Protocols About 2 min read

Modbus TCP

Modbus TCP carries Modbus exchanges over IP. Check the register map, network restrictions and permitted operations for the device you're connecting.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Does not define vendor register maps or claim interoperability with any product.

Verification and testing

Overview#

Modbus TCP carries each PDU behind a seven octet Modbus Application Protocol header (MBAP) over TCP, conventionally on port 502.1

text
transaction ID | protocol ID | length | unit ID | function + data
     2               2           2         1        variable

The transaction identifier correlates requests and responses. Protocol identifier is zero for Modbus. Length counts the following bytes, including unit identifier. The unit identifier is especially important when an IP endpoint fronts a downstream serial bus; it isn't a cryptographic identity.

Stream parser requirements#

TCP preserves order, not message boundaries. A parser must accept a partial MBAP header, a partial body, or multiple ADUs in one receive operation. Before allocation, validate protocol identifier and a locally configured maximum length. Consume exactly one declared ADU, and don't accept trailing bytes as part of it.

Maintain a bounded table of outstanding transaction IDs. Reject unexpected or duplicate IDs, and define behaviour for wraparound, late replies, reconnects, and a peer that reuses identifiers. Don't retry a timed out write blindly: the operation may have reached the server even if its response was lost.

Gateway semantics#

A unit ID commonly selects a device behind a bridge. Document whether the server ignores it, requires a fixed value, or routes it. Limit parallel requests to what the endpoint and downstream bus actually support. A reconnect must not replay old write queues automatically.

Keep these outcomes distinct: TCP connect failure, TCP close/reset, framing error, timeout, Modbus exception, successful protocol response, and observed physical state. Only a subsequent authoritative read or device specific completion event can support a state change claim.

Security#

Classic port 502 traffic has no built in confidentiality or peer authentication. Use Modbus Security where supported. Otherwise place the endpoint behind strict conduits, block public exposure, allowlist client/server pairs and functions, and protect the controller's management plane independently. A generic TLS tunnel can protect a path but isn't automatically conformant to the Modbus Security protocol or its authorisation model.

Primary sources#

Section overview · Wiki home

  1. Modbus Organization, Modbus Messaging on TCP/IP Implementation Guide V1.0b ↩