Modbus has been in use since 1979 and still lives in countless meters, drives, sensors and PLCs in the field. It is popular for its simplicity, but that simplicity also means it carries no meaning for the data. This guide collects what you need to know when working with Modbus.
Data model: four tables
| Table | Size | Access | Traditional address |
|---|---|---|---|
| Coils | 1 bit | Read/write | 0xxxx |
| Discrete inputs | 1 bit | Read-only | 1xxxx |
| Input registers | 16 bit | Read-only | 3xxxx |
| Holding registers | 16 bit | Read/write | 4xxxx |
Commonly used function codes
| Code | Function |
|---|---|
| 01 / 02 | Read coils / discrete inputs |
| 03 / 04 | Read holding / input registers |
| 05 / 06 | Write single coil / single register |
| 15 (0x0F) / 16 (0x10) | Write multiple coils / registers |
The amount readable in one request is limited: up to 125 registers for holding and input registers and up to 2000 bits for coils. When reading many tags you need to group requests with these limits, and the device’s own limits, in mind.
RTU and TCP: two frames
Modbus RTU runs over serial lines (RS-485/RS-232). A frame consists of a 1-byte device address, a 1-byte function code, data and a 2-byte CRC16 (low byte sent first). Frames are separated by silent intervals, so wiring, termination resistors and baud/parity settings are critical.
Modbus TCP runs over Ethernet (default port 502). There is no CRC; TCP provides integrity. A 7-byte MBAP header comes first: transaction ID (2 bytes), protocol ID (2 bytes, 0), length (2 bytes) and unit ID (1 byte). The unit ID is used to address serial devices behind a gateway.
To build and verify frames by hand, you can use the Modbus Frame Builder in the IT Hub.
The three mistakes that cost the most time
1. Address shift (0-based or 1-based?)
If the device manual says “40001”, at the protocol level this is usually holding register, address 0. But some manuals count addresses from 1 and others from 0. If the value you read looks “one register off”, check this first.
2. 32-bit and floating-point values
Registers are 16 bits; a 32-bit integer or float spans two registers. The word order of the two registers (which is the high word) and the byte order within each register vary by vendor: ABCD, CDAB, BADC, DCBA. The wrong choice produces nonsensical but “plausible-looking” numbers. The PLC Data Type Converter is handy for seeing these combinations.
3. Scaling and units
Modbus carries no unit or decimal information. Is “742” 74.2 °C or 742? That information comes from the device documentation and must be written down somewhere. Otherwise every consumer makes its own interpretation.
Polling and data quality
Modbus is request-response; devices do not send data on their own, so the client polls periodically. Set the scan interval according to the device’s response time and line speed; polling too often strains both the line and the device. Define timeout and retry behavior, and keep a quality value that distinguishes “last valid value” from “read failed”.
Security
Modbus has no authentication or encryption; anyone with network access can read and write. Modbus networks must therefore be segmented, write access restricted and gateways placed at controlled points.
Bringing Modbus data into a modern architecture
Before sharing Modbus data with analytics or the cloud, scaling, units and meaning must be added. In HighByte Intelligence Hub, Modbus TCP devices can be reached through an OPC UA gateway; the data can be modeled once and published consistently to targets such as OPC UA, MQTT or SQL. For the broader connectivity architecture, see our Industrial IoT & Connectivity solution page.