PLC Communication Protocols for SCADA: What to Pick

Modbus function code 03 reads at most 125 registers in one request, so a 400-register power meter map is four round trips every time the SCADA asks for it. An EtherNet/IP I/O connection at a 10 ms RPI sends its packet whether anything changed or not, and an OPC UA subscription sends nothing at all until a value leaves its deadband. Polled, cyclic, report by exception: that is the whole taxonomy, and it decides what the link costs the controller far more than any argument about which protocol is best. A line has three separate links and they do not need the same answer, so this is the comparison I use when a new one gets specified, with the ports, the poll behaviour and the traps.

Reference hardware: a 5069-L320ER CompactLogix, an S7-1500 with TIA Portal V18, a Kepware KEPServerEX 6 gateway and an Ignition SCADA node.

Three ways data gets from a PLC to a screen

Everything on the list below is one of these three, and that is what decides the load.

Polled. The client asks, the server answers, nothing moves in between. Modbus TCP and Modbus RTU work this way, so do most SCADA drivers reading Logix tags. Load scales with the number of requests, not the amount of data that changed.

Cyclic. Both ends agree on a period and produce data at that period without asking. EtherNet/IP implicit I/O and PROFINET RT work this way. Load is fixed and predictable, which is why it runs machines.

Report by exception. The server sends only when a value changes past a deadband. OPC UA subscriptions and MQTT with Sparkplug B work this way. Quiet on a stable process, and a burst on an upset.

Timing chart comparing polled Modbus TCP requests and responses at 25 ms against cyclic EtherNet/IP I/O packets at a 10 ms RPI

The chart shows the difference in one picture. The Modbus link is idle between transactions and every value costs a round trip. The EtherNet/IP link has a steady packet every RPI whether anything changed or not.

The protocols worth knowing, with their real parameters

ProtocolTransport and portHow it moves dataWhere it fits
Modbus TCPTCP 502Polled, function codes 01, 02, 03, 04, 06, 16Power meters, weighers, small drives, anything with a register map
Modbus RTURS-485, 9600 to 115200 bpsPolled, one master per segmentOld field devices, long multidrop runs
EtherNet/IPTCP 44818 explicit, UDP 2222 implicitCyclic for I/O, polled for MSGAllen-Bradley controllers, remote racks, PowerFlex drives
PROFINET RTLayer 2 EtherType 0x8892, no IPCyclic, 1 ms and upSiemens I/O, ET 200SP racks, SINAMICS drives
PROFIBUS DPRS-485, 9.6 kbps to 12 MbpsCyclic token passingInstalled base, still everywhere in process plants
OPC UATCP 4840 by defaultSubscriptions with deadband, plus reads and writesPLC to SCADA, PLC to MES, across a firewall
MQTT with Sparkplug BTCP 1883, TLS 8883Publish on change to a brokerRemote sites, cellular links, many small sources
DNP3TCP or UDP 20000Polled plus unsolicited, with timestampsWater, wastewater, power distribution
IEC 60870-5-104TCP 2404Polled plus spontaneousUtility telecontrol in Europe
S7 communicationTCP 102PolledWinCC and third-party drivers into S7 controllers
Advertisement

Two details from that table cause most of the support calls. Modbus function code 03 reads a maximum of 125 registers in one request, so a 400-register map is four round trips minimum. PROFINET RT frames carry no IP header at all, which is why a PROFINET device is identified by a device name rather than an address, and why an IP-based router will not pass it.

A line has three separate links and they do not need the same protocol.

  1. Controller to field device. Cyclic wins. EtherNet/IP on Rockwell, PROFINET on Siemens. Set the update rate from the process, not from ambition. Discrete I/O at 20 ms, analog at 50 to 100 ms.
  2. Controller to controller. Produced and consumed tags on EtherNet/IP, or an S7 connection between S7-1500s. Keep the payload as one structure, not forty separate reads.
  3. Controller to SCADA. OPC UA, or a native driver if the SCADA has a good one. This link carries the most tags and the least urgency, so one second is usually fine and half a second is plenty.

The mistake I see is one protocol pushed through all three links, normally Modbus TCP, because the integrator knew it. That gives you a SCADA polling registers that a cyclic link had already delivered.

Group the tags first. A SCADA that reads 600 individual BOOL tags from a Logix controller issues hundreds of CIP requests per second. The same 600 bits inside one UDT array come back in a handful of requests.

# Logix side: one structure the SCADA reads as a block
Line3_SCADA          UDT Line3_Status
  .MachineState      DINT
  .Alarms[0..3]      DINT          // 128 alarm bits in 4 words
  .SpeedPV           REAL
  .SpeedSP           REAL
  .CountGood         DINT
  .CountReject       DINT

# KEPServerEX 6: Allen-Bradley ControlLogix Ethernet channel
Channel   : AB_Line3      Driver: Allen-Bradley ControlLogix Ethernet
Device    : 192.168.1.20  Slot 0   Protocol: Logical Non-Blocking
Scan mode : Respect client-specified scan rate
Tag       : Line3_SCADA   Array of UDT, scan 1000 ms

# Wireshark filters for proving it on the wire
mbtcp                      # Modbus TCP, watch the transaction IDs
enip or cip                # EtherNet/IP explicit and implicit
pn_rt                      # PROFINET real time frames
opcua                      # OPC UA binary on 4840
tcp.port == 102            # S7 communication into a Siemens CPU

Run the capture at the switch mirror port for ten minutes with the line running. Count requests per second. If that number is above a few hundred for one controller, the tag layout is the problem, not the protocol.

Field notes: what actually goes wrong

The 32-bit float that read 3.4 million. A weigher on Modbus TCP fed a batch controller. Weight came back as a huge number that changed sensibly when material went on the scale. Modbus has no word order in the specification, so the vendor sent the low word first and the client assumed high word first. Swapping word order in the driver fixed it in one click. Any time a Modbus float looks like nonsense but tracks the process, check word order before you blame the device.

SCADA polling that starved the controller. A CompactLogix on a bottling line started reporting scan times creeping from 12 ms to over 40 ms, with no program change. The new SCADA had 2,100 individually browsed tags at 250 ms. The controller was spending its time servicing CIP requests. Moving the tags into three UDT structures and slowing the scan class to one second put the scan time back where it started. The channel setup that made this manageable is described in Kepware channel configuration.

Advertisement

PROFINET device name after a swap. An ET 200SP interface module was replaced. The rack stayed dark, the BF LED flashed, and the CPU logged the station as missing. A PROFINET device is addressed by name, and a new module out of the box has none. Fix is Online and Diagnostics in TIA Portal, Functions → Assign PROFINET device name, or configure the topology first so the CPU names the replacement automatically. Details on the Siemens toolchain are in Siemens TIA Portal.

RS-485 segment with no termination. A PROFIBUS DP drop with six drives worked cold and threw bus faults once the line warmed up. Two connectors had their termination switches on in the middle of the segment and the last connector had it off. Termination belongs at the two physical ends and nowhere else. The symptom list in Profibus faults and network problems matches this one exactly.

Frequently asked questions

Is Modbus TCP fast enough for SCADA?
For a few hundred registers at one second, yes. It falls apart when somebody uses it for thousands of tags, because every read is a round trip and the round trips add up.

Do I need OPC UA if my SCADA has a native driver?
Not necessarily. A native driver is usually faster because it speaks the controller protocol directly. OPC UA earns its place when several systems need the same data, or when the link crosses a firewall between control and IT.

Why does my PROFINET traffic not show up in a router?
PROFINET RT frames sit at Layer 2 with EtherType 0x8892 and have no IP header, so nothing routes them. They stay inside the broadcast domain by design.

What is a safe poll rate for a SCADA?
One second for process values, 250 to 500 ms for anything an operator drives by hand. Faster than that and you are recording noise while loading the controller.

Can I run control traffic and SCADA traffic on the same switch?
On separate VLANs, yes. Flat networks are where multicast floods and backup jobs turn into I/O faults.

Next step

If SCADA is new ground, start with the system view in what is SCADA, then set up the actual link. For an Allen-Bradley plant, the driver side begins with RSLinx configuration and connect to PLC, and for a quick reporting job that skips SCADA altogether there is how to get data from PLC to Excel.