Overview: The Addressing Anomaly
When engineers first drop the Siemens SM 336F fail-safe analog input module (order number 6ES7 336-4GE00-0AB0) into an S7-300F station in STEP 7 HW Config — or into TIA Portal as a PROFIsafe GSD device — they typically see something unexpected in the address overview: the configurator reserves both input (I) and output (Q) addresses for a module whose only role is to read analog process values into the F-CPU. A 24-channel fail-safe digital input may report only 3 bytes of input channels yet occupy 10 bytes total. The SM 336F behaves the same way.
This is not a configurator bug, slot mismatch, or hardware fault. It is a direct consequence of the PROFIsafe protocol architecture, the safety profile layered on top of PROFIBUS-DP and PROFINET IO to achieve SIL 3 / Category 4 functional safety per IEC 61508 and ISO 13849-1. PROFIsafe wraps each cyclic payload with bidirectional safety metadata — a control byte, a status byte, a CRC signature, and a sequence counter — and that metadata must live somewhere in the process image, in both directions.
Module Identification and PROFIsafe Fundamentals
The SM 336F (6ES7 336-4GE00-0AB0) is the fail-safe analog input module for the SIMATIC S7-300F and ET 200S distributed I/O families. Its catalog metadata determines the address layout:
| Parameter | Value |
|---|---|
| Order number (MLFB) | 6ES7 336-4GE00-0AB0 |
| Family | SIMATIC S7-300F / ET 200S |
| Module class | F-AI (Fail-safe Analog Input) |
| Channel count | 6 analog inputs |
| Functional safety class | SIL 3 / Category 4 (per IEC 61508 / EN 954-1) |
| Default PROFIsafe profile | V2 (24-bit CRC, 16-bit sequence counter) |
| Diagnostic concept | Channel-level: wire break, short circuit, overflow, underflow |
| Configuration tool | STEP 7 V5.x HW Config (native), TIA Portal via GSD/GSDML |
The same PROFIsafe addressing principles apply to the S7-1200F family, the S7-1500F successor module 6ES7536-1MF00-0AB0 (F-AI 8xI 0(4)…20 mA for ET 200MP, released per the Siemens Support delivery release note), and to the ET 200SP HF F-AI family documented in the Siemens S7-1200 F-Signal Modules Manual Collection. Cross-vendor equivalents such as the Allen-Bradley FLEX 5000 analog safety I/O modules use the same architectural pattern under CIP Safety rather than PROFIsafe.
PROFIsafe is the safety bus profile defined by PROFIBUS & PROFINET International (PI) for both PROFIBUS-DP and PROFINET IO. It is a black-channel implementation: the safety protocol travels alongside standard cyclic I/O data on the same physical network, without requiring a separate cable. Each PROFIsafe slot adds the following fields to its cyclic payload, regardless of whether the slot is an input, output, or mixed module:
- Control byte (1 byte, F-CPU → F-device) — host-side commands such as "passivate channel," "activate integrator," "operator acknowledgment," "iPar server request."
- Status byte (1 byte, F-device → F-CPU) — quality flags including "value valid" (FV), "channel passivated," "fault present," and vendor-specific diagnostic bits.
- CRC signature (24 bits in V1/V2, 32 bits in V2.6) — cyclic redundancy check computed over the payload, the sequence counter, and the configured F-source / F-destination address.
- Sequence counter (16 bits in V1/V2, 32 bits in V2.6) — incremented each cycle on both sides; mismatch triggers channel passivation.
Because the control byte is written by the F-CPU and read back by the F-device for verification, and the status byte is written by the F-device and read by the F-CPU, the PROFIsafe slot necessarily occupies both directions of the process image. This is true even on a pure input module, because the control byte still flows F-CPU → F-AI.
Why F-AI Modules Reserve Output Addresses
A standard (non-safe) SM 336 analog input module contributes only input words (IW) to the process image: the channel readings. The fail-safe SM 336F adds the PROFIsafe wrapper, which means the slot must carry:
- The user's analog input words (6 channels × 16 bits = 12 bytes of process data).
- The PROFIsafe status byte (input direction).
- The PROFIsafe CRC-24 bytes (input direction).
- The PROFIsafe sequence counter bytes (input direction).
- The PROFIsafe control byte (output direction).
- Reserved output bytes for CRC echo and iPar-server cycling (output direction).
These fields are placed at the top of the slot's address range, then the user's process data follows. The result in HW Config is shown below for a representative slot starting at IW 256 / QB 256:
| Address offset | Direction | Content | Used by application? |
|---|---|---|---|
IW 256…IW 266
|
Input (read by CPU) | Channels 0…5, 16-bit analog value | Yes — read via F-library block |
IB x (status) |
Input | PROFIsafe status byte (FV bit, passivation flags) | No — handled by F-library |
IB x+1…IB x+3
|
Input | PROFIsafe CRC-24 bytes | No |
IB x+4…IB x+5
|
Input | Sequence counter (16-bit) | No |
QB y |
Output | PROFIsafe control byte | No |
QB y+1…QB y+3
|
Output | Reserved / CRC echo | No |
The user application never touches the reserved bytes. The Siemens F-library blocks (for example the F-AI driver blocks within the S7 F-Library / Distributed Safety F-Library) and the F-runtime group manage them transparently. Manually overwriting these addresses is a frequent cause of "value invalid" and channel passivated errors at commissioning.
Memory Layout Examples
To illustrate the byte expansion, the SM 326F 24-channel F-DI reports only 3 bytes of "real" input channels (24 bits = 3 bytes) yet occupies 10 bytes total in HW Config. The breakdown is approximately:
| Byte offset | Direction | Function |
|---|---|---|
IB 0 |
Input | Channel bits 0..7 (real input data) |
IB 1 |
Input | Channel bits 8..15 (real input data) |
IB 2 |
Input | Channel bits 16..23 (real input data) |
IB 3 |
Input | PROFIsafe status byte |
IB 4 |
Input | CRC-24 byte 0 (low) |
IB 5 |
Input | CRC-24 byte 1 (middle) |
IB 6 |
Input | CRC-24 byte 2 (high) |
IB 7 |
Input | Sequence counter byte 0 |
IB 8 |
Input | Sequence counter byte 1 |
IB 9 |
Input | Reserved |
QB 0 |
Output | PROFIsafe control byte |
QB 1 |
Output | Reserved / CRC echo |
This expansion — 3 bytes of channel data inflated to 10 bytes of input plus reserved output bytes — is the visual signature of PROFIsafe in the address overview.
For the SM 336F (6ES7 336-4GE00-0AB0) with 6 analog inputs at 16-bit resolution, the user-data portion is 6 × 2 = 12 bytes. Adding the PROFIsafe overhead (status + CRC-24 + sequence counter + reserved), the slot consumes roughly 18 bytes of input plus several output bytes. A representative allocation starting at IW 512:
| Address | Direction | Function |
|---|---|---|
IW 512–IW 522
|
Input | Channels 0..5 (real analog values) |
IB 524 |
Input | PROFIsafe status byte |
IB 525–IB 527
|
Input | CRC-24 |
IB 528–IB 529
|
Input | Sequence counter (16-bit) |
QB 512 |
Output | PROFIsafe control byte |
QB 513–QB 515
|
Output | Reserved / CRC echo |
The exact offset of the safety wrapper depends on the slot's start address and the PROFIsafe profile version. TIA Portal's device view shows the breakdown directly; STEP 7 V5.x shows the total input and output byte count per slot in the "Addresses" tab.
PROFIsafe Profile Versions and F-Monitoring Time
The PROFIsafe profile is selected in HW Config's object properties for the F-CPU's PROFIBUS / PROFINET interface (or in the device configuration of the F-CPU in TIA Portal). The selection matters for both the wire format and the addressing overhead:
| Profile | CRC length | Sequence counter | Notes |
|---|---|---|---|
| V1 | 24-bit (CRC-24) | 16-bit | Legacy; widely supported on S7-300F / S7-400F |
| V2 | 24-bit (CRC-24) | 16-bit | Default for SM 336F (6ES7 336-4GE00-0AB0) |
| V2.4 | 24-bit (CRC-24) | 16-bit | Adds iPar (iParameter) device-side parameter server support |
| V2.6 | 32-bit (CRC-32) | 32-bit | Used by S7-1500F and successor F-modules including 6ES7536-1MF00-0AB0
|
If a profile mismatch is configured between the F-CPU and the F-AI, the slot will not pass data. Symptom: "Channel passivated" / "PROFIsafe communication error." Always match the profile on both sides, and re-issue the PROFIsafe F-source / F-destination address pair when swapping modules.
PROFIsafe runs a watchdog on each side: the F-CPU expects a fresh valid payload from the F-device within F_WD_TIME, and the F-device expects a fresh control byte from the F-CPU within F_WD_TIME. If either side times out, the corresponding channels passivate to safe-state substitute values. A common commissioning guideline from the PI PROFIsafe System Description is:
F_WD_TIME > 2 × T_bus + T_jitter
where T_bus is the worst-case bus cycle time (PROFINET update time or PROFIBUS DP cycle) and T_jitter accounts for non-isochronous jitter on the network. For PROFINET IRT with isochronous mode and a 1 ms update time, F_WD_TIME of 50–150 ms is typical. For PROFIBUS DP at 12 Mbit/s, F_WD_TIME of 100–500 ms is typical. Exact values must be validated against the F-CPU and F-module manuals; the formula above is a starting point.
Configuration in STEP 7 and TIA Portal
Configuration in STEP 7 V5.x HW Config (native for SM 336F):
- Open the S7-300F station in SIMATIC Manager → HW Config.
- Insert the SM 336F (
6ES7 336-4GE00-0AB0) into the rack. Catalog path: SIMATIC 300 → SM-300 → F-SM-300 →6ES7 336-4GE00-0AB0. - Open the module's object properties. Note the start address for inputs and outputs; this is the address the application program uses for analog channel 0.
- On the F-CPU's PROFIBUS / PROFINET interface, open "PROFIsafe" and confirm the profile version matches the module's expected profile (default V2 for SM 336F).
- Assign the F-monitoring time. Confirm
F_WD_TIME > 2 × T_bus + T_jitter. - Assign the F-source and F-destination addresses. The F-destination address is set either by DIL switch on the module or via PROFIsafe address assignment (slot 0 in the slave).
- Compile and download the hardware configuration. The reserved input / output bytes appear automatically in the Address overview.
- Insert the F-library block into the F-runtime group and wire its
ADDR_IN/ADDR_OUTparameters to the module's start address.
Configuration in TIA Portal (GSD-based, since SM 336F is not a native TIA Portal device):
- Open TIA Portal → Options → Manage general station description files (GSD). Install the SM 336F GSD.
- Add a PROFINET IO device / PROFIBUS DP slave in the device tree and select the SM 336F GSD entry.
- Configure the F-source / F-destination address pair in the slot properties (PROFIsafe tab).
- Set the PROFIsafe profile version (typically V2 for this module).
- Configure the F-monitoring time and assign the F-I/O DB number.
- Compile and download. The reserved bytes appear in the device view's "I/O addresses" tab.
Verification
After commissioning, open the F-AI's online diagnostics in STEP 7 (right-click → "Module Information" → "Diagnostics"). Expected states:
- Module status: OK
- PROFIsafe communication: OK
- Channel quality: "value valid" (status byte FV bit = 1)
- No passivated channels
- Sequence counter incrementing on each cycle
If the F-AI shows passivated channels, the F-CPU's F-runtime group must call the F-AI driver block to re-integrate the channels. The reserved PROFIsafe bytes are written by the F-library during this reintegration — do not interfere with them.
6ES7536-1MF00-0AB0) which is fully native in TIA Portal.Channel Reintegration State Machine
Once a PROFIsafe channel has been passivated (because of a CRC error, watchdog timeout, or channel-level diagnostic), it must be re-integrated by the F-CPU before the application can use its value again:
| State | Trigger | Action | Next state |
|---|---|---|---|
| Data valid | FV bit = 1, CRC OK | Normal operation | Data valid |
| Passivated | FV bit = 0, or CRC error, or WD timeout | F-library outputs substitute value | Awaiting ACK |
| Awaiting ACK | F-CPU application sets ACK = 1 on the F-block | F-library writes control byte "ACK" | Reintegration |
| Reintegration | F-device receives ACK with valid CRC | F-device re-enables channel, sets FV = 1 | Data valid |
Application engineers must wire the ACK input of the F-driver block to a deliberate operator action (for example an HMI button) — never auto-ACK. Auto-ACK defeats the diagnostic intent of the passivation and can mask intermittent faults that compromise safety.
Related Modules and Cross-Vendor Equivalents
The SM 336F is one member of the broader SIMATIC F-system family. Other commonly co-deployed safety modules and the cross-vendor equivalents:
| Order number / family | Platform | Function | Channel count |
|---|---|---|---|
6ES7 336-4GE00-0AB0 |
S7-300F (SM 336F) | F-AI 0/4…20 mA HF | 6 |
6ES7536-1MF00-0AB0 |
S7-1500F / ET 200MP | F-AI 0/4…20 mA (V2.6) | 8 |
6ES7136-6PA00-0CA0 |
ET 200SP HF | F-AI 0/4…20 mA | 4 |
| S7-1200 F-SM family | S7-1200F | F-DI / F-DQ / F-AI | Varies; see S7-1200 F-Signal Modules Manual Collection |
| Allen-Bradley FLEX 5000 analog safety I/O | Logix / CIP Safety | F-AI / F-AO | Varies; see Rockwell FLEX 5000 analog safety I/O release |
All these modules exhibit the same input/output address expansion behavior; the byte count differs by channel count and PROFIsafe profile version. The CIP Safety wrapper used by the Allen-Bradley FLEX 5000 family is structurally analogous (mode byte + CRC-32 + sequence bits) and occupies assembly bytes in both directions for the same architectural reason.
Troubleshooting Matrix
| Symptom | Probable cause | Remedy |
|---|---|---|
| "Channel passivated" on all inputs at startup | PROFIsafe F-source / F-destination address mismatch | Verify F-addresses match in F-CPU and F-module; re-issue |
| "Channel passivated" intermittent |
F_WD_TIME too tight or bus jitter |
Increase F_WD_TIME; verify F_WD_TIME > 2 × T_bus + T_jitter
|
| "Value invalid" with valid wiring | User program reads beyond the "real" input range into PROFIsafe status/CRC bytes | Use only the lowest addresses per module; let F-library manage safety bytes |
| Output addresses appear in HW Config for an F-AI | Normal — PROFIsafe control byte + CRC echo | No action; do not write to these addresses manually |
| "PROFIsafe CRC error" logged repeatedly | EMC disturbance or wrong profile version | Check grounding and shielding; match profile V1/V2/V2.x on F-CPU and F-module |
| Module not detected in HW Config catalog | HSP / GSD missing or outdated | Install latest HSP for STEP 7 or GSD for TIA Portal; update hardware catalog |
| "iPar server request" bit set in status byte after module replacement | iParameter mismatch between F-CPU and F-device | Trigger iPar upload from F-CPU; confirm CRC check passes |
Analog value stuck at 7FFFh
|
Overflow / channel fault, FV bit = 0 | Check wiring, sensor supply, and configured range; reintegrate after fix |
Field Tips and Best Practices
- Never edit the PROFIsafe control/status bytes from the user program. They are managed by the F-runtime group's F-library blocks. Touching them manually breaks the safety transport layer.
- Reserve enough free address space in HW Config for the additional safety bytes — common mistake is to back the next module up against the F-AI's "real" channels and overlap the reserved safety bytes.
- Document the module's reserved byte count in the project's "I/O address map" deliverable so commissioning engineers do not mistake them for free address ranges.
- Wire the
ACKinput of the F-driver block to a deliberate operator action (HMI button with confirmation) — never auto-ACK. Auto-ACK defeats the diagnostic intent of passivation. - Validate
F_WD_TIMEagainst the actual measured bus cycle and jitter, not just theoretical values. Use the diagnostic buffer to log watchdog timeout events and tune accordingly. - When wiring 0/4…20 mA safety sensors to the SM 336F, observe polarity and use shielded twisted-pair cable. Channel-level diagnostics (wire break, short circuit) require the configured measurement range to match the sensor output — a sensor wired for 4…20 mA but configured for 0…20 mA will not report wire break correctly.
Migration to S7-1500F
For projects migrating from S7-300F to S7-1500F, the addressing expansion is the same in concept but the slot details change:
| Parameter | S7-300F SM 336F | S7-1500F / ET 200MP F-AI |
|---|---|---|
| Order number | 6ES7 336-4GE00-0AB0 |
6ES7536-1MF00-0AB0 |
| Channels | 6 | 8 |
| Default PROFIsafe profile | V2 (24-bit CRC) | V2.6 (32-bit CRC) |
| Configuration tool | STEP 7 V5.x HW Config / TIA Portal via GSD | TIA Portal native |
| Address expansion | Yes (control + status + CRC + sequence) | Yes (same principle, slightly larger due to CRC-32) |
| Per-channel diagnostics | Yes | Yes (extended) |
| iPar server | Optional | Standard |
The TIA Portal "Migrating S7-300/400 projects to S7-1500" toolset converts STEP 7 V5.x hardware configurations into TIA Portal V17+ device configurations, but the F-I/O DBs and the F-library blocks must be re-mapped to the new naming conventions and the new V2.6 PROFIsafe profile. Validate the migration with the Safety Acceptance Test before live operation.
FAQ
Why does HW Config reserve output addresses for a Siemens F-AI module?
The F-AI communicates with the F-CPU over PROFIsafe, which adds a control byte (F-CPU → F-AI) plus a CRC echo. Even though the F-AI is read-only from the process, the safety wrapper needs those output bytes. The F-library manages them — never write to them from user code.
Does my application program need to handle the PROFIsafe status and CRC bytes?
No. The Siemens F-library (F-runtime group) handles them transparently. The user program only reads the analog value words at the lowest addresses of the F-AI's address range and wires them to the F-library driver block.
What is the difference between PROFIsafe V1, V2, and V2.6?
V1 and V2 use a 24-bit CRC and 16-bit sequence counter. V2.4 adds iPar device-side parameter storage. V2.6 uses a 32-bit CRC and 32-bit sequence counter and is used by newer S7-1500 F-modules. Both ends of a PROFIsafe link must use the same profile version, otherwise the slot will not pass data.
Can I use the reserved safety bytes for other I/O?
No. The reserved input and output bytes are managed by the PROFIsafe stack and the F-library. Reusing them will corrupt the safety transport layer and cause channel passivation or CRC errors, violating SIL 3 / Category 4.
What replaces the SM 336F (6ES7 336-4GE00-0AB0) on S7-1500?
The successor is the S7-1500 / ET 200MP F-AI 8xI 0(4)…20 mA, order number 6ES7536-1MF00-0AB0. It uses PROFIsafe V2.6, supports 8 channels instead of 6, and provides per-channel diagnostics. The reserved safety byte pattern is the same in principle, but the addressing must be recomputed in TIA Portal. See the Siemens Support delivery release note for order details.
How is F_WD_TIME sized for the SM 336F on PROFINET?
Use F_WD_TIME greater than twice the worst-case bus cycle plus jitter (F_WD_TIME > 2 × T_bus + T_jitter). With PROFINET IRT at 1 ms update time and isochronous mode, 50–150 ms is typical. For PROFIBUS DP at 12 Mbit/s, 100–500 ms is typical. Validate against the actual diagnostic buffer.