1. Problem Statement
A SIMATIC ET 200SP HF station built on an IM 155-6 PN ST interface module reports a persistent "Overtemperature" diagnostic on a 4-channel failsafe digital output card F-DQ 4x24VDC/2A PM HF (MLFB 6ES7136-6DB00-0CA0). The fault appears within seconds of inserting the module into its BaseUnit, even with no field wiring connected to any output channel. Once the overtemperature alarm is raised, the F-host passivates the module: every F-I/O channel enters the safe state and the diagnostic buffer of the F-CPU logs Channel fault / passivation.
The behavior is unusual because:
- Only channel 0 has been activated, and its load current is far below the 2 A per-channel limit.
- The fault occurs with or without load wiring attached to the terminal block.
- Power cycling the station clears the overtemperature indication, but the
FI/O Passivatedstatus latches and the F-CPU rejects a re-integration acknowledgment until the underlying cause is removed.
The remainder of this document shows how to separate a true silicon-level overload from a backplane/BaseUnit-induced short, and how to recover the channel through the F-CPU without violating the Profisafe re-integration rules.
2. Affected Hardware Identification
| Item | Designation | Order Number (MLFB) | Role |
|---|---|---|---|
| Interface module | IM 155-6 PN ST | 6ES7155-6AU00-0BN0 (or current revision) | PROFINET head, distributes the backplane bus |
| BaseUnit (BU) | BU15-PN+A0+2B / BU15-PN+A0+2D | 6ES7193-6BP00-0BAx / 6ES7193-6BP00-0BDx | Holds the F-DQ, provides the 24 V power contacts and mechanical/electronic keying |
| Safety output module | F-DQ 4x24VDC/2A PM HF | 6ES7136-6DB00-0CA0 | 4 fail-safe P-type semiconductor outputs, 2 A each, 24 V DC |
The "HF" suffix marks the High-Feature (HF) generation of the ET 200SP safety I/O, with extended diagnostics, value status (QI), and isochronous support. The "PM" denotes a P-switching output stage that can be parameterized to M-switching in TIA Portal. The "-0CA0" suffix is the current Siemens release of this article; earlier suffixes such as -0BB0 have different diagnostic bit assignments and should not be mixed in the same station.
3. ET 200SP HF Safety I/O Architecture
The ET 200SP HF safety module family is designed for PROFIsafe v2.6.1 over PROFINET. The F-CPU (an S7-1500F or S7-1200F) maintains a PROFIsafe watchdog; if the F-host does not receive a fresh safety telegram within the configured F_WD_Time, it passivates the channels and raises Communication failure. The reverse direction is also enforced: if the F-DQ cannot be addressed by the F-CPU for a single missed cycle, the module passivates itself locally.
Mechanically the station is a daisy-chain of BaseUnits. Each BaseUnit carries:
- Power contacts for 24 V (P1/P2) and 0 V (M1/M2), bridged from BU to BU through self-cutting knife contacts.
- Backplane pin connectors (the black plastic pin strip on the rear of the BU) that mate with the module's gold pads. These pins carry the backplane bus, the supply rails, and the AUX terminals.
- Mechanical coding key - a colored plastic key that physically prevents the wrong I/O module from being inserted into the BU.
- Electronic coding memory - a small EEPROM region inside the BU that records the last module type plugged into the slot, so that on a module swap TIA Portal can warn "wrong module type".
The output stage of the F-DQ PM HF is a high-side MOSFET per channel, with a current sense resistor in the source leg, thermal sensor bonded to the die, and an integrated watchdog that triggers Channel passivation if the die temperature exceeds the silicon limit (typically 135 to 150 °C). When the die cools, the module re-arms the channel but it remains passivated at the F-CPU level until a re-integration command (PROFIsafe control bit OA_ACK = 1 for one cycle) is received.
4. Decoding the Overtemperature Diagnostic
The F-DQ HF reports faults through PROFINET channel diagnostics (ChannelDiag) and extended channel diagnostics (ExtChannelDiag). For the F-DQ 4x24VDC/2A PM HF, the relevant diagnostic identifiers are:
| ChannelDiag bit / DS1 value | Meaning | Typical reason |
|---|---|---|
0x000A - Short circuit |
Output driver detected V_DS above short-circuit threshold | Wiring fault, cross-channel short, defective actuator |
0x000B - Overload |
Channel current exceeded 2 A nominal or thermal foldback engaged | Inductive load, capacitive inrush, parallel wiring |
0x000C - Overtemperature |
Die temperature > thermal shutdown threshold | Output stage overloaded, ventilation blocked, or backplane short feeding the output stage |
0x000D - Wire break |
Current below wire-break threshold (~1 mA) in ON state | Open cable, lamp/LED load burned out |
0x000E - Parameter error |
Invalid substitution value, mismatch in PROFIsafe address | Configuration download was incomplete |
0x000F - Safety-related passivation |
F-CPU has issued a passivation, or local self-test failed | Channel-level safety violation, PROFIsafe timeout, F-parameter mismatch |
In the failing station, only 0x000C (Overtemperature) is present, with the textual qualifier "the output stage is overloaded and gets too hot - match load and output stage". The qualifier is a generic user hint; it does not prove that an external load is the cause. The thermal sensor measures the die temperature of the output stage, which is heated both by legitimate load current and by current leaking into the output stage through a backplane short or a damaged BU power contact.
5. Primary Root Cause - BaseUnit Keying and Backplane Short
Field service cases on the F-DQ 4x24VDC/2A PM HF consistently show that a persistent, load-independent overtemperature fault on a brand-new station is almost always caused by a damaged or misaligned BaseUnit, not by the F-DQ module itself. The two most common BaseUnit failure modes are:
5.1 Damaged coding element / cover
The colored plastic key on the top of each BaseUnit serves two mechanical purposes:
- It blocks the wrong module type from being inserted.
- It locks the backplane pin strip's plastic retainer in the correct orientation so that the gold pads of the module align with the correct power and bus pins of the BU.
If the key's protective cover is broken or the key itself is missing, the backplane pin connector can be forced to rotate during module insertion. The black pin connector carries the 24 V power contacts, the 0 V contacts, and the AUX bus. A 90° or 180° rotation of the connector routes those contacts to the wrong pads on the F-DQ's underside. In practice, this has two effects:
- It shorts the 24 V rail to a signal pin that feeds the gate driver of an output MOSFET.
- It connects the output pin directly to 24 V regardless of the F-DQ's internal switch state.
The output stage is then powered permanently, dissipates P = V_x × I_leak continuously, and the die reaches the overtemperature threshold in 5 to 30 seconds - exactly the symptom observed in the failing station.
5.2 Reversed mechanical key
Replacing the module in the field without removing the BaseUnit can lead to a more subtle error: a technician may rotate the new module's key to match the slot, rotate the BU's keyway to match the new module, or - more dangerously - rotate the electronic coding element. The Siemens ET 200SP HF System Manual explicitly warns against manipulating the mechanical key or the electronic coding memory of a BaseUnit that is wired into an active station. The black pin connector is keyed to a single orientation (a half-moon keyway on the connector that must face downward when the BU is mounted horizontally). When that connector is forced to a different orientation, the backplane pinout shifts by one or two positions, with the same effect as in section 5.1.
5.3 Other contributing causes
- Bent backplane pins on the BU's pin strip (often caused by dropping the BU on a hard surface during cabinet assembly).
- Solder bridges on the BU PCB from manufacturing defect or rework.
- Contamination of the contact area with coolant, cable lubricant, or copper dust from drilling above the cabinet.
- Reverse polarity of the 24 V supply (P1/P2 and M1/M2 swapped) - less likely on a new cabinet, but possible if the power feed module on a previous slot was wired backwards.
6. Ruling Out Other Common Causes
Before replacing either the F-DQ or the BaseUnit, walk through the following elimination matrix to make sure the failure is not on the load side:
| Symptom | Likely cause | Quick check |
|---|---|---|
| Overtemperature only when load is connected | Inductive kick, capacitive inrush, lamp/LED inrush > 2 A | Measure cold and hot resistance; clamp the inrush with a current probe |
| Overtemperature with no load, single channel | Damaged MOSFET in that channel | Deactivate all channels, re-insert, observe which DS1 value appears |
| Overtemperature with no load, all slots, all channels | Backplane/BU short | Move the F-DQ to a known-good BU on a different slot; if fault follows the module, the module is bad; if it stays on the slot, the BU is bad |
| Overtemperature + PROFINET diagnostics of "station failure" | IM 155-6 PN ST has lost power to that segment | Check the power feed BU; the IM status LED should be solid green |
| Overtemperature + "parameter error" | Module was hot-swapped without re-download of the HW Config | Recompile the GSDML in TIA Portal and download to the F-CPU |
| Overtemperature + "module missing" in the device view | Module is not properly latched into the BU | Remove and re-seat the module until the locking lever clicks audibly |
The fastest single check in the field is to move the suspect F-DQ to a different slot on a known-good BU. If the overtemperature fault follows the module, the F-DQ itself is damaged (rare on a brand-new unit). If the fault stays on the original slot, the BaseUnit is the culprit.
7. Step-by-Step Field Resolution Procedure
- Place the safety function in maintenance state. In TIA Portal, open the safety administration editor, set the F-CPU to Safety mode: deactivated for the affected station, and confirm the operator that the safety outputs are in the safe (de-energized) state.
- Power down the station. Remove the 24 V supply to the IM 155-6 PN ST and to the BaseUnit power contacts. Wait at least 30 seconds for the output stage capacitors to discharge.
- Inspect the BaseUnit visually. Look at the colored mechanical key on top of the BU. The F-DQ 4x24VDC/2A PM HF is keyed with a specific color combination - verify that the slot's color matches the module. A missing or broken key cover is the most common cause on new cabinets.
- Inspect the backplane pin connector. With the module removed, look straight down into the BU's pin strip. All pins must be straight, parallel, and at the same height. A pin that sits higher than its neighbors is bent and will short against the module's pad. Do not attempt to straighten a bent pin with pliers - the gold plating will be damaged. Replace the BaseUnit.
- Verify the connector orientation. The black pin connector of the BU has a half-moon keyway. With the BU mounted normally in the cabinet (DIN rail horizontal), the half-moon must face downward. If it has been rotated, re-seat the connector with the half-moon facing down before re-inserting the module.
- Re-seat or replace the BaseUnit. If the BU shows any sign of physical damage, replace it with a new one of the same type (BU15-PN+A0+2B or BU15-PN+A0+2D depending on the screw vs push-in variant you are using). The mechanical keying is factory-set per BU type - do not change the coding once the BU is wired into the station.
- Re-insert the F-DQ module. Align the module's keyway with the BU's key, slide it in vertically, and close the locking lever until it clicks. Confirm the module's status LED shows solid green (RUN) without the red MF (maintenance/fault) LED.
- Re-apply 24 V power. Observe the diagnostic buffer in TIA Portal for at least 60 seconds. The overtemperature alarm must not reappear.
8. F-I/O Passivation Recovery Procedure
Replacing the BaseUnit clears the root cause, but the F-CPU still holds the channel in the passivated state because PROFIsafe requires an explicit operator acknowledgment. The re-integration sequence must follow the same rules used for any other safety module (compare with the passivation reset pattern documented in the POINT Guard I/O Safety Modules User Manual, 1734-UM013R-EN-P):
- In the TIA Portal online view, open Devices & Networks > [IM 155-6 PN ST] > Module parameters > F-parameters. Verify that the PROFIsafe F_source_address and F_destination_address match the rotary switch on the back of the F-DQ module (address range 1 to 1023; default 1 for the first safety module in the station).
- Confirm that the F_WD_Time matches the F-CPU project. A default of 100 ms is typical for PROFINET, but a value below 50 ms is fragile and can re-passivate the channel during the next diagnostic burst.
- Open Watch table and force the F-I/O DB to its safe state. Then set the operator acknowledgment bit (
ACK_OPor, for S7-1500F, the ACK_REI tag in the F-I/O DB) for one PROFIsafe cycle (one OB1 pass with the F-CPU in RUN). - Reset the bit immediately. The F-CPU will send a single
OA_ACK = 1control bit in the next PROFIsafe telegram; the F-DQ clears the local passivation flag and resumes normal operation. - Verify in the online diagnostic view that the channel value status (QI) returns to
1(valid process data) and that the channel diagnostic no longer reports0x000C.
F-STOP. The acknowledgment must be applied for exactly one F-cycle and then removed, exactly as the Siemens F-system manual describes.9. Verification and Safety Acceptance Test
After the BaseUnit has been replaced and the channels re-integrated, perform a full safety acceptance test that mirrors the SAT performed during commissioning. This is a regulatory requirement under IEC 61511 / IEC 62061 and must be signed off before the safety function is returned to service.
| Test step | Expected result | Pass criterion |
|---|---|---|
| 1. Apply 24 V supply with no load on the channels | Module RUN LED solid green, MF LED off | No diagnostic, no passivation for 5 min |
| 2. Activate channel 0 in TIA Portal watch table | Channel value QI = 1, no alarm | Measured output voltage at terminal 1.0 within 0.5 V of supply |
| 3. Apply 1.0 A resistive load on channel 0 for 10 min | Channel value stable, no overtemperature | Module case temperature rise < 30 K above ambient |
| 4. Force a short circuit on channel 0 (24 V to 0 V at the load) | Channel diagnostic 0x000A, channel passivated, other channels remain active |
Short-circuit detection within 5 ms, no overtemperature |
| 5. Remove the short, acknowledge the channel | Channel returns to active state, value QI = 1 | No re-trigger of the short-circuit diagnostic |
| 6. Disconnect the load wire, force channel 0 ON | Wire-break diagnostic 0x000D
|
Wire-break detected within 1 s |
| 7. Power-cycle the station | Module returns to RUN, all F-parameters intact | No re-commissioning required; PROFIsafe address preserved in the BU |
Steps 1 and 2 verify the overtemperature root cause has been eliminated. Steps 3 to 6 confirm the diagnostics still meet the response time and detection thresholds required by the original safety function. Step 7 confirms the electronic coding of the new BaseUnit has correctly inherited the project parameters from the F-CPU download.
10. Field Engineering Notes and Preventive Measures
- Always order BaseUnits in the exact variant you need. The BU15-PN+A0+2B (push-in) and BU15-PN+A0+2D (screw) have identical electrical pinout but different mechanical strain-relief geometry. Mixing them creates gaps in the cabinet cooling airflow and can produce local hot spots that confuse the thermal diagnostic.
- Never modify the mechanical key on an installed BaseUnit. Siemens documents this restriction in the ET 200SP HF System Manual. If the wrong module has been inserted into a slot, replace the BU, do not re-code it.
- Do not attempt to repair damaged BaseUnits. The plastic key retainer and the backplane pin strip are not user-serviceable. The same principle applies to most industrial safety components: do not deform, heat, incinerate, or disassemble them, as documented in safety literature such as Omron's safety precautions for temperature controllers for the general class of safety-critical components.
- Store spare BaseUnits in their original anti-static bag. The pin strip is gold-plated and will tarnish slowly if exposed to humid plant air, increasing contact resistance and causing local heating at the backplane interface.
-
Use the TIA Portal "Compare" function on the IM 155-6 PN ST after every BaseUnit swap. The electronic coding memory in the new BU will read "empty" until the F-CPU re-downloads the configuration. A mismatch triggers
0x000E - Parameter error, not0x000C- overtemperature - and the corrective action is different. - Document the failure mode. The combination of "overtemperature with no load + BaseUnit damaged" should be reported to your Siemens representative. The MLFB suffix and the production date code on the BU's side label (format YWW, e.g. 244 = mid-2024) are required for any warranty case or quality notification.
- Train cabinet builders on BaseUnit handling. Most field returns of new ET 200SP safety I/O with "mysterious overtemperature" trace back to mechanical damage during cabinet assembly, not to the module itself. A 10-minute toolbox talk on BU handling eliminates a large fraction of these returns.
Frequently Asked Questions
What is the order number (MLFB) of the F-DQ affected in this case?
The affected module is the F-DQ 4x24VDC/2A PM HF, MLFB 6ES7136-6DB00-0CA0, on a SIMATIC ET 200SP HF station with an IM 155-6 PN ST interface.
Can the F-DQ 4x24VDC/2A PM HF overtemperature fault be caused by an actual overload?
Yes - a sustained output current above 2 A or a heavy capacitive/inductive inrush will heat the die past the 135 to 150 °C thermal shutdown threshold. However, an overload can only occur with load wiring connected. If the alarm appears with no wires on the terminals, the heat is being generated by a backplane or BaseUnit fault, not by the load.
How do I clear the F-I/O passivated state after replacing the BaseUnit?
From the TIA Portal online view, force the F-CPU to issue a one-shot acknowledgment (ACK_OP or ACK_REI) for one PROFIsafe cycle, then clear the bit. The F-DQ clears its local passivation, the channel value status (QI) returns to 1, and the channel resumes normal operation. The bit must not be held high - holding it triggers the F-CPU's F-STOP safety stop.
Is a damaged BaseUnit repairable in the field?
No. Bent backplane pins, broken mechanical keys, and rotated pin connectors are not field-repairable; the BaseUnit must be replaced with a new unit of the same type (BU15-PN+A0+2B push-in or BU15-PN+A0+2D screw). The electronic coding memory of the new BU is reloaded by the F-CPU on the next configuration download.
How can I tell whether the F-DQ or the BaseUnit is the actual defective part?
Move the suspect F-DQ to a known-good BaseUnit in a different slot. If the overtemperature diagnostic follows the module, the F-DQ is damaged and must be replaced. If the diagnostic stays on the original slot, the BaseUnit is damaged and must be replaced. This single cross-swap test resolves the ambiguity in under five minutes without disconnecting any field wiring.