Configuring S7-300 SM331 4-Wire Current Input for ABB AC880

David Krause15 min read
S7-300SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Overview

An S7-300 station consisting of a CPU 315-2DP/PN (or comparable -2DP/-PN variant) is reading drive speed feedback from an ABB AC880 industrial drive through an SM331 analog input module, part number 6ES7331-7KF02-0AB0 (AI 8x12 Bit). The drive's analog reference output is configured for a 0 to 20 mA signal, but the operator can only see FC105 returning RET_VAL = W#16#0008 and the raw process image word (PIW) sitting at 32767 (0x7FFF), which is the over-range sentinel value for the SM331 channel.

This mismatch between drive signal type, hardware wiring, and STEP 7 hardware configuration is one of the most common field faults encountered when retrofitting legacy 4-20 mA I/O to drives that use 0-20 mA. The module is mechanically capable of measuring 0-20 mA, but only when the rear range module is in the correct slot. Selecting the wrong slot, or selecting 2-wire measurement, will produce exactly the symptoms described here.

Safety: Before removing or reseating the range module on the SM331 backplane connector, de-energise the S7-300 station and the drive's 24 V control supply. The range module is located on the rear of the analog input module and is exposed only when the terminal block is un-plugged.

2. Affected Hardware and Module Identification

The module in question is the SM 331, AI 8 x 12 Bit, with order number 6ES7331-7KF02-0AB0. The eight channels are organised as two groups of four. Each group of four shares a single range module inserted into a slot on the rear of the module. Removing the front cover / sub-D shell exposes two small rotary switch positions usually labelled A, B, C, D.

SM331 6ES7331-7KF02-0AB0 Range Module Positions
Position Measurement Type Supported Ranges
A Voltage (group-by-group) ±10 V, ±5 V, ±2.5 V, 0 to 10 V, 0 to 5 V, 1 to 5 V
B Voltage / RTD (per-channel) ±10 V, 0 to 10 V, ±5 V, 0 to 5 V; PT100 / Ni100 (climatic range)
C 4-wire current (per-channel) 0 to 20 mA, 4 to 20 mA
D 2-wire current (per-channel, loop-powered from module) 4 to 20 mA only

Notice the key constraint: the module only supports 0 to 20 mA on position C, in 4-wire mode. If you require 0 to 20 mA into this SM331, position C is the only valid selection, and the transmitter must either be self-powered or be supplied by an external 24 V source. Position D only supports 4 to 20 mA because the internal current sink can only source the loop power for a 4 mA pre-bias on a working 4-20 mA transmitter; there is no equivalent pre-bias support for a 0-20 mA loop.

Drive side, the ABB ACS880 / AC880 family industrial drive provides configurable analog outputs that can be programmed as either 0 to 20 mA or 4 to 20 mA via parameter group 14 (or the equivalent firmware menu, depending on firmware version). The drive hardware itself does not care whether the receiver is wired as 2-wire or 4-wire - the 2-wire / 4-wire distinction is a property of the receiver side and the wiring harness.

Firmware compatibility note: the SM331 6ES7331-7KF02-0AB0 is supported by STEP 7 V5.5 and the corresponding Hardware Support Packages. In TIA Portal it appears under article number 6ES7331-7KF02-0AB0 with HSP support; refer to the Siemens product support page for the current HSP version compatible with your TIA Portal installation.

3. Root Cause Analysis

The two observed symptoms trace back to a single mechanical configuration problem on the SM331.

3.1 Symptom A - PIW = 32767 (0x7FFF)

The SM331 returns 0x7FFF in the process image when the raw input signal is below the negative over-range or above the positive over-range of the configured span. The configured span is taken from both the HW Config measurement type and the rear range module position. If either is wrong, the ADC ends up looking at the wrong shunt resistor, and 0 mA signal current shows up either as 0x7FFF or 0x8000 on the process image.

Reading 32767 with the drive outputting a perfectly valid 4 mA signal in this case indicates that the range module is currently in position D (2-wire), but the wiring is not configured as 2-wire, or the range module is in position A / B (voltage), so the channel is looking at the wrong resistor divider and the input current is saturating the voltage range rail.

3.2 Symptom B - FC105 RET_VAL = W#16#0008

FC105 (SCALE) returns W#16#0008 when its IN parameter is either greater than 27648 (positive over-range) or less than 0 (negative over-range / open wire). Since the SCALE block passes the raw PIW into IN, an over-range PIW (32767) is reported as FC105 error 0008. The drive is fine. The PLC scan is fine. The fault is structural.

FC105 RET_VAL Codes Relevant to This Fault
RET_VAL (W#16#...) Meaning Typical Cause
0000 No error Normal execution
0007 Invalid range input HI_LIM ≤ LO_LIM or bipolar required by range card not honoured
0008 Input value out of range IN > 27648 or IN < 0 (over-range / open wire)
0009 Bipolar range not configured BIPOLAR input set but range card is unipolar
000A LO_LIM / HI_LIM out of integer range Limits not in -32768..32767

4. 2-Wire vs 4-Wire Current Topology

Understanding the difference between 2-wire and 4-wire transmitters is essential before touching the wiring or the range module. The terms describe the number of conductors that carry both power and signal:

4.1 2-Wire (Loop-Powered) Transmitter

The transmitter is powered by the analog input module over the same two wires that carry the current signal. The receiver (SM331 in position D) sources 24 V through the input terminals and regulates the loop current. The transmitter and receiver share both power and signal wires.

2-Wire (Loop-Powered) Topology - SM331 Position D ABB AC880 Analog Output 0-20 mA / 4-20 mA Self-contained + Loop - Loop SM331 6ES7331-7KF02 Terminals I+, I- (4-wire term) I+, I- (2-wire term) range module = D Only 4-20 mA supported

4.2 4-Wire (Self-Powered) Transmitter

The transmitter has its own dedicated 24 V supply (often drawn from the drive's control terminals or from a separate power supply). Two wires carry only the current signal, returning to the SM331 over a separate pair of terminals. With this topology, the SM331 is set to position C and supports both 0-20 mA and 4-20 mA.

4-Wire (Self-Powered) Topology - SM331 Position C ABB AC880 Analog Output Self-powered External 24 V L+ 24 V Sig+ Sig- 250 Ω shunt SM331 6ES7331-7KF02 I+ (signal in) I- (common) Range module = C 0-20 mA & 4-20 mA both supported

4.3 Which to Use with This Drive?

The drive is sometimes called "2-wire" colloquially because the drive terminals present a passive analog output. That does not mean the SM331 channel must be configured as 2-wire / position D. Because the AC880 supports 0-20 mA and the SM331 only accepts 0-20 mA on the 4-wire range (position C), the only correct configuration is:

  1. Drive side: any topology that exposes the 0-20 mA signal on two terminals with a common return.
  2. SM331: 4-wire measurement, range module position C.
  3. External 24 V: supplied to the drive output stage from the drive itself or a dedicated power supply.

5. STEP 7 Hardware Configuration

Open the hardware configuration (HW Config in STEP 7 V5.x, or Device Configuration in TIA Portal) and locate the SM331 module on the rail. Double-click the slot to open the Properties dialog, then go to Inputs. Set each channel used by the drive feedback to the following:

HW Config Channel Properties for 0-20 mA Speed Feedback
Property Setting Notes
Measurement type 4-wire current (4DMU / "I 4-wire" in TIA) Not "2-wire" / "U"
Measuring range 0 to 20 mA Only available with measurement type above
Diagnostics Enable group diagnostics for overflow / underflow Optional but recommended
Smoothing None, weak, medium, strong Weak or medium is typical for speed display

Save, then download the hardware configuration to the CPU. STEP 7 rewrites the diagnostic buffer with event "Hardware updated by STEP 7".

If you cannot see 0 to 20 mA in the dropdown list of measuring ranges, the hardware catalog entry is not aligned with the actual module revision. Update the HSP (Hardware Support Package) for TIA Portal, or in STEP 7 V5.5, run HW Update from the right-click menu and confirm the MLFB is exactly 6ES7331-7KF02-0AB0.

6. Range Module Physical Switch Setting

Even if HW Config says "4-wire current 0-20 mA", the SM331 will not convert correctly unless the rear range module is mechanically in position C. The following physical switch setting is the one that drives in this scenario must select:

  1. De-energise the S7-300 station. Remove the front connector / sub-D shell from the SM331 module.
  2. Locate the small rotary switch on the rear of the module. Each group of four channels has its own switch; the group that contains the speed feedback channel must be set.
  3. Use a small flat-blade screwdriver to rotate the switch so the arrow / letter points to C.
  4. If both groups have channels in use, confirm both switches are in C.
  5. Reinstall the front connector. Restore power.
Mis-step 1 - common: leaving the range module in D (the 2-wire setting) and then switching HW Config back to "U 0-10 V" to make the dropdown show 0-20 mA. STEP 7 will warn that the configuration and the range module disagree, and the resulting PIW will still saturate. The module must be moved mechanically; HW Config cannot override the shunt resistor.

7. FC105 Scaling Configuration

With the hardware configured and the input reading a clean 0-27648 mW mapped signal, FC105 (SCALE) is called to map the raw integer to engineering units. For a 0 to 20 mA speed feedback where 0 mA = 0 rpm and 20 mA = 1500 rpm, the FC105 call is:

CALL FC 105
  IN      := PIW 304          // raw input from SM331 channel 0, group 0
  LO_LIM  := 0.0              // engineering value at 0 mA
  HI_LIM  := 1500.0           // engineering value at 20 mA
  BIPOLAR := FALSE            // 0-20 mA is unipolar
  RET_VAL := MW 100           // store FC105 error code
  OUT     := MD 200            // engineering units (REAL)

7.1 Why BIPOLAR Must Be FALSE

A 0-20 mA signal occupies only the positive half of the converter's bipolar range. Setting BIPOLAR := TRUE would double the apparent resolution without giving any extra information and would also lift the integer zero point to a non-integer boundary. With the AC880 0-20 mA output, leave BIPOLAR off and treat the raw integer as 0-27648 unipolar.

7.2 Bipolar Note for 4-20 mA Applications

If the field application is changed to 4-20 mA (still on position C of the range module), the scaling changes:

  • Integer 0 corresponds to 4 mA (4 mA is the integer offset).
  • 4 mA = 0 engineering units (typically 0 rpm or live-zero scale).
  • 20 mA = 27648 = HI_LIM.
  • A reading of 0 or below is indicative of an open wire.

Open-wire detection on 4-20 mA is a useful diagnostic and is one reason industrial standards favour 4-20 mA over 0-20 mA for new installations.

8. FC105 RET_VAL Error Code Reference

The error code returned into the RET_VAL output of FC105 is a compact diagnostics channel. The codes most relevant to this application are listed below; reference the Siemens "Standard Functions" manual for the complete table.

FC105 RET_VAL Codes (Selected)
RET_VAL (hex) Decimal Meaning Action
W#16#0000 0 No error Proceed, OUT is valid
W#16#0007 7 BIPOLAR requested but range card is unipolar Set BIPOLAR := FALSE for 0-20 mA / 4-20 mA
W#16#0008 8 IN out of range (over / under) Check PIW; over-range equals 32767; under-range equals 0 with diagnostic interrupt
W#16#0009 9 Invalid bipolar setting for the active hardware Verify HW Config and FC105 argument align
W#16#000A 10 LO_LIM or HI_LIM outside integer range Re-check FC105 limits

A persistent W#16#0008 with the in-station hardware in position C almost always means the rear range module and the HW Config measurement type still disagree.

9. HMI Display Wiring

Once FC105 writes a clean REAL into MD 200, the HMI tag should reference MD 200 (or a copy in a global DB) and convert it to engineering units on display:

HMI Tag Configuration
Field Setting
PLC Tag "Drive_Speed_Actual" = MD200 (REAL)
Number Format Floating-point, 0 decimals or 1 decimal
Display Limits 0 to 1500 rpm
Alarm Limits Low 0 (live-zero check on 4-20 mA), High 1600

9.1 Watchdog Tag for FC105 Error

For predictive maintenance, expose MW100 (the FC105 RET_VAL) to the HMI as well, masked against W#16#0008. A persistent non-zero RET_VAL indicates that the FC105 call is misconfigured or that the PIW is in over-range. Either symptom should be alarmed at HMI level.

10. Verification Procedure

Confirm the fix on the running machine using the following ordered checks. Capture diagnostic buffer entries at each step.

  1. Verify range module position. Look at the SM331 rear slot. The letter exposed should be "C" for the relevant group.
  2. Verify HW Config. In STEP 7 or TIA Portal, double-click the module and confirm "Measuring type = 4-wire current" and "Measuring range = 0 to 20 mA".
  3. Monitor the PIW online. In a watch table (VAT), force the drive to 0 mA. Expected PIW = 0.
  4. Force the drive to 20 mA. Expected PIW ≈ 27648 (or 27646-27649 depending on converter linearity).
  5. Force the drive to 4 mA. On 0-20 mA this should give PIW ≈ 5529. On 4-20 mA it should give PIW ≈ 0 plus instrument error.
  6. Check FC105 RET_VAL. With the drive at any mid-scale current (e.g. 10 mA), FC105 RET_VAL should be W#16#0000.
  7. Verify HMI value. Confirm the HMI numeric field shows the engineering value, e.g. 750 rpm at 10 mA on a 0-1500 rpm scale.
  8. Disconnect the signal lead. Trigger diagnostic interrupt by pulling the signal terminal. Confirm "Analog input wire break" appears in the diagnostic buffer with the expected slot and channel.
Field tip - if you cannot persuade the drive to 0 mA because the drive is running the process, force a fixed reference from the drive's parameter menu (look for Fixed reference 1 or User reference 1) and confirm the resulting PIW in the VAT before exiting the menu.

11. Common Field Pitfalls

Even after the range module is correctly set, certain common mistakes show up repeatedly on site:

Mistakes Seen in the Field
Pitfall Symptom Fix
Wired as 2-wire, configured in HW Config as "U 0-10 V" (range module still in A / B) PIW = 32767, FC105 returns 0008 Set range module to A with HW Config "U 0-10 V"; or change wiring to 4-wire and use position C
Range module in D (loop-powered 2-wire), drive hardwired for 0 mA at standstill PIW sits at 7FFF because no loop power is present Either restore the 2-wire loop power, or move the range module to C and bring 24 V to the drive output
Range module not in any labelled position (in between two letters) PIW fluctuates with the slightest vibration; FC105 RET_VAL pulses non-zero Re-seat the switch firmly in C
Shared analog common not pulled to earth ground per local code PIW noisy, HMI flicker Add a single-point ground reference for the analog shield
BIPOLAR := TRUE on a unipolar 0-20 mA signal FC105 RET_VAL = W#16#0009 intermittently Set BIPOLAR := FALSE
FC105 IN fed from PIW of the wrong channel Scaled value follows the wrong physical input Re-check the slot-to-channel mapping; for module start address 256, channel 0 is PIW 256, channel 1 is PIW 258, etc.

12. Related Manual References

For further details, consult the primary Siemens documentation for the AI module and for the AC880 drive. The current versions are maintained on the Siemens and ABB product support portals:

13. Frequently Asked Questions

Why does FC105 return W#16#0008 even when the drive is OK?

FC105 returns W#16#0008 when its IN parameter is greater than 27648 or less than 0. With the SM331, an over-range condition produces a PIW of 32767. If the range module is mechanically in position D (2-wire) or A / B (voltage) but HW Config is set to "4-wire current 0-20 mA", the channel is reading through the wrong shunt and the PIW immediately saturates to 7FFF, which FC105 reports as W#16#0008. Move the range module to position C to clear the error.

Can the SM331 6ES7331-7KF02-0AB0 read 0-20 mA in 2-wire mode?

No. Position D of the range module on this SM331 only supports 4 to 20 mA in 2-wire (loop-powered) mode. To read 0 to 20 mA, use position C with the transmitter self-powered (4-wire configuration in HW Config).

What is the difference between 2-wire and 4-wire transmitters in this context?

A 2-wire transmitter carries power and signal on the same two conductors and is powered by the analog input module. A 4-wire transmitter has a separate power supply and uses two dedicated conductors for the analog signal. With the AC880 drive, you can wire either topology. Choose 4-wire if you need 0-20 mA on this SM331.

How do I check which range module position the SM331 is in?

Remove the front connector from the SM331 module on the S7-300. The two small lettered indicators (one per group of 4 channels) are visible on the back of the module near the DIN-rail latch. Confirm with the cover schematic diagram in the module manual before re-energising the station.

What scaling limits should I use in FC105 for a 0-1500 rpm drive feedback?

For a 0-20 mA signal corresponding to 0-1500 rpm, set LO_LIM := 0.0, HI_LIM := 1500.0, and BIPOLAR := FALSE. If the system is changed to 4-20 mA live-zero, the same integer count now corresponds to 4-1500 rpm, so LO_LIM becomes the speed equivalent of 4 mA (which may be non-zero for some drive parameter assignments) and HI_LIM becomes the speed equivalent of 20 mA.

Back to blog