Detailed explanation of Modbus TCP data packet structure

freeFree Technical Resource

This content is free to read, suitable for basic learning and search traffic.

Detailed explanation of Modbus TCP data packet structure

The message formats of Modbus TCP and Modbus UDP are the same, and the difference between them is actually the difference between TCP and UDP. Therefore, the following analysis focuses on the protocol of Modbus TCP. The difference between Modbus TCP and Modbus Rtu (Modbus ASCII) is shown in the following figure:

Detailed explanation of Modbus TCP data packet structureFigure

As can be seen from the above figure, ModbusTCPinModbusOn the basis of serial communication, Removed verification (Due toTCPIt already comes with a checksum) And device address (ModbusTCPWeakened the device address, usingIPAddress to replace) , plusMBAPMessage header(accounted for)7 bytes) , Below, we will focus onMBAPProvide analysis and explanation:

domainLengthInstructionsclientServer
transaction ID 2byteModbusIdentification of request/response transaction processingClient startupCopy response
Protocol Identifier2byte0=ModbusagreementClient startupCopy response
Length2byteTotal number of bytes after lengthClient startupServer startup
Unit identifier1byteSlave identification of serial links or other busesClient startupCopy response

Below is an analysis of specific messages, ModbusThe message format of the protocol on the Ethernet link is as follows:

transaction ID Protocol IdentifierLengthUnit identifierfunction codedata
2 bytes2 bytes2 bytes1 byte1 byteN bytes

After establishing the theoretical foundation mentioned above, Below is a detailed analysis of each function code:

Read output coil

The format for sending messages is as follows:

Detailed explanation of Modbus TCP data packet structureFigure1

Meaning of sending message: Read the output coil of server No.1 slave station, The starting address is0x13=19, The corresponding address is00020, The number of coils is0x1B=27, Read the output coil of the No.1 slave station, Address from00020-00046, in total27The state value of a coil.

It's worth noting here, The starting address in the protocol refers to the index, The following address refers to the specific address, For any storage area, All indexes start from 0, But the corresponding specific address, Related to storage area, For example, output coil, 0correspond to00001; Input coil, 0correspond to10001; input register, 0correspond to30001; holding register, 0correspond to40001.

The format of the returned message is as follows:

Detailed explanation of Modbus TCP data packet structureFigure2

Return message meaning: Return to the output coil of server 1 slave station00020-00046, in total27The state value of a coil, Return 4 bytes, respectivelyCD 6B B2 05.

CD=1100 1101 correspond to 00020-00027

6B=0110 1011 correspond to 00028-00035

B2=1011 0010 correspond to 00036-00043

05=0000 0101 correspond to 00044-00046

Read input coil

The format for sending messages is as follows:

Detailed explanation of Modbus TCP data packet structureFigure3

Meaning of sending message: Read the input coil of server No.1 slave station, The starting address is0xC4=196, The corresponding address is10197, The number of coils is0x1D=29, Read the input coil of station 1, Address from10197-10225, in total29The state value of a coil.

The format of the returned message is as follows:

Detailed explanation of Modbus TCP data packet structureFigure4

Return message meaning: Return to the input coil of server 1 slave station10197-10225, in total29The state value of a coil, Return 4 bytes, respectivelyCD 6B B2 05.

CD=1100 1101 correspond to 10197-10204

6B=0110 1011 correspond to 10205-10212

B2=1011 0010 correspond to 10213-10220

05=0000 0101 correspond to 10221-10225

Read and hold register

The format for sending messages is as follows:

Detailed explanation of Modbus TCP data packet structureFigure5

Meaning of sending message: Read the slave station holding register of server 1, The starting address is0x6B=107, The corresponding address is40108, The number of registers is0x02=2, Read the 1st slave station hold register, Address from40108-40109, The values of two registers in total.

The format of the returned message is as follows:

Detailed explanation of Modbus TCP data packet structureFigure6

Return message meaning: Return to server 1 and keep the register from the slave station40108-40109, The values of two registers in total, Return 4 bytes, respectively02 2B 01 06, 40108The corresponding numerical value is0x022B, 40109The corresponding numerical value is0x0106.

Read input register

The format for sending messages is as follows:

Detailed explanation of Modbus TCP data packet structureFigure7

Meaning of sending message: Read the input register of server No.1 slave station, The starting address is0x6B=107, The corresponding address is30108, The number of registers is0x02=2, Read the 1st slave station hold register, Address from30108-30109, The values of two registers in total.

The format of the returned message is as follows:

Detailed explanation of Modbus TCP data packet structureFigure8

Return message meaning: Return to the input register of server 1 slave station30108-30109, The values of two registers in total, Return 4 bytes, respectively02 2B 01 06, 30108The corresponding numerical value is0x022B, 30109The corresponding numerical value is0x0106.

Pre set single coil

The format for sending messages is as follows:

Detailed explanation of Modbus TCP data packet structureFigure9

Meaning of sending message: Pre set the value of a single coil for server No.1 slave station, The coil address is0x00AC=172, The corresponding address is00173, Disconnecting flag0xFF00Indicate the position, 0x000Indicates reset, Set the output coil of the No.1 slave station00173.

The format of the returned message is as follows:

Detailed explanation of Modbus TCP data packet structureFigure10

Return message meaning: Pre set single output coil original message return.

Pre set single register

The format for sending messages is as follows:

Detailed explanation of Modbus TCP data packet structureFigure11

Meaning of sending message: Pre set the value of a single holding register for server 1 slave station, The register address is0x0087=135, The corresponding address is40136, Write value as0x039E, Pre set the 1st slave station holding register40136value0x039E.

The format of the returned message is as follows:

Detailed explanation of Modbus TCP data packet structureFigure12

Return message meaning: Pre set order maintains register and returns original message.

Pre set multiple coils

The format for sending messages is as follows:

Detailed explanation of Modbus TCP data packet structureFigure13

Meaning of sending message: Pre set the values of multiple coils for server 1 slave station, The coil address is0x0013=19, The corresponding address is00020, The number of coils is0x0A=10, Write value as0xCD00, Pre set No.1 slave coil00020-00027=0xCD=1100 1101, 00028-00029=0x00=0000 0000.

The format of the returned message is as follows:

Detailed explanation of Modbus TCP data packet structureFigure14

Return message meaning: The preset multi output coil return message is returned after removing the number of bytes and specific bytes from the original message.

Preset Multiple Registers

The format for sending messages is as follows:

Detailed explanation of Modbus TCP data packet structureFigure15

Meaning of sending message: Pre set the values of multiple registers for server 1 slave station, The register address is0x0087=135, The starting address is40136, The number of registers is0x02=2, The ending address is40137, Write value as0xCD00and0x0A10, Pre set the 1st slave station register40136=0x0105, 40137=0x0A10.

The format of the returned message is as follows:

Detailed explanation of Modbus TCP data packet structureFigure16

Return message meaning: The preset multi hold register returns a message after removing the number of bytes and specific bytes from the original message.

Put this resource to use in a real project?

Go to the Tool Center for message parsing, CRC verification and device debugging, or submit your requirements for selection and integration advice.

Engineer Membership

Turn this article into actionable debugging resources

After activation, you can use advanced message parsing, resource pack downloads, code examples, engineering cases and priority technical support, suitable for real project delivery.

Unlimited Advanced Tools
Resource & Code Packs
Complete Engineering Case Library
Priority Technical Support

Leave a Reply

Your email address will not be published. Required fields are marked *.