1. Problem Description
On a SIMATIC S7-300F automation cell built around a CPU 315F-2 DP, a fully commissioned PROFIBUS DP network of distributed I/O operates without diagnostic events. Standard ET 200S stations report clean bus operation, the IM 151 interface modules show steady green LEDs, and the CPU remains in RUN with no entry in the diagnostic buffer. The fault appears only when two new PROFIsafe modules are inserted into an existing ET 200S station: a 4 F-DI (24 V) and a 4 F-DO (24 V/2 A) safety module pair. The instant these two slots are powered up under PROFIsafe, three different SF (group fault) LEDs turn red simultaneously: the SF on the CPU 315F itself, the SF on the IM 151 of the affected ET 200S, and the SF on the safety modules. The bus fault (BF) LED does not light, so PROFIBUS physical layer and DP cyclic communication are confirmed intact; the failure is isolated to the PROFIsafe safety protocol layer above PROFIBUS DP-V1.
Because the BF LED stays dark, the integrator immediately knows that wiring, shielding, baud rate, bus terminators, and DP slave address settings are not the cause. The PROFIsafe driver on the F-CPU detects that the safety telegram structure exchanged with the F-module does not match the configured safety parameters, and the F-host forces the device into its safe state. The exact reason is reported only through the diagnostic buffer of the CPU and through the on-line PROFIsafe diagnostics inside HW Config (STEP 7 V5.5 or earlier; TIA Portal equivalent is the device view of the safety station).
2. Affected Hardware and PROFIsafe Topology
The system under investigation uses the following components, all of which appear in the official SIMATIC S7-300F and ET 200S catalogs:
- 6ES7 315-6FF01-0AB0 – CPU 315F-2 DP (also valid for the later 6ES7 315-6FF04-0AB0 firmware release). This is the F-variant of the S7-300 CPU that supports PROFIsafe V2 on PROFIBUS DP via the integrated DP master port.
- 6ES7 151-1BA02-0AB0 – IM 151-1 STANDARD interface module for the ET 200S, terminating the PROFIBUS DP slave and exposing the backplane bus to the safety I/O.
- 6ES7 138-4FA00-0AB0 – SM 138 F-DI, 4-channel fail-safe digital input (24 V DC) for ET 200S. A common successor part is 6ES7 138-4FA04-0AB0.
- 6ES7 138-4FB00-0AB0 – SM 138 F-DO, 4-channel fail-safe digital output (24 V DC, 2 A) for ET 200S. A common successor part is 6ES7 138-4FB04-0AB0.
- 6ES7 138-4HA00-0AB0 – PM-E F power module that segregates the safety segment from non-safe power rails inside the ET 200S terminal.
The PROFIsafe profile applied to these modules is profile version V2.4 (or V2.6 for newer F-DI/F-DO firmware), which uses CRC2 over a 24-bit consecutive numbering field and a 16-bit CRC1. PROFIsafe V2 sits on top of PROFIBUS DP-V1 (or PROFINET IO) and is fully transparent to the cyclic data exchange – the safety layer is implemented entirely in the F-CPU's safety program and in the firmware of the F-module. The reference specification is published by PI (PROFIBUS & PROFINET International) and can be reviewed at the official PROFIsafe profile page.
The F-CPU and the F-module establish a point-to-point PROFIsafe relationship identified by a unique F-destination address (F_DEST_ADD). For PROFIBUS, this address is a value from 1 to 1023 (values 1024 and above are reserved for PROFINET). The address is assigned in two places, and both must match exactly:
- Inside HW Config, on the F-module's properties dialog, in the PROFIsafe parameter block, F_DEST_ADD is entered by the engineer.
- On the back of the F-module itself, an 8-position DIP switch (typically labeled S1, eight segments marked 1, 2, 4, 8, 16, 32, 64, 128) sets the same address in hardware. The F-module reads the DIP switch at power-up and silently ignores the configured address if the two values disagree.
This dual-source assignment is the central concept behind the safety address: it is the hardware root of trust that prevents a mis-configured engineering station from being able to "tune in" to a real-world F-device.
3. Root Cause Analysis
The reported root cause is F-destination address mismatch. The F-DI/DO modules were physically wired and inserted into the ET 200S backplane, the configuration was downloaded, and PROFIsafe was started. However, the F_DEST_ADD value set in HW Config did not match the binary value encoded on the DIP switch behind the module. The F-CPU's PROFIsafe stack calculates a CRC over the outgoing safety telegram and stamps it with the configured F_DEST_ADD. The F-module receives the telegram, compares the address against its own DIP-switch-derived value, and rejects the frame because the addresses do not agree. Per the PROFIsafe specification, the receiving F-device immediately enters the safe state and stops driving any process output. The F-CPU, after the F-monitoring time elapses without a valid safety telegram, generates a diagnostic interrupt and sets its own SF LED. The IM 151 in turn reports the slot fault to the diagnostic buffer, and the affected module's channel-level SF LED lights.
For a more general view, the following conditions all lead to the same SF-LED red signature with a green BF LED, and should be excluded in order:
| Cause | LED signature | Diagnostic buffer entry |
|---|---|---|
| F_DEST_ADD mismatch (DIP switch vs. HW Config) | SF on CPU, IM, F-module; BF off | "PROFIsafe: address comparison failed" or "F-Destination address incorrect" |
| F_Source_Address missing or wrong | SF on CPU, F-module; BF off | "PROFIsafe: F_Source_Add invalid" |
| F_Monitoring_Time too short for telegram cycle | SF on CPU, F-module; BF off; intermittent | "PROFIsafe: timeout, safe state entered" |
| PROFIsafe profile version mismatch (V1 vs. V2) | SF on CPU, F-module; BF off | "PROFIsafe: parameter assignment error" |
| Different safety program / different F-CPU swapped in | SF on CPU and F-module; BF off | "PROFIsafe: passivation due to F-source change" |
| PM-E F power module missing or 24 V not present at the safety segment | SF on F-module only; BF off | "Supply voltage missing on safety segment" |
The diagnostic buffer is the single most useful tool: a single right-click on the CPU 315F in STEP 7 and selecting "PLC → Diagnostic Buffer" will reveal the first diagnostic event that initiated the SF condition.
4. Step-by-Step Diagnostic Procedure
- Open STEP 7 (or TIA Portal) and connect online to the S7-300F station. Right-click the CPU in the project tree and select PLC → Diagnostic Buffer. Filter the entries to display only "Event ID 16#75xx" (PROFIsafe-related events) and note the first entry that triggered the SF.
- Open HW Config and go online. With the ET 200S station visible in the upper part of the workspace, double-click the F-DI or F-DO slot. Switch to the Diagnostics tab – STEP 7 will display the live PROFIsafe state of the module, the F-monitoring time, and any channel-level diagnostics (e.g. passivated, address comparison error).
- Cross-check the F-destination address. The value displayed under PROFIsafe destination address in HW Config must equal the binary value encoded on the DIP switch of the corresponding F-module. If they do not match, the F-module will go into passivation immediately and the SF LED will illuminate.
- Power down the station. The DIP switch on Siemens ET 200S F-modules (4 F-DI and 4 F-DO, part numbers 6ES7 138-4FA0x and 6ES7 138-4FB0x) is read at module power-up. Online changes to the DIP switch without a power cycle are ignored. Remove the F-module from the terminal block to access the eight-position DIP switch on the back of the module.
- Re-set the DIP switch to match the configured F_DEST_ADD. The eight segments are weighted 1, 2, 4, 8, 16, 32, 64, 128. To set, for example, address 5, place segments 1 and 4 in the ON position and the rest in OFF. The address range used in practice for ET 200S F-modules on PROFIBUS is normally 1 to 255 (a single byte), but the full PROFIsafe V2 range up to 1023 is also supported.
- Reinsert the module, repower the station. Wait for the IM 151 to complete its backplane bus startup. The green PWR LED on the F-module should come on; the red SF LED should extinguish within one F-monitoring cycle.
- Verify in the diagnostic buffer. No new "PROFIsafe" events should be logged after the next warm restart. The F-module's status in HW Config should switch from Passivated to OK and then to Valid data once cyclic safety telegrams are exchanged.
5. Setting the F-Destination Address: Worked Example
Suppose HW Config shows the F-DI slot configured with F_DEST_ADD = 73 decimal. The F-module behind the slot is currently out of the rack. Convert 73 to binary: 73 = 64 + 8 + 1 = 0100 1001. Set the eight-position DIP switch so that segments 1, 4, and 7 are ON (1 = LSB):
| Segment | Weight | State | Contribution |
|---|---|---|---|
| 1 | 1 | ON | 1 |
| 2 | 2 | OFF | 0 |
| 3 | 4 | OFF | 0 |
| 4 | 8 | ON | 8 |
| 5 | 16 | OFF | 0 |
| 6 | 32 | OFF | 0 |
| 7 | 64 | ON | 64 |
| 8 | 128 | OFF | 0 |
| Total | 73 | ||
Reinsert the module, power up, and confirm in HW Config that the F-DI status is Valid data. A common error is to count from the wrong end of the DIP switch or to interpret the label of the segment as its position number; always refer to the silkscreen weighting next to the switch (1-2-4-8-16-32-64-128 in that physical order from one end to the other). The detail is documented in the ET 200S distributed I/O system manual, available on the official Siemens ET 200S manual page (entry ID 12490437).
6. PROFIsafe Parameter Reference
Below are the most relevant PROFIsafe parameters as exposed in the HW Config properties dialog of an ET 200S F-module. The values are the same regardless of whether the F-modules are in an ET 200S, ET 200SP, or ET 200MP station; only the way the parameters are entered differs between STEP 7 V5.5 and TIA Portal.
| Parameter | Meaning | Typical value | Notes |
|---|---|---|---|
| F_DEST_ADD | F-destination address (1–1023 on PROFIBUS, 1–65535 on PROFINET) | Per project plan, unique per F-device | Must equal the DIP switch setting on the F-module |
| F_Source_Add | Address of the F-host (F-CPU) | 1 (default for CPU 315F/317F on PROFIBUS) | Assigned automatically by STEP 7 / TIA Portal |
| F_WD_Time | F-monitoring time in ms | 150 ms (default) | Must be larger than the worst-case PROFIsafe telegram cycle; too small causes spurious passivation |
| F_Par_Version | PROFIsafe profile version | V2.4 / V2.6 | Must match between F-CPU and F-module firmware |
| F_Block_ID | Identifies the F-I/O DB (iPar) | 0–65535 | Only relevant for iPar-aware F-modules |
| F_CRC_Length | CRC1 length in octets | 3 (V2.4+) or 4 (V2.6) | Set automatically; do not change manually |
| F_iPar_Enabled | Individual parameter assignment | FALSE for SM 138 F-DI/DO | TRUE only for iPar modules (e.g. S7-300F AI) |
Important: the F-monitoring time (F_WD_Time) is the maximum gap that the F-module will tolerate between two valid safety telegrams before it self-passivates. A safe sizing rule is F_WD_Time ≥ 2 × (DP cycle time + telegram transmission time). For a 1.5 Mbit/s PROFIBUS DP network with 1 ms OB1 time and a single F-DI/DO pair, 150 ms is a robust default; on a heavily loaded bus (e.g. many DP slaves, long diagnostic round-trips) raise it to 250 ms or 500 ms, but never below the worst-case cycle that the bus can deliver.
7. Diagnostic Buffer Entry Catalog
The following diagnostic events are the ones most commonly seen when an F-device does not start. Each one is logged with an event ID and a timestamp in the CPU 315F diagnostic buffer. The event IDs are identical for STEP 7 V5.5 and TIA Portal as long as the F-CPU is a 31xF or a 41xF with F-runtime license.
| Event ID (hex) | Meaning | Typical cause | Remedy |
|---|---|---|---|
| 16#7501 | PROFIsafe: passivation due to CRC error | EMC, wrong CRC length, wrong F_Par_Version | Check PROFIsafe V2.4/V2.6 alignment; check shielding |
| 16#7502 | PROFIsafe: F-monitoring time exceeded | F_WD_Time too small or bus overloaded | Increase F-monitoring time; reduce bus load |
| 16#7503 | PROFIsafe: F_DEST_ADD mismatch | DIP switch differs from HW Config | Re-set DIP switch on the F-module |
| 16#7505 | PROFIsafe: F_Source_Add invalid | F-CPU was swapped without re-parameterising | Recompile and download the safety program |
| 16#7507 | PROFIsafe: F-IO DB parameter error | iPar mismatch | Re-assign iPar parameters in the safety program |
| 16#7509 | PROFIsafe: passivation due to slot error | F-module removed, PM-E F voltage missing | Restore 24 V to the safety segment |
| 16#7561 | PROFIsafe: F-CPU passivated device | Operator-triggered passivation | Reintegrate the F-I/O in the safety program |
A more general troubleshooting matrix – including the F-host and the F-device – is also published by WAGO as a free PDF in its download center, see the official WAGO PROFIsafe troubleshooting documentation. The matrix is written for PROFINET/ET 200SP but the event IDs, root causes, and recovery steps map directly to PROFIBUS/ET 200S because the PROFIsafe layer is identical.
8. Verification and Commissioning
Once the DIP switch and HW Config are aligned, perform the following verification steps in order. They are the minimum required by IEC 61508 / IEC 62061 for a PROFIsafe I/O subsystem to enter normal operation.
- Power-up test: cycle power to the ET 200S station three times. The SF LED must not illuminate on any of the F-modules or on the CPU 315F.
- Online check in HW Config: with the project online, the F-DI and F-DO slots must show Valid data and the F-monitoring time must be reported as active.
- Diagnostic buffer: confirm that no new PROFIsafe event (16#75xx) is appended for at least 10 minutes of continuous RUN.
- Passivation / reintegration test: open the safety program in STEP 7 / TIA Portal and force a passivation (for example by switching the F-DI to channel fault). The F-DO must de-energize within the configured F-monitoring time. Then reintegrate the F-I/O via the ACK button or via the F-I/O DB; the F-DO must energize only after reintegration is complete.
- Signature test: if a third-party tool (SISTEMA, PAScal) is used to compute the safety function's PFHd, the input and output values, the F-monitoring time, and the PROFIsafe profile version must all match the actual configuration.
9. Preventive Configuration Checklist
For future ET 200S PROFIsafe additions, capture the following data in the project documentation so that an F-destination address mismatch never recurs:
- HW Config screenshot of the F-module's properties dialog showing F_DEST_ADD.
- Binary encoding of F_DEST_ADD for the eight-position DIP switch.
- Photograph of the back of the F-module with the DIP switch set in the final state.
- F-monitoring time value, written explicitly in the safety program header.
- PROFIsafe profile version (V2.4 or V2.6) of the F-module firmware, read from the module's label or from HW Config on-line diagnostics.
- Logical addressing of the F-I/O DB and the passivation/reintegration mechanism in the safety program.
10. Frequently Asked Questions
What does the red SF LED on a CPU 315F and on the ET 200S F-module mean at the same time?
It means the F-host (the CPU 315F) and the F-device (the ET 200S SM 138 F-DI or F-DO) are not exchanging valid safety telegrams. The most common cause is a mismatch between the F_DEST_ADD configured in HW Config and the binary value set on the eight-position DIP switch behind the F-module. Check the diagnostic buffer of the CPU for event ID 16#7503 first.
How is the PROFIsafe F-destination address set on the ET 200S SM 138 F-DI / F-DO?
The address is set in two places that must match exactly. In STEP 7 / TIA Portal, open the F-module's properties in HW Config and enter F_DEST_ADD (range 1 to 1023 on PROFIBUS). On the back of the F-module, an eight-position DIP switch encodes the same value in binary with weights 1, 2, 4, 8, 16, 32, 64, 128. The module reads the switch at power-up.
Why does the BF LED stay green when the SF LED is red?
PROFIBUS physical layer (DP-V0/V1 cyclic data) is intact. The BF LED is driven by the DP slave state machine and indicates bus-level errors only. PROFIsafe sits on top of DP-V1 as a separate protocol layer; failures in PROFIsafe do not raise BF but instead raise SF on the F-host and the F-device. The diagnostic buffer of the CPU is the authoritative source for PROFIsafe errors.
Can I change the DIP switch on a live F-module and expect the change to take effect?
No. The F-module reads the DIP switch once at power-up. After any change, power the module down (remove it from the ET 200S terminal or switch off the PM-E F supply) and then power it up again. Online changes to the switch without a power cycle are ignored by the module firmware.
What is a safe default value for the F-monitoring time on a PROFIBUS DP network with ET 200S F-modules?
Use 150 ms as the default for a 1.5 Mbit/s network with low-to-moderate bus load. For heavily loaded buses (more than 16 DP slaves, or any slave doing acyclic read/write to expand diagnostics), increase the F-monitoring time to 250 ms or 500 ms. The F-monitoring time must always be larger than twice the worst-case DP cycle time plus the PROFIsafe telegram transmission time, and it must be documented in the safety program.
Where do I find the official documentation for ET 200S PROFIsafe addressing?
Use the official ET 200S distributed I/O system manual on the Siemens support portal (entry ID 12490437), the CPU 315F-2 DP manual (entry ID 12996906), and the PROFIsafe profile page maintained by PI (PROFIBUS & PROFINET International) for the protocol-level specification. WAGO also publishes a free PROFIsafe troubleshooting PDF in its download center that maps event IDs to root causes.