Troubleshooting SINAMICS G120 PROFIBUS Communication Faults
The SINAMICS G120 modular drive platform is widely deployed in process and conveyor applications where a SIMATIC PLC issues the speed setpoint and control words over PROFIBUS DP. The platform combines a Control Unit (CU) and a Power Module (PM) and supports the PROFIdrive profile on PN/PN-Verschnitt, PROFIBUS, and PROFINET variants. Among these, the CU240S DP, CU240E DP, CU250S DP, and CU240B-2 DP variants expose a 9-pin D-sub PROFIBUS interface and are the most common variants encountered in brownfield troubleshooting.
This reference consolidates two real-world field cases that share a common pattern: the drive reports a healthy status, no alarm is active, the motor is mechanically free, and the PLC is generating the run command — yet the motor does not turn. The root cause is almost always a layer-1 (physical) or layer-2 (PROFIBUS DP) defect rather than a parameter problem. The article documents the diagnostic sequence, the parameter set to inspect, the cable/shielding rules, and the verification procedure required to close out a no-run / bus-fault ticket without a laptop or a live connection to STARTER or TIA Portal.
1. Problem Description and Symptoms
Two SINAMICS G120 drives at a single plant site exhibited behavior that initially looked identical but had distinct root causes. Cataloging the symptoms first allows the field engineer to distinguish between them without powering on a laptop.
| Symptom | Drive A (No Run) | Drive B (Bus Fault) |
|---|---|---|
| Active alarm on BOP/IOP | None — drive reports "Ready" / "Operation enabled ready" | F01910, A08502, or A08302 depending on the master |
| PLC output | STW1 bit0 (ON/OFF1) toggles, setpoint present | PLC transitions to SF (System Fault), DP slave drops off bus |
| Motor shaft | Does not turn; replaced motor with known-good unit — same result | Does not turn; PLC already in stop |
| Mechanical | Decoupled and tested; motor is free | Not decoupled — drive never reaches enable |
| Field observation | PROFIBUS T-connector with loose shield terminations | PROFIBUS D-sub connector visibly damaged / broken pins |
The crucial diagnostic insight: when the drive displays no alarm but does not run, the problem is not in the power section, not in the motor, and rarely in the parameter set. The fault sits between the SIMATIC master and the SINAMICS slave — in the bus cable, the shield, the connector, the address switch, or the cyclic PZD word.
2. Root Cause Analysis
SINAMICS G120 drives in PROFIBUS mode receive the ON command in STW1 (Control Word 1), bit 0 and the speed setpoint in NSOLL_A (Setpoint Speed, 16-bit). Both words are embedded inside the cyclic PZD (Process Data) channel, which is mapped to PROFIBUS slots 0/1 by default on the GSD file SIEM816F.GSD (for CU240B-2 / CU240E-2) or the matching GSD for older CU240S units. The drive's own state machine transitions r0002 = 007 (Operation) only when:
- The PROFIBUS slave has joined the cyclic exchange (DP state = Data Exchange).
- STW1 bit0 (ON/OFF1) = 1, bit1 (OFF2) = 1, bit2 (OFF3) = 1, bit3 (Enable/Inhibit) = 1.
- STW1 bit6 (Setpoint Enable) = 1.
- The drive is not in a fault condition and the safety/STO chain (if used) is closed.
If r0002 is frozen at 004 (Ready) or 000 (Commissioning) even after the ON command, one of those preconditions is failing. The first field check is always the physical layer because PROFIBUS RS-485 is sensitive to shield termination, cable impedance, and stub length, and a degraded segment can hold the slave in Data-Exchange but with corrupted PZD words.
3. Diagnostic Parameters to Read from the BOP/IOP
When a laptop with STARTER or TIA Portal is not available, the basic operator panel (BOP-2) or the intelligent operator panel (IOP) attached to the Control Unit provides read-only access to the most relevant diagnostics. The parameter set below is the minimum required to triage a "no run / no fault" condition.
| Parameter | Name | Expected (Healthy Run) | Indicates |
|---|---|---|---|
| r0002 | Drive Status | 007 (Operation) or 008 (Fault active) | Top-level state machine position |
| r0021 | CO: Actual Speed (smoothed) | Tracks NSOLL_A when running | Confirms whether the speed follower is active |
| r0024 | Output Frequency (smoothed) | 0.00 Hz when stopped, ramps with setpoint when running | Confirms inverter output state |
| r0025 | Output Voltage (smoothed) | 0 V when stopped, scales with V/f or vector | Confirms modulation is enabled |
| r0050 | CO: Active Command Data Set (CDS) | 0 or 1 depending on selection | Confirms the active parameter set |
| r0052 | CO: Active Drive Data Set (DDS) | 0 or 1 | Confirms the active drive data set |
| r0054 | CO: Active Control Word 1 (STW1) | 0x047E (ON, OFF2, OFF3, Enable, Ramp enable) → 0x047F after ON | What the drive actually received from the PLC |
| r0055 | CO: Active Setpoint (NSOLL_A) | Non-zero when running commanded | What the drive thinks the speed command is |
| r0947[0] | Last Fault Code | 0 when no fault active | Latest fault number, even if cleared |
| r0968 | Status Word 1 (ZSW1) | Bit0 (Ready) = 1, Bit2 (Operation) = 1, Bit3 (Fault) = 0 | Drive-to-PLC status word |
| r2050[0] | Connector Output PZD receive word | Matches the word from the PLC | Raw incoming PROFIBUS PZD |
| r2051[0] | Internal STW1 after interconnect | Matches STW1 from PLC after BICO interconnects | End-of-chain control word |
If r0054 does not show 0x047F after the PLC issues the ON command, the drive is not receiving the correct PZD word — the issue is upstream in the PLC-HW Config mapping or the bus quality. If r0054 is correct but r0002 is still 004, the drive has rejected the command for an internal reason (missing enable signal, missing STO, missing fieldbus sign-of-life, OFF2/OFF3 active, missing coasting stop, or a non-cleared fault). Always read r0947[0..7] through r0947[7] to scan the fault history.
4. PROFIBUS Layer-1 Inspection: Cable, Connector, Shield, Termination
PROFIBUS DP uses RS-485 over a 2-wire bus with a 9-pin D-sub connector. The cable must be PROFIBUS-certified (typically violet, type A, 150 Ω characteristic impedance, 24 AWG, ≤ 1100 m at 1.5 Mbit/s to ≤ 100 m at 12 Mbit/s). Two field cases illustrate how subtle physical defects produce the symptoms in Section 1.
4.1 Shield Continuity and Drain Wire
The PROFIBUS cable shield must be bonded to the connector's metal housing at both ends, and the drain wire must be clamped inside the D-sub connector's strain-relief/ground tab. A common installation defect is to leave the shield un-terminated at one or both ends, relying only on a pigtail connection. At 1.5–12 Mbit/s this causes:
- Common-mode voltage rise on the segment, with intermittent bit errors.
- Reduced signal-to-noise margin, especially with VFD-generated EMI.
- Master diagnostics reporting CRC errors and retries — which do not surface on the drive as a fault but do corrupt the PZD receive word.
Field fix: strip the cable jacket back 25–35 mm, fold the shield braid back over the jacket, and clamp the drain wire under the metal clamp of the D-sub connector. Repeat at every T-connector, every drop, and both terminating connectors. Use 360° low-impedance bondings — never pigtails longer than 25 mm.
4.2 Connector Damage and Broken Pins
PROFIBUS D-sub connectors in industrial cabinets suffer pin fatigue, especially on pin 6 (VP, +5V terminator power) and pin 5 (DGND, terminator ground). A connector with a cracked housing can also let the shield braid touch the data pins, which shorts the bus when the master toggles the line. Symptoms include intermittent bus failures, master-reported bus faults, and PLC stop. The fix is replacement with a 6GK1500-0FC10, 6GK1500-0EA02, or equivalent Siemens PROFIBUS connector with integrated terminating resistor and diagnostic LEDs.
4.3 T-Connector Topology and Stub Length
PROFIBUS DP-V0/V1 tolerates a stub length that depends on baud rate. At 1.5 Mbit/s, the cumulative stub length on a segment should not exceed 6.6 m. A loose T-connector or a hand-made T-junction (a passive splice in the trunk) introduces a stub the original design did not account for. The correct installation uses only Siemens 6GK1500-0FC10 or 6GK1500-0EA02 PROFIBUS connectors with the trunk passing through the connector and a separate drop cable going to the device. The G120 Control Unit itself has a 9-pin D-sub that requires a connector with an incoming trunk and an outgoing trunk (or a terminating resistor if end-of-segment).
| Baud Rate | Max Trunk Length | Max Stub per Segment (cumulative) |
|---|---|---|
| 9.6–93.75 kbit/s | 1200 m | 30 m |
| 187.5 kbit/s | 1000 m | 25 m |
| 500 kbit/s | 400 m | 20 m |
| 1.5 Mbit/s | 200 m | 6.6 m |
| 3 Mbit/s | 100 m | 4 m |
| 6 Mbit/s | 100 m | 4 m |
| 12 Mbit/s | 100 m | 4 m |
4.4 Terminating Resistor
Each PROFIBUS segment must have exactly two terminating resistors — one at each physical end. The G120 Control Unit D-sub does not have an internal terminator; it must be supplied by the connector (e.g., 6GK1500-0FC10 has a switchable resistor). Verify the two physical-end connectors have the switch in the "ON" position and every middle connector has the switch in the "OFF" position. An open segment (no terminator) or a double-terminated middle causes reflections that look like intermittent faults at the master and corrupted PZD at the slave.
5. PROFIBUS Address and PLC Configuration
Each G120 PROFIBUS node must have a unique address in the range 1–126, set either by the rotary switches on the Control Unit (CU240B-2 DP, CU240E-2 DP) or via p0918. The address must match the address configured in the SIMATIC HW Config / TIA Portal device configuration. If the address conflicts with another device, the slave logs F01910 and drops off the bus.
| Parameter | Name | Notes |
|---|---|---|
| p0918 | PROFIBUS Node Address | Range 1–126, default 126 |
| p0922 | PROFIdrive Telegram Selection | 1 = Standard Telegram 1 (STW1/ZSW1 + NSOLL_A/NIST_A), 20 = SIEMENS Telegram 350, 352, 999 = free interconnection |
| p2030 | Fieldbus Interface Protocol | Set to 2 (PROFIBUS) for DP variants |
| p2040 | Fieldbus Baud Rate (display only) | Read from the master's baud rate negotiation |
| p2051[0..7] | PZD Send Word (drive → PLC) | Interconnect ZSW1, NIST_A, IAIST, MELD_NAMUR, etc. |
| p2061[0..7] | PZD Receive Word (PLC → drive) | Interconnect STW1, NSOLL_A, etc. |
| p2035 | Sign-of-Life Tolerance | Number of missed telegrams before F01910 |
If the SIMATIC master has the wrong telegram type, the PZD words are misaligned and the drive will receive, for example, the speed setpoint as the control word. The motor will not start and r0054 will read a numeric value that looks like a setpoint, not a control word. The fix is to align p0922 with the master and to re-compile the STEP 7 / TIA Portal hardware configuration.
6. STW1 Bit-by-Bit Reference
The PROFIdrive control word for the SINAMICS G120 is 16 bits. Each bit is sourced from p2051[0] and then interconnected by BICO to the drive state machine. The PLC must set all the enable bits in the same telegram cycle.
| Bit | Name | Required Value | Notes |
|---|---|---|---|
| 0 | ON / OFF1 | 1 = ON, 0 = OFF1 (ramp-down) | The primary run command |
| 1 | OFF2 | 1 = Enable, 0 = Coast stop (immediate) | Logic-inverted enable |
| 2 | OFF3 | 1 = Enable, 0 = Quick stop (ramp-down per p1135) | Logic-inverted enable |
| 3 | Enable/Inhibit Operation | 1 = Enable, 0 = Inhibit | Must be 1 to run |
| 4 | Enable Ramp Generator | 1 = Enable | Allows setpoint to ramp |
| 5 | Unfreeze Ramp Generator | 1 = Continue | 0 freezes the ramp |
| 6 | Enable Setpoint | 1 = Accept NSOLL_A | Without this, the setpoint is ignored |
| 7 | Fault Acknowledge (0→1) | Rising edge clears faults | 0→1 transition only |
| 8–9 | Reserved | 0 | |
| 10 | Control by PLC | 1 = PLC has control | Prevents HMI/local override |
| 11–15 | Direction / motor identification / reserved | Application-specific | Direction in bit 11 for some telegrams |
A common field error is the PLC programmer writing 16#047E as a static value (OFF2=1, OFF3=1, Enable=1, Enable Ramp=0, Enable Setpoint=0) and not setting bits 4 and 6. The drive sits in "Ready" indefinitely. The correct pattern is to write 16#047F (all enable bits high) and toggle bit 0 for run/stop.
7. Step-by-Step Troubleshooting Procedure
The procedure below assumes the drive displays no fault, the motor is decoupled or known-good, and the SIMATIC PLC is online. It is the field procedure when no laptop is available — only the BOP-2 / IOP and a multimeter.
- De-energize the system. Open the cabinet main disconnect, verify zero potential with a CAT-IV meter, and apply lockout/tagout per site procedure.
- Inspect the PROFIBUS D-sub connector at the G120. Look for cracked housing, bent pins, broken strain relief, or a missing shield clamp. Replace with a new 6GK1500-0FC10 connector if any defect is visible.
- Verify shield bonding. Loosen the connector, lift the strain relief, and confirm the cable's shield braid is clamped 360° and the drain wire is bonded. A pigtail longer than 25 mm is unacceptable.
- Verify the trunk topology. Confirm the segment is a daisy-chain (in-out at every node) and not a star or splice. Cumulative stub length must be within the baud-rate table in Section 4.3.
- Verify termination. Walk the bus from end to end. The first and last connector must have the terminating resistor switch in the ON position. Every connector in between must be in the OFF position. Open circuit = reflections. Double-terminated middle = reflections.
-
Verify the address. Read the DIP switch on the Control Unit or
p0918from the IOP. Cross-check with the master configuration. Duplicate address = master reports station failure. - Re-energize and observe the BOP-2. Watch the LED sequence: green (RDY) → flashing green (commissioning) → solid green (ready). The PROFIBUS LED (BF, Bus Fault) must be OFF or flashing slowly (sign-of-life present).
-
Issue the ON command from the PLC. Observe
r0002on the BOP. It must transition to 007. If it stays at 004, readr0054: if the value is 0x047F, the command arrived but the drive is not running — check enable signals, STO chain, andp0852/p1140/p1141/p1142. Ifr0054is not 0x047F, the PZD mapping or telegram type is wrong. -
Read
r0024andr0025while commanding a small setpoint (5 Hz). The output frequency must ramp and the output voltage must rise to 50–80 V at 5 Hz for a 400 V motor. Ifr0024stays 0, the drive is in the OFF2/OFF3/Enable-Inhibit state. -
Read
r0947[0..7]for fault history even when r0002 reads "Ready" — older faults may have been cleared but indicate a recurring issue (F30002 DC-link overvoltage, F30003 DC-link undervoltage, F07900 motor blocked, F07801 motor overcurrent).
8. Field-Proven Fixes from the Two Case Studies
8.1 Case 1 — Motor Not Running, No Alarm
Root cause: PROFIBUS T-connector with broken shield bonding on the trunk. The drive reported ready because the slave was in Data-Exchange and the master was sending telegrams, but the cyclic PZD words were being received with bit errors. The control word bits were arriving with intermittent corruption, so bit 0 (ON) was sometimes read as 0 even though the master was sending 1. The PLC was not in fault because the master considered the slave healthy at the layer-2 level.
Fix: Power off, remove the T-connector, re-strip the cable, reclamp the shield braid with 360° bonding at both ends of the splice, and re-install. After re-energizing, the drive responded to the ON command immediately.
8.2 Case 2 — PLC System Fault and Bus Fault
Root cause: Mechanical damage to the PROFIBUS D-sub connector at the G120. A broken pin on the connector caused intermittent shorts on the data lines. When the master tried to read the slave, the bus collision caused the master to drop the slave. The PLC transitioned to SF (System Fault) and reported a DP bus fault.
Fix: Replace the damaged connector. After replacement, the bus came up cleanly, the master registered the slave, and the ON command was accepted.
9. Common PROFIBUS Faults on the G120 — Quick Reference
| Fault / Alarm Code | Name | Likely Cause | Field Action |
|---|---|---|---|
| F01910 | Fieldbus: setpoint timeout | No PZD from master for more than p2035 cycles | Check bus cable, terminator, connector, master CPU in RUN |
| A08502 | PROFIBUS: sign-of-life failure | Bit 12 of ZSW2 toggles incorrectly | Check PLC scan time vs. PROFIBUS cycle time |
| A08302 | PROFIBUS: DP slave not found | Address mismatch, bus not connected | Verify p0918 and connector pinning |
| F08501 | PROFIBUS: node address invalid | p0918 = 0 or 127 | Set 1–126 |
| F01910 + F08501 | Combined bus failure | Cable break or short | Section the bus with a BT200 bus tester |
| F07900 | Motor blocked | Mechanical load seized, ramp too short | Decouple, ramp p1120, check load |
| F07801 | Motor overcurrent | Wrong motor data, encoder fault, cable fault | Re-run motor identification, check insulation |
| F30002 | DC-link overvoltage | Braking energy exceeds line regen capacity | Add brake resistor, lengthen p1121 |
| F30003 | DC-link undervoltage | Line dip, missing phase, weak supply | Check line quality, line reactor, fuses |
| A01910 + r0002 = 004 | Drive in ready, waiting for PZD | PLC not sending, or mapping wrong | Check HW Config PZD slot, telegram type |
10. Verification — Confirming the Drive is Healthy
After applying the fix, perform the following verification sequence to close out the ticket. All steps can be done with the BOP-2 and a multimeter; STARTER or TIA Portal is optional.
- Power on the cabinet. Confirm the G120 CU shows solid green on the RDY LED and the BF LED is OFF.
- From the BOP, navigate to r0002. Verify it reads 001 (Ready to switch on) before the PLC issues a command.
- Issue the ON command from the PLC. Verify r0002 transitions to 007 (Operation).
- Monitor r0021 (actual speed) and r0024 (output frequency). Both must ramp in proportion to the setpoint.
- Monitor r0025 (output voltage). Must rise to a value proportional to the speed (V/f mode) or to the torque demand (vector mode).
- Read r0947[0..7]. All entries should be 0 (no recent fault).
- From the master diagnostics (STEP 7 → Module Information → Diagnostic Buffer; TIA Portal → Online & Diagnostics → Diagnostic Buffer), verify the slave is reporting clean DP state with no CRC errors and no retries.
- Run the drive for 30 minutes at 50% rated speed, then at 100% rated speed. Monitor r0021, r0024, r0025 for stability and r0039 for power stage temperature. Maximum heatsink temperature per the SINAMICS G120 datasheet is 90 °C continuous (derating above).
- Capture the parameter set with STARTER or TIA Portal (Upload to PG). Save the project file for the next shift.
11. Preventive Recommendations
- Use only Siemens 6GK1500-0FC10 or 6GK1500-0EA02 PROFIBUS connectors. Avoid third-party D-sub housings without a 360° shield clamp.
- Label every PROFIBUS cable at both ends with the segment ID, source, and destination. The two field cases above were both solved by re-doing the connection that nobody had labeled.
- Route PROFIBUS cables in a separate tray, ≥ 200 mm from VFD output power cables. Cross at 90° if crossing is unavoidable. See the SINAMICS family catalog (PDF) for cabinet wiring guidelines.
- Document the bus topology on the cabinet door — a one-line drawing of the daisy-chain, including terminator positions. This is the single most useful document for the next field engineer.
- Check terminating resistors annually. The switch can vibrate out of position. A quick BT200 or PROFIBUS tester walk around the segment takes 10 minutes.
- Capture a parameter set baseline for every G120 on commissioning, and compare periodically. The
p0918,p0922,p2035, andp0852values should never drift unless the master configuration has been formally re-issued.
12. Frequently Asked Questions
Why does my SINAMICS G120 show "Ready" on the BOP but not start, with no alarm, when the PLC is sending the run command?
The drive is in r0002 = 004 because the cyclic PZD is either absent, corrupted, or mapping the wrong telegram. Check r0054: if it is not 0x047F after the ON command, the issue is upstream. Verify the PROFIBUS cable shield, terminator, and p0922 (telegram type) match the SIMATIC HW Config. Verify the PLC is sending all six enable bits (STW1 bits 0, 1, 2, 3, 4, 6) every cycle.
The PLC transitions to System Fault (SF) and reports a DP bus fault when I command the G120 to run. What is the most likely cause?
A physical-layer defect on the PROFIBUS segment — typically a damaged D-sub connector, a broken pin, a missing terminator, a shorted shield, or a duplicate address. Replace the connector, re-strip and re-clamp the shield with 360° bonding, verify terminator switches at both ends, and confirm p0918 matches the master.
Which parameters do I read from the BOP-2 to diagnose a no-run condition without a laptop?
Read r0002 (drive state), r0021 (actual speed), r0024 (output frequency), r0025 (output voltage), r0054 (active control word), r0947[0..7] (fault history), and r0968 (status word 1). If r0054 reads 0x047F and r0002 is still 004, inspect the enable chain (p0852, p1140, p1141, p1142) and the safety/STO input.
What is the correct value of the PROFIdrive control word 1 (STW1) to start the G120 over PROFIBUS?
Write 0x047F to the first PZD word: ON/OFF1=1, OFF2=1, OFF3=1, Enable Operation=1, Enable Ramp Generator=1, Continue Ramp=1, Enable Setpoint=1. The PLC must also write a non-zero value to NSOLL_A in the second PZD word. The pattern 0x047E (without enable ramp and enable setpoint) leaves the drive in r0002 = 004 indefinitely.
Can a single damaged PROFIBUS connector on one G120 take down the entire bus?
Yes. PROFIBUS DP is a single RS-485 trunk. A shorted or open connector anywhere on the segment collapses the bus for every node downstream of the fault. Use a BT200 bus tester to localize the break, and physically inspect every D-sub on the segment. Always carry spare 6GK1500-0FC10 connectors in the truck for this reason.