Resolving S7-300 PIW Address Gaps on IM153-1 with TIA Portal

David Krause21 min read
PLC HardwareSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving S7-300 PIW Address Gaps on IM153-1 with TIA Portal

When you place a SIMATIC S7-300 CPU 319-3 PN/DP onto a PROFIBUS line of ET 200M stations behind one or more IM 153-1 interface modules, the TIA Portal hardware editor is supposed to slot every analog input (AI) module into a contiguous address range starting at PIW 0 and walking upward. In a real project with several stations and dozens of 8-channel AI modules, TIA Portal can refuse to place a module even though the Address Overview shows free space, e.g. at PIW 244. The compiler flags a "gap" that you cannot fill, and the start address is locked out.

The reason is not a hardware fault, a missing GSD, or a slot conflict. It is a Process Image Input (PII) boundary rule enforced by the S7-300 CPU. Understanding that rule, and learning how to either extend the process image or place modules outside it, removes the gap permanently and gives you a deterministic cycle time for the AI scan.

1. Problem Description

A typical layout is two ET 200M stations on PROFIBUS DP, each starting with an IM 153-1 (for example, 6ES7153-1AA03-0XB0 or 6ES7153-2BA10-0XB0 for the redundant IM 153-2) and populated with SM 331 AI8 modules (6ES7331-7KF02-0AB0). The engineer wants a contiguous 8-channel AI block per node:

Node 1  IM 153-1   PIW100 ... PIW227   (8 channels, 16 bytes)
Node 2  IM 153-1   PIW228 ... PIW243   (planned, 8 channels, 16 bytes starting at 228)

When configuring slot 5 of node 2 (SM 331 AI8, 16 bytes of input data) at start address PIW 244, the Address Overview marks PIW 244 as available, but the editor refuses the assignment. A red marker identifies 244 as a "gap" and the start address field is read-only or rejects manual entry. The TIA Portal warning text reads "Module cannot be placed at the configured start address" or "Start address is outside the process image of the CPU". On a fresh project the OB1 PII is 256 bytes, so the second station's 16-byte module is being asked to sit half inside and half outside that window.

This is a boundary problem, not a wiring problem. The desire to make the AI block contiguous is reasonable, but the S7-300 PII imposes a hard 256-byte partition window in the default configuration, and a single module cannot straddle that window.

2. Root Cause: Process Image Partition Boundary

The S7-300 CPU's Process Image Input is a fixed-size memory window that the operating system refreshes once per OB1 cycle (or once per the OB to which the partition is assigned). It is a contiguous input range starting at byte 0 of the partition and ending at a configurable upper bound. The size is an integer multiple of bytes and is configured per partition in the CPU properties.

The rule that blocks the address in the symptom is:

Module start address + module data length <= Process image end address + 1

The SM 331 AI8 in the example occupies 16 bytes (8 channels x 2 bytes/channel). The configured OB1 PII is 256 bytes (bytes 0 through 255). If the module is placed at 244:

244 + 16 = 260  >  255  --> rule violated

The PII cannot be split by a module. S7-300 will not copy a 16-byte module that crosses the 256-byte boundary, so the editor is correct to refuse the assignment. The Address Overview will show 244 as "free" because it is a free byte-level location in the peripheral address space, but it is not a free location inside the PII because the upper 4 bytes (PIW 258..PIW 259) lie outside the PII window.

A module cannot straddle the PII boundary, even partially. The CPU copies the entire module data in one OS transfer; if the tail of the module is outside the PII, the transfer cannot complete and the module is rejected by the hardware editor.
S7-300 PII Address Map - Module Crossing 256B Boundary Process Image Input (PII): Bytes 0 to 255 (256 bytes default) Outside PII (direct access only) AI8 start: 244 AI8 end: 259 (crosses boundary) PII boundary (byte 256) 244 + 16 = 260 > 255 REJECTED by TIA Portal Fix: Extend PII to 512+ bytes, or move module to PIW 256

3. Default and Maximum Process Image Size for the S7-300 CPU 319

For the SIMATIC S7-300 CPU 319-3 PN/DP, two part numbers are common in the field:

  • 6ES7318-3EL01-0AB0 - 2 MB work memory, FW V3.x
  • 6ES7318-3FL01-0AB0 - 4 MB work memory, FW V3.x

Both support a maximum process image of 2 KB per partition in TIA Portal, and the addressable I/O area extends to 16 KB across all partitions combined. TIA Portal ships with the OB1 process image partition pre-sized to 256 bytes for inputs and 256 bytes for outputs in a fresh project. The total PII/PIQ is configurable up to the CPU's addressable limit and can be split across up to 16 partitions, each assigned to a different OB.

CPU Order Number (MLFB) Work Memory Max PII/PIQ Default OB1 Partition
CPU 319-3 PN/DP 6ES7318-3EL01-0AB0 2 MB 2 KB / partition 256 bytes I + 256 bytes Q
CPU 319-3 PN/DP (4 MB) 6ES7318-3FL01-0AB0 4 MB 2 KB / partition 256 bytes I + 256 bytes Q
CPU 317-2 PN/DP 6ES7317-2EK14-0AB0 1 MB 2 KB / partition 256 bytes I + 256 bytes Q
CPU 315-2 PN/DP 6ES7315-2EH14-0AB0 512 KB 1 KB / partition 128 bytes I + 128 bytes Q
CPU 314C-2 PN/DP 6ES7314-6EH04-0AB0 192 KB 1 KB / partition 128 bytes I + 128 bytes Q

If the TIA Portal project shows "256 bytes" as the current OB1 PII size and the address gap appears at 244, the default 256-byte partition is in effect. The boundary rule is applied per partition, so a 256-byte partition for OB1 and a separate 256-byte partition for OB35 (cyclic interrupt) each have their own independent boundary at byte 255 of their respective partition. The address space 256..511 is not blocked globally - it is blocked only for the partition that does not contain it.

Reference: SIMATIC S7-300 CPU 31xC and CPU 31x: Technical Specifications Manual (Siemens Industry Online Support, Entry ID 109751586).

4. Solution A: Extend the Process Image in TIA Portal

The cleanest solution is to grow the OB1 PII partition so the 16-byte AI module fits. With 200+ AI channels this is the recommended approach if the application reads all analog values on every OB1 scan.

Procedure:

  1. In the TIA Portal project tree, open Devices & networks and double-click the CPU 319-3 PN/DP.
  2. Switch to Properties > General > Process image (in older TIA Portal versions: Properties > Cycle / Clock Memory).
  3. In the row OB1 process image partition, change the Input area end from 255 to 511 (giving a 512-byte PII) or to 1023 (1024-byte PII) for larger AI counts.
  4. Click Recalculate and compile the hardware configuration (Project tree > right-click CPU > Compile > Hardware (rebuild all)).
  5. Reopen the IM 153-1 station and place the SM 331 AI8 module at PIW 244. The address is now accepted because 244 + 16 = 260 falls inside the new 512-byte PII (0..511).

For a project with 200 AI channels you will need at least 400 bytes of PII (16 bytes per AI8 module x 25 modules). Round up to 512 or 1024 bytes for headroom.

Memory cost: the PII lives in the CPU's work memory (not load memory). Each byte of PII costs 1 byte of work memory. Growing PII from 256 to 1024 bytes adds 768 bytes of work memory - negligible on a CPU 319-3 with 2 MB or 4 MB of work memory. The trade-off is not memory; it is a small OB1 OS copy time increase on the order of 50-100 microseconds, which is acceptable for cycle times > 5 ms.

Reference: TIA Portal Help: Configuring the Process Image.

5. Solution B: Move the Module Outside the Process Image

If you do not want to consume work memory for a large PII, you can leave the OB1 partition at 256 bytes and place the second station's modules at PIW 256 (or higher). Modules outside the PII are accessed by the CPU through direct peripheral I/O (PI/PQ access) on demand. The trade-off is a small per-access overhead and slightly more S7-300 OS time per read, because each PIW access issues a backplane or PROFIBUS cycle.

Procedure:

  1. Select the IM 153-1 station whose modules you want to move.
  2. Open the slot properties of the SM 331 AI8 module and change Start address from 244 to 256 (or to the next free 16-byte-aligned address outside the OB1 PII, e.g. 256, 272, 288, 304, ...).
  3. Compile. The module is now in the peripheral address space only; access is by direct read (L PIW 256 in STL, or "PIW256" in SCL with the :P qualifier).
Approach OB1 PII Size AI Block Location Work Memory Read Time per AI
A: Extend PII 1024 bytes Inside OB1 PII (IW access) +768 bytes vs default 0.2-0.5 microseconds
B: Outside PII 256 bytes (default) PIW 256+ (PIW access) 0 (default) 5-15 microseconds
C: OB35 partition OB1 256 B + OB35 1024 B OB35 PII +1024 bytes 0.2-0.5 microseconds in OB35

For 200 AI channels refreshed once per OB1 cycle, Solution A or C is the right choice. For 200 AI channels read at 100 ms cadence via OB35, Solution C is the cleanest. Solution B is acceptable only for sub-50-channel counts sampled in OB1 or in OB35 where the cycle time has headroom.

6. TIA Portal Configuration Walkthrough

The complete step-by-step procedure for the project described in Section 1, using Solution A.

6.1. Open the CPU Properties

Navigate to Project tree > Devices & networks > PLC_1 [CPU 319-3 PN/DP]. Open the device view, then in the inspector window select the Properties tab. Click the General entry in the left pane. The Process image subsection is near the bottom of the General list (below System and clock memory).

6.2. Increase the OB1 Partition

Locate the table entry OB1 - Program cycle. Set the Input area start to 0 and Input area end to 1023 (giving a 1024-byte PII for OB1). Repeat for the Output area only if you also need digital outputs in PII; if there are no DQ modules behind the IM 153-1, leave the output area at the default 256 bytes.

6.3. Add OB35 Partition for Cyclic Interrupt (Optional)

If you decide to split the AI reads into a 100 ms timed interrupt, add a partition OB35 - Cyclic interrupt with its own input range, e.g. 1024..2047. This partition is refreshed only at the OB35 priority, keeping OB1 PII lean.

6.4. Place the AI Module

Open the IM 153-1 station's device view. Drag the SM 331 AI8 module (6ES7331-7KF02-0AB0) onto slot 5. In the slot's properties, the Input addresses field is now editable. Enter 244 as the start address. TIA Portal accepts the assignment because the partition now extends to 1023.

6.5. Compile and Download

Right-click the CPU and select Compile > Hardware (rebuild all). If the result is 0 errors, 0 warnings, the configuration is consistent. Download the hardware configuration to the CPU; a stop/start of the CPU is required after a PII size change. A cold restart (MRES) is not required - a warm restart with full PII resize is sufficient.

7. Verification Procedure

To confirm the process image fix is in effect:

  1. Go online with the CPU. In the project tree, right-click the CPU and select Go online > Online & diagnostics.
  2. Open Online & diagnostics > Information > Process image (or use a watch table on the inputs). The values at IW 244..IW 259 should be updating in sync with the analog input channels on the IM 153-1 station.
  3. In the watch table, force IW 244 to 0 and confirm the corresponding analog channel on the field side returns 0 V / 0 mA (i.e., the wiring is correct, not a slot-mismatch bug).
  4. Open Online & diagnostics > Diagnostics buffer and confirm no IO access error (event ID 0x2942) or Module fault (event ID 0x39xx) entries are written during the change.
  5. Run a continuity test: trigger OB1 in single-step mode (or set a breakpoint in OB1) and observe the value of IW 244 updates between successive OB1 cycles.
  6. Check the cycle time: Online & diagnostics > Information > Cycle time. Confirm OB1 cycle is still within the project budget (typically < 50% of the configured minimum cycle time).

If the values update in the watch table, the partition is correct. If the value remains 0 or shows a fixed value across cycles, recheck that the AI module's Start address matches the slot's I address in the device view, and that the IM 153-1 has the right DP slave address (1 or 2 in the example) and the same station number is configured in the CPU's DP master system.

8. PII vs. Direct I/O Access: Performance Analysis

A module inside the OB1 PII is read once per OB1 scan by the S7-300 operating system, and the user program reads from the IW/QW operand area. A module outside the PII requires a direct peripheral I/O instruction (L PIW / T PQW) for every read, which issues a bus cycle each time.

Characteristic Inside PII (IW access) Outside PII (PIW access)
OS refresh Once per partition's OB None (on-demand)
User instruction (STL) L IW 100 (load input word) L PIW 100 (load peripheral input word)
User instruction (SCL) "IW100" "PIW100" or "IW100":P
Typical S7-300 instruction time 0.1-0.3 microseconds 5-15 microseconds (depends on backplane/PROFIBUS latency)
Determinism Snapshot at start of OB Live read at execution time
Work memory cost 1 byte per byte of PII 0
Suitable for time-critical loops Yes (recommended) Use only for slow signals

The 10-30x performance advantage of IW over PIW comes from two sources. First, IW reads from the work-memory-resident PII, which is a direct memory load. Second, PIW reads issue a bus cycle on the backplane or PROFIBUS segment and stall the CPU until the slave returns the value, which is dominated by the PROFIBUS round-trip time of approximately 1 ms for a 1.5 Mbps segment with 32 slaves.

For 200+ AI channels sampled every OB1, the difference is real:

PII access, 200 channels, OB1  :  200 * 0.3 microseconds = 60 microseconds total
Direct access, 200 channels, OB1:  200 * 10 microseconds = 2 ms total

The 2 ms is a non-trivial fraction of a 10 ms OB1 cycle. For 5 ms OB1 cycles, it becomes critical. Hence the engineering rule: if you read all AIs every scan, put them in the PII.

Code example: reading 200 AI channels in OB35 with all channels in OB35 PII (Solution C):

// OB35 - 100 ms cyclic interrupt
// All 200 AI channels mapped to PII bytes 128..527 (PIW 128..PIW 527)
FOR #i := 0 TO 199 DO
    "DB_AI_Values".AI[#i] := WORD_TO_INT("IW" := INT_TO_WORD(128 + #i * 2));
END_FOR;

Code example: reading 200 AI channels via direct PIW access (Solution B):

// OB35 - 100 ms cyclic interrupt
// All 200 AI channels at PIW 256..PIW 655 (outside PII)
FOR #i := 0 TO 199 DO
    "DB_AI_Values".AI[#i] := "PIW"[256 + #i * 2];
END_FOR;

9. OB-Based Process Image Partitions

The S7-300 CPU supports up to 16 process image partitions, each tied to a specific OB. TIA Portal exposes this in the CPU properties under Process image > Partition assignment. Typical partition layout:

OB Priority Trigger Typical Partition Use Case
OB1 1 Free cycle 0..255 (digital + 4 fast AI) High-priority I/O read each scan
OB10 2 Time-of-day interrupt 256..383 Periodic fast analog batch
OB35 12 Cyclic interrupt 100 ms (default) 384..511 Slow analog sampling
OB40 16 Hardware interrupt 512..639 Event-driven AI on DI edge
OB55 2 DP interrupt (status) 640..767 PROFIBUS slave status
OB56 2 DP interrupt (update) 640..767 PROFIBUS slave update
OB57 2 DP interrupt (vendor-specific) 640..767 Vendor alarms
OB82 26 Diagnostic interrupt -- Fault handling (no PII)

When a partition is assigned to OB35, the OS updates only that range at the OB35 priority. The OB1 cycle continues to use its own PII range. This lets you scale large AI counts without inflating the OB1 PII.

A common pattern for 200+ AI:

  1. OB1 PII: 0..127 (digital + 4 fast AI modules, 32 bytes analog)
  2. OB35 PII: 128..1023 (200 AI channels, 400 bytes)

The OB1 cycle never touches the analog range; OB35 reads the AI values every 100 ms, writes them to a global DB, and the user code consumes the DB values as needed.

Reference: SIMATIC S7-300 CPU 31x: OBs and Process Image Partitions (Siemens Industry Online Support, Entry ID 109751586).

10. Memory and Scan-Time Trade-Offs

A larger PII costs work memory, but the cost is trivial relative to the cost of a non-deterministic scan time. The numbers below are order-of-magnitude estimates; actual times depend on CPU firmware version, backplane load, and PROFIBUS configuration.

PII Size Work Memory Cost OB1 OS Refresh Time (typical) Suitable AI Count (8-ch modules)
128 bytes 128 B 5-15 microseconds ~14 channels
256 bytes 256 B 10-30 microseconds ~62 channels
512 bytes 512 B 20-60 microseconds ~126 channels
1024 bytes 1 KB 40-120 microseconds ~254 channels
2048 bytes 2 KB 80-240 microseconds ~510 channels

An 8-channel AI module (SM 331 AI8) occupies 16 bytes of PII (8 channels x 2 bytes per 16-bit value). The 200-channel case in this article (25 AI8 modules) needs 25 x 16 = 400 bytes minimum; round up to 512 bytes for headroom.

OB1 cycle impact: the OS copy of 1 KB of PII at approximately 100 ns per byte is ~100 microseconds, which is 1% of a 10 ms OB1 cycle - negligible. Compared to the cost of 200 direct PIW reads (~2 ms), the PII approach is 20x faster.

Reference: Siemens Industry Online Support: ET 200M Distributed I/O System Manual.

11. Best Practices for 200+ Analog Input Channels

Based on the trade-offs above, the recommended configuration for a 200+ AI project is:

  1. Reserve a partition for AI: set OB1 PII to 256 bytes for digital I/O, then add a 512-1024 byte partition on OB35 for analog. The OB1 PII stays lean and deterministic.
  2. Read AI in OB35 at 100 ms: most analog signals (4-20 mA, RTD, TC) are slow. 100 ms is well below the typical 200-500 ms field update rate. 200 AI reads in 100 ms = 2 ms CPU load per OB35, leaving 98 ms headroom.
  3. Use direct PIW access for sub-100 ms AIs: if a few channels need faster updates, place them in OB1 PII (Solution A) or read them via PIW on demand from OB1.
  4. Align module start addresses to 16-byte boundaries: 16-byte AI8 modules fit cleanly into PII windows without crossing 16-byte boundaries. Avoid placing them at odd 2-byte boundaries (e.g. PIW 250) - it works but makes the layout harder to read.
  5. Avoid mixing partitions across stations: keep all of one IM 153-1 station's AI modules in the same partition. This isolates the bus traffic for that station and makes diagnostics easier.
  6. Do not exceed 80% of PII with analog: leave at least 20% of PII for digital inputs, diagnostics, and future expansion. On a 1024-byte PII, keep AI under 800 bytes (~200 channels).
  7. Verify scan time after each PII resize: use Online & diagnostics > Information > Cycle time to confirm OB1 and OB35 are within budget. Long-term logging with the trace function reveals jitter on OB1 not visible in single-point readings.
  8. Document partition ownership: in the project documentation, list the byte range of each partition, the OB that refreshes it, and the modules assigned to it. The Address Overview in TIA Portal is the authoritative source.
  9. Use IM 153-1 FW V6.0+ for DP-V1 diagnostics: the IM 153-1 (6ES7153-1AA03-0XB0) ships with FW V6.0 or later from 2014 onward. DP-V1 enables acyclic diagnostic reads via SFB 52 / SFB 53, which is useful for module health monitoring in 200+ AI stations. Older FW V5.x is DP-V0 only.
  10. Plan for hot-swap on IM 153-2: if you use the redundant IM 153-2 (6ES7153-2BA10-0XB0), the same PII rules apply, but module replacement during RUN is only possible with a configured redundant partner and the same module in both slots. Hot-swap modules must be installed in slots 4..15 only, not slot 1..3.

For a project that reads all 200 AIs in OB1 (e.g. a motion control loop with 1 ms cycle), the PII must be sized to fit all of them, and the OB1 cycle time must be monitored with the trace function. For a process control project that samples AIs at 100 ms, the OB35 partition is the right choice.

After changing the PII size, you must stop and restart the CPU for the new size to take effect. A download of the hardware configuration alone is not sufficient - the PII is allocated in work memory at startup.
The IM 153-1 (PROFIBUS) and the IM 153-4 (PROFINET, 6ES7153-4AA01-0XB0) implement the same S7-300 module addressing rules. The PII logic in the CPU is identical. The choice between PROFIBUS and PROFINET is a topology question, not an addressing question.

12. Troubleshooting Matrix

Common errors encountered while configuring the process image and IM 153-1 stations on the CPU 319-3 PN/DP, with root cause and field-proven fix.

Symptom Likely Cause Fix
PIW 244 (or any "gap" address) rejected as module start Module would cross the OB1 PII boundary at 256 bytes Extend OB1 PII to 512/1024 bytes, or move module to PIW 256+
"Module cannot be placed at the configured start address" warning Module start address inside another partition, or outside configured range Check Partition assignment table in CPU properties; reassign module to correct partition
AI value stuck at 0 or at full-scale (32767 / 27648) Module address wired to wrong slot, or IM 153-1 has wrong PROFIBUS address Verify DP slave address matches station number; verify slot start address matches channel wiring
AI value fluctuating wildly during OB1 scan Module outside PII, code uses PIW, PROFIBUS timeout Move module into PII, or use OB35 with consistent scan time; check PROFIBUS baud rate and cable diagnostics
OB1 cycle time increased by 2-5 ms after PII resize PII grew large, OS refresh time dominates OB1 Move slow AI to OB35 partition, keep OB1 PII under 512 bytes
Diagnostic buffer: "IO access error" (event 0x2942) Code reads PIW or PQW on a slot that has no module Check empty slot addresses; remove unused PIW reads
Diagnostic buffer: "Module fault" (event 0x39xx) Module removed, channel fault, or wire break on AI Open Online & diagnostics > Module information; check channel diagnostics with SFB 52
Module not detected after download IM 153-1 FW too old for DP-V1 features, or GSD version mismatch Update IM 153-1 to FW V6.0+; reload correct GSD (e.g. SIEM8010.GSD for IM 153-1)
CPU goes to STOP after PII resize Work memory exceeded due to oversized PII Reduce PII size to fit work memory; or upgrade CPU to 4 MB variant
Force table on IW does not affect field reading Module outside PII; IW only reads from PII Switch to PIW force, or move module into PII

Frequently Asked Questions

Why does TIA Portal show PIW 244 as free but reject it as a start address for an AI8 module?

The Address Overview reports byte-level availability in the peripheral address space, which is independent of the Process Image. A 16-byte AI8 module placed at 244 occupies bytes 244..259. If the OB1 PII is set to 256 bytes, byte 260 is outside the PII and the module is rejected because no S7-300 module may straddle the PII boundary. Increase the PII to 512+ bytes, or move the module to PIW 256.

What is the default process image size for the CPU 319-3 PN/DP?

TIA Portal sets the OB1 process image partition to 256 bytes (input) and 256 bytes (output) on a fresh project. The CPU 319-3 PN/DP supports PII/PIQ up to 2 KB per partition, and the addressable range extends to 16 KB across all partitions. The 256-byte default is per-partition, not per-CPU, and can be changed in the CPU properties.

Can a module outside the PII still be accessed as IW, or only as PIW?

A module outside the PII can only be read via the peripheral access path (PIW for inputs, PQW for outputs). The IW/QW operand area only sees the bytes that are inside the PII. To use IW semantics, the module must be assigned to a PII partition - either OB1 or a cyclic interrupt OB such as OB35.

Does increasing the process image size reduce work memory?

No, it increases work memory by 1 byte per byte of PII. The 200+ AI scenario in this article needs at least 400 bytes of PII; the cost of going from 256 to 512 bytes is 256 bytes of work memory, which is negligible on a CPU 319-3 with 2 MB or 4 MB. The relevant trade-off is OS refresh time, not memory size.

Should 200+ AI channels all be in OB1 PII, or split across OB35?

For motion or fast process control where every AI is read each OB1 cycle, place them all in OB1 PII. For slower process control where AI is sampled at 100-500 ms, place them in an OB35 partition and read them at 100 ms cadence. Direct PIW access for 200 channels in OB1 adds roughly 2 ms to OB1, which is rarely acceptable for sub-10 ms cycles.

Does changing the PII size require a CPU restart?

Yes. TIA Portal applies the new PII size on the next CPU startup. A download of the hardware configuration alone stores the new size in flash but does not resize the work-memory-resident PII until the CPU is stopped and restarted. Schedule the change in a maintenance window or during commissioning.

Are the IM 153-1 (PROFIBUS) and IM 153-4 (PROFINET) addressing rules identical?

Yes. Both implement the S7-300 slot-based module addressing, and the CPU's PII logic does not distinguish between PROFIBUS DP and PROFINET IO. The gap at the 256-byte boundary, the OB1 PII partition, and the module data length rules apply identically to PROFINET IM 153-4 stations (e.g. 6ES7153-4AA01-0XB0).

Back to blog