OMRON#Lets’s Establishing CIP Safety Connection Between the NX102-9000, NX-SL5500 and NXR-SXD1204-CST!

In this article, we will use OMRON NX102-9000 + NX-SL5500 as the Safety Controller, and connect NXR-SXD1204-CST as a CIP Safety Target on the EtherNet/IP network.

An emergency stop switch and Safety Output equipment are connected to the NXR-SXD1204-CST side, and the state of Safety Input is sent to the NX-SL5500 via CIP Safety.

Now, let’s enjoy FA!

NXR-SXD1204?

The NXR-SXD1204-CST is an OMRON environment-resistant remote Safety I/O compatible with CIP Safety. Since it is IP67 compliant, it can be installed outside control panels or near machinery, and can be connected to a Safety PLC via EtherNet/IP.

Main Features

  • 12 Safety Inputs
  • Has 4 Safety Outputs
  • In addition to Remote I/O, simple Safety Logic can be hosted inside the main unit
  • Equipped with 12 Safety Inputs / 4 Safety Outputs
  • Emergency stops, Safety Door Switches, Light Curtains, etc., can be directly connected.
  • IP67 rating allows installation near machinery rather than inside a control panel
  • Simple Safety Logic can be executed within the main unit, allowing local safety judgments.
  • On the Safety PLC side, not only simple I/O but also Status and diagnostic information for each Input/Output can be acquired
  • There are multiple Safety Input Assemblies, selectable from 2 bytes / 5 bytes / 9 bytes depending on the required amount of diagnostic data
  • Supports Type 1 / Type 2a / Type 2b SafetyOpen, allowing selection of the Configuration method.
  • M12 connector-centered configuration makes field wiring easy
  • Has a Web UI, making it easy to check I/O status, diagnostics, and settings
  • Supports DLR, enabling EtherNet/IP ring topology configurations

Product Lineup

In addition, Omron has released two products simultaneously this time.

  • NXR-SXD1204-CST
  • NXR-SXD1204B-CST

Item

NXR-SXD1204-CST

NXR-SXD1204B-CST

Safety Input

12 points

12 points

Safety Output

4 points

4 points

Safety Input Port

P1~P6

P1~P4

Safety Output Dedicated Port

P7~P8

None

Safety I/O Port

None

P5~P6

P5/P6 Contents

Safety Input

Safety Input + Test Output + Safety Output

Safety Output Location

P7/P8

Inside P5/P6

Safety Output Max Load Current

2.0 A/point

0.7 A/point

I/O Connector

M12 A-coded 5pin

P1~P4: 5pin / P5~P6: 8pin

System Configuration Example

This is an example configuration where NXR-S units are distributed across process steps and areas of an automotive manufacturing line, directly connecting safety devices like emergency stop switches and light curtains to each NXR-S.

Conventionally, in a configuration with long wiring runs from Safety Sensors or E-STOPs to Safety I/O inside the panel, Safety wiring increases as the facility grows larger. In this configuration, since the NXR-S can be placed near Safety Devices, the setup can be: Safety Scanner → CIP Safety → NXR → short hard wiring → Safety Device.

Features

Power Supply and Safety Signal in 1 Cable

NXR-S assumes a configuration where power supply and safety signals for Safety Devices such as light curtains can be connected using a single cable.

Smart Click

It uses Smartclick connectors, eliminating the need for a torque wrench during tightening, aiming to simplify wiring work.

Built-in Logic

Furthermore, the NXR-S unit itself features pre-configured Safety Applications, as well as Add-on Applications, User-defined Applications, and Logic functions. Therefore, instead of just using it as a simple Remote Safety I/O, the NXR-S itself can execute Safety Logic.

In the operation example in the diagram, an emergency stop switch and a Safety Light Curtain are connected to the NXR-S. Pressing the emergency stop switch stops both Segment A and Segment B. On the other hand, if the Safety Light Curtain is blocked, Segment A continues operation while only Segment B is stopped.

Web UI Support

The NXR requires no dedicated software; troubleshooting and unit replacement can be conducted via the built-in Web UI.

Type1 / Type2a / Type2b SafetyOpen Methods

As a CIP Safety Target, NXR-S is designed to allow selective use of Type1 / Type2a / Type2b SafetyOpen methods depending on the phase, such as startup, operation, or modification.

In Type1 in particular, not only I/O Block Parameters but also User-defined Logic can be automatically configured. This allows combining distributed control executing Safety Logic on the NXR-S side with Configuration management from the Originator side.

Additionally, since a single NXR-S can communicate with multiple CIP Safety Originators, it reduces the need to duplicate Safety Devices or NXR-S units for each Originator, simplifying the system configuration.

Compliance with International Safety Standards

The NXR-S is designed with an emphasis on compliance with international Safety Standards, assuming long-term use in global markets.

The documentation explicitly states compliance with IEC 61508 and ISO 13849-1:2023 (4th Edition). Furthermore, compliance with UL FSPC for North America and the Machinery Directive for Europe is indicated.

As a result, NXR-S is positioned as a Safety I/O intended for deployment in global equipment including North America and Europe, as well as domestically in Japan.

What is CIP Safety Communication?

CIP Safety is a Safety Protocol for transmitting functional safety data using EtherNet/IP. In CIP Safety, the device that initiates a Connection is defined as the Originator, and the device receiving the connection is defined as the Target. NXR-S operates as a CIP Safety Target and periodically exchanges Safety I/O Data with a higher-level Safety Controller. This transmits input states from field emergency stops, Safety Sensors, etc., to higher levels via the network, while Safety Data from the Safety Controller can be received on the NXR-S side for safety control.

Open Type

Open Type is a setting that determines the Configuration verification method when establishing a CIP Safety Connection.

Specified when establishing a Connection from Originator to Target, Configuration transfer and Safety Signature verification methods differ depending on Type 1 / Type 2a / Type 2b.

Type

Configuration Data in SafetyOpen

SCID

Target Side Behavior

Type1

Yes

Receives data necessary for Safety Device Configuration via SafetyOpen

Type2a

No

Other than 0

Compares with SCID of Configuration on Target side, accepting connection only when matched

Type2b

No

0

Connects by skipping SCID check

Connection Type

In CIP Safety, two communication methods can be selected: Multicast and Point-to-Point.

Multicast is a method of distributing one Input Assembly in a single packet to multiple Originators. It is characterized by easily suppressing communication load when wanting to receive the same Safety Data across multiple Controllers.

On the other hand, Point-to-Point is a method of sending data individually to each Originator. Therefore, when sending the same Input Assembly to multiple Originators, traffic increases accordingly.

Note that when distributing the same Input Assembly to multiple Originators via Multicast, Connection Type, Connection I/O Type, EPI, and Timeout values must match across all Connections.

Also, because unnecessary spread of Multicast Packets throughout the entire network causes communication overhead, a configuration using a Switching Hub with Multicast Filter functionality to distribute only to necessary nodes is recommended.

EPI (Expected Packet Interval)

EPI (Expected Packet Interval) is a setting value that determines the cycle at which Safety I/O Data is updated in CIP Safety communication.

EPI(Expected Packet Interval)は、CIP Safety通信でSafety I/O Dataをどの周期で更新するかを決める設定値です。

In EtherNet/IP, this EPI is set per Connection, and data exchange is performed according to that cycle.

Shortening the EPI speeds up Data updates, but Network Traffic and Device load increase accordingly. Conversely, lengthening the EPI lowers the communication load, but the Safety Data update interval becomes longer.

Therefore, EPI is not simply a matter of “shorter is better”; appropriate values must be selected considering the performance of the Safety Controller or Target Device used, number of Connections, required Response Time, etc. Since each device has a configurable EPI range, appropriate values should be chosen according to specifications.

I/O Assembly

An I/O Assembly is a collection of Safety I/O Data exchanged periodically between CIP Safety Originator and Target.
Multiple I/O Assemblies are provided in NXR-S, allowing selection of the Assembly to use according to the required amount of information. One I/O Assembly is assigned to a single CIP Safety Connection.

For example, the following Assemblies are provided on the Input side:

  • 0x25C:2 Byte
  • 0x3C0:5 Byte
  • 0x3C1:9 Byte

The amount of information included varies by Assembly, ranging from those handling basic Safety Inputs to those including detailed diagnostic information such as each Channel’s Status or Safety Output states.

Therefore, selective use is possible: choosing a smaller Assembly for simple Safety I/O monitoring, or an Assembly with richer information when prioritizing maintenance or fault diagnostics.

Safety IO Operation

Safety Input Function

Contact-type Safety Devices such as emergency stop switches or safety limit switches are connected combining Safety Input (Si) and Test Output (T).

In a dual-channel configuration, two channels of contacts are connected to independent Safety Inputs, and monitoring signals are supplied from the corresponding Test Outputs. In the diagram example, T00-Si00 and T01-Si01 are each used as one channel.

By using this Test Output, it becomes easier to detect wiring short circuits and certain abnormalities, rather than merely checking contact ON/OFF states.

Note that Safety Input and Test Output are paired with matching numbers. For example, T00 corresponds to Si00, and T01 to Si01. In this configuration, set the Test Output Mode of T00 and T01 to “Test Output”.

Test Output Terminal

The Test Output terminals of the NXR-S are used as auxiliary outputs to assist Safety Inputs.
Depending on the application, they can be configured for Output with Test Pulse, 24V Power Supply, or Standard Output.

For mechanical contact Safety Devices, selecting Test Output mode outputs 24V DC containing Test Pulses at fixed intervals, monitoring the signal on the input side. This enables detection of wiring abnormalities beyond simple ON/OFF checks.

On the other hand, for contact equipment or semiconductor output devices that do not require Test Pulses, continuous 24V DC can be supplied in Power Supply mode. It can also be used as a power supply for semiconductor output equipment.

In addition, Standard Output mode allows using Test Output terminals as standard digital outputs. This can be used for signal outputs to indicator lights or PLC inputs, but this is a non-safety output, not a Safety function.

Test Output Mode

Main Applications

Output Content

Test Output

Monitoring mechanical contact Safety Devices

24V DC with Test Pulse

Power Supply

Power supply to contact/semiconductor devices

Continuous 24V DC

Standard Output

Indicator lights, PLC inputs, etc.

Standard non-safety digital output

Test Pulse Evaluation Function

The test pulse evaluation function monitors Pulse signals output from Test Output on the Safety Input side to detect external device or wiring abnormalities.

When using mechanical contact Safety Devices, 24V DC containing Test Pulses is output from the Test Output terminal at fixed intervals, verifying if that signal returns to the Safety Input via the contact.

This detects wiring errors such as short circuits between input signal lines and power lines, or short circuits with other input signal lines, beyond simple input ON/OFF status.

When using dual channels, combine Test Output and Safety Input with matching numbers, such as T00-Si00, T01-Si01.

Dual Channel Evaluation Function

Dual Channel Evaluation monitors two Safety Inputs as a pair, checking if both states interlock correctly.

It monitors time elapsed from when one Input changes until the other changes, judging it as an abnormality if the difference exceeds the configured Discrepancy Time.

Channel Modes include Dual Channel Equivalent Input, expecting both Inputs to be in the same state, and Dual Channel Complementary Input, expecting opposite states.

Discrepancy Time can be set in the range 10–64000 ms, adjustable in 5 ms increments. Factory default is 500 ms.

Mode

Input States Judged Normal

Dual Channel Equivalent

0/0 or 1/1

Dual Channel Complementary

0/1 or 1/0

Input Filter Function

The Input Filter function suppresses false detections caused by chattering or noise from external devices connected to Safety Inputs.

When input changes ON→OFF or OFF→ON, a set delay time is applied, ignoring temporary signal changes shorter than that duration to stabilize the input.

On NXR-S, ON→OFF Delay and OFF→ON Delay can be set individually from 0–1600 ms in 5 ms increments. Factory default is 0 ms.

NXR-Sでは、ON→OFF Delay と OFF→ON Delay を個別に設定でき、どちらも 0~1600 ms、5 ms単位で調整できます。工場出荷時は0 msです。

Increasing delay time raises resistance to noise and chattering, but delays Safety Input response accordingly. Thus, settings must balance noise countermeasures against required Safety Response Time.

Input Error Latch Time

Input error latch time retains an error status for a fixed duration after an abnormality is detected on a Safety Input.

Even if transient error conditions clear immediately, it continues the error state for the set duration so the Originator side reliably recognizes the abnormality.

Setting range is 0–65530 ms in 10 ms increments. Setting 0 ms disables latching. Factory default is 1000 ms.

When determining setting values, Network Response Time between NXR-S and CIP Safety Originator must be considered to set a duration that detects errors without missing them.

Errors clear after removing cause of abnormality and setting the corresponding Safety Input to Inactive (OFF) state.

Safety Output Function

Safety Output on NXR-S can also be used to diagnose connected external Safety Devices.

Outputs are PNP type, capable of connecting Safety Relays, Contactors, Solenoid Valves, etc.

Configure Single Channel / Dual Channel and presence of Test Pulse according to connected equipment and Channel configuration.

When Test Pulse is enabled, superimposing diagnostic Pulses on output signals detects abnormalities in output circuits or external wiring. On the other hand, if connected equipment does not support Test Pulses, use without Test Pulse.

EDM Feedback

EDM stands for External Device Monitoring.

External devices here refer to Safety Relays or Contactors, for example. Even if NXR-S turns Safety Output OFF, if actual Contactor contacts are welded, the machine side will not stop. Therefore, auxiliary contacts are fed back to Safety Input to monitor whether external devices actually turned OFF.

Output Delay

Output delay intentionally delays Safety Output ON/OFF switching.

In User-defined Applications, Delays can be set for Safety Output transition from ON to OFF or OFF to ON matching operating characteristics of external equipment.

ON→OFF Delay is used when wanting to avoid mechanical damage from sudden stops, considering mechanical stopping characteristics of Motors or Brakes.

ON→OFF Delay は、MotorやBrakeなどの機械的な停止特性を考慮し、急停止による機械損傷を避けたい場合に使用します。

OFF→ON Delay is used when wanting to turn Safety Output ON after external equipment recovers and operation stabilizes.

Setting range is 0–1500 ms in 100 ms increments. Factory default is 0 ms.

Configuration Lock

Configuration Lock protects Safety-related configurations set on the NXR-S from unintended changes.

Enabling Lock restricts modifications to Safety Parameters, Safety Applications, and other settings affecting Safety operation.

This prevents changes to Safety Configuration due to operational error or unintended setting changes during mass production or after commissioning completion.

Configuration Lock can be set individually per unit or applied collectively to multiple NXR-S registered in Sysmac Studio. Setting and unlocking can be performed from Sysmac Studio or Web UI.

Enabling configuration lock prevents changing primary Safety and communication settings on the NXR-S.

Lock status can be checked via LOCK LED on the unit: lit indicates Locked state, while flashing or unlit indicates Unlocked state.

Lock targets include CIP Safety communication settings including TUNID, Safety Application settings, and communication settings such as EtherNet/IP or TCP/IP. Operations like I/O Wiring Check, Restore from Backup, and Memory All Clear are also prohibited during Lock.

Furthermore, if rotary switch settings are changed and power turned ON after Configuration Lock, the unit detects setting change and stops operation. In short, after Lock, a mechanism protects configuration across both Software settings and Hardware Mode selection.

さらに、Configuration Lock後にロータリースイッチの設定を変更して電源を入れると、設定変更を検出してユニットが動作停止する仕様になっています。つまり、Lock後はSoftware設定だけでなく、Hardware側のMode選択も含めて構成を保護する仕組みになっています。

Lock Target

Main Contents

CIP Safety Communication Settings

Safety communication settings including TUNID

Safety Application Settings

Applications for Add-on / User-defined / Remote I/O mode

Non-Safety Communication Settings

EtherNet/IP, TCP/IP, LINK, Ethernet Port, LLDP, etc.

Prohibited Functions

I/O Wiring Check, Restore, Memory All Clear

Safety Assembly

Next, Safety Assembly will be introduced.

Safety Input Assembly

Safety Input Assembly can include diagnostic information such as status of each Input, Test Output and Safety Output states, power supply abnormalities, Connection states, in addition to simple Safety Input ON/OFF states.

Therefore, the upper-level Safety Controller can check not only “whether input is ON or OFF”, but also whether that signal is normal, whether Output has abnormalities, and whether Connection is established.

Element

Meaning

Safety Input N

Logical value of Si input. 0=OFF/Abnormal, 1=ON

Safety Input N Status

Normal/Abnormal status of each Si input

Safety Input Status

Aggregated Status of all Safety Inputs

Test Output N Monitor

Actual ON/OFF state of Test Output terminal

Test Output N Status

Normal/Abnormal status of Test Output terminal

Safety Output N Monitor

Actual ON/OFF state output on So terminal

Safety Output N Status

Normal/Abnormal status of each Safety Output

Safety Output Status

Aggregated Status of all Safety Outputs

Output Power Supply Error Flag

Presence of Output power supply abnormality

Application Number

Current Safety Application number

Cnxn Status

CIP Safety Connection establishment status

Safety Output Assembly

Safety Output Assembly is a collection of output data sent from CIP Safety Originator to NXR-S. In addition to data controlling physical Safety Output terminals, it includes data using Test Output as Standard Output and Remote Output passed to internal NXR-S Logic.

Element

Meaning

Safety Output N

ON/OFF of physical Safety Output SoN

Standard Output N

ON/OFF of Test Output terminal TN as non-safety standard output

Remote N Output M

ON/OFF of Safety signal RoN-M passed to internal NXR-S Logic

Implementation

Now we will build the program.

Rotary Switch Settings

NXR-S features rotary switches used for setting operating modes and IP addresses.

On the SETTING side, select Safety Application and various functions to use. SW1 and SW2 are set to matching values; setting values switch between Remote I/O Mode, Fixed Application, Add-on Application, User-defined Application, etc.

On the ADDRESS side, 2 rotary switches represent 2 hexadecimal digits, used for IP Address setting.

Note that changing rotary switch settings requires power OFF/ON or Restart.

SETTING Value

Operation Details

0

Remote I/O Mode

1~3

Fixed Application

4~7

Reserved

8

IP Address Display Function

9~D

Add-on Application

E

I/O Wiring Check Function

F

User-defined Application

WEB Server Access

Default IP address of NXR is 192.168.250.1. Access https://192.168.250.1 from Firefox or another browser.

The Login screen of the NXR device is displayed.

Since we will not change the password this time, select “Continue using the initial safety password” → proceed with Set.

Done!

This is the NXR Web Server.

Program Construction

Add Safety PLC SL5000

Add the SL5500 Safety PLC to hardware configuration. Go to Configurations and Setup → CPU Rack → add NX-SL5500.

Done! SL5500 has been added.

Download EDS File

Next, please download NXR EDS FILE from Omron’s website.

https://www.fa.omron.co.jp/products/family/3964/download/softwares/

Install EDS File

Select Safety CPU from Multiview.

Go to Configurations and Setup > Communications > Safety > Safety I/O > EtherNet/IP Safety Connection Settings, double-click Connection Settings(Originator).

Right-click in blank space > select EDS Library CIP Safety.

CIP Safety Library is displayed.

Import EDS File via Install button.

Please select the EDS File downloaded earlier.

EDS File installed.

Close CIP Safety Library with “X” button.

Add NXR

Add NXR to CIP Safety network. Click Communications → Safety → Ethernet/IP Safety Connection Settings → Connection Settings(Originator).

Add NXR-SXD1204-CST.

Done! NXR-SXD1204-CST added to CIP Safety network.

IP Address

Double-click NXR-SXD1204-CST added previously.

Set IP address in IP Address field under General Tab.

IO Configuration

Next, open IO Configuration Tab.

This is the IO configuration screen for NXR-SXD1204-CST.

Safety Input Settings

In this article Si00 and Si01 connect to emergency stop, so drop Input Device:Safety Switch → Emergency Stop Switch for Dual Channel onto Si0.

Done!

Safety Output Settings

Next, open Output menu and drop So00 onto Dual Output without Test Pulse.

TUNID Setting

Next, with tool online, right-click NXR-SXD1204-CST added earlier → Set TUNID.

Done! TUNID is now set.

Variable Declaration

Next, click I/O Map to declare variables for NXR-SXD1204-CST added earlier.

IO variables can be declared from this screen.

Select Safety Input altogether → right-click → Create Device Variable with Prefix.

Define variable name.

Done! Declare output variables using the same operation.

Program

Finally, create safety program.

This time, use SF_EmergencySTOP as below so when Si00 and Si01 turn ON, So00 and So01 set to True.

Download Program

Not only Safety application, but the entire project must be Downloaded to CPU. Select Controller from Multiview Explorer.

Download project to CPU via to Controller.

Click Execute.

Click Yes.

Click Yes.

Completed!

Configuration Lock

Finally, lock configuration of NXR-SXD1204-CST. Lock operation is performed via Web Server. Access WEB Server, Executive Command → Configuration Lock.

Click Confirm button to toggle NXR-SXD1204-CST Lock → Unlock or Unlock → Lock.

From Sysmac Studio right-click locked/unlocked device → Target Device → Unlock or Lock.

Results

Now let’s check connection status. Select Safety CPU from Multiview Explorer.

Launch CIP Safety Monitor.

Confirmed CIP Safety communication is currently normal from CIP Safety Monitor screen.

Safety Forward requests can also be issued from Wireshark.

Can also be confirmed in CIP Safety IO messages.

Operation can be confirmed in this video.

シェアする

  • このエントリーをはてなブックマークに追加

フォローする