SINAMICS G120 CU240E USS Protocol Communication with SIMATIC S7-300
The SINAMICS G120 modular drive family supports several control unit (CU) variants. The original CU240E (Siemens part number 6SL3244-0BA10-0BA0) was delivered with a single RS485 interface intended primarily for USS protocol point-to-point or multi-drop communication. Because this Control Unit does not contain a PROFIBUS or PROFINET onboard interface, integrators pairing it with a SIMATIC S7-300 CPU must either add a Siemens CP340 RS485 communication processor and implement the USS master on the PLC side, or replace the CU with a PROFIBUS-capable variant such as the CU240S DP or the modern CU240E-2 DP/PN.
This reference covers the USS path in detail: bus topology, parameter set on the drive (P2010 through P2014 and the related ramp/PZD parameters), CP340 hardware setup on the S7-300, the Siemens USS library / FB blocks, terminal assignments on the CU240E, and a step-by-step commissioning checklist. It also provides a side-by-side comparison of every CU option that can substitute for the CU240E when PROFIBUS, PROFINET, or Modbus is required.
1. CU240E Communication Interface Inventory
The CU240E with article number 6SL3244-0BA10-0BA0 is the first-generation Control Unit for the SINAMICS G120 modular drive. Its communication capabilities are intentionally limited compared with later -2 variants:
| Interface | Physical | Protocol Support | Use with S7-300 |
|---|---|---|---|
| X11 RS485 (USS) | 2-wire / 4-wire RS485, terminal block | Siemens USS (master/slave, V1.x firmware) | Yes, via CP340/CP341 RS485 module |
| No PROFIBUS DP | — | — | Not available on this CU |
| No PROFINET | — | — | Not available on this CU |
| No Modbus RTU | — | — | Not available on this CU |
The label printed on the side of the CU240E confirms the absence of any fieldbus connector other than the four-pole terminal block on the front. The connector is internally wired to the drive's UART and can be reconfigured between 2-wire and 4-wire RS485 modes through parameter P2010 and the related switch settings on the drive.
Because the on-board RS485 supports a USS master/slave stack, the CU240E can be operated as a USS slave behind a SIMATIC S7-300 PLC that has been equipped with an RS485 USS master module. The legacy CP340 (article number 6ES7340-1CH02-0AE0) is the most common choice, although the newer CP341 (article number 6ES7341-1CH02-0AE0) is recommended for new projects because of its larger buffer and faster cycle times.
2. USS Protocol Engineering Overview
The Universal Serial Interface protocol (USS) is a Siemens-defined, master/slave serial bus used since the MASTERDRIVES / MICROMASTER 4 era. It operates over RS485 with the following characteristics:
- Topology: 2-wire or 4-wire RS485 bus, terminated at both ends (typically 120 Ω).
- Maximum nodes: 32 slaves, of which up to 31 may be SINAMICS G120 inverters. The USS master occupies one address.
- Cable length: Up to 1,000 m at 9.6 kbit/s; 200 m at 187.5 kbit/s; shorter lengths as baud increases to 57.6 kbit/s.
- Frame format: 11 bits (1 start, 8 data, 1 even parity, 1 stop). Half-duplex.
- Default baud on G120: 9,600 bit/s; settable from 1,200 to 57,600 bit/s.
- Cyclical PZD length: 1 to 16 process data words in each direction.
-
Addressing: Each slave is given a unique node number (1 to 31 on the drive, set in
P2011).
USS frames use a fixed 14-byte header followed by the user data. The master polls each slave cyclically; slaves only respond when addressed. The broadcast address 0 exists but does not return data, so it is only useful for synchronization commands.
3. Required Hardware for SINAMICS G120 + S7-300 USS
3.1 SINAMICS G120 components
-
Control Unit:
6SL3244-0BA10-0BA0(CU240E, RS485 USS) - Power Module: Any PM230, PM240, PM250, or PM260 from the SINAMICS G120 family, matched to the motor rating
-
Operator Panel: BOP-2 (
6SL3255-0AA00-4CA1) or IOP (6SL3255-0AA00-4HA1) for local parameterization
3.2 SIMATIC S7-300 components
-
CPU: 314C-2 DP (
6ES7314-6CH04-0AB0) or any S7-300 CPU that supports the USS library -
Communication processor: CP340 RS485 (
6ES7340-1CH02-0AE0) with the loadable driver for USS, or CP341 RS485 (6ES7341-1CH02-0AE0) with the USS driver license -
USS master software:
S7_USS/SIMATIC USS Protocollibrary (FB block shipped on the S7-300 toolbox CD or downloadable from Siemens SIOS)
3.3 Cables and accessories
- PROFIBUS / RS485 cable, shielded, 24 AWG (e.g.,
6XV1830-0EH10) — also used for USS even though it carries the PROFIBUS purple jacket - RS485 bus connector, 120 Ω termination, with PG socket (
6ES7972-0BA52-0XA0) or screw-terminal variant - Two-pole termination resistors (built into the bus connector or wired externally on the last drive)
4. SINAMICS G120 CU240E Wiring for USS
The CU240E exposes a four-pole pluggable terminal block on the front labelled with the signal assignments below. The drive automatically detects the topology from P2010 and the jumper on the connector.
| Terminal | Signal | Function (4-wire RS485) | Function (2-wire RS485) |
|---|---|---|---|
| 1 | R+ | Receive + (input) | Not used / tied |
| 2 | R− | Receive − (input) | Not used / tied |
| 3 | P+ | Transmit + (output) | Data + (bidirectional) |
| 4 | P− | Transmit − (output) | Data − (bidirectional) |
For a 2-wire USS link between S7-300 (CP340/CP341) and a single CU240E, wire terminal 3 to CP340 RxD/TxD-P and terminal 4 to RxD/TxD-N. Enable termination on the CP340 module by inserting the jumper that ships with the CP and switch on P2010 = 2 in the drive. When chaining multiple drives, place the 120 Ω termination only at the physical ends of the bus — typically inside the bus connector at the first and last device.
F0072 ("no telegram from USS setpoint channel").
5. SINAMICS G120 Parameter Set for USS
USS on the CU240E is configured by parameters P2010 through P2014, plus the command source / setpoint source selectors. The following table lists every parameter that must be set before the drive will respond to the S7-300.
| Parameter | Designation | Recommended Value | Notes |
|---|---|---|---|
| P0015 | Macro drive setting | 7 (USS fieldbus) or 8 (USS default) | Selects USS source as default; speeds up commissioning |
| P0700[0] | Command source selection | 5 (USS on RS485) | Control word received from USS master |
| P1000[0] | Setpoint source selection | 5 (USS on RS485) | Main setpoint from PZD word 2 |
| P2010[0] | USS baud rate | 9 (9,600 bit/s) or 12 (57,600) | Must match CP340 baud exactly |
| P2011[0] | USS node address | 1 to 31, unique | Slave address; address 0 reserved for broadcast |
| P2012[0] | USS PZD length (from master) | 2 (1 control word + 1 setpoint) | Number of 16-bit words received |
| P2013[0] | USS PZD length (to master) | 2 (1 status word + 1 actual value) | Number of 16-bit words returned |
| P2014[0] | USS telegram off time | 2000 ms | Triggers F0072 if exceeded |
| P2023[0] | RS485 parity / data bits | 0 (even parity) or 2 (no parity) | Must match CP340 setting |
| P0971 | Save parameters to RAM/ROM | 1 | Persist changes; cycle power or run P0971 = 1 |
After the values above are entered, save with P0971 = 1 or run a power cycle. The drive will acknowledge with a one-second blink on the RDY LED when ready.
5.1 Macro P0015 = 7 explained
The macro P0015 = 7 pre-populates P0700, P1000, and the relevant digital input functions in one step. Selecting macro 7 before entering the manual values above prevents conflicts between BOP local control and the USS channel. To use the macro through BOP-2, navigate to P0015, enter 7, confirm with OK, then wait for the drive to restart automatically.
5.2 Telegram layout used in PLC logic
With P2012 = 2 and P2013 = 2, the S7-300 must send a 2-word PZD payload every cycle:
- PZD word 1 from master: Control word 1 (bits per SINAMICS drive profile) — bits 0 (ON/OFF1), 1 (OFF2), 2 (OFF3), 3 (enable pulse), 4–6 (setpoint conditioning), 7 (fault acknowledge), 10 (control by PLC), 11/12 (reverse/speed direction)
- PZD word 2 from master: Main setpoint, normalized to 0x4000 = 100 % motor rated frequency
- PZD word 1 to master: Status word 1 — bits 0 (ready to switch on), 1 (ready to operate), 2 (operation enabled), 3 (fault present), 7 (alarm), 8 (speed set/actual deviation), 10 (f or n reached), 11 (current/torque limit)
- PZD word 2 to master: Actual frequency, normalized identically to the setpoint
6. S7-300 PLC Configuration with CP340
6.1 Hardware Configuration in STEP 7
- Open the S7 project in STEP 7 V5.5 or TIA Portal.
- In the hardware catalog, place a CP340 module adjacent to the CPU (slot 4 typical). Confirm that the article number matches
6ES7340-1CH02-0AE0and that the firmware selected isV1.x. - Open the CP340 properties, select protocol USS, and assign a byte address (typically PIB/PIB 256–259 or 288–291).
- Set the baud rate, parity, and number of stop bits to match
P2010andP2023on the drive. 9,600 bit/s, even parity, 1 stop bit is the safe default. - Compile and download the hardware configuration.
6.2 USS library blocks (STEP 7)
The legacy USS Protocol package contains the following FBs that must be instantiated in the user program:
| Block | Function | Typical Call |
|---|---|---|
| FB 7 | USS protocol driver (master, polling) | OB 1 / OB 35 |
| FC 1 / FC 2 / FC 21 | Read/write parameter jobs (PKW) | Background OB |
| DB | Per-drive instance DB (e.g., DB 100 for node 1) | Memory area for PZD/PKW |
| UDT | Data structure for control / status word | Imported with library |
A typical cyclic call from OB 35 (100 ms interrupt) reads as follows:
CALL "USS_DRIVER" , DB100 MODE := 1 SLOT := 0 LADDR := 256 // base address of CP340 DB_NO := 100 // instance DB for drive 1 USERDB := DB101 // user data with control / setpoint JOB_DB := DB102 // PKW parameter read/write TIME_OUT:= 2500 // telegram monitoring NOP := FALSE
Within DB101, build the control word according to the SINAMICS profile. The setpoint word is mapped at offset 2. The status and actual value returned by the drive appear in the same instance DB on the receive side, allowing the PLC to detect F0072 and other faults through bit 3 of the status word.
6.3 STEP 7 Safety Interlock
Before turning on the drive (control word bit 0), the PLC must confirm that the safety chain has been closed (STO terminals on the drive, hardware contactor upstream, etc.) and that no drive fault is active. A typical interlock sequence in ladder:
A "Hardware_OK" // external E-stop closed A "Drive_Not_Faulted" // status word bit 3 = 0 A "USS_Comm_OK" // heartbeat from FB 7 = "Drive_Enable_Command" // bits 0+3 of control word
7. Commissioning and Verification Procedure
- Pre-power checks. Verify the shield of the RS485 cable is bonded to PE at the cabinet entry, that the bus has 120 Ω termination at both ends, and that the wiring to the CU240E terminal block matches the table in section 4.
-
Drive parameters. Set
P0015 = 7on the CU240E via BOP-2 and wait for the auto-restart. Then enterP2010 = 9,P2011 = 1,P2012 = 2,P2013 = 2,P2014 = 2000. Save withP0971 = 1. - PLC parameters. Configure CP340 for 9,600 bit/s, even parity, 1 stop bit. Insert FB 7 into OB 35 with a 100 ms cycle time. Build the control word sequence ON/OFF1 / Enable pulse / Enable setpoint.
-
First online test. From STEP 7 in online mode, monitor DB100. The
USS_DRIVERblock will toggleDB100.DBX 0.0each polling cycle; if it stays FALSE, the CP340 is not receiving responses from the drive. -
Setpoint step test. Write
0x4000to the setpoint word and watch the actual frequency in the receive PZD. With the motor uncoupled, verify the actual value follows within 1 %. -
Fault simulation. Block the USS cable to verify that the CP340 raises
USS_Comm_OK= FALSE and thatF0072appears in the drive fault buffer after the 2 s telegram off time expires. -
Save and document. Once commissioning is complete, archive the drive parameter set using STARTER or the BOP-2 (menu
PAR_SAV) and the STEP 7 project to the project's documentation system.
8. Alternative: PROFIBUS Migration Path
If the project timeline permits, replacing the CU240E with a more capable Control Unit eliminates the CP340 module and gives full PROFIBUS DP or PROFINET access from the 314C-2 DP's onboard interface. The following table compares the available options.
| Article Number | Designation | Fieldbus | USS RS485 | Use Case |
|---|---|---|---|---|
| 6SL3244-0BA10-0BA0 | CU240E | None | Yes | Original target — USS only |
| 6SL3244-0BA20-1BA0 | CU240S DP | PROFIBUS DP | Yes (parallel) | PROFIBUS to 314C-2 DP onboard |
| 6SL3244-0BA20-1FA0 | CU240S DP-F | PROFIBUS DP with PROFIsafe | Yes | Safety-integrated drives |
| 6SL3244-0BE12-0FA0 | CU240E-2 PN | PROFINET | Yes | Modern replacement with Ethernet |
| 6SL3244-0BE22-1BA0 | CU240E-2 DP | PROFIBUS DP | Yes | Direct drop-in for PROFIBUS retrofits |
For users who must keep the CU240E but still want PROFIBUS integration, a Siemens DP/AS-i Link or a third-party gateway can convert USS to PROFIBUS DP. This is rarely the right engineering choice because the CP340 + USS solution is already a clean master/slave architecture, but it remains a viable fallback when the PLC does not have a free serial port and a PROFIBUS slot is open.
When using CU240E-2 DP, configuration is performed in TIA Portal or STEP 7 with a GSD file shipped with the drive. The PROFIBUS node address is set on the drive using P0918 (CU240E-2) rather than P2011 (USS). The CU240E-2 variants also support Modbus RTU and (on PN) PROFIenergy, so the same hardware can be repurposed for any modern fieldbus without a control unit swap.
9. Common USS Faults and Diagnostic Map
| Fault Code | Meaning | Likely Cause | Corrective Action |
|---|---|---|---|
| F0070 | CB / setpoint fault | PLC writing a value out of range to PKW | Check parameter access in FB 7; reset with P0952 = 4 |
| F0071 | USS setpoint end of telegram | P2012 = 0 | Set P2012 = 2 |
| F0072 | USS telegram off (timeout) | Cable break, wrong baud, or P2014 too short | Verify wiring; raise P2014 to 2000 ms; check CP340 baud |
| F0073 | USS setpoint end of telegram 1 | P2012 < PLC send length | Match P2012 to the PZD length in DB100 |
| F0074 | USS telegram off 1 | Master stopped polling | Investigate CP340 error LEDs; verify PLC is in RUN |
| A0700 | Warning: CB telegram timeout | Single missed telegram | Check for EMC interference; reroute shielded cable |
| A0701 | Warning: CB fault | Non-fatal bus error | Check parity and ground references |
| A0702 | Warning: CB setpoint end | Configuration mismatch | Match P2012/P2013 with PLC PZD length |
To clear a fault, acknowledge with control word bit 7 (rising edge) from the PLC or use P2103 = 1 on the BOP. Persistent faults after a power cycle usually indicate a wiring problem rather than a parameter mistake.
10. CP340 Diagnostics
The CP340 front panel provides five LEDs that surface the runtime state. Their meanings are:
- SF (red): Group error. Lit when the CP340 detects a hardware fault or has not been parameterized.
- BATF (red): Battery low. The CP340 has no battery; this LED indicates an internal backup fault and is rarely used.
- TxD (green): Flashes when the CP340 transmits a USS frame to the drive.
- RxD (green): Flashes when a response from the drive is received.
- 24 V (green): Power supply OK.
If TxD never flashes, the CP340 is not being polled by FB 7 — check the input/output address in the hardware configuration. If TxD flashes but RxD does not, the cable, parity, or address assignment on the drive is wrong.
11. Performance and Cycle-Time Notes
The USS cycle time seen at the drive depends on baud rate, PZD length, and the number of nodes. With the default 9,600 bit/s and 2 PZD words per direction, the per-drive round-trip is approximately 25 ms. The CP340 can buffer up to 32 nodes; for a single drive the polling cycle can be set to 50 ms. For multi-drive installations, calculate as:
t_cycle ≥ (PZD_words_in + PZD_words_out) × 11 × (1 / baud_rate) × n_nodes × 1.5
For example, 10 drives at 2 PZD words each way, 19,200 bit/s:
t_cycle ≥ 2 × 11 × (1 / 19200) × 10 × 1.5 ≈ 17 ms
This is comfortably below the typical 100 ms PLC scan time. If the drive requires faster response (e.g., positioning with fast ramp), move to PROFIBUS DP at 1.5 Mbit/s where the same 10-drive bus is polled in under 10 ms.
12. Migrating from STEP 7 to TIA Portal
The USS library for STEP 7 V5.5 still works in TIA Portal via the legacy block import or by re-implementing the same logic with a CP341 and the TIA USS block set. If a project is migrated, the legacy CP340 is replaced by CP341 (article 6ES7341-1CH02-0AE0) and the USS protocol license is activated through the CP341's parameter dialog. The SINAMICS G120 parameters do not need to change because the protocol is identical.
For greenfield TIA Portal projects, an even simpler approach is to swap the CU240E for a CU240E-2 PN, then use the ready-made SINAMICS G120 PROFINET GSD file to drop the drive into the TIA project and integrate it directly into the S7-300 / S7-1500 PROFINET network. Theuss migration to PROFINET removes the CP340 entirely.
13. EMC and Cable Routing Best Practices
- Keep USS cable runs at least 200 mm away from VFD power cables. Cross them at right angles when crossings are unavoidable.
- Bond the shield to PE at the cabinet entry using EMC glands. Avoid pigtails longer than 50 mm.
- Ground the S7-300 rack, the drive cabinet, and the USS bus reference to the same equipotential bus bar.
- Use a screened cable with at least 0.5 mm² cross-section for the data pairs. The PROFIBUS purple cable (
6XV1830-0EH10) is well suited. - Do not install terminators on intermediate nodes — only the first and last physical device.
14. Frequently Asked Questions
Can the CU240E (6SL3244-0BA10-0BA0) communicate with a SIMATIC S7-300 over USS protocol?
Yes. The CU240E has an on-board RS485 port that supports USS master/slave. Connect a Siemens CP340 (6ES7340-1CH02-0AE0) or CP341 (6ES7341-1CH02-0AE0) to the S7-300, wire the 2-wire RS485 link to terminals 3 and 4 of the CU240E, configure P2010 = 9 (9,600 bit/s) and P2011 = 1, then implement the Siemens USS master library on the PLC.
Does the CU240E support PROFIBUS?
No. The original CU240E does not have a PROFIBUS DP interface. For PROFIBUS control, replace the Control Unit with a CU240S DP (6SL3244-0BA20-1BA0), CU240S DP-F (6SL3244-0BA20-1FA0), or the modern CU240E-2 DP (6SL3244-0BE22-1BA0). The Power Module can remain unchanged.
What is the recommended baud rate for USS on CU240E?
9,600 bit/s (P2010 = 9) is the standard default and is supported by every CP340/CP341 firmware version. 19,200 bit/s or 57,600 bit/s can be used for faster bus cycles but require shorter cable lengths (under 200 m for 57,600) and better EMC shielding.
Which FB blocks are required to run USS from an S7-300?
The Siemens USS protocol library includes FB 7 (master driver), FC 21 (PKW read/write), and an instance DB per drive. The library is shipped with STEP 7 V5.5 and is also available on the SIOS portal. In TIA Portal, use the same logic with the TIA USS block set on a CP341.
What happens if the USS cable is disconnected from the CU240E?
The drive waits for the telegram off time defined by P2014 (default 2 s). If no valid frame is received within that window, fault F0072 is raised, the drive coasts to stop, and bit 3 of the status word is set. The PLC can detect this through the status word or by monitoring the FB 7 "communication OK" flag.
Can the CP340 RS485 interface support multiple SINAMICS G120 drives?
Yes. The CP340 can address up to 32 USS slaves. Each CU240E must be assigned a unique node number through P2011 (1–31). Use one instance DB per drive and configure the FB 7 driver accordingly.
What firmware version on the CU240E supports USS without restriction?
Firmware V1.0 and later on the original CU240E supports USS master/slave. V1.x remains in production for legacy installations. For new projects, migrate to the CU240E-2 family (firmware V4.x and later), which adds Modbus RTU, PROFINET/PROFIBUS, and the safety-licensed variants.