When a device understands your request but will not answer it, it returns an exception. That is good news: the device is alive, the framing is right, and the problem is in what you asked for. A timeout tells you much less.
How an exception looks on the wire
The device echoes your function code with the high bit set, then one byte of exception code. A failed FC03 comes back as 0x83 followed by the code.
request 01 03 00 64 00 02 read 2 holding registers from address 100
response 01 83 02 exception 02: illegal data addressThe codes you will actually see
| Code | Name | What it usually means |
|---|---|---|
| 01 | Illegal function | The device does not implement this function code. Reading input registers from a device that only has holding registers gives this. |
| 02 | Illegal data address | The address, or the address plus the quantity, is outside what the device maps. The most common exception by far. |
| 03 | Illegal data value | The quantity is out of range — asking for 0 registers, or more than 125 in one read. |
| 04 | Server device failure | The device hit an internal error trying to serve the request. |
| 05 | Acknowledge | The request was accepted but will take a while. Rare in reads. |
| 06 | Server device busy | The device is occupied. Retry after a pause. |
| 0B | Gateway target device failed to respond | A Modbus gateway could not reach the downstream device — the unit ID is wrong, or the serial device is off. |
Exception 02 is usually one of four things
- Off-by-one from the 4xxxx convention — you asked for 40100 instead of protocol address 99.
- The wrong table — the value is in input registers and you used FC03.
- A read that starts inside a valid block but runs past its end, because the quantity is too large.
- A gap in the device's map. Many devices map scattered blocks, not a continuous range.
Exception versus timeout
An exception is an answer. A timeout is silence, and the causes are different: wrong IP or port, wrong unit ID on a serial line, wrong baud rate or parity, a cable, or a device that is simply off. If some unit IDs answer and others time out on the same line, the line is fine and the unit ID is wrong.
Modbus Polling Tool
Poll, inspect and troubleshoot Modbus devices in real time.