Problem Overview
The Siemens RF180C (order number 6GT2002-0BA00) is a PROFINET communications gateway for the SIMATIC RF300 family of industrial RFID readers. When commissioning an RF180C with a SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0) using the official SIMATIC RF300 example project (Entry ID 109483372) under TIA Portal V14, a recurring symptom is the slow synchronous flashing of the front-panel ERR_1 and ERR_2 LEDs while every other LED - LINK, RX/TX, READY, BF - appears normal. This article traces the symptom to its root cause, lays out the diagnostic procedure, and provides the field-proven resolution using the Ident_Profile and Reset_RF300 function blocks of the RF300 function library.
The synchronous slow flash is often misread as a "firmware update in progress" condition because the same pattern is emitted by the loader when an image is being transferred. In steady state, however, the pattern is the RF180C's "reader reset / reader initialize required" indicator. The fix is not to reflash the firmware; it is to drive the readers through their initialization sequence from the S7-1500 application.
Hardware Setup and Part Identification
| Component | Order Number | Description |
|---|---|---|
| CPU 1512C-1 PN | 6ES7512-1CK00-0AB0 | SIMATIC S7-1500 compact CPU with 1 PROFINET interface (2-port switch) and integrated analog/digital I/O. Firmware V2.0 at shipment. |
| RF180C | 6GT2002-0BA00 | SIMATIC RF300 PROFINET communications module, 4 reader ports, M12 7/8" connectors. Hardware FS09, firmware V2.2.1. |
| RF310R reader | 6GT2801-1BA10 / 1BA12 | SIMATIC RF300 read/write device, 1 antenna port, IP67. |
| RF340R reader | 6GT2801-1BA30 | SIMATIC RF300 read/write device, mid range, IP67. |
| RF350R reader | 6GT2801-1BA50 | SIMATIC RF300 reader for harsh environments, IP67. |
| RF360R reader | 6GT2801-1BA60 | SIMATIC RF300 reader with extended temperature range, IP67. |
| RF380R reader | 6GT2801-1BA70 | SIMATIC RF300 reader, mid-range, IP67. |
For the S7-1500 CPU 1512C-1 PN, the article number 6ES7512-1CK00-0AB0 is the original V2.0 release. Successor part numbers such as 6ES7512-1CK01-0AB0 and 6ES7512-1CM02-0AB0 carry different firmware versions and a different system behavior, so be aware of the part number when cross-referencing TIA Portal projects. The example project 109483372_SIMATIC_RF300_RF180C_S7-1500.zip is published for the original V2.0 firmware and runs unchanged on later firmware revisions when recompiled.
For the RF180C, the order number 6GT2002-0BA00 corresponds to hardware revision FS09 (visible in TIA Portal as "Hardware version 9"). The GSDML file used in the project is GSDML-V2.32-Siemens-RF180C-20150826.xml or later. The current firmware at the time of this article is V2.2.1; the device ships with V2.0 from the factory and is upgraded in the field by TIA Portal when the project is downloaded.
Understanding the RF180C LED Array
The RF180C front panel exposes six status LEDs that provide a complete picture of the module's runtime state:
| LED | Color | Function |
|---|---|---|
| LINK | Green | PROFINET port 1 / port 2 link status. Steady ON = link up, OFF = no link. |
| RX/TX | Yellow | PROFINET traffic. Flickers with every frame. |
| READY | Green | Module ready. ON = OK, OFF = module in startup or defective. |
| BF | Red | PROFINET bus fault. ON or flash = no cyclic IO, wrong device name, cable fault. |
| ERR_1 | Red | Reader error group 1 (ports 1 and 2). |
| ERR_2 | Red | Reader error group 2 (ports 3 and 4). |
The ERR_1 and ERR_2 LEDs follow the truth table below (per the RF180C operating instructions, document BA_RF180C_76):
| ERR_1 | ERR_2 | Meaning |
|---|---|---|
| OFF | OFF | All reader channels OK. |
| Slow flash | OFF | Error on reader port 1 or 2 (cable break, reader missing, reader in fault). |
| OFF | Slow flash | Error on reader port 3 or 4. |
| Slow flash | Slow flash | Firmware update active OR all four readers need a reset / initialize. |
| Fast flash | Fast flash | Severe module fault; read the diagnostic buffer. |
| ON | ON | Module defective. Replace. |
The pattern observed in the source article - slow flash on both ERR_1 and ERR_2 in phase - is therefore either an in-flight firmware update or a collective "reader reset required" state. After a firmware update completes, the loader returns the module to OPERATE and the ERR LEDs are cleared by the S7-1500 application issuing a reader reset.
Root Cause Analysis
The RF300 protocol is a "command-driven" protocol: the reader does not enter OPERATE state on its own. The S7-1500 application must explicitly bring each attached reader into OPERATE state by issuing one of the following commands through the RF180C:
- A "RESET" command via the
RESET_RF300FB (or its newer equivalent in the Ident_Profile FB). - An initialization sequence via the
Ident_ProfileFB (FB 13650 in the RF300 library). - A power-cycle of the reader's 24 V supply.
When the example project (Entry ID 109483372) is downloaded to the CPU 1512C-1 PN, the application program contains the Ident_Profile FB and a reset routine. The reset routine, however, is only effective after the application has been started and the OB1 cycle has executed. If the download finished, the CPU is in RUN, and the ERR_1 / ERR_2 LEDs are still slow-flashing, the application is not reaching the reset call - either because:
- The cyclic OB1 is not calling the reset FB (FB removed from the call tree).
- The Ident_Profile FB has the wrong HW identifier (LADDR is a per-port identifier, not a per-module identifier).
- Two Ident_Profile FBs are racing for the same port (duplicate instance DBs).
- The "RF300 / Ident system" HSP is not installed and the FB is a placeholder.
- The RF180C has just been firmware-upgraded, the reset is queued, and the next reset call will clear the LEDs.
The "Firmware V2.0 / Hardware V7.0" offline vs. "Firmware V2.2.1 / Hardware V9.0" online mismatch reported in the source is the smoking gun for a completed firmware upgrade. The user correctly identified this via the device properties in TIA Portal, but misattributed the cause - the RF180C's bootloader is the component that emitted the synchronous slow flash, but the bootloader is now finished and the reader initialization is now the responsibility of the S7-1500 application.
Diagnostic Procedure
Use the following ordered checklist to isolate the root cause of the ERR_1 / ERR_2 slow flash.
Step 1 - Confirm the PROFINET layer
Resolve any BF (Bus Fault) LED before interpreting the ERR_1 / ERR_2 LEDs. A flashing or solid BF LED indicates that the RF180C has no PROFINET cyclic IO exchange and the reader LEDs are not meaningful. The BF LED is cleared by:
- Assigning the correct PROFINET device name (use "Online > Accessible devices > Assign PROFINET device name").
- Confirming the IP address is unique and on the same subnet as the CPU's PROFINET interface.
- Verifying the PROFINET cable integrity (M12 D-coded, max 100 m per segment).
- Confirming the GSDML file in the project matches the RF180C's hardware revision (FS09 requires GSDML from 2015-08-26 or later).
Step 2 - Read the diagnostic buffer
Open TIA Portal and navigate to Online > Online & diagnostics > Diagnostic buffer for the RF180C. The relevant event IDs are:
| Event ID | Meaning |
|---|---|
| 0x0301 | Channel error - reader port fault, cable break, or reader missing. |
| 0x0302 | Channel OK - port back to OPERATE. |
| 0x0500 | Reader state change - reader entered / left OPERATE state. |
| 0x0901 | Firmware update started. |
| 0x0902 | Firmware update completed. |
If the most recent event is 0x0901 followed by 0x0902, the firmware update is complete and the next event should be 0x0302 (port back to OK) once the application issues a reset. If no 0x0302 follows, the application has not yet issued the reset.
Step 3 - Inspect the application program
Open the S7-1500 program blocks in TIA Portal and verify that the following are present in OB1 (or a higher-priority cyclic OB):
- One
Ident_ProfileFB per RF180C reader port, each with a unique instance DB. - A "RESET" or "INIT" call at startup, before the first READ or WRITE.
- The LADDR (HW identifier) wired to the correct reader port. The HW identifier is visible in Device view > RF180C > Properties > System constants > HW identifier for each of the 4 ports.
- The reader-specific FBs
READ,WRITE, andRESET_RF300are called only after the Ident_Profile / initialization has returned STATUS = 0.
Step 4 - Watch the LEDs during reset
Force a reset by triggering the FB in the program or by cycling the reader's 24 V supply. The ERR_1 / ERR_2 LEDs should extinguish within 2-3 seconds of the reset acknowledgment. If they remain in slow flash, the reset command was rejected - read the Ident_Profile STATUS output and the diagnostic buffer for the rejection reason.
Solution: Drive the Reader Reset from the S7-1500 Application
The fix is to ensure the S7-1500 application calls the reader initialization FBs. The RF300 function library is part of the "SIMATIC RF300/600 identification system" HSP and is also pre-wired in the example project 109483372.
Required function blocks
| FB | Source | Function |
|---|---|---|
| Ident_Profile | RF300/600 library, FB 13650 (Siemens AG) | High-level command interface for reset, read, write, presence check. |
| RESET_RF300 | RF300/600 library, FB 13150 | Reader reset (cold, warm, factory). |
| READ | RF300/600 library, FB 13160 | Read transponder data. |
| WRITE | RF300/600 library, FB 13161 | Write transponder data. |
Minimum OB1 snippet to clear the ERR LEDs
Insert the following structured text (SCL) into OB1 of the S7-1500. Replace HW_ID_PORT_1 with the system constant for reader port 1 of your RF180C.
// RF180C reader initialization at startup
IF "FirstRun" THEN
"FirstRun" := FALSE;
// Issue cold reset to reader port 1
"iDB_Ident_Profile_P1"(LADDR := "HW_ID_PORT_1",
CMD := 16#01, // RESET command
DOP := 16#00, // Reset mode 0 = cold
ADR := 16#00, // Address 0 = port
DONE => "ix_Done_P1",
BUSY => "ix_Busy_P1",
ERROR => "ix_Err_P1",
STATUS => "iw_Status_P1");
END_IF;
// Cyclic call: poll Ident_Profile for completion
"iDB_Ident_Profile_P1"(LADDR := "HW_ID_PORT_1",
CMD := 16#00, // NOP - poll only
DOP := 16#00,
ADR := 16#00,
DONE => "ix_Done_P1",
BUSY => "ix_Busy_P1",
ERROR => "ix_Err_P1",
STATUS => "iw_Status_P1");
Reset command codes (CMD parameter):
| CMD | Function |
|---|---|
| 0x00 | No command (NOP, used to poll status). |
| 0x01 | RESET - cold start of the reader. |
| 0x02 | READ - read transponder data. |
| 0x03 | WRITE - write transponder data. |
| 0x04 | INITIALIZE - bring the reader to OPERATE state. |
| 0x05 | SET_ANTENNA - antenna on/off. |
The reset mode is set via the DOP parameter for the RESET command:
| DOP (RESET mode) | Function |
|---|---|
| 0 | Cold start - reader reinitializes, all stored tag data cleared from reader memory. |
| 1 | Warm start - reader reinitializes, tag data preserved. |
| 2 | Factory reset - reader returns to factory state. Use with caution. |
Verification of the reset
After issuing the reset, verify the following:
- ERR_1 and ERR_2 LEDs extinguish within 2-3 seconds.
-
STATUSfrom Ident_Profile reads 0x0000 (OK) or 0x0001 (no command active). - Diagnostic buffer shows a new 0x0302 "Channel OK" event for each initialized port.
- A subsequent READ command returns
DONE = TRUE,ERROR = FALSE,STATUS = 0x0000, and a valid transponder UID (4 or 8 bytes depending on the transponder type).
Firmware vs Hardware Version Mismatch
The user observed an offline-online mismatch:
| Property | Offline (TIA project) | Online (RF180C) |
|---|---|---|
| Firmware | V2.0 | V2.2.1 |
| Hardware | V7.0 | V9.0 |
This mismatch is the expected output of a completed firmware upgrade. The RF180C is shipped from the factory with firmware V2.0 and hardware FS07; when the user downloads the project (which targets a newer firmware), TIA Portal prompts to upgrade the firmware to V2.2.1. After the upgrade, the bootloader reports the new firmware version (V2.2.1) and the immutable hardware revision (FS09). The "hardware mismatch" is therefore not a fault - it is a tell-tale that the firmware upgrade has completed.
The user attempted to roll back the firmware to V2.0 using the procedure in Entry ID 51812897 but observed that the hardware version remained at 9.0. This is normal: the hardware revision cannot be downgraded in the field. The user's real complaint, however, was the slow-flashing ERR_1 / ERR_2 LEDs - and that complaint is resolved by driving the reader reset from the S7-1500 application, not by downgrading the firmware.
TIA Portal V14 Project Setup Checklist
Use the following ordered procedure to build a clean RF180C project against the example project 109483372.
- Install TIA Portal V14 (or V14 SP1 if available). Apply the latest updates via Support packages > Siemens Automation > TIA Portal Updates.
- Install the "SIMATIC RF300/600 identification system" HSP via Options > Support packages. Restart TIA Portal after the HSP install.
- Create a new project and add an S7-1500 station with CPU 6ES7512-1CK00-0AB0. The example project supplies the correct device description.
- Add the RF180C (6GT2002-0BA00) to the PROFINET subnet of the CPU. Confirm the GSDML version matches FS09.
- Assign a unique PROFINET device name to the RF180C (e.g., "rf180c-1"). Use the "Assign PROFINET device name" tool from the project tree.
- Open Properties > Module parameters on the RF180C and configure each of the 4 reader ports. Disable any port that has no physical reader attached to avoid spurious channel errors.
- From the project tree, open the S7-1500 program and verify the Ident_Profile FB is present in OB1. The example project pre-wires it; if you re-built the project from scratch, drag the FB from the library.
- Confirm the LADDR input of the Ident_Profile FB is wired to the system constant HW_ID_PORT_1 (or the correct port).
- Compile the project and download to the CPU 1512C-1 PN.
- Watch the RF180C LEDs during download. The ERR_1 / ERR_2 LEDs will slow-flash during the firmware update; once the update completes and OB1 starts cycling the Ident_Profile, the LEDs will clear.
- Use Online > Online & diagnostics > Diagnostic buffer to confirm a 0x0302 "Channel OK" event for each port.
Edge Cases and Field-Proven Pitfalls
1. Wrong HW identifier wired to the FB
The HW identifier is per reader port, not per RF180C module. A project with 4 ports requires 4 separate Ident_Profile FBs (or one FB that addresses all 4 ports in series). The most common error is wiring the LADDR of the RF180C module (which does not exist as a single identifier) to the FB. The FB will return STATUS = 0x8600 (hardware fault) and the LEDs will continue to slow-flash.
2. Two Ident_Profile FBs racing for the same port
If two FBs (e.g., a user-written FB and the example-project FB) are both enabled in OB1 with the same LADDR, the reader will reject the second command and the first will time out. The pattern is identical to the firmware-update pattern: slow-flash ERR_1 / ERR_2. Resolution: comment out or delete the redundant FB instance.
3. TIA Portal V14 with the wrong CPU firmware
The example project 109483372 was built for CPU V2.0. If you are running the project on a CPU 6ES7512-1CK01-0AB0 (V2.1+), the program will download, but the Ident_Profile FB may not initialize correctly because the system constants changed. Re-compile the project to the new firmware (right-click the CPU > "Compile all" with the new CPU as the target).
4. Multiple readers attached to a single port
The RF180C has 4 ports, and each port supports exactly one reader. If you daisy-chain readers on a single port, the second reader will not be detected and the ERR LED for that port group will slow-flash.
5. M12 7/8" power not connected
The RF180C's reader ports are powered by a separate 24 V supply on the M12 7/8" connector. If the 24 V is missing, the readers will not power up and the ERR LEDs will slow-flash. Verify the M12 7/8" cable and the 24 V supply.
6. Long cycle time of the cyclic OB
The Ident_Profile / RF300 FBs have a watchdog time of 100 ms by default. If the cyclic OB has a longer cycle time, the readers will be flagged as "lost" and the ERR LEDs will slow-flash. Solutions: (a) call the FB in OB1 with a higher priority, (b) reduce the OB cycle time, (c) increase the RF180C's watchdog time in Properties > Module parameters > Watchdog.
7. PROFINET name not unique
If two RF180C modules on the same PROFINET subnet have the same device name, the BF LED will flash (not the ERR LEDs) and the cyclic IO will be exchanged with the wrong module. The symptom is readers that "work" in TIA Portal's online view but respond to commands for the wrong port. Resolution: assign a unique device name to each RF180C.
8. Mixed firmware across multiple RF180C modules
If the project contains more than one RF180C and they have different firmware versions (e.g., one V2.0 from the factory, one upgraded to V2.2.1), the firmware-update prompt will be issued for both. After the upgrade, all modules will report V2.2.1 / FS09 online, but only the modules that received the update will have the new firmware loaded. Verify with Online > Accessible devices > Module information that all modules show the same firmware version.
Status Code Reference for Ident_Profile
The STATUS output of the Ident_Profile FB is the primary diagnostic for failed reset, read, and write commands. The most common values are:
| STATUS (hex) | Meaning | Recommended Action |
|---|---|---|
| 0x0000 | Command completed without error. | None - proceed. |
| 0x0001 | No command active (NOP poll). | None - reader ready. |
| 0x7000 | Command is busy, retry poll. | Wait and re-poll. |
| 0x8600 | Hardware fault - LADDR invalid. | Check HW identifier wiring. |
| 0x8601 | Reader not connected. | Check M12 cable and 24 V supply. |
| 0x8602 | Reader not in OPERATE state. | Issue a RESET or INITIALIZE command. |
| 0x8603 | Transponder missing or read error. | Check transponder positioning. |
| 0x860A | Command buffer overflow. | Reduce command rate. |
| 0x8611 | Reader reset in progress. | Wait for DONE = TRUE. |
| 0x8C01 | Internal RF180C fault. | Power cycle the module. |
Frequently Asked Questions
Why do ERR_1 and ERR_2 slow-flash on the RF180C after a firmware update?
The synchronous slow flash is the RF180C's "reader reset required" indicator, not a "firmware update in progress" indicator. The loader has already completed the firmware update; the readers have not yet been initialized by the S7-1500 application. Drive a RESET or INITIALIZE command from the Ident_Profile (FB 13650) or RESET_RF300 (FB 13150) function block in OB1 to clear the LEDs.
Is the firmware version mismatch between offline (V2.0) and online (V2.2.1) a problem?
No. The mismatch is the expected outcome of a completed firmware upgrade. The RF180C ships with firmware V2.0; downloading a project that targets V2.2.1 triggers the firmware upgrade. Once the upgrade finishes, the loader reports the new firmware version (V2.2.1) and the immutable hardware revision (FS09, shown as 9.0 in TIA Portal). Do not attempt to downgrade the firmware to clear the ERR LEDs - the fix is in the application, not the firmware.
Can the hardware version 9.0 be downgraded to 7.0?
No. The hardware revision of a Siemens SIMATIC module is fixed at the factory and cannot be downgraded in the field. The only field-changeable attribute is the firmware version. The "hardware mismatch" in TIA Portal is a display artifact - the project and the device are fully compatible; TIA Portal is showing the firmware-implied hardware revision that came with the upgrade.
Which function block resets the reader - Ident_Profile or RESET_RF300?
Both work. Ident_Profile (FB 13650 in the RF300/600 library) is the modern, profile-based interface and is the recommended block for new projects. RESET_RF300 (FB 13150) is the older, command-based interface and is still supported for legacy projects. If you are using the example project 109483372, the Ident_Profile FB is pre-wired and is the one to drive with CMD = 0x01 (RESET).
How do I tell the difference between a firmware-update flash and a reader-reset flash on the ERR LEDs?
Both patterns are the synchronous slow flash of ERR_1 and ERR_2 at approximately 0.5 Hz. The disambiguator is the diagnostic buffer: a firmware update produces 0x0901 (started) and 0x0902 (completed) events; a reader reset produces 0x0301 (channel error) and 0x0302 (channel OK) events. If the most recent event is 0x0902, the firmware update is done and the next reader reset will clear the LEDs.
Why does the BF LED stay off but the ERR LEDs flash?
The BF LED is tied to the PROFINET cyclic IO exchange. The ERR LEDs are tied to the reader channels. The two are independent: PROFINET can be healthy while the reader channels are uninitialized. If the BF LED is off, the problem is purely on the reader side, and the resolution is the Ident_Profile / RESET_RF300 initialization call described in this article.