S7-300 CPU 315-2DP SF Fault: PROFIBUS DP Diagnostics and Repair
When a Siemens SIMATIC S7-300 CPU 315-2DP (catalog 6ES7 315-2AF03-0AB0 or 6ES7 315-2AH10-0AB0) lights the red SF LED solid while the red BF LED blinks, the system has detected a diagnostic event that the standard cyclic scan cannot clear on its own. In plants where the CPU runs three PROFIBUS DP slaves plus an HMI panel on the integrated DP interface, this combination almost always points at a single failing DP slave or a marginal PROFIBUS cable segment. A temporary CPU restart clears the LED for a few hours or cycles, then the same fault returns — the classic signature of an intermittent physical-layer defect or a slave that is intermittently dropping off the bus.
This guide walks through the diagnostic decision tree when no programming device is on hand, shows how to read the diagnostic buffer through the HMI or a temporary PG, and gives a slave-by-slave isolation procedure to localize the defect. The methodology applies to all CPU 315-2DP variants with order numbers 6ES7 315-2AF0x-0AB0 and 6ES7 315-2AH10-0AB0, firmware V2.0 through V3.3.
1. Problem Definition: Recurring SF with Blinking BF
The reported symptoms are:
- SF LED (red, "System Fault") on solid.
- BF LED (red, "Bus Fault") on the DP interface blinking at 2 Hz.
- One of the three DP slaves had its power or address switch moved from OFF to ON just before the first occurrence.
- CPU restart (STOP/RUN or power cycle) clears the fault temporarily.
- Fault reappears after some operational cycles, never at a fixed interval.
2. SF and BF LED Definitions on the CPU 315-2DP
The CPU 315-2DP carries the standard S7-300 LED set: SF, BF, DC5V, FRCE, RUN, STOP, and MP. The two LEDs relevant to this case are:
| LED | State | Meaning |
|---|---|---|
| SF (red) | ON solid | Diagnostic event active in the CPU. Read the diagnostic buffer. CPU may still be in RUN if the event is a non-fatal diagnostic interrupt from a slave. |
| BF (red) | ON solid | Bus fault on the DP interface (X2). Wiring error, no connection, or address conflict. No slaves are reachable. |
| BF (red) | Blinking 2 Hz | Bus fault on DP, at least one configured slave is not responding. |
| SF solid + BF blink | SF on, BF blinking | A configured DP slave is reporting a diagnostic interrupt or is unreachable. The diagnostic buffer will name the slave's DP address. |
| SF solid + BF solid | Both on | Bus physically down — cable break, missing termination, or master hardware fault. |
Blinking BF with solid SF is the textbook signature of one (and only one) DP slave that has been configured but is not currently reachable, while the rest of the bus is healthy. A solid BF with solid SF would indicate the entire bus segment is down.
3. Why a "DP Switch OFF to ON" Triggers Recurring SF
Moving a switch from OFF to ON on a DP segment hardware is a re-energization event. Depending on what that switch is, the consequences are:
- Power switch on a slave's power supply: The slave is unpowered, then powers up. The master sees a brief "slave missing" event, then a "slave returned" event. If OB82 (diagnostic interrupt OB) is missing from the S7 program, the CPU keeps the SF LED on until the diagnostic buffer is cleared or the OB is added.
- PROFIBUS address switch on the slave: The slave reboots at the new address. If the configured address in HW Config does not match, the master will never see the slave at the new address, and the bus fault becomes permanent for that slot.
- Termination switch on a PROFIBUS connector: Turning termination ON in the middle of a segment (not at the ends) is one of the most common causes of intermittent bus faults. The bus sees a reflection at the mis-terminated node, which intermittently corrupts telegrams. The bus may work for hours, then fail under vibration or temperature change.
4. Root Cause Categories for Recurring SF on CPU 315-2DP
| Category | Probability | Typical diagnostic buffer signature |
|---|---|---|
| Wrong termination ON at a mid-segment node | Very high | "DP slave failure" / "Station failure" entries repeating |
| Loose PROFIBUS connector at one slave | High | "Station failure" then "Station return" pairs |
| Damaged PROFIBUS cable (intermittent break) | High | "Station failure" entries without "Station return" |
| Slave power supply failing under load | Medium | "Slave diagnostic" + "Diagnostic interrupt from slave" |
| Address mismatch (switch moved to wrong position) | Medium | "Slave not found" at expected DP address |
| Shield not bonded / ground loop | Medium | EMC-induced "Station failure" coincident with VFD or welding |
| Slave GSD file version mismatch | Low | "Parameter assignment error" on first scan |
| Master DP interface hardware fault | Low | BF solid, all slaves missing |
| OB82 (diagnostic interrupt OB) missing | Common programmer error | SF stays on after first diagnostic interrupt, even if slave recovers |
5. Accessing the Diagnostic Buffer Without a Programming Device
The user reports that no programming device is available. This is a common field constraint. Several alternative methods exist.
5.1. Method A — Configure the HMI to Display the Diagnostic Buffer
The S7-300 has no built-in web server on the CPU itself. However, the diagnostic buffer can be exposed to any HMI panel (TP177, MP277, KTP, Comfort Panel) by writing a small S7 program block that calls SFC 51 (RDSYSST) and stores the entries in a data block. The HMI then reads the DB and shows the entries in a screen.
This requires the S7 program to be edited in STEP 7 V5.5 SP4 (or TIA Portal V13 SP1) and downloaded. If the HMI was commissioned without this function, the field tech must add it. Sample code structure:
// OB1 — call SFC 51 to read diagnostic buffer
CALL "RDSYSST"
REQ := TRUE
SSL_ID := W#16#0131 // Diagnostic buffer (partial list)
INDEX := W#16#0000 // Read latest entries
RET_VAL := MW 100 // Return / error code
BUSY := M 101.0
SSL_RECORD := P#DB 50.DBX 0.0 BYTE 200 // Destination buffer
Each entry in SSL_ID W#16#0131 is 20 bytes. Up to 10 entries can be read in one call. The DB then contains time stamps, event IDs, and event information formatted for the HMI to display. This is the cleanest permanent solution; it converts a "blind" CPU into a CPU whose faults can be diagnosed by the operator from the HMI.
5.2. Method B — Borrow or Rent a Laptop with STEP 7
This is the fastest path. A laptop with STEP 7 V5.5 SP4 (or TIA Portal V13 SP1 or later with the CPU 315-2DP GSD file) and a USB PC Adapter (6ES7 972-0CB20-0XA0) connects to either the MPI port or the DP port of the CPU. From the STEP 7 menu choose PLC > Diagnostic/Setting > Diagnostic Buffer to read every event, in order, with time stamp and event ID.
Siemens documentation for the diagnostic buffer structure and event IDs is in the S7-300 Automation System manual at Siemens support entry ID 12996906 and in the STEP 7 Online Help. Field engineers can usually find a PG in maintenance, the OEM, or by renting one for a day. Many system integrators keep a dedicated spare PG.
5.3. Method C — Use a CP343-1 IT or Advanced with Web Diagnostics
Some plants have a CP343-1 IT (6GK7 343-1EX30-0XE0) or CP343-1 Advanced (6GK7 343-1GX30-0XE0) with the integrated web server enabled. The web server can be configured to display the diagnostic buffer. This is rare on legacy S7-300 plants and requires that the CP was commissioned with this function active.
5.4. Method D — Use the S7-300's Own LEDs and Operator Actions
Without a PG, the only diagnostic information available is from the LED pattern. The CPU 315-2DP supports the following operator-initiated functions via the mode selector switch:
- MRES: Master reset, clears the diagnostic buffer. Not useful for diagnosis; it destroys the evidence.
- STOP: CPU in stop. Useful to check the wiring without active telegrams. SF will remain on, BF will go off if the bus is OK in stop mode.
Do not use MRES during fault diagnosis. It clears the diagnostic buffer and the cause must then be re-introduced, which is destructive and slow.
6. Step-by-Step Diagnostic Procedure
Execute these steps in order. Do not skip ahead; each step rules in or out one fault category.
- Read the diagnostic buffer using Method A or B above. Note the first 5 entries with time stamp, event ID, and event information. The first entry is usually the most recent fault.
- Identify the slave's diagnostic address in the entry. A typical entry reads "Diagnostic interrupt from DP slave, address X, slot Y, module Z, channel W, event ID …". The address X is the PROFIBUS node number (1 to 125).
- Cross-reference address X to the physical slave by looking at the wiring drawing. If the address is unknown, walk the segment with a PROFIBUS tester (e.g., Softing BC-700-PB) to confirm which physical device is at that address.
- Power-cycle only the identified slave (not the CPU). If SF clears, the slave is the source of the diagnostic event. If SF remains, the cable or connector is the source.
- Swap the PROFIBUS connector at the identified slave for a known-good 6ES7 972-0BA12-0XA0 connector. The most common single point of failure on a working bus is the connector's insulation-displacement contact going intermittent.
- Check the termination switches on every connector in the segment. Exactly TWO terminations must be ON: one at each physical end of the bus segment. Every other connector must have termination OFF.
- Measure the bus with a PROFIBUS cable tester. The expected DC voltage between pins 3 (B, red) and 8 (A, green) of a healthy segment is approximately 1.0 V with termination, 0 V without. A shorted or open segment will read 0 V or 5 V.
- Replace the slave if all of the above are clean. The slave's PROFIBUS interface ASIC may be failing under load.
7. Physical Layer Inspection
The PROFIBUS DP physical layer is RS-485, 9.6 kbit/s to 12 Mbit/s, on a shielded twisted pair with a characteristic impedance of 150 ohms. The standard cable is Siemens PROFIBUS FC (6XV1 830-0EH10 violet for fixed installation, 6XV1 830-0CH10 for trailing). The following table summarizes the limits:
| Parameter | Value | Source |
|---|---|---|
| Baud rate | 9.6 kbps to 12 Mbps | IEC 61158-2 / EN 50170 |
| Topology | Line, terminated at both ends | PROFIBUS DP standard |
| Max nodes per segment | 32 | RS-485 limit |
| Max segment length at 1.5 Mbps | 200 m | PROFIBUS guideline |
| Max segment length at 12 Mbps | 100 m | PROFIBUS guideline |
| Cable characteristic impedance | 150 ohms ±15% at 3-20 MHz | PROFIBUS cable spec |
| Idle bus voltage (A-B) | ~1.0 V DC, A higher than B | RS-485 idle |
| Termination resistance | 220 ohms + 390 ohms pull-up/pull-down | PROFIBUS connector |
| Shield bonding | 360° at every connector, low-impedance to ground | EMC best practice |
Use a PROFIBUS connector with diagnostic LEDs (e.g., the diagnostic repeater 6ES7 972-1AA00-0XA0, or a third-party BC-700-PB tester) to see activity at each node in real time. A node whose LED is dark while the master is polling is the source of the bus fault.
7.1. Termination Rules
Termination must be ON at exactly two points in the entire PROFIBUS network: the physical start and physical end of each bus segment. With three slaves in line, the configuration is:
| Node | Termination | Notes |
|---|---|---|
| CPU 315-2DP (X2) | OFF if not at the physical end, ON if it is | Most layouts place the CPU at one end |
| First DP slave (closest to CPU) | OFF | Mid-segment |
| Middle DP slave | OFF | Mid-segment |
| Last DP slave (furthest) | ON | Physical end |
If any mid-segment slave has termination ON, the bus is mis-terminated. This is the most common single cause of "works for hours, then fails" intermittent faults.
8. Slave-by-Slave Isolation Methodology
If the diagnostic buffer is unavailable, isolate the failing slave by sequential removal:
- Power off slave #1. Note SF/BF state after 30 s.
- If SF/BF remains, slave #1 is not the source. Power it back on.
- Power off slave #2. Wait 30 s. Note SF/BF.
- Repeat for slave #3.
- If SF/BF clears when one specific slave is off, that slave is the source.
Powering off a configured slave will produce a "Station failure" diagnostic event. This is a normal consequence of the test; the goal is to identify which slave is causing the fault when the bus is otherwise healthy. The slave that, when removed, causes the SF/BF to clear is the failing one.
9. Configuration Check: HW Config, GSD, and Slot Mapping
If physical inspection is clean, the next category is configuration. Open the S7 project in STEP 7 and check:
- DP slave addresses in HW Config match the physical address switches on each slave. A slave whose address switch is at 3 but configured as address 5 will never respond.
- Slot assignments match the physical slave. A slot 1 mismatch will produce "Module does not match configuration" diagnostic events.
- GSD file version is correct for the slave's firmware. Siemens typically ships a slave with multiple GSD revisions; using a newer GSD on an older slave can produce parameter assignment errors that manifest as SF.
- OB82 is loaded in the S7 program. Without OB82, the CPU cannot process a diagnostic interrupt and SF stays on indefinitely.
- Watchdog time on the DP master is set appropriately. A watchdog of 10 ms is too short for a 12 Mbps bus with 32 nodes; 100 ms is a safer default.
The OB82 check is critical. If the original S7 program did not include OB82, any single diagnostic interrupt from any slave will leave SF lit permanently until the CPU is restarted. Adding OB82 to the project and downloading it will resolve the "SF returns after every cycle" symptom even if the underlying slave diagnostic event reoccurs.
// OB82 — Diagnostic Interrupt OB (always include in S7-300 programs)
OB82
// Empty body is acceptable; presence of OB82 prevents STOP on diagnostic interrupt
END_OB
10. Affected Hardware and Firmware Versions
The CPU 315-2DP exists in several order numbers relevant to field service:
| Order Number | Work Memory | Interfaces | Firmware Versions | Status |
|---|---|---|---|---|
| 6ES7 315-2AF03-0AB0 | 128 KB | X2 DP, X1 MPI/DP | V2.0, V2.1, V2.2, V2.3, V2.6, V2.7 | Discontinued, service only |
| 6ES7 315-2AF04-0AB0 | 128 KB | X2 DP, X1 MPI/DP | V2.7, V3.0, V3.1, V3.2, V3.3 | Service |
| 6ES7 315-2AH10-0AB0 | 256 KB | X2 DP, X1 MPI/DP | V3.3 only | Service |
All variants share the same diagnostic buffer structure and the same LED behavior. The diagnostic procedures in this article apply uniformly. If the CPU firmware is older than V2.0, consider an upgrade to the latest firmware available for that order number; firmware updates occasionally fix DP master state-machine bugs that cause SF in marginal conditions.
The Siemens support entry ID 12996906 is the S7-300 CPU 31x operating instructions, including firmware update procedures. Firmware updates require a SIMATIC MMC card (6ES7 953-8LF00-0AA0 or larger) and STEP 7 V5.5 SP4 or TIA Portal V13 SP1.
11. Repair Actions
After localizing the fault, execute the appropriate repair:
- Mis-terminated node: Switch the termination OFF on the mid-segment connector. Verify that exactly two terminations remain ON in the segment.
- Loose connector: Re-seat the PROFIBUS connector; if the insulation-displacement contact is damaged, replace the connector (6ES7 972-0BA12-0XA0). Do not crimp the same connector twice.
- Damaged cable: Replace the affected segment with new PROFIBUS FC cable. Do not use generic RS-485 cable; the characteristic impedance must be 150 ohms ±15%.
- Failing slave power supply: Replace the 24 V power supply on the slave. Use a separate 24 V supply for the slave logic and a separate one for the CPU to avoid ground loops.
- Address mismatch: Set the slave's address switch to match the configured value. Cycle power to the slave.
- Shielding or ground loop: Re-bond the cable shield at every connector with a 360° clamp. Verify ground potential difference between nodes is below 1 V AC.
- Failing slave: Replace the slave with a new unit of the same order number and firmware version. Re-import the GSD if needed.
- Missing OB82: Add OB82 to the S7 program and download. This prevents SF from sticking on diagnostic interrupts.
12. Verification Checklist
Before returning the system to production, confirm every item:
| Check | Method | Pass Criteria |
|---|---|---|
| SF LED off | Visual, 1 hour of operation | SF off continuously |
| BF LED off | Visual, 1 hour of operation | BF off continuously |
| Diagnostic buffer clean | Online > Diagnostic Buffer in STEP 7 | No new "Station failure" entries during test |
| Bus voltage | Multimeter at any node, pins 3 and 8 | ~1.0 V DC with termination |
| Termination count | Walk the segment | Exactly two terminations ON |
| All slaves reachable | Online > Accessible Nodes in STEP 7 | All three slaves listed at correct addresses |
| OB82 present | STEP 7 project view | OB82 in the offline and online program |
| EMC environment | Operate for one full production shift | No recurrence during normal operation |
| Shield bonding | Visual and continuity check | Shield bonded at every connector |
| Ground potential | Measure between node grounds | Below 1 V AC difference |
Operate the system for at least one full production shift (8-12 hours) under representative load before closing the work order. Intermittent PROFIBUS faults that have just been repaired frequently recur within the first shift.
13. Frequently Asked Questions
What does a solid SF LED with a blinking BF LED mean on a CPU 315-2DP?
It means a configured DP slave is currently not reachable on the PROFIBUS DP network (X2 interface), or a slave has raised a diagnostic interrupt that has not been acknowledged. The CPU itself is healthy; the fault is in the bus segment or in a slave. Read the diagnostic buffer to identify the slave's DP address.
Can I read the diagnostic buffer of a CPU 315-2DP from the HMI panel?
Only if the S7 program contains a block (typically OB1 or a periodic OB) that calls SFC 51 (RDSYSST) with SSL_ID W#16#0131 and stores the result in a DB, and if the HMI project is configured to read and display that DB. Out of the box, an S7-300 does not expose the diagnostic buffer to the HMI. The fastest path to a working diagnostic view is to add the SFC 51 call to OB1 and configure the HMI to display the DB.
Why does the SF return after every CPU restart?
Because the underlying fault (bad cable, bad slave, missing OB82, mis-termination) is still present. A CPU restart only clears the latched diagnostic event in the buffer; it does not fix the physical or configuration defect. If SF returns after every restart, the fault is not random — it is a real, persistent condition in your bus segment.
What is the difference between the MPI/DP interface (X1) and the DP interface (X2) on the CPU 315-2DP?
X1 is the combined MPI/DP interface, used for connecting programming devices, HMI panels, and DP slaves in mixed networks up to 12 Mbps. X2 is the dedicated DP master interface, used for the high-speed DP segment. The single BF LED reports faults on X2. If your HMI is on X1 and the slaves are on X2, BF blinking indicates a slave on X2 is missing.
Which OB do I need to add to clear SF after a diagnostic interrupt?
OB82 (Diagnostic Interrupt OB). The S7-300 will keep the SF LED lit after a diagnostic interrupt if OB82 is not loaded in the program. Adding an empty OB82 to the project and downloading it to the CPU prevents the SF from sticking. This is one of the most common configuration issues on legacy S7-300 installations.
What is the maximum PROFIBUS segment length for 1.5 Mbps and 12 Mbps?
For 1.5 Mbps, the maximum segment length is 200 m without repeater. For 12 Mbps, the maximum is 100 m. These are hard limits from the IEC 61158 standard. Exceeding them will produce intermittent telegram errors that show up as SF and BF on the CPU. Use a PROFIBUS repeater (6ES7 972-0AA01-0XA0) or OLM to extend.