Diagnosing Intermittent BF LED on S7-300 CPU 317 Profibus DP

David Krause16 min read
ProfibusSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

An S7-300 station built around a CPU 317 (typically 6ES7317-2AJ10-0AB0 or 6ES7317-2EK14-0AB0 for the -2DP/PN variants) drives four distributed racks over PROFIBUS DP through IM 153 interface modules mounted on ET 200S backplanes. The reported symptom is a one-second flash of the CPU's BF (Bus Fault) LED, during which the I/O image of the fourth ET 200S rack is briefly frozen or returns zeros, then communication recovers automatically. The event recurs 5–7 times per day and leaves no fault bit latched once the LED extinguishes.

This pattern is classic for an intermittent single-slave bus failure rather than a sustained DP master failure. The PROFIBUS link to the rest of the plant stays up; only one slave drops out for a few hundred milliseconds and re-enters the cyclic exchange. Because the CPU is password-protected, the diagnostic buffer cannot be cleared or inspected by maintenance personnel without the project password or a logged-in PG with the correct access level. That makes the on-line diagnostic buffer the single most important evidence in the loop.

Engineering note: A BF flash shorter than the DP watchdog time (configured under HW Config → Slave → DP slave properties, default typically 10 s) does not trigger a STOP, but it does reset the slave's outputs to their configured substitute/fail-safe values for the duration of the dropout. On the IM 153, this is what causes the I/O image to disappear for one second.

S7-300 CPU 317 BF LED Definition

The CPU 317 front panel carries a status LED bar that must be read together, not in isolation. The four LEDs most relevant to a Profibus fault are summarized below.

LED Color Meaning
SF Red System Fault – group error from the CPU itself, the program, or a configured slave reporting a diagnostic interrupt.
BF Red Bus Fault on the first PROFIBUS DP interface (X1). Lit = physical or logical link to one or more configured slaves has failed. Flashing = DP master configuration fault (slave not found, duplicate address, parameter error).
DC 5V Green Internal 5 V supply to backplane OK.
FRCE Yellow At least one I/O point is forced.

On a -2DP variant (6ES7317-2EK14-0AB0) the BF1 LED refers to the first DP interface and BF2 to the optional second interface. If the plant only uses X1, a BF1 flash is the relevant indicator. A flashing BF LED has a distinct meaning on Siemens DP masters (configuration mismatch) compared with a steady lit BF (link failure) – a one-second flash on its own is most often a transient physical-layer event, not a configuration mismatch.

ET 200S IM 153 BF LED Definition

The IM 153-1 (e.g., 6ES7153-1AA83-0XB0) and IM 153-2 (6ES7153-2BA10-0XB0) interface modules each carry three front-panel LEDs: ON (green), SF (red), and BF (red). The BF LED on the IM 153 behaves as follows:

IM 153 BF LED State Cause
Off Cyclic DP communication with master OK.
Lit, steady No parameterization from master (wrong address, duplicate address, no bus termination, cable break, master STOP with IM 153 not configured to free-port mode).
Flashing at ~2 Hz Parameterization error from master (GSD mismatch, slot mismatch, wrong configuration).
Flashing briefly during dropout, then off Single token-loss / re-parameterization event, typically a marginal cable, connector, or 24 V sag.

Recording the IM 153 BF behavior simultaneously with the CPU BF behavior is the cheapest diagnostic on the floor. If the fourth IM 153's BF also flashes for one second during the CPU BF event, the fault is on the physical layer or 24 V supply of that specific slave. If only the CPU BF lights and the IM 153 BF stays off, the fault is upstream (master interface, repeater, or cable to that slave's segment).

Why a One-Second BF Event is Critical

PROFIBUS DP diagnostics are timestamped by the CPU's diagnostic buffer, and a 1 s dropout is enough to:

  1. Trigger OB82 (Diagnostic Interrupt) on entry and exit if any module in the failing rack reports a diagnostic change.
  2. Trigger OB86 (Rack Failure) on the failure and again on the return.
  3. Trigger OB122 (I/O Access Error) on every direct I/O read or write that lands on the missing slot during the dropout window.
  4. Reset all outputs of that rack to the substitute values configured in HW Config (de-energize, hold last value, or substitute a fixed value).

If OB86 and OB82 are not loaded in the S7 program, the CPU continues running but still logs the events with a millisecond timestamp in the diagnostic buffer. If OB122 is not loaded, the CPU goes into STOP on the first access error. A plant that is surviving in RUN mode during these events therefore has at least OB122 loaded (or the access is occurring from a process-image update rather than direct P/Q access).

Probable Root Causes

Intermittent single-slave DP dropouts of sub-second duration almost always trace to one of the following, in order of probability:

Rank Cause Why it produces a 1 s flash
1 Loose or corroded PROFIBUS connector on the fourth IM 153 or its incoming drop cable. Mechanical micro-movement breaks the shielded contact; the slave de-parameterizes and re-parameterizes when contact is restored.
2 Intermittent 24 V DC supply to the fourth IM 153 (PS 307 undersized, long cable to the power supply, overloaded segment). Undervoltage on the IM 153's 24 V input causes a brown-out and reset; outputs stay low until the module reboots.
3 Missing or broken shield contact on the PROFIBUS connector backshell. EMI from a VFD or contactor injects noise into the bus when a parallel cable is energized, causing CRC errors and retries until the slave times out.
4 Missing or improperly placed bus termination on the segment containing rack 4. Signal reflections cause occasional framing errors that coincide with high-traffic cycle moments.
5 Faulty IM 153 module or one of the power modules in the fourth rack. Module occasionally locks up, recovers after watchdog reset.
6 EMI source (VFD output cable, unshielded motor leads, welding machine) routed parallel to the PROFIBUS drop. Periodic interference produces CRC errors with timing aligned to the offending load cycle.
7 Defective PROFIBUS repeater or OLMs in the segment to rack 4. Repeater occasionally loses regeneration.
8 Duplicate PROFIBUS address (slave or master) added by an integrator without removing an old node. Rare on a running plant but appears if a commissioning laptop is connected with the same address as a slave.

Diagnostic Buffer Retrieval Procedure

The diagnostic buffer is a ring of the last several hundred events, each with a millisecond timestamp relative to the CPU's power-on time. It is the highest-value artifact for an intermittent fault.

  1. Connect a programming device (PG) running STEP 7 V5.5 or TIA Portal V13+ to the CPU via MPI/PROFIBUS or PROFINET (for -2PN variants) using the correct access password.
  2. In STEP 7 classic: PLC → Diagnostic/Setting → Diagnostic Buffer. In TIA Portal: Online & Diagnostics → Diagnostics → Diagnostic buffer.
  3. Filter or scroll to events of type "Station failure", "Diagnostic interrupt", "Rack failure", and "I/O access error".
  4. Open each entry and record: event ID, timestamp, slave DP address, socket / slot, and any associated OB that was called.
  5. Cross-check the timestamps against the maintenance log of when operators observed the BF flash. A direct correlation confirms which slave is dropping.
If the CPU is password-protected and the password is unknown, the diagnostic buffer can still be read with a PG if the PG's access level is configured as Read access without password (CPU protection level set under HW Config → CPU → Protection). However, an OB86 cannot be added and the program cannot be modified. Plan the password reset with the plant operator before attempting program changes.

Interpreting OB82, OB86, and OB122

The three organization blocks fire for distinct reasons and the diagnostic buffer entry references the OB that ran.

OB82 – Diagnostic Interrupt

Fired when a module with diagnostic capability reports a status change (e.g., wire break on an analog input, overload on a digital output, channel error). It does not mean the bus dropped, but it appears in the same diagnostic buffer around the time of the BF event. Read OB82_MDL_ADDR to find the logical base address of the slot that raised the interrupt and inspect the module's diagnostic record in STEP 7 (Module Information → Diagnostics tab).

OB86 – Rack Failure / Return

Fired when the master loses contact with a DP slave (rack failure) and again on return. OB86_MDL_ADDR is irrelevant for PROFIBUS – use the diagnostic buffer to find the slave's DP address. OB86 is the most reliable indicator of which slave is dropping.

OB122 – I/O Access Error

Fired when the user program directly reads or writes an I/O point of a missing module (PIB, PQW, etc., or %I/%Q in immediate-access form in TIA Portal). Each access during the dropout generates one OB122 call. The diagnostic buffer entry lists the area (input/output), byte address, and the slot involved. OB122 is the consequence of the dropout, not the cause.

Buffer Event Text OB called Field of interest
"Station failure" OB86 DP slave address, rack number
"Rack returned" / "Return of station" OB86 DP slave address
"Diagnostic interrupt" OB82 Module logical address, DS0/DS1 record
"I/O access error when reading" / "when writing" OB122 Slot, area, byte
"PROFIBUS: Duplicate station address detected" none (logged only) Conflicting DP address

Step-by-Step Hardware Inspection

  1. Lockout/tag-out rack 4 only at the maintenance disconnect; leave racks 1–3 running so the master remains in RUN and the BF events continue to occur.
  2. Open the fourth IM 153's PROFIBUS connector and inspect the insulation-displacement contacts (IDC) for oxide, broken insulation, or bent pins. Siemens 6ES7972-0BA12-0XA0 and 6ES7972-0BB12-0XA0 connectors each have a PG socket for an online meter – do not insert a meter yet, just inspect.
  3. Pull the connector and re-terminate it. The cable must be cut cleanly, and the outer shield must make 360° contact with the metal strain relief.
  4. Check that the terminating resistor slider on the connector is set to ON only on the two physical ends of the segment. Confirm by counting: a four-rack star with a repeater will have exactly two terminators powered.
  5. Remove and reseat the IM 153 module. Power-cycle just the rack (PS 307 off, then on) and observe whether the BF flash pattern on the CPU changes.
  6. Inspect the 24 V supply wire at the rack: measure with a true-RMS multimeter at the IM 153 terminals. The IM 153 accepts 24 V DC nominal with a tolerance of 20.4–28.8 V (per the ET 200S manual). If the voltage sags below 20.4 V during a BF flash, the supply is the cause.
  7. Verify the PS 307 load: PS 307-1B (2 A) supplies only a limited number of ET 200S power modules. An undersized PS that is loaded at >70% will sag during inrush from neighboring loads.

PROFIBUS Cable and Connector Verification

Siemens PROFIBUS cable (6XV1830-0EH10 purple, or 6XV1830-0JH10 violet for trailing) has characteristic impedance of 150 Ω ±15 Ω. The following checks belong in any single-slave dropout investigation:

  • Measure loop resistance of the A and B cores end-to-end. A break of a single core (typically 100–150 Ω/km) reads as a normal value but is wrong; if the result varies by more than 5 Ω between A and B there is a partial fault.
  • Measure shield-to-ground resistance with the cable disconnected at both ends. It should be > 1 MΩ at the cable end and < 1 Ω where it bonds to the cabinet ground bar. Anything in between indicates a parallel ground path or a wet/damaged section.
  • Verify cable type: hybrid or non-PROFIBUS cable (CAT5 used as DP, multi-core signal cable) has wrong impedance and causes sporadic reflections.
  • Confirm segment length: at 1.5 Mbaud (default for IM 153-1) the max stub length is 6.6 m; at 12 Mbaud it is 0.3 m. A drop exceeding the spec produces reflections that align with cycle timing.
  • Confirm baud rate: a mixed-baud segment (older IM 153-1 at 1.5 Mbaud next to a 12 Mbaud node) causes intermittent reconfiguration events.

Shielding, Grounding, and EMC

PROFIBUS cable shield must be bonded to cabinet ground at both ends, with 360° contact on the connector backshell and a short pigtail (≤ 50 mm) to the ground bar inside the ET 200S enclosure. Common field mistakes:

  1. Shield clamped only with the connector strain relief (pigtail 100–300 mm) – this inductance injects HF currents that survive shielding.
  2. Shield bonded at one end only (cable labeled "grounded at one end" from a CAT5 install) – causes floating shield, which acts as an antenna.
  3. PROFIBUS cable routed in the same tray as a VFD output cable (without a metal separator) for more than 5 m. This couples common-mode noise that exceeds the IM 153's common-mode rejection at the worst-case phase angle of the drive.
  4. PROFIBUS cable passing through a ferrite-less cable gland that exposes the cable jacket near a contactor coil.

The bonding point on the IM 153 is the grounding screw on the lower front of the module (M5 terminal). Tighten to 2.5 N·m. Do not use this as the only cabinet bond – also bond the cable shield at the entry gland plate.

24 V Power Supply Integrity

The IM 153 reports internal errors but not external supply brown-outs. A 50–100 ms sag of the 24 V supply is invisible to the CPU diagnostic buffer but enough to reset the IM 153.

  • Capture the 24 V rail with an oscilloscope at the rack terminals, not at the PS 307 output. Trigger on a falling edge < 22 V and capture one full line cycle (16.7 ms at 60 Hz / 20 ms at 50 Hz). If a dip coincides with the BF flash on the CPU, the supply is the cause.
  • Check shared-return paths: the IM 153's 24 V return is typically common with digital output loads on the same PS 307. A high inrush load (solenoid, contactor coil) on a parallel branch will collapse the rail when energized.
  • Verify the PS 307 sizing: PS 307-1B (2 A, 6ES7307-1BA01-0AA0) supplies both the IM 153 and the module loads. ET 200S power modules (PM-E, PM-D) draw their own current; the IM 153 plus 16 DO on a single PS can exceed 1.6 A during inrush.
  • Check for a separate DC source: if the cabinet shares 24 V with safety circuits or motor brakes, a safety-OSSD test pulse can pull the rail low. This is the most common root cause in mixed safety/standard cabinets.

PROFIBUS Topology and Termination

A PROFIBUS segment is a single line with termination enabled at exactly the two physical ends. Star, hub, or repeater arrangements are permitted only through active repeaters (RS-485 repeater, OLM). Errors that produce one-second dropouts:

  • Terminator left ON at a repeater tap that is in the middle of the segment, instead of the end.
  • Terminator OFF at a true end-node because the cable was extended.
  • A spare PROFIBUS connector left plugged into a service port of an IM 153 with its terminator enabled.

Draw the segment with each node and its terminator state. If the segment is a four-rack line (rack 1 → rack 2 → rack 3 → rack 4) the terminator must be ON at rack 1 and rack 4 only. If a repeater sits between rack 3 and rack 4, the terminator on rack 4 stays ON and the segment ends there.

Slave Diagnostics via STEP 7

Once the diagnostic buffer points to the fourth slave, use STEP 7's slave-level diagnostic reader:

  1. Right-click the DP master system in HW Config and choose PROFIBUS → Diagnostics.
  2. The online view lists every slave with its current state. The fourth slave will show "Station failure" during a dropout and "OK" the rest of the time.
  3. For the affected slave, open Module Information (F11) and inspect the diagnostic bytes DS0 and DS1. These contain vendor-specific and standard diagnostic data, including communication status, identifier-related diagnostics, and module status.
  4. If a slot-level fault is reported, navigate to that slot's Diagnostics tab and read the channel-specific diagnostic record (DS0/1/2/3) to find the channel number and the error code.
  5. Repeat across Monitor/Modify with a fast scan to capture I/O that is in transition during the dropout.

Replacement Strategy

If the diagnostic buffer, hardware inspection, and supply checks still do not reveal a cause, replace in the following order – the cheapest and most likely parts first:

  1. PROFIBUS connector at the fourth IM 153 (6ES7972-0BB12-0XA0 with PG socket, or 6ES7972-0BA12-0XA0 without). A new connector removes a high proportion of intermittent faults.
  2. IM 153-1 module (6ES7153-1AA83-0XB0 latest firmware release). Always reinsert the SIMATIC MMC if present; the IM 153-1 keeps its DP address in MMC.
  3. PM-E DC 24 V power module feeding the fourth rack.
  4. PS 307 power supply in the fourth cabinet.
  5. Drop cable between the repeater/segment and the fourth rack. Use 6XV1830-0EH10 purple cable; do not reuse the suspect cable.
  6. Repeater (6ES7972-0AA01-0XA0) feeding the fourth segment.
Spare-parts note: Keep an IM 153-1 of the same firmware revision in the panel. Firmware V3.x and V4.x are not interchangeable without re-parameterizing the master against a matching GSD file. Confirm the MLFB (Siemens part number) before installing.

Verification Checklist

  1. Clear the diagnostic buffer and operate the plant under the same load profile for 48 hours.
  2. Confirm zero new "Station failure" entries for the fourth slave.
  3. Confirm the CPU BF LED has not illuminated.
  4. Confirm OB86 has not been called for the fourth rack.
  5. Measure the 24 V rail at the fourth IM 153 with the oscilloscope; confirm no sag below 22 V over a full shift.
  6. Inspect the diagnostic bytes DS0/DS1 of the fourth slave – they should be all-zero during normal operation.
  7. Capture one full PROFIBUS cycle with a PROFIBUS tracer (e.g., Softing PROFINET/PROFIBUS tracer or Siemens BT200) and verify zero error frames.

FAQ

What does a one-second BF flash on an S7-300 CPU mean?

The BF (Bus Fault) LED indicates that one or more configured PROFIBUS DP slaves have temporarily lost communication with the master. A flash lasting about one second is most often a single-slave physical-layer event: a bad connector, a 24 V sag, a shield fault, or a marginal IM 153. Read the diagnostic buffer for "Station failure" and "Return of station" events to identify which slave is dropping.

Can a one-second BF event put the CPU into STOP?

No, the CPU stays in RUN as long as the PROFIBUS watchdog (configured per slave, default 10 s) is not exceeded. However, the dropped slave's outputs go to their configured substitute values, and any direct P/Q access to those slots fires OB122. If OB122 is missing, the next access error forces a STOP.

How do I read the diagnostic buffer if the CPU is password-protected?

The diagnostic buffer can be read with a PG set to "Read access without password" if the CPU's protection level under HW Config permits it. The buffer is read-only in this mode. To add OB82/OB86/OB122 or change configuration, the full password is required. Document the password change with the plant operator before modifying the program.

Which OB should I add if the CPU does not have one loaded?

Add OB86 (Rack Failure) first – it logs entry/exit events and prevents the rack from being treated as permanently failed. Then add OB82 (Diagnostic Interrupt) for module-level diagnostic data, and OB122 (I/O Access Error) so the program survives direct P/Q access during a dropout. All three can be empty (just add the OB block and download) – the OB call alone is the safeguard.

Why does only the fourth rack drop while the other three are stable?

Because the symptom is on the physical path or the local supply of that rack only. Check the fourth rack's PROFIBUS connector, the IM 153's 24 V input, and any cable or shield change that was made on that segment but not on the others. If the segment is a chain, the last node is most exposed to termination and shield-daisy-chain errors.

Back to blog