Overview of Wireless Drive Control Requirements
Replacing hardwired control signals on a Siemens Micromaster MM440 (6SE6440) or Sinamics G120 (CU230P-2 / CU240E-2 / CU250S-2) with a wireless link is a recurring modernization request. Typical applications include remote start/stop of pump stations, mobile HMI panels on conveyors, tower-mounted fans, agricultural irrigation pumps, and retrofit installations where cable routing is impossible or cost-prohibitive. The customer's question is fundamentally a system-integration question: there is no single "wireless option module" for the MM440 or G120 because the wireless layer is an external network that carries an existing bus protocol (PROFINET, Modbus RTU, USS) to the drive.
This reference evaluates the six field-proven wireless topologies for MM440 and G120, the hardware part numbers required for each, the firmware prerequisites, the safety-relevant hardwired signals that must not be replaced by wireless, and the commissioning steps that confirm deterministic behavior. The reference applies to MM440 firmware V1.x and V2.x, and to G120 Control Units running SINAMICS firmware V4.5 through V5.2 SP3.
Wireless Control Architecture Decision Matrix
Select the wireless topology against the control requirement before choosing hardware. The table below maps drive-control use cases to the corresponding wireless architecture.
| Use Case | Recommended Wireless Architecture | Bus Protocol Carried | Typical Latency |
|---|---|---|---|
| Commissioning, parameterization, diagnostics from tablet/PC | G120 Smart Access (Wi-Fi) | Web server (HTTP/JSON) | 200-800 ms |
| Continuous run/stop, setpoint from PLC | PROFINET over Wi-Fi / 4G router | PROFINET RT (Class 1) | 5-50 ms |
| SCADA polling of multiple drives, no PLC | Modbus RTU wireless bridge | Modbus RTU over RS-485 | 50-300 ms |
| Start/stop and alarm from mobile phone, no local network | GSM/SMS modem with sm@rtserver | SMS, e-mail, MQTT | 2-15 s |
| Discrete start/stop only, no feedback | I/O wireless replicator (2.4 GHz) | Discrete mirror | 10-100 ms |
| S7-1200 control of MM440 with web visualization | S7-1200 + sm@rtserver + LAN/4G | USS / Modbus TCP | 100-500 ms |
Solution 1: Sinamics G120 Smart Access (Commissioning and Diagnostics Only)
The Sinamics G120 Smart Access module (part number 6SL3255-0AA00-5HA0) is a Wi-Fi access point that plugs into the G120 Control Unit's USB or RJ45 service port depending on CU variant. It is the only first-party Siemens wireless product in the G120 family. It broadcasts a WPA2-protected 2.4 GHz SSID of the form G120SmartAccess_[serial] with default passphrase on the device label.
Smart Access is not a control device in the closed-loop sense. It hosts a web-based commissioning interface served by the G120 webserver. Engineers connect a laptop, tablet (SINAMICS Smart Access App for iOS / Android), or phone, browse to 192.168.0.100, and gain read/write access to all parameters of P0000 through P9999. Functions include:
- Parameter upload/download (offline and online)
- Fault buffer reset (acknowledge faults remotely)
- Trace recording and download to USB
- Read-only actual values (r0021, r0022, r0035, r0070, r0078)
- Simple drive control via the "Control Panel" function (run forward, run reverse, stop, jog, set fixed setpoint)
Smart Access is intended for commissioning and diagnostics only. Do not use it for permanent process control: the connection drops on power cycles, the Wi-Fi range is limited to roughly 10 m inside cabinets, and the Web Control Panel times out after the configured inactivity interval (default 30 s, parameter p8992 on CU240E-2).
Solution 2: PROFINET over Industrial Wi-Fi / 4G Router
For continuous PROFINET control of a G120 with a CU250S-2 PN or CU240E-2 PN Control Unit, the wireless path is built between two industrial-grade Wi-Fi nodes. The PROFINET frames traverse the Wi-Fi link exactly as they would on copper. Both nodes must support the PROFINET update time of the configured IO device class.
Required hardware:
- G120 with PN-capable Control Unit:
6SL3246-0BA22-1FA0(CU240E-2 PN) or6SL3246-0BA22-1GA0(CU250S-2 PN) - Industrial Wi-Fi Access Point / Client pair with PROFINET passthrough. Validated devices include Scalance W778-1 (6GK5778-1AA00-0AA0) and third-party options such as Phoenix FL WLAN 5100 or Hirschmann BAT867-R.
- PROFINET-capable controller: S7-1200 (firmware V4.0+), S7-1500, ET 200SP CPU, or third-party PLC with PROFINET IRT/RT Class 1 conformance.
TIA Portal configuration procedure:
- Install the GSD file for the SINAMICS G120 PN from the Siemens support site and add the drive to the device configuration.
- Assign a unique PROFINET device name to the G120 (e.g.
g120-pump-01) and a fixed IP address (e.g.192.168.1.50). - Set the PROFINET send clock to 1 ms (RT Class 1) for low-latency control, or 4 ms when traversing multi-hop 4G networks. G120 supports send clocks of 1, 2, 4, 8, 16 ms on standard telegram 1.
- Slot the standard telegram 1 (STW1/ZSW1 + NSOLL_A/NIST_A) or Siemens telegram 350 into slot 1 / subslot 1.
- Configure the Scalance W778 in client mode at the drive end with a fixed 5 GHz channel (DFS-aware region) and a WPA2-Enterprise (RADIUS) or WPA2-PSK passphrase of at least 16 characters.
- Map STW1 bits per PROFIdrive profile: bit 0 = ON/OFF1, bit 1 = OFF2, bit 2 = OFF3, bit 3 = enable, bit 4 = enable ramp generator, bit 5 = ramp enable, bit 6 = setpoint enable, bit 10 = control by PLC.
MM440 PROFINET over wireless requires the PROFIBUS-to-PROFINET bridge: the MM440 ships only with PROFIBUS DP (6SE6400-1PB00-0AA0 option module). Connect the MM440 PROFIBUS to a Scalance XC206-2SFP or similar PN/DP coupler, then put the wireless path between the controller and the coupler. Set MM440 P0918 to the PROFIBUS address and verify P2051 indices match the controller slot map.
Solution 3: Modbus RTU Wireless Bridging
The MM440 (RS-485 port X27) and the G120 with CU240E-2 (RS-485 on terminals 29/30) support Modbus RTU as a native protocol. Wireless Modbus RTU bridges transmit each Modbus frame over a point-to-point 2.4 GHz or 433 MHz link. The G120 firmware must include Modbus RTU support (CU230P-2 HVAC and CU240E-2 ship with Modbus RTU enabled by default; for CU250S-2 enable bit in p2030 = 2).
Required hardware:
- Pair of wireless RS-485 modems. Examples: Advantech ADAM-4571W, Elpro 105U-N2, Phoenix Contact RAD-ISM-2400-SET, Antaira ARQ-W485-01.
- Termination resistor 120 Ω on each end of the RS-485 segment when the link is short; many wireless modems integrate termination.
- Bias resistors (680 Ω pull-up on D1, pull-down on D0) on at least one node if the master is not actively driving during idle.
Modbus register map essentials for G120:
| Modbus Register | Function | Drive Parameter |
|---|---|---|
| 40001 | Control word (STW) | r2050[0] |
| 40002 | Setpoint frequency (Hz × 100, signed integer) | r2050[1] |
| 40003 | Status word (ZSW) | p2050[0] |
| 40004 | Actual frequency (Hz × 100) | p2050[1] |
| 40005 | Output current (A × 10) | p2050[2] |
| 40006 | DC bus voltage (V) | p2050[3] |
| 40007 | Motor speed (RPM) | p2050[4] |
| 40008 | Fault code | p2050[5] |
Set the Modbus slave address on G120 via p2021 and the baud rate via p2020 (typical 19200 or 38400, 8N1). MM440 registers differ: MM440 uses USS register mapping (control word r0019, setpoint r0020) and parameter access via the 06 06 / 03 03 hex-coded parameter channel documented in the MM440 Parameter List. Configure MM440 P2014 = 0 for Modbus RTU mode, P0700 = 6 (command source) for remote control.
Solution 4: GSM / 4G SMS and MQTT Remote Control
For sites without local Ethernet infrastructure, a GSM modem connected to the drive's serial port or a PLC in front of the drive provides wireless control. The drive receives Modbus RTU commands from the modem, and the modem translates SMS messages or MQTT broker publishes to Modbus frames.
Architecture variants:
- Direct SMS to MM440/G120: a Siemens LOGO! CMR (6BK1700-0HA00-0AA0) or any industrial SMS modem (e.g. Wavecom Fastrack Supreme 20) wired to the drive's RS-485 port. SMS text is parsed by the modem firmware to Modbus write coils 1-4 mapped to STW bits 0-3 (run forward, run reverse, reset, stop). Acknowledgement is sent as an SMS containing the actual speed and fault word read from the drive.
- PLC front-end: an S7-1200 with a CM 1241 RS-485 module communicates Modbus RTU with the drive. The S7-1200 connects to the cloud over LTE/4G using a SCALANCE M874-3 (6GK5874-3AA00-2BA0) router. The S7-1200 program publishes setpoints and alarms to an MQTT broker, and a mobile app or web dashboard publishes back start/stop commands.
- Sinamics sm@rtserver: available on S7-1200 firmware V4.0+ and on G120 webserver-capable CU variants, sm@rtserver allows reading and writing the data records that map the drive parameter interface, exposing them to HTTPS and MQTT clients.
Mobile network latency is 2-15 s end-to-end, so GSM control is appropriate only for non-critical start/stop, setpoint changes that do not require high dynamic response, and alarm notification. The MM440/G120 ramp-up time (P1120 / p1120, default 10 s) absorbs the latency.
Solution 5: I/O Wireless Replicators (Discrete Start/Stop)
When the requirement is limited to one start/stop signal and a fault acknowledgment, the simplest wireless path is a digital I/O replicator. These are 24 V DC transmitters and receivers that mirror 2-4 inputs to 2-4 outputs. Examples: Banner Engineering DXM700 wireless controller, Phoenix Contact RAD-ISM-1700, Wago 750-652/000-001 with Bluetooth module, and Schneider Electric Harmony XB5R wireless push-button receivers.
Application limit: I/O replicators provide one-way or two-way radio transmission, not deterministic bus communication. They are not acceptable for SIL/PL-rated safety stops and provide no closed-loop feedback beyond a heartbeat contact. They are appropriate for nuisance applications (lighting, ventilation, pump start) where the operator can physically observe the motor starting.
Solution 6: S7-1200 + sm@rtserver Web SCADA
The sm@rtserver (S7-1200 firmware V4.0 or higher) exposes a web SCADA dashboard and accepts control commands from authorized HTTP clients. Combined with the S7-1200 controlling a G120 over Modbus TCP or PROFINET, the end-user gains a wireless HMI on a tablet.
Commissioning steps:
- Configure the S7-1200 with a CP 1243-1 (6GK7243-1BX30-0XE0) for secure internet connectivity and a static IP or DDNS hostname.
- Add the G120 to the S7-1200 PROFINET topology and map STW/ZSW + NSOLL/NIST to global data blocks (e.g. DB100).
- Enable the S7-1200 webserver and define a user-defined page with
WWWinstructions that read the drive status from DB100 and write commands from button widgets to a control DB (e.g. DB101). - Forward port 443 on the S7-1200's firewall and use TLS certificates (V4.4+).
- Test from a phone on the same network:
https://[s7-1200-ip]/awp/index.htmlshould show the HMI page with start, stop, and setpoint controls.
Sensorless Vector Control and Wireless Setpoints
When wireless control is added to a drive that requires precise low-speed torque (conveyors, hoists, extruders), confirm that the drive runs in Sensorless Vector Control (SLVC) and not V/f. SLVC is enabled on MM440 with P1300 = 20 and on G120 with p1300 = 20. SLVC operation depends on continuous parameter feedback from the motor model; intermittent setpoint updates over a high-latency link can cause the speed controller to wind up.
Refer to Siemens support entry "MICROMASTER 440 (MM4), SINAMICS G120 (CU2x0x): Applying Sensorless Vector Control (SLVC)" for the parameter set, motor identification procedure, and the SLVC limitations at low speed.
Hardwired Signals That Must Never Go Wireless
Regardless of the wireless architecture, the following signals must remain hardwired to the drive's terminal block. Each one corresponds to a safety-of-machine requirement in IEC 60204-1 and cannot be carried over any bus without violating functional-safety standards.
| Signal | MM440 Terminal | G120 Terminal | Reason |
|---|---|---|---|
| Safe Torque Off (STO) / hardware enable | 14, 15 | 16, 17 (or 15, 16 on PM250) | Hardware stop category 0/1 per IEC 61800-5-2 |
| Hardware fault reset (manual pushbutton) | DIN3 / DIN5 (configurable) | DI 3 / DI 4 (configurable) | Local operator override of bus fault |
| Motor thermistor / PTC | T1, T2 on Power Module | 14, 15 (PTC input, configurable) | Independent of bus, I²t protection |
| Emergency stop circuit | External contactor on line side | External contactor on line side | Safety category 3/4 requires hardware path |
Commissioning and Verification Procedure
- Baseline test on copper: confirm the drive runs correctly over the wired bus before introducing the wireless link. Record fault buffer (r0947) before and after to ensure the wireless layer is the variable changed.
- Signal-strength survey: position the wireless nodes and record RSSI with the manufacturer's diagnostic tool. Target a minimum of -65 dBm for PROFINET; -75 dBm acceptable for Modbus RTU.
- Round-trip latency: ping the wireless device pair for 5 minutes and verify p99 latency stays under 10 ms for PROFINET, 100 ms for Modbus RTU.
- Load test: run the drive through its full speed range (0 → max → 0) and verify no F0085 (PROFINET loss of connection), F0720 (Modbus timeout), or F0790 fault appears. F0085 corresponds to PROFINET telegram failure; F0720 maps to USS/Modbus timeout (P2040 / p2040); F0790 indicates encoder feedback loss on SLVC.
- Fail-safe response: physically remove power to the wireless AP. Verify the drive executes the configured bus-failure reaction: P2040 / p2040 sets the timeout (default 5000 ms) and P2041 / p2041 sets the reaction: 0 = fault trip (F0085), 1 = ramp to last setpoint, 2 = ramp to P2240 / p2240, 3 = immediate stop, 4 = hold setpoint indefinitely.
- Security audit: confirm the WPA2 key, the G120 PROFINET device name, and any S7-1200 access passwords are at least 12 characters and rotated quarterly. Disable the Smart Access SSID broadcast when not in use.
Troubleshooting Matrix
| Symptom | Likely Cause | Diagnostic Step | Remedy |
|---|---|---|---|
| Drive shows F0085 immediately after wireless link activation | PROFINET device name not assigned or duplicate | Check r61000[0..5] on G120 or P0918 on MM440 | Re-assign a unique PROFINET name and restart the Control Unit |
| Drive starts, then faults with F0720 after ~5 s | Modbus RTU master stop polling | Check p2040 timeout, scope RS-485 traffic | Increase p2040 to 10000 ms, verify bias/termination |
| Setpoint steps are jerky, motor audible growl | Setpoint update time too long for SLVC | Check p1130/p1131 ramp smoothing | Increase ramp smoothing, or drop to V/f (p1300 = 0) for low-bandwidth links |
| Smart Access page does not load | DHCP conflict, WPA2 mismatch, or device in "passive" mode | Reset Smart Access, hold pin > 5 s | Re-pair from scratch; ensure drive is in STOP state during commissioning |
| SMS start command is sent, drive does not start | STW bit 10 (control by PLC) is false | Read r0054 bit 10 / MM440 r0002 bit 10 | Set bit 10 in the Modbus control word from the SMS parser |
| Wireless link establishes, then G120 faults with F08501 | PROFINET watchdog timeout due to radio interference | Check r2054 PROFINET diagnostics, change Wi-Fi channel | Move to 5 GHz, disable DFS, add a directional antenna |
Recommendations by Application Class
Permanent process control, latency < 50 ms, multi-drive SCADA: PROFINET over industrial Wi-Fi with Scalance W778 access points and G120 PN Control Units. Avoid 4G routers unless the radio path is reliable and the watchdog is set to 3× the measured RTT.
Modbus RTU-only brownfield with no PLC upgrade: RS-485 wireless bridge (Phoenix RAD-ISM-2400-SET or Elpro 105U). Use 19.2 kbps or 38.4 kbps to maximize link margin; do not exceed 115.2 kbps in the 433/868/915 MHz bands.
Remote unattended site, GSM-only: S7-1200 + CM 1241 + SCALANCE M874-3 router with sm@rtserver web HMI and SMS alarm escalation. Use a local watchdog timer in the S7-1200 to issue STW bit 0 toggle to clear a network drop without manual intervention.
Single discrete start/stop, no data acquisition: Phoenix RAD-ISM I/O replicator or Banner DXM700. Limit to IP54 environments; the radio budget degrades quickly in metal cabinets.
Commissioning laptop/tablet only: G120 Smart Access (6SL3255-0AA00-5HA0). Disable and store the module in a secure location after the drive is in production. The Smart Access App and module are documented in the Sinamics G120 Smart Access announcement article.
FAQ
Does Siemens make a wireless option module for the MM440 or G120?
No. Siemens does not sell a wireless control module that slots into the MM440 or G120 firmware. The only Siemens wireless product in this drive family is the G120 Smart Access module (6SL3255-0AA00-5HA0), which provides wireless commissioning and diagnostics over Wi-Fi but is not intended for continuous process control. Wireless control of the MM440 and G120 is achieved by carrying an existing bus protocol (PROFINET, Modbus RTU, USS) over a third-party wireless link.
Can I use PROFINET wireless to control a G120 with a CU240E-2 PN?
Yes. The CU240E-2 PN (6SL3246-0BA22-1FA0) and CU250S-2 PN Control Units run PROFINET RT Class 1 with a minimum send clock of 1 ms. Use an industrial Wi-Fi pair such as Scalance W778-1 (6GK5778-1AA00-0AA0) configured in client mode at the drive end. Confirm RSSI is at least -65 dBm and that the G120 PROFINET device name and IP are unique before commissioning.
What Modbus registers control start/stop and setpoint on the G120?
The G120 Modbus RTU control word is register 40001 (mapped from r2050[0]) and the setpoint frequency is register 40002 (mapped from r2050[1], scaled as Hz × 100, signed integer). The status word is 40003, the actual frequency is 40004, output current is 40005, DC bus voltage is 40006, motor speed is 40007, and the active fault code is 40008. Set the slave address in p2021 and baud rate in p2020; 8 data bits, no parity, one stop bit (8N1) is the default.
Which safety-relevant signals must remain hardwired on the G120 and MM440?
The Safe Torque Off (STO) hardware enable on MM440 terminals 14/15 and on G120 terminals 16/17, the motor PTC thermistor input (T1/T2 on MM440, configurable on G120), the hardware fault reset pushbutton, and any external emergency stop contactor on the line side must all remain hardwired. Wireless is not acceptable for functional-safety signals in IEC 61800-5-2 systems. Wireless is only acceptable for command, setpoint, and status words in safety category 0 / SIL 0 applications.
How do I clear a PROFINET connection loss fault (F0085) on the G120 after a wireless drop?
First, verify the PROFINET device name in r61000[0..5] is unique and matches the TIA Portal configuration. Check the Wi-Fi RSSI and ensure the watchdog setting (p2040 in PROFINET mode) is at least 3× the measured round-trip latency. If the link is intermittent, increase the PROFINET update time from 1 ms to 4 ms, or change p2041 (bus-failure reaction) from 0 (fault trip) to 1 (ramp to last setpoint) so that a single drop does not fault the drive. Clear the fault by writing STW bit 7 = 1, or by cycling the enable input on a hardwired DI configured as fault acknowledge.