Scaling Siemens 6ES7134-4GD00-0AB0 4-20mA to 0-300°C in TIA V13

David Krause16 min read
SiemensTIA PortalTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

The 6ES7134-4GD00-0AB0 is a Siemens ET 200S 2AI 2-wire HART High Feature module (not a 4-channel module, despite several community references calling it 4AI; the 4GD order number is reserved for the 2-channel HART variant of the ET 200S analog family). It reads two 4–20 mA current loops with HART communication and resolves them into a Siemens S7 nominal range of 0 … 27648. When wired correctly, raw value 0 corresponds to 4 mA and 27648 corresponds to 20 mA. A raw value of 32768 (decimal) = 0x8000 means the input is out of range, typically wire-break, missing 24 V on the AUX1 loop-power terminal, or an unconfigured channel.

This reference covers wiring into the TM-E15C26-A1 terminal module (6ES7193-4CA50-0AA0), device configuration in TIA Portal V13, and the SCALE / NORM_X programming path that replaces the legacy Simatic Manager FC105/FC106 functions. The same logic extends to a 0–300 °C Pt100/voltage-from-transmitter range as long as the field instrument is loop-powered 4–20 mA and spans 0 °C at 4 mA and 300 °C at 20 mA.

Hardware Identification and Topology

The required physical chain for the signal is:

  1. ET 200S IM151-8PN/DP interface module (6ES7151-8AB01-0AB0 or later) — PROFINET head with backplane bus for the slice I/O.
  2. Power module (PM-E) feeding the backplane — typically 6ES7138-4CA01-0AA0 if the head is supplied separately.
  3. TM-E15C26-A1 terminal module 6ES7193-4CA50-0AA0 — accepts the 2AI HF electronic module and exposes the AUX1 bus for loop power.
  4. 6ES7134-4GD00-0AB0 electronic module — two isolated 2-wire 4–20 mA inputs with HART.
  5. Field-side 2-wire temperature transmitter (e.g. SITRANS TH100, Rosemount 644, or generic 4–20 mA T/C transmitter).
Confirm the electronic module part number on the side label: the order number 6ES7134-4GD00-0AB0 ships as the HF HART variant. Do not confuse it with 6ES7134-4GB01-0AB0 (2AI standard) or 6ES7134-4GB11-0AB0 (2AI High Feature, no HART) — wiring to AUX1 and channel resolution differ at the diagnostic-byte level.

Module Specifications at a Glance

Parameter 6ES7134-4GD00-0AB0 Value
Number of inputs 2 (2-wire, 4–20 mA)
Resolution 15 bits + sign
Nominal range raw 0 … 27648 (decimal)
Overrange 27649 … 32511
Overflow (OFL) 32767 (0x7FFF)
Underflow / wire break -32768 (0x8000) — see Siemens documentation; some firmware builds report 32768 = 0x8000 as out-of-range
Diagnostic interrupt Configurable (wire break, overflow, HART)
HART Rev 5–7, two variables per channel
Cycle time, both channels ≥ 10 ms (channel update time, depends on integration)
Required terminal module TM-E15C26-A1 (screw) or TM-E15N26-A1 (spring)
Loop power 24 V DC from AUX1; module does not source current itself

Source: Siemens ET 200S Analog Electronic Module Manual (entry ID 25545984) and ET 200S Distributed I/O System Manual (entry ID 25390457).

TM-E15C26-A1 Terminal Module Wiring

The TM-E15C26-A1 provides the screw terminals that the 2AI HF module plugs into, plus the AUX1 and AUX2 buses that carry the loop power. For a 2-wire transmitter on channel 0, the wiring is:

Terminal Signal Connection
AUX1 (top of module) +24 V DC loop supply 24 V from PM-E / external PSU, fused ≤ 1 A
1 Channel 0 + (I0+) Jumpered from AUX1 to terminal 1 inside the terminal block, OR brought out and fed to the transmitter's +
2 Channel 0 – (I0–, signal return) Transmitter's signal terminal
3 Channel 1 + (I1+) Jumpered from AUX1 if used
4 Channel 1 – (I1–) Channel 1 signal return
AUX1 bottom 0 V (ground return) Common 0 V of the PSU

If the transmitter is in the field, the cleanest path is to use AUX1 as the 24 V bus for both the module's loop supply and the transmitter's +V. The transmitter's –V returns on terminal 2 (channel 0) or 4 (channel 1). For 4-wire transmitters (separately powered), do not use AUX1; wire the transmitter's 4–20 mA output to terminals 1 and 2 only and leave the internal AUX1 link open.

TM-E15C26-A1 6ES7193-4CA50-0AA0 AUX1 +24V 1I0+ / loop + 2I0- / loop - 3I1+ 4I1- Field Transmitter (2-wire) 4-20 mA, 0-300°C + - 24V loop power 4-20 mA signal return

The voltage drop on the loop is typically 3.5 V at 20 mA. With a 24 V supply that gives ~20.5 V at the transmitter terminals, which is well within the 12–30 V compliance window of common 2-wire RTD/T/C transmitters.

Why Raw Value 32768 Appears

The decimal value 32768 is the bit pattern 0x8000, the sign bit set with the data bits at zero. For the ET 200S 2AI HF module family, this is the out-of-range / wire-break value. Possible causes ranked by frequency in the field:

  1. Loop power missing on AUX1 — the 2-wire transmitter has no supply, the input floats, and the module reports out-of-range. This is the most common cause when the AI module is being bench-tested with a mA source directly into terminals 1/2 without a 24 V supply on the loop.
  2. Channel not enabled in device configuration — by default in TIA the input is disabled and the value is 0, but in some firmware states an inactive but wired channel still scans and reads 0x8000.
  3. Polarity reversed on terminals 1/2 — 2-wire modules are polarity-sensitive only on current-flow direction; reversing them produces out-of-range because the input diode is reverse-biased.
  4. Source impedance of bench mA calibrator exceeds the module's input spec — the loop is open in the calibrator's "off" state.
  5. Module seated incorrectly on the terminal block — backplane contacts not making.
When injecting 4–20 mA from a calibrator into the 2-wire channel of a 4-wire powered module, you must drive current into terminal 1 and out of terminal 2 with the calibrator in sourcing mode. The module is not a current sink by default. Confirm with a multimeter in series; the loop must read 4 mA before any value other than 32768 will be reported.

TIA Portal V13 Device Configuration

  1. Open the TIA Portal V13 project, switch to Device View, and drag the IM151-8 PN/DP from the hardware catalog.
  2. Right-click the head module and assign a PROFINET device name + IP. Confirm with the topology editor that the head is reachable in the network view.
  3. Open the slot next to the head module and select the PM-E DC 24V power module.
  4. Place the TM-E15C26-A1 terminal module (order 6ES7193-4CA50-0AA0). TIA will auto-suggest the 2AI I 2WIRE HF HART electronic module 6ES7134-4GD00-0AB0 on top of it.
  5. Open the AI module's Properties dialog and verify:
    • Channel 0 / Channel 1 → Measurement type = Current (2-wire transmitter)
    • Measuring range = 4 … 20 mA
    • Integration time = 20 ms (50 Hz rejection) or 16.67 ms (60 Hz rejection). For temperature, 100 ms is preferred if the response can tolerate it.
    • Diagnostics → enable Wire break and Overflow interrupts (only if you need hardware interrupts; otherwise leave the diagnostics off for cleaner VAT values).
    • HART → optionally enable for PV/SV access, set the number of HART variables if you need to read out the transmitter's digital reading directly.
  6. Compile the hardware configuration and download to the head. The input addresses are visible in the device view, e.g. %IW64 (channel 0) and %IW66 (channel 1). Note these addresses — the program references them.

Raw Value Encoding for the 4–20 mA Range

The Siemens S7 Analog Value Processing fundamentals (entry ID 76463576) document defines the bipolar and unipolar tables used by every S7 analog module:

Current Nominal Raw (INT) Range
0 mA 0 Underflow < 4 mA
4 mA 0 Lower nominal
20 mA 27648 Upper nominal
> 20 mA (up to ~22.96 mA) 27649 … 32511 Overrange
Wire break / out of range 32768 (0x8000) Fault
Overflow 32767 (0x7FFF) Fault

For a 0–300 °C transmitter, the linear transfer is therefore:

T_°C = (Raw - 0) / (27648 - 0) * (300.0 - 0.0) = Raw * 0.01085069444...

Or, with a possible 4 mA live-zero trim, the general form is:

T_°C = OUTV_L + (Raw - MIN_IN) * (OUTV_H - OUTV_L) / (MAX_IN - MIN_IN)

That formula is exactly what the SCALE block implements internally — there is no need to hand-code it.

SCALE Block — TIA V13 Replacement for FC105

TIA Portal V13 ships the SCALE instruction under Instructions → Basic Instructions → Converter operations → SCALE. It is the direct equivalent of the legacy FC105 and avoids the need to recreate the formula in ladder or SCL. The block face is:

Pin Type Meaning Typical value
EN BOOL Enable TRUE
ENO BOOL Enable out (OK) —
IN INT or REAL Raw input %IW64
K1 / MIN INT or REAL Low raw value 0
K2 / MAX INT or REAL High raw value 27648
OUTV_L REAL Engineering low 0.0
OUTV_H REAL Engineering high 300.0
OUT REAL Engineering value "Temperature_CH0"
RET_VAL / OK BOOL Valid signal —
In TIA V13 the block has a slightly different signature than FC105. Older documentation refers to K1 / K2, TIA V13+ uses MIN / MAX. Both call the same scaling routine internally.

SCL Implementation (FB1 — Scale 2AI 4–20 mA)

FUNCTION_BLOCK "FB_AnalogIn_Scale"
VAR
    // raw inputs
    iRaw_CH0 : INT;       // IW64
    iRaw_CH1 : INT;       // IW66
    rTemp_CH0 : REAL;
    rTemp_CH1 : REAL;
    bValid_CH0 : BOOL;
    bValid_CH1 : BOOL;
    bOverflow  : BOOL;
    bWireBreak : BOOL;
END_VAR
BEGIN
    // Channel 0
    IF (iRaw_CH0 = 16#8000) OR (iRaw_CH0 = 16#7FFF) THEN
        rTemp_CH0  := 0.0;
        bValid_CH0 := FALSE;
        bWireBreak := (iRaw_CH0 = 16#8000);
        bOverflow  := (iRaw_CH0 = 16#7FFF);
    ELSE
        rTemp_CH0  := SCALE(  // TIA V13 SCALE function
            IN     := iRaw_CH0,
            MIN    := 0,
            MAX    := 27648,
            OUTV_L := 0.0,
            OUTV_H := 300.0,
            OK     => bValid_CH0 );
    END_IF;

    // Channel 1 — same wiring, different address
    IF (iRaw_CH1 = 16#8000) OR (iRaw_CH1 = 16#7FFF) THEN
        rTemp_CH1  := 0.0;
        bValid_CH1 := FALSE;
    ELSE
        rTemp_CH1  := SCALE(
            IN     := iRaw_CH1,
            MIN    := 0,
            MAX    := 27648,
            OUTV_L := 0.0,
            OUTV_H := 300.0,
            OK     => bValid_CH1 );
    END_IF;
END_FUNCTION_BLOCK

Ladder Implementation (Network 1 — Channel 0)

Network 1: Scale channel 0 (4-20 mA → 0-300 °C)
  |       SCALE                                       |
  |  EN  | IN  | MIN  | MAX  | OUTV_L | OUTV_H | OUT   |
  | TRUE | IW64| 0    | 27648| 0.0    | 300.0  |MD100  |
  |  <--> | <-->| <--> | <--> | <-->   | <-->  | <-->  |

Network 2: Out-of-range interlock
  | CMP <> |  IW64 | 16#8000 |
  |  IN1 <> IN2 |
  |  ---( )--- "bWireBreak_CH0"   |

The same networks are repeated for channel 1 with IW66 as the source and a second MD memory region for the engineering value.

NORM_X and SCALE_X for Floating-Point Pipelines

If the program already has the raw value as REAL (e.g. read via HART and stored in a DB), use the two-stage path that mirrors FC106-style processing:

// Normalize raw into 0.0 .. 1.0
rNorm_CH0 := NORM_X(
    MIN   := 0.0,
    VALUE := rRawFromHART_CH0,
    MAX   := 27648.0 );

// Scale the 0..1 into the engineering range
rTemp_CH0 := SCALE_X(
    MIN    := 0.0,
    VALUE  := rNorm_CH0,
    MAX    := 1.0,
    OUTV_L := 0.0,
    OUTV_H := 300.0 );

For 4–20 mA from a 4-wire transmitter that has been linearised to a live zero of 4 mA, the offset of 0 mA = –0.0145 × OUTV_H must be subtracted, or use a bipolar SCALE_X with OUTV_L = –25.0 if the range is bidirectional. For 0–300 °C unipolar the simple block is correct.

Diagnostic Mapping and 32768 Handling

When the module reports 0x8000 the program should:

  1. Hold the last good value (sample-and-hold) or set the output to a safe default (often 0.0 °C or a configurable fault value).
  2. Set a status bit in a process-image DB so the HMI shows "Sensor fault" rather than a misleading 0 °C.
  3. Trigger a non-acknowledgeable alarm to the operator (HMI alarm via WinCC) and optionally a hardware-interrupt OB if a fast response is required.
  4. Log the timestamp from the diagnostic interrupt OB (OB82 for diagnostic interrupt) to an alarm history DB.
Raw (INT) Hex Meaning Recommended action
< 0 (e.g. -32768) 0x8000 Wire break / underrange on 4–20 mA (some firmware) Hold last value, set bWireBreak
0 … 27648 0x0000 … 0x6C00 Valid measurement Pass scaled value to control
27649 … 32511 0x6C01 … 0x7EFF Overrange (current > 20 mA) Clamp to OUTV_H, set bOverrange
32512 … 32767 0x7F00 … 0x7FFF Overflow / module defect Set fault, request maintenance

Verification and Commissioning

Run the following sequence before declaring the loop ready for process service:

  1. Wiring continuity — with the head powered, the calibrator disconnected, and the transmitter powered, measure DC voltage between AUX1 (top) and AUX1 (bottom) at the TM-E15C26-A1. Expect 22.0–24.0 V. If zero, the PSU feed to the PM-E is missing.
  2. Loop current — break the loop at the transmitter terminals and insert a multimeter in series in mA mode. Force a known temperature on the sensor (ice bath at 0 °C, then a heated reference at 100 °C). Confirm 4.00 mA and ~7.20 mA respectively. Reverse the loop leads if you read 0.00 mA or –OL.
  3. Raw value in VAT — in TIA Portal V13, open a Watch table and force the online monitor. The raw value should sit between 0 and 27648 with a stable process, and should not return 32768 during normal operation. If it does, refer to the troubleshooting matrix below.
  4. Engineering value — check the SCALE block output MD100 (or DB tag) against the calibrator. At 4 mA expect 0.0 °C ± 0.1; at 20 mA expect 300.0 °C ± 0.1. A 0.5 % deviation points to a scaling parameter error, not a wiring problem.
  5. Diagnostic interrupt — disconnect the loop at the transmitter to deliberately force wire break. The module should raise OB82 and the DIAG LED should flash red. After re-connection, OB82 should clear the diagnostic automatically within one cycle.
  6. HART sanity (if used) — open the Online & Diagnostics view of the AI channel in TIA. PV should be in the configured engineering units and SV should match the tag in the transmitter's configuration tool.

Troubleshooting Matrix

Symptom in VAT Probable Cause Fix
Raw = 32768 (0x8000) No loop power / wire break Verify 24 V on AUX1 of TM-E15C26-A1, confirm transmitter polarity, replace the field cable
Raw = 32768 in normal operation Channel disabled in device view Enable channel and re-download the configuration
Raw = 0 mA, 4 mA on the wire but 0 in VAT Channel 0/1 address swapped, or wrong slot indexed Check the I-address of the slot in the device view; confirm with the program
Raw sits at 13824 regardless of input Channel wired to 0–10 V but measuring range set to 4–20 mA, or vice versa Match the channel "Measurement type" in the properties
Scaled value drifts ±5 °C at constant temperature EMI from VFD on the same cable tray, no shielding Use shielded twisted pair, ground the shield at the cabinet end only
Scaled value = 300.0 °C with input at 4 mA MIN/MAX inverted on the SCALE block Verify MIN = 0, MAX = 27648, OUTV_L = 0.0, OUTV_H = 300.0
SCALE block reports OK = FALSE IN is above 27648 or below 0 Inspect the raw value, check overrange
OB82 keeps firing even after re-connection Group diagnostic enabled but not cleared Disable "Wire break" diagnostic if the application cannot tolerate the interrupt, or wire the acknowledgment OB correctly
DIAG LED steady red Module is not seated, or backplane contact issue Power down the slice line, reseat the module firmly on the terminal block
FC105/FC106 not found in TIA V13 Legacy Simatic Manager library not imported Use the native SCALE / NORM_X / SCALE_X instructions; they are functionally identical

Field Wiring Checklist

  • Use twisted pair, preferably with an overall shield. Belden 8760 or 8719 are common.
  • Ground the shield at the cabinet end only; leave the field end floating. Ground loop currents will otherwise inject noise into the loop.
  • Keep analog wiring in a separate conduit ≥ 200 mm from VFD output cables and any 480 V or higher circuits.
  • Power the loop from the same PSU that feeds the ET 200S head (PM-E) so that a single UPS covers the loop.
  • Add a 100 mA self-resettable fuse per channel if the loop is routed through harsh environments, especially for outdoor RTDs.
  • Document the channel address (e.g. "AI0 = %IW64 = Furnace 1 Zone 1 PV") on the cabinet door schematic so a future engineer can trace the loop back to the SCALE block.
  • Record the loop voltage at the transmitter terminals in the commissioning report. Anything < 12 V on a 2-wire device will cause current-limit-induced scaling errors.

HART Layer Notes

The 6ES7134-4GD00-0AB0 supports up to two HART variables per channel. In TIA V13 enable the HART mapping under Module properties → Inputs → HART. The PV is typically the primary process variable (e.g. the linearised temperature in °C) and the SV is the sensor raw (e.g. resistance or mV). With HART enabled, the module's PIW is replaced by the primary variable in engineering units mapped via the HART record, but only if the HART status is good. If the HART status goes to Communication error, the fallback is the analog raw value — exactly the behaviour you want during a hot-swap of a transmitter.

FAQ

Why does my VAT show 32768 for a 4–20 mA input on the 6ES7134-4GD00-0AB0?

32768 (0x8000) is the out-of-range / wire-break value. The most common cause is missing 24 V on the AUX1 terminal of the TM-E15C26-A1 — the 2-wire transmitter has no loop power. Verify the AUX1 supply, confirm the loop carries 4–20 mA with a multimeter, and reverse-check the polarity on terminals 1 and 2.

What is the difference between SCALE, NORM_X, and SCALE_X in TIA Portal V13?

SCALE is the direct replacement for legacy FC105 and converts an INT/REAL raw value into an engineering range in one step. NORM_X normalises a value into 0.0–1.0 (FC106 partial). SCALE_X scales the normalised 0.0–1.0 into the engineering range. For a single 4–20 mA input mapped to 0–300 °C, SCALE alone is enough.

Why are FC105 and FC106 missing in TIA Portal V13?

TIA Portal V13+ uses native instructions from the Basic Instructions library. The legacy blocks FC105 and FC106 are in the Simatic Manager standard library. Import the Standard Library / TI-S7 Converting Blocks, or — preferred — use the new SCALE / NORM_X / SCALE_X instructions which compile faster and offer BOOL OK status.

Is the 6ES7134-4GD00-0AB0 a 4-channel or 2-channel module?

It is a 2-channel 4–20 mA 2-wire HART High Feature module. The 4AI variants of the ET 200S family belong to the 6ES7134-4JH / 4KB order numbers. The MLFB 4GD is always 2AI.

Can I use the same SCALE block for both channels and different temperature ranges?

Yes. Use one SCALE instance per channel, set the OUTV_L / OUTV_H to the per-channel range (e.g. 0.0–300.0 °C and 0.0–150.0 °C), and the same MIN/MAX raw range (0–27648). If you want a single FB, pass the four engineering limits as input parameters and the raw value as IN.

How do I scale 4–20 mA to a negative engineering range (e.g. –50 to +150 °C)?

Set OUTV_L = –50.0 and OUTV_H = 150.0 on the SCALE block; MIN and MAX stay 0 and 27648. The block handles the negative offset internally. Always verify with a calibrator at 4 mA (expect –50.0) and 20 mA (expect +150.0) before connecting the field instrument.

What is the input address for channel 0 in TIA Portal V13 with the IM151-8PN/DP?

It depends on the slot order. The default for the first AI slot after the head is %IW64 for channel 0 and %IW66 for channel 1. Always confirm the addresses in Device view → Module → I/O addresses before referencing them in code.

Back to blog