A must-have tool for Modbus engineers! RTU/TCP/ASCII message generation parser, efficiency increased by 10 times

freeFree Technical Resource

This content is free to read, suitable for basic learning and search traffic.

A must-have tool for Modbus engineers! RTU/TCP/ASCII message generation parser, efficiency increased by 10 times

A must-have tool for Modbus engineers! RTU/TCP/ASCII message generation parser, efficiency increased by 10 times

Byte order of 32-bit data (UINT32/INT32/FLOAT):


preface: Modbus The pain of debugging, Engineers understand

I did it 20 Annual industrial automation, Too familiar Modbus The pain of debugging.

Do you also frequently encounter these situations?

Scene 1: Manually calculate the message, Easy to make mistakes

To read and hold the register, Slave station address 01, Starting address 40001, quantity One 10 You use a calculator to calculate
Slave station address:

  • Function code: 01
  • Starting address: 03
  • wait: 00 00 (40001-1=40000=0x9C40, incorrect, quantity Verification...)
  • Calculate half: 00 0A
  • CRC The customer called: ? ? ?

I forgot where I counted when I came back, Recalculate, The calculation is incorrect
Calculate again, CRC Still not right
Scene, Received message...

Not able to parse 2: Equipment return, You stare

This is the function code: 01 03 14 00 0A 00 0B 00 0C 00 0D 00 0E xx xx
The response:

  • It is the number of bytes 03 Byte
  • 14 But what is the value of each register (20 The byte order is)
  • Still?
  • Scene AB Three protocols BA?

Confused 3: Use, Verification

  • RTU Use CRC Verification
  • ASCII have Head LRC Urgent
  • TCP Use MBAP The method of analysis

Message, No matter what, it doesn't match RTU Scene TCP Debugging records, cannot find

Scene 4: Debugging log, cannot find

The message that was adjusted yesterday, I couldn't find it today
Ask colleagues for it, My colleague said, 'I forgot too"
recalculated, spent hours 1 these pain points

I know all of them, so, I developed this.

message generation parser, it supports Modbus three protocols.

automatically generates request/response messages RTU/TCP/ASCII no need to manually calculate, no need to remember formulas.

just a few clicks to generate, one, core function.


why engineers always say good, all three protocols are covered: support?

1.1 three transmission modes

protocol Modbus verification method:

frame formatapplicable scenariosbinaryserial communication
Modbus RTUCRC16textold devices/modems (RS485/RS232)
Modbus ASCIILRCASCII no verificationguarantee
Modbus TCPheader (TCP Ethernet communication) MBAP one tool +ADUhandles everything

debugging scenarios, request command generator Modbus function description.


1.2 support

function code:

① function code 12 name

purposeRead coil statusRead switch output
01Read discrete inputRead switch input
02Read hold registerMost commonly used
03Analog outputRead input register (Read only)
04Analog inputWrite a single coil (Switch control)
05Write a single registerParameter Settings
06Write a single registerParameter Settings
0FWrite multiple coilsBatch switch control
10Write multiple registersBatch parameter setting
17Read/write multiple registersSimultaneously read and write
2BRead device identificationEquipment information query

② Parameter configuration

Using function codes 03 (Read and hold registers) For example:

从站地址:01(0-247)
功能码:03
起始地址:0000(十六进制或十进制)
数量:0010(读取 10 个寄存器)

③ Automatically generate messages

After inputting the parameters, Automatically generated:

RTU pattern:

01 03 00 00 00 0A C4 0B
│  │  │  │  │  │  │  │
│  │  │  │  │  │  │  └─ CRC 低字节
│  │  │  │  │  │  └──── CRC 高字节
│  │  │  │  │  └─────── 数量低字节
│  │  │  │  └────────── 数量高字节
│  │  │  └───────────── 起始地址低字节
│  │  └──────────────── 起始地址高字节
│  └─────────────────── 功能码
└────────────────────── 从站地址

ASCII pattern:

:01030000000AFB
│            │  │
│            │  └── LRC 校验(FB)
│            └───── 数据部分(ASCII 编码)
└────────────────── 起始符(:)

TCP pattern:

00 01 00 00 00 06 01 03 00 00 00 0A
│  │  │  │  │  │  │  │  │  │  │  │
│  │  │  │  │  │  │  │  │  │  │  └─ 数量低字节
│  │  │  │  │  │  │  │  │  └─────── 数量高字节
│  │  │  │  │  │  │  │  └────────── 起始地址低字节
│  │  │  │  │  │  │  └───────────── 起始地址高字节
│  │  │  │  │  │  └──────────────── 功能码
│  │  │  │  │  │  └──────────────── 单元标识符(从站地址)
│  │  │  │  │  └─────────────────── 长度(后续字节数)
│  │  │  │  └────────────────────── 协议标识符(0=Modbus)
│  │  │  └───────────────────────── 事务标识符低字节
│  │  └──────────────────────────── 事务标识符高字节
└─────────────────────────────────── MBAP 头(7 字节)

④ Support for special function codes

Function code 05 (Write a single coil) :

  • Switch selection: Open it (ON) / close (OFF)
  • Automatic conversion to FF00/0000

Function code 0F (Write multiple coils) :

  • Number of coils input
  • Visual coil selection (Dot button)
  • Click to switch states (Grey=OFF, Blue=ON)
  • Automatically calculate byte count

Function code 10 (Write multiple registers) :

  • Register list (Multiple can be added)
  • Each register setting:
    • Address (Automatic calculation)
    • Data type (UINT16/INT16/UINT32/INT32/FLOAT)
    • Byte order (AB/BA)
    • Numerical value (Decimal input)
  • Automatically convert to register values

1.3 Response message generator

Function description:

① Simulate device response

Used for testing upper computer software (Like Kingview, WinCC) Or PLC Program.

② Support normal response and abnormal response

Normal response (Function code 03) :

从站地址:01
功能码:03
字节数:20(10 个寄存器×2)
寄存器值:
  - Reg 0: 10(0x000A)
  - Reg 1: 20(0x0014)
  - Reg 2: 30(0x001E)
  - ...

Abnormal response:

从站地址:01
功能码:83(03+80)
异常码:
  - 01:非法功能
  - 02:非法数据地址
  - 03:非法数据值
  - 04:从站设备故障
  - 05:认可
  - 06:从属设备忙

③ Data type support

Support multiple data types, automatic conversion:

TypeByte countRangeByte order
UINT1620-65535Fixed
INT162-32768~32767Fixed
UINT3240-4294967295AB/BA
INT324-2147483648~2147483647AB/BA
FLOAT4IEEE 754 Single precisionAB/BA/CDAB/BADC

Example:

Enter decimal value: 25.5 (FLOAT Type)

Automatically convert to register values:

  • Reg 0: 0x41CC (High 16 Position)
  • Reg 1: 0x0000 (Low 16 Position)

1.4 Message parser

Function description:

① Paste message, Automatic parsing

Received the message returned by the device, Paste it in, Automatic parsing:

Input (RTU pattern) :

01 03 14 00 0A 00 0B 00 0C 00 0D 00 0E 7A 3B

Automatic parsing:

┌─────────────────────────────────────┐
│ 从站地址:01                        │
│ 功能码:03(读保持寄存器)          │
│ 字节数:20(0x14)                  │
│ 数据内容:                          │
│   Reg 0: 0x000A = 10                │
│   Reg 1: 0x000B = 11                │
│   Reg 2: 0x000C = 12                │
│   Reg 3: 0x000D = 13                │
│   Reg 4: 0x000E = 14                │
│ CRC 校验:7A3B ✓(正确)            │
└─────────────────────────────────────┘

② Support three types of protocol parsing

  • RTU: CRC16 Verification
  • ASCII: LRC Verification
  • TCP: MBAP Head analysis

③ Error detection

  • CRC/LRC Verification error prompt
  • Reminder for abnormal message length
  • Illegal function code warning

1.5 Historical records

Function description:

① Automatic saving

Automatically save each generated message, contain:

  • Message content
  • Generation time
  • Message type (Request/Response)

② Quick operation

  • Copy: One click copying of messages
  • WeChat sharing: Send to colleagues
  • Clearing: Clear historical records

③ Classification management

  • Request command history
  • Response message history
  • Separate management, Clear and concise

1.6 Visualization of message structure

Function description:

Each message generated, All come with structural analysis:

Example (RTU Request) :

┌─────────────────────────────────────┐
│ 报文结构解析                        │
├─────────────────────────────────────┤
│ 从站地址 (Slave Address): 01        │
│ 功能码 (Function Code): 03          │
│ 起始地址 (Start Address): 0000      │
│ 数量 (Quantity): 000A               │
│ CRC 校验 (CRC Check): C40B          │
└─────────────────────────────────────┘

Example (TCP Request) :

┌─────────────────────────────────────┐
│ 报文结构解析                        │
├─────────────────────────────────────┤
│ 事务标识符 (Transaction ID): 0001   │
│ 协议标识符 (Protocol ID): 0000      │
│ 长度 (Length): 0006                 │
│ 单元标识符 (Unit ID): 01            │
│ 功能码 (Function Code): 03          │
│ 起始地址 (Start Address): 0000      │
│ 数量 (Quantity): 000A               │
└─────────────────────────────────────┘

Two, Practical cases: The real usage scenarios of engineers

case Read temperature sensor data 1: Scene

Equipment:

  • A certain brand of temperature transmitter: signal communication
  • Demand: RS485 (Modbus RTU)
  • Read: The temperature value of each channel 10 Traditional methods

Refer to the manual:

  1. Maintain register address: Manually calculate the message 40001-40010
  2. Slave station address:
    • Function code: 01
    • Starting address: 03
    • quantity Verification: 40001-1=40000=0x9C40
    • Manually calculate or use online tools: 10=0x000A
    • CRC Send using serial debugging assistant: Received response
  3. Manual parsing
  4. Time consumption, minute

After using the tool: 15-20 Open the tool

choice:

  1. Input parameters, Slave station address Modbus RTU
  2. Function code:
    • Starting address: 01
    • quantity Click on "Generate request command: 03
    • Copy message: 9C40
    • Send: 10
  3. Receive response"
  4. Paste to parser, Automatically parse
  5. Temperature values, Time consumption
  6. Minutes 10 Efficiency improvement

Times: 2-3 Case

Batch setting of frequency converter parameters: 6-10 Scene


Equipment 2: A certain brand of frequency converter

Communication:

  • Requirement: Batch setting
  • Parameters: Modbus RTU
  • Traditional method: Write individual registers for each parameter 20 Function code

traditional method:

  1. Write a single register for each parameter individually (function code 06)
  2. Write 20 Secondly, Calculate the message every time
  3. Easy to make mistakes, Repetitive labor

After using the tool:

  1. Select function code 10 (Write multiple registers)
  2. add to 20 A register:
    • Address: Automatic calculation
    • Data type: choice
    • Numerical value: Input
  3. Generate a message at once
  4. send out, Completed

Time consumption: From 1 Hour → 5 minute


case Debugging the upper computer software 3: Scene

Develop Kingview:

  • project Need to simulate/WinCC Slave station equipment
  • Test the logic of the upper computer program Modbus Use tools
  • Use a response message generator

Set simulation data:

  1. Generate response messages
  2. Send to the upper computer
  3. Verify program logic
  4. Benefits
  5. No need for real equipment

Can simulate various anomalies:

  • Improve development efficiency
  • Three
  • Technical details

Engineers are concerned about, Verification algorithm: use

3.1 CRC16 Cyclic redundancy check

Modbus RTU Example CRC16 (Verification algorithm) :

// CRC16 计算(低字节在前)
function calcCRC16(bytes) {
  let crc = 0xFFFF;
  for (let i = 0; i < bytes.length; i++) {
    crc ^= bytes[i];
    for (let j = 0; j < 8; j++) {
      if (crc & 0x0001) {
        crc = (crc >> 1) ^ 0xA001;
      } else {
        crc >>= 1;
      }
    }
  }
  return crc; // 低字节在前
}

use:

报文:01 03 00 00 00 0A
CRC:C4 0B(低字节在前)
完整:01 03 00 00 00 0A C4 0B

3.2 LRC Vertical redundancy check

Modbus ASCII Example LRC (Byte order issue) :

// LRC 计算
function calcLRC(bytes) {
  let sum = 0;
  for (let i = 0; i < bytes.length; i++) {
    sum += bytes[i];
  }
  const lrc = ((~sum) + 1) & 0xFF;
  return lrc;
}

Bit data:

报文:01 03 00 00 00 0A
LRC:FB
完整::01030000000AFB

3.3 The byte order

32 Byte order (UINT32/INT32/FLOAT) name:

ExampleThe tool supports automatic conversionSelect byte order (0x12345678)
ABBig Endian12 34 56 78
BALittle Endian34 12 78 56
CDABMixed56 78 12 34
BADCMixed78 56 34 12

The tool supports automatic conversion:

  • Select byte order
  • Enter decimal value
  • Automatically convert to register values

3.4 Modbus TCP of Head MBAP Message structure

Modbus TCP Example:

┌─────────────────────────────────────┐
│ MBAP 头(7 字节)                   │
├─────────────────────────────────────┤
│ 事务标识符(2 字节)                │
│ 协议标识符(2 字节)=0              │
│ 长度(2 字节)                      │
│ 单元标识符(1 字节)=从站地址       │
├─────────────────────────────────────┤
│ PDU(功能码 + 数据)                │
└─────────────────────────────────────┘

Four:

00 01 00 00 00 06 01 03 00 00 00 0A
│  │  │  │  │  │  │  │  │  │  │  │
│  │  │  │  │  │  │  │  │  │  │  └─ 数量低字节
│  │  │  │  │  │  │  │  │  └─────── 数量高字节
│  │  │  │  │  │  │  │  └────────── 起始地址低字节
│  │  │  │  │  │  │  └───────────── 起始地址高字节
│  │  │  │  │  │  └──────────────── 功能码
│  │  │  │  │  │  └──────────────── 单元标识符
│  │  │  │  │  └─────────────────── 长度(6 字节)
│  │  │  │  └────────────────────── 协议标识符(0=Modbus)
│  │  │  └───────────────────────── 事务标识符低字节
│  │  └──────────────────────────── 事务标识符高字节
└─────────────────────────────────── MBAP 头

User feedback, What do engineers say: Feedback

Automation engineer 1: Years of experience (5 Previously manually calculated)

"Message Modbus Frequently miscalculating, Now use this tool. Generate with a few clicks, Automatic calculation, CRC Too convenient, Efficiency should be improved at least! Double 5 Feedback. "

electrical engineer 2: Years of experience (10 Support three protocols)

"No need to switch tools anymore, especially. of Head TCP I used to always confuse things MBAP Now automatically generated, Not wrong, Feedback, engineer. "

Years of experience 3: PLC The response message generator is very useful (8 Simulate slave station equipment testing)

"Program, No need for real equipment PLC The development efficiency has been greatly improved, Feedback, Debugging engineer. "

Years of experience 4: The historical record function is very practical (3 The message that was adjusted yesterday)

"Copy directly today, No need to recalculate, WeChat sharing is also very convenient, Send it to colleagues for debugging together. Five, Write at the end. "


I make this tool, Not to replace engineers

But rather to liberate manpower, Enable engineers to no longer manually calculate messages.

No longer memorize complex formulas.

No longer for, Worried about verification, Let everyone spend their time on more valuable things CRC System architecture design.

Let everyone spend their time on more valuable things:

  • System architecture design
  • Optimization of control logic
  • On site problem resolution

Tools are not enemies, But rather helpers.

Engineers who make good use of tools, Engineers who do not use tools will be eliminated.

I hope this tool can help more peers.


Appendix: Usage method

Usage method 1: Scan WeChat QR code

 

A must-have tool for Modbus engineers! RTU/TCP/ASCII message generation parser, efficiency increased by 10 timesFigure

Usage method 2: WeChat search

Search"Modbus Debugging assistant"


Regarding the author

20 Years of experience in industrial automation, Waiting for equipment manufacturers, Integrators, first party.

Currently focusing on industrial Internet of Things, Edge computing, Intelligent control.

Welcome to communicate:

  • 📧 Email address: support@modbus.cn
  • 💬 WeChat group: Scan the code to add an assistant to the group

If deemed useful, welcome give the thumbs-up + Watching + forward Support me!

Forward to more electrical engineers, Use tools together to improve efficiency!

Put this resource to use in a real project?

Go to the Tool Center for message parsing, CRC verification and device debugging, or submit your requirements for selection and integration advice.

Engineer Membership

Turn this article into actionable debugging resources

After activation, you can use advanced message parsing, resource pack downloads, code examples, engineering cases and priority technical support, suitable for real project delivery.

Unlimited Advanced Tools
Resource & Code Packs
Complete Engineering Case Library
Priority Technical Support

Leave a Reply

Your email address will not be published. Required fields are marked *.