WinCC Flexible 2008 Address Multiplexing: Reducing Power Tags

David Krause17 min read
HMI ProgrammingSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Statement: Power Tag License Exhaustion

WinCC Flexible 2008 (SP2, SP3, SP4) tags are metered against a license key. Each project has a Power Tag ceiling printed on the license certificate or visible under Project > Properties > Licensing. Power Tags are runtime variables bound to a PLC address; internal tags and constant tags are not counted.

A typical symptom is a project that compiles cleanly in the engineering station but aborts at runtime download with:

Scenario Application Power Tag Need License Available Shortfall
12 machines, 18 tags each (analog values, status, setpoints) WinCC Flexible 2008 SP2 RT on PC 218 128 90
24 heaters, 8 tags each (PV, SP, output, alarms) MP 277 10" touchscreen 192 128 64
40 conveyors, 5 tags each (run, fault, speed, current, hours) TP 177B 6" 200 128 72

The mismatch is fixed by reducing the counted Power Tag set without losing the data points visible to the operator. Siemens provides three built-in mechanisms:

  1. Address Multiplexing (sometimes called "indirect addressing" or, in older Siemens literature, "tag multiplexing")
  2. Array tags with index-based access
  3. Boolean packing into WORD / DWORD PLC words
Terminology note: The HMI community frequently uses "tag multiplexing" to mean the runtime ability of one tag to point at many addresses. Siemens officially calls this Address Multiplexing in both WinCC Flexible 2008 and the successor WinCC Unified V20. Both names refer to the same feature: a single tag definition whose address is calculated at runtime from an index tag.

2. Tag Multiplexing vs Address Multiplexing: What Siemens Actually Calls It

The phrase "tag multiplexing" is not a discrete configuration object in WinCC Flexible 2008. There is no property called Multiplexed on a tag in the editor. What exists is:

  • An address expression on a tag that contains a multiplexer index (an integer tag whose value is concatenated into the address at runtime).
  • The multiplexer index itself (a 16-bit unsigned internal or external tag that drives the address calculation).

Siemens Support Entry ID 21807421 (see "How does tag multiplexing work?" on the Siemens Industry Online Support portal) describes the feature as: "With tag multiplexing you can access multiple tags via one index tag. For example, for visualizing similar machines you configure just one picture." The document applies to WinCC Flexible 2005/2008, and the same behaviour continues in WinCC Unified V20 under the renamed section "Address Multiplexing (RT Unified)" (see TIA Portal V20 documentation: Address Multiplexing (RT Unified)).

Term Source Meaning
Tag Multiplexing Siemens FAQ 21807421, WinCC Flexible 2008 Legacy name. The ability of one configured tag to point at many PLC addresses via an index.
Address Multiplexing WinCC Unified V20, TIA Portal V20 docs Modern name. Identical feature with extended options (e.g., index tag can be an HMI tag or a PLC tag).
Indirect Addressing Generic HMI / PLC term Same concept. Avoid for Siemens projects because the HMI editor uses the word "Multiplexing" in the address dialog.
Symbolic Multiplexing Some third-party HMI vendors Different mechanism (DB slicing). Not available in WinCC Flexible.

3. Power Tag Licensing Fundamentals

WinCC Flexible counts a tag as a Power Tag if all of the following are true:

  • The tag's Acquisition mode is Cyclic continuous, Cyclic on use, or On change.
  • The tag is bound to a PLC address (external) and is in the active project scope.
  • The tag is enabled for use in screens, scripts, or logging.

Tags that do not count against the Power Tag license:

  • Internal tags (HMI-local memory).
  • Constants (literals shown on the screen).
  • Tags disabled in the project or filtered out by an area pointer selection.
  • Tags inside a screen that is not in the active screen tree on the target device.

The license check is performed at runtime start and at every project download. A typical error message displayed in the HMI loader is:

Error 130003:
"Maximum number of Power Tags exceeded.
The project requires 218 Power Tags,
but the license permits only 128."
License upgrade options: Siemens sells Power Tag upgrade packs (16, 32, 64, 128, 256) as floating licenses. The 128 Power Tag pack (article number 6AV6613-1XA01-1CE0, legacy) or its successors under the "WinCC flexible RT" range can be purchased and activated by re-licensing the runtime. The techniques below are the right answer when budget does not allow the upgrade, or when the same physical project must run on two device classes with different licenses.

4. Address Multiplexing Architecture

The multiplexer mechanism in WinCC Flexible 2008 works as a runtime address resolver. The configured tag carries an address expression with a placeholder; the placeholder is replaced by the value of the index tag on every read cycle.

4.1 Address expression syntax

The placeholder is the index tag name in angle brackets. For a tag whose value is read from DB100.DBW<IndexTag> (S7-300/400) or %DB100.DBW<IndexTag> (S7-1200/1500) the address dialog shows:

Address:      DB100.DBW<IndexTag>
Index Tag:    iMachineIndex    (INT, 0..11)
Acquisition:  Cyclic, 1 s

Runtime behaviour:
  If iMachineIndex = 0  -> reads DB100.DBW0
  If iMachineIndex = 1  -> reads DB100.DBW2
  If iMachineIndex = 2  -> reads DB100.DBW4
  ...
  If iMachineIndex = 11 -> reads DB100.DBW22

The PLC address offset is automatically scaled by the tag's data type. For a WORD (2 bytes) the index increments the address by 2; for a DWORD (4 bytes) by 4; for a BOOL by 1 bit (only meaningful with bit address syntax, see section 4.3).

4.2 Supported data types

HMI Tag Type PLC Address Step per Index Unit Typical Use
BOOL 1 bit (bit index within a byte) Status flags per machine
INT / WORD 2 bytes Analog values, setpoints, counters
REAL / DWORD 4 bytes Floating-point process values, timers
DINT 4 bytes 32-bit counters, encoders
STRING Length of string + 2 byte header Name plates, fault messages

4.3 Bit-level multiplexing

For BOOL tags the index drives a bit offset, not a byte offset. The address expression must use the bit syntax:

Address:      DB100.DBX<IndexTag>.0
Index Tag:    iBitIndex  (INT, 0..7)

This reads bit 0 of the byte formed by:
  iBitIndex=0 -> DB100.DBX0.0
  iBitIndex=1 -> DB100.DBX1.0
  iBitIndex=2 -> DB100.DBX2.0
  ...

For wider boolean fields pack eight machine-status bits into one byte and let the index select the bit, reducing the per-machine Power Tag count from 8 to 1.

4.4 Number of addresses addressable

The index tag is a 16-bit signed integer (range -32768..32767). The addressable address space is therefore 65536 units of the tag's type step. For WORD tags that is 128 KB of contiguous PLC memory, which is more than enough for typical multiplexing applications (12-40 machines).

5. Configuration Procedure in WinCC Flexible 2008 SP2/SP4

The following step-by-step configures a multiplexer that drives 12 identical machine pictures from a single set of screen objects, and demonstrates the Power Tag count reduction for a project that originally required 218 Power Tags.

5.1 Prerequisites

  • WinCC Flexible 2008 SP2 (or later SP) with the ES installed.
  • PLC project where process data is laid out in a contiguous data block, e.g. DB100 with a UDT UDT_Machine of 36 bytes per instance.
  • Index tag of type INT, written by either the PLC (e.g. MW 200) or an HMI internal tag driven by a screen selector button.

5.2 Step-by-step configuration

  1. Open the tag editor in WinCC Flexible. Right-click Tags > Analog / Binary and select New Tag.
  2. Define the index tag first, because other tags reference it. Name iMachineIndex, type INT, address MW 200 (PLC) or leave address blank for an internal tag.
  3. Create the multiplexed process tag. Name it e.g. rMachineTemp_PV, type REAL, address DB100.DBD<iMachineIndex>. The <iMachineIndex> placeholder appears in the address field as a token; the index tag is selected via a dropdown next to the address field.
  4. Set Acquisition mode to Cyclic continuous with a 1 s cycle. (Use On change only for slow-changing setpoints to reduce HMI-PLC traffic.)
  5. Repeat step 3 for every process value of the machine, using the same index tag. Each different data type requires its own tag, but every value type is multiplexed through the single index.
  6. Map the tag to a screen object (IO field, bar, etc.). The object references rMachineTemp_PV, not a per-machine tag.
  7. On the screen, place a machine selector: an IO field bound to iMachineIndex with limits 0..11, or 12 buttons that write 0..11 into the index tag via a "Set Value" event.
  8. Compile and download. Verify in the HMI loader that the Power Tag count reported during download is 1 (the process tag) plus the index tag, regardless of how many machine instances the screen can show.
Compile error trap: If the placeholder syntax is mistyped, WinCC Flexible shows Error 7001: Address syntax invalid. The placeholder must be the exact name of an existing tag, enclosed in angle brackets, with no extra whitespace.

6. Worked Example: Cutting 218 Power Tags to 38

Original machine panel architecture (per machine):

Tag Type Address Power Tags
Temperature PV REAL DB100.DBD0 1
Temperature SP REAL DB100.DBD4 1
Pressure PV REAL DB100.DBD8 1
Run command BOOL DB100.DBX12.0 1
Stop command BOOL DB100.DBX12.1 1
Fault status BOOL DB100.DBX12.2 1
Motor current INT DB100.DBW14 1
Operating hours DINT DB100.DBD16 1
Recipe number INT DB100.DBW20 1
Production count DINT DB100.DBD22 1
Operator name (string) STRING[16] DB100.DBB26 1
Material code STRING[8] DB100.DBB44 1
Per-machine subtotal 12
12 machines (218/12 ≈ 18 tags, plus panel-level tags) 216
Panel-level: alarm summary tag, user login, language index 2
Total original 218

After multiplexing, replace the 12 per-machine tags with 12 multiplexed tags (one per data point). Each multiplexed tag is still 1 Power Tag. Total goes from 12 × 12 = 144 + 2 = 146 down to 12 + 2 = 14 Power Tags for the data view, plus the multiplexed screen objects shared across machines. A more aggressive example combining multiplexed tags with a single combined status WORD per machine reduces further:

Configuration Power Tags vs 128 License
Original (one tag per data point per machine) 218 Over by 90
Address multiplexing on all 12 process values + index 15 Under by 113
Address multiplexing + 8 boolean status packed into 1 WORD per machine, multiplexed 9 Under by 119
Full multiplexing + Array tags for production count (1 tag, 12 elements) 8 Under by 120

7. Alternative: Array Tags with Index Access

Array tags are configured in WinCC Flexible 2008 SP2 and later under Tags > New Tag > Data type: Array. The HMI treats the array as a single Power Tag regardless of element count, because only the base address of the array is counted as a connection point; each element is then accessed by index at runtime.

Tag: arrMachineHours[0..11]
Type: Array of DINT
PLC address: DB200.DBD0   (PLC holds 12 consecutive DINTs, 48 bytes)

Usage in VB script:
  HMIruntime.Tags("arrMachineHours").Write i, value

Usage in screen:
  IO field connected to arrMachineHours with index tag iMachineIndex

Array tags are most efficient when many identical-type values are stored in the PLC as a contiguous block (e.g. shift counters, daily production totals, temperature log buffers).

Mechanism Power Tag Cost Best For
Address Multiplexing (one tag, index in address) 1 per data point per type Mixed-type per-instance data (PV, SP, status, string all in one UDT)
Array tag (one tag, index in tag name) 1 per array Same-type batches (12 counters, 24 setpoints)
Boolean packing into WORD 1 per 16 booleans Status flags, fault bits, mode selectors

8. Boolean Packing into WORD / DWORD

Where the HMI only needs to display or set individual boolean states (Run, Stop, Fault, Auto, Manual, etc.), bundling them into a single WORD or DWORD on the PLC side and reading it as one multiplexed tag reduces 16 or 32 individual Power Tags to one.

PLC DB100 layout (UDT_Bits, 2 bytes per machine):
  Bit 0:  bRun
  Bit 1:  bStop
  Bit 2:  bFault
  Bit 3:  bAutoSelected
  Bit 4:  bManualSelected
  Bit 5:  bRemoteSelected
  Bit 6:  bMaintMode
  Bit 7:  bEStopActive
  Bit 8:  bDoorClosed
  Bit 9:  bLubricationOK
  Bit 10: bHeaterOn
  Bit 11: bCoolingOn
  Bits 12-15: spare

HMI side:
  Tag wMachineBits, type WORD, address DB100.DBW<iMachineIndex>
  Power Tag cost: 1 (versus 12 individual BOOL tags)

To display bit 3 (Auto) of machine 5 on the HMI, use a script:

' VBScript in WinCC Flexible 2008
Dim wVal, bAuto
wVal = SmartTags("wMachineBits")(SmartTags("iMachineIndex"))
bAuto = (wVal And (2 ^ 3)) <> 0
SmartTags("bAutoDisplay") = bAuto

This is the most Power-Tag-efficient approach but loses the per-bit direct binding available in the IO field dialog. Use it when a script-driven bit view is acceptable.

9. Differences in WinCC Unified / TIA Portal V20

The successor platform, WinCC Unified as of TIA Portal V20, formalizes the feature as Address Multiplexing (RT Unified) with explicit configuration objects.

  • The address expression is now configured under the tag's Properties > Multiplexing tab rather than as inline angle brackets.
  • The index tag can be selected from a dropdown that lists all HMI tags (internal and external) and PLC tags exposed via the HMI connection.
  • Multiplexing can be combined with Quality of Service settings: an invalid index value (out of range) triggers a configurable fallback (last good value, default value, or quality code "bad-configuration").
  • WinCC Unified no longer has a hard Power Tag count cap on PC Runtime for most configurations; the licensing model shifted to "Tags" counted with a higher ceiling and many licenses ship with 4k-32k tags. Mobile panels and Comfort Panels retain a Power Tag-equivalent cap.

For new projects on TIA Portal V18-V20, prefer the explicit Address Multiplexing dialog. For legacy WinCC Flexible 2008 projects that are being migrated, the angle-bracket syntax is auto-converted by the TIA migration tool, with manual review required for any tag where the index tag name was renamed during migration.

10. Verification and Commissioning

After configuration, perform the following checks before handing the panel to operations.

  1. Power Tag counter: On the engineering station, run Project > Compiler > All > Consistency Check. The output should show "Power Tags used: N" where N matches the expected count from the design spreadsheet. The license error appears only on the runtime loader; this ES check gives a faster turnaround.
  2. Index boundary test: On the HMI, set the index tag to -1, 0, max-1, max, max+1. Each value should produce a valid HMI display (or a defined quality code) without crashing the runtime. Invalid indices typically result in Quality Code: Bad - Configuration rather than a hard fault.
  3. Cyclic stress: With the index tag driven by a PLC script that flips it 0..11 every 100 ms, observe in the HMI diagnostic page (if configured) that all values update and the cycle is smooth. Use Tools > HMI Diagnose on PC Runtime to see the tag cycle time.
  4. PLC-HMI consistency: Write a known value (e.g. 123.45) to a specific machine's PV in the PLC. Set the index tag to that machine's index. Verify the HMI shows 123.45. Repeat for each machine index.
  5. License check on target: After download, the loader reports the runtime Power Tag count. Confirm the number matches the design. The text of the loader dialog contains the exact "X Power Tags required, Y licensed" line.

11. Troubleshooting Matrix

Symptom Likely Cause Action
Address field shows red outline after typing placeholder Index tag name misspelled or not yet created Create the index tag first; refresh the address dialog dropdown
Runtime always reads the same value regardless of index Index tag is being overwritten by the PLC faster than the HMI can apply it, or HMI writes to a different index tag than the multiplexed tag references Verify the index tag address on both HMI and PLC; check the cycle time of the index update
Error 130003: Power Tags exceeded at runtime download A second image set or a script uses raw (non-multiplexed) tags Run the consistency check; search the project for tags whose name does not start with a multiplexed prefix
Quality code Bad-OutOfService on multiplexed BOOL Bit index out of range (e.g. index 8 for a 1-byte bit field) Constrain the index tag to 0..7; use a script to clamp on entry
Multiplexed string tag shows garbled characters Index step not aligned with the string header; STRING[16] occupies 18 bytes, not 16 Account for the 2-byte header in the address scaling or use a separate index with custom step
Multiplexed value is off by one machine PLC data block was created with one-based indexing, index tag is zero-based Add 1 in the script that drives the index, or remap the index origin in the HMI
TIA migration loses the angle-bracket placeholder Index tag was renamed in the new project Open each migrated tag, re-select the index tag from the new dropdown, save

12. Limits, Caveats, and Field-Notes

  • Multiplexing is runtime-only. The ES, the HMI loader, and the connection diagnostics all show only the base tag (one Power Tag), not the effective number of accessible PLC addresses. The actual data points available to the operator are still bound by the address space the index tag can address.
  • Multiplexing does not reduce HMI-PLC traffic. A multiplexed tag polled at 1 s still reads the current index's address every cycle. The PLC sees the same number of read requests as if 12 separate tags were configured, just sequential instead of parallel.
  • Alarm logging on a multiplexed tag produces alarms tagged with the value of the index at the time of the event. If the index changes between the trigger and the HMI's archive write, the alarm may be attributed to the wrong machine. For high-integrity alarming, use dedicated tags per machine for the alarm source.
  • Audit trails (WinCC Flexible 2008 SP3 "Audit" option) record the tag name, not the resolved address. If the audit log must show which machine a write was directed to, include the index tag in the audit entry manually via a script.
  • Multiplexing is not available on all connections. OPC DA, OPC UA Client, and some third-party PLC drivers do not support inline index expressions. The placeholder works on native S7 MPI/Profibus/Profinet and on Modbus TCP (with restrictions on the Modbus address range).
  • Index tag is single-threaded. If two screens on the HMI use multiplexed tags with different index tags, ensure the index tag is consistent. A common pattern is to drive one global index tag from a screen-stack mechanism so that switching screens does not leave stale indices.

13. Combining All Three Techniques

For a project that must fit a 128 Power Tag license but covers 18 machines with rich per-machine data, the typical maximum-compression design is:

Layer Technique Power Tags
Process values (temperature, pressure, setpoint, current, hours) Address Multiplexing on a UDT with REAL/INT/DINT fields 5
Status flags (run, stop, fault, auto, manual, etc.) Boolean packing into one WORD per machine, multiplexed 1
Production counters (per machine, per shift) Array tag of DINT, 18 elements 1
Index tag Internal INT, driven by screen selector 1
Panel-level: alarm summary, language, user Direct tags 3
Total 11

This is an order of magnitude under the 128 Power Tag license, leaving headroom for project growth or for additional tag requests from operations without a license upgrade.

14. Frequently Asked Questions

What is the difference between "tag multiplexing" and "address multiplexing" in WinCC?

They are the same feature. Siemens uses "tag multiplexing" in WinCC Flexible 2008 documentation (FAQ 21807421) and "address multiplexing" in WinCC Unified V20 documentation. The mechanism is identical: a configured tag whose address contains a placeholder for an index tag value, evaluated at runtime.

How many Power Tags does a multiplexed tag count as?

Exactly one Power Tag, regardless of how many PLC addresses it can reach. A multiplexed REAL tag pointing into a UDT of 12 machine instances counts as 1 Power Tag in the license check at runtime download.

What data types support address multiplexing in WinCC Flexible 2008?

BOOL, INT, WORD, DINT, DWORD, REAL, and STRING. The PLC address step per index unit is 1 bit for BOOL, 2 bytes for INT/WORD, 4 bytes for DINT/DWORD/REAL, and the full string length plus 2-byte header for STRING.

Can the index tag be an HMI internal tag instead of a PLC tag?

Yes. An internal INT tag works as the multiplexer index when the index is driven by HMI screen logic (selector buttons, screen stack, recipe selection). For values written by the PLC (current machine number, current operator), use an external tag bound to a PLC address.

Why does my migrated TIA Portal project lose the address multiplexing?

The TIA migration tool converts the angle-bracket placeholder, but only if the index tag still exists with the same name. If the index tag was renamed during cleanup, the placeholder becomes an unresolved reference and is replaced with the base address. Re-select the new index tag from the multiplexing dropdown in the migrated tag's properties.

Does address multiplexing work on OPC UA or Modbus connections?

On native S7 MPI/Profibus/Profinet it works fully. On Modbus TCP it works for register-based tags (INT, WORD, DINT, DWORD, REAL) but bit-level BOOL multiplexing is not supported on Modbus because of the addressing model. OPC DA and many third-party drivers do not support the inline index expression at all.

Back to blog