ET200pro with S7-400H Redundancy PROFINET Limits and Y-Link

David Krause13 min read
PLC HardwareSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

ET200pro with S7-400H Redundancy: PROFINET IO Limits and the Y-Link Workaround

Engineers planning an S7-400H redundant controller often discover too late that PROFINET IO is not released for the H-System. The interface module 6ES7 154-4AB10-0AB0 (ET200pro IM154-4 PN) cannot establish a redundant PROFINET AR (Application Relationship) with a pair of 6ES7 400-0HR50-4AB0 (CPU 412-3H) or 6ES7 417-4HR05-0AB0 (CPU 417-4H) CPUs. This article documents the constraint, the standard Siemens workaround (Y-Link), and the modern migration path to S7-1500H with S2 system redundancy.

Critical constraint: Per the S7-400H Automation System manual, only PROFIBUS DP ET200 stations can be connected redundantly to an S7-400H pair. PROFINET IO devices, including the ET200pro family, require either a Y-Link conversion or migration to a current H controller.

1. Problem Statement: Why the ET200pro + S7-400H Configuration Fails

The original configuration under review comprises:

  • Two S7-400H CPUs (e.g., 6ES7 412-3HJ14-0AB0 / 6ES7 414-4HM14-0AB0 / 6ES7 416-3HR05-0AB0), linked through the backplane redundancy bus and synchronized via fiber-optic sync modules.
  • SCALANCE X414-3E (6GK5 414-3FC00-2AA2) with an Extender (6GK5 495-8BA00-8AA2) acting as the PROFINET managed switch layer.
  • ET200pro stations with IM 154-4 PN interface modules (6ES7 154-4AB10-0AB0) carrying PROFINET I/O.

Architecturally, this is sound for a single S7-400 or S7-1500 controller. For an S7-400H pair, the architecture is invalid at the protocol level. The S7-400H redundancy concept (master/reserve, link-up, update) is implemented on PROFIBUS DP through the redundant IM (IM 153-2 HF with IM/IM bus module), not on PROFINET.

2. Root Cause: PROFINET IO Is Not Released for S7-400H

The S7-400H firmware does not support redundant PROFINET ARs to ET200pro I/O devices. The H-System requires that both CPUs can:

  1. Identify the current master controller.
  2. Discard incoming telegrams from the reserve controller.
  3. Switch the I/O device between the two PROFINET communication channels in the event of CPU failure.

Only the PROFIBUS DP IM 153-2 HF (6ES7 153-2BA10-0XB0) paired with an IM/IM bus module (6ES7 153-2AR00-0XA0) implements this channel-switching behavior. A PROFINET ET200pro IM 154-4 PN has no equivalent second-AR failover logic, so the redundant controller has no valid I/O to take over.

For documentation, the relevant source is the S7-400H manual, Chapter 10 "Using I/Os in S7-400H" and the function manual "S7-400H Fault-Tolerant Systems" published on the Siemens Support (SIOS) portal.

3. Solution Path A: Y-Link Conversion (PROFINET to PROFIBUS DP)

The Siemens-recommended workaround for connecting PROFINET I/O (including ET200pro) to an S7-400H is the Y-Link, part number 6ES7 197-1LA12-0XA0 (or the updated 6ES7 197-1LA14-0XA0). The Y-Link acts as a PROFINET IO device on its upper PN interface and presents a PROFIBUS DP slave view to the S7-400H pair, including the redundant DP2/DP3 segment that the H system expects.

3.1 Y-Link topology in the H-System

CPU 0 (H) 412-3H/414-3H/416-3H CPU 1 (H) Redundant partner Y-Link 6ES7 197-1LA12 PROFINET ↔ PROFIBUS DP SCALANCE X414-3E PROFINET managed switch ET200pro #1 IM 154-4 PN ET200pro #2 IM 154-4 PN DP2 DP3 (redundant)

The Y-Link is treated by the H-System as a DP slave on the redundant PROFIBUS segment. Each H CPU owns one of the two physical DP channels. On switchover, the I/O image is preserved through the master/reserve handshake that the Y-Link implements internally.

3.2 Y-Link configuration steps

  1. Insert the Y-Link in HW Config (SIMATIC Manager) as a DP slave under both CPU 0 and CPU 1 redundant PROFibus segments.
  2. Assign a unique PROFIBUS address (default 33) and a PROFINET device name to the Y-Link.
  3. Configure the Y-Link as a PROFINET IO controller for the downstream ET200pro stations in its own PN subnet.
  4. Insert each ET200pro IM 154-4 PN (6ES7 154-4AB10-0AB0) under the Y-Link's PROFINET port, with its GSDML file: GSDML-V2.31-Siemens-ET200pro-IM154-4PN-20150126.xml (GSD revision depends on firmware of the IM).
  5. Map the ET200pro I/O slots to the Y-Link's PROFIBUS I/O image (max 244 bytes input / 244 bytes output per Y-Link).
  6. Set the Y-Link operating mode to "DP master (redundant)" in HW Config to expose the DP2/DP3 failover behavior to the H-System.
Watchpoint: The Y-Link does not support PROFINET IRT, isochronous mode, or shared device on its upper PN interface. If your ET200pro application requires IRT (e.g., for motion control), the Y-Link path is not viable and you must migrate to S7-1500H.

3.3 Y-Link limitations and I/O budget

Parameter Y-Link 6ES7 197-1LA12 Y-Link 6ES7 197-1LA14
Max. PROFINET devices downstream 16 32
Max. I/O data per Y-Link 244 B in / 244 B out 244 B in / 244 B out
PROFINET transmission RT only RT only
IRT support No No
Shared device No No
Required DP slaves on H side 1 logical DP slave per Y-Link 1 logical DP slave per Y-Link
Firmware required (H CPU) V6.0 or higher V6.0 or higher

4. Solution Path B: S7-1500H Migration with S2 System Redundancy

For new projects or refreshes, the modern replacement for the S7-400H is the SIMATIC S7-1500H (e.g., CPU 1517H-3 PN, 6ES7 517-3HP00-0AB0). The S7-1500H supports PROFINET S2 system redundancy, which is the standardized mechanism for a PROFINET IO device to maintain two ARs to two redundant controllers and switch over automatically.

From the TIA Portal documentation on S2 system redundancy:

"An IO device with S2 system redundancy supports redundant ARs. In a redundant system, an IO device with S2 system redundancy has a redundant AR for each of the two controllers. The two ARs are mirrored, allowing failover without I/O loss."

The downstream interface module that supports S2 in the ET200 family is the IM 155-5 MF/HF (e.g., 6ES7 155-5MU00-0AB0 for ET 200MP, or the equivalent for ET 200SP / ET 200pro with HF firmware).

4.1 Migration comparison

Aspect S7-400H + Y-Link S7-1500H + S2 redundancy
PROFINET I/O support Indirect, via Y-Link RT only Native, including IRT and shared device
Redundant AR Not applicable (PROFIBUS DP-based) Standardized S2 per PROFINET spec
Configuration tool SIMATIC Manager / STEP 7 V5.5 TIA Portal V17 or higher
Switchover time ~100-300 ms (DP cycle dependent) <100 ms typical
I/O data width 244 B per Y-Link (bottleneck) Full slot I/O per device
Spare parts availability Phased out, limited Active product

The ET200pro Fail Safe Controller, when used with current IM 154-4 PN firmware (V7.0 or higher with the HF feature set), can be deployed under S7-1500H S2 control with PROFIisafe on the same AR. This is the recommended path for new safety-rated distributed I/O.

5. Connection Count and S7 Communication Constraints on the S7-400H

When designing the H-System it is critical to verify the connection budget of the selected CPU. The CPU 412-3H supports a maximum of 16 S7 connections. At least one is reserved for the programming device (PG) and one for the HMI/OP, leaving a tight margin once you add PN CPU partners, I-Device relationships, or S7 connections for cross-coupling.

S7-400H CPU Max. S7 connections Max. S7 basic communication
CPU 412-3H (6ES7 412-3HJ14-0AB0) 16 8
CPU 414-4H (6ES7 414-4HM14-0AB0) 32 16
CPU 416-3H (6ES7 416-3HR05-0AB0) 64 32
CPU 417-4H (6ES7 417-4HR05-0AB0) 64 32
Watchpoint: Each H CPU runs the full connection list, but the H firmware internally multiplexes the connections through the master/reserve link. External partners (PN CPUs, X-Stations, other H systems) each consume one connection per H CPU. A pair of PN CPU partners therefore costs 2 connection resources per H CPU.

6. SFC14 / SFC15 versus SFB14 / SFB15 in the H Context

Engineers often confuse the SFC and SFB families when they first work with S7-400H. The two pairs serve fundamentally different purposes.

Block Function Use with
SFC 14 DPRD_DAT Read consistent data from a standard DP slave or PN IO device DP slaves / PROFINET I/O
SFC 15 DPWR_DAT Write consistent data to a standard DP slave or PN IO device DP slaves / PROFINET I/O
SFB 14 GET Read data from a remote CPU via S7 communication S7 connections (CPU-to-CPU)
SFB 15 PUT Write data to a remote CPU via S7 communication S7 connections (CPU-to-CPU)

SFC14 and SFC15 are valid for the PROFIBUS DP side of the H system (including the Y-Link) but cannot be used to access another S7-CPU partner over S7 communication. For that you need SFB14 (GET) and SFB15 (PUT), and an S7 connection established in NetPro / HW Config.

7. Cycle Time and Update Time Considerations

The I/O update time on the H system depends on three factors that must be sized together:

  1. OB1 cycle time of each H CPU - set in HW Config under CPU properties → Cycle.
  2. PROFIBUS DP cycle - the time the DP master polls all configured slaves. For H, both CPUs run the DP cycle on their own segment, and the I/O image is then mirrored through the fiber-optic redundancy link.
  3. Redundancy link update time - the time it takes to copy the master process image to the reserve. With a sync module in fiber-optic mode, this is typically 1-3 ms per cycle, but the worst-case link-up time is bounded by the configured max. link-up time parameter.

When the Y-Link is in the path, add the PROFINET update time of the downstream ET200pro. With the default PROFINET update time of 1 ms (RT class 1), the Y-Link adds one RT cycle of latency. The S7-400H manual, Chapter 16 "S7-400 Cycle and Response Times", provides the response-time tables used for sizing; you must validate your worst-case with that data because the manual does not provide a closed-form formula for the H system with a Y-Link.

Field-proven caveat: Engineers frequently underestimate the link-up time. The S7-400H default max. link-up time of 100 ms is too short for many process applications (especially with many ET200pro slaves). Increase it to 300-500 ms during commissioning and then reduce it once the worst-case has been measured.

8. SCALANCE X414-3E Network Design for the H-System

The SCALANCE X414-3E (6GK5 414-3FC00-2AA2) is a PROFINET managed switch with three Gigabit combo ports and seven Fast Ethernet ports. It supports the redundancy protocols HRP (High-speed Redundancy Protocol, <300 ms) and MRP (Media Redundancy Protocol, <200 ms). When deployed as the PN segment carrying ET200pro and one or more Y-Links:

  • Configure the SCALANCE in HRP manager mode and use a ring topology for the PN segment.
  • For redundant Y-Links, give each Y-Link its own SCALANCE ring port pair to provide media diversity.
  • Disable Spanning Tree on the PN segment when HRP/MRP is in use; the protocols are mutually exclusive.
  • Keep the SCALANCE Extender (6GK5 495-8BA00-8AA2) for fiber uplinks in electrically noisy zones; it is media-transparent and does not participate in HRP.

9. Step-by-Step: Bringing Up the Y-Link Configuration

9.1 Prerequisites

  • STEP 7 V5.5 SP4 or higher (HF1 for the Y-Link GSD)
  • S7-400H CPU firmware V6.0 or higher
  • Y-Link 6ES7 197-1LA12 with firmware V4.0 or higher
  • ET200pro IM 154-4 PN firmware V6.0 or higher
  • GSDML file for the ET200pro IM (GSDML-V*-Siemens-ET200pro-IM154-4PN-*.xml)
  • SCALANCE X414-3E primary software (formerly "Web Based Management")

9.2 Procedure

  1. Build the S7-400H rack with two CPUs of matching order number and firmware. Install fiber-optic sync modules and connect them with a crossover fiber pair.
  2. Configure the redundancy in HW Config: insert CPU 1, mark it as redundant, and download the project to both CPUs.
  3. Insert the Y-Link in the rack view at PROFIBUS DP (1) on CPU 0 and PROFIBUS DP (1) on CPU 1 (the redundant PROFIBUS segments). Use the Y-Link GSD file (Siem80A0.gsd for 6ES7 197-1LA12).
  4. Configure the Y-Link as a PROFINET IO controller for the downstream ET200pro ring. In the Y-Link object properties, add the ET200pro IMs and assign PROFINET device names.
  5. Map the I/O: under the Y-Link, add the ET200pro slot-level modules (e.g., 6ES7 142-4BF00-0AA0 digital input module, 6ES7 142-4BF00-0AB0 digital output module). The I/O image is exposed to the H system as PROFIBUS I/O under the Y-Link DP slave.
  6. Set the DP cycle to 5 ms (typical) in HW Config on both DP segments. Verify with the response-time table in Chapter 16 of the S7-400H manual.
  7. Configure the SCALANCE as HRP manager, set ring ports, and assign IP addresses. Verify PN device names and IP addresses are consistent with HW Config.
  8. Download the project to both H CPUs and start them. The Y-Link will go online and report both PN and DP links up.

9.3 Verification

  1. Online → Accessible Nodes shows both H CPUs, both Y-Links, and all ET200pro IMs as reachable.
  2. Module Information on each ET200pro IM shows the AR is established and the I/O data is updating.
  3. Force a switchover by stopping CPU 0 (mode selector to STOP). The I/O must continue updating without a process fault, and CPU 1 must take over within the configured max. link-up time.
  4. Disconnect one PROFINET cable on the SCALANCE ring. HRP must converge in <300 ms and the I/O must continue updating.
  5. Disconnect one PROFIBUS DP cable between an H CPU and the Y-Link. The H system must continue to communicate through the other CPU and the Y-Link must continue to expose the I/O to the active CPU.

10. Troubleshooting Matrix

Symptom Likely cause Corrective action
ET200pro IM reports "IO device not accessible" after project download PROFINET device name mismatch Use the Topology Editor in STEP 7 to assign the device name from the H project. Verify with online diagnostics.
Y-Link shows DP fault on H CPU 1 only PROFIBUS address conflict on the redundant segment Ensure the Y-Link has a unique PROFIBUS address on each segment, and that no other DP slave shares that address.
Switchover takes >500 ms Max. link-up time too short for the configured I/O volume Increase max. link-up time to 500 ms in HW Config → CPU properties → H Parameters.
ET200pro station drops out intermittently PROFINET update time shorter than device refresh Increase PN update time to 2 ms on the Y-Link, and verify SCALANCE port statistics for CRC errors.
SFC14 returns STATUS = 80A1 or similar DP error SFC14 used on a non-DP slave partner (e.g., a PN CPU via S7 connection) Replace with SFB14 (GET). Reserve SFC14/SFC15 for the Y-Link PROFIBUS side only.
Connection count exceeded on CPU 412-3H More than 16 S7 connections configured Move to CPU 414-4H (32 connections) or restructure with one PN CPU as a shared partner rather than multiple direct connections.
Halt of H-System on "redundancy loss" after Y-Link stop Y-Link treated as a non-redundant slave In HW Config, set the Y-Link operating mode to "DP master (redundant)" and verify the DP2/DP3 slots are populated on both CPUs.

11. Frequently Asked Questions

Can ET200pro (IM 154-4 PN) be used directly on an S7-400H redundant CPU pair?

No. PROFINET IO is not released for S7-400H. The H firmware does not implement redundant PROFINET ARs. Use a Y-Link (6ES7 197-1LA12 or -1LA14) to convert PROFINET RT to PROFIBUS DP, or migrate to S7-1500H with S2 system redundancy and an IM 155-5 MF/HF device.

What is the maximum number of S7 connections on an S7-400H CPU 412-3H?

The CPU 412-3H (6ES7 412-3HJ14-0AB0) supports 16 S7 connections. At least one is reserved for the programming device and one for HMI, so the practical budget for PN CPU partners, I-Device links, and S7 cross-coupling is 14. Move to a CPU 414-4H or 417-4H if you exceed this.

Which Siemens I/O devices support S2 system redundancy on PROFINET?

The IM 155-5 MF/HF (6ES7 155-5MU00-0AB0 for ET 200MP) and the IM 154-4 PN with current HF firmware for ET200pro support S2. S2 is part of the PROFINET specification and is documented in the TIA Portal online help under "S2 system redundancy." Pair these with an S7-1500H controller.

Can I use SFC14 and SFC15 to read data from a remote S7 CPU partner of the H system?

No. SFC14 (DPRD_DAT) and SFC15 (DPWR_DAT) are for standard DP slaves and PROFINET IO devices only. For data exchange with a remote S7 CPU over an S7 connection, use SFB14 (GET) and SFB15 (PUT), as documented in the STEP 7 help for the S7-400H.

What is the failover time of the Y-Link path on S7-400H?

Switchover is dominated by the S7-400H max. link-up time (default 100 ms, typically raised to 300-500 ms for ET200pro volumes) and the PROFIBUS DP cycle (typically 5-10 ms). Realistic failover is 100-500 ms end-to-end. For sub-100 ms failover, migrate to S7-1500H with S2.

Back to blog