Troubleshooting S7-1200 PID Parameters Showing ##### on KTP600

David Krause17 min read
SiemensTIA PortalTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Troubleshooting S7-1200 PID Parameters Showing ##### on KTP600 HMI

A common field issue with S7-1200 CPU firmware V2.0 paired with KTP600 Basic panels programmed in TIA Portal V11 SP1 is the sudden appearance of ##### in PID tuning I/O fields after a routine download. The PLC tag itself remains valid in a Watch table, the HMI numeric keypad still opens, and entering a value produces no change in the watched variable. This article walks through the precise root causes, the exact tag structure used by the PID_Compact and PID_3Step V1 instructions, and a sequence of corrective actions that have resolved the issue in production systems.

Engineering note: A second, related symptom frequently reported in the same configuration is a blank or frozen time-of-day display. The KTP600 Basic does not contain a hardware real-time clock. The time variable must be sourced from the S7-1200 clock, not from the panel itself.

1. Problem Description

The reported symptoms appear immediately or intermittently after a download cycle in TIA Portal V11 SP1 with the following configuration:

  • SIMATIC S7-1200 CPU, firmware V2.0 (for example CPU 1214C DC/DC/DC, order number 6ES7214-1AE30-0XB0).
  • SIMATIC KTP600 Basic mono / Basic color PN (6AV6647-0AA11-3AX0 or 6AV6647-0AC11-3AX0).
  • TIA Portal V11 SP1 with WinCC Basic V11 SP1 (engineering software).
  • PID_Compact or PID_3Step (V1) instruction used in the user program.
  • I/O fields on the HMI linked to PID tuning tags such as PID_Loop.sRet.r_Gain, PID_Loop.sRet.r_Ti, PID_Loop.sRet.r_Td (some legacy or renamed projects use r_ctrl_Gain).

Field behavior after a second or subsequent download:

  • The PID I/O field shows ##### instead of the numeric value.
  • Other I/O fields on the same screen, even when bound to the same instance data block, continue to update correctly.
  • The PLC Watch table still shows the correct value being read from the instance DB.
  • The HMI numeric input keypad opens when the field is touched, but the keypad area also shows #####.
  • Entering a new value on the keypad and confirming it does not modify the value seen in the Watch table.
  • Time-of-day fields on the HMI also stop updating or remain blank.

This is a stale tag-reference problem combined with a KTP600 RTC absence, not a hardware failure. PLCs and panels that show the symptom almost always recover with the corrective procedure in Section 6.

2. Affected Hardware and Software

Component Catalog Number (example) Firmware / Version Notes
S7-1200 CPU 1214C DC/DC/DC 6ES7214-1AE30-0XB0 V2.0 Earliest widely deployed firmware for the 1214C; PID_Compact present.
S7-1200 CPU 1215C DC/DC/DC 6ES7215-1AG30-0XB0 V2.0 Same instruction set as 1214C V2.0.
S7-1200 CPU 1211C DC/DC/DC 6ES7211-1AD30-0XB0 V2.0 Smaller work memory; same PID behavior.
KTP600 Basic mono PN 6AV6647-0AA11-3AX0 Any HMI image No real-time clock. Time must come from PLC.
KTP600 Basic color PN 6AV6647-0AC11-3AX0 Any HMI image No real-time clock; 5.7" TFT.
TIA Portal 6AV2101-0AA01-0AA0 (V11) V11 SP1 + Update 5+ Earlier updates show more partial-compile defects.
Siemens documentation reference: The PID Parameters V1 reference in the TIA Portal Help (PID Control → S7-1200/S7-1500 → PID_3Step V1 → Advanced settings → PID parameters) defines the precise structure of the sRet tuning block referenced in this article. The same parameter layout applies to PID_Compact V1.

3. Root Cause Analysis

The ##### indicator on a WinCC I/O field is a generic "value present but not displayable" condition. TIA Portal V11 SP1 can leave a stale internal link between the HMI tag and the PLC tag in three documented ways; the PID tuning block is the most common victim because it is a deeply nested structure member.

3.1 Stale HMI Tag Reference After Partial Compilation

The most frequent cause is a partial compilation. TIA Portal V11 SP1 will re-use the HMI tag database from a previous build when a partial compile is performed on the PLC program. The PLC instance DB is regenerated with the same symbolic name, but its internal offsets can shift by a few bytes after a recompile, and the HMI tag continues to point at the old absolute address. The HMI requests the byte, receives a malformed REAL, and substitutes #####.

Indicators:

  • Symbolic reference still appears valid in HMI tags → PLC tags.
  • The tag was modified (a new element added, a variable renamed) since the last full build.
  • Watch table on the PLC side reads the same tag correctly.
  • Other tags that were not touched since the last full download continue to display.

3.2 Field Width Insufficient for the Value Range

The I/O field has a fixed display width set in the properties dialog. The PID_Compact V1 / PID_3Step V1 r_Gain, r_Ti, and r_Td parameters are IEEE 754 single-precision REALs, encoded in 32 bits. A gain of 1.5 displayed with the default 6 characters and two decimal places is rendered as 1.50; a gain of 25.0000 or a Ti of 3600.0 requires more characters. When the formatted value cannot fit in the field, WinCC Basic substitutes ##### even if the underlying variable is valid.

Indicator: the issue is deterministic with large or small tuning values but intermittent for small values.

3.3 Data Type Mismatch on the HMI Tag

If the HMI tag is created as INT or DINT while the PLC tag is REAL, the runtime conversion fails and the field shows #####. This typically occurs when the I/O field is recreated manually instead of being dragged from the PLC tag list, or when the project is migrated and the HMI tag data type is not updated.

3.4 KTP600 Basic Has No Real-Time Clock

The KTP600 Basic mono and color panels do not contain a battery-backed real-time clock. A time-of-day field showing ##### or a frozen value is normal on power-up; the value never refreshes because the HMI has no time source. The HMI must be bound to a PLC date/time tag (for example a buffer filled with RD_SYS_T) and not to the HMI system time.

4. PID Parameter Data Structure

The PID_Compact and PID_3Step instructions expose their tuning parameters in a structured tag inside the instance DB. The exact path depends on the instruction version. For V1 blocks shipping with S7-1200 firmware V2.0 and TIA Portal V11, the structure is:

Tag path (instance DB) Data type Engineering unit Default Display format
PID_Loop.sRet.r_Gain REAL (32-bit IEEE 754) Dimensionless 1.0 ########.##
PID_Loop.sRet.r_Ti REAL (32-bit IEEE 754) Seconds 4000.0 ########.#
PID_Loop.sRet.r_Td REAL (32-bit IEEE 754) Seconds 0.0 ########.#
PID_Loop.sRet.b_Retentive BOOL — FALSE Toggle button
PID_Loop.sRet.r_Ctrl_Gain (legacy / renamed) REAL Dimensionless 1.0 ########.##

The sRet (Setpoint / Retain) structure is the "output of the tuning wizard" block; values written here are picked up the next time the controller transitions from Manual to Automatic. Writing a value to r_Gain while the controller is in Automatic is permitted, but the value is masked by the controller's internal copy until the next transition unless the "Accept new tuning values immediately" project option is selected in the PID_Compact configuration.

Field width sizing for an I/O field bound to a REAL tag:

  • Sign character (1 if negative values are possible).
  • Integer digits (count based on max expected value, typically 4-5 for gain, 5 for Ti in seconds).
  • Decimal point (1).
  • Decimal digits (usually 1 to 3).
  • Recommended safety margin: 2 characters.

Example: a Ti field expected to display values up to 9999.9 seconds with 1 decimal place needs 1 (sign buffer) + 4 (integer) + 1 (point) + 1 (decimal) + 2 (margin) = 9 characters of width. Configuring a 6-character field guarantees ##### once the value exceeds 999.999.

5. Step-by-Step Diagnostic Procedure

Run the following checks in order. Each step produces an unambiguous yes/no answer that points at one of the four root causes above.

  1. Open the project in TIA Portal V11 SP1. Right-click the project tree and select Compile → Software (rebuild all). Watch the output window for warnings about address or symbol conflicts.
  2. In the S7-1200 project, open the PID instance DB. Right-click the relevant tag (for example r_Gain) and select Monitor/Modify. Verify the value is numeric and within the expected range.
  3. In the HMI project, open HMI tags. Locate the HMI tag bound to PID_Loop.sRet.r_Gain. Confirm:
    • PLC tag path points to <PLC name>::PID_Loop.sRet.r_Gain.
    • Data type is Real (32-bit float).
    • Acquisition mode is Cyclic in operation with a 1 s cycle (default 1 s).
  4. Right-click the I/O field on the screen and select Properties → Layout. Read the value in the Width field (in characters). Compare to the calculated width from Section 4.
  5. Hold the right mouse button over the tag name in the I/O field's Process tab. The tooltip should show the same sRet.r_Gain path as in the DB; if it shows a numeric address (for example DB123.DBX4.0) the tag was relinked manually and may point at the wrong offset.
  6. Select the HMI device in the project tree, right-click and choose Compile → Software (rebuild all). Repeat for the PLC station.
  7. Compare the project date of the running HMI image (panel menu Settings → OP) with the timestamp of the last full download. Mismatched timestamps indicate the HMI did not pick up the recompiled configuration.
PID Field ##### Diagnostic Decision Flow PID I/O field shows ##### PLC Watch table reads the tag OK? No Check HMI/PLC PROFINET link Yes Other tags work? No Rebuild + redownload PLC then HMI Yes

6. Step-by-Step Resolution

Apply the following actions in the order given. Stop after the field returns to normal and document which step fixed it.

Required Compile and Download Sequence 1. PLC SW Rebuild all 2. HMI SW Rebuild all 3. PLC Download Software (all) 4. HMI Download Software (all) Never reverse the order. Power-cycle both devices after the downloads. Reverse order = stale HMI tag address table = ##### on PID fields.
  1. Rebuild the project in the correct order. From the project tree: PLC station → Compile → Software (rebuild all). Wait for completion. Then: HMI station → Compile → Software (rebuild all). A partial compile is the single most common cause of the PID field going to #####.
  2. Download PLC first, then HMI. Right-click the PLC device → Download to device → Software (all). Confirm with the CPU. Then right-click the HMI → Download to device → Software (all). This sequence is mandatory; downloading the HMI configuration against an older PLC program produces tag mismatches that show as #####.
  3. Power-cycle both devices. After the download, cycle power on the HMI and the PLC. Some KTP600 images retain the previous tag table in non-volatile memory until a cold start.
  4. Increase the I/O field width. Open the screen with the I/O field, select it, and in Properties → Layout set the width to at least the value calculated in Section 4. The default 6-character width is too small for typical Ti values.
  5. Re-link the tag from the PLC database. Delete the HMI tag and the I/O field. Drag the tag sRet.r_Gain from the PLC project tree directly onto the I/O field. TIA Portal regenerates the HMI tag with the correct data type and absolute address.
  6. Verify the data type. Open the HMI tag properties. Confirm the data type is Real (32-bit float). If it shows Int or DInt, change it to Real and redownload.
  7. Check decimal places. In the I/O field's Properties → Display tab, set the Number of decimal places to a value that fits inside the field width. A field with width 7 and 2 decimal places cannot display a value with 3 decimal places.
  8. Fix the time field separately. If the time-of-day field also shows #####, the KTP600 Basic lacks a real-time clock. Bind the HMI time field to a PLC date/time tag and not to the HMI system time:
    • Create an HMI tag of type DateTime named PLC_DateTime.
    • Link it to the PLC tag %DB1.DBD0 (an 8-byte DATE_AND_TIME buffer) or to the S7-1200 system clock byte ReadClock.
    • Use the S7-1200 RD_SYS_T instruction in the user program to load the system time into the buffer the HMI polls.
    • Schedule RD_SYS_T in a cyclic OB1 segment with a 1 s cycle so the time field refreshes visibly.
  9. Update firmware only as a last resort. S7-1200 firmware V2.0 has known issues with HMI partial compile interactions. Firmware V2.2 or higher resolves several HMI tag synchronization defects. Update PLC firmware to V4.x (or the highest released V4 version) and the HMI image to the matching WinCC Basic image, then rebuild the project from scratch.
Safety notice: Before updating PLC firmware, archive the user program and the HMI configuration. A firmware update clears the CPU's work memory and reload is mandatory. PID tuning constants stored in the sRet instance DB are rebuilt by TIA Portal and must be re-entered after the firmware update unless the values are sourced from a retentative data block.

7. Verification Procedure

After each corrective action, verify the field returns to normal with the following checks:

  1. On the HMI, the PID gain, Ti, and Td fields show numeric values, not #####.
  2. Touching the field opens a numeric keypad that pre-fills with the current PLC value.
  3. Entering 2.0 for the gain and confirming causes the value in the PLC Watch table PID_Loop.sRet.r_Gain to update to 2.0 within the configured acquisition cycle (default 1 s).
  4. The controller responds to the new gain; if the loop is in Automatic, the process variable changes accordingly within a few cycles.
  5. The time-of-day field updates when the PLC clock changes (verify by changing the PLC clock with Online & Diagnostics → Set time).
  6. Reboot both PLC and HMI. The PID field must continue to display the value through the power cycle if Retentive = TRUE in the PID_Compact configuration.
  7. Perform a second download of the same project. The field must remain valid. This step catches partial-compile issues that the first download masked.

8. Firmware Update Considerations

S7-1200 CPUs in the V2.0 firmware era (specifically 6ES721x-1xx30-0XB0 series) shipped with TIA Portal V11. Several PID display defects are documented against this combination. Two specific defects are relevant to the ##### symptom:

  • Partial compilation of the PID instance DB does not always update the HMI tag address table on the KTP600. The result is a symbolic HMI tag that still resolves to the previous absolute address. Fixed in S7-1200 firmware V2.2 and later, and substantially hardened in the V4.x line.
  • WinCC Basic V11 SP1 HMI images can hold a tag table from a previous project, producing ##### on tags that are still valid on the PLC. Fixed in WinCC Basic V11 SP1 Update 7 and later; later WinCC Basic images shipping with TIA Portal V13 SP1 onward are not affected.

Recommended firmware baseline for new deployments:

Component Minimum recommended firmware Notes
S7-1200 CPU V4.4 (latest V4) PID_Compact V2 adds tuning features; V1 remains compatible.
KTP600 Basic mono / color PN WinCC Basic image matching TIA Portal V13 SP1 or V15.1 Same KTP600 hardware, newer image fixes tag re-sync issues.
TIA Portal engineering software V13 SP1 or later for the V2 PID instruction V11 SP1 remains supported for legacy projects only.
Migration note: Moving an existing V1 PID project to TIA Portal V13 or later preserves the sRet structure but adds sPid_Core and sPid_Compact substructures. Re-binding the HMI tag is required after the migration because the symbolic path changes from DB.sRet.r_Gain to DB.sPid_Core.sPid_Compact.sRet.r_Gain.

9. Preventive Measures and Best Practices

For systems that have been working, the following practices prevent the ##### symptom from reappearing:

  • Always perform Compile → Software (rebuild all) on the PLC first, then the HMI. Never rely on incremental compilation after a PID block modification.
  • Bind HMI I/O fields by dragging the tag from the PLC project tree. Manually typed tag paths are the leading cause of address drift when the instance DB is regenerated.
  • Size I/O fields to a width that fits the maximum expected value with at least 2 characters of headroom. For REAL tags, a 10-character width is safe for almost all PID tuning values and prevents the field-width class of ##### failures entirely.
  • Document the S7-1200 firmware version in the project header. Track TIA Portal updates separately. Maintain a one-to-one pairing in the project notes to make cross-version debugging tractable when a unit is replaced in the field.
  • For time-of-day displays, always use a PLC tag and a scheduled RD_SYS_T job in the user program. Never rely on the HMI's system time on KTP600 Basic panels.
  • After every download, perform a verification cycle as described in Section 7. The 1-minute cost of a verification cycle prevents hours of troubleshooting later, especially after PID block edits.
  • Back up the project with Project → Archive before any firmware update. Restoring from an archive is faster than re-deriving the PID configuration from a corrupted project.
  • Lock the panel's operating mode to "Online" on the HMI and disable the "Change operating mode" privilege for operators. Operator mode changes can clear the HMI tag table and reproduce the ##### symptom in the field.

10. Quick Reference: ##### Symptom Decision Matrix

Symptom Likely cause First action
All PID fields show #####, other tags work Partial compile of PID instance DB Rebuild PLC software first, then HMI; redownload in that order.
Single PID field shows #####, others work Field width too small Increase I/O field width in Properties → Layout to 10 characters.
PID field shows ##### after manual tag re-typing Data type mismatch (Int vs Real) Delete HMI tag, drag from PLC tree.
Time field shows #####, PID fields work KTP600 Basic has no RTC Bind time field to PLC DATE_AND_TIME tag, not HMI system time.
PID field shows ##### only after second download Stale HMI image tag table Power-cycle HMI; update HMI image; rebuild project.
All HMI fields show ##### HMI ↔ PLC connection lost Check PROFINET cable, IP address, PLC accessibility.
PID field value changes on PLC but HMI shows ##### Absolute address drift after recompile Delete the HMI tag, recreate by drag-and-drop from the PLC tree.

11. FAQ

Why does my S7-1200 PID gain field show ##### on the KTP600 while the Watch table reads the correct value?

The PLC value is correct; the HMI cannot display it. The leading cause is a stale absolute address in the HMI tag table caused by a partial compilation of the PID instance DB. Rebuild the PLC software first, then the HMI, and download in that order. If the field width is smaller than the formatted value, increase it under I/O field Properties → Layout to 10 characters.

Can the KTP600 Basic hold a real-time clock and display the time on its own?

No. The KTP600 Basic mono and color panels (6AV6647-0AA11-3AX0 and 6AV6647-0AC11-3AX0) have no battery-backed real-time clock. A time-of-day field must be bound to a PLC date/time tag. Use the S7-1200 RD_SYS_T instruction in a cyclic OB segment to load the PLC system clock into a DATE_AND_TIME buffer the HMI can poll on a 1 s acquisition cycle.

Does updating the S7-1200 firmware from V2.0 fix the ##### issue?

Usually yes. Firmware V2.0 has documented defects in the partial-compile interaction with WinCC Basic V11 SP1 that produce stale absolute addresses in the HMI tag table. Updating to V2.2 or V4.x and a matching WinCC Basic image resolves the most common causes. Always archive the project and document PID tuning values before a firmware update because the instance DB is rebuilt.

What is the minimum field width for an I/O field bound to a REAL PID parameter?

For PID_Compact V1 / PID_3Step V1, the gain can be displayed in 8 characters with two decimal places. The integral time Ti in seconds can reach 9999.9 and needs 9 characters with one decimal place. A 10-character width covers all realistic PID tuning values for an S7-1200 application with a 2-character safety margin and avoids the field-width class of ##### failures.

Why does the second download sometimes fix the issue and sometimes break it again?

The outcome depends on whether the incremental compile touches the PID instance DB. If the PID block is unchanged, the HMI tag table remains consistent and the field works. If the PID block is recompiled (for example, because a comment was added or a tag renamed), the absolute address may shift and the HMI tag points at the wrong offset, producing #####. A full rebuild of PLC and HMI in sequence, then a full download in sequence, is the only reliable procedure to keep the absolute address table in sync with the symbolic HMI tag references.

Is the symbolic tag path sRet.r_Gain valid in PID_Compact V1 and V2?

PID_Compact V1 (S7-1200 firmware V2.0 through V4.x with TIA Portal V11 SP1 through V13) exposes the path as DB_instance.sRet.r_Gain. PID_Compact V2 (TIA Portal V13 SP1 and later, S7-1200 firmware V4.x) nests the same parameters one level deeper: DB_instance.sPid_Core.sPid_Compact.sRet.r_Gain. When migrating a V1 project, recreate the HMI tag binding by drag-and-drop so TIA Portal resolves the new symbolic path automatically.

Back to blog