MODBUS

Modbus Tutorial: RTU, TCP, Registers and Function Codes Explained

How Modbus really works: the four data tables, the function codes you will use, why 40001 is offset 0, what an RTU and a TCP frame contain, and how to fault-find a link.

By EDWartens engineering team 22 January 2026 Updated 5 October 2026 6 min
Modbus Tutorial: RTU, TCP, Registers and Function Codes Explained

Modbus is a simple request and response protocol: a client (once called the master) asks a server (the slave) to read or write numbered bits and 16-bit registers. Modbus RTU carries it over serial RS-485; Modbus TCP carries it over Ethernet. Learn the four data areas, a handful of function codes and zero-based addressing, and you can connect almost anything. This Modbus tutorial covers each of those, then the frames, the wiring and fault finding.

“How does Modbus Communication Protocol Work?” by RealPars, 12 min. Played from the creator's own YouTube channel; the video belongs to them.

In this lesson by RealPars, the protocol is introduced from the ground up, including the difference between serial and TCP. Watch it first, then use the notes below as the written companion.

Why Modbus is still everywhere

Modicon published Modbus in 1979 for its PLCs. It spread because it is simple, openly documented and cheap to implement; the Modbus Organization still publishes the specifications free of charge. Today you meet it on energy meters, drives, temperature controllers, flow computers, gateways, solar inverters and almost every PLC and SCADA package. It is rarely the newest option on a project, but it is very often the one every device supports.

Modbus tutorial: the four data areas

Every Modbus device exposes its data as up to four tables.

The four Modbus data areas
The four Modbus data areas
  • Coils are single read/write bits, such as a run command.
  • Discrete inputs are single read-only bits, such as a limit switch state.
  • Input registers are read-only 16-bit words, such as a measured value.
  • Holding registers are read/write 16-bit words, such as a setpoint. Many devices put everything in holding registers, so function code 03 is the one you will use most.

A 16-bit register holds 0 to 65,535 (or minus 32,768 to 32,767 signed). Larger or fractional values span two registers, as a 32-bit integer or an IEEE 754 float.

Function codes you will actually use

  • 01 Read Coils
  • 02 Read Discrete Inputs
  • 03 Read Holding Registers
  • 04 Read Input Registers
  • 05 Write Single Coil
  • 06 Write Single Register
  • 15 Write Multiple Coils
  • 16 Write Multiple Registers

If a device receives a code it does not support, or an address it does not have, it replies with an exception response: the function code with its top bit set, plus an exception code such as 02 (illegal data address). Seeing exception 02 almost always means your address is off.

Addressing: the off-by-one that catches everyone

Device manuals often list registers as 40001, 40002 and so on. The leading 4 says "holding register", and the rest counts from 1. On the wire, though, the request carries a zero-based offset. So 40001 is offset 0, and 40108 is offset 107.

Some software wants the 4xxxx number, some wants the offset, and some wants the offset plus one. When a value comes back as the neighbour of what you expected, you are one register out. Write the map down in both forms before you start.

What goes on the wire

Modbus RTU

An RTU frame is: the server's address (1 byte), the function code (1 byte), the data, and a 2-byte CRC. Frames are separated by a silent gap of at least 3.5 character times. To read two holding registers starting at offset 0 from device 3, the client sends 03, 03, 00 00, 00 02, followed by the two CRC bytes. The server answers with its address, the function code, a byte count of 4, the four data bytes and its own CRC.

Modbus TCP

Modbus TCP drops the CRC, because TCP already checks data, and adds a 7-byte header called the MBAP header: a transaction ID, a protocol ID of zero, a length, and a unit ID. The unit ID matters when a gateway sits between Ethernet and serial devices: it tells the gateway which RTU device to forward the request to. The standard port is 502.

Modbus ASCII

A serial variant that sends each byte as two readable characters with an LRC check. It is rare today; you may meet it on older equipment.

RS-485 wiring in brief

Modbus RTU usually runs on RS-485: a two-wire differential pair, daisy-chained from device to device, not wired as a star. Fit a termination resistor (typically 120 ohms) at each end of the line, not at every device, and make sure the line has biasing so it sits in a known state when nobody is talking. Keep a common reference where devices require it. Every device on the bus must use the same baud rate, parity and stop bits, and each needs a unique address from 1 to 247. On a drive these are ordinary parameters, set during VFD start-up and parameter setup. Our RS-485 wiring guide goes further on termination, biasing, A/B naming and cable length.

Serial or TCP?

Use TCP when devices already have Ethernet and you want speed, many simultaneous connections or easy diagnostics; you will need to plan IP addresses, which our guide to subnetting for PLC and OT networks covers. Use RTU for simple field devices, long runs of cheap cable and places where adding a switch is awkward. Gateways convert between the two, which is how many SCADA systems reach older serial meters.

Fault finding

When a Modbus link will not talk
When a Modbus link will not talk

Most Modbus problems are one of four things: wiring, serial settings, the device address, or the register offset. Work through them in that order. A free Modbus simulator on a laptop lets you play either role, client or server, and a protocol analyser such as Wireshark shows exactly what is being sent over TCP. If you prefer code, PyModbus implements both client and server for RTU and TCP in Python. Once one register reads correctly, the rest of the map usually falls into place. To see the whole process in ten minutes, follow Modbus TCP explained by doing.

Security

Classic Modbus has no authentication and no encryption: anything that can reach port 502 can write a holding register. The Modbus Organization publishes a Modbus Security protocol that wraps Modbus in TLS with X.509 certificates on port 802, but most devices in service use plain Modbus. Keep Modbus inside protected network zones and never expose it to the internet. For how Modbus compares with a secure, modelled protocol, see OPC UA explained.

Practise Modbus free

Industrial Communication covers RS-485, Modbus RTU, ASCII and TCP in depth, with S7-1200 client and server practice and Modbus on other PLC families. Node-RED for Industrial IoT reads Modbus devices into dashboards, Industrial Data with Python reads them from Python with pymodbus, and VFDs is where you will most often write a Modbus map for real. Learning is free in full. Industrial Communication is an intermediate course: if you pass its final assessment, the optional EDWartens Certificate of Completion is a small one-off fee, and checkout shows your price. It is verifiable at edwartens.com/verification and is not a vendor certification.

Take the free course

Questions

What is the difference between Modbus RTU and Modbus TCP?

Modbus RTU sends compact binary frames over a serial line, usually RS-485, with a device address and a CRC check. Modbus TCP carries the same requests over Ethernet inside a TCP connection, normally on port 502, with a small header instead of the CRC.

Why does register 40001 mean address 0?

The 4xxxx numbers are a documentation convention: the first digit names the data area and the rest count from 1. On the wire, requests use a zero-based offset, so holding register 40001 is offset 0 and 40100 is offset 99.

How do I read a 32-bit float over Modbus?

Read two consecutive holding registers and combine them. Devices differ on which register holds the high word, so if the value looks wrong, swap the word order before assuming the data is bad.

Is Modbus secure?

Classic Modbus has no authentication or encryption. The Modbus Organization publishes a Modbus Security protocol that adds TLS on port 802, but most installed devices use plain Modbus, so keep it inside protected network zones.

How many devices can be on one Modbus RTU network?

Modbus addresses run from 1 to 247, with 0 used for broadcast. The practical limit on one RS-485 segment is usually set by the electrical load of the transceivers, commonly 32 standard unit loads without repeaters.

Sources

Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.