Resolving SM 1231 6ES7 231-4HF32 4-20 mA Wiring Errors

David Krause17 min read
S7-1200SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving SM 1231 6ES7 231-4HF32 4-20 mA Wiring and Scaling Errors on S7-1200

When the SM 1231 analog input module (6ES7 231-4HF32-0XB0) returns drifting, jumping, or non-deterministic values for a 4-20 mA source, the root cause is almost always a hardware/wiring mistake, an unterminated current loop, channel configured as voltage instead of current, or misuse of the discrete-signal simulator module (6ES7 274-1XH30-0XA0). This reference walks through module specifications, current-loop wiring, TIA Portal configuration, NORM_X and SCALE_X scaling, and verification steps that resolve the typical "my tags change automatically when I connect 4-20 mA" symptom on S7-1200 systems connected to a KTP 700 Basic panel.

1. Problem Description and Symptoms

The reported behavior — NORM_X / SCALE_X outputs drifting, jumping, or changing without corresponding changes at the test source — has a small set of root causes on a properly installed SM 1231. The most common, in order of frequency:

  1. Current loop is open or floating (only one wire landed, return path missing).
  2. The 6ES7 274-1XH30-0XA0 input simulator is being used in place of an actual 4-20 mA source.
  3. Channel is configured for voltage (±10 V / 0-10 V) instead of current (0-20 mA / 4-20 mA) in the device configuration.
  4. Wiring polarity reversed or shield not terminated at the panel.
  5. Field device is unpowered but the AI channel is left enabled, leaving the ADC input floating.
  6. HMI tag bound to the raw %IW rather than the SCALE_X output.
  7. Shared analog ground between channels causing cross-talk when sensor is unpowered.

The tag pipeline in a typical TIA Portal project is: physical current → SM 1231 ADC raw value (0–27648) → NORM_X (REAL 0.0–1.0) → SCALE_X (REAL engineering range) → KTP 700 Basic HMI tag. Any break or misconfiguration anywhere in that chain causes the HMI to display arbitrary or drifting values even when the field wiring "looks correct."

2. SM 1231 Module Identification and Specifications

The module order number 6ES7 231-4HF32-0XB0 is the SM 1231 analog input with the ratings below. Always verify the printed MLFB on the front label matches the configuration in TIA Portal, as several variants share the same housing. Refer to the SIMATIC S7-1200 Programmable Controller System Manual on Siemens Industry Online Support for the binding specification of your firmware revision.

Parameter Value
Order number (MLFB) 6ES7 231-4HF32-0XB0
Function SM 1231 Analog Input, 8 AI
Channels 8 single-ended or 4 differential (software configurable)
Resolution 12 bits + sign (13 bits effective)
Voltage ranges ±10 V, ±5 V, ±2.5 V, 0–10 V
Current ranges 0–20 mA, 4–20 mA
Nominal raw range for 4–20 mA 0 = 4 mA; 27648 = 20 mA; wire-break threshold ≈ 3.6 mA
Nominal raw range for 0–20 mA 0 = 0 mA; 27648 = 20 mA
Input impedance, current mode ≤ 250 Ω (active current input)
Input impedance, voltage mode ≥ 1 MΩ
Common-mode voltage Max 12 V DC between channels and to chassis ground
Integration time / mains rejection 1.7 ms / 6.6 ms / 10 ms / 16.6 ms / 20 ms (60 Hz / 50 Hz selection)
Backplane current consumption 80 mA from S7-1200 backplane
Sensor supply (24 V DC) 20.4–28.8 V DC; 60 mA per channel max
Galvanic isolation 500 V AC between field side and backplane

The module exposes two 12-pin connector rows behind the front door. Channel 0 (AI0+/AI0-) lands on terminals 2 and 3, channel 1 on 4 and 5, channel 2 on 6 and 7, channel 3 on 8 and 9. Single-ended inputs share a common return on terminals 1 (M0) and 11 (M1). Refer to the wiring label inside the door of your specific build for exact assignments.

3. Why the 6ES7 274-1XH30-0XA0 Simulator Cannot Replace a 4-20 mA Source

The 6ES7 274-1XH30-0XA0 is the SIMATIC S7-1200 Input Simulator. It is a passive switch bank with 14 toggle switches that mechanically inject either 24 V or 0 V into the 14 discrete inputs of the S7-1200 CPU. It plugs into the CPU's front connector and replaces field wiring for digital inputs only. It has no current source, no D/A converter, and no electrical connection to the SM 1231 analog module.

The 6ES7 274-1XH30-0XA0 cannot generate 4-20 mA. Using it to "simulate" a pressure transmitter into AI0 will leave the SM 1231 input floating or shorted to the CPU's 24 V rail, which is why the HMI tag appears to drift or jump when the simulator is connected. To commission a 4-20 mA input you need a true mA source, not a discrete simulator.

To inject a known 4-20 mA into the SM 1231, use one of:

  • Loop calibrator — preferred for commissioning because it sources and reads simultaneously. Examples: Beamex MC6, Druck/GE DPI 620, Fluke 754, Yokogawa CA150.
  • Handheld mA source — sources 4-20 mA only, cheaper than full calibrator. Examples: Fluke 787 ProcessMeter, Martel MC-1000.
  • Bench power supply with 250 Ω resistor — set 1–5 V across the resistor to drive 4–20 mA. Less accurate, suitable only for trend verification.
  • Spare transmitter — wire a known-good 4-20 mA transmitter into the same loop; varies with applied stimulus.
  • HART communicator — for HART-capable devices, set the transmitter to a fixed loop current for diagnostics.

4. 4-20 mA Hardware Wiring on the SM 1231

The SM 1231 4HF32 supports 2-wire (loop-powered) and 4-wire (self-powered) field devices. The wiring difference matters because the input is internally referenced; connecting a floating source or reversing polarity produces wild raw counts.

4.1 2-Wire (Loop-Powered) Transmitter Wiring

The most common industrial wiring. The transmitter receives 24 V from the panel's sensor supply and uses the same pair to send 4-20 mA back to the SM 1231.

2-Wire 4-20 mA Transmitter to SM 1231 AI0 24V Sensor Supply (PSU) L+ / M 2-Wire Tx Pressure / Level 4-20 mA loop-powered SM 1231 AI0 Terminal 2 (AI0+) Terminal 3 (AI0-) — config = 4-20 mA 24V+ to AI0+ (T2) 24V- / M to AI0- / M (T3 / T1) Loop current returns through panel 24V common — must be bonded to SM 1231 M terminal

4.2 4-Wire (Self-Powered) mA Source Wiring

The calibrator has its own 24 V supply and only the 4-20 mA signal pair connects to the SM 1231. This is the configuration to use when troubleshooting with a bench calibrator.

4-Wire mA Source (Loop Calibrator) to SM 1231 AI0 mA Source / Calibrator mA+ / mA- terminals Set: 4.00 / 12.00 / 20.00 mA Self-powered, isolated SM 1231 AI0 AI0+ → T2 AI0- → T3 (M) Config = 4-20 mA, single-ended mA+ mA- / return Calibrator mA- must tie to SM 1231 M terminal on the same 0V reference
For 4-20 mA on the SM 1231, the field return must land on the channel's M terminal (terminal 1 or 11 on the bottom row). Leaving the return floating causes the ADC to drift across the full input range as the input floats to common-mode potential. This is the single most common cause of "tag changes by itself."

4.3 Shielding and Grounding

  • Use shielded twisted pair (Belden 8760, 8761, or equivalent) for all analog runs.
  • Ground the shield at the panel end only, on the same ground bar as the SM 1231 24 V common (M).
  • Do not ground the shield at the field device end — differential grounds inject 50/60 Hz hum.
  • Keep analog runs in separate conduit at least 200 mm (8 in) from VFD output cables and any AC ≥ 230 V.
  • Bond panel 24 V common to protective earth (PE) at one point only — typically the PSU input side.

5. TIA Portal Hardware Configuration

Open the device configuration of the SM 1231 in TIA Portal. The default channel type after insertion is "Voltage ±10 V." You must explicitly change every channel you are using as current.

  1. Project tree → Devices & Networks → select the S7-1200 CPU → slot 101 (or the actual slot the SM 1231 occupies).
  2. Open the module's Properties → "Analog inputs" section.
  3. For each channel you wire to a 4-20 mA source, set:
    Measurement type: Current
    Current range: 4 to 20 mA
    Integration time / Smoothing: leave default (60 Hz rejection) unless the source is noisy.
  4. If the channel is unused, set it to "Deactivated" to speed up module cycle time and prevent spurious values from being read.
  5. Under "Diagnostics," enable "Wire break" if the input type supports it. 4-20 mA supports wire-break detection; the diagnostic bit sets when the input drops below ~3.6 mA.
  6. Compile the hardware configuration (HW) and download to the CPU. Online changes to channel type require STOP→RUN transition on older firmware.
Configuration Parameter Recommended Value Reason
Measurement type Current Required for 4-20 mA input; default is voltage
Current range 4 to 20 mA Matches industrial sensor standard; enables wire-break detection
Integration time 60 Hz (16.6 ms) Rejects 60 Hz mains pickup; use 50 Hz (20 ms) for 50 Hz regions
Smoothing None or Weak Avoids response lag in level measurement
Wire-break diagnostics Enabled Generates diagnostic interrupt at < 3.6 mA
Overflow diagnostics Enabled Catches > 20 mA or < 4 mA with broken loop
Unused channels Deactivated Prevents floating inputs from producing random counts

6. NORM_X and SCALE_X Programming

The standard Siemens scaling pipeline is NORM_X (normalize the raw INT to 0.0–1.0 REAL) followed by SCALE_X (scaling 0.0–1.0 to engineering units). On S7-1200 with firmware 4.x and TIA Portal V15.1 or later, both blocks live in "Basic Instructions → Converter operations."

6.1 NORM_X Parameters

Input Data Type Meaning Value for 4-20 mA on AI0
MIN REAL / INT / DINT Lower raw limit 0
VALUE REAL / INT / DINT Raw input (from %IW) %IW96 (PIW for AI0, slot 101)
MAX REAL / INT / DINT Upper raw limit 27648
OUT REAL Normalized 0.0–1.0 LevelNorm (REAL in DB)

6.2 SCALE_X Parameters

Input Data Type Meaning Example for 0–10 m Level
MIN REAL Engineering low 0.0
VALUE REAL Normalized input LevelNorm
MAX REAL Engineering high 10.0
OUT REAL Engineering value Level_m (REAL, used on HMI)

6.3 SCL Example (TIA Portal)

// Data Block "ProcessData"
// "RawAI0"     : INT     // mapped to %IW96 (input word for AI0 on slot 101)
// "LevelNorm"  : REAL    // normalized 0.0-1.0
// "Level_m"    : REAL    // engineering value, e.g. meters
// "FaultAI0"   : BOOL    // from module diagnostics word

IF "ProcessData".FaultAI0 THEN
    "ProcessData".LevelNorm := 0.0;
    "ProcessData".Level_m   := 0.0;
    RETURN;
END_IF;

NORM_X(
    MIN   := 0,
    VALUE := "ProcessData".RawAI0,
    MAX   := 27648,
    OUT   => "ProcessData".LevelNorm
);

SCALE_X(
    MIN   := 0.0,
    VALUE := "ProcessData".LevelNorm,
    MAX   := 10.0,
    OUT   => "ProcessData".Level_m
);

6.4 Ladder Example

Network 1: NORM_X  RawAI0 (%IW96) → LevelNorm (REAL 0.0-1.0)
[ NORM_X ]
   MIN   = 0
   VALUE = IW96
   MAX   = 27648
   OUT   = DB1.LevelNorm

Network 2: SCALE_X LevelNorm → Level_m (REAL 0.0-10.0 m)
[ SCALE_X ]
   MIN   = 0.0
   VALUE = DB1.LevelNorm
   MAX   = 10.0
   OUT   = DB1.Level_m
For a 4-20 mA input scaled to 0–10 m, 4 mA must yield exactly 0.000 on the HMI. If it does not, the issue is in the configuration (voltage vs current range, MAX value, or wiring polarity), not in NORM_X or SCALE_X. Add a watch table on %IW96 and verify the raw value is exactly 0 at 4 mA and exactly 27648 at 20 mA before debugging the SCALE block.

7. HMI Tag Wiring on the KTP 700 Basic

The KTP 700 Basic (for example 6AV2 123-2GB03-0AX0) reads tags directly from the PLC's data block. No additional scaling or transformation should be performed on the HMI side.

  1. In the TIA Portal HMI project, add a connection of type "S7-1200" pointing to the CPU's IP address.
  2. Add an HMI tag named "Level_m" pointing to PLC tag "Level_m" (the SCALE_X output in DB1 or ProcessData).
  3. On the screen, insert an "IO field" and bind the "Process value" tag to "Level_m". Set the format pattern to "s99.999" or "s9999.9" depending on engineering range.
  4. Verify in the HMI tag table that the "Acquisition mode" is "Cyclic continuous" with a 1 s cycle (default is fine for level measurement).
  5. Compile the HMI and download. Use WinCC's "Tag simulation" or the HMI's "Online → Tags" view to read Level_m directly. If the HMI shows the raw 0–27648, the tag is bound to the wrong source.

8. Why the Tag "Changes Automatically" — Root Cause Analysis

Each of the following has been confirmed to produce tags that drift or jump on an SM 1231 4HF32 4-20 mA input. Use the verification procedure in Section 9 to isolate which one applies to your installation.

8.1 Floating Current Loop

If only the AI0+ terminal is landed and the AI0- / M terminal is left open, the ADC input is referenced to undefined potential. Any nearby 24 V source or mains coupling pulls the value across the entire range. Connect the loop return to the M terminal on the SM 1231 and ensure the panel 24 V common is bonded to the same M.

8.2 Channel Configured as Voltage

If the channel is left at the default "Voltage ±10 V" while a current source is connected, the input impedance is high (megohms) instead of 250 Ω, and the current source cannot establish a voltage that the ADC can interpret. The raw value will float. Reconfigure the channel type in TIA Portal and redownload the hardware configuration.

8.3 Polarity Reversed

On a current input, reversing + and - produces a negative raw count and eventually -32768 or a similar negative overflow. NORM_X with MAX = 27648 will saturate at 0.0. Verify with a multimeter in current mode in series with the loop.

8.4 24 V Common Not Bonded Between Panel and Field

The SM 1231's M terminal must be at the same 0 V reference as the field device's 24 V common. If they are at different potentials (for example, the field device is powered from a separate PSU that is not bonded), the differential voltage at the input exceeds the common-mode range and the ADC saturates or wraps. Bond the two 24 V commons at a single point.

8.5 HMI Tag Bound to the Wrong PLC Tag

A common error is to bind the KTP 700 Basic tag to the raw %IW96 instead of the SCALE_X output. The raw value is 0–27648, which the HMI renders as "Level: 17453.2" without further scaling. Always bind the HMI tag to the final engineering tag (Level_m), not the raw input.

8.6 Sensor Power Supply Drop

If the 24 V sensor supply sags under load (long cable runs, undersized wire), the transmitter falls below its minimum operating voltage and drops out of the 4 mA region. This shows up as raw counts near zero even when the process variable is at mid-scale. Measure the transmitter terminal voltage with the loop at 20 mA; it must remain inside the transmitter's published compliance range.

8.7 50/60 Hz Hum on Unshielded Cable

Unshielded or improperly terminated cable picks up mains-frequency noise that rides on top of the 4-20 mA signal. The raw value oscillates by tens of counts at 50/60 Hz. Verify the shield is landed at the panel end only and the integration time is set to match the local mains frequency.

9. Step-by-Step Verification Procedure

  1. Verify hardware wiring. With the CPU powered off, ring out the loop with a multimeter. You should read ≤ 250 Ω across AI0+ to AI0- (with the SM 1231 powered), and 24 V nominal on the supply pair depending on device type.
  2. Verify configuration. Open TIA Portal online → Devices & Networks → SM 1231 → Properties → Analog inputs. Confirm AI0 is set to "Current, 4–20 mA." Confirm wire-break diagnostics are enabled.
  3. Verify raw input. Add a watch table containing %IW96 (and %IW98, %IW100 for AI1, AI2 if used). Drive 4.00 mA from a calibrator; the watch table must show 0 ± 4 LSB. Drive 12.00 mA; expect 13824 ± 8. Drive 20.00 mA; expect 27648 ± 4.
  4. Verify NORM_X output. Add LevelNorm to the watch table. At 4 mA expect 0.0; at 20 mA expect 1.0. If LevelNorm reads 0.0 at 20 mA, MAX is wrong; if it exceeds 1.0, polarity is reversed.
  5. Verify SCALE_X output. Add Level_m to the watch table. At 4 mA expect 0.000 m; at 20 mA expect 10.000 m. If Level_m equals LevelNorm (no scaling), SCALE_X is not in the network or its output is not assigned.
  6. Verify HMI tag. In WinCC on the KTP 700 Basic, open the tag view for Level_m and confirm the value matches the watch table. If it does not, recompile the HMI and re-download.
  7. Verify diagnostics. If a wire-break diagnostic bit is set, navigate to Online → Diagnostics and clear it. Persistent wire-break indicates a real loop fault — check for an open wire, failed transmitter, or blown fuse.

10. Troubleshooting Matrix

Symptom on HMI Likely Cause First Action
Tag shows 0.000 regardless of input Channel configured as voltage, not current Reconfigure AI0 to current range in TIA Portal
Tag drifts continuously (hunting) Floating current loop or open return Connect AI0- to M terminal on SM 1231
Tag shows negative engineering value Polarity reversed Swap + and - on the loop
Tag saturates at maximum Loop current > 20 mA or shorted return Insert multimeter in series and verify 4–20 mA
Tag saturates at minimum Loop current < 4 mA or transmitter drop-out Check 24 V supply at transmitter; measure compliance voltage
Tag shows raw 0–27648 on HMI HMI tag bound to raw %IW instead of SCALE_X output Re-bind HMI tag to Level_m in TIA Portal; recompile HMI
Tag changes only when simulator is plugged Simulator is for discrete signals, not analog Use loop calibrator for analog verification
Tag noisy / 50/60 Hz ripple Shield not grounded, integration time wrong Ground shield at panel only; set 50/60 Hz rejection
Wire-break diagnostic active Loop broken, < 3.6 mA Check for open wire, failed transmitter, blown fuse
Overflow diagnostic active Input > 20 mA or below 4 mA Verify range setting and transmitter calibration
Tag value jumps in discrete steps Module in voltage mode reading current loop Change channel type to current in device configuration

11. Cross-Reference Notes for Other Platforms

The same wiring and scaling principles apply on other small PLC platforms when commissioning 4-20 mA inputs:

  • AutomationDirect Productivity 2000 analog I/O modules use 16-bit analog modules with raw range -32768 to +32767; scale math differs accordingly.
  • Allen-Bradley MicroLogix and CompactLogix scale 4-20 mA to 0–32767 (8-bit 0–4095 on older MicroLogix 1100) and use the SCL or SCP instruction.
  • Omron CP1W-AD041 uses 0–6000 raw counts for 4–20 mA.
  • Mitsubishi FX5-4AD uses 0–4000 or 0–16000 depending on resolution mode.

The core principle is identical: configure the channel for current, verify with a calibrated mA source, confirm the raw range matches the module's datasheet, then scale to engineering units only after the raw input is verified correct.

FAQ

Why does my SM 1231 6ES7 231-4HF32-0XB0 show 0 counts when I connect 4 mA?

At 4.00 mA the SM 1231 should show a raw value of 0, which is the correct low-end of the 0–27648 range. If 0 counts is unexpected for your process, the issue is downstream — verify NORM_X is configured with MIN = 0 and MAX = 27648, and that SCALE_X uses the correct engineering minimum (for example 0.0 for 0 m level). A raw value of 0 at 4 mA is correct behavior, not a fault.

Can I use the 6ES7 274-1XH30-0XA0 simulator to inject 4-20 mA into the SM 1231?

No. The 6ES7 274-1XH30-0XA0 is the S7-1200 Input Simulator with 14 toggle switches for discrete signals only. It does not source current and cannot drive an analog input. Use a loop calibrator, mA source, or bench power supply with a 250 Ω resistor to simulate 4-20 mA into the SM 1231.

What is the difference between 0–20 mA and 4–20 mA on the SM 1231?

For 0–20 mA the raw range is 0–27648 with 0 mA = 0 counts. For 4–20 mA the raw range is 0–27648 with 4 mA = 0 counts and 20 mA = 27648. The 4–20 mA configuration provides wire-break detection because a true 0 mA indicates a broken loop, whereas 0–20 mA cannot distinguish between a legitimate 0 mA signal and a fault.

How do I scale a 4-20 mA signal with NORM_X and SCALE_X on S7-1200?

Use NORM_X with MIN = 0, VALUE = %IWxx (raw input word for the channel), MAX = 27648, and OUT = LevelNorm. Then use SCALE_X with MIN = 0.0, VALUE = LevelNorm, MAX = 10.0 (or your engineering maximum), and OUT = Level_m. Both blocks are in Basic Instructions → Converter operations in TIA Portal V15.1 and later. Verify the raw input with a watch table before debugging the scaling blocks.

Why is my KTP 700 Basic showing the wrong value even though the TIA Portal watch table shows the correct raw counts?

Verify the HMI tag connection points to the SCALE_X output (for example Level_m), not the raw %IW. The KTP 700 Basic does no automatic scaling, so binding the HMI tag to %IW96 displays the raw 0–27648 directly. Recompile and re-download the HMI after correcting the tag connection, and confirm the acquisition mode is cyclic continuous with a 1 s update cycle.

Back to blog