1. Overview: What "Online Editing" Actually Means on S7-300/400
Siemens SIMATIC S7-300 and S7-400 CPUs (programmed with STEP 7 V5.5) support online modifications to the user program, data blocks, and monitored variables while the CPU remains in RUN. The critical engineering point is that not every change is safe to apply online. The most common operations an automation engineer or process operator will perform online fall into four categories:
- Editing values in Watch / Variable (VAT) tables without downloading to the CPU.
- Force of inputs and outputs from a Force table.
- Download of logic blocks (OB/FB/FC/DB) to the running CPU.
- Download of hardware configuration (HW Config) – only supported in RUN on S7-400 CPUs with Configuration in Run (CIR) or on an H-CPU redundant pair.
Modifications to a running CPU that violate a programming error (e.g., call a non-existent DB, divide by zero, access a missing I/O) will trigger a STOP unless the corresponding error OB is present and downloaded. The first section of this reference is therefore the prerequisite for every other online change.
2. Prerequisites Before Any Online Change
Before opening STEP 7 V5.5 and downloading to a live pharmaceutical process, verify each of the following. Each is a precondition for a no-stop online change.
-
Identify the CPU family and firmware. S7-300 CPUs (312, 314, 315, 317, 319) and S7-400 CPUs (412, 414, 416, 417, 410) behave differently for hardware CIR. Confirm with
PLC > Module Information > Diagnostic Buffer. - Confirm the load memory type. S7-300 can use RAM (volatile) or MMC (Flash, non-volatile, mandatory on newer -3PN/DP CPUs). S7-400 uses a memory card (RAM or Flash) or, on the H-CPU, a paired card. Online block changes are written to work memory immediately and to load memory on the next backup, but the difference matters for cold-restart behavior.
-
Verify error OBs are present and loaded. Open
S7 Program > Blocksoffline and confirm that all needed error OBs exist (see Section 3). -
Connect the programming PG/PC via MPI, PROFIBUS, or Industrial Ethernet and reach the CPU through
Accessible Nodesor a configured online interface. Use the Siemens Online Support entry for STEP 7 V5.5 SP2 for the supported interface catalog. -
Take a backup of the offline project (
File > Archive) and a CPU backup (PLC > Upload Station to PG) before any modification. In a GxP environment this backup is your audit record.
3. Mandatory Error OBs for Online Editing
STEP 7 generates an OB for every error class that can otherwise drop the CPU into STOP. The following OBs must be present in the offline program and downloaded to the CPU before you start online block editing.
| OB | Triggered by | Purpose |
|---|---|---|
| OB80 | Time error | Catches OB request faults (e.g., synchronous OB call overflow). |
| OB82 | Diagnostic interrupt | Handles module diagnostic events; required for many I/O modules. |
| OB85 | Program execution error | Triggered when a module is missing or a slot is unconfigured. |
| OB86 | Loss of rack / DP slave / IO device failure | Required for distributed I/O (PROFIBUS DP / PROFINET IO). |
| OB87 | Communication error | Triggered by communication configuration faults. |
| OB100 | Warm restart | Startup routine; loads process image defaults. |
| OB101 | Hot restart | S7-400 only; resumes execution at the interruption point. |
| OB102 | Cold restart | Resets process image and retentive data. |
| OB121 | Programming error (BIE = 0) | Triggered by BCD conversion errors, illegal data types, or missing DB when a called DB was just deleted or not yet downloaded. |
| OB122 | I/O access error | Triggered when the program accesses a slot that has no module or a faulty one. |
OB121 and OB122 are the two OBs most often not present in legacy pharmaceutical projects. Their absence is the single most common reason that an online DB download pushes the CPU into STOP: the new logic tries to open DB 50, the old DB 50 was deleted, and OB121 does not exist, so the CPU faults.
3.1 Download Order for Safe Online Block Changes
- Download the DBs first (in increasing number order is safest).
- Download the FCs/FBs that call those DBs.
- Download OBs last if any new OBs (e.g., OB121) are required.
- Never download HW Config to a non-CIR/non-H CPU in RUN.
- Verify in
Module Information > Diagnostic Bufferafter each download that the CPU remains in RUN.
4. Using Watch / Variable Tables (VAT) for Online Value Changes
A Variable Table (VAT) – known as a Watch Table in TIA Portal – is the lowest-risk tool for changing a value online. The table is held in the PG, not the CPU; nothing is downloaded to the load memory. The VAT directly reads and writes the process image and data-block areas of the working memory.
4.1 Creating and Populating a VAT
- In the STEP 7 project, right-click
Blocksand chooseInsert New Object > Variable Table. - Name the VAT to reflect its intent (e.g.,
VAT_Recipe_Setpoints). In GxP contexts use a name that appears in the change-control record. - Add operands in the format:\pre> Address Symbol Display format Modify value DB101.DBD0 BatchSize FLOAT 1250.0 DB101.DBD4 FillRate FLOAT 42.5 M 0.1 RunEnable BOOL TRUE IW 64 PressPSI DEC 38 QW 80 ValvePct DEC 55
- Click
Monitor/Modifyon the toolbar, choose Trigger (once, periodic, or on a defined point), and clickModifyto write values.
4.2 Modify Trigger Settings
| Trigger | Behavior | Typical use |
|---|---|---|
| Once | Writes value at the next CPU scan boundary. | Setpoint change, mode bit. |
| Periodic | Writes value every N seconds (configurable in VAT properties). | Continuously driven simulation value. |
| Point of use | Writes value at a specific OB / priority transition. | Force value at a deterministic point in the OB1 cycle. |
4.3 Operands That Can Be Modified Online
| Operand area | Online modify | Persistent across power cycle? | Notes |
|---|---|---|---|
| I / Q process image | Yes (Modify) | No | Will be overwritten by I/O scan next OB1 cycle. |
| PIW / PQW (periphery) | Yes | No | Direct write to peripheral address, bypasses PI. |
| M (bit memory) | Yes | No (unless retentive configured) | Standard scratchpad area. |
| DB actual values | Yes | No – held in work memory only | Initial values in load memory are restored on cold restart. |
| DB initial values | No (offline edit + download required) | Yes | Use the Data View tab in the DB editor to set initial value columns. |
| Timers / Counters | Yes (modify current value) | No | Structure varies by CPU. |
5. Force Tables: When and How to Use Force
Force is the only mechanism that overrides a physical input regardless of what the field wiring is doing. The forced value is stored on the CPU and is reasserted on every scan cycle. It is also a documented permanent state in the diagnostic buffer.
5.1 Creating a Force Table
- Right-click
Blocks>Insert New Object > Force Table. - Add I or Q addresses:
I 0.0,IB 2,QW 4. - Set the force value column (0 or 1 for BOOL, DEC for bytes/words).
- Click
Forceon the toolbar. The CPU enters the FORCE state; the SF/DIAG LED on the CPU lights depending on firmware.
5.2 Force Precautions
I 8.0 = DoorClosed) removes a safety interlock. Document the force in the batch record, use a physical key switch on the operator panel to enable force, and always Stop Forcing immediately after the maintenance task.5.3 Difference Between "Modify" and "Force"
| Attribute | Modify (VAT) | Force |
|---|---|---|
| Persists across PG disconnect | No | Yes |
| Survives CPU STOP→RUN | No | Yes (until "Stop Forcing") |
| Triggers diagnostic interrupt | No | Yes (entry in diagnostic buffer) |
| Works on inputs | No (only process image) | Yes (overrides physical input) |
| Operator HMI sees same value | Yes (reads PI) | Yes (reads forced image) |
6. Data Block Initial Value vs Actual Value
This distinction is the most frequent source of "the value comes back after a restart" issues. Every DB has two value areas:
- Initial values (Startwerte) – stored in the load memory of the CPU and on the MMC/Flash card. Used as the source on a cold restart, on a memory reset, and when the DB is reloaded from the offline project.
- Actual values (Aktualwerte) – stored in the work memory of the CPU. Used by the program at runtime. They are the values visible from a VAT.
6.1 Setting a Value Permanently (Recipe Setpoint)
- Open the DB in the Data View tab of the DB editor.
- Change the Initial Value column (not the Actual Value column).
- Save and download only the DB to the CPU. The new initial value is written to load memory; on the next cold restart the actual values are reseeded from the initial values.
6.2 Setting a Value Temporarily (Live Tuning)
- Open the DB in the Data View tab.
- Change the Actual Value column.
- Trigger a
Monitor/Modifywrite from the VAT instead – the value will be written to the work memory directly and survives a warm restart only if the data area is configured as retentive in the CPU properties (PLC > Properties > Retentive Memory).
7. Hardware Configuration Changes and CIR
Configuration in Run (CIR) is a Siemens feature on S7-400 CPUs (e.g., CPU 414-3, 416-3, 417-4) that lets you add or remove certain distributed I/O slaves (PROFIBUS DP / PROFINET IO) without stopping the CPU. The S7-300 family does not support CIR; any HW Config change forces a STOP.
For a step-by-step procedure see the Siemens FAQ "Configuration in RUN (CIR) for S7-400" on the Siemens Online Support portal. Key constraints:
- CIR is enabled per DP master / IO controller in HW Config.
- The CPU must be in RUN with no faults.
- Only add or remove of slaves / modules is allowed; re-parameterization of a slot is not.
- S7-400 H-CPUs (e.g., 412-5H, 414-5H, 417-5H) support online HW Config changes during redundant operation through the H system mechanism, not CIR.
8. HMI Modifications During RUN
Changes to WinCC Flexible, ProTool, or third-party HMI projects that communicate with the CPU via S7 communication do not cause the CPU to stop. The HMI station and the CPU exchange data through PUT/GET or S7 connections; the CPU treats the partner as a passive consumer. HMI tag updates, screen modifications, and alarm configuration changes are safe to push while the process is running, subject to the following:
- A full compile + download to the HMI panel is not atomic; brief loss of communication is possible during the project transfer.
- Ensure the HMI connection in the PC station / panel is not in stop state during the transfer.
- PanelView or TP/OP panels must remain powered; do not interrupt the transfer.
9. Pharmaceutical and GxP Compliance Considerations
FDA 21 CFR Part 11 and EU GMP Annex 11 treat the PLC program and the values it writes as regulated electronic records. Online changes in a running batch are therefore not just an automation concern; they are a quality concern.
| Regulation | Requirement | Implementation in STEP 7 |
|---|---|---|
| 21 CFR §11.10(a) | System validation | Validated change-control SOP must cover online edits. |
| 21 CFR §11.10(e) | Audit trail of all GMP changes | Diagnostic buffer, VAT log files, and the WInCC audit trail together form the record. |
| 21 CFR §11.50/70 | Electronic signatures | Signatures captured at the MES / Batch level, not in STEP 7. |
| Annex 11 §10 | Security of electronic records | STEP 7 project archived with checksum; access to the programming PG controlled. |
| Annex 15 / GAMP 5 | Categorization of changes | Online value tweak = "minor change"; logic block edit = "major change" requiring impact assessment. |
Diagnostic Buffer (PLC > Module Information) and save a screenshot with timestamp. After the change, save the VAT as VAT_YYYYMMDD_HHMM_Reason.vat and file it in the change-control ticket. This creates an unbroken audit trail from intent to action.10. Step-by-Step: Safely Change a Recipe Value Online
The following procedure is recommended for a 21 CFR Part 11 compliant change of a recipe parameter in a running batch on an S7-315-2 DP controlled by STEP 7 V5.5 SP2.
- Open the offline project in STEP 7 and connect online via
Accessible Nodes. - Open
PLC > Module Information > Diagnostic Bufferand confirm no fault entries. - Open the
Blocksfolder and verify OB80, OB82, OB85, OB86, OB87, OB100, OB121, OB122 are present in the offline view. - Open or create the VAT for the recipe DB and enter the address, e.g.,
DB120.DBD0in FLOAT format. - Click
Monitor; confirm the displayed value matches the current setpoint. - Enter the new value in the Modify Value column and set Trigger =
Once. - Click
Modify. Observe the diagnostic buffer; no STOP entry must be generated. - Verify the HMI display updates within one OB1 cycle (typically 50–200 ms).
- Print or save the VAT table with the change; archive the diagnostic buffer screenshot.
11. Troubleshooting Matrix
| Symptom | Likely cause | Corrective action |
|---|---|---|
| CPU goes to STOP after VAT modify | DB access in FBs not paired with new DB content | Download DBs first, then FBs. Add OB121 to absorb programming errors. |
| CPU goes to STOP after HW Config download | Non-CIR / non-H CPU cannot reconfigure in RUN | Schedule a planned stop; perform HW Config download in STOP; perform warm restart. |
| Modified value reverts after restart | Initial vs actual value confusion | Edit the Initial Value column of the DB and re-download the DB. |
| Force command rejected | CPU in RUN but password protection on Force is active | Enter the CPU password under PLC > Access Rights; S7-300/400 allows separate force password. |
| VAT shows "???" for an address | Address does not exist in CPU configuration or DB not loaded | Download the missing DB; cross-check the absolute address with HW Config. |
| Online modify succeeds but HMI still shows old value | HMI tag is read from a different DB or a scaled variable | Verify the tag's DB reference in the HMI configuration; check the scaling block. |
| OB85 fault on distributed I/O | Slave failed or slot empty | Restore the slave; if the slot is intentionally unused, install OB85 to absorb the event. |
| OB122 during commissioning | Program accesses unconfigured I/O | Verify HW Config and the address ranges used in the program; install OB122 during commissioning. |
| Force lost after power cycle | Force is held in volatile work memory on some CPUs | Reissue the force after restart; consider using a VAT modify for non-safety values. |
12. Field-Proven Best Practices
- Always download in the order: OBs → DBs → FBs/FCs. Reorder only with a documented impact analysis.
- Keep a "gold" project archive after each successful commissioning. Use STEP 7's archive tool with the Compress option to minimize size.
-
Retentive settings in the CPU properties must match the VAT/DB strategy. If a value must survive a warm restart, declare the byte/bit range as retentive in the CPU's
Retentive Memorytab. - For recipe values, write the initial value, not the actual value. Operators should be trained on this distinction.
- Never force a safety input (E-Stop, guard door, light curtain) for convenience. The safety relay or F-CPU should be the source of truth.
- Use a dedicated programming PG with the STEP 7 project locked under a Windows account that has no operator privileges. The PG itself is a regulated asset in a GxP environment.
- Disable the "Load to MMC after every download" option during online tuning to avoid unnecessary write cycles to the Flash card (life expectancy ≈ 100,000 cycles per Siemens datasheet for S7-300 MMC).
Can I change a DB value online without a download?
Yes. Open a Watch / Variable Table (VAT), add the DB address (for example DB101.DBD0), and use Monitor/Modify with Trigger = Once. The change is written to the work memory of the CPU only; the initial value in load memory is unchanged, so a cold restart will revert the value.
Which OBs are mandatory to avoid a CPU STOP during online block downloads?
OB80, OB82, OB85, OB86, OB87, OB100, OB121, and OB122 are the typical minimum. OB121 and OB122 are the most often missing and are the most common cause of a STOP after a logic block download that references a different DB layout.
Does modifying an input in a VAT also force the physical input?
No. A VAT modify writes to the process image of the CPU, not to the physical input. The next I/O scan will overwrite the value with the actual field state. To override the physical input, use a Force table and the Force command.
How do I make a recipe value change persistent across a power cycle?
Edit the Initial Value column of the DB (not the Actual Value) and download the DB. Initial values are stored in load memory and are restored on cold restart, memory reset, and when the DB is reloaded from the offline project.
Is hardware configuration downloadable to a running S7-300 CPU?
No, with one exception: an S7-400 H-CPU pair, or an S7-400 CPU with the Configuration in Run (CIR) feature enabled. S7-300 CPUs do not support CIR; any HW Config download forces a STOP→START transition. Plan a maintenance window for HW Config changes on S7-300.
Where can I find the official Siemens documentation for STEP 7 V5.5 online editing?
The primary references are the Programming with STEP 7 V5.5 manual and the Modifying the User Program in the CPU Online section of the STEP 7 V5.5 online help. The most current manual revisions and FAQs are available on the Siemens Industry Online Support portal under product "STEP 7 V5.5".