Skip to main content
Industrial Networking · Technical Blog

Modbus RTU vs Modbus TCP: What Actually Changes Between Them

Same registers, same function codes — different wire, different frame, different rules. Both versions of Modbus compared diagram by diagram.

2,500+ engineers trained 4.9/5 Google rating 21+ years, Chinchwad, Pune Next batch: contact for dates
Quick answer

Modbus RTU is the serial version: RS-485, a slave address and a CRC in every frame, one master polling one device at a time. Modbus TCP is the same protocol over Ethernet: the request is wrapped in a seven-byte MBAP header with a transaction ID and a unit ID, the CRC is dropped because TCP checks the data, and several clients can talk at once on port 502. The request itself — function code, register number, data — is identical, so a device's register map never changes when it moves from one to the other.

  • Same function codes, same registers — only the wrapper and the wire change.
  • RTU allows exactly one master; TCP allows several clients.
  • Register 40001 is offset 0 on the wire, which is where most Modbus bugs come from.
  • Neither version has any security — keep the network separate.

The Same Request, a Different Wrapper

Modbus has one request format, called the PDU: a function code and its data. RTU and TCP are two ways of delivering that PDU. Everything people argue about — speed, wiring, how many masters — comes from the wrapper, not from Modbus itself.

The request is the same — only the wrapper changesMODBUS RTU FRAMEAddress1 byteFunction1 byteData0 – 252 bytesCRC-162 bytesmax 256 bytesMODBUS TCP FRAMETransaction ID2 bytesProtocol ID2 bytesLength2 bytesUnit ID1 byteFunction1 byteData0 – 252 bytesMBAP header — 7 bytesno CRC: TCP already checks the dataPDUPDUThe orange part is the PDU — function code plus data. It is identical on both, which is why a register map never changes when you move a device from RTU to TCP.
The orange block is the same in both. RTU adds an address and a CRC; TCP adds the MBAP header and lets TCP handle the checking.

Frame by Frame

An RTU frame carries the slave address first and a CRC-16 last, and frames are separated by a silent interval of about 3.5 character times — that gap is how a receiver knows where one frame ends. A TCP frame has no gap and no CRC: the length field says how long the message is, and the transaction ID lets a client match each answer to the request that caused it.

Wiring and Topology

This is where the two feel completely different on site. RTU is one pair of wires daisy-chained from device to device, terminated at both ends. TCP is a normal switched Ethernet network.

Modbus RTURS-485 multidrop · one masterModbus TCPSwitched Ethernet · many clientsPLCMaster / clientRRSlaveID 1SlaveID 2SlaveID 3…up to 247One transaction at a time · terminate both ends · 9.6 to 115.2 kbit/sPLC / SCADAClientSwitchServerport 502Serverport 502Serverport 502Gatewayto RTU lineMany clients at once · no terminators · a gateway reaches old RTU devices
RTU: one line, one master, terminators at the ends. TCP: a switch, several clients, and a gateway if old serial devices must stay.

How Transactions Run

RTU is strictly sequential: request, response, silent interval, next request. Add devices or registers and the cycle time grows. TCP can have several transactions in flight, and the transaction ID in the header keeps the answers straight.

RTU: one transaction at a timeSilent interval between framesTCP: transactions can overlapTransaction ID matches the answersMasterSlave 1Slave 2Slave 3reqrspgapreqrspgapreqrspgapCycle time = sum of every request, response and silent intervalClientServer 1Server 2Server 3id 1id 2id 3Requests go out together; the transaction ID pairs each answer with its request
The RTU master waits for every answer before asking the next question; a TCP client does not have to.

The Data Model and Function Codes

Both variants use the same four tables of data and the same function codes. In practice, industrial devices put nearly everything in holding registers.

One data model, four tables — identical on RTU and TCPCoilsRead / write · 1 bitFC 01, 05, 150xxxxDiscrete inputsRead only · 1 bitFC 021xxxxInput registersRead only · 16 bitFC 043xxxxHolding registersRead / write · 16 bitFC 03, 06, 164xxxxHolding registers carry almost everything in drives and instruments: setpoints, status, parameters.Register 40001 in documentation is offset 0 on the wire — the single most common Modbus mistake.
Coils and discrete inputs are single bits; input and holding registers are 16-bit words.
Function codeNameActs onRead / write
01Read coilsCoilsRead
02Read discrete inputsDiscrete inputsRead
03Read holding registersHolding registersRead
04Read input registersInput registersRead
05Write single coilCoilsWrite
06Write single registerHolding registersWrite
15 (0x0F)Write multiple coilsCoilsWrite
16 (0x10)Write multiple registersHolding registersWrite
23 (0x17)Read/write multiple registersHolding registersBoth

Register Numbering: the 40001 Trap

Documentation counts from one; the protocol counts from zero. A device manual listing holding register 40100 means offset 99 in the request. Some PLC blocks want the documented number, others want the offset — read the block's help before blaming the device.

In the manualData typeOn the wireFunction code
00001CoilOffset 001 / 05 / 15
10001Discrete inputOffset 002
30001Input registerOffset 004
40001Holding registerOffset 003 / 06 / 16
40100Holding registerOffset 9903 / 06 / 16

Full Comparison Table

Modbus RTUModbus TCP
Physical layerRS-485 (or RS-232) twisted pairEthernet, 100 Mbit/s, copper or fiber
Speed9.6 – 115.2 kbit/s typical100 Mbit/s, limited by the devices
FrameAddress + PDU + CRC-16MBAP header + PDU, no CRC
Error checkingCRC-16 in every frameHandled by TCP
AddressingSlave ID 1 – 247 set on the deviceIP address; unit ID only for gateways
Nodes per networkUp to 247 addresses, 32 per segmentLimited by the network, not the protocol
Masters / clientsExactly one masterSeveral clients at the same time
TransactionsOne at a time, then a silent intervalOverlapping, paired by transaction ID
DistanceUp to 1200 m at low baud rates100 m per copper link; fiber for more
TerminationRequired at both endsNot needed
Typical port / wiringTwo-wire, daisy chainedRJ45 into a switch, port 502
Cost per nodeVery lowLow, but every node needs Ethernet
DiagnosticsBus tester, error countersPing, Wireshark, switch statistics

Work with Modbus on real hardware

Wire an RS-485 line, configure a Modbus TCP client and read a live drive both ways. Pune classroom or live online.

Book a Free Demo Class

PLC Blocks for Each

On an S7-1200 or S7-1500 the difference is which instruction you call. Neither uses %IW or %QW addresses — Modbus data lives in data blocks.

TaskSiemens S7-1200 / S7-1500Notes
Set up an RS-485 portMB_COMM_LOADBaud rate, parity, port hardware identifier — call once
Act as RTU masterMB_MASTEROne request at a time, with MB_MODE and MB_DATA_ADDR
Act as RTU slaveMB_SLAVEThe PLC answers another master
Act as TCP clientMB_CLIENTConnection ID, partner IP, port 502
Act as TCP serverMB_SERVERThe PLC answers SCADA or another PLC
Data locationA data block arrayNeither method uses %IW or %QW addresses

A drive on Modbus RTU exposes its control and status words as holding registers. Register numbers differ between products and firmware, so confirm them in the drive's own register table.

Example G120 registerDirectionContent
40100PLC → driveControl word
40101PLC → driveSpeed setpoint, 16384 = 100 % of p2000
40110Drive → PLCStatus word
40111Drive → PLCActual speed
Parameter registersBothIndividual drive parameters

Gateways and Mixed Plants

Most plants end up with both. A Modbus gateway is a TCP server on one side and an RTU master on the other: the client sends a normal TCP request with a unit ID, and the gateway forwards it to that slave address on the serial line. The serial line keeps its own speed limits, so a gateway makes old devices reachable — it does not make them fast.

Which One to Use

Choosing between RTU and TCPDevice only has an RS-485 port?YESModbus RTUOr add a gatewayNOMore than one master must read it?YESModbus TCPRTU allows only oneNOEthernet already at the machine?YESModbus TCPNo new cable typeNOLong cable run, few devices, low cost?YESModbus RTU1200 m on one pairNOModbus TCPDefault for new installations
For new work TCP is the default; RTU still wins on long cheap runs and on devices that have no Ethernet port.

Security

Modbus was designed in 1979 for a trusted serial link, and nothing in either variant authenticates the sender. Over Ethernet that matters.

RiskWhy it existsWhat to do
No authenticationAny client on the network can write registersSegregate the Modbus network, firewall port 502
No encryptionFrames are readable with WiresharkKeep it off the business network and off the internet
Writes are uncheckedA wrong write can start a motorAllow only the registers the application needs; use a read-only gateway where possible

Common Faults

SymptomWhereLikely causeFix
No response at allRTUWrong slave ID, baud rate, parity or A/B swappedMatch the settings, swap A and B once to test
Works for one device, fails when a second is addedRTUDuplicate slave ID, or missing terminationUnique IDs, terminators only at the two ends
Values off by one registerBoth40001 counted as offset 1 instead of 0Subtract one from the documented register number
Byte order looks wrong on 32-bit valuesBothWord order differs between vendorsSwap the two words, or use the device's word-order setting
Connection drops under loadTCPToo many clients, or a client not closing connectionsLimit clients, reuse connections, check the server limit
Exception code 02 returnedBothRegister does not exist on that deviceCheck the register map and the quantity requested

Step-by-Step Lab: Read the Same Register Both Ways

Hands-on
Before you start
  • An S7-1200 or S7-1500 with an RS-485 communication module, and one Modbus device — a drive, a power meter or an instrument.
  • A Modbus TCP device or a gateway, and a PC with a Modbus test tool and Wireshark.
  • Estimated time: 60 minutes.
1

Set up the serial port

Call MB_COMM_LOAD once with the port hardware identifier, the device baud rate and parity.

The block returns DONE without an error, and the module LED shows activity.
2

Read a holding register over RTU

Call MB_MASTER with MB_MODE 0, the register address and a quantity of 1.

On screen: watch table showing the returned register value.
The value arrives in your data block. If it is one register out, revisit the 40001 rule.
3

Capture the serial transaction

Note how long a single read takes at your baud rate, then increase the quantity to 10 registers and compare.

Ten registers in one request take far less time than ten separate requests — batching is the main RTU optimisation.
4

Read the same data over TCP

Call MB_CLIENT with the partner IP address and port 502, requesting the same register.

The same value arrives, using the same function code and register number as the RTU read.
5

Watch it on the wire

Capture the TCP traffic in Wireshark and filter on modbus.

You can see the transaction ID, unit ID, function code and register offset — and confirm the offset is one lower than the documented number.
6

Break it on purpose

Change the slave ID on the RTU side, then request a register the device does not have on the TCP side.

No response on RTU; exception code 02 on TCP. Two faults that look nothing alike but have the same root cause: asking the wrong thing.
Checkpoint — how to know you did it right

You understand both variants if you can explain why the same register number worked on either connection, what the transaction ID is for, and why ten registers in one request beats ten requests.

Frequently asked questions

What is the difference between Modbus RTU and Modbus TCP?

They carry the same requests — the same function codes, the same registers — but wrap them differently. RTU is a serial protocol on RS-485 with a slave address and a CRC in every frame, and one master polling one device at a time. TCP puts the same request inside an Ethernet packet with a seven-byte MBAP header, drops the CRC because TCP already checks the data, and lets several clients talk at once.

Is Modbus TCP faster than Modbus RTU?

Almost always. RTU at 19.2 kbit/s needs milliseconds for a single small transaction and must wait for a silent interval before the next one, while TCP runs at 100 Mbit/s and allows overlapping transactions. The practical limit on TCP is usually how fast the device can answer, not the network.

Can I connect a Modbus RTU device to a Modbus TCP network?

Yes, with a Modbus gateway. The gateway is a TCP server on the Ethernet side and the RTU master on the serial side, and the unit ID field in the TCP frame tells it which serial device the request is for.

Why does register 40001 map to offset 0?

The 4xxxx numbering is a documentation convention that starts counting at one, while the protocol on the wire starts at zero. So holding register 40001 is offset 0, and 40100 is offset 99. Many devices and PLC blocks differ on this point, which is why values often come back one register out.

Does Modbus TCP still need a CRC?

No. TCP provides its own checksum and guarantees delivery and ordering, so the Modbus CRC is dropped. That is also why an RTU frame captured on a serial line has two extra bytes at the end that a TCP frame does not.

Can two masters share one Modbus RTU line?

No. RTU allows exactly one master on a line. If two devices need to read the same instrument, either poll it with one master and share the data, or move to Modbus TCP, where several clients can connect at once.

Is Modbus secure?

No. Neither variant authenticates or encrypts anything, and any client that reaches a Modbus TCP server can write to it. Treat the Modbus network as trusted-only: separate it from the business network, restrict port 502 at the firewall, and never expose it to the internet.

Reviewed by Bhawesh Kumar Singh Industrial Automation Trainer and Industry 4.0 Consultant · Softwell Automation · 21+ years industry experience

Get the full syllabus + free demo class

Share your details — a Softwell training advisor will call you within 24 hours with batch dates, fees and hardware access options.

No spam. Used only to share course details for this enquiry.

Learn with practical industrial examples

Join live online, Pune classroom or corporate in-plant automation training.

Request Course Details
Verified learning pathway

Discuss Your Automation Requirement

Get guidance for training, corporate programs, projects or technical resources.

Content reviewed: 22 September 2026

☎ Call WhatsApp ✉ Email Enquire Now