When configuring a fail-safe (F-) i-device safety network that couples two or more S7-1500F CPUs through PROFINET, TIA Portal V15 can refuse to compile the project and emit the message: Error during address synchronization of slot 1002 and slot 1003. Slot 1002 and slot 1003 are the PROFINET subslots of the first two F-CD (Fail-safe Communication Device) transfer areas on the i-device interface. The message indicates that TIA Portal cannot resolve overlapping input and acknowledgment ranges between the two slots. The error is documented in Siemens Support Entry 109771793 and is most commonly triggered when engineers manually edit the start addresses of F-CD transfer areas rather than letting TIA Portal auto-allocate them.
This article explains the root cause, the address arithmetic that governs F-CD slot allocation, and the field-proven step-by-step procedure to clear the error and recompile successfully on TIA Portal V15.0 Update 4 (and on V15.1, V16, and V17 in the same configuration).
Affected Hardware and Software Versions
| Component | Part Number / Version |
|---|---|
| TIA Portal project | V15.0 Update 4, V15.1, V16, V17 |
| F-CPU (i-device side) | 6ES7 512-1SK01-0AB0 (SIMATIC S7-1500F, CPU 1512F SP) |
| Interface Module | 6ES7 510-1SJ01-0AB0 (IM 155-6 PN HF, 4-port) |
| F-CPU (F-host side) | 6ES7 512-1SK01-0AB0 or compatible S7-1500F (6ES7 511/513/514/515/516) |
| PROFINET | PROFINET IO with PROFIsafe profile V2.4 or V2.6.1 |
| CPU firmware | Firmware ≥ V2.0 (required for F-CD i-device) |
Problem Description
During the compile step of a TIA Portal project containing an S7-1500F CPU configured as an i-device with F-CD transfer areas, the compiler aborts with:
Error during address synchronization of slot 1002 and slot 1003
Compile error (0916): The address areas of the F-CD transfer areas overlap and cannot be synchronized.
The error does not point to a specific F-block or instance DB; it is raised at the i-device PROFINET interface level. Slot 1002 and 1003 are the i-device subslot indices automatically assigned by TIA Portal to the first and second F-CD transfer areas. PROFINET subslot numbering on the i-device is fixed: subslot 0 is the device itself, subslot 1 is the PROFINET interface, subslots 2-999 are reserved for I/O modules on the i-device, subslot 1000 is the i-device communication relation, subslot 1001 is the F-parameter subslot, and F-CD transfer areas always start at subslot 1002.
Root Cause: F-CD Address Arithmetic
Each F-CD transfer area reserves a fixed memory layout starting at the configured start address:
| Region | Direction | Width | Description |
|---|---|---|---|
| Payload input | Inputs (I) | 12 bytes | F-process data read by the i-device CPU |
| Acknowledgment | Outputs (Q) | 6 bytes | Hidden F-host acknowledgment channel mapped at the same start address |
| Total reserved | — | ≥ 12 bytes | Slot N+1 start address must be ≥ slot N start + 12 |
The 6-byte acknowledgment range is a hidden Q-area that TIA Portal places at the same start address as the slot's I-area. Because the acknowledge channel is mapped into the lowest 6 bytes of the slot's address range, the next F-CD slot must start at least 12 bytes higher to avoid overlapping the input range of slot N+1 with the input bytes of slot N.
Concretely, if slot 1 is set to start address 2000 and slot 2 to 2010, the layout is:
| Slot | Start | End (I) | Ack Q-range | Conflict |
|---|---|---|---|---|
| Slot 1 (1002) | 2000 | 2011 | 2000-2005 | — |
| Slot 2 (1003, incorrect) | 2010 | 2021 | 2010-2015 | Bytes 2010-2011 collide with slot 1 input |
| Slot 2 (1003, correct) | 2012 | 2023 | 2012-2017 | No collision |
| Slot 2 (1003, generous) | 2018 | 2029 | 2018-2023 | 6-byte diagnostic headroom |
The arithmetic rule is therefore:
StartAddress(Slot N+1) ≥ StartAddress(Slot N) + 12
For diagnostic headroom, many engineers reserve 18 bytes between slots (12 bytes payload + 6 bytes acknowledge gap). When TIA Portal detects that the proposed slot N+1 start address falls within slot N's input range or acknowledgment range, it raises the address-synchronization error and refuses to compile.
Prerequisites
- TIA Portal V15.0 Update 4 (or later) installed and licensed for F-configuration.
- STEP 7 Safety Advanced (or F-safety bundle) installed.
- S7-1500F CPU on both the i-device and F-host sides, firmware ≥ V2.0.
- The i-device CPU configured with at least one F-CD transfer area under Devices & Networks → [CPU] → Properties → I-device Communication → Transfer areas.
- PROFIsafe source and destination addresses assigned on each F-CD (independent of the I/Q address ranges covered in this article).
- F-shared DB, F-FB, and F-FC blocks compiled without errors.
- Both the i-device and the F-host in the same TIA Portal project (mixed configuration with a GSD-imported i-device will not allow transfer-area edits).
Step-by-Step Resolution
Method 1 — Manual Address Realignment
- Open the project and select the i-device CPU in the project tree.
- Navigate to Devices & Networks → [i-device CPU] → Properties → I-device Communication → Transfer areas.
- Note the start address of the first F-CD transfer area (for example, 2372).
- Click the start-address field of the second F-CD slot and use the up/down arrow controls to nudge the address to a value that satisfies
Start(Slot 2) ≥ Start(Slot 1) + 12. With start 2372, the minimum valid slot-2 start is 2384; with a 6-byte acknowledge gap, 2378 is also acceptable. - Save the configuration.
- Open the F-host CPU in the project tree and mirror the same start addresses in Devices & Networks → [F-host CPU] → Properties → I-device communication (F-proxy).
- Right-click the i-device CPU → Compile → Hardware (rebuild all). The slot 1002/1003 error should be gone.
Method 2 — Recreate the First F-CD Line
If the address fields are greyed out, or the arrow control does not update, TIA Portal may be holding cached values from the previous compile:
- Open I-device → Transfer area overview.
- Select the first F-CD line.
- Click Delete.
- Re-insert a new F-CD transfer area. TIA Portal will auto-allocate non-overlapping addresses and the hidden acknowledge Q-range will be placed correctly.
- Repeat for any further F-CD lines.
- Recompile. No manual address arithmetic is required.
Method 3 — Reassign the F-host Acknowledgment
The F-host acknowledgment byte can also be remapped to a Q-area that lies outside the F-CD input ranges:
- Open the F-block (F-FB or F-FC) that owns the PROFIsafe communication.
- Open Properties → Safety → Acknowledgment (STEP 7 Safety).
- Change the acknowledgment output to a Q-byte that is not covered by any F-CD input range (for example, Q area 50 if all F-CDs live in 2000-2399).
- Save, compile, and re-check.
Verification
After applying one of the methods above, perform all four checks below before loading the project to the PLC.
- Compile check. Right-click the project → Compile all. No "address synchronization" error should appear. If a warning is raised on the F-host, repeat the same address mirror on the F-host side.
- Address report. In the i-device's Properties → I-device Communication, confirm each F-CD slot shows a 12-byte input range and that the next slot starts at least 12 bytes higher.
- Online diagnostics. Download the configuration, go online, and inspect the i-device's Diagnostics → PROFINET interface → F-CD status. Both slots should report Operational.
- PROFIsafe functional test. Trigger a stop on the F-host. The F-i-device should enter safe state within the configured PROFIsafe watchdog time (default 1500 ms, configurable under Properties → F-parameters → PROFIsafe).
Troubleshooting Matrix
| Symptom | Likely Cause | Corrective Action |
|---|---|---|
| Error persists after realignment | Old addresses cached in transfer area overview | Use Method 2 (recreate the F-CD line) |
| Slots 1002/1003 missing in error message | i-device not configured for F-CD | Enable F-CD in Properties → I-device → F-communication |
| F-host side also red | Mismatched start addresses between i-device and F-host | Mirror addresses on both sides |
| Acknowledge byte collides with F-shared DB | Acknowledge mapped into a DB input range | Reassign acknowledgment to a free Q-byte outside the F-CD ranges (Method 3) |
| Compile OK online, but i-device stays in "Not commissioned" | Start address on i-device CPU differs from F-host CPU | Cross-check with online Monitor/Modify |
| Error reappears after firmware update on the F-CPU | New FW stricter on F-CD address rules | Update to current FW, then re-do Method 1 |
| Compile error on slot 1004/1005 (third + fourth slot) | Cascade: error in slot 2 propagates upward | Fix slots 1+2 first; rest auto-align |
| Compile passes locally but fails on partner station download | PROFIsafe F-destination address duplicated network-wide | Reassign F-destination address under F-parameters |
Background: F-CD i-Device Mechanism
The F-CD (Fail-safe Communication Device) i-device function is defined in the PROFIsafe profile V2.4 and V2.6.1, both available on S7-1500F CPUs. It allows an S7-1500F to act as a PROFINET device that publishes safety-relevant data to a higher-level F-host CPU. The communication uses standard PROFINET IO with a PROFIsafe wrapper on the payload. From the F-host's perspective, the F-CD behaves like a distributed F-I/O module, but from the i-device's perspective, the F-CD is a logical interface that exposes preprocessed F-tags to the F-host.
Each F-CD is identified on the wire by two addresses that are independent of the I/Q address ranges discussed above:
- F-source address (F-quell-adresse): a unique 1-byte to 5-byte value assigned on the i-device side. Must be unique network-wide.
- F-destination address (F-ziel-adresse): a unique 1-byte to 5-byte value assigned on the F-host side. Must be unique network-wide.
The I/Q start address discussed in this article is the local memory map that TIA Portal generates for the F-runtime group to read the F-process data. It is not transmitted on the wire; only the PROFIsafe-wrapped payload crosses the network. This is why a start-address overlap can compile-fail on TIA Portal without ever manifesting as a wire-level error.
Common Configuration Mistakes
- Using HMI tags that alias F-CD input bytes. TIA Portal flags this as a read-only conflict on the F-tag and may surface a synchronization warning.
- Importing the i-device from a GSD file rather than from the project tree. In GSD-imported i-devices, the transfer areas are read-only; use a project-tree i-device to enable Method 2.
- Manually editing F-source/F-destination addresses while leaving I/Q start addresses at their defaults. The two are independent, but engineers frequently conflate them.
- Forgetting to enable F-communication in the i-device CPU properties. Without this checkbox, TIA Portal silently drops F-CD slots and surfaces a generic "no F-communication configured" error instead of the address-sync error.
- Not mirroring start addresses on the F-host side. The F-host's F-proxy must agree on the start address, otherwise the F-proxy is greyed out and the compile fails on the F-host CPU.
- Modifying the F-CD start address on only the i-device side after the F-host project has already been compiled. The F-host's compiled F-proxy will hold a stale start address and re-trigger the error.
PROFIsafe Watchdog Timing
The PROFIsafe watchdog time is the maximum interval the F-host waits for a fresh PROFIsafe frame before declaring the i-device failed. The default in TIA Portal is 1500 ms, which is appropriate for PROFINET update times of 1 ms. The recommended minimum is:
Watchdog ≥ 2 × PROFINET_Update_Time + jitter_tolerance
For typical values:
| PROFINET Update Time | Minimum Watchdog | Siemens Default |
|---|---|---|
| 1 ms | 2 ms + 1500 ms = 1502 ms | 1500 ms |
| 2 ms | 4 ms + 1500 ms = 1504 ms | 1500 ms |
| 4 ms | 8 ms + 1500 ms = 1508 ms | 1500 ms |
| 8 ms | 16 ms + 1500 ms = 1516 ms | 1500 ms |
The watchdog time is configured under Properties → F-parameters → PROFIsafe → Watchdog time on each F-CD. The address-synchronization error does not affect the watchdog timer, but if the F-CD is not commissioned (e.g., start-address mismatch between i-device and F-host), the F-host will time out and drop the F-i-device into safe state.
Edge Cases and Field-Proven Caveats
- Shared device: If the F-CPU is connected to a shared PROFINET with multiple controllers, each controller must have its own F-CD range. Overlapping ranges between two controllers will produce the same synchronization error.
- GSD import: Reducing the F-CD input width via a custom GSD is not supported on S7-1500F. The 12-byte payload is a fixed profile value.
- HMI access: HMI panels reading F-tags via the i-device should use read-only tags. F-tags are read-only on the HMI side by design; writing to them from HMI will raise a safety violation rather than a synchronization error.
- OPC UA exposure: Do not expose F-tags via the integrated OPC UA server of the F-CPU. Use a non-F-CPU bridge (e.g., a separate S7-1500 with OPC UA server) to publish non-safety aggregates.
- TIA V15.0 base install: On TIA Portal V15.0 (no update), the synchronization error may appear even with non-overlapping addresses due to a known bug. Apply Update 4 or later to clear it.
- Address caching: If you change an F-CD start address and recompile, but the F-host CPU's compiled F-proxy holds the old address, the F-host will flag a "F-proxy out of date" warning. Re-compile the F-host CPU after any i-device change.
Migration and Multi-CPU Considerations
Engineers migrating from S7-300F / S7-400F to S7-1500F often run into the address-synchronization error for the first time because the F-CD i-device function did not exist on the older platforms. S7-300F/400F used F-FB/DB-based F-communication (F_SENDBO / F_RCVBO) on PROFIBUS, while S7-1500F uses the F-CD i-device on PROFINET. The address model is entirely different: F_SENDBO/F_RCVBO mapped the safety data to a user-defined DB, while F-CD maps it to fixed I/Q areas. When migrating, do not attempt to translate the DB-based addresses into F-CD start addresses. Instead, start from a clean F-CD configuration and re-do the I/Q allocation using the 12-byte spacing rule described above.
For multi-CPU F-host configurations (one F-host with several i-devices), the F-host's F-runtime group must be large enough to scan all F-CDs within the watchdog. With 4 F-CDs at 1 ms PROFINET update, the F-host's F-cycle time should be ≤ 4 ms to leave 1496 ms of watchdog headroom. The F-CD address-synchronization error on the F-host side can also be triggered by overlapping F-proxy ranges; the same 12-byte rule applies.
FAQ
What does slot 1002 / 1003 mean in the error message?
These are the PROFINET subslot indices of the F-CD transfer areas on the i-device interface. Slot 1002 is the first F-CD, slot 1003 the second. The error means the address ranges of these two subslots overlap and TIA Portal cannot synchronize them.
Why are the F-CD input and acknowledge areas tied to the same start address?
The F-CD profile uses the first 6 bytes of the configured input range as the PROFIsafe acknowledgment channel back to the F-host, while the full 12 bytes carry the safety I/O payload. Because both share the start address, the acknowledge area of slot N can collide with the input area of slot N+1 if start addresses are too close.
What is the minimum gap between two F-CD start addresses?
12 bytes. Slot N+1 start address must be at least Slot N start address + 12. For a clean layout, leave exactly 12 bytes of separation; for diagnostic headroom, 18 bytes (12 bytes of payload + 6 bytes acknowledge gap) is common.
Does this error apply to S7-1200F i-devices as well?
No. The F-CD i-device function with the 12-byte/6-byte acknowledge layout is specific to S7-1500F CPUs. S7-1200F controllers do not support F-CD i-device communication and must use F-CPU-to-F-CPU communication via PUT/GET or open safety communication over PN/PN coupler instead.
Will upgrading TIA Portal to V16 or V17 eliminate the error?
Upgrading does not remove the root cause (overlapping start addresses), but later versions sometimes auto-correct minor overlaps and produce a warning rather than a hard error. The robust fix is still to space the F-CD start addresses by 12 bytes or more, as described in the procedure above.