Reading MC protocol error codes (end codes): C059, C056, 4031 and more
Where the end code sits in an MC protocol (SLMP) response, how to read it, and what the frequent error codes (C051, C056, C059, C05E, 4031 and others) mean and how to fix them, based on the Mitsubishi Electric manuals.
Updated
Every response from the PLC carries a 2-byte end code right after the response data length. Zero means normal completion. Anything else is an error, and that value is the error code.
The end code follows the response data length
As shown in the 3E frame article, a response is the subheader, the four destination fields, the response data length and then the end code. In binary the low byte comes first, so error C051 arrives as 51 C0. In ASCII it is the four characters C051.
On error, the end code is followed not by data but by:
- Information about the station that returned the error (network No., PC No., destination module I/O No., destination module station No.)
- The command and subcommand of the request that failed
For example, if a batch read (0401) asks for too many points and C051 comes back, the response looks like this (binary, own station):
D0 00 Subheader 3E response00 Network No. own stationFF PC No. own stationFF 03 I/O No. 03FF00 Station No. 0B 00 Response data length = 11 bytes51 C0 End code C05100 Network No. FF PC No. FF 03 I/O No. 00 Station No. 01 04 Command 040100 00 Subcommand The station information can differ from the request’s destination — when you go through other stations, a station along the way may be the one that returned the error. If several errors occur at once, the first one detected is returned.
Frequent error codes
These are taken from the error code list in the MELSEC iQ-R Ethernet User’s Manual, picking the ones you tend to meet when building messages or using a library.
| Code | Meaning | Fix |
|---|---|---|
C050 | In ASCII mode, received characters that cannot be converted to binary | Check the characters being sent |
C051 | Word-unit read/write point count out of range | Fix the count (batch read: up to 960 words) |
C052 | Bit-unit read/write point count out of range | Fix the count |
C054 | Word / double-word random read/write point count out of range | Fix the count |
C056 | Read/write request beyond the maximum address | Fix the head address or the count |
C058 | Request data length after ASCII→binary conversion does not match the data | Check the request data length |
C059 | Wrong command or subcommand, or a function the target does not support | Check the command and whether the target supports it |
C05C | Error in the request data | Check the request data |
C05E | No response from the target within the monitoring timer | Lengthen the timer; check the target and network settings |
C061 | Request data length does not match the data | Check the request data length |
C0B2 | No free space in the receive/send buffer | Wait for each response before sending the next request |
4031 | Device number out of range, or a device the CPU does not support | Check the device number and the CPU’s device assignment |
4031 is a CPU-side error listed in the MELSEC iQ-R CPU module manual. The C0xx descriptions above are for iQ-R Ethernet-equipped modules. On Q / L series Ethernet modules the codes and wording may differ, so check your module’s manual as well.
Narrowing it down
If the table doesn’t make the cause obvious, each kind of code points to a place to look.
On C059, suspect whether the target supports the command. A perfectly formed message still gets this error if the target doesn’t support it. Multiple block batch read (0406), for example, may not work on a CPU’s built-in Ethernet port. A wrong subcommand also triggers it, so make sure you aren’t sending the iQ-R subcommands 0002 / 0003 to a Q series PLC.
C051–C054 are about counts; C056 and 4031 are about addresses. Check that you are within the per-request limit and that the device number exists. If the PLC parameters reduce the number of device points, even an address within the default range returns 4031.
C05E means the PLC is slow, or the request never arrived. If a longer monitoring timer fixes it, it was processing time. If not, review the network No., station No. and routing settings.
Length errors (C058, C061) are message-building mistakes. Check that the request data length counts from the monitoring timer, and in ASCII that it counts characters.
Remote password errors
If the PLC has a remote password set, C2xx errors can come back.
| Code | Meaning | Fix |
|---|---|---|
C200 | Wrong remote password | Check the password and unlock / lock again |
C201 | The port used is locked | Unlock before communicating |
C204 | A different device requested the lock than the one that unlocked | Lock from the device that unlocked |
On a password-protected port, send unlock (command 1630) before communicating and lock (1631) when finished.
Getting the error code in McpX
In McpX, an error code from the PLC raises McProtocolException. From v0.11 the ErrorCode property gives you the value, so you can handle codes individually.
try
{
short[] d = mcpx.BatchRead<short>(Prefix.D, "0", 100);
}
catch (McProtocolException ex) when (ex.ErrorCode == 0x4031)
{
// Device number out of range: check the PLC's device assignment
}
catch (McProtocolException ex) when (ex.ErrorCode == 0xC059)
{
// The target does not support this command
}Sources
- MELSEC iQ-R Ethernet User's Manual (Application) (Japanese edition, SH-081253) pp.436–443, error code list
- MELSEC iQ-R CPU Module User's Manual (Application) (Japanese edition, SH-081224) Appendix 1 p.841
- MELSEC Communication Protocol Reference Manual (Japanese edition, SH-080003) pp.41, 44
- SLMP Reference Manual (Japanese edition, SH-080931) p.28