1. Problem Summary
A Siemens SIMATIC S7-1200 system built around a CPU 1215 AC/DC/RLY (article number 6ES7215-1AF40-0XB0) reports a red DIAG LED on an attached SM 1231 analog input module (article number pattern 6ES7231-...32-0XB0), a flashing ERROR/SF LED on the CPU, and the SM 1231 displays the "not reachable" symbol in the TIA Portal V17 project tree. The CPU diagnostics buffer contains the events Hardware component missing or removed and new I/O access error during process image update. Because the S7-1200 system bus is not hot-swappable, this combination of symptoms almost always indicates either a hardware configuration mismatch in TIA Portal, an interruption of the bus connector between CPU and SM, or permanent damage to the SM 1231 caused by inserting or removing it under power.
The symptom set is reproducible across all S7-1200 firmware versions that the CPU 1215-1AF40-0XB0 supports (firmware 4.2 through 4.6) and across TIA Portal V15.1 through V18. The recovery procedure below is the same regardless of the editor version, but screenshots and dialog paths shown here match TIA Portal V17.
2. Affected Hardware and Identification
Confirm the exact order numbers of the components in the rack before replacing anything. The hardware ID printed on the front of each module (top right corner) is the value the engineering tool uses to identify the device.
| Component | Order Number (MLFB) | Firmware | Role in the Fault |
|---|---|---|---|
| CPU 1215 AC/DC/RLY | 6ES7215-1AF40-0XB0 | V4.2 - V4.6 | Hosts the system bus; sources 24 V backplane to SM |
| SM 1231 AI 8x13 bit | 6ES7231-4HF32-0XB0 | V1.0 | Most common 32-0XB0 variant, 8 AI voltage/current |
| SM 1231 AI 4x16 bit | 6ES7231-5ND32-0XB0 | V1.0 | 4 AI high-resolution voltage/current |
| SM 1231 AI 8x16 bit | 6ES7231-5PD32-0XB0 | V1.0 | 8 AI high-resolution voltage/current |
| SM 1231 AI 4x16 bit TC/RTD | 6ES7231-5PF32-0XB0 | V1.0 | 4 AI thermocouple / RTD |
| SM 1231 AI 4x16 bit HS | 6ES7231-5QD32-0XB0 | V1.0 | 4 AI high-speed voltage/current |
3. LED and Diagnostics Buffer Interpretation
Each LED on the SM 1231 has a defined meaning per the SIMATIC S7-1200 Programmable Controller System Manual. The table below maps the states encountered in the field report to their meaning and the action they imply.
| LED | State | Meaning | Recommended Action |
|---|---|---|---|
| SM 1231 PWR | Off | No 24 V supply on system bus from CPU or external PS | Check the bus connector; verify CPU PWR |
| SM 1231 DIAG | Flashing red | Module has detected an error (configuration, channel, or internal) | Read the diagnostics buffer of the SM in TIA Portal |
| SM 1231 DIAG | Solid red | No configuration, or no bus communication | Re-add module to device configuration and download |
| CPU ERROR/SF | Flashing | At least one error in the diagnostics buffer | Open Online & Diagnostics > Diagnostics buffer |
| CPU ERROR/SF | Solid | Fatal error, CPU in STOP | Clear buffer, fix cause, perform STOP-RUN |
| CPU MAINT | Solid/flashing | Maintenance demand or required | Open diagnostics buffer; firmware update pending |
The two diagnostics events from the source case are translated as follows. The exact wording is the English-language event ID returned by the S7-1200 firmware 4.x operating system.
- Hardware component missing or removed (event ID 0x1D38 / 16#1D38 on the CPU side): the CPU cannot detect the SM 1231 on the I/O bus at the configured slot. Either the module is physically absent, the slide-in bus connector between CPU and SM is not fully engaged, or the module's internal interface IC is damaged.
- New I/O access error during process image update (event ID 0x1D31 / 16#1D31): the user program (or a system update) tried to read or write the SM 1231's process image, but the I/O access returned an error. This is a downstream effect of the first event; the CPU cannot access a module it cannot see.
4. Root Cause Analysis
For the symptom pair "DIAG red on SM 1231 + CPU ERROR flashing + module shows 'not reachable' in TIA Portal", the engineering record shows four root causes that account for the vast majority of field reports. They should be checked in the order listed because each is cheaper to eliminate than the next.
4.1 Hardware Configuration Mismatch
The most common cause. The SM 1231 present in the rack does not match the order number configured in the TIA Portal device configuration. The CPU performs a type check on power-up; if the configured MLFB does not match the physical module, the CPU raises event 0x1D38 and refuses to start the SM. Typical triggers include adding the wrong catalog SM (e.g. SM 1231 4AI when the installed unit is SM 1231 8AI), or a TIA Portal upgrade that swapped the catalog part.
4.2 Bus Connector and Mechanical Seating
The S7-1200 SM modules communicate with the CPU over a sliding bus connector that ships pre-installed on the back of the module. If the connector is folded out, missing, or not fully inserted into the previous module, the CPU will report the slot as empty. This causes the same 0x1D38 event as a missing module.
4.3 Hot Insertion or Removal (Permanent Damage)
The SIMATIC S7-1200 system manual, section "Mounting the signal modules", explicitly states: "Signal modules may only be mounted or removed when the CPU and all S7-1200 components are disconnected from the power supply." If the module was plugged in or removed while the CPU was energized, the input protection diodes, the bus interface ASIC, or the 5 V DC/DC converter of the SM 1231 may have suffered irreversible damage. In that case the DIAG LED will be red immediately on power-up, the CPU will continue to report 0x1D38, and the SM 1231 will fail the CPU's type check indefinitely.
4.4 Power Budget Exceeded
The CPU 1215-1AF40-0XB0 supplies 5 VDC to the backplane up to a budget of 1600 mA and 24 VDC sensor power up to 300 mA (derated for AC/DC/RLY variants). The SM 1231 family draws 60-80 mA at 5 V plus its own sensor supply. The 5 V budget is rarely the problem with a single SM 1231, but if other SMs (e.g. SM 1223, SM 1222 with relay outputs, CM/CP modules) are also on the bus, the sum may exceed the limit. The CPU signals this with a different diagnostics event (0x1D2A "internal supply voltage failed") rather than the 0x1D38 reported here, so this is the least likely cause for the exact symptoms described.
5. Step-by-Step Recovery Procedure
- Power down completely. Disconnect mains to the CPU 1215 and to any external 24 V supply feeding the SM's sensor terminals. The S7-1200 system bus must be de-energized for at least 10 seconds before any module is reseated.
- Inspect the bus connector. Unlatch the SM 1231 from the DIN rail, fold out the integrated bus connector, and verify the gold fingers are clean and not bent. Inspect the bus connector on the right side of the CPU for the same.
- Reseat the SM 1231. Hook the SM onto the DIN rail, swing it down, and push firmly on the front face until the slide latch clicks. Verify the bus connector is fully inserted into the CPU's socket. You should feel a single positive engagement.
-
Inspect the SM 1231 label. Read the order number off the side of the module and write it down exactly. The format is
6ES7 231-XXXXX-XXXX. - Cross-check the TIA Portal device configuration. Open the TIA Portal project, expand Device configuration > CPU > Signal module slot 1, and read the order number configured. It must match the label on the physical module exactly, including the function code and the 4-digit hardware release suffix.
- Correct the configuration if needed. Right-click the SM 1231 in the device view and choose "Replace device". Pick the exact MLFB that matches the physical module. Recompile the hardware configuration.
- Download the hardware configuration offline. Connect the programming PG to the CPU's PROFINET port. Select the CPU in the project tree, click "Download to device" (the green arrow), keep the action "Download to device", and check "Continue without recheck of project data". This downloads the new device configuration without altering the user program.
- Power-cycle the CPU. After a successful download, perform a STOP-RUN transition from the CPU's online panel, or power-cycle the mains.
- Read the SM 1231 diagnostics. After restart, go to Online & Diagnostics > Diagnostics buffer of the SM 1231 itself (right-click the SM in the online tree). If the DIAG LED is still red, the SM has internal damage and must be replaced.
6. Factory Reset of the CPU
If the diagnostics buffer keeps generating the same 0x1D38 and 0x1D31 events even after a correct device configuration has been downloaded, the CPU's internal module list may be in an inconsistent state. A factory reset forces the CPU to re-enumerate the I/O bus from scratch on the next power-up.
- Open TIA Portal V17, expand the project tree, and select the project node.
- In the "Online" menu, click "Update accessible devices" and double-click the network card of the PG that is physically connected to the CPU's PROFINET port.
- Select the detected CPU in the "Accessible devices" table and click "Show online devices".
- Open "Online & Diagnostics" for the CPU.
- In the left pane, expand "Functions" and select "Reset to factory settings".
- Check "Reset all" and confirm with "Reset". Enter the CPU's password if one is set.
- Wait for the CPU to perform the reset. The MAINT and STOP LEDs will be on during the process; RUN will be off.
- Power-cycle the CPU and download the project again.
7. Verifying the SM 1231 Function
Once the CPU is back in RUN with the SM 1231 DIAG LED solid green, perform the following verification sequence. These checks exercise both the analog front end and the diagnostic channel reporting and confirm that the module is operating within its published specifications.
- Open "Online & Diagnostics > Diagnostics buffer" of the SM 1231. There should be no events of class "Error".
- Open a watch table with the SM 1231's input addresses (e.g. IW64 onwards for slot 1). Force the SM to monitor mode if you need to view raw values without a user program running.
- Apply a known input signal: 0 V on all channels, then 10 V on channel 0. The corresponding input word should move from 0 (or the zero calibration value) to 27648 (full scale for the unipolar 0-10 V range of the 8AI 13-bit module).
- Short-circuit the input terminals of an unused channel to 0 V and confirm the value reads exactly 0. This confirms the input protection paths are intact and no channel has been damaged.
- Trigger an out-of-range condition by applying 11.5 V (above the overrange limit) and verify the diagnostics buffer of the SM 1231 reports channel overrange (event 0x0006 "High limit exceeded"). Clear the condition and verify the diagnostic clears automatically on the next scan.
- Cycle the CPU and confirm the SM 1231 DIAG LED is solid green at the end of the cycle, with no diagnostics buffer entries.
8. Preventing Hot-Swap Damage on the S7-1200
The S7-1200 family is mechanically similar to a backplane-based PLC, but the bus between CPU and SM is a passive ribbon connector that is not rated for live insertion. The I/O interface ICs on the SM 1231 are protected by TVS diodes on the 24 V rail and on the analog inputs, but the 5 V backplane and the inter-module clock lines do not have the staggered-pin arrangement of true hot-swap systems such as the S7-1500 with active backplane. Live insertion produces a sequence of voltage steps on the bus that can latch-up the interface ASIC. The first symptom is exactly what this source post reports: solid DIAG red on the SM, slot reported as missing by the CPU, no recovery short of replacement.
Best practice is to wire the system to a single disconnect, label that disconnect, and de-energize it before any module is added or removed. The disconnect must remove both the mains to the CPU and the 24 V sensor supply to the SM terminal block, because the 24 V rail back-powers the analog front end through protection diodes even when the 5 V bus is off.
9. Quick-Reference Troubleshooting Matrix
| Observed Symptom | Likely Root Cause | First Action |
|---|---|---|
| SM DIAG solid red, CPU ERROR flashing, SM "not reachable" in TIA | Hot-swap damage or bus connector not seated | Power down, reseat SM, replace SM if symptom persists |
| SM DIAG flashing red, CPU ERROR flashing, SM visible in TIA with wrench | Channel-level error (overrange, wire break, configuration) | Read SM diagnostics buffer; correct channel wiring or type |
| SM DIAG red, CPU MAINT solid, all SMs show red | Power budget exceeded (5 V or 24 V) | Compute 5 V budget; remove or repower SMs |
| SM DIAG off, no analog readings, no diagnostics events | Process image not updated or wrong slot address in user code | Verify I/O addresses in device configuration match watch table |
| SM DIAG red only after a TIA Portal project upgrade | Catalog part number swap during upgrade | Right-click SM in device view, "Replace device", pick installed MLFB |
10. Related Siemens Documentation
The official documents used to validate the recovery procedure and the diagnostics event codes below are listed here for reference. The exact S7-1200 system manual, section "Diagnostics of the analog inputs", covers event codes 6 through 12 (channel-level) and event code 0x1D38 (module-level). The TIA Portal V17 help, section "Reset to factory settings", describes the dialog path used in step 6 of the recovery procedure.
- SM 1231 Analog Input Module - Technical Specifications (Siemens TIA Documentation)
- SIMATIC S7-1200 Programmable Controller System Manual, chapter 6 "Diagnostics"
- TIA Portal V17 Online Help: "Updating the device configuration" and "Reset to factory settings"
Does the S7-1200 SM 1231 require a separate 24 V power supply?
No. The CPU 1215 supplies the SM 1231 with 5 V logic power through the backplane connector, and a 24 V sensor supply that is current-limited at 300 mA for the AC/DC/RLY variant. For most analog signals the on-board 24 V is enough; an external PS 305/PS 607 is only required when many SMs share the bus and the sensor current budget is exceeded.
Why does the CPU report "Hardware component missing or removed" even though the SM 1231 is physically attached?
The CPU performs a hardware type check on every power-up. If the configured order number in the TIA Portal device view does not match the MLFB of the physical module, or if the bus connector is not fully engaged, the CPU treats the slot as empty and raises event 0x1D38. Re-seat the module and verify the configured MLFB matches the side label of the SM.
Can a hot-swapped SM 1231 be recovered, or is it permanently damaged?
In most cases the damage is permanent. The S7-1200 bus interface is not rated for live insertion, and a single hot-swap event can latch the analog front end. The DIAG LED will remain red after a correct reseat and a factory reset of the CPU, and the only remedy is module replacement.
Will a factory reset of the CPU fix a red DIAG LED on the SM 1231?
Only if the CPU's internal module list is inconsistent after a series of configuration downloads. A factory reset forces the CPU to re-enumerate the I/O bus on the next power-up. If the SM 1231 itself is damaged, the reset will not clear the DIAG LED and the SM must be replaced.
Which TIA Portal version is required to configure the SM 1231 32-0XB0 variants?
TIA Portal V15.1 with HSP 0234 or later supports the 32-0XB0 hardware releases of the SM 1231 family. TIA Portal V16, V17, and V18 configure the modules directly from the base catalog without an HSP. The CPU 1215-1AF40-0XB0 requires TIA Portal V15.1 or later for firmware 4.4 and TIA Portal V17 for firmware 4.6.