FM350-2 Resolving Incorrect IW Readings and Value Swing on S7-400

David Krause14 min read
S7-400SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Description: Erratic IW Readings from FM350-2

A Siemens FM350-2 counter module on a SIMATIC S7-400 (CPU 416-3) returns measured speed values through the process input image (PIW/IW) that diverge wildly from the values shown by the FM350-2 commissioning tool. In a documented field case, a third FM350-2 station reading three 1000-PPR encoders reported values swinging from ~1 to ~9000 ×10⁻³ rpm while the machine actually ran at a steady 190 rpm (190000 ×10⁻³ rpm in the module's native milli-rpm format). Two companion FM350-2 stations on the same ET 200M rack, one reading a single 2500-PPR encoder and one reading three 2500-PPR encoders, returned stable readings through the same program logic.

Initial troubleshooting attempts included moving the read block from OB1 (cyclic) into OB35 (100 ms), then shortening the OB35 time window to 50 ms and 10 ms. None of these changes corrected the swing. Direct PIW access in VAT (Variable Table) returned the same incorrect values, which confirmed the problem was not in the application code but in how the module's measured values were being exposed to the CPU.

Symptom signature: FM350-2 commissioning tool reports a stable rpm value; PIW read in the user program or VAT swings across nearly the entire measurement range; OB1 and OB35 cycle time changes do not resolve the swing; only a subset of stations on the same rack show the fault.

Hardware and Software Configuration

The reported topology is a standard S7-400 high-availability automation cell:

  • CPU: SIMATIC S7-400, CPU 416-3 (order number 6ES7416-3ES06-0AB0 or equivalent generation). One central processor handles three decentralized stations.
  • Decentralization: Three ET 200M stations, each holding one FM350-2 counter module.
  • FM350-2 modules: 6ES7350-2AH01-0AE0 (8-channel counter/frequency module, 24 V variant) or 6ES7350-2AH03-0AE0 (updated version). Each module occupies 8 bytes of I/O and supports up to eight channels.
  • Encoder wiring:
    • Station 1: 1 × 2500-PPR encoder on channel 0 — correct readings
    • Station 2: 3 × 2500-PPR encoders on channels 0–2 — correct readings
    • Station 3: 3 × 1000-PPR encoders on channels 0–2 — faulting
  • STEP 7 / PCS 7: Program reads measured values through FB127 (PCS 7 Library "FM350-2") and through direct I/O access (PIW) inside OB1 and OB35.

The fact that the problem only appeared on the station whose combination of PPR count and channel count interacted unfavorably with the read method is the key diagnostic clue. The other stations worked because their read path matched the module's allowed access pattern.

Root Cause Analysis

Direct I/O Access to the FM350-2 Is Limited to Two or Four Channels

The FM350-2 does not expose all eight counters through the process image by default. According to Siemens Support entry ID 12159065, the FM350-2 permits a maximum of four measured or count values to be displayed directly on the module I/O. The number of channels that can be served through direct PIW access is selected in HW Config with the "Specify direct I/O access" property:

User Type Setting Channels Exposed to PIW Value Range per Channel Maximum Frequency
DWORD (32-bit) 2 0 to 4 294 967 295 counts / full range 500 kHz (encoder input)
WORD (16-bit) 4 0 to 65 535 (×10⁻³ rpm = 65.535 rpm max) 500 kHz
No direct I/O access 0 n/a (FC-based access only) n/a

When FB127 from the PCS 7 Library is used, the user type is fixed to DWORD to accommodate the full 32-bit range of the count value. This reduces the maximum number of simultaneously exposed channels from the theoretical eight down to two. Any attempt to read channels beyond the first two through PIW returns values from adjacent or uninitialized memory, which appears in the user program as the wild swinging observed in the field case.

The 65.535 rpm Ceiling on Four-Channel Direct Access

When the four-channel mode is selected (16-bit user type), the maximum representable speed per channel is 65 535 × 10⁻³ rpm = 65.535 rpm. Encoders whose computed speed exceeds this value wrap modulo 65 536, producing the appearance of a wildly fluctuating reading even when the shaft speed is constant. This ceiling is independent of PPR; it is a function of the integer width selected for direct I/O access. To raise the ceiling to the full DWORD range, the user must accept the two-channel exposure limit or abandon direct PIW access in favor of the FM350 library FCs.

Time Window and OB Cycle Interaction

The FM350-2 internal measurement is updated at the end of every configured integration time window (gate time). If the user program reads the PIW before the module has latched a new measured value, the previous latch is returned. When the integration window is long and the OB cycle is short, the user code can read the same latched value many times; when the OB cycle exceeds the integration window, the read occasionally catches a fresh value and occasionally catches a stale one. The mismatch between OB1 (typically 10–100 ms on a 416-3), OB35 (100 ms), and the FM350-2 gate time (default 10 ms in many configurations) is what produced the ~9000 ×10⁻³ rpm peaks in the field case: the read was catching the latch in transition.

Diagnostic clue: A user-reported "swing" that disappears when the integration time is lengthened to exceed several OB cycles is almost always a latch/cycle mismatch, not a wiring or encoder fault. Counter faults caused by wiring or PPR produce step changes, not bounded oscillation.

PPR and Frequency Relationship

The FM350-2 measures frequency f in Hz from the encoder pulses per integration window T:

f = N / T, where N is the count of pulses captured during the integration window T in seconds.

The shaft speed in rpm is then:

n = (60 × f) / PPR = (60 × N) / (T × PPR)

With the same shaft speed, a 1000-PPR encoder produces 2.5× fewer pulses per second than a 2500-PPR encoder. The FM350-2 firmware compensates for this by extending the effective gate time or scaling the result; however, at low pulse densities the absolute count N captured in one short integration window is small, so quantization noise and the read-timing window above have a proportionally larger effect on the reported value. This is why the 1000-PPR station with three encoders appeared to swing while the 2500-PPR stations looked clean: less pulse density means the user program's read cadence interacts with the module's internal gating more aggressively.

Resolution: Switch from Direct PIW to FM350 Library FCs

Siemens Support resolved the field case (Entry ID 19734436, "How do you interconnect an FM350-2 in PCS 7?") by replacing direct PIW access with the FC blocks from the FM350-2 function library. The FC family handles latch capture, scaling, and DB mirroring inside the module's firmware-aware code path, eliminating the user's exposure to the channel-count and value-range limits of the direct I/O window.

Required Function Blocks

The FM350-2 ships with a library of FBs/FCs accessible from STEP 7 → Libraries → FM350-2. For an 8-channel module configured for frequency measurement, the relevant blocks are:

Block Function Call Site
FC 0 (CNTR_INIT) Initializes the module after parameter assignment Startup (OB100) once
FC 1 (CNT_CTL1) Reads/writes control bits and process data Cyclic, e.g. OB35
FC 2 (CNT_CTL2) Sets comparator and load values On demand
FC 3 (CNT_RDWR) Reads/writes per-channel data Cyclic
FC 4 (CNT_RDOP) Reads operating data, error counters, measured values Cyclic, OB35
FC 5 (CNT_RDLD) Reads load values On demand
FC 6 (CNT_DIAG) Reads diagnostic data On error
FC 7 (CNT_SET_DIAG) Acknowledge / configure diagnostic interrupts OB82 handler
FB 1 (CNT_CHAN) Multi-instance wrapper around the FCs for one channel Cyclic, per channel

Configuration Procedure

  1. Open HW Config and select the FM350-2 in the ET 200M slot. In the module properties, set "Specify direct I/O access" to 0 channels (or "No") to free the entire 8-byte I/O area for the FC interface. This change is required if the application needs more than two channels at full DWORD range.
  2. Assign module parameters for each channel: measuring mode = frequency; gate time = 100 ms (increase for low-frequency signals to improve quantization); encoder type = 24 V incremental per the wiring; evaluation = ×1, ×2, or ×4 as required.
  3. Compile and download the HW Config to the CPU. The module's input bytes (addresses as configured) now carry only status, control, and handshake data, not the measured values themselves.
  4. Insert the FM350-2 library into the STEP 7 project: Options → Install Library → select "FM350-2" from the supplied CD or the Siemens support portal. The library appears under "FM350-2" in the Libraries tree.
  5. Create an instance DB (e.g., DB200) for each FB 1 instance. FB 1 encapsulates per-channel state. Multi-instantiate FB 1 eight times inside a higher-level FB to cover all eight channels.
  6. Call FC 0 (CNTR_INIT) in OB100 (or OB101 for restart) with the module's logical base address. The FC performs a software reset and applies the current HW Config parameters.
  7. Call FC 4 (CNT_RDOP) in OB35 to read the operating data block into the instance DB. The measured frequency for each channel is now in DBxx.CHx_FREQUENCY (DWORD, mHz) or the corresponding scaled rpm field, depending on parameter assignment.
  8. Replace the direct PIW read in the user program with a load from the instance DB. Values returned through the FC path are latched consistently and are not subject to the 65.535 rpm ceiling.
  9. Increase OB35 cycle time to at least 2× the gate time configured on the module. With a 100 ms gate, an OB35 of 200 ms or 500 ms gives the module time to settle before the next read.
  10. Download all blocks and verify in the FM350-2 commissioning tool that the value shown there matches the value the user program sees from the instance DB.

Working Sample: Reading Channel 0 Frequency via FC4

The following structured-text excerpt shows the typical pattern for reading a frequency into a user-visible tag without direct PIW access:


// OB35, 200 ms cycle
// Module base address = 512 (decimal), placed in DB200.DBD0
CALL FC 4 // CNT_RDOP
  DB_NO   := 200
  RET_VAL := MW 100
// After the call, DB200 contains the full channel state.
// DB200.DBD 50 = Frequency of channel 0 in mHz (DWORD)
// DB200.DBD 54 = Frequency of channel 1 in mHz
// ... and so on for channels 2..7
L     DB200.DBD 50
ITD
DTR
L     1.000000e+002
/ R                   // Scale mHz to rpm if needed
T     MD 200          // Application-visible rpm for channel 0

The exact offset of the frequency field in the instance DB depends on the FB 1 version and the parameter assignment chosen for the channel. The official FM350-2 operating instructions PDF lists the byte map for every channel layout.

Verification Procedure

  1. Commissioning tool cross-check: In STEP 7, open the FM350-2 online → Commissioning. Read the displayed rpm for each channel while the machine runs at a stable setpoint. Compare to the value the user program reads from the instance DB. Acceptable deviation is within the gate-time quantization step.
  2. Diagnostic buffer clean: In the CPU's diagnostic buffer, confirm no FM350-2 diagnostic interrupts have been raised. A clean buffer confirms HW Config and module firmware are consistent.
  3. LED inspection on FM350-2: The SF (red) LED must be off. The channel status LEDs should pulse at a rate proportional to the input frequency. A solid SF LED indicates a parameter mismatch or wire break; a flashing SF indicates a diagnostic event pending.
  4. Trend record: Insert a trend in WinCC (or PCS 7 OS) recording the FC-supplied rpm value across at least 60 s. The trace must show a stable, smooth line. Any oscillation exceeding one quantization step means the gate time is still too short or the OB cycle is still mismatched.
  5. OB82 diagnostic interrupt test: Withdraw and re-insert the FM350-2 to force a diagnostic interrupt. Confirm that FC 7 is wired into OB82 and that the diagnostic information is written to the configured diagnostic DB. This verifies the FC path is wired all the way through the OB structure.
  6. Channel-count validation: If the application legitimately needs more than four channels at the same time, confirm that "Specify direct I/O access" is set to 0 channels and that no code path reads PIW for the measured values. Any residual direct PIW read reintroduces the swing.

Parameter Reference

Parameter Setting Effect on Behavior
Direct I/O access = 0 channels Default for FC-based access All 8 channels accessible via FC; no rpm ceiling from PIW width
Direct I/O access = 2 channels, DWORD Used with FB127 PCS 7 Two channels at full DWORD range; six channels require FC
Direct I/O access = 4 channels, WORD Legacy direct access Four channels limited to 65 535 ×10⁻³ rpm
Gate time = 10 ms Default Fast update, lower resolution per gate
Gate time = 100 ms Recommended for 1000-PPR, low-speed encoders 10× better resolution; OB must cycle slower than 100 ms
Gate time = 1000 ms Very low speed / high precision Best quantization; OB cycle up to 1 s acceptable
OB35 cycle = 200 ms with 100 ms gate Recommended Module always latches before user read; no stale value
OB35 cycle = 10 ms with 100 ms gate Fault case Same value read many times; sensitive to PPIW offset
Encoder evaluation ×4 Quadrature decoding Effective PPR × 4; raises pulse density 4× without changing hardware

Common Pitfalls

  • Mixing FB127 and direct PIW reads on the same module. FB127 occupies the first 8 bytes of the I/O area for its own handshake. Reading PIW at addresses that overlap with FB127's data window returns FB127's internal state, not measured values, which appears as garbage.
  • Calling FC 0 outside OB100. A second CNTR_INIT call after the module has already started resets the counters and load values. Call it once at startup and never again unless the application explicitly needs to reinitialize.
  • OB35 shorter than the gate time. The OB must be slower than the gate, not faster. Setting OB35 to 10 ms when the gate is 100 ms means every cycle reads the same latch and the OB becomes the bottleneck rather than the module.
  • Confusing the 65.535 rpm ceiling with an encoder fault. A user who switches from 4-channel WORD to 2-channel DWORD mode without realizing that the ceiling is lifted will think the encoder is now broken because the value jumps above 65.535. The value is now correct; the previous value was clipping.
  • Forgetting to set the user type to DWORD for FB127. FB127 from the PCS 7 Library expects DWORD values. If the HW Config user type is left at WORD, FB127 reads the lower 16 bits twice and reports the high 16 bits as zero, producing a constant low reading.
  • Not wiring FC 7 into OB82. When a diagnostic interrupt occurs, the module sets SF and waits for the diagnostic DB to be populated. Without FC 7 in OB82, the diagnostic data is never acked and the module stays in diagnostic state indefinitely.
  • Using OB1 only and ignoring OB35. OB1's cycle time on a 416-3 is variable depending on the user program length. Using OB35 with a fixed time base removes the variability and makes the swing either present or absent based only on the OB period.

Related Siemens Documentation

FAQ

Why do PIW readings from the FM350-2 swing wildly while the commissioning tool shows a stable rpm?

Direct PIW access on the FM350-2 is limited to 2 channels at full DWORD range or 4 channels at WORD range (Entry ID 12159065). With FB127 from the PCS 7 Library the user type is DWORD, so only the first two channels are valid through PIW. Reads beyond that expose internal state or uninitialized memory. Switch to the FM350-2 library FCs (FC 4 / FB 1) to read all eight channels via an instance DB.

What is the maximum speed readable through direct I/O access on the FM350-2?

In 4-channel WORD mode the ceiling is 65 535 ×10⁻³ rpm = 65.535 rpm per channel. In 2-channel DWORD mode the ceiling is the full DWORD range (4 294 967 295 counts). To exceed 65.535 rpm on more than two channels, set "Specify direct I/O access" to 0 channels and read via the FM350-2 FC library.

Which OB and time window should I use to read the FM350-2?

Use OB35 with a period at least twice the FM350-2 gate time. For a 100 ms gate, OB35 at 200 ms or 500 ms is typical. Faster OB cycles (10–50 ms) with a long gate cause the user program to read the same latched value many times, and any read that lands between latches can return a transitional value that looks like a fault.

Do I need to call FC 0 (CNTR_INIT) on every restart?

Yes. Call FC 0 in OB100 (warm restart) or OB101 (hot restart) so that the module is re-initialized with the parameters from HW Config. Avoid calling FC 0 in cyclic OBs because it resets the counters and load values each call.

Can I use FB127 from PCS 7 and read more than two channels?

No. FB127 in the PCS 7 Library fixes the user type to DWORD, which limits direct I/O exposure to two channels. For three or more channels, supplement FB127 with the FM350-2 library FCs (FC 1, FC 3, FC 4) and store the additional channel values in an instance DB.

Back to blog