Resolving S_OFFDT Green Status Flow in TIA Portal V13 SP1

David Krause12 min read
SiemensTIA PortalTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

In TIA Portal V13 SP1, engineers using the S_OFFDT (off-delay timer) instruction in LAD (Ladder Logic) or FBD (Function Block Diagram) editors observe a visual anomaly during online monitoring: the status flow indicator on the Q (timer output) contact of the S_OFFDT block remains illuminated in green even when the boolean value of Q has dropped to logical 0. This contradicts the standard color-coding convention used throughout STEP 7 and TIA Portal, where green denotes an energized (1) signal and gray/blue denotes a de-energized (0) signal.

The condition is purely a monitoring/visualization defect in the editor. The actual scanned value of Q in the PLC's process image is correct; downstream logic and field outputs behave as expected. However, the false-positive green indicator misleads commissioning engineers who rely on status coloring to trace signal flow during fault-finding, especially in dense networks containing 100+ timer instances.

Initial reports of this defect trace back to TIA Portal V10 Basic and the issue persisted through every update up to V13 SP1, with affected CPUs including the S7-314C-2N DP and S7-313C. The behavior was never observed in STEP 5, STEP 7 (all versions), or Micro/WIN for S7-200.

Affected Software, Firmware, and Hardware

Component Confirmed Affected Not Affected
STEP 5 (all versions) — No green flow issue
STEP 7 V5.x (all versions) — No green flow issue
Micro/WIN (S7-200) — No green flow issue
TIA Portal V10 / V10 SPx Defect present —
TIA Portal V11 / V11 SPx Defect present —
TIA Portal V12 / V12 SPx Defect present —
TIA Portal V13 Defect present —
TIA Portal V13 SP1 Defect present (confirmed) —
TIA Portal V13 SP2 and later Verify against release notes —
S7-313C (CPU firmware ≥ V2.x) Reproduced —
S7-314C-2N DP (CPU firmware ≥ V2.x) Reproduced —
S7-300 (other CPU types) Likely (same editor path) —
S7-400 Same editor, same code path —
S7-1200 / S7-1500 (IEC timers) Uses TP/TON/TOF (IEC 61131-3), not S_OFFDT block —
Note: S7-1200 and S7-1500 do not expose the legacy S_OFFDT IEC timer box. They use the standard IEC 61131-3 TOF (off-delay) function block with IN, PT, Q, and ET ports. This article applies only to S7-300/400 projects using the classical S_OFFDT instruction in TIA Portal.

Root Cause Analysis

The S_OFFDT instruction in the S7-300/400 instruction set is defined in the SIMATIC S7-300 Programmable Controller System Manual and the STEP 7 Professional V13.0 / V13.0 SP1 System Manual. Its terminal definitions are:

Pin Type Description
IN BOOL (input) Start input; falling edge initiates the off-delay countdown
TV S5TIME (input) Preset time value (e.g., S5T#2s = 2 seconds)
R BOOL (input) Reset input; rising edge terminates timing and clears Q
BI WORD (output) Current time, binary-coded (residual time)
BCD WORD (output) Current time, BCD-coded (residual time)
Q BOOL (output) Status of timer; Q = 1 while timing or IN is held high

The behavior of S_OFFDT is summarized as:

  1. When IN transitions from 0 → 1, Q immediately goes to 1.
  2. While IN remains 1, Q stays 1 indefinitely (no timing occurs).
  3. When IN transitions from 1 → 0, the off-delay timing starts; Q remains 1 for the duration of TV.
  4. When the residual time reaches zero, Q drops to 0.
  5. A rising edge on R at any time clears the timing and forces Q to 0 immediately.

The defect is not in the firmware scan logic of the CPU; the bit at the process-image address wired to Q transitions correctly between 0 and 1. The defect is in the TIA Portal LAD/FBD online monitoring renderer, specifically in the path that paints the status overlay on the boolean output pin of the S5 timer box. The renderer appears to latch the previously-energized state and fail to repaint the pin's status attribute when the bit transitions back to 0. The trigger appears to be:

  • The timer block was previously scanned while IN was true and Q was 1.
  • After IN falls and the residual time elapses, the underlying status bit transitions to 0 in memory but the graphical overlay for the Q pin is not refreshed by the editor's invalidation loop.
  • Forcing an attribute change at the same network (writing to Q via a flag) or triggering the timer's R path causes the editor to invalidate the entire network and the false green is repainted correctly.

This explains why both empirical workarounds (intermediate flag on Q, and a reset pulse on R) clear the visual defect: both produce a network-level status invalidation event in the editor.

Workaround 1: Intermediate Flag on Q Output

The cleanest field-proven workaround is to read the timer output into an intermediate boolean tag and use that tag in downstream logic instead of the raw Q pin. The intermediate tag is a normal memory bit and is rendered correctly by the online monitor.

Step-by-Step Procedure

  1. In the S7-300 symbol table or PLC tag table, allocate a new BOOL tag, e.g., "Timer_Q_01_OK", in the Merker (M) area, e.g., M100.0.
  2. In the same network as the S_OFFDT block, add a normally-open contact assigned to the timer's Q pin, and wire it to a coil driving M100.0. This creates a one-cycle mirror of the timer's output.
  3. Replace every downstream contact that previously referenced the S_OFFDT Q pin with a contact on "Timer_Q_01_OK" (or M100.0).
  4. Save, compile, and download the modified block to the CPU.
  5. Go online and monitor the network. The flag's status will now track Q correctly and the false green on the timer's output pin will be effectively isolated from the rest of the program.

Ladder Logic Example

Network 17 — Off-delay pump drain timer
      IN     TV              R        BI    BCD   Q
|--| |----(S5T#30s)-----|/|----[T1]---[MW20]---[MW22]---( M100.0 )--|
  ↑ I0.0                  ↑ M50.0

Network 18 — Downstream consumer (use M100.0, not Q)
|--| M100.0  Q0.4  |
|--|  /     |( )|----|
  Drain valve

Workaround 2: Reset Pulse to R Input

A second workaround that requires no code change in the consumer networks is to periodically apply a rising edge to the R input of every S_OFFDT. The reset forces the editor to invalidate the network overlay.

Caution: This is a display-only workaround and must be implemented in a way that does not interfere with real timing. The reset must be a one-shot pulse generated after the legitimate off-delay has expired, never during active timing.

Implementation Pattern

  1. Add a clock generator OB (e.g., a 1 Hz bit in OB35) and route it through an edge detector to produce a 100 ms pulse on the timer's R input.
  2. AND the reset pulse with a contact of the timer's Q output, so the reset only fires when Q is currently 1. This guarantees the timer's real off-delay will be retriggered only after the legitimate TV expires.
  3. Alternatively, drive R from a watchdog tag that becomes true when the timer's residual time BI (binary time word) reaches zero, OR with the global clock pulse.

Ladder Logic Example

Network 17 — Off-delay pump drain timer
      IN     TV              R        BI    BCD   Q
|--| |----(S5T#30s)----|M200.0|----[T1]---[MW20]---[MW22]--|
  ↑ I0.0                  ↑ generated below

Network 16 — Generate reset pulse (one-shot, fires only when Q=1)
| M200.0  OB35_CLK  Q      R     M200.0 |
|   |     | |     |  |    |/|   | (S)  |
|----| |  |P|----|--|/|---| |---|     |--|
       ↑      ↑      ↑     ↑
    Q contact 100ms  neg.  Q echo
    on Q pin   pulse  edge

Permanent Resolution Path

Because the defect is in the TIA Portal editor rather than in the CPU firmware, the only permanent fix is to upgrade TIA Portal to a version in which the renderer is corrected. Recommended steps:

  1. Review the readme/release notes of each TIA Portal service pack from V13 SP2 onward. Siemens documents editor corrections in the "Notes on the S7-300/400 timer boxes" or "Online & Diagnosis" sections of the release notes.
  2. Open the TIA Portal installation: Help → Installed Software and note the exact build (e.g., V13.0 SP1 Upd 6, build 6.0.0.0). Compare against the official Siemens delivery release list at Siemens Industry Online Support.
  3. For new projects, prefer TIA Portal V15.1 or later for S7-300/400 work. Both the S7-300/400 legacy timer boxes and the modern SCL IEC timers are available, and the editor renderer has been reworked.
  4. For projects that must remain on V13 SP1 (regulatory freeze, validated system), keep the intermediate-flag workaround in place and add a code review note in the project QA log to ensure no new S_OFFDT instance is added without a paired mirror tag.

Verification Procedures

After applying either workaround, perform the following commissioning checks before signing off the network:

  1. Bit-level verification: Open a watch table (VAT) and force the timer's IN input high for at least 5 seconds, then drop it. Observe the boolean value of the timer's Q bit, the mirror flag (workaround 1), and the downstream contact. All three must read 1 while IN is high and during the off-delay, then transition cleanly to 0 at the same scan.
  2. Edge verification: Use the Monitor / Modify function in TIA Portal to apply a 1-shot pulse on the reset input (workaround 2) and confirm that Q returns to 0 within one scan cycle of the reset edge.
  3. Visual verification: With online monitoring active, scan the network in question and confirm the Q pin of the S_OFFDT block either (a) is hidden behind a flag contact (workaround 1) or (b) is repainted to gray/blue after the reset pulse (workaround 2).
  4. Cycle-time check: Confirm that adding 150 mirror flags does not exceed the OB1 cycle time budget. Each S_OFFDT consumes one scan to evaluate plus one scan for the mirror contact; a 150-timer project adds roughly 0.2–0.5 ms on a 314C-2N DP, well within typical 100 ms budgets.
  5. Documentation update: Add a cross-reference table from each S_OFFDT instance to its mirror flag in the project's I/O list, e.g., T1 → M100.0, T2 → M100.1, … T150 → M118.5.

S_OFFDT Functional Reference and Timing Diagram

The off-delay timing sequence for S_OFFDT with a preset of S5T#5s is illustrated below.

t (s) IN (I0.0) Q (T1.Q) BI (residual time, decremented) t0 t1 t2 (= t1+5s) t0: IN=0, Q=0, BI=0 t1: IN 0→1, Q 0→1 (instant), no timing while IN=1 t2: TV elapsed, Q 1→0, BI 0

Comparison with STEP 7 Classic and Micro/WIN Behavior

Property STEP 5 STEP 7 V5.x Micro/WIN S7-200 TIA Portal V13 SP1 TIA Portal V15+
Q rendered as gray when 0 Yes Yes Yes No (defect) Yes (corrected)
Q reflects actual scanned bit Yes Yes Yes Yes (PLC scan is correct) Yes
BI/BCD outputs color-rendered correctly Yes Yes Yes Yes (defect is Q-only) Yes
Reset edge visually repaints Q n/a n/a n/a Yes (forces repaint) n/a
Mirror flag workaround required? No No No Yes (if >10 instances) No

Troubleshooting Matrix

Symptom Likely Cause Verification Remediation
Green flow on Q when value is 0 TIA Portal V13 SP1 editor renderer defect Force Q in VAT, watch value Apply mirror flag or upgrade TIA
Green flow on Q when value is 1 Normal energised state Force Q in VAT, watch value No action
Q stays 0 even with IN held high CPU in STOP, or R input held true, or TV=0 Check CPU run LED, R input bit, TV literal Bring CPU to RUN, release R, set TV>0
Q never goes back to 0 after IN falls TV set too long, or residual time not elapsing due to scan stall Check BI word decrement in VAT Reduce TV, investigate scan time
Green flow persists after reset pulse Reset pulse too short to trigger repaint Lengthen pulse to ≥1 OB1 scan Hold R for at least one full scan
Mirror flag also green when 0 Mirror tag accidentally tied to a forced value Check force table Remove force on M flag

Project Migration Considerations

When migrating an S7-300/400 program that uses 150+ S_OFFDT instances from TIA Portal V13 SP1 to a later release, audit the project for residual mirror-flag workarounds. If the target TIA Portal version has the corrected renderer:

  1. Keep the mirror flags if they participate in HMI tag mapping or external visibility — they remain functionally correct.
  2. If the mirror flags exist only to suppress the green-flow defect and the target editor is fixed, the flags can be removed in a controlled refactor to reclaim Merker addresses.
  3. Always re-validate all 150 timer networks after a TIA Portal upgrade, because the S5TIME literal evaluation and the network layout renderer can change between major versions.

Safety and Documentation Requirements

For safety-related circuits (SIL 1/2/3 per IEC 61508, PL a–e per ISO 13849-1) the off-delay timer must be implemented with a certified safety timer block such as F_OFFDT from the S7-300F / S7-400F libraries, not the standard S_OFFDT. The display defect described in this article is purely visual and does not affect the safety integrity of the F-CPU; however, the standard S_OFFDT must never be used in the safety path itself, regardless of editor rendering. Document this exclusion in the project's Safety Requirement Specification (SRS) and the validation report.

FAQ

Does the S_OFFDT green-flow issue affect the actual PLC output behavior?

No. The defect is in the TIA Portal V13 SP1 online monitor's LAD/FBD renderer only. The boolean value of Q in the process image transitions correctly between 0 and 1. Field outputs wired to Q (or to a mirror flag of Q) behave as specified in the SIMATIC S7-300 system manual.

Which TIA Portal versions are confirmed affected by the S_OFFDT green-flow defect?

Field reports confirm the issue in TIA Portal V10 Basic, V11, V12, V13, and V13 SP1. The defect was not present in STEP 5, STEP 7 V5.x, or Micro/WIN. Siemens typically bundles editor corrections in service pack updates; check the release notes of V13 SP2 and later for explicit correction entries.

What is the quickest workaround to suppress the false green on S_OFFDT Q output?

Add an intermediate BOOL Merker tag (e.g., M100.0) wired as a contact of the timer's Q pin in the same network, then reference the Merker tag in all downstream logic. The Merker tag is rendered correctly by the online monitor and isolates the visual defect from the rest of the program.

Can I pulse the R input to clear the green indicator on every scan?

You can, but only after the legitimate off-delay has expired. Pulse R for at least one full OB1 scan only when the timer's Q is already 1, so the real timing behavior is not disturbed. This approach is more invasive than the mirror-flag workaround and is generally reserved for legacy code that cannot be refactored.

Does this defect apply to S7-1200 or S7-1500 PLCs?

No. S7-1200 and S7-1500 do not expose the legacy S_OFFDT box; they use the IEC 61131-3 TOF function block. The renderer for the IEC timers does not exhibit the false-green behavior. This article applies only to S7-300/400 projects using the legacy S_OFFDT instruction in TIA Portal V10 through V13 SP1.

What is the recommended permanent fix for a project that must stay on TIA Portal V13 SP1?

Use the mirror-flag workaround for every S_OFFDT instance, document each mapping in the project's I/O list, and apply a code-review rule to ensure no new S_OFFDT is added without a paired mirror flag. For a permanent fix, migrate the project to TIA Portal V15.1 or later after confirming the renderer is corrected in the target version's release notes.

Back to blog