Downloading S7 Hardware Configuration in RUN Mode Methods

David Krause21 min read
S7-300SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Downloading S7 Hardware Configuration in RUN Mode: Methods & Limits

The question of whether a Siemens S7-300 or S7-400 CPU can accept a hardware configuration (HW Config) download while the process remains in RUN is one of the most common engineering misconceptions in brownfield modernization. The short, unambiguous answer for a single, non-redundant CPU is no: any change to the central or distributed hardware configuration forces a STOP→STARTUP→RUN transition. The only true path to zero-process-impact hardware configuration changes is a redundant topology — either an S7-400H high-availability system or a Software Redundancy (SWR) pair of S7-300/S7-400 CPUs. This reference covers the underlying reasons, the exact exceptions, the TIA Portal and STEP 7 V5.x procedures that work, and the safety gates that must be implemented when you apply them.

1. Why Hardware Configuration Normally Forces a STOP Transition

When you change the hardware configuration of an S7-300 or S7-400 station, the engineering tool regenerates the system data blocks (SDBs). The CPU's startup routine re-reads the SDBs, rebuilds the hardware object list (HwIo) in work memory, reinitializes the process image partition (PIP) table, and re-runs the module parameter assignment handshake on the backplane bus or on PROFIBUS / PROFINET. None of those steps can occur on a live execution level of OB 1 without breaking the consistency guarantees that OB 35 (cyclic interrupt), OB 40–OB 47 (hardware interrupts), OB 55–OB 57 (DP/PROFINET interrupts), OB 70 (I/O redundancy error), OB 82 (diagnostic interrupt), OB 83 (insert/remove interrupt), OB 85 (program execution error), OB 86 (rack failure), OB 100 (warm restart), OB 101 (hot restart), and OB 102 (cold restart) rely on. Siemens therefore locks the operation: a hardware configuration download is only accepted when the target CPU is in STOP.

CPU operating modes relevant to HW config downloads
Mode Accept HW Config download? Process I/O User program
STOP Yes (only state that accepts it) Outputs to safe state (substitute value 0 unless changed per channel) Not executed
STARTUP (OB 100 / 101 / 102) No Restricted; depends on startup type Startup OBs only
RUN No (single CPU) Live OB 1 + cyclic/interrupt OBs
HOLD No Frozen Single-step debugging only

Diagnostic buffer entries for a forced STOP caused by a config download are typically in the operating-mode change class (event ID 16#43xx). Reading the buffer via Online > Diagnostics > Diagnostic Buffer in TIA Portal is the first verification step after any such event.

1.1 SDB Container Structure

The SDBs are stored in the load memory of the CPU (MMC for S7-300, integrated or MMC for S7-400). SDB 0 contains the central rack configuration; SDB 1 contains the distributed I/O configuration. Additional SDBs (SDB 2 through SDB 4xxx) hold per-module parameter records. A delta in any of these triggers the rebuild. TIA Portal's "Compile" step regenerates all SDBs; an incremental "Download to device" only transfers the changed SDBs but the CPU still restarts to apply them. The SZL (System State List) partial list 0x0111 (module identification) and 0x0A91 (module status) can be read back online to verify that the new SDB container is in effect after the restart.

2. Standard S7-300: Hardware Configuration Download Restrictions

All S7-300 CPUs — from the entry-level CPU 312 to the flagship CPU 319-3 PN/DP — share the same restriction: a hardware configuration download is rejected if the CPU is in RUN, STARTUP, or HOLD. This applies regardless of whether the change is a new module, a different slot, a re-parameterized analog input range, or a renamed PROFIBUS DP slave.

Workarounds occasionally proposed in field discussions — toggling the mode selector, removing the MMC, or "tricking" the online interface — do not change the result. The CPU performs the SDD (System Data Download) check, sees the configuration delta, and requests STOP. Attempting to download during RUN with the "Download to device" command in TIA Portal results in a dialog stating "The module does not support download in RUN". In legacy STEP 7 V5.x, the equivalent error is logged to the diagnostic buffer with a configuration-error event (16#45xx or 16#49xx range) and the CPU remains in STOP after the failed attempt.

Common S7-300 CPUs and their HW Config download behavior
CPU Typical order number Max modular I/O Hot config download?
CPU 312 6ES7 312-1AE14-0AB0 8 SMs No
CPU 313C-2 DP 6ES7 313-6CG04-0AB0 Compact + 8 SMs No
CPU 315-2 DP 6ES7 315-2AH14-0AB0 32 SMs No
CPU 317-2 PN/DP 6ES7 317-2EK14-0AB0 32 SMs No
CPU 319-3 PN/DP 6ES7 318-3EL01-0AB0 32 SMs No

If you need to add a signal module to a running S7-300 station, the supported pattern is: bring the CPU to STOP, perform the download, and execute a warm restart (OB 100) or cold restart (OB 102) — the choice of which OB runs is set in the CPU properties under Startup. Configure Startup when expected/actual configuration differ carefully: Startup only when compatible is the conservative setting for process-critical systems; Startup also when not compatible will accept a new module the CPU has not seen before but can mask genuine configuration errors.

3. Standard S7-400: Hardware Configuration Download Restrictions

S7-400 single CPUs (e.g., CPU 412-2 PN, CPU 414-3 PN/DP, CPU 416-3 PN/DP) are also locked to STOP for any hardware configuration change. S7-400 is faster at the SDD check than S7-300 because of the larger work memory and dedicated firmware path, but the rule is the same: a delta in HW Config means a restart. The diagnostic buffer entry for the STOP is in the operating-mode change class with event ID 16#4300.

The exception begins with the S7-400H family.

4. S7-400H: The Only True Online Hardware Configuration Path on a Siemens PLC

The S7-400H high-availability system uses two redundant CPUs (rack 0 and rack 1) connected by fiber-optic sync modules. One CPU holds the role of master; the other runs in hot-standby with synchronized program execution, memory image, and I/O. The system tolerates the loss of either CPU without interrupting the process — and it is precisely this tolerance that allows one CPU to be put in STOP, reconfigured, and restarted while the other carries the process.

S7-400H CPU pairings (must be identical in order number and firmware)
H-CPU Typical order number Work memory (code / data) Bit memory / S7 timers / S7 counters
CPU 412-3H 6ES7 412-3HJ14-0AB0 768 KB / 768 KB 4 KB / 256 / 256
CPU 414-4H 6ES7 414-4HM14-0AB0 2 MB / 2 MB 8 KB / 512 / 512
CPU 416-3H 6ES7 416-3HS16-0AB0 8.5 MB / 8.5 MB 16 KB / 1024 / 1024
CPU 417-4H 6ES7 417-4XT05-0AB0 32 MB / 32 MB 32 KB / 2048 / 2048

Sync modules are mandatory. The standard 10 m fiber pair is 6ES7 960-1AA04-0XA0; the long-distance variant 6ES7 960-1AB04-0XA0 supports up to 10 km over multi-mode fiber. Both CPUs must be loaded with the same project, same firmware, and the same SDB container version — a mismatch is caught at the first link-up and logged in OB 70 (I/O redundancy error) or OB 72 (CPU redundancy error).

4.1 Procedure to Update Hardware Configuration on a Live S7-400H

  1. Verify redundancy health. Open the H-system diagnostic screens and confirm RACK 0 and RACK 1 both show RUN-Redundant. The H-status LED on each CPU must be green. Any of the following states must be resolved first: Solo, Link down, Standby (not synchronized), Update in progress.
  2. Open the project in TIA Portal (V16 or later recommended for V8 firmware H-CPUs) and load the modified H-station project. Use Online > Download to device with the Consistent download option enabled. The tool detects the redundancy and offers to download to the standby CPU first.
  3. Force a role switch. Click Online > Operating Mode > Switch Master/Standby (or call the SFC 90 "H_CTRL" instruction with CTRL = "MASTER-STANDBY"). The current standby becomes master, the current master becomes standby. The H-system handles the role swap within a single cycle; outputs are unaffected.
  4. Download the new HW Config to the now-standby CPU. The download places that CPU in STOP, applies the new SDBs, and the CPU restarts in RUN-Redundant. The active master continues executing without process interruption.
  5. Repeat the role switch and download to the new standby (the original master). Confirm both CPUs return to RUN-Redundant and the link-up event is logged with the same firmware version on both.
  6. Verify with Online > Diagnostics > Diagnostic Buffer on both CPUs. The expected sequence is: standby download → startup → link-up → redundant sync established. The H-system's redundancy error OBs (OB 70, OB 72) should not have triggered during the procedure; if they did, investigate the sync link and the firmware compatibility matrix.
Process impact: Even on an S7-400H, a single-CPU download (i.e., a non-redundant S7-400) forces a STOP. Redundancy is the prerequisite, not a download flag. A failed redundancy link during the procedure means a real process stop, and the engineering station must be prepared to roll back the HW Config to the previous SDB container.

4.2 Module Replacement Under Power (Hot Swap) on S7-400H Racks

The S7-400H central rack supports module replacement under power via the redundant PS 405 / PS 407 power supplies and the active backplane bus. Both the master and standby racks can be serviced one at a time, and a single H-CPU can be replaced with the system running as long as the other CPU is healthy. Signal modules in the central rack use the S7-400 hot-swap mechanism: pull the failed module, insert the replacement, the surviving CPU detects the module change via OB 83 (insert/remove), and the new module is parameterized from the existing SDB without a CPU restart.

This is module-level hot swap, not a configuration change — the SDB is unchanged; the CPU is re-using the existing configuration against a freshly inserted module of the same type. Adding a module that is not in the SDB is a different operation and is still blocked without a STOP.

5. Software Redundancy (SWR) for S7-300 and S7-400

The Software Redundancy package (order number 6ES7 862-0AC01-0YA0 for SWR V2.0; SWR V3.x is delivered with STEP 7 V5.6+ and is integrated in TIA Portal V16+ for the S7-300/400 target) implements redundancy in software on top of two standard S7-300/S7-400 CPUs that are not necessarily identical to each other but must each be supported. The package adds four libraries: SWRS_CTRL (master/standby handshake), SWRS_SND and SWRS_RCV (DP slave data synchronization), and SWRS_DIAG (diagnostics). The two CPUs exchange their data images and the non-redundant DP slave image over PROFIBUS DP using a dedicated DP connection, so a slave failure on one side does not stop the other.

Unlike S7-400H, SWR does not provide hot-standby execution; the backup CPU is in RUN but only sends a heartbeat, it does not execute the process. When the master fails, the backup takes over within the configured monitoring time (typical: 100–500 ms, set in the SWR configuration). This makes the failover slower than S7-400H (which is in the millisecond range) but is acceptable for non-safety, non-motion processes.

SWR V2.0 vs. V3.0 capability matrix
Feature SWR V2.0 SWR V3.0 / V3.1
Max number of paired stations 2 2 (V3.0) / up to 4 in V3.1 with switchover mode
Data exchange medium PROFIBUS DP only PROFIBUS DP or PROFINET (PN-capable S7-300/400 CPUs)
Max mirrored data per slave 1024 bytes 4096 bytes
Supported S7-300 CPUs CPU 315-2 DP / 317-2 CPU 315-2 DP / 317-2 / 319-3 PN/DP
Supported S7-400 CPUs CPU 412-2 / 414-2 / 414-3 / 416-2 / 416-3 / 417-4 CPU 412-2 / 414-3 / 416-3 / 417-4
Staggered HW Config download Yes Yes

5.1 Updating HW Config on an SWR Pair

  1. Confirm the master CPU is the one you want to update first, or force a master/standby role swap through the SWRS_CTRL block. The two CPUs exchange their roles at the next SWR cycle.
  2. Download the new HW Config to the standby CPU. As in any single CPU, the download forces a STOP. The running master CPU continues the process.
  3. When the standby CPU completes its startup and is again in RUN, verify the SWR link status — the STATUS output of the SWRS_CTRL block must show SYNC_OK or the equivalent per SWR version. The two CPUs re-synchronize their data images.
  4. Download the same HW Config to the master CPU. A forced master/standby swap will then take place at the next SWR cycle, and the process sees a brief master transition (sub-millisecond to a few hundred ms depending on monitoring time).
  5. Validate in the diagnostic buffer of both CPUs: the SWR OBs (OB 86, OB 87, OB 88) should remain quiet, and the role swap events should be visible in the buffer with the standard "Standby → Master" / "Master → Standby" diagnostic events.
Prerequisite: SWR requires both CPUs to have a DP or PN interface for the SWR data exchange connection. S7-300 CPUs must support DP master functionality (CPU 315-2 DP / CPU 317-2 / CPU 319-3 PN/DP). The classic CPU 312/314 cannot be used as an SWR partner because they lack the required interface count for both the I/O and the SWR data exchange connection.

6. TIA Portal: The Download Mechanics

The TIA Portal menu path Online > Download to device is the single entry point for both the initial configuration download and incremental updates. Per the TIA Portal online help (Downloading a configuration to a device), the first download to a target device always transfers the complete hardware configuration. Subsequent downloads can be partial — only the changed objects are transferred — but the CPU still restarts to apply them.

What TIA Portal transfers on a HW Config download
Object First download Incremental download Requires STOP?
System data blocks (SDB 0, SDB 1, ...) Complete Delta only Yes
Module parameters (e.g., AI range, filter) Included Delta only Yes
PROFIBUS / PROFINET device list Complete Delta only Yes
User program (OBs, FBs, DBs) Complete Delta only No (with "Download to device > Software (only changes)" enabled)
Hardware catalog (library) Local to engineering station Local only N/A

Important operator action: uncheck All in the "Download to device" dialog and check only the items you intend to transfer. Selecting "Hardware configuration" by itself when the user program is unchanged is the correct pattern, and it is the configuration download that the CPU will reject in RUN.

For an S7-400H, the TIA Portal download dialog adds a "Download to both CPUs" option that performs the staggered download described in §4.1. For an SWR pair, the download is performed twice (once to each CPU), with the operator choosing the order to align with the planned role swap.

6.1 STEP 7 V5.x Equivalence

In STEP 7 V5.5 / V5.6, the equivalent menu path is PLC > Download to Target System (German: Zielsystem > Laden). The dialog shows the same delta detection. For S7-400H, the "Download to Target System — H Station" dialog adds the role-swap prompt. The HW Config tool (§3 of SIMATIC Manager) is the offline editor; the online consistency check is invoked before the download proceeds.

7. Hot-Swap Module Replacement vs. Configuration Download

A common confusion in the field is the difference between physically replacing a module that is already in the configuration versus adding a new module to the configuration. The first is supported on several S7-300 and S7-400 modules through the OB 83 mechanism; the second is not.

Hot-swap-capable S7 modules and their prerequisites
Module family Hot-swap capable? OB 83 required? CPU prerequisite
S7-300 SM 321/322/323/331/332/334 (central) Limited (only via active backplane in specific rack configurations) Yes Firmware V3.x or later
S7-400 SM 421/422/431/432 (central) Yes (central rack only, requires active backplane) Yes Any S7-400 CPU
ET 200M (IM 153-2) Yes, all SMs in the ET 200M station Yes PROFIBUS master capable CPU
ET 200S (IM 151-1) Yes, including power modules Yes PROFINET / PROFIBUS master
ET 200SP (IM 155-6) Yes, all BaseUnits without BU cover (no new config) Yes PROFINET controller capable CPU

OB 83 ("Insert/remove module interrupt") must be programmed in the user program. The default response in an S7-300/400 if OB 83 is not present is a CPU STOP — this is the most common reason that "hot swap" attempts fail in the field. Insert the OB 83 (empty or with a diagnostic logging statement), recompile, download to RUN (a software-only change), then attempt the physical replacement.

8. Comparison Matrix: Single CPU vs. S7-400H vs. SWR

Online HW config update capability by topology
Topology Online HW config update Process interruption Failover time Notes
Single S7-300 CPU No Full STOP→STARTUP→RUN N/A Standard case
Single S7-400 CPU No Full STOP→STARTUP→RUN N/A Standard case
S7-400H (two redundant H-CPUs) Yes (staggered per §4.1) None on the process <100 ms typical True hot redundancy, expensive
Software Redundancy pair Yes (staggered per §5.1) None on the process 100–500 ms (configured) Cheaper, slower failover
Schneider M580HSBY Hot-Standby Yes (similar staggered procedure) None on the process ~13 ms typical Comparable role to S7-400H on the Modicon platform, documented in the M580 Hot Standby System Planning Guide and EcoStruxure Control Expert (Unity Pro) help

The Schneider M580 Hot-Standby (M580HSBY) is referenced here as a cross-vendor comparison only; the engineering procedure is documented in the EcoStruxure Control Expert (Unity Pro) help and the Modicon M580 Hot Standby System Planning Guide, available from the Schneider Electric product documentation portal. The principle is the same: two CPUs, one runs the process, the other is on hot-standby, and the running CPU carries the load while the standby is brought down for a configuration update.

9. Commissioning and Verification Procedure

  1. Pre-flight check: confirm the redundant link (fiber for S7-400H, DP/PN cable for SWR) is healthy and the standby CPU is in sync. For S7-400H, the diagnostic buffer on both CPUs must show no pending errors; the redundancy status OBs (OB 70, OB 72) must be empty.
  2. Offline simulation: compile the project. TIA Portal's Compile reports SDB errors that would otherwise only surface at the target CPU. STEP 7 V5.x's Station > Check Consistency and PLC > Check Module Identification perform the same function.
  3. Download to standby: select the standby CPU, perform the download, verify it restarts to RUN-Redundant (H) or RUN with SWR sync (SWR).
  4. Role swap: trigger the master/standby swap, observe the diagnostic buffer event, confirm the process continues without I/O glitches.
  5. Download to new standby: repeat the download for the new standby CPU.
  6. Final check: confirm both CPUs report identical firmware version, identical SDB container version, and identical project checksum. Use the SZL partial list 0x0019 (H-system identification) and 0x0111 (module identification) to read back the live state.
  7. Operator acceptance: have the control room operator sign off on the role swap log and the diagnostic buffer excerpts; archive these in the project change log.

10. Safety and Process Protection Considerations

Even when the topology allows a zero-process-impact HW config update, treat every such change as a "near-live" maintenance window. Specific points:

  • Make sure the process area is informed and operators are aware that outputs may briefly transition during the role swap, even though the process should continue.
  • Disable any forced outputs or override conditions in the active CPU before the role swap. The S7-400H role swap does not preserve "force" states — a forced output on the master that is not forced on the standby will revert to the program value on swap.
  • For SWR pairs, the monitoring time setting is the worst-case process latency on a master failure. A value of 100 ms is typical; below 50 ms risks spurious swaps from network jitter, above 500 ms risks unacceptable process lag on a real failure.
  • Document the new SDB version (read it via the CPU's online diagnostics, "System data" tab). This is the audit trail for the change.
  • For functional safety systems (F-CPU in S7-300F / S7-400F / S7-1500F), no online HW config change is permitted in RUN even on a redundant F-system. Bring the F-CPU to STOP and follow the safety acceptance test procedure for the change.
  • For PROFIsafe slaves (F-modules in ET 200M / ET 200SP / ET 200pro), parameter changes require a re-acceptance test; staggered HW config updates on an H-system still trigger PROFIsafe re-parameterization, which forces a re-integration of the F-slave with the F-host's CRC checks.

11. Troubleshooting Matrix

Common download failures and their remedies
Symptom Likely cause Diagnostic clue Remedy
Download rejected with "CPU is in RUN" Single CPU, not in STOP Diagnostic buffer event class 16#43xx Bring CPU to STOP, or move to redundant topology
Download rejected with "SDB error" Mismatched module type or slot Diagnostic buffer event class 16#45xx / 16#49xx Correct module order number in HW Config
Download accepted, CPU does not return to RUN OB 83/85/86 missing for the new module Diagnostic buffer events from startup OBs Add missing error OBs or set "Startup only when expected/actual match"
H-system download to standby fails Redundancy link not healthy H-status LED amber/red, OB 70 fired Restore fiber link, re-establish sync, retry
SWR standby does not re-sync DP link failure, monitoring time too short SWRS_CTRL STATUS not SYNC_OK Check DP cable, increase monitoring time, verify GSD file version
Module replacement during RUN triggers STOP OB 83 not programmed Diagnostic buffer "Module removed/inserted, no OB available" Add OB 83 in the user program, recompile, download
Outputs go to "0" on a non-redundant CPU after download Normal STOP behavior; substitute values 0 LEDs: STOP, SF may be on briefly Set "Output substitute value" per channel in HW Config, then transition to redundant topology for zero-impact updates
Forced values lost after role swap on H-system Force table is per-CPU, not mirrored Compare force table on both CPUs after swap Re-apply forces on the new master before the next swap

12. Common Project Engineering Mistakes

  1. Assuming a CPU "supports" online HW config downloads — the S7-300/400 firmware has no such option; the only way to change configuration in RUN is through the redundant topology mechanisms above.
  2. Mismatched module order numbers in HW Config vs. installed module — a typo in the catalog number (e.g., 6ES7 331-7KF02 vs. 6ES7 331-1KF02) triggers a download-time configuration error even on a single CPU in STOP.
  3. OB 83 forgotten after the first hot-swap module was added — the OB exists in the offline project but is not in the CPU's load memory because it was never downloaded; or it was downloaded once and a later program change removed it.
  4. Substitute value strategy not defined — an S7-300/400 in STOP defaults to output = 0, which can drive actuators to unsafe positions. For a hydraulic valve, "0" might mean "open"; for an ESD solenoid, "0" might mean "trip".
  5. S7-400H firmware mismatch across the pair — after a TIA Portal upgrade, one CPU may receive a firmware update via the download while the other is still on the old version. The link-up will fail. Resolve by performing the firmware update on the standby first, then the master, and only then loading the new HW Config.
  6. SWR monitoring time set below 50 ms — network jitter from a busy PROFIBUS segment causes spurious role swaps, which can be worse than a process stop.
  7. Ignoring PROFIsafe re-parameterization — a staggered HW Config update on an H-system that includes F-slaves will force the F-host to re-integrate each F-slave. This re-integration is logged in the F-host's diagnostic buffer; operators may misinterpret the F-host's standard "F-integration in progress" event as a fault.

13. Cycle Time and Memory Implications

An S7-400H dual-CPU setup doubles the user program execution path in terms of compile-time validation, even though the redundant CPU does not actively execute OB 1 in parallel — it executes a cyclic "shadow" image used for the link-up comparison. This adds 10–20% to the OB 1 scan time in well-engineered systems. S7-300 SWR pairs add a smaller overhead (1–5%) because the standby CPU only runs the SWR synchronization OBs and a heartbeat.

Memory budget: an S7-400H station with the redundant configuration requires two SDB containers, two of every user block loaded, and the H-system library (H-system firmware blocks). Plan a 30–40% increase in load memory compared to a single S7-400 station. For SWR, the SWR library blocks add about 200 KB to the load memory of each CPU.

Can a single S7-300 CPU accept a hardware configuration download while in RUN?

No. All S7-300 CPUs reject the download and force a STOP→STARTUP→RUN transition. The diagnostic buffer logs an operating-mode change event in the 16#43xx class. Use a redundant topology (S7-400H or SWR) to avoid process interruption.

Which S7-400 CPU is required for a redundant hardware configuration download?

Only the S7-400H series: CPU 412-3H (6ES7 412-3HJ14-0AB0), 414-4H (6ES7 414-4HM14-0AB0), 416-3H (6ES7 416-3HS16-0AB0), or 417-4H (6ES7 417-4XT05-0AB0). Both CPUs must be identical in order number and firmware. They communicate via 6ES7 960-1AA04-0XA0 (10 m) or 6ES7 960-1AB04-0XA0 (10 km) fiber-optic sync modules.

Is Software Redundancy a substitute for S7-400H?

For non-safety, non-motion processes, yes. SWR (order number 6ES7 862-0AC01-0YA0 for V2.0) adds master/standby logic to two standard S7-300/400 CPUs and supports a staggered online config update. Failover is slower (100–500 ms vs. under 100 ms for S7-400H) and the backup CPU does not execute the process in parallel.

Does adding OB 83 to my program enable online HW config downloads?

No. OB 83 handles physical module removal and insertion at the backplane or on the distributed I/O. It does not let the CPU accept a new HW Config SDB. A CPU restart is still required for any configuration change; OB 83 only covers module-level hot swap against an unchanged SDB.

What is the correct TIA Portal menu to download only the HW Config and not the user program?

Open the project, select the device, choose Online > Download to device, then in the dialog uncheck "Software (all blocks)" and check "Hardware configuration" only. Click "Load". The CPU will still restart to apply the SDB changes. See the Downloading a configuration to a device page in the TIA Portal help for the full procedure.

Can an S7-300F or S7-400F safety CPU update its hardware configuration online through redundancy?

No. Functional safety CPUs (F-CPUs) require a STOP and a documented safety acceptance test for any change to the F-system configuration, including F-slave parameter changes. The redundant topology (S7-400H-F or S7-300F SWR-F) is used to maintain process continuity, but the safety acceptance gate applies to every F-system change regardless of the underlying redundancy.

Back to blog