Configuring SMH2Gi Watchdog and Boiler Safety Chain

David Krause6 min read
Other ManufacturerSafety SystemsTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Use the SMH2Gi watchdog and expansion-module safe mode to place outputs in defined states after an execution or communication failure, but do not make either feature the sole boiler protection. Route the critical temperature, pressure, airflow, and burner safety contacts through an independent, de-energize-to-trip permissive chain; use separate contacts to report their status to controller digital inputs. This architecture removes burner permission even when the controller stops scanning or continues to hold an obsolete command.

Symptom Interpretation

A controller failure can leave the burner power-demand signal at its last value. If heat demand then falls, the boiler can continue receiving an excessive firing command. A temperature or pressure relay connected only to a digital input cannot stop that condition when the application program no longer evaluates the input.

Observed symptom Engineering meaning Required response
Program values and outputs stop changing The controller scan or output update path may have stopped. Use the controller watchdog, then verify the actual output transition during a forced failure.
Expansion I/O communication disappears The controller can no longer command the affected module. Configure and test that module's safe mode.
Measurement inputs repeat plausible old values The input conversion path may be stale even though communications continue. Use independent limit devices and plausibility diagnostics; a communications watchdog alone will not detect this condition.
A safety relay changes state but only a digital input sees it The trip still depends on controller execution. Add an electrically independent contact to the burner permissive or safety chain.

Failure Mechanism

The term watchdog here means a timer that expects periodic service from a functioning controller or module. If servicing stops, the watchdog initiates its configured fault response. The SMH2Gi controller and each expansion module have separate watchdog facilities, so controller execution and module operation are distinct failure domains.

On loss of communication, expansion modules enter safe mode. Their output states are configurable. The stated defaults are open discrete outputs and analog outputs at 0 V. Treat those defaults as commissioning data, not as proof of a safe burner state: an open contact is safe only when the field circuit is wired so loss of energy removes permission, and 0 V is safe only when the receiving burner controller interprets it accordingly.

A stale-input failure is different. An analog-to-digital converter can continue operating and transmitting while repeatedly returning old measurements until its power is removed. Communication remains healthy, so neither a bus-loss response nor a simple communications watchdog detects the frozen process value. Independent temperature and pressure limit contacts break this dependency.

Independent Safety Architecture

Build the critical trip path outside the normal SMH2Gi application. Wire the safety devices through intermediate relays with isolated contacts: one contact set reports each state to a controller digital input, while another forms the hardwired burner permissive. The diagnostic contact supports alarms and orderly shutdown logic; the permissive contact performs the trip without waiting for a program scan.

Use a de-energize-to-trip circuit so a broken wire, lost control supply, released relay, or opened limit contact removes permission. Where the burner package contains the fuel shutoff devices internally, interrupt the designated external safety-chain supply or permissive interface rather than attempting to replace its internal sequence. Confirm that interface from the burner wiring documentation.

Signals selected for the independent chain must follow the boiler hazard assessment. The installation described calls out temperature and pressure relays; combustion-air fan operation and a flue thermostat are additional candidates identified for this class of application. Do not add an arbitrary delay to a protective trip. Use a time relay only when the burner design and applicable requirements call for delayed action, and obtain the delay from the required safety function rather than inventing a value.

Configuration Procedure

  1. Document every safety-related input, its normal energized state, its trip state, and the physical burner interface it must remove. Separate protective trips from ordinary operating interlocks.
  2. Assign two electrically isolated relay contacts where controller indication and independent shutdown are both required. Wire the indication contact to the SMH2Gi digital input and the shutdown contact into the burner safety or permissive chain.
  3. Configure each expansion module's safe mode. Set every discrete output to the state that removes its field permission. Set each analog output to the receiver-defined safe demand; use 0 V only after confirming the burner response to that signal.
  4. Configure the watchdog in the SMH2Gi controller and separately in each applicable expansion module. Read the selectable timeout and recovery action from the configuration interface or product documentation; no timeout value is established here.
  5. Program normal logic to react to the digital-input copies of the safety contacts. Generate the alarm, remove the run command, and perform the burner package's normal shutdown request before the independent chain acts when the required sequence permits it.
  6. Define restart behavior. A watchdog reset, restored network link, or returned limit contact must not create an unintended burner start. Require the normal permissives and the burner package's required reset sequence before restoring operation.
  7. Record the configured fault state beside each output on the I/O schedule and electrical drawings. The documented state must match the measured terminal state during commissioning.

Verification Checks

  1. Check 1: Open each critical field safety contact. Expect the hardwired burner permissive to de-energize without dependence on an SMH2Gi program action. Expect the corresponding digital input to change state for alarm reporting.
  2. Check 2: Interrupt communication to each expansion module. Expect the module to enter safe mode, its configured discrete outputs to open or assume their assigned safe states, and its analog outputs to reach their assigned values. Measure at the module terminals and at the burner interface.
  3. Check 3: Trigger the controller watchdog under a controlled commissioning test. Expect the configured controller fault response and loss of burner permission. Confirm the burner does not retain the previous power-demand command as an active firing request.
  4. Check 4: Simulate a stale process measurement. Hold or substitute an unchanged analog value while changing the independently sensed condition. Expect the physical limit device to remove permission even though the controller value remains plausible.
  5. Check 5: Restore power, communication, and safety contacts. Expect outputs to remain non-starting until all normal permissives and required resets are satisfied. Verify that recovery does not generate an automatic burner start.

Recurring Design Pitfalls

Wrong practice Why it fails Correction
Connecting every safety device only to controller inputs A stopped scan cannot process the trip. Provide an independent contact in the burner permissive chain.
Calling every frozen value a controller freeze A stale converter can keep communicating while repeating old data. Compare independent limits and process response rather than relying only on communications health.
Leaving module fault states at defaults without a field test Open discrete outputs or 0 V may not command a safe state at the receiver. Verify polarity and receiver behavior at the actual terminals.
Using one watchdog as coverage for all failure domains The controller, communication link, module, input conversion path, and burner package fail differently. Test each layer separately and retain the hardwired protective path.
Restoring permission immediately after fault recovery Returned communications can reapply a command before the plant is ready. Require normal permissives and the defined reset sequence.

FAQ

Can I use the SMH2Gi watchdog as the only boiler safety?

No. Use it to drive outputs to configured fault states, but route critical temperature, pressure, and combustion permissives through an independent de-energize-to-trip chain.

Does SMH2Gi expansion I/O have a safe mode?

Yes. Loss of communication places the expansion modules in safe mode; the stated defaults are open discrete outputs and analog outputs at 0 V. Configure every channel and verify its effect at the burner interface.

Can I verify boiler shutdown by watching the PLC input?

No. For the final verification, open each field safety contact and expect the physical burner permissive to de-energize while the controller application is unable to issue the trip.

Back to blog