HSMS Linktest Timeout While Data Still Flows: Close the Socket Anyway
A swallowed Linktest.req burns T6 while an S1F1 on the same socket answers with a full S1F2 in 0.3 ms, and the host should close the connection anyway.
Protocols
Protocol notes written for people who need to connect real devices, verify data, and troubleshoot communication paths.
Registers, unit IDs, polling, addressing, and mapping notes for Modbus TCP/RTU.
Typed data, subscriptions, address spaces, security, and interoperability notes.
Pub/sub telemetry patterns for edge gateways, brokers, topics, and payload context.
A swallowed Linktest.req burns T6 while an S1F1 on the same socket answers with a full S1F2 in 0.3 ms, and the host should close the connection anyway.
An S1F4 body carries no SVIDs at all. Real S1F11/S1F12 bytes showing where a host learns SVID numbers and names, and how S2F29 differs.
SELECTED is E37, COMMUNICATING is E30. Real bytes showing an S1F3 sent before S1F13/S1F14 aborted as S1F0, and the same S1F3 answered after.
You asked S2F13 for one ECID and S2F14 came back with two values. Real S2F29 and S2F13 bytes, and the length check host code must run.
Your report is defined but S6F11 never arrives. Real S2F33, S2F35 and S2F37 captures from two equipments, and what a non-zero LRACK tells the host.
Equipment clock drift reorders S6F11 events while HSMS stays green. Reading the clock with S2F17, setting it with S2F31, and why TIACK 0 proves nothing.
S2F41 START rejected with HCACK 2 while the equipment screen reads ONLINE. Separating the SEMI E30 communication state from the three control states, with a real HSMS capture showing the byte where HCACK flips from 2 to 0.
Run all ten SEMI E30 startup steps — S1F13 through S2F31 — with one npx command against a simulator, with the equipment-side wire capture of the run, what each PASS proves, and what a refused Select actually prints.
Five bad SECS-II messages pushed at a live HSMS listener. One drew a real S9F7, the rest came back as SxF0 aborts. What SEMI E5 stream 9 means and how to read MHEAD.
A real capture where two HSMS requests share one SystemBytes and the replies come back byte-identical, plus the allocation rules that prevent it.
One log line says timeout. A real HSMS capture separates T3 from T6, pins the SEMI E37 defaults (T3 45 s, T6 5 s, T7 10 s, T8 5 s) and shows the two timers your host has to enforce itself.
A 300-byte PPBODY is 330 bytes on the socket. A real S7F1 and S7F3 capture, and what a host loses by skipping the grant step.
Connection refused in 3 ms, or a TCP session where nothing ever arrives. Real captures that tell the two HSMS mode mistakes apart.
The HSMS session is SELECTED and S1F13 draws only a T3 timeout, while Linktest answers on the same socket in 0 ms. A capture, and two state machines.
An S1F3 body byte by byte: the item header packs format code and length-byte count, and one wrong length silences the whole connection.
A capture where Deselect.req, Reject.req and two unassigned STypes all draw silence, while Linktest answers instantly and the session stays SELECTED.
A capture of two host connections into one passive HSMS listener. Both get Select Status 0, and the first is never told the second arrived.
S1F1 sent, no S1F2, T3 expires — and the tool did nothing wrong. Captures of Header Byte 2 showing what packing the W-bit and Stream together costs.
A host that only drops replies under load is usually a parser treating one recv() as one message. Four captures: two messages in one write, one split, a body short of its length field, and a prefix claiming 1 MiB.
The host shut down but the tool still shows SELECTED. Two captures side by side: a session ended with Separate.req, and one where only the socket closed.
In HSMS, alive and connected are different states. A real capture of Linktest and S1F13 sent before Select ever goes out, the Reject.req reason 4 that SEMI E37 asks for there, and why the timer that fires first is T6, not T7.
Real Select.rsp captures — accepted, refused with SEMI E37 Select Status 1/2/3, and answered under a different SessionID — and where 'select failed' loses the detail.
Real captures of the three ways a Select gets no usable answer — silence, mismatched SystemBytes, and a wrong SessionID — and the SEMI E37 timers T5, T6 and T7 that decide what your log shows.
A real HSMS capture from 127.0.0.1:5501: request and mismatched Select.rsp decoded byte for byte, what a host's SystemBytes-keyed pending reply table does with the frame, and why the timer that fires is T6 and not T3.
Bringing WirelessHART gateway data into SCADA safely: update rate versus polling, stale-value detection, Modbus mapping pitfalls and join troubleshooting.
Sizing polls, timeouts and keepalives for SCADA over LTE: the byte arithmetic, carrier NAT timeouts, report-by-exception, and why nobody dials in.
How IEC 62439-3 PRP and HSR deliver bumpless redundancy for SCADA and IEC 61850, why a failed LAN goes unnoticed, and what to monitor at commissioning.
NTP holds most SCADA clocks within milliseconds, which is plenty — until you need 1 ms sequence-of-events across substations. Where PTP earns its cost.
How a driver discovers BACnet devices, reads present-value and writes commandable objects: object identifiers, the 16-slot priority array, COV and BBMD.
How GOOSE stNum/sqNum counters, allowedToLive and ConfRev decide whether SCADA sees a breaker trip in milliseconds or never — and proving it is alive.
How BRCB and URCB blocks feed substation data to SCADA: datasets, trigger options, buffer time, and the reservation fights that starve a client.
DNP3 double-bit inputs (groups 3 and 4) encode 52a/52b contacts as four states, killing the OPEN/CLOSED flicker single-bit status shows mid-travel.
Commissioning DNP3 Secure Authentication (SAv5, IEEE 1815-2012): which functions to mark critical, aggressive mode on slow links, and key mismatches.
Why OPC Classic (DA/HDA) links fail across DCOM — RPC endpoint mapper on 135, dynamic port ranges, server identity — and the fastest way through it.
A PLC exposes a UDT over OPC UA and your client shows a ByteString. What an ExtensionObject actually holds, and how clients decode structured DataTypes.
Pulling ControlLogix and CompactLogix tags over EtherNet/IP: connected versus unconnected CIP, RPI, connection budgets, and why array reads win.
TCP to port 2404 is up, the RTU is reachable, every point still stale. It is almost always STARTDT and the general interrogation nobody sent.
The two IIN octets in every DNP3 response report restart, lost events, missing time and local control. Reading them, and clearing the ones that stick.
How to pull HART secondary variables and diagnostics into SCADA beyond the 4-20 mA loop, using multiplexers, HART-enabled I/O, and WirelessHART gateways.
A VFD is commanded through a packed control word and reports through a status word. Map either wrong and it won't start, or it clears a latched fault.
The deadband decides whether a change becomes an event; the Group 32 variation decides its size. Set both wrong and you flood the buffer or lose time.
Commissioning a serial-to-Ethernet device server carrying Modbus RTU: operating mode, packing timers, TCP framing, idle timeouts and half-duplex control.
Computing usage across a wrapping counter without inventing phantom flow: register width, correcting the delta once, and rollover versus meter reset.
How drivers group Modbus registers into block reads, why gap tolerance and block size matter, and how one unmapped address takes down a whole block.
Sequence numbers and the Republish service turn a dropped notification into zero data loss — but only if the client watches them and the queue is sized.
Class 0/1/2/3 assignment, deadbands, unsolicited responses, event buffers, and the IIN bits that decide whether a master survives a comms gap.
A DNP3 link that stalls or logs CRC errors gets fixed one layer down: addressing, confirmed service, retry and timeout tuning on radio and serial.
Select-before-operate versus direct operate, CROB trip/close codes, the select timeout that bites on slow links, and verifying feedback not the response.
Why outstations stamp their own events, how the Need Time (IIN1.4) bit and delay-corrected clock writes work, and how bad sync turns an SOE log to fiction.
Running report-by-exception and change-of-state — DNP3 events, deadbands, heartbeats, integrity polls — without losing short events or stale values.
Intermittent bad quality usually starts at a switch port. Which SNMP objects are worth polling, why counters only mean anything as rates, and trap gaps.
A Modbus TCP-to-RTU gateway can answer ping and still drop requests. Finding the queue saturation behind stale tags, and tuning the driver for it.
Browse returns success but the tag import is short. The OPC UA Part 4 v1.05 continuation point rules, MaxBrowseContinuationPoints, and how to find the cause.
Commissioning OPC UA PubSub (Part 14, UADP over UDP) without shipping stale values as live: dataset contracts, VLAN checks, and reboot-only failures.
How to choose Modbus RTU baud rate, silent interval (t3.5), and turnaround delay so slow serial devices get a fair chance to reply on a SCADA link.
MQTT arrival order is not process order. Why the DUP flag never catches the duplicates that hurt, Sparkplug's 8-bit seq wrap, and the MQTT 5.0 properties that fix stale retained state.
Shared subscriptions split an MQTT stream across workers — and will quietly halve your historian feed and scramble trend order if you point them wrong.
Estimating the real load behind site/#, and the MQTT 5.0 features that actually contain it: Retain Handling, shared subscriptions, Receive Maximum, SUBACK reason codes.
AccessLevel vs UserAccessLevel vs WriteMask: why a setpoint that browses writable returns BadUserAccessDenied, and testing with the production identity.
NodeIds regenerate, browse paths move, DisplayName is a label. Picking the reference your HMI and historian store so firmware doesn't blank a screen.
Choosing DataChangeFilter settings — absolute versus percent deadband, DataChangeTrigger, queue size — so a filter cuts noise, not real movement.
Repairing a historian gap with OPC UA HistoryRead: scoping the window, letting returnBounds handle edges, keeping Bad quality, and paging safely.
A commissioning sequence for RSTP, MRP and PRP rings that measures what operators see: convergence time, dropped subscriptions, half-open sockets.
Modbus TCP devices cap simultaneous connections lower than you think. Inventorying clients, reading real socket behaviour, and protecting the HMI.
How a mishandled transaction ID lets a Modbus TCP gateway hand your SCADA driver the wrong register's value — and how to prove it with a capture.
Duplicate client IDs, wildcard rules nobody owns, retained commands that re-fire, and denied publishes that make no sound. What the MQTT spec actually guarantees at the edge.
The secure channel, the session and the subscription each expire on their own clock. Which one fired tells you to blame the firewall, load or keepalive.
Using StatusCode severity bits, SourceTimestamp and ServerTimestamp to catch frozen data, cached gateway values and clock drift a value-only HMI hides.
Why a flat 1-second scan overloads PLCs and gateways, and how scan classes and load shedding keep the data operators act on fast under stress.
Modbus has no standard endianness for 32-bit values, so two registers can decode to garbage. Proving byte and word order on site instead of guessing.
Versioning MQTT telemetry payloads so historians, HMI clients, MES connectors and analytics survive a field change instead of breaking on one.
Client won't connect though ping and port 4840 are open? Usually an endpoint URL, hostname SAN or ApplicationUri mismatch. Reading the status codes.
Where to tap, what to filter, and how to read the first thirty seconds of a capture when comms drop and recover before anyone can get to a keyboard.
The host wrote the EC, the tool returned EAC = 0, and nine lots ran on the old value. SEMI E5 EAC codes, a real S2F13 readback on the wire, the S2F29 namelist, and the SAT matrix.
A one-scan reject pulse lives for 20 ms. Poll every 250 ms and SCADA never sees it. Matching polling rates to PLC scan time, driver and historian.
SEMI E30 spooling only covers streams the host enabled with S2F43. SPOOL LOAD vs UNLOAD, the S2F44 RSPACK and STRACK codes, S6F24 RSDA, and the S2F43 bytes on a real socket.
Commissioning a Modbus RTU link the right way: prove polarity, termination, biasing and grounding before you ever open the register map.
Commissioning OPC UA Alarm & Condition subscriptions: event filters, the Retain flag, ConditionRefresh, and the failures that appear on reconnect.
A staged plan for rotating MQTT broker, client and CA certificates without breaking publishers, store-and-forward queues or Sparkplug birth sequences.
How OPC UA separates certificate trust, user identity and Part 18 role mapping — and commissioning writes so the wrong session can't move a setpoint.
The Modbus unit identifier is 'useless' on TCP until a gateway is involved. How routing works behind serial gateways, and finding the slave that answered.
How reverse connect flips the TCP direction through a cell firewall, and the certificate, endpoint and diagnostic traps that still bite afterward.
How monitored item queues, discard policy and the Overflow status bit decide whether your client sees every fast tag change or only the latest one.
Nobody memorizes a service account password, so a 90-day policy buys little. What IEC 62443-3-3 SR 1.2 and NIST 800-63B actually ask for.
Why an MQTT edge gateway loses data during a WAN outage, and how to buffer with source timestamps, sequence numbers and a replay policy that holds.
Reading SEMI E5 HCACK and CPACK codes against a real S2F41 wire capture: why HCACK=4 exists, E30 control-state gating, and a retry that won't fire a second START.
A Modbus TCP write response says the transaction was accepted, not that the motor moved. Command discipline: permissives, readback, and the retry trap.
An OPC UA method call can return Good while the machine never moves. Wiring HMI calls so operators see acceptance, execution and a real failure reason.
Designing SCADA remote access against IEC 62443-3-3 SR 5.2 and SR 1.13, testing the denied paths at commissioning, and the port and timeout numbers that break it.
Linking SECS/GEM collection events with S2F33/S2F35/S2F37, why report content empties after a tool restart, and proving S6F11 matches the real sequence.
Commissioning SCADA firewall rules from data flows rather than port lists — the supporting services that break at cutover, and proving each rule for real.
A field-tested procedure for OPC UA redundant failover: ServiceLevel, subscription recovery, certificates, and catching stale data before operators do.
Why a client browses fine with security off but drops the secure channel, and how to fix trust stores, endpoints and certificate names in a project.
How historian timestamps go wrong — clock drift, NTP versus PTP, OPC UA source time, late data, DST — and catching it before a report dispute does.
Setting Modbus TCP poll rates, timeouts, retries and scan groups so one stalled device or saturated gateway can't drag the whole driver down with it.
Practical notes for choosing MQTT QoS levels, retained messages, clean sessions, and duplicate handling in SCADA and industrial telemetry projects.
How sampling interval, publishing interval, queue size, deadband and the KeepAlive/Lifetime pair decide whether your client and historian see the process.
Reading Modbus exception responses on the wire, telling a refused request from a dead link, and chasing illegal-address and gateway causes.
After a PLC download the session opens and every item returns Bad_NodeIdUnknown. How namespace indexes and client caches shift, and what to check first.
Using Last Will, birth messages and retained state so a SCADA screen shows offline, stale and healthy as three things — not one green icon that lies.
A practical checklist for renewing OPC UA application certificates without breaking SCADA clients, historians, gateways, or production HMI connections.
Modbus connects, unit IDs respond, polls complete — and the operator still reads a swapped float. Proving a register map before the historian trusts it.
A SCADA screen shows a believable number long after the device stopped updating. Heartbeat, watchdog and stale-data tags that make freshness visible.
Laying out Sparkplug B group, edge node and device IDs — plus birth certificates, aliases and STATE — so a rename doesn't break every subscription.
A layered checklist for troubleshooting SCADA communication problems from physical link to protocol behavior.
S5F1 carries ALCD, ALID and ALTX. Bit 8 of ALCD is set-versus-clear, and dropping it leaves an MES alarm list that never goes green. Plus the S5F5/S5F6 recovery after a host restart.
A practical checklist for commissioning OPC UA client connections from SCADA, HMI, historian, or gateway software to PLCs and automation servers.
How raw SCADA, HMI and protocol values become useful machine state, process state, alarm state and control state, and where each one is decided.
A field checklist for commissioning managed industrial Ethernet switches used by SCADA servers, PLCs, remote I/O, drives, cameras, and protocol gateways.
How to think about OPC UA and MQTT in industrial systems without turning the comparison into a vendor argument.
A concise practical guide to Modbus TCP concepts: clients, servers, unit IDs, function codes, registers, polling, and mapping pitfalls.