Diagnosing Siemens S7-1215C Q1.1 Output Stuck ON Transistor

David Krause21 min read
S7-1200SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Summary: S7-1215C Output Q1.1 Stuck ON with Logic-Tracking LED

A Siemens SIMATIC S7-1215C CPU (6ES7215-1AG40-0XB0 family, DC/DC/DC variant) is exhibiting a single-point failure on onboard digital output Q1.1. The terminal voltage at Q1.1 remains at 24 VDC continuously, irrespective of the PLC run state, program logic, or force table. The corresponding status LED on the front of the CPU does correctly track the requested output state (LED on when logic requests ON, LED off when logic requests OFF). This decoupling of electrical output behavior from logical output behavior is the signature of a short-circuited low-side transistor inside the output driver IC. The load connected to Q1.1 is a string of white indicator LEDs in series with a safety-relay auxiliary contact (piloting a parcel-unloader conveyor run-permissive lamp string). No flyback suppression is fitted, and the safety-relay aux contact has been found mechanically loose (a single tap re-creates the dropout).

Field determination of failure mode: When the LED tracks the commanded state but the terminal voltage is pinned high, the failure is on the low-side (sinking) MOSFET/IGBT or the high-side driver has latched. When the LED does not track the logic either, suspect a logic-driver failure inside the output ASIC, a failed opto-coupler, or loss of the 24 V sensor supply rail.

Affected Hardware and Firmware

The failure described applies to S7-1200 G2 (compact) CPUs of the 1215C family with transistor outputs. The S7-1200 System Manual (SIMATIC S7-1200 Programmable Controller System Manual, 04/2024 edition) and the S7-1200 Function Manual should be consulted for the specific order number in service.

Order Number (MLFB) Designation Output Type Relevance
6ES7215-1AG40-0XB0 CPU 1215C DC/DC/DC Transistor (sourcing) Direct match – 0.5 A sourcing outputs
6ES7215-1BG40-0XB0 CPU 1215C AC/DC/RLY Relay Not applicable – would exhibit stuck contact, not latched transistor
6ES7215-1HG40-0XB0 CPU 1215C DC/DC/RLY Mixed (relay DQ + transistor DQ) Transistor outputs in this variant are Q0.0–Q0.3 only

Firmware status: this failure mode is independent of firmware revision. The energy delivered to the output stage is purely a function of the external load, not the CPU firmware. However, when replacing, reflash the replacement unit to the same firmware major.minor as the rest of the fleet, then re-download the project, technology objects, and any SINAMICS or third-party GSD files.

Engineering Specifications: S7-1215C Transistor Digital Outputs

Quoted from the S7-1200 System Manual, the DC/DC/DC variant's on-board digital outputs have the following key ratings, which directly inform the overstress calculation later in this article:

Parameter Value Notes
Number of outputs 10 DQ a.0 through DQ b.1 (Q0.0–Q0.7, Q1.0–Q1.1)
Output type Solid-state MOSFET, sourcing Not isolated per-point; group-isolated
Rated voltage 24 VDC (range 20.4–28.8 V) Reverse-polarity protected at the group
Continuous current per output 0.5 A Resistive load, vertical mount, 0–45 °C
Total current per group (Q0.0–Q0.7) 4.0 A Per CPU datasheet
Total current per group (Q1.0–Q1.1) 1.0 A Smaller group, two outputs
Surge current 0.5 A continuous; 5 A for ≤ 50 ms not rated Do not exceed 0.5 A
Switching frequency, resistive 100 Hz max
Switching frequency, inductive 0.5 Hz max Per Siemens datasheet, with external suppression
Output ON resistance (RDS(on)) ≤ 0.6 Ω typical Worst-case cold channel
Leakage current, output OFF ≤ 10 µA
Clamp voltage (inductive) Internally clamped to ~−1 V below 0 V Limited; cannot dissipate large inductive energy
Short-circuit protection Electronic, per channel; not designed for repetitive shorts Latches on overcurrent; re-armed by cycling logic
Status indication Green LED per output Driven from logic side, isolated from power stage
Critical spec for this failure mode: The internal clamp on S7-1200 transistor outputs is sized only for the small inductance of long field wiring. It is not a substitute for a flyback diode on a relay coil, solenoid, or – as in this case – a long LED indicator string driven through a relay contact where the wiring harness inductance plus the contact arcing energy can easily exceed the clamp's energy rating (E = 0.5·L·I²).

Root Cause Analysis

The observed symptoms point to a single dominant failure mechanism: avalanche/dielectric breakdown of the S7-1215C's high-side (sourcing) output MOSFET for channel Q1.1, caused by repetitive un-suppressed inductive kickback from a contactor/relay coil or from a long wiring harness being interrupted by a chattering mechanical contact.

Why the LED tracks logic but the terminal does not

The status LED is driven by the same logic signal that drives the gate of the output MOSFET, but the LED's return path is internal to the ASIC. When the MOSFET channel fails short (drain-to-source short, gate shorted high, or bond-wire fused), the silicon switch is now a low-impedance path from the 24 V rail to the output terminal. The logic correctly commands the gate OFF, the LED correctly extinguishes, but the failed silicon remains conducting. This is consistent with a hard, non-recoverable failure.

Why a relay contact failure upstream triggered the transistor failure

The load on Q1.1 is wired in the following topology, derived from the field report:

S7-1215C CPU +24V internal rail Q1.1 MOSFET (shorted D-S) Terminal Q1.1 Safety Relay S1 Aux Contact (loose screw) LED String white indicator 0V / M

The path of destruction is:

  1. Plc commands Q1.1 ON. Current flows through the (intact at the time) high-side MOSFET, out terminal Q1.1, through the safety-relay S1 aux contact, through the LED string, and back to 0 V.
  2. The safety relay's S1 aux contact is wired with an un-tightened screw. The contact chatters — perhaps imperceptibly at first, then more obviously as oxidation or micro-arcing degrades the contact face.
  3. Each chatter event is an interruption of current through the wiring inductance of the harness. The harness between the CPU and the remote contactor panel will easily accumulate 100 µH to 1 mH per 10 m of cable, plus the lumped inductance of any local chokes, ferrules, or PCB tracks on the LED indicator board.
  4. When the contact opens, the energy stored in the inductance L at current I is suddenly released. The energy is E = 0.5 · L · I². If I = 0.3 A and L = 200 µH (a 20 m round trip in a typical control cable), E = 9 µJ. That alone is trivial. But if there is contact arcing and the wiring forms a resonant tank with cable capacitance (~1 nF/m), the dV/dt on the output pin can exceed several hundred V/µs, easily enough to punch through the gate oxide of the output MOSFET.
  5. Over weeks of operation, the cumulative effect of repeated over-voltage events on the drain of the output MOSFET – particularly the negative-going transients that exceed the SOA of the device's internal avalanche clamp – causes progressive degradation. Final failure mode is a drain-to-source short, often with the bond wire fused open, so the LED and the logic return are still healthy.

Differential Diagnosis: Transistor vs Relay Output

It is critical to confirm the output type before any physical intervention. The S7-1215C exists in three output variants. The order number is on the front label of the CPU under the door flap, after the 6ES7215- prefix.

Test Relay Output (RLY) Transistor Output (DC/DC/DC) Interpretation
Voltage at terminal with logic OFF 0 V (or floating) Should be 0 V; if 24 V present, MOSFET is shorted 24 V stuck-on => transistor failure
Output with PLC in STOP Contact opens; 0 V present 0 V expected; 24 V present = shorted MOSFET STOP doesn't de-energize the rail, only the gate drive
Tap test with screwdriver handle May unstick the contact momentarily No effect on solid-state No tap effect on a transistor
Resistance from output to 24 V rail (PLC unpowered) > 100 MΩ (open contact) Diode-like behavior; < 10 Ω = short < 10 Ω = shorted D-S
Resistance from output to 0 V (PLC unpowered) Open circuit (relay is isolated) Open circuit (sourcing) Open = not shorted low-side

Procedure to differentiate in the field with the PLC powered and programmed (forces OFF, all logic-0 on Q1.1):

  1. With TIA Portal online, force the process image for %Q1.1 to 0. Confirm in the watch table that the output is OFF.
  2. Measure DC voltage between terminal Q1.1 and the adjacent 1M (0 V) terminal on the CPU. A reading of 0.0–0.3 V = healthy. A reading of 22–28 V = shorted output stage.
  3. Switch the PLC to STOP mode. Re-measure. If the reading is still 24 V, the failure is in the power stage and is not a logic issue.
  4. De-energize the 24 V supply to the CPU. Wait 60 s for capacitors to discharge. Measure resistance between terminal Q1.1 and the 24 V sensor-supply terminal on the CPU. A reading < 5 Ω confirms a shorted drain-to-source on the high-side switch.
Do not attempt to cycle the PLC into RUN and force the output OFF repeatedly to "clear" the fault. Each cycle deposits energy into an already-failed device and may propagate the short to adjacent channels Q1.0 or the sensor-supply rail.

Step-by-Step Field Procedure

1. Lock out and isolate

Place the machine in a safe state per the site's LOTO (lock-out tag-out) procedure. De-energize the 24 VDC control supply to the S7-1215C. Confirm zero energy with a known-good meter at the input terminals of the CPU's power supply module. De-energize the 24 VDC load supply if it is separately fed.

2. Disconnect the load

Remove the wire from terminal Q1.1 on the CPU. Note that with the CPU on a removable terminal block (the typical 1215C ships with a screw-type block), the entire block can be lifted off the CPU and the offending conductor can be cleanly lifted out. Mark the conductor with a numbered ferrrule or wrap so the wiring technician knows exactly which conductor was attached when re-energizing.

3. Confirm shorted output stage

With the load disconnected and the PLC de-energized, measure resistance between terminal Q1.1 and the 24 V sensor-supply terminal on the CPU. A reading of 0–5 Ω is a dead short. A reading of 50–500 kΩ suggests partial degradation that will worsen. Replace the CPU.

4. Inspect the safety relay wiring

With the safety relay still isolated, inspect the S1 aux contact terminal. Re-torque to the manufacturer's spec (typically 0.6–0.8 Nm for Phoenix or Wago spring-clamp terminals; 0.5 Nm for screw terminals). Verify that the conductor is correctly stripped, that no stray strands are present, and that the conductor is fully seated. If the conductor was tinned after stripping, cut back to bare copper — tinned conductors cold-flow under screw pressure and loosen over time. Re-verify by tugging with the rated pull force for the conductor (typically 10× the conductor weight in N).

5. Replace the CPU

  1. Document the exact order number, firmware version (from Online > Accessible Nodes > Online & Diagnostics > Diagnostics), and serial number of the failed unit. Photograph the label.
  2. Order a replacement with the same order number. Do not substitute a newer firmware major revision without first checking the project's TIA Portal compatibility list (TiaSelectionTool or the project right-click > Change device > Compatibility).
    Firmware compatibility example: a 1215C DC/DC/DC programmed in TIA V16 with firmware V4.4 will not accept a V4.6 CPU without a project change. Always upgrade the project to a new firmware major in a controlled engineering environment first.
  3. Mount the new CPU. Insert the SD card from the old unit (the CPU's plug-in SIMATIC Memory Card) – it contains firmware, project (if programmed to card), and IP address. If the project lives only in the old CPU's load memory, the project will need to be re-downloaded from TIA Portal.
  4. Reconnect the I/O wiring per the mark-up. Re-torque all CPU terminal screws to 0.5 Nm (per the S7-1200 System Manual).

6. Add flyback suppression before re-energizing

This step is non-negotiable. Even though the failed CPU is being replaced, the field wiring is unchanged. If the root cause is not addressed, the new CPU will fail in the same way in 3–24 months.

Load Type Suppression Element Component Value Wiring
DC relay coil (24 V, < 1 A) Flyback diode 1N4007 (1 A, 1000 V) is adequate; UF4007 (fast) better for > 1 Hz Cathode to +24 V, anode to Q1.1 (coil) terminal
DC solenoid / contactor coil Diode + RC snubber in parallel Diode 1N4007; 0.1 µF + 100 Ω in series, across the coil Snubber handles turn-off spike, diode handles turn-on asymmetry
Long cable with relay contactor in line RC snubber at the contact 0.1–1 µF (X2 class) + 47–100 Ω 1 W Directly across the contact terminals (downstream of the PLC)
LED string (the actual load in this fault) RC snubber across the contact, or MOV 0.1 µF + 100 Ω across the S1 aux contact, or 30 V MOV Mounts at the safety-relay terminal block

Recommended configuration for this specific case (LED indicator string switched by a relay aux contact, driven by an S7-1200 transistor output):

S7-1215C CPU Q1.1 Terminal Safety Relay S1 Aux Contact (re-torqued) LED String RC snubber 0.1 µF + 100 Ω 0V

7. Re-energize and verify

  1. Re-apply the 24 VDC control supply to the CPU. Confirm RUN LED is solid green (or solid yellow for STOP, depending on operating mode).
  2. Re-download the project if the SD card did not contain a fully bootable image. Verify in TIA Portal under Online > Accessible Nodes that the new CPU has the correct IP, PROFINET device name, and firmware.
  3. Run the machine in manual mode (no automatic cycles). Force %Q1.1 OFF and ON from the watch table. Verify with a meter at the CPU terminal: 0 V when OFF, 24 V when ON.
  4. Cycle the output 10–20 times at 1 Hz. Watch the output voltage on an oscilloscope if available; the rising edge should be a clean < 100 µs transition to 24 V with no ringing, and the falling edge should be a clean < 1 ms transition to 0 V with no negative spike below −5 V (an RC snubber will clamp the spike to within ±10 V).
  5. Run the production cycle for one full shift. Log the output state and the wiring temperature at the safety-relay terminal. A thermal image of the terminal block before and after the shift should show no more than 5 °C rise over ambient. A loose screw would show 20–40 °C rise.

Verification: Diagnostic Checklist

Check Expected Value Action if Failed
Voltage at Q1.1, output OFF, PLC in STOP 0.0–0.3 VDC Output stage shorted; replace CPU
Voltage at Q1.1, output OFF, PLC in RUN 0.0–0.3 VDC Output stage shorted; replace CPU
Resistance Q1.1 to +24V rail, CPU de-energized > 100 kΩ (typical 500 kΩ – infinite) < 5 Ω = hard short; 5–100 kΩ = degraded; replace CPU
Status LED at Q1.1, output OFF OFF (dark) LED stuck on = logic-driver failure; replace CPU
Status LED at Q1.1, output ON ON (green) LED stuck off = open bond wire or LED damage; replace CPU
Snubber installed across S1 contact 0.1 µF X2 + 100 Ω 1 W Install snubber; this is the root-cause fix
S1 contact terminal torque Per manufacturer spec (0.5–0.8 Nm) Re-torque; inspect for strand damage
Conductor type at S1 Bare copper, stranded, ferrule or directly clamped Cut back to bare copper; replace ferrule if deformed
Output current at Q1.1 under load ≤ 0.3 A continuous Reduce load or split across multiple outputs; 1215C limit is 0.5 A
Leakage current with PLC in STOP ≤ 10 µA (negligible) If a measurable voltage remains with all outputs off, check for back-feeding from the load

Why the Output Failed Even at 0.5 A or Less

The most common misconception is that the S7-1200 output failed because it was overloaded. The actual cause is voltage overstress, not current overstress. Three documented mechanisms can each destroy a transistor output long before the current rating is reached:

  1. Inductive kickback above the avalanche rating. A 0.5 A output interrupted in an inductive circuit can generate peak voltages of several hundred volts. The S7-1200 internal clamp is rated for an inductive load of approximately 1 H at rated current (per the System Manual's switching-frequency derating table). Real-world wiring plus a chattering contact can produce effective inductances and energy levels that exceed this.
  2. Contact arcing energy coupled back through the harness. A relay aux contact that is opening under load produces an arc. The arc's high-frequency content couples through the harness capacitance to the output pin. This dV/dt stress is invisible on a DC voltmeter but visible on a scope and is the primary cause of gate-oxide punch-through in modern MOSFETs.
  3. Thermal cycling of a partially failed junction. Once the junction has been over-avalanche-survivaged once, the damage accumulates. The device may pass a static test for weeks before finally shorting. This is why the field report describes the failure as appearing some time after the wiring was disturbed.

Energy-Budget Calculation for the Failed Channel

To make the failure mode quantitative:

Step 1: Load inductance. Estimate the harness inductance between the CPU and the safety relay panel. A typical control cable has 0.5–1.0 µH per metre of conductor. For a 20 m round trip: L ≈ 0.5 µH/m × 20 m × 2 (there and back) = 20 µH. Add the inductance of the LED string and any local chokes: assume total L = 50 µH.

Step 2: Steady-state current. I = V_LED_string / R_string. A white LED indicator string of 6 LEDs in series, each with a 2.2 kΩ ballast resistor at 24 V: I ≈ 24 V / (6 × 2.2 kΩ) = 1.8 mA — trivial. A more realistic value if the LEDs are higher-current types: I ≈ 0.05–0.3 A. Use 0.2 A as a typical case.

Step 3: Energy per interruption. E = 0.5 × L × I² = 0.5 × 50 × 10⁻⁶ × (0.2)² = 1.0 µJ. That is below the single-pulse avalanche rating of the output MOSFET.

Step 4: Cumulative energy over service life. At one chatter event per minute during a degraded contact, over 90 days: 90 × 24 × 60 = 130,000 events × 1 µJ = 130 mJ cumulative. Combined with the thermal cycling of each event (junction heats briefly, cools briefly), this is enough to age the device past its avalanche-energy rating.

Step 5: The actual failure mode is voltage, not energy. The peak voltage on interruption is V_peak = I × √(L/C), where C is the cable capacitance. For C ≈ 2 nF (1 nF/m × 20 m round trip), V_peak = 0.2 × √(50e-6 / 2e-9) = 0.2 × 158 = 31.6 V. That alone is not destructive. But the dV/dt is V_peak / t_rise, where t_rise is the arc extinction time, on the order of 10–100 ns. dV/dt = 31.6 / 50e-9 = 6.3 × 10⁸ V/s. This is sufficient to induce gate-oxide breakdown on a stressed device, especially when combined with the small dv/dt capacitive coupling from the safety-relay coil (which has its own 50–200 µH of inductance and is being switched by the same CPU indirectly via the safety logic).

Why Tapping the Module Will Not Recover a Transistor Output

The technique of tapping a relay output with a screwdriver handle to free a stuck contact is field-tested and sometimes works because the contact is mechanically jammed. A transistor output has no moving parts. Tapping will not unstick a shorted MOSFET. The repair is replacement of the CPU module, or — at the board level — replacement of the output ASIC. The latter is not Siemens-supported; the supported repair path is whole-unit replacement under warranty or as a billable exchange.

Related Failure Modes to Watch For on the Same Machine

Once one S7-1200 transistor output has failed from this root cause, the other outputs in the same group and on adjacent groups should be inspected:

Channel Likely Load Risk Inspection
Q0.0 – Q0.7 (8 outputs, 4 A group) Indicator lamps, conveyor run permissives, brake releases High — same wiring topology Inspect for snubbers, re-torque aux contacts
Q1.0 (paired with Q1.1 in the same 1 A group) Most likely a similar LED string or relay coil Highest — shares internal driver supply with Q1.1 Static test Q1.0 with output OFF: must read < 0.3 V
Sensor-supply 24 V at terminal L+ / M 3-wire sensors fed from the CPU's 24 V rail Medium — overcurrent on the rail can knock the CPU into fault Measure 24 V under load; should be > 22 V
Digital inputs I0.0 – I1.5 Field devices, safety E-Stops, sensors Low — inputs are protected, not the failure target Verify wiring, check for chattering inputs in the diagnostic buffer
PROFINET port HMI, drive, remote I/O Low Check for diagnostic interrupts in TIA Portal

Preventive Measures for the Whole Machine

  1. Audit every S7-1200 transistor output on the machine for inductive loads. Anything that is or could be inductive (relay coil, solenoid, contactor, brake, long cable to a relay aux contact) must have local suppression. Use the table in Step 6 as a baseline.
  2. Re-torque every field-side screw terminal on the panel to spec. A loose screw is a future failure waiting to happen. Use a torque-limiting screwdriver (Wera, Stahlwille, or similar) and log the torque value on a checklist.
  3. Add a surge suppressor (varistor or TVS) at the CPU terminal block if long field cables are unavoidable. A 30 V TVS (e.g., Littelfuse SMAJ30A) from Q1.1 to 1M clamps transients to within the output's safe operating area.
  4. Consider migrating the indicator lamps to a relay output variant (6ES7215-1HG40-0XB0 has relay outputs on Q0.4–Q0.7 and the on-board Q0.0–Q0.3 are still transistor) or a signal module (SM 1226) that is rated for the application. Relay outputs are far more tolerant of abuse and are the correct choice for indicator lamps in noisy industrial environments.
  5. Update the schematic and the maintenance manual to show the new snubber. A future maintenance technician who sees the snubber in the panel will know it is intentional, not a mistake.
  6. Add a diagnostic alarm in the PLC program that triggers if any digital output is commanded ON but the feedback (from a 24 V sense input wired in parallel with the load, or from the on-board diagnostics) disagrees. This is a watchdog that catches a shorted output before a process upset.

Warranty and Replacement Logistics

For a CPU still within the 24-month warranty period, contact your Siemens regional support or authorized distributor with the serial number, the diagnostic buffer export (TIA Portal > Online > Diagnostics > Save As), and a clear description of the fault. Siemens typically replaces failed units under warranty with a refurbished unit of the same firmware revision. The diagnostic buffer entry to look for is event ID SF: 0x031A (IO fault, output short-circuit) or SF: 0x030A (IO fault, output wire break / open-load), depending on the firmware major revision. These entries are written when the on-board diagnostics detect an anomaly at the output stage; their presence is strong evidence of a hardware failure and is needed for the warranty claim.

Frequently Asked Questions

How do I know if my S7-1215C has transistor or relay outputs without opening the panel?

Check the order number on the front label: 6ES7215-1AG40-0XB0 is DC/DC/DC (transistor), 6ES7215-1BG40-0XB0 is AC/DC/RLY (relay), 6ES7215-1HG40-0XB0 is DC/DC/RLY (mixed, with transistor outputs only on Q0.0–Q0.3). Alternatively, measure between an output terminal and 0V with the PLC unpowered — a reading of 0 Ω to 24V rail (via internal diode) indicates transistor; an open circuit indicates relay.

Can a stuck-on transistor output be cleared without replacing the CPU?

No. A shorted MOSFET inside the S7-1200 output ASIC is a permanent silicon failure. Power cycling, firmware reset, factory reset, and SD-card reformat will not recover it. The CPU must be replaced. Do not attempt repeated output toggling in RUN mode — it can propagate the fault to adjacent channels or the sensor-supply rail.

What is the correct flyback diode for a 24 VDC relay coil driven by an S7-1200 transistor output?

Use a 1N4007 (1 A, 1000 V) for switching frequencies below 1 Hz, or a UF4007 / ES1J (fast-recovery) for higher frequencies. Wire the cathode to +24V and the anode to the CPU output terminal (i.e., directly across the coil, in reverse-bias under steady state). The diode conducts only when the output switches OFF and the coil's magnetic field collapses.

Is a loose screw terminal really enough to destroy a PLC output?

Yes. A loose screw on a load-side contact introduces intermittent contact resistance, micro-arching, and high dV/dt transients. On a sourcing 24 V output, this is the same failure mechanism as unplugging an inductive load under power. The output MOSFET's gate oxide and drain avalanche clamp are not designed to absorb this energy continuously, and the device will eventually fail short. Always re-torque terminals to the manufacturer spec and inspect periodically.

Do I need to reflash the firmware on the replacement CPU?

Not necessarily if the new CPU ships with the same firmware version as the failed one — TIA Portal will download the project. If the firmware on the replacement is newer, you must update the TIA Portal project to the new firmware (project right-click > Change device > select newer CPU) before downloading, or the download will fail. The SD card from the old CPU can also be inserted into the new CPU to transfer the project and firmware, but always verify with a full online comparison after the swap.

Where can I find the official Siemens documentation for the 1215C output specifications?

The S7-1200 Programmable Controller System Manual is the primary reference. The S7-1200 Function Manual and the CPU-specific datasheet (downloadable from the Siemens Industry Online Support portal) contain the per-channel current limits, the inductive-load switching-frequency derating, and the diagnostic buffer event IDs. The 1215C is also documented in the TIA Portal Help system under "S7-1200 CPU 1215C".

Back to blog