SR3MBU01BD input word %MW16 is Modbus 400017 in InTouch

Karen Mitchell6 min read
ModbusSchneider ElectricTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Why does the InTouch tag show zero or bad quality on the default 300001 address?

The InTouch tag sits on 300001, a 3x input-register address from a generic Modbus tutorial, while the SR3MBU01BD publishes its logic image as %MW words. Those words are the addresses the Zelio register map provides for inputs, outputs, and clock. The screen symptom is a tag frozen at 0, a bad-quality flag, or a value that does not change when the pushbutton is pressed. The cause is an item pointing at the wrong register, not a fault in the Zelio program.

Move the item from the generic 300001 address to the register that carries the signal you need. Address 400017 is the correct target for the first input word if your I/O server uses 1-based Modbus references, because %MW16 + 1 = 400017. If your server takes raw protocol offsets instead, the same word is offset 16 in the 4x table. Check which convention your topic uses before you decide the address is wrong.

Which Zelio words carry the inputs, outputs, and clock?

The Zelio register map assigns inputs to %MW16-%MW19, outputs to %MW20-%MW23, and the clock to %MW32-%MW35. The InTouch column below is derived with the 1-based assumption (add 1 to the %MW number, prefix 4).

Function Zelio word InTouch item (1-based)
Logic inputs %MW16-%MW19 400017-400020
Logic outputs %MW20-%MW23 400021-400024
Clock %MW32-%MW35 400033-400036

Confirm in the Zelio programming software that these words are present in the Modbus register table of your program before you build tags. A tag pointed at a register the unit does not expose returns an exception or a constant zero, and that looks identical to a wiring fault on the operator screen.

How do you read one pushbutton bit: bit item or integer tag with script?

Each input word packs several logic inputs as bits, so 400017 returns one 16-bit value, not one pushbutton. Two approaches exist for isolating a single PB.

Criterion A: Discrete tag on a bit of the word B: Integer tag on the word plus script extraction
InTouch tag I/O Discrete, item is the word address with a bit designator I/O Integer on 400017, memory discrete for the PB
Dependency Bit-suffix syntax must be supported by your I/O server; check its documentation None beyond standard 4x word reads
Bit-to-input mapping Hidden in the tag definition Visible in one script line per bit
Write behavior Server may do read-modify-write on the word You control the whole word write explicitly
Fault isolation Bad bit and bad word look the same Raw word visible on screen, so bit logic and binding are separable

Use B. It works on any Modbus RTU I/O server, and the raw word stays visible on a diagnostic window, so you separate a binding fault (word wrong) from a tag fault (bit extraction wrong). Use A only after your server documentation confirms the bit syntax and you have verified it against a live input.

How do you configure the read of a PB input from %MW16?

  1. Match the serial parameters (slave address, baud rate, parity, stop bits) between the Zelio Modbus settings and the InTouch I/O server topic. Read the Zelio values from its communication configuration; do not copy them from a tutorial.
  2. Create an I/O Integer tag, for example Zelio_IN_W0, with the item 400017 on that topic, read-only.
  3. Create a memory discrete tag, for example PB1_Status, for the pushbutton.
  4. In a data-change QuickScript on Zelio_IN_W0, extract bit n of the word. Logic, adapt to the functions your InTouch version provides:
    PB1_Status = ( Zelio_IN_W0 / 2^n ) mod 2   \ integer division, n = bit position of the PB in the word
  5. Find n by toggling the physical input and watching which bit of Zelio_IN_W0 changes. Bit order per input comes from the Zelio documentation; confirm it on the live unit.

For writes from InTouch, use a word the Zelio program is written to read, and confirm in the Zelio software that the word is writable. Treat the input image words %MW16-%MW19 as a status image refreshed by the unit; a write to them from the supervisory side can be overwritten on the next cycle. Write whole words, not single bits, so no other bit in the word changes unintentionally.

What faults look like a Modbus problem but are not?

Operator sees Layer Check
All Zelio tags bad quality Binding (topic, serial, slave address) Server diagnostics for the topic; parameters against the Zelio settings
Word reads, but always 0 Binding (wrong table, e.g. 3x instead of 4x) Item must start with 4 for holding registers
Value is the neighbor word's data Offset (0-based vs 1-based) Compare 400017 with 16 against a known non-zero word such as the clock
Word correct, PB indicator wrong Tag (bit position or script) Watch raw word bits while pressing the PB
PB indicator sticks after release Tag (script runs only on change of the wrong tag) Script trigger must be the word tag, condition on data change

The offset check is quick: the clock words at %MW32-%MW35 change with time, so a 1-based item 400033 that shows moving values confirms the offset convention without touching the process.

How do you verify the PB read end to end?

  1. Read Zelio_IN_W0 (400017) with all inputs off; the word reads 0 or the known idle value.
  2. Press the pushbutton and confirm exactly one bit of Zelio_IN_W0 changes, and that it is the bit your script extracts.
  3. Confirm PB1_Status follows the pushbutton on press and release.
  4. Read the clock item 400033 and confirm it changes with time, which proves the offset convention.
  5. Cycle the unit's power and confirm the tags return to good quality without a manual restart of the topic.

FAQ

What happens if I keep the 300001 address in InTouch?

The item addresses the 3x input-register table, so the tag returns zero, a constant, or bad quality instead of the Zelio logic image. Change it to a 4x holding-register item such as 400017 for the input word.

What happens if my I/O server uses 0-based addressing and I enter 400017?

The item lands one word high and reads the next register (%MW17) instead of %MW16. Enter the 0-based equivalent your server expects, and confirm with the clock words, which change continuously.

What happens if I write a single bit to a holding register from InTouch?

The Modbus write goes to the whole 16-bit word, so a server that does not read-modify-write can clear the other bits in it. Write complete words and use a Zelio-side word designed to receive them.

What happens if I write to the input words %MW16-%MW19?

Those words are the logic-input image, refreshed by the unit, so a written value can be replaced on the next cycle. Use a word the Zelio program reads for commands from the supervisory system.

What happens if the bit position in my script is wrong?

The raw word 400017 changes correctly but PB1_Status shows another input or never changes. Press the physical pushbutton, watch which bit of the raw word toggles, and correct n in the script.

Back to blog