Marcio Cunha

Redundancy and Failover Configuration in PLCs with Redundant Modbus TCP Networks

Learn how to architect redundant Modbus TCP networks for Programmable Logic Controllers, ensuring high availability and seamless transition in industrial environments.

Marcio Cunha•5 min
Also available in:EspañolPortuguês
Summary
  • Industrial bus redundancies require ring network topologies to eliminate physical and logical single points of failure.
  • The Modbus TCP protocol operates over standard Ethernet layers, requiring heartbeat mechanisms to detect connection drops between primary and backup PLCs.
  • Synchronizing retentive memory and control tags between controllers reduces downtime to mere milliseconds.
  • Managed switches with link redundancy protocols prevent broadcast storms during device role transitions.
  • Rigorous hardware failure simulation tests validate the integrity of the switching logic prior to production deployment.

High Availability Architecture in Industrial Automation

In modern manufacturing environments, unplanned downtime of a production process results in catastrophic financial losses. This is why engineers rely on fault-tolerant systems where two Programmable Logic Controllers (the electronic brains that command machines and processes) work in synchronization. While the primary controller executes the control logic and commands the actuators, the secondary controller remains in standby mode, ready to take over instantly should the first exhibit any physical or software anomaly.

In practice, this strategy is known as hardware redundancy with failover (an automated transition mechanism to a backup system). For this to work seamlessly, devices must continuously exchange state data over a robust communication network. When discussing industrial networks, the Modbus TCP protocol emerges as a popular choice due to its simplicity and openness, but its original nature was not natively designed for complex redundancy. Overcoming this limitation requires intelligent network architectures and additional software layers.

The Role of Modbus TCP in Critical Control Networks

Modbus TCP encapsulates classical Modbus industrial protocol messages inside standard Ethernet network packets, using TCP port 502 to transmit commands and readings between devices. In engineering terms, this means we can use common IT market network switches and cables to connect our PLCs to sensors, HMIs (Human-Machine Interfaces), and supervisory servers (SCADA). However, because traditional Modbus operates on a strict client-server relationship (formerly master-slave), managing two servers sending identical commands without causing write conflicts requires rigorous architectural planning.

To implement redundancy, we configure the primary PLC to actively interact with field devices, while the secondary PLC listens to the traffic or periodically queries the primary to update its internal memory. If the connection with the primary PLC is lost, the supervision system and network nodes transition to the secondary PLC's IP address. This handover must happen in fractions of a second to prevent valves from closing incorrectly or motors from stopping abruptly, ensuring operational plant safety.

Network Topologies and Fault Detection Mechanisms

The reliability of a redundant Modbus TCP network directly depends on the physical infrastructure supporting it. Simple star topologies leave the central switch as a single point of failure, violating high availability principles. The solution is to adopt ring topologies using managed industrial switches that support link recovery protocols, such as MRP (Media Redundancy Protocol) or RSTP (Rapid Spanning Tree Protocol). These protocols reorganize data paths in a few milliseconds if a cable is severed or a switch fails.

Beyond the physical layer, logical detection of PLC failure occurs through monitoring packets known as heartbeats. This is a digital signal sent cyclically between the two controllers. If the secondary PLC stops receiving this pulse within a predetermined time window, it assumes the primary has failed. Immediately, it activates its physical outputs, takes over the shared floating IP addresses, and begins responding to Modbus TCP requests from supervisory systems as the new process master.

Data Synchronization and Floating IP Management

One of the greatest challenges in configuring redundant PLCs is ensuring that both devices possess the exact same internal state at the moment of transition. If the primary PLC was controlling a conveyor belt at position 3 and failed, the secondary PLC cannot restart the process from zero. It needs to know the belt was at position 3 to continue operation without causing parts collisions or raw material waste. This synchronization of retentive variables and process data occurs via a dedicated high-speed communication port between the two controllers.

For the rest of the network, the command switch must be completely transparent, eliminating the need to reconfigure IP addresses plant-wide. This is resolved by using a floating or virtual IP address. Both the primary and backup PLCs share this logical identity on the network, but only the currently active device responds to packets destined for this address. When failover occurs, the virtual IP instantly migrates to the backup controller's network interface, ensuring supervisory software continues reading and writing to the exact same Modbus TCP registers without noticing the hardware swap.

Practical Implementation and Configuration Strategy

The practical configuration of a redundant environment requires establishing dedicated routines within the PLC programming logic. Below, we present a simplified snippet in structured text simulating heartbeat verification and takeover by the secondary PLC.

// Routine executed on the Secondary PLC for Failover monitoring
VAR
    Heartbeat_Primary : BOOL;
    Timer_Failover : TON;
    Active_Control : BOOL;
END_VAR

// Check if the primary's heartbeat signal is still oscillating
Timer_Failover(IN := NOT Heartbeat_Primary, PT := T#500MS);

IF Timer_Failover.Q THEN
    // Time limit expired; take over process control
    Active_Control := TRUE;
    // Activate the virtual IP address on the network interface
    Set_Virtual_IP_Active(TRUE);
ELSE
    Active_Control := FALSE;
END_IF;

This code exemplifies the logical simplicity behind a robust system. The timer evaluates whether the life signal has vanished for more than five hundred milliseconds. If affirmative, the active control flag is triggered and the virtual IP address is assumed, allowing the system to continue operating without human intervention.

Validation and Final Considerations on Reliability

Configuring redundancy and failover in Modbus TCP networks requires careful balancing between choosing appropriate industrial hardware, fault-tolerant network topologies, and flawless synchronization logic between controllers. Simply connecting cables is not enough; it is essential to simulate extreme failure scenarios, such as unplugging network cables during production or abruptly cutting power to the primary PLC, to test system resilience on the test bench before commercial deployment.

Ultimately, investing time in high availability engineering protects company assets, prevents operational accidents, and ensures business continuity. When properly planned, the transition between controllers occurs so subtly that operators in the control room barely notice that a hardware failure was just successfully averted.