Diagnosing PROFIBUS DP Slaves in SIMATIC S7 with OB86 and SFC51
This reference documents five field-proven methods for detecting PROFIBUS DP slave presence, loss, and return events from STEP 7 (SIMATIC Manager) without requiring an external diagnostics tool. It targets S7-300, S7-400, and the DP-master variants of those CPUs (also valid in concept for S7-1500 with adaptation to OBs and SFCs in TIA Portal). The methods span event-driven OB86 processing, cyclic SFC51 (RDSYSST) polling with SSL_ID = W#16#00B4, cyclic SFC13 (DPNRM_DG) standard-slave diagnostics, the WinCC Flexible FB125 block, and the "Report System Errors" generator. Each method is documented with input/output parameters, working STL samples, and the wiring required in HW Config so the diagnostic frames actually reach the CPU.
1. PROFIBUS DP Diagnostic Architecture in an S7 Station
A PROFIBUS DP master (integrated on the CPU, or via CP 342-5 / CP 443-5) maintains a cyclic poll to every configured slave. The slave returns a fixed-length diagnostic telegram. When a slave disappears, breaks, or returns, the DP master raises an event that propagates into the CPU as an OB86 call and as a system status list (SSL) update. STEP 7 exposes this information through three coordinated mechanisms:
| Path | Trigger | SFC / OB | Information delivered |
|---|---|---|---|
| Asynchronous event | Slave fail / return | OB86 + SFC 13 / 51 follow-up | Diagnostic address (MDL_ADDR), event class (EV_CLASS), fault ID (FLT_ID), rack/station flags |
| Cyclic system status | Each OB1 cycle | SFC 51 (RDSYSST), SSL_ID W#16#00B4 | DP-slave diagnostic status, 6 bytes per slave |
| Cyclic standard diagnostics | Each OB1 cycle | SFC 13 (DPNRM_DG) | Up to 32 bytes of standard PROFIBUS DP diagnostic frame per slave |
| HMI status block | Cyclic | FB125 (WinCC Flexible) | Per-slave status, station number, error code mapped for panel tags |
| Report System Errors | Configuration-driven | FB-generated (RSE wizard) | Standardised diagnostic DBs with HMI text references |
For a "slave present / not present" decision alone, the OB86 + bit-map approach is the lightest and most CPU-efficient. For richer fault analysis (e.g. channel-level diagnostics on SINAMICS, SIMOCODE), SFC13 must be called once the event is detected.
2. Prerequisites and HW Config Requirements
Before any user program can react to DP slave state, two configuration rules must be satisfied in HW Config (SIMATIC Manager → Station → Open HW Config):
- Diagnostic address must be assigned to every DP slave. Open the slave properties, switch to the "DP Slave Diagnostics" tab, and accept the default diagnostic address (typically the next free input address above the I/O area). Without this address, OB86 will not be raised for the slave.
- For I-slaves (S7-300/400 acting as intelligent slave), assign diagnostic addresses to both the DP master interface and the I-slave interface. This is documented in the TIA Portal / STEP 7 online help at Configuring diagnostic addresses (S7-300, S7-400). If either side is missing a diagnostic address, OB86 will not fire for the affected slot.
3. Method 1 — OB86 Event-Driven Slave Status (Recommended Baseline)
OB86 is called by the operating system when a DP slave fails or returns. The temporary (TEMP) variables of OB86 give the diagnostic address, event class, fault ID, and a rack/station bitmap. The relevant inputs are:
| Symbolic name | Type | Meaning |
|---|---|---|
| OB86_EV_CLASS | BYTE | B#16#38 = "incoming" (slave returned / OK), B#16#39 = "outgoing" (slave failed) |
| OB86_FLT_ID | BYTE | B#16#C4 = DP slave failure; B#16#C5 = DP slave OK (rack fault variants exist for H/F systems) |
| OB86_MDL_ADDR | WORD | Configured diagnostic address of the affected slave (the DP master module address or the slave's diagnostic base address) |
| OB86_RACKS_FLTD | DWORD | Bit-mask of the affected slots/stations |
| OB86_DATE_TIME | DATE_AND_TIME | Timestamp of the event |
3.1 STL implementation — single slave into a single bit
The reference program used in the field by the original author captures each event, derives the DP slave number from the diagnostic address, and writes a single bit per slave into a marker word area. The pattern M[MD 1304] is an indirect bit-mapped marker access, where the address of the bit to set or reset is computed at runtime.
// ===== OB86 — DP slave status bit map =====
// Inputs (TEMP) auto-populated by the CPU
L #OB86_MDL_ADDR // diagnostic address of failed/returned slave
T "MDL_ADDRs" // DB / MW copy for visibility
L #OB86_EV_CLASS
T "EV_CLASS"
L #OB86_FLT_ID
T "FLT_ID"
L #OB86_RACKS_FLTD
T "rack_fltd"
// Convert diagnostic address → slave number (lower 8 bits)
L "rack_fltd"
L DW#16#FF // mask low byte
AD
T "dp_slave_number"
// Build pointer: bit address = slave_number * 8
L "dp_slave_number"
SLD 3 // shift left 3 bits → byte offset (×8)
T MD 1304 // pointer into bit-mapped marker area
// Filter: only handle DP-slave failure/return events
L "FLT_ID"
L B#16#C4 // DP slave diagnostic event
<>I
JC nosl
L "EV_CLASS"
L B#16#38 // incoming: slave back in operation
==I
JC inwr
L "EV_CLASS"
L B#16#39 // outgoing: slave lost
==I
JC ouwr
JU nosl
inwr: NOP 0 // set the "life" bit
SET
S M [MD 1304]
JU nosl
ouwr: NOP 0 // reset the "life" bit
SET
R M [MD 1304]
JU nosl
nosl: NOP 0
BE
3.2 Behavioural rules and pitfalls
- OB86 fires only on state change. A healthy running plant produces zero OB86 calls. Do not implement "presence detection" by counting OB86 events; instead use the marker word itself.
- The mapping
DP_address → M[bit]works only while the diagnostic addresses are configured consistently with the marker layout. If diagnostic addresses are renumbered in HW Config, the mapping must be regenerated. - For projects with > 50 DP slaves, indirect addressing via
MD 1304eliminates hundreds of lines of code compared toA M 5.0 / S M 5.0blocks. - If the master is configured as DP-V1, OB86 also handles "station failure" with
FLT_ID = B#16#C5on return. Both 0xC4 and 0xC5 may need to be accepted depending on firmware.
4. Method 2 — Cyclic SFC 51 (RDSYSST) with SSL_ID W#16#00B4
SFC 51 reads a partial list of the System Status List (SSL). The sub-list W#16#00B4 returns the diagnostic status of a single DP slave. The result is a 6-byte record where byte 0 reports the slave diagnostic state:
-
B#16#00— Slave is present and configured (normal operation). -
B#16#01— Slave is not reachable / station failure. -
B#16#02— Diagnostic data available, slave is in a fault condition (call SFC 13 for details). -
B#16#03— Slave does not respond / is not configured.
4.1 SFC 51 call interface
| Parameter | Type | Value for DP slave status |
|---|---|---|
| REQ | BOOL | Edge-triggered TRUE per call (call each OB1 cycle) |
| SSL_ID | WORD | W#16#00B4 (DP slave status) |
| INDEX | WORD | Diagnostic address of the DP slave (must match HW Config) |
| SZL_HEADER | STRUCT | Output — 4-byte header (length, SZL_ID, SZL_INDEX) |
| DR | ANY | Destination area — 6 bytes recommended (e.g. MB 1000..MB 1005) |
| BUSY | BOOL | TRUE while SFC is reading |
| RET_VAL | INT | 0 = OK; non-zero = error code (see §10) |
4.2 STL implementation
// ===== OB1 — read DP slave status with SFC 51 =====
// Repeat this block for every slave, change SZL_INDEX
CALL "RDSYSST"
REQ :=TRUE
SSL_ID:=W#16#00B4
INDEX :=W#16#0800 // diagnostic address of slave (example 0x0800)
SZL_HEADER:="".SZL_HEADER_1
DR :=P#M 1000.0 BYTE 6
BUSY :=M 1100.0
RET_VAL:=MW 1102
// Evaluate byte 0 of result
L MB 1000 // status byte
L B#16#00
==I
S "slave_OK" // set "present" flag
L MB 1000
L B#16#01
==I
S "slave_LOSS" // set "lost" flag
L MB 1000
L B#16#02
==I
S "slave_FAULT" // set "fault" flag
INDEX = 0 (e.g. for a global overview). For 50+ slaves, prefer the per-slave call in a loop with the diagnostic address list loaded from a DB.5. Method 3 — SFC 13 (DPNRM_DG) Standard Slave Diagnostics
SFC 13 reads the standard PROFIBUS DP diagnostic buffer of a single slave. This is mandatory when the answer to "is the slave alive?" must be followed by "what is wrong?". For SINAMICS drives and SIMOCODE pro devices, the standard diagnostic frame is followed by identifier- and channel-specific extensions that identify the faulting module and channel.
| Parameter | Type | Description |
|---|---|---|
| REQ | BOOL | Edge TRUE to start read |
| LADDR | WORD | Configured diagnostic address of the slave |
| RET_VAL | INT | 0 = OK; W#16#80A1 = station failure; W#16#80C3 = no resources; W#16#8090 = slave not configured |
| BUSY | BOOL | TRUE while reading |
| RECORD | ANY | Destination buffer (up to 32 bytes for DP-V0; up to 244 bytes for DP-V1 extended diagnostics) |
5.1 When to use SFC 13
- You need the slave manufacturer, module, or channel information.
- You want to log the standard PROFIBUS diagnostic frame into a circular DB for trending.
- You need to forward the diagnostics to an HMI/SCADA tag.
SFC 13 must be called at the diagnostic address — not at the slave's station number. The DP master module address (e.g. LADDR = W#16#0800) is what HW Config exposes.
6. Method 4 — FB125 (WinCC Flexible Slave Diagnostics)
When a SIMATIC Panel with WinCC Flexible is in the project, the FB125 "DP_Diagnostics" block provides a pre-built interface for displaying DP slave status, station number, and error code on the HMI. It iterates through all configured slaves and updates a UDT that WinCC Flexible can pick up directly.
Typical call in OB1:
CALL "DP_DIAG"
DP_MASTERSYSTEM :=1
EXTERNAL_DP_INTERFACE :=FALSE
DP_DIAG_OUTPUT :="DP_DIAG_DB" // UDT with status per slave
The HMI engineer then binds the panel tags to the fields of DP_DIAG_DB without any extra PLC code. FB125 is the path of least resistance when a panel already exists in the project.
7. Method 5 — Report System Errors (RSE)
Report System Errors is a STEP 7 / TIA Portal generator that automatically produces standardized diagnostic blocks (one central FB, one central DB) covering PROFIBUS DP, PROFINET, and module-level faults. To use it:
- In HW Config, right-click the DP master system → "Report System Errors" → enable for the whole station.
- Select the OB priority, the diagnostic DB number, and the languages in which error texts are generated.
- Compile. STEP 7 inserts
FB_SERR,DB_SERR, and the supporting DBs automatically. - Connect the panel to the standard diagnostic DB; error texts appear as messages on the HMI without further code.
8. Configuring DP Diagnostic Addresses (S7-300 / S7-400)
The diagnostic address is the address space where the CPU writes slave-level diagnostic events so OB86 can reference them. Without a correctly assigned diagnostic address, the operating system has nothing to raise OB86 against. For S7-300/S7-400 DP slaves, follow the Siemens online help procedure at Configuring diagnostic addresses (S7-300, S7-400):
- Open the DP slave properties dialog from HW Config.
- Switch to the "Addresses" tab; ensure the diagnostic address checkbox is enabled.
- For I-slaves, repeat the assignment on both the master and slave side, and ensure that the two ranges do not overlap.
- Save and recompile HW Config, then download to the CPU.
8.1 Diagnostic address layout example
| Slave | Station # | I/O address | Diagnostic address | Marker bit |
|---|---|---|---|---|
| ET200M #1 | 3 | 0..31 | 2047 (input) | M 24.0 |
| SINAMICS G120 #2 | 5 | 256..279 | 2043 (input) | M 40.0 |
| SIMOCODE pro #3 | 7 | 288..311 | 2041 (input) | M 56.0 |
| ET200S #4 | 10 | 512..559 | 2035 (input) | M 80.0 |
9. STL Code Example — Compact Multi-Slave Status Map
The complete OB86 block below accepts any DP slave event and updates one bit per slave in a marker word area. The pattern is parameterised so a single copy serves a 100+ slave installation. For multi-master stations, call this code with different diagnostic address filters.
FUNCTION_BLOCK FB 2000
TITLE =DP Slave Status Map
VAR_TEMP
t_addr : WORD ;
t_ev : BYTE ;
t_flt : BYTE ;
t_mask : DWORD ;
END_VAR
BEGIN
NETWORK 1 // Capture OB86 inputs
L #OB86_MDL_ADDR ; T #t_addr ;
L #OB86_EV_CLASS ; T #t_ev ;
L #OB86_FLT_ID ; T #t_flt ;
L #OB86_RACKS_FLTD ; T #t_mask ;
NETWORK 2 // Filter on DP-slave events
L #t_flt ; L B#16#C4 ; <>I ; JC END_FB ;
NETWORK 3 // Determine slave number from mask
L #t_mask ; L DW#16#FF ; AD ;
SLD 3 ; T MD 1304 ; // byte pointer into marker area
NETWORK 4 // Set / reset by event class
L #t_ev ; L B#16#38 ; ==I ; JC SET_BIT ;
L #t_ev ; L B#16#39 ; ==I ; JC RES_BIT ;
JU END_FB ;
SET_BIT: SET ; S M [MD 1304] ; JU END_FB ;
RES_BIT: SET ; R M [MD 1304] ;
END_FB: BE ;
END_FUNCTION_BLOCK
Place CALL FB 2000, DB 2000 inside the OB86 STL body. The DB must be an instance DB created when FB 2000 is compiled.
10. Comparison Table — Choose the Right Method
| Criterion | OB86 bit map | SFC51 SSL 0x00B4 | SFC13 DPNRM_DG | FB125 | Report System Errors |
|---|---|---|---|---|---|
| Trigger | Event (state change only) | Cyclic (each OB1) | Cyclic on demand | Cyclic | Event + cyclic |
| CPU load (50 slaves) | Negligible (only on change) | Low | Medium | Medium | Medium/High |
| Fault detail level | Present / not present | Status byte only | Full standard diag | Status + error code | Channel-level |
| HMI text | None (manual) | None (manual) | None (manual) | Built-in | Built-in (multi-lang) |
| Works without panel | Yes | Yes | Yes | No (panel required) | Yes |
| Impact on STOP behaviour | Requires OB86 in program | None | None | None | None |
| Best use case | Compact "life" bit per slave | Plant-wide periodic checks | Detailed fault logging | Panel-driven diagnosis | Multi-device, multi-vendor |
11. Verification and Commissioning Procedure
- Static check. In HW Config, verify that every DP slave in the project tree shows a green diagnostic-address bar. Greyed-out bars indicate no diagnostic address has been assigned.
- Download and go online. Connect via MPI/Profibus/TCP and force the CPU to RUN with the OB86 code present.
- Read the marker word. Open the VAT online viewer and check that all slave status bits are TRUE (1) once the bus is fully cyclic.
- Pull a slave. Disconnect the PROFIBUS connector of one slave. Within one OB86 cycle, the corresponding bit must drop to 0 (0). The CPU must remain in RUN.
- Reconnect. Reconnect the slave; the bit must return to 1 within the next DP cycle and a B#16#38 OB86 event should appear in the diagnostic buffer.
- SFC51 sanity check. Call SFC51 against the same slave with SSL_ID = W#16#00B4; byte 0 must return B#16#00 in steady state and B#16#01 when disconnected.
- SFC13 sanity check (optional). If detailed diagnostics are required, call SFC13 and verify the standard diagnostic byte sequence. For a healthy SINAMICS, the first bytes should decode to "station OK, no module fault".
12. Troubleshooting Matrix
| Symptom | Likely cause | Resolution |
|---|---|---|
| OB86 never fires | No diagnostic address assigned in HW Config | Open slave properties, enable diagnostic address, recompile, download |
| CPU goes STOP on slave loss | OB86 not loaded in the project | Add empty OB86 to the S7 program and download |
| Marker bit stuck high despite slave loss | Diagnostic address mismatch between HW Config and pointer math | Recompute byte offset from the actual configured diagnostic address |
| SFC 51 RET_VAL = W#16#8090 | Slave not configured in HW Config | Confirm slave entry in the master system and re-download HW Config |
| SFC 51 RET_VAL = W#16#80A1 | Station failure | Check PROFIBUS cabling, terminating resistors, baud rate, station number |
| SFC 13 returns short record (6 bytes) | Slave does not support extended diagnostics | Accept DP-V0 length; rely on standard bytes for fault code |
| Bit toggles repeatedly (flapping) | Marginal PROFIBUS physical layer | Check cable shielding, terminators, EMC; examine station diagnostics for retries |
| I-slave events missing | Diagnostic addresses not assigned on both sides | Follow the procedure at Configuring diagnostic addresses (S7-300, S7-400) |
13. Field-Proven Best Practices
- Always download OB86, OB82, OB121, OB122 together. They cover rack faults, diagnostics, and programming errors. Their presence is the difference between a fault-tolerant system and a CPU that drops to STOP on a single disconnected slave.
- Place the marker-word slave map in a retentive DB if you want the last-known-good state visible after a CPU restart.
- For SINAMICS drives, do not stop at OB86 — the drive's own fault buffer (r0947 / r0948) contains fault codes (F-code numbers like F30002) that OB86 cannot expose. Combine DP slave presence detection with drive-side parameter fault retrieval for complete diagnosis.
- For SIMOCODE pro, the standard diagnostic byte 1 reports the device state (0 = run, 1 = fault). SFC 13 is the only path to retrieve it.
- Decide diagnostic polling cadence per criticality. Safety-relevant drives should not be polled faster than the DP cycle; non-critical slaves can be polled at multi-second intervals to reduce bus load.
- Reserve an M-word block (e.g. MW 1000..MW 1099) for slave status only, and document the bit-to-slave mapping in a comment row of the symbol table.
14. Frequently Asked Questions
How do I detect a PROFIBUS DP slave disconnection in STEP 7 without any panel or extra hardware?
Insert OB86 into the S7 program (so the CPU does not STOP), ensure every DP slave has a diagnostic address assigned in HW Config, and copy the OB86 inputs into your code. Set or reset a single bit per slave based on OB86_EV_CLASS (B#16#38 = incoming, B#16#39 = outgoing) and OB86_MDL_ADDR (the slave's diagnostic address). This is the lowest-overhead method.
What SSL_ID do I use with SFC 51 (RDSYSST) to read DP slave status?
Use SSL_ID = W#16#00B4 and pass the slave's configured diagnostic address as INDEX. The function returns a 6-byte record where byte 0 equals B#16#00 (slave OK), B#16#01 (slave lost), B#16#02 (slave fault, read SFC13), or B#16#03 (not configured).
Why does OB86 never fire even though my slave is missing?
The most common cause is a missing diagnostic address in HW Config. Open the DP slave properties, switch to the DP slave diagnostics tab, and accept the default address. For I-slaves (S7-300/400 as intelligent slaves), diagnostic addresses must be assigned on both the master and the slave side as described in the Siemens online help for S7-300/S7-400.
Can I read the actual fault code of a SINAMICS drive on PROFIBUS DP from SFC 13?
SFC 13 (DPNRM_DG) returns the standard PROFIBUS DP diagnostic frame. For SINAMICS, fault code and fault value are also exposed in drive parameter r0947/r0949. To read those from the S7 user program, use the acyclic DP-V1 read/write services (SFB 52 / SFB 53) against the SINAMICS parameter channel rather than the standard diagnostic buffer.
What is the difference between FB125 and Report System Errors for DP diagnosis?
FB125 is a single block that maps DP slave status to a UDT for WinCC Flexible panels, with no automatic message texts. Report System Errors is a STEP 7 generator that creates a central FB/DB pair plus multi-language HMI texts for DP, PROFINET and module-level faults. RSE is heavier but produces standardised, multi-language diagnostics out of the box.