Protocol conversion

The gateway polls Modbus TCP and RTU devices and presents their values to SCADA masters as an IEC 60870-5-104 server and/or an IEC 60870-5-101 outstation. Both servers can run at the same time from the same point list.

  • IEC 60870-5-104 server on TCP port 2404 (configurable), up to 10 client connections
  • IEC 60870-5-101 outstation on a COM port: balanced or unbalanced, 8 data bits, even parity, 1 stop bit
  • Configurable COT (1-2 octets), common address (1-2) and IOA (1-3) sizes for IEC 101
  • Any number of Modbus TCP, RTU and RTU-over-TCP devices, each with its own unit ID, poll interval, timeout and retries
  • Common address (CA) and information object address (IOA) set per point
  • Spontaneous transmission (COT 3) whenever a value or its quality changes
Point mappings: each Modbus value gets an IEC type ID, IOA and common address.

IEC type IDs and Modbus data

Modbus registers are read with FC01 (coils), FC02 (discrete inputs), FC03 (holding registers) and FC04 (input registers). Registers can be decoded as UInt16, Int16, UInt32, Int32, Float32 or Float64 in ABCD, CDAB, BADC or DCBA byte order, with a scale factor and offset per point. Addresses are 0-based protocol addresses (register 40001 = address 0).

Monitoring direction (Modbus → SCADA)

Type IDDescription
M_SP_NA_1 (1)Single-point information
M_DP_NA_1 (3)Double-point information
M_ST_NA_1 (5)Step position information
M_BO_NA_1 (7)Bitstring of 32 bits
M_ME_NA_1 (9)Measured value, normalized
M_ME_NB_1 (11)Measured value, scaled
M_ME_NC_1 (13)Measured value, short float
M_SP_TB_1 (30)Single point with CP56Time2a time tag
M_DP_TB_1 (31)Double point with CP56Time2a time tag
M_ME_TF_1 (36)Short float with CP56Time2a time tag
M_IT_NA_1 (15)Integrated totals (energy counter)
M_ST_TB_1 (32)Step position with CP56Time2a time tag
M_BO_TB_1 (33)Bitstring of 32 bits with CP56Time2a time tag
M_ME_TD_1 (34)Normalized value with CP56Time2a time tag
M_ME_TE_1 (35)Scaled value with CP56Time2a time tag
M_IT_TB_1 (37)Integrated totals with CP56Time2a time tag

Control direction (SCADA → Modbus)

Type IDDescriptionModbus write
C_SC_NA_1 (45)Single commandFC05 Write Single Coil
C_DC_NA_1 (46)Double commandFC05 Write Single Coil
C_SE_NA_1 (48)Set-point, normalized valueFC06/FC16 to the mapped holding register(s)
C_SE_NB_1 (49)Set-point, scaled valueFC06 Write Single Register
C_SE_NC_1 (50)Set-point, short floatFC16 Write Multiple Registers (2 registers)
C_IC_NA_1 (100)General interrogationAnswered from the latest polled values
C_SC_TA_1 (58), C_DC_TA_1 (59)Single and double command with CP56Time2a time tagSame writes as C_SC_NA_1 / C_DC_NA_1
C_SE_TA_1 (61), C_SE_TB_1 (62), C_SE_TC_1 (63)Set-points with CP56Time2a time tagSame writes as the untagged set-points
C_CI_NA_1 (101)Counter interrogationRead, freeze, freeze and reset, reset; groups 1-4
C_RD_NA_1 (102)Read commandAnswered with the latest value (COT 5)
C_CS_NA_1 (103)Clock synchronizationOffset logged; optionally sets the PC clock

Typical mapping choices

Modbus sourceUsual IEC type
Coil / discrete input (1 bit)M_SP_NA_1 or M_SP_TB_1 single point; M_DP_NA_1 double point
Register, 16-bit integerM_ME_NB_1 scaled value (-32768 to 32767 after scaling)
Register pair, Float32 or 32-bit integerM_ME_NC_1 short float (M_ME_TF_1 with time tag)
Value scaled to -1 … +1M_ME_NA_1 normalized value
Register used as a bit patternM_BO_NA_1 bitstring of 32 bits
Tap-changer or step positionM_ST_NA_1 step position

Mapping is free: any register can be mapped to any supported monitoring type. See the mapping guide and type ID and COT reference.

Commands from SCADA to Modbus

IEC control commands are written to the mapped Modbus coil or holding register.

  • Single commands (C_SC_NA_1) and double commands (C_DC_NA_1) to coils with FC05
  • Scaled set-points (C_SE_NB_1) with FC06, short-float set-points (C_SE_NC_1) with FC16
  • Direct execute or select-before-operate (SBO) mode
  • Optional activation termination (ACT_TERM) for commands and set-points
  • Every command and its confirmation is recorded in the Commands log

Web-based configuration

Everything is configured in a browser: open http://localhost:5000 on the gateway PC, or the PC's address from another computer on your network.

  • Devices with enable/disable switch
  • Point mappings with scale and offset, filtered per device
  • Live dashboard with current values and quality
  • Apply and reload without restarting the process
  • Configuration export and import as JSON
  • License activation page
IEC 104 and IEC 101 settings page.

Traffic monitor

Four separate live logs show what the gateway is doing while you commission a site.

  • Modbus: poll results and value changes
  • IEC: spontaneous, interrogation and ASDU traffic
  • Commands: IEC command requests and results
  • Connections: IEC 104/101 connect and disconnect events
  • Auto-refresh every 3 seconds; ring buffers keep memory use bounded
Traffic monitor with separate Modbus, IEC, command and connection logs.

Historian and trends

The built-in historian stores point values in the local database for trend analysis.

  • Retention period configurable (default 72 hours), sampling every 2 seconds by default
  • Trend charts with 1 h, 6 h, 24 h and 7 d ranges
  • Several points on the same chart
  • CSV export per point
  • Historian can be switched off
Historian trends with 1 h, 6 h, 24 h and 7 d ranges and CSV export.

IEC 60870-5-104 parameters

All APCI timers and window sizes are editable in the settings page. Values must match what the SCADA master expects; see the timer and troubleshooting guide.

ParameterMeaningGateway default
t0Connection establishment timeout10 s (standard: 30 s)
t1Timeout for send or test APDUs (waiting for acknowledgement)15 s
t2Acknowledge received I-frames when no data is sent (t2 < t1)10 s
t3Send a TESTFR test frame after this idle time20 s
kMaximum number of unacknowledged I-frames12
wAcknowledge at the latest after w received I-frames8

Also included

Quality handling

Points are sent as invalid (IV) when their Modbus device stops answering, and as invalid and not topical (NT) until their first successful read.

Auto-reconnect

Lost Modbus TCP connections are re-established automatically; failed reads are retried a configurable number of times per device.

SQLite database

Configuration and history live in a local SQLite file; no database server is needed.

Structured logging

Serilog log files with rolling files and configurable log levels.

Scaling and offset

Engineering units per point: IEC value = raw value × scale + offset.

.NET 8, self-contained

Installer and portable ZIP include the .NET 8 runtime; nothing else to install.

New in version 1.1

Added in the 1.1 release.

  • Modbus RTU (RS-485/RS-232) and Modbus RTU over TCP devices in addition to Modbus TCP, several devices per serial line
  • Integrated totals (energy counters, M_IT_NA_1/M_IT_TB_1) with counter interrogation: read, freeze, freeze and reset, reset, groups 1-4, sequence number and carry; optional periodic counter reports
  • Deadband per measured value (absolute or percent) and cyclic transmission (COT 1)
  • Event buffering while no IEC master is connected
  • Single and double points from register bits (all four double-point states)
  • Int64 and UInt64 register values
  • Time-tagged types M_ST_TB_1, M_BO_TB_1, M_ME_TD_1, M_ME_TE_1 and M_IT_TB_1
  • Time tags in UTC or local time (SU bit), invalid-until-synchronized option; clock synchronization (C_CS_NA_1) is logged and can optionally set the PC clock
  • IEC 104 master IP allow-list, applied live
  • IEC 101 parity, stop bits and master link address settings
  • Configurable select-before-operate timeout (1-60 s, default 10 s)
  • Time-tagged commands (C_SC_TA_1, C_DC_TA_1, C_SE_TA_1, C_SE_TB_1, C_SE_TC_1) and read command (C_RD_NA_1)
  • CSV import and export of mappings with a validated preview and all-or-nothing import
  • 9 device templates: Eastron SDM120 and SDM630, Schneider PM5xxx and Altivar, Carlo Gavazzi EM24, SMA, SunSpec, Growatt, ABB ACS580
  • Every change applies live without restarting the service; only the affected part restarts
  • Secure web interface login: administrator password, CSRF protection, lockout after failed logins, optional HTTPS and an allowed-networks list
  • Runs as a Windows service or a Linux systemd service; Linux (x64) build
  • Deactivating the license frees the computer on the license server (one computer per license)

Trial and licensed version

FeatureFree trialLicensed
IEC 104 server and IEC 101 outstationYesYes
Modbus TCP/RTU polling, commands, traffic monitor, historianYesYes
Period of use30 daysUnlimited (lifetime license)
Session length15 minutes, then restartUnlimited
Computers1 (evaluation)1 (movable)
Production useNoYes
Updates and email supportNoLifetime free updates, email support