Affected hardware: SIMATIC S7-416-5H (6ES7 416-5HS0x-xAB0) configured as a fault-tolerant H-system (S7-400H), backed by an MC SRAM 4 MB memory card on each CPU and four ET200S IM 153-2 (6ES7 153-2AA0x-xXB0) PROFIBUS-DP stations on the standby CPU. Firmware stacks observed: CPU firmware V6.x, ET200S IM 153-2 firmware V8.x, STEP 7 V5.5 SPx with S7-400H option installed.
Problem Overview
Two SIMATIC S7-416-5H CPUs configured as a redundant H-system refuse to complete a clean redundancy take-over. The master CPU shows a steady REDF LED, while the standby CPU carries a steady REDF, a steady EXTF, and a flashing BUS1F. The standby CPU sits in STOP and will not transition to RUN, so the system runs in solo mode on the master.
After resolving the STOP condition with a memory reset (MRES), the standby CPU returns to RUN, but the redundancy link remains degraded (REDF on master, REDF on standby) and the second, third, and fourth ET200 IM 153-2 stations on the standby CPU's PROFIBUS segment light BUSF1.
A separate but related symptom appears in SIMATIC Manager: any attempt to monitor a block online is rejected with the message "The displayed block cannot be monitored because it does not match the block on the CPU. Do you want to load the displayed block on the CPU and then monitor it?"
This article provides a reproducible diagnostic sequence for the CPU side and the ET200 side, explains the relevant H-system Event IDs (notably 43D5), and gives a step-by-step MRES recovery, sync-module verification, and PROFIBUS segment recovery procedure that aligns with the SIMATIC S7-400H System Manual.
Affected Hardware and LED Meanings
The first diagnostic task is to map the lit LEDs to their physical meaning. The S7-416-5H front panel and the IM 153-2 LED set are documented in the SIMATIC S7-400 CPU Data Sheet (Equipment Manual) and the ET200S IM 153-2 Manual.
| Component | LED | State observed | Meaning |
|---|---|---|---|
| S7-416-5H Master | REDF | Steady ON | Redundancy loss / redundant link fault. Master is in solo run, no clean standby. |
| S7-416-5H Standby | REDF | Steady ON | Standby CPU cannot sync-up; cannot establish role redundancy with master. |
| S7-416-5H Standby | EXTF | Steady ON | External fault present; check diagnostic buffer for I/O, sync-module, or rack fault. |
| S7-416-5H Standby | BUS1F | Flashing | PROFIBUS-DP interface 1 (lower) fault: physical or logical link error on the standby CPU's DP master port. |
| ET200S IM 153-2 (#2, #3, #4) | BUSF1 | Steady ON | Bus fault on PROFIBUS interface 1 (DP master line); these stations are not exchanging I/O with the standby CPU. |
Reading the Diagnostic Buffer
In STEP 7 / SIMATIC Manager, select the affected CPU (right-click Target System > Diagnostics > CPU Diagnostic Buffer, or open the online view with Accessible Nodes). The diagnostic buffer is the canonical source of truth for H-system events because the LEDs alone do not order the faults.
- Open SIMATIC Manager and go online to the standby CPU (PLC > Operating Mode > Connect to Target System).
- Right-click the standby CPU object and choose PLC > Diagnostics > CPU Diagnostic Buffer.
- Export the buffer to a text file (Save As) before any MRES, because MRES on S7-400H also clears entries.
- Repeat the export on the master CPU for the same time window.
- Filter on Event IDs in the 0x4300-0x43FF range for H-system events, 0x35xx for PROFIBUS events, and 0x39xx for I/O faults.
| H-System Event ID (hex / dec) | Meaning |
|---|---|
| 0x43D0 | Redundancy link connection error |
| 0x43D1 | Sync-up aborted; standby returned to STOP |
| 0x43D2 | Loss of redundancy (one CPU is passive) |
| 0x43D5 | Redundant link not ready / synchronization module or fiber problem. This is the canonical event for the symptom pattern described above. |
| 0x43D8 | Standby CPU has left the redundant system (passivated) |
| 0x43E0-0x43EF | Sync module firmware / type mismatch |
Root Cause: Event ID 43D5 and Why the Standby CPU Stays in STOP
Event ID 43D5 is logged when the standby CPU cannot establish or maintain the redundant link with the master. In the field pattern documented in the source case, three independent causes converge to produce a 43D5 entry plus EXTF:
- Synchronization module mismatch. Both CPUs must use the same type of redundancy sync module, properly seated in the rear of the CPU rack slot. A loose or unmatched pair logs 43D5 and forces the standby into STOP to protect deterministic behavior.
- Fiber-optic link integrity. The two sync modules connect with a dedicated LC-LC fiber pair. A bent cable, contaminated connector, or mismatch (one side MM 50/125 μm, other side MM 62.5/125 μm) will surface as 43D5 plus the optical-link diagnostic counters.
- Memory card inconsistency. An MC SRAM card must be present in both CPUs, of identical order number and identical size, and the load memory must contain the same project revision. Different card sizes or one CPU running without a card logs a redundancy-related event and prevents clean sync-up.
The mode-switch MRES on the standby CPU resets the work memory, drops the corrupt link state, and allows the standby to re-attempt the sync-up. After MRES, the standby returns to RUN but REDF remains lit because the underlying cause (sync module, fiber, or memory card) has not been physically corrected. That is the moment MRES is no longer a fix; the hardware must be inspected.
Step-by-Step Recovery Procedure (MRES)
The S7-400 mode selector has four stable positions: RUN, RUN-P, STOP, and the momentary MRES. The MRES sequence for an S7-416-5H standby CPU is:
- Export the diagnostic buffer of both CPUs before any switch movement.
- Verify the mode selector on the standby CPU; it must be in
STOPbefore MRES will be recognized. - Toggle the switch to
MRESand hold until theSTOPLED changes from steady to slow blink (about 3 s), then release. - Within 1 second, toggle the switch back to
MRESand hold until theSTOPLED is steady ON again. The CPU now performs a full work-memory reset. - Release the switch; the CPU returns to
STOP. Reload the project via STEP 7 (PLC > Download) before moving the switch toRUN. - Toggle to
RUN-Pand observe:BUS1Fmust extinguish within 30 s,REDFwithin 60 s. IfREDFremains after 120 s, the redundant link is hardware-faulted and needs physical inspection.
Resolving ET200 IM 153-2 BUSF1 on the Standby Segment
After MRES brings the standby CPU back to RUN, the second, third, and fourth ET200 IM 153-2 stations retain BUSF1. The cause is not the reset itself; the reset merely removed the masking effect of the standby's STOP. Three things typically drive this secondary fault:
- PROFIBUS line topology. Verify the DP cable from the standby CPU's DP1 port is continuous and properly terminated. The last IM 153-2 must have its terminator enabled (slide switch on the module, position "ON"); all intermediate stations must be "OFF".
- Identical PROFIBUS addresses. ET200 IM 153-2 stations 2, 3, and 4 must have unique addresses set via DIL switch on the back, matching the HW Config in STEP 7. Address duplication between stations on the same segment lights BUSF1.
- Baud rate and repeater budget. If the link runs above 1.5 Mbps, confirm at most 32 stations per segment and a maximum segment length within the PROFIBUS-DP cabling guideline (table below).
| Baud rate | Max segment length (m) | Stations / segment |
|---|---|---|
| 9.6 kbps - 93.75 kbps | 1200 | 32 |
| 187.5 kbps | 1000 | 32 |
| 500 kbps | 400 | 32 |
| 1.5 Mbps | 200 | 32 |
| 3 Mbps | 100 | 32 |
| 6 Mbps | 100 | 32 |
| 12 Mbps | 100 | 32 |
To re-establish the ET200 stations:
- Open HW Config in STEP 7 and confirm the four IM 153-2 objects on the standby's DP1 master system have correct PROFIBUS addresses and firmware version assignments.
- Recompile the HW target (Station > Save and Compile) and download (PLC > Download to Target System).
- Cycle power on the affected IM 153-2 modules in descending order (4, 3, 2) to force a re-join with new parameters.
- Verify
BUSF1extinguishes within 30 s per station; the online DP diagnostics (DP Slave Diagnostics) should show Station OK.
Synchronization Modules and Fiber Links
The S7-416-5H redundancy pair communicates exclusively over the fiber pair between the two CPU redundancy control modules (sync modules) plugged into the rear of each CPU. A continuity problem on these links causes the standby to refuse RUN. The checklist is:
- Both sync modules must carry the same order number. Typical: 6ES7 960-1AA04-0XA0 (sync module, long) or 6ES7 960-1AB04-0XA0 (sync module, short version for tight rack spacing). Mixed generations are not supported.
- Both fiber cables must be LC-LC multi-mode, 50/125 μm or 62.5/125 μm. Mixing diameters halves the optical budget and produces intermittent REDF.
- Insertion loss per cable must stay below 3 dB; total link loss must stay below Siemens' specified 7.5 dB envelope.
- Tighten the LC connectors until the audible click is heard; an unclicked connector shows up as a sync-link error within minutes.
Block Mismatch and Online Monitoring Issue
The message "The displayed block cannot be monitored because it does not match the block on the CPU" indicates a checksum/time-stamp mismatch between the offline project in SIMATIC Manager and the online project on the CPU. This is a separate failure mode from the H-system redundancy, but in this case the two failures coexist because:
- The user-side offline blocks were edited in STEP 7 after the last download.
- The CPU was not reloaded after the MRES reset, so the online memory has the older revision.
To reconcile:
- In SIMATIC Manager, run PLC > Compare Blocks Online/Offline. The difference list highlights every divergent block (timestamp and/or path mismatch).
- Select Download to Target System > All Blocks (or only the differing blocks) to push the offline project onto the CPU.
- Confirm the dialog Do you want to overwrite existing blocks? with Yes. During this phase, the CPU may briefly leave RUN; recheck
BUS1Fonce online again. - Re-attempt Monitor/Modify on the block; the mismatch message should no longer appear.
Verification Procedure
After completing the recovery, verify the H-system in the order below. Each step has a concrete pass criterion.
-
Standby CPU is RUN. Mode selector at
RUN-P,RUNandIFMLEDs are steady green,STOPoff. - REDF off on both CPUs. The CPU > Operating Mode dialog in STEP 7 should show Master and Standby in correct roles with no redundancy-fault indicator.
- BUS1F off on the standby. PROFIBUS DP1 is alive; online Accessible Nodes lists all four IM 153-2 stations reachable.
- ET200 BUSF1 off. Online DP diagnostics for stations 2, 3, and 4 report Station OK with diagnostic buffer free of new entries since the recovery.
- Diagnostic buffer clean. No new Event ID in the 43D0-43DF range and no new 35xx/39xx entries for at least five minutes after sync-up.
- Block monitoring works. Open any standard block in OB1, right-click Monitor/Modify; the value/status display must come up without a re-download prompt.
- Switch-over test. With the system in redundant run, toggle the master CPU to STOP; the standby must become the new master without losing the process. Return the original master to RUN and confirm it re-attaches as standby, REDF extinguishing within 60 s.
Preventive Checklist
- Use matching MC SRAM cards on both CPUs (same MLFB, same size). Mixing FLC/FMC FLASH with SRAM is not allowed by Siemens for H-systems.
- Replace sync modules and fiber patch cords as a pair every five years, regardless of visible LED state.
- Clean LC connectors every 12 months with a proper IEC 61753 fiber cleaning pen; 80% of intermittent REDF in the field trace to contaminated ends.
- Maintain terminator discipline on the DP1 segments: terminator ON only at the physical line ends.
- Export and archive the diagnostic buffer at every shift change while REDF or BUS1F is lit; this preserves evidence for Siemens Support.
- Keep STEP 7 V5.5 with the latest HSP (Hardware Support Package) installed; older HSPs do not recognize newer IM 153-2 firmware revisions and trigger spurious BUSF1 alarms.
- Always download the project after every MRES; a project reload is required to re-establish the block checksums.
Field-Notes and Edge Cases
- Power outage during MRES: If mains loss happens between step 3 and step 6 of the MRES sequence, the SRAM card may carry an inconsistent state and the standby may continue to refuse RUN even though LEDs appear correct. Power-cycle the standby, re-format the SRAM card, reload, then re-run MRES.
- H-system with PCS 7: In PCS 7 V8.x/V9.x, do not bypass the PCS 7 > H-System > Maintenance overlay for MRES. Use the operator dialog Maintenance Override to keep the AS in solo run during the procedure; this prevents loss of OS alarming.
- CPU firmware mismatch: Two CPUs with different firmware V-vintage (for example V6.0.4 and V6.0.7) will not form a clean redundancy. Always upgrade or downgrade the pair to the same firmware revision, then verify with PLC > Module Information > Identification.
- Symptom only on cold start: If REDF and BUS1F only appear on cold start and disappear after the second warm restart, suspect the redundancy warm-up sequence, not the hardware. Reduce OB cycle load or increase the sync-up window in HW Config.
What does Event ID 43D5 actually mean on the S7-400H?
Event ID 43D5 indicates that the redundancy link between the two sync modules is not ready or has been disrupted. Typical triggers are a loose or mismatched sync module, a contaminated or bent fiber patch cord, or a memory-card size/type mismatch between the master and standby CPUs. Treat 43D5 as a redundancy-layer fault and inspect the sync hardware before reloading software.
How do I perform a memory reset on an S7-416-5H standby CPU?
Set the mode selector on the standby CPU to STOP, then toggle to MRES and hold until the STOP LED blinks (about 3 s). Release, then immediately toggle back to MRES and hold until STOP is steady again. Release the switch; the CPU completes the work-memory reset, returns to STOP, and the project must be re-downloaded from STEP 7 before RUN is attempted.
What does BUS1F on the S7-416-5H CPU actually mean?
BUS1F refers to the first PROFIBUS-DP interface. A steady BUS1F means the physical link is broken (cable, connector, or terminator). A flashing BUS1F means the link layer is up but the CPU cannot exchange I/O data with one or more slaves (configuration or address conflict). Resolve the physical layer first if BUS1F is steady, then go online with HW Config if it is flashing.
Why do three of four IM 153-2 stations show BUSF1 after the MRES reset?
The MRES cleared the masking effect of the standby's STOP but not the underlying DP1 segment fault. Most commonly the cause is a missing terminator on the new line end, an address conflict between stations, or a cabling break introduced during maintenance. Power-cycle the affected IM 153-2 stations in reverse order after confirming the HW Config matches the DIL switch settings on the modules.
How do I clear the "block cannot be monitored" error in SIMATIC Manager?
The error means the offline block in the STEP 7 project does not match the online block on the CPU. Run PLC > Compare Blocks Online/Offline, then PLC > Download to Target System > All Blocks. After the project is fully reloaded, the monitoring dialog opens without the prompt. If the message persists in the form "The symbol information of the block is invalid", the symbol table is corrupted and the program must be reloaded from the archived source.