Resolving BAF-FAULT on Siemens S7-400 PS407 Battery Backup

David Krause13 min read
S7-400SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Overview

The BAF (Battery Fault) LED on a Siemens PS407 power supply module lights red whenever the backup voltage presented to the S7-400 backplane bus drops below the supervisor threshold. On a CPU 414-4H (or any S7-400 CPU), this means the buffered RAM, retentive flags, and the entire load image can be lost the moment the 24 V DC rail collapses. The classic symptom is:

  • PS407 runs normally with the front-panel BATT INDIC switch in position OFF.
  • When the operator flips the switch to 1 BATT or 2 BATT, the red BAF LED and one of the yellow battery LEDs (BATTF, BATT1F, or BATT2F) illuminate.
  • A subsequent power-off/on cycle erases the user program from both H-CPUs; the project must be reloaded from the engineering station.

The fault is hardware-detected by the PS module itself and is not a CPU diagnostic in the strict sense. It is signalled on the backplane bus to the CPU, where it can be evaluated through OB81 (Power Supply / Battery Fault OB) for controlled reaction.

Critical safety point: A steady BAF on a redundant CPU 414-4H means the buffered RAM of both H-CPUs is unprotected. A mains failure or 24 V drop-out will result in full loss of program, retentive data, and the active link table. Treat the fault as a process-safety-relevant event, not a nuisance.

2. Affected Hardware and Battery Types

The following PS407 variants are typically involved in this fault class. The diagnostic behaviour is identical across the family because the BAF supervision is implemented in the same backplane interface ASIC.

PS407 Order Number Output Battery Slots Backup Type
6ES7407-0DA02-0AA0 5 V / 5 A, 24 V / 0.5 A 1 or 2 Lithium, 3.6 V
6ES7407-0KA02-0AA0 5 V / 10 A, 24 V / 1 A 1 or 2 Lithium, 3.6 V
6ES7407-0KR02-0AA0 5 V / 10 A, 24 V / 1 A (redundant) 2 Lithium, 3.6 V
6ES7407-0RA02-0AA0 5 V / 20 A, 24 V / 1 A 1 or 2 Lithium, 3.6 V

Siemens recommends the following backup battery:

  • 6ES7971-0BA00 – Lithium back-up battery, 3.6 V, 2.4 Ah, AA-size, for S7-400 PS407 and IM460/IM461 repeater diagnostics.

Operating temperature of the battery is -40 °C to +85 °C, with a self-discharge below 1 % per year at 25 °C. Expected service life in a PS407 is typically 2 to 4 years depending on ambient temperature and number of deep-discharge events. The PS407 supervises the cells through a precision comparator; an open-circuit voltage below ~3.0 V or a polarity inversion will be detected within seconds of the BATT INDIC switch being moved to a monitored position.

3. BAF LED and BATT INDIC Switch Operation

The front panel of every PS407 carries the same set of indicators, in the same physical layout:

Element Type Function
INTF Red LED Internal fault on the PS module (5 V / 24 V out-of-tolerance, overtemperature)
BAF Red LED Backup voltage on the backplane bus is too low
BATTF Yellow LED Battery holder empty or holder switch open
BATT1F Yellow LED Slot 1 battery exhausted or reverse-polarised
BATT2F Yellow LED Slot 2 battery exhausted or reverse-polarised (only on 2-slot versions)
BATT INDIC 3-position toggle Selects the battery channel(s) that are supervised

The toggle has three discrete positions:

  1. OFF – Neither battery slot is supervised. If a battery fails, no front-panel LED is lit. The CPU still receives the bus signal BAF only if the buffered backplane voltage itself collapses; an open cell under no load may go unnoticed for weeks.
  2. 1 BATT – Slot 1 is supervised. A bad or missing cell in slot 1 lights BATT1F and BAF.
  3. 2 BATT – Slot 2 is supervised (1-slot PS modules ignore this position mechanically; on 2-slot modules the switch actually moves to a 2 BATT detent).

The combined indication BAF + BATT1F or BAF + BATT2F therefore uniquely identifies which physical battery must be replaced. The combination BAF + BATTF indicates a holder wiring problem rather than a bad cell.

4. Root Cause Analysis

Per the SIMATIC S7-400 Module Data manual and the S7-400 Hardware and Installation manual, the BAF fault is set when the backup voltage on the rear bus drops below a threshold nominally set at 2.7 V per cell. Practical causes observed in the field are summarised in priority order:

# Root Cause Detection Cue Likelihood
1 Battery end-of-life (open circuit or < 3.0 V OCV) BAF + BATT1F or BATT2F lit immediately after switch to a supervised position High
2 Reversed polarity during a previous replacement Identical to a dead cell; voltage measurement reveals −0.4 V instead of +3.6 V at the holder High
3 Holder contacts contaminated or oxidised BAF + BATTF; cell removed and reinserted, fault returns Medium
4 BATT INDIC switch was left in OFF and batteries were never tested (hidden depletion) BAF appears only after a real mains event, not after a switch change Medium
5 External DC backup on the front-panel jack is missing or the wrong polarity is applied BAF present regardless of BATT switch position when an external supply is connected Low
6 PS module hardware fault (broken supervisor comparator, dry-jointed holder lead) BAF remains after two known-good cells inserted, all four LEDs are correct, cable is OK Low
On the CPU 414-4H, both H-CPUs share the same backplane but each PS407 in the redundant power segment has its own battery pair. If only the right-hand PS is fitted with batteries, the left PS still has to be supervised; otherwise the H-system enters a single-feed state during a battery-only window.

5. Diagnostic Procedure

  1. Power down the rack. The PS module can be hot-inserted in some configurations, but the BAF should be diagnosed cold to avoid spurious BATT 1F/2F toggles during capacitor discharge.
  2. Open the battery holder on the front of the PS407. There is no screw – the cover is a spring-loaded slide.
  3. For each cell, measure the open-circuit voltage with a calibrated DMM. The expected reading is 3.40 V to 3.65 V for a healthy 3.6 V lithium-thionyl chloride AA cell.
  4. Check the polarity marking on the holder. The positive terminal is the side nearest the upper lip of the holder on every PS407 variant.
  5. Inspect the contact springs for white-green oxidation or mechanical deformation. If present, clean with isopropyl alcohol and a non-metallic brush. Do not bend the springs back into shape – replace the holder assembly (6ES7971-0BA00 includes the cell only; the holder is part of the PS407 spare-parts kit).
  6. Reinsert the cells, re-engage the holder switch, and apply 24 V DC to the PS input.
  7. Move the BATT INDIC toggle to 1 BATT. The BAF and BATT1F LEDs should be dark within 5 s, indicating that the supervisor has accepted the new cell.
  8. Repeat with 2 BATT on dual-slot variants.

If BAF returns at step 7 with a cell that measured > 3.4 V, the supervisor is detecting an internal resistance problem. Lithium cells can develop high internal impedance near end-of-life even when the open-circuit voltage looks healthy. Replace the cell.

6. Battery Replacement Procedure

  1. Order the correct battery: 6ES7971-0BA00 (lithium 3.6 V 2.4 Ah). Two cells are required for the redundant-slot PS407 (6ES7407-0KR02 and 6ES7407-0RA02). Do not substitute alkaline cells – the discharge curve is incompatible and the supervisor will flag them as end-of-life within weeks.
  2. Take an ESD wrist-strap precaution. The S7-400 backplane connector is not as ESD-sensitive as a CompactFlash card, but the PS supervisor is a precision analog circuit and should be treated as such.
  3. With mains on and the CPU in RUN, the replacement can be done hot – but you must complete the swap within approximately 30 s per cell to avoid the capacitor-backed hold-up time of the PS expiring and the BATT1F retriggering. If you exceed this window, the CPU will go to STOP with a buffer failure on the next scan.
  4. Insert the new cell in the same orientation as the failed cell. Reverse-polarity is the single most common cause of the original BAF; positive pole must face the spring marked with the “+” or the cell-side contact with the red flag.
  5. Close the holder, re-engage the interlock switch, and verify that BATT1F / BATT2F extinguish.
  6. Update the maintenance log: the date, cell serial, and the technician ID. The replacement is now traceable in your CMMS.
Disposal: Lithium-thionyl chloride cells are classified as Class 9 dangerous goods. Do not incinerate; discharge fully and recycle through a licensed Li battery handler.

7. Using the External Power Jack (Field Trick)

The PS407 has a 4-pole DC jack on the front face. This jack is internally connected in parallel with the backup battery rail and accepts a 3.6 V to 5 V DC external source. Engineers in the field frequently use a standard 9 V battery behind a series diode and a 1 kΩ resistor to keep the RAM alive while the cells are out:

+-------+      +-----+      +----+
| 9 V   |--+---| D  |--+---| 1k |---o PS407 EXT jack (+)
| PP3   |  |   +-----+  |   +----+
+------+  |             |
         ===            o PS407 EXT jack (−) / GND
         GND

With the external supply connected, the BAF LED may stay lit – this is normal because the supervisor only validates cells inside the holder. The external supply is not supervised. Use it for the short window of a battery swap, then remove it.

8. Programmatic Handling with OB81

Once the hardware is healthy, capture the BAF in firmware so a future battery failure is logged and alarmed instead of silently erasing the program. The standard approach is OB81 (Power Supply / Battery Fault OB). A minimal implementation in STL follows:

ORGANIZATION_BLOCK OB81
TITLE = "Battery / PS Fault Handler"

AUTHOR  : MAINT
FAMILY  : S7400

BEGIN
    // OB81_EX_FLT_ID = B#16#22 -> Battery exhausted
    // OB81_EX_FLT_ID = B#16#23 -> Backup voltage low
    // OB81_EX_FLT_ID = B#16#25 -> Power supply failure
    // OB81_EX_FLT_ID = B#16#26 -> Power supply OK (incoming event)
    // OB81_MDL_ADDR  = 0x0C00 .. base address of the PS slot

    L     #OB81_EX_FLT_ID          // load the event ID
    L     B#16#22                  // expected ID for empty battery
    ==I
    S     "BAF_LATCH"              // set a retentive bit

    L     #OB81_MDL_ADDR           // which PS module triggered it
    T     "BAF_PS_LOG"             // write the slot byte for HMI

    CALL  "WR_USMSG"               // write a diagnostic buffer entry
      SF  := "BAF_LATCH"
      EV  := B#16#22
    BE

END_ORGANIZATION_BLOCK

The corresponding incoming event (B#16#26 – power supply OK) is generated when the cell is replaced and the supervisor sees the bus voltage recover. In a CPU 414-4H, you should also evaluate OB72 (CPU redundancy loss) because a single PS failure that takes the bus down may simultaneously trip the H-link, and you want to know which one was primary.

9. H-System Specific Considerations (CPU 414-4H)

For a CPU 414-4H rack, the BAF must be evaluated against the redundancy context:

  • Each H-CPU reads the backplane bus through its own PS407 (or one shared PS407 in UR2). The OB81 OB81_MDL_ADDR will differ between H-stations.
  • If both PS modules report BAF, both H-CPUs lose buffer protection at the same instant. The H-link will not save you – it is RAM-resident as well.
  • A single PS407 with one failed cell is a single-point-of-failure in an otherwise fault-tolerant H-system. Replace the cell on the next planned outage, not at the next PM interval.
  • Configure OB81_TIME_STAMP capture in both H-CPUs to synchronise battery telemetry in WinCC; this helps correlate a future RAM loss with the maintenance log.

10. Verification and Commissioning

  1. Power on the rack with the new battery in place and the BATT INDIC toggle at OFF. Confirm INTF, BAF, and BATT1F / BATT2F are dark.
  2. Switch to 1 BATT; wait 10 s; verify the BATT1F remains dark. If it lights, recheck the cell voltage under load by inserting a 100 Ω resistor across the holder for 5 s and re-measuring.
  3. Switch to 2 BATT (if applicable); repeat.
  4. Force an OB81 test by removing the cell again, waiting 60 s, and confirming the diagnostic buffer entry appears with event ID B#16#22.
  5. Reload the user program if it was lost in the original event. Verify all retentive DBs, M flags, and the SFC / SFB instance DBs are restored from the project.
  6. Mark the rack in RUN; have a colleague cycle the 24 V DC feed on the upstream breaker. Confirm the program survives, the diagnostic buffer shows an incoming OB81 with B#16#26, and the CPU does not transition to STOP.

11. Preventive Maintenance Schedule

Interval Action
Quarterly Visual inspection of the holder, clean the front-panel vents.
Semi-annually Toggle the BATT INDIC switch through all three positions and confirm BATT1F / BATT2F remain dark with a known-good cell.
24 months Proactive cell replacement, regardless of measured voltage, in ambient > 35 °C installations.
36 months Standard proactive cell replacement, in ambient ≤ 25 °C installations.
After every deep discharge Replace the cell within 7 days – a deep discharge below 2.0 V permanently reduces the capacity and the supervisor will retrigger BAF within weeks.

12. Related Diagnostics and Cross-Reference

The BAF LED is the only PS-side indicator of backup health. Other LEDs that can co-occur and that should not be confused with BAF:

  • INTF red – internal 5 V or 24 V out of tolerance, or overtemperature on the PS. Replace the PS module.
  • SF on the CPU – a group error; clicking through the diagnostic buffer in STEP 7 will usually reveal an OB81 entry that points back to the same PS slot.
  • EXTF on the CPU – external fault, often a wire-break on a signal module; do not confuse with a battery issue.

For the wider fault taxonomy of S7-400 power, refer to the Fault types, causes, and corrective measures section of the Siemens fail-safe modules reference.

13. Summary of Indicators and Action

LED Pattern Meaning Action
BAF only Bus backup voltage low, but switch may be in OFF Move BATT INDIC to 1 BATT; recheck
BAF + BATTF Holder interlock not engaged Close holder, verify switch is fully down
BAF + BATT1F Slot 1 cell empty, reverse-polarised, or below 2.7 V Replace cell 1; verify polarity
BAF + BATT2F Slot 2 cell empty, reverse-polarised, or below 2.7 V (2-slot PS only) Replace cell 2; verify polarity
BAF + INTF PS module hardware fault in addition to backup issue Replace PS407; investigate upstream 24 V

What does the BAF LED on a Siemens S7-400 PS407 indicate?

BAF (red) lights whenever the backup voltage presented by the batteries to the S7-400 backplane bus drops below the supervisor threshold of approximately 2.7 V per cell. It is paired with BATT1F, BATT2F, or BATTF to identify which slot or the holder itself is at fault. It is independent of the CPU run state.

Why does the program disappear from both CPU 414-4H stations after a mains event when BAF is on?

The PS407 only buffers RAM when the supervisor detects a valid 3.6 V cell. If BAF is lit, the supervisor has already determined the bus backup is below the threshold, so the next 24 V drop-out leaves the backplane with no energy and the CPU retentive memory is erased. Both H-CPUs are wiped because the backplane is shared; the H-link cannot recover what was never saved.

Which battery part number is correct for the PS407?

Use the 6ES7971-0BA00 lithium back-up battery (3.6 V, 2.4 Ah, AA-size). The 6ES7407-0KR02 and 6ES7407-0RA02 dual-slot variants require two cells each. Do not substitute alkaline or NiMH cells – their discharge curve is incompatible with the supervisor and BAF will return within weeks.

How is the BAF fault read inside the S7-400 program?

The PS module signals the fault to the CPU over the backplane bus. The CPU calls OB81 (Power Supply / Battery Fault OB). Inside OB81, OB81_EX_FLT_ID = B#16#22 means the battery is exhausted, and OB81_MDL_ADDR gives the base address of the slot reporting the fault. Use the diagnostic buffer (DBA0 / DBA1) and the OB81 timestamps to log the event in WinCC.

Can the batteries be replaced while the CPU is in RUN?

Yes, on a single PS407 the holder allows hot-swap. The replacement must be completed in under 30 s per cell to stay within the PS module's capacitor hold-up; otherwise the CPU will go to STOP on the next scan with a buffer failure. On a CPU 414-4H, perform the swap during a planned H-system single-mode window, with the partner CPU carrying the process.

What is the role of the BATT INDIC switch on the PS407?

The switch selects which battery slot the front-panel supervisor is monitoring. In OFF, neither slot is checked and a depleted cell can go unnoticed. In 1 BATT slot 1 is supervised, in 2 BATT slot 2 is supervised. The recommended position during normal operation is 2 BATT on a dual-slot module so that both cells are actively supervised.

Back to blog