Overview: Validating S7-1200 Modbus RTU Slave Communication
Field commissioning of a SIMATIC S7-1200 CPU fitted with a CB 1241 RS485 communication board (Siemens part number 6ES7 241-1CH30-1XB0) requires verification that the Modbus RTU slave responds correctly to register reads, register writes, coil operations, and exception handling. The most efficient validation path is to use a PC-based Modbus master over a USB-to-RS485 converter. This approach removes dependency on the actual field master, allows deterministic polling of every address range, and produces reproducible test logs that can be archived with the project file.
The CB 1241 RS485 is a cost-effective add-on board for the S7-1200 family. It is mechanically mounted on the left side of the CPU and is electrically isolated. It supports Modbus RTU master and slave modes via the TIA Portal library instructions MB_COMM_LOAD and MB_SLAVE (or MB_MASTER when the CPU is the master). The board is pin-compatible with the modular CM 1241 RS422/485 (6ES7 241-1CH32-0XB0) from a software perspective, but is targeted at smaller installations where the 6 signal-status LEDs and 15-pin sub-D of the CM are not required.
This article covers hardware wiring, TIA Portal configuration of the Modbus slave instruction, PC-side master tooling (free and commercial), and a verification procedure with concrete register values that you can replicate on the bench.
Prerequisites
Before commissioning the slave, confirm the following items are available and that the engineering environment is current.
| Category | Item | Detail / Version |
|---|---|---|
| Hardware | S7-1200 CPU | Any CPU with FW 4.x or later that supports the Modbus library (1211C, 1212C, 1214C, 1215C, 1217C) |
| Hardware | CB 1241 RS485 | 6ES7 241-1CH30-1XB0, firmware V1.0 or higher |
| Hardware | USB-to-RS485 converter | FTDI FT232-based, Moxa UPort 1130/1150, or industrial-grade isol |
| Software | TIA Portal | V15.1 or later; library "MODBUS" or "MODBUS_PN" depending on TIA version |
| Software | Modbus master tool | ModScan32 (Win-Tech), Modbus Poll (Witte Software), or Simply Modbus (simplymodbus.ca) |
| Cabling | RS485 twisted pair | Shielded, 120 Ω characteristic impedance, termination at both ends |
CB 1241 RS485 Hardware Specifications
The CB 1241 RS485 shares the electrical interface characteristics of the modular CM 1241 RS422/485. The relevant limits must be respected when designing the bus segment, particularly when connecting to industrial PCs and field devices with different ground references.
| Parameter | Value |
|---|---|
| Type | RS422 or RS485, software-selectable |
| Connector | 9-pin sub-D female |
| Common-mode voltage range | -7 V to +12 V, 1 second, 3 V RMS continuous |
| Baud rates | 300, 600, 1200, 2400, 4800, 9600, 19200, 38400, 57600, 76800, 115200 bps |
| Parity | None, Even, Odd, Mark, Space |
| Maximum cable length | 1000 m at ≤ 19200 bps; 50 m at 115200 bps (per RS485 spec) |
| Max nodes | 32 unit loads |
| Isolation | Functional isolation from CPU logic |
Source: Siemens SIMATIC S7-1200 Manual Collection - CM 1241 RS422/485 Specifications.
RS485 Wiring and Bus Topology
RS485 is a differential, multi-drop bus. The CB 1241 exposes the following signals on its 9-pin sub-D connector:
| Pin | Signal | Function |
|---|---|---|
| 2 | TxD+ / RxD+ (D+) | Non-inverting line |
| 3 | GND | Signal ground |
| 5 | TxD- / RxD- (D-) | Inverting line |
| 7 | +5 V | Optional bus power, 50 mA max |
| 8 | TxD+ (RS422 only) | Transmit non-inverting |
| 9 | TxD- (RS422 only) | Transmit inverting |
For half-duplex Modbus RTU, use pins 2 (D+) and 5 (D-) only, plus 3 (GND) for reference. Place 120 Ω termination at both physical ends of the trunk. A daisy-chain layout is required; star topologies cause reflections.
TIA Portal Configuration of the Modbus Slave
Three TIA Portal steps are required: assign the CB 1241 to a free communication interface, instantiate the MB_COMM_LOAD block to configure the port, and instantiate MB_SLAVE with the data buffer.
Step 1 - Hardware Configuration
- Open the device view of the S7-1200 station in TIA Portal.
- Drag the CB 1241 RS485 (order number 6ES7 241-1CH30-1XB0) from the catalog onto the left slot of the CPU.
- Open the board's properties. The port is automatically addressed as
CM/CPorCBslot 1 depending on the catalog. The default hardware identifier is used by theMB_COMM_LOADinstruction.
Step 2 - Add the Modbus Library
From the right-side task card, open Libraries > Global Libraries > MODBUS (or MODBUS_PN in older TIA versions). Drop the following blocks into a new program block:
-
MB_COMM_LOAD(FB 1200) - one-time port configuration in OB100 or first cycle. -
MB_SLAVE(FB 1201) - polled in OB1.
Step 3 - Configure MB_COMM_LOAD
| Input | Recommended Value | Comment |
|---|---|---|
| REQ | TRUE (one-shot) | Triggered in OB100 |
| PORT | CB slot identifier (HW ID) | From device configuration |
| BAUD | 9600 | Default for diagnostic work |
| PARITY | 0 (Even) | Modbus RTU standard |
| FLOW_CTRL | 0 (None) | RS485 half-duplex |
| RTS_ON_DLY | 0 | No transmitter delay |
| RTS_OFF_DLY | 0 | No receiver delay |
| RESP_TO | 2000 ms | Slave response timeout |
Step 4 - Configure MB_SLAVE
| Input | Value | Comment |
|---|---|---|
| MB_ADDR | 1 | Slave ID 1, must match PC master |
| MODE | 1 (full processing) | After commissioning, set to 0 to disable |
| DATA_PTR | P#DB1.DBX0.0 BYTE 100 | 100-byte data buffer (50 holding registers) |
| DATA_LEN | 100 | Bytes, must match DATA_PTR size |
The default Modbus mapping applied by MB_SLAVE on the S7-1200 is:
| Modbus Function | Access | Data Area (DATA_PTR offset) |
|---|---|---|
| 01, 05, 15 | Read/Write Coils | 0 to 7 (bit-addressed 0xxxx) |
| 02 | Read Discrete Inputs | 0 to 7 (bit-addressed 1xxxx) |
| 03, 06, 16 | Read/Write Holding Registers | 0 to 49 (16-bit, 4xxxx) |
| 04 | Read Input Registers | 0 to 49 (16-bit, 3xxxx) |
Download the project to the CPU. The CB 1241's diagnostic LED should go green, indicating the port is active and no framing errors are present.
Setting Up the PC as Modbus Master
Three components are required on the bench:
- USB-to-RS485 converter - an FTDI-based cable is sufficient for short test runs. For permanent bench setup or noisy environments, use an industrial converter such as the Moxa UPort 1130 (isolated) or UPort 1150. Check the Windows Device Manager for the assigned COM port number (typically COM3 or higher).
- Modbus master software - the most common Windows tools are detailed in the next section.
- Wiring harness - connect D+ of the converter to pin 2 of the CB 1241, D- to pin 5, and ground to pin 3. Add the 120 Ω terminator at the CB 1241 if it is the end of the bus.
PC Software Comparison: Modbus Master Tools
| Tool | Vendor | Cost | Role | Notes |
|---|---|---|---|---|
| ModScan32 | Win-Tech Software | Free, registration required | Master | Industry standard, fast polling, hex view |
| Modbus Poll | Witte Software | Trial (10-min limit) | Master / Slave | Polling at sub-millisecond intervals |
| ModView | Witte Software | Free | Master / Slave | Lightweight, good for initial verification |
| Simply Modbus | simplymodbus.ca | Trial (limited sessions) | Master / Slave | Includes Modbus TCP and RTU in one package |
| QModMaster | Open source | Free | Master | Qt-based, multi-platform |
For an S7-1200 slave verification the ModScan32 utility is the most widely used. Its single-pane read/write layout and unlimited polling make it ideal for the bench. Modbus Poll is preferred for long-duration capture with logging, and is the tool to use when demonstrating to a buyer the same way the field master will behave.
Verification Procedure: End-to-End Slave Test
The following procedure produces a reproducible set of read/write checks against the Modbus slave. Run it with the converter connected, ModScan32 launched, and TIA Portal online to the CPU.
1. Physical Layer Check
- Open ModScan32, select Connection > Connect.
- Choose the COM port assigned to the USB-to-RS485 converter.
- Set baud rate to 9600, parity Even, data bits 8, stop bits 1.
- Set Slave ID to 1.
- Set scan rate to 1000 ms (slow for manual observation).
If polling works at 9600, raise the baud to 38400, then 115200 to confirm the upper limit of the CB 1241. The communication LED on the CB 1241 should pulse at the configured poll rate.
2. Register Read Test (Function 03)
In TIA Portal, force the first five holding registers of DB1 to known values, for example:
DB1.DBW0 = 16#1234
DB1.DBW2 = 16#5678
DB1.DBW4 = 16#9ABC
DB1.DBW6 = 16#DEF0
DB1.DBW8 = 16#0000
In ModScan32, configure Function 03, address 0, length 5, display format HEX. The displayed values must match the forced values byte-swapped (Modbus is big-endian, S7-1200 is little-endian; the swap is handled by MB_SLAVE). Expect 0x1234 0x5678 0x9ABC 0xDEF0 0x0000.
3. Register Write Test (Function 06)
Select register address 9 in ModScan32, click the cell, set the value to 0xAAAA, and send. Watch the traffic: the master issues a write, the S7-1200 echoes the response, and DB1.DBW18 in the PLC should read 0xAAAA. Use a monitor table in TIA Portal to confirm without stopping the scan.
4. Multi-Register Write Test (Function 16)
From ModScan32, write 10 registers starting at address 0 with a known pattern, for example 0x0102, 0x0304, ..., 0x1314. Verify in TIA Portal that DB1.DBW0 through DB1.DBW18 reflect the same pattern.
5. Coil Read/Write Test (Functions 01, 05)
Force DB1.DBX0.0 = TRUE in TIA Portal. In ModScan32, switch the function code to 01 and read address 0; the display must show 1 (ON). Switch to function 05, address 0, value 0, write. The bit must clear in the PLC monitor table.
6. Exception Response Test
Send a read to a non-existent address, e.g. function 03, address 9999. The S7-1200 must return Modbus exception 02 (Illegal Data Address). ModScan32 displays the exception in the status bar. This proves that the slave's exception handler is wired correctly before the field master is connected.
7. Loopback / Multi-Day Stability
Use Modbus Poll in "Save data to file" mode to log 24 hours of read traffic at the production baud rate. The bus should remain free of CRC errors, timeouts, and exception responses. A single CRC error per hour is acceptable for a lab environment; zero is the target for a delivered system.
Troubleshooting Matrix
| Symptom | Likely Cause | Corrective Action |
|---|---|---|
| No response, ModScan32 reports timeout | Wiring polarity reversed (D+/D- swapped) or slave ID mismatch | Swap pins 2 and 5; confirm MB_ADDR equals master slave ID |
| CRC error counter increments on every poll | Baud rate or parity mismatch | Verify BAUD and PARITY in MB_COMM_LOAD match the master |
| Intermittent timeouts under load | Missing or wrong termination | Install 120 Ω at both ends; check shield is grounded at one end only |
| First poll works, subsequent polls time out | USB converter driver drops the COM port under sustained load | Disable FIFO buffers in the COM port advanced settings; use an industrial converter |
| Exception 02 on valid addresses | DATA_LEN too small for the requested range | Increase DATA_LEN to cover the maximum address polled |
| Exception 03 on write attempts | Address range locked or outside DATA_PTR | Confirm DB1 is non-optimized (absolute addressing enabled) |
| CB 1241 diagnostic LED red | Port not configured or hardware fault | Check that MB_COMM_LOAD has run; reseat the board |
| Field master reports "device not found" | Master polling faster than 3.5 char gap | Reduce scan rate on the master; respect Modbus RTU inter-frame delay |
Advanced Topics
Using a Second S7-1200 as the Master
When a permanent test fixture is preferred, a second S7-1200 fitted with a CB 1241 can act as the Modbus master. The test program uses MB_MASTER to poll the slave at fixed intervals and writes pass/fail bits to a status word. The advantage is that the test fixture is identical in form factor to the field hardware and survives power cycles. The disadvantage is the need to maintain two TIA Portal projects.
Long-Distance and Industrial-Grade Testing
When the slave is located more than 10 m from the bench PC, the bus begins to exhibit real-world impairments: ground potential differences, EMI from VFD cables, and reflections from improperly terminated stubs. In that scenario, use:
- An isolated USB-to-RS485 converter (Moxa UPort 1130I, Phoenix Contact PSM-ME-RS232/RS485-P).
- Shielded twisted pair (Belden 3106A or equivalent) with the shield bonded to ground at one end only.
- Optically isolated repeaters (e.g., Moxa TCC-80) every 1.2 km if the bus is stretched beyond the RS485 spec.
Logging and Test Reports
For customer acceptance tests, export the Modbus Poll log to CSV, include the slave configuration screen from TIA Portal, and archive the wiring diagram. The audit trail proves that the slave was verified against an external master before shipment.
FAQ
What is the part number of the CB 1241 RS485 used with the S7-1200?
The CB 1241 RS485 board for the S7-1200 is ordered as 6ES7 241-1CH30-1XB0. It is mechanically mounted on the left side of the CPU and exposes a 9-pin sub-D female RS485/RS422 port.
Which free Modbus master tool is recommended for testing the S7-1200 slave?
Win-Tech's ModScan32 is the most widely used free Modbus RTU master. Modbus Poll (10-minute trial) and the open-source QModMaster are alternatives. All three support function codes 01, 02, 03, 04, 05, 06, 15, and 16 needed to validate the MB_SLAVE instruction.
What baud rate, parity, and stop bits should be used for Modbus RTU on the CB 1241?
Modbus RTU over serial defaults to 9600 bps, 8 data bits, even parity, and 1 stop bit (8E1). The S7-1200 supports all standard rates from 300 to 115200 bps; the choice should match the field master. Mismatched parity is the most common cause of CRC errors during bench tests.
Why does my Modbus master receive exception code 02 (Illegal Data Address) from the S7-1200?
Exception 02 means the master requested an address outside the buffer mapped by MB_SLAVE. Increase the DATA_LEN parameter of the MB_SLAVE block so that the highest polled offset fits inside DATA_PTR. With the default 100-byte buffer, holding registers 4xxxx0 through 4xxxx49 are valid.
Can I test the S7-1200 Modbus slave without buying a USB-to-RS485 converter?
Yes, if you have a second S7-1200 or any Modbus RTU master available, you can use it directly. A bench laptop without a serial port still requires a USB-to-RS485 adapter; FTDI-based cables are inexpensive and sufficient for short runs of less than 100 m, but an isolated converter is recommended for permanent or industrial use.