0% found this document useful (0 votes)
9 views9 pages

Modbus Protocol Overview and Modes

The document describes the Modbus protocol, including the structure of Modbus messages, the request and response formats, and supported function codes. Modbus allows for master-slave communication between devices using either ASCII or RTU transmission modes, each with different character framing and error checking methods. Common function codes allow reading and writing of coils, registers, and other data.

Uploaded by

Ricardo Fuentes
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views9 pages

Modbus Protocol Overview and Modes

The document describes the Modbus protocol, including the structure of Modbus messages, the request and response formats, and supported function codes. Modbus allows for master-slave communication between devices using either ASCII or RTU transmission modes, each with different character framing and error checking methods. Common function codes allow reading and writing of coils, registers, and other data.

Uploaded by

Ricardo Fuentes
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

12/6/2016

ModbusProtocol

modbustools
Fortest,simulationandprogramming.
HOME

PRODUCTS

ORDER

DOWNLOAD

MODBUS

CONTACT

ProtocolDescription
MODBUSProtocolisamessagingstructure,widelyusedtoestablishmasterslave
[Link]
containstheaddressoftheslave,the'command'(e.g.'readregister'or'writeregister'),the
data,andachecksum(LRCorCRC).
SinceModbusprotocolisjustamessagingstructure,itisindependentoftheunderlying
physicallayer.ItistraditionallyimplementedusingRS232,RS422,orRS485
TheRequest
Thefunctioncodeintherequesttellstheaddressedslavedevicewhatkindofactionto
[Link]
[Link],functioncode03willrequesttheslavetoreadholding
[Link]
[Link]
providesamethodfortheslavetovalidatetheintegrityofthemessagecontents.
TheResponse
Iftheslavemakesanormalresponse,thefunctioncodeintheresponseisanechoofthe
[Link],suchas
[Link],thefunctioncodeismodifiedtoindicatethatthe
responseisanerrorresponse,[Link]
errorcheckfieldallowsthemastertoconfirmthatthemessagecontentsarevalid.
ControllerscanbesetuptocommunicateonstandardModbusnetworksusingeitheroftwo
transmissionmodes:ASCIIorRTU.
ASCIIMode
WhencontrollersaresetuptocommunicateonaModbusnetworkusingASCII(American
StandardCodeforInformationInterchange)mode,eacheightbitbyteinamessageissentas
[Link]
onesecondtooccurbetweencharacterswithoutcausinganerror.
CodingSystem
HexadecimalASCIIprintablecharacters0...9,A...F
BitsperByte
1startbit
7databits,leastsignificantbitsentfirst
1bitforeven/oddparitynobitfornoparity
1stopbitifparityisused2bitsifnoparity
ErrorChecking
LongitudinalRedundancyCheck(LRC)
RTUMode
WhencontrollersaresetuptocommunicateonaModbusnetworkusingRTU(RemoteTerminal
Unit)mode,eacheightbitbyteinamessagecontainstwofourbithexadecimalcharacters.
Themainadvantageofthismodeisthatitsgreatercharacterdensityallowsbetterdata
[Link]
continuousstream.
CodingSystem
Eightbitbinary,hexadecimal0...9,A...F
Twohexadecimalcharacterscontainedineacheightbitfieldofthemessage
BitsperByte
1startbit
8databits,leastsignificantbitsentfirst
1bitforeven/oddparitynobitfornoparity
1stopbitifparityisused2bitsifnoparity
ErrorCheckField
CyclicalRedundancyCheck(CRC)
InASCIImode,messagesstartwithacolon(:)character(ASCII3Ahex),andendwitha
carriagereturnlinefeed(CRLF)pair(ASCII0Dand0Ahex).
Theallowablecharacterstransmittedforallotherfieldsarehexadecimal0...9,A...F.
[Link]
received,eachdevicedecodesthenextfield(theaddressfield)tofindoutifitistheaddressed
device.
[Link]
intervaloccurs,[Link]

[Link]

1/9

12/6/2016

ModbusProtocol

shownbelow.
Start

Address

Function

Data

LRC

End

2Chars

2Chars

NChars

2Chars

CRLF

RTUFraming
InRTUmode,[Link]
easilyimplementedasamultipleofcharactertimesatthebaudratethatisbeingusedonthe
network(shownasT1T2T3T4inthefigurebelow).Thefirstfieldthentransmittedisthe
deviceaddress.
Theallowablecharacterstransmittedforallfieldsarehexadecimal0...9,A...[Link]
devicesmonitorthenetworkbuscontinuously,[Link]
firstfield(theaddressfield)isreceived,eachdevicedecodesittofindoutifitistheaddressed
device.
Followingthelasttransmittedcharacter,asimilarintervalofatleast3.5charactertimes
[Link].
[Link]
morethan1.5charactertimesoccursbeforecompletionoftheframe,thereceivingdevice
flushestheincompletemessageandassumesthatthenextbytewillbetheaddressfieldofa
newmessage.
Similarly,ifanewmessagebeginsearlierthan3.5charactertimesfollowingaprevious
message,[Link]
setanerror,asthevalueinthefinalCRCfieldwillnotbevalidforthecombinedmessages.A
typicalmessageframeisshownbelow.
Start

Address

3.5Chartime 8Bit

Function

Data

CRC

End

8Bit

N*8Bit

16Bit

3.5Chartime

AddressField
Theaddressfieldofamessageframecontainstwocharacters(ASCII)oreightbits(RTU).The
individualslavedevicesareassignedaddressesintherangeof1...247.
FunctionField
TheFunctionCodefieldtellstheaddressedslavewhatfunctiontoperform.
ThefollowingfunctionsaresupportedbyModbuspoll
01READCOILSTATUS
02READINPUTSTATUS
03READHOLDINGREGISTERS
04READINPUTREGISTERS
05WRITESINGLECOIL
06WRITESINGLEREGISTER
15WRITEMULTIPLECOILS
16WRITEMULTIPLEREGISTERS
Thedatafieldcontainstherequestedorsenddata.
ContentsoftheErrorCheckingField
[Link]
checkingfieldcontentsdependuponthemethodthatisbeingused.
ASCII
WhenASCIImodeisusedforcharacterframing,theerrorcheckingfieldcontainstwoASCII
[Link]
(LRC)calculationthatisperformedonthemessagecontents,exclusiveofthebeginningcolon
andterminatingCRLFcharacters.
TheLRCcharactersareappendedtothemessageasthelastfieldprecedingtheCRLF
characters.
LRCExampleCode
RTU
WhenRTUmodeisusedforcharacterframing,theerrorcheckingfieldcontainsa16bitvalue
[Link]
RedundancyCheckcalculationperformedonthemessagecontents.
[Link],
theloworderbyteofthefieldisappendedfirst,[Link]
highorderbyteisthelastbytetobesentinthemessage.
CRCExampleCode
Function01(01hex)ReadCoils
ReadstheON/OFFstatusofdiscretecoilsintheslave.
Request
Therequestmessagespecifiesthestartingcoilandquantityofcoilstoberead.

[Link]

2/9

12/6/2016

ModbusProtocol

Exampleofarequesttoread10...22(Coil11to23)fromslavedeviceaddress4:
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
QuantityofCoilsHi
QuantityofCoilsLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
04
01
00
0A
00
0D
DD
98
None
8

ASCIICharacters
:(Colon)
04
01
00
0A
00
0D
LRC(E4)

CRLF
17

Response
[Link]
indicatedas:1isthevalueON,[Link]
[Link]
[Link]
multipleofeight,theremainingbitsinthefinaldatabytewillbepaddedwithzeroes(toward
thehighorderendofthebyte).Thebytecountfieldspecifiesthequantityofcompletebytes
ofdata.
Exampleofaresponsetotherequest:
FieldName
Header
SlaveAddress
Function
ByteCount
Data(Coils7...10)
Data(Coils27...20)
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
04
01
02
0A
11
B3
50
None
7

ASCIICharacters
:(Colon)
04
01
02
0A
11
LRC(DE)
None
CRLF
15

Function02(02hex)ReadDiscreteInputs
ReadstheON/OFFstatusofdiscreteinputsintheslave.
Request
Therequestmessagespecifiesthestartinginputandquantityofinputstoberead.
Exampleofarequesttoread10...22(input10011to10023)fromslavedeviceaddress4:
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
QuantityofinputsHi
QuantityofinputsLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
04
02
00
0A
00
0D
99
98
None
8

ASCIICharacters
:(Colon)
04
02
00
0A
00
0D
LRC(E3)

CRLF
17

Response
[Link]
indicatedas:1isthevalueON,[Link]
[Link]
[Link]
notamultipleofeight,theremainingbitsinthefinaldatabytewillbepaddedwithzeroes
(towardthehighorderendofthebyte).Thebytecountfieldspecifiesthequantityof
completebytesofdata.
Exampleofaresponsetotherequest:

[Link]

3/9

12/6/2016
FieldName
Header
SlaveAddress
Function
ByteCount
Data(Inputs17...10)
Data(Inputs27...20)
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

ModbusProtocol
RTU(hex)
None
04
02
02
0A
11
B3
14
None
7

ASCIICharacters
:(Colon)
04
02
02
0A
11
LRC(DD)
None
CRLF
15

Function03(03hex)ReadHoldingRegisters
Readthebinarycontentsofholdingregistersintheslave.
Request
Therequestmessagespecifiesthestartingregisterandquantityofregisterstoberead.
Exampleofarequesttoread0...1(register40001to40002)fromslavedevice1:
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
QuantityofRegistersHi
QuantityofRegistersLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
01
03
00
00
00
02
C4
0B
None
8

ASCIICharacters
:(Colon)
01
03
00
00
00
02
LRC(FA)

CRLF
17

Response
Theregisterdataintheresponsemessagearepackedastwobytesperregister,withthe
[Link]
highorderbits,andthesecondcontainstheloworderbits.
Exampleofaresponsetotherequest:
FieldName
Header
SlaveAddress
Function
ByteCount
DataHi
DataLo
DataHi
DataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
01
03
04
00
06
00
05
DA
31
None
8

ASCIICharacters
:(Colon)
01
03
04
00
06
00
05
LRC(ED)
None
CRLF
19

Function04(04hex)ReadInputRegisters
Readthebinarycontentsofinputregistersintheslave.
Request
Therequestmessagespecifiesthestartingregisterandquantityofregisterstoberead.
Exampleofarequesttoread0...1(register30001to30002)fromslavedevice1:
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo

[Link]

RTU(hex)
None
01
04
00
00

ASCIICharacters
:(Colon)
01
0
00
00

4/9

12/6/2016
QuantityofRegistersHi
QuantityofRegistersLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

ModbusProtocol
00
02
71
CB
None
8

00
02
LRC(F9)

CRLF
17

Response
Theregisterdataintheresponsemessagearepackedastwobytesperregister,withthe
[Link]
highorderbits,andthesecondcontainstheloworderbits.
Exampleofaresponsetotherequest:
FieldName
Header
SlaveAddress
Function
ByteCount
DataHi
DataLo
DataHi
DataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
01
04
04
00
06
00
05
DB
86
None
9

ASCIICharacters
:(Colon)
01
04
04
00
06
00
05
LRC(EC)
None
CRLF
19

Function05(05hex)WriteSingleCoil
WritesasinglecoiltoeitherONorOFF.
Request
[Link]
zerocoil1isaddressedas0.
TherequestedON/[Link]
[Link]
illegalandwillnotaffectthecoil.
Hereisanexampleofarequesttowritecoil173ONinslavedevice17:
FieldName
Header
SlaveAddress
Function
CoilAddressHi
CoilAddressLo
WriteDataHi
WriteDataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
11
05
00
AC
FF
00
4E
8B
None
8

ASCIICharacters
:(Colon)
11
05
00
AC
00
FF
LRC(3F)

CRLF
17

Response
Thenormalresponseisanechooftherequest,returnedafterthecoilstatehasbeenwritten.
Exampleofaresponsetotherequest:
FieldName
Header
SlaveAddress
Function
CoilAddressHi
CoilAddressLo
WriteDataHi
WriteDataLo
ErrorCheckLo
ErrorCheckHi
Trailer

[Link]

RTU(hex)
None
11
05
00
AC
FF
00
4E
8B
None

ASCIICharacters
:(Colon)
11
05
00
AC
00
FF
LRC(3F)

CRLF

5/9

12/6/2016
TotalBytes

ModbusProtocol
8

17

Function06(06hex)WriteSingleRegister
Writesavalueintoasingleholdingregister.
Request
[Link]
startingatzeroregister1isaddressedas0.
[Link]
requesttoWriteregister40002to0003hexinslavedevice17.
FieldName
Header
SlaveAddress
Function
RegisterAddressHi
RegisterAddressLo
WriteDataHi
WriteDataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
11
06
00
01
00
03
9A
9B
None
8

ASCIICharacters
:(Colon)
11
06
00
01
00
03
LRC(E5)

CRLF
17

Response
Thenormalresponseisanechooftherequest,returnedaftertheregistercontentshavebeen
written.
FieldName
Header
SlaveAddress
Function
CoilAddressHi
CoilAddressLo
WriteDataHi
WriteDataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
11
06
00
01
00
03
9A
9B
None
8

ASCIICharacters
:(Colon)
11
06
00
01
00
03
LRC(E5)

CRLF
17

Function15(0Fhex)WriteMultipleCoils
WriteseachcoilinasequenceofcoilstoeitherONorOFF.
Request
[Link]
zerocoil1isaddressedas0.
TherequestedON/OFFstatesarespecifiedbycontentsoftherequestdatafield.Alogical1
inabitpositionofthefieldrequeststhecorrespondingcoilstobeON.Alogical0requestsitto
beOFF.
Belowisanexampleofarequesttowriteaseriesoftencoilsstartingatcoil20(addressedas
19,or13hex)inslavedevice17.
Therequestdatacontentsaretwobytes:CD01hex(1100110100000001binary).The
binarybitscorrespondtothecoilsinthefollowingway:
Bit:1100110100000001
Coil:27262524232221202928
Thefirstbytetransmitted(CDhex)addressescoils27...20,withtheleastsignificantbit
addressingthelowestcoil(20)inthisset.
Thenextbytetransmitted(01hex)addressescoils29and28,withtheleastsignificantbit
addressingthelowestcoil(28)[Link]
filled.
FieldName

[Link]

RTU(hex)

ASCIICharacters

6/9

12/6/2016
Header
SlaveAddress
Function
CoilAddressHi
CoilAddressLo
QuantityofCoilsHi
QuantityofCoilsLo
ByteCount
WriteDataHi
WriteDataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

ModbusProtocol
None
11
0F
00
13
00
0A
02
CD
01
BF
0B
None
11

:(Colon)
11
0F
00
13
00
0A
02
CD
01
LRC(F3)

CRLF
23

Response
Thenormalresponsereturnstheslaveaddress,functioncode,startingaddress,andnumberof
[Link]
FieldName
Header
SlaveAddress
Function
CoilAddressHi
CoilAddressLo
QuantityofCoilsHi
QuantityofCoilsLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
11
0F
00
13
00
0A
26
99
None
8

ASCIICharacters
:(Colon)
11
0F
00
13
00
0A
LRC(C3)

CRLF
17

Function16(10hex)WriteMultipleRegisters
Writesvaluesintoasequenceofholdingregisters
Request
[Link]
startingatzeroregister1isaddressedas0.
[Link]
perregister.
Hereisanexampleofarequesttowritetworegistersstartingat40002to000Aand0102
hex,inslavedevice17:
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
QuantityofRegistersHi
QuantityofRegistersLo
ByteCount
DataHi
DataLo
DataHi
DataLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

RTU(hex)
None
11
10
00
01
00
02
04
00
0A
01
02
C6
F0
None
13

ASCIICharacters
:(Colon)
11
10
00
01
00
02
04
00
0A
01
02
LRC(CB)

CRLF
23

Response
Thenormalresponsereturnstheslaveaddress,functioncode,startingaddress,andquantity
[Link].

[Link]

7/9

12/6/2016
FieldName
Header
SlaveAddress
Function
StartingAddressHi
StartingAddressLo
QuantityofRegistersHi
QuantityofRegistersLo
ErrorCheckLo
ErrorCheckHi
Trailer
TotalBytes

ModbusProtocol
RTU(hex)
None
11
10
00
01
00
02
12
98
None
8

ASCIICharacters
:(Colon)
11
10
00
01
00
02
LRC(DC)

CRLF
17

LRCExampleCode
ThisfunctionisanexamplehowtocalculateaLRCBYTEusingtheClanguage.
BYTELRC(BYTE*nData,WORDwLength)
{
BYTEnLRC=0;//LRCcharinitialized
for(inti=0;i<wLength;i++)
nLRC+=*nData++;
return(BYTE)(nLRC);
}//End:LRC
CRCExampleCode
ThisfunctionisanexamplehowtocalculateaCRCwordusingtheClanguage.
WORDCRC16(constBYTE*nData,WORDwLength)
{
staticconstWORDwCRCTable[]={
0X0000,0XC0C1,0XC181,0X0140,0XC301,0X03C0,0X0280,0XC241,
0XC601,0X06C0,0X0780,0XC741,0X0500,0XC5C1,0XC481,0X0440,
0XCC01,0X0CC0,0X0D80,0XCD41,0X0F00,0XCFC1,0XCE81,0X0E40,
0X0A00,0XCAC1,0XCB81,0X0B40,0XC901,0X09C0,0X0880,0XC841,
0XD801,0X18C0,0X1980,0XD941,0X1B00,0XDBC1,0XDA81,0X1A40,
0X1E00,0XDEC1,0XDF81,0X1F40,0XDD01,0X1DC0,0X1C80,0XDC41,
0X1400,0XD4C1,0XD581,0X1540,0XD701,0X17C0,0X1680,0XD641,
0XD201,0X12C0,0X1380,0XD341,0X1100,0XD1C1,0XD081,0X1040,
0XF001,0X30C0,0X3180,0XF141,0X3300,0XF3C1,0XF281,0X3240,
0X3600,0XF6C1,0XF781,0X3740,0XF501,0X35C0,0X3480,0XF441,
0X3C00,0XFCC1,0XFD81,0X3D40,0XFF01,0X3FC0,0X3E80,0XFE41,
0XFA01,0X3AC0,0X3B80,0XFB41,0X3900,0XF9C1,0XF881,0X3840,
0X2800,0XE8C1,0XE981,0X2940,0XEB01,0X2BC0,0X2A80,0XEA41,
0XEE01,0X2EC0,0X2F80,0XEF41,0X2D00,0XEDC1,0XEC81,0X2C40,
0XE401,0X24C0,0X2580,0XE541,0X2700,0XE7C1,0XE681,0X2640,
0X2200,0XE2C1,0XE381,0X2340,0XE101,0X21C0,0X2080,0XE041,
0XA001,0X60C0,0X6180,0XA141,0X6300,0XA3C1,0XA281,0X6240,
0X6600,0XA6C1,0XA781,0X6740,0XA501,0X65C0,0X6480,0XA441,
0X6C00,0XACC1,0XAD81,0X6D40,0XAF01,0X6FC0,0X6E80,0XAE41,
0XAA01,0X6AC0,0X6B80,0XAB41,0X6900,0XA9C1,0XA881,0X6840,
0X7800,0XB8C1,0XB981,0X7940,0XBB01,0X7BC0,0X7A80,0XBA41,
0XBE01,0X7EC0,0X7F80,0XBF41,0X7D00,0XBDC1,0XBC81,0X7C40,
0XB401,0X74C0,0X7580,0XB541,0X7700,0XB7C1,0XB681,0X7640,
0X7200,0XB2C1,0XB381,0X7340,0XB101,0X71C0,0X7080,0XB041,
0X5000,0X90C1,0X9181,0X5140,0X9301,0X53C0,0X5280,0X9241,
0X9601,0X56C0,0X5780,0X9741,0X5500,0X95C1,0X9481,0X5440,
0X9C01,0X5CC0,0X5D80,0X9D41,0X5F00,0X9FC1,0X9E81,0X5E40,
0X5A00,0X9AC1,0X9B81,0X5B40,0X9901,0X59C0,0X5880,0X9841,
0X8801,0X48C0,0X4980,0X8941,0X4B00,0X8BC1,0X8A81,0X4A40,
0X4E00,0X8EC1,0X8F81,0X4F40,0X8D01,0X4DC0,0X4C80,0X8C41,
0X4400,0X84C1,0X8581,0X4540,0X8701,0X47C0,0X4680,0X8641,
0X8201,0X42C0,0X4380,0X8341,0X4100,0X81C1,0X8081,0X4040};
BYTEnTemp;
WORDwCRCWord=0xFFFF;
while(wLength)
{
nTemp=*nData++^wCRCWord;

[Link]

8/9

12/6/2016

ModbusProtocol

wCRCWord>>=8;
wCRCWord^=wCRCTable[nTemp];
}
returnwCRCWord;
}//End:CRC16

Copyright2016WitteSoftwareAllrightsreserved.

[Link]

9/9

You might also like