The short answer
Modicon M580
The Modicon M580 is the flagship of the Schneider Electric Modicon range: a rack-based controller whose backplane carries Ethernet as well as the classic bus, so that I/O, communication modules, and the CPU share an Ethernet fabric, and whose remote I/O drops connect over an Ethernet daisy-chain ring that heals a single break. It uses the same X80 I/O modules as the M340, adds CPU variants for hot standby with a direct synchronization link between two CPUs, and was designed with cybersecurity in mind, with certified network stacks, access control lists, and secure firmware. It is the natural migration target for Quantum and Premium plants and the usual choice for a treatment plant that needs redundancy, a large I/O count, or several remote racks. It is programmed in Control Expert, and its configuration is as much a network design as a program.
Key points
- Ethernet on the backplane; remote I/O drops on a daisy-chain ring with single-break recovery.
- Hot standby CPU variants with a dedicated synchronization link; I/O on the remote drops, not in the CPU racks.
- Same X80 I/O modules as the M340, with Ethernet-capable adapters for the drops.
- Security features built in: certified stacks, access control lists, IPsec on some modules, secure firmware.
- Configuration in Control Expert covers the device networks, the drops, and the addressing, not just the logic.
Architecture
| Element | Notes |
|---|---|
| CPU | Standalone and hot standby variants at several performance levels; a service port and device network ports on the front; a safety variant for safety functions |
| Backplane | Ethernet and the classic bus; modules that support Ethernet use it, older X80 modules use the bus |
| Local rack | The CPU rack and extension racks; in hot standby systems the CPU racks hold no process I/O |
| Remote I/O drops | Racks with an Ethernet adapter, connected on the remote I/O ring; the ring uses a recovery protocol that heals one break |
| Distributed I/O | Modbus TCP or EtherNet/IP devices scanned by the CPU or a network module on the device network |
| Network modules | Additional Ethernet ports, network isolation, a firewall module, and modules that support encryption |
The networks it defines
An M580 system has at least two Ethernet networks and often three: the remote I/O network, which is the ring of drops and is kept private to the controller; the device network, which carries drives, meters, and distributed I/O; and the control network, through which SCADA and engineering reach the CPU. The remote I/O ring is not a general network and nothing else belongs on it; the device network is scanned by the CPU with a cycle time that depends on the device count; and the control network is where the switch design, the firewall, and the access control lists apply. The configuration in Control Expert declares the topology, and a switch that is not configured for the ring protocol or that puts SCADA traffic on the I/O ring produces I/O faults that look like hardware.
Hot standby
Two CPUs, each in its own rack, are linked by a dedicated synchronization cable, copper or fiber depending on the variant. One is primary and runs the process; the other is standby and receives the data every scan. On a primary failure the standby takes over within a scan or two, and the remote I/O drops, which are on the ring and connected to both, do not notice. The application must be identical in both, which the system enforces, and the I/O must be on remote drops, because I/O in the CPU rack is lost with that CPU. A switchover is a routine test at commissioning and on a schedule; a hot standby system that has never switched over has not been proven.
Security
- Network stacks certified for robustness against malformed traffic.
- Access control lists on the CPU and network modules restrict which addresses may connect and which services they may use.
- IPsec on modules that support it, for encrypted links to engineering and SCADA.
- Signed firmware, application password, section protection, and the ability to disable unused services and ports.
- Event logging to a syslog server on recent firmware.
- None of it replaces network segmentation; the control network still sits behind a firewall.
Migration from Quantum and Premium
Many M580 systems replaced a Quantum or Premium controller at the end of its life. The migration paths keep as much of the installed I/O as possible: Quantum remote I/O drops can be attached to the M580 remote I/O network with the appropriate adapters, so the field wiring stays while the CPU changes; Premium systems typically move to X80 I/O with wiring conversion. Application conversion in Control Expert brings the logic across, with the hardware configuration and the I/O addressing rebuilt for the new platform, and every converted routine tested. A phased migration that runs the old and new controllers in parallel on different process areas is the usual approach at a plant that cannot stop.
On a site visit
- 1
CPU display and indicators
The state of each CPU in a hot standby pair, the primary and standby roles, and any error.
- 2
Remote I/O ring
The ring status in the diagnostics: a healthy ring has no broken segment; a ring running on one break is one break from losing drops.
- 3
Drop status
Each drop connected and its modules healthy; the diagnostic screens show which drop and which slot.
- 4
Device network
The scanner status per device; a device with timeouts is failing.
- 5
Access control
Whether access control lists are enabled and whether the engineering laptop address is on them; a refused connection is not a network fault.
- 6
Firmware
CPU and module versions against the compatibility list for the Control Expert version in use; record them in the asset inventory.
Frequently asked questions
- Can I put SCADA on the remote I/O network?
- No. The remote I/O ring is a deterministic private network for the drops. SCADA and engineering connect through the control network on the CPU service port or a network module, with the traffic kept off the ring.
- What happens to a drop when the ring breaks?
- Nothing, for a single break: the ring protocol reroutes within the recovery time. A second break isolates the drops between the breaks, and the CPU reports them lost. The first break must be alarmed and fixed; a ring that runs broken for months is a line.
- Do I need a hot standby system?
- When a controller failure would stop treatment or cause an overflow and the process cannot ride through the time to replace a CPU from spares. Many plants use a single M580 with a spare CPU on the shelf and the application on a card; a hot standby pair is for the processes that cannot wait even that long.
- Why does the engineering laptop get refused after a firmware update?
- The update enabled or reset the access control list, or a service the software uses was disabled. Read the security settings in the configuration and add the engineering addresses deliberately rather than turning the list off.
Related topics
- Modicon M340Field notes on the Schneider Electric Modicon M340, a rack-based mid-range controller common in water plants: rack and CPU layout, X80 I/O, memory card behavior, Ethernet and serial communications, programming in Control Expert, and what to check on site.
- Control ExpertField notes on Control Expert, the Schneider Electric engineering software for the Modicon M340 and M580: project structure, the five languages and derived function blocks, versions and files, online changes, upload information, and security settings.
- SCADA RedundancyWhat redundant SCADA servers protect against and what they do not, how failover works for tags, alarms, history, and clients, the network and controller layers beneath it, and why an untested failover is not redundancy.
- Remote I/OExtending controller I/O to another panel or another site over a network: the adapter and the rack, the update rate and what it costs, what the outputs do when the link fails, the difference between remote I/O and a remote controller, and the wiring, addressing, and diagnostics that make it dependable.
- Controller HardeningWhat can be locked down on a PLC or RTU: keyswitch and mode, credentials, unused services, access lists, firmware, and the engineering workstation that is the real target.
- Zones and ConduitsThe IEC 62443 way to segment a control system: grouping assets into zones with a shared security level, inventorying every conduit between them, and turning the drawing into firewall rules. With a worked water utility example.
Direct contact
Have a controls question?
Reach Eric Sullivan directly about anything on this site, a controls or automation topic, or one of his personal projects.