indicates that death or severe personal injury will result if proper precautions are not taken.
WARNING
indicates that death or severe personal injury may result if proper precautions are not taken.
CAUTION
indicates that minor personal injury can result if proper precautions are not taken.
NOTICE
indicates that property damage can result if proper precautions are not taken.
Qualified Personnel
personnel qualified
Proper use of Siemens products
WARNING
Siemens products may only be used for the applications described in the catalog and in the relevant technical
maintenance are required to ensure that the products operate safely and without any problems. The permissible
ambient conditions must be complied with. The information in the relevant documentation must be observed.
Trademarks
Disclaimer of Liability
This manual contains notices you have to observe in order to ensure your personal safety, as well as to prevent
damage to property. The notices referring to your personal safety are highlighted in the manual by a safety alert
symbol, notices referring only to property damage have no safety alert symbol. These notices shown below are
graded according to the degree of danger.
If more than one degree of danger is present, the warning notice representing the highest degree of danger will
be used. A notice warning of injury to persons with a safety alert symbol may also include a warning relating to
property damage.
The product/system described in this documentation may be operated only by
task in accordance with the relevant documentation, in particular its warning notices and safety instructions.
Qualified personnel are those who, based on their training and experience, are capable of identifying risks and
avoiding potential hazards when working with these products/systems.
Note the following:
documentation. If products and components from other manufacturers are used, these must be recommended
or approved by Siemens. Proper transport, storage, installation, assembly, commissioning, operation and
All names identified by ® are registered trademarks of Siemens AG. The remaining trademarks in this publication
may be trademarks whose use by third parties for their own purposes could violate the rights of the owner.
We have reviewed the contents of this publication to ensure consistency with the hardware and software
described. Since variance cannot be precluded entirely, we cannot guarantee full consistency. However, the
information in this publication is reviewed regularly and any necessary corrections are included in subsequent
editions.
15 System expansion card ....................................................................................................................... 251
16 Technical data .................................................................................................................................... 253
17 Properties and technical specifications of CPU 410 SMART ................................................................ 283
12.9 Removal of components ....................................................................................................... 211
A.2 Comparison of MTBF for selected configurations ................................................................ 383
A.2.1 System configurations with redundant CPU 410 .................................................................. 383
A.2.2 System configurations with distributed I/Os .......................................................................... 384
A.2.3 Comparison of system configurations with standard and fault-tolerant communication ...... 388
C.1 MTA terminal modules (Marshalled Termination Assemblies) ............................................. 391
C.2 Interconnection of output modules ........................................................................................ 391
C.3 8-channel HART analog input MTA ...................................................................................... 393
C.4 8-channel HART analog output MTA .................................................................................... 394
C.5 SM 321; DI 16 x DC 24 V, 6ES7 321–1BH02–0AA0 ............................................................ 395
C.6 SM 321; DI 32 x DC 24 V, 6ES7 321–1BL00–0AA0 ............................................................. 396
C.7 SM 321; DI 16 x AC 120/230V, 6ES7 321–1FH00–0AA0 .................................................... 397
C.8 SM 321; DI 8 x AC 120/230 V, 6ES7 321–1FF01–0AA0 ...................................................... 398
C.9 SM 321; DI 16 x DC 24V, 6ES7 321–7BH00–0AB0 ............................................................. 399
C.10 SM 321; DI 16 x DC 24V, 6ES7 321–7BH01–0AB0 ............................................................. 400
C.11 SM 326; DO 10 x DC 24V/2A, 6ES7 326–2BF01–0AB0 ...................................................... 401
C.12 SM 326; DI 8 x NAMUR, 6ES7 326–1RF00–0AB0 ............................................................... 402
C.13 SM 326; DI 24 x DC 24 V, 6ES7 326–1BK00–0AB0 ............................................................ 403
C.14 SM 421; DI 32 x UC 120 V, 6ES7 421–1EL00–0AA0 ........................................................... 404
C.15 SM 421; DI 16 x DC 24 V, 6ES7 421–7BH01–0AB0 ............................................................ 405
C.16 SM 421; DI 32 x DC 24 V, 6ES7 421–1BL00–0AB0 ............................................................. 406
C.17 SM 421; DI 32 x DC 24 V, 6ES7 421–1BL01–0AB0 ............................................................. 407
C.18 SM 322; DO 8 x DC 24 V/2 A, 6ES7 322–1BF01–0AA0 ...................................................... 408
C.19 SM 322; DO 32 x DC 24 V/0,5 A, 6ES7 322–1BL00–0AA0 ................................................. 409
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
9
Page 10
Table of contents
Index ................................................................................................................................................... 429
Tables
C.20 SM 322; DO 8 x AC 230 V/2 A, 6ES7 322–1FF01–0AA0 .................................................... 410
C.21 SM 322; DO 4 x DC 24 V/10 mA [EEx ib], 6ES7 322–5SD00–0AB0 .................................. 411
C.22 SM 322; DO 4 x DC 15 V/20 mA [EEx ib], 6ES7 322–5RD00–0AB0 .................................. 412
C.23 SM 322; DO 8 x DC 24 V/0.5 A, 6ES7 322–8BF00–0AB0 .................................................. 413
C.24 SM 322; DO 16 x DC 24 V/0.5 A, 6ES7 322–8BH01–0AB0 ................................................ 414
C.25 SM 332; AO 8 x 12 Bit, 6ES7 332–5HF00–0AB0 ................................................................ 415
C.26 SM 332; AO 4 x 0/4...20 mA [EEx ib], 6ES7 332–5RD00–0AB0 ......................................... 416
C.27 SM 422; DO 16 x AC 120/230 V/2 A, 6ES7 422–1FH00–0AA0 .......................................... 417
C.28 SM 422; DO 32 x DC 24 V/0.5 A, 6ES7 422–7BL00–0AB0 ................................................ 418
C.29 SM 331; AI 4 x 15 Bit [EEx ib]; 6ES7 331–7RD00–0AB0 .................................................... 419
C.30 SM 331; AI 8 x 12 Bit, 6ES7 331–7KF02–0AB0 .................................................................. 420
C.31 SM 331; AI 8 x 16 Bit; 6ES7 331–7NF00–0AB0 .................................................................. 421
C.32 SM 331; AI 8 x 16 Bit; 6ES7 331–7NF10–0AB0 .................................................................. 422
C.33 AI 6xTC 16Bit iso, 6ES7331-7PE10-0AB0 .......................................................................... 423
C.34 SM331; AI 8 x 0/4...20mA HART, 6ES7 331-7TF01-0AB0 ................................................. 424
C.35 SM 332; AO 4 x 12 Bit; 6ES7 332–5HD01–0AB0 ................................................................ 426
C.36 SM332; AO 8 x 0/4...20mA HART, 6ES7 332-8TF01-0AB0 ................................................ 427
Table 3- 1 LED displays on the CPUs ........................................................................................................... 36
Table 3- 2 Possible states of the RUN and STOP LEDs .............................................................................. 41
Table 3- 3 Possible states of the MSTR, RACK0 and RACK1 LEDs ............................................................ 42
Table 3- 4 Possible states of the INTF and EXTF LEDs ............................................................................... 42
Table 3- 5 Possible states of the BUS1F, BUS5F, and BUS8F LEDs .......................................................... 42
Table 3- 6 Possible states of the IFM1F and IFM2F LEDs ........................................................................... 43
Table 3- 7 Possible states of the LINK and RX/TX LEDs ............................................................................. 43
Table 3- 8 Possible states of the REDF LED ................................................................................................ 43
Table 3- 9 Possible states of the LINK1 OK and LINK2 OK LEDs ............................................................... 44
Table 4- 1 Meaning of the "BUSF" LED of the CPU 410 as DP master ....................................................... 49
Table 6- 1 System modifications during operation ........................................................................................ 56
Table 6- 2 Measures in PROFIsafe for error avoidance ............................................................................... 60
Table 6- 3 Interface modules for use of single-channel switched I/O configuration at the PROFIBUS
Figure 18-4 S7 routing: TeleService application example ............................................................................. 315
Figure 18-5 Data set routing .......................................................................................................................... 316
Figure 18-6 Example of an S7 connection .................................................................................................... 322
Figure 18-7 Example that shows that the number of resulting partial connections depends on the con-
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
13
Page 14
Table of contents
Figure 18-24 Example of minimum signal duration of an input signal during the update ............................... 346
Figure 18-25 Redundant one-sided and switched I/O ..................................................................................... 354
Figure 18-26 Flow chart for OB 1 .................................................................................................................... 356
Figure 18-27 Elements and composition of the cycle time .............................................................................. 358
Figure 18-28 Formula: Influence of communication load ................................................................................ 362
Figure 18-29 Distribution of a time slice .......................................................................................................... 362
Figure 18-30 Dependency of the cycle time on communication load .............................................................. 363
Figure 18-31 DP cycle times on the PROFIBUS DP network ......................................................................... 365
Figure 18-32 Shortest response time .............................................................................................................. 366
Figure 18-33 Longest response time ............................................................................................................... 367
Figure C-1 Interconnection example for SM 331, Al 8 x 0/4...20mA HART ................................................. 393
Figure C-2 Interconnection example for SM 322, Al 8 x 0/4...20mA HART ................................................. 394
Figure C-3 Example of an interconnection with SM 321; DI 16 x DC 24 V.................................................. 395
Figure C-4 Example of an interconnection with SM 321; DI 32 x DC 24 V.................................................. 396
Figure C-5 Example of an interconnection with SM 321; DI 16 x AC 120/230 V ......................................... 397
Figure C-6 Example of an interconnection with SM 321; DI 8 x AC 120/230 V ........................................... 398
Figure C-7 Example of an interconnection with SM 321; DI 16 x DC 24V................................................... 399
Figure C-8 Example of an interconnection with SM 321; DI 16 x DC 24V................................................... 400
Figure C-9 Example of an interconnection with SM 326; DO 10 x DC 24V/2A ........................................... 401
Figure C-10 Example of an interconnection with SM 326; DI 8 x NAMUR .................................................... 402
Figure C-11 Example of an interconnection with SM 326; DI 24 x DC 24 V.................................................. 403
Figure C-12 Example of an interconnection with SM 421; DI 32 x UC 120 V................................................ 404
Figure C-13 Example of an interconnection with SM 421; DI 16 x 24 V ........................................................ 405
Figure C-14 Example of an interconnection with SM 421; DI 32 x 24 V ........................................................
406
Figure C-15 Example of an interconnection with SM 421; DI 32 x 24 V ........................................................ 407
Figure C-16 Example of an interconnection with SM 322; DO 8 x DC 24 V/2 A ........................................... 408
Figure C-17 Example of an interconnection with SM 322; DO 32 x DC 24 V/0.5 A ...................................... 409
Figure C-18 Example of an interconnection with SM 322; DO 8 x AC 230 V/2 A.......................................... 410
Figure C-19 Example of an interconnection with SM 322; DO 16 x DC 24 V/10 mA [EEx ib] ....................... 411
Figure C-20 Example of an interconnection with SM 322; DO 16 x DC 15 V/20 mA [EEx ib] ....................... 412
Figure C-21 Example of an interconnection with SM 322; DO 8 x DC 24 V/0.5 A ........................................ 413
Figure C-22 Example of an interconnection with SM 322; DO 16 x DC 24 V/0.5 A ...................................... 414
CPU 410 Process Automation/CPU 410 SMART
14System Manual, 05/2017, A5E31622160-AC
Page 15
Table of contents
Figure C-23 Example of an interconnection with SM 332, AO 8 x 12 Bit ...................................................... 415
Figure C-24 Example of an interconnection with SM 332; AO 4 x 0/4...20 mA [EEx ib] ............................... 416
Figure C-25 Example of an interconnection with SM 422; DO 16 x 120/230 V/2 A ...................................... 417
Figure C-26 Example of an interconnection with SM 422; DO 32 x DC 24 V/0.5 A ...................................... 418
Figure C-27 Example of an interconnection with SM 331, AI 4 x 15 Bit [EEx ib] ........................................... 419
Figure C-28 Example of an interconnection with SM 331; AI 8 x 12 Bit ........................................................ 420
Figure C-29 Example of an interconnection with SM 331; AI 8 x 16 Bit ........................................................ 421
Figure C-30 Example of an interconnection with SM 331; AI 8 x 16 Bit ........................................................ 422
Figure C-31 Example of an interconnection AI 6xTC 16Bit iso ...................................................................... 423
Figure C-32 Interconnection example 1 SM 331; AI 8 x 0/4...20mA HART ................................................... 424
Figure C-33 Interconnection example 2 SM 331; AI 8 x 0/4...20mA HART ................................................... 425
Figure C-34 Example of an interconnection with SM 332, AO 4 x 12 Bit ...................................................... 426
Figure C-35 Interconnection example 3 SM 332; AO 8 x 0/4...20mA HART ................................................. 427
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
15
Page 16
Table of contents
CPU 410 Process Automation/CPU 410 SMART
16System Manual, 05/2017, A5E31622160-AC
Page 17
1
1.1
Preface
Purpose of this manual
Changes compared with the previous version
Scope of the manual
The information in this manual enables you to look up operator inputs, function descriptions
and technical specifications of the CPU 410-5H Process Automation, CPU 410E Process
Automation and CPU 410 SMART.
For information on installing and wiring this and other modules in order to set up an
automation system, refer to Manual
Changes compared with the previous version of the SIMATIC PCS 7 Process Control
System CPU 410-5H Process Automation/CPU 410 SMART, 09/2014 edition
(A5E32631620-AB):
Automation System S7-400, Hardware and Installation
.
● CPU 410E has been added.
● The connection of redundant I/O via the PROFINET interface is described.
● The "Configuration changes during operation" functionality via the PROFINET interface is
● The "Configuration changes during redundant operation" functionality via the PROFINET
● The retentive load memory is described.
● A two-step firmware update procedure is described.
● Time synchronization for purposes of time stamping via PROFINET is described.
● The signaling of security events via SysLog is described.
The manual is relevant to the following components:
● CPU 410-5H Process Automation; 6ES7 410-5HX08-0AB0 as of Firmware Version V8.2
● CPU 410E Process Automation; 6ES7410-5HM08-0AB0 as of Firmware Version V8.2
● CPU 410 SMART; 6ES7 410-5HN08-0AB0 as of firmware version V8.2
described.
interface is described.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
17
Page 18
Preface
Note
CPU 410-5H and CPU 410E
Except for different technical specifications and quantity frameworks, the CPU 410E behaves
the same as a CPU 410
CPU 410 apply to both the CPU 410
Note
CPU 410 and CPU 410 SMART
Except for the special features described in the s
specifications of CPU 410 SMART
While taking this section into co
410 also apply to the CPU 410 SMART.
Basic knowledge required
Approvals
Online help
1.1 Preface
Use of the current version of PCS 7 or the engineering tools is only required if the current
CPU has new functions compared to the last firmware version and you want to use these
functions. The same applies when an old CPU is replaced by a CPU with current firmware: If
you do not want to use any properties beyond the scope of the replaced CPU, you can use
the CPU with the old article number and old firmware version when configuring in HW
Config.
-5H. For this reason, the statements made in this manual about a
-5H and the CPU 410E.
ection Properties and technical
(Page 283), CPU 410 SMART reacts like a CPU 410.
nsideration, the statements made in this manual about CPU
This manual requires general knowledge of automation engineering.
Knowledge of the use of computers or PC-like tools such as programming devices with a
Windows operating system is also required. The SIMATIC PCS 7 readme includes
information on which operating system is suitable for your SIMATIC PCS 7 configuration.
The CPU 410 is configured using the SIMATIC PCS 7 software, and you should therefore be
familiar with this software.
In particular when operating a CPU 410 in potentially explosive atmospheres, please always
observe the information on the safety of electronic control systems provided in the appendix
Automation System S7-400, Hardware and Installation
to the
For details on certifications and standards, refer to Manual
Module Data
specification for the entire S7-400.
You will need the SIMATIC PCS 7 Programming Package V9.0 or higher to work with CPU
410.
In addition to the manual, you will find detailed support on how to use the software in the
integrated online help system of the software.
manual.
S7-400 Automation System,
, section 1.1, Standards and Certifications. Here you will also find the technical
CPU 410 Process Automation/CPU 410 SMART
18System Manual, 05/2017, A5E31622160-AC
Page 19
Preface
Help
Contents
Configuring fault-tolerant systems
Using Help
Recycling and disposal
Additional support
Functional Safety Services
1.1 Preface
The help system can be accessed using various interfaces:
● The
help on fault-tolerant systems in
●
● The context-sensitive help system provides information on the current context, for
example, on an open dialog or active window. You can call this help by clicking "Help" or
using the F1 key.
● The status bar provides a further form of context-sensitive help. It shows a short
description of each menu command when you position the mouse pointer over a
command.
● A short info text is also shown for the toolbar buttons when you hold the mouse pointer
briefly over a button.
If you prefer to read the information of the online help in printed form, you can print individual
topics, books or the entire help system.
Because it is constructed from environmentally compatible materials, the CPU 410 can be
recycled. For ecologically compatible recycling and disposal of your old device, contact a
certificated disposal service for electronic scrap.
menu contains several commands:
provides detailed instructions on using the online help system.
opens the Help index. You will find
.
If you have any questions relating to the products described in this manual, and do not find
the answers in this documentation, please contact your Siemens partner at our local offices.
You can find the online catalog and order system under:
Catalog (http://mall.automation.siemens.com/)
Siemens Functional Safety Services is a comprehensive performance package that supports
you in risk assessment and verification all the way to plant commissioning and
modernization. We also offer consulting services for the application of fail-safe and faulttolerant SIMATIC S7 automation systems.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
19
Page 20
Preface
Training center
Technical Support
Service & Support on the Internet
1.2
Security information
1.2 Security information
We offer a range of relevant courses to help you to get started with the SIMATIC S7
automation system. Please contact your local training center or the central training center.
Training (http://www.sitrain.com/index_en.html)
For technical support of all Industry Automation products, fill in and submit the online
Support Request:
Support Request (http://www.siemens.de/automation/support-request)
In addition to our documentation, we offer a comprehensive online knowledge base on the
Internet at:
Service & Support (http://www.siemens.com/automation/service&support)
There you will find:
● The newsletter containing the latest information on your products.
● The latest documents via our search function in Service & Support.
● A forum for global information exchange by users and specialists.
● Your local Automation representative.
● Information on field service, repairs and spare parts. Much more can be found under
"Services".
Siemens provides products and solutions with industrial security functions that support the
secure operation of plants, systems, machines, and networks.
In order to protect plants, systems, machines and networks against cyber threats, it is
necessary to implement – and continuously maintain – a holistic, state-of-the-art industrial
security concept. Siemens’ products and solutions only form one element of such a concept.
Customer is responsible to prevent unauthorized access to its plants, systems, machines
and networks. Systems, machines and components should only be connected to the
enterprise network or the internet if and to the extent necessary and with appropriate security
measures (e.g. use of firewalls and network segmentation) in place.
Additionally, Siemens’ guidance on appropriate security measures should be taken into
account. For more information about industrial security, please visit:
http:/www.siemens.com/industrialsecurity.
Siemens’ products and solutions undergo continuous development to make them more
secure. Siemens strongly recommends to apply product updates as soon as available and to
always use the latest product versions. Use of product versions that are no longer supported,
and failure to apply latest updates may increase customer’s exposure to cyber threats.
CPU 410 Process Automation/CPU 410 SMART
20System Manual, 05/2017, A5E31622160-AC
Page 21
Preface
1.3
Documentation
User documentation
Topic
Documentation
See also
ns.com/WW/view/en/1117849)
ns.com/WW/view/en/1117740)
System
en)
ns.com/WW/view/en/22063748)
ns.com/WW/view/en/1142696)
en)
8/en)
1.3 Documentation
To stay informed about product updates, subscribe to the Siemens Industrial Security RSS
Feed under
http://www.siemens.com/industrialsecurity.
The table below provides an overview of the descriptions of the various components and
options in the S7-400 automation system.
Setting up an automation system
Data of the standard modules of
an automation system
IM 155-6 PN HA ET 200SP HA Distributed I/O
IM 152 ET 200iSP Distributed I/O Sys-
IM 153-2
IM 153-4 PN
IM 157
S7-400, Hardware and Installation
S7-400 Module Data SIMATIC S7-400 S7-400 Auto-
tem
ET 200M Distributed I/O Device SIMATIC ET 200M Distributed
DP/PA Link and Y Link Bus
Links
S7-400 Automation System
Hardware and Installation
(http://support.automation.sieme
mation System Module Data
(http://support.automation.sieme
SIMATIC Distributed I/O System
ET 200iSP
(https://support.industry.siemen
s.com/cs/ww/de/view/28930789/
I/O Device, HART Analog Modules
(http://support.automation.sieme
SIMATIC Bus Links DP/PA
Coupler, Active Field Distributors, DP/PA Link and Y Link
(http://support.automation.sieme
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
IM 153-2 FF FF Link Bus Links SIMATIC Bus Links - FF Link
Bus Link
(https://support.industry.siemen
s.com/cs/ww/de/view/47357205/
Compact FF Link Compact FF Link Bus Links SIMATIC Bus Link Compact FF
Link
(https://support.industry.siemen
s.com/cs/ww/de/view/10973957
21
Page 22
Preface
Topic
Documentation
See also
IO system
ns.com/WW/view/en/19292127)
0/en)
dok-pcs7/Seiten/Default.aspx)
ns.com/WW/view/en/18652631)
ns.com/WW/view/en/14044916)
1.3 Documentation
Configuring, commissioning,
and operation of a PROFINET
Fail-safe systems
Configuring and programming
fail-safe systems
Working with S7 F-Systems V
6.2
Solution concepts
Function mechanisms
Configurations of SIMATIC PCS
7
Configuring hardware Configuring Hardware and
System Modifications during
Stand-Alone Operation
PROFINET IO System Description
S7 F/FH Systems SIMATIC Industrial Software S7
SIMATIC PCS 7 Technical Documentation
Communication Connections
with STEP 7
Modifying the System during
Operation via CiR
PROFINET system description
(http://support.automation.sieme
F/FH Systems - Configuring and
Programming
(https://support.industry.siemen
s.com/cs/ww/de/view/10974210
SIMATIC PCS 7 Process Control System
(http://www.automation.siemenh
Configuring Hardware and
Communication Connections
with STEP 7
(http://support.automation.sieme
Modifying the System during
Operation via CiR
(http://support.automation.sieme
CPU 410 Process Automation/CPU 410 SMART
22System Manual, 05/2017, A5E31622160-AC
Page 23
2
2.1
Area of application of the CPU 410 in SIMATIC PCS 7
Purpose of redundant automation systems
Why use fault-tolerant automation systems?
In practice, redundant automation systems are used to achieve fault-tolerant or fail-safe
systems.
Figure 2-1 Purpose of redundant automation systems
Please note the difference between fail-tolerant and fail-safe
systems. The AS 410 H is a fault-tolerance automation system. You may only use it for
controlling safety-related processes if you program and configure it in accordance with the
rules for F systems. You can find information on this in following manual: SIMATIC Industrial
Software S7 F/FH Systems (http://support.automation.siemens.com/WW/view/en/2201072)
The purpose of fault-tolerance automation systems is to reduce production downtime caused
by faults or by maintenance work.
The greater the costs of downtime, the more worthwhile a fault-tolerant system. The costs of
investing in a fault-tolerant system are generally higher, but are rapidly recovered by the
avoidance of production downtime.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
23
Page 24
Introduction to the CPU 410
SIMATIC PCS 7 and CPU 410-5H Process Automation
The SIMATIC PCS 7 project
SIMATIC PCS 7 applications
2.1 Area of application of the CPU 410 in SIMATIC PCS 7
SIMATIC PCS 7 uses selected standard hardware and software components from the TIA
building block system for the process control system in the company-wide automation
network called Totally Integrated Automation. It offers an open basis for automation solutions
with its consistent data management, communication and configuration.
You can use SIMATIC PCS 7 to create customized and project-specific solutions tailored to
specific requirements. Further information about these customized solutions can be found in
the configuration manuals.
The CPU 410-5H Process Automation is a controller of the latest generation. This controller
is specifically designed for the SIMATIC PCS 7 control system. As with previous controllers
of the SIMATIC PCS 7 system, the CPU 410-5H Process Automation can be used in all
Process Automation industries. Highly flexible scalability based on SIMATIC PCS 7 process
objects makes it possible to cover the entire performance range from the smallest to the
largest controller in standard, fault-tolerant and fail-safe applications with just one hardware.
You must create a new configuration for use of a CPU 410-5H. The parameters of a CPU
410-5H are set to SIMATIC PCS 7 default values when a new configuration is created. Some
parameters that were previously freely assignable cannot be changed in the CPU 410-5H.
You can apply charts from existing SIMATIC PCS 7 projects.
A SIMATIC PCS 7 project includes the following objects:
● Hardware configuration
● Blocks
● CFCs and SFCs
These objects are always present - regardless of the number of operator stations and
modules and their networking.
You create a SIMATIC PCS 7 project on an engineering station (ES for short). A variety of
applications are available on the ES:
● SIMATIC Manager - the central application of SIMATIC PCS 7. From here, you can open
all other applications in which you need to make settings for the SIMATIC PCS 7 project.
You will set up your entire project from SIMATIC Manager.
● HW Config – configuration of all hardware of a system, e.g., CPUs, power supply,
communications processors.
● CFC editor and SFC editor - creation of continuous function charts (CFC) and sequential
control systems.
● SIMATIC PCS 7 OS in conjunction with various editors - Implementation of OS
configuration
Every application has a graphic user interface for easy operation and clear representation of
your configuration data.
CPU 410 Process Automation/CPU 410 SMART
24System Manual, 05/2017, A5E31622160-AC
Page 25
Introduction to the CPU 410
Important information on configuration
WARNING
Open equipment
Additional information
See also
2.2
Possible applications
Important information on configuration
WARNING
Open equipment
2.2 Possible applications
Risk of death or serious injury.
S7–400 modules are classified as open equipment, meaning you must install the S7–400 in
an enclosure, cabinet, or switch room that can only be accessed by means of a key or tool.
Only instructed or authorized personnel are permitted to access these enclosures, cabinets,
or switch rooms.
The components of the standard S7-400 system, e.g., power supplies, I/O modules, CPs,
and FMs, are also used in the high availability S7-400H automation system. For a detailed
description of all hardware components for S7-400, refer to Reference Manual
Automation System, Module Data
.
S7-400
For the S7-400H high availability automation system, the same rules apply for planning the
user program and for using blocks as for a standard S7-400 system. Please observe the
descriptions in the
Programming with STEP 7
300/400 System and Standard Functions
Summary of parameters for CPU 410 (Page 48)
S7–400 modules are classified as open equipment, meaning you must install the S7–400 in
an enclosure, cabinet, or switch room that can only be accessed by means of a key or tool.
Only instructed or authorized personnel are permitted to access these enclosures, cabinets,
or switch rooms.
manual and the
reference manual.
System Software for S7-
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
The following figure shows an example of an S7–400H configuration with shared distributed
I/O and connection to a redundant plant bus. The next pages deal with the hardware and
software components required for the installation and operation of the S7–400H.
25
Page 26
Introduction to the CPU 410
Additional information
2.2 Possible applications
Figure 2-2 Overview
The components of the S7–400 standard system are also used in connection with the CPU
410-5H Process Automation. For a detailed description of all hardware components for S7400, refer to Reference Manual
CPU 410 Process Automation/CPU 410 SMART
S7-400 Automation System; Module Specifications
26System Manual, 05/2017, A5E31622160-AC
.
Page 27
Introduction to the CPU 410
2.3
The CPU 410 basic system for stand-alone operation
Definition
Note
Rack number "0" must be set on the CPU.
Hardware of the basic system
Central controller and expansion units
Power supply
2.3 The CPU 410 basic system for stand-alone operation
Stand-alone operation refers to the use of a CPU 410 in a standard SIMATIC-400 station.
The basic system consists of the required hardware components of a controller. The
following figure shows the components in the configuration.
You can expand the basic system with standard S7-400 modules. There are limitations in the
case of function and communication modules. See Appendix Function and communication
modules that can be used in a redundant configuration (Page 389).
Figure 2-3 Hardware of the S7-400H basic system
The rack containing the CPU is called the central controller (CC). The racks in the system
that are equipped with modules and connected to the CC are the expansion units (EU).
For the power supply you need a power supply module from the standard S7-400 system
spectrum.
To increase availability of the power supply, you can also use two redundant power supplies.
In this case, you use the power supply modules PS 405 R / PS 407 R.
A combination of these can also be used in redundant configurations (PS 405 R with PS 407
R).
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
27
Page 28
Introduction to the CPU 410
Operation
2.4
The basic system for redundant operation
Hardware of the basic system
Central processing units
on the rear
Rack for S7-400H
2.4 The basic system for redundant operation
You need a system expansion card for operation of a CPU 410. The system expansion card
specifies the maximum number of process objects that can be loaded to the CPU and saves
the license information in case of a system expansion. The system expansion card forms a
hardware unit with the CPU 410.
The basic system consists of the hardware components required for a fault-tolerant
controller. The following figure shows the components in the configuration.
The basic system can be expanded with standard modules of the S7-400. There are
restrictions for the function modules and communication processors. See Appendix Function
and communication modules that can be used in a redundant configuration (Page 389).
Figure 2-4 Hardware of the S7-400H basic system
The two CPUs are the heart of the S7-400H. Use the switch
the rack numbers. In the following sections, we will refer to the CPU in rack 0 as CPU 0, and
to the CPU in rack 1 as CPU 1.
of the CPU to set
The UR2-H rack supports the installation of two separate subsystems with nine slots each,
and is suitable for installation in 19" cabinets.
You can also set up the S7-400H in two separate racks. The racks UR1, UR2, and CR3 are
available for this purpose.
CPU 410 Process Automation/CPU 410 SMART
28System Manual, 05/2017, A5E31622160-AC
Page 29
Introduction to the CPU 410
Power supply
Synchronization modules
Fiber-optic cable
Operation
2.4 The basic system for redundant operation
You require a power supply module from the standard system range of the S7-400 for each
of the two subsystems of the S7-400H.
To increase availability of the power supply, you can also use two redundant power supplies
in each subsystem. In this case, you use the power supply modules PS 405 R / PS 407 R.
A combination (PS 405 R with PS 407 R) can also be used.
The synchronization modules are used to link the two CPUs. They are installed in the CPUs
and interconnected by means of fiber-optic cables.
Two types of synchronization modules are available:
● Synchronization modules for synchronization cables up to 10 meters long
● Synchronization modules for synchronization cables up to 10 kilometers long
You must use 4 synchronization modules of the same type in a fault-tolerant system. For a
description of the synchronization modules, refer to the section Synchronization modules for
the CPU 410. (Page 239).
The fiber-optic cables are used to interconnect the synchronization modules for the
redundant link between the two CPUs. They interconnect the upper and lower
synchronization modules in pairs.
You will find the specification of the fiber-optic cables you can use in an S7-400H in the
section Selecting fiber-optic cables (Page 245).
You need a system expansion card for operation of a CPU 410. The system expansion card
specifies the maximum number of process objects that can be loaded to the CPU and saves
the license information in case of a system expansion. The system expansion card forms a
hardware unit with the CPU 410. In redundant operation, each CPU 410 must have a system
expansion card with identical quantity framework and scope of functions.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
29
Page 30
Introduction to the CPU 410
2.5
Rules for H station assembly
2.6
I/O for the CPU 410
2.5 Rules for H station assembly
The following rules have to be complied with for a fault-tolerant station, in addition to the
rules that generally apply to the arrangement of modules in the S7-400:
● The CPUs have to be inserted in the same slots.
● Redundantly used external CP443-5DX DP master interfaces or communication modules
must be inserted in the same slots in each case.
● External DP master interface modules for redundant DP master systems may only be
inserted in central controllers and not in expansion units.
● Redundantly used CPUs must be identical, which means they must have the same article
number, product version and firmware version. It is not the marking on the front side that
is decisive for the product version, but the revision of the "Hardware" component
("Module status" dialog mask) to be read using STEP 7.
● Redundantly used other modules must be identical, i.e. they must have the same article
number, product version and - if available - firmware version.
● Two CPU 410-5H must have system expansion cards with the same configuration size
and the same functional scope.
You can use SIMATIC S7 input/output modules with the CPU 410. The I/O modules can be
used in the following devices:
● Central controllers
● Expansion units
● Distributed via PROFIBUS DP
● Distributed via PROFINET IO
The function modules (FM) and communication modules (CP) that can be used with CPU
410 are listed in the appendix Function and communication modules that can be used in a
redundant configuration (Page 389).
CPU 410 Process Automation/CPU 410 SMART
30System Manual, 05/2017, A5E31622160-AC
Page 31
Introduction to the CPU 410
2.7
I/O configuration variants of the fault-tolerant system
2.7 I/O configuration variants of the fault-tolerant system
The following configuration variants are available for the input/output modules:
● In stand-alone operation: one-sided configuration.
In the one-sided configuration, there is a single set of the input/output modules (singlechannel) that are addressed by the CPU.
● In redundant operation: Single-channel switched configuration with enhanced availability.
In the single-channel switched distributed configuration, there is a single set of the I/O
modules, but they can be addressed by both subsystems.
● In redundant operation: Dual-channel configuration with maximum availability.
In dual-channel switched configuration, there are two of each of the input/output modules
and the modules can be addressed by both subsystems.
Like S7-400, CPU 410-5H Process Automation is configured with STEP 7 HW Config.
You can find information on limitations for configuring CPUs and the fault-tolerant system in
the STEP 7 HW Config online help.
You can use all optional packages available in SIMATIC PCS 7.
STEP 7 is the core component for configuring the SIMATIC PCS 7 process control system
with the engineering system.
STEP 7 supports the various tasks involved in creating a project with the following project
views:
● Component view (HW Config)
● Process object view
● Technological perspective
The hardware that you need in a SIMATIC project, such as automation systems,
communication components, and process I/O, is stored in an electronic catalog. You
configure this hardware and assign the hardware parameters with HW Config.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
31
Page 32
Introduction to the CPU 410
2.9.1
Scaling and licensing (scaling concept)
License management
Use of the system expansion card
Expansion of a PCS 7 project
Expanding the number of POs by replacing the SEC
2.9 The SIMATIC PCS 7 project
You can protect function blocks (FBs) and functions (FCs) against unauthorized access
using the S7 Block Privacy application. You can no longer edit protected blocks in STEP 7.
Only the interfaces of the blocks are then visible.
If you protect blocks with S7 Block Privacy, you may encounter longer download and startup
times.
License objects are process objects (PO) and their associated runtime licenses (RT-PO).
When a SIMATIC PCS 7 application is created, the SIMATIC PCS 7 system determines the
number of POs that corresponds to the scope of that application.
For productive operation of the SIMATIC PCS 7 application, there must be enough runtime
licenses (AS RT POs) to cover the required number of POs. The system expansion card of
the associated CPU 410-5H must also have at least the same PO count.
The CPU is scaled by means of the system expansion card, which means the system
expansion card determines the maximum quantity of POs. The CFC counts and manages
the POs used in the application. The number of POs that can be downloaded to the CPU is
limited to the maximum number of POs specified by the system expansion card.
The number of POs of a CPU 410 is stored on a system expansion card (SEC). You insert
the SEC in a slot on the back of the CPU before commissioning the CPU. The SEC is an
essential part of the CPU hardware. The CPU cannot be operated without an SEC. If no
valid SEC is detected, the corresponding CPU does not start up. A loss of synchronization is
triggered in the fault-tolerant system, in which a start-up block prevents automatic
reconnection. You cannot operate two CPUs 410 redundantly with two different SECs.
When you expand a SIMATIC PCS 7 project and load it to the CPU, the system checks
whether the project can run in the CPU with the current number of POs. If this is not the
case, you have two options to expand the number of POs:
● Replacing the system expansion card
● Online with CPU 410 expansion packs.
There are expansion packs with 100 POs and with 500 POs. These can also be
combined.
To replace the system expansion card (SEC), you must remove the CPU. You must replace
both SECs for redundant operation. The new SECs must have the same number of POs.
CPU 410 Process Automation/CPU 410 SMART
32System Manual, 05/2017, A5E31622160-AC
Page 33
Introduction to the CPU 410
Expanding the number of POs without replacing the SEC
Note
This function can
expand
number of POs without replacing the SEC.
Expansion of the functionality of the CPU
2.9 The SIMATIC PCS 7 project
You can expand the number of POs in four steps without replacing the SEC.
Step 1: Order the number CPU 410 expansion packs you need using the regular ordering
process. You can order expansions for 100 POs and 500 POs.
Step 2: Assign the CPU 410 expansion packs to the respective CPU.
Step 3: Activate the expansion.
Step 4: Transfer the release of the expansion to the CPU.
A detailed description of the procedure is available in the
Service support and diagnostics (V8.1)
only be used to
You can activate support for redundant subsystems for the CPU:
● Step 1: Follow the standard ordering procedure to obtain the necessary license.
● Step 2: Assign the license to the relevant CPU.
● Step 3: Activate the expansion.
● Step 4: Transfer the activation of the expansion to the CPU.
PCS 7 process control system,
manual.
the number of POs. You cannot the reduce the
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
33
Page 34
Introduction to the CPU 410
2.9 The SIMATIC PCS 7 project
CPU 410 Process Automation/CPU 410 SMART
34System Manual, 05/2017, A5E31622160-AC
Page 35
3
3.1
Operator controls and indicators on the CPU 410
Arrangement of the operator controls and indicators on the CPU 410
Figure 3-1 Arrangement of the operator controls and indicators on the CPU 410
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
35
Page 36
Configuration of the CPU 410
LED displays
LED display
Color
Meaning
Top bar
EXTF
red
External error
REDF
red
Loss of redundancy/Redundancy fault
BUS1F
red
Bus fault at the PROFIBUS interface
BUS5F
red
Bus fault at the first PROFINET IO interface
BUS8F
red
Bus fault at the second PROFINET IO interface
IFM1F
red
Error in synchronization module 1
IFM2F
red
Error in synchronization module 2
MAINT
yellow
Maintenance request pending
RUN
green
RUN mode
STOP
yellow
STOP mode
Bottom bar
MSTR
yellow
CPU controls the process
RACK0
yellow
CPU in rack 0
RACK1
yellow
CPU in rack 1
For the interfaces
LINK
green
Connection at the PROFINET IO interface is active
RX/TX
orange
Receiving or sending data at the PROFINET IO interface.
LINK 1 OK
green
Connection via synchronization module 1 is active and OK
Reset button
Slot for synchronization modules
3.1 Operator controls and indicators on the CPU 410
The following table gives an overview of the available LED displays.
Sections CPU 410 monitoring functions (Page 39) and Status and error displays
(Page 41) describe the states and errors/faults indicated by these LEDs.
Table 3- 1 LED displays on the CPUs
INTF red Internal error
LINK 2 OK green Connection via synchronization module 2 is active and OK
You operate the reset button in the following cases:
● You want to reset the CPU to the factory state, see section Resetting the CPU 410 to
delivery condition (reset to factory setting) (Page 142)
● You want to reset the CPU during operation, see section Reset during operation
(Page 143)
The reset button is on the front of the CPU directly below the LED strip. Press it with a
suitably thin round object.
The synchronization modules for redundant operation are inserted in these slots. See
section Synchronization modules (Page 239).
CPU 410 Process Automation/CPU 410 SMART
36System Manual, 05/2017, A5E31622160-AC
Page 37
Configuration of the CPU 410
PROFIBUS DP interface
PROFINET IO interface
Label
Meaning
X5 P1 R
Interface X5, Port 1, ring port possible
X8 P1 R
Interface X8, Port 1, ring port possible
X8 P2 R
Interface X8, Port 2, ring port possible
When media redundancy is activated, the corresponding port is configured as a ring port.
NOTICE
Connecting only to Ethernet LAN
3.1 Operator controls and indicators on the CPU 410
You can connect the distributed I/O to the PROFIBUS DP interface.
The PROFINET IO interfaces establish the connection to Industrial Ethernet. The
PROFINET IO interfaces also serve as the access point for the engineering system. The
PROFINET IO interfaces feature two switched ports with external connectors (RJ 45). You
can find further information on PROFINET IO in sections PROFINET IO systems (Page 52).
The meaning of the interface labels is as follows:
X5 P2 R Interface X5, Port 2, ring port possible
These interfaces only allow connection to an Ethernet LAN. You cannot connect them to
the public telecommunication network, for example.
You may only connect PROFINET IO-compliant network components to this interface.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
37
Page 38
Configuration of the CPU 410
Rear of the CPU 410
Setting the rack number
Slot for system expansion card
3.1 Operator controls and indicators on the CPU 410
Use the switch on the rear panel of the CPU to set the rack number. The switch has two
positions: 1 (up) and 0 (down). One CPU is allocated rack number 0, and the partner CPU is
assigned rack number 1. The default setting of all CPUs is rack number 0.
The back of the CPU has a slot in which you insert the system expansion card (SEC) before
commissioning the CPU. The SEC contains information that specifies the performance class
of the CPU in terms of the amount of POs it supports. The SEC is an essential part of the
CPU hardware. The CPU cannot be operated without an SEC. If an SEC is not detected, the
corresponding CPU goes to STOP and requests a memory reset. "STOP by CPU memory
management" is also entered in the diagnostics buffer.
You need a small screwdriver to remove the SEC. Place the screwdriver at the top of the
SEC slot and lift out the SEC with the screwdriver.
CPU 410 Process Automation/CPU 410 SMART
38System Manual, 05/2017, A5E31622160-AC
Page 39
Configuration of the CPU 410
3.2
CPU 410 monitoring functions
Monitoring functions and error messages
Type of error
Cause of error
Error LED
Access error
Module failure (SM, FM, CP)
EXTF
and goes out with the outgoing diagnostic interrupt.
Removing a synchronization module.
3.2 CPU 410 monitoring functions
The hardware of the CPU and operating system provide monitoring functions to ensure
proper operation and defined reactions to errors. Various errors may also trigger a reaction
in the user program.
The table below provides an overview of possible errors and their causes, and the
corresponding responses of the CPU.
Additional test and information functions are available in each CPU; they can be initiated in
STEP 7.
Time error
Power supply module(s)
fault (not power failure)
Diagnostic interrupt An I/O module with interrupt capability reports a diagnostic interrupt
Swapping interrupt Removing or inserting a module as well as inserting an incorrect
Redundancy error
CPU hardware fault
Program execution error
• The user program execution time (OB 1 and all interrupts and
error OBs) exceeds the specified maximum cycle time.
• OB request error
• Overflow of the start information buffer
• Time-of-day error interrupt
In the central or S7-400 expansion rack
• at least one backup battery of the power supply module is com-
pletely discharged.
• the backup battery voltage is missing.
• the 24 V supply to the power supply module has failed.
The synchronization module signals a diagnostic interrupt; see
Chapter Synchronization modules for the CPU 410. (Page 239)
The LED EXTF lights up with the first incoming diagnostic interrupt
module type.
• Loss of redundancy on the CPUs
• Redundancy loss/ station failure of a switched DP station
• Failure of a DP master
• Redundancy loss/station failure of a switched IO device
• A memory error was detected and eliminated
• Priority class is called, but the corresponding OB is not availa-
ble.
• In the event of an SFB call: Missing or faulty instance DB
• Process image update error
INTF
EXTF
EXTF
EXTF
REDF
INTF
INTF
EXTF
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
39
Page 40
Configuration of the CPU 410
Type of error
Cause of error
Error LED
brary.
software
error).
brary.
compiled user program, for example, illegal OP code or
brary.
3.2 CPU 410 monitoring functions
Failure of a rack/station
Communication error Communication error:
Execution canceled The execution of a program block was canceled. Possible reasons
Missing license for Runtime
Programming error User program error:
• Power failure in an S7-400 expansion unit
• Failure of a DP/PN segment
• Failure of a coupling segment: Missing or defective IM, inter-
rupted cable
• Time synchronization
• Access to DB when exchanging data via communications func-
tion blocks
for the cancellation are:
• Nesting depth of nesting levels too great
• Nesting depth of master control relay too great
• Nesting depth of synchronization errors too great
• Nesting depth of block call commands (U stack) too great
• Nesting depth of block call commands (B stack) too great
• Error during allocation of local data
Such errors cannot occur with blocks from a SIMATIC PCS 7 li-
The Runtime software could not be completely licensed (internal
• BCD conversion error
• Range length error
• Range error
• Alignment error
• Write error
• Timer number error
• Counter number error
• Block number error
• Block not loaded
Such errors cannot occur with blocks from a SIMATIC PCS 7 li-
EXTF
BUSF for PN and DP
REDF for redundant
segments
INTF
INTF
INTF
INTF
MC7 code error Error in the
CPU 410 Process Automation/CPU 410 SMART
40System Manual, 05/2017, A5E31622160-AC
INTF
a jump beyond the block end
Such errors cannot occur with blocks from a SIMATIC PCS 7 li-
Page 41
Configuration of the CPU 410
3.3
Status and error displays
RUN and STOP LEDs
LED
Meaning
RUN
STOP
possible.
2 Hz
2 Hz
0.5 Hz
RUN, there might be an error in the system configuration, for example.
0.5 Hz
access to the CPU until completed.
the load memory, set the CPU to delivery state before powering it up.
3.3 Status and error displays
The RUN and STOP LEDs provide information about the CPU's currently active operating
state.
Table 3- 2 Possible states of the RUN and STOP LEDs
Lit Dark CPU is in RUN state.
Dark Lit CPU is in STOP state. The user program is not being executed. Cold restart/restart is
Flashes
Flashes
Flashes
2 Hz
Dark Flashes
Dark Flashes
Flashes
0.5 Hz
Flashes
0.5 Hz
Flashes
Lit HOLD status has been triggered by a test function.
Lit A cold restart/restart was initiated. The cold restart/warm start may take a minute or
2 Hz
Flashes
0.5 Hz
Flashes
2 Hz
The CPU has detected a serious error that is blocking startup. All other LEDs also
flash at 2 Hz.
longer, depending on the length of the called OB. If the CPU still does not change to
• A high-quality RAM test (self-test) is executed after POWER ON. The duration of
the self-test is at least 7 minutes.
• CPU memory reset is active.
The CPU requests a memory reset.
• Troubleshooting mode
• Startup (POWER ON) of a CPU on which a large number of blocks is loaded. If
encrypted blocks are loaded, startup may take a longer time depending on the
number of such blocks.
This display also indicates that internal processes are busy on the CPU and prevent
The CPU has downloaded another program and is powering up after power on.
Note that, if necessary, another program and a configuration may be present in the
retentive load memory in the CPU. Ensure that this cannot pose a hazard if the CPU
switches automatically to RUN state. If you have no information about the content of
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
41
Page 42
Configuration of the CPU 410
MSTR, RACK0, and RACK1 LEDs
LED
Meaning
MSTR
RACK0
RACK1
Lit
Irrelevant
Irrelevant
CPU controls switched I/O
Irrelevant
Lit
Dark
CPU on rack number 0
INTF and EXTF LEDs
LED
Meaning
INTF
EXTF
error).
Irrelevant
Lit
An external error has been detected (i.e. an error not caused by the CPU)
BUS1F, BUS5F, and BUS8F LEDs
LED
Meaning
BUS1F
BUS5F
BUS8F
Lit
Irrelevant
Irrelevant
An error was detected on the PROFIBUS DP interface X1.
A PROFINET IO system is configured but not connected.
A PROFINET IO system is configured but not connected.
Irrelevant
Flashes
Irrelevant
One or more devices on the first PROFINET IO interface X5 is not responding.
Irrelevant
Irrelevant
Flashes
One or more devices on the second PROFINET IO interface X8 is not responding.
Flashes
Irrelevant
Irrelevant
One or more slaves on the PROFIBUS DP interface X1 is not responding.
3.3 Status and error displays
The three LEDs MSTR, RACK0, and RACK1 provide information about the rack number set
on the CPU and show which CPU controls the switched I/O.
Table 3- 3 Possible states of the MSTR, RACK0 and RACK1 LEDs
Irrelevant Dark Lit CPU on rack number 1
The two INTF and EXTF LEDs provide information about errors and other particular things
that happen during user program execution.
Table 3- 4 Possible states of the INTF and EXTF LEDs
Lit Irrelevant An internal error was detected (programming, parameter assignment, or license
The BUS1F, BUS5F and BUS8F LEDs indicate errors associated with the PROFIBUS DP
interface and the PROFINET IO interfaces.
Table 3- 5 Possible states of the BUS1F, BUS5F, and BUS8F LEDs
Irrelevant Lit Irrelevant An error was detected on the first PROFINET IO interface X5.
Irrelevant Irrelevant Lit An error was detected on the second PROFINET IO interface X8.
CPU 410 Process Automation/CPU 410 SMART
42System Manual, 05/2017, A5E31622160-AC
Page 43
Configuration of the CPU 410
IFM1F and IFM2F LEDs
LED
Meaning
IFM1F
IFM2F
Irrelevant
Lit
An error was detected on synchronization module 2
LINK and RX/TX LEDs
LED
Meaning
LINK
RX/TX
Lit
Irrelevant
Connection at the PROFINET IO interface is active
Note
The LINK and RX/TX LEDs are located directly next to the sock
interfaces. They are not labeled.
REDF LED
REDF LED
System state
Basic requirements
0.5 Hz
2 Hz
3.3 Status and error displays
The IFM1F and IFM2F LEDs indicate errors on the first or second synchronization module.
Table 3- 6 Possible states of the IFM1F and IFM2F LEDs
Lit Irrelevant An error was detected on synchronization module 1.
The LINK and RX/TX LEDs indicate the current state of the PROFINET IO interfaces.
Table 3- 7 Possible states of the LINK and RX/TX LEDs
Irrelevant Flashes
6 Hz
Receiving or sending data at the PROFINET IO interface.
The REDF LED indicates specific system states and redundancy errors.
Table 3- 8 Possible states of the REDF LED
Flashes
Flashes
Link-up -
Update -
ets of the PROFINET IO
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
43
Page 44
Configuration of the CPU 410
REDF LED
System state
Basic requirements
Dark
Redundant (CPUs are redundant)
No redundancy error
LEDs LINK1 OK and LINK2 OK
LED LINKx OK
Meaning
Lit
The connection is OK
Check whether the synchronization module works in another CPU.
If necessary, replace the synchronization module in the other CPU.
LED MAINT
Diagnostics buffer
3.3 Status and error displays
Lit Redundant (CPUs are redundant) There is an I/O redundancy error:
• Failure of a DP master, or partial or total failure of a
DP master system
• Failure of a PN IO subsystem
• Loss of redundancy on the DP slave
• Loss of redundancy at the PN IO device
• Loss of redundancy on the DP slave/slave failure
• Loss of redundancy at the PN IO device/device
failure
When commissioning the fault-tolerant system, you can use the LINK1 OK and LINK2 OK
LEDs to check the quality of the connection between the CPUs.
Table 3- 9 Possible states of the LINK1 OK and LINK2 OK LEDs
Flashes The connection is not reliable, and the signal is disrupted
Check the connectors and cables
Ensure that the fiber-optic cables are installed in accordance with the guidelines in Chapter
Installation of fiber-optic cables (Page 243).
Dark The connection is interrupted, or there is insufficient light intensity
Check the connectors and cables
Ensure that the fiber-optic cables are installed in accordance with the guidelines in Chapter
Installation of fiber-optic cables (Page 243).
Check whether the synchronization module works in another CPU.
This LED indicates that maintenance is required. Maintenance is required when there are
problems with the synchronization modules or if maintenance is demanded by one of the
PROFINET devices. For more information, refer to the STEP 7 Online Help.
The LED MAINT also displays an error during address assignment of the PROFINET
interfaces X5 or X8.
In STEP 7, you can select "PLC -> Module Information" to read the cause of an error from
the diagnostics buffer.
CPU 410 Process Automation/CPU 410 SMART
44System Manual, 05/2017, A5E31622160-AC
Page 45
Configuration of the CPU 410
3.4
PROFIBUS DP interface (X1)
Connectable devices
Connectors
Redundant operation
3.5
PROFINET IO interfaces (X5, X8)
Assigning an IP address
Devices that can be connected via PROFINET IO (PN)
3.4 PROFIBUS DP interface (X1)
The PROFIBUS DP interface can be used to set up a PROFIBUS master system, or to
connect PROFIBUS I/O devices.
All DP slaves that conform to the standard can be connected to the PROFIBUS DP interface.
You can connect the PROFIBUS DP I/O to the PROFIBUS DP interface in redundant or
single-channel switched configuration.
In this case, the CPU is the DP master, which is connected to the passive slave stations or,
in stand-alone operation, to other DP masters.
Some of the devices that can be connected draw 24 V from the interface for their power
supply. This voltage is provided as non-isolated voltage at the PROFIBUS DP interface.
Use only PROFIBUS DP bus connectors or PROFIBUS cables for connecting devices to the
PROFIBUS DP interface (
see installation manual
).
The PROFIBUS DP interfaces have the same baud rate and the same operating mode in
redundant operation.
You assign an IP address to an Ethernet interface in the CPU properties using HW Config.
Download the modified configuration to the CPU. The IP address is valid for the duration of
the project.
For technical reasons, the two interfaces X5/X8 must be located in different IP subnets.
● SIMATIC PCS 7 ES/OS with Ethernet network card or CP16xx communications
processor
● Active network components, e.g., Scalance X200
● S7-300/S7-400, e.g., CPU 417-5H or communication processor CP443-1
● PROFINET IO devices, e.g. ET 200SP HA or ET 200M
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
45
Page 46
Configuration of the CPU 410
Connectors
Properties of the PROFINET IO interfaces
Protocols and communication functions
PROFINET IO
PG functions
Yes
Detection of the network topology (LLDP)
Yes
Media redundancy (MRP)
Yes
Time synchronization in NTP method as client
Yes
Time synchronization in SIMATIC method
Yes
Time synchronization in pTCP method
Yes
Connection per interface
Version
2 x RJ45
Switch with 2 ports
Media
Twisted pair Cat5
Transmission rate
10/100 Mbps
Autonegotiation
3.5 PROFINET IO interfaces (X5, X8)
The PROFINET interfaces are implemented as Ethernet RJ45 interfaces. Always use RJ45
connectors to hook up devices to a PROFINET interface.
According to IEC 61784-2 Conformance Class A und B
Open block communication over
S7 communication Yes
Port statistics of PN IO devices (SNMP) Yes
• TCP
• UDP
• ISO-on-TCP
You can find further information about the properties of the PROFINET IO interfaces in the
technical specifications of the CPUs in section Technical data (Page 253).
Autosensing
Autocrossing
CPU 410 Process Automation/CPU 410 SMART
46System Manual, 05/2017, A5E31622160-AC
Page 47
Configuration of the CPU 410
Note
Networking of PROFINET IO components
The PROFINET IO interfaces of our devices are set to "automatic setting" (autonegotiation)
by default. Verify that all devices connected to the PROFINET IO interface of the CPU are
also set to the "Autonegot
IO/Ethernet components.
If you connect a device to a PROFINET IO interface of the CPU that does not support the
"automatic setting" (Autonegotiation) operating mode or you choose a setting othe
"automatic setting" (Autonegotiation) for this device, note the following:
•
•
Background: If a switch that is
interface of the CPU, the "Autonegotiation" setting forces the CPU to adapt itself to the
settings of the partner device, which means the communication operates de facto at
"10
PROFINET IO demands operation at 100
option to address IO devices.
Reference
3.5 PROFINET IO interfaces (X5, X8)
iation" mode. This is the default setting of standard PROFINET
r than the
PROFINET IO requires 100 Mbps full-duplex operation, which means if the PROFINET
IO interface of the CPU is used simultaneously for PROFINET IO communication and
Ethernet communication, operation of the PROFINET IO interface is permissible only in
100 Mbps full-duplex mode.
If an PROFINET IO interface of the CPU is used for Ethernet communication only, 100
Mbps full-duplex mode is possible.
permanently set to "10 Mbps half-duplex" is connected to an
Mbps half-duplex". This is permitted for an Ethernet communication. But because
Mbps full-duplex, this would not be a long-term
● For details about PROFINET, refer to PROFINET System Description
(http://support.automation.siemens.com/WW/view/en/19292127)
● For detailed information about Ethernet networks, network configuration and network
components refer to SIMATIC NET Manual: Twisted-Pair and Fiber-Optic Networks
(http://support.automation.siemens.com/WW/view/en/8763736).
● For additional information about PROFINET IO, refer to: PROFINET
(http://www.profibus.com/)
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
47
Page 48
Configuration of the CPU 410
3.6
Summary of parameters for CPU 410
Default values
Parameter blocks
Parameter assignment tool
Further settings
3.6 Summary of parameters for CPU 410
All parameters are set to factory defaults. These defaults are suitable for a wide range of
standard applications and can be used to operate the CPU 410 directly without having to
make any additional settings.
You can define the defaults using the "Configuring Hardware" tool in STEP 7.
The responses and properties of the CPU are defined in parameters. The CPU 410 has a
defined default setting. You can modify this default setting by editing the parameters in the
hardware configuration.
The list below provides an overview of the assignable system properties of the CPUs.
● Startup, for example, times for completed message from modules and transfer of
parameters to modules
You can set the individual CPU parameters using "Configuring hardware" in STEP 7. For
additional information, see I/O configuration variants (Page 55).
● The rack number of a CPU 410, 0 or 1
Use the selector switch on the rear panel of the CPU to change the rack number.
● The operating mode of a CPU 410, stand-alone operation or redundant operation
You set the operating mode by configuring a SIMATIC 400 station (stand-alone
operation) or a SIMATIC H station in HW Config.
CPU 410 Process Automation/CPU 410 SMART
48System Manual, 05/2017, A5E31622160-AC
Page 49
4
4.1
CPU 410 as PROFIBUS DP master
Startup of the DP master system
PROFIBUS address of the DP master
Output and input data length
4.2
Diagnostics of the CPU 410 as PROFIBUS DP master
Diagnostics using LED displays
BUS1F
Meaning
Remedy
all configured slaves are addressable
You use the following parameters to set startup monitoring of the DP master:
● Ready message from module
● Transfer of parameters to modules
This means that the DP slaves must be started up and their parameters assigned by the
CPU (as DP master) within the set time.
PROFIBUS addresses 0 to 126 are permissible.
The maximum output or input data length you can use for each DP station is 244 bytes.
When an ET 200PA SMART is used, the maximum usable output or input data length is 242
bytes
For each ET 200PA SMART you are using in a DP line, the total number of user data of this
DP line is reduced by one output word and one input word.
Table 4- 1 Meaning of the "BUSF" LED of the CPU 410 as DP master
Off Configuration correct;
The following table explains the meaning of the BUS1F LED.
-
Lit
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
• Bus fault (physical fault) • Check whether the bus cable has shorted.
• DP interface fault
• Different baud rates in multi-DP master
operation (only in stand-alone operation)
• Analyze the diagnostic data. Reconfigure or correct the
configuration.
49
Page 50
PROFIBUS DP
BUS1F
Meaning
Remedy
Diagnostic addresses for the DP master
4.2 Diagnostics of the CPU 410 as PROFIBUS DP master
Flashes
• Station failure
• At least one of the assigned slaves cannot
be addressed
You assign diagnostic addresses for PROFIBUS DP for the CPU 410.
When configuring the DP master, you specify a diagnostic address for the DP slave in the
associated project of the DP master.
This diagnostic address is used by DP master to obtain information about the status of DP
slave or a bus interruption.
• Check whether the bus cable is connected to the
CPU 410 or the bus is interrupted.
• Wait until the CPU 410 has started up. Check the DP
slaves if the LED does not stop flashing. If possible,
evaluate the diagnostics of the DP slaves with direct access via the bus.
CPU 410 Process Automation/CPU 410 SMART
50System Manual, 05/2017, A5E31622160-AC
Page 51
5
5.1
Introduction
What is PROFINET IO?
RT communication (real-time communication)
Documentation on the Internet
PROFINET IO is the open, cross-vendor Industrial Ethernet standard for automation. It
enables continuous communication from the business management level down to the field
level. PROFINET IO is based on switched Ethernet with full duplex mode and a bandwidth of
100 Mbps.
With PROFINET IO a switching technology is implemented that allows all stations to access
the network at any time. As a result, the network can be utilized more efficiently through
simultaneous data transmission of multiple nodes. Simultaneous sending and receiving is
enabled through the full-duplex operation of Switched Ethernet.
In PROFINET IO communication, a portion of the transmission time is reserved for cyclic,
deterministic data transmission (real-time communication). This allows you to split the
communication cycle into a deterministic and an open part. Communication takes place in
real-time.
RT communication is the basic communication mechanism for PROFINET IO and is used
during device monitoring. The transmission of real-time data with PROFINET IO is based on
the cyclic data exchange with a provider-consumer model. To better scale the
communication options and therefor the determinism for PROFINET IO, real-time classes
have been defined for data exchange. These are unsynchronized and synchronized
communication. The details are handled independently in the field devices. Real-time
automatically includes an increase in priority with PROFINET compared to UDP/IP frames.
This is necessary to prioritize the transmission of data in the switches so that RT frames are
not delayed by UDP/IP frames.
Comprehensive information about PROFINET (http://www.profibus.com/) is available on the
Internet.
Also observe the following documents:
● Installation guideline
● Assembly guideline
● PROFINET_Guideline_Assembly
Additional information on the use of PROFINET IO in automation engineering is available at
the following Internet address (http://www.siemens.com/profinet/).
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
51
Page 52
PROFINET IO
5.2
PROFINET IO systems
Functions of PROFINET IO
The graphic shows
Examples of connection paths
can also access one of the other areas of the Industrial Ethernet from an ES on the field
5.2 PROFINET IO systems
The following graphic shows the new functions in PROFINET IO:
The connection of company
network and field level
Connections between the
automation system and field
level
CPU 410 Process Automation/CPU 410 SMART
52System Manual, 05/2017, A5E31622160-AC
You can access devices at the field level from PCs in your company network
• Example:
PC - Firewall - Switch 1 - Router - Switch 2 - Switch 3 - CPU 410
You
level.
Example:
• ES - Integrated switch 3 - Switch 2 - Switch 4 - CPU 410
①.
③.
Page 53
PROFINET IO
The graphic shows
Examples of connection paths
Further information
5.3
Device replacement without exchangeable medium / ES
5.3 Device replacement without exchangeable medium / ES
The IO controller of CPU
① spans
410
PROFINET IO system 1
and directly controls devices
on the Industrial Ethernet
and PROFIBUS.
The fault-tolerant system,
consisting of CPU 410
② + ③, spans the
PROFINET IO system 2 as
IO controller.
This IO controller operates
IO devices in system redundancy as well as a onesided IO device.
You will find further information about PROFINET IO in the documents listed below:
At this point, you see the IO features between the IO controller, intelligent device, and the
IO device(s) on Industrial Ethernet:
• The CPU 410
– for the ET 200SP HA I/O device
– for switch 3
– for the I device CPU 317-2 PN/DP
– for the IE/PB link ⑥
• The IE/PB link is the master for the DP slave ⑩ and maps the latter as a device ⑩ in
the PROFINET IO.
The fault-tolerant system, consisting of CPU 410 ② + ③, spans the PROFINET IO controller system 2 as IO controller. This IO controller operates IO devices in system redundancy
as well as a one-sided IO device.
Here, you can see that a fault-tolerant system can operate both system-redundant IO devic-
es and one-sided IO devices:
• The fault-tolerant system with its two IO controllers in rack 0 and rack 1 provides the IO
controller for both system-redundant IO devices ET 200
IO device
① is the IO controller for the following components:
● In Programming Manual Migration from PROFIBUS DP to PROFINET IO
(http://support.automation.siemens.com/WW/view/en/19289930)
IO devices having this function can be replaced in a simple manner:
● No exchangeable medium with stored device name is required. The name that you
assigned for the IO device in HW Config applies.
● The PROFINET IO topology must be configured in HW Config for this.
● The "Support device replacement without exchangeable medium" option must be
selected on the interface of the IO controller.
● The device name does not have to be assigned with the ES.
The replacement IO device receives the device name from the IO controller. The IO
controller uses the configured topology and the relations determined by the IO devices.
The configured target topology must match the actual topology.
Before reusing IO devices that you already had in operation, reset these to factory settings.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
53
Page 54
PROFINET IO
Additional information
5.3 Device replacement without exchangeable medium / ES
For additional information, refer to the STEP 7 Online Help and to the PROFINET System
Description (http://support.automation.siemens.com/WW/view/en/19292127) manual.
CPU 410 Process Automation/CPU 410 SMART
54System Manual, 05/2017, A5E31622160-AC
Page 55
6
6.1
Stand-alone operation
Overview
Definition
Reasons for stand-alone operation
Note
The self
performed in stand
What you must observe for stand-alone operation of a CPU 410
This section provides information needed for stand-alone operation of the CPU 410. You will
learn:
● how stand-alone operation is defined
● when stand-alone operation is required
● what you have to take into account for stand-alone operation
● how the fault tolerance-specific LEDs react in stand-alone operation
● how you configure a CPU 410 for stand-alone operation
● how you can expand a CPU 410 into a fault-tolerant system
● which system modifications are possible during stand-alone operation and which
hardware requirements must be met
Stand-alone operation is the use of a CPU 410 in a standard SIMATIC-400 station.
● No requirements for increased availability
● Use of fault-tolerant communication connections
● Configuration of the S7-400F fail-safe automation system
-test is an integral component of the F-concept of the CPU 410 and is also
-alone operation.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
Observe the following for stand-alone operation of a CPU 410:
● No synchronization modules are permitted to be inserted in stand-alone operation of a
CPU 410.
● The rack number must be set to "0".
55
Page 56
I/O configuration variants
CPU 410 in stand-alone operation
CPU 410 in redundant system state
operation - H-CiR (Page 197) for redundant operation.
Fault tolerance-specific LEDs
LED
Behavior
IFM1F
Dark
MSTR
Lit
RACK0
Lit
RACK1
Dark
Configuring stand-alone operation
Expanding the configuration to a fault-tolerant system
Note
You can only expand your system to a fault
odd numbers to expansion units in stand
6.1 Stand-alone operation
Note the different procedures described below for any system change during operation:
Table 6- 1 System modifications during operation
As described in Plant changes in RUN - CiR (Page 155). As described in section Plant changes during redundant
The REDF, IFM1F, IFM2F, MSTR, RACK0 and RACK1 LEDs show the reaction specified in
the table below in stand-alone operation.
REDF Dark
IFM2F Dark
Requirement: No synchronization module is permitted to be inserted in the CPU 410.
Procedure:
1. Insert the CPU 410 in a standard rack (Insert > Station > SIMATIC 400 Station in
SIMATIC Manager).
2. Configure the station with the CPU 410 corresponding to your hardware configuration.
3. Assign the parameters of the CPU 410. Use the default values, or customize the
necessary parameters.
4. Configure the necessary networks and connections. For stand-alone operation, you can
also configure "fault-tolerant S7 connections".
For help on procedure refer to the Help topics in SIMATIC Manager.
-tolerant system if you have not assigned any
-alone operation.
CPU 410 Process Automation/CPU 410 SMART
56System Manual, 05/2017, A5E31622160-AC
Page 57
I/O configuration variants
Changing the operating mode of a CPU 410
Change from stand-alone to redundant operation, rack number 0
Change from stand-alone mode to redundant operation, rack number 1
Changing from redundant to stand-alone operation
6.1 Stand-alone operation
If you later want to expand the CPU 410 to a fault-tolerant system, proceed as follows:
1. Open a new project and insert a fault-tolerant station.
2. Copy the entire rack from the standard SIMATIC-400 station and insert it twice into the
fault-tolerant station.
3. Insert the required subnets and IO devices.
4. Copy the DP slaves from the old stand-alone operation project to the fault-tolerant station
as required.
5. Reconfigure the communication connections.
6. Carry out all changes required, such as the insertion of one-sided I/O.
For information on how to configure the project, refer to the online help.
To change the operating mode of a CPU 410, you proceed differently depending on which
operating mode you want to change to and which rack number was configured for the CPU:
1. Insert the synchronization modules into the CPU.
2. Carry out a CPU memory reset or load a project to the CPU in which the CPU is
configured for redundant operation.
3. Insert the synchronization cables into the synchronization modules.
1. Set rack number 1 on the CPU.
2. Install the CPU.
3. Carry out a CPU memory reset.
4. Insert the synchronization modules into the CPU.
5. Insert the synchronization cables into the synchronization modules.
1. Remove the CPU.
2. Remove the synchronization modules.
3. Set rack number 0 on the CPU.
4. Install the CPU.
5. Download a project to the CPU in which the CPU is configured for stand-alone operation.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
57
Page 58
I/O configuration variants
6.2
Fail-safe operation
Ensuring functional safety
Safety of fail-safe SIMATIC Safety Integrated systems
Functions of a fail-safe CPU
S7 F/FH Systems
Fail-safe I/O modules (F-modules)
6.2 Fail-safe operation
A safety-related system encompasses sensors for signal acquisition, an evaluation unit for
processing the signals, and actuators for signal output.
All of the components contribute to the functional safety of the system, in order, when a
dangerous event occurs, to put the system into a safe state or to keep it in a safe state.
For SIMATIC Safety Integrated systems, the evaluation unit consists, for example, of failsafe single-channel CPUs and fail-safe dual-channel I/O modules. The fail-safe
communications take place via the safety-related PROFIsafe profile.
A fail-safe CPU has the following functions:
● Comprehensive self-tests and self-diagnostics check the fail-safe state of the CPU.
● Simultaneous execution of standard and safety programs on one CPU. When there are
changes to the standard user program, there are no unwanted effects on the safety
program.
The S7 F Systems optional package adds security functions to the CPU 410. The current
TÜV certificates are available on the Internet: TÜV certificates
(http://support.automation.siemens.com) under "Product Support".
F-modules have all of the required hardware and software components for safe processing
in accordance with the required safety class. This includes wire tests for short-circuit and
cross-circuit. You only program the user safety functions.
Safety-related input and output signals form the interface to the process. This enables, for
example, direct connection of single-channel and two-channel I/O signals from devices such
as EMERGENCY STOP buttons or light barriers.
CPU 410 Process Automation/CPU 410 SMART
58System Manual, 05/2017, A5E31622160-AC
Page 59
I/O configuration variants
Safety-related communication with PROFIsafe profile
6.2 Fail-safe operation
PROFIsafe was the first communication standard according to the IEC 61508 safety
standard that permits both standard and safety-related communication on one bus line. This
not only results in an enormous savings potential with regard to cabling and part variety, but
also the advantage of retrofit ability.
Figure 6-2 Safety-related communication
Safety-related and standard data are transmitted with PROFIsafe over the same bus line.
Black channel means that collision-free communication via a bus system with mediaindependent network components (also wireless) is possible.
PROFIsafe is an open solution for safety-related communication via standard fieldbuses.
Numerous manufacturers of safety components and end users of safety technology have
helped to develop this vendor-neutral and open standard for PROFIBUS International (PI).
The PROFIsafe profile supports safe communication for the open PROFIBUS and
PROFINET standard buses. An IE/PB Link ensures integrated, safety-related communication
between PROFIBUS DP and PROFINET IO.
PROFIsafe is is certified to IEC 61784-3 and meets the highest requirements for the
manufacturing and process industry.
PROFIBUS is the global standard for fieldbuses with approximately 13 million installed
nodes. Its market acceptance is so high because a large number of manufacturers offer
many products for PROFIBUS. With the PA transmission variant (IEC 1158-2), PROFIBUS
extends the unified system concept of distributed automation to the process world.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
59
Page 60
I/O configuration variants
Measure/
Error
Consecutive number
Time expectation with
acknowledgment
Identifier for sender
and receiver
Data backup CRC
Repetition
✓
Insertion
✓✓✓
Incorrect sequence
✓
Data falsification
✓
Delay
✓
(masquerade)
sequence)
See also
6.2 Fail-safe operation
PROFINET IO is the innovative and open Industrial Ethernet standard for automation. It
enables fast reaction times and transmission of large data quantities.
PROFIsafe uses the PROFIBUS or PROFINET IO services for safe communication. A failsafe CPU 410 and the fail-safe I/O exchange both user data as well as status and control
information; no additional hardware is required for this.
PROFIsafe takes the following measures to counteract the various possible errors when
transferring messages.
Table 6- 2 Measures in PROFIsafe for error avoidance
Loss ✓✓
Coupling of safetyrelated messages and
standard messages
FIFO errors (first-infirst-out data register
for maintaining the
✓✓✓
✓
S7 F Systems optional package
(http://support.automation.siemens.com/WW/view/en/35130252)
CPU 410 Process Automation/CPU 410 SMART
60System Manual, 05/2017, A5E31622160-AC
Page 61
I/O configuration variants
6.3
Fault-tolerant automation systems (redundancy operation)
6.3.1
Redundant SIMATIC automation systems
Operating objectives of redundant automation systems
Why fault-tolerant automation systems?
Redundant I/O
6.3 Fault-tolerant automation systems (redundancy operation)
Redundant automation systems are used in practice with the aim of achieving a higher
degree of availability or fault tolerance.
Figure 6-3 Operating objectives of redundant automation systems
Note the difference between fault-tolerant and fail-safe systems.
The S7-400H is a fault-tolerant automation system. You may only use the S7-400H to
control safety-related processes if you have programmed it and assigned its parameters in
accordance with the rules for F-systems. You can find information on this in following
manual: SIMATIC Industrial Software S7 F/FH Systems
(http://support.automation.siemens.com/WW/view/en/2201072)
The purpose of using fault-tolerant automation systems is to reduce production downtimes,
regardless of whether the failures are caused by an error/fault or are due to maintenance
work.
The higher the costs of production stops, the greater the need to use a fault-tolerant system.
The generally higher investment costs of fault-tolerant systems are soon recovered since
production stops are avoided.
Input/output modules are termed redundant when they exist twice and they are configured
and operated as redundant pairs. The use of redundant I/O provides the highest degree of
availability, because the system tolerates the failure of a CPU or of a signal module.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
61
Page 62
I/O configuration variants
Single-channel switched I/O
See also
6.3.2
Increase of plant availability, reaction to errors
System-wide integration
Graduated availability by duplicating components
Redundancy nodes
one
6.3 Fault-tolerant automation systems (redundancy operation)
In single-channel switched configuration, there is one of each of the input/output modules. In
redundant operation, these modules can addressed by both subsystems. The single-channel
switched I/O configuration is recommended for system components which tolerate the failure
of individual modules.
Connection of two-channel I/O to the PROFIBUS DP interface (Page 80)
The CPU 410 and all other SIMATIC components, such as the SIMATIC PCS 7 control
system, are matched to one another. The system-wide integration, ranging from the control
room to the sensors and actuators, is implemented as a matter of course and ensures
maximum system performance.
The redundant structure of the S7-400H ensures requirements to reliability at all times. This
means: all essential components are duplicated.
This redundant structure includes the CPU, the power supply, and the hardware for linking
the two CPUs.
You yourself decide on any other components you want to duplicate to increase availability
depending on the specific process you are automating.
Redundant nodes represent the fail safety of systems with redundant components. A
redundant node can be considered as independent when the failure of a component within
the node does not result in reliability constraints in other nodes or in the overall system.
The availability of the overall system can be illustrated simply in a block diagram. With a 1out-of-2 system,
operability of the overall system. The weakest link in the chain of redundant nodes
determines the availability of the overall system
component of the redundant node may fail without impairing the
CPU 410 Process Automation/CPU 410 SMART
62System Manual, 05/2017, A5E31622160-AC
Page 63
I/O configuration variants
No error/fault
6.3 Fault-tolerant automation systems (redundancy operation)
Figure 6-4 Example of redundancy in a network without error
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
63
Page 64
I/O configuration variants
With error/fault
6.3 Fault-tolerant automation systems (redundancy operation)
The following figure shows how a component may fail without impairing the functionality of
the overall system.
Figure 6-5 Example of redundancy in a 1-out-of-2 system with error
CPU 410 Process Automation/CPU 410 SMART
64System Manual, 05/2017, A5E31622160-AC
Page 65
I/O configuration variants
Failure of a redundant node (total failure)
6.4
Introduction to the I/O link to fault-tolerant system
I/O installation types
Configuration
Availability
or switched I/O
switched I/O
Redundant I/O
High
6.4 Introduction to the I/O link to fault-tolerant system
The following figure shows that the overall system is no longer operable, because both
subunits have failed in a 1-out-of-2 redundancy node (total failure).
Figure 6-6 Example of redundancy in a 1-out-of-2 system with total failure
In addition to the power supply module and CPUs, which are always redundant, the
operating system supports the following I/O installation types. You specify the I/O installation
types when configuring in HW Config.
Fault-tolerant PROFINET IO (S2 with system redundancy)
Redundant PROFINET IO (R1 with system redundancy) or
Enhanced
Enhanced
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
65
Page 66
I/O configuration variants
Note
IO redundancy
The term IO redundancy is als
Addressing
6.5
Using single-channel switched I/O
What is single-channel switched I/O?
all switched I/O
6.5 Using single-channel switched I/O
o used for the connection of a redundant I/O to PROFINET IO
If you are using an I/O in a system-redundant configuration, you always use the same
address when addressing the I/O.
In single-channel switched configuration, there is one of each of the input/output modules.
In redundant operation, these can addressed by both subsystems.
In stand-alone operation, the master subsystem always addresses
contrast to one-sided I/O).
The single-channel switched I/O configuration is recommended for system components
which tolerate the failure of individual modules within the ET 200M, ET 200iSP or ET 200SP
HA.
(in
CPU 410 Process Automation/CPU 410 SMART
66System Manual, 05/2017, A5E31622160-AC
Page 67
I/O configuration variants
Single-channel switched I/O configuration at the PROFIBUS DP interface
Interface module
Article No.
IM 152 for ET 200iSP
6ES7152-1AA00-0AB0
6ES7153-2BA02-0XB0
6.5 Using single-channel switched I/O
The installation with single-channel switched I/O is possible with the ET 200M distributed I/O
device with active backplane bus and redundant PROFIBUS DP slave interface and with the
ET 200iSP distributed I/O device.
Figure 6-7 Single-channel switched distributed I/O configuration at the PROFIBUS DP interface
You can use the following interface modules for the I/O configuration at the PROFIBUS DP
interface:
Table 6- 3 Interface modules for use of single-channel switched I/O configuration at the PROFIBUS
DP interface
IM 153-2 for ET 200M 6ES7153-2BA82-0XB0
Each S7-400H subsystem is interconnected with one of the two DP slave interfaces of the
ET 200M over a DP master interface.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
67
Page 68
I/O configuration variants
Bus modules for hot swapping
Bus module
Article No.
and IM 153
width
design of redundant systems
DP/PA link
DP/PA link
Article No.
6ES7153-2BA70-0XB0
Y-Link
Y-Link
Article No.
6ES7153-2BA70-0XB0
6.5 Using single-channel switched I/O
You can use the following bus modules for hot swapping a variety of components:
Table 6- 4 Bus modules for hot swapping
BM PS/IM for load power supply
BM 2 x 40 for two modules with 40
mm width
BM 1 x 80 for a module with 80 mm
BM IM/IM for two IM 153-2/2 FO for
The DP/PA link consists of one or two IM 153-2 interface modules, and one to five DP/PA
couplers that are either connected with one another via passive bus couplers or via bus
modules.
The DP/PA link creates a gateway from a PROFIBUS DP master system to PROFIBUS PA.
In this case the two bus systems are non-interacting through the IM 153-2 both physically
(galvanically) and in terms of protocols and time.
PROFIBUS PA can be connected to a redundant system via a DP/PA link. The following IM
157 PA coupler is permissible: 6ES7157-0AC83-0XA0
You can use the following DP/PA links:
6ES7195-7HA00-0XA0
6ES7195-7HB00-0XA0
6ES7195-7HC00-0XA0
6ES7195-7HD10-0XA0
ET 200M as DP/PA link with 6ES7153-2BA82-0XB0
6ES7153-2BA81-0XB0
The Y Link consists of two IM 153-2 interface modules and one Y coupler that are connected
with one another by bus modules.
The Y Link creates a gateway from the redundant DP master system of an S7-400H to a
non-redundant DP master system. This means that devices with only one PROFIBUS DP
interface can be connected to a S7-400H as switched I/Os.
A single-channel DP master system can be connected to a redundant system via a Y
coupler.
The following IM 157 Y coupler is permissible: 6ES7197-1LB00 0XA0.
You can use the following Y-Links:
ET 200M as Y-Link with 6ES7153-2BA82-0XB0
CPU 410 Process Automation/CPU 410 SMART
68System Manual, 05/2017, A5E31622160-AC
Page 69
I/O configuration variants
FF Link
FF Link
FDC 157
6ES7157-0AC85-0XA0
Rule for PROFIBUS DP
6.5 Using single-channel switched I/O
The FF Link bus link is a gateway between a PROFIBUS DP master system and a
FOUNDATION Fieldbus H1 segment and thus enables the integration of FF devices in
SIMATIC PCS 7. The two bus systems are uncoupled from each other by the IM 153-2 FF
both physically (galvanically) and with respect to protocol and time.
The FF Link bus link consists of one or two IM 153-2 FF interface modules and an FDC 157
field device coupler or a redundant FDC 157 coupler pair, which are connected to one
another via passive bus connectors or, in the case of the redundant installation, via bus
modules.
The Compact FF Link bus link consists of one or two IM 655-5 FF interface modules.
IM 153-2
Compact FF Link 6ES7655-5BA00-0AB0
A single-channel switched I/O configuration must always be symmetrical.
● This means the fault-tolerant CPU and other DP masters must be installed in the same
slots in both subsystems (for example slot 4 in both subsystems) or
● The DP slaves must be connected to the same DP interface in both subsystems (for
example to the PROFIBUS DP interfaces of both fault-tolerant CPUs).
6ES7153-2DA80-0XB0
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
69
Page 70
I/O configuration variants
Single-channel switched I/O configuration at the PROFINET IO interface
6.5 Using single-channel switched I/O
The installation with single-channel switched I/O is possible with the ET 200M and ET 200SP
HA distributed I/O devices with active backplane bus and redundant PROFINET IO interface.
Figure 6-8 Single-channel switched distributed I/O configuration at the PROFINET IO interface
Each subsystem of the S7-400H is connected (over a PROFINET IO interface) to the
PROFINET IO interface of the ET 200M or ET 200SP HA over one connection each. If the
two PROFINET IO interfaces are located on one IM, this is known as an S2 configuration.
The S stands for a single (single) IM and thus for only one PROFINET IO interface. If the
CPU 410 Process Automation/CPU 410 SMART
70System Manual, 05/2017, A5E31622160-AC
Page 71
I/O configuration variants
Interface module
Article No.
IM 153-4 PN V4.0 and higher
6ES7153-4BA00-0XB0
Single-channel switched I/O and user program
active
channel
passive channel
Failure of the single-channel switched I/O
6.5 Using single-channel switched I/O
PROFINET IO interfaces are located on two different IMs, this is known as an R1
configuration The R stands for redundant IMs and thus for two PROFINET IO interfaces. See
Chapter Communication services (Page 308).
You can use the following interface module for the I/O configuration at the PROFINET IO
interface:
Table 6- 5 Interface module for use of single-channel switched I/O configuration at the PROFINET
IO interface
IM 155-6 PN HA 6DL1155-6AU00-0PM0
In redundant operation, in principle any subsystem can access single-channel switched I/O.
The data is automatically transferred via the synchronization link and compared. An identical
value is available to the two subsystems at all times owing to the synchronized access.
If you have connected the I/O over two IMs, the CPU accesses the I/O over one IM. The
active IM is indicated by illumination of the ACT LED.
The path via the currently active DP interface or PROFINET IO interface is called the
, while the path via the other interface is called the
cycle is always active on both channels. However, only the input and output values of the
active channel are processed in the user program or output to the I/O. The same applies to
asynchronous activities, such as interrupt processing and the exchange of data records.
The fault-tolerant system with single-channel switched I/O responds to errors as follows:
● The faulty I/O is no longer available if an input/output module or a connected device fails.
● In certain failure situations (for example failure of a subsystem, a DP master system or an
IM153-2 DP slave interface), the single-channel switched I/O continues to be available for
the process.
This is achieved by a changeover between active and passive channel. This changeover
takes place separately for each DP or PNIO station. A distinction is made between the
following two types of failure:
– Failures affecting only one station (such as failure of the DP slave interface of the
channel currently active)
– Failures affecting all stations of a DP master system or PNIO system
. The DP or PNIO
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
These include removal of the connector at the DP master interface or PNIO interface,
shutdown of the DP master system (for example a RUN-STOP transition on a CP 443-
5), and short-circuits at the cable harness of a DP master system or PNIO system.
The following applies to each station affected by a failure: If both DP slave interfaces or PN
IO connections are functional and the active channel fails, the channel previously passive
automatically becomes the active channel. A redundancy loss is reported to the user
program when OB 70 starts (event W#16#73A3).
71
Page 72
I/O configuration variants
Note
If the external DP master interface module can detect failure of the entire DP master system
(due to a short
nt ("Master system failure entering
state" W#16#39C3). The operating system no longer reports individual station failures. This
feature can be used to accelerate the changeover between the active and passive channel.
Duration of a changeover of the active channel
Note
When using fail
longer than the changeover time of
ignore this rule, you risk passivation of the fail
active channel.
You can use the Excel file "s7ftimea.xls" to calculate the monitoring and reaction times.
file is available at the following address:
Please note that the CPU can only detect a signal change if the signal duration is greater
than the specified changeover time.
When there is
slowest DP component applies to all DP components. A DP/PA link or Y
determines the changeover time and the corresponding minimum signal duration. We
therefore recommend t
6.5 Using single-channel switched I/O
Once the problem is eliminated, redundancy is restored. This also starts OB 70 (event
W#16#72A3). In this situation, there is no changeover between the active and passive
channel.
If one channel has already failed, and the remaining (active) channel also fails, then there is
a complete station failure. This starts OB 86 (event W#16#39C4).
There is also complete station failure if an IM fails in an S2 configuration. This starts OB 86
(event W#16#39C4).
-circuit, for example), it reports only this eve
The maximum changeover time is
DP/PN error detection time + DP/PN changeover time + changeover time of the DP slave
interface/PNIO interface
You can determine the first two values from the bus parameters of your DP master system or
PNIO system in STEP 7. You determine the last two values using the manuals of the DP
slave interfaces or PNIO interfaces in question.
-safe modules, always set a monitoring time for each fail-safe module that is
the active channel in the fault-tolerant system. If you
-safe modules during the changeover of the
The
a changeover of the entire DP master system, the changeover time of the
-Link usually
hat you connect DP/PA and Y-Links to a separate DP master system.
CPU 410 Process Automation/CPU 410 SMART
72System Manual, 05/2017, A5E31622160-AC
Page 73
I/O configuration variants
Changeover of the active channel during link-up and updating
Bumpless changeover of the active channel
System configuration and project engineering
See also
6.6
Versions of I/O connection to the PROFINET IO interface
6.6.1
Use of I/O connected to the PROFINET IO interface, system redundancy
System redundancy
Note
The PROFINET IO device must support this function in order to be operated redundantly on
the fault
created, thereby achieving system redundancy.
6.6 Versions of I/O connection to the PROFINET IO interface
During link-up and updating with master/standby changeover (see Link-up sequence
(Page 346)), a changeover between the active and passive channels occurs for all stations
of the switched I/O. At the same time OB 72 is called.
To prevent the I/O failing temporarily or outputting substitute values during the changeover
between the active and passive channel, the DP or PNIO stations of the switched I/O put
their outputs on hold until the changeover is completed and the new active channel has
taken over.
To ensure that total failure of a DP or PNIO station is also detected during the changeover,
the changeover is monitored by both the various DP/PNIO stations and by the DP master
system or IO system.
You should allocate switched I/O with different changeover times to separate chains. This,
for example, simplifies the calculation of monitoring times.
Time monitoring (Page 120)
You can configure the PROFINET IO system redundancy with switched devices connected
to an IM. The configuring of the PROFINET I/O is comparable to the configuring of the
PROFIBUS I/O.
You can connect a maximum of 256 IO devices to each of the two integrated PN/IO
interfaces. You can configure these as one-sided or switched devices as desired. The station
numbers are disjoint across both PN/IO interfaces and are between 1 and 256.
-tolerant system. Two ports does not mean that two system connections can be
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
73
Page 74
I/O configuration variants
Configuration
Configuration
Properties
This type of connection is also known as fault-tolerant PROFINET IO.
②
tolerant system. Each IM is assigned
③
Note
Logical configuration and topology
The topology alone does not determine whether IO devices are configured at one side
(assigned to only one CPU in
configuration. This is specified in configuration. The IO devices in configuration
example, also be configured on one side instead of in a system
6.6 Versions of I/O connection to the PROFINET IO interface
The following figure shows various different configurations for connecting IO devices to the
fault-tolerant system.
Figure 6-9 System redundancy
①
and ③
Switched I/O at the PROFINET IO
Each IO device is connected over one IM with two logic connections (system redundancy) to the two CPUs
in the fault-tolerant system.
Switched I/O at the redundant PROFINET IO
Each IO device is connected over two IMs to the two CPUs in the fault-
to one of the CPUs. The IM must support system redundancy.
This type of connection is also known as redundant PROFINET IO.
This allows independent redundant PROFINET networks to operate in the fault-tolerant system. At the
same time, the two IMs increase availability.
, the connection to the CPU is also configured as a ring (redundant fault-tolerant PROFINET IO).
In
the fault-tolerant system) or in a system-redundant
① can, for
-redundant configuration.
CPU 410 Process Automation/CPU 410 SMART
74System Manual, 05/2017, A5E31622160-AC
Page 75
I/O configuration variants
Configuration with two IO devices with independent, system-redundant connection
Network addresses on the PROFINET IO subsystem
Commissioning of a system-redundant configuration
Note
To edit the topology of a project, use the topology editor in HW Config.
S2 and R1 devices
6.6 Versions of I/O connection to the PROFINET IO interface
This configuration has the following advantage: The complete system can continue operating
after a wire break, no matter where the wire break is located. One of the two communication
connections of the IO devices is always retained. The IO devices that are redundant up this
point continue operating as one-sided IO devices.
In a redundant configuration, the network addresses of the interface modules must be
unique across both PROFINET IO subsystems.
● In a ring structure, all network addresses must be within a PROFINET IO subsystem and
you must specify the MRP role for each node.
● In the case of system redundancy with two subnets, the two interface modules of a
station must be assigned to the following PROFINET IO subnet:
– Interface module in slot 0 of the IO device is assigned to rack 0 of the IO controller.
– Interface module in slot 1 of the IO device is assigned to rack 1 of the IO controller.
It is imperative that you assign unique names when commissioning.
When you change a project or download a new project, follow these steps:
1. Put the fault-tolerant system in STOP state on both ends
2. Perform a memory reset of the standby CPU
3. Download the new project to the master CPU
4. Start the Fault-tolerant system
S2 device: There is one IM connected to both CPUs.
R1 device: There are two IM (redundant). Each IM is connected to one CPU.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
75
Page 76
I/O configuration variants
Cabinet concept with switched I/O connected to PROFINET IO
6.6.2
Redundant I/O in an ET 200SP HA
Redundant I/O
6.6 Versions of I/O connection to the PROFINET IO interface
The following figure shows the system-redundant connection of nine IO devices via three
switches. With this configuration, for example, IO devices can be arranged in multiple
cabinets.
Figure 6-10 IO devices in multiple cabinets
To configure the redundant I/O connected to PROFINET IO, insert two I/O modules of the
same type next to each other in a special terminal block (TB45R...).
CPU 410 Process Automation/CPU 410 SMART
76System Manual, 05/2017, A5E31622160-AC
Page 77
I/O configuration variants
Application planning
Hardware rule
Mounting rule
TB45R
Note
Specific wiring
Always read the documentation of the I/O module used.
Configuring
6.6 Versions of I/O connection to the PROFINET IO interface
This terminal block connects the respective process signals of the two IO modules to a
common process terminal.
● There is less wiring work compared to connecting separate I/O modules, because the
interconnection of the process signals is integrated in the system.
● The redundant signal processing of the sensors and actuators on the module level
increases the availability of the system.
● In redundant operation, the switching characteristics of the output modules that can
control the actuator in parallel are improved.
Observe the following rules for configuring redundant I/O modules:
● The I/O modules must be approved for redundant operation. You can find this information
in the manual for the respective module.
● Redundantly deployed I/O modules must be identical, i.e. they must have the same article
number, the same hardware version and the same firmware version.
I/O modules of the same type are plugged in pairs next to each other in the same IO device.
● Both slots are located on the same support module.
● Both slots are located on the same terminal block (
).
● Configure redundancy for the I/O module.
The settings you make for an I/O module always apply to the module pair.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
77
Page 78
I/O configuration variants
Configuration
Response to failure
Connecting sensors/actuators
6.6 Versions of I/O connection to the PROFINET IO interface
The following figure shows an example for the connection of the sensors or actuators each
with two redundantly used input/output modules.
Figure 6-11 S7-400 H-system with sensors and actuators on module pairs (redundant signal processing)
The following applies when a I/O module or a channel of the two I/O modules fails (valid for
input/output and mixed modules):
● The inputs continue to be available in the system.
● The outputs are controlled in the system.
You can connect a sensor/actuator to two redundant input/output modules.
The failure of an input module does not result in the loss of sensor data. When an output
module fails, the connected actuator continues to be controlled.
In some cases, the hardware design requires the sensor also to be implemented
redundantly, for example for RTD thermal resistors. Sensors can be powered using suitable
input modules.
The redundant signal processing of the sensors and actuators at the module level increases
the availability of the system. Firmware update and module replacement are possible during
operation.
In redundant operation, the switching characteristics of the output modules that can control
the actuator in parallel are improved. The modules can operate with twice the switching
current and power distribution between two output modules.
The figure below shows a configuration with one sensor and one actuator for a pair of
redundant I/O modules.
CPU 410 Process Automation/CPU 410 SMART
78System Manual, 05/2017, A5E31622160-AC
Page 79
I/O configuration variants
Maintenance and service
6.6 Versions of I/O connection to the PROFINET IO interface
Figure 6-12 AS 410 with redundant module pairs
One of the following functions is possible in each case during operation:
● Firmware update
● Replacing a module
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
79
Page 80
I/O configuration variants
6.7
Connection of two-channel I/O to the PROFIBUS DP interface
6.7.1
Connecting redundant I/O
Redundant I/O in the switched DP slave
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
To achieve this, the signal modules are installed in pairs in ET 200M distributed I/O devices
with active backplane bus.
Figure 6-13 Redundant I/O in the switched DP slave
CPU 410 Process Automation/CPU 410 SMART
80System Manual, 05/2017, A5E31622160-AC
Page 81
I/O configuration variants
Principle of channel group-specific redundancy
Note
Channel and channel group
Depending on the module, a
channels, or all channels of the module. You can therefore operate all modules with
redundancy capability in channel group
"Functional I/O redundancy" block library
Using the blocks
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
Channel errors due to discrepancy cause the passivation of the respective channel. Channel
errors due to diagnostic interrupts (OB82) cause the passivation of the channel group
affected. Depassivation depassivates all affected channels as well as the modules
passivated due to module errors. Channel group-specific passivation significantly increases
availability in the following situations:
● Relatively frequent encoder failures
● Repairs that take a long time
● Multiple channel errors on one module
channel group contains a single channel, a group of several
-specific redundancy mode.
You can find an up-to-date list of modules with redundancy capability in Signal modules for
redundancy (Page 83).
The blocks you use for channel group-specific redundancy are located in the "Redundant IO
CGP V50" library.
The "Functional I/O redundancy" block libraries that support the redundant I/O each contain
the following blocks:
● FC 450 "RED_INIT": Initialization function
● FC 451 "RED_DEPA": Initiate depassivation
● FB 450 "RED_IN": Function block for reading redundant inputs
● FB 451 "RED_OUT": Function block for controlling redundant outputs
● FB 452 "RED_DIAG": Function block for diagnostics of redundant I/O
● FB 453 "RED_STATUS": Function block for redundancy status information
Configure the numbers of the management data blocks for the redundant I/O in HW Config
under "CPU properties -> Fault-tolerant parameters". Assign unassigned DB numbers for
these data blocks. The data blocks are created by FC 450 "RED_INIT" during CPU startup.
The default setting for the management data block numbers is 1 and 2. These data blocks
are not the instance data blocks of FB 450 "RED_IN" or FB 451 "RED_OUT".
You can open the libraries in the SIMATIC Manager with "File -> Open -> Libraries"
The relevant online help describes the functions and use of the blocks.
Before using the blocks, configure the redundant modules as redundant in HW Config.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
81
Page 82
I/O configuration variants
Block
OB
Depassivation is delayed by 10 s.
Note
Use of FB 450 "RED_IN" and 451 "RED_OUT" when using process image partitions
For each priority class used (OB 1, OB 30 ... OB 38), you must use a separate process
image partition.
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
The OBs into which you need to link the various blocks are listed in the table below:
FC 450 "RED_INIT"
FC 451 "RED_DEPA" If you call FC 451 in OB 83 while inserting modules or in OB 85 dur-
FB 450 "RED_IN"
FB 451 "RED_OUT"
FB 452 "RED_DIAG"
FB 453 "RED_STATUS"
• OB 72 "CPU redundancy error" (only with fault-tolerant systems)
FC 450 is only processed after start event
B#16#33:"Standby/master switchover by operator"
• OB 80 "Timeout error" (only in single mode)
FC 450 is only executed after the start event "Resume RUN after
reconfiguring"
• OB 100 "Restart" (the administration DBs are recreated, see the
online help)
• OB 102 "Cold restart"
ing alarm output, depassivation is delayed by approximately 3 seconds.
In addition the FC 451 should be executed after the removal of the
error response as specific call in OB 1 and/or OB 30 to 38. The
FC451 only depassivates modules in the corresponding process
image partition.
• OB 1 "Cyclic program"
• OB 30 to OB 38 "Watchdog interrupt"
• OB 1 "Cyclic program"
• OB 30 to OB 38 "Watchdog interrupt"
• OB 72 "CPU redundancy error"
• OB 82 "Diagnostic interrupt"
• OB 83 "Remove/insert interrupt"
• OB 85 "Program execution error"
• OB 1 "Cyclic program" (fault-tolerant systems only)
• OB 30 to OB 38 "Watchdog interrupt"
To be able to address redundant modules using process image partitions in watchdog
interrupts, the relevant process image partition must be assigned to this pair of modules and
to the watchdog interrupt. Call FB 450 "RED_IN" in this watchdog interrupt before you call
the user program. Call FB 451 "RED_OUT" in this watchdog interrupt after you call the user
program.
The valid values that can be processed by the user program are always located at the lower
address of both redundant modules. This means that only the lower address can be used for
the application; the values of the higher address are not relevant for the application.
CPU 410 Process Automation/CPU 410 SMART
82System Manual, 05/2017, A5E31622160-AC
Page 83
I/O configuration variants
HW configuration and configuring the redundant I/O
Note
System modifications during operation are also supported with redundant I/O. You are
not permitted to change the parameter settings for a redundant module per SFC.
Note
Always swit
module that does not support diagnostics functions and is not passivated. You might
otherwise passivate the wrong module. This procedure is necessary, for example, when
replaci
Redundant modules must be in the process image of the inputs or outputs. Redundant
modules are always accessed using the process image.
If you use redundant modules, you need to make the following settings on
"Cycle/clock memory" tab under "HW Config
"OB 85 call on I/O area access error > Only incoming and outgoing errors"
6.7.2
Signal modules for redundancy
Signal modules as redundant I/O
Note
The statements on the individual signal modules in this section refer e
in redundant operation. Restrictions and special features listed here especially do not apply
to the use of the corresponding module in stand
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
Follow the steps below to use redundant I/O:
1. Insert all the modules you want to operate redundantly. Please also observe the default
rules for configuration detailed below.
2. Configure module redundancy in HW Config in the object properties of the relevant
module.
Either search for a partner module for each module or use the default settings.
If the module is inserted in the slave with a DP address at slot X, the module in the slave
with the next Profibus address at slot X will be suggested.
3. Enter the remaining redundancy parameters for the input modules.
ch off power to the station or rack before you remove a redundant digital input
ng the front connector of a redundant module.
You can use the signal modules listed below as redundant distributed I/O connected to
PROFIBUS DP. Please note the latest information on use of the modules in the SIMATIC
PCS 7 readme.
the
-> CPU 41x-H properties":
-alone operation.
Take into account that you can only use modules of the same product version and same
firmware version as redundant pairs.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
xclusively to their use
83
Page 84
I/O configuration variants
Module
Article No.
Redundant DI dual-channel
DI16xDC 24 V
6ES7 321-7BH01-0AB0
DI16xDC 24 V
6ES7 321-1BH02-0AA0
the second module is removed. This is prevented by using series diodes.
DI32xDC 24 V
6ES7 321-1BL00-0AA0
the second module is removed. This is prevented by using series diodes.
DI 8xAC 120/230V
6ES7 321-1FF01-0AA0
DI 4xNamur [EEx ib]
6ES7 321-7RD00-0AB0
properties with the specified input characteristics. Remember that this function
DI 16xNamur
6ES7321-7TH00-0AB0
6ES7326-1BK02-0AB0
DI 8xNAMUR [EEx ib]
6ES7326-1RF00-0AB0
F module in standard mode
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
A complete list of all modules released for SIMATIC PCS 7 V9.0 can be found in the
SIMATIC PCS 7 technical documentation, see Technical documentation.
Table 6- 6 Signal modules for redundancy
DI16xDC 24 V, interrupt 6ES7 321-7BH00-0AB0
In the event of an error on one channel, the entire group (2 channels) is passivated. When using the module with HF index,
only the faulty channel is passivated in the event of a channel error.
Use with non-redundant encoder
• This module supports the "wire break" diagnostic function. To implement this function, make sure that a total current
between 2.4 mA and 4.9 mA flows even at signal state "0" when you use an encoder that is evaluated at two inputs in
parallel.
You achieve this by connecting a resistor across the encoder. Its value depends on the type of switch and usually
ranges between 6800 and 8200 ohms for contacts.
For BEROS, calculate the resistance using the following formula:
(30 V / (4.9 mA - I_R_Bero) < R < (20 V / (2.4 mA - I_R_Bero)
In some system states, it is possible that an incorrect value of the first module is read in briefly when the front connector of
In some system states, it is possible that an incorrect value of the first module is read in briefly when the front connector of
You cannot use the module in redundant operation for applications in hazardous areas.
Use with non-redundant encoder
• You can only connect 2-wire NAMUR encoders or contact makers.
• Equipotential bonding of the encoder circuit should always be at one point only (preferably encoder negative).
• When selecting encoders, compare their
must always be available, regardless of whether you are using one or two inputs.
Use with non-redundant encoder
• Equipotential bonding of the encoder circuit should always be at one point only (preferably encoder negative).
• Operate the two redundant modules on a common load power supply.
• When selecting encoders, compare their properties with the specified input characteristics. Remember that this function
must always be available, regardless of whether you are using one or two inputs.
DI 24xDC 24 V 6ES7326-1BK01-0AB0
F module in standard mode
CPU 410 Process Automation/CPU 410 SMART
84System Manual, 05/2017, A5E31622160-AC
Page 85
I/O configuration variants
Module
Article No.
Redundant DO dual-channel
ally in your configuration.
DO32xDC 24 V/0.5 A
6ES7322-1BL00-0AA0
DO8xAC 120/230 V/2 A
6ES7322-1FF01-0AA0
DO 4x24 V/10 mA [EEx ib]
6ES7322-5SD00-0AB0
You cannot use the module in redundant operation for applications in hazardous areas.
DO 4x15 V/20 mA [EEx ib]
6ES7322-5RD00-0AB0
You cannot use the module in redundant operation for applications in hazardous areas.
DO 16xDC 24 V/0.5 A
6ES7322-8BH01-0AB0
DO 16xDC 24 V/0.5 A
6ES7322-8BH10-0AB0
6ES7326-2BF01-0AB0
F module in standard mode
Redundant AI dual-channel
AI8x12Bit
6ES7331-7KF02-0AB0
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
DO8xDC 24 V/0.5 A 6ES7322-8BF00-0AB0
Definite evaluation of the diagnostics information "P short-circuit" and "wire break" is not possible. Deselect these individu-
DO8xDC 24 V/2 A 6ES7322-1BF01-0AA0
• The equipotential bonding of the load circuit should always be at one point only (preferably load minus).
• Diagnostics of the channels is not possible.
• The equipotential bonding of the load circuit should always be at one point only (preferably load minus).
DO 10xDC 24 V/2 A 6ES7326-2BF00-0AB0
Use in voltage measurement
• The "wire break" diagnostics function in HW Config must not be enabled either the modules are operated with transmit-
ters or when thermocouples are connected.
Use for indirect current measurement
• When determining the measuring error, observe the following: The total input resistance in measuring ranges > 2.5 V is
reduced from a nominal 100 kilohms to 50 kilohms when you operate two inputs connected in parallel.
• The "wire break" diagnostics function in HW Config must not be enabled either the modules are operated with transmit-
ters or when thermocouples are connected.
• Use a 50 ohm resistor (measuring range +/- 1 V) or 250 ohm resistor (measuring range 1 to 5 V) to map the current on
a voltage. The tolerance of the resistor must be added on to the module error.
• This module is not suitable for direct current measurement.
Use of redundant encoders:
• You can use a redundant encoder with the following voltage settings:
+/- 80 mV (only without wire break monitoring)
+/- 250 mV (only without wire break monitoring)
+/- 500 mV (wire break monitoring not configurable)
+/- 1 V (wire break monitoring not configurable)
+/- 2.5 V (wire break monitoring not configurable)
+/- 5 V (wire break monitoring not configurable)
+/- 10 V (wire break monitoring not configurable)
1...5 V (wire break monitoring not configurable)
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
85
Page 86
I/O configuration variants
Module
Article No.
AI 8x16Bit
6ES7 331-7NF00-0AB0
When using indirect current measurement, ensure a reliable connection between the sensor resistances and the actual
AI 8x16Bit
6ES7 331-7NF10-0AB0
AI 6xTC 16Bit iso
6ES7331-7PE10-0AB0
Notice:
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
Use in voltage measurement
• The "wire break" diagnostics function in HW Config must not be enabled when the modules are operated with transmit-
ters.
Use in indirect current measurement
•
inputs, because a reliable wire break detection cannot be guaranteed in the case of a wire break of individual cables of
this connection.
• Use a 250 ohm resistor (measuring range 1 to 5 V) to map the current on a voltage.
Use in direct current measurement
• Suitable Zener diode: BZX85C8v2
• Circuit-specific additional error: If one module fails, the other may suddenly show an additional error of approx. 0.1%.
• Load capability of 4-wire transmitters: R
(determined for worst case: 1 input + 1 Zener diode at an S7 overload value of 24 mA to R
• Input voltage in the circuit when operating with a 2-wire transmitter: U
(determined for worst case: 1 input + 1 Zener diode at an S7 overload value of 24 mA to U
> 610 ohms
B
e-2w
< 15 V
= (RE * I
B
= RE * I
e-2w
max
+ U
max
+ U
z max
z max
) / I
)
max)
Use in voltage measurement
• The "wire break" diagnostics function in HW Config must not be enabled either the modules are operated with transmit-
ters or when thermocouples are connected.
Use in indirect current measurement
• Use a 250 ohm resistor (measuring range 1 to 5 V) to map the current on a voltage.
Use in direct current measurement
• Suitable Zener diode: BZX85C8v2
• Load capability of 4-wire transmitters: R
(determined for worst case: 1 input + 1 Zener diode at an S7 overload value of 24 mA to R
> 610 ohms
B
= (RE * I
B
• Input voltage in the circuit when operating with a 2-wire transmitter:
U
< 15 V (determined for worst case: 1 input + 1 Zener diode at an S7 overload value of 24 mA to U
e-2w
U
)
z max
You may use this module only with redundant sensors.
You can use this module with Version 3.5 or higher of FB 450 "RED_IN" in the library "Redundant IO MGP" and Version
5.8 or higher of FB 450 "RED_IN" in the library "Redundant IO CGP" V50.
Observe the following when measuring temperatures by means of thermocouples and assigned redundancy:
The value specified in "Redundancy" under "Tolerance window" is always based on 2765 °C. For example, a check is
made for a tolerance of 27 degrees when "1" is entered and 138 degrees when "5" is entered.
A FW update is not possible in redundant operation
An online calibration is not possible in redundant operation.
Use in voltage measurement
• The "wire break" diagnostics function in HW Config must not be enabled when the modules are operated with thermo-
couples.
Use in indirect current measurement
• Due to the maximum voltage range +/- 1 V, the indirect current measurement can be carried out exclusively via a 50
ohm resistor. Mapping that conforms to the system is only possible for the area +/- 20 mA.
max
+ U
e-2w
) / I
z max
= RE * I
max)
max
+
CPU 410 Process Automation/CPU 410 SMART
86System Manual, 05/2017, A5E31622160-AC
Page 87
I/O configuration variants
Module
Article No.
AI 4x15Bit [EEx ib]
6ES7331-7RD00-0AB0
Note:
ply only 5 V to the transmitter.
AI 8x0/4...20mA HART
6ES7 331-7TF01-0AB0
See Manual
ET 200M Distributed I/O Device; HART Analog Modules
manual
AI6x0/4...20mA HART
6ES7336-4GE00-0AB0
F module in standard mode
AI 6x13Bit
6ES7 336-1HE00-0AB0
F module in standard mode
Redundant AO dual-channel
AO4x12 Bit
6ES7332-5HD01-0AB0
AO8x12 Bit
6ES7332-5HF00-0AB0
AO4x0/4...20 mA [EEx ib]
6ES7332-5RD00-0AB0
You cannot use the module in redundant operation for applications in hazardous areas.
AO 8x0/4...20mA HART
6ES7 332-8TF01-0AB0
See Manual
ET 200M Distributed I/O Device; HART Analog Modules
Note
You need to install the F
The F C
You can find it on the Customer Support site at Download of F Configuration Pack
(
Using digital input modules as redundant I/O
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
You cannot use the module in redundant operation for applications in hazardous areas.
It is not suitable for indirect current measurement.
Use in direct current measurement
• Suitable Zener diode 6.2 V, for example BZX85C6v2
• Load capability of 4-wire transmitters: RB > 325 ohms
)/I
z max
max
determined for worst case: 1 input + 1 Zener diode at an S7 overload value of 24 mA to RB = (RE * I
• Input voltage for 2-wire transmitters: Ue-2Dr < 8 V
calculated for worst case: 1 input + 1 Zener diode at an S7 overload value of 24 mA to Ue-2Dr = RE * I
You can only connect 2-wire transmitters with a 24 V external supply or 4-wire transmitters. The internal power sup-
ply for transmitters cannot be used in the circuit because it outputs only 13 V, which means in the worst case it would sup-
A firmware update is not possible in redundant operation.
Online calibration is not possible in redundant operation.
max + Uz max
+ U
max
A firmware update is not possible in redundant operation.
Online calibration is not possible in redundant operation.
-ConfigurationPack for F modules.
onfigurationPack can be downloaded free of charge from the Internet.
The following parameters were set to configure digital input modules for redundant
operation:
● Discrepancy time (maximum permitted time in which the redundant input signals may
differ). The specified discrepancy time must be a multiple of the update time of the
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
87
Page 88
I/O configuration variants
Note
The time that the system actually needs to determine a discrepancy depends on various
factors: Bus runtimes, cycle times and call times of the user program, conversion times,
etc. For this reason, it is possible for redundant input
than the configured discrepancy time.
MTA Terminal Modules
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
process image and therefore also the basic conversion time of the channels.
When there is still a discrepancy in the input values after the configured discrepancy time
has expired, an error has occurred.
● Response to a discrepancy in the input values
First, the input signals of the paired redundant modules are checked for consistency. If the
values match, the uniform value is written to the lower memory area of the process input
image. If there is a discrepancy and it is the first, it is marked accordingly and the
discrepancy time is started.
During the discrepancy time, the most recent matching (non-discrepant) value is written to
the process image of the module with the lower address. This procedure is repeated until the
values once again match within the discrepancy time or until the discrepancy time of a bit
has expired.
If the discrepancy continues past the expiration of the configured discrepancy time, an error
has occurred.
The defective side is localized according to the following strategy:
1. During the discrepancy time, the most recent matching value is retained as the result.
2. Once the discrepancy time has expired, the following error message is displayed:
Error code 7960: "Redundant I/O: discrepancy time at digital input expired, error not yet
localized". Passivation is not performed and no entry is made in the static error image.
Until the next signal change occurs, the configured response is performed after the
discrepancy time expires.
3. If another signal change now occurs, the channel in which the signal change occurred is
the intact channel and the other channel is passivated.
Modules with diagnostics capability are also passivated by calling OB 82.
MTA terminal modules (Marshalled Termination Assemblies) can be used to connect field
devices, sensors and actuators to the I/O modules of the ET 200M remote I/O stations
simply, quickly and reliably. They can be used to significantly reduce the costs and required
work for cabling and commissioning, and prevent wiring errors.
The individual MTA terminal modules are each tailored to specific I/O modules from the
ET 200M range. MTA versions for standard I/O modules are also available, as for redundant
and safety-related I/O modules. The MTA terminal modules are connected to the I/O
modules using 3 m or 8 m long preassembled cables.
Details on combinable ET 200M modules and suitable connecting cables and on the current
MTA product range can be found at the following address: Update and expansion of the
MTA terminal modules (http://support.automation.siemens.com/WW/view/en/29289048)
signals to be different for longer
CPU 410 Process Automation/CPU 410 SMART
88System Manual, 05/2017, A5E31622160-AC
Page 89
I/O configuration variants
Using redundant digital input modules with non-redundant encoders
Note
Remember that the proximity switches (Beros) must provide the current for the channels of
both digital input modules. The technical specifications of the respective modules, however,
specify only the required current per input.
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
With non-redundant encoders, you use digital input modules in a 1-out-of-2 configuration:
Figure 6-14 Fault-tolerant digital input module in 1-out-of-2 configuration with one encoder
The use of redundant digital input modules increases their availability.
Discrepancy analysis detects "Continuous 1" and "Continuous 0" errors of the digital input
modules. A "Continuous 1" error means the value 1 is applied permanently at the input; a
"Continuous 0" error means that the input is not energized. This can be caused, for example,
by a short-circuit to L+ or M.
The current flow over the chassis ground connection between the modules and the encoder
should be the minimum possible.
When connecting an encoder to several digital input modules, the redundant modules must
operate at the same reference potential.
If you want to replace a module during operation and are not using redundant encoders, you
will need to use decoupling diodes.
If you do not use terminal modules, see the interconnection examples in the Appendix
Connection examples for redundant I/Os (Page 391).
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
89
Page 90
I/O configuration variants
Using redundant digital input modules with redundant encoders
Redundant digital output modules
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
With redundant encoders, you use digital input modules in a 1-out-of-2 configuration:
Figure 6-15 Fault-tolerant digital input modules in 1-out-of-2 configuration with two encoders
The use of redundant encoders also increases their availability. A discrepancy analysis
detects all errors, except for the failure of a non-redundant load voltage supply. You can
enhance availability by installing redundant load power supplies.
You will find interconnection examples in Appendix Connection examples for redundant I/Os
(Page 391).
Fault-tolerant control of a final controlling element can be achieved by connecting two
outputs of two digital output modules or fail-safe digital output modules in parallel (1-out-of-2
configuration).
Figure 6-16 Fault-tolerant digital output modules in 1-out-of-2 configuration
The digital output modules must be connected to a common load voltage supply.
If you do not use terminal modules, see the interconnection examples in the Appendix
Connection examples for redundant I/Os (Page 391).
CPU 410 Process Automation/CPU 410 SMART
90System Manual, 05/2017, A5E31622160-AC
Page 91
I/O configuration variants
Using analog input modules as redundant I/O
Note
The time that the system actually needs to determine a discrepancy de
factors: Bus runtimes, cycle times and call times of the user program, conversion times, etc.
For this reason, it is possible for redundant input signals to be different for longer than the
configured discrepancy time.
Note
There is no
underflow with 16#8000. The relevant channel is passivated immediately.
You should therefore disable all unused inputs in HW Config using the "Measurement type"
parameter.
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
You specified the following parameters when you configured the analog input modules for
redundant operation:
● Tolerance window (configured as a percentage of the end value of the measuring range)
Two analog values are considered equal if they are within the tolerance window.
● Discrepancy time (maximum permitted time in which the redundant input signals can be
outside the tolerance window). The specified discrepancy time must be a multiple of the
update time of the process image and therefore also the basic conversion time of the
channels.
An error is generated when there is an input value discrepancy after the configured
discrepancy time has expired.
If you connect identical sensors to both analog input modules, the default value for the
discrepancy time is usually sufficient. If you use different sensors, in particular
temperature sensors, you will have to increase the discrepancy time.
● Applied value
The applied value represents the value of the two analog input values that is applied to
the user program.
The system verifies that the two read-in analog values are within the configured tolerance
window. If they are, the applied value is written to the lower data memory area of the process
input image. If there is a discrepancy and it is the first, it is marked accordingly and the
discrepancy time is started.
When the discrepancy time is running, the most recent valid value is written to the process
image of the module with the lower address and made available to the current process. If the
discrepancy time expires, the channel with the configured standard value is declared as valid
and the other channel is passivated. If the maximum value from both modules is configured
as the standard value, this value is then taken for further program execution and the other
channel is passivated. If the minimum value is set, this channel supplies the data to the
process and the channel with the maximum value is passivated. Whichever is the case, the
passivated channels are entered in the diagnostic buffer.
If the discrepancy is eliminated within the discrepancy time, analysis of the redundant input
signals is still carried out.
pends on various
discrepancy analysis when a channel reports an overflow with 16#7FFF or an
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
91
Page 92
I/O configuration variants
Redundant analog input modules with non-redundant encoder
Redundant analog input modules for indirect current measurement
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
With non-redundant encoders, analog input modules are used in a 1-out-of-2 configuration:
Figure 6-17 Fault-tolerant analog input modules in 1-out-of-2 configuration with one encoder
Remember the following when connecting an encoder to multiple analog input modules:
● Connect the analog input modules in parallel for voltage sensors (left in figure).
● You can convert a current into voltage using an external load to be able to use voltage
analog input modules connected in parallel (center in the figure).
● 2-wire transmitters are powered externally to allow you to repair the module online.
The redundancy of the fail-safe analog input modules enhances their availability.
If you do not use terminal modules, see the interconnection examples in the Appendix
Connection examples for redundant I/Os (Page 391).
The following applies to the wiring of analog input modules:
● Suitable encoders for this circuit are active transmitters with voltage output and
thermocouples.
● The "wire break" diagnostics function in HW Config must not be enabled either the
modules are operated with transmitters or when thermocouples are connected.
● Suitable encoder types: active 4-wire and passive 2-wire transmitters with output ranges
+/-20 mA, 0 to 20 mA, and 4 to 20 mA. 2-wire transmitters are powered by an external
auxiliary voltage.
● Criteria for the selection of resistance and input voltage range are the measurement
accuracy, number format, maximum resolution and possible diagnostics.
● In addition to the options listed, other input resistance and voltage combinations
according to Ohm’s law are also possible. However, note that the number format,
diagnostic capability and resolution may then be lost. The measurement error also
depends largely on the size of the measure resistance of certain modules.
● Use a measure resistance with a tolerance of +/- 0.1% and TC 15 ppm.
CPU 410 Process Automation/CPU 410 SMART
92System Manual, 05/2017, A5E31622160-AC
Page 93
I/O configuration variants
Additional conditions for specific modules
Resistor
50 ohms
250 ohms
Current measuring range
+/-20 mA
+/-20 mA *)
4...20 mA
Measuring range cube position
"A"
"B"
Resolution
12 bits + sign
12 bits + sign
12 bits
S7 number format
x
x
- 1 input
"Wire break" diagnostics
- - x *)
Load for 4-wire transmitters
50 ohms
250 ohms
Input voltage for 2-wire transmitters
> 1.2 V
> 6 V
*) The AI 8x12bit outputs diagnostic interrupt and measured value "7FFF" in the event of wire break.
Resistor
250 ohms *)
Current measuring range
+/-20 mA
4...20 mA
Input range to be assigned
+/-5 V
1...5 V
Resolution
15 bits + sign
15 bits
S7 number format
x
- 1 input
"Wire break" diagnostics
-
x
Load for 4-wire transmitters
250 ohms
Input voltage for 2-wire transmitters
> 6 V
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
AI 8x12 bit 6ES7 331-7K..02-0AB0
● Use a 50 ohm or 250 ohm resistor to map the current on a voltage:
Input range to be assigned +/-1 V +/-5 V 1...5 V
Circuit-specific measuring error
- 2 parallel inputs
-
-
0.5%
0.25%
The listed measuring error results solely from the interconnection of one or two voltage
inputs with a measure resistance. Allowance has neither been made here for the tolerance
nor for the basic/operational limits of the modules.
The measuring error for one or two inputs shows the difference in the measurement result
depending on whether two inputs or, in case of error, only one input acquires the current of
the transmitter.
AI 8x16 bit 6ES7 331-7NF00-0AB0
● Use a 250 ohm resistor to map the current on a voltage:
Circuit-specific measuring error
- 2 parallel inputs
*) It may be possible to use the freely connectible internal module 250 ohm resistors
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
-
-
93
Page 94
I/O configuration variants
Redundant analog input modules for direct current measurement
Redundant analog input modules with redundant encoders
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
The following applies for wiring analog input modules:
● Suitable encoder types: active 4-wire and passive 2-wire transmitters with output ranges
+/-20 mA, 0 to 20 mA, and 4 to 20 mA. 2-wire transmitters are powered by an external
auxiliary voltage.
● The "wire break" diagnostics function supports only the 4...20 mA input range. All other
unipolar or bipolar ranges are excluded in this case.
● Suitable diodes include the types of the BZX85 or 1N47..A series (1.3 W Zener diodes)
with the voltages specified for the modules. When selecting other elements, make sure
that the reverse current is as low as possible.
● A fundamental measuring error of max. 1 µA results from this type of circuit and the
specified diodes due to the reverse current. In the 20 mA range and at a resolution of
16 bits, this value leads to an error of < 2 bits. Individual analog inputs in the circuit above
lead to an additional error, which may be listed in the constraints. The errors specified in
the manual must be added to these errors for all modules.
● The 4-wire transmitters used must be capable of driving the load resulting from the circuit
above. You will find details in the technical specifications of the individual modules.
● When connecting 2-wire transmitters, please note that the Zener diode circuit weighs
heavily in the power budget of the transmitter. The required input voltages are therefore
included in the technical specifications of the individual modules. Together with the
inherent supply specified on the transmitter data sheet, the minimum supply voltage is
calculated to L+ > U
e-2w
+ U
IS-TR
With double-redundant encoders, it is better to use fail-safe analog input modules in a 1-outof-2 configuration:
Figure 6-18 Fault-tolerant analog input modules in 1-out-of-2 configuration with two encoders
The use of redundant encoders also increases their availability.
A discrepancy analysis also detects external errors, except for the failure of a non-redundant
load voltage supply.
You will find interconnection examples in Appendix Connection examples for redundant I/Os
(Page 391).
The general comments made at the beginning of this documentation apply.
CPU 410 Process Automation/CPU 410 SMART
94System Manual, 05/2017, A5E31622160-AC
Page 95
I/O configuration variants
Redundant analog output modules
Analog output signals
Note
The output value drops briefly to half, and after
the proper value. The duration of the output value drop is determined by the following time
intervals:
•
•
•
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
You implement fault-tolerant control of a final controlling element by wiring two outputs of two
analog output modules in parallel (1-out-of-2 configuration)
Figure 6-19 Fault-tolerant analog output modules in 1-out-of-2 configuration
The following applies to the wiring of analog output modules:
● Wire the ground connections in a star structure to avoid output errors (limited common-
mode suppression of the analog output module).
If you do not use terminal modules, see the interconnection examples in the Appendix
Connection examples for redundant I/Os (Page 391)
Only analog output modules with current outputs (0 to 20 mA, 4 to 20 mA) can be operated
redundantly.
The output value is divided by 2, and each of the two modules outputs half. If one of the
modules fails, the failure is detected and the remaining module outputs the full value. As a
result, the surge at the output module in the event of an error is not as high.
Time interval between the initial occurrence of an interrupt and the interrupt report
reaching the CPU.
Time interval until the next RED_OUT (FB 451) call.
Time interval until the intact analog output module has doubled the output value.
the reaction in the program it is returned to
In the case of passivation or a CPU STOP, redundant analog outputs output an assignable
minimum current of approximately 120-1000 μA per module (or 240-1000 μA for HART
analog output modules), i.e., a total of approximately 240-2000 µA (or 480-2000 μA for
HART analog output modules). Considering the tolerance, this means that the output value
is always positive.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
95
Page 96
I/O configuration variants
Note
If both channels of a channel pair were passivated (e.g., by OB 85), the respective half of the
current value is still output to both storage locations in the process image of outputs. If one
channel is depassivated, then the full value is output on the available channel. If this is not
required, a substitute value must be writte
executing FB 451 "RED_OUT".
Depassivation of modules
Note
When a redundant module is assigned a process image partition and the corresponding OB
is not available on the CPU, the complete passivation process may take approximately 1
minute.
See also
6.7 Connection of two-channel I/O to the PROFIBUS DP interface
A configured substitute value of 0 mA will produce at least these output values. In a
redundant configuration of analog outputs, the substitute value of the current outputs is
automatically set permanently to "zero current and zero voltage". You can also specify a
configurable compensation current of 0-400 µA for an output range of 4-20 mA.
This means you have the option of matching the minimum/compensation current to the
connected I/O.
To minimize the error of the total current at the summing point in case of one-sided
passivation, the assigned compensation current is subtracted in this case from the current of
the depassivated (i.e., active) channel with a pre-set value of 4 mA (range +-20 µA).
n to the lower channels of both modules prior to
Passivated modules are depassivated by the following events:
● When the fault-tolerant system starts up
● When the fault-tolerant system switched to "redundant" mode
● After system modifications during operation
● If you call FC 451 "RED_DEPA" and at least one redundant channel or module is
passivated.
The depassivation is executed in FB 450 "RED IN" after one of these events has occurred.
Completion of the depassivation of all modules is logged in the diagnostics buffer.
SIMATIC Process Control System PCS 7 Released Modules
(https://support.industry.siemens.com/cs/ww/de/view/109736547/en)
S7-400H Systems Redundant I/O
(http://support.automation.siemens.com/WW/view/en/9275191)
CPU 410 Process Automation/CPU 410 SMART
96System Manual, 05/2017, A5E31622160-AC
Page 97
I/O configuration variants
6.7.3
Evaluating the passivation status
Procedure
Evaluating the passivation status using the status byte
Evaluating the passivation status of individual module pairs by means of MODUL_STATUS_WORD
6.8
Media redundancy
Note
Support of PRP (Parallel Redundancy Protocol) or MRPD (Media Redundancy Protocol
Domain) does not equal MRP functionality or vice versa.
6.8 Media redundancy
First, determine the passivation status by evaluating the status byte in the status/control
word "FB_RED_IN.STATUS_CONTROL_W". If you see that one or more modules have
been passivated, determine the status of the respective module pairs in
MODUL_STATUS_WORD.
The status word "FB_RED_IN.STATUS_CONTROL_W" is located in the instance DB of FB
450 "RED_IN". The status byte returns information on the status of the redundant I/Os. The
assignment of the status byte is described in the online help for the respective block library.
MODUL_STATUS_WORD is an output parameter of FB 453 and can be interconnected
accordingly. It returns information on the status of individual module pairs.
The assignment of the MODUL_STATUS_WORD status byte is described in the online help
for the respective function block library.
Media redundancy is a function for ensuring network availability and thus contributes to
increasing the plant availability. Redundant transmission links in a ring topology ensure that
an alternative communication path is always available if a transmission link fails. Following a
fault in one transmission link, data traffic can resume over the alternative link after a
maximum reconfiguration time of 200 ms.
For the components involved, you can enable the media redundancy protocol (MRP) in HW
Config. The components (IO devices, switches) must support MRP. MRP is a component of
the PROFINET IO standardization according to IEC 61158.
In the case of media redundancy with MRP, one device is specified as the media
redundancy manager (MRM) in HW Config. All other devices are redundancy clients.
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
97
Page 98
I/O configuration variants
Configuration
Configuration
Properties
The nodes connected to PROFINET IO must be assigned unique names.
The nodes on the fieldbus (PROFINET IO) must be assigned unique names.
Installing a ring topology
Note
The real
the ring exceeds the selected watc
whose IO data is transmitted over a ring.
6.8 Media redundancy
The following figure shows examples of the connection of IO devices to the PROFINET IO
system:
①
②
Media redundancy
Each node is connected to two other nodes in a ring configuration.
The IO controller must be configured as an MRP manager in HW Config.
Media redundancy + system redundancy
The PROFINET IO system begins and ends at one IO controller each in this example.
Each node is connected to two other nodes in a ring configuration.
The MRP parameter assignment must be complete. If a PROFINET IO system is created at each PN IO
connection of the CPU, a newly inserted interface module is automatically connected to the PROFINET IO
system of the CPU.
To set up a ring topology with media redundancy, you must join both free ends of a line
network topology in the same device. You join the line topology to form a ring via two ports
(ring ports, port ID "R") of a device connected to the ring.
The data paths between the individual devices are automatically reconfigured if the ring is
interrupted at any point. The devices are available again after reconfiguration.
-time communication is interrupted (station failure) when the reconfiguration time of
hdog time of the IO devices. This applies to all IO devices
CPU 410 Process Automation/CPU 410 SMART
98System Manual, 05/2017, A5E31622160-AC
Page 99
I/O configuration variants
Note
Before physically joining the ring together, download the configuration of your project to the
individual devices.
Topology
Additional information
6.8 Media redundancy
You can also combine media redundancy under PROFINET IO with other PROFINET IO
functions.
For additional information, refer to the STEP 7 Online Help and to Manual PROFINET
System Description (http://support.automation.siemens.com/WW/view/en/19292127).
CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
99
Page 100
I/O configuration variants
6.8 Media redundancy
CPU 410 Process Automation/CPU 410 SMART
100System Manual, 05/2017, A5E31622160-AC
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.