When a Modbus device receives a request it cannot carry out, it answers with an exception response: the function code with its top bit set (the code plus 0x80), then a one-byte exception code. 83 02 means a Read Holding Registers request (0x03) failed with exception 02, Illegal Data Address. Paste the response bytes into the box above to decode them.
The function byte
function in the response = request function + 0x80
A normal reply repeats the request’s function code. An exception sets the top bit, so 0x03 becomes 0x83 and 0x10 becomes 0x90. Subtract 0x80 to find the request that failed.
The exception code
01 function · 02 address · 03 value · 04 device failure
01 Illegal Function: the device does not support the request. 02 Illegal Data Address: the address, or the address plus the count, is outside what it holds. 03 Illegal Data Value: a value in the request is not allowed. 04 Server Device Failure: the device failed while carrying it out.
Function codes in decimal and hex
FC16 = 16 decimal = 0x10
Manuals quote function codes both ways. The box above reads a bare number as decimal when that names a function (16 is Write Multiple Registers) and shows the hexadecimal reading beside it; write 0x16 to mean hexadecimal.
No reply at all is not an exception. A timeout points at the wiring, the unit ID, the baud rate and parity, termination, or a frame the device threw away for a bad CRC. Only a device that understood the frame can send an exception.
Modbus exception code examples
Response 83 02 from a meter
Subtract 0x80 from 0x83 to get 0x03, Read Holding Registers. Exception 02 is Illegal Data Address: the registers asked for do not exist in the device. The usual cause is an off-by-one address from a 40001-style reference, or a request that runs past the end of a block; the Modbus address converter settles the first.
0x90 − 0x80 = 0x10, Write Multiple Registers, and 03 is Illegal Data Value. The device received the frame but refused a value in it: a setpoint outside its range, a register count that does not match the byte count, or a write to a read-only block.
In decimal, function 16 is Write Multiple Registers, sent on the wire as 0x10. Read as hexadecimal, 0x16 would be Mask Write Register, a different request. When a manual says “FC16” it means decimal.
Illegal Data Address. The device does not hold the address asked for, or the address plus the number of registers runs past what it holds. Check the address convention and the length of the read.
What does Modbus exception 01 mean?
Illegal Function. The device does not support that function code, or not in its current state. Many meters support only a few functions, often 03, 04 and 16.
Why do I get a timeout instead of an exception?
The device never understood the request: wrong unit ID, baud rate or parity, reversed A and B wires, missing termination, or a CRC error. Exceptions only come from a device that read the frame correctly. The RS-485 termination and bias checker covers the wiring side.
What are exceptions 0A and 0B?
Gateway exceptions. 0A, Gateway Path Unavailable, means the gateway could not route the request; 0B, Gateway Target Device Failed to Respond, means the device behind it did not answer. Both point past the gateway, to the serial side.
Limits of this result
A public function code is not proof that a particular server implements it; confirm the current device register map and firmware documentation.
Function code alone does not establish register meaning, scaling, signedness, byte/word order, address convention or whether a write is safe.
Functions marked serial-line only are not general Modbus TCP services. Gateway behaviour can add further restrictions.
Treat no response separately from an exception response. Cabling, timing, unit ID, CRC/parity, routing and device availability still require diagnosis.
Read Modbus devices on the Gateway
A ZMB reads and writes Modbus RTU devices locally and sends the data to the Gateway over the wireless mesh, so a meter can be integrated without a data cable back to the panel.