High Availability Systems Manual
High Availability Systems Manual
Activities including installation, adjustments, putting into service, use, assembly, disassembly, and maintenance are required to
be carried out by suitably trained personnel in accordance with applicable code of practice.
If this equipment is used in a manner not specified by the manufacturer, the protection provided by the equipment may be
impaired.
In no event will Rockwell Automation, Inc. be responsible or liable for indirect or consequential damages resulting from the use
or application of this equipment.
The examples and diagrams in this manual are included solely for illustrative purposes. Because of the many variables and
requirements associated with any particular installation, Rockwell Automation, Inc. cannot assume responsibility or liability for
actual use based on the examples and diagrams.
No patent liability is assumed by Rockwell Automation, Inc. with respect to use of information, circuits, equipment, or software
described in this manual.
Reproduction of the contents of this manual, in whole or in part, without written permission of Rockwell Automation, Inc., is
prohibited.
Throughout this manual, when necessary, we use notes to make you aware of safety considerations.
WARNING: Identifies information about practices or circumstances that can cause an explosion in a hazardous environment,
which may lead to personal injury or death, property damage, or economic loss.
ATTENTION: Identifies information about practices or circumstances that can lead to personal injury or death, property
damage, or economic loss. Attentions help you identify a hazard, avoid a hazard, and recognize the consequence.
IMPORTANT Identifies information that is critical for successful application and understanding of the product.
SHOCK HAZARD: Labels may be on or inside the equipment, for example, a drive or motor, to alert people that dangerous
voltage may be present.
BURN HAZARD: Labels may be on or inside the equipment, for example, a drive or motor, to alert people that surfaces may
reach dangerous temperatures.
ARC FLASH HAZARD: Labels may be on or inside the equipment, for example, a motor control center, to alert people to potential
Arc Flash. Arc Flash will cause severe injury or death. Wear proper Personal Protective Equipment (PPE). Follow ALL Regulatory
requirements for safe work practices and for Personal Protective Equipment (PPE).
Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
About This Publication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Download Firmware, AOP, EDS, and Other Files . . . . . . . . . . . . . . . . . . . . 5
Additional Resources . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Chapter 1
High Availability Systems What is High Availability?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
Methods to Improve Availability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
Increase Availability with ControlLogix Redundancy . . . . . . . . . . . . . . . . 8
Chapter 2
High Availability Redundant Controllers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
System Components ControlLogix 5580 Redundant Controllers . . . . . . . . . . . . . . . . . . . . . 10
ControlLogix Chassis Power Supplies. . . . . . . . . . . . . . . . . . . . . . . . . . 11
Redundancy Modules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
Communication Modules in a Redundant Chassis . . . . . . . . . . . . . . 12
I/O Networks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Network Communication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Network Nodes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Legacy Networks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
I/O Products. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
1756 ControlLogix I/O . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
1715 Redundant I/O . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
FLEX 5000 I/O . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
1794 FLEX I/O . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
1734 POINT I/O . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Field Device Interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
FOUNDATION Fieldbus Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
PROFIBUS PA Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
Chapter 3
High Availability Networks General Network Guidelines . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
IT/OT Convergence . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Dedicated Upstream Communication for Non-converged Topologies. 23
Upstream Redundant Star Versus Ring Topologies . . . . . . . . . . . . . 24
Network Cable Routing Considerations. . . . . . . . . . . . . . . . . . . . . . . . 25
Recommended Topologies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
DLR I/O Network Topologies and Design Guidelines . . . . . . . . . . . . . . . 28
Direct DLR, Non-converged Topology . . . . . . . . . . . . . . . . . . . . . . . . . 29
Indirect DLR, Non-converged Topology. . . . . . . . . . . . . . . . . . . . . . . . 30
Fiber Segments within DLR Networks . . . . . . . . . . . . . . . . . . . . . . . . . 32
Indirect Nodes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Direct DLR, Converged Topology. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
Chapter 4
Additional High Availability Virtualization. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39
Considerations Computer Hardware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
Application Level Redundancy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
Microsoft Domain Controllers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
FactoryTalk Directory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41
FactoryTalk Server Redundancy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42
FactoryTalk View Site Edition (SE) HMI Servers . . . . . . . . . . . . . . . . 42
FactoryTalk Alarms and Events Servers . . . . . . . . . . . . . . . . . . . . . . . . 42
FactoryTalk Linx or OPC Data Servers . . . . . . . . . . . . . . . . . . . . . . . . . 42
FactoryTalk ThinManager Redundancy . . . . . . . . . . . . . . . . . . . . . . . . . . . 43
FactoryTalk Historian Redundancy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44
Redundant ControlLogix Controller Shortcut Paths . . . . . . . . . . . . . . . . 45
Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
About This Publication This publication describes guidelines for high availability systems, including
redundant system components, networks, and other hardware and software
considerations.
Download Firmware, AOP, Download firmware, associated files (such as AOP, EDS, and DTM), and access
EDS, and Other Files product release notes from the Product Compatibility and Download Center at
[Link]/pcdc.
Additional Resources These documents contain additional information concerning related products
from Rockwell Automation.
Table 1 - Additional Resources
Resource Description
Controllers Reduce Unplanned Downtime with Logix Redundant Control Solutions, Provides an overview and high-level features of Logix redundant
publication 1756-PP014 controller solutions.
ControlLogix 5580 Redundant Controller User Manual, Describes how to install, configure, program, operate, and troubleshoot
publication 1756-UM015 a ControlLogix® 5580 redundancy system.
Configuration and Implementation User Manual, Provides guidelines and procedures for the implementation and
publication PROCES-UM100 configuration of a PlantPAx® distributed control system.
ControlLogix Redundant Power Supply Installation Instructions, Describes how to install, remove, and troubleshoot a redundant power
publication 1756-IN620 supply system.
ControlLogix 5580 and GuardLogix 5580 Controllers User Manual, Provides information about designing a system, operating a
publication 1756-UM543 ControlLogix or GuardLogix®-based controllers system, and developing
applications.
I/O Redundant I/O System User Manual, publication 1715-UM001 Describes how to install, configure, program, operate, and troubleshoot
a Redundant I/O system.
FLEX 5000 Standard and Safety I/O Modules User Manual, Describes how to use FLEX 5000™ standard and safety I/O modules in
publication 5094-UM001 Logix 5000™ control systems.
FLEX I/O, FLEX I/O-XT, and FLEX Ex Selection Guide, Provides guidance about how to select FLEX™ I/O, FLEX I/O-XT™, and
publication 1794-SG0002 FLEX Ex™ products.
Field devices EtherNet/IP and ControlNet to FOUNDATION Fieldbus Linking Device User Describes installation and operation of the 1788-EN2FFR and
Manual, publication 1788-UM057 1788-CN2FFR linking devices.
FOUNDATION Fieldbus Design, see the FOUNDATION Fieldbus Design Provides design choices and practices for implementing a FOUNDATION
Considerations Reference Manual, publication PROCES-RM005 Fieldbus network with the 1788-EN2FFR and 1788-CN2FFR linking
devices.
EtherNet/IP and ControlNet to PROFIBUS-PA Linking Device User Manual, Describes the installation and operation of the 1788-EN2PAR and 1788-
publication 1788-UM05 CN2PAR linking devices.
Networks Converged Plantwide Ethernet (CPwE) Design and Implementation Guide, Represents a collaborative development effort from
publication ENET-TD001 Rockwell Automation and Cisco® Systems. The design guide is built on,
and adds to, design guidelines from the Cisco Ethernet-to-the-Factory
(EttF) solution and the Rockwell Automation® Integrated Architecture™.
The design guide focuses on the manufacturing industry.
Deploying Device Level Ring within a Converged Plantwide Ethernet Provides design recommendations for connecting device-level
Architecture, publication ENET-TD015 topologies to networks comprised of Layer 2 switches. It also covers the
implementation of embedded switch technology within the Converged
Plantwide Ethernet (CPwE) Cell/Area zone.
Deploying the Resilient Ethernet Protocol (REP) in a Converged Plantwide Describes the implementation of REP for a switch ring topology in the
Ethernet System (CPwE) Design Guide, publication ENET-TD005 CPwE system.
EtherNet/IP Device Level Ring Application Technique, Describes Device Level Ring (DLR) topologies, configuration
publication ENET-AT007 considerations, and diagnostic methods.
EtherNet/IP Parallel Redundancy Protocol Application Technique, Describes Parallel Redundancy Protocol (PRP) topologies, configuration
publication ENET-AT006 considerations, and diagnostic methods.
Topic Page
What is High Availability? 7
Methods to Improve Availability 8
Increase Availability with ControlLogix Redundancy 8
What is High Availability? Availability is the percentage of time that a system is functioning and able to
perform its mission. High availability is a characteristic of a system that aims
to achieve an agreed level of availability, for a higher than normal period.
Investing in a high availability system over simply an available one can make a
significant difference in lost time or costs due to unscheduled downtime.
Methods to Improve When considering different methods to improve the availability of a system, it
Availability helps to understand some of the most common causes for unplanned
downtime. Operational errors, hardware, software, and other control system
infrastructure failures are common causes of unplanned downtime.
Increase Availability with This publication focuses on ControlLogix® 5580 redundancy with
ControlLogix Redundancy EtherNet/IP™ I/O networks. Rockwell Automation provides redundancy
solutions for many different components of a ControlLogix system. Product
selection for high availability is dependent on application requirements.
Topic Page
Redundant Controllers 9
I/O Networks 13
I/O Products 14
Field Device Interfaces 18
For more information about ControlLogix 5580 process controllers, see the
Configuration and Implementation User Manual, publication
PROCES-UM100.
(1) PlantPAx guidelines also recommend only one controller per ControlLogix redundancy
chassis. Non-PlantPAx ControlLogix 5570 redundancy applications support as many as two
controllers in each redundant chassis. If a non-PlantPAx application requires two controllers
in a redundant chassis, use a ControlLogix 5570 solution.
10 Rockwell Automation Publication HIGHAV-RM002A-EN-P - September 2020
Chapter 2 High Availability System Components
Each power supply includes the option to add annunciator wiring to connect
the power supplies to remote input modules. Power supply annunciator wiring
enables quick isolation and detection of failures, which directly impacts
system maintainability. For more information, see the ControlLogix
Redundant Power Supply Installation Instructions, publication 1756-IN620.
Annunciator Wiring
Redundancy Modules
I/O Networks ControlLogix 5580 redundancy connects with I/O devices through EtherNet/IP
networks only.
Network Communication
Network Nodes
Legacy Networks
(1) The Logix Designer application enables you to build a ControlLogix 5580 redundancy
application with DeviceNet scanners in a remote chassis. However, a warning appears when
verifying the application because DeviceNet outputs are not bumpless during a ControlLogix
5580 redundancy switchover. For that reason, we recommend that you do not use DeviceNet
with ControlLogix 5580 redundancy.
Rockwell Automation Publication HIGHAV-RM002A-EN-P - September 2020 13
Chapter 2 High Availability System Components
I/O Products ControlLogix 5580 redundancy supports most standard and redundant I/O
products. Legacy 1747, 1746, 1771, and 1769 I/O products are not supported. The
following section highlights the most common I/O networks that you can use
with ControlLogix 5580 redundancy.
For added resiliency at the adapter level in a ControlLogix I/O chassis, use
redundant 1756-EN4TR adapters. In a qualified adapter pair, one adapter acts
as the primary and controls the I/O, while the other adapter acts as a secondary
and can take over as the primary if needed. Redundant adapter functionality is
available for 1756-EN4TR adapters with firmware revision 3.001 and later.
1715 Redundant I/O provides these features to help increase system availability:
• Redundant, partnered EtherNet/IP adapters monitor inputs, outputs,
and diagnostics for I/O modules in the remote chassis. If a fault occurs in
one of the redundant adapters, an IP address switchover occurs and I/O
monitoring and communication to the ControlLogix System continues
without interruption. This switchover is transparent. Status information
available to the ControlLogix application enables you to determine the
status of each 1715-AENTR adapter.
• Support for duplex I/O module pairs provides fault tolerance for module
failures. You can install or remove a partnered I/O module while the
system is operational without impact to the rest of the system.
• Hardware and software diagnostic features indicate when a module fault
occurs. Module status indicators and the Logix Designer application
graphically display faults. Fault messages describe the nature of the fault.
These features show how a module has been affected and what action to
take to resume normal operation.
• Removal and insertion under power (RIUP) lets you replace modules and
make cable connections while the system is in operation.
• Electronic keying helps prevent replacement errors.
IMPORTANT If you use 1715 Redundant I/O with ControlLogix 5580 redundancy, SIL 2
cannot be achieved. Systems that require SIL 2 with 1715 Redundant I/O
and ControlLogix redundancy must use a ControlLogix 5570 redundant
controller solution.
Each ControlLogix I/O chassis with redundant EtherNet/IP adapters counts as two
DLR nodes towards the recommended limit of 50 nodes per DLR network.
FLEX 5000™ adapters with firmware revision 5.011 or later offer a rugged,
distributed I/O solution for ControlLogix redundancy systems:
• 1 gigabit (Gb) backplane speed and 1 Gb EtherNet/IP connectivity
provides higher speed and increased bandwidth.
• Two copper or two fiber SFP ports provide flexibility in network
architecture.
FLEX 5000 I/O provides these features to help increase system availability:
• Support for DLR and PRP for fault tolerant network topologies
• Removal and insertion under power (RIUP) lets you replace modules and
make cable connections while the system is in operation
• Visibility to device tag diagnostics based on Device Description (DD) files
for ease of maintenance
• Support for HART 8-channel analog I/O modules with Premier
Integration in the Logix Designer application helps to reduce downtime
with process diagnostics
• Available with conformal coating for durability
• G3 rating for harsh environments
For more information, see the FLEX 5000 Standard and Safety I/O Modules
User Manual, publication 5094-UM001.
1794 FLEX™ I/O modules offer flexibility with digital, analog, HART analog,
and specialty I/O:
• Removal and Insertion Under Power (RIUP) lets you replace modules
and make cable connections while the system is in operation.
• Adjustable keyswitch helps prevent incorrect module insertion into a
preconfigured terminal base.
• FLEX I/O provides additional savings if system problems develop.
Combining field-wiring terminations and the I/O interface into the same
location saves time and money by making the system easier to maintain
and troubleshoot.
For additional information, see the FLEX I/O, FLEX I/O-XT™, and FLEX Ex™
Selection Guide, publication 1794-SG0002.
1734 POINT I/O™ modules offer digital, analog, and specialty I/O. POINT I/O
modules provide these features to help increase system availability:
• Modules slide together to provide ease of installation and maintenance
• Removable wiring system saves time during installation and
troubleshooting
• Comprehensive diagnostics
• Removal and Insertion Under Power (RIUP) lets you replace modules
while the system is in operation
• Auto Device Replacement (ADR) reduces downtime
• Available with conformal coating for durability
Field Device Interfaces Redundant process network interfaces are available for FOUNDATION
Fieldbus and PROFIBUS PA networks.
For more information about the FOUNDATION Fieldbus H1 linking device, see
the EtherNet/IP and ControlNet to FOUNDATION Fieldbus Linking Device
User Manual, publication 1788-UM057.
PROFIBUS PA Devices
Notes:
Topic Page
General Network Guidelines 21
Recommended Topologies 27
DLR I/O Network Topologies and Design Guidelines 28
PRP I/O Network Topologies and Design Guidelines 35
General Network Guidelines The following guidelines apply to all networks and provide important
considerations for system availability.
IT/OT Convergence
Non-converged
I/O Network
With a converged I/O network, you can reach the I/O network from the
manufacturing zone without traversing the controller chassis backplane.
Converged I/O networks potentially improve availability by providing direct
access to devices in the I/O networks, which can simplify maintenance.
Converged
I/O Network
Redundant star and ring topologies are common design choices for high
availability between controllers and distribution switches. For maximum
network performance and availability, Cisco® and Rockwell Automation
recommend that you plan, design, and implement network topologies that are
based on the redundant star configuration. However, requirements can
dictate the use of other topologies. The following table highlights the key
advantages and disadvantages of the redundant star versus ring topology
solutions.
• Resiliency from multiple connection failures • Resiliency from loss of one network connection
• Faster convergence to connection loss • When using Resilient Ethernet Protocol (REP), convergence times range from
• Consistent number of hops (typically two in a flat design) provides predictable 50…150 ms
and consistent performance and real-time characteristics • Variable number of hops makes designing predictable performance more
• Fewer bottlenecks in the design reduce the chances of segment over-subscription complex
• Less cabling complexity in certain plant floor layouts
• Multiple paths reduce the potential for over-subscription and bottlenecks
For more information, see the Converged Plantwide Ethernet (CPwE) Design
and Implementation Guide, publication ENET-TD001.
For more information about Resilient Ethernet Protocol (REP), see the
Deploying the Resilient Ethernet Protocol (REP) in a Converged Plantwide
Ethernet System (CPwE) Design Guide, publication ENET-TD005.
Building 1
Building 2
Central Building
Recommended Topologies This chapter provides recommended topologies and design guidance for high
availability Ethernet networks that include ControlLogix redundancy. The
recommended topology protocols include Device Level Ring (DLR) and Parallel
Redundancy Protocol (PRP). These protocols provide either single- or multiple-
fault tolerance. The following table summarizes the important differences
between the protocols.
While other topologies and configurations can be valid, follow these tested
topologies to decrease the risk of network downtime:
• Direct DLR, Non-converged Topology on page 29
• Indirect DLR, Non-converged Topology on page 30
• Direct DLR, Converged Topology on page 34
• PRP, Non-converged Topology on page 36
• PRP, Converged Topology on page 37
DLR I/O Network Topologies Device Level Ring (DLR) is an EtherNet/IP™ protocol that is defined by the
and Design Guidelines Open DeviceNet Vendors’ Association (ODVA). DLR provides a means to
detect, manage, and recover from single faults in a ring-based network.
Node Description
A ring supervisor provides these functions:
• Manages traffic on the DLR network
Ring supervisor • Collects diagnostic information for the network
A DLR network requires at least one node to be configured as ring supervisor.
By default, the supervisor function is disabled on supervisor-capable devices.
Ring participants provide these functions:
• Process data that is transmitted over the network.
Ring participants • Pass on the data to the next node on the network.
• Report fault locations to the active ring supervisor.
When a fault occurs on the DLR network, ring participants reconfigure themselves and
relearn the network topology.
Redundant gateways are multiple switches that are connected to a single DLR network
Redundant gateways and also connected together through the rest of the network.
(optional) Redundant gateways provide DLR network resiliency to the rest of the network.
For more information about DLR, see the EtherNet/IP Device Level Ring
Application Technique, publication ENET-AT007.
This topology is less common than the direct DLR, non-converged topology
described on page 29. However, it provides another topology option that can be
beneficial, depending on where the controllers and I/O are physically located.
For example, consider a scenario where the redundant controllers are in a
central location that is a considerable distance from the I/O. With this indirect
DLR topology, 1756 EtherNet/IP fiber modules in the redundant chassis pair
can connect to the remote Stratix switches in the field. This could potentially
reduce the amount of required fiber for the system, depending on how the I/O
is physically distributed throughout a facility.
DLR 1, VLAN 10
DLR 2, VLAN 20
DLR 3, VLAN 30
DLR 1, VLAN 10
DLR 2, VLAN 20
DLR 3, VLAN 30
VLAN Considerations
IMPORTANT When using an Ethernet tap, know that the device counts as a DLR node,
even if no device is connected to the non-DLR port. Each Ethernet tap
counts against the recommended maximum of 50 nodes per DLR
network. For more information, see the EtherNet/IP Device Level Ring
Application Technique, publication ENET-AT007.
Indirect Nodes
When designing a DLR network, you can indirectly connect nodes to a DLR
network through a Stratix switch.
A direct DLR, converged I/O topology uses DLR gateways to converge the I/O
network with the manufacturing zone. Converged I/O networks can
potentially improve availability by providing direct access to devices in the I/O
networks, which can simplify maintenance workflows.
When a DLR redundant gateway switchover occurs, traffic traversing the DLR
gateways can be interrupted. If an application requires peer-to-peer, produce/
consume traffic through DLR redundant gateways, and the application cannot
tolerate the traffic disruption, we recommended that the design keeps
peer-to-peer communication on its own dedicated DLR network.
PRP I/O Network Topologies Parallel Redundancy Protocol (PRP) is defined in international standard
and Design Guidelines IEC 62439-3 and provides high availability in Ethernet networks. PRP
technology creates seamless redundancy by sending duplicate frames to two
independent network infrastructures, which are known as LAN A and LAN B.
Component Description
LAN A and LAN B Redundant, active Ethernet networks that operate in parallel.
Double attached node (DAN) An end device with PRP technology that connects to both LAN A and LAN B.
An end device without PRP technology that connects to either LAN A or LAN B.
Single attached node (SAN) A SAN does not have PRP redundancy.
A switch with PRP technology that connects devices without PRP technology to
Redundancy box (RedBox) both LAN A and LAN B.
An end device without PRP technology that connects to both LAN A and LAN B
Virtual double attached node through a RedBox.
(VDAN) A VDAN has PRP redundancy and appears to other nodes in the network as a DAN.
A switch that connects to either LAN A or LAN B and is not configured as a
Infrastructure switch RedBox.
For for more information about PRP, see the EtherNet/IP Parallel Redundancy
Protocol Application Technique, publication ENET-AT006.
All PRP network design guidelines apply to all PRP networks, regardless of
whether there are redundant ControlLogix chassis in the design. For more
information about PRP, including more restrictions and requirements, see the
EtherNet/IP Parallel Redundancy Protocol Application Technique, publication
ENET-AT006.
LAN A LAN B
Stratix 5400 RedBoxes can connect a PRP network to the supervisory network.
The following must be Layer 3 routed connections:
• Connections between RedBoxes and distribution switches in the
manufacturing zone
• Connections between RedBoxes
For Layer 3 redundancy in the PRP network, you can configure Hot Standby
Routing Protocol (HSRP) on redundant RedBoxes.
In Figure 19, all four Stratix 5400 switches are configured as RedBoxes.
LAN A LAN B
When incorporating ControlLogix I/O chassis into a PRP topology, you can
increase availability further by using redundant EtherNet/IP adapters.
Redundant adapters eliminate a single point of failure in the ControlLogix I/O
chassis.
LAN A LAN B
RedBoxes
Topic Page
Virtualization 39
Computer Hardware 40
Application Level Redundancy 40
FactoryTalk Server Redundancy 42
FactoryTalk ThinManager Redundancy 43
FactoryTalk Historian Redundancy 44
Redundant ControlLogix Controller Shortcut Paths 45
Computer Hardware Most control systems rely on computer hardware. When multiple virtual
machines run on one physical host, a hardware failure can have a broader
impact than a 1:1 server-to-application model. By improving the reliability of
computer infrastructure, you can help to maintain a continuously available
processing environment. Some common ways to improve system reliability
with computer hardware are as follows:
• Uninterruptible power supplies (UPS)—Provide emergency power to a
load when the input power source or main power fails.
• Network Interface Card (NIC) Teaming—Provides fault tolerance or load
balancing.
• Redundant Array of Independent Disk (RAID)—Computer hard drive
virtualization technology that combines multiple physical disk drive
components into one or more logical units for data redundancy,
performance improvement, or both.
Application Level Server applications that are not configured for redundancy introduce
Redundancy potential single points of failure. Both Microsoft® and Rockwell Automation
offer ways to increase system availability with application level redundancy.
System designers must determine the level of application level redundancy
that best match their application and economic requirements.
If any of these three functions are unavailable or perform poorly, then the
entire distributed system can be adversely impacted. To provide these
functions in a centralized and secure manner, use a Windows® domain that is
implemented to optimize performance and resiliency. For systems with more
than 10 machines, a domain is required to minimize effort, centralize
administration, and provide additional security than a Windows workgroup
can provide.
For all high availability architecture designs, we strongly recommend that you
have redundant domain controllers. Place the domain controllers in a
replicating pair close to and on the same network segment as the
manufacturing zone.
FactoryTalk Directory
The FactoryTalk Directory role provides a central lookup service for all
FactoryTalk products in an application. The FactoryTalk Directory references
tags and other system elements, such as screens, from multiple data sources
and makes the information available to clients through a lookup service.
Although you can locate the FactoryTalk Directory on the same host as another
FactoryTalk server component, such as a primary HMI server or Historian SE
server, this is not a best practice for high availability. To reduce risk and
maximize availability, we recommend that the FactoryTalk Directory role is
located on a separate host apart from any other FactoryTalk component for
these reasons:
• System startup—It is best if the FactoryTalk Directory is the first
component to start and the last to stop. Because most FactoryTalk
software products rely on various services that the FactoryTalk Directory
provides, the lowest risk scenario is to make directory available as these
products start up.
• Compatibility—While all CPR9 versions are generally compatible, the
FactoryTalk Directory is sometimes required to be at the highest version
of FactoryTalk Services Platform installed in the system. This
requirement can interfere with another FactoryTalk component if the
FactoryTalk Directory is co-located with another product.
• Patching/upgrading—Maintenance of the FactoryTalk Directory role
hosted on a dedicated computer translates to minimum system
downtime because it does not affect the operation of other FactoryTalk
components while restarting.
• Redundancy—In systems with other redundant FactoryTalk servers, it is
best if the FactoryTalk Directory remains available during any failover
scenarios. While the redundant server pair can function without the
FactoryTalk Directory, the lowest risk scenario is to keep it available.
FactoryTalk Server In a FactoryTalk View SE network distributed application, you can configure
Redundancy redundancy on paired computers for critical FactoryTalk components.
FactoryTalk server redundancy can be configured for the following products.
If the primary HMI server cannot provide service to application clients, the
system automatically switches to the secondary server, and FactoryTalk View
SE clients continue to function normally. There is no need to restart client or
active server computers. For more information, see the FactoryTalk View Site
Edition User Guide, publication VIEWSE-UM006.
Control Room
HMI HMI CMMS HTTTP ERP MES
Applications
& Content
ThinManager Deliver sessions to multiple Access Feeds from
monitors and virtual screens USB & IP Cameras
Application
on one thin client.
Delivery Provides secure configuration and content delivery
to any combination of device, user, and location.
PanelView Plus
Deliver content to the right person
Users at the right time and place.
Remote Desktop to HMI
VersaView 5200
Assigns content to users. Industrial Thin Clients
Applications follow a user Manage & deliver
Deliver applications based virtual desktops
from terminal to terminal.
on what is assigned to the while running PCs
terminal or user. Get mobile access to applications
as a thin client.
specific to user roles.
Offices
FactoryTalk Historian Data loss prevention can be one of the most critical considerations when
Redundancy designing a system that requires high availability. FactoryTalk Historian SE
provides separate methods for data collection redundancy and data
availability redundancy.
Clients
User workstation connects to
any available data source.
One way to minimize the path from a ControlLogix® data source and a
data collector is to use Historian ME modules. You can place Historian
ME modules in a non-redundant ControlLogix chassis that is located as
close as possible to the data source. Like interface nodes, Historian ME
modules can buffer historical data if the module temporarily loses
communication with the Historian SE server. The Historian ME module
forwards its buffered data to the Historian SE server once
communications is established.
For more information about the Historian ME module, see the Historian ME
Module Configuration Guide, publication 1756-UM106.
Redundant ControlLogix When configuring the connection between a FactoryTalk Linx data server and
Controller Shortcut Paths a redundant ControlLogix controller, you can configure redundant shortcut
paths to the primary and secondary controllers. These shortcut paths help to
reduce data server communication recovery time during a redundancy
switchover. Data server communication recovery time applies to any software
that uses tag data, such as HMI displays, data loggers, alarm systems, or
historians.
Notes:
Numerics DLR
about 28
1734 POINT I/O 17 direct, non-converged topologies 29
1756 ControlLogix I/O 14 fiber segments 32
1756 Redundant I/O 15 indirect nodes 33
1756-EN4TR adapters 12, 14 indirect, non-converged topologies 30
1756-RM2 redundancy modules 11 PRP comparison 27
redundant gateways 34
1794 FLEX I/O 17 VLAN considerations 31
domain controllers 40
A
adapters E
1756-ENT4TR 12, 14 enable redundancy 9
FLEX 5000 16
EtherNet/IP adapters,1756-ENTR 14
annunciator wiring 11
explicit messaging 13
availability
methods to improve 8
percentage 7 F
FactoryTalk Alarms and Events 42
B FactoryTalk Directory 41
bridged I/O topologies 15 FactoryTalk Historian 44
FactoryTalk Linx 42, 45
FactoryTalk Server 42
C FactoryTalk Services 40
cable routing 25 FactoryTalk ThinManager 43
chassis, redundant 12 FactoryTalk View SE 42
CIP 22 fault tolerance
communication modules 12 multiple 27
computer hardware 40 single 27
conformal coating 14, 16, 17 fiber ports, redundant 11
consumed tags 13 fiber segments 32
controller resources 13 field device interfaces 18
controllers FLEX 5000 I/O 16
ControlLogix 5570 10 FOUNDATION Fieldbus devices 18
ControlLogix 5580 10
GuardLogix 5580 10
ControlLogix 5570 redundancy 10 G
ControlLogix 5580 redundancy 9 - 12 gateways, redundant 34
ControlLogix chassis 11 GuardLogix 5580 controllers 10
ControlNet network 13
converged plantwide Ethernet 21
converged topologies 22, 27, 34, 37 H
hardware, computer 40
Historian SE servers 44
D HMI redundancy 42
data loss prevention 44
data servers 42, 44, 45
DeviceNet network 13 I
DH+ network 13 I/O products
direct DLR topologies 29 1715 Redundant I/O 15
distributed control system 10 1734 POIN I/O 17
1756 ControlLogix 14
1794 FLEX 17
FLEX 5000 16
indirect nodes 33
interfaces, field device 18
R V
RedBoxes 37
virtualization 39
redundancy modules 11
VLAN considerations 31
redundancy, ControlLogix 5580 8, 9, 10
redundant gateways 34
redundant shortcut paths 45 W
redundant star 24 wiring, annunciator 11
Technical Support Center Find help with how-to videos, FAQs, chat, user forums, and product notification updates. [Link]/support
Knowledgebase Access Knowledgebase articles. [Link]/knowledgebase
Local Technical Support Phone Numbers Locate the telephone number for your country. [Link]/phonesupport
Literature Library Find installation instructions, manuals, brochures, and technical data publications. [Link]/literature
Product Compatibility and Download Center Download firmware, associated files (such as AOP, EDS, and DTM), and access product [Link]/pcdc
(PCDC) release notes.
Documentation Feedback
Your comments help us serve your documentation needs better. If you have any suggestions on how to improve our
content, complete the form at [Link]/docfeedback.
At the end of life, this equipment should be collected separately from any unsorted municipal waste.
Rockwell Automation maintains current product environmental compliance information on its website at [Link]/pec.
Allen-Bradley, CIP, ControlLogix, DH+, Integrated Architecture, FactoryTalk, FLEX, FLEX 5000, FLEX Ex, FLEX I/O-XT, GuardLogix, Logix 5000, PlantPAx, PLC-2, PLC-5, POINT I/O,
Rockwell Automation, Rockwell Automation Encompass, Rockwell Software, SLC, Stratix, and Studio 5000 Logix Designer, and ThinManager, are trademarks of Rockwell Automation, Inc.
CIP, CIP Sync, ControlNet, DeviceNet, and EtherNet/IP are trademarks of ODVA, Inc.
Cisco and Cisco Systems are trademarks of Cisco Systems, Inc.
Microsoft and Windows are trademarks of Microsoft Corporation.
Trademarks not belonging to Rockwell Automation are property of their respective companies.
Rockwell Otomasyon Ticaret A.Ş. Kar Plaza İş Merkezi E Blok Kat:6 34752, İçerenköy, İstanbul, Tel: +90 (216) 5698400 EEE Yönetmeliğine Uygundur