S7-400H ET 200M SM 326F Fail-Safe I/O Configuration Guide

David Krause16 min read
Safety SystemsSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview: SM 326F Fail-Safe I/O in S7-400H ET 200M

Engineers integrating legacy fail-safe I/O modules from the SIMATIC ET 200M family into a SIMATIC S7-400H high-availability controller frequently encounter a configuration paradox: the F-modules (SM 326F, SM 336F) are physically capable of acting as standard I/O in older firmware revisions, yet operating them in "standard" mode defeats the SIL 2/3 capability that the customer paid for. This reference documents the boundary conditions under which each operating mode is permissible, the required S7 F Systems software stack, and the parameter assignment error conditions that arise when the hardware DIL switches and the software F-destination address fall out of sync.

The three module catalog numbers in scope are:

  • 6ES7326-1BK02-0AB0 — SM 326F, F-DI 24×DC24V
  • 6ES7326-2BF10-0AB0 — SM 326F, F-DO 10×24VDC/2A
  • 6ES7336-4GE00-0AB0 — SM 336F, F-AI 6×0/4...20mA HART

All three modules live in an ET 200M station headed by an IM 153-2 (PROFIBUS) or IM 153-4 PN (PROFINET) interface module and communicate with the S7-400H CPUs via the PROFIsafe profile on top of PROFIBUS DP or PROFINET IO. The default and intended mode is fail-safe (F-mode). Using these modules in standard mode is technically possible only with specific firmware revisions, and it is rarely justified when the end customer requires SIL 2 certification.

Engineering principle: If the application is required to meet IEC 61508 SIL 2 or higher, configure the modules in F-mode using S7 F Systems. Standard-mode operation forfeits the diagnostic coverage and discrepancy monitoring that justify the cost premium of F-I/O.

2. Module Identification and Technical Specifications

Each SM 326F / SM 336F module is identified by its Siemens MLFB (catalog number). The following table summarizes the headline specifications and indicates whether standard-mode operation is supported on each MLFB revision.

Catalog Number Description Channels Signal Range Standard Mode Notes
6ES7326-1BK02-0AB0 SM 326F, F-DI 24 24 V DC, sink/source Yes (F-DE = 0) BK02 revision explicitly retains standard-mode fallback
6ES7326-2BF10-0AB0 SM 326F, F-DO 10 24 V DC / 2 A, P/P and P/M Restricted (older FW) Newer firmware revisions lock the module to F-mode
6ES7336-4GE00-0AB0 SM 336F, F-AI HART 6 0/4...20 mA, HART v5/v6/v7 Restricted (older FW) Verify firmware before relying on standard-mode fallback

6ES7326-1BK02-0AB0 — F-DI 24×DC24V

  • Number of inputs: 24 (isolated in groups of 12)
  • Nominal input voltage: 24 V DC (permissive range 20.4–28.8 V)
  • Input current per channel: typ. 7 mA at 24 V
  • Sensor supply: internal, short-circuit-proof, per group
  • Achievable safety class: SIL 2 / SIL 3 (depends on 1oo1, 1oo2, 2oo2 evaluation)
  • PROFIsafe profile: V2.4 or higher on PROFIBUS, V2.6 or higher on PROFINET
  • DIL switch: 8-pole, sets F-destination address (F-DE)
  • Diagnostics: discrepancy error, wire break, short circuit, internal fault, channel passivation

6ES7326-2BF10-0AB0 — F-DO 10×24VDC/2A

  • Number of outputs: 10
  • Output voltage: 24 V DC (typ. UL+ − 0.5 V at full load)
  • Output current per channel: 2 A continuous, 4 A inrush for 100 ms
  • Aggregate current: 10 A across all channels
  • Switching mode: P/P (high-side) or P/M (push-pull) — configurable per channel pair
  • Achievable safety class: SIL 2 / SIL 3
  • Diagnostics: overload, short circuit, wire break, cross-fault, channel passivation

6ES7336-4GE00-0AB0 — F-AI 6×0/4...20mA HART

  • Number of inputs: 6
  • Input range: 0/4...20 mA, differential
  • Resolution: 16 bits including sign
  • Conversion time: typ. 18 ms per channel (4-wire / 2-wire configurable)
  • HART: v5, v6, v7 pass-through supported; HART variables readable via PDM
  • Achievable safety class: SIL 2 / SIL 3
  • Diagnostics: wire break, short circuit, range violation, HART communication error, channel passivation
Firmware caveat: The ability to fall back to standard mode is firmware-dependent. Before relying on a module to operate without an S7 F Systems license, verify the firmware version on the module side label and consult the Siemens Product Support database for that specific MLFB. Newer firmware revisions (released approximately 2016 and later) lock F-modules to F-mode at boot.

3. F-Mode Versus Standard-Mode Operation

F-modules contain two microcontrollers that evaluate every input or output twice (dual-channel). The PROFIsafe layer on top of the fieldbus carries both values plus a CRC and a consecutive number, and the F-CPU compares them. If the comparison fails, the input is "passivated" — i.e., the value is replaced by a safe substitute (typically 0 for digital, 0 mA for analog) and a diagnostic is reported. This mechanism is the core of fail-safe operation and is summarized in the Siemens TIA documentation on fail-safe automation systems.

In standard mode, the module behaves like a regular SM 321 / SM 322 / SM 331:

  • Single-channel acquisition is allowed.
  • No discrepancy monitoring occurs.
  • PROFIsafe is disabled; the fieldbus protocol carries only the process value.
  • The F-destination address is set to 0 in HW Config and the DIL switch on the rear of the module must read 0.

The transition from F-mode to standard mode is governed by two parameters that must agree:

  1. F-destination address (F-DE) in STEP 7 HW Config: Set to 0 to disable PROFIsafe for that slot.
  2. DIL switch on the module: All 8 switches to OFF (binary 00000000 = decimal 0).

If HW Config reports an F-DE of 0 but the DIL switch encodes a non-zero address, the module refuses to start up and generates a parameter assignment error. The same error appears if the DIL switch is set to a non-zero value but HW Config reports the module as "F-capable with PROFIsafe enabled". The parameter assignment error is the single most common start-up fault on F-modules and is almost always caused by a DIL switch / software mismatch. Industry coverage of this class of failure is summarized in the Control Engineering article on SIMATIC fail-safe modules.

Operational warning: Operating an F-module in standard mode removes the diagnostic coverage that justifies its use in safety functions. The customer requirement for SIL 2 certification is incompatible with standard-mode operation. Re-deploy the modules in F-mode with a licensed copy of S7 F Systems instead.

4. S7-400H System Architecture and F-CPU Selection

The S7-400H is a hot-standby redundant PLC with two CPUs (rack 0 and rack 1) coupled through fiber-optic synchronization modules. For fail-safe applications, an F-CPU is mandatory. The standard catalog numbers for F-capable H-CPUs are:

  • 6ES7414-4HM14-0AB0 — CPU 414-4H (F-capable)
  • 6ES7416-3FS06-0AB0 — CPU 416F-3 PN/DP (F-capable)
  • 6ES7417-4XT05-0AB0 — CPU 417-4H (F-capable)

The ET 200M station that hosts the SM 326F / SM 336F modules is connected to the S7-400H via PROFIBUS DP or PROFINET. The interface module is the IM 153-2 (for PROFIBUS) or IM 153-4 PN (for PROFINET). Both support F-modules natively as long as the F-modules' PROFIsafe addresses fall within the configured F-host range.

Topology

+----CPU0----+      +----CPU1----+
| CPU 414F-4H|      | CPU 414F-4H|
|  Rack 0    |======|  Rack 1    |   (fiber-optic sync)
+----+--------+      +----+-------+
     |                     |
     +---PROFIBUS DP-------+
              |
        +-----v-----+
        |  IM 153-2 |
        | (ET 200M) |
        +-----+-----+
              |
   +----------+----------+--------+
   |          |          |        |
[SM 326F DI][SM 326F DO][SM 336F AI]
  1BK02       2BF10        4GE00

In a redundant H-system, both CPUs independently run the same F-runtime group. The PROFIsafe protocol carries the safety frame to both F-CPUs, and either CPU can place the F-module in a safe state. This redundancy is in addition to the dual-channel evaluation inside the F-module itself. The redundancy also extends the proof-test interval: because the H-system continues operation on a single CPU, the diagnostic coverage of a single-channel fault inside the F-CPU does not interrupt the safety function.

5. PROFIsafe Protocol Fundamentals

PROFIsafe is the safety layer defined in IEC 61784-3-3 that runs as a black channel on top of PROFIBUS DP or PROFINET IO. The protocol adds the following to a standard fieldbus telegram:

  • A 4-byte CRC (Cyclic Redundancy Check) over the process data
  • A consecutive number that increments on every telegram
  • A status/control byte (1 byte) that communicates passivation requests and acknowledgements
  • Watchdog timing on both ends, with a configurable timeout (typically 100 ms–2 s)

The F-destination address (F-DE) is a unique, station-wide identifier that ties the F-module to its F-host (the CPU slot). On PROFIBUS, F-DE is set via the DIL switch. On PROFINET, the F-DE is assigned in HW Config because PROFINET devices typically do not have a mechanical address switch. The F-source address (F-SE) is the PROFIsafe address of the F-host and is configured in HW Config on the CPU side.

Evaluation classes per IEC 61784-3-3

  • Class 1 (1oo1): Single-channel, lowest coverage
  • Class 2 (1oo2): Dual-channel, same logic; either channel can place the system in safe state
  • Class 3 (2oo2): Dual-channel, both must agree; higher diagnostic coverage
  • Class 4 (2oo3): Triple-channel, voting (rare; high-availability applications)

For SIL 2, classes 1 or 2 are typically acceptable when paired with adequate diagnostic coverage. For SIL 3, class 3 or higher is generally required.

6. S7 F Systems Software Requirements

Configuring fail-safe I/O in a STEP 7 Classic project requires the optional software package S7 F Systems (also referenced as "S7 F/FH Systems" in some Siemens documentation). The package adds the F-configuration editor to STEP 7 and provides the F-runtime libraries required for safety logic.

Compatibility matrix

S7 F Systems Version STEP 7 Version F-CPU Coverage F-Module Support
V5.2 SP1 STEP 7 V5.4 SP5 CPU 414F / 416F / 417F SM 326F / SM 336F classic
V6.0 STEP 7 V5.5 SP2 CPU 414F / 416F / 417F + 315F / 317F SM 326F / SM 336F classic + F-Link
V6.4 STEP 7 V5.5 SP4+ CPU 314C-2 F (limited) SM 326F / SM 336F classic

For newer TIA Portal environments, the equivalent package is STEP 7 Safety Advanced (TIA Portal V15 or higher). However, the modules in the original question (1BK02, 2BF10, 4GE00) are legacy and are best handled in STEP 7 Classic V5.x with S7 F Systems V6.x.

License requirement: S7 F Systems requires a valid license on the engineering station. Without it, the F-configuration editor is grayed out and the project will compile but cannot be downloaded to an F-CPU.

The S7 F Systems install includes:

  • F-configuration editor (HW Config extension)
  • F-runtime libraries: F-FB / F-FC / F-DB / F-I-DB / F-O-DB
  • Acceptance test workbench (printable signature reports, test checklists)
  • S7 F Configuration Pack (GSD/GSDML files for F-modules)

7. SIL 2 Certification and Safety Lifecycle

SIL 2 is defined in IEC 61508 as the Safety Integrity Level for which the average probability of dangerous failure on demand (PFDavg) lies between 10-2 and 10-3, or the probability of dangerous failure per hour (PFH) lies between 10-6 and 10-7 per hour. For an S7-400F with SM 326F / SM 336F modules, achieving SIL 2 requires:

  1. A TÜV-certified F-CPU in the S7-400 family.
  2. S7 F Systems option package, licensed.
  3. PROFIsafe configured for the appropriate evaluation class (typically 1oo2 for SIL 2).
  4. An acceptance test documented and signed.
  5. Operation within the proof-test interval declared in the FMEDA.

The safety lifecycle per IEC 61511 (process industry) or IEC 62061 (machinery) typically follows the sequence:

  1. Process hazard and risk assessment (PHA / HAZOP / LOPA)
  2. Safety function specification (SRS)
  3. Safety instrumented function (SIF) design
  4. Detailed engineering (S7 F configuration)
  5. Installation and commissioning
  6. Validation / acceptance test
  7. Operation, maintenance, proof testing

For comparison, fail-safe I/O families from other vendors (for example, the IP65/IP67/IP69K-rated safety blocks described in the TURCK safety I/O module catalog) typically implement the same IEC 61508 / IEC 61784-3 framework but on CIP Safety or IO-Link Safety transports rather than PROFIsafe.

8. Standard-Mode Configuration Procedure (Legacy)

If a customer expressly requires the SM 326F / SM 336F modules to behave as standard I/O, and the firmware revision permits, follow this procedure. Note that this configuration is not acceptable for SIL 2 certified functions.

Prerequisites

  • STEP 7 V5.5 SP2 or higher (no S7 F Systems license required)
  • IM 153-2 (6ES7153-2BA02-0XB0 or compatible) or IM 153-4 PN
  • F-modules with firmware revisions that allow F-DE = 0 — verify by module side label
  • ET 200M station configured in HW Config

Step-by-step

  1. In HW Config, open the ET 200M station and insert the F-module into the appropriate slot.
  2. Double-click the module. The Properties dialog opens.
  3. Navigate to the "Parameters" tab.
  4. In the F-destination address field, enter 0 (decimal zero).
  5. Confirm with OK. STEP 7 prompts you to install S7 F Systems if F-mode is still active — accept the prompt to install, or use the alternative path below.
  6. Physically access the module. On the rear of the module, locate the 8-pole DIL switch. Set all 8 switches to OFF (binary 00000000 = decimal 0).
  7. Reinsert the module into the ET 200M rack.
  8. Save and compile the STEP 7 project.
  9. Download the hardware configuration to the IM 153-2.
  10. Cycle power on the ET 200M station. The module should now come up in standard mode and the process values will appear in the I/O image without any F-signature or PROFIsafe frames.
Watch out: If the DIL switch is set to 0 but HW Config reports a non-zero F-DE, the module generates SF (system fault) and BF (bus fault) LEDs and the CPU diagnostic buffer records "Parameter assignment error on module / F-DE mismatch". The error is cleared by either correcting the DIL switch or correcting the HW Config to match.

9. Fail-Safe Configuration Procedure (Recommended)

For any application that must meet SIL 2 (or higher), configure the modules in F-mode. The recommended procedure is:

Prerequisites

  • STEP 7 V5.5 SP2 or higher
  • S7 F Systems V6.x license installed
  • S7 F Configuration Pack (current revision)
  • F-CPU module (CPU 414F-4H, 416F-3 PN/DP, or 417-4H)
  • F-modules with DIL switches set to a non-zero F-DE (unique per station)

Step-by-step

  1. In SIMATIC Manager, open the S7 project that contains the S7-400H station.
  2. Open HW Config and navigate to the ET 200M station.
  3. Insert the F-modules (SM 326F DI, SM 326F DO, SM 336F AI) into the appropriate slots.
  4. For each F-module, open Properties → Parameters and assign a unique F-destination address (e.g., 1, 2, 3).
  5. Note the assigned F-DE. Physically set the DIL switches on each module to the matching binary value. For F-DE = 1: switch 1 = ON, switches 2–8 = OFF. For F-DE = 2: switch 2 = ON, others OFF. Continue to F-DE = 255 (binary 00000001 = 1, 00000010 = 2, etc., with the LSB on switch 1).
  6. Open the F-configuration editor. STEP 7 with S7 F Systems adds an "F-configuration" entry under each F-CPU.
  7. Assign each F-module to an F-runtime group (a logical container for safety logic, scheduled in a cyclic OB such as OB35).
  8. Configure the F-runtime group signature, the watchdog time (typical: 100–500 ms), and the passivation behavior.
  9. Open the F-library and insert the appropriate F-FBs (e.g., ESTOP1, FDBACK, F-I/O driver blocks) into the F-runtime group.
  10. Wire the safety logic. Use only F-typed blocks (F-FB, F-FC, F-DB) inside the F-runtime group. Standard blocks are not permitted inside.
  11. Compile and save. STEP 7 generates an F-signature (a CRC of the safety program) that must be recorded for the acceptance test.
  12. Download the hardware configuration to the S7-400H and to the IM 153-2.
  13. Download the F-program to the F-CPU. The CPU prompts for the F-signature on the operator panel.
  14. Run the acceptance test per IEC 61508 / 61511. Document all safety functions exercised.

Sample safety block call (FBD)

The following simplified FBD illustrates how an emergency-stop chain is typically wired inside the F-runtime group:

        +-------+       +--------+       +--------+
[E_STOP]-->|ESTOP1|--+-->|FDBACK  |--+-->|F-DO    |-->[Output to F-DO channel]
        +-------+   |  +--------+   |  +--------+
                      |              |
                  [F-DI channel]  [Feedback contact]

ESTOP1 evaluates the discrepancy between two redundant E-stop contacts. FDBACK checks the readback of the contactor to confirm the safe state was achieved. The output is then written to a channel of the F-DO module.

10. Parameter Assignment Error: Troubleshooting Matrix

The "parameter assignment error" diagnostic is the most common start-up fault on F-modules. It can be triggered by the following conditions:

Symptom Cause Remedy
SF LED on, BF LED off, "Parameter assignment error" in diagnostic buffer DIL switch on module encodes a non-zero F-DE but HW Config has F-DE = 0 Either re-set the DIL switch to 0, or change HW Config F-DE to match the switch.
SF and BF LEDs on, "PROFIsafe address error" DIL switch on module differs from F-DE in HW Config (both non-zero, but different) Verify F-DE in HW Config and set the DIL switch to match exactly.
SF LED on, BF LED blinking, "Module not parameterized" F-DE in HW Config is unique on the PROFIsafe network but the module was inserted into the wrong slot Verify slot assignment and PROFIsafe slot number.
"F-source address / F-destination address collision" Two F-modules share the same F-DE on the same PROFIBUS segment Re-number one of the F-DE values; each F-DE must be unique per F-host.
"F-signature mismatch" on operator panel The F-signature in the F-CPU does not match the F-signature in STEP 7 Re-compile the F-program and re-download, then confirm signature at the operator panel.

Diagnostic buffer entries to expect on F-DE mismatch

On a CPU 414F-4H with firmware V6.0 or higher, the diagnostic buffer for the relevant slot typically records events in the 0x39Ex range (station-related) and 0x35Ex range (PROFIsafe-related). Translate these in STEP 7 via "Module Information → Diagnostic Buffer" and resolve the indicated slot. The exact event ID to expect depends on the firmware revision of the CPU and the IM 153-2; refer to the CPU's diagnostic manual for the precise mapping.

11. Verification and Acceptance Test

Verification is mandatory before a SIL 2 system can be handed over. The acceptance test must cover:

  1. Proof test of each safety function: Trigger the initiating event (E-stop, over-pressure, etc.) and confirm that the defined safe state is reached within the required response time.
  2. Discrepancy time verification: For 1oo2 / 2oo2 inputs, artificially delay one channel and confirm the module passivates within the configured discrepancy time (default 100 ms).
  3. Passivation test: Disconnect one channel of a redundant input. The F-CPU should report the channel as passivated and substitute the safe value (0).
  4. Re-integration test: Restore the channel. The F-CPU should re-integrate the channel after the configured re-integration time.
  5. F-signature verification: Print the F-signature from STEP 7 and the F-CPU. They must match.
  6. Watchdog test: Stop the F-runtime group and confirm the F-CPU transitions to STOP within the watchdog time.
  7. Diagnostic coverage test: Force wire-break, short-circuit, and over-range faults and confirm the diagnostics are correctly reported.

Document the test results in an acceptance test report. The report should reference the version of S7 F Systems, the firmware versions of all F-modules, and the F-signature of the F-runtime group. The acceptance test report is a regulatory deliverable and must be retained for the lifetime of the installation per IEC 61511.

12. Frequently Asked Questions

Can the SM 326F and SM 336F modules be used as standard I/O?

Only on older firmware revisions. Set the F-destination address (F-DE) to 0 in both HW Config and on the rear DIL switch of the module. Newer firmware revisions (released approximately 2016 onward) lock the modules to F-mode and standard-mode operation is not possible. For SIL 2 applications, use F-mode with S7 F Systems instead.

What software is required to program the fail-safe modules?

The optional package S7 F Systems (V6.0 or higher) for STEP 7 Classic V5.5, or STEP 7 Safety Advanced for TIA Portal V15+. S7 F Systems adds the F-configuration editor, F-runtime libraries, and the acceptance test workbench.

What causes "parameter assignment error" on an SM 326F?

Almost always a mismatch between the DIL switch setting on the rear of the module and the F-destination address in HW Config. Both must be the same value (or both must be 0 for standard mode). Verify the binary representation: switch 1 is the LSB, switch 8 is the MSB.

Do I need a special F-CPU for S7-400H with F-modules?

Yes. The CPU must be an F-capable variant: CPU 414F-4H (6ES7414-4HM14-0AB0), CPU 416F-3 PN/DP (6ES7416-3FS06-0AB0), or CPU 417-4H (6ES7417-4XT05-0AB0). Standard S7-400H CPUs cannot execute F-runtime groups.

What is the maximum number of F-modules per ET 200M station?

For IM 153-2 (PROFIBUS), up to 12 F-modules per station is supported. For IM 153-4 PN (PROFINET), up to 20 F-modules per station. These limits are governed by the PROFIsafe timing budget on the fieldbus and the cycle time of the F-runtime group.

Can I mix F-modules and standard SM 321 / SM 322 modules in the same ET 200M station?

Yes. The IM 153-2 accepts a mix of F-modules and standard modules in the same station as long as slot and addressing rules are respected. PROFIsafe and standard PROFIBUS / PROFINET IO coexist on the same fieldbus.

Back to blog