Resolving ADFWeb HD67719 Bacnet-Profinet Byte Swap Errors in TIA

David Krause15 min read
SiemensTIA PortalTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Overview

When integrating the ADFWeb HD67719-IP-A1 Profinet Slave / BACnet Master gateway with a Siemens SIMATIC S7-1200 or S7-1500 controller programmed in TIA Portal V15.1, engineers routinely observe that Analog Input (AI) values retrieved from a BACnet device (for example, BACnet object instance 20400) are present in the peripheral input image but contain numerically incorrect data. The four-byte payload is read correctly into the process image, but the interpreted value does not match the engineering range of the source measurement (e.g., a temperature reported as -2.147E+09 or as a maximum unsigned value when the field device is transmitting a value such as 23.7 °C or 4.000 mA scaled to 0–100 %).

The most frequent root cause of this discrepancy is an endianness / byte ordering mismatch between the BACnet/IP transport representation exposed by the ADFWeb gateway's process data and the native byte layout used by the Siemens CPU when it copies peripheral inputs into the I/O address area. A second-order cause is a data-type length mismatch (e.g., reading a 16-bit BACnet object as 32 bits, or reading a 32-bit float as a 32-bit integer).

This reference documents the complete diagnostic procedure, the configuration of the ADFWeb HD67719-IP-A1, the TIA Portal V15.1 SWAP instruction variants (one for S7-300/400 and one for S7-1200/1500), and the verified commissioning workflow that resolves the issue without firmware changes to either the gateway or the controller.

Field note: The issue is not a hardware fault, firmware bug, or cabling problem. It is a data-interpretation error caused by the combination of (a) BACnet's network byte order, (b) ADFWeb's default process-data layout, and (c) the SIMATIC S7-1200/1500 little-endian representation of 32-bit values. The SWAP instruction is the canonical Siemens fix.

2. Affected Components and Versions

Component Model / Version Role Notes
Protocol converter ADFWeb HD67719-IP-A1 Profinet IO Slave / BACnet/IP Master 4-byte process data block per configured BACnet point
PLC – S7-1200 family CPU 1211C, 1212C, 1214C, 1215C, 1217C; firmware ≥ V4.2 recommended Profinet IO Controller Uses the "S7-1200/1500 SWAP" instruction variant
PLC – S7-1500 family CPU 1511, 1513, 1515, 1516, 1518; firmware ≥ V2.0 Profinet IO Controller Uses the "S7-1200/1500 SWAP" instruction variant
PLC – S7-300/400 CPU 315, 317, 319, 414, 416, 417 Profinet IO Controller (via CP/IM) Uses the "S7-300/400 SWAP" instruction variant
Engineering tool SIMATIC STEP 7 / TIA Portal V15.1 PLC configuration and programming The 32-byte SWAP variant is available in both Basic and Professional editions
Gateway configurator ADFWeb Compositor (SW67719) Mapping BACnet objects to Profinet slots Default install path: C:\ADFWeb\Compositor_SW67719

3. Root Cause Analysis

BACnet/IP transmits Application Layer data using big-endian (network byte order) per ASHRAE Standard 135. ADFWeb's HD67719-IP-A1 mirrors this byte order in the Profinet IO process data by default: byte 0 (most significant) is mapped to the lowest Profinet offset, byte 3 (least significant) to the highest. The S7-1200/1500 CPUs, by contrast, store 32-bit values in little-endian format in the process image. When the gateway writes 0x 41 BD 70 A4 (IEEE-754 representation of 23.7) into the input image at offset 0, the CPU interprets the same four bytes as 0x A4 70 BD 41, yielding a wildly different value (a negative, denormalized, or saturated reading depending on interpretation mode).

There are three possible byte-ordering problems to disambiguate before applying a fix:

  1. Full 32-bit byte reverse – The entire DWORD is reversed (byte 0 ↔ byte 3, byte 1 ↔ byte 2). This is the most common case for a 32-bit BACnet REAL (float) or a 32-bit unsigned/signed integer.
  2. Word swap only (16-bit swap) – The two 16-bit words within the DWORD are exchanged, but the bytes inside each word remain in their original order. Typical when the gateway is configured to present data in "Motorola" word order inside a little-endian slot.
  3. Byte swap inside each word – The bytes of each 16-bit word are reversed. Rare; only encountered when the gateway is configured with a non-default byte-alignment option.

Always identify which of the three cases applies by writing a known stimulus to the BACnet object (e.g., force the source to 0x3F800000 = 1.0 in IEEE-754, or write 0x12345678 to a 32-bit unsigned object) and observing the four bytes in the TIA Portal watch table before selecting a SWAP variant.

Critical: Do not assume the issue is a SWAP problem without first confirming that the BACnet object is being read at all. Use a BACnet browser (e.g., YABE, BACnet Discovery Tool) to verify the object exists, is readable, and contains the expected value at the network level. Only then proceed to interpret the data inside the PLC.

4. ADFWeb HD67719-IP-A1 Configuration Reference

The HD67719-IP-A1 is configured with the ADFWeb Compositor software (SW67719). The relevant configuration columns for this issue are:

Column Function Default When to Change
BACnet Object Type AI / AO / AV / BI / BO / BV / MSI / MSO / MSV AI (Analog Input) Match the type of the target BACnet object
BACnet Instance Object instance number (e.g., 20400) — Must match the device's published point list
Data Length (bytes) Length of the BACnet payload in the Profinet slot 4 4 for REAL (32-bit float) or 32-bit integer; 2 for 16-bit integer
Read/Write Mode Polled, COV, or COV-Property Polled Use COV subscriptions for high-latency networks to reduce BACnet traffic
Byte Order "MSB first" (default) or "LSB first" MSB first (big-endian) If set to LSB first, the S7 SWAP is not required
Swap Words Word swap inside the DWORD Disabled Enable only if confirmed word-swap is required

For a typical AI object returning a 32-bit IEEE-754 REAL, the default of Data Length = 4, Byte Order = MSB first, Swap Words = Disabled is correct. The conversion to little-endian must be performed inside the PLC.

5. BACnet Data Representation in the Gateway

BACnet encodes analog values as one of the following primitive data types in the Application Layer:

  • REAL (32-bit IEEE-754 single precision, 4 bytes, big-endian) – the most common for engineering values.
  • Unsigned Integer (8/16/32-bit, big-endian) – used for counts, setpoints in discrete steps.
  • Signed Integer (8/16/32-bit, big-endian, two's complement) – used for signed counters and differential values.
  • Double (64-bit IEEE-754, 8 bytes, big-endian) – rare; only when the device explicitly supports it.

The HD67719-IP-A1 maps each configured BACnet point to a fixed offset inside a Profinet slot. If the slot is configured as 4 bytes, the four bytes [B0][B1][B2][B3] are placed in the input image in the order B0 at the lowest offset. B0 is the most significant byte of the BACnet value (per the BACnet big-endian convention).

6. TIA Portal SWAP Instruction Variants

The SWAP instruction in TIA Portal reverses the byte order within a data unit. Two instruction variants are provided because the S7-300/400 and S7-1200/1500 families use different parameter block layouts and instruction signatures.

6.1 SWAP for S7-1200/1500 (32-bit variant)

This variant operates on a single DWORD input and writes the byte-reversed result to a DWORD output. It is located in Basic Instructions → Converter operations → SWAP in the TIA Portal instruction catalog.

// STL equivalent (S7-1200/1500)
// "Tag_Input"  : DWORD read from %IW area at the gateway offset
// "Tag_Output" : DWORD after byte swap, ready for REAL/DINT conversion
SWAP(Tag_Input := "gw_AI_raw",   // DWORD, peripheral input
     Tag_Output => "gw_AI_swap"); // DWORD, byte-reversed

Refer to the official Siemens KB article S7-1200/1500 SWAP instruction (entry ID 109755202) for the parameter block, error flags, and EN/ENO behavior.

6.2 SWAP for S7-300/400 (16-bit variant)

On S7-300/400, the SWAP instruction reverses the bytes of an ACCU 1 word. It is a standalone instruction without an explicit parameter block.

// STL equivalent (S7-300/400)
L    "gw_AI_raw"        // Load 32 bits from process image
SWAP                    // Byte-reverses the low word of ACCU 1
SWAP                    // Reverses the high word of ACCU 1
T    "gw_AI_swap"       // Store back; effectively a full DWORD reverse

Two consecutive SWAPs on the S7-300/400 are required to reverse all four bytes of a 32-bit value. A single SWAP reverses only the bytes within the low word (16 bits).

6.3 Selecting the Correct Variant

PLC Family Instruction Block Operates On Calls Required for 32-bit Reverse
S7-1200 SWAP (32-bit block) DWORD → DWORD 1
S7-1500 SWAP (32-bit block) DWORD → DWORD 1
S7-300 SWAP (STL) 16-bit word in ACCU 1 2 (low + high word)
S7-400 SWAP (STL) 16-bit word in ACCU 1 2 (low + high word)
Engineering tip: For S7-300/400, the second SWAP is non-obvious. Missing the second call results in word-swapped data (case 2 in Section 3) instead of fully byte-swapped data. This frequently leads to a second round of debugging where the values are "partially correct." Always verify the result against a known stimulus before declaring the fix complete.

7. Step-by-Step Resolution Procedure

Prerequisites

  • ADFWeb HD67719-IP-A1 with at least one BACnet AI object exposed as 4 bytes in a Profinet slot.
  • TIA Portal V15.1 (or compatible) with the project containing the gateway as a Profinet IO device.
  • The HW identifier of the gateway's input submodule (visible under Device view → Properties → System constants in TIA Portal).
  • A known test value (e.g., force the BACnet object to 23.7 °C, which is 0x41BD70A4 in IEEE-754 single precision).

Step 1 – Confirm the BACnet value at the network level

  1. Install a BACnet browser (YABE, BACnet Discovery Tool) on a laptop on the same IP subnet as the HD67719.
  2. Discover the device, read the AI object at instance 20400, and confirm the present value is 23.7.
  3. Record the hex bytes shown by the browser; this is the big-endian reference: 41 BD 70 A4.

Step 2 – Add the gateway to the TIA Portal project as a Profinet device

  1. Import the ADFWeb GSDML file (provided on the ADFWeb USB stick or download portal).
  2. Drag the HD67719-IP-A1 into the Profinet topology and assign it an IP address and device name consistent with the gateway's DIP switch / web server configuration.
  3. Map the gateway's input submodule to a starting address in the S7 process image, for example %IW100 for the first 4 bytes of the AI object.

Step 3 – Observe the raw input image

  1. Download the project to the PLC and go online.
  2. Open a watch table and monitor the four input bytes at the mapped address (%IB100 through %IB103, or as a DWORD at %ID100).
  3. Expected raw value (no swap applied): 0x41BD70A4 at the byte level only if the gateway has been configured for little-endian. With the default big-endian gateway setting, the PLC will display the DWORD as 0x A470BD41 because the CPU reinterprets the bytes in little-endian order.

Step 4 – Apply the SWAP instruction

For an S7-1200 or S7-1500:

// FB or FC block – S7-1200/1500
// Read 4 bytes from the gateway input image as DWORD
"gw_AI_raw"    := %ID100;                    // Raw little-endian interpretation
// Perform full DWORD byte reverse
SWAP(Tag_Input  := "gw_AI_raw",
     Tag_Output => "gw_AI_swap");
// Interpret the corrected DWORD as a 32-bit IEEE-754 REAL
"gw_AI_value"  := DWORD_TO_REAL("gw_AI_swap");

For an S7-300 or S7-400:

// STL in OB1 or a dedicated FC – S7-300/400
L     %ID 100          // Load 4 bytes (raw, little-endian interpreted)
SWAP                   // Reverse low word
SWAP                   // Reverse high word
T     "gw_AI_swap"     // Store fully reversed DWORD
// Interpret as REAL
L     "gw_AI_swap"
DTR                    // DWORD to REAL (32-bit IEEE-754)
T     "gw_AI_value"

Step 5 – Scale the engineering value (if required)

If the BACnet object is a scaled count rather than a REAL, use NORM_X and SCALE_X (S7-1200/1500) or manual scaling (S7-300/400) to convert the integer count to engineering units.

// S7-1200/1500 scaling example: 0–27648 raw → 0.0–100.0 %
"gw_AI_pct" := SCALE_X(MIN := 0.0,
                       VALUE := NORM_X(MIN := 0,
                                      VALUE := "gw_AI_value",
                                      MAX := 27648),
                       MAX := 100.0);

8. Verification Procedure

  1. Go online in TIA Portal with the watch table open on gw_AI_raw, gw_AI_swap, and gw_AI_value.
  2. Force the BACnet object to three reference values: 0.0, 1.0, and 23.7.
  3. Confirm that gw_AI_swap displays the expected big-endian hex (e.g., 0x3F800000 for 1.0).
  4. Confirm that gw_AI_value (REAL) matches the forced BACnet value within IEEE-754 rounding tolerance.
  5. Toggle the BACnet object between two extreme values (e.g., 0.0 and 100.0) ten times in succession to confirm the swap is stable and not dependent on the input pattern.
  6. Cycle power to the PLC to verify that the swapped value is correctly reconstructed on cold restart.
Verification check: If the value is correct for one stimulus (e.g., 1.0) but inverted for another (e.g., 100.0), the swap is partial (word-swap only) – add or remove a SWAP call as appropriate. If the value is constant regardless of the BACnet stimulus, the gateway is not refreshing the data – check the BACnet Read Property service in the gateway's diagnostic web page.

9. Edge Cases and Field-Tested Caveats

9.1 Multi-point configurations

If the HD67719 is configured to expose multiple BACnet objects in a single contiguous slot, ensure that the SWAP is applied to each 4-byte (or 2-byte) block individually, not to the entire block. Applying a single SWAP across an 8-byte block will corrupt the data. Use a loop or explicit field selection.

9.2 16-bit BACnet objects

For a 16-bit BACnet integer (Unsigned or Signed), a single word swap is sufficient, but the S7-1200/1500 SWAP block operates on a DWORD. Mask the result with WORD_TO_INT(DWORD_TO_WORD(swap_result)) to extract the lower 16 bits.

9.3 COV (Change of Value) subscriptions

If the gateway is configured for COV instead of polling, the input image will only update when the BACnet value changes by more than the configured COV increment. This can simulate a "stuck value" if the COV increment is too large. Verify the COV increment in the gateway's web interface.

9.4 IEEE-754 NaN and Inf

BACnet devices may return 0x7F800000 (+Inf), 0xFF800000 (-Inf), or 0x7FC00000 (NaN) for faulted or out-of-range inputs. The S7-1200/1500 REAL type follows IEEE-754 and will propagate these values. Add validity checks in the application code to avoid saturating downstream control loops.

9.5 Big-endian configured in ADFWeb

Some ADFWeb firmware versions allow the gateway to be configured in little-endian mode ("LSB first" in the Compositor). In that case, the SWAP instruction is not required. Mixing gateway-side and PLC-side byte swaps is a common cause of the problem recurring after a gateway firmware update.

9.6 Negative-value handling

For signed 32-bit integers in the range -2,147,483,648 to 2,147,483,647, the SWAP must be applied before the integer interpretation. If DWORD_TO_DINT is applied first, the sign bit may be in the wrong position and the conversion will yield a wrong value. The byte reverse must occur on the raw DWORD before any integer interpretation.

9.7 Watch table display format

TIA Portal V15.1 watch tables can display DWORDs in HEX or DEC. Make sure the HEX column is enabled to compare directly with the expected BACnet payload. The DEC view hides the byte ordering problem because it shows the integer interpretation of the (incorrect) little-endian value.

9.8 Profinet slot alignment

ADFWeb gateways sometimes align 4-byte BACnet objects to a slot boundary offset of 0, 4, or 8 bytes. If the offset is non-zero within a slot, the I/O address in TIA Portal must be increased by that offset. Misalignment results in the PLC reading a partial or shifted value, which can mimic a byte-swap problem.

10. Diagnostic Watch Table Procedure

Use the following watch table as a template for online diagnostics during commissioning. Save it as WatchTable_ADFWeb_BACnet in the TIA Portal project.

// Watch table – online monitoring of the gateway BACnet point
// Add the following tags (all DWORD or REAL):
"gw_AI_raw_HEX"          // HEX view of the raw %ID at the gateway offset
"gw_AI_swap_HEX"         // HEX view after SWAP
"gw_AI_value_REAL"       // REAL view after DWORD_TO_REAL
"gw_AI_pct_engineering"  // Scaled engineering value (e.g., 0.0–100.0 %)
// Optional diagnostic tags
"gw_diag_link_ok"        // BOOL: Profinet connection status (device-level)
"gw_diag_bacnet_fault"   // BOOL: gateway's BACnet communication fault (if mapped)

Toggle the BACnet object through three known values (0.0, 1.0, and a project-specific reference) and record the watch table for inclusion in the commissioning report.

11. Alternative Approaches (When SWAP Is Not Acceptable)

In legacy or safety-critical codebases where adding a SWAP call is not desirable, three alternatives exist:

  1. Gateway-side conversion – Reconfigure the HD67719 to expose the data in little-endian (LSB first) using the ADFWeb Compositor. The SWAP in the PLC is then no longer required. Verify the gateway's firmware supports this option (firmware ≥ 1.40 typically required).
  2. Manual byte assembly with PEEK/POKE – Use PEEK_BOOL / PEEK or direct AT-view declarations to assemble the big-endian value into a REAL tag byte by byte. Slower at runtime but transparent in code review.
  3. Block move with explicit byte index – Use MOVE_BLK or a loop to copy the four input bytes into a temporary array, swap the indices, and interpret the result. Useful when the SWAP instruction is unavailable in the project's instruction set.

12. Related Siemens and ADFWeb Documentation

Why do I see four correct bytes in the input image but a wrong engineering value?

The four bytes are being placed into the input image in the gateway's native big-endian order (MSB first), but the SIMATIC S7-1200/1500 CPU interprets 32-bit values in little-endian order. Apply the SWAP instruction (single call for S7-1200/1500, double call for S7-300/400) to reverse the bytes before interpreting the value as REAL or DINT.

Which SWAP instruction do I use in TIA Portal V15.1 for an S7-1500?

Use the 32-bit SWAP block under Basic Instructions → Converter operations → SWAP. The block has a DWORD input and DWORD output, and a single instance reverses all four bytes. The S7-300/400 SWAP is a 16-bit STL instruction and requires two consecutive calls to fully reverse a 32-bit value.

Can the byte swap be performed inside the ADFWeb HD67719 instead of the PLC?

Yes. In the ADFWeb Compositor, change the "Byte Order" column for the affected BACnet point from "MSB first" to "LSB first." The gateway will then place the four bytes in little-endian order in the Profinet slot, and no SWAP is required in the PLC. Verify the gateway firmware supports this option (typically firmware ≥ 1.40).

My value is correct for some stimuli but inverted for others. What is wrong?

The swap is partial – only the words inside the DWORD are being reversed, not the bytes inside each word. On an S7-300/400, this indicates a single SWAP call was used instead of two. On any PLC, verify that the SWAP is applied to a DWORD (32 bits) and not to a WORD (16 bits). Use a known stimulus (e.g., 0x12345678) and check that the output is 0x78563412.

Is this a Profinet configuration error in TIA Portal?

No. The Profinet IO device configuration, slot mapping, and IP/device-name assignment are correct. The byte-swap problem originates in the data representation layer (BACnet big-endian vs. SIMATIC little-endian) and is resolved either at the gateway (Compositor setting) or in the PLC program (SWAP instruction). Re-importing the GSDML or re-assigning the IP address will not resolve the issue.

Back to blog