Explanation of MODBUS Communication Protocol for Delta PLC

freeFree Technical Resource

This content is free to read, suitable for basic learning and search traffic.

Explanation of MODBUS Communication Protocol for Delta PLC

communication port

LRC verification code

COM1After receiving the command message from the master station, the slave station expects a normal response message to be sent to the master station. However, sometimes the PLC does not respond or responds incorrectly after receiving the command message from the master station. The following will describe the situation where the PLC does not respond to the master station equipment or responds incorrectly.

COM2Assuming the number of node states in the request message is n (decimal), the quotient of n/8 is M, and the remainder is N.

ESLow byte dataEX2/SA2 COM3 :  RS-485 Communication port, capable of serving as a master or slave station.

SX2 COM3: USB Communication port, Can be used as a slave station.

COM1~COM3 The communication port can be used for Modbus ASCII Or RTU Mode communication.

Communication structure:

Communication parameters of communication portRS-232(COM1)RS-485(COM2)RS-485(COM3)USB(COM3)
Baud rate110~115200 bps110~921,000 bps110~115200 bps
Data bit length7~8 Position
Parity check bitOdd check/even check/no check
Stop data bit length1~2 Data bits
Communication parameter setting registerD1036D1120D1109
Maintain communication formatM1138M1120M1136
ASCII patternBoth master and slave stations are validEffective from the station
RTU patternBoth master and slave stations are validEffective from the station
ASCII /RTU Mode switchingM1139M1143M1320
Set a buffer for the communication address of the slave stationD1121D1255
Read and write data length (ASCII pattern)100 A register
Read and write data length (RTU pattern)100 A register

The default communication format of the communication port

L     Modbus ASCII pattern

L     7 Data bits

L     1 A stop position

L     Odd check digit (EVEN)

L     9600bps Baud rate

4.2    ASCII Mode communication protocol

Communication data structure

9600 (Baud rate), 7 (Data bits), Even (Parity check bit) 1 (Starting position), 1 (Stop position)

Field nameformexplain
Starting characterSTXThe starting character is:’,The colon ASCII The code is 3AH
Slave station addressADR 1The communication address consists of two parts ASCII Code composition
ADR 0
Command codeCMD 1The command code consists of two parts ASCII Code composition
CMD 0
  data The data content is composed of:DATA (0)  one 2n one ASCII Code composition, ns205.
DATA (1)
……… .
DATA (n-1)
LRC Verification codeLRC CHK 1LRC Verification code: 2 One ASCII Code composition
LRC CHK 0
End characterEND1The ending character is 2 One ASCII Code compositionEND1 = CR (0DH) ,END0 = LF (0AH)
END0

16 Binary and ASCII The code correspondence relationship is shown in the following table:

ASCII Code“0““1““2““3““4““5““6““7“
16 Base system30H31H32H33H34H35H36H37H
ASCII Code“8““9““A““B““C““D““E““F“
16 Base system38H39H41H42H43H44H45H46H

4.2.1  ADR (postal address)

The effective range of communication addresses is: 0~254. When the mailing address is 0 Time represents for all PLC radio broadcast, Received broadcast messages PLC can't Responding to broadcast messages. When PLC The address is not 0 Time, PLC Will respond to normal messages to the main station device.

For example, the mailing address is 16  (decimal system) of The address of PLC The code representation method is as follows: decimal number ASCII hexadecimal 16 basesystem is command code and data 10).

(ADR 1, ADR 0)=’1’,’0’s’1’=31H, ‘0’ = 30H

4.2.2  the format of data characters depends on the command code, and the description of valid command codes is shown in the table below

command code:

Explanation of MODBUS Communication Protocol for Delta PLCFiguremeaning(Hex)Explanation of MODBUS Communication Protocol for Delta PLCFigure1operable deviceread node state (unreadable input node state
01 (01 H)read node state (readable input node state)S, Y, M, T, C
02 (02 H)read register content value)S, X, Y, M,T, C
03 (03 H)force individual node stateT, C, D
05 (04 H)preset individual register value On/OffS, Y, M, T, C
06 (06 H)force multiple node statesT, C, D
15 (0F H)preset multiple register values On/OffS, Y, M, T, C
16 (10 H)report slave station addressT, C, D
17 (11 H)perform read and write functions simultaneously within a polling timeNone
23 (17 H)PLC LINK for example readNone

communication address: address PLC register 01, continuous H0614~H61B (character group data T20~T27)  hexadecimal 8 for. 0614 (internal) address PLC internal T20 The address.

PCOnePLC:

“: 01 03 06 14 00 08 DA CR LF”

Request message:

Field nameASCII Code16 Base system
Starting character:3A
Slave station address0130 31
Command code0330 33
High byte starting data address0630 36
Low byte starting data address1431 34
High byte number of contacts0030 30
Low byte number of contacts0830 38
LRC Verification codeDA44 41
End characterCR LF0D 0A

PLCOnePC

“: 01 03 10 00 01 00 02 00 03 00 04 00 05 00 06 00 07 00 08 C8 CR LF”

Response message:

Field nameASCII Code16 Base system
Starting character:3A
Slave station address0130 31
Command code0330 33
Field nameASCII Code16 Base system
Byte count1031 30
High byte(T20)0030 30
Low byte(T20)0130 31
High byte(T21)0030 30
Low byte(T21)0230 32
High byte(T22)0030 30
Low byte(T22)0330 33
High byte(T23)0030 30
Low byte(T23)0430 34
High byte(T24)0030 30
Low byte(T24)0530 35
High byte(T25)0030 30
Low byte(T25)0630 36
High byte(T26)0030 30
Low byte(T26)0730 37
High byte(T27)0030 30
Low byte(T27)0830 38
LRC Verification codeC843 38
End characterCR LF0D 0A

4.2.3   LRCVerification (Checksum)

LRC The verification code is from the station address to the last data content 16 Take the opposite of the values obtained by superimposing binary numbers and then add them again 1 The value. As follows: As shown in the example,LRC The value of the verification code is F6(16 Base system). LRC The calculation method of the verification code is as follows::01H+03H+04H+01H+00+01H = 0AH, 0A  (16 Add the result obtained by taking the reverse of (base) 1 For F6  (16 Base system).

Field nameASCII Code16 numeral system
Starting character:3A
Slave station address0130 31
Command code0330 33
High byte starting data address0430 34
Low byte starting data address0130 31
High byte number of contacts0030 30
Low byte number of contacts0130 31
LRC Verification codeF646 36
End characterCR LF0D 0A

Abnormal response:

After receiving the command message from the main station, expect a normal response message to be sent to the main station, But sometimes PLC Upon receiving commands from the main station The reasons for not responding or responding incorrectly after the message will be described below PLC The situation where there is no response from the main station device or the reason for the error response is not given.

1.  Due to communication errors, PLC Not receiving the correct command message: Therefore, when PLC When there is no response message, the main station device must set a communication timeout condition.

2. When no communication errors occur, PLC Received a valid communication message, But PLC Unable to understand the meaning of this message, So PLC Will provide abnormal response to the main station. The highest bit of the command code for responding to messages will be set to 1 And it will return an exception code indicating the cause of the exception response Reasons for response.

The command code is 01H Example of abnormal response in time, The abnormal response code is 02H

Request message:

Field nameASCII Codehexadecimal
Starting character:3A
30 31
Slave station address01
Command code0130 31
High byte starting data address0430 34
Low byte starting data address0030 30
High byte number of contacts (Unit: Position)0030 30
Low byte number of contacts (Unit: Position)1031 30
LRC Verification codeEA45 41
End characterCR LF0D 0A

Response message

Field nameASCII Codehexadecimal
Starting character:3A
30 31
Slave station address01
Command code8138 31
30 32
Exception code02
LRC Verification code7C37 43
End characterCR LF0D 0A
Exception codemeaning
01Illegal command code: PLC The command code in the received command information is invalid
02Illegal device address: The address in the received command information is invalid.
03Illegal device value: PLC The data content in the received command information is invalid.
071.    Verification and error●     Check if the checksum is correct
Exception codemeaning
 2.    Illegal command messages●     The command message is too short●     The length of the command message exceeds the range

4.3      RTU  Mode communication protocol

Communication data structure

9600 (Baud rate), 8 (Data bits), Even (Parity check bit) 1 (Starting position), 1 (Stop position)

StartMaintain no input data≥10 ms
Slave station addressSlave station address:: 8 Binary digit address
Command codeCommand code:: 8 Binary digit address
data Data content (n-1)Binary digitn  × 8 data Checksum low byte, n<=202
…… .
Checksum 0
CRC The checksum consists of two componentsCRC Composed of binary digitsCRC Checksum high byte 8 end
CRC Maintain no input data
Addresspostal address≥10 ms

4.3.1  The effective range of communication addresses is: (When the mailing address is)

Time represents for all 0~254. radio broadcast 0 Received broadcast messages PLC can't, Responding to broadcast messages PLC When The address is not. Time PLC Will respond to normal messages to the main station device 0 For example, PLC When the communication address is.

decimal system, of When communicating 16 (The address of the slave station must be set as) Base system PLC Decimal numbers, The hexadecimal system is 10 (16 Command codes and data), The format of data characters depends on the command code 16 The hexadecimal system is 10).

4.3.2  Command codes and data

The format of data characters depends on the command code, Please refer to the description of the valid function code 4.2.2 Festival.

example: Read PLC Station number 01, Address H0614~H61B (T20~T27)Continuity 8 Data of character sets. Read slave devices (Tong The mailing address is: 1)The value.

PCOnePLC

“ 01 03 06 14 00 08 04 80”

Sending messages:

Field namedata Base system (16 Start)
Maintain no input dataSlave station address≥10 ms
Command code01
Starting address of data03
Field name06
data Base systemNumber of data (in bytes (16 checksum low byte)
 14
checksum high byte)00
08
CRC end04
CRC keep no input data80
oneresponse message≥10 ms

PLCfield namePC

“ 01 03 10 00 01 00 02 00 03 00 04 00 05 00 06 00 07 00 08 72 98”

data:

basestart (16 keep no input data)
slave addresscommand code≥10 ms
number of data (in bytes01
data high byte03
data low byte)10
data high byte (T20)00
data low byte (T20)01
data high byte (T21)00
data low byte (T21)02
data high byte (T22)00
data low byte (T22)03
data low byte (T23)00
data low byte (T23)04
data high byte (T24)00
data low byte (T24)05
data high byte (T25)00
data high byte (T25)06
data high byte (T26)00
data low byte (T26)07
data low byte (T27)00
data low byte (T27)08
CRC checksum low byte72
CRC checksum high byte98
endkeep no input data)≥10 ms

4.3.3  CRC Verification (Checksum)

CRC Verify from "starting from the station address" to "ending with the last data content". The verification calculation method is as follows: steps: load a content value of "hexadecimal"" bit register (called "register". CRC step ": the first byte of the instruction message 1 : bit data and" register low byte " FFFF  (XOR the bit data) store the result in the register 16 step CRC move the content value of the register to the right).

bit and fill in its highest bit 2 : step 8 check CRC check the value of the lowest bit of the register, if it is" 8 repeat step if it is " CRC register content and" hexadecimal ") for XOR operation.

store the operation result in the register 3: CRC step 1 repeat step 0.

and step 4:  until CRC register The content has been shifted to the right by 0 bit 3:at this time 1 , CRC the first byte of the instruction message A001  (processing has been completed, step CRC repeat step to the next byte of the instruction message.

operation to step 5 : Until all bytes of the instruction message have been processed 3 Cheng 4,The final content of the register is:CRC Verification value8 Transmitting in command messages. When verifying values, Calculated School.

The high and low bytes of the verification value must be exchanged 6 : That is 2 The low byte of the verification value is transmitted first 5 Below is for use, Language demand Calculation example of verification value. CRC Instruction message content pointer CRC The length of the command message. Abnormal response CRC When verifying values, Calculated CRC school The high and low bytes of the verification value must be exchanged, namely CRC The low byte of the verification value is transmitted first.

Below is for use C Language Request CRC Calculation Example of Verification Value

unsigned char* data     <// Command message content pointer

unsigned char length   <// The length of the command message

unsigned int crc_chk(unsigned char* data, unsigned char length)

{

int j;

unsigned int reg_crc=0Xffff;

while(length--)

{

reg_crc ^= *data++;

for (j=0;j<8;j++)

{

If (reg_crc & 0x01) reg_crc=(reg_crc>>1) ^ 0Xa001; /* LSB(b0)=1 */

else reg_crc=reg_crc >>1;

}

}

return reg_crc;       // the value that sent back to the CRC register finally

}

Abnormal response:

After receiving the command message from the main station, expect a normal response message to be sent to the main station, But sometimes PLC Upon receiving commands from the main station The reasons for not responding or responding incorrectly after the message will be described below PLC The situation where there is no response from the main station device or the reason for the error response is not given.

1.  Due to communication errors, PLC Not receiving the correct command message: Therefore, when PLC When there is no response message, the main station device must set a communication timeout condition.

2. When no communication errors occur, PLC Received a valid communication message, But PLC Unable to understand the meaning of this message, So PLC Will provide abnormal response to the main station. The highest bit of the command code for responding to messages will be set to 1 And it will return an exception code indicating the cause of the exception response Reasons for response.

The following example is the command code: 01H Example of abnormal response in time, The abnormal response code is 02H.

Sending messages:

Field namedata Base system (16 Start)
Maintain no input dataSlave station address≥10 ms
Command code01
Starting address of data01
Number of data (in bytes04
00
checksum low byte)00
10
CRC checksum high byte3C
CRC endF6
keep no input dataresponse message≥10 ms

field name:

Explanation of MODBUS Communication Protocol for Delta PLCFigure2database(16 start)
keep no input dataslave address≥10 ms
command code01
exception code81
checksum low byte02
CRC checksum high byteC1
CRC end91
keep no input datadevice address≥10 ms

Explanation of MODBUS Communication Protocol for Delta PLCFigure3PLCdevice

Explanation of MODBUS Communication Protocol for Delta PLCFigure4rangevalid rangeaddressMODBUSodd address validdevice
ES2/EX2SS2SA2/SX2
S000~255 000~1023 000~1023000001~0002560000~00FF
S256~511000257~0005120100~01FF
S512~767000513~0007680200~02FF
S768~1023000769~0010240300~03FF
X000~377 (Octal)000~377000~377101025~1012800400~04FF
Y000~377 (Octal)000~377000~377001281~0015360500~05FF
T000~255 bit000~255000~255001537~0017920600~06FF
000~255 word000~255000~255401537~4017920600~06FF
M000~255         0000~4095         0000~4095   002049~0035840800~08FF
M256~5110900~09FF
M512~7670A00~0AFF
M768~10230B00~0BFF
M1024~12790C00~0CFF
M1280~15350D00~0DFF
M1536~1791     045057~047616B000~B0FF
M1792~2047B100~B1FF
M2048~2303B200~B2FF
M2304~2559B300~B3FF
M2560~2815B400~B4FF
M2816~3071B500~B5FF
M3072~3327B600~B6FF
M3328~3583B700~B7FF
M3584~3839B800~B8FF
M3840~4095B900~B9FF
  C000~199 (16-bit)000~199000~199003585~0037840E00~0EC7
000~199000~199403585~4037840E00~0EC7
 200~255 (32-bit)200~255200~255003785~0038400EC8~0EFF
200~255200~255401793~401903(range)0700~076F
valid rangeaddressdevice communication address)MODBUSaddressDevice communication address
ES2/EX2SS2SA2/SX2
D000~255                       0000~9999          0000~4999                       0000~9999  404097~4053761000~10FF
D256~5111100~11FF
D512~7671200~12FF
D768~10231300~13FF
D1024~12791400~14FF
D1280~1535      405377~4081921500~15FF
D1536~17911600~16FF
D1792~20471700~17FF
D2048~23031800~18FF
D2304~25591900~19FF
D2560~28151A00~1AFF
D2816~30711B00~1BFF
D3072~33271C00~1CFF
D3328~35831D00~1DFF
D3584~38391E00~1EFF
D3840~40951F00~1FFF
D4096~4351         436865~4409609000~90FF
D4352~46079100~91FF
D4608~48639200~92FF
D4864~51199300~93FF
D5120~5375           None9400~94FF
D5376~56319500~95FF
D5632~58879600~96FF
D5888~61439700~97FF
D6144~63999800~98FF
D6400~66559900~99FF
D6656~69119A00~9AFF
D6912~71679B00~9BFF
D7168~74239C00~9CFF
D7424~76799D00~9DFF
D7680~79359E00~9EFF
D7936~81919F00~9FFF
D8192~8447    440961~442768A000~A0FF
D8448~8703A100~A1FF
D8704~8959A200~A2FF
D8960~9215A300~A3FF
D9216~9471A400~A4FF
D9472~9727A500~A5FF
D9728~9983A600~A6FF
D9984~9999A700~A70F

4.5    Command code

4.5.1  Command code: 01, Read node status(Unreadable input point status)

Maximum number of data points= 255  (10 Base system) = FF  (16 Base system)

Example: Read the node status of the slave device (communication address:) 1)T20~T56 1.

PCsend messagePLC: “:01 01 06 14 00 25 BF CR LF”

field name:

codeASCII start character
slave address:
command code01
start data address high byte01
start data address low byte06
node status high byte14
node status low byte00
checksum25
LRC end characterBF
end character 10D (Hex)
assuming the number of node statuses in the request message is 00A (Hex)

decimal n  (quotient is), n/8 remainder is M,when N..

when N=0 byte number in the response message is, when M;byte number in the response message is N≠0 one, response message M+1. PLCfield namePC: “:01 01 05 CD 6B B2 0E 1B D6 CR LF”

code:

start characterASCII slave address
command code:
byte number01
node status01
node status05
T20~T27 node statusCD
T35~T38 node status6B
T36~T43 Node statusB2
T44~T51 Node status0E
T52~T56 Check code1B
LRC End characterE6
End character 10D (Hex)
Command code 00A (Hex)

4.5.2  Read node status: 02,Read input node status(Example: Read the node status of the slave device (communication address:))

Send message 1) Y024~Y070 Field name.

PCCodePLC “: 01 02 05 14 00 25 BF CR LF”

Starting character:

field nameASCII code
Starting character:
Slave station address01
Command code02
High byte starting data address05
Low byte starting data address14
High number of data bytes00
Low byte data count25
LRC Verification codeBF
End character 10D (Hex)
End character 00A (Hex)

Assuming the number of node states in the request message is n  (decimal system), n/8 The business is M,The remainder is N..

When N=0 Time, The number of bytes in the response message is M;When N≠0 Time, The number of bytes in the response message is M+1. PLCOnePC “: 01 01 05 CD 6B B2 0E 1B E5 CR LF”

Response message:

Explanation of MODBUS Communication Protocol for Delta PLCFigure2Field nameASCII Code
Starting character:
Slave station address01
Command code02
Number of bytes05
Y024~Y033 Node statusCD
Y034~Y043 Node status6B
Y044~Y053 Node statusB2
Y054~Y063 Node status0E
Y064~Y070 Node status1B
LRC Verification codeE5
End character 10D (Hex)
End character 00A (Hex)

4.5.3  Command code: 03,Read the register contents value

Command code 03 Readable registers: T, C, D

example::Read the slave station address as: 1 of of The content value PLC One T20~T27 Sending messages.

PCField namePLC: “: 01 03 06 14 00 08 DA CR LF”

Code:

Explanation of MODBUS Communication Protocol for Delta PLCFigure2Starting characterASCII Slave station address
Command code:
High byte data address01
High byte starting data address03
Read high byte count of data06
Read the low byte of the number of data (number of data in words14
checksum00
end character)08
LRC end characterDA
one 10D (Hex)
response message) 00A (Hex)

PLCOnePC: “:01 03 10 00 01 00 02 00 03 00 04 00 05 00 06 00 07 00 08 B8 CR LF” Response message:

Field nameASCII Code
Starting character3A
Slave station address01
Command code03
Number of bytes10
High byte data (T20)00
Low byte data (T20)01
High byte data (T21)00
Low byte data (T21)02
High byte data (T22)00
Low byte data (T22)03
High byte data (T23)00
Low byte data (T23)04
High byte data (T24)00
Low byte data (T24)05
High byte data (T25)00
Low byte data (T25)06
High byte data (T26)00
Low byte data (T26)07
Field nameASCII Code
High byte data (T27)00
Low byte data (T27)08
LRC Verification codeC8
End character 10D (Hex)
End character 00A (Hex)

4.5.4  Command code: 05, Enforce separate node status

The command code is 05 Mandatory data FF00  (16 Binary system) represents forcing a node to On;  Mandatory data 0000  (16 Binary system) represents forcing a node to Off. Other mandatory data is invalid and will not affect the mandatory nodes.

Example: Mandatory Y0 Node is On.

PCOnePLC   “: 01 05 05 00 FF 00 F6 CR LF”

Sending messages:

Field nameASCII Code
Starting character:
Slave station address01
Command code05
Node address high byte05
Node address low byte00
Force high byte dataFF
Mandatory low byte data00
LRC Verification codeF6
End character 10D (Hex)
End character 00A (Hex)

PLCOnePC   “: 01 05 05 00 FF 00 F6 CR LF”

Responding to information:

Field nameASCII Code
Starting character:
Slave station address01
Command code05
Node address high byte05
Node address low byte00
Force high byte dataFF
Mandatory low byte data00
LRC Verification codeF6
End character 10D (Hex)
End character 00A (Hex)

4.5.5  Command code: 06, Preset the value of a separate register

example: :Set registers T0 The value is 12 34  (16 Base system), T0 The mailing address is: 0600  (16 Base system).  PCOnePLC   “: 01 06 06 00 12 34 AD CR LF”

Sending messages:

Field nameASCII Code
Starting character:
Slave station address01
Command code06
Register address high byte06
Register address low byte00
Preset high byte data value12
Low byte preset data value34
LRC Verification codeAD
End character 10D (Hex)
End character 00A (Hex)

PLCOnePC   “: 01 06 06 00 12 34 AD CR LF”

Responding to information:

Field nameASCII Code
Starting character:
Slave station address01
Command code06
Register address high byte06
Register address low byte00
Preset high byte data value12
Low byte preset data value34
LRC Verification codeAD
End character 10D (Hex)
End character 00A (Hex)

4.5.6  Command code: 15, Enforce multiple nodes

Maximum number of nodes = 255

Example: Setting up nodes Y007…Y000 = 1100 1101, Y011…Y010 = 01.

PCOnePLC: “: 01 0F 05 00 00 0A 02 CD 01 11 CR LF”

Sending messages:

Field nameASCII Code
Starting character3A
Slave station address01
Command code0F
Field nameASCII Code
Node address high byte05
Node address low byte00
High number of nodes in bytes00
Low number of nodes in bytes0A
Number of bytes02
Force high byte dataCD
Mandatory low byte data01
LRC Verification code11
End character 10D (Hex)
End character 00A (Hex)

PLCOnePC: “: 01 0F 05 00 00 0A E1 CR LF”

Responding to information:

Field nameASCII Code
Starting character:
Slave station address01
Command code0F
High byte starting data address05
Low byte starting data address00
Preset high byte data value00
Low byte preset data value0A
LRC Verification codeE1
End character 10D (Hex)
End character 00A (Hex)

4.5.7  Command code: 16, Preset values for multiple registers

Example: Settings T0  The value is 000A  (16 Base system),set up T1 The value is 0102  (16 Base system).

PCOnePLC: “: 01 10 06 00 00 02 04 00 0A 01 02 D6 CR LF”

Sending messages:

Field nameASCII Code
Starting character:
Slave station address01
Command code10
High byte starting data address06
Low byte starting data address00
High number of registers in bytes00
Low number of registers in bytes02
Number of data (in bytes)04
data high byte00
data low byte0A
data high byte01
data low byte02
LRC checksumD6
end character 10D (Hex)
end character 00A (Hex)

PLConePC: “: 01 10 06 00 00 02 E7 CR LF”

response message:

field nameASCII code
start character:
slave address01
command code10
start data address high byte06
start data address low byte00
register high byte00
register low byte02
LRC checksumE7
end character 10D (Hex)
end character) 00A (Hex)
Related Tags
Put this resource to use in a real project?

Go to the Tool Center for message parsing, CRC verification and device debugging, or submit your requirements for selection and integration advice.

Engineer Membership

Turn this article into actionable debugging resources

After activation, you can use advanced message parsing, resource pack downloads, code examples, engineering cases and priority technical support, suitable for real project delivery.

Unlimited Advanced Tools
Resource & Code Packs
Complete Engineering Case Library
Priority Technical Support

Leave a Reply

Your email address will not be published. Required fields are marked *.