Resolving S7-300 REAL Overflow to InTouch via IBH OPC Server

David Krause15 min read
SCADA ConfigurationSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Summary

A SIMATIC S7-300 CPU 312C running STEP 7 V5.x is publishing values to a supervisory InTouch application through an IBHsoftec IBH OPC Server (S7-MPI / S7-TCP), with two SIMATIC panels (TP/OP/MP 277 or similar) connected on the same MPI bus. BOOL, INT, and DINT tags transfer correctly. The output of the standard library block FC105 SCALE, which is a 32-bit IEEE 754 REAL, reads correctly on the IBH OPC server browser but appears as the integer sentinel value 32768 (or as the lower-16-bit garbage of the REAL bit pattern) inside InTouch WindowMaker/WindowViewer and on the SIMATIC panel. A raw peripheral word such as PEW 272 continues to display correctly, confirming that the physical reading path and the OPC server are functioning.

The fault is not in the PLC, not in the analog wiring, and not in the OPC server's read engine. It is a consumer-side data-type mismatch: the InTouch tag and the SIMATIC panel variable are configured to consume a 16-bit integer (VT_I2), so the OPC client and the panel HMI each truncate or reinterpret only two of the four bytes that make up a REAL. The fix is to redeclare the consumer-side tag/variable as a 32-bit REAL/float, with the OPC server item bound to a 32-bit DB area (DBD, MD, or LD), and to verify byte ordering against the S7 REAL encoding.

System Architecture and Data Flow

The end-to-end signal chain for a single analog channel is:

  1. Analog input module (e.g., SM 331) presents the raw count in PEW 272 (16-bit INT, ±27648).
  2. The user program copies PEW 272 into a temporary INT and calls FC105 SCALE with the engineering range (HI_LIM, LO_LIM, BIPOLAR).
  3. FC105 writes a 32-bit IEEE 754 REAL to OUT, typically placed in a global data block (e.g., DB100.DBD0) or a bit-memory double word (e.g., MD100).
  4. The IBH OPC server (DA 2.05 / 3.0) reads the 4-byte area DB100.DBD0 over MPI/PROFIBUS and exposes it as an OPC item with native type VT_R4 (4-byte IEEE single precision).
  5. InTouch's OPCLink / DAServer subscribes to that OPC item; the InTouch tag dictionary entry determines how the bytes are interpreted.
  6. SIMATIC panels read the same data block (or a mirrored area) over MPI directly through WinCC flexible / TIA Portal; the panel-side connection and variable configuration determines the displayed value.

The PLC program and the OPC server do not require modification. The misconfiguration sits in steps 5 and 6.

Root Cause Analysis

Two independent but identical misconfigurations cause the 32768 overflow symptom:

Consumer Tag/Variable declaration Bytes delivered Effect
InTouch tag ScaledAI_1 Integer / 16-bit (VT_I2) 4 bytes (REAL) Upper 2 bytes ignored, lower 2 bytes cast as signed INT; common patterns read as 0, ±32768, or random noise.
WinCC flexible variable
ScaledAI_1
INT (16-bit) 4 bytes (REAL) Panel reads only the low word; output wraps to 32767 / -32768 with one-bit LSB toggling.

Because PEW 272 is a true 16-bit value, declaring the matching InTouch tag and panel variable as INT works correctly for that single address. But FC105 produces a 32-bit REAL, and the consumer must be configured to accept 32 bits. Per the official AVEVA InTouch documentation on Specifying integer and real I/O tags, you must assign I/O integer and real tags a set of attributes that characterize the numerical data sent between the InTouch application and external processes; this includes the data type itself (Integer / Real / Discrete / Message), min/max range, and access name. The AVEVA InTouch I/O tag specification guide documents the type attribute choices; selecting Real (32-bit IEEE 754) is mandatory for any scaled analog value.

Confirm the OPC server is healthy first. If you can browse the IBH OPC server and the value displays as the correct scaled number (e.g., 23.7 for a 4-20 mA pressure), the server is working. Capture a screenshot of the IBH OPC browser showing DB100.DBD0 with a numeric value; this is your proof that downstream clients are misconfigured, not the OPC bridge.

IEEE 754 Single-Precision REAL Encoding Reference

The S7-300 stores REAL as a 32-bit IEEE 754 single-precision value in big-endian byte order on the wire (Motorola byte order, most-significant byte at the lowest memory address). This is consistent across STEP 7 V5.x, the IBH OPC server, and WinCC flexible when the address is a double word.

Bit position 31 30 - 23 22 - 0
Field Sign (S) Biased exponent (E + 127) Mantissa (fraction, implicit leading 1)
Value (REAL = 1.0) 0 01111111 000...0
Hex pattern (REAL = 1.0) 0x3F800000

If the IBH OPC server returns the value as VT_R4 and the InTouch tag is declared as Integer (VT_I2), the OPC client reads bytes 0 and 1 (the high word, 0x3F80 for the value 1.0) and discards bytes 2 and 3. Cast to signed 16-bit integer, 0x3F80 = 16256. The same mechanism produces 32767 / -32768 / 32768 type overflow readouts whenever the upper word of the REAL is close to 0x8000 (i.e., negative or near-zero values). This is the entire root cause; it is not a bug in FC105, the IBH OPC server, or the panel.

FC105 SCALE Block — Output Type and Memory Layout

The standard library block FC105 SCALE is shipped in the Standard Library > TI-S7 Converting Blocks project in STEP 7 V5.x. Its interface is fixed and must be respected when sizing the destination memory area:

Parameter Declaration Data type Width (bytes) Description
IN INPUT INT 2 Raw input value (e.g., PEW 272)
HI_LIM INPUT REAL 4 Engineering high limit
LO_LIM INPUT REAL 4 Engineering low limit
BIPOLAR INPUT BOOL 1 1 = bipolar (±27648), 0 = unipolar (0..27648)
RET_VAL OUTPUT WORD 2 Error word (W#16#0000 = OK)
OUT OUTPUT REAL 4 Engineering-scaled result

The OUT parameter is strictly a 32-bit REAL. When wiring OUT to a DB, you must use a double-word absolute address, not a word address:

  • Correct: DB100.DBD0 (double word at byte 0 of DB100), or an MD, LD, or DBD symbolic tag of type REAL.
  • Wrong: DB100.DBW0, DB100.DBW2, or DB100.DBB0. These are 1- or 2-byte areas that will alias only part of the REAL bit pattern.

If the destination in STEP 7 is declared as a symbolic tag of type REAL, the IBH OPC server will automatically size the item to 4 bytes. If you typed the destination as INT by mistake, STEP 7 will accept the connection with a width warning and produce 2-byte writes, which the OPC server will then re-broadcast as a 16-bit value; this is an alternative root cause that is also resolved by the steps below.

OPC DA Data Type Mapping for S7 REAL

The IBH OPC server maps STEP 7 data types to OPC DA 2.05/3.0 VARIANT types. The mapping relevant to scaled analog values is:

STEP 7 area OPC DA VARIANT type Bytes Engineer-visible type
PEW / DBW / MW / IW (INT) VT_I2 2 Signed 16-bit
PED / DBD / MD / ID (DINT) VT_I4 4 Signed 32-bit
PED / DBD / MD / ID (REAL) VT_R4 4 IEEE 754 single precision
DBX / M / I / Q (BOOL) VT_BOOL 1 Boolean

Note that DINT and REAL share the same memory width (4 bytes) and address syntax (DBD / MD / PED). The OPC server disambiguates by the declared symbolic type or by the operator's explicit selection in the IBH OPC item editor. If you created the item using a wizard that defaulted to DINT for any 4-byte address, the OPC server will hand the bytes back to InTouch as a signed 32-bit integer; the resulting integer will be on the order of 1,065,353,216 for a REAL of 23.7, which also looks like garbage. Pick REAL explicitly in the IBH OPC item dialog.

Fix 1 — InTouch Access Name and Tag Configuration

  1. Open InTouch WindowMaker. In the Special menu, select Access Names.
  2. Confirm an access name exists that points to the IBH OPC server application, typically IBH.IBHOPCServer or IBHOPC.IBHOPCServer. The Node should be either localhost (if OPCLink/DAServer runs on the same machine as the IBH OPC server) or the remote IP address of the OPC server machine. Set Application Name to the exact registered ProgID of the IBH server; do not type it differently from what the IBH OPC server's About dialog reports.
  3. Open the Tagname Dictionary and create or edit the tag that maps to FC105.OUT. Choose a meaningful name such as PT_101_EU.
  4. Set Type = Real (not Integer, not Discrete). The Min/Max fields default to 0; for a 0-100 °C loop set them to 0 and 100, or to the engineering limits of your transmitter.
  5. Set Access Name to the IBH OPC access name from step 2.
  6. Set Item Name to the exact OPC item path reported by the IBH OPC browser. For an S7 data block this is typically DB100.DBD0 or the symbolic name (e.g., S7:DB100.REAL0) — copy it from the browser to avoid typos.
  7. Save the dictionary. Run a Tools > Cross Reference to make sure no animation in any window is referencing the tag as an Integer; if any are, change them to use the Real tag and adjust format strings accordingly.
InTouch Real tags are 32-bit IEEE 754 single precision (4 bytes). There is no separate Double type in classic InTouch; for S7 LREAL (64-bit double), use a custom OPC bridge or upgrade to Application Server / InTouch OMI.

Fix 2 — IBH OPC Server Item Definition

  1. Launch the IBH OPC Server configuration utility (typically IBH OPC Server.exe or S7-OPC Config).
  2. In the project tree, select the S7-300 station and the connection (MPI or TCP).
  3. Navigate to the data block that contains FC105.OUT (for example, DB 100).
  4. Insert a new item with address DB100.DBD0 (or the symbolic name). In the Data Type dropdown select REAL (4 bytes). If the dropdown is grayed-out, switch the source definition from Absolute to Symbolic and import the DB symbols from the STEP 7 project; the type is then locked to REAL.
  5. Repeat for any other REAL outputs (FC105 OUT into additional DBs, plus any FC106, scaling loops, or PID controller outputs).
  6. Right-click the connection and Apply / Restart. The OPC server caches the project; restart is required for type changes to take effect for active subscriptions.
  7. Verify with the OPC server's built-in browser. The value column should display a real number with decimal fraction (e.g., 23.748), not an integer. If the browser shows an integer, the item is still bound as INT/DINT; redo step 4.

Fix 3 — SIMATIC Panel Variable Configuration

WinCC flexible (2008 SP5 and earlier) and TIA Portal (WinCC Comfort/Advanced) treat REAL as a 32-bit floating-point tag. The configuration steps below apply to both; menu paths differ by tool.

  1. Open the project for the affected panel.
  2. In the project tree, open Communication > Connections and verify the panel-side MPI / PROFIBUS connection. The Partner must be the S7-300 CPU 312C and the Partner Address the same MPI station number as configured in STEP 7's hardware configuration (default 2).
  3. Open Tags > SIMATIC S7-300/400 Tags (WinCC flexible) or PLC Tags (TIA). Locate the tag that should display the scaled value (e.g., PT_101_EU).
  4. Set Data type = Real. The length should auto-fill to 4 bytes. The address must be the same 4-byte area used by FC105's OUT, for example DB 100 DBD 0.
  5. On the screen object (I/O field, bar graph, trend), open Properties > General and confirm the process value reference points to the Real tag. Set the I/O field's Output Format to a decimal string such as 999.9 to render the fractional part.
  6. Compile and download to the panel. On the panel, the value should now match STEP 7 and the IBH OPC browser.
Byte order trap. S7 panels always read REAL in big-endian (Motorola) byte order over MPI/PROFIBUS. Do not swap bytes in STEP 7 to "fix" endianness — that will corrupt the REAL for both InTouch and the panel. If a value reads correctly in STEP 7 but is wildly negative on the panel, the connection address is wrong (e.g., pointing into the next variable's area), not the byte order.

MPI Bus and Address Sanity Checks

Although the primary fault is consumer-side, MPI misconfiguration can hide the diagnosis. Confirm the following before declaring the fix complete:

Setting CPU 312C default IBH OPC Server SIMATIC Panel
MPI address 2 0 (master) or 1 (master) 1 (default), 2, 3, … unique
Baud rate 187.5 kbps (default) or 19.2 kbps on older panels Match CPU Match CPU and OPC server
Highest MPI address (HSA) 31 Match bus master n/a
Bus terminator Enabled on first and last physical node n/a Enabled on last physical node

If the IBH OPC server and the panel share the bus, they must use distinct MPI addresses. A common error is leaving the panel at address 1 and the OPC server at address 1 — both default values collide; the bus token will bounce and the OPC subscription will intermittently fall back to old cached values (which can resemble a stuck 32768).

Verification Procedure and Field Tests

  1. Force FC105.IN (the input INT) to 27648 in STEP 7 (or use VAT/Variable Table online monitor). Confirm FC105.OUT reads exactly HI_LIM.
  2. Force FC105.IN to 0. Confirm FC105.OUT reads exactly LO_LIM.
  3. Force FC105.IN to 13824. Confirm FC105.OUT reads (HI_LIM + LO_LIM) / 2 within rounding tolerance.
  4. In the IBH OPC server browser, subscribe to the FC105 output item and verify the same three engineering values appear.
  5. In InTouch WindowViewer, animate a value display bound to the Real tag. Verify the three values match the IBH OPC browser and that the field updates within one polling cycle (default 250 ms for OPCLink).
  6. On the SIMATIC panel, navigate to the I/O field bound to the Real tag. Verify the same three values appear. Cycle power on the panel once to confirm the value is read on each startup, not a startup-stuck integer.
  7. Generate a step change in the raw input (e.g., simulate an open-circuit on the 4-20 mA loop with a calibrator). Confirm the REAL and the panel track the change smoothly, without the 32768 sentinel reappearing.

Troubleshooting Matrix

Observed value Where observed Likely cause Fix
32768 (or -32768) InTouch, Panel Tag declared as INT, REAL read as 16-bit Change tag/variable type to Real (32-bit)
1,065,353,216 (~1.07e9) InTouch, Panel Tag declared as DINT, REAL bits interpreted as signed 32-bit Change tag/variable type to Real
0 always InTouch Item name points to the low word of a DBD; lower 2 bytes happen to be zero for the current value Correct the IBH OPC item to the proper DBD address
Correct value in STEP 7, correct in IBH OPC browser, wrong in InTouch only InTouch InTouch tag is Integer or DINT Reconfigure the tag type (Fix 1)
Correct value in STEP 7, wrong in IBH OPC browser IBH OPC server Item type in IBH OPC server is INT/DINT, or address is a DBW Change to REAL and use DBD address (Fix 2)
Correct value on InTouch, wrong on panel Panel Panel variable type is INT Set panel variable to Real (Fix 3)
Correct on InTouch and panel, but with low-resolution decimal Both I/O field Output Format string truncated Adjust the format string (e.g., 999.99)

Commissioning Checklist and Common Pitfalls

  • Always declare FC105 OUT destinations as a symbolic tag of type REAL in a DB; never as INT.
  • Use 4-byte DBD / MD / LD areas exclusively for any REAL tag, both in STEP 7 and in the OPC item.
  • Configure IBH OPC server items as REAL, not DINT, even though both share 4 bytes — the type selector disambiguates wire format.
  • Configure every InTouch access name with the exact ProgID of the OPC server; mismatched case is the most common cause of "no items visible".
  • Configure every SIMATIC panel variable bound to a scaled value as Real, with the I/O field Output Format set to a decimal pattern.
  • Avoid pulling a REAL into a S7 BOOL array, MERGE bits into a BKW, or other 2-byte workarounds — they all break the 4-byte REAL invariant.
  • If the project later migrates to TIA Portal and an S7-1200/1500, replace FC105 with the modern SCALE / NORM_X + SCALE_X instructions and use LREAL (64-bit) on the HMI side, with the corresponding OPC item type declared as Double (VT_R8).

FAQ

Why does InTouch show exactly 32768 for FC105's REAL output?

The InTouch tag is configured as a 16-bit Integer (VT_I2), so the OPC client reads only the upper 2 bytes of the 4-byte IEEE 754 REAL. For values whose upper word is close to 0x8000 (negative numbers, signed-zero, or values near the engineering limit), the casted 16-bit signed integer sits at +32767 or -32768. Reconfigure the InTouch tag as Real (32-bit float) to consume all 4 bytes.

Is the IBH OPC server at fault when InTouch reads a wrong scaled value?

No. The IBH OPC server reports the FC105 output correctly as VT_R4 in its built-in browser. The mismatch is downstream: the InTouch access name or tag type is wrong, the SIMATIC panel variable is declared as INT, or the OPC item is bound to a DBW (2 bytes) instead of a DBD (4 bytes). Always verify the value inside the OPC browser before reconfiguring the consumer.

Can I use a S7 INT (16-bit) tag in InTouch to read a scaled analog value?

Only if the scaled value never exceeds the 16-bit signed integer range (±32767). FC105 outputs a REAL by design; if you must stay with INT, pre-multiply the engineering range into a 16-bit integer in STEP 7 and document the scaling factor in the tag comment. The recommended practice is to keep the REAL and configure the HMI for 32-bit float.

Does FC105 work with S7-1200 and S7-1500 controllers?

No. FC105 is part of the STEP 7 V5.x Standard Library for S7-300/400 only. On S7-1200/1500, use the NORM_X and SCALE_X instructions, which produce LREAL (64-bit) output. Configure the OPC item type as Double (VT_R8) and the HMI tag as Double (64-bit float) accordingly.

How do I confirm the OPC item is truly bound as REAL and not as DINT?

In the IBH OPC server configuration, edit the item and inspect the Data Type dropdown — it must read REAL. Both REAL and DINT use a 4-byte DBD address, so the address alone does not disambiguate. Confirm by forcing a known FC105.IN value (e.g., 13824) and checking the browser: the OPC server must display a fractional engineering value, not a 32-bit integer like 0x42C94000 (= 1,121,599,488 as DINT).

Back to blog