SINAMICS G120 CU240E USS Protocol with S7-300 Wiring, CP340

David Krause17 min read
SiemensTechnical ReferenceVFD / Drives
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

SINAMICS G120 CU240E USS Protocol Communication with SIMATIC S7-300

The SINAMICS G120 modular drive family supports several control unit (CU) variants. The original CU240E (Siemens part number 6SL3244-0BA10-0BA0) was delivered with a single RS485 interface intended primarily for USS protocol point-to-point or multi-drop communication. Because this Control Unit does not contain a PROFIBUS or PROFINET onboard interface, integrators pairing it with a SIMATIC S7-300 CPU must either add a Siemens CP340 RS485 communication processor and implement the USS master on the PLC side, or replace the CU with a PROFIBUS-capable variant such as the CU240S DP or the modern CU240E-2 DP/PN.

This reference covers the USS path in detail: bus topology, parameter set on the drive (P2010 through P2014 and the related ramp/PZD parameters), CP340 hardware setup on the S7-300, the Siemens USS library / FB blocks, terminal assignments on the CU240E, and a step-by-step commissioning checklist. It also provides a side-by-side comparison of every CU option that can substitute for the CU240E when PROFIBUS, PROFINET, or Modbus is required.

Safety notice: SINAMICS G120 drives must be wired and parameterized in accordance with the CU240B-2 / CU240E-2 Operating Instructions shipped with the unit and the SINAMICS G120 Function Manual. All work on the drive or PLC must be performed by qualified personnel observing ESD and lock-out/tag-out procedures. Before any configuration download, verify that the motor is mechanically disconnected and that STO (Safe Torque Off) is functional.

1. CU240E Communication Interface Inventory

The CU240E with article number 6SL3244-0BA10-0BA0 is the first-generation Control Unit for the SINAMICS G120 modular drive. Its communication capabilities are intentionally limited compared with later -2 variants:

Interface Physical Protocol Support Use with S7-300
X11 RS485 (USS) 2-wire / 4-wire RS485, terminal block Siemens USS (master/slave, V1.x firmware) Yes, via CP340/CP341 RS485 module
No PROFIBUS DP — — Not available on this CU
No PROFINET — — Not available on this CU
No Modbus RTU — — Not available on this CU

The label printed on the side of the CU240E confirms the absence of any fieldbus connector other than the four-pole terminal block on the front. The connector is internally wired to the drive's UART and can be reconfigured between 2-wire and 4-wire RS485 modes through parameter P2010 and the related switch settings on the drive.

Because the on-board RS485 supports a USS master/slave stack, the CU240E can be operated as a USS slave behind a SIMATIC S7-300 PLC that has been equipped with an RS485 USS master module. The legacy CP340 (article number 6ES7340-1CH02-0AE0) is the most common choice, although the newer CP341 (article number 6ES7341-1CH02-0AE0) is recommended for new projects because of its larger buffer and faster cycle times.

2. USS Protocol Engineering Overview

The Universal Serial Interface protocol (USS) is a Siemens-defined, master/slave serial bus used since the MASTERDRIVES / MICROMASTER 4 era. It operates over RS485 with the following characteristics:

  • Topology: 2-wire or 4-wire RS485 bus, terminated at both ends (typically 120 Ω).
  • Maximum nodes: 32 slaves, of which up to 31 may be SINAMICS G120 inverters. The USS master occupies one address.
  • Cable length: Up to 1,000 m at 9.6 kbit/s; 200 m at 187.5 kbit/s; shorter lengths as baud increases to 57.6 kbit/s.
  • Frame format: 11 bits (1 start, 8 data, 1 even parity, 1 stop). Half-duplex.
  • Default baud on G120: 9,600 bit/s; settable from 1,200 to 57,600 bit/s.
  • Cyclical PZD length: 1 to 16 process data words in each direction.
  • Addressing: Each slave is given a unique node number (1 to 31 on the drive, set in P2011).

USS frames use a fixed 14-byte header followed by the user data. The master polls each slave cyclically; slaves only respond when addressed. The broadcast address 0 exists but does not return data, so it is only useful for synchronization commands.

The maximum number of slaves per USS master is set by the cycle time budget. At 9,600 bit/s and 4 PZD words per direction, a single CU240E can be polled in under 25 ms, allowing about 20 slaves per second from the CP340/CP341. The PLC's cycle time should be shorter than the polling interval to avoid queue overflow.

3. Required Hardware for SINAMICS G120 + S7-300 USS

3.1 SINAMICS G120 components

  • Control Unit: 6SL3244-0BA10-0BA0 (CU240E, RS485 USS)
  • Power Module: Any PM230, PM240, PM250, or PM260 from the SINAMICS G120 family, matched to the motor rating
  • Operator Panel: BOP-2 (6SL3255-0AA00-4CA1) or IOP (6SL3255-0AA00-4HA1) for local parameterization

3.2 SIMATIC S7-300 components

  • CPU: 314C-2 DP (6ES7314-6CH04-0AB0) or any S7-300 CPU that supports the USS library
  • Communication processor: CP340 RS485 (6ES7340-1CH02-0AE0) with the loadable driver for USS, or CP341 RS485 (6ES7341-1CH02-0AE0) with the USS driver license
  • USS master software: S7_USS / SIMATIC USS Protocol library (FB block shipped on the S7-300 toolbox CD or downloadable from Siemens SIOS)

3.3 Cables and accessories

  • PROFIBUS / RS485 cable, shielded, 24 AWG (e.g., 6XV1830-0EH10) — also used for USS even though it carries the PROFIBUS purple jacket
  • RS485 bus connector, 120 Ω termination, with PG socket (6ES7972-0BA52-0XA0) or screw-terminal variant
  • Two-pole termination resistors (built into the bus connector or wired externally on the last drive)

4. SINAMICS G120 CU240E Wiring for USS

The CU240E exposes a four-pole pluggable terminal block on the front labelled with the signal assignments below. The drive automatically detects the topology from P2010 and the jumper on the connector.

Terminal Signal Function (4-wire RS485) Function (2-wire RS485)
1 R+ Receive + (input) Not used / tied
2 R− Receive − (input) Not used / tied
3 P+ Transmit + (output) Data + (bidirectional)
4 P− Transmit − (output) Data − (bidirectional)

For a 2-wire USS link between S7-300 (CP340/CP341) and a single CU240E, wire terminal 3 to CP340 RxD/TxD-P and terminal 4 to RxD/TxD-N. Enable termination on the CP340 module by inserting the jumper that ships with the CP and switch on P2010 = 2 in the drive. When chaining multiple drives, place the 120 Ω termination only at the physical ends of the bus — typically inside the bus connector at the first and last device.

The CU240E has no internal bus termination. Always fit an external 120 Ω resistor between the two data lines at the last drive. Failure to terminate will cause intermittent USS fault F0072 ("no telegram from USS setpoint channel").

5. SINAMICS G120 Parameter Set for USS

USS on the CU240E is configured by parameters P2010 through P2014, plus the command source / setpoint source selectors. The following table lists every parameter that must be set before the drive will respond to the S7-300.

Parameter Designation Recommended Value Notes
P0015 Macro drive setting 7 (USS fieldbus) or 8 (USS default) Selects USS source as default; speeds up commissioning
P0700[0] Command source selection 5 (USS on RS485) Control word received from USS master
P1000[0] Setpoint source selection 5 (USS on RS485) Main setpoint from PZD word 2
P2010[0] USS baud rate 9 (9,600 bit/s) or 12 (57,600) Must match CP340 baud exactly
P2011[0] USS node address 1 to 31, unique Slave address; address 0 reserved for broadcast
P2012[0] USS PZD length (from master) 2 (1 control word + 1 setpoint) Number of 16-bit words received
P2013[0] USS PZD length (to master) 2 (1 status word + 1 actual value) Number of 16-bit words returned
P2014[0] USS telegram off time 2000 ms Triggers F0072 if exceeded
P2023[0] RS485 parity / data bits 0 (even parity) or 2 (no parity) Must match CP340 setting
P0971 Save parameters to RAM/ROM 1 Persist changes; cycle power or run P0971 = 1

After the values above are entered, save with P0971 = 1 or run a power cycle. The drive will acknowledge with a one-second blink on the RDY LED when ready.

5.1 Macro P0015 = 7 explained

The macro P0015 = 7 pre-populates P0700, P1000, and the relevant digital input functions in one step. Selecting macro 7 before entering the manual values above prevents conflicts between BOP local control and the USS channel. To use the macro through BOP-2, navigate to P0015, enter 7, confirm with OK, then wait for the drive to restart automatically.

5.2 Telegram layout used in PLC logic

With P2012 = 2 and P2013 = 2, the S7-300 must send a 2-word PZD payload every cycle:

  • PZD word 1 from master: Control word 1 (bits per SINAMICS drive profile) — bits 0 (ON/OFF1), 1 (OFF2), 2 (OFF3), 3 (enable pulse), 4–6 (setpoint conditioning), 7 (fault acknowledge), 10 (control by PLC), 11/12 (reverse/speed direction)
  • PZD word 2 from master: Main setpoint, normalized to 0x4000 = 100 % motor rated frequency
  • PZD word 1 to master: Status word 1 — bits 0 (ready to switch on), 1 (ready to operate), 2 (operation enabled), 3 (fault present), 7 (alarm), 8 (speed set/actual deviation), 10 (f or n reached), 11 (current/torque limit)
  • PZD word 2 to master: Actual frequency, normalized identically to the setpoint

6. S7-300 PLC Configuration with CP340

6.1 Hardware Configuration in STEP 7

  1. Open the S7 project in STEP 7 V5.5 or TIA Portal.
  2. In the hardware catalog, place a CP340 module adjacent to the CPU (slot 4 typical). Confirm that the article number matches 6ES7340-1CH02-0AE0 and that the firmware selected is V1.x.
  3. Open the CP340 properties, select protocol USS, and assign a byte address (typically PIB/PIB 256–259 or 288–291).
  4. Set the baud rate, parity, and number of stop bits to match P2010 and P2023 on the drive. 9,600 bit/s, even parity, 1 stop bit is the safe default.
  5. Compile and download the hardware configuration.

6.2 USS library blocks (STEP 7)

The legacy USS Protocol package contains the following FBs that must be instantiated in the user program:

Block Function Typical Call
FB 7 USS protocol driver (master, polling) OB 1 / OB 35
FC 1 / FC 2 / FC 21 Read/write parameter jobs (PKW) Background OB
DB Per-drive instance DB (e.g., DB 100 for node 1) Memory area for PZD/PKW
UDT Data structure for control / status word Imported with library

A typical cyclic call from OB 35 (100 ms interrupt) reads as follows:

CALL "USS_DRIVER" , DB100
MODE := 1
SLOT := 0
LADDR := 256 // base address of CP340
DB_NO := 100 // instance DB for drive 1
USERDB := DB101 // user data with control / setpoint
JOB_DB := DB102 // PKW parameter read/write
TIME_OUT:= 2500 // telegram monitoring
NOP := FALSE

Within DB101, build the control word according to the SINAMICS profile. The setpoint word is mapped at offset 2. The status and actual value returned by the drive appear in the same instance DB on the receive side, allowing the PLC to detect F0072 and other faults through bit 3 of the status word.

6.3 STEP 7 Safety Interlock

Before turning on the drive (control word bit 0), the PLC must confirm that the safety chain has been closed (STO terminals on the drive, hardware contactor upstream, etc.) and that no drive fault is active. A typical interlock sequence in ladder:

A "Hardware_OK" // external E-stop closed
A "Drive_Not_Faulted" // status word bit 3 = 0
A "USS_Comm_OK" // heartbeat from FB 7
= "Drive_Enable_Command" // bits 0+3 of control word

7. Commissioning and Verification Procedure

  1. Pre-power checks. Verify the shield of the RS485 cable is bonded to PE at the cabinet entry, that the bus has 120 Ω termination at both ends, and that the wiring to the CU240E terminal block matches the table in section 4.
  2. Drive parameters. Set P0015 = 7 on the CU240E via BOP-2 and wait for the auto-restart. Then enter P2010 = 9, P2011 = 1, P2012 = 2, P2013 = 2, P2014 = 2000. Save with P0971 = 1.
  3. PLC parameters. Configure CP340 for 9,600 bit/s, even parity, 1 stop bit. Insert FB 7 into OB 35 with a 100 ms cycle time. Build the control word sequence ON/OFF1 / Enable pulse / Enable setpoint.
  4. First online test. From STEP 7 in online mode, monitor DB100. The USS_DRIVER block will toggle DB100.DBX 0.0 each polling cycle; if it stays FALSE, the CP340 is not receiving responses from the drive.
  5. Setpoint step test. Write 0x4000 to the setpoint word and watch the actual frequency in the receive PZD. With the motor uncoupled, verify the actual value follows within 1 %.
  6. Fault simulation. Block the USS cable to verify that the CP340 raises USS_Comm_OK = FALSE and that F0072 appears in the drive fault buffer after the 2 s telegram off time expires.
  7. Save and document. Once commissioning is complete, archive the drive parameter set using STARTER or the BOP-2 (menu PAR_SAV) and the STEP 7 project to the project's documentation system.

8. Alternative: PROFIBUS Migration Path

If the project timeline permits, replacing the CU240E with a more capable Control Unit eliminates the CP340 module and gives full PROFIBUS DP or PROFINET access from the 314C-2 DP's onboard interface. The following table compares the available options.

Article Number Designation Fieldbus USS RS485 Use Case
6SL3244-0BA10-0BA0 CU240E None Yes Original target — USS only
6SL3244-0BA20-1BA0 CU240S DP PROFIBUS DP Yes (parallel) PROFIBUS to 314C-2 DP onboard
6SL3244-0BA20-1FA0 CU240S DP-F PROFIBUS DP with PROFIsafe Yes Safety-integrated drives
6SL3244-0BE12-0FA0 CU240E-2 PN PROFINET Yes Modern replacement with Ethernet
6SL3244-0BE22-1BA0 CU240E-2 DP PROFIBUS DP Yes Direct drop-in for PROFIBUS retrofits

For users who must keep the CU240E but still want PROFIBUS integration, a Siemens DP/AS-i Link or a third-party gateway can convert USS to PROFIBUS DP. This is rarely the right engineering choice because the CP340 + USS solution is already a clean master/slave architecture, but it remains a viable fallback when the PLC does not have a free serial port and a PROFIBUS slot is open.

When using CU240E-2 DP, configuration is performed in TIA Portal or STEP 7 with a GSD file shipped with the drive. The PROFIBUS node address is set on the drive using P0918 (CU240E-2) rather than P2011 (USS). The CU240E-2 variants also support Modbus RTU and (on PN) PROFIenergy, so the same hardware can be repurposed for any modern fieldbus without a control unit swap.

9. Common USS Faults and Diagnostic Map

Fault Code Meaning Likely Cause Corrective Action
F0070 CB / setpoint fault PLC writing a value out of range to PKW Check parameter access in FB 7; reset with P0952 = 4
F0071 USS setpoint end of telegram P2012 = 0 Set P2012 = 2
F0072 USS telegram off (timeout) Cable break, wrong baud, or P2014 too short Verify wiring; raise P2014 to 2000 ms; check CP340 baud
F0073 USS setpoint end of telegram 1 P2012 < PLC send length Match P2012 to the PZD length in DB100
F0074 USS telegram off 1 Master stopped polling Investigate CP340 error LEDs; verify PLC is in RUN
A0700 Warning: CB telegram timeout Single missed telegram Check for EMC interference; reroute shielded cable
A0701 Warning: CB fault Non-fatal bus error Check parity and ground references
A0702 Warning: CB setpoint end Configuration mismatch Match P2012/P2013 with PLC PZD length

To clear a fault, acknowledge with control word bit 7 (rising edge) from the PLC or use P2103 = 1 on the BOP. Persistent faults after a power cycle usually indicate a wiring problem rather than a parameter mistake.

10. CP340 Diagnostics

The CP340 front panel provides five LEDs that surface the runtime state. Their meanings are:

  • SF (red): Group error. Lit when the CP340 detects a hardware fault or has not been parameterized.
  • BATF (red): Battery low. The CP340 has no battery; this LED indicates an internal backup fault and is rarely used.
  • TxD (green): Flashes when the CP340 transmits a USS frame to the drive.
  • RxD (green): Flashes when a response from the drive is received.
  • 24 V (green): Power supply OK.

If TxD never flashes, the CP340 is not being polled by FB 7 — check the input/output address in the hardware configuration. If TxD flashes but RxD does not, the cable, parity, or address assignment on the drive is wrong.

11. Performance and Cycle-Time Notes

The USS cycle time seen at the drive depends on baud rate, PZD length, and the number of nodes. With the default 9,600 bit/s and 2 PZD words per direction, the per-drive round-trip is approximately 25 ms. The CP340 can buffer up to 32 nodes; for a single drive the polling cycle can be set to 50 ms. For multi-drive installations, calculate as:

t_cycle ≥ (PZD_words_in + PZD_words_out) × 11 × (1 / baud_rate) × n_nodes × 1.5

For example, 10 drives at 2 PZD words each way, 19,200 bit/s:

t_cycle ≥ 2 × 11 × (1 / 19200) × 10 × 1.5 ≈ 17 ms

This is comfortably below the typical 100 ms PLC scan time. If the drive requires faster response (e.g., positioning with fast ramp), move to PROFIBUS DP at 1.5 Mbit/s where the same 10-drive bus is polled in under 10 ms.

12. Migrating from STEP 7 to TIA Portal

The USS library for STEP 7 V5.5 still works in TIA Portal via the legacy block import or by re-implementing the same logic with a CP341 and the TIA USS block set. If a project is migrated, the legacy CP340 is replaced by CP341 (article 6ES7341-1CH02-0AE0) and the USS protocol license is activated through the CP341's parameter dialog. The SINAMICS G120 parameters do not need to change because the protocol is identical.

For greenfield TIA Portal projects, an even simpler approach is to swap the CU240E for a CU240E-2 PN, then use the ready-made SINAMICS G120 PROFINET GSD file to drop the drive into the TIA project and integrate it directly into the S7-300 / S7-1500 PROFINET network. Theuss migration to PROFINET removes the CP340 entirely.

13. EMC and Cable Routing Best Practices

  • Keep USS cable runs at least 200 mm away from VFD power cables. Cross them at right angles when crossings are unavoidable.
  • Bond the shield to PE at the cabinet entry using EMC glands. Avoid pigtails longer than 50 mm.
  • Ground the S7-300 rack, the drive cabinet, and the USS bus reference to the same equipotential bus bar.
  • Use a screened cable with at least 0.5 mm² cross-section for the data pairs. The PROFIBUS purple cable (6XV1830-0EH10) is well suited.
  • Do not install terminators on intermediate nodes — only the first and last physical device.

14. Frequently Asked Questions

Can the CU240E (6SL3244-0BA10-0BA0) communicate with a SIMATIC S7-300 over USS protocol?

Yes. The CU240E has an on-board RS485 port that supports USS master/slave. Connect a Siemens CP340 (6ES7340-1CH02-0AE0) or CP341 (6ES7341-1CH02-0AE0) to the S7-300, wire the 2-wire RS485 link to terminals 3 and 4 of the CU240E, configure P2010 = 9 (9,600 bit/s) and P2011 = 1, then implement the Siemens USS master library on the PLC.

Does the CU240E support PROFIBUS?

No. The original CU240E does not have a PROFIBUS DP interface. For PROFIBUS control, replace the Control Unit with a CU240S DP (6SL3244-0BA20-1BA0), CU240S DP-F (6SL3244-0BA20-1FA0), or the modern CU240E-2 DP (6SL3244-0BE22-1BA0). The Power Module can remain unchanged.

What is the recommended baud rate for USS on CU240E?

9,600 bit/s (P2010 = 9) is the standard default and is supported by every CP340/CP341 firmware version. 19,200 bit/s or 57,600 bit/s can be used for faster bus cycles but require shorter cable lengths (under 200 m for 57,600) and better EMC shielding.

Which FB blocks are required to run USS from an S7-300?

The Siemens USS protocol library includes FB 7 (master driver), FC 21 (PKW read/write), and an instance DB per drive. The library is shipped with STEP 7 V5.5 and is also available on the SIOS portal. In TIA Portal, use the same logic with the TIA USS block set on a CP341.

What happens if the USS cable is disconnected from the CU240E?

The drive waits for the telegram off time defined by P2014 (default 2 s). If no valid frame is received within that window, fault F0072 is raised, the drive coasts to stop, and bit 3 of the status word is set. The PLC can detect this through the status word or by monitoring the FB 7 "communication OK" flag.

Can the CP340 RS485 interface support multiple SINAMICS G120 drives?

Yes. The CP340 can address up to 32 USS slaves. Each CU240E must be assigned a unique node number through P2011 (1–31). Use one instance DB per drive and configure the FB 7 driver accordingly.

What firmware version on the CU240E supports USS without restriction?

Firmware V1.0 and later on the original CU240E supports USS master/slave. V1.x remains in production for legacy installations. For new projects, migrate to the CU240E-2 family (firmware V4.x and later), which adds Modbus RTU, PROFINET/PROFIBUS, and the safety-licensed variants.

Back to blog