Programming And Debugging Tool (Padt); About The Controllogix System; Gas And Fire Considerations - Allen-Bradley 1756-L7 Series Reference Manual

Using controllogix in sil 2 applications
Table of Contents

Advertisement

Chapter 1
SIL Policy
12

Programming and Debugging Tool (PADT)

For support in creation of programs, the PADT (Programming and Debugging
Tool) is required. The PADT for ControlLogix is RSLogix 5000, per
IEC 61131-3, and this Safety Reference Manual.
For more information about programming a system by using pre-developed
subroutines or Add-On Instructions, see these publications:
• ControlLogix SIL 2 System Configuration Using RSLogix 5000
Subroutines, publication
• ControlLogix SIL 2 System Configuration Using RSLogix 5000
Subroutines, publication

About the ControlLogix System

The ControlLogix system is a modular programmable automation system with
the ability to pre-configure outputs and other responses to fault conditions. As
such, a system can be designed to meet requirements for 'hold last state' in the
event of a fault so that the system can be used in up to, and including, SIL 2-level
Gas and Fire and other applications that require that output signals to actuators
remain ON. By understanding the behavior of the ControlLogix system for an
emergency shutdown application, you can incorporate appropriate system design
measures to meet other application requirements. These measures relate to the
control of outputs and actuators which must remain ON to be in a safe state.
Other requirements for SIL 2 (inputs from sensors, software used, and so on)
must also be met.

Gas and Fire Considerations

Listed below are the measures and modifications related to the use of the
ControlLogix system in Gas and Fire applications.
• The use of a manual override is necessary to make sure the operator can
maintain the desired control in the event of a controller failure. This is
similar in concept to the function of the external relay or redundant
outputs required to make sure a de-energized state is achieved for an ESD
system should a failure occur (for example, a shorted output driver) that
would prevent this from normally occurring. The system knows it has a
failure, but the failure state requires an independent means to maintain
control and either remove power or provide an alternate path to maintain
power to the end actuator.
• If the application cannot tolerate an output that can fail shorted
(energized), then an external means such as a relay or other output must be
wired in series to remove power when the fail shorted condition occurs.
See
Figure
1.
Rockwell Automation Publication 1756-RM001I-EN-P - May 2012
1756-AT010
1756-AT012

Advertisement

Table of Contents
loading

This manual is also suitable for:

1756-l6 series

Table of Contents