A must-have tool for Modbus engineers! RTU/TCP/ASCII message generation parser, efficiency increased by 10 times
Byte order of 32-bit data (UINT32/INT32/FLOAT):
preface: Modbus The pain of debugging, Engineers understand
I did it 20 Annual industrial automation, Too familiar Modbus The pain of debugging.
Do you also frequently encounter these situations?
Scene 1: Manually calculate the message, Easy to make mistakes
To read and hold the register, Slave station address 01, Starting address 40001, quantity One 10 You use a calculator to calculate
Slave station address:
- Function code: 01
- Starting address: 03
- wait: 00 00 (40001-1=40000=0x9C40, incorrect, quantity Verification...)
- Calculate half: 00 0A
- CRC The customer called: ? ? ?
I forgot where I counted when I came back, Recalculate, The calculation is incorrect
Calculate again, CRC Still not right
Scene, Received message...
Not able to parse 2: Equipment return, You stare
This is the function code:
01 03 14 00 0A 00 0B 00 0C 00 0D 00 0E xx xx
The response:
- It is the number of bytes 03 Byte
- 14 But what is the value of each register (20 The byte order is)
- Still?
- Scene AB Three protocols BA?
Confused 3: Use, Verification
- RTU Use CRC Verification
- ASCII have Head LRC Urgent
- TCP Use MBAP The method of analysis
Message, No matter what, it doesn't match RTU Scene TCP Debugging records, cannot find
Scene 4: Debugging log, cannot find
The message that was adjusted yesterday, I couldn't find it today
Ask colleagues for it, My colleague said, 'I forgot too"
recalculated, spent hours 1 these pain points
I know all of them, so, I developed this.
message generation parser, it supports Modbus three protocols.
automatically generates request/response messages RTU/TCP/ASCII no need to manually calculate, no need to remember formulas.
just a few clicks to generate, one, core function.
why engineers always say good, all three protocols are covered: support?
1.1 three transmission modes
protocol Modbus verification method:
| frame format | applicable scenarios | binary | serial communication |
|---|---|---|---|
| Modbus RTU | CRC16 | text | old devices/modems (RS485/RS232) |
| Modbus ASCII | LRC | ASCII no verification | guarantee |
| Modbus TCP | header (TCP Ethernet communication) | MBAP one tool +ADU | handles everything |
debugging scenarios, request command generator Modbus function description.
1.2 support
function code:
① function code 12 name
| purpose | Read coil status | Read switch output |
|---|---|---|
| 01 | Read discrete input | Read switch input |
| 02 | Read hold register | Most commonly used |
| 03 | Analog output | Read input register (Read only) |
| 04 | Analog input | Write a single coil (Switch control) |
| 05 | Write a single register | Parameter Settings |
| 06 | Write a single register | Parameter Settings |
| 0F | Write multiple coils | Batch switch control |
| 10 | Write multiple registers | Batch parameter setting |
| 17 | Read/write multiple registers | Simultaneously read and write |
| 2B | Read device identification | Equipment information query |
② Parameter configuration
Using function codes 03 (Read and hold registers) For example:
从站地址:01(0-247) 功能码:03 起始地址:0000(十六进制或十进制) 数量:0010(读取 10 个寄存器)
③ Automatically generate messages
After inputting the parameters, Automatically generated:
RTU pattern:
01 03 00 00 00 0A C4 0B │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ └─ CRC 低字节 │ │ │ │ │ │ └──── CRC 高字节 │ │ │ │ │ └─────── 数量低字节 │ │ │ │ └────────── 数量高字节 │ │ │ └───────────── 起始地址低字节 │ │ └──────────────── 起始地址高字节 │ └─────────────────── 功能码 └────────────────────── 从站地址
ASCII pattern:
:01030000000AFB │ │ │ │ │ └── LRC 校验(FB) │ └───── 数据部分(ASCII 编码) └────────────────── 起始符(:)
TCP pattern:
00 01 00 00 00 06 01 03 00 00 00 0A │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ └─ 数量低字节 │ │ │ │ │ │ │ │ │ └─────── 数量高字节 │ │ │ │ │ │ │ │ └────────── 起始地址低字节 │ │ │ │ │ │ │ └───────────── 起始地址高字节 │ │ │ │ │ │ └──────────────── 功能码 │ │ │ │ │ │ └──────────────── 单元标识符(从站地址) │ │ │ │ │ └─────────────────── 长度(后续字节数) │ │ │ │ └────────────────────── 协议标识符(0=Modbus) │ │ │ └───────────────────────── 事务标识符低字节 │ │ └──────────────────────────── 事务标识符高字节 └─────────────────────────────────── MBAP 头(7 字节)
④ Support for special function codes
Function code 05 (Write a single coil) :
- Switch selection: Open it (ON) / close (OFF)
- Automatic conversion to FF00/0000
Function code 0F (Write multiple coils) :
- Number of coils input
- Visual coil selection (Dot button)
- Click to switch states (Grey=OFF, Blue=ON)
- Automatically calculate byte count
Function code 10 (Write multiple registers) :
- Register list (Multiple can be added)
- Each register setting:
- Address (Automatic calculation)
- Data type (UINT16/INT16/UINT32/INT32/FLOAT)
- Byte order (AB/BA)
- Numerical value (Decimal input)
- Automatically convert to register values
1.3 Response message generator
Function description:
① Simulate device response
Used for testing upper computer software (Like Kingview, WinCC) Or PLC Program.
② Support normal response and abnormal response
Normal response (Function code 03) :
从站地址:01 功能码:03 字节数:20(10 个寄存器×2) 寄存器值: - Reg 0: 10(0x000A) - Reg 1: 20(0x0014) - Reg 2: 30(0x001E) - ...
Abnormal response:
从站地址:01 功能码:83(03+80) 异常码: - 01:非法功能 - 02:非法数据地址 - 03:非法数据值 - 04:从站设备故障 - 05:认可 - 06:从属设备忙
③ Data type support
Support multiple data types, automatic conversion:
| Type | Byte count | Range | Byte order |
|---|---|---|---|
| UINT16 | 2 | 0-65535 | Fixed |
| INT16 | 2 | -32768~32767 | Fixed |
| UINT32 | 4 | 0-4294967295 | AB/BA |
| INT32 | 4 | -2147483648~2147483647 | AB/BA |
| FLOAT | 4 | IEEE 754 Single precision | AB/BA/CDAB/BADC |
Example:
Enter decimal value: 25.5 (FLOAT Type)
Automatically convert to register values:
- Reg 0: 0x41CC (High 16 Position)
- Reg 1: 0x0000 (Low 16 Position)
1.4 Message parser
Function description:
① Paste message, Automatic parsing
Received the message returned by the device, Paste it in, Automatic parsing:
Input (RTU pattern) :
01 03 14 00 0A 00 0B 00 0C 00 0D 00 0E 7A 3B
Automatic parsing:
┌─────────────────────────────────────┐ │ 从站地址:01 │ │ 功能码:03(读保持寄存器) │ │ 字节数:20(0x14) │ │ 数据内容: │ │ Reg 0: 0x000A = 10 │ │ Reg 1: 0x000B = 11 │ │ Reg 2: 0x000C = 12 │ │ Reg 3: 0x000D = 13 │ │ Reg 4: 0x000E = 14 │ │ CRC 校验:7A3B ✓(正确) │ └─────────────────────────────────────┘
② Support three types of protocol parsing
- RTU: CRC16 Verification
- ASCII: LRC Verification
- TCP: MBAP Head analysis
③ Error detection
- CRC/LRC Verification error prompt
- Reminder for abnormal message length
- Illegal function code warning
1.5 Historical records
Function description:
① Automatic saving
Automatically save each generated message, contain:
- Message content
- Generation time
- Message type (Request/Response)
② Quick operation
- Copy: One click copying of messages
- WeChat sharing: Send to colleagues
- Clearing: Clear historical records
③ Classification management
- Request command history
- Response message history
- Separate management, Clear and concise
1.6 Visualization of message structure
Function description:
Each message generated, All come with structural analysis:
Example (RTU Request) :
┌─────────────────────────────────────┐ │ 报文结构解析 │ ├─────────────────────────────────────┤ │ 从站地址 (Slave Address): 01 │ │ 功能码 (Function Code): 03 │ │ 起始地址 (Start Address): 0000 │ │ 数量 (Quantity): 000A │ │ CRC 校验 (CRC Check): C40B │ └─────────────────────────────────────┘
Example (TCP Request) :
┌─────────────────────────────────────┐ │ 报文结构解析 │ ├─────────────────────────────────────┤ │ 事务标识符 (Transaction ID): 0001 │ │ 协议标识符 (Protocol ID): 0000 │ │ 长度 (Length): 0006 │ │ 单元标识符 (Unit ID): 01 │ │ 功能码 (Function Code): 03 │ │ 起始地址 (Start Address): 0000 │ │ 数量 (Quantity): 000A │ └─────────────────────────────────────┘
Two, Practical cases: The real usage scenarios of engineers
case Read temperature sensor data 1: Scene
Equipment:
- A certain brand of temperature transmitter: signal communication
- Demand: RS485 (Modbus RTU)
- Read: The temperature value of each channel 10 Traditional methods
Refer to the manual:
- Maintain register address: Manually calculate the message 40001-40010
- Slave station address:
- Function code: 01
- Starting address: 03
- quantity Verification: 40001-1=40000=0x9C40
- Manually calculate or use online tools: 10=0x000A
- CRC Send using serial debugging assistant: Received response
- Manual parsing
- Time consumption, minute
After using the tool: 15-20 Open the tool
choice:
- Input parameters, Slave station address Modbus RTU
- Function code:
- Starting address: 01
- quantity Click on "Generate request command: 03
- Copy message: 9C40
- Send: 10
- Receive response"
- Paste to parser, Automatically parse
- Temperature values, Time consumption
- Minutes 10 Efficiency improvement
Times: 2-3 Case
Batch setting of frequency converter parameters: 6-10 Scene
Equipment 2: A certain brand of frequency converter
Communication:
- Requirement: Batch setting
- Parameters: Modbus RTU
- Traditional method: Write individual registers for each parameter 20 Function code
traditional method:
- Write a single register for each parameter individually (function code 06)
- Write 20 Secondly, Calculate the message every time
- Easy to make mistakes, Repetitive labor
After using the tool:
- Select function code 10 (Write multiple registers)
- add to 20 A register:
- Address: Automatic calculation
- Data type: choice
- Numerical value: Input
- Generate a message at once
- send out, Completed
Time consumption: From 1 Hour → 5 minute
case Debugging the upper computer software 3: Scene
Develop Kingview:
- project Need to simulate/WinCC Slave station equipment
- Test the logic of the upper computer program Modbus Use tools
- Use a response message generator
Set simulation data:
- Generate response messages
- Send to the upper computer
- Verify program logic
- Benefits
- No need for real equipment
Can simulate various anomalies:
- Improve development efficiency
- Three
- Technical details
Engineers are concerned about, Verification algorithm: use
3.1 CRC16 Cyclic redundancy check
Modbus RTU Example CRC16 (Verification algorithm) :
// CRC16 计算(低字节在前)
function calcCRC16(bytes) {
let crc = 0xFFFF;
for (let i = 0; i < bytes.length; i++) {
crc ^= bytes[i];
for (let j = 0; j < 8; j++) {
if (crc & 0x0001) {
crc = (crc >> 1) ^ 0xA001;
} else {
crc >>= 1;
}
}
}
return crc; // 低字节在前
}
use:
报文:01 03 00 00 00 0A CRC:C4 0B(低字节在前) 完整:01 03 00 00 00 0A C4 0B
3.2 LRC Vertical redundancy check
Modbus ASCII Example LRC (Byte order issue) :
// LRC 计算
function calcLRC(bytes) {
let sum = 0;
for (let i = 0; i < bytes.length; i++) {
sum += bytes[i];
}
const lrc = ((~sum) + 1) & 0xFF;
return lrc;
}
Bit data:
报文:01 03 00 00 00 0A LRC:FB 完整::01030000000AFB
3.3 The byte order
32 Byte order (UINT32/INT32/FLOAT) name:
| Example | The tool supports automatic conversion | Select byte order (0x12345678) |
|---|---|---|
| AB | Big Endian | 12 34 56 78 |
| BA | Little Endian | 34 12 78 56 |
| CDAB | Mixed | 56 78 12 34 |
| BADC | Mixed | 78 56 34 12 |
The tool supports automatic conversion:
- Select byte order
- Enter decimal value
- Automatically convert to register values
3.4 Modbus TCP of Head MBAP Message structure
Modbus TCP Example:
┌─────────────────────────────────────┐ │ MBAP 头(7 字节) │ ├─────────────────────────────────────┤ │ 事务标识符(2 字节) │ │ 协议标识符(2 字节)=0 │ │ 长度(2 字节) │ │ 单元标识符(1 字节)=从站地址 │ ├─────────────────────────────────────┤ │ PDU(功能码 + 数据) │ └─────────────────────────────────────┘
Four:
00 01 00 00 00 06 01 03 00 00 00 0A │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ └─ 数量低字节 │ │ │ │ │ │ │ │ │ └─────── 数量高字节 │ │ │ │ │ │ │ │ └────────── 起始地址低字节 │ │ │ │ │ │ │ └───────────── 起始地址高字节 │ │ │ │ │ │ └──────────────── 功能码 │ │ │ │ │ │ └──────────────── 单元标识符 │ │ │ │ │ └─────────────────── 长度(6 字节) │ │ │ │ └────────────────────── 协议标识符(0=Modbus) │ │ │ └───────────────────────── 事务标识符低字节 │ │ └──────────────────────────── 事务标识符高字节 └─────────────────────────────────── MBAP 头
User feedback, What do engineers say: Feedback
Automation engineer 1: Years of experience (5 Previously manually calculated)
"Message Modbus Frequently miscalculating, Now use this tool. Generate with a few clicks, Automatic calculation, CRC Too convenient, Efficiency should be improved at least! Double 5 Feedback. "
electrical engineer 2: Years of experience (10 Support three protocols)
"No need to switch tools anymore, especially. of Head TCP I used to always confuse things MBAP Now automatically generated, Not wrong, Feedback, engineer. "
Years of experience 3: PLC The response message generator is very useful (8 Simulate slave station equipment testing)
"Program, No need for real equipment PLC The development efficiency has been greatly improved, Feedback, Debugging engineer. "
Years of experience 4: The historical record function is very practical (3 The message that was adjusted yesterday)
"Copy directly today, No need to recalculate, WeChat sharing is also very convenient, Send it to colleagues for debugging together. Five, Write at the end. "
I make this tool, Not to replace engineers
But rather to liberate manpower, Enable engineers to no longer manually calculate messages.
No longer memorize complex formulas.
No longer for, Worried about verification, Let everyone spend their time on more valuable things CRC System architecture design.
Let everyone spend their time on more valuable things:
- System architecture design
- Optimization of control logic
- On site problem resolution
Tools are not enemies, But rather helpers.
Engineers who make good use of tools, Engineers who do not use tools will be eliminated.
I hope this tool can help more peers.
Appendix: Usage method
Usage method 1: Scan WeChat QR code

Usage method 2: WeChat search
Search"Modbus Debugging assistant"
Regarding the author
20 Years of experience in industrial automation, Waiting for equipment manufacturers, Integrators, first party.
Currently focusing on industrial Internet of Things, Edge computing, Intelligent control.
Welcome to communicate:
- 📧 Email address: support@modbus.cn
- 💬 WeChat group: Scan the code to add an assistant to the group
If deemed useful, welcome give the thumbs-up + Watching + forward Support me!
Forward to more electrical engineers, Use tools together to improve efficiency!
Leave a Reply