Resolving SIMADYN D 'C' Fault on PM6 CPU2 Excitation Racks

David Krause14 min read
PLC HardwareSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving SIMADYN D 'C' Fault on PM6 CPU2 Excitation Racks

The Siemens SIMADYN D control platform is widely deployed in Chinese power-generation plants as the digital regulator for static excitation systems. Field experience across dozens of hydro and thermal units shows a recurring, often winter-clustered 'C' fault on the PM6 CPU2 of the secondary channel, frequently cascading to the SS4 communication modules and the SS52 Profibus gateway on the companion CS7 communication card. The fault may clear on power-cycle and dust cleaning, or it may persist until the affected module is replaced. This reference consolidates the diagnostic procedure—D7-SYS / CFC online error capture, HEX/Debug Monitor extraction, and the offline fallback when CPU serial access is dead—together with the environmental and hardware mitigations that drive fault frequency down to near zero in properly conditioned cabinets.

1. SIMADYN D Architecture in Dual-Channel Excitation

SIMADYN D is a multiprocessor, modular real-time controller from the Siemens SIMADYN family. In excitation service it is configured as a hot-standby, dual-channel regulator: each channel runs independently, exchanges status over a dedicated SS4 cross-link, and shares a process database with an OP operator panel and an external Profibus monitor.

1.1 Typical Rack Population (24-Slot Subrack)

Slot Range Module Qty Function
CPU slot PM6 2 CPU1 / CPU2 processors; main regulation tasks
COM slot CS7 2 Communication master; hosts SS4 / SS52 daughter cards
Daughter on CS7-A SS4 3 (a) PG/PC Struc G/L or D7-SYS debug link
(b) Cross-channel link to other rack
(c) OP operator panel link
Daughter on CS7-B SS52 1 Profibus DP gateway to external monitoring / SCADA
I/O slots IT41 / IT42 / EA12 etc. various Analog in, binary in, analog out, binary out, encoder

1.2 Communication Paths That the 'C' Fault Touches

  • PM6 X01 (local serial) — direct PG/PC port for DUST1 cable and online CFC. This is the only path that survives the 'C' fault when CS7/SS4 stacks drop.
  • SS4 ↔ SS4 cross-link — inter-channel synchronization and warm-standby arbitration. Loss of this link is the most common visible symptom of a PM6 'C' fault.
  • SS4 → OP — operator panel and alarm annunciator. Goes blank or freezes.
  • SS52 → Profibus DP — external monitor, plant DCS, and event/SOE recorder. Drops off-line; DCS sees a station-level communication failure.

The full system base manual with parameter letter codes (H/L for read-write, c/d for read-only) and a/b/c/d parameter-number ranges is published by Siemens as the SIMADYN D System Manual (dyn_system_e.pdf) on the Siemens Industry Online Support portal; refer to its parameter-coding section whenever you need to interpret a tag returned by D7-SYS in the error panel.

2. Defining the 'C' Fault

The letter 'C' is the PM6 firmware class code for Communication-class exceptions raised by the run-time system when a configured mailbox, sampling, or inter-processor handshake fails. In the SIMADYN D exception taxonomy:

Class Code Meaning Typical Trigger
A Application / user FB Logical fault inside a function block (e.g., divide-by-zero, range violation)
B Boot / startup Configuration checksum, missing firmware, rack ID mismatch
C Communication SS4 / SS52 mailbox timeout, Profibus slave lost, inter-CPU handshake abort
D Diagnostic / hardware RAM parity, watchdog, slot-ID EPROM, dust on backplane

A 'C' fault is therefore not a single root cause but a class of symptoms, all of which surface in the PM6 error fields and exception buffer. The diagnostic task is to read the underlying error code (commonly a 16-bit hex value such as 0x6014) and trace it back to a specific FB, signal, or physical interface.

Field observation: In the Chinese excitation fleet, >80% of 'C' faults eventually resolve to one of three sub-causes — (1) SS4 cross-link cable oxidation, (2) Profibus connector loss on the SS52, or (3) PM6 socket contamination that is unmasked by dry winter air and seasonal HVAC cycling.

3. Root Cause Analysis

Treat every 'C' fault as a four-axis investigation. The cause is almost always a combination of two or more axes.

3.1 Hardware Axis — Contact and Contamination

  • Backplane connector oxidation. PM6 and CS7 use gold-plated DIN-41612 connectors; dust combined with low humidity creates a non-conductive film that breaks high-speed mailbox strobes.
  • SS4 / SS52 socket seating. Daughter cards can walk out of their CS7 host by 0.5–1 mm during thermal cycling, producing intermittent contact loss that the PM6 reports as a 'C' exception.
  • PM6 EPROM / NV-RAM retention. A weak NV-RAM battery corrupts the configuration signature, leading to a B-class on boot but a C-class on mailbox re-initialization when the CPU reaches run state.

3.2 Environmental Axis — Temperature and Humidity

  • Winter clustering. Indoor static-charge spikes (often <30% RH) and cabinet heater cycling cause both ESD events and connector-film buildup.
  • Summer mitigation. Higher humidity (40–60% RH) maintains a thin conductive film on connectors, paradoxically reducing open-circuit events even though it increases leakage risk in adjacent analog inputs.
  • Dust loading. Coal-handling and hydro-turbine halls deposit conductive particulates (carbon, graphite) that short adjacent backplane pins during high-humidity days and break contact during dry days.

3.3 Configuration Axis — Sampling and Mailbox

  • Mismatched sampling time (T0 / TA). If the receiving task runs faster than the producer, the mailbox queue under-runs and PM6 raises a C-class timeout.
  • Cross-channel task skew. The two PM6 CPUs must be resynchronized; if the SS4 link is slow, the master keeps logging C-exceptions on the slave mailbox.
  • Profibus slave address collision. Adding a new SS52 slave without re-addressing can produce C-class on the SS52 transmit side only.

3.4 Firmware Axis — IBS and D7-SYS Versions

Older IBS releases (pre-5.x) and earlier D7-SYS builds do not expose the full error-panel field set; upgrading the engineering tool is often the difference between an ambiguous 'C' and a precise 0x6xxx fault code with FB reference.

4. Diagnostic Procedure A — D7-SYS / CFC Online Capture

This is the primary procedure and is applicable when the PG/PC can still reach PM6 X01 after the 'C' fault is latched.

4.1 Prerequisites

  • D7-SYS (or Step7 Classic with the SIMADYN D option pack) installed on the PG/PC.
  • DUST1 programming cable (RS-232 to SIMADYN D local service port) or USB-to-DUST1 adapter for newer PGs.
  • Direct connection to PM6 X01 — do not chain through CS7 / SS4 when a 'C' fault is active; the higher-level stacks may already be down.
  • CPU2 chart file (*.sdf or *.dat depending on the Struc G/L vs CFC toolchain) opened locally.

4.2 Step-by-Step

  1. Power the rack normally; do not reset the 'C' fault — the error fields are volatile and are cleared on the next CPU restart.
  2. Connect the DUST1 cable between the PG/PC COM port (or USB-COM bridge) and PM6 X01.
  3. Start D7-SYS, open the CPU2 program, and double-click into any chart to put the editor into online mode.
  4. From the menu, choose CPU → Module Information (in older CFC builds: Target System → Module Information).
  5. In the dialog that opens, switch to the Error fields tab. Record every entry. Typical content:
    Error field 0 :  0x6014   FB=AV44  Sig=QV_FIELD
    Error field 1 :  0x0000
    Error field 2 :  0x0000
  6. Switch to the Exception buffer tab. Scroll through the last 16 exceptions; note the time stamps and the FB chain that triggered the cascade.
  7. Open CFC online Help → Contents → Index; type the 4-hex-digit code (e.g., 6014) to retrieve the fault description and the recommended remedy.
  8. Document the chain in your maintenance log: error code → FB name → I/O tag → physical channel.
Common 0x6xxx class codes seen in the field: 0x6014 = sampling-time violation on a configured connection; 0x6023 = mailbox overflow on SS4 cross-link; 0x6041 = Profibus slave timeout on SS52. Always confirm against the CFC online help index in the version of D7-SYS that matches the rack firmware.

5. Diagnostic Procedure B — HEX/Debug Monitor via IBS

When D7-SYS is unavailable, or when the chart file is in the legacy Struc G/L format and cannot be opened by D7-SYS, fall back to the HEX/Debug Monitor utility inside IBS.

5.1 Launch Sequence

  1. Start IBS and verify COM-port settings (baud, parity, handshaking) match the rack; 19200 8E1 is the most common SIMADYN D default.
  2. From the menu bar: Activities → IBS Program.
  3. From the menu bar: Diagnostics → Start Debug Monitor; when prompted, enter the CPU number (typically 2 for the secondary channel where the 'C' fault is latched).
  4. Close the IBS program cleanly: Service → Exit IBS Program. The Debug Monitor keeps running in the background.
  5. Return to the top-level menu: Activities → HEX/Debug Monitor.

5.2 Reading the Error Panels

  1. At the HEX/Debug Monitor prompt, type ? or dh and press Enter. IBS writes a fresh log file to the IBS working directory as HEX.txt.
  2. Open HEX.txt in any text editor and search for the literal string Diagnostics of the error panels. The line directly below it contains the suggested command, e.g.:
    Diagnostics of the error panels: jm 0x80000F20
  3. Type the suggested command at the HEX/Debug Monitor prompt:
    jm 0x80000F20
    The monitor prints the contents of the error panels. Capture the FB references and the 16-bit error codes, exactly as in Procedure A.
  4. Cross-reference the codes against the SIMADYN D System Manual error-code appendix. The same 0x6xxx codes apply.
Tip: Always keep a rolling archive of HEX.txt files captured at fault time. Trending the same FB appearing across multiple 'C' events is the fastest way to prove a single hardware root cause versus an environmental one.

6. Diagnostic Procedure C — When CPU Communication Is Dead

If the 'C' fault is so severe that PM6 X01 also stops responding, the engineer cannot read error fields in-circuit. The following sequence is the field-proven fallback used by Siemens commissioning engineers in China.

6.1 Physical Checks First

  1. Verify 24 VDC on the rack power supply; an under-voltage of >5% on a heavily loaded rack can cause mailbox strobes to fail before CPU is fully down.
  2. Remove and reseat every SS4, SS52, and the PM6 in question. Inspect the DIN-41612 pins for oxidation, bending, or fiber contamination. Clean with a Siemens-approved contact cleaner (e.g., Cramolin, Kontakt 60) and a lint-free swab; do not use eraser rubbers on gold-plated contacts.
  3. Inspect the backplane under oblique light; even a hairline fiber across two pins can hold a C-class communication line low.

6.2 Card-Swap Triage

Symptom Suspect Module Swap Priority
Cross-channel link lost, OP blank, Profibus still up SS4 on CS7-A 1
Profibus drops, OP and cross-link OK SS52 on CS7-B 1
All COM paths down, CPU STOP / blink PM6 CPU2 1
Intermittent recovery on reseat CS7 host 2

6.3 Off-Line Error Capture

When the 'C' fault has latched but PM6 will still boot to its loader, the loader menu exposes the exception buffer over the same X01 port. Cycle rack power, hold the loader break, and read the exception buffer with the DUMP command from a terminal program (HyperTerminal, PuTTY in serial mode, or Tera Term at 19200 8E1).

6.4 Struc G/L vs CFC Toolchain

Many Chinese excitation installations were originally programmed in Struc G/L, the predecessor of CFC. Struc G/L programs (*.sdf) cannot be directly opened in modern D7-SYS, but the error codes produced are identical because they are generated by the PM6 firmware, not by the engineering tool. The HEX/Debug Monitor route (Procedure B) is therefore the recommended path for any Struc G/L site, with the caveat that the online FB reference name will read as a Struc G/L block name (e.g., AI8, AV44, BIC) rather than a CFC FB name.

7. Error Code Quick Reference

Code (hex) Class Likely Source First Action
0x6014 C Sampling-time / connection violation Reconcile TA in producer and consumer charts
0x6023 C SS4 mailbox overflow (cross-link) Reduce cross-link message count; check SS4 cable
0x6041 C SS52 Profibus slave lost Verify Profibus connector and termination
0x6050 C OP panel link timeout Reseat SS4 (OP); check OP port fuse
0x6102 C CPU-to-CPU handshake abort Check both PM6 NV-RAM batteries; reload firmware
0x6F00 C Generic comm exception (firmware-version specific) Upgrade IBS / D7-SYS; reflash PM6 firmware

This table is derived from field reports on the China excitation fleet; the authoritative description of any code is in the CFC online help of the matching D7-SYS version and in the error-code appendix of the SIMADYN D System Manual.

8. Hardware Mitigation and Environmental Controls

The single largest reduction in 'C' fault frequency is achieved by attacking the environmental axis while the diagnostic axis is being run.

8.1 Cabinet Environmental Targets

Parameter Target Rationale
Cabinet temperature 18–28 °C year-round Limits thermal cycling that unseats daughter cards
Relative humidity 35–55% RH Maintains a thin conductive film on connectors without leakage
Dust loading < ISO 14644-1 Class 7 Eliminates conductive particulate shorts
ESD floor / wrist strap Mandatory at door Prevents installer-induced C-class

8.2 Mechanical Hardening

  • Add card locks to PM6 and CS7. The standard plastic extractors loosen with thermal cycling; Siemens card-lock kits or third-party latches are inexpensive and eliminate 80% of reseat-induced 'C' faults.
  • Replace all SS4 and SS52 retaining screws. Torque to 0.4–0.5 Nm; over-torque warps the host CS7 PCB.
  • Apply a thin bead of dielectric grease on the Profibus D-sub connector at the SS52 to prevent oxidation in humid plant environments. Do not apply grease on the backplane DIN-41612 connectors.

8.3 PM6 NV-RAM and Firmware

  • Replace the PM6 NV-RAM battery every 3 years, regardless of measured voltage. A weak battery at the moment of a 'C' fault will mask the true cause by also corrupting configuration.
  • Maintain a firmware register: record the PM6 firmware version (visible in CPU → Module Information) and the IBS / D7-SYS version that last successfully connected. Mismatches are a leading source of undecodable 0x6F00-class exceptions.

8.4 Preventive Maintenance Schedule

Interval Task
Monthly Visual cabinet inspection; humidity log review
Quarterly Reseat and clean all SS4 / SS52 daughter cards
Semi-annually Full rack power-down, backplane cleaning, connector inspection
Annually Capture a clean HEX.txt baseline; compare against fault-time captures
3 years Replace PM6 NV-RAM batteries; verify firmware version

9. Verification After Repair

After clearing the 'C' fault, whether by reseat, environmental correction, or card replacement, run a four-step verification before returning the unit to service.

  1. Watchdog test. From D7-SYS, force a CPU stop / run transition. Both PM6 channels must come back to RUN within 5 s; any longer indicates a lingering C-class.
  2. Cross-link check. Confirm that the SS4 cross-link LED is steady green on both racks and that the partner CPU is visible in the CFC online browser.
  3. Profibus check. With the SS52, read the slave diagnostic buffer; all slaves must report 0x00 (no diag) and the cyclic exchange must be at the configured baud rate (typically 1.5 Mbps).
  4. OP check. Force a process variable change in the chart and verify the OP reflects it within one OP scan. This proves the SS4 OP link is fully alive, not merely electrically present.
Safety gate: Do not return the excitation regulator to automatic voltage regulator (AVR) mode until all four verification steps pass. A 'C' fault that recovers but leaves a stale cross-link image will appear healthy for tens of seconds and then re-trip on the next heavy load step.

10. Frequently Asked Questions

What does the 'C' fault on a SIMADYN D PM6 mean?

The 'C' class code on a PM6 indicates a communication-class exception raised by the run-time system, typically triggered by SS4 mailbox timeouts, SS52 Profibus slave loss, or inter-CPU handshake aborts. The error-panel capture returns a 4-hex-digit code such as 0x6014 that maps to a specific FB and signal.

Why do SIMADYN D 'C' faults cluster in winter?

Low relative humidity (often <30% RH) inside the cabinet allows a non-conductive film to form on gold-plated DIN-41612 backplane pins, breaking high-speed mailbox strobes. Coal-handling-area dust combined with the dry air creates intermittent open circuits that the PM6 reports as 'C' exceptions. Maintaining 35–55% RH and a regular cleaning schedule eliminates the seasonal peak.

Can I read the error code when the CPU is no longer reachable over CS7/SS4?

Yes. Connect the DUST1 cable directly to the PM6 X01 local service port and use either D7-SYS (CPU → Module Information) or the HEX/Debug Monitor inside IBS. Use the literal string jm 0x800..... shown in HEX.txt to dump the error panels when the chart cannot be opened in D7-SYS.

Does Struc G/L programming prevent D7-SYS from reading the error code?

No. The error codes are generated by the PM6 firmware, not by the engineering tool. Struc G/L sites can use the HEX/Debug Monitor route to capture the same 0x6xxx codes; the only difference is that the FB reference name will be a Struc G/L block name (e.g., AI8, AV44) instead of a CFC FB name. Reference the codes in the SIMADYN D System Manual error-code appendix.

What is the fastest way to confirm a hardware versus environmental 'C' fault?

Capture a clean HEX.txt baseline at known-good state (annually), then trend the FB references and error codes at every fault. If the same FB and the same 0x6xxx code recur across multiple winter events and disappear in summer, the cause is environmental (humidity, dust). If the FB or code changes each event, the cause is most likely a single failing module that should be swapped on suspicion.

Back to blog