Skip to content

Modbus TCP ​

Modbus TCP is a version of the Modbus protocol based on Ethernet, which uses TCP/IP for communication. Unlike the traditional Modbus RTU protocol, Modbus TCP allows devices to be interconnected directly through Ethernet without any special hardware or communication interface. Compared with Modbus RTU, this gives it a higher communication speed and a wider range of applications.

For the generic steps, see Create a Southbound Driver and Groups and Tags.

For measured tag counts and polling intervals, see Modbus TCP Driver Performance.

In addition to supporting data acquisition and processing via TCP client mode, the EMQX Neuron Modbus TCP driver also supports TCP server mode, which allows devices to connect to EMQX Neuron actively. This feature is mainly used for 4G DTU because the IP address of 4G network is a private IP. In this case, the DTU device can only connect to EMQX Neuron actively.

Add Driver ​

On Data Collection → South Devices, click Add Device.

  • Name: The name of this device node.
  • Driver: Select the Modbus TCP or Modbus TCP QH driver.
DriverDescription
Modbus TCPStandard Modbus TCP protocol implementation supports both TCP client and server modes, providing better compatibility with devices.
Modbus TCP QHCustomized Modbus TCP protocol implementation supports a maximum of 65530 bytes for one read operation, while the standard protocol only allows a maximum of 250 bytes to be read at a time.

Connection Parameters ​

Click the driver card to open the Device Configuration page and fill in:

ParameterDescription
Connection ModeChoose whether EMQX Neuron acts as the TCP client or the TCP server.
Maximum Retry TimesThe maximum number of retries after a failed attempt to send a read command.
Retry IntervalResend reading instruction interval(ms) after a failed attempt to send a read command.
4-byte EndiannessByte order of tags with 32 bits, ABCD corresponds to 1234.
8-byte EndiannessByte order of tags with 64 bits, with each number representing one byte.
Start AddressAddress starts from 1 or 0.
Send IntervalThe waiting time between sending each read/write command. Some serial devices may discard certain commands if they receive consecutive commands in a short period of time.
IP AddressThe IP address of the device when using TCP connection with EMQX Neuron as the client, or the IP address of EMQX Neuron when using TCP connection with EMQX Neuron as the server. The default value is 0.0.0.0.
PortThe port number of the device when using TCP connection with EMQX Neuron as the client, or the port number of EMQX Neuron when using TCP connection with EMQX Neuron as the server.
Connection TimeoutThe time the system waits for a device to respond to a command.
Enable 0x16Enable or disable the 0x16 function.
Check HeaderChoose whether to verify the message header. After selecting True, when encountering packet header errors, the neuron and device will reconnect.
Device DegradationEnable or disable device degradation mechanism.
Failure Threshold for DegradationThe number of consecutive failure cycles required to trigger device degradation.
Recovery Time After DegradationThe time in seconds after which the device recovers from degradation.
Backup IP AddressOptional, when the connection is abnormal, it will automatically connect to the backup address. If the backup address connection is abnormal, it will automatically connect to the original address.
Backup PortOptional, when the connection is abnormal, it will automatically connect to the backup address. If the backup address connection is abnormal, it will automatically connect to the original address.

TIP

The above configuration can meet the individualized needs of the device:

  1. Retry requests are considered as the same request, i.e., a successful retry is regarded as a successful request.
  2. In the same read cycle, if a certain tag under a slave id does not receive a response, requests for other tags under the same slave id in that cycle will be skipped.
  3. The device degradation is triggered when a certain tag under a slave id fails to respond for multiple consecutive cycles (or can be configured to trigger after just one failed cycle). Once triggered, all requests for that slave will be stopped for the configured period.

Tag Configuration ​

The data types and address formats supported by this driver are listed below.

Data types ​

  • INT16
  • UINT16
  • INT32
  • UINT32
  • INT64
  • UINT64
  • FLOAT
  • DOUBLE
  • BIT
  • STRING
  • BYTES

Address format ​

SLAVE!ADDRESS[.BIT][#ENDIAN][.LEN[H][L][D][E]][.BYTES]

SLAVE ​

Required, Slave is the slave address or site number.

ADDRESS ​

Required, Address is the register address. The Modbus protocol has four areas, each area has a maximum of 65536 registers, and the address range of each area is shown in the table below. In practice a storage area that large is rarely needed: most PLC vendors use addresses below 10000. Enter the address that matches the area and function code of the device.

AreaAddress RangeAttributeRegister SizeFunction CodeData Type
Coil000001 ~ 065536Read/Write1Bit0x01, 0x05, 0x0fBIT
Input100001 ~ 165536Read1Bit0x02BIT
Input Register300001 ~ 365536Read16Bit,2Byte0x04BIT, INT16, UINT16,
INT32, UINT32, INT64,
UINT64, FLOAT,
DOUBLE, STRING
Hold Register400001 ~ 465536Read/Write16Bit,2Byte0x03, 0x06, 0x10BIT, INT16, UINT16,
INT32, UINT32, INT64,
UINT64, FLOAT,
DOUBLE, STRING

.BIT ​

Optional, specify a specific bit in a register

AddressData TypeDescription
1!300004.0bitRefers to station 1, input register area, address 300004, bit 0
1!400010.4bitRefers to station 1, hold register area, address 400010, bit 4
2!400001.15bitRefers to station 2, hold register area, address 400001, bit 15

#ENDIAN ​

Optional, byte order, applicable to data types int16/uint16/int32/uint32/float, see the table below for details.

SymbolByte OrderSupported Data TypesNote
#B2,1int16/uint16
#L1,2int16/uint16Default byte order if not specified
#LL1,2,3,4int32/uint32/floatDefault byte order if not specified
#LB2,1,4,3int32/uint32/float
#BL3,4,1,2int32/uint32/float
#BB4,3,2,1int32/uint32/float

Byte order also applies to int64/uint64/double data types. Each digit represents one byte. See the following table for detailed information.

SymbolByte OrderSupported Data TypesNote
#LL12,34,56,78int64/uint64/doubleDefault byte order if not specified
#LB21,43,65,87int64/uint64/double
#BL78,56,34,12int64/uint64/double
#BB87,65,43,21int64/uint64/double

TIP

The byte order of a tag has a higher priority than the byte order configuration of a node. That is to say, once the byte order is configured for a tag, it follows the configuration of that tag and ignores the node configuration. The byte order can be illustrated using the notation ABCD, which corresponds directly to the sequence 1234. As an example, the ABCD designation represents the standard or default Endianness 1234. (#LL).

.LEN[H][L][D][E] ​

When the data type is STRING, .LEN is a required field, indicating the number of bytes the string occupies. Each register contains four storage methods: H, L, D, and E, as shown in the table below.

SymbolDescription
HOne register stores two bytes, with the high byte first
LOne register stores two bytes, with the low byte first
DOne register stores one byte, and it is stored in the low byte
EOne register stores one byte, and it is stored in the high byte

.BYTES ​

Optional, read and write the length of bytes type data, applicable to bytes data type.

TIP

A register of the Modbus driver contains 2 bytes. When reading and writing Modbus register data in the bytes data type, please ensure that the bytes parameter is set to an even number.

Example Addresses ​

AddressData TypeDescription
1!300004int16Refers to station 1, input register area, address 300004, byte order #L
1!300004#Bint16Refers to station 1, input register area, address 300004, byte order #B
1!300004#Luint16Refers to station 1, input register area, address 300004, byte order #L
1!400004int16Refers to station 1, hold register area, address 400004, byte order #L
1!400004#Lint16Refers to station 1, hold register area, address 400004, byte order #L
1!400004#Buint16Refers to station 1, hold register area, address 400004, byte order #B
1!300004int32Refers to station 1, input register area, address 300004, byte order #LL
1!300004#BBuint32Refers to station 1, input register area, address 300004, byte order #BB
1!300004#LBuint32Refers to station 1, input register area, address 300004, byte order #LB
1!300004#BLfloatRefers to station 1, input register area, address 300004, byte order #BL
1!300004#LLint32Refers to station 1, input register area, address 300004, byte order #LL
1!400004int32Refers to station 1, hold register area, address 400004, byte order #LL
1!400004#LBuint32Refers to station 1, hold register area, address 400004, byte order #LB
1!400004#BBuint32Refers to station 1, hold register area, address 400004, byte order #BB
1!400004#LLint32Refers to station 1, hold register area, address 400004, byte order #LL
1!400004#BLfloatRefers to station 1, hold register area, address 400004, byte order #BL
1!300001.10StringRefers to station 1, input register area, address 300001, character length 10, byte order L, which occupies addresses 300001 to 300005
1!300001.10HStringRefers to station 1, input register area, address 300001, character length 10, byte order H, which occupies addresses 300001 to 300005
1!300001.10LStringRefers to station 1, input register area, address 300001, character length 10, byte order L, which occupies addresses 300001 to 300005
1!400001.10StringRefers to station 1, hold register area, address 400001, character length 10, byte order L, which occupies addresses 400001 to 400005
1!400001.10HStringRefers to station 1, hold register area, address 400001, character length 10, byte order H, which occupies addresses 400001 to 400005
1!400001.10LStringRefers to station 1, hold register area, address 400001, character length 10, byte order L, which occupies addresses 400001 to 400005
1!400001.10DStringRefers to station 1, hold register area, address 300001, character length 10, byte order D, which occupies addresses 400001 to 400005
1!400001.10EStringRefers to station 1, hold register area, address 300001, character length 10, byte order E, which occupies addresses 400001 to 400005

Use Case ​

This chapter also provides practical examples to facilitate a quick start.