Siemens CM AS-i Master ST: Outputs Hold on CPU STOP Transition

David Krause16 min read
Safety SystemsSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Summary

An S7-300 system based on a CPU 319-3 PN/DP communicating with a SIMATIC ET 200SP station over PROFIBUS DP — and an AS-i sub-network served by a CM AS-i Master ST plugged into that ET 200SP — exhibits the following field symptom: when the CPU transitions from RUN to STOP, the digital AS-i outputs do not drop to a safe / zero state. Instead, the AS-i outputs remain latched at the value they held at the instant of the mode change. Loads driven by those outputs (contactors, motor starters, valve coils) continue to be energized, which in safety-relevant applications violates the expectation that a STOP transition produces a deterministic, de-energize-to-safe response.

Key observations that confirm this defect versus a generic wiring problem:

  • No diagnostic or system fault is raised on the CPU, the IM 155-6, or the CM AS-i Master when the symptom occurs.
  • The PROFIBUS DP link to the ET 200SP stays healthy — there is no station failure or bus error masking the cause.
  • The AS-i slaves themselves report no diagnostic flag and continue to receive output telegrams.
  • The behavior is firmware-version dependent: it is reproducible on V1.1.6 and V1.1.7 of the CM AS-i Master ST but not on V1.1.5.
  • A bench replication with identical hardware but older firmware does not reproduce the symptom, which is a strong tell that the defect is embedded in the firmware load of the CM AS-i Master and not in the user program.
Safety impact. Any application where STOP is used as an emergency-stop-equivalent path (operator-initiated STOP, key switch STOP, programming device STOP) is exposed. Treat this as a functional-safety deviation until the CM is on a known-good firmware or an independent watchdog forces the outputs off.

2. Affected Hardware and Firmware

Component Order number (MLFB) Firmware status Behavior on CPU STOP
SIMATIC S7-300 CPU 319-3 PN/DP 6ES7318-3EL01-0AB0 Any released firmware Replaces process image; writes substitute values to local outputs as configured (default 0). Cannot directly enforce substitute values on downstream AS-i slaves.
ET 200SP interface module (PROFIBUS) 6ES7155-6BU01-0BN0 (IM 155-6 DP HF) Any released firmware Passes the substituted output image down to the I/O slots; however, the CM AS-i Master slot interprets the substituted image itself.
CM AS-i Master ST for ET 200SP 3RK7137-6SA00-0BC1 (V1.1) / 3RK7137-6SA00-0BC1 (V1.1.x) V1.1.5 Drops AS-i outputs to 0 on CPU STOP — correct, expected behavior.
CM AS-i Master ST for ET 200SP 3RK7137-6SA00-0BC1 V1.1.6 Defect: AS-i outputs retain last value when CPU enters STOP.
CM AS-i Master ST for ET 200SP 3RK7137-6SA00-0BC1 V1.1.7 Defect persists: AS-i outputs retain last value when CPU enters STOP.

The CM AS-i Master ST (catalog number family 3RK7137-6SAxx-xxx1) is a single-master module conforming to the AS-Interface specification IEC 62026-2 and integrates up to 62 AS-i slaves with binary or analog profile. It supports the ET 200SP backplane bus and is configured as a standard slot in the ET 200SP head station. The device ships with onboard firmware that is updated through STEP 7 / TIA Portal via the standard SIMATIC firmware update channel (online via PROFIBUS or PROFINET of the CPU that owns the DP master).

Firmware files are distributed by Siemens as signed UPD packages. Update is performed via: Online → Accessible nodes → [Target CM] → Online & Diagnostics → Firmware update in STEP 7 V5.5 SPx or TIA Portal, with the project offline to avoid parameter conflicts.

3. Root Cause: CM AS-i Master Firmware Defect

When the CPU transitions to STOP, the SIMATIC runtime executes the standard substitution strategy on its local process image: by default the output process image is overwritten with zero, and for a configured output the substitute value (0 or 1, with the option of holding the last value) is written instead of the actual user-program result.

The expected behavior at a downstream PROFIBUS DP ET 200SP head station is that the substituted image is forwarded to all slot modules as if the user program had produced it. The CM AS-i Master ST, as the slot 1 (or higher) module on the ET 200SP, must then translate that image into AS-i output telegrams and either:

  • Transmit zeros to all AS-i output slaves, or
  • Apply its own configured substitute behavior.

Beginning with firmware V1.1.6, the CM AS-i Master ST no longer applies the substituted image on STOP. Its internal task continues to transmit the most recently written AS-i output image (held in the master's local buffer) instead of zeroing it. The slave actuators therefore stay energized as if the CPU were still in RUN.

The defect is reproducible without user-program modification, without OB1 changes, without DP configuration changes, and without any change to the AS-i topology — moving the same CM between two identical racks and only changing its firmware load between V1.1.5 and V1.1.6 toggles the symptom. This isolates the cause to the firmware load of the CM, not the project, the CPU, the DP slave, or the AS-i slaves themselves.

Engineering rule: When STOP behavior of a remote I/O subsystem differs from the local subsystem's documented substitute-value behavior, suspect a remote-module firmware regression before suspecting wiring, grounding, or noise. Field evidence of the regression here rules out the noise hypothesis cited in some generic troubleshooting guides such as the AutomationDirect maintenance manual (ch13.pdf), because the symptom is reproducible on the bench and tracks the firmware version exactly.

4. AS-i Output Behavior on the RUN-to-STOP Transition

The substitute-value behavior for a SIMATIC CPU is documented in the S7-1200 system manual under the topic "Configuring the outputs on a RUN-to-STOP transition" (TIA Portal docs). The same rules apply to S7-300/400 and apply to the local output image:

  • Default: All digital outputs are set to 0 (de-energize-to-safe).
  • Hold last value: Set per-point in the hardware configuration (HW Config → Properties → Outputs → "Reaction to CPU STOP").
  • Substitute value: Set per-point in HW Config.

For a remote PROFIBUS DP station, the substituted image is forwarded. For a downstream AS-i master, however, the master has its own behavior layer and must interpret the substituted image. With CM AS-i Master ST firmware V1.1.5 the layer correctly zeroed the AS-i output image. With V1.1.6 and V1.1.7 the layer holds the last written image.

Field consequence table:

Trigger Local S7-300 outputs ET 200SP slot outputs AS-i outputs (CM V1.1.5) AS-i outputs (CM V1.1.6 / V1.1.7)
CPU RUN → STOP (no fault) 0 (or per-config) 0 (or per-config) 0 ✓ Held last value ✗
CPU RUN → STOP via key 0 (or per-config) 0 (or per-config) 0 ✓ Held last value ✗
CPU RUN → STOP via PG 0 (or per-config) 0 (or per-config) 0 ✓ Held last value ✗
DP master failure Hold last value (DP default) Hold last value Hold last value Hold last value
AS-i slave failure n/a n/a AS-i watchdog trips in slave; CM reports diag Same

5. Diagnostic Procedure

  1. Capture the firmware version of the CM AS-i Master ST. In STEP 7 V5.5 select the ET 200SP station in HW Config, right-click the CM slot, choose Object Properties → Diagnostics, or use Online → Accessible nodes → Module Information → Firmware. Confirm whether the module reports V1.1.6 or V1.1.7.
  2. Force the CPU into STOP. Use the mode selector on the CPU 319-3 PN/DP, or use STEP 7 Target system → STOP, or trigger a programming device command. Do not rely on a fault-induced STOP first; repeat for operator-initiated STOP.
  3. Observe the AS-i outputs physically. Watch the contactor LEDs and motor contactor auxiliaries. If the actuators remain energized with the CPU in STOP, the defect is present.
  4. Inspect the CPU diagnostics buffer. PLC → Diagnostics/Setting → Diagnostics Buffer. A clean STOP entry without fault indicates the issue is not a CPU-induced abnormality but a CM-level retention bug.
  5. Inspect the CM AS-i Master diagnostics. Use Online → Accessible nodes → [CM] → Module Information → Diagnostic Buffer. Look for non-fatal entries around the time of STOP. With V1.1.6 / V1.1.7 the CM does not raise a diagnostic flag — the absence of a diagnostic event combined with the held outputs is itself diagnostic.
  6. Compare against V1.1.5. If a spare CM with V1.1.5 is available, swap it into the same slot with the same configuration and re-test. Outputs must drop to zero. This step is the most reliable confirmation that the firmware load is the root cause.
  7. Rule out wiring / noise / back-feed. The bench replication in the source field note disproves the hypothesis that AS-i power back-feeding through external wiring keeps outputs on. Confirm the CM's 24 V is dropped (or held) by the same source that drops the CPU's outputs so that the AS-i supply is also de-energized on STOP; this is a separate precaution but is not the cause of this defect.

6. Immediate Mitigation: Firmware Downgrade to V1.1.5

The fastest, fully-defensible remediation is to downgrade the CM AS-i Master ST to firmware V1.1.5. The downgrade is supported through the standard Siemens firmware update path because Siemens distributes firmware as loadable UPD files independent of the module's current version; a downgrade is permissible when the hardware version (HW Rev) supports it.

  1. Obtain the V1.1.5 firmware file from the Siemens Industry Online Support portal (article search "3RK7137-6SA00-0BC1 firmware 1.1.5" or via the Support Request entry tied to the customer account).
  2. Connect the programming device to the S7-300 CPU 319-3 PN/DP via MPI/PROFIBUS or via the integrated PROFINET interface. The CM is reached as a downstream node on PROFIBUS DP.
  3. Open STEP 7 V5.5 (or TIA Portal with the S7-300 HSP for the ET 200SP family).
  4. Navigate: Online → Accessible Nodes. The CM appears under the ET 200SP DP slave with its full MLFB and current firmware version.
  5. Right-click the CM → Firmware Update → select the V1.1.5 UPD file → activate "Update firmware" → confirm.
  6. Wait for the CM to complete the update cycle (typically 30 to 90 seconds). The CM performs an automatic restart; the slot momentarily drops off PROFIBUS and reappears.
  7. Verify online that the CM now reports V1.1.5 in Module Information.
  8. Repeat the STOP test from section 5; AS-i outputs must now drop to 0.
Commissioning caveat. When downgrading, the project configuration in STEP 7 may carry a "newer firmware expected" hint. This is informational only; if the parameter set of the module is unchanged between V1.1.5 and V1.1.7 the project compiles and downloads without modification. If STEP 7 reports an HSP mismatch, install the matching HSP for V1.1.5 from the legacy HSP collection.

7. Software Workaround: Independent Watchdog on the AS-i Outputs

Where a firmware downgrade cannot be applied immediately (for example, multiple remote sites with active production windows, or a vendor that no longer authorizes V1.1.5), an independent watchdog must force the AS-i actuators to a safe state on any loss of CPU-RUN indication. The watchdog must run on a path that is not the same module that holds the defect; otherwise it cannot bypass the held outputs. Three viable patterns are described below.

7.1 Pattern A — Mechanical watchdog via separate hard-wired relay

Insert a force-guided safety relay in series with the AS-i output power supply (24 V to the AS-i slaves' actuator coils). Drive the relay from a CPU RUN contact (S7-300 has no native RUN relay; instead use an output that the user program explicitly resets on STOP, but recognize that on a defect path this still may not drop). For a more robust implementation use a separate watchdog timer module (e.g., a 3SK1 safety relay or a Sirius 3UG48 monitoring relay) whose input is a 1 Hz heartbeat toggle from the CPU; loss of the heartbeat drops the relay within 1 s and mechanically disconnects AS-i output power.

7.2 Pattern B — CPU-side heartbeat with SCL/ST timer

In S7-300 / S7-400, implement a watchdog bit in OB1 that toggles every cycle. A separate cyclic OB (e.g., OB35 at 100 ms) drives an output that mirrors the heartbeat. Pair this with a hardware watchdog relay on the field side. The relay drops if either the CPU stops or the OB35 stops executing.

// OB35 - 100 ms cyclic, SCL example for S7-300
// Toggle a heartbeat marker once per OB35 call
IF "Heartbeat" = FALSE THEN
  "Heartbeat" := TRUE;
ELSE
  "Heartbeat" := FALSE;
END_IF;

// Force the AS-i enable output when CPU is RUN and
// heartbeat has toggled at least once within 200 ms.
"Watchdog_TON"(IN := "Heartbeat", PT := T#200MS);
IF "Watchdog_TON".Q AND NOT "CPU_Stop_Indication" THEN
  "ASi_Enable" := TRUE;
ELSE
  "ASi_Enable" := FALSE;
END_IF;

The signal ASi_Enable drives a hardware relay that supplies the 24 V rail to the AS-i slaves' actuators. On CPU STOP the CPU_Stop_Indication flag from the S7-300 status word immediately forces ASi_Enable false; the relay drops the AS-i output rail regardless of what the CM AS-i Master is transmitting.

7.3 Pattern C — Reassign CM AS-i Master firmware to a known-good revision

Hold a spare CM AS-i Master ST at V1.1.5 in stores and swap modules during a planned outage. Maintain a written firmware-pin procedure so that a future technician does not accidentally flash V1.1.6 / V1.1.7 onto a known-good spare.

8. Verification Steps

After remediation, perform a documented acceptance test before returning the line to production:

  1. Read the CM firmware version via STEP 7 / TIA Portal Module Information. The version must read exactly V1.1.5. Capture a screenshot of the version field as commissioning record evidence.
  2. Operator-STOP test. Turn the CPU mode selector to STOP from the operator panel. All AS-i-driven contactors and motor starters must drop within 200 ms. Record a video or use a current clamp on a representative load.
  3. PG-STOP test. From the programming device, command the CPU into STOP via Target system → STOP. Repeat the load-drop verification.
  4. Fault-STOP test. Force a controlled fault (e.g., temporarily remove a configured PROFIBUS slave or simulate a wire-break on a diagnostic input) to provoke a CPU STOP. Verify the same drop behavior.
  5. Heartbeat-drop test. If a watchdog relay was installed, open the heartbeat output (e.g., via a force or by blocking OB35 with a breakpoint). The watchdog relay must drop within the configured 200 ms window.
  6. AS-i slave diagnostics. Confirm the AS-i slaves show no persistent diagnostic state after the test — they should re-energize cleanly on the next CPU RUN.
  7. Update the project documentation. Record the firmware version of the CM in the project's HW Config offline parameter record so a future download cannot silently roll the firmware forward.

9. Long-Term Recommendations and Standards

The CM AS-i Master ST is a standard (non-F) module. Even when on V1.1.5, the system does not satisfy SIL-rated de-energize-to-safe on its own; safety functions must be implemented with F-CPU and F-I/O per IEC 61508 / IEC 62061 / ISO 13849-1. If the application claims a safety function on CPU STOP, the safety chain must include:

  • An F-CPU (e.g., CPU 319F-3 PN/DP, 6ES7318-3FL01-0AB0) or a separate safety controller,
  • F-I/O with PROFIsafe on PROFINET, or F-modules in the ET 200SP,
  • A force-guided safety relay downstream of the actuator drive stage.

For non-F applications where the operator STOP is treated as an emergency-stop-equivalent (common in packaging, intralogistics, and conveyor cells), follow the mitigation steps in section 7 and the verification in section 8. Do not rely on the CM AS-i Master ST firmware's substitute-value behavior alone to de-energize actuators.

Always verify against the current Siemens product support page for the CM AS-i Master ST and the latest firmware release notes before commissioning, because the manufacturer may issue a corrected firmware (a V1.1.8 or later) that resolves the V1.1.6 / V1.1.7 regression. Capture a copy of the release note that explicitly states "AS-i outputs drop to 0 on CPU STOP" before upgrading to a newer firmware on a safety-relevant site.

10. Troubleshooting Matrix

Symptom Likely cause Confirm Fix
AS-i outputs hold last value on CPU STOP, no diagnostics CM AS-i Master ST firmware V1.1.6 / V1.1.7 defect Read module firmware; bench-test against V1.1.5 Downgrade to V1.1.5; install hardware watchdog
AS-i outputs hold last value on CPU STOP, CPU has fault in buffer CPU STOP from fault; possibly redundant with defect Inspect diagnostics buffer Clear CPU fault, then re-test; if outputs still hold, treat as defect
AS-i outputs hold last value on CPU STOP, DP slave is failing DP link loss before STOP Check DP diagnostics; check IM 155-6 BF LED Restore DP link; outputs by default hold last value on DP loss — verify application requires this
AS-i outputs stay on, AS-i slaves report diag flag AS-i slave power not removed; AS-i watchdog in slave not respected Check slave LEDs; check 24 V at slave Verify AS-i power supply path and 24 V distribution
AS-i outputs stay on, only some loads affected Mechanical latch in contactor or back-feed through wiring Isolate load wiring; test coil voltage Replace contactor; route wiring through dedicated breaker
Outputs intermittently hold on STOP Race between OB100 restart, DP resync, and CM firmware Capture PLC and CM diagnostic buffers with timestamps Add OB100 startup delay for downstream outputs
Outputs flicker on STOP Substitute value set to "hold last value" by configuration HW Config → CM → Properties → Output substitute Set substitute value to 0 explicitly

11. Field Commissioning Notes

  • Document the exact firmware version of every CM AS-i Master ST in the plant's asset register. Include the firmware load as a bill-of-material attribute, not just the hardware MLFB.
  • Whenever a Siemens firmware update is approved through change control, run the section-5 diagnostic on a representative machine before authorizing a fleet-wide rollout. STOP behavior regressions are common and historically under-detected in vendor release notes.
  • Pin the firmware in TIA Portal / STEP 7 by uploading the actual firmware to the project so a download does not silently roll the firmware forward.
  • Hold at least one V1.1.5-loaded spare CM as a cold spare until a Siemens release explicitly closes the regression.
  • For F-CPU retrofits in the future, plan to migrate the actuator drive stage to PROFIsafe output modules (e.g., ET 200SP F-DQ) so safety does not depend on the AS-i master's STOP-time behavior.

FAQ

Why do the AS-i outputs stay energized when the S7 CPU enters STOP on CM AS-i Master ST firmware V1.1.6 / V1.1.7?

Firmware V1.1.6 and V1.1.7 of the CM AS-i Master ST (3RK7137-6SA00-0BC1 family) do not honor the CPU's substituted output image at STOP. The CM holds the last AS-i output image in its local buffer and continues to transmit it to the slaves, so the actuators stay energized. The defect is reproducible on the bench and tracks the firmware version exactly.

Which firmware version of the CM AS-i Master ST does not have this defect?

Firmware V1.1.5 of the CM AS-i Master ST correctly drops all AS-i outputs to 0 on a CPU RUN-to-STOP transition. Downgrade via the standard Siemens firmware update channel (Online → Accessible Nodes → CM → Firmware Update) to recover the safe behavior.

How do I confirm the firmware version of the CM AS-i Master ST in STEP 7?

Open STEP 7 V5.5 or TIA Portal, connect online to the CPU 319-3 PN/DP, navigate Online → Accessible Nodes, select the CM under the ET 200SP PROFIBUS slave, and read Module Information → Firmware. The version string reads as V1.1.5, V1.1.6, or V1.1.7 depending on the load.

Can a CPU-side watchdog substitute for the firmware downgrade?

A CPU-only watchdog cannot bypass the defect, because the held outputs are driven by the CM, not by the CPU. The watchdog must be implemented in a separate hardware path — for example, a force-guided safety relay that drops the 24 V supply to the AS-i actuators on loss of a CPU heartbeat (a 3SK1 or 3UG48 monitoring relay driven by an OB35 toggle).

Does the CM AS-i Master ST V1.1.5 firmware satisfy SIL-rated safety on its own?

No. The CM AS-i Master ST is a standard (non-F) module and does not provide SIL-rated safety functions. For SIL-rated de-energize-to-safe behavior on STOP, use an F-CPU with PROFIsafe F-I/O and a force-guided safety relay downstream of the actuator drive stage, per IEC 61508 / IEC 62061 / ISO 13849-1.

Back to blog