1. Problem Summary
An SB 1231 analog input signal board (SB) installed on a SIMATIC S7-1200 CPU burns out repeatedly on a 4-20 mA pressure transmitter loop. Field symptoms:
- Input reads correctly for 1-2 weeks after replacement, then drifts and saturates.
- PLC reports diagnostic events
"High limit violated"and"Low limit violated"while the loop current measured at the transmitter is within normal bounds (4-20 mA, with peaks to 20.2 mA at 1 bar and 5.5 mA at 0 bar). - Board is destroyed and must be replaced; the transmitter itself remains functional.
- Wiring length is approximately 20 m on 4 x 0.75 mm² unshielded conductors, later replaced with shielded cable but burnout still recurs.
- PLC power supply and sensor power supply are the same 24 VDC source.
The combination of repeated hardware failure with otherwise correct transmitter operation and correct TIA Portal configuration points to a common-mode voltage or transient over-stress on the analog input. The transmitter, the cable, and the surrounding environment (welding, VFDs, ground potential differences) are the prime suspects - not the parameter set.
2. SB 1231 Signal Board Technical Specifications
The SB 1231 is a plug-in signal board that mounts on the front of an S7-1200 CPU and provides additional analog inputs. Two variants matter for this discussion:
| Parameter | SB 1231 (1 AI, classic) | SB 1231 AI 4x14 bit (newer generation) |
|---|---|---|
| Number of inputs | 1 (differential) | 4 |
| Supported types | Voltage or current | Voltage or current |
| Voltage ranges | ±10 V, ±5 V, ±2.5 V | ±10 V, ±5 V, ±2.5 V, 0-10 V |
| Current ranges | 0-20 mA | 0-20 mA, 4-20 mA |
| Resolution | 11 bits + sign | 14 bits |
| Integration time | 50 Hz (20 ms) / 60 Hz (16.67 ms) / 400 Hz (2.5 ms) | Same, plus configurable channel groups |
| Diagnostic interrupt | Yes (overflow / underflow) | Yes (overflow / underflow / wire break on 4-20 mA) |
| Hardware limit monitoring | High/low limit configurable | High/low limit configurable |
| Smoothing | None / weak / medium / strong | None / weak / medium / strong |
Source: Siemens S7-1200 manual collection - SB 1231 1 AI specifications and SB 1231 AI 4x14 bit specifications.
Important operational note from Siemens: for the 4x14 bit SB, "Set unused current input channels to the 0 to 20 mA range and/or disable broken wire error reporting. Inputs configured for current mode do not conduct loop power when the channel is disabled." This matters when spare channels are floating; leaving them in 4-20 mA with broken-wire diagnostic enabled will generate nuisance faults and can invite leakage paths that degrade neighbouring channels.
The user's configuration (firmware V2.0, 0-20 mA range, 50 Hz integration, weak smoothing with 4 cycles) matches the hardware capabilities of the classic SB 1231 1 AI. None of these parameters is the cause of the burnout.
3. Wiring Topology for 4-20 mA Pressure Transmitters
A 4-20 mA loop is a current loop, not a voltage loop. The transmitter regulates current; the loop impedance is set by the receiver (the SB input shunt) plus the cable resistance. The PLC's analog input is just the far end of the loop.
For a 2-wire (loop-powered) pressure transmitter, the canonical wiring is:
+24 VDC ----> Transmitter (+) Transmitter (-) ----> SB 1231 terminal 0+ SB 1231 terminal M (or 0-) ----> 24 V common (0 V)
For a 3-wire transmitter (separate supply, current output referenced to common):
+24 VDC ----> Transmitter supply (+) Transmitter GND ----> 24 V common Transmitter Iout (+) ----> SB 1231 terminal 0+ SB 1231 terminal M ----> 24 V common
For a 4-wire (fully isolated) transmitter, the signal return is independent of the supply return; the SB M terminal must connect to the transmitter signal-return terminal, and 24 V common must connect to the transmitter supply-return terminal. Bond the two commons at one point only - usually at the PLC cabinet ground bar.
Terminal R on the SB 1231 is the sense resistor tap used in voltage measurement mode. In current mode it is not normally used; if a manual shows R being shorted to 0+ in current mode, that is a legacy variant. The crucial point is that 0+ and M are the two current-loop terminals.
Wire the shield at one end only, preferably at the cabinet entry, and bond the cabinet ground bar to a low-impedance facility ground. Do not use the shield as a current-carrying conductor. Cable types such as Belden 8761 (1 twisted pair, foil + braid shield) or Lapp Ölflex 110 CY are appropriate for 20 m runs in industrial environments.
4. Root Cause Analysis: Common-Mode Voltage and Transient Damage
Analog inputs fail when the voltage between any input terminal and the PLC's internal reference exceeds the common-mode limit. The SB is a precision front end with a limited common-mode range; exceeding it, even briefly, damages the input structure. Configuration in TIA Portal does not change the hardware's voltage-withstand rating. A "0-20 mA" software setting tells the ADC how to interpret the current; it does not protect the input from over-voltage. Input modules do not burn out because of wrong parameter settings; they burn out when a voltage above their rating is applied.
Common sources of common-mode or differential over-voltage on a 4-20 mA loop:
- Ground potential differences between the sensor's bonding point and the PLC cabinet. With a 20 m run, a 6 V ground-potential difference between sensor ground and PLC ground is plausible if the sensor is bonded to a structural steel point that has a different ground reference than the cabinet. This potential appears directly across the SB's M-to-PE insulation. Sustained over-voltage degrades the input; a transient spike destroys it.
- Induced transients from welding, VFDs, contactors, or lightning. A 24 V control circuit that shares a cable tray with welding returns or motor leads receives capacitive or inductive coupling that injects spikes bypassing the 24 V rail and reaches the analog input. The current loop is a low-impedance antenna for nearby high-di/dt events.
- Loop-powered devices with shared commons. If the 24 V supply to the sensor is referenced to a different ground point than the PLC 24 V, the 0 V rail sits above or below the PLC M terminal. Even 5-10 V of offset is enough to push the input outside its linear range and, with sustained stress, cause failure.
- Sensor failure modes. A failed sensor can present a short or a voltage to its output terminals. If the sensor's output is not current-limited, the SB input sees the supply rail directly. A failed regulator in a 3-wire sensor is a common culprit.
- Cable damage. Crushed or abraded insulation exposes the loop conductors to a chassis ground or to an AC power conductor. The 24 V supply and the SB input share a common return; a hard short to a power leg sends destructive energy into the input.
- Loose connector at the SB. The SB plugs onto the CPU's front connector; vibration, thermal cycling, or a poorly seated board can intermittently break the loop. This does not normally cause burnout, but it does generate high/low limit violations as the input floats.
The reported diagnostic events "High limit violated" and "Low limit violated" are dual-direction symptoms: the input is seeing values above the configured high limit and below the configured low limit, in turn. This is consistent with a floating input (cable broken or connector loose) or with the input structure saturating under common-mode stress. A working current loop with a working transmitter does not produce alternating high/low faults; the loop current is well-defined.
The reported peak loop current of 20.2 mA at 1 bar and 5.5 mA at 0 bar is normal for a 4-20 mA transmitter with the standard range. Current "above 20 mA but not above 55 mA" indicates the transmitter is operating correctly within its overrange margin and is not the source of the burnout. The burnout is on the SB side.
5. TIA Portal Configuration Parameters
The user's TIA Portal configuration is correct for a 4-20 mA loop on a 0-20 mA hardware range:
| Parameter | Value | Notes |
|---|---|---|
| Signal board / slot | AI1 (SignalBoard) | Configured under CPU properties > Signal Board |
| Firmware | V2.0 | Verify against installed CPU firmware; mismatched firmware can cause initialization faults |
| Measuring type | Current | Required for 4-20 mA |
| Range | 0-20 mA | Acceptable; 4-20 mA range is not available on the classic SB 1231 1 AI - the loop is read on a 0-20 mA scale and the 4 mA offset is handled in the application |
| Integration time | 50 Hz / 20 ms | Use 50 Hz in 50 Hz regions, 60 Hz in 60 Hz regions. Wrong setting adds mains-frequency ripple to the reading |
| Smoothing | Weak (4 cycles) | Light filtering; appropriate for a pressure loop. Strong smoothing increases step-response time |
| Overflow diagnostic | Enabled | Generates diagnostic interrupt on overrange |
| Underflow diagnostic | Enabled | Generates diagnostic interrupt on underrange |
| Hardware limit high | Configured value | Set above 20 mA scaled value with margin to detect out-of-range loop current |
| Hardware limit low | Configured value | Set below 4 mA scaled value with margin to detect loop break |
| I/O start address | 80 | IW80 (input word 80) for the AI value |
| I/O end address | 81 | One word for 1 AI |
| Process image | Cyclic PI | Standard for analog inputs |
| Hardware identifier | 270 | Used in OB82 (diagnostic interrupt) and WRREC/RDREC for parameter reassignment |
These settings do not protect the input from electrical over-stress. The hardware limit diagnostics only monitor the converted value within the configured range. To map a 4-20 mA loop to engineering units on a 0-20 mA scale in the application code, use the standard Siemens linearization:
EngineeringValue = ((RawValue - 0) / 27648) * (EngMax - EngMin) + EngMin
where 27648 is the nominal full-scale count for the 0-20 mA range on an S7-1200 analog input. A current of 4 mA reads 5529 counts, 20 mA reads 27648 counts. If raw reads above 27648 or below 0, the input is outside the nominal range - a sign of common-mode stress or sensor fault.
6. Diagnostic Event Interpretation
The PLC reports two diagnostic events on this installation: "High limit violated" and "Low limit violated". These come from the hardware limit monitor, not from the overflow/underflow diagnostics of the ADC. They fire when the converted count crosses the user-configured upper or lower limit.
Interpretation matrix:
| Symptom | Most likely cause |
|---|---|
| Alternating high and low limit violations with a working transmitter | Floating input (cable break, loose connector at SB) or input structure saturated by common-mode stress |
| Sustained high limit violation only | Transmitter out of range high, or input shorted to supply rail through a fault |
| Sustained low limit violation only | Loop break, transmitter at 0 mA, or input shorted to M terminal |
| Reading drifts, then the SB fails entirely | Common-mode stress has damaged the input; replace SB and remediate the loop |
| Reading correct, then sudden jump to overrange, then SB fails | Transient over-voltage event; install surge protection and isolation |
Handle the diagnostic interrupt in OB82 to log the event and the time stamp. The hardware identifier (270 in the user's case) appears in the OB82 start info and identifies which SB raised the event.
7. SCL Code for Scaling and OB82 Handling
Scale the raw input in a dedicated function block so that the scaling is consistent across the program and the 4 mA zero offset is handled in one place.
FUNCTION "AI_PressureScaling" : Real
TITLE = 'Scale SB 1231 0-20 mA raw to engineering units'
AUTHOR : 'Automation'
VERSION : 1.0
VAR_INPUT
i_RawValue : INT; // IW80 from SB 1231
i_RawMin : INT := 0;
i_RawMax : INT := 27648;
i_EngMin : REAL := 0.0;
i_EngMax : REAL := 10.0;
END_VAR
VAR_TEMP
t_Scaled : REAL;
END_VAR
BEGIN
IF i_RawValue < i_RawMin OR i_RawValue = 0 THEN
t_Scaled := i_EngMin; // Loop break / underflow
ELSIF i_RawValue > i_RawMax THEN
t_Scaled := i_EngMax; // Overrange / overstress
ELSE
t_Scaled := i_EngMin +
(INT_TO_REAL(i_RawValue - i_RawMin) /
INT_TO_REAL(i_RawMax - i_RawMin)) *
(i_EngMax - i_EngMin);
END_IF;
"AI_PressureScaling" := t_Scaled;
END_FUNCTION
Capture the diagnostic interrupt in OB82. The hardware identifier in OB82_MDL_ADDR tells you which module raised the event. For the SB 1231, the value is 270 in the user's configuration.
{ S7_Optimized_Access := 'FALSE' }
TITLE = 'Diagnostic Interrupt OB82'
AUTHOR : 'Automation'
VERSION : 1.0
VAR_TEMP
t_LADDR : WORD; // OB82_MDL_ADDR - hardware identifier
t_EventNo : WORD; // OB82_FLT_ID - diagnostic event number
t_Channel : WORD; // OB82_CHANNEL - channel number
END_VAR
BEGIN
NETWORK
TITLE = 'Log SB 1231 diagnostic event'
"DB_Diagnostics".Timestamp := INT_TO_REAL(READ_CLK());
"DB_Diagnostics".LADDR := #t_LADDR;
"DB_Diagnostics".EventNo := #t_EventNo;
"DB_Diagnostics".Channel := #t_Channel;
IF #t_LADDR = 270 THEN
"DB_Diagnostics".SB1231_Fault := TRUE;
// Optional: set a maintenance bit to flag SB replacement
END_IF;
END_ORGANIZATION_BLOCK
8. Field-Proven Remediation Procedure
Stop replacing the SB until the loop is corrected. Each replacement costs the board and the production time; repeated replacement without root-cause repair will keep failing. Execute the following steps in order:
- Isolate the input electrically. Insert a 4-20 mA loop isolator (also called a signal conditioner or galvanic isolator) between the field transmitter and the SB. The isolator provides galvanic isolation up to 1.5-3 kV, breaks ground loops, and clamps transients before they reach the SB. Recommended types: Phoenix Contact MACX MCR-EX-SL, Wago 857-401, or Siemens 6ES7 134-4GB52.
- Verify the cable. Replace the 4 x 0.75 mm² run with a shielded, twisted-pair instrumentation cable. Belden 8761, 8719, or 8762 are common choices. Use one pair for the current loop, one pair for the 24 V supply to a 2-wire transmitter. Ground the shield at the cabinet end only; do not ground at the field end to avoid ground loops.
- Bond grounds at one point. The PLC cabinet ground bar, the field transmitter's local ground (if any), and the 24 V supply 0 V must be bonded at a single point. If the sensor is bonded to structural steel, isolate the sensor signal from that bond with the loop isolator.
- Check the 24 V supply. Measure the 24 V rail at the PLC terminals under load. Ripple above 1 V peak-to-peak indicates a weak supply that may be sagging on transients. Use a linear or low-ripple DC supply for analog loops; switch-mode supplies can introduce common-mode noise that couples into the analog front end.
- Verify common-mode voltage. With the loop running, measure the voltage between SB terminal M and the transmitter's local ground. If the measured value is more than a few volts, the loop isolator is mandatory, not optional.
- Check for EMI sources. Inspect the cable route. Cable trays carrying VFD output cables, welding leads, or unfiltered relay contactor lines inject common-mode noise. Re-route the analog cable at least 200 mm from these sources, or use a steel conduit as a shield.
- Inspect the sensor. Disconnect the sensor and measure its output terminals with a multimeter. A 2-wire loop-powered sensor should source 4-20 mA into a 24 V loop with no more than 12 V drop across itself. If the sensor has an internal regulator failure, it may present a voltage instead of a current.
- Verify the SB seating. Power down, remove the SB, inspect the edge connector on the CPU and the mating connector on the SB. Look for bent pins, contamination, or cold solder joints. Reseat firmly.
9. Loop Isolator Selection and Wiring
A loop isolator converts a 4-20 mA input to an isolated 4-20 mA output. It has three ports: input (from the field), output (to the SB), and power (24 VDC). The input is galvanically isolated from the output and from the power supply, typically to 1.5-3 kV.
Selection criteria for the isolator:
- Input range: 4-20 mA (or 0-20 mA; many isolators accept both)
- Output range: 4-20 mA (or 0-20 mA to match SB)
- Isolation voltage: 1.5 kV minimum, 2.5 kV preferred for industrial sites
- Accuracy: < 0.1% of full scale
- Loop voltage drop: < 5 V at 20 mA (so the isolator does not starve a 2-wire transmitter)
- DIN rail mount, 6 mm or 12.5 mm width depending on channel count
For a 2-wire loop-powered transmitter, the isolator's input side provides the loop compliance voltage (typically 15-17 V at 20 mA). The transmitter's maximum loop voltage drop is 24 V - isolator drop - cable drop. With 20 m of 0.75 mm² copper, the cable drop is approximately 0.5 V at 20 mA, well within margin.
10. Surge and Transient Protection Strategy
Industrial analog loops are exposed to three classes of transient: (1) lightning-induced surges on outdoor cable runs, (2) switching transients from VFDs and contactors on shared cable trays, and (3) electrostatic discharge on operator-accessible equipment. For an indoor 20 m run with no outdoor exposure, class (2) is the dominant threat.
Protection components, applied as a two-stage scheme:
- Gas discharge tube (GDT) at the cabinet entry, between each loop conductor and the ground bar. Crowbar device, fires at 75-250 V. Slow response, high energy handling. Used as the first stage.
- TVS diode across the SB input terminals, 26 V working voltage (24 V nominal + tolerance), low capacitance. Fast response, low energy handling. Used as the second stage inside the cabinet near the SB.
- RC snubber on the 24 V supply rail near the isolator, 100 Ω + 100 nF typical. Suppresses switching transients from the supply itself.
- Common-mode choke in series with the loop, ferrite core, 1-2 mH. Attenuates high-frequency common-mode noise without affecting the 4-20 mA signal.
Siemens does not sell a dedicated surge protector for SB 1231 inputs. Third-party products such as Phoenix Contact PT-IQ series, Dehn DEHNguard, or Weidmüller VSPC are appropriate. For an indoor 20 m run, a PT-IQ 1x24 AC/DC is sufficient on the loop supply and a PT-IQ 2x24 on the signal pair.
11. Verification and Commissioning Procedure
After remediation, verify the loop before commissioning. Do not energise the new SB into a faulted loop.
- With the SB removed, power the loop. Measure the current at the SB end of the cable with a multimeter in series. It should read 4-20 mA over the transmitter's range.
- Measure the voltage between SB terminal M and the transmitter local ground. Less than 1 V is acceptable; more than 5 V means the isolator must remain in place.
- Measure the voltage between each loop conductor and the cabinet ground bar. Less than 24 V is acceptable; if it reads 0 V, the loop is shorted to ground somewhere.
- Power down, install the SB, power up. Verify the TIA Portal online diagnostics show no faults.
- Force the transmitter to its low and high calibration points (0 bar and full scale). Verify the PLC reading matches the transmitter datasheet within the documented accuracy of the SB (typically 0.3% of full scale for the 11-bit + sign SB).
- Run a 24-hour burn-in. Log the AI value to a trend and look for drift or spikes. A healthy loop holds within ±0.5% of full scale over 24 hours at constant pressure.
- Trigger a deliberate overrange by forcing the transmitter to 110% of range. Verify the diagnostic interrupt fires in OB82 and the high-limit violation is logged.
- Trigger a deliberate loop break by disconnecting one wire. Verify the underflow diagnostic fires and the low-limit violation is logged.
12. Field Commissioning Checklist
| Item | Check | Pass criterion |
|---|---|---|
| Cable type | Shielded, twisted pair | Yes, shield grounded at one end only |
| Cable route | Away from VFD / welding / contactor lines | > 200 mm separation, no parallel run in same tray |
| Loop isolator | Installed between field and SB | Yes, 1.5 kV isolation minimum |
| Common-mode voltage | Measured SB M to field ground | < 1 V with isolator |
| 24 V supply ripple | Measured at SB terminals | < 1 V peak-to-peak |
| SB seating | Visual inspection of edge connector | No bent pins, fully seated |
| TIA Portal configuration | Measuring type = Current, range = 0-20 mA | Matches wiring |
| Configuration downloaded | Online > Extended download to device | Yes, not just initial download |
| Diagnostic interrupt | OB82 present and tags filled | Logs hardware ID and event type |
| Hardware limits | High / low limits configured with margin | High > 20 mA scaled, Low < 4 mA scaled |
| Sensor health | Current sweep 0-100% of range | Linear within transmitter spec |
| 24-hour burn-in | Trend log of AI value | ±0.5% full scale, no spikes |
| Overrange test | Force 110% of range | High-limit diagnostic fires |
| Loop break test | Disconnect one conductor | Underflow diagnostic fires |
Reference for configuration parameter definitions: Siemens ID 91696622 - SB 1231 RTD signal board wiring and configuration.
Reference for unused-channel handling: SB 1231 AI 4x14 bit technical specifications.
13. Frequently Asked Questions
Can incorrect TIA Portal parameters cause the SB 1231 to burn out?
No. Configuration in TIA Portal sets the ADC range, integration time, smoothing, and diagnostic behaviour. It does not change the input's voltage or current-withstand rating. A wrong range produces a wrong reading, not a hardware failure. Burnout is caused by electrical over-stress on the input terminals - voltage above the common-mode limit, transients from welding or VFDs, or a sensor fault that injects supply voltage into the loop.
Why does the SB report "High limit violated" and "Low limit violated" at the same time?
These events fire from the hardware limit monitor when the converted value crosses the configured high or low threshold. A working current loop does not cross both limits in alternation. If the events alternate, the input is either floating (cable break, loose SB connector) or the input structure is saturated by common-mode stress. Treat alternating high/low violations as a symptom of an unhealthy loop, not as a sensor problem.
Is a 4-wire pressure sensor better than a 3-wire sensor for the SB 1231?
Yes for noise immunity. A 4-wire sensor has isolated supply and signal returns; the signal return is independent of the supply ground. This breaks the ground loop between the PLC cabinet and the sensor. A 3-wire sensor shares the supply return with the signal reference, which is the most common source of common-mode voltage on industrial analog loops.
What is the maximum common-mode voltage the SB 1231 can tolerate?
Refer to the specific SB variant's data sheet in the Siemens manual collection. Common-mode limits depend on the variant (classic 1 AI vs 4x14 bit) and the configured range. The official specification must be checked against the application; do not infer a limit from the symptom. The field fix - a loop isolator - eliminates the common-mode voltage entirely, which is the safer engineering approach.
Why does the SB read correctly for two weeks and then fail?
Repetitive failure after a working period is the signature of cumulative electrical over-stress. The input structure is damaged incrementally by repeated transients that exceed its common-mode or differential rating. Each event pushes the input closer to failure. The first weeks of operation are within the device's margin; the final event crosses the damage threshold. This is also a sign of an external stress (welding, lightning, VFD switching) that the loop is not protected against.