Why use Wireshark to analyze Modbus?
Wireshark It is the most popular open-source network protocol analyzer in the world, From Gerald Combs In 1998 Annual creation, Currently Wireshark Foundation maintenance. Official website www.wireshark.org. It has a complete built-in Modbus TCP Protocol parser (dissector) , Can automatically identify and parse Modbus TCP In the message MBAP Head, Function code, Data area and exception code. For Modbus RTU Message, Wireshark It can also be done through USB Analyze by using a serial port adapter or remote packet capture method.
At the debugging site of industrial automation, The most common pain points are "communication failure but not knowing why". Wireshark allowing you to see every frame of data on the bus——what requests were sent, what responses were received, where the timeout occurred, what the exception code is——turning the invisible communication process into a traceable chain of evidence.
Wireshark support for the protocol Modbus the protocol parser is located
Wireshark able to automatically recognize the following content Modbus default port epan/dissectors/packet-modbus.c, automatic recognition:
- Modbus/TCP: header 502, and various function codes MBAP function code parsing (Transaction ID, Protocol ID, Length, Unit ID) request and response formats for commonly used function codes PDU
- exception codes: FC01-FC06, FC15-FC16, FC23 automatic annotation of exception responses
- and display of the meaning of exception codes: illegal functions, illegal data addresses (01=illegal data values, 02=slave device failures, etc., 03=some gateways encapsulate frames in the middle for transmission. It can also parse, install, download from the official website page, download, install packages, check when installing, capture package driver, and if needed, convert serial data, capture messages, 04=Substation equipment malfunction, etc)
- Modbus RTU over TCP: Some gateways will RTU Frame encapsulation in TCP Medium transmission, Wireshark It can also be analyzed
Install Wireshark
Linux (Ubuntu/Debian)
sudo apt-get update
sudo apt-get install wireshark
# Allow non root User packet capture
sudo usermod -a -G wireshark $USER
# After logging out, logging in again will take effectWindows
from Official website download page Download Windows installation package. Check the box during installation Npcap (Windows Capture packet driver) and USBPcap (If you need to catch USB Convert serial data) .
macOS
brew install --cask wiresharkcapture Modbus TCP message
Linux Server side packet capture
If Modbus TCP Communication occurs in Linux On the server or gateway, Directly use tcpdump The highest packet capture efficiency:
# Capture all target ports as 502 of TCP message(Modbus TCP Default port)
sudo tcpdump -i eth0 -w modbus_capture.pcap 'tcp port 502'
# Only capture designated items IP Communication of equipment
sudo tcpdump -i eth0 -w modbus_capture.pcap 'host 192.168.1.100 and tcp port 502'
# press Ctrl+C Stop packet capture
# Translate .pcap File transfer to Wireshark Analyzing on a computerWindows Capture packets directly from the end
Open it Wireshark, Select the network card that communicates with the target device (Such as Ethernet cards or Wi-Fi) , In Capture Filter Chinese input tcp port 502, Click to start packet capture. Run your at this time Modbus Main station program (Like Modbus Poll) , You can capture the complete Modbus TCP Communication process.
Modbus TCP Detailed message explanation
In Wireshark Select one among them Modbus TCP Message, open "Modbus/TCP" Layer. A typical read hold register request message structure is as follows::
| Fields | Byte count | Example values | explain |
|---|---|---|---|
| Transaction ID | 2 | 0x0001 | Transaction identifier, Client self augmentation, The server returns as is |
| Protocol ID | 2 | 0x0000 | Protocol identification, Modbus Fixed as 0 |
| Length | 2 | 0x0006 | Subsequent byte count (Unit ID + PDU) |
| Unit ID | 1 | 0x01 | Slave station address (Slave ID) |
| Function Code | 1 | 0x03 | Function code (03=Read and hold registers) |
| Starting Address | 2 | 0x0000 | Starting register address |
| Quantity | 2 | 0x000A | Read quantity (10One) |
The corresponding response message contains the same MBAP Head + Function code 0x03 + Byte count 0x14 (20Byte=10A register) + Data area.
Wireshark Display filter techniques
Display filter (Display Filter) Used to quickly filter target data in captured messages. The following are commonly used Modbus Related filters:
# 筛选所有 Modbus 协议报文
modbus
# 筛选指定功能码(如 03 读保持寄存器)
modbus.func_code == 3
# 筛选异常响应
modbus.exception_code
# 筛选指定从站地址
modbus.unit_id == 1
# 筛选包含异常的报文
modbus.exception_code != 0
# 组合过滤:从站 1 的功能码 16(写多寄存器)
modbus.unit_id == 1 and modbus.func_code == 16
# 按 IP 地址和 Modbus 功能码过滤
ip.addr == 192.168.1.100 and modbus.func_code == 3
# 只看 MBAP 头 Transaction ID 为 5 的请求-响应对
modbus.trans_id == 5Practical cases: Use Wireshark Investigation Modbus Communication failure
case Unable to read data1: No response from the slave station——No response from the slave station
After capturing the packet, it was found that only the request frame had no response frame (Or appear TCP RST/Retransmission) , Indicating that the slave device is not responding correctly. Inspection method:
- Confirm TCP Port (Default 502) Opened on the slave device
- Check the address of the slave station (Unit ID) Is it consistent with the request
- Check if there is TCP Layer anomaly (Retransmission, RST) , If so, it indicates that there is a problem with the network layer
case Return exception code2: Illegal data address 02 (You can see the starting address in the request)
Wireshark The quantity exceeds the register range of the slave station + In. Right click on the request message Wireshark You can see the complete request and exception response dialogue → "Follow → TCP Stream", case Abnormal data values.
Byte order issue3: Read it——The floating point number is
The display is normal 32 But it is displayed in the main station program as: Wireshark Or maximum value, This indicates that there is no problem with the communication layer NaN The byte order parsing of the main station program is incorrect. Can be in, Manual calculation verification in the middle. Right click on register data Wireshark Obtain the hexadecimal original value: Use → "Copy → Value" Calculator online verification, Capture IEEE 754 Serial port.
Message Modbus RTU (Through) Or
Modbus RTU Physical layer transmission RS-232 Cannot be used directly RS-485 Capture, Common solutions Wireshark Plan. Convert to serial port:
In1: USB Installation on top + USBPcap
Optional components during installation Windows Can grab USBPcap (Wireshark Convert raw data from serial devices) , But it needs to be parsed by oneself USB Frame. Address RTU Function code (data + function code + data + CRC) .
Plan2: Serial port monitoring software
Recommend using specialized serial port monitoring tools:
- Serial Port Monitor (Windows Commercial software) : Can be directly monitored and analyzed Modbus RTU Frame
- CAS Modbus RTU Parser: Free online tools, Paste hexadecimal bytes for automatic parsing
- PortMon (Windows free Microsoft's low-level serial port monitoring tool) : Plan
In3: Turn RTU Capture packets on the gateway TCP If a serial server is used on site
Like (Can be in MOXA NPort) , Side use TCP Capture packets Wireshark The message content is as follows:, Frame RTU Advanced analytical skills.
Wireshark Modbus Statistical analysis
Chart: I/O Menu
Set the filter to → Statistics → I/O Graph, It can be observed that modbus, Frequency and time distribution of communication Modbus If periodic spikes or gaps are found. Perhaps due to improper configuration of polling parameters, View the complete.
Flow TCP Right click on any option
Message Modbus TCP Can be viewed in full once → Follow → TCP Stream, All connected TCP Raw data for requests and responses Modbus This is a powerful tool for troubleshooting the problem of "misplaced data reading". Export.
data All decoded data can be processed Modbus Export the message as:
File → Export Packet Dissections → As CSV, Format Modbus Convenient to use CSV Or, Conduct batch analysis Excel Summary Python Yes.
An irreplaceable tool in protocol debugging
Wireshark It can visualize the communication process that is' invisible ' Modbus Assist engineers in accurately locating the layer of the protocol stack where the problem occurs. Yes, Connection establishment failed——Header field error TCP Function code mismatch, MBAP Register address out of bounds or data byte order parsing error, For any engagement, Engineers responsible for communication development and debugging. Mastery Modbus Packet capture analysis is an essential skill, master Wireshark Packet capture analysis is an essential skill.
Leave a Reply