Troubleshooting S7-400H Redundant I/O in One-Sided DP Slave

David Krause17 min read
S7-400SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

An S7-400H fault-tolerant system is configured with redundant I/O on a one-sided DP slave — that is, a single ET 200M (or compatible) PROFIBUS-DP station is wired to both H-CPUs through two independent PROFIBUS segments, but only one CPU is logically the "active" reader/writer of the I/O at any given instant. The reported failure exhibits an asymmetric symptom set:

  • When the system is running on CPU0 (master) and a switchover to CPU1 (reserve) is forced, the remote I/O station stops updating and outputs are cleared on both H-CPUs.
  • When the system is running on CPU1 (master) and CPU0 is stopped, or its PROFIBUS cable is physically removed, the system continues to run normally with no loss of I/O.
  • The I/O addresses in the user program are defined only for the CPU currently expected to act as the active partner, so any fault on the partner causes the user program to see a process-image freeze.

The asymmetry is the diagnostic fingerprint of a missing or improperly wired redundant-I/O software layer. The hardware (ET 200M dual IM 153-2, dual PROFIBUS cables, redundant power) is intact. The problem lives in the H-CPU software where the redundant signal processing is supposed to be installed.

Diagnostic intent of this guide: confirm the presence of the SIMATIC H-library redundant I/O blocks in the user program, verify that the passivation / depassivation state machine is being driven, and validate the PROFIBUS topology so that each CPU physically owns a deterministic path to the slave during the failover window.

Affected Platforms and Firmware

The configuration described in this article applies to the SIMATIC S7-400H family with two H-CPUs (CPU 412-3H / 414-4H / 416-4H / 417-4H) running in hot-standby redundancy. The redundant I/O library and FC/FB numbering referenced here corresponds to the block set delivered with the SIMATIC Fault-tolerant systems S7-400H documentation set.

Component Order Number (MLFB) Minimum Firmware / Library Notes
CPU 412-3H 6ES7 412-3HJ14-0AB0 Firmware V6.0.x Hot-standby, single PROFIBUS DP port plus PN
CPU 414-4H 6ES7 414-4HM14-0AB0 Firmware V6.0.x Two DP interfaces — required for redundant DP segments
CPU 416-4H 6ES7 416-4ER05-0AB0 Firmware V6.0.x Two DP interfaces, hot-standby
CPU 417-4H 6ES7 417-4HT14-0AB0 Firmware V6.0.x Top-of-range, two DP interfaces
ET 200M IM 153-2 6ES7 153-2BA02-0XB0 Firmware V4.x or later Pair required for one-sided redundant DP slave
SIMATIC H Library Delivered with PCS 7 / STEP 7 V5.5+ H-library accompanying S7-400H V6.0 Source of FC 450/451 and FB 450-453

The authoritative reference for the redundant I/O programming model is the SIMATIC Fault-tolerant systems S7-400H (V6.0) manual, section on Redundant I/O in the one-sided DP slave, published in the Siemens Industry Online Support portal: SIMATIC Fault-tolerant systems S7-400H (V6.0) – Siemens Support.

Root Cause Analysis

The root cause of the asymmetric switchover behavior is that the user program is reading and writing the redundant I/O as if it were standard, non-redundant distributed I/O. When the active H-CPU changes, the new active CPU is not given a chance to re-take ownership of the slave channel — and even if it is, the user program has no logic to:

  1. Initialize the redundant channel pointers and quality codes at startup (FC 450 "RED_INIT").
  2. Drive a depassivation request after switchover (FC 451 "RED_DEPA").
  3. Read the redundant inputs through the H-library that abstracts the active/passive channel (FB 450 "RED_IN").
  4. Write the redundant outputs through the H-library that decides which physical channel is currently authoritative (FB 451 "RED_OUT").
  5. Report the redundancy state for HMI / diagnostics (FB 452 "RED_DIAG", FB 453 "RED_STATUS").

Without the RED_IN and RED_OUT abstractions, the program reads the process image of the CPU that currently owns the bus. After failover, the new active CPU is still seeing the partner CPU's old process image slot. The slave I/O is therefore not refreshed until the partner side is passivated and depassivated, and the outputs are not driven out to the new active channel.

Why the fault is asymmetric

When CPU0 is master and CPU1 is reserve, the partner physical bus access is the one that fails. If the user program is "hard-wired" to use the input/output addresses corresponding to CPU0's logical view of the slave, then any disturbance to CPU0 (Stop, PROFIBUS pull, bus fault) immediately removes the source of those I/O addresses, even though CPU1 has a perfectly good path to the same slave. Because the I/O in the program is "defined for the master" rather than for the redundant channel, the switchover never completes from a program-execution standpoint.

When CPU1 is master and CPU0 stops, the same program keeps working because the I/O addresses referenced in the program happen to be valid for the CPU currently in RUN. This is not true redundancy — it is coincidence of address selection.

Engineering rule: in any S7-400H configuration that uses one-sided redundant I/O, the program MUST read inputs via FB 450 "RED_IN" and write outputs via FB 451 "RED_OUT". Direct PII/PIQ accesses to the redundant channel addresses are not supported across failover.

Prerequisites for the Fix

Before editing the user program, confirm the following:

  1. Both H-CPUs are accessible online from STEP 7 (HW Config > Online).
  2. The redundant I/O library is available in the project: the FC 450, FC 451, FB 450, FB 451, FB 452, FB 453 blocks must be present in the S7 program of each H-CPU. They are typically installed with the PCS 7 / S7-400H optional package and reside in the Standard Library under "Redundant IO".
  3. OB 70, OB 72, OB 73 (I/O redundancy loss / CPU redundancy loss) are loaded on both H-CPUs so that passivation events are not treated as fatal stop conditions. OB 82 (diagnostic interrupt) must also be present.
  4. The ET 200M station uses a pair of IM 153-2 modules configured as a redundant DP slave in HW Config (DP slave properties > "Redundancy" tab), with a unique PROFIBUS address per IM and matching slot assignments.
  5. The two PROFIBUS segments (DP1, DP2) terminate at IM 153-2 #1 and IM 153-2 #2 respectively. Cables must be physically independent and routed on separate cable trays to qualify as redundant media.

Step-by-Step Resolution

Step 1 – Insert the H-library blocks

In the STEP 7 project, open the S7 program of both H-CPUs. From the Standard Library / "Redundant IO" library, copy the following blocks into each CPU's Blocks container:

Block Name Function Call Location
FC 450 RED_INIT Initializes the redundant I/O data structures; called once on startup OB 100 (restart) or OB 102 (cold restart)
FC 451 RED_DEPA Requests depassivation of the standby channel OB 72 (CPU redundancy loss), or cyclically after a switchover is detected
FB 450 RED_IN Reads the redundant input channel and provides a quality flag OB 1 / OB 35 cyclic section that consumes process inputs
FB 451 RED_OUT Writes the redundant output channel; handles channel failover internally OB 1 / OB 35 cyclic section that drives process outputs
FB 452 RED_DIAG Provides diagnostic information for the redundant I/O OB 82 (diagnostic interrupt) or cyclic diagnostics task
FB 453 RED_STATUS Provides the current redundancy status (active channel, passivation state) Anywhere a status word is needed; HMI typically polls this

Step 2 – Configure FC 450 (RED_INIT)

FC 450 must be called in OB 100 or OB 102 with the following typical input parameters. Refer to the manual for the exact signature of the installed library version:

// OB 100 – Restart
// Initialization of redundant I/O data structures
CALL FC 450 (
    CHANNEL_ID    := DW#16#00000001,   // 1 = first redundant channel
    SLOT_LEFT     := 0,                // logical slot of the left (active) channel
    SLOT_RIGHT    := 1,                // logical slot of the right (passive) channel
    RET_VAL       := MW 200            // return code
);

A non-zero RET_VAL after a successful warm restart indicates that the channel configuration is inconsistent with the HW Config definitions. Common values include W#16#8xxx series codes that map to "address mismatch" or "module not in redundant mode".

Step 3 – Use FB 450 (RED_IN) for input acquisition

Replace all direct peripheral input reads (for example, L PIB 256) that point to redundant I/O with FB 450 calls. A typical instance call:

// Cyclic section – read redundant input word 0
CALL FB 450, DB 450 (
    CHANNEL_ID    := DW#16#00000001,
    PIW_START     := 256,              // logical start of the input range
    LEN           := 4,                // 4 bytes / 2 words
    VALUE         := P#DB100.DBX 0.0 BYTE 4,
    QUALITY       := M 300.0,          // 1 = value valid, 0 = passivated
    RET_VAL       := MW 202
);

The QUALITY bit must be checked before using VALUE. A QUALITY = 0 indicates that the input is currently passivated; the program should treat the value as a substitute or hold last value depending on the safety class of the process.

Step 4 – Use FB 451 (RED_OUT) for output drive

All redundant output writes must pass through FB 451 so that the H-library can decide which physical channel is currently authoritative:

// Cyclic section – drive redundant output word 0
CALL FB 451, DB 451 (
    CHANNEL_ID    := DW#16#00000001,
    VALUE         := P#DB101.DBX 0.0 BYTE 4,
    PQW_START     := 256,              // logical start of the output range
    LEN           := 4,
    HOLD_LAST     := FALSE,            // FALSE = output to 0 on passivation
    RET_VAL       := MW 204
);

The HOLD_LAST parameter is critical. If the process requires that outputs hold their last value during passivation (typical for heating or continuous-control loops), set HOLD_LAST = TRUE. If the process must drop outputs to a safe state (typical for E-stop logic or motor contactors), set HOLD_LAST = FALSE.

Step 5 – Drive FC 451 (RED_DEPA) on switchover

After a switchover — for example, when OB 72 (CPU redundancy loss) fires — call FC 451 to request depassivation of the channel that just became the standby side. The H-library will then coordinate the new active channel:

// OB 72 – CPU redundancy loss
CALL FC 451 (
    CHANNEL_ID    := DW#16#00000001,
    RET_VAL       := MW 206
);

Calling FC 451 too frequently is harmless; the H-library debounces. Failing to call FC 451 at all is the second most common cause of "I/O freezes on switchover" complaints.

Step 6 – Surface diagnostics via FB 452 and FB 453

FB 452 (RED_DIAG) should be called from OB 82 to map module-level diagnostic events to the H-system's redundancy state. FB 453 (RED_STATUS) can be polled from HMI to display the active channel and the passivation state of each redundant I/O channel.

Verification Procedure

After the block changes are compiled and downloaded to both H-CPUs, validate the fix in this order:

  1. Clean restart. Power down both racks. Power up the reserve side first, confirm OB 100 executes and FC 450 returns RET_VAL = W#16#0000. Then power up the previously active side, confirm a clean RUN-RUN link-up and a synchronized state on both CPUs (no SF, no BF on either CPU).
  2. Watch the I/O state. With the system in RUN-RUN synchronized, force a process value into one of the redundant inputs. The program should read the correct value via FB 450 with QUALITY = 1.
  3. Force a switchover (master → reserve). In STEP 7, go Online > "Switchover" on the active CPU. Verify: (a) the new active CPU's RUN LED is steady, (b) FB 450 continues to return QUALITY = 1 within two OB 1 cycles, (c) FB 451 continues to drive outputs to the process, (d) FB 453 reports the channel's active side has flipped.
  4. Force a switchover (reserve → master) and pull the PROFIBUS cable on the new reserve. Confirm the new active CPU continues to read and write the redundant I/O with no program-visible discontinuity.
  5. Pull the PROFIBUS cable on the currently active CPU. This simulates a bus fault on the active side. The H-system should perform a switchover, FC 451 should fire, the new active CPU should depassivate the channel, and the process should be served by the surviving segment without any program-visible I/O gap longer than the configured OB 1 / OB 35 cycle time.
  6. LED check. On both H-CPUs, the LED pattern should show RUN steady green, LINK-UP / LINKING green, and no SF or BF red. On the ET 200M, both IM 153-2 modules should show their active and standby LEDs as documented in the IM 153-2 manual.

Diagnostic Address Map for One-Sided Redundant I/O

When configured in HW Config as a redundant DP slave, the ET 200M occupies a pair of diagnostic address ranges. The following is a representative mapping for a 16-DI / 16-DO one-sided redundant station. Confirm the exact values against HW Config on the live system.

Logical I/O Channel A (Active IM 153-2) Channel B (Reserve IM 153-2) Quality Flag Bit
Inputs word 0..7 PIW 256..271 PIW 288..303 M 300.0..M 300.7
Outputs word 0..7 PQW 256..271 PQW 288..303 —
Module diagnostic Diagnostic address 2046 Diagnostic address 2047 OB 82 trigger

The H-library internally selects between PIW 256 and PIW 288 depending on which IM 153-2 is currently the active side. The program only ever references the abstracted VALUE and QUALITY outputs of FB 450/451.

Common Error Patterns and How to Read Them

Observed Symptom Likely Cause Corrective Action
I/O freezes when active CPU is disturbed; passes when reserve CPU is disturbed Program reads PIW/PIQ directly instead of via FB 450/451 Replace direct accesses with FB 450 / FB 451
Switchover occurs, but outputs drop to 0 unexpectedly HOLD_LAST = FALSE in FB 451 call, or the channel is being depassivated by FC 451 with no replacement value Set HOLD_LAST appropriately; verify FC 451 is only called after a real switchover event
OB 72 not loaded; CPU goes to STOP on switchover Missing OB 72 in the S7 program of one or both H-CPUs Load OB 72 (CPU redundancy loss) on both CPUs; configure it to perform depassivation and then return
FC 450 returns a non-zero RET_VAL after restart CHANNEL_ID or SLOT parameters do not match the HW Config definition of the redundant channel Cross-check HW Config slot assignments with FC 450 input parameters; recompile and reload
BF (Bus Fault) LED on reserve CPU lights when active CPU is stopped PROFIBUS cable on reserve side is broken or terminated incorrectly Verify termination (terminator ON only on the two physical ends of each segment), check connector pin-out, check shield grounding
Outputs jitter / oscillate on switchover OB 35 cycle time too long relative to process dynamics; FC 451 not called on switchover Reduce OB 35 cycle time; call FC 451 in OB 72
FB 450 returns QUALITY = 0 permanently Channel is passivated but no depassivation request has been issued Call FC 451 in OB 72; verify OB 82 is loaded so diagnostics are processed

Configuration Checklist

  • Both H-CPUs run matching firmware versions and synchronized configuration.
  • ET 200M uses two IM 153-2 modules, each on a separate PROFIBUS segment.
  • HW Config marks the ET 200M as a redundant DP slave (DP slave properties > "Activate redundancy").
  • FC 450 is called in OB 100 / OB 102 on both H-CPUs.
  • FB 450 is called for every redundant input group on both H-CPUs.
  • FB 451 is called for every redundant output group on both H-CPUs.
  • FC 451 is called in OB 72 on both H-CPUs.
  • FB 452 is called in OB 82 on both H-CPUs (or its diagnostic data is collected via a periodic task).
  • FB 453 is exposed to the HMI for visualization of the active / passive side.
  • OB 70, OB 72, OB 73, OB 82 are loaded on both H-CPUs.
  • PROFIBUS segments are physically separated (different cable trays, different power feeds).
  • The user program never reads / writes the redundant I/O addresses directly outside the H-library.

Edge Cases and Field-Proven Caveats

  • Asymmetric direction of I/O freeze. If the program was written for an older version of the H-library that did not include RED_IN / RED_OUT for one-sided slaves, direct PII / PIQ access was once acceptable. With firmware V6.0 and later, this is no longer the case. Do not assume legacy code is still valid — verify against the current manual.
  • Mixing of redundant and non-redundant I/O on the same PROFIBUS segment. A non-redundant slave on the same physical segment does not break the redundant slave, but the bus failure of one slave does not necessarily cause a switchover of the H-CPUs. Plan the diagnostics separately.
  • HOLD_LAST and the safety path. HOLD_LAST = TRUE retains the last-written output value during the brief depassivation window. For SIL-rated outputs, this is generally not acceptable; the safety path must drop the output to the safe state regardless of HOLD_LAST. Wire the safety-rated outputs through a separate non-redundant channel.
  • PROFIBUS DP baud rate. 1.5 Mbps is the typical maximum for redundant one-sided DP slaves. Do not push to 12 Mbps without verifying the cable length, drop length, and shield termination of both segments — the active / reserve timing windows become very tight.
  • Time stamping of passivation events. Use FB 453 + PCS 7 OS time stamping to record the active-side flip. Field engineers who skip this lose the forensic data needed to identify whether the freeze was caused by a real switchover or by a single-channel disturbance.
  • Firmware mix. Do not run a CPU 414-4H V6.0 paired with a CPU 414-4H V5.x. The H-system requires symmetric firmware on both H-CPUs; otherwise, link-up will not complete and the redundant I/O will be reported as not-ready.

Standards and Reference Documents

The following official Siemens documents are the engineering references for this configuration. Verify the revision on the project documentation control system before applying changes:

  • SIMATIC Fault-tolerant systems S7-400H (V6.0) – Siemens Industry Online Support — defines the FC 450/451 and FB 450–453 programming model and the one-sided DP slave hardware topology.
  • SIMATIC S7-400H system manual — section on Redundant I/O, including passivation / depassivation state machine.
  • ET 200M IM 153-2 manual (6ES7 153-2BA02) — wiring, addressing, and LED behavior of the redundant interface module.
  • STEP 7 / S7-400H optional package release notes — confirms the exact block signatures of FC 450, FC 451, FB 450–453 for the installed library version.
Safety notice: any change to a redundant I/O program on a running process must be preceded by a Management of Change review, an LOTO of the affected outputs, and a documented step-by-step rollback plan. The configuration changes described here can affect which physical channel is driving the process during a switchover. Always bench-test with the SIMATIC S7-PLCSIM H-system simulation before touching a live process.

FAQ

Why does my S7-400H I/O freeze on switchover from CPU0 to CPU1 but not CPU1 to CPU0?

The asymmetry is a fingerprint of a program that reads PIW/PIQ addresses that only exist on the currently active CPU. The H-library FB 450 RED_IN and FB 451 RED_OUT are missing. Once you replace the direct accesses with FB 450/451 calls and add FC 451 RED_DEPA in OB 72, the freeze on switchover will no longer depend on which CPU is master.

Which OB do I call FC 450 RED_INIT from, and how often?

Call FC 450 once at restart, in OB 100 (warm restart) or OB 102 (cold restart). Do not call it cyclically — the H-library is not designed for repeated initialization. If RET_VAL comes back non-zero, check the CHANNEL_ID and SLOT parameters against the HW Config of the redundant DP slave.

Do I need two PROFIBUS cables and two IM 153-2 modules for a one-sided redundant DP slave?

Yes. One-sided redundant means a single physical ET 200M station reachable by both H-CPUs, but the physical reachability requires two independent PROFIBUS segments, each terminated on its own IM 153-2 inside the ET 200M. A single cable or a single IM 153-2 does not provide redundancy; it provides a single point of failure.

What does OB 72 have to do with redundant I/O?

OB 72 is the CPU-redundancy-loss interrupt. It fires on the surviving CPU when a switchover is completed. The H-library expects OB 72 to call FC 451 RED_DEPA so that the newly reserved channel is properly depassivated and the new active channel is selected. If OB 72 is missing, the CPU may STOP on switchover; if FC 451 is not in OB 72, the redundant I/O will appear to freeze.

How do I monitor which side of the redundant channel is currently active?

Call FB 453 RED_STATUS and expose its output word to the HMI. The block returns the active channel identifier and the passivation state of each configured channel. In PCS 7, this is typically displayed on a redundancy overview faceplate so the operator can see immediately whether the field I/O is healthy on both sides.

Back to blog