1. Overview: S7-400H Redundant CPU Upgrades
The SIMATIC S7-400H is Siemens' high-availability, fault-tolerant PLC platform. The "H" suffix denotes redundant operation: two identical CPUs run synchronously, exchange process state through fiber-optic sync modules, and take over each other's load if a fault is detected. The platform supports online repair and component replacement without stopping the process, but only when the change rules in the S7-400H Fault-Tolerant Systems manual are followed.
This reference addresses two upgrade paths commonly raised by integrators and plant engineers:
- Path A — 6ES7 417-4HL00-0AB0 or 6ES7 417-4HL01-0AB0 → 6ES7 417-4HL04-0AB0 (in-frame, re-using the existing backplane and I/O).
- Path B — 6ES7 417-4HL04-0AB0 → 6ES7 417-5HT06-0AB0 (CPU 417-4H generation 4 → CPU 417-5H generation 5, V6.x firmware).
Both paths keep the user program in STEP 7, but Path B crosses a major firmware generation boundary (V4.x → V6.x). That boundary introduces behavior changes that must be reviewed against the running program before the new CPU is inserted.
2. Order Number Decoding and CPU Identification
Siemens encodes the CPU family, generation, firmware version, and hardware revision in the MLFB (order number). Decoding the strings in the source:
| Order Number | Family | CPU | Generation | Firmware | Notes |
|---|---|---|---|---|---|
| 6ES7 417-4HL00-0AB0 | S7-400H | CPU 417-4H | 1 | V1.x | Discontinued; original release |
| 6ES7 417-4HL01-0AB0 | S7-400H | CPU 417-4H | 2 | V2.x | Discontinued; functional successor to HL00 |
| 6ES7 417-4HL04-0AB0 | S7-400H | CPU 417-4H | 3 | V4.x | Last 417-4H variant; the V4.5 firmware is the reference target for Path A |
| 6ES7 417-5HT06-0AB0 | S7-400H | CPU 417-5H | 5 | V6.x | Newer CPU 417-5H; "5HT06" indicates generation 5, H-class, V6 firmware |
3. Hardware Comparison: 417-4H vs 417-5H
| Parameter | 417-4H (4HL04) | 417-5H (5HT06) |
|---|---|---|
| Form factor | S7-400H slot module, 2-slot width | S7-400H slot module, 2-slot width |
| Work memory (code) | 4 MB | 16 MB |
| Work memory (data) | 4 MB | 16 MB |
| Load memory (RAM/Flash) | ~ 8 MB / 64 MB | ~ 32 MB / 256 MB |
| Bit instruction execution | ~ 0.1 µs | ~ 0.03 µs |
| Floating-point | ~ 0.1 µs | ~ 0.04 µs |
| OB1 cycle (typical) | approx. 6 ms at 1k statements | approx. 2 ms at 1k statements |
| PROFIBUS DP interfaces | 2 (master/slave switchable) | 2 (master/slave switchable) |
| MPI/PROFIBUS combined | 1 (configurable as MPI or DP) | 1 (configurable as MPI or DP) |
| Sync module interface | 2 (for fiber-optic pair) | 2 (for fiber-optic pair) |
| Redundancy mode | Hot-standby / Synchronous | Hot-standby / Synchronous |
| Power supply requirement | PS 405 / PS 407, 10 W typical | PS 405 / PS 407, ~ 12 W typical |
| Supported STEP 7 | STEP 7 V5.4 SPx; partial V5.5 | STEP 7 V5.5 SPx and TIA Portal (with HSP) |
4. Firmware Generation Differences (V4.x → V6.x)
Path B is a firmware-generation upgrade, not just a memory upgrade. The 5HT06 runs V6.x firmware, and the running user program must be reviewed for behavior deltas. Categories of change typically encountered between V4.5 and V6.x:
- System data blocks (SDB): generated differently. Recompiling the HW Config from STEP 7 V5.5 SPx (or TIA with the matching HSP) produces the new SDB set. Old SDBs are not portable.
- OB reaction to faults: OB 80, OB 82, OB 83, OB 85, OB 86, OB 87, OB 121, OB 122 priorities and start information were adjusted. Any user code in these OBs must be re-validated.
- Self-test diagnostics: extended self-test runs; some previously logged diagnostic events are now classified differently. Diagnostic buffer (OB 100, SZL lists) layout changed.
- Communication: the S7 communication resource table, connection count limits, and ISO-on-TCP keep-alive behavior changed in V6. Programs that rely on exact timing of PUT/GET/BSEND may need timing adjustments.
- Time synchronization: handling of SIMATIC Time, NTP, and PROFIBUS time master has been unified. Any time-of-day conversion blocks should be re-tested.
5. Path A: 4HL00 / 4HL01 → 4HL04
This is a same-family, same-form-factor replacement. The 4HL04 is mechanically and electrically compatible with the 4HL00 / 4HL01 slots. The backplane, sync modules, sync cables, and power supply are reused.
5.1 Hardware impact
- Mechanical: none. The 4HL04 occupies the same 2-slot width as the 4HL00/4HL01.
- Electrical: none. Insertion into a UR2/UR2-H or CR3-H rack is identical.
- Sync modules: reuse the existing 6ES7 960-1AA04-0XA0 (or 6ES7 960-1AB04-0XA0) modules. The fiber-optic cables do not need replacement.
- Battery / MMC: the 4HL04 supports the SIMATIC Memory Card. The Flash card from the older CPU can be re-used if the firmware on the card matches the destination; otherwise, a fresh card is required.
5.2 Software impact
- The user program is re-compiled against the V4.5 firmware target. STEP 7 V5.4 SP5 or higher is recommended.
- Hardware Config is re-loaded; the SDBs are regenerated.
- Symbol table, comments, and source structure are preserved.
- Existing PCS 7 libraries and CFC/SFC charts can normally be loaded unchanged if the PCS 7 version is the same or newer.
5.3 Procedure (Path A, in H redundancy)
- Document the current diagnostic buffer of both CPUs (online → CPU → Diagnostic buffer).
- Download a backup of the project from the running H station.
- Switch the master CPU to STOP-RUN with the standby CPU in RUN (H system tolerates single-CPU redundancy briefly). Confirm the standby is in RUN and synchronized.
- Pull the master CPU (4HL00 or 4HL01). H system continues in single-CPU mode.
- Insert the 4HL04 in the same slot. Wire the sync cable into the new sync modules if pre-wired; otherwise reuse existing modules.
- Insert the Flash card. Power up the new CPU.
- Download the project to the new CPU. The CPU performs link-up and establishes redundancy.
- Verify H status:
LED RACK 0andIFMon the sync modules; both CPUs reachRUN-H. - Repeat steps 3–8 for the second CPU once the system has stabilized for the documented dwell time (typically 10–15 minutes of clean redundancy).
6. Path B: 4HL04 → 5HT06
This is a CPU-generation upgrade. Although the 417-5H is mechanically compatible with the 417-4H slot footprint, the V6.x firmware and the new system data set require careful preparation. The single biggest risk is bringing a 5HT06 into a redundancy pair that still contains a 4HL04: an H pair with mixed generations does not enter RUN-H. The mixed pair must be operated in single-CPU mode until both CPUs have been replaced.
6.1 Hardware impact
- Mechanical: identical form factor; no rack or wiring changes.
- Power consumption: marginally higher. If the existing PS 405/PS 407 is loaded above 70% of its rated current, recalculate with the new figure. The 5HT06 is in the same bracket as the 4HL04, so a well-sized supply typically does not need replacement.
- Sync modules and cables: reuse existing 6ES7 960-1Ax04-0XA0 modules. The 5HT06 supports the same fiber-optic sync interface.
- Memory cards: the 5HT06 requires a Flash card with the matching V6.x firmware image. The card from a 4HL04 cannot be read by the 5HT06 because of the firmware change. Order the Flash card pre-imaged or use a separate programming device to load the firmware image before insertion.
6.2 Software impact
- Project must be migrated to STEP 7 V5.5 SPx (or to TIA Portal with the appropriate H-System Package). V5.4 cannot generate SDBs for the 5HT06.
- HW Config must be re-built with the 417-5H as the target. Slot numbering, module selection, and PROFIBUS addresses are preserved.
- All blocks must be re-compiled; the compilation flags for V6 are different.
- All OB fault-handling code must be re-validated against the V6 startup information.
- CFC/SFC charts from PCS 7 V7.1 SPx or higher can normally be carried over if the underlying CPU target is updated. Older PCS 7 charts must be migrated to the matching PCS 7 release before download.
6.3 Mixed-pair behavior
| CPU 0 | CPU 1 | Result |
|---|---|---|
| 4HL04 (V4.5) | 4HL04 (V4.5) | RUN-H, full redundancy (baseline) |
| 4HL04 (V4.5) | 5HT06 (V6.x) | No link-up. System stays in single-CPU mode on the surviving CPU. Process continues, but no redundant takeover possible. |
| 5HT06 (V6.x) | 5HT06 (V6.x) | RUN-H after link-up completes |
Because of this restriction, the second CPU must be replaced in a planned outage window or during a temporary period of single-CPU operation.
7. Programming / Software Migration Procedure (Path B)
- Open the project in STEP 7 V5.5 SPx (or later). Do not open the same project in two different STEP 7 versions.
- In HW Config, replace the CPU 417-4H order number with the 417-5H (6ES7 417-5HT06-0AB0). Keep slot, sub-module, and addressing unchanged.
- Compile and save HW Config. The compiler regenerates the system data blocks (SDBs).
- Re-compile the entire user program: Program blocks → right-click → Compile All. Resolve any redefinition warnings that appear.
- Re-compile CFC/SFC charts if PCS 7 is in use: Chart → Compile → Chart → Save As.
- Run a consistency check:
Options → Check Block ConsistencyandOptions → Cross Referencesto flag any unresolved symbols. - Perform a program download dry run on the engineering station to confirm the block sizes fit in the new work memory limits.
- Save the project under a new name (e.g.,
plant_xy_417-5H_V6.mcp) and archive the previous project.
8. Hot-Swap Procedure for Both CPUs in Path B
-
Preconditions:
- Both CPUs (4HL04) are in RUN-H and synchronized.
- Two replacement 5HT06 CPUs are on site, each with a Flash card loaded with the target firmware.
- Engineering station has the migrated project loaded and compiled.
- Plant operator and maintenance are informed; critical interlocks are monitored.
-
Replace CPU 0:
- CPU 0 is the master (or one of the master pair, depending on assignment). The other CPU takes over automatically when CPU 0 is pulled.
- Remove CPU 0.
- Insert the new 5HT06 into slot 0. Insert the pre-loaded Flash card.
- The new CPU powers up in STOP. Download the migrated project.
- Switch the new CPU 0 to RUN. The system runs in mixed pair / single-CPU mode: the new 5HT06 is the master, the old 4HL04 is in standby but cannot link up. Process continues on the 5HT06 alone.
-
Replace CPU 1:
- Plan this step during a maintenance window, or accept a short single-CPU interval.
- Stop the existing CPU 1 (the 4HL04). The 5HT06 continues as sole master.
- Pull the 4HL04, insert the second 5HT06 with its Flash card.
- Download the project to the new CPU 1 and switch it to RUN.
- The system performs link-up. After the configured redundancy dwell time (default 10 s; check LINK_UP_DELAY parameter in HW Config) both CPUs reach RUN-H.
-
Post-replacement checks:
- Diagnostic buffer of both CPUs: no new error events.
- Sync module LEDs:
LINK-UPgreen on both modules of both CPUs. - Operator view: H status indicator is green on both racks.
- Forced test of takeover: on an out-of-service actuator, pull the master CPU and confirm the standby takes over within the configured max-tolerated takeover time (default 100 ms; check
MONITOR_TIMEin the H parameters).
9. Verification and Commissioning Checklist
| Check | Method | Pass criterion |
|---|---|---|
| CPU in RUN-H | Mode selector LED on both CPUs | Green RUN + green RACK 0 |
| Sync link active | Sync module LEDs (LINK-UP) | All four LINK-UP indicators green |
| Redundant event log | Diagnostic buffer on both CPUs | No OB 70 / OB 72 redundancy loss after migration |
| User program | Monitor blocks online | Outputs respond identically to inputs in both CPUs |
| Process image | Force / monitor a known tag | Updates within 1 OB 1 cycle |
| Forced failover | Pull master during test window | Standby takes over within MONITOR_TIME |
| Firmware versions | Online → Module Information → Firmware | Both CPUs report identical V6.x |
| SDB consistency | HW Config → Save/Compile | No warnings |
10. Risk Matrix and Mitigations
| Risk | Severity | Mitigation |
|---|---|---|
| Mixed-pair non-link-up | High | Plan CPU 1 swap as separate window; do not assume live link-up is possible |
| OB behavior change | Medium | Re-validate every OB 80-87, 121, 122 before download |
| Old Flash card inserted | Medium | Label new cards clearly; keep old cards out of the cabinet |
| SDB mismatch after recompile | Medium | Always recompile HW Config; never carry SDBs from the old project |
| Power supply overload | Low | Recalculate the 5HT06 contribution against the existing PS 405/PS 407 budget |
| Operator not informed | High | Issue maintenance permit and H-status change notice before any action |
11. Engineering Reference Links
- S7-400H Fault-Tolerant Systems, System Manual (entry point)
- SIMATIC S7-400H CPU 417-5H (6ES7 417-5HT06-0AB0) data sheet
- S7-400H module replacement during operation (section 17.2 reference)
- PCS 7 / S7-400H compatibility list
- STEP 7 V5.5 SPx — Hardware Configuration for S7-400H
Can a 417-4H (4HL04) and a 417-5H (5HT06) form a working redundant H pair?
No. A mixed pair will not link up. The system operates in single-CPU mode on the surviving CPU until both units are replaced with the same generation and firmware version.
Do I need a new backplane when upgrading to the 5HT06?
No. The 417-5H has the same form factor and slot footprint as the 417-4H. The existing UR2-H, CR3-H, or UR2 rack, power supply, and I/O modules are reused.
Which STEP 7 version is required to program the 6ES7 417-5HT06-0AB0?
STEP 7 V5.5 SPx with the matching Hardware Support Package, or TIA Portal with the corresponding S7-400H HSP. STEP 7 V5.4 cannot generate SDBs for the 417-5H.
Is the Flash card from the 4HL04 reusable in the 5HT06?
No. The 5HT06 needs a Flash card loaded with the V6.x firmware image. The card from a 4HL04 contains V4.x firmware and is not accepted by the 417-5H.
Can both CPUs be replaced while the process stays in RUN?
Path A (4HL00/4HL01 → 4HL04) supports full online replacement in both slots with redundant takeover. Path B (4HL04 → 5HT06) keeps the process running, but the system runs in single-CPU mode between the two replacements, so a brief redundant takeover is not possible during the swap window.
What is the controlling Siemens document for replacing an H-CPU during operation?
The S7-400H Fault-Tolerant Systems manual, section 17.2 ("Component changes during operation"). It contains the exact sequence, the requirements on the standby CPU, and the verification steps for online replacement.