Modbus-RTUfunction code
0X4800~0X4807: PLC Y0~Y7 0X4810 : PLC Y10
Testing equipment: Xinjie PLC ;
PLC The internal software component number and Modbus-RTU Please refer to Xinjie for the address number PLC Modbus Communication function chapter.
Modbus Functional code:
| Function code(16 Base system) | Function |
| 01 | Read multiple bits |
| 03 | Read multiple registers |
| 05 | Write a single bit |
| 06 | Write a single register |
| 0F | Write multiple digits |
| 10 | Write multiple registers |
Communication format: Baud rate 19200, Occasional verification(EVEN), Data bits 8 Position, Stop position 1 Position.
Note The following test addresses are all hexadecimal addresses: The actual operation requires converting the hexadecimal address to ten, Input the base address into the touch screen Function code.
1. 01 Read multiple coil positions for operation: For example
Read the coil: The status of the position 0X4800~0X4815 Send commands.
0X4800~0X4807: PLC Y0~Y7 0X4808~0X4815: PLC Y10~Y17
Action: 01 01 48 00 00 10 2A 66
| Equipment number | Function code (1 Byte) | Starting address (1 Byte) | high position Starting address(1 Byte) | Low level High total digits(1 Byte) | Low total digits(1 Byte) | send out(1 Byte) | CRC(1 Byte) | (1 Byte) |
| Return command | 01 | 01 | 48 | 00 | 00 | 10 | 2A | 66 |
Action: 01 01 02 00 00 B9 FC
| Equipment number | Function code (1 Byte) | Byte count (1 Byte) | Position status (2 Byte) | Position status (On/Off) | return (On/Off) | CRC(1 Byte) | (1 Byte) |
| return ON | 01 | 01 | 02 | FF | 03 | B8 | 0D |
| Function code Off | 01 | 01 | 02 | 00 | 00 | B9 | FC |
2. 03 Read multiple words operation: Data display(For example)
Read:The data 4X00~4X02 Send commands.
4X000~4X003 : PLC D0~D2
4X00 = 4, 4X01= 5, 4X001= 1, 4X02= 2
Action: 01 03 00 00 00 04 44 09
| Device number | Device number (1 Byte) | Function code (1 Byte) | Starting address high position(1 Byte) | Starting address Low level(1 Byte) | High total digits(1 Byte) | Low total digits (1 Byte) | CRC(1 Byte) | (1 Byte) |
| send out | 01 | 03 | 00 | 00 | 00 | 04 | 44 | 09 |
Send commands: 01 03 08 00 04 00 05 00 01 00 02 CC 16
| Action | Equipment number(1 Byte) | Function code(1 Byte) | Byte count (1Byte) | Sending Memory High value 4X00 | Sending Memory Low value 4X00 | Register value high position 4X01 | Register value Low level 4X01 | Sending Memory High value 4X02 | Sending Memory Low value 4X02 |
| return | 01 | 03 | 08 | 00 | 04 | 00 | 05 | 00 | 01 |
| Register value high position 4X023 | Register value Low level 4X023 | CRC | |||||||
| 00 | 02 | CC | 16 |
3. 05 Function code: Write single bit operations(Button)
For example: Place ON 0X4800
0X4800 : PLC Y0
Send commands: 01 05 48 00 FF 00 9B 9A
| Action | Equipment number(1 Byte) | Function code(1 Byte) | The starting address is high Position(1 Byte) | The starting address is low Position(1 Byte) | Total digits High Position (1 Byte) | Total digits Low Position (1 Byte) | CRC(1Byte) | (1Byte) |
| send out | 01 | 05 | 48 | 00 | FF | 00 | 9B | 9A |
Return command: 01 05 48 00 FF 00 9B 9A
| Action | Equipment number(1 Byte) | Function code(1 Byte) | Starting address high bit(1 Byte) | Low order starting address(1 Byte) | High total digits(1 Byte) | Low total digits(1 Byte) | CRC(1 Byte) | (1 Byte) |
| return | 01 | 05 | 48 | 00 | FF | 00 | 9B | 9A |
For example: Place OFF 0X4800
0X4800 : PLC Y0
Send commands: 01 05 48 00 00 00 DA 6A
| Action | Equipment number (1 Byte) | Function code (1 Byte) | Starting address high position(1 Byte) | Starting address Low level(1 Byte) | High total digits (1 Byte) | Low total digits (1 Byte) | CRC(1 Byte) | (1 Byte) |
| send out | 01 | 05 | 48 | 00 | 00 | 00 | DA | 6A |
Return command: 01 05 48 00 00 00 DA 6A
| Action | Equipment number (1 Byte) | Function code (1 Byte) | Starting address high position(1 Byte) | Starting address Low level(1 Byte) | High total digits (1 Byte) | Low total digits (1 Byte) | CRC(1 Byte) | (1 Byte) |
| return | 01 | 05 | 48 | 00 | 00 | 00 | DA | 6A |
4. 06 Function code: Write a single word operation
For example: Address 4X00 Write data 8
4X00 : PLC D0
Send commands: 01 06 00 00 00 08 88 0C
| Action | Equipment number (1 Byte) | Function code(1 Byte) | Starting address high position(1 Byte) | Starting address Low level(1 Byte) | Register value high position(1 Byte) | Register value Low level(1 Byte) | CRC (1 Byte) | (1 Byte) |
| send out | 01 | 06 | 00 | 00 | 00 | 08 | 88 | 0C |
Return command: 01 06 00 00 00 08 88 0C
| Action | Equipment number (1 Byte) | Function code(1 Byte) | Starting address high position(1 Byte) | Starting address Low level(1 Byte) | Register value high position(1 Byte) | Register value Low level(1 Byte) | CRC (1 Byte) | (1 Byte) |
| return | 01 | 06 | 00 | 00 | 00 | 08 | 88 | 0C |
5. 10 Function code: Write multiple words operation(Write two characters for data input Dword)
For example: Provide addresses separately 4X00 Write data 10, 4X01 Write data 11, 4X02 Write data 12
4X00~4X02 : PLC D0~D2
Send commands: 01 10 00 00 00 03 06 00 0A 00 0B 00 0C 0F 46
| Action | Equipment number(1 | Function Code(1 | Starting address high position(1 Byte) | Starting address Low level(1 Byte) | Register High total number (1 Byte) | Register Low total count (1 Byte) | Register Total number of bytes (1 Byte) | Register High value | Register value Low level(1 Byte) |
| Byte) | Byte) | (1Byte) | |||||||
| send out | 01 | 10 | 00 | 00 | 00 | 03 | 06 | 00 | 0A |
| Register value high position(1 Byte) | Register value Low level(1 Byte) | Register value high position(1 Byte) | Register value Low level(1 Byte) | CRC | |||||
| 00 | 0B | 00 | 0C | 0F | 46 |
Return command: 01 10 00 00 00 03 80 08
| Action | Equipment number(1 Byte) | Function code(1 Byte) | Starting address high bit(1 Byte) | Low order starting address(1 Byte) | The total number of registers is high(1 Byte) | Low total number of registers(1 Byte) | CRC(1 Byte) | (1 Byte) |
| send out | 01 | 10 | 00 | 00 | 00 | 03 | 80 | 08 |
6. 0F Function code: Write multiple bit operations
For example: Place ON 0X4800~0X4803
0X4800~0X4807: PLC Y0~Y7 0X4810 : PLC Y10
Send commands: 01 0F 48 00 00 09 02 FF 01 AD 48
| Action | Equipment number (1 Byte) | Function code (1 Byte) | Starting address high position(1 Byte) | Starting address Low level(1 Byte) | Total number of positions high position (1 Byte) | Total number of positions low position (1 Byte) | Total mailing location Byte count (1 Byte) | The value of a position Low level (1Byte) | The value of a position high position (1Byte) |
| Sending data | 01 | 0F | 48 | 00 | 00 | 09 | 02 | FF | 01 |
| CRC | |||||||||
| AD | 48 |
Return command: 01 0F 48 00 00 09 82 6D
| Action | Equipment number (1 Byte) | Function code (1 Byte) | Starting address high bit (1 Byte) | Low order starting address (1 Byte) | High total number of bits(1 Byte) | Low total number of bits(1 Byte) | CRC | |
| Return | 01 | 0F | 48 | 00 | 00 | 09 | 82 | 6D |
Leave a Reply