The TCP port used is: 502.
Request Format:| Name | | Length | Function |
|---|
| Transaction Identifier | MBAP | 2 | For synchronization between messages of server and client |
| Protocol identifier | 2 | 0 for Modbus/TCP |
| Length field | 2 | Number of remaining bytes in this frame |
| Unit identifier | 1 | Unit address (255 if not used) |
| Function code | PDU | 1 | Function codes as in other variants |
| Address of first register | 2 | Address of the first register |
| Number of registers | 2 | Number of registers |
Response:| Name | | Length | Function |
|---|
| Transaction Identifier | MBAP | 2 | For synchronization between messages of server and client |
| Protocol identifier | 2 | 0 for Modbus/TCP |
| Length field | 2 | Number of remaining bytes in this frame |
| Unit identifier | 1 | Unit address (255 if not used) |
| Number of Bytes following | PDU | 1 | Number of Bytes following |
| Data | N | Data |
MBAP Header = Modbus Application Header
PDU = Protocol Data Unit
Sample Master to Slave message:
| position | 00 01 | 02 03 | 04 05 | 06 | 07 | 08 09 | 10 11 |
| value | 12 34 | 00 00 | 00 06 | 255 | 03 | 00 01 | 00 01 |
Explanation:
| Position | Length | Value | Meaning |
| 00 01 | 2 | 12 34 | transaction id |
| 02 03 | 2 | 00 00 | Protocol identifier (high byte first) |
| 04 05 | 2 | 00 06 | Number of bytes following (high byte first) |
| 06 | 1 | 255 | slave address (255 = not used |
| 07 | 1 | 03 | function code |
| 08 09 | 2 | 00 01 | first register to be returned (high byte first) |
| 10 11 | 2 | 00 01 | number of registers to be returned (high byte first) |
Simply Modbus: Modbus TCP Protocol
Wikipedia: Modbus TCP