Resolving S7-400F CPU 416F-2 STOP Fault After Safety Input Add

David Krause18 min read
Safety SystemsSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving S7-400F CPU 416F-2 STOP Fault After Adding a Safety Input Address

When a Siemens CPU 416F-2 drops to STOP immediately after a new fail-safe (F-) input address is added to the safety program, the failure is almost always rooted in PROFIsafe address assignment, an undownloaded hardware configuration, or a safety signature mismatch between STEP 7 and the F-CPU. This guide consolidates the diagnostic procedure, the underlying S7-400F safety model, the relevant diagnostic-buffer event IDs, and a step-by-step recovery sequence that field engineers can apply on a live PROFIBUS DP network that includes a DP-DP coupler and a partner CPU (such as a 412-2 PN).

Affected platform: SIMATIC S7-400F / S7-400FH, CPU 416F-2 (order number 6ES7 416-2FP07-0AB0 and earlier -2FN05/-2FK04 variants) with Distributed Safety V5.4 SP5 or later (now superseded by SIMATIC S7 F-Configuration Pack in TIA Portal). The procedure also applies to 416F-3 PN/DP, 416F-2 DP, and 414F/412F CPUs that share the same F-runtime architecture.

1. Problem Description and Typical Symptoms

On a redundant safety station that uses a DP-DP coupler (e.g., 6ES7 158-0AD01-0XA0) to exchange fail-safe I/O between two F-CPUs, the symptom presents as:

  1. The SF (Safety Fault) LED on the 416F-2 turns red.
  2. The CPU transitions from RUN to STOP immediately after the modified safety program is downloaded, or after a power-cycle/restore-from-CPU.
  3. The IM (interface module) and DP LEDs indicate bus activity, but the BUSF/BF LED on the DP master port may blink depending on whether the F-module lost its PROFIsafe connection.
  4. STEP 7 online view reports the operating mode as STOP with the reason "STOP caused by F-STOP request" or "Safety program was changed online".
  5. The diagnostic buffer contains F-specific events (Event ID 16#75xx range) pointing to a PROFIsafe address, monitoring-time, or signature problem on the newly added F-channel.

The root cause is rarely a defective module. It is almost always a configuration consistency problem between the three artifacts that an F-CPU must validate on every restart:

  • The compiled safety program in the F-CPU's flash memory.
  • The hardware configuration (HW Config) for the F-I/O slots and the DP-DP coupler.
  • The PROFIsafe address pair (F-source address / F-destination address) on every F-slave.

2. S7-400F Safety Architecture Background

The 416F-2 is a fail-safe PLC certified to IEC 61508 SIL 3 and EN 954-1 Cat. 4 (and ISO 13849-1 PLe on later firmware). It runs a standard user program and a safety program in parallel, both compiled from the same STEP 7 project. The safety program is generated by the Safety Compile Editor (F-Compiler) and stored separately from the standard blocks. Key architectural facts that drive the troubleshooting procedure:

Element Purpose Storage in F-CPU
F-signature (collective signature) 32-bit CRC of the entire safety program; verified at every restart and on every safety-relevant code change Retained in F-CPU flash; must match the offline value in the F-Compile Editor
F-source address (F_SRCAD) Unique PROFIsafe address assigned to the F-CPU (range 1-65534, default starts at 1) Configured in HW Config on the F-CPU's DP/PN interface
F-destination address (F_DSTAD) Unique PROFIsafe address assigned to the F-slave channel (range 1-65534, must differ from F_SRCAD) Set in HW Config on the F-I/O module properties, "PROFIsafe" tab
F-monitoring time (F_WD_TIME) Maximum time between two valid PROFIsafe telegrams before the F-slave goes to safe state (typical 100-1000 ms, min 1 ms) Set per channel in HW Config
F-runtime group signature Per F-FB/F-FC block signature to detect unauthorized modifications Stored in the F-runtime group's data block

Every time the safety program is recompiled, the F-Compile Editor recomputes the collective F-signature and the runtime-group signatures. The HW Config editor also re-validates the F-source and F-destination addresses. If the F-CPU's stored F-signature does not match the signature of the safety program being loaded, the CPU refuses to start in RUN and goes to STOP with an F-error.

3. Root Cause Analysis

For the specific failure mode "CPU 416F-2 goes to STOP after a new input address is added", the most common root causes in descending order of frequency are:

3.1 HW Configuration Not Downloaded After Address Change

When the engineer adds a new F-input bit (e.g., a channel on an ET 200S F-module behind the DP-DP coupler, or a new channel on an SM 326F DO10/8x24V in the central rack), the F-I/O hardware object is modified in HW Config. If the engineer downloads only the safety program (Blocks folder) but not the HW Config, the F-CPU is asked to map F-process data to a slot/channel that the F-runtime does not recognize. The F-runtime issues an F-startup error and forces the CPU to STOP.

Field rule: Any change to an F-module's channel assignment, F-address, or F-monitoring time requires a full HW Config download to the F-CPU before the safety program is downloaded. STEP 7 will allow an inconsistent download, but the F-CPU will reject the startup.

3.2 F-Address Collision or Invalid F-Destination Address

Each F-slave on the PROFIsafe network must have a unique F-destination address. If a new F-input is wired to a channel whose F-destination address collides with an existing F-source or F-destination address (this frequently happens when an existing F-station is duplicated to a new slot), the F-CPU logs an F-parameterization error and enters STOP. The DP-DP coupler makes this more likely because both sides of the coupler appear in the F-CPU's HW Config and must each have their own PROFIsafe address space.

3.3 Safety Program Not Compiled After HW Change

Adding a new F-input address requires the F-Compile Editor to regenerate the F-DB (instance DB) and the F-shared DB, recompute the F-signature, and update the F-IO mapping in the F-runtime group. If the engineer edits the standard program and the safety program but skips the Compile step (or compiles only the standard program), the safety program on the F-CPU becomes inconsistent with the new I/O assignment.

3.4 F-Monitoring Time Too Short for the DP-DP Coupler Latency

Each direction of the DP-DP coupler introduces 1-3 PROFIBUS cycle latencies. If the new F-channel is on the far side of the coupler and the F-monitoring time was left at the default 150 ms, the F-CPU may report intermittent W#16#75xx "PROFIsafe communication error" events. Repeated F-communication failures with the new channel will cause the F-CPU to enter STOP if the F-shutdown group is configured to trip the CPU on channel failure.

3.5 Safety Signature Mismatch After Online Edit

If the new input address was added via an online edit on the F-CPU (e.g., adding an F-bit in a watch table and modifying the F-FB), STEP 7 will mark the safety program as "modified online" and the F-CPU's stored collective signature will not match. The CPU goes to STOP with the diagnostic event "F-signature mismatch". The fix is to perform a full STOP-to-RUN transition only after recompiling and downloading both the HW Config and the safety program in offline mode.

4. Diagnostic Buffer and F-LED Interpretation

Open the 416F-2 in STEP 7 via Online > Accessible Nodes (or via the online project), then navigate to CPU > Diagnostic Buffer. The relevant event IDs for F-runtime errors are documented in the SIMATIC S7-400F/FH Automation System manual. The most common F-events you will see for this failure are:

Event ID (hex) Meaning Typical Cause Corrective Action
16#7520 F-source address invalid or duplicate F_SRCAD not unique in PROFIsafe subnet Reassign F-source address in HW Config > F-CPU properties > F-Parameters
16#7521 F-destination address invalid or duplicate F_DSTAD collides with another F-slave Reassign F-destination address in HW Config > F-module > PROFIsafe tab
16#7522 F-monitoring time out of range F_WD_TIME < 1 ms or > 65535 ms Set F-monitoring time to a value > 2 * PROFIBUS cycle time
16#7524 F-parameter assignment error HW Config inconsistent with the F-runtime Recompile safety program and re-download HW Config
16#7530 PROFIsafe communication error (channel-level) F-monitoring time exceeded, bus fault, or DP-DP coupler reset Increase F_WD_TIME; check PROFIBUS cable and termination; verify DP-DP coupler diagnostics
16#75E1 F-collective signature changed Safety program recompiled but not downloaded, or wrong safety program version in F-CPU Download the safety program; verify offline/online F-signature match
16#75E2 F-runtime group signature mismatch F-FB modified online Recompile in offline mode and re-download F-blocks
16#79xx F-I/O access error (F-source or F-destination unreachable) F-module missing or wrong slot Verify slot assignment and module order in HW Config

The SF LED on the 416F-2 indicates a safety fault and is the primary visual indicator. The BF (bus fault) LED on the DP master port indicates a PROFIBUS problem, which may be secondary. The F-CPU front-panel display will show STOP followed by a short reason code; pressing the right arrow on the display scrolls to the diagnostic event details.

5. Step-by-Step Resolution Procedure

Perform the following steps in order. Each step verifies the previous one before proceeding. Do not skip the verification points.

Step 1 - Capture the Diagnostic Buffer

  1. Connect STEP 7 to the 416F-2 online.
  2. Open CPU > Diagnostic Buffer and note the most recent F-event IDs (typically the top 3-5 entries are relevant).
  3. Click Open Block on each F-event that references a block to jump to the affected F-FB or F-DB.
  4. Save the diagnostic buffer to a text file (right-click > Save As) for inclusion in the maintenance log.

Step 2 - Verify the DP-DP Coupler Configuration

  1. In HW Config, open the DP-DP coupler properties.
  2. Confirm that both DP-1 and DP-2 networks have unique PROFIBUS addresses (typically 1 for the master side, 3 for the partner side).
  3. Open the partner 412-2 PN online and verify that the coupler appears in its HW Config with matching diagnostic address assignments.
  4. Check the coupler's S7-400F/FH system manual section on DP-DP coupler for F-parameter propagation rules.

Step 3 - Download the Hardware Configuration

  1. In HW Config on the 416F-2 station, right-click the F-CPU and select Download to Target > Hardware Configuration.
  2. Confirm the prompt "Download hardware configuration to target module".
  3. Wait for the download to complete. The CPU will remain in STOP if it was already in STOP; if it was in RUN, it will request an STOP > RUN transition.
  4. Do not put the CPU into RUN yet.

Step 4 - Re-validate the F-Addresses

  1. Open the F-CPU properties > F-Parameters tab. Note the F-source address (default 1 for the first F-CPU in the project).
  2. For each F-I/O module (ET 200S F-modules, SM 326F, F-CP behind the DP-DP coupler), open its properties and select the PROFIsafe tab.
  3. Confirm that the F-destination address is unique within the F-CPU's PROFIsafe subnet. STEP 7 highlights collisions in red.
  4. If the new input is on a module that previously had no F-channels assigned, set a fresh F-destination address (use a block of addresses: e.g., 100, 101, 102 for module-level uniqueness).
  5. Set the F-monitoring time to at least 2 * PROFIBUS cycle time + DP-DP coupler latency. With a 10 ms PROFIBUS cycle and a 3 ms coupler latency, 100 ms is a safe minimum; 150-200 ms is the typical field value.

Step 5 - Recompile the Safety Program

  1. Open the Safety Compile Editor from the STEP 7 project (Options > Safety Compile Editor, or via the F-Block right-click menu).
  2. Click Compile. The F-Compile Editor will regenerate the F-DBs, recompute the F-signature, and report any signature or address warnings in the output window.
  3. Confirm that the new collective F-signature is displayed and matches the value expected by the project documentation.
  4. Document the new F-signature and the new F-runtime group signature in the safety change log (this is required by IEC 61511 for safety-relevant modifications).

Step 6 - Download the Safety Program

  1. In STEP 7, select the Blocks folder containing the F-blocks (F-FB, F-FC, F-DB, F-OB, F-SFC).
  2. Right-click > Download to Target. STEP 7 will prompt for confirmation that the F-program signature will change.
  3. Accept the prompt. The download may take 30-60 seconds depending on program size.
  4. After download, the CPU remains in STOP with the new F-signature stored.

Step 7 - Perform the STOP-to-RUN Transition

  1. Set the mode selector to RUN (or use STEP 7 CPU > Operating Mode > RUN).
  2. Watch the SF LED: it should turn off within 2-3 seconds if the F-startup checks pass.
  3. Open the F-runtime group monitoring view (STEP 7 > F-Blocks > F-Runtime Group Status) and confirm that the F-runtime group reports ACTIVE with the new signature.
  4. Monitor the F-channel for the new input: it should report OK in the F-I/O diagnostics view.

Step 8 - Verify the DP-DP Coupler Data Exchange

  1. On the partner 412-2 PN, open the DP-DP coupler diagnostic view.
  2. Confirm that input and output byte counts match the 416F-2's HW Config (the coupler swaps the inputs and outputs across the two networks).
  3. Force-test the new safety input: apply a 24 V signal to the F-input channel and verify that the corresponding bit appears in the 416F-2's input process image and propagates to the 412-2 PN via the DP-DP coupler if the input is forwarded.

6. Verification Procedure

After the CPU returns to RUN, perform the following verification checks before declaring the fault resolved:

  1. SF LED off: The Safety Fault LED must be off. If it remains on, the F-startup check still failed - capture the new diagnostic buffer and repeat from Step 1.
  2. F-signature match: In STEP 7, open F-Compile Editor > View > Signatures and confirm the offline F-signature matches the online F-signature reported by the F-CPU.
  3. F-runtime group status: All F-runtime groups must report ACTIVE. Any group in DEACTIVATED state indicates a runtime error that requires F-runtime group error OB (OB 82, OB 85, OB 86) inspection.
  4. F-I/O channel diagnostics: In F-Blocks > F-I/O Diagnostics, every F-channel must show OK. Channels showing Passivated indicate either a wiring fault or a residual F-communication error.
  5. Diagnostic buffer clean: No new F-event IDs (16#75xx) should appear in the diagnostic buffer after 10 minutes of RUN operation. Buffer growth indicates intermittent PROFIsafe or F-monitoring time issues.
  6. Functional safety test: Perform a complete safety function test (e.g., E-stop chain, guard door interlock) on the new input and on the cross-coupler link to the 412-2 PN. This is a documented requirement of IEC 61508 SIL 3 revalidation after a safety-relevant change.

7. DP-DP Coupler Specific Considerations

The DP-DP coupler (6ES7 158-0AD01-0XA0) is a frequent source of confusion in S7-400F setups because each F-CPU sees only its own side of the coupler. The F-parameter assignment on the far-side F-I/O must be configured in the far-side F-CPU's HW Config and propagated through the coupler's process image. Key field-proven caveats:

  • The DP-DP coupler does not modify F-addresses. The F-source and F-destination addresses are local to each F-CPU and must be assigned independently on both sides.
  • PROFIsafe telegrams do not pass through the DP-DP coupler. The coupler is a non-safe router; the F-CPU on the far side of the coupler terminates the PROFIsafe protocol on its own F-I/O. If the 412-2 PN is the F-CPU for the far-side F-I/O, it must have its own F-parameters and its own F-signature.
  • The DP-DP coupler must be assigned a PROFIBUS diagnostic address on each side. Mismatches cause intermittent BF events and can trigger F-communication errors if the F-monitoring time is tight.
  • Always power-cycle the DP-DP coupler after an F-parameter change on either side; the coupler's internal address table is non-volatile but it is cached in RAM and may hold a stale address for one cycle.

8. Common Edge Cases and Multi-CPU Setups

8.1 Mixed F and Non-F I/O on the Same DP Subnet

Standard PROFIBUS slaves and F-slaves can coexist on the same subnet, but the F-CPU's PROFIsafe address range must not overlap with any non-F PROFIBUS address. STEP 7 will warn about address overlap at compile time; ignore the warning only if the addresses are explicitly verified.

8.2 Two F-CPUs Sharing One F-I/O Station

If the 416F-2 and the 412-2 PN both need to read a single F-input module (e.g., a shared ET 200S F-station), only one F-CPU can own the F-destination address for that module. The other F-CPU reads the input as a standard input via the DP-DP coupler or via shared input. Configuring both as PROFIsafe masters to the same F-slave will cause F-parameter assignment errors on both CPUs.

8.3 Online Editing of F-Blocks

STEP 7 allows online editing of F-FBs only if the F-runtime supports it (CPU firmware V6.0 or later on 416F-2). Even then, the F-signature will change and the CPU will enter STOP on the next restart until the offline project is recompiled and downloaded. Always perform F-block modifications offline.

8.4 Backup Battery Low on the F-CPU

A low backup battery on the 416F-2 can cause the F-CPU to lose the stored F-signature on power-down. The diagnostic buffer will show a battery event combined with a signature-mismatch event. Replace the backup battery, re-download the safety program, and re-validate.

8.5 Firmware Mismatch Between the 416F-2 and the 412-2 PN

The 416F-2 (firmware V6.0.7 or later) and the 412-2 PN (firmware V3.x) are typically compatible via PROFIBUS DP, but the PROFIsafe profile version must match. If the 412-2 PN runs PROFIsafe V2.4 and the 416F-2 expects V2.6.1, the F-startup will fail with event ID 16#7530. Upgrade the partner CPU firmware to a version that supports the same PROFIsafe profile, or adjust the F-parameter profile in HW Config (Properties > F-Parameters > Profile). See the PROFIsafe profile and system description for the compatibility matrix.

9. Preventive Best Practices

  1. Always download HW Config before the safety program when modifying F-I/O assignments. Use STEP 7's Download to Target > Hardware and Software option for bulk changes.
  2. Document every F-signature change in the safety change log. The F-signature is the audit trail for IEC 61511 compliance.
  3. Reserve a contiguous block of F-destination addresses for each F-station (e.g., 100-199 for ET 200S station 1, 200-299 for station 2). This prevents address collisions when stations are added.
  4. Set F-monitoring time to 2-3x the worst-case PROFIBUS cycle on every F-channel. For a DP-DP coupler with a 10 ms cycle, use 200-300 ms.
  5. Periodically export the diagnostic buffer (monthly) and archive it. F-events with timestamps are the only way to correlate intermittent F-communication issues with field disturbances.
  6. Use the F-Compile Editor's "Check Consistency" function before every download. It catches F-address and signature issues that the standard STEP 7 compiler does not check.
  7. Train field service engineers on the difference between standard and F-blocks. A common mistake is to copy an F-DB from one station to another, which silently copies F-address assignments and causes collisions on the new station.
  8. Maintain a separate F-parameter spreadsheet outside the STEP 7 project. STEP 7 projects can be archived and modified; the spreadsheet is the authoritative reference for the as-built F-parameter list.

10. Quick Reference: Event ID to Action Matrix

Event ID F-LED CPU State First Action Second Action
16#7520 SF on STOP Check F-source address in HW Config Reassign if duplicate
16#7521 SF on STOP Check F-destination address on new F-module Reassign unique address
16#7522 SF on STOP Check F-monitoring time value Set to > 2 * bus cycle
16#7524 SF on STOP Recompile safety program Re-download HW Config and F-blocks
16#7530 SF + BF on STOP or RUN Check PROFIBUS cable and termination Increase F-monitoring time
16#75E1 SF on STOP Verify F-signature match (offline vs online) Download safety program in offline mode
16#75E2 SF on STOP Recompile F-runtime group Re-download F-FB and F-DB
16#79xx SF on STOP Check slot assignment of F-module in HW Config Verify physical module is seated

11. Related Siemens Documentation

For deeper reference, consult the official Siemens support documentation:

12. Frequently Asked Questions

Why does my CPU 416F-2 go to STOP immediately after I add a new F-input address?

The F-CPU performs a startup check that validates the F-signature, the F-source/destination addresses, and the F-monitoring time. If the new F-input address is not consistent with the downloaded HW Config, or if the F-Compile Editor was not run after the change, the F-startup fails and the CPU enters STOP with a 16#75xx diagnostic event. Download HW Config first, recompile the safety program, then download the F-blocks before transitioning to RUN.

Do I need to download HW Config every time I add a new F-channel?

Yes. Any change to an F-module's channel assignment, F-destination address, or F-monitoring time is a hardware configuration change. The F-CPU compares the in-memory F-parameter set against the F-parameter set in the compiled safety program on every restart. A mismatch forces the CPU to STOP. Use STEP 7 "Download to Target > Hardware Configuration" to push the HW Config, then download the safety program.

What F-monitoring time should I use with a DP-DP coupler?

Set the F-monitoring time to at least 2 times the worst-case PROFIBUS cycle time plus the DP-DP coupler latency. With a 10 ms PROFIBUS cycle and a 3 ms coupler latency, 150-300 ms is typical. Values below 100 ms on a DP-DP coupler link frequently cause event ID 16#7530 "PROFIsafe communication error" events. See the S7-400F/FH manual section on DP-DP coupler for the exact calculation.

Can two F-CPUs share the same F-input module through a DP-DP coupler?

No. A PROFIsafe slave has a single F-destination address and is owned by a single F-CPU. The second F-CPU can read the input as a standard (non-safe) input by routing it through the DP-DP coupler, but the F-IO must be configured and parameterized by only one F-CPU. Configuring two F-CPUs as PROFIsafe masters for the same F-slave will cause F-parameter assignment errors on both CPUs.

How do I find the F-signature of my 416F-2 online?

Open STEP 7 online, right-click the F-CPU, and select "F-Compile Editor > View > Signatures". The online F-signature is reported in the F-CPU's flash memory and must match the offline F-signature in the STEP 7 project. A mismatch indicates that the safety program was changed online (or that the backup battery failed and the signature was lost). Recompile offline and re-download to restore consistency.

Is event ID 16#7530 always a hardware problem?

No. Event ID 16#7530 ("PROFIsafe communication error") can be caused by an F-monitoring time that is too short, by PROFIBUS cable/termination faults, by a DP-DP coupler reset, or by an F-source/destination address conflict. Check the bus topology and termination first, then verify the F-monitoring time, then re-check the F-addresses. The diagnostic buffer will typically contain 2-3 entries in sequence that pinpoint the actual cause.

Back to blog