes the RTU driver on a separate CD (the "Loadable Driver for Point-to-Point CPs" package) and binds the runtime authorization to a small hardware token.
- Master and slave roles are licensed independently, so a site that only polls slaves pays for a master dongle only.
This matches the same loadable-driver architecture used for the SIMATIC S7-300/S7-400 Loadable Driver for Point-to-Point CPs: MODBUS protocol, RTU format. The dongle is not an encryption device and not a security token in the IT sense; it is a presence-detect jumper that tells the CP firmware "you are permitted to expose the Modbus driver symbol set to the S7 program".
Compatible Communication Processors
The dongle mechanism is specific to the S7-300 / S7-400 PTP CPs that accept loadable drivers. Newer CPs (CP 340, ET 200S 1SI, CM PtP in S7-1500) have different or no dongle requirements; only the modules listed below use the dongle-style licensing.
| CP | MLFB (order number) | Interfaces | Modbus support | Manual entry |
|---|---|---|---|---|
| CP 341-1A | 6ES7341-1AH02-0AE0 | 1 × RS 232C (V.24) | Loadable RTU master / slave (dongle) | Entry 51992638 |
| CP 341-1B | 6ES7341-1BH02-0AE0 | 1 × 20 mA TTY | Loadable RTU master / slave (dongle) | Entry 51992638 |
| CP 341-1C | 6ES7341-1CH02-0AE0 | 1 × RS 422 / RS 485 | Loadable RTU master / slave (dongle) | Entry 51992638 |
| CP 441-2 | 6ES7441-2AA03-0AE0 / -2AA04-0AE0 | 2 × plug-in submodules (RS 232C, RS 422/485, 20 mA) | Loadable RTU master / slave (dongle, per interface) | Entry 1117702 |
Verify the MLFB and firmware version (read with STEP 7 → Online → Module Information) match the dongle variant. A master dongle will not activate a slave driver and vice versa.
Dongle Order Numbers
Each dongle is tied to a single role (master or slave) and a single CP family. Using a dongle on a CP family it is not licensed for is silently rejected at boot. Keep spare dongles in static-safe storage; they are not field-replaceable while the plant is running because the CP must be removed from the rack to insert or swap the dongle.
| Role | CP family | Dongle MLFB | Packaged with |
|---|---|---|---|
| Modbus RTU master | CP 341 | 6ES7870-1AA01-0YA0 | Loadable Driver CD, master edition |
| Modbus RTU slave | CP 341 | 6ES7870-1AB01-0YA0 | Loadable Driver CD, slave edition |
| Modbus RTU master | CP 441-2 | 6ES7870-1AC01-0YA0 | Loadable Driver CD, CP 441 master |
| Modbus RTU slave | CP 441-2 | 6ES7870-1AD01-0YA0 | Loadable Driver CD, CP 441 slave |
Hardware Installation Procedure
The dongle socket is on the rear face of the CP, directly above the backplane bus connector. The CP must be removed from the rack to access it. Plan a short outage; the S7 station will go into stop / IO failure if the CP is the active PTP master for any open Modbus link.
- Power the S7 station down. Place the CPU in STOP, then remove the 24 V supply to the rack or de-energise the backplane per local lockout / tagout procedure. Removing the CP under power can corrupt the driver load.
- Label and disconnect the serial cable. Note the RS 232C / RS 422 / RS 485 pinout; the CP 341 connector is keyed but label wires for fast re-seat.
- Release the CP from the rack. On the S7-300 rack, press the locking tab above the CP and tilt it forward. On the S7-400 rack, loosen the two screws at the top and bottom of the front panel.
- Locate the dongle socket. Turn the CP so the backplane connector faces you. The dongle socket is the small card-edge connector centred horizontally, located directly above the backplane bus plug.
- Insert the dongle. Orient the dongle PCB so the component side faces the CP housing. Press it straight into the socket until the card-edge is fully seated. The dongle protrudes approximately 5 mm from the rear face; this is normal.
- Re-install the CP. Re-seat the module on the rack, tighten the locking screws, and re-attach the serial connector.
- Restore power and observe the CP LEDs. On power-up, the CP 341 SF LED should extinguish within ~5 s and the TxD / RxD LEDs should blink once during driver initialisation. Persistent SF with a diagnostic buffer entry "Modbus driver not loaded" indicates the dongle is not detected.
Driver Loading and Configuration in STEP 7
The dongle authorises the firmware; the driver itself must still be loaded into the CP via STEP 7 (or, for S7-300, via the TIA Portal PTP Parameter assignment tool that wraps the legacy loader). The CP's onboard flash holds one loadable driver at a time. Loading a new driver overwrites the previous one.
Loading path in STEP 7 (Classic)
- Open the S7 project, expand the S7-300 / S7-400 station, and double-click the CP 341 / CP 441-2 in HW Config.
- Select the CP, then choose PLC → Load Driver to CP (or right-click → "Loadable driver").
- Browse to the directory containing the Modbus RTU driver files (the CD or extracted folder from the Loadable Driver package). The driver file is named
CP341MOD.MSEfor the CP 341 master orCP341SLA.MSEfor the slave variant. - STEP 7 transfers the driver to the CP's flash; progress is shown in a status bar. Total transfer time is typically 30–90 s over MPI/PROFIBUS at 1.5 Mbit/s.
- After successful transfer, the CP performs a reset and comes back online. The diagnostic buffer records entry
0x0B / W#16#0311"Driver loaded successfully".
PTP Parameter Assignment
After the driver is loaded, open the CP's properties dialog in HW Config and configure each interface:
| Parameter | Typical value | Notes |
|---|---|---|
| Protocol | MODBUS master / MODBUS slave | Selects the role of this CP on this interface |
| Baud rate | 9600 / 19200 bit/s | CP 441-2 supports up to 38400 bit/s; CP 341 up to 19200 (RS 232C) or 9600 (RS 485) |
| Parity | Even | Modbus RTU mandates even or no parity; most slaves default to even |
| Data bits | 8 | Fixed for Modbus RTU |
| Stop bits | 1 | Fixed for Modbus RTU |
| Response timeout | 2000 ms | Adjust per slave turnaround; default 2000 ms covers most serial-line slaves |
| Inter-character timeout | 50 ms (auto-derived) | CP computes from baud; do not manually override unless documenting a deliberate relaxation |
Compile and download the HW Config to the CPU. The new parameters are pushed to the CP on next STOP → RUN transition of the CPU.
Modbus RTU Protocol Implementation
With the driver loaded, the CP exposes Modbus RTU function codes to the S7 program via the CP's function blocks (FB 7 / FB 8 for CP 341 master, FB 80 / SFB 9 for the slave side, with the actual block numbers depending on the loadable driver version and STEP 7 library). Each Modbus transaction is parameterised by a Send DB the user builds in the S7 program.
| Modbus function code | Name | Use on CP | Typical Send DB layout (master side) |
|---|---|---|---|
| 01 | Read Coils | Master → slave | Slave address, starting coil, quantity |
| 02 | Read Discrete Inputs | Master → slave | Slave address, starting input, quantity |
| 03 | Read Holding Registers | Master → slave | Slave address, starting register, quantity |
| 04 | Read Input Registers | Master → slave | Slave address, starting register, quantity |
| 05 | Write Single Coil | Master → slave | Slave address, coil address, value (0xFF00 / 0x0000) |
| 06 | Write Single Register | Master → slave | Slave address, register address, value |
| 15 (0x0F) | Write Multiple Coils | Master → slave | Slave address, starting coil, quantity, byte count, coil bytes |
| 16 (0x10) | Write Multiple Registers | Master → slave | Slave address, starting register, quantity, byte count, register words |
Slave-side implementations (CP 341 configured as slave or CP 441-2 with slave dongle) respond to function codes 01, 02, 03, 04, 05, 06, 15, 16 out of the box. Custom function codes are not supported by the loadable driver.
Send and Receive Data Block Structure
The Send DB is the parameter buffer the S7 program hands to the Modbus FB on each request. For a master read holding register (FC 03) request, the Send DB is structured as:
DATA_BLOCK "ModReq_DB"
STRUCT
SlaveAddress : BYTE := B#16#01; // Modbus slave address 1
FunctionCode : BYTE := B#16#03; // Read Holding Registers
StartAddress : WORD := W#16#0000; // Holding register 40001
Quantity : WORD := W#16#000A; // 10 registers
END_STRUCT;
END_DATA_BLOCK
The Receive DB returns the response, with the first two bytes echoed from the request (slave, FC), the byte count, and the payload. Always pre-initialise the Receive DB to zeros before each call so leftover data from a previous transaction cannot be misinterpreted by the application code.
For a master write-multiple-registers (FC 16) request, the Send DB must include the byte-count and the register payload. Slave-side writes land in the configured Receive DB on the slave CP, which the S7 program polls and converts to process I/O.
Verification and Diagnostics
After commissioning, verify the dongle is recognised, the driver is loaded, and the protocol stack is responsive at the link layer before declaring the Modbus link healthy.
-
Dongle detection. In STEP 7, go online, open the CP, and select PLC → Module Information → Diagnostic Buffer. Look for entry
W#16#0311"Driver loaded successfully" recorded at the most recent STOP → RUN transition. The absence of this entry, combined with entryW#16#0312"Modbus driver not found", confirms a missing or mis-seated dongle. -
Parameter check. Open PLC → Accessible Nodes, double-click the CP, and look at the "Loaded drivers" line. The entry should read
MODBUS master v1.xorMODBUS slave v1.x. A line showing--means the CP booted without a loadable driver. - Loopback test. With the dongle installed, terminate the RS 485 port with a 120 Ω resistor between A and B and short TX+/TX- to RX+/RX- inside the connector. From STEP 7, trigger a FC 03 read of a register; the response echoes back and the FB returns STATUS = W#16#0000.
- Link LED pattern. TxD and RxD LEDs should blink alternately during a poll. A solid TxD with no RxD return typically indicates a wiring inversion (A/B swapped) or a missing termination.
- Cyclic test against the live slave. Use the standard S7 Modbus example project included with the Loadable Driver CD. Run the example master against the actual slave for at least 100 transactions and verify zero CRC errors in the CP diagnostic buffer.
Troubleshooting Matrix
| Symptom | Diagnostic buffer entry | Root cause | Corrective action |
|---|---|---|---|
| SF LED on, no driver loaded | W#16#0312 "Modbus driver not found" | Dongle absent, wrong dongle (master on a slave CP), or dongle not fully seated | Power down, reseat the dongle; verify MLFB matches CP role |
| Driver loaded but FB returns STATUS W#16#0E01 | W#16#0E01 "Driver not loaded" | CPU is referencing the wrong CP logical address, or driver was deleted by another download | Re-load the driver from STEP 7 |
| No response from slave, TxD blinks, RxD stays off | W#16#0801 "No response from slave within timeout" | Wrong baud / parity on either end, swapped A/B on RS 485, or slave address mismatch | Verify both ends at the same 9600/8E1, swap A/B, confirm slave address in Send DB |
| Frequent CRC errors, response timeouts intermittent | W#16#0802 "CRC error in response" | Missing termination, long stub, or EMI on the RS 485 cable | Add 120 Ω terminators at both ends, use twisted pair, keep stubs under 1 m |
| Slave CP does not respond to FC 06 from master | W#16#0803 "Illegal function" | Function code disabled in slave's PTP parameter assignment | Open the slave CP properties, enable FC 06 in the function mask |
| Communication works in test rig, fails on plant power-up | W#16#0311 then W#16#0312 after restart | Vibration unseating the dongle, or backplane connector intermittent | Add vibration mounts, verify rack grounding, replace the backplane connector |
Migration and Replacement Notes
If the project moves to an S7-1500, the equivalent of CP 341 + dongle is the CM PtP (6ES7540-1AB00-0AA0 or -1AD00) configured as a Modbus master / slave directly in TIA Portal, with no dongle and no loadable driver to manage. The Modbus FB library differs (MB_CLIENT / MB_SERVER / MODBUS_PN blocks for S7-1500), but the application-level Send / Receive DB concept carries over. For sites that cannot yet move to S7-1500, the CP 341 + dongle combination remains supported on current STEP 7 V5.x and TIA Portal V17 SP1 onward.
Frequently Asked Questions
Does the CP 341 need a dongle for ASCII or 3964(R) protocols?
No. The dongle is only required for the loadable Modbus RTU driver. ASCII, 3964(R), and RK 512 ship as base drivers inside the CP and do not need a hardware license key.
Can one dongle unlock both interfaces of a CP 441-2?
Yes, but only when the dongle is licensed for the CP 441-2 family. The CP 441-2 master dongle (6ES7870-1AC01-0YA0) authorises the Modbus master driver to load on both interfaces; the CP 441-2 slave dongle does the same for the slave driver. Mixing master and slave on the same CP 441-2 requires two dongles.
What happens if the dongle is removed while the CPU is in RUN?
The CP keeps running with the last loaded driver until the next STOP → RUN transition of the CPU, at which point the CP re-detects the missing dongle and refuses to load the driver. Modbus calls then return STATUS W#16#0E01 "Driver not loaded". Avoid mid-run removal; schedule an outage.
Which Modbus function codes are supported by the loadable driver?
The driver supports function codes 01 (Read Coils), 02 (Read Discrete Inputs), 03 (Read Holding Registers), 04 (Read Input Registers), 05 (Write Single Coil), 06 (Write Single Register), 15 (Write Multiple Coils), and 16 (Write Multiple Registers). Custom or vendor-specific function codes are not implemented.
Can I write my own Modbus RTU driver instead of buying the dongle?
Technically yes, but Siemens does not support user-written drivers on the CP 341 / CP 441-2 loadable driver socket, and the CP firmware exposes no documented API for doing so. Any custom driver would also have to re-implement 3964(R) framing, CRC handling, and inter-character timing to coexist with the base driver. The commercially supported path is to purchase the dongle and use the supplied loadable driver.