Diagnosis and troubleshooting of communication failures in industrial PLC networks: Profinet, EtherNet/IP, Modbus

Technical analysis: Troubleshooting PLC communication failures: fieldbus diagnostics (Profinet, EtherNet/IP, Modbus), ca

Diagnosis and troubleshooting of communication failures in industrial PLC networks: Profinet, EtherNet/IP, Modbus

1. Problem Description and Area of Application

This manual is intended for chief engineers in maintenance, specialists in control and measuring instruments and automation (CMI&A) and technicians of the chief engineer's service, serving Ukrainian manufacturing enterprises. The document covers methods of systematic diagnostics and troubleshooting of communication at the level of field buses and industrial Ethernet for protocols Profinet, EtherNet/IP and Modbus TCP/RTU.

Communication failures in modern automated control systems for technological processes (ACS) lead to production line stoppages, data packet loss, false alarm signals, and transition of equipment to a safe mode (Fail-Safe). This manual focuses on identifying root causes: from physical cable damage and electromagnetic interference (EMC) to configuration errors of nodes and failures in switch hardware.

Classification of criticality level:

  • Critical: Full line stop, loss of communication with the main PLC or key safety modules (Safety Integrated). Immediate intervention is required.
  • Major: Periodic packet loss, high delay (jitter > 50 ms), sporadic node errors without complete process stoppage.
  • Minor: Single protocol errors in the diagnostic buffer that do not affect the PLC cycle execution.

2. Precautionary Measures and Safety

DANGER HIGH VOLTAGE AND ELECTRICAL SHOCK!

Safety requirements before starting diagnostics:

  • Perform the procedures Lockout/Tagout (LOTO) before any physical intervention in power circuits or switchgear.
  • Use personal protective equipment (PPE): safety goggles, dielectric gloves (class 0, up to 1000 V), footwear with anti-static and insulating sole.
  • Remember the risks of electrostatic discharge (ESD): use grounded wrist straps when working with open boards and communication modules.
  • Take into account the residual energy in the capacitive filters of the frequency converters and power supply units. Wait at least 5 minutes after removing the voltage before checking the terminals.

3. Required diagnostic tools

For effective localization and elimination of communication failures, use the following set of measuring instruments and software:

Tool Name Specification / Model Measurement range Purpose
Industrial multimeter Fluke 87V or equivalent (True RMS, CAT IV 600V) 0 - 1000 V AC/DC, 0 - 50 MOhm, 0 - 10 A Grounding check, supply voltage, integrity of non-conductive cable cores.
Ethernet Cable Tester Fluke Networks LinkIQ / MicroScanner2 Categories Cat5e, Cat6, Cat6A; length up to 300 m Measurement of cable length, detection of breaks, short circuits, cross-talk (NEXT) and pair imbalance.
Optical reflectometer (OTDR) / Fiber optic tester EXFO MaxTester or similar 850 nm / 1300 nm (multimode), 1310 nm / 1550 nm (singlemode) Optical fiber line diagnostics (attenuation level, reflection at weld joints).
Portable Oscilloscope / Bus Analyzer ProfiShark / Wireshark on an industrial laptop Transmission speed up to 1 Gbit/s Packet Capture and analysis, jitter detection, collisions and broadcast storm detection.
Thermal imager Flir E8 / Testo 883 -20°C ... +550°C, accuracy ±2°C Temperature check of switches, power supply units and connectors (detection of overheating due to poor contact).

4. Initial Inspection Checklist

Before connecting diagnostic equipment, record the current state of the system, saving data from controllers and control cabinets:

What to check / fix Acceptable Values (Acceptable) Emergency values (Alarm) Action / Recording
Status LED Indicators for PLC (SF, BF, MNS) All green (RUN, OK, Link) lights are on or blinking in the normal mode. Red indicator SF (System Fault), BF (Bus Fault) or MS/NS (Module/Network Status) is lit or blinking. Record the status of the LEDs for a specific module in the diagnostic protocol.
Power supply of communication modules and switches 24 V DC ± 2% (23.5 - 24.5 V). Less than 21.5 V or presence of pulsations above 250 mV. Measure with a multimeter at the device's power terminals.
Temperature in the distribution cabinet +15°C ... +35°C (internal space of the enclosure). Over +45°C. Check the operation of the fans and air conditioners in the cabinet.
Integrity and quality of the enclosure grounding Grounding resistance < 4 Ω. Cable screen is grounded on both or one side according to the manufacturer's specification. Resistance > 10 Ohm, absence of reliable screen contact with the grounding bar (EMC bar). Check the earth connection using an ohmmeter and visually.
History of Last Changes (Change Management) Absence of unauthorized changes in the PLC project or switch configuration (VLAN, IP addresses). Works were carried out for connecting new equipment or updating the software. Train the personnel, check the event logs (Event Log) in the development environment (TIA Portal, Studio 5000).

5. Systematic Diagnostic Block Diagram (Decision Tree)

Use this algorithm for sequential fault search from the physical level to the application level:

  1. Рівень 1: Фізичний стан лінії зв'язку та живлення
    • IF світлодіод "Link/Act" на порті світча або ПЛК не горить або блимає нерегулярно:
      • CHECK фізичний стан кабелю та роз'ємів (RJ45, M12, оптичні патч-корди).
        • IF виявлено механічне пошкодження або перегин кабелю з радіусом менше допустимого (менше 8-кратного діаметра кабелю для Cat5e/Cat6):
          • Першопричина: Пошкодження внутрішніх провідників або порушення кросування.
          • Резолюція: Замінити кабель або пошкоджену ділянку з використанням промислових роз'ємів IP67.
        • If cable is visually intact:
          • CHECK with cable tester (LinkIQ) for breaks, short circuits between pairs, and also check loop resistance.
          • IF loop resistance exceeds 15 Ohm per 100 meters or high level of cross-talk (NEXT) is detected:
            • Root cause: Poor quality installation, poor crimping of connectors (violation of EIA/TIA-568B or PROFINET cabling guideline).
            • Resolution: Recrimp RJ45 connectors / check installation of terminal blocks for Profibus/Modbus.
  2. Рівень 2: Рівень комунікаційного обладнання та перешкод (EMC)
    • IF світлодіоди "Link" горять, але зв'язок втрачається під час запуску потужних приводів (частотних перетворювачів):-
      • CHECK стан екранування кабелю зв'язку та наявність зрівняльних струмів.
        • IF екран кабелю підключений з обох боків на пофарбовані поверхні або довжина кабелю паралельна силовим кабелям двигунів ближче ніж на 300 мм без металевого розділювального лотка:
          • Першопричина: Електромагнітні перешкоди (EMC) від кабелів живлення двигунів, що наводять високий потенціал на екран.
          • Резолюція: Перекласти кабелі зв'язку в окремий металевий заземлений лоток, забезпечити правильне кругове підключення екрана через EMC-затискачі (shield clamps).
  3. Рівень 3: Рівень логіки та конфігурації мережі
    • IF фізичний лінк є, перешкод немає, але модуль повертає помилку зв'язку:
      • CHECK налаштування IP-адрес, масок підмережі та імені пристрою (Device Name для Profinet).
        • IF виявлено конфлікт IP-адрес або невідповідність Device Name у конфігурації ПЛК та реальному пристрої:
          • Першопричина: Помилка конфігурації під час заміни польового пристрою або несанкціонована зміна параметрів.
          • Резолюція: Присвоїти правильне ім'я та IP-адресу через інструмент конфігурації (Primary Setup Tool, Proneta або через середовище ПЛК).

6. Fault-Cause Matrix

Symptom Likely causes (by likelihood) Diagnostic test Expected result upon confirmation of the cause
Periodic connection dropouts (Timeouts) with Profinet / EtherNet/IP devices during cycle operation 1. Exceeded waiting time (Update Time / RPI too small).
2. Network overload (Broadcast storm).
3. Defective switch (Switch).
Traffic capture (Wireshark) / Port utilization check (SNMP). High level of discarded packets (Discards/Errors on switch port), response delay (Response Time > 50 ms).
Complete loss of connection with the network segment after welding works or switching on powerful equipment 1. Damage to the output ports of the switch due to voltage spike.
2. High potential leakage along the cable screen.
Testing the switch ports by connecting a test notebook directly to the port. The switch port does not respond to connection, the Link LED does not light up regardless of the cable's integrity.
CRC Errors in Modbus RTU (RS-485) Bus 1. Absence or incorrect nominal of terminal resistors (120 Ohm).
2. Incorrect polarity of the line (A and B lines are swapped).
3. Long cable length or star topology instead of linear (Daisy Chain).
Resistance measurement between lines A and B with a multimeter (with power off). Line topology check. Resistance between lines is less than 50 ohms or more than 150 ohms (without terminators, the line resistance in open state tends to infinity or does not correspond to 60 ohms for parallel 120-ohm resistors).
Error "Device Name not found" when replacing a Profinet device The new device does not have a programmed name in non-volatile memory. Scanning the network using Siemens Proneta or similar utility. The device is displayed in the network with the standard factory name or empty name.

7. Root Cause Analysis

To prevent repeated equipment stoppages, it is necessary to thoroughly understand the mechanisms of occurrence of key problems:

7.1. Electromagnetic Interferences (EMC) and Ground Loops

Why it occurs: Industrial facilities are filled with frequency converters, welding machines, and powerful transformers. If the communication cable is laid in the same tray with motor power cables at a distance less than critical, or if the shield of the cable is grounded at both ends to grounding loops with different earth potentials, equalizing currents occur. These currents create high-frequency induced voltages, which distort the fronts of digital pulses.

Як підтвердити: Використання осцилографа для виміру напруги на екрані кабелю відносно локальної землі. Наявність змінної складової напруги понад 1 В свідчить про проблему з заземленням.

Наслідки: Спотворення пакетів даних, зростання кількості помилок кадрів (Frame Errors), передчасний вихід з ладу інтерфейсних мікросхем PHY (Physical Layer Transceiver).

7.2. Non-compliance with topology and connection line length

Why it occurs: Technicians often use a "star" topology for Modbus RTU instead of the classical bus (Daisy Chain) or exceed the maximum Ethernet segment length (100 meters for Cat5e/Cat6 copper cable) without using intermediate switches or optical repeaters.

Як підтвердити: Фізичний огляд траси прокладання кабелю, звірка з проєктною документацією та вимірювання затримки поширення сигналу.

Наслідки: Відображення сигналів від кінців лінії (відбиття хвилі), що призводить до хибного розпізнавання бітів та зриву синхронізації протоколу.

8. Step-by-Step Resolution (Troubleshooting Procedures)

8.1. Procedure for restoring the connection in case of Ethernet cable damage (Profinet / EtherNet/IP)

  1. Deactivate the damaged area and install the LOTO signs.
  2. Cut the damaged cable section with a reserve of 0.5 meters on each side.
  3. Use industrial quick-connect fittings (for example, piercing/IDC connectors without wire stripping or screw terminals IP67) or install an industrial junction box with protection rating not lower than IP65.
  4. Mount screened RJ45 or M12 connectors according to the TIA-568B standard, ensuring a continuous uninterrupted screen contact of the cable with the metal housing of the connector.
  5. Perform testing of the restored line using a cable tester (LinkIQ). Success criterion: absence of length errors, short circuits, and crosstalk attenuation (PASS in the category Cat5e/Cat6).
  6. Remove LOTO lockout, supply power and check for the disappearance of alarm signals on the PLC.
  7. 8.2. Fault Removal Procedure on the RS-485 Line (Modbus RTU)

    1. Turn off the power supply of the devices in the bus segment.
    2. Check the resistance between the Data+ (A) and Data- (B) terminals with a multimeter. Expected value: approximately 60 ohms (if two terminal resistors of 120 ohms are installed at the ends of the line) or 120 ohms (if the terminator is single). If the resistance approaches infinity — line break or absence of terminators. If less than 40 ohms — short circuit in the cable or incorrect parallel connection.
    3. Check the integrity of the screen connection: the screen must be grounded only on one side (usually on the side of the main controller or control cabinet), to avoid the formation of a ground loop.
    4. Check the correct pairing of conductors (A to A, B to B). Crossed lines — the most common error during installation.
    5. After eliminating the defects, turn on the power and check for the absence of CRC error counters in the controller's polling program.

    9. Preventive Measures

    Maintenance of a minimum distance (300 mm) between the power and signal cable trays. Use of screened cable with proper grounding of the screen. Infrared inspection of grounding contacts and measurement of screen currents.Use of spring-loaded push-in connectors or screw terminals with thread locking (thread lockers such as Loctite for screws, or crimping of terminals). Visual and instrumental inspection of terminal tightening force using a torque wrench.Network segmentation using managed switches to create VLANs and limit broadcast storms. Switch port utilization monitoring via SNMP protocol (PRTG, Zabbix).
    Primary Cause Preventive strategy Monitoring method Recommended interval
    Electromagnetic Interferences (EMC)Every 6 months
    Oxidation and weakening of contacts through vibrationAnnually (during scheduled major maintenance)
    Software Failures and Traffic OverloadContinuously (in real-time)

    10. Spare Parts and Components

    For rapid restoration of industrial network functionality at enterprises in Ukraine, we recommend using reliable components from the UNITEC-D GmbH warehouse assortment:

    Description of the part Specification When to replace Category UNITEC
    Industrial Managed Switch 8 ports RJ45 10/100/1000 Mb/s, IP20, power supply 24 V DC, support Profinet Conformance Class B. Port failure, overheating, or internal microprogram malfunction. Industrial Networking
    Industrial Ethernet Cable (Profinet Type B / C) Cat5e, SF/UTP, PUR jacket, oil resistant and bend resistant (drag line). In case of mechanical damage to the sheath, broken wires, or signal attenuation. Cables & Connectors
    Industrial RJ45 connector IP20/IP67 Metal housing, Cat6A, quick mounting without special tools (Piercing technology). When the fixator (snap) is damaged or the contacts are oxidized. Cables & Connectors
    Terminal Resistor RS-485 / Profibus 120 Ohm, built-in plug with switch connector. When the resistor is damaged or there is instability in the Modbus/Profibus bus. Automation Spares

    Familiarize yourself with the complete range of components for industrial automation and communication in our electronic catalog: https://www.unitecd.com/e-catalog/.

    11. Regulatory Basis and References

    • ISO/IEC 11801: Information Technology. Universal cable system for user premises.
    • EN 50170 / EN 50254: Standards for industrial bus systems and local networks in a production environment.
    • PROFINET Installation Guideline (PI): Official Installation and Testing Instructions for Profinet Networks.
    • DSTU EN 60204-1: Machine Safety. Electrical Equipment of Machines and Mechanisms. Part 1. General Requirements.
    • Internal Guides UNITEC-D: "Electromagnetic Compatibility Diagnosis in ACSUTP" (Guide #UA-EMC-04).

Related Articles

Diagnosis of PLC communication failures: Profinet, EtherNet/IP, Modbus

Technical analysis: Troubleshooting PLC communication failures: fieldbus diagnostics (Profinet, EtherNet/IP, Modbus), ca

Diagnosis of PLC communication failures: Profinet, EtherNet/IP, Modbus
Посібник із системної діагностики та усунення несправностей зв'язку ПЛК у промислових мережах Profinet, EtherNet/IP та Modbus для забезпечення безперебійної роботи обладнання.

1. Description of the problem and scope of application

This guide is intended for diagnosing and troubleshooting PLC (industrial controller) data networks. The main protocols covered are Profinet, EtherNet/IP and Modbus. Communication failures are classified as critical because they lead to the stoppage of production processes, loss of control over executive mechanisms, and dangerous conditions.

Symptoms:

  • Sudden loss of communication with a node or group of nodes.
  • Random data transmission errors (CRC errors, packet loss).
  • Delays (jitter) in cyclic communications.
  • Failure to initialize the network when power is turned on.

Importance criteria:

SeverityInfluence
CriticalComplete stoppage of the line, safety risk
SignificantPartial loss of functionality, reduced performance
InsignificantSingle errors that do not affect the cycle

2. Safety measures

WARNING: Lockout/Tagout (LOTO) must be performed before starting diagnostic work. Turn off all power sources, discharge stored energy (capacitors, pneumatic systems, batteries) and install blocking devices. Working with live equipment is prohibited without the use of PPE (personal protective equipment) of class 0 (up to 1000V), dielectric gloves and safety glasses. Check the absence of voltage at each step of the measurements.

3. Necessary diagnostic tools

ToolSpecification/ModelMeasurement rangePurpose
Digital multimeterTrue RMS, cat. III 1000VOhm, mA, V (DC/AC)Checking the integrity of cables, power supply voltage
Network analyzerFluke DTX/DSX or equivalentCAT 6/6A, ProfinetCertification of cables, signal loss
OscilloscopePortable, 100 MHz±10V, 10 μs/subRS-485 (Modbus) signal quality analysis
Thermal cameraFLIR or similar-20°C – +500°CDetection of overheated connectors/cables

4. Initial assessment checklist

stepactionRecord
1Check the LED indication on the PLC and modulesStatus (Green/Red/Flash)
2Record time of error occurrence and conditions (load)Time/Event
3Ask operators about recent changes or technical workChanges in the system
4Inspect cable ducts for damageType of damage

5. Systematic diagram of diagnostics

  1. Checking the physical level (L1):
    • If the loss of communication occurred suddenly: Check the integrity of the cable, the reliability of connecting the connectors (RJ45, M12). Use a tester to test for an open/short circuit.
    • IF open → replace cable segment. IF connector is weak → re-clamp.
  2. Power analysis (L0):
    • Check the supply voltage of the nodes.
    • IF voltage < 22.8V DC (for 24V systems) → check the voltage drop on the power supply lines, check the power supply unit.
  3. Logical layer diagnosis (L2/L3):
    • If the physical level is normal: Use diagnostic software (Profinet Commander, Wireshark).
    • Error analysis: CRC errors, packet loss.
    • IF high CRC level → electromagnetic interference or shielding defect.

6. Matrix of errors and reasons

SymptomProbable reasonsDiagnostic testExpected result
Complete loss of communicationCut cable, power failure, PLC failureMultimeter (integrity), measuring 24VThe connection has been restored
Random CRC errorsInterference (EMI), poor ground, poor contactOscilloscope (noise), screen checkLow noise
Failures when starting the equipmentIncorrect topology, network congestionWireshark (traffic)Stable cycle

7. Analysis of the main reasons

Electromagnetic interference (EMI): Communication cables are laid parallel to the power cables of the frequency converters without sufficient separation. This causes inductive biases that distort digital signals. Confirmation: the presence of high-frequency noise on the oscillogram.

Grounding problems: The potential difference between the grounding of the PLC and the nodes causes currents to flow through the cable shield. This leads to damage to the connectors and the occurrence of communication errors. Confirmation: measurements of alternating voltage between the housings of the devices.

Incorrect termination (Modbus): In RS-485 networks, the absence or excess of 120 ohm terminators at the ends of the line causes signal reflections. Confirmation: a “ringing” waveform on the oscillogram.

8. Step-by-step elimination procedure

  1. Cable replacement: Always use an industry standard cable (eg Profinet Type B or C). Do not allow bends less than 10 times the diameter of the cable.
  2. Grounding correction: Connect the enclosures with an equipotential bus (minimum 16 mm² copper). Ensure that the cable shield is grounded at only one point (unless otherwise required by the device specification).
  3. Parameter settings: If using EtherNet/IP, check the RPI (Requested Packet Interval) setting - if it is too small for the current load, increase it.

9. Preventive measures

The reasonStrategyMonitoring methodInterval
EMIPhysical separation (min. 300mm)Thermal cameraAnnually
Cable wearUse of cables for power chainsVisual inspectionEvery 6 months
CorrosionApplication of protective lubricants for connectorsIntegrity testingEvery 12 months

10. Spare parts and components

Description of the spare partSpecificationWhen to replaceCategory UNITEC
RJ45 industrial cableCat6A S/FTP, shieldedIn case of mechanical damageCommunication/Cables
Connector M12 D-codedIP67, 4-pinIn case of loss of tightnessCommunication/Connectors
RS-485 terminator120 Ohm, 0.5WIn case of Modbus failuresCommunication/Accessories

To order spare parts, refer to our catalog: https://www.unitecd.com/e-catalog/

11. Links

  • ISO/IEC 61158 (Industrial communication networks)
  • TIA/EIA-568-B (Structured Cabling System Standard)
  • Manuals of PLC manufacturers (Siemens, Rockwell Automation, Schneider Electric)

Related Articles