Explore The Industrial Wireless RS485 Modbus Transmitter Capabilities
Device Overview
The NCD Industrial Wireless RS485 Modbus Transmitter (PR55-88F) transforms Modbus devices into seamless wireless nodes, enabling effortless integration into the NCD wireless network and eliminating the need for cumbersome wired connections. .
Instead of relying on a central gateway to constantly request data, the Industrial Wireless RS485 Modbus Transmitter operates as the “Master” of its own RS485 loop. It bridges the gap between legacy hardware and modern wireless networks by operating autonomously on a user-defined schedule.
Features:
- Industrial Grade IoT Modbus RS485 To Wireless Converter
- Works With VFD, PLC, SCADA systems
- Works With HVAC Control Systems
- Ideal For MODBUS-RTU Communication Over Wireless
- Convert any RS485 Sensor/Device into a Wireless Sensor/Device
- API communication over Wireless for Robust Reliability
- Operating Temperature Range -40 to +85 °C
- 5V-24VDC Input Voltage Range
Frame Structure
Frame Communication at Power Up
When the device powers up, depending on the mode it is going to work in, it will have a different Power Up Frame
Figure 3 provides an outline of the frame structure at Power Up, where the bytes highlighted in Red denote which mode the device has started in (Run, Configuration or Factory Default). You can look up the corresponding codes in Table 2.
If we further examine the Payload, we can use the Node ID and Sensor Type fields to determine the exact sensor that is sending the data.
A shown in the second column in Table 2, the sensor configures its PAN ID automatically depending upon the mode it is working in. During factory reset it sets the PAN ID to the value given in table therefore the factory reset frame will only be received if your Modem/Gateway PAN ID matches this ID. All 3 types of frames are shown in Figure 3, Figure 4 and Figure 5.
| Mode Type | PAN ID set by Sensor (ASCII) | Frame field | Offset (Payload section) | Value |
|---|---|---|---|---|
| Run | ID save by user / Default | Mode bytes | 7 | 0x52 |
| 8 | 0x55 | |||
| 9 | 0x4E | |||
| Configuration | 7BCD | Mode bytes | 7 | 0x50 |
| 8 | 0x47 | |||
| 9 | 0x4D | |||
| Factory Reset | 7FFF | Mode bytes | 7 | 0x50 |
| 8 | 0x55 | |||
| 9 | 0x4D |
Run Mode Frame
| Field | Number of bytes | Description |
|---|---|---|
| 7E 00 1C 90 00 13 A2 00 42 35 89 86 FF FE C2 7A 01 00 02 1B 00 00 52 55 4E 00 00 00 00 00 00 79 | Example frame | |
| 0x7E | 1 | Delimiter |
| 0x001C | 2 | Length |
| 0x90 | 1 | Frame Type (Power Up) |
| 0x0013A20042536453 | 8 | Source Address |
| 0xFFFE | 2 | Reserved |
| 0xC2 | 1 | R. Option |
| 0x7A | 1 | Header with Power Up value |
| 0x00 | 1 | Node ID |
| 0x00 | 1 | Separator |
| 0x021B | 2 | Sensor Type |
| 0x0000 | 2 | Separator |
| 0x52554E | 3 | Mode Byte for Run Mode |
| 0x000000000000 | 6 | Reserved |
| 0x79 | 1 | Checksum |
Configuration Mode Frame
| Field | Number of bytes | Description |
|---|---|---|
| 7E 00 44 90 00 13 A2 00 42 35 89 86 FF FE C2 4F 00 00 19 07 02 1B 00 00 01 AF 55 88 00 7F FF 00 00 FF FF 00 00 00 03 84 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 07 D0 00 00 03 00 01 5F | Example frame | |
| 0x7E | 1 | Delimiter |
| 0x0044 | 2 | Length |
| 0x90 | 1 | Frame Type |
| 0x0013A20042536453 | 8 | Source Address |
| 0xFFFE | 2 | Reserved |
| 0xC2 | 1 | R. Option |
| 4F | 1 | Header |
| 0000 | 2 | Reserved |
| 17 | 1 | Core Engine Version |
| 0B | 1 | Firmware Version |
| 007F | 2 | Sensor Type |
| 00000001 | 4 | Tx Life Counter |
| 633D00 | 3 | Hardware ID |
| 7FFF | 2 | Network ID |
| 0000FFFF | 4 | Destination Address |
| 00 | 1 | Node ID |
| 0000000A | 4 | Report Rate |
| 01 | 1 | Register to Read |
| 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000 | 32 | Modbus Registers Address |
| 00 | 1 | Baud Rate |
| 00 | 1 | Bootup Time |
| 01 | 1 | Slave Address ID |
| 00 01 | 2 | RS485 Rx Timeout |
| 01 | 1 | Sub Device Type |
| 01 | 1 | Number of Read Retries |
| 01 | 1 | Modbus Function Code |
| 00 | 1 | Parity Bit |
| 00 | 1 | Stop Bit |
| 5F | 1 | Checksum |
Factory Reset Mode Frame
| Field | Number of bytes | Description |
|---|---|---|
| 7E 00 1C 90 00 13 A2 00 42 53 64 53 FF FE C2 7A 00 00 02 1B 00 00 50 55 4D 00 00 00 00 00 00 D1 | Example frame | |
| 0x7E | 1 | Delimiter |
| 0x001C | 2 | Length |
| 0x90 | 1 | Frame Type |
| 0x0013A20042536453 | 8 | Source Address |
| 0xFFFE | 2 | Reserved |
| 0xC2 | 1 | R. Option |
| 0x7A | 1 | Header |
| 0x00 | 1 | Node ID |
| 0x00 | 1 | Separator |
| 0x021B | 2 | Sensor Type |
| 0x0000 | 2 | Separator |
| 0x50554D | 3 | Mode Byte for Factory Reset Mode |
| 0x000000000000 | 6 | Reserved |
| 0xD1 | 1 | Checksum |
Sync Check In Frame
| Field | Number of bytes | Description |
|---|---|---|
| 7E 00 44 90 00 13 A2 00 42 35 89 86 FF FE C2 6F 00 00 19 07 02 1B 00 00 01 AF 55 88 00 7F FF 00 00 FF FF 00 00 00 03 84 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 07 D0 00 00 03 00 01 | Example frame | |
| 0x7E | 1 | Delimiter |
| 0x001C | 2 | Length |
| 0x90 | 1 | Frame Type |
| 0x0013A20042536453 | 8 | Source Address |
| 0xFFFE | 2 | Reserved |
| 0x00 | 1 | R. Option |
| 6F | 1 | Header |
| 0000 | 2 | Reserved |
| 17 | 1 | Core Engine Version |
| 0B | 1 | Firmware Version |
| 0018 | 2 | Sensor Type |
| 00000001 | 4 | Tx Life Counter |
| 633D00 | 3 | Hardware ID |
| 7FFF | 2 | Network ID |
| 0000FFFF | 4 | Destination Address |
| 00 | 1 | Node ID |
| 0000000A | 4 | Report Rate |
| 01 | 1 | Register to Read |
| 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000 | 32 | Modbus Registers Address |
| 00 | 1 | Baud Rate |
| 00 | 1 | Bootup Time |
| 01 | 1 | Slave Address ID |
| 00 01 | 2 | RS485 Rx Timeout |
| 01 | 1 | Sub Device Type |
| 01 | 1 | Number of Read Retries |
| 01 | 1 | Modbus Function Code |
| 00 | 1 | Parity Bit |
| 00 | 1 | Stop Bit |
| 5F | 1 | Checksum |
Sync Acknowledgment Frame
| Field | Number of bytes | Description |
|---|---|---|
| 7E 00 44 90 00 13 A2 00 42 35 89 86 FF FE C2 5F 00 00 19 07 02 1B 00 00 01 AF 55 88 00 7F FF 00 00 FF FF 00 00 00 03 84 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 07 D0 00 00 03 00 01 D6 | Example frame | |
| 0x7E | 1 | Delimiter |
| 0x001C | 2 | Length |
| 0x90 | 1 | Frame Type |
| 0x0013A20042536453 | 8 | Source Address |
| 0xFFFE | 2 | Reserved |
| 0x00 | 1 | R. Option |
| 5F | 1 | Header |
| 0000 | 2 | Reserved |
| 17 | 1 | Core Engine Version |
| 0B | 1 | Firmware Version |
| 02 1B | 2 | Sensor Type |
| 00000001 | 4 | Tx Life Counter |
| 633D00 | 3 | Hardware ID |
| 7FFF | 2 | Network ID |
| 0000FFFF | 4 | Destination Address |
| 00 | 1 | Node ID |
| 0000000A | 4 | Report Rate |
| 01 | 1 | Register to Read |
| 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000 | 32 | Modbus Registers Address |
| 00 | 1 | Baud Rate |
| 00 | 1 | Bootup Time |
| 01 | 1 | Slave Address ID |
| 00 01 | 2 | RS485 Rx Timeout |
| 01 | 1 | Sub Device Type |
| 01 | 1 | Number of Read Retries |
| 01 | 1 | Modbus Function Code |
| 00 | 1 | Parity Bit |
| 00 | 1 | Stop Bit |
| 5F | 1 | Checksum |
Assertion Reason Frame
| Field | Number of bytes | Description |
|---|---|---|
| 77 00 00 00 6E 00 00 00 08 C3 61 70 70 5F 73 74 61 72 74 5F 66 6C 79 5F 74 69 6D 65 72 00 00 00 00 00 00 00 00 00 | Example frame | |
| 0x77 | 1 | Delimiter |
| 0x00 | 2 | Node ID |
| 0x0000 | 2 | Reserved |
| 0x007F | 2 | Sensor Type |
| 0x000008C3 | 4 | Line Number |
| 0x00 | Function Name |
Run mode is the default mode of operation of this sensor. In this mode, the sensor sends periodic packets with the sensor measurement data. During the time it is not sending it enters deep-sleep to conserve power. The sensor’s X-bee Radio module operates in API mode and sends packets to the saved destination address on the network specified by the saved PAN ID. Figure 4 illustrates the API transmission/reception procedure.
Sensor Data Frame
| Frame Field | Offset (Payload section) | Fixed Value (if any) | Length | Description |
|---|---|---|---|---|
| Header | 0 | 0x7F | 1 | Header to differentiate various types of packets |
| Node ID | 1 | 0x00 | 1 | Node ID to differentiate up to 256 nodes in a network. User configurable values |
| Firmware | 2 | 0x01 | 1 | Used to determine firmware version programmed in the device |
| Battery Voltage | MSB 3 | 0x03 | 2 | Battery Voltage = 0.00322*(03*FF+FE) |
| LSB 4 | 0xFE | Battery Voltage = ((Battery Voltage MSB x 256) + Battery Voltage LSB) x 0.00322 V | ||
| Packet Counter | 5 | - | 1 | It is an 8-bit counter that increments with each packet transmission. It can be used to detect missing packets |
| Sensor Type | MSB 6 | 0x02 | 2 | Two bytes to determine sensor type. It can be used in conjunction with Node ID to create sensor networks of up to 256 nodes for a single type of sensor and multiple such networks can coexist and can be differentiated in processing software on PC end. |
| LSB 7 | 0x1B | Sensor Type 539 | ||
| Error/Reserved byte | 8 | 0x00 | 1 | Bit 7: Reserved Bit 6: Reserved Bit 5: Reserved Bit 4: Reserved Bit 3: Reserved Bit 2: Reserved Bit 1: Reserved Bit 0: Reserved |
| Sub Device Type | 9/ Data[0] | - | 1 | |
| Number of Registers | 10/ Data[0] | - | 1 | |
| Register Status | 11/ Data[0] | - | ||
| 12/ Data[1] | - | |||
| 13/ Data[2] | - | |||
| 14/ Data[3] | - | 4 | Each bit describes status of a register (0 --> fail, 1-->success) | |
| Register Data | 15/ Data[0] | - | ||
| n/Data[n] | up to 64 Bytes | 2 bytes each register --> Total length 64 bytes |
Configuration Mode
To put an NCD.io wireless sensor into manual configuration mode, you can do the following:
Using Buttons
1. Press and release the RESET button
2. Immediately press and hold the CONFIGURATION button
3. Hold the CONFIGURATION button for about 5–8 seconds
4. Release the CONFIGURATION button
In configuration mode, the device sets its X-bee pan id to 7BCD. Also, the destination address used by the sensor is extracted from the incoming packet (source address). This ensures that once you put a device in configuration mode you just need to change the PAN ID you are sending to in your Modem/Gateway to match with the sensor and start configuring your device.
A standard configuration packet and its fields are explained in Figure 5. Its possible responses are also shown. The complete set of commands supported by this sensor are shown in тхе Appendix, these can be used in the Parameters field of the Payload section. The sensor responds to these commands with an acknowledgement if the process completed successfully or with an error if it failed to setup a parameter. The respective Data and Reserve section length and values are shown in Table 6 for the case of acknowledgement. In the case of error, the reserved section will be fixed and not used, while the Error number byte will determine the type of error returned. These errors are in a separate section in the Appendix.
Sync/Config Mode
This specific device also supports SYNC mode, which allows you to configure the sensor without needing physical access to it (no need to press buttons or trigger a magnetic switch).
By default, the device automatically enters SYNC mode every hour and transmits a SYNC packet (described below). This packet serves two main purposes:
Current Settings: It includes all the active settings, allowing you to easily verify or read the sensor’s current configuration.
Configuration Window: It signals that the sensor is temporarily in configuration mode. During this brief time window, you can transmit a Master Command to update the settings.
Once the time window closes, the device automatically returns to its normal operation (Run mode).
Example Configuration Command
The following is an example on how to read and change some of the parameters that affect the operation of the NCD Sensor.
Master Command
The Master Command is a comprehensive command that allows you to configure all of the device’s settings in a single transmission.
Below, you will find the structure of the master command, along with a detailed payload description for each byte.
7E 00 38 10 01 00 00 00 00 00 00 FF FF FF FE 00 00 6C 00 00 7F FF 00 00 FF FF 00 00 00 00 3C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 01 07 D0 00 00 03 00 01 C9
Complete Payload
6C 00 00 7F FF 00 00 FF FF 00 00 00 00 3C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 04 00 01 07 D0 00 00 03 00 01
Master Command Payload Description
| Byte | Size (bytes) | Setting | Valid Options | Description |
|---|---|---|---|---|
| 6C | 1 | Header | ||
| 00 00 | 2 | Reserved | ||
| 7F FF | 2 | Network ID | 0x00 -- 0x7FFF | Network ID Valid Range: 0-0x7FFF. |
| 00 00 FF FF | 4 | Destination Address | Default value: 0000FFFF for Broadcast Mode Example of targeted address: 41D5EC37 | Sets the Destination Address of the sensor. The sensor will send Run mode Data packets to this Address |
| 00 | 1 | Node ID | 0x00 -- 0xFF | Sets the Device node ID and Data Transmission Interval. The node id value can go from 0-255 and The Data transmission value can go from 3-0xFFFFFF Seconds |
| 00 00 00 3C | 1 | Report Rate | Valid Range: 0x01 -- 0xFFFFFFFF | Sets the Data Transmission Interval |
| 00 | 1 | Register to Read | Valid Range: 0x01 -- 0x20 | Set the total number of registers to read on interval in the Register Reads field. Set the individual Registers to read below in the correspond Register field. |
| 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000000000000000 00000000 | 64 | Modbus Registers | the Modbus Register Address (0-based offset). | |
| 04 | 1 | Baud Rate | 0x00 -- 4800 0x01 -- 9600 0x02 -- 19200 0x03 -- 38400 0x04 -- 115200 | |
| 00 | 1 | Bootup Time | Valid Range: 0x01 -- 0xFF | Sets the delay interval (in seconds) that the NCD transmitter waits after powering on the connected Modbus device before issuing the first command. This delay ensures the external Modbus device has sufficient time to complete its internal initialization sequence before the transmitter begins polling. |
| 01 | 1 | Slave address | Valid Range: 0x01 -- 0xFF | |
| 07D0 | 2 | Response Timeout (in milliseconds) | Valid Range: 0x01 -- 0xFFFF | Sets the maximum time (in milliseconds) that the device will wait to receive a response from the RS485 field device via the serial port after it sends command. |
| 00 | 1 | Slave ID | Valid Range: 0x01 -- 0xFF | Configures the unique Slave Modbus device address (Slave ID) for the transmitter. |
| 00 | 1 | Number of Read Retries | Valid Range: 0x01 -- 0x03 | Sets the maximum number of attempts the device will make to perform a Modbus RTU register query. |
| 03 | 1 | Modbus Function Code. | 0x03 -- Read Holding Register (0x03) 0x04 -- Read Input Register (0x03) | |
| 00 | 1 | Set Parity | 0x00 -- None 0x01 -- Even 0x02 -- Odd | |
| 01 | 1 | Set Stop Bit | 0x00 -- Half 0x01 -- 1 bit 0x02 -- 1.5 bit 0x03 -- 2 bit |
Read Sensor Settings
Sync
By using the SYNC packet, you can easily check the current settings configured on your sensor. The SYNC message includes the exact bytes that correspond to your active configuration values (you can find an example of a SYNC packet at the beginning of this document).
If you ever need to manually trigger a SYNC message, simply press the reset button. When you do this, the sensor will respond by sending a quick sequence of three messages: RUN, followed by sensor_data, and finally SYNC.
Additionally, the sensor will automatically transmit a SYNC message every hour by default to keep everything updated.
Read Wireless Sensor Transmission Power Level
This Command may be used to read the wireless radio transmission power. This value will indicate how much RF power the radio is emitting. The higher the value, the higher the radiated wireless power, resulting in a longer range and decreased battery life (please note that all battery ratings are shown at maximum wireless transmission power). Lower values are desirable in application that may benefit from greatly improve battery life, especially when high power data transmissions are not required.
Read Sensor Power Command:
7E 00 13 10 00 00 00 00 00 00 00 FF FF FF FE 00 00 F7 16 00 00 00 E7
Sensor will respond with the Power Level value:
7E 00 1C 90 00 13 A2 00 41 91 1B 83 FF FE C1 7C 00 09 00 0E 00 00 04 00 00 00 00 00 00 00 00 F5
From the above command, the following data may be extracted:
A. Sensor MAC Address
00 13 A2 00 41 91 1B 83
B. Sensor Payload
7C 00 09 00 0E 00 00 04 00 00 00 00 00 00 00 00
C. Power Level
0x04 (data byte 23)
The sensor will respond with a value from 0x00 to 0x04. The default value is 0x04, allowing for the greatest possible transmission range and the shortest battery life.
Read Wireless Sensor Retries
The following command may be used to read the number of retires. The number of retries is one of the most useful settings for NCD wireless sensors.
Lets say the number of retires is set to 5. In a normal case, the sensor will wake up, gather data, send data to the modem, and go back to sleep. But due to some environmental issues (lets say a few trucks were driving by and they came in between the sensor and the modem) the modem didn’t receive the data. In that case, the sensor will try 4 more times to send the data. If the modem still doesn’t get the data after all 5 tries, the sensor will quite trying and will go back to sleep. The Machine Uptime sensor will wake up after the predefined sleep time and will try again.
The highest number of retries allowed is 10.
Read The number of Sensor Retries:
7E 00 13 10 00 00 00 00 00 00 00 FF FF FF FE 00 00 F7 17 00 00 00 E6
Sensor will respond with the Retries value:
7E 00 1C 90 00 13 A2 00 41 91 1B 83 FF FE C1 7C 00 1B 00 0E 00 00 0A 00 00 00 00 00 00 00 00 DD
From the above command, the following data may be extracted:
A. Sensor MAC Address
00 13 A2 00 41 91 1B 83
B. Complete Sensor Payload
7C 00 1B 00 0E 00 00 0A 00 00 00 00 00 00 00 00
C. Retries Number
0x0A (data byte 23)
Error Code Descriptions
Here a summary is provided of what the different error codes mean (in case a valid Ack has not been received).
| Error Number | Description |
|---|---|
| 0x01 | Invalid command |
| 0x02 | Sensor Type mismatch |
| 0x03 | Node ID mismatch |
| 0x04 | Apply change command failed during X-bee parameter update |
| 0x05 | Invalid API packet command response received after Apply change command |
| 0x06 | Write command failed during X-bee parameter update |
| 0x07 | Invalid API packet command response received after Write command |
| 0x08 | Parameter change command failed during X-bee parameter update |
| 0x09 | Invalid Parameter change command response packet received after Write command |
| 0x0A | Invalid/Incomplete packet received |
| 0x0F | Invalid parameter for setup/saving |
Frame Checksum Calculation
In order to successfully communicate over the API protocol, the checksum is of vital importance. The X-bee at either end of the link will reject packets if the checksum does not match.
Calculation for transmission
For sending packets, the checksum calculation works as follows:
1. Not including the frame delimiter and length, add all the bytes and keep the lower 8 bits of result
2. Subtract this value from 0xFF (hex)
3. The resultant value is the checksum
4. Append this byte to the original packet for sending
Consider the example for the command Set Broadcast shown in APPENDIX A and see that the calculated checksum matches with the checksum sent by the terminal/LabVIEW. Let us break the example command below:
7E00 1310 0000 0000 0000 00FF FFFF FE00 00F7 0100 0001 FB
If we extract the relevant bytes from the command we get:
10 0000 0000 0000 00FF FFFF FE00 00F7 0100 0001
Adding the bytes and taking the last 8 bits yields:
0x04
Substract the value obtained (0x04) from 0xFF
0xFF-0x04=0xFB
We get a value matching the one in the packet checksum field.
Calculation for reception
Although checksum is matched by the X-bee itself, but for understanding follow these steps to match checksum at reception
1. Not including the frame delimiter and length, add all the bytes including the received checksum
2. Keep only the last 8 bits
3. If the result is 0xFF, the checksum is correct and the packet can be processed.
Consider the example for the command Set Broadcast shown in APPENDIX A and see that the received packet checksum verifies since the result is 0xFF.
7E00 1C90 1310 A200 4158 1CCB FFFE C17C 000D 0001 0000 FF00 0000 0000 0000 00F3
If we extract the relevant bytes from the command we get:
90 1310 A200 4158 1CCB FFFE C17C 000D 0001 0000 FF00 0000 0000 0000 00F3
Adding the bytes and taking the last 8 bits yields:
0xFF