Overview: The Indexed HMI Variable Problem
When a SIMATIC PLC exposes a data block that contains an ARRAY of identical structures (for example, DB_Drive.DRV[0..31] holding Goal_Pos, Actual_Pos, Enable and other parameters per drive), engineers naturally want to bind a single HMI faceplate or a single set of E/A fields to "whichever drive the operator currently selects". The selection is driven by an index variable such as DriveNumber typed as INT or DINT.
The intuitive attempt is to type the symbolic path directly into the HMI variable table, for example "DB_Drive".DRV[DriveNumber].Goal_Pos. The HMI compiler rejects the path because TIA Portal HMI tags require a static, fully resolved symbolic name at compile time; only the PLC's SCL/ STL/ LAD/FBD editors evaluate index expressions at runtime. The same restriction applies to Drive.DRV_[Index].Goal_Pos or any bracketed indirection embedded inside an HMI tag's PLC name field.
Three production-grade methods solve the problem without changing the existing DB_Drive structure or breaking the installed base of running machines:
- Method 1 – Native HMI tag multiplexing (WinCC Unified, WinCC Professional, WinCC Comfort/Advanced where supported).
- Method 2 – PLC-side mirror DB that copies the indexed element into a single-instance shadow structure that the HMI addresses directly.
- Method 3 – VBScript or C-script runtime indirection on legacy panels that lack multiplexing support.
Why Direct Indexed Addressing Fails in TIA Portal HMI Tags
The HMI tag table in TIA Portal produces a fixed-point list of absolute PLC addresses at compile time. The runtime on the panel resolves each tag only by its symbolic name to a single byte/bit offset inside a known DB. The HMI does not contain the SCL compiler; expressions such as DRV[DriveNumber] cannot be evaluated by the panel firmware. The PLC accepts the index because the SCL/STL instruction set implements DB[DBD].DRV[i] at runtime, but the HMI side has no equivalent engine.
The result on screen is one of the following diagnostics in the TIA Portal "Compile" output or directly on the panel:
- "The PLC tag does not exist or is not accessible."
- "Invalid address or unsupported data type."
- Field remains greyed out and shows
####or???at runtime.
Prerequisites
- TIA Portal V16 or later recommended. Multiplexing for WinCC Unified became broadly available from V15.1; legacy Comfort/Advanced panels require the multiplexing add-on from V14 SP1. Refer to the Siemens Industry Online Support entry for "Multiplexing in WinCC" for the exact panel firmware / TIA Portal compatibility matrix.
- SIMATIC panel: Comfort, Unified Comfort, or WinCC Runtime Professional. Basic panels (KTP400 mono and KTP700/1000 mono) historically did not support multiplexing; use the mirror-DB method instead.
- PLC: SIMATIC S7-1200 (firmware V4.2 or later) or S7-1500 (any standard firmware). Symbolic addressing must be enabled and the DB must be downloaded with optimized access or with standard access as appropriate for the chosen method.
- Source DB structure already defined (do not modify it because the installed base depends on it). A typical pattern:
TYPE UDT_Drive :
STRUCT
Goal_Pos : REAL;
Actual_Pos : REAL;
Enable : BOOL;
Run : BOOL;
Error : BOOL;
END_STRUCT;
END_TYPE
DATA_BLOCK DB_Drive
STRUCT
DRV : ARRAY[0..31] OF UDT_Drive;
END_STRUCT
END_DATA_BLOCK
Method 1 – Native HMI Tag Multiplexing (WinCC)
Native multiplexing in WinCC Unified and WinCC Comfort/Advanced lets a single HMI tag point to one of N configured PLC tags. The selection is driven by a separate HMI index tag whose value the runtime reads to choose which physical connection is active. Bidirectional read/write is supported, which makes this method the cleanest answer to "I want to see and modify the value with one E/A box".
Configuration Steps
- In the TIA Portal project tree, open HMI Tags and create a new tag, e.g.
HMI_Goal_Pos, with data typeREALand the desired acquisition cycle (250 ms default is acceptable for axis position). - Open the tag's properties and select Multiplexing. Enable the option and add one row per drive index you want to address. Each row contains the fully qualified symbolic PLC tag:
"DB_Drive".DRV[0].Goal_Pos,"DB_Drive".DRV[1].Goal_Pos, …"DB_Drive".DRV[31].Goal_Pos. - Bind the Index tag property to the PLC tag that carries the current drive selection, typically
"DB_Drive".DriveNumber(INT) or any HMI tag that mirrors it. - Drag the multiplexed tag
HMI_Goal_Posonto the screen and bind an E/A field to it. Set the field to Input/Output mode. The field now reads from and writes to whichever drive the index variable points at. - Repeat the procedure for each member of the UDT you want to expose (for example
HMI_Enable,HMI_Actual_Pos).
HMI_Goal_Pos from the panel is routed back to the currently indexed PLC tag exactly as a write to a non-multiplexed tag would be. This is the answer to the field question "does it work for read and write?" – yes.Runtime Behaviour and Limits
- Index out of range (for example DriveNumber = 32 in a 0..31 array) causes the HMI to keep the previous value and raise a connection diagnostic in the alarm log. Always clamp the index in the PLC:
IF DriveNumber > 31 OR DriveNumber < 0 THEN DriveNumber := 0; END_IF; - Multiplexing is processed on every acquisition cycle of the tag. A 100 ms cycle is the practical lower bound; faster rates consume significant CPU on Comfort panels.
- WinCC Unified supports multiplexing across multiple PLCs as well, useful for cells that are split across controllers.
Method 2 – PLC-Side Mirror DB Approach
If the panel does not support multiplexing (Basic panels, older Multi panels, third-party SCADA, or WinCC Runtime on a PC that needs indirect addressing without tag lists), build a "mirror" or "shadow" DB on the PLC that always contains exactly one drive's data. The HMI addresses only this single-instance structure; a PLC routine copies the indexed element in and out on every scan.
Mirror DB Definition
DATA_BLOCK DB_DriveMirror
STRUCT
SelectedIndex : INT;
DRV : UDT_Drive; // single instance, not an array
NewValue : REAL; // staging area for incoming writes
Cmd_Apply : BOOL; // rising edge triggers a copy back
Cmd_Read : BOOL; // rising edge triggers a refresh from indexed source
END_STRUCT
END_DATA_BLOCK
Mirror Logic in SCL (S7-1500 / S7-1200)
// Called from OB35 every 100 ms or from a cyclic interrupt OB
IF #Cmd_Read OR (mirror.SelectedIndex <> last_index) THEN
IF (#SelectedIndex >= 0) AND (#SelectedIndex <= 31) THEN
#DRV := "DB_Drive".DRV[#SelectedIndex]; // copy indexed element to mirror
last_index := #SelectedIndex;
END_IF;
#Cmd_Read := FALSE;
END_IF;
IF #Cmd_Apply THEN
IF (#SelectedIndex >= 0) AND (#SelectedIndex <= 31) THEN
"DB_Drive".DRV[#SelectedIndex].Goal_Pos := #NewValue;
END_IF;
#Cmd_Apply := FALSE;
END_IF;
Bidirectional Operation
The mirror makes read flow trivial: the HMI binds an E/A field to DB_DriveMirror.DRV.Goal_Pos and the field always reflects the indexed drive. Writes need a small handshake because the panel cannot write directly into an array element. Typical pattern:
- Operator edits
DB_DriveMirror.NewValuein an HMI input field. - Operator presses Apply; the HMI button sets
DB_DriveMirror.Cmd_Apply= TRUE. - The PLC detects the rising edge and copies
NewValueinto the indexedDB_Drive.DRV[SelectedIndex].Goal_Pos, then clearsCmd_Apply. - On the next cycle,
DB_DriveMirror.DRV.Goal_Posis refreshed by the read direction, so the field shows the new value.
Method 3 – VBScript Runtime Multiplexing (Legacy Panels)
On Comfort panels running V14 firmware or earlier, and on WinCC Runtime Advanced, scripting is the alternative when neither native multiplexing nor a PLC mirror is desired. Two scripts, executed on tag-value-change or on button events, achieve the indirection.
Read Script (cyclically executed)
' VBScript – bound to the "Change value" event of the index HMI tag
Dim idx, path
idx = SmartTags("DriveNumber")
path = "DB_Drive".DRV[" & idx & "].Goal_Pos" ' symbolic path
SmartTags("HMI_Goal_Pos").Read path ' runtime resolve
Write Script (button "Apply" click)
Dim idx, newVal
idx = SmartTags("DriveNumber")
newVal = SmartTags("HMI_Goal_Pos_New")
SmartTags("HMI_Goal_Pos").Write "DB_Drive".DRV[" & idx & "].Goal_Pos", newVal
SmartTags("Cmd_Apply") = True
The script approach is the most fragile of the three because tag paths are concatenated at runtime; a typographical error in the DB name or a typo in the UDT element name produces a silent fault that only shows up in the panel's diagnostic buffer. Reserve this method for situations where Method 1 and Method 2 are not options.
Known Bugs and Field-Proven Caveats
Several issues are reported by field engineers when implementing indexed HMI bindings. The following list captures the most reproducible ones and the verified workaround for each.
| Symptom | Affected Configuration | Root Cause | Verified Workaround |
|---|---|---|---|
E/A field works but a button cannot toggle a BOOL when bound to a multiplexed tag |
WinCC Comfort V15.1, V16, V17 with Multiplexing enabled | The button toggles the local HMI tag value but the multiplexing engine writes the value back to the index only on a fixed acquisition cycle; rapid toggles are dropped. | Use Method 2 (mirror DB with explicit Cmd_Apply handshake) for BOOL tags. Alternatively, increase the acquisition cycle to 200 ms and use a button with Switch on / Switch off instead of Toggle. |
| Slider becomes invisible when its "Process value" tag is multiplexed | WinCC Unified V15 / V16 / V17, Comfort V17 | Slider visibility is computed from the minimum/maximum range, which are evaluated from the multiplexed source. If the indexed source is briefly invalid during index change, the range collapses and the slider is rendered with zero height. | Bind the slider to a non-multiplexed mirror tag (Method 2) and refresh the mirror in OB35. Keep the index change and the slider refresh inside the same PLC cycle. |
| Multiplexed tag shows the value of the previous index after a fast index change | All WinCC versions that support multiplexing | Acquisition cycle of the index tag is longer than the time between two index writes. | Reduce the index tag's acquisition cycle to 100 ms and clamp the index in the PLC; additionally, debounce the index using a hysteresis of 50 ms. |
| Multiplexing row editor refuses to accept a symbolic path with array brackets | TIA Portal V15 with WinCC Comfort older than V14 SP1 | Multiplexing feature not installed in this combination. | Update TIA Portal to V16 or later and ensure the WinCC option is installed. Reference the Siemens Industry Online Support compatibility matrix. |
Field shows #### on panel boot |
Panels with reduced memory (KTP700 Basic, KTP1000 Basic) | Multiplexing is not available on Basic panels. | Use Method 2 (mirror DB). |
Verification Checklist
- Compile the TIA Portal project. The "Compile" log must contain no "The tag is not assigned to a PLC tag" entries for multiplexed tags.
- Download the HMI and PLC programs. Open an online watch table on the PLC and force
DriveNumberto 0, 1, 2, … 31. Verify thatDB_Drive.DRV[i].Goal_Poswrites from the HMI land in the correct array element. - On the panel, open the diagnostics view (Diagnostics > Connections on Unified, System > Diagnostics on Comfort). Confirm that no multiplexed tag reports a connection error.
- Run a 24-hour soak test with an automated index sweep in OB35:
i := (i + 1) MOD 32;. Verify that no alarm is raised and that the E/A field always shows the value from the currently indexed drive. - For
BOOLtags, verify both directions: write from the panel, observe in the watch table; force from the watch table, observe the panel update. - For sliders, change the index through the full 0..31 range while the panel is in runtime. The slider must remain visible at all times.
Troubleshooting Matrix
| Symptom | First Check | Second Check | Resolution |
|---|---|---|---|
E/A field shows ???? permanently |
Is the HMI tag bound to a multiplexed list? | Is at least one row in the list a valid symbolic path? | Open the tag properties, add the missing PLC tags to the multiplexing list. |
| Field shows correct value but writes are dropped | Is the field set to Input/Output (not Output)? | Acquisition cycle > 1 s? | Set the field to Input/Output and reduce the acquisition cycle to 250 ms. |
| Writes land in the wrong array element | Is the index clamped in the PLC? | Does the index tag's acquisition cycle introduce latency? | Clamp DriveNumber in the PLC and reduce the index tag acquisition cycle. |
| Compile error: "symbol not found" | Is the DB marked as optimized access only but the panel uses absolute addressing? | Is the HMI connection set to use S7-1200/1500 symbolic? | Switch the HMI connection to symbolic addressing, or use a standard-access DB for the multiplexed elements. |
| Slider invisible after index change | Min/max range re-evaluated during invalid state? | Mirror DB refresh out of phase with index change? | Use Method 2 and refresh mirror inside the same OB cycle as the index change. |
| Bool toggle does not stick | Multiplexing + Toggle button? | Acquisition cycle too long? | Switch to mirror DB or use Switch-on / Switch-off buttons with longer acquisition cycle. |
Field-Engineering Notes
- Always keep the original
DB_Drivestructure intact. The mirror DB is a non-invasive add-on, which is critical when many running machines already use the original layout. - Document the multiplexing lists in the project documentation. Each row must be listed with the symbolic path, the data type, and the acquisition cycle.
- When migrating from a Comfort panel to a Unified panel, re-test the multiplexing behaviour: the acquisition cycle default is different (250 ms vs 100 ms), and some bug fixes (slider visibility) are panel-firmware-specific.
- For S7-1500, prefer symbolic addressing on the HMI connection. This is required for any multiplexed tag whose source is an optimized-access DB.
- Use the Siemens Industry Online Support entry "Multiplexing HMI Tags" as the canonical reference. Cross-check the panel firmware and TIA Portal version in the compatibility matrix before commissioning.
- For PC-based SCADA (WinCC Runtime Professional), multiplexing is supported in the same way as on Unified; the same caveats about range re-evaluation of sliders apply.
Can a TIA Portal HMI tag use a dynamic array index like DRV[DriveNumber]?
No. HMI tags are compiled to a fixed address table at build time; the panel firmware cannot evaluate expressions. Use HMI tag multiplexing (Method 1), a mirror DB (Method 2), or a VBScript (Method 3) to achieve the same effect at runtime.
Does HMI multiplexing work for both reading and writing values?
Yes. Multiplexed tags in WinCC Unified, Comfort, and Professional support bidirectional read and write. Writes from the panel are routed to the currently indexed PLC tag, exactly as a non-multiplexed tag would route them.
Why does my button not toggle a BOOL when bound to a multiplexed tag?
This is a known issue where rapid toggles are dropped because multiplexing writes the value back only on each acquisition cycle. Use the mirror DB approach with a Cmd_Apply handshake, increase the acquisition cycle, or switch the button from Toggle to Switch on/off.
Why does my slider disappear when the multiplexed process value changes index?
The slider's range is re-evaluated from the multiplexed source. If the new index is briefly invalid, the range collapses and the slider is rendered with zero height. Bind the slider to a non-multiplexed mirror tag and refresh the mirror in the same PLC cycle as the index change.
Do I need to modify the existing DB structure to add dynamic HMI binding?
No. The original DB_Drive can stay exactly as it is. Methods 1 and 2 only require adding HMI-side configuration (multiplexing list) or a new mirror DB. The installed base of running machines that depend on the original layout is unaffected.