Troubleshooting Profibus Signal Oscillation on S7-300 DP

David Krause20 min read
ProfibusSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Definition and Symptoms

Signal oscillation on a Profibus DP segment is the most common physical-layer defect seen in brownfield plants running Siemens S7-300 controllers. The failure mode shows up as a fluctuating AB-differential voltage on the wire, which the master interprets as corrupted telegrams rather than steady idle potential. The user-visible symptom is intermittent loss of communication with one or more DP slaves, even though no slave reports a station-level fault and the bus is not transitioning into a hard bus fault (BF on the CPU).

The reference case here is a CPU 314C-2 PN/DP (Siemens order number 6ES7314-6EH04-0AB0) configured as a Profibus DP master on the X2 interface, supervising 8 ET 200M stations built around IM 153-1 (6ES7153-1AA03-0XB0) or IM 153-2 (6ES7153-2BA10-0XB0) interface modules. The application monitors coolant temperature and flow for seven DC motors on an industrial cooling skid. A handheld Profibus tester such as the Softing BC-700-PB or Procentec ProfiTrace reports huge signal oscillations at node 3 and node 7, while all other nodes show a clean idle level around 1.0 V differential and stable telegrams. The CPU diagnostic buffer records DP station failure events for those two slaves, but neither slave's SF LED illuminates and no module on the affected ET 200M stations reports an I/O fault.

Topology of the affected Profibus DP segment (8 ET 200M stations on X2 of the CPU 314C-2 PN/DP) CPU N1 N2 N3* N4 N5 N6 N7* Healthy station Oscillating station

The defining characteristic that distinguishes a signal oscillation fault from a normal bus fault:

  • Intermittent, transient loss of slave response - events cluster, then clear, then return.
  • No station diagnostics from the slave (the IM 153-x does not raise SF).
  • Bus fault (BF) LED on the CPU may flicker rather than latch.
  • Profibus tester shows the AB voltage bouncing, the edges dirty, and the idle level distorted.
Engineering note: When a slave is "lost" by the master but the slave itself shows no fault, the cause is almost always on the physical layer between the master and that slave. Treat any such event as a wiring problem until the physical layer is proven clean.

Profibus DP Physical Layer Reference

Profibus DP (IEC 61158 / IEC 61784) uses RS-485 signalling on a 2-wire, shielded, twisted-pair violet cable (Siemens 6XV1830-0EH10 standard, 6XV1830-3EH10 PUR for oil-exposed areas, 6XV1830-5FH10 trailing). The relevant electrical parameters when interpreting any signal trace are:

Parameter Specification Field interpretation
Nominal bus impedance 150 Ω ± 15 Ω at 3-20 MHz Characteristic impedance of the cable; mismatched cable = reflected edges
Termination resistance 220 Ω pull-up (to VP / 5 V) and 390 Ω pull-down (to GND) per line, plus 150 Ω bridge A-B Implemented inside the bus connector; active at both line ends only
Differential output voltage (driver) ≥ 2.1 V on 55 Ω load Measured across the terminating 150 Ω
Differential input sensitivity (receiver) ± 0.2 V typical, 0.8 V worst case Anything under ± 0.2 V is decoded as a logic zero
Idle bus voltage (AB idle, both ends terminated) ~1.0 V differential (5 V × 150 / (220 + 150 + 390) = 0.99 V) Stable value, no chatter
Active telegram voltage ~0.8 V to 1.0 V peak, switching between 0.2 V and 1.0 V Sharp edges, no ringing
Supply voltage on connector pin 6 (VP) 5 V ± 5 % Powers the termination network; short to ground = master power supply issue
Max cable length @ 12 Mbps 100 m segment, 400 m total with 3 repeaters 1.5 Mbps is the typical DP-V0/V1 limit at 200 m
Max cable length @ 1.5 Mbps 200 m segment Common default for ET 200M
Max stations per segment 32 (master + 31 slaves, or 126 with repeaters) A repeater counts as a station

For installation rules, the binding reference is the Siemens installation guideline (SIMATIC NET PROFIBUS Network Manual) and IEC 61784-1. The rule is that only the first and last physical devices on a segment carry termination; every connector in between must have the termination switch in the OFF position. A common field defect is the bus-termination switch left in the ON position on a mid-segment IM 153 - that places a 220 Ω / 390 Ω / 150 Ω network in the middle of the line, which loads the bus and reflects edges back into the segment. The reflection coefficient at a mis-terminated stub is calculated as:

Gamma = (Z_term - Z_cable) / (Z_term + Z_cable)

For 220 Ohm pull-up alone (no 150 Ohm bridge, no 390 pull-down):
Gamma = (220 - 150) / (220 + 150) = 70 / 370 = 0.19

For 110 Ohm (two 220 in parallel) at one end missing:
Gamma = (110 - 150) / (110 + 150) = -0.15

A reflection coefficient above ± 0.10 is a guaranteed source of edge ringing visible on the AB trace.

Root Cause Taxonomy

When oscillation is observed at two specific nodes on a 9-node network and not on the others, the cause is local to the wiring, connector, or interface of those two nodes. The following list ranks the typical culprits in the order they should be investigated.

  1. Damaged transceiver on the IM 153-x or the master X2 port. A failing RS-485 driver loses its output symmetry and injects noise onto the bus. This is most likely when one node is at the end of a long cable run that absorbs extra electrical stress.
  2. Shield discontinuity between segments. Where the violet cable enters the cabinet, the shield must land on the grounding bar through a 360° low-impedance bond. A pigtail or paint-over bond turns the shield into an antenna and produces oscillation especially at end-of-segment nodes.
  3. Ground potential difference between cabinets. If the cabinet for node 3 and node 7 sits on a different ground rod or on a different power feed than the rest, the equipotential bonding conductor is undersized and the shield currents are large.
  4. Loose or contaminated connector pin. A partially seated connector produces micro-interruptions that show up as ringing on the AB edges.
  5. Cable damage. Kink, crush, or moisture ingress anywhere in the run between the previous and current node is a frequent source. This is true even when the connector at the node was just replaced - the new connector may be terminated onto an already-damaged cable.
  6. EMI from a co-located source. VFD output cables, weld leads, or DC motor armature cables routed within 200 mm of the Profibus cable for any length will couple noise in.
  7. Termination not enabled at the line end. A single missing or open termination at the very last slave produces an unterminated reflection that looks exactly like the symptom shown here.
  8. Excessive stub length or daisy-chain violation. Each Profibus connector drops into the cable; the stub length from the cable to the device socket must be kept below the impedance-matched limit (a few centimetres for high baud rates).
  9. Mix of cable types. Field installations sometimes splice a 100 Ω control cable onto a 150 Ω Profibus cable to make a connector reach. The impedance mismatch reflects every edge.
Field heuristic: If oscillation is local to two nodes that are not adjacent (3 and 7), suspect the cable between node 2 to 3 and node 6 to 7, and the connectors at the ends of those two segments. If it had been a master-side defect, every node would be affected.

Diagnostic Buffer Interpretation on S7-300

On the CPU 314C-2 PN/DP the diagnostic buffer is read with STEP 7 V5.5 / V5.6 or TIA Portal V16+ via Online > Online & Diagnostics > Diagnostic Buffer. The events relevant to a Profibus signal oscillation fault come from the OB 1 / OB 82 / OB 86 set. The most common entries are:

Event ID OB / class Meaning What to do
13:01 DP station failure Slave did not respond within the configured watchdog (Ttr) Check the wiring and termination on the affected slave
13:02 DP station diagnostic Slave returned a diagnostic frame Read the slave diagnostics (SFC 13 / RD_REC)
38:01 OB not loaded An OB the system tried to call does not exist (commonly OB 82, OB 86) Load the missing OB; default STOP entry
84:01 DP bus fault The DP master detected a bus short, bus interruption, or signal fault Inspect the physical layer of the entire segment
84:02 DP bus short Bus voltage out of range; short between A and B or to shield Power down and measure the DC resistance of the segment
85:01 DP slave diagnostic Slave raised a channel-level diagnostic Read the slave diagnostic record set
85:02 DP slave process interrupt lost Process interrupt queue overflow Reduce interrupt rate
86:01 DP diagnostic frame error The master received a corrupted diagnostic frame Almost always physical layer
88:01 / 89:0A DP link down / link up Master saw the link transition out and back Correlate with the time stamp of the slave events

The classic signature of a signal oscillation problem is 13:01 entries for the affected slave with no matching 85:xx diagnostic from the slave, and the 84:01 bus-fault event appearing only when the line is severely disturbed. The time stamp on the 13:01 events is the single most useful data point: if the timestamps cluster, the disturbance is environmental (a press starts, a VFD ramps, etc.). If they are spread randomly, the disturbance is a marginal physical-layer defect.

Programmatically, the slave diagnostic set can be read with:

CALL SFC 13 "DPNRM_DG"
REQ     := TRUE
LADDR   := W#16#03FF   // slave diagnostic address for node 3
RET_VAL := MW100
RECORD  := P#DB20.DBX0.0 BYTE 32
BUSY    := M110.0

If the returned record set is empty when the master has just lost the slave, that confirms the slave never had a chance to put a diagnostic frame on the wire - the bus itself was the failure.

Programming note: If OB 86 is not loaded in the S7-300 program, a DP station failure takes the CPU to STOP. Verify that OB 82 and OB 86 are present in the project (right-click on the CPU in STEP 7 > Object Properties > Interface > OB list) and that they at minimum contain a placeholder return.

Field Measurement Procedure

Before any component is replaced, take a baseline of the segment with a Profibus tester. The most accessible handheld tools are the Softing BC-700-PB / BC-600-PB and the Procentec ProfiTrace 2. Each one combines a Profibus master class 2 tap, a signal-quality oscilloscope, and an automatic topology scan. The Softing all-in-one tester integrates the oscilloscope into the analysis workflow, so a single device can capture the live waveform, decode the telegrams, and grade the signal quality in a few minutes (see Softing: Solving Network Problems with our All-in-One PROFIBUS Tester).

Use the following measurement sequence:

  1. Tap the segment at the affected node. Plug the tester into the Profibus connector in place of, or in parallel with, the slave, and capture the AB differential voltage versus ground. Look for a stable 1.0 V idle, a clean 5 V square when telegrams arrive, and a sharp transition between levels.
  2. Capture a long time-domain trace. Set the time base to 1 s/div and record for 30 s. The oscillation seen in the original report is what you are looking for - a slow wandering of the idle level or a noise ripple superimposed on the square edges.
  3. Read the SignalQuality index. Most modern testers give a 0-100 grade. A healthy segment is > 75. A segment with intermittent slave loss is typically 30-60.
  4. Run the topology scan. The tester will measure the distance to each device, the cable reflection coefficient at the line end, and the termination integrity. Termination is reported as OK / missing / shorted / multiple.
  5. Compare node 3 and node 7 with the other nodes. If two specific nodes are bad and the rest are good, the problem is between the last good node and the first bad node.
  6. Trigger a long recording (5-10 minutes) on the scope with a rising-edge trigger on the AB line. A real oscillation will be captured in this window; a one-shot 30 s capture may miss it.
Warning: When tapping the segment, never short A and B. The 5 V supply on pin 6 is current-limited, but a short can pull the bus into reset and drop every other slave.

Cable, Connector, and Termination Verification

Once the tester has localized the fault, the following checks are performed at the affected nodes. The order is the order of probability for the failure described in the source.

  1. Power down the segment and disconnect both terminators. Measure the DC resistance between A and B with a DMM: it must read 110-130 Ω (the parallel combination of the two 220 Ω pull-ups in series with the two 390 Ω pull-downs, plus the 150 Ω bridge). If the reading is open, the termination network is missing or open. If it reads 50 Ω or less, there is a short.
  2. Inspect the violet cable at the connector. The two cores must be soldered or crimped to pins 3 (B) and 4 (A) of the Siemens 6ES7972-0BA12-0XA0 (35° cable outlet) or 6ES7972-0BB12-0XA0 (90° outlet) connector. The shield drain wire must be landed on the connector's strain-relief clamp and bonded to the cabinet ground bar. A floating shield drain is the most common cause of the oscillation shown in the source capture.
  3. Verify the termination switch position. A Siemens Profibus connector has a slide switch labeled "ON" / "OFF". It must be ON only at the two physical ends of the segment. For an inline node 3 or node 7 the switch must be OFF.
  4. Measure the cable shield-to-ground resistance. With the connector unplugged, the shield continuity from this connector to the previous connector must be < 1 Ω. A reading of 5 Ω or higher is a sign of a corroded or loose bonding point.
  5. Verify the cable type. Profibus DP cable must be 150 Ω characteristic impedance, violet sheath, and the two cores must be a twisted pair. Field installations sometimes use grey control cable (different impedance) for "Profibus" - this fails signal integrity at any meaningful baud rate.

ET 200M IM 153-x Interface Verification

When the wiring has been ruled out, the IM 153-x interface is the next suspect. Both the IM 153-1 (6ES7153-1AA03-0XB0) and the IM 153-2 (6ES7153-2BA10-0XB0) are interchangeable on the bus side - they differ in clock synchronisation, isochronous mode support, and firmware features, not the Profibus DP slave interface itself.

To confirm a healthy interface, perform the following:

  1. Power down the ET 200M station and re-seat the IM 153 in its backplane socket. Bent or oxidized pins on the backplane connector are a frequent cause of intermittent faults.
  2. Power up the station and read the SF / BF LEDs on the IM 153. A steady SF indicates a configuration mismatch or a defective module. A steady BF with flashing SF indicates a Profibus physical-layer problem at the slave. A flashing BF with no SF is consistent with a master-side or cable problem.
  3. Swap the suspect IM 153 with a known-good spare. If the oscillation disappears, the original IM is damaged. A damaged RS-485 transceiver can usually be confirmed by measuring the AB impedance of the IM with the bus disconnected: a healthy IM measures roughly 15-20 kΩ between A and B (high-impedance input); a damaged IM often measures < 1 kΩ.
  4. Check the firmware version of the IM 153 against the HW Config entry. Mismatch between the configured GSD file and the actual IM 153 firmware can produce diagnostic events that look like physical-layer problems. The IM 153-2 ships with firmware V7.x or V8.x depending on the variant; the IM 153-1 ships with V6.x or V7.x. Compare against the installed GSD in STEP 7 (HW Config > right-click the IM 153 > Object Properties > Diagnostics).
  5. Confirm the Profibus address switches on the back of the IM 153. The dip switches must match the slave number in HW Config. A mis-set address does not normally cause oscillation but it does change which node the master reports as failed.
Engineering note: When the spare is installed, perform a power cycle of the entire DP segment, not just the swapped station. Some IM 153-x revisions require a segment-wide restart to re-register on the bus.

Shielding, Grounding, and EMI Mitigation

If the cable, connector, and IM swap do not resolve the oscillation, the next-most-probable cause is shielding and grounding. The Profibus installation rules are unambiguous: the shield of the violet cable must be bonded to a low-impedance ground at both ends, and the two cabinet grounds must be equipotentially bonded. The equipotential bonding conductor is sized per IEC 61784 and is typically a 16 mm² copper braid.

In the reference installation, with seven DC motors and their power cables in the same cable tray, two specific failure modes are common:

  • Common-mode current on the shield. A VFD or a DC motor armature drive pumps high-frequency common-mode current through the Profibus shield. If the shield is bonded at both ends, this current circulates and is dissipated through the equipotential bond. If the bond is missing, the current returns through the AB pair, distorting the signal.
  • Capacitive coupling. A Profibus cable run in parallel with a motor power cable for more than 1 m couples noise by capacitance. Maintain at least 200 mm of separation, and cross power cables at 90° if they must share a tray.

Ferrites on the Profibus cable at each cabinet entry are a low-cost, high-value fix for common-mode current. A clip-on ferrite (e.g., TDK ZCAT2235-1030A or Würth Elektronik 74270097) attenuates the common-mode component by 10-20 dB at 30-100 MHz without affecting the differential signal. Ferrites are not a substitute for proper bonding, but they often resolve residual oscillation once the cable and connector are clean.

Step-by-Step Repair Procedure

The following is a field-proven sequence that resolves the symptom in the source report. The procedure assumes the segments can be taken offline without stopping the cooling system. Adjust the lock-out / tag-out steps for the local site rules.

  1. Capture the diagnostic buffer from the CPU 314C-2 PN/DP, with timestamp and event ID, and export it as a CSV via STEP 7 / TIA Portal.
  2. Run the Profibus tester on the segment, capturing a 30 s waveform at each affected node. Save the trace files for the maintenance log.
  3. Power down the segment at the master cabinet. Lock-out the 24 V supply that feeds the segment terminator power.
  4. Disconnect the cable at the IM 153 for node 3 and the IM 153 for node 7.
  5. Inspect the connectors for shield bond, conductor crimp, and switch position. Re-terminate the cable on a new Siemens 6ES7972-0BA12-0XA0 connector if any of the three are questionable. The connector is a low-cost item and is not worth re-using if there is any doubt.
  6. Cut back 50 cm of cable at the IM 153 entry and re-strip. Cable damage at the connector entry is common because the cable is flexed every time the cabinet door is opened.
  7. Re-verify the shield continuity end-to-end with a low-voltage ohmmeter (< 5 V on the test leads to avoid driving the transceiver ESD clamp).
  8. Swap the IM 153 at node 3 and node 7 with known-good spares.
  9. Power up the segment and confirm the BF LED on the CPU is off, and the IM 153 SF / BF LEDs are off on all 8 stations.
  10. Run the Profibus tester again and confirm the AB voltage is stable, the idle level is in spec, and the SignalQuality index is > 75 at all 8 nodes.
  11. Clear the diagnostic buffer in the CPU and run a 24-hour soak test with the diagnostic buffer capture on. The buffer must remain empty of 13:01, 84:01, 86:01 events for the affected slaves.

Verification and Acceptance Test

The repair is accepted only when all of the following pass:

Test Pass criterion Tool
Idle AB voltage (segment-wide) 1.0 V ± 0.1 V at every node, no drift over 60 s Profibus tester oscilloscope
Idle AB voltage stability at node 3 and node 7 Ripple < 50 mV peak-peak Profibus tester / scope
SignalQuality index > 75 at every node, 100 preferred Profibus tester
Diagnostic buffer, CPU No 13:01, 84:01, 86:01 events over 24 h STEP 7 / TIA Portal
IM 153 SF / BF LEDs Both off on all 8 stations Visual
Topology scan 8 slaves detected at the correct distances, no missing-termination warning Profibus tester
Slave diagnostics (SFC 13) Returns an empty record set or a clean status User program
Cyclic data exchange All 8 slaves are in DXCHG for > 1 h without retries STEP 7 / TIA Portal online

Preventive Maintenance Schedule

Once the network is clean, log the baseline SignalQuality index for every node. A drop of 10 points between annual inspections is the trigger for a deeper investigation. Recommended cadence:

  • Monthly: Read the CPU diagnostic buffer; flag any slave that appears more than once per month.
  • Annually: Run the Profibus tester along the segment, save the topology and signal-quality report, and compare against the baseline. Look for any node whose SignalQuality has dropped 10 points or more.
  • Every 5 years (or after any mechanical work in the cabinet): Re-crimp the Profibus connectors and re-verify the shield bonding. Connector wear is the highest single contributor to intermittent faults after environmental disturbance.
Engineering note: Document the spare IM 153 firmware version in the same maintenance log as the GSD revision used in HW Config. A spare IM with newer or older firmware will work electrically but may produce OB 82 / OB 86 events if the diagnostic frame set does not match the configured GSD.

Frequently Asked Questions

What does "signal oscillation" on Profibus actually look like on a scope?

A healthy Profibus DP segment shows a clean 1.0 V differential idle, switching sharply to a 0.2 V low when telegrams arrive. Signal oscillation looks like a slow ripple or wandering of the idle level (typically tens to hundreds of millivolts), or noise superimposed on the square edges, or both. The Softing BC-700-PB PROFIBUS tester captures this directly and grades the segment with a SignalQuality index between 0 and 100.

Why does the CPU report a station fault when the IM 153 SF LED is off?

The master counts a station as failed if the slave does not return a token-holding response within the configured Ttr watchdog. If the physical layer is disturbed, the IM 153 never gets a chance to put a diagnostic frame on the wire, so its SF LED stays off. The master-side event 13:01 (DP station failure) and possibly 84:01 (DP bus fault) are the only evidence the operator sees.

Can a damaged IM 153 RS-485 transceiver cause oscillation on a healthy cable?

Yes. A failing transceiver loses output symmetry and injects common-mode noise onto the bus. The fastest field test is to measure the AB resistance of the IM with the bus disconnected: a healthy IM measures 15-20 kΩ, a damaged IM often measures under 1 kΩ. Swap with a known-good spare to confirm.

Is it ever acceptable to leave termination on a mid-segment connector?

No. Active termination (220 Ω / 390 Ω / 150 Ω) loads the bus and reflects edges. Termination must be ON only at the two physical ends of a segment, and OFF on every inline node. Some installers leave termination on every connector as a precaution; this is a common cause of the very symptom it is meant to prevent, including visible AB ringing and intermittent station loss.

What baud rate is safe for an 8-station ET 200M network at 200 m total length?

At 1.5 Mbps the maximum segment length is 200 m, so 8 stations along 200 m is at the limit but acceptable if termination is correct and the cable is undamaged. At 12 Mbps the segment limit drops to 100 m, so 8 stations must be reached with repeaters or a lower baud rate. A Profibus tester will grade the SignalQuality index and report margin; do not increase the baud rate until the SignalQuality index is > 75 at every node.

Back to blog