Modbus Protocol Overview and Modes
Modbus Protocol Overview and Modes
ModbusProtocol
modbustools
Fortest,simulationandprogramming.
HOME
PRODUCTS
ORDER
DOWNLOAD
MODBUS
CONTACT
ProtocolDescription
MODBUSProtocolisamessagingstructure,widelyusedtoestablishmasterslave
[Link]
containstheaddressoftheslave,the'command'(e.g.'readregister'or'writeregister'),the
data,andachecksum(LRCorCRC).
SinceModbusprotocolisjustamessagingstructure,itisindependentoftheunderlying
physicallayer.ItistraditionallyimplementedusingRS232,RS422,orRS485
TheRequest
Thefunctioncodeintherequesttellstheaddressedslavedevicewhatkindofactionto
[Link]
[Link],functioncode03willrequesttheslavetoreadholding
[Link]
[Link]
providesamethodfortheslavetovalidatetheintegrityofthemessagecontents.
TheResponse
Iftheslavemakesanormalresponse,thefunctioncodeintheresponseisanechoofthe
[Link],suchas
[Link],thefunctioncodeismodifiedtoindicatethatthe
responseisanerrorresponse,[Link]
errorcheckfieldallowsthemastertoconfirmthatthemessagecontentsarevalid.
ControllerscanbesetuptocommunicateonstandardModbusnetworksusingeitheroftwo
transmissionmodes:ASCIIorRTU.
ASCIIMode
WhencontrollersaresetuptocommunicateonaModbusnetworkusingASCII(American
StandardCodeforInformationInterchange)mode,eacheightbitbyteinamessageissentas
[Link]
onesecondtooccurbetweencharacterswithoutcausinganerror.
CodingSystem
HexadecimalASCIIprintablecharacters0...9,A...F
BitsperByte
1startbit
7databits,leastsignificantbitsentfirst
1bitforeven/oddparitynobitfornoparity
1stopbitifparityisused2bitsifnoparity
ErrorChecking
LongitudinalRedundancyCheck(LRC)
RTUMode
WhencontrollersaresetuptocommunicateonaModbusnetworkusingRTU(RemoteTerminal
Unit)mode,eacheightbitbyteinamessagecontainstwofourbithexadecimalcharacters.
Themainadvantageofthismodeisthatitsgreatercharacterdensityallowsbetterdata
[Link]
continuousstream.
CodingSystem
Eightbitbinary,hexadecimal0...9,A...F
Twohexadecimalcharacterscontainedineacheightbitfieldofthemessage
BitsperByte
1startbit
8databits,leastsignificantbitsentfirst
1bitforeven/oddparitynobitfornoparity
1stopbitifparityisused2bitsifnoparity
ErrorCheckField
CyclicalRedundancyCheck(CRC)
InASCIImode,messagesstartwithacolon(:)character(ASCII3Ahex),andendwitha
carriagereturnlinefeed(CRLF)pair(ASCII0Dand0Ahex).
Theallowablecharacterstransmittedforallotherfieldsarehexadecimal0...9,A...F.
[Link]
received,eachdevicedecodesthenextfield(theaddressfield)tofindoutifitistheaddressed
device.
[Link]
intervaloccurs,[Link]
[Link]
1/9
12/6/2016
ModbusProtocol
shownbelow.
Start
Address
Function
Data
LRC
End
2Chars
2Chars
NChars
2Chars
CRLF
RTUFraming
InRTUmode,[Link]
easilyimplementedasamultipleofcharactertimesatthebaudratethatisbeingusedonthe
network(shownasT1T2T3T4inthefigurebelow).Thefirstfieldthentransmittedisthe
deviceaddress.
Theallowablecharacterstransmittedforallfieldsarehexadecimal0...9,A...[Link]
devicesmonitorthenetworkbuscontinuously,[Link]
firstfield(theaddressfield)isreceived,eachdevicedecodesittofindoutifitistheaddressed
device.
Followingthelasttransmittedcharacter,asimilarintervalofatleast3.5charactertimes
[Link].
[Link]
morethan1.5charactertimesoccursbeforecompletionoftheframe,thereceivingdevice
flushestheincompletemessageandassumesthatthenextbytewillbetheaddressfieldofa
newmessage.
Similarly,ifanewmessagebeginsearlierthan3.5charactertimesfollowingaprevious
message,[Link]
setanerror,asthevalueinthefinalCRCfieldwillnotbevalidforthecombinedmessages.A
typicalmessageframeisshownbelow.
Start
Address
3.5Chartime 8Bit
Function
Data
CRC
End
8Bit
N*8Bit
16Bit
3.5Chartime
AddressField
Theaddressfieldofamessageframecontainstwocharacters(ASCII)oreightbits(RTU).The
individualslavedevicesareassignedaddressesintherangeof1...247.
FunctionField
TheFunctionCodefieldtellstheaddressedslavewhatfunctiontoperform.
ThefollowingfunctionsaresupportedbyModbuspoll
01READCOILSTATUS
02READINPUTSTATUS
03READHOLDINGREGISTERS
04READINPUTREGISTERS
05WRITESINGLECOIL
06WRITESINGLEREGISTER
15WRITEMULTIPLECOILS
16WRITEMULTIPLEREGISTERS
Thedatafieldcontainstherequestedorsenddata.
ContentsoftheErrorCheckingField
[Link]
checkingfieldcontentsdependuponthemethodthatisbeingused.
ASCII
WhenASCIImodeisusedforcharacterframing,theerrorcheckingfieldcontainstwoASCII
[Link]
(LRC)calculationthatisperformedonthemessagecontents,exclusiveofthebeginningcolon
andterminatingCRLFcharacters.
TheLRCcharactersareappendedtothemessageasthelastfieldprecedingtheCRLF
characters.
LRCExampleCode
RTU
WhenRTUmodeisusedforcharacterframing,theerrorcheckingfieldcontainsa16bitvalue
[Link]
RedundancyCheckcalculationperformedonthemessagecontents.
[Link],
theloworderbyteofthefieldisappendedfirst,[Link]
highorderbyteisthelastbytetobesentinthemessage.
CRCExampleCode
Function01(01hex)ReadCoils
ReadstheON/OFFstatusofdiscretecoilsintheslave.
Request
Therequestmessagespecifiesthestartingcoilandquantityofcoilstoberead.
[Link]
2/9
12/6/2016
ModbusProtocol
Exampleofarequesttoread10...22(Coil11to23)fromslavedeviceaddress4:
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
QuantityofCoilsHi
QuantityofCoilsLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
04
01
00
0A
00
0D
DD
98
None
8
ASCIICharacters
:(Colon)
04
01
00
0A
00
0D
LRC(E4)
CRLF
17
Response
[Link]
indicatedas:1isthevalueON,[Link]
[Link]
[Link]
multipleofeight,theremainingbitsinthefinaldatabytewillbepaddedwithzeroes(toward
thehighorderendofthebyte).Thebytecountfieldspecifiesthequantityofcompletebytes
ofdata.
Exampleofaresponsetotherequest:
FieldName
Header
SlaveAddress
Function
ByteCount
Data(Coils7...10)
Data(Coils27...20)
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
04
01
02
0A
11
B3
50
None
7
ASCIICharacters
:(Colon)
04
01
02
0A
11
LRC(DE)
None
CRLF
15
Function02(02hex)ReadDiscreteInputs
ReadstheON/OFFstatusofdiscreteinputsintheslave.
Request
Therequestmessagespecifiesthestartinginputandquantityofinputstoberead.
Exampleofarequesttoread10...22(input10011to10023)fromslavedeviceaddress4:
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
QuantityofinputsHi
QuantityofinputsLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
04
02
00
0A
00
0D
99
98
None
8
ASCIICharacters
:(Colon)
04
02
00
0A
00
0D
LRC(E3)
CRLF
17
Response
[Link]
indicatedas:1isthevalueON,[Link]
[Link]
[Link]
notamultipleofeight,theremainingbitsinthefinaldatabytewillbepaddedwithzeroes
(towardthehighorderendofthebyte).Thebytecountfieldspecifiesthequantityof
completebytesofdata.
Exampleofaresponsetotherequest:
[Link]
3/9
12/6/2016
FieldName
Header
SlaveAddress
Function
ByteCount
Data(Inputs17...10)
Data(Inputs27...20)
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
ModbusProtocol
RTU(hex)
None
04
02
02
0A
11
B3
14
None
7
ASCIICharacters
:(Colon)
04
02
02
0A
11
LRC(DD)
None
CRLF
15
Function03(03hex)ReadHoldingRegisters
Readthebinarycontentsofholdingregistersintheslave.
Request
Therequestmessagespecifiesthestartingregisterandquantityofregisterstoberead.
Exampleofarequesttoread0...1(register40001to40002)fromslavedevice1:
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
QuantityofRegistersHi
QuantityofRegistersLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
01
03
00
00
00
02
C4
0B
None
8
ASCIICharacters
:(Colon)
01
03
00
00
00
02
LRC(FA)
CRLF
17
Response
Theregisterdataintheresponsemessagearepackedastwobytesperregister,withthe
[Link]
highorderbits,andthesecondcontainstheloworderbits.
Exampleofaresponsetotherequest:
FieldName
Header
SlaveAddress
Function
ByteCount
DataHi
DataLo
DataHi
DataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
01
03
04
00
06
00
05
DA
31
None
8
ASCIICharacters
:(Colon)
01
03
04
00
06
00
05
LRC(ED)
None
CRLF
19
Function04(04hex)ReadInputRegisters
Readthebinarycontentsofinputregistersintheslave.
Request
Therequestmessagespecifiesthestartingregisterandquantityofregisterstoberead.
Exampleofarequesttoread0...1(register30001to30002)fromslavedevice1:
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
[Link]
RTU(hex)
None
01
04
00
00
ASCIICharacters
:(Colon)
01
0
00
00
4/9
12/6/2016
QuantityofRegistersHi
QuantityofRegistersLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
ModbusProtocol
00
02
71
CB
None
8
00
02
LRC(F9)
CRLF
17
Response
Theregisterdataintheresponsemessagearepackedastwobytesperregister,withthe
[Link]
highorderbits,andthesecondcontainstheloworderbits.
Exampleofaresponsetotherequest:
FieldName
Header
SlaveAddress
Function
ByteCount
DataHi
DataLo
DataHi
DataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
01
04
04
00
06
00
05
DB
86
None
9
ASCIICharacters
:(Colon)
01
04
04
00
06
00
05
LRC(EC)
None
CRLF
19
Function05(05hex)WriteSingleCoil
WritesasinglecoiltoeitherONorOFF.
Request
[Link]
zerocoil1isaddressedas0.
TherequestedON/[Link]
[Link]
illegalandwillnotaffectthecoil.
Hereisanexampleofarequesttowritecoil173ONinslavedevice17:
FieldName
Header
SlaveAddress
Function
CoilAddressHi
CoilAddressLo
WriteDataHi
WriteDataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
11
05
00
AC
FF
00
4E
8B
None
8
ASCIICharacters
:(Colon)
11
05
00
AC
00
FF
LRC(3F)
CRLF
17
Response
Thenormalresponseisanechooftherequest,returnedafterthecoilstatehasbeenwritten.
Exampleofaresponsetotherequest:
FieldName
Header
SlaveAddress
Function
CoilAddressHi
CoilAddressLo
WriteDataHi
WriteDataLo
ErrorCheckLo
ErrorCheckHi
Trailer
[Link]
RTU(hex)
None
11
05
00
AC
FF
00
4E
8B
None
ASCIICharacters
:(Colon)
11
05
00
AC
00
FF
LRC(3F)
CRLF
5/9
12/6/2016
TotalBytes
ModbusProtocol
8
17
Function06(06hex)WriteSingleRegister
Writesavalueintoasingleholdingregister.
Request
[Link]
startingatzeroregister1isaddressedas0.
[Link]
requesttoWriteregister40002to0003hexinslavedevice17.
FieldName
Header
SlaveAddress
Function
RegisterAddressHi
RegisterAddressLo
WriteDataHi
WriteDataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
11
06
00
01
00
03
9A
9B
None
8
ASCIICharacters
:(Colon)
11
06
00
01
00
03
LRC(E5)
CRLF
17
Response
Thenormalresponseisanechooftherequest,returnedaftertheregistercontentshavebeen
written.
FieldName
Header
SlaveAddress
Function
CoilAddressHi
CoilAddressLo
WriteDataHi
WriteDataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
11
06
00
01
00
03
9A
9B
None
8
ASCIICharacters
:(Colon)
11
06
00
01
00
03
LRC(E5)
CRLF
17
Function15(0Fhex)WriteMultipleCoils
WriteseachcoilinasequenceofcoilstoeitherONorOFF.
Request
[Link]
zerocoil1isaddressedas0.
TherequestedON/OFFstatesarespecifiedbycontentsoftherequestdatafield.Alogical1
inabitpositionofthefieldrequeststhecorrespondingcoilstobeON.Alogical0requestsitto
beOFF.
Belowisanexampleofarequesttowriteaseriesoftencoilsstartingatcoil20(addressedas
19,or13hex)inslavedevice17.
Therequestdatacontentsaretwobytes:CD01hex(1100110100000001binary).The
binarybitscorrespondtothecoilsinthefollowingway:
Bit:1100110100000001
Coil:27262524232221202928
Thefirstbytetransmitted(CDhex)addressescoils27...20,withtheleastsignificantbit
addressingthelowestcoil(20)inthisset.
Thenextbytetransmitted(01hex)addressescoils29and28,withtheleastsignificantbit
addressingthelowestcoil(28)[Link]
filled.
FieldName
[Link]
RTU(hex)
ASCIICharacters
6/9
12/6/2016
Header
SlaveAddress
Function
CoilAddressHi
CoilAddressLo
QuantityofCoilsHi
QuantityofCoilsLo
ByteCount
WriteDataHi
WriteDataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
ModbusProtocol
None
11
0F
00
13
00
0A
02
CD
01
BF
0B
None
11
:(Colon)
11
0F
00
13
00
0A
02
CD
01
LRC(F3)
CRLF
23
Response
Thenormalresponsereturnstheslaveaddress,functioncode,startingaddress,andnumberof
[Link]
FieldName
Header
SlaveAddress
Function
CoilAddressHi
CoilAddressLo
QuantityofCoilsHi
QuantityofCoilsLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
11
0F
00
13
00
0A
26
99
None
8
ASCIICharacters
:(Colon)
11
0F
00
13
00
0A
LRC(C3)
CRLF
17
Function16(10hex)WriteMultipleRegisters
Writesvaluesintoasequenceofholdingregisters
Request
[Link]
startingatzeroregister1isaddressedas0.
[Link]
perregister.
Hereisanexampleofarequesttowritetworegistersstartingat40002to000Aand0102
hex,inslavedevice17:
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
QuantityofRegistersHi
QuantityofRegistersLo
ByteCount
DataHi
DataLo
DataHi
DataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
RTU(hex)
None
11
10
00
01
00
02
04
00
0A
01
02
C6
F0
None
13
ASCIICharacters
:(Colon)
11
10
00
01
00
02
04
00
0A
01
02
LRC(CB)
CRLF
23
Response
Thenormalresponsereturnstheslaveaddress,functioncode,startingaddress,andquantity
[Link].
[Link]
7/9
12/6/2016
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
QuantityofRegistersHi
QuantityofRegistersLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes
ModbusProtocol
RTU(hex)
None
11
10
00
01
00
02
12
98
None
8
ASCIICharacters
:(Colon)
11
10
00
01
00
02
LRC(DC)
CRLF
17
LRCExampleCode
ThisfunctionisanexamplehowtocalculateaLRCBYTEusingtheClanguage.
BYTELRC(BYTE*nData,WORDwLength)
{
BYTEnLRC=0;//LRCcharinitialized
for(inti=0;i<wLength;i++)
nLRC+=*nData++;
return(BYTE)(nLRC);
}//End:LRC
CRCExampleCode
ThisfunctionisanexamplehowtocalculateaCRCwordusingtheClanguage.
WORDCRC16(constBYTE*nData,WORDwLength)
{
staticconstWORDwCRCTable[]={
0X0000,0XC0C1,0XC181,0X0140,0XC301,0X03C0,0X0280,0XC241,
0XC601,0X06C0,0X0780,0XC741,0X0500,0XC5C1,0XC481,0X0440,
0XCC01,0X0CC0,0X0D80,0XCD41,0X0F00,0XCFC1,0XCE81,0X0E40,
0X0A00,0XCAC1,0XCB81,0X0B40,0XC901,0X09C0,0X0880,0XC841,
0XD801,0X18C0,0X1980,0XD941,0X1B00,0XDBC1,0XDA81,0X1A40,
0X1E00,0XDEC1,0XDF81,0X1F40,0XDD01,0X1DC0,0X1C80,0XDC41,
0X1400,0XD4C1,0XD581,0X1540,0XD701,0X17C0,0X1680,0XD641,
0XD201,0X12C0,0X1380,0XD341,0X1100,0XD1C1,0XD081,0X1040,
0XF001,0X30C0,0X3180,0XF141,0X3300,0XF3C1,0XF281,0X3240,
0X3600,0XF6C1,0XF781,0X3740,0XF501,0X35C0,0X3480,0XF441,
0X3C00,0XFCC1,0XFD81,0X3D40,0XFF01,0X3FC0,0X3E80,0XFE41,
0XFA01,0X3AC0,0X3B80,0XFB41,0X3900,0XF9C1,0XF881,0X3840,
0X2800,0XE8C1,0XE981,0X2940,0XEB01,0X2BC0,0X2A80,0XEA41,
0XEE01,0X2EC0,0X2F80,0XEF41,0X2D00,0XEDC1,0XEC81,0X2C40,
0XE401,0X24C0,0X2580,0XE541,0X2700,0XE7C1,0XE681,0X2640,
0X2200,0XE2C1,0XE381,0X2340,0XE101,0X21C0,0X2080,0XE041,
0XA001,0X60C0,0X6180,0XA141,0X6300,0XA3C1,0XA281,0X6240,
0X6600,0XA6C1,0XA781,0X6740,0XA501,0X65C0,0X6480,0XA441,
0X6C00,0XACC1,0XAD81,0X6D40,0XAF01,0X6FC0,0X6E80,0XAE41,
0XAA01,0X6AC0,0X6B80,0XAB41,0X6900,0XA9C1,0XA881,0X6840,
0X7800,0XB8C1,0XB981,0X7940,0XBB01,0X7BC0,0X7A80,0XBA41,
0XBE01,0X7EC0,0X7F80,0XBF41,0X7D00,0XBDC1,0XBC81,0X7C40,
0XB401,0X74C0,0X7580,0XB541,0X7700,0XB7C1,0XB681,0X7640,
0X7200,0XB2C1,0XB381,0X7340,0XB101,0X71C0,0X7080,0XB041,
0X5000,0X90C1,0X9181,0X5140,0X9301,0X53C0,0X5280,0X9241,
0X9601,0X56C0,0X5780,0X9741,0X5500,0X95C1,0X9481,0X5440,
0X9C01,0X5CC0,0X5D80,0X9D41,0X5F00,0X9FC1,0X9E81,0X5E40,
0X5A00,0X9AC1,0X9B81,0X5B40,0X9901,0X59C0,0X5880,0X9841,
0X8801,0X48C0,0X4980,0X8941,0X4B00,0X8BC1,0X8A81,0X4A40,
0X4E00,0X8EC1,0X8F81,0X4F40,0X8D01,0X4DC0,0X4C80,0X8C41,
0X4400,0X84C1,0X8581,0X4540,0X8701,0X47C0,0X4680,0X8641,
0X8201,0X42C0,0X4380,0X8341,0X4100,0X81C1,0X8081,0X4040};
BYTEnTemp;
WORDwCRCWord=0xFFFF;
while(wLength)
{
nTemp=*nData++^wCRCWord;
[Link]
8/9
12/6/2016
ModbusProtocol
wCRCWord>>=8;
wCRCWord^=wCRCTable[nTemp];
}
returnwCRCWord;
}//End:CRC16
Copyright2016WitteSoftwareAllrightsreserved.
[Link]
9/9