Baud
All protocols

Modbus RTU

The factory-floor classic: address, function code, data, CRC, over RS-485.

Request: read two registers

The master asks slave 1 for two holding registers. The CRC is computed for real; step through each field.

Modbus RTU request · read 2 registers0010000000103000000110000000000000000000000000000000200000010C4110001000B00001011Slave add…Function …Starting addressQuantityCRC-16Click a field to inspect it

Whole frame

8 bytes: 01 03 00 00 00 02 C4 0B. No start/end markers: the frame is delimited by silence of at least 3.5 character times before and after it.

FieldOffsetExample valueMeaning
Slave addressByte 00x01 = 1Which device should answer: 1–247 (0 is broadcast, nobody replies). Every device on the RS-485 pair hears the frame; only address 1 acts on it.
Function codeByte 10x03 = Read Holding RegistersWhat to do. 0x03 = Read Holding Registers. Others: 0x01 read coils, 0x04 read input registers, 0x06 write one register, 0x10 write many registers.
Starting addressByte 2–30x0000 = register 0 (documented as 40001)The first register to read, counted from 0 on the wire. Documentation often prints it as 40001 (the 4xxxx range means holding registers), which is address 0 here.
QuantityByte 4–52 registersHow many consecutive 16-bit registers to read: 1–125.
CRC-16Byte 6–70x0BC4 (sent low byte first)A CRC-16 over every byte before it (initial value 0xFFFF, polynomial 0xA001). Quirk: it is sent low byte first, so the value 0x0BC4 appears as C4 0B on the wire. A receiver that computes a different CRC discards the frame silently.

Overview

Modbus (1979) is the lingua franca of industrial devices: power meters, inverters, temperature controllers, PLCs. The RTU variant sends compact binary frames over a serial line, usually RS-485 so many slaves can share one twisted pair over hundreds of metres.

A master polls; slaves only answer. Data lives in numbered 16-bit registers, so 'reading the temperature' means reading register N. There is no frame marker: a pause of 3.5 character times separates frames, and a CRC proves the content.

Key facts

Physical layer
RS-485 (or RS-232)
Framing
UART, 8E1 or 8N2 typical
Typical speeds
9600 / 19200 baud
Addresses
1 – 247
Max frame
256 bytes
Error check
CRC-16 (low byte first)

Response

The slave echoes address and function, says how many bytes follow, and returns the values.

Modbus RTU response · 2 registers0801000000010300000011040000010000000000000A0000101000000000001400010100DA110110103E00111110Slave add…Function …Byte countRegister 0Register 1CRC-16Click a field to inspect it

Whole frame

9 bytes: 01 03 04 00 0A 00 14 DA 3E. The slave answers only when asked; it never speaks first.

FieldOffsetExample valueMeaning
Slave addressByte 00x01 = 1The responder echoes its own address so the master knows who is speaking.
Function codeByte 10x03Echoed from the request. If something went wrong, the slave sets the top bit (0x83) and sends an exception instead.
Byte countByte 24How many data bytes follow: 2 registers × 2 bytes = 4.
Register 0Byte 3–40x000A = 10Value of register 0, big-endian (high byte first). Say it is a temperature in tenths of a degree: 10 = 1.0 °C.
Register 1Byte 5–60x0014 = 20Value of register 1, big-endian: 0x0014 = 20.
CRC-16Byte 7–80x3EDA (sent low byte first)A CRC-16 over every byte before it (initial value 0xFFFF, polynomial 0xA001). Quirk: it is sent low byte first, so the value 0x3EDA appears as DA 3E on the wire. A receiver that computes a different CRC discards the frame silently.

When something goes wrong

An error reply is only five bytes. The top bit of the function code is the flag.

Modbus RTU exception response0010000000183100000110200000010C011000000F111110001Slave add…Function …Exception…CRC-16Click a field to inspect it

Whole frame

An error is a 5-byte frame: the function code with its top bit set, then a one-byte reason.

FieldOffsetExample valueMeaning
Slave addressByte 00x01Same slave answering.
Function code + 0x80Byte 10x83 = 0x03 | 0x800x03 with the top bit set = 0x83. That single bit is how the master tells an error from a normal reply.
Exception codeByte 20x02 = Illegal Data AddressWhy it failed. 0x01 illegal function, 0x02 illegal data address (the register does not exist), 0x03 illegal data value, 0x04 device failure.
CRC-16Byte 3–40xF1C0 (sent low byte first)A CRC-16 over every byte before it (initial value 0xFFFF, polynomial 0xA001). Quirk: it is sent low byte first, so the value 0xF1C0 appears as C0 F1 on the wire. A receiver that computes a different CRC discards the frame silently.

One poll cycle

Turn-taking on a single shared pair.

MasterPLC / PCSlave 1temperature sensorRequest01 03 00 00 00 02Response01 03 04 00 0A 00 14IDLEIDLEPROCESSDONEIDLE

Whole exchange

Strict master/slave: the master asks, one slave answers, the line goes quiet. All timing is decided by silence on the wire.

  1. 1Master asks

    The master sends the 8-byte request on the shared RS-485 pair. Every slave hears it, but only the one whose address matches processes it. The others wait out the frame.

  2. 2Slave answers

    After at least 3.5 character times of silence, the slave sends its 9-byte reply. Master and slaves take turns on the single pair: the half-duplex line is never driven by two at once.

Where you meet it

  • Energy meters, solar inverters, heat pumps
  • PLCs, temperature controllers, motor drives
  • Modbus TCP wraps the same function codes in a TCP packet (no CRC, a 7-byte header instead)

Watch out for

  • Register numbering is a mess: 40001 in the manual is address 0 on the wire. Check whether your tool is 0-based or 1-based.
  • The CRC goes out low byte first, while all register data goes out high byte first.
  • RS-485 needs termination (120 Ω) and biasing at the ends of the line, and the direction pin on the transceiver must be switched fast enough.

Standards

  • Modbus Application Protocol Specification V1.1b3
  • Modbus over Serial Line Specification V1.02

Related protocols