Resolving 'Invalid Address' Error in S7-1200 PTO Configuration

David Krause12 min read
S7-1200SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview: 'Direccion no valida' / 'Invalid Address' on PTO Parameterization

When configuring a Pulse Train Output (PTO) on a Siemens SIMATIC S7-1200 CPU in TIA Portal, technicians frequently encounter the runtime or compile-time message The parameterization of the pulse generator (PTO) is not valid (Invalid address) — the original Spanish being La parametrizacion del generador de impulsos (PTO) no es valida (Direccion no valida). The error blocks the motion output, prevents the CTRL_PTO instruction from compiling cleanly, stops the project download, or disables the pulse output during operation.

The message appears in one of three locations:

  • Device configuration: The Properties dialog for the PTO channel shows a red "Invalid address" indicator on the pulse generator.
  • Compile log: TIA Portal flags CTRL_PTO or the axis technology object with Address of pulse generator invalid.
  • Online diagnostics: The CPU diagnostic buffer logs a parameter error event tied to PTO parameter assignment.
The PTO function is supported only on the S7-1200 family. The S7-200 PTO API uses a different instruction set and is not interchangeable. For full motion control features on the S7-1200, the CPU must be a DC/DC/DC variant with firmware V4.0 or later.

Affected Hardware and Firmware

CPU Model Order Number (6ES7...) Onboard PTO Channels Min. Firmware for CTRL_PTO Max PTO Frequency
CPU 1211C DC/DC/DC 211-1AD30-0XB0 or later 2 V4.0 100 kHz (Q0.0-Q0.1)
CPU 1212C DC/DC/DC 212-1AD30-0XB0 or later 2 V4.0 100 kHz (Q0.0-Q0.1)
CPU 1214C DC/DC/DC 214-1AG30-0XB0 or later 4 V4.0 100 kHz (Q0.0-Q0.3)
CPU 1215C DC/DC/DC 215-1AG30-0XB0 or later 4 V4.0 100 kHz (Q0.0-Q0.3)
CPU 1217C DC/DC/DC 217-1AG30-0XB0 or later 4 V4.0 1 MHz (Q0.0-Q0.3)

Reference: Configuring a pulse channel for PWM or PTO - SIMATIC S7-1200 Manual Collection.

AC/DC/RLY variants cannot source PWM/PTO at the frequencies required for stepper or servo pulse input because the relay outputs cannot switch fast enough. Only the DC/DC/DC transistor outputs support PTO.

Root Cause Analysis

Six distinct root conditions produce the "Invalid address" message. Diagnose by working through them in this order.

1. PTO channel not enabled in Device Configuration

The most common cause. The pulse generator output is disabled by default. The output byte/bit is therefore not assigned a hardware identifier (HW ID), and CTRL_PTO cannot bind to it. Symptoms: no PTO listed under the CPU in the project tree, and Properties > Pulse generators shows the channel as "Not used".

2. Hardware mismatch between PTO channel and the physical output

The output selected in the PTO configuration is the wrong physical terminal. For example, trying to assign a PTO to a Q-output that is already in use by the high-speed counter (HSC) or by an axis technology object. The error is raised at compile time when the assignment overlaps.

3. CTRL_PTO HW_ID does not match the configured pulse generator

After enabling the PTO in Device Configuration, TIA Portal assigns a hardware identifier (commonly 256 through 259). The CTRL_PTO instruction's HW_ID input must reference the same identifier, not the I/O address (P#Q0.0). Symptom: compile error Hardware identifier not found or runtime error Parameter assignment of pulse generator not valid.

4. Project downloaded to wrong CPU

If the project target device is a different CPU type than the one physically connected, the PTO outputs that exist on the target may not map to the same terminals on the detected CPU, and the HW_ID becomes invalid.

5. Firmware version too old for the configured feature

PTO motion control technology objects require firmware V4.0 or later. V3.x CPUs do not support the newer motion APIs. Some frequency options, such as 1 MHz on the CPU 1217C, require V4.1+.

6. PTO and HSC share the same input/output pin

On S7-1200, a single physical output can be allocated to either a PTO or an HSC, not both. The error is raised at compile time when the assignment overlaps.

Diagnostic Procedure

  1. Open the project in TIA Portal and select the CPU device in the project tree.
  2. Open Device view and double-click the CPU module.
  3. Navigate to Properties > Pulse generators (PTO/PWM) in the inspector window.
  4. Note the channel selection: PTO1, PTO2, PTO3, PTO4.
  5. For each PTO channel, check the Output dropdown. It should show a fixed Q-address (for example, Q0.0 for PTO1 on a CPU 1214C).
  6. Right-click the CPU and choose Compile > Hardware (rebuild all). Read the messages carefully.
  7. Open the Program blocks and inspect the CTRL_PTO instance DB. Expand it and check the HW_ID parameter under Input.
  8. Online: right-click the CPU and select Online & Diagnostics > Diagnostics buffer. Look for events in the 16#FFD0-16#FFD9 range or motion events related to PTO parameter error.
  9. Compare the online HW_ID (read from the instance DB) with the configured HW_ID in Device Configuration (Properties > System constants).
Never edit a download without first performing an upload of the online version. Stale offline configurations frequently produce the "Invalid address" message when the project is modified on a different PC and then re-downloaded.

Step-by-Step Solution

Step 1 - Enable the PTO channel in Device Configuration

  1. In the TIA Portal project tree, double-click Device & Networks to open the device view.
  2. Click the CPU module (not the signal board).
  3. In the Properties inspector, go to Pulse generators (PTO/PWM).
  4. Select channel PTO1/PWM1.
  5. Set the Operating mode drop-down to PTO (pulse train output).
  6. Optionally enable PTO2/PWM2, PTO3/PWM3, PTO4/PWM4 if your application needs multiple pulse channels.
  7. Close the properties pane. The hardware identifier is now created (typically 256, 257, 258, 259 in sequence).

Reference: Siemens SIMATIC S7-1200 Manual: Configuring a pulse channel for PWM or PTO.

Step 2 - Set the output terminal and direction control

  1. Still in the Pulse generators properties, expand the channel selected.
  2. The Pulse output field shows the assigned Q-bit (for example, Q0.0 for PTO1). This field is read-only because the assignment is fixed by hardware.
  3. If a direction output is required (for example, for a stepper drive with a DIR input), enable Use direction output and select a Q-bit from the dropdown. The direction bit is one of the remaining high-speed outputs on the CPU.
  4. Optionally enable Output of the HSC value if the application needs the current position to be readable from the system.

Step 3 - Read the hardware identifier

  1. Right-click the CPU in the project tree and choose Properties.
  2. Navigate to System constants.
  3. Locate the constants named PTO1_PULSE, PTO1_DIR, PTO2_PULSE, and so on.
  4. Note the integer value next to each (for example, 256, 257). These are the HW_IDs you must reference in your program.

Step 4 - Add the CTRL_PTO instruction

  1. Open the program block (OB1) where motion control is required.
  2. In the project tree, expand Instructions > Technology > Pulse.
  3. Drag CTRL_PTO into the network.
  4. Click the ??? on the HW_ID input and enter the system constant for the pulse channel, for example, "PTO1_PULSE".
  5. Click ??? on the instance DB drop-down to create a new instance data block, for example, iDB_PTO1.

Step 5 - Wire CTRL_PTO inputs and outputs

A minimal CTRL_PTO call in Structured Text (SCL) for stepper control:

// Drive enable input
iDB_PTO1.EN          := TRUE;             // Enable pulse output
iDB_PTO1.SW_STOP     := FALSE;            // No software stop
iDB_PTO1.RESUME      := FALSE;            // No resume
iDB_PTO1.STEP_NUMBER := 16#80000000;      // Single step, no continuous run
iDB_PTO1.SET_DUTY    := 50;               // Not used for PTO
iDB_PTO1.FREQUENCY   := 5000;             // 5 kHz pulse rate
iDB_PTO1.COUNT       := 2000;             // Number of pulses

// Status outputs (read for diagnostics)
rStatus := iDB_PTO1.STATUS;
bBusy   := iDB_PTO1.BUSY;
bError  := iDB_PTO1.ERROR;

For LAD/FBD, the equivalent block has these terminals:

Input Type Description
HW_ID HW_IO Hardware identifier of the pulse generator (system constant, e.g., "PTO1_PULSE")
EN BOOL Enable pulse output (TRUE = output active)
SW_STOP BOOL Software-controlled stop (TRUE = immediate stop, no ramp)
RESUME BOOL Resume after interrupted motion (TRUE = continue)
STEP_NUMBER DWORD Number of pulses; hex 0x80000000 = continuous; positive = forward, negative = reverse (when DIR output enabled)
SET_DUTY INT Duty cycle 0-100 (only relevant for PWM, ignored for PTO)
FREQUENCY DINT Output frequency in Hz
COUNT DINT Step count for the next motion segment (used with PTO multi-segment)

Step 6 - Compile, download, and verify

  1. Right-click the CPU and choose Compile > Hardware and software (rebuild all).
  2. Resolve any remaining error messages. The "Invalid address" message should now be gone.
  3. Download to the CPU.
  4. Go online and monitor the CTRL_PTO instance DB online values.
  5. Force EN := TRUE momentarily and confirm the Q-output shows pulses with a scope or counter.

Hardware Configuration Patterns

Pattern A: Single-axis stepper with direction

For a stepper drive that takes PULSE and DIR signals:

Signal S7-1200 Terminal Drive Terminal (typical)
PULSE+ Q0.0 (PTO1 pulse) PUL+ or STEP+
PULSE- Q0.1 (return/direction) * PUL- or STEP-
DIR+ Q0.2 (PTO1 direction) ** DIR+
DIR- Q0.3 (return) ** DIR-

* Most drives use differential inputs; wire PULSE- to the drive's reference ground or differential return.
** Q0.2 and Q0.3 are NOT shared with the next PTO channel; they are dedicated DIR outputs.

Pattern B: Servo drive with CW/CCW pulse

Set the PTO channel to use Pulse + Direction in Device Configuration. The drive must be configured for Pulse + Sign mode. Frequency ranges: 500 Hz minimum, up to 1 MHz on CPU 1217C outputs Q0.0-Q0.3.

Pattern C: PTO versus Motion Control axis technology object

S7-1200 firmware V4.x offers two motion APIs:

  • CTRL_PTO: simple pulse output with no ramp. Good for steppers that take step + direction. Use when you need raw, real-time pulse stream control.
  • Axis technology object (TO_Axis_PTO): full motion control with ramp, jerk limit, homing, and positioning table. Use when you need an absolute move or synchronized motion.

If both are configured for the same output, the second one configured takes priority and the first one reports the "Invalid address" error.

Verification Tests

  1. Static check: Open the Properties of the PTO channel in Device Configuration. The Address area must show a valid HW identifier, not "-".
  2. Compile check: TIA Portal should report 0 errors and 0 warnings for the project.
  3. Download check: Successful download with no Cannot write technology object warning.
  4. Online diagnostic buffer check: No events with ID 16#FFD1 (technology object parameter error) immediately after download.
  5. Oscilloscope check: Probe the assigned Q-bit with a scope. Expect 50% duty cycle pulses at the configured frequency when EN is TRUE.
  6. Drive response check: Stepper or servo should execute the commanded number of steps. Use the drive's position-feedback display (for example, the integrated display on a SINAMICS V90) to confirm the commanded pulse count was received.

Error Code Reference for CTRL_PTO STATUS

STATUS (hex) Meaning Corrective Action
0x0000 No error -
0x8001 Hardware identifier invalid Re-link HW_ID to the system constant, not the I/O address
0x8002 Operating mode not PTO Set channel to PTO in Device Configuration
0x8003 Frequency outside limits Check max frequency of the selected output (100 kHz or 1 MHz)
0x8004 Step count negative and direction disabled Enable direction output or use positive count
0x8005 Software stop active Set SW_STOP := FALSE
0x800D Hardware fault on output Check wiring, short circuit, overload
0x8090 CPU in STOP Run the CPU; verify RUN LED
0x80C0 Axis technology object active on same output Disable the conflicting TO or use the other API

Frequently Confused Settings

Mistake Symptom Fix
Using the Q-address (P#Q0.0) as HW_ID "Invalid hardware identifier" compile error Use the system constant (PTO1_PULSE)
Enabling PWM instead of PTO No pulse output, STATUS 0x8002 Change operating mode drop-down to PTO
Assigning Q0.4/Q0.5 to a high-frequency application Frequency is capped at 20 kHz Use Q0.0-Q0.3 for > 20 kHz step rates
Forgetting the signal board address PTO on SB outputs not working Confirm SB is detected in Device Configuration
Adding two CTRL_PTO instances with the same HW_ID Compile warning, runtime race Use one instance per PTO channel
Configuring STEP_NUMBER as 0 expecting infinite pulses No motion (zero pulses) Use 16#80000000 for continuous

Field-Commissioning Checklist

  • CPU catalog number ends in DC/DC/DC; not AC/DC/RLY.
  • Firmware version V4.0 or later under Online & Diagnostics > Identification.
  • PTO channel enabled in Device Configuration with the correct mode (PTO, not PWM).
  • System constant for the pulse channel used as the HW_ID input of CTRL_PTO.
  • Direction output enabled only if the drive requires DIR (or skip for CW/CCW with two PTO channels).
  • FREQUENCY value within the Q-output capability (1 MHz max on Q0.0-Q0.3 of CPU 1217C, 100 kHz on other CPUs).
  • Wiring uses shielded twisted pair for PULSE/DIR signals; shield grounded at the drive end only.
  • Drive's pulse input mode matches the S7-1200 configuration (Pulse + Direction or CW/CCW).
  • 24 V supply to the S7-1200 output groups is sourced from a clean, isolated 24 VDC rail.
  • Digital outputs used for PTO are NOT used elsewhere (no output coil, no HSC, no other TO).
If the drive does not move and the STATUS byte reads 0x8001, do not suspect the wiring first. Re-verify the HW_ID linkage in the project. Over 80% of "Invalid address" cases in the field are caused by a stale HW_ID input on CTRL_PTO after the project was migrated from a different CPU type.

FAQ

Why does my S7-1200 PTO show 'Invalid address' even though the output LED is on?

The CTRL_PTO instruction's HW_ID input is not linked to the pulse channel's system constant. Open the CTRL_PTO instance DB, expand Input, and replace the numeric or symbolic value with the constant "PTO1_PULSE" or "PTO2_PULSE" from the System constants list of the CPU.

How many PTO channels does my CPU 1214C support and which outputs do they use?

CPU 1214C DC/DC/DC supports four PTO/PWM channels. PTO1 uses Q0.0, PTO2 uses Q0.1, PTO3 uses Q0.2, and PTO4 uses Q0.3. Each pulse channel can additionally drive one dedicated direction output (Q0.4, Q0.5, Q0.6, Q0.7 respectively). Outputs Q0.0-Q0.3 switch at up to 100 kHz; Q0.4-Q0.5 are limited to 20 kHz.

Can I use a signal board (SB) for PTO on an S7-1200?

No. The pulse generators are tied to the onboard CPU outputs only. Signal boards and signal modules can be used for high-speed counters and standard digital I/O, but not for PTO/PWM. See the SIMATIC S7-1200 system manual for the assignment table.

What is the difference between CTRL_PTO and the axis technology object?

CTRL_PTO is a low-level instruction that produces a pulse stream with a fixed frequency and step count, with no ramp or jerk limit. The axis technology object (TO_Axis_PTO) provides positioning, homing, jogging, and a configurable acceleration/deceleration profile. Use CTRL_PTO for simple stepper applications; use the TO when the application needs absolute positioning or coordinated motion.

My project compiled fine but the stepper does not move. What should I check first?

Verify the output wiring with an oscilloscope on Q0.0. If a clean pulse train is present, check the drive's pulse input mode (Pulse + Direction versus CW/CCW) and the active level of the PULSE signal. Many drives require the PULSE signal to be active-high; S7-1200 transistor outputs sink current, so a pull-up resistor at the drive input is often required.

Back to blog