Problem Overview
Engineers integrating the SIMATIC ET 200S IM151-8 PN/DP CPU into a TIA Portal V11 project with WinCC Professional V11 runtime frequently encounter a hard limitation: PLC-side alarm messages generated with the standard S7 alarm function blocks (SFB33 ALARM_D, SFB35 ALARM_DQ, SFB36 ALARM_S) fail to surface on the HMI, even though the same program logic works flawlessly against a CPU 315-2 PN/DP. The root cause is a defect in the TIA Portal V11 SP2 HMI connection editor for the IM151-8 device variant: an integrated S7 connection from the IM151-8 to a WinCC Professional RT cannot be created through the standard project tree, so the HMI never participates in the alarm subscription that WinCC uses to receive the S7-ALARM-SQ/AP service.
Siemens confirmed the limitation and shipped a hotfix to affected customers. The same fix is incorporated in WinCC Professional V11 SP2 Update 4, which is the first generally available release that allows PLC alarms (programmatically generated, message-configured alarms originating on the CPU) to be displayed in a WinCC Professional runtime sourced from an IM151-8 PN/DP CPU. This reference documents the supported configuration path, the SFB call conventions, the WinCC Professional alarm view wiring, and the diagnostic steps that confirm the S7 alarm subscription is active.
IM151-8 PN/DP Architecture and Alarming Capability
The IM151-8 PN/DP is the CPU slot module of the ET 200S distributed I/O system. Although packaged in a slim single-width terminal module, it is functionally a full S7-300-class CPU: it executes the same STEP 7 instruction set, supports the same system function blocks for alarms, and participates in the same S7 communication services over PROFINET IO and PROFIBUS DP. According to the S7-300 Operations List, the IM151-8 CPU is fully listed as an alarm-capable device supporting both bit-message (SFB36 ALARM_S / SFB37 ALARM_SQ) and value-message (SFB33 ALARM_D / SFB35 ALARM_DQ) signalling.
From the perspective of the HMI, what matters is not the package type but the following three system-side prerequisites:
- An S7 connection is established between the operator station and the IM151-8.
- The S7 alarm subscription service is enabled on that connection (default for an S7 connection, but it must survive the TIA Portal project compilation without being stripped).
- The IM151-8 CPU project contains configured alarm messages with associated message numbers and the runtime data is downloaded with those message texts and attributes.
On standard S7-300 CPUs, all three prerequisites are satisfied automatically when the HMI connection is created in the TIA Portal. On the IM151-8 in V11 SP2 prior to Update 4, the HMI connection itself cannot be added, so prerequisites 1 and 2 fail together. Update 4 patches the project editor and the runtime gateway so the connection can be authored and the alarm subscription negotiated.
PLC Alarm Mechanism: SFB33 / SFB35 / SFB36 / SFB37
S7 PLC alarms are server-pushed events. Unlike a poll-based tag, the CPU emits a record on the S7 connection whenever the calling SFB detects a signal edge, a value change, or a programmed trigger condition. The HMI does not request the alarm; it receives it and matches the incoming event against the alarm class, message number, and parameter set configured in the HMI's alarm configuration.
| SFB | Designation | Behavior | Typical Use |
|---|---|---|---|
| SFB33 | ALARM_D | Value message, no acknowledgment, status only | Threshold breach, mode change |
| SFB35 | ALARM_DQ | Value message with acknowledgment required | Critical fault that must be acknowledged at HMI |
| SFB36 | ALARM_S | Bit message, no acknowledgment, status only | Discrete state notifications |
| SFB37 | ALARM_SQ | Bit message with acknowledgment required | Discrete fault requiring operator ack |
Each SFB is called from the user program in OB1 (cyclic) or in an alarm/time OB. The SFB instance DB is created automatically the first time the SFB is placed; the instance contains the EV_ID (event ID), the IN/IN0..IN7 input words (for value messages), and the message-class / state parameters required by the CPU operating system.
For an ALARM_DQ call, the canonical call signature is:
CALL "ALARM_DQ", DB35
EV_ID := DW#16#0001_0000 // 32-bit event ID, must be unique CPU-wide
CMP_ID := // optional comparison ID, leave blank
SD := // ACK state reference (BOOL)
SIG := BOOL#TRUE // 1 = trigger alarm, 0 = trigger clear event
IN0 := MW100 // associated value 0
IN1 := MW102 // associated value 1
IN2 := MW104
IN3 := MW106
IN4 := MW108
IN5 := MW110
IN6 := MW112
IN7 := MW114
ACK_DONE:= // output: 1 when operator has acknowledged
HMI Connection Requirements and the V11 SP2 Update 4 Fix
For WinCC Professional to receive PLC alarms, the operator station must terminate an HMI connection against the IM151-8. In the TIA Portal project tree this appears as a node under "HMI connections" within the WinCC Professional device. Prior to WinCC Professional V11 SP2 Update 4, the device-type check inside the HMI connection editor rejected the IM151-8 PN/DP CPU as a valid S7 partner, so the connection node could not be created. With the connection absent, WinCC RT Professional neither opens the S7-ALARM-SQ subscription nor binds any alarm-config entry to a source CPU.
Update 4 corrects the device-type filter and, more importantly, also corrects the runtime registration of the IM151-8 as a valid alarm source. Once both ends of the connection are in place, the standard alarm subscription is negotiated at runtime: the WinCC RT Professional process opens the S7 connection, the CPU responds to the S7-ALARM-SQ REGISTER request, and incoming ALARM_S / ALARM_SQ / ALARM_D / ALARM_DQ records are decoded against the alarm configuration resident on the HMI side.
| Item | Pre-Update 4 | Post-Update 4 |
|---|---|---|
| HMI connection to IM151-8 | Cannot be created in editor | Available in editor and runtime |
| ALARM_S / ALARM_SQ on HMI | No — connection absent | Yes — standard subscription |
| ALARM_D / ALARM_DQ on HMI | No | Yes — value messages with parameters |
| Acknowledgment from HMI | No | Yes — ACK from RT is written back via SD/ACK_DONE |
| Alarm logging (CSV / SQL) | Unavailable for IM151-8 sources | Available, standard logging path |
Reference for the alarm flow on the WinCC side, applicable to RT Professional: Alarms (Basic Panels, Panels, Comfort Panels, RT Advanced, RT Professional) — Communicating with S7-300/400.
Prerequisites
Before commissioning, confirm the following:
- TIA Portal V11 SP2 installed on the engineering station.
- WinCC Professional V11 SP2 Update 4 or later installed (download from the Siemens support portal entry "WinCC Professional V11 SP2 Update 4").
- IM151-8 PN/DP GSD / HSP file present in TIA Portal so the device appears in the hardware catalog (HSP for V11 SP2 covers 6ES7151-8AB00, 6ES7151-8AB01, 6ES7151-8FB00, 6ES7151-8FB01).
- STEP 7 program with at least one ALARM_S, ALARM_SQ, ALARM_D, or ALARM_DQ instance.
- Profinet or Profinet/Profibus path between engineering station, IM151-8, and the WinCC RT Professional station.
- Operator-station license: a WinCC RT Professional runtime license matched to the maximum number of tags / alarms / archive tags used.
Step-by-Step Configuration
Step 1 — Author the IM151-8 Project
Insert the IM151-8 PN/DP from the catalog into the project, assign the PROFINET device name and IP, and add any distributed I/O modules configured for the application. Confirm that the device compiles green before proceeding.
Step 2 — Insert and Call the Alarm SFBs
Open the STEP 7 program of the IM151-8 and, for each message, drop the appropriate SFB from the "System Function Blocks" folder. The instance DB is created automatically. Wire the EV_ID symbolically against a project constant so it can be cross-referenced. Compile the program. Note that the SFB call is allowed in the IM151-8 — it is the HMI-side connection layer that was broken in V11 SP2 prior to Update 4, not the CPU alarm logic.
Step 3 — Configure HMI Tags and Connection to the IM151-8
- Add a WinCC Professional RT device to the project (PC station or Panel PC).
- Open the WinCC Professional device > "Connections."
- Create a new HMI connection, set the partner to the IM151-8 PN/DP. With Update 4 installed, the IM151-8 appears in the partner drop-down.
- Set the connection type to "S7 connection," specify the PROFINET interface of the operator station and the IP of the IM151-8. The default rack/slot for an S7-300-class CPU is rack 0 / slot 2.
- Compile the WinCC device. Compilation must complete with zero errors; warnings about implicit access or unqualified tags are acceptable.
Step 4 — Configure Alarm Messages in the HMI
- Open the HMI device > "HMI alarms."
- Add a new alarm entry. The alarm text, class, trigger tag, and EV_ID must be set.
- For bit-triggered alarms (ALARM_S, ALARM_SQ), enter the EV_ID of the SFB that drives the message. For value-triggered alarms (ALARM_D, ALARM_DQ), enter the EV_ID and associate the up-to-8 process values with their format and scaling.
- Assign the alarm to an alarm class (e.g., "Errors," "Warnings") and, if needed, an alarm group for the alarm view filtering.
Step 5 — Place an Alarm View in the Screen
Insert an "Alarm view" control on the operator screen. The control binds to the alarm log, which in WinCC Professional defaults to a circular memory buffer. If persistent logging is required, configure an alarm log with a backing database (SQL) or CSV archive before the runtime is started.
Step 6 — Compile and Download
Compile the WinCC device, then download to the operator station. Separately, download the STEP 7 program (with the SFB instances) to the IM151-8. The download order matters: the CPU must hold the running program before the HMI establishes the connection, otherwise the HMI's initial subscription is rejected with a "partner not reachable" or "AS not in RUN" warning.
Verification
After the download is complete, perform the following verification steps to confirm that PLC alarms are being received by the WinCC Professional runtime:
- On the operator station, open the WinCC RT Professional runtime.
- Switch the IM151-8 to RUN with the STEP 7 program loaded.
- Confirm the HMI connection state in the WinCC diagnostics page: status should report "Connected (S7)" and the partner should match the configured IP.
- Force the SIG input of an ALARM_S instance to TRUE. The corresponding message must appear in the Alarm View within a single polling cycle (typically under 1 s on PROFINET).
- Force the SIG input back to FALSE. The clear event should be logged and the active-state should clear in the alarm view.
- For ALARM_DQ, click "Acknowledge" in the alarm view. Verify that the ACK_DONE output of the instance is set on the CPU. Read the output via an HMI tag or via the online monitor.
If the alarm does not appear, switch to the S7 diagnostics channel in the WinCC runtime (Control Panel > S7 Diagnostics) and confirm that the partner reports an active S7-ALARM subscription.
Troubleshooting Matrix
| Symptom | Likely Cause | Diagnostic | Remediation |
|---|---|---|---|
| IM151-8 absent from HMI connection partner list | WinCC Professional V11 SP2 pre-Update 4 | Check Help > About for build / update level | Install Update 4 or later; re-create the project |
| Connection compiles but runtime shows "Not connected" | Wrong rack / slot or partner IP | WinCC online diagnostics: S7 partner info | Match the connection to IM151-8 rack 0 / slot 2; correct IP |
| Connection OK, but no alarm in view | EV_ID mismatch between SFB and alarm config | Cross-reference: SFB EV_ID vs HMI alarm EV_ID | Align EV_IDs; do not reuse EV_ID across multiple SFBs |
| Alarm appears, but values show "???" | Process-value format / scaling mismatch | Check alarm config: format, decimal places, scaling | Set format string and decimal places to match the value domain |
| Alarm appears but acknowledgment has no effect | Wrong SFB variant (SFB36 used where SFB37 expected) | Inspect the instance DB online | Use ALARM_SQ / ALARM_DQ when acknowledgment is required |
| Alarms stop after a CPU STOP/RUN transition | HMI does not re-subscribe after reconnect | Watch the S7 connection state during transition | Use a cyclic re-connect on RT startup; ensure IM151-8 has alarm subscription enabled in CPU properties |
| Alarm visible, but not logged to the archive | Alarm logging disabled in alarm class or log not configured | Check the alarm log settings | Enable logging on the alarm class; configure the alarm log path |
| Time stamp off by hours | Time-of-day synchronization not configured on the IM151-8 | Compare CPU time with WinCC time | Set the IM151-8 clock master (CPU > Properties > Time of Day) and the WinCC clock to the same source |
Edge Cases and Field-Proven Caveats
1. HMI connection survives project migration but alarms do not. When migrating a project from V11 SP2 Update 3 (or earlier) to Update 4, the project upgrade sometimes leaves the HMI connection configured but does not re-import the alarm subscription. After migration, recompile the WinCC device and re-download to the operator station. The CPU program does not need to be reloaded, but the HMI runtime must re-register with the CPU.
2. Multiple operator stations against one IM151-8. The IM151-8 supports up to 16 S7 connections; each WinCC RT Professional station consumes one connection. Alarm subscriptions are independent per operator station, so a single ALARM_SQ trigger is reflected on all connected operator stations. Plan connection budget on heavily multi-station cells.
3. Mixed CPU population in one project. When the project contains a CPU 315-2 PN/DP and an IM151-8, the CPU 315-2 path was working in V11 SP2 prior to Update 4 and continues to work after Update 4. The fix is additive — it does not require re-validating CPU 315-2 alarms.
4. Subnet routing through PROFINET and PROFIBUS. The IM151-8 PN/DP is a dual-port device. If the HMI is on the PROFIBUS side, the S7 routing must be configured explicitly on the CPU. Without routing, the HMI connection is reported as established at the link layer but the alarm subscription is silently dropped. Use the integrated PROFINET port whenever possible to avoid the routing edge case.
5. CPU operating mode at HMI startup. If the IM151-8 is in STOP when the operator station first runs, the S7 connection may report "established" but the alarm subscription is rejected. Force the CPU to RUN, then restart the WinCC RT Professional runtime. The alternative is to enable HMI-side reconnection retries on loss of the S7-ALARM subscription.
6. Multi-project and shared engineering stations. When several engineers collaborate on the same project, the IM151-8 connection entry must be present in the merged project graph. If a partial merge removes the connection but keeps the alarm configuration, the runtime compiles without error but the alarm subscription is never negotiated.
Differences Versus S7-300 CPU 31x for PLC Alarms
| Aspect | CPU 31x | IM151-8 PN/DP |
|---|---|---|
| SFB support (ALARM_S/SQ/D/DQ) | Full | Full — same SFBs, same instance DB layout |
| EV_ID space | 32-bit, project-wide unique | Same |
| Default rack / slot in TIA connection | 0 / 2 | 0 / 2 |
| Number of S7 connections | Up to 16 (CPU-dependent) | Up to 16 |
| Maximum simultaneous active alarms | CPU-dependent, typically 200+ | Same range; identical S7-300-class behavior |
| WinCC RT Professional V11 SP2 alarm subscription | Available in all V11 SP2 builds | Available from Update 4 onward |
The functional surface of PLC alarms is therefore identical between the IM151-8 and a CPU 31x. What differs is purely the engineering-tool support window for creating the HMI connection that carries the alarm subscription. Once the connection is in place, no further caveats apply.
Migrating to TIA Portal V12 / V13 / V14 or Later
Projects that originally required the V11 SP2 Update 4 fix can be migrated upward to TIA Portal V12 and beyond without re-encountering the original defect. The HMI connection editor in TIA Portal V12+ does not enforce the device-type filter that V11 SP2 Update 3 (and earlier) imposed, so the connection can be created against the IM151-8 regardless of the SIMATIC PLC used. When migrating, perform a full project recompile, re-download the CPU program, and re-download the HMI runtime; then re-run the verification steps in the Verification section of this article.
For long-term support, prefer WinCC Professional V13 SP1 or V14 SP1 if the project allows, as these branches extend the support window and consolidate additional alarm-related corrections. The SFB33/SFB35/SFB36/SFB37 program logic and the alarm configuration schema have not changed across the migration; the EV_ID, instance DB, and message-number conventions carry forward.
Field Commissioning Checklist
- TIA Portal build = V11 SP2 Update 4 (or V12+ for new projects).
- IM151-8 PN/DP firmware version compatible with the HSP installed; consult the release notes for the HSP for any alarm-related firmware notes.
- STEP 7 program compiled green; all SFB instances have unique EV_IDs.
- HMI connection partner = IM151-8, rack 0 / slot 2, IP matches the configured PROFINET device name resolution.
- Alarm entries created in WinCC Professional with matching EV_IDs; alarm class and group assigned.
- Alarm view placed on at least one operator screen; alarm log enabled if persistent logging is required.
- CPU downloaded and in RUN; HMI runtime started; HMI connection reports "Connected (S7)."
- Forced alarm test performed for each SFB variant (S, SQ, D, DQ); acknowledgment path tested for SQ and DQ.
- Time-of-day synchronized on both CPU and HMI; time-stamp drift verified < 1 s.
- Operator SOP updated to cover the new alarm paths; alarm class color / sound mapping documented.
FAQ
Can the IM151-8 PN/DP generate PLC alarms that WinCC Professional V11 will display?
Yes. The IM151-8 supports the full S7 PLC alarm suite (SFB33 ALARM_D, SFB35 ALARM_DQ, SFB36 ALARM_S, SFB37 ALARM_SQ) exactly like a CPU 31x. WinCC Professional V11 SP2 Update 4 (or any later TIA Portal V12+ release) is required so that the HMI connection can be created in the project editor; without that connection, the alarm subscription is never negotiated.
Which Siemens build is the earliest that supports PLC alarms from the IM151-8 in WinCC Professional V11?
WinCC Professional V11 SP2 Update 4 is the first generally available build that resolves the IM151-8 HMI connection defect. Earlier SP2 builds (Update 1, Update 2, Update 3) require a Siemens support hotfix to enable the same behavior.
Do I have to use the PROFINET port of the IM151-8, or can the HMI communicate over PROFIBUS?
Either port can carry the S7 connection and the alarm subscription. When PROFIBUS is used, the IM151-8 must be configured as a PROFIBUS master and S7 routing must be enabled; otherwise the S7 link is established at the link layer but the alarm subscription is silently dropped. The integrated PROFINET port is the simpler choice.
How are ALARM_DQ associated values shown in WinCC Professional?
Up to 8 process values (IN0..IN7) can be passed in the ALARM_DQ call. In the WinCC Professional alarm configuration, the format and decimal places of each value must be set; otherwise the alarm view shows "???" in place of the value. The values can be reformatted as text with the % character format strings.
Why is my alarm visible in the alarm view but not logged to the archive?
The alarm class must have logging enabled, and the alarm log itself must be configured with a backing store (SQL database or CSV file). Without the log, incoming alarms are buffered only in the runtime memory. Check the alarm class properties and the alarm log settings in the WinCC Professional device.
Will the IM151-8 PLC alarm project migrate cleanly to TIA Portal V12 / V13?
Yes. The IM151-8 HMI connection limitation does not exist in V12 and later, so the migration is additive. Recompile and re-download both the CPU program and the HMI runtime after migration, then re-run the verification steps to confirm the alarm subscription.