1. Problem Overview
An Siemens S7-300 CPU that transitions to STOP during operation and refuses to return to RUN is one of the most disruptive failure modes in brownfield plants. Operators see the STOP LED illuminated, the process outputs drop to their configured substitute values, and field equipment either holds last state (for retentive outputs) or de-energizes depending on the wiring and the values defined in the hardware configuration (HW Config) of STEP 7. The user program is no longer executed, so the controlled process is brought to a safe, idle state per Siemens functional description of S7-300/S7-400 operating modes (STOP mode - S7-300/S7-400).
The classic field symptom reported is: CPU enters STOP, MRES / RUN selector toggle fails to recover, hot-restart does not occur, and only a hardware swap returns the line to service. Before declaring the CPU scrap, every STOP event must be traced to a root cause through the diagnostic buffer (Diagnostic Buffer / Diagnosepuffer) and the active error organization blocks (OBs).
2. STOP Mode Fundamentals on S7-300 CPUs
The S7-300 operating state machine is shared across the 312, 314, 315-2 DP/PN, 315F-2 DP/PN, 317-2 DP/PN, 317F-2 DP/PN, and 319-3 PN/DP families. STOP semantics per the Siemens functional description:
- User program execution is suspended (OB1, OB35, OB40, OB82, OB85, OB86, OB100, OB121, OB122 all stop).
- All process outputs are forced to the substitute values configured in HW Config (0, 1, or Hold Last Value).
- Forcing is removed; the force table is reset on the next RUN start.
- The diagnostic buffer, real-time clock, and retentive flags/Markers/timers/counters remain intact.
- The CPU accepts online configuration changes only via STEP 7 and ignores most user commands from the program.
Powering the CPU down and back up performs a complete restart (OB100); the MRES selector position performs a memory reset that clears the work memory, reload from MMC, and a cold restart. If MRES is not successful, the failure is almost always traceable to either a corrupted MMC, a defective CPU firmware, or a system fault that the OB hierarchy cannot mask.
3. Root Cause Matrix
STOP events on S7-300 fall into seven well-defined categories. The diagnostic buffer event ID and the active SF/BF/FRCE/MAINT/SD LED combination disambiguates each case.
| Category | Typical LED State | Diagnostic Buffer Signature | Recovery Action |
|---|---|---|---|
| Programming / logic error (OB121) | SF on, STOP on | Event ID 0x2521, 0x2522, 0x2523, 0x2524 (programming error) | Download corrected logic; load OB121 to mask |
| I/O access error (OB122) | SF on, STOP on | Event ID 0x2525, 0x2526, 0x2527, 0x2528 (I/O access fault) | Repair rack slot, replace IM/IM153, load OB122 |
| Diagnostic interrupt (OB82) | SF on, STOP on | Event ID 0x2540–0x2547 (diagnostic interrupt from module) | Resolve module/channel fault, replace module, load OB82 |
| Rack / station failure (OB86) | SF on, BF on, STOP on | Event ID 0x2730, 0x2731, 0x2732, 0x2733 (rack failure / PROFINET / PROFIBUS station failure) | Repair DP/PN cable, replace IM/IO device, load OB86 |
| Priority class error (OB85) | SF on, STOP on | Event ID 0x2530–0x2536 (OB not loaded / OB not found) | Download missing OB; verify HW Config matches installed modules |
| System fault / CPU-internal | SF on, STOP on, FRCE off | Event ID 0x2300–0x23FF (internal CPU error, firmware watchdog, memory parity) | MRES, MMC re-image, firmware update, CPU replacement |
| Power / backplane | SF on or off, STOP on | Event ID 0x2780, 0x2781 (PS failure), or no event (hard fail) | Check PS 305 / PS 307 output, backplane connector, grounding |
4. Diagnostic Buffer Retrieval Procedure
The diagnostic buffer is the single most valuable artifact when an S7-300 enters STOP. The buffer holds the last 100 (small) to 500 (large) entries with millisecond timestamps, allowing reconstruction of the chain of events leading to STOP.
- Connect the engineering station running STEP 7 V5.6 / V5.7 (classic) or TIA Portal V17–V20 to the CPU's MPI/DP/PN interface.
- Open the project that contains the offline hardware configuration matching the physical rack. If the offline project is unavailable, use "Accessible Nodes / Online > Diagnostic" for read-only retrieval.
- Navigate to CPU > Module Information > Diagnostic Buffer (in TIA Portal: Online & Diagnostics > Diagnostics buffer).
- Read the most recent events in reverse chronological order. Identify the event ID, the affected OB, the module address (logical / geographic), and the timestamp.
- Export the buffer to a text file (right-click > Save As). The export preserves the 16-bit and 32-bit raw values needed to query Siemens SIMATIC Technical Support.
- Cross-reference the top-of-buffer STOP entry with the Stack tab of the Module Information dialog. The B (break) stack pinpoints the instruction that triggered a programming error (OB121/OB122).
RD_SINFO / SFC 51 read in the user program if necessary.5. OB-Based Fault Classification
Error OBs are the second pillar of the diagnostic process. The presence or absence of an OB at runtime determines whether the CPU enters STOP for a given fault class. This is the principle alluded to in the field report: "Hardware problems will only cause the PLC to stop if you haven't loaded the corresponding hardware error OBs into the PLC."
| OB | Name | Trigger | Effect if OB is missing |
|---|---|---|---|
| OB82 | Diagnostic interrupt | SM/CP/IM diagnostic event (wire break, short circuit, channel fault) | CPU enters STOP with SF LED |
| OB83 | Insert/remove interrupt | Module pulled under power, hot-swap on ET 200M | CPU enters STOP |
| OB85 | Priority class error | Access to non-existent module, OB not loaded, update OB error | CPU enters STOP |
| OB86 | Rack/station failure | PROFIBUS DP slave failure, PROFINET IO device failure, IM failure | CPU enters STOP |
| OB100 | Complete restart | Power up or MRES | STOP if OB100 is missing and CPU is configured for restart |
| OB101 | Hot restart | Hot-restart on power return | STOP on power return |
| OB121 | Programming error | BCD conversion overflow, illegal instruction, range violation | CPU enters STOP for the priority class of the fault |
| OB122 | I/O access error | Direct I/O access to a faulty/removed module | CPU enters STOP for the priority class of the fault |
For a robust installation, a minimum set of OBs should be loaded even if empty: OB82, OB85, OB86, OB100, OB121, OB122. This converts a hard STOP into a logged and recoverable fault, allowing the process to be brought down through controlled logic in OB85/OB86 rather than the CPU dropping outputs to substitute values instantly.
6. Hardware vs Software Causes
The field report raises a valid point: replacing the CPU cleared the problem, but did the cause move with the CPU, or was it environment-related? The diagnostic answer rests on two questions:
- Did the diagnostic buffer (on the failed CPU) show OB85/OB86 entries referencing a specific slot?
- Did the new CPU exhibit the same STOP after the same operating hours, or is the new CPU still running clean after 30 days?
If the new CPU runs cleanly, the cause was internal to the original CPU: MMC wear-out, firmware checksum fault, retentive memory cell exhaustion, or aging electrolytics on the backplane connector. These faults are non-reproducible on a fresh CPU with a known-good MMC.
If the new CPU also enters STOP, the cause is environment: PS 305/PS 307 sagging under load, common-mode noise on the backplane, ground loops, or a marginal PROFINET/PROFIBUS device. Replace the original CPU first to keep the line running, then troubleshoot on the bench.
7. Bench Test Procedure for the Suspect CPU
Per the field-proven suggestion in the field report, a shop test of the removed CPU is the fastest path to a verdict. Use the following procedure:
- Place the suspect CPU on a known-good rail with a known-good PS 307 (5 A or 10 A).
- Insert the original MMC, or a freshly imaged MMC with the project's
.s7p/.s7lblocks. - Toggle the mode selector to MRES for at least 3 seconds until the STOP LED blinks slowly, release, toggle once more within 3 seconds. The CPU performs a memory reset.
- Toggle to RUN. If the CPU starts and runs OB1 with an empty program for 24–48 hours, the CPU is healthy. The issue was the project, the MMC, or the I/O.
- If the CPU enters STOP during the empty OB1 run, the CPU is internally defective. Re-image the firmware via SIMATIC Automation Tool or STEP 7 to rule out a firmware issue; if the fault persists, scrap the CPU.
- Load the original program and exercise the I/O on a simulator rack (SM 374 / dummy modules) to rule out field-side faults.
The empty OB1 test is the gold standard because it eliminates every user-written cause: no programming errors, no I/O access errors, no priority class errors. Any STOP during this test is conclusively an internal CPU fault.
8. MMC, Firmware, and Retentive Memory Considerations
For S7-300 CPUs with an MMC slot (CPU 312, 314, 315-2, 317-2, 319-3; the original CPU 312 IFM / 314 IFM had integrated memory and no MMC), the Micro Memory Card is a frequent STOP source:
- MMC read failure: Event ID 0x2x0F range. The CPU cannot load the user program and drops to STOP with the STOP and SF LEDs on, the MCE (Memory Card Error) LED may blink on older firmware.
- MMC write wear: SIMATIC MMCs have a finite write endurance. Using the MMC as a recipe storage area with frequent SFC 82 / SFC 84 writes (legacy) accelerates wear. Modern practice is to use recipes in the retentive load memory area, not the MMC.
- Firmware mismatch: A newer MMC written on a CPU with firmware V3.x may not run on a CPU at V2.x. Event ID 0x2x1F signals the incompatibility.
- Password-protected MMC: Forgetting the MMC password on a CPU 317/319 leaves the CPU in STOP with a "password error" diagnostic event. MRES does not clear the MMC password; only a PG with the password can unlock it.
To re-image the MMC, insert it into a PG with an external MMC reader, then use SIMATIC Manager > S7 Memory Card > Show Properties > Erase and Format (or the corresponding TIA Portal action) and reload the project.
9. Power Supply and Backplane Diagnostics
The S7-300 power supply module is often overlooked. Measure under load, not at idle.
| PS Model | Nominal 24 V DC Input | 5 V DC Output Tolerance | 24 V DC Output Tolerance | Diagnostic Cue |
|---|---|---|---|---|
| PS 305 | 24–110 V DC | 5.0 V ± 2% | 24 V ± 5% | DC OK LED off if input < 19 V or > 132 V |
| PS 307-1B (2 A) | 120/230 V AC | 5.0 V ± 2% | 24 V ± 5% | DC 24V / DC 5V LEDs |
| PS 307-1E (5 A) | 120/230 V AC | 5.0 V ± 2% | 24 V ± 5% | DC 24V / DC 5V LEDs |
| PS 307-1K (10 A) | 120/230 V AC | 5.0 V ± 1% | 24 V ± 3% | DC 24V / DC 5V LEDs, OVT alarm |
Pull the backplane connector and inspect for greenish corrosion on the gold fingers. Re-seat every module. Confirm the shield bus is grounded at a single point per cabinet and the functional earth (FE) terminal on the PS is bonded to the cabinet PE bar.
10. Replacement vs Repair Decision Matrix
Use the following matrix to decide whether to scrap, repair, or keep the original CPU as a spare:
| Condition | Decision | Justification |
|---|---|---|
| Diagnostic buffer empty, MMC unreadable, original PG unavailable | Scrap | No forensic trail, replacement cost is low |
| Diagnostic buffer shows OB85/OB86 to specific slot, no buffer on bench test | Keep as spare | CPU is healthy; original fault was field-side |
| Diagnostic buffer shows 0x23xx internal error, fault repeats on bench | Scrap | Internal defect confirmed |
| Fault clears after firmware update and bench test passes | Return to service | Firmware was the root cause |
11. Verification Checklist After Repair
- Power the rack, observe the LED sequence: all LEDs on briefly, then only RUN should be solid green within 10 seconds on a healthy CPU with a valid project.
- Confirm
SF,BF,FRCE,MAINTare off. TheSDLED may be lit if the MMC is accessed (e.g., recipe write), but should be mostly off at steady state. - Force a restart from STEP 7 (CPU > Operating Mode > Complete Restart) and verify OB100 fires. Watch the diagnostic buffer for the restart entry.
- Simulate a rack failure by removing a dummy module from a free slot; verify OB86 fires and the CPU does not STOP (assuming OB86 is loaded).
- Monitor the diagnostic buffer for 72 hours; the buffer should be clean or contain only the routine restart entries.
12. Preventive Measures
- Load a minimal set of error OBs (
OB82, OB85, OB86, OB100, OB121, OB122) in every project, even if empty. - Keep the diagnostic buffer retention active; do not perform MRES as a recovery step without first exporting the buffer.
- Schedule the PS module for replacement every 8–10 years; electrolytic aging is the leading cause of brownouts on the backplane.
- Use original Siemens MMCs (6ES7 953-…) and avoid consumer-grade SD cards in industrial settings.
- Document the firmware version on every CPU and update SIMATIC Automation Tool inventory accordingly.
FAQ
Why does my S7-300 CPU go to STOP immediately after I select RUN?
The CPU is encountering a fault the first scan of OB1: a programming error (OB121), an I/O access error (OB122), or a priority class error (OB85). Open CPU > Module Information > Diagnostic Buffer in STEP 7 or TIA Portal; the top entry identifies the fault class, the affected OB, and the slot address. Load the corresponding error OB (OB121, OB122, OB85) to prevent immediate STOP, then correct the underlying code.
How do I read the diagnostic buffer on an S7-300 that is in STOP?
Connect a PG/PC running STEP 7 V5.6+ or TIA Portal V17+ via MPI, PROFIBUS, or PROFINET to the CPU. Navigate to CPU > Module Information > Diagnostic Buffer (TIA: Online & Diagnostics > Diagnostics buffer). The buffer survives STOP and most power cycles and contains up to 500 timestamped entries, including the STOP reason and the module / slot that triggered it.
Can a bad PROFIBUS cable or PROFINET device put the CPU in STOP?
Yes, if OB86 (rack / station failure) is not loaded in the CPU. Event IDs 0x2730, 0x2731, 0x2732, and 0x2733 in the diagnostic buffer indicate a DP master / slave or IO controller / device failure. Load OB86 to allow the CPU to continue running with a logged fault, then troubleshoot the physical layer (cable, connector, shield, device health).
Does an empty OB1 program reliably identify an internal CPU fault?
Yes. An empty OB1 removes every user-written cause: no I/O access, no BCD conversion, no indirect addressing, no priority class error. If the CPU still enters STOP after 24–48 hours running only OB1 with a known-good PS 307 and no I/O, the fault is internal (firmware, MMC, CPU hardware) and the CPU should be replaced or returned to Siemens for repair.
What is the difference between a complete restart (OB100), hot restart (OB101), and a warm restart on S7-300?
OB100 is the complete restart: all retentive data is preserved, non-retentive is cleared, OB1 starts at the beginning. OB101 is the hot restart, available only on specific CPU models (e.g., CPU 318, 319) and on PROFIBUS DP masters, resuming execution at the interrupted instruction. A warm restart (manual MRES) clears all work memory and reloads from the MMC; OB100 runs after the load. Power up by default triggers OB100 on S7-300 unless the hardware is configured for hot restart.