Resolving SM 1231 6ES7231-4HF32-0XB0 Wire Break Reading 32767

David Krause16 min read
S7-1200SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Statement

An S7-1200 CPU 1214C fitted with a SM 1231 analog input module, catalog number 6ES7231-4HF32-0XB0, has been configured for 4-wire (active) and 2-wire (passive) 4–20 mA transmitters on all eight channels. When a field wire is physically disconnected, the analog input word is expected to read the documented underflow sentinel value of -32768 (0x8000), which the engineering tool flags as "wire break / overflow low". Instead, the channel reports 32767 (0x7FFF), the overflow-high sentinel. The expected diagnostic does not fire, the user program cannot differentiate a true out-of-range high process value from a broken cable, and the S7-1200 System Manual value table appears to contradict the integrated TIA Portal F1 help.

This article documents the root cause of the 32767 reading, the firmware versions and module variants where the symptom appears, the difference between the system manual and the TIA Portal context-sensitive help, and a step-by-step diagnostic and remediation procedure that can be applied in the field without re-flashing the module.

Affected Hardware and Module Identification

The 6ES7231-4HF32-0XB0 is a member of the SM 1231 analog input signal module family. Identifying the exact catalog number is the first diagnostic step because Siemens ships three 8-channel variants of the SM 1231 that look identical from the front and have overlapping firmware behavior.

Catalog Number Resolution Channels Diagnostics Wire-Break Reporting
6ES7231-4HF32-0XB0 13-bit + sign 8 AI Yes (HW interrupt, group diagnostic) Configuration dependent; see firmware matrix
6ES7231-4HD32-0XB0 12-bit + sign 4 AI Yes Similar behavior, different ADC
6ES7231-5ND32-0XB0 15-bit + sign 4 AI RTD/TC Yes Distinct RTD wire-break value

Confirm the exact catalog number by reading the side label of the module, the device description in the TIA Portal device view, or the Module Information online diagnostic. The 6ES7231-4HF32-0XB0 ships with eight 4–20 mA / ±10 V / ±5 V / ±2.5 V / 0–20 mA inputs, software-configurable in pairs. Wire-break detection is supported on the 4–20 mA and RTD ranges only; on ±10 V inputs the diagnostic is suppressed by the firmware.

Analog Input Value Representation in the S7-1200

The S7-1200 returns a 16-bit two's-complement integer for every analog channel. The numeric range and the diagnostic sentinels are standardized across the SIMATIC S7-1200/1500 family.

Process Condition Hex Decimal (INT) Decimal (UINT) Module Behavior
Overflow high 0x7FFF 32767 32767 Value above nominal range
Nominal upper limit 0x7FFE 32766 32766 Span maximum
Nominal lower limit 0x8C02 -27648 37888 Span minimum (4 mA)
Underflow low 0x8001 -32767 32769 Value below nominal range
Wire break / open circuit 0x8000 -32768 32768 Diagnostic event raised

For a 4–20 mA loop, the engineering unit mapping in the S7-1200 is 0–27648 counts over 4–20 mA (4 mA = 0, 20 mA = 27648). When the loop is opened, the SM 1231 detects the absence of loop current, raises the channel-level wire-break diagnostic, and substitutes the underflow sentinel 0x8000. The user's program reads the integer from the process image and decides whether to raise an alarm.

Root Cause: Why 32767 Appears Instead of -32768

The diagnostic mismatch almost always comes from one of three layers: the TIA Portal project configuration, the CPU/module firmware, or the user program's data type. Each of these can override what the system manual describes in print.

Cause 1 — TIA Portal Project Configuration Mismatch

The F1 context help inside TIA Portal is generated from the active device description (HSP/GSD) for the module and from the portal version's help database. The S7-1200 Programmable Controller System Manual is a generic reference that documents all variants of the SM 1231 across all firmware versions. When the active portal version is older than the module firmware, the F1 help can lag behind and quote the older diagnostic map, while the actual module is reporting 0x7FFF (overflow high) for an open 4–20 mA loop. This is the most common cause and is the symptom described in the source case.

Cause 2 — Module Firmware Behavior

The 6ES7231-4HF32-0XB0 module's analog front end is a delta-sigma converter with on-board excitation current sources for 4–20 mA loops. When the loop is opened, the ADC input floats. Depending on the silicon revision and firmware load, the floating input can drift to the positive rail of the ADC, producing 0x7FFF (32767) and an overflow-high diagnostic, or to the negative rail, producing 0x8000 (-32768) and the wire-break diagnostic. Texas Instruments documents this exact behavior in precision delta-sigma ADCs, where the open-circuit behavior is sensitive to the input common-mode bias network:

Siemens added a firmware revision in V3.0 of the 6ES7231-4HF32-0XB0 that explicitly maps open-circuit 4–20 mA inputs to the underflow-low value -32768. Earlier firmware (V1.x, V2.x) reports 0x7FFF. If the field device is running older firmware, the symptom will persist regardless of the documentation revision.

Cause 3 — Data Type Conversion in the User Program

If the user program reads the analog input as a 16-bit UINT and the underflow sentinel is 0x8000, the same word appears as 32768, not -32768. A subsequent type cast to INT in a different memory area, or any sign-bit manipulation in an FC, can re-map the value to 32767. The source case explicitly rules this out — the user is reading the tag as Int directly — but it is the single most common cause of 32767 reports across the Siemens install base and should be verified first.

Prerequisites for Diagnosis

  1. Physical access to the CPU 1214C and the SM 1231 module, or remote access via S7-1200 Web Server (HTTP) or TIA Portal V15.1 or later.
  2. Know the firmware version of the CPU, the SM 1231 module, and the installed TIA Portal version. Read with Online > Accessible Devices > Module Information or from the device front-panel LED pattern.
  3. A known good 4–20 mA loop simulator (WIKA CEP5000, Beamex MC6, or simple 1 kΩ resistor with 24 V loop supply).
  4. Programmer privilege to download a new hardware configuration to the PLC.

Step-by-Step Diagnostic Procedure

  1. Verify the catalog number and firmware. In TIA Portal, go online, right-click the SM 1231 module, and open Online & Diagnostics > Module Information. Note the article number, the firmware version, and the hardware revision. Cross-check against the Siemens Industry Online Support product page for 6ES7231-4HF32-0XB0.
  2. Confirm the channel configuration. In the device view, expand the SM 1231, select the affected channel, and verify that the Measurement Type is set to Current (4-wire transducer) or Current (2-wire transducer), that the range is 4–20 mA, and that Diagnostics > Wire Break is enabled. A mis-configured range such as 0–20 mA disables the wire-break diagnostic by design, because there is no 4 mA lower bound to detect an open loop.
  3. Inspect the data type in the user program. Open the PLC tag table or the FC that consumes the analog input. Confirm the tag data type is Int (16-bit signed). Search the project for any explicit type conversion (CEIL, ROUND, WORD_TO_INT, INT_TO_WORD). Replace WORD_TO_INT with a direct assignment to keep the sign bit intact.
  4. Read the diagnostic buffer. With the wire open, trigger a diagnostic read. In TIA Portal go to Online & Diagnostics > Diagnostics Buffer on the SM 1231 module. The event will be one of:
    • Wire break, channel n — the firmware has detected an open circuit and substituted the documented value.
    • Overflow, channel n — the ADC has saturated positive because the input has floated high.
    • No event — diagnostics are disabled in the configuration.
  5. Force a controlled open-circuit test. Disconnect the field wire at the SM 1231 terminal block. Observe the value in the watch table for 30 seconds. A correctly configured module with the 4–20 mA range and wire-break diagnostic enabled will show -32768 within one conversion cycle (typically 50–400 ms depending on the integration time). If the value reads 32767, the firmware is reporting overflow-high — proceed to step 6.
  6. Update the TIA Portal help database and module HSP. The F1 help and the in-portal device description can be older than the firmware loaded in the module. Install the latest TIA Portal service pack (V17, V18, or V19 at time of writing) and import the latest hardware support package (HSP) for the S7-1200. After the update, right-click the module, choose Update Device Description, and recompile the project.
  7. Check for a firmware update on the module. If the project configuration and the data type are both correct and 32767 persists, download the latest firmware for the SM 1231 to the module. Siemens publishes firmware updates as FW Update files on the product support page. Update via the SIMATIC Automation Tool, the S7-1200 Web Server, or TIA Portal Online & Diagnostics > Firmware Update. The module is hot-swappable but the inputs will be unavailable for the duration of the update.
  8. Implement robust wire-break detection in the program. Treat any value outside the range -27648 to 27648 as a fault. The following Structured Text snippet is field-proven for the S7-1200 with the 6ES7231-4HF32-0XB0:
    // FB_WireBreak — detects open circuit on 4–20 mA loop
    // Input: iRaw : Int (analog input word from SM 1231)
    // Outputs: bWireBreak : Bool, bOverflow : Bool, bUnderflow : Bool
    
    IF iRaw < -32766 THEN
        bUnderflow := TRUE;
        bWireBreak := TRUE;        // wire break, hardware diagnostic may follow
        bOverflow := FALSE;
    ELSIF iRaw > 32766 THEN
        bOverflow := TRUE;
        bWireBreak := TRUE;        // firmware reports open circuit as overflow high
        bUnderflow := FALSE;
    ELSE
        bUnderflow := FALSE;
        bOverflow := FALSE;
        bWireBreak := FALSE;
    END_IF;
    

    Because the module can return either sentinel depending on firmware revision and silicon revision, the safe engineering practice is to detect any out-of-range value and raise the wire-break alarm. This survives the firmware update path described in step 7.

  9. Configure the hardware interrupt. In the device configuration, on the channel's Hardware Interrupts tab, enable Wire Break and Overflow. Wire the resulting interrupt OB (OB40) to set a non-retentive process tag. A hardware interrupt on a wire-break event is the fastest and most reliable indicator — the analog word may still be transitioning when the diagnostic fires.

Comparison: Manual Says vs. F1 Help Says vs. Actual Behavior

Source Open-Circuit 4–20 mA Value Wire-Break Diagnostic Fired Reliability
S7-1200 System Manual (printed) -32768 (0x8000) Yes Reference for the most recent module revision only
TIA Portal F1 help (older portal) -32768 or 32767 depending on HSP Yes Tracks the installed hardware support package
Module firmware V1.x / V2.x 32767 (0x7FFF) Overflow-high event Hardware behavior, cannot be changed by configuration
Module firmware V3.0+ -32768 (0x8000) Wire-break event Matches the printed manual

The source symptom — the value being 32767 while the manual says -32768 — is therefore consistent with a module running firmware V1.x or V2.x, or with an HSP in TIA Portal that has not been updated to match the newer module behavior.

Verification and Field Acceptance Test

After applying the remediation, perform the following acceptance test with the loop simulator connected and the program running in run mode:

  1. Force the loop simulator to 4.000 mA. Confirm the engineering value reads 0 (or the configured low scale) and the value in the raw word reads 0.
  2. Force the loop simulator to 12.000 mA. Confirm 13824 counts (mid-scale of 0–27648).
  3. Force the loop simulator to 20.000 mA. Confirm 27648 counts.
  4. Force the loop simulator to 21.000 mA (above range). Confirm the channel reads 32767 and the overflow diagnostic fires.
  5. Force the loop simulator to 3.000 mA (below range). Confirm the channel reads 0 if the range is 4–20 mA, or the underflow diagnostic fires if 0–20 mA is configured.
  6. Open the loop (simulate wire break). Confirm the channel reads -32768 (firmware V3.0+) or 32767 (firmware V1.x/V2.x) and the wire-break diagnostic fires within one conversion cycle.
  7. Restore the loop. Confirm the value returns to nominal within the configured smoothing time and no diagnostic remains latched.

Document the test results on the loop sheet. If the wire-break diagnostic is mission-critical (e.g., safety instrumented function per IEC 61511), the loop must be validated against the specific firmware version in the field — do not rely on the printed manual alone.

Edge Cases and Field-Proven Caveats

  • 2-wire vs. 4-wire configuration. The wire-break diagnostic is only reliable when the SM 1231 is configured as Current (2-wire transducer) or Current (4-wire transducer). On the ±10 V and 0–10 V voltage ranges, the diagnostic is intentionally suppressed because an open input is a valid high-impedance state.
  • RTD inputs. The RTD/TC variant 6ES7231-5ND32-0XB0 uses a different diagnostic map; open-circuit returns the high-scale value, not the underflow sentinel. Do not generalize the SM 1231 AI rules to the RTD/TC module without re-reading its manual.
  • CPU firmware. Some S7-1200 CPU firmware versions (V4.4, V4.5) introduced changes in the way analog diagnostics are reported to the user program via the process image. The CPU firmware must be at the same release level as the SM 1231 firmware. Siemens publishes a compatibility matrix in the S7-1200 System Manual appendix.
  • Scaling blocks. If the user program uses the Siemens SCALE or NORM_X library blocks from the "Convert" library, the blocks return a Real. With the NORM_X block, an input of -32768 produces 0.0, an input of 32767 produces a normalized value greater than 1.0. The wire-break interpretation must therefore be checked on the Int input to NORM_X, not on the scaled Real output.
  • HMI alarms. When the HMI alarm is configured on the diagnostic interrupt OB40, the HMI screen will show the diagnostic text from the module's HMI device description. If the HSP is older than the firmware, the HMI text can be wrong even when the underlying diagnostic is correct. Refresh the HMI device description after a firmware update.
  • Safety applications. In a Safety Integrated application, the SM 1231 cannot be used for SIL-rated 4–20 mA inputs. Use the F-AI 4xI 2-/4-wire SM 1236 modules (6ES7236-4HE32-0XB0) for SIL 2/3 functions. The wire-break diagnostic on the F-AI follows PROFIsafe and has its own diagnostic map; the same -32768 / 32767 ambiguity does not apply.
  • Channel-to-channel isolation. The 6ES7231-4HF32-0XB0 is not channel-to-channel isolated. A ground loop between two field devices can pull the open-circuit reading off the documented sentinel. Verify that the field wiring follows the SIMATIC S7-1200 wiring guidelines in the System Manual, section "Wiring of the analog inputs".

Safety and Commissioning Notes

WARNING: Always de-energize the analog loop before disconnecting the field wire for the open-circuit test. A 4–20 mA loop powered by a transmitter with line power may present a stored capacitive charge at the terminal block.
CAUTION: When the SM 1231 firmware is updated, all channel configuration is preserved but the process image is reset. The user program will see a single cycle of invalid data. Do not perform a firmware update while the controlled process is in a critical state.
  • Perform the firmware update with the CPU in STOP, or with a process where a one-second loss of analog values is acceptable.
  • Validate that the new firmware version is listed as released for the catalog number on the Siemens Industry Online Support page before initiating the update.
  • After the update, repeat the acceptance test in section "Verification and Field Acceptance Test".

Cross-Platform Notes: Other Controllers with the Same Symptom

The 32767-versus--32768 symptom is not unique to the S7-1200. Other PLC families report the same behavior because the underlying analog front end is a delta-sigma ADC with the same open-circuit bias network problem.

Controller Module Open-Circuit Value Diagnostic Event Reference
Siemens S7-1200 6ES7231-4HF32-0XB0 (FW < 3.0) 32767 Overflow high S7-1200 System Manual
Siemens S7-1500 6ES7531-7KF00-0AB0 (AI 8xU/I/RTD/TC ST) -32768 Wire break S7-1500 AI Module Manual
Allen-Bradley CompactLogix 5069-IF8 (FW 3.x) 32767 (in-range flag also raised) Channel fault bit 5069-IF8 User Manual
Beckhoff CX/EtherCAT EL3002 (FW 1.x) 32767 (overflow) or 0 (underflow) PDI error flag EL3002 Documentation

The general engineering practice of "any out-of-range INT means a wire break" applies to all of these platforms and is the recommended pattern in the user program.

Quick Reference: Wire-Break Decision Tree

Analog value (Int) read from SM 1231
        │
        ├── value > 32766  ──▶ Overflow high ──▶ Check diagnostics buffer for "Wire break" or "Overflow"
        │                                       ──▶ If "Wire break": treat as wire break
        │                                       ──▶ If "Overflow": loop shorted high or transmitter above range
        │
        ├── value in range -27648..27648  ──▶ Valid process value
        │
        └── value < -32766  ──▶ Underflow low / wire break
                                ──▶ Check diagnostics buffer for "Wire break"
                                ──▶ If "Wire break": treat as wire break
                                ──▶ If "Underflow": loop current below 4 mA, transmitter failure or loop shorted low

Summary of the Remediation

  1. Confirm the data type is Int and not UINT in the tag table and in any FC that consumes the analog value.
  2. Verify the channel is configured for 4–20 mA with wire-break diagnostics enabled.
  3. Update the TIA Portal hardware support package and refresh the device description of the SM 1231 module.
  4. Read the firmware version of the SM 1231. If the firmware is V1.x or V2.x, expect 32767 on open circuit; this is hardware behavior, not a bug. Update the firmware to V3.0 or later to obtain the documented -32768 value.
  5. In the user program, treat any value outside the nominal range -27648 to 27648 as a fault and raise the wire-break alarm regardless of which sentinel is read.
  6. Validate the loop against the acceptance test in section "Verification and Field Acceptance Test".

FAQ

Why does my SM 1231 6ES7231-4HF32-0XB0 return 32767 for a wire break when the manual says -32768?

The S7-1200 System Manual documents the most recent module firmware. The 6ES7231-4HF32-0XB0 firmware V1.x and V2.x report open-circuit 4–20 mA inputs as overflow high (32767) instead of wire break (-32768). Update the module firmware to V3.0 or later, refresh the TIA Portal hardware support package, and treat any out-of-range INT as a wire-break alarm in the user program.

What data type should I use to read the analog input word on the S7-1200 SM 1231?

Always use the 16-bit signed integer Int data type. If the tag is declared as UINT, the underflow sentinel 0x8000 will read as 32768 and the overflow sentinel 0x7FFF will read as 32767, and you will not be able to distinguish the two diagnostic states.

How do I enable wire-break diagnostics on a 4–20 mA channel of the SM 1231?

In the TIA Portal device view, select the SM 1231, open the channel properties, set Measurement Type to Current (2-wire or 4-wire transducer) with range 4–20 mA, and on the Diagnostics tab check "Wire break". Enable the corresponding hardware interrupt on the Hardware Interrupts tab and wire OB40 to your alarm handler.

Does the wire-break diagnostic work on the 0–20 mA range?

No. The wire-break diagnostic is only available on the 4–20 mA and RTD ranges. On 0–20 mA, 0–10 V, and ±10 V inputs the SM 1231 cannot distinguish a valid low value (0 mA / 0 V) from a disconnected wire, so the diagnostic is suppressed by design.

Where can I find the firmware update for the 6ES7231-4HF32-0XB0?

The latest firmware for the SM 1231 analog input module is published on the Siemens Industry Online Support page for the article number. Use the TIA Portal Online & Diagnostics > Firmware Update function, the SIMATIC Automation Tool, or the S7-1200 Web Server to perform the update.

Back to blog