
TP1000F Mobile RO
Operating Instructions, 08/2017, A5E39831415-AA
25
Safety instructions
2
2.1
General safety instructions
WARNING
Personal injury or material damage due to non-compliance with safety regulations
Failure to exactly comply with the safety regulations and procedures in this document can
result in hazards and disable safety functions. This can result in personal injuries or
material damage.
Closely follow closely the safety regulations and procedural instructions in each situation.
Observe the safety and accident prevention regulations applicable to your application in
addition to the safety instructions given in this document.
Safety during configuration and operational safety of the plant
WARNING
Personal injury or material damage due to improper configuration of the plant
The configuration engineer for plant control must take precautions to ensure that an
interrupted program will be correctly integrated again after communication failures, voltage
dips or power outages.
A dangerous operating state must not be allowed to occur - not even temporarily - during
the entire execution of the control program, even during a troubleshooting.
WARNING
Programming startup protection in the safety program
At a STOP/RUN transition of an F-CPU, the standard user program starts up as usual.
When the safety program starts up, all FDBs are initialized with values from the load
memory, same as during a cold restart. As a result, saved error information is lost. The F-
system performs an automatic reintegration of the F-I/O. A startup of the safety program
with values from the load memory can also be initiated by a handling error or an internal
error. If the process does not permit this, a (re)start protection must be programmed in the
safety program. The output of process values must be disabled until manually enabled; this
must not occur until the process values can be output without posing a hazard and errors
have been eliminated.