Description of Modbus RTU Communication Protocol for Xinjie Human Machine Interface

freeFree Technical Resource

This content is free to read, suitable for basic learning and search traffic.

Description of Modbus RTU Communication Protocol for Xinjie Human Machine Interface

Modbus-RTUfunction code

0X4800~0X4807: PLC Y0~Y7 0X4810 : PLC Y10

Testing equipment: Xinjie PLC ;                                                               

PLC The internal software component number and Modbus-RTU Please refer to Xinjie for the address number PLC Modbus Communication function chapter.

Modbus Functional code:

Function code(16 Base system)Function
01Read multiple bits
03Read multiple registers
05Write a single bit
06Write a single register
0FWrite multiple digits
10Write multiple registers

Communication format: Baud rate 19200, Occasional verification(EVEN), Data bits 8 Position,  Stop position 1 Position.

Note The following test addresses are all hexadecimal addresses: The actual operation requires converting the hexadecimal address to ten, Input the base address into the touch screen Function code.

1.    01 Read multiple coil positions for operation:  For example

Read the coil: The status of the position 0X4800~0X4815 Send commands.

0X4800~0X4807: PLC Y0~Y7       0X4808~0X4815: PLC Y10~Y17

Action: 01 01 48 00 00 10 2A 66

Equipment numberFunction code (1 Byte)Starting address (1 Byte)high position  Starting address(1 Byte)Low level  High total digits(1 Byte)Low total digits(1 Byte)send out(1 Byte)CRC(1 Byte) (1 Byte)
Return command0101480000102A66

Action: 01 01 02 00 00 B9 FC

Equipment numberFunction code (1 Byte)Byte count (1 Byte)Position status (2 Byte)Position status  (On/Off)return  (On/Off)CRC(1 Byte) (1 Byte)
return ON010102FF03B80D
Function code Off0101020000B9FC

2.    03 Read multiple words operation:  Data display(For example)

Read:The data 4X00~4X02 Send commands.

4X000~4X003 : PLC D0~D2

4X00 = 4, 4X01= 5, 4X001= 1, 4X02= 2

Action:  01 03 00 00 00 04 44 09

Device numberDevice number (1 Byte)Function code (1 Byte)Starting address  high position(1 Byte)Starting address  Low level(1 Byte)High total digits(1 Byte)Low total digits (1 Byte)CRC(1 Byte) (1 Byte)
send out0103000000044409

Send commands: 01 03 08 00 04 00 05 00 01 00 02 CC 16

ActionEquipment number(1 Byte)Function code(1 Byte)Byte count (1Byte)Sending Memory High value 4X00Sending Memory Low value 4X00Register value high position    4X01Register value Low level    4X01Sending Memory High value 4X02Sending Memory Low value 4X02
return010308000400050001
      Register value high position    4X023Register value Low level    4X023CRC 
      0002CC16

3.    05 Function code:  Write single bit operations(Button)

For example:  Place ON 0X4800

0X4800 : PLC Y0

Send commands: 01 05 48 00 FF 00 9B 9A

ActionEquipment number(1 Byte)Function code(1 Byte)The starting address is high Position(1 Byte)The starting address is low Position(1 Byte)Total digits High Position (1 Byte)Total digits Low Position (1 Byte)CRC(1Byte)(1Byte)
send out01054800FF009B9A

Return command: 01 05 48 00 FF 00 9B 9A

ActionEquipment number(1 Byte)Function code(1 Byte)Starting address high bit(1 Byte)Low order starting address(1 Byte)High total digits(1 Byte)Low total digits(1 Byte)CRC(1 Byte)(1 Byte)
return01054800FF009B9A

For example: Place OFF    0X4800

0X4800 : PLC Y0

Send commands: 01 05 48 00 00 00 DA 6A

ActionEquipment number (1 Byte)Function code (1 Byte)Starting address  high position(1 Byte)Starting address  Low level(1 Byte)High total digits (1 Byte)Low total digits (1 Byte)CRC(1 Byte)(1 Byte)
send out010548000000DA6A

Return command: 01 05 48 00 00 00 DA 6A

ActionEquipment number (1 Byte)Function code (1 Byte)Starting address  high position(1 Byte)Starting address  Low level(1 Byte)High total digits (1 Byte)Low total digits (1 Byte)CRC(1 Byte) (1 Byte)
return010548000000DA6A

4.    06 Function code:  Write a single word operation

For example:  Address 4X00 Write data 8

4X00 : PLC D0

Send commands: 01 06 00 00 00 08 88 0C

ActionEquipment number (1 Byte)Function code(1 Byte)Starting address high position(1 Byte)Starting address Low level(1 Byte)Register value high position(1 Byte)Register value Low level(1 Byte)CRC     (1 Byte) (1 Byte)
send out010600000008880C

Return command: 01 06 00 00 00 08 88 0C

ActionEquipment number (1 Byte)Function code(1 Byte)Starting address high position(1 Byte)Starting address Low level(1 Byte)Register value high position(1 Byte)Register value Low level(1 Byte)CRC     (1 Byte) (1 Byte)
return010600000008880C

5.    10 Function code:  Write multiple words operation(Write two characters for data input Dword)

For example:  Provide addresses separately 4X00 Write data 10, 4X01 Write data 11, 4X02 Write data 12

4X00~4X02 : PLC D0~D2

Send commands: 01 10 00 00 00 03 06 00 0A 00 0B 00 0C 0F 46

ActionEquipment number(1Function Code(1Starting address high position(1 Byte)Starting address Low level(1 Byte)Register  High total number (1 Byte)Register  Low total count (1 Byte)Register  Total number of bytes (1 Byte)Register High valueRegister value Low level(1 Byte)
 Byte)Byte)     (1Byte) 
send out01100000000306000A
    Register value high position(1 Byte)Register value Low level(1 Byte)Register value high position(1 Byte)Register value Low level(1 Byte)CRC 
    000B000C0F46

Return command:  01 10 00 00 00 03 80 08

ActionEquipment number(1 Byte)Function code(1 Byte)Starting address high bit(1 Byte)Low order starting address(1 Byte)The total number of registers is high(1 Byte)Low total number of registers(1 Byte)CRC(1 Byte) (1 Byte)
send out0110000000038008

6.    0F Function code:  Write multiple bit operations

For example:  Place ON 0X4800~0X4803

0X4800~0X4807: PLC Y0~Y7 0X4810 : PLC Y10

Send commands: 01 0F 48 00 00 09 02 FF 01 AD 48

ActionEquipment number (1 Byte)Function code (1 Byte)Starting address high position(1 Byte)Starting address Low level(1 Byte)Total number of positions high position  (1 Byte)Total number of positions low position  (1 Byte)Total mailing location Byte count (1 Byte)The value of a position Low level  (1Byte)The value of a position high position  (1Byte)
Sending data010F4800000902FF01
        CRC 
        AD48

Return command: 01 0F 48 00 00 09 82 6D

ActionEquipment number (1 Byte)Function code (1 Byte)Starting address high bit (1 Byte)Low order starting address (1 Byte)High total number of bits(1 Byte)Low total number of bits(1 Byte)CRC 
Return010F48000009826D
Related Tags
Put this resource to use in a real project?

Go to the Tool Center for message parsing, CRC verification and device debugging, or submit your requirements for selection and integration advice.

Engineer Membership

Turn this article into actionable debugging resources

After activation, you can use advanced message parsing, resource pack downloads, code examples, engineering cases and priority technical support, suitable for real project delivery.

Unlimited Advanced Tools
Resource & Code Packs
Complete Engineering Case Library
Priority Technical Support

Leave a Reply

Your email address will not be published. Required fields are marked *.