1. Problem Overview
An S7-300 station consisting of a CPU 315-2DP/PN (or comparable -2DP/-PN variant) is reading drive speed feedback from an ABB AC880 industrial drive through an SM331 analog input module, part number 6ES7331-7KF02-0AB0 (AI 8x12 Bit). The drive's analog reference output is configured for a 0 to 20 mA signal, but the operator can only see FC105 returning RET_VAL = W#16#0008 and the raw process image word (PIW) sitting at 32767 (0x7FFF), which is the over-range sentinel value for the SM331 channel.
This mismatch between drive signal type, hardware wiring, and STEP 7 hardware configuration is one of the most common field faults encountered when retrofitting legacy 4-20 mA I/O to drives that use 0-20 mA. The module is mechanically capable of measuring 0-20 mA, but only when the rear range module is in the correct slot. Selecting the wrong slot, or selecting 2-wire measurement, will produce exactly the symptoms described here.
2. Affected Hardware and Module Identification
The module in question is the SM 331, AI 8 x 12 Bit, with order number 6ES7331-7KF02-0AB0. The eight channels are organised as two groups of four. Each group of four shares a single range module inserted into a slot on the rear of the module. Removing the front cover / sub-D shell exposes two small rotary switch positions usually labelled A, B, C, D.
| Position | Measurement Type | Supported Ranges |
|---|---|---|
| A | Voltage (group-by-group) | ±10 V, ±5 V, ±2.5 V, 0 to 10 V, 0 to 5 V, 1 to 5 V |
| B | Voltage / RTD (per-channel) | ±10 V, 0 to 10 V, ±5 V, 0 to 5 V; PT100 / Ni100 (climatic range) |
| C | 4-wire current (per-channel) | 0 to 20 mA, 4 to 20 mA |
| D | 2-wire current (per-channel, loop-powered from module) | 4 to 20 mA only |
Notice the key constraint: the module only supports 0 to 20 mA on position C, in 4-wire mode. If you require 0 to 20 mA into this SM331, position C is the only valid selection, and the transmitter must either be self-powered or be supplied by an external 24 V source. Position D only supports 4 to 20 mA because the internal current sink can only source the loop power for a 4 mA pre-bias on a working 4-20 mA transmitter; there is no equivalent pre-bias support for a 0-20 mA loop.
Drive side, the ABB ACS880 / AC880 family industrial drive provides configurable analog outputs that can be programmed as either 0 to 20 mA or 4 to 20 mA via parameter group 14 (or the equivalent firmware menu, depending on firmware version). The drive hardware itself does not care whether the receiver is wired as 2-wire or 4-wire - the 2-wire / 4-wire distinction is a property of the receiver side and the wiring harness.
3. Root Cause Analysis
The two observed symptoms trace back to a single mechanical configuration problem on the SM331.
3.1 Symptom A - PIW = 32767 (0x7FFF)
The SM331 returns 0x7FFF in the process image when the raw input signal is below the negative over-range or above the positive over-range of the configured span. The configured span is taken from both the HW Config measurement type and the rear range module position. If either is wrong, the ADC ends up looking at the wrong shunt resistor, and 0 mA signal current shows up either as 0x7FFF or 0x8000 on the process image.
Reading 32767 with the drive outputting a perfectly valid 4 mA signal in this case indicates that the range module is currently in position D (2-wire), but the wiring is not configured as 2-wire, or the range module is in position A / B (voltage), so the channel is looking at the wrong resistor divider and the input current is saturating the voltage range rail.
3.2 Symptom B - FC105 RET_VAL = W#16#0008
FC105 (SCALE) returns W#16#0008 when its IN parameter is either greater than 27648 (positive over-range) or less than 0 (negative over-range / open wire). Since the SCALE block passes the raw PIW into IN, an over-range PIW (32767) is reported as FC105 error 0008. The drive is fine. The PLC scan is fine. The fault is structural.
| RET_VAL (W#16#...) | Meaning | Typical Cause |
|---|---|---|
| 0000 | No error | Normal execution |
| 0007 | Invalid range input | HI_LIM ≤ LO_LIM or bipolar required by range card not honoured |
| 0008 | Input value out of range | IN > 27648 or IN < 0 (over-range / open wire) |
| 0009 | Bipolar range not configured | BIPOLAR input set but range card is unipolar |
| 000A | LO_LIM / HI_LIM out of integer range | Limits not in -32768..32767 |
4. 2-Wire vs 4-Wire Current Topology
Understanding the difference between 2-wire and 4-wire transmitters is essential before touching the wiring or the range module. The terms describe the number of conductors that carry both power and signal:
4.1 2-Wire (Loop-Powered) Transmitter
The transmitter is powered by the analog input module over the same two wires that carry the current signal. The receiver (SM331 in position D) sources 24 V through the input terminals and regulates the loop current. The transmitter and receiver share both power and signal wires.
4.2 4-Wire (Self-Powered) Transmitter
The transmitter has its own dedicated 24 V supply (often drawn from the drive's control terminals or from a separate power supply). Two wires carry only the current signal, returning to the SM331 over a separate pair of terminals. With this topology, the SM331 is set to position C and supports both 0-20 mA and 4-20 mA.
4.3 Which to Use with This Drive?
The drive is sometimes called "2-wire" colloquially because the drive terminals present a passive analog output. That does not mean the SM331 channel must be configured as 2-wire / position D. Because the AC880 supports 0-20 mA and the SM331 only accepts 0-20 mA on the 4-wire range (position C), the only correct configuration is:
- Drive side: any topology that exposes the 0-20 mA signal on two terminals with a common return.
- SM331: 4-wire measurement, range module position C.
- External 24 V: supplied to the drive output stage from the drive itself or a dedicated power supply.
5. STEP 7 Hardware Configuration
Open the hardware configuration (HW Config in STEP 7 V5.x, or Device Configuration in TIA Portal) and locate the SM331 module on the rail. Double-click the slot to open the Properties dialog, then go to Inputs. Set each channel used by the drive feedback to the following:
| Property | Setting | Notes |
|---|---|---|
| Measurement type | 4-wire current (4DMU / "I 4-wire" in TIA) | Not "2-wire" / "U" |
| Measuring range | 0 to 20 mA | Only available with measurement type above |
| Diagnostics | Enable group diagnostics for overflow / underflow | Optional but recommended |
| Smoothing | None, weak, medium, strong | Weak or medium is typical for speed display |
Save, then download the hardware configuration to the CPU. STEP 7 rewrites the diagnostic buffer with event "Hardware updated by STEP 7".
6. Range Module Physical Switch Setting
Even if HW Config says "4-wire current 0-20 mA", the SM331 will not convert correctly unless the rear range module is mechanically in position C. The following physical switch setting is the one that drives in this scenario must select:
- De-energise the S7-300 station. Remove the front connector / sub-D shell from the SM331 module.
- Locate the small rotary switch on the rear of the module. Each group of four channels has its own switch; the group that contains the speed feedback channel must be set.
- Use a small flat-blade screwdriver to rotate the switch so the arrow / letter points to C.
- If both groups have channels in use, confirm both switches are in C.
- Reinstall the front connector. Restore power.
7. FC105 Scaling Configuration
With the hardware configured and the input reading a clean 0-27648 mW mapped signal, FC105 (SCALE) is called to map the raw integer to engineering units. For a 0 to 20 mA speed feedback where 0 mA = 0 rpm and 20 mA = 1500 rpm, the FC105 call is:
CALL FC 105
IN := PIW 304 // raw input from SM331 channel 0, group 0
LO_LIM := 0.0 // engineering value at 0 mA
HI_LIM := 1500.0 // engineering value at 20 mA
BIPOLAR := FALSE // 0-20 mA is unipolar
RET_VAL := MW 100 // store FC105 error code
OUT := MD 200 // engineering units (REAL)
7.1 Why BIPOLAR Must Be FALSE
A 0-20 mA signal occupies only the positive half of the converter's bipolar range. Setting BIPOLAR := TRUE would double the apparent resolution without giving any extra information and would also lift the integer zero point to a non-integer boundary. With the AC880 0-20 mA output, leave BIPOLAR off and treat the raw integer as 0-27648 unipolar.
7.2 Bipolar Note for 4-20 mA Applications
If the field application is changed to 4-20 mA (still on position C of the range module), the scaling changes:
- Integer 0 corresponds to 4 mA (4 mA is the integer offset).
- 4 mA = 0 engineering units (typically 0 rpm or live-zero scale).
- 20 mA = 27648 = HI_LIM.
- A reading of 0 or below is indicative of an open wire.
Open-wire detection on 4-20 mA is a useful diagnostic and is one reason industrial standards favour 4-20 mA over 0-20 mA for new installations.
8. FC105 RET_VAL Error Code Reference
The error code returned into the RET_VAL output of FC105 is a compact diagnostics channel. The codes most relevant to this application are listed below; reference the Siemens "Standard Functions" manual for the complete table.
| RET_VAL (hex) | Decimal | Meaning | Action |
|---|---|---|---|
| W#16#0000 | 0 | No error | Proceed, OUT is valid |
| W#16#0007 | 7 | BIPOLAR requested but range card is unipolar | Set BIPOLAR := FALSE for 0-20 mA / 4-20 mA |
| W#16#0008 | 8 | IN out of range (over / under) | Check PIW; over-range equals 32767; under-range equals 0 with diagnostic interrupt |
| W#16#0009 | 9 | Invalid bipolar setting for the active hardware | Verify HW Config and FC105 argument align |
| W#16#000A | 10 | LO_LIM or HI_LIM outside integer range | Re-check FC105 limits |
A persistent W#16#0008 with the in-station hardware in position C almost always means the rear range module and the HW Config measurement type still disagree.
9. HMI Display Wiring
Once FC105 writes a clean REAL into MD 200, the HMI tag should reference MD 200 (or a copy in a global DB) and convert it to engineering units on display:
| Field | Setting |
|---|---|
| PLC Tag | "Drive_Speed_Actual" = MD200 (REAL) |
| Number Format | Floating-point, 0 decimals or 1 decimal |
| Display Limits | 0 to 1500 rpm |
| Alarm Limits | Low 0 (live-zero check on 4-20 mA), High 1600 |
9.1 Watchdog Tag for FC105 Error
For predictive maintenance, expose MW100 (the FC105 RET_VAL) to the HMI as well, masked against W#16#0008. A persistent non-zero RET_VAL indicates that the FC105 call is misconfigured or that the PIW is in over-range. Either symptom should be alarmed at HMI level.
10. Verification Procedure
Confirm the fix on the running machine using the following ordered checks. Capture diagnostic buffer entries at each step.
- Verify range module position. Look at the SM331 rear slot. The letter exposed should be "C" for the relevant group.
- Verify HW Config. In STEP 7 or TIA Portal, double-click the module and confirm "Measuring type = 4-wire current" and "Measuring range = 0 to 20 mA".
- Monitor the PIW online. In a watch table (VAT), force the drive to 0 mA. Expected PIW = 0.
- Force the drive to 20 mA. Expected PIW ≈ 27648 (or 27646-27649 depending on converter linearity).
- Force the drive to 4 mA. On 0-20 mA this should give PIW ≈ 5529. On 4-20 mA it should give PIW ≈ 0 plus instrument error.
- Check FC105 RET_VAL. With the drive at any mid-scale current (e.g. 10 mA), FC105 RET_VAL should be W#16#0000.
- Verify HMI value. Confirm the HMI numeric field shows the engineering value, e.g. 750 rpm at 10 mA on a 0-1500 rpm scale.
- Disconnect the signal lead. Trigger diagnostic interrupt by pulling the signal terminal. Confirm "Analog input wire break" appears in the diagnostic buffer with the expected slot and channel.
11. Common Field Pitfalls
Even after the range module is correctly set, certain common mistakes show up repeatedly on site:
| Pitfall | Symptom | Fix |
|---|---|---|
| Wired as 2-wire, configured in HW Config as "U 0-10 V" (range module still in A / B) | PIW = 32767, FC105 returns 0008 | Set range module to A with HW Config "U 0-10 V"; or change wiring to 4-wire and use position C |
| Range module in D (loop-powered 2-wire), drive hardwired for 0 mA at standstill | PIW sits at 7FFF because no loop power is present | Either restore the 2-wire loop power, or move the range module to C and bring 24 V to the drive output |
| Range module not in any labelled position (in between two letters) | PIW fluctuates with the slightest vibration; FC105 RET_VAL pulses non-zero | Re-seat the switch firmly in C |
| Shared analog common not pulled to earth ground per local code | PIW noisy, HMI flicker | Add a single-point ground reference for the analog shield |
| BIPOLAR := TRUE on a unipolar 0-20 mA signal | FC105 RET_VAL = W#16#0009 intermittently | Set BIPOLAR := FALSE |
| FC105 IN fed from PIW of the wrong channel | Scaled value follows the wrong physical input | Re-check the slot-to-channel mapping; for module start address 256, channel 0 is PIW 256, channel 1 is PIW 258, etc. |
12. Related Manual References
For further details, consult the primary Siemens documentation for the AI module and for the AC880 drive. The current versions are maintained on the Siemens and ABB product support portals:
- S7-300 SM331 Analog Input Module Manual (6ES7331-7KF02-0AB0)
- Siemens Industry Online Support for the latest HSP packages for STEP 7 / TIA Portal
- ABB Library - ACS880 / AC880 Drive Firmware Manuals for analog output configuration parameter groups
13. Frequently Asked Questions
Why does FC105 return W#16#0008 even when the drive is OK?
FC105 returns W#16#0008 when its IN parameter is greater than 27648 or less than 0. With the SM331, an over-range condition produces a PIW of 32767. If the range module is mechanically in position D (2-wire) or A / B (voltage) but HW Config is set to "4-wire current 0-20 mA", the channel is reading through the wrong shunt and the PIW immediately saturates to 7FFF, which FC105 reports as W#16#0008. Move the range module to position C to clear the error.
Can the SM331 6ES7331-7KF02-0AB0 read 0-20 mA in 2-wire mode?
No. Position D of the range module on this SM331 only supports 4 to 20 mA in 2-wire (loop-powered) mode. To read 0 to 20 mA, use position C with the transmitter self-powered (4-wire configuration in HW Config).
What is the difference between 2-wire and 4-wire transmitters in this context?
A 2-wire transmitter carries power and signal on the same two conductors and is powered by the analog input module. A 4-wire transmitter has a separate power supply and uses two dedicated conductors for the analog signal. With the AC880 drive, you can wire either topology. Choose 4-wire if you need 0-20 mA on this SM331.
How do I check which range module position the SM331 is in?
Remove the front connector from the SM331 module on the S7-300. The two small lettered indicators (one per group of 4 channels) are visible on the back of the module near the DIN-rail latch. Confirm with the cover schematic diagram in the module manual before re-energising the station.
What scaling limits should I use in FC105 for a 0-1500 rpm drive feedback?
For a 0-20 mA signal corresponding to 0-1500 rpm, set LO_LIM := 0.0, HI_LIM := 1500.0, and BIPOLAR := FALSE. If the system is changed to 4-20 mA live-zero, the same integer count now corresponds to 4-1500 rpm, so LO_LIM becomes the speed equivalent of 4 mA (which may be non-zero for some drive parameter assignments) and HI_LIM becomes the speed equivalent of 20 mA.