Problem Description: Erratic IW Readings from FM350-2
A Siemens FM350-2 counter module on a SIMATIC S7-400 (CPU 416-3) returns measured speed values through the process input image (PIW/IW) that diverge wildly from the values shown by the FM350-2 commissioning tool. In a documented field case, a third FM350-2 station reading three 1000-PPR encoders reported values swinging from ~1 to ~9000 ×10⁻³ rpm while the machine actually ran at a steady 190 rpm (190000 ×10⁻³ rpm in the module's native milli-rpm format). Two companion FM350-2 stations on the same ET 200M rack, one reading a single 2500-PPR encoder and one reading three 2500-PPR encoders, returned stable readings through the same program logic.
Initial troubleshooting attempts included moving the read block from OB1 (cyclic) into OB35 (100 ms), then shortening the OB35 time window to 50 ms and 10 ms. None of these changes corrected the swing. Direct PIW access in VAT (Variable Table) returned the same incorrect values, which confirmed the problem was not in the application code but in how the module's measured values were being exposed to the CPU.
Hardware and Software Configuration
The reported topology is a standard S7-400 high-availability automation cell:
- CPU: SIMATIC S7-400, CPU 416-3 (order number 6ES7416-3ES06-0AB0 or equivalent generation). One central processor handles three decentralized stations.
- Decentralization: Three ET 200M stations, each holding one FM350-2 counter module.
- FM350-2 modules: 6ES7350-2AH01-0AE0 (8-channel counter/frequency module, 24 V variant) or 6ES7350-2AH03-0AE0 (updated version). Each module occupies 8 bytes of I/O and supports up to eight channels.
- Encoder wiring:
- Station 1: 1 × 2500-PPR encoder on channel 0 — correct readings
- Station 2: 3 × 2500-PPR encoders on channels 0–2 — correct readings
- Station 3: 3 × 1000-PPR encoders on channels 0–2 — faulting
- STEP 7 / PCS 7: Program reads measured values through FB127 (PCS 7 Library "FM350-2") and through direct I/O access (PIW) inside OB1 and OB35.
The fact that the problem only appeared on the station whose combination of PPR count and channel count interacted unfavorably with the read method is the key diagnostic clue. The other stations worked because their read path matched the module's allowed access pattern.
Root Cause Analysis
Direct I/O Access to the FM350-2 Is Limited to Two or Four Channels
The FM350-2 does not expose all eight counters through the process image by default. According to Siemens Support entry ID 12159065, the FM350-2 permits a maximum of four measured or count values to be displayed directly on the module I/O. The number of channels that can be served through direct PIW access is selected in HW Config with the "Specify direct I/O access" property:
| User Type Setting | Channels Exposed to PIW | Value Range per Channel | Maximum Frequency |
|---|---|---|---|
| DWORD (32-bit) | 2 | 0 to 4 294 967 295 counts / full range | 500 kHz (encoder input) |
| WORD (16-bit) | 4 | 0 to 65 535 (×10⁻³ rpm = 65.535 rpm max) | 500 kHz |
| No direct I/O access | 0 | n/a (FC-based access only) | n/a |
When FB127 from the PCS 7 Library is used, the user type is fixed to DWORD to accommodate the full 32-bit range of the count value. This reduces the maximum number of simultaneously exposed channels from the theoretical eight down to two. Any attempt to read channels beyond the first two through PIW returns values from adjacent or uninitialized memory, which appears in the user program as the wild swinging observed in the field case.
The 65.535 rpm Ceiling on Four-Channel Direct Access
When the four-channel mode is selected (16-bit user type), the maximum representable speed per channel is 65 535 × 10⁻³ rpm = 65.535 rpm. Encoders whose computed speed exceeds this value wrap modulo 65 536, producing the appearance of a wildly fluctuating reading even when the shaft speed is constant. This ceiling is independent of PPR; it is a function of the integer width selected for direct I/O access. To raise the ceiling to the full DWORD range, the user must accept the two-channel exposure limit or abandon direct PIW access in favor of the FM350 library FCs.
Time Window and OB Cycle Interaction
The FM350-2 internal measurement is updated at the end of every configured integration time window (gate time). If the user program reads the PIW before the module has latched a new measured value, the previous latch is returned. When the integration window is long and the OB cycle is short, the user code can read the same latched value many times; when the OB cycle exceeds the integration window, the read occasionally catches a fresh value and occasionally catches a stale one. The mismatch between OB1 (typically 10–100 ms on a 416-3), OB35 (100 ms), and the FM350-2 gate time (default 10 ms in many configurations) is what produced the ~9000 ×10⁻³ rpm peaks in the field case: the read was catching the latch in transition.
PPR and Frequency Relationship
The FM350-2 measures frequency f in Hz from the encoder pulses per integration window T:
f = N / T, where N is the count of pulses captured during the integration window T in seconds.
The shaft speed in rpm is then:
n = (60 × f) / PPR = (60 × N) / (T × PPR)
With the same shaft speed, a 1000-PPR encoder produces 2.5× fewer pulses per second than a 2500-PPR encoder. The FM350-2 firmware compensates for this by extending the effective gate time or scaling the result; however, at low pulse densities the absolute count N captured in one short integration window is small, so quantization noise and the read-timing window above have a proportionally larger effect on the reported value. This is why the 1000-PPR station with three encoders appeared to swing while the 2500-PPR stations looked clean: less pulse density means the user program's read cadence interacts with the module's internal gating more aggressively.
Resolution: Switch from Direct PIW to FM350 Library FCs
Siemens Support resolved the field case (Entry ID 19734436, "How do you interconnect an FM350-2 in PCS 7?") by replacing direct PIW access with the FC blocks from the FM350-2 function library. The FC family handles latch capture, scaling, and DB mirroring inside the module's firmware-aware code path, eliminating the user's exposure to the channel-count and value-range limits of the direct I/O window.
Required Function Blocks
The FM350-2 ships with a library of FBs/FCs accessible from STEP 7 → Libraries → FM350-2. For an 8-channel module configured for frequency measurement, the relevant blocks are:
| Block | Function | Call Site |
|---|---|---|
| FC 0 (CNTR_INIT) | Initializes the module after parameter assignment | Startup (OB100) once |
| FC 1 (CNT_CTL1) | Reads/writes control bits and process data | Cyclic, e.g. OB35 |
| FC 2 (CNT_CTL2) | Sets comparator and load values | On demand |
| FC 3 (CNT_RDWR) | Reads/writes per-channel data | Cyclic |
| FC 4 (CNT_RDOP) | Reads operating data, error counters, measured values | Cyclic, OB35 |
| FC 5 (CNT_RDLD) | Reads load values | On demand |
| FC 6 (CNT_DIAG) | Reads diagnostic data | On error |
| FC 7 (CNT_SET_DIAG) | Acknowledge / configure diagnostic interrupts | OB82 handler |
| FB 1 (CNT_CHAN) | Multi-instance wrapper around the FCs for one channel | Cyclic, per channel |
Configuration Procedure
- Open HW Config and select the FM350-2 in the ET 200M slot. In the module properties, set "Specify direct I/O access" to 0 channels (or "No") to free the entire 8-byte I/O area for the FC interface. This change is required if the application needs more than two channels at full DWORD range.
- Assign module parameters for each channel: measuring mode = frequency; gate time = 100 ms (increase for low-frequency signals to improve quantization); encoder type = 24 V incremental per the wiring; evaluation = ×1, ×2, or ×4 as required.
- Compile and download the HW Config to the CPU. The module's input bytes (addresses as configured) now carry only status, control, and handshake data, not the measured values themselves.
- Insert the FM350-2 library into the STEP 7 project: Options → Install Library → select "FM350-2" from the supplied CD or the Siemens support portal. The library appears under "FM350-2" in the Libraries tree.
- Create an instance DB (e.g., DB200) for each FB 1 instance. FB 1 encapsulates per-channel state. Multi-instantiate FB 1 eight times inside a higher-level FB to cover all eight channels.
- Call FC 0 (CNTR_INIT) in OB100 (or OB101 for restart) with the module's logical base address. The FC performs a software reset and applies the current HW Config parameters.
-
Call FC 4 (CNT_RDOP) in OB35 to read the operating data block into the instance DB. The measured frequency for each channel is now in
DBxx.CHx_FREQUENCY(DWORD, mHz) or the corresponding scaled rpm field, depending on parameter assignment. - Replace the direct PIW read in the user program with a load from the instance DB. Values returned through the FC path are latched consistently and are not subject to the 65.535 rpm ceiling.
- Increase OB35 cycle time to at least 2× the gate time configured on the module. With a 100 ms gate, an OB35 of 200 ms or 500 ms gives the module time to settle before the next read.
- Download all blocks and verify in the FM350-2 commissioning tool that the value shown there matches the value the user program sees from the instance DB.
Working Sample: Reading Channel 0 Frequency via FC4
The following structured-text excerpt shows the typical pattern for reading a frequency into a user-visible tag without direct PIW access:
// OB35, 200 ms cycle
// Module base address = 512 (decimal), placed in DB200.DBD0
CALL FC 4 // CNT_RDOP
DB_NO := 200
RET_VAL := MW 100
// After the call, DB200 contains the full channel state.
// DB200.DBD 50 = Frequency of channel 0 in mHz (DWORD)
// DB200.DBD 54 = Frequency of channel 1 in mHz
// ... and so on for channels 2..7
L DB200.DBD 50
ITD
DTR
L 1.000000e+002
/ R // Scale mHz to rpm if needed
T MD 200 // Application-visible rpm for channel 0
The exact offset of the frequency field in the instance DB depends on the FB 1 version and the parameter assignment chosen for the channel. The official FM350-2 operating instructions PDF lists the byte map for every channel layout.
Verification Procedure
- Commissioning tool cross-check: In STEP 7, open the FM350-2 online → Commissioning. Read the displayed rpm for each channel while the machine runs at a stable setpoint. Compare to the value the user program reads from the instance DB. Acceptable deviation is within the gate-time quantization step.
- Diagnostic buffer clean: In the CPU's diagnostic buffer, confirm no FM350-2 diagnostic interrupts have been raised. A clean buffer confirms HW Config and module firmware are consistent.
- LED inspection on FM350-2: The SF (red) LED must be off. The channel status LEDs should pulse at a rate proportional to the input frequency. A solid SF LED indicates a parameter mismatch or wire break; a flashing SF indicates a diagnostic event pending.
- Trend record: Insert a trend in WinCC (or PCS 7 OS) recording the FC-supplied rpm value across at least 60 s. The trace must show a stable, smooth line. Any oscillation exceeding one quantization step means the gate time is still too short or the OB cycle is still mismatched.
- OB82 diagnostic interrupt test: Withdraw and re-insert the FM350-2 to force a diagnostic interrupt. Confirm that FC 7 is wired into OB82 and that the diagnostic information is written to the configured diagnostic DB. This verifies the FC path is wired all the way through the OB structure.
- Channel-count validation: If the application legitimately needs more than four channels at the same time, confirm that "Specify direct I/O access" is set to 0 channels and that no code path reads PIW for the measured values. Any residual direct PIW read reintroduces the swing.
Parameter Reference
| Parameter | Setting | Effect on Behavior |
|---|---|---|
| Direct I/O access = 0 channels | Default for FC-based access | All 8 channels accessible via FC; no rpm ceiling from PIW width |
| Direct I/O access = 2 channels, DWORD | Used with FB127 PCS 7 | Two channels at full DWORD range; six channels require FC |
| Direct I/O access = 4 channels, WORD | Legacy direct access | Four channels limited to 65 535 ×10⁻³ rpm |
| Gate time = 10 ms | Default | Fast update, lower resolution per gate |
| Gate time = 100 ms | Recommended for 1000-PPR, low-speed encoders | 10× better resolution; OB must cycle slower than 100 ms |
| Gate time = 1000 ms | Very low speed / high precision | Best quantization; OB cycle up to 1 s acceptable |
| OB35 cycle = 200 ms with 100 ms gate | Recommended | Module always latches before user read; no stale value |
| OB35 cycle = 10 ms with 100 ms gate | Fault case | Same value read many times; sensitive to PPIW offset |
| Encoder evaluation ×4 | Quadrature decoding | Effective PPR × 4; raises pulse density 4× without changing hardware |
Common Pitfalls
- Mixing FB127 and direct PIW reads on the same module. FB127 occupies the first 8 bytes of the I/O area for its own handshake. Reading PIW at addresses that overlap with FB127's data window returns FB127's internal state, not measured values, which appears as garbage.
- Calling FC 0 outside OB100. A second CNTR_INIT call after the module has already started resets the counters and load values. Call it once at startup and never again unless the application explicitly needs to reinitialize.
- OB35 shorter than the gate time. The OB must be slower than the gate, not faster. Setting OB35 to 10 ms when the gate is 100 ms means every cycle reads the same latch and the OB becomes the bottleneck rather than the module.
- Confusing the 65.535 rpm ceiling with an encoder fault. A user who switches from 4-channel WORD to 2-channel DWORD mode without realizing that the ceiling is lifted will think the encoder is now broken because the value jumps above 65.535. The value is now correct; the previous value was clipping.
- Forgetting to set the user type to DWORD for FB127. FB127 from the PCS 7 Library expects DWORD values. If the HW Config user type is left at WORD, FB127 reads the lower 16 bits twice and reports the high 16 bits as zero, producing a constant low reading.
- Not wiring FC 7 into OB82. When a diagnostic interrupt occurs, the module sets SF and waits for the diagnostic DB to be populated. Without FC 7 in OB82, the diagnostic data is never acked and the module stays in diagnostic state indefinitely.
- Using OB1 only and ignoring OB35. OB1's cycle time on a 416-3 is variable depending on the user program length. Using OB35 with a fixed time base removes the variability and makes the swing either present or absent based only on the OB period.
Related Siemens Documentation
- FM 350-2 Counter Module — Operating Instructions (Siemens Support PDF) — primary reference for FCs, parameter blocks, and byte maps.
- Using FM 350-2 (S7-300, S7-400) — TIA Portal Documentation — covers front connector assignment, HW Config, and F-parameter assignment.
- Specifying Direct I/O Access to the FM 350-2, 2 Channels (Entry ID 12159065) — authoritative limit on channel count and value range exposed through PIW.
FAQ
Why do PIW readings from the FM350-2 swing wildly while the commissioning tool shows a stable rpm?
Direct PIW access on the FM350-2 is limited to 2 channels at full DWORD range or 4 channels at WORD range (Entry ID 12159065). With FB127 from the PCS 7 Library the user type is DWORD, so only the first two channels are valid through PIW. Reads beyond that expose internal state or uninitialized memory. Switch to the FM350-2 library FCs (FC 4 / FB 1) to read all eight channels via an instance DB.
What is the maximum speed readable through direct I/O access on the FM350-2?
In 4-channel WORD mode the ceiling is 65 535 ×10⁻³ rpm = 65.535 rpm per channel. In 2-channel DWORD mode the ceiling is the full DWORD range (4 294 967 295 counts). To exceed 65.535 rpm on more than two channels, set "Specify direct I/O access" to 0 channels and read via the FM350-2 FC library.
Which OB and time window should I use to read the FM350-2?
Use OB35 with a period at least twice the FM350-2 gate time. For a 100 ms gate, OB35 at 200 ms or 500 ms is typical. Faster OB cycles (10–50 ms) with a long gate cause the user program to read the same latched value many times, and any read that lands between latches can return a transitional value that looks like a fault.
Do I need to call FC 0 (CNTR_INIT) on every restart?
Yes. Call FC 0 in OB100 (warm restart) or OB101 (hot restart) so that the module is re-initialized with the parameters from HW Config. Avoid calling FC 0 in cyclic OBs because it resets the counters and load values each call.
Can I use FB127 from PCS 7 and read more than two channels?
No. FB127 in the PCS 7 Library fixes the user type to DWORD, which limits direct I/O exposure to two channels. For three or more channels, supplement FB127 with the FM350-2 library FCs (FC 1, FC 3, FC 4) and store the additional channel values in an instance DB.