Resolving S7-1200 SM 1231 Phantom Voltage on Analog Inputs

David Krause18 min read
S7-1200SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Summary

The reported symptom is consistent across multiple S7-1200 installations using SM 1231 analog input modules (both 4-channel and 8-channel variants). When two 0-10 V actuator feedback signals share the same module, the channel that is supposed to read 0 V (because its actuator is stationary at the start position) instead shows a phantom voltage that climbs as the adjacent channel's signal rises. With the active channel driven to the full-scale 10 V output (raw value 27648), the idle channel typically settles near 2.7 V to 3.0 V (raw value approximately 7500-8294).

The issue is reproducible with a bench setpoint generator, which rules out actuator noise as the cause. It is also reproducible across multiple channel pairs on the same module (IW112/IW114, IW116/IW118, and so on), which rules out a single bad ADC channel. The pattern is the signature of a high-impedance floating analog return rather than a hardware defect inside the SM 1231 module itself.

Field signature: Idle channel voltage tracks approximately 25-30% of the driven neighbor's voltage. 10 V on channel A yields approximately 3 V on adjacent channel B. 5 V on channel A yields approximately 1.5 V on adjacent channel B. The ratio stays roughly constant because the coupling path is resistive divider-based, not capacitive transient.

Affected Hardware and Module Catalog Numbers

The problem is documented on Siemens SM 1231 signal boards and signal modules used with the S7-1200 CPU family. The most commonly deployed catalog numbers are:

Catalog Number Description Channels Resolution Voltage Ranges
6ES7 231-4HD32-0XB0 SM 1231 AI4 4 13 bit + sign +/-10 V, 0-10 V, +/-5 V, 0-5 V, +/-2.5 V
6ES7 231-4HF32-0XB0 SM 1231 AI8 8 13 bit + sign +/-10 V, 0-10 V, +/-5 V, 0-5 V
6ES7 231-5ND32-0XB0 SM 1231 AI4 HS 4 16 bit +/-10 V, 0-10 V, +/-5 V, 0-5 V, +/-2.5 V, 0-1 V
6ES7 231-5PD32-0XB0 SM 1231 AI8 HS 8 16 bit +/-10 V, 0-10 V, +/-5 V, 0-5 V
6ES7 231-4HA30-0XB0 SB 1231 AI1 (signal board) 1 11 bit + sign 0-10 V

The voltage ranges listed for the 13-bit modules match the S7-1200 analog input raw value normalization used in user programs:

Range Engineering Range Raw Low Raw High 1 LSB
0-10 V 0 to 10 V 0 27648 361.69 uV
+/-10 V -10 to +10 V -27648 +27648 361.69 uV
0-5 V 0 to 5 V 0 27648 180.85 uV
+/-5 V -5 to +5 V -27648 +27648 180.85 uV
+/-2.5 V -2.5 to +2.5 V -27648 +27648 90.42 uV

Refer to the S7-1200 Programmable Controller System Manual on Siemens Industry Online Support for the complete electrical specification of these modules, including channel-to-channel isolation, common-mode voltage limits, and the maximum allowed voltage on any input relative to the CPU's 24 V supply common (M).

Root Cause Analysis: Floating M- Terminal and Common-Mode Coupling

The SM 1231 voltage inputs are differential from the module's perspective. Each channel uses two terminals: the signal terminal (V+, also written as '+' or 'V' in some Siemens schematics) and the signal return (V-, also called 'M', 'M-', or 'sensor supply common' depending on module variant). Inside the module, a multiplexer selects the differential pair for the successive-approximation ADC. When the return terminal V- is left open (floating), the ADC sees an undefined reference.

The phantom voltage is not random noise; it is the result of the active channel's input signal coupling through the protection resistor network and input MUX back to the floating channel. The 25-30% ratio is consistent with a divider formed by the input protection resistors of the two channels (typically tens of kohm on each input) with the floating channel acting as a high-impedance pickup point. Driving the neighbor to 10 V pushes about 3 V onto the floating pin through this divider.

Key contributors in a typical cabinet:

  1. M- of the SM 1231 module is not bonded to the field device common. The most common mistake is to wire only V+ to the actuator feedback terminal and assume the PLC backplane ground is the reference. For an SM 1231, the channel reference is the M- terminal at the module's connector, not the CPU's M terminal, and not PE.
  2. Belimo actuator output is referenced to the actuator's 24 V supply common, not to the SM 1231 module's internal analog ground. If those two commons are at different potentials (often because the 24 V supply is a separate, isolated PSU for the actuator, and only the +24 V is paralleled to the CPU PS), the V- return path is broken.
  3. Unused channels are not shorted V+ to V-. The SM 1231 manual explicitly requires unused voltage channels to have V+ and V- jumpered together so the ADC sees a defined 0 V rather than a floating input.
  4. Adjacent channel coupling. Even after the wiring is corrected, channels with very different signal levels can show small crosstalk (typically less than 0.5% of the adjacent reading) if the analog cable shield is not terminated at one end. This is a separate, smaller issue from the primary phantom-voltage fault.
Why a calibrator reproduces the fault: A bench setpoint generator that drives V+ only - without also bonding its output LO to the SM 1231 module's V- terminal - will produce the same phantom-voltage symptom on adjacent channels. This proves the fault is in the wiring topology, not the SM 1231 hardware.

Per the Siemens S7-1200 System Manual, the maximum permissible common-mode voltage between any input channel and the CPU's 24 V supply common (M) is typically +/-12 V (verify against the specific module's data sheet; for the 6ES7 231-4HD32-0XB0 the absolute maximum input voltage relative to M is +/-35 V continuous). Exceeding the common-mode range causes not just reading errors but also potential damage to the input protection network.

Diagnostic Procedure

Before replacing any hardware, prove the fault with the following sequence. Each step eliminates one hypothesis.

  1. Verify the loaded hardware configuration matches the physical module. In TIA Portal, go offline with the PLC, then Project tree -> PLC -> Device configuration. Confirm the slot occupied by the SM 1231 has the exact catalog number that is physically installed. Right-click the module and choose Hardware detection if the configuration is empty. A common commissioning error is to load an SM 1231 AI8 configuration into an SM 1231 AI4 module, which truncates input addresses and shifts the IW mapping.
  2. Confirm each input is configured as a voltage input (not current). In the module's properties under Analog inputs, set Input type = Voltage and Range to 0-10 V (or +/-10 V if the actuator can swing negative on over-travel). Current configuration on a voltage-driven source produces a saturated near-zero reading, not the symptom in this report.
  3. Use a watch table to read IW112 and IW114 in real time. Create a watch table with both IW addresses, monitor online, and physically command Actuator 1 through its full stroke with Actuator 2 powered but held still. Record the raw IW114 value at five points: 0%, 25%, 50%, 75%, 100% on Actuator 1. The expected reading on IW114 should remain within +/-50 counts (approximately +/-180 mV) of zero if wiring is correct.
  4. Disconnect the field wiring at the SM 1231 terminals. Leave only a wire jumper from V+ to V- on IW114 (channel grounded at the terminal block). With Actuator 1 still driving IW112 from 0 to 10 V, IW114 must read 0 plus or minus a few counts. If it still reads approximately 3 V at 10 V on IW112 with the field wiring removed, the module is defective. If it now reads 0, the fault is in the field wiring or the actuator's return path - continue.
  5. Check the M- terminal voltage with respect to the CPU's M terminal. Place one DMM lead on the SM 1231 channel V- terminal (the return for the actuator being tested) and the other on the CPU's M terminal. With the actuator powered, this should read less than 100 mV. A reading of several hundred millivolts or more confirms the two commons are not bonded.
  6. Test with a calibrator. Drive V+ with a precision 0-10 V source, with the source's LO bonded to the channel's V- terminal. Sweep 0 to 10 V and read IW back. Linearity and offset must be within the module's published accuracy spec (typically +/-0.3% of full scale at 25 deg C).

Step-by-Step Wiring Correction

The wiring fix has three components: bond the field device common to the SM 1231 channel return, ground any unused voltage inputs, and confirm the actuator power supply common is the same reference as the PLC analog common.

  1. Identify the actuator's 0-10 V output reference. For a Belimo modulating actuator (LM, NM, AF, GM, or equivalent series with proportional control), the position feedback terminal (typically marked 'U' or 'Y') sources 0-10 V referenced to the actuator's 24 V supply common (typically terminal 'G0' or pin 2). The actuator is a 3-wire device: 24 V supply, supply common, and signal output. Do not assume the actuator's signal common is earth-grounded; in most installations it floats relative to PE.
  2. Run a dedicated 3-conductor shielded cable from each actuator to the SM 1231 terminal block. Conductor 1: +24 V to actuator supply. Conductor 2: signal common (bonded at the SM 1231 channel V- terminal AND at the actuator's supply common terminal). Conductor 3: signal + to actuator feedback output (wired to the SM 1231 channel V+ terminal).
  3. Bond the channel V- to the field device common at the SM 1231 terminal block. Use a short, dedicated jumper from the channel's V- terminal to the field-side common terminal block (or to the CPU's M terminal if the 24 V supply is shared). Do not rely on the backplane or DIN-rail contact as the return path - those are not designed as precision analog references.
  4. Jumper V+ to V- on every unused voltage channel. This is mandatory on the SM 1231 family per the System Manual. Without this jumper, unused channels float and the ADC returns random near-full-scale readings that contaminate adjacent channel readings through the internal MUX and protection network.
  5. Terminate the cable shield at one end only. Preferred end is the cabinet entry, bonded to the cabinet's analog ground bar (or the CPU's M terminal via a short pigtail). Do not bond the shield at the actuator end unless the actuator's body is isolated from PE; double-grounding a shield creates a ground loop that injects 50/60 Hz into the analog signal.
  6. Verify polarity of the 24 V supply to the actuator. If the actuator's supply common is connected to PE at the actuator (some installations do this), the SM 1231 channel V- terminal will sit at PE potential. As long as that potential is within the SM 1231's allowable common-mode range, the channel will read correctly, but you must size the common-mode voltage against the module's data sheet.
Common-mode limit reminder: For the SM 1231 AI4 (6ES7 231-4HD32-0XB0), the maximum input voltage relative to CPU M is +/-35 V continuous. The maximum transient input voltage (under- or over-range) is +/-75 V for 1 ms every 100 ms. If your actuator's supply common sits more than 12 V away from the CPU M, you are operating outside the recommended common-mode range and must use an isolated signal conditioner between the actuator and the SM 1231.

TIA Portal Configuration for 0-10 V Inputs

Open the device configuration, select the SM 1231 module, and navigate to Properties -> Analog inputs. For each channel:

  1. Set Input type = Voltage. (The dropdown also includes Current (4-20 mA, 0-20 mA) and Resistance / RTD; selecting the wrong one routes the signal through the wrong input network and produces nonsense readings.)
  2. Set Range = 0 to 10 V for unipolar Belimo position feedback. Use +/-10 V only if your actuator can drive below 0 V on under-travel (rare on modulating dampers and valves).
  3. Set Integration time = 60 Hz (16.67 ms) for installations in 60 Hz regions or 50 Hz (20 ms) for 50 Hz regions. The 60 Hz setting provides one cycle of mains rejection at the cost of a slightly slower update rate; the 50 Hz setting is the inverse. Do not use the 400 Hz integration unless the application requires it - the additional noise rejection is marginal and the response is much slower.
  4. Enable Diagnostics for over-range and under-range only if you need them to drive a process alarm; otherwise leave disabled to reduce CPU scan load. Wire-break detection is supported on the AI4 HS (16-bit) module on the 0-10 V range, but is not reliable on the 13-bit modules for voltage inputs.
  5. Confirm the channel addresses in the I/O addresses tab. The system assigns IW addresses starting from the configured start address (default 0 for the first AI module, then increments in word boundaries). If you have changed the start address to 112 to match IW112/IW114, verify it matches the IW used in your user program.

The hardware configuration must be downloaded to the PLC after any change. Use Online -> Download to device, mark Consistent download, and confirm that the catalog number reported back from the PLC matches the physical module. A mismatch silently truncates the I/O map and is the root cause of many 'phantom IW' reports.

PLC Program Verification

Once wiring and configuration are confirmed, add the following to your user program as a permanent verification block:

// FB "AI_Diag_SM1231" - block-level diagnostic for an SM 1231 0-10V input pair
// Monitors crosstalk from neighbor channel and latches fault if ratio exceeds limit

FUNCTION_BLOCK "AI_Diag_SM1231"
VAR_INPUT
    iw_Signal      : INT;    // Active channel reading, e.g. IW112
    iw_Neighbor    : INT;    // Adjacent channel that should be idle, e.g. IW114
    i_CrosstalkPct : REAL := 30.0; // Allowed crosstalk as percent of full scale (27648)
END_VAR
VAR_OUTPUT
    b_CrosstalkFault : BOOL; // TRUE if neighbor reading exceeds allowed crosstalk ratio
    r_NeighborPct    : REAL; // Neighbor reading expressed as percent of full scale
END_VAR
VAR
    r_Sig        : REAL;
    r_Nbr        : REAL;
    r_Ratio      : REAL;
END_VAR

BEGIN
    r_Sig := INT_TO_REAL(iw_Signal);
    r_Nbr := INT_TO_REAL(iw_Neighbor);

    IF r_Sig > 1000.0 THEN
        // Active channel has meaningful drive > ~36 mV; sample neighbor
        r_Ratio := (r_Nbr / 27648.0) * 100.0;
        r_NeighborPct := r_Ratio;
        IF r_Ratio > i_CrosstalkPct THEN
            b_CrosstalkFault := TRUE;
        ELSE
            b_CrosstalkFault := FALSE;
        END_IF;
    ELSE
        // Active channel near zero; cannot evaluate crosstalk
        b_CrosstalkFault := FALSE;
        r_NeighborPct   := 0.0;
    END_IF;
END_FUNCTION_BLOCK

Call this FB once per active/inactive pair and route b_CrosstalkFault into your HMI alarm log. A persistent TRUE reading with the wiring corrected indicates either an open V- terminal on the neighbor or a configuration mismatch between the project and the physical module.

Verification Procedure and Acceptance Test

After correcting the wiring and downloading the updated hardware configuration:

  1. Static zero test. With all actuators powered but at their start positions, every 0-10 V feedback channel must read within +/-50 counts of 0 (i.e., less than or equal to +/-180 mV). Document the offset for each channel and apply it as a calibration constant if your application requires high absolute accuracy.
  2. Crosstalk test. Drive Actuator 1 through its full stroke (0 -> 100% -> 0) while Actuator 2 is held at 0. The IW114 reading must remain within +/-50 counts of 0 throughout the test. Repeat the test in reverse (drive Actuator 2, monitor Actuator 1's channel). Any pair that fails this test has a wiring defect, not a module defect.
  3. Dynamic response test. Run your PID loop on Actuator 1 against a step setpoint change of 50%. Confirm the position feedback tracks the setpoint within the PID tuning envelope and that no oscillation is introduced by the previously phantom voltage on the neighbor channel. Capture a trend of the PID error and the neighbor channel's raw value side by side; the trend should show the neighbor staying flat at 0.
  4. Long-term drift test. Log the IW readings for 24 hours under normal operating conditions. A channel that drifts more than the module's published temperature coefficient (typically +/-0.005%/degK of full scale, so approximately +/-30 counts over a 20 deg C cabinet swing) suggests an actual module issue and warrants replacement.
Acceptance criterion summary: Idle channel reading less than +/-50 counts (+/-180 mV) regardless of neighbor's drive level. Active channel linearity less than +/-0.3% of full scale (approximately +/-83 counts) after calibration offset.

Related Defects and Edge Cases

The same symptom family appears under several other root causes that are easy to confuse with the floating V- fault:

Symptom Root Cause How to Distinguish
Idle channel tracks active channel at approximately 25-30% Floating V- terminal (this article's fault) Bond V- to field common; symptom disappears
All channels drift together when one is driven Common-mode voltage exceedance (actuator PSU floating above CPU M) Measure V- to CPU M under load; must be less than +/-1 V
One specific channel reads junk, others fine Damaged protection resistor on that input (overvoltage event) Replace module; fault persists with all wiring removed
Random spikes on idle channel, not correlated to neighbor EMI pickup from VFD output cable or unshielded power wiring Re-route analog cable, terminate shield, separate from VFD cable by at least 200 mm
All channels read saturated high (approximately 32767) regardless of input Module configured as current input on voltage source (or vice versa) Check TIA Portal device configuration; match input type to actual signal
Reading inverted (10 V input reads 0, 0 V reads 27648) V+ and V- reversed at terminal Inspect terminal polarity; correct wiring
Reading is correct at 0 V but caps at approximately 13824 with 10 V applied Module configured for +/-5 V or 0-5 V range on a 0-10 V source Correct range in TIA Portal to 0-10 V
Reading is correct then jumps after warm-up Thermistor drift in cold-junction (not applicable to 0-10 V) or actual module thermal defect Wait 30 min; if reading stabilizes, normal; if not, replace module

Field-Commissioning Checklist

Use this checklist on every new installation that uses SM 1231 modules for 0-10 V actuator feedback.

  1. Confirm the SM 1231 catalog number in TIA Portal matches the module physically installed.
  2. Confirm each input type and range in the device configuration matches the field signal (Voltage, 0-10 V).
  3. Download the hardware configuration and read it back; verify catalog number reports correctly.
  4. Bond every channel V- to the field device common with a dedicated conductor; do not rely on DIN rail contact.
  5. Jumper V+ to V- on every unused voltage channel.
  6. Terminate each analog cable shield at the cabinet end only, bonded to the analog ground bar.
  7. Power the actuators and measure V- to CPU M with a DMM under full load; reading must be less than +/-1 V.
  8. Run the static zero test on every channel; record offsets.
  9. Run the crosstalk test on every active/inactive pair.
  10. Sign off the loop performance with a PID trend capture.

Following this checklist on every commissioning eliminates the floating-V- defect class entirely. Documented evidence (trend captures and DMM readings) provides the data needed to escalate any residual hardware defect to Siemens Industry Online Support with the specific catalog number and firmware version of the SM 1231 in question.

FAQ

Why does my idle S7-1200 SM 1231 channel read 3 V when the adjacent channel reads 10 V?

The channel's V- (signal return) terminal is floating, meaning it is not bonded to the field device common. The 10 V on the neighbor channel couples through the input protection resistor network and the internal multiplexer into the floating channel, producing roughly 25-30% of the neighbor's voltage as a phantom reading. Bond the V- terminal to the actuator's supply common at the SM 1231 terminal block to eliminate the fault.

Do I need to ground unused voltage channels on the SM 1231?

Yes. Per the S7-1200 System Manual, every unused voltage input must have V+ and V- jumpered together at the terminal block. An unused channel left floating returns random near-full-scale readings that can also inject noise into adjacent active channels through the internal MUX. Failure to ground unused channels is a common source of unexplained high IW values.

What is the maximum common-mode voltage allowed between the SM 1231 input and the CPU M terminal?

For the SM 1231 AI4 (6ES7 231-4HD32-0XB0), the absolute maximum continuous input voltage relative to CPU M is +/-35 V, with +/-75 V transient allowed for 1 ms every 100 ms. The recommended operating common-mode range is much tighter (+/-12 V typical). If your actuator's 24 V supply common sits more than 12 V away from the CPU M, insert an isolated signal conditioner between the actuator and the SM 1231 to prevent damage and reading errors.

How do I configure the SM 1231 for a Belimo 0-10 V position feedback?

In TIA Portal, open the device configuration, select the SM 1231 module, and set each used channel to Input type = Voltage and Range = 0 to 10 V. Set the integration time to 50 Hz (20 ms) in 50 Hz regions or 60 Hz (16.67 ms) in 60 Hz regions. Download the hardware configuration and confirm the catalog number reports back correctly. Wire the actuator's 24 V supply common to the channel's V- terminal at the SM 1231 connector.

How can I prove the fault is wiring and not the SM 1231 module?

Disconnect the field wiring at the SM 1231 terminal block and place a wire jumper from V+ to V- on the suspected channel. Drive the adjacent channel from 0 to 10 V using either the actuator or a precision calibrator. If the suspect channel still reads approximately 3 V at 10 V on the neighbor, the module is defective. If the suspect channel reads 0 plus or minus a few counts, the fault is in the field wiring topology - bond the channel V- to the field device common and rerun the test.

Back to blog