The S7-400 is the most powerful PLC in the family of SIMATIC controllers. It enables successful automation solutions with Totally Integrated Automation (TIA). The S7-400 is an automation platform for system solutions in production and process engineering, and it is characterized primarily by its modularity and performance reserves.
You can also find information about SIMATIC S7-400 in Catalog ST 70:
http://www.automation.siemens.com/salesmaterial-as/catalog/en/simatic_st70_chap06_english_2013.pdf
Manuals / Operating instructions
The SIMATIC S7-400 is the power PLC for the mid to high-end performance ranges.
The modular and fan-free design, high level of expandability, extensive communication and networking options, simple implementation of distributed structures, and user-friendly handling make the SIMATIC S7-400 the ideal solution even for the most demanding tasks in the mid to high-end performance ranges.
Application areas of the SIMATIC S7-400 include:
Several performance-graded CPU classes and a comprehensive range of modules with a host of user-friendly functions allow users to perform their automation tasks individually.
In the case of task expansions, the controller can be expanded at any time without significant cost by means of additional modules.
The SIMATIC S7-400 is universal in use:
In many areas of automation technology, demands are increasing all the time with regard to the availability and thus the fail-safety of the automation systems. There are areas where a plant standstill can result in extremely high costs. Here, only redundant systems can do justice to the availability requirements.
The fault-tolerant SIMATIC S7-400H meets these requirements. It continues to operate even when parts of the controller have failed due to one or more faults. The availability thus achieved makes the SIMATIC S7-400H especially suitable for the following application areas:
Ordering data
The ordering data of the components for the S7-400H can be found with the relevant modules under "S7-400/S7-400H/S7-400F/FH".
The SIMATIC S7-400F/FH fail-safe automation system is used in plants with increased safety requirements. It controls processes where immediate shutdown presents no danger to personnel or the environment. The S7-400F/FH has two basic designs:
The additional use of standard modules makes it possible to establish a fully integrated control system for a plant where non-safety related tasks and safety-related tasks co-exist. The overall plant is configured and programmed with the same standard tools.
The SIMATIC S7-400 is available in several versions:
S7-400
The S7-400 automation system is modular in design. It has a comprehensive range of modules that can be combined individually.
A system includes the following:
The following can also be used depending on requirements:
If users require more than one central controller for their applications, the S7-400 can be expanded:
Connection type |
Maximum (total) cable length |
Local link with 5-V transfer via IM 460-1 and IM 461-1 |
1.5 m |
Local link without 5-V transfer via IM 460-0 and IM 461-0 |
5 m |
Remote link via IM 460-3 and IM 461-3 |
102.25 m |
Remote link via IM 460-4 and IM 461-4 |
605 m |
The SIMATIC S7-400 has different communication options:
Process communication via PROFIBUS DP
The SIMATIC S7-400 can be connected as master with PROFIBUS DP via the integral PROFIBUS DP interface of the S7-400-CPU (optional).
The following can be connected as masters on PROFIBUS DP:
Although PG/PCs with STEP 7 or OPs are masters on the bus, they only use the PG and OP functions that also run in part via PROFIBUS DP.
The following can be connected as slaves:
Data communication via multipoint interface (MPI)
The multipoint interface (MPI) is a communication interface integrated into the CPUs of the SIMATIC S7-400.
It is used for
Data communication via CP (point-to-point)
Powerful point-to-point connections can be implemented via the CP 441 communications processors.
Data communication via CP (PROFIBUS or Industrial Ethernet)
The SIMATIC S7-400 can be connected to the PROFIBUS and Industrial Ethernet bus systems via the CP 443-x communications processors.
The following can be connected for example:
S7-400H
The SIMATIC S7-400H consists of the following components:
Central functions are always redundant in design.
I/O can be configured with normal availability and switched.
In a one-sided configuration, I/O modules are single-channel in design and are addressed by only one of the two central controllers. One-sided I/O modules can be plugged into
.
Information read in on one side is always available to both central controllers provided the device addressing the I/O is working correctly. In the event of a fault, the I/O modules of the affected central controller are out of service.
One-sided configuration is used:
In a switched configuration, I/O modules are single-channel in design but they are addressed via a redundant PROFIBUS DP by both central controllers. Switched I/O modules can only be plugged into
.
Connection to the central controllers is made via PROFIBUS DP. The switched ET 200Ms are connected to both subunits here.
The redundancy of the I/O is supported from operating system version 3.1.
Redundant I/O modules are configured redundantly in pairs. The use of redundant I/O offers maximum availability because in this way, the failure of a CPU, a PROFIBUS or a signal module is tolerated.
Configuration options
The following configurations are possible:
Suitable I/O modules
The mutually redundant modules must be of the same type and design (e.g. both centralized or both distributed). The slots are not stipulated. However, use in different stations is recommended for availability reasons. Please refer to Customer Support or the manual to see which modules can be used.
Function modules (FMs) and communications processors (CPs) can be used redundantly in two different configurations:
The redundancy of the modules is achieved in different ways here:
S7-400F/FH
A fail-safe S7-400F/FH automation system can be configured differently according to requirements:
The plant requires a fail-safe controller. Fault tolerance is not required. The following are required:
In the event of a fault, the I/O is no longer available. The fail-safe signal modules are passivated.
The plant requires a fail-safe controller. Fault tolerance is required on the CPU side. The following are required:
If the CPU, IM 153-2 or PROFIBUS DP line fails, the controller remains available. In the case of failure of the fail-safe signal modules or the ET 200M, the I/O is no longer available. The fail-safe signal modules are passivated.
The plant requires a fail-safe controller. Fault tolerance is required on the CPU side and the I/O side. The following are required:
In the event of failure of the CPU, IM 153-2 or PROFIBUS DP line, fail-safe signal modules or ET 200M, the controller remains available.
Standard modules can also be used in the S7-400F/FH automation system. These must not be used together with fail-safe modules in one ET 200M.
Safety-related and standard communication between the central controller and the ET 200M takes place via PROFIBUS DP. The specially developed PROFIBUS profile PROFIsafe allows the transmission of user data associated with the safety function within the standard data telegram. Additional hardware components, e.g. special safety buses, are not required. The necessary software is either integrated into the hardware components as an expansion, or reloaded into the CPU as a certified software block.
Use of the isolation module in the ET 200M offers the following benefits:
The isolation module is not required if safety class SIL 2 is to be achieved.
S7-400
A host of features support users in programming, commissioning and servicing the S7-400:
The SIMATIC S7-400 complies with national and international standards:
For details, refer to Manual "S7-400 Automation System S7-400 Module Specifications".
An S7-400 system can be established with a modular design and simply, ignoring slot rules. The S7-400 is characterized by rugged operation without fans in which signal modules can be connected and disconnected under power.
Its simple design makes the S7-400 flexible and service-friendly:
The CPUs and the communications processors support the following communication types:
Data communication
The SIMATIC S7-400 has different data communication mechanisms:
Networking can take place via MPI, PROFIBUS or PROFINET.
Global data (GD)
With the "Global data communication" service, networked CPUs can exchange data with each other cyclically via MPI (max. 16 GD packets, max. size of the GD packets 64 bytes per cycle). This allows, for example, one CPU to access the data/bit memories/process image of another CPU. If an S7-300 is networked, data exchange is restricted to a maximum of 22 bytes per packet. Global data communication can only take place via the MPI. Configuring takes place via the GD table in STEP 7. In the segmented CR2 mounting rack, two CPUs can communicate via the C bus using GD.
Communication functions
Communication services with S7/C7 partners can be established with system-integrated blocks.
The services are:
Communication services with S5 partners and non-Siemens devices can be established with reloadable blocks.
The services are:
In contrast to global data, communication connections must be set up for the communication functions.
Integration into the IT world
The S7-400 makes it possible to simply link the modern IT world with automation engineering. The following functions are possible via the plug-in CP 443-1 Advanced:
The S7-400 PROFINET CPUs have integral Web servers. Information can thus be read out of the S7-400 station using a standard Web browser:
Security mechanisms are available within the Web server mechanisms with the possibility of using user rights and supporting the HTTPS protocol.
The system function isochronous mode enables synchronous coupling
to the cycle of the isochronous PROFIBUS and PROFINET.
An automation solution is created that captures and processes the input signals and outputs output signals at constant intervals (constant bus cycle time). A consistent partial process image is created at the same time.
By means of constant bus cycle times and synchronous signal processing of the distributed I/O, the S7-400 ensures precisely reproducible and defined process response times.
An extensive range of components that support the isochronous mode system function is available for handling demanding tasks from the areas of motion control, measured value acquisition, high-speed controls, etc.
In distributed automation solutions, the SIMATIC S7-400 also opens up the important application area of high-speed processing operations and enables the achievement of maximum precision and reproducibility. This means increased production with optimal and constant quality.
With SIMATIC S7-400, hardware configuration changes can be made without reaction during operation of a plant. The following are possible for example:
CiR – Configuration in RUN reduces commissioning and retooling times by enabling plant expansions and conversions during the operating phase. In addition, this system functionality allows flexible response to process changes (e.g. process optimization) since the plant does not have to be re-initialized or synchronized due to hardware configuration changes.
Many input/output modules of the SIMATIC S7-400 have intelligent abilities:
Diagnostics
An intelligent diagnostics system can be used to determine whether signal acquisition (in the case of digital modules) or analog processing (in the case of analog modules) of the module is functioning fault-free. In diagnostics analysis, a distinction must be made between parameterizable and non-parameterizable diagnostics messages:
If a diagnostics message is active (e.g. "No sensor supply”), the module triggers a diagnostics interrupt (if the diagnostics message is parameterized, only after the appropriate parameterization). The CPU interrupts processing of the user program or low priority classes, and processes the relevant diagnostics interrupt block (OB 82). Process signals can be monitored via hardware interrupts and responses to changes in the signals can be triggered.
Different diagnostics messages are available depending on the module type:
Digital input/output modules |
|
Diagnostics message |
Possible fault cause |
No sensor supply |
|
No external auxiliary voltage |
|
No internal auxiliary voltage |
|
Fuse blown |
|
Incorrect parameters in module |
|
Time monitoring addressed (watchdog) |
|
EPROM fault |
|
RAM fault |
|
Hardware interrupt lost |
|
Analog input modules |
|
Diagnostics message |
Possible fault cause |
No external load voltage |
|
Configuring/parameterization errors |
|
Common mode error |
|
Wirebreak |
|
Measuring range low limit violated |
|
Measuring range high limit violated |
|
Analog output modules |
|
Diagnostics message |
Possible fault cause |
No external load voltage |
|
Configuring/parameterization errors |
|
Short-circuit to M |
|
Wirebreak |
|
Hardware interrupt
Process signals can be monitored via hardware interrupts and responses to changes in the signals can be triggered.
S7-400H
With fault-tolerant communication SIMATIC offers a new communication type with the following features:
Fault-tolerant communication is currently supported by the S7-400H (redundant and non-redundant configuration) and by PCs. On PCs, the Redconnect program package is required (see "SIMATIC NET communication systems").
Depending on availability requirements, different configuration options can be used:
The operating system of the CPU 417-4H, CPU 414-4H and CPU 412-3H executes all the necessary additional functions of the S7-400H autonomously:
Redundancy principle
The S7-400H works according to the principle of active redundancy in "hot standby" mode (reaction-free automatic switchover in the event of a fault). According to this principle, both subunits are active during fault-free operation. In the event of a fault, the intact device assumes control of the process alone.
To guarantee this transfer bumplessly, fast and reliable data exchange via the central controller link is required.
In the course of the failover, the devices automatically retain
This means both devices are always completely up-to-date and can continue control alone in the event of a fault.
For redundant operation of the I/O this results in the following:
Synchronization
For reaction-free switchover, synchronization of both subunits is necessary.
The S7-400H works with "event-drive synchronization".
This involves a synchronization operation whenever events could result in different internal states in the two subunits, e.g. in the case of
The synchronization takes place automatically by means of the operating system and can be ignored at the programming stage.
Self-test
The S7-400H executes extensive self-tests. This involves testing the following:
Every detected fault is reported.
Self-test at startup
At startup, each subunit executes all self-test functions fully.
Self-test in cyclic operation
The complete self-test is spread over several cycles. A short section of the self-test is executed per cycle so that the load on the actual controller is insignificant.
The S7-400H is programmed like an S7-400. All the STEP 7 functions available there are used.
STEP 7 V5.2 is required for programming the S7-400H.
Configuring of I/O modules
When configuring the hardware, users must specify via HW Config which modules are mutually redundant. This only requires the specification of the modules to be operated in redundant mode and the second module that is to be the "redundancy partner". In the user program, the module with the lowest address is to be accessed. The second address remains hidden from the user and programming of the control section with redundant and non-redundant I/O is identical. The only difference to non-redundant I/O are two FBs (RED_IN and RED_OUT) from the block library that are to be called at the start and at the end of the user program.
The library is integrated into STEP 7 as standard from STEP 7 V5.3.
S7-400F/FH
The S7-400F/FH meets the following safety requirements:
The safety functions of the S7-400F/FH are contained in the F program of the CPU and in the fail-safe signal modules.
The signal modules monitor output and input signals by means of discrepancy analyses and test signal injections.
The CPU checks the proper operation of the controller with regular self-tests, command tests, and logical and chronological program execution checks. In addition, the I/O is checked by means of sign-of-life requests.
If a fault is diagnosed in the system, the system is brought to a safe state.
F-Runtime license
The F-Runtime license must be loaded onto the CPU 417-4H to operate the S7-400F/FH. One license is required for each S7-400F/FH.
The S7-400F/FH is programmed in the same way as the other SIMATIC S7 systems. The user program for non-fail-safe plant sections is created with the field-proven programming tools, e.g. STEP 7.
S7 F Systems option package
The option package "S7 F Systems" is required for programming the safety-related program sections. The package contains all the necessary functions and blocks for creating the F program. The following software packages must be loaded onto the PG/PC for S7 F Systems to run:
For the F program with the safety functions, special function blocks from the F library are called up with CFC and interconnected. The use of CFC simplifies the configuring and programming of the plant and, thanks to plant-wide, uniform representation, also the acceptance test. Programmers can concentrate fully on the safety-related application without having to use additional tools.
General technical data |
|
Degree of protection |
IP20 |
Ambient temperature |
0 to 60 °C |
Relative humidity |
5 to 95%, no condensation |
Atmospheric pressure |
1080 to 795 hPa (corresponds to an altitude of -1000 m to +2,000 m) |
Electromagnetic compatibility |
|
|
According to EN 61000-6-2 |
|
According to EN 61000-6-4 |
Mechanical load |
|
|
IEC 60068-2-6 (sine) 10 to 58 Hz; constant amplitude 0.075 mm; |
|
IEC 60068-2-27 |
Information material for downloading can be found in the Internet:
http://www.automation.siemens.com/infocenter
The S7-400 is the most powerful PLC in the family of SIMATIC controllers. It enables successful automation solutions with Totally Integrated Automation (TIA). The S7-400 is an automation platform for system solutions in production and process engineering, and it is characterized primarily by its modularity and performance reserves.
You can also find information about SIMATIC S7-400 in Catalog ST 70:
http://www.automation.siemens.com/salesmaterial-as/catalog/en/simatic_st70_chap06_english_2013.pdf
Manuals / Operating instructions
The SIMATIC S7-400 is the power PLC for the mid to high-end performance ranges.
The modular and fan-free design, high level of expandability, extensive communication and networking options, simple implementation of distributed structures, and user-friendly handling make the SIMATIC S7-400 the ideal solution even for the most demanding tasks in the mid to high-end performance ranges.
Application areas of the SIMATIC S7-400 include:
Several performance-graded CPU classes and a comprehensive range of modules with a host of user-friendly functions allow users to perform their automation tasks individually.
In the case of task expansions, the controller can be expanded at any time without significant cost by means of additional modules.
The SIMATIC S7-400 is universal in use:
In many areas of automation technology, demands are increasing all the time with regard to the availability and thus the fail-safety of the automation systems. There are areas where a plant standstill can result in extremely high costs. Here, only redundant systems can do justice to the availability requirements.
The fault-tolerant SIMATIC S7-400H meets these requirements. It continues to operate even when parts of the controller have failed due to one or more faults. The availability thus achieved makes the SIMATIC S7-400H especially suitable for the following application areas:
Ordering data
The ordering data of the components for the S7-400H can be found with the relevant modules under "S7-400/S7-400H/S7-400F/FH".
The SIMATIC S7-400F/FH fail-safe automation system is used in plants with increased safety requirements. It controls processes where immediate shutdown presents no danger to personnel or the environment. The S7-400F/FH has two basic designs:
The additional use of standard modules makes it possible to establish a fully integrated control system for a plant where non-safety related tasks and safety-related tasks co-exist. The overall plant is configured and programmed with the same standard tools.
The SIMATIC S7-400 is available in several versions:
S7-400
The S7-400 automation system is modular in design. It has a comprehensive range of modules that can be combined individually.
A system includes the following:
The following can also be used depending on requirements:
If users require more than one central controller for their applications, the S7-400 can be expanded:
Connection type |
Maximum (total) cable length |
Local link with 5-V transfer via IM 460-1 and IM 461-1 |
1.5 m |
Local link without 5-V transfer via IM 460-0 and IM 461-0 |
5 m |
Remote link via IM 460-3 and IM 461-3 |
102.25 m |
Remote link via IM 460-4 and IM 461-4 |
605 m |
The SIMATIC S7-400 has different communication options:
Process communication via PROFIBUS DP
The SIMATIC S7-400 can be connected as master with PROFIBUS DP via the integral PROFIBUS DP interface of the S7-400-CPU (optional).
The following can be connected as masters on PROFIBUS DP:
Although PG/PCs with STEP 7 or OPs are masters on the bus, they only use the PG and OP functions that also run in part via PROFIBUS DP.
The following can be connected as slaves:
Data communication via multipoint interface (MPI)
The multipoint interface (MPI) is a communication interface integrated into the CPUs of the SIMATIC S7-400.
It is used for
Data communication via CP (point-to-point)
Powerful point-to-point connections can be implemented via the CP 441 communications processors.
Data communication via CP (PROFIBUS or Industrial Ethernet)
The SIMATIC S7-400 can be connected to the PROFIBUS and Industrial Ethernet bus systems via the CP 443-x communications processors.
The following can be connected for example:
S7-400H
The SIMATIC S7-400H consists of the following components:
Central functions are always redundant in design.
I/O can be configured with normal availability and switched.
In a one-sided configuration, I/O modules are single-channel in design and are addressed by only one of the two central controllers. One-sided I/O modules can be plugged into
.
Information read in on one side is always available to both central controllers provided the device addressing the I/O is working correctly. In the event of a fault, the I/O modules of the affected central controller are out of service.
One-sided configuration is used:
In a switched configuration, I/O modules are single-channel in design but they are addressed via a redundant PROFIBUS DP by both central controllers. Switched I/O modules can only be plugged into
.
Connection to the central controllers is made via PROFIBUS DP. The switched ET 200Ms are connected to both subunits here.
The redundancy of the I/O is supported from operating system version 3.1.
Redundant I/O modules are configured redundantly in pairs. The use of redundant I/O offers maximum availability because in this way, the failure of a CPU, a PROFIBUS or a signal module is tolerated.
Configuration options
The following configurations are possible:
Suitable I/O modules
The mutually redundant modules must be of the same type and design (e.g. both centralized or both distributed). The slots are not stipulated. However, use in different stations is recommended for availability reasons. Please refer to Customer Support or the manual to see which modules can be used.
Function modules (FMs) and communications processors (CPs) can be used redundantly in two different configurations:
The redundancy of the modules is achieved in different ways here:
S7-400F/FH
A fail-safe S7-400F/FH automation system can be configured differently according to requirements:
The plant requires a fail-safe controller. Fault tolerance is not required. The following are required:
In the event of a fault, the I/O is no longer available. The fail-safe signal modules are passivated.
The plant requires a fail-safe controller. Fault tolerance is required on the CPU side. The following are required:
If the CPU, IM 153-2 or PROFIBUS DP line fails, the controller remains available. In the case of failure of the fail-safe signal modules or the ET 200M, the I/O is no longer available. The fail-safe signal modules are passivated.
The plant requires a fail-safe controller. Fault tolerance is required on the CPU side and the I/O side. The following are required:
In the event of failure of the CPU, IM 153-2 or PROFIBUS DP line, fail-safe signal modules or ET 200M, the controller remains available.
Standard modules can also be used in the S7-400F/FH automation system. These must not be used together with fail-safe modules in one ET 200M.
Safety-related and standard communication between the central controller and the ET 200M takes place via PROFIBUS DP. The specially developed PROFIBUS profile PROFIsafe allows the transmission of user data associated with the safety function within the standard data telegram. Additional hardware components, e.g. special safety buses, are not required. The necessary software is either integrated into the hardware components as an expansion, or reloaded into the CPU as a certified software block.
Use of the isolation module in the ET 200M offers the following benefits:
The isolation module is not required if safety class SIL 2 is to be achieved.
S7-400
A host of features support users in programming, commissioning and servicing the S7-400:
The SIMATIC S7-400 complies with national and international standards:
For details, refer to Manual "S7-400 Automation System S7-400 Module Specifications".
An S7-400 system can be established with a modular design and simply, ignoring slot rules. The S7-400 is characterized by rugged operation without fans in which signal modules can be connected and disconnected under power.
Its simple design makes the S7-400 flexible and service-friendly:
The CPUs and the communications processors support the following communication types:
Data communication
The SIMATIC S7-400 has different data communication mechanisms:
Networking can take place via MPI, PROFIBUS or PROFINET.
Global data (GD)
With the "Global data communication" service, networked CPUs can exchange data with each other cyclically via MPI (max. 16 GD packets, max. size of the GD packets 64 bytes per cycle). This allows, for example, one CPU to access the data/bit memories/process image of another CPU. If an S7-300 is networked, data exchange is restricted to a maximum of 22 bytes per packet. Global data communication can only take place via the MPI. Configuring takes place via the GD table in STEP 7. In the segmented CR2 mounting rack, two CPUs can communicate via the C bus using GD.
Communication functions
Communication services with S7/C7 partners can be established with system-integrated blocks.
The services are:
Communication services with S5 partners and non-Siemens devices can be established with reloadable blocks.
The services are:
In contrast to global data, communication connections must be set up for the communication functions.
Integration into the IT world
The S7-400 makes it possible to simply link the modern IT world with automation engineering. The following functions are possible via the plug-in CP 443-1 Advanced:
The S7-400 PROFINET CPUs have integral Web servers. Information can thus be read out of the S7-400 station using a standard Web browser:
Security mechanisms are available within the Web server mechanisms with the possibility of using user rights and supporting the HTTPS protocol.
The system function isochronous mode enables synchronous coupling
to the cycle of the isochronous PROFIBUS and PROFINET.
An automation solution is created that captures and processes the input signals and outputs output signals at constant intervals (constant bus cycle time). A consistent partial process image is created at the same time.
By means of constant bus cycle times and synchronous signal processing of the distributed I/O, the S7-400 ensures precisely reproducible and defined process response times.
An extensive range of components that support the isochronous mode system function is available for handling demanding tasks from the areas of motion control, measured value acquisition, high-speed controls, etc.
In distributed automation solutions, the SIMATIC S7-400 also opens up the important application area of high-speed processing operations and enables the achievement of maximum precision and reproducibility. This means increased production with optimal and constant quality.
With SIMATIC S7-400, hardware configuration changes can be made without reaction during operation of a plant. The following are possible for example:
CiR – Configuration in RUN reduces commissioning and retooling times by enabling plant expansions and conversions during the operating phase. In addition, this system functionality allows flexible response to process changes (e.g. process optimization) since the plant does not have to be re-initialized or synchronized due to hardware configuration changes.
Many input/output modules of the SIMATIC S7-400 have intelligent abilities:
Diagnostics
An intelligent diagnostics system can be used to determine whether signal acquisition (in the case of digital modules) or analog processing (in the case of analog modules) of the module is functioning fault-free. In diagnostics analysis, a distinction must be made between parameterizable and non-parameterizable diagnostics messages:
If a diagnostics message is active (e.g. "No sensor supply”), the module triggers a diagnostics interrupt (if the diagnostics message is parameterized, only after the appropriate parameterization). The CPU interrupts processing of the user program or low priority classes, and processes the relevant diagnostics interrupt block (OB 82). Process signals can be monitored via hardware interrupts and responses to changes in the signals can be triggered.
Different diagnostics messages are available depending on the module type:
Digital input/output modules |
|
Diagnostics message |
Possible fault cause |
No sensor supply |
|
No external auxiliary voltage |
|
No internal auxiliary voltage |
|
Fuse blown |
|
Incorrect parameters in module |
|
Time monitoring addressed (watchdog) |
|
EPROM fault |
|
RAM fault |
|
Hardware interrupt lost |
|
Analog input modules |
|
Diagnostics message |
Possible fault cause |
No external load voltage |
|
Configuring/parameterization errors |
|
Common mode error |
|
Wirebreak |
|
Measuring range low limit violated |
|
Measuring range high limit violated |
|
Analog output modules |
|
Diagnostics message |
Possible fault cause |
No external load voltage |
|
Configuring/parameterization errors |
|
Short-circuit to M |
|
Wirebreak |
|
Hardware interrupt
Process signals can be monitored via hardware interrupts and responses to changes in the signals can be triggered.
S7-400H
With fault-tolerant communication SIMATIC offers a new communication type with the following features:
Fault-tolerant communication is currently supported by the S7-400H (redundant and non-redundant configuration) and by PCs. On PCs, the Redconnect program package is required (see "SIMATIC NET communication systems").
Depending on availability requirements, different configuration options can be used:
The operating system of the CPU 417-4H, CPU 414-4H and CPU 412-3H executes all the necessary additional functions of the S7-400H autonomously:
Redundancy principle
The S7-400H works according to the principle of active redundancy in "hot standby" mode (reaction-free automatic switchover in the event of a fault). According to this principle, both subunits are active during fault-free operation. In the event of a fault, the intact device assumes control of the process alone.
To guarantee this transfer bumplessly, fast and reliable data exchange via the central controller link is required.
In the course of the failover, the devices automatically retain
This means both devices are always completely up-to-date and can continue control alone in the event of a fault.
For redundant operation of the I/O this results in the following:
Synchronization
For reaction-free switchover, synchronization of both subunits is necessary.
The S7-400H works with "event-drive synchronization".
This involves a synchronization operation whenever events could result in different internal states in the two subunits, e.g. in the case of
The synchronization takes place automatically by means of the operating system and can be ignored at the programming stage.
Self-test
The S7-400H executes extensive self-tests. This involves testing the following:
Every detected fault is reported.
Self-test at startup
At startup, each subunit executes all self-test functions fully.
Self-test in cyclic operation
The complete self-test is spread over several cycles. A short section of the self-test is executed per cycle so that the load on the actual controller is insignificant.
The S7-400H is programmed like an S7-400. All the STEP 7 functions available there are used.
STEP 7 V5.2 is required for programming the S7-400H.
Configuring of I/O modules
When configuring the hardware, users must specify via HW Config which modules are mutually redundant. This only requires the specification of the modules to be operated in redundant mode and the second module that is to be the "redundancy partner". In the user program, the module with the lowest address is to be accessed. The second address remains hidden from the user and programming of the control section with redundant and non-redundant I/O is identical. The only difference to non-redundant I/O are two FBs (RED_IN and RED_OUT) from the block library that are to be called at the start and at the end of the user program.
The library is integrated into STEP 7 as standard from STEP 7 V5.3.
S7-400F/FH
The S7-400F/FH meets the following safety requirements:
The safety functions of the S7-400F/FH are contained in the F program of the CPU and in the fail-safe signal modules.
The signal modules monitor output and input signals by means of discrepancy analyses and test signal injections.
The CPU checks the proper operation of the controller with regular self-tests, command tests, and logical and chronological program execution checks. In addition, the I/O is checked by means of sign-of-life requests.
If a fault is diagnosed in the system, the system is brought to a safe state.
F-Runtime license
The F-Runtime license must be loaded onto the CPU 417-4H to operate the S7-400F/FH. One license is required for each S7-400F/FH.
The S7-400F/FH is programmed in the same way as the other SIMATIC S7 systems. The user program for non-fail-safe plant sections is created with the field-proven programming tools, e.g. STEP 7.
S7 F Systems option package
The option package "S7 F Systems" is required for programming the safety-related program sections. The package contains all the necessary functions and blocks for creating the F program. The following software packages must be loaded onto the PG/PC for S7 F Systems to run:
For the F program with the safety functions, special function blocks from the F library are called up with CFC and interconnected. The use of CFC simplifies the configuring and programming of the plant and, thanks to plant-wide, uniform representation, also the acceptance test. Programmers can concentrate fully on the safety-related application without having to use additional tools.
General technical data |
|
Degree of protection |
IP20 |
Ambient temperature |
0 to 60 °C |
Relative humidity |
5 to 95%, no condensation |
Atmospheric pressure |
1080 to 795 hPa (corresponds to an altitude of -1000 m to +2,000 m) |
Electromagnetic compatibility |
|
|
According to EN 61000-6-2 |
|
According to EN 61000-6-4 |
Mechanical load |
|
|
IEC 60068-2-6 (sine) 10 to 58 Hz; constant amplitude 0.075 mm; |
|
IEC 60068-2-27 |
Information material for downloading can be found in the Internet:
http://www.automation.siemens.com/infocenter