Take Standard Telegram 20 (PZD-2/6) as the data model: two words written — control word and speed setpoint — and six words read — status, speed, current, torque, power and a message word. Write one function block, FB_Drive_2x6, that takes SW[0..5] in and returns CW[0..1] out, with a Transport input that switches the scaling rule. On Modbus RTU a three-step MB_MASTER chain fills those arrays from registers 40100, 40110 and 40340–40347; on PROFINET two MOVE networks fill them from the telegram. The FB, and everything above it, stays identical.
- Two words out, six words in — the same shape on either network.
- The FB never touches the network; only the transport networks differ.
- PROFINET sends normalised values against p2000/p2002/p2003; Modbus sends fixed factors of 1 or 100.
- One step bit per job, handed over on DONE or ERROR.
Hardware and Wiring
One master, one drive. The CB 1241 clips into the communication board slot on the front of the CPU, and the line is a shielded twisted pair plus a core for signal common — leaving the common out is a classic cause of intermittent faults.
| Item | Used here | Notes |
|---|---|---|
| CPU | S7-1215C DC/DC/DC | Any S7-1200 with a free CB slot works the same way |
| Serial interface | CB 1241 (RS485) | Fits the communication board slot on the front of the CPU; a CM 1241 (RS485) behaves the same in the program |
| Drive | SINAMICS G120 with an RS-485 capable control unit | Slave address 1 |
| Cable | Shielded twisted pair plus a core for signal common | Daisy chained, terminated at both ends |
| Software | TIA Portal | The Modbus instructions are in the standard library |
The CB 1241 has bias and termination resistors on board; you switch them in by jumpering TA to T/RA and TB to T/RB.
Line Settings and TIA Configuration
| Setting | Value here | Why |
|---|---|---|
| Baud rate | 19200 | Fast enough for one drive and tolerant of long cable |
| Data bits | 8 | Fixed by the Modbus RTU standard |
| Parity | Even | The Modbus default — the drive must match |
| Stop bits | 1 with parity, 2 without | The standard pairs them; the instruction follows your parity choice |
| Flow control | None | Half duplex, direction handled by the module |
| Response timeout | 1000 ms | How long MB_MASTER waits before reporting ERROR |
| Step | Where in TIA Portal | What to do |
|---|---|---|
| 1 | Device view of the CPU | Drag CB 1241 (RS485) into the CB slot of the S7-1215C |
| 2 | CB properties → Port configuration | Set baud rate and parity |
| 3 | CPU properties → System constants | Note the port hardware identifier, e.g. Local~CB_1241_(RS485) |
| 4 | Program blocks | Create DB_Drive as a standard (non-optimised) block — DATA_PTR needs it |
| 5 | Start-up OB | Call MB_COMM_LOAD once |
| 6 | OB1 | Call the Modbus step chain, the mapping network and FB_Drive_2x6 |
| 7 | Online | Watch DONE, ERROR and STATUS per step, then the scaled values |
Why Telegram 20 Is the Reference
Telegram 20 is PZD-2/6: two process-data words to the drive and six back. It carries everything a machine program normally wants — run and speed out, and status, speed, current, torque, power and a message word back — without the extra words a longer telegram would add.
That shape also survives the move to Modbus. The same six values exist as registers, so if the program is written against a two-in, six-out interface, the network underneath becomes an implementation detail.
Mapping: Telegram 20 to Modbus Registers
| PZD | Telegram 20 signal | Modbus register | FB pin | PROFINET scaling | Modbus scaling |
|---|---|---|---|---|---|
| PZD1 | ZSW1 — status word | 40110 | SW[0] | Bit field | Bit field |
| PZD2 | NIST_A — actual speed | 40341 | SW[1] | 16#4000 = p2000 | rpm, factor 1 |
| PZD3 | IAIST — actual current | 40345 | SW[2] | 16#4000 = p2002 | A, factor 100 |
| PZD4 | MIST — actual torque | 40346 | SW[3] | 16#4000 = p2003 | Nm, factor 100 |
| PZD5 | PIST — active power | 40347 | SW[4] | 16#4000 = r2004 | kW, factor 100 |
| PZD6 | MELD_NAMUR (PN) / output frequency (Modbus) | 40342 | SW[5] | Bit field | Hz, factor 100 |
| OUT 1 | STW1 — control word | 40100 | CW[0] | Bit field | Bit field |
| OUT 2 | NSOLL_A — speed setpoint | 40101 | CW[1] | 16#4000 = p2000 | 16#4000 = p2000 |
Only PZD6 has no exact Modbus equivalent. The PROFINET message word is a bit field; on Modbus the nearest useful value is output frequency in 40342, so the FB treats SW[5] according to the Transport input. The underlying register list from the drive's fieldbus manual is below.
| Register | Description | Access | Unit | Scaling | Value range | Parameter |
|---|---|---|---|---|---|---|
| 40340 | Speed setpoint | R | rpm | 1 | −16250 … 16250 | r0020 |
| 40341 | Actual speed value | R | rpm | 1 | −16250 … 16250 | r0022 |
| 40342 | Output frequency | R | Hz | 100 | −327.68 … 327.67 | r0024 |
| 40343 | Output voltage | R | V | 1 | 0 … 32767 | r0025 |
| 40344 | DC link voltage | R | V | 1 | 0 … 32767 | r0026 |
| 40345 | Current actual value | R | A | 100 | 0 … 163.83 | r0027 |
| 40346 | Actual torque value | R | Nm | 100 | −325.00 … 325.00 | r0031 |
| 40347 | Actual active power | R | kW | 100 | 0 … 327.67 | r0032 |
The Standard FB
The block does four things: build the control word from Run, Rev and AckFlt, scale the speed setpoint, decode ZSW1 into bits, and scale the four measured values. It takes and returns arrays, so it never knows which network delivered them.
| Section | Name | Type | Meaning |
|---|---|---|---|
| Input | Run | Bool | Run command from the machine sequence |
| Input | Rev | Bool | Reverse, where the mechanics allow it |
| Input | AckFlt | Bool | Fault acknowledge — a short pulse, not a level |
| Input | Set_RPM | Real | Speed setpoint in rpm |
| Input | Transport | Int | 0 = PROFINET telegram 20, 1 = Modbus RTU — selects the scaling rule |
| Input | Ref_Speed | Real | p2000 reference speed |
| Input | Ref_Current | Real | p2002 reference current (PROFINET scaling only) |
| Input | Ref_Torque | Real | p2003 reference torque (PROFINET scaling only) |
| Input | Ref_Power | Real | r2004 reference power (PROFINET scaling only) |
| Input | SW | Array[0..5] of Int | The six status words, whatever brought them in |
| Output | CW | Array[0..1] of Word | Control word and speed setpoint, ready to send |
| Output | Ready / Running / Fault / Warning | Bool | Decoded from ZSW1 |
| Output | Speed_rpm / Current_A / Torque_Nm / Power_kW | Real | Engineering values |
| Static | AckPulse, RestartLock | Bool | Edge handling and restart interlock |
| Temp | tmpReal | Real | Used by the scaling conversions |
The control word it builds is the familiar STW1 pattern — 16#047E ready, 16#047F running, bit 7 pulsed to acknowledge. See Siemens G120 STW1 and ZSW1 bits, or drive it yourself in the Live PLC–VFD Simulator.
Scaling Rules for Both Transports
This is the one place the two networks really differ, and it is why the FB has a Transport input rather than two separate blocks.
| Value | PROFINET (telegram 20) | Modbus RTU |
|---|---|---|
| Speed | SW[1] / 16384.0 * Ref_Speed | SW[1] — already rpm |
| Current | SW[2] / 16384.0 * Ref_Current | SW[2] / 100.0 |
| Torque | SW[3] / 16384.0 * Ref_Torque | SW[3] / 100.0 |
| Power | SW[4] / 16384.0 * Ref_Power | SW[4] / 100.0 |
| Setpoint out | Set_RPM / Ref_Speed * 16384 | Same formula |
On Modbus, speed arrives in rpm and needs no conversion at all, while current, torque and power are multiplied by 100. On PROFINET every value is normalised, so each needs its own reference parameter. Get the two branches right once inside the block and no application program ever has to think about it again.
MB_COMM_LOAD and MB_MASTER
MB_COMM_LOAD configures the port and links it to the master; call it once on the first scan. MB_MASTER sends one request, and MODE together with DATA_ADDR selects the function code.
| Step bit | MODE | DATA_ADDR | DATA_LEN | Target array | Function code | Next step |
|---|---|---|---|---|---|---|
Step[1] | 1 write | 40100 | 2 | "DB_Drive".CW | FC 16 | Step[2] |
Step[2] | 0 read | 40110 | 2 | "DB_Drive".Raw110 | FC 03 | Step[3] |
Step[3] | 0 read | 40340 | 8 | "DB_Drive".Raw340 | FC 03 | Step[1] |
| Tag | Data type | Purpose |
|---|---|---|
"Modbus".Step | Array[1..3] of Bool | One bit per job; exactly one is TRUE |
"Modbus".Done / .Error | Array[1..3] of Bool | Result bits of each job |
"Modbus".Status | Array[1..3] of Word | STATUS of each job, kept for diagnostics |
"DB_Drive".CW | Array[0..1] of Word | Control word and setpoint, written by the FB |
"DB_Drive".Raw110 | Array[0..1] of Int | Raw read of 40110 – 40111 |
"DB_Drive".Raw340 | Array[0..7] of Int | Raw read of 40340 – 40347 |
"DB_Drive".SW | Array[0..5] of Int | The six status words handed to the FB |
The Ladder: Three Jobs and the Mapping
One bit per job in an array, "Modbus".Step[1..3]. The bit enables its MB_MASTER network and drives its REQ; the hand-over rung sets the next bit and resets its own on DONE or ERROR.
Modbus transport — six networks
One more network gathers the raw registers into the array the FB expects. It is plain MOVE work, and it is the only place the Modbus register numbers appear.
The Same FB on PROFINET
Swap the drive onto PROFINET with telegram 20 and the six Modbus networks collapse into two MOVE networks. The FB call in the previous section does not change — only the Transport input goes from 1 to 0.
PROFINET transport — two networks instead
For the telegram itself see Siemens G120 telegram selection in TIA Portal, and for a block built directly on telegram 1 see the G120 PROFINET standard FB.
Drive Parameters
| Drive parameter | Sets | Value here |
|---|---|---|
p2030 | Fieldbus protocol | Modbus RTU |
p2021 | Modbus slave address | 1 |
p2020 | Baud rate | 19200 |
p2040 | Fieldbus monitoring time | Longer than the worst-case polling cycle |
p2000 | Reference speed | Must equal Ref_Speed in the FB |
p2002 / p2003 / r2004 | Reference current, torque, power | Only used by the PROFINET scaling branch |
p0922 | Telegram (PROFINET) | 20 — PZD-2/6 |
Build this block on real hardware
Wire the RS-485 line, commission a G120 on Modbus RTU, then move the same block onto PROFINET. Pune classroom or live online.
Common Faults
| Symptom | Likely cause | Fix |
|---|---|---|
| Every job times out | Baud, parity or A/B swapped; wrong PORT constant | Match the drive settings; swap A and B once as a test |
| Jobs work, then stop after minutes | Missing bias or termination, or a stub in the cable | Jumper TA–T/RA and TB–T/RB at the CB, terminate the far end |
| Speed reads right, current and torque are 100× out | Scaling branch wrong for the transport | Check the Transport input: 0 for PROFINET, 1 for Modbus |
| Torque always positive | Raw register read into a Word instead of an Int | Signed values need Int |
| Values one register out | Register numbering confusion | With MB_MASTER use the documented number — 40340, not 40339 |
| The drive trips on communication failure | Polling slower than p2040 | Shorten the cycle or lengthen p2040 |
| Everything works on Modbus but not on PROFINET | Telegram is not 20, or the I/Q addresses moved | Set p0922 = 20 and re-read the Device overview |
Step-by-Step Lab: One Block, Two Networks
Hands-on- An S7-1215C with a CB 1241 (RS485) and a G120 with both an RS-485 port and PROFINET.
- A motor on a test bench, and the drive's fieldbus manual for the register list.
- Estimated time: 90 minutes.
Wire and terminate
Daisy chain A, B and common from the CB 1241 to the drive. Jumper TA–T/RA and TB–T/RB, terminator on at the drive.
Set the drive
p2030 to Modbus RTU, p2021 = 1, p2020 = 19200, and note p2000.
Build the arrays
Create DB_Drive as a standard block with CW, Raw110, Raw340 and SW, and the Modbus step arrays.
Run the step chain
Add MB_COMM_LOAD and the three jobs with their hand-over rungs.
Map and call the FB
Add the MOVE network, then call FB_Drive_2x6 with Transport = 1.
Check the scaling against reality
Run at half speed and compare Current_A with a clamp meter.
Move to PROFINET
Set p0922 = 20, configure the telegram, replace the six Modbus networks with the two MOVE networks and set Transport = 0.
You have it if the drive runs identically on both networks, the four engineering values read correctly on each, and the only edit between them was the transport networks and one input.
Frequently asked questions
Why use Standard Telegram 20 as the reference?
Telegram 20 is PZD-2/6 — two words out, six words in. The two out are the control word and the speed setpoint; the six in are status, speed, current, torque, power and a message word. That is exactly the data a machine program needs from a drive, and it maps cleanly onto Modbus registers, so one function block can serve both networks.
How can the same FB work on PROFINET and on Modbus RTU?
The FB never touches the network. It takes six status words in an array and returns two control words in another array, and a Transport input tells it which scaling rule to apply. On PROFINET two MOVE networks copy the telegram words in and out; on Modbus a step chain of MB_MASTER jobs does the same thing. The machine program above the FB is identical either way.
Why does the scaling differ between the two networks?
PROFINET sends normalised values: 16#4000 means 100 % of a reference parameter, so current is scaled against p2002 and torque against p2003. The Modbus register map sends engineering values already multiplied by a fixed factor — 100 for current, torque, power and frequency, and 1 for speed in rpm.
Which Modbus registers give the six status values?
40110 for the status word, 40341 for actual speed, 40345 for current, 40346 for torque, 40347 for active power, and 40342 for output frequency in place of the PROFINET message word. Registers 40340 to 40347 are a continuous block, so one read of eight registers covers five of them.
How does the step chain move from one job to the next?
Each job has a bit in an array, Step[1] to Step[3]. That bit enables the job's MB_MASTER network and drives its REQ. A hand-over rung watches the job's DONE and ERROR bits and, when either appears, sets the next step bit and resets its own. After the last job it sets Step[1] again.
What happens if the drive stops answering?
MB_MASTER reports ERROR after the response timeout, and the hand-over rung treats ERROR like DONE, so the chain keeps running. Status[n] keeps the reason for that job, and the FB should hold the drive outputs at a safe state while no fresh status word arrives.
Can I add a second drive to the same line?
Yes. Give it a different slave address, add three more steps to the chain with their own DATA_PTR arrays, and call a second instance of the FB. The FB itself does not change — only the transport networks grow.
Do I still need the STW1 and ZSW1 bit knowledge?
Yes. The control word the FB builds is the same STW1 pattern — 16#047E ready, 16#047F running — and Ready, Running, Fault and Warning are decoded from ZSW1 bits. Only the delivery changes between the two networks.