A BACnet client that reads analog-input 3 on a room controller gets back 21.5, the unit degrees-Celsius and four status flags. A Modbus client that reads input register 30012 on a meter gets back 215 and nothing else. The number becomes 21.5 °C only when someone applies the manufacturer's register map. That difference drives most of the work when BACnet controllers and Modbus meters on one site must share data.
Side by side
| BACnet | Modbus | |
|---|---|---|
| Standard | ANSI/ASHRAE 135, also ISO 16484-5 | Modbus Organization specifications |
| Data model | Objects such as analog-input, analog-value, binary-output, multi-state-value, schedule and trend-log, each with properties | Four tables: coils, discrete inputs, input registers and holding registers; each register is 16 bits |
| Addressing | Device instance (0 to 4,194,302), unique across the internetwork, then object type and instance | Server address (1 to 247 on a serial bus) or IP address, then register number |
| Meaning of a value | In the object: name, units, status flags | In a separate register map for each model |
| Networks | BACnet/IP, MS/TP over RS-485, BACnet/SC and others | Modbus TCP; Modbus RTU over RS-485, or RS-232 for one device |
| Default port | UDP 47808 (0xBAC0) | TCP 502 |
| Finding devices | Discovery with Who-Is and I-Am | None; configure the address of each device |
| Receiving changes | Polling, or change-of-value (COV) subscriptions | Polling only |
| Reading many values | ReadPropertyMultiple, where the device supports it | Up to 125 contiguous registers per function 03 or 04 request |
| Commands | A 16-level priority array on commandable objects | Direct writes; the last write wins |
| Alarms and schedules | Standard objects and services | Device-specific registers, if any |
| Security | BACnet/SC (TLS over WebSockets) | Modbus Security (TLS) on TCP 802, rarely implemented |
| Typical devices | HVAC controllers, VAV boxes, chillers, BMS supervisors | Electricity meters, inverters, drives, PLCs |
Objects compared with registers
A BACnet temperature point is an object, for example analog-input 3 on device 12001. Its properties include Object_Name ("Room 2.14 temperature"), Present_Value (21.5), Units (degrees-Celsius) and Status_Flags. Status_Flags has four bits: in-alarm, fault, overridden and out-of-service. A client can read the value and also tell whether to trust it.
Units is an enumeration in Standard 135, so a client can decode it without a vendor document. The value still depends on the person who configured the controller. An analog-value set to no-units, or to the wrong unit, needs a point list as much as a Modbus register does. Object names also differ between vendors and sites, and one controller can publish hundreds of objects. The BACnet objects guide shows how to build a point list that a receiving system can use.
On a Modbus device, the same temperature is input register 30012, which holds 215. The register map says that it is an int16 with a scale of 0.1 and a unit of °C. Two conventions cause most Modbus mapping errors.
First, 30012 is a documentation number, not the address on the wire. The leading 3 means input register, and the count starts at 30001 for protocol address 0. The client therefore reads address 11 with function 04. A client set to 12 reads the next register and returns a plausible but wrong value. The Modbus address converter does this conversion.
Second, a 32-bit value spans two registers. The Modbus specification puts the high byte of each register first, but it does not define the order of the two registers, and vendors differ. An energy total of 1,234.5 kWh as a float32 is 0x449A followed by 0x5000. Read with the words swapped, it decodes as 8,607,918,080. Check every 32-bit point against a known, non-zero value on the meter display. The Modbus register decoder shows each byte and word order for one pair of registers, and the Modbus register map guide covers types and scaling.
Networks
BACnet/IP sends BACnet messages in UDP datagrams, on port 47808 by default. Discovery uses broadcasts, and IP routers do not forward them. A BACnet network that spans several IP subnets therefore needs one BACnet broadcast management device (BBMD) on each subnet. Each BBMD has a broadcast distribution table that lists its peers. Do not put two BBMDs on one subnet, because both forward the same broadcasts. A single client on another subnet can register with a BBMD as a foreign device, for a time-to-live in seconds, and must renew the registration before it expires. The routing and BBMD guide covers both.
MS/TP runs over RS-485. Masters take MAC addresses 0 to 127 and pass a token. Only the token holder can start a request. Slaves take addresses up to 254, answer requests and never hold the token. Every MS/TP device must support 9,600 and 38,400 bit/s. The standard also defines 19,200, 57,600, 76,800 and 115,200 bit/s as options. Set Max_Master to the highest master address on the bus, so that masters do not poll empty addresses and the token cycle stays short. The BACnet/IP vs MS/TP guide compares the two.
BACnet/SC sends BACnet over TLS-secured WebSockets. Every node connects to a hub. Direct connections between nodes are optional.
Every BACnet device has a device instance from 0 to 4,194,302. Instance 4,194,303 is reserved as a wildcard. The instance must be unique across the whole internetwork, including every network behind a router. Each BACnet network also has a network number, from 1 to 65,534, which routers use. Duplicate device instances are a common commissioning fault. Two controllers answer a Who-Is for the same instance, and a client that binds by instance can read from the wrong one. Check for duplicates before a second client goes live. The discovery guide explains how.
Modbus TCP runs over TCP on port 502. Modbus RTU runs over RS-485, or over RS-232 for a single device. One client polls up to 247 server addresses, and each server answers only when asked. The Modbus TCP vs RTU guide compares them.
An MS/TP bus and a Modbus RTU bus can use the same cable type, but they cannot share one pair. The framing is different, and MS/TP masters transmit tokens without being asked, which corrupts Modbus traffic.
Commands and priority
A commandable BACnet object, such as a binary output that starts a fan, holds a 16-slot priority array. Each system that commands the object writes to its own slot. The object follows the lowest-numbered slot that holds a value. Standard 135 names five slots: 1 manual life safety, 2 automatic life safety, 5 critical equipment control, 6 minimum on/off and 8 manual operator. The other slots are available for site use. When every slot is empty, the object uses its Relinquish_Default value.
A command stays in its slot until the system that wrote it releases the slot by writing null. The common failure is a command that nobody releases. Suppose an energy system switches a fan off at priority 12 during a demand response event and then stops without a release. The fan stays off after the event, although the BMS schedule commands it on at priority 16, which ranks below 12. Agree the slot and the release procedure with the BMS owner before the first write. After a write, read Priority_Array as well as Present_Value.
A Modbus write overwrites the register. If a BMS and an energy system both write the same set point, the last write wins, and neither system knows. The BACnet priority array guide explains how priority, release and default interact.
Which one to use
The equipment usually decides the protocol. The system owner decides how you connect: the BMS owner holds the BACnet point list and approves every write.
| Situation | Usual approach |
|---|---|
| Meters with Modbus, a BMS on BACnet | Read the meters over Modbus. Give the BMS the data it needs through a gateway or the energy system, mapped point by point |
| HVAC plant on BACnet/IP, energy analysis wanted | Read the BACnet objects directly as a second client. Do not write unless the BMS owner agrees |
| HVAC controllers on MS/TP only | Read through the BMS supervisor, which already polls them, or through a BACnet router to BACnet/IP. A router puts your polls on the MS/TP trunk, often at 38,400 or 76,800 bit/s, so agree the poll rate with the BMS owner |
| New submeters for an existing BMS | Choose meters with the interface that the BMS reads best, or add a gateway that publishes BACnet objects |
Mapping between the two
A gateway that publishes Modbus meter readings as BACnet objects needs one line in its map for each point. The line gives the register and function code, the data type and word order, the scale, the BACnet object type and instance, and the Units value.
The map also needs a fault rule for a meter that stops answering. A correct gateway sets the object's Reliability to communication-failure. This sets the fault bit in Status_Flags, and a BMS that checks the flag then knows the value is not current. A gateway that holds the last value with no fault flag shows a flat line that looks like a real reading. To test the rule, disconnect the meter and read Reliability and Status_Flags on the BACnet side. The protocol gateway guide lists what else to specify, and the stale data guide explains how to handle old values downstream.
Security
Neither BACnet/IP nor Modbus TCP authenticates clients or encrypts data. Any host that reaches UDP 47808 can write to any object that the controller allows writes to. Any host that reaches TCP 502 can write a holding register. Put building control equipment on its own VLAN. Allow UDP 47808 only from the BACnet clients and the BBMD peers. Allow TCP 502 only from the gateway or BMS that polls the meters. Do not forward either port from the internet. Check each BBMD's broadcast distribution table, because a wrong entry forwards every local broadcast to that address. BACnet/SC and Modbus Security add TLS, but both ends must support them, and most installed equipment does not.
BACnet and Modbus with Edge
Edge on the ZGW-20 Gateway reads both protocols. As a BACnet/IP client, it polls Present_Value from analog, binary and multi-state input, output and value objects. One network configuration holds up to 16 controllers, with up to 64 points on each. Edge polls every minute, or on a minute-aligned interval such as 300 seconds. As a Modbus client, it reads Modbus TCP and RTU equipment, with the data type and the byte and word order set for each point. Readings from EpiSensor Zigbee meters and sensors sit beside these points, each with its own export identifier, and go to the same destinations.
Edge can also give readings to a BMS as Modbus TCP registers. Its Modbus Server listens on TCP 10502 and maps each reading to a coil, or to one or two registers as int16, uint16, int32, uint32 or float32. When a source stops reporting, the register keeps its last value. The BMS therefore needs its own staleness check, for example an alarm when an energy counter stops rising.
The BACnet client has limits. It polls and does not subscribe to COV. The COV guide compares the two. It does not connect to an MS/TP bus, so read MS/TP controllers through a BACnet router. Its settings have no foreign device registration, so put the Gateway on the controllers' subnet, or ask the BMS owner to provide routing. Writes to output and value objects work only for points that an administrator provisions for control. Each write uses a priority from 1 to 16, and 16 when none is set. Edge cannot release a command, because its write rejects a null value. Agree a release procedure with the equipment owner before any write. The BMS and SCADA meter integration application shows a complete architecture.
Common questions
What is the main difference between BACnet and Modbus?
BACnet carries meaning with the data: each point is an object with a name, a present value, units and status flags, and devices can be discovered. Modbus carries numbers in registers, and the meaning, units and scale come from a separate register map for each device model.
When does a project need BACnet rather than Modbus?
When the receiving system needs change-of-value notifications, standard alarm, schedule or trend objects, or commands that respect other systems' priorities. For polling energy readings, Modbus is enough, and it is the interface found on most electricity meters.
What port does BACnet/IP use?
UDP port 47808 (0xBAC0) by default. A site can use other UDP ports to separate BACnet/IP networks. Modbus TCP uses TCP port 502.
Can BACnet and Modbus devices work together?
Yes, through a gateway or a controller that speaks both. Each point needs a mapping between a Modbus register and a BACnet object, including the data type, word order, scale and unit. It also needs a fault rule: when the Modbus device stops answering, the BACnet object should report Reliability communication-failure, not hold the last value as if it were current.