For high reliability applications, redundant controllers, -power supplies, -Ethernet-connections, -racks, -PROFIBUS and –PROFINET networks shall be available.
Regarding the PROFINET standard, the redundant controller must support system redundancy S2 and redundant PROFINET configuration R1.
Redundant controllers must support changeability during operation, configuration and changes in run.
Physical Separation of Redundant Controllers
When required it shall be possible to physically locate redundant controllers in separate panels/rooms/buildings to mitigate any risk potential from common cause failures (e.g. fire). A separation distance between both redundancy partners up to 10km must be possible.
Switchover Time with Redundant Systems
In a redundant system, controllers shall operate with a “hot backup” where both CPUs execute the identical step of the user program in parallel. When a CPU error is detected, a bumpless switchover shall be initiated between the controllers in app. 10 ms w/o loss of signals and alarms.
Connected redundant I/O components typically switch over within 20 ms if a fault occurs.