Welcome to the Industrial Automation website!

NameDescriptionContent
XING-Automation
E-mail  
Password  
  
Forgot password?
  Register
当前位置:

Based on the S7-300/400 Ethernet module CP343-1 &CP443-1 Modbus TCP used in STEP7 Door (V6.0)

F: | Au:佚名 | DA:2023-11-21 | 1274 Br: | 🔊 点击朗读正文 ❚❚ | Share:

1 Overview of Modbus TCP communication

MODBUS TCP is a simple, vendor-neutral derivative of the MODBUS family of communication protocols for managing and controlling automation devices, and it obviously covers the purpose of MODBUS messages in the "Intranet" and "Internet" environments that use TCP/IP. The most common use of the protocol is for services such as PLCS and gateways connecting to other simple domain buses or I/O modules.

MODBUS TCP enables MODBUS_RTU to run on Ethernet. MODBUS TCP uses TCP/IP and Ethernet to transmit MODBUS packets between sites. MODBUS TCP combines Ethernet physical networking with the networking standard TCP/IP and data representation with MODBUS as the application protocol standard. MODBUS TCP communication packets are encapsulated in Ethernet TCP/IP packets. Unlike the traditional serial port mode, MODBUS TCP inserts a standard MODBUS message into the TCP message without the data checksum address.

1.1 Ethernet reference model for communication

The Modbus TCP transmission process uses Layer 5 of the TCP/IP Ethernet reference model:

Layer 1: The physical layer provides the physical interface of the device and is compatible with the commercially available media/network adapter.

The second layer: the data link layer, formats the signal to the source/destination hardware address data frame.

Layer 3: The network layer implements packets with 32-bit IP addresses.

The fourth layer: the transport layer, to achieve reliable connection, transmission, error checking, retransmission, port service, transmission scheduling.

Layer 5: Application layer, Modbus protocol packets.

1.2 Modbus TCP Data frame

Modbus data is transmitted over TCP/IP Ethernet and supports Ethernet II and 802.3 frame formats. The Modbus TCP data frame consists of three parts: packet header, function code and data. The Modbus Application Protocol (MBAP) packet header is divided into four domains. Total 7 bytes.

1.3 Port Number for Modbus TCP

(1) When PLC is used as Modbus server, Port 502 communication port is used according to default protocol, and any communication port is set in the Modus client program.

(2) When PLC is used as Modbus client, it is not necessary to set the local port number; If you want to specify a client port number, you are advised to start with 2000 to avoid conflicts with other communication protocols.

2 Overview of Modbus TCP communication on the S7-300/400 Ethernet module

This document applies to SIMATIC S7-300, S7-400 CPU with Ethernet module CP343-1 or CP443-1 software products. The instructions allow communication between S7-300, S7-400 systems with Ethernet modules CP343-1 or CP443-1 and devices that support the Modbus TCP protocol.

Data transmission is carried out according to the client-server principle. SIMATIC S7 can be used as a client or server during transfer.

2.1 Software and Hardware

When Modbus TCP commands are used in STEP7 software, the Modbus TCP CP instruction library needs to be installed before SIMATIC S7-300, S7-400 CPU with Ethernet module CP343-1 or CP443-1 can communicate with the communication partners that support Modbus TCP. As shown in Figure 2-1:

2.2 Modbus TCP CP V6.0 Software Option Package

When the software package is installed and integrated into Step7, you can find the block library, routines, and English manual in the corresponding directory of the Step7 installation file, as shown in the following figure. In the actual debugging process of the project, since the functions of the example program are relatively perfect, you can directly use the example program and modify the corresponding parameters according to the actual situation of the project. Can save a lot of parameter setting time.

3 Configure the Ethernet module as the Modbus TCP Server to communicate with the communication partner

The following uses the S7-300 single-site system and Modscan32 software as an example to describe how to configure the S7-300 single-site system as the Modbus TCP Server through the Ethernet module CP343-1 to communicate with Modscan32 as a Client.

3.1 Configuring Hardware

Create a new project (project name: MB_TCP_CP_V60) in STEP7.

3.2 Adding a TCP Connection

On the Hardware Configuration page, click "Configure Network" under Options to enter the network configuration page.

Next, select CPU, and in the table below, right-click and select "Insert New Connection" to add the TCP connection.

The communication partner is Unspecified and the connection type is TCP connection.

Select the local connection resource number (default ID=1) and PLC as the server. Note that "Active connection establishment" is not checked.

Click the "Addresses" page and set the local port number to 502.

3.3 Routine Description

Open the routine and copy all program Blocks (do not copy System data) from site SIMATIC 300 (Server) to the blocks of site SIMATIC 300 (1) of new project MB_TCP_CP_V60.

(1) Open OB1 and view the command "MODBUSCP"

The Modbus TCP command is invoked in the OB1 organizational block of the project,

The following are some pin descriptions (for other pin information, please see the instruction library manual) :

id: indicates the ID of the configured connection in Configure Network. The connection ID is the unique identification of the connection between the CPU and the connection partner through the CP. Enter the number for the connection configuration here. This parameter ranges from 1 to 64.

db_param: parameter data block that contains modbus data parameters for the modbus block instance. The CPU determines the value range of this parameter. DB number 0 is reserved for the system and cannot be used. Enter the DB number "DBxy" in plain text format. If multiple connections are to be implemented, the parameter data block can contain the parameters required for all connections in order.

REG_KEY_DB: Registration key used for authorization.

MONITOR: Monitoring time MONITOR is used to monitor incoming data from connection partners. The time format T# is used to specify the monitoring time. It is recommended that the monitoring time be about 1.5s.

In "S7 as server" mode, the input of the second part of the frame is monitored by MONITOR time. If the monitoring time is exceeded, an error is reported. This time is calculated from the receipt of the MODBUS/TCP specific packet header and ends when the request is fully received.

Init: initializes the Modbus block when there is a rising edge in the parameter. Initialization can only be performed if no jobs are currently running. This condition must be ensured in the program by ENQ_ENR = FALSE and BUSY = FALSE.

(2) Parameter data block DB2

Parameter data block DB2 (name MODBUS_PARAM_CP). This parameter DB block is used to set the modbus data area.

Notice To modify Data in the DB block, switch the DB block to Data view and modify the DB block in the Actual value column.

In this example, you need to change DB2 ID2_ID to 16#1 according to the connection Settings in Figure 3-7. To facilitate the mapping of subsequent communication test addresses, change the start and end addresses of the modbus register to 16#0 and 16#1F3 respectively.

3.4 Communication Test

Download the project to the CPU, open the Modsan32 application, the following to the hold register as an example to introduce the communication test process.

First, select connect under the Connection menu for ModScan32 and set the IP address and port number for ModScan32 to access the PLC as the server side.

Finally, set the start address and length of Modbus to be accessed in Modscan32 software (in this test, Modscan32 uses data type 3 and the start address of the access hold register is 10 words of 40001), establish a communication connection with PLC, and carry out data reading.

You can view the communication status in the network configuration window.

Some considerations for using the function block "MODBUSCP" :

1) The S7-300CPU supports communication with multiple Modbus clients through the function block "MODBUSCP" of the Ethernet module CP343-1. The number supported depends on the number of TCP connections supported by the CP343-1. The function block "MODBUSCP" must be invoked once for each client connection. Parameters such as background data block, ID, and port number must be unique.

2) The S7-300CPU can be used as the Server and Client of Modbus TCP through the Ethernet module CP343-1.

3) The S7-300CPU supports multiple protocols through the Ethernet module CP343-1, which can run PROFINET, TCP/IP, S7 and other protocols in addition to Modbus TCP.

4 Configure the Ethernet module as the Modbus TCP Client to establish communication with the communication partner

The following uses the S7-300 single-site system and ModSim32 software as an example to describe how to configure the S7-300 single-site system as the Modbus TCP Client through the Ethernet module CP343-1 to communicate with Modsim32 as the Server.


  • Lauer LCA 200 V03907 Control Console Operator Interface
  • Lauer PCS 095 PG095.507.A Operator Panel Industrial HMI
  • Lauer 035/24 Industrial Control Module Automation Component
  • Systeme Lauer PCS830-31 Interface Module Industrial Automation
  • Lauer PCS090.M 190.203.3 Operator Panel Industrial Control
  • Systems Lauer LCA045 Text Display Operator Terminal
  • Lauer EPC-PM-1200TC Industrial PC Panel
  • Lauer PCS095 Topline Mini Operator Panel 095.506.8
  • Lauer PCS 8010 Expansion Module
  • Lauer PCS950Q PLUS Membrane Keypad
  • Lauer Tele Service TSN 110 Module
  • Lauer PCS950C User Interface Trepko 95C.201.0
  • Lauer PCS 200FZ Control Console XX2.1031.SHX
  • Lauer PCS950 Operator Panel Wifag 950.000.5
  • Lauer PCS 950 Topline Midi Control Panel 950.000.05
  • Lauer LHT-T40m-P Control Panel V15-10-10
  • Lauer Operator Panel PCS Light PG080.308.F
  • Lauer LCA Starline Mini 200.102.1
  • Lauer VPC Take Off Line VK212B.II.LAU
  • Lauer Grießbach Printing Machine Operating Terminal BAB34098
  • BS Lauer LP 056/02 Operator Panel
  • Lauer AVTCE212.3 HMI Panel
  • Lauer PCS950 Operator Panel 950.000.5 Wifag
  • Lauer PCS095 Topline Mini 095.508.B Operator Panel
  • Lauer PCS 811 Interbus-S Module Fieldbus Communication Interface
  • Systeme Lauer 035/18F Industrial Control Module Automation
  • LAUER PCS090 090.202.7 Operator Panel Industrial Control
  • Lauer PCS 600 Control Console Industrial Operator Panel
  • Lauer PCS095 Topline PG095.505.8 Operator Panel HMI
  • Systeme Lauer PCS830-3 Control Module Industrial Automation
  • Lauer EPC-PM-1200TR Industrial PC Panel Touch Display Computer
  • Lauer PCS090 PG090.208.E Operator Panel Industrial Terminal
  • Lauer PCS 804 Interbus Interface Module Fieldbus Adapter
  • Lauer PCS 802 Control Console Industrial Operator Panel
  • Lauer Operator Panel PCS950 with PCS808
  • Lauer PCS950Q Topline Midi 950.000.5
  • Lauer LCA 320 300.001.0 Text Display
  • Lauer Operator Panel PCS090 PG090.207.D
  • Lauer PCS PCS095.1 Operator Panel Skinetta
  • Lauer PCS8010 035/28B Expansion Module
  • Lauer Topline Mini Operator Panel PCS 090 PG090.208.E
  • Systeme Lauer PCS830-1 Interface Board 830.1-00124-H6
  • Kuttler Lauer PCS090.M PG190.203.3 Operator Panel
  • Lauer PCS 090 Control Console Operator Terminal Industrial
  • Lauer PCS 804.1 Interbus Adapter Module Fieldbus Interface
  • Lauer LCA 300.0 Starline Midi Text Display Control Panel
  • Systems Lauer PCS811 GEB Interbus-S Slave Module Fieldbus
  • Lauer PCS 811 Interbus-S Module PG 811.000.1 Fieldbus Interface
  • LAUER WOP-IT-X-550-KTC Industrial Touch Panel HMI Terminal
  • Lauer PCS609 Topline Micro Panel Operator Interface Industrial
  • Lauer PCS 090 Topline Mini PG 090.207.D Operator Panel Industrial HMI
  • Lauer AIO Automation in One PC Unit 24V DC
  • Lauer WOP-IT-X-640TC UMP
  • Systeme Lauer LCA 265 Text Display 24V
  • Lauer VPC Take Off Line MT215.LAU
  • Systeme Lauer SIMATIC S5 Serial Interface Board PCS 810-1
  • Lauer PCS WIN Profibus DP PCS 090b/L033/03
  • Lauer LCA200 Starline Mini
  • Lauer DJ432 Control Panel EPC 1200tc Eltex ESC2/EBE
  • Lauer LK2438 Control Panel Branson PCS095
  • LAUER PCS LIGHT PG 080.308.E Operator Panel PLC HMI
  • Lauer LCA 200 Starline Mini Control Console Operator Interface
  • LAUER LCA300 Starline Midi Operator Console Panel Industrial
  • LAUER PCS 009 Topline Micro Operator Panel 24VDC Industrial
  • LAUER LCA320.1 Text Display Operator Terminal Industrial
  • LAUER PCS812 Operator Panel Control Interface Industrial
  • LAUER PCS LIGHT 00190 K4 Operator Panel Industrial Display
  • Lauer PCS 8100 Memory Module Control Panel Industrial Storage
  • Lauer PSC095.5 A Operator Interface Panel Industrial HMI
  • LAUER PCS 9100 LCD Display Module Industrial Replacement Screen HLD0909-010050
  • Lauer Systeme LCA620.1 Operating Terminal Industrial HMI Keypad Panel
  • LAUER LXT-K10m Beijer EXTER-K10m Operator Interface Keypad HMI Panel
  • LAUER EPC-PM-1500tc Embedded PC 15 Inch TFT Touch Screen Industrial Computer
  • Lauer Industrial VPC Color Panel Control ID64680
  • Lauer PCSsmart PCS-10TVD-102 Touchscreen Panel
  • Lauer EPC 1200TC Embedded Industrial PC
  • Lauer Control Console PCS 095
  • Lauer PCS-090 Topline Mini Operator Panel PG090.208.D
  • Systeme Lauer 14X Operator Panel
  • Lauer Topline midi PCS950C Operator Panel 24V
  • Lauer PCS090 Topline Mini Control Console – Compact Operator Panel
  • Lauer PCS950 Topline Midi Operator Panel PG 950.100.6 – HMI Terminal
  • Lauer LCA 285.0 Text Display – Alphanumeric Operator Terminal
  • Lauer PCS100 Operator Panel V100.305.7 – Industrial HMI Terminal
  • Systeme Lauer PCS810-1 Interface Module – Communication Board
  • Lauer EPCG Box Embedded 1000TC Motherboard
  • Lauer Systeme LCA285 LCA 285.9 Text Display – 24V Alphanumeric Terminal
  • LAUER PSC090.S Operator Interface Panel – Compact HMI with Serial Communication
  • Lauer PCS590p / PCS595p Busline Mini Profibus DP Panel
  • LAUER PCS009 Control Panel – Compact Operator Terminal
  • Lauer PCS595 Business Mini Profibus DP Control Panel – Compact HMI with Fieldbus
  • LAUER PCS600 Operator Panel PG 600.105.2 – Compact HMI Terminal
  • Lauer LCA Terminal 640.1 – Advanced Operator Workstation
  • LAUER PCS807 Profibus-DP Module 24V DC 5.0VA – Fieldbus Adapter
  • SYSTEME LAUER PCS810.1 Interface Module – Communication Adapter
  • Lauer PCS090 Topline Operator Panel PG 090.204.9 – Compact HMI
  • LAUER PCS950 Rismat Label Operator Panel PG 950.100.6 – HMI Terminal
  • Lauer PCS609 Operator Interface Panel – Keypad Display Terminal
  • LAUER PCS095 Branson Label Operator Panel PG 095.508.A – HMI Terminal
  • Systems Lauer LCA 265 Text Display – Alphanumeric Operator Terminal
  • Lauer PCS-10TVD-102 Touch Panel – Smart HMI for Industrial Control
  • Lauer PCS595i Industrial Operator Panel – High-Performance HMI
  • LAUER PCS950 Operator Panel – Advanced HMI Terminal
  • Lauer PCS100FZ Control Console – Industrial Operator Station
  • Lauer LCA320.0 Industrial Controller – Compact Logic Module
  • Lauer PCS950.000.5 Control Panel PG 950.103.0 – Branson Compatible HMI
  • Lauer LCA Busline 320 Controller Module i01457 – Industrial Logic Unit
  • LAUER PCS095 Complete Controller Display – Graphic Operator Panel
  • Lauer PCS807 Profibus-DP Module PX 807.101.5BM – Fieldbus Adapter
  • Lauer PCS090 Topline Operator Panel PG 090.206.D – Compact HMI Terminal
  • Lauer PCS095 Branson Label Operator Panel PG 095.507.A – HMI Terminal
  • Lauer PCS009 Topline Micro Operating Terminal PG 009.204.1 – Mini HMI
  • LAUER AVTCE210.2 – Industrial Vision and Control Terminal
  • LAUER LCA 245 Text Display SU 245.100.1
  • LAUER PCS807 Profibus DP Module 807.101.5BM
  • Lauer PSC090 Topline Mini Operator Interface Panel – Compact HMI
  • Lauer EPC X 550 TC Embedded Industrial PC with Touch Panel
  • LAUER SYSTEME PCS-900 Operator Panel – Advanced HMI Workstation
  • Lauer PCS095.P PCS Plus Profibus DP Operator Interface – Control Panel
  • Systeme Lauer LCA 180 Text Monitor LD 180.004.1 – Industrial Text Display Terminal
  • LAUER PCS950C – High-Performance Process Control Station
  • LAUER SYSTEME LCA142 – Compact Industrial Controller and Logic Unit
  • LAUER SYSTEME PCS-810-1 – Industrial Panel PC and Control Terminal
  • ASML Right Field Detector 874-0084-002 – Light Intensity Measurement Module
  • ASML IPCB SEM-I-319 Interface Board 4022.636.58181 – VME I/O Module
  • ASML Temperature Sensor Assembly PT1000 4022.481.27732
  • ASML PCB FEI PHILIPS FIDT BD 4022.192.71178
  • ASML IR1-NIR Module 4022.639.86644 – Infrared Near-Infrared Sensor Unit