Java应用与OMRON CS1 PLC通信:FINS命令构建故障排查
Hey there, let's walk through how to fix the FINS command you're building for your CS1 PLC. Based on the topology and packet details you shared, here's a step-by-step troubleshooting plan:
1. Fix the GCT (Gateway Count) Field
You mentioned the GCT is 0x20 in your breakdown, but the actual packet uses 0x02—both are wrong. For a direct PC-to-PLC connection (no gateways in between), the GCT field (3rd byte) must be 0x00. This tells the PLC there's no routing needed, and an incorrect value here will make the PLC ignore your packet entirely.
2. Correct the Command Code
Your current command code is 0x82, which is for force set/reset operations—not reading or writing D registers:
- Use
0x01if you want to read D0100 - Use
0x02if you want to write to D0100
3. Fix the Register Address Byte Order
D0100 translates to decimal address 100, which is 0x0064 in hex. FINS requires address bytes to be big-endian (high byte first). Your packet uses 0x64 0x00—flip this to 0x00 0x64 to target the correct register.
4. Example of a Valid FINS Packet
Read D0100 (UDP)
80 00 00 00 32 00 00 39 00 01 01 01 82 00 00 64 00 01
Let's break this down to confirm:
- ICF:
0x80(UDP frame, expects a response) - RSV:
0x00(reserved field, always 0) - GCT:
0x00(no gateways) - DNA/DA2/SNA/SA2:
0x00(required for IP-based FINS communication) - DA1:
0x32(last octet of PLC IP: 50) - SA1:
0x39(last octet of PC IP: 57) - SID:
0x01(session ID, increment this for each new request) - MR:
0x01(main request) - SR:
0x01(no sub-request) - Command Code:
0x01(read data area) - Sub-Command:
0x00(default for read) - Data Area Code:
0x82(D register area) - Address:
0x00 0x64(D0100, decimal 100) - Word Count:
0x00 0x01(read 1 word)
Write Value 123 to D0100
Add the value bytes (0x00 0x7B = decimal 123) at the end:
80 00 00 00 32 00 00 39 00 01 01 02 82 00 00 64 00 01 00 7B
5. Basic Communication Checks
- First, confirm your PC can ping the PLC at
10.1.0.50—if ping fails, fix network connectivity first. - Use Wireshark to capture traffic on port 9600 (default FINS UDP port) to see if your packet is reaching the PLC and if a response is sent back.
- Verify the CS1's Ethernet module settings: ensure FINS UDP communication is enabled, and no firewall (on PC or PLC side) is blocking port 9600.
- Double-check your SID logic: incrementing it for each new request is correct, as this helps match responses to the right request.
内容的提问来源于stack exchange,提问作者Adam Macierzyński

