From 04e50120988d7c6f52aba75c658c8e975e8db46d Mon Sep 17 00:00:00 2001 From: Simone Bortolin Date: Sat, 10 Oct 2026 00:11:01 +0200 Subject: [PATCH 1/3] Update the Realtek pages with the RTL960x repository info - Luna SDK partial: OMCI MEs to check, diag commands (flows, L2 table, bandwidth), OMCC_VER, OMCI_TM_OPT, VEIP slot ID, identity values, PON/VLAN modes, factory reset and a generic firmware modding procedure (transfer, unsquashfs/mksquashfs, flashing the inactive image, repacking the upgrade tar, emulator) - ODI DFP-34X/34G-2C2 (Realtek): SFU/HGU firmware table, default values, MAC_KEY generation, fix scripts, UART pins, slow upload - V-SOL V2801F: fix the recommended firmware (240614), VS_AUTH_KEY and reboot loop fix - T&W TWCGPON657: telnet enabling, firmware list, V2801F flashing - UFiber UF-Instant: credentials, full partitions, UART - GPON chipset page: RTL960x family and sticks, Anime4000 link - GPON auth: fake O5 remedies and O2-O5 loop - MikroTik/TP-Link: 2.5G settings and GPON upstream flooding - Technicolor AFM0002/AFM0003: use the shared modding procedure Closes #178 Co-Authored-By: Claude Opus 5.5 --- gpon/gpon-auth.md | 22 +- gpon/ont.md | 30 +- ont/_partials/ont-luna-sdk-useful-commands.md | 284 ++++++++++++++++++ ont/ont-odi-realtek-dfp-34g-2c2.md | 17 ++ ont/ont-odi-realtek-dfp-34x-2c2.md | 94 +++++- ont/ont-t-w-twcgpon657.md | 48 ++- ont/ont-technicolor-afm0002.md | 39 +-- ont/ont-technicolor-afm0003.md | 60 +--- ont/ont-ufiber-uf-instant.md | 28 +- ont/ont-vsol-v2801f.md | 71 ++++- sfp-cage/mikrotik.md | 43 +++ sfp-cage/tp-link.md | 21 ++ 12 files changed, 653 insertions(+), 104 deletions(-) diff --git a/gpon/gpon-auth.md b/gpon/gpon-auth.md index ec3f063d..738d69d5 100644 --- a/gpon/gpon-auth.md +++ b/gpon/gpon-auth.md @@ -43,8 +43,28 @@ This happens when the OLT detects that the ONT is `drunk`, so it tries to update This is most likely to reduce logs from misconfigured ONTs and to be able to send updates automatically to ONTs. +The same happens on other OLTs that support any ONU (e.g. Fiberhome, Calix and Nokia): the ONU reaches `O5` even with a wrong serial number or PLOAM password, but the OLT does not send the VLAN configuration (ME 84 and ME 171)[^rtl960x]. To fix it: + +- check again the serial number and the PLOAM password; +- clone all the identity values of the original ONT: vendor ID, equipment ID, hardware and software versions, OMCC version and, for some OLTs, OUI, hardware serial number and MAC address; +- some ISPs require vendor specific MEs (350-399), which a stick may not be able to emulate. + +On the Realtek based sticks, `OMCI_FAKE_OK` (reply OK to every OMCI message) and `OMCI_OLT_MODE` (vendor compatibility mode) can help, see for example the [ODI DFP-34X-2C2](/ont-odi-realtek-dfp-34x-2c2#gpon-omci-settings). Some ISPs keep the OMCI configuration in cache on the OLT: e.g. Chunghwa Telecom (Taiwan) can reset the line from its support. Some ISPs blacklist the PON port after a few failed attempts (e.g. Movistar Chile after 3 attempts), and the reset requires a technician[^anime4000]. + +# `O2`-`O5` loop + +The ONU cycles between `O2` and `O5` without ever staying in `O5`[^rtl960x]: + +- the OLT does not accept the ONU identity, as in the [Fake O5](#fake-o5-status) case, e.g. with some Fiberhome OLTs, or with PLDT (Philippines) when a SFU firmware is used instead of an HGU one; +- the received optical power is too low (e.g. ≤ -23 dBm): clean the connectors and check the RX power again. + +::: danger Warning +If the ONU still does not work after checking all the values, stop: every failed attempt is logged by the OLT, and a misbehaving ONU can disrupt the whole PON tree, with service suspension or penalties from the ISP. +::: +
[^huawei]: *The Process for an ONU to go Online* https://forum.huawei.com/enterprise/en/the-process-for-an-onu-to-go-online-gpon-technical-posts-12/thread/462895-100181 [^standardgpon]: *G.984.3: Gigabit-capable passive optical networks (GPON): Transmission convergence layer specification* https://www.itu.int/rec/T-REC-G.984.3 -[^anime4000]: *`O5` No Internet* https://github.com/Anime4000/RTL960x/blob/main/Docs/fakeO5.md \ No newline at end of file +[^anime4000]: *`O5` No Internet* https://github.com/Anime4000/RTL960x/blob/main/Docs/fakeO5.md +[^rtl960x]: *Hacking RTL960x: Fake O5 State and O2-O5 Loop*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x \ No newline at end of file diff --git a/gpon/ont.md b/gpon/ont.md index a05f7a00..de97d75a 100644 --- a/gpon/ont.md +++ b/gpon/ont.md @@ -75,7 +75,33 @@ HSGMII chipsets are relatively recent, they became more common starting in 2020, The Realtek xPON ICs (RTL9601, RTL9602, RTL9603, RTL9607 and the RTL8290 laser driver) support GPON, EPON and Active Fiber mode, and are distributed in Europe by [MEV Elektronik](https://shop.mev-elektronik.com/product/xpon-ics/). -Community guides for the RTL960x based sticks and ONTs (OMCI cloning, flash variables, 4-port emulation, firmware and key generators): [Hacking RTL960x](https://github.com/fernandothx/Hacking-RTL960x-your-ISP-Fiber). +The RTL960x family[^rtl960x]: + +| Chipset | Architecture | Type | Notes | +| --------- | ------------ | ------- | ----------------------------------------------------------- | +| RTL9601B | Lexra | SFU | First generation of GPON SFP ONTs, 1G only | +| RTL9601C1 | Lexra | SFU | Second generation of GPON SFP ONTs, 1G and partially 2.5G | +| RTL9601D | Lexra | SFU/HGU | Third generation of GPON SFP ONTs, stable 2.5G | +| RTL9602C | Lexra | SFU/HGU | Only in box ONTs | +| RTL9603C | MIPS | SFU/HGU | All-in-one, 1 core at 900 MHz | +| RTL9607C | MIPS | SFU/HGU | All-in-one, 2 cores at 1.15 GHz, USB and POTS | +| RTL9607DQ | ARM64 | SFU/HGU | All-in-one, 4 cores at 1 GHz, optional 2.5GbE and POTS | +| RTL9607F | ARM64 | SFU/HGU | All-in-one, 2 cores at 1 GHz, optional USB and POTS | + +The most common RTL960x based SFP ONTs: + +| Stick | Chipset | Flash | UNI | 4-port emulation | 2.5G | +| ------------------------------------------------------------ | --------- | ------ | ----------- | ---------------- | ------------------ | +| [V-SOL V2801F](/ont-vsol-v2801f) | RTL9601CI | 8 MB | VEIP & PPTP | ✅ | modded firmware | +| [T&W TWCGPON657](/ont-t-w-twcgpon657) | RTL9601CI | 16 MB | VEIP & PPTP | ✅ (V2801F fw) | modded firmware | +| [UFiber UF-Instant](/ont-ufiber-uf-instant) | RTL9601CI | 16 MB | PPTP | ❌ LAN 1 only | ❌ | +| [ODI DFP-34X-2C2 (Realtek)](/ont-odi-realtek-dfp-34x-2c2) | RTL9601D | 8 MB | VEIP & PPTP | ✅ SFU firmwares | ✅ | +| [Nokia G-010S-Q](/ont-nokia-g-010s-q) | RTL9601CI | 16 MB | PPTP | ❌ | ❌ | +| [LEOX LXT-010S-H](/ont-leox-lxt-010s-h) | RTL9601CI | 128 MB | | | ✅ | + +Community guides for the RTL960x based sticks and ONTs (OMCI cloning, flash variables, 4-port emulation, 2.5G compatibility, firmwares and key generators): [Hacking RTL960x](https://github.com/Anime4000/RTL960x) by Anime4000 and its [forum](https://pururin.moe/viewtopic.php?t=7), and the [Hacking RTL960x your ISP Fiber](https://github.com/fernandothx/Hacking-RTL960x-your-ISP-Fiber) fork. The XGS-PON sticks based on the Realtek/Cortina CA8271x are documented in [CA8271x](https://github.com/YuukiJapanTech/CA8271x). + +The useful commands for the Realtek sticks running the Luna SDK are in each device page, e.g. [ODI DFP-34X-2C2](/ont-odi-realtek-dfp-34x-2c2#gpon-onu-status). ::: warning End Of Life Realtek announced that the RTL9601C and RTL9601CI will be End Of Life at the end of November 2026, and they will not get a replacement. @@ -99,3 +125,5 @@ Playing with ONTs can cause your serial number/PLOAM password to be banned and f ::: tip Tip You can also help us with the content of this site, on each page you will find a button to edit on GitHub. ::: + +[^rtl960x]: *Hacking RTL960x*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x diff --git a/ont/_partials/ont-luna-sdk-useful-commands.md b/ont/_partials/ont-luna-sdk-useful-commands.md index 54577cd3..496aaa54 100644 --- a/ont/_partials/ont-luna-sdk-useful-commands.md +++ b/ont/_partials/ont-luna-sdk-useful-commands.md @@ -28,6 +28,77 @@ diag gpon get onu-state # omcicli mib get MIB_IDX ``` +The most useful MEs to check the provisioning received from the OLT[^rtl960x_omci]: + +| ME | Name | Notes | +| --- | -------------------------------- | ------------------------------------------------------------------------------- | +| 6 | Circuit pack | Type and number of ports emulated by the stick | +| 7 | Software image | Software versions reported to the OLT | +| 11 | PPTP Ethernet UNI | Physical LAN ports, with the `AdminState` set by the OLT | +| 84 | VLAN tagging filter data | VLANs sent to the stick by the OLT, e.g. the internet VLAN to use on the router | +| 131 | OLT-G | OLT vendor ID | +| 171 | Extended VLAN tagging operation | VLAN translation rules, which VLAN goes to which LAN port | +| 256 | ONU-G | Vendor ID, version and serial number | +| 257 | ONU2-G | Equipment ID, OMCC version | +| 262 | T-CONT | | +| 263 | ANI-G | PON side | +| 264 | UNI-G | LAN side | +| 277 | Priority queue | | +| 309 | Multicast operations profile | VLANs used for the IPTV multicast traffic | +| 329 | Virtual Ethernet interface point | VEIP, used for VoIP, TR-069 or the router mode of the HGUs | + +To dump all the MEs at once: + +```sh +for ME in 2 5 6 7 11 24 45 47 49 50 52 78 79 83 84 89 130 131 133 134 136 137 148 157 158 171 240 244 245 248 249 250 253 255 256 257 262 263 264 266 267 268 272 273 274 277 278 280 281 284 287 296 298 307 308 309 310 311 312 321 322 329 330 334 340 341 65282 65294 65408 65527 65528 65529 65530 65531; do echo "MIB: $ME"; omcicli mib get $ME; done +``` + +See [PPTP and VEIP](/gpon/pptp_veip) for the meaning of the UNIs and [OMCI Wireshark](/tools/omci-wireshark) to decode the full OMCI log. + +## Getting the GEM ports and the flows + +```sh +# diag gpon show us-flow +============================================================ + GPON ONU MAC U/S Flow Status +Flow ID | GEM Port | Type | TCont + 0 | 263 | ETH | 0 + 1 | 264 | ETH | 1 + 64 | 2 | OMCI | 16 +============================================================ +# diag gpon show ds-flow +``` + +## Getting the VLANs bridged by the stick + +The L2 table shows the learned MAC addresses with their VLAN (`Vid`): if the internet traffic arrives untagged on the router, this is a way to find which VLAN is used on the PON side[^rtl960x_diag]. + +```sh +# diag l2-table get entry address valid +``` + +On the RTL9601D (e.g. ODI DFP-34X-2C2) the `valid` parameter is not available, the table has to be read entry by entry: + +```sh +i=0 +while [ $i -lt 2047 ]; do + diag l2-table get entry address $i | grep -q "LUT" && diag l2-table get entry address $i + i=$((i+1)) +done +``` + +## Getting the port status and the bandwidth limits + +```sh +# diag port get status port all +Port Status Speed Duplex TX_FC RX_FC +---- ------ ----- ------ ----- ----- +0 Up 1000M Full Dis Dis +2 Up 1000M Full Dis Dis +# diag bandwidth get egress port all +# diag bandwidth get ingress port all +``` + {% if include.speedLan %} @@ -57,6 +128,18 @@ LAN_SDS_MODE=0 | 7 | `<4>change mode to 7(SGMII Force)` | `TP` | 1GbaseT with auto-neg off |{% endif %}{% if include.speedLan contains '8' %} | 8 | `<4>change mode to 8(HISGMII Force)` | `TP` | 2500baseT with auto-neg off |{% endif %} +{% if include.speedLanDefault %} +The default value on this stick is `{{ include.speedLanDefault }}`. +{% endif %} + +{% if include.speedLan contains '6' %} +The 2.5G modes are `4` (HiSGMII PHY), `5` (HiSGMII MAC) and `6` (2500BASE-X): most of the hosts that support 2.5G work with the mode `6` and the port forced to 2500BASE-X, see the [SFP standard](/sfp/sfp-standard) page and the [2.5G compatibility list](https://github.com/Anime4000/RTL960x/blob/main/Docs/2.5Gb.md)[^rtl960x_25g]. +{% endif %} + +::: warning +A `LAN_SDS_MODE` not supported by the host makes the stick unreachable: the only way to restore it is the serial console. +::: + {% endif %} # GPON/OMCI settings @@ -88,6 +171,10 @@ GPON_PLOAM_PASSWD=AAAAAAAAAA The PLOAM password is stored in HEX format, without any 0x or separators ::: +{% if include.rtl960x %} +From the firmware `220304` onwards only the HEX format is accepted via telnet/SSH (`GPON_PLOAM_FORMAT` set to `0`): use the Web GUI to enter it in ASCII[^rtl960x_setup]. +{% endif %} + ```sh # {{ include.flash }} get GPON_PLOAM_PASSWD GPON_PLOAM_PASSWD=41414141414141414141 @@ -212,6 +299,84 @@ OMCI_FAKE_OK=0 # {{ include.flash }} set OMCI_FAKE_OK 1 ``` +{% if include.rtl960x %} +## Getting/Setting the OMCC version + +The OMCC version (ME 257) advertised to the OLT, e.g. `128` (`0x80`) or `160` (`0xA0`): + +```sh +# {{ include.flash }} get OMCC_VER +OMCC_VER=128 +# {{ include.flash }} set OMCC_VER 160 +``` + +## Getting/Setting the OMCI traffic management option + +How the OLT manages the upstream bandwidth (ME 256 `Traffic management option`): if the upload speed is lower than expected, try the other values[^rtl960x_slow]. + +```sh +# {{ include.flash }} get OMCI_TM_OPT +OMCI_TM_OPT=2 +# {{ include.flash }} set OMCI_TM_OPT 0 +``` + +| Value | Mode | +| ----- | ---------------------------- | +| 0 | Priority controlled | +| 1 | Rate controlled | +| 2 | Priority and rate controlled | + +## Getting/Setting the VEIP slot ID + +Some OLTs expect the VEIP (ME 329) with the same Entity ID of the original ONT, usually `0x0e01`. The slot ID is the most significant byte of the Entity ID (`0x0e` = `14`), and it is applied only if the bit `0x100` (`cf_apply_customized_veip_slot_id`) of `OMCI_CUSTOM_ME` is set: the default value on the SFU firmwares is `65536` (`0x10000`), so it must be set to `65792` (`0x10100`)[^rtl960x_veip]. + +```sh +# {{ include.flash }} set OMCI_VEIP_SLOT_ID 14 +# {{ include.flash }} set OMCI_CUSTOM_ME 65792 +``` + +The other feature bits of `OMCI_CUSTOM_ME` have been documented by [@rajkosto](https://gist.github.com/rajkosto/79034a1f7b3de3f40edf50ffbd8396b0). + +## Getting/Setting the other identity values + +Some OLTs (mostly the ones that accept any ONU, e.g. Fiberhome and Calix) also check other values of the original ONT[^rtl960x_setup]: + +| Variable | Description | Example | +| ---------------------- | -------------------------------------------------------------- | ------------------------------ | +| `OUI` | Organizationally Unique Identifier of the original MAC address | `875773` | +| `HW_SERIAL_NO` | Hardware serial number (not the GPON serial number) | `UONHUWH12341234123` | +| `ELAN_MAC_ADDR` | MAC address of the stick, required by EPON | `781735000000` | +| `HW_CWMP_MANUFACTURER` | TR-069 manufacturer | `Huawei Technologies Co., Ltd` | +| `HW_CWMP_PRODUCTCLASS` | TR-069 product class | `HG8240H` | +| `LOID`, `LOID_PASSWD` | Logical ONU ID and password, used by EPON and some GPON ISPs | | + +```sh +# {{ include.flash }} set OUI 875773 +# {{ include.flash }} set HW_CWMP_MANUFACTURER 'Huawei Technologies Co., Ltd' +``` + +{% if include.macKey == 'odi' %} +::: warning +Changing `ELAN_MAC_ADDR` requires a new `MAC_KEY`, see [MAC key](/ont-odi-realtek-dfp-34x-2c2#mac-key). +::: +{% elsif include.macKey == 'vsol' %} +::: warning +Changing `ELAN_MAC_ADDR` or `HW_HWVER` requires a new `VS_AUTH_KEY`, see [VS_AUTH_KEY](/ont-vsol-v2801f#vs-auth-key). +::: +{% endif %} + +## Getting/Setting the PON mode, device type and VLAN mode + +| Variable | Values | +| ---------------- | -------------------------------------------------------------------------------------------------- | +| `PON_MODE` | `1` GPON (default), `2` EPON, `3` Ethernet (the PON side works as an Ethernet fiber transceiver) | +| `DEVICE_TYPE` | `0` bridge, `1` router, `2` hybrid | +| `VLAN_CFG_TYPE` | `0` auto (from OMCI), `1` manual (uses `VLAN_MANU_MODE`) | +| `VLAN_MANU_MODE` | `0` transparent, `1` tagging (Q-in-Q, the outer tag is removed), `2` remote access, `3` special case | + +Every `{{ include.flash }} set` requires a reboot to be applied[^rtl960x_flash]. +{% endif %} + # Advanced settings ## Setting management IP @@ -248,7 +413,126 @@ sw_version1=V1_7_8_210412 ``` ## Booting to a different image + +The firmware upgrade always writes the inactive image, so it is possible to go back to the previous firmware[^rtl960x_fw]: + ```sh # nv setenv sw_commit 0|1 +# nv setenv sw_active 0|1 # reboot ``` +{% if include.rtl960x %} + +## Factory reset + +::: danger +Make a backup of the `env`, `env2` and `config` partitions (see this [guide](https://github.com/Anime4000/RTL960x/discussions/28)) and write down `ELAN_MAC_ADDR` and the license key ({% if include.macKey == 'vsol' %}`VS_AUTH_KEY`{% else %}`MAC_KEY`{% endif %}) before the reset: after it the stick uses the default MAC address, and a wrong key prevents the authentication to the OLT. +::: + +The configuration is stored in the `config` partition (`/dev/mtd3`), erasing it restores the default settings[^rtl960x_reset]: + +```sh +# flash_eraseall /dev/mtd3 +# reboot +``` + +If the stick reboots in a loop, the [reset-config-partition.sh](https://github.com/Anime4000/RTL960x/blob/main/Tools/reset/reset-config-partition.sh) script keeps trying until it can erase the partition via SSH. +{% endif %} + +# Modifying the firmware + +::: danger Warning +A wrong rootfs makes the image unbootable: always flash the **inactive** image, so that the stick can still boot the other one, and keep a backup of all the partitions. +::: + +## Transferring files from/to the stick + +Run `md5sum` on the source and on the destination to make sure that the file has not been corrupted. + +Via SSH, from the stick to the PC and vice versa: + +```sh +ssh admin@{{ include.ip | default: "192.168.1.1" }} "cat /dev/mtd5" > mtd5.bin +cat rootfs.new | ssh admin@{{ include.ip | default: "192.168.1.1" }} "cat > /tmp/rootfs.new" +``` + +Via TFTP (a TFTP server must be running on the PC): + +```sh +# tftp +tftp> get rootfs.new +tftp> put +tftp> q +``` + +Via netcat (`nc` on the stick does not exit at the end of the transfer: stop it with `CTRL+C`)[^rtl960x_mod]: + +```sh +# on the stick +nc -l -p 12345 > /tmp/rootfs.new +# on the PC +nc {{ include.ip | default: "192.168.1.1" }} 12345 < rootfs.new +``` + +::: info Info +On Windows run the commands from `cmd` (not PowerShell) and replace `cat` with `type`. +::: + +## Extracting and repacking the rootfs + +The rootfs is a SquashFS (LZMA) image: on the stick it is in `r0` (`/dev/mtd5`) for the image 0 and in `r1` (`/dev/mtd7`) for the image 1, while the kernel is in `k0` (`/dev/mtd4`) and `k1` (`/dev/mtd6`). + +::: danger Warning +Run both commands as root, otherwise the rootfs image might be damaged. +::: + +```sh +# unsquashfs mtd5.bin +# mksquashfs squashfs-root rootfs.new -b 131072 -comp lzma -no-recovery +``` + +The [RTL960x emulator](https://github.com/Anime4000/RTL960x/tree/main/Tools/emulator) runs the extracted firmware in QEMU (`qemu-user-static`) to modify and test it before flashing it: any file in its `custom` folder is copied over `squashfs-root` when leaving the chroot, and the custom startup scripts go in `/etc/init.d/rc35`. + +## Flashing a new rootfs + +Check which image is running (`nv getenv sw_active`): flash `mtd6`/`mtd7` if the image 0 is running, `mtd4`/`mtd5` if the image 1 is running. The following commands flash a new rootfs to the image 1 and boot it: + +```sh +# flash_eraseall /dev/mtd7 +# cat /tmp/rootfs.new > /dev/mtd7 +# nv setenv sw_version1 NEW_SOFTWARE_VERSION +# nv setenv sw_commit 1 +# reboot +``` + +If `cat` fails with `cat: write error: Invalid Argument`, write the image to the block device instead: + +```sh +# flash_eraseall /dev/mtd7 +# cat /tmp/rootfs.new > /dev/mtdblock7 +``` + +## Repacking a firmware upgrade file + +The firmware upgrade files of the ODM firmwares (e.g. V-SOL, T&W, ODI) are a `tar` containing the kernel (`uImage`), the `rootfs`, the `fwu.sh` upgrade script, the `fwu_ver` version file and the `md5.txt` checksums: after replacing the rootfs, update the checksums and repack it, then upload it from the Web GUI firmware upgrade page[^rtl960x_mod]: + +```sh +tar -xf firmware.tar +mv rootfs.new rootfs +md5sum fwu.sh rootfs uImage fwu_ver > md5.txt +tar -cvf ../firmware-mod.tar * +``` + +The [Firmware_Mod](https://github.com/Anime4000/RTL960x/tree/main/Firmware_Mod) folder of the RTL960x repository contains the community patches for the ODI DFP-34X-2C2, V-SOL V2801F and T&W TWCGPON657 (Bootstrap Web GUI, VLAN, speed and software version fixes). + +[^rtl960x_omci]: *OMCI MIB*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/OMCI_CLI.md +[^rtl960x_diag]: *Diag*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/DIAG.md +[^rtl960x_fw]: *Firmware Partition*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/fw_part.md +[^rtl960x_mod]: *Modify firmware*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/Modify_Firmware.md +{% if include.speedLan contains '6' %}[^rtl960x_25g]: *2.5Gb Compatibility*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/2.5Gb.md +{% endif %}{% if include.rtl960x %}[^rtl960x_setup]: *RTL960x SFP xPON ONU Configuration Guide*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/StickSetup.md +[^rtl960x_flash]: *`flash get`, `flash set`*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/FLASH_GETSET_INFO.md +[^rtl960x_slow]: *Slow Upload Speed*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/SlowUploadSpeed.md +[^rtl960x_veip]: *`OMCI_VEIP_SLOT_ID`*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/VEIP.md +[^rtl960x_reset]: *Factory Reset*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/factory_reset.md +{% endif %} diff --git a/ont/ont-odi-realtek-dfp-34g-2c2.md b/ont/ont-odi-realtek-dfp-34g-2c2.md index 47766cfa..215b6e06 100644 --- a/ont/ont-odi-realtek-dfp-34g-2c2.md +++ b/ont/ont-odi-realtek-dfp-34g-2c2.md @@ -39,6 +39,19 @@ ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 -oCiphers=+3des-cbc -oHostKeyAlg The recommended versions are `M114_sfp_ODI_Vlan_220414.tar`, `M114_sfp_ODI_hybrid_220527.tar` or `M114_sfp_ODI_hybrid_220916.tar`, as these have working VLAN translation. +The firmwares are the same of the [ODI Realtek DFP-34X-2C2](/ont-odi-realtek-dfp-34x-2c2#list-of-firmwares-and-files), see that page for the SFU/HGU type of each firmware: switching between a SFU and an HGU firmware requires a [factory reset](#factory-reset) and a new [MAC key](#mac-key). + +## MAC key + +From the firmware `V1.0-220304` onwards, changing `ELAN_MAC_ADDR` requires a matching `MAC_KEY`, the MD5 of `hsgq1.9a` followed by the MAC address in uppercase[^rtl960x_setup]: + +```sh +echo -n "hsgq1.9aFFFFFF000000" | md5sum +46f4ea2e3f18ba3bc1f2671b5f7e1f62 - +flash set ELAN_MAC_ADDR FFFFFF000000 +flash set MAC_KEY 46f4ea2e3f18ba3bc1f2671b5f7e1f62 +``` + ## List of partitions | dev | size | erasesize | name | @@ -79,15 +92,19 @@ ploam: "hex" customSwVersionAlert: "This needs either `OMCI_OLT_MODE` to be set to 3 and firmware version 220530 or 220923 as modded by @stich86 or, if you don't want to replace the installed firmware, set `OMCI_OLT_MODE` value to `21`. This will force the stick to use your own settings from the XML file, but this is a hack and causes sigsegv of `/bin/checkomci`." speedLan: "1234567" omciOLT21: "true" +rtl960x: true +macKey: "odi" --> # Known Bugs - Auto-sensing mode to switch between SGMII/HiSGMII +- Slow upload with the 2.5G modes on some OLTs, see the [DFP-34X-2C2 known bugs](/ont-odi-realtek-dfp-34x-2c2#known-bugs) # Miscellaneous Links - [Hacking RTL960x](https://github.com/Anime4000/RTL960x) +- [RTL960x stick setup guide](https://github.com/Anime4000/RTL960x/blob/main/Docs/StickSetup.md) - [Ditch ONU, use GPON SFP on Business Grade Router, Mikrotik/Ubiquiti/pfSense (Home Networking)](https://forum.lowyat.net/topic/4925452) - [For the new model ODI ZTE DFP-34X-C2C](/ont-odi-zte-dfp-34x-2c2) diff --git a/ont/ont-odi-realtek-dfp-34x-2c2.md b/ont/ont-odi-realtek-dfp-34x-2c2.md index 1e73b465..13aea489 100644 --- a/ont/ont-odi-realtek-dfp-34x-2c2.md +++ b/ont/ont-odi-realtek-dfp-34x-2c2.md @@ -35,8 +35,37 @@ ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 -oCiphers=+3des-cbc -o HostKeyAl +::: warning +The ODI DFP-34X-2C2 has been sold with two different chipsets with the same name: this page is about the Realtek RTL9601D one, the firmwares are not compatible with the [ZTE based one](/ont-odi-zte-dfp-34x-2c2). +::: + +## Default credentials + +Besides `admin`/`admin`, the firmware has some system users[^rtl960x_reset]: `adsl`/`realtek`, `user`/`user` (changed with `flash set USER_PASSWORD`) and `administrator`/`Stel$864` (changed with `flash set E8BDUSER_PASSWORD`). + +## Default values + +| Variable | Value | +| ---------------- | ----------------------- | +| `GPON_SN` | `XPON1234ABCD` | +| `PON_VENDOR_ID` | `HSGQ` | +| `GPON_ONU_MODEL` | `DFP-34X-2C2` | +| `HW_HWVER` | `V2.0` | +| `OMCI_SW_VER1` | `V1.0-220923` | +| `OMCI_SW_VER2` | `V1.0-220304` | +| `OMCC_VER` | `128` | +| `OMCI_OLT_MODE` | `0` | +| `OMCI_FAKE_OK` | `1` | +| `OMCI_TM_OPT` | `2` | +| `OMCI_CUSTOM_ME` | `65536` | +| `LAN_SDS_MODE` | `3` (SGMII MAC) | + +The defaults of the other ONTs that can be useful to clone are in the [configuration table](https://github.com/Anime4000/RTL960x/blob/main/Docs/FlashSetTable.md) and in the [list of stock ONUs](https://github.com/Anime4000/RTL960x/blob/main/Docs/Stock_ONU.md) of the RTL960x repository. + ## List of software versions -- V1.0-220923 (hybrid by @lanseyujie and @stich86) +- V1.0-221209 (hybrid, HSGQ) +- V1.0-220923 (by @lanseyujie, also modded by @stich86) +- V1.0-220916 (hybrid by @lanseyujie) - V1.0-220817 - V1.0-220530 (hybrid by @stich86) - V1.0-220414 (vlan working) @@ -46,7 +75,47 @@ ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 -oCiphers=+3des-cbc -o HostKeyAl ## List of firmwares and files - [Firmware repository by Anime4000](https://github.com/Anime4000/RTL960x/tree/main/Firmware/DFP-34X-2C2) -The recommended versions are `M114_sfp_ODI_hybrid_220527.tar` or `M114_sfp_ODI_hybrid_220916.tar`, as these have working VLAN translation. +The firmwares are either SFU (bridge only) or HGU/IGD (the stick reports itself as a router to the OLT, and can also be used as a router)[^rtl960x_odi_fw]: + +| Firmware | Type | 4-port emulation | Notes | +| -------------------------------- | ---- | ---------------- | ------------------------------------------------------------------------------------------------------------- | +| `M110_sfp_ODI_210702.tar` | HGU | ❌ | `DEVICE_TYPE` is `1` (router) by default | +| `M110_sfp_ODI_220304.tar` | SFU | ✅ | Introduces the `MAC_KEY` | +| `M114_sfp_ODI_Vlan_220414.tar` | SFU | ✅ | | +| `M114_sfp_ODI_hybrid_220527.tar` | HGU | ❌ | | +| `M110_sfp_ODI_220817.tar` | SFU | ✅ | Includes the `fix_speed.sh`, `fix_sw_ver.sh` and `fix_vlan_tag.sh` scripts | +| `M114_sfp_ODI_hybrid_220916.tar` | HGU | ❌ | Provided by [@lanseyujie](https://github.com/Anime4000/RTL960x/issues/24#issuecomment-1297975439) | +| `M110_sfp_ODI_220923.tar` | SFU | ✅ | Provided by [@lanseyujie](https://github.com/Anime4000/RTL960x/issues/24#issuecomment-1297975439) | +| `M114_sfp_ODI_hybrid_221209.tar` | HGU | ❌ | HSGQ, provided by [@physx2494](https://github.com/Anime4000/RTL960x/discussions/148#discussioncomment-5802985) | + +The recommended versions are `M114_sfp_ODI_hybrid_220527.tar` or `M114_sfp_ODI_hybrid_220916.tar`, as these have working VLAN translation. Use an SFU firmware if the original ONT is a bridge, an HGU firmware if the original ONT is a router (some OLTs, e.g. PLDT, loop between `O2` and `O5` with a SFU firmware)[^rtl960x_isp]. + +::: warning +Switching between a SFU and an HGU firmware requires a [factory reset](#factory-reset), and then a new [MAC key](#mac-key) for the MAC address. +::: + +### Fix scripts of the 220817 firmware + +| Script | Description | Activation | +| ----------------- | --------------------------------------------------------------------------- | -------------------------------------------------------------- | +| `fix_speed.sh` | Fixes the slow upload with the 2.5G modes (`LAN_SDS_MODE` `4`, `5` or `6`) | `echo 1 > /etc/config/fix_speed` | +| `fix_sw_ver.sh` | Applies the custom software version (`sw_custom_version0`/`1`) | `OMCI_OLT_MODE` set to `3` | +| `fix_vlan_tag.sh` | VLAN tag fix by @inyourgroove | `echo 1 > /etc/config/fix_vlan` | + +The sources of the scripts are in the [Firmware_Mod](https://github.com/Anime4000/RTL960x/tree/main/Firmware_Mod/DFP-34X-2C2/etc/scripts) folder. The community is working on the *Nijika* firmware, with a Bootstrap Web GUI that also shows the ME 84 and ME 171 received from the OLT and allows to change the VLAN forwarding operation. + +## MAC key + +From the firmware `V1.0-220304` onwards, changing `ELAN_MAC_ADDR` requires a matching `MAC_KEY`, the MD5 of `hsgq1.9a` followed by the MAC address in uppercase[^rtl960x_setup]: + +```sh +echo -n "hsgq1.9aFFFFFF000000" | md5sum +46f4ea2e3f18ba3bc1f2671b5f7e1f62 - +flash set ELAN_MAC_ADDR FFFFFF000000 +flash set MAC_KEY 46f4ea2e3f18ba3bc1f2671b5f7e1f62 +``` + +A key generator by @rajkosto is available [here](https://gist.github.com/rajkosto/29c513b96ea6262d2fb1f965a52ce16f). ## List of partitions @@ -82,22 +151,43 @@ The stick has a TTL 3.3v UART console (configured as 115200 8-N-1) that can be a Some USB TTL adapters label TX and RX pins the other way around: try to swap them if the connection doesn't work. ::: +On the RTL9601D (88 pins) the UART is on the pins 15 (TX) and 16 (RX)[^rtl960x_uart]. To power the stick outside of the host use an SFP breakout board or an SFP connector without cage: the USB TTL adapter can't power it. + # Known Bugs - Auto-sensing mode to switch between SGMII/HiSGMII +- Slow upload with the 2.5G modes on some OLTs, mostly when the original ONT is also Realtek based: try another [`OMCI_TM_OPT`](#getting-setting-the-omci-traffic-management-option), the `fix_speed.sh` script or remove the bandwidth limits at runtime[^rtl960x_slow]: + ```sh + diag port set auto-nego port all ability asy-flow-control + diag bandwidth set egress port all rate 4194296 + diag bandwidth set ingress port all rate 4194296 + ``` +- With a 2.5G link the host can send more than the ~1.24 Gbps of the GPON upstream, causing drops and bufferbloat: limit the egress on the host, see [MikroTik](/sfp-cage/mikrotik#gpon-upstream-flooding) # Miscellaneous Links - [Hacking RTL960x](https://github.com/Anime4000/RTL960x) +- [RTL960x stick setup guide](https://github.com/Anime4000/RTL960x/blob/main/Docs/StickSetup.md) +- [English ODI configuration guide by @rajkosto](https://gist.github.com/rajkosto/b684b7bb2697baa342cd2601ed5717d2) +- [Making it work on the Intel 82599ES](https://omaera.org/wlog/tech/odi_sfp) - [Ditch ONU, use GPON SFP on Business Grade Router, Mikrotik/Ubiquiti/pfSense (Home Networking)](https://forum.lowyat.net/topic/4925452) +- [Orange France at 2 Gbps with a MikroTik CCR2004](https://lafibre.info/remplacer-livebox/guide-de-connexion-fibre-directement-sur-un-routeur-voire-meme-en-2gbps/) +- [Pururin Collective forum](https://pururin.moe/viewtopic.php?t=7) - [For the old model ODI ZTE DFP-34G-C2C](/ont-odi-zte-dfp-34g-2c2) +[^rtl960x_odi_fw]: *ODI DFP-34X-2C2 firmware*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/tree/main/Firmware/DFP-34X-2C2 +[^rtl960x_isp]: *ISP specific configuration*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/ISP_specific_configuration.md +[^rtl960x_uart]: *UART*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/UART.md + diff --git a/ont/ont-t-w-twcgpon657.md b/ont/ont-t-w-twcgpon657.md index f67670d5..e20a7329 100644 --- a/ont/ont-t-w-twcgpon657.md +++ b/ont/ont-t-w-twcgpon657.md @@ -29,17 +29,58 @@ parent: T&W - [VSOL V2801F](/ont-vsol-v2801f) - [UFiber UF-Instant](/ont-ufiber-uf-instant) +## Enabling telnet + +Telnet must be enabled from the Web GUI before the configuration[^rtl960x_setup]: + +| State | URL | +| ------- | ---------------------------------------- | +| Enable | `http://192.168.1.1/bd/telnet_open.asp` | +| Disable | `http://192.168.1.1/bd/telnet_close.asp` | + ## List of firmwares and files - [Firmware repository by Anime4000](https://github.com/Anime4000/RTL960x/tree/main/Firmware/TWCGPON657) -The recommended version is `C00R657V2801F_V1.9.0-220404.tar`, because it is the V2801F firmware for T&W TWC GPON657. +| Firmware | Notes | +| --------------------------------- | ----------------------------------------- | +| `C00R657V00B12_20191121.tar` | Stock `B12` | +| `C00R657V00B13_20191024.tar` | Stock `B13` | +| `C00R657V00B13_20191205.tar` | Stock `B13` | +| `C00R657V00B13_20200507.tar` | Stock `B13` | +| `C00R657V00B15_20201222.tar` | Stock `B15` | +| `C00R657V2801F_V1.9.0-220404.tar` | V2801F firmware for the TWCGPON657 | +| `TWCGPON657_V1.9.0-240204.tar` | V2801F firmware for the TWCGPON657, 4-port emulation | + +The recommended version is `TWCGPON657_V1.9.0-240204.tar` (or `C00R657V2801F_V1.9.0-220404.tar`), the V2801F firmware for the T&W TWC GPON657: it supports both VEIP and PPTP, and the `240204` also the 4-port emulation. + +## Flashing the V2801F firmware + +The V2801F firmware checks the `VS_AUTH_KEY` license key, which does not exist on the stock firmware: without a valid key the stick reboots in a loop, see [V-SOL V2801F](/ont-vsol-v2801f#vs-auth-key)[^rtl960x_twc]. + +1. If the stock firmware is newer than `B13`, downgrade it to `B13` or older; +2. Via telnet, set the stick to 1000BASE-X and to the Ethernet mode, which prevents the reboot loop: + ```sh + # flash set LAN_SDS_MODE 1 + # flash set PON_MODE 3 + ``` +3. Upload the V2801F firmware from the Web GUI and wait; +4. Set a MAC address, hardware version and key that match: + ```sh + # flash set ELAN_MAC_ADDR 6CEFC6000000 + # flash set HW_HWVER RTL960x + # flash set VS_AUTH_KEY 00CF646955CCBDB88AB3B68922DB810F + ``` +5. Set `PON_MODE` back to `1` (GPON) or `2` (EPON) and reboot. # Known Bugs @@ -52,5 +93,8 @@ You should use the VID/VLAN shown by executing the command `omcicli mib get 84` # Miscellaneous Links - [Hacking RTL960x](https://github.com/Anime4000/RTL960x) +- [RTL960x stick setup guide](https://github.com/Anime4000/RTL960x/blob/main/Docs/StickSetup.md) - [forum lowyat](https://forum.lowyat.net/topic/4925452/+460) +[^rtl960x_twc]: *TWCGPON657 firmware*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/tree/main/Firmware/TWCGPON657 + diff --git a/ont/ont-technicolor-afm0002.md b/ont/ont-technicolor-afm0002.md index f7f770bb..fbfb64c9 100644 --- a/ont/ont-technicolor-afm0002.md +++ b/ont/ont-technicolor-afm0002.md @@ -96,6 +96,7 @@ customSwVersionAlert: "This needs the `/etc/scripts/flash` modded" customHwVersionAlert: "This needs the `/etc/scripts/flash` modded" customVendorAlert: "This needs the `/etc/scripts/flash` modded" customEquipAlert: "This needs the `/etc/scripts/flash` modded" +ip: "192.168.2.1" --> ## Enabling the Web UI @@ -103,47 +104,13 @@ customEquipAlert: "This needs the `/etc/scripts/flash` modded" # /bin/iptables -D INPUT -p tcp --dport 80 -j DROP ``` -## Transfering files from/to the stick -Works with binary files too, just run md5sum on source and destination to make sure you are not corrupting anything... -From the stick to the PC: +## Copying the configuration and the logs +The same commands of [Transferring files from/to the stick](#transferring-files-from-to-the-stick) work for the configuration and the logs: ```sh # ssh admin@192.168.2.1 "cat /tmp/omcilog" > omcilog.log -``` -From the PC to the stick: -```sh # cat lastgood.xml | ssh admin@192.168.2.1 "cat > /var/config/lastgood.xml" ``` -::: info Info -If a Windows system is used replace type with cat and run the commands from cmd (not Powershell) -::: - -## Extracting and repacking the rootfs -::: danger Warning -Make sure you run both commands as root, otherwise you might get a damaged rootfs image -::: - -```sh -# unsquashfs mtd5.bin -# mksquashfs squashfs-root rootfs -b 131072 -comp lzma -no-recovery -``` -## Flashing a new rootfs - -::: info Info -Only the inactive image can be flashed, change sw_versionX and sw_commit X based on the bank you have flashed -::: - -Flash mtd4/5 if you are on image1, mtd6/7 if you are on image0. - -The following commands are used to flash a new rootfs to image1 and then boot to it -```sh -# flash_eraseall /dev/mtd7 -# cat /tmp/rootfs.new > /dev/mtd7 -# nv setenv sw_version1 NEW_SOFTWARE_VERSION -# nv setenv sw_commit 1 -# reboot -``` - ::: info Info This section is based on the `V1_7_8_210412` version of the stick's firmware ::: diff --git a/ont/ont-technicolor-afm0003.md b/ont/ont-technicolor-afm0003.md index d0655dcf..f6103e32 100644 --- a/ont/ont-technicolor-afm0003.md +++ b/ont/ont-technicolor-afm0003.md @@ -78,68 +78,16 @@ speedLan: "123456" customSpeedLanAlert: "The default firmware does not allow modification of the `LAN_SDS_MODE` parameter. Using modded firmware is needed. Before editing the sync speed make sure your hardware supports it." lastgoodHs: true flashSwVersion: true +ip: "192.168.2.1" --> -## Enabling the Web UI -```sh -# /bin/iptables -D INPUT -p tcp --dport 80 -j DROP -``` - -## Transfering files from/to the stick -Works with binary files too, just run md5sum on source and destination to make sure you are not corrupting anything... -From the stick to the PC: -```sh -# tftp -tftp> put -tftp> q -``` -From the PC to the stick: -```sh -# tftp -tftp> get -tftp> q -``` - -## Extracting and repacking the rootfs -::: danger Warning -Make sure you run both commands as root, otherwise you might get a damaged rootfs image -::: - -```sh -# unsquashfs mtd5.bin -# mksquashfs squashfs-root rootfs -b 131072 -comp lzma -no-recovery -``` -## Flashing a new rootfs - ::: info Info -Only the inactive image can be flashed, change sw_versionX and sw_commit X based on the bank you have flashed +On this stick the files are usually transferred via TFTP (see [Transferring files from/to the stick](#transferring-files-from-to-the-stick)), and writing the rootfs to `/dev/mtd7` may fail with `Invalid Argument`: in that case write it to the block device `/dev/mtdblock7`. ::: -Flash mtd4/5 if you are on image1, mtd6/7 if you are on image0. - -The following commands are used to flash a new rootfs to image1 and then boot to it -```sh -# flash_eraseall /dev/mtd7 -# cat /tmp/rootfs.new > /dev/mtd7 -``` - -If you get this error on `cat` command -```sh -# cat /tmp/rootfs.new > /dev/mtd7 -cat: write error: Invalid Argument -``` - -Use this proceudre instead to write firmware back to mtd: -```sh -# flash_eraseall /dev/mtd7 -# cat /tmp/rootfs.new > /dev/mtdblock7 -``` - -Then make new firmware bootable +## Enabling the Web UI ```sh -# nv setenv sw_version1 NEW_SOFTWARE_VERSION -# nv setenv sw_commit 1 -# reboot +# /bin/iptables -D INPUT -p tcp --dport 80 -j DROP ``` # Miscellaneous Links diff --git a/ont/ont-ufiber-uf-instant.md b/ont/ont-ufiber-uf-instant.md index c3386956..4857c7d9 100644 --- a/ont/ont-ufiber-uf-instant.md +++ b/ont/ont-ufiber-uf-instant.md @@ -16,11 +16,11 @@ parent: UFiber | System | Linux (Luna SDK) | | SFP interfaces | 1 Gbps only, no HSGMII | | Optics | SC/APC | -| IP address | | -| Web Gui | ✅ | -| SSH | ✅ | +| IP address | 192.168.1.1 | +| Web Gui | ✅ user `ubnt`, password `ubnt` | +| SSH | ✅ user `ubnt`, password `ubnt`, disabled by default | | Telnet | | -| Serial | | +| Serial | ✅ | | Form Factor | miniONT SFP | ## Firmware is interchangeable with: @@ -47,6 +47,20 @@ The UFiber UF-Instant can be used as universal GPON stick with V2801F rootfs, bu | mtd7 | 004b0000 | 00001000 | "r1" | | mtd8 | 00010000 | 00001000 | "hw" | | mtd9 | 00010000 | 00001000 | "sec" | +| mtd10 | 00001000 | 00001000 | "Partition_010" | +| mtd11 | 00001000 | 00001000 | "Partition_011" | +| mtd12 | 00300000 | 00001000 | "linux" | +| mtd13 | 004b0000 | 00001000 | "rootfs" | + +This stick supports dual boot: `k0` and `r0` contain kernel and rootfs of the first image, `k1` and `r1` of the second one. A full flash dump (with `flash_all.xml`) is available in the [RTL960x repository](https://github.com/Anime4000/RTL960x/tree/main/Firmware/UF-Instant)[^rtl960x_uf]: SSH is disabled in the stock configuration and had to be enabled to make the dump. + +```sh +ssh ubnt@192.168.1.1 'cat /dev/mtd0' > dev_mtd0 +``` + +## Serial + +The UART pads are, from the front (SC connector) to the back (SFP connector): GND, VCC, RX, TX[^rtl960x_uf]. On the RTL9601CI (76 pins) the UART is on the pins 12 (TX) and 13 (RX)[^rtl960x_uart]. # Know Bugs @@ -54,6 +68,8 @@ VLAN swap issue (MEID 171), auto-sensing mode to switch between SGMII/HiSGMII You should use the VID/VLAN shown by executing the command `omcicli mib get 84` via telnet to bring up PPPoE +The stock firmware supports only the PPTP, and only on the LAN 1: it does not support the VEIP nor the 4-port emulation[^rtl960x]. + # Miscellaneous Links @@ -61,3 +77,7 @@ You should use the VID/VLAN shown by executing the command `omcicli mib get 84` - [UF INstant Mod](https://github.com/stich86/UF-Instant-Mod) - [SFP GPON ONU](https://github.com/zry98/SFP-GPON-ONU) - [UFiber.Configurator](https://github.com/Unifi-Tools/UFiber.Configurator) + +[^rtl960x]: *Hacking RTL960x*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x +[^rtl960x_uf]: *UF-Instant flash dump*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/tree/main/Firmware/UF-Instant +[^rtl960x_uart]: *UART*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/UART.md diff --git a/ont/ont-vsol-v2801f.md b/ont/ont-vsol-v2801f.md index 185edf3b..fe7edc0b 100644 --- a/ont/ont-vsol-v2801f.md +++ b/ont/ont-vsol-v2801f.md @@ -28,17 +28,74 @@ parent: V-SOL - [T&W TWC GPON657](/ont-t-w-twcgpon657) - [UFiber UF-Instant](/ont-ufiber-uf-instant) +It supports both VEIP and PPTP, and it is the only RTL9601CI stick that emulates all the 4 LAN ports of the original ONT (4-port emulation), which is required by the ISPs that provision the internet on a specific LAN port[^rtl960x]. + +## List of software versions +- V1.9.0-240614 (community build, modern WebGUI, 2.5GbE) +- V1.9.0-201104 +- V1.9.0-200827 +- V1.9.0-200825 +- V1.9.0-200417 +- V1.9.0-200410 +- V1.9.0-200323 +- V1.9.0-191015 + ## List of firmwares and files - [Firmware repository by Anime4000](https://github.com/Anime4000/RTL960x/tree/main/Firmware/V2801F) -The recommended version is `V2801F_V1.9.0-220425.tar` because it has a modern WebGUI, 2.5GbE support, patched `runlansds.sh`, `tftpd` and more. +The recommended version is `V2801F_V1.9.0-240614.tar` because it has a modern WebGUI, 2.5GbE support, patched `runlansds.sh`, `tftpd` and more. Before upgrading to it set `LAN_SDS_MODE` to `1`[^rtl960x_v2801f_fw]: + +```sh +# flash set LAN_SDS_MODE 1 +``` + +## VS_AUTH_KEY + +The V2801F checks a license key, `VS_AUTH_KEY`, generated from `ELAN_MAC_ADDR` and `HW_HWVER`: if it does not match, the stick reboots in a loop. A new key must be generated every time the MAC address or the hardware version are changed[^rtl960x_key]: + +```sh +VsAuthKeyGen.exe [HW_HWVER] +VsAuthKeyGen.exe 000000111111 168D.A +9E7E54597511D721D3A2932B048C0494 +``` + +The `VsAuthKeyGen.exe` key generator is available [here](https://drive.google.com/drive/folders/19kkrr8aHL1I5W_Poq_Y8Zd5hCpYU6H1Q). Some pre-generated keys: + +| `ELAN_MAC_ADDR` | `HW_HWVER` | `VS_AUTH_KEY` | +| --------------- | -------------- | ---------------------------------- | +| `000000ABCDEF` | `RTL960x` | `A73BF734A3348731274ACCADCF9E1E2A` | +| `00C2C6012345` | `RTL960x` | `B905D1A8C43571BA70A66C1B59BE2A86` | +| `6CEFC6000000` | `RTL960x` | `00CF646955CCBDB88AB3B68922DB810F` | +| `781735D35DA0` | `3FE48153CBAA` | `4DFD2ADED74CFC990DFE675EF527D815` | +| `043389FE8F59` | `BF9.A` | `4FF78A9422FCBC797A0A3061186F20B7` | +| `D0C65BE047E8` | `168D.A` | `F2A45DE3ADFD73916F09D9FAB84CEAE0` | + +```sh +# flash set ELAN_MAC_ADDR 043389FE8F59 +# flash set HW_HWVER BF9.A +# flash set VS_AUTH_KEY 4FF78A9422FCBC797A0A3061186F20B7 +# reboot +``` + +### Stopping the reboot loop + +With a wrong key there are only a few seconds to log in via telnet before the reboot (an [AutoIt script](https://github.com/Anime4000/RTL960x/blob/main/Tools/force-telnet/quick_telnet-login.au3) can do it automatically). The loop stops by switching the stick to Ethernet mode[^rtl960x_reboot]: + +```sh +# echo 3 > /proc/fiber_mode +``` + +Then fix `VS_AUTH_KEY` (or update the firmware). In Ethernet mode the telnet access is lost: unplug the fiber to get it back. `flash set PON_MODE 3` does the same persistently, set it back to `1` (GPON) at the end. # Known Bugs @@ -47,8 +104,18 @@ VLAN swap issue (MEID 171), auto-sensing mode to switch between SGMII/HiSGMII You should use the VID/VLAN shown by executing the command `omcicli mib get 84` via telnet to bring up PPPoE +With the stock firmwares the stick works as a 1000BASE-X fiber transceiver (`LAN_SDS_MODE` `1`), which is not supported by some hosts: on MikroTik the SFP port settings must match, and some models (RB4011, RB5009) have issues and may require to reinsert the stick[^rtl960x_twc]. + # Miscellaneous Links - [Hacking RTL960x](https://github.com/Anime4000/RTL960x) +- [RTL960x stick setup guide](https://github.com/Anime4000/RTL960x/blob/main/Docs/StickSetup.md) +- [V2801F Firmware_Mod (Bootstrap WebGUI)](https://github.com/Anime4000/RTL960x/tree/main/Firmware_Mod/V2801F) - [SFP GPON ONU](https://github.com/zry98/SFP-GPON-ONU) - [forum lowyat](https://forum.lowyat.net/topic/4925452/+460) + +[^rtl960x]: *Hacking RTL960x*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x +[^rtl960x_v2801f_fw]: *V2801F firmware*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/tree/main/Firmware/V2801F +[^rtl960x_key]: *`VS_AUTH_KEY`*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/VS_AUTH_KEY.md +[^rtl960x_reboot]: *V2801F Auto Reboot Fix*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/V2801F.md +[^rtl960x_twc]: *TWCGPON657*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/TWCGPON657.md diff --git a/sfp-cage/mikrotik.md b/sfp-cage/mikrotik.md index 6d221f3e..5ce50a4f 100644 --- a/sfp-cage/mikrotik.md +++ b/sfp-cage/mikrotik.md @@ -20,6 +20,46 @@ Note that Mikrotik RouterOS before 7.15beta4 requires the fiber to be plugged be This will trigger an alarm on the OLT at least on the first config. It is suggested upgrade to 7.15 and activate "Interface/SFP/Ignore Rx LOS", or use a media converter for the first config. +# 2.5G with the Realtek sticks + +With the Realtek RTL960x based sticks (e.g. [ODI DFP-34X-2C2](/ont-odi-realtek-dfp-34x-2c2)) the 2.5G link works on RouterOS 7.11+ with the port forced to `2.5G-baseX` and `LAN_SDS_MODE` set to `6` (2500BASE-X) on the stick[^rtl960x_25g]: + +```rsc +/interface/ethernet/set sfp-sfpplus1 auto-negotiation=no speed=2.5G-baseX +``` + +| Model | Working configuration | +| ------------------------ | ------------------------------------------------------------------------------------------------------ | +| RB4011iGS+RM | ❌ 2.5G not supported | +| RB5009UG+S+IN | ROS 7.11+, `2.5G-baseX`, `LAN_SDS_MODE 6` | +| hEX S 2025 (E60iUGS) | `2.5G-baseX`, `LAN_SDS_MODE 6` | +| CCR1036-8G-2S+ | ROS 7.11.2, `2.5G-baseX`, `LAN_SDS_MODE 6` | +| CCR2004-1G-12S+2XS | [@stich86 tweaks](https://github.com/Anime4000/RTL960x/issues/17#issuecomment-1101435506) | +| CCR2116-12G-4S+ | `LAN_SDS_MODE 4` | +| CRS305-1G-4S+IN | [@stich86 tweaks](https://github.com/Anime4000/RTL960x/issues/17#issuecomment-1101435506) | +| CRS309-1G-8S+IN | ROS 7.11+, `2.5G-baseX`, `LAN_SDS_MODE 6` | +| CRS310-1G-5S-4S+IN | ROS 7.11+, `2.5G-baseX`, `LAN_SDS_MODE 6` | +| CRS317-1G-16S+RM | ROS 7.11+, `2.5G-baseX`, `LAN_SDS_MODE 6` | +| CRS328-24P-4S+RM | ROS 7.11.2, `2.5G-baseX`, `LAN_SDS_MODE 6` | +| CRS354-48G-4S+2Q+RM | ROS 7.9.1+, `LAN_SDS_MODE 4` | + +## GPON upstream flooding + +The GPON upstream is ~1.24 Gbps: with a 2.5G link the router can send faster than the stick can transmit, causing drops, bufferbloat and a slow upload[^rtl960x_slow]. On the devices with a switch chip (e.g. RB5009) limit the egress of the port and enable the flow control: + +```rsc +/interface/ethernet/switch/port/set sfp-sfpplus1 egress-rate=1200M +/interface/ethernet/set sfp-sfpplus1 auto-negotiation=no speed=2.5G-baseX rx-flow-control=on tx-flow-control=on +/queue interface set sfp-sfpplus1 queue=multi-queue-ethernet-default +``` + +On the devices without a switch chip (e.g. CCR2004-1G-12S+2XS) use a CAKE queue instead: + +```rsc +/queue type add name=cake-egress-gpon kind=cake cake-bandwidth=1200M +/queue interface set sfp-sfpplus1 queue=cake-egress-gpon +``` + # CRS305-1G-4S+IN ## Bridge Mode @@ -45,3 +85,6 @@ Note that when using **Huawei MA5671A with right.com.cn firmware** on a Fastweb - [CRS305 Fastweb Italy SFP Router Mode](https://pastebin.com/zRaidTx4) - [@stich86 tweaks](https://github.com/Anime4000/RTL960x/issues/17#issuecomment-1101435506) - [Mikrotik changelogs](https://mikrotik.com/download/changelogs) + +[^rtl960x_25g]: *2.5Gb Compatibility*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/2.5Gb.md +[^rtl960x_slow]: *Slow Upload Speed*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/SlowUploadSpeed.md diff --git a/sfp-cage/tp-link.md b/sfp-cage/tp-link.md index 90eff5ad..cdf6aca1 100644 --- a/sfp-cage/tp-link.md +++ b/sfp-cage/tp-link.md @@ -18,4 +18,25 @@ has_children: false | Type | Router | VPN Router | +With the Realtek RTL960x based sticks the 2.5G link works on the TL-XDR5480 with the ODI DFP-34X-2C2 `220304` firmware, and on the TL-ER2260T with `LAN_SDS_MODE` set to `4` (HiSGMII PHY)[^rtl960x_25g]. + +# Archer GE800, BE800 and BE900 + +The 2.5G mode on the SFP port of these routers is available only on debug firmwares[^rtl960x_tplink]. The BE800 and BE900 are End Of Life and can't be downgraded to the debug firmware anymore, while the GE800 with the firmware `1.1.5` or older can use the [debug firmware](https://github.com/Anime4000/RTL960x/tree/main/Firmware_Router/TP-Link/Archer%20GE800). + +On the GE800 set up the internet with the stick at 1 Gbps first, then open `http://192.168.0.1/webpages/debug.html` and enter: + +``` +combo_debug stop +combo_debug set plus +combo_debug ipg_set combo10g 1_192bit +``` + +`combo_debug ipg_set combo10g 1` goes back to 1 Gbps. The setting is lost at every reboot. + +On the hosts that detect the 2.5G modules from the EEPROM (e.g. Linux `sfp-bus.c`), the stick must report the transceiver code `00h` at the offset `06h` and the nominal bit rate `1Fh` (2500 Mbps) at the offset `0Ch`, see [SFP standard](/sfp/sfp-standard). + - [2.5Gb Compatibility](https://github.com/Anime4000/RTL960x/blob/main/Docs/2.5Gb.md) + +[^rtl960x_25g]: *2.5Gb Compatibility*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/2.5Gb.md +[^rtl960x_tplink]: *TP-Link Archer GE800*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/tree/main/Firmware_Router/TP-Link/Archer%20GE800 From 9b53a4a386d61be7c8c7dde763edf5d8e770255f Mon Sep 17 00:00:00 2001 From: Simone Bortolin Date: Sat, 10 Oct 2026 00:17:50 +0200 Subject: [PATCH 2/3] Move the useful MEs to the MIB page and fix the internal links - The list of the most useful MEs is now in the GPON MIB page, the Luna SDK partial links it and also dumps only those MEs - Use the published URLs for the links to the gpon, tools, sfp and sfp-cage pages - Drop the rsc code fences, not supported by the highlighter Co-Authored-By: Claude Opus 5.5 --- gpon/mib.md | 24 ++++++++++++++ ont/_partials/ont-luna-sdk-useful-commands.md | 31 ++++++------------- ont/ont-odi-realtek-dfp-34x-2c2.md | 2 +- sfp-cage/mikrotik.md | 6 ++-- sfp-cage/tp-link.md | 2 +- 5 files changed, 38 insertions(+), 27 deletions(-) diff --git a/gpon/mib.md b/gpon/mib.md index 4f3e0f8b..26cfeb8f 100644 --- a/gpon/mib.md +++ b/gpon/mib.md @@ -360,6 +360,29 @@ The new ME introduced in G.988 [^G_988] do not have a description because G.988 | 453-65279 | Reserved for future standardization | | | | | | | | | | | | 65280-65535 | Reserved for vendor-specific use | | | | | | | | | | | +# Most useful MEs to check the provisioning + +When an ONT or a stick replaces the ISP one, these are the MEs to check to understand what the OLT has provisioned[^rtl960x_omci]: + +| ME | Name | Notes | +| --- | -------------------------------- | ------------------------------------------------------------------------------- | +| 6 | Circuit pack | Type and number of ports emulated by the ONT | +| 7 | Software image | Software versions reported to the OLT | +| 11 | PPTP Ethernet UNI | Physical LAN ports, with the `AdminState` set by the OLT | +| 84 | VLAN tagging filter data | VLANs sent to the ONT by the OLT, e.g. the internet VLAN to use on the router | +| 131 | OLT-G | OLT vendor ID | +| 171 | Extended VLAN tagging operation | VLAN translation rules, which VLAN goes to which LAN port, see the [OMCI VLAN table parser](/gpon-omci-vlan-parser) | +| 256 | ONU-G | Vendor ID, version and serial number | +| 257 | ONU2-G | Equipment ID, OMCC version | +| 262 | T-CONT | | +| 263 | ANI-G | PON side | +| 264 | UNI-G | LAN side | +| 277 | Priority queue | | +| 309 | Multicast operations profile | VLANs used for the IPTV multicast traffic | +| 329 | Virtual Ethernet interface point | VEIP, used for VoIP, TR-069 or the router mode of the HGUs, see [PPTP and VEIP](/pptp_veip) | + +The commands to read the MEs depend on the chipset, see the useful commands in the device pages (e.g. `omcicli mib get` on the [Realtek sticks](/ont-odi-realtek-dfp-34x-2c2#querying-a-particular-omci-me)), or decode the full OMCI log with [OMCI Wireshark](/omci-wireshark). + --- @@ -372,3 +395,4 @@ The new ME introduced in G.988 [^G_988] do not have a description because G.988 [^verizon_open_omci]: *Verizon OpenOMCI Specification, Version 1.00 June 30, 2017* [^B-PON]: MIB for legacy B-PON +[^rtl960x_omci]: *OMCI MIB*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/OMCI_CLI.md diff --git a/ont/_partials/ont-luna-sdk-useful-commands.md b/ont/_partials/ont-luna-sdk-useful-commands.md index 496aaa54..22524c10 100644 --- a/ont/_partials/ont-luna-sdk-useful-commands.md +++ b/ont/_partials/ont-luna-sdk-useful-commands.md @@ -28,32 +28,19 @@ diag gpon get onu-state # omcicli mib get MIB_IDX ``` -The most useful MEs to check the provisioning received from the OLT[^rtl960x_omci]: - -| ME | Name | Notes | -| --- | -------------------------------- | ------------------------------------------------------------------------------- | -| 6 | Circuit pack | Type and number of ports emulated by the stick | -| 7 | Software image | Software versions reported to the OLT | -| 11 | PPTP Ethernet UNI | Physical LAN ports, with the `AdminState` set by the OLT | -| 84 | VLAN tagging filter data | VLANs sent to the stick by the OLT, e.g. the internet VLAN to use on the router | -| 131 | OLT-G | OLT vendor ID | -| 171 | Extended VLAN tagging operation | VLAN translation rules, which VLAN goes to which LAN port | -| 256 | ONU-G | Vendor ID, version and serial number | -| 257 | ONU2-G | Equipment ID, OMCC version | -| 262 | T-CONT | | -| 263 | ANI-G | PON side | -| 264 | UNI-G | LAN side | -| 277 | Priority queue | | -| 309 | Multicast operations profile | VLANs used for the IPTV multicast traffic | -| 329 | Virtual Ethernet interface point | VEIP, used for VoIP, TR-069 or the router mode of the HGUs | - -To dump all the MEs at once: +The list of the MEs is in [GPON MIB](/mib), and the most useful ones to check the provisioning received from the OLT are in [Most useful MEs to check the provisioning](/mib#most-useful-mes-to-check-the-provisioning). + +To dump all the MEs at once[^rtl960x_omci]: ```sh for ME in 2 5 6 7 11 24 45 47 49 50 52 78 79 83 84 89 130 131 133 134 136 137 148 157 158 171 240 244 245 248 249 250 253 255 256 257 262 263 264 266 267 268 272 273 274 277 278 280 281 284 287 296 298 307 308 309 310 311 312 321 322 329 330 334 340 341 65282 65294 65408 65527 65528 65529 65530 65531; do echo "MIB: $ME"; omcicli mib get $ME; done ``` -See [PPTP and VEIP](/gpon/pptp_veip) for the meaning of the UNIs and [OMCI Wireshark](/tools/omci-wireshark) to decode the full OMCI log. +To dump the most useful MEs at once: + +```sh +for ME in 6 7 11 84 131 171 256 257 262 263 264 277 309 329; do echo "MIB: $ME"; omcicli mib get $ME; done +``` ## Getting the GEM ports and the flows @@ -133,7 +120,7 @@ The default value on this stick is `{{ include.speedLanDefault }}`. {% endif %} {% if include.speedLan contains '6' %} -The 2.5G modes are `4` (HiSGMII PHY), `5` (HiSGMII MAC) and `6` (2500BASE-X): most of the hosts that support 2.5G work with the mode `6` and the port forced to 2500BASE-X, see the [SFP standard](/sfp/sfp-standard) page and the [2.5G compatibility list](https://github.com/Anime4000/RTL960x/blob/main/Docs/2.5Gb.md)[^rtl960x_25g]. +The 2.5G modes are `4` (HiSGMII PHY), `5` (HiSGMII MAC) and `6` (2500BASE-X): most of the hosts that support 2.5G work with the mode `6` and the port forced to 2500BASE-X, see the [SFP standard](/sfp-standard) page and the [2.5G compatibility list](https://github.com/Anime4000/RTL960x/blob/main/Docs/2.5Gb.md)[^rtl960x_25g]. {% endif %} ::: warning diff --git a/ont/ont-odi-realtek-dfp-34x-2c2.md b/ont/ont-odi-realtek-dfp-34x-2c2.md index 13aea489..c019b843 100644 --- a/ont/ont-odi-realtek-dfp-34x-2c2.md +++ b/ont/ont-odi-realtek-dfp-34x-2c2.md @@ -173,7 +173,7 @@ macKey: "odi" diag bandwidth set egress port all rate 4194296 diag bandwidth set ingress port all rate 4194296 ``` -- With a 2.5G link the host can send more than the ~1.24 Gbps of the GPON upstream, causing drops and bufferbloat: limit the egress on the host, see [MikroTik](/sfp-cage/mikrotik#gpon-upstream-flooding) +- With a 2.5G link the host can send more than the ~1.24 Gbps of the GPON upstream, causing drops and bufferbloat: limit the egress on the host, see [MikroTik](/mikrotik#gpon-upstream-flooding) # Miscellaneous Links diff --git a/sfp-cage/mikrotik.md b/sfp-cage/mikrotik.md index 5ce50a4f..bc862c27 100644 --- a/sfp-cage/mikrotik.md +++ b/sfp-cage/mikrotik.md @@ -24,7 +24,7 @@ It is suggested upgrade to 7.15 and activate "Interface/SFP/Ignore Rx LOS", or u With the Realtek RTL960x based sticks (e.g. [ODI DFP-34X-2C2](/ont-odi-realtek-dfp-34x-2c2)) the 2.5G link works on RouterOS 7.11+ with the port forced to `2.5G-baseX` and `LAN_SDS_MODE` set to `6` (2500BASE-X) on the stick[^rtl960x_25g]: -```rsc +``` /interface/ethernet/set sfp-sfpplus1 auto-negotiation=no speed=2.5G-baseX ``` @@ -47,7 +47,7 @@ With the Realtek RTL960x based sticks (e.g. [ODI DFP-34X-2C2](/ont-odi-realtek-d The GPON upstream is ~1.24 Gbps: with a 2.5G link the router can send faster than the stick can transmit, causing drops, bufferbloat and a slow upload[^rtl960x_slow]. On the devices with a switch chip (e.g. RB5009) limit the egress of the port and enable the flow control: -```rsc +``` /interface/ethernet/switch/port/set sfp-sfpplus1 egress-rate=1200M /interface/ethernet/set sfp-sfpplus1 auto-negotiation=no speed=2.5G-baseX rx-flow-control=on tx-flow-control=on /queue interface set sfp-sfpplus1 queue=multi-queue-ethernet-default @@ -55,7 +55,7 @@ The GPON upstream is ~1.24 Gbps: with a 2.5G link the router can send faster tha On the devices without a switch chip (e.g. CCR2004-1G-12S+2XS) use a CAKE queue instead: -```rsc +``` /queue type add name=cake-egress-gpon kind=cake cake-bandwidth=1200M /queue interface set sfp-sfpplus1 queue=cake-egress-gpon ``` diff --git a/sfp-cage/tp-link.md b/sfp-cage/tp-link.md index cdf6aca1..e81fbc71 100644 --- a/sfp-cage/tp-link.md +++ b/sfp-cage/tp-link.md @@ -34,7 +34,7 @@ combo_debug ipg_set combo10g 1_192bit `combo_debug ipg_set combo10g 1` goes back to 1 Gbps. The setting is lost at every reboot. -On the hosts that detect the 2.5G modules from the EEPROM (e.g. Linux `sfp-bus.c`), the stick must report the transceiver code `00h` at the offset `06h` and the nominal bit rate `1Fh` (2500 Mbps) at the offset `0Ch`, see [SFP standard](/sfp/sfp-standard). +On the hosts that detect the 2.5G modules from the EEPROM (e.g. Linux `sfp-bus.c`), the stick must report the transceiver code `00h` at the offset `06h` and the nominal bit rate `1Fh` (2500 Mbps) at the offset `0Ch`, see [SFP standard](/sfp-standard). - [2.5Gb Compatibility](https://github.com/Anime4000/RTL960x/blob/main/Docs/2.5Gb.md) From e3fed36a683eb0aea26355444c73250be62def45 Mon Sep 17 00:00:00 2001 From: Simone Bortolin Date: Sat, 10 Oct 2026 00:25:00 +0200 Subject: [PATCH 3/3] Add the CA8271x repository info to the Cortina pages - GPON chipset: Cortina families and SoCs (code names, applications) - FS XGS-ONU-25-20NI: CA8271S chipset, uboot access on the new CIG models, switching between XGS-PON and 10G-EPON (XE-99S) - HiSense LTF7267-BHA+: CA8271S chipset, real partition layout, scfg.txt files, OEM variants, switching to 10G-EPON (LTF7263-BH+), UART pins - Nokia XS-010S-Q: CIG XG-99S OEM, flash chip, NAND dump - CIG XE-99S, LTF7263-BH+: link to the switching procedure Co-Authored-By: Claude Opus 5.5 --- gpon/ont.md | 28 ++++++++- ont-epon/CIG_XE-99S.md | 2 + ont-epon/LTF7263-BH+.md | 2 + ont-xgs/ont-fs-XGS-ONU-25-20NI.md | 40 +++++++++++- ont-xgs/ont-hisense-ltf7267-bha+.md | 96 ++++++++++++++++++++++++----- ont-xgs/ont-nokia-xs-010s-q.md | 10 ++- 6 files changed, 157 insertions(+), 21 deletions(-) diff --git a/gpon/ont.md b/gpon/ont.md index 2ab4a5c1..8723c17f 100644 --- a/gpon/ont.md +++ b/gpon/ont.md @@ -26,11 +26,12 @@ Currently, there are only a few main PON chipset vendors: * RTL8290 (laser driver) - Cortina Systems/Cortina Access (previously StorLink) * Cortina QWCS8032E - * Cortina CA8289 + * Cortina CA8289 (HGU, XGS-PON and 10G-EPON) * CA8271 series (XGS-PON and 10G-EPON) - CA8271A - CA8271S - CA8271NI + - CA8271N - Lantiq (then Intel, then MaxLinear): * Falcon series (GPON, End Of Life) - PEB98010 @@ -109,6 +110,30 @@ The useful commands for the Realtek sticks running the Luna SDK are in each devi Realtek announced that the RTL9601C and RTL9601CI will be End Of Life at the end of November 2026, and they will not get a replacement. ::: +## Cortina Chipsets + +Cortina Access makes the 10G SoCs used by many XGS-PON and 10G-EPON ONTs and SFP+ sticks[^ca8271x]: + +| Family | CPU | Applications | +| -------- | ------------------------- | --------------------------------------------------------------------------------------------------------- | +| CA8271 | MIPS R3000 | SFU ONTs and SFP+ sticks, with the minimum ports for a bridge and a low power CPU | +| CA8289 | AArch64 Cortex-A55, 4 cores | HGU ONTs, with multiple LAN PHYs, USB 3.0 and PCIe for the Wi-Fi | +| RTL9615C | AArch64 Cortex-A55, 2 cores | Low cost version of the CA8289 made by Realtek, with 2 XFI and 1 1G LAN, half the cores and memory channels | +| CA7774 | AArch64 Cortex-A53, 4 cores | HGU routers, like the CA8289 without the PON interface | + +| SoC | Family | Code name | Applications | +| ---------- | ------ | --------- | -------------------------------------------------------------- | +| CA8271A | CA8271 | SATURN | PON SFU ONTs, cable TV RF | +| CA8271N | CA8271 | | PON SFU ONTs | +| CA8271NI | CA8271 | SATURN2 | PON SFU ONTs (e.g. [Nokia XS-010X-R](/xgs/ont-nokia-xs-010x-r)) | +| NLD0605APB | CA8271 | SATURN2 | CA8271NI made by NTT Electronics for the NTT 10G-EPON ONUs | +| CA8271S | CA8271 | SATURN | SFP+ sticks (e.g. [FS.com XGS-ONU-25-20NI](/xgs/ont-fs-XGS-ONU-25-20NI), [HiSense LTF7267-BHA+](/xgs/ont-hisense-ltf7267-bha+)) | +| CA8289 | CA8289 | VENUS | PON HGU ONTs | +| RTL9615C | CA8289 | TAURUS | Realtek XG-PON/XGS-PON ONTs | +| CA7774 | CA7774 | G3 | Routers without PON | + +Some CA8271S sticks are the same hardware in an XGS-PON and in a 10G-EPON version, and can be switched between the two by replacing the firmware: CIG XG-99S ↔ [CIG XE-99S](/epon/CIG_XE-99S) and [HiSense LTF7267-BH+](/xgs/ont-hisense-ltf7267-bha+) ↔ [LTF7263-BH+](/epon/LTF7263-BH+). The community guides (root shell, `scfg.txt`, mtd dumps, SIEPON Package-A custom firmware) are in [Hacking CA8271x](https://github.com/YuukiJapanTech/CA8271x) by YuukiJapanTech. + ## Lantiq Chipsets Unfortunately Lantiq no longer exists as it has been bought out and dismembered by Intel. This purchase was a huge deal as at the time Lantiq was at the forefront of the GPON and xDSL chipset market. @@ -129,3 +154,4 @@ You can also help us with the content of this site, on each page you will find a ::: [^rtl960x]: *Hacking RTL960x*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x +[^ca8271x]: *Hacking CA8271x / CA8289x XGS-PON & 10G-EPON ONTs*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x diff --git a/ont-epon/CIG_XE-99S.md b/ont-epon/CIG_XE-99S.md index 216ae470..2523ffb1 100644 --- a/ont-epon/CIG_XE-99S.md +++ b/ont-epon/CIG_XE-99S.md @@ -71,6 +71,8 @@ The custom firmware is compatible with the following. - Hisense LTF-7267-BH+ (GPON) - Hisense LTF-7263-BH+ +The stick is the same hardware of the CIG XG-99S (XGS-PON), and it can be switched to XGS-PON and back by replacing the firmware, see [Switching between XGS-PON and 10G-EPON](/xgs/ont-fs-XGS-ONU-25-20NI#switching-between-xgs-pon-and-10g-epon). + ## Firmware versions ### Original firmware (SIEPON Package-C) - CTC20220901 diff --git a/ont-epon/LTF7263-BH+.md b/ont-epon/LTF7263-BH+.md index cc43bf64..f6967bd9 100644 --- a/ont-epon/LTF7263-BH+.md +++ b/ont-epon/LTF7263-BH+.md @@ -45,6 +45,8 @@ The custom firmware is compatible with the following. - CIG XE-99S - Hisense LTF-7263-BH+ +The stick is the same hardware of the HiSense LTF7267-BH+ (XGS-PON), and it can be switched to XGS-PON and back by replacing the firmware, see [Switching between XGS-PON and 10G-EPON](/xgs/ont-hisense-ltf7267-bha+#switching-between-xgs-pon-and-10g-epon). + ## Firmware versions ### Original firmware (SIEPON Package-C) - 20210421024332 diff --git a/ont-xgs/ont-fs-XGS-ONU-25-20NI.md b/ont-xgs/ont-fs-XGS-ONU-25-20NI.md index 2546e13d..638792f4 100644 --- a/ont-xgs/ont-fs-XGS-ONU-25-20NI.md +++ b/ont-xgs/ont-fs-XGS-ONU-25-20NI.md @@ -13,7 +13,7 @@ parent: FS.com | Model | XGS-ONU-25-20NI | | ODM | CIG | | ODM Product Code | XG-99S | -| Chipset | Cortina CA8271A | +| Chipset | Cortina CA8271S | | Flash | MX35LF1GE4AB 128MB | | RAM | 128MB | | CPU | Taroko V0.2 (MIPS) | @@ -487,6 +487,8 @@ ERROR: can't get kernel image! SATURN# ``` +If the stick still boots, the uboot prompt can be reached while `Hit any key to stop autoboot` is displayed: on the old models any key works, while the new CIG models (XGS-ONU-25-20NI, XE-99S, ...) require to send the raw bytes `0x1b 0x1d 0x0f 0x0b`, e.g. with a Tera Term macro or PComm Terminal Emulator (found by [@rssor](https://github.com/rssor))[^ca8271x_mtd]. + Download the stick's mtd dump from [GitHub.](https://github.com/YuukiJapanTech/CA8271x/tree/main/mtd) Enable NAND with the following command: @@ -536,6 +538,38 @@ SATURN# spi_nand write 0x81000000 0x000003b00000 0x2800000 When the stick turns back on, it will boot with the transferred kernel and rootfs. +## Switching between XGS-PON and 10G-EPON + +The XG-99S (and its OEMs, like this stick) and the [CIG XE-99S](/epon/CIG_XE-99S) (10G-EPON) are the same hardware, so the stick can be switched between XGS-PON and 10G-EPON by replacing the firmware: changing only `scfg.txt` is not enough[^ca8271x_switch]. + +::: danger +Backup all the partitions first, and never remove the power while writing the partitions: a bricked stick can be repaired only via UART, see [Bricked stick Repair](#bricked-stick-repair). +::: + +The following must be replaced, using the [images](https://github.com/YuukiJapanTech/CA8271x/tree/main/XG-XE_Switch) of the CA8271x repository (they contain the GPON serial number `GPON2350004b`, login password `UzwugGYT`, and the EPON MAC address `CC:CF:83:59:FF:F8`): + +| Partition / item | Content | +| ------------------------- | --------------------------------------------------------------------------- | +| `mtd2` / `mtd5` | `dtb` | +| `mtd3` / `mtd6` | `kernel` | +| `mtd4` / `mtd7` | `rootfs` | +| `mtd9` / `mtd10` | `mfginfo` | +| `/userdata` | `userdata.tar.gz` (only when switching from XG-99S to XE-99S) | +| uboot `setpartlayout`, `more_args` | partition layout and boot partition (`rootfs` is `/dev/mtdblock12` for XGS-PON, `/dev/mtdblock11` for 10G-EPON) | + +Each partition is written with: + +```sh +# flash_eraseall /dev/mtd3 +# flashcp -v kernel.bin /dev/mtd3 +``` + +The full procedure, with the uboot environment for both directions, is in the [CA8271x repository](https://github.com/YuukiJapanTech/CA8271x/tree/main/XG-XE_Switch). The current mode is shown in the kernel log: + +```sh +# grep "ca-pon: load PON_MAC_MODE:" /var/log/messages +Jan 1 00:00:13 saturn-sfpplus-eng user.warn kernel: [ 13.843922] ca-pon: load PON_MAC_MODE: XGSPON +``` # Known Bugs - There is a bug in the `register_id` command in the `misc` CLI option that changes the value of `pon_passwd` (LOID Password) instead of `register_id` (PLOAM). @@ -543,4 +577,8 @@ When the stick turns back on, it will boot with the transferred kernel and rootf # Miscellaneous Links - [GitHub - CA8271x](https://github.com/YuukiJapanTech/CA8271x) +- [FS.com XGS-ONU-25-20NI / CIG XG-99S Modification Utility](https://github.com/rssor/fs_xgspon_mod) + +[^ca8271x_mtd]: *Dump images & Bricked Stick Repair*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x/tree/main/mtd +[^ca8271x_switch]: *Switch between XGS and 10GE*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x/tree/main/XG-XE_Switch diff --git a/ont-xgs/ont-hisense-ltf7267-bha+.md b/ont-xgs/ont-hisense-ltf7267-bha+.md index e770fd3c..f0e181fe 100644 --- a/ont-xgs/ont-hisense-ltf7267-bha+.md +++ b/ont-xgs/ont-hisense-ltf7267-bha+.md @@ -11,7 +11,7 @@ parent: HiSense | Vendor/Brand | HiSense | | Model | LTF7267-BHA+ | | ODM | ✅ | -| Chipset | Cortina CA8271A | +| Chipset | Cortina CA8271S | | Flash | 128MB | | RAM | 128MB | | System | Custom Linux by Cortina (Saturn SDK) based on Kernel 4.4 | @@ -40,29 +40,40 @@ The stick has a TTL 3.3v UART console (configured as 115200 8-N-1) that can be a Some USB TTL adapters label TX and RX pins the other way around: try to swap them if the connection doesn't work. ::: +The UART pads are connected to the `15K` and `16K` pins of the CA8271S[^ca8271x_uart]. + ## List of software versions - 22.05.26.1 - 20220527052622 (from /etc/hi_version - /etc/version) ## List of partitions -| dev | size | erasesize | name | -| ----- | -------- | --------- | --------------- | -| mtd0 | 00040000 | 00001000 | "ssb" | -| mtd1 | 00002000 | 00001000 | "uboot-env" | -| mtd2 | 00002000 | 00001000 | "dtb0" | -| mtd3 | 0003c000 | 00001000 | "kernel0" | -| mtd4 | 00300000 | 00001000 | "rootfs0" | -| mtd5 | 004c0000 | 00001000 | "dtb1" | -| mtd6 | 00300000 | 00001000 | "kernel1" | -| mtd7 | 004c0000 | 00001000 | "rootfs1" | -| mtd8 | 00001000 | 00001000 | "userdata" | -| mtd9 | 00001000 | 00001000 | "squashfs_ubi" | -| mtd10 | 00001000 | 00001000 | "userdata" | +| dev | start | size | name | +| ---- | ------------ | --------- | ----------- | +| mtd0 | `0x00000000` | `0x400000` | "ssb" (U-Boot) | +| mtd1 | `0x00400000` | `0x100000` | "uboot-env" | +| mtd2 | `0x00500000` | `0x100000` | "dtb0" | +| mtd3 | `0x00600000` | `0x600000` | "kernel0" | +| mtd4 | `0x00c00000` | `0x2800000` | "rootfs0" | +| mtd5 | `0x03400000` | `0x100000` | "dtb1" | +| mtd6 | `0x03500000` | `0x600000` | "kernel1" | +| mtd7 | `0x03b00000` | `0x2800000` | "rootfs1" | +| mtd8 | `0x06300000` | `0x1400000` | "userdata" | This ONT supports dual boot. -`kernel0` and `rootfs0` respectively contain the kernel and firmware of the first image, `kernel1` and `rootfs1` the kernel and firmware of the second one. +`kernel0` and `rootfs0` respectively contain the kernel and firmware of the first image, `kernel1` and `rootfs1` the kernel and firmware of the second one. The mtd dumps of the LTF7263-BH+, XGS800E and NATYWISH LTF-7267-BH+ are available in the [CA8271x repository](https://github.com/YuukiJapanTech/CA8271x/tree/main/mtd)[^ca8271x_mtd]. + +## Configuration files + +The stick reads its configuration from two `scfg.txt` files, the second one overrides the first one[^ca8271x_scfg]: + +| File | Description | +| -------------------------- | ------------------------------------------------------------------------------------ | +| `/config/default_scfg.txt` | Default settings of the manufacturer, do not change it | +| `/config/scfg.txt` | Settings of the user or of the ISP, the settings below are appended here | + +The default `scfg.txt` files of many CA8271x ONTs (LTF-7263-BH+, NATYWISH LTF-7267-BH+, XGS800E, NTT, NEC, ...) are in the [CA8271x repository](https://github.com/YuukiJapanTech/CA8271x/tree/main/default_scfg). # XGS-PON ONU status @@ -457,10 +468,63 @@ Reboot ONT to apply the change. ## Variants -The LTF7267-BH+ is a variant of the LTF7267-BHA+ with the same Cortina CA8271A chipset. The information on this page applies to both models. +The LTF7267-BH+ is a variant of the LTF7267-BHA+ with the same Cortina CA8271S chipset. The information on this page applies to both models. + +The same hardware is also sold as[^ca8271x]: + +| Model | Mgmt IP | Notes | +| --------------------------- | ------------- | ------------------------------------------------------------------------------------------------------- | +| XGS800E | 192.168.0.1 | OEM | +| ZTE E910F | 192.168.0.1 | OEM | +| Raisecom ISCOM HT801-XGSFP | 192.168.0.1 | OEM | +| NATYWISH LTF-7267-BH+ | 192.168.1.1 | Custom firmware with kernel 4.14: telnet user `hbmt`, password `hbmt521@`; UART user `admin`, password `hbmt521@`; Web GUI `http://192.168.1.1/hihtml/login_hi.html` user `useradmin`, password `12345678` | +| [HiSense LTF7263-BH+](/epon/LTF7263-BH+) | 192.168.0.1 | 10G-EPON version, see below | + +## Switching between XGS-PON and 10G-EPON + +The LTF7267-BH+ (and its OEMs) and the [LTF7263-BH+](/epon/LTF7263-BH+) (10G-EPON) are the same hardware: the stick can be switched between XGS-PON and 10G-EPON by replacing the kernel (`mtd3`/`mtd6`) and the rootfs (`mtd4`/`mtd7`) with the [images](https://github.com/YuukiJapanTech/CA8271x/tree/main/XG-XE_Switch) of the CA8271x repository[^ca8271x_switch]. Changing only `scfg.txt` is not enough, and the NATYWISH LTF-7267-BH+ is not compatible with this procedure. + +::: danger +Backup all the partitions first, and never remove the power while writing the partitions: a bricked stick can be repaired only via UART. +::: + +From the root shell, in `/tmp` (one file at a time, to avoid filling the tmpfs): + +```sh +tftp -r kernel.bin -g +flash_eraseall /dev/mtd3 +flashcp -v kernel.bin /dev/mtd3 +flash_eraseall /dev/mtd6 +flashcp -v kernel.bin /dev/mtd6 +rm kernel.bin +tftp -r rootfs.bin -g +flash_eraseall /dev/mtd4 +flashcp -v rootfs.bin /dev/mtd4 +flash_eraseall /dev/mtd7 +flashcp -v rootfs.bin /dev/mtd7 +rm -r /overlay/upper* +reboot +``` + +The images contain the GPON serial number `HBMT00000001` (LTF7267-BH+) or the EPON MAC address `00:13:25:00:00:01` (LTF7263-BH+). The current mode is shown in the boot log: + +```sh +# grep "app dev mode:1, scfg mode:" /var/log/boot +Fri May 27 05:31:39 2022: app dev mode:1, scfg mode:[XGS-PON] +``` # Known Bugs - `ALCL` OLT mode uses some static configurations on MIBs, so if your OLT has strict configuration checks it might not work properly. - During initial tests the only currently working mode of the stick is `PPTP EthUni`. - Stick can be configured to also emulate `VEIP` mode (adding it to the scfg.txt file), but the current firmware doesn't link correctly the XGBE interface, so no traffic is passing between LAN and PON interfaces. - On some SFP+ cages that do not support USXGMII, the kernel may log `Warning!!! port 6 isnt USXGMII and can't do AN` during activation. This can cause repeated ONU deactivation/reactivation cycles (`DEACTIVE_ONUID_REQ`). Ensure your host device's SFP+ cage supports 10GBase-R or USXGMII auto-negotiation. + +# Miscellaneous Links + +- [GitHub - CA8271x](https://github.com/YuukiJapanTech/CA8271x) + +[^ca8271x]: *Hacking CA8271x / CA8289x XGS-PON & 10G-EPON ONTs*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x +[^ca8271x_mtd]: *Dump images & Bricked Stick Repair*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x/tree/main/mtd +[^ca8271x_scfg]: *scfg.txt*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x/blob/main/doc/scfg_files.md +[^ca8271x_switch]: *Switch between XGS and 10GE*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x/tree/main/XG-XE_Switch +[^ca8271x_uart]: *UART pin*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x/blob/main/doc/UART.md diff --git a/ont-xgs/ont-nokia-xs-010s-q.md b/ont-xgs/ont-nokia-xs-010s-q.md index 91a87c84..914dde05 100644 --- a/ont-xgs/ont-nokia-xs-010s-q.md +++ b/ont-xgs/ont-nokia-xs-010s-q.md @@ -10,14 +10,14 @@ parent: Nokia | ---------------- | ------------------------------------------------------------------ | | Vendor | Nokia | | Model | XS-010S-Q | -| ODM | ? | -| ODM Product Code | ? | +| ODM | CIG | +| ODM Product Code | [XG-99S](/xgs/ont-fs-XGS-ONU-25-20NI) | | Chipset | Cortina CA8271S | | CPU | Dual core CPU (four virtual CPUs) running at 800 MHz | | L1 Cache | 64KB (32KB instruction, 32KB data) | | L2 Cache | 256KB with I/O coherency | | Manufacter | ? | -| Flash | 1GB | +| Flash | Macronix MX35LF1GE4AB 1 Gbit (128 MB) SPI NAND | | RAM | ? | | System | ? | | SFP interfaces | 10GBASE-R | @@ -28,6 +28,10 @@ parent: Nokia | Telnet | ✅ Port 23 user: `admin`, password: `1234` (see Telnet Full Shell) | | Form Factor | SFP+ | +This stick is an OEM of the CIG XG-99S, the same hardware of the [FS.com XGS-ONU-25-20NI](/xgs/ont-fs-XGS-ONU-25-20NI), and it supports only the PPTP[^ca8271x]. A NAND dump is available in the [CA8271x repository](https://github.com/YuukiJapanTech/CA8271x/tree/main/NAND_dump/NOKIA_XS-010S-Q): in that dump the kernel partition had been erased and the uboot is password protected, with an unknown password. + +[^ca8271x]: *Hacking CA8271x / CA8289x XGS-PON & 10G-EPON ONTs*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x + # Module Pinout | | | |