Resolving PROFIsafe Address Assignment Failure on ET 200SP F-IO (6ES7155-6AU02-0BN0)
1. Problem Overview
Engineers integrating fail-safe I/O into a SIMATIC ET 200SP distributed I/O station frequently encounter a configuration deadlock in which the PROFINET interface module accepts the F-CPU assignment but refuses to accept the PROFIsafe F-destination address. The symptom is reproducible across TIA Portal V18 and V19: the safety module is visible in the device view, the F-CPU has been assigned as the PROFIsafe proxy, and yet the Assign PROFIsafe address function either does not appear, returns a greyed-out menu, or completes without writing a valid address to the module.
The reference part number for the interface module in this scenario is:
- 6ES7155-6AU02-0BN0 — IM 155-6 PN HF (ET 200SP PROFINET interface module, high feature, type 3)
Downgrading the module firmware to a previous major release does not resolve the issue. The underlying cause is a tooling gap, not a firmware defect. The fix is to align the engineering environment with the firmware generation that matches the device version of the IM 155-6 PN HF.
2. Affected Hardware and Software Matrix
| Component | Catalog Number | Relevant Versions |
|---|---|---|
| IM 155-6 PN HF (Type 3) | 6ES7155-6AU02-0BN0 | Firmware V6.0 / V6.1 / V6.2 |
| TIA Portal | 6ES7822-1A.. | V18, V19, V20 (project dependent) |
| SIMATIC S7-FCT | 6ES7810-4CC10-0YA7 (or higher) | Version aligned to F-CPU firmware |
| HSP (Hardware Support Package) | Siemens Support download | HSP for TIA V19, includes V6.2 firmware entry |
| ET 200SP F-modules (examples) | 6ES7136-6BA00-0CA0, 6ES7136-6DB00-0CA0 | Must match HSP/V19 catalog |
3. Root Cause Analysis
The PROFIsafe address assignment workflow depends on three converging factors:
- Device version registration — TIA Portal must know the exact article number and firmware version of the IM 155-6 PN HF. The PROFINET interface module 6ES7155-6AU02-0BN0 ships in multiple firmware generations; the latest (V6.2) is not natively recognized in TIA Portal V18 and requires an HSP upgrade in V19 to be selectable from the hardware catalog.
- Configuration channel selection — Projects created from a GSD file (third-party controller or non-Siemens master) require the S7-FCT tool to write the F-destination address. Projects created from the TIA Portal hardware catalog allow direct assignment through the Assign F-destination address shortcut menu.
- PLC assignment — The F-IO cannot be safety-bound until a F-CPU has been assigned as the PROFIsafe proxy in the same PROFINET subnet. Without this link, the safety slot is decoupled and the address assignment option is hidden.
The typical failure chain is therefore:
4. Solution Path 1 — Install the Hardware Support Package (HSP)
The recommended first-line fix is to bring the TIA Portal hardware catalog up to date so the IM 155-6 PN HF device version (with V6.2 firmware) is selectable.
4.1 Prerequisites
- TIA Portal V19 installed and licensed.
- Administrator rights on the engineering station (HSP installation modifies the catalog database).
- Active Siemens Support account with access to the HSP download area.
4.2 Step-by-step
- Open TIA Portal V19 and select Options → Support Packages → Install.
- Download the latest HSP for TIA Portal V19 from the Siemens Industry Online Support portal. The HSP package name typically follows the convention
HSP_TIA_V19_<build>. - Close all open TIA Portal projects before installing the HSP. The installer requires an exclusive lock on the catalog files.
- Restart TIA Portal. The new device versions become available under Add new device → Controllers/HMI/PC systems → ET 200SP → Interface modules → PROFINET.
- Verify the article number
6ES7155-6AU02-0BN0now shows firmware version V6.2 in the Device overview → Properties → General tab. - Reinsert the IM 155-6 PN HF into the project from the catalog. Do not use the GSD file path; use the catalog entry to ensure PROFIsafe parameters are exposed correctly.
- Add the F-modules from the catalog and assign the F-CPU as PROFIsafe proxy.
- Right-click the IM 155-6 PN HF in the network view → Assign F-destination address.
For the official Siemens documentation on the assign F-destination-address workflow in the network view, refer to the Step 8: Assign PROFIsafe addresses procedure in the SIMATIC S7-1500/ET 200MP manual collection.
5. Solution Path 2 — SIMATIC S7-Fail-safe Configuration Tool (S7-FCT)
If the project is built around a third-party PROFINET controller (e.g., Allen-Bradley ControlLogix, Beckhoff TwinCAT, B&R Automation, Wago PFC, Schneider M580 with PROFINET scanner) or any scenario that requires importing the ET 200SP via GSD/GSDML rather than the TIA Portal catalog, the PROFIsafe address cannot be assigned from TIA Portal directly. The F-destination address is not part of the standard PROFINET record set that the GSD exposes.
Siemens provides the SIMATIC S7-Fail-safe Configuration Tool (S7-FCT) as the dedicated utility for this scenario.
5.1 S7-FCT scope
- Assigns the PROFIsafe F-destination address to the F-module.
- Reads the assigned address back for verification.
- Operates in conjunction with the PROFIsafe address switch (DIL switch) on the F-module for fail-safe modules in ET 200pro and selected ET 200SP variants. Refer to Assignment of PROFIsafe Address for the addressing switch conventions.
5.2 Procedure
- Install S7-FCT on the engineering station. The tool is licensed separately under catalog number
6ES7810-4CC10-0YA7(or its successor). - Import the ET 200SP station from the GSD file: File → Open → GSD project.
- Select the F-module slot and open PROFIsafe → Assign address.
- S7-FCT writes the F-destination address over the PROFINET connection to the device, bypassing the catalog-driven dialog of TIA Portal.
- Save the project and verify the address on the device display or via the F-diagnostic buffer.
SF: PROFIsafe address mismatch at the F-CPU.
6. Solution Path 3 — TIA Portal Catalog Configuration (Native Siemens Topology)
For pure Siemens topologies (S7-1500 F-CPU as the PROFINET IO controller), the cleanest path is to abandon GSD and use the catalog entry.
6.1 Step-by-step
- Confirm the F-CPU is added to the project and connected to the same PROFINET subnet as the IM 155-6 PN HF.
- Assign the F-CPU as the IO controller of the ET 200SP station: right-click the F-CPU → Assign IO controller if using a separate IO device, or simply insert the ET 200SP station under the F-CPU's PROFINET interface in the network view.
- Add the F-modules from the catalog (not from GSD). Verify the F-modules have a yellow safety indicator in the device view.
- Compile the project. During compilation, TIA Portal performs consistency checks on the safety configuration. Resolve any errors in the Messages pane before proceeding.
- Select the ET 200SP station in the network view and right-click → Assign F-destination address.
- In the dialog, choose the Identification method: either by LED flash on the device or by serial number / PROFINET device number.
- Confirm the address assignment. The F-destination address is now written to the F-module and the safety program can reference it.
7. Detailed Step-by-Step: Assign PROFIsafe Addresses in the Network View
The following procedure expands the Assign F-destination address workflow into the sub-steps expected by TIA Portal V19 with a current HSP.
7.1 Pre-conditions
- Project compiles without safety-relevant errors.
- The F-CPU is configured as PROFINET IO controller.
- The IM 155-6 PN HF and the F-modules are in the device view with valid slots.
- The ET 200SP station is online-reachable or the offline configuration is being prepared for download.
7.2 Action sequence
- In the project tree, double-click Devices & Networks to open the network view.
- Click the ET 200SP station to select it. The station's PROFINET interface is highlighted.
- Right-click the station → Assign F-destination address from the context menu.
- The Assign PROFIsafe addresses editor opens. It lists all F-modules in the station with the currently configured F-destination address and the proposed new address.
- Under Identification, select one of:
- Flash LED — triggers a visual flash on the F-module's status LED for physical identification.
- Device number — assigns by PROFINET device number.
- Serial number — assigns by the device's unique serial number, recommended for redundant or multi-instance stations.
- Click Assign. TIA Portal writes the address to the module.
- Click Finish to close the editor.
- Compile the project again to ensure consistency.
For the complete official procedure, refer to Step 8: Assign PROFIsafe addresses in the SIMATIC S7-1500/ET 200MP manual collection.
8. Firmware and Version Compatibility Matrix
| IM 155-6 PN HF Firmware | TIA Portal V18 | TIA Portal V19 (with HSP) | F-IO via Catalog | F-IO via S7-FCT |
|---|---|---|---|---|
| V6.0 | Supported natively | Supported | Yes | Yes |
| V6.1 | Supported natively | Supported | Yes | Yes |
| V6.2 | Not supported | Supported (HSP required) | Yes | Yes |
The V6.2 firmware is the cutoff where native V18 support ends. The V6.2 HSP is delivered as part of the TIA Portal V19 support package set and is not retroactively available for V18. For projects locked to V18, the only option is to keep the IM 155-6 PN HF at V6.1 (or earlier) and to import the corresponding V6.1 GSDML.
9. Verification Procedures
After applying any of the three solution paths, verify the assignment with the following checks before commissioning the safety function.
9.1 Offline verification
- Open the Assign PROFIsafe addresses editor and confirm the F-destination address column is populated for every F-module.
- In the safety program, confirm the F-I/O DB references the same F-destination address.
- Compile the safety program. TIA Portal performs cross-checks between the configured address and the safety program references.
9.2 Online verification
- Go online to the F-CPU.
- Open Online & Diagnostics → PROFINET interface → F-diagnostics on the F-module.
- Verify the F-destination address displayed in the diagnostics matches the configured value.
- Check the diagnostic buffer for events
PROFIsafe: Address assignment OKor anySF: PROFIsafe address mismatchevents.
9.3 Hardware-level verification
- Power-cycle the ET 200SP station.
- Observe the F-module status LED sequence: green → flashing → steady green. A red SF LED indicates address assignment failure.
- On the F-module display (if equipped), navigate to Diagnostics → PROFIsafe → F-address and confirm the displayed decimal value.
10. Common Error Conditions and Diagnostic Codes
| Symptom | Probable Cause | Resolution |
|---|---|---|
| Assign F-destination address menu greyed out | F-CPU not assigned as PROFIsafe proxy | Drag-and-drop the ET 200SP onto the F-CPU's PROFINET interface |
| Module not found in catalog | V6.2 firmware in V18 environment | Upgrade to TIA Portal V19 + HSP, or downgrade firmware to V6.1 |
| Address write fails, SF LED red | Wrong PROFINET device name on F-module | Assign PROFINET device name via Online → Assign PROFINET device name |
| S7-FCT cannot connect to device | PROFINET topology mismatch | Verify port interconnection in the network view |
Diagnostic buffer: 0x001F PROFIsafe address invalid |
Address 0 or out-of-range value | Set F-destination address to a valid value (1–65534) |
F-CPU reports SF: PROFIsafe communication fault
|
Address mismatch between F-CPU and F-module | Reassign F-destination address, recompile safety program |
| Compile error: F-destination address not unique | Two F-modules with the same F-address in the same station | Renumber one F-module to a unique address |
11. Edge Cases and Field-Proven Caveats
11.1 Module hot-swap after firmware update
Replacing an IM 155-6 PN HF with a V6.2 module in a project created in V18 will not be detected as a configuration mismatch until the next compile. The compiler will report Device version not supported in current TIA Portal. The only legal fix is the HSP upgrade path described in Section 4.
11.2 Mixed safety and standard I/O
The PROFIsafe F-destination address is per-F-module, not per station. A station with one F-DI and one standard DI requires only one F-address assignment — for the F-DI. The standard DI uses standard PROFINET slot addressing and is unaffected.
11.3 Racked F-modules and the backplane bus
The IM 155-6 PN HF (type 3) supports up to 64 I/O modules, including F-modules. The F-destination address is bound to the F-module's slot, not the backplane address. Hot-swapping an F-module to a different slot requires re-assignment of the F-destination address.
11.4 PROFIsafe address switch on ET 200pro F-modules
For ET 200pro F-modules, the F-destination address is set via a DIL switch on the module itself, in addition to the software assignment. The setting on the DIL switch must match the software-assigned address. This is documented at Assignment of PROFIsafe Address in the Fail-safe Modules manual collection.
11.5 Multiple F-CPUs in the project
If the project contains more than one F-CPU, the IO controller assignment must be explicit. The ET 200SP station can be assigned to only one F-CPU. PROFIsafe addresses are unique per F-CPU, so the same F-destination address can exist in two F-CPUs without conflict as long as they are on different PROFINET subnets.
12. Safety and Commissioning Considerations
Document the following for every F-module after successful assignment:
- PROFINET device name
- PROFINET IP address
- F-destination address (decimal)
- F-source address (F-CPU PROFIsafe address, decimal)
- F-monitoring time (ms)
- Module serial number
These values feed the PROFIsafe response time calculation and are required for the safety validation per IEC 61508 / IEC 62061. The exact format and signature of the F-destination address field is defined in the PROFIsafe profile (PNO order number 3.192).
13. Summary and Recommended Action Plan
- Identify the firmware version of the IM 155-6 PN HF (6ES7155-6AU02-0BN0). The version is shown on the packaging label and on the module's Web server diagnostics page.
- If the firmware is V6.2 and the project is in TIA Portal V19 → install the latest HSP for V19. Reinsert the module from the catalog. Reassign the F-destination address.
- If the firmware is V6.2 and the project is locked to TIA Portal V18 → downgrade the module firmware to V6.1 using SIMATIC Automation Tool or the Web server. Reinsert the module from the V18 catalog.
- If the project uses a non-Siemens PROFINET controller → use S7-FCT to assign the F-destination address.
- Verify online via the F-diagnostics page and the module display.
- Re-run the safety acceptance test.
Why does TIA Portal V18 fail to assign a PROFIsafe address on an IM 155-6 PN HF with V6.2 firmware?
TIA Portal V18 does not have a catalog entry for the V6.2 firmware generation of the 6ES7155-6AU02-0BN0. The Assign F-destination address menu is disabled because the device version is not registered. Either install the TIA Portal V19 HSP and migrate the project, or downgrade the module firmware to V6.1 (or earlier) which V18 supports natively.
Do I need the SIMATIC S7-FCT to assign PROFIsafe addresses for an ET 200SP connected to a third-party PROFINET controller?
Yes. When the ET 200SP is imported via GSD/GSDML rather than the TIA Portal hardware catalog, the F-destination address must be written using the SIMATIC S7-Fail-safe Configuration Tool (S7-FCT). The standard PROFINET GSD does not expose the PROFIsafe address parameter; only S7-FCT or a TIA Portal catalog-based configuration can complete the assignment.
Where is the PROFIsafe F-destination address stored — in the module, in the project, or both?
The F-destination address is stored in the F-module's non-volatile memory and is also recorded in the TIA Portal project. The address must match between the F-module and the F-CPU safety program. A mismatch causes the F-CPU to passivate the safety slot with a PROFIsafe communication fault.
Can I assign the same F-destination address to two different F-modules in the same station?
No. The F-destination address must be unique per PROFINET subnet, not per station. Duplicate addresses in the same subnet will cause a compile error and a runtime diagnostic event on the F-CPU. The valid address range is 1 to 65534; address 0 is reserved and treated as "unassigned".
Is it possible to assign the PROFIsafe address without going online to the F-CPU?
Yes. The Assign F-destination address function in the TIA Portal network view writes the address to the ET 200SP station over the PROFINET connection. The F-CPU does not need to be in RUN for the address write; however, the safety program must be downloaded and consistent for the safety function to validate the assigned address at runtime.