Description
Honeywell CC-PCF901 CF9 Control Firewall Module for Experion PKS Series C
Core Product Overview
CC-PCF901 is the CF9 Control Firewall (FTE network security module) of Honeywell Experion PKS Series C platform. It must be installed on the matching IOTA base CC-TCF901. It is not a controller CPU. It integrates FTE (Fault Tolerant Ethernet) switching + industrial firewall filtering, providing 8 downstream FTE ports for cabinet C300 controllers plus 1 uplink port to the supervisory FTE network. It filters non-control traffic, suppresses broadcast storms, isolates cabinet-level control network to protect deterministic C300 control execution, complies with IEC 62443 industrial cybersecurity requirements. Widely used in petrochemical, refinery, power plant Experion PKS control cabinets.
Main Technical Specifications
- Part Number: CC-PCF901, Honeywell spare PN: 51405047-175
- Manufacturer: Honeywell
- Device Type: CF9 FTE Control Firewall Module
- Compatible IOTA Base: CC-TCF901
- Port allocation: 8 × 10/100 Mbps FTE downstream ports; 1 × uplink port
- Function: FTE switching, L2 traffic filtering, broadcast/multicast storm suppression, access control
- Power: 24 VDC supplied by CC-TCF901 IOTA
- PCB Coating: Conformal coated (CC prefix) for harsh industrial environments
- Operating Temperature: 0 ~ +60°C
- Humidity: 10%–90% non-condensing
- Form Factor: Series C carrier rack plug-in module
- Status: EOL, original production discontinued; spare stock available as new surplus or professionally refurbished bench-tested units
Same-Series Model Recommendations (8 Models)
-

CC-PCF901
Professional Quality Control & Testing Standard Operating Procedures
All surplus and refurbished Honeywell CC-PCF901 modules follow this inspection workflow:
- Visual Inspection: Inspect PCB, gold edge fingers, front LED indicators, capacitors and soldering; verify Honeywell part label and revision.
- IOTA Base Power Bench Test: Install on CC-TCF901, apply 24VDC, confirm stable power rails, no overcurrent or cycling.
- Boot & Firmware Validation: Complete power-on self-test, read firmware revision, confirm no permanent hardware fault codes.
- FTE Port Function Test: Test all 8 downstream ports and uplink port, verify link negotiation and traffic forwarding.
- Firewall Filter Test: Verify non-control packet blocking and broadcast storm suppression.
- Network Redundancy Test: Validate FTE fault tolerance and switchover when one FTE path fails.
- Thermal Soak Test: Run module at upper ambient temperature to expose intermittent port or timing faults.
- Final Cleaning & Packaging: Clean edge contacts, reset configuration, ESD packaging with printed test certificate.
New / Refurbished Module Installation Guidelines
- Pre-Installation Safety: Execute lockout-tagout; isolate rack 24V supply and FTE network to avoid control network interruption.
- Rack & IOTA Check: Confirm CC-TCF901 IOTA base is correctly mounted on Series C carrier, protective earth and cabinet ventilation.
- Mechanical Insertion: Align CC- edge connector with CC-, insert smoothly and lock the module latch.
- Network Wiring: Connect C300 FTE cables to downstream ports; connect uplink to supervisory FTE network; use Honeywell specified shielded FTE cables.
- System Configuration: Configure firewall rules and FTE topology via Experion PKS engineering tools.
- Offline Functional Test: Power rack offline; verify port link LEDs, firewall filtering and FTE redundancy switchover.
- Commissioning & Acceptance: Monitor network load and controller communication, verify no unexpected broadcast flooding, archive network configuration.
Application Scenarios & Product Features
Typical Application Scenarios
- Experion PKS Series C control cabinet FTE network segmentation
- Petrochemical, refinery and power plant DCS control room cabinets
- Cybersecurity isolation between cabinet local C300 controllers and plant supervisory FTE network
- Retrofit and spare replacement of existing CF9 control firewall installations
Core Product Features
- Dedicated CF9 FTE control firewall for Experion PKS Series C
- 8 downstream FTE ports for controllers + 1 uplink port
- Layer 2 traffic filtering to protect deterministic control traffic
- Broadcast and multicast storm suppression to avoid controller scan disruption
- FTE fault-tolerant Ethernet support for redundant network paths
- Conformal coated PCB for corrosive or high-humidity cabinet environments
- Hot-swap capable; replacement requires network bypass and site work permit procedures
- Cannot be substituted by ordinary commercial IT switches
Frequently Asked Questions (FAQ)
A1: No. It is a network firewall/FTE switch module. The controller is CC-TDCU01.
A2: No, CC- is the mandatory IOTA termination base that provides power and physical FTE wiring terminals.
A3: No. Standard IT switches do not support Honeywell proprietary FTE protocol and control firewall filtering, which may break deterministic control.
Q4: Is it hot-swappable? A4: Hardware supports hot swap, but removal will interrupt FTE communication for all controllers connected to this CF9. Implement network bypass and work permit before replacement.
Q5: What are common failure modes? A5: Edge connector oxidation, RJ45 port ESD damage, ageing capacitors, firmware corruption induced by voltage transients, port link instability.


