Reading ET200SP HA Channel & Module Diagnostics in PCS 7 V9.0 SP2
Channel-level and module-level diagnostics for SIMATIC ET 200SP HA remote I/O stations on a redundant CPU 410-5H automation system are generated automatically by the PCS 7 V9.0 SP2 Advanced Process Library (APL). The default @charts of every process tag already contain the channel driver instance, the alarm logic, and the operator messages required by Planning the configuration of an ET 200SP HA distributed I/O - no custom diagnostic block programming is required for the standard process alarms such as wire break, short circuit, underrange, and overrange.
This tutorial consolidates the PCS 7 APL mechanism, the underlying PROFINET IO diagnostic data records defined for the SIMATIC ET 200SP HA Technology Modules manual, and the asset-management view provided by the Maintenance Station option. The goal is to make module and channel diagnostics visible both in the WinCC operator station and on the diagnostic screens produced by the Maintenance Station, on a CPU 410-5H redundant AS running PCS 7 V9.0 SP2.
1. System Prerequisites and Licensing
Before you plan diagnostics, the engineering station, the AS 410H pair, and the operator station must satisfy the following minimum configuration.
| Component | Required item | Notes |
|---|---|---|
| Engineering Station (ES) | SIMATIC PCS 7 V9.0 SP2, APL V9.0 SP2 | Includes CFC, SFC, SCL compilers and the APL master data library |
| Automation System (AS) | CPU 410-5H (6ES7410-5HX08-0AB0) firmware V8.2 or later | Redundant pair with sync module V4.0+, fiber-optic sync cables |
| Head-end station | IM 155-6 PN HA (6DL1155-2AU00-0PM0) firmware V6.0 or later | One per ET 200SP HA rack, two for redundancy |
| I/O modules | ET 200SP HA digital / analog / technology modules with channel diagnostics | Check module faceplate: "D" in the article number indicates channel diagnostics |
| Operator Station (OS) | WinCC Runtime V9.0 SP2, Maintenance Station Basic (no licence) or Standard (licence) | Basic is included with the OS server licence |
2. Automatic Diagnostics via APL Channel Drivers
When you compile the CFC chart of a process tag (e.g. Pcs7AnIn, Pcs7DiIn, Pcs7AnOu, Pcs7DiOu, Pcs7Mot, Pcs7Valve), PCS 7 does the following automatically:
- Generates the driver instance in the unit-level
@chart(for exampleUnit1/AI_101→ instance DBDB1001). - Generates the alarm and message logic including the standard process alarms "Failure", "Upper limit violated", "Lower limit violated", "Bad quality", and the channel-diagnostic alarms "Wire break", "Short circuit", "Underflow", "Overflow".
- Wires the channel-diagnostic input of the driver to the value status (QUALITY_BAD, bit 0x40 "Channel diagnostic available") of the input/output address from the PROFINET IO frame.
- Creates the corresponding WinCC message in the OS project, with the message class, priority, and the operator text configured in the APL block icon properties.
Therefore no additional program code is required in the @chart to obtain wire break, short circuit, and overflow alarms for a standard channel. The diagnostics are read by the PROFINET IO stack of the CPU 410-5H from the channel-specific diagnostic data records (DS 100) of the ET 200SP HA module and are forwarded to the OS as channel diagnostic alarms.
3. APL Channel Driver Block Reference
The following APL blocks implement the standard channel driver with full diagnostic evaluation. Use the version that ships with the APL V9.0 SP2 master data library.
| Block | Function | Typical use on ET 200SP HA | Diagnostic alarms emitted |
|---|---|---|---|
Pcs7AnIn (FB 1869) |
Analog input 0/4-20 mA, RTD, TC | AI 8xI 2/4-wire HA, AI 8xTC/RTD HA, AI 16xI 2-wire HA | Wire break, Underflow, Overflow, High/Low limit, Bad quality |
Pcs7DiIn (FB 1861) |
Digital input 24 V DC, NAMUR | DI 16x24VDC HA, DI 16xNAMUR HA | Wire break, Short circuit, Failure, Bad quality |
Pcs7AnOu (FB 1870) |
Analog output 0/4-20 mA | AO 4xI/P HA, AO 8xI HA | Wire break, Short circuit, Bad quality |
Pcs7DiOu (FB 1862) |
Digital output 24 V DC, relay | DO 4x24VDC/2A HA, DO 8x24VDC/0.5A HA | Wire break, Short circuit, Failure, Bad quality |
Pcs7Mot (FB 1874) |
Reversing motor (forward / reverse / off) | DO 4x24VDC HA + DI 16x24VDC HA feedback | Contactor feedback failure, Thermal overload, Bad quality |
Pcs7Valve (FB 1875) |
On/off valve with end-position feedback | DO 4x24VDC HA + DI 16x24VDC HA feedback | End-position deviation, Bad quality |
For the full list of block numbers, signal pin names, and the runtime licence per channel driver see the PCS 7 V9.0 SP2 APL Function Manual shipped on the PCS 7 installation media (entry ID 109811210 in the Siemens Industry Online Support).
4. @Charts Architecture and Driver Instances
Every PCS 7 plant unit contains an automatically generated @chart (driver chart). The chart holds one instance of the channel driver per process tag of the unit and a single instance of MOD_PREP plus the S7 standard blocks OB_BEGIN, OB_END, and (if redundancy is enabled) RED_AGO / RED_ANA. A simplified view of a single unit is shown below.
To make the channel diagnostics visible in the OS, set the following attributes in the block icon properties of the channel driver:
- Message class: Process - Failure or Process - Warning depending on the alarm category.
- Operator text: &1 &2 failed: channel &3, slot &4 (substitutes the tag name, unit, channel and slot at runtime).
- Acknowledgement: enabled for the "Failure" class, disabled for warnings such as wire break if the HCI / Maintenance policy is configured to treat them as a non-ack warning.
5. Module and Channel Diagnostics Data Records
The ET 200SP HA modules expose a defined set of PROFINET IO diagnostic data records. The CPU 410-5H reads them on demand and on diagnostic interrupt; the values are the source of the "Bad quality" bit and the channel-diagnostic alarms seen on the OS. The data records most relevant to operator-visible diagnostics are listed below; refer to the SIMATIC ET 200SP HA Technology Modules manual for the full set and the byte layout.
| Data record | Hex index | Content | Source / use in PCS 7 |
|---|---|---|---|
| DS 0 | 0x8000 | Standard diagnostics (module state, channel 0..63 status, channel group error) | CPU 410-5H PROFINET stack; shows on OS via MOD_PREP and the IM 155-6 PN HA faceplate |
| DS 1 | 0x8001 | Module identification (order number, serial, firmware, slot) | Read with SFB 52 / SFB 81 on operator request |
| DS 12-15 | 0x800C-0x800F | I&M 0..3 (identification & maintenance) | Read with SFB 52; used by Maintenance Station Standard |
| DS 50 / DS 51 | 0x8032 / 0x8033 | Module parameter (read / write) | Used by HW Config of STEP 7 / TIA Portal |
| DS 92 | 0x805C | Reference data for PROFINET diagnostics | Internal - PROFINET stack |
| DS 94 | 0x805E | Diagnostic interrupt (with channel-diagnostic structure) | Triggered on alarm; read with SFB 52 RDREC |
| DS 100 | 0x8064 | Channel diagnostics (per-channel status and channel error type) | Source of the channel-level alarms in the OS |
| DS 192 | 0x80C0 | Watchdog time of the slot | Diagnostic - timeout indication |
| DS 200 | 0x80C8 | Maintenance information (counters, lifecycle) | Used by Maintenance Station Standard to render card status |
| DS 201 | 0x80C9 | Maintenance information (extended) | Optional, module-dependent |
RDREC is the unsigned 16-bit value (0x8000..0x80FF) - not the decimal number - and the slot/IM index must match the device's HW identifier in the PROFINET IO device table.6. Reading Diagnostics with SFB 52 / SFB 81
Although the standard process alarms are generated automatically, two scenarios still require an explicit read:
- Operator-triggered module information from a custom WinCC dialog.
- Custom maintenance logic that has to decide between two state categories (for example "warning" vs "failure") based on the maintenance information in DS 200.
Use the standard S7 system blocks - no proprietary block has to be written. The required SFBs are part of the CPU 410 firmware and are therefore available without a licence.
| SFB | Name | Purpose | Typical ID input |
|---|---|---|---|
| SFB 52 | RDREC | Read a data record (any index, including DS 0 / DS 1 / DS 12 / DS 100 / DS 200) |
ID := HW_ID(ET200SP HA slot) - decimal HW identifier from HW Config |
| SFB 53 | WRREC | Write a data record (e.g. command or parameter change) | ID := HW_ID(slot) |
| SFB 81 | RD_DPAR | Read the parameter assignment of a module (per device, not per channel) | ID := HW_ID(ET200SP HA head-end) |
| SFB 54 | RALRM | Receive an interrupt / alarm with the raw diagnostic data |
MODE := 1 (read full interrupt info) |
A minimal Structured Text wrapper for reading the channel diagnostic record of a digital input module is shown below. The block can be instantiated as a function block in the unit chart or in a dedicated "diagnostics" chart at plant level.
FUNCTION_BLOCK FB_RdChannelDiag
VAR_INPUT
hwId : DWORD; // HW identifier of the slot, e.g. DW#16#0000012C = 300
recIndex : BYTE; // 100 = 0x64, channel diagnostics
END_VAR
VAR_OUTPUT
status : WORD; // RET_VAL of RDREC, 0 = no error
busy : BOOL;
done : BOOL;
error : BOOL;
diagBytes : ARRAY[0..63] OF BYTE;
END_VAR
VAR
rdrec : RDREC; // SFB 52 instance
start : BOOL;
i : INT;
END_VAR
// request trigger
start := NOT busy AND NOT done;
rdrec(REQ := start,
ID := hwId,
INDEX := WORD#16#0064, // DS 100 = channel diagnostics
MLEN := 64,
VALID := done,
BUSY := busy,
ERROR := error,
STATUS := status,
RECORD := diagBytes);
After a successful read, decode diagBytes using the channel-diagnostic structure documented in chapter "Diagnostics / Alarms" of the ET 200SP HA configuration manual. Channel error codes 0x0001..0x000F (short circuit, wire break, underflow, overflow, parameterisation error) map to the channel alarm bits used by the APL drivers and the WinCC message system.
RDREC on the CPU 410-5H that currently owns the I/O. With the H-system firmware V8.2 or later, the PROFINET stack transparently routes the request to the active CPU, so a user block does not need to query RED_AGO.AS_ACTIVE first.7. Maintenance Station: Basic vs Standard
The PCS 7 Maintenance Station is the asset-management view of the plant. It renders block icons for every AS, every PROFINET/PN IO device, and (with the Standard option) every ET 200SP HA station and I/O card, and updates the state in real time using the data records listed above.
| Item | Maintenance Station Basic | Maintenance Station Standard |
|---|---|---|
| Licence | No additional licence (included in OS server) | Per-station licence (count-based) |
| AS block icons | Yes (CPU 410-5H pair) | Yes |
| PC-station block icons | Yes (OS server, ES, network components) | Yes |
| ET 200SP HA station block icon | No | Yes |
| ET 200SP HA I/O card block icons | No | Yes (DI, DO, AI, AO, technology modules) |
| Maintenance state machine (OK / Maintenance demanded / Maintenance required) | Partial | Full - based on DS 200 counters |
| WebNavigator / Information Server export | Yes | Yes (extended KPI set) |
To enable the Maintenance Station Standard:
- In SIMATIC Manager, open the OS project, right-click the OS server and select Object properties → OS server → Maintenance Station.
- Tick Maintenance Station Standard and enter the licence key in the "Authorisation" tab.
- In HW Config of the AS, mark the IM 155-6 PN HA as "diagnostics-capable" and enable the data record reads on slot 0 and on every I/O slot.
- Compile the OS - the compilation step automatically creates the block icons in the standard picture
@Maintenance.pdland adds the necessary WinCC tags under theDiagnostics\prefix.
8. Step-by-Step: Make Channel Diagnostics Visible in PCS 7 V9.0 SP2
- Compile the HW Config of the AS 410H with "Generate diagnostic data record reads = ON" for every ET 200SP HA head-end. The AS then reads DS 1, DS 12..15 and DS 200 cyclically (default 1 s).
-
Insert the APL channel driver in the unit chart: Pcs7AnIn, Pcs7DiIn, Pcs7AnOu, Pcs7DiOu, Pcs7Mot, Pcs7Valve - or one of the type-specific derivatives. Compile the chart. PCS 7 generates the
@chartwith the driver instance and theMOD_PREPblock. - Set the message classes in the block icon properties. For channel diagnostics, the APL default of Process - Failure for wire break / short circuit and Process - Warning for underflow / overflow is appropriate for most process plants.
- Download the AS program to the H-system. The PROFINET IO stack synchronises the channel-diagnostic information to the active CPU and the partner.
-
Compile the OS (full compile, not incremental). The new messages appear in the WinCC message configuration; the new variables appear under
Diagnostics\<unit>\. - Open the OS Runtime and acknowledge the test alarm triggered by pulling the sensor wire on a digital input channel. The corresponding message "Wire break DI_202 / channel 5" should appear in the message line and the Maintenance Station view should switch the block icon of slot 5 to "Maintenance demanded".
9. Verification Checklist
Run the following verification matrix before signing off the diagnostics configuration on a CPU 410-5H AS.
| # | Test | Expected result | Tool |
|---|---|---|---|
| 1 | Open HW Config → "Online → Accessible nodes" on the AS | IM 155-6 PN HA visible with firmware and order number | STEP 7 V5.6 + HSP |
| 2 | Disconnect one sensor on a digital input channel | OS message "Wire break" appears within < 1 s, Maintenance Station icon turns yellow | OS Runtime |
| 3 | Force a channel to exceed 20.5 mA on an AI 4-20 mA channel | OS message "Overflow" appears, value clamps at 21 mA with quality "bad, upper limit violated" | OS Runtime + maintenance view |
| 4 | Simulate slot failure by removing a module | OS message "Module failure", Maintenance Station icon turns red, redundant CPU stays in master | OS Runtime + Maintenance view |
| 5 | Trigger a CPU stop on the standby CPU 410-5H | No spurious channel diagnostic messages appear (PROFINET stack filters on the standby CPU) | OS Runtime |
| 6 | Trigger a CPU stop on the master CPU 410-5H | Failover completes in < 700 ms, channel diagnostics continue on the new master without operator intervention | OS Runtime + AS switchover log |
| 7 | Read DS 100 of the AI slot with SFB 52 from a custom block | Status word = 0 (no error), VALID goes high within 50 ms |
STEP 7 online monitor / SCL debug |
10. Troubleshooting Matrix
| Symptom | Likely root cause | Countermeasure |
|---|---|---|
| No message on the OS for a known wire break | Module is configured in HW Config without "Channel diagnostics = enabled" | Open the slot properties, tick "Channel diagnostics", re-download the HW Config and the AS program |
| Message appears, but the Maintenance Station icon stays green | Maintenance Station Standard is not licensed | Activate the licence under OS server → Object properties → Maintenance Station, recompile the OS |
| Channel diagnostic only on one CPU of the H-system | Diagnostic interrupt blocked by user-acked MSG_LOCK on the standby CPU |
Remove the MSG_LOCK input on the APL driver or wire it to the RED_AGO.AS_ACTIVE signal |
RDREC returns status W#16#80A1 |
Negative acknowledgement, slot not accessible | Check the HW identifier, ensure the slot is owned by the master CPU. Verify the head-end has the latest IM 155-6 PN HA firmware |
RDREC returns status W#16#80B1 |
Index out of range | The data record index is 16-bit (0x8000-0x80FF). Re-check the INDEX parameter, not the decimal number |
| Overflow alarm appears on every channel of a module | Common-mode voltage on the AI reference ground; module is in "voltage measurement" but wired in current | Wire the channel as 0/4-20 mA, configure measuring range "2-wire / 4-wire transducer" in HW Config, re-download |
| Diagnostic buffer of the CPU 410-5H is full of "Module removed / inserted" events | Loose D-sub connector on the front connector of the ET 200SP HA terminal block | Re-tighten the front connector, re-seat the terminal block until the latch audibly clicks |
| Wire-break alarm is missing on a NAMUR input channel | NAMUR channel must be explicitly configured as "NAMUR", not as "24 V DC standard" | Set the channel type to "NAMUR" in HW Config slot properties, re-download the HW Config |
11. Field-Commissioning Notes
-
CFC compile order. Compile the unit charts before the
@chartis generated. The@chartdepends on the chart-folders of the unit; an out-of-order compile creates a@chartwith missing channel-driver instances. - I&M data. Fill the I&M 1, I&M 2, I&M 3 fields per module before the first cold start. The Maintenance Station Standard depends on I&M 1 ("Location") to render the asset tree correctly.
-
OS redundancy. If the OS server is redundant, the Maintenance Station views are mirrored automatically. Verify the
Diagnostics\tag prefix is identical on both servers, otherwise messages from the partner server will be tagged as "Unknown". - PROFINET update time. The default update time of 1 ms for the IM 155-6 PN HA may be too aggressive for analog channels. Use 2 ms for AI/AO channels in the process industry, and 1 ms only for fast DI/DO. See Reading out the diagnostics in STEP 7 (TIA Portal).
- Cybersecurity. Channel diagnostic reads use plain S7 communication. If the AS is on a security-zoned network, open the firewall only for S7 port 102 and the PROFINET-RT class 1 multicast ranges.
FAQ
Which PCS 7 block reads ET 200SP HA module diagnostics automatically?
None of the user blocks does it manually. The PROFINET IO stack of the CPU 410-5H reads the diagnostic data records of every ET 200SP HA slot, and the APL channel drivers (Pcs7AnIn, Pcs7DiIn, Pcs7AnOu, Pcs7DiOu, Pcs7Mot, Pcs7Valve) in the unit @chart evaluate the value status and emit the channel-diagnostic alarms. No additional block has to be programmed for the standard alarms.
Can I read a specific data record (for example DS 100) from an ET 200SP HA module?
Yes. Use SFB 52 "RDREC" with the slot's HW identifier and the 16-bit PROFINET IO index of the data record (for example 0x0064 for DS 100, channel diagnostics). SFB 81 "RD_DPAR" reads the parameter assignment of the head-end module, and SFB 54 "RALRM" returns the full interrupt data of a diagnostic interrupt.
What is the difference between Maintenance Station Basic and Standard?
Maintenance Station Basic is included with the OS server licence and generates block icons only for the AS, the PC stations and the network components. Maintenance Station Standard requires an additional per-station licence and additionally generates block icons for the ET 200SP HA stations and every I/O card, with a full maintenance state model based on data record 200.
Does diagnostics work on a redundant CPU 410-5H pair?
Yes. With H-system firmware V8.2 or later the PROFINET stack synchronises the channel-diagnostic state to the partner CPU in the background, and the application code does not need to be aware of which CPU is currently the master. The standby CPU does not generate duplicate diagnostic interrupts for the same I/O.
Where can I get a sample project that uses APL diagnostics on ET 200SP HA?
Siemens does not ship a "PCS 7 with ET 200SP HA diagnostics" sample as a single archive. Build the sample yourself by creating a unit, dropping the APL channel driver into its chart, compiling the unit, and enabling Maintenance Station Standard in the OS server. The PCS 7 V9.0 SP2 APL Function Manual describes the inputs, outputs and message classes of every APL channel driver, and the ET 200SP HA configuration manual describes the diagnostic data records that the drivers evaluate.
What does status W#16#80A1 of SFB 52 mean on an ET 200SP HA slot?
W#16#80A1 is a negative acknowledgement and means that the slot is currently not accessible - usually because the slot is in the partner CPU, the module is in startup, or the HW identifier in the call does not match the slot. Verify the HW identifier, wait until the module is back in operation, and call RDREC again.