ModbusBB 2.0 documentation
Everything you need to connect, decode, diagnose, simulate and automate with ModbusBB
Quick answer: Install ModbusBB, select the connection in the side tree, choose a transport (TCP, UDP, RTU-over-TCP, RTU or ASCII) and click Connect. Then set Slave, Function, Address and Quantity in a poll tab and press F5 to read once or F6 to poll. Add more connections or poll tabs from the Connection menu, and save everything as a workspace (.mbws). For scripts, use ModbusBB.CLI.exe; see the CLI reference. For step-by-step instructions with screenshots, read the user manual (also as PDF, 6.7 MB).
Contents
Getting started
System requirements
Operating system
Windows 10 or Windows 11, 64-bit (x64)
Runtime
None to install. The .NET 8 runtime is built into the self-contained executables
Disk and memory
About 250 MB of disk space; 4 GB RAM recommended
Serial (RTU/ASCII)
An RS-485 or RS-232 adapter that Windows shows as a COM port
Install
Get ModbusBB_Setup_2.1.0.exe or ModbusBB_Portable_2.1.0.zip from the download page. You can compare the file's SHA-256 with the published checksum.
It installs the GUI (ModbusBB.GUI.exe) and the CLI (CLI\ModbusBB.CLI.exe) and creates Start-menu shortcuts. Optionally tick Add CLI to system PATH. To upgrade, run it over the existing installation; see Upgrading from 1.x.
On first start, enter your license key or continue with the 30-day trial (15 minutes per session). Activating a key needs an internet connection.
Set up the connection (next section), then press F5 to read the active poll tab once or F6 to start polling.
Portable version
Extract ModbusBB_Portable_2.1.0.zip to any folder. Run GUI\ModbusBB.GUI.exe for the application or CLI\ModbusBB.CLI.exe for the command line. Nothing needs to be installed. License, trial and settings are stored per Windows user in %LOCALAPPDATA%\ModbusBB.
Connections & transports
A connection is one link to a device or network, such as a TCP endpoint or a COM port. You can have as many connections as you like, and each runs independently. Add one with Connection > Add Connection or the + Conn button, and rename or remove it from the same menu or the tree's context menu.
| Type | Use for | Settings |
|---|---|---|
| Modbus TCP | Ethernet devices and Modbus TCP gateways | IP/host, port (default 502) |
| Modbus UDP | Devices that speak Modbus (MBAP) over UDP | IP/host, port (default 502) |
| RTU over TCP | Serial device servers in transparent/raw mode that pass RTU frames (with CRC) through a TCP socket | IP/host, port of the device server |
| Modbus RTU | RS-485/RS-232 serial devices | COM port, baud (1200-230400), data bits (7/8), parity (None/Odd/Even/Mark/Space), stop bits (1/1.5/2) |
| Modbus ASCII | Serial devices using ASCII framing (often 7 data bits) | Same as RTU |
Timing, retries and auto-reconnect
| Setting | Meaning | Default |
|---|---|---|
| Timeout | How long to wait for a response (50-60000 ms) | 1000 ms |
| Retries / every | Extra attempts per request after a timeout, and the pause between them (0-10 retries) | 3 retries, 250 ms |
| Reconnect automatically | Re-open the link when it drops and resume the polls | On |
| First delay / Max delay | Wait before the first reconnect attempt; the upper limit for the wait | 1000 ms / 30000 ms |
| Back-off factor | Each failed attempt multiplies the wait by this factor (1-10) | 2 |
| Max attempts | Stop trying after this many attempts; 0 = keep trying | 0 |
| Connect when the workspace is opened | Auto-connect this connection when its workspace loads | Off |
The tree and status bar show each connection's state: Connected, Reconnecting or Connection lost. Connect All and Disconnect All act on every connection. The Ping button checks whether a network device answers before you connect.
Polls & tabs
A poll is one read request on a connection: Slave (unit ID), Function, Address and Quantity, repeated at an interval. Each poll is a tab, and a connection can have many. Polls on the same connection share the link and are sent one at a time. Polls on different connections run in parallel.
Connection > Add Poll (Ctrl+T) adds a tab to the selected connection. Rename it with Rename Poll….
Slave 0-255 (1-247 for most devices), Function FC01/02/03/04, Address 0-65535 (decimal or 0x hex, always the 0-based protocol address), Quantity 1-125 registers or 1-2000 bits, and Interval 100 ms to 1 h. Invalid values are marked and not sent.
F5 reads the active tab once. F6 starts or stops polling it. Start All Polls / Stop All Polls act on every tab of every connection.
Writing values
Type a value into the Set Value column and press Enter, or use the Write value box and Write button. One 16-bit value uses FC06 (coils FC05) when Use FC05/FC06 for a single value is ticked, otherwise FC16/FC15. Values accept decimal, 0x hex and 0b binary. Coils accept 1/0, on/off and true/false. Multi-register types are encoded with the row's format and byte order.
Read-only rows and write safety
Rows read with FC02 (discrete inputs) or FC04 (input registers) cannot be written, because Modbus has no write function for them. Read the same address with FC01 or FC03 to write coils or holding registers. Incomplete multi-register values and rows marked read-only in the register map are also blocked. Writing can operate real equipment, so check the unit ID, address and value before you write.
Workspaces (.mbws)
A workspace stores your whole setup in one file. It holds every connection and its settings, every poll tab, per-register settings (name, format, byte order, scale, offset, unit), watchdog rules, the alert log path and view options such as address notation.
- File menu - New Workspace (Ctrl+N), Open Workspace (Ctrl+O), Open Recent, Save (Ctrl+S) and Save As (Ctrl+Shift+S)
- Auto-connect - Connections with Connect when the workspace is opened connect on load and resume the polls that were running when you saved
- Old files - Open Workspace also accepts 1.x connection profiles (
.json,.mbprofile) and.mbcfgfiles and converts them. Save the result as.mbws - CLI -
ModbusBB.CLI workspace run plant.mbwsruns the enabled polls from a workspace.--profile plant.mbws --connection "Meter bus"takes the connection for any command from it
Data types & byte order
Set the format for the whole tab (Format / Byte order above the grid) or per row (the grid's Format and Byte Order columns). Multi-register values take several consecutive registers. Cycle Byte Order (context menu or Cycle button) steps through the four orders so you can spot the one that gives a sensible value.
| Format | Registers | Range / notes | CLI --format |
|---|---|---|---|
| Unsigned decimal | 1 | 0 to 65535 | uint16 |
| Signed decimal | 1 | -32768 to 32767 | int16 |
| Hexadecimal | 1 | 0x0000 to 0xFFFF | hex |
| Binary | 1 | 16 bits | binary |
| Int32 / UInt32 | 2 | 32-bit signed / unsigned | int32 / uint32 |
| Float32 | 2 | IEEE 754 single precision | float32 |
| Int64 / UInt64 | 4 | 64-bit signed / unsigned | int64 / uint64 |
| Float64 | 4 | IEEE 754 double precision | float64 |
| String | N (GUI: String regs, default 8) | 2 characters per register | string + --string-length <chars> |
Byte order table
A, B, C, D… are the value's bytes from most to least significant. The table shows how they are laid out on the wire. The example is Float32 123.456 = 0x42F6E979.
| Order | Name | 32-bit layout | 64-bit layout | Float32 123.456 registers |
|---|---|---|---|---|
ABCD | Big-endian (default) | AB CD | AB CD EF GH | 0x42F6, 0xE979 |
CDAB | Word swap | CD AB | GH EF CD AB | 0xE979, 0x42F6 |
BADC | Byte swap | BA DC | BA DC FE HG | 0xF642, 0x79E9 |
DCBA | Little-endian | DC BA | HG FE DC BA | 0x79E9, 0xF642 |
64-bit byte order (Float64, Int64, UInt64)
| Order | 8 bytes on the wire | Float64 123.456 registers |
|---|---|---|
ABCD | A B C D E F G H | 0x405E, 0xDD2F, 0x1A9F, 0xBE77 |
CDAB | G H E F C D A B | 0xBE77, 0x1A9F, 0xDD2F, 0x405E |
BADC | B A D C F E H G | 0x5E40, 0x2FDD, 0x9F1A, 0x77BE |
DCBA | H G F E D C B A | 0x77BE, 0x9F1A, 0x2FDD, 0x5E40 |
For String, only the byte swap matters. ABCD and CDAB put the first character in the high byte of each register, while BADC and DCBA put it in the low byte. More background is in the Float32 and byte order guide.
Scaling, offset & units
Each row has Scale, Offset and Unit columns. The Eng. Value column shows:
engineering value = decoded value × scale + offset
For example, a UInt16 of 2305 with scale 0.1 and unit V shows 230.5 V. The raw value, hex and binary stay visible next to it. Watchdog rules and CLI workspace run output use the same engineering value. Scaling can also come from a register map or the device library.
Address notation
View > Address Notation changes how the grid's Address column is displayed:
| Notation | Holding register at protocol address 0 shows as | Notes |
|---|---|---|
| 0-based (protocol / PDU) | 0 | The address actually sent in the request (default) |
| 1-based (register number) | 1 | Address + 1 |
| Modicon | 40001 | Prefix 0 = coils, 1 = discrete inputs, 3 = input registers, 4 = holding registers, then address + 1 (5 digits after the prefix above 9999) |
View > Show Hex Addresses shows 0-based and 1-based addresses in hex. The notation only changes the display. The poll's Address field and all CLI --address options always take the 0-based protocol address, so a manual's register 40001 is address 0. See 40001 vs address 0.
Register maps & aliases
Type a name in the Alias column, or load a whole map with File > Import Register Map… (CSV or JSON). Export Register Map… saves the current settings, and Create Register Map Template… writes a CSV with every column.
Columns: Address, Name, Description, Format, ByteOrder, Type, RegisterCount, ScaleFactor, Offset, Unit, MinValue, MaxValue, ReadOnly. ByteOrder and RegisterCount are optional (the count defaults from the format), and older 1.x CSV files still import. MinValue/MaxValue limit what can be written, and ReadOnly blocks writes.
Traffic monitor (raw frames)
View > Traffic Monitor (raw frames) opens the Traffic tab below the grid. It lists every frame on every connection: time (ms), direction (TX/RX), connection, length and the bytes in hex. TX frames are exactly what was sent. RX bytes are grouped per response, timestamped at the first byte. Frames are complete ADUs: MBAP header for TCP/UDP, address + CRC for RTU and RTU-over-TCP, and :…LRC for ASCII.
- Filter - Free text (matches hex bytes, ASCII text or connection name), direction (All/TX/RX) and connection
- Pause - Freezes capture while you read; Auto-scroll follows the newest frame
- Copy - Select rows and press Ctrl+C or Copy
- Export… - Save the frames to CSV or TXT
- Max rows - Oldest frames are dropped above the limit (default 5000)
Capture only runs while the Traffic tab is visible, so it costs nothing when you don't need it. The Communication Log tab shows decoded transactions with response times and errors. It keeps the last 2000 entries and can be cleared or exported (File > Export Log…). In the CLI, --trace prints the same TX/RX hex to stderr.
Scans & connection statistics
- Scan for Slaves… (Tools menu or Scan Slaves) - Probes unit IDs 1-247 on the selected connection, with progress and Cancel Scan. A device that answers with a Modbus exception counts as found, because it is present
- Scan Registers… - Probes a range of addresses for a function code and reports the readable ranges
- Connection Statistics - A summary for each connection (protocol, endpoint, state, retries, timeout, auto-reconnect) with each poll's interval, state and OK/error counts, plus logging and watchdog status
To measure loss and response time, use the CLI: ModbusBB.CLI stats --tcp 192.168.1.10 --samples 100 --delay 0. It sends single-register reads without retries. It reports valid responses, exception replies, timeouts, other errors and loss % (requests without any response ÷ requests sent), plus avg/min/median/p95/max response time. Exception replies count as responses, because the device is reachable.
CSV logging
- Tools > Data Logging > Start Logging Active Tab to CSV… - Pick a file (default name
ModbusBB_Data_yyyyMMdd_HHmmss.csv). Every sample of that tab is appended with a timestamp until Stop Logging - Export Current Data… - Saves the tab's latest values once
- Files are UTF-8 with BOM (opens cleanly in Excel), and values are CSV-escaped
- For unattended logging, use the CLI:
poll … --output csv > log.csvorworkspace run plant.mbws --output csv(see CSV logging with the CLI)
Trend chart
Tools > Live Trends… opens a chart that samples the values shown in the active poll tab (Sample main grid every 0.1 s to 10 s). Each register becomes a series that you can show or hide in the list, or remove.
- Navigation - Wheel: zoom time. Ctrl+wheel: zoom Y. Drag: pan. Shift/right-drag: zoom box. Double-click or Home: reset
- Follow live keeps the newest samples at the right edge. Window sets the visible span (10 s to 1 h, or All)
- History - Maximum points kept per series (the oldest are dropped), with an optional age limit
- Auto Y or a manual Min/Max range
- Pause, Clear, Export CSV… (all buffered samples) and Export PNG… (the chart image)
Watchdog alerts & actions
Tools > Watchdog Alerts > Configure Rules… opens the rule editor. Tick Enable Watchdog to evaluate rules on every polled sample.
| Part | Options |
|---|---|
| Source & filters | Address (first register for 32/64-bit), optional tag, connection, slave and function (empty = any) |
| Decoding | Format, byte order, scale and offset. The rule compares the engineering value |
| Condition | On change, greater than, less than, equals, not equals, inside range, outside range; tolerance for equality and change |
| Debounce | The condition must be true for N consecutive samples |
| Cooldown | Minimum time between two alerts of the rule (default 5000 ms) |
| Only on transition | Fire once when the condition becomes true, not on every sample |
| Actions | Raise alert (Alerts tab), log to file (CSV line in the alert log), play sound (system sounds or a .wav), write value (register or coil, with its own slave, address, value, format and byte order) |
Alerts appear in the Alerts tab (its header shows the count) and never block polling, because actions run in the background. Set the CSV file with Alert Log File… and open it with Open Alert Log Folder.
Write actions change the device
A Write value action sends a real Modbus write every time the rule fires, subject to the cooldown. Double-check the slave, address, value and format. A wrong write can start or stop machinery or change setpoints.
Device Tools
Tools > Device Tools… (or the Device Tools button) sends extended requests on a chosen connection. At the top you set the session, Slave ID, Timeout (empty = the connection's setting), Retries (default 0, a single attempt), and Confirm writes (asks before anything that changes data). Cancel aborts a running request.
Category Basic (objects 0-2: vendor, product code, revision), Regular (adds 3-6: vendor URL, product name, model name, user application name), Extended (private objects) or Individual (one object, set by Start object id). Multi-part replies are followed automatically. Results show object id, name, value and raw bytes; Copy or Export to CSV. CLI: devid --category regular.
Shows server ID, run indicator (0xFF = ON), additional data as hex and text, and all data bytes. The content is device specific. CLI: slaveid.
Sub-function 0x00 (Return Query Data) echoes the data you send (default A5 37), a quick end-to-end link test. Counter sub-functions return one 16-bit value. CLI: diag --sub 0 --data "12 34" (a mismatched echo exits with code 1).
result = (current AND and-mask) OR (or-mask AND NOT and-mask). A 1 in the AND mask keeps the bit; a 0 forces it to the OR-mask bit. Masks accept decimal, 0x or 0b. A bit preview shows the effect, Read current (FC03) fills the preview, and Read back after write verifies it. CLI: maskwrite --address 4 --and 0xFFF0 --or 0x0005.
Writes 1-121 values, then reads 1-125 registers, in one transaction (the write happens first). Results are shown as unsigned, signed, hex and binary. CLI: rw --read-address 0 --read-count 4 --write-address 10 --value 1,2,3.
Send Function code + data or a Full PDU in hex; presets fill common requests. The transport adds the MBAP header or address + CRC/LRC. You see the request frame, response frame, PDU and time. An exception reply is shown with its code and name, not treated as a failure. The history keeps earlier requests (double-click to reuse). CLI: raw --fc 3 --data "00 00 00 02".
Device library
Tools > Device Library… lists built-in register maps. Filter by manufacturer, model or description, check the source, default connection settings and register table, then click Use this map to load names, formats, byte order and scaling into the main window, or Export… to JSON or CSV.
| Library id | Device |
|---|---|
eastron-sdm120 | Eastron SDM120-Modbus single-phase energy meter |
eastron-sdm630 | Eastron SDM630-Modbus V2 three-phase energy meter |
schneider-pm5xxx | Schneider Electric PM5100 / PM5300 / PM5500 power meters |
carlo-gavazzi-em24 | Carlo Gavazzi EM24 energy analyzer |
sunspec-common | SunSpec Common Model (ID 1) identification block |
growatt-inverter-v120 | Growatt inverters (Modbus RTU protocol V1.20) |
sma-inverter | SMA Sunny Boy / Sunny Tripower (SMA Modbus profile) |
abb-acs580 | ABB ACS580 drive (embedded fieldbus, ABB Drives profile) |
schneider-altivar | Schneider Electric Altivar ATV320 / ATV340 / ATV630 drives |
Addresses are 0-based wire addresses, and the register type selects the function code (input = FC04, holding = FC03). Every map names its source document.
Verify against your manual
Maps can differ between models, firmware versions and variants. Check every address, data type and scale against your device manual before relying on it.
Simulator (slave / server)
Tools > Modbus Simulator (slave)… makes ModbusBB answer requests like a field device.
- Transport - TCP or UDP (listens on all interfaces; port 502 may need admin rights or be in use, so try 5020), RTU or ASCII on a COM port with baud, data bits, parity and stop bits. To test on one PC over serial, use a virtual COM-port pair
- Unit IDs - Add several (1-247; 0 and 248-255 allowed for testing). Each has its own coils, discrete inputs, holding and input registers
- Data - Pick unit, table, start and count; edit values in any format and byte order and Apply edits. Auto-refresh shows what masters write
- Generators - Static, Ramp, Sine, Random, Counter or Toggle on any unit/table/address, with min, max, period, step, format and byte order. Add demo set creates an example. They run while the simulator is started (tick default 100 ms)
- Exceptions - Rules with unit (or any), FC (or any), address range and exception code. Matching requests get that exception
- Response delay + jitter - A fixed delay plus a random 0..N ms before every response, to test master timeouts
- Request log - Time, unit, function, address, quantity, result and delay, with pause and clear
The CLI has the same simulator without the window: ModbusBB.CLI simulate --tcp 5020 --unit 1,2 --generator "holding:0:sine:0:100:5000" (see simulate). Exception rules are available in the GUI only.
More: How to use a Modbus simulator to test a PLC or SCADA client.
CLI reference (summary)
ModbusBB.CLI.exe covers the tasks you'd want to script: read, write, poll, scan, stats, device identification, slave ID, diagnostics, mask write, read/write multiple, raw requests, the device library, running workspaces and the simulator. Interactive-only GUI features have no CLI command. That covers the trend chart, watchdog rules and actions, register-map import/export, the traffic monitor window (use --trace instead) and simulator exception injection. Every command is one-shot, with the connection given inline. Run it with no arguments for an interactive prompt.
| Command | Purpose |
|---|---|
read | Read coils, discrete inputs, holding or input registers (FC01-04), any format |
write | Write registers or coils (FC05/06/15/16), --dry-run to preview the frame |
poll | Read repeatedly; CSV rows or NDJSON per sample; auto-reconnect |
scan | Find unit IDs or readable register ranges |
stats | Response time and loss statistics |
devid / slaveid / diag | FC43/14, FC17, FC08 |
maskwrite / rw / raw | FC22, FC23, any FC 1-127 |
library | List, show or export built-in device maps |
workspace run | Run the enabled polls of a .mbws file and print decoded values |
simulate | Run the slave simulator (TCP/UDP/RTU/ASCII, generators, delay) |
connect, disconnect, status, ports, version, help | Connection test / interactive session, list COM ports, help topics |
# Read 2 input registers as Float32 (word swapped), JSON output ModbusBB.CLI read --tcp 192.168.1.10 --unit 1 --input --address 0 --format float32 --byte-order CDAB --output json # Log 4 registers every second to CSV for one hour ModbusBB.CLI poll --rtu COM3 --baud 19200 --parity E --unit 5 --address 0 --count 4 --duration 3600 --output csv > log.csv
Exit codes: 0 success · 1 runtime error (connection failed, timeout, Modbus exception reply, I/O error) · 2 usage error · 3 license error · 130 interrupted with Ctrl+C (poll, simulate and workspace run exit 0 when stopped with Ctrl+C). The full option list, output formats and PowerShell/cmd examples are in the CLI reference.
--trace.Licensing, activation & devices
Free trial
30 days from first start, all features, 15 minutes per session (restart to begin a new session). No key or credit card needed.
Lifetime license ($10)
Unlimited session time, up to 3 activated devices, free updates. One key covers the GUI and CLI.
Activation
Purchase on the buy page; the key arrives by email.
Start ModbusBB. The license window opens before the main window. Paste the key and activate. In the CLI, run ModbusBB.CLI in a terminal without --no-prompt and paste the key when asked.
The key is checked online and bound to this PC. That needs an internet connection. GUI and CLI share the stored license (per Windows user, in %LOCALAPPDATA%\ModbusBB).
Offline use and re-verification
After activation ModbusBB works offline. The license is re-checked online in the background when a connection is available, and it must be confirmed at least once every 30 days (the offline grace period). A key copied from another PC is not accepted until it has been verified for the new PC.
Device limit and deactivation
A license can be active on 3 devices. If activation reports that the limit is reached, open the self-service license portal, deactivate a device you no longer use, and activate again. Minor hardware changes don't count as a new device.
Upgrading from 1.x to 2.0
Run the new ModbusBB_Setup_2.1.0.exe without uninstalling 1.x first. The installer replaces the program files and keeps your stored license and settings.
2.0 finds the stored key and re-activates it for this PC automatically. Your existing key keeps working, with no new purchase and no new key.
File > Open Workspace opens 1.x connection profiles (.json/.mbprofile) and .mbcfg files. Save them as .mbws workspaces. Old register-map CSV files still import.
Don't uninstall 1.x first
The 1.x uninstaller removes %LOCALAPPDATA%\ModbusBB, including the stored key. (The 2.0 uninstaller keeps this folder.) If that already happened, enter your key again (from your purchase email or the license portal). It activates as usual and counts against your 3 devices only if it's a new PC.
Scripts that used the 1.x CLI should be checked against the 2.0 CLI reference. Commands are now one-shot with inline connection options (--tcp, --rtu, …) and return exit codes.
Keyboard shortcuts
| Keys | Action |
|---|---|
| Ctrl+N / Ctrl+O | New / open workspace |
| Ctrl+S / Ctrl+Shift+S | Save / save workspace as |
| Ctrl+T | Add poll tab |
| F5 | Read active tab once |
| F6 | Start/stop polling the active tab |
| Ctrl+C (Traffic tab) | Copy selected frames |
The full list is under Help > Keyboard Shortcuts.
Frequently asked questions
What operating systems does ModbusBB support?
64-bit Windows 10 and Windows 11. The .NET 8 runtime is included, and both an installer and a portable ZIP are available.
Can I connect to multiple devices at the same time?
Yes. In 2.0, add one connection per device or network (Connection > Add Connection). Each connection can have several poll tabs, and all polls can run at the same time. Save the setup as a workspace (.mbws).
Can I use ModbusBB as a Modbus slave/server?
Yes. The built-in simulator runs as a Modbus TCP, UDP, RTU or ASCII slave with several unit IDs, editable data, value generators, exception injection and response delay.
Do I need special hardware for Modbus RTU?
Yes. For RTU or ASCII you need an RS-485 adapter (or RS-232 for point-to-point) that Windows shows as a COM port. For serial devices behind an Ethernet device server, use RTU over TCP instead.
What is the difference between 0-based and 1-based addressing?
The Modbus request always carries a 0-based address, and that is what you enter in ModbusBB's Address field. Manuals often list 1-based or Modicon numbers such as 40001, which is address 0. View > Address Notation can display addresses as 0-based, 1-based or Modicon.
How do I read Float32 or Float64 values?
Set the row or tab format to Float32 (2 registers) or Float64 (4 registers). If the value looks wrong, try another byte order (ABCD, CDAB, BADC, DCBA). The Cycle Byte Order command steps through them.
Does my 1.x license key work in 2.0?
Yes. Install 2.0 over your current version and start it once with an internet connection. The stored key is found and re-activated for that PC automatically.
Can I transfer my license to another computer?
Yes. Deactivate the old device in the self-service license portal, then activate on the new computer. Up to 3 devices can be active at a time.
Does ModbusBB work offline?
Yes. After activation it works offline for up to 30 days between online license checks.
Is my Modbus data sent to the internet?
No. ModbusBB talks directly to your devices over your network or serial port. No register values, frames or logs are sent to our servers. Only license checks and the update check contact modbus.maxenergic.com.
Troubleshooting
Timeout / no response
- Open the Traffic tab. If you see TX frames but no RX, the device isn't answering: check the IP/port or COM settings, the unit ID and the wiring
- TCP: use Ping, check that port 502 (or the device's port) is open, and that the device allows another client
- RTU/ASCII: baud, parity, data bits and stop bits must match exactly. Check A/B polarity and termination (RS-485 wiring)
- Serial device server: choose RTU over TCP if the gateway passes RTU frames through, or Modbus TCP if it converts to Modbus TCP
- Measure loss with
ModbusBB.CLI stats --samples 100. See Fix Modbus timeouts
Illegal Function (exception 01)
- The device doesn't support that function code. Check the manual, or try FC04 instead of FC03. Device Tools > Raw Request is a quick way to test what the device accepts
Illegal Data Address (exception 02)
- The address or range doesn't exist. Remember 40001 = address 0, reduce the quantity, and use Scan Registers to find the valid ranges. See Modbus exception codes
Wrong or garbled values
- Check the format (16/32/64-bit, float, string) and use Cycle Byte Order
- Check the address notation and whether the value spans 2 or 4 registers
- Apply the device's scale factor in the Scale column
- If you used a device library map, compare it with your manual
Connection keeps dropping
- Leave Reconnect automatically on. Increase the timeout and retries for slow links. The log shows each reconnect attempt and the reason for the drop
- Too many clients on one TCP device can cause disconnects, so close other masters
COM port not found
- Plug in the adapter, install its driver, check Device Manager, click Refresh, and close other programs using the port.
ModbusBB.CLI portslists the ports Windows reports
License says the device limit is reached
- Deactivate an unused PC in the license portal, then activate again
Still need help?
Email support@maxenergic.com with a description, your ModbusBB version and, if you can, an export of the Traffic tab or communication log.
Ready to get started?
Download ModbusBB 2.0 and start testing your Modbus devices today.