QUICK REFERENCE
MODBUS RTU CHEAT SHEET
Print this. Tape it to the bench. Stop guessing.
1. THE FOUR DATA TYPES
| Type | Size | Access | Function codes |
|---|---|---|---|
| Coils | 1 bit | R/W | 0x01 read · 0x05 write1 · 0x0F writeN |
| Discrete Inputs | 1 bit | R only | 0x02 |
| Holding Registers | 16 bits | R/W | 0x03 read · 0x06 write1 · 0x10 writeN |
| Input Registers | 16 bits | R only | 0x04 |
2. FUNCTION CODES
- 0x01Read Coils
- 0x02Read Discrete Inputs
- 0x03Read Holding Registers
- 0x04Read Input Registers
- 0x05Write Single Coil
- 0x06Write Single Register
- 0x0FWrite Multiple Coils
- 0x10Write Multiple Registers
- FC + 0x80Exception response (e.g. 0x83 = exception on 0x03)
3. ADDRESSING PREFIX → WIRE ADDRESS
| Prefix | Data type | Convert |
|---|---|---|
| 0xxxx (1–9999) | Coils | subtract 1 |
| 1xxxx (10001–19999) | Discrete Inputs | subtract 10001 |
| 3xxxx (30001–39999) | Input Registers | subtract 30001 |
| 4xxxx (40001–49999) | Holding Registers | subtract 40001 |
⚠ Documented "register 40001" = wire address 0. Off-by-one is the #1 Modbus bug.
4. PACKET STRUCTURE
Slave Addr
1 B
Func Code
1 B
Data
N B
CRC
2 B (lo, hi)
Max RTU frame = 256 bytes. Silent interval ≥ 3.5 char times marks end.
5. EXCEPTION CODES
- 0x01Illegal Function — device doesn't support that FC
- 0x02Illegal Data Address — register doesn't exist
- 0x03Illegal Data Value — value out of range
- 0x04Slave Device Failure — internal error
- 0x05Acknowledge — accepted, will take time
- 0x06Slave Device Busy — retry later
- 0x08Memory Parity Error
- 0x0AGateway Path Unavailable
- 0x0BGateway Target Failed
6. 32-BIT VALUES OVER MODBUS
A 32-bit float/int spans TWO 16-bit registers. Vendors disagree on byte order:
- ABCD — Big-endian (most common, Schneider)
- CDAB — Word-swap big-endian (Modicon legacy)
- BADC — Byte-swap big-endian
- DCBA — Little-endian (rare)
If reading 3.14 gives 0.00 — try CDAB. Always verify against device HMI.
7. COMMON PITFALLS
- Off-by-one addressing — forgot to subtract the 40001/30001/etc prefix.
- Missing termination resistor — 120Ω at BOTH ends of an RS-485 bus.
- Baud / parity / stop-bit mismatch — every device on the bus must agree.
- Two masters on one bus — Modbus RTU is strictly single-master.
- Master timeout shorter than slave's worst-case response — causes retry storms.
8. QUICK DIAGNOSIS
| Symptom | Likely cause |
|---|---|
| No response, ever | Baud/parity mismatch · wrong slave ID · cable |
| Sometimes works | Termination missing · electrical noise · shield grounding |
| Exception 0x02 | Off-by-one address · register doesn't exist |
| Exception 0x03 | Value out of range for that register |
| Reads wrong float value | Word/byte order mismatch (try CDAB) |
| Works for one slave, not another | Slave-specific address offset · documentation lies |
| Garbled bytes / collisions | Two masters on the bus |
| CRC errors | Termination · shielding · noise |
tryplc.com · Modbus Dojo · v1