Point-table-less PLC Device
Intelligent Protocol Detection · Full-plant Data Collection & Networking
A large mold production factory; its welding (spot-welding robots, arc-welding robots) and stamping (200T~2000T) equipment are mostly 10+-year-old legacy PLC-controlled. The original vendors cannot provide a point table, making traditional integration difficult. AIS-G160 is inserted in series between the PLC and HMI to monitor communication packets in real time; through protocol analysis it automatically identifies the register addresses corresponding to parameters displayed on the HMI, completing acquisition — whatever is visible on the HMI can be identified. On site, 45 devices are equipped one by one, achieving full-plant data collection & networking.
45 point-table-less legacy PLCs over a decade old, with no vendor cooperation needed — G160 protocol detection automatically completes full-plant data collection & networking.
Core solution for this case

I. Customer Background
A large mold production factory; welding and stamping equipment are mostly 10+-year-old legacy PLC-controlled, with vendors unable to provide a point table.
- The customer is a large mold production factory; the main equipment is welding equipment (spot-welding robots, arc-welding robots) and stamping equipment (200T, 630T, 800T, 1600T, 2000T), with a large production-line scale and heterogeneous equipment brands.
- A large number of in-plant devices are 10+-year-old legacy equipment, all PLC-controlled, covering Mitsubishi FX2N, FX3U, FX3GA, FX5U, Q06UDEHCPU, L02CPU, L08HCPU, Siemens S7-200 SMART, OMRON CJ1M, CJ2M and other models.
- These PLCs were put into use long ago; most original vendors no longer provide technical support and cannot assist in providing the "point table" (the correspondence between register addresses and parameters), so digital integration has long been stuck at the step of "not knowing where the parameters are."
II. Core Pain Points
No point table and multi-brand heterogeneity make legacy PLC data collection & networking impossible from the very first step.
- No point table, no starting point for integration: Legacy PLCs have no documentation and vendors do not cooperate; the first step of traditional acquisition — "obtain register addresses" — cannot be done, as no one knows which controller and which address hold the parameters.
- Multi-brand heterogeneous PLCs: Different brands and series such as Mitsubishi, Siemens and OMRON use different protocols; per-device custom development is costly and lengthy, and on-site engineers cannot fully cover all of them.
- Broken MES quality traceability: Without parameter acquisition, the production process cannot achieve one-item-one-code quality traceability and quality control; when a quality deviation occurs, it is hard to trace back to the specific equipment and time period.
- No run monitoring for the equipment department: Equipment working status is a black box; faults rely on manual inspection, and downtime losses are hard to locate in time; the equipment department lacks a unified run-monitoring platform.
III. Why Traditional Approaches Fail
Asking vendors for a point table, manual packet-capture reverse engineering, or modifying PLC programs — none of these can be implemented at the scale of 45 legacy devices.
- Ask the vendor for a point table: Most legacy-equipment vendors have discontinued support or will not cooperate; even if they do, the cycle is long and the cost is high, and some equipment cannot even be fully restored by the vendor to its address mapping.
- Manual packet-capture reverse engineering: Analyzing PLC–HMI communication device by device with packet-capture tools and manually reverse-inferring register addresses is labor-intensive and demanding on personnel, making it hard to replicate across 45 devices.
- Modify the PLC / HMI program: This is a controlled change, high-risk and requiring downtime; the customer is unwilling to take this risk for equipment that has been in service for over a decade.
IV. Solution: G160 Protocol Detection + Serial Splitter
Without relying on a point table, use "monitoring + protocol analysis" to automatically identify the register addresses of HMI parameters, completing acquisition.
- Serial splitter connection — parallel and non-intrusive: Insert a splitter module in series between each serial PLC and HMI; G160 is connected in parallel on the communication line, without modifying the original wiring and programs — plug-and-play.
- Real-time communication-packet monitoring: G160 captures the interaction packets between the PLC and HMI in real time, without changing any logic on either side; the original HMI display and operation are completely unaffected.
- Protocol analysis automatically identifies register addresses: Through protocol parsing, it automatically scans and identifies the register addresses corresponding to parameters displayed on the HMI, building a "parameter–address" mapping without any point table.
- HMI-visible means acquirable: Any parameter visible and operable on the HMI can be identified and acquired through this method, completely bypassing the "no point table" roadblock.
- 45 devices equipped one by one for full-plant networking: On site, 45 devices are deployed with G160 + splitter one by one and uniformly uploaded to the platform, achieving full-plant data collection & networking and centralized management.
V. Value Comparison & Implementation Results
Upgrade from "stuck at the point table, unable to acquire parameters" to "monitor-and-acquire, visible-means-acquirable" full-plant data collection & networking.
| Comparison | Traditional Packet Capture / Vendor | G160 Protocol Detection |
|---|---|---|
| Point-table dependency | Requires the vendor or manual reverse engineering; long cycle, high cost | No point table needed; automatically identifies register addresses |
| Implementation difficulty | Per-device capture; labor-intensive, hard to replicate | Splitter in parallel; plug-and-play; 45 units batch-replicable |
| Legacy devices | Vendor non-cooperation; often stuck | Old models such as FX2N are also readable; not limited by the vendor |
| Acquisition completeness | Only partially acquired via manual reverse engineering | All HMI-visible parameters identified; more complete coverage |
| Traceability | No parameters; quality hard to trace | Real-time process-parameter acquisition; MES one-item-one-code traceability |
| O&M mode | Faults by manual inspection; large downtime loss | Remote PLC access within the LAN; remote debugging & O&M |
VI. Why AIS-G160
The two capabilities — "splitter parallel monitoring + protocol-analysis auto-identification" — exactly match all the demands of point-table-less acquisition for legacy PLCs.
- Monitoring without intrusion: The splitter is connected in parallel on the PLC–HMI communication line, with zero modification to the original programs and wiring; 10+-year-old legacy equipment is accessed with zero risk.
- Protocol-analysis auto-identification: Automatically scans the register addresses corresponding to parameters displayed on the HMI, eliminating the point table and vendor cooperation, solving the source problem of "where the parameters are."
- Legacy models also supported: Built-in 500+ industrial-protocol driver library; old models such as Mitsubishi FX2N/FX3U/FX5U, Q series, Siemens S7-200 SMART, OMRON CJ are plug-and-play.
- LAN remote O&M: After deployment, the PLC can be accessed remotely within the LAN, enabling a degree of remote debugging and O&M, reducing on-site travel.
VII. FAQ
High-frequency questions on "point-table-less PLC protocol detection + serial splitter".
Does G160 need to modify the PLC or HMI program?
No. G160 is connected in parallel on the PLC–HMI communication line via a serial splitter module, monitoring both sides' packets in real time, without changing either side's original program and wiring; legacy equipment is accessed with zero risk.
Can parameters be acquired without a point table?
Yes. G160 monitors the communication between the PLC and HMI, and through protocol analysis automatically identifies the register addresses corresponding to parameters displayed on the HMI, completing acquisition without any point table.
Are very old PLC models such as FX2N supported?
Yes. AIS-G160 has a built-in library of 500+ industrial-protocol drivers; old models such as Mitsubishi FX2N/FX3U/FX5U, Q series, Siemens S7-200 SMART, OMRON CJ are verified connectable. See the "Device Compatibility" list on this page for specific models.
Does the parallel splitter affect the HMI's original display and operation?
No. The splitter module is only connected in parallel on the original communication line for monitoring; the original interaction between the PLC and HMI is completely unchanged; HMI display and operation are unaffected.
Which PLC brands are supported?
The PLC-controlled equipment in this case covers mainstream brands (Mitsubishi, Siemens, OMRON, etc.), all verified supported by AIS-G160. See the "Device Compatibility" list on this page for specific models.
VIII. PLC (Programmable Logic Controller) Brands & Models Supported by G160
This case centers on G160 connecting to legacy PLC-controlled equipment. AIS-G160 has a built-in library of 500+ industrial-device protocol drivers. The following are mainstream PLC brands and models verified for data acquisition (some models require on-site interface confirmation), serving as a basis for solution selection and field verification.
| Manufacturer / Brand | Typical Series & Models | Communication | Protocol / Driver |
|---|---|---|---|
| Siemens | S7-200 (PPI), S7-300/400 (MPI), S7-200 Smart, S7-1200, S7-1500, LOGO! | Serial / Ethernet | S7 PPI, MPI, S7comm, Modbus TCP |
| Mitsubishi | FX0/FX1/FX2, FX3U/3G, Q series (Q00J/Q00/Q02/Q02H/Q06H/Q12H/Q25H, QnU Q00U~Q26U, QnA/A series), FX3U-ENET, FX5U, QJ71E71 | Serial / Ethernet | Mitsubishi MC, MELSEC, SLMP |
| Rockwell AB | Micro800 | Ethernet | EtherNet/IP |
| LS Electric | XGT, XGB, XBC-DN32U | Serial / Ethernet | Proprietary protocol |
| Modbus (Modicon) | Standard Modbus devices | Serial / Ethernet | Modbus RTU / ASCII / TCP / RTU over TCP |
| Schneider | Full range | Serial / Ethernet | Modbus RTU / TCP |
| HollySys | LE/LK220, LK210 | Serial / Ethernet | Modbus RTU |
| THINGET (Xinje) | XD/XL, XC | Serial / Ethernet | Modbus TCP |
| Inovance | H1U/H2U, H3U, H5U | Serial / Ethernet | Modbus |
| OMRON | CJ/CS, CV, CP | Serial / Ethernet | OMRON FINS, Ethernet TCP |
| FATEK | Full range | Serial / Ethernet | Proprietary protocol |
| Delta | DVP, AS228T | Serial / Ethernet | Modbus RTU / TCP |
| Panasonic | FPX, FP | Serial / Ethernet | MEWTOCOL_COM |
| Haiwell | Full range | Serial | Modbus RTU / ASCII |
| Kewei | LP series | Serial | Modbus RTU / proprietary protocol |
| OPC UA | Software / devices supporting OPC UA | Ethernet | OPC UA |
Related Scenarios & Products
SMT / Electronics Manufacturing
Equipment status, parameters, fault & event alarm-log parsing acquisition
→ View Scenario