For the DL05 windmill controller, adding a separate operating mode for every fault is the wrong fix; keep each turbine’s operating mode separate from its fault-tracking states. The revised design used additional offline/fault states to simplify the operating transitions. Three shortcuts still need correction before commissioning: packing all fault logic into every arrow makes transition priority hard to audit; relying on a cut-in RPM alone to close the grid relay does not verify electrical synchronization; and using one RPM threshold for both connection and disconnection invites rapid state changes near the threshold.
The first three-mode diagram was superseded. Treat the later design—with an additional software offline lockout and separate fault tracking—as the reference architecture, while verifying the actual program and output sequence on the controller. The project used a DL05 (DR model), an external HSIO card, discrete voltage/frequency/temperature signals, and a C-More Micro HMI to control two windmills.
Keep fault tracking out of the operating-mode state list
Do not create a complete operating-state copy for every possible fault. A temperature fault, voltage fault, or windspeed fault can all require the same immediate operating response, so modeling each as a new turbine mode duplicates transition logic and makes it easier for two paths to disagree. The design revision separated fault tracking from the windmill’s operating logic; the resulting fault/no-fault and fault-clear/not-clear status can then be checked by the operating states.
Also avoid one overloaded transition expression that mixes operator commands, sensor conditions, RPM comparisons, and timer exceptions. It may fit on one rung, but it obscures why a transition fired and makes it harder to verify that two competing transitions cannot be true at once. Keep the mode list small and make each transition condition explicit.
A third unsafe shortcut is treating an RPM threshold as proof that the machine is ready to connect to the utility. RPM can be an operating permissive for the controller, but it does not by itself establish the electrical conditions required for grid connection. Keep the grid connection decision separate and subject it to the approved interconnection and protection design.
Use operating modes for each turbine’s sequence
Use a compact operating sequence for each windmill, such as Offline, Freewheel, and Online, with a separate software lockout state if an operator must deliberately reset a fault. The source design described Offline as the stopped/braked condition, Freewheel as running but not connected to the grid, and Online as grid-connected operation. Define the output behavior for each state rather than inferring it from the state name.
The mode states answer “what is this turbine doing?” The independent fault stages answer “what condition is present, and has it cleared?” This division makes it possible to reuse the same fault evaluation for both turbines while applying the resulting status to each turbine’s own operating sequence. A stage bit also provides a direct way to see which fault-monitoring stage is active during troubleshooting.
The mechanical brake and grid relay are distinct outputs. Document their intended state in every operating mode and test the actual sequence used to open the relay and apply or release the brake. The source identifies the brake as the means to place a turbine offline and the relay as the grid connection; it does not specify their switching order, so define and validate that order for the installation rather than assuming it.
Make the five operating transitions mutually exclusive
Write transition conditions so every pair of competing paths has a clear priority. The original sequence gives a useful base:
| Transition | Condition to evaluate |
|---|---|
| Offline to Freewheel | Fault status is clear and no manual Offline command is active. |
| Freewheel to Offline | A required permissive becomes unhealthy, or the operator requests Offline. |
| Freewheel to Online | All required permissives remain healthy and measured alternator RPM exceeds the configured cut-in threshold. |
| Online to Freewheel | No higher-priority trip is active and RPM falls below the cut-out threshold after the configured cut-in/cutout delay logic. |
| Online to Offline | A fault or manual Offline command requires the turbine to leave service. |
Resolve fault/manual-stop priority ahead of RPM transitions. For example, if RPM is above cut-in during the same scan that voltage permissive becomes unhealthy, the fault path must win; the Online transition must not be able to override it. Likewise, state exactly whether the Freewheel-to-Online threshold uses “greater than” or “greater than or equal to.” The initial description says RPM greater than cut-in and RPM less than cut-out; implement the selected comparison consistently and record it for test.
Check every transition pair against combinations that can occur in one PLC scan. An engineer should be able to trace one set of input values to exactly one next state, not discover the outcome by watching which rung happens to write the state bit last.
Separate a recoverable fault from a manual lockout
A fault stage should evaluate the sensor/permissive conditions and expose whether faults are active and whether they have cleared. The operating mode then decides whether to remain offline, return to Freewheel, or permit Online operation. This avoids embedding fault-clear timers and reset rules in every mode transition.
The later design added an offline lockout state so that clearing a signal fault does not automatically restart a turbine that requires manual attention. It also described using a deliberate Offline-to-Standby action to reset a future fault timer. If a restart delay or manual reset is part of the final behavior, define exactly which condition starts the timer, what clears it, and whether an operator command can bypass it. The proposed high-temperature wait and reset behavior was an idea, not a confirmed implemented function.
The project’s failsafe-stage examples were “RPM greater than zero while the brake is set” as a possible brake problem and “windspeed equals zero while RPM is greater than zero” as a possible windspeed sensor problem. Treat these as plausibility checks, not universal fault definitions: confirm signal scaling, brake feedback, and sensor behavior first, then decide the thresholds and response. A zero reading can mean a stopped turbine or a failed sensor, depending on the other measured conditions.
Two additional ideas were still on the to-do list: lock out after three high-windspeed faults within ten minutes, and predict next-scan RPM from the average rise over five scans. Do not present either as existing logic. Before implementing one, define event counting, timer reset conditions, startup behavior, and behavior when a measurement is stale; test it independently from the core state transitions.
Keep threshold, hysteresis, and delay semantics distinct
The initial setpoints listed cut-in at 1805 RPM and cut-out at 1800 RPM for both turbines. Those values create a 5 RPM gap. Although the same description also says the thresholds would ideally be the same, the listed defaults are not equal. Preserve the gap if the approved operating design calls for that hysteresis; otherwise document the commissioned values and the reason for changing them. Separate thresholds prevent noisy or fluctuating RPM near one boundary from repeatedly switching modes.
The initial cut-in delay was 250 ms. Its stated purpose was to ignore a brief RPM drop below cut-out immediately after connecting the grid, when the added load could reduce alternator speed. Limit that exception to the specified cut-out RPM test: do not let a timer suppress a voltage, frequency, temperature, high-windspeed, or manual-stop fault. Define whether the timer begins on the transition request or confirmed relay state and test the timeout in the PLC.
The later memory map calls the per-turbine setting a “Cutout delay,” with a BCD range of 0.00 to 99.99 seconds and two assumed decimal places. This differs from the earlier “Cutin delay” name and 250 ms example. Resolve the meaning and units in the HMI label, PLC timer logic, and commissioning sheet; do not copy the value into a differently defined timer. Verify BCD conversion and decimal scaling by changing the HMI setting through known values before enabling automatic operation.
The initial high-windspeed interlock is described as one site-wide 45 MPH threshold, but the later variable map assigns separate high-windspeed and resume setpoints to each turbine. There is one anemometer per site. Decide whether it feeds one shared trip/resume threshold or two turbine-specific thresholds; make the HMI and fault logic agree. The resume values are not stated, so set them from the approved operating design rather than guessing.
Keep two turbine instances independent and share only site data
Use a common program structure, but maintain separate operating modes, RPM comparisons, brakes, grid relays, and turbine-specific settings for Windmill 1 and Windmill 2. The project had one anemometer per location/site, so windspeed acquisition can be shared; explicitly map that measurement into each turbine’s permissive logic. Do not let a fault or HMI command for one turbine change the other turbine’s mode unless the condition is intentionally site-wide.
The proposed address organization reserved V2000-V2007 for site values, including V2000 for windspeed and V2001 for windspeed update frequency, which was not programmed yet. It reserved V2010-V2017 for Windmill 1 and V2020-V2027 for Windmill 2. Both blocks included windspeed high/resume, cut-in RPM, cut-out RPM, cutout delay, and high alternator RPM settings. The mapped high alternator RPM setpoint is intended to protect against overspeed; its value was not provided.
Keep the reserved space and naming pattern consistent when expanding the project. It reserved V2030-V2047 for future per-windmill values, V2050-V2067 for HMI display flags, and for HMI interaction. The noted HMI interaction values were V2070 current screen, V2071 function-button press, V2073 PLC screen change, V2074 HMI speaker beep, and V2075 screen-color change. Avoid using a single HMI flag or setpoint address for both turbines if the screens can edit the values independently.
Separate sensor acquisition, HMI work, and failsafe checks
Keep high-speed measurement, HMI interaction, failsafe checks, and operating-state transitions in distinct program stages. The described anemometer measurement used the PLC’s onboard HSIO input at X0 and placed calculated windspeed in V2000 once each second. The 500 PPR alternator encoders were quadrature devices, but bench tests used only the A-phase pulse train with a pull-up resistor; the external HSIO card monitored each turbine’s RPM. Prove scaling and update freshness on the installed hardware before the mode logic consumes those values.
The reserved external-HSIO values were V3000 for Windmill 1 scaled RPM (32-bit), V3002 for its raw encoder count (32-bit), V3004 for Windmill 2 scaled RPM (32-bit), and V3006 for its raw count (32-bit). Confirm that each 32-bit value is read and compared as the intended data type, and verify that the two counters cannot be swapped in the HMI or logic.
The external temperature controller, voltage sensor, and frequency sensor provide discrete signals. The stated electrical windows were 120 VAC ±5% and 60 Hz ±5%; verify the actual sensor output polarity and fault contact behavior instead of assuming that an energized input always means healthy. The planned move to direct analog measurement on a DL06 was future work, not the present input architecture. Do not transplant the discrete-input logic into a future analog implementation without defining scaling, limits, and sensor-failure handling.
The HMI stage can handle screen changes, function-button presses, and display lookup bits without writing directly to safety-critical outputs. Validate button edge detection and screen-change behavior separately; the project listed HMI button detection and a brief screen-color flash as bugs to fix. Parameter edits should be range-checked and should not silently change the active turbine’s settings while an unsafe state transition is underway.
Do not use RPM as the grid-connection proof
The proposed grid relay connects a windmill alternator to the grid, and the design correctly identifies the risk of grid power flowing backward and driving the alternator as a motor. But the listed voltage and frequency sensors only report whether voltage is within 120 VAC ±5% and frequency is within 60 Hz ±5%. A turbine RPM threshold plus those discrete “within range” signals does not measure the alternator-to-grid phase relationship or prove that the approved interconnection conditions are met.
The system description includes induction generators and permanent-magnet alternators, with some permanent-magnet machines connected through a synchronous inverter. These are different electrical configurations. Do not assume that a single RPM-based Online permissive is valid for all of them. The approved connection method and protective functions must govern grid relay operation; obtain the utility/interconnection engineer’s approval before enabling the relay. Keep the PLC state machine responsible for supervisory mode sequencing unless the approved design explicitly assigns it additional protection functions.
Commission each mode and fault path before automatic operation
Commission from inputs and outputs toward state changes. Use a documented test matrix for both turbines, since a correct Windmill 1 result does not prove Windmill 2 addressing or output mapping.
- With the turbine prevented from connecting to the grid, verify each raw input: anemometer pulse processing, each encoder count/RPM value, temperature status, voltage status, frequency status, brake feedback if available, and HMI manual Offline command.
- Confirm that input polarity and diagnostic text agree. Simulate or safely produce each fault condition and verify that the fault monitor reports the expected state without affecting the other turbine.
- Test Offline-to-Freewheel only with all required permissives healthy and no manual Offline request. Confirm the brake and relay outputs match the defined Offline and Freewheel output tables.
- Test Freewheel-to-Online threshold behavior below, at, and above the selected cut-in comparison. Keep the utility relay disabled unless the approved interconnection procedure authorizes a live test.
- Test the cut-out threshold and delay separately. Reproduce the expected post-connection RPM dip in a safe test environment and verify that only the intended RPM check is delayed.
- Assert each fault while Freewheel and Online, then issue a manual Offline command. Confirm fault/manual-stop priority, final state, relay command, brake command, HMI indication, and whether the fault requires manual reset.
- Change each HMI setpoint through its allowed range. Verify BCD/decimal scaling, separate values for the two turbines, and behavior after PLC restart. EEPROM backup and reload were listed as future work, so do not assume changed setpoints persist through power loss.
Log the measured input, active fault status, current state, transition condition, and output state for every test. If the controller cannot explain why a transition occurred from those values, add diagnostics before commissioning rather than adding more conditions to the same transition.
FAQ
How do I separate windmill faults from operating states in a PLC?
Use fault-monitoring stages to evaluate permissives and expose fault/clear status, then let each turbine’s Offline, Freewheel, and Online sequence consume that status. Add a manual lockout state only when the recovery procedure requires deliberate operator reset.
How do I choose cut-in and cut-out RPM values?
The initial settings were 1805 RPM cut-in and 1800 RPM cut-out, a 5 RPM gap. Treat those as initial project values, verify the generator and approved operating design, and document the commissioned thresholds and comparison operators.
How do I set the cut-in delay without masking a fault?
Confirm whether the final parameter is the original 250 ms cut-in delay or the later mapped cutout-delay value in the 0.00–99.99-second BCD range. Apply the delay only to the intended RPM cut-out check, and test timer start, expiry, and HMI scaling.
Can alternator RPM alone control a grid relay?
No. RPM does not establish phase alignment or utility-approved connection conditions, and the listed voltage/frequency window signals only indicate their respective ranges. Use the approved interconnection and protection design for grid connection permissives.
When should I stop commissioning a windmill PLC?
Stop before enabling the grid relay if phase/synchronization requirements, fault priority, sensor polarity, or brake/relay output behavior are unresolved. Escalate to the utility-approved interconnection engineer and the PLC or HSIO manufacturer’s official technical support before returning the turbine to automatic operation.