King Pigeon M T Series User Manual
King Pigeon M T Series User Manual
Manuals / Brands / King Pigeon Manuals / I/O Systems / M T Series / User manual / PDF
Industrial
Ethernet Remote I/O Module
MxxT Series
User Manual
Ver 2.3
[Link]
Industrial Ethernet Remote I/O Module
IoT Data Acquisition Module
【UPGRADE HISTORY】...........................................................................................................................................................4
1. Brief introduction.................................................................................................................................................................4
[Link] Packing List............................................................................................................................................................ 5
3. Mainly Features....................................................................................................................................................................6
4. Technical Specifications....................................................................................................................................................... 6
5. Physical Layout and Installation Diagram............................................................................................................................ 9
5.1 Physical Layout....................................................................................................................................................... 9
5.2 Led Instruction...................................................................................................................................................... 10
5.3 Interface Instructions for installation................................................................................................................... 10
5.4 RTD/AI/AO............................................................................................................................................................. 15
RS485...................................................................................................................................................................19
5.5 Setup the DIN1 High Speed Pulse Count & Low Speed Pulse Count Mode:.............................................................20
6. Initialize/Reset the Module................................................................................................................................................21
7. Settings&Operation........................................................................................................................................................... 21
7.1 Ready to Set up:....................................................................................................................................................21
7.2 Selection Description................................................................................................................................................22
7.3 Basic Setting......................................................................................................................................................... 23
7.4 Network Settings.................................................................................................................................................. 24
7.5 Slave Settings........................................................................................................................................................25
7.6 Register list........................................................................................................................................................... 27
7.7 System Log............................................................................................................................................................ 29
8. Modbus Protocol................................................................................................................................................................30
8.1Introduction to Modbus Register Address............................................................................................................... 30
8.1.1 Read Input Coil (Function Code 2: Read Coil)............................................................................................... 30
8.1.2 Read and Write Holding Coil........................................................................................................................ 31
8.1.3 Read Input Register...................................................................................................................................... 32
8.1.4 Read and Write Holding Register......................................................................................................................... 34
8.1.5 Mapping Register----Transit BIT Register Address....................................................................................... 36
8.1.6 Mapping Register----Transit 16-Bit Register Address.................................................................................. 36
8.2Example of reading and writing registers.................................................................................................................36
8.2.1 Read the input coil of this device.................................................................................................................36
8.2.2 Read this device holding coil........................................................................................................................37
8.2.3 Write device holding coil..............................................................................................................................39
8.2.4 Read native input register............................................................................................................................41
8.2.5 Read local holding register...........................................................................................................................42
8.2.6 Control the local holding register.................................................................................................................44
8.3Read device map register......................................................................................................................................... 46
8.3.1Read Bit mapping address data46
8.3.2Rewrite the bit mapping address data..........................................................................................................47
8.3.3Read 16-bit mapped address data................................................................................................................ 48
8.3.4Write 16-bit mapped address data............................................................................................................... 49
9. Warranty............................................................................................................................................................................ 50
[Link] Application of MQTT......................................................................................................................................52
This user manual has been designed as a guide to the installation and operation of MxxT Ethernet Remote I/O Module.
Statements contained in the manual are general guidelines only and in no way are designed to supersede the
instructions contained with other products.
We recommend the advice of a registered electrician before any Installation work.
King Pigeon [Link]., Ltd, its employees and distributors, accept no liability for any loss or damage including
consequential damage due to reliance on any material contained in this manual.
King Pigeon [Link]., Ltd, its employees and distributors, accept no liability for any Network upgrading or due to
the technology specifications contained in this manual.
【UPGRADE HISTORY】
1. Brief introduction
The MxxxT Ethernet Remote I/O Module is an industrial class, isolated designed, high reliability, high stability and
high precision data acquisition module, embedded 32-Bit High Performance Microprocessor MCU, Integrated 1
Industrial 10/100M adaptive Ethernet module inside. It provides multi I/O, supports standard Modbus TCP,
supports modbus master and slave, can be integrated into SCADA, OPC server, and other automation systems. It is
design for working in the harsh industrial application environment, widely used in a variety of industrial
automation, security monitoring system, automatically measurement and control system.
The MxxxT Ethernet Remote I/O module provides a RS485 interface, through the RS485 bus, it can cascade
Modbus I/O devices or Modbus meters, e.g.: a variety of digital input or digital outputs, analog inputs or outputs,
thermal resistance IO module combination, save costs. At the same time, the Ethernet Remote I/O module has
register mapping function, the cascade Modbus I/O data are automatically collected to the register mapping area,
the TCP Client polling without waiting then can get a quick response to meet the industrial timely requirements.
The MxxxT Ethernet Remote I/O module provides different I/O ports for variety applications. Includes
optical-isolated digital inputs, compatibles dry contact and wet contact, supports max 700KHz high speed pulse
counter, digital outputs supports 10Hz~300Khz high speed pulse output or relay outputs, isolated 12bits analog
inputs, supports 0~5V, 0~10V, 4~20mA, 0~20mA analog signal, 12bits analog outputs, supports 0~10VDC signal
The MxxxT Ethernet Remote I/O module can work at wide working voltage range, the range is 12 ~ 36VDC with
anti-reverse protection design. Also, it provides 1channel 12~36VDC power output for external device to save
wiring cost.
Ethernet Remote I/O Module X 1, Card type Manual X 1, 35mm Standard DIN rail fixed Bracket*1.
Note: The package does not include AC/DC Adaptor.
Standard Modbus TCP protocol and Modbus RTU over TCP communication protocol and MQTT protocol;
Embedded 32-Bit High Performance Microprocessor MCU, inbuilt watchdog;
Power supply 9~36V DC with over voltage and phase-reversal protection;
Management and configuration via LAN connection configuration software for easy operation and
maintenance;
Integrated 10/100M adaptive Ethernet port, With 15KV ESD protection;
Optical isolated digital input(Compatible Dry or Wet type), supports max 700KHz high speed pulse counter;
Support DIN2~DIN12 as a low-speed pulse counter. The anti-jitter time can be set to 1~2000ms, the default is
1ms, and the corresponding pulse frequency is up to 1KHz;
DO supports Sink output,DO1 can be used as high-speed pulse output, supports 10Hz~300KHz ;
Isolated analog input, 12-bit resolution, supports 0~20mA,4~20mA,0-5VDC, 0-10VDC;
Analog output, 12-bit resolution, supports 0-10VDC;
RTD input, supports PT100 and PT1000 resistance sensor, compatible 2 or 3 wires;
High sampling frequency and special filtering strategy to ensure reliability;
1 RS485 Serial port, supports Modbus RTU Master/Slave, can extend I/O modules;
Supports register mapping function and extend I/O inquiry strategy;
Supports TCP Client and TCP Server, supports max. 5 TCP Client connections;
Provides 1 channel VDC power source output for external device, saving wiring cost;
LED instructions work status, with reset button to reset, easy on-site installation and commissioning;
Using metal shell, protection class IP30. Metal shell and system security isolation, especially suitable for
industrial applications in the field;
Small size, L82 * W40 * H99mm, compatible wall installation and DIN35mm industrial rail installation.
4. Technical Specifications
• Digital Input
Wet Contact (NPN or PNP), Dry Contact. Default wet contact, if need dry
Type
contact ,pleases tell us when order
I/O Mode DI or Pulse Counter
• On: short to GND, logic=1
Dry Contact
• Off: open, logic=0
• On: 10 to 30 VDC,logic=1
Wet Contact (DI to COM)
• Off: 0 to 3 VDC,logic=0
Only the 1st Channel can be used as pulse counter, Compatibles DI and
Pulse Counter Frequency
counter simultaneously. Counter value will save if power off.
• Analog Input
Type mA/V
Resolution 12 bits
Voltage type: >1M ohms
input impedance
Current type: 162 ohms
Input Range 0~5VDC , 0~10VDC, 0~20 mA, 4~20mA,
±0.1% FSR @ 25°C
Accuracy
±0.3% FSR @ -10 and 60°C
Sampling frequency 20Hz
• RTD Input
Sensor Type PT100 or PT1000(default PT100,If need PT1000,please tell us when order)
Mapping registers Bit registers: 300, 16-Bit register: 300. Total 600 mapping registers.
• Physical Characteristics
Wiring I/O cable max. 14 AWG
Dimensions 82x 40 x 99 mm
Weight 300 g
Digital input status indicator, turn on or input high level, or will close.
Digital Output status indicator, turn on or output high level, or will close.
DI&DO
Digital input (DI) supports up to 16 channels, with dry contact/wet contact type optional, and the default type is wet
[Link] output (DO) supports up to 16 channels and supports sink type.
DI&DO
DIN1~DIN
1~16 digital input
16
COM Digital input common
DO1~DO1
1~16 digital (sink) output
6
COM Digital output common
5.4 RTD/AI/AO
The top terminal pins are multiplexed functions, and the specific function definitions are determined
according to the model selection table.
Tips:
Resistance Thermal Detector (RTD) compatibles 2-wire or 3-wire, please reference above mentioned wiring instruction. If
the sensor near the module and the wire resistance is small can be ignored, can be used 2-wire wiring, if the distance is far
and the wire resistance affect the value, should be used 3-wire way connection.
RTD/AI/AO
AI wiring (2 wire)
AI Wiring (3 wire)
AO wiring
RS485
A RS485 Data A
B RS485 Data B
RS485 Wiring
Ethernet
5.5 Setup the DIN1 High Speed Pulse Count & Low Speed Pulse Count Mode:
The DIN1 can be used as pulse counter, default is high speed mode, the max. Frequency is 700Khz. it can be change
to low speed pulse count mode by open the shell, and change the JP2&JP3’s jump Caps to the right side2PINs, see
below pictures.
The device can be reset to factory default if mistake programmed. Please follow below steps to initialize it. After
initialized, the parameters will set as factory default.
1) Switch off the device
2) Press and hold the RESET button;
3) Power ON the Unit, waiting for 3 seconds, all the 4 lights( PWR, Link, RS485, Error Led Indicators) will turn on,
then loose the RESET Button, the other lights will flick for 5 times then turn off, while the PWR Led indicator
keeps on.
4) Turn off and Restart the device then recovery to factory default settings, and will enter to work mode. All of
the parameters will be reset to factory default.
7. Settings&Operation
The MxxxT Ethernet Remote I/O module provides a standard Ethernet RJ45 interface, through the direct line
connect to the router, switches, HUB and other interconnect switching equipment, or through the cross-line
connect to PC and other terminal devices. The user can program parameters, firmware upgrades and debugging
through the WEB configuration interface. In the actual use, the Master will communicate it by MODBUS to read
and write the local register address and mapped registers of the slave I / O.
Below are the steps to setup the parameters by software, please follow it step by step.
1) Through the direct line connect to the router, switches, HUB and other interconnect switching equipment, or
through the crossover cable connect to PC and other terminal devices, And make sure the device and computer are
in the same LAN.
2) Powered on the device, the PWR LED indicator will turn on and the device will initialize within several second.
System Settings
[Login Password]: Parameter setting can be done after login. The default password is 1234.
[Change Password]: Modify the device password. After modification, you need to log in with the new password.
[Save Data]: Save the parameter configuration to the device.
[Loading Data]: Read the parameter configuration of the device. Please read the current configuration before
setting the parameters.
[Time/MAC address]: Click this item to read and modify the device time and MAC address (restart to take effect
after the MAC address is modified).
[Restart]: Click this item to restart the device.
[Close]: Click this item to close the configuration software.
Device Search
[Login Password]: Click this item to search device.
File Operation
[Load File]: Import the previously exported configuration file parameter information to the configuration
software.
[Save File]: Export the current parameter information on the configuration software to a computer configuration
Language Selection
[Chinese]: Click to switch language to Chinese.
[English]: Click to switch language to English.
Got the IP address Auto: Tick it stands for: the device automatically obtains the IP address in the LAN. Only when
the router in the LAN allows the dynamic allocation of IP addresses can be used.
User Specifies the IP Address: Tick it stands for the user setup a fixed IP address for the module.
IP Address,Gateway,Netmask,Primary DNS,Secondary DNS: Only can be set After choose ”User specifies the IP
address”.
Modbus TCP listening port: 1~65535, default is 502, listen TCP Client establish connection port, supports max 5
TCP Client connection.
Modbus over TCP Active Connection Settings: Tick it stands for device will connect to the server automatically, or
will not connect.
Connection Mode: Optional [Modbus RTU over TCP], [Modbus TCP], [MQTT] communication protocol.
Server 1/2 IP/Domain,Server 1/2 Port: The device will connect to server 1 first, and connect to server 2 when the
connection fails.
Register Packets: Registration packet sent by the device to the server when connecting to the server.
This series of products provide a serial port and network port to make it have powerful expansion functions. In the
device's internal storage area, 300 BIT-bit registers (Boolean) and 300 16-bit register mapping areas are provided.
(those 300 register can be 16-bit,32-bit or 64-bit,32-bit takes 2 16-bit address,64-bit takes 4 16-bit address ,
etc).This storage area is used to store slave data, which can reduce the communication response waiting time of
the entire network device and improve communication efficiency.
RS485 Settings
If the slave is only provides RS-232 interface, please use the RS-232/RS-485 converter connected to the 485
network. It is strongly recommended to use the isolated RS485 converter to improve system reliability. In a BUS, all
of the equipment ‘data A + should be connected together, and data B- should be connected together, cannot be
reversed, RS485 signal to the GND terminal should be shorted together, and connect to the module’s ground only.
RS-485 network generally allows up to 32 nodes in parallel devices, more than 32 systems need to use RS485
repeater to expand. RS-485 communication line should be STP(shielded twisted pair), the shield should be
single-ended ground; RS485 communication distance can be up to 1200 meters, when a bus connected to a lot of
RS485 devices, or use high baud rate higher communication distance Will be correspondingly shortened
accordingly, then you can use RS485 repeater to expand. RS-485 network has a variety of topology, the general use
of linear connection, that is, start from near to far, connecting devices to the master one by one. In the far end can
be connected to 120 ~ 300Ω / 0.25 watts of terminal matching resistance (depending on the communication
quality to determine).
Mode Selection : Master or Slave optional.
Baud rate : 2400,4800,9600,14400,19200,38400,57600,115200,128000 optional.
Data Bit: 7, 8 bit.
Parity Bit: None, Even and Odd optional.
Stop Bit: 0.5Bit, 1Bit, 1.5Bit, and 2Bit optional.
Over time: Wait for the command reply time, the next command will be sent after timeout, default 200ms
Interval: Polling time, each command sending interval time, default is 200ms; please increase the time
appropriately when there are too many slaves.
Retry counts: command reply timeout retry times, default is 3 times.
Mapping Registers--Read Coil & Registers: Mapping registers between the slaves and module
Mapping Registers--Write Coil & Registers: Mapping registers between the slave and module
After configuration, the module will write the Modbus slaves automatically by the corresponding Function codes
according to the mapped registers.
Slave address : slave device ID, range 1~247.
Function code : Sets the type of action host to slave. Including 05/15 write holding coil and 06/16 write holding
register, where the value of the holding coil is automatically allocated to the mapping storage area
of the relay bit register, and the value of the holding register is automatically allocated In the
mapped memory area of the transit 16-bit register.
Slave Start addr : The starting register address for slave data writing.
Number of registers: How many register need to write.
Mapped Addr(100-399) : Stand for mapping the slave start register data to the device start mapping address, Can
be set 100-399, the mapping addresses of the transit Bit and 16-bit registers are
separate, each occupying 300. The mapping addresses of the same type must not be the
same, and the mapping addresses for reading and writing cannot be the same.
Collection Target: Optional RS485, ports 1 ~ 5, corresponding to TCP slaves 1 ~ 5 respectively.
Add: After editing a slave information, click” Add” to map the register address of the cluster device to the mapping
storage area of this device.
Note: After setting, please click "System Settings"-"Loading data" option to save the set parameters.
The mapped register list in the Web page is only readable and cannot be written. It is used to display the current
value of the register in the mapping area, which is convenient for user debugging. There are 300 registers for the
Bit Type register, used to store one bit can represent the state of the data, e.g.: input coil, holding coil value. 300
registers for the 16-bit type register, used to store input register and holding register data. 300 BIT-bit registers
(Boolean) and 300 16-bit register mapping areas are provided. (Those 300 register can be 16-bit, 32-bit or 64-bit,
This device supports the system log function, which is convenient for users to analyze the operation of the device.
The Record types includes below:
Normal power on, nth boot.
Caused by hardware failure, nth boot
Caused by memory failure, nth boot
Caused by CPU bus failure, nth boot
Caused by command failure, nth boot
Factory data restart, nth boot
Server mode connection request, allow connection
Server mode connection request, exceeding the number of connections, forbidden to connect
Server mode, close connection received
Server mode, no data for a long time, close the connection
Client mode, successful connection to the server
Client mode, the server closes the connection
Client mode, no data for 10 minutes disconnect
Client mode, data transmission error, disconnection
Client mode, receiving disconnected packets
Client mode, 3 failed connections
Ethernet slave mode, successfully connected to the server
Ethernet slave mode, the server closes the connection
8. Modbus Protocol
This Table corresponds to all MxxxT series models, some of the models do not exist in
Notice the corresponding channel then its register address is empty. For example, if DIN1 and
DIN2 are available for M100T, the DIN3 to DIN16 registers are empty.
(Function Code 1: Read Coil, Function Code 5: Write Single Coil, Function Code 15: Write multi Coils.)
Read and Write Holding Coil (Function Code 1, Function Code, Function Code 15.)
Modbus
PLC or configuration use
register
Channel address Data Type Description
address
(Decimal )
(Decimal )
RTD 2 ADC 1 30002 16 Bit int RTD2 ADC Value, Read Only.
RTD 3 ADC 2 30003 16 Bit int RTD3 ADC Value, Read Only.
RTD 5 ADC 4 30005 16 Bit int RTD5 ADC Value, Read Only.
RTD 6 ADC 5 30006 16 Bit int RTD6 ADC Value, Read Only.
RTD 7 ADC 6 30007 16 Bit int RTD7 ADC Value, Read Only.
RTD 8 ADC 7 30008 16 Bit int RTD8 ADC Value, Read Only.
After converted RTD1 Value, Read
Only.
RTD1 Temp 8 30009 16 Bit int
Real value= Current value stored in
register/10.
RTD2 ADC Value, Read Only.
RTD 2 Temp 9 30010 16 Bit int Real value= Current value stored in
register/10.
RTD3 ADC Value, Read Only.
RTD 3 Temp 10 30011 16 Bit int Real value= Current value stored in
register/10.
RTD4 ADC Value, Read Only.
RTD 4 Temp 11 30012 16 Bit int Real value= Current value stored in
register/10.
RTD5 ADC Value, Read Only.
RTD 5 Temp 12 30013 16 Bit int Real value= Current value stored in
register/10.
RTD6 ADC Value, Read Only.
RTD 6 Temp 13 30014 16 Bit int Real value= Current value stored in
register/10.
RTD7 ADC Value, Read Only.
RTD 7 Temp 14 30015 16 Bit int Real value= Current value stored in
register/10.
RTD8 ADC Value, Read Only.
RTD 8 Temp 15 30016 16 Bit int Real value= Current value stored in
register/10.
Reserved 16~25 30017~30026 16 Bit unsigned Reserved
This Table corresponds to all MxxT series models, some of the models do not exist in the
Notice corresponding channel then its register address is empty. For example, only AIN1 and
AIN2 are available for M100T, the AIN3 to AIN8 registers are empty.
Read and Write Holding Register (Function Code 3,Function Code 6, Function Code 16)
PLC or
Register
configuration
Channel Address Data Type Description
use address
(Decimal)
(Decimal)
16 Bit AO1/AO2 output value, resolution 12bits,
AO 1 0 40001 unsigned Range = 0 - 4095 corresponds to output
16 Bit voltage 0-10V, Maximum loading is 1
AO 2 1 40002 unsigned Ampere.
DIN1 Pulse 0= Falling, 1=Rising, can be changed in
16 Bit
2 40003 unsigned
operation, after opto-coupler isolation will
Counter Trigger become low level trigger.
Counting does not affect the normal input,
3(High) 40004(High) DIN1 high-speed mode pulse frequency up
32 Bit
to 700KHz, low-speed mode the frequency
DIN1 Pulse Counter unsigned
up to 10KHz. Can change the High-speed
4(Low) 40005(Low) ABCD
or low-speed by internal switch. Default is
high-speed mode.
5(High) 40006(High) 32 Bit
DO1 Pulse Counter unsigned Read Only, automatically clear the value.
6(Low) 40007(Low) ABCD
DO1 Pulse 1-30000, unit:10Hz, means the DO1
16 Bit
7 40008 unsigned
output frequency range is 10Hz-300KHz.
Frequency Can be changed in operation.
Range=10-90, stands for pulse Duty Ration
DO1 Pulse 16 Bit is 10%-90%. Cannot be 0% and 100%. Can
8 40009 unsigned be changed in operation. Recommend set
Duty Ration
as 20% while driving the motor.
DO2 Pulse =1 stands for output high level, =0stands
16 Bit
9 40010 unsigned
for output low level. Can be changed in
Output Direction operation.
DIN3 pulse count 15(High) 40016(High) 32 Bit The anti-shake time can be set from 1 to
(Function Code 1: Read Coil, Function Code 5: Write Single Coil, Function Code 15: Write multi Coils.)
Transit BIT Register Address (Function Code 1, Function Code 5, Function Code 15.)
(Function Code 3: Read Holding Register, Function Code 6: Write single Holding Register, Function Code 16: Write
multi Holding Registers)
Transit 16-Bit Register Address(Function Code 3:, Function Code 6, Function Code 16)
For example:MXXXT device 485 is used as a slave, we can use other host software or host device to read (or
write commands) the value of the data point of the local device. Moreover, the network port of the device can also
be used as a master, adding other slaves to the mapping register through the Modbus TCP protocol.
Example: Query 16 DIN data of this device at the same time, then:
Server send: 01 02 00 00 00 10 79 C6
01= Device address;
02= Query DIN status command;
00 00=DIN starting address;
00 10 = Continuously read 16 DIN states;
BD D9= CRC verify.
Device answer: 01 02 02 03 90 B9 24
01= Device address;
02= Query DIN status command;
02= Return Byte Length;
03 90= DIN status, each bit represents a DIN status, 0 represents open, 1 represents closed; the first byte 03H
is converted into binary: 0000 0011, corresponding to DIN1-DIN8 status from low to high; the second byte
90H is converted into binary: 1001 0000, corresponding to
DIN8 DIN7 DIN6 DIN5 DIN4 DIN3 DIN2 DIN1
0 0 0 0 0 0 1 1
open open open open open open closed closed
DIN16 DIN15 DIN14 DIN13 DIN12 DIN11 DIN10 DIN9
1 0 0 1 0 0 0 0
closed open open closed open open open open
B9 24 =CRC verify.
If you want to query certain DIN statuses, you only need to change the "register starting address" and "read
register number", recalculate the CRC check, and the returned data is analyzed as described above.
Example: At the same time query the 16 DO status of this device, the device address is 1,then:
Server send: 01 01 00 00 00 10 3D C6
01= Device address;
01= Read DO function code;
00 00=DO register starting address;
00 10 = Read 16 DO data continuously;
3D C6 = CRC verify.
Device answer: 01 01 02 05 C3 FA FD
01= Device address;
01= Read DO function code;
02= Return Byte Length;
05 C3= The returned DO status data, each bit represents a DO status, 0 represents open, 1 represents closed;
the first byte 05H is converted into binary: 0000 0101, corresponding to DO1-DO8 status from low to high;
second The byte C3H converted into binary is: 1100 0011, corresponding to the state of DO9-DO16 from low
to high. The details are as follows;
DO8 DO7 DO6 DO5 DO4 DO3 DO2 DO1
0 0 0 0 0 1 0 1
open open open open open closed open closed
DO16 DO15 DO14 DO13 DO12 DO11 DO10 DO9
1 1 0 0 0 0 1 1
closed closed open open open open closed closed
FA FD = CRC verify.
If you want to read the state of a certain DO or certain DO states, you only need to modify the "register starting
address" and "read register quantity", and then recalculate the CRC check. The returned data is analyzed as
described above..
5D 0F = CRC verify.
Device answer: 01 0F 00 00 00 10 54 07
01= Device address;
05= Write a single holding coil;
00 00= DO1 register starting address;
00 10 = 16 DO performed actions.
54 07 = CRC verify.
46 A0 = CRC verify.
If you want to read certain input registers, you only need to modify the "register starting address" and "read
register quantity", and then recalculate the CRC check. The returned data is analyzed as described above.
B3 E6 = CRC verify.
Device answer: 01 10 00 00 00 02 41 C8
01= Device address;
10= Write multiple holding registers;
00 00= AO1 register starting address;
00 02 = 2 AO executed data.
41 C8 = CRC verify.
The platform can access the slave device by accessing the mapped address of the local device through the
Modbus protocol. The correspondence between the mapped address and the slave device address needs to be
configured through the Modbus master configuration page.
Example: starting from address 100, read the value of 10 Bit mapping data,then:
Server send: 01 01 00 64 00 0A FD D2
01= Device address;
01= Read hold coil;
00 64=Read data starting from the starting address 100;
00 0A = Continuously read 10 bit status;
FD D2 = CRC verify.
Device answer:01 01 02 73 01 5D 0C
01= Device address;
01= Read hold coil;
02= Return Byte Length;
73 01= The returned DO status data, each bit represents a DO status, 0 represents open, 1 represents closed;
the first byte 05H is converted into binary: 0000 0101, corresponding to DO1-DO8 status from low to high; second
The byte C3H converted into binary is: 1100 0011, corresponding to the state of DO9-DO16 from low to high;
Register map address invalid invalid invalid invalid invalid invalid 109 108
value 0 0 0 0 0 0 0 1
Register map address 107 106 105 104 103 102 101 100
value 0 1 1 1 0 0 1 1
Address values higher than 10 bits are considered invalid values.
5D 0C = CRC verify.
If you want to control the status of the holding coil connected to the slave, you must configure the instruction
mapping for adding slave 01 function code. After the mapping address value is changed, the corresponding slave
address data will be written.
Master Send Data Format:
Data
Content Bytes Description
(H: HEX)
Device Address 1 01H 01H Device, Range: 1-247, according to setting address
Function Code 1 05H Write a single holding coil, use function code 05
Bit register starting Initial addressFor address correspondence, please refer
2 00 64H
address to the mapping register address
This value is: FF 00H or 00 00H, FF 00H means written 1,
Value written 2 FF 00H
00 00H means written 0.
16 CRC Verify 2 CD E5H CRC0 CRC1 low byte in front, high behind
Example: Rewrite the state value of Bit mapping address 100, rewritten to 1, then:
Server send: 01 05 00 64 FF 00 CD E5
01= Device address;
05= Write a single holding coil;
00 64=Mapped address to be written;
FF 00 = written 1;
8D EE = 16 Bit CRC verify.
Device answer: 01 05 00 64 FF 00 CD E5
01= Device address;
05= Write a single holding coil;
00 64= Mapped address to be written;
FF 00 = written 1.
8D EE = 16 Bit CRC verify.
If you need to rewrite more than one, please read Modbus protocol 15 function code.
Example:The mapping address startings from 100, and the data of 10 addresses is read, then:
Server send: 01 03 00 64 00 0A 84 12
01= Device address;
03= Read holding register;
00 64=The starting address of the mapping register, the current decimal number is 100;
00 0A = Read 10 register values;
84 12 = 16 Bit CRC verify.
Device answer: 01 03 14 00 14 00 1E 00 28 00 32 00 4B 00 41 00 0A 00 25 00 14 00 2A FB 34
01= Device address;
03= Read holding register;
14= Returns 20 bytes;
00 14 00 1E 00 28 00 32 00 4B 00 41 00 0A 00 25 00 14 00 2A=The returned data is detailed in the following
table:
Mapping
register 100 101 102 103 104 105 106 107 108 109
address
Hexadecim
00 14 00 1E 00 28 00 32 00 4B 00 41 00 0A 00 25 00 14 00 2A
al value
Decimal
20 30 40 50 75 65 10 37 20 42
value
FB 34 = CRC verify.
If you want to write the data of the connected slave, you must configure the instruction mapping for adding slave
03 function code. After the mapping address value is changed, the corresponding slave address data will be
written.
If the data type of the mapped slave at the mapped address 101 is signed integer, the order is AB.
Because the register address 100 is occupied by the data point of the added slave. We need to create a 101 slave to
execute the write command.
Master Send Data Format:
Data
Content Bytes Description
(H: HEX)
Device Address 1 01H 01H Device, Range: 1-247, according to setting address
Function Code 1 06H Write a single holding register, function code 06
Mapping register For address correspondence, please refer to the
2 00 65H
starting address mapping register address
Example: If the data type of the mapped address 20001 and the mapped slave is a signed integer, sorting AB,
rewrite the mapped address 20001 register to 100 then, then:
Server send: 01 06 00 65 00 64 98 3E
01= Device address;
06= Write command function code;
00 65=Write address 101 register value;
00 64 = Write the decimal value 100;
98 3E = CRC verify.
Device answer: 01 06 00 65 00 64 98 3E
01= Device address;
06= Write command function code;
00 65= Write address 101 register value;
00 64 =Has been rewritten to the decimal value 100.
98 3E = CRC verify.
If you need to write multiple data type mapping addresses, please read Modbus protocol 16 function code.
9. Warranty
1) This module is warranted to be free of defects in material and workmanship for one year.
2) This warranty does not extend to any defect, malfunction or failure caused by abuse or misuse by the
Operating Instructions. In no event shall the manufacturer be liable for any module altered by purchasers
The End!
Any questions please help to contact us feel free.
Introduction to mqtt
MQTT is a client-server based message publish/subscribe transfer protocol. The MQTT protocol is
lightweight,simple, open, and easy to implement. These characteristics make it applicable to a wide range. In many
cases,including restricted environments, such as: machine-to-machine (M2M) communication and Internet ofThings
(IoT). It has been widely used in communication sensors via satellite links, occasionally dialed medicaldevices,
smart homes, and some miniaturized devices. The MQTT protocol runs on TCP/IP or other network
protocols and provides orderly, lossless, bidirectional connections.
After the configuration is completed, the client will initiate a connection to the server:
Connect: the client sends a connect message request to the server;
Connack: the server responds to a connack confirmation message, indicating that the connection is successful;
After the client establishes a connection, it is a long connection, and the client can publish or subscribe messages on
the server;
Take devices and customers' mobile phones as clients
After the device publishes the topic on the proxy server, customers can view the data through
[Link] is, the device is the publisher, and the customer's mobile phone is the subscriber.
Similarly, users can control the device by publishing topics through the mqtt [Link] is, the user is the
publisher and the device is the subscriber.
}
Note:
Read / write identifier: the character is "flag", followed by "read / write ID representing IO data point"
Time identification: the character is "time", followed by "specific reporting time stamp"
Alarm and recovery identification: the character is "state", followed by "alarm" or "recovery" (alarm
{
"sensorDatas":
[
{
"sensorsId": 211267, //Platform sensor ID
"switcher":1, //Data type and value
"flag":"DO1" //Read write identification
}
],
"down":"down" Platform downlink message identification
}
Note:
Platform sensor ID: character is "sensorid", followed by ID number (ID is automatically generated by platform)
Read / write identifier: the character is "flag", followed by "read / write ID representing IO data point"
Platform downlink message identification: the character is "down", followed by "down", which means that
this is the platform downlink data.