// LEARN · MC Protocol Guide

Reading MC protocol error codes (end codes): C059, C056, 4031 and more

Where the end code sits in an MC protocol (SLMP) response, how to read it, and what the frequent error codes (C051, C056, C059, C05E, 4031 and others) mean and how to fix them, based on the Mitsubishi Electric manuals.

Updated

Every response from the PLC carries a 2-byte end code right after the response data length. Zero means normal completion. Anything else is an error, and that value is the error code.

The end code follows the response data length

As shown in the 3E frame article, a response is the subheader, the four destination fields, the response data length and then the end code. In binary the low byte comes first, so error C051 arrives as 51 C0. In ASCII it is the four characters C051.

On error, the end code is followed not by data but by:

  • Information about the station that returned the error (network No., PC No., destination module I/O No., destination module station No.)
  • The command and subcommand of the request that failed

For example, if a batch read (0401) asks for too many points and C051 comes back, the response looks like this (binary, own station):

Error response (binary) 20 bytes
D0 00 Subheader 3E response
Destination (echoed)
00 Network No. own station
FF PC No. own station
FF 03 I/O No. 03FF
00 Station No.
0B 00 Response data length = 11 bytes
51 C0 End code C051
Station that returned the error
00 Network No.
FF PC No.
FF 03 I/O No.
00 Station No.
Failed request
01 04 Command 0401
00 00 Subcommand

The station information can differ from the request’s destination — when you go through other stations, a station along the way may be the one that returned the error. If several errors occur at once, the first one detected is returned.

Frequent error codes

These are taken from the error code list in the MELSEC iQ-R Ethernet User’s Manual, picking the ones you tend to meet when building messages or using a library.

CodeMeaningFix
C050In ASCII mode, received characters that cannot be converted to binaryCheck the characters being sent
C051Word-unit read/write point count out of rangeFix the count (batch read: up to 960 words)
C052Bit-unit read/write point count out of rangeFix the count
C054Word / double-word random read/write point count out of rangeFix the count
C056Read/write request beyond the maximum addressFix the head address or the count
C058Request data length after ASCII→binary conversion does not match the dataCheck the request data length
C059Wrong command or subcommand, or a function the target does not supportCheck the command and whether the target supports it
C05CError in the request dataCheck the request data
C05ENo response from the target within the monitoring timerLengthen the timer; check the target and network settings
C061Request data length does not match the dataCheck the request data length
C0B2No free space in the receive/send bufferWait for each response before sending the next request
4031Device number out of range, or a device the CPU does not supportCheck the device number and the CPU’s device assignment

4031 is a CPU-side error listed in the MELSEC iQ-R CPU module manual. The C0xx descriptions above are for iQ-R Ethernet-equipped modules. On Q / L series Ethernet modules the codes and wording may differ, so check your module’s manual as well.

Narrowing it down

If the table doesn’t make the cause obvious, each kind of code points to a place to look.

On C059, suspect whether the target supports the command. A perfectly formed message still gets this error if the target doesn’t support it. Multiple block batch read (0406), for example, may not work on a CPU’s built-in Ethernet port. A wrong subcommand also triggers it, so make sure you aren’t sending the iQ-R subcommands 0002 / 0003 to a Q series PLC.

C051–C054 are about counts; C056 and 4031 are about addresses. Check that you are within the per-request limit and that the device number exists. If the PLC parameters reduce the number of device points, even an address within the default range returns 4031.

C05E means the PLC is slow, or the request never arrived. If a longer monitoring timer fixes it, it was processing time. If not, review the network No., station No. and routing settings.

Length errors (C058, C061) are message-building mistakes. Check that the request data length counts from the monitoring timer, and in ASCII that it counts characters.

Remote password errors

If the PLC has a remote password set, C2xx errors can come back.

CodeMeaningFix
C200Wrong remote passwordCheck the password and unlock / lock again
C201The port used is lockedUnlock before communicating
C204A different device requested the lock than the one that unlockedLock from the device that unlocked

On a password-protected port, send unlock (command 1630) before communicating and lock (1631) when finished.

Getting the error code in McpX

In McpX, an error code from the PLC raises McProtocolException. From v0.11 the ErrorCode property gives you the value, so you can handle codes individually.

try
{
    short[] d = mcpx.BatchRead<short>(Prefix.D, "0", 100);
}
catch (McProtocolException ex) when (ex.ErrorCode == 0x4031)
{
    // Device number out of range: check the PLC's device assignment
}
catch (McProtocolException ex) when (ex.ErrorCode == 0xC059)
{
    // The target does not support this command
}

Sources

  • MELSEC iQ-R Ethernet User's Manual (Application) (Japanese edition, SH-081253) pp.436–443, error code list
  • MELSEC iQ-R CPU Module User's Manual (Application) (Japanese edition, SH-081224) Appendix 1 p.841
  • MELSEC Communication Protocol Reference Manual (Japanese edition, SH-080003) pp.41, 44
  • SLMP Reference Manual (Japanese edition, SH-080931) p.28