Symptom Profile and Field Configuration
A redundant pair of SIMATIC S7-300 PLCs has been deployed with two CPU 313C-2 DP units (MLFBs typically 6ES7 313-6CF04-0AB0, 6ES7 313-6CF14-0AB0, 6ES7 313-6CG04-0AB0, or 6ES7 313-6CG14-0AB0), both configured through the SIMATIC S7-300 Software Redundancy (SWR) library. After energising the cabinet, one of the two CPUs (CPU2) fails to enter RUN. The reported front-panel indication on CPU2 is:
- SF (System Fault) — RED, solid ON
- BF (Bus Fault, PROFIBUS DP) — RED, flashing at ~1 Hz
- MAINT — OFF
- DC 5V — GREEN, solid ON
- FRCE — OFF
- RUN — OFF
- STOP — ORANGE/YELLOW, solid ON
The downstream ET 200M station connected to the shared (or paired) PROFIBUS DP segment of CPU2 reports simultaneously:
- SF — RED, flashing
- BF1 — RED, flashing
- BF2 — RED, flashing
- ACT — ORANGE, flashing
- ON — GREEN, flashing
The combined signature — solid STOP+SF+BF-flashing on CPU2 with every fault indicator flashing on the IM 153 — is a textbook reading of a CPU that has been unable to complete startup or maintain its PROFIBUS master role and has been forced to STOP by its own diagnostics. The downstream IM 153 has lost its logical DP master, which is the expected downstream behaviour when its assigned master drops.
CPU 313C-2 DP LED Reference
The following table summarises the front-panel LED meanings on a CPU 313C-2 DP (6ES7 313-6xx04-0AB0 and 6ES7 313-6xx14-0AB0 families). It maps the standard Siemens notation to operating-state behaviour.
| LED | Colour | State | Meaning |
|---|---|---|---|
| SF | RED | Off | No system fault detected |
| Solid ON | Hardware, firmware, or user-program error recognised; CPU has gone to STOP | ||
| BF | RED | Off | PROFIBUS DP interface is error-free |
| Solid ON | Physical PROFIBUS DP fault (wire break, baud-rate detection failure) | ||
| Flashing | DP slave not reachable on bus; configuration mismatch; bus-power error | ||
| MAINT | YELLOW | Solid | Maintenance event pending (rarely used on S7-300) |
| Flashing | Maintenance demanded | ||
| DC 5V | GREEN | Off | Internal 5 V supply absent or out of tolerance |
| Solid ON | Backplane 24 V and internal 5 V within range | ||
| FRCE | YELLOW | Off | No force job active |
| Solid ON | At least one I/O point is forced in the user program | ||
| RUN | GREEN | Solid ON | CPU is in RUN executing OB1 |
| Flashing (2 Hz) | CPU is in startup (OB 100 warm restart) | ||
| Off | CPU is not in RUN | ||
| STOP | ORANGE/YELLOW | Solid ON | CPU is in STOP mode |
| Flashing (~1 Hz) | CPU requests memory reset (MRES) |
Reading SF=solid, BF=flashing, STOP=solid, RUN=off, DC5V=on against the table narrows the cause to one of three families — a PROFIBUS DP master-side failure detected during startup, a required OB missing or in error, or a configuration / SD-card checksum error. The DC 5V LED being GREEN rules out the internal 5 V rail and the 24 V backplane. The MAINT LED OFF rules out maintenance-diagnostic interventions. FRCE=OFF rules out a forced I/O lockup. The remaining candidates all relate either to the PROFIBUS DP segment or to the SWR sync link.
ET 200M IM 153 LED Reference
The ET 200M in question uses either IM 153-1 (single PROFIBUS interface, MLFB 6ES7 153-1AA03-0XB0 or later) or IM 153-2 (dual PROFIBUS interface for redundant masters, MLFB 6ES7 153-2AB02-0XB0 or later). The presence of BF2 in the panel reading confirms an IM 153-2 dual-port device.
| LED | Colour | State | Meaning (IM 153-1 and IM 153-2) |
|---|---|---|---|
| SF | RED | Off | No group fault pending |
| Solid ON | Configured module missing or in group/diagnostic fault | ||
| Flashing | At least one module reports channel-level diagnostics or cannot be reached | ||
| BF1 | RED | Off | DP1 segment healthy |
| Solid ON | Physical-layer fault on DP1 (cable, termination, baud detection) | ||
| Flashing | DP1 slaves cannot reach this master, or configuration mismatch | ||
| BF2 | RED | Off | DP2 segment healthy |
| Solid ON | Physical fault on DP2 | ||
| Flashing | DP2 slaves cannot reach this master (IM 153-2 only) | ||
| ACT | YELLOW | Off | Passive role: back-up IM |
| Solid ON | Active role: this IM is currently serving as primary on its segment | ||
| Flashing | Switch-over in progress between the two IM instances, or AR lost | ||
| ON | GREEN | Off | No 24 V supply at the IM |
| Solid or flashing | 24 V supply present at the IM power terminals |
A reading of SF+BF1+BF2=flashing, ACT=flashing, ON=flashing on an IM 153-2 indicates that the IM is powered (ON flashes during AR negotiation by firmware design) but cannot complete arbitration with either master — typical when both CPU sides are at fault, when the DP segment from CPU2 was disconnected at the time of switch-over, or when the SWR sync link between the two CPUs is broken. The combination rules out a single-segment incident and points instead to a fault affecting both masters simultaneously — a configuration the IM recognises as a complete loss of arbitration partner.
Probable Root Causes Ranked by Probability
The following matrix lists the most common root causes observed for this front-panel combination, ranked by frequency across the entire S7-300 installed base. Each row ties the diagnostic-buffer evidence to a concrete first-remedy on site.
| Rank | Cause | Likelihood | Diagnostic evidence | First fix attempt |
|---|---|---|---|---|
| 1 | PROFIBUS segment between CPU2 and ET 200M physically broken or disconnected | High | BF flashing on CPU2 + BF1/BF2 flashing on IM 153; diagnostic-buffer event 0x0A41 (DP slave failure) | Discharge ESD; inspect D-sub backshells; reseat; check 9-pin in/out segment |
| 2 | Termination resistor missing or duplicated on the DP segment | High | BF solid or flashing on multiple slaves; oscilloscope on line shows reflections | Verify exactly two terminators at the end nodes, both enabled; expect 220 Ω series with 390 Ω pull-up/pull-down |
| 3 | DP master address conflict or slave address conflict | Medium | BF flash on IM 153 only; one CPU stays in RUN, the other in STOP | Read addresses via PG/MPI; ensure each IM 153 has a unique slave address different from master addresses 1 and 2 |
| 4 | IM 153 firmware too old for CPU 313C-2 DP firmware after engineering reload | Medium | SF solid on CPU2; diagnostic buffer 0x2712 indicating DPV1/DPV2 protocol mismatch | Compare IM 153 firmware against the GSD revision loaded by HW Config |
| 5 | Required OBs (OB 82, OB 86, OB 87, OB 100, OB 102, OB 121, OB 122) missing from CPU2 program | Medium | CPU in STOP; diagnostic buffer 0x2520 ("OB not loaded") | Insert all SWR-required OBs; recompile; reload with matching checksums |
| 6 | CPU2 PROFIBUS DP master interface hardware fault | Low | BF solid after substituting cable; buffer shows time-out to all DP slaves even with known-good bench slaves | Replace CPU2 with the same MLFB; restore project; verify SWR re-pairing |
| 7 | IM 153-2 module failure | Low | BF+SF on IM 153 with healthy inputs from both CPU sides | Replace IM 153 with the same MLFB and firmware revision |
| 8 | S7-300 connection-resource exhaustion | Low | CPU goes STOP a few hours after energise with 0x0050 / 0x005C / 0x0070 in buffer; PG/OP connections all used | Free PG/OP/HMI connections; check Communication tab of the module info |
| 9 | Mix of master and standby firmware versions in the SWR pair | Low | CPU2 in STOP right after power-on; buffer 0x0188 / 0x0189 firmware mismatch | Update both CPU 313C-2 DP to identical firmware level |
All nine above reproduce the observed LED combination; the order is empirical and shifts on any specific site depending on cabinet age, vibration exposure, and connection-resource budget. The diagnostic flowchart below ties the most likely causes to ordered actions.
Software Redundancy (SWR) Architecture Implications
Two CPU 313C-2 DP units running S7-300 Software Redundancy form a one-master/one-standby pair. The SWR library is installed into the STEP 7 catalog; the standard calls include SWR_START, SWR_DIAG, SWR_ZYK, and SWR_SYC, instantiated through their FBs in OB 1, OB 100, OB 86, and OB 87. Their work and instance DBs (DB 101..DB 104 or higher, project-specific) hold the data image that the standby keeps aligned with the master. The pattern of LEDs after energise reveals the operating state:
- If only one CPU is in RUN and the other is in STOP without SF or BF, this is the standby in normal quiescent state.
- If the standby CPU is in STOP with SF/BF, the SWR pair has not been able to form, because the standby is signalling an I/O or sync fault that prevents it from entering the SWR ready-to-takeover state.
- If both CPUs are in STOP after energise, SWR has failed on both halves and the application is not running anywhere.
The fact that only CPU2 is in the abnormal state confirms that CPU1 is the active master. CPU2 should normally either be a passive standby with no fault LEDs or be carrying its own dedicated segment with the IM 153 reporting clean. In SWR, the sync channel is typically MPI between the two CPUs (a dedicated cable with two 9-pin D-sub connectors, terminators OFF) or an Ethernet pair on the integrated PN interface (CPU 313C-2 PN/DP variant). If the sync link between CPU1 and CPU2 is broken, both CPUs independently treat each other as missing; each one attempts to start as master and may go to STOP once the application is rebuilt and a duplicate master role is detected.
STEP 7 Diagnostic Buffer Extraction Procedure
Open STEP 7 V5.x and reach the diagnostic buffer. The buffer is the only authoritative source for the cause of the STOP transition; it stores a chronological ring of hex-coded events with timestamps and OB references.
- Connect the PG to the surviving CPU (CPU1) over MPI/PROFIBUS adapter, e.g. PC Adapter USB 6GK1 571-1AA00-1AA0, with the PG/PC interface set to PC Adapter (MPI) or PC Adapter (PROFIBUS).
- In SIMATIC Manager select PLC > Accessible Nodes and locate both CPU 313C-2 DP nodes. CPU1 shows the master status; CPU2 should also respond, even in STOP.
- Right-click CPU2 > PLC > Module Information.
- Open the Diagnostic Buffer tab. Set the filter to Errors and Events only.
- Scroll to the bottom (most recent events). Expand each entry by clicking Detail — Siemens stores the full event, secondary event, and informational event in the same record.
- Click the Save As… button on the toolbar; export the entire buffer to
*.txt. Repeat for CPU1. - Open the text exports in a text editor and search for the following hex event codes first.
| Event ID (hex) | Class | Meaning | First-response action |
|---|---|---|---|
| 0x0A41 | Communication | DP slave failure / DP master cannot reach slave | Check the slave listed in the buffer for cabling and power |
| 0x0A81 | Communication | DP slave diagnostic mismatch | Read the slave identifier and read the slot diagnostic |
| 0x0110 | CPU | CPU went to STOP because of stop cause | Note the Initiator field; follow the secondary event |
| 0x0155 | CPU | STOP due to stop cause — OB stop | OB has error; reload the affected OB |
| 0x0188 / 0x0189 | CPU | Firmware mismatch on CPU pair | Restore matching firmware via online update |
| 0x2520 | CPU | OB missing (e.g. OB 82, OB 86, OB 87) | Insert all SWR-mandatory OBs and reload |
| 0x2712 | DP | DPV1/DPV2 protocol mismatch | Replace IM 153 firmware with one matching the GSD |
| 0x39xx | Module | Module pulled/plugged or diagnostic pending | Verify module seating; reseat if recent maintenance |
| 0x494C | SWR | SWR partner not found / sync link down | Check MPI cable and SWR partner address between CPU1 and CPU2 |
| 0x0050 / 0x005C / 0x0070 | Communication | Connection resource exhausted | Free PG/OP connections; check Communication tab in module info |
The full dictionary of error messages returned at the STATUS outputs of instructions is published in the Siemens documentation "Error messages S7-300, S7-400": Error messages S7-300, S7-400 — Siemens documentation portal. Cross-reference any STATUS hex code returned by an instruction against this list before declaring the CPU hardware at fault.
PROFIBUS Physical Layer Verification Procedure
Once the diagnostic buffer confirms a DP-bus cause (event ID 0x0A41 or similar), verify the physical layer top-down — segment, connectors, terminators, shield, and slave power.
- Disconnect power and de-energise the segment.
- Confirm cable shield continuity end-to-end; shields are bonded at both ends through clamps.
- Confirm the topology is bus (line), not star. Repeaters off the trunk form a chain only up to the manufacturer specification for the relevant IM 153 firmware generation.
- Verify termination: exactly two terminators across the segment, both ON, located at the two physical ends of the trunk. On SIMATIC PROFIBUS connectors the terminator slides into one of three positions: ON, OFF, or "RC" branch. Leaving a middle-node terminator ON is the single most common cause of intermittent DP faults.
- Measure the voltage between pins 3 and 8 (the data lines) at each end. With both ends terminated and the master powered but no other traffic, the voltage is approximately 1.1 V (logic "1" level 5 V idle on the bus); an open end reads ≈5 V DC; a shorted end reads ≈0.4 V.
- Measure the bus termination resistance across pins 3 and 8 with master and slaves powered off; expect 220 Ω in series with each parallel 390 Ω pull-up/pull-down at the two end nodes (a Thévenin equivalent of ≈110 Ω).
- Replace the connector at the trouble device first; bent pins 3 and 8 are common in cabinet-shifted hardware.
- Re-energise and observe BF. The flashing BF transitions to OFF or SOLID as the physical layer is repaired; only a configuration mismatch continues a flashing BF.
Configuration and GSD Verification
If the physical layer verifies cleanly but the diagnostic buffer still shows DP-slave failure, the next surface is the HW Config. A configuration drift after a memory-card replacement is a frequent root cause.
- Open HW Config for the SWR station in STEP 7 V5.x.
- Compare the IM 153 MLFB and order number against the GSD catalog. Right-click the IM and re-select the precise article number. For an S7-300 SWR installation both CPU 313C-2 DP MLFBs must match exactly: different firmware suffix letters (e.g.
-6CF04versus-6CF14) are not interchangeable in HW Config without warning. - Check the PROFIBUS address of each IM. SWR-pair CPUs are typically master address 1 (CPU1) and 2 (CPU2), each with slaves on unique addresses; no slave can share an address with another on the same segment.
- Verify the slots for digital input/output modules: missing slots cause CPU startup delay and, with required OBs absent, force a STOP.
- Compile and download to CPU2 with CPU > Download to Target System; select Reset if HW Config does not yet match the CPU.
- Cross-check that the GSD file revision loaded into HW Config is at least as high as the IM 153 firmware revision actually installed on the field device (read with PG/MPI).
Connection Resources and PG Adapter Limits
Older S7-300 CPUs have a hard connection-resource budget. The CPU 313C-2 DP family is constrained to small fixed numbers; SWR itself consumes four connections per direction, plus one connection to each HMI panel and one PG connection for commissioning. With low FW and several HMIs the budget is exceeded easily. Older S7-300 processors provide a connection-resources view under Online > Module Information > Communication; read this view for the live count.
| CPU | FW level | PG/OP resources | S7/HMI resources | Total OP / PG / S7 |
|---|---|---|---|---|
| CPU 313C-2 DP | V2.x | 2 | 4 | 6 |
| CPU 313C-2 DP | V3.x | 4 | 6 | 10 |
| CPU 314C-2 DP | V3.x | 4 | 8 | 12 |
| CPU 315-2 DP | V3.x | 4 | 10 | 14 |
| CPU 316-2 DP | V3.x | 8 | 14 | 22 |
Persistent resource codes 0x0050, 0x005C, or 0x0070 in the diagnostic buffer confirm a resource-limit event; the recovery is to close any opened Online windows in STEP 7 (each PG window locks a connection) and to verify that the HMI panel is still talking and not holding orphan sockets.
Corrective Action Matrix
| Buffered cause | LED signature before | LED signature after fix | Corrective action |
|---|---|---|---|
| Broken PROFIBUS cable to IM 153 | CPU BF flashing + IM SF/BF1/BF2 flashing | CPU BF OFF, IM SF OFF, BF1/BF2 OFF, ACT ON | Re-lay cable; replace D-sub backshell; re-terminate |
| Duplicated terminator on middle node | CPU BF flashing, IM BF flashing | CPU BF OFF, IM BF1/BF2 OFF | Disable middle-node terminators via slider |
| Missing or unsupported OB | CPU STOP + SF solid, BF off when no DP | RUN after OB load + reload | Insert OB 82, OB 86, OB 87, OB 100, OB 102, OB 121, OB 122; recompile |
| Slave address conflict | CPU BF flashing, IM BF flashing on affected IM only | BF OFF after re-address | Set unique PROFIBUS addresses via PG |
| GSD / IM 153 firmware mismatch | SF solid CPU, BF flashing IM | BF OFF after IM FW update | Update IM 153 to GSD-required firmware via FW update tool |
| SWR partner not found | CPU2 STOP + SF solid | CPU2 ready after sync link restored | Restore MPI or PN cable between CPU1 and CPU2; confirm partner address |
| Connection-resource exhaustion | CPU2 STOP appearing after PG sessions | CPU2 stays RUN once orphan sockets cleared | Re-init online sessions; reduce HMI / OPC connections |
| CPU 313C-2 DP interface hardware fault | CPU BF solid even with bench-only slaves | BF OFF after CPU swap | Replace CPU with the same MLFB; restore SWR pair via STEP 7 |
Re-commissioning and Verification Checklist
- Connect STEP 7 to CPU1 (the surviving master). Read its diagnostic buffer; confirm SWR is stable.
- Power down CPU2. Disconnect the DP connectors, look for bent pins or backshell strain.
- Power up CPU2 only. Observe LED transition: BF flashing → OFF, MAINT OFF, FRCE OFF, STOP solid (expected — CPU2 in solo STOP is its cold state).
- With STEP 7 connected to CPU2, reset and download the SWR project. Wait for the buffer to clear ERROR entries.
- Add CPU1 to the partner list under SWR configuration; both CPUs should now reflect SWR ready states, with one CPU in RUN and the other in STOP without fault LEDs.
- On the ET 200M, confirm SF OFF, BF1/BF2 OFF, ACT ON (if dual-port), ON solid.
- Trigger a manual failover from STEP 7 (SWR > Start Switchover). The roles must swap cleanly without SF/BF on the side taking over.
- After a successful failover, repeat SWR switchover three times to validate that the SWR library has received its inputs correctly.
Preventive Hardening and Spares Strategy
Recurrence of this exact combination is reduced through a small set of lifecycle measures:
- Spare CPU 313C-2 DP at the cabinet: one MLFB-aligned unit with the firmware pre-loaded to the field level, ready for cold replacement.
- Spare IM 153-2 at the cabinet with the same MLFB generation and firmware revision.
- Pre-terminated spare PROFIBUS cable assemblies (5 m, 10 m, 15 m) with shielded D-sub end-shells.
- PG/PC adapter cable (e.g. 6GK1 571-1AA00) on the operator desk, with the PG/PC interface preset to PC Adapter (MPI) and the binding to CPU1.
- Diagnostic buffer exports archived daily to a versioned STEP 7 project directory.
- Connection-resource budget tracked in the project documentation; reserve at least two OP/PG resources for commissioning.
- Annual PROFIBUS physical-layer audit (resistance check, terminator survey, shield-clamp tightening).
For broader control-system standards and PROFIBUS DP reference material, refer to the Siemens Industry Online Support pages and the IEC 61158 / EN 50170 PROFIBUS standards.
FAQ
Why does CPU2 show STOP with SF solid and BF flashing simultaneously?
This is a CPU-detected fault that forced the transition to STOP. SF means a system fault is pending in the diagnostic buffer; BF means the PROFIBUS DP interface can no longer reach at least one slave. The combination is typical of a CPU that has had to drop to STOP because of an I/O subsystem (DP) error and that does not have the OBs (e.g. OB 82, OB 86) installed to mask the failure. Read the diagnostic buffer, check for events 0x2520 (OB missing), 0x0A41 (slave failure), or 0x0110 (STOP cause), and start your physical-layer check from the PROFIBUS segment rather than swapping the CPU.
Can Software Redundancy survive a PROFIBUS master failure on one CPU?
Yes, but only if the SWR library is properly configured and the sync link between CPU1 and CPU2 is intact. On failover the standby CPU takes over with its own master role and outputs are re-asserted from the work-DB mirror. The sync link is typically MPI or industrial Ethernet; if this link is broken, both CPUs may treat each other as missing and the application may stop completely on both sides. Always check the SWR partner address, sync cable, and the SWR library block calls in OB 1, OB 100, OB 86, and OB 87 first.
How do I read S7-300 diagnostic-buffer entries offline without STEP 7?
You cannot read the diagnostic buffer offline; it exists only in the live CPU's RAM. Connect STEP 7 V5.x with a PC Adapter over MPI/PROFIBUS and open PLC > Module Information > Diagnostic Buffer. Use Save As… to export the full buffer as plain text and document every error event before changing hardware. If TIA Portal is used, the path is Online > Online & Diagnostics > Diagnostic Buffer; note that TIA Portal V16 and later may not fully support CPU 313C-2 DP troubleshooting, and STEP 7 Classic remains the official tool for the CPU 31xC family.
Are PROFIBUS connectors required to have termination resistors installed?
Only the two devices at the physical ends of the trunk require terminators; any termination in the middle must be OFF. The SIMATIC PROFIBUS connector slider has three positions (ON, OFF, RC): the RC position routes the bus through and drops the terminator from the secondary stub. Verify which devices sit at the segment ends and ensure their connectors are set to ON, with backshell strain-relief properly applied.
When does the standby CPU in SWR come out of STOP?
The standby CPU remains in STOP as long as the master CPU is in RUN and the sync link is healthy. It auto-transitions to RUN only when it takes over the master role after a failover or after the engineer issues a forced switchover via SWR > SWR Switchover in the project. While in passive standby with no faults, SF / BF are OFF, MAINT is OFF, STOP is solid, RUN is OFF, DC5V is solid GREEN; any other combination indicates a fault on the standby side.