Wireshark packet capture analysis Modbus TCP/RTU packet complete guide

freeFree Technical Resource

This content is free to read, suitable for basic learning and search traffic.

Wireshark packet capture analysis Modbus TCP/RTU packet complete guide

Why use Wireshark to analyze Modbus?

Wireshark It is the most popular open-source network protocol analyzer in the world, From Gerald Combs In 1998 Annual creation, Currently Wireshark Foundation maintenance. Official website www.wireshark.org. It has a complete built-in Modbus TCP Protocol parser (dissector) , Can automatically identify and parse Modbus TCP In the message MBAP Head, Function code, Data area and exception code. For Modbus RTU Message, Wireshark It can also be done through USB Analyze by using a serial port adapter or remote packet capture method.

At the debugging site of industrial automation, The most common pain points are "communication failure but not knowing why". Wireshark allowing you to see every frame of data on the bus——what requests were sent, what responses were received, where the timeout occurred, what the exception code is——turning the invisible communication process into a traceable chain of evidence.

Wireshark support for the protocol Modbus the protocol parser is located

Wireshark able to automatically recognize the following content Modbus default port epan/dissectors/packet-modbus.c, automatic recognition:

  • Modbus/TCP: header 502, and various function codes MBAP function code parsing (Transaction ID, Protocol ID, Length, Unit ID) request and response formats for commonly used function codes PDU
  • exception codes: FC01-FC06, FC15-FC16, FC23 automatic annotation of exception responses
  • and display of the meaning of exception codes: illegal functions, illegal data addresses (01=illegal data values, 02=slave device failures, etc., 03=some gateways encapsulate frames in the middle for transmission. It can also parse, install, download from the official website page, download, install packages, check when installing, capture package driver, and if needed, convert serial data, capture messages, 04=Substation equipment malfunction, etc)
  • Modbus RTU over TCP: Some gateways will RTU Frame encapsulation in TCP Medium transmission, Wireshark It can also be analyzed

Install Wireshark

Linux (Ubuntu/Debian)

sudo apt-get update
sudo apt-get install wireshark

# Allow non root User packet capture
sudo usermod -a -G wireshark $USER
# After logging out, logging in again will take effect

Windows

from Official website download page Download Windows installation package. Check the box during installation Npcap (Windows Capture packet driver) and USBPcap (If you need to catch USB Convert serial data) .

macOS

brew install --cask wireshark

capture Modbus TCP message

Linux Server side packet capture

If Modbus TCP Communication occurs in Linux On the server or gateway, Directly use tcpdump The highest packet capture efficiency:

# Capture all target ports as 502 of TCP message(Modbus TCP Default port)
sudo tcpdump -i eth0 -w modbus_capture.pcap 'tcp port 502'

# Only capture designated items IP Communication of equipment
sudo tcpdump -i eth0 -w modbus_capture.pcap 'host 192.168.1.100 and tcp port 502'

# press Ctrl+C Stop packet capture
# Translate .pcap File transfer to Wireshark Analyzing on a computer

Windows Capture packets directly from the end

Open it Wireshark, Select the network card that communicates with the target device (Such as Ethernet cards or Wi-Fi) , In Capture Filter Chinese input tcp port 502, Click to start packet capture. Run your at this time Modbus Main station program (Like Modbus Poll) , You can capture the complete Modbus TCP Communication process.

Modbus TCP Detailed message explanation

In Wireshark Select one among them Modbus TCP Message, open "Modbus/TCP" Layer. A typical read hold register request message structure is as follows::

FieldsByte countExample valuesexplain
Transaction ID20x0001Transaction identifier, Client self augmentation, The server returns as is
Protocol ID20x0000Protocol identification, Modbus Fixed as 0
Length20x0006Subsequent byte count (Unit ID + PDU)
Unit ID10x01Slave station address (Slave ID)
Function Code10x03Function code (03=Read and hold registers)
Starting Address20x0000Starting register address
Quantity20x000ARead quantity (10One)

The corresponding response message contains the same MBAP Head + Function code 0x03 + Byte count 0x14 (20Byte=10A register) + Data area.

Wireshark Display filter techniques

Display filter (Display Filter) Used to quickly filter target data in captured messages. The following are commonly used Modbus Related filters:

# 筛选所有 Modbus 协议报文
modbus

# 筛选指定功能码(如 03 读保持寄存器)
modbus.func_code == 3

# 筛选异常响应
modbus.exception_code

# 筛选指定从站地址
modbus.unit_id == 1

# 筛选包含异常的报文
modbus.exception_code != 0

# 组合过滤:从站 1 的功能码 16(写多寄存器)
modbus.unit_id == 1 and modbus.func_code == 16

# 按 IP 地址和 Modbus 功能码过滤
ip.addr == 192.168.1.100 and modbus.func_code == 3

# 只看 MBAP 头 Transaction ID 为 5 的请求-响应对
modbus.trans_id == 5

Practical cases: Use Wireshark Investigation Modbus Communication failure

case Unable to read data1: No response from the slave station——No response from the slave station

After capturing the packet, it was found that only the request frame had no response frame (Or appear TCP RST/Retransmission) , Indicating that the slave device is not responding correctly. Inspection method:

  1. Confirm TCP Port (Default 502) Opened on the slave device
  2. Check the address of the slave station (Unit ID) Is it consistent with the request
  3. Check if there is TCP Layer anomaly (Retransmission, RST) , If so, it indicates that there is a problem with the network layer

case Return exception code2: Illegal data address 02 (You can see the starting address in the request)

Wireshark The quantity exceeds the register range of the slave station + In. Right click on the request message Wireshark You can see the complete request and exception response dialogue → "Follow → TCP Stream", case Abnormal data values.

Byte order issue3: Read it——The floating point number is

The display is normal 32 But it is displayed in the main station program as: Wireshark Or maximum value, This indicates that there is no problem with the communication layer NaN The byte order parsing of the main station program is incorrect. Can be in, Manual calculation verification in the middle. Right click on register data Wireshark Obtain the hexadecimal original value: Use → "Copy → Value" Calculator online verification, Capture IEEE 754 Serial port.

Message Modbus RTU (Through) Or

Modbus RTU Physical layer transmission RS-232 Cannot be used directly RS-485 Capture, Common solutions Wireshark Plan. Convert to serial port:

In1: USB Installation on top + USBPcap

Optional components during installation Windows Can grab USBPcap (Wireshark Convert raw data from serial devices) , But it needs to be parsed by oneself USB Frame. Address RTU Function code (data + function code + data + CRC) .

Plan2: Serial port monitoring software

Recommend using specialized serial port monitoring tools:

  • Serial Port Monitor (Windows Commercial software) : Can be directly monitored and analyzed Modbus RTU Frame
  • CAS Modbus RTU Parser: Free online tools, Paste hexadecimal bytes for automatic parsing
  • PortMon (Windows free Microsoft's low-level serial port monitoring tool) : Plan

In3: Turn RTU Capture packets on the gateway TCP If a serial server is used on site

Like (Can be in MOXA NPort) , Side use TCP Capture packets Wireshark The message content is as follows:, Frame RTU Advanced analytical skills.

Wireshark Modbus Statistical analysis

Chart: I/O Menu

Set the filter to → Statistics → I/O Graph, It can be observed that modbus, Frequency and time distribution of communication Modbus If periodic spikes or gaps are found. Perhaps due to improper configuration of polling parameters, View the complete.

Flow TCP Right click on any option

Message Modbus TCP Can be viewed in full once → Follow → TCP Stream, All connected TCP Raw data for requests and responses Modbus This is a powerful tool for troubleshooting the problem of "misplaced data reading". Export.

data All decoded data can be processed Modbus Export the message as:

File → Export Packet Dissections → As CSV, Format Modbus Convenient to use CSV Or, Conduct batch analysis Excel Summary Python Yes.

An irreplaceable tool in protocol debugging

Wireshark It can visualize the communication process that is' invisible ' Modbus Assist engineers in accurately locating the layer of the protocol stack where the problem occurs. Yes, Connection establishment failed——Header field error TCP Function code mismatch, MBAP Register address out of bounds or data byte order parsing error, For any engagement, Engineers responsible for communication development and debugging. Mastery Modbus Packet capture analysis is an essential skill, master Wireshark Packet capture analysis is an essential skill.

Put this resource to use in a real project?

Go to the Tool Center for message parsing, CRC verification and device debugging, or submit your requirements for selection and integration advice.

Engineer Membership

Turn this article into actionable debugging resources

After activation, you can use advanced message parsing, resource pack downloads, code examples, engineering cases and priority technical support, suitable for real project delivery.

Unlimited Advanced Tools
Resource & Code Packs
Complete Engineering Case Library
Priority Technical Support

Leave a Reply

Your email address will not be published. Required fields are marked *.