Detecting PROFINET Device Errors on S7-1200 in TIA Portal V15

David Krause11 min read
S7-1200SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview

Detecting a peripheral fault on a Siemens SIMATIC S7-1200 connected to a PROFINET IO device (for example, a Festo valve manifold or I/O module referenced in the SIMATIC compatibility list) requires more than simply waiting for a watchdog LED. TIA Portal V15 provides three complementary mechanisms:

  • OB82 – Diagnostic interrupt OB, triggered by a device-originated diagnostic event.
  • OB86 – Rack or PROFINET IO system failure OB, triggered when an IO device goes offline, returns, or fails to come online.
  • GET_DIAG – A user-program instruction that reads structured diagnostic data from a PROFINET IO device, including channel status, port status, and module status.

Many users start with OB82 and find it silent when a device is physically disconnected. This is expected: OB82 fires for a diagnostic interrupt condition reported by the device, not for a link-down condition. For a cable pull or power-loss on a PROFINET slave, OB86 is the correct OB. GET_DIAG complements both by providing a polled, structured view of the device's current health.

This article covers the architecture of PROFINET diagnostics on S7-1200, the role of each OB, the configuration of OB86, the parameter set of GET_DIAG, and a startup-time strategy that handles the 30–45 second PROFINET bring-up window typical for cold-start configurations.

2. Prerequisites

Item Requirement
Controller SIMATIC S7-1200 CPU (tested on CPU 1214C, CPU 1215C, CPU 1217C)
Firmware (CPU) V4.2 or higher recommended when paired with TIA Portal V15.1; V4.4 required for full GET_DIAG channel diagnostics
Engineering tool STEP 7 Basic / Professional V15 (V15.1 preferred) – see S7-1200 System Manual (entry ID 109751587)
PROFINET slave Any PN device with GSD file; e.g., Festo CTEU, VTEM, or CPX-CEC (GSDML import required for non-listed devices)
PROFINET topology Configured device name assigned to each slave, IP in PROFINET subnet, watchdog time set per device
Wiring PROFINET cable (Cat 5e or higher), switch optional but recommended; shield grounded at one end
Programming language LAD, FBD, or SCL (SCL used in examples here for compactness)
Note on TIA Portal V15: V15 was the first release aligned with Windows 10 1809. If you are still on V15.0, install Update 4 (entry ID 109751559) or migrate to V15.1 to receive the corrected GSDML import for Festo devices and improved diagnostic buffer entries.

3. PROFINET Diagnostic Architecture on S7-1200

PROFINET diagnostics flow upward through three layers:

  1. Channel diagnostics – A specific channel inside a slot reports a problem (e.g., wire break on input 3 of a digital input module). Encoded as a channel-related diagnostic record (alarm type 0x0002 / 0x0003).
  2. Module diagnostics – An entire module is flagged. Encoded as alarm type 0x0004 / 0x0005.
  3. Device / station diagnostics – The entire PROFINET IO device becomes unavailable (link loss, power loss, watchdog timeout). Encoded as a PNIO alarm with ChannelProperties set to the device (slot 0).

The S7-1200 firmware translates these alarms into OB calls. The mapping is as follows:

PROFINET Event Triggered OB Behavior in TIA Portal V15
Device returns / fails (rack fault) OB86 Called on both coming and going events
Device sends diagnostic alarm (e.g., wire break) OB82 Called on both incoming and outgoing diagnostic events
Module removed or inserted during RUN OB83 Only for hot-swap-capable stations
Hardware interrupt from PN device OB40 Optional, not used for fault detection

For a Festo CTEU or CPX manifold pulled from the network while the CPU is in RUN, OB86 is the only OB that fires reliably. OB82 will not fire because the device no longer has power to send a diagnostic alarm. The user's symptom – "OB82 without success" – is therefore not a configuration error; it is a normal behavior of the OB82 contract.

4. Step-by-Step: Configure OB86 for PROFINET Failure Detection

4.1 Create the OB

  1. In the TIA Portal project tree, right-click Program blocks > Add new block > Organization block.
  2. Select OB86 (Rack or station failure). The S7-1200 firmware automatically populates the OB's local variables with the failure event and the affected logical address.
  3. Choose a language (LAD, FBD, or SCL). For pure detection, FBD is clearest.

4.2 Read OB86 local variables

OB86 exposes the following input parameters in its temporary variables (visible in the OB's interface):

Variable Type Meaning
LADDR HW_IO (Word) Logical base address of the failed PROFINET IO device
EVENT Byte Event ID: B#16#39 (entering), B#16#38 (leaving), B#16#35 / B#16#36 (partial fail / partial return)
ID Word For S7-1200 PN: usually 0. For ET200S PN with sub-modules, identifies the slot.
PRIORITY Byte Priority class of the OB

4.3 SCL example – fault flag and diagnostic buffer entry

// OB86 - PROFINET station failure handling
#iEventClass := OB86_EV_CLASS;       // B#16#38 leaving, B#16#39 entering
#wFaultIO    := OB86_MDL_ADDR;       // Logical base address of failed device
#bEventID    := OB86_EVENT;          // Detailed event code

IF #iEventClass = B#16#39 THEN
    // Coming event: device is back
    "DB_Diag".DeviceFault[#wFaultIO] := FALSE;
    "DB_Diag".LastRecoveredIO := #wFaultIO;
ELSIF #iEventClass = B#16#38 THEN
    // Going event: device is gone
    "DB_Diag".DeviceFault[#wFaultIO] := TRUE;
    "DB_Diag".LastFaultedIO := #wFaultIO;
END_IF;
Indexing the fault array: On the S7-1200, OB86_MDL_ADDR returns the I/O logical address assigned in the device configuration (Devices & Networks > Properties > IO addresses). For an input with address 0, LADDR = 0. Use this value as the array index, but be sure the array in your data block covers the full address range (0..maximum configured I/O address).

5. Step-by-Step: Use GET_DIAG for Structured Diagnostics

OB86 is event-driven and binary: you know that a device has gone away, but you do not know why. GET_DIAG reads the current state of a PROFINET device, port, or module, including error codes, on demand.

5.1 Insert the instruction

  1. Open the OB where you want to perform the diagnostic poll (typically a cyclic OB1 segment or a watchdog OB35).
  2. From the Instructions pane, expand Diagnostics > GET_DIAG and drag it into the segment.
  3. On the instruction, click the MODE input to expose additional outputs.

5.2 Pinout of GET_DIAG

Pin Direction Data Type Purpose
REQ Input Bool Trigger a new read (rising edge)
MODE Input UInt 0 = status of the device, 1 = IO module status, 2 = port status
LADDR Input HW_IO Logical address of the device (slot 0) or module (slot 1..n) or port
RET_VAL Output Int Return value; 0 = OK
BUSY Output Bool True while the read is in progress
DIAG Output Variant Pointer to a structure of type Diag_*
STATUS Output DWord Detailed status word (see below)

For details, see the SIMATIC S7-1200 / S7-1500 GET_DIAG reference (entry ID 57132240).

5.3 SCL example – poll all configured PROFINET devices every 2 s

// Call once per scan in OB1 or on a 2-second timer
FOR #i := 0 TO "DB_Devices".Count DO
    #iStatus := GET_DIAG(
        REQ     := #xTrig,             // pulse from timer
        MODE    := 0,                  // device-level status
        LADDR   := "DB_Devices".Addr[#i],
        RET_VAL := #iRetVal,
        BUSY    := #xBusy,
        STATUS  => "DB_Diag".Status[#i]
    );
    IF #iRetVal = 0 AND #xBusy = FALSE THEN
        "DB_Diag".Present[#i] := ("DB_Diag".Status[#i] AND 16#0000_0001) <> 0;
    END_IF;
END_FOR;
STATUS word bit meaning (MODE 0): bit 0 = device available, bit 1 = module OK, bit 2 = channel diagnostic present, bit 3 = maintenance required, bit 4 = maintenance demanded, bit 5 = diagnostics available. See the STEP 7 V15 online help for the full STATUS structure.

6. Handling PLC Startup State

After a STOP-to-RUN transition, all PROFINET devices must be parameterized and AR-established. The S7-1200 user report quoted a 45-second window before all devices are responsive. This is realistic for an installation with multiple slaves and I&M data exchange. The recommended strategy is to suppress fault evaluation until the system is in steady state.

6.1 Use a startup-elapsed timer

// In OB1 or a watchdog OB
IF "DB_Init".StartTime = 0 THEN
    "DB_Init".StartTime := TIME_TCK();
END_IF;
IF (TIME_TCK() - "DB_Init".StartTime) > T#45s THEN
    "DB_Init".Ready := TRUE;       // diagnostics are now valid
END_IF;

6.2 Use the standard OB100 / startup OBs

Add code in OB100 (warm restart) to clear your fault flags and the diagnostic DB at the moment of transition. This ensures stale entries from the previous session are not latched into the new RUN cycle. On the S7-1200, OB100 is automatically called once after STOP-to-RUN; it is the correct place to initialize state.

7. Verification and Online Testing

  1. Build and download the project to the CPU.
  2. Go online in TIA Portal. Open Online & Diagnostics > Diagnostics buffer.
  3. Power the CPU and all PN devices. Wait for the AR to be established (the I/O area of the device turns green in Online & Diagnostics > PROFINET IO).
  4. Force a fault: pull the PROFINET cable from the Festo device or cycle its 24 V supply.
  5. Watch the diagnostic buffer. You should see entries of class "IO device failure" with the LADDR matching the device.
  6. Confirm that DB_Diag.DeviceFault[LADDR] flips to TRUE in the online watch table.
  7. Reconnect the device. The flag should return to FALSE on the "coming" event of OB86.

If the buffer shows "IO device failure" but OB86 does not execute, the most common cause is that OB86 was not downloaded or its priority was overridden. Confirm by right-clicking the project > Compile > Software (rebuild all blocks).

8. Edge Cases and Field Notes

8.1 Partial station failure

For a Festo CPX manifold with multiple sub-modules, an individual sub-module (e.g., one valve slice) may fail while the rest of the station remains online. In this case OB86 fires with EVENT = B#16#35 (partial failure) rather than B#16#38. The ID parameter identifies the slot. Your handler should distinguish these cases if you need per-module granularity.

8.2 Tool changer and topology reconfiguration

If your Festo device is part of a tool-changing PROFINET topology, the device may deliberately come and go. Do not treat every OB86 event as a fault – instead, use it as a state change notification and combine it with a permissive from your tool-change handshake.

8.3 Diagnostic alarm from a powered device

If a powered Festo device reports a wire break or overload via a diagnostic alarm, OB86 will not fire. You need OB82 for that. The fix is to keep both OBs in the program: OB82 for "device says something is wrong", OB86 for "device is unreachable".

8.4 Acyclic parameter read for non-listed devices

If the Festo slave was added with its GSDML but is not in the device catalog, you can still read acyclic parameters using the RDREC instruction (index 0x8000 series). This returns the IM0/IM1/IM2 records, which include the OrderId and serial number – useful for confirming that the device responding is the device you expect.

8.5 Watchdog time

For a station that may be temporarily offline (e.g., on a flexible cable carrier), raise the PROFINET watchdog from the default 3 to 30 cycles (in Devices & Networks > Properties > PROFINET interface > Watchdog). This prevents OB86 from firing during a normal 1–2 s plug event.

9. Troubleshooting Matrix

Symptom Likely Cause Fix
OB82 does not fire on cable pull Wrong OB for this event class Implement OB86 for station failure; keep OB82 for device-originated alarms
OB86 does not fire on cable pull OB not downloaded or not built into the program Compile > Software (rebuild all); verify in the device's block list
Fault flag flutters at startup PROFINET AR not yet established Suppress fault evaluation for first 45 s using T#45s gate
GET_DIAG returns RET_VAL 80A1 Invalid LADDR or address not configured Confirm logical base address in device configuration
GET_DIAG returns RET_VAL 80A2 Device not reachable This is itself a fault – treat as station failure equivalent
Device OK in online view, OB86 still fires Watchdog timeout, not real link loss Increase watchdog time; check for EMC or cable damage
Festo device not in catalog GSDML not installed Tools > Manage device description files (GSD)

10. Reference Links

Frequently Asked Questions

Why does OB82 not fire when my Festo PROFINET device is disconnected?

OB82 is a diagnostic-interrupt OB; it only fires when the device itself sends a PROFINET diagnostic alarm. A cable pull or power loss removes the device from the network, so it cannot send an alarm. Use OB86 for rack/station failure detection instead.

What is the correct OB to detect a PROFINET IO device failure on an S7-1200?

OB86. It is called on both the leaving event (B#16#38) and the returning event (B#16#39). Its temporary variable OB86_MDL_ADDR contains the logical base address of the failed device.

How long after PLC startup are PROFINET devices actually ready?

Typically 5–15 seconds for a small installation, but a 30–45 second window is normal for multi-slave systems that exchange I&M data. Use a T#45s gate or read OB86 events only after Ready is set in your initialization DB.

Can I use GET_DIAG to detect whether a device is online?

Yes. With MODE = 0, the STATUS word bit 0 indicates "device available". Call GET_DIAG cyclically (e.g., every 2 s) from OB1. A RET_VAL of 80A2 also means the device is unreachable, which is itself a fault indication.

What is the difference between OB82 and OB86 in TIA Portal V15?

OB82 handles a diagnostic interrupt reported by the device (e.g., wire break, overload). OB86 handles the disappearance or reappearance of an entire PROFINET IO device or sub-module. Use both: OB82 for in-device alarms, OB86 for station-level connectivity.

Back to blog