S7-412-3H Online Monitoring: Resolving Slave CPU Access Errors

David Krause22 min read
S7-400SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

S7-412-3H Online Monitoring: Resolving Slave CPU Access and Connection Errors

The Siemens SIMATIC S7-412-3H is a fault-tolerant CPU from the S7-400H family designed for high-availability automation in power, water, petrochemical, and process industries. Engineers commissioning redundant S7-400H systems frequently encounter online monitoring failures when attempting to access the standby (slave) CPU directly, when an upload from the master returns the message "Compiler address empty" (German: "Baugruppenträger leer"), or when a previously uploaded backup throws "Connection aborted" / "Verbindung abgebrochen" the moment the engineer chooses View > Online. This troubleshooting reference covers the architectural reasons behind these symptoms, the diagnostic workflow, and the field-proven resolution path for the 6ES7412-3HJ14-0AB0 (CPU 412-3H), 6ES7412-3EK07-0AB0 (CPU 412-3H PN/DP), and 6ES7412-3EM08-0AB0 variants, all deployed in an H-system chassis (UR1-H 6ES7400-1JA01-0AA0 or UR2-H 6ES7400-2JA10-0AA0).

1. Problem Description and Reported Symptoms

Engineers report the following set of symptoms on S7-412-3H systems fitted with a flash memory card (MMC, 5 V version such as 6ES7952-1KS00-0AA0 or 6ES7952-1KP00-0AA0):

  • Uploading via MPI cable from the standby CPU returns the message "Compiler address empty" (or the equivalent in localized STEP 7: "Baugruppenträger leer", "Target rack empty", or "Online: no nodes found").
  • Uploading from the master CPU completes successfully and writes a backup project to disk, but opening the backup and selecting View > Online returns "Connection aborted" (or "Verbindung abgebrochen", "Online not possible").
  • View > Online on the master CPU's S7 program inside SIMATIC Manager (STEP 7 V5.5 SP4 or V5.7) works normally and shows live process values, indicating that the physical PG/PC interface and bus wiring are functional.
  • No RED, SF, EXTF, or BF LED is active on either CPU, and the diagnostic buffer of both CPUs is free of redundancy errors. The system is in RUN-Redundant (RUN on master, SYNCUP and RUN on standby).
  • The same MPI interface on a sibling S7-400H rack deployed elsewhere in the same plant can successfully upload from the standby CPU and monitor it. This proves the cable, the PC adapter (e.g. 6ES7972-0CB20-0XA0 USB-MPI), and the STEP 7 installation are not at fault.
Engineering note: The presence of a successful upload on a sibling S7-400H rack in the same plant is a key indicator that the failure is logical, not physical. The cause is specific to the way the H-system presents itself to engineering tools over MPI/PROFIBUS/Industrial Ethernet.

2. S7-400H System Architecture Recap

The S7-400H is Siemens' high-availability PLC platform, marketed as "Fault-Tolerant Systems". Each rack contains two CPUs of identical type (for example two CPU 412-3H or two CPU 414-4H) that execute the user program in parallel. One CPU is designated the master and the other the standby; the assignment is determined at startup based on the configured roles in HW Config and, if the configured master is missing, by the CPU with the higher ramp-up priority. See the SIMATIC S7-400H Fault-Tolerant Systems Manual, section 4.3 "H-system behavior during operation".

Key architectural properties of the S7-400H that are directly relevant to online access:

Property Master CPU Standby CPU
Executes user program Yes Yes (synchronized, hot-standby)
Updates process I/O Yes No (passive role)
Accepts online connection from PG Yes No (system policy)
Visible in "Accessible Nodes" via MPI/DP/IE Yes No, the standby responds with the master's address
Independent connection resources Yes No (mirrored to the master)
Holds the SYNC link to partner CPU Yes Yes (via fiber-optic cable on synchronization modules 6ES7960-1AA04-0XA0 or 6ES7960-1AB05-0XA0)
Carries DP/PN master role Yes No (in pure H-mode, only master is DP/PN master)

The two CPUs communicate over a dedicated, redundant fiber-optic synchronization link. Each CPU has two synchronization module slots. The link is established automatically at startup; loss of the link forces the standby into STOP with a redundancy error (red LED on). Once the link is restored and both CPUs have synchronized, the H-system transitions to RUN-Redundant.

3. Root Cause 1 — The Standby CPU Is Not a Standalone Engineering Target

On an H-system, the standby CPU is not an independent online target for STEP 7. The two CPUs form a single logical controller, sometimes referred to in Siemens documentation as a "redundancy node" or "H-station". The standby's MPI/DP/PN interface responds to address resolution queries with the master CPU's address and routing information, not its own. This is the reason that the "Accessible Nodes" list (or a direct online upload via "PLC > Upload Station to PG") returns a single node even though the rack contains two CPUs.

The "Compiler address empty" / "Baugruppenträger leer" message in this context means that STEP 7 resolved the physical destination on the bus but found no engineering target that matches the configured access point. The PG attempted to authenticate against the standby's slot, the standby redirected the request to the master, and the master's slot is reachable only on its own MPI/DP address — not on the standby's. The STEP 7 path is therefore syntactically valid but semantically rejected by the H-system firmware.

This is documented behavior, not a bug. The S7-400H manual, chapter 5.2 states explicitly: "Online functions of the programming device (PG) can only be performed on the master CPU of the H-system. Online access to the standby CPU is not supported and will be rejected."

4. Root Cause 2 — Connection Resource Exhaustion

The CPU 412-3H has a fixed number of online connection resources, partitioned into PG, OP, and S7 slots. According to the S7-400 CPU 412-3H data sheet (Firmware V6.0 and later, 6ES7412-3HJ14-0AB0), the standard allocation is:

Resource type Default count Configurable range
PG connections (engineering) 1 1 to 4
OP connections (HMI / WinCC flexible / TIA panels) 16 0 to 16
S7 connections (S7-300/400, OPC, routing) 16 0 to 16
Total connection resources (master + standby) 32

Important: connection resources in an H-system are counted once for the pair, not per CPU. If all 32 slots are held by HMI panels, OPC servers (e.g. SIMATIC NET OPC, WinCC, third-party SCADA via S7-MPI/TCP), and active S7 routes, the engineering station's attempt to open a PG connection can return "Connection aborted" because the CPU has refused to allocate a slot. The SF/BF/RED LEDs do not illuminate for resource exhaustion — this is a normal rejection, not a system fault. The diagnostic buffer of the master will contain entries with ID W#16#4570 ("resource exhausted") or W#16#4301 ("connection aborted").

Reference: SIMATIC S7-400 CPU 412-3H PN/DP data sheet, section "Communication resources".

5. Root Cause 3 — Uploaded Backup Program Has No Online Path

Uploading a program from the master CPU produces an offline S7 program (the source blocks FBs, FCs, DBs, SFBs, SFCs, SDBs, and the system data). The offline program does not contain a complete online path. When the engineer opens the offline project and chooses View > Online, STEP 7 attempts to resolve the configured "online interface" (PG/PC interface) and the partner address stored in the project header. If that address happens to be the standby CPU's MPI node (which can occur when the original online project was edited against the standby's address in a different S7-400H rack), the request will fail with "Connection aborted" because, per Section 3, the standby is not a valid engineering target.

Critical: Even if the upload came from the master, STEP 7 sometimes stores the standby's MPI address in the connection table of the offline project, particularly if the engineer had previously executed PLC > Download to Target System from a project that listed the standby as the online partner. The remedy is to manually correct the online access point to the master's address in the S7 program properties.

6. Diagnostic Workflow

Use the following ordered procedure to isolate the failure before changing configuration. Do not skip steps; an incorrectly edited S7 program in an H-system is more disruptive to recover from than in a single-CPU system.

  1. Open SIMATIC Manager, choose Options > Set PG/PC Interface, and select the correct access point (S7ONLINE) for the physical adapter. For the USB-MPI cable (6ES7972-0CB20-0XA0) select "S7ONLINE (STEP 7) -> PC Adapter (MPI)". For CP 5611 A2 (6GK1561-1AA01) or CP 5612 select "CP 5611 A2 MPI" or "CP 5612 MPI".
  2. Confirm the baud rate matches the H-system MPI subnet. CPU 412-3H defaults to 187.5 kbit/s; older systems may be 19.2 kbit/s or 1.5 Mbit/s. Mismatched baud rates produce timeout errors (W#16#4542 "partner not found") rather than "Compiler address empty".
  3. Open PLC > Accessible Nodes (or "Erreichbare Teilnehmer"). Confirm that only one node is listed for the rack. If the standby address is configured with a different MPI address, two nodes may appear in the list — only the master is usable. Note the master's MPI address, rack number, and slot (typically rack 0, slot 3 for a 412-3H; rack 0, slot 4 for the standby in the standard UR2-H configuration).
  4. Open PLC > Online & Diagnostics on the master, then choose Diagnostic Buffer. Look for entries with ID W#16#4301, W#16#4542, or W#16#4570 indicating PG connection activity. Persistent "connection aborted" entries point to resource exhaustion.
  5. In HW Config, double-click the master CPU, open the Communication tab, and read the configured number of PG, OP, and S7 connection slots. If the totals exceed 32, STEP 7 will refuse to download the configuration.
  6. List active connections with PLC > Connection Status or via NetPro: the number of established partners equals the number of consumed resources. Cross-reference with the operator station's active HMI panels and OPC server sessions.
  7. Check the role of each CPU with PLC > H-system > CPU Roles (introduced in STEP 7 V5.5 SP3) or in the master diagnostic buffer entry 0x49A0 "CPU role: master". The standby should show entry 0x49A1 "CPU role: standby".
  8. Inspect the SYNC link LED state on the synchronization modules 6ES7960-1AA04-0XA0 (IF 960) or 6ES7960-1AB05-0XA0 (IF 960-H, for 414-4H and 416-4H). The LED on each module should be solid green when synchronization is healthy. A blinking LED indicates a SYNC failure; both CPUs will be in STOP in that case.

7. Resolution

7.1 Use the Master CPU as the Sole Online Target

Configure the PG/PC interface to point at the master's MPI, DP, or PN address. The standby address is reserved for redundancy control and cannot be used for engineering access. The H-system properties page in HW Config shows the role of each CPU slot; confirm that slot 3 holds the master and slot 4 the standby for the standard UR2-H chassis. If the engineer has physically reversed the slots in HW Config without a corresponding role assignment, both CPUs will fight for the master role and the system will report a redundancy error (RED LED on). The default in HW Config places the master on slot 3.

7.2 Re-Assign the Online Access Point in the Offline Project

After uploading from the master, modify the project's online path:

  1. Right-click the S7 program in the offline project, choose Properties.
  2. Open the Online tab.
  3. Change the Interface parameter to the master's MPI/DP/PN subnet.
  4. Change the Address parameter to the master's node number (typically 2 for the master of a default 412-3H rack, 3 for the standby if explicitly addressed).
  5. Click OK, then test View > Online. The block icons in the project tree should now display yellow (online, no differences) or solid color (online with differences).

If the address table is shown as empty, the PG/PC interface is misconfigured or the bus is unloaded. Re-check Options > Set PG/PC Interface and physically verify the MPI bus terminators (typically two 120 Ω resistors, one at each end of the segment).

7.3 Free Connection Resources

If the diagnostic buffer shows connection-rejection entries (W#16#4570 "resource exhausted"), free resources as follows:

  • Reduce the number of active HMI panels logged into the master. Each HMI panel maintains one OP connection. A typical S7-400H plant with five TP1900 Comfort panels, two TP900 Comfort panels, and one WinCC Runtime (16,384 PowerTags) consumes 8 OP connections plus 1 S7 connection from the master.
  • Consolidate OPC tags into fewer S7 connections. For example, use a single SIMATIC NET OPC server connection with multiple items instead of multiple point-to-point S7 connections. Each S7 connection is a separate resource slot on the CPU 412-3H.
  • Increase the PG connection count to the maximum allowed (typically 4 for CPU 412-3H) in HW Config > CPU Properties > Communication. Note that this reallocates resources from the OP/S7 pool; verify that the OPC server and HMI panels still fit within the 32-slot total. For example, moving PG from 1 to 4 and reducing OP from 16 to 13 leaves the 32-slot total unchanged.
  • As a temporary measure, power-cycle the HMI panels or restart the OPC service so they release their sessions. The released slots become available within one watchdog tick (typically 10 s).
  • Re-evaluate the routing configuration. Static S7 routes configured in NetPro (e.g. PG routing across multiple subnets) consume one S7 connection slot per route. Disable unused routes.

7.4 Verify with a Direct PROFIBUS or Ethernet Connection

If MPI traffic is congested (large plant, many devices on the bus, slow bus parameters), the PG/PC interface can switch to the integrated PROFIBUS DP or PROFINET interface of the master CPU. The CPU 412-3H PN/DP variants (6ES7412-3EK07-0AB0, 6ES7412-3EM08-0AB0) provide a PROFINET interface (X5, two-port switch) that can be used as a direct engineering access. Configure a unique IP address (for example 192.168.0.10) in HW Config and connect the PG to the same subnet. The H system uses both ports for the redundancy link as well, so dedicated IP configuration is required to avoid a duplicate IP condition.

For the classic 6ES7412-3HJ14-0AB0 (no integrated PROFINET), an Ethernet engineering link requires a CP 443-1 (6GK7443-1EX30-0XE0 or later) in the central rack. Configure the CP in HW Config and set the IP address in the same subnet as the PG. Engineering access via Ethernet typically uses TCP port 102 (ISO-on-TCP RFC 1006) and bypasses MPI bus contention.

8. Verification

After applying the resolution, perform the following verification sequence:

  1. Open PLC > Accessible Nodes and confirm one node returns with the master's address, rack 0, and slot 3.
  2. Open the offline program and choose View > Online. All blocks should be marked online (yellow or solid color).
  3. Open the variable table (VAT) and confirm monitored values refresh. Force a test bit (with safety approval) to confirm write access works.
  4. Inspect the master diagnostic buffer for new entries. No new "connection aborted" entries (W#16#4301 or W#16#4570) should appear within 10 minutes of normal use.
  5. Use PLC > H-system > CPU Roles to confirm the role of each CPU is unchanged after the verification (master on slot 3, standby on slot 4).
  6. Trigger a manual switchover (if permitted by plant operations) with PLC > H-system > Switchover Master <-> Standby. Confirm that the previous master becomes the new standby and that online access now points to the new master's MPI address.

9. Connection Resource Reference for S7-400H CPUs

The connection budgets of the S7-400H CPUs in the 412-3H, 414-3H/414-4H, and 416-3H/416-4H families differ. Use this table as a baseline when planning an upgrade or replacing a CPU.

CPU Order number (typical) Total conn. PG (default) OP (default) S7 (default)
CPU 412-3H 6ES7412-3HJ14-0AB0 32 1 16 16
CPU 412-3H PN/DP 6ES7412-3EK07-0AB0 32 1 16 16
CPU 414-3H 6ES7414-3HM14-0AB0 32 1 16 16
CPU 414-4H 6ES7414-4HM14-0AB0 32 1 16 16
CPU 416-3H 6ES7416-3HS07-0AB0 64 2 32 32
CPU 416-4H 6ES7416-4ER05-0AB0 64 2 32 32
CPU 417-4H 6ES7417-4HT14-0AB0 64 2 32 32

Reference: SIMATIC S7-400H Installation and Operation Manual, Appendix A "Communication resources".

10. Flash Memory Card (MMC) Behavior and S7-412-3H

The CPU 412-3H requires a 5 V flash memory card (MMC) for operation. Without the MMC, the CPU will not start. Common order numbers:

  • 6ES7952-1KS00-0AA0 — 1 MB MMC
  • 6ES7952-1KP00-0AA0 — 2 MB MMC
  • 6ES7952-1KT00-0AA0 — 4 MB MMC
  • 6ES7952-1KK00-0AA0 — 8 MB MMC

The MMC is used as the boot media and for non-volatile project storage. In an H-system, the MMC must be present in both CPUs of the rack. If the MMC is missing or unreadable in the standby, the standby CPU will fault and the master will report a redundancy error. The MMC does not affect online access directly, but a corrupted MMC in the master will produce "Compiler address empty" symptoms because the project cannot be loaded from the MMC. Replace the MMC and re-download the project via PLC > Download to Target System to resolve that scenario.

11. Firmware and Compatibility Notes

CPU 412-3H (6ES7412-3HJ14-0AB0) ships with Firmware V6.0. The online behavior described in this article is consistent across Firmware V4.x, V5.x, and V6.x. Upgrading to V6.0.8 or later is recommended when used with STEP 7 V5.7 because older firmware releases occasionally refused new PG connections while in RUN-Redundant. The firmware update is delivered as a SIMATIC Micro Memory Card update image and is applied with the S7 Firmware Update Tool.

For PROFINET-based engineering, Firmware V6.0.7+ is required on the CPU 412-3H PN/DP (6ES7412-3EK07-0AB0) to support the full PROFINET IO redundancy function with system redundancy S2. The integrated Ethernet interface also supports engineering access regardless of PROFINET IO configuration. Compatible STEP 7 versions: STEP 7 V5.5 SP4 (or later) and STEP 7 Professional (TIA Portal) V13 SP1 or later via the S7-400H GSD migration package.

12. Error Code Reference

STEP 7 message Hex ID (if in diag. buffer) Meaning Resolution
"Compiler address empty" / "Baugruppenträger leer" — PG/PC interface is set, but STEP 7 could not resolve any online node on the selected subnet. Verify PG/PC interface, physical cable, and bus termination; ensure the master address is reachable; do not target the standby.
"Connection aborted" / "Verbindung abgebrochen" W#16#4301 The CPU rejected the PG connection, typically because no PG connection resource is free or the partner address is the standby. See Section 7.3 (free resources) and Section 7.2 (re-assign access point).
"Online: not possible" / "Online: nicht möglich" — STEP 7 cannot open an online path to the configured partner. See Section 7.2 — re-assign the access point in the offline project.
"Partner not found" / "Partner nicht gefunden" W#16#4542 Address resolution timeout on MPI/DP. Check address, baud rate, and bus terminators. Default MPI baud 187.5 kbit/s.
"Resource exhausted" W#16#4570 Connection resource table is full. Free or re-allocate resources (Section 7.3).
"Connection terminated by user" W#16#4300 The PG initiated a clean disconnect. Not a fault. Triggered by clicking "Disconnect" in STEP 7.
SF / BF / RED LED illuminated — Hardware or redundancy fault; out of scope of this article. See S7-400H manual, chapter "Diagnostics and troubleshooting".

13. Related Online Operations

Once the master is reachable, the following operations are recommended to bring the engineering state into alignment with the running plant:

  1. PLC > Upload Station to PG: build a complete offline mirror of the running project, including symbol table and HW Config. In an H-system, the upload captures the master's project; both CPUs have identical projects, so the upload is sufficient.
  2. PLC > Download Station Configuration: if the offline project diverges, download the configuration back to the CPUs to keep documentation and runtime aligned. STEP 7 automatically targets both CPUs of the H-system during a download.
  3. CPU > Operating Mode: confirm that both CPUs are in RUN (master) and RUN (standby). The H-system should not be put in STOP from STEP 7 unless coordinated with operations. Stopping the master forces a switchover to the standby, which may disturb the process.
  4. CPU > Time of Day: synchronize PG and master time to maintain consistent event logging in the diagnostic buffer. The master propagates the time to the standby over the SYNC link.
  5. PLC > Clear/Reset: only use this to clear a complete restart of the CPU. The operation deletes the project from the MMC and the working memory. Do not use it on the standby without first stopping the master.

For general online & diagnostic tools applicable to S7 controllers, see the Siemens documentation set: Online and diagnostic tools — monitoring and modifying values in the CPU. The principles are identical for S7-400H; only the menu paths in STEP 7 V5.x differ.

14. PG/PC Interface and Cable Selection

Choosing the wrong PG/PC interface is a frequent cause of "Compiler address empty". Common configurations:

Cable / CP Order number Sub-net Default baud Set PG/PC Interface entry
USB-MPI PC Adapter 6ES7972-0CB20-0XA0 MPI 187.5 kbit/s PC Adapter (MPI)
USB-MPI/DP Adapter 6ES7972-0BD52-0XA0 MPI/DP 187.5 kbit/s to 1.5 Mbit/s PC Adapter (PROFIBUS)
CP 5611 A2 6GK1561-1AA01 MPI/DP 1.5 Mbit/s max CP 5611 A2 MPI / CP 5611 A2 PROFIBUS
CP 5612 6GK1561-2AA00 MPI/DP 12 Mbit/s max CP 5612 PROFIBUS
CP 5711 6GK1571-1AA00 PROFINET 100 Mbit/s CP 5711 IE / TCP/IP
CP 343-1 / CP 443-1 6GK7443-1EX30-0XE0 PROFINET 100 Mbit/s TCP/IP > Intel NIC

If the wrong entry is selected in Set PG/PC Interface, STEP 7 will issue "Compiler address empty" or "Address not found". Verify the selected entry matches the physical cable plugged into the PG.

15. Master/Standby Switchover Behavior

The S7-400H allows a controlled switchover of the master and standby roles. The switchover is initiated by either of the following:

  • Operator action on the H-system operator panel (if fitted) or via SIMATIC Manager PLC > H-system > Switchover.
  • Automatic failover when the master detects a fatal hardware or software fault that prevents it from continuing operation.
  • Online command PLC > H-system > Switchover Master <-> Standby from STEP 7.

After a switchover, the MPI/DP/PN address of the master is unchanged (the H-system presents a single address to the network). The role of each CPU in HW Config is unchanged, but the runtime role flips. STEP 7 will continue to find the master on the same address; no reconfiguration of the PG/PC interface is required. If the standby was the previous master, the new master's diagnostic buffer will contain entry 0x49A2 "Role changed: master".

Important: A switchover that occurs while the engineer is online may drop the active PG connection. Re-establish the connection by clicking View > Online again; STEP 7 will re-resolve the new master transparently.

16. Safety Considerations

When forcing outputs or modifying values online on an S7-400H, observe the following:

  • All forcing operations must be authorized by plant operations and the safety officer. The S7-400F/FH variants (CPU 412-3H, 414-4H, 416-4H with the "F" suffix) require the safety program to be deactivated before force operations; F-active and F-passive blocks are read-only online.
  • Do not change the assignment of the master CPU while the system is in production. Use the H-system operator panel (if fitted) or set the standby to master via SIMATIC Manager > H-system > Switchover only after confirming process safety and notifying operations.
  • A modification that changes block signatures (FC/FB) requires downloading the modified block to both CPUs. STEP 7's "Download to Target System" handles this for H-systems automatically; the operation writes to the master first, then to the standby. A failed standby download is reported as a warning, not a fatal error — the master continues to run with the new code, and the standby will synchronize on the next switchover.
  • Do not insert or remove the flash memory card while the CPU is in RUN. Always switch the CPU to STOP first, then power down, then service the MMC.

17. Preventive Maintenance

To reduce the likelihood of online access failures on an S7-412-3H:

  • Document the active connection count weekly. Use a script to read the connection status via SZL index W#16#0132 from each CPU. The number should be stable; a gradual increase indicates an HMI panel or OPC client holding an orphan connection.
  • Maintain the HMI panels and OPC servers. Configure keep-alive timeouts in the OPC server (e.g. SIMATIC NET: 30 s) so that disconnected clients release their connection slots promptly.
  • Reserve at least one PG connection slot in HW Config so that engineering access is always possible, even when the OP/S7 pool is saturated.
  • Keep the STEP 7 installation current. STEP 7 V5.5 SP4 and V5.7 include diagnostic buffer decoders that recognize the W#16#4570 resource-exhausted entry and present a clear message.
  • Back up the offline project to the engineering server after every online edit. The H-system's MMC is the runtime source, but a documented offline source is required for change control and disaster recovery.

18. FAQ

Why can I not go online to the standby CPU of an S7-412-3H?

The standby (slave) of an S7-400H is not an independent engineering target. The two CPUs form one logical controller, and STEP 7 only accepts online connections to the master. Configure your PG/PC interface to the master's MPI, DP, or PN address, not the standby's. See the S7-400H manual, section 4.3 for the architectural rationale.

Why does my uploaded backup show "connection aborted" on a redundant 412-3H?

The offline backup inherits the access point stored in the project. If that access point points to the standby, STEP 7 will try to reach a target that the H-system refuses. Re-assign the S7 program's online path in Properties > Online to the master's address, typically rack 0 slot 3 for a default 412-3H rack.

How many PG connections does a CPU 412-3H support?

By default one PG connection is reserved. You can increase it to a maximum of four in HW Config > CPU Properties > Communication, provided that the total connection count of 32 (master plus standby) is not exceeded by other OP and S7 connections. Reserve at least one PG slot for engineering to prevent resource exhaustion.

Can I use the integrated PROFINET port of the CPU 412-3H PN/DP for engineering access?

Yes. Configure a unique IP address in HW Config and connect the PG to the same subnet. The PROFINET ports (X5) are also used for the redundancy link on certain H-system variants, so ensure the IP is not duplicated by another station. Engineering access uses ISO-on-TCP port 102.

Does a "connection aborted" error indicate a hardware fault?

No. A "connection aborted" message with no SF/BF/RED LED illuminated is a normal rejection caused by exhausted connection resources (W#16#4570) or an incorrect online path pointing at the standby. Hardware faults generate SF or RED LEDs and write specific diagnostic buffer entries such as W#16#4001 (power supply) or W#16#4101 (rack failure). The S7-400H manual, chapter "Diagnostics and troubleshooting", contains the complete diagnostic entry reference.

What is the correct MPI address for the master of a 412-3H?

By default, the master sits at MPI address 2 and the standby at MPI address 3 in STEP 7 HW Config. The addresses are not used for online access; only the master is addressable. If your plant uses different addresses, the value is set in HW Config > CPU Properties > General > Interface. Verify the actual address on the rack using the MODE switch position or the diagnostic buffer entry 0x49A0.

Can I monitor both CPUs simultaneously from a single PG?

No. STEP 7 maintains one online connection per project to the master of an H-system. To view standby-specific data (for example, the standby diagnostic buffer), the engineer must trigger a master/standby switchover from the H-system operator panel, then re-open the online view. The new master (formerly the standby) will respond on the same MPI address.

Back to blog