Overview: Combining System and Media Redundancy in a PROFINET Network
A SIMATIC S7-400H system with a CPU 410-5H provides system redundancy (two redundant controllers in hot standby, with the H-CiR mechanism, redundant PROFINET interfaces, and a sync link). Media redundancy at the physical layer is a different concern: it protects the network from the failure of a single cable, connector, or unmanaged switch by closing a physical ring and using the Media Redundancy Protocol (MRP) defined in IEC 61158 Type 10 (PROFINET).
This article answers a recurring question: can a 410-5H H-station with four ET 200M stations (IM 153-4) achieve both system redundancy and media redundancy without a SCALANCE switch, and if so, what topology is the most cost-efficient? It also documents the configuration procedure in STEP 7 V5.x / TIA Portal, role assignment, port assignments, and the verification steps required before commissioning.
The protocol behavior described here is the standard MRP client/manager model used by all PROFINET devices that conform to IEC 61158-6-10. The Siemens-specific configuration objects (MRP roles, ring ports, domain, MRP interconnection) are defined in the PROFINET IO device description (GSD) and in STEP 7 / TIA Portal under the device properties of each PROFINET node.
Prerequisites
- SIMATIC S7-400H with CPU 410-5H (firmware V8.x or higher recommended for PROFINET System Redundancy with MRP, current firmware per Siemens Product Support). Verify the exact firmware with the Siemens Online Support entry for 6ES7410-5HX08-0AB0.
- Four ET 200M stations with IM 153-4 PN (6ES7153-4BA00-0AB0 or higher; PROFINET IO devices). Each IM 153-4 must be configured as an MRP-capable PROFINET device. The IM 153-4 supports MRP as a client and as a manager, depending on the GSD file revision.
- STEP 7 V5.5 SP4 / SP5 with HSPs installed, or TIA Portal V15.1 and newer with the S7-400H option package, depending on the engineering toolchain in use.
- Every switch, controller and PROFINET device inside the ring must support MRP per IEC 61158-6-10. Devices that do not support MRP must not be inserted into the ring because they will break the reconfiguration sequence.
- One and only one MRP Manager (MRM) per ring. All other PROFINET devices are MRP Clients (MRC). A device configured as MRC and one configured as MRM is the standard pattern.
- Industrial Ethernet cabling: copper (100 Mbps, full-duplex) PROFINET-compatible cable, or fiber with PROFINET media converters rated for MRP. The ring ports must be set to 100 Mbps full-duplex with auto-negotiation disabled, otherwise MRP test frames may be lost.
Topology Options for an S7-400H with Four ET 200M Stations
Option A: Open Star (Line) Topology
Connect the two PROFINET interfaces of the CPU 410-5H (port X1 P1R and X1 P2R, or the two PROFINET IO interfaces of the H-system) to the two PROFINET ports of the IM 153-4 stations, and cascade the four IM 153-4 stations in a line. This is the simplest topology. It provides line redundancy only if the H-system's redundant PROFINET interfaces are wired so that one interface connects to one end of the line and the other to the other end, which is itself a ring without the formal MRP configuration. In practice, line topology alone does not provide media redundancy unless the line is closed into a ring.
Option B: Closed Ring with One MRM and Four MRCs (No SCALANCE)
Close the line into a physical ring by connecting the last IM 153-4 back to the first PROFINET interface of the 410-5H. Configure the CPU's PROFINET interface 1 (or a designated IM 153-4) as the MRM. Configure every other PROFINET node as MRC. This topology is fully functional with the 410-5H + IM 153-4 hardware alone, and it is the cost-minimized solution when SCALANCE is not required for any other reason (no MRP Interconnect, no diagnostic buffer, no non-MRP device attached).
Option C: Closed Ring with a SCALANCE as MRM
Insert a SCALANCE XC/XB/XR/XC-200/XC-300 as the dedicated MRM, with all other devices (CPU 410-5H interfaces and IM 153-4 stations) as MRCs. This is the recommended topology when a SCALANCE is already present in the plant, when MRP Interconnect is needed, or when the ring is to be segmented into redundant sub-rings. The SCALANCE provides additional diagnostic visibility (LLDP topology, port statistics, SNMP).
| Topology | System Redundancy | Media Redundancy | SCALANCE Required? | Reconfiguration Time | Recommended Use |
|---|---|---|---|---|---|
| A. Open line / star | Yes (H-system) | No | No | N/A | Small non-critical segments |
| B. Ring without SCALANCE | Yes (H-system) | Yes (MRP) | No | ≤ 200 ms (typical < 50 ms) | Cost-minimized 410-5H + ET 200M networks |
| C. Ring with SCALANCE MRM | Yes (H-system) | Yes (MRP) | Yes (1 unit) | ≤ 200 ms (typical < 50 ms) | Networks with MRP Interconnect or advanced diagnostics |
PROFINET MRP Roles, Frames, and State Machine
MRP is described in IEC 61158-6-10 (Type 10, PROFINET) and IEC 62439-2. The relevant objects and frame types are:
- MRP Manager (MRM): One per ring. Sends MRP_Test frames on both ring ports, detects link changes, and reconfigures the ring by blocking one ring port in the redundant state. The MRM is always a switch, or the integrated PROFINET switch of a controller (the 410-5H PROFINET interface acts as a managed 2-port switch).
- MRP Client (MRC): Forwards MRP_Test frames but does not take configuration actions. Every other ring member must be an MRC.
- MRP Test frame: Multicast, destination MAC 01:15:4E:00:00:01, EtherType 0x88E3. Used to detect ring breaks.
- MRP Topology Change frame: Multicast, destination MAC 01:15:4E:00:00:02. Used to flush MAC tables after a reconfiguration.
The two ring states are:
- Redundancy Available: Ring closed, one ring port of the MRM is blocked. No break in the ring; no traffic is forwarded through the blocked port. The MRM continues to send MRP_Test frames.
- Redundancy Lost / Reconfiguring: The MRM detects that a ring port has lost link or that test frames are not returning. The MRM unblocks its previously blocked port, restoring line topology across the entire ring. After reconfiguration, all FDB entries must be relearned. The MRP Topology Change frame flushes the MAC tables of the MRCs.
Topology Mapping for a 410-5H + 4 × IM 153-4 Network
The 410-5H provides two PROFINET interfaces, each of which is a 2-port switch. The PROFINET topology object in STEP 7 / TIA Portal describes which physical port of each device is connected to which physical port of the next device. The order is:
- 410-5H PROFINET interface 1, port 1 (X1 P1) → IM 153-4 #1 port 1
- IM 153-4 #1 port 2 → IM 153-4 #2 port 1
- IM 153-4 #2 port 2 → IM 153-4 #3 port 1
- IM 153-4 #3 port 2 → IM 153-4 #4 port 1
- IM 153-4 #4 port 2 → 410-5H PROFINET interface 1, port 2 (X1 P2) — closes the ring
The H-system's second PROFINET interface (X2) connects to the same ring, or is used as the system-redundancy channel. In the simplest configuration, both 410-5H CPUs each have one PROFINET interface connected to the ring; the ring contains the CPU 410-5H (interface X1 on CPU 0 and X1 on CPU 1, or two separate ring instances if isolation is required).
Step-by-Step Configuration in STEP 7 V5.5 (H-System)
This procedure is for the engineering tool STEP 7 V5.5 SP4 / SP5 with the S7-400H option package installed. The TIA Portal workflow is similar in concept and is described in the next section.
Step 1: Create the H-Station
- Insert a SIMATIC H-Station in the project. Select CPU 410-5H (article number 6ES7410-5H…).
- Configure the H-system CPU parameters: H-CPU sync link, the H-Station configuration, and the redundant PROFINET interface parameters.
- Set the PROFINET IO system for the H-Station. Configure the PROFINET interface X1 of the 410-5H as the IO controller for the ring.
Step 2: Add the ET 200M Stations
- In the PROFINET IO system, insert four IM 153-4 PN devices.
- For each IM 153-4, assign a device name and a unique IP address. Use the device-name convention of the plant, e.g.
et200m-001,et200m-002,et200m-003,et200m-004. - Assign the IM 153-4 to the H-CPU's PROFINET IO system. Configure PROFINET IO redundancy mode S2 for System Redundancy if both H-CPUs are to communicate with each IM 153-4. (Not all IM 153-4 firmware versions support S2; verify the firmware release.)
Step 3: Configure the Topology Editor
- Open the Topology Editor. For each device, specify the two port interconnections that form the ring.
- Set the port speed and duplex to 100 Mbps full-duplex for every ring port. Disable auto-negotiation if the port allows it.
- Save and compile. The topology is downloaded to the IO controller at the next download.
Step 4: Configure MRP Roles
- Open the PROFINET interface properties of the CPU 410-5H (interface X1).
- On the MRP tab, set the role to Manager. Specify the two ring ports: port 1 and port 2 of the X1 interface.
- For each IM 153-4, open its PROFINET interface properties, MRP tab, and set the role to Client. Specify the two ring ports (port 1 and port 2 of the IM 153-4's PROFINET interface).
- If a SCALANCE is inserted as the dedicated MRM (Option C), set the SCALANCE MRP role to Manager and set every other device to Client.
Step 5: Download and Assign Device Names
- Compile the H-station and the PROFINET IO system.
- Download the H-system to the 410-5H pair.
- Use the Assign PROFINET Device Name tool to assign the configured device names to each IM 153-4 (via MAC address or topology discovery).
- Verify the IO devices are online and AR (Application Relationship) is established for both H-CPUs.
Step-by-Step Configuration in TIA Portal (V15.1 and Newer)
- Add a SIMATIC S7-400H device with CPU 410-5H to the project.
- Add four ET 200M stations from the catalog: drag IM 153-4 PN into the PROFINET IO system of the H-CPU.
- Open the Devices & Networks editor, select the PROFINET subnet, and click Topology view.
- Draw the interconnections in the topology view: each port to port.
- Select the H-CPU's PROFINET interface. In the inspector window, Properties > PROFINET interface > MRP: enable MRP, role = MRP Manager, ring port 1 = port 1, ring port 2 = port 2.
- For each IM 153-4 PROFINET interface, enable MRP, role = MRP Client, ring port 1 = port 1, ring port 2 = port 2.
- Compile, then download to the H-station. Assign device names. Verify in the online diagnostics that MRP is active.
Verification: Confirming the MRP Ring is Functional
After commissioning, run the following checks. All are mandatory before handing the system over to operations.
- Online diagnostics > PROFINET > Topology: every port is connected to exactly one neighbor; the topology matches the engineering data.
- Online diagnostics > PROFINET > MRP: the MRM reports ring state Redundancy available. All MRCs report the MRM MAC address. The MRM's blocked port is identified.
- Cable break test: disconnect one cable in the ring. Observe that the MRM unblocks its previously blocked port within 200 ms. PROFINET IO devices do not drop. The H-system stays in RUN. Reconnect the cable. The MRM blocks the configured ring port and resumes test frame exchange. The IO devices must not drop during the entire test.
- Link-loss test on a ring port of an MRC: this is a partial cable break. The ring remains closed by the MRM, but the topology has changed. The MRP Topology Change frame must flush the FDBs of all MRCs. Verify that no IO device logs a communication error.
- H-system failover test: with the ring closed, stop the active H-CPU. The standby CPU takes over. PROFINET IO devices do not drop because of H-system redundancy. The MRP ring is not affected by the H-system failover because MRP runs on the ring ports and not on the H-system sync link.
- Combined test: with the active H-CPU stopped, simultaneously break a ring cable. Verify that the standby H-CPU takes over and the MRP ring reconfigures without losing IO connectivity.
Parameter Reference: MRP Tab in STEP 7 / TIA Portal
| Parameter | Value (MRM) | Value (MRC) | Comment |
|---|---|---|---|
| MRP role | Manager | Client | Exactly one MRM per ring |
| Ring port 1 | Port 1 of the device's PROFINET interface | Port 1 of the device's PROFINET interface | Physical port number, e.g. X1 P1 |
| Ring port 2 | Port 2 of the device's PROFINET interface | Port 2 of the device's PROFINET interface | Physical port number, e.g. X1 P2 |
| MRP domain | default (1) | default (1) | All devices in one ring must be in the same MRP domain |
| Test frame interval | 10 ms (default) | N/A | IEC 61158 default |
| Topology change reaction | Enabled | Enabled | MRCs flush FDBs on reception of MRP_TC |
| Diagnostic alarms | Enabled | Enabled | Ring break alarms on the controller |
Interaction Between H-System Redundancy and MRP
The H-system provides:
- CPU redundancy: two CPU 410-5H modules in hot-standby, one active, one standby. Failover time is typically in the low seconds for the H-system to switch over, with bumpless handover of the PROFINET IO controllers.
- PROFINET System Redundancy (PN-S2): an ET 200M assigned in PROFINET IO mode S2 has ARs to both H-CPUs. If the active H-CPU fails, the standby H-CPU continues the AR with the ET 200M. The ET 200M does not see an AR abort; the user program is not affected.
MRP is independent of the H-system. MRP provides cable-fault tolerance on the physical layer of the ring. When a ring cable breaks, MRP reconfigures the ring in ≤ 200 ms; the PROFINET IO traffic continues through the MRM's previously blocked port. When a CPU fails, the H-system switches the active CPU; MRP is unaffected because the ring ports of the failed CPU are taken over by the now-active CPU's PROFINET interface (or, in the case of two redundant PROFINET interfaces per H-system, the redundancy manager and MRM roles may be re-evaluated per the configuration).
Troubleshooting Matrix: Common Issues with PROFINET MRP on a 410-5H Network
| Symptom | Likely Cause | Action |
|---|---|---|
| MRP state shows "Redundancy not available" immediately after startup | Ring not closed; cable missing between last IM 153-4 and the 410-5H | Verify physical cabling. Check that topology editor matches the physical cabling. |
| MRP state oscillates between available and not available | Intermittent link; bad connector; EMI | Replace cable, check connector crimp, check for noise sources near the cable path. |
| PROFINET IO device drops during a cable break test | IO watchdog time too short; update time too short; MRP reconfiguration time exceeds watchdog | Increase the update time on the IO device, or increase the watchdog factor. Verify MRP test frame interval and timeout are at IEC defaults (10 ms / 30 ms). |
| Ring has SCALANCE but MRP still does not start | SCALANCE is in MRP role "Manager" but the 410-5H is also configured as Manager; duplicate MRM | Set the SCALANCE to Manager and the 410-5H to Client, or vice versa. Exactly one MRM per ring. |
| MRP test frames lost on a ring port | Port speed/duplex mismatch; auto-negotiation interfering with full-duplex | Hard-code 100 Mbps full-duplex on all ring ports. |
| MRP interrupts IO traffic after H-system failover | The PROFINET interface of the failed CPU was the MRM; the new active CPU has the role configured but the role change has a small delay | Move the MRM role to a non-CPU device (a SCALANCE) to avoid MRM hand-over during H-system failover. Document the failover impact in the system manual. |
| MRP works during steady-state but does not recover after cable break | The blocked port of the MRM is on the same device as the failed link; the unblocking did not propagate | Check the ring port status LEDs on the MRM. Verify with a network capture that MRP_TC frames are received on the new ring topology. |
| IM 153-4 logs "MRP manager detected" but ring is not in redundancy | A device that does not support MRP is in the ring; it does not forward MRP test frames | Remove all non-MRP devices from the ring. Use a SCALANCE to attach non-MRP devices as a spur. |
Frequently Asked Questions
Do I need a SCALANCE switch to run PROFINET MRP with a 410-5H CPU?
No. MRP is defined in IEC 61158-6-10 and is supported by the 410-5H PROFINET interfaces and by the IM 153-4 PROFINET interface. A ring with the 410-5H as the MRP Manager and the four IM 153-4 stations as MRP Clients is fully functional without a SCALANCE. A SCALANCE is required only if you need MRP Interconnect (MRPD), redundant rings, advanced port diagnostics, or if you need to attach non-MRP devices to the ring.
How many MRP Managers can a ring have?
Exactly one. The MRP standard specifies that a single MRM controls the ring. The MRM sends test frames on both ring ports and blocks one port in the redundant state. Configuring a second device as MRM in the same ring is a configuration error and is reported by the diagnostic system. The Siemens engineering tools (STEP 7 and TIA Portal) warn at compile time if multiple MRMs are detected.
What is the MRP reconfiguration time on a 410-5H + IM 153-4 ring?
Worst case 200 ms, typical under 50 ms, with the default MRP test frame interval of 10 ms and timeout of 30 ms. The PROFINET IO watchdog on each IM 153-4 must be set to a value greater than the maximum reconfiguration time. For ET 200M, an update time of 1 ms with a watchdog factor of 100 gives a 100 ms watchdog, which is sufficient. Reduce the test frame interval only if the application requires it and the network is sized for the additional load.
Can the 410-5H and the IM 153-4 stations run PROFINET System Redundancy (S2) and MRP at the same time?
Yes. The two mechanisms are independent. PROFINET S2 provides AR redundancy to both H-CPUs. MRP provides link redundancy on the ring. They stack: if the active H-CPU fails, the standby H-CPU continues the S2 ARs without interruption; if a ring cable breaks, MRP reconfigures the ring without affecting the S2 ARs. The H-system failover does not depend on MRP, and MRP reconfiguration does not depend on the H-system state.