1. Problem Profile
An S7-300 PLC acting as the Profibus DP master reports intermittent station failure on a single remote ET200/S7-300 slave rack (rack #23) immediately after the hoist is commanded to lower. The Diagnostic Buffer of the CPU logs a Profibus DP slave failure, OB86 enters, and the HMI simultaneously displays Overweight and Over-Speed alarms. Both alarms originate from normally-closed (NC) safety contacts wired into the digital inputs of the affected rack; the same rack disappears from the cyclic Profibus exchange during the fault window, so the CPU reads the inputs as de-energised (1 -> 0 transition) and the safety logic trips.
Symptoms in the field:
- Fault occurs only during the lower motion (hoist unspooling). Hoist-up, bridge travel, and trolley travel are unaffected.
- Duration of the dropout is short (200 ms - 3 s) but enough for OB86 to enter.
- All four drives on the bus are reachable when the hoist is stationary.
- Replacing the CPU rack with a known-good unit from another crane did not change the failure pattern.
- Rerouting the Profibus cable along a separate tray did not change the failure pattern.
2. Probable Root Causes
| # | Root Cause | Evidence / Indicator | Quick Test |
|---|---|---|---|
| 1 | Regenerative energy from hoist drive injected back onto the DC bus / supply | Fault coincides with hoist-down; torque proving shows negative torque | Inspect drive parameter P1240 / brake chopper threshold |
| 2 | Missing or undersized brake resistor on the hoist drive | DC-link voltage rises above 760 V on a 400 V line | Measure DC-link with isolated scope during lower |
| 3 | Common-mode EMI on the Profibus cable screen | Repeater or slave at far end drops first | Clamp-on EMC probe on PB cable during lowering |
| 4 | Faulty Profibus connector termination (no or double termination) | Reflected waveform on bus monitor | BT200 bus test or ProfiTrace during event |
| 5 | PS307 supply dip on remote rack (inrush from the drive's DC link) | CPU SF/BF lights blink together with PS307 DC OK LED | Oscilloscope PS307 24 V output during lowering |
| 6 | Shielding / equipotential bonding not bonded at both ends on the crane | Screen continuity varies with crane slew | Measure screen-to-ground at every junction box |
| 7 | Drive-to-bus cable parallel run > 1 m without separation | Fault rate increases as cable runs cross | Inspect cable routing, enforce 200 mm separation |
| 8 | Profibus repeater powered from same 24 V bus as drive fan / brake | Repeater drops before the remote slave | Power repeater from a separate PS307 |
3. Drive Regeneration as the Trigger
When a hoist motor is lowered with a heavy load, the load overhauls the motor and the drive operates in regenerative mode. The motor becomes a generator, and the energy flows back into the DC link of the drive. Three things then happen, each of which can knock a sensitive Profibus receiver off-line:
- The DC-link voltage rises. If the drive has no brake chopper or the brake chopper resistor is open, the drive's internal over-voltage controller tries to absorb the energy by ramping the pulses. On a SINAMICS S120 or MASTERDRIVES MC the parameter
p1240(Vdc_max controller) will engage; if disabled, the DC link can exceed 800 V and the drive will trip on F30002 (DC link overvoltage) or F30001. - If a four-quadrant line supply (Active Line Module) is not used, the regen energy is forced back into the line through the rectifier. The line-side current waveform becomes highly distorted and the line-to-line voltage can dip below 0.8 pu for 20 - 100 ms - long enough to sag a 24 V supply on a lightly-loaded PS307.
- The switching events of the IGBTs at the hoist drive inject common-mode currents onto the motor cable. These currents return through any parallel path - including the Profibus screen and the 24 V return - if the bonding is not designed for high-frequency equipotential.
3.1 What to verify on the drive side
- Drive parameter
p1240= 1 (Vdc_max controller enabled). Source: SINAMICS S120/S150 List Manual, parameter description p1240. - Brake chopper threshold
p1271set per drive family (typically 760 V on a 400 V line). Source: SINAMICS S120 List Manual p1271. - Brake resistor resistance matches drive nameplate within +/- 10 %. Open resistor = no regen absorption.
- If multiple drives share a common DC bus, confirm the bus fuses and the DC bus cable gauge are rated for the worst-case hoist regen current.
4. Hardware Audit on the S7-300 Racks
With the Profibus connection acting as the casualty, not the cause, the next step is to harden the receiver hardware.
| Module | Typical Part Number | Check |
|---|---|---|
| CPU 315-2 DP | 6ES7315-2AH14-0AB0 | Firmware >= V3.3; OB86/OB82 fault-tolerant |
| CPU 317-2 DP | 6ES7317-2AK14-0AB0 | Diagnostic buffer entries decoded |
| IM360 (sender) | 6ES7360-3AA01-0AA0 | Seated, backplane connector latched |
| IM361 (receiver) | 6ES7361-3CA01-0AA0 | 24 V supply from PS307 only, no shared return |
| PS307 5 A | 6ES7307-1EA01-0AA0 | DC OK LED stable under hoist-down |
| PS307 10 A | 6ES7307-1KA02-0AA0 | Used when repeater + slave + HMI panel on one PS |
| Profibus connector | 6ES7972-0BA12-0XA0 | Terminating switch ON only at end-of-line slaves |
| Profibus cable | 6XV1830-0EH10 | Characteristic impedance 150 ohm, loop resistance 110 ohm/km |
| RS485 repeater | 6GK1500-0EA02 | Powered from isolated PS307, not from drive aux |
4.1 Power-supply load calculation
Sum the worst-case 24 V current of every module on the affected rack, plus 0.5 A margin. The PS307 5 A (6ES7307-1EA01-0AA0) provides a nominal 5 A at 24 V but derates with input voltage. If the rack current exceeds 3.5 A continuous, switch to the 10 A unit. PS307 hold-up time is approximately 20 ms at full load; a regen-induced sag of > 25 ms will reset the IM361 or the slave CPU.
5. Profibus Physical-Layer Verification
Even a perfect drive cannot crash Profibus if the physical layer is healthy. The Profibus DP cable is a 150-ohm differential transmission line; any mismatch of termination, screen continuity, or common-mode voltage will turn a marginal EMI event into a slave dropout.
5.1 Termination rules
- Terminating resistors ON at exactly two nodes: the physical first and last device on the segment.
- All other nodes: terminating switch OFF. Use the diagnostic LED on the 6ES7972-0BA12 connector - green = segment OK, red = short or break.
- Never put the terminator on a T-connector that is not at a physical end.
5.2 Shielding and bonding
Per SIMATIC Profibus Network Manual, the screen must be bonded to a low-impedance ground at both ends of every segment, with a large-surface clamp (not a pigtail). On a crane, the ground is the conductive structure of the crane itself - confirm continuity with a 4-wire milliohm meter from end to end of the bus, target < 1 ohm.
5.3 Cable separation
Maintain at least 200 mm parallel separation between the Profibus cable and any drive power cable. Crossings should be at 90 degrees. If the cable tray cannot guarantee separation, use double-shielded Profibus cable (6XV1830-0JH10) or run the Profibus inside a grounded steel conduit.
6. OB86 / OB122 Diagnostic Logic in the CPU
The diagnostic buffer entries to look for during the event are:
-
Event ID 0x3931 / 0x3941- Profibus DP: station failure, slave diagnostic -
Event ID 0x3872- Profibus DP: bus fault, repeat count exceeded -
Event ID 0x38C3- Profibus DP: sync fault, retries exhausted
OB86 is the rack/station failure OB and is automatically called by the S7-300 CPU when a slave disappears. If OB86 is not programmed, the CPU will go STOP on the first fault - in the field this often masks the regen event because the operator only sees the STOP. The OB86 priority should be 25 (above OB1 and below OB82). OB122 handles I/O access errors and should be programmed to return a substitute value of 0 so that the safety logic reads the failed input as a passive state and the system recovers cleanly when the slave reappears.
// OB86 sample logic - rack failure on slave #3
// LADDR is read from OB86_START_INFO[6..7] (WORD)
// For the affected rack set OB86_RES := OB86_OB_NUM
// OB86_EV_CLASS = 0x39 = incoming, 0x38 = outgoing
L #OB86_EV_CLASS
L W#16#39 // incoming fault
==I
JC FAULT
L #OB86_EV_CLASS
L W#16#38 // fault cleared
==I
JC CLR
BEU
FAULT: L #OB86_MDL_ADDR // diagnostic address of failed slave
T MW 100 // store for HMI message
SET
S M 102.0 // set fault latched bit
BEU
CLR: CLR
R M 102.0 // clear fault latched bit
BEU
7. Diagnostic Buffer Interpretation
Open the online diagnostics in STEP 7 (Target system > CPU messages) and filter by the fault window. The timestamps relative to the hoist-down command tell you which event is primary:
| Timestamp delta to hoist-down | Buffer entry | Interpretation |
|---|---|---|
| 0 - 50 ms | Drive reports torque negative, Vdc climbing | Regen event started, drive is source |
| 50 - 200 ms | PS307 DC OK LED flicker on remote rack | Supply dip on 24 V distribution |
| 200 - 400 ms | Profibus DP station failure event 0x3931 | Slave dropped out - primary symptom |
| 400 - 800 ms | OB86 entered, M102.0 latched | CPU reacted to slave loss |
| 1 - 3 s | OB86 outgoing, station returns | Drive brake chopper absorbed regen, link recovered |
If the buffer shows the drive event before the Profibus event, the drive is causal. If the Profibus event appears first, suspect a physical-layer issue independent of the drive.
8. Mitigation Playbook
- Confirm regenerative path. Measure DC-link voltage on the hoist drive during a controlled lower with 100 % load. Verify the brake chopper engages and the resistor reaches the expected temperature rise.
-
Enable Vdc_max controller on the hoist drive (
p1240 = 1). For SIMOVERT MASTERDRIVES MC, the equivalent parameter isP375. Reference: SINAMICS S120 List Manual. -
Add or replace the brake resistor with one sized for the worst-case lowering energy:
E_k = m * g * h, derated by the resistor's continuous power rating. - Install a line filter on the hoist drive (e.g. Schaffner FN3270 or Siemens 6SE7090 series) to clamp common-mode current.
- Power the remote Profibus repeater from a dedicated PS307, not from the same 24 V bus that feeds drive fans or brakes.
- Re-terminate the Profibus segment: exactly two terminations, end-to-end, on the 6ES7972-0BA12 connector blocks.
- Bond the screen at both ends with a 360-degree clamp at every junction box, then re-verify with a milliohm meter.
- Add surge protection on the 24 V supply feeding each remote rack (Phoenix Contact PT 2-PE-24 or Weidmuller VPU I).
- Program OB86 and OB122 if not already present, and wire a fault-latched bit to the HMI for explicit fault notification.
9. EMC and Grounding Best Practices for Crane Installations
A crane is a particularly hostile EMC environment because the entire structure moves, slews, and carries high-current trailing cables. The Profibus cable is laid in a festoon or reeling system and the screen continuity varies with motion.
- Use a continuous-rotation slip ring rated for shielded cable if the bus crosses a slewing joint, instead of relying on brush contact through the slew bearing.
- Keep the equipotential bonding conductor (typically 16 mm^2 green/yellow) parallel to and bonded to the crane structure at every joint.
- Install ferrite cores (Wurth Elektronik 74270097 or equivalent) on each Profibus cable pass through junction boxes - 1 to 2 turns depending on bus speed.
- Avoid routing Profibus in the same tray as the hoist motor cable; minimum 200 mm separation, crossings at 90 degrees.
- For 1.5 Mbps Profibus, the maximum segment length is 200 m without repeaters. Beyond that, use a 6GK1500-0EA02 repeater - one repeater extends a segment and provides galvanic isolation. Reference: SIMATIC NET Profibus Network Manual.
10. Verification Procedure After Mitigation
- Power up the crane, run the hoist-up at 100 % load to confirm no regression on the upward motion.
- Command hoist-down from maximum hook height at 100 % rated load - the worst case for regeneration.
- Repeat the cycle 10 times while a ProfiTrace or BT200 bus monitor records the wire signal at the slave end.
- Acceptance criteria:
- No Profibus station-failure event in the diagnostic buffer.
- Repeater and slave DO LEDs steady green throughout.
- DC-link voltage stays within 560 V - 760 V on a 400 V line.
- PS307 24 V stays within 22.0 V - 28.8 V on the remote rack.
- Capture the diagnostic buffer before and after each test cycle. Store the exported buffer file as part of the commissioning record.
11. Field-Proven Diagnostic Flowchart
12. Document References
- S7-300 CPU 31xC and CPU 31x Manual (Edition 06/2008)
- S7-300 Automation System - Module Data Manual
- SINAMICS S120/S150 List Manual (parameter p1240, p1271)
- STEP 7 System and Standard Functions Reference Manual (OB86 / OB122)
- SIMATIC NET Profibus Network Manual
- SIMATIC Profibus DP / DP-V1 Installation Guidelines
- ProSoft Technology Knowledge Base - Cable faults and noise on communication lines
FAQ
Why does the Profibus slave drop only when the hoist lowers, not when it raises?
When lowering, the load overhauls the hoist motor and the drive operates in regenerative mode. The DC-link voltage rises and, without a working brake chopper or four-quadrant supply, the regen energy distorts the line voltage and injects common-mode noise onto the Profibus cable screen. Hoist-up consumes power from the line, so no regen event occurs.
Which S7-300 event ID confirms a Profibus slave dropout?
Event ID 0x3931 (incoming) and 0x3932 (outgoing) indicate a Profibus DP station failure. Event ID 0x3872 indicates a Profibus DP bus fault with retry count exceeded. All three are recorded in the diagnostic buffer of CPUs such as the 6ES7315-2AH14-0AB0.
Is OB86 mandatory for an S7-300 crane PLC?
Yes. Without OB86 programmed, the CPU goes STOP on the first Profibus slave failure. In crane applications the OB86 priority should be 25 and OB122 should be present to substitute a safe value when an input becomes inaccessible during the dropout window.
Can a single drive cause a Profibus fault across the whole crane?
Yes - if the hoist drive shares a common DC bus or 24 V aux supply with the rest of the system, the regen event propagates through the supply and through the cable screen. Isolating the hoist drive aux supply, adding a line filter, and powering the remote Profibus repeater from a dedicated PS307 resolves the majority of these events.
What is the maximum Profibus segment length at 1.5 Mbps?
At 1.5 Mbps the maximum trunk length per segment is 200 m when using 6XV1830-0EH10 cable. Beyond 200 m, insert a 6GK1500-0EA02 repeater. Each repeater provides galvanic isolation and refreshes the signal so EMC events on one segment do not propagate across the bus.