Problem Symptom Summary
Engineers commissioning SIMATIC S7-400 stations equipped with the SM 431 analog input module, MLFB 6ES7 431-0HH00-0AB0, frequently report a twin-symptom pattern that survives every standard check the CPU diagnostic buffer offers:
- With the measuring-range selector on the side of the module set to position D and the channel configured in STEP 7 for 2-wire 4-20 mA, every channel returns the saturated value +32767 (0x7FFF) regardless of what is connected at the terminals. The loop is not 'broken' in the wiring sense - the 2-wire transmitter powers up and the field device indicates a value on its local display.
- With the selector set to position B and the channel configured in STEP 7 for +/-10 V, the raw input word reads roughly -8 counts (0xFFF8) with no signal applied and 0 counts (0x0000) for any input between 0 V and approximately 8.5 V. Above 8.5 V the word latches to overflow.
- The CPU SF (group fault) LED, the module SF LED, and the diagnostic buffer all remain clear. The two 16-channel SM 431s - including the channels that have been software-deactivated - all behave identically.
Every one of these symptoms is the signature of a single, common, mechanical configuration mismatch on the SM 431 hardware. The remainder of this reference walks through the diagnostic, the root cause, the recovery procedure, and the field-proven caveats observed on S7-400 stations from AS 414 to AS 416F.
Module Identification and Key Specifications
Before any troubleshooting step is taken, confirm the module order number. The 0HH00 version is the 16-channel, 13-bit isolated SM 431, and its measuring-range selector behaviour differs from the 1KF-series 8-channel modules. The full MLFB breakdown is 6ES7 431-0HH00-0AB0, with each segment carrying a specific meaning:
| Segment | Decoding |
|---|---|
| 6ES7 | SIMATIC S7 product family |
| 431 | SM 431 analog input |
| 0 | Floating, 16 AI group |
| HH | 16 channels, 13 bit + sign, no HART |
| 00 | Standard speed / standard firmware |
| 0AB0 | Hardware release 0, product release 0 |
Critical electrical and functional parameters that drive this fault pattern:
| Parameter | Value | Notes for troubleshooting |
|---|---|---|
| Number of analog inputs | 16 | 4 groups of 4 channels; each group has its own selector switch |
| Resolution | 13 bit + sign | Range +/-10 V: 1 LSB = 20 V / 8192 = 2.44 mV |
| Galvanic isolation | Yes, to backplane; channels grouped 4+4+4+4 | Mana (analog ground) is common within a group, isolated between groups |
| Internal loop power supply | None | 2-wire 4-20 mA requires an external 24 V supply |
| Maximum current input voltage | 2.5 V sustained | Applying >2.5 V to a current input burns the 250 ohm shunt |
| Measuring range selection | Mechanical slide switch per group | Located on the side of the module housing; not visible from the front |
| STEP 7 integration path | HW Config > SIMATIC 400 Station > AI-300/SM-431 | HSP bundled in STEP 7 V5.5+ and TIA Portal V13+ |
| Overflow (overrange) word | 0x7FFF / +32767 | All Siemens AI: input above configured range |
| Underflow (underrange) word | 0x8000 / -32768 | 4-20 mA: current below 4 mA (wire break signature) |
| Diagnostic interrupt | Configurable per channel | Default is 'no diagnostic'; must be enabled in HW Config for SF LED activation |
Reference the official SIMATIC S7-400 SM 431 Manual on the Siemens Industry Online Support portal for the full specification. For S7-400F / fail-safe applications, see the S7-400F Automation System product page for group-fault propagation rules.
Why 32767 Means Open Loop or Wrong Range
The SM 431 reports a fixed overrange value of 0x7FFF when the analog input signal is above the configured range maximum. The underrange value is 0x8000 (decimal -32768). For a 4-20 mA input, 'above range' can mean two physically different things:
- Wire break / open loop: the input current collapses to 0 mA. The 4 mA live zero is missing, and the input is below the 4 mA floor of the configured range. The S7-400 firmware returns the underrange value 0x8000, not 32767. So a 0x7FFF read-out on a 4-20 mA channel does not mean wire break; it means the input sees a current or voltage above the configured maximum, or the input is connected to a range where 0 mA is interpreted as overflow.
- Wrong range selection: the measuring-range slide switch is set to a position that the firmware cannot use for the configured input. For 2-wire 4-20 mA on this module, the switch must be in position B with the HW-Config measuring range '4-20 mA' selected. If the switch is in position D (4-wire RTD), the input path is routed through the resistance-measurement front end, not the current shunt. The 4 mA current is too small to be detected as a resistance change and is read as overflow.
The classic 32767 symptom therefore has three possible root causes, in order of frequency:
- Selector switch position does not match the configured measuring range (most common).
- 2-wire loop is not closed: loop power is missing, the +24 V wire is open, or the transmitter output is in fault.
- Channel is configured as 'deactivated' in STEP 7. By default, deactivated channels return 0x7FFF on this firmware. Check HW Config > Object Properties > Inputs > 'Deactivated' tick-box.
For the +/-10 V symptom set, the dominant causes are:
- Selector switch in the wrong position, with the voltage front end shorted through a current-mode shunt (e.g. switch in C or D, configured for voltage).
- Field cable shield bonded at both ends inducing common-mode current that pushes Mana outside the +/-1 V tolerance of the input front end.
- Input terminals reversed at the connector (M+ and M- swapped), driving a negative offset that offsets the entire transfer curve.
- Module connector not fully seated: a half-inserted front connector produces a small bias of 0-15 mV which presents as -8 counts and zero for signals up to the offset value.
Measuring-Range Selector Switch: The Hidden Configuration
The most distinctive feature of the SM 431 family is the four mechanical slide switches on the left-hand side of the module housing. Each switch selects the analog front-end circuitry for one group of four channels. The switch has multiple detent positions; the switch must be set on the hardware itself - STEP 7 cannot read or override it. Switch-to-channel mapping for the 6ES7 431-0HH00-0AB0:
| Switch | Channels | Pos A | Pos B | Pos C | Pos D |
|---|---|---|---|---|---|
| SW1 | 0-3 | +/-1 V | +/-10 V / 0-10 V / 4-20 mA / 0-20 mA | TC / +/-80 mV | Pt100 / Pt1000 / 0-600 ohm (4-wire) |
| SW2 | 4-7 | +/-1 V | +/-10 V / 0-10 V / 4-20 mA / 0-20 mA | TC / +/-80 mV | Pt100 / Pt1000 / 0-600 ohm (4-wire) |
| SW3 | 8-11 | +/-1 V | +/-10 V / 0-10 V / 4-20 mA / 0-20 mA | TC / +/-80 mV | Pt100 / Pt1000 / 0-600 ohm (4-wire) |
| SW4 | 12-15 | +/-1 V | +/-10 V / 0-10 V / 4-20 mA / 0-20 mA | TC / +/-80 mV | Pt100 / Pt1000 / 0-600 ohm (4-wire) |
The fact that position B handles both voltage and current sub-ranges is why the HW Config measuring range must be set to match. The selector on the module and the measuring range in HW Config are both required, and both must agree on the same group of four channels.
For a 2-wire 4-20 mA transmitter, the operator must set the selector switch to B on the housing and choose 'Current / 4-20 mA' in HW Config. For a 4-wire RTD, the selector is D and the HW Config range is 'Resistance / Pt100 (4-wire)'. Mixing them gives the symptoms described.
2-Wire vs 4-Wire Transmitter Wiring
The SM 431 does not provide loop power to 2-wire transmitters. The user must supply a regulated 24 V DC source in the loop. The correct topology for a 2-wire 4-20 mA field device is:
For a 4-wire transmitter (separate loop-power pair and signal pair), the topology simplifies: the 24 V supply goes directly to the transmitter's '+V' and 'GND' terminals, and the 4-20 mA signal comes back on two dedicated wires to the SM 431 M+ and M-. The selector is still position B; HW Config is still 'Current / 4-20 mA'.
- Transmitter 'signal -' tied to chassis ground at the field device and at the SM 431 Mana. This creates a 0.1-2 V ground loop that pushes the input above the 20 mA ceiling. Remove the field-side ground and let the SM 431 Mana define the reference.
- Cable shield bonded at both ends. Cut the shield at the field device; bond it once at the cabinet backplate.
- Reversed polarity. 2-wire transmitters reverse-polarity-protect by blocking current, not by surviving it. The transmitter appears dead, the SM 431 reads overflow because the loop is open. Check with a clamp meter: 4 mA flowing indicates correct polarity.
- Loop resistance > 600 ohm. The 24 V supply cannot drive 20 mA through 1200 ohm, so the transmitter saturates at 12-15 mA and the SM 431 reads above range. Either shorten the cable, increase the supply to 26-28 V, or use a 4-wire transmitter.
STEP 7 Hardware Configuration
After the physical switches are correct, the HW Config in STEP 7 (or TIA Portal) must be set to the same measuring range. The procedure in STEP 7 V5.5+ is:
- Open the SIMATIC 400 station in HW Config.
- Locate the SM 431 in slot n of the rack; double-click the module to open Object Properties.
- Switch to the Inputs tab. The 16 channels appear as 4 channel groups (0-3, 4-7, 8-11, 12-15).
- For each channel group that is in use, set:
- Measurement type: Voltage or Current (4-wire / 2-wire is a property of the field wiring, not a HW Config setting - the module's terminal wiring handles the difference).
- Range: 4..20 mA, 0..20 mA, +/-10 V, 0..10 V, +/-5 V, 1..5 V, etc.
- Interference frequency: 50 Hz or 60 Hz. The 50 Hz setting integrates over 20 ms and gives the best 50 Hz mains rejection; 60 Hz does the same for 60 Hz systems. Wrong setting causes a 0.1-0.3% ripple in the reading.
- Smoothing: none / weak / medium / strong. 'Strong' applies a 4th-order filter and a 1.6 s settling time; do not use on a closed control loop unless the loop tuning accounts for it.
- Diagnostic interrupt: enable. Without this, wire breaks do not raise a CPU diagnostic.
- For channels that are not in use, select Deactivated. This stops the channel from being scanned; the only way to make it return 0x8000 instead of 0x7FFF. The default for an unconfigured channel on the SM 431 is 0x7FFF (overflow), and a 'deactivated' channel returns 0x8000 (-32768) on this firmware. If you observe 32767 on every channel including the ones you have marked Deactivated, the configuration has not been re-downloaded to the CPU.
- Save, compile, and download the HW Config to the CPU. The 6ES7 431-0HH00-0AB0 requires a STOP-to-RUN transition or a power cycle to re-read the selector switch; HW Config changes alone do not take effect.
For TIA Portal V16+, the same steps apply under Device view > SM 431 > Properties > Analog inputs > Channels. The STEP 7 Professional manual on the Siemens Industry Online Support covers the HW Config tree in detail.
STEP 7 Online Diagnostics and Error Codes
When the module is in RUN and the selector/HW Config are aligned, the following online tools confirm proper operation:
- HW Config > Module Information > Diagnostics: the SM 431 returns no diagnostic interrupts on a healthy channel with a valid input. If wire break is enabled, a 4-20 mA channel with a broken wire returns DS0 = 0x0001 (wire break) and DS1 = 0x0000, plus a diagnostic interrupt OB82.
- Monitor / Modify > VAT table: read the input word directly in hex. 0x7FFF is overflow, 0x8000 is underflow, 0x7FFE is 'just below overflow' (e.g. 19.99 mA on 4-20 mA range).
-
CPU diagnostic buffer: enter 'OB82' in the filter to surface module-fault events. The SM 431 raises OB82 on:
- Wire break on 4-20 mA (DS0 bit 0)
- Overrange on any input (DS0 bit 1)
- Underrange on any input (DS0 bit 2)
- Parameter assignment error (DS0 bit 3) - typically a selector/HW Config mismatch on power-up
- Module failure (DS0 bit 4) - rare, requires module replacement
Key error codes for the SM 431 family:
| DS0 / DS1 bit | Meaning | Likely cause |
|---|---|---|
| 0x0001 | Wire break | Loop open, fuse blown, or 4-wire transmitter powered down |
| 0x0002 | Overrange | Input above configured range maximum |
| 0x0004 | Underrange | Input below configured range minimum (4-20 mA: <3.6 mA) |
| 0x0008 | Parameter assignment error | Selector position and HW Config range disagree |
| 0x0010 | Module failure | Internal hardware fault; replace module |
| 0x0020 | Channel temporarily unavailable | Module is calibrating or re-init after parameter change |
| 0x0100 | External auxiliary voltage missing | Loop power 24 V absent |
A minimum OB82 fault-evaluation block in STEP 7 V5.5 STL:
FUNCTION_BLOCK FB_AI_DIAG
VAR_INPUT
OB82_EV_CLASS : BYTE; // 0x38 entering, 0x39 leaving
OB82_FLT_ID : BYTE; // 0x42 = SM 431 fault
OB82_MDL_ADDR : INT; // Logical base address of the SM 431
OB82_IO_FLAG : BOOL; // 0 = input, 1 = output
OB82_ERR_EV : WORD; // DS0 / DS1 from module
END_VAR
VAR_TEMP
DS0_WORD : WORD;
CHANNEL : INT;
END_VAR
BEGIN
// Map DS0 / DS1 from OB82_ERR_EV (bits 0..7 = DS0, 8..15 = DS1)
DS0_WORD := OB82_ERR_EV AND W#16#00FF;
IF (DS0_WORD AND W#16#0001) <> 0 THEN
// Wire break on at least one channel in the affected group
; // raise alarm to OS / HMI
ELSIF (DS0_WORD AND W#16#0008) <> 0 THEN
// Parameter assignment error: check selector and HW Config
; // re-cycle STOP-RUN after fixing
END_IF;
END_FUNCTION_BLOCK
For the standard Siemens S7-400 OB82 evaluation, use the system function blocks SFB 54 (RALRM) to retrieve the full module diagnostic record. See the STEP 7 System and Standard Functions reference manual for the full API.
Linear Scaling with FC105
For a 4-20 mA channel driving a 0-100% engineering range, the standard Siemens scaling is the integer-to-real FC105 'SCALE' block. The SM 431 raw input is bipolar-ish: 0 at 4 mA and 27648 at 20 mA, with 0x8000 at < 3.6 mA. Sample call in STL:
CALL FC 105
IN := MW 100 // raw input word from AI module
HI_LIM := 1.000000e+002 // 100.0 %
LO_LIM := 0.000000e+000 // 0.0 %
BIPOLAR:= FALSE // 4-20 mA is unipolar (only positive values)
RET_VAL:= MW 110 // scaling error code
OUT := MD 120 // scaled REAL result in %
// MW 100 = 0 (0%) when raw = 0 (4 mA)
// MW 100 = 27648 (100%) when raw = 27648 (20 mA)
NOP 0
If BIPOLAR = TRUE, the block uses -27648 to +27648 over +/-10 V, +/-5 V, etc. For thermocouples and RTDs, the FC105 is not used; the module returns a temperature in 0.1 deg C or 0.01 deg C directly. See the HW Config 'Temperature unit' setting for the resolution.
EMC, Cable Routing, and Field Installation
Analog signals on the SM 431 are vulnerable to capacitive and inductive coupling from VFD power cables, contactor coils, and switched-mode power supplies. Field-proven routing rules:
- Route analog signal cables in a dedicated cable tray at least 200 mm away from any VFD output cable and at least 100 mm away from 400 V power cables.
- Use twisted-pair shielded cable; recommended types: Belden 8761, Lapp UNITRONIC LiYCY (TP), or Siemens 6XV1 801-5B. The shield is bonded once, at the cabinet backplate, never at the field device.
- Maximum cable length for 4-20 mA: 600 m at 24 V with a 250 ohm input shunt, or 1200 m with a 28 V supply. For voltage inputs (+/-10 V), keep the cable under 50 m to avoid 50 Hz common-mode pickup.
- For hazardous-area installations, install a Zener barrier (e.g. Pepperl+Fuchs Z728) or an isolated repeater (e.g. Phoenix Contact MACX MCR-EX-SL) on the loop. The barrier's resistance adds 200-350 ohm; size the loop supply accordingly.
Step-by-Step Recovery Procedure
- Confirm the MLFB. Verify the label on the front of the module reads 6ES7 431-0HH00-0AB0 and not 6ES7 431-1KF00-0AB0 (8 AI) or 6ES7 431-7QH00-0AB0 (16 AI 16 bit). The selector switch mapping is identical for the 13-bit and 16-bit families but the wiring diagram differs.
- Cycle power and inspect the module. Power down the S7-400 rack. Pull the SM 431 forward by 5 cm. Inspect the four selector switches on the left side of the housing. They must be in detent B for any voltage or current input; in C for thermocouples; in D for 4-wire RTD; in A for +/-1 V or low-level voltage. Lock each switch with a small flat-blade screwdriver. Re-seat the module firmly; the backplane connector is a Siemens 48-pin F48 type, and a half-inserted module produces the exact -8/0 counts symptom on voltage inputs.
- Measure loop integrity with a DMM. Disconnect the field cable at the SM 431 front connector. Place a 24 V supply and a 250 ohm precision resistor in series. The resistor simulates a current loop. Read the voltage across the resistor: 1.000 V = 4.000 mA, 5.000 V = 20.000 mA. If the loop will not drive 20 mA, the cable resistance is too high or the supply is too low.
- Reconnect the field cable with the loop supply confirmed. Power up. In STEP 7, open Monitor / Modify on the input word for the channel. The value should now move with the field signal. If it still reads 32767, the loop is open - check transmitter polarity and verify that the transmitter output is not in fault (many smart transmitters drive 3.6 mA on internal fault and 21 mA on overrange; both of these can read as 0x7FFF depending on configuration).
- For the +/-10 V symptom, connect a precision voltage calibrator to the channel. With the calibrator set to 0.000 V, the SM 431 should read 0 +/- 2 counts. At +10.000 V, it should read 27648 +/- 4 counts. At -10.000 V, -27648 +/- 4 counts. Any reading of -8 or 0 with a known input indicates either a short at the connector, a broken conductor in the cable, or a hardware fault on the module. Move the calibrator to an adjacent channel in the same group; if the symptom follows the group, the selector is wrong; if the symptom follows the channel, the module is damaged.
- Re-download HW Config to the CPU. After a STOP-RUN transition, verify the input words in the VAT table. If all 16 channels return 0x7FFF after a clean configuration with a valid signal, the module firmware is corrupted; clear the CPU and reload the project, then cycle power.
- Enable diagnostic interrupt on the channels in use, download, and verify that OB82 fires when the loop is intentionally broken. This confirms the end-to-end diagnostic path.
Verification and Online Monitoring
After the recovery steps, run the following verification before handing the station over to operations:
| Test | Expected result | Acceptance threshold |
|---|---|---|
| Apply 0% signal (4.000 mA) | Raw input word 0 / scaled 0% | +/- 0.2% of full scale |
| Apply 50% signal (12.000 mA) | Raw input word 13824 / scaled 50% | +/- 0.2% of full scale |
| Apply 100% signal (20.000 mA) | Raw input word 27648 / scaled 100% | +/- 0.2% of full scale |
| Open loop intentionally | OB82 fires, DS0 = 0x0001 (wire break), input word 0x8000 | Within 1 s of opening the loop |
| Apply -10.000 V | Raw input word -27648 / scaled -100% | +/- 0.2% of full scale |
| Apply +10.000 V | Raw input word 27648 / scaled 100% | +/- 0.2% of full scale |
| Cycle CPU from STOP to RUN | Module diagnostic LED green, input words update within 100 ms | No OB82, no OB100 fault |
| Check the unused channels | 0x8000 (deactivated) or 0x7FFF (unconfigured) | Same value on all four channels in a group |
The 100 ms update latency in the table is the channel conversion time of the SM 431 with 50 Hz integration: 25 ms per active channel times the number of active channels in the group. With 16 channels active, full-scan latency is approximately 200 ms; with 4 active, 100 ms. Smoothing adds a 4 to 6 cycle delay on top.
Common Pitfalls and Field-Proven Caveats
Issues seen on live S7-400 stations with the 6ES7 431-0HH00-0AB0, gathered from commissioning and field service across multiple sites:
- Selector switch detent wear: the white plastic actuator shears off if forced. Always depress with a fingernail or a soft tool, never with pliers. A missing actuator leaves the switch in an undefined state, and the module reads 0x7FFF. Siemens replacement part number for the housing is 6ES7 431-0HH00-0AB0 itself; the actuator is not sold separately.
- Channels disabled in software reading 32767: on the 0HH00 firmware, a disabled channel returns 0x8000 (-32768), not 0x7FFF. If you see 0x7FFF on disabled channels, the configuration has not been downloaded, or the CPU is in a stop-state that did not re-read HW Config. Force a STOP-RUN transition.
- Field cable with shield bonded at both ends: the SM 431 has a 100 Mohm / 1 nF common-mode impedance. A 50 m cable with shield bonded at both ends creates a ground loop that injects 0.5-2 V common-mode; with the input configured for 4-20 mA, this is enough to push the loop above 20 mA and read overflow. Always bond the shield at the cabinet end only.
- Mixing 2-wire and 4-wire on the same group: the SM 431 uses one selector switch per group of four channels. If channel 0 is 2-wire 4-20 mA and channel 1 is +/-10 V, the switch must be in position B (which handles both) and the HW Config per-channel measuring range must reflect the per-channel choice. Mixing within a group is supported; mixing across groups with different selector positions is supported but the panel wiring must follow the same switch position.
- CPU in RUN but module in STOP: the SM 431 can be in module-STOP if the HW Config is wrong for the module firmware. Check the diagnostic buffer for entry 'Module parameter assignment error' and the entry 'Module OK' - if the 'Module OK' entry is missing after a STOP-RUN transition, the module rejected the configuration. Re-confirm the MLFB in HW Config matches the physical module to the digit.
- Loop powered through the wrong terminals: 2-wire transmitters expect loop power on their '+' terminal and the signal return on their '-' terminal. If the loop power is reversed, the transmitter blocks current, and the SM 431 sees an open loop. The transmitter may still show a value on its local HMI because many transmitters display a 'fault' or last-value on internal power.
- Front connector retention screws not torqued: the 48-pin front connector of the SM 431 uses two 4-40 screws. If either screw is loose, intermittent contact produces -8 counts noise on voltage inputs and 0x7FFF spikes on current inputs. Torque both screws to 0.4 Nm.
- HSP not installed: the 6ES7 431-0HH00-0AB0 was originally released with a hardware support package (HSP) for STEP 7 V5.4. STEP 7 V5.5 and TIA Portal V13+ ship the HSP in the standard package. If the module does not appear in the HW catalog, the HSP is missing; install it from the Siemens support portal.
- Over-temperature on a high-density chassis: with 16 AI active in a high-density S7-400 chassis (e.g. UR2-AL with redundant PS), the SM 431 dissipates 6 W. Combined with adjacent SM 431s and a CPU 416, the airflow may not be sufficient. The module's internal temperature sensor trips and forces a 0x7FFF read-out. Install a fan subassembly 6ES7 408-1TA00-0AA0 in the rack.
Cross-Reference: SM 431 vs SM 331 and S7-400 vs S7-1500
For S7-300 stations the equivalent is the SM 331 family, which uses the same selector-switch concept but with five positions (A through E) on the 6ES7 331-7KF02-0AB0. The S7-1500 equivalent is the AI 8xU/R/RTD/TC ST (6ES7 531-7KF00-0AB0) which is software-configured only - no selector switch. A summary:
| Feature | SM 331 (S7-300) | SM 431 (S7-400) | AI ST (S7-1500) |
|---|---|---|---|
| Range selection | Hardware switch (A-E) | Hardware switch (A-D) | Software only |
| Loop power for 2-wire | No (some 6ES7 331-7PF01-0AB0 have yes) | No | No (24 V from system) |
| Resolution | 13/14/15/16 bit | 13/14/16 bit | 16/24 bit |
| OB82 on wire break | Yes (configurable) | Yes (configurable) | Yes (default) |
| Field wiring | 20-pin front connector | 48-pin front connector | Push-in terminal block |
| Configuration tool | STEP 7 V5.5+ / TIA V13+ | STEP 7 V5.5+ / TIA V13+ | TIA V13+ only |
For the ET 200M equivalent in PROFINET systems, the 6ES7 331-7KF02-0AB0 SM 331 family provides the same 8-AI functionality over PROFINET IO, and the 6ES7 331-1KF02-0AB0 is the older 8-AI 13-bit version. The selector switch concept is identical. Migration to the S7-1500 platform is recommended for new installations; see the Siemens migration matrix on the S7-400 product page for the full footprint-compatible drop-in modules.
FAQ
What does a 32767 reading on the S7-400 SM 431 mean?
A raw input word of 0x7FFF (decimal 32767) on the SM 431 indicates overrange: the input signal is above the configured measuring-range maximum, the wrong range is selected, or the loop is open and the firmware is reading a noise floor above 20 mA equivalent. For 4-20 mA inputs, the corresponding underrange value is 0x8000 (-32768), which appears at current below 4 mA. Always check the selector switch position and the HW Config range first.
Why does my 2-wire 4-20 mA transmitter read 32767 even though the field device works?
The SM 431 does not power 2-wire loops; the transmitter and SM 431 are reading different circuits. With selector in position D (4-wire RTD), the current input is routed through the resistance front end and the 4 mA signal is invisible. With selector in position B but no external 24 V loop supply, the loop is open and the input is undefined. Verify the selector is in position B, install an external 24 V supply, and confirm 4-20 mA flows with a clamp meter.
How do I access the measuring-range selector switch on the SM 431?
Power down the S7-400 rack, pull the module forward by approximately 5 cm, and look on the left-hand side of the housing. Four white plastic slide switches are visible, one per channel group (0-3, 4-7, 8-11, 12-15). Set each switch to A, B, C, or D per the field signal type. Use a fingernail or a small flat-blade screwdriver; do not use pliers, the actuator is plastic.
What is the difference between a deactivated channel returning 0x7FFF versus 0x8000?
On the 6ES7 431-0HH00-0AB0 firmware, a deactivated channel in HW Config returns 0x8000 (-32768). A channel that is not configured (no group setting) returns 0x7FFF (32767). If you observe 32767 on a channel you have marked Deactivated, the configuration has not been re-downloaded to the CPU, or the CPU is in a STOP state that has not yet re-initialised the module. Force a STOP-RUN transition to re-read.
Can I mix 2-wire 4-20 mA and +/-10 V on the same SM 431 group?
Yes, if the selector switch for that group is in position B (which handles both voltage and current sub-ranges). The HW Config must be set per channel: channels used for current at 4-20 mA, channels used for voltage at +/-10 V. The selector is group-wide; the HW Config is per-channel. Position B is the only position that supports both voltage and current on the same group.