51-52-25-133 - Redundancy Overview & System - Sep23 - Rev.17
51-52-25-133 - Redundancy Overview & System - Sep23 - Rev.17
Redundancy
Overview & System Operation
Warranty/Remedy
Honeywell warrants goods of its manufacture as being free of defective materials and faulty workmanship. Contact
your local sales office for warranty information. If warranted goods are returned to Honeywell during the period of
coverage, Honeywell will repair or replace without charge those items it finds defective. The foregoing is Buyer's sole
remedy and is in lieu of all other warranties, expressed or implied, including those of merchantability and
fitness for a particular purpose. Specifications may change without notice. The information we supply is believed
to be accurate and reliable as of this printing. However, we assume no responsibility for its use.
While we provide application assistance personally, through our literature and the Honeywell web site, it is up to the
customer to determine the suitability of the product in the application.
Abstract
This manual gives an overview of the ControlEdge HC900 Redundancy architecture and products.
References
The following list identifies all documents that may be sources of reference material for topics discussed in this
publication.
ControlEdge HC900 Process & Safety Controller User and Installation 51-52-25-154
Manual
Revision 17 ControlEdge HC900 Controller Redundancy Overview & System Operation iii
Sep 2023
Contents
Corporate http://www.honeywell.com
Symbol Definitions
The following table lists those symbols that may be used in this document to denote certain conditions.
Symbol Definition
WARNING
PERSONAL INJURY: Risk of electrical shock. This symbol warns the user of a
potential shock hazard where HAZARDOUS LIVE voltages greater than 30 Vrms,
42.4 Vpeak, or 60 Vdc may be accessible. Failure to comply with these
instructions could result in death or serious injury.
Protective Earth (PE) terminal. Provided for connection of the protective earth
(green or green/yellow) supply system conductor.
Functional earth terminal. Used for non-safety purposes such as noise immunity
improvement. NOTE: This connection shall be bonded to protective earth at the
source of supply in accordance with national local electrical code requirements.
Earth Ground. Functional earth connection. NOTE: This connection shall be bonded
to Protective earth at the source of supply in accordance with national and local
electrical code requirements.
Revision 17 ControlEdge HC900 Controller Redundancy System Operation & Overview Summary v
Sep 2023
Contents
Contents
Introduction ..................................................................................................................... 1
Overview .................................................................................................................................................... 1
Purpose of this document ...................................................................................................................................... 1
What’s in this document ......................................................................................................................................... 1
Documentation .......................................................................................................................................... 1
Purpose of the product .................................................................................................... 2
Product architecture ........................................................................................................ 2
Key components ............................................................................................................. 5
Redundant Controller Rack ....................................................................................................................... 5
CPU ....................................................................................................................................................................... 6
Power ..................................................................................................................................................................... 6
Redundant Switch Module (RSM) .......................................................................................................................... 6
Remote I/O Racks ..................................................................................................................................... 7
Dual-Port Scanner2 Module ................................................................................................................................... 7
Power Status Module ............................................................................................................................................. 7
I/O Modules ............................................................................................................................................................ 8
Operator Interfaces & Serial Ports ............................................................................................................ 8
Networking ...................................................................................................................... 9
System Network ........................................................................................................................................ 9
System Network Supervisory Functions.................................................................................................. 12
To PC Applications............................................................................................................................................... 12
To Peer ControlEdge HC900 Controllers ............................................................................................................. 12
Connection options .............................................................................................................................................. 13
I/O Network to Remote Racks ................................................................................................................. 14
Device Network (Serial) ........................................................................................................................... 15
Modbus Host ........................................................................................................................................................ 15
Modbus Device .................................................................................................................................................... 15
Modbus Host and/or Device ................................................................................................................................. 15
Remote Access ....................................................................................................................................... 15
Configuration ................................................................................................................. 16
Lead Controller configuration .................................................................................................................. 16
Configuration & Setup Parameters for Redundant Controllers ............................................................................. 16
Reserve Controller configuration ............................................................................................................. 16
Software .................................................................................................................................................. 17
HC Designer & HC Utilities PC Software ............................................................................................................. 17
Downloading configuration from PC to controller ................................................................................................. 17
Configuration storage ........................................................................................................................................... 18
Configuration edits ............................................................................................................................................... 18
Uploading configuration from controller to PC ...................................................................................................... 18
Downloading to multiple controllers ...................................................................................................................... 18
Configuration backup ........................................................................................................................................... 18
Configuration conversion ..................................................................................................................................... 18
Monitoring configurations ..................................................................................................................................... 19
Operation ...................................................................................................................... 20
Revision 17 ControlEdge HC900 Controller Redundancy System Operation & Overview Summary vii
Sep 2023
Contents
Overview .................................................................................................................................................. 20
Start-Up ................................................................................................................................................... 20
Modes of operation .................................................................................................................................. 20
RUN Mode (Locked) ............................................................................................................................................ 21
RUN/PROGRAM Mode (Unlocked)...................................................................................................................... 21
PROGRAM Mode (Locked) .................................................................................................................................. 21
Steady State Operations ......................................................................................................................... 22
Execution time...................................................................................................................................................... 22
Execution sequence ............................................................................................................................................. 22
Lead/Reserve controller synchronization ............................................................................................................. 23
Failover .................................................................................................................................................... 24
Automatic Failover ............................................................................................................................................... 24
Manual Failover.................................................................................................................................................... 24
Failover Performance ........................................................................................................................................... 24
Redundancy Diagnostic Monitoring ...................................................................................................................... 24
IO Module Redundancy ........................................................................................................................... 25
Overview .............................................................................................................................................................. 25
Installation ..................................................................................................................... 26
Installing the Redundant Controller Rack ................................................................................................ 26
Installing the I/O Racks ........................................................................................................................... 26
Installing Networking Equipment ............................................................................................................. 27
I/O Network .......................................................................................................................................................... 27
Supervisory / Peer Network.................................................................................................................................. 27
Installing a Panel-Mounted Operator Interface ....................................................................................... 27
3rd Party Panel-Mounted OI................................................................................................................................. 27
Installing PC Hosts .................................................................................................................................. 28
Honeywell HC Designer & HC Utilities Software .................................................................................................. 28
Honeywell Experion Software .............................................................................................................................. 28
3rd Party PC Application Software ....................................................................................................................... 28
Troubleshooting ............................................................................................................ 29
Diagnostic Indicators ............................................................................................................................... 29
Diagnostic Monitoring from HC Designer and HC Utilities PC Software ................................................. 29
Status data available via Supervisory PC ............................................................................................... 29
Troubleshooting ....................................................................................................................................... 30
Servicing ....................................................................................................................... 33
Module Replacement ........................................................................................................................................... 33
C75 Module Replacement .................................................................................................................................... 33
Redundancy Switch Module Replacement ........................................................................................................... 33
Scanner2 Module Replacement ........................................................................................................................... 33
C75/C75S Power Supply Replacement ............................................................................................................... 33
Non-Redundant Power Supply for I/O Rack or Redundant Split Rack Replacement ........................................... 34
Optional Redundant Power Supply for I/O Rack Replacement ............................................................................ 34
Power Status Module Replacement ..................................................................................................................... 34
I/O Module Replacement ..................................................................................................................................... 34
Redundant I/O Module Replacement ................................................................................................................... 35
viii ControlEdge HC900 Controller Redundancy Overview & System Operation Revision 17
Sep 2023
Contents
Revision 17 ControlEdge HC900 Controller Redundancy System Operation & Overview Summary ix
Sep 2023
Contents
Figures
Figure 1 - ControlEdge HC900 Redundant Controller architecture (Star topology) ..................................................... 2
Figure 2 - ControlEdge HC900 Redundant Controller Architecture (Ring topology) ................................................... 3
Figure 3 - ControlEdge HC900 Split Rack Architecture (Star topology) ...................................................................... 3
Figure 4 - ControlEdge HC900 Split Rack Architecture (Ring topology) ..................................................................... 4
Figure 5 Redundant controller rack components ........................................................................................................... 5
Figure 6 Redundant Controller on 900R01.................................................................................................................... 5
Figure 7 Ethernet switch with redundant controller..................................................................................................... 10
Figure 8 Ethernet switches with dual networks ........................................................................................................... 10
Figure 9 Peer Data Exchange, Redundant Controllers, Non-Redundant Network ..................................................... 13
Figure 10 Peer Data Exchange, Redundant Controllers, Non-Redundant Network ................................................... 13
Figure 11 Peer Data Exchange, Redundant Controllers, Dual Networks ................................................................... 14
Figure 12 Connection from Lead controller to PC ...................................................................................................... 17
Figure 13 Modes of operation on RSM and on Split Rack Controller......................................................................... 21
Figure 14 Lead/Controller synchronization ................................................................................................................. 23
Figure 15 Connecting UIO Terminal to RTP Using Pre-Fabricated Cable ................................................................. 25
Overview
Purpose of this document
Provide an overview of the Redundant ControlEdge HC900 product.
Documentation
See References on page iii.
Product architecture
The Redundant ControlEdge HC900 controller uses a separate rack for controller processors mounted
separately from I/O Racks
Key components
• Holds two redundant C75 CPUs, two power supplies, and one Redundancy Switch Module (RSM).
• Contains the back-plane for C75-to-C75 communications, power, and interface to RSM.
• The C75 Controller Rack does not support any local I/O Modules; I/O Modules are read from and written
to directly from a Scanner2 module.
•Cannot be used with C50 or C70 CPU’s. C70R/C75/C75S must be matched with another
C70R/C75/C75S CPU and must be used in 900RR0-0001 racks.
CPU
• Requires Scanner2 module(s).
• Reads inputs from I/O Racks through Scanner2 modules.
• Executes control strategy (function blocks).
• Writes outputs to I/O Racks through Scanner2 modules.
• Dual Ethernet communication ports to host systems. It is good engineering practice to isolate the control
network, E1 and E2 ports, from unknown Ethernet traffic to ensure robust reliable communications with
a properly configured firewall such as the MOXA EDR-810.
• Each C75 Controller CPU has a dedicated, single Ethernet communication port to I/O racks.
• Two RS485 serial ports – Modbus or ELN protocols for interface to OI, Modbus Host, or Modbus Device.
• Lead Controller CPU – writes to the physical outputs; serves as the single external interface to other
devices and systems (i.e., responds to requests from PC Hosts, a local Operator Interface, communicates
to ControlEdge HC900 peers, and polls network device).
• Reserve Controller CPU – executes control strategy in sync with Lead but does not write to physical
outputs; does not respond to Hosts or OI.
• Reserve Controller CPU receives configuration updates and run-time data (operator entries, supervisory
changes) from the Lead CPU with no manual user interaction. Configuration changes to a Reserve CPU
are not permitted, except through the Lead CPU where both CPUs receive the change.
• The C75 is not recommended for non-redundant applications.
• C75 non-SIL models MUST BE matched with non-SIL Scanner2s.
• C75S SIL models MUST BE matched with SIL Scanner2s S75.
Power
• Each C75 CPU has a dedicated Power Supply (two in the controller rack). Failure of the Lead CPU
power supply will cause a failover condition.
• CPU's prior to Version 6 require 900P02 power supplies for use in the redundant controller rack. If no
longer available, use 900P01 with Ferrite Filter (p/n: 51197612-001, Fair Rite p/n: 0443164151 or
equal) on incoming power cable
• Each power supply should be powered from a separate circuit protected mains.
Note: Controller in the 900R01 (Split rack installation) can have dual power supplies using Redundant
Power supply Equipment (RPE).
I/O Modules
CAUTION: For I/O redundancy, prefabricated cable length from RTP to Redundant UIO modules must be same.
• The full complement of ControlEdge HC900 Analog and Digital I/O modules are available for use in I/O
racks using the Scanner2 module connected to redundant C75 Controller CPU’s.
• Any module may be inserted into any rack slot location.
• Redundant UIO modules are supported in the ControlEdge HC900 system.
I/O modules may be replaced under power- user to take proper precautions (Refer “Redundant I/O Module
Replacement”).
Networking
System Network
Each C75 CPU provides two 10/100base T Ethernet Host ports with Modbus TCP protocol. A total of 10
sockets are available and are shared by the two ports of the CPU for host device interfacing. Either port
may be used in a non-redundant connection for host systems that do not support redundant network
communications.
Note:
It is good engineering practice to isolate the control network, E1 and E2 ports, from unknown Ethernet
traffic to ensure robust reliable communications with a properly configured firewall such as the MOXA
EDR-810.
• Requires Honeywell (PN 50008930-001) or commercially available industrial switches, routers, etc for
10/100-baseT connection to the host/peer network. See Figure 7.
• Supports single or dual network interface to PC Hosts.
E1 and E2 ports must be configured for separate subnets.
• Supports single or dual network interface to peer ControlEdge HC900 Redundant Controllers.
• Supports single network interface to peer ControlEdge HC900 Non-Redundant Controllers or other
Modbus/TCP devices.
• Network changes such as setting IP addresses must be made with the controller in the Program mode.
See Modes of operation on page 20.
• Maximum distance of system network (per 10/100 baseT specification, 100 meters per segment).
• Host devices or Managed switches (if used) must be configured to Auto Negotiate (speed and duplex).
The following table lists the Qualified Ethernet Switches used to connect CPU with the remote IO rack:
For applications where the host supports redundant networks, two separate Ethernet switches/routers are
required, one for each port of the CPUs to supply dual network connection. See Figure 8.
In this configuration, a second communication path is available between the Host and the controller in the
event of an Ethernet switch /router or connection failure.
Note: The E1 and E2 ports should be configured on separate subnets. Dual Ethernet (E1 & E2) active only
in LAN and at any point only one port (default E1 port) is the active gateway for outside LAN. So, unless
E1 port fails controller will not switch active gateway to E2 or vice versa.
Connection options
Modbus Device
• The two serial ports of the C75 CPU may each be set to RS-485 and Modbus device operation.
• Supports data exchange with an external Modbus host such as a local operator panel or PC application.
• Port connections to redundant C75 CPUs should be made to both CPUs in the rack.
• Uses same local Modbus unit address for both RS-485 serial ports of the two C75 CPUs.
• A modem configuration selection extends the 3-character timeout limit of Modbus protocol for remote
access.
Remote Access
• Requires an external modem.
• Available with HC Designer software.
• Lead Controller provides communications.
Configuration
Software
HC Designer & HC Utilities PC Software
• The version number of the software should be equal to or greater than the version number of the
controller CPU being configured.
• The same software is used to configure both redundant and non-redundant ControlEdge HC900
controllers.
• Supports forward migration of existing C30, C50, C70 and C70R configurations to the C75.
Configuration storage
• Controller configurations downloaded to the controller are stored in battery backed RAM memory and
non-volatile Flash memory.
− The controller CPU executes its program from RAM memory. The battery backed RAM memory
also stores the controller dynamic status during a loss of power to allow graceful resumption of
controller operation following the interruption. If the battery is not available, startup following a
power loss will use the configuration stored in Flash memory.
Configuration edits
• On-line edits to the configuration may be downloaded to the controller.
− On-line edits made to C75 CPU configurations are stored in both RAM and Flash memory.
− HC Designer software lets you monitor the controller’s live configuration to verify edits. All edits are
made to the configuration of the Lead controller. The Reserve controller’s configuration is
automatically updated following a change to the Lead controller’s configuration.
Configuration backup
• Controller configurations may be uploaded and saved as Backup Files.
− Backup files contain all of the information needed to restore a CPU to the operating conditions at the
time the backup file was created, eliminating the need to for separate manual entries.
− Useful facility to quickly get a controller back on-line following CPU replacement.
− Backup configuration files use file extension .cbk.
Configuration conversion
• Configurations built for use with C30, C50, C70 or C70R CPUs may be saved and downloaded into C75
CPUs following a file conversion performed using the appropriate version of HC Designer software.
− To convert C30, C50, C70 or C70R configuration files for used with C75 CPUs, open the files to be
converted using HC Designer and perform a “Save As” operation and select a C75 file type.
Monitoring configurations
• Monitoring the configuration of the Lead Controller may be performed using Process Control Designer
software.
• Controller connection via Ethernet or serial.
• When Ethernet is used, HC Designer consumes one network socket.
• While in the monitor mode, viewing the function block diagram allows the user to view the input and
output values for each function block.
• Watch windows allow viewing data by parameter type and in a user specified group.
• System Monitor (ASYS) function blocks provide an output to indicate the Reserve status of the CPU.
• Redundant controller status may be monitored from HC Designer.
• A redundancy icon is provided to allow access to information in the monitor menu.
• Selections under the Utilities Tab allow users to view diagnostic status and perform maintenance level
activities.
• Redundancy Status (RSTAT) block provides additional monitoring and failover input pin. Adding the
RSTAT block to an existing configuration requires a COLD START.
Operation
Overview
In a redundant ControlEdge HC900 system, the Lead Controller performs all primary tasks including
interfacing with remote I/O racks, communicating with a local HMI, exchanging data with peer controllers,
interfacing with Modbus device, and communicating with a Host PC application. Detection of a fault or
removing power from a Reserve Controller will initiate a diagnostic prompt in the Lead Controller, but will
have no impact on the process under control. The detection of a fault or removing power from a Lead
Controller will initiate failover, that is, transfer all primary tasks to the available Reserve Controller,
establishing this controller as the new Lead. Following a failover, the new Lead Controller will remain the
Lead, even if the condition that caused the failover is corrected.
Start-Up
• Assignment of Lead and Reserve status is determined at start-up
− First available C75 assumes Lead
− In case of a tie, CPU mounted in the left position of the rack will Lead
− No user configuration or manual operations required to establish Lead / Reserve status
• Lead Controller assumes control of I/O and all external communication interfaces.
• Reserve Controller receives the configuration from the Lead Controller
Modes of operation
The modes of operation are:
• Run
This is also the SAFE mode for SIL Controllers.
• Run/Program
• Program
You can change modes with:
• key-switch on the redundancy control module
• HC Designer software
• HC Utilities software
• a command from a supervisory host (address 0000h, bit 6)
Both Lead and Reserve Controllers maintain the same mode. Placing the Lead Controller into the Program
mode will also place the Reserve Controller in the Program mode.
Execution time
ControlEdge HC900 Controllers are designed to execute control functions within fixed scan cycles for
analog data types and logic data types. In redundant controllers, the minimum scan time is 100ms for
analog data types and 25ms for logic data types; scan time varies depending on configuration.
Execution sequence
• The type of control functions executed during a scan is determined by the system configuration.
− Controller configurations contain a series of algorithms in the form of function blocks that get
executed in a fixed sequence. The first 100 function blocks are pre-assigned by the system to handle
communication tasks, alarm processing, system monitoring functions, etc. and cannot be changed by
the user. Starting with function block number 101, the user may select the type of function to be
executed.
• The sequence of function block execution is initially determined by the sequence in which the function
blocks are placed on the graphic diagram in HC Designer.
− Final desired sequence must be set by the user to achieve proper and optimum performance.
− Incorrect execution sequences can contribute to delays in processing outputs and/or improper or
unexpected operation.
• The ControlEdge HC900 controller samples all inputs before the start of a controller scan.
− Each input being used in the configuration must be assigned to a function block. The sequence order
of the function block determines when in time the actual value will be updated. It is important that
algorithms that need updated input values for their calculations have the inputs execute first in the
sequence.
• Except for Time Proportioning Output (TPO), Three-Position-Step-Control (TPSC) and Position
Proportional Output (PPO) function block types that update their physical output values while the
function blocks are being executed, all physical outputs are updated at the end of a scan.
SYNC SYNC
Write Outputs
Communications
Failover
Automatic Failover
• Triggered on any of the following conditions of the Lead Controller:
− Loss of communications with I/O Rack(s) than Reserves communication with IO Racks. (i.e. Reserve
has greater IO rack communication).
− Processor exception conditions
• Error conditions that occur in the following areas will not cause a failover:
− Loss of communications to a Host on a network
− Loss of communications to Modbus Device
− Loss of communications to Operator Interface
− Loss of communications with a Peer controller
• During the transition from the Lead to the Reserve, analog and digital output status is maintained at the
I/O racks.
Manual Failover
• Via Key Switch on the Redundancy Switch Module in the Redundant Controller Rack
• Via Software Command from HC Designer & HC Utilities PC Software
• Via Software Command from Modbus / TCP & Serial Modbus RTU Hosts
• Via command from RSTAT Function Block
Failover Performance
Failure condition detection and failover from Lead to Reserve CPU executed in 4 analog control cycles or
less.
IO Module Redundancy
Overview
The UIO modules can be used as redundant or non-redundant based on the configuration. The UIO
modules must be connected through RTP (900RTI) for using as redundant.
Use RUIO function block to configure a pair of UIO modules as redundant. UIO module pair can be placed
in any rack or slot position. In UIO redundancy user can configure only 14 channels out of 16.
Connect UIO terminal to RTP using pre-fabricated cable as shown in the above figure. For more details on
field wiring, refer “RTP (900RTI-0100) Installation manual”.
Installation
Installing PC Hosts
Honeywell HC Designer & HC Utilities Software
• Operating Systems supported: Win 7, 8 & 10 Professional (32 and 64 bit)
• PC hardware requirements (minimum):
− Pentium Class 1.2 Ghz with minimum 1 GB of RAM (minimum)
− Screen resolution – SVGA (1024x768 recommended) or better
− CD ROM drive (for loading software)
• Connects to the C75/C75S Controllers using Ethernet, USB to RS-485 converter or Modbus RTU
• Available on CD
Troubleshooting
Diagnostic Indicators
• LEDs on the front of each module are provided to indicate the module’s health. These include:
− C75/C75S Controller Status LEDs
− Scanner2 Status LEDs
− I/O Module Status LEDs
• The ControlEdge HC900 modules use a combination of color and flashing patterns to indicate fault
conditions and the type of fault detected. See the ControlEdge HC900 controller manual for a detailed
explanation of fault conditions.
• LEDs on the front of the Redundancy Switch Module indicate the Lead/Reserve status of the two
redundant C75/C75S controllers
− Reserve indicator will flash while Reserve CPU is being updated by Lead.
− Reserve controller is not available during this flashing period.
• LEDs on the front of the Power Status Module indicate the status of the redundant Power Supplies for an
I/O Rack
− ON if the power supply if functioning properly
− Off if either the 5 volt or the 24 volt source of a power supply has a fault.
ATTENTION:
With: Reserve CPU; Unsynchronized database error,
• if current lead shuts down, system will fail to back up CPU and likely see an I/O bump during transition.
• if power to Lead is lost combined with a fault then Lead will not likely failover.
Troubleshooting
Note: This table assumes the system was properly commissioned and all devices and cabling were proven
and only one failure existed prior to the failover occurrence. It also assumes Honeywell recommended I/O
Switches are being used and all Ethernet cables are properly shielded.
Cable between Scanner2 Lead determines that the If the cable is in a failed state 1. Make sure cable is
and I/O Ethernet switch Reserve can at the time of observation: plugged into
fails hard or intermittently communicate to more Scanner2
scanner2's than it can 1. On Scanner2 module look at
the port's upper LED 2. Make sure cable is
associated with prior Lead. It plugged into network
will be off. This port's lower switch
LED may or may not be off
depending on the nature of the 3. Replace the cable
cable failure.
4. Make sure cable is
2. On the I/O Link Switch properly shielded
associated with the prior Lead
look at port associated with the
Scanner2. Both of this port's
LEDs will be off.
Cable between I/O Lead determines that the If the cable is in a failed state 1. Make sure cable is
Ethernet switch and prior Reserve can at the time of observation: plugged into prior
Lead fails hard or communicate to more Lead
intermittently scanner2's than it can 1. On prior Lead look at the I/O
port. Both of this port's LEDs 2. Make sure cable is
will be off. If observed during plugged into network
the transition into the cable switch
failure these LEDs will
transition over a brief time from 3. Replace the cable
on to off.
4. Make sure cable is
2. On the I/O Link Switch properly shielded
associated with the prior Lead
look at port associated with the
C75/C70R. Both of this port's
LEDs will be off.
Lead I/O Ethernet switch Lead determines that the If the switch is in a failed state 1. Replace the Switch
electronics failure Reserve can at the time of observation: with a Honeywell
communicate to more recommended Switch
scanner2's than it can 1. On this I/O Switch check the
LEDs for abnormal activity 2. Check for and
correct any improper
2. On each Scanner2 check grounding.
the LEDs for abnormal activity
Lead I/O Ethernet switch Lead determines that the The I/O Link Switch associated 1. Investigate why
is power cycled. Reserve can with the prior Lead will show all power was
communicate to more its LEDs off while power is off temporarily lost
scanner2's than it can and then should return to
normal operations after power 2. Check that the
is re-applied (unless the switch switch is operating
was damaged during the properly. Replace if it
power cycle) is not.
Scanner2's I/O port to Lead determines that the If the port is in the failed state Replace the
prior Lead failed hard or Reserve can at the time of observation: Scanner2 module
intermittently. communicate to more
scanner2's than it can 1. On Scanner2 module look at
the port's LEDs associated
with prior Lead. One or both
should be off.
I/O port on the prior Lead Lead determines that the If the port is in the failed state Replace the prior
failed hard or Reserve can at the time of observation: Lead C75/C70R
intermittently. communicate to more module
scanner2's than it can 1. On prior Lead look at the
port's LEDs associated with
prior Lead. One or both should
be off.
Lead C75/C75S lost Reserve is not receiving On RSM module both LEDs for Restore power to
power data messages from the the prior Lead Controller will be prior Lead C75/C75S
Lead, AND off and all LEDs will be off on
the Lead Controller. The
Reserve is not receiving associated power supply
any replies from any module's LED will also be off.
Scanner2's, AND
Lead C75/C75S resets Reserve is not receiving On RSM module Reserve LED 1. Replace the
due to CPU exception data messages from the for the prior Lead C75/C75S C75/C75S module
occurrence Lead, AND will be on to indicate it is a
ready reserve or it will be 2. Check and correct
Reserve is not receiving flashing to indicate it is improper grounding
any replies from any synchronizing with the Lead
Scanner2's, AND prior to becoming a ready
reserve.
Reserve is not sensing
the physical presence of
the Lead
Lead C75/C75S hard or Reserve is not receiving 1. RSM module will indicate 1. Replace the
intermittent unit failure data messages from the the prior Reserve is now the C75/C75S module
Lead, AND Lead
2. Check and correct
Reserve is not receiving 2. The prior Lead may be in improper grounding
any replies from any one of several observable
Scanner2's, BUT states ranging from being
unpowered to being an
Reserve is still sensing unavailable Reserve.
the physical presence of
the Lead
Very high burst of network 1. RSM module will indicate Analyze network
traffic on E1 and/or E2 the prior Reserve is now the traffic to check for
ports Lead any periods of high
traffic
2. The prior Lead may be in
one of several observable
states ranging from being
unpowered to being an
unavailable Reserve.
Servicing
Module Replacement
• Servicing a failed module is accomplished by replacing only that module
Non-Redundant Power Supply for I/O Rack or Redundant Split Rack Replacement
• Requires power for the module to be turned off during replacement, which supplies power to a single I/O
Rack or Redundant Split Rack.
• IO or Redundant Split Racks may have power supplied through separate mains. Proper precautions and
safety procedures must be followed.
d. Enter “RUIO Address” details in the Rack and Module columns and then click Force Shutdown.
Note: This operation can perform only in the normal mode (not in the monitor mode).
After I/O module replacement, perform RSTRT on channel block to get channel back in operation.
Upgrading Firmware
1. PRIOR TO STARTING THE UPGRADE, THE PROCESS MUST BE TAKEN OFF-LINE. The
code download procedure requires that the controller be put into the Program mode using the
Keyswitch. In this mode, all outputs are forced to their off state.
2. Disable WI-FI on your PC, as it can interfere with firmware downloads.
3. Honeywell requires that you perform the CPU firmware upgrades individually by having only one
of the CPUs powered at a time. Please note, both CPUs must be running the same version of
software in order to operate as a redundant pair. A software version mismatch will prevent
the reserve CPU from synchronizing with the lead.
4. Code Download can take from approximately 5 minutes using Ethernet; therefore, it is highly
recommended that you do not start the code download procedure at a time when the likelihood of
a power failure is increased, such as during thunderstorms.
5. The code download function is only available through the Utilities tab of the Hybrid Control
Designer program or the Hybrid Control Utilities program. The upgrade is available via the
controller Ethernet ports.
6. Code download will clear the configuration database in the controller. Therefore, before code
download is started, you must upload it into the Hybrid Control Designer and save it. Save As the
appropriate model type and revision for which you are updating the firmware.
7. For the controller version less than 6.5X, the controller will not allow the controller firmware
download to begin if there is a low battery diagnostic for both batteries and require at least one
good to proceed.
8. The upgrade files are distributed as a complete package and must reside in a unique subdirectory
separate from any other previously distributed firmware upgrade files. Failure to comply could
result in abnormal behavior when performing the upgrade.
9. If you are planning to upgrade the firmware in the Scanner2 Racks, scanners need to be upgraded
to the latest version before controller firmware upgraded; perform the scanner upgrade with only
one of the CPUs powered. Follow the upgrade instructions provided with the new Scanner2 code.
Note: If starting with Firmware < 6.005 consult your vendor for update instructions.
Program Mode
Before starting the Controller Firmware Download, make sure the controller is in the "Program Lock" mode or
"Program mode". Note: A controller with software prior to version 4.000 must be in the "Program Lock" mode.
To enter "Program Lock" mode, turn the Mode Switch on the Redundancy Switch Module (RSM) counter-
clockwise to the position labeled "Pgm".
To enter "Program" mode, use the "Set Controller Mode" function found in "Utilities" tab of the Hybrid
Control Designer program or the Hybrid Control Utilities program. (This function no longer supported after
firmware revision 6.005).
Note: When programming the CPUs individually put the controller in the “Program Lock mode.
Download procedure
Step 1: Backup the controller configuration as described in step 6 of GETTING STARTED above.
Step 4: From the "Controller Utility Functions" select "Download to Controller". On the sub-menu, select
"Controller Firmware", then "Controller Module".
Step 5: Use the "Look in:" drop down list in the "Open" dialog box to select the drive and folder you placed
the files in.
Step 6: Select and open the file "C70Rv04_xxx.cpu" (or HC975v06_xxx.cpu or HC975SILv06_xxx.cpu)
displayed in the file list box.
Step 7: Select the "Port" and "Address" on the "Download File" dialog box.
Step 8: Click on the "Start" button in the "Download File" dialog box. The download will start, and
progress is displayed. The download itself will take several minutes.
Step 9: A "Download Succeeded" status will be displayed in the "Download File" dialog box. If a failure is
detected, an error message will appear in the Status section of the "Download File" dialog box. See "Error
Messages" for a list of possible messages and resolutions. Also see “Failure Modes”.
Step 10: Remove power from the CPU you just updated and apply power to the CPU not yet updated.
Leave the Mode switch in the “Program Lock” position. Repeat steps 2 through 9.
Step 12: Restore the configuration from the backup copy you previously made.
Step 13: Return the mode switch on the RSM to "Run" or "Run Lock" if "Program Lock" was used to do
the upgrade.
Step 14: Set Real Time Clock (RTC) via HC Designer/ Utilities (Utilities tab).
Failure Modes
If there is a download failure indication on the "Download File" dialog box:
o Check the physical connections.
o Check for power failures.
o Power cycle the controller and start download from the beginning.
Error Messages
This is a list of possible error messages that could be displayed as the result of a Download Firmware
failure:
Programming is not required; the downloaded version The version in the controller matches the version that
matches the code in the controller. was downloaded.
The downloaded file is corrupted The firmware file was bad. Replace the firmware file.
Could be caused by communication loss or controller
Failed to complete file transfer
power failure. Restart code download again.
Could be caused by communication loss or controller
Controller is not responding, code download failed
power failure. Restart code download again.
Could be caused by communication loss or controller
Failed to put instrument into loader transfer mode
power failure. Restart code download again.
Could be caused by communication| loss or controller
Failed to get controller status
power failure. Restart code download again.
Unexpected controller mode. Code download will abort. Could be caused by communication| loss or controller
The controller will now reset power failure. Restart code download again.
The controller has a hardware problem. Replace the
FLASH erase failure. Replace the controller card
controller card.
FLASH programming failure. Replace the controller The controller has a hardware problem. Replace the
card controller card.
The controller has a hardware problem. Replace the
FLASH memory failure. Replace the controller card
controller card.
An incomplete code download has been detected. Code A previous code download was aborted or failed. Code
download will proceed using the selected file download will proceed using the selected
Getting Started
Before you begin the download, there are a few things you need to be aware of:
4. Code Download can take from approximately 5 minutes plus an additional 5 minutes per scanner
when using Ethernet. Therefore, it is highly recommended that you do not start the code download
procedure at a time when the likelihood of power failure is increased, such as during
thunderstorms.
5. The code download function is only available through the Utilities tab of the Hybrid Control
Designer program or the Hybrid Control Utilities program. The upgrade is available via the
controller Ethernet ports.
6. Code download will clear the configuration database in the controller. Therefore, before code
download is started, you must upload it into the Hybrid Control Designer and save it. Save As the
appropriate model type and revision for which you are updating the firmware.
7. The controller (version <6.5x) will not allow the controller firmware downloading process to
begin if there is a low battery diagnostic for both batteries. It requires at least one good to proceed.
8. The upgrade files are distributed as a complete package and must reside in a unique subdirectory
separate from any other previously distributed firmware upgrade files. Failure to comply could
result in abnormal behavior when performing the upgrade.
Utilities Program
Download procedure
Step 1: Backup the controller configuration as described in step 6 of GETTING STARTED above.
Step 2: Make sure the controller is in "Program Lock" or "Program" mode (version <6.1x).
Step 4: From the "Controller Utility Functions" select "Download to Controller". On the sub-menu, select
"Controller Firmware", then scanner Module".
Step 5: Use the "Look in:" drop down list in the "Open" dialog box to select the drive and folder you placed
the files in.
Step 7: Select the "Port" and "Address" on the "Download File" dialog box.
Step 8: Click on the "Start" button in the "Download File" dialog box. The download will start, and
progress is displayed. The download itself will take several minutes.
Step 9: "SUCCESS", "FAILED" or "MISSING" status will be displayed in the "Download File" dialog box
for each of the five possible scanners. If status of any of the scanners is "FAILED", see "Error Messages"
for a list of possible messages and resolutions. Also see “Failure Modes”. The same applies for any
scanners that are present but have a status of MISSING".
Step 10: Restore the configuration from the backup copy you previously made.
Step 11: Return the mode switch on the RSM to "Run" or "Run Lock" if "Program Lock" was used to do
the upgrade.
Failure Modes
If there is a download failure indication on the "Download File" dialog box:
o DO NOT cycle the controller or scanner power.
o Power cycle the controller and start download from the beginning.
Error Messages
This is a list of possible error messages that could be displayed as the result of a Download Firmware failure:
Instrument's battery missing or dead (Version Replace lead or reserve controller battery starting the
<6.5) code download
Instrument must be in PROGRAM LOCK Put controller in program-lock mode before starting
mode to perform this operation mode before code download
starting code
Missing loader binary file Could not open the loader file. Make sure the
“loader.s19” file is in the same directory as the firmware
file to be downloaded.
Could not open firmware update file Make sure the firmware file is present in the directory
selected.
The downloaded file is corrupted The firmware file was bad. Replace the firmware file
Failed to put instrument into loader transfer Could be caused by communication| loss or controller
mode power failure. Restart code download again.
Unexpected controller mode. Code download Could be caused by communication loss or controller
will abort. power failure. Restart code download again.
The controller will now reset
An incomplete code download has been A previous code download was aborted or failed. Code
detected. Do not remove controller power! download will proceed using the selected file.
Removing controller power could result
in damage to the scanner card(s)
No scanner racks detected Most likely cause is no expansion racks connected to
the main controller. It can also be caused by a scanner
card failure. If a scanner is properly connected to
the controller and this message is displayed, replace the
scanner card.
“Rack 1: SUCCESS, Rack 2: FAILED" Completion report for scanner code download. There
should be a SUCCESS status for each card connected
to the main controller rack. A FAILED status could
be caused by a communications problem between the
main controller rack and the scanner racks or by a failed
scanner
South Korea
Honeywell Korea Co Ltd
Phone: +(822) 799 6114
Fax: +(822) 792 9015
Process Solutions
Honeywell
1250 W Sam Houston Pkwy S
Houston, USA, TX 77042