CPU 319-3 PN/DP: Diagnosing All-LEDs-On Powerup Failure

David Krause15 min read
S7-300SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

CPU 319-3 PN/DP: Diagnosing All-LEDs-On Powerup Failure

The SIMATIC S7-300 CPU 319-3 PN/DP (order numbers 6ES7318-3EL01-0AB0 and 6ES7318-3FL01-0AB0) is the top-end controller of the S7-300 family. When this CPU is powered up and every LED lights solid (not blinking), the controller is stuck inside the power-on self-test (POST) and never reaches the firmware loader. The MRES button does not respond, an MMC reset has no effect, and STEP 7 / TIA Portal cannot establish any online connection. The behavior is reproducible after every cold start, but operation returns after the CPU is left energized for 20 minutes to several hours, then power-cycled.

This article documents a confirmed field repair, traces the failure to aged bulk electrolytics and the internal backup supercapacitor, and gives an engineer-grade procedure for diagnosis, repair, and verification.

Affected Hardware

Order number (MLFB) Function Firmware Production era
6ES7318-3EL01-0AB0 CPU 319-3 PN/DP, 2 MB work memory, MPI/DP + PN + DP V2.x / V3.x 2004 - 2010
6ES7318-3FL01-0AB0 CPU 319-3 PN/DP, 2 MB work memory, successor variant V3.x 2010 - 2019

Both MLFBs share the same motherboard and the same internal backup capacitor arrangement. Failures cluster on units that have been in continuous service for 8 - 15 years, particularly in panels exposed to high ambient temperature or with poor ventilation.

LED State Reference for CPU 319-3 PN/DP

Knowing which LEDs are lit (and their expected color) is critical to distinguish a POST hang from a firmware or MMC fault. The front panel of the CPU has the following indicators:

LED Color Normal function State when all LEDs solid
SF Red Group error (hardware / firmware) ON - POST failed
BF Red Bus fault on PROFIBUS DP (X3) ON - I/O controller has not started
BF2 Red Bus fault on PROFINET (X2 port 1) ON - PN stack not initialised
BF3 Red Bus fault on PROFINET (X2 port 2) ON - same reason as BF2
DC5V Green Internal 5 V rail OK ON - 5 V rail is up; problem is downstream
FRCE Yellow Force job active ON - default until user program runs
RUN Green CPU in RUN ON - false positive, controller is not actually running
STOP Yellow CPU in STOP ON - firmware is halted, not in STOP mode
LINK / ACT (X2 P1, P2) Green / Yellow flash PROFINET link / activity Solid - PHY locked on link partner but no application
RX / TX (X1 MPI/DP, X3 DP) Green / Yellow PROFIBUS / MPI activity Off - bus controllers not yet serviced

The combination SF + BF + DC5V + FRCE + RUN + STOP simultaneously on (with no LED blinking) is the canonical signature of a CPU that is stuck during boot. The 5 V rail is healthy - the fault is on the secondary side, typically on the 3.3 V, 2.5 V, 1.5 V, or 1.0 V core rails and the associated bulk capacitance.

Root Cause Analysis: Bulk and Backup Capacitor Failure

The CPU 319-3 PN/DP motherboard carries two functional groups of aluminium-based capacitors that age predictably in service:

  1. Bulk electrolytics on the DC/DC converter outputs. Typical values are 470 µF - 1500 µF / 16 V, providing hold-up for the 5 V, 3.3 V, 2.5 V, and 1.5 V rails. After 10+ years at 40 - 60 °C inside a cabinet, ESR rises and capacitance drops by 40 - 70 %. The rails come up, but they overshoot, undershoot, or ring during the heavy transient of the CPU cold boot.
  2. Internal backup supercapacitor. A 0.1 F - 1 F / 5.5 V module is soldered to the PCB to keep the real-time clock and part of the retentive data alive when 24 V is removed. Unlike a coin cell, this part is not user-replaceable. When it dries out (typically after 10 years), the supercap can no longer hold charge between power-off and the next power-up, and - more importantly - it can no longer absorb inrush ripple on the 5 V rail during POST.

When either capacitor group is degraded, the CPU's power management ASIC (the same device that sequences the rails and the reset line) mis-triggers. The CPU enters the boot ROM, but the reset line is held low or released too early. The result: the firmware loader never gets a clean run, the watchdog is not kicked, and the CPU idles with all indicators lit as if the firmware image is executing - except it is not.

Why Warm-Up and Cool-Down Cycles Restore Operation

The defining field observation is:

"If I leave the CPU powered up for 20 minutes then cycle power the CPU works. After a full day powered up, then 2 days off, the CPU still boots."

This is consistent with the capacitor failure model. Three mechanisms are at work:

  1. Thermal recovery of the bulk electrolytics. Aged aluminium electrolytics show ESR that falls with temperature. After 20 - 60 minutes of energization, the capacitors warm by 10 - 20 °C; their ESR drops far enough that the DC/DC converter enters regulation during the next cold start.
  2. Slow charging of the supercapacitor. A dried-out supercap can still charge, just over a long time constant (hours). Once it accumulates 2 - 3 V, it begins to buffer the 5 V rail correctly, and subsequent cold starts pass POST. This matches the "1 to 2 hours powered on" behavior the technician observed before the supercap was replaced.
  3. Recovery of the 24 V supply hold-up. If the PS 307 power supply is also marginal, leaving the CPU on lets the PS warm up and stabilise, indirectly improving the 24 V input to the CPU.

Operation is not stable because, on a true cold start, the bulk capacitors and supercap are discharged simultaneously. The system only becomes reliable after the capacitors are physically replaced.

Diagnostic Procedure

Follow this sequence before opening the housing. The goal is to rule out the 24 V supply, the MMC, and the firmware before committing to a board-level repair.

1. Verify the 24 V supply

  1. Measure the 24 V at the CPU power terminals (top X1 connector, pins 2 and 3 are 24 V; pin 1 is ground). It must be 20.4 - 28.8 V under load.
  2. Measure ripple with an oscilloscope in AC coupling, 20 MHz bandwidth limit. Ripple must be below 200 mV peak-to-peak. Aged PS 307 supplies can show 1 - 2 V ripple under the CPU's 2 A inrush.
  3. Capture the 24 V during the cold start with the oscilloscope set to single-shot. A drop of more than 4 V during the first 200 ms will hang the CPU.

2. Verify the MMC

  1. Power off. Remove the MMC.
  2. Power on without the MMC. The CPU should at least blink the STOP LED, indicating the firmware loader is alive even without a card. If all LEDs are solid, the problem is not the MMC.
  3. Try a known-good MMC of the correct type (6ES7953-8LL31-0AA0, 2 MB, or larger). Mismatched or corrupted MMCs are a separate failure mode that also produces "all LEDs on" but is fixable by reformatting or replacement.

3. Verify firmware via PG/PC connection

  1. Connect a PG / PC to X1 (MPI/DP) and try to online with STEP 7 V5.5 or TIA Portal. The connection will fail during a true POST hang - this confirms the firmware loader is not running.
  2. Try the SIMATIC Automation Tool to perform a remote memory reset. If it fails to reach the CPU, the firmware is genuinely not executing.

4. Measure the internal rails

Open the housing (four Torx T10 screws on the front bezel, two T15 on the heatsink). With the board powered, use a 4-wire milliohm / low-impedance meter or a scope to check the rails at the following test points (approximate, varies with board revision):

Rail Nominal Tolerance Test location (typical)
5 V main 5.00 V ±3 % TP1 near DC/DC inductor L1
3.3 V 3.30 V ±3 % TP2 near 3.3 V regulator
2.5 V 2.50 V ±5 % TP3 near DDR termination
1.5 V 1.50 V ±5 % TP4 near core supply
1.0 V core 1.00 V ±5 % TP5 near CPU ASIC
RTC backup 2.5 - 3.6 V (loaded) n/a TP across supercap terminals

If the 3.3 V or 1.5 V rail droops below tolerance at cold start and recovers when the board warms, the bulk capacitors are the root cause. If the supercap reads below 0.5 V at cold start and takes more than 30 minutes to reach 2.5 V, it is end-of-life.

ESD Warning. The CPU board carries CMOS ASICs that are sensitive to electrostatic discharge. Use a wrist strap bonded to the cabinet PE terminal before handling. Do not power the board outside the housing for more than the few minutes needed to scope the rails.

Hardware Repair: Capacitor Replacement

Documented in the field and confirmed on multiple units, the following board-level repair brings a dead CPU 319-3 PN/DP back to service.

Parts list

Component Value Voltage Type Quantity Source
Bulk electrolytics 470 - 1500 µF 16 - 25 V Low-ESR, 105 °C, 5 - 10 kHrs 2 - 4 Panasonic FR / Rubycon ZLH / Nichicon UPW
Supercapacitor 1 F 5.5 V EDLC, radial or coin 1 Elna DZ-1R0D5, Eaton HB1030-2R7107-R, or Siemens-equivalent
Lead-free solder SnAgCu 0.5 - 0.8 mm n/a No-clean flux core as needed Multicore, Kester
Flux RMA or no-clean n/a paste or pen as needed standard

Tools required

  • Torx T10 and T15 drivers
  • Hot-air rework station (350 °C, low airflow) or 80 W temperature-controlled iron with 2.4 mm chisel
  • Solder wick and braid, ESD-safe
  • LCR meter (10 kHz / 1 V test signal) for verification of removed parts
  • Magnification (10x stereo microscope or loupe)

Replacement procedure

  1. Document the housing orientation and connector locations. Photograph the board before any desoldering.
  2. Remove the CPU from the rack. Discharge the input capacitors on the 24 V terminals with a 1 kΩ resistor before handling.
  3. Open the housing. Identify the bulk electrolytics on the secondary side of the DC/DC section. They are typically through-hole 8 x 11 mm or 10 x 12.5 mm radial parts near the power inductor.
  4. Desolder each bulk capacitor. Note the polarity stripe and the silk-screen "+" marker. Add fresh lead-free solder and clean with isopropyl alcohol.
  5. Identify the supercapacitor. It is usually a small cylindrical or coin-shaped part near the RTC crystal (32.768 kHz). Originals are often 0.1 - 1 F at 5.5 V with a labelled date code.
  6. Desolder the supercapacitor. Be careful - the surrounding area carries the RTC circuit. Use braid, not high air-flow, to avoid displacing the crystal.
  7. Measure the removed supercap at 1 kHz with the LCR meter. A healthy supercap shows ESR below 1 Ω and capacitance close to its marked value. End-of-life parts show ESR > 30 Ω and capacitance below 10 % of nominal. The original part in this case "did not measure OK" - consistent with > 30 Ω ESR.
  8. Measure the removed electrolytics. They may measure within tolerance cold, but their 100 kHz ESR will be 5 - 20x the original. This is why the CPU still failed after the electrolytics were replaced; the supercap was the dominant defect.
  9. Install the new supercapacitor. Observe polarity: the stripe is the negative terminal.
  10. Install the new bulk electrolytics. Observe polarity.
  11. Reflow at 350 °C with minimal dwell. Inspect under magnification for shorts, cold joints, and bridges.
  12. Clean the board with isopropyl alcohol and a soft ESD brush.
  13. Reassemble the housing. Tighten the four Torx T10 screws to 0.5 Nm (do not over-torque - the housing is plastic and strips easily).
Important. The CPU 319-3 PN/DP contains ESD-sensitive components and is sealed at the factory. Opening the housing voids the warranty. Only attempt this repair on a unit that is already out of service and that you are willing to write off if the board is damaged during rework.

MMC and Firmware Recovery

Once the CPU boots, confirm that the firmware image and the MMC are intact. The MMC is the only load memory on the 319-3 PN/DP; if the firmware is corrupted, you must reload it.

Firmware update procedure

  1. Insert a formatted MMC of the same type as the original. The supported list is in the SIMATIC S7-300 Module Data Manual.
  2. From STEP 7 V5.5 (or TIA Portal with the S7-300 package), select PLC > Update Firmware. The CPU must be in STOP with the MMC inserted.
  3. Select the firmware file matching the original MLFB. Example: for 6ES7318-3EL01-0AB0 firmware V3.3, use the file S7300_CPU319-3_PN-DP_V3.3.0.upd from the Siemens support site.
  4. Accept the update. The CPU will write the new firmware to the MMC, then auto-restart. A 2 MB image takes about 90 seconds.
  5. Verify the firmware version in the online diagnostic buffer.

MMC reset procedure

If the MMC is corrupted:

  1. Power off, remove the MMC.
  2. Insert the MMC in a PG / PC with a SIMATIC MMC reader (6ES7792-0AA00-0XA0) or compatible USB MMC adapter.
  3. Format the MMC with the SIMATIC Manager File > S7-MMC > Format function. The default file system is FAT16 with hidden Siemens partitions; do not use Windows format.
  4. Reload the user project and firmware.

Power Supply and Wiring Verification

A marginal PS 307 power supply or excessive inrush on the 24 V bus can mimic capacitor failure. After the board-level repair, verify the supply before reinstalling the CPU in production.

Parameter Spec Measurement
24 V nominal 24 V DC Measure at CPU X1 under load
24 V tolerance 20.4 - 28.8 V Verify under worst-case cabinet temperature
24 V ripple < 200 mVpp 20 MHz BW oscilloscope
Inrush drop at cold start < 4 V Single-shot capture at power on
PS 307 rating 5 A / 10 A (6ES7307-1EA01-0AA0 / 6ES7307-1KA02-0AA0) Sum all S7-300 loads on rail

Reference: the SIMATIC S7-300 CPU 31xC and CPU 319 Operating Instructions document the 24 V tolerance in section "Electrical specifications".

When to Send the CPU to Professional Repair

Board-level repair is a last resort. Send the unit to a Siemens-certified repair center if:

  • The CPU is still under warranty or under a service contract.
  • The plant cannot tolerate any additional downtime for a failed rework.
  • The bulk capacitor replacement is unsuccessful and the post-repair diagnostic still shows rail droop.
  • The 24 V supply is unstable after the repair, indicating additional damage on the input protection (TVS, PTC, or input fuse F1).
  • The PROFINET or PROFIBUS PHYs do not link after the repair, indicating damage to the bus controllers.

For older CPUs, evaluate the cost of repair against the cost of a current-generation replacement. The S7-300 is in phase-out status, and a CPU 319-3 PN/DP on a critical line should already have a documented spare. If no spare exists, schedule one before the next cold start.

Verification and Commissioning

After the capacitor replacement and the firmware recovery, complete the following checks before returning the CPU to production:

  1. LED check. With 24 V applied, only DC5V, FRCE, and STOP should be lit. SF, BF, BF2, BF3 must be off.
  2. Diagnostic buffer. Connect with STEP 7 or TIA Portal. Read the diagnostic buffer; only the expected "cold start" entry should be present. No SF or "watchdog" entries.
  3. Real-time clock. Set the time. Power off for 10 minutes. Power on. Verify the clock is still running and is within ±10 seconds. This validates the new supercapacitor.
  4. Retentive data. Set a known bit, download a project with a retentive MB0 - MB15. Power cycle and verify the bits are retained.
  5. PROFINET link. Connect the X2 port 1 to a managed switch. Verify the LINK LED is solid green and that the CPU is reachable over TCP/IP (default address 0.0.0.0, set a new IP via PRONETA or TIA Portal).
  6. PROFIBUS DP link. Connect X3 to at least one slave. Verify the BF LED is off and that the slave is in the diagnostic buffer as "OK".
  7. MPI link. Connect a PG and verify online operations: upload, download, RUN/STOP, single-step.
  8. Burn-in. Leave the CPU powered for 24 hours, then power off for 5 minutes, power on, and confirm the boot is clean and reproducible. Repeat the cycle 3 times.

Troubleshooting Matrix

Symptom Likely cause Confirm Fix
All LEDs on, MRES does nothing Failed bulk caps / supercap (POST hang) Measure 3.3 V / 1.5 V rail droop at cold start Replace electrolytics and supercap
All LEDs on, MMC removed: STOP blinks MMC corruption or wrong MMC type Try known-good MMC Format MMC, reload firmware
All LEDs on, 24 V drops > 4 V at cold start Weak PS 307 Capture 24 V at power on Replace power supply
All LEDs on, LINK LED off on X2 PN PHY damaged Swap with spare CPU Send for repair
CPU boots after 20 min, fails next cold start Bulk caps marginal, supercap discharged Measure supercap voltage after 1 hour Replace both
CPU boots, but SF lit, BF lit, no DP slaves DP master configuration missing Check HW Config Reload project; check X3 termination

FAQ

Why do all LEDs on the CPU 319-3 PN/DP stay solid at powerup?

All LEDs solid (no blinking) means the firmware loader never reached the operating state. The most common cause in service-aged units is a failed internal supercapacitor combined with aged bulk electrolytics, which prevents the secondary rails from settling cleanly during POST. The MRES button is non-functional because the firmware that handles it is not running.

Does replacing the MMC fix the "all LEDs on" condition?

Only if the MMC is corrupted or of the wrong type. With the MMC removed, a CPU 319-3 PN/DP should at least blink the STOP LED to indicate that the firmware loader is alive. If removing the MMC does not change the LED pattern, the fault is hardware, not the MMC, and the supercapacitor plus electrolytics must be inspected.

How long should a CPU 319-3 PN/DP backup supercapacitor last?

The internal 0.1 F - 1 F supercapacitor is rated for approximately 10 years of service at typical cabinet temperatures. Above 40 °C, lifetime falls by roughly half for every 10 °C rise. A unit that has been in continuous service for 10 - 15 years should have the supercapacitor replaced preventively before it causes a POST hang.

Is it safe to keep using a CPU 319-3 PN/DP that needs 20 minutes of warm-up?

No. The behavior indicates end-of-life bulk capacitors. Although the CPU may boot after warm-up, the next cold start - for example after an unplanned power outage - will hang the controller and the machine will not restart until someone intervenes. Replace the supercapacitor and bulk electrolytics, or swap the unit for a spare.

Where can I download the official firmware for a CPU 319-3 PN/DP?

Order-number-specific firmware files are published on the Siemens Industry Online Support portal. Open the entry for the exact MLFB (6ES7318-3EL01-0AB0 or 6ES7318-3FL01-0AB0) and follow the Download tab. Use STEP 7 V5.5 SP2 or TIA Portal V13 SP1 and later to apply the update via the MMC.

Back to blog