GE 8712-CA-NS Node services carrier, Profibus-DP LAN
Once the Ethernet LANs are isolated,
SafetyNet Controllers can be removed and
replaced - with the local power supplies still
connected - even in Division 1, Class 2 or
Zone 2 hazardous areas.
Redundant Controllers
SafetyNet Controllers can be used in a
master - standby redundant configuration to
improve the availability of the safety
function, but this is not required for safety.
Redundancy is implemented by simply
inserting the new Controller in to the free
slot on the Controller Carrier.
The SafetyNet system will automatically
upload the required SafetyNet application to
the new Controller and initiate the
redundancy algorithms. Switching between
redundant Controllers on detection of a fault
is automatic and bumpless.
The standby Controller continually performs
the same processing, on the same data and
at the same time as the Master and the
results are routinely cross-checked. This
ensures that the Standby is always ready to
take over control from the Master. The
redundancy strategy employed is known as
"rendezvous redundancy".
The "Change State" button on the Controller
Carrier is used to switch a master to being
the standby in a redundant pair, to switch a
standby offline and to instruct an offline
standby Controller to synchronise itself with
the Controller and to enter standby.
If a SafetyNet Controller has entered the
“Failsafe” state, it can be brought out of this
state by use of the “Change State” button.
Serial communications
Each SafetyNet Controller provides two
serial ports - one of which is physically
connected via the Controller Carrier, the
other directly on the Controller itself. The two
ports can be configured to be entirely
independent, or can be made to work
redundantly, either as redundant
connections to the same serial link or as
redundant connections to redundant links.
When redundant ports of a single Controller
are configured as Modbus masters,
redundancy issues are handled
automatically by the SafetyNet Controller
(deciding when to switch to the standby port,
alarming failures in the standby).
When redundant ports of a single Controller
are configured as Modbus slaves and multidropped on a single serial link, the
SafetyNet Controller will again manage the
redundancy (deciding which port respond to
the Modbus master and alarming a fault in
the standby port).
When redundant Controllers are used, this
adds additional availability to the
arrangements above. It is not possible to use
the ports on the standby Controller as
additional serial connections.

♦ Certified for use in SIL 2 safety applications, according to
IEC 61508
♦ Comprehensive internal diagnostics provide basis for
safety architecture 1oo1D
♦ Optional redundancy with bumpless transfer for increased
availability
♦ Dual redundant high speed fault tolerant Ethernet LAN
♦ Two connections to serial devices
♦ On-line configuration and re-configuration
♦ Communicates with up to 64 I/O modules
♦ Communicates on peer-to-peer basis with other SafetyNet
and standard Controllers
♦ Can write to standard output modules without
compromising safety function
♦ Live maintainable and hot-swappable - even in Class 1,
Div 2 or Zone 2 hazardous areas
♦ HART pass-through of process and status variables
♦ Event logging up to 8000 events
♦ 12Vdc Controller power required from 8913-PS-AC
CONTROLLER SPECIFICATION
See also System Specification
LAN INTERFACE
Transmission medium.............100BaseTX or 10BaseT Ethernet™
Transmission protocol........................................SafetyNet P2P*
Transmission rates ........................................10 - 100 Mbits/s
LAN connector type (x2) .................................RJ 45 (8-pin)
LAN isolation (dielectric withstand)............................1500 V
Action on software malfunction ............Halt CPU / Reset CPU
* SafetyNet P2P is a modified form of Modbus™ certified as suitable
for use in SIL 2 safety related applications that require peer-to-peer
communication.
SERIAL INTERFACES (COM 1 & COM 2)
Transmission rates.....................1.2 – 115.2 kbits/s (async.)
Transmission standard.................................RS485 half-duplex
COM 1 connector (on carrier).............9-pin D-type connector (F)
COM 2 connector (on controller) .......9-pin D-type connector (M)
HAZARDOUS AREA SPECIFICATION
Protection Technique............................................EEx nL IIC T4
Location (FM and CSA) ...........Class 1, Div.2, Grps A,B,C,D T4
POWER SUPPLIES
Controller Power Voltage................12V dc (from 8913-PS-AC)
Controller Power Supply............0.4A (typical), 0.5A (max.)
System Power Supply......................................15mA (max.)
MECHANICAL
Module dimensions .....................69 (w) x 232 (l) x 138 (h) mm
Weight (approx.)..............................................................1.35kg