IEC 60870-5-104 Integration Guide
IEC 60870-5-104 (IEC 104) is the telecontrol standard used by power utilities, substations, solar and wind parks, and other energy sites. MaestroHub connects as the controlling station (the SCADA master side) to an outstation: an RTU, a protection relay, or a gateway that concentrates many devices. This guide covers connection setup, the connect sequence, TLS, the five function types, and how the matching nodes and trigger slot into the Pipeline Designer.
Overview
The IEC 104 connector provides:
- A live process image: the latest report of every point the outstation sends, with its quality flags and device timestamp
- Monitor Points trigger: start a pipeline for every point the outstation reports, with no polling
- Read Points: the latest known value of the points you list, with quality and age, never a made-up 0
- Interrogation: station, group (1–16) and counter (1–4) interrogations on demand, on connect, and periodically
- Commands: single, double, regulating-step, set-point and bitstring commands with select-before-operate, sent at most once
- Clock synchronisation: on connect and on demand, written in the device's time zone
- TLS (IEC 62351-3): TLS 1.2+ with mutual authentication
How IEC 104 delivers data
An IEC 104 outstation pushes its data. It sends a point when the value changes (spontaneous), on a fixed cycle (periodic), or when it is asked for a snapshot (interrogation). MaestroHub keeps the latest report of every point in a process image for the connection, and pipelines use that image in two ways:
- Monitor Points is a trigger. It starts a pipeline for every point the outstation reports, with no polling.
- Read Points returns the latest known value of the points you list, with its quality and age.
Every point is addressed by its information object address (IOA), a number from 0 to 16,777,215, within one common address (the station address, 1 to 65,534).
What happens on connect
After the TCP (or TLS) connection is up and data transfer has started, MaestroHub runs up to three requests, in this order. Each one has its own switch and all three are on by default:
- Clock synchronisation: sends the current time, written in the device's time zone. Turn this off for outstations whose clock comes from GPS or from another master.
- Station interrogation: asks for the current value of every point, so the process image is complete straight away.
- Counter interrogation: asks for every integrated total (energy counters).
MaestroHub also repeats the station interrogation when the outstation reports that it restarted (end of initialisation), and, if you set Periodic Interrogation, at that interval.
If the outstation refuses or does not answer one of these requests, the connection stays up, and the connection log says which request failed and what to change.
Connection Configuration
Creating an IEC 104 Connection
Navigate to Connections → New Connection → IEC 60870-5-104 and configure the form. The form is organized into seven tabs: Connection, Startup, Link Timers, Security, Functions, Scaling, and Health. The Functions, Scaling, and Health tabs unlock after the connection is saved.
1. Profile Information
| Field | Default | Description |
|---|---|---|
| Profile Name | — | A descriptive name for this connection profile (required). Must be unique across all connections. |
| Description | — | Optional description for this IEC 104 connection |
| Labels | — | Key-value pairs to categorize and organize the connection |
Example Labels
site: substation-north— Sitevoltage: 110kv— Voltage leveldevice: rtu-1— Specific outstationenvironment: production— Deployment environment
2. Outstation
| Field | Default | Meaning |
|---|---|---|
| Address | (required) | Outstation host name or IP address |
| Port | 2404 | 2404 for plain IEC 104; 19998 is the port IEC 62351-3 assigns for IEC 104 over TLS |
| Common Address | 1 | The station address used in every request. Messages for any other common address are ignored |
| Originator Address | 0 | Identifies MaestroHub when several masters share the outstation. 0 = not used |
| Device Time Zone | UTC | The zone the outstation's clock runs in. Device timestamps carry no zone; MaestroHub converts them from this zone to UTC |
3. Startup
The Startup tab holds the three on-connect requests described in What happens on connect, and the periodic interrogation.
| Field | Default | Meaning |
|---|---|---|
| Synchronise Clock on Connect | on | See What happens on connect |
| Interrogate on Connect | on | See What happens on connect |
| Counter Interrogation on Connect | on | See What happens on connect |
| Periodic Interrogation | 0s (off) | Repeat the station interrogation at this interval |
4. Link Timers
These are the standard IEC 104 link parameters. Change them only to match what the outstation is configured with.
| Field | Default | Meaning |
|---|---|---|
| Connection Timeout (t0) | 30s | Time allowed to open the connection |
| Send / Test Timeout (t1) | 15s | The link is closed if a sent frame is not acknowledged within t1. Also bounds waiting for a request's confirmation |
| Acknowledge Delay (t2) | 10s | Received frames are acknowledged at the latest after t2. Must be shorter than t1 |
| Idle Test Interval (t3) | 20s | A test frame is sent when nothing has been received for t3 |
| Send Window (k) | 12 | Maximum unacknowledged frames MaestroHub sends |
| Acknowledge After (w) | 8 | Received frames are acknowledged at the latest after w frames. Must not exceed k |
5. Security: TLS (IEC 62351-3)
Turn on Enable TLS and, usually, set the port to 19998.
- CA Certificate: the CA that signed the outstation's certificate. Leave it empty to use the host's system roots.
- Client Certificate / Client Private Key: MaestroHub's certificate for mutual authentication. Most utilities require one. Both are stored encrypted.
- Server Name: the name expected in the outstation's certificate. It defaults to the address.
- Skip Certificate Verification: accepts any certificate. Use it only while commissioning.
TLS 1.2 is the minimum. MaestroHub accepts a renegotiation started by the outstation but cannot start one itself, so it covers the IEC 62351-3 transport profile without claiming full conformance.
If TLS fields are filled in while Enable TLS is off, the connection is refused rather than silently connecting without TLS.
Testing the Connection
Click Test Connection at the bottom of the form to try the current settings before saving. Once the connection runs, its health probe sends an IEC 104 test frame and reports the round trip; a test frame the outstation does not answer drops the session, and the connection reconnects.
Function Builder
Creating IEC 104 Functions
After the connection is saved:
- Open the connection and navigate to the Functions tab
- Click New Function to open the function type selection dialog
- Choose Monitor Points, Read Points, Interrogate, Send Command, or Synchronise Clock
- Fill the Basic tab (name, description, labels) and the Configuration tab (operation-specific parameters)
- Use the Test button to run the function against the live outstation before saving
Monitor Points (iec104.monitor)
Purpose: Starts a pipeline for each point the outstation reports. This function type is a pipeline trigger: see Pipeline Integration and the IEC 104 Trigger node.
| Parameter | Meaning |
|---|---|
| Information Object Addresses | Addresses and ranges to watch, e.g. 1001, 2000-2999. Empty = every point |
| Include Interrogation Responses | On (default): points that arrive as interrogation responses also fire the trigger. Off: only spontaneous and periodic changes do |
Each event's payload:
{
"commonAddress": 1,
"ioa": 1001,
"type": "M_DP_TB_1",
"value": 2,
"detail": { "state": "on" },
"quality": "good",
"flags": { "invalid": false, "notTopical": false, "substituted": false, "blocked": false, "overflow": false, "timeInvalid": false },
"cause": "spontaneous",
"sourceTimestamp": "2026-09-30T10:14:03.221Z",
"serverTimestamp": "2026-09-30T10:14:03.240Z"
}
Every point has the same top-level keys, whatever its type; what only some types carry sits in detail.
sourceTimestampis the device's own timestamp, in UTC. It isnullfor types that carry none, and when the device marked its time tag invalid (thenflags.timeInvalidistrue).serverTimestampis when MaestroHub received the point.qualityis the platform's band:badwhen the device marked the value invalid;uncertainwhen it is blocked, substituted, not topical, has overflowed, or is a counter with carry or adjustment; otherwisegood. The individual flags stay inflags.
When the link to the outstation drops, the trigger fires once per outage with quality bad and the cause under error; see the IEC 104 Trigger node.
How value is written depends on the type:
| Types | value |
|---|---|
Single point (M_SP_*) | true / false |
Double point (M_DP_*) | 0–3; detail.state is intermediate, off, on or faulty |
Step position (M_ST_*) | -64–63; detail.transient |
Bitstring (M_BO_*) | 32-bit unsigned number |
Normalized (M_ME_NA_1, M_ME_TD_1, M_ME_ND_1) | -1.0 to just under 1.0 |
Scaled (M_ME_NB_1, M_ME_TE_1) | whole number, -32768–32767 |
Short float (M_ME_NC_1, M_ME_TF_1) | number |
Integrated totals (M_IT_*) | whole number; detail.counterSequence, detail.carry, detail.adjusted |
Types this connector does not decode (for example protection events, types 38–40) are skipped. The connection log names each such type once.
Read Points (iec104.read)
Purpose: Returns the latest value of each listed point, for example 1001-1004, 2001 (at most 10,000 addresses). Each entry is the payload above plus status: "ok" and ageMs, the time since the point was received. A point the outstation has not reported since the connection came up is returned as { "ioa": 1003, "status": "noValueYet" }, never as 0.
The process image starts empty on every new connection, so a read never returns a value from a link that has since dropped.
Interrogate (iec104.interrogate)
Purpose: Asks the outstation for a snapshot and returns every point it sends until it reports the interrogation finished.
| Parameter | Meaning |
|---|---|
| Kind | station = process values; counter = integrated totals |
| Group | 0 = all. Station groups are 1–16; counter groups are 1–4 |
| Timeout | Bound on the whole interrogation (default 30m) |
The interrogation also updates the process image and fires any matching Monitor Points triggers.
Send Command (iec104.command)
Purpose: Operates one information object and waits for the outstation's confirmation.
| Parameter | Meaning |
|---|---|
| Command Type | single (C_SC), double (C_DC), regulatingStep (C_RC), setpointNormalized (C_SE_NA), setpointScaled (C_SE_NB), setpointFloat (C_SE_NC), bitstring (C_BO) |
| Information Object Address | The object to operate |
| Value | single/double: on or off. regulatingStep: higher or lower. setpointNormalized: -1 to just under 1. setpointScaled: -32768 to 32767. setpointFloat: a number. bitstring: a 32-bit number, decimal or 0x hex |
| Select Before Operate | On (default): select first, execute only when the selection is confirmed. Bitstring commands have no select step, so for them it has no effect |
| Qualifier | single/double/regulatingStep: 0 = outstation default, 1 = short pulse, 2 = long pulse, 3 = persistent. Set-points: the QL value. Bitstring commands carry no qualifier: leave 0 |
| Time Tag | Send the time-tagged variant (C_xx_TA_1) |
| Wait for Termination | Also wait for the outstation to report the command finished. Many outstations send none |
Every parameter is checked before anything is sent; a bad value never reaches the outstation.
If the outstation does not confirm it within t1, or the timeout ends the wait, the outcome is unknown: the outstation may have acted. MaestroHub then reports command outcome unknown and never sends it again on its own, not by the connector and not by a pipeline's Retry on Fail or ForEach retry. A refused command is reported as refused and is not retried either. Commands are never buffered for later delivery, and a pipeline started by a late (replayed) value does not execute them unless the node allows late input.
Synchronise Clock (iec104.clockSync)
Purpose: Sends the current time, written in the device time zone, and waits for the confirmation. The connection also does this on every connect unless Synchronise Clock on Connect is off.
Pipeline Integration
Use the IEC 104 functions you configure here as nodes inside the Pipeline Designer. Read Points, Interrogate, Send Command and Synchronise Clock are exposed as matching connector nodes, and Monitor Points functions drive the IEC 104 trigger node:
- IEC 104 Read Points (
connected.iec104.read) — executes aniec104.readfunction - IEC 104 Interrogate (
connected.iec104.interrogate) — executes aniec104.interrogatefunction - IEC 104 Send Command (
connected.iec104.command) — executes aniec104.commandfunction - IEC 104 Synchronise Clock (
connected.iec104.clockSync) — executes aniec104.clockSyncfunction - IEC 104 Trigger (
trigger.iec104) — starts a pipeline for each point aniec104.monitorfunction matches
For node-level details (output structure, execution settings), see the IEC 60870-5-104 Nodes and IEC 104 Trigger pages.
For orchestration strategies that mix IEC 104 with other data sources, see the Connector Nodes page.
Common Use Cases
Substation Telemetry to a Historian or UNS
Author a Monitor Points function over the measured-value range (for example 2000-2999), then use the IEC 104 Trigger node to route every reported point to a historian, MQTT topic or the Unified Namespace. Each event carries the platform quality band and the device timestamp, so a UNS Publish node stores what the outstation said, not just the value.
Breaker and Alarm Events
Watch the single- and double-point addresses with Include Interrogation Responses off, so the pipeline fires only on spontaneous changes: a breaker opening, a protection alarm, a door contact. The device's own time-tagged timestamp (sourceTimestamp) orders events correctly even when they arrive in a burst.
Energy Metering
Read integrated totals with a counter Interrogate driven by a Schedule trigger, for example every 15 minutes, and forward the counter values with their counterSequence, carry and adjusted detail to billing or reporting.
Supervised Switching and Set-Points
Receive a switching order or set-point from an upstream system or operator UI, validate it with a Condition node, then issue a Send Command with select-before-operate on. Because a command whose outcome is unknown is never re-sent, confirm the device state with a Read Points before trying again.
Troubleshooting
Error Reference
| What you see | Meaning | Retried? |
|---|---|---|
the outstation refused C_IC_NA_1: unknown common address | The outstation rejected the request (also: unknown type, unknown cause, unknown IOA, or a negative confirmation) | No, it will not change on retry |
no activation confirmation within t1 | The request was sent but not confirmed in time | Reads and interrogations: yes. Commands: never (the outstation may have acted) |
... was confirmed but not finished before the timeout (N points received) | The interrogation started but did not finish within the function's timeout | Yes |
| A certificate error on connect | The outstation's certificate does not match the CA or server name | No |
not connected | The connection is not up | Yes, after reconnect |
Connection Issues
| Symptom | Possible Cause | Solution |
|---|---|---|
| No point ever arrives for a station | The Common Address does not match the outstation's | Messages for any other common address are ignored. Set the station address the outstation is configured with. |
| Connection refused with TLS fields filled in | TLS material is set while Enable TLS is off | Turn on Enable TLS, or clear the TLS fields. |
| Device timestamps are hours off | Device Time Zone does not match the outstation's clock | Set the zone the outstation's clock runs in; MaestroHub converts from it to UTC. |
A read returns noValueYet for a point | The outstation has not reported it since the connection came up | Keep Interrogate on Connect on, or run an Interrogate, so the process image is filled. |