Problem Overview
When configuring a Siemens SIMATIC S7-1200 CPU 1212C (firmware V3.0) with an SB 1222 signal board for four simultaneous pulse-width-modulation (PWM) channels, the TIA Portal device configuration flags the error: "Enable this pulse generator: pulse outputs uses overlapping address areas." The diagnostic affects pulse generators 3 and 4 even when the user assigns four distinct output-word addresses (%QW1000, %QW1005, %QW1010, %QW1015 or the default %QW1000, %QW1002, %QW1004, %QW1008). The user observes that the SB 1222 outputs are mapped to Q4.0, Q4.1, Q4.2, Q4.3 and reasonably expects those outputs to honor the signal-board datasheet claim of 200 kHz switching capability.
The fault is not an address-conflict bug in the project; it is a CPU/firmware architectural constraint that the configuration editor enforces in the device view. Understanding the underlying mapping between the CPU pulse generator (PTO/PWM) hardware blocks and the available digital outputs is the first step toward a working four-channel PWM deployment.
Root Cause Analysis
The CPU 1212C has a fixed number of hardware pulse generators. Pulse generators are dedicated hardware counters in the CPU ASIC; they are not a generic software service that can be re-targeted to any output bit. Each generator can drive a single output with high-resolution timing, and the firmware reserves the corresponding process-image output-word area for that generator's hardware compare register.
The error "pulse outputs uses overlapping address areas" is raised by the TIA Portal configuration checker when two pulse generators are configured to claim the same output region, or when a generator is assigned to an output that is not licensed for PTO/PWM operation. On the CPU 1212C, the relevant mapping is:
- PWM_1 (PTO/PWM generator 1) – hardware-pinned to
Q0.0 - PWM_2 (PTO/PWM generator 2) – hardware-pinned to
Q0.2 - PWM_3 – not available on the 1212C ASIC
- PWM_4 – not available on the 1212C ASIC
Furthermore, the SB 1222 signal board outputs (Q4.0 through Q4.3) are standard digital outputs only; they do not include a high-speed comparator stage and therefore cannot be driven by a pulse generator. The "200 kHz" figure quoted for the SB 1222 in some marketing collateral refers to the maximum input frequency on the interrupt-capable inputs, or in different SKUs the high-speed output toggle rate of the CPU outputs—not to PWM capability on the signal-board outputs themselves.
When the user enables a third and fourth pulse generator in the device configuration, TIA Portal checks for a free pulse-generator resource. Because the 1212C has only two, the editor either silently re-targets one of them to an already-claimed output, or refuses to assign addresses and surfaces the overlap error.
S7-1200 Pulse Generator Architecture
Every S7-1200 CPU integrates a fixed set of "PTO/PWM generators" inside the system ASIC. These are high-resolution 16-bit or 32-bit counters clocked from a prescaled peripheral clock; their compare register is what ultimately toggles the output. Because the compare register and the corresponding process-image output are physically wired in the silicon, you cannot "re-route" a pulse generator to a different output bit than the one its hardware channel is bound to.
| CPU | PTO/PWM Generators | Default Output Mapping | High-Speed Output Frequency |
|---|---|---|---|
| CPU 1211C DC/DC/DC | 2 | Q0.0, Q0.2 | 100 kHz / 1 MHz (relay/SSR variants) |
| CPU 1212C DC/DC/DC | 2 | Q0.0, Q0.2 | 100 kHz standard, 1 MHz with HS output option |
| CPU 1213C DC/DC/DC | 2 | Q0.0, Q0.2 | 100 kHz |
| CPU 1214C DC/DC/DC | 4 | Q0.0, Q0.2, Q0.4, Q0.6 | 100 kHz |
| CPU 1215C DC/DC/DC | 4 | Q0.0, Q0.2, Q0.4, Q0.6 | 100 kHz / 1 MHz on Q0.0–Q0.3 |
| CPU 1217C DC/DC/DC | 4 | Q0.0, Q0.2, Q0.4, Q0.6 | 1 MHz on all four high-speed outputs |
The maximum PWM frequency achievable on a given output is dictated by the CPU prescaler. For the standard 100 kHz outputs the period range is 1 µs to 16,777,216 µs (≈ 16.7 s) in 1 µs steps. For the 1 MHz high-speed outputs the period range is 0.1 µs (100 ns) to 16,777,215.9 µs in 100 ns steps. Duty cycle is set in 0.1 % or 1 % increments depending on output class.
CPU 1212C Hardware Output Limits
The CPU 1212C is sold in three variants: AC/DC/RLY, DC/DC/DC, and DC/DC/RLY. Only the DC/DC/DC variant (and the relay-output DC/DC/RLY) provides transistor outputs suitable for high-speed switching. The DC/DC/DC unit exposes eight integrated inputs (I0.0–I0.7) and six integrated outputs (Q0.0–Q0.5), grouped as follows:
- Standard outputs: Q0.0, Q0.2, Q0.4 (and Q0.1, Q0.3, Q0.5 when used as ordinary digital outputs)
- PTO/PWM-capable outputs: Q0.0 and Q0.2 only on the 1212C
- High-speed counter (HSC) inputs: I0.0–I0.3 (4 HSC channels)
The standard PWM block (PWM from the "Extended Instructions > Pulse" palette in TIA Portal) requires a hardware pulse generator. Selecting PWM_3 or PWM_4 in the device configuration on a 1212C is a configuration-time error: the generator does not exist in the ASIC, and the address area is therefore implicitly zero-length, causing TIA Portal to treat any output word assigned to that generator as overlapping with the next valid generator's reserved region.
SB 1222 Signal Board Output Limits
The SB 1222 is a plug-on signal board installed on top of the CPU front connector. Several SKUs exist:
| MLFB | Outputs | Output Type | PWM Support | Max Switching Rate |
|---|---|---|---|---|
| 6ES7222-1AD30-0XB0 | 4 × DO (Q4.0–Q4.3) | 24 V DC, 0.5 A sourcing | No | 100 Hz standard, no PTO/PWM |
| 6ES7222-1BD30-0XB0 | 4 × DO (Q4.0–Q4.3) | 24 V DC, 0.5 A sourcing | No | 100 Hz standard |
| 6ES7222-1HD30-0XB0 | 2 × DO + 2 × DI | 24 V DC | No | 100 Hz |
| 6ES7222-1XF30-0XB0 | 2 × Relay | 2 A / 30 V DC, 0.5 A / 125 V AC | No | 1 Hz mechanical |
The "200 kHz" figure some users cite for the SB 1222 is generally a misreading of the SB 1221 digital-input signal board (which has high-speed interrupt inputs) or the high-speed output rating of the CPU outputs themselves. No SB 1222 SKU has PTO/PWM-capable outputs. The signal-board outputs appear in the process image at addresses Q4.0 through Q4.3 (on the 1212C with DC outputs) and are bit-addressable and byte-addressable only; they have no associated hardware compare register and therefore cannot perform time-base pulse generation.
Q4.0–Q4.3 is not a valid configuration. TIA Portal may silently fail to commit, raise the overlap error described here, or simply grey out the PTO/PWM option in the per-output properties.The "Overlapping Address Areas" Error Explained
The TIA Portal device configuration reserves a contiguous output-word range for each pulse generator because the hardware compare register and the hardware direction/control register are word-sized and adjacent in the I/O map. The default reservations are:
- PTO/PWM 1 –
%QW1000(output) and%QW1004(motion control, optional) - PTO/PWM 2 –
%QW1002(output) and%QW1006 - PTO/PWM 3 –
%QW1004(output) and%QW1008 - PTO/PWM 4 –
%QW1006(output) and%QW1010
On a 1212C only generators 1 and 2 are valid. If you try to enable a third generator, TIA Portal will assign %QW1004–%QW1006 to that generator, which collides with the same words reserved for generator 2's motion-control shadow area. The check that the editor runs is "are any of the words already in use by another generator or by the HSC block?" – and the answer is yes. That is the precise condition described by the error message.
Even if you manually retype the addresses to %QW1000, %QW1005, %QW1010, %QW1015, the editor validates the underlying generator-resource availability and refuses, because the 1212C ASIC has no third and fourth hardware channel. TIA Portal reports the symptom in terms of overlapping addresses because that is the user-visible field that is inconsistent; the root cause is the missing hardware resource.
Solution Path Selection
Three solution paths are available, depending on the application's PWM channel-count and frequency requirements.
Path A – Reduce to Two PWM Channels on the 1212C
If the application can be re-architected for two channels, configure PWM_1 on Q0.0 and PWM_2 on Q0.2 using the default %QW1000 and %QW1002 addresses. Use the SB 1222 outputs for ordinary on/off actuation (e.g., direction lines, enables, valve solenoids). This is the lowest-risk path and is firmware-agnostic across all 1212C variants.
Path B – Upgrade to a CPU with Four Generators
If four independent PWM channels are mandatory, migrate the application to a CPU 1214C DC/DC/DC, 1215C DC/DC/DC, or 1217C DC/DC/DC. The 1214C and 1215C both expose four pulse generators, with the 1215C adding four 1 MHz-capable high-speed outputs. The 1217C adds differential line-driver outputs for high-noise environments. After upgrading, the device configuration in TIA Portal will show four PTO/PWM-capable outputs (Q0.0, Q0.2, Q0.4, Q0.6), and the overlap error will not appear.
Path C – Use an External PWM Generator Module
When the application is locked to a 1212C BOM and four PWM channels are required, add an external multi-channel PWM generator. The Texas Instruments UCD9222 is a two-rail digital PWM controller with 250 ps duty-cycle resolution and switching frequencies up to 2 MHz, addressed via PMBus/I²C. Two UCD9222 devices can supply four independent rails from the same PLC, driven by an I²C master implementation in the S7-1200 user program. Alternatives include ET 200S PWM modules, the SIMATIC ET 200SP pulse generator, or a Modbus/IO-Link slave with PWM output capability.
Step-by-Step TIA Portal Configuration (Two-Channel Path)
- Open the project in TIA Portal V15.1 or later (V16+ recommended for the 1212C V3.0 firmware feature set).
- Double-click Device & Networks and select the CPU 1212C.
- In the device view, expand Properties > Pulse generators (PTO/PWM).
- For PWM_1: select Enable; the editor will expose output
Q0.0. Set the time base to microseconds and the output address to%QW1000(default). - For PWM_2: select Enable; the editor will expose output
Q0.2. Accept the default%QW1002. - For PWM_3 and PWM_4: do not enable. If you are converting a project from a 1214/1215/1217, these will appear greyed out.
- Verify that the SB 1222 catalog entry is present in the device configuration (signal-board slot, top of the CPU). Confirm that its outputs
Q4.0–Q4.3are accessible as standard digital outputs but are not listed in the pulse generator properties. - Compile the project (Project > Compile > Hardware (rebuild all)). The error "pulse outputs uses overlapping address areas" should no longer appear.
- In the user program, add a
PWM_CTRL(or use the simplifiedPWMinstruction) and call it cyclically, or use the TIA Portal pulse-channel configuration workflow to set the period and duty cycle in the device view directly.
Verification Procedure
- After download, switch the CPU to RUN. The status LEDs for outputs
Q0.0andQ0.2should remain OFF at a 50 % duty cycle when the duty cycle equals 50 %, because the LED driver integrates the average. - Use a scope on
Q0.0andQ0.2to verify the period and duty cycle. The frequency should match the configured pulse-generator time base, and the two channels should be phase-coherent when both are driven by the same OB1 cycle. - In the watch table, force
%QW1000to a known pattern (e.g., 0x4000 for 50 % at 1 ms period on 100 kHz outputs) and observe the actual output on the scope. - Confirm that the error is absent from Project > Compile > Error list and that the device configuration compiles cleanly.
- From the online & diagnostics view, open Diagnostics > Pulse generators and check that the status word reports
STATE = RUNNINGfor both enabled generators.
Hardware Watch-Dog Considerations for PWM
When the S7-1200 CPU enters STOP, all pulse generators are halted and the outputs return to their configured substitute behavior. To guarantee a defined safe state (e.g., low) on a controlled load, wire a pull-down or use the CPU's "substitute value" property on the PTO/PWM channel. The 1212C will de-assert the output within 100 µs of STOP entry; downstream MOSFETs or relays must be chosen for failsafe state. The SB 1222 outputs likewise default to OFF in STOP mode and can be reconfigured to retain last state via the device view "Behavior in STOP" property.
Frequency vs. Load Current Trade-offs
Higher PWM frequencies improve current ripple in inductive loads but increase switching loss in the output stage. The 1212C DC outputs are rated for 0.5 A continuous, 1 A peak. At 200 kHz the dynamic losses in the output FET approach 30 % of the available dissipation budget, so 100 kHz is the practical ceiling for sustained 0.5 A operation. If a 200 kHz PWM is required, de-rate the load to 0.35 A and ensure ambient temperature is below 40 °C, or move the switching function to an external driver with proper gate-charge handling.
Troubleshooting Matrix
| Symptom | Likely Cause | Resolution |
|---|---|---|
| "Overlapping address areas" on 1212C | Attempting to enable PWM_3/PWM_4 (not present on 1212C) | Disable generators 3 and 4; use 1214C/1215C for 4-channel |
| PWM output stays low regardless of duty cycle | Output is configured as PTO (stepper mode) instead of PWM | Re-select "PWM" in pulse generator properties |
| PWM frequency half of expected | Time base is set to milliseconds, not microseconds | Switch time base to 1 µs for 100 kHz+ output |
| Output glitches when OB1 cycle is slow | Duty cycle updated in OB1 with variable cycle time | Move updates to a time-of-day interrupt or a hardware-triggered OB |
| SB 1222 output does not toggle | Output is mapped but PLC is in STOP; or "Enable output" is not set in the user program | Verify PLC is in RUN; set %Q4.0 := TRUE from user program |
| Compiler warns "Pulse generator not assigned to any output" | Generator was enabled but output was left on default (None) | Assign generator to a valid PTO/PWM-capable output |
Migrating From 1212C to 1214C/1215C
If you choose Path B, the migration is largely transparent. The TIA Portal device swap replaces the 1212C with the 1214C, recompiles, and the four PTO/PWM generators become available on Q0.0, Q0.2, Q0.4, Q0.6. Two important caveats apply:
- The default process-image output address for the new generators will be
%QW1000,%QW1002,%QW1004,%QW1006– verify that no other code in the project reuses these addresses. - The motion-control resource table expands. If the project uses the
MC_instruction set (axis control), the 1214C has one less axis than the 1212C in the same firmware series, so axis assignments may need to be re-mapped.
Best Practices for Multi-Channel PWM on S7-1200
- Reserve PTO/PWM-capable outputs for pulse generation; do not assign them as ordinary digital outputs in the user program.
- Document the pulse generator number, target output bit, time base, and frequency in the project HMI or comments for each generator.
- For phase-critical applications, use the same OB (OB1, or a synchronous OB such as OB61) to update all PWM duty cycles; this minimizes phase drift between channels.
- Add a hardware low-pass filter on the scope probe (or a 1 kΩ / 1 nF RC) when measuring high-frequency PWM edges to avoid ringing artifacts.
- Use a freewheel diode on every inductive load (relay coils, solenoids, motor windings) to suppress back-EMF that can damage the SB 1222 outputs.
FAQ
How many PWM channels does the S7-1200 CPU 1212C support?
The 1212C supports a maximum of two PTO/PWM generators, mapped to outputs Q0.0 (PWM_1) and Q0.2 (PWM_2). Generators 3 and 4 do not exist in the 1212C ASIC and cannot be enabled in TIA Portal; enabling them produces the "overlapping address areas" error.
Can the SB 1222 signal board outputs do PWM?
No. The SB 1222 outputs (Q4.0–Q4.3 on a 1212C) are standard digital outputs only. They have no hardware compare register and cannot perform time-based pulse generation. The "200 kHz" figure sometimes cited is a misreading of the high-speed input specification on SB 1221 or the high-speed CPU output rating.
Which S7-1200 CPU should I use for four PWM channels?
Use the CPU 1214C DC/DC/DC, 1215C DC/DC/DC, or 1217C DC/DC/DC. All three provide four PTO/PWM generators on Q0.0, Q0.2, Q0.4, and Q0.6. The 1215C and 1217C additionally support 1 MHz high-speed outputs on those four bits.
What is the maximum PWM frequency on the 1212C standard outputs?
Standard 1212C DC outputs are limited to 100 kHz PWM. The 1 MHz high-speed variant of the 1212C exists as a separate MLFB; verify the CPU order code (look for the "high-speed" suffix in the catalog number) before assuming 1 MHz capability.
How do I clear the "overlapping address areas" compiler error?
Disable PWM_3 and PWM_4 in the device configuration (they are not valid on the 1212C) and accept the default output-word addresses for PWM_1 and PWM_2 (%QW1000 and %QW1002). Recompile the hardware configuration; the error will be cleared.
Can I use the SB 1222 outputs as ordinary digital outputs in the same project that uses PWM on the CPU outputs?
Yes. The SB 1222 outputs are independent of the CPU pulse generators and can be used as standard 24 V DC outputs (0.5 A per channel) for direction lines, enables, indicator lamps, or valve actuation in parallel with the CPU PWM channels. There is no hardware conflict between SB 1222 outputs and CPU PWM outputs.