S7-400H CPU 414-H All LEDs Blinking: Defective Mode Troubleshooting
The SIMATIC S7-400H fault-tolerant controller family uses redundant CPUs that continuously cross-check each other. When the standby (slave) CPU enters the DEFECTIVE operating state, every status LED on the front panel flashes in unison, the diagnostic buffer records an internal checksum error, and the controller drops out of redundant operation. This article explains how to read the diagnostic events, isolate the root cause, verify the memory-card configuration, update the firmware, and replace the CPU in an S7-400H system based on the CPU 414-4H (medium performance range) and the related CPU 412-3H / CPU 417-4H variants.
1. Problem Description
Field report: an S7-400H rack contains a primary CPU in rack 0 and a secondary (standby) CPU in rack 1. The standby CPU enters a fault state with all front-panel LEDs flashing simultaneously at approximately 2 Hz. STEP 7 / PCS 7 displays the following diagnostic buffer entries:
| Field | Value |
|---|---|
| Event number | Event 1 of 1500 |
| Event text | Check sum error |
| No relevance for user (Z1) | 0003 |
| Previous operating mode | STOP (internal) |
| Requested operating mode | DEFECTIVE |
| Event location | Standby CPU in rack 1 |
| Event class | Internal error, incoming event |
Per the SIMATIC S7-400H System Manual, simultaneous flashing of all LEDs on a CPU 41x-H is the unambiguous hardware indicator for the DEFECTIVE state. The CPU has detected an internal error that it cannot clear by itself; it has intentionally disabled all process I/O update functions and will not accept a START/RUN command from STEP 7 until the underlying fault is removed.
2. Operating Modes of an S7-400H CPU
An S7-400H CPU moves between the following modes. The diagnostic entry "Requested operating mode: DEFECTIVE" indicates the transition arrow shown in bold below.
| Mode | Meaning | Front-panel indication |
|---|---|---|
| RUN (redundant) | Both CPUs active, role = master or standby | RUN LED green, IFM/IFC LED per link state |
| RUN (solo) | Single CPU active, partner missing/failed | RUN LED green, partner LED off |
| STOP | User-initiated stop, outputs disabled | STOP LED yellow |
| STARTUP | Power-on / restart, OB 100/101/102 executing | RUN + STOP LEDs flash alternately |
| HOLD | Breakpoint reached, single-step mode | RUN + STOP LEDs steady, HOLD LED on |
| DEFECTIVE | Internal error not recoverable; CPU needs service | All LEDs flash at 2 Hz |
| Link-Update / Link-Down | Redundancy link status during sync | IFM / IFC LEDs blink |
The DEFECTIVE state is intentionally sticky: even if the internal cause is transient, the CPU will not return to RUN on its own. You must perform a power cycle after fixing the underlying cause, and in many cases the CPU must be replaced.
3. Root Cause Analysis
From the diagnostic buffer and the field history, the most likely root causes for a CPU 414-4H (or 412-3H / 417-4H) entering DEFECTIVE with a checksum error are listed in order of frequency observed in installed bases.
| # | Root cause | Diagnostic signature | Affected versions |
|---|---|---|---|
| 1 | Missing or incompatible memory card in the CPU slot. S7-400 CPUs require a RAM (MC 952) or FEPROM (MC 952 Flash / 5V Flash) card. A CPU without a card, or with an MMC (S7-300 type), declares itself DEFECTIVE on startup. | Checksum error on internal load memory; "No relevance for user (Z1): 0003" (no user-relevant info for this internal fault) | All firmware versions V3.x, V4.x, V5.x, V6.x |
| 2 | Corrupted load memory caused by interrupted firmware update, ESD event, or aged Flash card wear-out. | Checksum error on load memory; STOP (internal) before DEFECTIVE | Flash cards > 10 years in service; FEPROM cards with > 100k write cycles |
| 3 | Firmware/F-CPU mismatch between master and standby CPU, or firmware older than required for the configured H-system version. | DEFECTIVE on the standby only; master in RUN-redundant | Mixing V4.x and V5.x, or V5.x and V6.x, between the two H-CPUs |
| 4 | Hardware defect on the CPU mainboard (DRAM, Flash controller, processor). | DEFECTIVE persists after card swap; same event on a known-good card | Random; more frequent on units with > 15 years of continuous service |
| 5 | Redundancy-fiber or backplane fault causing a sync overflow that the CPU cannot recover from. | IFM / IFC LED errors before the checksum event; redundant link-down events | Firmware < V4.5 on CPU 414-4H; longer fiber runs > 10 m with poor SFPs |
Z1: 0003 is the S7-400 internal classification "no user-relevant additional info" for checksum errors. Do not interpret 0003 as a memory offset or a register address — it is a flag that the descriptive text "No relevance for user" applies to this event.4. Memory Card Requirements: S7-400 vs S7-300
The most common cause of a "spare CPU with all LEDs flashing" is a confusion between S7-300 and S7-400 memory cards. S7-400 CPUs do not accept MMC (Micro Memory Card); they require MC 952 modules in either RAM or FEPROM technology.
| Card family | Used in | Voltage | Backup | Writable from CPU? |
|---|---|---|---|---|
| MC 952 (RAM) | S7-400 / S7-400H | 3.3 V or 5 V depending on variant | Battery in CPU (no battery = data lost on power down) | Yes, no wear-out |
| MC 952 (5V Flash, FEPROM) | S7-400 / S7-400H | 5 V | Non-volatile, no battery required | Limited; uses block-erase |
| MC 952 (3.3V Flash) | S7-400 / S7-400H newer | 3.3 V | Non-volatile | Limited; block-erase |
| MMC (Micro Memory Card) | S7-300, S7-1200, S7-1500 | 3.3 V | Non-volatile | Yes |
The CPU 414-4H has only 512 or 1024 kB of internal load memory, which is insufficient for any realistic H-system program including the S7-H Communication blocks. If no card is inserted, the CPU cannot load the project from EPROM, and it transitions to DEFECTIVE on power-up.
5. Memory Card Catalog Numbers
The following SIMATIC MC 952 part numbers are the most common cards used with the CPU 41x-H family. All numbers are 6ES7 952-1xxx-0AA0 series. Confirm the voltage variant against the CPU manual before ordering.
| Part number | Type | Size | Voltage | Typical use |
|---|---|---|---|---|
| 6ES7952-0AF00-0AA0 | RAM | 64 kB | 5 V | Small test programs |
| 6ES7952-0AH00-0AA0 | RAM | 256 kB | 5 V | Small H programs |
| 6ES7952-0AK00-0AA0 | RAM | 512 kB | 5 V | CPU 412-3H |
| 6ES7952-0AL00-0AA0 | RAM | 1 MB | 5 V | CPU 414-4H |
| 6ES7952-1AL00-0AA0 | RAM | 2 MB | 5 V | CPU 414-4H, CPU 417-4H |
| 6ES7952-1AM00-0AA0 | RAM | 4 MB | 5 V | CPU 417-4H large projects |
| 6ES7952-1AP00-0AA0 | RAM | 8 MB | 5 V | CPU 417-4H very large |
| 6ES7952-1AS00-0AA0 | RAM | 16 MB | 5 V | CPU 417-4H maximum |
| 6ES7952-0KF00-0AA0 | Flash (FEPROM) | 64 kB | 5 V | Boot-only |
| 6ES7952-0KH00-0AA0 | Flash (FEPROM) | 256 kB | 5 V | CPU 412-3H |
| 6ES7952-0KK00-0AA0 | Flash (FEPROM) | 512 kB | 5 V | CPU 414-4H |
| 6ES7952-0KL00-0AA0 | Flash (FEPROM) | 1 MB | 5 V | CPU 414-4H |
| 6ES7952-1KL00-0AA0 | Flash (FEPROM) | 2 MB | 5 V | CPU 414-4H, CPU 417-4H |
| 6ES7952-1KM00-0AA0 | Flash (FEPROM) | 4 MB | 5 V | CPU 417-4H |
| 6ES7952-1KP00-0AA0 | Flash (FEPROM) | 8 MB | 5 V | CPU 417-4H |
| 6ES7952-1KS00-0AA0 | Flash (FEPROM) | 16 MB | 5 V | CPU 417-4H |
| 6ES7952-1KT00-0AA0 | Flash (FEPROM) | 32 MB | 5 V | CPU 417-4H |
| 6ES7952-1KY00-0AA0 | Flash (FEPROM) | 64 MB | 5 V | CPU 417-4H maximum |
6. Front-Panel LED Reference for CPU 41x-H
The CPU 41x-H front panel provides the following LED indicators. Reading them in combination is the fastest way to differentiate a DEFECTIVE state from a normal redundancy failover.
| LED | Color | Meaning when ON | Meaning when flashing |
|---|---|---|---|
| INTF | Red | Internal error (e.g., module fault, programming error) | — |
| EXTF | Red | External error (I/O, distributed I/O, CP) | — |
| FRCE | Yellow | Force request active | — |
| CRST | Yellow | Cold restart possible | — |
| WRST | Yellow | Warm restart possible | — |
| STOP | Yellow | CPU in STOP | Memory reset request |
| RUN | Green | CPU in RUN | CPU in STARTUP |
| MAST | Yellow | CPU is the redundancy master | — |
| STBY | Yellow | CPU is the standby | — |
| LINK | Green | Redundancy link OK | Link update active |
| IFM1 / IFM2 | Green | PROFINET / sync interface link up | Port activity |
| IFC1 / IFC2 | Green | Sync fiber link up | Port activity / link down |
| All LEDs | — | — | DEFECTIVE state (2 Hz) |
7. Step-by-Step Recovery Procedure
7.1 Prerequisites
- A PG/PC with STEP 7 V5.5 SP4 (or later) or TIA Portal V13+ and an Ethernet or MPI/DP cable to the CPU.
- The original S7-400H project, archived, with the most recent System Data and Hardware Configuration.
- A compatible MC 952 memory card (RAM or FEPROM) with sufficient capacity for the project.
- Spare CPU of the exact same order number (MLFB), for example 6ES7414-4HM14-0AB0 for a CPU 414-4H.
- The correct firmware update file for the H-CPU, downloaded from the Siemens Industry Online Support portal (see section 8).
- Access to the relevant Siemens manuals:
7.2 Confirm the State
- Open STEP 7 → Accessible Nodes or the online view of the H-station.
- Select the standby CPU (rack 1) and read the diagnostic buffer: PLC → Diagnostic/Setting → Diagnostic Buffer.
- Confirm Event 1 / 1500 is a checksum error, "Requested operating mode: DEFECTIVE".
- Look at the LEDs: all flashing in unison at 2 Hz indicates DEFECTIVE.
7.3 Check the Memory Card
- Power down the standby CPU only (do not de-energize the master CPU; in an S7-400H, the master must keep controlling the process).
- Remove the card from the CPU slot.
- Visually inspect the card: check for cracked housing, oxidized contacts, missing label, and confirm it is a MC 952 module — not an MMC.
- If the card is the wrong family (MMC) or the slot is empty, the CPU will go to DEFECTIVE on the next power-up regardless of any other fix.
7.4 Reload the Project onto a New Card
- Insert the card into the PG's prommer (or use the CPU's online card-flash function: PLC → Download User Program to Memory Card).
- Select RAM if the CPU has a backup battery installed (recommended for H systems), or FEPROM if you want non-volatile storage without a battery.
- Download the project. Verify in STEP 7 that the card's Used / Total memory matches the project size.
7.5 Firmware Update (Recommended)
- Check the current firmware on the defective CPU: PLC → Diagnostic/Setting → Module Information → Firmware.
- Go to Siemens Industry Online Support and search for "Operating System Update CPU 412-3H / CPU 414-4H / CPU 414-4H PG / CPU 417-4H". The current entry lists the latest V6.x firmware packages.
- Match the firmware version to both CPUs of the H system; mixed firmware is not supported.
- Run the update from STEP 7: PLC → Update Firmware. The CPU must be in STOP or unconfigured; the update takes approximately 5 to 15 minutes depending on the package.
- Power cycle the CPU when prompted.
7.6 CPU Replacement
- Take the master CPU offline only if you are prepared to lose the redundant backup during the swap. In most cases, leave the master in RUN and swap the standby.
- Open SIMATIC Manager with the project online.
- On the standby CPU, select PLC → Operating Mode → STOP.
- Disconnect the sync fiber (IFC1/IFC2) and any PROFINET cables; mark them.
- Power down the standby rack or remove the CPU from its slot.
- Insert the spare CPU and the loaded MC 952 card.
- Power up: the new CPU performs a self-test, then displays STOP with the MAST/STBY LEDs off (no role assigned yet).
- Reconnect the sync fibers and PROFINET cables.
- In STEP 7, select PLC → H-System → Link-Update, or trigger a redundancy update from the HMI / PCS 7 faceplate. The new CPU is assigned the standby role and begins to sync.
- When the LINK LED is steady green on both CPUs, redundancy is restored.
8. Firmware Update Sources
Siemens publishes firmware update packages per CPU order number. For the CPU 414-4H and its H-system siblings, look in the Siemens Industry Online Support under "Product Support → Automation Technology → SIMATIC → PLC → S7-400 / S7-400H → CPUs → CPU 414-4H". The page referenced in the research lists the current medium-performance-range CPU and the supported firmware upgrade path.
Common firmware update file names follow the convention S7H4xx_Vxx_x.exe, for example S7H414_V06.exe for CPU 414-4H V6 firmware. Always match the MLFB (order number, e.g. 6ES7 414-4HM14-0AB0) to the update before running it.
9. Verification
After completing the fix, perform the following checks before declaring the H-system healthy.
- LED verification: Master — RUN green, MAST yellow, LINK green. Standby — RUN green, STBY yellow, LINK green.
- STEP 7 module information: PLC → Module Information → Diagnostic Buffer on the standby should show "H-system standby in sync", no DEFECTIVE entries.
- Self-test: In SIMATIC Manager, PLC → H-System → H-Status reports Redundant operation: OK.
- Failover test: Pull the master CPU's power. The standby should take over the process within the configured OB 72 / OB 80 reaction time (typically < 100 ms) and the system should remain in RUN-solo. Re-seat the master and verify that it returns as a new standby.
- Card contents: Re-read the MC 952 with the PG and confirm the checksum of the downloaded block matches the project source.
10. Troubleshooting Matrix
| Symptom | First check | If the check fails | Reference |
|---|---|---|---|
| All LEDs flash, event 1 = checksum error | Is an MC 952 (not MMC) card inserted? | Insert correct MC 952; download project | S7-400H System Manual |
| All LEDs flash after firmware update | Was power lost during the update? | Reload firmware using the FW update tool; if it still fails, replace CPU | Firmware update notes |
| All LEDs flash, card is good | Is the firmware of the two H-CPUs identical? | Update both CPUs to the same Vx.x | H-CPU compatibility list |
| All LEDs flash only on cold start (no warm restart) | Backup battery of the CPU dead + RAM card inserted | Replace battery; switch to FEPROM card if no battery can be guaranteed | S7-400 CPU Manual, Battery section |
| All LEDs flash, IFC1/IFC2 errors before DEFECTIVE | Sync fiber bent, dirty, or wrong polarity | Replace fiber, clean connectors, verify IFC LED is steady | IFC fiber installation guide |
| All LEDs flash repeatedly after each power-up | Suspect hardware defect on CPU | Replace CPU; RMA to Siemens | Siemens Support Request |
11. S7-400H vs S7-300 Memory Card Pitfalls
Many field engineers keep S7-300 and S7-400 spare parts in the same cabinet. The following pitfalls are the most common sources of a DEFECTIVE state in mixed-stock environments.
| Pitfall | Symptom | Resolution |
|---|---|---|
| Inserting an MMC (6ES7953-...) into an S7-400 CPU | Card is mechanically accepted but CPU reports "unknown card" then DEFECTIVE | Replace with MC 952 (6ES7952-...) |
| Inserting a 5 V Flash card into a 3.3 V-only slot | Voltage error in diagnostic buffer, then checksum error | Order the 3.3 V variant of the same size |
| Using a 64 kB card on a CPU 414-4H with a 4 MB project | CPU loads first part, runs out of memory, DEFECTIVE | Use a card at least 2× the project size |
| Card label shows MC 952 but it is an MMC under the label | Mechanical fit feels wrong, contacts are mirrored | Verify Siemens hologram; order direct from Siemens |
| Card reader formatted the card with FAT32 | CPU cannot read FAT, reports checksum error | Reformat the card by downloading from STEP 7 |
12. Preventive Measures
- Mark every spare CPU with the firmware version it last carried, and keep the project file in the same drawer.
- Always store spare S7-400 CPUs with an MC 952 card inserted — even an empty FEPROM card prevents the DEFECTIVE state on first power-up.
- Track Flash card service life: replace FEPROM cards every 10 years in continuous service, or after 100,000 write cycles.
- Run a redundancy failover test at least once a year; log the H-status to the process historian.
- Maintain identical firmware on both H-CPUs; never mix V4.x with V5.x, or V5.x with V6.x.
- When decommissioning, write-protect the FEPROM card to prevent accidental overwrite during testing.
What does it mean when all LEDs on a CPU 414-4H blink at the same time?
It means the CPU has entered the DEFECTIVE operating state. An internal error — typically a checksum error on the load memory — is not recoverable by the CPU, and it disables all process I/O updates. The CPU must be reset, the underlying cause fixed (often a missing or wrong memory card), and if the error persists the CPU must be replaced.
Why does my S7-400 CPU go to DEFECTIVE with no memory card or with an MMC card?
S7-400 CPUs require a MC 952 (6ES7952-...) RAM or FEPROM card; they do not accept S7-300 MMC (6ES7953-...) cards. With no card the CPU has only 512 or 1024 kB of internal load memory, which is insufficient for an H-system project. Inserting a correctly sized MC 952 with the project loaded is the standard fix.
Can a firmware update recover a CPU 414-4H stuck in DEFECTIVE?
Sometimes. If the DEFECTIVE state is caused by a known firmware bug or a corrupted firmware image, reloading the operating system using the FW update tool (for example S7H414_V06.exe for the latest V6 package) can clear it. If the CPU remains in DEFECTIVE after a clean re-flash on a known-good card, the mainboard is defective and the CPU must be replaced.
Can I mix firmware versions between the two CPUs of an S7-400H system?
No. Both CPUs of an H system must run the same firmware major and minor version (for example both V5.3.7 or both V6.0.4). Mismatched firmware causes a sync failure that the standby cannot clear and results in a DEFECTIVE state on the standby. Always update both CPUs in the same maintenance window.
How do I get the standby CPU back into redundancy after a replacement?
After inserting the spare CPU with the loaded MC 952 card, reconnect the IFC sync fibers and the PROFINET cables, then trigger a Link-Update from STEP 7 (PLC → H-System → Link-Update) or from the PCS 7 faceplate. When the LINK LED on both CPUs is steady green and STEP 7 reports Redundant operation: OK under H-Status, the system is back in full redundancy.