Modbus Register Addresses: Convert 40001 to Offset 0

Gepubliceerd op October 7, 2026
Bijgewerkt op October 8, 2026
Toolgebruik-tutorials
5 minuten leestijd

The manual says register 40010, but the request needs offset 9. Follow a complete Modbus read to check address notation, FC03, and decimal versus hex input.

Modbus
Register addresses
Holding registers
FC03
FLOAT32

Modbus Register Addresses: Convert 40001 to Offset 0

The manual says 40010, but the software wants a starting address of 9. Both can refer to the same register. If the manual numbers its first holding register 40001 and the software expects a protocol offset, enter decimal 9. This is how the ModbusKit RTU request generator's address field works.

Some software accepts reference numbers such as 40010 and performs the conversion for you. A field labelled “Address” alone does not tell you which format it expects.

What does 40010 mean in this manual?

Addresses in a Modbus PDU start at zero. How a manual labels those addresses, and how they map to the device's data, depends on the manufacturer. Section 4.4 of the Application Protocol describes that mapping.

When the manual numbers holding registers from 40001, the conversion is:

40001 - 40001 = 0  ->  0000 HEX
40010 - 40001 = 9  ->  0009 HEX

The Modbus Organization introduction uses this reference notation. Its leading 4 identifies the holding-register area; that digit is not a prefix carried in the request's address bytes.

Another manual might label the same location as zero-based offset 9, hexadecimal offset 0009, or one-based register number 10. Look for a column heading or note that states the number base and where numbering starts. A worked request in the manual can help resolve an unclear table. An offset already given as 9 needs no subtraction: applying “always subtract one” would move it to the wrong register.

Six-digit references such as 400001 need their own conversion, too. The register address converter lets you choose five-digit references, six-digit references, or request offsets. Select the data area and notation used in the manual before entering the value. For request offsets, you can also use HEX with a 0x prefix.

Build a request for register 40010

Suppose the manual uses the 40001 convention, the device address is 1, and you need two holding registers starting at 40010. Open the RTU request generator, select DEC, then enter device address 1, function FC03, Start Address 9, and Quantity 2. The request is:

01 03 00 09 00 02 14 09

The address bytes are 00 09, followed by the register count 00 02. The final bytes, 14 09, are the CRC in transmission order; its numerical value is 0914. Paste the complete frame into the frame parser to inspect these fields.

The function code is a separate choice. The 4 at the start of a holding-register reference does not mean FC04. FC03 reads holding registers; FC04 reads input registers, as defined in sections 6.3 and 6.4 of the Application Protocol. A device can place different data at the same offset in those two areas, or support only one of the functions.

If the manual calls for an input-register read at protocol offset 9, the request is:

01 04 00 09 00 02 A1 C9

Changing the function changes the CRC as well. A valid CRC can still accompany a request for the wrong area or offset; the CRC guide explains what the checksum checks.

Why entering 10 can read offset 16

The input format matters even after you have calculated the offset. 9 happens to mean the same value in decimal and HEX. 10 does not:

Intended offsetEnter with DEC selectedEnter with HEX selected
Nine90009
Ten10000A
Sixteen160010

Entering 10 in HEX mode produces address bytes 00 10, which select decimal offset 16. The device may return data without an error if that register exists, and the value may even look plausible. Check the address bytes in the generated request when the input format is in doubt.

Check the address before changing FLOAT32 word order

Suppose the value starting at 40010 is a FLOAT32. Each register holds 16 bits, so you need two consecutive registers to read the complete 32-bit value. Quantity 2 in the request above reads the two words belonging to one float.

With the high word first, data bytes 3F 80 00 00 represent FLOAT32 value 1. Here is a complete example response:

01 03 04 3F 80 00 00 F7 CF

The 04 is the data byte count; the next four bytes contain the float. After parsing the complete response, use the FLOAT32 example to inspect those four data bytes.

There is no starting offset in this response. A normal FC03 response does not repeat the request's 00 09, so keep the matching request to establish which registers were read.

If the float looks wrong, check that the request started at the right address and read both registers before trying another word order. Swapping the wrong pair of registers cannot recover the missing data. Once the address and count are correct, use the float and byte-order guide to check the layout specified by the manufacturer.

Gerelateerde artikelen

Modbus Register Addresses: Convert 40001 to Offset 0 | ModbusKit