Skip to Content
Modbus & RS-485What is Modbus?

What Is Modbus? Modbus RTU and Modbus TCP Explained for BMS Engineers

Modbus is a simple, open master-slave protocol for reading and writing device registers, used on RS-485 (Modbus RTU) and Ethernet (Modbus TCP).

Modbus is the most common protocol on energy meters, variable speed drives, boilers, heat pumps, chillers, generators and I/O modules. It is old, simple and everywhere, which is exactly why BMS engineers need to understand it well. This guide covers how Modbus works, the difference between RTU and TCP, registers and function codes, the addressing and data type traps that waste days on site, and how Modbus is integrated into Niagara 4.

A short history of Modbus

Modbus was published by Modicon in 1979 for its programmable logic controllers. Its specification was openly available and royalty-free, so manufacturers adopted it widely. Today the protocol is maintained by the Modbus Organization, but the core has barely changed in four decades. A modern energy meter speaks essentially the same Modbus as a 1980s PLC.

That stability is both its strength and its weakness. Modbus is easy to implement and almost universally supported, but it carries no information about what a value means: no units, no names, no alarms. The meaning lives in each manufacturer's register map document.

How Modbus works: client and server (master and slave)

Modbus uses a request-response model:

  • One device, the client (traditionally called the master), sends requests. In a BMS this is usually the JACE, IONA or other supervisory controller.
  • Other devices, the servers (traditionally slaves), respond. Meters, drives and plant controllers are servers.

A server never speaks unless asked. The client polls each server in turn, reading and writing values. This makes Modbus predictable and easy to troubleshoot, but it means data is only as fresh as the poll rate allows.

Modbus RTU vs Modbus TCP

Modbus RTU Modbus TCP
Physical layer RS-485 serial (sometimes RS-232) Ethernet / IP
Addressing Unit ID 1–247 on the bus IP address (+ unit ID, usually 1 or 255)
Port Serial port settings TCP port 502
Speed Typically 9,600 to 115,200 bit/s Network speed
Error checking CRC-16 TCP/IP checksums
Masters per network One Many clients can connect to one server
Cable Twisted pair, daisy chain Standard network cabling
Typical devices Meters, drives, boilers, I/O modules Larger plant controllers, meter gateways, I/O

Modbus RTU

Modbus RTU sends compact binary frames over RS-485. Devices share a two-wire bus (plus a reference conductor) in a daisy chain, each with a unique unit ID (slave address) from 1 to 247. All devices must share the same serial settings:

  • baud rate (9,600 and 19,200 are most common)
  • data bits (8)
  • parity (none, even or odd)
  • stop bits (1 or 2; with no parity, 2 stop bits is the strict standard but many devices use 1)

A single mismatched setting stops a device responding entirely. Wiring, termination and biasing matter just as much: see RS-485 wiring, termination and biasing.

Modbus TCP

Modbus TCP wraps the same messages in a TCP/IP packet and sends them over Ethernet to port 502. It is faster, needs no serial settings, and lets several clients talk to one device. Many sites combine both with a Modbus TCP to RTU gateway, which lets an IP client reach serial devices behind it; the gateway uses the unit ID to route each request to the right serial device.

Modbus ASCII

A third variant, Modbus ASCII, sends data as text characters. It is rare in modern buildings, but some older devices still offer it.

Modbus registers: the four data tables

Every Modbus device exposes its data in four tables:

Table Access Size Traditional address range Typical use
Coils Read/write 1 bit 0xxxx (00001–09999) Start/stop commands, enable flags
Discrete inputs Read only 1 bit 1xxxx (10001–19999) Status and alarm bits
Input registers Read only 16 bit 3xxxx (30001–39999) Measurements: voltage, temperature, energy
Holding registers Read/write 16 bit 4xxxx (40001–49999) Setpoints, configuration, and often measurements too

Many devices put everything in holding registers, regardless of whether a value is read-only. The register map will tell you which table each value is in.

Modbus function codes

The client tells the server what it wants with a function code:

Code Function
01 Read coils
02 Read discrete inputs
03 Read holding registers
04 Read input registers
05 Write single coil
06 Write single register
15 (0x0F) Write multiple coils
16 (0x10) Write multiple registers

If the server cannot do what was asked, it replies with an exception code: 01 illegal function, 02 illegal data address, 03 illegal data value, 04 server device failure. Exception 02 is the one you will see most, and it nearly always means the register address is wrong.

The addressing trap: off-by-one errors

The single most common Modbus problem on site is an address offset. Register maps are written in two conventions:

  • Register numbers such as 40001, which include the table prefix and start at 1
  • Protocol addresses such as 0 or 0x0000, which are what is actually sent on the wire and start at 0

So "holding register 40001" is protocol address 0, and "40101" is address 100. If you enter the wrong convention, you read the register next door: a plausible-looking but wrong number, which is worse than an error. Always test one known value, such as a meter's voltage, against its display before configuring the rest.

Data types: 16-bit, 32-bit and 64-bit values

A Modbus register holds 16 bits. Larger values are spread across consecutive registers:

Data type Registers Range or use
Unsigned 16-bit integer 1 0–65,535
Signed 16-bit integer 1 −32,768 to 32,767
32-bit integer (signed/unsigned) 2 Energy totals, large counters
32-bit float (IEEE 754) 2 Most meter readings
64-bit integer or double 4 High-resolution energy totals

Byte and word order

Manufacturers do not agree on the order of the registers that make up a 32-bit or 64-bit value. A float might be sent high word first ("big-endian") or low word first ("word-swapped"). If a value reads as nonsense such as 1.2E-38 or 3.4E+12, try swapping the word order. Niagara's Modbus driver lets you set this per point. Reading 64-bit registers has its own considerations, covered in how to read a 64-bit register in Niagara 4.

Scaling

Integers are often scaled. A temperature of 21.5 °C may be sent as 215 with a scale of 0.1. The register map gives the scale; apply it in the point's conversion.

Worked example: reading an energy meter

A typical three-phase energy meter's register map might include:

Value Register (map) Protocol address Table Data type Units
Phase 1 voltage 30001 0 Input registers 32-bit float V
Phase 1 current 30007 6 Input registers 32-bit float A
Total active power 30053 52 Input registers 32-bit float W
Total import energy 30073 72 Input registers 32-bit float kWh

To read total active power you would configure a point that reads input registers (function code 04) starting at protocol address 52, two registers long, decoded as a 32-bit float, with the word order the manufacturer specifies. Check it against the meter's display. If the meter shows 12.4 kW and Niagara shows 12,400, the units are watts and you scale by 0.001; if Niagara shows a tiny or enormous number, swap the word order.

This example is illustrative; every meter's map is different, which is exactly why the first rule of Modbus is to work from the manufacturer's document for that model and firmware.

Modbus performance: read in blocks

Each Modbus request carries overhead, especially on a slow serial line. Reading 40 values with 40 separate requests can take many times longer than reading them in one or two blocks of consecutive registers. A Modbus read can return up to 125 registers per request.

Good practice:

  • read consecutive registers together where the device allows it
  • avoid gaps that force extra requests, but do not read huge unused ranges either
  • poll slowly changing values (energy totals, configuration) less often than fast-changing ones
  • spread heavy devices across several RS-485 ports

Niagara's Modbus drivers can group points into block reads; combined with sensible poll scheduler settings this makes a large difference on busy trunks.

Modbus in Niagara 4

Niagara 4 includes Modbus drivers for both variants:

  • ModbusAsyncNetwork for Modbus RTU and ASCII on a serial port
  • ModbusTcpNetwork for Modbus TCP

The workflow:

  1. Add the network and set the serial port settings (RTU) or check IP connectivity (TCP).
  2. Add a device for each server with its unit ID (and IP address for TCP).
  3. Add proxy points for each register, choosing the table, address, data type, word order and scaling.
  4. Test against the device's own display or software.
  5. Tune polling with the poll scheduler and tuning policies.

See how Niagara point types translate to Modbus register types for choosing the right proxy point, and how many Modbus networks a JACE supports and how many devices fit on a Modbus network for sizing. LAB 04 in the Niagara 4 TCP videos walks through Modbus integration on screen.

Modbus troubleshooting checklist

No response from any device (RTU). Check the serial port is the right one, settings match, A/B polarity is correct (manufacturers label A and B inconsistently, so try swapping), and the bus is terminated and biased.

One device not responding (RTU). Wrong unit ID, a duplicate unit ID elsewhere on the bus, or mismatched serial settings on that device.

Timeout on Modbus TCP. Check IP connectivity, that port 502 is not blocked, and that the device's unit ID matches. Some devices only accept a limited number of simultaneous TCP connections.

Exception 02 (illegal data address). The register address is wrong (check the 0/1 offset) or the table is wrong (input vs holding).

Values are wrong but plausible. Address off by one, wrong scale, or wrong data type.

Values are wildly wrong. Word order or data type mismatch on 32-bit or 64-bit values.

Values update slowly. Too many points on a slow serial bus. Read consecutive registers in blocks, poll slowly changing values less often, raise the baud rate if all devices support it, or split the bus across more ports.

Modbus products

Tyrrell Products supplies Modbus integration hardware for UK BMS projects, including Modbus I/O modules, Modbus to BACnet gateways and Modbus TCP gateways in the integration gateway range, the Modbus booster RS-485 signal amplifier, and Niagara 4 controllers with multiple RS-485 ports.

Frequently asked questions

What is Modbus used for in building automation?

Modbus connects energy meters, variable speed drives, boilers, heat pumps, chillers, generators and I/O modules to the BMS so their readings and commands can be monitored and controlled.

What is the difference between Modbus RTU and Modbus TCP?

Modbus RTU sends binary frames over RS-485 serial cable using unit IDs 1–247. Modbus TCP sends the same messages over Ethernet on TCP port 502 using IP addresses. TCP is faster; RTU is cheaper to wire to many small devices.

What port does Modbus TCP use?

TCP port 502.

How many devices can be on a Modbus RTU network?

The address range allows 247 devices, but the RS-485 electrical limit is 32 unit loads per segment without repeaters, and polling speed limits practical numbers further. See how many slave devices a Modbus network supports.

Why does my Modbus value read the wrong number?

Usually an address offset (register 40001 is address 0), the wrong table, a missing scale factor, or the wrong word order on a 32-bit value.

What is a Modbus register map?

A manufacturer's document listing every value a device exposes over Modbus: its register address, table, data type, scaling and units. Without it you cannot configure Modbus points reliably.

Is Modbus secure?

Standard Modbus has no encryption or authentication. Keep Modbus networks isolated from corporate and internet-facing networks and let the BMS controller act as the secure boundary.