1. Problem Description and Field Symptoms
When a Rosemount PT100 temperature transmitter (TT) with a 4-20 mA output is wired directly to a Siemens SIMATIC S7-300 analog input module (SM 331, order number 6ES7 331-7KF02-0AB0), engineers frequently report three categories of fault:
- Unstable readings: the engineering value oscillates by several degrees Celsius even though the process is steady.
- Wrong readings: the displayed value is consistently offset or pinned to the upper/lower rail of the measuring range.
- Intermittent total failure: the channel goes to overrange, underrange, or reports open wire (diagnostic interrupt) only after a few days in service.
In the vast majority of these field cases, the root cause is not the transmitter but the combination of (a) wrong measuring range module position on the side of the SM 331, (b) wrong wiring for 2-wire vs 4-wire transmitters, (c) the Mana terminal not being jumpered to M of the module, and (d) channels that are wired but not configured in STEP 7 (or vice versa). This article walks through each of these root causes using the S7-300 Module Data reference manual as the authoritative source.
2. Module Identification: SM 331 AI 8x12Bit (6ES7 331-7KF02-0AB0)
The module in the fault report is the SM 331 analog input, 8 channels, 12-bit resolution, with diagnostic and hardware interrupt capability. The full Siemens order number is 6ES7 331-7KF02-0AB0. Key specifications from the S7-300 Module Data manual:
| Parameter | Value |
|---|---|
| Order number (MLFB) | 6ES7 331-7KF02-0AB0 |
| Number of inputs | 8 |
| Channel groups | 4 (channels 0/1, 2/3, 4/5, 6/7) |
| Resolution (voltage/current) | 12 bits + sign (13 bits effective) |
| Resolution (RTD/TC) | 14 bits + sign (15 bits effective) |
| Supported current ranges | 0-20 mA, 4-20 mA, ±20 mA |
| Supported voltage ranges | ±80 mV, ±250 mV, ±500 mV, ±1 V, ±2.5 V, ±5 V, 0-5 V, ±10 V |
| Galvanic isolation | Yes (to backplane bus; groups not isolated from each other) |
| Diagnostic interrupt | Configurable (open wire, overflow, underflow, wire break on 4-20 mA) |
| Measuring range module | 4 mechanical selectors, one per channel group, on the left side of the module |
| Supply to 2-wire transmitter | 24 V from module (L+ terminal) — up to 25 mA per channel |
Each channel group is configured by a small plug-in measuring range module located on the side of the SM 331. To access these, the SM 331 must be removed from the DIN rail (or at least pulled out of the ET 200/S7-300 rack far enough to expose the four small square headers). The position of the measuring range module MUST match the type of input wired to that group. STEP 7 hardware configuration (HW Config) and the mechanical position MUST agree — if they disagree, the channel returns either 7FFFh (overrange) or 8000h (underrange), or the analog value is incorrect because the input multiplexer is set up for a different range.
3. 2-Wire vs 4-Wire Transmitter: The Critical Distinction
The first decision point is whether each Rosemount PT100 transmitter is a 2-wire or 4-wire instrument. This determines (a) how the 24 VDC supply gets to the transmitter electronics and (b) which measuring range module position is required.
3.1 4-Wire (self-powered) Transmitter
A 4-wire transmitter has a separate mains or 24 VDC supply powering its internal electronics. The transmitter is fed from a dedicated power supply on the L+/M terminals of the head, and only the two signal wires (signal+ and signal-) run back to the AI module. The SM 331 sees a passive current source. Measuring range module position for 4-wire current 0/4-20 mA is position A. STEP 7 HW config: Measuring type = Current, Measuring range = 4-20 mA (or 0-20 mA).
3.2 2-Wire (loop-powered) Transmitter
A 2-wire transmitter draws its operating current from the AI module itself. The module sources 24 VDC out on the channel terminal; the transmitter regulates the loop current between 4 and 20 mA back to the module. Only two wires connect the transmitter to the AI module. Measuring range module position for 2-wire current 0/4-20 mA is position D. STEP 7 HW config: Measuring type = Current, Measuring range = 4-20 mA (or 0-20 mA), 2-wire mode enabled.
4. Measuring Range Module Position and Channel Group Mapping
For the 6ES7 331-7KF02-0AB0, the four measuring range modules on the side of the module each control one channel group:
| Channel group | Channels | Selector label on side of module |
|---|---|---|
| Group 0 | AI0 / AI1 | Top selector |
| Group 1 | AI2 / AI3 | Second selector |
| Group 2 | AI4 / AI5 | Third selector |
| Group 3 | AI6 / AI7 | Bottom selector |
The letter on the side of the selector must match the type of input wired to that group. For the SM 331 AI 8x12Bit (6ES7 331-7KF02-0AB0), the positions for current measurement are:
| Position | Type | Notes |
|---|---|---|
| A | Voltage (±80 mV ... ±10 V, 0-5 V, 0-10 V) | Default factory position |
| B | 4-wire current 0/4-20 mA, ±20 mA | Used for self-powered 4-wire transmitters |
| C | Not used / reserved for 4DMU (4-wire only on some firmware) | Verify against the manual sticker on the module |
| D | 2-wire current 0/4-20 mA, RTD, Thermocouple | Used for loop-powered 2-wire transmitters |
If the position is wrong:
- Power down the S7-300 station.
- Remove the SM 331 from the rack.
- Inspect the four small white square selectors on the left side of the module housing.
- Pull each selector out with small pliers, rotate to the correct position (A / B / C / D), and reinsert.
- Reinstall the module, then go online with STEP 7 and read the diagnostic buffer. A position mismatch in the field will appear as "Measuring range module position error" or the channel will report 7FFFh.
5. Wiring the 4-20 mA Loop
5.1 Terminal Layout for 6ES7 331-7KF02-0AB0
The SM 331 has 20 front-panel screw terminals. The terminal assignments for current input are:
| Terminal | Signal | Function |
|---|---|---|
| 1 | AI0+ | Channel 0 positive input |
| 2 | AI0- | Channel 0 negative input |
| 3 | AI1+ | Channel 1 positive input |
| 4 | AI1- | Channel 1 negative input |
| 5 | AI2+ | Channel 2 positive input |
| 6 | AI2- | Channel 2 negative input |
| ... | ... | ... |
| 19 | COMP+ | Compensation for TC |
| 20 | COMP- | Compensation for TC |
The Mana terminal is the analog ground reference for the module. On the 6ES7 331-7KF02-0AB0, Mana is the screw terminal strip between the input channels and the backplane connector. It MUST be jumpered to M of the load voltage supply (24 VDC return of the S7-300 power supply, terminal M on the PS).
5.2 Wiring Diagram — 2-Wire Transmitter (4-20 mA)
Rosemount PT100 (2-wire) SM 331 (6ES7 331-7KF02-0AB0)
+-------+
| TT |
| |
| + ----------------+------ Terminal 1 (AI0+) <- signal+
| | |
| - ----------------+------ Terminal 2 (AI0-) <- signal- / 24V return from module
+-------+ Measuring range module Group 0 = Position D
Mana ------------------ M of PS 307 (24V return)
Measuring range module Group 0 = Position D
For a 2-wire transmitter, the module sources 24 VDC on the AI0+ / AI0- pair, the transmitter regulates the loop current to 4-20 mA, and the same pair carries the signal back. No external 24 V supply is required at the transmitter head.
5.3 Wiring Diagram — 4-Wire Transmitter (4-20 mA)
External 24 VDC Supply Rosemount PT100 (4-wire) SM 331 (6ES7 331-7KF02-0AB0)
+ ----------------+------ L+ of TT
- ----------------+------ M of TT
+-------+
| TT |
| |
| Sig+ ---- Terminal 1 (AI0+)
| |
| Sig- ---- Terminal 2 (AI0-)
+-------+
Measuring range module Group 0 = Position B
Mana ------------------ M of PS 307 (24V return)
For a 4-wire transmitter, the transmitter electronics are powered from a separate 24 VDC source (or 110/230 VAC mains through a local PSU). The signal pair is fully isolated from the power pair. The SM 331 only sees the regulated 4-20 mA current loop.
6. Mana Connection and Grounding
The Mana terminal is the most common root cause of unstable analog readings on the S7-300. According to the S7-300 Module Data manual, chapter 6, the Mana terminal must be connected to the M terminal of the S7-300 power supply (PS 307 / PS 305) with a low-impedance link. If Mana is left floating:
- The analog input common-mode voltage is undefined.
- Any coupled noise on the cable shield or on the transmitter power line appears directly at the ADC input.
- Readings will wander by tens of counts, especially on long cable runs near VFDs or contactors.
7. STEP 7 Hardware Configuration (HW Config)
After the wiring is in place and the measuring range modules are set, the next step is to configure the SM 331 in STEP 7. Open the SIMATIC Manager, navigate to the S7-300 station, open HW Config, and double-click the SM 331. For each channel group, the required settings are:
| Parameter | Value for 4-20 mA, 2-wire PT100 TT | Value for 4-20 mA, 4-wire PT100 TT |
|---|---|---|
| Measuring type | Current (I) | Current (I) |
| Measuring range | 4-20 mA | 4-20 mA |
| 2-wire / 4-wire | 2-wire (loop-powered) | 4-wire (external supply) |
| Integration time / noise rejection | 60 Hz (for North America) or 50 Hz (for Europe/Asia) | Same |
| Diagnostic interrupt | Enable (open wire detection) | Enable (open wire detection) |
| Hardware interrupt on limit | Disable unless required | Disable unless required |
| Measuring range module position | D | B |
Click "OK" and save + compile the HW Config. Download the configuration to the CPU. If there is a mismatch between the STEP 7 setting and the actual measuring range module position on the side of the module, the CPU will report "I/O access error" and the diagnostic buffer will contain entry "Module error in slot X — measuring range module position Y does not match configuration".
8. Scaling the Raw Value to Engineering Units
The SM 331 returns a 16-bit integer (0 to 27648 for unipolar ranges, -27648 to +27648 for bipolar ranges). For a 4-20 mA input the mapping is linear:
I (mA) = (Raw / 27648) * 16 + 4
Once the mA value is computed, the temperature is recovered with the transmitter-specific scaling. The original report mentions a Rosemount PT100 TT scaled 0-600 °C, 4-20 mA. Using the Siemens FC105 "SCALE" block (or the IEC variant FC106 / NORM_X and SCALE_X):
// Inputs to FC105
IN := PIW256 // raw value from SM 331
HI_LIM := 600.0 // engineering value at 20 mA
LO_LIM := 0.0 // engineering value at 4 mA
BIPOLAR:= FALSE // unipolar 0-27648
RET_VAL := MW100 // FC105 return code
OUT := MD104 // temperature in degrees C (REAL)
For a bipolar range (±20 mA) the input limits are -27648 and +27648. For a 0-20 mA range the lower engineering value corresponds to 0 mA. For a 4-20 mA range the lower engineering value corresponds to 4 mA; a raw value of 0 mA (less than 0.0 in the unipolar map) means the loop is broken and the channel is in the underrange diagnostic state. Siemens S7-300 AI documentation recommends that 4-20 mA ranges be preferred over 0-20 mA specifically because of the broken-loop detection capability.
9. Open-Wire Detection and Diagnostic Behavior
The SM 331 with order number 6ES7 331-7KF02-0AB0 supports open-wire detection on 4-20 mA ranges. When enabled in HW Config, the module monitors the loop current continuously. If the current drops below approximately 1.185 mA (the "open wire" threshold for the 4-20 mA range), the module:
- Sets the channel value to 7FFFh (overrange) or 8000h (underrange) depending on the direction of the deviation.
- Fires a diagnostic interrupt (OB82).
- Writes the diagnostic event to the diagnostic buffer of the CPU (accessible via STEP 7 / TIA Portal online > module information > diagnostics tab).
The same open-wire threshold is documented across the Siemens SIMATIC analog input family. The 1.185 mA threshold value is also documented in the SM 1231 (S7-1200) specification sheet as the open-wire trip point for the 4-20 mA range. SM 1231 analog input module specifications. Use this as cross-reference when comparing the S7-300 SM 331 behavior to the S7-1200 SM 1231.
Field experience: a channel that is wired to a transmitter but reports intermittent open-wire diagnostic a few days after commissioning is almost always a loose terminal screw, a corroded terminal, or a transmitter whose loop voltage compliance is insufficient for the cable resistance. With a Rosemount 4-wire PT100 TT, a 24 VDC supply, and a cable run under 200 m of 1.0 mm² shielded twisted pair, compliance is normally not an issue — the suspect is the screw terminal.
10. Unused Channels
Per the S7-300 Module Data manual, unused channels on a SM 331 must be configured in HW Config. The recommended setting is "Measuring type = Voltage, Measuring range = ±10 V" with diagnostics disabled, and the channel input must be shorted (a jumper from AI+ to AI- on the front connector). This prevents the channel from floating and emitting phantom diagnostic interrupts every scan cycle. The S7-300 Module Data manual states this requirement explicitly in chapter 6, section "Unused channels".
11. Troubleshooting Matrix
| Symptom | Likely Root Cause | Verification | Remediation |
|---|---|---|---|
| Channel value = 7FFFh (overrange, +32767) | Measuring range module position wrong, OR transmitter loop current > 20 mA, OR sense wires swapped on RTD | Pull module, inspect position. Measure loop current with multimeter in series. | Re-seat selector to correct position. Reverse sense wires. Replace faulty transmitter. |
| Channel value = 8000h (underrange, -32768) | Loop broken (open wire), OR 2-wire transmitter without 24 V from module, OR transmitter set to 0-20 mA but PLC expects 4-20 mA | Measure voltage at the AI terminals with no transmitter. Check STEP 7 measuring range config. | Replace selector to position D for 2-wire. Restore wire. Re-configure STEP 7 to match transmitter output. |
| Unstable reading (jitters ±20 °C) | Mana not connected, shield not grounded at one end only, or 50/60 Hz noise coupling | Verify Mana → M of PS 307. Check shield termination. Check integration time setting. | Add Mana jumper. Re-terminate shield. Set integration time to 50/60 Hz. |
| Wrong reading (constant offset, e.g. reads 25 °C when process is 200 °C) | Wrong scaling (LO_LIM / HI_LIM in FC105), OR transmitter not ranged to 0-600 °C as expected, OR wrong loop range (0-20 vs 4-20) | Inject 4 mA and 20 mA from a calibrator. Read back the engineering value. | Correct FC105 LO_LIM / HI_LIM. Re-range transmitter. Re-configure STEP 7 measuring range. |
| Reads correctly for a few days, then drifts / fails | Loose terminal, thermal cycling of a bad crimp, or transmitter running out of compliance due to cable resistance increase from corrosion | Re-torque all AI terminals to 0.6 Nm. Measure loop voltage at transmitter. Measure cable resistance. | Re-terminate with ferrules. Replace cable. Add local 24 VDC booster at the transmitter head. |
| Diagnostic interrupt OB82 fires for unused channel | Channel left "deactivated" but not shorted, OR configured as 0-10 V but left floating | Read OB82 start info — note the channel number. | Configure unused channel as ±10 V and short AI+/AI- at the front connector. |
| Channel reports "Measuring range module position error" | Mechanical selector position does not match STEP 7 configuration | Compare selector letter to HW Config setting for that group. | Pull module, reset selector, reinstall. |
12. Verification Procedure
After wiring, range module, Mana jumper, and STEP 7 configuration are all in place, perform the following verification sequence before returning the loop to service:
- Power down the S7-300 station.
- Re-torque every screw terminal on the SM 331 to 0.6 Nm with a calibrated torque driver.
- Verify the Mana jumper is in place between the SM 331 Mana terminal and the M terminal of the PS 307.
- Verify each unused channel has its AI+ and AI- terminals shorted at the front connector.
- Power up. In STEP 7, go online > Module Information > Diagnostics. Confirm no diagnostic events are present.
- Open a VAT or watch table on the PIW for each active channel. Read the raw integer value.
- Disconnect the transmitter wires from one channel. Confirm the raw value goes to 7FFFh and OB82 fires (if diagnostic interrupt is enabled). Reconnect.
- Inject 4.000 mA and 20.000 mA from a calibrated mA source into each channel in turn. Confirm the engineering value reads LO_LIM and HI_LIM respectively.
- Return the transmitter wiring to service. Monitor the engineering value for 24 hours. Confirm stability within ±1 LSB of the converter.
13. Safety and Field-Commissioning Notes
- The SM 331 (6ES7 331-7KF02-0AB0) is a Class I Div 2 / ATEX Zone 2 compatible device when installed in a S7-300 rack. Always conform to the safety instructions in chapter 1 of the S7-300 Module Data manual.
- The module's 24 VDC supply to a 2-wire transmitter is current-limited to approximately 25 mA per channel. A short circuit on a 2-wire loop will not damage the module but will force the channel into overrange.
- If the process being measured is in a hazardous area, the transmitter and the cable must be certified for the zone. The SM 331 is the safe-area side of the loop; it does not provide isolation for hazardous-area installation by itself.
- Use shielded twisted pair (e.g. Belden 8761 or equivalent) for the analog signal cable. Ground the shield at the cabinet end only, on the S7-300 ground bar. Do not ground the shield at the transmitter end.
- Separate the analog signal cable from any VFD power cable by at least 200 mm in the cabinet tray. Cross at 90° if a crossing is unavoidable.
14. Cross-Reference: Differences vs S7-1200 SM 1231
Engineers migrating from S7-300 to S7-1200 frequently ask whether the SM 331 and the SM 1231 behave identically. The diagnostic philosophy is the same, but the part numbers, channel count, and resolution differ. The SM 1231 open-wire threshold on 4-20 mA is also approximately 1.185 mA (less than -4864 raw), documented in the SM 1231 spec sheet. SM 1231 analog input module specifications. The mechanical measuring range module on the side of the SM 331 is replaced in the SM 1231 by software-only configuration in TIA Portal. For wiring only, the terminal layout, the Mana / M ground reference, and the 2-wire / 4-wire distinction are unchanged.
Is it safe to wire 2-wire and 4-wire transmitters on the same SM 331 (6ES7 331-7KF02-0AB0)?
Yes, as long as each 2-channel group is configured for one type only. Channel group 0 (AI0/AI1) must be either all 2-wire or all 4-wire — the measuring range module is set per group, not per channel. Mixing 2-wire on AI0 and 4-wire on AI1 in the same group is not supported by the module.
What happens if the measuring range module position does not match the STEP 7 configuration?
The module enters the diagnostic state and the channel value is invalid (typically 7FFFh). The CPU diagnostic buffer records a "module error / measuring range module position" entry. To recover, power down, remove the module, reset the selector, reinstall, and power up.
Why does my 4-20 mA reading wander by several degrees even with a stable process?
The two most common causes are a floating Mana terminal (no connection to M of the PS 307) and a shield that is grounded at both ends. Tie Mana to the S7-300 PSU M terminal, ground the shield at the cabinet end only, and re-test.
What is the raw count for 4 mA on the SM 331 AI 8x12Bit?
The unipolar range maps 0 mA to 0 decimal and 20 mA to 27648 decimal. Linear interpolation gives 4 mA as 0 + (4/20) * 27648 = 5530 decimal. A raw value of 0 on a 4-20 mA configured channel indicates a broken loop and is the basis for open-wire detection.
Do I need to short unused channels on the SM 331?
Yes. Unused channels must be configured in HW Config as ±10 V voltage and the front-panel AI+ / AI- terminals must be shorted together. This prevents floating-channel diagnostic interrupts from flooding the CPU.