Beginner Guide
August 14, 2026
6 min read

How to Scan a Network for Modbus Devices

You know there's a PLC, meter, or sensor on the network somewhere — but not its IP address or slave ID. Here's how a Modbus scanner finds it for you.

Why You'd Need to Scan

A Modbus TCP client needs three things to talk to a device: an IP address, a port (almost always 502), and a slave/unit ID. On a documented, well-labeled system you'd just read these off a network diagram. In practice, that diagram is missing, outdated, or was never written — commissioning engineers move on, integrators change, and devices get swapped without updating the paperwork.

Scanning solves this by testing a range of IP addresses (and often slave IDs) and reporting which ones respond to a Modbus request. It turns "I don't know what's out there" into a list of live devices in a couple of minutes.

Scanning Step by Step

1. Find your subnet range

Check the IP address and subnet mask of the network interface you're connecting through. A typical industrial subnet is something like 192.168.1.0/24, meaning addresses 192.168.1.1 through 192.168.1.254 are in play. If you're not sure, check your PC's network adapter settings — the scanner needs to be on the same subnet as the devices, or routed to it.

2. Set the port and scan speed

Leave the port at 502 unless you have a specific reason to believe a device uses a nonstandard one. Choose a conservative scan speed on a live production network — a fast scan hammering every address at once can add noticeable load to older PLCs and switches that were never designed to field a burst of simultaneous connection attempts. Quiet, sequential scanning is slower but safer when the network is already in service.

3. Run the scan and read the results

The scanner attempts a connection to each address in range. Addresses that respond to a Modbus request get flagged as live — some scanners will also try a handful of common slave IDs (1, 2, 247 are frequent defaults) against each responding IP to narrow things down further.

4. Confirm before you write anything

A scan tells you a device exists and answers Modbus requests — it doesn't tell you what that device is or what its registers mean. Read a few known registers (device ID, firmware version, a status word) to confirm you've found the device you expect before attempting any write commands.

Common Pitfalls

  • Scanning the wrong subnet. If your laptop has multiple network adapters (Wi-Fi plus a wired industrial NIC), make sure the scan is bound to the adapter actually connected to the Modbus network.
  • Scanning too aggressively on a live line. A full scan of a /24 subnet at maximum speed can look like a port scan to a firewall or intrusion detection system, and can genuinely slow down constrained embedded devices. Start conservative on production networks.
  • Assuming "no response" means "no device." A device can be alive but have Modbus TCP disabled, be listening on a nonstandard port, or sit behind a firewall rule that silently drops the scan traffic. See our connection troubleshooting guide if a device you expect to find doesn't show up.

Scan Your Network with Modbus Connect

Modbus Connect includes a built-in IP range scanner with quiet and fast modes, CIDR support, and scan time estimation — so you can find every device on the network without risking a production outage.

Download Free Beta →