Safety Mechanisms
Fail-Safe Systems
A5E00085588-03
3-3
3.3 Fault
Reactions
Safe State
The basis of the safety concept is that there must be a safe, neutral position for all
process variables. In the case of binary signal modules, this is always the value
"0".
Fault Reactions in the CPU and Operating System
If the CPU detects a fault by means of the hardware (time monitoring) or operating
system (self-tests etc.), the Safety Program may become disabled or a switchover
may occur if the fault occurs on the master side in a redundant system.
Fault Reactions in the Safety Program
All the fault reactions of the Safety Program lead to a safe state:
Note
When a failure is detected, Full Shutdown occurs and all F-run-time groups in the
Safety Program are disabled.
When a failure is detected, Partial Shutdown occurs and an F-run-time group
(where the failure occurs) is disabled, leaving other run-time groups activated.
•
Full and Partial Safety Program Shutdown (F_SHUTDN input
SHUTDOWN=Full and all F-run-time groups disabled). This state can be
reversed by two methods: restarting the shutdown logic through the RESTART
input on the F_SHUTDN block or by stopping the F-CPU and forcing a
coldstart. You can find information on restart behavior, startup protection and
restartup protection in section, "Startup of an F-System".
•
Power failure-proof disabling of the safety-related outputs. I/O or
communication faults lead to the affected outputs being disabled. The outputs
can be enabled after user acknowledgment via an ACK_REI input on the F
channel driver.
Typically, in reaction to the detection of faults, non-safety-related diagnostic and
report functions can be executed.
A master/standby switchover is initiated in the S7 FH system if the master is
switched to STOP mode.
You will find a list of causes of F-run-time group shutdown in the section "Error
Information After F-Run-time group shutdown".
Summary of Contents for SIMATIC S7 F
Page 8: ...Important Information Fail Safe Systems viii A5E00085588 03 ...
Page 16: ...Contents Fail Safe Systems xvi A5E00085588 03 ...
Page 38: ...Product Overview Fail Safe Systems 1 22 A5E00085588 03 ...
Page 56: ...Getting Started Fail Safe Systems 2 18 A5E00085588 03 ...
Page 70: ...Safety Mechanisms Fail Safe Systems 3 14 A5E00085588 03 ...
Page 115: ...Programming Fail Safe Systems A5E00085588 03 5 33 Examples Receive Block Send Block ...
Page 154: ...Programming Fail Safe Systems 5 72 A5E00085588 03 ...
Page 166: ...Operation and Maintenance Fail Safe Systems 6 6 A5E00085588 03 ...
Page 332: ...Fail Safe Blocks Fail Safe Systems 8 144 A5E00085588 03 ...
Page 344: ...References Fail Safe Systems B 2 A5E00085558 03 ...
Page 350: ...Glossary Fail Safe Systems Glossary 6 A5E00085588 03 ...