Problem Summary
A SIMATIC S7-300 CPU 312C running STEP 7 V5.x is publishing values to a supervisory InTouch application through an IBHsoftec IBH OPC Server (S7-MPI / S7-TCP), with two SIMATIC panels (TP/OP/MP 277 or similar) connected on the same MPI bus. BOOL, INT, and DINT tags transfer correctly. The output of the standard library block FC105 SCALE, which is a 32-bit IEEE 754 REAL, reads correctly on the IBH OPC server browser but appears as the integer sentinel value 32768 (or as the lower-16-bit garbage of the REAL bit pattern) inside InTouch WindowMaker/WindowViewer and on the SIMATIC panel. A raw peripheral word such as PEW 272 continues to display correctly, confirming that the physical reading path and the OPC server are functioning.
The fault is not in the PLC, not in the analog wiring, and not in the OPC server's read engine. It is a consumer-side data-type mismatch: the InTouch tag and the SIMATIC panel variable are configured to consume a 16-bit integer (VT_I2), so the OPC client and the panel HMI each truncate or reinterpret only two of the four bytes that make up a REAL. The fix is to redeclare the consumer-side tag/variable as a 32-bit REAL/float, with the OPC server item bound to a 32-bit DB area (DBD, MD, or LD), and to verify byte ordering against the S7 REAL encoding.
System Architecture and Data Flow
The end-to-end signal chain for a single analog channel is:
- Analog input module (e.g., SM 331) presents the raw count in
PEW 272(16-bit INT, ±27648). - The user program copies
PEW 272into a temporary INT and callsFC105 SCALEwith the engineering range (HI_LIM,LO_LIM,BIPOLAR). -
FC105writes a 32-bit IEEE 754 REAL toOUT, typically placed in a global data block (e.g.,DB100.DBD0) or a bit-memory double word (e.g.,MD100). - The IBH OPC server (DA 2.05 / 3.0) reads the 4-byte area
DB100.DBD0over MPI/PROFIBUS and exposes it as an OPC item with native typeVT_R4(4-byte IEEE single precision). - InTouch's OPCLink / DAServer subscribes to that OPC item; the InTouch tag dictionary entry determines how the bytes are interpreted.
- SIMATIC panels read the same data block (or a mirrored area) over MPI directly through WinCC flexible / TIA Portal; the panel-side connection and variable configuration determines the displayed value.
The PLC program and the OPC server do not require modification. The misconfiguration sits in steps 5 and 6.
Root Cause Analysis
Two independent but identical misconfigurations cause the 32768 overflow symptom:
| Consumer | Tag/Variable declaration | Bytes delivered | Effect |
|---|---|---|---|
InTouch tag ScaledAI_1
|
Integer / 16-bit (VT_I2) | 4 bytes (REAL) | Upper 2 bytes ignored, lower 2 bytes cast as signed INT; common patterns read as 0, ±32768, or random noise. |
WinCC flexible variable
|
INT (16-bit) | 4 bytes (REAL) | Panel reads only the low word; output wraps to 32767 / -32768 with one-bit LSB toggling. |
Because PEW 272 is a true 16-bit value, declaring the matching InTouch tag and panel variable as INT works correctly for that single address. But FC105 produces a 32-bit REAL, and the consumer must be configured to accept 32 bits. Per the official AVEVA InTouch documentation on Specifying integer and real I/O tags, you must assign I/O integer and real tags a set of attributes that characterize the numerical data sent between the InTouch application and external processes; this includes the data type itself (Integer / Real / Discrete / Message), min/max range, and access name. The AVEVA InTouch I/O tag specification guide documents the type attribute choices; selecting Real (32-bit IEEE 754) is mandatory for any scaled analog value.
DB100.DBD0 with a numeric value; this is your proof that downstream clients are misconfigured, not the OPC bridge.IEEE 754 Single-Precision REAL Encoding Reference
The S7-300 stores REAL as a 32-bit IEEE 754 single-precision value in big-endian byte order on the wire (Motorola byte order, most-significant byte at the lowest memory address). This is consistent across STEP 7 V5.x, the IBH OPC server, and WinCC flexible when the address is a double word.
| Bit position | 31 | 30 - 23 | 22 - 0 |
|---|---|---|---|
| Field | Sign (S) | Biased exponent (E + 127) | Mantissa (fraction, implicit leading 1) |
| Value (REAL = 1.0) | 0 | 01111111 | 000...0 |
| Hex pattern (REAL = 1.0) | 0x3F800000 | ||
If the IBH OPC server returns the value as VT_R4 and the InTouch tag is declared as Integer (VT_I2), the OPC client reads bytes 0 and 1 (the high word, 0x3F80 for the value 1.0) and discards bytes 2 and 3. Cast to signed 16-bit integer, 0x3F80 = 16256. The same mechanism produces 32767 / -32768 / 32768 type overflow readouts whenever the upper word of the REAL is close to 0x8000 (i.e., negative or near-zero values). This is the entire root cause; it is not a bug in FC105, the IBH OPC server, or the panel.
FC105 SCALE Block — Output Type and Memory Layout
The standard library block FC105 SCALE is shipped in the Standard Library > TI-S7 Converting Blocks project in STEP 7 V5.x. Its interface is fixed and must be respected when sizing the destination memory area:
| Parameter | Declaration | Data type | Width (bytes) | Description |
|---|---|---|---|---|
| IN | INPUT | INT | 2 | Raw input value (e.g., PEW 272) |
| HI_LIM | INPUT | REAL | 4 | Engineering high limit |
| LO_LIM | INPUT | REAL | 4 | Engineering low limit |
| BIPOLAR | INPUT | BOOL | 1 | 1 = bipolar (±27648), 0 = unipolar (0..27648) |
| RET_VAL | OUTPUT | WORD | 2 | Error word (W#16#0000 = OK) |
| OUT | OUTPUT | REAL | 4 | Engineering-scaled result |
The OUT parameter is strictly a 32-bit REAL. When wiring OUT to a DB, you must use a double-word absolute address, not a word address:
-
Correct:
DB100.DBD0(double word at byte 0 of DB100), or anMD,LD, orDBDsymbolic tag of type REAL. -
Wrong:
DB100.DBW0,DB100.DBW2, orDB100.DBB0. These are 1- or 2-byte areas that will alias only part of the REAL bit pattern.
If the destination in STEP 7 is declared as a symbolic tag of type REAL, the IBH OPC server will automatically size the item to 4 bytes. If you typed the destination as INT by mistake, STEP 7 will accept the connection with a width warning and produce 2-byte writes, which the OPC server will then re-broadcast as a 16-bit value; this is an alternative root cause that is also resolved by the steps below.
OPC DA Data Type Mapping for S7 REAL
The IBH OPC server maps STEP 7 data types to OPC DA 2.05/3.0 VARIANT types. The mapping relevant to scaled analog values is:
| STEP 7 area | OPC DA VARIANT type | Bytes | Engineer-visible type |
|---|---|---|---|
| PEW / DBW / MW / IW (INT) | VT_I2 | 2 | Signed 16-bit |
| PED / DBD / MD / ID (DINT) | VT_I4 | 4 | Signed 32-bit |
| PED / DBD / MD / ID (REAL) | VT_R4 | 4 | IEEE 754 single precision |
| DBX / M / I / Q (BOOL) | VT_BOOL | 1 | Boolean |
Note that DINT and REAL share the same memory width (4 bytes) and address syntax (DBD / MD / PED). The OPC server disambiguates by the declared symbolic type or by the operator's explicit selection in the IBH OPC item editor. If you created the item using a wizard that defaulted to DINT for any 4-byte address, the OPC server will hand the bytes back to InTouch as a signed 32-bit integer; the resulting integer will be on the order of 1,065,353,216 for a REAL of 23.7, which also looks like garbage. Pick REAL explicitly in the IBH OPC item dialog.
Fix 1 — InTouch Access Name and Tag Configuration
- Open InTouch WindowMaker. In the Special menu, select Access Names.
- Confirm an access name exists that points to the IBH OPC server application, typically
IBH.IBHOPCServerorIBHOPC.IBHOPCServer. The Node should be eitherlocalhost(if OPCLink/DAServer runs on the same machine as the IBH OPC server) or the remote IP address of the OPC server machine. Set Application Name to the exact registered ProgID of the IBH server; do not type it differently from what the IBH OPC server's About dialog reports. - Open the Tagname Dictionary and create or edit the tag that maps to
FC105.OUT. Choose a meaningful name such asPT_101_EU. - Set Type = Real (not Integer, not Discrete). The Min/Max fields default to
0; for a 0-100 °C loop set them to0and100, or to the engineering limits of your transmitter. - Set Access Name to the IBH OPC access name from step 2.
- Set Item Name to the exact OPC item path reported by the IBH OPC browser. For an S7 data block this is typically
DB100.DBD0or the symbolic name (e.g.,S7:DB100.REAL0) — copy it from the browser to avoid typos. - Save the dictionary. Run a Tools > Cross Reference to make sure no animation in any window is referencing the tag as an Integer; if any are, change them to use the Real tag and adjust format strings accordingly.
Fix 2 — IBH OPC Server Item Definition
- Launch the IBH OPC Server configuration utility (typically
IBH OPC Server.exeor S7-OPC Config). - In the project tree, select the S7-300 station and the connection (MPI or TCP).
- Navigate to the data block that contains
FC105.OUT(for example,DB 100). - Insert a new item with address
DB100.DBD0(or the symbolic name). In the Data Type dropdown select REAL (4 bytes). If the dropdown is grayed-out, switch the source definition from Absolute to Symbolic and import the DB symbols from the STEP 7 project; the type is then locked to REAL. - Repeat for any other REAL outputs (FC105 OUT into additional DBs, plus any FC106, scaling loops, or PID controller outputs).
- Right-click the connection and Apply / Restart. The OPC server caches the project; restart is required for type changes to take effect for active subscriptions.
- Verify with the OPC server's built-in browser. The value column should display a real number with decimal fraction (e.g.,
23.748), not an integer. If the browser shows an integer, the item is still bound as INT/DINT; redo step 4.
Fix 3 — SIMATIC Panel Variable Configuration
WinCC flexible (2008 SP5 and earlier) and TIA Portal (WinCC Comfort/Advanced) treat REAL as a 32-bit floating-point tag. The configuration steps below apply to both; menu paths differ by tool.
- Open the project for the affected panel.
- In the project tree, open Communication > Connections and verify the panel-side MPI / PROFIBUS connection. The Partner must be the S7-300 CPU 312C and the Partner Address the same MPI station number as configured in STEP 7's hardware configuration (default 2).
- Open Tags > SIMATIC S7-300/400 Tags (WinCC flexible) or PLC Tags (TIA). Locate the tag that should display the scaled value (e.g.,
PT_101_EU). - Set Data type = Real. The length should auto-fill to 4 bytes. The address must be the same 4-byte area used by FC105's
OUT, for exampleDB 100 DBD 0. - On the screen object (I/O field, bar graph, trend), open Properties > General and confirm the process value reference points to the Real tag. Set the I/O field's Output Format to a decimal string such as
999.9to render the fractional part. - Compile and download to the panel. On the panel, the value should now match STEP 7 and the IBH OPC browser.
MPI Bus and Address Sanity Checks
Although the primary fault is consumer-side, MPI misconfiguration can hide the diagnosis. Confirm the following before declaring the fix complete:
| Setting | CPU 312C default | IBH OPC Server | SIMATIC Panel |
|---|---|---|---|
| MPI address | 2 | 0 (master) or 1 (master) | 1 (default), 2, 3, … unique |
| Baud rate | 187.5 kbps (default) or 19.2 kbps on older panels | Match CPU | Match CPU and OPC server |
| Highest MPI address (HSA) | 31 | Match bus master | n/a |
| Bus terminator | Enabled on first and last physical node | n/a | Enabled on last physical node |
If the IBH OPC server and the panel share the bus, they must use distinct MPI addresses. A common error is leaving the panel at address 1 and the OPC server at address 1 — both default values collide; the bus token will bounce and the OPC subscription will intermittently fall back to old cached values (which can resemble a stuck 32768).
Verification Procedure and Field Tests
- Force
FC105.IN(the input INT) to27648in STEP 7 (or use VAT/Variable Table online monitor). ConfirmFC105.OUTreads exactlyHI_LIM. - Force
FC105.INto0. ConfirmFC105.OUTreads exactlyLO_LIM. - Force
FC105.INto13824. ConfirmFC105.OUTreads(HI_LIM + LO_LIM) / 2within rounding tolerance. - In the IBH OPC server browser, subscribe to the FC105 output item and verify the same three engineering values appear.
- In InTouch WindowViewer, animate a value display bound to the Real tag. Verify the three values match the IBH OPC browser and that the field updates within one polling cycle (default 250 ms for OPCLink).
- On the SIMATIC panel, navigate to the I/O field bound to the Real tag. Verify the same three values appear. Cycle power on the panel once to confirm the value is read on each startup, not a startup-stuck integer.
- Generate a step change in the raw input (e.g., simulate an open-circuit on the 4-20 mA loop with a calibrator). Confirm the REAL and the panel track the change smoothly, without the 32768 sentinel reappearing.
Troubleshooting Matrix
| Observed value | Where observed | Likely cause | Fix |
|---|---|---|---|
| 32768 (or -32768) | InTouch, Panel | Tag declared as INT, REAL read as 16-bit | Change tag/variable type to Real (32-bit) |
| 1,065,353,216 (~1.07e9) | InTouch, Panel | Tag declared as DINT, REAL bits interpreted as signed 32-bit | Change tag/variable type to Real |
| 0 always | InTouch | Item name points to the low word of a DBD; lower 2 bytes happen to be zero for the current value | Correct the IBH OPC item to the proper DBD address |
| Correct value in STEP 7, correct in IBH OPC browser, wrong in InTouch only | InTouch | InTouch tag is Integer or DINT | Reconfigure the tag type (Fix 1) |
| Correct value in STEP 7, wrong in IBH OPC browser | IBH OPC server | Item type in IBH OPC server is INT/DINT, or address is a DBW | Change to REAL and use DBD address (Fix 2) |
| Correct value on InTouch, wrong on panel | Panel | Panel variable type is INT | Set panel variable to Real (Fix 3) |
| Correct on InTouch and panel, but with low-resolution decimal | Both | I/O field Output Format string truncated | Adjust the format string (e.g., 999.99) |
Commissioning Checklist and Common Pitfalls
- Always declare FC105 OUT destinations as a symbolic tag of type REAL in a DB; never as INT.
- Use 4-byte DBD / MD / LD areas exclusively for any REAL tag, both in STEP 7 and in the OPC item.
- Configure IBH OPC server items as REAL, not DINT, even though both share 4 bytes — the type selector disambiguates wire format.
- Configure every InTouch access name with the exact ProgID of the OPC server; mismatched case is the most common cause of "no items visible".
- Configure every SIMATIC panel variable bound to a scaled value as Real, with the I/O field Output Format set to a decimal pattern.
- Avoid pulling a REAL into a S7 BOOL array, MERGE bits into a BKW, or other 2-byte workarounds — they all break the 4-byte REAL invariant.
- If the project later migrates to TIA Portal and an S7-1200/1500, replace FC105 with the modern
SCALE/NORM_X+SCALE_Xinstructions and use LREAL (64-bit) on the HMI side, with the corresponding OPC item type declared as Double (VT_R8).
FAQ
Why does InTouch show exactly 32768 for FC105's REAL output?
The InTouch tag is configured as a 16-bit Integer (VT_I2), so the OPC client reads only the upper 2 bytes of the 4-byte IEEE 754 REAL. For values whose upper word is close to 0x8000 (negative numbers, signed-zero, or values near the engineering limit), the casted 16-bit signed integer sits at +32767 or -32768. Reconfigure the InTouch tag as Real (32-bit float) to consume all 4 bytes.
Is the IBH OPC server at fault when InTouch reads a wrong scaled value?
No. The IBH OPC server reports the FC105 output correctly as VT_R4 in its built-in browser. The mismatch is downstream: the InTouch access name or tag type is wrong, the SIMATIC panel variable is declared as INT, or the OPC item is bound to a DBW (2 bytes) instead of a DBD (4 bytes). Always verify the value inside the OPC browser before reconfiguring the consumer.
Can I use a S7 INT (16-bit) tag in InTouch to read a scaled analog value?
Only if the scaled value never exceeds the 16-bit signed integer range (±32767). FC105 outputs a REAL by design; if you must stay with INT, pre-multiply the engineering range into a 16-bit integer in STEP 7 and document the scaling factor in the tag comment. The recommended practice is to keep the REAL and configure the HMI for 32-bit float.
Does FC105 work with S7-1200 and S7-1500 controllers?
No. FC105 is part of the STEP 7 V5.x Standard Library for S7-300/400 only. On S7-1200/1500, use the NORM_X and SCALE_X instructions, which produce LREAL (64-bit) output. Configure the OPC item type as Double (VT_R8) and the HMI tag as Double (64-bit float) accordingly.
How do I confirm the OPC item is truly bound as REAL and not as DINT?
In the IBH OPC server configuration, edit the item and inspect the Data Type dropdown — it must read REAL. Both REAL and DINT use a 4-byte DBD address, so the address alone does not disambiguate. Confirm by forcing a known FC105.IN value (e.g., 13824) and checking the browser: the OPC server must display a fractional engineering value, not a 32-bit integer like 0x42C94000 (= 1,121,599,488 as DINT).