ET200pro with S7-400H Redundancy: PROFINET IO Limits and the Y-Link Workaround
Engineers planning an S7-400H redundant controller often discover too late that PROFINET IO is not released for the H-System. The interface module 6ES7 154-4AB10-0AB0 (ET200pro IM154-4 PN) cannot establish a redundant PROFINET AR (Application Relationship) with a pair of 6ES7 400-0HR50-4AB0 (CPU 412-3H) or 6ES7 417-4HR05-0AB0 (CPU 417-4H) CPUs. This article documents the constraint, the standard Siemens workaround (Y-Link), and the modern migration path to S7-1500H with S2 system redundancy.
1. Problem Statement: Why the ET200pro + S7-400H Configuration Fails
The original configuration under review comprises:
- Two S7-400H CPUs (e.g., 6ES7 412-3HJ14-0AB0 / 6ES7 414-4HM14-0AB0 / 6ES7 416-3HR05-0AB0), linked through the backplane redundancy bus and synchronized via fiber-optic sync modules.
- SCALANCE X414-3E (6GK5 414-3FC00-2AA2) with an Extender (6GK5 495-8BA00-8AA2) acting as the PROFINET managed switch layer.
- ET200pro stations with IM 154-4 PN interface modules (6ES7 154-4AB10-0AB0) carrying PROFINET I/O.
Architecturally, this is sound for a single S7-400 or S7-1500 controller. For an S7-400H pair, the architecture is invalid at the protocol level. The S7-400H redundancy concept (master/reserve, link-up, update) is implemented on PROFIBUS DP through the redundant IM (IM 153-2 HF with IM/IM bus module), not on PROFINET.
2. Root Cause: PROFINET IO Is Not Released for S7-400H
The S7-400H firmware does not support redundant PROFINET ARs to ET200pro I/O devices. The H-System requires that both CPUs can:
- Identify the current master controller.
- Discard incoming telegrams from the reserve controller.
- Switch the I/O device between the two PROFINET communication channels in the event of CPU failure.
Only the PROFIBUS DP IM 153-2 HF (6ES7 153-2BA10-0XB0) paired with an IM/IM bus module (6ES7 153-2AR00-0XA0) implements this channel-switching behavior. A PROFINET ET200pro IM 154-4 PN has no equivalent second-AR failover logic, so the redundant controller has no valid I/O to take over.
For documentation, the relevant source is the S7-400H manual, Chapter 10 "Using I/Os in S7-400H" and the function manual "S7-400H Fault-Tolerant Systems" published on the Siemens Support (SIOS) portal.
3. Solution Path A: Y-Link Conversion (PROFINET to PROFIBUS DP)
The Siemens-recommended workaround for connecting PROFINET I/O (including ET200pro) to an S7-400H is the Y-Link, part number 6ES7 197-1LA12-0XA0 (or the updated 6ES7 197-1LA14-0XA0). The Y-Link acts as a PROFINET IO device on its upper PN interface and presents a PROFIBUS DP slave view to the S7-400H pair, including the redundant DP2/DP3 segment that the H system expects.
3.1 Y-Link topology in the H-System
The Y-Link is treated by the H-System as a DP slave on the redundant PROFIBUS segment. Each H CPU owns one of the two physical DP channels. On switchover, the I/O image is preserved through the master/reserve handshake that the Y-Link implements internally.
3.2 Y-Link configuration steps
- Insert the Y-Link in HW Config (SIMATIC Manager) as a DP slave under both CPU 0 and CPU 1 redundant PROFibus segments.
- Assign a unique PROFIBUS address (default 33) and a PROFINET device name to the Y-Link.
- Configure the Y-Link as a PROFINET IO controller for the downstream ET200pro stations in its own PN subnet.
- Insert each ET200pro IM 154-4 PN (6ES7 154-4AB10-0AB0) under the Y-Link's PROFINET port, with its GSDML file:
GSDML-V2.31-Siemens-ET200pro-IM154-4PN-20150126.xml(GSD revision depends on firmware of the IM). - Map the ET200pro I/O slots to the Y-Link's PROFIBUS I/O image (max 244 bytes input / 244 bytes output per Y-Link).
- Set the Y-Link operating mode to "DP master (redundant)" in HW Config to expose the DP2/DP3 failover behavior to the H-System.
3.3 Y-Link limitations and I/O budget
| Parameter | Y-Link 6ES7 197-1LA12 | Y-Link 6ES7 197-1LA14 |
|---|---|---|
| Max. PROFINET devices downstream | 16 | 32 |
| Max. I/O data per Y-Link | 244 B in / 244 B out | 244 B in / 244 B out |
| PROFINET transmission | RT only | RT only |
| IRT support | No | No |
| Shared device | No | No |
| Required DP slaves on H side | 1 logical DP slave per Y-Link | 1 logical DP slave per Y-Link |
| Firmware required (H CPU) | V6.0 or higher | V6.0 or higher |
4. Solution Path B: S7-1500H Migration with S2 System Redundancy
For new projects or refreshes, the modern replacement for the S7-400H is the SIMATIC S7-1500H (e.g., CPU 1517H-3 PN, 6ES7 517-3HP00-0AB0). The S7-1500H supports PROFINET S2 system redundancy, which is the standardized mechanism for a PROFINET IO device to maintain two ARs to two redundant controllers and switch over automatically.
From the TIA Portal documentation on S2 system redundancy:
"An IO device with S2 system redundancy supports redundant ARs. In a redundant system, an IO device with S2 system redundancy has a redundant AR for each of the two controllers. The two ARs are mirrored, allowing failover without I/O loss."
The downstream interface module that supports S2 in the ET200 family is the IM 155-5 MF/HF (e.g., 6ES7 155-5MU00-0AB0 for ET 200MP, or the equivalent for ET 200SP / ET 200pro with HF firmware).
4.1 Migration comparison
| Aspect | S7-400H + Y-Link | S7-1500H + S2 redundancy |
|---|---|---|
| PROFINET I/O support | Indirect, via Y-Link RT only | Native, including IRT and shared device |
| Redundant AR | Not applicable (PROFIBUS DP-based) | Standardized S2 per PROFINET spec |
| Configuration tool | SIMATIC Manager / STEP 7 V5.5 | TIA Portal V17 or higher |
| Switchover time | ~100-300 ms (DP cycle dependent) | <100 ms typical |
| I/O data width | 244 B per Y-Link (bottleneck) | Full slot I/O per device |
| Spare parts availability | Phased out, limited | Active product |
The ET200pro Fail Safe Controller, when used with current IM 154-4 PN firmware (V7.0 or higher with the HF feature set), can be deployed under S7-1500H S2 control with PROFIisafe on the same AR. This is the recommended path for new safety-rated distributed I/O.
5. Connection Count and S7 Communication Constraints on the S7-400H
When designing the H-System it is critical to verify the connection budget of the selected CPU. The CPU 412-3H supports a maximum of 16 S7 connections. At least one is reserved for the programming device (PG) and one for the HMI/OP, leaving a tight margin once you add PN CPU partners, I-Device relationships, or S7 connections for cross-coupling.
| S7-400H CPU | Max. S7 connections | Max. S7 basic communication |
|---|---|---|
| CPU 412-3H (6ES7 412-3HJ14-0AB0) | 16 | 8 |
| CPU 414-4H (6ES7 414-4HM14-0AB0) | 32 | 16 |
| CPU 416-3H (6ES7 416-3HR05-0AB0) | 64 | 32 |
| CPU 417-4H (6ES7 417-4HR05-0AB0) | 64 | 32 |
6. SFC14 / SFC15 versus SFB14 / SFB15 in the H Context
Engineers often confuse the SFC and SFB families when they first work with S7-400H. The two pairs serve fundamentally different purposes.
| Block | Function | Use with |
|---|---|---|
| SFC 14 DPRD_DAT | Read consistent data from a standard DP slave or PN IO device | DP slaves / PROFINET I/O |
| SFC 15 DPWR_DAT | Write consistent data to a standard DP slave or PN IO device | DP slaves / PROFINET I/O |
| SFB 14 GET | Read data from a remote CPU via S7 communication | S7 connections (CPU-to-CPU) |
| SFB 15 PUT | Write data to a remote CPU via S7 communication | S7 connections (CPU-to-CPU) |
SFC14 and SFC15 are valid for the PROFIBUS DP side of the H system (including the Y-Link) but cannot be used to access another S7-CPU partner over S7 communication. For that you need SFB14 (GET) and SFB15 (PUT), and an S7 connection established in NetPro / HW Config.
7. Cycle Time and Update Time Considerations
The I/O update time on the H system depends on three factors that must be sized together:
- OB1 cycle time of each H CPU - set in HW Config under CPU properties → Cycle.
- PROFIBUS DP cycle - the time the DP master polls all configured slaves. For H, both CPUs run the DP cycle on their own segment, and the I/O image is then mirrored through the fiber-optic redundancy link.
- Redundancy link update time - the time it takes to copy the master process image to the reserve. With a sync module in fiber-optic mode, this is typically 1-3 ms per cycle, but the worst-case link-up time is bounded by the configured max. link-up time parameter.
When the Y-Link is in the path, add the PROFINET update time of the downstream ET200pro. With the default PROFINET update time of 1 ms (RT class 1), the Y-Link adds one RT cycle of latency. The S7-400H manual, Chapter 16 "S7-400 Cycle and Response Times", provides the response-time tables used for sizing; you must validate your worst-case with that data because the manual does not provide a closed-form formula for the H system with a Y-Link.
8. SCALANCE X414-3E Network Design for the H-System
The SCALANCE X414-3E (6GK5 414-3FC00-2AA2) is a PROFINET managed switch with three Gigabit combo ports and seven Fast Ethernet ports. It supports the redundancy protocols HRP (High-speed Redundancy Protocol, <300 ms) and MRP (Media Redundancy Protocol, <200 ms). When deployed as the PN segment carrying ET200pro and one or more Y-Links:
- Configure the SCALANCE in HRP manager mode and use a ring topology for the PN segment.
- For redundant Y-Links, give each Y-Link its own SCALANCE ring port pair to provide media diversity.
- Disable Spanning Tree on the PN segment when HRP/MRP is in use; the protocols are mutually exclusive.
- Keep the SCALANCE Extender (6GK5 495-8BA00-8AA2) for fiber uplinks in electrically noisy zones; it is media-transparent and does not participate in HRP.
9. Step-by-Step: Bringing Up the Y-Link Configuration
9.1 Prerequisites
- STEP 7 V5.5 SP4 or higher (HF1 for the Y-Link GSD)
- S7-400H CPU firmware V6.0 or higher
- Y-Link 6ES7 197-1LA12 with firmware V4.0 or higher
- ET200pro IM 154-4 PN firmware V6.0 or higher
- GSDML file for the ET200pro IM (GSDML-V*-Siemens-ET200pro-IM154-4PN-*.xml)
- SCALANCE X414-3E primary software (formerly "Web Based Management")
9.2 Procedure
- Build the S7-400H rack with two CPUs of matching order number and firmware. Install fiber-optic sync modules and connect them with a crossover fiber pair.
- Configure the redundancy in HW Config: insert CPU 1, mark it as redundant, and download the project to both CPUs.
- Insert the Y-Link in the rack view at PROFIBUS DP (1) on CPU 0 and PROFIBUS DP (1) on CPU 1 (the redundant PROFIBUS segments). Use the Y-Link GSD file (Siem80A0.gsd for 6ES7 197-1LA12).
- Configure the Y-Link as a PROFINET IO controller for the downstream ET200pro ring. In the Y-Link object properties, add the ET200pro IMs and assign PROFINET device names.
- Map the I/O: under the Y-Link, add the ET200pro slot-level modules (e.g., 6ES7 142-4BF00-0AA0 digital input module, 6ES7 142-4BF00-0AB0 digital output module). The I/O image is exposed to the H system as PROFIBUS I/O under the Y-Link DP slave.
- Set the DP cycle to 5 ms (typical) in HW Config on both DP segments. Verify with the response-time table in Chapter 16 of the S7-400H manual.
- Configure the SCALANCE as HRP manager, set ring ports, and assign IP addresses. Verify PN device names and IP addresses are consistent with HW Config.
- Download the project to both H CPUs and start them. The Y-Link will go online and report both PN and DP links up.
9.3 Verification
- Online → Accessible Nodes shows both H CPUs, both Y-Links, and all ET200pro IMs as reachable.
- Module Information on each ET200pro IM shows the AR is established and the I/O data is updating.
- Force a switchover by stopping CPU 0 (mode selector to STOP). The I/O must continue updating without a process fault, and CPU 1 must take over within the configured max. link-up time.
- Disconnect one PROFINET cable on the SCALANCE ring. HRP must converge in <300 ms and the I/O must continue updating.
- Disconnect one PROFIBUS DP cable between an H CPU and the Y-Link. The H system must continue to communicate through the other CPU and the Y-Link must continue to expose the I/O to the active CPU.
10. Troubleshooting Matrix
| Symptom | Likely cause | Corrective action |
|---|---|---|
| ET200pro IM reports "IO device not accessible" after project download | PROFINET device name mismatch | Use the Topology Editor in STEP 7 to assign the device name from the H project. Verify with online diagnostics. |
| Y-Link shows DP fault on H CPU 1 only | PROFIBUS address conflict on the redundant segment | Ensure the Y-Link has a unique PROFIBUS address on each segment, and that no other DP slave shares that address. |
| Switchover takes >500 ms | Max. link-up time too short for the configured I/O volume | Increase max. link-up time to 500 ms in HW Config → CPU properties → H Parameters. |
| ET200pro station drops out intermittently | PROFINET update time shorter than device refresh | Increase PN update time to 2 ms on the Y-Link, and verify SCALANCE port statistics for CRC errors. |
| SFC14 returns STATUS = 80A1 or similar DP error | SFC14 used on a non-DP slave partner (e.g., a PN CPU via S7 connection) | Replace with SFB14 (GET). Reserve SFC14/SFC15 for the Y-Link PROFIBUS side only. |
| Connection count exceeded on CPU 412-3H | More than 16 S7 connections configured | Move to CPU 414-4H (32 connections) or restructure with one PN CPU as a shared partner rather than multiple direct connections. |
| Halt of H-System on "redundancy loss" after Y-Link stop | Y-Link treated as a non-redundant slave | In HW Config, set the Y-Link operating mode to "DP master (redundant)" and verify the DP2/DP3 slots are populated on both CPUs. |
11. Frequently Asked Questions
Can ET200pro (IM 154-4 PN) be used directly on an S7-400H redundant CPU pair?
No. PROFINET IO is not released for S7-400H. The H firmware does not implement redundant PROFINET ARs. Use a Y-Link (6ES7 197-1LA12 or -1LA14) to convert PROFINET RT to PROFIBUS DP, or migrate to S7-1500H with S2 system redundancy and an IM 155-5 MF/HF device.
What is the maximum number of S7 connections on an S7-400H CPU 412-3H?
The CPU 412-3H (6ES7 412-3HJ14-0AB0) supports 16 S7 connections. At least one is reserved for the programming device and one for HMI, so the practical budget for PN CPU partners, I-Device links, and S7 cross-coupling is 14. Move to a CPU 414-4H or 417-4H if you exceed this.
Which Siemens I/O devices support S2 system redundancy on PROFINET?
The IM 155-5 MF/HF (6ES7 155-5MU00-0AB0 for ET 200MP) and the IM 154-4 PN with current HF firmware for ET200pro support S2. S2 is part of the PROFINET specification and is documented in the TIA Portal online help under "S2 system redundancy." Pair these with an S7-1500H controller.
Can I use SFC14 and SFC15 to read data from a remote S7 CPU partner of the H system?
No. SFC14 (DPRD_DAT) and SFC15 (DPWR_DAT) are for standard DP slaves and PROFINET IO devices only. For data exchange with a remote S7 CPU over an S7 connection, use SFB14 (GET) and SFB15 (PUT), as documented in the STEP 7 help for the S7-400H.
What is the failover time of the Y-Link path on S7-400H?
Switchover is dominated by the S7-400H max. link-up time (default 100 ms, typically raised to 300-500 ms for ET200pro volumes) and the PROFIBUS DP cycle (typically 5-10 ms). Realistic failover is 100-500 ms end-to-end. For sub-100 ms failover, migrate to S7-1500H with S2.