verified connector library

Honeywell UDC2500/3200/3300 controller (Modbus comms option)

Register map(s) for this device, each at the trust rung it earned. Addresses are 0-based as on the wire. Word order and scaling are confirmed at the hardware-verified rung and at no rung below it.

interop-verified

Read + decoded cleanly over a real network vs an independent third-party Modbus test server (transport and framing; reads are remapped into the server's register window, so the map's own addresses are NOT exercised). Does NOT prove word order/scaling against the actual device.

pointaddress (0-based)typescaleunit
pv_integer0I160.1Prescale * 10
remote_set_point_integer1I160.1
working_set_point_integer2I160.1Prescale * 10
output_integer3I160.1Prescale * 10
input_1_integer4I160.1
input_2_integer5I160.1
pv_float64F32BE1EU
remote_set_point_float66F32BE1EU
working_set_point_float68F32BE1EU
output_float70F32BE1EU
input_1_float72F32BE1EU
input_2_float74F32BE1EU
analog_input_16144F32BE1EU
analog_input_26146F32BE1EU
analog_input_36148F32BE1
analog_input_46150F32BE1
totalizer_16912F32BE1EU
totalizer_26914F32BE1
alarm_status_1_167152U161
alarm_set_point_17168F32BE1EU
alarm_set_point_27170F32BE1

link settings as documented (unverified): RTU; baud 300/600/1200/2400/4800/9600/19200/38400; FC 01,02,03,04,05,06,08,16,17,20,21

bench facts as documented (unverified)
wiring notesThe Modbus RTU allows the instrument to be a citizen on a data link shared with other devices that subscribe to the Modbus RTU RS-485 specification.
max registers/read22
broadcastnot supported
protocol notesRequest delay time is 20 ms (or 3.5 characters for newer versions).
identification notesUses Function Code 17 (11h) to report Device ID.
FC 43 device IDnot supported
doc revisionRevision T
field reports — community-sourced, unverified (checked 2026-06-11)
  • The standard UDC2500/3200 product manuals only document registers for Function Codes 20 and 21, which are proprietary and unsupported by most commercial Modbus masters. Users must refer to the separate Modbus RTU Serial Communications User Manual (51-52-25-66) to obtain the standard operational register map (FC03/FC04/FC06/FC16). [source]
  • The Ethernet IP address on the UDC2500/3200 Ethernet option card cannot be configured via the front keypad; it can only be configured using Honeywell's proprietary PIE (Process Instrument Explorer) software. The default IP address is 10.0.0.2. [source]
  • Writing setpoints or parameters continuously to the UDC controller via Modbus will cause premature EEPROM memory fatigue and eventual hardware failure. Setpoints should only be written on change or at the start of a segment. [source]
  • Writing to UDC2500 controllers using Function Code 6 can trigger Modbus Exception Code 3 (Illegal Data Value) due to High Limit FM approval constraints or incorrect register mapping. [source]
  • confirmed: comms defaults (baud rates up to 38400, 8-N-1 framing) — confirmed by Honeywell Modbus RTU Serial Communications User Manual (51-52-25-66, Rev T) and field integration notes on Control.com
  • confirmed: Function Code 17 (11h) used for Device ID — confirmed by Honeywell Modbus RTU Serial Communications User Manual
  • confirmed: pv_integer @ 0 (40001) and pv_float @ 64 (40065) — confirmed by Honeywell Modbus RTU Serial Communications User Manual and Control.com forum threads
  • confirmed: analog_input_1 @ 6144 (1800h) — confirmed by Honeywell Modbus RTU Serial Communications User Manual

The trust ladder

Each rung states what it proved and what it did not. Gray until proven; green is earned by hardware only.

If your device isn't here, upload its register map. Generation is free, and the connector keeps the rung it earns under testing.

To prove a connector against your own device, order hardware verification. If it doesn't verify, you don't pay.

Platform builders can license the verified library: machine-readable maps, the firmware matrix, API access.