Siemens SIMATIC S7-1500 System Manual page 335

Drive controller
Hide thumbs Also See for SIMATIC S7-1500:
Table of Contents

Advertisement

Fault reactions and startup of the F-system
The safety function requires the output of substitute values (safe state) instead of process
values for a failsafe module (passivation of the failsafe module) in the following cases:
• When the F-system is started up
• If errors are detected during safety-related communication between the F-CPU and the F-
module via the PROFIsafe safety protocol (communication error)
• If F-I/O faults or channel faults are detected (for example wire break, discrepancy error)
Detected faults are written to the diagnostic buffer of the F-CPU and communicated to the
safety program in the F-CPU.
F-modules cannot save errors as retentive data. When the system is powered down and then
restarted, any faults persisting are detected again during startup. However, you have the
option of saving faults in your safety program.
Channel faults do not trigger any diagnostic reactions or error handling for channels that
have been set to "deactivated" in STEP 7. This applies even if such a channel is affected
indirectly by a channel group fault (channel parameter "activated/deactivated").
Remedying faults in the F-system
To remedy faults in your F-system, follow the procedure described in IEC 61508-1:2010
section 7.15.2.4 and IEC 61508-2:2010 section 7.6.2.1 e.
The following steps must be performed:
1. Diagnostic and repair of the fault
2. Revalidation of the safety function
3. Recording in the service report
Fail-safe value output for F-modules
In the case of F-modules with inputs, if there is passivation, the F-system provides
substitute values (0) for the safety program instead of the process data pending at the
failsafe inputs.
In the case of F-modules with outputs, if there is passivation, the F-system transfers
substitute values (0) to the failsafe outputs instead of the output values provided by the
safety program. The output channels are de-energized. This also applies when the F-CPU goes
into STOP mode. The parameter assignment of fail-safe values is not possible.
Substitute values are used either for the relevant channel only or for all channels of the
relevant failsafe module depending on:
• The F-system used
• The type of error that occurred (F-I/O, channel or communication error)
• The F-module parameter assignment
SIMATIC Drive Controller
System Manual, 11/2023, A5E46600094-AD
WARNING
15.7 Fault reactions with failsafe components
Maintenance
333

Advertisement

Table of Contents
loading

Table of Contents