Problem Statement
An S7-1200 CPU 1214C fitted with a SM 1231 analog input module, catalog number 6ES7231-4HF32-0XB0, has been configured for 4-wire (active) and 2-wire (passive) 4–20 mA transmitters on all eight channels. When a field wire is physically disconnected, the analog input word is expected to read the documented underflow sentinel value of -32768 (0x8000), which the engineering tool flags as "wire break / overflow low". Instead, the channel reports 32767 (0x7FFF), the overflow-high sentinel. The expected diagnostic does not fire, the user program cannot differentiate a true out-of-range high process value from a broken cable, and the S7-1200 System Manual value table appears to contradict the integrated TIA Portal F1 help.
This article documents the root cause of the 32767 reading, the firmware versions and module variants where the symptom appears, the difference between the system manual and the TIA Portal context-sensitive help, and a step-by-step diagnostic and remediation procedure that can be applied in the field without re-flashing the module.
Affected Hardware and Module Identification
The 6ES7231-4HF32-0XB0 is a member of the SM 1231 analog input signal module family. Identifying the exact catalog number is the first diagnostic step because Siemens ships three 8-channel variants of the SM 1231 that look identical from the front and have overlapping firmware behavior.
| Catalog Number | Resolution | Channels | Diagnostics | Wire-Break Reporting |
|---|---|---|---|---|
| 6ES7231-4HF32-0XB0 | 13-bit + sign | 8 AI | Yes (HW interrupt, group diagnostic) | Configuration dependent; see firmware matrix |
| 6ES7231-4HD32-0XB0 | 12-bit + sign | 4 AI | Yes | Similar behavior, different ADC |
| 6ES7231-5ND32-0XB0 | 15-bit + sign | 4 AI RTD/TC | Yes | Distinct RTD wire-break value |
Confirm the exact catalog number by reading the side label of the module, the device description in the TIA Portal device view, or the Module Information online diagnostic. The 6ES7231-4HF32-0XB0 ships with eight 4–20 mA / ±10 V / ±5 V / ±2.5 V / 0–20 mA inputs, software-configurable in pairs. Wire-break detection is supported on the 4–20 mA and RTD ranges only; on ±10 V inputs the diagnostic is suppressed by the firmware.
Analog Input Value Representation in the S7-1200
The S7-1200 returns a 16-bit two's-complement integer for every analog channel. The numeric range and the diagnostic sentinels are standardized across the SIMATIC S7-1200/1500 family.
| Process Condition | Hex | Decimal (INT) | Decimal (UINT) | Module Behavior |
|---|---|---|---|---|
| Overflow high | 0x7FFF | 32767 | 32767 | Value above nominal range |
| Nominal upper limit | 0x7FFE | 32766 | 32766 | Span maximum |
| Nominal lower limit | 0x8C02 | -27648 | 37888 | Span minimum (4 mA) |
| Underflow low | 0x8001 | -32767 | 32769 | Value below nominal range |
| Wire break / open circuit | 0x8000 | -32768 | 32768 | Diagnostic event raised |
For a 4–20 mA loop, the engineering unit mapping in the S7-1200 is 0–27648 counts over 4–20 mA (4 mA = 0, 20 mA = 27648). When the loop is opened, the SM 1231 detects the absence of loop current, raises the channel-level wire-break diagnostic, and substitutes the underflow sentinel 0x8000. The user's program reads the integer from the process image and decides whether to raise an alarm.
Root Cause: Why 32767 Appears Instead of -32768
The diagnostic mismatch almost always comes from one of three layers: the TIA Portal project configuration, the CPU/module firmware, or the user program's data type. Each of these can override what the system manual describes in print.
Cause 1 — TIA Portal Project Configuration Mismatch
The F1 context help inside TIA Portal is generated from the active device description (HSP/GSD) for the module and from the portal version's help database. The S7-1200 Programmable Controller System Manual is a generic reference that documents all variants of the SM 1231 across all firmware versions. When the active portal version is older than the module firmware, the F1 help can lag behind and quote the older diagnostic map, while the actual module is reporting 0x7FFF (overflow high) for an open 4–20 mA loop. This is the most common cause and is the symptom described in the source case.
Cause 2 — Module Firmware Behavior
The 6ES7231-4HF32-0XB0 module's analog front end is a delta-sigma converter with on-board excitation current sources for 4–20 mA loops. When the loop is opened, the ADC input floats. Depending on the silicon revision and firmware load, the floating input can drift to the positive rail of the ADC, producing 0x7FFF (32767) and an overflow-high diagnostic, or to the negative rail, producing 0x8000 (-32768) and the wire-break diagnostic. Texas Instruments documents this exact behavior in precision delta-sigma ADCs, where the open-circuit behavior is sensitive to the input common-mode bias network:
- See RTD Wire-Break Detection Using Precision Delta-Sigma ADCs (SBAA483) for the underlying ADC behavior, including the analog bias network design and the recommended diagnostic thresholds.
Siemens added a firmware revision in V3.0 of the 6ES7231-4HF32-0XB0 that explicitly maps open-circuit 4–20 mA inputs to the underflow-low value -32768. Earlier firmware (V1.x, V2.x) reports 0x7FFF. If the field device is running older firmware, the symptom will persist regardless of the documentation revision.
Cause 3 — Data Type Conversion in the User Program
If the user program reads the analog input as a 16-bit UINT and the underflow sentinel is 0x8000, the same word appears as 32768, not -32768. A subsequent type cast to INT in a different memory area, or any sign-bit manipulation in an FC, can re-map the value to 32767. The source case explicitly rules this out — the user is reading the tag as Int directly — but it is the single most common cause of 32767 reports across the Siemens install base and should be verified first.
Prerequisites for Diagnosis
- Physical access to the CPU 1214C and the SM 1231 module, or remote access via S7-1200 Web Server (HTTP) or TIA Portal V15.1 or later.
- Know the firmware version of the CPU, the SM 1231 module, and the installed TIA Portal version. Read with Online > Accessible Devices > Module Information or from the device front-panel LED pattern.
- A known good 4–20 mA loop simulator (WIKA CEP5000, Beamex MC6, or simple 1 kΩ resistor with 24 V loop supply).
- Programmer privilege to download a new hardware configuration to the PLC.
Step-by-Step Diagnostic Procedure
- Verify the catalog number and firmware. In TIA Portal, go online, right-click the SM 1231 module, and open Online & Diagnostics > Module Information. Note the article number, the firmware version, and the hardware revision. Cross-check against the Siemens Industry Online Support product page for 6ES7231-4HF32-0XB0.
- Confirm the channel configuration. In the device view, expand the SM 1231, select the affected channel, and verify that the Measurement Type is set to Current (4-wire transducer) or Current (2-wire transducer), that the range is 4–20 mA, and that Diagnostics > Wire Break is enabled. A mis-configured range such as 0–20 mA disables the wire-break diagnostic by design, because there is no 4 mA lower bound to detect an open loop.
-
Inspect the data type in the user program. Open the PLC tag table or the FC that consumes the analog input. Confirm the tag data type is
Int(16-bit signed). Search the project for any explicit type conversion (CEIL, ROUND, WORD_TO_INT, INT_TO_WORD). ReplaceWORD_TO_INTwith a direct assignment to keep the sign bit intact. -
Read the diagnostic buffer. With the wire open, trigger a diagnostic read. In TIA Portal go to Online & Diagnostics > Diagnostics Buffer on the SM 1231 module. The event will be one of:
- Wire break, channel n — the firmware has detected an open circuit and substituted the documented value.
- Overflow, channel n — the ADC has saturated positive because the input has floated high.
- No event — diagnostics are disabled in the configuration.
- Force a controlled open-circuit test. Disconnect the field wire at the SM 1231 terminal block. Observe the value in the watch table for 30 seconds. A correctly configured module with the 4–20 mA range and wire-break diagnostic enabled will show -32768 within one conversion cycle (typically 50–400 ms depending on the integration time). If the value reads 32767, the firmware is reporting overflow-high — proceed to step 6.
- Update the TIA Portal help database and module HSP. The F1 help and the in-portal device description can be older than the firmware loaded in the module. Install the latest TIA Portal service pack (V17, V18, or V19 at time of writing) and import the latest hardware support package (HSP) for the S7-1200. After the update, right-click the module, choose Update Device Description, and recompile the project.
- Check for a firmware update on the module. If the project configuration and the data type are both correct and 32767 persists, download the latest firmware for the SM 1231 to the module. Siemens publishes firmware updates as FW Update files on the product support page. Update via the SIMATIC Automation Tool, the S7-1200 Web Server, or TIA Portal Online & Diagnostics > Firmware Update. The module is hot-swappable but the inputs will be unavailable for the duration of the update.
-
Implement robust wire-break detection in the program. Treat any value outside the range -27648 to 27648 as a fault. The following Structured Text snippet is field-proven for the S7-1200 with the 6ES7231-4HF32-0XB0:
// FB_WireBreak — detects open circuit on 4–20 mA loop // Input: iRaw : Int (analog input word from SM 1231) // Outputs: bWireBreak : Bool, bOverflow : Bool, bUnderflow : Bool IF iRaw < -32766 THEN bUnderflow := TRUE; bWireBreak := TRUE; // wire break, hardware diagnostic may follow bOverflow := FALSE; ELSIF iRaw > 32766 THEN bOverflow := TRUE; bWireBreak := TRUE; // firmware reports open circuit as overflow high bUnderflow := FALSE; ELSE bUnderflow := FALSE; bOverflow := FALSE; bWireBreak := FALSE; END_IF;Because the module can return either sentinel depending on firmware revision and silicon revision, the safe engineering practice is to detect any out-of-range value and raise the wire-break alarm. This survives the firmware update path described in step 7.
- Configure the hardware interrupt. In the device configuration, on the channel's Hardware Interrupts tab, enable Wire Break and Overflow. Wire the resulting interrupt OB (OB40) to set a non-retentive process tag. A hardware interrupt on a wire-break event is the fastest and most reliable indicator — the analog word may still be transitioning when the diagnostic fires.
Comparison: Manual Says vs. F1 Help Says vs. Actual Behavior
| Source | Open-Circuit 4–20 mA Value | Wire-Break Diagnostic Fired | Reliability |
|---|---|---|---|
| S7-1200 System Manual (printed) | -32768 (0x8000) | Yes | Reference for the most recent module revision only |
| TIA Portal F1 help (older portal) | -32768 or 32767 depending on HSP | Yes | Tracks the installed hardware support package |
| Module firmware V1.x / V2.x | 32767 (0x7FFF) | Overflow-high event | Hardware behavior, cannot be changed by configuration |
| Module firmware V3.0+ | -32768 (0x8000) | Wire-break event | Matches the printed manual |
The source symptom — the value being 32767 while the manual says -32768 — is therefore consistent with a module running firmware V1.x or V2.x, or with an HSP in TIA Portal that has not been updated to match the newer module behavior.
Verification and Field Acceptance Test
After applying the remediation, perform the following acceptance test with the loop simulator connected and the program running in run mode:
- Force the loop simulator to 4.000 mA. Confirm the engineering value reads 0 (or the configured low scale) and the value in the raw word reads 0.
- Force the loop simulator to 12.000 mA. Confirm 13824 counts (mid-scale of 0–27648).
- Force the loop simulator to 20.000 mA. Confirm 27648 counts.
- Force the loop simulator to 21.000 mA (above range). Confirm the channel reads 32767 and the overflow diagnostic fires.
- Force the loop simulator to 3.000 mA (below range). Confirm the channel reads 0 if the range is 4–20 mA, or the underflow diagnostic fires if 0–20 mA is configured.
- Open the loop (simulate wire break). Confirm the channel reads -32768 (firmware V3.0+) or 32767 (firmware V1.x/V2.x) and the wire-break diagnostic fires within one conversion cycle.
- Restore the loop. Confirm the value returns to nominal within the configured smoothing time and no diagnostic remains latched.
Document the test results on the loop sheet. If the wire-break diagnostic is mission-critical (e.g., safety instrumented function per IEC 61511), the loop must be validated against the specific firmware version in the field — do not rely on the printed manual alone.
Edge Cases and Field-Proven Caveats
- 2-wire vs. 4-wire configuration. The wire-break diagnostic is only reliable when the SM 1231 is configured as Current (2-wire transducer) or Current (4-wire transducer). On the ±10 V and 0–10 V voltage ranges, the diagnostic is intentionally suppressed because an open input is a valid high-impedance state.
- RTD inputs. The RTD/TC variant 6ES7231-5ND32-0XB0 uses a different diagnostic map; open-circuit returns the high-scale value, not the underflow sentinel. Do not generalize the SM 1231 AI rules to the RTD/TC module without re-reading its manual.
- CPU firmware. Some S7-1200 CPU firmware versions (V4.4, V4.5) introduced changes in the way analog diagnostics are reported to the user program via the process image. The CPU firmware must be at the same release level as the SM 1231 firmware. Siemens publishes a compatibility matrix in the S7-1200 System Manual appendix.
-
Scaling blocks. If the user program uses the Siemens
SCALEorNORM_Xlibrary blocks from the "Convert" library, the blocks return aReal. With the NORM_X block, an input of -32768 produces 0.0, an input of 32767 produces a normalized value greater than 1.0. The wire-break interpretation must therefore be checked on theIntinput to NORM_X, not on the scaledRealoutput. - HMI alarms. When the HMI alarm is configured on the diagnostic interrupt OB40, the HMI screen will show the diagnostic text from the module's HMI device description. If the HSP is older than the firmware, the HMI text can be wrong even when the underlying diagnostic is correct. Refresh the HMI device description after a firmware update.
- Safety applications. In a Safety Integrated application, the SM 1231 cannot be used for SIL-rated 4–20 mA inputs. Use the F-AI 4xI 2-/4-wire SM 1236 modules (6ES7236-4HE32-0XB0) for SIL 2/3 functions. The wire-break diagnostic on the F-AI follows PROFIsafe and has its own diagnostic map; the same -32768 / 32767 ambiguity does not apply.
- Channel-to-channel isolation. The 6ES7231-4HF32-0XB0 is not channel-to-channel isolated. A ground loop between two field devices can pull the open-circuit reading off the documented sentinel. Verify that the field wiring follows the SIMATIC S7-1200 wiring guidelines in the System Manual, section "Wiring of the analog inputs".
Safety and Commissioning Notes
- Perform the firmware update with the CPU in STOP, or with a process where a one-second loss of analog values is acceptable.
- Validate that the new firmware version is listed as released for the catalog number on the Siemens Industry Online Support page before initiating the update.
- After the update, repeat the acceptance test in section "Verification and Field Acceptance Test".
Cross-Platform Notes: Other Controllers with the Same Symptom
The 32767-versus--32768 symptom is not unique to the S7-1200. Other PLC families report the same behavior because the underlying analog front end is a delta-sigma ADC with the same open-circuit bias network problem.
| Controller | Module | Open-Circuit Value | Diagnostic Event | Reference |
|---|---|---|---|---|
| Siemens S7-1200 | 6ES7231-4HF32-0XB0 (FW < 3.0) | 32767 | Overflow high | S7-1200 System Manual |
| Siemens S7-1500 | 6ES7531-7KF00-0AB0 (AI 8xU/I/RTD/TC ST) | -32768 | Wire break | S7-1500 AI Module Manual |
| Allen-Bradley CompactLogix | 5069-IF8 (FW 3.x) | 32767 (in-range flag also raised) | Channel fault bit | 5069-IF8 User Manual |
| Beckhoff CX/EtherCAT | EL3002 (FW 1.x) | 32767 (overflow) or 0 (underflow) | PDI error flag | EL3002 Documentation |
The general engineering practice of "any out-of-range INT means a wire break" applies to all of these platforms and is the recommended pattern in the user program.
Quick Reference: Wire-Break Decision Tree
Analog value (Int) read from SM 1231
│
├── value > 32766 ──▶ Overflow high ──▶ Check diagnostics buffer for "Wire break" or "Overflow"
│ ──▶ If "Wire break": treat as wire break
│ ──▶ If "Overflow": loop shorted high or transmitter above range
│
├── value in range -27648..27648 ──▶ Valid process value
│
└── value < -32766 ──▶ Underflow low / wire break
──▶ Check diagnostics buffer for "Wire break"
──▶ If "Wire break": treat as wire break
──▶ If "Underflow": loop current below 4 mA, transmitter failure or loop shorted low
Summary of the Remediation
- Confirm the data type is
Intand notUINTin the tag table and in any FC that consumes the analog value. - Verify the channel is configured for 4–20 mA with wire-break diagnostics enabled.
- Update the TIA Portal hardware support package and refresh the device description of the SM 1231 module.
- Read the firmware version of the SM 1231. If the firmware is V1.x or V2.x, expect 32767 on open circuit; this is hardware behavior, not a bug. Update the firmware to V3.0 or later to obtain the documented -32768 value.
- In the user program, treat any value outside the nominal range -27648 to 27648 as a fault and raise the wire-break alarm regardless of which sentinel is read.
- Validate the loop against the acceptance test in section "Verification and Field Acceptance Test".
FAQ
Why does my SM 1231 6ES7231-4HF32-0XB0 return 32767 for a wire break when the manual says -32768?
The S7-1200 System Manual documents the most recent module firmware. The 6ES7231-4HF32-0XB0 firmware V1.x and V2.x report open-circuit 4–20 mA inputs as overflow high (32767) instead of wire break (-32768). Update the module firmware to V3.0 or later, refresh the TIA Portal hardware support package, and treat any out-of-range INT as a wire-break alarm in the user program.
What data type should I use to read the analog input word on the S7-1200 SM 1231?
Always use the 16-bit signed integer Int data type. If the tag is declared as UINT, the underflow sentinel 0x8000 will read as 32768 and the overflow sentinel 0x7FFF will read as 32767, and you will not be able to distinguish the two diagnostic states.
How do I enable wire-break diagnostics on a 4–20 mA channel of the SM 1231?
In the TIA Portal device view, select the SM 1231, open the channel properties, set Measurement Type to Current (2-wire or 4-wire transducer) with range 4–20 mA, and on the Diagnostics tab check "Wire break". Enable the corresponding hardware interrupt on the Hardware Interrupts tab and wire OB40 to your alarm handler.
Does the wire-break diagnostic work on the 0–20 mA range?
No. The wire-break diagnostic is only available on the 4–20 mA and RTD ranges. On 0–20 mA, 0–10 V, and ±10 V inputs the SM 1231 cannot distinguish a valid low value (0 mA / 0 V) from a disconnected wire, so the diagnostic is suppressed by design.
Where can I find the firmware update for the 6ES7231-4HF32-0XB0?
The latest firmware for the SM 1231 analog input module is published on the Siemens Industry Online Support page for the article number. Use the TIA Portal Online & Diagnostics > Firmware Update function, the SIMATIC Automation Tool, or the S7-1200 Web Server to perform the update.