Resolving S7-1200 SM 1231 DIAG Red LED and Not Reachable Errors

David Krause13 min read
S7-1200SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Summary

A Siemens SIMATIC S7-1200 system built around a CPU 1215 AC/DC/RLY (article number 6ES7215-1AF40-0XB0) reports a red DIAG LED on an attached SM 1231 analog input module (article number pattern 6ES7231-...32-0XB0), a flashing ERROR/SF LED on the CPU, and the SM 1231 displays the "not reachable" symbol in the TIA Portal V17 project tree. The CPU diagnostics buffer contains the events Hardware component missing or removed and new I/O access error during process image update. Because the S7-1200 system bus is not hot-swappable, this combination of symptoms almost always indicates either a hardware configuration mismatch in TIA Portal, an interruption of the bus connector between CPU and SM, or permanent damage to the SM 1231 caused by inserting or removing it under power.

The symptom set is reproducible across all S7-1200 firmware versions that the CPU 1215-1AF40-0XB0 supports (firmware 4.2 through 4.6) and across TIA Portal V15.1 through V18. The recovery procedure below is the same regardless of the editor version, but screenshots and dialog paths shown here match TIA Portal V17.

2. Affected Hardware and Identification

Confirm the exact order numbers of the components in the rack before replacing anything. The hardware ID printed on the front of each module (top right corner) is the value the engineering tool uses to identify the device.

Component Order Number (MLFB) Firmware Role in the Fault
CPU 1215 AC/DC/RLY 6ES7215-1AF40-0XB0 V4.2 - V4.6 Hosts the system bus; sources 24 V backplane to SM
SM 1231 AI 8x13 bit 6ES7231-4HF32-0XB0 V1.0 Most common 32-0XB0 variant, 8 AI voltage/current
SM 1231 AI 4x16 bit 6ES7231-5ND32-0XB0 V1.0 4 AI high-resolution voltage/current
SM 1231 AI 8x16 bit 6ES7231-5PD32-0XB0 V1.0 8 AI high-resolution voltage/current
SM 1231 AI 4x16 bit TC/RTD 6ES7231-5PF32-0XB0 V1.0 4 AI thermocouple / RTD
SM 1231 AI 4x16 bit HS 6ES7231-5QD32-0XB0 V1.0 4 AI high-speed voltage/current
The order number suffix "32-0XB0" in the source post identifies the module family as the second hardware revision of the SM 1231 (release 2). The 5-digit "function" portion of the MLFB determines the channel count and signal type. Always cross-check the side label of the actual module against the order number you have configured in the device configuration.

3. LED and Diagnostics Buffer Interpretation

Each LED on the SM 1231 has a defined meaning per the SIMATIC S7-1200 Programmable Controller System Manual. The table below maps the states encountered in the field report to their meaning and the action they imply.

LED State Meaning Recommended Action
SM 1231 PWR Off No 24 V supply on system bus from CPU or external PS Check the bus connector; verify CPU PWR
SM 1231 DIAG Flashing red Module has detected an error (configuration, channel, or internal) Read the diagnostics buffer of the SM in TIA Portal
SM 1231 DIAG Solid red No configuration, or no bus communication Re-add module to device configuration and download
CPU ERROR/SF Flashing At least one error in the diagnostics buffer Open Online & Diagnostics > Diagnostics buffer
CPU ERROR/SF Solid Fatal error, CPU in STOP Clear buffer, fix cause, perform STOP-RUN
CPU MAINT Solid/flashing Maintenance demand or required Open diagnostics buffer; firmware update pending

The two diagnostics events from the source case are translated as follows. The exact wording is the English-language event ID returned by the S7-1200 firmware 4.x operating system.

  • Hardware component missing or removed (event ID 0x1D38 / 16#1D38 on the CPU side): the CPU cannot detect the SM 1231 on the I/O bus at the configured slot. Either the module is physically absent, the slide-in bus connector between CPU and SM is not fully engaged, or the module's internal interface IC is damaged.
  • New I/O access error during process image update (event ID 0x1D31 / 16#1D31): the user program (or a system update) tried to read or write the SM 1231's process image, but the I/O access returned an error. This is a downstream effect of the first event; the CPU cannot access a module it cannot see.

4. Root Cause Analysis

For the symptom pair "DIAG red on SM 1231 + CPU ERROR flashing + module shows 'not reachable' in TIA Portal", the engineering record shows four root causes that account for the vast majority of field reports. They should be checked in the order listed because each is cheaper to eliminate than the next.

4.1 Hardware Configuration Mismatch

The most common cause. The SM 1231 present in the rack does not match the order number configured in the TIA Portal device configuration. The CPU performs a type check on power-up; if the configured MLFB does not match the physical module, the CPU raises event 0x1D38 and refuses to start the SM. Typical triggers include adding the wrong catalog SM (e.g. SM 1231 4AI when the installed unit is SM 1231 8AI), or a TIA Portal upgrade that swapped the catalog part.

4.2 Bus Connector and Mechanical Seating

The S7-1200 SM modules communicate with the CPU over a sliding bus connector that ships pre-installed on the back of the module. If the connector is folded out, missing, or not fully inserted into the previous module, the CPU will report the slot as empty. This causes the same 0x1D38 event as a missing module.

4.3 Hot Insertion or Removal (Permanent Damage)

The SIMATIC S7-1200 system manual, section "Mounting the signal modules", explicitly states: "Signal modules may only be mounted or removed when the CPU and all S7-1200 components are disconnected from the power supply." If the module was plugged in or removed while the CPU was energized, the input protection diodes, the bus interface ASIC, or the 5 V DC/DC converter of the SM 1231 may have suffered irreversible damage. In that case the DIAG LED will be red immediately on power-up, the CPU will continue to report 0x1D38, and the SM 1231 will fail the CPU's type check indefinitely.

4.4 Power Budget Exceeded

The CPU 1215-1AF40-0XB0 supplies 5 VDC to the backplane up to a budget of 1600 mA and 24 VDC sensor power up to 300 mA (derated for AC/DC/RLY variants). The SM 1231 family draws 60-80 mA at 5 V plus its own sensor supply. The 5 V budget is rarely the problem with a single SM 1231, but if other SMs (e.g. SM 1223, SM 1222 with relay outputs, CM/CP modules) are also on the bus, the sum may exceed the limit. The CPU signals this with a different diagnostics event (0x1D2A "internal supply voltage failed") rather than the 0x1D38 reported here, so this is the least likely cause for the exact symptoms described.

5. Step-by-Step Recovery Procedure

  1. Power down completely. Disconnect mains to the CPU 1215 and to any external 24 V supply feeding the SM's sensor terminals. The S7-1200 system bus must be de-energized for at least 10 seconds before any module is reseated.
  2. Inspect the bus connector. Unlatch the SM 1231 from the DIN rail, fold out the integrated bus connector, and verify the gold fingers are clean and not bent. Inspect the bus connector on the right side of the CPU for the same.
  3. Reseat the SM 1231. Hook the SM onto the DIN rail, swing it down, and push firmly on the front face until the slide latch clicks. Verify the bus connector is fully inserted into the CPU's socket. You should feel a single positive engagement.
  4. Inspect the SM 1231 label. Read the order number off the side of the module and write it down exactly. The format is 6ES7 231-XXXXX-XXXX.
  5. Cross-check the TIA Portal device configuration. Open the TIA Portal project, expand Device configuration > CPU > Signal module slot 1, and read the order number configured. It must match the label on the physical module exactly, including the function code and the 4-digit hardware release suffix.
  6. Correct the configuration if needed. Right-click the SM 1231 in the device view and choose "Replace device". Pick the exact MLFB that matches the physical module. Recompile the hardware configuration.
  7. Download the hardware configuration offline. Connect the programming PG to the CPU's PROFINET port. Select the CPU in the project tree, click "Download to device" (the green arrow), keep the action "Download to device", and check "Continue without recheck of project data". This downloads the new device configuration without altering the user program.
  8. Power-cycle the CPU. After a successful download, perform a STOP-RUN transition from the CPU's online panel, or power-cycle the mains.
  9. Read the SM 1231 diagnostics. After restart, go to Online & Diagnostics > Diagnostics buffer of the SM 1231 itself (right-click the SM in the online tree). If the DIAG LED is still red, the SM has internal damage and must be replaced.
Step 6 (Replace device) is the highest-leverage action in this procedure. A configuration mismatch is by far the most common cause of the reported symptoms and is fixed without touching the wiring. If the SM still shows DIAG red after a correct download and a clean reseat, move to step 10.

6. Factory Reset of the CPU

If the diagnostics buffer keeps generating the same 0x1D38 and 0x1D31 events even after a correct device configuration has been downloaded, the CPU's internal module list may be in an inconsistent state. A factory reset forces the CPU to re-enumerate the I/O bus from scratch on the next power-up.

  1. Open TIA Portal V17, expand the project tree, and select the project node.
  2. In the "Online" menu, click "Update accessible devices" and double-click the network card of the PG that is physically connected to the CPU's PROFINET port.
  3. Select the detected CPU in the "Accessible devices" table and click "Show online devices".
  4. Open "Online & Diagnostics" for the CPU.
  5. In the left pane, expand "Functions" and select "Reset to factory settings".
  6. Check "Reset all" and confirm with "Reset". Enter the CPU's password if one is set.
  7. Wait for the CPU to perform the reset. The MAINT and STOP LEDs will be on during the process; RUN will be off.
  8. Power-cycle the CPU and download the project again.
A factory reset erases the user program, all data blocks, all recipes, all IP parameters, and the time-of-day clock. Back up the project before performing the reset, and be prepared to re-download the full program after the reset.

7. Verifying the SM 1231 Function

Once the CPU is back in RUN with the SM 1231 DIAG LED solid green, perform the following verification sequence. These checks exercise both the analog front end and the diagnostic channel reporting and confirm that the module is operating within its published specifications.

  1. Open "Online & Diagnostics > Diagnostics buffer" of the SM 1231. There should be no events of class "Error".
  2. Open a watch table with the SM 1231's input addresses (e.g. IW64 onwards for slot 1). Force the SM to monitor mode if you need to view raw values without a user program running.
  3. Apply a known input signal: 0 V on all channels, then 10 V on channel 0. The corresponding input word should move from 0 (or the zero calibration value) to 27648 (full scale for the unipolar 0-10 V range of the 8AI 13-bit module).
  4. Short-circuit the input terminals of an unused channel to 0 V and confirm the value reads exactly 0. This confirms the input protection paths are intact and no channel has been damaged.
  5. Trigger an out-of-range condition by applying 11.5 V (above the overrange limit) and verify the diagnostics buffer of the SM 1231 reports channel overrange (event 0x0006 "High limit exceeded"). Clear the condition and verify the diagnostic clears automatically on the next scan.
  6. Cycle the CPU and confirm the SM 1231 DIAG LED is solid green at the end of the cycle, with no diagnostics buffer entries.

8. Preventing Hot-Swap Damage on the S7-1200

The S7-1200 family is mechanically similar to a backplane-based PLC, but the bus between CPU and SM is a passive ribbon connector that is not rated for live insertion. The I/O interface ICs on the SM 1231 are protected by TVS diodes on the 24 V rail and on the analog inputs, but the 5 V backplane and the inter-module clock lines do not have the staggered-pin arrangement of true hot-swap systems such as the S7-1500 with active backplane. Live insertion produces a sequence of voltage steps on the bus that can latch-up the interface ASIC. The first symptom is exactly what this source post reports: solid DIAG red on the SM, slot reported as missing by the CPU, no recovery short of replacement.

Best practice is to wire the system to a single disconnect, label that disconnect, and de-energize it before any module is added or removed. The disconnect must remove both the mains to the CPU and the 24 V sensor supply to the SM terminal block, because the 24 V rail back-powers the analog front end through protection diodes even when the 5 V bus is off.

9. Quick-Reference Troubleshooting Matrix

Observed Symptom Likely Root Cause First Action
SM DIAG solid red, CPU ERROR flashing, SM "not reachable" in TIA Hot-swap damage or bus connector not seated Power down, reseat SM, replace SM if symptom persists
SM DIAG flashing red, CPU ERROR flashing, SM visible in TIA with wrench Channel-level error (overrange, wire break, configuration) Read SM diagnostics buffer; correct channel wiring or type
SM DIAG red, CPU MAINT solid, all SMs show red Power budget exceeded (5 V or 24 V) Compute 5 V budget; remove or repower SMs
SM DIAG off, no analog readings, no diagnostics events Process image not updated or wrong slot address in user code Verify I/O addresses in device configuration match watch table
SM DIAG red only after a TIA Portal project upgrade Catalog part number swap during upgrade Right-click SM in device view, "Replace device", pick installed MLFB

10. Related Siemens Documentation

The official documents used to validate the recovery procedure and the diagnostics event codes below are listed here for reference. The exact S7-1200 system manual, section "Diagnostics of the analog inputs", covers event codes 6 through 12 (channel-level) and event code 0x1D38 (module-level). The TIA Portal V17 help, section "Reset to factory settings", describes the dialog path used in step 6 of the recovery procedure.

Does the S7-1200 SM 1231 require a separate 24 V power supply?

No. The CPU 1215 supplies the SM 1231 with 5 V logic power through the backplane connector, and a 24 V sensor supply that is current-limited at 300 mA for the AC/DC/RLY variant. For most analog signals the on-board 24 V is enough; an external PS 305/PS 607 is only required when many SMs share the bus and the sensor current budget is exceeded.

Why does the CPU report "Hardware component missing or removed" even though the SM 1231 is physically attached?

The CPU performs a hardware type check on every power-up. If the configured order number in the TIA Portal device view does not match the MLFB of the physical module, or if the bus connector is not fully engaged, the CPU treats the slot as empty and raises event 0x1D38. Re-seat the module and verify the configured MLFB matches the side label of the SM.

Can a hot-swapped SM 1231 be recovered, or is it permanently damaged?

In most cases the damage is permanent. The S7-1200 bus interface is not rated for live insertion, and a single hot-swap event can latch the analog front end. The DIAG LED will remain red after a correct reseat and a factory reset of the CPU, and the only remedy is module replacement.

Will a factory reset of the CPU fix a red DIAG LED on the SM 1231?

Only if the CPU's internal module list is inconsistent after a series of configuration downloads. A factory reset forces the CPU to re-enumerate the I/O bus on the next power-up. If the SM 1231 itself is damaged, the reset will not clear the DIAG LED and the SM must be replaced.

Which TIA Portal version is required to configure the SM 1231 32-0XB0 variants?

TIA Portal V15.1 with HSP 0234 or later supports the 32-0XB0 hardware releases of the SM 1231 family. TIA Portal V16, V17, and V18 configure the modules directly from the base catalog without an HSP. The CPU 1215-1AF40-0XB0 requires TIA Portal V15.1 or later for firmware 4.4 and TIA Portal V17 for firmware 4.6.

Back to blog