Problem Overview
In TIA Portal V13 SP1, engineers using the S_OFFDT (off-delay timer) instruction in LAD (Ladder Logic) or FBD (Function Block Diagram) editors observe a visual anomaly during online monitoring: the status flow indicator on the Q (timer output) contact of the S_OFFDT block remains illuminated in green even when the boolean value of Q has dropped to logical 0. This contradicts the standard color-coding convention used throughout STEP 7 and TIA Portal, where green denotes an energized (1) signal and gray/blue denotes a de-energized (0) signal.
The condition is purely a monitoring/visualization defect in the editor. The actual scanned value of Q in the PLC's process image is correct; downstream logic and field outputs behave as expected. However, the false-positive green indicator misleads commissioning engineers who rely on status coloring to trace signal flow during fault-finding, especially in dense networks containing 100+ timer instances.
Initial reports of this defect trace back to TIA Portal V10 Basic and the issue persisted through every update up to V13 SP1, with affected CPUs including the S7-314C-2N DP and S7-313C. The behavior was never observed in STEP 5, STEP 7 (all versions), or Micro/WIN for S7-200.
Affected Software, Firmware, and Hardware
| Component | Confirmed Affected | Not Affected |
|---|---|---|
| STEP 5 (all versions) | — | No green flow issue |
| STEP 7 V5.x (all versions) | — | No green flow issue |
| Micro/WIN (S7-200) | — | No green flow issue |
| TIA Portal V10 / V10 SPx | Defect present | — |
| TIA Portal V11 / V11 SPx | Defect present | — |
| TIA Portal V12 / V12 SPx | Defect present | — |
| TIA Portal V13 | Defect present | — |
| TIA Portal V13 SP1 | Defect present (confirmed) | — |
| TIA Portal V13 SP2 and later | Verify against release notes | — |
| S7-313C (CPU firmware ≥ V2.x) | Reproduced | — |
| S7-314C-2N DP (CPU firmware ≥ V2.x) | Reproduced | — |
| S7-300 (other CPU types) | Likely (same editor path) | — |
| S7-400 | Same editor, same code path | — |
| S7-1200 / S7-1500 (IEC timers) | Uses TP/TON/TOF (IEC 61131-3), not S_OFFDT block | — |
S_OFFDT IEC timer box. They use the standard IEC 61131-3 TOF (off-delay) function block with IN, PT, Q, and ET ports. This article applies only to S7-300/400 projects using the classical S_OFFDT instruction in TIA Portal.Root Cause Analysis
The S_OFFDT instruction in the S7-300/400 instruction set is defined in the SIMATIC S7-300 Programmable Controller System Manual and the STEP 7 Professional V13.0 / V13.0 SP1 System Manual. Its terminal definitions are:
| Pin | Type | Description |
|---|---|---|
| IN | BOOL (input) | Start input; falling edge initiates the off-delay countdown |
| TV | S5TIME (input) | Preset time value (e.g., S5T#2s = 2 seconds) |
| R | BOOL (input) | Reset input; rising edge terminates timing and clears Q |
| BI | WORD (output) | Current time, binary-coded (residual time) |
| BCD | WORD (output) | Current time, BCD-coded (residual time) |
| Q | BOOL (output) | Status of timer; Q = 1 while timing or IN is held high |
The behavior of S_OFFDT is summarized as:
- When
INtransitions from 0 → 1,Qimmediately goes to 1. - While
INremains 1,Qstays 1 indefinitely (no timing occurs). - When
INtransitions from 1 → 0, the off-delay timing starts;Qremains 1 for the duration ofTV. - When the residual time reaches zero,
Qdrops to 0. - A rising edge on
Rat any time clears the timing and forcesQto 0 immediately.
The defect is not in the firmware scan logic of the CPU; the bit at the process-image address wired to Q transitions correctly between 0 and 1. The defect is in the TIA Portal LAD/FBD online monitoring renderer, specifically in the path that paints the status overlay on the boolean output pin of the S5 timer box. The renderer appears to latch the previously-energized state and fail to repaint the pin's status attribute when the bit transitions back to 0. The trigger appears to be:
- The timer block was previously scanned while
INwas true andQwas 1. - After
INfalls and the residual time elapses, the underlying status bit transitions to 0 in memory but the graphical overlay for theQpin is not refreshed by the editor's invalidation loop. - Forcing an attribute change at the same network (writing to
Qvia a flag) or triggering the timer'sRpath causes the editor to invalidate the entire network and the false green is repainted correctly.
This explains why both empirical workarounds (intermediate flag on Q, and a reset pulse on R) clear the visual defect: both produce a network-level status invalidation event in the editor.
Workaround 1: Intermediate Flag on Q Output
The cleanest field-proven workaround is to read the timer output into an intermediate boolean tag and use that tag in downstream logic instead of the raw Q pin. The intermediate tag is a normal memory bit and is rendered correctly by the online monitor.
Step-by-Step Procedure
- In the S7-300 symbol table or PLC tag table, allocate a new BOOL tag, e.g.,
"Timer_Q_01_OK", in the Merker (M) area, e.g.,M100.0. - In the same network as the
S_OFFDTblock, add a normally-open contact assigned to the timer'sQpin, and wire it to a coil drivingM100.0. This creates a one-cycle mirror of the timer's output. - Replace every downstream contact that previously referenced the
S_OFFDTQpin with a contact on"Timer_Q_01_OK"(orM100.0). - Save, compile, and download the modified block to the CPU.
- Go online and monitor the network. The flag's status will now track
Qcorrectly and the false green on the timer's output pin will be effectively isolated from the rest of the program.
Ladder Logic Example
Network 17 — Off-delay pump drain timer
IN TV R BI BCD Q
|--| |----(S5T#30s)-----|/|----[T1]---[MW20]---[MW22]---( M100.0 )--|
↑ I0.0 ↑ M50.0
Network 18 — Downstream consumer (use M100.0, not Q)
|--| M100.0 Q0.4 |
|--| / |( )|----|
Drain valve
Workaround 2: Reset Pulse to R Input
A second workaround that requires no code change in the consumer networks is to periodically apply a rising edge to the R input of every S_OFFDT. The reset forces the editor to invalidate the network overlay.
Implementation Pattern
- Add a clock generator OB (e.g., a 1 Hz bit in OB35) and route it through an edge detector to produce a 100 ms pulse on the timer's
Rinput. - AND the reset pulse with a contact of the timer's
Qoutput, so the reset only fires whenQis currently 1. This guarantees the timer's real off-delay will be retriggered only after the legitimate TV expires. - Alternatively, drive
Rfrom a watchdog tag that becomes true when the timer's residual timeBI(binary time word) reaches zero, OR with the global clock pulse.
Ladder Logic Example
Network 17 — Off-delay pump drain timer
IN TV R BI BCD Q
|--| |----(S5T#30s)----|M200.0|----[T1]---[MW20]---[MW22]--|
↑ I0.0 ↑ generated below
Network 16 — Generate reset pulse (one-shot, fires only when Q=1)
| M200.0 OB35_CLK Q R M200.0 |
| | | | | | |/| | (S) |
|----| | |P|----|--|/|---| |---| |--|
↑ ↑ ↑ ↑
Q contact 100ms neg. Q echo
on Q pin pulse edge
Permanent Resolution Path
Because the defect is in the TIA Portal editor rather than in the CPU firmware, the only permanent fix is to upgrade TIA Portal to a version in which the renderer is corrected. Recommended steps:
- Review the readme/release notes of each TIA Portal service pack from V13 SP2 onward. Siemens documents editor corrections in the "Notes on the S7-300/400 timer boxes" or "Online & Diagnosis" sections of the release notes.
- Open the TIA Portal installation: Help → Installed Software and note the exact build (e.g.,
V13.0 SP1 Upd 6, build6.0.0.0). Compare against the official Siemens delivery release list at Siemens Industry Online Support. - For new projects, prefer TIA Portal V15.1 or later for S7-300/400 work. Both the S7-300/400 legacy timer boxes and the modern SCL IEC timers are available, and the editor renderer has been reworked.
- For projects that must remain on V13 SP1 (regulatory freeze, validated system), keep the intermediate-flag workaround in place and add a code review note in the project QA log to ensure no new
S_OFFDTinstance is added without a paired mirror tag.
Verification Procedures
After applying either workaround, perform the following commissioning checks before signing off the network:
-
Bit-level verification: Open a watch table (VAT) and force the timer's
INinput high for at least 5 seconds, then drop it. Observe the boolean value of the timer'sQbit, the mirror flag (workaround 1), and the downstream contact. All three must read1whileINis high and during the off-delay, then transition cleanly to0at the same scan. -
Edge verification: Use the Monitor / Modify function in TIA Portal to apply a 1-shot pulse on the reset input (workaround 2) and confirm that
Qreturns to 0 within one scan cycle of the reset edge. -
Visual verification: With online monitoring active, scan the network in question and confirm the
Qpin of theS_OFFDTblock either (a) is hidden behind a flag contact (workaround 1) or (b) is repainted to gray/blue after the reset pulse (workaround 2). -
Cycle-time check: Confirm that adding 150 mirror flags does not exceed the OB1 cycle time budget. Each
S_OFFDTconsumes one scan to evaluate plus one scan for the mirror contact; a 150-timer project adds roughly 0.2–0.5 ms on a 314C-2N DP, well within typical 100 ms budgets. -
Documentation update: Add a cross-reference table from each
S_OFFDTinstance to its mirror flag in the project's I/O list, e.g.,T1 → M100.0, T2 → M100.1, … T150 → M118.5.
S_OFFDT Functional Reference and Timing Diagram
The off-delay timing sequence for S_OFFDT with a preset of S5T#5s is illustrated below.
Comparison with STEP 7 Classic and Micro/WIN Behavior
| Property | STEP 5 | STEP 7 V5.x | Micro/WIN S7-200 | TIA Portal V13 SP1 | TIA Portal V15+ |
|---|---|---|---|---|---|
| Q rendered as gray when 0 | Yes | Yes | Yes | No (defect) | Yes (corrected) |
| Q reflects actual scanned bit | Yes | Yes | Yes | Yes (PLC scan is correct) | Yes |
| BI/BCD outputs color-rendered correctly | Yes | Yes | Yes | Yes (defect is Q-only) | Yes |
| Reset edge visually repaints Q | n/a | n/a | n/a | Yes (forces repaint) | n/a |
| Mirror flag workaround required? | No | No | No | Yes (if >10 instances) | No |
Troubleshooting Matrix
| Symptom | Likely Cause | Verification | Remediation |
|---|---|---|---|
| Green flow on Q when value is 0 | TIA Portal V13 SP1 editor renderer defect | Force Q in VAT, watch value | Apply mirror flag or upgrade TIA |
| Green flow on Q when value is 1 | Normal energised state | Force Q in VAT, watch value | No action |
| Q stays 0 even with IN held high | CPU in STOP, or R input held true, or TV=0 | Check CPU run LED, R input bit, TV literal | Bring CPU to RUN, release R, set TV>0 |
| Q never goes back to 0 after IN falls | TV set too long, or residual time not elapsing due to scan stall | Check BI word decrement in VAT | Reduce TV, investigate scan time |
| Green flow persists after reset pulse | Reset pulse too short to trigger repaint | Lengthen pulse to ≥1 OB1 scan | Hold R for at least one full scan |
| Mirror flag also green when 0 | Mirror tag accidentally tied to a forced value | Check force table | Remove force on M flag |
Project Migration Considerations
When migrating an S7-300/400 program that uses 150+ S_OFFDT instances from TIA Portal V13 SP1 to a later release, audit the project for residual mirror-flag workarounds. If the target TIA Portal version has the corrected renderer:
- Keep the mirror flags if they participate in HMI tag mapping or external visibility — they remain functionally correct.
- If the mirror flags exist only to suppress the green-flow defect and the target editor is fixed, the flags can be removed in a controlled refactor to reclaim Merker addresses.
- Always re-validate all 150 timer networks after a TIA Portal upgrade, because the
S5TIMEliteral evaluation and the network layout renderer can change between major versions.
Safety and Documentation Requirements
For safety-related circuits (SIL 1/2/3 per IEC 61508, PL a–e per ISO 13849-1) the off-delay timer must be implemented with a certified safety timer block such as F_OFFDT from the S7-300F / S7-400F libraries, not the standard S_OFFDT. The display defect described in this article is purely visual and does not affect the safety integrity of the F-CPU; however, the standard S_OFFDT must never be used in the safety path itself, regardless of editor rendering. Document this exclusion in the project's Safety Requirement Specification (SRS) and the validation report.
FAQ
Does the S_OFFDT green-flow issue affect the actual PLC output behavior?
No. The defect is in the TIA Portal V13 SP1 online monitor's LAD/FBD renderer only. The boolean value of Q in the process image transitions correctly between 0 and 1. Field outputs wired to Q (or to a mirror flag of Q) behave as specified in the SIMATIC S7-300 system manual.
Which TIA Portal versions are confirmed affected by the S_OFFDT green-flow defect?
Field reports confirm the issue in TIA Portal V10 Basic, V11, V12, V13, and V13 SP1. The defect was not present in STEP 5, STEP 7 V5.x, or Micro/WIN. Siemens typically bundles editor corrections in service pack updates; check the release notes of V13 SP2 and later for explicit correction entries.
What is the quickest workaround to suppress the false green on S_OFFDT Q output?
Add an intermediate BOOL Merker tag (e.g., M100.0) wired as a contact of the timer's Q pin in the same network, then reference the Merker tag in all downstream logic. The Merker tag is rendered correctly by the online monitor and isolates the visual defect from the rest of the program.
Can I pulse the R input to clear the green indicator on every scan?
You can, but only after the legitimate off-delay has expired. Pulse R for at least one full OB1 scan only when the timer's Q is already 1, so the real timing behavior is not disturbed. This approach is more invasive than the mirror-flag workaround and is generally reserved for legacy code that cannot be refactored.
Does this defect apply to S7-1200 or S7-1500 PLCs?
No. S7-1200 and S7-1500 do not expose the legacy S_OFFDT box; they use the IEC 61131-3 TOF function block. The renderer for the IEC timers does not exhibit the false-green behavior. This article applies only to S7-300/400 projects using the legacy S_OFFDT instruction in TIA Portal V10 through V13 SP1.
What is the recommended permanent fix for a project that must stay on TIA Portal V13 SP1?
Use the mirror-flag workaround for every S_OFFDT instance, document each mapping in the project's I/O list, and apply a code-review rule to ensure no new S_OFFDT is added without a paired mirror flag. For a permanent fix, migrate the project to TIA Portal V15.1 or later after confirming the renderer is corrected in the target version's release notes.