Problem Overview
An S7-400H fault-tolerant system is configured with redundant I/O on a one-sided DP slave — that is, a single ET 200M (or compatible) PROFIBUS-DP station is wired to both H-CPUs through two independent PROFIBUS segments, but only one CPU is logically the "active" reader/writer of the I/O at any given instant. The reported failure exhibits an asymmetric symptom set:
- When the system is running on CPU0 (master) and a switchover to CPU1 (reserve) is forced, the remote I/O station stops updating and outputs are cleared on both H-CPUs.
- When the system is running on CPU1 (master) and CPU0 is stopped, or its PROFIBUS cable is physically removed, the system continues to run normally with no loss of I/O.
- The I/O addresses in the user program are defined only for the CPU currently expected to act as the active partner, so any fault on the partner causes the user program to see a process-image freeze.
The asymmetry is the diagnostic fingerprint of a missing or improperly wired redundant-I/O software layer. The hardware (ET 200M dual IM 153-2, dual PROFIBUS cables, redundant power) is intact. The problem lives in the H-CPU software where the redundant signal processing is supposed to be installed.
Affected Platforms and Firmware
The configuration described in this article applies to the SIMATIC S7-400H family with two H-CPUs (CPU 412-3H / 414-4H / 416-4H / 417-4H) running in hot-standby redundancy. The redundant I/O library and FC/FB numbering referenced here corresponds to the block set delivered with the SIMATIC Fault-tolerant systems S7-400H documentation set.
| Component | Order Number (MLFB) | Minimum Firmware / Library | Notes |
|---|---|---|---|
| CPU 412-3H | 6ES7 412-3HJ14-0AB0 | Firmware V6.0.x | Hot-standby, single PROFIBUS DP port plus PN |
| CPU 414-4H | 6ES7 414-4HM14-0AB0 | Firmware V6.0.x | Two DP interfaces — required for redundant DP segments |
| CPU 416-4H | 6ES7 416-4ER05-0AB0 | Firmware V6.0.x | Two DP interfaces, hot-standby |
| CPU 417-4H | 6ES7 417-4HT14-0AB0 | Firmware V6.0.x | Top-of-range, two DP interfaces |
| ET 200M IM 153-2 | 6ES7 153-2BA02-0XB0 | Firmware V4.x or later | Pair required for one-sided redundant DP slave |
| SIMATIC H Library | Delivered with PCS 7 / STEP 7 V5.5+ | H-library accompanying S7-400H V6.0 | Source of FC 450/451 and FB 450-453 |
The authoritative reference for the redundant I/O programming model is the SIMATIC Fault-tolerant systems S7-400H (V6.0) manual, section on Redundant I/O in the one-sided DP slave, published in the Siemens Industry Online Support portal: SIMATIC Fault-tolerant systems S7-400H (V6.0) – Siemens Support.
Root Cause Analysis
The root cause of the asymmetric switchover behavior is that the user program is reading and writing the redundant I/O as if it were standard, non-redundant distributed I/O. When the active H-CPU changes, the new active CPU is not given a chance to re-take ownership of the slave channel — and even if it is, the user program has no logic to:
- Initialize the redundant channel pointers and quality codes at startup (FC 450 "RED_INIT").
- Drive a depassivation request after switchover (FC 451 "RED_DEPA").
- Read the redundant inputs through the H-library that abstracts the active/passive channel (FB 450 "RED_IN").
- Write the redundant outputs through the H-library that decides which physical channel is currently authoritative (FB 451 "RED_OUT").
- Report the redundancy state for HMI / diagnostics (FB 452 "RED_DIAG", FB 453 "RED_STATUS").
Without the RED_IN and RED_OUT abstractions, the program reads the process image of the CPU that currently owns the bus. After failover, the new active CPU is still seeing the partner CPU's old process image slot. The slave I/O is therefore not refreshed until the partner side is passivated and depassivated, and the outputs are not driven out to the new active channel.
Why the fault is asymmetric
When CPU0 is master and CPU1 is reserve, the partner physical bus access is the one that fails. If the user program is "hard-wired" to use the input/output addresses corresponding to CPU0's logical view of the slave, then any disturbance to CPU0 (Stop, PROFIBUS pull, bus fault) immediately removes the source of those I/O addresses, even though CPU1 has a perfectly good path to the same slave. Because the I/O in the program is "defined for the master" rather than for the redundant channel, the switchover never completes from a program-execution standpoint.
When CPU1 is master and CPU0 stops, the same program keeps working because the I/O addresses referenced in the program happen to be valid for the CPU currently in RUN. This is not true redundancy — it is coincidence of address selection.
Prerequisites for the Fix
Before editing the user program, confirm the following:
- Both H-CPUs are accessible online from STEP 7 (HW Config > Online).
- The redundant I/O library is available in the project: the FC 450, FC 451, FB 450, FB 451, FB 452, FB 453 blocks must be present in the S7 program of each H-CPU. They are typically installed with the PCS 7 / S7-400H optional package and reside in the Standard Library under "Redundant IO".
- OB 70, OB 72, OB 73 (I/O redundancy loss / CPU redundancy loss) are loaded on both H-CPUs so that passivation events are not treated as fatal stop conditions. OB 82 (diagnostic interrupt) must also be present.
- The ET 200M station uses a pair of IM 153-2 modules configured as a redundant DP slave in HW Config (DP slave properties > "Redundancy" tab), with a unique PROFIBUS address per IM and matching slot assignments.
- The two PROFIBUS segments (DP1, DP2) terminate at IM 153-2 #1 and IM 153-2 #2 respectively. Cables must be physically independent and routed on separate cable trays to qualify as redundant media.
Step-by-Step Resolution
Step 1 – Insert the H-library blocks
In the STEP 7 project, open the S7 program of both H-CPUs. From the Standard Library / "Redundant IO" library, copy the following blocks into each CPU's Blocks container:
| Block | Name | Function | Call Location |
|---|---|---|---|
| FC 450 | RED_INIT | Initializes the redundant I/O data structures; called once on startup | OB 100 (restart) or OB 102 (cold restart) |
| FC 451 | RED_DEPA | Requests depassivation of the standby channel | OB 72 (CPU redundancy loss), or cyclically after a switchover is detected |
| FB 450 | RED_IN | Reads the redundant input channel and provides a quality flag | OB 1 / OB 35 cyclic section that consumes process inputs |
| FB 451 | RED_OUT | Writes the redundant output channel; handles channel failover internally | OB 1 / OB 35 cyclic section that drives process outputs |
| FB 452 | RED_DIAG | Provides diagnostic information for the redundant I/O | OB 82 (diagnostic interrupt) or cyclic diagnostics task |
| FB 453 | RED_STATUS | Provides the current redundancy status (active channel, passivation state) | Anywhere a status word is needed; HMI typically polls this |
Step 2 – Configure FC 450 (RED_INIT)
FC 450 must be called in OB 100 or OB 102 with the following typical input parameters. Refer to the manual for the exact signature of the installed library version:
// OB 100 – Restart
// Initialization of redundant I/O data structures
CALL FC 450 (
CHANNEL_ID := DW#16#00000001, // 1 = first redundant channel
SLOT_LEFT := 0, // logical slot of the left (active) channel
SLOT_RIGHT := 1, // logical slot of the right (passive) channel
RET_VAL := MW 200 // return code
);
A non-zero RET_VAL after a successful warm restart indicates that the channel configuration is inconsistent with the HW Config definitions. Common values include W#16#8xxx series codes that map to "address mismatch" or "module not in redundant mode".
Step 3 – Use FB 450 (RED_IN) for input acquisition
Replace all direct peripheral input reads (for example, L PIB 256) that point to redundant I/O with FB 450 calls. A typical instance call:
// Cyclic section – read redundant input word 0
CALL FB 450, DB 450 (
CHANNEL_ID := DW#16#00000001,
PIW_START := 256, // logical start of the input range
LEN := 4, // 4 bytes / 2 words
VALUE := P#DB100.DBX 0.0 BYTE 4,
QUALITY := M 300.0, // 1 = value valid, 0 = passivated
RET_VAL := MW 202
);
The QUALITY bit must be checked before using VALUE. A QUALITY = 0 indicates that the input is currently passivated; the program should treat the value as a substitute or hold last value depending on the safety class of the process.
Step 4 – Use FB 451 (RED_OUT) for output drive
All redundant output writes must pass through FB 451 so that the H-library can decide which physical channel is currently authoritative:
// Cyclic section – drive redundant output word 0
CALL FB 451, DB 451 (
CHANNEL_ID := DW#16#00000001,
VALUE := P#DB101.DBX 0.0 BYTE 4,
PQW_START := 256, // logical start of the output range
LEN := 4,
HOLD_LAST := FALSE, // FALSE = output to 0 on passivation
RET_VAL := MW 204
);
The HOLD_LAST parameter is critical. If the process requires that outputs hold their last value during passivation (typical for heating or continuous-control loops), set HOLD_LAST = TRUE. If the process must drop outputs to a safe state (typical for E-stop logic or motor contactors), set HOLD_LAST = FALSE.
Step 5 – Drive FC 451 (RED_DEPA) on switchover
After a switchover — for example, when OB 72 (CPU redundancy loss) fires — call FC 451 to request depassivation of the channel that just became the standby side. The H-library will then coordinate the new active channel:
// OB 72 – CPU redundancy loss
CALL FC 451 (
CHANNEL_ID := DW#16#00000001,
RET_VAL := MW 206
);
Calling FC 451 too frequently is harmless; the H-library debounces. Failing to call FC 451 at all is the second most common cause of "I/O freezes on switchover" complaints.
Step 6 – Surface diagnostics via FB 452 and FB 453
FB 452 (RED_DIAG) should be called from OB 82 to map module-level diagnostic events to the H-system's redundancy state. FB 453 (RED_STATUS) can be polled from HMI to display the active channel and the passivation state of each redundant I/O channel.
Verification Procedure
After the block changes are compiled and downloaded to both H-CPUs, validate the fix in this order:
- Clean restart. Power down both racks. Power up the reserve side first, confirm OB 100 executes and FC 450 returns RET_VAL = W#16#0000. Then power up the previously active side, confirm a clean RUN-RUN link-up and a synchronized state on both CPUs (no SF, no BF on either CPU).
- Watch the I/O state. With the system in RUN-RUN synchronized, force a process value into one of the redundant inputs. The program should read the correct value via FB 450 with QUALITY = 1.
- Force a switchover (master → reserve). In STEP 7, go Online > "Switchover" on the active CPU. Verify: (a) the new active CPU's RUN LED is steady, (b) FB 450 continues to return QUALITY = 1 within two OB 1 cycles, (c) FB 451 continues to drive outputs to the process, (d) FB 453 reports the channel's active side has flipped.
- Force a switchover (reserve → master) and pull the PROFIBUS cable on the new reserve. Confirm the new active CPU continues to read and write the redundant I/O with no program-visible discontinuity.
- Pull the PROFIBUS cable on the currently active CPU. This simulates a bus fault on the active side. The H-system should perform a switchover, FC 451 should fire, the new active CPU should depassivate the channel, and the process should be served by the surviving segment without any program-visible I/O gap longer than the configured OB 1 / OB 35 cycle time.
- LED check. On both H-CPUs, the LED pattern should show RUN steady green, LINK-UP / LINKING green, and no SF or BF red. On the ET 200M, both IM 153-2 modules should show their active and standby LEDs as documented in the IM 153-2 manual.
Diagnostic Address Map for One-Sided Redundant I/O
When configured in HW Config as a redundant DP slave, the ET 200M occupies a pair of diagnostic address ranges. The following is a representative mapping for a 16-DI / 16-DO one-sided redundant station. Confirm the exact values against HW Config on the live system.
| Logical I/O | Channel A (Active IM 153-2) | Channel B (Reserve IM 153-2) | Quality Flag Bit |
|---|---|---|---|
| Inputs word 0..7 | PIW 256..271 | PIW 288..303 | M 300.0..M 300.7 |
| Outputs word 0..7 | PQW 256..271 | PQW 288..303 | — |
| Module diagnostic | Diagnostic address 2046 | Diagnostic address 2047 | OB 82 trigger |
The H-library internally selects between PIW 256 and PIW 288 depending on which IM 153-2 is currently the active side. The program only ever references the abstracted VALUE and QUALITY outputs of FB 450/451.
Common Error Patterns and How to Read Them
| Observed Symptom | Likely Cause | Corrective Action |
|---|---|---|
| I/O freezes when active CPU is disturbed; passes when reserve CPU is disturbed | Program reads PIW/PIQ directly instead of via FB 450/451 | Replace direct accesses with FB 450 / FB 451 |
| Switchover occurs, but outputs drop to 0 unexpectedly | HOLD_LAST = FALSE in FB 451 call, or the channel is being depassivated by FC 451 with no replacement value | Set HOLD_LAST appropriately; verify FC 451 is only called after a real switchover event |
| OB 72 not loaded; CPU goes to STOP on switchover | Missing OB 72 in the S7 program of one or both H-CPUs | Load OB 72 (CPU redundancy loss) on both CPUs; configure it to perform depassivation and then return |
| FC 450 returns a non-zero RET_VAL after restart | CHANNEL_ID or SLOT parameters do not match the HW Config definition of the redundant channel | Cross-check HW Config slot assignments with FC 450 input parameters; recompile and reload |
| BF (Bus Fault) LED on reserve CPU lights when active CPU is stopped | PROFIBUS cable on reserve side is broken or terminated incorrectly | Verify termination (terminator ON only on the two physical ends of each segment), check connector pin-out, check shield grounding |
| Outputs jitter / oscillate on switchover | OB 35 cycle time too long relative to process dynamics; FC 451 not called on switchover | Reduce OB 35 cycle time; call FC 451 in OB 72 |
| FB 450 returns QUALITY = 0 permanently | Channel is passivated but no depassivation request has been issued | Call FC 451 in OB 72; verify OB 82 is loaded so diagnostics are processed |
Configuration Checklist
- Both H-CPUs run matching firmware versions and synchronized configuration.
- ET 200M uses two IM 153-2 modules, each on a separate PROFIBUS segment.
- HW Config marks the ET 200M as a redundant DP slave (DP slave properties > "Activate redundancy").
- FC 450 is called in OB 100 / OB 102 on both H-CPUs.
- FB 450 is called for every redundant input group on both H-CPUs.
- FB 451 is called for every redundant output group on both H-CPUs.
- FC 451 is called in OB 72 on both H-CPUs.
- FB 452 is called in OB 82 on both H-CPUs (or its diagnostic data is collected via a periodic task).
- FB 453 is exposed to the HMI for visualization of the active / passive side.
- OB 70, OB 72, OB 73, OB 82 are loaded on both H-CPUs.
- PROFIBUS segments are physically separated (different cable trays, different power feeds).
- The user program never reads / writes the redundant I/O addresses directly outside the H-library.
Edge Cases and Field-Proven Caveats
- Asymmetric direction of I/O freeze. If the program was written for an older version of the H-library that did not include RED_IN / RED_OUT for one-sided slaves, direct PII / PIQ access was once acceptable. With firmware V6.0 and later, this is no longer the case. Do not assume legacy code is still valid — verify against the current manual.
- Mixing of redundant and non-redundant I/O on the same PROFIBUS segment. A non-redundant slave on the same physical segment does not break the redundant slave, but the bus failure of one slave does not necessarily cause a switchover of the H-CPUs. Plan the diagnostics separately.
- HOLD_LAST and the safety path. HOLD_LAST = TRUE retains the last-written output value during the brief depassivation window. For SIL-rated outputs, this is generally not acceptable; the safety path must drop the output to the safe state regardless of HOLD_LAST. Wire the safety-rated outputs through a separate non-redundant channel.
- PROFIBUS DP baud rate. 1.5 Mbps is the typical maximum for redundant one-sided DP slaves. Do not push to 12 Mbps without verifying the cable length, drop length, and shield termination of both segments — the active / reserve timing windows become very tight.
- Time stamping of passivation events. Use FB 453 + PCS 7 OS time stamping to record the active-side flip. Field engineers who skip this lose the forensic data needed to identify whether the freeze was caused by a real switchover or by a single-channel disturbance.
- Firmware mix. Do not run a CPU 414-4H V6.0 paired with a CPU 414-4H V5.x. The H-system requires symmetric firmware on both H-CPUs; otherwise, link-up will not complete and the redundant I/O will be reported as not-ready.
Standards and Reference Documents
The following official Siemens documents are the engineering references for this configuration. Verify the revision on the project documentation control system before applying changes:
- SIMATIC Fault-tolerant systems S7-400H (V6.0) – Siemens Industry Online Support — defines the FC 450/451 and FB 450–453 programming model and the one-sided DP slave hardware topology.
- SIMATIC S7-400H system manual — section on Redundant I/O, including passivation / depassivation state machine.
- ET 200M IM 153-2 manual (6ES7 153-2BA02) — wiring, addressing, and LED behavior of the redundant interface module.
- STEP 7 / S7-400H optional package release notes — confirms the exact block signatures of FC 450, FC 451, FB 450–453 for the installed library version.
FAQ
Why does my S7-400H I/O freeze on switchover from CPU0 to CPU1 but not CPU1 to CPU0?
The asymmetry is a fingerprint of a program that reads PIW/PIQ addresses that only exist on the currently active CPU. The H-library FB 450 RED_IN and FB 451 RED_OUT are missing. Once you replace the direct accesses with FB 450/451 calls and add FC 451 RED_DEPA in OB 72, the freeze on switchover will no longer depend on which CPU is master.
Which OB do I call FC 450 RED_INIT from, and how often?
Call FC 450 once at restart, in OB 100 (warm restart) or OB 102 (cold restart). Do not call it cyclically — the H-library is not designed for repeated initialization. If RET_VAL comes back non-zero, check the CHANNEL_ID and SLOT parameters against the HW Config of the redundant DP slave.
Do I need two PROFIBUS cables and two IM 153-2 modules for a one-sided redundant DP slave?
Yes. One-sided redundant means a single physical ET 200M station reachable by both H-CPUs, but the physical reachability requires two independent PROFIBUS segments, each terminated on its own IM 153-2 inside the ET 200M. A single cable or a single IM 153-2 does not provide redundancy; it provides a single point of failure.
What does OB 72 have to do with redundant I/O?
OB 72 is the CPU-redundancy-loss interrupt. It fires on the surviving CPU when a switchover is completed. The H-library expects OB 72 to call FC 451 RED_DEPA so that the newly reserved channel is properly depassivated and the new active channel is selected. If OB 72 is missing, the CPU may STOP on switchover; if FC 451 is not in OB 72, the redundant I/O will appear to freeze.
How do I monitor which side of the redundant channel is currently active?
Call FB 453 RED_STATUS and expose its output word to the HMI. The block returns the active channel identifier and the passivation state of each configured channel. In PCS 7, this is typically displayed on a redundancy overview faceplate so the operator can see immediately whether the field I/O is healthy on both sides.