Fault tolerance
Hot-Standby with SIMATIC S7-400H
| The SIMATIC S7-400H is a controller with two H CPUs of the same type; in the event of a fault, changeover takes place from the master system to the standby station. It is suitable for high-availability processes with hot standby requirements (processes with changeover times shorter than 100 ms). Two CPUs are available for the SIMATIC S7-400H to suit different performance requirements. |
 |
Apart from high volumes, the H-CPUs are also characterized by high performance. The two H CPUs are connected over fiber-optic cables and socalled Sync modules that can be directly plugged into the CPU. This means that no slot in the rack is lost and that communication is extremely fast. The Sync modules can be replaced with the voltage applied.
Synchronization
The method of event-driven synchronization supports fast and bumpless changeover to the redundant CPU in the event of a fault. It resumes processing at the point of interruption without any loss of information or interrupts. The operating system ensures that all commands, which if executed independently would produce different states in the two systems, operate in synchronism. No programming or parameterization has to be performed by the user for this purpose.
Design
The central devices can be configured in two different ways:
- When the subunits have to be completely separated from each other for availability reasons, it is appropriate to use two standard racks (UR1 and UR2). Each rack accommodates one CPU and one power supply (PS). If extremely high availability is required, two redundant power supply modules can be used. The distance between the two racks can be up to 10 km.
- Two CPUs, each with either a single or a redundant power supply, are plugged into the UR2-H rack with a segmented backplane bus. This supports an extremely compact configuration.
Distributed I/O
Depending on the type of connection, the following I/O components can be used:
- All PROFIBUS slaves for single-sided connection
- ET 200M for switched and redundant connection
Engineering
Programming is possible, as in the case of a standard system, in all STEP 7 programming languages. The programs can easily be ported from standard systems to a redundant system and vice-versa. When the program is loaded, it is automatically distributed onto the two redundant CPUs. The functions and configurations specific to redundancy are parameterized using the S7 H-Systems option package (integrated into STEP 7 Version 5.3 or higher). The planning engineer is free to concentrate solely on controlling the process.
Diagnostics / Module replacement
Apart from the standard diagnostic functions, the following functions are also available:
- With the integrated self-diagnostics functions, the system detects and signals errors before they can affect the process. They enable the faulty components to be identified and replaced quickly which speeds up repairs.
- All components can be replaced during normal operation (online repair). When a CPU is replaced, all the current programs and data are automatically reloaded. It is also possible to modify the program during normal operation, e.g. changing and reloading function blocks.
- Changes can also be made to the configuration during normal operation, e.g. adding or removing of DP slaves or modules, changing the memory configuration of the CPU.