S7-400H Hardware Diagnostics Reading Module LED Status with SFC

David Krause17 min read
S7-400SiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Siemens S7-400H fault-tolerant systems are deployed in process plants where unplanned downtime is unacceptable. Each CPU 41x-H, power supply, communications processor, and PROFIBUS interface module exposes its health through front-panel LEDs. Reading these LEDs in software lets a SCADA system mirror the panel state, log every transition, and page the operator the moment a redundant partner takes over. This guide documents how to retrieve the LED bitmap of every module in an S7-400H rack using SFC 51 (RDSYSST) with SSL ID W#16#0174 and how to forward that bitmap to a SCADA tag.

1. Overview of S7-400H Hardware Diagnostics

Two reading mechanisms are available in STEP 7 V5.x and TIA Portal V16+:

  • SFC 51 "RDSYSST" – reads partial system state lists (SSL) and is the only way to retrieve the LED bitmap of any module in rack 0 or a connected DP station.
  • Report System Errors (RSE) – TIA Portal V20+ generates diagnostic blocks that decode SSL data and raise alarms with default texts; useful when you want alarms rather than a raw bit image, but does not expose the raw LED bitmap that an HMI mimic needs.

This reference focuses on SFC 51 because the application requires a 1:1 LED mirror in SCADA. Where the two approaches differ, the alternative path is noted in Section 10.

2. Prerequisites

Item Required version / value
STEP 7 V5.6 SP2 or higher (STEP 7 Professional in TIA Portal V16+ also supported for S7-400H)
CPU CPU 412-3H, 414-4H, 416-4H, 417-4H (firmware V6.x or later; 6ES7417-4HT14-0AB0 used in this example)
PS module PS 407 10A, R-type, order number 6ES7407-0KA02-0AA0 (10 A, redundant pair)
CP module CP 443-1, e.g. 6GK7443-1EX30-0XE0
IM module IM 153-2 redundant, e.g. 6ES7153-2BA10-0XB0
SCADA WinCC V7.5 SP2, WinCC Professional V16, or third-party via OPC UA on the CP 443-1
Documentation SIMATIC S7-300/400 System and Standard Functions Reference Manual (entry ID 109751826)
The S7-400H system state lists used here are defined in Chapter 34 of the System and Standard Functions manual. Always cross-check the SSL ID and INDEX against the latest edition of that manual for your CPU firmware.

3. SFC 51 (RDSYSST) Architecture and Parameter Reference

SFC 51 reads a partial system state list. The block is asynchronous, so the BUSY flag must be polled when REQ is set for a list longer than one element. The interface is identical in STEP 7 V5.x and TIA Portal.

Parameter Declaration Type Description
REQ INPUT BOOL Edge-triggered request. Set TRUE to start a read; reset when BUSY is FALSE.
SZL_ID INPUT WORD System state list ID. Use W#16#0174 for module LED status.
INDEX INPUT WORD Sub-index, slot address or CPU number depending on SSL.
RET_VAL OUTPUT INT Return value; 0 on success, error code per System and Standard Functions manual Chapter 33.
BUSY OUTPUT BOOL TRUE while the read is in progress. DR is only valid after BUSY returns FALSE.
SZL_HEADER OUTPUT STRUCT Header with LENTHDR, N_DR, and DR_VERSION.
DR OUTPUT ANY Destination for the read data record. Pre-size the area to the maximum expected length (4 bytes per LED record).

Standard SCL wrapper used in OB1 or a cyclic OB (TIA Portal V16+):

// FB_HardwareDiag - cyclic read of LED status
// Inputs:  iStart (BOOL) - trigger pulse
//          iSZL_ID (WORD) - usually W#16#0174
//          iIndex  (WORD) - slot or CPU number
// Outputs: oData   (DWORD) - 32-bit LED bitmap
//          oError  (INT)  - RET_VAL from SFC 51
//          oBusy   (BOOL) - busy flag

#sBusy := FALSE;
IF #iStart THEN
    "RDSYSST_DB".REQ     := TRUE;
    "RDSYSST_DB".SZL_ID  := #iSZL_ID;
    "RDSYSST_DB".INDEX   := #iIndex;
    "RDSYSST_DB".DR      := P#DB100.DBX0.0 BYTE 4;   // 4-byte destination
    "RDSYSST_DB".BUSY    := FALSE;
    "RDSYSST_DB".DONE    := FALSE;
    CALL "RDSYSST" , "RDSYSST_DB"
         REQ       := "RDSYSST_DB".REQ
         SZL_ID    := "RDSYSST_DB".SZL_ID
         INDEX     := "RDSYSST_DB".INDEX
         RET_VAL   := #oError
         BUSY      := #oBusy
         SZL_HEADER:= "RDSYSST_DB".HEADER
         DR        := "RDSYSST_DB".DR;
    IF NOT #oBusy THEN
        "RDSYSST_DB".REQ := FALSE;
        #oData := DWORD_FROM_DB100;
    END_IF;
END_IF;

For STL (STEP 7 V5.x), the same call reduces to the four-line ladder-equivalent shown later in this article for each module type. Always treat w#16#.... notation as hexadecimal in your program comments and naming.

4. CPU 41x-H LED Status via SSL W#16#0174

SSL ID W#16#0174 returns the LED status of a module. When INDEX = W#16#0001 to W#16#0080, the returned data record is the LED bitmap of the CPU in the corresponding logical slot of the H-system. For an S7-400H with two racks, the slot mapping is:

INDEX Module targeted
W#16#0001 Rack 0, slot 1 – CPU 0 (master)
W#16#0002 Rack 0, slot 2 – CPU 1 (standby)
W#16#0003 Rack 0, slot 3 – PS 1 / CP / IM
W#16#0004 Rack 0, slot 4 – PS 2 / CP / IM
W#16#0011 Rack 1, slot 1 – CPU 0 (redundant rack)
W#16#0012 Rack 1, slot 2 – CPU 1
Slot numbering is hardware dependent. Read the actual slot map with SSL W#16#0011 before driving the read loop from a constant.

The 4-byte LED record returned by SFC 51 is interpreted for a 41x-H CPU as follows (bits are lit-when-set, because the LED is driven by the firmware; verify the polarity in Chapter 34 of the System and Standard Functions manual):

Bit LED name Meaning
0 SF Group error (hardware or firmware fault on at least one subordinate component)
1 INTF Internal fault – CPU-internal diagnostic event
2 EXTF External fault – I/O or submodule fault outside the CPU
3 RUN CPU in RUN
4 STOP CPU in STOP or HOLD
5 MAST CPU 0 is master of the H-system
6 STBY CPU is in standby
7 LINK Sync link up (fibre-optic pair)
8 IF Interface fault on PN/DP
9 IF1F / IF2F Fault on interface 1 / 2
10 FORCE Force job active
11 CRST Cold restart in progress
12 BAF Battery alarm active
13 USR User-defined LED
14 USR1 User-defined LED 1
15 USR2 User-defined LED 2

STL snippet (STEP 7 V5.6) to read the master CPU LED bitmap once per second from OB35:

// OB35 - 1 s cycle, call SFC 51 once per scan
CALL "RDSYSST"
     REQ       := M    200.0          // trigger pulse
     SZL_ID    := W#16#0174
     INDEX     := W#16#0001          // CPU 0 in rack 0
     RET_VAL   := MW   202
     BUSY      := M    204.0
     SZL_HEADER:= DB200.DBD   0
     DR        := P#DB200.DBX  4.0 BYTE 4;
A     M      204.0;                    // skip while busy
JC    END;
L     DB200.DBD    4;                  // load 4-byte LED bitmap
T     MD    206;                       // mirror for SCADA tag "CPU0_LED"
SET;
R     M      200.0;                    // clear trigger
END:  NOP   0;

5. Power Supply Module PS 407 10A LED Status

The PS 407 10A (R-type, order number 6ES7407-0KA02-0AA0) provides the following front-panel LEDs that map to the SSL W#16#0174 record when INDEX = W#16#0003 or W#16#0004 depending on slot position:

Bit LED name Meaning Operator action
0 INTF Internal PS fault (defective module, fan stalled) Replace module on next outage
1 BAF Battery alarm aggregate (one or both batteries low or missing) Replace battery
2 BATT1F Battery 1 below threshold Replace battery 1
3 BATT2F Battery 2 below threshold Replace battery 2
4 DC5V 5 V DC rail OK (lit-when-OK on R-type, lit-on-fault on A-type – verify by hardware revision) None / replace PS
5 DC24V 24 V DC rail OK None / replace PS

Read both PS modules sequentially; OR the two returned 4-byte values to a single word PS_LED_AGG for the SCADA:

// PS 1 (rack 0, slot 3)
CALL "RDSYSST"
     REQ    := M 210.0
     SZL_ID := W#16#0174
     INDEX  := W#16#0003
     RET_VAL:= MW 212
     BUSY   := M 214.0
     DR     := P#DB210.DBX 0.0 BYTE 4;
A     M   214.0;
JC    PS1_BSY;
L     DB210.DBD 0;
T     MD 216;                          // PS1_LED
R     M   210.0;
PS1_BSY: NOP 0;

// PS 2 (rack 0, slot 4)
CALL "RDSYSST"
     REQ    := M 220.0
     SZL_ID := W#16#0174
     INDEX  := W#16#0004
     RET_VAL:= MW 222
     BUSY   := M 224.0
     DR     := P#DB220.DBX 0.0 BYTE 4;
A     M   224.0;
JC    AGGR;
L     DB220.DBD 0;
T     MD 226;                          // PS2_LED
R     M   220.0;
AGGR: L   MD 216;
     OW  MD 226;
     T   MD 230;                        // PS_LED_AGG
In a redundant PS configuration, the rack 1 PS modules use INDEX = W#16#0013 and W#16#0014. Treat all four PS records in the same OR-aggregate to obtain a single "any PS fault" tag for the HMI alarm summary.

6. CP 443-1 Communications Processor LED Status

CP 443-1 modules such as 6GK7443-1EX30-0XE0 expose six front-panel LEDs. Reading them via SFC 51 requires the slot address in INDEX:

Bit LED name Meaning
0 INTF Internal CP fault (firmware, configuration)
1 EXTF External fault (cable, partner device)
2 BUSF Bus fault on the connected PROFINET/PROFIBUS segment
3 MAINTF Maintenance required (e.g. port error counters above threshold)
4 RUN CP in RUN – services active
5 STOP CP in STOP
6 LINK Ethernet link up
7 RX/TX Activity on the interface

For S7-400H dual-CP configurations, both CPs are typically placed in slot 7 and slot 8 of each rack. The slot map is read with SSL W#16#0091 at startup. Once the slot is known, call SFC 51 with the resolved INDEX value:

// CP_LED -- once per 2 s from OB35, parameterise from DB
CALL "RDSYSST"
     REQ    := M 240.0
     SZL_ID := W#16#0174
     INDEX  := "Diag_DB".CP_Index      // WORD, e.g. W#16#0007
     RET_VAL:= MW 242
     BUSY   := M 244.0
     DR     := P#DB240.DBX 0.0 BYTE 4;
A     M   244.0;
JC    CP_BSY;
L     DB240.DBD 0;
T     "Diag_DB".CP_LED;                 // expose as OPC tag "CP_443_1_LED"
R     M   240.0;
CP_BSY: NOP 0;

To detect "interface up" specifically, AND the returned value with W#16#0010 (RUN) and W#16#0040 (LINK) and compare to zero. Add W#16#0004 for BUSF and W#16#0008 for MAINTF to the alarm mask.

7. IM 153-2 PROFIBUS DP Interface LED Status (Redundant)

An ET 200M station with a redundant pair of IM 153-2 modules (e.g. 6ES7153-2BA10-0XB0) reports five front-panel LEDs per module. Reading them requires an SFC 13 (DPNRM_DG) call because the IM is a DP slave, not a module of rack 0. The diagnostic data record layout for IM 153-2 is standard PROFIBUS DP-V1 diagnostic and is documented in the IM 153-2 manual, but the LED bitmap is also returned in the slot-related partial SSL when read from the DP master interface (CPU DP port).

Bit LED name Meaning
0 SF Group error (module diagnostics present)
1 BF1 Bus fault on PROFIBUS interface 1
2 BF2 Bus fault on PROFIBUS interface 2 (active in redundant mode)
3 ACT IM is the active partner of the redundant pair
4 ON 24 V supply present

Reading the IM bitmap from the H-CPU uses the SSL W#16#0174 with the slot index returned by the DP master system. The cleanest pattern is to read DP-slave diagnostics with SFC 13 (DPNRM_DG) per ET 200M station, then unpack the LED bytes locally.

// SFC 13 - read standard slave diagnostics
CALL "DPNRM_DG"
     REQ      := M 260.0
     LADDR    := "Diag_DB".IM_LADDR      // diagnostic address of ET200M
     RET_VAL  := MW 262
     BUSY     := M 264.0
     RECORD   := P#DB260.DBX 0.0 BYTE 26 // standard diag = 26 bytes
A     M   264.0;
JC    DG_BSY;
L     DB260.DBB 5;                       // byte 5 = LED bitmap
T     "Diag_DB".IM_LED;                  // 5 bits used
R     M   260.0;
DG_BSY: NOP 0;
The exact byte position of the LED bitmap inside the standard DP-V1 diagnostic buffer depends on the IM 153-2 firmware. For 6ES7153-2BA10-0XB0 firmware V4.x, byte 5 holds the five IM 153-2 LEDs. Confirm against the IM 153-2 manual in the Hardware Documentation package for the firmware you ship.

8. Distributed I/O Module SF LED Diagnostics

Every ET 200M I/O module (SM, FM, CP) reports a single SF (group error) LED that turns on when channel-level or module-level diagnostics exist. The diagnostic data record is read with SFB 52 (RDREC) for PROFINET devices and with SFC 13 (DPNRM_DG) for PROFIBUS stations.

Recommended reading pattern for an ET 200M PROFIBUS station with sixteen SM modules in slots 4-19:

// FB_ET200M_Loop - one call per module
FOR #i := 0 TO 15 DO
    #slot := #i + 4;
    #ioAddr := "Diag_DB".StationBase + (#slot * 4); // offset, depends on configuration
    CALL "RDREC" , "RDREC_DB"
         REQ     := M 280.0
         ID      := #ioAddr
         INDEX   := 0                       // standard diag index
         MLEN    := 26
         VALID   := M 282.0
         BUSY    := M 283.0
         ERROR   := M 284.0
         STATUS  := "Diag_DB".RDREC_Status
         LEN     := "Diag_DB".RDREC_Len
         RECORD  := P#DB280.DBX 0.0 BYTE 26;
    A     M   284.0;
    JC    LOOP_END;
    A     M   282.0;
    JCN   LOOP_END;
    L     DB280.DBB 5;                      // module status byte
    L     W#16#0002;                        // mask SF bit
    AD;
    <>I;
    S     "Diag_DB".SM_SF[#i];              // one bit per slot
LOOP_END: NOP 0;
END_FOR;

On PROFINET, replace the call with SFB 52 (RDREC) using the device's slot number; the same byte/bit mapping holds. For the slot/IO address scheme, the CPU's system data records SDB 0/1/2 and SDB 1000+ are parsed at startup and the resulting table stored in a global DB so the diagnostic loop does not need to be re-configured if a module is added.

9. SCADA Integration with WinCC / TIA Portal

The 4-byte DR returned for each module is exposed as a DWORD tag. SCADA mimics the LED panel by extracting individual bits and applying a colour mapping:

Tag (DWORD) Bit HMI label Tag colour
CPU0_LED 0 SF Red
CPU0_LED 3 RUN Green (lit-when-1, verify against your CPU FW)
CPU0_LED 4 STOP Yellow (lit-when-1)
PS_LED_AGG 1 BAF Yellow
PS_LED_AGG 2 BATT1F Yellow
CP_443_1_LED 2 BUSF Red
IM_LED 1 BF1 Red
SM_SF[x] 0 SF Red

WinCC Professional convention: configure each LED as a separate tag of type BOOL derived from a 32-bit source by mask + shift in a script, or use the integrated "Status word to Boolean" conversion in the HMI tag properties. The script-based method is preferred for thousands of LEDs because it loads the source as a single DWORD:

' WinCC V7.5 VBS at tag change on CPU0_LED (DWORD)
Dim s : s = ""
If (CPU0_LED And &H1)  <> 0 Then s = s & "SF;"     ' bit 0
If (CPU0_LED And &H8)  <> 0 Then s = s & "RUN;"    ' bit 3
If (CPU0_LED And &H10) <> 0 Then s = s & "STOP;"   ' bit 4
HMIRuntime.Trace "CPU0 LEDs: " & s

Alarm generation: drive a discrete alarm for each bit. The alarm text in WinCC is parameterised with the bit name so the operator sees e.g. "PS module – BATT1F" rather than a hex code. Where the SCADA is third-party (Ignition, iFIX, WinCC OA), the same DWORD is published as an OPC UA tag and split on the HMI side with the same bit mapping.

10. Alternative: Report System Errors (TIA Portal V20+)

TIA Portal V20 added Report System Errors support for S7-300/S7-400. The wizard generates OB82, OB83, OB86, OB87, OB122, OB121 and FB 49 (or FB 126 for fault-tolerant systems) plus a UDT that describes every diagnostic event with default alarm texts. The UDT includes a fault class, the device identifier and the standard diagnostic text; the LED bitmap itself is not directly exposed, but the EV_ID and the module's slot/IO address are.

Pros:

  • Zero hand-written code: alarms and texts are configured by checkbox.
  • Consistent text across plants using the standard Siemens message database.

Cons:

  • Per-event scanning can be slower than one-shot SFC 51 reads in large I/O plants.
  • LED-by-LED mimic in HMI requires an additional mapping of the alarm status word to the LED widget – you are effectively rebuilding the SSL decode.

Use RSE for alarm notifications, and SFC 51 when the operator needs a faithful image of every LED on the front panel. The two are not exclusive; the S7-400H system diagnostics blocks can be generated by RSE while the SFC 51 read loop runs in parallel for the HMI mimic.

See the official guide "Basics of system diagnostics (S7-300, S7-400) – TIA Portal V20" for the full configuration flow.

11. Verification and Commissioning Checklist

Use the following checks to confirm the diagnostic loop is wired correctly before plant handover:

  1. Compile the SFC 51 instance DB; download and switch CPU to RUN-P. Confirm RET_VAL = 0 and BUSY returns to FALSE within one OB1 cycle.
  2. Open DB200.DBD 4 in the variable table. The CPU0_LED word should read 0x0008 (RUN only) within five seconds of a clean cold restart.
  3. Trigger a forced peripheral error: enter SF_ON on a DO word in the watch table. Wait 6 s. The SF bit (bit 0) of the corresponding SM_SF should be set in the SCADA tag.
  4. Pull a PROFIBUS connector at the active IM 153-2. The BF1 bit should toggle within 2 s. Reconnect; BF1 should clear after the link-up time (typically 30 s, dominated by the watchdog).
  5. Stop the master CPU in HW Config (online → stop). The STOP bit of CPU0_LED must be set within 1 s. Switch the standby CPU to master: the MAST bit must move to CPU1_LED within 200 ms.
  6. For the PS module test, remove the battery from slot 1. BATT1F should appear within 60 s (CPU scans the PS at 60-s intervals).
All timings are typical values for a 417-4H running firmware V6.0.5. Faster updates are not possible; if the SCADA needs sub-second update, decimate the trigger pulse with a counter (e.g. fire SFC 51 every 250 ms only on the active CPU).

12. Troubleshooting Matrix

Symptom RET_VAL (decimal) Root cause Corrective action
BUSY stays TRUE — SFC 51 was called before the previous read completed; SSL index out of range Poll BUSY and only start the next call after BUSY returns FALSE; verify INDEX against Chapter 34 of the System and Standard Functions manual
RET_VAL = 8082 8082 CPU busy (communications or self-test) Retry; or re-issue from OB100 cold-start only
RET_VAL = 8090 8090 Specified SSL ID/INDEX not available on this CPU firmware Check CPU firmware release notes; some SSLs were added in V5.3 (W#16#0091) and V6.0 (extended LED bitmaps)
RET_VAL = 80A1 80A1 DR area too small for the partial list length Increase the BYTE count on the DR pointer; LED partial list always returns 4 bytes
All LEDs show as 0 even on a faulted CPU 0 INDEX is a slot number, not a CPU logical address; the rack was renumbered after a hot swap Re-read SSL W#16#0011 at startup and refresh the index table; or use the symbolic slot from HW Config
CP 443-1 LEDs are stuck at last value 0 (intermittent) CP in STOP because the connected partner went down; LEDs freeze until link returns Cross-check the BUSF bit toggling; the CP firmware is allowed to freeze LEDs in STOP
DPNRM_DG returns BUSY but no RECORD update — Diagnostic address is wrong; SFC 13 targets the master (LADDR) but the slave has multiple DP masters Use the diagnostic address of the slave's first slot, not the master port address; check in HW Config → DP slave properties → Diagnostics address
SF bit is permanently set on a healthy SM 0 The I/O module's diagnostic interrupt is configured but no OB82 is loaded Insert OB82 (and OB83, OB86 for full coverage); otherwise the SF LED has no consumer and remains latched in the diagnostic buffer

For deeper reference material on S7-400H diagnostics, the "Realization of a Fault-Tolerant Tunnel Lighting System With S7-400H" application example contains a complete STEP 7 V5.6 project with SFC 51 wrappers for CPU, PS, and IM modules and a WinCC flexible faceplate – the example is published by Siemens and is suitable for adapting to the S7-400H hardware diagnostics use case.

Frequently Asked Questions

Which SFC reads the LED status of an S7-400H CPU in STEP 7 V5.x?

SFC 51 (RDSYSST) with SZL_ID = W#16#0174 and INDEX = W#16#0001 for CPU 0 (rack 0, slot 1). The 4-byte data record returned contains one bit per LED; the bit-to-LED mapping is documented in Chapter 34 of the System and Standard Functions manual (entry ID 109751826).

How do I read the PS 407 10A LED bitmap for a redundant pair?

Call SFC 51 with SZL_ID = W#16#0174 once per PS module – INDEX = W#16#0003 for the slot-3 PS and W#16#0004 for the slot-4 PS (use W#16#0013 / W#16#0014 in rack 1). OR the two 4-byte records to a single PS_LED_AGG tag. The INTF, BAF, BATT1F, BATT2F, DC5V, and DC24V bits occupy bits 0-5 of the resulting DWORD.

Why does SFC 51 keep BUSY = TRUE and never finish?

Either the previous call has not yet completed (SFC 51 is asynchronous) or the SSL_ID/INDEX combination is not supported by the current CPU firmware (typical RET_VAL = 8090). Poll BUSY and only issue a new REQ when BUSY is FALSE, and verify the requested SSL against the firmware release notes for your CPU 41x-H.

Can Report System Errors in TIA Portal V20 read the same LED bitmaps?

Not directly. RSE generates text-based diagnostic alarms via FB 49 / FB 126, but the raw LED bitmap for an HMI mimic is still produced by SFC 51 or by an FB 125-equivalent decoding of the diagnostic buffers. Use both in parallel: RSE for alarm messaging and SFC 51 for the operator mimic.

How often should SFC 51 be triggered for the SCADA to look "live"?

Trigger every 250 ms to 1 s for the active master CPU; the partial list read is short (4 bytes) and typically returns in 5-15 ms on a 417-4H. Faster polling wastes OB35 time without improving the visible LED response, because the CPU's diagnostic update interval is already 250 ms by default.

Back to blog