Problem Summary
A field case on a SIMATIC S7-1200 1214C DC/DC/DC (firmware V4.3) equipped with an SM 1231 AI8 (6ES7 231-4HF32-0XB0, 13-bit, firmware V2.1) reports a clipped analog reading on channel 2. With 9.89 V measured directly at the terminal using a digital multimeter, the input word IW100 saturates at approximately 21,300 counts rather than the expected 27,648 counts that correspond to the full 10 V range. The onboard CPU analog input on the same machine reads the same signal correctly up to 27,648. All eight channel LEDs and the DIAG LED on the SM 1231 remain solid green. TIA Portal V16 online diagnostics show no fault, no diagnostic buffer entry, and no channel-level error. The reading is simply mathematically wrong without throwing a hardware fault.
This is a classic symptom of an exceeded common-mode input voltage on an SM 1231 AI8 module whose analog ground reference is not bonded to the ground of the signal source. Because the module never flags a diagnostic event, the issue is silent and frequently misdiagnosed as a calibration problem, a wrong configuration, or a defective module.
Affected Hardware and Firmware
| Item | Catalog Number | Version in this case | Notes |
|---|---|---|---|
| CPU | 6ES7 214-1AG40-0XB0 (S7-1214C DC/DC/DC) | Firmware V4.3 | Onboard AI0/AI1 used as reference |
| Analog Input Module | 6ES7 231-4HF32-0XB0 (SM 1231 AI8, 13-bit) | Firmware V2.1 | 8 channels, ±10 V / 0-20 mA / 4-20 mA |
| Signal Source | LOGO! analog output | 0-10 V output | Powered from a separate 24 V supply |
| Engineering | TIA Portal V16 | Step 7 Basic V16 | Device configuration matched catalog |
Root Cause: Common-Mode Voltage Exceeded
The SM 1231 AI8 input stage is designed to measure a differential signal riding on a defined common-mode voltage. The permitted common-mode range is bounded by the module's internal reference; if the potential of the signal-source ground (M of the LOGO! 24 V supply) drifts more than the specified limit away from the module's M terminal, the input amplifier begins to saturate well before the differential voltage reaches the full-scale value. The result is a non-linear, compressed reading that tops out at a count that has no obvious relationship to the configured range.
In the documented case, the LOGO! 24 V supply and the S7-1200 24 V supply were floating with respect to each other. The 0-10 V output of the LOGO! sat on the LOGO! M, which could be several volts away from the S7-1200 M referenced by the SM 1231 channel 2 negative input. The differential voltage measured by the multimeter (9.89 V) was correct because the meter references the LOGO! M, but the SM 1231 saw that same 9.89 V plus a substantial common-mode offset, which pushed the input stage into compression. The onboard CPU AI worked because the negative terminal of the CPU AI is tied to the CPU's M internally, so the reference path was direct.
SM 1231 AI8 Technical Specifications (Relevant Subset)
| Parameter | Value |
|---|---|
| Catalog | 6ES7 231-4HF32-0XB0 |
| Number of inputs | 8 (or 4 differential depending on wiring mode) |
| Resolution | 13 bits + sign (voltage), 12 bits (current) |
| Voltage range | ±10 V, 0-10 V |
| Current range | 0-20 mA, 4-20 mA |
| Nominal digital range (voltage) | -27,648 to +27,648 |
| Nominal digital range (current) | 0 to 27,648 |
| Overshoot range | 27,649 to 32,511 |
| Undershoot range | -32,512 to -27,649 |
| Overrange indication | 32,512 to 32,767 (positive), -32,768 to -32,513 (negative) |
| Update time | Channel-by-channel conversion; refer to manual for cycle |
| Galvanic isolation | 500 V AC between channel group and backplane |
| Common-mode voltage limit | Restricted; see manual — typically must remain within ± signal range of module M |
The full nominal and overshoot/undershoot mapping is documented in the section on analog input ranges for voltage and current in the SM 1231 AI Module Specifications in the TIA Portal Manual Collection. Always verify against the manual for the firmware revision you are running; the underlying data word is encoded in two's complement for bipolar ranges and unsigned for unipolar ranges.
Wiring Topology in the Field
The original wiring in the case had these connections:
- SM 1231 L+ and M powered from the S7-1200 24 V supply (PS1).
- CPU S7-1214C powered from the same PS1.
- LOGO! 24 V supplied by a separate 24 V source (PS2).
- LOGO! analog output AQ+ connected to SM 1231 channel 2+.
- LOGO! analog output AQ- floating with respect to SM 1231 channel 2- (no bond between PS1 M and PS2 M).
- Unused channels 0 and 1 configured as 0-20 mA inputs; channels 3-7 likewise configured (channel 3 was also shorted 3+ to 3- as a looped test).
- PE not connected to the module.
This is a textbook setup for a common-mode violation. The SM 1231 channel negative is referenced to PS1 M, while the LOGO! output is referenced to PS2 M. The two 24 V supplies floated by more than the common-mode budget, compressing the channel 2 reading.
Diagnostic Procedure
- Confirm the configuration in TIA Portal. Open the device view for the SM 1231, expand Analog inputs, and verify channel 2 is set to Voltage with the 0-10 V (or ±10 V) range. Ensure unused channels are set to a defined range, not left at default, since undefined channels can also report confusing values.
- Read the input word live. With the system online, force a watch table on IW100. Sweep the LOGO! analog output from 0 to 100% and record the integer returned at each step.
- Compare to a known reference. Run the same signal into the onboard CPU AI (IW64 in this case). If the CPU AI reads correctly to 27,648 and the SM 1231 caps at a lower value with the same physical signal, the issue is local to the module's reference path.
- Measure with a multimeter referenced to the SM 1231 M terminal. Place the black probe on the M terminal of the SM 1231 (PS1 M) and the red probe on the LOGO! M. This is the common-mode voltage the module is experiencing. If it is non-zero and approaches the supply potential, the common-mode limit is being violated.
- Check for diagnostic events. In the online Diagnostics view of the SM 1231, confirm there are no channel-level entries. The absence of a diagnostic is consistent with a common-mode offset, not a wiring fault or sensor failure.
- Verify the sensor output. With the multimeter referenced to the LOGO! M, confirm the LOGO! is producing the expected 0-10 V. In the case the value was 9.89 V at 100% output, which is normal for a LOGO! analog output under load.
Step-by-Step Solution
- Power down the system. De-energize the S7-1200, the SM 1231, and the LOGO!. Verify zero potential with a multimeter before touching any conductor.
- Bond the two 24 V commons. Run a dedicated conductor (minimum 1.5 mm² / 16 AWG) from the M terminal of the LOGO! 24 V supply (PS2) to the M terminal of the S7-1200 24 V supply (PS1). Keep this conductor short and avoid routing it parallel to AC power or VFD motor cables.
- Re-check the SM 1231 wiring. Confirm channel 2- lands on the SM 1231 M terminal block at the same physical M that the PS1 supply returns to. The SM 1231 has per-channel M terminals and a common M for the analog section; consult the wiring diagram in the SM 1231 AI Module Specifications page for the exact pinout for 6ES7 231-4HF32-0XB0.
- Power up in sequence. Energize PS1 first (S7-1200), then PS2 (LOGO!). Bringing up the LOGO! first or simultaneously with floating commons can produce momentary common-mode transients.
- Re-test the sweep. With IW100 monitored online, sweep the LOGO! output from 0 to 100%. Expect a near-linear rise to 27,648 counts at 10 V. A residual non-linearity of ±0.3% of full scale is normal for the 13-bit module.
- Verify against the onboard CPU AI. Read IW64 simultaneously. The two values should track within the module's specified accuracy.
Verification and Calibration
After the bond is in place, perform the following verifications before returning the system to production:
- Zero check: With the LOGO! output commanded to 0 V (or its equivalent 0% scaling), the SM 1231 channel 2 input word should be 0 for unipolar 0-10 V and 0 for 4-20 mA on the unused channels. Any offset greater than a few counts points to a remaining ground issue or a long cable picking up noise.
- Span check: Apply 5 V and 10 V references from a calibrated source. The expected counts for 0-10 V are 13,824 and 27,648 respectively, per the data word formula:
Counts = (V_input / V_fullscale) × 27,648
- Diagnostic view: Confirm that Online > Diagnostics shows no overflow, underflow, wire break, or short-circuit entries. The SM 1231 supports wire break detection on 4-20 mA ranges, so a 4-20 mA loop sanity test on a spare channel is a good additional check.
- Long-run stability: Monitor the input word for several hours with the input held constant. A drift larger than the module's temperature coefficient (specified in the manual) suggests a remaining ground loop or thermistor-type drift in the cabling.
Preventive Design Guidelines
The fix is a single wire, but the underlying lesson applies across any S7-1200 deployment with multiple field devices powered from different sources.
- Single-point ground reference. All analog signal sources feeding an SM 1231 should share a common 24 V return (M) with the S7-1200 supply. If isolation is required, use an isolated signal conditioner or a dedicated isolated analog input module rather than floating the source and hoping the common-mode range holds.
- Avoid PE on the signal negative. The SM 1231 channel negative is not a safety ground. Tying it to PE at multiple points creates ground loops and injects line-frequency noise. The PE terminal on the module is for chassis/EMC bonding only.
- Configure unused channels explicitly. Set unused channels to a defined current or voltage range rather than leaving them at default. This prevents floating inputs from picking up noise and reporting sporadic counts in the input image.
- Document the wiring class. Keep analog signal cables (twisted, shielded) physically separated from 24 V power and from any VFD output cables. The S7-1200 system manual prescribes a minimum separation of 200 mm in a shared cable tray.
- Use shielded twisted pair for voltage signals > 24 V or runs > 10 m. For 0-10 V outputs, the SM 1231 input impedance is high, so noise pickup is a real concern on long runs. Ground the shield at the S7-1200 end only, leaving the source end floating, to break ground loops through the shield.
- Pre-commissioning bench test. Before installing a mixed-supply system in the field, bring the analog source and the S7-1200 to a common bench 24 V supply and confirm a full-scale sweep. If the system works on the bench but not in the field, the issue is almost always the field wiring of the M reference.
Troubleshooting Matrix
| Observed Symptom | Most Likely Cause | Confirm With | Fix |
|---|---|---|---|
| Reading tops out at ~21,000-22,000 with 10 V applied; no diagnostic | Common-mode voltage exceeded; floating source supply | Measure voltage between source M and SM 1231 M with multimeter | Bond source M to S7-1200 M |
| Reading goes negative when input is positive | Polarity reversed on differential pair | Measure at terminals with reference to module M | Swap + and - at the terminal block |
| Reading is 0 with a valid input | Channel configured for current but wired for voltage (or vice versa) | Check TIA Portal device configuration | Set channel to voltage range matching wiring |
| Reading is 32,511 or -32,512 stuck | Overrange or underrange; input out of configured range | Check wiring; verify signal against configured range | Adjust input to configured range or reconfigure channel |
| Reading is 32,768 (negative full) on a 4-20 mA channel | Wire break detected (4-20 mA only) | Check continuity; check loop power | Repair loop; verify burden voltage |
| Reading is correct at low values, distorted at high values | Common-mode or EMI; possible ground loop on shield | Disconnect shield at source end; reroute cable | Single-point shield ground; reroute away from VFD cables |
| All channels read noise or random values | L+/M not powered; 24 V missing on module | Measure 24 V at L+ and M of SM 1231 | Restore 24 V supply; check fuse |
Edge Cases and Related Issues
Onboard CPU AI versus SM 1231 AI. The onboard analog inputs on the S7-1200 CPU share the CPU's M reference and have a more permissive connection topology in low-noise environments. Once you move to an SM 1231, the per-channel M terminals must be deliberately wired. This asymmetry is a common trap for engineers moving from the CPU to the signal module for the first time.
LOGO! as analog source. The LOGO! AM2 AQ0 module outputs 0-10 V referenced to its own M. When feeding an S7-1200, the M bonding is essential. If the LOGO! is also reading from a 4-20 mA sensor that loops back to a third supply, the bonding problem compounds and the SM 1231 readings can become very erratic. Bond every M in the chain.
Isolated analog input modules. If a project requires floating signal sources, consider the 6ES7 231-5ND32-0XB0 (SM 1231 AI4) or other variants with channel-to-channel isolation. These modules tolerate wider common-mode voltages and are designed for systems with multiple isolated field supplies.
Accuracy versus reading compression. The 13-bit SM 1231 has a published accuracy of about 0.3% of full scale. If the reading is off by more than 1% and the trend is non-linear, suspect a wiring issue rather than a calibration issue. The module is factory-calibrated and does not require field calibration.
Effect of unused channels. Leaving unused channels unconfigured in TIA Portal can cause channel LEDs to indicate an undefined state. Configure every channel, even unused ones, to a defined range. The factory default for many SM 1231 channels is voltage, which can be misleading if the field wiring is actually current-loop powered.
FAQ
Why does my SM 1231 AI8 read 21,300 instead of 27,648 at 10 V input?
Almost always a common-mode voltage issue. The signal source ground is floating with respect to the SM 1231 M, so the input stage saturates before reaching full scale. Bond the M of the source 24 V supply to the M of the S7-1200 24 V supply and the reading will rise to 27,648 counts.
Can the SM 1231 detect a common-mode violation and raise a diagnostic?
No. The SM 1231 does not monitor common-mode voltage at its terminals. As long as the absolute maximum ratings are respected, no DIAG event is generated. The reading is silently compressed by the analog front end, which is why the field problem is easy to miss.
Why does the onboard CPU AI read correctly while the SM 1231 AI reads low on the same signal?
The CPU AI negative terminal is bonded to the CPU M internally, giving a direct reference. The SM 1231 has per-channel M terminals that must be wired back to the S7-1200 system M. If the source and the S7-1200 use different 24 V supplies, only the bonded path (the CPU AI) reads correctly.
What is the correct digital full-scale count for a 0-10 V input on the 6ES7 231-4HF32-0XB0?
0 V = 0 counts, 10 V = 27,648 counts. Values up to 32,511 indicate the overshoot range, and 32,512-32,767 is the positive overrange. Negative values indicate a bipolar configuration or reversed wiring. The full mapping is in the SM 1231 AI Module Specifications page.
Do I need to bond PE between the LOGO! and the S7-1200 to fix this?
No. Bonding M (the 24 V common/return) is the fix. PE is for chassis and EMC bonding only. Tying the analog signal negative to PE at multiple points creates ground loops and injects 50/60 Hz noise into the reading.
Is there a firmware bug on the 6ES7 231-4HF32-0XB0 firmware V2.1 that causes this?
No known firmware issue matches this symptom. The behavior is fully explained by the analog front-end topology. Always rule out grounding, configuration, and wiring before assuming a firmware bug; consult the S7-1200 manual collection for any open firmware notes.