Академический Документы
Профессиональный Документы
Культура Документы
Preface 1
Configuration Options 3
ET 200S Configuration and Parameter
Assignment 4
Distributed I/O System
Address Assignment and
Fail-Safe Modules Installation 5
Diagnostics 7
The following supplement is part of this documentation:
Appendices
Dimension Drawings 10
Response Times 12
Glossary 13
Index
This manual is part of the documentation
packages with the order numbers:
6ES7988-8FA10-8BA0
6ES7988-8FB10-8BA0
Edition 03/2002
A5E00103686-01
Safety Guidelines
This manual contains notices that you should observe to ensure your own personal safety, as well as to
protect the product and connected equipment from damage. These notices are highlighted in the manual by
a warning triangle and are marked as follows according to the level of danger:
! Safety Note
Contains important information relating to approval and safety-related use of a product.
! Danger
Indicates that death, severe physical injury, or substantial property damage will result if proper
precautions are not taken.
! Warning
Indicates that death, severe physical injury, or substantial property damage can result if proper
precautions are not taken.
! Caution
Indicates that minor physical injury or property damage can result if proper precautions are not taken.
Caution
Indicates that property damage can result if proper precautions are not taken.
Notice
Indicates important information relating to the product or draws special attention to part of the
documentation.
Qualified Personnel
This device/system may only be set up and operated by qualified personnel. Qualified personnel are
defined as persons who are authorized to commission, to ground, and to tag circuits, equipment, and
systems in accordance with established safety practices and standards.
Proper Use
Note the following:
! Warning
This device and its components may only be used for the applications described in the catalog or the
technical description, and only in connection with devices or components from other manufacturers
which have been approved or recommended by Siemens.
This product can only function correctly and safely if it is transported, stored, set up, and installed
correctly, and operated and maintained as recommended.
Trademarks
SIMATIC®, SIMATIC HMI®, and SIMATIC NET® are trademarks of Siemens AG.
Other names in this publication might be trademarks, the use of which by third parties for their own purposes
may violate the rights of the registered holder.
Siemens AG
Bereich Automation and Drives
Geschaeftsgebiet Industrial Automation Systems ©Siemens AG 2002
Postfach 4848, D- 90327 Nuernberg Technical data subject to change.
Siemens Aktiengesellschaft A5E00103686
Contents
1 Preface
2 Product Overview
2.1 Introduction ....................................................................................................... 2-1
2.2 Using ET 200S Fail-Safe Modules ................................................................... 2-2
2.3 Step-by-Step Guide to Commissioning ET 200S
with Fail-Safe Modules on PROFIBUS-DP....................................................... 2-5
3 Configuration Options
3.1 Introduction ....................................................................................................... 3-1
3.2 Configuring ET 200S with Fail-Safe Modules................................................... 3-2
3.3 Assigning Modules of an ET 200S ................................................................... 3-4
3.4 Maximum Number of Connectable Modules/Maximum Configuration ............. 3-6
4 Configuration and Parameter Assignment
9 Fail-Safe Modules
9.1 Introduction ....................................................................................................... 9-1
9.2 PM-E F 24 VDC PROFIsafe Power Module ..................................................... 9-2
9.2.1 Diagnostic Functions of PM-E F 24 VDC PROFIsafe Power Module ............. 9-9
9.2.2 Technical Specifications for PM-E F 24 VDC PROFIsafe Power Module..... 9-12
9.3 4/8 F-DI 24 VDC PROFIsafe Digital Electronic Module ................................. 9-16
9.1.1 Applications for 4/8 F-DI 24 VDC PROFIsafe Digital Electronic Module........ 9-23
9.1.2 Application 1: Safety Mode AK4/SIL2/Category 3.......................................... 9-25
9.1.3 Application 2: Safety Mode AK6/SIL3/Category 3.......................................... 9-27
9.1.4 Application 3: Safety Mode AK6/SIL3/Category 4.......................................... 9-35
9.1.5 Diagnostic Functions of the EM 4/8 F-DI 24 VDC PROFIsafe ....................... 9-39
9.1.6 Technical Specifications for the EM 4/8 F-DI 24 VDC PROFIsafe................. 9-41
9.4 4 F-DO 24 VDC/2 A PROFIsafe Digital Electronic Module ............................ 9-45
9.4.1 Diagnostic Functions of the EM 4 F-DO 24 VDC/2 A PROFIsafe
Digital Electronic Module ................................................................................ 9-51
9.4.2 Technical Specifications for EM F-DO 24 VDC/2 A PROFIsafe..................... 9-54
10 Dimension Drawings
12 Response Times
13 Glossary
Index
Approvals
ET 200S complies with the requirements and criteria of IEC 61131-2 and the
requirements for the CE label. ET 200S has earned CSA, UL, and FM approvals. In
addition, ET 200S fail-safe modules are certified for use in safety mode up to the
following levels:
· Safety class SIL3 (Safety Integrity Level) in accordance with IEC 61508
· Requirements class (AK) 6 in accordance with DIN V 19250 (DIN V VDE 0801)
· Category 4 in accordance with EN 954-1
When working with ET 200S fail-safe modules, you will need to consult the
supplementary documentation presented below according to your particular
application.
You can obtain the entire SIMATIC S7 documentation set in the SIMATIC S7
collection on CD-ROM.
Guide
This manual describes the fail-safe modules of the ET 200S distributed I/O system.
It consists of instructive sections and reference sections (technical specifications
and appendices).
This manual presents the following basic aspects of fail-safe modules:
· Design and use
· Configuration and parameter assignment
· Addressing, assembly, and wiring
· Diagnostic assessment
· Technical specifications
· Order numbers
Conventions
In this manual, the terms "safety engineering" and "fail-safe engineering" are used
synonymously.
The same applies to the terms "fail-safe" and "F-".
Additional Support
If you have any additional questions about the use of products presented in this
manual, contact your local Siemens representative:
http://www.ad.siemens.de/partner
Training Center
We offer courses to help you get started with the S7 automation system. Contact
your regional training center or the central training center in Nuremberg (90327),
Federal Republic of Germany.
Telephone: +49 (911) 895-3200
http://www.sitrain.com
H/F Competence Center
The H/F Competence Center in Nuremberg offers special workshops on SIMATIC
S7 fail-safe and redundant automation systems. The H/F Competence Center can
also provide assistance with onsite configuration, commissioning, and
troubleshooting.
Telephone: +49 (911) 895-4759
Fax: +49 (911) 895-5193
For questions about workshops, etc., contact:
hf-cc@nbgm.siemens.de
For Safety Integrated questions (system, wiring, etc.), contact:
cocsi@nbgm.siemens.de
Nuremberg
Nürnberg
Johnson City
Singapore
Singapur
SIMATIC Hotline
2.1 Introduction
Overview
This chapter provides information about the following topics:
· ET 200S distributed I/O system with fail-safe modules and its place in
SIMATIC S7 fail-safe automation systems.
· Components comprising the ET 200S distributed I/O system with fail-safe
modules.
· Steps to be performed, from selecting F-modules to commissioning ET 200S
on PROFIBUS-DP.
Applicable DP Masters
You can use the following fail-safe DP masters for ET 200S with fail-safe modules:
· S7-300F automation system with F-capable CPU, such as CPU 315F-2 DP
The fail-safe DP master exchanges safety-related and non-safety-related data with
fail-safe and standard ET 200S modules.
S7-300F ET 200M
Automation system
Fail-safe signal
modules
Fail-safe
modules
PROFIBUS-DP
ET 200S
ET 200S
Note
You can use S7-300 fail-safe signal modules either in an ET 200M or centrally,
that is, in a rack next to the F-CPU. You can find a description of the various
configuration options in the system description Safety Engineering in
SIMATIC S7.
Introduction
In the following table, you will find all the important steps you must perform to
commission ET 200S distributed I/O systems with fail-safe modules as DP slaves
on PROFIBUS-DP.
Note
You must configure and assign parameters to the F-modules in STEP 7 before
mounting them.
This is required because the PROFIsafe addresses of F-modules are assigned
automatically by STEP 7. You must set these PROFIsafe addresses on each
F-module by means of switches before mounting the module.
3.1 Introduction
Overview
This chapter provides information about the following topics:
· Fail-safe modules that can be used to configure an ET 200S distributed
I/O system
· Terminals, F-power modules, and F-electronic modules that can be used
together
· Number of fail-safe modules that can be used per ET 200S
· Maximum configuration per voltage group
Introduction
You can configure ET 200S distributed I/O systems with standard and fail-safe
modules. This chapter present an example configuration.
Terminal module
Fail-safe modules
Safety Note
! Note that F-DI modules and F-DO modules cannot be combined with standard
DI/DO/FM modules within a voltage group.
Introduction
This section presents the following module assignments for ET 200S:
· F-power modules to terminal modules
· F-electronic modules to terminal modules
· Power modules to electronic modules
Table 3-3 Assigning Power Modules to Electronic Modules and Safety Classes
Safety Note
! Note that F-DI modules and F-DO modules cannot be combined with standard
DI/DO/FM modules within a voltage group.
Example
In the following example, modules with a total parameter length of 219 bytes have
been used in an ET 200S. This means that 25 bytes are still available for inserting
additional modules.
Number of 1 +1 +5 +2 = 9 modules
Modules/M IM 151 PM-E 24 F-DI F-DO
odule Type VDC/120/230 VAC modules* modules*
Parameter 26 bytes + 3 bytes + 150 bytes + 40 bytes = 219 bytes
Length
* Five F-DI moduIes provide: 20 SIL3 inputs or 40 SIL2 inputs
Two F-DO modules provide: 8 SIL2/SIL3 outputs
Requirements
The following optional package must be installed in STEP 7 to configure and
assign parameters to ET 200S fail-safe modules in S7-300F:
· S7 Distributed Safety, Version V 5.1 or higher
Configuration
Follow the usual procedure with STEP 7 HW Config to configure fail-safe modules
(in the same way as standard ET 200S modules).
Introduction
Before installing fail-safe modules, you must set the PROFIsafe address on each
F-module.
PROFIsafe Address
Every fail-safe module has its own PROFIsafe address which it uses to send safety
message frames to the F-CPU and to receive them from the F-CPU.
Note
Fail-safe modules in ET 200S can only be used in safety mode.
Example:Address 1018
9 8 7 6 54 3 2 1 0
ON
512 OFF
256
128
64
32
16
8
4
2
1
Figure5-1 Example for Setting the Address Switch (DIL Switch)
Safety Note
! Ensure that the address switch setting on the module matches the PROFIsafe
address in STEP 7 HW Config.
Table 5-1 Address Areas for Fail-Safe Modules in the Target F-System
OB0 OB1 OB2 OB3 OB4 OB5 OB6 OB7 OB8 OB9 OB10 OB11 OB12 OB13 OB14 OB15 OB16 OB17 OB18
* Allocation of PM-E F corresponds to an F-DO module
Mounting Dimensions
Note that fail-safe modules are 30 mm wide (twice as wide as standard ET 200S
modules). Otherwise, information provided in the ET 200S Distributed I/O System
manual is applicable.
6.1 Introduction
Overview
This chapter presents special features involved in wiring and fitting fail-safe
modules. Information on this subject that applies to both ET 200S with fail-safe
modules and ET 200S with standard modules can be found in the ET 200S
Distributed I/O System manual.
Warning
! Fail-safe modules must be operated with safe functional extra low voltage. This
means that these modules, even in the event of an fault, can only have a
maximum voltage of Um. The following applies for all fail-safe modules:
Um < 60.0 V
You can find additional information about safe functional extra low voltage, for
example, in the data sheets of the applicable power supplies.
All components of the system that are capable of supplying electrical energy in any
form must satisfy this requirement.
Each additional circuit (24 VDC) implemented must have a safe functional extra
low voltage. Refer to the relevant data sheets or contact the manufacturer for this
information.
Note, too, that sensors and actuators having an external power supply can be
connected to F-modules. Ensure that a safe functional extra low voltage is used
here, as well. The process signal of a 24 VDC digital module must not exceed a
fault voltage of Um in the event of a fault.
Warning
! All voltage sources (such as 24 VDC internal load voltage power supplies, 24
VDC external load voltage power supplies, and 5 VDC bus voltages) must be
electrically connected to prevent voltage additions from occurring in individual
voltage sources, even in the event of voltage differences. Such voltage additions
could cause fault voltage Um to be exceeded. Ensure that there is sufficient line
cross section for the electrical connection, in accordance with the ET 200S
configuration guidelines (see ET 200S Distributed I/O System manual).
Note
You must use only power packs or power supplies (230 VAC --> 24 VDC) with a
power failure ride-through of at least 20 ms to comply with NAMUR
recommendation NE 21, IEC 61131-2, and EN 298. The following power supply
board components are available:
S7-400:
· 6ES7407-0KA01-0AA0 for 10 A
· 6ES7407-0KR00-0AA0 for 10 A
S7-300:
· 6ES7307-1BA00-0AA0 for 2 A
· 6ES7307-1EA00-0AA0 for 5 A
· 6ES7307-1KA00-0AA0 for 10 A
These requirements also apply, of course, to power packs and power supplies
that do not have an S7-300 or S7-400 configuration.
Mounting Rails
Only 35 x 15 mm zinc-plated mounting rails in accordance with EN 50022 can be
used for installing ET 200S with fail-safe modules. Mounting rails with the following
order numbers, for example, comply with this requirement:
· 6ES5710-8MA11
· 6ES5710-8MA21
· 6ES5710-8MA31
· 6ES5710-8MA41
Note
Note that replacing fail-safe modules in ET 200S during operation can cause a
communication error in the F-CPU.
You must acknowledge a communication error in your safety program (see S7
Distributed Safety, Configuring and Programming manual).
If the communication error is not acknowledged, the useful data of the F-DO
modules remain passivated (outputs at "0").
The inputs forward the current useful data to the safety program.
Safety Note
! The use of sensors and actuators is outside of our sphere of influence. We have
equipped our electronics with such safety engineering features as to leave 85%
of the maximum permissible probability of hazardous faults for sensors and
actuators up to you. (This corresponds to the recommended load division in
safety engineering between sensing devices, actuating devices, and electronic
switching for input, processing, and output).
Note, therefore, that instrumentation with sensors and accouters bears a
considerable safety responsibility. Consider, too, that sensors and actuators do
not generally withstand proof-test intervals of 10 years (the interval for an external
function test according to IEC 61508) without considerable loss of safety.
The probability of hazardous faults and the rate of occurrence of hazardous faults
of a safety function must comply with an upper limit determined by a safety
integrity level (SIL). You will find a listing of values achieved by F-modules under
"Fail-Safe Performance Characteristics" in the technical specifications for F-
modules in Chapter 9.
Safety Note
! In order to guarantee accurate detection of the sensor signal by the F-DI module,
you must ensure that the sensor signals have a particular minimum duration.
The following table presents the minimum duration of sensor signals for the F-DI
module, which depends on the short-circuit test parameter and the input delay in
STEP 7 (see Section 9.3).
Table 6-2 Minimum Duration of Input Signals for Accurate Detection by the F-DI
Module
Examples of Actuators
In the following table, you will find a listing of coupling relays with sufficient inertia
so as not to drop out during the dark period.
Table 6-3 Actuators That Can Be Used for Fail-Safe Output Modules
Safety Note
! If the actuators are operated at voltages higher than 24 VDC (for example, 230
VDC) or if the actuators clear higher voltages, safe isolation must be ensured
between the outputs of a fail-safe output module and the components carrying a
higher voltage (in accordance with EN 50178).
This is generally the case for relays and contactors. Particular attention must be
paid to this aspect for semiconductor switching devices.
Definition
Diagnostics are used to determine whether fail-safe module signal acquisition is
taking place without errors. Diagnostic information is assigned either to one
channel or to the entire F-module.
React to Faults
If a fail-safe module detects an fault/error, it switches the affected channel or all
channels to a safe state; this means that the channels of the F-module are
passivated. The F-module reports the fault/error it has detected to the F-CPU by
means of slave diagnostics.
F-modules cannot save data as retentive data. When the system is powered down
and then back up, any faults still existing are detected again during startup.
However, you have the option of saving faults/errors in your safety program.
Safety Note
! When a channel fault occurs, there is no fault reaction or fault handling for
channels to which you have assigned the "deactivated" parameter in STEP 7; this
is also the case when a "deactivated" channel is indirectly affected by a channel
group fault. (For information about the "Channel activated/deactivated“
parameter, see Sections 9.2 to 9.4.)
Passivation
Passivation of digital output channels means that output channels are placed in a
deenergized state.
Passivation of digital input channels means that the inputs transmit the substitute
value 0 to the F-CPU, regardless of the current process signal. When a channel
fault occurs (for example, a wire break), the affected channel is passivated. In the
event of a module fault (for example, overtemperature), all channels of the fail-safe
module are passivated. (The react for communication errors is different; see
below.)
As long as a passivated channel has a fault, it supplies a channel value and a
value status of "0“. Diagnostics are transmitted. If no more channel faults occur, the
channel is either automatically unpassivated or the F-module must be removed and
inserted.
A complete listing of faults requiring removal and insertion of the F-module can be
found in the "Causes of Faults/Errors and Corrective Measures" tables
in Sections 9.2 to 9.4.
Safety Note
! Diagnostic functions should be activated or deactivated in accordance with the
application.
For example, for applications involving press machines, the short-circuit test for
F-DI modules must be activated because line isolation is jeopardized by constant
vibration.
For applications involving machine protection, a short circuit in the sensor line is
always considered to be a possible source of fault. Here too, one option for
preventing faults is to activate the short-circuit test in conjunction with 1oo2
evaluation with 2-channel sensors (see also Section 9.3).
Slave Diagnostics
Slave diagnostics behave in accordance with PROFIBUS standard EN 50170/A2.
Fail-safe electronic and power modules support slave diagnostics in the same way
as standard ET 200S modules.
You will find a description of the general configuration of slave diagnostics for
ET 200S and the fail-safe modules in the ET 200S Distributed I/O System manual . A
supplementary description of channel-specific diagnostics for fail-safe modules is
presented below.
Channel-Specific Diagnostics
As with ET 200S, three bytes of channel-specific diagnostics are available per
F-module starting with byte 35. Channel-specific diagnostics for fail-safe modules
are configured as follows:
7 6 5 4 3 2 1 0 Bit no.
Byte 35 1 0
7 6 5 4 3 2 1 0 Bit no.
Byte 37
Note
In byte 35, bit 0 to 5, the module slot is encoded. The following applies:
Displayed number +1 = module slot (0 = slot 1; 1 = slot 2, etc.)
Note
Channel-specific diagnostics are always updated to the current diagnostic
function in the diagnostic message frame. Subsequent, older diagnostic functions
are not deleted.
Remedy: Evaluate the valid current length of the diagnostic message frame in
STEP 7 using the SFC 13 parameter RET_VAL.
8.1 Introduction
Overview
This chapter presents the following information about fail-safe modules:
· Information about the most important standards and approvals
· Information about the general technical specifications
PROFIBUS Standard
The ET 200S distributed I/O system is based on PROFIBUS standard EN
50170/A2.
IEC 61131
Fail-safe modules comply with the requirements and criteria of IEC 61131, Part 2.
CE Mark
Siemens products satisfy the requirements and safety objectives of the following
European Community directives and comply with the harmonized European
standards (EN) for programmable logic controllers published in the Gazette of the
European Community:
· 92/31/EEC and 93/68/EEC ”Electromagnetic Compatibility” (EMC directive)
· 93/68/EEC ”Electrical Equipment Designed for Use within Certain Voltage
Limits” (low voltage directive)
The EC declarations of conformity are available to the competent authorities at:
Siemens Aktiengesellschaft
Automation and Drives Division
A&D AS E4
Postfach 1963
D-92209 Amberg Federal Republic of Germany
All SIMATIC products bearing the mark depicted to the left comply with the
requirements of the standard AS/NZS 2064 (Class A).
Use in Industry
SIMATIC products are designed for use in industrial environments.
UL Approval
UL Recognition Mark
Underwriters Laboratories (UL) in accordance with
UL 508, file No. 116536
CSA Approval
CSA Certification Mark
Canadian Standard Association (CSA) in accordance with
C22.2 No. 142, file no. LR 48323
FM Approval
Factory Mutual Approval Standard Class Number 3611, Class I, Division 2,
Group A, B, C, D.
Warning
! There is a risk of personal injury or property damage.
In areas exposed to explosion hazard, personal injury or property damage can
occur if plug-in connections are disconnected during operation.
Before disconnecting plug-in connections in areas exposed to explosion hazard,
always deenergize the distributed I/O.
Summary
In the following table, you will find an overview of fail-safe modules with information
about approvals and areas of application.
Introduction
This chapter presents information about immunity to interference of fail-safe
modules and about EMC conformity.
Fail-safe modules comply with the requirements of the EMC law for the European
internal market.
Definition of EMC
Electromagnetic compatibility is the ability of an electrical device to function in its
electromagnetic environment in a satisfactory manner without affecting this
environment.
Pulse-Shaped Interference
The following table presents the electromagnetic compatibility of fail-safe modules
with regard to pulse-shaped interference. As a requirement, the ET 200S
distributed I/O system must comply with the specifications and guidelines for
electrical configuration.
IM 151-1
A5E00103686-01
4 DI
4 DI
Mounting rail
2 DO
2 DO
4 F-DO
PM-E-F
4/8 F-DI
4/8 F-DI
24 VDC
24 VDC
24 VDC
24 VDC
24 VDC
24 VDC/2A
24 VDC/2A
24 VDC/2A
120/230 VAC
DP
PM-E 24 VDC/
120/230 VAC
PM-E 24 VDC/
Shielded line
Unshielded line (suppressor circuit
not required)
element*
L+
see
element*
no. 5
see
module
no. 6
module
2 6 5 3 2 8 10
Shielded connecting
Shielded connecting
8/ 16/ terminal modules
2 4/ 14/
7/ 11/ 12/ 6/ 12/
3** 1 5 2 6 1 5 3 9 10 13 14 15 16 1 25 69 10 13 14 2 1 5 3 7 10 9 11 13 15
OUT + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + -
IN B10 + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + -
1L+
2L+ 4L+
PROFIBUS-DP
-230 VAC -230 VAC -230 VAC Name Dehn Order Number
-230 VAC
8-7
General Technical Specifications
Sinusoidal Interference
HF radiation of the device in accordance with IEC 61000-4-3:
· Electromagnetic HF field, amplitude-modulated:
· HF coupling with signal lines and data lines, etc., in accordance with IEC
61000-4-6, high frequency, asymmetric, amplitude-modulated:
between 0.15 MHz and 80 MHz; 10 V R.M.S. value, unmodulated; 80% AM (1
kHz); 150 W source impedance
Between 0.15 MHz and 0.5 MHz; < 79 dB (µV)Q, < 66 dB (µV)M
Between 0.5 MHz and 5 MHz < 73 dB (µV)Q, < 60 dB (µV)M
Between 5 MHz and 30 MHz < 73 dB (µV)Q, < 60 dB (µV)M
Conditions of Use
Fail-safe modules are intended for use as permanently installed modules protected
from the elements. The conditions of use exceed the requirements of IEC 61131-2.
Fail-safe modules comply with the conditions of use of Class 3C3 in accordance
with DIN EN 60721 3-3 (use in locations with heavy traffic and in the immediate
vicinity of industrial systems with chemical emissions).
Restrictions
Fail-safe modules cannot be implemented in the following locations without
additional measures being taken:
· Locations with a high level of ionizing radiation
· Locations with difficult operating conditions, for example, due to:
- Dust
- Corrosive vapors or gases
· Systems that require special monitoring, such as:
- Electrical systems in particularly hazardous areas
An additional measure for implementing fail-safe modules can be, for example,
installing the ET 200S in cabinets.
Reduction of Oscillation
If fail-safe modules are subjected to sizable shock pulses or oscillation, you must
take appropriate measures to reduce acceleration and amplitude.
We recommend that you mount the ET 200S on cushioning material (for example,
on a rubber-metal vibration damper).
Test Voltages
Isolation stability is proven in routine testing with the following test voltages in
accordance with IEC 61131 Part 2:
Protection Class
The protection class is in accordance with IEC 60536 (VDE 0106, Part 1). That is,
a ground terminal is required on the mounting rail.
9.1 Introduction
Overview
One fail-safe power module and two fail-safe digital modules are available for
connecting digital sensors or encoders and actuators or loads to ET 200S. This
chapter provides the following information for each fail-safe module:
· Properties and special features
· Front view, terminal assignment for terminal modules, and block diagram
· Wiring diagram and programmable parameters
· Diagnostic functions, including corrective measures
· Technical specifications
Safety Note
! The fail-safe performance characteristics in the technical specifications are valid
for a proof-test interval of 10 years.
Order Number
6ES7138-4CF00-0AB0
Properties
The PM-E F 24 VDC PROFIsafe power module has the following properties:
· Two relays for switching voltage buses P1 and P2, 10 A output current
· Two fail-safe digital outputs, P-M switching (current sourcing/sinking), 2 A
output current
· 24 VDC rated load voltage
· Suitable for solenoid valves, DC contactors, and indicator lights
· Group fault display (SF; red LED)
· Status display for each output (green LED)
· Status display for load current power supply (PWR; green LED)
· Assignable diagnostics
· Safety class SIL3 achievable
Condition Achievable
AK/SIL/Category
ET 200S standard modules supplied by means of P1 and P2 AK4/SIL2/Category 3 on
P1 and P2
DO 0 and DO 1 used, modules not supplied by means of P1 AK6/SIL3/Category 4 on
and P2 DO 0 and DO 1
Safety Note
! Always connect the 24 VDC supply for the standard ET 200S modules on the
PM-E F 24 VDC PROFIsafe power module. Otherwise, the outputs of DO
modules may exhibit safety-critical behavior.
Safety Note
! When supplying standard DI/DO modules, always use the terminal modules to
supply the sensors or actuators (sensor supply on the DI module; actuator
feedback on the DO module). Otherwise, the power module signals a short circuit
and the load voltage of this voltage group is deactivated.
Safety Note
! Fail-safe activation of outputs of standard DO modules is not possible; rather,
only fail-safe deactivation is possible. That is, the PM E-F 24 VDC PROFIsafe
power module does not detect external short circuits after L+ on the outputs of
standard ET 200S DO modules.
If short circuits after L+ cannot be ruled out in your process, we recommend the
use of P-M switching (current sourcing/sinking) fail-safe 4 F-DO 24 VDC/2 A
PROFIsafe electronic modules in place of standard modules (see Section 9.4).
Incoming Supply of the 24 VDC Supply for Electronic Modules with Process-
Related Functions
Depending on whether the electronic and load current supplies are electrically
isolated in the electronic modules with process-related functions (positioning,
counting), you must adhere to the following wiring instructions:
· If electrically isolated, provide an external 24 VDC feed for the electronic
module.
· If not electrically isolated, you must supply the electronic module by the voltage
bus voltage P1 of the PM-E F 24 VDC PROFIsafe power module.
AK4/SIL2/Category 3 is achievable in both cases.
Front View
Safety Note
! The SF LED and the status displays of the outputs must not be evaluated for fail-
safe activities.
Terminal Assignment
The terminal assignment of the PM-E F 24 VDC PROFIsafe power module for the
applicable terminal modules TM-P30S44-A0 and TM-P30C44-A0 is shown in the
following figure and table.
AUX1
DO0 DO1
4 8 9 13 P P
M M DO2 DO2
(Incoming supply) P P
3 7 11 15
Figure 9-2 Terminal Assignment of TM-P30S44-A0 and TM-P30C44-A0 for PM-E F 24 VDC PROFIsafe
Terminal Designation
2 24 VDC 24 VDC rated load voltage for: inserted power module,
associated voltage group, DO 0 and DO 1, and
voltage buses P1 and P2
3 M Ground
4 AUX 1 Any terminal for PE or voltage bus up to the maximum rated load
voltage of the module
6 24 VDC 24 VDC rated load voltage for: inserted power module, associated
voltage group, DO 0 and DO 1, and voltage buses P1 and P2
7 M Ground
8 AUX 1 Any terminal for PE or voltage bus up to the maximum rated load
voltage of the module
9 DO 0 P Terminals for fail-safe digital output 0 (P-M switching)
10 DO 0 M
11 DO 2 P Terminals (relay contacts) for fail-safe switching of voltage buses P1
12 DO 2 M and P2
P1 and P2 can also be used as DO 2 M and DO 2 P
13 DO 1 P Terminals for fail-safe digital output 1 (P-M switching)
14 DO 1 M
15 DO 2 P Terminals (relay contacts) for fail-safe switching of voltage buses P1
16 DO 2 M and P2
P1 and P2 can also be used as DO 2 M and DO 2 P
Caution
! If strong currents can occur on DO 2 P and DO 2 M, both terminals 11 and 15
(DO 2 P) and terminals 12 and 16 (DO 2 M) must be wired in parallel.
Otherwise, the current loading could cause the terminals to heat up.
Block Diagram
Address switch
PWR P-switch
M 9
Processing logic
13
Backplane bus interface module
Read back
10
SF
M
M-switch
14
M
Status of
output
Relays 5V
12, 16 M24
24 V
3, 7
P1
P2
11, 15 P24
2, 6
Wiring Diagram
The three digital outputs each consist of one P-switch (current sourcing) DOx P
and one M-switch (current sinking) DOx M. They connect the load between the P
and M-switches. The two switches are always controlled so that voltage is applied
to the load.
The wiring for the power module is carried out on the special terminal module.
P1 (P)
P1 P2
DO0 DO0 DO1 DO1 (P) (M) P2 (M)
L+ M (P) (M) (P) (M) DO2 DO2 DO3 M DO4 M DO5 M
K0 K1 K2 K3 K4 K5
L+ M
Safety Note
! To protect the relay contacts from overload, use of an external fuse with the
following properties is recommended for L+ on the PM-E F: B-characteristic
circuit breaker in accordance with IEC 947-5-1, 10 A.
Safety Note
!
For safety reasons, you must disconnect the supply voltage to the fail-safe digital
outputs DO 0 and DO 1 within one hour after their passivation.
Relay Output DO 2
The relay output DO 2 connects the voltage L+ and M using one relay contact for
each. The voltage is fed outwards to the terminal module and to the internal
voltage buses P1 and P2. This results in two connection options that can be used
at the same time:
· A load can be connected directly to the terminal module (K2 in Figure 9-4).
· Electronic modules can be supplied by means of the internal voltage buses P1
and P2. Loads can be connected to these modules in turn (K3, K4, and K5 in
Figure 9-4).
P1 (P)
P1 P2
DO0 DO0 DO1 DO1 (P) (M) P2 (M)
L+ M (P) (M) (P) (M) DO2 DO2 DO3 M DO4 M DO5 M
K1 K2 K3 K4
K1 K3
K2 K4
L+ M
Figure 9-5 Wiring Diagram for Each of Two Relays on DO 0 and DO 1 of the PM-E F 24 VDC PROFIsafe
Safety Note
! When connecting two relays on one digital output, the faults "wire break“ and
"overload“ are detected only on the P-switch of the output (not on the M-switch).
Parameters in STEP 7
The following table presents the parameters that can be assigned for the
PM-E F 24 VDC PROFIsafe power module (see also Chapter 4).
Note
A supply voltage failure in the PM-E F PROFIsafe power module causes the SF
LEDs of the electronic modules to behave differently in the voltage group:
· Standard DI or DO modules: SF LED is off
· Standard AI or AO modules: SF LED is on
· Electronic modules with process-related functions: SF LED is on
Diagnostic Functions
The following table presents an overview of the diagnostic functions of the
PM-E F 24 VDC PROFIsafe power module. The diagnostic functions are assigned
either to one channel or the entire module.
Table 9-5 Causes of Faults and Corrective Measures for Diagnostic Functions of the
PM-E F 24 VDC PROFIsafe
Technical Specifications
Dimensions and Weight
Dimensions W x H x D (mm) 30 x 81 x 52
Weight Approx. 88 g
Module-Specific Data
Number of outputs
· Semiconductor outputs (P-M switching) 2
· Relay outputs (P-M switching) 1
Assigned address area
· In PII 5 bytes
· In PIQ 5 bytes
Length of cable
· Unshielded 200 m, maximum
· Shielded 200 m, maximum
Maximum achievable safety class
· In accordance with IEC 61508, DIN SIL2, AK4, Category 3:
VDE 0801, and EN 954 · With ET 200S standard DOs
· Without ET 200S standard DOs for
relay outputs with static output signal
SIL3, AK6, Category 4:
· For semiconductor outputs
Without ET 200S standard DOs for relay
outputs with dynamic output signal
Fail-safe performance characteristics SIL3
· Low demand mode (average probability << 1.00 E-05
of failure on demand)
· High demand/continuous mode << 1.00 E-10
(probability of a dangerous failure per
hour)
Voltages, Currents, Potentials
Rated supply voltage L+ 24 VDC
· Permissible range 20.4 V to 28.8 V
· Power loss ride-through of L+ None
· Power loss ride-through of internal P5 5 ms
· Reverse polarity protection No
Aggregate current
· Horizontal installation
Up to 40°C 10 A
Up to 55°C 7A
Up to 60°C 6A
· Vertical installation
Up to 40°C 6A
Electrical isolation
· Between channels and backplane bus Yes
· Between channels and power supply No
Technical Specifications
· Between channels No
· Between channels/power supply and Yes
shield
Permissible potential difference between
· Shield and ET 200S bus connection 75 VDC/60 VAC
· Shield and I/O (DOs, P1/P2 buses) 75 VDC/60 VAC
· ET 200S bus connection and I/O (DOs, 250 VAC
P1/P2 buses)
Isolation in the series checked with
· Shield and ET 200S bus connection 500 VDC/1 min or 600 VDC/1 s
· Shield and I/O (DOs, P1/P2 buses) 500 VDC/1 min or 600 VDC/1 s
· ET 200S bus connection and I/O (DOs, 1500 VAC/1 min or 2545 VDC/1 s
P1/P2 buses)
Isolation in the type test checked with
· Shield and ET 200S bus connection 350 VAC/1 min
· Shield and I/O (DOs, P1/P2 buses) 350 VAC/1 min
· ET 200S bus connection and I/O (DOs, 2830 VAC/1 min
P1/P2 buses)
· Impulse current test between ET 200S 6000 VDC/5 positive and 5 negative pulses
bus connection and I/O (DOs, P1/P2
buses)
Current consumption
· From backplane bus 28 mA, maximum
· From load voltage L+ (without load) 100 mA, typical
Power dissipation of the module 4 W, typical
Status, Interrupts, Diagnostics
Status display · Green LED per channel
· Green LED for the load voltage
Diagnostic functions
· Group fault display Red LED (SF)
· Diagnostic information can be displayed Possible
Data for Selecting an Actuator for the Semiconductor Outputs*
Output voltage
· For "1“ signal · Minimum L+ (-2.0 V)
· (P-switch minimum L+
(-1.5 V), voltage drop in M-switch:
maximum 0.5 V)
Output current for "1“ signal
· Rated value 2A
· Permissible range 20 mA to 2.4 A
For "0“ signal (residual current) 0.5 mA, maximum
Indirect control of load by means of interface
relay:
Residual current for "0“ signal
· P-switch (current sourcing) 0.5 mA, maximum
· M-switch (current sinking) 4 mA, maximum
Load resistance range 12 W to 1 kW
Lamp load 10 W, maximum
Technical Specifications
Wire break monitoring (open load detection)
and overload monitoring
· Response threshold I < 4 to 19 mA
Parallel connection of 2 outputs Not possible
Control of a digital input Not possible
Switching frequency
· With resistive load 30 Hz, maximum
· With inductive load in accordance with 0.1 Hz, maximum
IEC 947-5-1, DC13
· With lamp load 10 Hz, maximum
Voltage induced on current interruption
limited to
· Semiconductor outputs L+ (-2x 47 V)
· Relay outputs P1/P2 (1 V)
Short-circuit protection of semiconductor Yes, electronic
outputs
· Response threshold of short circuit 5 A to 12 A
· Response threshold of external M-short 5 A to 12 A
circuit
· Response threshold of external P-short 25 A to 45 A
circuit
Overload protection of semiconductor Yes
outputs
· Response threshold I >2.6 A to 2.8 A
Data for Selecting an Actuator for the Relay Outputs*
Switching capacity and service life of the
contacts at 24 VDC
· Mechanical endurance (without load) Current No. of switching cycles
(typical)
0A 10 million
· For resistive load Current No. of switching cycles
(typical)
10 A 0.23 million
8A 0.3 million
6A 0.38 million
4A 0.5 million
2A 1.0 million
1A 2.0 million
· For inductive load in accordance with Current No. of switching cycles
IEC 947-5-1, DC13 (typical)
10 A 0.1 million
8A 0.15 million
6A 0.2 million
4A 0.3 million
2A 0.5 million
1A 1.0 million
· For lamp load Power No. of switching cycles
(typical)
100 W 0.12 million
Technical Specifications
Contact protection (internal) Internal readback circuit
· Between P and M relay output 39 V suppressor diode
Wire break monitoring No
Parallel connection of 2 outputs Not possible
Control of a digital input Not possible
Switching frequency
· Mechanical 10 Hz, maximum
· With resistive load 2 Hz, maximum
· With inductive load in accordance with 0.1 Hz, maximum
IEC 947-5-1, DC13
· With lamp load 2 Hz, maximum
Short-circuit protection of output No, external miniature circuit breaker, "B"
characteristic (in accordance with IEC 947-
5-1), 10 A required
Time, Frequency
Internal preparation times See Chapter 12
Acknowledgment time in safety mode 4 ms minimum/6 ms maximum
Protection against Overvoltage
Protection of supply voltage L+ from surge
in accordance with IEC 1000-4-5 with
external protection elements only
· Symmetrical (L+ to M) + 1 kV; 1.2/50 µs
· Asymmetrical (L+ to FE, M to FE) + 2 kV; 1.2/50 µs
Protection of outputs from surge in
accordance with IEC 1000-4-5 with external
protection elements only
· Symmetrical (L+ to M) + 1 kV; 1.2/50 µs
· Asymmetrical (L+ to FE, ground to FE) + 2 kV; 1.2/50 µs
* For requirements for sensors and actuators, refer to Section 6.5
Order Number
6ES7138-4FA00-0AB0
Properties
The 4/8 F-DI 24 VDC PROFIsafe digital electronic module has the following
properties:
· Eight inputs (AK4/SIL2/Category 3) or four inputs (AK6/SIL3/Category 3 or 4)
· 24 VDC rated input voltage
· Suitable for switches and 3 or 4-wire proximity switches (BEROs)
· Two short-circuit-proof sensor supplies for each of the four inputs
· External sensor supply possible
· Group fault display (SF; red LED)
· Status display for each input (green LED)
· One fault display for each sensor supply (1VsF and 2VsF; red LED)
· Assignable diagnostics
Table 9-6 EM 4/8 F-DI 24 VDC PROFIsafe: Power Modules for AK/SIL/Category
Front View
Terminal Assignment
The terminal assignment of the EM 4/8 F-DI 24 VDC PROFIsafe digital electronic
module for the applicable terminal modules TM-E30S44-01, TM-E30C44-01,
TM-E30S46-A1, and TM-E30C46-A1 is shown in the following figure.
A15
AUX1 AUX1 (PE) A3 A7 A11 AUX1 AUX1 (PE)
Block Diagram
Address switch
1Vs 2VsF
M M
2,6,4,8 10,14,12,16 VS2
VS1
1 9
5 13
3 11
7 M 15
Processing logic
Backplane bus interface module
Test
Filter logic
Status
M
SF
5V
M
24 V
P1
P2
Parameters in STEP 7
The following table presents the parameters that can be assigned for the
EM 4/8 F-DI 24 VDC PROFIsafe digital electronic module (see also Chapter 4).
Input Delay of 3 ms
Safety Note
! To avoid a safety-related deactivation, you must use shielded cables for the fail-
safe digital inputs and sensor supply when using an assigned input delay of
3 ms. Alternatively, you can assign an input delay of 15 ms.
"Discrepancy Time"
The "discrepancy time“ parameter is only relevant for 1oo2 evaluation with a
2-channel sensor. For 1oo2 evaluation with a 1-channel sensor, the discrepancy
time is permanently preset to 10 ms.
The maximum time that the effective discrepancy time of the F-DI module can be
extended compared to the assigned discrepancy time is shown in the following
table.
In the case of 1oo2 evaluation, the F-DI module reads the input signals twice,
performs an internal comparison, and then sends the harmonized result to the
F-CPU.
Safety Note
! The input signals from the process are considered to be correct process values
within the effective discrepancy time even if the redundant input signal readings
are different.
While the discrepancy time procedure is in progress within the module, the old
value of the relevant input channel is sent to the F-CPU.
Note
The discrepancy time for 2-channel sensors must be set to short response times
for fast response.
Thus, for example, it makes no sense for a time-critical deactivation to be
triggered by 2-channel sensors with a discrepancy time of 500 ms. In the worst
case, the sensor-actuator response time is extended by an amount approximately
equal to the discrepancy time:
· For this reason, position the sensor in the process in such a way to minimize
discrepancy.
· Then select the shortest possible discrepancy time that also has sufficient
back up against false tripping of discrepancy errors.
Required
safety class?
Application 1 to 3
1 2 3
See See See
Sec. 9.3.2 Sec. 9.3.3 Sec. 9.3.4
Figure 9-9 Selecting the Application – Electronic Module 4/8 F-DI 24 VDC PROFIsafe
Safety Note
! The achievable safety class is dependent on the quality of the sensor and the
magnitude of the proof-test interval in accordance with IEC 61508 (interval for
external function test). If the quality of the sensor is lower than the quality
stipulated in the required safety class, the sensor must be applied redundantly
with a 2-channel connection.
Table 9-9 EM 4/8 F-DI 24 VDC PROFIsafe: Conditions for Achieving AK/SIL/Category
Note
You can operate the various inputs of an F-DI module simultaneously in
AK4/SIL2/Category 3 and in AK6/SIL3/Category 3 or 4. You only have to connect
the inputs and assign parameters as shown in the following chapters.
Sensor Requirements
For safety-related use of sensors, refer to Section 6.5 Requirements for Sensors
and Actuators.
Sensor Supply
The EM 4/8 F-DI 24 VDC PROFIsafe digital electronic module provides sensor
supply Vs1 for inputs 0 to 3 and sensor supply Vs2 for inputs 4 to 7. The sensor
supply can be provided internally or externally.
8 F-DI
L+ M Vs1 DI0 DI1 DI2 DI3 Vs2 DI4 DI5 DI6 DI7
S0 S1 S2 S3 S4 S5 S6 S7
L+ M
Figure 9-10 Wiring Diagram EM 4/8 F-DI 24 VDC PROFIsafe – 1-Channel Sensor (1oo1), Internal Sensor
Supply
8 F-DI
L+ M Vs1 DI0 DI1 DI2 DI3 Vs2 DI4 DI5 DI6 DI7
S0 S1 S2 S3 S4 S5 S6 S7
L+ M
Figure 9-11 Wiring Diagram EM 4/8 F-DI 24 VDC PROFIsafe – 1-Channel Sensor (1oo1), External Sensor
Supply
Table 9-10 EM 4/8 F-DI 24 VDC PROFIsafe: Fault Detection for Application 1
* Fault is detected only in case of signal corruption. That is, the signal read differs from the sensor
signal. If there is no signal corruption with respect to the sensor signal, fault detection is not
possible and is not required from a safety standpoint.
Sensor Supply
The EM 4/8 F-DI 24 VDC PROFIsafe digital electronic module provides sensor
supply Vs1 for inputs 0 to 3 and sensor supply Vs2 for inputs 4 to 7. The sensor
supply can be provided internally or externally.
Note
If the voltage is supplied to the sensor by the F-DI module, you must use the
internal sensor supply Vs1. Connection to Vs2 is not possible.
4 F-DI
L+ M Vs1 DI0 DI1 DI2 DI3 Vs2 DI4 DI5 DI6 DI7
S0
S1
S2
S3
L+ M
Figure 9-12 Wiring Diagram for EM 4/8 F-DI 24 VDC – Sensor Signal Read Twice (1oo2), Internal Sensor
Supply
4 F-DI
L+ M Vs1 DI0 DI1 DI2 DI3 Vs2 DI4 DI5 DI6 DI7
S0
S1
S2
S3
L+ M
Figure 9-13 Wiring Diagram for EM 4/8 F-DI 24 VDC – Sensor Signal Read Twice (1oo2), External Sensor
Supply
Safety Note
! To achieve AK6/SIL3/Category 3 using this wiring, you must use a sensor
qualified for this class.
Table 9-11 EM 4/8 F-DI 24 VDC PROFIsafe: Fault Detection for Application 2.1
* Fault is detected only in case of signal corruption. That is, the signal read differs from the sensor
signal. If there is no signal corruption with respect to the sensor signal, fault detection is not
possible and is not required from a safety standpoint.
4 F-DI
L+ M Vs1 DI0 DI1 DI2 DI3 Vs2 DI4 DI5 DI6 DI7
S0
S1
S2
S3
L+ M
Figure 9-14 Wiring Diagram for EM 4/8 F-DI 24 VDC – 2-Channel Sensor Signal (1oo2), Internal Sensor
Supply
4 F-DI
L+ M Vs1 DI0 DI1 DI2 DI3 Vs2 DI4 DI5 DI6 DI7
S0
S1
S2
S3
L+ M
Figure 9-15 Wiring Diagram for EM 4/8 F-DI 24 VDC – 2-Channel Sensor Signal (1oo2), External Sensor
Supply
Safety Note
! To achieve AK6/SIL3/Category 3 using this wiring, you must use a sensor
qualified for this class.
Table 9-12 EM 4/8 F-DI 24 VDC PROFIsafe: Fault Detection for Application 2.2
* Fault is detected only in case of signal corruption. That is, the signal read differs from the sensor
signal. If there is no signal corruption with respect to the sensor signal, fault detection is not
possible and is not required from a safety standpoint.
Note
If the voltage is supplied to sensor by the F-DI module, you must use the internal
sensor supply Vs1. Connection to Vs2 is not possible.
4 F-DI
L+ M Vs1 DI0 DI1 DI2 DI3 Vs2 DI4 DI5 DI6 DI7
S0
S1
S2
S3
L+ M
Figure 9-16 Wiring Diagram for EM 4/8 F-DI 24 VDC – Non-Equivalent Sensor Signal (1oo2), Internal
Sensor Supply
4 F-DI
L+ M Vs1 DI0 DI1 DI2 DI3 Vs2 DI4 DI5 DI6 DI7
S0
S1
S2
S3
L+ M
Figure 9-17 Wiring Diagram for EM 4/8 F-DI 24 VDC – Non-Equivalent Sensor Signal (1oo2), External
Sensor Supply
Safety Note
! To achieve AK6/SIL3/Category 3 using this wiring, you must use a sensor
qualified for this class.
Table 9-13 EM 4/8 F-DI 24 VDC PROFIsafe: Fault Detection for Application 2.3
* Fault is detected only in case of signal corruption. That is, the signal read differs from the sensor
signal. If there is no signal corruption with respect to the sensor signal, fault detection is not
possible and is not required from a safety standpoint.
Sensor Supply
The EM 4/8 F-DI 24 VDC PROFIsafe digital electronic module provides sensor
supply Vs1 for inputs 0 to 3 and sensor supply Vs2 for inputs 4 to 7. The sensor
must be supplied internally.
4 F-DI
L+ M Vs1 DI0 DI1 DI2 DI3 Vs2 DI4 DI5 DI6 DI7
S0
S1
S2
S3
L+ M
Figure 9-18 Wiring Diagram for EM 4/8 F-DI 24 VDC – 2-Channel Sensor Signal (1oo2), Internal Sensor
Supply
Safety Note
! To achieve AK6/SIL3/Category 4 using this wiring, you must use a sensor
qualified for this class.
Note
You must use the internal sensor supply Vs1 to supply voltage to the sensor.
Connection to Vs2 is not possible.
4 F-DI
L+ M Vs1 DI0 DI1 DI2 DI3 Vs2 DI4 DI5 DI6 DI7
S0
S1
S2
S3
L+ M
Figure 9-19 Wiring Diagram for EM 4/8 F-DI 24 VDC – Non-Equivalent Sensor Signal (1oo2), Internal
Sensor Supply
Safety Note
! To achieve AK6/SIL3/Category 4 using this wiring, you must use a sensor
qualified for this class.
Table 9-14 EM 4/8 F-DI 24 VDC PROFIsafe: Fault Detection for Application 2.3
* Fault is detected only in case of signal corruption. That is, the signal read differs from the sensor
signal. If there is no signal corruption with respect to the sensor signal, fault detection is not
possible and is not required from a safety standpoint.
Diagnostic Functions
The following table presents an overview of the diagnostic functions of the
EM 4/8 F-DI 24 VDC PROFIsafe digital electronic module. The diagnostic functions
are assigned either to one channel or the entire module.
Note
If you have activated the short-circuit test for the F-DI module in STEP 7 and
are using only one of the two internal sensor supplies of the module (Vs1 or Vs2),
a channel M-short circuit is then detected for each of the four channels that has
an unused sensor supply. Four "short-circuit" diagnostic functions are generated
in the diagnostic buffer of the module.
Table 9-16 Diagnostic Functions of the EM 4/8 F-DI 24 VDC PROFIsafe, Causes of
Faults and Corrective Measures
Technical Specifications
Dimensions and Weight
Dimensions W x H x D (mm) 30 x 81 x 52
Weight Approx. 78 g
Module-Specific Data
Number of inputs
· 1-channel 8, maximum
· 2-channel 4, maximum
Assigned address area
· In PII 6 bytes
· in PIQ 4 bytes
Length of cable
· Unshielded 200 m, maximum
· Shielded 200 m, maximum
Maximum achievable safety class 1-channel 2-channel
· In accordance with IEC 61508 SIL2 SIL3
· In accordance with DIN VDE 0801 AK4 AK6
· In accordance with EN 954 Category 3 Category 4
Fail-safe performance characteristics SIL2 SIL3
· Low demand mode (average probability of failure << 1.00 E-03 << 1.00 E-05
on demand)
· High demand/continuous mode (probability of a << 1.00 E-08 << 1.00 E-10
dangerous failure per hour)
Voltages, Currents, Potentials
Rated supply voltage L+ 24 VDC
· Permissible range 20.4 V to 28.8 V
· Power loss ride-through of L+ None
· Power loss ride-through of internal P5 5 ms
· Reverse polarity protection No
Number of simultaneously controllable inputs
· Horizontal installation
Up to 55°C 8 (with 28.8 V)
Up to 60°C 8 (with 24 V)
Up to 60°C 6 (with 28.8 V)
· Vertical installation
Up to 40°C 8
Technical Specifications
Electrical isolation
· Between channels and backplane bus Yes
· Between channels and power supply No
· Between channels No
· Between channels/power supply and shield Yes
Permissible potential difference between
· Shield and ET 200S bus connection 75 VDC/60 VAC
· Shield and I/O (DIs, P1/P2 buses) 75 VDC/60 VAC
· ET 200S bus connection and I/O (DIs P1/P2 250 VAC
buses)
Isolation in the series checked with
· Shield and ET 200S bus connection 500 VDC/1 min or 600 VDC/1 s
· Shield and I/O (DIs, P1/P2 buses) 500 VDC/1 min or 600 VDC/1 s
· ET 200S bus connection and I/O (DIs, P1/P2 1500 VAC/1 min or 2545 VDC/1 s
buses)
Isolation in the type test checked with
· Shield and ET 200S bus connection 350 VAC/1 min
· Shield and I/O (DIs, P1/P2 buses) 350 VAC/1 min
· ET 200S bus connection and I/O (DIs, P1/P2 2830 VAC/1 min
buses)
· Impulse current test between ET 200S bus 6000 VDC/5 positive and 5 negative pulses
connection and I/O (DIs, P1/P2 buses)
Current consumption
· From backplane bus 28 mA, typical
· From load voltage L+ (without load) 120 mA, typical
Power dissipation of module 4 W, typical
Status, Interrupts, Diagnostics
Status display
Inputs Green LED per channel
Sensor supply Red LED per channel
Diagnostic functions
· Group fault display Red LED (SF)
· Diagnostic information can be displayed Possible
Sensor Supply Outputs
Number of outputs 2
Output voltage
· Loaded Minimum L+ (-1.5 V)
Output current
· Rated value 300 mA
· Permissible range 0 mA to 300 mA
Permissible aggregate current of outputs 600 mA
Short-circuit protection Yes, electronic
· Operating value 0.7 A to 1.8 A
Technical Specifications
Data for Selecting a Sensor**
Input voltage
· Rated value 24 VDC
· For "1“ signal 15 V to 30 V
· For "0“ signal -30 V to 5 V
Input current
· For "1“ signal 3.7 mA, typical
Input delay* Assignable (for all inputs combined)
· For "0“ after "1“ 0.5 ms, typical (0.3 ms to 0.7 ms)
3 ms, typical (2.6 ms to 3.4 ms)
15 ms, typical (13 ms to 17 ms)
· For "1“ after "0“ 0.5 ms, typical (0.3 ms to 0.7 ms)
3 ms, typical (2.6 ms to 3.4 ms)
15 ms, typical (13 ms to 17 ms)
Input characteristic In accordance with IEC 1131, Type 1
Connection of 2-wire proximity switch Not possible
· Permissible quiescent current 0.6 mA, maximum
Time, Frequency
Internal preparation times See Chapter 12
Acknowledgment time in safety mode
· Short-circuit test activated with input delay of 0.5
ms: 4 ms, minimum/7 ms, maximum
with input delay of 3 ms: 4 ms, minimum/12 ms, maximum
with input delay of 15 ms: 4 ms, minimum/9 ms. maximum
· Short-circuit test deactivated 4 ms, minimum/6 ms, maximum
Minimum sensor signal duration See Table 6.2 in Section 6.5
Protection against Overvoltage
Protection of supply voltage L+ from surge stressing in
accordance with IEC 1000-4-5 with external protection
elements only
· Symmetrical (L+ to M) + 1 kV; 1.2/50 µs
· Asymmetrical (L+ to FE, M to FE) + 2 kV; 1.2/50 µs
Protection of inputs and outputs from surge stressing
in accordance with IEC 1000-4-5 with external
protection elements only
· Symmetrical (L+ to M) + 1 kV; 1.2/50 µs
· Asymmetrical (L+ to FE, M to FE) + 2 kV; 1.2/50 µs
* With an input delay of 0.5 ms, shielded cable must be used for the digital inputs and the sensor
supply.
With an input delay of 3 ms, shielded cable must be used for the fail-safe digital inputs and the
sensor supply to avoid a safety-related deactivation.
** For requirements for sensors and actuators, refer to Section 6.5
Order Number
6ES7138-4FB00-0AB0
Properties
The 4 F-DO 24 VDC/2 A PROFIsafe digital electronic module has the following
properties:
· Four outputs, P-M switching (current sourcing/sinking)
· 2 A output current
· 24 VDC rated load voltage
· Suitable for solenoid valves, DC contactors, and indicator lights
· Group fault display (SF; red SLED)
· Status display for each output (green LED)
· Assignable diagnostics
· Safety class SIL3 achievable
Front View
Safety Note
! The SF LED and the status displays of the outputs must not be evaluated for fail-
safe activities.
Terminal Assignment
The terminal assignment of the EM 4 F-DO 24 VDC/2 A PROFIsafe digital
electronic module for the applicable terminal modules TM-E30S44-01,
TM-E30C44-01, TM-E30S46-A1, and TM-E30C46-A1 is shown in the following
figure.
- - 3 7 11 15 - -
- - 4 8 12 16
- -
A15
AUX1 AUX1 (PE) A3 A7 A11 AUX1 AUX1 (PE)
DOx P and DOx M: interface module for fail-safe digital output (P-M switching)
For TM-E30S46-A1 and TM-E30C46-A1:
AUX 1 bus in place: Use terminals A3 to A16, as desired, to connect to PE (individual
grouping of sensor supplies possible)
Block Diagram
Address switch
P-switch
1
9
2 13
Read back
Processing logic
6
M-switch
14
M
Status of
output
SF
5V
M
24 V
P1
P2
Wiring Diagram
The four fail-safe digital outputs each consist of one P-switch (current sourcing)
DOx P and one M-switch (current sinking) DOx M. They connect the load between
the P and M-switches. The two switches are always controlled so that voltage is
applied to the load.
The wiring is carried out on an appropriate terminal module.
4 F-DO
DO0 DO0 DO1 DO1 DO2 DO2 DO3 DO3
L+ M (P) (M) (P) (M) (P) (M) (P) (M)
K0 K1 K2 K3
L+ M
Safety Note
! For safety reasons, you must disconnect the supply voltage to the fail-safe digital
outputs within one hour after their passivation.
4 F-DO
DO0 DO0 DO1 DO1 DO2 DO2 DO3 DO3
L+ M (P) (M) (P) (M) (P) (M) (P) (M)
K1 K2 K3 K4
K1 K3
K2 K4
L+ M
Figure 9-24 Wiring Diagram for Each of Two Relays to One F-DO of the EM 4 F-DO 24 VDC/2 A
PROFIsafe
Safety Note
! When connecting two relays on one digital output, the faults "wire break“ and
"overload“ are detected only on the P-switch of the output (not on the M-switch).
Parameters in STEP 7
The following table presents the parameters that can be assigned for the F-DO
module (see also Chapter 4).
Diagnostic Functions
The following table presents an overview of the diagnostic functions of the
EM 4 F-DO 24 VDC/2 A PROFIsafe digital electronic module. The diagnostic
functions are assigned either to one channel or to the entire module.
Technical Specifications
Dimensions and Weight
Dimensions W x H x D (mm) 30 x 81 x 52
Weight Approx. 85 g
Data for Specific Module
Number of outputs (P-M switching) 4
Assigned address area
· In PII 5 bytes
· in PIQ 5 bytes
Length of cable
· Unshielded 200 m, maximum
· Shielded 200 m, maximum
Maximum achievable safety class
· In accordance with IEC 61508 SIL3
· In accordance with DIN VDE 0801 AK6
· In accordance with EN 954 Category 4
Fail-safe performance characteristics SIL3
· Low demand mode (average probability << 1.00 E-05
of failure on demand)
· High demand/continuous mode << 1.00 E-10
(probability of a dangerous failure per
hour)
Voltages, Currents, Potentials
Rated supply voltage L+ 24 VDC
· Permissible range 20.4 V to 28.8 V
· Power loss ride-through of L+ None
· Power loss ride-through of internal 5 ms
power supply
· Reverse polarity protection No
Aggregate current of outputs
· Horizontal installation
Up to 40°C 6A
Up to 55°C 5A
Up to 60°C 4A
· Vertical installation
Up to 40°C 4A
Electrical isolation
· Between channels and backplane bus Yes
· Between channels and power supply No
· Between channels No
· Between channels/power supply and Yes
shield
Technical Specifications
Permissible potential difference between
· Shield and ET 200S bus connection 75 VDC/60 VAC
· Shield and I/O (DOs, P1/P2 buses) 75 VDC/60 VAC
· ET 200S bus connection and I/O (DOs, 250 VAC
P1/P2 buses)
Isolation in the series checked with
· Shield and ET 200S bus connection 500 VDC/1 min or 600 VDC/1 s
· Shield and I/O (DOs, P1/P2 buses) 500 VDC/1 min or 600 VDC/1 s
· ET 200S bus connection and I/O (DOs, 1500 VAC/1 min or 2545 VDC/1 s
P1/P2 buses)
Isolation in the type test checked with
· Shield and ET 200S bus connection 350 VAC/1 min
· Shield and I/O (DOs, P1/P2 buses) 350 VAC/1 min
· ET 200S bus connection and I/O (DOs, 2830 VAC/1 min
P1/P2 buses)
· Impulse current test between ET 200S 6000 VDC/5 positive and 5 negative pulses
bus connection and I/O (DOs, P1/P2
buses)
Current consumption
· From backplane bus 28 mA, maximum
· From load voltage L+ (without load) 100 mA, typical
Power dissipation of the module 3.5 W, typical
Status, Interrupts, Diagnostics
Status display
Outputs Green LED per channel
Diagnostic functions
· Group fault display Red LED (SF)
· Diagnostic information can be displayed Possible
Data for Selecting an Actuator*
Output voltage
· For "1“ signal Minimum L+ (-2.0 V)
(P-switch output minimum L+ (-1.5 V)
Voltage drop in the M-switch output:
maximum 0.5 V)
Output current for "1“ signal
· Rated value 2A
· Permissible range 20 mA to 2.4 A
For "0“ signal (residual current) 0.5 mA, maximum
Indirect control of load by means of interface
relay:
For "0“ signal (residual current)
· P-switch 0.5 mA, maximum
· M-switch 4 mA, maximum
Load resistance range 12 W to 1 kW
Technical Specifications
Lamp load 10 W, maximum
Wire break monitoring (open load detection)
and overload monitoring
· Response threshold I < 4 to 19 mA
Parallel connection of 2 outputs Not possible
Control of a digital input Not possible
Switching frequency
· With resistive load 30 Hz, maximum
· With inductive load in accordance with 0.1 Hz, maximum
IEC 947-5-1, DC13
· With lamp load 10 Hz, maximum
Voltage induced on current interruption typical L+ (-47 V)
limited to
Short-circuit protection of output Yes, electronic
· Response threshold (short circuit) 5 A to 12 A
· Response threshold (external M-short 5 A to 12 A
circuit)
· Response threshold (external P-short 25 A to 45 A
circuit)
Overload protection Yes
· Response threshold I >2.6 A to 2.8 A
Time, Frequency
Internal preparation times See Chapter 12
Acknowledgment time in safety mode 3 ms minimum/5 ms maximum
Protection against Overvoltage
Protection of supply voltage L+ from surge
stressing in accordance with IEC 1000-4-5
with external protection elements only
· Symmetrical (L+ to M) + 1 kV; 1.2/50 µs
· Asymmetrical (L+ to FE, M to FE) + 2 kV; 1.2/50 µs
Protection of inputs and outputs from surge
stressing in accordance with IEC 1000-4-5
with external protection elements only
· Symmetrical (L+ to M) + 1 kV; 1.2/50 µs
· Asymmetrical (L+ to FE, M to FE) + 2 kV; 1.2/50 µs
The following figure applies to an inserted PM-E F, F-DI, or F-DO module. The
same dimensions always apply.
3
66,5
Mounting rail
support
157
90,5
30 67
3 66,5
Mounting rail
132
support
65,5
30
67
Figure 10-1 Dimension Drawing of Terminal Modules with Inserted PM-E F, F-DI, or F-DO Module
Introduction
The response times of ET 200S fail-safe modules are presented below. The
response times of fail-safe modules are included in the calculation of F-system
response time.
You will find information about the calculation of F-system response times in the
Safety Engineering in SIMATIC S7 system description.
Parameters for the input delay and the short-circuit test are assigned in STEP 7
(see Section 9.3).
Maximum Response Time with a Fault/Error:
The following table presents the maximum response times of the F-DI module
when a fault/error is present, depending on the parameter assignment in STEP 7
and the evaluation of the sensors.
Table 12-3 EM 4/8 F-DI 24 VDC PROFIsafe: Maximum Response Time with a
Fault/Error
1oo1 Evaluation
1oo1 evaluation is a type of sensor evaluation in which one sensor is connected to
the F-module by means of a single channel.
1oo2 Evaluation
1oo2 evaluation is a type of sensor evaluation in which the signal statuses of the
inputs are compared internally for equivalence or nonequivalence.
Acknowledgment Time
Within the acknowledgment time, the F-I/O modules acknowledge the sign of life
specified by the F-CPU. The acknowledgment time is included in the calculation of
the watchdog and response time of the entire F-system.
Actuator
Actuators can be power relays or contactors for switching on consumers, or they
can be consumers themselves (for example, directly controlled solenoid valves).
AUX1 Bus
Power modules enable the additional connection of electric potential (24 VDC),
which can be applied by means of an AUX(iliary) bus. AUX(iliary) buses can be
used individually as a protective conductor bus or they can be used to supply
additional voltage.
Availability
Availability is the probability that a system is functional at a specific point in time. It
can be increased by redundancy, for example, by using multiple sensors at the
same measuring point.
Backplane Bus
The backplane bus is a serial data bus used by the interface module IM 151 to
communicate with the electronic modules and motor starters and to supply them
with the required voltage. The connection between individual modules is
established by means of the terminal modules.
Category
Category in accordance with EN 954-01:
Safety modules can be used in safety mode up to Category 4.
Channel Fault
This is a channel-specific fault, such as a wire break or a short circuit. In channel-
specific passivation, the affected channel is either automatically depassivated or
the F-module must be removed and reinserted after the fault has been eliminated.
Channel Group
The channels of a module are grouped together in a channel group. Certain
parameters in STEP 7 can only be assigned to channel groups, rather than to
individual channels.
Channel Number
In the safety functions, the inputs and outputs are addressed by means of channel
numbers. The channel number is a consecutive number starting with “0“.
Channel-Specific Passivation
With channel-specific passivation, only the affected channel is passivated when a
channel fault occurs. In the event of a module fault, all channels of the fail-safe
module are passivated.
Configuration
A configuration is a systematic arrangement of the individual modules of ET 200S.
CRC
Cyclic Redundancy Check -> CRC signature
CRC Signature
The validity of the process values in the safety message frame, the accuracy of the
assigned address references, and the safety-related parameters are ensured by
means of a CRC signature contained in the safety message frame.
Dark Period
Dark periods occur during switch-off tests and during complete bit pattern tests.
This involves test-related 0 signals being switched to the output by the fail-safe
output module while the output is active. The output is then switched off briefly
(dark period). A sufficiently slow actuator does not respond to this and remains
switched on.
Discrepancy Analysis
Discrepancy analysis is used to detect errors based on the time characteristic of
two signals with the same functionality. Discrepancy analysis is initiated when
different levels are detected in two associated input signals. After a programmable
time interval (discrepancy time) has elapsed, a check is carried out to determine
whether or not the discrepancy has disappeared. If not, this means that a
discrepancy error exists.
A discrepancy analysis is carried out between the two input signals of the 1oo2
evaluation in the fail-safe input module.
Discrepancy Time
Discrepancy time is a period of time configured for the discrepancy analysis. If the
discrepancy time is set too high, the times for error detection and fault reaction are
extended unnecessarily. If the discrepancy time is set too low, availability is
decreased unnecessarily because a discrepancy error is detected when, in reality,
no error exists.
DP Master
A DP master is a master that behaves in accordance with the PROFIBUS standard
EN 50170/A2.
DP Slave
A DP slave is a slave operated on the PROFIBUS with the PROFIBUS-DP protocol
that behaves in accordance with the PROFIBUS standard EN 50170/A2.
Fail-Safe Modules
Fail-safe modules are ET 200S modules that can be used for safety-related
operation (in safety mode) in the ET 200S distributed I/O system. These modules
are equipped with integrated safety functions.
Fail-Safe Systems
Fail-safe systems (F-systems) ensure that safety functions can be executed
reliably and without error (functional safety). If individual components fail, the safety
functions are retained.
F-CPU
An F-CPU is a central processing unit with fail-safe capability that is permitted for
use in S7-300F/S7-400F/FH. For S7-400F/FH, the F-copy license allows the
central processing unit
to be used as an F-CPU. That is, it can execute a safety program. No F-copy
license is required for S7-300F. A standard user program can also be run on the F-
CPU.
F-I/O
F-I/O is a group designation for fail-safe inputs and outputs available in
SIMATIC S7 for integration in the S7-300F and S7-400F/FH fail-safe systems.
The following F-I/O modules are available:
· S7-300 fail-safe signal modules
· Fail-safe electronic modules in the ET 200S distributed I/O system
(only for S7-300F)
· Fail-safe DP standard slaves (only for S7-300F)
Module Fault
Module faults can be external faults (for example, missing load voltage) or internal
faults (for example, processor failure). An internal fault always requires module
replacement.
Monitoring Time
Time monitoring of message frames updates takes place when the F-CPU
specifies a sign of life to the fail-safe module.
A valid current message frame must be received by the F-CPU with a new sign of
life within a configurable monitoring time.
M-Switch
In ET 200S F-modules, every fail-safe digital output consists of a P-switch (DOx P
current sourcing switch)and an M-switch (DOx M current sinking switch). The load
is connected between the P-switch and the M-switch. Both switches are always set
so that voltage is applied to the load.
Parameter Assignment
When parameters are assigned by means of PROFIBUS-DP, slave parameters are
transferred from the DP master to the DP slave.
When parameters are assigned to modules, STEP 7 configuration software is
used to set module behavior.
Passivation
Passivation of digital output channels means that the outputs are deenergized.
Passivation of the input channels occurs when the inputs transfer a fail-safe value
to the F-CPU, irrespective of the current processor value.
PG
Programming devices (PGs) are compactly designed personal computers
especially made for use in an industrial setting. A programming device (PG) is
entirely equipped for programming SIMATIC automation systems.
Prewiring
Prewiring entails wiring the terminal modules before inserting the electronic
modules.
Process Image
The process image is a component of the system memory of the CPU. At the
beginning of the cyclic program, the signal states of the input modules are
transferred to the process image of the inputs. At the end of the cyclic program, the
process image of the outputs are transferred as a signal state to the DP slave.
PROFIBUS
PROFIBUS stands for PROcess Field BUS, a German process and field bus
standard set forth in the PROFIBUS standard EN 50170/A2. This standard
specifies functional, electric, and mechanical properties for a bit-serial field bus
system.
PROFIBUS is available with the following protocols: DP (= distributed I/O), FMS (=
Fieldbus Message Specification), PA (= Process automation), or TF (=
Technological functions).
PROFIsafe
PROFIsafe is a safety-related bus profile of PROFIBUS DP/PA for communication
between the safety program and the F-I/O.
PROFIsafe Address
Every fail-safe module has a PROFIsafe address over which it sends safety
message frames to the F-CPU and receives safety message frames from the F-
CPU.
Proof-Test Interval
A component must be set in the fail-safe state following the proof-test interval. That
is, it is replaced by an unused component or it is proven to be completely error-
free.
P-Switch
-> See M-Switch.
Redundancy, Availability-Enhancing
Availability-enhancing redundancy means multiple availability of components to
ensure that components continue to function even in the event of hardware faults.
Redundancy, Safety-Enhancing
Safety-enhancing redundancy means multiple availability of components with the
use of comparison to reveal hardware faults (for example, 1oo2 evaluation in fail-
safe modules).
Response Time
Response time starts with the detection of an input signal and ends with the
modification of a gated output signal.
The actual response time is between the shortest and the longest response time.
The longest response time must be used as a reference for configuring a system.
For fail-safe digital inputs, the response time begins with a signal change at the
digital input and ends when the safety message frame is safely prepared at the
backplane bus.
For fail-safe digital outputs, the response time begins with an incoming safety
message frame from the backplane bus and ends with a signal change at the
digital output.
Reversing Starter
A reversing starter is a motor starter that determines the rotational direction of a
motor. It comprises a circuit-breaker and two contactors.
Safe State
The basic principle of the safety concept in F-systems is the existence of a safe
state for all process variables. For digital F-modules, this is always the value “0“.
Safety Function
Safety function is a mechanism integrated in fail-safe signal modules enabling
them to be used in fail-safe systems.
In accordance with IEC 61508, a safety function is implemented by a safety
system to ensure that the system is kept in a safe state or brought into a safe state
in the event of a particular fault
Safety Mode
Safety mode is the operating mode of the F-I/O that allows safety-related
communication by means of safety message frames.
ET 200S fail-safe modules are designed for operation only in safety mode.
Safety Note
The safety note contains important information relating to approval and safety-
related use of a product.
Sensor Evaluation
There are two types of sensor evaluation:
· 1oo1 evaluation: The sensor signal is read once.
· 1oo2 evaluation:To increase availability, the sensor signal is read in twice by
the same module and compared internally.
Sensors
Sensors are used for exact measurement of paths, positions, velocities, rotational
speeds, mass, etc.
Standard Operation
In the standard operation mode of F-I/O, safety-related communication by means
of safety message frames is not possible; only standard communication is possible
in this operating mode.
S7-300 F-SMs can be used in standard operation or safety mode. ET 200S fail-
safe modules are designed for operation only in safety mode.
Static Parameters
Static parameters can only be set when the CPU is in STOP mode and cannot be
changed by means of SFC (system function) while the user program is running.
Terminal Module
The ET 200S distributed I/O system is terminated with a terminal module. If a
terminal module is not inserted, the ET 200S is not ready for operation.
Voltage Group
A voltage group is a group of electronic modules supplied by a power module.
Edition 07/2003
This Product Information contains important information about the Documentation packages S7 F
Systems, 6ES7 988-8FA10-8BA0 and S7 Distributed Safety, 6ES7 988-8FB10-8BA0. The Product
Information is part of the product supplied and the information in it should be considered more
up-to-date if uncertainties arise.
Range of Validity
This product information represents a supplementary documentation to the manual Distributed I/O System
ET 200S, Fail-safe Modules, A5E00103686-01, as of Edition 03/2002.
The new fail-safe power module PM-D F DC24V PROFIsafe has been described thoroughly in this product
information.
Siemens Aktiengesellschaft
Copyright
Copyright Siemens AG 2003 All rights reserved.
The reproduction, transmission or use of this document or its contents is not permitted without express written authority.
Offenders will be liable for damages. All rights, including rights created by patent grant or registration of a utility model or
design, are reserved.
The reproduction, transmission or use of this document or its We have checked the contents of this manual for agreement with
contents is not permitted without express written authority. the hardware and software described. Since deviations cannot be
Offenders will be liable for damages. All rights, including rights precluded entirely, we cannot guarantee full agreement. However,
created by patent grant or registration of a utility model or the data in this manual are reviewed regularly and any necessary
design, are reserved. corrections included in subsequent editions. Suggestions for
improvement are welcomed.
Siemens AG
Bereich Automation and Drives
Geschaeftsgebiet Industrial Automation Systems ©Siemens AG 2003
Postfach 4848, D- 90327 Nuernberg Technical data subject to change.
Safety Note
! Please note that for AK6/SIL3/Cat.4 it is not allowed to combine F-DI-/F-DO
modules and standard-DI-/DO-/FM modules in the same potential group.
You can combine F-DI-/F-DO modules and standard DI-/DO-/FM modules in a
potential group for AK4/SIL2/Cat.3.
Safety Note
! If an F module with fail-safe outputs is passivated over a long period of time
(> 100 h) without the error being corrected, the possibility of a second error
activating the F module unintentionally and putting the F system in a dangerous
state cannot be ruled out.
Although the probability of the occurrence of such hardware error is very low, an
unintentional activation of F modules with fail-safe outputs must be prevented via
circuit technique or organizational measures. One possibility is switching off the
power supply of the passivated f module within a period of times von z. B. 100 h.
The required measures are standardized for plants with product. For all other
plants, the plant operator has to develop his own concept for the necessary
measures to be taken and have them acknowledged by a certified expert.
Note
Lightning protective measures always require individual consideration of the
entire plant. Relatively complete protection against overvoltage can only be
achieved when the entire surrounding building is designed for overvoltage
protection. Above all, this affects building features even in the design phase.
If you wish to inform yourself in depth about overvoltage protection, we
therefore recommend that you contact a Siemens representative or a
company specialized in lightning protection.
Safety Note
! The safety parameters in the technical specification are valid for a proof-test
interval of 10 years and a repair time of 100 hours.
1 0 0 .0
50
20
1 0 .0
5,0
2,0
1 .0
0,5
0, 3
0 .1
20 50 100 200 500 750 1000 1250 1500 1750 2000
Load c urrent in mA
Remedy:
1. Determine the load current and the capacity of the load.
2. Determine the working point in the graph above.
3. If the working point is above the curve, you must connect a resistor in parallel
to raise the resistance of the load current to bring it to a new working point
below the curve.
Ausgang-
s
P2
Output
driver
Central
ground
point
M P1
Load
M M-switch 1P5
Readback M-rail
Figure 2 Relationship between load resistance and connectable load resistance (example with EM 4 F-
DO DC24V/2A PROFIsafe)
Safety Note
! The digital electronic module 4DO DC24V/0,5A (order no. 6ES7 132-4BD00-
0AA0) is the only standard ET 200S module released for the safety-related
shutdown according to SIL2.
If you want to avoid the errors described above entirely, we recommend you use
the P switch/M switch fail-safe electronics modules 4 F-DO DC24V/2A PROFIsafe
with standard ET 200S power modules (see Chapter 9.4 and table 3-3 in Chapter
3.3) instead of the standard DO modules.
Advantage and disadvantage of the safety-related shutdown of the standard
DO modules via the PM-D F DC24V PROFIsafe:
Advantage: inexpensive solution
Disadvantage: When an error is detected in the process or on the PM-D F DC24V
PROFIsafe, all the affected outputs are shutdown globally and simultaneously.
Advantage and disadvantage of the individual shutdown of the F modules
with fail-safe outputs:
Advantage: The scope of a shutdown is at a minimum when an error is detected. In
addition, critical processing states can be reacted to gradually or outputs can be
shutdown.
Disadvantage: expensive.
P1 (P)
P1 P2
DO0 DO0 DO1 DO1 (P) (M) P2 (M)
L+ M (P) (M) (P) (M) DO2 DO2 DO3 M DO4 M DO5 M
C1 C2 C3 C4
C1 C3
C2 C4
L+ M
Figure 3 Wiring Diagram for Each of Two Relays on DO 0 and DO 1 of the PM-D F 24 VDC PROFIsafe
Further information
The IM 151-7 F-CPU is described in a product information, part of the
documentation package S7 Distributed Safety.
The information in the following manuals applies to the implementation of ET 200S
with fail-safe modules in S7 F/FH systems:
• Distributed I/O System ET 200S, Fail-safe modules
• S7 F and S7 FH Systems
1 2 3 4 5 6 7 8 Terminator Slot
IM 151-1 High
PROFIsafe
F-CM
3~
M M
3~ 3~
Figure 4 Example of an ET 200S installation with fail-safe motor starters and contact replicator
Table 3 Assigning power modules to electronic modules and to the safety class
Parameter Length
The parameter length for a PM-D F DC24V PROFIsafe is 20 bytes.
Order Number
3RK1903-3BA00
Properties
The characteristics of the power module PM-D F DC24V PROFIsafe are as follows:
• 6 safety groups SG 1 to SG 6 (Safety Group)
• Output current of SG 1 ... SG 6 respectively: 3 A (accumulative current 6 A)
• Rated load voltage: 24 VDC per safety group
• suitable for the supply of:
- fail-safe motor starter F-DS1e-x, F-RS1e-x
- fail-safe contact replicators F-CM,
- fail-safe power modules / expansion modules PM-D F X1.
- Expansion modules Brake Control xB1, xB2, xB3 and xB4
• Group error message (SF; red LED)
• Status display for each safety group (SG1 to SG6; green LED)
• Status display for the load power supply (PWR; green LED)
• Status display for the electronic power supply (U1; green LED)
• maximum safety class AK6/SIL3/Cat.4
Note
Please observe the safety notes described in this Distributed I/O System
ET 200S manual, Fail-safe Module, which are also valid for all fail-safe modules
in general. They are also valid for the PM-D F DC24V PROFIsafe.
Condition Achievable
AK/SIL/Category
fail-safe motor starters will be expanded with the modules: AK4/ SIL2/ Category 3
• Brake Control xB3 and xB4
Power is supplied to: AK6/SIL3/Category 4
• fails-safe motor starters F-DS1e-x and
F-RS1e-x only,
• fail-safe contact replicators F-CM,
• fail-safe power modules / expansion modules PM-D F X1.
fail-safe motor starters will be expanded with the modules:
• Brake Control xB1 and xB2
Note
The safety classes AK4/SIL2/Cat.3 and AK6/SIL3/Cat.4 specified in the table
above can only be achieved with the modules specified in the "Condition" column.
Configuration with other modules (e. g. motor starters DS1-x/RS1x, DS1e-x/
RS1e-x, DSS1e-x) are not permissible for safety-related use.
PM-D F
PROFIsafe
Display of group errors - red
24 VDC 24 VDC
(Power supply)
M M
(Power supply)
Safety Note
! The SF LED and the status displays of the outputs must not be evaluated for
safety relevant activities.
Terminal Designation
20 24 VDC Rated load voltage 24 VDC for: inserted power modules and
bus bar SG 1 to SG 6 and U 1
21 M Ground
27 24 VDC Rated load voltage 24 VDC for: inserted power modules and
bus bar SG 1 to SG 6 and U 1
28 M Ground
Block Diagram
...SG6
M
SG_1...6
RL
U1
5V SF
24 V
20.27 P24 U1
M
21.28 M24
Figure 6 Block diagram of the PM-D F DC24V PROFIsafe
Diagnostic Functions
The following table presents an overview of the diagnostic functions of the
PM-D F DC24V PROFIsafe power module. The diagnostic functions are assigned
either to one channel or to the entire module.
Excess Always Temperature limit in the Check the load circuit wiring and
temperature module housing is the ambient temperature
exceeded causing Once the error is eliminated, the
module to be module must be removed and
deactivated reinserted or powered off and on
Internal error Always Internal module error Replace module
has occurred
Parameter Always Inserted module does Correct the configuration
assignment not match configuration (compare actual and preset
error Faulty parameter configuration), and
assignment check communication paths
Correct the parameter assignment
wrong setting of the Verify that the PROFIsafe address
PROFIsafe address at the module corresponds with
switch the configuration in STEP 7 HW
Config
External Always No supply voltage or Check the contacting of the
auxiliary supply voltage is too low module
power supply Once the error is eliminated, the
missing module must be removed and
reinserted or powered off and on
Communicati Always Error in communication Check the PROFIBUS connection
on error between F-CPU and Eliminate the interference
module due to defective
PROFIBUS connection
or higher than
permissible EMI, for
example
PROFIsafe watchdog Increase the "F watchdog time"
time too low parameter for the module in
STEP 7 HW Config
If no error has occurred, the maximum response time of the PM-D F DC24V
PROFIsafe is equivalent to the maximum internal processing time Tmax.
The max. response time of the PM-D F DC24V PROFIsafe to errors is equivalent
to the time required after an error has occurred.