What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Modbus RTU and Modbus TCP carry the same command. Both wrap one Modbus application data unit (PDU), a function code followed by function-specific data, but they package it differently. RTU puts the PDU in a serial frame with a one-byte server address and a two-byte CRC, and it uses silent intervals on the line to mark where frames start and end. Modbus TCP puts the same PDU behind a seven-byte MBAP header and sends it over TCP/IP. The command semantics stay the same; the envelope and the link behavior change.
What stays the same: the shared PDU
The Modbus Organization’s application specification defines the protocol data unit independently of the communication layer beneath it. In its words, “The MODBUS protocol defines a simple protocol data unit (PDU) independent of the underlying communication layers.” (MODBUS Application Protocol Specification V1.1b3, section 4.1, dated April 26, 2012, available at https://www.modbus.org/file/secure/modbusprotocolspecification.pdf.)
A request PDU is a one-byte function code followed by request data. That data carries whatever the function needs, such as a starting address, a quantity, a subfunction code, or a value. A normal response echoes the function code and returns response data. An exception response sets the high bit of the function code and supplies an exception code. Addresses and multi-byte values are big-endian in both transports.
The data model is also shared. The application specification defines four data types:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
- Supports Auto Device Routing for easy configuration
- Supports route by TCP port or IP address for flexible deployment
- Connects up to 32 Modbus TCP servers
- Connects up to 31 or 62 Modbus RTU/ASCII slaves
- Accessed by up to 32 Modbus TCP clients (retains 32 Modbus requests for each Master)
| Data type | Size | Access |
|---|---|---|
| Discrete inputs | Single bit | Read-only |
| Coils | Single bit | Read-write |
| Input registers | 16-bit | Read-only |
| Holding registers | 16-bit | Read-write |
What the specification does not standardize is how a device maps its internal memory onto these data points. That mapping is vendor- and device-specific, so the device’s register map is the authority for any given address.
The RTU envelope
The Modbus serial line guide (Specification and Implementation Guide for MODBUS over serial line V1.02, dated December 20, 2006, at https://www.modbus.org/file/secure/modbusoverserial.pdf) defines the RTU message as:
- One-byte server address
- One-byte function code
- Zero to 252 bytes of data
- Two-byte CRC
RTU is a binary mode. Nothing on the wire is hexadecimal text. Each character is sent asynchronously as 8 data bits with the least significant bit first. The guide’s default is even parity. Odd or no parity may also be supported; with no parity, two stop bits are used so the character stays at 11 bits. Every device on the same serial line must use the same transmission mode and serial port settings.
Frame boundaries come from timing
Because RTU has no length field, the receiver relies on time. The complete frame is sent as one continuous character stream. A silent interval of at least 3.5 character times marks the end of a frame. A gap longer than 1.5 character times inside a frame makes the frame incomplete, and the receiver should discard it. For rates above 19,200 bps, the guide recommends fixed timer values of 750 microseconds for t1.5 and 1.750 milliseconds for t3.5.
Rank #2
- Supports Auto Device Routing for easy configuration
- Supports route by TCP port or IP address for flexible deployment
- Converts between Modbus TCP and Modbus RTU/ASCII protocols
- 1 Ethernet port and 1, 2, or 4 RS-232/422/485 ports
- 16 simultaneous TCP masters with up to 32 simultaneous requests per master
The CRC
The RTU CRC is 16 bits. It covers the message and is transmitted low byte first, which is a common source of mismatches when a frame is checked by hand.
The TCP envelope
The application specification gives the Modbus TCP application data unit (ADU) as the PDU plus a seven-byte MBAP header. The header carries:
- Transaction identifier, which lets a client match each response to its request
- Protocol identifier, which is zero for Modbus
- Length, the byte count of the remaining fields, including the unit identifier
- Unit identifier, which addresses a device behind a bridge or gateway
TCP is a byte stream, so Modbus TCP does not use RTU’s silent intervals. The receiver uses the MBAP length field to find message boundaries and the transaction identifier to correlate replies.
Modbus TCP/IP uses TCP/IP port 502, according to the Modbus Organization’s FAQ (https://www.modbus.org/faq). That is a port convention, not a security control. The organization describes a separate Modbus Security protocol that layers TLS over Modbus and uses X.509 certificates. Ordinary Modbus TCP should not be assumed to provide those protections.
Rank #3
- Serial Port: RS232 and RS485, can be used simultaneously
- Redundant Power supply: DC 5-36V or Terminal power supply
- Modbus Gateway: Modbus RTU to Modbus TCP, Modbus Polling
- Work mode: TCP Server/Client, UDP Server/Client, HTTPD Client
- Configuration by Webpage, AT command and Setup software
Side-by-side comparison
| Aspect | Modbus RTU | Modbus TCP |
|---|---|---|
| Shared payload | Modbus PDU (function code plus data) | Modbus PDU (function code plus data) |
| Envelope | Serial frame: server address, PDU, CRC | MBAP header (7 bytes), then PDU |
| Frame boundary | Silent interval of at least 3.5 character times | MBAP length field |
| Error check | 16-bit CRC, low byte first | Handled by TCP/IP transport; no Modbus CRC in the TCP ADU (per the application specification’s ADU layout) |
| Addressing | Server address byte on the serial line | Unit identifier byte in MBAP; IP address and port for the connection |
| Physical or transport layer | Serial line, such as EIA/TIA-485 (commonly called RS-485) | TCP/IP over Ethernet or other IP networks |
| Default port | Not applicable | TCP port 502 |
| Maximum sizes | 256-byte serial ADU (253-byte PDU) | 260-byte TCP ADU (253-byte PDU) |
| Built-in encryption | Not stated in the cited serial guide | Not in ordinary Modbus TCP; Modbus Security (TLS with X.509 certificates) is a separate protocol |
The same command in both envelopes
Take a read of two holding registers starting at address 0x006B on a device addressed as unit 17. The PDU is the same in both cases: function code 03, starting address 0x006B, quantity 0x0003.
RTU frame: 11 03 00 6B 00 03 followed by the 2-byte CRC (low byte first).
TCP frame: 00 01 00 00 00 06 11 03 00 6B 00 03.
In the TCP frame, the bytes 00 01 are the transaction identifier, 00 00 is the protocol identifier, 00 06 is the length (unit identifier plus the five-byte PDU), and 11 is the unit identifier. The function and data bytes are identical to the RTU example, which is the core of the distinction.
Note the register-address convention. The PDU uses zero-based addresses, while many device manuals list registers starting at one. A manual entry labelled 108 may correspond to PDU address 0x006B (107 decimal), depending on the vendor’s convention. Check the manual before assuming either form.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #4
- This is an RS485 device data acquisitor / IoT gateway designed for the industrial environment. It combines multi functions in one, including serial server, Modbus gateway, MQTT gateway, RS485 to JSON, etc. Bi-directional transparent data transmission between RS485 and Ethernet.
- Support Rail-mount :easy to combine multi rail-mounted serial server together, more freely. Support Modbus gateway: suitable for Modbus gridding upgrade, can be used with 3D configuration software. Support NTP protocol: getting network time info for serial output or data upload.
- Multi communication modes: supports TCP server / TCP client / UDP mode / UDP multicast. Multi configuration methods: supports Web browser configuration, obtaining dynamic IP via DHCP,DNS protocol connected domain server address. MQTT/JSON to Modbus: more flexible conversion between different protocols.
- Multi hosts roll-polling support: different network devices will be identified and responsed respectively, no more crosstalk issue while communicating with multi network devices
- User-defined heartbeat/registration packet: easy for cloud communication and device identification.
Choosing between RTU and TCP
The protocol does not determine which transport is better. The physical layout of the installation does.
- Choose RTU when the device or the existing network exposes a serial interface, such as EIA/TIA-485, and the wiring, baud rate, parity, and device addresses are known.
- Choose TCP when devices communicate over Ethernet and TCP/IP and you need network-based client and server connectivity.
Before deciding, compare the following for your installation: available interfaces, distance and topology, network reach, expected polling rate and load, latency requirements, unit and device addressing, gateway requirements, and the security architecture. These are trade-offs that follow from the different media and framing. The protocol documents do not establish that one transport is always faster or better.
Bridging serial devices to a TCP network
A gateway connects a serial Modbus device to an IP network. The Modbus Organization’s FAQ describes a gateway that converts a physical layer such as RS-232 or RS-485 to Ethernet and converts Modbus to Modbus TCP/IP. When you evaluate one, confirm three things: it passes the unit identifiers your system uses, it supports the function codes your devices implement, and its register mapping matches the target system.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting
RTU frames fail
- Confirm that every device on the line uses the same transmission mode and serial settings (baud rate, data bits, parity, and stop bits).
- Check that characters are sent continuously and that no gap longer than 1.5 character times appears inside a frame.
- Check the 3.5-character silent interval between frames. At rates above 19,200 bps, the guide’s fixed values are 750 microseconds (t1.5) and 1.750 milliseconds (t3.5).
- Verify the server address and the CRC byte order, low byte first.
TCP requests fail
- Verify IP reachability between client and device.
- Confirm the port configuration. Modbus TCP/IP uses port 502 per the Modbus Organization’s FAQ.
- Check the MBAP length field and transaction handling in the client.
- If a gateway is involved, check the unit identifier it expects.
- Confirm the device supports the requested function.
The Modbus Organization’s Modbus TCP Toolkit (https://www.modbus.org/modbus-tcp-toolkit) includes official documentation, diagnostic tools, sample source code, and pre-test software. The organization states that it is not intended for serial-line implementations.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
- Master mode supports 32 TCP slaves at the same time
- Slave mode supports 16 TCP masters, up to 31 or 62 serial slaves at the same time
- Serial redirect function
- Redundant dual DC power inputs
- Easy configuration & Build-in Ethernet cascading for easy wiring
A valid frame still gets a wrong answer
A correctly formed frame can address a register the device does not implement, or one whose meaning differs from what you expect. The application specification leaves the memory mapping to the vendor, so check the manufacturer’s register map for each address.
Function codes behave differently by device
Several functions are defined for serial lines only: Read Exception Status (07), Diagnostics (08), Get Comm Event Counter (11), Get Comm Event Log (12), and Report Server ID (17). Do not assume these work over TCP. Device implementations may also support only a subset of the standard functions.
Specification versions
The Modbus Organization’s specifications index (https://www.modbus.org/modbus-specifications) lists MODBUS Application Protocol Specification V1.1b3 and the Serial Line Protocol and Implementation Guide V1.02 as the current documents for new implementations. It marks the 1996 serial-line specification as legacy only. The application specification is dated April 26, 2012, and the serial guide is dated December 20, 2006. The sources examined do not restrict these documents to any geographic region.
When you read a device manual, check which version of the specifications it claims to follow. Older devices may implement earlier revisions, and the register map, not the specification, governs what each address does.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




