PMT Hps Sms r210 6 SCN
PMT Hps Sms r210 6 SCN
PMT Hps Sms r210 6 SCN
R210.6
Software Change Notice
Version: 1.3
While this information is presented in good faith and believed to be accurate, Honeywell disclaims the implied
warranties of merchantability and fitness for a purpose and makes no express warranties except as may be
stated in its written agreement with and for its customer.
In no event is Honeywell liable to anyone for any direct, special, or consequential damages. The information
and specifications in this document are subject to change without notice.
4 Anomalies Resolved................................................................................................. 31
4.1 S300 Firmware .................................................................................................................................. 31
4.2 QPP-0002 Firmware .......................................................................................................................... 32
4.3 FC-PDIO01 firmware ......................................................................................................................... 33
4.4 FC-PUIO01 firmware ......................................................................................................................... 34
4.5 Safety Manager SC FC-RUSIO-3224 firmware ................................................................................... 35
4.6 Safety Manager FC-RUSIO-3224 firmware ........................................................................................ 36
4.7 FX-USI-0002 firmware ....................................................................................................................... 37
4.8 Safety Builder .................................................................................................................................... 37
4.9 Experion Integration ......................................................................................................................... 38
Safety Manager SC is a modular, fault tolerant safety system capable of solving the most challenging
Emergency Shutdown (ESD) / Safety Instrumented System (SIS) applications in the Process Control
industry. Certified by TUV Rheinland, for use in safety applications up to Safety Integrity Level 3
(SIL3), Safety Manager SC is operationally integrated with Experion® and meets the latest cyber
security standards, up to ISA Secure level 2.
Safety Manager is a modular, fault tolerant safety system capable of solving the most challenging
Emergency Shutdown (ESD) / Safety Instrumented System (SIS) applications in the Process Control
industry. Certified by TUV Rheinland, for use in safety applications up to Safety Integrity Level 3
(SIL3), Safety Manager is operationally integrated with Experion® and meets the latest cyber security
standards, up to ISA Secure level 1.
Latest versions of Safety Management Systems R210.6 Software Change Notice can be found at
process.honeywell.com.
After you log in to process.honeywell.com, Click here or search for "SMSC-MAN" AND "R210.6"
including the quotes.
Tip
This symbol is used for useful, but not essential, suggestions.
Attention
This symbol is used for information that emphasizes or supplements important
points
Caution
This symbol warns of important facts on Safety Management Systems behavior or
architecture.
Chassis IO
19" rack/
Redundant
4HE
19" rack/
Non-Redundant
4HE
Redundant 18"
Non-Redundant 12"
Redundant 18"
Non-Redundant 12"
Redundant 12"
Non-Redundant 12"
Redundant 12"
Non-Redundant 12"
Safety Manager
Systems Release
Hardware required
Feature Earth Leakage
From To IOTA + Control Processor IOTA + Universal IO IOTA + Digital IO
Detection
Redundant Safety Manager SC R200.1 --- FC-TCNT11 + 2 X FC-SCNT01
Experion Scada R200.1 --- FC-TCNT11 + 2 X FC-SCNT01
SafeNet R200.1 --- FC-TCNT11 + 2 X FC-SCNT01
Modbus slave R200.1 --- FC-TCNT11 + 2 X FC-SCNT01
Modbus Master R201.1 --- FC-TCNT11 + 2 X FC-SCNT01
Experion CDA/FTE support R200.1 --- FC-TCNT11 + 2 X FC-SCNT01 `
SafeNet: Safety Manager to
R201.1 --- FC-TCNT11 + 2 X FC-SCNT01
Safety Manager SC
Redundant FC-RUSIO-3224 R200.1 --- FC-TCNT11 + 2 X FC-SCNT01 FC-IOTA-R24 + 2 X FC-RUSIO-3224
Non Redundant FC-RUSIO-3224 R210.1 --- FC-TCNT11 + 2 X FC-SCNT01 FC-IOTA-NR24 + FC-RUSIO-3224
FC-IOTA-R24 + 2 X FC-RUSIO-3224 or
FC-RUSIO-3224 Earth Leakage Detection R200.1 --- FC-TCNT11 + 2 X FC-SCNT01 FC-TELD-0001
FC-IOTA-NR24 + FC-RUSIO-3224
HART Handheld R200.1 --- FC-TCNT11 + 2 X FC-SCNT01
FC-IOTA-R24 + 2 X FC-RUSIO-3224 or
Low Latency SOE / FC-RUSIO-3224 R200.1 --- FC-TCNT11 + 2 X FC-SCNT01
FC-IOTA-NR24 + FC-RUSIO-3224
FC-IOTA-R24 + 2 X FC-RUSIO-3224 or
HART Pass thru / FC-RUSIO-3224 R200.1 --- FC-TCNT11 + 2 X FC-SCNT01
FC-IOTA-NR24 + FC-RUSIO-3224
FC-TDIO11 + 2 X FC-PDIO01
Redundant FC-PDIO01 R200.2 --- FC-TCNT11 + 2 X FC-SCNT01 2 X FC-SIC<20/10><Lx>
2 X (FC-TDIO51 OR FC-TDIO52)
FC-TDIO11 + 1 X FC-PDIO01
Non Redundant FC-PDIO01 R210.1 --- FC-TCNT11 + 2 X FC-SCNT01 2 X FC-SIC<20/10><Lx>
2 X (FC-TDIO51 OR FC-TDIO52)
Low Latency SOE / FC-PDIO01 R201.1 --- FC-TCNT11 + 2 X FC-SCNT01 FC-TDIO11 + 2 OR 1 FC-PDIO01
ART+ / FC-PDIO01 R210.1 --- FC-TCNT11 + 2 X FC-SCNT01 FC-TDIO11 + 2 FC-PDIO01
FC-PUIO01 Earth Leakage Detection R210.1 --- FC-TCNT11 + 2 X FC-SCNT01 FC-TELD-0001 FC-TUIO11 + 2 OR 1 FC-PUIO01
HART Pass thru / FC-PUIO01 R210.1 --- FC-TCNT11 + 2 X FC-SCNT01 FC-TUIO11 + 2 OR 1 FC-PUIO01
Low Latency SOE / FC-PUIO01 R210.1 --- FC-TCNT11 + 2 X FC-SCNT01 FC-TUIO11 +2 OR 1 FC-PUIO01
FC-IOTA-R24 + 2 X FC-RUSIO-3224
UMS / FC-RUSIO-3224 R210.1 --- FC-TCNT11 + 2 X FC-SCNT01
2 X CC-SICC1011/<Ly> + UMS
FC-TDIO11 + 2 OR 1 FC-PDIO01 +
UMS / FC-PDIO01 R210.1 --- FC-TCNT11 + 2 X FC-SCNT01
2 X FC-SIC5<Lx> + UMS
FC-TUIO11 + 2 OR 1 X FC-PUIO01
UMS / FC-PUIO01 R210.1 --- FC-TCNT11 + 2 X FC-SCNT01
2 X FC-SIC5<Lx> + UMS
Lx = In decimeters Ly = in meters
Hardware required
BASE Control Earth Leakage
Chassis Communication Universal Safety IO Universal Logic Solver
Processor Detection
FS-CPCHAS-0001
Safety Manager R100 FS-IOCHAS-0001R FC-QPP-0001 FC-USI-0001 10310
FS-IOCHAS-0001S
FS-CPCHAS-0003
Power infrastructure improvement R100 FS-IOCHAS-0003R
FS-IOCHAS-0003S
SafeNet R110
High performance Processor R130 FC-QPP-0002
Universal Safety Interface (FC-USI-0001) R100 <R160 FC-USI-0001
Universal Safety Interface (FC-USI-0002) R100 FC-USI-0002
Universal Safety Interface (FE-USI-0002) R130 FE-USI-0002
Universal Safety Interface (FX-USI-0002) R140 FX-USI-0002
Redundant Universal Safety IO R140 R145 FC-QPP-0002 FC-IOTA-R24 + 2X FC-RUSIO-3224
Redundant Universal Safety IO R150 FC-QPP-0002 FC-IOTA-R24 + 2X FC-RUSIO-3224
FC-USI-0002,
Experion CDA/FTE support R150 FC-QPP-0002 FE-USI-0002 or
FX-USI-0002
FS-CPCHAS-0002
Advanced Redundancy Technique R150 FS-IOCHAS-0002R FC-QPP-0002
FS-IOCHAS-0002S
Universal Safety Logic Solver
R150 <R200 FC-QPP-0002 FC-IOTA-R24 + 2X FC-RUSLS-3224
(Localized Safeguarding)
Non Redundant Universal Safety IO R150 FC-QPP-0002 FC-IOTA-NR24 + FC-RUSIO-3224 FC-IOTA-NR24 + FC-RUSLS-3224
FC-IOTA-NR24 + FC-RUSIO-3224 or FC-IOTA-NR24 + FC-RUSLS-3224 or
HART Pass thru R150 FC-QPP-0002
FC-IOTA-R24 + 2X FC-RUSIO-3224 FC-IOTA-R24 + 2X FC-RUSLS-3224
FC-USI-0002,
Modbus Master TCP R150 FC-QPP-0002 FE-USI-0002 or
FX-USI-0002
FC-IOTA-NR24 + FC-RUSIO-3224 or FC-IOTA-NR24 + FC-RUSLS-3224 or
HART Handheld R152 FC-QPP-0002
FC-IOTA-R24 + 2X FC-RUSIO-3224 FC-IOTA-R24 + 2X FC-RUSLS-3224
FE-USI-0002 or
EUCN R160.1b FC-QPP-0002
FX-USI-0002
FC-USI-0002,
FSC to SM Migration R160 FC-QPP-0002 FE-USI-0002 or
FX-USI-0002
FC-USI-0002,
SafeNet : SM-FSC R161 FC-QPP-0002 FE-USI-0002 or
FX-USI-0002
FC-USI-0002,
AutroCom SIL 2 protocol R162 FC-QPP-0002 FE-USI-0002 or
FX-USI-0002
Supported operating systems are available online in "Safety Systems Software Support Guidelines"
on the Honeywell support guidelines.
This guideline can be found at MyHPS (https://process.honeywell.com/us/en/services-and-
support/support-center/technical-support/technical-solutions/article-detail.ka_000135672 )
Login, Select “Support” “Knowledge Articles”, and search for "Safety Systems Software Support
Guidelines”
R146.2 a p p p p p
R154.5 a p p p p
R162.9 a p p p
R200.1 u4 u4 u4
R200.2 u4 u4 u4
R200.3 u4 u4 u4
R201.1 u4 u4 u4
R201.2 a u4 u4 u4
R210.1 p p p
R210.2 p p p
R210.3 p p p
R210.4 p p p
R210.5 p p p
R210.6 a p p
R211.1 p p
R211.2 a p
R212.1 a
R146.1 √ √ √ √ √ √ √
R146.2 √ √ √ √ √ √
R151.2 √ √ √ √ √ √
R151.4 √ √ √ √ √ √
R152.2 √ √ √ √ √ √
R152.3 √ √ √ √ √ √
R153.3 √ √ √ √ √ √
R153.4 √ √ √ √ √ √
R153.5 √ √ √ √ √ √
R153.6 √ √ √ √ √ √
R153.7 √ √ √ √ √ √
R154.1 √ √ √ √ √ √
R154.2 √ √ √ √ √ √
R154.3 √ √ √ √ √ √
R154.4 √ √ √ √ √ √
R154.5 √ √ √ √ √
R160.2 √ √ √ √ √
R160.3 √ √ √ √ √
R161.1 √ √ √ √ √
R162.1 √ √ √ √ √
R162.2 √ √ √ √ √
R162.3 √ √ √ √ √
R162.4 √ √ √ √ √
R162.5 √ √ √ √ √
R162.6 √ √ √ √ √
R162.9 √ √ √ √
R200.1 √ √ √ √
R200.2 √ √ √ √
R200.3 √ √ √ √
R201.1 √ √ √ √
R201.2 √ √ √
R210.1 √ √ √
R210.2 √ √ √
R210.3 √ √ √
R210.4 √ √ √
R210.5 √ √ √
R210.6 √ √
R211.2 √
R212.1
• Safety Manager Universal Safety IO modules are flexible and perform additional tasks like
communication with Safety Manager, scanning and updating IO, internal diagnostics, SOE
generation and HART communication. The Universal IO modules require firmware, configuration,
and application program to operate. These three components are automatically updated, when
required as soon as the module is powered-up and connection to its Safety Manager is
established.
o firmware changes are normally part of a new software release,
o configuration changes are for example changes to a channel parameter, and
o application changes apply to the Universal logic solver when the FLD has been assigned to
the Universal Logic Solver.
Be aware that any update to any of these three components will force a reboot of the module.
During the update and reboot the Universal IO module will behave as follows:
o system and process data communication between the Universal Safety IO module and its
Safety Manager is not active,
o all Universal Safety IO outputs on the module will go to the safe, de-energized state,
o HART communication and SOE event reporting are not active, and
o on a Universal Safety Logic Solver (FC-RUSLS-3224 only) the application is not executed.
Important:
• During an on-line modification for redundant Universal Safety IO module configurations, the
redundancy will ensure that operation is continued. When the first Universal Safety IO
module of the redundant pair is loaded, the second Universal Safety IO module continues
operation and vice versa.
• During a Safety Manager on-line modification for non-redundant Universal Safety IO modules
configurations operation will be discontinued whenever firmware, configuration or
application has been changed.
• When an USIO module is detected faulty during initialization of the Safety Manager Control
Processor with new application loaded, the Safety Manager Controller will not block online
modification. Performing the fault reset to continue OLM will start the Safety Manager
Control Processor with a faulty reported USIO.
Before plant and applications can be used by Safety Management Systems R210.6 the Safety
Manager Database(s) need to be converted to SQL database using option: File-Migrate to Microsoft
SQL Server… .
Safety Manager Controller - Experion integration via SCADA and PCDI protocol over Dual LAN
The Experion communication link can only be configured on channel A of the USI communication
module. This means that Experion links configured on channel B cannot be migrated.
Before starting the migration, change the configuration of the Experion link to channel A.
NOTE: The Safety Management Systems R210.6 Experion Components.msi is a standalone installer.
For CDA Experion integration, the detail displays must be installed using this installer, before starting
Experion.
2.6.5.6 On-line software upgrade from Safety Manager R150.1 shows multiple EC 141
During On-line software upgrade executed from Safety Manager R150.1 following anomaly may be
observed:
Multiple error codes 141 appear. (Internal communication failure or redundant CP degraded)
If this is observed, it is strongly advised to complete the following steps before commencing the on-
line modification:
1. Turn the QPP key switch of the non-running QPP to the STOP position. The R150.1 Control
Processor remains RUNNING.
2. Toggle the Reset key switch once.
3. Turn the QPP key switch of the non-running QPP to the RUN position. The R150.1 Control
Processor remains RUNNING.
4. Wait for the QPP to show “CPReady” on the display,
5. Wait 10 seconds
6. Check Diagnostics,
7. If 0 to 3 error code 141 is reported, then all is OK and continue with next step else repeat
from step 1.
8. Resume the on-line modification procedure at step C2.i as defined in the On-line
Modification Guide
Adding/deleting of Universal Safety IO / Universal Safety Logic solver must not be done as
part of a firmware upgrade to Safety Management Systems R210.6 (1-UA45D9)
2.7.1 Compatibility
Safety Management Systems R210.6 can migrate FSC R80x applications.
Safety Management Systems R210.6 supports most of FSC IO Modules.
More detail can be obtained by contacting local Honeywell affiliate.
Phased Migration
No 5A. Upgrade complete application (all the controllers)
to FSC R80x
Single step?
5B. Run “Verify Application” for all controllers running
on FSC >=R420 software and Save the VA report
Yes 5C. Create the FSC system(s) migration phases/plan.
6. Run Migration Audit Tool for all the controllers in the application
upgraded in step 4C, find Un-Supported Features/Hardware
using “FSC to SM Migration Audit Tool” and remove them from
the FSC application
7A. Migrate the FSC Controller using Safety 7B. Migrate the FSC Controller using Safety
Builder option “Migrate to SM Controller”, Builder option “Migrate to SM Controller...”,
Uncheck “Change to SM IO Chassis” Option check “Change to SM IO Chassis” Option
All Controllers
done?
Yes
No
Refer to
Can all differences be
Migration
explained?
document
Migration
Complete
2.8.1 Installation
More details on Installing Safety Management Systems R210.6 is available in Installation and Upgrade
Guide EP-SMSC-MAN-7053-210C, Paragraph INSTALLING AND REMOVING SAFETY BUILDER
The latest update of Safety Manager User Assistance Documentation R210 is available on
Honeywell Process website. (https://process.honeywell.com/us/en/services-and-support/support-
center/technical-support/technical-solutions/article-detail.ka_000135672)
Safety Management Systems R210.6 provides Safety Manager Controller version R163.1
For more detail information regarding updates for Safety Manager Controller, check the Software
Change Notices for Safety Manager R162.x, which can be found at MyHPS website
(https://process.honeywell.com/us/en)
Search for "Safety Manager - SoftwareChangeNotification – R162"
5.1.2.1 Performance
FC-RUSIO-3224 has one HART modem serving channels 1-16 and a second HART modem serving
channels 17-32. In a redundant configuration, the two HART modems assigned to the same group of
channels are sharing the HART communication load.
Communication with the HART enabled channels is scheduled round-robin. With a typical HART
request-response communication cycle of 800ms, this implies that when running non-redundant,
each HART configured channel is on average serviced 800ms x (number of HART enabled channels in
the same group – 1). When running redundant, this will be approximately 800ms x (number of HART
enabled channels in the same group / 2 – 1). If communication retries are requested, the
performance will be lower.
Work around:
Use ‘Change’ option from the pop-up menu to update the FLD’s that use this changed Function
Block.
Workaround:
Not applicable.
Workaround:
Not applicable.
Configurations:
Safety Builder is installed on Experion server or another node having BootP service running
Workaround:
BootP service to be disabled before the temporary connect on controller (without IP address, and node
number) is performed.
Configurations:
Application having SCADA and Safety Historian protocol on same USI
Workaround:
Change original application
Configurations:
Safety Manager Controller running release prior to R160 and configured as QPP-0001 where QPP-
0002 from Safety Manager system running R160 or later release is applied as spare part.
Workaround:
Before using a QPP-0002 from SM R16x system as spare part in system running release prior to R160.
Remove the USI modules before the QPP-0002 is inserted. Once the QPP-0002 has been loaded with
the firmware of the controller the USI's can be re-inserted.
It is strongly recommended to wait at least 90 minutes before manually aborting the download or
power cycle the IO modules. Power cycling FC-PDIO01, while the upgrade is in progress, may result
in an unusable module.
6.1.3 Accessing project simultaneously by SQL Server and Remote Safety Builder
Machine (SMSC-6146)
To prevent Safety Builder stop when simultaneously accessing same project from SQL Server and
Remote Safety Builder Machine, make the user accessing Safety Builder in all the machines part of
Safety builder product administrator group.
This procedure must be followed in case the configuration of Modbus Responder endianness is
started ‘undefined’, Controller gets loaded and then endianness is changed.
Error code 123 – “Download failure” will be reported if you are not following the above procedure.
This is due to Endianness changes for the Long and Float data type.
When migrating an FSC Responder system to Safety Manager Controller the loaded state for all
Safety Manager controllers on the same physical network changes.
6.2.3 Remove points from TPS point database before removing from Safety Manager
Database and online modification (1-44RPJAH)
In case that it is required to remove Points from the Safety Manager application, the following
sequence shall be followed:
1. Remove the associated point(s) from the nodes point database at the TPS side.
2. Save the point database to a new checkpoint
3. Remove the Point(s) from the Safety Manager database in safety builder.
When ready compile the application
4. Perform the online modification
In General:
Be conscious when using “Multiple feedbacks on ONE sheet”
Feedback loops should be tested thoroughly
Work around.
- Implement feedback via multiple sheets using off and on sheet references.
- Prevent the Application compiler to generate internal points to store intermediate
results. (3) e.g. In Sheet example connect 3 to off sheet reference.
To activate the Safety Management Systems R210.6 parameter names when migrating from Safety
Manager R150 the “Force Update All” option in the publish dialog box must be selected. (Only first
time with Safety Management Systems R210.6)
The Experion Custom displays (faceplates), trends, history, peer to peer configurations and all other
Experion clients using Safety Manager parameters that have been changed has to be modified
according to new parameters names in Safety Management Systems R210.6.
Since Release SM R14x Safety Manager supports Smoke & Heat detectors. The property (‘Boolean
Property Output” was introduced. The Smoke & Heat detectors of Safety Manager R140 is fully
supported by UNISIM R400 or Higher
UNISIM supports FLD Intellectual Property Protection.
Safety Management Systems R210.6 UNISIM export format is fully supported as of UNISIM R430
6.2.20 Universal Safety Logic Solver does not make use of power up values. (1-U0U6RX)
Configured power-up values of Register, counter and flip-flops are not applied in FLD’s running on
the Universal Safety Logic Solver.
0x0409.ini
{AAFA7177-856D-4DE5-AED9- ISSetup.dll
5DAD8B2CD770} Safety Manager.msi
setup.exe
Setup.ini
splash.bmp
CommonAppData \Honeywell\CommonLicense\Config.txt
\Favorites\Honeywell Hyperlinks www.HoneywellProcess.com and www.Honeywell.com
ISSetupPrerequisites {63A88B12-4E66-43FC-8869-2360D32FB05D}
\sqlncli.msi
{125AB5F8-0156-4A9F-B1D1-C2B7E7D82A60}
\sqlncli.msi
{506A420F-1F74-4371-9E84-EFF365724DAA}
\NDP46-KB3045557-x86-x64-AllOS-ENU.exe
Honeywell International
Process Solutions
1860 West Rose Garden Lane
Phoenix, AZ, 85027, USA
+1 800-822-7673
www.honeywell.com/ps