Configuring WinCC V7.0 Modbus TCP 16-Bit Register Float Values

David Krause13 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Configuring WinCC V7.0 Modbus TCP 16-Bit Register Float Values

This reference documents how to configure a Siemens WinCC V7.0 HMI/SCADA station (acting as a Modbus TCP client) to correctly interpret engineering values that a server device stores as scaled 16-bit integers in the 4xxxx holding register range. It is a common failure mode in field commissioning to misconfigure a WinCC tag as a 32-bit IEEE-754 floating-point value, only to discover that the device packs one fractional value per register (resolution factor applied on the SCADA side) and the tag displays garbage. The procedures below cover the three valid configurations: linear scaling on a 16-bit unsigned tag, the Adapt Format conversion FloatToUnsignedWord on a 32-bit float tag, and a 32-bit signed (DINT) tag for integral cross-register values.

Engineering intent: The device ships each variable in one 16-bit register; the engineering value is reconstructed at the SCADA layer by multiplying the raw word by the documented resolution. Selecting 32-bit float in WinCC consumes two 16-bit registers (40001 and 40002) and decodes them as an IEEE-754 float, which is the wrong transform for an integer-encoded scaled value.

1. Problem Summary

A WinCC V7.0 tag is created against a Modbus TCP channel that points to register 40001. The HMI engineer opens the tag properties and selects one of the available data types:

WinCC V7.0 Data Type Register Width Consumed Use Case
Binary Tag 1 bit Coils / discrete inputs only
Signed Value 8 / 16 / 32 bits 1 or 2 registers Two's-complement integer variables
Unsigned Value 8 / 16 / 32 bits 1 or 2 registers Non-negative integer variables
Floating-point 32 / 64 bits 2 or 4 registers IEEE-754 floats packed across registers
Text tag 8-bit character set n registers ASCII strings
Text tag 16-bit character set n registers Unicode strings
Raw Data Type n registers Opaque byte buffer for scripts

Selecting Floating-point 32-bit at register 40001 instructs the driver to read registers 40001 and 40002 and combine them into an IEEE-754 single-precision float. The combined word pair is interpreted as a 32-bit big-endian value:

float_value = reinterpret<float>( (reg40001 << 16) | reg40002 )

If the device returns only one scaled integer per register, the IEEE-754 decode is meaningless (often a negative number, an overflow, or a value one or two orders of magnitude out of range). This is the central symptom reported in the original support case.

2. Root Cause Analysis

The conflict emerges from three orthogonal encoding schemes meeting at the tag dialog:

Layer Encoding Implication
Modbus register on device 16-bit unsigned word Raw range 0..65535
WinCC internal data type Must support fractional engineering units Requires 32-bit float OR 16-bit + scaling
Engineering representation value = raw_register × resolution Resolution documented per variable

The device vendor publishes a "resolution" per variable (e.g., 0.1, 0.01, 1). A raw register value of 321 therefore represents an engineering value of 32.1 (resolution 0.1), 3.21 (resolution 0.01), or 321 (resolution 1). The Modbus TCP driver passes the raw 16-bit word to WinCC; WinCC does not infer the resolution, and there is no automatic scaling on read. A 32-bit float tag decodes the word pair incorrectly because the assumption (two-register IEEE-754 packing) is false.

3. Method A - Linear Scaling on an Unsigned 16-Bit Tag

This is the cleanest configuration when the raw-to-engineering transform is a single linear multiplication by a constant. WinCC's driver-level linear scaling executes at acquisition time and does not require a script.

  1. Create the tag with data type Unsigned Value, 16 bits.
  2. Set the tag address to Modbus register 40001 (offset 0 in holding register space).
  3. In the tag properties, enable Linear Scaling.
  4. Set Raw range low = 0 and Raw range high = 65535.
  5. Set Engineering range low = 0 / resolution and Engineering range high = 65535 / resolution.
  6. Optionally enable Invert if the device swaps the scaling direction.

Example: variable Temperature with resolution 0.1 °C:

  • Raw range: 0 to 65535
  • Engineering range: 0.0 to 6553.5
  • A raw register value of 321 displays as 32.1 °C.

For resolution 0.01:

  • Engineering range: 0.00 to 655.35
  • A raw register value of 321 displays as 3.21.

4. Method B - Adapt Format FloatToUnsignedWord

If downstream WinCC tags, scripts, archives, or faceplate widgets require a 32-bit float surface, configure the tag as a 32-bit float and apply the Adapt Format conversion FloatToUnsignedWord. The function takes a 32-bit float tag declaration but reads the data as a 16-bit unsigned word at acquisition time, then promotes the result back to a 32-bit float for use throughout the project.

  1. Create the tag with data type Floating-point 32-bit IEEE 754.
  2. Set the tag address to Modbus register 40001, length 1 word.
  3. Open Tag Properties > Adapt Format.
  4. Select conversion function FloatToUnsignedWord.
  5. Confirm the conversion direction (Word → Float) and commit the dialog.

The FloatToUnsignedWord conversion is documented in the WinCC V7.0 Information System under Working with WinCC > Tag Management > Adapt Format. The function prevents the driver from consuming a second register for the IEEE-754 decode, while preserving the float data type for the rest of the WinCC project.

Important: FloatToUnsignedWord handles only the data-type promotion. The resolution scaling (e.g., ×0.1) is still required; apply it via Linear Scaling on the same tag, or via a downstream C / VBScript that multiplies the tag value by the resolution constant.

5. Method C - DINT Tag for Cross-Register Integral Values

When the device returns a 32-bit signed integer across two consecutive registers and the engineering value is integral (no fractional component), use a 32-bit signed (DINT) tag.

  1. Create the tag with data type Signed Value, 32 bits (DINT).
  2. Set the tag address to Modbus register 40001, length 2 words.
  3. Verify the word order against the device documentation. Modbus standard is big-endian (MSW at 40001, LSW at 40002); some instruments use the reverse.
  4. If the read value appears rotated, swap MSW/LSW with a script or with the driver's word-order configuration.

DINT must not be used as a substitute for a true float read. If the engineering value has a fractional component, DINT will truncate the fractional bits and produce visibly wrong results.

6. Register Addressing Reference (Modicon 4xxxx Convention)

The Modicon 4xxxx holding register address space maps to WinCC offsets as follows:

Modbus Address WinCC Offset Function Code Used Description
00001..09999 0..9998 FC 01 (Read Coils), FC 05 (Write Single Coil) Coil outputs
10001..19999 0..9998 FC 02 (Read Discrete Inputs) Discrete inputs
30001..39999 0..9998 FC 04 (Read Input Registers) Analog inputs (read-only)
40001..49999 0..9998 FC 03 (Read Holding), FC 06/16 (Write) Holding registers (read/write)

A 32-bit IEEE-754 float on a Modbus-conforming server occupies two consecutive registers (e.g., 40001 + 40002) in big-endian word order. WinCC's driver automatically reads both registers when a 32-bit float tag is created at register 40001. If the device places only one 16-bit value per register, a 32-bit float tag will overrun into the next variable's register and produce invalid data.

7. Step-by-Step WinCC V7.0 Configuration

7.1 Prerequisites

  • WinCC V7.0 SP3 or later installed on the HMI/runtime station.
  • Modbus TCP channel driver installed and licensed (Siemens "SIMATIC WinCC Modbus TCP" add-on or equivalent Connectivity Pack component).
  • Ethernet connectivity from the HMI station to the device's TCP port 502 (default Modbus TCP port).
  • Device address map documentation showing the holding register base (e.g., 40001) and per-variable resolution (e.g., 0.1, 0.01, 1).

7.2 Procedure

  1. Open WinCC Explorer and select the project node Tag Management.
  2. Expand the Modbus TCP channel (e.g., ModbusTCPIP). If the channel is missing, install the Modbus TCP driver and create a new connection with the device IP address and port 502.
  3. Right-click the channel and select New Tag.
  4. In the Tag Properties dialog, configure:
    • Name: engineering name, e.g., Tank_Level_Actual
    • Data type: Unsigned 16-bit value (Method A) or Floating-point 32-bit IEEE 754 (Method B)
    • Address: Modbus register 40001, length 1 word
    • Acquisition cycle: 1 s (operator HMI) or 5 s (diagnostics)
  5. For Method A: enable Linear Scaling, set raw range 0-65535, set engineering range using the resolution from the device manual.
  6. For Method B: open Adapt Format, select FloatToUnsignedWord, then enable Linear Scaling for the resolution factor.
  7. Click OK to commit the tag.
  8. Test the tag in WinCC's internal Tag Simulation tool, or wire it to a numeric I/O field on a graphics screen.

8. Verification Procedure

  1. Raw read check. Use WinCC's internal tag diagnostics or a third-party Modbus master (e.g., Modbus Poll, CAS Modbus Scanner) to read register 40001 and confirm the raw 16-bit value.
  2. Scaling check. Multiply the raw value by the documented resolution. The result must match the device's local display to within ±0.5 LSB.
  3. Continuity check. Force a known value at the device (e.g., 4 mA loop trim or a calibration reference) and confirm the HMI value follows within the configured acquisition cycle (default 1 s, 250 ms, or 500 ms depending on driver settings).
  4. Range check. Sweep the input across the full 0-65535 raw range and confirm no HMI overflow, no NaN, and no negative readings (unless the device documentation explicitly permits negative values).
  5. Quality check. Confirm the tag quality stays Good (OPC quality 0xC0) under steady-state operation. If quality drops to Bad - Communication Error (0x00), refer to the timeout section below.

9. Driver Timeout and Channel Health

The WinCC Modbus TCP driver (and most third-party Modbus drivers, including those bundled with Ignition, Kepware, and TOP Server) enforces a default timeout on tag acquisition. If no successful tag read occurs within the timeout window (typically 10 seconds), the channel marks the connection as bad and all dependent tags drop to Bad - Communication Error quality.

Best practice to keep the channel healthy:

  • Assign an explicit acquisition cycle to every Modbus tag (no on-demand-only tags) so the driver polls at least one register continuously.
  • Set the driver timeout to at least 2× the worst-case device response time observed during commissioning.
  • Add a keep-alive read of a known-good register (a static diagnostic or a coil that the device toggles) so polling continues even when operator screens are closed.
  • Enable driver-side TCP keep-alive at the operating system level (default Windows TCP keep-alive is 2 hours; reduce to 30-60 s for industrial Modbus).

10. Alternative OPC Server Solutions

If the WinCC native Modbus TCP driver cannot satisfy resolution or scaling requirements (e.g., complex per-tag transforms, signed/unsigned mixing, byte-swap requirements), route the data through an OPC server and consume the OPC tags in WinCC via the OPC channel.

  • Siemens PCS 7 Modbus TCP/IP Library (V1.63): driver FBs for S7-400 and S7-400H CPUs; provides native Modbus master functionality with FC 03, FC 06, and FC 16 support for direct integration of third-party Modbus slaves into PCS 7 CFC charts. See PCS 7 Modbus TCP/IP library manual.
  • TOP Server Modbus TCP Ethernet Driver (Software Toolbox): client and server Modbus TCP connectivity, with built-in scaling, signed/unsigned handling, and float byte-swap options for Modicon and compatible devices. See TOP Server Modbus driver page.
  • Kepware Modbus Ethernet Driver (PTC): extensive Modbus device database covering 200+ instrument vendors; supports 16-bit/32-bit/64-bit data types, float byte order selection, and per-tag linear scaling. See Kepware Modbus Ethernet driver.
  • IGSS32 MODBUS/TCP Driver (Schneider Electric): uses a standard Windows TCP/IP socket to communicate with Modbus/TCP PLCs; well suited when IGSS is the supervisory layer alongside WinCC. See IGSS Modbus/TCP driver documentation.

11. PCS 7 Modbus TCP/IP Integration Notes

For PCS 7 V7.1+ plants that include non-Siemens Modbus devices, the PCS7v7_MODBUS_TCPIP library provides pre-built FBs (e.g., MODB_TCP, MODB_4REG, MODB_8REG) that can be inserted into an S7-400 or S7-400H CFC chart. The library supports:

  • FC 03 (Read Holding Registers)
  • FC 06 (Write Single Register)
  • FC 16 (Write Multiple Registers)

The FBs expose the register value as WORD and the engineering value as REAL after applying the resolution in the calling block, which resolves the same 16-bit-scaled-vs-IEEE-754 conflict that WinCC users encounter. The library runs on the S7-400 CPU as a Modbus master and publishes the converted values to WinCC over the standard S7 protocol, removing the Modbus driver from the WinCC layer entirely.

12. Troubleshooting Matrix

Symptom Probable Cause Action
HMI shows 0 or constant value Tag address offset mismatch; WinCC reads wrong register Verify 4xxxx offset; check whether device uses 1-based or 0-based addressing
HMI shows wildly large or negative number 32-bit float tag consuming two registers when only one carries data Switch to Unsigned 16-bit + Linear Scaling
HMI shows value 256× too large Word-order swap (MSW/LSW reversed) Swap word order in driver or apply byte-swap script
HMI shows value 0.5 LSB low / high Rounding error from integer division Apply Linear Scaling in float domain or use a script for non-integer resolutions
HMI value flickers / quality = Bad Driver timeout exceeded; device not responding within timeout window Increase timeout, verify TCP keep-alive, check network path
HMI shows half expected value Resolution factor not applied Multiply by resolution in Linear Scaling or script
HMI shows sign-flipped value Tag data type is Signed 16-bit but device returns unsigned Switch to Unsigned 16-bit
HMI shows NaN or +Inf 32-bit float decode of a non-IEEE-754 word pair Switch to Unsigned 16-bit + Linear Scaling
HMI shows zero, channel error Device offline or wrong port Verify TCP 502 reachable; check device IP; confirm no firewall blocking

13. Float Encoding Diagnostic Procedure

If the device documentation is ambiguous and you need to determine whether a 4xxxx register pair carries a true IEEE-754 float or a scaled integer, run this diagnostic:

  1. Read register 40001 (high word) and 40002 (low word) as two separate Unsigned 16-bit tags.
  2. Concatenate the words: value32 = (high_word << 16) | low_word.
  3. Reinterpret the 32-bit word as IEEE-754 single-precision float (C union or WinCC C-script: memcpy(&f, &v, 4);).
  4. If the resulting float matches the device display, the device is returning a true float; configure the WinCC tag as 32-bit Floating-point IEEE 754 at register 40001, length 2 words.
  5. If the resulting float is NaN, +Inf, or wildly out of range, the device is returning scaled integers; fall back to Method A or Method B above.

Confirm with the device vendor whether the byte order inside each word is big-endian (Modbus standard) or little-endian. Some Chinese-vendor instruments use little-endian word order; correct with a script or driver byte-swap setting.

14. Performance and Cycle Tuning

For HMI stations polling dozens of Modbus devices:

  • Acquisition cycle: 1 s for operator-relevant values, 5 s for diagnostics, 30 s for static configuration. Avoid sub-250 ms cycles on TCP unless the device is on a dedicated VLAN and latency has been measured under 10 ms.
  • Multiplexing: group consecutive registers into a single FC 03 multi-register read to minimize round-trip overhead. A 10-register read is one transaction; ten 1-register reads are ten transactions.
  • Buffering: enable driver-side read buffering (where supported) to absorb transient TCP latency without dropping the tag quality to Bad.
  • Channel count: limit to one Modbus TCP connection per device IP; multiple WinCC tags on the same device share the channel.

15. Glossary of Acronyms

Term Definition
FC Modbus function code (e.g., FC 03 = Read Holding Registers)
MSW / LSW Most Significant Word / Least Significant Word in a 32-bit value
DINT 32-bit signed integer (Double INT)
WORD 16-bit unsigned integer
REAL IEEE-754 single-precision 32-bit float
PLC / SCADA Programmable Logic Controller / Supervisory Control and Data Acquisition
HMI Human-Machine Interface

FAQ

Why does WinCC offer only 32-bit or 64-bit float data types when my device returns 16-bit values?

WinCC float data types consume two or four 16-bit Modbus registers for IEEE-754 encoding. If the device returns scaled 16-bit integers (e.g., 321 = 32.1 with 0.1 resolution), configure the tag as Unsigned 16-bit and apply Linear Scaling, or use a 32-bit float tag with the Adapt Format conversion FloatToUnsignedWord.

What Modbus function codes does the WinCC Modbus TCP driver use by default?

Reading holding registers (4xxxx) uses function code 03 (FC 03). Input registers (3xxxx) use FC 04. Coils (0xxxx) use FC 01, and discrete inputs (1xxxx) use FC 02. The driver selects the function code based on the configured register range.

What is the standard TCP port for Modbus TCP?

Modbus TCP uses TCP port 502. The WinCC channel configuration requires the device IP address and port 502 unless the device is mapped through a gateway on a different port.

How do I know whether a register is signed or unsigned?

Refer to the device Modbus register map. Most 16-bit holding registers exposed by sensors, drives, and RTUs are unsigned (0-65535). A negative value (e.g., -10) on a 16-bit register is encoded as the two's complement representation, which the WinCC Signed 16-bit tag type decodes automatically.

Can I use DINT (32-bit signed) instead of float for a scaled value?

Use DINT only when the engineering value is integral. For scaled values with a resolution factor (0.1, 0.01), use Unsigned 16-bit with Linear Scaling, or Floating-point 32-bit with the FloatToUnsignedWord Adapt Format function plus Linear Scaling.

Back to blog