Quick answer: IEC 60870-5-104 uses four timers and two window sizes. Standard defaults: t0 = 30 s (connect), t1 = 15 s (wait for acknowledgement), t2 = 10 s (acknowledge received data), t3 = 20 s (send TESTFR when idle), k = 12 unacknowledged I-frames and w = 8. Keep t2 below t1, keep w at most two thirds of k, and use the same values on master and outstation.

An IEC 60870-5-104 connection is kept alive and flow-controlled by four timers and two window sizes. When they do not match between master and outstation, the link typically connects and then drops at a regular interval. This guide explains each parameter and how to troubleshoot the usual symptoms.

Which frames do the timers supervise?

  • I-frames (information) carry ASDUs and a send and receive sequence number.
  • S-frames (supervisory) only acknowledge received I-frames.
  • U-frames (unnumbered) control the link: STARTDT and STOPDT start and stop data transfer, TESTFR checks that the link is alive. Each has an "act" and a "con" variant.

After the TCP connection is up, the master sends STARTDT act and the outstation answers STARTDT con. Only then does the outstation send data. A connection without STARTDT is a standby connection.

What do t0, t1, t2, t3, k and w mean?

ParameterStandard defaultRangeMeaning
t030 s1-255 sTimeout for establishing the TCP connection
t115 s1-255 sTimeout waiting for an acknowledgement of a sent I-frame or TESTFR/STARTDT/STOPDT act
t210 s1-255 sMaximum time before acknowledging received I-frames with an S-frame when there is no data to send
t320 s1 s-48 hIdle time after which a TESTFR act is sent
k121-32767Maximum number of sent but unacknowledged I-frames
w81-32767Acknowledge at the latest after receiving w I-frames

Two rules keep both ends consistent: t2 must be smaller than t1, so acknowledgements arrive before the sender gives up; and w should not exceed two thirds of k, so the receiver acknowledges before the sender's window is full. Use the same values on both sides unless the SCADA vendor specifies otherwise.

How do the parameters work together?

The sender may have at most k I-frames unacknowledged. The receiver acknowledges after w I-frames, or when t2 expires without it having data to send (an I-frame in the other direction also acknowledges). If the sender gets no acknowledgement within t1, it closes the connection. When nothing at all is exchanged for t3, a station sends TESTFR act; if TESTFR con does not arrive within t1, the connection is closed.

How do you troubleshoot an unstable IEC 104 link?

SymptomLikely causeWhat to do
Connection closes about 15 s after data startst1 expired: the peer does not acknowledge I-frames (w larger than the peer's k, peer not sending S-frames, packet loss)Match k and w on both ends, keep w ≤ ⅔ k, capture traffic to see which side stops acknowledging
Connection closes after 20-40 s of silenceTESTFR act unanswered, or a firewall/NAT drops idle TCP sessionsCheck TESTFR con in the log, lower t3 below the firewall idle timeout
TCP connects but no data arrivesMaster never sent STARTDT act, or the connection is a redundancy standbyEnable STARTDT on the master, check which connection is active
Only data after general interrogation, no changesValues do not change, or spontaneous transmission not configuredChange a value at the source and watch for COT 3; check the point is enabled
Negative confirmations with COT 44-47Unknown type ID, COT, common address or IOACompare the signal list and CA in master and outstation
Connection refusedWrong IP or port, firewall, maximum connections reached, IP not allowedTest port 2404, check allow-lists and connection limits
Connection closed with sequence number errorFrames lost or a device restarted without a new TCP connectionCheck network quality; both ends must reset sequence numbers on a new connection

What should you check first?

  1. Can the master reach the outstation at all? Test TCP port 2404 from the master's network (firewall, routing, VPN).
  2. Does the outstation accept the connection? Check its maximum number of connections and any IP allow-list.
  3. Does the master send STARTDT act, and does it receive STARTDT con?
  4. Are k, w, t1, t2 and t3 identical on both sides, with t2 < t1 and w ≤ ⅔ k?
  5. Do the common address and the COT/CA/IOA sizes match? (They are fixed at 2/2/3 in standard IEC 104.)
  6. Does a general interrogation return all expected points with COT 20, followed by an activation termination?

Max IEC Gateway shows the timer and window settings on its Settings page (defaults t0 10 s, t1 15 s, t2 10 s, t3 20 s, k 12, w 8) and logs every IEC connect, disconnect and interrogation on the Traffic page, which is usually enough to see which of the cases above applies.

Frequently asked questions

Why must t2 be smaller than t1?

The receiver waits up to t2 before acknowledging. If t2 were longer than the sender's t1, the sender would time out and close the connection before the acknowledgement could arrive.

Is it safe to increase k for faster transfers?

Only if the master is configured with the same k and a matching w. A larger k lets more frames travel before an acknowledgement, which helps on high-latency links, but a mismatch causes t1 timeouts.

Try it with Max IEC Gateway. The gateway polls Modbus TCP and RTU devices and serves the values as an IEC 60870-5-104 server or IEC 60870-5-101 outstation, with a traffic monitor that shows every exchange.

Download the free 30-day trial See all features