Detecting Lost PROFIBUS Stations After Siemens Y-Link with SFC59

David Krause11 min read
ProfibusSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

On a Siemens H-System (S7-400H) where one or more Y-Link couplers are used to attach PROFIBUS PA segments to a PROFIBUS DP network, the loss of a downstream PA slave (or DP slave attached through the Y-Link's lower segment) is normally invisible to the H-CPU at the application level. The CPU only sees a healthy diagnostic frame from the IM 153-2 (or the older IM 157) and is not automatically informed which individual station on the lower segment has dropped out, exchanged a module, or signaled a channel fault.

The supported mechanism for surfacing these events is the diagnostic buffer that the Y-Link's head module (IM 153-2 in current hardware, IM 157 in legacy hardware) maintains for every diagnostics-capable DP-V1 slave on its lower segment. The H-CPU reads this buffer with SFC 59 "RD_REC" (Read Data Record). The data record layout, the slot/index mapping, and the call parameters are documented in Siemens manual entry ID 1142696 – Bus links DP/PA coupler, DP/PA link, and Y link, section 12.2.2 "Reading out the diagnostics of underlying slaves".

This reference covers the complete procedure: SFC 59 invocation, record-number and I/O-ID semantics, the differences between the old IM 157 and the new IM 153-2, integration into the S7-400H fault-tolerant program, and a working STL sample that exposes lost-station events to the OS or HMI.

Y-Link Position in the Network

The Y-Link acts as a DP-V1 master on the lower (PA/DP) segment and as a DP slave on the upper (DP) segment. The head module is addressed by the H-CPU as a standard PROFIBUS DP slave; every PA/DP device that sits behind it is invisible to the upper master unless diagnostics are explicitly requested.

Position Device Address range (typical) Visible to H-CPU without SFC 59?
Upper DP segment H-CPU 417-4H (A & B) Master n/a
Upper DP segment Y-Link head module (IM 153-2 / IM 157) DP address 7 (example) Yes (as DP slave)
Lower segment (PA) PA slave 1 PA address 1 No
Lower segment (PA) PA slave 2 PA address 2 No
Lower segment (PA) PA slave N PA address N No
Note: The H-CPU cannot individually address a PA slave that lives behind a Y-Link. All diagnostics must be polled through the Y-Link's head module diagnostic buffer.

Prerequisites

  • Y-Link head module must be configured as a DP-V1 slave on the upper segment. The DPV1 master attribute is required for the diagnostics buffer in the IM 153-2 to be populated.
  • Each downstream slave that is to be monitored must be a DP-V1 diagnostics-capable station. Pure DP-V0 devices do not write extended diagnostic records; the buffer entry will not appear.
  • STEP 7 V5.x or PCS 7 V6.x/V7.x/V8.x with the corresponding GSD file for the Y-Link installed in HW Config.
  • Available OB1 / OB35 / OB82 / OB86 time slice for the SFC 59 call. The call must not be issued more often than the Y-Link refreshes its buffer (typically 1–2 s, dependent on the configured bus parameters).
  • For S7-400H: both H-CPUs must be able to issue RD_REC independently; the read result is the same on both sides because the buffer is owned by the Y-Link itself, not by the H-CPU.

Diagnostic Data Flow

H-CPU 417-4H (A) SFC 59 RD_REC H-CPU 417-4H (B) SFC 59 RD_REC Y-Link (addr 7) IM 153-2 / IM 157 PA / DP segment behind Y-Link PA 1 PA 2 PA N RD_REC returns diagnostic data records that identify the failed slave by PROFIBUS address.

SFC 59 RD_REC Call Parameters

The call to SFC 59 is structured as follows. The combination of LADDR, IOID, and RECNUM is what targets the Y-Link's slave-diagnostic buffer rather than any other record.

Parameter Type Value (Y-Link buffer read) Description
REQ INPUT (BOOL) Rising edge Start the read
IOID INPUT (BYTE) B#16#54 Identifies the slot as the head module of the Y-Link (DP-V1 head station)
LADDR INPUT (WORD) W#16#007F (= 127 dec, addr 7 in this example) Diagnostic address of the Y-Link head module from HW Config
RECNUM INPUT (BYTE) W#16#00 … W#16#3F (index range depends on firmware) Data record number; iterate 0–63 to walk the buffer
RET_VAL OUTPUT (INT) W#16#0000 on success, see error table below Return value
BUSY OUTPUT (BOOL) TRUE while the read is in progress Job status
RECORD OUTPUT (ANY) Pointer to a DB / area, e.g. P#DB100.DBX0.0 BYTE 64 Destination buffer for the read record

The semantics of IOID are critical. Per the standard functions manual for S7-300/400, IOID = B#16#54 denotes a "head module" slot. For the Y-Link this is mandatory; using B#16#54 on a normal DP slave slot returns an error.

Data Record Layout

Each valid data record returned by the Y-Link identifies a single underlying slave. The structure is the standard PROFIBUS DP-V1 diagnostic data record, but the Y-Link attaches the slave's PROFIBUS address in the slot/index field, which is what makes lost-station detection possible. The relevant fields are:

Byte offset Field Meaning for lost-station detection
0–1 Block type / length Standard DP-V1 header
2 Slot number Slot of the failed channel inside the slave
3 Bit pointer / qualifier Channel-level identifier
4–5 PROFIBUS address of the slave Key field – station that generated the diagnostic
6–7 Diagnostic flags / status Station lost (0x10), module mismatch, channel fault
8..N Vendor-specific extension Manufacturer-specific data; do not parse generically
Note: The exact byte layout and the available record numbers (RECNUM) are tabulated in manual 1142696, section 12.2.2. The values shown above match the standard DP-V1 diagnostic record type 0x02 ("Alarm") and 0x04 ("Status") as forwarded by the Y-Link. Treat the vendor extension as opaque.

STL Sample: Polling the Y-Link Buffer

The following STL shows a complete polling cycle. The instance DB (DB100) holds the returned record, the station address, and a per-station latch bit that the OS can scan.

// OB1 – call once per scan, on rising edge of OB1_PREV_CYCLE
CALL SFC 59 (
    REQ    := TRUE,                              // trigger every cycle
    IOID   := B#16#54,                           // head module
    LADDR  := W#16#007F,                         // Y-Link at DP addr 7
    RECNUM := B#16#00,                           // first record
    RET_VAL:= MW 200,                            // result code
    BUSY   := M 202.0,                           // job in progress
    RECORD := P#DB100.DBX 0.0 BYTE 64            // 64-byte destination
);

// When RET_VAL = 0 and BUSY = 0, parse the record
A     M 202.0;          // BUSY
JC    POLL;             // still running, skip parse
L     MW 200;           // RET_VAL
L     W#16#0000;
<>I;
JC    ERR;              // non-zero RET_VAL

// Extract the station address from byte 4 of the record
L     DB100.DBB 4;      // low byte of PA/DP station address
T     DB101.DBB 0;      // station_of_interest
L     DB100.DBB 5;
T     DB101.DBB 1;      // high byte (PA addresses fit in low byte only)

// Read the station-lost flag from byte 6
L     DB100.DBB 6;
L     B#16#10;          // bit mask 0x10 = station lost
AB    ;
=     DB101.DBX 2.0;    // station_lost_latch

POLL: NOP 0;
ERR:  NOP 0;

Walking the Full Buffer

A single RD_REC returns only one record. To find all failed stations, iterate RECNUM from 0 upward until RET_VAL = W#16#80B2 ("record not available") is returned. The recommended scan period is 2–5 seconds; faster scans saturate the Y-Link and starve the process data cycle.

RECNUM Meaning Action
0x00…0x3F Possible diagnostic records (range is firmware-dependent) Parse if RET_VAL = 0
0x00 (return empty) No active diagnostic Skip, no station lost
0x80B2 End of buffer / record not available Reset scan, wait next cycle

Old (IM 157) vs New (IM 153-2) Y-Link

The field report explicitly highlights that the diagnostic mechanism is identical in concept, but the data record contents differ between the legacy IM 157 and the current IM 153-2. The principal differences an integrator must handle in code are:

Aspect IM 157 (legacy) IM 153-2 (current)
Slot in HW Config Slot 0 only (single-slot DP slave) Slot 0 (head) + optional slot 1…3
Maximum slaves Up to 31 PA slaves (max bus cycle 60 s) Up to 64 PA slaves with the new coupler, faster cycles
RECNUM range 0x00…0x07 typical 0x00…0x3F depending on firmware
Station-lost bit in record Byte 6, mask 0x10 Byte 6, mask 0x10 (same location, new interpretation of extension bytes)
DPV1 required Yes Yes
One-to-one mapping per station No – records can be aggregated; the integrator must correlate by PA address No – same constraint; records still identify PA address only
Field-proven caveat (from source): “it is not possible to have a one-on-one data to station readout.” Multiple PA slaves can share a single aggregated record. The application program must keep a station table of all configured PA addresses and mark a station as "lost" only after a configured number of consecutive polls fail to see it in the buffer.

Integration into S7-400H

In an H-system, RD_REC is called on each H-CPU independently against the Y-Link's diagnostic address. Because the Y-Link is a single physical device on the PROFIBUS, both H-CPUs see the same buffer state. To avoid duplicate alarming on the OS, the recommended pattern is:

  1. Run the polling on the master H-CPU only, identified by OB70 / OB72 state flags or the standard block FC 100 "SWR\_AGGR" from the PCS 7 library.
  2. Mirror the resulting station-lost bits into a redundant DB that is exchanged via the H-sync mechanism, or send them to the standby CPU via SFC 90 "H_CTRL"-compatible shared data blocks.
  3. Generate the operator message (e.g., "&PA field failure, addr N") once, from the master side only.

Troubleshooting Matrix

Symptom RET_VAL Likely cause Action
RD_RET always 0x80A2 0x80A2 DP-V1 not negotiated; Y-Link is running in DP-V0 mode Check bus parameters, enable DPV1 in HW Config of the H-CPU
RET_VAL = 0x80B2 on first call 0x80B2 Buffer empty, or RECNUM out of range Normal if no failure; verify RECNUM starts at 0x00
RET_VAL = 0x80A1 0x80A1 Wrong IOID (not B#16#54) Change IOID to B#16#54
RET_VAL = 0x80C3 0x80C3 Resource bottleneck on the Y-Link Increase poll interval, reduce number of concurrent RD_REC calls
Record returned, but byte 4 = 0xFF 0x0000 Slot 0xFF means the Y-Link itself failed, not a slave Treat as Y-Link failure, raise a separate alarm
Same station reported as lost every cycle 0x0000 Chattering fault – PA device power supply or termination Check PA segment voltage, terminator, shield

Verification

After implementing the polling loop, verify with the following checks before going into production:

  1. Disconnect a single PA slave's segment. Within one poll cycle (2–5 s) the station-lost bit for that address must be set in DB101.
  2. Reconnect the slave. The bit must clear after a configurable confirmation time (recommend 3 consecutive successful reads).
  3. Power down the entire Y-Link. The H-CPU must detect the Y-Link's own DP slave failure via OB86; the RD_REC path must return 0x80A2 (timeout) and the program must not hang in BUSY.
  4. In the H-system, force a master/standby failover (SWR switch). Polling must resume on the new master without operator action.
  5. Trigger OB82 (diagnostic interrupt) and confirm the OS does not duplicate the lost-station alarm from the H-CPU that is now in standby.

Field Commissioning Tips

  • Always commission with PCS 7 plant view: the OS will auto-generate the operator message text from the slave's tag, so the manual parse above is only needed if PCS 7 messages are not sufficient.
  • Set the PA coupler termination resistors ON at the two physical ends of the segment and OFF on every coupler in between. A common cause of intermittent station-lost events is a missing or doubled terminator.
  • Keep the RD_REC polling on OB35 (1000 ms) rather than OB1; OB1 will starve the H-CPU's main cycle if the poll returns BUSY = TRUE for several scans.
  • Do not poll the same Y-Link from both H-CPUs simultaneously. Coordinate via the redundancy status word.

FAQ

Can SFC 59 detect every PA slave loss in real time?

No. The Y-Link aggregates diagnostics and updates its buffer only on a poll cycle (typically 1–2 s). The H-CPU will see the lost station within one to two poll intervals of the RD_REC scan, not instantly. Plan for a 2–5 s detection latency.

What is the difference between SFC 59 and SFC 13 for Y-Link diagnostics?

SFC 13 "DPNRM_DG" reads the standard 6-byte DP diagnostic frame of a DP slave, which only tells the master that some diagnostic exists. SFC 59 "RD_REC" reads the extended DP-V1 data record from the Y-Link and is the only call that exposes the PROFIBUS address of the failing lower-segment slave.

Does the Y-Link need to be configured as a DPV1 master for this to work?

Yes. The diagnostic buffer in the IM 153-2 (and the IM 157) is only populated when the lower segment is operated in DP-V1 mode. With DP-V0 the buffer is not maintained and RD_REC returns 0x80A2. Enable DPV1 in the H-CPU's PROFIBUS interface properties in HW Config.

How does the IM 157 (old Y-Link) differ from the IM 153-2 (new Y-Link) for diagnostics?

The conceptual call is the same, but the IM 157 has a smaller RECNUM range (0x00…0x07 typical) and may aggregate records so that one entry can refer to multiple lower-segment slaves. The IM 153-2 supports a wider RECNUM range and a higher slave count, but the application must still correlate the address in byte 4 of the record against its own station table.

Can this method be used in an S7-400H redundant system?

Yes. Run the RD_REC scan on the active H-CPU only, identified by the redundancy status. Mirror the resulting station-lost bits to the standby via shared DB. Do not poll from both H-CPUs simultaneously, as the Y-Link serializes the requests and the active CPU's result is sufficient.

Back to blog