Modbus RTU is the serial version: RS-485, a slave address and a CRC in every frame, one master polling one device at a time. Modbus TCP is the same protocol over Ethernet: the request is wrapped in a seven-byte MBAP header with a transaction ID and a unit ID, the CRC is dropped because TCP checks the data, and several clients can talk at once on port 502. The request itself — function code, register number, data — is identical, so a device's register map never changes when it moves from one to the other.
- Same function codes, same registers — only the wrapper and the wire change.
- RTU allows exactly one master; TCP allows several clients.
- Register 40001 is offset 0 on the wire, which is where most Modbus bugs come from.
- Neither version has any security — keep the network separate.
The Same Request, a Different Wrapper
Modbus has one request format, called the PDU: a function code and its data. RTU and TCP are two ways of delivering that PDU. Everything people argue about — speed, wiring, how many masters — comes from the wrapper, not from Modbus itself.
Frame by Frame
An RTU frame carries the slave address first and a CRC-16 last, and frames are separated by a silent interval of about 3.5 character times — that gap is how a receiver knows where one frame ends. A TCP frame has no gap and no CRC: the length field says how long the message is, and the transaction ID lets a client match each answer to the request that caused it.
Wiring and Topology
This is where the two feel completely different on site. RTU is one pair of wires daisy-chained from device to device, terminated at both ends. TCP is a normal switched Ethernet network.
How Transactions Run
RTU is strictly sequential: request, response, silent interval, next request. Add devices or registers and the cycle time grows. TCP can have several transactions in flight, and the transaction ID in the header keeps the answers straight.
The Data Model and Function Codes
Both variants use the same four tables of data and the same function codes. In practice, industrial devices put nearly everything in holding registers.
| Function code | Name | Acts on | Read / write |
|---|---|---|---|
| 01 | Read coils | Coils | Read |
| 02 | Read discrete inputs | Discrete inputs | Read |
| 03 | Read holding registers | Holding registers | Read |
| 04 | Read input registers | Input registers | Read |
| 05 | Write single coil | Coils | Write |
| 06 | Write single register | Holding registers | Write |
| 15 (0x0F) | Write multiple coils | Coils | Write |
| 16 (0x10) | Write multiple registers | Holding registers | Write |
| 23 (0x17) | Read/write multiple registers | Holding registers | Both |
Register Numbering: the 40001 Trap
Documentation counts from one; the protocol counts from zero. A device manual listing holding register 40100 means offset 99 in the request. Some PLC blocks want the documented number, others want the offset — read the block's help before blaming the device.
| In the manual | Data type | On the wire | Function code |
|---|---|---|---|
| 00001 | Coil | Offset 0 | 01 / 05 / 15 |
| 10001 | Discrete input | Offset 0 | 02 |
| 30001 | Input register | Offset 0 | 04 |
| 40001 | Holding register | Offset 0 | 03 / 06 / 16 |
| 40100 | Holding register | Offset 99 | 03 / 06 / 16 |
Full Comparison Table
| Modbus RTU | Modbus TCP | |
|---|---|---|
| Physical layer | RS-485 (or RS-232) twisted pair | Ethernet, 100 Mbit/s, copper or fiber |
| Speed | 9.6 – 115.2 kbit/s typical | 100 Mbit/s, limited by the devices |
| Frame | Address + PDU + CRC-16 | MBAP header + PDU, no CRC |
| Error checking | CRC-16 in every frame | Handled by TCP |
| Addressing | Slave ID 1 – 247 set on the device | IP address; unit ID only for gateways |
| Nodes per network | Up to 247 addresses, 32 per segment | Limited by the network, not the protocol |
| Masters / clients | Exactly one master | Several clients at the same time |
| Transactions | One at a time, then a silent interval | Overlapping, paired by transaction ID |
| Distance | Up to 1200 m at low baud rates | 100 m per copper link; fiber for more |
| Termination | Required at both ends | Not needed |
| Typical port / wiring | Two-wire, daisy chained | RJ45 into a switch, port 502 |
| Cost per node | Very low | Low, but every node needs Ethernet |
| Diagnostics | Bus tester, error counters | Ping, Wireshark, switch statistics |
Work with Modbus on real hardware
Wire an RS-485 line, configure a Modbus TCP client and read a live drive both ways. Pune classroom or live online.
PLC Blocks for Each
On an S7-1200 or S7-1500 the difference is which instruction you call. Neither uses %IW or %QW addresses — Modbus data lives in data blocks.
| Task | Siemens S7-1200 / S7-1500 | Notes |
|---|---|---|
| Set up an RS-485 port | MB_COMM_LOAD | Baud rate, parity, port hardware identifier — call once |
| Act as RTU master | MB_MASTER | One request at a time, with MB_MODE and MB_DATA_ADDR |
| Act as RTU slave | MB_SLAVE | The PLC answers another master |
| Act as TCP client | MB_CLIENT | Connection ID, partner IP, port 502 |
| Act as TCP server | MB_SERVER | The PLC answers SCADA or another PLC |
| Data location | A data block array | Neither method uses %IW or %QW addresses |
A drive on Modbus RTU exposes its control and status words as holding registers. Register numbers differ between products and firmware, so confirm them in the drive's own register table.
| Example G120 register | Direction | Content |
|---|---|---|
| 40100 | PLC → drive | Control word |
| 40101 | PLC → drive | Speed setpoint, 16384 = 100 % of p2000 |
| 40110 | Drive → PLC | Status word |
| 40111 | Drive → PLC | Actual speed |
| Parameter registers | Both | Individual drive parameters |
Related: the same drive on PROFINET uses a telegram instead of registers — see Siemens PLC and VFD networking and the Live PLC–VFD Simulator.
Gateways and Mixed Plants
Most plants end up with both. A Modbus gateway is a TCP server on one side and an RTU master on the other: the client sends a normal TCP request with a unit ID, and the gateway forwards it to that slave address on the serial line. The serial line keeps its own speed limits, so a gateway makes old devices reachable — it does not make them fast.
Which One to Use
Security
Modbus was designed in 1979 for a trusted serial link, and nothing in either variant authenticates the sender. Over Ethernet that matters.
| Risk | Why it exists | What to do |
|---|---|---|
| No authentication | Any client on the network can write registers | Segregate the Modbus network, firewall port 502 |
| No encryption | Frames are readable with Wireshark | Keep it off the business network and off the internet |
| Writes are unchecked | A wrong write can start a motor | Allow only the registers the application needs; use a read-only gateway where possible |
Common Faults
| Symptom | Where | Likely cause | Fix |
|---|---|---|---|
| No response at all | RTU | Wrong slave ID, baud rate, parity or A/B swapped | Match the settings, swap A and B once to test |
| Works for one device, fails when a second is added | RTU | Duplicate slave ID, or missing termination | Unique IDs, terminators only at the two ends |
| Values off by one register | Both | 40001 counted as offset 1 instead of 0 | Subtract one from the documented register number |
| Byte order looks wrong on 32-bit values | Both | Word order differs between vendors | Swap the two words, or use the device's word-order setting |
| Connection drops under load | TCP | Too many clients, or a client not closing connections | Limit clients, reuse connections, check the server limit |
| Exception code 02 returned | Both | Register does not exist on that device | Check the register map and the quantity requested |
Step-by-Step Lab: Read the Same Register Both Ways
Hands-on- An S7-1200 or S7-1500 with an RS-485 communication module, and one Modbus device — a drive, a power meter or an instrument.
- A Modbus TCP device or a gateway, and a PC with a Modbus test tool and Wireshark.
- Estimated time: 60 minutes.
Set up the serial port
Call MB_COMM_LOAD once with the port hardware identifier, the device baud rate and parity.
Read a holding register over RTU
Call MB_MASTER with MB_MODE 0, the register address and a quantity of 1.
Capture the serial transaction
Note how long a single read takes at your baud rate, then increase the quantity to 10 registers and compare.
Read the same data over TCP
Call MB_CLIENT with the partner IP address and port 502, requesting the same register.
Watch it on the wire
Capture the TCP traffic in Wireshark and filter on modbus.
Break it on purpose
Change the slave ID on the RTU side, then request a register the device does not have on the TCP side.
You understand both variants if you can explain why the same register number worked on either connection, what the transaction ID is for, and why ten registers in one request beats ten requests.
Frequently asked questions
What is the difference between Modbus RTU and Modbus TCP?
They carry the same requests — the same function codes, the same registers — but wrap them differently. RTU is a serial protocol on RS-485 with a slave address and a CRC in every frame, and one master polling one device at a time. TCP puts the same request inside an Ethernet packet with a seven-byte MBAP header, drops the CRC because TCP already checks the data, and lets several clients talk at once.
Is Modbus TCP faster than Modbus RTU?
Almost always. RTU at 19.2 kbit/s needs milliseconds for a single small transaction and must wait for a silent interval before the next one, while TCP runs at 100 Mbit/s and allows overlapping transactions. The practical limit on TCP is usually how fast the device can answer, not the network.
Can I connect a Modbus RTU device to a Modbus TCP network?
Yes, with a Modbus gateway. The gateway is a TCP server on the Ethernet side and the RTU master on the serial side, and the unit ID field in the TCP frame tells it which serial device the request is for.
Why does register 40001 map to offset 0?
The 4xxxx numbering is a documentation convention that starts counting at one, while the protocol on the wire starts at zero. So holding register 40001 is offset 0, and 40100 is offset 99. Many devices and PLC blocks differ on this point, which is why values often come back one register out.
Does Modbus TCP still need a CRC?
No. TCP provides its own checksum and guarantees delivery and ordering, so the Modbus CRC is dropped. That is also why an RTU frame captured on a serial line has two extra bytes at the end that a TCP frame does not.
Can two masters share one Modbus RTU line?
No. RTU allows exactly one master on a line. If two devices need to read the same instrument, either poll it with one master and share the data, or move to Modbus TCP, where several clients can connect at once.
Is Modbus secure?
No. Neither variant authenticates or encrypts anything, and any client that reaches a Modbus TCP server can write to it. Treat the Modbus network as trusted-only: separate it from the business network, restrict port 502 at the firewall, and never expose it to the internet.