This manual is part of the documentation
package with the order number:
6ES7988-8FA10-8BA0
Edition 02/2003
A5E00085588-03
Check Lists
References
Glossary, Index
A
B
Safety Guidelines
This manual contains notices intended to ensure personal safety, as well as to protect the products and
connected equipment against damage. These notices are highlighted by the symbols shown below and
graded according to severity by the following texts:
!
!
!
Safety Note
Contains important information on the acceptance and safety-related use of the product.
Warning
indicates that death, severe personal injury or substantial property damage can result if proper
precautions are not taken.
Caution
indicates that minor personal injury can result if proper precautions are not taken.
Note
draws your attention to particularly important information on the product, handl i ng the product , or to a
particular part of the documentation.
Qualified Personnel
Only qualified personnel should be allowed to install and work on this equipment. Qualified persons are
defined as persons who are authorized to commission, to ground and to tag circuits, equipment, and
systems in accordance with established safety practices and standards.
The reproduction, transmission or use of this document or its
contents is not permitted without express written authority.
Offenders will be liable for damages. All rights, including rights
created by patent grant or registration of a utility model or design,
are reserved.
Siemens AG
Automation and Drives
Industrial Automation Systems
Postfach 4848, D- 90327 Nuern be rg
Siemens AktiengesellschaftA5E00085588-03
This device and its components may only be used for the applications described in the catalog or the
technical description, and only in connection with devices or components f rom other manufacturers
which have been approved or recommended by Siemens.
This product can only function correctly and safely if it is transported, stored, s et up, and install ed
correctly, and operated and maintained as recommended.
SIMATIC®, SIMATIC HMI® and SIMATIC NET® are registered trademarks of SIEMENS AG.
Some of the other designations used in these documents are also registered trademarks; the owner’s rights
may be violated if they are used by third parties for their own purposes.
Disclaimer of Liability
We have checked t he contents of this manual for agreem ent with
the hardware and s oftware described. Since de viations cannot be
precluded entirel y, we cannot guarantee full a greement. However,
the data in this m anual are reviewed regul arly and any necessary
corrections included in subsequent editions. Suggestions for
improvement are welcom e d.
The information contained in this manual enables you to configure and program S7
F/FH Systems using S7 F Systems V5.2.
Target Group
This manual is intended for system planners, configuration engineers and
programmers. Knowledge of STEP 7 and CFC is assumed in most areas.
Contents
This manual describes how to work with the S7 F/FH Systems using S7 F-Systems
V5.2 software. It consists of instructive chapters and reference chapters
(descriptions of the fail-safe function blocks and check lists for acceptance). The
manual covers the following topics:
• Safety Mechanisms
• Configuration
• Programming
• Maintenance
• Safety
• Fail-Safe Blocks
Scope of the Manual
The S7 F Systems V5.2
Options Package including
Authorization License V5.0
F-Copy License6ES7 833 1CC00 6YX0V5.0
ModuleOrder NumberAs of Version
6ES7 833 1CC00 0YX0V5.2
Fail-Safe Systems
A5E00085588-03iii
Important Information
What’s New?
The following changes are new in the S7 F Systems V5.2:
Topic Chapter
New Fail-Safe BlocksFail-Safe Blocks
Introduction to the F_Shutdown LogicGetting Started
Support of the new ET 200S failsafe modules to the S7 F/FH
Systems
Enhanced usabilityProgramming
Standards, Certificates and Approvals
The S7 FH System and the fail-safe F-I/O’s are certified for use in safety mode up
to the following levels:
Throughout the
document
•Requirement classes AK1 to AK6
DIN V VDE 0801
• SIL1 to SIL3 (Safety Integrity Level) in accordance with IEC 61508
• Categories 1 to 4 in accordance with EN 954-1
Place in the Information Landscape
This manual is part of the documentation package for the S7 F/FH System.
System Documentation Package Order Number
S7 F Systems• Safety Engineering in SIMATIC S7
• Programmable Controllers,
S7 F/FH Systems
• ET200 S Distributed I/O System Fail-
Safe Modules
• Automation Systems S7-300 Fail-Safe
Signal Modules
CD-ROM
in accordance with DIN V 19250/
6ES7988-8FB10-8BA0
You can also obtain all the SIMATIC S7 documentation as a dedicated SIMATIC
S7 collection on CD-ROM.
ivA5E00085588-03
Fail-Safe Systems
How to Use this Manual
To help you find specific information quickly, the manual contains the following
aids:
• There is a complete table of contents at the beginning of the manual.
• A heading indicating the contents of each section is provided in the left-hand
column on each page of each chapter.
•Following the appendices, you will find a glossary in which important technical
terms used in the manual are defined.
•At the end of the manual you will find a detailed index, which makes it easy for
you to find the information you are looking for.
Additional Support
For any unanswered questions about the use of products presented in this manual,
contact your local Siemens representative:
http://www.siemens.com/automation/partner
Important Information
Training Center
We offer courses to help you get started with the S7 automation system. Contact
your regional training center or the central training center in Nuremberg (90327),
Federal Republic of Germany.
Telephone:+49 (911) 895–3200
http://www.sitrain.com
H/F Competence Center
The H/F Competence Center in Nuremberg offers special workshops on SIMATIC
S7 fail-safe and fault-tolerant automation systems. The H/F Competence Center
can also provide assistance with onsite configuration, commissioning, and
troubleshooting.
8.16.1Run Times of the Fail-Safe Blocks................................................................8-141
ACheck ListsA-1
A.1 Life Cycle of the Fail-Safe Programmable Controllers..................................... A-1
A.2Check List of the Certified Modules ................................................................. A-5
A.3Check List of the Certified F-Blocks.................................................................A-7
A.4Check List of the Safety Parameters of the F-Drivers ................................... A-10
BReferencesB-1
GlossaryGlossary-1
IndexIndex-1
Fail-Safe Systems
A5E00085588-03
xv
Contents
Fail-Safe Systems
xviA5E00085588-03
1 Product Overview
1.1 Overview
SIMATIC S7 F/FH Systems
The S7 F/FH Programmable Controllers (F-Systems) are used in systems with
increased safety requirements. The aim of the S7 F/FH System is to control
processes that can immediately be returned to a safe state. In other words, when
these processes are suddenly shut down, it represents no danger to either man or
the environment.
Safety Requirements
The S7 F/FH System fulfills the following safety requirements:
•Requirement classes AK1 to AK6 in accordance with DIN V 19250/DIN V VDE
0801
•SIL1 to SIL3 (Safety Integrity Level)
•Categories 1 to 4 in accordance with EN 954-1
Principle Behind the Safety Functions
Fail-safe behavior is achieved by means of safety functions primarily in the
software. Safety functions are executed by the S7 F/FH programmable controller in
order to return the system to a safe state, or keep it in a safe state when a
hazardous event occurs.
The safety function for the process can be executed by means of a user safety
function or a fault reaction function. If the F-System can no longer execute its
actual user safety function in the event of a fault, it executes the fault reaction
function. For example, the associated outputs are switched off and the Safety
Program or parts of the Safety Program are disabled, if necessary.
For example: The F-System has to open a valve when there is excess pressure
(user safety function). In the event of a dangerous fault occurring in the CPU, all
the outputs are switched off (fault reaction function), thus opening the valve and
returning the other actuators to a safe state
valve would be opened.
in accordance with IEC 61508
. If the F-System were intact, only the
Fail-Safe Systems
A5E00085588-03
1-1
Product Overview
The safety functions are primarily incorporated in the following components:
•In the safety-related user program on the central processing unit
•In the fail-safe input/output modules
Safety and Availability
To increase the availability of the automation system and consequently avoid
process downtimes as a result of failures in the F-System, fail-safe systems can be
optionally configured for high availability (fault tolerance). This increased
availability can be achieved by means of redundant components (power supply,
central processing unit and communication and I/O systems).
The fail-safe and fault-tolerant S7 F/FH Systems allow production to continue
without causing any harm to people or the environment.
Use in Process Engineering
The figure below shows integration options for the S7 F/FH Systems in process
automation systems with PCS 7.
Fail-Safe Systems
1-2A5E00085588-03
Product Overview
Operator Stations (OS)
Central engineering system (ES)
PC
S7 F Sys
F-SMs
Standard SMs
ET 200M ET 200M
Standard SMs
ET 200S
Standard SMs
PC
PC
...
Standard Ethernet
Industrial Ethernet or PROFIBUS
S7-400H S7 FH Sys S7-400 Standard
F-SMs
F-SMs
ET 200M ET 200M
Boiler prot.
Emerg. stop
PC
Burner,
coal mill
Fail-Safe Systems
A5E00085588-03
1-3
Product Overview
7 F System
safe signal modules
1.2 Basic Configuration Variants
This section describes the two basic configuration variants of F-Systems:
•Fail-safe S7 F System
•Fail-safe, fault-tolerant S7 FH System
S7 F System
The S7 F System is a fail-safe automation system consisting of at least the
following components:
•An F-capable CPU module such as CPU 417-4 H that can run a fail-safe (F)
user program
•One or more fail-safe inputs/outputs (F-I/Os) in a distributed I/O device
(redundancy optional)
The following figure shows the hardware and software components of an F
System.
modules.
You can expand the configuration with standard S7-400 and S7-300
Operator Station
(system visualization)
Programming device
Programmable controller
S
ET 200M distributed I/O device
Fail-
(optionally redundant)
ET 200M distributed I/O device
Standard modules
(optionally redundant)
ET 200S distributed I/O device
Standard modules
Fail-Safe Systems
1-4A5E00085588-03
Product Overview
S7 FH System
The S7 FH System is a fail-safe, fault-tolerant automation system consisting of at
least the following components:
•A fault-tolerant S7 400H system (master and standby) running a fail-safe (F)
•One or more fail-safe inputs/outputs (F-I/Os) in a distributed I/O device
The following figure shows an example of an S7 FH configuration with a redundant
CPU, shared, switched distributed I/O modules connected via a redundant system
bus.
user program
(redundancy optional)
Redundant system bus (PROFIBUS or Ethernet)
Operator station
(System visualization)
Redundant
PROFIBUS - DP
Programmable controller
S7 FH System
ET 200M distributed I/O device
Fail - safe signal modules
(optionally redundant)
ET 200M distributed I/O device
Standard modules
(optionally redun dant)
Fail-Safe Systems
A5E00085588-03
1-5
Product Overview
Combination of Standard, Fault-Tolerant and Fail-Safe Components
Standard, fault-tolerant (H) and fail-safe (F) components and systems can be used
together as follows:
•Standard systems, H systems, F Systems and FH Systems can be used
together in a single system.
•Standard modules and F-I/Os can be used together in a single automation
system.
•A safety-related F user program can be run together with a non-safety-related
standard user program in a fail-safe (F) or fail-safe, fault-tolerant (FH) system.
The fact that fail-safe (F), fault-tolerant (H) and standard components can be
combined has the following advantages:
•You can set up a fully integrated automation system in which you can make
use of the innovation of the standard CPUs and, at the same time, use fail-safe
components independently of standard components such as FMs or CPs. You
can configure and program the whole system using standard tools such as
HWCONFIG and CFC.
•The fact that you can combine standard and fail-safe program parts in a single
CPU reduces acceptance costs because only fail-safe program parts are
subject to acceptance procedures. Maintenance costs can also be reduced by
locating as many functions as possible in the standard section, which can be
modified during operation.
Fail-Safe Systems
1-6A5E00085588-03
Product Overview
1.3 Components of an S7 F System
The figure below shows the hardware and software components required for the
configuration and operation of the S7 F.
S7 F programmable controller
F user program
Programming device
Optional package
S7 F Systems with
•
Configuration tool
•
F library
•
Safety program
editing
F run - time license
distributed I/O device
(optionally redundant)
F - I /Os
Interaction of the Components
The S7 F System consists of hardware and software components that have to be
combined with one another in order to configure an S7 F System.
Wiring the F-I/Os
The F-I/Os must be wired with the sensors and actuators in such a way as to
ensure that the desired safety level can be achieved.
Configuring the Hardware
The configuration set using HWCONFIG must correspond to the hardware
configuration; in other words, the circuit diagram of the I/O system must be
reflected in the parameter settings. The F-capable CPU must be configured.
Creating the F User Program
You create the fail-safe user program in CFC using fail-safe blocks from the
"Failsafe Blocks" library. For the connection to the F-I/Os you use F Channel and
Module driver blocks, to which you have to assign parameters. Some of the
parameters are assigned automatically as a result of the hardware configuration of
the F-I/Os.
When the executable F user program is generated, safety tests are carried out
automatically and additional fault detection functions incorporated.
Fail-Safe Systems
A5E00085588-03
1-7
Product Overview
Compatibility of standard and fail-safe components in a programmable logic
controller
If you use a safety protector in the ET 200M, then you can operate fail-safe signal
modules with the S7-300 standard signal modules in an ET 200M even in safetymode in SIL 3.
The safety protector protects the fail-safe signal modules from possible overvoltage
in the event of a fault. To do this, the fail-safe signal modules must be inserted in
the ET 200M configuration to the right of the safety protector, and all the standard
signal modules must be inserted to the left of the safety protector.
1.4 Hardware Components
An F System consists of hardware components that fulfill certain safety
requirements, such as:
•A CPU such as the CPU 417-4H with an F-Copy License
•F-I/Os
You can also expand the F System with standard components.
F-Capable CPUs
For S7 F/FH Systems, the CPU (e.g. the CPU 417-4 H as of V2.0) with an F-Copy
License is used either individually or as a fault-tolerant master/standby system.
The F-Copy License permits you to use the CPU as an F-CPU (i.e. to run a failsafe user program on it).
An F-capable CPU is a CPU that is approved for use in the S7 F/FH. It only
becomes an F-CPU if there is an F user program running on it. Otherwise, a
standard S7 program runs on the CPU. A combination of standard and F user
programs is possible because the safety-related data of the F user program is
protected from the influence of non-safety-related data. The CPU must be
configured as an F-CPU in this case as well.
Safety-relevant sections of the user program must be password-protected on the
CPU and in the ES/programming device against unauthorized access. In addition,
comprehensive self-tests run on the CPU. These ensure a high rate of fault
detection.
F-I/Os
The following F-I/Os are available:
For ET 200M:
•SM 326; DI 24 x 24 V DC; with Diagnostic Interrupt
•SM 326; DI 8 x NAMUR; with Diagnostic Interrupt
•SM 326; DO 10 x 24 V DC/2A, with Diagnostic Interrupt
•SM 336; AI 6 x 13Bit, with Diagnostic Interrupt
Fail-Safe Systems
1-8A5E00085588-03
Product Overview
ET 200M F-I/Os can be used in a single-channel or redundant configuration:
Please refer to the manual: Automation System S7-300 Fail-Safe Signal Modules’
For ET 200S:
•PM-E F 24 VDC PROFIsafe Power Module
•4/8 F-DI 24 VDC PROFIsafe Digital Electronic Mod ul e
•4 F-DO 24 VDC/2 A PROFIsafe Digital Electronic Module
•PM-D F PROFIsafe Power Module
Please refer to the manual: ET 200S Distributed I/O System, Fail-Safe Modules
Standard Components
The restrictions for fault-tolerant systems apply to the use of standard components.
You will find the restrictions for standard components in safety mode of fail-safe
signal modules in the safety information in Chapter 3 of the "S7-300 Programmable
Controller, Fail-Safe Signal Modules".
Additional Information
You can find detailed descriptions of the hardware components for the S7 F/FH
Systems in the following manuals:
•S7-400, M7-400 Programmab le Con tr ol lers , Insta llati on and Modu le Data
•S7-400H Programmable Controller, Fault-Tolerant Systems
•S7-300 Programmable Controller, Fail-Safe Signal Modules
The S7 F Systems have the following software components:
•S7 F Systems (Programming)
•S7 F Configuration Pack (Configuration of the F-I/O’s)
•The fail-safe user program (F user program) on the CPU
The S7 F Systems Optional Package
The S7 F Systems optional package is available for the configuration and
programming of the S7 F System. This gives you:
•Support for the configuration of the F-I/Os with HWCONFIG.
•The "Failsafe Blocks" library for the programming of fail-safe user programs.
•Support for the processing of the F user program and for the integration of fault
detection functions in the F user program.
Fail-Safe User Program
A fail-safe user program is referred to below simply as a Safety Program.
You create Safety Programs with CFC using the fail-safe blocks contained in a
library shipped with the S7 F Systems optional package. The fail-safe blocks
contain fault detection and fault reaction functions, as well as functions for
programming safety functions. In other words, they ensure that failures and faults
are detected and that an appropriate reaction is initiated that will keep the Fsystem in a safe state or return it to a safe state.
The user program on the CPU can be made up of safety-related sections (Safety
Program) and not safety-related sections (Standard Program). The Safety Program
is written in separate CFC charts. A combination of F and standard blocks in one
chart is not permissible and is detected during compilation. Data transfers between
the standard and the Safety Program are carried out via conversion blocks.
During compilation, certain fault detection and fault reaction functions are
automatically added to the Safety Program. The S7 F Systems optional package
also provides functions for comparing Safety Programs and supporting the
acceptance of Safety Program s .
Additional Information
You can find detailed information in the following sections.
•Configuration
•Programming
•Fail-Safe Blocks
and in the context-sensitive help information.
Fail-Safe Systems
1-10A5E00085588-03
Product Overview
1.6 Installing the S7 F Systems Optional Package
Before using an existing project with S7 F Systems V5.2, please read this entire
section which provides you with:
•getting started information applicable to the three use-case-scenarios
described below.
•the three use-case-scenarios are as follows, please select the one that best
suits your needs:
1. Compiling/editing current projects based on Failsafe Blocks (V1_1)
a. Upgrading a PC/Programming Device/Workstation containing S7 F
Systems V5.1 Optional Package
b. Installing S7 F Systems V5.2 Optional Package on a new
PC/Programming Device/Workstation
2. Upgrading current projects based on Failsafe Blocks (V1_1) to Failsafe Blocks
(V1_2)
3. Modifying or creating projects based on Failsafe Blocks (V1_2)
1.6.1 Getting Started Information Applicable to All Use-Case-Scenarios
Installing the Optional Package
1. Start the PC/Programming Device/Workstation that has the STEP 7 basic
software package installed. Make sure that there are no open STEP 7
applications.
2. Insert the optional package product CD.
3. Run the SETUP.EXE program on the CD.
4. Follow the setup program instructions.
Reading the Readme File
The readme file (S7 F Systems – Readme) contains important, up-to-date
information about the software. You can display this file on completion of the setup
program, or open it later using the Start > Simatic > Product Notes > English
menu command. It is located in the S7ftl directory of STEP 7.
Starting the Optional Package
The optional package does not contain any applications that have to be started
explicitly. Support for configuration and programming of the F-Systems is
integrated in SIMATIC Manager, HWCONFIG and CFC.
Fail-Safe Systems
A5E00085588-03
1-11
Product Overview
Displaying the Integrated Help System
Context-sensitive help information is available for the optional package dialog
boxes. Help can be displayed at any time during configuration or programming by
pressing F1, or clicking the Help button. You can obtain more help information by
choosing the Help > Contents > Calling Help on Optional Packages > S7-
400F/FH – Working with F Systems.
Authorization
Authorization is required for the S7 F Systems optional package. Authorization can
be installed in the same way as STEP 7 and the optional packages. You can find
information on how to install and work with the authorization component in the
readme file and in STEP 7’s main help system.
Note
SIMATIC S7 F Systems V5.0 lic en se al so su pports V5.2
F-Copy License
An F-Copy License permits you to use the CPU as an F-CPU (e.g. to run a Safety
Program on it).
1.6.2 Use-case-scenarios
Scenario 1: Compiling/Editing Current Projects based on Failsafe Blocks (V1_1)
1. a. Upgrading From S7 F-Systems V5.1 to S7 F-Systems V5.2 to Support
Failsafe Blocks (V1_1) Projects
Use this scenario if you have:
An existing PC/Programming Device/Workstation with S7 F Systems V5.1 Optional
Package installed, and you wish to use existing projects based on Failsafe Blocks
(V1_1).
Fail-Safe Systems
1-12A5E00085588-03
Product Overview
Software Requirements
The following software packages must be installed on the PC/programming device
in order to use, modify, or create projects based on Failsafe Blocks (V1_1) library
with S7 F Systems V5.2:
•S7 F Systems V5.2
•STEP 7 V5.1.3 or higher
•CFC V5.2.4
•S7 H Systems Optional Package V5.1or higher (required for S7 FH Systems)
Procedure
If S7 F Systems V5.1 is already installed, the projects based on Failsafe Blocks
(V1_1) library are supported without an y addit ional pr oc ed ures .
1.b. Installing S7 F Systems V5.2 on a New PC to Support Failsafe Blocks (V1_1)
Projects
Use this scenario if you have:
Purchased a new PC/Programming Device/Workstation, and you wish to use
projects based on Failsafe Blocks (V1_1) library.
Software Requirements
The following software packages must be installed on the PC/programming device
in order to use, modify, or create projects based on Failsafe Blocks (V1_1) library
with S7 F Systems V5.2:
•S7 F Systems V5.2
•STEP 7 V5.1.3 or higher
•CFC V5.2.4
•S7 H Systems Optional Package V5.1or higher (required for S7 FH Systems)
Procedure
1. If S7 F Systems V5.2 is installed, uninstall it.
2. Install S7 F Systems V5.1
3. Install S7 F Systems V5.2
4. If you had PCS7 Driver Blocks or PCS7 Library installed, you must also install
Use this scenario if you wish to:
Upgrade current projects based on Failsafe Blocks (V1_1) to the new Failsafe
Blocks (V1_2) library contained in S7 F Systems V5.2. You must have the
minimum software requirements to allow this.
Software/Firmware Requirements
The following software packages must be installed on the PC/Programming
Device/Workstation in order to upgrade projects based on Failsafe Blocks (V1_1)
library to Failsafe Blocks (V1_2):
•S7 F Systems V5.2
•STEP7 V5.2 or higher
•S7 H Systems Optional Package V5.1 or higher (required for S7 FH Systems)
•CFC V5.2.4
•CPU S7-417F/FH V3.1 or higher
ET 200S fail-safe module drivers are available, but this requires CFC V6.0.
Fail-Safe Systems
1-14A5E00085588-03
Loading...
+ 324 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.