The S7-200 CPU 224 and its memory
The CPU 224 of the PLC-200 trainer, its memory areas (I, Q, M, V, SM, T, C, S, AC, HC), addressing bits, bytes, words and double words, data types, and the trainer's modules and enable switches.
30 min
On this page
Every instruction of an S7-200 program reads or writes an address. Knowing the memory areas is knowing the vocabulary of the language.
The CPU 224 of the PLC-200
The trainer is built around a SIMATIC S7-200 CPU 224 DC/DC/DC: 24 V DC supply, 24 V DC inputs, 24 V DC transistor outputs.
| Resource | CPU 224 |
|---|---|
| Digital inputs / outputs | 14 (I0.0–I0.7, I1.0–I1.5) / 10 (Q0.0–Q0.7, Q1.0–Q1.1) |
| High-speed counters | 6 (HC0–HC5), up to 30 kHz |
| Pulse outputs (PTO/PWM) | 2, on Q0.0 and Q0.1 only |
| Analogue adjustment potentiometers | 2, read in SMB28 and SMB29 (0–255) |
| Timers / counters | 256 (T0–T255) / 256 (C0–C255) |
| Data memory V | 8 KB (VB0–VB8191) |
| Communication | port 0, PPI (Micro/WIN), 9.6 kbps by default |
Memory areas
| Area | Meaning | Examples | Access |
|---|---|---|---|
| I | process-image inputs, read at the start of the scan | I0.0, IB0, IW0 | read |
| Q | process-image outputs, written at the end of the scan | Q0.0, QB0 | read/write |
| M | internal bits (markers): your own flags | M0.0, MB1, MW2 | read/write |
| V | variable memory: data, counts, tables | V20.3, VB10, VW100, VD200 | read/write |
| SM | special memory: system bits and CPU registers | SM0.0, SM0.1, SMB28, SMB67 | mostly read |
| T | timers: a bit (done) and a word (current value) | T37 | read, R |
| C | counters: a bit and a current value | C0 | read, R |
| S | sequence control relays: the GRAFCET steps | S0.0 … S31.7 | LSCR/SCRT, S/R |
| AC | accumulators, fast scratch registers | AC0–AC3 | read/write |
| HC | high-speed counter values | HC0 | read |
The system bits you will use most:
| Bit | Symbol in Micro/WIN | Meaning |
|---|---|---|
| SM0.0 | Always_On | always 1 |
| SM0.1 | First_Scan_On | 1 during the first scan only: initialise, set the initial GRAFCET step |
| SM0.5 | Clock_1s | 0.5 s on, 0.5 s off |
| SM0.4 | Clock_60s | 30 s on, 30 s off |
| SMB28, SMB29 | – | the two potentiometers under the front cover, 0–255 |
Bits, bytes, words and double words
An address names a bit (V20.3: byte 20, bit 3), a byte VB20 (8 bits), a word VW20 (16 bits: VB20 and VB21), or a double word VD20 (32 bits: VB20 to VB23). The S7-200 is big-endian: in VW20, VB20 is the high byte.
The same four bytes read four ways. VW0 is VB0 (high byte) followed by VB1 (low byte): the S7-200 stores numbers big-endian. VW1 would overlap VW0 and VW2, so use even addresses for words and multiples of 4 for double words. A REAL uses the same 32 bits as VD0 in IEEE 754 format.
Data types follow the size: BYTE (0–255), INT (16-bit signed, −32768 to +32767), DINT (32-bit signed), REAL (32-bit IEEE 754 floating point). Constants are written +50, -2000, 16#DB (hexadecimal), 2#1010 (binary), 3.14 (real).
Predict first
A word constant must hold 50 000 (a PTO cycle time in µs). Why does the booklet ask you to write it 16#C350?
Timers, counters and their numbers
A timer's number fixes its type and its resolution, so choosing a timer is choosing an address:
| Timer numbers | Type | Resolution | Maximum |
|---|---|---|---|
| T32, T96 | TON/TOF | 1 ms | 32.767 s |
| T33–T36, T97–T100 | TON/TOF | 10 ms | 327.67 s |
| T37–T63, T101–T255 | TON/TOF | 100 ms | 3276.7 s |
| T0, T64 | TONR | 1 ms | 32.767 s |
| T1–T4, T65–T68 | TONR | 10 ms | 327.67 s |
| T5–T31, T69–T95 | TONR | 100 ms | 3276.7 s |
The lesson on timers uses this table in practice.
The trainer around the CPU
The PLC-200 wires modules to the CPU: input switches (three positions: ON, OFF, momentary ON), output relays RQ0.0–RQ1.1 enabled by SW5/SW6/SW7, a stepper motor (SW2) with its encoder, a DC motor with a proximity sensor and a micro-switch, traffic lights (SW3), a tank device (SW4), a 7-segment display (SW8), a thumbwheel, a keypad and a buzzer.
Several modules are hard-wired to the same PLC points: a module you do not use must be switched OFF with its enable switch, and the thumbwheel must stay at 0000 (it has no enable switch and feeds back into I1.2–I1.5). Every TP page lists the switches to set.
FoundationStart here if this is new to you
Think of the memory as a hotel. The area letter is the floor (I, Q, M, V…), the byte number is the room, the bit number is the bed in the room. A word is two neighbouring rooms booked together, a double word four. Two bookings that share a room will fight over the beds.