GE Multilin SR345 Transformer Protection System Communications Guide for revision 1.30.
SR345 Transformer Protection System, EnerVista, EnerVista Launchpad, and EnerVista SR3
Setup, are registered trademarks of GE Multilin Inc.
The contents of this manual are the property of GE Multilin Inc. This documentation is
furnished on license and may not be reproduced in whole or in part without the permission
of GE Multilin. The content of this manual is for informational use only and is subject to
change without notice.
Data Frame Format and Data Rate........................................................................................................ 2
Data Packet Format ....................................................................................................................................... 3
DNP serial EnerVista Setup........................................................................................................................13
DNP general .....................................................................................................................................................15
IEC 60870-5-103 serial communication............................................................................................. 16
Link layer ........................................................................................................................................................... 17
Type identification.........................................................................................................................................21
Function type...................................................................................................................................................22
Information number.....................................................................................................................................22
Data management ....................................................................................................................................... 22
Digital states ....................................................................................................................................................23
103 general settings ....................................................................................................................................25
DNP port allocation.......................................................................................................................................41
DNP general .....................................................................................................................................................49
GOOSE Rx status ............................................................................................................................................66
Data Frame Format and Data Rate......................................................................................................72
Data Packet Format......................................................................................................................................72
Format Codes ...............................................................................................................................................128
Function Code 03H.....................................................................................................................................171
Function Code 04H.....................................................................................................................................171
Function Code 05H.....................................................................................................................................172
Function Code 06H.....................................................................................................................................173
Function Code 07H.....................................................................................................................................173
Function Code 08H.....................................................................................................................................174
Function Code 10H.....................................................................................................................................175
Force coil commands................................................................................................................................176
Performing Commands Using Function Code 10H.....................................................................177
Using the MODBUS User Map............................................................................... 179
MODBUS User Map.....................................................................................................................................179
TOC
toc–2345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 5
Digital Energy
Multilin
345 Transformer Protection System
Communications Guide
Communications Guide
Communications interfaces
The 345 has three communications interfaces. These can be used simultaneously:
•RS485
•USB
•Ethernet
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–1
Page 6
RS485 INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
NOTE
NOTE
RS485 interface
The hardware or electrical interface in the 345 is two-wire RS485. In a two-wire link, data is
transmitted and received over the same two wires. Although RS485 two wire
communication is bi-directional, the data is never transmitted and received at the same
time. This means that the data flow is half duplex.
NOTE:
Electrical Interface
NOTE:
Polarity is important in RS485 communications. The '+' (positive) terminals of every device
must be connected together.
The hardware or electrical interface in the 345 is two-wire RS485. In a two-wire link, data is
transmitted and received over the same two wires. Although RS485 two wire
communication is bi-directional, the data is never transmitted and received at the same
time. This means that the data flow is half duplex.
RS485 lines should be connected in a daisy chain configuration with terminating networks
installed at each end of the link (i.e. at the master end and at the slave farthest from the
master). The terminating network should consist of a 120 W resistor in series with a 1 nF
ceramic capacitor when used with Belden 9841 RS485 wire. Shielded wire should always
be used to minimize noise. The shield should be connected to all of the 345s as well as the
master, then grounded at one location only. This keeps the ground potential at the same
level for all of the devices on the serial link.
Polarity is important in RS485 communications. The '+' (positive) terminals of every device
must be connected together.
MODBUS Protocol
Data Frame Format
and Data Rate
The 345 implements a subset of the Modicon Modbus RTU serial communication standard.
The Modbus protocol is hardware-independent. That is, the physical layer can be any of a
variety of standard hardware configurations. This includes USB, RS485, fibre optics, etc.
Modbus is a single master / multiple slave type of protocol suitable for a multi-drop
configuration.
The 345 is always a Modbus slave. It can not be programmed as a Modbus master.
Computers or PLCs are commonly programmed as masters.
Both monitoring and control are possible using read and write register commands. Other
commands are supported to provide additional functions.
The Modbus protocol has the following characteristics.
One data frame of an asynchronous transmission to or from a 345 typically consists of 1
start bit, 8 data bits, and 1 stop bit . This produces a 10 bit data frame. This is important for
transmission through modems at high bit rates.
Modbus protocol can be implemented at any standard communication speed. The 345
supports operation at 9600, 19200, 38400, 57600, and 115200 baud.
1–2345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 7
CHAPTER 1: COMMUNICATIONS GUIDERS485 INTERFACE
Data Packet FormatA complete request/response sequence consists of the following bytes (transmitted as
separate data frames):
Master Request Transmission:
SLAVE ADDRESS: 1 byte
FUNCTION CODE: 1 byte
DATA: variable number of bytes depending on FUNCTION CODE
CRC: 2 bytes
Slave Response Transmission:
SLAVE ADDRESS: 1 byte
FUNCTION CODE: 1 byte
DATA: variable number of bytes depending on FUNCTION CODE
CRC: 2 bytes
SLAVE ADDRESS: This is the first byte of every transmission. This byte represents the userassigned address of the slave device that is to receive the message sent by the master.
Each slave device must be assigned a unique address and only the addressed slave will
respond to a transmission that starts with its address. In a master request transmission the
SLAVE ADDRESS represents the address of the slave to which the request is being sent. In a
slave response transmission the SLAVE ADDRESS represents the address of the slave that is
sending the response.
FUNCTION CODE: This is the second byte of every transmission. Modbus defines function
codes of 1 to 127.
DATA: This will be a variable number of bytes depending on the FUNCTION CODE. This may
be Actual Values, Setpoints, or addresses sent by the master to the slave or by the slave to
the master.
CRC: This is a two byte error checking code.
Error CheckingThe RTU version of Modbus includes a two byte CRC-16 (16 bit cyclic redundancy check)
with every transmission. The CRC-16 algorithm essentially treats the entire data stream
(data bits only; start, stop and parity ignored) as one continuous binary number. This
number is first shifted left 16 bits and then divided by a characteristic polynomial
(11000000000000101B). The 16 bit remainder of the division is appended to the end of the
transmission, MSByte first. The resulting message including CRC, when divided by the
same polynomial at the receiver will give a zero remainder if no transmission errors have
occurred.
If a 345 Modbus slave device receives a transmission in which an error is indicated by the
CRC-16 calculation, the slave device will not respond to the transmission. A CRC-16 error
indicates than one or more bytes of the transmission were received incorrectly and thus
the entire transmission should be ignored in order to avoid the 345 performing any
incorrect operation.
The CRC-16 calculation is an industry standard method used for error detection. An
algorithm is included here to assist programmers in situations where no standard CRC-16
calculation routines are available.
CRC-16 AlgorithmOnce the following algorithm is complete, the working register “A” will contain the CRC
value to be transmitted. Note that this algorithm requires the characteristic polynomial to
be reverse bit ordered. The MSBit of the characteristic polynomial is dropped since it does
not affect the value of the remainder. The following symbols are used in the algorithm:
—>: data transfer
A: 16 bit working register
AL: low order byte of A
AH: high order byte of A
CRC: 16 bit CRC-16 value
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–3
Page 8
RS485 INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
i, j: loop counters
(+): logical exclusive or operator
Di: i-th data byte (i = 0 to N-1)
G: 16 bit characteristic polynomial = 1010000000000001 with MSbit dropped and bit order
reversed
shr(x): shift right (the LSbit of the low order byte of x shifts into a carry flag, a '0' is shifted
into the MSbit of the high order byte of x, all other bits shift right one location
The algorithm is:
1. FFFF hex —> A
2. 0 —> i
3. 0 —> j
4. Di (+) AL —> AL
5. j+1 —> j
6. shr(A)
7. is there a carry? No: go to 8. Yes: G (+) A —> A
TimingData packet synchronization is maintained by timing constraints. The receiving device
345 supported
functions
8. is j = 8? No: go to 5. Yes: go to 9.
9. i+1 —> i
10. is i = N? No: go to 3. Yes: go to 11.
11. A —> CRC
must measure the time between the reception of characters. If 3.5 character times elapse
without a new character or completion of the packet, then the communication link must
be reset (i.e. all slaves start listening for a new transmission from the master). Thus at 9600
baud a delay of greater than 3.5 x 1 / 9600 x 10 x = x 3.65 x ms will cause the
communication link to be reset.
The following functions are supported by the 345:
•FUNCTION CODE 03 - Read Setpoints
•FUNCTION CODE 04 - Read Actual Values
•FUNCTION CODE 05 - Execute Operation
•FUNCTION CODE 06 - Store Single Setpoint
•FUNCTION CODE 07 - Read Device Status
•FUNCTION CODE 08 - Loopback Test
•FUNCTION CODE 10 - Store Multiple Setpoints
Refer to section 5 of this guide for more details on MODBUS function codes.
1–4345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 9
CHAPTER 1: COMMUNICATIONS GUIDERS485 INTERFACE
S1 DNP GENERAL
DNP ADDRESS
DNP TCP/UDP PORT
CHANNEL 1 PORT
CHANNEL 2 PORT
TME SYNC IIN PER.
DNP MSG FRAG SIZE
DNP TCP CONN. T/O
▼
S1 DNP
DNP GENERAL
DNP UNSOL RESPONSE*
DEFAULT VARIATION
DNP CLIENT ADDRESS*
DNP POINTS LIST
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–5
Page 10
RS485 INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
DNP device profile
DNP 3.0 Device Profile
(Also see the IMPLEMENTATION TABLE in the following section)
Vendor Name: General Electric Multilin
Device Name: SR345 Relay
Highest DNP Level Supported:
For Requests: Level 2
For Responses: Level 2
Device Function:
□ Master
⊠ Slave
Notable objects, functions, and/or qualifiers supported in addition to the Highest DNP Levels
Supported (the complete list is described in the attached table):
Binary Inputs (Object 1)
Binary Input Changes (Object 2)
Binary Outputs (Object 10)
Control Relay Output Block (Object 12)
Binary Counters (Object 20)
Frozen Counters (Object 21)
Counter Change Event (Object 22)
Frozen Counter Event (Object 23)
Analog Inputs (Object 30)
Analog Input Changes (Object 32)
Analog Deadbands (Object 34)
Time and Date (Object 50)
Internal Indications (Object 80)
Maximum Data Link Frame Size (octets):Maximum Application Fragment Size (octets):
Transmitted: 292Transmitted: configurable up to 2048
Received: 292Received: 2048
Maximum Data Link Re-tries:Maximum Application Layer Re-tries:
⊠None⊠ None
□Fixed at 3□ Configurable
□Configurable
Requires Data Link Layer Confirmation:
⊠ Never
□ Always
□ Sometimes
□ Configurable
Requires Application Layer Confirmation:
□ Never
□ Always
1–6345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 11
CHAPTER 1: COMMUNICATIONS GUIDERS485 INTERFACE
DNP 3.0 Device Profile
⊠ When reporting Event Data
⊠ When sending multi-fragment responses
□ Sometimes
□ Configurable
Timeouts while waiting for:
Data Link Confirm:⊠ None □ Fixed □ Variable □ Configurable
Complete Appl. Fragment:⊠ None □ Fixed □ Variable □ Configurable
Application Confirm:□ None ⊠ Fixed at 10 s □ Variable □ Configurable
Complete Appl. Response: ⊠ None □ Fixed at ___ □ Variable □ Configurable
Others:
Transmission Delay: No intentional delay
Need Time Interval: Configurable (default = 24 hrs.)
Select/Operate Arm Timeout: 10 s
Binary input change scanning period: 8 times per power system cycle
Analog input change scanning period: 500 ms
Counter change scanning period: 500 ms
Frozen counter event scanning period: 500 ms
Sends/Executes Control Operations:
WRITE Binary Outputs⊠ Never □ Always □ Sometimes □Configurable
SELECT/OPERATE□ Never ⊠ Always
□ Sometimes □ Configurable
DIRECT OPERATE□ Never ⊠Always □ Sometimes □ Configurable
DIRECT OPERATE – NO ACK□ Never ⊠ Always □ Sometimes □ Configurable
Count > 1⊠ Never □ Always □ Sometimes □ Configurable
Pulse On□ Never □ Always ⊠ Sometimes □ Configurable
Pulse Off□ Never □ Always ⊠ Sometimes □ Configurable
Latch On□ Never □ Always ⊠ Sometimes □ Configurable
Latch Off□ Never □ Always ⊠ Sometimes □ Configurable
Queue⊠ Never □ Always □ Sometimes □ Configurable
Clear Queue⊠ Never
□ Always □ Sometimes □ Configurable
Explanation of ‘Sometimes’: Object 12 points are mapped to Virtual Inputs. Both “Pulse On” and
“Latch On” operations perform the same function in the 345; that is, the appropriate Virtual Input is
put into the “On” state. The On/Off times and Count value are ignored. “Pulse Off” and “Latch Off”
operations put the appropriate Virtual Input into the “Off” state.
Reports Binary Input Change Events when no
specific variation requested:
Reports time-tagged Binary Input Change
Events when no specific variation
requested:
□ Never□ Never
⊠ Only time-tagged⊠ Binary Input Change With Time
□ Only non-time-tagged□ Binary Input Change With Relative Time
□ Configurable□ Configurable (attach explanation)
Sends Unsolicited Responses:Sends Static Data in Unsolicited Responses:
□ Never⊠ Never
□ Configurable□ When Device Restarts
□ Only certain objects□ When Status Flags Change
⊠ SometimesNo other options are permitted.
⊠ ENABLE/DISABLE unsolicited Function codes
supported
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–7
Page 12
RS485 INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
DNP 3.0 Device Profile
Explanation of ‘Sometimes’: It will be disabled for
RS-485 applications, since there is no collision
avoidance mechanism. For Ethernet communication
it will be available and it can be disabled or enabled
with the proper function code.
Default Counter Object/Variation:Counters Roll Over at:
□ No Counters Reported□ No Counters Reported
□ Configurable (attach explanation)□ Configurable (attach explanation)
⊠ Default Object: 20⊠ 16 Bits
Default Variation: 1
⊠ Point-by-point list attached□ Other Value: _____
⊠ Point-by-point list attached
Sends Multi-Fragment Responses:
⊠ Yes
□ No
DNP implementationTable 1: DNP Implementation
OBJECT REQUEST RESPONSE
OBJECT
NO.
1 0 Binary Input (Variation 0
2 0 Binary Input Change
10 0 Binary Output Status
VARIATION
NO.
1 Binary Input 1 (read) 22
2 Binary Input with Status 1 (read) 22
1 Binary Input Change
2 Binary Input Change
3 Binary Input Change
DESCRIPTIONFUNCTION
is used to request
default variation)
(Variation 0 is used to
request default
variation)
without Time
with Time
with Relative Time
(Variation 0 is used to
request default
variation)
CODES
(DEC)
1 (read) 22
(assign
class)
(assign
class)
(assign
class)
1 (read) 06 (no range, or all)
1 (read) 06 (no range, or all)
1 (read) 06 (no range, or all)
1 (read) 06 (no range, or all)
1 (read) 00, 01(start-stop)
QUALIFIER CODES
(HEX)
00, 01 (start-stop)
06 (no range, or all)
07, 08 (limited
quantity) 17, 28
(index)
00, 01 (start-stop)
06 (no range, or all)
07, 08 (limited
quantity) 17, 28
(index)
00, 01 (start-stop)
06 (no range, or all)
07, 08 (limited
quantity) 17, 28
(index)
07, 08 (limited
quantity)
07, 08 (limited
quantity)
07, 08 (limited
quantity)
07, 08 (limited
quantity)
06 (no range, or all)
07, 08 (limited
quantity) 17, 28
(index)
FUNCTION
CODES
(DEC)
--- ---
129
(response)
129
(response)
--- ---
129
(response)
130 (unsol.
resp.)
129
(response)
130 (unsol.
resp.)
--- ---
--- ---
QUALIFIER
CODES
(HEX)
00, 01
(start-stop)
17, 28
(index) (see
Note 2)
00, 01
(start-stop)
17, 28
(index) (see
Note 2)
17, 28
(index)
17, 28
(index)
1–8345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 13
CHAPTER 1: COMMUNICATIONS GUIDERS485 INTERFACE
OBJECT REQUEST RESPONSE
OBJECT
NO.
12 1 Control Relay Output
VARIATION
NO.
DESCRIPTIONFUNCTION
CODES
QUALIFIER CODES
(HEX)
(DEC)
2 Binary Output Status 1 (read) 00, 01 (start-stop)
06 (no range, or all)
07, 08 (limited
quantity) 17, 28
(index)
1.A default variation refers to the variation response when variation 0 is requested and/
13 (cold
restart)
14 (warm
restart)
23 (delay
meas.)
00 (start-stop)
(index =7)
--- --- ---
--- --- ---
--- --- ---
129
(response)
00, 01
(start-stop)
--- ---
or in class 0, 1, 2, or 3 scans. The default variations for object types 1, 2, 20, 21, 22, 23,
30, and 32 are selected via relay settings. This optimizes the class 0 poll data size.
2.For static (non-change-event) objects, qualifiers 17 or 28 are only responded when a
request is sent with qualifiers 17 or 28, respectively. Otherwise, static object requests
sent with qualifiers 00, 01, 06, 07, or 08, will be responded with qualifiers 00 or 01 (for
changeevent objects, qualifiers 17 or 28 are always responded.)
3.Cold restarts are implemented the same as warm restarts – the 345 is not restarted,
but the DNP process is restarted.
1–12345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 17
CHAPTER 1: COMMUNICATIONS GUIDERS485 INTERFACE
DNP serial EnerVista
Setup
The following tables show the settings needed to configure all the DNP 3.0 implementation
parameters.
In order to activate DNP 3.0 at the RS485 rear port, the setting "Rear 485 Protocol" must be
set to DNP 3.0. Once the setting has been changed, the relay must be switched off, then
switched on.
Table 3: DNP protocol
SETTINGS PARAMETER RANGE FORMAT
DNP Unsol Resp Function Disabled Disabled ; Enabled F126
DNP Unsol Resp Timeout 5 s 0 to 60 s F1
DNP Unsol Resp Max Retries 10 1 to 255 F1
DNP Unsol Resp Dest Addr 1 0 to 65519 F1
DNP Time Sync IIN Period 1440 min 1 to 10080 min F1
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–13
Page 18
RS485 INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Table 4: DNP point list
SETTINGS PARAMETER RANGE FORMAT
Binary Input Point 0 Entry Select entry
from a list
Operands F134
Binary Input Point 63 Entry Select entry
Analog Input Point 0 Entry Select entry
Analog Input Point 0 Scale Factor 1 0.001 ; 0.01 ; 0.1 ; 1 ; 10 ; 100 ;
Analog Input Point 0 Deadband 30000 0 to 100000000 F9
Analog Input Point 31 Entry Select entry
Analog Input Point 31 Scale
Factor
Analog Input Point 31 Deadband 30000 0 to 100000000 F9
Binary Output Point 0 ON Select entry
Binary Output Point 0 OFF Select entry
Binary Output Point 15 ON Select entry
Binary Output Point 15 OFF Select entry
from a list
from a list
from a list
1 0.001 ; 0.01 ; 0.1 ; 1 ; 10 ; 100 ;
from a list
from a list
from a list
from a list
Operands F134
Analog parameters
1000 ; 10000 ; 100000
Analog parameters
1000 ; 10000 ; 100000
Virtual Input 1 to 32 and Force
Coils
Virtual Input 1 to 32 and Force
Coils
Virtual Input 1 to 32 and Force
Coils
Virtual Input 1 to 32 and Force
Coils
F85
F85
F86
F86
F86
F86
•DNP UNSOL RESPONSE FUNCTION should be “Disabled” for RS485 applications, since
there is no collision avoidance mechanism.
•The DNP Time Sync IIN Period setting determines how often the Need Time Internal
Indication (IIN) bit is set by the 345. Changing this time allows the 345 to indicate that
a time synchroniztion command is necessary more or less often
•Various settings have been included to configure Default Variation for the Binary
Inputs, Counters and Analog Inputs Objects. The default variation refers to the
variation response when variation 0 is requested, and/or in class 0, 1, 2, or 3 scans
•Up to 64 Binary Inputs and 32 Analog Input entries can be mapped to an item from a
list of 345 status events and metered values. Status events correspond to Funcion
Code 134B.
•Each Analog Input point Deadband and Scale Factor can be set individually instead of
setting a general deadband or scale for different metering groups. This will avoid scale
and deadband conflicts for different meterings of the same nature.
•Up to 16 Binary/Control Outputs can be configured by selecting a Virtual Input or
Command from a list of 32 Virtual Inputs and Commands (Force Coils). Some legacy
DNP implementations use a mapping of one DNP Binary Output to two physical or
virtual control points. In Order to configure Paired Control Points the source for states
ON and OFF should be set to different Virtual Inputs or Commands.
•The DNP Technical Committee recommends using contiguous point numbers, starting
at 0, for each data type, because some DNP3 Master implementations allocate
contiguous memory from point 0 to the last number for each data type.
1–14345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 19
CHAPTER 1: COMMUNICATIONS GUIDERS485 INTERFACE
NOTE:
Binary Inputs are inputs to the Master. Binary Outputs are outputs from the Master.
DNP generalDefault variations for Object 1, 2 , 20 , 21 , 22 , 23 , 30 and Object 32 will be set by settings
and returned for the object in a response when no specific variation is specified in a Master
request.
Any change in the state of any binary point causes the generation of an event, and
consequently, if configured, an unsolicited response, or it is returned when the Master asks
for it. The same behaviour will be seen when an analog value changes by more than its
configured deadband limit . There can be up to 3 Masters in total, but only one Serial
Master.
The following Default Classes will be fixed for the different blocks of data:
Binary Input Points Default Class = 1
Analog Input Point Default Class = 2
Counters Default Class = 3
Each Data Point Class can be changed by protocol function code 22 in volatile mode. If a
restart is performed, the new values will be lost.
DNP Object 34 points can be used to change deadband values from the default for each
individual DNP Analog Input point. These new deadbands will be maintained such that in
the case of a relay restart, the values are not lost.
Requests for Object 20 (Binary Counters), Object 21 (Frozen Counters), and Object 22
(Counter Change Events) must be accepted.
Function codes “Immediate Freeze”, “Freeze and Clear” etc. are accepted as well.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–15
Page 20
RS485 INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
S1 103 FIRST ASDU
ID TYPE
FUNCTION TYPE
INFORMATION NO
SCAN TIMEOUT
FIRST ANLG ENTRY
FIRST ANLG FACTOR
FIRST ANLG OFFSET
...
NINTH ANLG ENTRY
NINTH ANLG FACTOR
NINTH ANLG OFFSET
▼
S1 103 GENERAL
SLAVE ADDRESS
SYNCH TIMEOUT
▼
897770.cdr
S1 103 MEASURANDS
FIRST ASDU
SECOND ASDU
THIRD ASDU
FOURTH ASDU
▼
S1 60870-5-103
GENERAL
BINARY INPUTS
MEASURANDS
COMMANDS
▼
S1 103 COMMANDS
CMD 0 FUNC TYPE
CMD 0 INFO NO:
CMD 0 ON OPER:
CMD 0 OFF OPER:
...
CMD 15 FUNC TYPE:
CMD 15 INFO NO:
CMD 15 ON OPER:
CMD 15 OFF OPER:
▼
S1 103 FOURTH ASDU
ID TYPE
FUNCTION TYPE
INFORMATION NO
SCAN TIMEOUT
FIRST ANLG ENTRY
FIRST ANLG FACTOR
FIRST ANLG OFFSET
...
NINTH ANLG ENTRY
NINTH ANLG FACTOR
NINTH ANLG OFFSET
▼
S1 103 B INPUTS
POINT 0
POINT 0 FUNC TYPE
POINT 0 INFO NO:
...
POINT 63
POINT 63FUNC TYPE
POINT 63 INFO NO:
Table 8: Earth fault indications in monitor direction
INF Semantics345 Identifier345 Data Text
□ INF Semantics345 Identifier345 Data Text
□ <48> Earth fault L1
□ <49> Earth fault L2
□ <50> Earth fault L3
□ <51> Earth fault forward, i.e. line
□ <52> Earth fault reverse, i.e. busbar
1–18345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 23
CHAPTER 1: COMMUNICATIONS GUIDERS485 INTERFACE
Table 9: Fault indications in monitor direction
INF Semantics345 Identifier345 Data Text
□ INF Semantics345 Identifier345 Data Text
□ <64> Start / pick-up L1
□ <65> Start / pick-up L2
□ <66> Start / pick-up L3
□ <67> Start / pick-up N
□ <68> General trip
□ <69> Trip L1
□ <70> Trip L2
□ <71> Trip L3
□ <72> Trip I>> (back-up operation)
□ <73> Fault location X in ohms
□ <74> Fault forward / line
□ <75> Fault reverse / busbar
□ <76> Teleprotection signal transmitted
□ <77> Teleprotection signal received
□ <78> Zone 1
□ <79> Zone 2
□ <80> Zone 3
□ <81> Zone 4
□ <82> Zone 5
□ <83> Zone 6
□ <84> General start / pick-up
□ <85> Breaker failure
□ <86> Trip measuring system L1
□ <87> Trip measuring system L2
□ <88> Trip measuring system L3
□ <89> Trip measuring system E
□ <90> Trip I>
□ <91> Trip I>>
□ <92> Trip IN>
□ <93> Trip IN>>
Table 10: Auto-reclosure indications in monitor direction
□ <128> CB ‘on’ by AR
□ <129> CB ‘on’ by long-time AR
□ <130> AR blocked
Table 11: Measurands in monitor direction
□ <144> Measurand I
□ <145> Measurands I, V
□ <146> Measurands I, V, P, Q
□ <147> Measurands In, Ven
□ <148> Measurands IL123, VL123, P, Q, f
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–19
INF Semantics345 Identifier345 Data Text
INF Semantics345 Identifier345 Data Text
Page 24
RS485 INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Table 12: Generic functions in monitor direction
INF Semantics
□ <240> Read headings of all defined groups
□ <241> Read values or attributes of all entries of one group
□ <243> Read directory of a single entry
□ <244> Read value or attribute of a single entry
□ <245> End of general interrogation of generic data
□ <249> Write entry with confirmation
□ <250> Write entry with execution
□ <251> Write entry aborted
Selection of standard
information numbers
in control direction
Table 13: System functions in control direction
INF Semantics
⊠ <0> Initiation of general interrogation
⊠ <0> T ime synchronization
Table 14: General commands in control direction
INF Semantics
□ <16> Auto-recloser on / off
□ <17> Teleprotection on / off
□ <18> Protection on / off
□ <19> LED reset
□ <23> Activate characteristic 1
□ <24> Activate characteristic 2
□ <25> Activate characteristic 3
□ <26> Activate characteristic 4
Table 15: General functions in control direction
INF Semantics
□ <240> Read headings of all defined groups
□ <241> Read values or attributes of all entries of one group
□ <243> Read directory of a single entry
□ <244> Read value or attribute of a single entry
□ <245> General interrogation of generic data
□ <248> Write entry
□ <249> Write entry with confirmation
□ <250> Write entry with execution
□ <251> Write entry abort
Basic application
functions
1–20345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
□ Test mode
□ Blocking of monitor direction
□ Disturbance data
□ Generic services
□ Private data
Page 25
CHAPTER 1: COMMUNICATIONS GUIDERS485 INTERFACE
Miscellaneous
Measurand Max. MVAL = times rated value
1,2or2,4
Current L1□⊠
Current L2□⊠
Current L3□⊠
Voltage L1-E□□
Voltage L2-E□□
Voltage L3-E□□
Active power P□□
Reactive power Q□□
Frequency f□⊠
Voltage L1-L2□□
Application level
Application functionsThe unbalanced transmission mode of the protocol is used to avoid the possibility of more
than one protection device attempting to transmit on the channel at the same time, over
the RS485 port.
Data is transferred to the primary or control station (master) using the “data acquisition by
polling” principle. Cyclically, the master will request class 2 data to the secondary station
(slave).
When slave has class 1 data (high priority) pending, the ACD control bit will be set to 1
demanding the master to request for that data.
Periodically, the master may send a General Interrogation in order to update the complete
database.
The measurands will be sent to the primary station as a response to class 2 request. A
setting (0 to 60 min) is available to configure the desired interval, where 0 means
transmission as fast as possible.
The following functions are supported:
•Initialization
•General Interrogation
•Synchronization
•Commands transmission
Type identificationThe Type Identification implemented will be:
Information in monitor direction:
Information in control direction:
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–21
TYPE IDENTIFICATION UI8[1..8] <1..255>
<1..31>:= definitions of this companion standard(compatible range)
<32..255>:= for special use (private range)
<1>:= time-tagged message
<3>:= measurands I
<5>:= identification
<6>:= time synchronization
<8>:= general interrogation termination
<9>:= measurands II
<6>:= time synchronization
<7>:= general interrogation
Page 26
RS485 INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
<20>:= general command
Function typeFUNCTION TYPE UI8 [1..8] <0..255>
<0..127>:= private range
<128..129>:= compatible range
<130..143>:= private range
<144..145>:= compatible range
<146..159>:= private range
<160..161>:= compatible range
<162..175>:= private range
<176..177>:= compatible range
<178..191>:= private range
<192..193>:= compatible range
<194..207>:= private range
<208..209>:= compatible range
<210..223>:= private range
<224..225>:= compatible range
<226..239>:= private range
<240..241>:= compatible range
<242..253>:= private range
<254..255>:= compatible range
The 345 relay is identified in this protocol as “overcurrent protection”, so it will use the
Function Type <160> for all the digital and analogues points proposed by the standard and
mapped in this profile. For the other data supported by the device, the customer will have
the capability to use them by setting a number from the private range.
Information numberINFORMATION NUMBER := UI8 [1..8] <0..255>
Monitor direction := <0..255>
<0..15>:=system functions
<16..31>:= status
<32..47>:=supervision
<48..63>:=earth fault
<64..127>:=short circuit
<128..143>:=auto-reclosure
<144..159>:=measurands
<160..239>:=not used
<240..255>:=generic functions
Control direction:=<0..255>
<0..15>:=system functions
<16..31>:=general commands
<32..239>:=not used
<240..255>:=generic functions
Data management
The 345 relay supports a fixed profile and data that is configurable using the EnerVista
SR3 Setup program.
The data that can be configured are:
•digital states
1–22345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 27
CHAPTER 1: COMMUNICATIONS GUIDERS485 INTERFACE
•measurands
•commands.
Digital statesDigital states in the relay may be mapped using the EnerVista SR3 Setup program. By
default, states are mapped to information numbers proposed by the standard, but the
user may delete these mappings if desired.
All the mapped information will be sent as a response to a general interrogation like ASDU
1.
For the other states, the customer can assign:
1.Information Number <1..255>
2.Function Type <0..255>.
Settings Digital Status Information Number Function Type
Point 1 Entry Select entry from list <0 – 255 > <0 – 255 >
….
.…
Point 64 Entry Select entry from list <0 – 255 > <0 – 255 >
This means that for each digital point 3 settings are required.
Example:
Modbus Address Description Value Format
43879 Point 1 Entry Digital Status 0x8242 (Undercurrent Trip) FC134
44223 Point 1 Entry Function Type 160 F1
44224 Point 1 Entry Information Number 144 F1
The “Point Entry Digital Status” reuses the DNP Binary Input 43029, 43030, …
MeasurandsSome analog points are supported by the 345 relay, with compatible information number
that have been identified in the device profile.
For the other measurands, it is possible to use the EnerVista SR3 Setup to select the
desired point and assign the Identification Type (3 or 9), Function Type <0..255>, and
Information Number <1..255>.
If the user selects Identification Type 3 (ASDU 3) only four measurands are available for
configuration, but if Identif ication Type 9 (ASDU 9) is selected, up to nine measurands can
be sent in the IEC103 slave answer. For each measurand, all metering values that the 345
supports, are available in order to be mapped. There are 3 possible configurable ASDUS.
For example, eDataVab is the index in the Modbus Memory Map.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–23
Page 28
RS485 INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Modbus Address Description Value Format
44384 First ASDU Identification Type 3 or 9 F1
44385 First ASDU Function Type <0 – 255 > F1
44386 First ASDU Information Number < 0 – 255 > F1
44387 First ASDU Scan Timeout < 0 – 1000> secs F1
44388 First ASDU First Analog Entry Vab F1
44389 First ASDU First Analog Factor 1 F3
44390 First ASDU First Analog Offset 0 F1
44391 First ASDU Second Analog Entry Ib F1
44392 First ASDU Second Analog Factor 1 F3
44393 First ASDU Second Analog Offset 0 F1
... ... ... ...
44412 First ASDU Ninth Analog Entry Ib F1
44413 First ASDU Ninth Analog Factor 1 F3
... ... ... ...
44443 Second ASDU Ninth Analogue Entry
44444 Second ASDU Ninth Analogue Factor
44445 Second ASDU Ninth Analogue Offset
... ... ... ...
44446 Third ASDU Identification Type
... … ... ...
44476 Third ASDU Ninth Analogue Offset
In the measurands configuration screen, with each selected measurement, a Factor and
an Offset must be configured.
•The Factor is a multiplier factor.
•The Offset is an offset factor to be applied to the relay measurement to make the final
The factor and offset parameters allow the user to perform different scaling in the relay
measurements. The final measurement sent to the IEC103 master will be: “a*x+b”, where
“x” is the relay measurement, “a” is the multiplier factor and “b” is the offset.
The measurands will be sent to the primary station as a response to a class 2 request.
There is a Timeout configurable with increments of 100 ms, between 0 and 60 min, in order
to configure the desired interval.
Commands
All the commands and virtual inputs are available to be mapped using the EnerVista Setup
program. It is possible to choose the desired command for the ON state and the same or
different command for the OFF state.
The user is able to select the Information Number <1..255> and the Function Type <0..255>
command mappings, but the Identification Type 20 (General Commands) is fixed.++ There
are 32 configurable commands.
In this case it will be necessary to define a new format.
For example, FC500:
measurement calculation to be sent to the master
1–24345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 29
CHAPTER 1: COMMUNICATIONS GUIDERS485 INTERFACE
Description Value
Virtual Input 1 0
Virtual Input 2 1
...
Virtual Input 32 31
Reset 32
Open 35
Close 36
Modbus Address Description Value Format
Command 1 Function Type <0 – 255 > F1
Command 1 Information Number < 0 – 255 > F1
Command 1 Operation ON 2 FC500
Command 1 Operation OFF 8 FC500
...
Command 16 Function Type <0 – 255 > F1
Command 16 Information Number < 0 – 255 > F1
Command 16 Operation ON 6 FC500
Command 16 Operation OFF 34 FC500
The “Command Operations ON and OFF” reuse the DNP Binary Outputs 43189, 43190,
…
103 general settings
Number Value Range
Comms Port COM1 Enum[None,Com1]
Slave Address 1 [0..254]
Synchronization Timeout 30 min [0..1440]min
If Comms Port is set to NONE, the IEC 870-5-103 communication protocol will not be
available.
If the user sets a value other than 0 in the Synchronization Timeout setting, when this time
expires without receiving a synchronization message, the Invalid bit will be set in the time
stamp of a time-tagged message.
It is necessary to configure other port settings: Baud Rate, etc.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–25
Page 30
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Ethernet interface
The Ethernet option for the 345 provides both a 1300 nm optical interface, and a 10/100
auto-negotiating copper interface. To select which interface is active, a MODBUS setpoint
(see below) must be modified:
MODBUS
Address
40191 BE EthernetConnectionType 0 1 1 FC230 0
Hex
Address
Description Min Max Step Function
Code
Factory
Default
SNTP
SNTP settingsWith SNTP, the device can obtain the clock time over an Ethernet network, acting as an
SNTP client to receive time values from an SNTP server.
SNTP Port configures the ports that the device uses, so it’s necessary to configure it in all
cases.
The relay binds to the first unicast message (see below) received from any server, then
continues operating with the SNTP server in unicast mode. Any further responses from
other SNTP servers are ignored. In the unicast mode of operation the chosen time server
can go offline, in which case it takes about one minute for the device to signal an SNTP
FAIL state and switch again to anycast mode in order to try to find another time server.
SNTP modesThree different modes of SNTP operation are supported. These modes are unicast,
broadcast and anycast.
To use SNTP in unicast mode, the SNTP IP Address must be set to the SNTP server IP
address. Once this address is set and the function setting is “UNICAST”, the device attempts
to obtain time values from the SNTP server. Since many time values are obtained and
averaged, it generally takes 10 seconds until the clock is synchronized with the SNTP
server.
It may take up to 30 seconds for the device to signal an SNTP FAIL state if the server is offline. In this case the main CPU generates an alarm similar to that of the IRIG-B case.
To use SNTP in broadcast mode, set the function setting to “BROADCAST”. The device
listens to SNTP messages sent to "all" the broadcast addresses for the subnet .
The device waits up to eighteen minutes (>1024 seconds) to receive an SNTP broadcast
message before signaling an SNTP FAIL state.
To use SNTP in anycast mode, set the function setting to “ANYCAST”. Anycast mode is
designed for use with a set of cooperating servers whose addresses are not known
beforehand by the client. The device sends a request to a multicast group address
assigned by IANA for SNTP protocol purposes. This address is 224.0.1.1 and a group of
SNTP servers listens to it . Upon receiving such a request, each server sends a unicast
response to the SNTP client.
The relay binds to the first unicast message received from any server, then it continues
operating with the SNTP server in unicast mode. Any further responses from other SNTP
servers are ignored. In the unicast mode of operation, the chosen time server can go
offline, in which case it takes about one minute for the device to signal an SNTP FAIL state
and to switch again to the anycast mode to try to find another time server.
1–26345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 31
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
MODBUS TCP/IP
This section describes the procedure to read and write data in the 350 relay using MODBUS
TCP protocol. The MODBUS communication allows the 350 relay to be connected to a
supervisor program or any other device with a master MODBUS communication channel.
The 350 will be always a slave station.
MODBUS TCP is a variant of the MODBUS protocol, intended for supervision and control of
automation equipment. It covers the use of MODBUS messaging in an 'Intranet' or
'Internet' environment using the TCP/IP protocols.
MODBUS TCP basically embeds a MODBUS frame into a TCP frame in a simple manner. This
is a connection-oriented transaction which means that every query expects a response.
When the relay communicates using MODBUS TCP, it does not require a checksum
calculation of the MODBUS frame as does the MODBUS RTU.
The 350 relay supports only a subset of the MODBUS protocol functions.
Data and control
functions
The following functions are supported:
01H Read Coil Status
Just respond, no action required for now.
Outgoing message for this function is the same as input one.
02H Read Input Status
Just respond, no action required for now.
Outgoing message for this function is the same as input one.
03H Read Holding Registers
Reads the binary contents of holding registers in the slave.
Query:
The query message specifies the starting register and quantity of registers to be read.
Registers are addressed starting at zero: registers 1 to 16 are addressed as 0 to 15.
Here is an example of a request to read registers 40172 to 40175 from slave device 254:
Field Name Hex
Slave Address FE
Function 03
Starting Address Hi 00
Starting Address Lo AB
No. of Points Hi 00
No. of Points Lo 04
Response:
The register data in the response message are packed as two bytes per register, with the
binary contents right justified within each byte. For each register, the first byte contains the
high order bits and the second contains the low order bits.
The response is returned when the data is completely assembled.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–27
Page 32
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Field Name Hex
Slave Address FE
Function 03
Byte Count 08
Data Hi (Register 40172) 00
Data Lo (Register 40172) FE
Data Hi (Register 40173) 00
Data Lo (Register 40173) 04
Data Hi (Register 40174) 00
Data Lo (Register 40174) 00
Data Hi (Register 40175) 00
Data Lo (Register 40175) 00
The contents of register 40172 are shown as the two byte values of 00 FE hex, or254
decimal. The contents of registers 40173 to 40175 are 00 04, 00 00 and 00 00 hex, or4, 0
and 0 decimal.
04H Read Input Registers
Reads the binary contents of input registers (3X references) in the slave.
Query:
The query message specifies the starting register and quantity of registers to be read.
Registers are addressed starting at zero: registers 1 to 16 are addressed as 0 to 15.
Here is an example of a request to read register 30305 from slave device 254:
Field Name Hex
Slave Address FE
Function 04
Starting Address Hi 01
Starting Address Lo 30
No. of Points Hi 00
No. of Points Lo 01
Response:
The register data in the response message are packed as two bytes per register, with the
binary contents right justified within each byte. For each register, the first byte contains the
high order bits and the second contains the low order bits.
Field Name Hex
Slave Address FE
Function 04
Byte Count 02
Data Hi (Register 30305) 80
Data Lo (Register 30305) 80
05H Force Single Coil
Forces a single coil (0X reference) to either ON or OFF.
The query message specifies the coil reference to be forced. Coils are addressed starting at
zero: coil 1 is addressed as 0.
The reguested ON/OFF state is specified by a constant in the query data field.
1–28345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 33
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
A value of FF 00 hex requests the coil to be ON. A value of 00 00 requests it to be OFF. All
other values are illegal and will not affect the coil.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–29
Page 34
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Description Coil Address (DEC)
eCmdCO6_On 42
eCmdCO6_Off 43
eCmdCO7_On 44
eCmdCO7_Off 45
eCmdCO8_On 46
eCmdCO8_Off 47
eCmdCO9_On 48
eCmdCO9_Off 49
eCmdCO10_On 50
eCmdCO10_Off 51
eCmdCO11_On 52
eCmdCO11_Off 53
eCmdCO12_On 54
eCmdCO12_Off 55
eCmdCO13_On 56
eCmdCO13_Off 57
eCmdCO14_On 58
eCmdCO14_Off 59
eCmdCO15_On 60
eCmdCO15_Off 61
eCmdCO16_On 62
eCmdCO16_Off 63
eCmdCO17_On 64
eCmdCO17_Off 65
eCmdCO18_On 66
eCmdCO18_Off 67
eCmdCO19_On 68
eCmdCO19_Off 69
eCmdCO20_On 70
eCmdCO20_Off 71
eCmdCO21_On 72
eCmdCO21_Off 73
eCmdCO22_On 74
eCmdCO22_Off 75
eCmdCO23_On 76
eCmdCO23_Off 77
eCmdCO24_On 78
eCmdCO24_Off 79
eCmdCO25_On 80
eCmdCO25_Off 81
eCmdCO26_On 82
eCmdCO26_Off 83
eCmdCO27_On 84
eCmdCO27_Off 85
eCmdCO28_On 86
eCmdCO28_Off 87
eCmdCO29_On 88
1–30345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 35
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
Description Coil Address (DEC)
eCmdCO29_Off 89
eCmdCO30_On 90
eCmdCO30_Off 91
eCmdCO31_On 92
eCmdCO31_Off 93
eCmdCO32_On 94
eCmdCO32_Off 95
CmdClearTripData 96
eCmdResetPowerMeters 97
eCmdClearDemand 98
eCmdClearCounters 99
eCmdClearEvents 100
eCmdClearWaveform 101
eCmdClearMaintenanceTimer 102
eCmdClearDataLogger 103
eCmdClearTemperatureHistory 104
eCmdClearThermal_Image 105
eCmdRTDMaximums 112
eCmdResetMotorInfo 113
eCmdAutoMode 114
eCmdManualMode 115
eCmdManualInhibit 116
eCmdManualRestore 117
eCmdStartInhibit 118
eCmdStartRestore 119
eCmdTriggerWaveform 120
eCmdStartDataLog 121
eCmdStopDatalog 122
eCmdTempResetIntValues 123
eCmdTempFactoryClear 124
eCmdTempFactoryStoreSample 125
eCmdClearSecurityLog 126
eCmdStartUploadingSetpointFile 127
eCmdEndUploadingSetpointFile 128
eCmdForceLEDs 140
eCMDNoKeyPress 141
eCMDNavUpKey 142
eCMDNavLeftKey 143
eCMDNavDownKey 144
eCMDNavRightKey 145
eCMDUpKey 146
eCMDDownKey 147
eCMDEnterKey 148
eCMDMenuKey 149
eCMDEscapeKey 150
eCMDResetKey 151
eCmdUploadModeEntry2 159
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–31
Page 36
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Description Coil Address (DEC)
eCmdUploadModeEntry1 160
eCmdReloadFactorySetpts2 161
eCmdReloadFactorySetpts1 162
eCmdSecurityMin 163
eCmdFactoryUse1 164
eCmdFactoryUse2 165
eCmdFactoryUse3 166
eCmdFactoryUse4 167
eCmdFactoryUse5 168
eCmdFactoryUse6 169
eCmdFactoryUse7 170
eCmdFactoryUse8 171
eCmdFactoryUse9 172
eCmdFactoryUse10 173
eCmdPaintGCPRed 174
eCmdPaintGCPGreen 175
eCmdPaintGCPBlue 176
eCmdReboot2 177
eCmdReboot1 178
eCmdMAC2 179
eCmdMAC1 180
eCmdCalOffsets2 181
Query:
Here is an example of a request to force Virtual Input1 to ON in slave device 254:
Field Name Hex
Slave Address FE
Function 05
Coil Address Hi 10
Coil Address Lo 00
Force Data Hi FF
Force Data Lo 00
Response:
The normal response is an echo of the query, returned after the coil state has been forced.
Field Name Hex
Slave Address FE
Function 05
Coil Address Hi 10
Coil Address Lo 00
Force Data Hi FF
Force Data Lo 00
07H Read Exception Status
Modbus Implementation: Read Exception Status
350 Implementation: Read Device Status
1–32345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 37
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
This is a function used to quickly read the status of a selected device. A short message
length allows for rapid reading of status. The status byte returned will have individual bits
set to 1 or 0 depending on the status of the slave device. For this example, consider the
following 350 general status byte:
The master/slave packets have the following format:
Mask Function
0x01 Alarm
0x02 Trip
0x04 Self Test Fault
0x08 Breaker Connected
0x10 52a Status
0x20 52b Status
0x40 Maintenance
0x80 In Service
Query:
Field Name Hex
Slave Address FE
Function 07
Response:
Field Name Hex
Slave Address FE
Function 07
Device Status (see definition above) 2C
08H Diagnostics
Just respond, no action required for now.
Serves as a loopback test.
Outgoing message for this function is the same as input one.
16 (10 Hex) Preset Multiple Registers
Presets values into a sequence of holding registers (4X references.
Query:
The query message specifies the register references to be preset. Registers are addressed
starting at zero: register 1 is addressed as 0.
The requested preset values are specified in the query data field. Data is packed as two
bytes per register.
Here is an example of a request to preset two registers starting at 43851 to 00 01 and 00
00 hex, in slave device 254:
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–33
Page 38
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Field Name Hex
Slave Address FE
Function 10
Starting Address Hi 0F
Starting Address Lo 0A
No. of Registers Hi 00
No. of Registers Lo 02
Byte Count 04 04
Data Hi 00
Data Lo 01
Data Hi 00
Data Lo 00
Response:
The normal response returns the slave address, function code, starting address, and
quantity of registers preset.
Field Name Hex
Slave Address FE
Function 10
Starting Address Hi 0F
Starting Address Lo 0A
No. of Registers Hi 00
No. of Registers Lo 02
42H Read Settings Group
Not a standard function.
All the protection function has two sets of settings - Group 1 and Group 2. This function
number is used to read the settings for each group.
Example:
Field Name Hex
Slave Address FE
Function 42
Group Activation 00
Starting Address Hi 0A
Starting Address Lo B3
No. of Registers Hi 00
No. of Registers Lo 01
1–34345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 39
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
Response:
Field Name Hex
Slave Address FE
Function 42
Byte Count 02
Data Hi 00
Data Lo 00
43H Write Settings Group
Not a standard function
This function is used to write settings in a specific settings group.
Example: (In the example there is a write setting procedure in the Group 1 (00) , setting
address 0x09C1 and 2 bytes of data with value 0x0001.)
Field Name Hex
Slave Address FE
Function 43
Group Activation 00
Starting Address Hi 09
Starting Address Lo C1
No. of Registers Hi 00
No. of Registers Lo 01
Byte Count 04 02
Data Hi 00
Data Lo 01
Exception and error
responses
Request response
sequence
Response:
Field Name Hex
Slave Address FE
Function 43
Starting Address Hi 09
Starting Address Lo C1
No. of Registers Hi 00
No. of Registers Lo 01
One data frame of an asynchronous transmission to or from a 345 typically consists of 1
start bit, 8 data bits, and 1 stop bit . This produces a 10 bit data frame. This is important for
transmission through modems at high bit rates.
Modbus protocol can be implemented at any standard communication speed. The
SR350supports operation at 9600, 19200, 38400, 57600, and 115200 baud.
A complete request/response sequence consists of the following bytes (transmitted as
separate data frames):
Master Request Transmission:
SLAVE ADDRESS: 1 byte
FUNCTION CODE: 1 byte
DATA: variable number of bytes depending on FUNCTION CODE
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–35
Page 40
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
CRC: 2 bytes
Slave Response Transmission:
SLAVE ADDRESS: 1 byte
FUNCTION CODE: 1 byte
DATA: variable number of bytes depending on FUNCTION CODE
CRC: 2 bytes
SLAVE ADDRESS: This is the first byte of every transmission. This byte represents the userassigned address of the slave device that is to receive the message sent by the master.
Each slave device must be assigned a unique address and only the addressed slave will
respond to a transmission that starts with its address. In a master request transmission the
SLAVE ADDRESS represents the address of the slave to which the request is being sent. In a
slave response transmission the SLAVE ADDRESS represents the address of the slave that is
sending the response.
FUNCTION CODE: This is the second byte of every transmission. Modbus defines function
codes of 1 to 127.
DATA: This will be a variable number of bytes depending on the FUNCTION CODE. This may
be Actual Values, Setpoints, or addresses sent by the master to the slave or by the slave to
the master.
CRC: This is a two byte error checking code.
CRCThe TCP version of Modbus includes a two byte CRC-16 (16 bit cyclic redundancy check)
with every transmission. The CRC-16 algorithm essentially treats the entire data stream
(data bits only; start, stop and parity ignored) as one continuous binary number. This
number is first shifted left 16 bits and then divided by a characteristic polynomial
(11000000000000101B). The 16 bit remainder of the division is appended to the end of the
transmission, MSByte first. The resulting message including CRC, when divided by the
same polynomial at the receiver will give a zero remainder if no transmission errors have
occurred.
If a 345 Modbus slave device receives a transmission in which an error is indicated by the
CRC-16 calculation, the slave device will not respond to the transmission. A CRC-16 error
indicates than one or more bytes of the transmission were received incorrectly and thus
the entire transmission should be ignored in order to avoid the 345 performing any
incorrect operation.
The CRC-16 calculation is an industry standard method used for error detection. An
algorithm is included here to assist programmers in situations where no standard CRC-16
calculation routines are available.
Once the following algorithm is complete, the working register “A” will contain the CRC
value to be transmitted. Note that this algorithm requires the characteristic polynomial to
be reverse bit ordered. The MSBit of the characteristic polynomial is dropped since it does
not affect the value of the remainder. The following symbols are used in the algorithm:
—>: data transfer
A: 16 bit working register
AL: low order byte of A
AH: high order byte of A
CRC: 16 bit CRC-16 value
i, j: loop counters
(+): logical exclusive or operator
Di: i-th data byte (i = 0 to N-1)
G: 16 bit characteristic polynomial = 1010000000000001 with MSbit dropped and bit order
reversed
shr(x): shift right (the LSbit of the low order byte of x shifts into a carry flag, a '0' is shifted
into the MSbit of the high order byte of x, all other bits shift right one location
1–36345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 41
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
The algorithm is:
1. FFFF hex —> A
2. 0 —> i
3. 0 —> j
4. Di (+) AL —> AL
5. j+1 —> j
6. shr(A)
7. is there a carry? No: go to 8. Yes: G (+) A —> A
8. is j = 8? No: go to 5. Yes: go to 9.
9. i+1 —> i
10. is i = N? No: go to 3. Yes: go to 11.
11. A —> CRC
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–37
Page 42
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
S1 DNP GENERAL
DNP ADDRESS
DNP TCP/UDP PORT
CHANNEL 1 PORT
CHANNEL 2 PORT
TME SYNC IIN PER.
DNP MSG FRAG SIZE
DNP TCP CONN. T/O
▼
S1 DNP
DNP GENERAL
DNP UNSOL RESPONSE*
DEFAULT VARIATION
DNP CLIENT ADDRESS*
DNP POINTS LIST
1–38345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
DNP 3.0 Device Profile
(Also see the IMPLEMENTATION TABLE in the following section)
Vendor Name: General Electric Multilin
Device Name: SR345 Relay
Page 43
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
DNP 3.0 Device Profile
Highest DNP Level Supported:
For Requests: Level 2
For Responses: Level 2
Device Function:
□ Master
⊠ Slave
Notable objects, functions, and/or qualifiers supported in addition to the Highest DNP Levels
Supported (the complete list is described in the attached table):
Binary Inputs (Object 1)
Binary Input Changes (Object 2)
Binary Outputs (Object 10)
Control Relay Output Block (Object 12)
Binary Counters (Object 20)
Frozen Counters (Object 21)
Counter Change Event (Object 22)
Frozen Counter Event (Object 23)
Analog Inputs (Object 30)
Analog Input Changes (Object 32)
Analog Deadbands (Object 34)
Time and Date (Object 50)
Internal Indications (Object 80)
Maximum Data Link Frame Size (octets):Maximum Application Fragment Size (octets):
Transmitted: 292Transmitted: configurable up to 2048
Received: 292Received: 2048
Maximum Data Link Re-tries:Maximum Application Layer Re-tries:
⊠None⊠ None
□Fixed at 3□ Configurable
□Configurable
Requires Data Link Layer Confirmation:
⊠ Never
□ Always
□ Sometimes
□ Configurable
Requires Application Layer Confirmation:
□ Never
□ Always
⊠ When reporting Event Data
⊠ When sending multi-fragment responses
□ Sometimes
□ Configurable
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–39
Page 44
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
DNP 3.0 Device Profile
Timeouts while waiting for:
Data Link Confirm:⊠ None □ Fixed □ Variable □ Configurable
Complete Appl. Fragment:⊠ None □ Fixed □ Variable □ Conf igurable
Application Confirm:□ None ⊠ Fixed at 10 s □ Variable □ Conf igurable
Complete Appl. Response: ⊠ None □ Fixed at ___ □ Variable □ Configurable
Others:
Transmission Delay: No intentional delay
Need Time Interval: Configurable (default = 24 hrs.)
Select/Operate Arm Timeout: 10 s
Binary input change scanning period: 8 times per power system cycle
Analog input change scanning period: 500 ms
Counter change scanning period: 500 ms
Frozen counter event scanning period: 500 ms
Sends/Executes Control Operations:
WRITE Binary Outputs⊠ Never □ Always □ Sometimes □Conf igurable
SELECT/OPERATE□ Never ⊠ Always □ Sometimes □ Configurable
DIRECT OPERATE□ Never ⊠Always
□ Sometimes □ Configurable
DIRECT OPERATE – NO ACK□ Never ⊠ Always □ Sometimes □ Configurable
Count > 1⊠ Never □ Always □ Sometimes □ Configurable
Pulse On□ Never □ Always ⊠ Sometimes □ Configurable
Pulse Off□ Never □ Always ⊠ Sometimes □ Configurable
Latch On□ Never □ Always ⊠ Sometimes □ Configurable
Latch Off□ Never □ Always ⊠ Sometimes □ Configurable
Queue⊠ Never □ Always □ Sometimes □ Configurable
Clear Queue⊠ Never □ Always □ Sometimes □ Configurable
Explanation of ‘Sometimes’: Object 12 points are mapped to Virtual Inputs. Both “Pulse On” and
“Latch On” operations perform the same function in the 345; that is, the appropriate Virtual Input is
put into the “On” state. The On/Off times and Count value are ignored. “Pulse Off” and “Latch Off”
operations put the appropriate Virtual Input into the “Off” state.
Reports Binary Input Change Events when no
specific variation requested:
Reports time-tagged Binary Input Change
Events when no specific variation
requested:
□ Never□ Never
⊠ Only time-tagged⊠ Binary Input Change With Time
□ Only non-time-tagged□ Binary Input Change With Relative Time
□ Configurable□ Configurable (attach explanation)
Sends Unsolicited Responses:Sends Static Data in Unsolicited Responses:
□ Never⊠ Never
□ Configurable□ When Device Restarts
□ Only certain objects□ When Status Flags Change
⊠ SometimesNo other options are permitted.
⊠ ENABLE/DISABLE unsolicited Function codes
supported
Explanation of ‘Sometimes’: It will be disabled for
RS-485 applications, since there is no collision
avoidance mechanism. For Ethernet communication
it will be available and it can be disabled or enabled
with the proper function code.
1–40345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 45
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
DNP 3.0 Device Profile
Default Counter Object/Variation:Counters Roll Over at:
□ No Counters Reported□ No Counters Reported
□ Configurable (attach explanation)□ Configurable (attach explanation)
⊠ Default Object: 20⊠ 16 Bits
Default Variation: 1
⊠ Point-by-point list attached□ Other Value: _____
⊠ Point-by-point list attached
Sends Multi-Fragment Responses:
⊠ Yes
□ No
DNP port allocation
Channel 1 Port Channel 2 Port DNP Availability
None None DNP not available over Ethernet port
None NETWORK-TCP One Master over TCP
None NETWORK-UDP "Various" Masters over UDP
NETWORK-TCP None One Master over TCP
NETWORK-TCP NETWORK-TCP Two Masters over TCP
NETWORK-TCP NETWORK-UDP One Master over TCP and "various" Masters over UDP
NETWORK-UDP None "Various" Masters over UDP
NETWORK-UDP NETWORK-TCP "Various" Masters over UDP and one Master over TCP
NETWORK-UDP NETWORK-UDP "Various" Masters over UDP
The DNP Eth Channel 1 Port and DNP Eth Channel 2 Port settings select the
communications port assigned to the DNP protocol for each Ethernet channel. When this
setting is set to "Network-TCP" the DNP protocol can be used over TCP/IP channels 1 or 2.
When this value is set to "Network-UDP" the DNP protocol can be used over UDP/IP on one
channel only.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–41
Page 46
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
DNP implementationTable 16: DNP Implementation
OBJECT REQUEST RESPONSE
OBJECT
NO.
1 0 Binary Input (Variation 0
2 0 Binary Input Change
10 0 Binary Output Status
12 1 Control Relay Output
20 0 Binary Counter
VARIATION
NO.
1 Binary Input 1 (read) 22
2 Binary Input with Status 1 (read) 22
1 Binary Input Change
2 Binary Input Change
3 Binary Input Change
2 Binary Output Status 1 (read) 00, 01 (start-stop)
DESCRIPTIONFUNCTION
is used to request
default variation)
(Variation 0 is used to
request default
variation)
without Time
with Time
with Relative Time
(Variation 0 is used to
request default
variation)
Block
(Variation 0 is used to
request default
variation)
1.A default variation refers to the variation response when variation 0 is requested and/
13 (cold
restart)
14 (warm
restart)
23 (delay
meas.)
00 (start-stop)
(index =7)
--- --- ---
--- --- ---
--- --- ---
129
(response)
00, 01
(start-stop)
--- ---
or in class 0, 1, 2, or 3 scans. The default variations for object types 1, 2, 20, 21, 22, 23,
30, and 32 are selected via relay settings. This optimizes the class 0 poll data size.
2.For static (non-change-event) objects, qualifiers 17 or 28 are only responded when a
request is sent with qualifiers 17 or 28, respectively. Otherwise, static object requests
sent with qualifiers 00, 01, 06, 07, or 08, will be responded with qualifiers 00 or 01 (for
changeevent objects, qualifiers 17 or 28 are always responded.)
3.Cold restarts are implemented the same as warm restarts – the 345 is not restarted,
but the DNP process is restarted.
1–46345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 51
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
DNP Ethernet
EnerVista Setup
NOTE:
Table 17: DNP protocol
SETTINGS PARAMETER RANGE FORMAT
DNP Channel 1 Port NONE NONE ; COM-RS485 ; NETWORK-
TCP ; NETWORK –UDP
DNP Channel 2 Port NONE NONE ; COM-RS485 ; NETWORK-
TCP ; NETWORK –UDP
DNP Address 65519 0 to 65519 F1
DNP Client Address 1 0. 0. 0. 0 F150
DNP Client Address 2 0. 0. 0. 0 F150
DNP Client Address 3 0. 0. 0. 0 F150
DNP Client Address 4 0. 0. 0. 0 F150
DNP Client Address 5 0. 0. 0. 0 F150
DNP TCP/UDP Port Number 20000 0 to 65535 F1
DNP Unsol Resp Function Disabled Disabled ; Enabled F126
DNP Unsol Resp Timeout 5 s 0 to 60 s F1
DNP Unsol Resp Max Retries 10 1 to 255 F1
DNP Unsol Resp Dest Addr 1 0 to 65519 F1
DNP Time Sync IIN Period 1440 min 1 to 10080 min F1
The setting DNP Unsolicited Response Timeout affects DNP TCP clients only; not serial
and UDP clients. Possible values that can be selected for this setting lie between 0 and 60
seconds.
In addition to this selected timeout, up to an additional 10 seconds is required to send
the response packet.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–47
Page 52
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
NOTE
Table 18: DNP point list
SETTINGS PARAMETER RANGE FORMAT
Binary Input Point 0 Entry Select entry
from a list
Operands F134
Binary Input Point 63 Entry Select entry
Analog Input Point 0 Entry Select entry
Analog Input Point 0 Scale Factor 1 0.001 ; 0.01 ; 0.1 ; 1 ; 10 ; 100 ;
Analog Input Point 0 Deadband 30000 0 to 100000000 F9
Analog Input Point 31 Entry Select entry
Analog Input Point 31 Scale
Factor
Analog Input Point 31 Deadband 30000 0 to 100000000 F9
Binary Output Point 0 ON Select entry
Binary Output Point 0 OFF Select entry
Binary Output Point 15 ON Select entry
Binary Output Point 15 OFF Select entry
from a list
from a list
from a list
1 0.001 ; 0.01 ; 0.1 ; 1 ; 10 ; 100 ;
from a list
from a list
from a list
from a list
Operands F134
Analog parameters
1000 ; 10000 ; 100000
Analog parameters
1000 ; 10000 ; 100000
Virtual Input 1 to 32 and Force
Coils
Virtual Input 1 to 32 and Force
Coils
Virtual Input 1 to 32 and Force
Coils
Virtual Input 1 to 32 and Force
Coils
F85
F85
F86
F86
F86
F86
•The DNP Time Sync IIN Period setting determines how often the Need Time Internal
Indication (IIN) bit is set by the 345. Changing this time allows the 345 to indicate that
a time synchroniztion command is necessary more or less often
•Various settings have been included to configure Default Variation for the Binary
Inputs, Counters and Analog Inputs Objects. The default variation refers to the
variation response when variation 0 is requested, and/or in class 0, 1, 2, or 3 scans
•Up to 64 Binary Inputs and 32 Analog Input entries can be mapped to an item from a
list of 345 status events and metered values. Status events correspond to Funcion
Code 134B.
•Each Analog Input point Deadband and Scale Factor can be set individually instead of
setting a general deadband or scale for different metering groups. This will avoid scale
and deadband conflicts for different meterings of the same nature.
•Up to 16 Binary/Control Outputs can be configured by selecting a Virtual Input or
Command from a list of 32 Virtual Inputs and Commands (Force Coils). Some legacy
DNP implementations use a mapping of one DNP Binary Output to two physical or
virtual control points. In Order to configure Paired Control Points the source for states
ON and OFF should be set to different Virtual Inputs or Commands.
•The DNP Technical Committee recommends using contiguous point numbers, starting
at 0, for each data type, because some DNP3 Master implementations allocate
contiguous memory from point 0 to the last number for each data type.
NOTE:
Binary Inputs are inputs to the Master. Binary Outputs are outputs from the Master.
1–48345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 53
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
DNP generalDefault variations for Object 1, 2 , 20 , 21 , 22 , 23 , 30 and Object 32 will be set by settings
and returned for the object in a response when no specific variation is specified in a Master
request.
Any change in the state of any binary point causes the generation of an event, and
consequently, if configured, an unsolicited response, or it is returned when the Master asks
for it. The same behaviour will be seen when an analog value changes by more than its
configured deadband limit . There can be up to 3 Masters in total, but only one Serial
Master.
The following Default Classes will be fixed for the different blocks of data:
Binary Input Points Default Class = 1
Analog Input Point Default Class = 2
Counters Default Class = 3
Each Data Point Class can be changed by protocol function code 22 in volatile mode. If a
restart is performed, the new values will be lost.
DNP Object 34 points can be used to change deadband values from the default for each
individual DNP Analog Input point. These new deadbands will be maintained such that in
the case of a relay restart, the values are not lost.
Requests for Object 20 (Binary Counters), Object 21 (Frozen Counters), and Object 22
(Counter Change Events) must be accepted.
Function codes “Immediate Freeze”, “Freeze and Clear” etc. are accepted as well.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–49
Page 54
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
104 BINARY INPUTS
POINT 0
POINT 1
...
POINT 63
▼
S1 104 GENERAL
FUNCTION
CYCLIC DATA PERIOD
TCP CONN. TIMEOUT
TCP PORT
SLAVE ADDRESS
▼
897794.cdr
S1 104 POINT LIST
BINARY INPUTS
ANALOG INPUTS
BINARY OUTPUTS
S1 60870-5-104
GENERAL
CLIENT ADDRESS
POINT LIST
104 ANALOG INPUTS
POINT 0 ENTRY
POINT 0 SCALE FCTR
POINT 0 DEADBAND
...
POINT 31 ENTRY
POINT 31 SCALE FCTR
POINT 31 DEADBAND
▼
S1 104 CLIENT ADDRESS
CLIENT ADDRESS 1
CLIENT ADDRESS 2
...
CLIENT ADDRESS 5
▼
.
.
.
.
104 BINARY OUTPUTS
POINT 0 ON:
POINT 0 OFF:
...
POINT 15 ON:
POINT 15 OFF:
▼
.
.
.
.
IEC60870-5-104 protocol
IEC 60870-5-104
interoperability
This document is adapted from the IEC 60870-5-104 standard. For this section the boxes
indicate the following: ⊠ – used in the standard direction; □– not used.
IEC 60870-5-104 Interoperability Document
1.System or device:
□ System definition.
□ Controlling station definition (master).
⊠ Controlled station definition (slave).
2.Application layer:
3.Transmission mode for application data:
Mode 1 (least significant octet first), as defined in Clause 4.10 of IEC 60870-5-4, is used
exclusively in this companion standard.
4.Common address of ADSU:
⊠ Two octets.
5.Information object address:
⊠ Three octets.
⊠ Structured
⊠ Unstructured
6.Cause of transmission:
1–50345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 55
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
⊠ Two octets (with originator address). Originator address is set to zero if not used.
7.Maximum length of APDU.
253 in both directions (the maximum length is a fixed system parameter).
8.Selection of standard ASDUs.
For the following lists, the boxes indicate the following: ⊠ – used in standard direction;
□ – not used.
Process information in monitor direction:
Table 19: Process information in monitor direction
Number / description Mnemonic
⊠ <1> := Single-point information M_SP_NA_1
□ <3> := Double-point information M_DP_NA_1
□ <5> := Step position information M_ST_NA_1
□ <7> := Bitstring of 32 bits M_BO_NA_1
□ <9> := Measured value, normalized value M_ME_NA_1
⊠ <11> := Measured value, scaled value M_ME_NB_1
□ <13> := Measured value, short floating point value M_ME_NC_1
⊠ <15> := Integrated totals M_IT_NA_1
□ <20> := Packed single-point information with status change detection M_SP_NA_1
□ <21> := Measured value, normalized value without quantity descriptor M_ME_ND_1
⊠ <30> := Single-point information with time tag CP56Time2a M_SP_TB_1
□ <31> := Double-point information with time tag CP56Time2a M_DP_TB_1
□ <32> := Step position information with time tag CP56Time2a M_ST_TB_1
□ <33> := Bitstring of 32 bits with time tag CP56Time2a M_BO_TB_1
□ <34> := Measured value, normalized value with time tag CP56Time2a M_ME_TD_1
⊠ <35> := Measured value, scaled value with time tag CP56Time2a M_ME_TE_1
□ <36> := Measured value, short floating point value with time tag CP56Time2a M_ME_TF_1
⊠ <37> := Integrated totals with time tag CP56Time2a M_IT_TB_1
□ <38> := Event of protection equipment with time tag CP56Time2a M_EP_TD_1
□ <39> := Packed start events of protection equipment with time tag
CP56Time2a
□ <40> := Packed output circuit information of protection equipment with time
tag CP56Time2a
M_EP_TE_1
M_EP_TF_1
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–51
Either the ASDUs of the set <2>, <4>, <6>, <8>, <10>, <12>, <14>, <16>, <17>, <18>,
and <19> or of the set <30> to <40> are used.
Page 56
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Table 20: Process information in control direction
Number / description Mnemonic
⊠ <45> := Single command C_SC_NA_1
⊠ <46> := Double command C_DC_NA_1
□ <47> := Regulating step command C_RC_NA_1
□ <48> := Set point command, normalized value C_SE_NA_1
□ <49> := Set point command, scaled value C_SE_NB_1
□ <50> := Set point command, short floating point value C_SE_NC_1
□ <51> := Bitstring of 32 bits C_BO_NA_1
⊠ <58> := Single command with time tag CP56Time2a C_SC_TA_1
⊠ <59> := Double command with time tag CP56Time2a C_DC_TA_1
□ <60> := Regulating step command with time tag CP56Time2a C_RC_TA_1
□ <61> := Set point command, normalized value with time tag CP56Time2a C_SE_TA_1
□ <62> := Set point command, scaled value with time tag CP56Time2a C_SE_TB_1
□ <63> := Set point command, short floating point value with time tag
CP56Time2a
□ <64> := Bitstring of 32 bits with time tag CP56Time2a C_BO_TA_1
C_SE_TC_1
Either the ASDUs of the set <45> to <51> or of the set <58> to <64> are used.
Table 21: System information in monitor direction
Number / description Mnemonic
⊠ <70> := End of initialization M_EI_NA_1
Table 22: System information in control direction
Number / description Mnemonic
⊠ <100> := Interrogation command C_IC_NA_1
⊠ <101> := Counter interrogation command C_CI_NA_1
⊠ <102> := Read command C_RD_NA_1
⊠ <103> := Clock synchronization command (see Clause 7.6 in standard) C_CS_NA_1
⊠ <105> := Reset process command C_RP_NA_1
⊠ <107> := Test command with time tag CP56Time2a C_TS_TA_1
Table 23: Parameter in control direction
Number / description Mnemonic
□ <110> := Parameter of measured value, normalized value PE_ME_NA_1
⊠ <111> := Parameter of measured value, scaled value PE_ME_NB_1
□ <112> := Parameter of measured value, short floating point value PE_ME_NC_1
□ <113> := Parameter activation PE_AC_NA_1
1–52345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 57
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
Type identifier and cause of transmission assignments (station-specific parameters)
are shown in the following tables. In these tables, shaded boxes (░) are not required,
black boxes (█) are not permitted in the companion standard, empty cells indicate the
functions or ASDU are not used, and a cross (╳) indicates availability only in the
standard direction.
14. Double transmission of information objects with cause of transmission spontaneous:
The following type identifications may be transmitted in succession caused by a single
status change of an information object. The particular information object addresses
for which double transmission is enabled are defined in a project-specific list.
□ Single point information: M_SP_NA_1, M_SP_TA_1, M_SP_TB_1, and M_PS_NA_1.
□ Double point information: M_DP_NA_1, M_DP_TA_1, and M_DP_TB_1.
□ Step position information: M_ST_NA_1, M_ST_TA_1, and M_ST_TB_1.
□ Bitstring of 32 bits: M_BO_NA_1, M_BO_TA_1, and M_BO_TB_1 (if defined for a
specific project).
□ Measured value, normalized value: M_ME_NA_1, M_ME_TA_1, M_ME_ND_1, and
M_ME_TD_1.
□ Measured value, scaled value: M_ME_NB_1, M_ME_TB_1, and M_ME_TE_1.
□ Measured value, short floating point number: M_ME_NC_1, M_ME_TC_1, and
M_ME_TF_1.
15. Station interrogation:
⊠ Group 1.
⊠ Group 2.
⊠ Group 3.
⊠ Group 4.
⊠ Group 5.
⊠ Group 6.
⊠ Group 7.
⊠ Group 8.
⊠ Group 9.
⊠ Group 10.
⊠ Group 11.
⊠ Group 12.
⊠ Group 13.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–55
Page 60
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
⊠ Group 14.
⊠ Group 15.
⊠ Group 16.
⊠ Global.
16. Clock synchronization:
⊠ Clock synchronization (optional, see Clause 7.6).
□ Day of week used.
□ RESI, GEN (time tag substituted/not substituted)
□ SU-bit (summertime) used.
17. Command transmission:
⊠ Direct command transmission.
□ Direct setpoint command transmission.
⊠ Select and execute command.
□ Select and execute setpoint command.
⊠ C_SE ACTTERM used.
⊠ No additional definition.
⊠ Short pulse duration (duration determined by a system parameter in the
outstation).
⊠ Long pulse duration (duration determined by a system parameter in the
outstation).
⊠ Persistent output.
⊠ Supervision of maximum delay in command direction of commands and setpoint
commands.
Maximum allowable delay of commands and setpoint commands: 5 s.
18. Transmission of integrated totals:
⊠ Mode A: Local freeze with spontaneous transmission.
⊠ Mode B: Local freeze with counter interrogation.
⊠ Mode C: Freeze and transmit by counter-interrogation commands.
⊠ Mode D: Freeze by counter-interrogation command, frozen values reported
simultaneously.
⊠ Counter read.
⊠ Counter freeze without reset.
⊠ Counter freeze with reset.
⊠ Counter reset.
⊠ General request counter.
⊠ Request counter group 1.
⊠ Request counter group 2.
⊠ Request counter group 3.
⊠ Request counter group 4.
19. Parameter loading:
⊠ Threshold value.
□ Smoothing factor.
□ Low limit for transmission of measured values.
□ High limit for transmission of measured values.
20. Parameter activation:
□ Activation/deactivation of persistent cyclic or periodic transmission of the
addressed object.
21. Test procedure:
1–56345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 61
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
□ Test procedure.
22. File transfer in monitor direction:
□ Transparent file.
□ Transmission of disturbance data of protection equipment.
□ Transmission of sequences of events.
□ Transmission of sequences of recorded analog values.
23. File transfer in control direction:
□ Transparent file.
24. Background scan:
□ Background scan.
25. Definition of timeouts:
Parameter Default value Remarks Selected value
t
0
t
1
t
2
t
3
30 s Timeout of connection establishment Configurable
15 s Timeout of send or test APDUs 15 s
10 s Timeout for acknowledgements in case of no
data messages t
20 s Timeout for sending test frames in case of a
long idle state
< t
2
1
10 s
20 s
Maximum range of values for all time outs: 1 to 255 s, accuracy 1 s.
26. Maximum number of outstanding I-format APDUs (k) and latest acknowledge APDUs
(w):
Parameter Default value Remarks Selected value
k 12 APDUs Maximum difference receive sequence number
w 8 APDUs Latest acknowledge after receiving w I-format
Maximum range of values k: 1 to 32767 (2
to send state variable
APDUs
15
– 1) APDUs, accuracy 1 APDU.
12 APDUs
8 APDUs
Maximum range of values w: 1 to 32767 APDUs, accuracy 1 APDU.
Recommendation: w should not exceed two-thirds of k.
27. Port number:
Parameter Value Remarks
Port number 2404 In all cases
28. RFC 2200 suite:
RFC 2200 is an official Internet Standard which describes the state of standardization
of protocols used in the Internet as determined by the Internet Architecture Board
(IAB). It offers a broad spectrum of actual standards used in the Internet. The suitable
selection of documents from RFC 2200 defined in this standard for given projects has
to be chosen by the user of this standard.
⊠ Ethernet 802.3.
□ Serial X.21 interface.
□ Other selection(s) from RFC 2200 (list below if selected).
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–57
Page 62
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
NOTE
IEC 60870-5-104
protocol settings
NOTE:
Select the Settings > Communications > IEC 60870-5-104 > Protocol menu item to open
the IEC 60870-5-104 protocol configuration window.
Settings Range Default
GENERAL
IEC 60870-5-104 Function Disabled, Enabled Disabled
IEC TCP Port 1 to 65535 2404
IEC Common Address of ASDU 0 to 65535 0
IEC Cyclic Data Period 0 to 65535 s 60 s
IEC TCP Connection Timeout 10 to 300 s 120 s
CLIENT ADDRESS
Client Address 1* 0.0.0.0
Client Address 2* 0.0.0.0
Client Address 3* 0.0.0.0
Client Address 4* 0.0.0.0
Client Address 5* 0.0.0.0
The Client Address setpoints marked "*" are shared with DNP, as only one protocol can be
active at a time.
The 345 can be used as an IEC 60870-5-104 slave device connected to a maximum of two
masters (usually either an RTU or a SCADA master station). Since the 345 maintains two
sets of IEC 60870-5-104 data change buffers, no more than two masters should actively
communicate with the 345 at one time. Five client address settings are used to filter which
master is suitable for communicating with 345.
The IEC 60870-5-104 and DNP protocols cannot be used simultaneously. When the IEC
60870-5-104 FUNCTION setting is set to “Enabled”, the DNP protocol will not be
operational.
If IEC Cyclic Data Period is set to 0 there will be no cyclic data response.
Some other settings can be added to select the first address of the different Object
Information. These settings can be removed to be consistent with the UR but are very
useful for integrating the relay into a system.
Settings Range Default
Object Information Address Binary 1 to 16777215 1000
Object Information Address Analog 1 to 16777215 2000
Object Information Address Counters 1 to 16777215 3000
Object Information Address Command 1 to 16777215 4000
By default, the Object Information Address for the different data will be as follows:
The Single Points (M_SP) can be configured to a maximum of 64 points. The value for each
point is user-programmable and can be configured by assigning FlexLogic™ operands.
Up to 32 Measured values (M_ME) can be configured assigning FlexAnalog parameters to
each data point.
The Commands points (C_SC or C_DC) can be configured to a maximum of 16 points
selecting data from a list of Virtual Inputs and Force Coil commands.
The table below shows all the Configurable Points settings:
1–58345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 63
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
NOTE
SettingsRangeDefault
Binary Input Point 0 Entry*FlexLogic Operands0
Binary Input Point 63 Entry*FlexLogic Operands0
Analog Input Point 0 Entry*0 to 280
Analog Input Point 0 Scale Factor*0.001, 0.01, 0.1, 1, 10, 100, 1000, 10000,
Analog Input Point 0 Deadband*0 to 10000000030000
Analog Input Point 31 Entry*0 to 280
Analog Input Point 31 Scale Factor*0.001, 0.01, 0.1, 1, 10, 100, 1000, 10000,
Analog Input Point 31 Deadband*0 to 10000000030000
Binary Output Point 0 ON*Virtual Input 1 to 32 and Force Coils0
Binary Output Point 0 OFF*Virtual Input 1 to 32 and Force Coils0
Binary Output Point 15 ON*Virtual Input 1 to 32 and Force Coils0
Binary Output Point 15 OFF*Virtual Input 1 to 32 and Force Coils0
NOTE:
The settings marked "*" are the same as those used by the DNP 3.0 protocol to configure
100000
100000
1
1
the point mapping from address 43878 to 44101.
The IEC 60870-5-104 Deadbands settings are used to determine when to trigger
spontaneous responses containing M_ME_NB_1 analog data. Each setting represents the
threshold value for each M_ME_NB_1 analog point.
For example, to trigger spontaneous responses from the 345 when a current value
changes by 15 A, the "Analog Point xx Deadband" setting should be set to 15. Note that
these settings are the default values of the deadbands. P_ME_NB_1 (parameter of
measured value, scaled value) points can be used to change threshold values from the
default, for each individual M_ME_NB_1 analog point.
There are three ways to send the measurands to the Master station. As the measurands
will be part of the General Group and Group 2, when a general interrogation or group 2
interrogation takes place, all the measurands will be included in the response. There is also
a cyclic data period setting where the scan period is configured to send the measurands to
the Master. The final way is to send the measurands spontaneously when a deadband
overflow takes place.
Groups of Data
The data will be organized in groups in order to provide values when the controlling station
requests by general or group interrogation.
Group 1 will be set by the 64 Single Points(M_SP).
Group 2 will be set by the 32 Measured values (M_ME).
These 64 Single Points and 32 Measured Values will also be sent as a response to a General
Interrogation.
Integrated Totals (M_IT) will have its own Counter Group 1 and these will be sent as a
response to a General Request Counter
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–59
Page 64
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Summary of Ethernet client connections
Table 27: Case A
Settings Ethernet
DNP CHANNEL 1 PORT NONE
DNP CHANNEL 2 PORT NONE
104 GENERAL FUNCTION DISABLE
Client 1 Client 2 Client 3
MODBUS NOTHING NOTHING
MODBUS MODBUS NOTHING
MODBUS MODBUS MODBUS
Table 28: Case B
Settings Ethernet
DNP CHANNEL 1 PORT TCP
DNP CHANNEL 2 PORT NONE
104 GENERAL FUNCTION DISABLE
Client 1 Client 2 Client 3
DNP NOTHING NOTHING
DNP MODBUS NOTHING
DNP MODBUS MODBUS
Table 29: Case C
Settings Ethernet
DNP CHANNEL 1 PORT UDP
DNP CHANNEL 2 PORT NONE
104 GENERAL FUNCTION DISABLE
Client 1 Client 2 Client 3 Client 4
DNP NOTHING NOTHING NOTHING
DNP MODBUS NOTHING NOTHING
DNP MODBUS MODBUS NOTHING
DNP MODBUS MODBUS MODBUS
Table 30: Case D
Settings Ethernet
DNP CHANNEL 1 PORT TCP
DNP CHANNEL 2 PORT TCP
104 GENERAL FUNCTION DISABLE
Client 1 Client 2 Client 3
DNP DNP NOTHING
DNP DNP MODBUS
1–60345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 65
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
Table 31: Case E
Settings Ethernet
DNP CHANNEL 1 PORT TCP
DNP CHANNEL 2 PORT UDP
104 GENERAL FUNCTION DISABLE
Client 1 Client 2 Client 3 Client 4
DNP-TCP DNP-UDP NOTHING NOTHING
DNP-TCP DNP-UDP MODBUS NOTHING
DNP-TCP DNP-UDP MODBUS MODBUS
Table 32: Case F
Settings Ethernet
DNP CHANNEL 1 PORT XX (any
DNP CHANNEL 2 PORT XX (any
104 GENERAL FUNCTION ENABLE
value)
value)
Client 1 Client 2 Client 3
IEC104 IEC104 NOTHING
IEC104 IEC104 MODBUS
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–61
Page 66
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
IEC 61850 GOOSE communications
The 345 firmware supports IEC61850 GOOSE communications on the optional
communications daughter board.
Portions of the IEC61850 standard not pertaining to GOOSE, are not implemented in the
345 relay.
The 345 relay does not support
•an IEC61850 MMS server
•the mapping of analogue values to data points in data sets in either the transmit or
receive direction
•a file system to maintain SCL, ICD or CID files, for IEC61850 GOOSE. As such the
implementation stores GOOSE configuration using MODBUS set points.
Configuration of transmission and reception settings for the GOOSE feature are performed
using EnerVista SR3 Setup Software.
The 345 firmware accepts GOOSE messages from UR, F650 and UR Plus. The
interoperability with other manufacturers will be guaranteed in almost all cases, by
implementing the reception side with nested structures (one level of nesting) and all the
standard data types.
GOOSE settings changes will take effect only after the 345 relay is re-booted. One setting is
available to Enable/Disable both Transmission and Reception. It is possible to change this
setting from the Front Panel of the relay.
Figure 1: EnerVista SR3 GOOSE General Settings
EnerVista SR3 Setup
software structure
1–62345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
The structure below reflects how the EnerVista SR3 Setup software should be used to
implement the sections detailed in this document , in order to enable both transmission
and reception of GOOSE messages.
Page 67
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–63
Page 68
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
GOOSE transmissionThe 345 firmware supports one transmission dataset.
All elements in the transmit dataset must be Booleans values.
The user can define the number of items in the transmit data setup, to a maximum of 32.
The minimum number of items in a data set is 1.
The number of data items configured before the NULL (below), determines the dataset
length. It is also possible to map any Item to a fixed value (ON or OFF).
For GOOSE transmission the firmware allows users to assign, (through EnerVista SR3
Setup Software) an DataSetReference composed as follows:
1.IEDNameLDInst/LLN0$
2.the string (default: GOOSE1) contained in the Modbus address:
eDataSetName 44671 123E DATASET NAME
The IEDName is taken from setting S1 Relay Setup > Installation > Relay Name
Setting the IEDName to "Feeder_25Kv_Line1" (for example) would result in a DataSet
Reference:
Feeder_25Kv_Line1LDInts/LLN0$GOOSE1
Another, less common, possibility is to change the 123E setting ( using modbus ) for
example to "GOOSE_Points" resulting in a DataSet Reference:
Feeder_25Kv_Line1LDInts/LLN0$GOOSE_Points
Figure 2: EnerVista SR3 GOOSE Transmission page
1–64345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 69
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
•GOOSE ID: A string of up to 40 characters that represent the IEC 61850 GOOSE
application ID (GoID). This string identifies the GOOSE Tx message to the receiving
device.
•VLAN Identifier/Priority: a two-byte value whose 3 most significant bits define the
user priority and the twelve least significant bits are for the VLAN identifier. I.e. 32768.
•ETYPE AppID ): to select ISO/IEC 8802-3 frames containing GSE Management and
GOOSE messages and to distinguish the application association.
•Update Time: time to delay transmission of the next iteration of a particular GOOSE
message if no value within the message has changed. I.e. 60. Measured in ms.
•Conf Revision Number: This number updates automatically after Tx data set has been
modified and the relay power has been cycled.
•Destination MAC Address: This setting is required to ensuring interoperability as some
vendors require valid range of destination MAC addresses in GOOSE messages.
•Quality Flags: In order to ensure interoperability with some vendors, it has been
added a quality flag associated to a data item. The quality flags item only can be set if
its associated data item is selected. The data type of the quality flags is Bitstring13
and the attribute will always set to value “0” at the protocol level.
All the elements in a dataset can be mapped by the user to any available digital value
within the 345 relay, including:
•Alarm elements
•Protection elements (Pickup, Dropout and Operate of all available protection elements)
•Control element (all available control elements)
•Status of digital inputs
•Status of digital outputs
•Status of virtual inputs
•Status of virtual outputs.
The destination multicast address for GOOSE messages is composed of the MAC address
of the device, with the least significant bit in the most significant byte, set to 1.
The 345 relay does not generate ICD files that describe the format of transmitted GOOSE
items. EnerVista SR3 software is used to generate these files, and the files must contain at
least the following information:
•Mandatory Nodes: LLN0, LPHD, GGIO, etc.
•GOOSE Configuration: Control Block, Dataset, etc.
•Dataset configuration.
Once a GOOSE message is transmitted, it will be retransmitted at an increasing time
interval as follows: 4ms, 8ms, 16ms, and then 1 second.
GOOSE RxThe 345 firmware allows the user to configure up to 8 separate GOOSE messages for
reception. One GOOSE message consists of 2 parts: Header and Dataset. The Header is
used for identification and the Dataset for data handling.
At this point , it is convenient to clarify the difference between Remote GOOSE and Remote
Device. One Remote Device can send more than one GOOSE, so from the reception point of
view, it is not very useful to handle Remote Devices. Instead, it is simpler to deal with
Remote GOOSE messages.
The 345 firmware is able to receive up to a total of 8 remote GOOSE messages transmitted
from up to a maximum of 8 remote devices.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–65
Page 70
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
GOOSE Rx statusIn order to visualize the status of the incoming GOOSE messages, the following status
registers must be available in the MODBUS memory map:
Data Item SR3 Text MMI Text Value Format
eDataRemoteGOOSEStat
us
eDataRemoteGOOSEHea
derStatus
GOOSE 1 0x0000 0001
GOOSE 2 0x0000 0010
GOOSE 3 0x0000 0100
GOOSE 4 0x0000 1000
GOOSE 5 0x0001 0000
GOOSE 6 0x0010 0000
GOOSE 7 0x0100 0000
GOOSE 8 0x1000 0000
EnumFC215 0x0001 eFMT_GOOSE1 GOOSE 1 RECEIVED
Remote
GOOSE Status
Remote
GOOSE
Header
Status
unsigned 32 bits GOOSE Receive Status Text String
0x0002 eFMT_GOOSE2 GOOSE 2 RECEIVED
0x0004 eFMT_GOOSE3 GOOSE 3 RECEIVED
0x0008 eFMT_GOOSE4 GOOSE 4 RECEIVED
0x0010 eFMT_GOOSE5 GOOSE 5 RECEIVED
0x0020 eFMT_GOOSE6 GOOSE 6 RECEIVED
0x0040 eFMT_GOOSE7 GOOSE 7 RECEIVED
0x0080 eFMT_GOOSE8 GOOSE 8 RECEIVED
REM GOOSE
STAT
REM GOOSE
HDR STAT
0xFFFF
FFFF
0xFFFF
FFFF
Code
FC215 2
FC215 2
Size
in
word
s
Modb
us
Addre
ss
31515
31517
The GOOSE Header Status is set at 1 if all the header’s filters are passed. Otherwise, the
Header Status will be set at 0.
After a GOOSE header is accepted, the 345 firmware either accepts or rejects the
associated dataset. The firmware bases this decision on the R
configured for the header. If both (Header and Dataset structure) are accepted, the Remote
GOOSE Status is set to 1, otherwise it is set to 0. If the header status is never set to 1, then
the associated GOOSE status always remains at 0.
The incoming GOOSE defines the timeout for the next message. GOOSE Header Status is
set to 0 if the next message is not received within the specified amount of time. GOOSE
Status is also set to 0 if the next message is not accepted within the specified amount of
time.
If a GOOSE message is received, and its header has not been configured for reception, the
firmware ignores the message.
It is possible to see this GOOSE status information from the 345 relay front panel.
1–66345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
dataset that has been
X
Page 71
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
Figure 3: EnerVista SR3 GOOSE Status page
GOOSE Rx headersThe 345 firmware supports GOOSE messages that contain up to one level of nesting, and
that are capable of mapping only digital values to the remote inputs.
The 345 firmware maintains the format of GOOSE messages that can be received in
MODBUS registers.
Configuration of GOOSE messages to be received by the device, is implemented using the
EnerVista SR3 Setup software, as shown below, either by reading in and parsing the ICD, or
SCD file from a remote device, or by manually conf iguring the settings.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–67
Page 72
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Figure 4: EnerVista SR3 GOOSE Rx Header
GOOSE receive
dataset structure
The format of the GOOSE messages that can be accepted by the firmware is stored in
MODBUS registers. The maximum total storage size for the 8 Rx GOOSE structure is 250
registers. This means that the number of elements per Rx GOOSE is unlimited provided that
the total size of all Rx structures doesn’t exceed the defined limit of 250 registers.
The User can configure the Datasets of his choice, and if he exceeds the 250 registers limit
when he tries to SAVE, the following message appears, saying that the selection of the user
has exceeded the limit of 250 registers and that anything beyond will be lost.
Clicking on YES will save Dataset items selection up to 250 registers and the others will be
lost. The screen then refreshes, reflecting the saved data. Clicking on NO will do nothing
and the user can make changes on the screen (shown below).
The RX GOOSE message data types that are handled by the software, are:
1–68345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
GOOSE remote inputsThe firmware allows the user to map each of the digital data points received in a data set,
configured for reception, to one of 32 GOOSE remote inputs.
More than 1 GOOSE remote input can be mapped to the same data element, in a data set
belonging to a received GOOSE message.
GOOSE remote inputs can only be mapped to digital data elements.
The firmware considers a GOOSE remote input to be in the “on/off” state when the digital
data element to which it is mapped, is in the “on/off” state.
The firmware allows the user to assign a string name to each of the 32 remote inputs, and
allows the string name assigned to each remote input to be between 1 and 32 characters.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–69
Page 74
ETHERNET INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
Figure 6: EnerVista SR3 GOOSE Remote Inputs 1
Figure 7: EnerVista SR3 GOOSE Remote Inputs 2
1–70345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 75
CHAPTER 1: COMMUNICATIONS GUIDEETHERNET INTERFACE
The following format indicates the source of the GOOSE message:
The string name of each remote input is maintained in a set of MODBUS registers, where
each string name consumes up to 16 MODBUS registers.
Each GOOSE remote input can be mapped to one of the following functions:
•protection element block (all protection elements that have a single or multiple block
setting)
•group setting change
•user assignable LED
•digital output
The 345 records changes in GOOSE remote inputs in the Event Log.
The time recorded in a GOOSE remote input’s event log entry, is the time at which the
change in the input’s state is detected.
The 345 invokes a logic (block / control) function when its corresponding GOOSE remote
input is asserted.
In the 345 there are many different settings where it is possible to select between a
Contact Input (1 to 8 ), a Virtual Input (1 to 32 ) or a Logic Element (1 to 8 ). In all of these
settings it is also possible to select Remote Input (1-32 ) if the GOOSE feature is enabled on
the relay.
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–71
Page 76
USB INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
USB interface
The USB inferface supports only the Modbus protocol.
For information on using the USB port on the 345 relay, please refer to Chapter 3 of the 345
Instruction Manual.
MODBUS Protocol
The 345 implements a subset of the Modicon Modbus RTU serial communication standard.
The Modbus protocol is hardware-independent. That is, the physical layer can be any of a
variety of standard hardware configurations. This includes USB, RS485, fibre optics, etc.
Modbus is a single master / multiple slave type of protocol suitable for a multi-drop
configuration.
The 345 is always a Modbus slave. It can not be programmed as a Modbus master.
Computers or PLCs are commonly programmed as masters.
Both monitoring and control are possible using read and write register commands. Other
commands are supported to provide additional functions.
The Modbus protocol has the following characteristics.
One data frame of an asynchronous transmission to or from a 345 typically consists of 1
start bit, 8 data bits, and 1 stop bit . This produces a 10 bit data frame. This is important for
transmission through modems at high bit rates.
Modbus protocol can be implemented at any standard communication speed. The 345
supports operation at 9600, 19200, 38400, 57600, and 115200 baud.
Data Packet FormatA complete request/response sequence consists of the following bytes (transmitted as
separate data frames):
Master Request Transmission:
SLAVE ADDRESS: 1 byte
FUNCTION CODE: 1 byte
DATA: variable number of bytes depending on FUNCTION CODE
CRC: 2 bytes
Slave Response Transmission:
SLAVE ADDRESS: 1 byte
FUNCTION CODE: 1 byte
DATA: variable number of bytes depending on FUNCTION CODE
CRC: 2 bytes
SLAVE ADDRESS: This is the first byte of every transmission. This byte represents the userassigned address of the slave device that is to receive the message sent by the master.
Each slave device must be assigned a unique address and only the addressed slave will
respond to a transmission that starts with its address. In a master request transmission the
SLAVE ADDRESS represents the address of the slave to which the request is being sent. In a
slave response transmission the SLAVE ADDRESS represents the address of the slave that is
sending the response.
FUNCTION CODE: This is the second byte of every transmission. Modbus defines function
codes of 1 to 127.
1–72345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE
Page 77
CHAPTER 1: COMMUNICATIONS GUIDEUSB INTERFACE
DATA: This will be a variable number of bytes depending on the FUNCTION CODE. This may
be Actual Values, Setpoints, or addresses sent by the master to the slave or by the slave to
the master.
CRC: This is a two byte error checking code.
Error CheckingThe RTU version of Modbus includes a two byte CRC-16 (16 bit cyclic redundancy check)
with every transmission. The CRC-16 algorithm essentially treats the entire data stream
(data bits only; start, stop and parity ignored) as one continuous binary number. This
number is first shifted left 16 bits and then divided by a characteristic polynomial
(11000000000000101B). The 16 bit remainder of the division is appended to the end of the
transmission, MSByte first. The resulting message including CRC, when divided by the
same polynomial at the receiver will give a zero remainder if no transmission errors have
occurred.
If a 345 Modbus slave device receives a transmission in which an error is indicated by the
CRC-16 calculation, the slave device will not respond to the transmission. A CRC-16 error
indicates than one or more bytes of the transmission were received incorrectly and thus
the entire transmission should be ignored in order to avoid the 345 performing any
incorrect operation.
The CRC-16 calculation is an industry standard method used for error detection. An
algorithm is included here to assist programmers in situations where no standard CRC-16
calculation routines are available.
CRC-16 AlgorithmOnce the following algorithm is complete, the working register “A” will contain the CRC
value to be transmitted. Note that this algorithm requires the characteristic polynomial to
be reverse bit ordered. The MSBit of the characteristic polynomial is dropped since it does
not affect the value of the remainder. The following symbols are used in the algorithm:
—>: data transfer
A: 16 bit working register
AL: low order byte of A
AH: high order byte of A
CRC: 16 bit CRC-16 value
i, j: loop counters
(+): logical exclusive or operator
Di: i-th data byte (i = 0 to N-1)
G: 16 bit characteristic polynomial = 1010000000000001 with MSbit dropped and bit order
reversed
shr(x): shift right (the LSbit of the low order byte of x shifts into a carry flag, a '0' is shifted
into the MSbit of the high order byte of x, all other bits shift right one location
The algorithm is:
1. FFFF hex —> A
2. 0 —> i
3. 0 —> j
345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE1–73
4. Di (+) AL —> AL
5. j+1 —> j
6. shr(A)
7. is there a carry? No: go to 8. Yes: G (+) A —> A
8. is j = 8? No: go to 5. Yes: go to 9.
Page 78
USB INTERFACECHAPTER 1: COMMUNICATIONS GUIDE
9. i+1 —> i
10. is i = N? No: go to 3. Yes: go to 11.
11. A —> CRC
TimingData packet synchronization is maintained by timing constraints. The receiving device
must measure the time between the reception of characters. If 3.5 character times elapse
without a new character or completion of the packet, then the communication link must
be reset (i.e. all slaves start listening for a new transmission from the master). Thus at 9600
baud a delay of greater than 3.5 x 1 / 9600 x 10 x = x 3.65 x ms will cause the
communication link to be reset.
345 supported
functions
The following functions are supported by the 345:
•FUNCTION CODE 03 - Read Setpoints
•FUNCTION CODE 04 - Read Actual Values
•FUNCTION CODE 05 - Execute Operation
•FUNCTION CODE 06 - Store Single Setpoint
•FUNCTION CODE 07 - Read Device Status
•FUNCTION CODE 08 - Loopback Test
•FUNCTION CODE 10 - Store Multiple Setpoints
Refer to section 5 of this guide for more details on MODBUS function codes.
1–74345 TRANSFORMER PROTECTION SYSTEM – COMMUNICATIONS GUIDE