Quick answer: A 32-bit Modbus float spans two 16-bit registers, and devices store them as ABCD (big-endian), CDAB (word swapped), BADC (byte swapped) or DCBA. Choose the order that turns a known reading into the right number, then send the value as M_ME_NC_1 short float; IEC 104 transmits it in its own fixed octet order, so the SCADA master needs no byte-order setting.
Modbus registers are 16 bits wide, so a 32-bit float occupies two registers. The Modbus specification does not say which register holds which half, and manufacturers chose differently. A gateway has to reassemble the four bytes in the right order before it can send the value to an IEC 104 master.
What do ABCD, CDAB, BADC and DCBA mean?
Name the four bytes of the IEEE 754 value A (most significant) to D (least significant). The order describes how they appear in the two consecutive registers:
| Order | Also called | Register 1 | Register 2 | Read as ABCD gives |
|---|---|---|---|---|
| ABCD | big-endian, high word first | 42F6 | E979 | 123.456 (correct) |
| CDAB | word swapped, little-endian word order | E979 | 42F6 | -1.883 × 1025 |
| BADC | byte swapped | F642 | 79E9 | -9.861 × 1032 |
| DCBA | fully little-endian | 79E9 | F642 | 1.518 × 1035 |
If the gateway decodes with the wrong order, the result is usually an absurd number. The last column shows what the correct value 123.456 turns into when the registers are read as ABCD although the device uses another order.
How do you find the right order?
- Pick a value you know: a voltage near 230 V, a frequency near 50 or 60 Hz, a set-point you wrote yourself.
- Read the two registers and decode them in all four orders. A tool that shows every interpretation at once, such as ModbusBB's data-type decoding, saves time.
- The order that produces the plausible value is the one to configure. It normally applies to every float of that device.
- Check one negative or very small value as well, because a wrong order can occasionally look plausible by coincidence.
How is the float sent over IEC 104?
Once decoded, the value is sent as M_ME_NC_1 (type 13, short floating point) or, with a time tag, M_ME_TF_1 (type 36). IEC 60870-5 defines the byte order on the wire itself: the IEEE 754 value is transmitted least significant octet first. For 123.456 the four value octets in the ASDU are 79 E9 F6 42, followed by the quality descriptor. The Modbus byte order is therefore only a setting on the Modbus side; the SCADA master never sees it.
What about 32-bit integers and Float64?
- 32-bit integers have the same word-order problem as floats. Send them as M_ME_NC_1 (exact up to 16,777,216) or, after scaling into -32768 to 32767, as M_ME_NB_1.
- Float64 values (four registers) have no IEC 60870-5 equivalent; they are converted to the 32-bit short float, which keeps about 7 significant digits.
- Energy counters are normally sent in IEC 104 as integrated totals (M_IT_NA_1, type 15), a 32-bit signed binary counter with a sequence number, read by counter interrogation. If the counter can exceed 231 in its unit, choose a coarser unit (kWh instead of Wh).
Should you scale before or after decoding?
After. First assemble the raw number in the correct order, then apply scale and offset (value = raw × scale + offset). For a float register that already holds engineering units the scale is 1 and the offset 0.
How is this configured in Max IEC Gateway?
Each mapping has a register type (UInt16, Int16, UInt32, Int32, Float32 or Float64), a register count and a byte order (ABCD, CDAB, BADC or DCBA), plus scale and offset. Map the result to M_ME_NC_1 or M_ME_TF_1 for floats. The Traffic page shows each decoded value, so a wrong byte order is obvious straight away.
Frequently asked questions
Which byte order is most common?
ABCD (big-endian) follows the Modbus convention for single registers and is common, but CDAB (word swapped) is also widespread, especially in energy meters and PLCs that store floats low word first. Always check with a known value.
Does IEC 104 need a byte-order setting?
No. IEC 60870-5 fixes the octet order on the wire, so the master decodes M_ME_NC_1 the same way for every outstation. Only the Modbus side needs the byte-order setting.
Try it with Max IEC Gateway. The gateway polls Modbus TCP and RTU devices and serves the values as an IEC 60870-5-104 server or IEC 60870-5-101 outstation, with a traffic monitor that shows every exchange.
Related guides
Modbus basics on the ModbusBB site: register addressing, function codes, Modbus timeouts.