Siemens S7-400H fault-tolerant systems are deployed in process plants where unplanned downtime is unacceptable. Each CPU 41x-H, power supply, communications processor, and PROFIBUS interface module exposes its health through front-panel LEDs. Reading these LEDs in software lets a SCADA system mirror the panel state, log every transition, and page the operator the moment a redundant partner takes over. This guide documents how to retrieve the LED bitmap of every module in an S7-400H rack using SFC 51 (RDSYSST) with SSL ID W#16#0174 and how to forward that bitmap to a SCADA tag.
1. Overview of S7-400H Hardware Diagnostics
Two reading mechanisms are available in STEP 7 V5.x and TIA Portal V16+:
- SFC 51 "RDSYSST" – reads partial system state lists (SSL) and is the only way to retrieve the LED bitmap of any module in rack 0 or a connected DP station.
- Report System Errors (RSE) – TIA Portal V20+ generates diagnostic blocks that decode SSL data and raise alarms with default texts; useful when you want alarms rather than a raw bit image, but does not expose the raw LED bitmap that an HMI mimic needs.
This reference focuses on SFC 51 because the application requires a 1:1 LED mirror in SCADA. Where the two approaches differ, the alternative path is noted in Section 10.
2. Prerequisites
| Item | Required version / value |
|---|---|
| STEP 7 | V5.6 SP2 or higher (STEP 7 Professional in TIA Portal V16+ also supported for S7-400H) |
| CPU | CPU 412-3H, 414-4H, 416-4H, 417-4H (firmware V6.x or later; 6ES7417-4HT14-0AB0 used in this example) |
| PS module | PS 407 10A, R-type, order number 6ES7407-0KA02-0AA0 (10 A, redundant pair) |
| CP module | CP 443-1, e.g. 6GK7443-1EX30-0XE0 |
| IM module | IM 153-2 redundant, e.g. 6ES7153-2BA10-0XB0 |
| SCADA | WinCC V7.5 SP2, WinCC Professional V16, or third-party via OPC UA on the CP 443-1 |
| Documentation | SIMATIC S7-300/400 System and Standard Functions Reference Manual (entry ID 109751826) |
3. SFC 51 (RDSYSST) Architecture and Parameter Reference
SFC 51 reads a partial system state list. The block is asynchronous, so the BUSY flag must be polled when REQ is set for a list longer than one element. The interface is identical in STEP 7 V5.x and TIA Portal.
| Parameter | Declaration | Type | Description |
|---|---|---|---|
| REQ | INPUT | BOOL | Edge-triggered request. Set TRUE to start a read; reset when BUSY is FALSE. |
| SZL_ID | INPUT | WORD | System state list ID. Use W#16#0174 for module LED status. |
| INDEX | INPUT | WORD | Sub-index, slot address or CPU number depending on SSL. |
| RET_VAL | OUTPUT | INT | Return value; 0 on success, error code per System and Standard Functions manual Chapter 33. |
| BUSY | OUTPUT | BOOL | TRUE while the read is in progress. DR is only valid after BUSY returns FALSE. |
| SZL_HEADER | OUTPUT | STRUCT | Header with LENTHDR, N_DR, and DR_VERSION. |
| DR | OUTPUT | ANY | Destination for the read data record. Pre-size the area to the maximum expected length (4 bytes per LED record). |
Standard SCL wrapper used in OB1 or a cyclic OB (TIA Portal V16+):
// FB_HardwareDiag - cyclic read of LED status
// Inputs: iStart (BOOL) - trigger pulse
// iSZL_ID (WORD) - usually W#16#0174
// iIndex (WORD) - slot or CPU number
// Outputs: oData (DWORD) - 32-bit LED bitmap
// oError (INT) - RET_VAL from SFC 51
// oBusy (BOOL) - busy flag
#sBusy := FALSE;
IF #iStart THEN
"RDSYSST_DB".REQ := TRUE;
"RDSYSST_DB".SZL_ID := #iSZL_ID;
"RDSYSST_DB".INDEX := #iIndex;
"RDSYSST_DB".DR := P#DB100.DBX0.0 BYTE 4; // 4-byte destination
"RDSYSST_DB".BUSY := FALSE;
"RDSYSST_DB".DONE := FALSE;
CALL "RDSYSST" , "RDSYSST_DB"
REQ := "RDSYSST_DB".REQ
SZL_ID := "RDSYSST_DB".SZL_ID
INDEX := "RDSYSST_DB".INDEX
RET_VAL := #oError
BUSY := #oBusy
SZL_HEADER:= "RDSYSST_DB".HEADER
DR := "RDSYSST_DB".DR;
IF NOT #oBusy THEN
"RDSYSST_DB".REQ := FALSE;
#oData := DWORD_FROM_DB100;
END_IF;
END_IF;
For STL (STEP 7 V5.x), the same call reduces to the four-line ladder-equivalent shown later in this article for each module type. Always treat w#16#.... notation as hexadecimal in your program comments and naming.
4. CPU 41x-H LED Status via SSL W#16#0174
SSL ID W#16#0174 returns the LED status of a module. When INDEX = W#16#0001 to W#16#0080, the returned data record is the LED bitmap of the CPU in the corresponding logical slot of the H-system. For an S7-400H with two racks, the slot mapping is:
| INDEX | Module targeted |
|---|---|
| W#16#0001 | Rack 0, slot 1 – CPU 0 (master) |
| W#16#0002 | Rack 0, slot 2 – CPU 1 (standby) |
| W#16#0003 | Rack 0, slot 3 – PS 1 / CP / IM |
| W#16#0004 | Rack 0, slot 4 – PS 2 / CP / IM |
| W#16#0011 | Rack 1, slot 1 – CPU 0 (redundant rack) |
| W#16#0012 | Rack 1, slot 2 – CPU 1 |
SSL W#16#0011 before driving the read loop from a constant.The 4-byte LED record returned by SFC 51 is interpreted for a 41x-H CPU as follows (bits are lit-when-set, because the LED is driven by the firmware; verify the polarity in Chapter 34 of the System and Standard Functions manual):
| Bit | LED name | Meaning |
|---|---|---|
| 0 | SF | Group error (hardware or firmware fault on at least one subordinate component) |
| 1 | INTF | Internal fault – CPU-internal diagnostic event |
| 2 | EXTF | External fault – I/O or submodule fault outside the CPU |
| 3 | RUN | CPU in RUN |
| 4 | STOP | CPU in STOP or HOLD |
| 5 | MAST | CPU 0 is master of the H-system |
| 6 | STBY | CPU is in standby |
| 7 | LINK | Sync link up (fibre-optic pair) |
| 8 | IF | Interface fault on PN/DP |
| 9 | IF1F / IF2F | Fault on interface 1 / 2 |
| 10 | FORCE | Force job active |
| 11 | CRST | Cold restart in progress |
| 12 | BAF | Battery alarm active |
| 13 | USR | User-defined LED |
| 14 | USR1 | User-defined LED 1 |
| 15 | USR2 | User-defined LED 2 |
STL snippet (STEP 7 V5.6) to read the master CPU LED bitmap once per second from OB35:
// OB35 - 1 s cycle, call SFC 51 once per scan
CALL "RDSYSST"
REQ := M 200.0 // trigger pulse
SZL_ID := W#16#0174
INDEX := W#16#0001 // CPU 0 in rack 0
RET_VAL := MW 202
BUSY := M 204.0
SZL_HEADER:= DB200.DBD 0
DR := P#DB200.DBX 4.0 BYTE 4;
A M 204.0; // skip while busy
JC END;
L DB200.DBD 4; // load 4-byte LED bitmap
T MD 206; // mirror for SCADA tag "CPU0_LED"
SET;
R M 200.0; // clear trigger
END: NOP 0;
5. Power Supply Module PS 407 10A LED Status
The PS 407 10A (R-type, order number 6ES7407-0KA02-0AA0) provides the following front-panel LEDs that map to the SSL W#16#0174 record when INDEX = W#16#0003 or W#16#0004 depending on slot position:
| Bit | LED name | Meaning | Operator action |
|---|---|---|---|
| 0 | INTF | Internal PS fault (defective module, fan stalled) | Replace module on next outage |
| 1 | BAF | Battery alarm aggregate (one or both batteries low or missing) | Replace battery |
| 2 | BATT1F | Battery 1 below threshold | Replace battery 1 |
| 3 | BATT2F | Battery 2 below threshold | Replace battery 2 |
| 4 | DC5V | 5 V DC rail OK (lit-when-OK on R-type, lit-on-fault on A-type – verify by hardware revision) | None / replace PS |
| 5 | DC24V | 24 V DC rail OK | None / replace PS |
Read both PS modules sequentially; OR the two returned 4-byte values to a single word PS_LED_AGG for the SCADA:
// PS 1 (rack 0, slot 3)
CALL "RDSYSST"
REQ := M 210.0
SZL_ID := W#16#0174
INDEX := W#16#0003
RET_VAL:= MW 212
BUSY := M 214.0
DR := P#DB210.DBX 0.0 BYTE 4;
A M 214.0;
JC PS1_BSY;
L DB210.DBD 0;
T MD 216; // PS1_LED
R M 210.0;
PS1_BSY: NOP 0;
// PS 2 (rack 0, slot 4)
CALL "RDSYSST"
REQ := M 220.0
SZL_ID := W#16#0174
INDEX := W#16#0004
RET_VAL:= MW 222
BUSY := M 224.0
DR := P#DB220.DBX 0.0 BYTE 4;
A M 224.0;
JC AGGR;
L DB220.DBD 0;
T MD 226; // PS2_LED
R M 220.0;
AGGR: L MD 216;
OW MD 226;
T MD 230; // PS_LED_AGG
INDEX = W#16#0013 and W#16#0014. Treat all four PS records in the same OR-aggregate to obtain a single "any PS fault" tag for the HMI alarm summary.6. CP 443-1 Communications Processor LED Status
CP 443-1 modules such as 6GK7443-1EX30-0XE0 expose six front-panel LEDs. Reading them via SFC 51 requires the slot address in INDEX:
| Bit | LED name | Meaning |
|---|---|---|
| 0 | INTF | Internal CP fault (firmware, configuration) |
| 1 | EXTF | External fault (cable, partner device) |
| 2 | BUSF | Bus fault on the connected PROFINET/PROFIBUS segment |
| 3 | MAINTF | Maintenance required (e.g. port error counters above threshold) |
| 4 | RUN | CP in RUN – services active |
| 5 | STOP | CP in STOP |
| 6 | LINK | Ethernet link up |
| 7 | RX/TX | Activity on the interface |
For S7-400H dual-CP configurations, both CPs are typically placed in slot 7 and slot 8 of each rack. The slot map is read with SSL W#16#0091 at startup. Once the slot is known, call SFC 51 with the resolved INDEX value:
// CP_LED -- once per 2 s from OB35, parameterise from DB
CALL "RDSYSST"
REQ := M 240.0
SZL_ID := W#16#0174
INDEX := "Diag_DB".CP_Index // WORD, e.g. W#16#0007
RET_VAL:= MW 242
BUSY := M 244.0
DR := P#DB240.DBX 0.0 BYTE 4;
A M 244.0;
JC CP_BSY;
L DB240.DBD 0;
T "Diag_DB".CP_LED; // expose as OPC tag "CP_443_1_LED"
R M 240.0;
CP_BSY: NOP 0;
To detect "interface up" specifically, AND the returned value with W#16#0010 (RUN) and W#16#0040 (LINK) and compare to zero. Add W#16#0004 for BUSF and W#16#0008 for MAINTF to the alarm mask.
7. IM 153-2 PROFIBUS DP Interface LED Status (Redundant)
An ET 200M station with a redundant pair of IM 153-2 modules (e.g. 6ES7153-2BA10-0XB0) reports five front-panel LEDs per module. Reading them requires an SFC 13 (DPNRM_DG) call because the IM is a DP slave, not a module of rack 0. The diagnostic data record layout for IM 153-2 is standard PROFIBUS DP-V1 diagnostic and is documented in the IM 153-2 manual, but the LED bitmap is also returned in the slot-related partial SSL when read from the DP master interface (CPU DP port).
| Bit | LED name | Meaning |
|---|---|---|
| 0 | SF | Group error (module diagnostics present) |
| 1 | BF1 | Bus fault on PROFIBUS interface 1 |
| 2 | BF2 | Bus fault on PROFIBUS interface 2 (active in redundant mode) |
| 3 | ACT | IM is the active partner of the redundant pair |
| 4 | ON | 24 V supply present |
Reading the IM bitmap from the H-CPU uses the SSL W#16#0174 with the slot index returned by the DP master system. The cleanest pattern is to read DP-slave diagnostics with SFC 13 (DPNRM_DG) per ET 200M station, then unpack the LED bytes locally.
// SFC 13 - read standard slave diagnostics
CALL "DPNRM_DG"
REQ := M 260.0
LADDR := "Diag_DB".IM_LADDR // diagnostic address of ET200M
RET_VAL := MW 262
BUSY := M 264.0
RECORD := P#DB260.DBX 0.0 BYTE 26 // standard diag = 26 bytes
A M 264.0;
JC DG_BSY;
L DB260.DBB 5; // byte 5 = LED bitmap
T "Diag_DB".IM_LED; // 5 bits used
R M 260.0;
DG_BSY: NOP 0;
6ES7153-2BA10-0XB0 firmware V4.x, byte 5 holds the five IM 153-2 LEDs. Confirm against the IM 153-2 manual in the Hardware Documentation package for the firmware you ship.8. Distributed I/O Module SF LED Diagnostics
Every ET 200M I/O module (SM, FM, CP) reports a single SF (group error) LED that turns on when channel-level or module-level diagnostics exist. The diagnostic data record is read with SFB 52 (RDREC) for PROFINET devices and with SFC 13 (DPNRM_DG) for PROFIBUS stations.
Recommended reading pattern for an ET 200M PROFIBUS station with sixteen SM modules in slots 4-19:
// FB_ET200M_Loop - one call per module
FOR #i := 0 TO 15 DO
#slot := #i + 4;
#ioAddr := "Diag_DB".StationBase + (#slot * 4); // offset, depends on configuration
CALL "RDREC" , "RDREC_DB"
REQ := M 280.0
ID := #ioAddr
INDEX := 0 // standard diag index
MLEN := 26
VALID := M 282.0
BUSY := M 283.0
ERROR := M 284.0
STATUS := "Diag_DB".RDREC_Status
LEN := "Diag_DB".RDREC_Len
RECORD := P#DB280.DBX 0.0 BYTE 26;
A M 284.0;
JC LOOP_END;
A M 282.0;
JCN LOOP_END;
L DB280.DBB 5; // module status byte
L W#16#0002; // mask SF bit
AD;
<>I;
S "Diag_DB".SM_SF[#i]; // one bit per slot
LOOP_END: NOP 0;
END_FOR;
On PROFINET, replace the call with SFB 52 (RDREC) using the device's slot number; the same byte/bit mapping holds. For the slot/IO address scheme, the CPU's system data records SDB 0/1/2 and SDB 1000+ are parsed at startup and the resulting table stored in a global DB so the diagnostic loop does not need to be re-configured if a module is added.
9. SCADA Integration with WinCC / TIA Portal
The 4-byte DR returned for each module is exposed as a DWORD tag. SCADA mimics the LED panel by extracting individual bits and applying a colour mapping:
| Tag (DWORD) | Bit | HMI label | Tag colour |
|---|---|---|---|
| CPU0_LED | 0 | SF | Red |
| CPU0_LED | 3 | RUN | Green (lit-when-1, verify against your CPU FW) |
| CPU0_LED | 4 | STOP | Yellow (lit-when-1) |
| PS_LED_AGG | 1 | BAF | Yellow |
| PS_LED_AGG | 2 | BATT1F | Yellow |
| CP_443_1_LED | 2 | BUSF | Red |
| IM_LED | 1 | BF1 | Red |
| SM_SF[x] | 0 | SF | Red |
WinCC Professional convention: configure each LED as a separate tag of type BOOL derived from a 32-bit source by mask + shift in a script, or use the integrated "Status word to Boolean" conversion in the HMI tag properties. The script-based method is preferred for thousands of LEDs because it loads the source as a single DWORD:
' WinCC V7.5 VBS at tag change on CPU0_LED (DWORD)
Dim s : s = ""
If (CPU0_LED And &H1) <> 0 Then s = s & "SF;" ' bit 0
If (CPU0_LED And &H8) <> 0 Then s = s & "RUN;" ' bit 3
If (CPU0_LED And &H10) <> 0 Then s = s & "STOP;" ' bit 4
HMIRuntime.Trace "CPU0 LEDs: " & s
Alarm generation: drive a discrete alarm for each bit. The alarm text in WinCC is parameterised with the bit name so the operator sees e.g. "PS module – BATT1F" rather than a hex code. Where the SCADA is third-party (Ignition, iFIX, WinCC OA), the same DWORD is published as an OPC UA tag and split on the HMI side with the same bit mapping.
10. Alternative: Report System Errors (TIA Portal V20+)
TIA Portal V20 added Report System Errors support for S7-300/S7-400. The wizard generates OB82, OB83, OB86, OB87, OB122, OB121 and FB 49 (or FB 126 for fault-tolerant systems) plus a UDT that describes every diagnostic event with default alarm texts. The UDT includes a fault class, the device identifier and the standard diagnostic text; the LED bitmap itself is not directly exposed, but the EV_ID and the module's slot/IO address are.
Pros:
- Zero hand-written code: alarms and texts are configured by checkbox.
- Consistent text across plants using the standard Siemens message database.
Cons:
- Per-event scanning can be slower than one-shot SFC 51 reads in large I/O plants.
- LED-by-LED mimic in HMI requires an additional mapping of the alarm status word to the LED widget – you are effectively rebuilding the SSL decode.
Use RSE for alarm notifications, and SFC 51 when the operator needs a faithful image of every LED on the front panel. The two are not exclusive; the S7-400H system diagnostics blocks can be generated by RSE while the SFC 51 read loop runs in parallel for the HMI mimic.
See the official guide "Basics of system diagnostics (S7-300, S7-400) – TIA Portal V20" for the full configuration flow.
11. Verification and Commissioning Checklist
Use the following checks to confirm the diagnostic loop is wired correctly before plant handover:
- Compile the SFC 51 instance DB; download and switch CPU to RUN-P. Confirm RET_VAL = 0 and BUSY returns to FALSE within one OB1 cycle.
- Open
DB200.DBD 4in the variable table. The CPU0_LED word should read 0x0008 (RUN only) within five seconds of a clean cold restart. - Trigger a forced peripheral error: enter
SF_ONon a DO word in the watch table. Wait 6 s. The SF bit (bit 0) of the corresponding SM_SF should be set in the SCADA tag. - Pull a PROFIBUS connector at the active IM 153-2. The BF1 bit should toggle within 2 s. Reconnect; BF1 should clear after the link-up time (typically 30 s, dominated by the watchdog).
- Stop the master CPU in HW Config (online → stop). The STOP bit of CPU0_LED must be set within 1 s. Switch the standby CPU to master: the MAST bit must move to CPU1_LED within 200 ms.
- For the PS module test, remove the battery from slot 1. BATT1F should appear within 60 s (CPU scans the PS at 60-s intervals).
12. Troubleshooting Matrix
| Symptom | RET_VAL (decimal) | Root cause | Corrective action |
|---|---|---|---|
| BUSY stays TRUE | — | SFC 51 was called before the previous read completed; SSL index out of range | Poll BUSY and only start the next call after BUSY returns FALSE; verify INDEX against Chapter 34 of the System and Standard Functions manual |
| RET_VAL = 8082 | 8082 | CPU busy (communications or self-test) | Retry; or re-issue from OB100 cold-start only |
| RET_VAL = 8090 | 8090 | Specified SSL ID/INDEX not available on this CPU firmware | Check CPU firmware release notes; some SSLs were added in V5.3 (W#16#0091) and V6.0 (extended LED bitmaps) |
| RET_VAL = 80A1 | 80A1 | DR area too small for the partial list length | Increase the BYTE count on the DR pointer; LED partial list always returns 4 bytes |
| All LEDs show as 0 even on a faulted CPU | 0 | INDEX is a slot number, not a CPU logical address; the rack was renumbered after a hot swap | Re-read SSL W#16#0011 at startup and refresh the index table; or use the symbolic slot from HW Config |
| CP 443-1 LEDs are stuck at last value | 0 (intermittent) | CP in STOP because the connected partner went down; LEDs freeze until link returns | Cross-check the BUSF bit toggling; the CP firmware is allowed to freeze LEDs in STOP |
| DPNRM_DG returns BUSY but no RECORD update | — | Diagnostic address is wrong; SFC 13 targets the master (LADDR) but the slave has multiple DP masters | Use the diagnostic address of the slave's first slot, not the master port address; check in HW Config → DP slave properties → Diagnostics address |
| SF bit is permanently set on a healthy SM | 0 | The I/O module's diagnostic interrupt is configured but no OB82 is loaded | Insert OB82 (and OB83, OB86 for full coverage); otherwise the SF LED has no consumer and remains latched in the diagnostic buffer |
For deeper reference material on S7-400H diagnostics, the "Realization of a Fault-Tolerant Tunnel Lighting System With S7-400H" application example contains a complete STEP 7 V5.6 project with SFC 51 wrappers for CPU, PS, and IM modules and a WinCC flexible faceplate – the example is published by Siemens and is suitable for adapting to the S7-400H hardware diagnostics use case.
Frequently Asked Questions
Which SFC reads the LED status of an S7-400H CPU in STEP 7 V5.x?
SFC 51 (RDSYSST) with SZL_ID = W#16#0174 and INDEX = W#16#0001 for CPU 0 (rack 0, slot 1). The 4-byte data record returned contains one bit per LED; the bit-to-LED mapping is documented in Chapter 34 of the System and Standard Functions manual (entry ID 109751826).
How do I read the PS 407 10A LED bitmap for a redundant pair?
Call SFC 51 with SZL_ID = W#16#0174 once per PS module – INDEX = W#16#0003 for the slot-3 PS and W#16#0004 for the slot-4 PS (use W#16#0013 / W#16#0014 in rack 1). OR the two 4-byte records to a single PS_LED_AGG tag. The INTF, BAF, BATT1F, BATT2F, DC5V, and DC24V bits occupy bits 0-5 of the resulting DWORD.
Why does SFC 51 keep BUSY = TRUE and never finish?
Either the previous call has not yet completed (SFC 51 is asynchronous) or the SSL_ID/INDEX combination is not supported by the current CPU firmware (typical RET_VAL = 8090). Poll BUSY and only issue a new REQ when BUSY is FALSE, and verify the requested SSL against the firmware release notes for your CPU 41x-H.
Can Report System Errors in TIA Portal V20 read the same LED bitmaps?
Not directly. RSE generates text-based diagnostic alarms via FB 49 / FB 126, but the raw LED bitmap for an HMI mimic is still produced by SFC 51 or by an FB 125-equivalent decoding of the diagnostic buffers. Use both in parallel: RSE for alarm messaging and SFC 51 for the operator mimic.
How often should SFC 51 be triggered for the SCADA to look "live"?
Trigger every 250 ms to 1 s for the active master CPU; the partial list read is short (4 bytes) and typically returns in 5-15 ms on a 417-4H. Faster polling wastes OB35 time without improving the visible LED response, because the CPU's diagnostic update interval is already 250 ms by default.