86
Rockwell Automation Publication ICSTT-RM446N-EN-P - April 2018
Chapter 4
AADvance Functional Safety System Implementation
• diagnostics, fault indications and degradation of input modules
• initiating diagnostics, fault declaration and for some fault conditions the
degradation of output modules
• recovery mode operation
Reaction to faults in the processor module
The processor module reports faults by front panel indicators and fault codes
stored in the System Event log.
SYSTEM HEALTHY
and
HEALTHY
LEDs
go RED when a fault is detected in the processor module. Fault indications are
also sent to the user application by variables that you can set up during the
system configuration process. These variables provide the following
information:
• module presence
• module health and status
• channel health and status
• an echo of the front panel indications
For a single fault deemed by the system to be a "critical failure" the processor
module enters the Recovery Mode.
Recovery Mode
Recovery Mode is a shutdown mode and uses a base level firmware. It is entered
automatically when a critical firmware failure occurs or it can be entered
manually by pressing either the processor
Fault Reset
button or enabling the
remote fault/reset join feature immediately after the module has booted up.
As an alternative firmware version it allows the following maintenance
activities:
• Update the firmware using the
ControlFLASH
utility
• Program the processor IP Address with the AADvance Discover utility
• Extract diagnostic information
In Recovery Mode the
Ready
,
Run
,
Force
and
Aux
LEDs go Amber and the
Healthy
and
System Healthy
LEDs stay Green. The System Healthy and
Healthy LEDs may go Red if a fault is detected while in the Recovery Mode.
NOTE
When in Recovery Mode the I/O communications are disabled and the
Application code is not running.