Maintenance
14.7 Fault reactions with fail-safe modules
Automation system
System Manual, 01/2023, A5E03461182-AK
325
Failure of downstream stations is possible
from the interface module can fail when the factory settings are
restored on an interface module.
Substitute value behavior of the installed I/O modules during reset to factory settings
The I/O modules in the station do not have the configured st
atus after a "reset to factory
settings". The interface module does not acquire any input data and does not output any
output data.
Reference
You will find more information on the procedure in the STEP 7 online help.
14.7 Fault reactions with fail-safe modules
Safe state (safety concept)
The basic principle behind the safety concept is the existence of a safe state for all process
variables.
For fail-safe input and output modules, this safe state is the value "0".
Fault reactions and startup of the F-system
The safety function requires that substitute values (safe state) be output instead of process
values for a fail-safe module (passivation of the fail-safe module) in the following cases:
• When the F-system is started up
• If errors are detected during safety-related communication between the F-CPU and the F-
module via the PROFIsafe safety protocol (communication error)
• If fail-safe I/O faults or channel faults are detected (e.g., wire break, discrepancy error)
Detected faults are written to the diagnostic buffer of the F-CPU and communicated to the
safety program in the F-CPU.