1. S7-400H vs Software Redundancy (SWR): Choosing the Right Path
Before any hardware list is finalized, the first design decision on a Siemens redundancy project is the redundancy mechanism. Siemens offers two technically distinct families, and the component list in the field report — S7-414-4H CPUs, CP 443-1, PS 407-4A, Y-Link, ET200M — narrows that decision immediately. The S7-414-4H is a member of the S7-400H fault-tolerant family, which means the project is targeting hot redundancy, not SWR.
| Attribute | S7-400H (Hot Redundancy) | S7 Software Redundancy (SWR) |
|---|---|---|
| CPU families | S7-400H only (e.g., 412-4H, 414-4H, 416-4H, 417-4H) | S7-300 / S7-400 standard CPUs |
| Switchover time | Milliseconds; bounded and deterministic | Up to ~1 second (warm redundancy) |
| Data sync mechanism | Fiber-optic link between synchronization modules | User program copy via MPI / PROFIBUS / Ethernet CPs |
| Library required | No SWR library; standard STEP 7 blocks suffice | Yes — SWR library (SWR_RED, SWR_DIAG, etc.) |
| Programming model | Single program; both CPUs execute identical code | Master/standby FB/DB pairs must be coded by the user |
| Typical use | Process-critical, fast-bumpless transfer | Cost-sensitive, slower processes |
2. S7-400H System Architecture Overview
An S7-400H station consists of two electrically isolated sub-racks (UR1/UR2 or one UR split into two logical halves), each populated with a CPU 414-4H, a power supply (PS 407-4A or PS 405-4A), and an optional CP 443-1 for plant Ethernet. The two CPUs are connected through synchronization modules mounted on the back of each CPU and joined by fiber-optic patch cords. Up to four sync modules can be cascaded per CPU to extend the maximum distance.
Process I/O is typically placed on redundant PROFIBUS-DP segments that lead to ET200M stations or to switched DP/PA couplers. Where single-channel (non-redundant) I/O must remain on the existing bus — for example, third-party DP slaves or older ET200M that cannot be paired — a Y-Link (6ES7 197-1LA02 or later) is inserted in front of the segment, presenting a redundant interface to the H-system and a single interface to the legacy devices.
3. Required Hardware Components and Catalog Numbers
| Component | MLFB / Catalog No. | Qty | Function |
|---|---|---|---|
| CPU 414-4H | 6ES7 414-4HM14-0AB0 (or -4HL14) | 2 | Fault-tolerant CPU; executes identical user program |
| Power supply PS 407-4A | 6ES7 407-0DA02-0AA0 (10 A) or 0KR02 (20 A) | 2 | 24 V / 120/230 V → 5 V/24 V backplane |
| Sync module | 6ES7 960-1AA04 (short) / -1AB04 (long) | 2 to 8 | Optical interface on rear of CPU 414-4H |
| Fiber-optic patch cord | 6ES7 960-1AA04-0XA0 (1 m) / -1AA04-0XB0 (2 m) / -1AA04-0XC0 (10 m) | 2+ | Sync link between CPU0 ↔ CPU1 |
| CP 443-1 | 6GK7 443-1EX30-0XE0 (or -1GX30 for 1 Gbit) | 2 | Industrial Ethernet to plant network |
| Y-Link | 6ES7 197-1LA02 | 1+ | Single-channel DP slave ↔ redundant DP master |
| ET200M (IM 153-2) | 6ES7 153-2BA10-0XB0 or -2BA70 | 2 per segment | Redundant PROFIBUS-DP slave |
| Digital / analog I/O | SM 321 / SM 322 / SM 331 / SM 332 | as required | Process I/O |
| PROFIBUS cable | 6XV1 830-0EH10 | per segment | DP segment wiring |
4. Synchronization Modules and Fiber-Optic Cabling
The synchronization modules plug into the rear of each CPU 414-4H. Two slots are provided, allowing the link to be split across up to four FO cables (for longer distances or to traverse cabinet partitions). At each cycle the primary CPU transmits the process image, the active DBs, and configuration data to the standby. On any of the following events the standby becomes primary within milliseconds:
- Primary CPU STOP / hardware fault / power loss
- Sync module failure or FO cable break
- PROFIBUS-DP master failure on one sub-rack
- Triggered by
OB 70 / OB 72fault OBs
Maximum FO length between two sync modules is 10 m with the standard plastic cable; with the glass-fiber variant (6ES7 960-1AC04) distances up to 10 km can be achieved using two pairs of sync modules per CPU.
| Sync module pair | Cable type | Max distance |
|---|---|---|
| 6ES7 960-1AA04 ↔ -1AA04 | Plastic duplex, 1 m / 2 m / 10 m | 10 m |
| 6ES7 960-1AC04 ↔ -1AC04 | Glass (62.5/125 µm) | 10 km with 4 modules |
5. Y-Link Integration for Single-Channel I/O
Not every DP slave in a brown-field plant is redundant. Y-Link (6ES7 197-1LA02) is a Siemens DP/DP coupler with a "redundant DP master system" port on one side and a "single DP master system" port on the other. Configure the redundant side as follows:
- In HW Config, drag Y-Link from the catalog (path: PROFIBUS-DP > Network components > Y-Link) onto the redundant DP master system of CPU0.
- Assign a unique PROFIBUS address (default 33) to the Y-Link.
- On the lower (single-channel) side, drag the legacy DP slaves that must remain single-channel — older ET200M with IM 153-1, third-party drives, etc.
- Set the Y-Link operating mode to DPM1+DPM2 = active if both masters must drive it; otherwise leave the default where the active master is selected automatically by the H-system.
6. ET200M Distributed I/O Configuration
Redundant ET200M stations use the IM 153-2 (6ES7 153-2BA10-0XB0 or -2BA70). Each ET200M contains two IM 153-2 modules and a single backplane. To make the station redundant, both IMs must be assigned separate PROFIBUS addresses and connected to the two redundant DP master interfaces (one to CPU0, one to CPU1). All signal modules (SM 321, SM 322, SM 331, SM 332) are read by both IMs; the H-system selects the active IM.
| Module slot | Typical MLFB | Channel count |
|---|---|---|
| SM 321 DI 16×DC24V | 6ES7 321-1BH02-0AA0 | 16 DI |
| SM 322 DO 16×DC24V/0.5A | 6ES7 322-1BH01-0AA0 | 16 DO |
| SM 331 AI 8×12-bit | 6ES7 331-1KF02-0AB0 | 8 AI |
| SM 332 AO 8×12-bit | 6ES7 332-5HF00-0AB0 | 8 AO |
Configure the redundant ET200M by selecting DP slave properties > "Redundant operation" in HW Config. STEP 7 will then automatically assign two PROFIBUS addresses (e.g., 4 and 5) and generate the relevant diagnostic blocks.
7. STEP 7 / TIA Portal Project Setup
The S7-400H can be configured in either SIMATIC Manager STEP 7 V5.5 SP4+ or TIA Portal V14 SP1+. The procedure differs slightly:
7.1 STEP 7 V5.5 path
- Create a new project: File > New > User Project.
- Insert an S7-400H station (not an S7-400 station — the wizard explicitly offers "S7-400H").
- HW Config opens automatically with both sub-racks. Slot 1: PS 407-4A; Slot 3: CPU 414-4H; Slot 4: CP 443-1.
- Insert the sync module under the CPU properties ("Synchronization" tab).
- Configure the PROFIBUS-DP master system on each CPU and add Y-Link and ET200M stations.
7.2 TIA Portal path
- Create a new project and add a "Device" of type SIMATIC S7-400H with two RACK-0 / RACK-1 racks.
- Drag the CPU 414-4H into each rack; TIA Portal automatically proposes the H-system structure.
- Configure PROFINET / PROFIBUS interfaces from the device view.
- Use "Redundancy" properties on the CPU to enable hot redundancy.
8. Hardware Configuration in HW Config
After the mechanical build, HW Config is the single source of truth for the rack layout. The following parameters must be set identically on both sub-racks; STEP 7 does not enforce symmetry, but mismatches cause an "Rack fault" (SF LED on, diagnostic buffer entry Rack 0/1 configuration difference):
- Slot assignment and module type per slot
- PROFIBUS / PROFINET addresses and baud rate (DP master system: 1.5 Mbit/s default)
- IP addresses for CP 443-1 (CPU0: 192.168.0.10, CPU1: 192.168.0.11 typical)
- Subnet mask and router (if applicable)
- Synchronization module assignment (ports 1 and 2)
Compile and download to both CPUs in the order CPU0 first, then CPU1. After download each CPU will report "Standby" or "Active" in the diagnostic buffer; the operator panel on the CPU face displays the current role.
9. Communication Setup with CP 443-1
CP 443-1 (firmware V2.x or V3.x depending on catalog number) is the Ethernet gateway. In an H-system, the two CPs must run in redundant mode, meaning only one CP is logically "active" while the other is "passive" but continuously updates its connection list.
- In HW Config, open the CP 443-1 properties and select "Redundant operation with partner CP".
- Set the partner CP's MAC address (read from the face of the second CP).
- Configure an S7 connection for each CP using NetPro.
- For HMI / SCADA, use the S7-REDCONNECT function block (FB 405) so the client automatically fails over from CP0 to CP1 within ~3 s.
10. Programming Considerations and OB1 Execution
Hot redundancy means one user program is loaded into both CPUs. There is no master/standby branch in the application code; the active CPU simply executes OB 1 while the standby runs but is inhibited from writing outputs. The following OBs are critical for fault handling:
| OB | Trigger | Recommended handling |
|---|---|---|
| OB 70 | Redundancy loss (e.g., FO link break with master/standby still alive) | Log via SFC 6 / SFC 13; raise operator alarm |
| OB 72 | CPU redundancy failure (standby no longer usable) | Same as OB 70; optionally transfer process to safe state |
| OB 80 / 81 / 82 / 83 / 84 / 85 / 86 | Time, power, interrupt, pull/plug, CPU, comms, rack faults | Default empty OBs are acceptable; populate for diagnostics |
| Warm restart | ||
| OB 101 | Hot restart | |
| OB 102 | Cold restart |
The standard library "S7HCOM" provides FB 405 (S7-REDCONNECT) for redundant S7 connections and FB 458 (S7-F-REDCONNECT) for fail-safe variants. These blocks are not the same as the SWR library and are not interchangeable.
11. Commissioning and Verification
- Pre-power checks. Verify that all backplane screws are torqued, PS 407 input is wired to a redundant 24 V source, and FO cables have clean connectors. A single contaminated FO end-face can prevent sync startup.
- Power-on sequence. Energize PS 407-4A on rack 0; wait until CPU 0 reaches "RUN/Active". Then energize rack 1; CPU 1 will boot, sync, and report "RUN/Standby".
-
Diagnostic verification. On each CPU, open SIMATIC Manager > CPU > Module Information > Diagnostic Buffer. Confirm
Event ID 16#4949"H-system synchronized" is present on both. - Switchover test. With the process in a safe state, stop CPU 0 (toggle the mode switch to STOP). CPU 1 must transition to "Active" within 100 ms (typical) without any OB 85 / OB 122 being called.
-
PROFIBUS redundancy test. Pull the DP connector on CPU 0's PROFIBUS interface. All redundant ET200M stations must continue to communicate via CPU 1. Verify in the diagnostic buffer that the affected DP slave reports
16#394A"Master changed". - CP 443-1 failover test. From an HMI / SCADA client, ping CPU 0's CP; the connection should reroute to CPU 1 within ~3 s when the CP 443-1 on rack 0 is unplugged.
- Y-Link test. Force a switch on Y-Link (PROFIBUS diagnostics > "Slot 0") and verify that single-channel slaves downstream remain accessible.
12. Troubleshooting Matrix
| Symptom | Diagnostic entry / LED | Probable root cause | Corrective action |
|---|---|---|---|
| CPU 1 stays in "STOP/Defect" after power-up | SF on; buffer event 16#4971 sync error |
FO cable crossed or damaged; sync module not fully seated | Re-seat sync modules; swap FO cables; clean end faces with IPA |
| CPU 1 in "RUN/Solo" — no standby | Buffer event 16#4954
|
Firmware mismatch or CPU type mismatch | Use identical MLFBs and identical firmware versions |
| Frequent switchovers (every few minutes) | OB 70 called repeatedly | Marginal FO link (length, bend radius, dirty connectors) | Replace FO cable; verify bend radius ≥ 30 mm; inspect connectors under magnifier |
| ET200M loses I/O on switchover | Buffer event 16#3942 on DP slave |
ET200M not configured as redundant in HW Config | Open DP slave properties; tick "Redundant operation"; recompile |
| Y-Link does not appear in HW Config | GSD file missing | Y-Link GSD not installed for this STEP 7 version | Install Y-Link GSD from Siemens support; restart HW Config |
| CP 443-1 partner CP not visible | Diagnostic buffer 16#4583
|
Wrong partner MAC address entered | Read MAC from face of partner CP; correct in CP properties |
| S7-REDCONNECT status = 16#0001 (no redundancy) | FB 405 status word | CP 443-1 firmware too old, or H-system not in RUN/Active | Upgrade CP firmware to V2.5+; verify CPU mode |
| OB 85 called on standby CPU | Buffer event 16#35xx
|
Residual I/O access from outside OB 1 (e.g., in OB 100) | Move all I/O accesses inside OB 1 or OB 35; use process image partition |
13. Field-Proven Caveats
- Hot-standby timing. A scan-time of 20 ms with full sync each cycle means roughly 5–8 % of CPU throughput is consumed by redundancy housekeeping. On a CPU 414-4H, do not budget above 80 % program execution.
- Programming tool choice. Newer projects benefit from TIA Portal V16+ for unified engineering, but STEP 7 V5.5 SP4 still offers the most mature set of redundancy diagnostic faceplates and is the de-facto standard in brown-field plants.
- Documentation set. Reference the SIMATIC S7-400H Fault-Tolerant Systems manual (entry ID 1186523 on Siemens Industry Online Support) and the S7-400H Programmable Controller system manual (entry ID 1109502) for hardware specifications.
- Spare-parts strategy. Always stock two spare sync modules and two spare CP 443-1 modules; a swap requires both racks to be powered down only if the active CP fails simultaneously.
14. Related Documentation on Siemens Industry Online Support
For ordering data, firmware updates, GSD files, and application examples refer to the Siemens Industry Online Support portal at support.industry.siemens.com. Common entry IDs relevant to S7-400H are 1186523 (Fault-Tolerant Systems manual), 1109502 (S7-400 system manual), 16818709 (S7-400H configuration example), and 77377611 (CP 443-1 firmware). Search by these IDs if direct navigation is not available.
Which Siemens manuals do I need for an S7-400H project?
Use the SIMATIC S7-400H Fault-Tolerant Systems manual (Siemens support entry ID 1186523) as the primary reference for architecture, sync modules, and Y-Link. Pair it with the S7-400 Programmable Controller system manual (entry ID 1109502) and the CP 443-1 manual for Ethernet configuration.
Do I need the SWR library for an S7-414-4H redundant station?
No. The SWR library applies only to Software Redundancy between standard S7-300/S7-400 CPUs. The S7-414-4H is a fault-tolerant CPU with hot redundancy built into its firmware; user-level synchronization is handled by the CPU, not by an FB library.
What is the typical switchover time of an S7-400H?
Switchover from active to standby CPU occurs in single-digit milliseconds (typically < 100 ms including output update). Compare this to SWR, where switchover can take up to 1 s — too slow for fast processes.
Can I mix redundant and single-channel I/O on the same H-system?
Yes, using a Y-Link (6ES7 197-1LA02). The Y-Link presents a redundant DP master interface to the H-system and a single DP master interface to downstream single-channel devices. Note that single-channel I/O downstream is not made redundant by the Y-Link itself.
Why does the standby CPU remain in STOP after power-up?
Common causes are damaged or swapped fiber-optic cables, misseated sync modules, or firmware mismatch between the two CPUs. Verify FO connectors under a magnifier, confirm sync modules are fully clipped into the rear of the CPU, and ensure both CPUs carry identical MLFBs and firmware versions.
How many ET200M stations can a CPU 414-4H address?
The CPU 414-4H supports up to 125 DP slaves per PROFIBUS master system. With two DP master interfaces per CPU and redundant ET200M using two PROFIBUS addresses each, plan for roughly 30 to 50 redundant ET200M stations depending on cycle-time budget and signal-module density.