Resolving S7-400 PROFIBUS DP Bus Faults at 19.2 kbps

David Krause12 min read
ProfibusSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

An S7 414-2DP master reports periodic PROFIBUS DP bus faults (1-2 events per 5-minute window) when running at 19.2 kbps against a CP 342-5 slave attached to a third-party S7-300 furnace controller. The same network is stable at 1.5 Mbps. The peripheral footprint is small: 24 bytes I/O for each of three distributed stations and 80 bytes of consistent SFC14/SFC15 data on the CP 342-5 link. Because the furnace PLC mandates 19.2 kbps, the speed cannot simply be raised.

This document walks through the root cause tree, the correct configuration of Siemens OLM (Optical Link Module) G11/G12 in STEP 7 HW-Config, diagnostic buffer analysis, and bus parameter verification required to clear the faults without changing the requested baud rate.

System Architecture and Topology

The reported master station is a SIMATIC S7 414-2DP (6ES7414-2XG04-0AB0 or comparable order number). The DP master port serves four slaves, with the following physical arrangement:

DP Station Type Medium Approx. Distance Order Number (typical)
Slave 1 ET 200S PROFIBUS copper 5 m 6ES7151-1BA02-0AB0 (IM151-1)
Slave 2 ET 200M Fiber (OLM) 300 m 6ES7153-2BA02-0XB0 (IM153-2)
Slave 3 ET 200M Fiber (OLM) 300 m 6ES7153-2BA02-0XB0 (IM153-2)
Slave 4 CP 342-5 (S7-300 furnace side) PROFIBUS copper 50 m 6GK7342-5DA03-0XE0
Topology note. Each OLM star segment terminates the copper PROFIBUS at the OLM chassis. There is no redundant ring. Star topology is the only legal layout for PROFIBUS when OLM/G devices break the electrical segment into multiple isolated galvanic subsegments.

Two OLM variants are deployed: OLM G11-1300 (6GK1503-2CC00) for the first fiber link, and OLM G12-1300 (6GK1503-3CC00) for the second. The G11 has one optical port; the G12 has two. Both operate at 1300 nm and are designed for distances up to several kilometers on multimode fiber, well above the 300 m used here.

PROFIBUS DP Baud Rate, Cable Length, and Slot Time

PROFIBUS DP transmission speed vs. segment length per IEC 61158 / EN 50170 is the first thing to verify when low baud rate problems appear. The copper segment length is not the limiting factor at 19.2 kbps (1.2 km is supported), but the slot time T_sl and the min Tsdr values change significantly compared to 1.5 Mbps.

Baud Rate Max Copper Segment (m) Typical T_sl (bit times) Min T_sdr (bit times) Max T_sdr (bit times)
9.6 kbps 1200 1023 11 60
19.2 kbps 1200 1023 11 60
45.45 kbps 1200 1023 11 60
93.75 kbps 1200 1023 11 60
187.5 kbps 1000 1023 11 60
500 kbps 400 512 11 100
1.5 Mbps 200 300 11 150
3 Mbps 100 150 11 250
6 Mbps 100 100 11 450
12 Mbps 100 75 11 800

The slot time at 19.2 kbps is the maximum possible (1023 bit times). Each bit time at 19.2 kbps is 52.08 us, so T_sl is approximately 53.3 ms end-to-end. This huge timing window is precisely the source of the issue when the OLM is not declared to the master.

Root Cause Analysis

The dominant cause of "runs at 1.5 Mbps but not at 19.2 kbps" symptoms on a multi-segment PROFIBUS network with OLMs is that the OLM is not entered in HW-Config as a passive station. Without that entry, the master calculates bus timing (slot time, min/max Tsdr, quiet time, retry value) as if the entire network is one copper segment. When the OLM is then inserted in the physical path, the additional propagation delay and signal regeneration alter the bit-level timing window, and at 19.2 kbps the slot time calculation is large enough that the master's watchdog for slave response trips sporadically.

Secondary contributors worth ruling out:

  1. Terminating resistors on the CP 342-5 subsegment. With a 50 m copper run and a CP 342-5 at the end, both ends must have termination ON, with all intermediate nodes OFF. The OLM copper ports have built-in selectable terminations.
  2. Shielding/grounding of the PROFIBUS cable. At 19.2 kbps the signal rise time is long enough that 50 Hz/60 Hz hum from poor shield bonding appears as bit errors.
  3. CP 342-5 operating mode mismatch. The CP must be configured as DP Slave in the S7-300 project, and the S7-300 side must be in RUN or RUN-P for the slave to be reachable. A stopped CPU on the furnace side still toggles the bus, which is consistent with the report that disconnecting the furnace PLC reduced but did not eliminate faults.
  4. Diagnostic repeater presence. The diagnostic repeater (6GK1500-0AA10) actively monitors segment health and can be inserted between master and OLM to capture which segment drops the token.
Field evidence. Removing the furnace PLC reduced the fault count but did not eliminate it. This is consistent with OLM being the dominant cause and the CP 342-5 / furnace PLC being an additional aggravator. Both must be addressed.

Solution: Configure OLM in HW-Config

STEP 7 / SIMATIC Manager must know about the OLM so that the master's bus parameters include the additional repeater-related timing overhead. Procedure:

  1. Open the STEP 7 project containing the S7 414-2DP station.
  2. Launch HW-Config and select the PROFIBUS subnet on the DP master port.
  3. Open Properties > Network Settings on the PROFIBUS subnet object.
  4. Switch to the Options tab.
  5. In the repeater / OLM section, add the OLM as a passive station. Siemens provides GSD-style catalog entries for the G11 (6GK1503-2CC00) and G12 (6GK1503-3CC00) under PROFIBUS DP > Other field devices > Repeater > OLM.
  6. Assign the OLM the same PROFIBUS address it occupies physically (typically 0 is reserved for masters; OLMs commonly use 1-3 in a small network, but the OLM address is purely a placeholder for timing calculation, not for token passing).
  7. Save and recompile (Station > Save and Compile).
  8. Download the HW configuration to the S7 414-2DP CPU while it is in STOP.
  9. Restart the CPU and observe the diagnostic buffer.
Why this works. The OLM catalog entry tells the STEP 7 bus parameter calculator how many repeater delays are in the path. The bus profile recomputes T_sl, min Tsdr, max Tsdr, and the GAP factor for the actual topology. At 1.5 Mbps the unaccounted OLM delay is small relative to the slot time and hidden; at 19.2 kbps it is large enough to push the slave response outside the master's permitted window.

CP 342-5 Configuration on the Furnace Side

The CP 342-5 is configured as a DP slave in the S7-300 project that controls the furnace. Confirm:

Parameter Setting Notes
Operating mode DP Slave Not "DP Master" and not "S7 Communication only"
Baud rate 19.2 kbps Hard requirement from furnace PLC
PROFIBUS address Matches the master project Verify with BT 200 or Amprobe BT-1
I/O slot assignment 80 bytes consistent data Triggers use of SFC14/15
Watchdog Enabled, 10 s default Check DP slave diagnostic for timeout events

The S7-300 user program on the furnace side must call SFC14 'DPRD_DAT' and SFC15 'DPWR_DAT' for the 80-byte consistent CP slots. The S7 414-2DP master program must do the same on the master side. Verify that the SFC calls are placed in OB1 (or a time-driven OB if non-cyclic transfer is required) and that the RECORD parameter points to a DB of sufficient length:

// S7-400 master side, reading 80 bytes from CP 342-5
CALL  "DPRD_DAT"
  LADDR  := W#16#0100      // I/O base address of CP 342-5 in master view
  RET_VAL:=#status         // Any non-zero value indicates DP error
  RECORD  :=P#DB100.DBX0.0 BYTE 80

// S7-400 master side, writing 80 bytes to CP 342-5
CALL  "DPWR_DAT"
  LADDR  := W#16#0100
  RECORD  :=P#DB110.DBX0.0 BYTE 80
  RET_VAL:=#status

Wrap both SFC calls in an error-handling block that reads RET_VAL; for low baud rates a small percentage of retries is normal, but the master should not drop the slave within 10 s. The SIMATIC S7-300 CP 342-5 manual specifies that SFC14 returns W#16#8xxx on slave failure and W#16#0xxx on success.

Diagnostic Buffer Analysis

Open the S7 414-2DP online with STEP 7 and navigate to CPU > Diagnostic Buffer. The PROFIBUS-related events arrive in this format:

Event ID (hex) Meaning Action
0xE0C0 Distributed I/O: station failure (slave x) Identify which slave and check physical link
0xE0C1 Distributed I/O: station return (slave x) Confirms intermittent physical/electrical issue
0xE0C4 Bus fault on DP master system Look for OLM/repeater/termination issue
0xE0C5 Sync/Freeze error Check group assignment in HW-Config
0xE1C0 Diagnostic interrupt from a DP slave Read slave diagnostic with SFC13

Sort the buffer chronologically. If the failing slave ID varies between CP 342-5 (slave 4) and ET 200M (slave 2/3) and the OLM address appears in the failure window, the OLM is the suspect. If only the CP 342-5 fails, concentrate on the 50 m copper segment, termination, and the furnace-side CPU state.

For slave-level diagnostics from the master, use:

CALL  "DPNRM_DG"   // SFC13, read complete diagnostic from DP slave
  LADDR  :=W#16#0100   // Slave diagnostic address
  RET_VAL:=#ret        // Error code
  RECORD :=P#DB200.DBX0.0 BYTE 32  // Diagnostic buffer in master DB

Bus Parameter Verification

After the OLM is added in HW-Config, export the calculated bus parameters and confirm:

Parameter Value @ 19.2 kbps (expected) Notes
T_sl (slot time) ≥ 1023 bit times × 52.08 us = 53.3 ms Will grow further if OLM is in path
min T_sdr 11 bit times Master minimum response delay
max T_sdr 60 bit times Slave maximum response delay
T_set 1 bit time Setup time
T_tr ≤ 8 bit times per repeater Each OLM counts as one repeater delay
GAP factor 1-10 GAP refresh cycle multiplier
HSA (Highest Station Address) Set to 126 for diagnostic repeater support Common pitfall: set too low
Retry limit 1-8 (default 1) Already increased per report; verify value is downloaded
Retry limit caveat. Increasing the retry limit on the DP master interface masks the symptom but does not fix it. A bus parameter mismatch will still produce a slave diagnostic interrupt; only the master fault LED will stay off. Always fix the root cause and keep the retry limit at 1 or 2 in production.

Fiber Segment and OLM Checks

For the OLM G11-1300 and G12-1300 fiber links, verify:

  1. Optical power budget. On 1300 nm multimode fiber, 300 m should yield 1-3 dB attenuation. The OLM receiver threshold is typically -30 dBm; if a dirty connector pushes the link above -25 dBm, intermittent loss-of-light events will occur that are invisible to the user but visible to the DP master as a slave dropout.
  2. Connector cleanliness. Clean both SC connectors with a proper fiber optic cleaning pen (e.g., Cletop S-250). One OLM fault often masquerades as ten.
  3. Termination on the OLM copper side. Switch the OLM's termination ON only at the bus ends, OFF for any OLM in the middle of a copper chain. Each OLM has a slide switch for the terminating resistor and bus termination pull-up/pull-down.
  4. OLM operating mode DIP switches. The G11/G12 ship with all DIP switches OFF (transparent mode). Do not enable segment monitoring mode unless a diagnostic repeater is part of the design.

Verification

After the HW-Config change, follow this verification protocol:

  1. Download HW Config to the S7 414-2DP while in STOP.
  2. Switch to RUN, clear the diagnostic buffer.
  3. Run the bus at 19.2 kbps for a minimum of 4 hours continuously while exercising all 80 bytes of SFC14/SFC15 data at 100 ms cycle.
  4. Confirm zero new 0xE0C0, 0xE0C1, or 0xE0C4 events in the diagnostic buffer.
  5. Force a slave failure (unplug the CP 342-5 PROFIBUS connector) and confirm the master logs 0xE0C0 within 2 s and recovers within 10 s when the connector is reinserted.
  6. Use a PROFIBUS cable tester or diagnostic repeater (6GK1500-0AA10) to capture a 24-hour bus trace at 19.2 kbps and verify no spur errors, retries, or illegal responses appear.
  7. Compare the failure rate per 24 h to the original 1.5 Mbps baseline. They should be statistically indistinguishable (near zero).
Acceptance criterion. 0 bus faults per 24 h at 19.2 kbps is the engineering target. If a residual fault rate remains below 1 per 24 h and the SFC14/15 RET_VAL never indicates a loss, the network is operating within PROFIBUS spec. Anything above this means the OLM is still missing from the configuration or a copper segment has a marginal connector.

Frequently Asked Questions

Why does the bus run at 1.5 Mbps but fail at 19.2 kbps with the same hardware?

At 1.5 Mbps the slot time is short (300 bit times) and unaccounted OLM propagation delay is a small fraction of the response window. At 19.2 kbps the slot time is 1023 bit times (53.3 ms) and a missing OLM entry in HW-Config shifts the actual bus timing past the master's permitted max Tsdr, causing intermittent slave dropouts. Configure the OLM as a passive station in HW-Config to add the repeater delay to the bus parameter calculation.

Do I have to add both the OLM G11 and the OLM G12 to the STEP 7 project?

Yes. Every OLM/G repeater on the PROFIBUS path between master and slave contributes to the bus timing. Insert the G11-1300 (6GK1503-2CC00) and G12-1300 (6GK1503-3CC00) as passive stations under the same PROFIBUS subnet, each with its assigned address. The OLM address is for timing calculation only and does not participate in token passing.

Can I keep the furnace PLC at 19.2 kbps and run the rest of the network at 1.5 Mbps?

No. PROFIBUS DP enforces a single transmission rate per segment. If the CP 342-5 slave and its master port must run at 19.2 kbps, the entire subnet served by that master port must also run at 19.2 kbps. The 1.5 Mbps test only proves the physical layer is sound; it does not validate bus parameter timing for the production baud rate.

What SFC return value indicates a CP 342-5 slave failure during SFC14/15 processing?

On the master, SFC14 (DPRD_DAT) and SFC15 (DPWR_DAT) return a 16-bit value where the high byte is the DP error code and the low byte is the IEC error code. W#16#8xxx indicates a slave-side fault (slave not reachable, diagnostic data not OK, or module failure). W#16#0xxx indicates success. A periodic mix of W#16#0000 and W#16#8090 means the slave is dropping off the bus between calls, which is exactly the symptom of the OLM timing issue described here.

Is a diagnostic repeater required, or is configuring the OLM in HW-Config enough?

Configuring the OLM in HW-Config resolves the timing calculation and is the primary fix. A diagnostic repeater (6GK1500-0AA10) is not required for steady-state operation but is highly recommended during commissioning and during any future fault analysis because it records segment-level signal quality, retries, and spur errors that the master's diagnostic buffer cannot capture.

Back to blog