S7-400H Optical Ring PROFIBUS: DP Slave Redundancy and Y-Link Integration
This reference documents the engineering constraints, failure modes, and approved configurations when connecting a SIMATIC S7-400H fault-tolerant system to a PROFIBUS optical ring populated with ET 200M stations (IM 153) and non-redundant DP slaves. It is written for system engineers commissioning high-availability plants where I/O availability under CPU switchover is a contractual requirement.
1. S7-400H Redundancy Architecture Overview
The SIMATIC S7-400H is a fault-tolerant automation system built around two H-CPUs of identical type and firmware revision (for example CPU 417-3H, CPU 414-4H, CPU 416-3H, CPU 412-3H) running in synchronized hot-standby. Synchronization is performed over two dedicated fiber-optic links routed through synchronization modules (Sync-Module / Sync-Sub-Module) plugged into the CPU backplane. The standard fiber-optic redundancy connections are described for the S7-1500H in the SIMATIC S7-1500 / ET 200MP manual collection under Connecting redundancy connections (fiber-optic cables) to S7-1500H: Connecting redundancy connections (fiber-optic cables) to S7-1500H. The S7-400H implements the same concept with the older H sync modules, but the link budget, max cable length (typically up to 10 m between H-CPUs in the same cabinet, or up to 10 km with long-distance sync modules), and the requirement for two physically diverse fiber routes are identical in principle.
Each H-CPU owns its own PROFIBUS DP interfaces (typically IF 964-DP / CP 443-5 Extended). The H system exposes two logical stations to STEP 7 HW Config: Station 0 (CPU0/master) and Station 1 (CPU1/standby). On a runtime fault, the standby CPU takes over mastership and the failing CPU is suppressed. This switchover is the central reason that DP slaves must be addressed in a redundant-aware way.
2. Optical Ring Topology with OLM
PROFIBUS copper segments are limited to 12 Mbit/s over 100 m, which is insufficient for plant-wide PROFIBUS backbones. Siemens Optical Link Modules (OLM) convert the electrical PROFIBUS DP signal to fiber and allow ring, line, or star topologies. Typical OLM modules for PROFIBUS are:
| OLM | Fiber type | Max ring length | Diagnostic |
|---|---|---|---|
| 6GK1 502-2CB00 (OLM/P11) | Plastic / PCF | Up to 400 m | Basic LED |
| 6GK1 502-3CB00 (OLM/P12) | Plastic / PCF | Up to 400 m | Basic LED |
| 6GK1 503-2CB00 (OLM/G11) | Glass multimode | Up to 3,000 m | Basic LED |
| 6GK1 503-3CB00 (OLM/G12) | Glass multimode | Up to 3,000 m | Basic LED |
| 6GK1 503-2CC00 (OLM/G11-1300) | Glass single-mode / 1300 nm | Up to 15 km | Web / SNMP |
| 6GK1 503-3CC00 (OLM/G12-1300) | Glass single-mode / 1300 nm | Up to 15 km | Web / SNMP |
An OLM ring (RS-485 optical ring) provides cable-break tolerance: if any single fiber segment fails, the OLMs close the ring within milliseconds and PROFIBUS traffic continues. The ring must be closed physically and OLMs must have the ring-closure function enabled in their DIP switches (termination + ring on the two ring ports). Mixing P and G types on a single ring is not permitted; use the same family end-to-end to avoid timing budget errors.
2.1 Connection of H-CPUs to the OLM ring
Each H-CPU connects to the optical ring via a dedicated OLM pair. A typical layout for a single shared ring is:
S7-400H CPU0 ---[Cu PROFIBUS]--- OLM1 ---[Fiber]--- OLM2 ---[Cu]--- S7-400H CPU1
| |
[Fiber] [Fiber]
| |
OLM3 ------------------------------ OLM4
| |
[Cu] [Cu]
IM 153-1 IM 153-1
The OLM ring tolerates one break; however, this topology has a single point of failure on the H side: the two OLM uplinks to the CPUs are on the same physical ring. A break between OLM1 and OLM2 isolates one of the H-CPUs from the distributed I/O.
3. The Non-Redundant DP Slave Switchover Problem
The fundamental engineering constraint that drives the dual-ring / Y-Link architecture is: a single-channel DP slave connected to Station 0 of an H system cannot survive a CPU switchover. After switchover, the new master (formerly Station 1) takes over the bus and re-initializes DP slaves that belong to the old Station 0. The slave loses its process image, its outputs go to fail-safe state, and the application sees an I/O fault on the first scan after the switchover — typically for the duration of one DP bus cycle plus the slave's parameterization time (50 ms to several seconds for an ET 200M).
Configuring the same DP slave on both Station 0 and Station 1 does not solve the problem. STEP 7 will assign the same PROFIBUS address to the slave from both logical stations, but at runtime exactly one H-CPU is master at any given time. The other H-CPU is in standby and does not arbitrate the bus. The slave cannot be "owned" by both logical stations simultaneously — the bus is single-master.
4. IM 153-1 versus IM 153-2 Migration
ET 200M stations are connected to the optical ring through IM 153 interface modules. The two relevant variants are:
| Feature | IM 153-1 (6ES7 153-1AA..) | IM 153-2 (6ES7 153-2BA.. / 2BB..) |
|---|---|---|
| Status | Product discontinued / not available for new projects | Active product, current portfolio |
| Max number of modules | 8 | 12 (high-feature) |
| Redundancy support | No | Yes, with IM 153-2 paired on redundant PROFIBUS |
| PROFIBUS | DP-V0 | DP-V1, DP-V2 |
| Diagnostic buffer | Limited | Extended, channel-level diagnostics |
| Y-Link compatible | Marginal | Yes, required for non-redundant S7-300/S7-200 slaves |
For any S7-400H project commissioned today, specify IM 153-2. The IM 153-1 is no longer available, and using it forces a redesign once spares are exhausted. Pair two IM 153-2 modules with active backplane bus (redundant PROFIBUS interface) to obtain I/O-level redundancy; a single IM 153-2 does not provide I/O redundancy under H-CPU switchover.
5. Y-Link Solution Architecture
A Y-Link (6ES7 197-1LA02 / 1LA12) is a PROFIBUS DP/DP coupler that connects a single-channel PROFIBUS DP segment (lower-level, non-redundant) to the redundant PROFIBUS of an S7-400H. The Y-Link appears to the H system as two PROFIBUS slaves (one on Station 0, one on Station 1). It forwards process data to and from the lower-level single-channel DP slaves transparently. The H system can address the slaves through the Y-Link as if they were redundant participants, because the H system only sees the Y-Link proxy.
Architecture with Y-Link:
S7-400H CPU0 (Station 0) S7-400H CPU1 (Station 1)
| |
+-------[Redundant PROFIBUS]----+
|
Y-Link
|
[Single-channel PROFIBUS]
|
+-------+--------+--------+-------+
| | | | |
S7-200 S7-300 Drive I/O Encoder
slave slave (CU) module (SSI)
The Y-Link must be configured in STEP 7 with:
- Upper PROFIBUS addresses on Station 0 and Station 1 (e.g., address 3 and 4)
- Lower PROFIBUS address space (default 1 to 49, configurable)
- DP-V1 mode enabled if the lower-level slaves use DP-V1 diagnostics
- Slave diagnostic filtering set to "forward all" if the lower-level slaves are mixed vendors
The Y-Link is hot-swappable and supports PROFIsafe pass-through when the lower-level slaves are PROFIsafe devices — this is the only approved topology for PROFIsafe S7-300/ET 200M stations on a non-redundant segment of an S7-400H.
6. Recommended Dual-Ring Configuration
The configuration that delivers full H-system availability for distributed I/O is two physically independent optical rings, one per H-CPU. The drawing below corresponds to the layout that was finally accepted on the project that prompted this article:
S7-400H CPU0 -----high-speed fiber----- S7-400H CPU1
(Station 0) (Station 1)
| |
Cu Cu
| |
OLM1 ------- optical ring 1 (CPU0) ------- OLM2
| |
OLM3 ------- optical ring 2 (CPU1) ------- OLM4
| |
Cu Cu
| |
IM 153-2 IM 153-2
(redundant pair, (redundant pair,
active bus) active bus)
Component count and topology requirements for the dual-ring configuration:
| Item | Quantity | Notes |
|---|---|---|
| OLM ring masters (or RS-485 with ring closure) | 2 rings × 2 OLMs = 4 minimum, more if distributed I/O has > 2 OLM drops per ring | Match fiber type to plant backbone |
| IM 153-2 (redundant pair, active bus modules) | 1 pair per ET 200M station | Both IM 153-2 must be on the same PROFIBUS address on ring 1 / ring 2 respectively; configure as H-station in STEP 7 |
| Y-Link | 1 per non-redundant DP segment (S7-200, S7-300, drives, third-party) | Place Y-Link on both rings; it appears as a slave on each |
| Fiber patch panels | 1 per ring | ST or SC connectors depending on OLM type |
| Diagnostic repeater (optional) | 1 per ring | RS-485 diagnostic repeater 6ES7 972-0AB01 for segment-level diagnostics |
This is the configuration deployed in the final customer solution: double CPU 417-3H with double optical ring, redundant IM 153-2 (active bus) and Y-Link for S7-200 and S7-300 slaves. CPU 417-3H is the highest-end H-CPU in the S7-400H portfolio (article number 6ES7 417-3XT05-0AB0) and supports up to 4 DP lines, of which two can be used for the redundant distributed I/O.
7. PROFINET MRP Alternative for New Projects
For new S7-400H plants, the trend is to substitute the PROFIBUS optical ring with PROFINET MRP (Media Redundancy Protocol) on SCALANCE switches. The official reference configuration is Configuration Examples for S7-400H with PROFINET: Configuration Examples for S7-400H with PROFINET (PDF). The same constraint applies: the subordinate MRP ring can be connected either via SCALANCE switches or directly at the PN devices of the subordinate station. IM 153-2 PN IO (6ES7 153-2BA10-0XB0) replaces IM 153-2 DP in the PROFINET version, with the same redundancy semantics on the PROFINET ring.
When migrating an existing PROFIBUS OLM ring to PROFINET MRP, retain the Y-Link topology. The PROFINET equivalent of the Y-Link is the PN/PN coupler (6ES7 158-3AD01) which is the redundancy-aware gateway between a redundant PROFINET ring and a non-redundant PROFINET segment.
8. Step-by-Step Configuration Procedure
The following procedure is for STEP 7 V5.5 / SIMATIC Manager with S7-400H. For TIA Portal with S7-1500H, the steps are similar but the catalog differs.
- Insert H-station in HW Config. Open SIMATIC Manager → HW Config → File → New. Insert SIMATIC 400 → S7-400H. Choose a CPU from the rack; place two of the same article number (for example 6ES7 417-3XT05-0AB0) in slots 1 and 2 of the two H-racks. The synchronization modules occupy the slots immediately adjacent to the CPU.
- Configure sync modules. Assign a sync module to each CPU. The two fiber-optic links between the sync modules must follow physically diverse routes. Note the maximum length: 10 m for short-distance modules (FO), 10 km for long-distance (LD) modules.
- Insert PROFIBUS DP master interfaces. For each H-CPU, add IF 964-DP (only for older CPUs) or use the integrated DP interface of CPU 41x-3/4. Configure PROFIBUS addresses: typically CPU0 = 2, CPU1 = 3. Enable DP master mode.
- Insert OLM objects. From the catalog, insert PROFIBUS DP → OLM. Assign a unique PROFIBUS address to each OLM (e.g., 1, 2, 3, 4 for the four OLMs of a two-ring configuration). Set ring closure on the appropriate ports.
- Insert ET 200M stations (IM 153-2 redundant pair). Configure two IM 153-2 modules in a redundant PROFIBUS configuration: DP slave properties → Operating mode → Redundant. Assign lower PROFIBUS addresses for ring 1 and ring 2 respectively. The modules must have the same firmware revision.
- Insert Y-Link for non-redundant slaves. From catalog → PROFIBUS DP → Y-Link. Connect the Y-Link to both rings (Station 0 and Station 1 DP lines). Configure the lower-level address range. Connect downstream S7-200 / S7-300 / drives to the lower-level segment.
- Configure OB 70 / OB 72 / OB 82 / OB 83 / OB 85 / OB 86 / OB 87 / OB 88 / OB 121 / OB 122. These organization blocks handle H-system events: OB 70 (I/O redundancy loss), OB 72 (CPU redundancy loss), OB 86 (DP slave failure). Without OBs loaded, the CPU goes to STOP on the first slave fault.
-
Download to both H-CPUs. Use STEP 7 → PLC → Download to H-CPU. Always perform a consistent download of the H-station to both CPUs. After the download, the H system performs a link-up and synchronizes; verify both CPUs are in RUN with H-status
RUN-REDUNon the HMI.
9. Verification and Commissioning
After the configuration is downloaded, run the following verification sequence. Each step has a pass/fail criterion that must be met before proceeding to the next step.
| Step | Action | Pass criterion |
|---|---|---|
| 1 | Check H-sync status in STEP 7 (PLC → H-CPU Diagnostics) | Both CPUs RUN-REDUN, sync link OK, no diagnostic buffer entries of class 2 or higher |
| 2 | Check PROFIBUS diagnostics for each ring | All OLMs report ring closed, no slave with Station Failure or Diagnostic Not Available
|
| 3 | Check IM 153-2 redundant pair | Both IM 153-2 report Primary/Backup status, channel diagnostics OK on the active module |
| 4 | Check Y-Link diagnostics | Y-Link shows OK on both upper and lower segments, lower-level slaves visible in the H-station slave list |
| 5 | Forced switchover test | Trigger H-CPU switchover via STEP 7 (PLC → H-CPU → Switchover). Outputs on redundant IM 153-2 must not glitch. Outputs on single-channel Y-Link slaves will drop for one DP cycle and recover — this is expected and must be documented in the Functional Safety report if PROFIsafe is involved. |
| 6 | Optical ring break test | Disconnect one fiber segment between OLM1 and OLM2. Ring must auto-close within < 200 ms. All DP slaves must remain online. Reconnect; ring must auto-recover. |
| 7 | CPU power-cycle test | Power off CPU0. CPU1 takes over. Application continues. Power on CPU0; it must re-sync and return to standby. Repeat with CPU1. |
The forced switchover test (step 5) is the critical verification. The expected result on a properly configured Y-Link is: outputs on the single-channel lower-level slaves drop for one PROFIBUS cycle (typically 5 to 50 ms depending on baud rate and bus load), the H-system continues to run, and the process recovers. If the H-CPU goes to STOP after the switchover, OB 86 (or another OB) is missing — do not attempt to mask the symptom by removing diagnostics.
10. Troubleshooting Matrix
| Symptom | Likely root cause | Diagnostic | Remediation |
|---|---|---|---|
H-CPU goes to STOP after switchover with SF LED on the DP master |
OB 86 not loaded; DP slave failure on switchover | STEP 7 → Module Information → Diagnostic Buffer | Load OB 86 (and OB 82, OB 85, OB 122) into the H-station and re-download |
| DP slave fails on switchover, never recovers | Single-channel slave on Station 0, no Y-Link | STEP 7 → PROFIBUS Diagnostics → Slave List | Insert Y-Link on the lower-level segment; or migrate to a redundant IM 153-2 pair |
| Y-Link lower-level slaves flicker continuously | Y-Link address conflict or DP-V1 mismatch | Y-Link diagnostic buffer via web interface (if equipped) or STEP 7 | Verify Y-Link address range; enable DP-V1 on lower-level slaves; check that the same address is not used on both H-station sides |
| IM 153-2 does not establish redundant pair | Different firmware revisions, wrong GSD file | Online → IM 153-2 → Module Information | Equalize firmware; use the correct GSD for the redundant pair configuration |
| Optical ring does not close after fiber break | OLM ring-closure DIP switch not set; mixed OLM types | OLM LED status; diagnostic via web (on managed OLMs) | Enable ring closure on the appropriate ports; replace mixed OLM types with a single family |
| H-sync link fails intermittently | Bent fiber, dirty connector, exceeded link budget | Sync module signal level diagnostic; visual inspection with fiber scope | Clean connectors; verify link budget with optical loss test set; check that the two sync fiber paths follow diverse routes |
| CPU 0 cannot reach I/O on ring 1, but CPU 1 can | Single point of failure on OLM uplink to CPU 0 | OLM LED; OLM diagnostic | Adopt the dual-ring configuration (one ring per CPU) for true independent paths |
11. Field-Proven Caveats
12. Specifications Summary
| Parameter | Value |
|---|---|
| H-CPU maximum | CPU 417-3H (6ES7 417-3XT05-0AB0) |
| Sync module max distance | 10 m (FO standard), 10 km (LD long-distance) |
| Sync module count | 2 (mandatory) per H-station |
| PROFIBUS DP master per H-CPU | Up to 4 DP lines (CPU-dependent) |
| PROFIBUS baud rate | 9.6 kbit/s to 12 Mbit/s |
| OLM ring fault reaction time | < 200 ms typical |
| IM 153-2 redundant pair max modules | 12 per station (high-feature) |
| Y-Link upper PROFIBUS addresses | 2 (one on Station 0, one on Station 1) |
| Y-Link lower address range | Configurable, default 1 to 49 |
| PROFINET MRP equivalent | PN/PN coupler 6ES7 158-3AD01 |
Is it possible to connect an S7-400H to a non-redundant IM 153 through a single optical ring?
It is technically possible, but the IM 153-1 (and a single IM 153-2) cannot survive an H-CPU switchover. The DP segment will fail for one bus cycle and the application will see an I/O fault. For any availability target above best-effort, use a redundant IM 153-2 pair on a dual-ring configuration, or place non-redundant slaves behind a Y-Link.
Why does configuring the same DP slave on Station 0 and Station 1 not provide redundancy?
PROFIBUS DP is a single-master bus. At any given time, only one H-CPU is the active master; the other is in standby and does not arbitrate the bus. A slave can be addressed by only one logical station at a time, so the switchover re-initializes the slave from the new master and the process image is lost for the parameterization duration.
Which IM 153 module should I use today for an S7-400H project?
Use IM 153-2 (6ES7 153-2BA02 or 2BB02), configured in redundant pairs with active backplane bus. The IM 153-1 is discontinued and no longer available for new orders; spares are also constrained.
What is the difference between a Y-Link and a PN/PN coupler?
Both are redundancy-aware gateways between an S7-400H redundant segment and a non-redundant lower-level segment. The Y-Link (6ES7 197-1LA02 / 1LA12) is for PROFIBUS DP. The PN/PN coupler (6ES7 158-3AD01) is the PROFINET equivalent. Use the device that matches the physical layer of the lower-level segment.
How long does an H-CPU switchover take, and what is the I/O drop-out time?
The H-system switchover is typically completed within 100 ms. Outputs on redundant IM 153-2 stations are not interrupted. Outputs on single-channel slaves behind a Y-Link drop for one PROFIBUS cycle (5 ms at 1.5 Mbit/s, up to 50 ms at 187.5 kbit/s). Configure OB 70, OB 72, OB 82, OB 86, and OB 122 to prevent the CPU from going to STOP during switchover.