Skip to content

MODBUS-RTU Protocol

1 Protocol overview

Communication uses the MODBUS-RTU protocol (national standard GB/T19582-2008). One master node controls multiple slave nodes; the bundled host software can configure 247 slave addresses (0 is the broadcast address, 1-247 are unicast addresses). The master can be a microcontroller, a PLC, a PC, etc.

2 Communication parameters

Factory default serial settings: baud rate defaults to 115200bps, 8 data bits, no parity, 1 stop bit; the baud rate is configurable in the range 4800~256k0bps, and the drive's default communication address (station number) is 1.

3 modbus-rtu frame format

This drive supports modbus 0x03 (read holding registers), 0x06 (write single register), 0x10 (write multiple registers), and 0x83 (exception code); the exception codes support 0x01 (operation code error) and 0x02 (address error).

3.1 Read holding registers 0x03

Sent by the master:

Byte 1 2 3 4 5 6 7 8
Content Slave address 0x03 Register address high byte Register address low byte Read data length high byte Read data length low byte CRC high byte CRC low byte

Byte 1, slave address: slave address code (1~247) Byte 2, 0x03: read register value function code Bytes 3 and 4: start address of the registers to read Bytes 5 and 6: read data length Bytes 7 and 8: CRC16 checksum of bytes 1 to 6

Normal response from the slave:

Byte 1 2 3 4, 5 6, 7 n-1, n n+1 n+2
Content Slave address 0x03 Total register bytes Register data 1 Register data 2 ... Register data m CRC high byte CRC low byte

Byte 1, slave address: slave address code (1~247) Byte 2, 0x03: read register value function code Byte 3: total number of register bytes from 4 to n (including 4 and n) Bytes 4~n: the m register data values read, where m=(n-3)/2, n-1 is the high byte, and n is the low byte Bytes n+1 and n+2: CRC16 checksum of bytes 1 to n

Exception response from the slave:

Byte 1 2 3 4 5
Content Slave address 0x83 0x02 CRC high byte CRC low byte

3.2 Write single register 0x06

Sent by the master:

Byte 1 2 3 4 5 6 7 8
Content Slave address 0x06 Register address high byte Register address low byte Register data high byte Register byte count low byte CRC high byte CRC low byte

Byte 1, slave address: slave address code (1~247) Byte 2, 0x06: write single register function code Bytes 3 and 4: address of the register to write Bytes 5 and 6: register data to write Bytes 7 and 8: CRC16 checksum of bytes 1 to 6

Normal response from the slave:

Byte 1 2 3 4 5 6 7 8
Content Slave address 0x06 Register address high byte Register address low byte Register data high byte Register byte count low byte CRC high byte CRC low byte

Exception response from the slave:

Byte 1 2 3 4 5
Content Slave address 0x86 Exception code CRC high byte CRC low byte

Exception codes: 0x02 means the address requested by the master is invalid, 0x03 means the requested data is invalid

3.3 Write multiple registers 0x10

Sent by the master:

Byte 1 2 3 4 5 6 7 8, 9 10, 11 n-1, n n+1 n+2
Content Slave address 0x10 Register address high byte Register address low byte Register length high byte Register length low byte Total register bytes Register data 1 Register data 2 ... Register data m CRC high byte CRC low byte

Byte 1, slave address: slave address code (1~247) Byte 2, 0x03: response read function code Bytes 3 and 4: address of the registers to write; 3 is the high byte and 4 is the low byte Bytes 5 and 6: length m of the registers to write Byte 7: total number of bytes from 8 to n (including 8 and n) Bytes 8~n: the m register data values written, where m=(n-7)/2, n-1 is the high byte, and n is the low byte Bytes n+1 and n+2: CRC16 checksum of bytes 1 to n

Normal response from the slave:

Byte 1 2 3 4 5 6 7 8
Content Slave address 0x10 Register address high byte Register address low byte Register length high byte Register length low byte value CRC high byte CRC low byte

Byte 1, slave address: slave address code (1~247) Byte 2, 0x10: write multiple registers function code Bytes 3 and 4: address of the registers to write Bytes 5 and 6: register length to write Bytes 7 and 8: CRC16 checksum of bytes 1 to 6

Exception response from the slave:

Byte 1 2 3 4 5
Content Slave address 0x90 Exception code CRC high byte CRC low byte

Exception codes: 0x02 means the address requested by the master is invalid, 0x03 means the requested data is invalid

3.4 Query bus slave device ID 0x11

Sent by the master:

Byte 1 2 3 4
Content Slave address 0x11 CRC high byte CRC low byte

Byte 1, slave address: slave address code (1~247); the broadcast ID 0 may be used for the query only when a single slave device is connected to the ID bus Byte 2, 0x11: function code Bytes 3 and 4: CRC16 checksum of bytes 1 to 3

Normal response from the slave:

Byte 1 2 3 4 5 6 7 8
Content Slave address 0x17 3 Slave address Status code high byte Status code low byte CRC high byte CRC low byte

Byte 1, slave address: slave address code (1~247) Byte 2, 0x11: function code Byte 3: number of valid bytes returned Byte 4: slave address code (1~247) Bytes 6 and 7: status code Bytes 8 and 9: CRC16 checksum of bytes 1 to 6

3.5 Restart the slave device with the specified ID 0x41

Sent by the master:

Byte 1 2 3 4
Content Slave address 0x41 CRC high byte CRC low byte

Byte 1, slave address: slave address code (1~247); using 0 as the broadcast ID restarts all slave devices on the bus Byte 2, 0x41: function code Bytes 3 and 4: CRC16 checksum of bytes 1 to 3