Fixing Siemens 1FK7042 SLS Trip: p9520-p9522 Safety Parameters

David Krause18 min read
Safety SystemsSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Description

A common commissioning defect on a Siemens SINAMICS S120 or SINAMICS S210 drive running Safety Integrated (SI) together with the Basic Positioner (EPOS) is that the Safely Limited Speed (SLS) function trips far above the configured limit. On a Simotics S-1FK7 servo motor (1FK7042-2AK71-1CH1, 6000 rpm rated) driving a rack-and-pinion axis through a planetary gearbox with ratio i = 7, the operator commands an axis velocity that EPOS correctly executes — the motor spins at the expected speed, the rack moves the right distance — yet the safety monitor raises an SLS-limit-exceeded alarm at a velocity well above the SLS setpoint.

Reference case from the field:

  • Motor: 1FK7042-2AK71-1CH1 (6000 rpm rated, absolute encoder, EPOS ready)
  • Gearbox: planetary, ratio i = 7 (motor : load)
  • Load: rack-and-pinion, 186 597 mm per load revolution (configured in p2506)
  • EPOS setpoint: 5000 mm/min via the HT8 hand-held terminal, safety door open
  • Observed motor speed (r0021): 187.5 rpm
  • EPOS active SLS limit: 2000 mm/min
  • Symptom: SLS-limit-exceeded alarm raised at 5000 mm/min, not at 2000 mm/min

The fault is reproducible and survives an OFF/ON of the drive. The motion path is correct, the encoder feedback is correct, and the EPOS scaling is correct. The fault is in the safety parameter set: the safety monitor is operating in a different mechanics scale than the standard motion controller.

Diagnostic signature. The SLS-limit-exceeded alarm trips at a velocity that is not the configured SLS limit. The r0021 motor speed display and the EPOS command path both confirm the actual axis speed matches the commanded speed. The discrepancy is between the standard motion path (r0021, r2521) and the safety motion path (r9714, r9708).

Affected Drives, Motors, and Firmware

The fault is not specific to a single firmware release. It appears on every SINAMICS drive that combines the Basic Positioner with Safety Integrated on a linear axis with a gearbox:

  • SINAMICS S120 on CU310-2, CU320-2, or CU320-2 PN, Safety Integrated firmware V4.4 onward (V4.x, V5.x, V6.x)
  • SINAMICS S210 with Safety Integrated (firmware V5.1 SP1 onward)
  • SIMOTION D4xx-2 / CX32-2 driving a SINAMICS S120 drive object with EPOS + SI
  • 1FK7 servo motors with absolute encoder (1FK7042, 1FK7060, 1FK7080 in any shaft / holding-brake variant)

The 1FK7042-2AK71-1CH1 motor used in the reference case is documented in the SIMOTICS S-1FK7 synchronous servo motors configuration manual. The Safety Integrated functions for SINAMICS S120 are described in the SINAMICS S120 Safety Integrated Function Manual. The parameter numbering referenced in this article corresponds to that manual. Cross-reference the active firmware List Manual in the same Siemens support portal for any change between V4.x, V5.x, and V6.x parameter ranges.

Mechanical and Kinematic Verification

Before any safety change, confirm the kinematics on the standard motion side. The relation between axis velocity, gearbox ratio, and motor speed is:

n_motor [rpm] = v_axis [mm/min] × i / LU_per_load

For the reference installation the parameters are:

Quantity Symbol Value
Load distance per load revolution LU_per_load 186 597 mm
Gearbox ratio (motor : load) i 7 : 1
Motor rated speed n_N 6000 rpm
EPOS LU per load revolution p2506 186 597
EPOS motor revolutions per load revolution p2504 7
EPOS load revolutions p2505 1
EPOS position reference p2502 1 (linear with gearbox)
Commanded axis velocity (test) v_axis 5000 mm/min
Observed motor speed r0021 187.5 rpm

The 187.5 rpm reading on the drive display matches the calculated value. The EPOS path executes 5000 mm/min correctly, and a tape measure on the rack confirms 5000 mm of travel over 60 s. The EPOS scaling is therefore correct, which isolates the fault to the safety parameter set.

Translated to the safety side, the SLS setpoint of 2000 mm/min should map to a motor speed limit of approximately 75 rpm at the safety monitor's input. With a properly configured safety mechanics, the safety monitor raises SLS-limit-exceeded the moment the actual axis speed exceeds 2000 mm/min — long before the operator reaches 5000 mm/min. The fact that the alarm fires at 5000 mm/min instead of 2000 mm/min is the diagnostic signature of the bug.

Reference 1FK7042 axis kinematics EPOS setpoint5000 mm/min Gearbox i = 7+ p2504, p2506 Motor 1FK7042187.5 rpm Rack-and-pinion5000 mm / 60 s p2504 = 7p2506 = 186 597 EPOS scalingCORRECT r0021 = 187.5display axis moves5000 mm in 60 s SI Motion path is INDEPENDENT — needs p9520/p9521/p9522 separately

Root Cause: Independent Safety Mechanics Parameters

SINAMICS Safety Integrated executes a parallel motion model inside the safety firmware. The safety model is isolated from the standard motion model and reads its own copy of the mechanics parameters. If the safety parameters are left at default, the safety monitor scales actual speed and the SLS limit using a default of 1 motor revolution = 1 LU with no gearbox compensation and a linear axis scaling of 1 LU = 1 mm.

With this default scaling the SLS limit set to 2000 mm/min in the operator panel is compared against an actual speed that the safety monitor measures against the wrong scale. The result is that the safety function trips at a velocity that is off by a factor that depends on the unconfigured gearbox and load-rotation scaling. In the reference case, the alarm fires at 5000 mm/min rather than 2000 mm/min, a ratio of 2.5×. The same configuration with the safety mechanics correctly filled in produces the intended 2000 mm/min trip threshold.

The SINAMICS S120 Safety Integrated Function Manual documents this requirement explicitly: the safety-relevant actual-value acquisition must be parameterized so that it matches the mechanical conditions of the axis, including the load-side gearbox and the load distance per load revolution. The standard EPOS commissioning screen does not feed the safety screen — the two parameter sets are independent by design.

Copying RAM to ROM, copying the safety parameter set, or activating a configuration does not auto-propagate the EPOS mechanics into the safety set. This is by design: the safety model must be commissioned independently, and it must be deliberately entered by the integrator as part of the safety acceptance procedure. The safety commissioning cannot rely on the standard motion commissioning.

Required Parameters: EPOS Mechanics vs SI Motion Mechanics

The mechanical system is configured in two parallel places. Both must be filled in. If the EPOS mechanics is correct but the SI Motion mechanics is left at default, SLS misbehaves as described above.

Function EPOS parameter SI Motion parameter Value for 1FK7042 reference
Axis type / mechanics selected p2502 (linear with gearbox) p9502 (linear axis) 1 / 1
Motor revolutions per load revolution p2504 p9522 7
Load revolutions p2505 p9521 1
Distance per load revolution [LU] p2506 p9520 186 597
SI Motion resolution (LU / motor rev) derived from encoder p9520 / p9522 26 656.7

Mapping rule (consistent with the SINAMICS S120 List Manual for firmware V5.x):

  • p9520 (SI Motion LU per load revolution) = p2506 (EPOS)
  • p9521 (SI Motion load revolutions) = p2505 (EPOS)
  • p9522 (SI Motion motor revolutions) = p2504 (EPOS)

The mapping for p9521 / p9522 has been revised between firmware V4.x and V5.x — the integer / floating-point representation of the gearbox ratio changed. Always re-read the parameter help text in the SINAMICS S120 List Manual that ships with the firmware actually loaded in the drive. Some firmware versions also expose an additional resolution parameter p9523 that is implicit in V5.x and explicit in V4.x.

The full parameter mapping to confirm in STARTER / Startdrive before saving:

p9501.0 = 1                  (SLS enabled)
p9502   = 1                  (linear axis)
p9520   = p2506 = 186 597    (LU per load revolution)
p9521   = p2505 = 1          (load revolutions)
p9522   = p2504 = 7          (motor revolutions)
p9531[0] = 2000              (SLS level 1, mm/min)
p9531[1] = 1000              (SLS level 2, mm/min)
p9531[2] = 500               (SLS level 3, mm/min)
p9531[3] = 0                 (SLS level 4, unused)
p9551   = 100                (SLS filter, ms)
p9547   = 0                  (SS1 as stop reaction)

Step-by-Step Configuration in STARTER / Startdrive

  1. Open the project in STARTER (classic) or Startdrive (TIA Portal) and go online to the SINAMICS drive object.
  2. Open Configuration → Mechanics under the EPOS function block. Confirm p2502 = 1 (linear with gearbox), p2504 = 7, p2505 = 1, p2506 = 186 597. Save and download to the drive.
  3. Open the Safety Integrated → Configuration tree. In STARTER this is under the safety function folder; in Startdrive it is in the Safety configuration screen. Locate the Mechanics dialog that exposes p9520, p9521, p9522.
  4. Enter p9520 = 186 597, p9521 = 1, p9522 = 7. Save.
  5. Open Safety Integrated → Functions → SLS. Confirm the SLS limits in p9531[0..3] are in the same LU as the EPOS axis — for a linear axis that is mm/min. The values 2000 / 1000 / 500 / 0 are typical for a four-level SLS configuration.
  6. Execute Copy RAM to ROM on the safety parameter set.
  7. STARTER / Startdrive will request a safety restart. Perform a safety POWER ON (or a power cycle) to activate the new mechanics parameters. The standard application restart is not sufficient — only a safety POWER ON activates the new SI Motion parameters.
  8. Verify the safety checksum in p9798 (control unit) and p9898 (motor module) has updated. Verify r9720[0] shows the active SLS level and r9714[0] shows the safety-monitored actual velocity in the correct units (mm/min).
Safety POWER ON required. Safety parameters do not become effective with a normal download or a warm restart of the standard application. The drive must be power-cycled, or commanded to perform a safety restart (p7826 = 1, then power cycle). If the drive is not power-cycled, the old safety mechanics remain active and the SLS trip is not resolved.

Verification Procedure

  1. Jog the axis at 1000 mm/min with the safety door open and SLS active at 2000 mm/min. The drive must accept the speed and the safety diagnostics must show SLS active.
  2. Jog at 5000 mm/min. The drive must raise F01714 (SI Motion: SLS limit exceeded) or trigger the configured stop reaction (SS1 / STOP A, STOP C, etc.) the moment the actual speed exceeds 2000 mm/min, not at 5000 mm/min.
  3. Read r0021 (motor speed smoothed, standard) and r9714[0] (SI Motion actual velocity diagnostics). The two values must agree in their ratio via the safety mechanics. In the reference case r9714[0] should read approximately 5000 mm/min when r0021 reads 187.5 rpm, and 2000 mm/min when r0021 reads 75 rpm.
  4. Compare r9708[0] (SI Motion actual position, in LU) with r2521[0] (EPOS actual position, in LU). They must match LU by LU. A mismatch indicates that one of the safety mechanics parameters is still wrong.
  5. Run the SLS accept test documented in chapter 6.4 of the SINAMICS S120 Safety Integrated Function Manual and archive the report as part of the machine dossier.
  6. Cross-check the PROFIsafe status word S_ZSW1 bits 0–3 to confirm the safety PLC sees the active SLS level correctly.

SLS Function Reference

Safely Limited Speed (SLS) is a Type 3 safety function per EN ISO 13849-1 and a SIL 2 / PL d function per IEC 61508 / EN 62061. The function monitors the actual velocity of the axis and triggers a configurable stop reaction when the actual speed exceeds the active SLS limit. The general definition of SLS in a machine-safety context is given on the Pilz technical reference page for SLS; the Siemens-specific implementation is in the SINAMICS S120 Safety Integrated Function Manual.

Relevant SLS parameters on SINAMICS S120:

Parameter Description Typical value (1FK7042 reference)
p9501.0 Enable SLS in SI Motion 1 (enabled)
p9502 SI Motion axis type (1 = linear) 1
p9531[0] SLS level 1 limit value [LU/min] 2000 (mm/min)
p9531[1] SLS level 2 limit value 1000
p9531[2] SLS level 3 limit value 500
p9531[3] SLS level 4 limit value 0 (unused)
p9551 SLS switching time / filter typical 100 ms
p9547 SLS stop reaction 0 = SS1, 1 = STOP C, 2 = STOP D, 3 = STOP E
p9561 SLS tolerance (overshoot window) default
p9533 SLS setpoint limit (ramp) 0 = no ramp, 1 = ramp active
p9566 SLS stop ramp (when p9533 = 1) depends on axis dynamics
p9503 SI Motion PROFIsafe assignment slot / subslot of safety PLC

The SLS level is selected via the PROFIsafe control word S_STW1, bits 0–3. The actual level is reported back in S_ZSW1. For a 1FK7042 application with a single SLS setpoint, the typical PROFIsafe telegram is 30 (SLS) or 31 (SLS + SDI). The standard telegram 701 / 702 (S120 safety slot) is also valid.

The standard stop reactions for SLS, per the Safety Integrated Function Manual, are:

  • SS1 (STOP A): ramp down the speed with the OFF3 ramp (p1135), trigger STO at end of ramp or on timeout
  • STOP C: ramp down with the OFF3 ramp, transition to STOP B, then STO
  • STOP D: ramp down with the OFF1 ramp, transition to STOP B, then STO
  • STOP E: ramp down with the path ramp, transition to SOS monitoring, then STO

For a vertical axis with gravity load, SS1 or STOP C is mandatory. STOP D and STOP E are reserved for horizontal axes where the load is not affected by gravity. The stop reaction is a safety function and must be configured by the safety engineer, not the standard motion engineer.

Safety Encoder Configuration (1FK7042-specific)

The 1FK7042-2AK71-1CH1 is delivered with an absolute encoder (typically AM22DQC, 22-bit singleturn, or AS20DQC, 20-bit singleturn + 12-bit multiturn). For Safety Integrated the encoder is configured in:

Parameter Description Typical value
p9506 SI Motion encoder configuration (1 = motor encoder, 2 = second encoder) 1 (motor encoder)
p9507 SI Motion function specification (sub-function set) per drive family
p9311 SI Motion actual value configuration per encoder type
p9312 SI Motion linear encoder increments (only for linear encoders) N/A for motor encoder
p9313 SI Motion rotary encoder increments per encoder resolution
r0470 Active encoder identification diagnostic
p0410 Encoder type (standard) must match SI encoder

For 1FK7 motors with built-in absolute encoders the SI encoder must be set to motor encoder (p9506 = 1). If the drive is configured to use an external second encoder for safety, p9506 = 2 and the second encoder must be installed and wired to the SINAMICS SMC30 sensor module. Mismatched SI encoder configuration produces F01670 / F01671 and a STOP F, which can mask the SLS issue and lead to confusing diagnostics.

The encoder resolution enters the safety kinematics as the limit of the LU / motor revolution. For 1FK7042 with a 20-bit singleturn encoder the limit is 1 048 576 increments per motor revolution. The safety LU / motor revolution parameter p9520 / p9522 must be a whole-number multiple of the encoder resolution, or the safety monitor will round and produce sub-LU jitter on the position readout.

PROFIsafe Telegram and SIMOTION Integration

For a SINAMICS S120 controlled from a SIMOTION D4xx-2 or an F-CPU via PROFIsafe, the safety function selection is encoded in the S_STW1 control word of the PROFIsafe telegram. The standard safety telegrams are:

Telegram Content Use case
30 S_STW1 / S_ZSW1, 1 SLS level Single SLS, no SDI
31 S_STW2 / S_ZSW2, SLS + SDI SLS + Safe Direction
701 / 702 S120 safety slot variants Compact F-CPU integration
900 / 901 Vendor-specific Custom safety logic

The SLS level is selected by writing the binary value 0..3 to bits 0..1 of S_STW1. Bit 4 of S_STW1 enables SDI in telegram 31. The safety monitor responds in S_ZSW1 with the active level and the SLS status (bit 6 = SLS active, bit 7 = SLS limit exceeded). When the safety PLC sees bit 7 set, it must initiate the configured stop reaction on the standard motion path.

For a SIMOTION configuration with NC axes, the NC may carry its own mechanics that overwrites the safety mechanics on startup. Always commission the SIMOTION axis first (with p2502, p2504, p2505, p2506) and then the drive's safety mechanics (p9520, p9521, p9522). After any change to the SIMOTION axis scaling, re-download the safety parameters and perform a safety POWER ON. The NC and the safety firmware do not auto-synchronise.

Safety Configuration Best Practices

  • Treat the SI Motion mechanics screen as a mandatory commissioning step. It is not an optional add-on. Every linear axis with a gearbox running SLS needs p9520, p9521, p9522 configured.
  • After changing p9520, p9521, or p9522, perform a full safety POWER ON and run the SINAMICS safety accept test (mandatory per EN ISO 13849-1 PL d and above).
  • Document the safety parameter set in the safety acceptance report and the machine dossier. The values must be reproducible from the archived project.
  • Cross-check the SLS limit in p9531 against the safety-monitored actual velocity r9714[0]. The two must scale together with the mechanics parameters.
  • Do not copy parameter sets across firmware versions without re-reading the parameter help. The semantics of p9521 and p9522 changed between V4.x and V5.x of SINAMICS S120.
  • If the drive is part of a SIMOTION configuration, propagate the mechanics into the SIMOTION axis first and then into the drive. The NC may carry its own mechanics that overwrites the safety mechanics on startup.
  • Use r9700, r9701, r9708, r9714, r9720 to read back the active safety state during commissioning. Do not rely on r0021 alone — that is the standard motion value, not the safety-monitored value.
  • For 1FK7 motors with absolute singleturn or multiturn encoders, configure p9506, p9507, p9311, p9312, and p9313 to match the encoder type. Mismatched SI encoder configuration produces F01670 / F01671 and a STOP F.
  • Keep the SLS tolerance (p9561) wider than the maximum dynamic overshoot of the axis. Too tight a tolerance creates nuisance trips during acceleration. For a 1FK7042 with a 6000 rpm motor and a 100 mm/s² acceleration ramp, a 100–200 ms filter (p9551) is a reasonable starting point.
  • Configure the SLS stop reaction (p9547) according to the axis type: SS1 / STOP C for vertical axes, STOP D / STOP E allowed for horizontal axes. The stop reaction is a safety function and must be configured by the safety engineer, not the standard motion engineer.
  • Use the safety acceptance test procedure from chapter 6.4 of the SINAMICS S120 Safety Integrated Function Manual as a checklist. Archive the report.
  • Do not reuse the EPOS encoder configuration parameters (p0400, p0420, p0430) for the safety encoder. The safety encoder configuration is independent and lives in the p93xx parameter range.

Troubleshooting Matrix

Symptom Probable cause Check Fix
SLS trips at a multiple of the configured limit (e.g. 2.5×) Safety mechanics wrong (this case) p9520, p9521, p9522 vs p2504, p2505, p2506 Set safety mechanics, safety POWER ON
SLS trips immediately at any motion Axis type mismatch (p9502 = 0 rotary on a linear axis) p9502 vs mechanical design Set p9502 = 1 (linear), restart safety
SLS never trips, even at high speed Encoder not configured for SI (p9506, p9507, p9311) SI encoder configuration Configure SI encoder, safety POWER ON
SLS trips during acceleration but not at constant speed SLS filter time p9551 too short p9551 value vs axis acceleration Increase p9551 to 100–500 ms
SLS trips at correct speed but fault is F01711, not F01714 Wrong fault class assignment p9580, p9501 Confirm p9501.0 = 1, check stop reaction in p9547
EPOS shows correct speed, safety shows wrong speed Safety encoder is a second encoder not geared to the load p9520, p9521, p9522 Match safety mechanics, safety POWER ON
SLS trips correctly but axis coasts to stop instead of SS1 Stop reaction in p9547 = STOP D/E instead of SS1 p9547 value Set p9547 = 0 (SS1) for safe stop
SLS parameter changes do not take effect after download Safety POWER ON not performed p7826 / p9762 Command safety restart and power cycle
SLS trip has wrong polarity (limiting below setpoint) SLS setpoint is positive but axis is moving negative r9714[0] sign vs p9531[0] sign Match sign, check p9502
SLS trips with no PROFIsafe telegram PROFIsafe not configured (p9503, p9610) PROFIsafe slot Configure PROFIsafe telegram 30 / 31
SLS trips on a SIMOTION NC axis regardless of speed NC axis mechanics overriding safety mechanics SIMOTION axis scaling vs SINAMICS SI Re-commission safety after SIMOTION download

FAQ

Why does SLS trip at a higher speed than the SLS limit I configured?

The safety monitor scales actual speed and the SLS limit through its own mechanics parameters p9520, p9521, p9522. If those parameters are at default (1 motor revolution = 1 LU, no gearbox compensation), the safety monitor compares the configured SLS limit in mm/min against an actual speed measured in a different scale. Set p9520, p9521, and p9522 to match the EPOS parameters p2504, p2505, and p2506, then perform a safety POWER ON.

Are p2504 and p9520 the same parameter?

No. p2504 is the EPOS motor revolutions per load revolution. p9520 is the SI Motion LU per load revolution. They describe the same physical system but live in two independent parameter sets. Both must be configured for any linear axis with a gearbox running SLS.

Do I need a safety POWER ON after changing p9520?

Yes. Safety Integrated does not activate new mechanics parameters with a normal parameter download. The drive must be power-cycled, or commanded to perform a safety restart (set p7826 = 1, then power cycle). The standard application restart is not sufficient.

Which Siemens manual documents p9520, p9521, and p9522?

The SINAMICS S120 Safety Integrated Function Manual describes p9520, p9521, p9522 and the SLS function group. The List Manual in the same Siemens support portal gives the parameter help text for the firmware version loaded in the drive.

Can EPOS parameters be copied into the safety set automatically?

No. SINAMICS does not auto-propagate EPOS mechanics into the safety set. In a SIMOTION NC configuration, the NC has its own axes and the integrator must enter the mechanics in each subsystem explicitly. Treat p9520, p9521, p9522 as a separate mandatory commissioning step.

What fault number does SLS raise when the limit is exceeded?

SLS-limit-exceeded on SINAMICS S120 raises F01714 with the appropriate reaction (alarm / stop). The associated PROFIsafe status word S_ZSW1 reports the active SLS level. Cross-reference the fault with r9714[0] (SI Motion actual velocity diagnostics) to confirm the safety monitor saw the overshoot.

Back to blog