1. Problem Overview
When integrating the ADFWeb HD67719-IP-A1 Profinet Slave / BACnet Master gateway with a Siemens SIMATIC S7-1200 or S7-1500 controller programmed in TIA Portal V15.1, engineers routinely observe that Analog Input (AI) values retrieved from a BACnet device (for example, BACnet object instance 20400) are present in the peripheral input image but contain numerically incorrect data. The four-byte payload is read correctly into the process image, but the interpreted value does not match the engineering range of the source measurement (e.g., a temperature reported as -2.147E+09 or as a maximum unsigned value when the field device is transmitting a value such as 23.7 °C or 4.000 mA scaled to 0–100 %).
The most frequent root cause of this discrepancy is an endianness / byte ordering mismatch between the BACnet/IP transport representation exposed by the ADFWeb gateway's process data and the native byte layout used by the Siemens CPU when it copies peripheral inputs into the I/O address area. A second-order cause is a data-type length mismatch (e.g., reading a 16-bit BACnet object as 32 bits, or reading a 32-bit float as a 32-bit integer).
This reference documents the complete diagnostic procedure, the configuration of the ADFWeb HD67719-IP-A1, the TIA Portal V15.1 SWAP instruction variants (one for S7-300/400 and one for S7-1200/1500), and the verified commissioning workflow that resolves the issue without firmware changes to either the gateway or the controller.
2. Affected Components and Versions
| Component | Model / Version | Role | Notes |
|---|---|---|---|
| Protocol converter | ADFWeb HD67719-IP-A1 | Profinet IO Slave / BACnet/IP Master | 4-byte process data block per configured BACnet point |
| PLC – S7-1200 family | CPU 1211C, 1212C, 1214C, 1215C, 1217C; firmware ≥ V4.2 recommended | Profinet IO Controller | Uses the "S7-1200/1500 SWAP" instruction variant |
| PLC – S7-1500 family | CPU 1511, 1513, 1515, 1516, 1518; firmware ≥ V2.0 | Profinet IO Controller | Uses the "S7-1200/1500 SWAP" instruction variant |
| PLC – S7-300/400 | CPU 315, 317, 319, 414, 416, 417 | Profinet IO Controller (via CP/IM) | Uses the "S7-300/400 SWAP" instruction variant |
| Engineering tool | SIMATIC STEP 7 / TIA Portal V15.1 | PLC configuration and programming | The 32-byte SWAP variant is available in both Basic and Professional editions |
| Gateway configurator | ADFWeb Compositor (SW67719) | Mapping BACnet objects to Profinet slots | Default install path: C:\ADFWeb\Compositor_SW67719
|
3. Root Cause Analysis
BACnet/IP transmits Application Layer data using big-endian (network byte order) per ASHRAE Standard 135. ADFWeb's HD67719-IP-A1 mirrors this byte order in the Profinet IO process data by default: byte 0 (most significant) is mapped to the lowest Profinet offset, byte 3 (least significant) to the highest. The S7-1200/1500 CPUs, by contrast, store 32-bit values in little-endian format in the process image. When the gateway writes 0x 41 BD 70 A4 (IEEE-754 representation of 23.7) into the input image at offset 0, the CPU interprets the same four bytes as 0x A4 70 BD 41, yielding a wildly different value (a negative, denormalized, or saturated reading depending on interpretation mode).
There are three possible byte-ordering problems to disambiguate before applying a fix:
- Full 32-bit byte reverse – The entire DWORD is reversed (byte 0 ↔ byte 3, byte 1 ↔ byte 2). This is the most common case for a 32-bit BACnet REAL (float) or a 32-bit unsigned/signed integer.
- Word swap only (16-bit swap) – The two 16-bit words within the DWORD are exchanged, but the bytes inside each word remain in their original order. Typical when the gateway is configured to present data in "Motorola" word order inside a little-endian slot.
- Byte swap inside each word – The bytes of each 16-bit word are reversed. Rare; only encountered when the gateway is configured with a non-default byte-alignment option.
Always identify which of the three cases applies by writing a known stimulus to the BACnet object (e.g., force the source to 0x3F800000 = 1.0 in IEEE-754, or write 0x12345678 to a 32-bit unsigned object) and observing the four bytes in the TIA Portal watch table before selecting a SWAP variant.
4. ADFWeb HD67719-IP-A1 Configuration Reference
The HD67719-IP-A1 is configured with the ADFWeb Compositor software (SW67719). The relevant configuration columns for this issue are:
| Column | Function | Default | When to Change |
|---|---|---|---|
| BACnet Object Type | AI / AO / AV / BI / BO / BV / MSI / MSO / MSV | AI (Analog Input) | Match the type of the target BACnet object |
| BACnet Instance | Object instance number (e.g., 20400) | — | Must match the device's published point list |
| Data Length (bytes) | Length of the BACnet payload in the Profinet slot | 4 | 4 for REAL (32-bit float) or 32-bit integer; 2 for 16-bit integer |
| Read/Write Mode | Polled, COV, or COV-Property | Polled | Use COV subscriptions for high-latency networks to reduce BACnet traffic |
| Byte Order | "MSB first" (default) or "LSB first" | MSB first (big-endian) | If set to LSB first, the S7 SWAP is not required |
| Swap Words | Word swap inside the DWORD | Disabled | Enable only if confirmed word-swap is required |
For a typical AI object returning a 32-bit IEEE-754 REAL, the default of Data Length = 4, Byte Order = MSB first, Swap Words = Disabled is correct. The conversion to little-endian must be performed inside the PLC.
5. BACnet Data Representation in the Gateway
BACnet encodes analog values as one of the following primitive data types in the Application Layer:
- REAL (32-bit IEEE-754 single precision, 4 bytes, big-endian) – the most common for engineering values.
- Unsigned Integer (8/16/32-bit, big-endian) – used for counts, setpoints in discrete steps.
- Signed Integer (8/16/32-bit, big-endian, two's complement) – used for signed counters and differential values.
- Double (64-bit IEEE-754, 8 bytes, big-endian) – rare; only when the device explicitly supports it.
The HD67719-IP-A1 maps each configured BACnet point to a fixed offset inside a Profinet slot. If the slot is configured as 4 bytes, the four bytes [B0][B1][B2][B3] are placed in the input image in the order B0 at the lowest offset. B0 is the most significant byte of the BACnet value (per the BACnet big-endian convention).
6. TIA Portal SWAP Instruction Variants
The SWAP instruction in TIA Portal reverses the byte order within a data unit. Two instruction variants are provided because the S7-300/400 and S7-1200/1500 families use different parameter block layouts and instruction signatures.
6.1 SWAP for S7-1200/1500 (32-bit variant)
This variant operates on a single DWORD input and writes the byte-reversed result to a DWORD output. It is located in Basic Instructions → Converter operations → SWAP in the TIA Portal instruction catalog.
// STL equivalent (S7-1200/1500)
// "Tag_Input" : DWORD read from %IW area at the gateway offset
// "Tag_Output" : DWORD after byte swap, ready for REAL/DINT conversion
SWAP(Tag_Input := "gw_AI_raw", // DWORD, peripheral input
Tag_Output => "gw_AI_swap"); // DWORD, byte-reversed
Refer to the official Siemens KB article S7-1200/1500 SWAP instruction (entry ID 109755202) for the parameter block, error flags, and EN/ENO behavior.
6.2 SWAP for S7-300/400 (16-bit variant)
On S7-300/400, the SWAP instruction reverses the bytes of an ACCU 1 word. It is a standalone instruction without an explicit parameter block.
// STL equivalent (S7-300/400)
L "gw_AI_raw" // Load 32 bits from process image
SWAP // Byte-reverses the low word of ACCU 1
SWAP // Reverses the high word of ACCU 1
T "gw_AI_swap" // Store back; effectively a full DWORD reverse
Two consecutive SWAPs on the S7-300/400 are required to reverse all four bytes of a 32-bit value. A single SWAP reverses only the bytes within the low word (16 bits).
6.3 Selecting the Correct Variant
| PLC Family | Instruction Block | Operates On | Calls Required for 32-bit Reverse |
|---|---|---|---|
| S7-1200 | SWAP (32-bit block) | DWORD → DWORD | 1 |
| S7-1500 | SWAP (32-bit block) | DWORD → DWORD | 1 |
| S7-300 | SWAP (STL) | 16-bit word in ACCU 1 | 2 (low + high word) |
| S7-400 | SWAP (STL) | 16-bit word in ACCU 1 | 2 (low + high word) |
7. Step-by-Step Resolution Procedure
Prerequisites
- ADFWeb HD67719-IP-A1 with at least one BACnet AI object exposed as 4 bytes in a Profinet slot.
- TIA Portal V15.1 (or compatible) with the project containing the gateway as a Profinet IO device.
- The HW identifier of the gateway's input submodule (visible under Device view → Properties → System constants in TIA Portal).
- A known test value (e.g., force the BACnet object to 23.7 °C, which is
0x41BD70A4in IEEE-754 single precision).
Step 1 – Confirm the BACnet value at the network level
- Install a BACnet browser (YABE, BACnet Discovery Tool) on a laptop on the same IP subnet as the HD67719.
- Discover the device, read the AI object at instance 20400, and confirm the present value is 23.7.
- Record the hex bytes shown by the browser; this is the big-endian reference:
41 BD 70 A4.
Step 2 – Add the gateway to the TIA Portal project as a Profinet device
- Import the ADFWeb GSDML file (provided on the ADFWeb USB stick or download portal).
- Drag the HD67719-IP-A1 into the Profinet topology and assign it an IP address and device name consistent with the gateway's DIP switch / web server configuration.
- Map the gateway's input submodule to a starting address in the S7 process image, for example
%IW100for the first 4 bytes of the AI object.
Step 3 – Observe the raw input image
- Download the project to the PLC and go online.
- Open a watch table and monitor the four input bytes at the mapped address (
%IB100through%IB103, or as a DWORD at%ID100). - Expected raw value (no swap applied):
0x41BD70A4at the byte level only if the gateway has been configured for little-endian. With the default big-endian gateway setting, the PLC will display the DWORD as0x A470BD41because the CPU reinterprets the bytes in little-endian order.
Step 4 – Apply the SWAP instruction
For an S7-1200 or S7-1500:
// FB or FC block – S7-1200/1500
// Read 4 bytes from the gateway input image as DWORD
"gw_AI_raw" := %ID100; // Raw little-endian interpretation
// Perform full DWORD byte reverse
SWAP(Tag_Input := "gw_AI_raw",
Tag_Output => "gw_AI_swap");
// Interpret the corrected DWORD as a 32-bit IEEE-754 REAL
"gw_AI_value" := DWORD_TO_REAL("gw_AI_swap");
For an S7-300 or S7-400:
// STL in OB1 or a dedicated FC – S7-300/400
L %ID 100 // Load 4 bytes (raw, little-endian interpreted)
SWAP // Reverse low word
SWAP // Reverse high word
T "gw_AI_swap" // Store fully reversed DWORD
// Interpret as REAL
L "gw_AI_swap"
DTR // DWORD to REAL (32-bit IEEE-754)
T "gw_AI_value"
Step 5 – Scale the engineering value (if required)
If the BACnet object is a scaled count rather than a REAL, use NORM_X and SCALE_X (S7-1200/1500) or manual scaling (S7-300/400) to convert the integer count to engineering units.
// S7-1200/1500 scaling example: 0–27648 raw → 0.0–100.0 %
"gw_AI_pct" := SCALE_X(MIN := 0.0,
VALUE := NORM_X(MIN := 0,
VALUE := "gw_AI_value",
MAX := 27648),
MAX := 100.0);
8. Verification Procedure
- Go online in TIA Portal with the watch table open on
gw_AI_raw,gw_AI_swap, andgw_AI_value. - Force the BACnet object to three reference values: 0.0, 1.0, and 23.7.
- Confirm that
gw_AI_swapdisplays the expected big-endian hex (e.g.,0x3F800000for 1.0). - Confirm that
gw_AI_value(REAL) matches the forced BACnet value within IEEE-754 rounding tolerance. - Toggle the BACnet object between two extreme values (e.g., 0.0 and 100.0) ten times in succession to confirm the swap is stable and not dependent on the input pattern.
- Cycle power to the PLC to verify that the swapped value is correctly reconstructed on cold restart.
9. Edge Cases and Field-Tested Caveats
9.1 Multi-point configurations
If the HD67719 is configured to expose multiple BACnet objects in a single contiguous slot, ensure that the SWAP is applied to each 4-byte (or 2-byte) block individually, not to the entire block. Applying a single SWAP across an 8-byte block will corrupt the data. Use a loop or explicit field selection.
9.2 16-bit BACnet objects
For a 16-bit BACnet integer (Unsigned or Signed), a single word swap is sufficient, but the S7-1200/1500 SWAP block operates on a DWORD. Mask the result with WORD_TO_INT(DWORD_TO_WORD(swap_result)) to extract the lower 16 bits.
9.3 COV (Change of Value) subscriptions
If the gateway is configured for COV instead of polling, the input image will only update when the BACnet value changes by more than the configured COV increment. This can simulate a "stuck value" if the COV increment is too large. Verify the COV increment in the gateway's web interface.
9.4 IEEE-754 NaN and Inf
BACnet devices may return 0x7F800000 (+Inf), 0xFF800000 (-Inf), or 0x7FC00000 (NaN) for faulted or out-of-range inputs. The S7-1200/1500 REAL type follows IEEE-754 and will propagate these values. Add validity checks in the application code to avoid saturating downstream control loops.
9.5 Big-endian configured in ADFWeb
Some ADFWeb firmware versions allow the gateway to be configured in little-endian mode ("LSB first" in the Compositor). In that case, the SWAP instruction is not required. Mixing gateway-side and PLC-side byte swaps is a common cause of the problem recurring after a gateway firmware update.
9.6 Negative-value handling
For signed 32-bit integers in the range -2,147,483,648 to 2,147,483,647, the SWAP must be applied before the integer interpretation. If DWORD_TO_DINT is applied first, the sign bit may be in the wrong position and the conversion will yield a wrong value. The byte reverse must occur on the raw DWORD before any integer interpretation.
9.7 Watch table display format
TIA Portal V15.1 watch tables can display DWORDs in HEX or DEC. Make sure the HEX column is enabled to compare directly with the expected BACnet payload. The DEC view hides the byte ordering problem because it shows the integer interpretation of the (incorrect) little-endian value.
9.8 Profinet slot alignment
ADFWeb gateways sometimes align 4-byte BACnet objects to a slot boundary offset of 0, 4, or 8 bytes. If the offset is non-zero within a slot, the I/O address in TIA Portal must be increased by that offset. Misalignment results in the PLC reading a partial or shifted value, which can mimic a byte-swap problem.
10. Diagnostic Watch Table Procedure
Use the following watch table as a template for online diagnostics during commissioning. Save it as WatchTable_ADFWeb_BACnet in the TIA Portal project.
// Watch table – online monitoring of the gateway BACnet point
// Add the following tags (all DWORD or REAL):
"gw_AI_raw_HEX" // HEX view of the raw %ID at the gateway offset
"gw_AI_swap_HEX" // HEX view after SWAP
"gw_AI_value_REAL" // REAL view after DWORD_TO_REAL
"gw_AI_pct_engineering" // Scaled engineering value (e.g., 0.0–100.0 %)
// Optional diagnostic tags
"gw_diag_link_ok" // BOOL: Profinet connection status (device-level)
"gw_diag_bacnet_fault" // BOOL: gateway's BACnet communication fault (if mapped)
Toggle the BACnet object through three known values (0.0, 1.0, and a project-specific reference) and record the watch table for inclusion in the commissioning report.
11. Alternative Approaches (When SWAP Is Not Acceptable)
In legacy or safety-critical codebases where adding a SWAP call is not desirable, three alternatives exist:
- Gateway-side conversion – Reconfigure the HD67719 to expose the data in little-endian (LSB first) using the ADFWeb Compositor. The SWAP in the PLC is then no longer required. Verify the gateway's firmware supports this option (firmware ≥ 1.40 typically required).
-
Manual byte assembly with PEEK/POKE – Use
PEEK_BOOL/PEEKor direct AT-view declarations to assemble the big-endian value into a REAL tag byte by byte. Slower at runtime but transparent in code review. -
Block move with explicit byte index – Use
MOVE_BLKor a loop to copy the four input bytes into a temporary array, swap the indices, and interpret the result. Useful when the SWAP instruction is unavailable in the project's instruction set.
12. Related Siemens and ADFWeb Documentation
- Siemens KB 109755202 – SWAP instruction for S7-1200/1500
- Siemens – STEP 7 Basic V15.1 system manual
- Siemens – S7-1200 Programmable Controller system manual
- ASHRAE Standard 135 – BACnet Application Layer specification (data encoding section)
- ADFWeb HD67719-IP-A1 user manual (shipped with the device; also available from the ADFWeb support portal – request the "HD67719-IP-A1 BACnet/Profinet converter user manual" PDF).
Why do I see four correct bytes in the input image but a wrong engineering value?
The four bytes are being placed into the input image in the gateway's native big-endian order (MSB first), but the SIMATIC S7-1200/1500 CPU interprets 32-bit values in little-endian order. Apply the SWAP instruction (single call for S7-1200/1500, double call for S7-300/400) to reverse the bytes before interpreting the value as REAL or DINT.
Which SWAP instruction do I use in TIA Portal V15.1 for an S7-1500?
Use the 32-bit SWAP block under Basic Instructions → Converter operations → SWAP. The block has a DWORD input and DWORD output, and a single instance reverses all four bytes. The S7-300/400 SWAP is a 16-bit STL instruction and requires two consecutive calls to fully reverse a 32-bit value.
Can the byte swap be performed inside the ADFWeb HD67719 instead of the PLC?
Yes. In the ADFWeb Compositor, change the "Byte Order" column for the affected BACnet point from "MSB first" to "LSB first." The gateway will then place the four bytes in little-endian order in the Profinet slot, and no SWAP is required in the PLC. Verify the gateway firmware supports this option (typically firmware ≥ 1.40).
My value is correct for some stimuli but inverted for others. What is wrong?
The swap is partial – only the words inside the DWORD are being reversed, not the bytes inside each word. On an S7-300/400, this indicates a single SWAP call was used instead of two. On any PLC, verify that the SWAP is applied to a DWORD (32 bits) and not to a WORD (16 bits). Use a known stimulus (e.g., 0x12345678) and check that the output is 0x78563412.
Is this a Profinet configuration error in TIA Portal?
No. The Profinet IO device configuration, slot mapping, and IP/device-name assignment are correct. The byte-swap problem originates in the data representation layer (BACnet big-endian vs. SIMATIC little-endian) and is resolved either at the gateway (Compositor setting) or in the PLC program (SWAP instruction). Re-importing the GSDML or re-assigning the IP address will not resolve the issue.