You read 40001 in the manual, type 40001 into your Modbus client, and get an exception. This is the most common first hour of a Modbus integration, and the cause is that two different numbering conventions share the same documents.
Two numbering schemes
The wire protocol uses a zero-based address: a 16-bit number from 0 to 65,535 carried in the request. The first holding register is address 0.
The older data-model convention writes a reference number whose leading digit names the table and whose remaining digits are a one-based index:
| Reference | Table | Protocol address |
|---|---|---|
| 0xxxx — 00001 | Coil | 0 |
| 1xxxx — 10001 | Discrete input | 0 |
| 3xxxx — 30001 | Input register | 0 |
| 4xxxx — 40001 | Holding register | 0 |
So 40001 means "the first holding register", which on the wire is address 0. 40100 is protocol address 99. The conversion is: drop the leading digit, subtract one.
40001 -> holding register, protocol address 0
40100 -> holding register, protocol address 99
30011 -> input register, protocol address 10
10001 -> discrete input, protocol address 0
protocol address = reference - 40001 (for holding registers)How to tell which one a document means
- A five-digit number starting with 0, 1, 3 or 4 is a reference. It also tells you the table, which is useful.
- A number under 65,536 with the table named separately — "holding register 99" — is almost always a protocol address.
- If the manual has a column headed "address" and another headed "register", they are usually the two conventions side by side.
- If the first documented register is 1 rather than 0, the document is one-based even if it does not say so.
When you are still not sure
Read both. If the manual says 40100 and you read protocol address 100 and get something that looks like the value for 40101, you are one out. Reading a small range around the address and looking at the shape of the data usually settles it in seconds — a scanner that shows a block of registers at once makes this obvious.
Modbus Polling Tool
Poll, inspect and troubleshoot Modbus devices in real time.