Troubleshooting
August 14, 2026
8 min read

Modbus TCP Connection Failures: Timeouts, Refused Connections & Gateway Errors

Your Modbus TCP client won't connect. Here's how to tell which of the three common failure modes you're looking at, and what actually fixes each one.

Modbus TCP fails in three distinct ways at the connection level, and each one points to a different layer of the problem. Getting this right first saves you from swapping cables when the actual issue is a firewall rule, or rebooting a PLC when the actual issue is a typo in the IP address.

The rule of thumb: a timeout means nothing answered. A refused connection means something answered and said no. A gateway error means the connection worked, but the device behind it didn't.

Connection Times Out

A timeout means your client sent a TCP SYN packet to port 502 and never got a reply — not even a rejection. Nothing at that IP and port acknowledged the connection attempt.

Most likely causes, in order

  • Wrong IP address. The single most common cause. DHCP-assigned devices, dual-NIC PLCs, and VLAN misconfigurations all produce a plausible-looking but wrong IP. Ping the address first — if ping also fails, this is almost certainly it.
  • Firewall dropping the packet silently. Most firewalls (and Windows Defender Firewall by default) drop unsolicited inbound traffic rather than rejecting it, which produces a timeout, not a refusal. Check outbound rules on your machine and inbound rules on the device network.
  • Device is on a different subnet or VLAN and there's no routing between them. Common after a network re-segmentation project that didn't account for the OT VLAN.
  • Device is powered off, in fault state, or its network stack has hung. Some embedded Modbus stacks stop responding to new TCP connections after running for weeks without a reboot.

Fastest way to isolate it: run a network scan across the subnet instead of connecting to one IP at a time. If the device shows up at a different address than you expected, you've found the problem in seconds instead of after twenty minutes of retrying the same wrong IP. See our guide to scanning for Modbus devices.

Connection Refused on Port 502

A refusal is different from a timeout — the device is reachable and its network stack is alive, but nothing is listening on TCP port 502. You'll usually see an explicit ECONNREFUSED or “connection actively refused” message instead of a timer running out.

Most likely causes

  • Modbus TCP is disabled on the device. Many PLCs and gateways ship with the Modbus TCP server switched off by default and require it to be enabled in the device's own configuration tool or web interface.
  • Wrong port. 502 is the registered default, but some vendors let it be changed, and some gateways deliberately move it off 502 for security-by-obscurity. Check the device manual.
  • Connection limit reached. Many embedded Modbus TCP servers only accept a small, fixed number of simultaneous connections (often just one to four). If another client — including a stale connection nobody closed cleanly — is still holding a socket open, new connection attempts get refused until it times out or is released.
  • Device just rebooted. Its TCP stack can come up before its Modbus server task finishes initializing, producing a brief window of refused connections right after power-on.

Gateway Errors: 0x0A and 0x0B

These show up differently — the TCP connection succeeds, and you get a valid Modbus response, but it's an exception. This means the problem has moved past the network layer entirely: you're now inside a Modbus TCP-to-serial gateway that can't reach the device on its serial side.

0x0A — Gateway Path Unavailable

The gateway itself is fine, but it has no configured route or mapping to the slave ID you requested. Check the gateway's routing table and confirm the slave ID in your request matches what the gateway expects on its serial bus.

0x0B — Gateway Target Device Failed to Respond

The gateway found the right route and forwarded your request onto the RS-485 bus, but nothing answered. This is now a serial-side problem: check wiring, termination resistors, A/B polarity, and that baud rate/parity/stop bits match on both the gateway and the end device.

For a full breakdown of every standard exception code, see our Modbus exception codes guide.

Quick Diagnosis Table

SymptomWhat It MeansCheck First
Times out, no responseNothing answered at that IP:portIP address, ping, firewall, VLAN
Connection refusedDevice reachable, nothing listening on 502Modbus TCP enabled?, port number, connection limit
Exception 0x0AGateway has no route to that slave IDGateway routing table, slave ID
Exception 0x0BGateway can't reach device on serial busRS-485 wiring, termination, baud/parity settings

Diagnose Connection Issues Faster

Modbus Connect shows you the exact failure — timeout, refusal, or exception code — the moment it happens, with connection logging so you're not guessing which layer broke.

Download Free Beta →
Modbus TCP Connection Failures: Timeouts, Refused Connections & Gateway Errors | Modbus Connect Blog