Industrial IoT

Modbus TCP and RTU Guide: Registers, Function Codes and Common Mistakes

We explain the Modbus data model, the RTU and TCP frames, the most-used function codes and the address/byte-order mistakes that cost the most time in the field.

3 min read ASP Dijital

Modbus TCP and RTU Guide: Registers, Function Codes and Common Mistakes
In this article
  1. Data model: four tables
  2. Commonly used function codes
  3. RTU and TCP: two frames
  4. The three mistakes that cost the most time
  5. Polling and data quality
  6. Security
  7. Bringing Modbus data into a modern architecture

Modbus has been in use since 1979 and still lives in countless meters, drives, sensors and PLCs in the field. It is popular for its simplicity, but that simplicity also means it carries no meaning for the data. This guide collects what you need to know when working with Modbus.

Data model: four tables

TableSizeAccessTraditional address
Coils1 bitRead/write0xxxx
Discrete inputs1 bitRead-only1xxxx
Input registers16 bitRead-only3xxxx
Holding registers16 bitRead/write4xxxx

Commonly used function codes

CodeFunction
01 / 02Read coils / discrete inputs
03 / 04Read holding / input registers
05 / 06Write single coil / single register
15 (0x0F) / 16 (0x10)Write multiple coils / registers

The amount readable in one request is limited: up to 125 registers for holding and input registers and up to 2000 bits for coils. When reading many tags you need to group requests with these limits, and the device’s own limits, in mind.

RTU and TCP: two frames

Modbus RTU runs over serial lines (RS-485/RS-232). A frame consists of a 1-byte device address, a 1-byte function code, data and a 2-byte CRC16 (low byte sent first). Frames are separated by silent intervals, so wiring, termination resistors and baud/parity settings are critical.

Modbus TCP runs over Ethernet (default port 502). There is no CRC; TCP provides integrity. A 7-byte MBAP header comes first: transaction ID (2 bytes), protocol ID (2 bytes, 0), length (2 bytes) and unit ID (1 byte). The unit ID is used to address serial devices behind a gateway.

To build and verify frames by hand, you can use the Modbus Frame Builder in the IT Hub.

The three mistakes that cost the most time

1. Address shift (0-based or 1-based?)

If the device manual says “40001”, at the protocol level this is usually holding register, address 0. But some manuals count addresses from 1 and others from 0. If the value you read looks “one register off”, check this first.

2. 32-bit and floating-point values

Registers are 16 bits; a 32-bit integer or float spans two registers. The word order of the two registers (which is the high word) and the byte order within each register vary by vendor: ABCD, CDAB, BADC, DCBA. The wrong choice produces nonsensical but “plausible-looking” numbers. The PLC Data Type Converter is handy for seeing these combinations.

3. Scaling and units

Modbus carries no unit or decimal information. Is “742” 74.2 °C or 742? That information comes from the device documentation and must be written down somewhere. Otherwise every consumer makes its own interpretation.

Polling and data quality

Modbus is request-response; devices do not send data on their own, so the client polls periodically. Set the scan interval according to the device’s response time and line speed; polling too often strains both the line and the device. Define timeout and retry behavior, and keep a quality value that distinguishes “last valid value” from “read failed”.

Security

Modbus has no authentication or encryption; anyone with network access can read and write. Modbus networks must therefore be segmented, write access restricted and gateways placed at controlled points.

Bringing Modbus data into a modern architecture

Before sharing Modbus data with analytics or the cloud, scaling, units and meaning must be added. In HighByte Intelligence Hub, Modbus TCP devices can be reached through an OPC UA gateway; the data can be modeled once and published consistently to targets such as OPC UA, MQTT or SQL. For the broader connectivity architecture, see our Industrial IoT & Connectivity solution page.