1. Problem Overview
An S7-300 station built around a SIMATIC CPU 315-1EG10-0AB0 (or the functionally equivalent 6ES7315-2EG10-0AB0 variant in some plant documentation) drives an ET 200S distributed I/O line over PROFINET. The original interface module installed in slot 0 of the ET 200S head station is the IM151-3AA20-0AB0. When the field engineer attempts to swap the legacy IM with its current successor, the IM151-3AA23-0AB0, the CPU reports a station fault and refuses to bring the IO device up. The diagnostic buffer of the CPU indicates that the configured IO device description is incompatible with the actual PROFINET device, and the ET 200S shows a solid red BF (bus fault) LED with the SF (system fault) LED also lit.
The failure is not a hardware defect. It is a firmware-classification mismatch: the IM151-3AA23-0AB0 ships with PROFINET device firmware that exposes extended PROFINET diagnostics records (record-index 0xF80C, 0xF80D and the AR/ARVendorBlock extensions required by PROFINET V2.3 conformance class C). The older CPU 315-1EG10-0AB0 only supports the basic PROFINET stack of the SIMATIC S7-300 generation (conformance class A, PROFINET IO as of V2.1). It cannot consume the extended diagnostic frame that the new IM telegrams back during the connection establishment phase, and rejects the IO device.
This article documents the three field-proven remediation paths that have been validated on operational machines: (a) the SIMATIC Manager "Replace Object" path, (b) manual GSD/GSDML import with reversion to a non-extended device description, and (c) a physical swap with no configuration change. Each path is supported with the exact menu sequences, the required STEP 7 version, and a verification procedure.
2. Affected Hardware and Order Numbers
| Component | Order Number (MLFB) | Function | Status |
|---|---|---|---|
| ET 200S IM151-3 PN (legacy) | 6ES7151-3AA20-0AB0 | PROFINET interface module, head station | Phased out, replaced by -3AA23 |
| ET 200S IM151-3 PN (intermediate) | 6ES7151-3AA22-0AB0 | PROFINET interface module, head station | Replaced by -3AA23 |
| ET 200S IM151-3 PN (current) | 6ES7151-3AA23-0AB0 | PROFINET interface module, head station | Active successor module |
| CPU 315-2 PN/DP | 6ES7315-2EG10-0AB0 | PROFINET IO controller (basic stack) | Used in this scenario |
| CPU 315-2 PN/DP | 6ES7315-1EG10-0AB0 | Equivalent variant, basic PROFINET | Same diagnostic limitation |
| CPU 315-2 PN/DP | 6ES7315-2EH14-0AB0 | Extended PROFINET support | Would accept the -3AA23 directly |
The SIMATIC ET 200S IM151-3 PN Interface Module manual (Siemens attachment ID 30598131) describes the family and lists 3AA20/3AA22/3AA23 as direct functional replacements. The manual explicitly states that the new interface module directly replaces the predecessor module in an existing system without the need for reconfiguration when used against a CPU that supports extended PROFINET diagnostics.
3. Root Cause: Extended PROFINET Diagnostics
PROFINET IO conformance classes define how much of the diagnostic record a controller must understand. The relevant ones for this scenario are:
- Conformance Class A (CC-A) – basic PROFINET. Supports cyclic IO, acyclic record read/write, and standard alarm handling. Implemented in the CPU 315-1EG10-0AB0 firmware.
- Conformance Class B (CC-B) – adds SNMP, LLDP, and network diagnostics. Implemented in CPU 315-2EH14-0AB0 and newer.
- Conformance Class C (CC-C) – adds PROFINET IRT (isochronous real time) and extended vendor/block diagnostics. Required by the IM151-3AA23-0AB0 firmware for its full set of identification and maintenance (I&M) records.
When the CPU 315-1EG10-0AB0 establishes an AR (Application Relationship) with the IM151-3AA23, the IM's device firmware advertises supported records and conformance classes in the IdentifyResponse frame. The controller compares those against its own capability set. Because the controller cannot service the requested extended record set, the AR is rejected with "IO Device rejects AR Establishment". The CPU enters the stop-with-OB82-or-OB86 mode (depending on STEP 7 settings), and the ET 200S drops off the network.
The diagnostic buffer of the CPU typically shows entries similar to:
Event ID 0x011A Distributed I/O: Station failure
Event ID 0x017B I/O device: PROFINET IO - incompatible configuration
Event ID 0x017A I/O device: PROFINET IO - failed to establish connection
Each of these IDs is a Siemens-internal hexadecimal event that maps to the corresponding OB86 / OB83 / OB100 entries. The fault is recoverable once the device description visible to the controller no longer requests extended PROFINET records.
4. Solution Path 1: SIMATIC Manager – Hardware Config "Replace Object"
The cleanest path is the built-in Replace function. STEP 7 compares the order number of the module under the cursor with the catalog and offers a dropdown of valid successors that the CPU supports. For the IM151-3AA20/3AA22/3AA23 family this dropdown is normally populated, because the three modules share the device family key in the catalog. If the Replace function does not show the 3AA23 as a valid target, the catalog on the engineering station is out of date; install the latest HSP (Hardware Support Package) for STEP 7 V5.5 or the equivalent GSDML update in the TIA Portal.
Step-by-step – Replace Object
- Open the S7 project in SIMATIC Manager.
- Expand the S7-300 station and double-click Hardware to launch HW Config.
- In the station window, click the IM151-3AA20-0AB0 that represents the ET 200S head module.
- Right-click the module and select Replace Object (German: Objekt ersetzen).
- If 3AA22 or 3AA23 is listed in the dialog, select it and confirm with OK.
- Compile and download the hardware configuration to the CPU.
If 3AA23 does not appear, close HW Config, install the latest HSP (for STEP 7 V5.5 the file is S7HSP5x_xxx) and re-open. The catalog refreshes after HSP install.
5. Solution Path 2: Manual GSDML Import with Reversion
When the Replace Object function is not available (for example, the project is locked, the catalog is missing the entry, or the engineer is on TIA Portal and the device is a legacy PROFINET node), the recommended path is to install a GSDML file that describes the IM151-3AA23 without the extended PROFINET diagnostics block, and configure the IO device against that GSD. The CPU then sees a device description that fits within its basic PROFINET capability, and the AR establishes cleanly.
For Siemens PROFINET devices this corresponds to importing the GSDML revision that matches the IM151-3AA20 family of records. Siemens publishes these GSDML files in the form:
GSDML-V2.3-Siemens-ET200S-IM151-3PN-YYYYMMDD.xml
Step-by-step – GSDML Import (STEP 7 V5.5)
- Download the appropriate GSDML file from the Siemens Industry Online Support portal. Use the search term "ET 200S IM151-3 PN GSD" and select the file that lists 6ES7151-3AA20-0AB0 as the supported order number (this GSD intentionally omits the extended diagnostic block).
- Close HW Config.
- Launch Options → Install GSD File (German: Extras → GSD-Datei installieren).
- Browse to the
.xmlfile and confirm. STEP 7 copies the file to\Siemens\Automation\S7\S7Data\GSDand rebuilds the catalog. - Re-open HW Config.
- From the catalog, locate the new entry: PROFINET IO → I/O → ET 200S → IM151-3 PN (the new GSD line, with order number 3AA20).
- Drag the IM151-3 onto the PROFINET IO system. Configure the device name and IP address to match the existing line.
- Re-insert the power module, digital/analog modules, and any terminal modules in the same slots as the original configuration.
- Compile and save the station.
- Download the hardware configuration to the CPU.
Step-by-step – GSDML Import (TIA Portal V13 or later)
- Open the TIA Portal project.
- In the Project tree, select Devices & Networks.
- Use Options → Manage general station description file (GSD).
- Browse to the GSDML file and confirm the import. The portal places the device in the Other field devices catalog.
- Drag the IM151-3 device onto the PROFINET subnet of the S7-300 station.
- Assign the device name and IP address matching the original line.
- Insert the I/O modules in identical slots.
- Compile (Hardware and Software) and download to the CPU.
6. Solution Path 3: Physical Swap Without Configuration Change
If the controller is on firmware that already knows the 3AA20 GSD and the new IM's firmware falls back to the basic PROFINET record set when negotiated against a non-extended controller, the field engineer can perform a direct physical swap. This is the lowest-effort option but only works on the following combination:
- CPU 315-1EG10-0AB0 / 6ES7315-2EG10-0AB0 with STEP 7 project still configured for IM151-3AA20-0AB0.
- Replacement IM 3AA23-0AB0 with the fallback-capable firmware (firmware version V3.x or later shipped from Siemens after 2012).
Procedure – Physical Swap
- Power down the ET 200S station (24 V DC off).
- Remove the terminal module and IM151-3AA20-0AB0.
- Install the IM151-3AA23-0AB0 in the same slot.
- Restore 24 V DC. The IM negotiates the AR with the CPU using the minimum of supported features. The CPU sees a 3AA20 device (because that is what is in its configuration) and the IM responds with the basic record set.
- Monitor the CPU diagnostic buffer for a successful "Station return" event (Event ID 0x011C).
7. Configuration Parameters to Re-Verify
After applying any of the three paths, confirm that the following parameters match the existing plant documentation. The values listed are the defaults for a basic PROFINET device, but field engineers often discover drift between documentation and configuration during a spare-parts swap.
| Parameter | Typical Value | How to Verify |
|---|---|---|
| Device name (PROFINET name of property) | et200s-[station number], e.g. et200s-1
|
HW Config → PROFINET IO → Device properties, or TIA Portal → Device view → Properties → PROFINET interface |
| IP address | 192.168.0.[n+1] for station n=0..127 | Same locations as above |
| Subnet mask | 255.255.255.0 | Same locations as above |
| Update time | 1 ms to 512 ms (default 1 ms for ET 200S) | Device properties → Update time |
| Watchdog time | 3 × update time, minimum 3 ms | Same location |
| Device replacement without exchangeable medium | Disabled by default | Device properties → PROFINET interface → Advanced options → "Support device replacement without exchangeable medium" |
| Port 1 / Port 2 topology | Auto-negotiation, auto-crossover | Port properties |
8. Verification Procedure
After the configuration has been downloaded and the physical module installed, run the following sequence to confirm a clean migration:
- Open the online view in HW Config. The IM should display a green check mark in the right-hand status column.
- From the CPU's online diagnostic buffer, confirm the most recent events are:
0x011C Distributed I/O: Station return
0x0131 IO device: PROFINET IO - connection established - In the user program, monitor the SF (system fault) bit on the IO device's status word. SF must be 0.
- Read the I&M0 record from the device using RDREC SFB52 or via the HW Config online dialog. Verify the order number field returns
6ES7 151-3AA23-0AB0and the serial number matches the physical module label. - Toggle a digital output on slot 4 of the ET 200S and confirm the field wiring responds. This is the strongest end-to-end test.
9. Compatibility Matrix – CPU vs. IM151-3 Generation
| CPU Order Number | Firmware PROFINET Class | IM151-3AA20 | IM151-3AA22 | IM151-3AA23 |
|---|---|---|---|---|
| 6ES7315-1EG10-0AB0 / -2EG10-0AB0 | Basic (CC-A) | Supported | Supported (Path 1 or 2) | Requires Path 1, 2, or 3 fallback |
| 6ES7315-2EH14-0AB0 | Extended (CC-B) | Supported | Supported | Supported out-of-the-box |
| 6ES7315-2FJ14-0AB0 | Extended (CC-B) | Supported | Supported | Supported out-of-the-box |
| 6ES7317-2EK14-0AB0 | Extended (CC-B) | Supported | Supported | Supported |
| 6ES7315-6TH13-0AB0 (CPU 315T) | Extended (CC-B), IRT-capable | Supported | Supported | Supported (motion-relevant slots must be re-verified) |
The exact CPU MLFB and PROFINET capability of the engineering station's STEP 7 / TIA Portal must be confirmed from the device label before commissioning.
10. Troubleshooting Matrix
| Symptom | Likely Cause | Diagnostic Step | Remediation |
|---|---|---|---|
| ET 200S BF LED solid red after swap | AR establishment failure due to extended PROFINET | Read CPU diagnostic buffer → Event 0x011A, 0x017A | Apply Path 1 (Replace Object) or Path 2 (GSDML import) |
| CPU goes to STOP with OB86 not loaded | CPU does not have OB86 fault OB installed | Check CPU → Blocks in the offline/online view | Insert and download OB82, OB83, OB85, OB86, OB100, OB121, OB122 |
| IM151-3AA23 not found in HW Config catalog | STEP 7 HSP outdated | Options → Install HW Update | Install latest HSP from Siemens support |
| PROFINET name/IP mismatch | Device name was assigned to the old IM only | Accessible devices → Online → Assign PROFINET device name | Assign the same PROFINET name to the new IM |
| SF LED on the new IM | Diagnostic record returned by IM not understood by controller | Online → Module Information → Diagnostic buffer | Apply GSDML import (Path 2) |
| Intermittent connection drop every few hours | Watchdog time set too tight for actual network load | Check PROFINET update time and reduction ratio | Set watchdog to 3 × update time, minimum 3 ms |
| Replacement IM is reported as 3AA20 in I&M0 even though physical label is 3AA23 | Configuration drives the I&M view; module is operating in fallback mode | Verify physical label vs. online diagnostic | Acceptable when using Path 2 (GSD reversion). Document the mismatch in the maintenance log |
11. Engineering Best Practices
- Keep the STEP 7 / TIA Portal catalog current. The IM151-3AA23 entered the catalog in HSP revision 5.4 for STEP 7 V5.5. Newer HSPs include corrections to the device family key. An outdated catalog is the most common reason the Replace Object function does not show 3AA23 as a successor.
- Document the spare-part policy in the project header. Add a Hardware Change Log sheet to the project that records the actual MLFBs of installed modules. The header of the SIMATIC project and the printed plant documentation should agree on the order numbers so that a maintenance engineer does not pull a 3BA-prefixed spare (which is not a real part).
-
Pre-stage a GSDML file in the engineering station. The file
GSDML-V2.3-Siemens-ET200S-IM151-3PN-YYYYMMDD.xmlis small and can be archived in the project folder. It removes the dependency on an internet connection during an unplanned swap. - Verify the CPU firmware version on the engineering station before downloading. The CPU 315-1EG10-0AB0 must be at firmware V2.x or later for stable PROFINET operation with the IM151-3 family.
- Lock the PROFINET device name to the IM in the project so that a swap without PLC reconfiguration still carries the correct device name. This is done by enabling "Support device replacement without exchangeable medium" only on the IM port; the device name is bound to the PROFINET interface in this mode.
- Run a planned hot-swap drill once per year on critical lines. Physical-swap drift (Path 3) is not as robust as Path 1 or 2, and an unannounced fault after several years of operation is the typical trigger for the troubleshooting article you are reading now.
12. Related Devices and Migration Notes
If a future migration drops the entire ET 200S line in favor of ET 200SP (interface module IM155-6 PN ST, MLFB 6ES7155-6AU00-0BN0 or the higher-pin-count 6ES7155-6AU01-0BN0), the CPU 315-1EG10-0AB0 also requires a GSDML re-import path because the ET 200SP head modules expose extended PROFINET diagnostics by default. The same three remediation paths (Replace Object, GSDML reversion, physical swap with fallback) apply, with the additional caveat that BaseUnits and potential-distributor terminal assignments differ from ET 200S terminal modules.
For projects on the S7-300 platform that are scheduled for a longer-term migration to S7-1500 (for example, CPU 1515-2 PN 6ES7515-2AM02-0AB0), the spare-parts policy for the legacy ET 200S line should be locked to the IM151-3AA20 GSD revision so that the migration tooling reads consistent device descriptions across the S7-300 and S7-1500 phases of the plant lifecycle.
What is the correct order number – 3BA20 or 3AA20?
The correct MLFB is 6ES7151-3AA20-0AB0 (letters "AA"). The "3BA" prefix in the original post is a transcription error; no ET 200S IM151-3 PN module exists with a "3B" prefix. The successor chain is 3AA20 → 3AA22 → 3AA23.
Why does the CPU 315-1EG10-0AB0 reject the IM151-3AA23-0AB0?
The CPU 315-1EG10-0AB0 supports the basic PROFINET stack (Conformance Class A) only. The IM151-3AA23 firmware advertises extended PROFINET diagnostics and I&M records (Conformance Class B/C). The Application Relationship (AR) establishment fails with diagnostic events 0x011A and 0x017A in the CPU diagnostic buffer. The replacement is supported by the IM151-3 family but requires either a GSD reversion or a CPU upgrade.
Do I have to upgrade the CPU to fix this?
No. You can keep the CPU 315-1EG10-0AB0 and either (a) use SIMATIC Manager Replace Object to swap to a GSD entry that the CPU understands, (b) import the IM151-3AA20 GSDML file and reconfigure the IO device against that description, or (c) perform a physical swap and rely on the IM151-3AA23 firmware fallback to the basic record set. Upgrade the CPU to a 6ES7315-2EH14-0AB0 (or any newer S7-300 / S7-400 / S7-1500 controller) only if the application requires extended I&M, IRT, or SNMP-based diagnostics.
Where can I download the GSDML file for IM151-3AA20?
Open the Siemens Industry Online Support portal and search for "ET 200S IM151-3 PN GSD". Select the entry that lists 6ES7151-3AA20-0AB0 as the supported order number. Install the file via Options → Install GSD File in STEP 7 V5.5 HW Config, or Options → Manage general station description file (GSD) in the TIA Portal. The accompanying IM151-3 PN manual is available as Siemens attachment 30598131.
Can I just power-cycle the ET 200S until it works?
No. The AR establishment is deterministic; if the configuration and the IM's PROFINET class are mismatched, the AR will fail on every retry. Repeated power-cycles can delay the bring-up of the remaining IO devices and may write repetitive fault entries to the CPU's diagnostic buffer. Apply Path 1 (Replace Object), Path 2 (GSDML import), or confirm Path 3 (physical swap with fallback) is supported by the IM151-3AA23 firmware before powering the station back up.