Overview: S5-135U and CPU 928B Analog I/O Architecture
The Siemens SIMATIC S5-135U is a mid-range PLC from the SIMATIC S5 family. The CPU 928B is the high-end processor of that platform and continues to appear in legacy machine retrofits, brownfield process skids, and maintenance contracts for plants that have not yet migrated to S7-1500 or PCS 7. When a maintenance engineer says "I need to check the analog input and output cards," they typically mean three field tasks: verifying the analog input (AI) module converts a known sensor signal to the expected digital count, confirming the analog output (AO) module converts a written count to the expected voltage or current, and proving the backplane wiring, shield grounding, and 24 V supply are all healthy before the production program takes over.
All three tasks reduce to the same STEP 5 routine: a load from the peripheral area (L PW) for the read path and a transfer to the peripheral area (T PW) for the write path, executed inside a logic block (PB1 in the example) that OB1 calls on every scan. The rest of this article covers the address map that makes those instructions point at the correct slot, the scaling rules that turn counts into engineering units, and a multimeter-driven verification sequence that an instrumentation technician can complete without a STEP 5 programmer online.
Why PW and Not PY
Analog channels on the S5-135U occupy 16 bits, so the correct operand size is the peripheral word (PW). Using PY (peripheral byte) reads only 8 bits and returns the wrong half of the conversion. STEP 5 will accept PY on legacy digital modules, but any analog module in the 6ES5 460, 6ES5 463, 6ES5 464, 6ES5 470, or 6ES5 472 families must be addressed with PW. The same rule applies in the extended O area: use OW, not OY, for analog channels. This is the single most common mistake when bringing an AI/AO card back into service after a long shutdown, and it is the first thing to verify in any L PW / T PW troubleshooting call.
CPU 928B Address Areas
The CPU 928B organises process I/O into four address spaces that STEP 5 instructions can read or write:
| Area | Mnemonic | Operand Size | Typical Use |
|---|---|---|---|
| P (Peripheral) | PY / PW | Byte / Word | Default I/O slots 0-20 in the central rack and on IM 300/301 expansion racks |
| O (Extended Peripheral) | OY / OW | Byte / Word | Extended analog I/O via IM 3 / IM 4 interfaces |
| I (Input) | IB / IW | Byte / Word | Digital inputs (PII - Process Image Input) |
| Q (Output) | QB / QW | Byte / Word | Digital outputs (PIQ - Process Image Output) |
| F (Flag) | FY / FW | Byte / Word | Internal memory for scratch and intermediate values |
The analog backplane data lives in the P area; if you have IM 3 or IM 4 interface modules, additional analog channels may appear in the O area. Confirm which area your module is wired to by checking the slot assignment in the STEP 5 hardware configuration (COM 928B / COM 135U) or by reading the module's label.
CPU 928B Memory Model and Scan Cycle
The CPU 928B holds up to 46 KB of user RAM organised into blocks of 2 KB each. OB1, PB1..PB256, FB1..FB256, DB1..DB255, and SB0..SB255 share that address space. The CPU runs OB1 cyclically; any block OB1 calls runs in priority order. Analog I/O is read directly from the peripheral area and is not latched into the process image, which means the value seen by L PW is always current to the last backplane scan. By contrast, L IB reads the process image that was captured at the start of the cycle, which is acceptable for digital inputs but stale for analog inputs sampled between two OB1 passes.
Prerequisites
Before loading the test routine, assemble the following:
- STEP 5 programming device. A PG 685, PG 710, PG 720, PG 740, PG 750, or any PC running STEP 5 V6.x or V7.x with the COM 928B driver. STEP 5 V7.x supports the CPU 928B but blocks written in older STL syntax still load and run.
- Online connection. Either the serial PG cable to the CPU 928B front port or an AS511 interface. Newer PGs may need an RS-232-to-TTY converter for the CPU 928B front port.
- Calibrated multimeter. For verifying AO voltage or current and for measuring sensor excitation at the AI terminal block. True-RMS meters are preferred so noise on the loop can be quantified.
- Calibrated signal source. Either a process calibrator (Beamex MC5, Fluke 754, or similar) or a precision voltage/current reference capable of producing the module's full input range. If neither is available, jumper the AI input to a known 24 VDC loop supply and accept that the resulting reading will sit near full scale, not at engineering zero.
- Module datasheet. The 6ES5 4xx module manual showing the slot-to-address map, the input/output ranges selected by the front-panel DIL switch, and the pinout.
- Lockout/tagout on field wiring. Disconnect the loop from the controlled device before driving an AO test value, and isolate the AI loop from the sensor before back-driving with a calibrator.
Peripheral (P) Area Address Map for Analog Modules
The default analog address window on a CPU 928B without extended I/O is P 128 to P 255 (words). Each analog module occupies one 16-bit word per channel, but the channels are packed into a single word in groups of two when the module supports it, so the slot-to-PW translation depends on the module.
Default Slot Map (Central Rack, S5-135U)
| Slot | Module Family | Typical Address (Word) | Address (Byte) |
|---|---|---|---|
| 0 | PS 951 / 952 power supply | — | — |
| 1-2 | CPU 928B | — | — |
| 3 | Reserved / IM 300/301 | — | — |
| 4 | Digital I/O (default) | PW 0-127 | PY 0-255 |
| 5 | Digital I/O or analog | PW 128-255 | PY 256-511 |
| 6-20 | Analog I/O | PW 128-255 | PY 256-511 |
Slots 4 and above are configurable. The COM 928B configuration tool assigns each slot's start address. Without a custom configuration, the S5-135U reserves slots 0-4 for the CPU and digital I/O, and places the analog modules starting at slot 5 with their first word at PW 128. If your analog module is in slot 4 because digital cards have been moved, the start address may be PW 0. Read the configuration before assuming PW 128.
Module-Specific Start Addresses
| MLFB | Module | Channels | Channels / Word |
|---|---|---|---|
| 6ES5 460-7LA12 | AI 8x ±10 V / 0-10 V | 8 | 2 |
| 6ES5 463-4UA12 | AI 8x ±20 mA / 4-20 mA | 8 | 2 |
| 6ES5 464-8MA12 | AI 8x RTD (Pt100) | 8 | 1 |
| 6ES5 470-4UA12 | AO 8x ±10 V | 8 | 2 |
| 6ES5 472-4UA12 | AO 8x 0/4-20 mA | 8 | 2 |
For 2-channel-per-word modules, channel 0 and channel 1 share PW n, channel 2 and channel 3 share PW n+2, and so on. The high byte of the word is channel n+1, the low byte is channel n. To isolate one channel for diagnostics, mask the unwanted byte with AW (AND Word) and shift with SLW / SRW.
STEP 5 Instructions for Analog I/O
L PW: Load Peripheral Word (Read Analog Input)
L PW reads 16 bits from the peripheral area without altering the process image. It is the correct instruction to read a live analog value mid-scan. Operands are 0 to 255 in the P area. On a CPU 928B without IM 3/IM 4, the analog read fits inside PW 128 to PW 255. The instruction does not block, does not require the CPU to be in RUN-P (it works in RUN and STOP for read), and does not need an explicit enable bit.
L PW 144
T FW 100
BE
This reads the analog input at PW 144 (default for slot 6, channels 0/1 on a 6ES5 460-x) and stores the 16-bit count into flag word FW 100, where a programmer online can monitor it without disturbing the scan.
T PW: Transfer to Peripheral Word (Write Analog Output)
T PW writes 16 bits directly to the peripheral output. Unlike Q outputs, P outputs are written immediately and do not pass through the process image output (PIQ). For AO modules, immediate peripheral write is mandatory because the analog converter needs the value at the end of every scan. T PW is allowed in RUN, RUN-P, and STOP with output enable; in plain STOP without output enable, the AO returns to its de-energised state.
L FW 100
T PW 160
BE
This copies the count from FW 100 directly to PW 160 (default start address for slot 7, channels 0/1 on a 6ES5 470-x), forcing that output to the corresponding voltage or current level.
L OW / T OW: Extended Analog via O Area
If the analog module sits behind an IM 3 or IM 4 expansion interface and has been configured for O area addressing, use OW instead of PW. The O area is a second 256-word peripheral window that does not collide with the central P area. This is the only case where L OY / T OY is appropriate (and even then, only for digital channels, since analog must be OW).
L OW 16
T OW 32
BE
Do not mix P and O addressing for the same module. If the COM 928B configuration placed the slot in the O area, every read or write for that module uses L OW / T OW.
L PB / T PB: Edge Cases
STEP 5 also supports peripheral byte operations (L PB / T PB) on some versions of the CPU 928B for diagnostic or partial-word writes. These are not recommended for analog modules because they leave half the channel un-updated and may cause the converter to latch a stale half. Use only PW for any analog channel that is part of a 2-channel-per-word module.
STEP 5 Programs to Check Analog Modules
The block structure on the CPU 928B follows the SIMATIC S5 convention: organisation blocks (OB) are called by the system, program blocks (PB) and function blocks (FB) are called by OBs. The simplest analog check uses a single PB1 called once per scan from OB1.
Read AI into a Flag (Diagnostic Read)
Load the analog input at PW 144 into flag word FW 100. Watch FW 100 in the PG status display or cross-reference while varying the input with a calibrator.
PB 1
L PW 144
T FW 100
BE
To call PB1 from OB1, add the call to OB1:
OB 1
SPA PB 1
BE
Echo AI to AO (End-to-End Loop Check)
Once the AI reads correctly, drive the AO with the same count to verify the output stage. This is the standard bench-test before a controlled device (valve, VFD reference, transmitter) is wired in.
PB 1
L PW 144
T PW 160
BE
Use a multimeter on the AO terminals to confirm the loop current or voltage matches the expected value. Drive the AI calibrator through its full range and confirm the AO follows linearly.
Hard-Coded AO Test Value
To isolate the AO from the AI, write a fixed count and verify the output. Useful when the AI is faulty but the AO card is the suspect.
PB 1
L KH 7FFF
T PW 160
BE
KH 7FFF is the maximum 16-bit count (32767). For a 0-10 V AO module, this produces +10 V at the terminal; for ±10 V, this is +10 V. Use KH 0000 for 0 V and KH 8000 for -10 V. For a 4-20 mA module with a 0-32767 raw scale, 4 mA corresponds to 0 counts and 20 mA to 32767; mid-scale 12 mA is roughly KH 4000.
Byte-Mask One Channel
To read a single channel from a two-channel-per-word AI module, mask the unwanted byte:
PB 1
L PW 144
SRW 8
T FW 100
BE
SRW 8 (Shift Right Word 8) drops the high byte and leaves FW 100 holding channel 0. Swap the shift direction for channel 1.
Status Word Output for HMI Display
During commissioning, copy the raw AI value to the flag area that the HMI polls, then graph it on a trend. A flat-line trend with no movement is the same diagnostic as a frozen FW 100, but the trend makes the fault visible to operators without a PG.
PB 1
L PW 144
T FW 200
T FW 202
T FW 204
BE
Three flag words (200, 202, 204) feed the trend at the HMI. Each can be scaled later when the engineering units are confirmed.
Scaling the Raw Count to Engineering Units
Siemens S5 analog modules return a signed 16-bit count whose range depends on the resolution of the converter and the configured input type. The most common configurations and their conversion factors are:
| Module Range | Raw Min | Raw Max | Engineering Min | Engineering Max | Linear Equation |
|---|---|---|---|---|---|
| ±10 V (12-bit) | -2048 | +2047 | -10.000 V | +10.000 V | V = count × 10 / 2048 |
| 0-10 V (12-bit) | 0 | +2047 | 0.000 V | 10.000 V | V = count × 10 / 2047 |
| 0-20 mA (12-bit) | 0 | +2047 | 0.000 mA | 20.000 mA | mA = count × 20 / 2047 |
| 4-20 mA (12-bit) | 0 | +2047 | 4.000 mA | 20.000 mA | mA = 4 + (count × 16 / 2047) |
| ±20 mA (12-bit) | -2048 | +2047 | -20.000 mA | +20.000 mA | mA = count × 20 / 2048 |
| Pt100 (4-wire) | 0 | +2047 | -50 °C | +850 °C | °C = -50 + (count × 900 / 2047) |
Standard STEP 5 function blocks FB 250 (analog input scaling) and FB 251 (analog output scaling) implement these equations automatically when supplied with the module's range codes. FB 250 takes the raw count from a configured PW input and returns a scaled floating-point result in a flag word pair. FB 251 takes a flag word pair containing the engineering value and produces the raw count for T PW to write. The block library entries are documented in the STEP 5 standard software manual.
When FB 250 is not present in the project's library, the scaling can be hand-coded in STL:
PB 2
L PW 144
L KF +2048
>F
L KF +10000
*F
L KF +2048
/F
RND
T FW 110
BE
The above routine rescales a ±10 V AI (range -2048 to +2047) to engineering units -10000 to +10000 (hundredths of a volt). RND rounds the floating-point result back to integer for flag storage. STEP 5 floating-point uses 32-bit mantissa + 8-bit exponent, giving roughly 7 significant digits before rounding errors become visible.
Worked Example: 4-20 mA Pressure Transducer
A pressure transmitter is ranged 0-10 bar across 4-20 mA. The AI module is configured for 4-20 mA, so the raw range is 0 to 2047 counts.
- 0 bar corresponds to 4 mA = 0 counts
- 10 bar corresponds to 20 mA = 2047 counts
- bar = count × 10 / 2047
- For count = 1024 (mid-scale 12 mA): bar = 1024 × 10 / 2047 = 5.00 bar
If the engineering units are required in tenths of a bar (0-100), multiply the result by 10:
PB 3
L PW 144
L KF +2047
>F
L KF +1000
*F
L KF +2047
/F
RND
T FW 110
BE
Verification Procedure with a Multimeter
Once the test program is loaded and the PB1 call is confirmed in OB1, run the following verification sequence. Execute with the field wiring isolated.
- Confirm PB1 is called. Open OB1 in STEP 5 and verify SPA PB 1 is present at the desired priority. If absent, the block never runs and the analog read stays at zero regardless of input.
- Confirm STOP -> RUN transition. The mode selector on the CPU 928B must be in RUN or RUN-P. If the CPU is in STOP, no analog writes happen and P reads return either the de-energised state or frozen data depending on the module.
- Watch FW 100 in status. From the PG, open FW 100 in the status display. The value should change as the input changes. A frozen value at 0 or 7FFF indicates a wiring or addressing fault.
- Verify AI with a calibrator. Inject a known signal at the AI terminal block: 0%, 25%, 50%, 75%, 100% of range. Each step should produce a count at the expected percentage of the raw range. Calculate the expected count for each step using the scaling table.
- Verify AO with a multimeter. With PB1 echoing AI to AO (T PW 160), the AO terminal voltage or current should follow the calibrator input linearly. For 4-20 mA, expect 4.00 mA at count 0 and 20.00 mA at count 2047.
- Verify AO with hard-coded value. Change PB1 to L KH 7FFF / T PW 160. Confirm the AO reads full scale. Restore the echo routine after the test.
- Check shield and ground. One of the most common field faults is a broken shield bond, which couples 50/60 Hz into the AI and shows up as noise on the count. Use the multimeter AC range to measure between the shield and panel ground; expect less than 1 V AC.
- Verify module DIL switch position. Each 6ES5 4xx module has a DIL switch selecting the input/output range. Confirm the switch matches the COM 928B configuration or the project's documentation. A mismatched switch produces wrong counts even with a correct address.
Expected Reading Reference Table
| Range | Calibrator Setting | Expected Count | Acceptable Tolerance |
|---|---|---|---|
| 0-10 V | 0.000 V | 0 | ±2 counts |
| 0-10 V | 5.000 V | 1024 | ±2 counts |
| 0-10 V | 10.000 V | 2047 | ±2 counts |
| 4-20 mA | 4.000 mA | 0 | ±2 counts |
| 4-20 mA | 12.000 mA | 1024 | ±2 counts |
| 4-20 mA | 20.000 mA | 2047 | ±2 counts |
| ±10 V | -10.000 V | -2048 | ±2 counts |
| ±10 V | 0.000 V | 0 | ±2 counts |
| ±10 V | +10.000 V | +2047 | ±2 counts |
Extended I/O via IM 3, IM 4, and the O Area
The CPU 928B supports the IM 3 and IM 4 interface modules for distributed I/O racks. When analog modules are placed behind an IM 3 or IM 4, COM 928B may assign them to the O area instead of the P area. In that case:
- Use L OW (not L PW) to read
- Use T OW (not T PW) to write
- The O area shares the 0-255 address window with the P area, but the addresses are independent
- L OY / T OY is only valid for digital channels on the O area; analog must be OW
If the project documentation does not state whether the AI/AO module is on the P area or the O area, try L PW first. If the value reads as zero or as a frozen all-ones pattern, switch to L OW. The CPU 928B will not trap the wrong operand, so the wrong instruction simply returns junk without raising a fault.
On platforms that pre-date the unified STEP 5 addressing model (CPU 922, CPU 928, CPU 928B), the O area was reserved for the expanded I/O subsystem and was only available when the IM 3 / IM 4 interface was fitted. On the CPU 928B, the O area is enabled by setting the corresponding bits in the system data word. The exact system data word depends on the COM 928B configuration; consult the S5-135U hardware manual for the active version.
IM 300 vs IM 301 vs IM 3 vs IM 4
| Interface Module | Used For | Address Area | Max Distance |
|---|---|---|---|
| IM 300 | Central rack expansion | P area, slots 0-20 | Within cabinet |
| IM 301 | Distributed rack expansion | P area, slots 0-20 | Up to 100 m |
| IM 3 | Extended I/O for CPU 928 family | O area | Up to 200 m |
| IM 4 | Extended I/O with diagnostics | O area | Up to 600 m |
IM 300 and IM 301 keep the modules in the P area, so L PW / T PW is correct. IM 3 and IM 4 push the modules into the O area, so L OW / T OW is required. This distinction is the single most common source of "address looks right but value is wrong" faults.
Troubleshooting Matrix
| Symptom | Probable Cause | Diagnostic Step | Fix |
|---|---|---|---|
| FW 100 stays 0000 regardless of input | Wrong PW address; PB1 not called from OB1; module not configured | Verify SPA PB 1 in OB1; check module slot in COM 928B; verify 24 V supply | Correct address or add PB1 call; reconfigure slot; restore 24 V |
| FW 100 stays 7FFF (32767) | Open input wire; over-range signal; wrong polarity | Measure loop voltage; check polarity at terminal block | Repair open wire; correct polarity; reduce signal to range |
| FW 100 stays 8000 (-32768) | Negative over-range; broken sensor; RTD open | Check sensor wiring; verify DIL switch on RTD module | Repair sensor; reset DIL switch |
| FW 100 noisy (jumps ±20 counts) | Shield not bonded; long cable run; AC coupling | Measure AC between shield and ground; check for VFD or large motors nearby | Bond shield at panel end only; segregate from power; add filtering |
| FW 100 drifts with temperature | Module self-heating; cold-junction compensation drift on TC module | Wait 30 minutes for warmup; check ambient temp near module | Re-locate module; install CJC compensation |
| AO at 0 V despite T PW 160 | Wrong PW address; AO module not inserted; 24 V supply missing on AO module | Verify slot in COM 928B; check AO module 24 V LED | Correct address; reseat module; restore 24 V supply |
| AO reads -10 V when +10 V expected | Sign bit interpretation wrong; wrong range selected on module DIL switch | Verify DIL switch position matches STEP 5 configuration | Re-set DIL switch to match configuration |
| AO reads half-scale regardless of written value | Module in test mode; DIL switch on "default" rather than "configured" | Inspect module DIL switch; check module manual | Set DIL switch to match COM 928B configuration |
| STEP 5 rejects L PW 256 | PW address out of range (0-255 only) | Re-examine slot-to-address map; consider IM 3/IM 4 and O area | Use L OW with appropriate O area address |
| PG status shows PB1 "not loaded" | Block was deleted from RAM; EPROM/Flash mismatch | Check EPROM presence; reload PB1 from PG | Reload PB1; re-burn EPROM if needed |
| CPU 928B enters STOP after PB1 call | Stack overflow; floating-point exception in scaling | Check ACCU2 for divide-by-zero; verify scaling constants | Guard division with limit check; add OB21/OB22 handler |
Safety and Field Commissioning Notes
- Lockout/tagout the 24 V field supply before removing the module's terminal block.
- Never back-drive a current-output transmitter with a voltage source; the transmitter will clamp and may be damaged.
- Verify the shield is bonded at the panel end only. Bonding at both ends creates a ground loop that injects 50/60 Hz noise into the AI.
- Confirm the module's 24 V supply is fused. The S5-135U backplane does not fuse the field-side 24 V; a wiring fault on the terminal block can short the supply and damage the module.
- Record the slot-to-address map and the DIL switch position for every analog module. This information is required to interpret future fault diagnostics and is frequently missing on legacy systems.
- When migrating a STEP 5 program to STEP 7 / TIA Portal, the L PW / T PW instructions become %IW / %QW with a PQW address. The address translation is not 1:1; consult the migration guide for the target platform and rebuild the scaling with FC105 / FC106 or the new SCL blocks.
- Always verify the analog reading against a known good reference (calibrator, dead-weight tester, or calibrated transmitter) before declaring the loop "checked." A green LED on the module only confirms that the module has power, not that the reading is correct.
Cross-Platform Reference
The principle of reading analog inputs into the peripheral area and writing to the peripheral area for outputs is consistent across SIMATIC families and across non-Siemens platforms. Allen-Bradley ControlLogix uses analog modules with status and fault words that occupy the same chassis slot as the data words, documented in the ControlLogix Analog I/O Modules User Manual (1756-UM009). AutomationDirect Do-more CPUs auto-map analog I/O into the memory map based on slot population, as described in the Do-more analog module mapping documentation. When porting a STEP 5 analog test to ControlLogix or Do-more, the address arithmetic changes, but the read-back and force-output verification methodology is identical: load the input word, transfer to a flag, then optionally echo to the output word and confirm with a multimeter.
For historical Siemens S5 documentation, the CPU 928B and STEP 5 programming manual are available through the Siemens Industry Online Support portal at support.industry.siemens.com; the historical entry referenced by the source community is archived under entry 40127.
FAQ
Why does my S5-135U analog input read 0 or 32767 instead of the process value?
An all-zeros reading with the field wired typically means PB1 is not being called from OB1, the module is not configured in COM 928B, or the 24 V supply on the analog module is missing. A frozen 7FFF (32767) reading means the input is open or the applied signal is above range. Measure the loop voltage at the terminal block, confirm 24 V is present, and verify SPA PB 1 is in OB1.
Can I use PY to read an analog input on the S5-135U?
No. Analog modules in the 6ES5 460-x, 6ES5 463-x, 6ES5 464-x, 6ES5 470-x, and 6ES5 472-x families are 16-bit and must be addressed with PW (or OW in the extended O area). PY reads only the low or high byte and returns a corrupted count, which shows up as a noisy or zero reading even with a correct signal applied.
How do I scale 0-2047 counts to 4-20 mA on an S5-135U 4-20 mA input?
The linear equation is mA = 4 + (count × 16 / 2047). Use FB 250 from the STEP 5 standard library if available, or hand-code the scaling in STL using F (floating-point) operations and RND to round back to integer for flag storage. For 0 bar to 10 bar on a 4-20 mA pressure transmitter, the equivalent equation is bar = count × 10 / 2047.
What is the difference between the P area and the O area on the CPU 928B?
P area (PY/PW) is the default peripheral window for the central rack and IM 300/301 expansion. O area (OY/OW) is the extended peripheral window used by IM 3/IM 4 interfaces. The two areas share the 0-255 address window but are independent. If your module is on the O area, you must use L OW / T OW; if it is on the P area, use L PW / T PW. Wrong-area addressing does not raise a fault, so verify against the COM 928B configuration rather than guessing.
PB1 is loaded but does not appear to execute. What should I check first?
Confirm SPA PB 1 (or JU PB 1) is present in OB1 at the desired priority. The CPU 928B only executes blocks called from OB1, OB21, OB22, or by interrupt OBs. A block that is loaded but never called produces no scan output even though it appears in the cross-reference. Also confirm the block is in user RAM and not shadowed by an EPROM of the same number; if both are present, the EPROM version wins.