Interrupts/diagnostic messages/diagnostics
6.1 Reactions to faults
Digital I/O module F-DI 4+F-DQ 2x24VDC/2A, 4xM12 (6ES7146-5FF00-0BA0)
64
Equipment Manual, V1.0, 05/2021, A5E51082342-AA
Safety repair time
The repair time used for PFH and PFD calculations is 100 hours.
Passivation is designed to provide the safe state of the safety function in the event of a single
fault. While a channel is passivated and energy is still available to the channel, there is a
possibility that additional faults can cause a dangerous failure of the safety function. You
should respond to passivations by repairing the fault or taking the passivated channel out of
service in less than 100 hours to preserve the safety integrity level of your system.
Deactivated fail-safe I/O are not being diagnosed and are subject to dangerous failure without
warning.
If any error persists for 100 hours, the entire module is passivated and can only be recovered
by power cycling.
If a repair within 100 hours is not possible, passivated fail-safe outputs should be taken out of
service by physically disconnecting or opening circuits so that faults in the fail-safe module
cannot apply energy to the load. To remove input channels from service in an operating PLC
system, references to any passivated fail-safe inputs are removed from any operating F-CPU
Safety program logic that can result in activation of a safety function output.
Do not depend on channel or module passivation to maintain safe state for more than 100
hours.
Do not depend on deactivation or lack of configuration to maintain safe state in any
circumstances.
WARNING
Unintentional activation of F-I/O module with fail-safe output
If a fail-safe output is passivated for a period longer than the safety repair time (> 100
hours) and the fault remains uncorrected, you need to be aware that an F-output could be
activated unintentionally due to a second fault. This would place the F-system in a
dangerous state.
Even though it is highly unlikely that such hardware faults occur, you must prevent the
unintentional activation of a fail-safe output by using measures for the physical circuits or
other organizational measures. One possibility is the shutdown of the power supply to the
affected F-module. Required measures are often standardized for operations with defined
design and risk reduction principles. For all other situations, necessary measures must be
defined and approved.
Additional information on passivation and reintegration
For further information about fail-safe module access, refer to the
SIMATIC Safety -
Configuring and Programming, Programming and Operating Manual
on the Internet
Summary of Contents for SIMATIC ET 200AL
Page 2: ......
Page 143: ......
Page 218: ......
Page 250: ......
Page 296: ......
Page 337: ......
Page 365: ......
Page 392: ......
Page 419: ......
Page 451: ......
Page 483: ......
Page 597: ......
Page 648: ......
Page 702: ......
Page 739: ......
Page 781: ......
Page 804: ......
Page 828: ......
Page 853: ......
Page 880: ......
Page 906: ......
Page 996: ...Diagnostics ...
Page 1121: ......
Page 1565: ......