verified connector library

AERCO BMS/C-More boiler controller

Register map(s) for this device, each at the trust rung it earned. Addresses are 0-based as on the wire. Word order and scaling are confirmed at the hardware-verified rung and at no rung below it.

interop-verified

Read + decoded cleanly over a real network vs an independent third-party Modbus test server (transport and framing; reads are remapped into the server's register window, so the map's own addresses are NOT exercised). Does NOT prove word order/scaling against the actual device.

pointaddress (0-based)typescaleunit
default_message_display_code0U161
unit_status1U161
outlet_temp2U161DEGREES_1
inlet_temp3U161DEGREES_1
aux_temp4U161DEGREES_1
outdoor_temp5U161DEGREES_2
exhaust_temp6U161DEGREES_2
ffwd_temp7U161DEGREES_1
fire_rate_out8U161%
o2_level9U161%
co_level10U161PPM
run_cycles_low11U161
run_cycles_high12U161
run_hours_low13U161
run_hours_high14U161
flame_strength15U161%
active_setpoint16U161DEGREES_1
fire_rate_in17U161%
manual_fire_rate18U161%

link settings as documented (unverified): RTU; default 9600 8??; unit ID 128; FC 03,04,06,08,17; RTU transmission ONLY. C-More baud rate is fixed at 9600.

bench facts as documented (unverified)
terminalsRS485, 2-Wire Differential Bus With Shield
A/B polarityIt is imperative that polarity be maintained between all Modbus Network connections.
terminationA terminating resistor (120 ohms) on each end of the RS485 loop. BMS/BMS II has a built-in 120 ohm terminating resistor.
connectorRS232 (DB9-Female) and internal RS232 connector
isolation232 ISO GND
shield/groundtwisted-pair wiring shield should only be terminated at the controlling Master Controller for the Modbus Network.
broadcastsupported
protocol notesHeartbeat Timeout: Fixed at 10 seconds For C-More, Adjustable For BMS/BMS II: 5 to 240 Seconds
firmware register20
FC 43 device IDnot supported
power85-265 VAC
doc revisionREVISED FEBRUARY 17, 2011
field reports — community-sourced, unverified (checked 2026-06-11)
  • confirmed: comms defaults (baud rate 9600, default unit ID 128, RTU framing) — confirmed by AERCO Modbus Communication User Manual OMM-0035 (GF-114)
  • confirmed: physical layer (RS485 2-wire differential bus, 120 ohm termination, RS232 DB9 connector) — confirmed by AERCO Modbus Guidelines GF-2080 and OMM-0035
  • confirmed: register map summary (default_message_display_code @ 0, unit_status @ 1, outlet_temp @ 2, inlet_temp @ 3, aux_temp @ 4, outdoor_temp @ 5, exhaust_temp @ 6, ffwd_temp @ 7, fire_rate_out @ 8, o2_level @ 9, co_level @ 10, run_cycles_low @ 11, run_cycles_high @ 12, run_hours_low @ 13, run_hours_high @ 14, flame_strength @ 15, active_setpoint @ 16, fire_rate_in @ 17, manual_fire_rate @ 18) — confirmed by AERCO Modbus Communication User Manual OMM-0035 (GF-114) Standard Input Register Address Mapping

The trust ladder

Each rung states what it proved and what it did not. Gray until proven; green is earned by hardware only.

If your device isn't here, upload its register map. Generation is free, and the connector keeps the rung it earns under testing.

To prove a connector against your own device, order hardware verification. If it doesn't verify, you don't pay.

Platform builders can license the verified library: machine-readable maps, the firmware matrix, API access.