Modbus to IEC 60870-5-104 gateway for SCADA integration

Max IEC Gateway polls your Modbus TCP and RTU devices and serves their values to SCADA masters over IEC 60870-5-104 (TCP) or IEC 60870-5-101 (serial). Configure it in a web browser, send IEC commands back to Modbus and watch every exchange in the traffic monitor.

30-day free trial • no credit card • Windows 10/11 (64-bit) and Linux

Dashboard of the Max IEC Gateway web interface with live values. Click to enlarge.

What is Max IEC Gateway?

Quick answer: Max IEC Gateway is gateway software for Windows and Linux that converts Modbus TCP/RTU to IEC 60870-5-104 and IEC 60870-5-101. It reads coils and registers from Modbus devices, maps each value to an IEC type ID and information object address, reports changes spontaneously, answers general interrogation and writes IEC commands back to Modbus.

IEC 60870-5-104

TCP server for SCADA and control-centre links.

  • Port 2404, up to 10 client connections
  • Configurable k, w and t0–t3
  • Spontaneous data and general interrogation

IEC 60870-5-101

Serial outstation for RTU-style links.

  • Balanced or unbalanced link mode
  • RS-232/RS-485 COM port, 8E1
  • Configurable baud rate and link address

Modbus TCP/RTU

Client that polls any number of devices.

  • Coils, inputs and registers (FC01–FC04)
  • 16/32-bit integers, Float32, Float64
  • ABCD, CDAB, BADC and DCBA byte order

Key features

Everything needed to bring Modbus field devices into an IEC 60870-5 SCADA system

Web-based configuration

Add Modbus devices and point mappings in any browser, then apply and reload without restarting the gateway.

IEC commands to Modbus

Single, double and set-point commands are written to coils and holding registers, direct or select-before-operate.

Traffic monitor

Separate live logs for Modbus polls, IEC traffic, commands and connection events help you commission and troubleshoot.

Historian and trends

Values are recorded (72 hours by default), shown as trend charts and exported to CSV.

Quality flags

Points carry the invalid (IV) flag when their Modbus device stops answering, and IV + not topical (NT) until their first successful read.

Import and export

Export the whole configuration as JSON and load it on another gateway.

Supported IEC type IDs

Monitoring and control types available for point mappings in version 1.1.0

Monitoring direction (Modbus → SCADA)

Type IDDescription
M_SP_NA_1 (1)Single-point information
M_DP_NA_1 (3)Double-point information
M_ST_NA_1 (5)Step position information
M_BO_NA_1 (7)Bitstring of 32 bits
M_ME_NA_1 (9)Measured value, normalized
M_ME_NB_1 (11)Measured value, scaled
M_ME_NC_1 (13)Measured value, short float
M_SP_TB_1 (30)Single point with CP56Time2a time tag
M_DP_TB_1 (31)Double point with CP56Time2a time tag
M_ME_TF_1 (36)Short float with CP56Time2a time tag
M_IT_NA_1 (15)Integrated totals (energy counter)
M_ST_TB_1 (32)Step position with CP56Time2a time tag
M_BO_TB_1 (33)Bitstring of 32 bits with CP56Time2a time tag
M_ME_TD_1 (34)Normalized value with CP56Time2a time tag
M_ME_TE_1 (35)Scaled value with CP56Time2a time tag
M_IT_TB_1 (37)Integrated totals with CP56Time2a time tag

Control direction (SCADA → Modbus)

Type IDDescriptionModbus write
C_SC_NA_1 (45)Single commandFC05 Write Single Coil
C_DC_NA_1 (46)Double commandFC05 Write Single Coil
C_SE_NA_1 (48)Set-point, normalized valueFC06/FC16 to the mapped holding register(s)
C_SE_NB_1 (49)Set-point, scaled valueFC06 Write Single Register
C_SE_NC_1 (50)Set-point, short floatFC16 Write Multiple Registers (2 registers)
C_IC_NA_1 (100)General interrogationAnswered from the latest polled values
C_SC_TA_1 (58), C_DC_TA_1 (59)Single and double command with CP56Time2a time tagSame writes as C_SC_NA_1 / C_DC_NA_1
C_SE_TA_1 (61), C_SE_TB_1 (62), C_SE_TC_1 (63)Set-points with CP56Time2a time tagSame writes as the untagged set-points
C_CI_NA_1 (101)Counter interrogationRead, freeze, freeze and reset, reset; groups 1-4
C_RD_NA_1 (102)Read commandAnswered with the latest value (COT 5)
C_CS_NA_1 (103)Clock synchronizationOffset logged; optionally sets the PC clock

How it works

1

Add Modbus devices

Enter IP address, port, unit ID, poll interval, timeout and retries for each device.

2

Map points

Give each coil or register an IEC type ID, IOA and common address, with scale and offset.

3

Connect SCADA

Point the IEC 104 master at port 2404 (or wire the IEC 101 link) and start data transfer.

Read the Modbus to IEC 104 mapping guide

Lifetime license

$150

One-time payment · 1 license = 1 computer · no subscription

  • No device or data-point limits in the software
  • IEC 60870-5-104 and IEC 60870-5-101
  • Web configuration, traffic monitor and historian
  • Lifetime free updates
  • Email support
  • 30-day money-back guarantee
Buy now

Or start with the free 30-day trial

Where it is used

Substations

Bring Modbus TCP meters and relays into an IEC 104 SCADA system.

Renewable plants

Report inverter, meter and weather-station values to grid operators over IEC 104.

Water and utilities

Connect pump and flow controllers with Modbus TCP to telecontrol masters.

Industrial sites

Expose PLC and energy-management data to an IEC 60870-5 control centre.

Frequently asked questions

It polls Modbus TCP and RTU devices such as meters, relays, inverters and PLCs and makes their values available to a SCADA master as an IEC 60870-5-104 server (TCP port 2404) or an IEC 60870-5-101 serial outstation. Commands from the SCADA master are written back to Modbus coils and holding registers.

Monitoring: M_SP_NA_1, M_DP_NA_1, M_ST_NA_1, M_BO_NA_1, M_ME_NA_1, M_ME_NB_1, M_ME_NC_1 and integrated totals M_IT_NA_1, plus the CP56Time2a time-tagged M_SP_TB_1, M_DP_TB_1, M_ST_TB_1, M_BO_TB_1, M_ME_TD_1, M_ME_TE_1, M_ME_TF_1 and M_IT_TB_1. Control: C_SC_NA_1, C_DC_NA_1, C_SE_NA_1, C_SE_NB_1, C_SE_NC_1 and their time-tagged variants, plus general interrogation C_IC_NA_1, counter interrogation C_CI_NA_1, read C_RD_NA_1 and clock synchronization C_CS_NA_1.

Yes. Version 1.1.0 polls Modbus RTU devices on an RS-485 or RS-232 serial port (several devices per line) and Modbus RTU over TCP devices behind serial device servers, as well as Modbus TCP devices.

A lifetime license costs $150 as a one-time payment and is activated on one computer at a time; you can move it to a new computer whenever you need to. It includes lifetime free updates and a 30-day money-back guarantee.

Yes. The 30-day trial includes every feature. Trial sessions run for 15 minutes; restart the gateway to start a new session. No credit card is needed.

Point it at a Modbus slave simulator, for example the simulator in ModbusBB, and connect any IEC 60870-5-104 test master to port 2404. The traffic monitor shows every Modbus poll and IEC exchange while you test.

Yes. Every change to devices, mappings, IEC settings, ports and the web interface address applies live without restarting the service. Only the part affected by the change restarts: for example, a changed device restarts only that device's polling, and a changed IEC 104 port restarts only that listener, so the SCADA master reconnects.

Yes. Commands can run in direct-execute or select-before-operate mode. In select-before-operate mode an execute must match a preceding select within the select timeout (1 to 60 seconds, 10 seconds by default); otherwise the gateway answers with a negative confirmation. A deactivation (COT 8) cancels a pending select.

Yes. Energy registers can be mapped as integrated totals (M_IT_NA_1 or M_IT_TB_1). The SCADA master reads, freezes or resets them with counter interrogation (C_CI_NA_1, groups 1 to 4), and the gateway can also report them periodically.

Yes. Version 1.1.0 is available for Windows 10/11 (64-bit), where it runs as a Windows service, and for Linux x64, where it runs as a systemd service.

Try it on your own devices

Download the free trial and have Modbus values on your IEC 104 master in minutes.