A meter on an RS-485 trunk and the same meter with an Ethernet port answer the same Modbus requests from the same register map. Only the transport differs: Modbus RTU on the serial line, Modbus TCP on the IP network. For an existing site, the choice usually follows the interface that the equipment already has.
This guide is part of the Modbus and RS-485 series.
Side by side
| Modbus RTU | Modbus TCP | |
|---|---|---|
| Transport | Serial line: RS-485, or RS-232 for one device | TCP/IP over Ethernet or Wi-Fi |
| Device address | 1 to 247 on the bus, 0 for broadcast | IP address, plus a unit identifier for devices behind a gateway |
| Frame | Address, function code, data, 16-bit CRC | MBAP header (7 bytes), function code, data |
| Error check | CRC in every frame | TCP checksums; no Modbus CRC |
| Frame separation | A silence of at least 3.5 character times | The length field in the header |
| Requests in progress | One at a time on the bus | Several connections; the transaction identifier pairs each response |
| Typical settings | Baud rate, parity, stop bits, address | IP address, port 502, unit identifier |
| Cabling | A daisy-chained twisted pair, terminated at both ends | The site network |
The RS-485 vs Modbus guide explains the serial layer under Modbus RTU, and how RS-232 differs. The function codes (03 read holding registers, 04 read input registers, 06 and 16 write) are the same in both. So are the data types, word order and scaling. The register map guide covers those.
Frames compared
A request to read three holding registers from address 0x006B, on device 17, looks like this in each variant:
| Variant | Bytes (hexadecimal) |
|---|---|
| Modbus RTU | 11 03 00 6B 00 03 followed by the 2-byte CRC |
| Modbus TCP | 00 01 00 00 00 06 11 03 00 6B 00 03 |
In the TCP frame, the first seven bytes are the MBAP header: a transaction identifier (0x0001), the protocol identifier (always 0 for Modbus), the length of what follows (6 bytes) and the unit identifier (0x11). The protocol data unit after the header is identical. The Modbus CRC and LRC calculator computes the RTU check bytes:
Timing and throughput
On an RTU bus, one request is in progress at a time. The time per request is the time on the wire for the request and the response, plus the device's response time, plus the gap between frames. At 9,600 baud with even parity, each character takes 11 bits, so one byte takes about 1.15 ms. The Modbus serial guide fixes the frame gap at 1.75 ms above 19,200 baud. The Modbus RTU timing calculator adds it up for a whole bus:
The polling and retries guide shows what one offline device does to that cycle. On Modbus TCP, the network is rarely the limit. The device's own processing time and its limit on simultaneous connections usually are. Many meters accept only a few TCP connections at once, and some accept one. Check the limit before several systems poll the same meter.
Unit identifiers and gateways
A serial-to-Ethernet gateway lets Modbus TCP clients reach RTU devices. The client sends a TCP request to the gateway's IP address, with the serial device's address in the unit identifier. The gateway sends the request on the bus, waits for the response and returns it over TCP.
Three points need care:
- Unit identifier for direct TCP devices. The Modbus TCP guide says that the unit identifier is not used when the server is addressed by its IP address, and recommends 0xFF. Many devices ignore it; some require 1 or their own serial address. Use the value in the device manual.
- Timeouts. The client's TCP timeout must be longer than the gateway's serial timeout plus the time the gateway waits for other requests on the bus. Otherwise the client gives up while the gateway is still waiting.
- RTU over TCP. Some converters pass RTU frames, with the CRC and without the MBAP header, straight through a TCP connection. This is not Modbus TCP, and the client must be set for it. The protocol gateway guide explains the difference between a bridge and a translating gateway.
Record, for each point, the IP address, port, unit identifier and the physical device that answers. After a gateway is replaced, the routing is the first thing to check.
Choosing for a site
Choose the transport that the equipment already has:
| Situation | Usual choice |
|---|---|
| Meters with RS-485 terminals only, in one or two panels | Modbus RTU on a short bus, or a local interface |
| Equipment with an Ethernet port on a managed network | Modbus TCP, with a network address plan agreed with site IT |
| An existing RTU bus already polled by a BMS | Read from the BMS or a gateway; do not add a second master |
| Many serial devices that several systems must read | A Modbus TCP gateway in front of the bus |
| Serial meters far from the gateway with no cable route | A wireless Modbus interface next to the meters |
For both variants, get the register map for the exact model and firmware before you choose hardware. "Modbus supported" does not tell you which values the device publishes.
Security
Modbus TCP and Modbus RTU have no authentication and no encryption. Any client that can reach port 502 can read and, where the device allows it, write. Protect them with the network design: a separate network or VLAN for control equipment, firewall rules that allow only the systems that need access, and no exposure to the internet.
The Modbus Organization publishes a separate Modbus Security protocol, which wraps Modbus in TLS with X.509 certificates on port 802. Both ends must support it. A gateway in front of a plain Modbus device does not make the device secure; it only moves the boundary.
Test reads before any write. Treat writes as a separate, approved step with the equipment owner.
Modbus TCP and RTU with Edge
Edge on the ZGW-20 Gateway is a Modbus client for both variants. It polls Modbus TCP devices on the site network, including RTU-over-TCP converters, and Modbus RTU devices on a serial port of the Gateway. Each connection has its own queue, timeouts and polling rate. For a meter where no data cable can reach the Gateway, a ZMB Modbus interface reads it over RS-485 and sends the registers over the Zigbee mesh. Edge also includes a Modbus server, so a BMS or SCADA system can read the site's data from the Gateway as Modbus TCP registers. The Modbus RS-485 commissioning guide covers the serial side in detail.
Common questions
What is the difference between Modbus TCP and Modbus RTU?
Modbus RTU runs on a serial line such as RS-485: binary frames, a CRC for error checking and one master polling devices by address. Modbus TCP runs on an IP network: the same requests inside a 7-byte MBAP header, sent over TCP to port 502, with TCP providing error checking. The function codes and register maps are the same.
What port does Modbus TCP use?
TCP port 502. The Modbus Security protocol, which wraps Modbus in TLS, uses port 802.
What is the unit ID in Modbus TCP?
A one-byte field in the MBAP header. A gateway uses it to route a request to a serial device behind it, so it carries that device's address. For a device that speaks Modbus TCP directly, the Modbus TCP guide recommends 0xFF, but many devices expect 1 or accept any value.
What is Modbus RTU over TCP?
An RTU frame, with its address and CRC, sent unchanged over a TCP connection, without the MBAP header. Some serial-to-Ethernet converters work this way. It is not Modbus TCP, and a client must be set to the right mode for each device.