Bridging legacy RS485 PLCs and RTUs onto an IP network without touching the field device is one of the most requested — and most commonly misconfigured — tasks in retrofit SCADA integration. Here is the complete configuration walkthrough, from serial parameters to Modbus TCP verification.
Written by E-Lins Engineering Team
Why a Modbus RTU to TCP Gateway Industrial Router Is the Retrofit Integrator’s Default Tool
Almost every SCADA retrofit project I get called into starts the same way: the customer has a field device — a flow computer, a genset controller, an energy meter, an old PLC — that has been running Modbus RTU over RS485 for a decade or more, and now the operations team wants that data in a modern IP-based historian, cloud dashboard, or centralized polling master. Replacing the field device is not on the table. It works, it’s certified for its environment, and there is no business case for swapping it out. The only thing that needs to change is how the data gets off the serial bus and onto the network.

That is exactly the job of a Modbus RTU to TCP gateway industrial 4G/5G router: a single device that terminates the RS232 or RS485 serial bus on one side, and presents that same data as Modbus TCP — or as a transparent IP tunnel — on the other. No protocol converter box, no external DTU module, no changes to the PLC’s ladder logic or register map. The router does the translation. Get the configuration right and the SCADA master never knows the difference between a device that is three meters away on a local RS485 bus and one that is three hundred kilometers away behind a cellular or Ethernet WAN link.
The four failure modes I see most often on Modbus gateway configuration jobs: serial parameters that don’t match the field device exactly — wrong baud rate, parity, or stop bits; the wrong operating mode selected for the SCADA polling architecture in use; TCP connection limits that quietly drop a second polling client; and no VPN or firewall rule protecting a Modbus TCP port that has no authentication of its own. Every one of these is preventable by working through the configuration in the right order.
Two Ways to Bridge Serial to IP: Transparent DTU Mode vs. Modbus RTU Gateway Mode
Before touching the web interface, it’s worth being clear on which of the two bridging modes the application actually needs — this single decision shapes almost everything else in the configuration.
Transparent DTU Mode
In transparent DTU (Data Transfer Unit) mode, the router opens a raw TCP or UDP socket and passes every byte that arrives on the serial port straight out to the network, and vice versa — no protocol awareness, no translation. The SCADA master on the other end still needs to speak Modbus RTU itself; the router is simply extending the serial cable over IP. This is the right mode when the upstream software is a legacy SCADA package that only has a serial driver, or when the field protocol on the bus is not Modbus at all (a proprietary RTU protocol, for example) and a byte-transparent tunnel is the only option.
Modbus RTU Gateway Mode
In Modbus RTU gateway mode, the router actively participates in the protocol: it runs a Modbus TCP server on a configured port, accepts standard Modbus TCP requests (function code, unit/slave ID, register address, register count) from any Modbus TCP master, translates each request into a Modbus RTU frame on the RS485 bus, waits for the RTU response from the field device, and translates that response back into a Modbus TCP reply. This is the mode almost every modern serial to IP bridging for legacy PLCs and RTUs project should use when the polling master supports Modbus TCP — which is the default protocol for practically every current SCADA, historian, and IIoT platform.

Rule of thumb: if the upstream software already speaks Modbus TCP (Ignition, ClearSCADA, most modern historians, most cloud IoT platforms), use Modbus RTU gateway mode — it’s simpler to secure, supports multiple simultaneous masters correctly, and doesn’t require the SCADA host to carry a serial driver. Use transparent DTU mode only when the polling software genuinely has no Modbus TCP option and must see a virtual COM port.
Pre-Configuration Checklist — Gather This Before You Open the Web GUI
The single biggest time-saver on a gateway configuration job is walking in with the field device’s serial parameters already documented, rather than discovering them through trial and error at the site. Confirm the following before you start:
- Baud rate, parity, data bits, and stop bits for every device on the RS485 bus — from the instrument’s manual, not a guess. 9600 8N1 is the most common default, but plenty of older PLCs run at 19200 or non-standard values.
- Modbus slave/unit ID for each device on the bus, and whether the bus is single-drop or multi-drop with several instruments sharing the same pair.
- Which protocol mode the upstream SCADA master expects — Modbus TCP gateway, or a transparent serial tunnel to a virtual COM port.
- How many simultaneous Modbus TCP masters need to poll this gateway at once — a historian and an HMI polling the same device concurrently is common and needs to be planned for at configuration time, not discovered afterward.
- The IP addressing and network path between the router and the polling master — LAN, cellular WAN with a static or dynamic public IP, or a VPN tunnel back to a central SCADA host.
- RS232 or RS485 wiring — confirm which physical layer the field device uses, and for RS485 confirm 2-wire vs 4-wire and whether termination resistors are required at the bus ends.
Choosing the Right E-Lins Router for a Modbus RTU to TCP Gateway Deployment
All of the E-Lins industrial router models with a serial interface support both transparent DTU mode and Modbus RTU gateway mode as standard firmware features — the choice between models comes down to how many serial buses need bridging, how many Ethernet or Wi-Fi clients need to share the connection, and whether cellular dual-SIM redundancy is required for the site.
Single Instrument, Compact Footprint
- One RS232 or RS485 port bridging a single field device or short multi-drop bus.
- Panel or DIN-rail mounting inside an existing cabinet with limited space.
- Single SIM cellular or wired WAN uplink is acceptable.
- Recommended: E-Lins H685f — compact 5G/4G router (100×60×21 mm) with RS232/RS485, 2× LAN/WAN, and native Modbus and DTU support.

Multi-Instrument or Redundant Coverage
- Single RS485 bus with multiple slave devices, or a site needing dual SIM carrier failover.
- DI/DO hardware alarm reporting alongside the Modbus data path.
- GPS/GNSS location tagging for mobile or distributed assets.
- Recommended: E-Lins H750 or H720 — dual SIM, RS232/RS485, 4× DI/DO, GPS.
H700 — When Two Separate RS485 Buses Need Independent Gateways
Some retrofit sites have two physically separate serial buses — a wellhead safety controller on one bus and a flow computer on another, for example — that should not share a multi-drop line. The E-Lins H700 provides two independent serial ports (DB9 + terminal block), each configurable as its own Modbus RTU gateway with its own TCP listening port, alongside five Gigabit Ethernet ports and dual-band Wi-Fi for sites where an engineering workstation also needs local wireless access.
H820 — For Modernized Sites With a Lighter Serial Requirement
The E-Lins H820 offers RS232/RS485 as an order-time option on a more compact, single-SIM chassis with five switchable Ethernet ports and optional Wi-Fi 6 — a fit for sites where cellular coverage is reliable enough that dual SIM isn’t required, but a Modbus RTU to TCP bridge is still needed for one legacy instrument alongside newer Ethernet-native equipment.
Serial Port & Gateway Specification Comparison
All specifications below are drawn from the manufacturer’s datasheets. Confirm the current SKU configuration before ordering, as serial and DI/DO ports are order-time options on some models.
| Specification | H685f Compact Single SIM | H750 Dual SIM Standard | H720 Dual SIM 5-Port | H700 Dual Serial / Gigabit | H820 Compact Indoor |
|---|---|---|---|---|---|
| Serial Ports | 1× RS232 or RS485 terminal block | 1× RS232 or RS485 terminal block | 1× RS232 or RS485 terminal block | 2× serial ports DB9 + terminal block | Optional RS232/RS485 order-time option |
| Gateway Modes | Modbus RTU gateway + transparent DTU | Modbus RTU gateway + transparent DTU | Modbus RTU gateway + transparent DTU | Modbus RTU gateway + transparent DTU (per port) | Modbus RTU gateway + transparent DTU |
| SIM Slots | Single SIM E-SIM/EUICC option | Dual SIM 8 switching modes | Dual SIM 8 switching modes | Dual SIM 8 switching modes | Single SIM dual cellular option |
| Ethernet Ports | 2× switchable LAN/WAN | 3× switchable LAN/WAN | 5× switchable LAN/WAN | 5× Gigabit, switchable | 5× switchable LAN/WAN |
| Digital I/O | 4× DI/DO SMS alarm; 0–3.3V | 4× DI/DO SMS alarm; 0–3.3V; 5–40V option | 4× DI/DO SMS alarm; 0–3.3V; 5–40V option | 4× DI/DO SMS alarm; 0–3.3V; 5–40V option | Not listed standard |
| Power Input | 5–40V DC 5–60V option; dual/tri inputs | 5–40V DC 5–60V option; dual inputs | 5–40V DC 5–60V option; dual inputs; PoE PD | 5–40V DC 5–60V option; dual inputs | 5–40V DC 5–60V option; PoE PD/PSE option |
| Operating Temp | −35°C to +75°C | −35°C to +75°C | −35°C to +75°C | −35°C to +75°C | −35°C to +75°C |
| Size (with case) | 100×60×21 mm | 136×109×45 mm | 180×114×32 mm | 231×116×35 mm | 168×104×25 mm |
| VPN | IPsec, L2TP, GRE, PPTP, OpenVPN, DMVPN, WireGuard, ZeroTier, EoIP — all models | ||||
| Management | E-Lins NMS, Web GUI, SMS, SNMP, TR-069, SSH/CLI — all models | ||||
* All specifications from E-Lins official datasheets. Verify current SKU configuration before procurement, as serial ports and DI/DO are order-time options on some models.
Step-by-Step: Configuring the Modbus RTU to TCP Gateway
The following walkthrough covers Modbus RTU gateway mode, which is the correct choice for the great majority of retrofit SCADA integrations connecting to a modern Modbus TCP polling master. The menu labels below reflect the standard E-Lins web GUI; exact wording can vary slightly by firmware version.
- Wire the serial connection before powering up. Confirm RS232 (TX/RX/GND) or RS485 (A/B, plus GND if available) wiring against the field device’s terminal labeling — reversed A/B pairs are the most common wiring mistake and produce no data with no error message on either side.
- Log in to the router’s web GUI. Connect a laptop to a LAN port, browse to the router’s default LAN IP (typically
192.168.1.1), and log in with the device’s admin credentials — found on the unit label or the order documentation. - Navigate to the serial port configuration menu — typically under
Network > Serial PortorServices > Serialdepending on firmware version. Enable the port and select the physical mode: RS232 or RS485. - Set the serial parameters to match the field device exactly. Baud rate, data bits, parity, and stop bits must be identical to what you documented in the pre-configuration checklist. A single mismatched parameter — parity set to Even instead of None, for example — produces a serial link that appears connected but returns no valid Modbus responses.
- Select the protocol/working mode. Choose Modbus RTU Gateway (sometimes labeled Modbus TCP Server or Modbus Gateway) rather than Transparent/DTU mode, unless the upstream master specifically requires a raw serial tunnel.
- Configure the TCP listening port. The Modbus TCP standard port is
502; this can be changed if the port is already in use on the network or if policy requires a non-standard port. Note the port number for the SCADA master’s configuration. - Set the maximum simultaneous TCP connections. If more than one master (a historian and an HMI, for example) will poll this gateway concurrently, increase this value from its default of one — leaving it at one is a common cause of “works from my laptop, fails from the SCADA server” symptoms during commissioning.
- Set the inter-frame and response timeout. Slower or older field devices may need a longer response timeout than the router’s default; if the polling master reports intermittent timeouts, this is usually the first setting to check.
- Save and apply the configuration. Some firmware versions require a router reboot for serial port changes to take effect — check the confirmation message after saving.
- Configure network reachability for the Modbus TCP port from the polling master’s location: a LAN route if the master is local, port forwarding plus a firewall rule if the router is WAN-facing, or a VPN tunnel (see the security section below) for anything crossing a public network.

On multi-drop RS485 buses with several slave devices: the router’s serial port configuration is shared across the whole bus — baud rate and framing parameters apply to every device on that RS485 line. Each Modbus TCP request specifies its own unit/slave ID, which the router passes through unchanged to the RTU frame, so multiple devices on one bus are addressed correctly as long as every device shares the same serial parameters and has a unique slave ID.
Verifying the Gateway and Securing Modbus TCP Traffic
Testing the Gateway Before Connecting the Production SCADA Master
Before pointing the production polling system at the new gateway, verify it independently with a Modbus TCP client utility (a Modbus polling/testing tool running on a laptop is the standard approach). Point the tool at the router’s IP address and the configured TCP port, set the correct unit/slave ID, and read a known holding register or coil from the field device. A successful read confirms the full path — serial wiring, serial parameters, gateway mode, and network reachability — is correct before the SCADA team’s polling schedule depends on it.
| Typical Verification Values |
| Gateway IP:Port — router LAN or WAN address, port 502 (or configured alternate) |
| Unit/Slave ID — as documented for the specific field device on the bus |
| Function code — Read Holding Registers (03) or Read Input Registers (04) are the most common first tests |
| Expected result — a valid register value returned within the configured response timeout, with no exception code in the reply |
Securing the Modbus TCP Path
Modbus TCP has no built-in authentication or encryption — any device that can reach the configured port can issue read and write requests to the field device. For any gateway reachable over a cellular WAN or the public internet, this makes a VPN tunnel back to the operations center a requirement rather than an option. All of the E-Lins models covered in this guide support IPsec, OpenVPN, WireGuard, L2TP, GRE, PPTP, and DMVPN, terminating on firewalls from Cisco, Juniper, Checkpoint, Palo Alto, SonicWall, and other enterprise vendors. For deployments connecting many remote gateways back to a single operations center, DMVPN or WireGuard avoids the operational overhead of a static point-to-point tunnel configuration per site.

“The gateway configuration itself is rarely the hard part — it’s usually a fifteen-minute job once the serial parameters are confirmed. The part people skip is the VPN. A Modbus TCP port sitting open on a cellular WAN IP with no tunnel in front of it is a write-access door into a PLC, and that’s true whether the device controls a vending machine or a pressure relief valve.”— E-Lins Engineering Team, on Modbus gateway security
Common Configuration Mistakes on Modbus RTU to TCP Gateway Deployments
Guessing Serial Parameters Instead of Confirming Them
The most frequent cause of “the router shows connected but no data is coming through” is a serial parameter mismatch — usually parity or stop bits, since baud rate mismatches tend to fail more obviously. Get the parameters from the field device’s documentation, or capture the RS485 traffic with a protocol analyzer if documentation isn’t available, rather than cycling through combinations by trial and error on a live production bus.
Using Transparent DTU Mode When Modbus Gateway Mode Was the Right Choice
Transparent DTU mode works, but it ties the polling master to a single serial-style connection and generally does not support multiple simultaneous clients cleanly, since the underlying link behaves like a shared serial port rather than a stateless TCP service. If the SCADA platform speaks Modbus TCP natively, gateway mode is simpler to secure, easier to troubleshoot with standard Modbus tools, and supports multiple masters correctly.
Leaving the Maximum TCP Connection Count at the Default
A default of one simultaneous connection is fine for a single-master proof of concept, but production sites frequently have a historian, an HMI, and an engineer’s laptop all wanting to poll the same gateway at different times. Increase the connection limit during commissioning, not after a second system mysteriously fails to connect.
Deploying a WAN-Facing Modbus TCP Port Without a VPN
Modbus TCP was designed for trusted industrial LANs, not for exposure on a cellular or public WAN. Every E-Lins gateway configuration that crosses a WAN link should terminate inside a VPN tunnel — IPsec, OpenVPN, or WireGuard — rather than forwarding the Modbus TCP port directly to the internet.
Not Accounting for RS485 Bus Termination and Wiring Polarity
On longer or multi-drop RS485 runs, missing termination resistors at the bus ends or a reversed A/B pair produces intermittent or garbled communication that can look like a router configuration problem when the root cause is physical layer wiring. Confirm bus topology and termination as part of the pre-configuration site check, not after the gateway configuration has been ruled out as the cause.
Extended Reading
E-Lins H685f Compact 5G Router — RS232/RS485, single SIM, Modbus and DTU support in a 100×60×21 mm chassis for single-instrument retrofit gateways.
E-Lins H750 Dual SIM 4G Industrial Router — RS232/RS485, dual SIM, DI/DO ×4, and GPS for standard remote Modbus gateway deployments.
E-Lins H720 Dual SIM 4G Router — five Ethernet ports alongside the same serial and DI/DO capability as the H750, for multi-device sites.
E-Lins H700 Gigabit Dual-Band Wi-Fi 4G Router — two independent serial ports for sites bridging two separate RS485 buses simultaneously.
E-Lins H820 4G Industrial Router — compact five-port router with optional RS232/RS485 for modernized sites with a lighter serial requirement.
Frequently Asked Questions
Q1:What’s the difference between Modbus RTU gateway mode and transparent DTU mode?
Modbus RTU gateway mode makes the router an active Modbus TCP server: it understands the protocol, accepts standard Modbus TCP requests, and translates them into Modbus RTU frames on the serial bus, supporting multiple simultaneous TCP clients correctly. Transparent DTU mode simply extends the serial connection over a raw TCP or UDP socket without protocol awareness — the polling master still needs a serial-capable Modbus driver on its own end. Use gateway mode whenever the upstream software supports Modbus TCP, which covers the majority of current SCADA and historian platforms.
Q2:Can multiple SCADA masters poll the same Modbus RTU to TCP gateway at once?
Yes, as long as the router is configured in Modbus RTU gateway mode (not transparent DTU mode). The key setting is the maximum simultaneous TCP connections parameter in the serial port configuration — the default is typically 1, so you’ll need to increase it to match the number of masters that will poll the gateway (e.g., a historian plus an HMI = 2). Each master connects to the same TCP port (default 502) and specifies the target slave/unit ID in each Modbus TCP request. The router handles the translation and response routing correctly for multiple clients as long as the connection limit is set high enough. Transparent DTU mode does NOT support multiple simultaneous masters cleanly, since it treats the serial link as a single shared connection.
Q3:Do I need to change the Modbus register addresses when bridging RTU to TCP?
No. The router passes the function code, unit/slave ID, register address, and register count through unchanged between Modbus TCP and Modbus RTU — it is a transport-layer translation, not a register remapping. The SCADA master’s register map should be configured exactly as it would be for a direct serial connection to the same device.
Q4:Which E-Lins router should I use for a single legacy PLC retrofit versus a multi-instrument site?
For a single field device on a compact panel, the H685f’s small footprint and single RS232/RS485 port are usually sufficient. For sites needing dual SIM cellular redundancy, DI/DO hardware alarm reporting, or GPS tagging alongside the serial bridge, the H750 or H720 are the standard recommendation. Sites with two physically separate RS485 buses that need independent gateways should use the H700, which provides two serial ports.
Q5:Why is the gateway showing as connected but no Modbus data is coming through?
This is almost always a serial parameter mismatch — baud rate, parity, data bits, or stop bits not matching the field device exactly — or an RS485 wiring issue such as a reversed A/B pair or missing bus termination. Confirm the serial parameters against the device’s documentation, verify wiring polarity, and test with a Modbus TCP client tool directly against a single known register before troubleshooting further up the network path.
Q6:Is it safe to expose the Modbus TCP port directly on a cellular WAN IP?
No. Modbus TCP has no built-in authentication or encryption, so any device that can reach the configured port can issue read and, critically, write requests to the field device. For any gateway reachable over a cellular or public WAN, wrap the connection in a VPN tunnel — IPsec, OpenVPN, or WireGuard, all supported on E-Lins routers — rather than forwarding the port directly to the internet.
Conclusion: Get the Serial Parameters Right, Then the Rest Is Straightforward
Configuring a Modbus RTU to TCP gateway on an E-Lins industrial router is, in practice, a short list of settings — physical serial mode, baud/parity/stop bits, gateway mode selection, TCP port, and connection limit. The projects that go smoothly are the ones where those serial parameters were confirmed from the field device’s documentation before the router was ever powered on, and where the network path back to the SCADA master was secured with a VPN from the start rather than added after an audit flagged an open port.
Three things to verify before calling a Modbus gateway configuration complete:
- The serial parameters — baud rate, parity, data bits, stop bits — match the field device exactly, confirmed against its documentation rather than assumed from a common default.
- Modbus RTU gateway mode is selected (not transparent DTU) whenever the upstream SCADA platform supports Modbus TCP, with the maximum simultaneous connection count increased to match the number of masters that will actually poll the gateway.
- The Modbus TCP path back to the operations center runs inside a VPN tunnel rather than a directly forwarded port, for any gateway reachable over a cellular or public WAN.
Retrofitting a Legacy RTU or PLC onto IP?
Share your field device’s serial parameters, the number of instruments on the bus, and your SCADA platform’s protocol support, and E-Lins engineering can confirm the right router model and gateway configuration for your site.






