FSoE protocol

FSoE is a safe protocol (Safety Integrity Level 3 according to IEC 61508). With it, safety functions ('functional safety') can be implemented via EtherCAT. For more details: see IEC 61784-3 'Functional safety fieldbus'.

The FSoE cycle time is 15 ms and cannot be changed.

The transmission via EtherCAT is carried by one channel and is not relevant for the safety assessment.

FSoE transmits control and status data. The FSoE data exchange is mirrored via the standard unsafe parameters ID33210 'FSoE master command' to ID33249 'FSoE slave ConnID'.

Controller enable

After switching-on the device, FSoE master and FSoE slave build a save connection via EtherCAT. The FSoE master recognises the valid date from FSoE slave and evaluates bit 28 'VALID' of the status word.

Controller enable RF cannot be set and safe operation is not started, until the FSoE master signals that the monitoring can be started and the controller sets the system ready message SBM.

Reaction in case of an error

Maloperation of the FSoE communication causes 'Safe torque off (STO)'.

Commanding

During commanding via FSoE (Prm7 = 0), the safe inputs will not be analysed by the safety functions but by the PLC controller. The kind of activation of the safe outputs SA1 and SA2 is defined by parameter Prm8

Parameters

Safe parameters

Parameter

Name

Code

Unit

Min

Max

Prm7

'Commanding'

Cmd_Src

-

0

1

Prm8

'Output control'

Out_Src

-

0

1