Safety Mechanisms
Fail-Safe Systems
3-4
A5E00085588-03
3.4
Startup of an F-System
Operating Modes of an S7 F/FH Systems
The operating modes of an S7 F System differ from the normal ones only in their
startup characteristics and behavior in HOLD mode. Otherwise, the system states
of the fault-tolerant system and the operating modes of the master CPU and
standby CPU occur in an S7 FH System as described in Chapter 4.
Startup Characteristics
The startup characteristics are determined by the Safety Program as follows. After
each interruption of the user program, by means of power off CPU STOP, or Safety
Program disable, startup of the Safety Program is only possible with the initial
values of the fail-safe blocks.
If a warm restart is requested during startup, a warm restart is only carried out for
the standard section of the user program. A warm restart for the fail-safe section of
the user program is not possible; the Safety Program starts up with the initial
values of the fail-safe blocks in the same way as after a cold restart.
To handle Warm or Cold Start of the Safety Program, additional blocks (DB_RES)
and calls that must not be changed are automatically inserted in the OB 100 and
blocks DB_INIT are automatically placed into @F_DbInit at compile time.
Startup Protection
A startup of the Safety Program using the initial values can also be triggered by a
handling error or an internal error. If the process does not permit this, a reaction to
this must be programmed in the Safety Program. The F_START block is available
to signal a startup of the Safety Program with the initial values (see the section
entitled "Programming the Startup Characteristics).
Hot Restart Protection
If a hot restart (Power Off > Power On) of the process is not permissible after the
reaction of the S7 F System to an internal fault, manual enabling of the outputs
after the startup of the Safety Program with the initial values (see above) must be
programmed.
HOLD Mode
HOLD mode is not supported for the S7 F/FH systems. If the execution of the user
program is stopped by a HOLD request, the F-I/Os go to failsafe (Outputs
disabled). Once the CPU is back in RUN mode, the Safety Program performs a
Full Shutdown. The Shutdown logic must be Restarted and the F-I/Os
reintegrated.
See Also
Programming the Startup Characteristics
Содержание SIMATIC S7 F
Страница 8: ...Important Information Fail Safe Systems viii A5E00085588 03 ...
Страница 16: ...Contents Fail Safe Systems xvi A5E00085588 03 ...
Страница 38: ...Product Overview Fail Safe Systems 1 22 A5E00085588 03 ...
Страница 56: ...Getting Started Fail Safe Systems 2 18 A5E00085588 03 ...
Страница 70: ...Safety Mechanisms Fail Safe Systems 3 14 A5E00085588 03 ...
Страница 115: ...Programming Fail Safe Systems A5E00085588 03 5 33 Examples Receive Block Send Block ...
Страница 154: ...Programming Fail Safe Systems 5 72 A5E00085588 03 ...
Страница 166: ...Operation and Maintenance Fail Safe Systems 6 6 A5E00085588 03 ...
Страница 332: ...Fail Safe Blocks Fail Safe Systems 8 144 A5E00085588 03 ...
Страница 344: ...References Fail Safe Systems B 2 A5E00085558 03 ...
Страница 350: ...Glossary Fail Safe Systems Glossary 6 A5E00085588 03 ...