Overview
CoLa-B (Command Language Binary) is the binary variant of SICK AG's CoLa command protocol, part of the SOPAS device-communication framework used by SICK industrial sensors such as LiDAR/laser scanners, radar sensors and other detection devices. It runs over TCP, typically on port 2112. On some devices (e.g. SICK RMS radar sensors) this port defaults to the ASCII variant CoLa-A and can be switched to CoLa-B, while port 2111 carries CoLa-A. Both are vendor defaults, not IANA assignments: IANA registers 2111 to dsatp and 2112 to idonix-metanet. CoLa-B follows a client-server model: a host (PLC, PC, or the SOPAS ET configuration tool) sends command telegrams to the sensor to read and write variables, invoke methods, and subscribe to events such as scan-data streams.
Every CoLa-B telegram begins with a fixed 4-byte start sequence 02 02 02 02, followed by a 4-byte big-endian length field, the payload, and a 1-byte XOR checksum over the payload bytes. The payload opens with a 3-byte ASCII command type: sRN/sRI (read by name/index), sWN (write by name), sMN (method), sEN (event), with matching replies sRA, sWA, sAN/sMA, sEA. The variable or method is addressed either by name (e.g. DeviceIdent) or by a 2-byte index. A DeviceIdent read returns length-prefixed ASCII strings for the device name and firmware version (e.g. ML20 / 1.110), and related variables expose the serial number and order number. CoLa-B traffic is sent in cleartext. Write and method access is gated by a SetAccessMode login that sends a user level and a password hash, with no transport encryption. The newer CoLa-2 variant (port 2122) uses a different session-based framing.
Protocol Stacks
------------------------------------
| Sensor/Host Application | <= Client (e.g., PLC, PC, SOPAS ET software)
|------------------------------------|
| CoLa-B Telegrams | <= Binary command/data framing (SOPAS commands)
|------------------------------------|
| TCP | <= Reliable, connection-oriented transport
|------------------------------------|
| TCP/IP |
------------------------------------
CoLa-B Dataframe
technical_information_ml20_en_im0059796.pdf#page=8&zoom=100
| Request by client (PC) |
Response by server (ML20) |
Command |
|---|---|---|
| sRI{SVIdx} | sRA{SVIdx}{variable value} | Read variable identified by index SVIdx |
| sWI{SVIdx} | sWA{SVIdx} | Write variable identified by index SVIdx |
| sMI{MIdx}{parameters} | sMA{MIdx}{return values} | Invoke method identified by index MIdx |
| sFA{error code} | Alternatively, the device can respond to every command with an error code. |
Request Frame
| Byte Index | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 |
| Content (as hex-Value) |
02 | 02 | 02 | 02 | 00 | 00 | 00 | 05 | 73 | 52 | 49 | 00 | 04 | 6c |
| Description | STx framing start |
Length = 5 bytes Length of CoLa-B data (without checksum byte) |
„sRI“ ASCII-command read Variable |
Var.-Idx = 4 | Checksum = 6c | |||||||||
| Layer | CoLa framing start | CoLa-B command Valid indices see following chapters. |
CoLa framing end | |||||||||||
Response Frame
| Byte Index | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 |
| Content (as hex-Value) |
02 | 02 | 02 | 02 | 00 | 00 | 00 | 15 | 73 | 52 | 41 | 00 | 04 | 00 | 0e | 44 | 35 |
| Description | STx Framing Start |
Length = 21 bytes Length of CoLa-B data (without checksum byte) |
„sRA“ ASCII-answer read acknowledge |
Var.-Idx = 4 | Flexstring-length = 14 | ||||||||||||
| Layer | CoLa framing start | CoLa-B command Valid indices see following chapters. |
CoLa-B value | ||||||||||||||
| Byte Index | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 |
| Content (as hex-Value) |
2e | 31 | 33 | 2e | 30 | 30 | 38 | 2e | 32 | 37 | 32 | 32 | 0a |
| Description | Variable content, here: Flexstring, ascii: „D5.13.008.2722“ |
Checksum = 0a | |||||||||||
| Layer | CoLa-B value (continued) | CoLa framing end | |||||||||||
checksum = XOR all bytes 9 to 13
CoLa-A Dataframe
telegram_listing_nav210_en_im0084703.pdf#page=5&zoom=100,97,700
| Byte index | frame start | Command Type | Command | Parameter | frame end |
| In ASCII | <STX> | sMN | SetAccessMode | 3 F4724744 | <ETX> |
| In Hex | 02 | same | same | same | 03 |
There has to be a space in between the command and the parameters and also in between each parameter.
In HEX the command start with 02 and ends with 03. The spaces are marked as 20. Single numbers that are converted to ASCII always get a 3 in front.
below two are the hex and ascii format equivalent
<STX>sMN SetAccessMode 3 F4724744<ETX>
02 73 4D 4E 20 53 65 74 41 63 63 65 73 73 4D 6F 64 65 20 33 20 46 34 37 32 34 37 34 34 03
Known Command Type/Command
| Description | Value ASCII | Value Hex | Request/Response |
|---|---|---|---|
| Read by name | sRN | 73 52 4E | request |
| Write by name | sWN | 73 57 4E | request |
| Method | sMN | 73 4D 4E | request |
| Read by name | sRA | 73 52 41 | response |
| Method | sAN | 73 41 4E | response |
Telegram Example
| Read Variable: | ||||
| sRI 0 | ||||
| Telegram Part | Telegram | Type | Length [Byte] | Description |
| Command Type | sRI | String | 3 | Read SOPAS Variable by Name |
| Command | 0 | String | 1 | Unique Identification of device |
| Read Variable Response: | ||||
| sRA 0 <Name> <Version> | ||||
| Telegram Part | Telegram | Type | Length [Byte] | Description |
| Command Type | sRA | String | 3 | SOPAS Variable Read Acknowledge |
| Command | 0 | String | 1 | Unique Identification of device |
| Variable Data 1 | Name | FlexString | 4 | |
| Variable Data 2 | Version | FlexString | 5 | |
CoLa-B (DeviceIdent)
Read Variable: 02 02 02 02 00 00 00 05 73 52 49 00 00 68 ········sRI··h
Read Variable Response: 02 02 02 02 00 00 00 12 73 52 41 00 00 00 04 4D ········sRA····M
4C 32 30 00 05 31 2E 31 31 30 4D L20··1.110M
CoLa-A (DeviceIdent)
Read Variable: 02 02 02 02 00 00 00 0f 73 52 4E 20 44 65 76 69 .......-sRN Devi
63 65 49 64 65 6E 25
Read Variable Response: 02 02 02 02 00 00 00 2d 73 52 41 20 44 65 76 69 .......-sRA Devi
63 65 49 64 65 6e 74 20 00 0f 54 72 69 53 70 65 ceIdent ..TriSpe
63 74 6f 72 20 31 30 36 30 00 0a 34 2e 33 2e 31 ctor 1060..4.3.1
2e 32 34 32 52 55 .242RU
Client / Server Script
Reconstruct from TCP payload. For instance
0000 02 02 02 02 00 00 00 2d 73 52 41 20 44 65 76 69 .......-sRA Devi
0010 63 65 49 64 65 6e 74 20 00 0f 54 72 69 53 70 65 ceIdent ..TriSpe
0020 63 74 6f 72 20 31 30 36 30 00 0a 34 2e 33 2e 31 ctor 1060..4.3.1
0030 2e 32 34 32 52 55 .242RU
The scripts below extract TCP payload, save to "payloads.hex", iterate through to next line on each response.
tshark -r sick_cola-b_evaluated.pcap -Y "tcp.srcport == 2112" -T fields -e tcp.payload > payloads.hex
PORT=2112
FILE=payloads.hex
while read line; do
echo "Serving: $line"
echo -n "$line" | xxd -r -p | nc -l $PORT
done < "$FILE"
while echo -n "0202020200000005735249000068" | xxd -r -p | nc -w 2 10.119.24.84 2112 | xxd -p; do :; done