1. Overview: Where the SIMATIC S7-400 Sits in the Siemens Portfolio
The SIMATIC S7-400 is Siemens' mid-to-high-end modular programmable logic controller platform, positioned above the S7-300 and below the S7-1500 in the current generation (the S7-400 remains available and supported for process and plant modernization projects even after the S7-1500 launch). It is designed for system solutions in process engineering, factory automation with high I/O density, and redundant configurations in the S7-400H / S7-400F / S7-400FH variants for safety-instrumented systems up to SIL 3 per IEC 61508.
The defining architectural traits of the S7-400 platform are:
- True modular backplane with separately ordered racks (UR1, UR2, UR2-H, CR3, ER1, ER2) that accept up to 18 slots depending on configuration.
- Multi-row distributed installation with IM (Interface Module) send/receive pairs over distances up to 100 m with the S7-400 IM cable and far further when used with repeaters/FO.
- High-instruction-throughput CPUs (CPU 412, 414, 416, 417) with bit operation times down to approximately 18 ns on the CPU 417-4 and work memory up to 30 MB.
- Native support for PROFIBUS DP (via CP 443-5 or integrated DP interface on the CPU), PROFINET IO (via CP 443-1), point-to-point, ASI, and Ethernet/PROFINET CBA.
- Hot-swappable signal modules in selected configurations with the S7-400H redundant CPU pair, subject to firmware and ET 200M station rules.
The official product family is documented in the SiePortal product tree under SIMATIC S7-400 / S7-400H / S7-400F / FH Automation Systems. The installation-level hardware manual is the SIMATIC S7-400 Automation System Hardware and Installation (manual 6ES7398-8AA10-8BA0 / 424ish_e) and the SIMATIC S7-400 CPU Specifications manual (422rfhcpu_en) covers every shipped CPU family.
2. Mechanical Architecture: Racks, Backplane, and Power Supply
The S7-400 backplane is fundamentally different from the S7-300's bus-connector approach. Each module plugs into a passive rack with a continuous backplane that carries both the P-bus (peripheral / I/O bus, the segment used by signal modules) and the K-bus (communication bus used by CPs and FMs that need high-throughput PII/PIQ exchange with the CPU). The K-bus is a token-passing serial segment between K-bus-capable modules and the CPU; the P-bus is a parallel backplane bus driven by the CPU's IM/CPU interface.
Rack families and slot counts (from the S7-400 Hardware and Installation manual):
| Rack Type | Order Number (MLFB) | Slots | Use Case |
|---|---|---|---|
| UR1 | 6ES7400-1TA01-0AA0 | 18 | Universal rack, standard CPU or H CPU, full P/K bus |
| UR2 | 6ES7400-1JA01-0AA0 | 9 | Compact universal rack |
| UR2-H | 6ES7400-2JA00-0AA0 | 2 x 9 (split) | H-system redundant CPU mounting |
| CR3 | 6ES7401-3DA01-0AA0 | 4 with P/K bus | Compact rack with segmented P-bus (each slot independent) |
| ER1 | 6ES7403-1ER60-0AA0 | 18 (extension only) | Expansion rack without CPU, requires IM |
| ER2 | 6ES7403-1JR60-0AA0 | 9 (extension only) | Smaller expansion rack |
The CR3 rack is special: it segments the P-bus into four isolated bus segments so that a fault on one segment does not propagate to the others. This is the rack of choice when mixing intrinsically safe (Ex) and non-Ex signal modules in the same physical controller or when you want short-circuit isolation between field groups.
Power supplies (PS 405 / PS 407) are mounted on the leftmost slot of the rack:
- PS 405 (6ES7405-0DA02-0AA0): 24 V DC input, 10 A output, for DC-only cabinets.
- PS 407 (6ES7407-0DA02-0AA0 / -0KR02-0AA0): 120/230 V AC or 24 V DC wide-range input, 10 A or 20 A output variants.
Each PS powers the backplane and field-side supply rails for the SMs. Two PS modules can be paralleled for redundancy on a single rack using the redundant-mode wiring shown in the hardware manual section 4.5. The standby module will pick up load within milliseconds of a primary failure, so PII updates from SMs are not lost.
3. CPU Families and Specifications
The S7-400 CPU lineup (per the CPU Specifications manual) is segmented by instruction time, work memory, and the number of integrated interfaces. The relevant families and the typical order numbers (current revision; verify against Siemens Product Support before ordering):
| CPU | Order Number | Work Memory (Code + Data) | Bit Op. Time | Integrated Interfaces |
|---|---|---|---|---|
| CPU 412-1 | 6ES7412-1XJ07-0AB0 | 512 KB / 512 KB | ~75 ns | MPI/DP |
| CPU 412-2 PN | 6ES7412-2EK07-0AB0 | 1 MB / 1 MB | ~75 ns | MPI/DP + PROFINET 2-port switch |
| CPU 414-2 | 6ES7414-2XK07-0AB0 | 2 MB / 2 MB | ~45 ns | DP + MPI/DP |
| CPU 414-3 PN/DP | 6ES7414-3EM08-0AB0 | 4 MB / 4 MB | ~45 ns | DP + MPI/DP + PROFINET 2-port switch |
| CPU 416-2 | 6ES7416-2XS07-0AB0 | 8 MB / 8 MB | ~30 ns | DP + MPI/DP |
| CPU 416-3 PN/DP | 6ES7416-3ES07-0AB0 | 16 MB / 16 MB | ~30 ns | DP + MPI/DP + PROFINET |
| CPU 417-4 | 6ES7417-4XT07-0AB0 | 30 MB / 30 MB | ~18 ns | 2x DP + MPI/DP + PROFINET-ready (via CP) |
Key CPU features common to the family:
- Retentive work memory: The CPU backs up a configurable portion of DBs, Merker (M), timers, and counters to NV-RAM via a backup battery (order number 6ES7971-0BA00) or the maintenance-free accumulator (from firmware V6 on most models).
- Configuration in RUN (CIR): Withdraw-add of signal modules, addition of new PROFIBUS slaves, and limited program changes are possible without stopping the CPU. The historical limit was that you could not change the slot mapping of existing modules; this is the "less restrictive CIR" that began to roll out with the newer CPU 410 (the S7-410 Process Automation / SIPLUS S7-410 line).
- Operating modes: RUN (cyclic), RUN-P (cyclic + programmer access), STOP, STARTUP (OB 100 / OB 101 / OB 102 cold/warm/hot restart), and HALT (program breakpoint debug).
- Diagnostic buffer: Last 200 events with timestamp, retentive across power loss, downloadable via STEP 7 Hardware Diagnostics.
0x2521 = "STOP because diagnostic interrupt OB82 not loaded", 0x3942 = "module removed/inserted", 0x4304 = "PROFIBUS DP station failure"). Cross-reference event IDs in the List Manual appendix "Diagnostic Buffer Event IDs" before assuming a CPU fault. About 70 % of S7-400 "CPU failures" traced by service engineers are actually a missing OB where the diagnostic interrupt was raised.4. Signal Modules (SM): DI, DO, AI, AQ Internals
Signal modules are the I/O boundary of the S7-400. Each SM has a module-specific ASIC that performs P-bus arbitration, parameter storage in the CPU's SDB (System Data Block), and per-channel status reporting. The module's behavior at power-up is driven by parameters from SDB 100 or higher that STEP 7 / TIA Portal writes into the CPU's load memory during configuration download.
4.1 Digital Input (SM 421) Modules
Typical SM 421 DI modules and their characteristics:
| Module | Order Number | Channels | Voltage | Input Delay | Diagnostics |
|---|---|---|---|---|---|
| SM 421 DI 16 x DC 24 V | 6ES7421-1BH01-0AA0 | 16 (isolated groups of 16) | 24 V DC | 1.2 / 3.4 / 4.5 / 15 ms selectable | Wire break (with "diagnostic interrupt" param) |
| SM 421 DI 16 x UC 24-60 V | 6ES7421-1EH00-0AA0 | 16 | 24-60 V UC | 0.5 / 3 / 10 / 20 ms | Yes, group-level |
| SM 421 DI 32 x DC 24 V | 6ES7421-1BL00-0AA0 | 32 (isolated groups of 8) | 24 V DC | 3.4 ms typical | Group-level |
Internally, each DI channel is a galvanically isolated optocoupler feeding a debounce counter. The "input delay" parameter is not just a filter cap; it programs a hardware counter in the module's ASIC so the input must remain stable for the configured number of CPU clock cycles before the status is latched into the PII (Process Input Image). Selectable delays allow the same module to interface with mechanical contacts (long delay, contact bounce immunity) or with high-speed 24 V encoders (short delay).
The 32-channel DI variants use a shared power group of 8 channels: a wire break on one channel is reported as a group diagnostic because the diagnostic bit is per power group, not per channel, in the older ASIC revisions.
4.2 Digital Output (SM 422) Modules
SM 422 DO modules switch the load via either a transistor (DC) or a relay / triac (AC). The transistorized modules include a read-back circuit on each output that compares the commanded state against the actual output transistor voltage; a mismatch raises a diagnostic interrupt. This is the standard mechanism that catches "output commanded ON but transistor blown" faults.
| Module | Order Number | Channels | Type | Rated Current |
|---|---|---|---|---|
| SM 422 DO 16 x DC 24 V / 2 A | 6ES7422-1BH11-0AA0 | 16 | Transistor, read-back | 2 A per channel |
| SM 422 DO 16 x AC 120/230 V / 2 A | 6ES7422-1FH00-0AA0 | 16 | Triac, zero-cross | 2 A |
| SM 422 DO 32 x DC 24 V / 0.5 A | 6ES7422-1BL00-0AA0 | 32 | Transistor | 0.5 A per channel |
| SM 422 DO 8 x Relay | 6ES7422-1HF00-0AA0 | 8 | SPDT relay | 5 A @ 250 V AC |
4.3 Analog Input (SM 431) Modules
Analog inputs are the most complex of the SM family. The SM 431 family includes modules with 8, 16, or 8 isolated channels; common part numbers:
- SM 431 AI 8 x 13 bit (6ES7431-1KF00-0AB0): non-isolated, 8 channels, +/-10 V, +/-20 mA, 4-wire RTD via parameter.
- SM 431 AI 8 x 14 bit (6ES7431-1KF10-0AB0): isolated, 13/14 bit resolution depending on integration time.
- SM 431 AI 8 x 16 bit (6ES7431-1KF20-0AB0): 16 bit, integration time 2.5 / 16.67 / 20 / 100 ms selectable per channel group.
- SM 431 AI 16 bit with HART (6ES7431-1KF50-0AA0): adds HART pass-through for smart instrumentation.
The conversion cycle of an SM 431 module is governed by the integration time parameter. A longer integration time improves effective resolution and mains hum rejection:
- 2.5 ms integration: rejects 400 Hz noise, low resolution.
- 16.67 ms: rejects 60 Hz line noise exactly (integration equals one full 60 Hz cycle).
- 20 ms: rejects 50 Hz line noise exactly (one full 50 Hz cycle). This is the default for European mains.
- 100 ms: highest effective bits, slow update, suitable for temperature measurement.
For thermocouple and RTD inputs the module performs cold-junction compensation using its on-board reference-junction sensor. A constant in the module's parameter set must be set for the channel mode (RTD-4L, TC type K, etc.). Overrange and wire-break diagnostics are raised as diagnostic interrupts on the configured OB82.
4.4 Analog Output (SM 432) Modules
SM 432 modules are 8-channel DAC boards with selectable voltage or current output per channel. The standard part number is SM 432 AO 8 x 13 bit (6ES7432-1HF00-0AB0). Each channel is independently configurable for +/-10 V or 0-20 mA / 4-20 mA output. Like DO modules, SM 432 has read-back that detects open current loops (the current output stage will not achieve commanded current, diagnostic interrupt fires).
5. Function Modules (FM)
Function modules carry their own microcontroller and execute time-critical or computationally expensive tasks offloaded from the CPU. The classic S7-400 FM family:
| Module | Function | Order Number Example |
|---|---|---|
| FM 450-1 | Counter module, 2 channels, 500 kHz | 6ES7450-1AP03-0AE0 |
| FM 451 | Positioning, 3-axis stepper control | 6ES7451-3AL00-0AE0 |
| FM 452 | Electronic cam controller | 6ES7452-1AH00-0AE0 |
| FM 453 | Multi-axis positioning, servo/stepper up to 6 axes | 6ES7453-3AH00-0AE0 |
| FM 455 | PID control, 16 channels | 6ES7455-1VS00-0AE0 |
| FM 458-1 DP | High-end closed-loop control, SIMADYN D successor | 6DD1607-0AA1 |
Each FM is parameterized from STEP 7 via a dedicated "Technology" screen and exchanges its process values with the CPU through the K-bus. The FM's firmware handles interrupts (measuring-value, comparison, limit) and signals the CPU via a configurable interrupt OB (typically OB40 hardware interrupt).
6. Communication Processors (CP) and Integrated Interfaces
The S7-400 has both integrated interfaces on the CPU front panel and plug-in CPs:
- MPI/DP combined port: Available on every CPU. Default MPI 187.5 kbps for programming and HMI. Switchable to PROFIBUS DP master (up to 12 Mbps) via HW Config.
- PROFIBUS DP port: On CPU 414-3 / 416-3 / 417-4, a dedicated DP master interface (9-pin D-sub).
- PROFINET 2-port switch: On PN models, two RJ45 ports that act as an internal managed switch, allowing line topology with up to ~50 IO devices per port.
Common plug-in CPs:
- CP 443-1 (6GK7443-1EX30-0XE0): Industrial Ethernet, ISO/TCP, S7 communication, open TCP/UDP socket programming.
- CP 443-1 Advanced: Adds PROFINET IO controller and web server, supports up to 128 IO devices.
- CP 443-5 Basic / Extended (6GK7443-5DX02-0XE0): PROFIBUS DP master or slave, up to 12 Mbps.
- CP 444: For connecting to industrial Ethernet with Send/Receive and Fetch/Write.
- CP 441-1 / 441-2: Point-to-point serial, RS232/RS422/RS485 with modbus master, RK512, 3964R, ASCII drivers.
The CP 443-1 Advanced can publish data to OPC UA servers when used with appropriate firmware. Programming of these CPs in STEP 7 is via the "Connections" editor under NetPro where you define the connection endpoints and type (S7, ISO-on-TCP, TCP, UDP, etc.).
7. ET 200M: Distributed I/O Backbone
ET 200M is a PROFIBUS DP / PROFINET IO distributed I/O station that accepts the same SM 421/422/431/432 signal modules used in the S7-400 central rack. It is the workhorse remote I/O of any PCS7 or S7-400 system. The core component is the IM 153 (PROFIBUS) or IM 153-4 PN (PROFINET) interface module mounted in slot 1 of the ET 200M station.
7.1 ET 200M Mechanical Assembly
An ET 200M station consists of:
- Power supply on the leftmost slot (typically PS 305 or PS 307, 24 V DC).
- IM 153 interface module in slot 1 (some configurations allow slot 1 for IM and slot 0 unused).
- Up to 8 or 12 SM / FM / CP modules on the backplane bus after the IM, depending on the IM firmware revision. IM 153-4 PN supports up to 12 modules.
The backplane in ET 200M is the S7-300 style, but the SM 331/332/321/322 modules from S7-300 are pin-compatible with the SM 431/432/421/422 S7-400 modules (the part numbers differ but the bus protocol is the same). This is why ET 200M is so widely used as a remote S7-400 I/O island.
7.2 PROFIBUS DP Configuration
When configured as a DP slave on PROFIBUS, the ET 200M receives its parameter set from the DP master (CPU or CP) at start-up. Each slot in the ET 200M maps to a specific I-address range that you specify in HW Config. Example mapping for a DP slave address 3 with 4 SMs:
| Slot | Module | I Address Range | Q Address Range |
|---|---|---|---|
| 1 | IM 153-4 PN | - | - |
| 2 | SM 321 DI 16 x DC 24 V | IB 0 - IB 1 | - |
| 3 | SM 322 DO 16 x DC 24 V | - | QB 0 - QB 1 |
| 4 | SM 331 AI 8 x 13 bit | IW 4 - IW 19 | - |
| 5 | SM 332 AO 4 x 12 bit | - | QW 20 - QW 27 |
The DP slave's diagnostic data is read with SFC 13 "DPNRM_DG" in the user program. The standard diagnostic frame structure includes station status (1 byte), master address (1 byte), manufacturer ID (2 bytes), module status (bytes per slot), and channel diagnostics (per-channel fault bits). Always check RET_VAL from SFC 13 before interpreting the buffer.
7.3 PROFINET IO Configuration
With IM 153-4 PN, the ET 200M attaches as a PROFINET IO device on a PROFINET IO controller (CP 443-1 Advanced or PROFINET-enabled CPU). The slot mapping remains the same but the diagnostic model is GSDML-based rather than GSD-based. The PROFINET diagnostics include:
- Channel diagnostics with channel properties (line break, short circuit, over-range).
- Extended diagnostics via alarm mechanism.
- Port-level link status from the embedded switch.
PROFINET IO allows line topology with port-to-port cabling through the IM's integrated 2-port switch, eliminating the need for external switches for a linear run of stations. Maximum devices per controller depends on CP firmware: a CP 443-1 Advanced with firmware V3.x supports up to 128 IO devices.
8. Interface Modules (IM) for Multi-Rack Expansion
Within a single S7-400 station, expansion racks connect via IM pairs. The sending IM (IM 460) goes in the CPU rack; the receiving IM (IM 461) goes in the expansion rack. The two IM modules are connected with a shielded 468-1 cable (e.g., 6ES7468-1AH50-0AA0, 0.5 m; up to 100 m for IM 461-1 with appropriate cable spec).
IM 460 / IM 461 variants:
- IM 460-0 / IM 461-0: P-bus only, no K-bus extension, no interrupt transmission. Cheapest, suitable for slow I/O expansion.
- IM 460-1 / IM 461-1: P-bus + K-bus, no interrupt transmission.
- IM 460-3 / IM 461-3: P-bus + K-bus, with interrupt transmission. Required if FMs in the expansion rack need to raise interrupts to the CPU.
- IM 460-4 / IM 461-4: Long-distance version with FO interface for distances up to 1.5 km using multimode fiber, 10 km using singlemode.
The IM 461 sits in the leftmost slot of the expansion rack and forwards the backplane bus segments to the rack. From the CPU's perspective the I/O slots in the expansion rack are configured identically to local slots; the only difference is the cycle time overhead for remote rack updates (typically 2-3 ms additional).
9. Programming Interface: STEP 7 / TIA Portal
The S7-400 is configured and programmed with either:
- STEP 7 (Classic, V5.5 SP2 or higher): The traditional tool with HW Config, NetPro, SCL editor, and integrated SFC/SFB libraries. Required for older firmware revisions and for PCS7 V8.x.
- TIA Portal (V14 or higher): The unified tool that supports S7-300/400/1200/1500 and WinCC. TIA Portal V17 and later support current S7-400 CPUs in the device catalog. For S7-400H redundant systems, TIA Portal V17 introduced improved H-system handling.
The user program is a collection of blocks:
- OB 1: Main cyclic program. Called by the operating system at the start of every cycle.
- OB 10/11: Time-of-day interrupts (absolute, configurable).
- OB 20-23: Delay / cyclic interrupts (e.g., OB 35 for 100 ms cyclic user code).
- OB 40-47: Hardware interrupts, triggered by FM/CP/SM with diagnostic interrupt enabled.
- OB 80-87: Error and fault OBs (time, power supply, diagnostic interrupt, insert/remove, CPU fault, etc.).
- OB 100/101/102: Startup OB (cold/warm/hot restart).
- FB / FC: User function blocks (FB with instance DB) and functions.
- DB: Data blocks (global DB for cross-block data, instance DB for FB static variables).
- SFB / SFC: System function blocks supplied by the operating system (e.g., SFC 13 DPNRM_DG, SFB 52 RDREC for PROFINET record reads).
A typical "good citizen" OB 1 snippet that calls a structured process block looks like:
CALL "Main_Process" // FB 100
i_Inputs := P#E 0.0 BYTE 16 // 16 bytes process image input
o_Outputs := P#A 0.0 BYTE 16 // 16 bytes process image output
b_Start := E 0.0
b_Stop := E 0.1
10. Configuration in RUN (CIR) and Online Engineering
CIR is the operation that lets you download configuration changes (HW Config deltas) without going through a CPU stop. The procedure in STEP 7 V5.5 is "PLC > Download to Target CPU > with Operation Mode in RUN". TIA Portal adds a wizard for CIR downloads.
What CIR can and cannot do, historically and with newer firmware:
| Operation | CIR Pre-Firmware V6 | CIR Firmware V6+ and S7-410 |
|---|---|---|
| Add a new SM to an empty slot | Yes | Yes |
| Add a new DP slave to a configured PROFIBUS line | Yes | Yes |
| Change the I/Q address mapping of an existing module | No (full stop required) | Yes (the "less restrictive CIR" feature) |
| Replace a module with one of a different order number | No | Yes if channel count and diagnostics type match |
| Add a new CP or FM | No | Yes, with K-bus reset window |
| Change CPU firmware | No (separate FW update procedure) | No |
The "less restrictive CIR" referenced in service bulletins is a firmware evolution that came with CPU 410 controllers (SIPLUS S7-410, used in PCS7 neo) and with the V7 firmware update on CPU 417-4. It is not available on early CPU 412/414 units; verify your CPU's article number against the firmware release notes before assuming CIR.
11. Diagnostics, Diagnostic Buffer, and Field-Proven Caveats
11.1 Diagnostic Buffer Decoding Workflow
- Connect to the CPU with STEP 7 / TIA online; open the diagnostic buffer (CPU > Module Information > Diagnostic Buffer).
- Note the timestamp of the most recent STOP transition.
- Walk upward in the buffer to find the trigger event; often it is an OB loading issue (event ID 0x2544 = "OB not loaded").
- Cross-reference the event ID against the List Manual "Diagnostic Event ID" appendix.
- If the CPU is in S7-400H, check whether the H-system went redundant; event IDs in the 0x7xxx range are H-system specific.
11.2 Common Event IDs (CPU 41x, firmware V6.x)
| Event ID (hex) | Meaning | Typical Cause |
|---|---|---|
| 0x4304 | PROFIBUS station failure | DP slave powered down or cable broken |
| 0x4344 | PROFINET device failure | IO device link lost |
| 0x2521 | Diagnostic interrupt OB82 missing | SM raised diagnostic but no OB82 loaded |
| 0x3942 | Module removed/inserted | CIR or unplanned hot swap |
| 0x3581 | Power supply failure | PS module fault or 24 V under-voltage |
| 0x113D | Battery low / exhausted | Replace backup battery |
| 0x7960 | H-system: link-up failure | Redundancy loss, check fiber pair |
11.3 Field-Proven Failure Modes
Service experience from integrators and the issues called out in Siemens Product Support FAQs surfaces the following recurring failure patterns on S7-400 installations:
- PROFIBUS cable faults: The DP cable is a shielded twisted pair (Siemens purple cable 6XV1830-0EH10 is the historical standard). When a high voltage (230 V AC or higher) crosses to the PROFIBUS cable due to insulation failure in the field, the surge enters the DP interface ASIC on the IM 153 or the CPU's DP port and destroys it. Field evidence in the trade literature has documented CP 443-5 and CPU 416-2 ports lost in such incidents. Mitigation: always run DP cable in dedicated cable trays with proper segregation; install the recommended 24 V / signal surge suppressors; fit Profibus DP terminators (the 9-pin D-sub on the last node) that include the integrated 220 ohm termination + 390 ohm pull-ups per the PROFIBUS DP standard.
- Memory backup battery exhaustion: The 3.6 V lithium battery (6ES7971-0BA00) backs up RAM and the diagnostic buffer during power loss. A weak battery logs event 0x113D and after one further power cycle the CPU may stop with BATTF LED on. Replace the battery with the power on to preserve RAM; the CPU supports hot-swap of the backup battery.
- Cold-junction compensation drift: ET 200M stations with thermocouple inputs must keep the connector block cold-junction reference consistent. A loose TC connector block or thermal disturbance (sunlight on the cabinet, heat from a drive below) introduces offset errors of 2-5 degrees C. Use a fan-stabilized cabinet or the dedicated cold-junction compensation module.
- Backup battery polarity: The 6ES7971-0BA00 has a defined insertion direction. Reverse insertion does not damage the CPU but the battery is not detected; the BATTF LED lights immediately. Verify polarity on every commissioning.
- CP 443-1 firmware / firmware mismatch: The CP firmware must match the catalog number on the module; firmware V3.2 on a V3.x module or vice versa can produce a "module not responding" error after a hot plug event.
11.4 PROFIBUS DP Cable Length Limits (Field Practical)
The PROFIBUS DP baud rate directly determines maximum trunk length without repeaters:
| Baud Rate | Max Trunk Length per Segment | Typical Use |
|---|---|---|
| 9.6 kbps | 1200 m | Rare in modern use |
| 19.2 kbps | 1200 m | Legacy |
| 93.75 kbps | 1200 m | Slow DP |
| 187.5 kbps | 1000 m | Default MPI |
| 500 kbps | 400 m | Common DP-V0/V1 |
| 1.5 Mbps | 200 m | Common DP-V1/V2 |
| 3 Mbps | 100 m | Faster cycles |
| 6 Mbps | 100 m | Faster cycles |
| 12 Mbps | 100 m | Maximum DP baud rate |
Use the Diagnostic Repeater (6ES7972-0AB01-0XA0) for cable break detection; it reports the distance to a fault via SFC 13 or PROFINET/PROFIBUS diagnostics, saving hours of troubleshooting on long lines.
12. Safety Systems: S7-400F and S7-400FH
The S7-400F variant adds safety functionality for SIL 2 / SIL 3 per IEC 61508. The S7-400FH adds hot-redundant CPU pairs (H stands for high-availability) with safety. Typical safety CPUs include CPU 416F-2, CPU 416F-3 PN/DP, CPU 417-4H, and CPU 414F-4H.
Safety I/O is achieved via SM modules with F-designation (e.g., SM 326F DI 24 x DC 24V, 6ES7326-1BK02-0AB0) and dedicated safety ET 200M stations (ET 200M with IM 153-2 F). The Distributed Safety (S7 Distributed Safety V5.4 SP5 or Distributed Safety in TIA Portal) programming add-on provides F-FB and F-FC libraries for safety logic.
Key safety rules:
- 1001 / 1002 / 2003 voting logic is enforced in the safety program, not in the hardware.
- The safety program runs in a separate cycle within the same CPU; both standard and safety logic are on one controller. This is unlike Safety Integrated in SINAMICS drives which has separate hardware.
- The profisafe protocol carries safety messages over PROFINET (PROFIsafe on PROFINET) or PROFIBUS (PROFIsafe profile). Each F-module has a unique profisafe address set via DIP switches or GSD parameter.
- Proof test intervals (T-proof) for SIL 3 typically range 1-5 years depending on the application.
13. Hot-Redundant H-System Configuration
The S7-400H places two redundant CPUs in the UR2-H rack (each CPU on one segment) with a fiber-optic pair connecting them for synchronization. Both CPUs run the user program in lockstep; the backup CPU takes over within milliseconds if the primary fails. Failover tests are configured via STEP 7's H-CIR wizard and validated with the H-System Diagnostic Tool.
Key H-system parameters:
- Sync rate: Default 100-200 ms. Determines how often the two CPUs exchange the dynamic state.
- Master/Reserve role: Decided by which CPU powers up first, but can be forced via configuration.
- Standby-master upgrade: When the failed primary is replaced, the system can automatically promote the standby master to master without disturbing the process (if hardware configuration permits).
The H-system requires all I/O to be on PROFIBUS DP with redundant DP master capability (CP 443-5 Extended, Y-link for non-redundant devices, or IM 153-2 FOO for redundant PROFIBUS). ET 200M stations with IM 153-2 FOO support both redundant PROFIBUS interfaces, which is the standard pattern for H-system I/O.
14. Common Hardware Swap Procedures
Hot-swap rules for S7-400 modules, summarized:
| Module | Hot-Swap Allowed in Standard S7-400 | Hot-Swap Allowed in S7-400H |
|---|---|---|
| Power supply (PS 405/407) | Yes, with redundancy configured | Yes, redundant |
| CPU | No | Yes, in standby CPU |
| Signal module (SM) | No (CIR not for SM swap) | Yes, on redundant I/O |
| CP / FM | No | Limited |
| Backup battery | Yes, always | Yes, always |
For S7-400 SM swap in a running CPU, the supported procedure is to use CIR (download configuration delta). The actual module changeover is not "hot" - the module's slot goes through a bus reset and PII for that slot is held at last value or zero for a few hundred milliseconds.
15. Comparison: S7-400 vs S7-1500 Selection Notes
Engineers selecting a controller for a new project today should compare the S7-400 (and its successor S7-410 Process Automation) against the S7-1500. Some practical rules of thumb from experience:
| Criterion | S7-400 / S7-410 | S7-1500 |
|---|---|---|
| Maximum I/O per station | ~6500 (H-System up to 12,800) | ~8000 per station with PROFINET |
| Bit operation time (top CPU) | ~18 ns (CPU 417-4) | ~1 ns (CPU 1518) |
| Native PROFINET | Via CP 443-1 or PN CPUs | Integrated on every CPU |
| Native OPC UA server | CP 443-1 with firmware V3 | Standard on CPU 1515+ |
| H-System availability | S7-400H, mature | S7-1500R/H (newer, smaller scale) |
| Safety (SIL 3) | S7-400F / FH, mature | S7-1500F, mature |
| Time to market / support | Maintenance phase, supported | Active development |
| Process industry (PCS7) | Native platform | PCS7 neo / S7-410 Process Automation |
Choose S7-400 / S7-410 when: the project is a brownfield expansion of an existing PCS7 plant; the plant requires S7-400H redundancy at scale; SIL 3 is required on existing S7-400F logic. Choose S7-1500 when: greenfield project, need OPC UA, want faster scan times, want a longer forward support window.
16. Commissioning Checklist
- Verify rack earthing: each S7-400 rack must be bonded to cabinet ground at the dedicated M6 grounding point. Cross-sectional area minimum 10 mm^2 copper to cabinet PE.
- Install PS module and verify the DC OK LED; measure 5 VDC and 24 VDC on the backplane test points.
- Install CPU with backup battery installed. Insert in slot 1 of UR1 / UR2.
- Connect programming PC via MPI/DP cable to the CPU's combined port; default MPI address 2, default baud 187.5 kbps.
- Open STEP 7 / TIA Portal and perform "Accessible Nodes" scan to confirm CPU is reachable. Verify firmware version shown matches the catalog.
- Configure rack layout in HW Config. Save and compile. Note that STEP 7 will report "compile errors" if a CPU firmware version is not in the HW catalog; install the corresponding HSP (Hardware Support Package) from Siemens Product Support.
- Configure PROFIBUS / PROFINET topology and DP/IO device addresses. Use the diagnostic repeater on long segments.
- Download hardware configuration. CPU goes through STOP > RUN transitions as part of the download.
- Download user program (blocks). Confirm DB, FB, FC, OB are present in the online block list.
- Set the date and time on the CPU; confirm diagnostic buffer timestamps are coherent with the controller's location time zone.
- Force-test each SM by toggling a field input and confirming the PII updates in the variable table. Force-test each output with a measured load to verify transistor switching.
- Perform PROFIBUS DP diagnostic test by unplugging a slave and confirming event 0x4304 plus an OB82 diagnostic interrupt entry.
- Document the commissioning with a printout of the HW Config, the NetPro connection list, and the diagnostic buffer baseline (typically the first 50 entries after first RUN).
17. Troubleshooting Matrix
| Symptom | First Action | Likely Root Cause |
|---|---|---|
| CPU STOP, BATTF LED | Replace backup battery with power on | Battery exhausted |
| CPU STOP, SF LED | Read diagnostic buffer, check OB loading | Missing OB or program error |
| CPU STOP, BF1/BF2 LED | Check PROFIBUS / PROFINET cable and slave | DP/IO device missing |
| CPU STOP, FRCE LED flashing | Check forced variables in variable table | Force job in place |
| DP slave intermittently missing | Check cable shield, terminators, baud rate | EMC interference or terminator missing |
| Analog input reads -32768 / 7FFFh | Check wiring and channel mode parameter | Wire break or wrong measuring range |
| SM 421 group diagnostic | Inspect channel group power and wiring | Power group loss or short circuit |
| CP 443-1 not visible in HW Config | Install correct HSP / firmware | HSP missing in STEP 7 catalog |
| H-System link-down | Inspect fiber-optic pair and synchronization module | Fiber damaged or sync module fault |
| ET 200M station dropouts in DCS | Verify DP address DIP switches match configuration | Address conflict or wrong GSD |
18. Frequently Asked Questions
What is the difference between S7-400, S7-400H, and S7-400F?
S7-400 is the standard CPU line (e.g., CPU 414-3, CPU 416-3). S7-400H adds a redundant CPU pair with optical sync for high-availability failover in milliseconds. S7-400F and S7-400FH combine either a single or redundant CPU with safety functions for SIL 2 / SIL 3 per IEC 61508 using the PROFIsafe profile over PROFINET or PROFIBUS.
Can ET 200M use the same signal modules as the S7-400 central rack?
Yes. ET 200M accepts S7-300-style SM 321 / 322 / 331 / 332 modules. The SM 421 / 422 / 431 / 432 modules for S7-400 are pin- and protocol-compatible with their S7-300 counterparts. The main difference is firmware: an SM 431 designed for S7-400 will also work in an ET 200M station because both use the same backplane protocol.
How is the diagnostic buffer accessed when the CPU is in STOP?
Open STEP 7 / TIA Portal, go online to the CPU via MPI/DP/Ethernet, and select "PLC > Module Information > Diagnostic Buffer". The buffer is retained through power loss if the backup battery is healthy. If the CPU is unreachable, check the battery, the 24 V supply, and the MPI cable; an S7-400 CPU with no battery can still be read online via MPI.
What is the practical maximum number of PROFIBUS DP slaves on one CPU 416-3 master port?
PROFIBUS DP allows up to 126 stations on a logical bus segment, but practically for S7-400 the limit is around 64 slaves per DP master because of cyclic time, configuration size in the SDB, and the DP-V1 / DP-V2 timing windows. Each slave with 32 bytes of I/O consumes ~50 microseconds of bus time at 1.5 Mbps. For more than 64 slaves, split the plant onto separate DP master ports or use PROFINET.
What firmware version enables the "less restrictive CIR" on S7-400?
The enhanced Configuration in RUN functionality (allowing re-mapping of existing I/O addresses and module-for-module substitution with same channel count) ships in CPU 410 Process Automation and from firmware V7.x on CPU 417-4 / CPU 416-3 PN/DP. The standard S7-400 CPUs (412-2 PN, 414-3 PN/DP) typically support classic CIR with slot add/remove only. Always verify against the firmware release notes for the specific article number before planning a CIR retrofit.
Is the S7-400 still orderable in 2026 and beyond?
Yes. Siemens has placed the S7-400 in the active support phase for process-industry customers with PCS7 plants. New units and spare parts are orderable through the SiePortal catalog tree at SIMATIC S7-400 product family. The newer S7-410 Process Automation CPU is the recommended path for greenfield PCS7 work.