Configuring WinCC V7.0 Modbus TCP 16-Bit Register Float Values
This reference documents how to configure a Siemens WinCC V7.0 HMI/SCADA station (acting as a Modbus TCP client) to correctly interpret engineering values that a server device stores as scaled 16-bit integers in the 4xxxx holding register range. It is a common failure mode in field commissioning to misconfigure a WinCC tag as a 32-bit IEEE-754 floating-point value, only to discover that the device packs one fractional value per register (resolution factor applied on the SCADA side) and the tag displays garbage. The procedures below cover the three valid configurations: linear scaling on a 16-bit unsigned tag, the Adapt Format conversion FloatToUnsignedWord on a 32-bit float tag, and a 32-bit signed (DINT) tag for integral cross-register values.
1. Problem Summary
A WinCC V7.0 tag is created against a Modbus TCP channel that points to register 40001. The HMI engineer opens the tag properties and selects one of the available data types:
| WinCC V7.0 Data Type | Register Width Consumed | Use Case |
|---|---|---|
| Binary Tag | 1 bit | Coils / discrete inputs only |
| Signed Value 8 / 16 / 32 bits | 1 or 2 registers | Two's-complement integer variables |
| Unsigned Value 8 / 16 / 32 bits | 1 or 2 registers | Non-negative integer variables |
| Floating-point 32 / 64 bits | 2 or 4 registers | IEEE-754 floats packed across registers |
| Text tag 8-bit character set | n registers | ASCII strings |
| Text tag 16-bit character set | n registers | Unicode strings |
| Raw Data Type | n registers | Opaque byte buffer for scripts |
Selecting Floating-point 32-bit at register 40001 instructs the driver to read registers 40001 and 40002 and combine them into an IEEE-754 single-precision float. The combined word pair is interpreted as a 32-bit big-endian value:
float_value = reinterpret<float>( (reg40001 << 16) | reg40002 )
If the device returns only one scaled integer per register, the IEEE-754 decode is meaningless (often a negative number, an overflow, or a value one or two orders of magnitude out of range). This is the central symptom reported in the original support case.
2. Root Cause Analysis
The conflict emerges from three orthogonal encoding schemes meeting at the tag dialog:
| Layer | Encoding | Implication |
|---|---|---|
| Modbus register on device | 16-bit unsigned word | Raw range 0..65535 |
| WinCC internal data type | Must support fractional engineering units | Requires 32-bit float OR 16-bit + scaling |
| Engineering representation | value = raw_register × resolution |
Resolution documented per variable |
The device vendor publishes a "resolution" per variable (e.g., 0.1, 0.01, 1). A raw register value of 321 therefore represents an engineering value of 32.1 (resolution 0.1), 3.21 (resolution 0.01), or 321 (resolution 1). The Modbus TCP driver passes the raw 16-bit word to WinCC; WinCC does not infer the resolution, and there is no automatic scaling on read. A 32-bit float tag decodes the word pair incorrectly because the assumption (two-register IEEE-754 packing) is false.
3. Method A - Linear Scaling on an Unsigned 16-Bit Tag
This is the cleanest configuration when the raw-to-engineering transform is a single linear multiplication by a constant. WinCC's driver-level linear scaling executes at acquisition time and does not require a script.
- Create the tag with data type Unsigned Value, 16 bits.
- Set the tag address to Modbus register 40001 (offset 0 in holding register space).
- In the tag properties, enable Linear Scaling.
- Set
Raw range low = 0andRaw range high = 65535. - Set
Engineering range low = 0 / resolutionandEngineering range high = 65535 / resolution. - Optionally enable Invert if the device swaps the scaling direction.
Example: variable Temperature with resolution 0.1 °C:
- Raw range: 0 to 65535
- Engineering range: 0.0 to 6553.5
- A raw register value of 321 displays as 32.1 °C.
For resolution 0.01:
- Engineering range: 0.00 to 655.35
- A raw register value of 321 displays as 3.21.
4. Method B - Adapt Format FloatToUnsignedWord
If downstream WinCC tags, scripts, archives, or faceplate widgets require a 32-bit float surface, configure the tag as a 32-bit float and apply the Adapt Format conversion FloatToUnsignedWord. The function takes a 32-bit float tag declaration but reads the data as a 16-bit unsigned word at acquisition time, then promotes the result back to a 32-bit float for use throughout the project.
- Create the tag with data type Floating-point 32-bit IEEE 754.
- Set the tag address to Modbus register 40001, length 1 word.
- Open Tag Properties > Adapt Format.
- Select conversion function
FloatToUnsignedWord. - Confirm the conversion direction (Word → Float) and commit the dialog.
The FloatToUnsignedWord conversion is documented in the WinCC V7.0 Information System under Working with WinCC > Tag Management > Adapt Format. The function prevents the driver from consuming a second register for the IEEE-754 decode, while preserving the float data type for the rest of the WinCC project.
FloatToUnsignedWord handles only the data-type promotion. The resolution scaling (e.g., ×0.1) is still required; apply it via Linear Scaling on the same tag, or via a downstream C / VBScript that multiplies the tag value by the resolution constant.5. Method C - DINT Tag for Cross-Register Integral Values
When the device returns a 32-bit signed integer across two consecutive registers and the engineering value is integral (no fractional component), use a 32-bit signed (DINT) tag.
- Create the tag with data type Signed Value, 32 bits (DINT).
- Set the tag address to Modbus register 40001, length 2 words.
- Verify the word order against the device documentation. Modbus standard is big-endian (MSW at 40001, LSW at 40002); some instruments use the reverse.
- If the read value appears rotated, swap MSW/LSW with a script or with the driver's word-order configuration.
DINT must not be used as a substitute for a true float read. If the engineering value has a fractional component, DINT will truncate the fractional bits and produce visibly wrong results.
6. Register Addressing Reference (Modicon 4xxxx Convention)
The Modicon 4xxxx holding register address space maps to WinCC offsets as follows:
| Modbus Address | WinCC Offset | Function Code Used | Description |
|---|---|---|---|
| 00001..09999 | 0..9998 | FC 01 (Read Coils), FC 05 (Write Single Coil) | Coil outputs |
| 10001..19999 | 0..9998 | FC 02 (Read Discrete Inputs) | Discrete inputs |
| 30001..39999 | 0..9998 | FC 04 (Read Input Registers) | Analog inputs (read-only) |
| 40001..49999 | 0..9998 | FC 03 (Read Holding), FC 06/16 (Write) | Holding registers (read/write) |
A 32-bit IEEE-754 float on a Modbus-conforming server occupies two consecutive registers (e.g., 40001 + 40002) in big-endian word order. WinCC's driver automatically reads both registers when a 32-bit float tag is created at register 40001. If the device places only one 16-bit value per register, a 32-bit float tag will overrun into the next variable's register and produce invalid data.
7. Step-by-Step WinCC V7.0 Configuration
7.1 Prerequisites
- WinCC V7.0 SP3 or later installed on the HMI/runtime station.
- Modbus TCP channel driver installed and licensed (Siemens "SIMATIC WinCC Modbus TCP" add-on or equivalent Connectivity Pack component).
- Ethernet connectivity from the HMI station to the device's TCP port 502 (default Modbus TCP port).
- Device address map documentation showing the holding register base (e.g., 40001) and per-variable resolution (e.g., 0.1, 0.01, 1).
7.2 Procedure
- Open WinCC Explorer and select the project node Tag Management.
- Expand the Modbus TCP channel (e.g., ModbusTCPIP). If the channel is missing, install the Modbus TCP driver and create a new connection with the device IP address and port 502.
- Right-click the channel and select New Tag.
- In the Tag Properties dialog, configure:
-
Name: engineering name, e.g.,
Tank_Level_Actual -
Data type:
Unsigned 16-bit value(Method A) orFloating-point 32-bit IEEE 754(Method B) -
Address: Modbus register
40001, length 1 word - Acquisition cycle: 1 s (operator HMI) or 5 s (diagnostics)
-
Name: engineering name, e.g.,
- For Method A: enable Linear Scaling, set raw range 0-65535, set engineering range using the resolution from the device manual.
- For Method B: open Adapt Format, select
FloatToUnsignedWord, then enable Linear Scaling for the resolution factor. - Click OK to commit the tag.
- Test the tag in WinCC's internal Tag Simulation tool, or wire it to a numeric I/O field on a graphics screen.
8. Verification Procedure
- Raw read check. Use WinCC's internal tag diagnostics or a third-party Modbus master (e.g., Modbus Poll, CAS Modbus Scanner) to read register 40001 and confirm the raw 16-bit value.
- Scaling check. Multiply the raw value by the documented resolution. The result must match the device's local display to within ±0.5 LSB.
- Continuity check. Force a known value at the device (e.g., 4 mA loop trim or a calibration reference) and confirm the HMI value follows within the configured acquisition cycle (default 1 s, 250 ms, or 500 ms depending on driver settings).
- Range check. Sweep the input across the full 0-65535 raw range and confirm no HMI overflow, no NaN, and no negative readings (unless the device documentation explicitly permits negative values).
-
Quality check. Confirm the tag quality stays
Good(OPC quality 0xC0) under steady-state operation. If quality drops toBad - Communication Error(0x00), refer to the timeout section below.
9. Driver Timeout and Channel Health
The WinCC Modbus TCP driver (and most third-party Modbus drivers, including those bundled with Ignition, Kepware, and TOP Server) enforces a default timeout on tag acquisition. If no successful tag read occurs within the timeout window (typically 10 seconds), the channel marks the connection as bad and all dependent tags drop to Bad - Communication Error quality.
Best practice to keep the channel healthy:
- Assign an explicit acquisition cycle to every Modbus tag (no on-demand-only tags) so the driver polls at least one register continuously.
- Set the driver timeout to at least 2× the worst-case device response time observed during commissioning.
- Add a keep-alive read of a known-good register (a static diagnostic or a coil that the device toggles) so polling continues even when operator screens are closed.
- Enable driver-side TCP keep-alive at the operating system level (default Windows TCP keep-alive is 2 hours; reduce to 30-60 s for industrial Modbus).
10. Alternative OPC Server Solutions
If the WinCC native Modbus TCP driver cannot satisfy resolution or scaling requirements (e.g., complex per-tag transforms, signed/unsigned mixing, byte-swap requirements), route the data through an OPC server and consume the OPC tags in WinCC via the OPC channel.
- Siemens PCS 7 Modbus TCP/IP Library (V1.63): driver FBs for S7-400 and S7-400H CPUs; provides native Modbus master functionality with FC 03, FC 06, and FC 16 support for direct integration of third-party Modbus slaves into PCS 7 CFC charts. See PCS 7 Modbus TCP/IP library manual.
- TOP Server Modbus TCP Ethernet Driver (Software Toolbox): client and server Modbus TCP connectivity, with built-in scaling, signed/unsigned handling, and float byte-swap options for Modicon and compatible devices. See TOP Server Modbus driver page.
- Kepware Modbus Ethernet Driver (PTC): extensive Modbus device database covering 200+ instrument vendors; supports 16-bit/32-bit/64-bit data types, float byte order selection, and per-tag linear scaling. See Kepware Modbus Ethernet driver.
- IGSS32 MODBUS/TCP Driver (Schneider Electric): uses a standard Windows TCP/IP socket to communicate with Modbus/TCP PLCs; well suited when IGSS is the supervisory layer alongside WinCC. See IGSS Modbus/TCP driver documentation.
11. PCS 7 Modbus TCP/IP Integration Notes
For PCS 7 V7.1+ plants that include non-Siemens Modbus devices, the PCS7v7_MODBUS_TCPIP library provides pre-built FBs (e.g., MODB_TCP, MODB_4REG, MODB_8REG) that can be inserted into an S7-400 or S7-400H CFC chart. The library supports:
- FC 03 (Read Holding Registers)
- FC 06 (Write Single Register)
- FC 16 (Write Multiple Registers)
The FBs expose the register value as WORD and the engineering value as REAL after applying the resolution in the calling block, which resolves the same 16-bit-scaled-vs-IEEE-754 conflict that WinCC users encounter. The library runs on the S7-400 CPU as a Modbus master and publishes the converted values to WinCC over the standard S7 protocol, removing the Modbus driver from the WinCC layer entirely.
12. Troubleshooting Matrix
| Symptom | Probable Cause | Action |
|---|---|---|
| HMI shows 0 or constant value | Tag address offset mismatch; WinCC reads wrong register | Verify 4xxxx offset; check whether device uses 1-based or 0-based addressing |
| HMI shows wildly large or negative number | 32-bit float tag consuming two registers when only one carries data | Switch to Unsigned 16-bit + Linear Scaling |
| HMI shows value 256× too large | Word-order swap (MSW/LSW reversed) | Swap word order in driver or apply byte-swap script |
| HMI shows value 0.5 LSB low / high | Rounding error from integer division | Apply Linear Scaling in float domain or use a script for non-integer resolutions |
| HMI value flickers / quality = Bad | Driver timeout exceeded; device not responding within timeout window | Increase timeout, verify TCP keep-alive, check network path |
| HMI shows half expected value | Resolution factor not applied | Multiply by resolution in Linear Scaling or script |
| HMI shows sign-flipped value | Tag data type is Signed 16-bit but device returns unsigned | Switch to Unsigned 16-bit |
| HMI shows NaN or +Inf | 32-bit float decode of a non-IEEE-754 word pair | Switch to Unsigned 16-bit + Linear Scaling |
| HMI shows zero, channel error | Device offline or wrong port | Verify TCP 502 reachable; check device IP; confirm no firewall blocking |
13. Float Encoding Diagnostic Procedure
If the device documentation is ambiguous and you need to determine whether a 4xxxx register pair carries a true IEEE-754 float or a scaled integer, run this diagnostic:
- Read register 40001 (high word) and 40002 (low word) as two separate Unsigned 16-bit tags.
- Concatenate the words:
value32 = (high_word << 16) | low_word. - Reinterpret the 32-bit word as IEEE-754 single-precision float (C union or WinCC C-script:
memcpy(&f, &v, 4);). - If the resulting float matches the device display, the device is returning a true float; configure the WinCC tag as 32-bit Floating-point IEEE 754 at register 40001, length 2 words.
- If the resulting float is NaN, +Inf, or wildly out of range, the device is returning scaled integers; fall back to Method A or Method B above.
Confirm with the device vendor whether the byte order inside each word is big-endian (Modbus standard) or little-endian. Some Chinese-vendor instruments use little-endian word order; correct with a script or driver byte-swap setting.
14. Performance and Cycle Tuning
For HMI stations polling dozens of Modbus devices:
- Acquisition cycle: 1 s for operator-relevant values, 5 s for diagnostics, 30 s for static configuration. Avoid sub-250 ms cycles on TCP unless the device is on a dedicated VLAN and latency has been measured under 10 ms.
- Multiplexing: group consecutive registers into a single FC 03 multi-register read to minimize round-trip overhead. A 10-register read is one transaction; ten 1-register reads are ten transactions.
-
Buffering: enable driver-side read buffering (where supported) to absorb transient TCP latency without dropping the tag quality to
Bad. - Channel count: limit to one Modbus TCP connection per device IP; multiple WinCC tags on the same device share the channel.
15. Glossary of Acronyms
| Term | Definition |
|---|---|
| FC | Modbus function code (e.g., FC 03 = Read Holding Registers) |
| MSW / LSW | Most Significant Word / Least Significant Word in a 32-bit value |
| DINT | 32-bit signed integer (Double INT) |
| WORD | 16-bit unsigned integer |
| REAL | IEEE-754 single-precision 32-bit float |
| PLC / SCADA | Programmable Logic Controller / Supervisory Control and Data Acquisition |
| HMI | Human-Machine Interface |
FAQ
Why does WinCC offer only 32-bit or 64-bit float data types when my device returns 16-bit values?
WinCC float data types consume two or four 16-bit Modbus registers for IEEE-754 encoding. If the device returns scaled 16-bit integers (e.g., 321 = 32.1 with 0.1 resolution), configure the tag as Unsigned 16-bit and apply Linear Scaling, or use a 32-bit float tag with the Adapt Format conversion FloatToUnsignedWord.
What Modbus function codes does the WinCC Modbus TCP driver use by default?
Reading holding registers (4xxxx) uses function code 03 (FC 03). Input registers (3xxxx) use FC 04. Coils (0xxxx) use FC 01, and discrete inputs (1xxxx) use FC 02. The driver selects the function code based on the configured register range.
What is the standard TCP port for Modbus TCP?
Modbus TCP uses TCP port 502. The WinCC channel configuration requires the device IP address and port 502 unless the device is mapped through a gateway on a different port.
How do I know whether a register is signed or unsigned?
Refer to the device Modbus register map. Most 16-bit holding registers exposed by sensors, drives, and RTUs are unsigned (0-65535). A negative value (e.g., -10) on a 16-bit register is encoded as the two's complement representation, which the WinCC Signed 16-bit tag type decodes automatically.
Can I use DINT (32-bit signed) instead of float for a scaled value?
Use DINT only when the engineering value is integral. For scaled values with a resolution factor (0.1, 0.01), use Unsigned 16-bit with Linear Scaling, or Floating-point 32-bit with the FloatToUnsignedWord Adapt Format function plus Linear Scaling.