MC protocol (Mitsubishi calls it the MELSEC Communication protocol) is how a Mitsubishi PLC talks to the outside world over Ethernet without any extra software running on it. Spall reads it natively, no gateway software on the PLC side, no OPC server in between. This guide covers the PLC-side setup, what MC protocol actually gives you versus what a named CNC API like FANUC’s FOCAS gives you, and what it takes to reach an M700/M800 CNC through the same protocol.
Before you start You’ll need the controller’s IP address, the port its Ethernet module is configured to listen on, and a device address list, which memory addresses (D, M, R, W, and so on) carry the values you want. That last part matters more here than on most protocols in this series, more on why below. You’ll also need an Ethernet drop at the panel, a fixed IP, and the Spall gateway on the same network. The gateway reads only. It never writes to the controller.
1. What MC protocol actually reads
Every other CNC guide in this series describes a protocol with names built in. FOCAS returns “active program” and “spindle load.” MTConnect returns a labeled <Execution> tag. MC protocol doesn’t work that way. It reads and writes raw device memory by address, D100, M50, R200, the same registers the ladder program itself uses. There’s no symbolic tag lookup and no built in meaning attached to any of them.
That’s not a limitation Spall is working around, it’s how MC protocol has worked since it shipped. What it means in practice: before you can read “is the machine running” or “how many parts has it made,” someone has to tell you which device address the ladder program is already using to store that value. That’s usually the machine builder’s PLC documentation, an I/O list, or the ladder program itself opened in GX Works. Budget time for this step. It’s closer to reading a Modbus register map than to plugging in a FOCAS handle.
2. Confirm the Ethernet module’s Open Settings
On the PLC, open the project in GX Works2 or GX Works3, go to Network Parameter > Ethernet/CC IE, and check the Operational Settings and Open Settings for the port Spall will connect through:
- Protocol: TCP
- Open System: MC Protocol
- Communication Method: Binary Code (the common choice) or ASCII Code, either works, but note which one you picked, Spall’s setup asks for it
- Host Station Port No.: whatever’s configured here is the port you’ll enter in Spall. If nothing’s been set, Spall’s own default fallback is port 5007, but the controller’s actual configured port always wins, use what’s on this screen
Write down the frame type your firmware answers to as well, most Q/L series controllers speak the 3E frame, iQ-R controllers commonly use 4E. If you’re not sure, either one is worth trying first, the wrong frame type fails cleanly rather than returning garbage.
3. Confirm the port answers
From a PC on the same network:
nc -vz 192.168.1.30 5007
-> Connection to 192.168.1.30 5007 succeeded!
A refused connection here usually means the port in Spall doesn’t match the Open Settings screen, or the Ethernet module hasn’t been power cycled since the parameter change, Mitsubishi controllers apply network parameter changes on the next PLC reset or power cycle, not live.
4. Add the source in Spall
In Spall, add the machine, choose Mitsubishi (MC protocol) as the source, and enter the controller’s address, port, and frame type:
192.168.1.30:5007, frame 3E, binary
Assign the Spall gateway on that network and save.
5. Add a tag per device address
For every value you want, add a tag with its device address (D100, M50, R200) and a data type, 16 bit or 32 bit integer for most process values, bit for a run or alarm flag packed into an M or X device. This is the step that depends on the address list from Step 1. There’s no shortcut around knowing what the ladder program already put there.
6. Reaching an M700/M800 CNC the same way
An M700 or M800 series CNC carries its own MELSEC compatible sequencer inside the control, the PLC side that handles machine logic, I/O, and interlocks. Mitsubishi’s own documentation for that sequencer describes reading it over the same MC protocol frames covered above. Spall’s driver is protocol level, it doesn’t check whether the memory it’s reading belongs to a Q series PLC or a CNC’s embedded sequencer, the frames and addressing rules are identical either way.
What’s different: unlike FOCAS, there’s no CNC specific API layer here returning “spindle load” by name. You’re reading the sequencer’s device memory directly, the same as any other MC protocol target, which means the address list has to come from your machine builder’s PLC interface documentation for that specific model, not a generic template. If you’re planning to bring an M700/M800 on this way, get that documentation lined up before the pilot call, or send us a photo of the control cabinet and we’ll help figure out what’s reachable.
What Spall does with this data
Every MC protocol tag lands in Spall the same place a fresh Modbus tag does, the Signal inbox, unclassified until someone confirms what it actually means. Once you classify a device as a run signal, part counter, or sensor reading, it feeds availability, downtime, production, and OEE exactly like a native FOCAS or MTConnect feed, the same three factors and the same six big losses any other connection method rolls up into OEE.
One thing worth repeating Spall issues MC protocol read requests only. It never writes a device, a coil, or a parameter back to the controller. The gateway reads on your network and sends what it reads outbound over encrypted MQTT. No inbound port opens on your firewall, no changes to the ladder program, no touching the sequencer’s own logic.
Quick recap
- MC protocol reads raw device memory (D, M, R, W), not named values, get the address list from your machine builder before you start
- Confirm Protocol, Open System, Communication Method, and Host Station Port No. on the Ethernet module’s Open Settings
- Power cycle or reset the PLC after a network parameter change, it doesn’t apply live
- An M700/M800 CNC’s embedded sequencer speaks the same MC protocol frames, same setup, different address list source
- Every tag lands in the Signal inbox unclassified until someone tells Spall what it means
If your machine builder’s documentation is thin, send us a photo of the cabinet and the model number on a pilot call. We’ll tell you what’s realistically reachable before you spend an afternoon hunting through a ladder program.