Configuring Siemens 6ES7336-4GE00-0AB0 F-AI: PROFIsafe Addressing

David Krause15 min read
Safety SystemsSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: The Addressing Anomaly

When engineers first drop the Siemens SM 336F fail-safe analog input module (order number 6ES7 336-4GE00-0AB0) into an S7-300F station in STEP 7 HW Config — or into TIA Portal as a PROFIsafe GSD device — they typically see something unexpected in the address overview: the configurator reserves both input (I) and output (Q) addresses for a module whose only role is to read analog process values into the F-CPU. A 24-channel fail-safe digital input may report only 3 bytes of input channels yet occupy 10 bytes total. The SM 336F behaves the same way.

This is not a configurator bug, slot mismatch, or hardware fault. It is a direct consequence of the PROFIsafe protocol architecture, the safety profile layered on top of PROFIBUS-DP and PROFINET IO to achieve SIL 3 / Category 4 functional safety per IEC 61508 and ISO 13849-1. PROFIsafe wraps each cyclic payload with bidirectional safety metadata — a control byte, a status byte, a CRC signature, and a sequence counter — and that metadata must live somewhere in the process image, in both directions.

Every Siemens F-AI or F-DI module reserves additional output bytes, and every F-DQ module reserves additional input bytes, regardless of whether the application code uses those bytes. The application code only reads the "real" input words or writes the "real" output words, which are always the lowest addresses in the module's address range. The remainder is managed by the F-library at runtime.

Module Identification and PROFIsafe Fundamentals

The SM 336F (6ES7 336-4GE00-0AB0) is the fail-safe analog input module for the SIMATIC S7-300F and ET 200S distributed I/O families. Its catalog metadata determines the address layout:

Parameter Value
Order number (MLFB) 6ES7 336-4GE00-0AB0
Family SIMATIC S7-300F / ET 200S
Module class F-AI (Fail-safe Analog Input)
Channel count 6 analog inputs
Functional safety class SIL 3 / Category 4 (per IEC 61508 / EN 954-1)
Default PROFIsafe profile V2 (24-bit CRC, 16-bit sequence counter)
Diagnostic concept Channel-level: wire break, short circuit, overflow, underflow
Configuration tool STEP 7 V5.x HW Config (native), TIA Portal via GSD/GSDML

The same PROFIsafe addressing principles apply to the S7-1200F family, the S7-1500F successor module 6ES7536-1MF00-0AB0 (F-AI 8xI 0(4)…20 mA for ET 200MP, released per the Siemens Support delivery release note), and to the ET 200SP HF F-AI family documented in the Siemens S7-1200 F-Signal Modules Manual Collection. Cross-vendor equivalents such as the Allen-Bradley FLEX 5000 analog safety I/O modules use the same architectural pattern under CIP Safety rather than PROFIsafe.

PROFIsafe is the safety bus profile defined by PROFIBUS & PROFINET International (PI) for both PROFIBUS-DP and PROFINET IO. It is a black-channel implementation: the safety protocol travels alongside standard cyclic I/O data on the same physical network, without requiring a separate cable. Each PROFIsafe slot adds the following fields to its cyclic payload, regardless of whether the slot is an input, output, or mixed module:

  • Control byte (1 byte, F-CPU → F-device) — host-side commands such as "passivate channel," "activate integrator," "operator acknowledgment," "iPar server request."
  • Status byte (1 byte, F-device → F-CPU) — quality flags including "value valid" (FV), "channel passivated," "fault present," and vendor-specific diagnostic bits.
  • CRC signature (24 bits in V1/V2, 32 bits in V2.6) — cyclic redundancy check computed over the payload, the sequence counter, and the configured F-source / F-destination address.
  • Sequence counter (16 bits in V1/V2, 32 bits in V2.6) — incremented each cycle on both sides; mismatch triggers channel passivation.

Because the control byte is written by the F-CPU and read back by the F-device for verification, and the status byte is written by the F-device and read by the F-CPU, the PROFIsafe slot necessarily occupies both directions of the process image. This is true even on a pure input module, because the control byte still flows F-CPU → F-AI.

The control byte is the mechanism the F-CPU uses to issue safety-relevant commands such as reintegration after a detected error. The status byte lets the F-AI flag channel passivation, overflow, short circuit, or wire-break faults back to the F-CPU. Neither byte carries the user's analog process value — both carry safety transport metadata only.

Why F-AI Modules Reserve Output Addresses

A standard (non-safe) SM 336 analog input module contributes only input words (IW) to the process image: the channel readings. The fail-safe SM 336F adds the PROFIsafe wrapper, which means the slot must carry:

  1. The user's analog input words (6 channels × 16 bits = 12 bytes of process data).
  2. The PROFIsafe status byte (input direction).
  3. The PROFIsafe CRC-24 bytes (input direction).
  4. The PROFIsafe sequence counter bytes (input direction).
  5. The PROFIsafe control byte (output direction).
  6. Reserved output bytes for CRC echo and iPar-server cycling (output direction).

These fields are placed at the top of the slot's address range, then the user's process data follows. The result in HW Config is shown below for a representative slot starting at IW 256 / QB 256:

Address offset Direction Content Used by application?
IW 256…IW 266 Input (read by CPU) Channels 0…5, 16-bit analog value Yes — read via F-library block
IB x (status) Input PROFIsafe status byte (FV bit, passivation flags) No — handled by F-library
IB x+1…IB x+3 Input PROFIsafe CRC-24 bytes No
IB x+4…IB x+5 Input Sequence counter (16-bit) No
QB y Output PROFIsafe control byte No
QB y+1…QB y+3 Output Reserved / CRC echo No

The user application never touches the reserved bytes. The Siemens F-library blocks (for example the F-AI driver blocks within the S7 F-Library / Distributed Safety F-Library) and the F-runtime group manage them transparently. Manually overwriting these addresses is a frequent cause of "value invalid" and channel passivated errors at commissioning.

Memory Layout Examples

To illustrate the byte expansion, the SM 326F 24-channel F-DI reports only 3 bytes of "real" input channels (24 bits = 3 bytes) yet occupies 10 bytes total in HW Config. The breakdown is approximately:

Byte offset Direction Function
IB 0 Input Channel bits 0..7 (real input data)
IB 1 Input Channel bits 8..15 (real input data)
IB 2 Input Channel bits 16..23 (real input data)
IB 3 Input PROFIsafe status byte
IB 4 Input CRC-24 byte 0 (low)
IB 5 Input CRC-24 byte 1 (middle)
IB 6 Input CRC-24 byte 2 (high)
IB 7 Input Sequence counter byte 0
IB 8 Input Sequence counter byte 1
IB 9 Input Reserved
QB 0 Output PROFIsafe control byte
QB 1 Output Reserved / CRC echo

This expansion — 3 bytes of channel data inflated to 10 bytes of input plus reserved output bytes — is the visual signature of PROFIsafe in the address overview.

For the SM 336F (6ES7 336-4GE00-0AB0) with 6 analog inputs at 16-bit resolution, the user-data portion is 6 × 2 = 12 bytes. Adding the PROFIsafe overhead (status + CRC-24 + sequence counter + reserved), the slot consumes roughly 18 bytes of input plus several output bytes. A representative allocation starting at IW 512:

Address Direction Function
IW 512–IW 522 Input Channels 0..5 (real analog values)
IB 524 Input PROFIsafe status byte
IB 525–IB 527 Input CRC-24
IB 528–IB 529 Input Sequence counter (16-bit)
QB 512 Output PROFIsafe control byte
QB 513–QB 515 Output Reserved / CRC echo

The exact offset of the safety wrapper depends on the slot's start address and the PROFIsafe profile version. TIA Portal's device view shows the breakdown directly; STEP 7 V5.x shows the total input and output byte count per slot in the "Addresses" tab.

Always verify the precise layout by opening the slot's object properties in HW Config (or the device view in TIA Portal) and selecting "I/O addresses." The displayed start address is the user's first channel; the additional bytes are reserved automatically and must not be used for anything else.

PROFIsafe Profile Versions and F-Monitoring Time

The PROFIsafe profile is selected in HW Config's object properties for the F-CPU's PROFIBUS / PROFINET interface (or in the device configuration of the F-CPU in TIA Portal). The selection matters for both the wire format and the addressing overhead:

Profile CRC length Sequence counter Notes
V1 24-bit (CRC-24) 16-bit Legacy; widely supported on S7-300F / S7-400F
V2 24-bit (CRC-24) 16-bit Default for SM 336F (6ES7 336-4GE00-0AB0)
V2.4 24-bit (CRC-24) 16-bit Adds iPar (iParameter) device-side parameter server support
V2.6 32-bit (CRC-32) 32-bit Used by S7-1500F and successor F-modules including 6ES7536-1MF00-0AB0

If a profile mismatch is configured between the F-CPU and the F-AI, the slot will not pass data. Symptom: "Channel passivated" / "PROFIsafe communication error." Always match the profile on both sides, and re-issue the PROFIsafe F-source / F-destination address pair when swapping modules.

PROFIsafe runs a watchdog on each side: the F-CPU expects a fresh valid payload from the F-device within F_WD_TIME, and the F-device expects a fresh control byte from the F-CPU within F_WD_TIME. If either side times out, the corresponding channels passivate to safe-state substitute values. A common commissioning guideline from the PI PROFIsafe System Description is:

F_WD_TIME > 2 × T_bus + T_jitter

where T_bus is the worst-case bus cycle time (PROFINET update time or PROFIBUS DP cycle) and T_jitter accounts for non-isochronous jitter on the network. For PROFINET IRT with isochronous mode and a 1 ms update time, F_WD_TIME of 50–150 ms is typical. For PROFIBUS DP at 12 Mbit/s, F_WD_TIME of 100–500 ms is typical. Exact values must be validated against the F-CPU and F-module manuals; the formula above is a starting point.

Configuration in STEP 7 and TIA Portal

Configuration in STEP 7 V5.x HW Config (native for SM 336F):

  1. Open the S7-300F station in SIMATIC Manager → HW Config.
  2. Insert the SM 336F (6ES7 336-4GE00-0AB0) into the rack. Catalog path: SIMATIC 300 → SM-300 → F-SM-300 → 6ES7 336-4GE00-0AB0.
  3. Open the module's object properties. Note the start address for inputs and outputs; this is the address the application program uses for analog channel 0.
  4. On the F-CPU's PROFIBUS / PROFINET interface, open "PROFIsafe" and confirm the profile version matches the module's expected profile (default V2 for SM 336F).
  5. Assign the F-monitoring time. Confirm F_WD_TIME > 2 × T_bus + T_jitter.
  6. Assign the F-source and F-destination addresses. The F-destination address is set either by DIL switch on the module or via PROFIsafe address assignment (slot 0 in the slave).
  7. Compile and download the hardware configuration. The reserved input / output bytes appear automatically in the Address overview.
  8. Insert the F-library block into the F-runtime group and wire its ADDR_IN / ADDR_OUT parameters to the module's start address.

Configuration in TIA Portal (GSD-based, since SM 336F is not a native TIA Portal device):

  1. Open TIA Portal → Options → Manage general station description files (GSD). Install the SM 336F GSD.
  2. Add a PROFINET IO device / PROFIBUS DP slave in the device tree and select the SM 336F GSD entry.
  3. Configure the F-source / F-destination address pair in the slot properties (PROFIsafe tab).
  4. Set the PROFIsafe profile version (typically V2 for this module).
  5. Configure the F-monitoring time and assign the F-I/O DB number.
  6. Compile and download. The reserved bytes appear in the device view's "I/O addresses" tab.

Verification

After commissioning, open the F-AI's online diagnostics in STEP 7 (right-click → "Module Information" → "Diagnostics"). Expected states:

  • Module status: OK
  • PROFIsafe communication: OK
  • Channel quality: "value valid" (status byte FV bit = 1)
  • No passivated channels
  • Sequence counter incrementing on each cycle

If the F-AI shows passivated channels, the F-CPU's F-runtime group must call the F-AI driver block to re-integrate the channels. The reserved PROFIsafe bytes are written by the F-library during this reintegration — do not interfere with them.

Native TIA Portal configuration of S7-300F modules is not supported. The GSD-based workflow is the only path. For new projects, Siemens recommends the S7-1500F / ET 200MP family (e.g. 6ES7536-1MF00-0AB0) which is fully native in TIA Portal.

Channel Reintegration State Machine

Once a PROFIsafe channel has been passivated (because of a CRC error, watchdog timeout, or channel-level diagnostic), it must be re-integrated by the F-CPU before the application can use its value again:

State Trigger Action Next state
Data valid FV bit = 1, CRC OK Normal operation Data valid
Passivated FV bit = 0, or CRC error, or WD timeout F-library outputs substitute value Awaiting ACK
Awaiting ACK F-CPU application sets ACK = 1 on the F-block F-library writes control byte "ACK" Reintegration
Reintegration F-device receives ACK with valid CRC F-device re-enables channel, sets FV = 1 Data valid

Application engineers must wire the ACK input of the F-driver block to a deliberate operator action (for example an HMI button) — never auto-ACK. Auto-ACK defeats the diagnostic intent of the passivation and can mask intermittent faults that compromise safety.

Related Modules and Cross-Vendor Equivalents

The SM 336F is one member of the broader SIMATIC F-system family. Other commonly co-deployed safety modules and the cross-vendor equivalents:

Order number / family Platform Function Channel count
6ES7 336-4GE00-0AB0 S7-300F (SM 336F) F-AI 0/4…20 mA HF 6
6ES7536-1MF00-0AB0 S7-1500F / ET 200MP F-AI 0/4…20 mA (V2.6) 8
6ES7136-6PA00-0CA0 ET 200SP HF F-AI 0/4…20 mA 4
S7-1200 F-SM family S7-1200F F-DI / F-DQ / F-AI Varies; see S7-1200 F-Signal Modules Manual Collection
Allen-Bradley FLEX 5000 analog safety I/O Logix / CIP Safety F-AI / F-AO Varies; see Rockwell FLEX 5000 analog safety I/O release

All these modules exhibit the same input/output address expansion behavior; the byte count differs by channel count and PROFIsafe profile version. The CIP Safety wrapper used by the Allen-Bradley FLEX 5000 family is structurally analogous (mode byte + CRC-32 + sequence bits) and occupies assembly bytes in both directions for the same architectural reason.

Troubleshooting Matrix

Symptom Probable cause Remedy
"Channel passivated" on all inputs at startup PROFIsafe F-source / F-destination address mismatch Verify F-addresses match in F-CPU and F-module; re-issue
"Channel passivated" intermittent F_WD_TIME too tight or bus jitter Increase F_WD_TIME; verify F_WD_TIME > 2 × T_bus + T_jitter
"Value invalid" with valid wiring User program reads beyond the "real" input range into PROFIsafe status/CRC bytes Use only the lowest addresses per module; let F-library manage safety bytes
Output addresses appear in HW Config for an F-AI Normal — PROFIsafe control byte + CRC echo No action; do not write to these addresses manually
"PROFIsafe CRC error" logged repeatedly EMC disturbance or wrong profile version Check grounding and shielding; match profile V1/V2/V2.x on F-CPU and F-module
Module not detected in HW Config catalog HSP / GSD missing or outdated Install latest HSP for STEP 7 or GSD for TIA Portal; update hardware catalog
"iPar server request" bit set in status byte after module replacement iParameter mismatch between F-CPU and F-device Trigger iPar upload from F-CPU; confirm CRC check passes
Analog value stuck at 7FFFh Overflow / channel fault, FV bit = 0 Check wiring, sensor supply, and configured range; reintegrate after fix

Field Tips and Best Practices

  • Never edit the PROFIsafe control/status bytes from the user program. They are managed by the F-runtime group's F-library blocks. Touching them manually breaks the safety transport layer.
  • Reserve enough free address space in HW Config for the additional safety bytes — common mistake is to back the next module up against the F-AI's "real" channels and overlap the reserved safety bytes.
  • Document the module's reserved byte count in the project's "I/O address map" deliverable so commissioning engineers do not mistake them for free address ranges.
  • Wire the ACK input of the F-driver block to a deliberate operator action (HMI button with confirmation) — never auto-ACK. Auto-ACK defeats the diagnostic intent of passivation.
  • Validate F_WD_TIME against the actual measured bus cycle and jitter, not just theoretical values. Use the diagnostic buffer to log watchdog timeout events and tune accordingly.
  • When wiring 0/4…20 mA safety sensors to the SM 336F, observe polarity and use shielded twisted-pair cable. Channel-level diagnostics (wire break, short circuit) require the configured measurement range to match the sensor output — a sensor wired for 4…20 mA but configured for 0…20 mA will not report wire break correctly.

Migration to S7-1500F

For projects migrating from S7-300F to S7-1500F, the addressing expansion is the same in concept but the slot details change:

Parameter S7-300F SM 336F S7-1500F / ET 200MP F-AI
Order number 6ES7 336-4GE00-0AB0 6ES7536-1MF00-0AB0
Channels 6 8
Default PROFIsafe profile V2 (24-bit CRC) V2.6 (32-bit CRC)
Configuration tool STEP 7 V5.x HW Config / TIA Portal via GSD TIA Portal native
Address expansion Yes (control + status + CRC + sequence) Yes (same principle, slightly larger due to CRC-32)
Per-channel diagnostics Yes Yes (extended)
iPar server Optional Standard

The TIA Portal "Migrating S7-300/400 projects to S7-1500" toolset converts STEP 7 V5.x hardware configurations into TIA Portal V17+ device configurations, but the F-I/O DBs and the F-library blocks must be re-mapped to the new naming conventions and the new V2.6 PROFIsafe profile. Validate the migration with the Safety Acceptance Test before live operation.

FAQ

Why does HW Config reserve output addresses for a Siemens F-AI module?

The F-AI communicates with the F-CPU over PROFIsafe, which adds a control byte (F-CPU → F-AI) plus a CRC echo. Even though the F-AI is read-only from the process, the safety wrapper needs those output bytes. The F-library manages them — never write to them from user code.

Does my application program need to handle the PROFIsafe status and CRC bytes?

No. The Siemens F-library (F-runtime group) handles them transparently. The user program only reads the analog value words at the lowest addresses of the F-AI's address range and wires them to the F-library driver block.

What is the difference between PROFIsafe V1, V2, and V2.6?

V1 and V2 use a 24-bit CRC and 16-bit sequence counter. V2.4 adds iPar device-side parameter storage. V2.6 uses a 32-bit CRC and 32-bit sequence counter and is used by newer S7-1500 F-modules. Both ends of a PROFIsafe link must use the same profile version, otherwise the slot will not pass data.

Can I use the reserved safety bytes for other I/O?

No. The reserved input and output bytes are managed by the PROFIsafe stack and the F-library. Reusing them will corrupt the safety transport layer and cause channel passivation or CRC errors, violating SIL 3 / Category 4.

What replaces the SM 336F (6ES7 336-4GE00-0AB0) on S7-1500?

The successor is the S7-1500 / ET 200MP F-AI 8xI 0(4)…20 mA, order number 6ES7536-1MF00-0AB0. It uses PROFIsafe V2.6, supports 8 channels instead of 6, and provides per-channel diagnostics. The reserved safety byte pattern is the same in principle, but the addressing must be recomputed in TIA Portal. See the Siemens Support delivery release note for order details.

How is F_WD_TIME sized for the SM 336F on PROFINET?

Use F_WD_TIME greater than twice the worst-case bus cycle plus jitter (F_WD_TIME > 2 × T_bus + T_jitter). With PROFINET IRT at 1 ms update time and isochronous mode, 50–150 ms is typical. For PROFIBUS DP at 12 Mbit/s, 100–500 ms is typical. Validate against the actual diagnostic buffer.

Back to blog