Skip to main content
Logo
Back to Blog List

Quickly understand RS485 communication message (Brief description of Modbus protocol)

LMS_FanLg2024-07-304 views

As a widely used industrial automation communication protocol, Modbus protocol realizes data exchange between electronic devices through serial communication lines (such as RS-485) or Ethernet. This article will focus on a brief description of Modbus protocol messages based on RS-485 communication.

 

1. Common function code description

 

 

Function code

name

Remark

16-bit access

Input Memory

0x04

Read Input Register

The IO system provides this type of data

Internal memory or physical output memory

0X03

Read Holding Registers

Change this data through the application

0X06

Writing a single register

 

0X10

Writing multiple registers

 

2. Read the format of function code 0X04

Follow the rule: high digit first, low digit last

Read the value of motor 1 input voltage H0x01F7:

Address bits

Function code

Register Address

Number of registers

CRCCheck code

High

Low

High

Low

High

Low

01

04

01

F7

00

01

slightly

Return message:

Address bits

Function code

Number of bytes

Register Value

CRCCheck code

High

Low

High

Low

01

04

02

00

E7

slightly

3. Write the format of single register function code 0X06

Write the value of motor baud rate H0x0231=5: the factory default baud rate is 115200

Address bits

Function code

Register Address

Register Value

CRCCheck code

High

Low

High

Low

High

Low

01

06

02

31

00

05

slightly

Return message: original instruction returns

Address bits

Function code

Register Address

Register Value

CRCCheck code

High

Low

High

Low

High

Low

01

06

02

31

00

05

slightly

Setting values ​​and corresponding table with baud rate:

hexadecimal

Baud rate

0

9.6Kbps

1

9.6Kbps

2

19.2Kbps

3

38.4Kbps

4

57.6Kbps

5

115.2Kbps

6

256Kbps

7

500Kbps

4. Format of writing multiple registers function code 0X10

Write the value of register address H0230=2; H0x0231=1 of motor 1:

Address bits

Function code

Register Address

Number of registers

Number of bytes

Register Value

CRCCheck code

High

Low

High

Low

High

Low

High

Low

01

10

02

30

00

02

04

00 01 00 02

slightly

Return message:

Address bits

Function code

Register Address

Number of registers

CRCCheck code

High

Low

High

Low

High

Low

01

06

02

30

00

02

slightly

5. Quick Reference Table of Instructions

project

instruction

Read parameters (holding registers)

01 03 XX XX 00 0Z(CRCslightly)

Read parameters (input registers)

01 04 XX XX 00 0Z(CRCslightly)

Write Parameters

Parameter size: 1 register

(CRCslightly)or

01 10 XX XX 00 01 02 yy yy(CRCslightly)

Write Parameters

Parameter size: 2 registers

01 10 XX XX 00 02 04 yy yy yy yy(CRCslightly)

Relative Movement in Profile Position Mode

Switch to position control mode (1-PP mode)

01 10 03 C2 00 01 02 00 01(CRCslightly)

Can be omitted if the motor is in position mode

Write target location

01 10 03 E7 00 02 04 yy yy yy yy (CRCslightly)

The forward and reverse rotation of the motor depends on the positive and negative value of the given position

Write motion speed

01 10 03 F8 00 02 04 yy yy yy yy (CRCslightly)

Starter Motor

01 10 03 80 00 01 00 06 (CRCslightly)

Motor ready status

01 10 03 80 00 01 02 00 07 (CRCslightly)

Send control word 4F (motor enable, shaft holding)

01 10 03 80 00 01 02 00 4F  (CRCslightly)

Send control word 5F

01 10 03 80 00 01 02 00 5F  (CRCslightly)(4F-5F motor movement)

Keep moving

To modify the target position (if necessary), send control words 4F…5F in sequence.

Absolute motion in profile position mode

Switch to position control mode (1-PP mode)

01 10 03 C2 00 01 02 00 01(CRCslightly)

Can be omitted if the motor is in position mode

Write target location

01 10 03 E7 00 02 04 yy yy yy yy (CRCslightly)

The forward and reverse rotation of the motor depends on the positive and negative value of the given position

Write motion speed

01 10 03 F8 00 02 04 yy yy yy yy (CRCslightly)

Starter Motor

01 10 03 80 00 01 02 00 06  (CRCslightly)

Motor ready status

01 10 03 80 00 01 02 00 07  (CRCslightly)

Send control word 0F (motor enable)

01 10 03 80 00 01 02 00 0F  (CRCslightly)

Send control word 1F

01 10 03 80 00 01 02 00 1F  (CRCslightly)

Keep moving

To modify the target position (if necessary), send control words F→1F;

Running in profile speed mode

Switch to profile velocity mode (3-PV mode)

01 10 03 C2 00 01 02 00 03(CRCslightly)

Can be omitted if the motor is in profile speed mode

Set the direction of movement

01 10 03 F3 00 01 02 00 00(CRCslightly) or

01 10 03 F3 00 01 02 00 40(CRCslightly)

Write target speed

01 10 04 48 00 02 04 yy yy yy yy (CRCslightly)

Starter Motor

01 10 03 80 00 01 02 00 06  (CRCslightly)

Motor ready status

01 10 03 80 00 01 02 00 07  (CRCslightly)

Send control word 0F

01 10 03 80 00 01 02 00 0F  (CRCslightly)

Modify running speed

Modify the running speed (if necessary), and send 0F after modification

Running in origin return mode

Switch to origin return mode (6-HM mode)

01 10 03 C2 00 01 02 00 06(CRCslightly)

This can be omitted if the motor is in origin return mode

Origin return method (method: 17-32)

01 10 04 16 00 01 02 yy yy (CRCslightly)

Starter Motor

01 10 03 80 00 01 02 00 06  (CRCslightly)

Motor ready status

01 10 03 80 00 01 02 00 07  (CRCslightly)

Send control word 0F

01 10 03 80 00 01 02 00 0F  (CRCslightly)

Send control word 1F

01 10 03 80 00 01 02 00 1F  (CRCslightly)

Motor motion state switching

Motor emergency stop

01 10 03 80 00 01 02 01 02 (CRCslightly)

Send control word 02 for emergency stop, and send 06-07 first to run

Motor stopped (offline)

01 10 03 80 00 01 02 00 07  (CRCslightly)

Motor free stop

Motor pause (enable shaft holding)

01 10 03 80 00 01 02 01 1F (CRCslightly)

Send control word 11F to pause (motor is enabled), send 0F to run

Save parameter H1010:01(H0026)

01 10 00 26 00 02 04 65 76 61 73 (CRCslightly)

Restore parameter H1011:01(H003C)

01 10 00 3C 00 02  04 64 61 6F 6C (CRCslightly)

Fault reset

01 10 03 80 00 01 02 00 80 (CRCslightly)

After the fault source is cleared, the control word 80 can release the device fault state.

 

Share to:

Related Articles

Related Solutions

Related News

Need help with product selection?

Download the selection guide or consult our engineers to quickly find the right motion control product.