Skip to main content
Siemens · Technical Blog

Siemens PLC to G120 Drive: Modbus RTU and PROFINET with One Standard FB

Two control words out, six status words in — telegram 20 as the reference, mapped to Modbus registers and wrapped in one reusable function block.

2,500+ engineers trained 4.9/5 Google rating 21+ years, Chinchwad, Pune Next batch: contact for dates
Quick answer

Take Standard Telegram 20 (PZD-2/6) as the data model: two words written — control word and speed setpoint — and six words read — status, speed, current, torque, power and a message word. Write one function block, FB_Drive_2x6, that takes SW[0..5] in and returns CW[0..1] out, with a Transport input that switches the scaling rule. On Modbus RTU a three-step MB_MASTER chain fills those arrays from registers 40100, 40110 and 40340–40347; on PROFINET two MOVE networks fill them from the telegram. The FB, and everything above it, stays identical.

  • Two words out, six words in — the same shape on either network.
  • The FB never touches the network; only the transport networks differ.
  • PROFINET sends normalised values against p2000/p2002/p2003; Modbus sends fixed factors of 1 or 100.
  • One step bit per job, handed over on DONE or ERROR.

Hardware and Wiring

One master, one drive. The CB 1241 clips into the communication board slot on the front of the CPU, and the line is a shielded twisted pair plus a core for signal common — leaving the common out is a classic cause of intermittent faults.

One master, one drive — the line is ready for more drives laterS7-1215CModbus masterCB 1241 (RS485)in the CB slot of the CPUT/RA · T/RB · Mjumper TA–T/RA and TB–T/RB hereSINAMICS G120Slave address 1p2030 = Modbus RTU · p2021 = 1 · 19200 baud, even parityterminator ON — last device on the lineA (T/RA)B (T/RB)M (common)BIAS+TERMTERM
The CB 1241 end carries bias and termination; the drive at the far end has its own terminator.
ItemUsed hereNotes
CPUS7-1215C DC/DC/DCAny S7-1200 with a free CB slot works the same way
Serial interfaceCB 1241 (RS485)Fits the communication board slot on the front of the CPU; a CM 1241 (RS485) behaves the same in the program
DriveSINAMICS G120 with an RS-485 capable control unitSlave address 1
CableShielded twisted pair plus a core for signal commonDaisy chained, terminated at both ends
SoftwareTIA PortalThe Modbus instructions are in the standard library

The CB 1241 has bias and termination resistors on board; you switch them in by jumpering TA to T/RA and TB to T/RB.

Line Settings and TIA Configuration

SettingValue hereWhy
Baud rate19200Fast enough for one drive and tolerant of long cable
Data bits8Fixed by the Modbus RTU standard
ParityEvenThe Modbus default — the drive must match
Stop bits1 with parity, 2 withoutThe standard pairs them; the instruction follows your parity choice
Flow controlNoneHalf duplex, direction handled by the module
Response timeout1000 msHow long MB_MASTER waits before reporting ERROR
StepWhere in TIA PortalWhat to do
1Device view of the CPUDrag CB 1241 (RS485) into the CB slot of the S7-1215C
2CB properties → Port configurationSet baud rate and parity
3CPU properties → System constantsNote the port hardware identifier, e.g. Local~CB_1241_(RS485)
4Program blocksCreate DB_Drive as a standard (non-optimised) block — DATA_PTR needs it
5Start-up OBCall MB_COMM_LOAD once
6OB1Call the Modbus step chain, the mapping network and FB_Drive_2x6
7OnlineWatch DONE, ERROR and STATUS per step, then the scaled values

Why Telegram 20 Is the Reference

Telegram 20 is PZD-2/6: two process-data words to the drive and six back. It carries everything a machine program normally wants — run and speed out, and status, speed, current, torque, power and a message word back — without the extra words a longer telegram would add.

That shape also survives the move to Modbus. The same six values exist as registers, so if the program is written against a two-in, six-out interface, the network underneath becomes an implementation detail.

The same function block on either networkFB_Drive_2x6mapping + scaling + drive logicCW[0..1] out · SW[0..5] inRun · Set_RPM → Speed, Current, Torque, PowerPROFINETTelegram 20 (PZD-2/6)%QW256…258 · %IW256…266MOVE the words, or DPRD_DATModbus RTUMB_MASTER jobsMachine programHMI, interlocks, recipesOnly the transport networks change. The FB, its scaling and the machine program stay identical.
One function block, two transports. The machine program never learns which network is in use.

Mapping: Telegram 20 to Modbus Registers

Six read words, two write words — one FB, two transportsPZDSIGNAL (TELEGRAM 20)MODBUS REGISTERPROFINET SCALINGMODBUS SCALINGFB PINPZD1ZSW1 status word40110bit fieldbit fieldSW[0]PZD2NIST_A actual speed4034116#4000 = p2000rpm, ÷ 1SW[1]PZD3IAIST actual current4034516#4000 = p2002A, ÷ 100SW[2]PZD4MIST actual torque4034616#4000 = p2003Nm, ÷ 100SW[3]PZD5PIST active power4034716#4000 = r2004kW, ÷ 100SW[4]PZD6MELD_NAMUR / frequency40342bit fieldHz, ÷ 100SW[5]OUTSTW1 + NSOLL_A (2 words)40100 – 4010116#4000 = p200016#4000 = p2000CW[0..1]
Each PZD word has a Modbus register that carries the same quantity — with a different scaling rule.
PZDTelegram 20 signalModbus registerFB pinPROFINET scalingModbus scaling
PZD1ZSW1 — status word40110SW[0]Bit fieldBit field
PZD2NIST_A — actual speed40341SW[1]16#4000 = p2000rpm, factor 1
PZD3IAIST — actual current40345SW[2]16#4000 = p2002A, factor 100
PZD4MIST — actual torque40346SW[3]16#4000 = p2003Nm, factor 100
PZD5PIST — active power40347SW[4]16#4000 = r2004kW, factor 100
PZD6MELD_NAMUR (PN) / output frequency (Modbus)40342SW[5]Bit fieldHz, factor 100
OUT 1STW1 — control word40100CW[0]Bit fieldBit field
OUT 2NSOLL_A — speed setpoint40101CW[1]16#4000 = p200016#4000 = p2000

Only PZD6 has no exact Modbus equivalent. The PROFINET message word is a bit field; on Modbus the nearest useful value is output frequency in 40342, so the FB treats SW[5] according to the Transport input. The underlying register list from the drive's fieldbus manual is below.

RegisterDescriptionAccessUnitScalingValue rangeParameter
40340Speed setpointRrpm1−16250 … 16250r0020
40341Actual speed valueRrpm1−16250 … 16250r0022
40342Output frequencyRHz100−327.68 … 327.67r0024
40343Output voltageRV10 … 32767r0025
40344DC link voltageRV10 … 32767r0026
40345Current actual valueRA1000 … 163.83r0027
40346Actual torque valueRNm100−325.00 … 325.00r0031
40347Actual active powerRkW1000 … 327.67r0032

The Standard FB

The block does four things: build the control word from Run, Rev and AckFlt, scale the speed setpoint, decode ZSW1 into bits, and scale the four measured values. It takes and returns arrays, so it never knows which network delivered them.

SectionNameTypeMeaning
InputRunBoolRun command from the machine sequence
InputRevBoolReverse, where the mechanics allow it
InputAckFltBoolFault acknowledge — a short pulse, not a level
InputSet_RPMRealSpeed setpoint in rpm
InputTransportInt0 = PROFINET telegram 20, 1 = Modbus RTU — selects the scaling rule
InputRef_SpeedRealp2000 reference speed
InputRef_CurrentRealp2002 reference current (PROFINET scaling only)
InputRef_TorqueRealp2003 reference torque (PROFINET scaling only)
InputRef_PowerRealr2004 reference power (PROFINET scaling only)
InputSWArray[0..5] of IntThe six status words, whatever brought them in
OutputCWArray[0..1] of WordControl word and speed setpoint, ready to send
OutputReady / Running / Fault / WarningBoolDecoded from ZSW1
OutputSpeed_rpm / Current_A / Torque_Nm / Power_kWRealEngineering values
StaticAckPulse, RestartLockBoolEdge handling and restart interlock
TemptmpRealRealUsed by the scaling conversions
Network 9: Call the drive block — the same call on PROFINET or Modbus
%DB20"DB_Conv1"FB_Drive_2x6"FB_Drive_2x6"ENENORun"Conv1_Run"RevFALSEAckFlt"Conv1_Ack_Pulse"Set_RPM"HMI_Conv1_SetRPM"Transport1 // 0 = PROFINET, 1 = ModbusRef_Speed1500.0 // p2000Ref_Current5.5 // p2002Ref_Torque35.0 // p2003Ref_Power7.5 // r2004SW"DB_Drive".SWCW"DB_Drive".CWReady"Conv1_Ready"Running"Conv1_Running"Fault"Conv1_Fault"Warning"Conv1_Warning"Speed_rpm"Conv1_Speed"Current_A"Conv1_Current"Torque_Nm"Conv1_Torque"Power_kW"Conv1_Power"

The control word it builds is the familiar STW1 pattern — 16#047E ready, 16#047F running, bit 7 pulsed to acknowledge. See Siemens G120 STW1 and ZSW1 bits, or drive it yourself in the Live PLC–VFD Simulator.

Scaling Rules for Both Transports

This is the one place the two networks really differ, and it is why the FB has a Transport input rather than two separate blocks.

ValuePROFINET (telegram 20)Modbus RTU
SpeedSW[1] / 16384.0 * Ref_SpeedSW[1] — already rpm
CurrentSW[2] / 16384.0 * Ref_CurrentSW[2] / 100.0
TorqueSW[3] / 16384.0 * Ref_TorqueSW[3] / 100.0
PowerSW[4] / 16384.0 * Ref_PowerSW[4] / 100.0
Setpoint outSet_RPM / Ref_Speed * 16384Same formula

On Modbus, speed arrives in rpm and needs no conversion at all, while current, torque and power are multiplied by 100. On PROFINET every value is normalised, so each needs its own reference parameter. Get the two branches right once inside the block and no application program ever has to think about it again.

MB_COMM_LOAD and MB_MASTER

MB_COMM_LOAD configures the port and links it to the master; call it once on the first scan. MB_MASTER sends one request, and MODE together with DATA_ADDR selects the function code.

MB_MASTER: MODE plus DATA_ADDR decide the function codeMODEDATA_ADDRFUNCTION CODEMEANING000001 – 09999FC 01Read coils010001 – 19999FC 02Read discrete inputs030001 – 39999FC 04Read input registers040001 – 49999FC 03Read holding registers100001 – 09999FC 05 / 15Write coil(s)140001 – 49999FC 06 / 16Write holding register(s)200001 / 40001 …FC 15 / 16Always multiple writeSiemens uses the documented 4xxxx numbering, so DATA_ADDR 40110 really is register 40110 — the instruction handles the offset.
Read or write is MODE; the register range in DATA_ADDR does the rest.
Step bitMODEDATA_ADDRDATA_LENTarget arrayFunction codeNext step
Step[1]1 write401002"DB_Drive".CWFC 16Step[2]
Step[2]0 read401102"DB_Drive".Raw110FC 03Step[3]
Step[3]0 read403408"DB_Drive".Raw340FC 03Step[1]
TagData typePurpose
"Modbus".StepArray[1..3] of BoolOne bit per job; exactly one is TRUE
"Modbus".Done / .ErrorArray[1..3] of BoolResult bits of each job
"Modbus".StatusArray[1..3] of WordSTATUS of each job, kept for diagnostics
"DB_Drive".CWArray[0..1] of WordControl word and setpoint, written by the FB
"DB_Drive".Raw110Array[0..1] of IntRaw read of 40110 – 40111
"DB_Drive".Raw340Array[0..7] of IntRaw read of 40340 – 40347
"DB_Drive".SWArray[0..5] of IntThe six status words handed to the FB

The Ladder: Three Jobs and the Mapping

One bit per job in an array, "Modbus".Step[1..3]. The bit enables its MB_MASTER network and drives its REQ; the hand-over rung sets the next bit and resets its own on DONE or ERROR.

Three jobs, chained by step bitsStep[1]write 40100, 2control word + setpointDONE / ERRORStep[2]read 40110, 2status wordDONE / ERRORStep[3]read 40340, 8measured valuesafter the last job the chain sets Step[1] again
Write, read status, read measurements — then back to the start.

Modbus transport — six networks

Network 1: Load the RS-485 port once at start-up
%DB10"MB_COMM_LOAD_DB"MB_COMM_LOAD"MB_COMM_LOAD""FirstScan"ENENOREQTRUEPORT"Local~CB_1241_(RS485)"BAUD19200PARITY2FLOW_CTRL0RTS_ON_DLY0RTS_OFF_DLY0RESP_TO1000MB_DB"MB_MASTER_DB".MB_DBDONE"Modbus".PortDoneERROR"Modbus".PortErrorSTATUS"Modbus".PortStatus
Network 2: First scan — start the chain at step 1
"FirstScan""Modbus".Step[1]S
Network 3: Step 1 — write the two control words (40100 – 40101)
%DB11"MB_MASTER_DB"MB_MASTER"MB_MASTER""Modbus".Step[1]ENENOREQ"Modbus".Step[1]MB_ADDR1MODE1DATA_ADDR40100DATA_LEN2DATA_PTR"DB_Drive".CWDONE"Modbus".Done[1]BUSY"Modbus".BusyERROR"Modbus".Error[1]STATUS"Modbus".Status[1]
Network 4: Step 1 done or error → set step 2, reset step 1
"Modbus".Done[1]"Modbus".Error[1]"Modbus".Step[2]S"Modbus".Step[1]R
Network 5: Step 2 — read the status word (40110 – 40111)
%DB11"MB_MASTER_DB"MB_MASTER"MB_MASTER""Modbus".Step[2]ENENOREQ"Modbus".Step[2]MB_ADDR1MODE0DATA_ADDR40110DATA_LEN2DATA_PTR"DB_Drive".Raw110DONE"Modbus".Done[2]BUSY"Modbus".BusyERROR"Modbus".Error[2]STATUS"Modbus".Status[2]
Network 6: Step 2 done or error → set step 3, reset step 2
"Modbus".Done[2]"Modbus".Error[2]"Modbus".Step[3]S"Modbus".Step[2]R
Network 7: Step 3 — read the eight measured values (40340 – 40347)
%DB11"MB_MASTER_DB"MB_MASTER"MB_MASTER""Modbus".Step[3]ENENOREQ"Modbus".Step[3]MB_ADDR1MODE0DATA_ADDR40340DATA_LEN8DATA_PTR"DB_Drive".Raw340DONE"Modbus".Done[3]BUSY"Modbus".BusyERROR"Modbus".Error[3]STATUS"Modbus".Status[3]
Network 8: Step 3 done or error → set step 1 again, reset step 3 (cycle repeats)
"Modbus".Done[3]"Modbus".Error[3]"Modbus".Step[1]S"Modbus".Step[3]R

One more network gathers the raw registers into the array the FB expects. It is plain MOVE work, and it is the only place the Modbus register numbers appear.

Network 10: Modbus mapping — build the six status words the FB expects
MOVEINOUT1"DB_Drive".Raw110[0]"DB_Drive".SW[0]MOVEINOUT1"DB_Drive".Raw340[1]"DB_Drive".SW[1]MOVEINOUT1"DB_Drive".Raw340[5]"DB_Drive".SW[2]MOVEINOUT1"DB_Drive".Raw340[6]"DB_Drive".SW[3]MOVEINOUT1"DB_Drive".Raw340[7]"DB_Drive".SW[4]MOVEINOUT1"DB_Drive".Raw340[2]"DB_Drive".SW[5]
The same function block on either networkFB_Drive_2x6mapping + scaling + drive logicCW[0..1] out · SW[0..5] inRun · Set_RPM → Speed, Current, Torque, PowerPROFINETTelegram 20 (PZD-2/6)%QW256…258 · %IW256…266MOVE the words, or DPRD_DATModbus RTUMB_MASTER jobsMachine programHMI, interlocks, recipesOnly the transport networks change. The FB, its scaling and the machine program stay identical.
With the mapping done, the FB call is the same on either network.

The Same FB on PROFINET

Swap the drive onto PROFINET with telegram 20 and the six Modbus networks collapse into two MOVE networks. The FB call in the previous section does not change — only the Transport input goes from 1 to 0.

PROFINET transport — two networks instead

Network 1: Telegram 20: move the six input words into the same SW array
MOVEINOUT1%IW256"DB_Drive".SW[0]MOVEINOUT1%IW258"DB_Drive".SW[1]MOVEINOUT1%IW260"DB_Drive".SW[2]MOVEINOUT1%IW262"DB_Drive".SW[3]MOVEINOUT1%IW264"DB_Drive".SW[4]MOVEINOUT1%IW266"DB_Drive".SW[5]
Network 2: Telegram 20: move the two control words out
MOVEINOUT1"DB_Drive".CW[0]%QW256MOVEINOUT1"DB_Drive".CW[1]%QW258

For the telegram itself see Siemens G120 telegram selection in TIA Portal, and for a block built directly on telegram 1 see the G120 PROFINET standard FB.

Drive Parameters

Drive parameterSetsValue here
p2030Fieldbus protocolModbus RTU
p2021Modbus slave address1
p2020Baud rate19200
p2040Fieldbus monitoring timeLonger than the worst-case polling cycle
p2000Reference speedMust equal Ref_Speed in the FB
p2002 / p2003 / r2004Reference current, torque, powerOnly used by the PROFINET scaling branch
p0922Telegram (PROFINET)20 — PZD-2/6

Build this block on real hardware

Wire the RS-485 line, commission a G120 on Modbus RTU, then move the same block onto PROFINET. Pune classroom or live online.

Book a Free Demo Class

Common Faults

SymptomLikely causeFix
Every job times outBaud, parity or A/B swapped; wrong PORT constantMatch the drive settings; swap A and B once as a test
Jobs work, then stop after minutesMissing bias or termination, or a stub in the cableJumper TA–T/RA and TB–T/RB at the CB, terminate the far end
Speed reads right, current and torque are 100× outScaling branch wrong for the transportCheck the Transport input: 0 for PROFINET, 1 for Modbus
Torque always positiveRaw register read into a Word instead of an IntSigned values need Int
Values one register outRegister numbering confusionWith MB_MASTER use the documented number — 40340, not 40339
The drive trips on communication failurePolling slower than p2040Shorten the cycle or lengthen p2040
Everything works on Modbus but not on PROFINETTelegram is not 20, or the I/Q addresses movedSet p0922 = 20 and re-read the Device overview

Step-by-Step Lab: One Block, Two Networks

Hands-on
Before you start
  • An S7-1215C with a CB 1241 (RS485) and a G120 with both an RS-485 port and PROFINET.
  • A motor on a test bench, and the drive's fieldbus manual for the register list.
  • Estimated time: 90 minutes.
1

Wire and terminate

Daisy chain A, B and common from the CB 1241 to the drive. Jumper TA–T/RA and TB–T/RB, terminator on at the drive.

On screen: the CB 1241 terminal strip with both jumpers fitted.
Continuity on all three cores, shield earthed at one end only.
2

Set the drive

p2030 to Modbus RTU, p2021 = 1, p2020 = 19200, and note p2000.

The drive shows its address and baud rate, and p2000 matches what you will put in Ref_Speed.
3

Build the arrays

Create DB_Drive as a standard block with CW, Raw110, Raw340 and SW, and the Modbus step arrays.

Compiling gives no pointer errors — DATA_PTR needs a non-optimised block.
4

Run the step chain

Add MB_COMM_LOAD and the three jobs with their hand-over rungs.

All three Done bits pulse in turn and Raw340 fills with plausible numbers.
5

Map and call the FB

Add the MOVE network, then call FB_Drive_2x6 with Transport = 1.

Speed shows rpm, current shows amps with two decimals, torque is signed.
6

Check the scaling against reality

Run at half speed and compare Current_A with a clamp meter.

The reading matches. If it is 100 times out, the Transport input is wrong.
7

Move to PROFINET

Set p0922 = 20, configure the telegram, replace the six Modbus networks with the two MOVE networks and set Transport = 0.

The same FB, the same HMI values — only the transport changed.
Checkpoint — how to know you did it right

You have it if the drive runs identically on both networks, the four engineering values read correctly on each, and the only edit between them was the transport networks and one input.

Frequently asked questions

Why use Standard Telegram 20 as the reference?

Telegram 20 is PZD-2/6 — two words out, six words in. The two out are the control word and the speed setpoint; the six in are status, speed, current, torque, power and a message word. That is exactly the data a machine program needs from a drive, and it maps cleanly onto Modbus registers, so one function block can serve both networks.

How can the same FB work on PROFINET and on Modbus RTU?

The FB never touches the network. It takes six status words in an array and returns two control words in another array, and a Transport input tells it which scaling rule to apply. On PROFINET two MOVE networks copy the telegram words in and out; on Modbus a step chain of MB_MASTER jobs does the same thing. The machine program above the FB is identical either way.

Why does the scaling differ between the two networks?

PROFINET sends normalised values: 16#4000 means 100 % of a reference parameter, so current is scaled against p2002 and torque against p2003. The Modbus register map sends engineering values already multiplied by a fixed factor — 100 for current, torque, power and frequency, and 1 for speed in rpm.

Which Modbus registers give the six status values?

40110 for the status word, 40341 for actual speed, 40345 for current, 40346 for torque, 40347 for active power, and 40342 for output frequency in place of the PROFINET message word. Registers 40340 to 40347 are a continuous block, so one read of eight registers covers five of them.

How does the step chain move from one job to the next?

Each job has a bit in an array, Step[1] to Step[3]. That bit enables the job's MB_MASTER network and drives its REQ. A hand-over rung watches the job's DONE and ERROR bits and, when either appears, sets the next step bit and resets its own. After the last job it sets Step[1] again.

What happens if the drive stops answering?

MB_MASTER reports ERROR after the response timeout, and the hand-over rung treats ERROR like DONE, so the chain keeps running. Status[n] keeps the reason for that job, and the FB should hold the drive outputs at a safe state while no fresh status word arrives.

Can I add a second drive to the same line?

Yes. Give it a different slave address, add three more steps to the chain with their own DATA_PTR arrays, and call a second instance of the FB. The FB itself does not change — only the transport networks grow.

Do I still need the STW1 and ZSW1 bit knowledge?

Yes. The control word the FB builds is the same STW1 pattern — 16#047E ready, 16#047F running — and Ready, Running, Fault and Warning are decoded from ZSW1 bits. Only the delivery changes between the two networks.

Reviewed by Bhawesh Kumar Singh Industrial Automation Trainer and Industry 4.0 Consultant · Softwell Automation · 21+ years industry experience

Get the full syllabus + free demo class

Share your details — a Softwell training advisor will call you within 24 hours with batch dates, fees and hardware access options.

No spam. Used only to share course details for this enquiry.

Learn with practical industrial examples

Join live online, Pune classroom or corporate in-plant automation training.

Request Course Details
Verified learning pathway

Discuss Your Automation Requirement

Get guidance for training, corporate programs, projects or technical resources.

Content reviewed: 22 September 2026

☎ Call WhatsApp ✉ Email Enquire Now