S7-1200 CPU 1214C DC/DC/DC Intermittent ERROR LED and Output Auto-Reset: Hardware ID 276 Root-Cause Resolution
This technical reference addresses a recurring fault pattern on the SIMATIC S7-1200 CPU 1214C DC/DC/DC (order number 6ES7214-1AG40-0XB0 or the equivalent 6ES7214-1AE30-0XB0 first-generation variant) where the CPU ERROR LED transitions to red, all digital and analog outputs drop to a safe (reset) state for approximately 1-3 seconds, and the PLC then resumes normal scan operation. The diagnostic buffer entry associated with this behavior typically references Hardware ID 276, which corresponds to a downstream I/O module on the internal backplane bus rather than the CPU itself. The article combines the field report, the TIA Portal diagnostic procedure, mechanical and electrical checks, and firmware verification into a single commissioning-grade procedure.
1. Problem Statement and Symptoms
The reported installation consists of:
- 1 × S7-1200 CPU 1214C DC/DC/DC with 14 DI / 10 DO onboard, 2 AI onboard, 100 kB work memory, 24 V DC supply on the CPU power terminals (L+ / M).
- 4 × SM 1223 DI8/DO8 digital input/output signal modules (8 DI 24 V DC / 8 DO relay or transistor depending on order number).
- 1 × SM 1232 AQ2 analog output module (2 × ±10 V or 0-20 mA).
- 1 × SIMATIC HMI KTP400 Basic mono (or KP400 Basic mono) for parameter entry.
- 2 × Siemens converters (SINAMICS V20 or MICROMASTER 4 family, depending on the field installation) controlled by the 0-10 V output of the SM 1232 AQ2.
The fault presents as:
- CPU ERROR LED changes from off / flashing to steady red.
- All physical outputs on the CPU and on the signal modules go to a defined off state (DOs open relays or turn off transistors; AQs drop to 0 V / 0 mA).
- After approximately 2 seconds the CPU returns to RUN, the ERROR LED extinguishes, and outputs are re-driven by the cyclic OB1 image.
- The HMI remains online; the user can confirm that the PLC did not perform a STOP-to-RUN transition but rather executed a module re-initialization sequence.
This pattern is consistent with a transient module-station failure rather than a hard CPU fault. A hard CPU fault would normally drop the CPU to STOP mode, light the red ERROR LED, and require either power-cycle or STOP-RUN toggle for recovery. Because the controller recovers in 1-3 seconds without user action, the fault originates in the I/O expansion bus or the supply rail feeding a downstream module.
2. Why Hardware ID 276 Matters
Every device on the S7-1200 backplane is assigned a Hardware Identifier (HW ID) when the device configuration is compiled in TIA Portal. The identifier is referenced by:
- System constants in the user program (for example,
HW_DI_8x24VDC_HW_IDor a genericHW_IOsystem constant). - Diagnostic interrupt OB blocks (
OB82- diagnostic interrupt,OB83- module pull/plug,OB86- rack failure). - Diagnostic buffer entries written by the CPU firmware when a station error occurs.
For a CPU 1214C with the configuration described above, the typical HW ID allocation is:
| HW ID (typical) | Device |
|---|---|
| 0 | PROFINET interface of the CPU |
| 1 - 60 | PROFINET sub-modules and onboard I/O of the CPU |
| 64 - 127 | Onboard digital I/O byte/bit submodules |
| 128 - 255 | Onboard analog I/O channels |
| 256 - 511 | Signal module (SM) slots 1-8 in the central rack |
| 512 - 1023 | I/O channel submodules of the SMs |
HW ID 276 falls inside the 256-511 range, which means the diagnostic buffer entry points at the module header (the plug connector carrying the backplane signals) of a signal module, not at a specific channel. In a four-SM configuration, the slot number is calculated as (276 - 256) + 1 = 21, but the actual mapping depends on the firmware version and the slot order declared in the device configuration. In most real installations, HW ID 276 maps to SM slot 2, 3, or 4 - which is consistent with the reported four-SM stack and the user's observation that the error is reported against the SM row and not against a channel.
3. Reading the Diagnostic Buffer in TIA Portal
Open the project in TIA Portal, establish an online connection to the CPU (Ethernet or PROFIBUS depending on the gateway), then:
- Right-click the CPU in the project tree and select Go online > Online & diagnostics.
- Open the Diagnostics folder in the left navigation pane.
- Click Diagnostics buffer. The right pane lists timestamped events.
- Sort the table by the Time column descending and locate the most recent fault entry (it will be highlighted in the user's screenshot).
- Select the event row; the lower pane shows the Event ID, the affected HW ID, and a textual description.
The event IDs that most commonly appear behind an intermittent output reset with HW ID in the 256-511 range are:
| Event ID (hex) | Event text (paraphrased) | Trigger condition |
|---|---|---|
| 0x1381 | Station failure on module / sub-module | Module drop on the backplane, ribbon cable intermittent, connector vibration |
| 0x1382 | Station return after failure | Module re-appears within the configured monitoring time |
| 0x3942 | Diagnostics interrupt from module - channel fault | SM reports broken wire, overload, or short circuit |
| 0x39C1 | Diagnostics interrupt: supply voltage too low | 24 V at SM terminals collapses under load |
| 0x39C3 | Diagnostics interrupt: sensor supply short circuit | VS or Vaux short to M on a DO module |
| 0x135E | Module does not support configured parameters | Firmware mismatch between SM and CPU configuration |
| 0x130E | Module firmware update completed | Only relevant after a firmware update |
Capture the exact event ID from the diagnostic buffer, the OB that processed the interrupt (typically OB82 or OB86), and the timestamp. The OB assignment is the most useful single field: OB86 indicates a rack/submodule failure, which is the highest-probability event for the symptom described.
4. Root-Cause Matrix for the Symptom
The following matrix ranks the most likely root causes for a S7-1200 that auto-recovers from a station failure every 1-3 seconds while driving 2 converters from an AQ2 module.
| Rank | Root cause | Indicative evidence | First diagnostic step |
|---|---|---|---|
| 1 | Loose / vibrating ribbon cable between CPU and SM, or between adjacent SMs | Event ID 0x1381 paired with OB86; tactile click on module-to-module connector; vibration on the cabinet door | Power down, reseat every module, retighten the bus connector slide, power up, run a 24-hour no-fault test |
| 2 | Insufficient 24 V supply to a SM - 24 V dips under inrush from the converter AO loop | Event ID 0x39C1 / 0x39C3; SM LEDs briefly flicker; fault coincides with AQ update | Measure 24 V at the SM power terminals with an isolated oscilloscope (peak-to-peak ripple > 5 % triggers the diagnostic) |
| 3 | Firmware mismatch between SM 1223 / SM 1232 and the CPU firmware | Event ID 0x135E; the SM was added later; the CPU was updated | Check Online & diagnostics > Diagnostics > Module information for each module; update to the matching firmware in the TIA Portal HSP |
| 4 | AQ2 channel overload - driving a converter's analog input in parallel with another source | Event ID 0x3942; AQ fault LED; one converter setpoint is unstable | Disconnect the field wire, terminate the AQ with the manufacturer's test load, observe the diagnostic buffer |
| 5 | EMC-induced backplane noise from VFD or converter switching | Event correlates with converter output frequency or ramp | Verify shielded cable on the analog pair, 360-degree shield termination at the cabinet gland, separate 24 V DC and 400 V AC routes |
| 6 | Defective SM (intermittent internal failure) | All of the above ruled out; the fault follows the module when moved to another slot | Swap the suspect SM with a known-good spare; if the HW ID in the buffer changes, the original module is faulty |
5. Mechanical and Electrical Inspection Procedure
Run the following checks in the order shown. Stop the moment the fault becomes reproducible or reproducible-corrected - do not perform unneeded steps on energized equipment.
5.1 Power down and de-energize
- Place the controlled process in a safe state.
- Set the CPU mode switch to STOP.
- Open the main disconnect, lock out / tag out.
- Verify zero energy with a calibrated test instrument at the CPU power terminals (L+ / M).
5.2 Mechanical re-seat of the backplane
- Remove every signal module by pressing the release lever on the underside of the module.
- Inspect the ribbon bus connector on the right side of the CPU and on the right side of every SM. Look for oxidation, bent pins, or broken plastic.
- Re-seat each module firmly until the release lever clicks. The module must sit flush against the previous module - any visible gap means the bus is not engaged.
- Tighten the DIN-rail end brackets of the CPU and the SMs. The S7-1200 modules clip onto a 35 mm DIN rail but will slide under vibration; this is a known field issue.
5.3 Power supply verification
- Re-energize the 24 V DC supply to the CPU. The CPU should boot to STOP with no ERROR LED.
- Switch the mode selector to RUN. Wait 30 seconds and confirm no diagnostic buffer entry has been added.
- With the PLC online in TIA Portal, open Online & diagnostics > Diagnostics > Power supply (CPU 1214C reports the 24 V rail value). A reading below 19.2 V or above 28.8 V is a hardware issue on the supply side.
- Measure the 24 V at the L+ / M terminals of each SM with a multimeter. The tolerance is the same: 19.2 V to 28.8 V. The two converters drawing analog setpoint current from the SM 1232 AQ2 must not be back-fed through the 24 V rail - if they are, the SM's internal DC-DC will dip during converter inrush.
5.4 Analog output loop check
- Disconnect the field wires from the SM 1232 AQ2 channel 0 and channel 1.
- Connect a precision 250 Ω resistor (for 0-10 V test) or 500 Ω (for 4-20 mA test) across the channel terminals.
- Force a value of 50 % from the user program (write
27648into the corresponding%QWaddress using a watch table). - Measure the voltage or current with a calibrated meter. Compare with the diagnostic value reported in Online & diagnostics > I/O > Analog outputs. A deviation greater than 1 % indicates an overloaded or damaged channel.
- If the diagnostic buffer is now clean with the converter field wires removed, the converters are loading the AQ2 beyond its rated 600 Ω (voltage) or 500 Ω (current) capability. Move the converter analog input to a dedicated signal conditioner or a SM 1232 with current output.
6. Firmware Verification
Firmware version compatibility is a frequent source of station-failure events on the S7-1200. The CPU 1214C has been shipped in three hardware versions (FW 1.0, FW 2.0, FW 3.0 / 4.x) and each version requires SM firmware of the same major release line.
| CPU firmware | Compatible SM firmware | TIA Portal version |
|---|---|---|
| V1.0 (6ES7214-1AE30-0XB0) | V1.0 only | V11 / V12 SP1 |
| V2.0 (6ES7214-1AE31-0XB0) | V1.0 - V2.0 | V12 SP1 - V14 |
| V2.2 (6ES7214-1AG31-0XB0) | V2.0 - V2.2 | V13 SP1 - V15.1 |
| V3.0 (6ES7214-1AG40-0XB0) | V3.0 - V4.x | V15.1 - V17 |
| V4.1 / V4.2 (6ES7214-1AG40-0XB0) | V4.x | V15.1 - V18 |
To check the firmware of every module on the live system:
- Go online with the CPU.
- Open Online & diagnostics on the CPU and switch to Diagnostics > Module information.
- The CPU reports its own firmware in the header, and a list of the detected SMs below.
- Alternatively, in the project tree right-click the CPU, choose Online & diagnostics > Functions > Firmware update. The dialog enumerates the slots and shows the live firmware version of each.
If a SM 1223 DI8/DO8 reports firmware V1.0 against a CPU V3.0, the diagnostic interrupt OB82 will fire intermittently with event ID 0x135E. The fix is a HSP (Hardware Support Package) update of the TIA Portal installation to expose the matching firmware, followed by a firmware update of the SM using a SIMATIC memory card or the online firmware loader.
6ES7232-4HB32-0XB0) ships with firmware V1.0 and is only compatible with CPU firmware V2.0 and above. Mixing a V1.0 AQ2 with a V1.0 CPU is allowed but mixing a V2.x AQ2 with a V1.0 CPU is not. The S7-1200 web-based firmware update utility is documented in the SIMATIC S7-1200 Programmable Controller system manual, chapter "Firmware update".7. Set / Reset Instructions and Output Behavior
The S7-1200 firmware reacts to a station-failure event in a deterministic way: while the diagnostic interrupt OB82 / OB86 is being processed, the process image of the outputs is frozen to the last valid value. If the failure persists beyond the configured monitoring time (default 100 ms × 5 retries = 500 ms), the outputs of the missing module are forced to 0 by the system. The user program continues to run on the CPU, and the values written by the user into the %Q image become visible only after the module returns.
This is one of the most common sources of confusion: the user expects the S7-1200 to behave like a relay circuit and keep the last coil state. In reality, the system overwrites the output image for a failed station. If the user program uses SET and RESET instructions (or the bit-field instructions SET_BF and RESET_BF), the moment the station returns the bit-field values are re-written by the next scan, restoring the user-program intent. If the program uses S (set latching) instructions, the latched bit is preserved in the I/O image and the output returns to the latched value the instant the module recovers.
The behavior of the RESET_BF instruction is documented in the S7-1200 Basic Instructions manual:
"RESET_BF writes a data value of 0 to "n" bits starting at address tag OUT. When RESET_BF is not activated, OUT is not changed." - S7-1200 Basic Instructions - Set and Reset Instructions
In a station-failure scenario, the system acts like a software RESET_BF on the failed slot for the duration of the failure. Two practical implications follow:
- If the user program uses
S/Ron outputs that drive the converters via the SM 1232 AQ2, the AO value is reset to 0 mA / 0 V for the 1-3 second failure window. The VFD will interpret 0 V as a stop command (default for a 0-10 V reference on Siemens converters). The mechanical consequence is a motor decel-to-zero, then a re-accel when the module returns. - If the user program re-initializes the AQ2 every scan (writes the speed reference to
%QWfrom a continuous calculation), the value is restored the moment OB86 reports the station return and the next OB1 cycle writes the new image. The mechanical jerk is therefore bound to the OB86 monitoring time, not to the user-program scan time.
For critical applications, the recommended pattern is to wrap the AQ write in a RESET_BF latch and to use OB82 to suppress the converter enable until the SM has been healthy for at least 2 seconds. A reference implementation in SCL:
// SCL code - SM 1232 AQ2 station-failure debounce
// Place in OB1, run each scan
// Track the AQ2 health bit from OB82
IF #sm1232_fault_latch THEN
IF #sm1232_healthy_time_ms > 2000 THEN
#sm1232_fault_latch := FALSE;
END_IF;
ELSE
// Write the speed reference to AQ2
"AQ2_channel0" := #speed_ref_scaled;
END_IF;
// OB82 - diagnostics interrupt
IF #EventClass = OB82 AND #Fault_ID > 0 THEN
#sm1232_fault_latch := TRUE;
#sm1232_healthy_time_ms := 0;
"AQ2_channel0" := 0; // explicit RESET_BF on the analog value
END_IF;
// OB82 - fault cleared
IF #EventClass = OB82 AND #Fault_ID = 0 THEN
#sm1232_healthy_time_ms := 0;
END_IF;
8. TIA Portal Configuration Hardening
Beyond replacing the failing hardware, several project-level changes reduce the probability of a re-occurrence.
8.1 Module monitoring time
The S7-1200 backplane station monitoring time can be tuned in Device configuration > Properties > Module parameters > Module monitoring time. The default of 100 ms is conservative and triggers an OB86 on brief disturbances. Setting it to 250 ms accepts short transients but extends the recovery time. Do not exceed 1000 ms; the IEC 61131-3 cycle watchdog is 1500 ms and a longer monitoring time will push the CPU into STOP on the next transient.
8.2 Diagnostics interrupt enabling
For every SM, confirm that Diagnostics interrupt is checked in the module properties. Without this, OB82 will not fire and the user program has no way to debounce the failure. OB82 must exist in the project - if the program does not contain OB82, the CPU will go to STOP on the first diagnostics interrupt.
8.3 Time-of-day interrupt for cyclic diagnostics
Use a time-of-day OB (OB10) running every 10 minutes to copy the most recent diagnostic buffer into a data block. This is invaluable for post-incident analysis because the diagnostics buffer is volatile across a power cycle.
// OB10 - archive diagnostics buffer (every 10 min)
// Uses RD_SINFO and RD_DIAG instructions to read the last 10 events
// into a DB that is retained ("Non-retentive" = unchecked)
8.4 HMI alarm configuration
The HMI should display a non-clearable alarm when OB86 fires. In the KTP400 alarm configuration, create a discrete alarm bound to the sm1232_fault_latch tag with the priority "Error". The user can acknowledge the alarm only after the latch has been cleared by the program, which forces the operator to investigate rather than mute the alarm.
9. Wiring and Electrical Considerations
The two Siemens converters are powered from 400 V AC three-phase. The 0-10 V analog reference is generated by the SM 1232 AQ2 and runs on a shielded twisted pair back to the converter's analog input. Three wiring problems repeatedly cause intermittent station failures:
- Common-ground loops - the converter's 24 V control supply and the PLC's 24 V supply share the same -V rail, but the converter's 0-10 V return is tied to its chassis. If the cabinet PE is not a single star-point, circulating currents modulate the AQ2's reference. Fix: insert an isolated signal conditioner (Phoenix Contact MINI MCR or WAGO 857) between the AQ2 and the converter's analog input.
- Missing shield termination - the analog cable shield must be terminated 360 degrees at the cabinet gland, not pinned to a terminal. A "pigtail" termination acts as an antenna for the VFD switching noise and injects common-mode voltage on the AQ2, which can corrupt the backplane through the SM's ground reference.
- 24 V DC and 400 V AC routed together - the cable duct layout must enforce a minimum 200 mm separation between 24 V DC and any 400 V AC cable for the entire run. A SM adjacent to a long parallel run of 400 V AC picks up capacitive coupling and the SM's internal DC-DC converter can hiccup, registering as a station failure.
10. Verification Procedure
After the corrective action is complete, run the following verification sequence to confirm the fault has been resolved.
- Power cycle the complete PLC rack. The CPU should boot to RUN with the existing project.
- Open TIA Portal, go online, open the diagnostic buffer, and clear the existing entries (right-click > Clear buffer).
- Drive the system through a full operating cycle that includes the operations that previously triggered the fault (converter speed changes, HMI parameter writes, digital output toggles).
- After 24 hours of continuous operation, re-open the diagnostic buffer. There should be no OB82 / OB86 entries related to HW ID 276.
- Record the diagnostic buffer snapshot from the project archive for traceability.
11. Preventive Maintenance Schedule
| Interval | Action |
|---|---|
| Monthly | Walk the cabinet and confirm all module release levers are flush; verify the 24 V DC rail voltage at the CPU and at each SM. |
| Quarterly | Download the diagnostic buffer from the CPU to a memory card or to TIA Portal; archive with the maintenance log. |
| Annually | Open the cabinet and physically inspect the ribbon bus connectors for oxidation. Reseat each SM one at a time with the power off, then power up and verify the CPU goes to RUN without diagnostic buffer entries. |
| Every firmware update | Update the SM firmware to match the CPU firmware major release line. Document the versions in the project header. |
12. When the Fault Persists
If the diagnostic buffer continues to record station failures on the same HW ID after all of the above steps, the most likely remaining cause is a defective SM. Swap it with a known-good spare. If the spare also fails in the same slot, the backplane connector on the CPU is the suspect. If the spare works, the original SM has an internal intermittent - replace it.
For installations where downtime is critical, order a pre-flashed spare SM with the matching firmware. The S7-1200 supports in-rack firmware update using a SIMATIC memory card, so the spare can be brought to the correct firmware version offline.
For further official documentation, refer to:
- SIMATIC S7-1200 Programmable Controller - System Manual (entry ID 109767171) on the Siemens Industry Online Support portal.
-
S7-1200 Basic Instructions - Set and Reset Instructions for the
SET_BFandRESET_BFsemantics. - S7-1200 Function Manuals (entry ID 109751216) for diagnostic interrupt OB82 and station failure OB86 handling.
What does Hardware ID 276 mean on an S7-1200 CPU 1214C?
HW ID 276 falls in the 256-511 range assigned to signal module (SM) headers on the central rack. It identifies the module that reported the station failure, not a specific channel. Open Device configuration > System constants in TIA Portal to read the exact slot number and module description associated with the ID in your project.
Why do all S7-1200 outputs reset when a single signal module fails?
When the S7-1200 detects a station failure it calls OB86 and zeroes the process-image outputs of the affected module for the duration of the failure. The system behaves like a RESET_BF on the missing slot. The user program's S (set) latches remain in the I/O image but are not driven onto the field until the station returns.
How do I read the diagnostic buffer on an S7-1200?
Go online with the CPU in TIA Portal, right-click the CPU, choose Online & diagnostics > Diagnostics > Diagnostics buffer. The list shows event ID, OB that processed the interrupt, HW ID, and timestamp. The most useful field is the OB number: OB82 indicates a diagnostics interrupt, OB86 indicates a rack/submodule failure.
Can a loose ribbon cable between signal modules cause the CPU ERROR LED to flash red?
Yes. A loose or oxidized ribbon bus connector on the right side of a SM is the most common cause of intermittent station-failure events on the S7-1200. The fault clears in 1-3 seconds when the connector briefly reconnects, which matches the symptom described. Power down, reseat every module, retighten the DIN-rail end brackets, and re-test.
How do I match SM firmware to the CPU firmware on the S7-1200?
Read the CPU firmware under Online & diagnostics > Functions > Firmware update, then compare the live SM firmware shown in the same dialog against the SM's required major version. If they are out of line, install the matching HSP in TIA Portal, then update the SM using a SIMATIC memory card or the online firmware loader. Mixing V1.x SMs with V3.x / V4.x CPUs is not supported and triggers event 0x135E in the diagnostic buffer.
How do I stop the converters from coasting when the SM 1232 AQ2 drops out?
Implement a debounce in OB82 that sets a fault latch for at least 2 seconds before re-enabling the AQ write. While the latch is set, force the AQ2 value to 0 (a software RESET_BF equivalent). After the latch is cleared, write the speed reference back to the AQ2. The SCL reference implementation is provided in section 7 above.