S7-414H PROFIBUS Diagnostics via Y-Link: Replacing FC125 in a Redundant H-System
The legacy FC125/FB125 block that scans PROFIBUS node status on a standard S7-300/S7-400 does not behave reliably on an S7-414H fault-tolerant CPU when the PROFIBUS segment downstream of the CPU is reached through a Y-Link. The block internally calls SFC51 (RDSYSST) and assumes a single DP master system, an assumption that breaks on the H-system where two CPUs own a switched DP master system and the slaves behind the Y-Link live in a transparent DP master system with its own ID (commonly 5980 in the field). This reference documents the root cause, the available S7-400H diagnostics primitives, the parameter set required to read slave status, and a step-by-step recipe to build a replacement block that returns the same status list FC125 produced on the pre-H machine.
1. Problem Description
After migrating a single-CPU S7-400 application to a redundant S7-414H configuration, the engineering team observed that the diagnostics FC used on the previous machine no longer reported node failures during commissioning. The affected PROFIBUS network is reached through a Y-Link (Siemens DP/PA link with PROFIsafe/y-proxy capability, order number 6GK1 416-3AB00 etc., depending on variant) and is configured with DP master system number 5980. The symptom is consistent across the H-system:
- FC125 returns an empty station list when called on the active CPU.
- No fault bits are set for slaves known to be in diagnostic state during forced fault tests.
- The same FC, when run on the reserve CPU during a master failover, returns inconsistent results (different SZL header values for the same slave).
- Direct ET200M slaves on the same CPU (without Y-Link) may or may not be reported, depending on whether the FC was called with DP_MASTERSYSTEM = 1 or = 2.
Engineers familiar with classic S7-400 expect FC125/FB125 to enumerate every node in the local DP master system. The H-system's switched DP master, the Y-Link's transparent lower-level master, and the way SFC51 indexes system state lists by DP master system all interact to break that assumption.
2. H-System PROFIBUS Topology and the Y-Link
An S7-414H contains two CPUs (CPU 0 and CPU 1) that share a synchronized DP master system through the IF module pair. A Y-Link (PROFIBUS Y-Link, e.g., 6GK1 416-3AB00 or 6ES7 197-1LB00-0XA0) sits between the redundant DP master and a lower-level, non-redundant DP master system that carries the field devices. From the perspective of the CPU, the slaves behind the Y-Link live in a different DP master system ID than the slaves connected directly to the CPU's PROFIBUS interface.
Step 7 assigns DP master system IDs in the range 1..32 by default, but the H-system tools often allocate higher IDs (for example 5980 as in the case described) to the Y-Link's lower-level master. The figure below illustrates the topology:
The critical fact: in the H-system, the active CPU owns the DP master at any one time, and SFC51 reports slave status from the perspective of the CPU executing the call. If you call FC125 with DP_MASTERSYSTEM = 1, the block queries the switched master; with = 2, the backup CPU's master. The Y-Link itself is not a slave in either list - it is the gateway to a separate DP master system (ID 5980) that the CPU sees only as an attached device.
3. Root Cause: Why FC125 Fails on an H-System with a Y-Link
FC125 (and the functionally identical FB125) is a thin wrapper around SFC51 (RDSYSST) that requests partial system state lists with the following SZL IDs:
| SZL ID (W#16#) | Contents | FC125 usage |
|---|---|---|
| 0019h | Module status information | Used to detect module faults at the local interface |
| 0025h | Status of a DP slave | Used per-slave to test for diagnostic/operational state |
| 0A0h / 042h | PROFIBUS / DP master system diagnostic list | Used to enumerate slaves in the local DP master system |
| 094h / 042h | PROFINET / PROFINET+DP combined master system diagnostic list | Used on PN-capable CPUs |
The parameter DP_MASTERSYSTEM is passed to the SZL INDEX. The SFC51 documentation for the S7-400 CPU states that INDEX = 0 returns the list for the local DP master system of the CPU executing the call. INDEX = 1 or 2 selects the corresponding switched master in the H-system. INDEX = <DP master system number> (e.g., 5980) is, for several S7-414H firmware versions, not accepted: the SFC returns RET_VAL = 808Ah (SZL index not allowed) or 80A2h (SZL_ID cannot be read for this object). The reported symptoms in the field match this failure mode exactly.
The Y-Link complicates the picture further. From the CPU, the Y-Link is a regular DP slave on master system 1 (or 2, depending on which CPU is active). Its lower-level PROFIBUS segment is not visible to SFC51 as a list of slaves - it appears only as a single slave entry pointing at the Y-Link. There is no SZL that returns the sub-network of a transparent slave. Siemens documents this gap in the manual for the Y-Link (entry ID 19243932 in the Siemens Support knowledge base and the manual for 6GK1 416-3AB00): diagnosis of slaves downstream of the Y-Link must be performed with record-based reads, i.e., SFC13 (DPNRM_DG) or SFC58 (RD_REC) against the Y-Link's own records, or with the dedicated DP/PA slaves diagnostics addon.
The combination of these two constraints - SFC51 refusing to read slave lists for the lower-level master system, and the Y-Link being a transparent gateway - is the definitive reason FC125 returns nothing on the H-system.
4. Available Diagnostics Primitives in STEP 7 for S7-400H
STEP 7 V5.5 (and the matching TIA Portal V16+ for legacy S7-400H support) exposes four primitives that can substitute for FC125 on an H-system. Each has trade-offs in latency, supported slave types, and CPU load.
| Primitive | Function | Use on H-system with Y-Link | Notes |
|---|---|---|---|
| SFC51 (RDSYSST) | Read system state lists (SZL) | Works for the switched master (ID 1 / 2). Does not enumerate slaves behind the Y-Link (ID 5980). Returns RET_VAL 808Ah for the sub-master on several firmwares. | Use SZL W#16#94 (PROFINET+DP combined list) on PN-capable CPUs, W#16#42 (DP-only) on classic DP CPUs. |
| SFC13 (DPNRM_DG) | Read diagnostic buffer of a DP slave | Direct slaves only. On the Y-Link lower segment, the call must be issued to the Y-Link itself with the appropriate record index, or - if the Y-Link is configured for DP/PA routing - to the PA slaves via record routing. | Latency: one PROFIBUS round-trip per slave. Avoid scanning every slave every OB1 cycle; use a cyclic scheduler. |
| SFC58 (RD_REC) | Read record from I/O | Reads vendor-specific records from the Y-Link and from downstream slaves (DPV0/DPV1). Returns the slave's own diagnosis record (record 0) and configuration data. | Preferred for DP/PA slaves and for vendor-specific diagnostics of ET200 stations. |
| System diagnostics DP/PA Slaves addon | Higher-level diagnostics for PROFIBUS PA and DP slaves, designed for redundant systems | Yes - this is the path Siemens explicitly recommends for H-system PROFIBUS diagnostics. | Distributed as an addon for STEP 7; provides faceplates and block library; supports redundant operation natively. |
5. Solution A: SFC51 with Correct SZL/INDEX for the H-System Switched Master
If you only need diagnostics for the slaves on the H-system's switched master (i.e., everything connected to the CPU's DP port including the Y-Link itself but not the slaves downstream of it), call SFC51 directly with the correct SZL and INDEX. The legacy FC125 cannot be parameterised to do this reliably; you should write a small FB that wraps SFC51 per the pattern below.
5.1 Parameter table for SFC51 on S7-414H
| Input | Value | Meaning |
|---|---|---|
| REQ | TRUE on rising edge | Start the read |
| SZL_ID | W#16#0094 (PN+DP) or W#16#0042 (DP only) | W#16#94 for CPUs with PROFINET interface; W#16#42 for DP-only CPUs. S7-414H with order number 6ES7 414-4HM14 supports both via the IF modules. |
| INDEX | W#16#0001 or W#16#0002 (switched master) or W#16#0000 (local CPU's own master) | Set INDEX = 1 when CPU 0 is active, = 2 when CPU 1 is active. Use the active master detection via SFC51 SZL W#16#0019 to switch INDEX dynamically. |
| RET_VAL | INT | Status: 0000h = OK, 808Ah = invalid INDEX, 80A2h = SZL not readable for this object, 80C3h = resource busy |
| BUSY | BOOL | TRUE while SFC51 is processing |
| SZL_HEADER | STRUCT | LENTHDR (WORD), N_DR (WORD) - number of data records returned |
| DR | ARRAY of BYTE / STRUCT | Receives the SZL data records; size depends on the SZL |
5.2 STL code pattern
// FB1900 - H-Profibus node status
CALL "RDSYSST" // SFC51
REQ := #startJob
SZL_ID := W#16#0094 // PN+DP combined master diagnostic list
INDEX := #activeMasterId // 1 or 2 derived from SZL W#16#0019
RET_VAL:= #sfcStatus
BUSY := #busy
SZL_HEADER := #header
DR := #stationList
When #sfcStatus = W#16#0000, evaluate #stationList. For SZL W#16#94 the structure of each entry is documented in the S7-400 system and standard functions reference manual:
| Byte | Field | Meaning |
|---|---|---|
| 0..1 | Logical base address | I/O address of the slave's diagnostic interface |
| 2..3 | PROFIBUS address | Physical station number on the segment (0..125) |
| 4 | Slave type | 0 = DP slave, 1 = DP master (class 2), 2 = passive coupler, 3 = PN device |
| 5 | State | 0 = OK, 1 = fault, 2 = not reachable, 3 = not configured |
| 6..7 | Vendor ID | Identifies the slave manufacturer |
This is exactly the data FC125 was exposing on the pre-H machine, so the HMI faceplate can be reused unchanged.
6. Solution B: SFC58 Against the Y-Link for Downstream Slaves
For slaves behind the Y-Link, the recommended approach is record-based diagnostics. The Y-Link exposes the lower-level PROFIBUS segment as a set of records. According to the Y-Link manual (Siemens entry ID 19243932), records in the range 1..7 contain the diagnostic records of the connected PA/DP slaves.
6.1 Parameter table for SFC58 against the Y-Link
| Input | Value | Meaning |
|---|---|---|
| REQ | TRUE on rising edge | Trigger read |
| IOID | B#16#00 (input) or B#16#01 (output) or B#16#FF (diagnostic) | Use B#16#FF for diagnostic records |
| LADDR | W#16#<diagnostic address of the Y-Link> | The Y-Link's diagnostic address is configured in HW Config (typically the slot's logical base address) |
| RECNUM | B#16#00 | Record 0 = standard DP diagnostic buffer (max 244 bytes) |
| RET_VAL | INT | 0000h = OK, 80A0h = negative acknowledgement from slave, 80B0h = record not available, 80B1h = user data length error |
| BUSY | BOOL | TRUE while SFC58 is reading |
| RECORD | ARRAY[0..243] of BYTE | Receives the diagnostic buffer |
A single SFC58 call to the Y-Link with record 0 returns the Y-Link's own diagnostic state, but the downstream PA/DP slave diagnostics are accessed differently: the Y-Link multiplexes the lower-level master's records. To obtain diagnostics for a specific PA slave, you issue a SFC58 call routed through the Y-Link by setting the LADDR to the Y-Link's diagnostic address and RECNUM to the index that corresponds to the downstream station. The Y-Link manual provides a table mapping downstream PROFIBUS addresses to record numbers.
7. Solution C: System Diagnostics DP/PA Slaves Addon
Siemens ships a free addon named "System diagnostics DP/PA Slaves" that is explicitly tested on the S7-400H. It packages SFC51, SFC13, and SFC58 access into a pre-built FB library with faceplates for WinCC flexible and ProTool. The addon downloads from the Siemens Support site (entry ID 22681001 in the Siemens Industry Online Support, search keyword "Systemdiagnose DP/PA-Slaves"). It is the path of least resistance for plants that already have a ProTool/WinCC flexible HMI. On the H-system the addon distinguishes between CPU 0 and CPU 1 active state and reads both masters in alternation, eliminating the FC125 ambiguity.
8. Step-by-Step Replacement Recipe
- Confirm firmware. Open SIMATIC Manager > PLC > Module Information. Verify the S7-414H firmware is >= V5.3 (recommended V5.4 or V6.0 for full Y-Link record support). CPU 6ES7 414-4HM14-0AB0 is the most common variant in this generation.
- Capture the active master ID. In OB1, call SFC51 with SZL_ID = W#16#0019, INDEX = 0. The returned byte 0 contains the active master (1 or 2). Cache this in a global data block (e.g., DB1900.DBD0 = active master ID).
- Write a new FB (e.g., FB1901) that contains a single CALL to SFC51 with SZL_ID = W#16#94 (or W#16#42 for DP-only CPUs) and INDEX = DB1900.DBD0. The DR must be at least 256 bytes; size it to 512 to be safe across firmwares. Mark the FB as "Multi-Instance Capable" and set the instance DB to be non-removable (via SFC82 or by retaining).
- Decode the SZL in the same FB. Walk the DR array, copy each entry's logical base address, PROFIBUS address, state, and vendor ID into a structured DB (e.g., DB1902 with UDT1902 per-slave). FC125 used offset 22 in the FC return DB for the state byte - preserve that layout so the existing HMI screens do not need changes.
- For the Y-Link downstream slaves, instantiate a second FB (e.g., FB1902) that schedules SFC58 calls against the Y-Link's diagnostic address in a round-robin fashion (one slave per OB1 cycle). Use a 10-s scheduler via a timer pulse so you do not load the PROFIBUS during process scans.
- Wire the new blocks in OB1. Remove FC125. Wire FB1901 to the HMI tag "DP.SlaveCount" and FB1902 to "DP.Downstream.SlaveCount".
- Download to both CPUs. On an H-system, both CPUs need the new blocks, otherwise the reserve CPU will revert to old code on a failover.
- Verify in Monitor/Modify with the PROFIBUS cable intentionally disconnected from one ET200M. The state byte in the corresponding DB1902 entry must read 02h (not reachable) within 10 s of disconnect.
9. Verification Procedure
- Open the HMI diagnostic page. The total slave count must equal the count configured in HW Config on master 1 (or 2) for the active CPU.
- Disconnect one PROFIBUS connector. Within 10 s the corresponding row turns red, and the state field reads "Fault" or "Not reachable" depending on the encoding you chose.
- Reconnect the connector. The state clears within 5 s (PROFIBUS default retry timing).
- Force a CPU failover. Hot-swap the master role from CPU 0 to CPU 1 (via STEP 7 > PLC > Operating Mode > Switch Master). The SFC51 INDEX must flip to 2 within one OB1 cycle; otherwise your active-master detection has a bug.
- With the system on CPU 1, repeat steps 2-3 to confirm the diagnostics work identically on the reserve master.
- For the Y-Link downstream segment, disconnect a PA segment. The corresponding entry in DB1903 must change to "Not reachable" within 30 s (record reads are slower than direct SFC51 reads).
10. Common Errors and Their Meanings
| RET_VAL (hex) | Source | Meaning | Action |
|---|---|---|---|
| 0000 | SFC51 / SFC58 | OK | None |
| 808A | SFC51 | SZL index not allowed for this object (typical when INDEX = 5980 is rejected by the H firmware) | Use INDEX = 1 or 2 (switched master) or the DP/PA Slaves addon |
| 80A2 | SFC51 | SZL_ID cannot be read on this CPU | Confirm SZL_ID compatibility with the CPU firmware |
| 80A0 | SFC58 | Negative acknowledgement from slave | Check slave power and PROFIBUS termination; verify PROFIBUS address not duplicated |
| 80B0 | SFC58 | Record not available on the addressed slave | Confirm the record number in the Y-Link manual; vendor-specific records may require DPV1 |
| 80B1 | SFC58 | User data length error | Increase RECORD buffer; SFC58 needs RECORD >= actual returned length; use 244 bytes for record 0 |
| 80C3 | SFC51 | Resource busy | Re-issue on the next OB1 cycle; do not call SFC51 in OB100 with REQ = TRUE |
| 80B5h | SFC58 | Y-Link record routing failed | Y-Link is in fallback - check DP/PA segment power and DP master redundancy state |
11. Performance and CPU-Load Considerations
SFC51 with SZL W#16#94 returns up to 128 slaves per call on a typical S7-414H. The call itself takes 8-15 ms when 64 entries are populated. Call it once per OB35 (100 ms cycle) on the active CPU only - calling it on both CPUs wastes CPU time and can confuse the HMI if both are broadcasting updates. SFC58 record reads are slower: a single record read against the Y-Link takes 30-60 ms plus the Y-Link's internal round-trip to the downstream slave (another 30-200 ms). Schedule downstream reads at 1-Hz or slower; the DP/PA Slaves addon uses a 2-s cycle by default, which is a good starting point.
12. Migration Checklist
- Document the DP master system IDs of every PROFIBUS network in HW Config (Export > Station Configuration). Y-Link downstream segments are usually in the 5x range (e.g., 5980); direct slaves are in 1..4.
- Identify which FC/FBs in the existing project read DP slave status. FC125, FB125, FB126, and any project-specific blocks that call SFC51 with a hard-coded INDEX are candidates for replacement.
- Add a global data block for the active master ID; subscribe both CPUs to it.
- Replace FC125 with the new FB on both CPUs. The download must be to the H-station (both CPUs in a single operation); do not download to CPU 0 and CPU 1 separately, as this desynchronises the program level.
- Test a forced failover with diagnostics active. Confirm that the HMI does not freeze or show stale data during the switchover.
- Update the plant's HMI tag list. If the new FB uses a different DB layout than FC125, run a HMI variable export/import or recompile the HMI project.
13. Field-Proven Notes and Caveats
The S7-414H firmware versions most often encountered in production plants are V5.3, V5.4, and V6.0. The 5980 DP master system ID is not special from the firmware's perspective - it is simply the next free ID that HW Config allocated when the Y-Link was added. On V5.3 firmware, SFC51 with INDEX > 32 always returns 808Ah. On V5.4, INDEX up to 256 is accepted, but the lower-level slaves are still not enumerated - only the Y-Link itself appears in the result list. On V6.0, the behaviour is the same as V5.4 but with a higher SZL size, allowing the entire network in one call. Do not assume the SZL_HEADER N_DR value means "all slaves" - it is the number of records in the SZL, not the number of slaves you care about.
For PA slaves downstream of the Y-Link, the Siemens DP/PA coupler profile requires record routing through the Y-Link. Trying to call SFC13 directly against a PA slave's logical address fails with 80A0 because the CPU does not have a direct connection to the PA segment. The Y-Link documentation explicitly states: "Diagnostics of DP/PA slaves downstream of the Y-Link is performed via records read from the Y-Link itself."
If the plant has a mix of ET200M (DPV0) and ET200S with DPV1, use SFC59 (WR_REC) and SFC58 (RD_REC) for the DPV1 records and SFC13 only for DPV0. The SZL W#16#94 returns the slave type, which you can use to branch the diagnostics routine.
Finally, in H-systems, SFC51 calls must be issued on the active CPU only. If you wire SFC51 to OB1 in both CPUs, the reserve CPU will consume cycles reading SZLs that are then discarded when the master switches. The active-master detection in step 2 of the recipe (SZL W#16#0019) gates the call and prevents the wasted work.
14. References to Official Documentation
- Siemens Industry Online Support, "PROFIBUS diagnostics (S7-300, S7-400) - STEP 7" - S7-300/S7-400 PROFIBUS diagnostics
- Siemens Function Manual "System and Standard Functions for S7-300/400" - SFC51 RDSYSST (SZL list parameters and SZL_ID constants)
- Siemens Manual "S7-400H Fault-Tolerant Systems" - section on diagnostics on the switched DP master and active-master detection
- Siemens Manual "Y-Link (6GK1 416-3AB00)" - record routing for DP/PA slaves
- Siemens Industry Online Support entry ID 22681001 - "System diagnostics DP/PA Slaves" addon for STEP 7 V5.5 (download and application note)
Why does FC125 return no errors on my S7-414H PROFIBUS network?
FC125 is a wrapper around SFC51 (RDSYSST) and assumes a single DP master system with INDEX = 0. On an S7-414H with a Y-Link, the downstream slaves are on a separate DP master system (often ID 5980). SFC51 rejects INDEX = 5980 on most H-system firmwares (RET_VAL = 808Ah) and does not enumerate slaves behind a transparent Y-Link, so FC125 returns an empty list. Use a new FB that calls SFC51 with SZL W#16#94 and INDEX = 1 (or 2) for the active switched master, and SFC58 against the Y-Link for downstream slaves.
Which SZL ID should I use for SFC51 on an S7-414H?
Use W#16#0094 for CPUs with a PROFINET interface combined with a DP master system (S7-414H with PN IF module), or W#16#0042 for classic DP-only CPUs. Both SZLs return the diagnostic list of the local DP master system of the CPU executing the call; with INDEX = 1 or 2 you select the H-system's switched master.
How do I read the diagnostic state of a DP/PA slave behind a Y-Link?
You cannot read PA slaves directly with SFC13. Issue a SFC58 (RD_REC) call against the Y-Link's diagnostic address with IOID = B#16#FF and the appropriate RECNUM, which the Y-Link routes to the downstream slave. The Y-Link manual (6GK1 416-3AB00) lists the record numbers for each downstream station, or use the "System diagnostics DP/PA Slaves" addon which automates this mapping.
Do I need to call the diagnostic FB on both CPUs of the H-system?
Wire the diagnostic FB in OB1 of both CPUs so that failover does not interrupt diagnostics, but gate the SFC51/SFC58 calls with the active-master flag (read via SZL W#16#0019). The reserve CPU executes the FB but skips the call, avoiding redundant PROFIBUS traffic and CPU load. Both CPUs must hold the same program version, so download the new FB to the H-station as a single operation.
Is there a pre-built solution for H-system PROFIBUS diagnostics?
Yes - the "System diagnostics DP/PA Slaves" addon from Siemens Industry Online Support (entry ID 22681001) provides an FB library and HMI faceplates explicitly designed for redundant S7-400H systems. It handles active-master switching, Y-Link record routing, and DP/PA slave decoding out of the box and is the path of least resistance for plants that already use WinCC flexible or ProTool.