S7-400H 414-4H Hard Stop: Recovery After Wrong CPU Addressing

David Krause25 min read
S7-400SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Overview

An S7-400H redundant master/slave pair, comprising two CPU 414-4H modules, was reconfigured outside its engineered H-station topology by personnel who were not trained on SIMATIC H-system addressing. The resulting field signature is consistent and unmistakable: every CPU in the pair is in hard stop with red EXTF and SF LEDs, every CP 443-1 is in STOP with red INTF, every IM 153-2 on the redundant Profibus DP segments shows red BF1, and every CP 341-1 point-to-point module shows red SF. The plant network sees nothing of the H-station because the integrated Profibus DP master on each CPU has stopped cycling tokens, the redundant fiber link is down, and the CP 443-1 cannot complete initialization without a valid CPU host configuration.

The diagnostic buffer compounds the confusion. After a backup-battery discharge or full RAM loss, the CPU real-time clock rolls back to the factory default of 01.01.1994 00:00:00, so every event in the buffer appears to have happened three decades ago—even though the controller was built and commissioned in 2009. The combination of "1994" timestamps and present-day hardware faults gives the misleading impression that the controller itself is ancient hardware, when in reality it is a serviceable S7-400H that simply needs the engineered configuration reloaded and the clock battery replaced.

Do not assume hardware failure when the diagnostic buffer shows 01.01.1994 events. The CPU's lithium backup battery has discharged and the real-time clock has rolled back. Replace the battery (one or two 3.6 V lithium thionyl chloride AA cells, Siemens 6ES7971-0BA00) before continuing the recovery. The diagnostic buffer entries themselves persist in flash; only the timestamps of new events are wrong.

2. Affected Hardware and Fault LED Interpretation

The following table maps the typical S7-400H redundant station hardware to the LED status expected when the CPU has been readdressed out of its configured topology. Module order and MLFBs should be cross-checked against the physical rack before any reconfiguration is attempted.

Module MLFB example Function LEDs in fault state Meaning
CPU 414-4H (rack 0, slot 3) 6ES7414-4HM14-0AB0 / 6ES7414-4HT14-0AB0 H-system central processor, master side STOP (yellow), SF (red), EXTF (red) Hardware configuration error: configured rack/slot no longer matches physical insertion. CPU refuses to enter RUN.
CPU 414-4H (rack 1, slot 3) 6ES7414-4HM14-0AB0 / 6ES7414-4HT14-0AB0 H-system central processor, redundant partner STOP (yellow), SF (red), EXTF (red) Same as above. Both CPUs share the same project, so both are affected.
CP 443-1 (Industrial Ethernet) 6GK7443-1EX20-0XE0 / 6GK7443-1GX20-0XE0 Plant Ethernet gateway, optional PROFINET IO controller STOP (yellow), INTF (red) Internal fault: no valid host configuration downloaded; CPU host is in STOP. May also show LINK and RX/TX activity if the physical Ethernet link is still up.
IM 153-2 (ET 200M Profibus DP) 6ES7153-2BA10-0XB0 / 6ES7153-2BA70-0XB0 Profibus DP slave interface for distributed I/O BF1 (red), SF (red) Bus fault on Profibus DP interface 1: master is in STOP, no token rotation, no cyclic I/O exchange. SF indicates a configuration mismatch between the engineered GSD and the actual module insertion.
CP 341-1 (point-to-point) 6ES7341-1AH02-0AE0 / 6ES7341-1BH02-0AE0 RS-232/422/485 serial communications SF (red) Group fault: loadable protocol driver missing, host CPU in STOP, or hardware mismatch.
SM 321 (digital input) 6ES7321-1BH02-0AA0 / 6ES7321-1BL00-0AA0 Digital input module SF on some variants Process image not updated because OB1 is not executed (CPU in STOP). Module may be fine.
SM 331 (analog input) 6ES7331-1KF02-0AB0 / 6ES7331-7HF01-0AB0 Analog input module SF on some variants Same as SM 321: no process image update during CPU STOP. Channel diagnostics only become accessible once the CPU is in RUN.

All module manuals, firmware notes, and diagnostic descriptions are available on the official Siemens Industry Online Support portal, including the SIMATIC S7-400H system manual, the CPU 414-4H device manual, and the individual CP/IM/SM device manuals.

3. Root Cause: Why S7-400H Addressing Is Rigid

The S7-400H pair is mounted in a UR2-H rack (two 9-slot segments in a single subrack) or in two UR racks connected by an IM 460/IM 461 receive/transmit pair. Each CPU sits in a fixed slot determined by the rack engineering drawing, and the rack numbers must be unique within the H-station. By Siemens convention, CPU 0 occupies rack 0, slot 3 of segment A, and CPU 1 occupies rack 1, slot 3 of segment B. The default MPI and Profibus DP address on each integrated port of a 414-4H is 2, but the project download typically overwrites this with the engineered value.

The H-station concept requires:

  • Both CPUs share the same HW Config project. The offline project determines rack numbers, slot numbers, MPI/Profibus addresses, sync module assignments, and the redundant I/O Profibus DP segments.
  • The first CPU is configured as the master (CPU 0, rack 0, slot 3 by default) and the second as the redundant partner (CPU 1, rack 1, slot 3 by default). The PROFIBUS DP address of the integrated master interface is typically 2.
  • If the project is altered so that the configured rack/slot does not match the physical insertion, the CPU detects the mismatch during startup (or on a download while in RUN) and refuses to enter RUN. It logs "Incorrect module in slot X" or "Module does not exist in configured slot" in the diagnostic buffer and switches to STOP with EXTF lit.
  • The redundant I/O Profibus DP segment (the H-system's primary DP master system) is tied to the integrated DP interface of the active CPU. The redundant segment (Profibus(1)) is tied to the partner CPU. A mismatch on either CPU halts both segments.

When personnel unfamiliar with the S7-400H simply open a CPU, change the rack number to 0 and the slot to 2 (which is what was reported in the field), and download, the project that lands in the CPU no longer matches the physical world, and the CPU stops. Worse, if the change is downloaded to both CPUs in the H-pair, the redundancy link and the cross-CPU communication break, every I/O module on the active Profibus DP segment loses its master, and every CP that depends on the CPU's services (configuration download, KeepAlive, host services) reports internal faults.

S7-400H Station — Two UR Racks / UR2-H with Sync FOC Rack 0 (UR2-H Seg A) PS PS CPU 414-4H #0 SM 321 SM 331 CP 443-1 CP 341-1 IM 460 / 461 Slot 1 2 3 4 5 6 7 8 9 Rack 1 (UR2-H Seg B) PS PS CPU 414-4H #1 SM 321 SM 331 CP 443-1 CP 341-1 IM 460 / 461 Slot 1 2 3 4 5 6 7 8 9 Sync FOC pair (redundant link) IM 460/461 interconnect PROFIBUS DP integrated (IF1) to ET 200M Industrial Ethernet to plant network (CP 443-1)
An S7-400H must always be commissioned as a complete H-station. A single CPU cannot be reconfigured in isolation; both CPUs require the same project, and both should be targeted by a single download from STEP 7 / SIMATIC Manager. The "wrong rack/slot" condition reported in the field is a textbook violation of this rule.

4. Pre-Recovery Isolation and Safety

  1. Lock out and tag out the affected power block per the plant's electrical safety procedure. Confirm the 24 V DC and 120/230 V AC supplies feeding the S7-400H rack, the ET 200M stations, and the CP 341-1 power supplies are de-energized.
  2. Document the actual physical layout: take photographs of the front of each rack with module order, slot numbers, and module MLFBs visible. The S7-400H should be in a UR2-H (or two UR racks); each CPU 414-4H is in slot 3 of one segment.
  3. Verify the CPU backup battery state. A 414-4H holds a lithium backup battery that retains the RAM contents and the real-time clock. If the EXTF LED is lit and the diagnostic buffer is dated 1994, the battery is dead. The BATTF LED on the CPU front will be lit or flashing yellow.
  4. Disconnect the redundant fiber-optic sync cables between the two CPUs to prevent optical faults or stray light from confusing the recovery. Mark and protect the FOC connectors with the dust caps that ship with the CPU.
  5. Disconnect the Industrial Ethernet and Profibus cables from the CP 443-1 and IM 153-2 modules if you intend to do the recovery in stand-alone mode without disturbing the running plant network.
  6. Stage a PG/PC with STEP 7 V5.5 + SP2 (or the latest SP applicable to the plant) installed and a working MPI cable. The PC-Adapter USB A2 (Siemens 6ES7972-0CB20-0XA0) is the standard field tool. Confirm the PG can go online with another S7-300/S7-400 on the site as a sanity check before connecting to the affected H-station.
  7. Locate the original STEP 7 project archive (.s7p or .zip), the most recent project backup, and the printed rack configuration. If none of these exist, the recovery is still possible by uploading from the CPU, but it is much slower.

5. Establishing PG-to-CPU Communication via MPI

The most reliable path back into a stopped S7-400H is the CPU's MPI port. The default MPI address of a brand-new CPU 414-4H is 2; if a project download has overwritten it, the value lives in the project. When the project is unknown or lost, use the "Accessible Nodes" function in SIMATIC Manager to scan MPI at 187.5 kbit/s — the rate every S7-400 supports out of the box, regardless of project state.

  1. Set the PG/PC interface to "PC Adapter (MPI)" with transmission rate 187.5 kbit/s and the highest station address 31. Bus profile "MPI".
  2. In SIMATIC Manager, choose PLC → Accessible Nodes. The MPI scan reveals the CPU even if the project is corrupt, because the MPI protocol is implemented in firmware and is not dependent on the user program or HW Config.
  3. If two CPUs appear, note both. The S7-400H pair shows up as two separate MPI nodes (CPU 0 and CPU 1). Each will report STOP and a rack/slot mismatch in its online diagnostics.
  4. Open the CPU's online view with PLC → Diagnostics/Settings → Module Information. Read the diagnostic buffer from the top (most recent) down. Look for events: "Incorrect module in slot X", "Module removed/inserted", "Distributed I/O: station failure", and—critically—"Set time of day" entries.

Once online, force the time-of-day so subsequent diagnostic events carry real timestamps. Use PLC → Diagnostics/Settings → Set Time of Day and tick "On PG" so the CPU takes the time from the PG's clock:


PLC → Set Time of Day ...
[x] On PG
[x] In CPU
[Apply] → [OK]

This does not rewrite the existing 1994 entries—those remain in the buffer because they are stored in flash with the timestamp at the moment of the event—but every new event from this point forward is timestamped with the PG time. Combined with a fresh battery, the clock will hold on its own.

Do not change the CPU's MPI/Profibus address until the configuration is corrected. Readdressing a CPU that is still running the bad project only makes the problem harder to find and can prevent the PG from connecting to it again.

6. CPU Readdressing and Configuration Recovery

The recovery sequence assumes the original STEP 7 project is available, either on the engineering server, a project backup, or as a printed configuration. If no project exists, use PLC → Upload Station to PG (hardware) on each CPU to read back the engineered configuration. The H-station cannot be reconstructed without the project, the loadable protocol drivers, or the GSD files for the ET 200M stations.

6.1 Recover the project from the CPU

  1. From SIMATIC Manager, select the CPU in "Accessible Nodes" and choose PLC → Upload Station to PG. This pulls the S7 program blocks (OB, FB, FC, DB) and the HW Config from the CPU's flash.
  2. Save the uploaded project immediately as ProjectName_RECOVERY.s7p and back it up to the engineering server. The uploaded HW Config is the configuration the CPU was last running; it is the ground truth for slot numbers, MPI addresses, and CP parameters.
  3. Repeat for the second CPU. The two H-partners should be byte-identical in terms of program and HW Config after a successful sync.
  4. If the upload fails with "Cannot read from CPU", check the MPI cable, the PG/PC interface setting, and the bus termination. The MPI bus must be terminated at both ends with 220 Ω.

6.2 Compare the project to the physical rack

  1. Open HW Config in the recovered project and confirm the rack type is UR2-H (or two UR racks with IM 460/IM 461 interconnections). The rack type is set in the rack properties dialog.
  2. Confirm CPU 0 is in rack 0, slot 3, and CPU 1 is in rack 1, slot 3. If the field-reported change shows rack 0, slot 2 for either CPU, this is the source of the fault. Drag the CPU back to its correct slot from the catalog on the right.
  3. Confirm the Profibus DP subnet master interface is on IF1 (Profibus DP, integrated) with the correct station address (typically 2 for the active CPU). The integrated DP master is enabled in the CPU properties → "Interface" tab.
  4. Confirm the redundant Profibus DP segment (Profibus(1) for the H-system) is configured with the proper DP master system, including all IM 153-2 slaves and their assigned station addresses.
  5. Confirm the CP 443-1 has the correct IP address, subnet mask, router, and MAC. Record the IP and MAC from the physical module label and verify against the project. The CP 443-1 is configured in HW Config → CP 443-1 → Properties → Ethernet Interface.
  6. Confirm the CP 341-1 protocol parameters: baud rate, parity, character framing, and the loadable driver assignment.

6.3 Correct HW Config and download to the H-station

  1. Drag the CPU back to its correct rack/slot in HW Config. Use the catalog on the right to drop the correct CPU MLFB if it is missing.
  2. Save and compile HW Config. Resolve any compile errors. They typically include "module not in catalog", "duplicate station address", or "subnet configuration inconsistent".
  3. Connect to the H-station (not a single CPU) in SIMATIC Manager via the plant's MPI or Ethernet route. The H-station is the parent object in the project tree; downloading at this level pushes the configuration to both CPUs in parallel.
  4. Choose PLC → Download to Target System. In the dialog, select "Download to H-Station" and tick "Replace object". STEP 7 will warn that both CPUs will be stopped; acknowledge and proceed.
  5. Observe the diagnostic LEDs on both CPUs. The expected sequence is: STOP → startup (RUN blinks yellow) → RUN (green). If startup halts at STOP with EXTF, the diagnostic buffer will identify the new problem—typically a module in the wrong slot or a duplicate Profibus address.
If the original project is truly unrecoverable, you must rebuild HW Config from scratch. Walk the rack from left to right with the module MLFB list in hand, recreate the Profibus DP and Industrial Ethernet subnets, and re-add the IM 153-2 slaves with their GSD files. Download the rebuilt project to a single CPU first, verify, then re-download to the H-station.

6.4 Re-establishing MPI and Profibus addresses on the CPU

CPU 414-4H has two integrated Profibus DP interfaces (IF1, IF2) and one MPI/DP combination port. The default address on every port is 2, so a stopped CPU almost always responds to "Accessible Nodes" at 187.5 kbit/s. To change an address from the PG after the project is correct:


PLC → Properties → MPI/DP Interface
  • Address: 2 (H-station master default)
  • Subnet: Plant_MPI

PLC → PROFIBUS Interface (IF1) → Properties
  • Address: 2
  • Transmission rate: 1.5 Mbps (or per project)
  • Bus profile: DP

PLC → Download to Target System

Do not skip the "Download to Target System" step after changing the interface address. The change does not take effect until the CPU is stopped and the new interface properties are committed. The CPU restarts with the new addresses and goes through the standard startup sequence.

7. Restoring Time-of-Day and Diagnostic Buffer Timestamps

Once the CPU is in RUN, the time-of-day can be set from the PG, from a plant time master (NTP, SICLOCK, or CPU-to-CPU time sync), or from a hardware solution. The diagnostic buffer entries with 1994 timestamps cannot be rewritten in the field; they remain in flash as historical record.

7.1 Set Time of Day from PG (one-time)

  1. Select the online H-station in SIMATIC Manager.
  2. Choose PLC → Diagnostics/Settings → Set Time of Day.
  3. Tick "On PG" and "In CPU". Apply. Both CPUs receive the new time via the redundant link within one scan cycle.

7.2 Automatic time-of-day synchronization (recommended)

For ongoing accuracy, configure one of the following on the H-station:

  • SIMATIC mode: In HW Config → CPU properties → Diagnostics/Clock, set "Synchronization in the AS" to "As slave", pointing at a master CPU on MPI or Profibus. The master CPU should itself be synced from a plant time source.
  • NTP via CP 443-1: Configure the CP 443-1 for NTP time-of-day synchronization. The CPU's time is then updated by the CP at a defined interval (default 10 s). The CP 443-1 manual lists the NTP server address and polling interval parameters. Available on CP 443-1 with firmware V3.0 and later (6GK7443-1EX30-0XE0 / 6GK7443-1GX30-0XE0 or newer).
  • SICLOCK GPS/plant time: Use a SICLOCK TC 400 or similar to broadcast time on the Industrial Ethernet backbone; both CPUs and the CPs subscribe via the SIMATIC time protocol.

7.3 Battery replacement procedure

  1. Power down the affected S7-400 rack (or hot-swap the battery if the CPU is a -4HX model that supports it; refer to the CPU manual for hot-swap support on the specific MLFB).
  2. Open the battery compartment on the lower front of the CPU. The compartment is held by a single captive screw.
  3. Insert one or two 3.6 V lithium thionyl chloride AA cells, Siemens 6ES7971-0BA00 (single pack) or equivalent. Observe polarity; the spring contact is the negative end.
  4. Restore power. The diagnostic buffer keeps all events but the timestamp of new events is now correct.
The battery retains RAM only. Even with a dead battery, the diagnostic buffer persists because the buffer is stored in flash. Only the timestamps of new events are affected by the clock battery state. The user program in RAM is lost on power down without a healthy battery, which is why the project must be reloaded after a power cycle.

8. Clearing CP 443-1, IM 153-2, and CP 341-1 Faults

Once the CPU is back in RUN with the correct configuration, the downstream modules will not automatically clear their fault LEDs. Each module must be re-initialized or re-parameterized by the CPU host, and the engineer must verify that the parameter download succeeded.

8.1 CP 443-1 (Industrial Ethernet) — clear INTF

  1. Open HW Config and double-click the CP 443-1. Verify the IP address, subnet mask, MAC, port properties, and any PROFINET or TCP connections.
  2. Select the CP in HW Config and choose PLC → Download to Target System for that single CP, or download the entire H-station. The CP restarts, the STOP LED extinguishes, the RUN LED turns green, and INTF clears.
  3. If INTF persists, the CP has a duplicate IP, a bad firmware version, or a hardware fault. Ping the CP from a plant network terminal. If the CP responds to ping but INTF is still lit, the CP has rejected the configuration—check the firmware version against the GSD/EDD in the project.
  4. If the CP is unresponsive, swap the CP with a known-good spare, reassign the IP via the PG (the new CP starts with the default IP 0.0.0.0), and re-download.

8.2 IM 153-2 (Profibus DP) — clear BF1 and SF

  1. Verify the IM 153-2 in HW Config matches the physical module: 6ES7153-2BA10-0XB0 (standard) or 6ES7153-2BA70-0XB0 (high feature). The GSD file must match the MLFB; the high-feature variant supports isochronous mode and module-hot-swap, the standard does not.
  2. Confirm the Profibus DP address on the IM 153-2's rotary switch matches the configured address. Typical values: 3, 4, 5, etc. The factory default is "0" (legal but reserved by PROFIBUS for class-2 masters). Use a small screwdriver to set the address; the new value is read on power-up.
  3. Re-power the ET 200M station: power off the 24 V DC, wait 5 s, power on. The IM 153-2 re-acquires the Profibus DP token, the BF1 LED extinguishes, and the SF LED clears once the configured I/O modules are detected.
  4. If BF1 stays lit, the Profibus DP master is still not cycling tokens. This indicates the CPU's integrated DP interface is still in fault—recheck the CPU diagnostic buffer and the Profibus(1) master system configuration.
  5. If SF stays lit but BF1 is off, an I/O module in the ET 200M is missing or has a wrong part number. Compare the physical module list to the project, slot by slot.

8.3 CP 341-1 (point-to-point) — clear SF

  1. Open HW Config → CP 341-1 → Properties. Verify the protocol (ASCII, 3964(R), RK512), baud rate, parity, and character framing. The CP 341-1 supports 300 to 115 200 bit/s depending on the protocol.
  2. Check the loadable driver. CP 341-1 requires a loadable protocol driver in addition to the HW Config parameters. In SIMATIC Manager, the driver is assigned via PLC → CP 341-1 → Driver. The driver must match the part number and firmware of the CP; common drivers are 6ES7870-1AC01-0YA0 (ASCII), 6ES7870-1AB01-0YA0 (3964R), and 6ES7870-1AE01-0YA0 (Modbus master, for CP 341-1 with Modbus firmware).
  3. Download the configuration and driver to the CP. The SF LED clears once the driver is loaded and the protocol is operational. Confirm the TXD and RXD LEDs flicker at the configured baud rate to verify the serial line is alive.

9. Re-establishing S7-400H Redundancy Operation

With both CPUs in RUN and the I/O modules cleared, restore the H-system as the final step. The redundant link is the most safety-critical element; do not hot-plug the sync fiber without confirming the process is in a safe state.

  1. Reconnect the redundant fiber-optic sync cables between the two CPU 414-4H modules. The connectors are keyed FOC sockets; insert until you feel the detent click. The cable is a Siemens-specific duplex FOC, typically 6ES7960-1AA04-0XA0 (1 m) or longer variants.
  2. Watch the redundancy status LEDs on each CPU. The expected state is "Redundancy OK" — the LED indicators on the CPU front include REDF (redundancy fault) and the IFM1F / IFM2F indicators for the two DP ports. All four must be off. The HMI or SCADA should show "H-System is in redundant mode" once the link is up.
  3. From SIMATIC Manager, open the H-station online view and check the redundancy state. It should read "H-System is in redundant mode" with both CPUs in RUN (one as master, one as standby). The role (master/standby) is determined automatically by the H-system based on the configured priority and the link-up sequence.
  4. Trigger a manual switchover test: PLC → Diagnostics/Settings → H-System → Switchover. The standby CPU takes over; the previously active CPU should go to STOP-H (Halt) and then back to RUN-Standby. Confirm that the I/O process values remain stable and that no HMI or SCADA loses communication for more than one scan. The expected switchover time is < 100 ms.
  5. Document the switchover test result in the plant's commissioning log. The H-system is now considered operational and redundant.
S7-400H State Machine — Recovery Path STOP (EXTF) STOP-H (fault) RUN (master) RUN-Standby STOP (cold/warm restart) download OK switchover link OK config error
Never hot-plug the sync fiber while the active CPU is serving a live process. Always confirm the I/O is in a safe state, or perform the fiber reconnection during a planned outage. Hot-plug of the sync fiber is supported by the 414-4H, but the standby CPU may briefly go to STOP-H if the link is lost during a switchover.

10. Verification and Commissioning Checklist

Check Expected result Method Pass / Fail
CPU 0 and CPU 1 mode RUN, green LED on CPU front, plus SIMATIC Manager online view
EXTF on both CPUs Off LED on CPU front
Diagnostic buffer (CPU 0 and 1) No unresolved hardware configuration errors; new entries are timestamped with current date Module Information → Diagnostic Buffer
Time of day Within ±1 s of plant master time Module Information → Time of Day
CP 443-1 mode RUN, INTF off, LINK LED on LED on CP front; ping from plant network
IM 153-2 BF1 / SF Off on every ET 200M LED on IM 153-2 front
CP 341-1 SF / TXD / RXD SF off, TXD/RXD active at configured baud rate LED on CP front; oscilloscope on serial line
Redundant link REDF off, both sync fibers active, redundant mode reported LED on CPU front, H-station online view
Manual switchover Standby becomes active with no process interruption > 1 scan SIMATIC Manager → H-System → Switchover
PG access PG can read/write the H-station via MPI and Ethernet routes Accessible Nodes from plant network
SM 321/331 process image Updating; values match field Variable table online monitor (VAT)
Battery state BATTF off; battery voltage within spec (> 3.0 V) LED on CPU front; multimeter on battery holder

11. Preventive Measures and Lessons Learned

  • Lock the STEP 7 project behind a corporate change-control process. The H-station is the most safety-critical component of the plant; exploratory downloads by personnel without SIMATIC training are unacceptable. All hardware configuration changes should be reviewed by the plant's automation engineer and a MoC (Management of Change) record opened.
  • Restrict MPI/Profibus access at the firewall level. Most S7-400H plants should not expose the MPI port to the corporate IT network. Use the CP 443-1 (with appropriate access lists in CP 443-1 Properties → Security) as the only gateway between the plant network and the controller. Disable the MPI port on the CPU if the plant does not require it.
  • Maintain at least two project backups on independent media: the engineering server, an offline archive, and a printed configuration binder. A S7-400H without a project is a S7-400H that can only be recommissioned by upload from the CPU—and the upload must succeed before the battery dies.
  • Replace the CPU backup battery on a defined schedule. Siemens recommends replacement every 5 years or on first low-battery diagnostic. A dead battery causes the 1994-timestamp symptom and a full RAM loss on power down, which then requires a project reload.
  • Label every MPI/Profibus/Ethernet cable at the rack and the field device with a unique tag. Field engineers who cannot identify a cable will eventually unplug the wrong one. Use color-coded cable ties for redundancy pairs.
  • Add an H-station redundancy monitoring screen to the SCADA so that any unplanned CPU STOP, EXTF, BATTF, or REDF generates an immediate operator alarm. The WinCC or FactoryTalk View should poll the H-station online view at least once per second.
  • Provide the operations and IT teams with a documented "what not to touch" list, including the rack numbers, slot numbers, and MPI addresses of every CPU, HMI, and CP in the plant. Post laminated copies in the MCC and the control room.
  • Add a "rack/slot right-click → Properties" warning to the engineering workstation's STEP 7 install, so that any change to a CPU rack or slot number must be confirmed in a dialog with the H-station name and the engineer's initials.
If the plant uses TIA Portal projects, the same H-station recovery principles apply, but the engineering tool is "Device View" and "Network View" instead of HW Config. The CPU slot can be edited in the device view; the redundancy relationship is configured in the "Redundancy" tab of the CPU properties. TIA Portal V16 and later support S7-400H engineering with reduced functionality compared to STEP 7 V5.5; some legacy CP 341-1 drivers may need to be carried forward manually.

For ongoing support, consult the official Siemens Industry Online Support portal. The SIMATIC S7-400 product page lists the current S7-400H manuals, firmware notes, and the S7-400H system manual (entry point for all H-system documentation). The CP 443-1, IM 153-2, and CP 341-1 product manuals are also available on SIOS, with firmware-version-specific configuration notes and known-issue lists.

Frequently Asked Questions

Why does the S7-400H CPU enter hard stop after a rack/slot change in STEP 7?

The CPU compares the configured rack/slot to the physical insertion during startup. If they do not match, the CPU reports "Incorrect module in slot X" in the diagnostic buffer and switches to STOP with EXTF lit. The S7-400H will not start with a mismatched configuration because the redundancy link and the Profibus DP master assignments depend on the engineered topology.

How do I read the diagnostic buffer when timestamps show 01.01.1994 00:00:00?

The 1994 timestamps indicate a discharged CPU backup battery. The diagnostic events themselves are still valid; only the time-of-day stamps are wrong. Replace the lithium battery (Siemens 6ES7971-0BA00 or equivalent), set the time of day from the PG via PLC → Set Time of Day, and re-establish automatic time-of-day synchronization via NTP or a master CPU so new events carry real timestamps.

Can I re-address an S7-400H CPU online without stopping the redundant partner?

No. The H-station is a single engineering object in STEP 7. Any change to rack, slot, or interface address requires stopping both CPUs, downloading the corrected project, and restarting the H-system. Always perform a controlled switchover first to confirm the standby is healthy before initiating a download.

What does the BF1 LED on the IM 153-2 indicate during an H-system hard stop?

BF1 means the IM 153-2 has lost its Profibus DP connection. During a CPU hard stop, the DP master stops cycling tokens, the IM 153-2 cannot exchange cyclic I/O data, and BF1 turns red. The fault clears automatically once the DP master is back in RUN and the IM 153-2 re-acquires the token. No action on the IM 153-2 itself is required.

How do I force an S7-400H CPU to a known MPI address for emergency access?

Set the PG/PC interface to "PC Adapter (MPI)" at 187.5 kbit/s, the rate every S7-400 supports out of the box. In SIMATIC Manager choose PLC → Accessible Nodes; the stopped CPU responds on its last-configured MPI address, which is usually 2. If multiple CPUs are present, identify each by its rack/slot. Once online, set the time of day, read the diagnostic buffer, and prepare the corrected HW Config for download.

Back to blog