The H51q System Family
14
4.2 Concepts of the Safety Switch-Off at H51q
In the system descriptions of the safety related PES H51q-MS, -HS, -HRS the ways for shut-
down if a fault occurs are shown. Depending on the fault location the reactions of the systems
are fixed or they can be defined in the user program.
Parameters are set
– in the resource properties I/O parameter
– by activating of a system variable for emergency shutdown
– via function block H8-STA-3.
An overview of the system variables including the corresponding error code you will find in the
operating system manual.
Reaction to faults of safety-related modules during operation:
Definitions:
Double fault = fault within an output channel and the electronic switch-off part of a testable out-
put module
Abbreviations in the table:
CU Central Module
I/O bus Input/output bus
I/O subrack Input/output subrack
WD Watchdog signal
More explanations on the following page.
Location of fault
I/O parameter in the pro-
perties of the resource
Reaction of system
Output modules
single error
(also voltage failure)
- display only or
- normal operation
Module switch-off
- normal operation and
one function block
H8-STA-3 per group
Group shutdown
- Emergency off WD switch-off
of the appertaining CU
I/O bus within I/O subrack or
double fault in
output modules
- display only Slot with error code in I/O
subrack display of the
CPU,
WD is still switched on
- normal operation WD switch-off of the apper-
taining coupling module
- Emergency off WD switch-off
of the appertaining CU
Central modules (CU) or
I/O bus between CU and cou-
pling modules
independent of the I/O
parameter
WD switch-off
of the appertaining CU
Input modules independent of the I/O
parameter
Operation of 0-signal for all
inputs of this module
Independent of a fault of the
output module
System variable for emer-
gency switch-off activated,
independent of the I/O
parameter
WD switch-off
of the appertaining CU
Table 5: Concepts of the Safety Switch-Off at H51q