Resolving Ultramat 23 ELAN Communication Failures to PLC
The Siemens ULTRAMAT 23 (order code 7MB2338-2AK00-3NW1 used here) is a three-channel NDIR gas analyzer deployed in CEMS service on GE 6FA gas turbines. Loss of the analyzer's remote signal to the DCS is almost always traced to the analyzers' serial link to the PLC, not to the upstream PLC-to-DCS layer. This field reference walks through ELAN protocol behavior, the failure modes specific to the 7MB2338 platform, the diagnostic procedure to apply, the spares to stage, and the preventive measures that prevent recurrence.
1. Problem Definition and Boundary
The reported fault presents as follows on a unit that has been in CEMS service since 2010:
- ULTRAMAT 23 local display shows valid gas concentrations (NO, NO2, SO2, CO, CO2, CH4, H2O, O2 per the configured channel map).
- PLC-to-DCS link is healthy (verified independently; tag updates from other analyzers on the same PLC are visible at the HMI).
- Analyzer-specific measurement tags (e.g., NOX, SO2, O2 ppm/corrected) are stale, frozen, or marked bad quality at the HMI.
- No firmware, network, or hardware change was performed at the PLC, DCS, managed switch, or engineering station immediately prior to the loss.
By elimination the fault is inside the ULTRAMAT 23 communication interface or its physical connection to the PLC. The PLC tag database and DCS interface can be ruled out as long as the PLC remains in run mode with the analyzer block not faulted on the engineering side.
EN input is TRUE, and the Simulation bit is FALSE. Many CEMS PLCs were retrofitted with bypass logic; a toggled simulation bit presents the same symptom as a real analyzer fault.2. ULTRAMAT 23 Communication Architecture
The ULTRAMAT 23 platform supports two analyzers' network options, electrically and logically distinct:
| Option | Hardware | Protocol | Topology | Typical Use |
|---|---|---|---|---|
| ELAN (Ethernet LAN over RS-485) | 2-wire or 4-wire RS-485, terminals on the analyzer backplane | Siemens-proprietary master/slave polling protocol | Multi-drop, address 1 to 31, terminated at both ends | Siemens analyzer networks, RS-485 fieldbus |
| PROFIBUS PA / DP | RS-485 (DP) or IEC 61158-2 (PA), 9-pin D-sub or M12 | PROFIBUS DP-V0/V1 or PROFIBUS PA profile 3.02 | Multi-drop, address 1 to 126, terminated and shielded | Plant-wide DCS integration, Siemens PCS 7 |
The 7MB2338-2AK00-3NW1 order code carries the ELAN communication option in this service. Confirm the installed option by reading the analyzer nameplate on the right-hand side of the enclosure (the option suffix decodes to either ELAN or PROFIBUS) before proceeding; the diagnostic paths diverge completely.
2.1 The ELAN Protocol on the 7MB2338
ELAN is a Siemens proprietary serial protocol layered on RS-485. The ULTRAMAT 23 always operates as an ELAN slave; a host (typically a Siemens PLC module or a SIPART DR / ELAN gateway) polls the analyzer. Key parameters:
| Parameter | Factory default | Field-typical value | Notes |
|---|---|---|---|
| Physical layer | RS-485, 2-wire (half-duplex) | 2-wire, occasionally 4-wire | Jumpers on the COM board select 2W/4W |
| Baud rate | 19200 bit/s | 19200 or 38400 | Selected in menu under Communication |
| Data bits | 8 | 8 | Fixed by protocol |
| Parity | Even | Even | No user setting |
| Stop bits | 1 | 1 | Fixed by protocol |
| ELAN address | 1 | 1 to 31 | Must be unique on the segment |
| Handshake | None | None | ELAN does not use RTS/CTS |
| Maximum nodes | 31 | 31 (with repeater up to 124) | RS-485 unit-load limit |
The 7MB2338 only responds when the host issues a command. The Siemens ULTRAMAT 23 operating manual (A5E37100388-003) states: "The unit only transmits data on request with a command message, but always only one command can be processed and answered." This single-command-at-a-time behavior is a common source of intermittent failures: if the PLC issues a second poll before the previous response is received, the analyzer drops both transactions.
2.2 The Menu Function 88 Path
Function 88 on the ULTRAMAT 23 is the on-board communication diagnostics menu. From the analyzer's local display, navigate to Menu → Service → Function and enter code 88. This menu shows:
- Last received command in hex
- Last response transmitted in hex
- Frame error counter
- Parity error counter
- Timeout counter
A non-zero frame or parity error counter, or a frozen last received command field, is the single most useful diagnostic indicator available without external tooling. The EPA-published ULTRAMAT 23 specification confirms that "Funktion 88 permits to call the menu" for communication diagnostics and is the standard Siemens procedure for verifying the link without a laptop.
3. Root Cause Analysis Matrix
The following matrix captures the most frequent root causes observed on 7MB2338 analyzers in CEMS service beyond the standard 5-year duty cycle, ranked by field incidence:
| Rank | Root cause | Typical age to failure | Observable symptom | Diagnostic test |
|---|---|---|---|---|
| 1 | RS-485 termination resistor failure or drift | 8–15 years | Intermittent loss, recovers when cabinet door is opened/closed | Measure termination resistance (120 Ω ± 5%) at both ends with analyzer and PLC powered down |
| 2 | Corroded or loose terminal on the analyzer backplane | 5–12 years | Hard loss, recovers after re-seating connector | Power down, inspect Phoenix/MCS connector for green corrosion, re-torque screws |
| 3 | ELAN COM board electrolytic capacitor degradation | 10–14 years | Hard loss after analyzer warm-up, restores when cold | Monitor Function 88 last-received field; replace COM board (Siemens part 6DR1124-2Gxx or local equivalent) |
| 4 | PLC ELAN master firmware bug or hot-swap event | Anytime | Loss immediately follows PLC firmware change or module replacement | Check PLC event log; verify GSD/FB version matches prior |
| 5 | Shield/ground potential difference (> 1 V) on the RS-485 segment | Anytime | Loss coincident with cooler/heater operation | Measure AC and DC voltage between shield and analyzer ground; must be < 1 V |
| 6 | Duplicate ELAN address on the segment after commissioning | Anytime | Two analyzers go bad simultaneously | Function 88 on each analyzer; verify unique addresses |
| 7 | PROFIBUS/ELAN option mis-configuration (option code mismatch) | Anytime | No TX LED activity on COM board, even with valid frames on the wire | Verify option module in menu; compare to nameplate MLFB |
| 8 | PLC poll rate too fast, violating ≥ 50 ms response window | Anytime after PLC code change | Function 88 increments timeout counter continuously | Verify PLC scan/poll cycle ≥ 100 ms; insert OB1 cycle-time check |
| 9 | RS-485 transceiver failure in PLC module (CP 341, CM PtP, ET200S 1SI) | 8–12 years | Loss of all devices on that port, not only the analyzer | Loop-back test on the PLC port; swap with known-good module |
| 10 | Analyzer internal mainboard failure pulling the segment down | 12–15 years | All devices on segment fail simultaneously, segment is shorted | Disconnect analyzer from segment; verify segment recovers |
4. Diagnostic Procedure (Step-by-Step)
- Verify the local display reads correctly. A green status LED on the front panel and a non-zero, non-frozen concentration value confirms the optical bench, sample conditioning, and analyzer CPU are healthy. If the local display is also bad, the fault is upstream of the COM board (power supply, mainboard, IR source) and must be resolved before chasing the link.
- Open Function 88 on the analyzer. From the local keypad, navigate Menu → Service → Function → 88. Record: last received command, last response, error counters, and the value of the RS-485 echo on the wire. The manual A5E37100388-003 has the full menu map on page 145 (ELAN and PROFIBUS sections).
- Inspect the analyzer COM LEDs. With the cover removed, the ELAN option board has a TX and RX LED. A continuously lit or rapidly blinking TX LED with no RX indicates the analyzer is transmitting unprompted (incorrect) or the host is not polling. No TX and no RX indicates a hardware failure of the COM board or its host link.
- Measure the RS-485 segment electrically. Power down the analyzer and the PLC. At each end of the segment, measure resistance across the data pair (D+ / D-). The reading should be 60 Ω with 120 Ω termination at both ends (parallel combination). Open readings indicate a missing or open termination; readings near 0 Ω indicate a short in the cable, a connector, or a transceiver.
- Check shield bonding and ground potential. With both ends powered, measure AC and DC voltage between the cable shield at the analyzer end and the analyzer chassis ground. Voltages above 1 V AC or any DC offset above 0.5 V cause RS-485 receiver errors. Bond the shield to ground at one end only (typically the PLC end) to break ground loops; leave the analyzer end floating through a 100 nF / 10 MΩ parallel network if recommended by site practice.
- Capture traffic with an RS-485 monitor. Use a portable serial analyzer (e.g., AnyBus X-gateway, M&B Technologies RS-485 sniffer, or a laptop with a USB-to-RS-485 adapter) connected as a passive tap. Verify that the PLC is actually issuing ELAN frames addressed to the configured analyzer address. If no frames appear, the PLC program or its COM port is the fault. If frames appear and the analyzer does not respond, the COM board is the suspect.
- Verify ELAN address uniqueness. Walk to every other analyzer on the RS-485 segment and check its address. A duplicate address produces silent arbitration failure with no LED activity on either device.
- Verify the PLC poll discipline. The Siemens ULTRAMAT 23 requires the host to wait for the response before issuing the next command. The FB / function block in the PLC must include a response-received flag before retriggering the read. A common bug introduced during PLC code edits is to retrigger on a simple cyclic timer. Re-check the OB1 cycle time and the FB instance call interval; both should be no faster than 100 ms for ELAN.
- Power-cycle the analyzer. After all the above, perform a full power-down of the analyzer (not just the display) for 60 seconds. This forces a full re-initialization of the COM board. Many intermittent ELAN link faults clear on a hard reset, which provides diagnostic information even if the fault returns later.
- Substitute the COM board. If all of the above checks pass and the analyzer still does not respond, replace the ELAN option board. On the 7MB2338 this is a plug-in module accessible from the front after loosening the bezel screws; the user does not need to disturb the IR bench, sample lines, or calibration.
5. Hardware Replacement Strategy
For a 2010-vintage analyzer in 2024 service, the following parts should be on the shelf for the 7MB2338-2AK00-3NW1:
| Part / MLFB | Description | Lead time | Stocking guidance |
|---|---|---|---|
| ELAN option board (6DR1124-2G series or current equivalent) | RS-485 ELAN communication module for ULTRAMAT 23 | 4–12 weeks (Siemens) | 1 minimum, 2 if analyzer is a regulatory-critical CEMS asset |
| A5E37100388-003 (operating manual) | Current revision operating instructions | PDF, immediate download | 1 printed binder per site |
| Phoenix / Wago 231-303/xx series connector | RS-485 backplane terminal | Stock | 4 spare connectors |
| 120 Ω 0.25 W termination resistor | RS-485 segment termination | Stock | 10 pieces |
| ULTRAMAT 23 mainboard (C79451-A3494-Bxxx or successor) | CPU and IR driver board | 8–16 weeks | Not stocked by most sites; if stocked, 1 piece |
| IR source module | Replacement IR emitter | 4–8 weeks | 1 piece if analyzer is on 24/7 duty |
| O2 paramagnetic cell (if fitted) | Replacement O2 sensor | 4–8 weeks | 1 piece only if the unit has the O2 option |
6. PLC-Side Configuration Notes
For the ELAN-equipped 7MB2338 the PLC side typically uses one of:
- S7-1200 with CM 1241 RS-485: User-programmed USS or generic free-port FB, or vendor library block (Siemens does not ship a native ELAN library for the S7-1200; third-party libraries from Siemens Industry Online Support partners or the local Siemens representative are used).
- S7-300 / S7-400 with CP 341 / CP 441: Siemens ELAN loadable driver is available under the CP 341 / CP 441 driver collection; the loadable driver uses function block FB ELAN / FB ELEM.
- S7-1500 with CM PtP RS-485: No native ELAN driver is shipped; user must implement framing in a similar way to the S7-1200 path.
Verify the following PLC-side parameters exactly match the analyzer:
- Baud rate: 19200 (or 38400, depending on the analyzer's menu setting).
- Parity: even.
- Data bits: 8.
- Stop bits: 1.
- Protocol framing: ELAN (not USS, not Modbus, not PPI).
- ELAN address of the analyzer: matches the value in Menu → Configuration → Communication → Address.
- Initial response timeout: ≥ 200 ms (ELAN is slower than PROFIBUS; default 50 ms is too aggressive).
6.1 ELAN Command/Response Framing
An ELAN request to read a measured value follows the Siemens frame format. The host sends an address byte, a function code, a parameter index for the value to be read, and a checksum. The analyzer responds with the value, status flags, and the same address. The exact byte sequence is documented on page 145 of the operating manual (A5E37100388-003). When implementing a custom block, treat the address, function, and checksum as fixed by the analyzer; only the parameter index and the response payload vary.
7. Verification Procedure
After the analyzer-side or PLC-side fix, verify end-to-end as follows:
- Power the analyzer and PLC; allow 10 minutes for the IR source to stabilize.
- From the local display, confirm the concentration reading is updating and within range of a span gas check.
- Open Function 88 on the analyzer. Trigger a poll from the PLC. Verify the last received command field updates and the error counters do not increment.
- On the PLC, observe the raw input bytes (using a watch table in TIA Portal or STEP 7). The response from the analyzer must be visible and must match the request's parameter index.
- On the DCS HMI, force a tag refresh. The analyzer tags must update within one scan cycle and must show good quality.
- Run a span check at the analyzer; verify the corresponding HMI value tracks the local display within 2–3% of reading.
- Run a 24-hour soak test. Poll the analyzer continuously and verify the timeout counter at Function 88 remains at zero or its prior baseline.
8. Preventive Measures and Reliability Improvements
For a CEMS-critical analyzer on a 6FA gas turbine, a multi-layer reliability program is appropriate:
| Interval | Task | Outcome |
|---|---|---|
| Monthly | Verify Function 88 error counters; trend in maintenance log | Detects early RS-485 signal degradation |
| Quarterly | Inspect RS-485 connector terminations for corrosion; re-torque | Prevents cold-solder and oxidation faults |
| Quarterly | Measure shield-to-ground voltage at analyzer end | Catches ground-loop drift before it causes errors |
| Annual | Replace desiccant / membrane dryer in sample line | Prevents moisture damage to optical bench and COM board |
| Annual | Full CGA calibration with EPA-protocol gases (NO, NOx, SO2, CO, CO2, O2) | Verifies measurement performance and CEMS compliance |
| 3 years | Replace analyzer internal backup battery (where fitted) | Prevents parameter loss on power-down |
| 5 years | Replace IR source module proactively | Source degrades 8–12% per 1000 h; scheduled replacement prevents unplanned loss |
| 5 years | Replace O2 paramagnetic cell (if fitted) | Cell life is approximately 5–7 years in CEMS service |
| 8 years | Proactively replace the ELAN option board (capacitor-limited) | Avoids mid-cycle unplanned loss; aligns with electrolytic-cap aging |
| 10 years | Begin end-of-life planning: budget for analyzer replacement or major overhaul | 2010-vintage analyzers should be scheduled for replacement by 2025–2030 |
For the network layer specifically:
- Add a redundant PLC tag with a quality flag; alarm on the bad-quality condition within 60 seconds. This is the most important software safeguard.
- Add a maintenance screen on the HMI that displays the Function 88 counters from the analyzer, refreshed every minute, with a trip alarm on any non-zero counter.
- Move from ELAN to PROFIBUS DP if a planned outage is available; ELAN is a legacy Siemens protocol and is increasingly hard to support. PROFIBUS DP allows integration into PCS 7 with standard diagnostics.
- Use a managed switch / RS-485 repeater with line diagnostics, where feasible, to trend signal quality over time.
- Add an RS-485 line isolator at each analyzer end to break ground loops; inexpensive industrial-grade isolators (Phoenix Contact PSR-ME-485 or similar) significantly improve CEMS-segment reliability in turbine hall environments.
9. Safety and Regulatory Considerations
The ULTRAMAT 23 in CEMS service on a 6FA gas turbine is a regulatory-monitored analyzer. Any communication outage that prevents remote monitoring is a deviation under most jurisdictions' CEMS rules (40 CFR Part 75 in the US, similar regimes in EU/UK/MENA). The following should be observed:
- Report the data-loss event to the environmental compliance officer per the site's CEMS quality assurance plan.
- Follow the site's CEMS data substitution procedures (e.g., conservative substitute value, max potential, or zero, depending on the pollutant and the regulatory regime).
- Restore remote monitoring within the time window required by the local permit (typically 24–72 hours for full restoration).
- Do not perform a field repair inside the optical bench or sample system while the analyzer is in service. Isolate the analyzer from the sample, vent, and power before opening the optical bench.
- Cap all open gas sample lines to prevent ambient air ingress; even brief exposure of the bench to ambient moisture can damage the IR source.
10. Quick Reference: Fault-to-Action Map
| Symptom | First check | If failed |
|---|---|---|
| Local display bad, no comms | Power supply, fuses, IR source | Replace mainboard or IR source |
| Local display good, no comms, no TX LED | Function 88, verify ELAN option fitted | Replace ELAN option board |
| Local display good, no comms, TX LED on, no RX LED on PLC | PLC port configuration, baud/parity/address | Re-load PLC FB or check port hardware |
| Local display good, intermittent loss, error counter incrementing | RS-485 termination, shield bonding | Replace termination, add line isolator |
| Local display good, Function 88 last-received frozen for > 5 min | PLC is not polling; check OB1, FB, scan time | Fix PLC program; do not retrigger before response |
| Multiple analyzers on the segment fail simultaneously | Segment wiring, PLC port, RS-485 short | Check PLC RS-485 transceiver, check segment for short |
11. Frequently Asked Questions
What protocol does the Siemens ULTRAMAT 23 (7MB2338-2AK00-3NW1) use by default?
The 7MB2338 supports either ELAN (Siemens proprietary RS-485 protocol) or PROFIBUS PA/DP, depending on the fitted option module. The -NW1 suffix in the order code indicates the ELAN option; the analyzer operates as an ELAN slave at 19200 bit/s, 8E1 by default, on a 2-wire RS-485 segment. See the operating manual A5E37100388-003 for the full parameter set.
Why does the ULTRAMAT 23 stop responding on the ELAN link after a PLC code change?
Two causes are typical. First, the PLC poll function block may be triggering on a fixed timer rather than on a response-received flag, violating the "one command at a time" rule documented on page 145 of the operating manual. Second, the port configuration (baud, parity, stop bits, ELAN address) may have been overwritten by the code change. Open Function 88 on the analyzer to confirm the analyzer side is intact, then inspect the PLC FB and port configuration.
How do I verify the RS-485 segment is healthy without disconnecting the analyzer from service?
Use Function 88 on the analyzer's local display to read the last received command, last response, and the frame / parity / timeout error counters. A non-zero or steadily incrementing error counter is the first sign of segment degradation. For an electrical check, measure the parallel resistance of the two termination resistors with the segment powered down; the reading should be 60 Ω with 120 Ω terminations at both ends. Anything below 50 Ω or above 80 Ω indicates a missing or shorted termination.
Can the ULTRAMAT 23 be upgraded from ELAN to PROFIBUS in the field?
Yes. The ELAN option board and the PROFIBUS PA option board are mechanically interchangeable on the 7MB2338. A field swap requires opening the analyzer, replacing the option module, changing the option code in the analyzer menu, and updating the PLC GSD file and tag database. The PLC will also need the new PROFIBUS slave address configured. Plan a 4–8 hour outage; budget for one full day if the site is unfamiliar with PROFIBUS commissioning.
What is the expected service life of a ULTRAMAT 23 in CEMS service on a 6FA gas turbine?
With preventive replacement of the IR source every 5 years, the O2 cell every 5–7 years, and the ELAN option board every 8–10 years, the analyzer is realistically good for 12–15 years of 24/7 service. A unit commissioned in 2010 is at the end of its economic life; budget for replacement rather than another major overhaul. Plan the replacement to coincide with the next major turbine inspection to avoid separate outage cost.