
The manual's number trap
A manual that calls the first holding register 40001 is not telling you what to put in the request. The message counts from zero, the manual counts from one, and a wrong guess often still gets an answer, only from the neighbouring register.
Two numberings in one specification
The Modbus Application Protocol specification numbers things twice. In its data model every element of a table is numbered from 1 to n. In the message, the address field is a 16-bit number counted from 0. The first register is 1 in the model and 0 on the wire, so holding registers 1 to 16 are addressed as 0 to 15.
What 40001 is
Many manuals print register numbers as 00001, 10001, 30001 and 40001: a leading digit for the table, then a count from 1. It is a convention used in manuals. Neither the Application Protocol specification nor the serial line guide contains it, and it never travels on the wire, where the function code names the table. Under that convention 40001 is the first holding register, and the address field carries 0000. Some manuals use six digits, and some print the plain address.
What goes wrong
Put 40001 itself in the address field and the field holds 9C41. A device with fewer registers than that answers with exception 02, illegal data address. That error is at least honest. It is also how an off-by-one at the end of a table shows itself: the read one past the last register is refused.
The quiet failure is the neighbour. Ask for 1 where 0 was meant and the server answers normally with its second register. Both numbers are valid, so no error appears and the value looks plausible: a setpoint turns up where a temperature should be.
Test with a value you know
Whether a manual's 40001, 1 or 0 is the first register has to be confirmed by a test read. Find a register whose value you can see another way, on the device's display or a label, and read it. The address that returns that value is the one to use for that device.
Common mistakes
- Putting the manual's number in the address field. The wire carries the position in the table counted from 0. Subtract the table's base, then confirm with a test read.
- Taking a reply as proof of the right register. A valid reply proves only that the address exists. Compare it with a value you can see.
- Assuming every manual counts alike. Some count from 0, some from 1, some add a table digit. Read the manual's own example, then test.
Edit this page — content/fundamentals/rs485-modbus/the-manuals-number-trap.mdx
Discuss this article
Ask about this page. The answer stays here, on the page it belongs to, for whoever hits the same wall next.