Overview
When migrating a legacy SIMATIC S5-100U program to a modern SIMATIC S7-1200 in TIA Portal, two STL constructs routinely confuse first-time converters: the ---( # )--- element labeled "midline output," and flag-memory operands written as Fxx.y. The original code segment in this article uses F66.2 as the destination of a midline output inside PB5, segment 3, and the engineer converting it was unsure whether the bit was active, redundant, or deletable.
This reference documents:
- The exact semantics of the midline output in S5 and S7 STL.
- How F-flag memory (Merker/flag bytes) maps between S5-100U and the S7-1200/%MW area.
- Why a midline output
---( # )---is not interchangeable with a coil---( )---. - How TIA Portal handles residual F-references during conversion.
- How to replace the extended pulse timer (SE) on S7-1200, which lacks a direct instruction.
- How to evaluate empty organization blocks such as OB31 and OB34.
The companion Siemens document "STEP 7 – From S5 to S7" (S5_to_S7 conversion manual, edition 09/2008) is the official Siemens source for migration rules; the indirect-addressing reference for STL on S7-300/S7-400 (TIA Portal V20 Help – Indirect Addressing in STL) provides the canonical syntax for any indexed bit operations encountered later.
The Midline Output ---( # )--- Instruction
In S5 (and historically in S7 STL where it survives from the STEP 5 instruction set), ---( # )--- is the midline output. It is an intermediate assignment element that stores the current RLO (Result of Logic Operation) – the equivalent of power flow – into the specified operand, without terminating the network.
Key behavioural rules:
- It does not reset the RLO, so subsequent logic on the same rung continues to see the same RLO value.
- It is not a coil (output,
---( )---). A coil terminates the rung's RLO evaluation in ladder, although in pure STL there is no such hard terminator – the difference is logical: a coil finalises the network, a midline output does not. - It cannot be used as the first element in a network. There must be logic before it that establishes an RLO.
- It writes the operand on every cycle, regardless of edge – the value tracks the live RLO, not a transition.
Example S5 STL excerpt from PB5 Segment 3:
Network 3
A I 32.0 // input bit
A I 32.1 // AND input bit
= F 66.2 // midline output, NOT a coil
A F 66.2 // reuse of stored RLO downstream
= Q 16.0 // final coil to output
Conversion note: in TIA Portal, when S5 STL is imported via the legacy converter, midline outputs are preserved as STL and translated to LAD/FBD only if you re-author the network. The F operand on the left of = remains a flag; do not change = to S (set) or R (reset) – that would alter the level-tracking behaviour.
F-Flag Memory: What F66.2 Means in S5
The F prefix in STEP 5 denotes Flag memory – internal scratch bits used by the user program. The format is:
F <byte> . <bit> e.g. F 66.2 → Flag byte 66, bit 2
In an S5-100U, flag memory is part of the internal RAM area. The CPU 100U (e.g., CPU 102, CPU 103, CPU 104) typically provides 1024 flag bits (FY 0 … FY 63 in some firmware, FY 0 … FY 255 in others) depending on the CPU variant. The exact byte range is documented in the S5-100U manual; F66.2 is well inside the supported area for any 100U CPU.
S5 Flag to S7 Memory-Bit Mapping
| S5 Operand | S7 Operand (S7-300/400) | S7-1200 Equivalent | Notes |
|---|---|---|---|
| F 0.0 … F 255.7 | M 0.0 … M 255.7 | %M0.0 … %M4095.7 (or symbolic tag in DB/Global) | Full bytewise mapping; bits within a byte retain their index. |
| FY 0 … FY 255 | MB 0 … MB 255 | %MB0 … %MB4095 | Byte access translates directly. |
| FW 0 … FW 254 (even) | MW 0 … MW 254 | %MW0 … %MW4094 (word-aligned) | S5 words may start at odd addresses on some CPUs – verify alignment after conversion. |
| FD 0 … FD 252 (even) | MD 0 … MD 252 | %MD0 … %MD4092 | Dword access; same alignment caveat. |
Concretely, F66.2 in S5 maps to:
-
S7-300/400:
M 66.2 -
S7-1200 / S7-1500:
%M66.2(or a symbolic tag – recommended for readability)
Flag_66_2 : Bool in a user-defined DB or in the global PLC tags. Avoid leaving them as raw %M addresses where possible; symbolic naming preserves readability of older logic.
STL Indirect Addressing on S7-300/S7-400
If during the S5-to-S7 conversion you encounter loops or pointer-style constructs that previously used F-flag pairs as index registers, modern STL offers two indirect-addressing modes documented in the TIA Portal help (Indirect Addressing in STL – TIA Portal V20):
| Mode | Syntax | Typical Use |
|---|---|---|
| Memory-indirect | A M[MD10] |
Index inside a DB or M area using a pointer in MD10. |
| Register-indirect, area-internal | A M[AR1, P#0.0] |
Index using address register AR1 with offset. |
| Register-indirect, area-crossing | L W[AR1, P#0.0] |
Cross-area (DB/PI/PQ) via AR with offset. |
S5-100U lacked AR1/AR2 as full address registers – index loops used flag-word pairs (e.g., FW 10 as a counter, FW 12 as a pointer). On S7-300/400 these collapse to a single MD; on S7-1200 STL is restricted and indirect addressing is largely replaced by SCL FOR/array indexing, so plan to re-author any indexed loops in SCL.
Converting F66.2 in the TIA Portal Workflow
The engineer in this case is working in TIA Portal V15.1. The conversion of an S5 program is two-stage:
- STEP 5 → STEP 7 (Classic) conversion using the S5 import tool inside STEP 7 V5.x or the SIMATIC Manager. This produces a runnable S7-300/S7-400 program with F-operands renamed to M.
- STEP 7 → TIA Portal migration using the TIA "Migrate project" function, which retains the M-area addresses and the STL networks.
For an S5-100U → S7-1200 migration the second stage is non-trivial – the S7-1200 is not a direct drop-in replacement. You must also re-target:
- The hardware configuration (signal modules vs. S5-100U I/O bus).
- Any instructions the S7-1200 does not support (notably the extended pulse timer, see below).
- OB architecture (S7-1200 has a different OB numbering scheme).
Practical Steps for the F66.2 Network
- Open the imported project in TIA Portal V15.1 and locate
PB5(now typically mapped to an FB or a Program block depending on whether you used a converter that wraps PBs into FBs). - Open segment 3 and confirm the instruction is
---( # )---with operand%M66.2(post-conversion). - Decide if F66.2 is still referenced downstream. If the only reader was inside the same network (re-using the stored RLO) and the network has been refactored, the flag may be dead.
- If still required, assign a symbolic tag:
midline_RLO_seg3 : Boolin the standard tag table, and replace the bare %M66.2. - Recompile; verify no cross-reference entry under "unused" remains.
Extended Pulse Timer (SE) on S7-1200
The S5-100U instruction set includes the extended pulse timer (SE), which produces a pulse of a programmed duration triggered by a rising edge, with extended timing range and retention across power cycles on the S7 equivalent. The classic STEP 7 timers (S5TON, S5TOF, S5TP, S5TONR – IEC library) map easily, but the S7-1200 / S7-1500 do not expose the legacy S5 timer block in the same way; the recommended replacement is the IEC TP (pulse) from the "Timers" instructions palette.
Replacement Logic in SCL (S7-1200)
// S5 SE replacement, edge-triggered pulse of duration PT
IF "SE_Trig" AND NOT "SE_Trig_prev" THEN
"TP_DB".TP(IN := TRUE, PT := T#5s);
END_IF;
"SE_Trig_prev" := "SE_Trig";
"SE_Q" := "TP_DB".Q;
"SE_ET" := "TP_DB".ET;
Replacement Logic in LAD (S7-1200)
┌──────────────┐
"SE_Trig"──┤P│ TP ├─"SE_Q"
PT := T#5s│ │ TP_DB ├─"SE_ET"
└──────────────┘
Where TP_DB is a multi-instance or a standalone IEC_TIMER/DB instance for the TP block. Configure the time base in the PT input; the S5 SE's range (10 ms to 9990 s in S5-100U) maps to S7 TIME which supports T#-24d20h31m23s648ms .. T#+24d20h31m23s647ms.
Empty Organization Blocks: OB31 and OB34
The S5-100U supports a set of OBs for time-of-day interrupts, cyclic interrupts, and error handling. OB31 and OB34 on the S5-100U are typically used for time-of-day or cyclic interrupt classes (the exact OB number-to-class mapping is documented in the S5-100U CPU manual; OB31/OB34 generally correspond to higher-priority time-of-day interrupt levels).
In S7-1200 the equivalent architecture is:
| S5-100U OB | S7-1200 Equivalent | Function |
|---|---|---|
| OB31 (interrupt class) | Time-of-day interrupt OB (e.g., OB10x with multiple instances) | Time-of-day alarm |
| OB34 (interrupt class) | Cyclic interrupt OB (OB30x) | Cyclic execution at fixed interval |
| OB1 | OB1 (Main, cyclic) | Main program |
| OB21/OB22 | OB100 / OB101 / OB102 | Startup (warm restart / hot restart / cold restart) |
| OB13 / OB25 | OB80 / OB82 / OB85 / OB86 (error OBs) | Error handling |
If OB31 and OB34 in the S5 program are empty – no code other than the default BE – they were either placeholders or have had their interrupt class re-wired elsewhere. Decision path:
- Confirm via the S5 cross-reference (XRF) that no timer assignment or interrupt-trigger tag references these OBs.
- If truly empty and unreferenced, do not recreate them in S7-1200. The S7-1200 has no OB31/OB34 numbering – create only the OBs you need (e.g., a cyclic OB30 with a 100 ms interval if the original OB34 was a 100 ms cyclic).
- If they carried configuration only (e.g.,
OB31configured for a specific time-of-day via the S5 system data), recreate that configuration in the S7-1200 device configuration under "Time-of-day interrupts".
Function Blocks (FB) in the Converted Program
In the original S5 program, FB-references inside PBs are common; for example, JU FB5 or conditional JC FB5. After conversion these become calls to S7 FBs. Three things to verify on the migrated FBs:
- Instance DBs: S5 FBs used the global flag area or the FB's own local data. S7 FBs require an Instance DB. The converter creates one automatically – verify the DB number assignment.
- Local data width: S5 FBs had a fixed local-data footprint per L stack entry. S7 FBs use multi-instance capability; if you chain FBs, you may need to enable the "Multi-instance" attribute on the FB type.
-
Parameter passing: S5 used FW/FD pairs in/out of FBs; S7 uses the IN/OUT/IN_OUT/TEMP interface of the FB. Verify all parameters are correctly mapped and that
F66.2-style scratch bits inside the FB are not being passed by reference where the converter expected a value parameter.
Conversion Address-Mapping Reference
| S5 Address | S7-300/400 Address | S7-1200 Address | Width |
|---|---|---|---|
| I 0.0 … I n.n | I 0.0 … I n.n | %I0.0 … %In.n | Bit |
| IB 0 … IB n | IB 0 … IB n | %IB0 … %IBn | Byte |
| IW 0 (even) | IW 0 (even) | %IW0 (word-aligned) | Word |
| ID 0 (even) | ID 0 (even) | %ID0 (dword-aligned) | Dword |
| Q 0.0 … Q n.n | Q 0.0 … Q n.n | %Q0.0 … %Qn.n | Bit |
| F 0.0 … F 255.7 | M 0.0 … M 255.7 | %M0.0 … %M4095.7 | Flag bit |
| T 0 … T n | T 0 … T n (legacy) or IEC TP/TON/TOF/TONR instances | IEC_TP/IEC_TON/IEC_TOF/IEC_TONR instances | Timer |
| C 0 … C n | C 0 … C n (legacy) or IEC CTU/CTD/CTUD instances | IEC_CTU/IEC_CTD/IEC_CTUD instances | Counter |
| DB n DX n.n / DW n | DBn.DBX n.n / DBn.DBW n / DBn.DBD n | "DB_name".n.n / ".n" (S7-1200 symbolic) | Data word |
| PB n / SB n / FB n / OB n | FB n / FC n / OB n (PB/SB become FB or FC depending on converter) | FB n / FC n / OB n (re-authored) | Block |
Verification and Commissioning Steps
After the conversion, run the following checks before commissioning on the S7-1200:
- Compile clean – zero errors, zero warnings. Any warning about "operand area mismatch" or "implicit conversion" usually means an F-address was not mapped correctly.
-
Cross-reference (XREF) – confirm every
%Mxx.yreference in the converted program has at least one read access if it has a write, and that no flags remain orphaned. - Online watch on PB5 segment 3 – force the input bits that drive F66.2's network and watch the flag bit toggle. If the bit never sets, the midline output's input logic has been broken during the conversion.
- Run OB diagnostics – check that OB82 / OB85 / OB86 are not being triggered, which would indicate an I/O or fault mismatch between the S5 I/O map and the S7-1200 hardware configuration.
-
Timing test – for the extended-pulse replacement, verify with a stopwatch that the TP pulse duration matches
PTto within one scan cycle. S7-1200 scan times differ from S5-100U; if the SE was used for a tightly timed event (e.g., a debounce or a one-shot relay substitute), account for scan jitter. - Retention test – power-cycle the S7-1200 and verify any SE/TP timers that were retentive on S5 still behave correctly (or have been re-engineered as documented above).
Troubleshooting Matrix
| Symptom | Likely Cause | Fix |
|---|---|---|
| F66.2 always reads 0 in S7 online watch | The converter left it as %M66.2 but a previous tag with the same name overwrites it (symbolic-tag priority). | Remove duplicate symbolic tags, keep the explicit %M66.2 reference or rename the symbol. |
| Network runs but output never asserts | Midline output was changed to a coil or to a set/reset during re-typing. | Restore ---( # )--- semantics; verify the rung's RLO propagation. |
| Extended pulse timer does not compile on S7-1200 | Direct call of legacy S5 timer block (FB n) that the S7-1200 library does not include. | Replace with IEC TP block (instance DB) per the LAD/SCL examples above. |
| OB31/OB34 error on first download | Converter auto-created OBs that do not match S7-1200 OB numbering. | Delete the auto-created OBs and create only the OB30/OB40-class OBs the application actually needs. |
| FB instance DB "wrong type" warning | Original S5 FB had no declared instance DB; converter created a generic one. | Regenerate the instance DB from the updated FB interface. |
| Flag area write triggers unexpected outputs | %M66.2 was being used as a shared scratch byte by two blocks; S5 assumed single-CPU exclusivity, but TIA Portal may have flagged a multi-write collision. | Split the scratch byte into two separate flags, or assign a per-block instance-DB location. |
Edge Cases and Field-Proven Caveats
- Byte ordering: S5 words/dwords are big-endian on the wire; S7-300/400 are little-endian for the byte layout in memory but big-endian for network/peripheral access. If a flag word (FW) was being used as a counter that crosses byte boundaries (e.g., FW 65 = FY65 + FY66 high byte), verify the migration does not flip high and low bytes.
-
Edge detection on midline outputs: Because
---( # )---is level-tracking, an S5 program that relied on the previous value of F66.2 to detect a change in input conditions (effectively using it as an edge detector) loses that behaviour if the converter substitutes a coil. Re-author with an explicitFPedge flag if an edge is required. -
Empty OB detection: Siemens S5 conversion tools sometimes copy OB31/OB34 skeletons with default
BE. Always check the source listing; an empty BE-only OB is a candidate for deletion, but an OB containingJU FBxxxor interrupt-specific code is not. -
Symbolic-tag priority in S7-1200: When a tag named
Flag_66_2exists in the PLC tag table, an absolute%M66.2reference in a different block will resolve to the symbolic tag. This is a common source of "phantom" mismatches after migration. - Scan time: S5-100U typically scans at 10–50 ms; S7-1200 at 1–10 ms. Any midline-output + downstream-coil sequence that the S5 program relied on having a particular scan-time-related pulse width will behave differently – check pulse-shaping networks.
Related Instruction Reference
| S5 Instruction | Function | S7 STL Equivalent |
|---|---|---|
| ---( )--- | Output coil |
= Mxx.y / = %Mx.y
|
| ---( # )--- | Midline output | Same = syntax but used mid-network; semantics preserved automatically. |
| ---( S )--- / ---( R )--- | Set / Reset latch |
S Mxx.y / R Mxx.y
|
| SP / SE / SS / SA / SF | Pulse / Extended pulse / Retentive on-delay / Off-delay / Extended off-delay | IEC TP / TP+retention / TONR / TOF / TP variants on S7-1200 |
| SU / SD / SE counters | Up / Down / Up-down counters | IEC CTU / CTD / CTUD |
| L / T / + / - / * / : | Load / Transfer / arithmetic | L / T / +I / -I / *I / /I (S7-1200 STL subset – prefer SCL for complex math) |
Standards and Documentation Cross-References
For the formal migration ruleset, the canonical Siemens document is "STEP 7 – From S5 to S7", available on Siemens Industry Online Support (S7_S5S7B manual). It contains:
- The S5-to-S7 instruction-by-instruction mapping.
- The S5 block-type to S7 block-type mapping (PB → FB/FC, SB → FC, OB → OB).
- The S5 system data word (SD/SDx/SDW) to S7 system data block mapping.
- The S5 hardware configuration to S7 hardware configuration conversion rules.
For indirect addressing syntax (relevant if you encounter pointer-driven loops in the S5 code), use the TIA Portal V20 help page on indirect addressing (Indirect Addressing in STL – TIA Portal V20). On S7-1200, prefer SCL with array indexing; STL indirect addressing is supported in a restricted form.
What does the # symbol mean in a Siemens S5 or S7 STL network?
The ---( # )--- symbol is the midline output. It writes the current RLO (power flow) to the specified operand without ending the network, so subsequent logic can continue using the same RLO. It is not a coil, not a set, and not a reset.
How do I convert an F66.2 flag reference from S5 to S7-1200?
Map F 66.2 directly to %M66.2 on the S7-1200 (or to a symbolic Bool tag Flag_66_2 in the PLC tag table). The bit index is preserved: byte 66, bit 2. Verify with the TIA Portal cross-reference that the bit is not duplicated by a symbolic tag.
Why does my S5 extended pulse timer (SE) not compile on S7-1200?
The S7-1200 does not expose legacy S5 timer blocks. Replace the SE instruction with the IEC TP (pulse) block from the Timers palette, drive it with a rising-edge-detected enable input, and set the PT duration to the original SE time base. Add retentive storage in a retentive DB if power-cycling behaviour was important.
Do I need to recreate empty OB31 and OB34 on the S7-1200?
No. The S7-1200 has no OB31/OB34 numbering – those were S5 interrupt-class OBs. If the original OBs were empty (default BE) and unreferenced, omit them. If they carried active interrupt logic, recreate the equivalent as a time-of-day OB (OB10x class) or cyclic OB (OB30x class) in the TIA Portal device configuration.
Can I delete F66.2 if I refactor the network around it?
Yes, provided the cross-reference shows no other read or write of that bit. Run a project-wide XREF in TIA Portal; if F66.2 is only used as a midline output in PB5 segment 3 and you have rewritten that network to remove the need for the stored RLO, the bit is dead and the symbol can be removed from the tag table.