Modbus Error Codes Explained
What exception codes mean - and how to fix them fast
Quick answer: A Modbus exception code is the slave’s reason for rejecting a request. 01 Illegal Function means the function code is unsupported, 02 Illegal Data Address means the register does not exist, 03 Illegal Data Value means the value or quantity is out of range, and 04 Slave Device Failure is an internal device error.
When a Modbus device cannot satisfy a request, it replies with an exception response: the original function code with the high bit set, followed by a one-byte exception code. Knowing these codes turns a frustrating "it doesn't work" into a quick fix.
What do Modbus exception codes 01–06 mean?
The device does not support that function code. Use a different function (e.g. FC 04 instead of FC 03) and check the device docs.
The address does not exist on the device. The most common cause is 0-based vs 1-based addressing - if the manual says 40001, use address 0. Also try a smaller quantity.
The value or quantity in the request is out of range for the device. Check valid ranges and limits in the documentation.
An unrecoverable error occurred inside the device while processing the request. Retry, and check the device status/logs.
The request was accepted and is being processed (used with long operations). Not an error - poll again shortly.
The device is busy with another command. Wait and retry.
How do you spot an exception response in the raw frames?
An exception reply carries the original function code with the high bit set (0x80 added), followed by one exception-code byte. For example, a rejected FC 03 read comes back as 83 02 after the slave address (RTU) or the MBAP header (TCP): 0x83 = 0x03 + 0x80, and 02 = Illegal Data Address.
- Traffic Monitor: shows every TX and RX frame as hex. You can filter by text, direction and connection, pause the view and export it to CSV or TXT. Frames are captured only while the tab is visible.
- Device Tools > Raw Request: sends any function code (1-127) with your own data bytes, or a full PDU, and shows the request and response frames. Exception replies are displayed with their code instead of being treated as a transport failure, which makes it easy to check whether a device supports an unusual function code.
- CLI:
--traceprints TX/RX hex frames to stderr for any command.ModbusBB.CLI raw --tcp 192.168.1.10 --fc 3 --data "00 00 00 02"sends a raw request; an exception reply is printed and the command exits with code 1. See the raw command.
How do you test a master's exception handling?
Real devices rarely produce exceptions on demand. The ModbusBB 2.0 simulator has exception injection rules (GUI, Exceptions tab). Each rule matches a unit ID (or any unit), a function code (or any function) and an address range, and it answers with the exception code you choose (for example 02 or 06). Point your PLC, SCADA or gateway at the simulator and confirm that it reports the fault correctly and recovers. Function codes the simulator does not implement are answered with 01 Illegal Function, just as a real device would. See the simulator guide.
Why do timeouts and CRC errors have no exception code?
Two of the most common problems never produce an exception code at all, because nothing comes back:
- Timeout - no reply arrived. Check the IP/port (TCP) or COM port and serial settings (RTU), confirm the slave ID, and verify wiring. Increase the timeout for slow devices.
- CRC error (RTU) - the reply was corrupted or the serial settings are wrong. Make sure baud rate, parity, data bits and stop bits exactly match the device, and that the RS-485 bus is terminated.
Diagnose faster with ModbusBB
In ModbusBB 2.0 the Traffic Monitor (View > Traffic Monitor (raw frames)) shows the exact TX/RX request and response frames in hex. The communication log shows each decoded transaction, with the exception code name when a device rejects a request. ModbusBB also includes a slave scanner, register scanner and ping tool to track down addressing and connectivity problems. Download the free trial or read the troubleshooting guide.
Frequently asked questions
What does Modbus Illegal Data Address (02) mean?
The register or coil address does not exist on the device. Check 0-based vs 1-based addressing (a manual listing 40001 usually means address 0), reduce the quantity so you do not read past the end of the map, or scan the device for valid registers.
What does Modbus Illegal Function (01) mean?
The device does not support that function code. Try a different function - for example use Read Input Registers (FC 04) instead of Read Holding Registers (FC 03) - and check the device documentation for supported codes.
Why do I get Modbus timeouts?
No response arrived in time. Verify the IP/port (TCP) or COM port and serial settings (RTU), confirm the slave ID matches the device, check wiring and termination on RS-485, and make sure baud rate and parity match exactly.
How can I see the exact Modbus exception frame?
Open View > Traffic Monitor (raw frames) in ModbusBB 2.0, or add --trace to a CLI command. An exception reply shows the function code plus 0x80 (for example 83 for FC 03) followed by the exception code byte.
Put It Into Practice
Test, simulate and debug Modbus devices with one tool.