Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 21 additions & 1 deletion gpon/gpon-auth.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,8 +43,28 @@ This happens when the OLT detects that the ONT is `drunk`, so it tries to update

This is most likely to reduce logs from misconfigured ONTs and to be able to send updates automatically to ONTs.

The same happens on other OLTs that support any ONU (e.g. Fiberhome, Calix and Nokia): the ONU reaches `O5` even with a wrong serial number or PLOAM password, but the OLT does not send the VLAN configuration (ME 84 and ME 171)[^rtl960x]. To fix it:

- check again the serial number and the PLOAM password;
- clone all the identity values of the original ONT: vendor ID, equipment ID, hardware and software versions, OMCC version and, for some OLTs, OUI, hardware serial number and MAC address;
- some ISPs require vendor specific MEs (350-399), which a stick may not be able to emulate.

On the Realtek based sticks, `OMCI_FAKE_OK` (reply OK to every OMCI message) and `OMCI_OLT_MODE` (vendor compatibility mode) can help, see for example the [ODI DFP-34X-2C2](/ont-odi-realtek-dfp-34x-2c2#gpon-omci-settings). Some ISPs keep the OMCI configuration in cache on the OLT: e.g. Chunghwa Telecom (Taiwan) can reset the line from its support. Some ISPs blacklist the PON port after a few failed attempts (e.g. Movistar Chile after 3 attempts), and the reset requires a technician[^anime4000].

# `O2`-`O5` loop

The ONU cycles between `O2` and `O5` without ever staying in `O5`[^rtl960x]:

- the OLT does not accept the ONU identity, as in the [Fake O5](#fake-o5-status) case, e.g. with some Fiberhome OLTs, or with PLDT (Philippines) when a SFU firmware is used instead of an HGU one;
- the received optical power is too low (e.g. ≤ -23 dBm): clean the connectors and check the RX power again.

::: danger Warning
If the ONU still does not work after checking all the values, stop: every failed attempt is logged by the OLT, and a misbehaving ONU can disrupt the whole PON tree, with service suspension or penalties from the ISP.
:::

<hr>

[^huawei]: *The Process for an ONU to go Online* https://forum.huawei.com/enterprise/en/the-process-for-an-onu-to-go-online-gpon-technical-posts-12/thread/462895-100181
[^standardgpon]: *G.984.3: Gigabit-capable passive optical networks (GPON): Transmission convergence layer specification* https://www.itu.int/rec/T-REC-G.984.3
[^anime4000]: *`O5` No Internet* https://github.com/Anime4000/RTL960x/blob/main/Docs/fakeO5.md
[^anime4000]: *`O5` No Internet* https://github.com/Anime4000/RTL960x/blob/main/Docs/fakeO5.md
[^rtl960x]: *Hacking RTL960x: Fake O5 State and O2-O5 Loop*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x
24 changes: 24 additions & 0 deletions gpon/mib.md
Original file line number Diff line number Diff line change
Expand Up @@ -360,6 +360,29 @@ The new ME introduced in G.988 [^G_988] do not have a description because G.988
| 453-65279 | Reserved for future standardization | | | | | | | | | | |
| 65280-65535 | Reserved for vendor-specific use | | | | | | | | | | |

# Most useful MEs to check the provisioning

When an ONT or a stick replaces the ISP one, these are the MEs to check to understand what the OLT has provisioned[^rtl960x_omci]:

| ME | Name | Notes |
| --- | -------------------------------- | ------------------------------------------------------------------------------- |
| 6 | Circuit pack | Type and number of ports emulated by the ONT |
| 7 | Software image | Software versions reported to the OLT |
| 11 | PPTP Ethernet UNI | Physical LAN ports, with the `AdminState` set by the OLT |
| 84 | VLAN tagging filter data | VLANs sent to the ONT by the OLT, e.g. the internet VLAN to use on the router |
| 131 | OLT-G | OLT vendor ID |
| 171 | Extended VLAN tagging operation | VLAN translation rules, which VLAN goes to which LAN port, see the [OMCI VLAN table parser](/gpon-omci-vlan-parser) |
| 256 | ONU-G | Vendor ID, version and serial number |
| 257 | ONU2-G | Equipment ID, OMCC version |
| 262 | T-CONT | |
| 263 | ANI-G | PON side |
| 264 | UNI-G | LAN side |
| 277 | Priority queue | |
| 309 | Multicast operations profile | VLANs used for the IPTV multicast traffic |
| 329 | Virtual Ethernet interface point | VEIP, used for VoIP, TR-069 or the router mode of the HGUs, see [PPTP and VEIP](/pptp_veip) |

The commands to read the MEs depend on the chipset, see the useful commands in the device pages (e.g. `omcicli mib get` on the [Realtek sticks](/ont-odi-realtek-dfp-34x-2c2#querying-a-particular-omci-me)), or decode the full OMCI log with [OMCI Wireshark](/omci-wireshark).


---

Expand All @@ -372,3 +395,4 @@ The new ME introduced in G.988 [^G_988] do not have a description because G.988
[^verizon_open_omci]: *Verizon OpenOMCI Specification, Version 1.00 June 30, 2017*
[^B-PON]: MIB for legacy B-PON

[^rtl960x_omci]: *OMCI MIB*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/OMCI_CLI.md
58 changes: 56 additions & 2 deletions gpon/ont.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,11 +26,12 @@ Currently, there are only a few main PON chipset vendors:
* RTL8290 (laser driver)
- Cortina Systems/Cortina Access (previously StorLink)
* Cortina QWCS8032E
* Cortina CA8289
* Cortina CA8289 (HGU, XGS-PON and 10G-EPON)
* CA8271 series (XGS-PON and 10G-EPON)
- CA8271A
- CA8271S
- CA8271NI
- CA8271N
- Lantiq (then Intel, then MaxLinear):
* Falcon series (GPON, End Of Life)
- PEB98010
Expand Down Expand Up @@ -77,12 +78,62 @@ HSGMII chipsets are relatively recent, they became more common starting in 2020,

The Realtek xPON ICs (RTL9601, RTL9602, RTL9603, RTL9607 and the RTL8290 laser driver) support GPON, EPON and Active Fiber mode, and are distributed in Europe by [MEV Elektronik](https://shop.mev-elektronik.com/product/xpon-ics/).

Community guides for the RTL960x based sticks and ONTs (OMCI cloning, flash variables, 4-port emulation, firmware and key generators): [Hacking RTL960x](https://github.com/fernandothx/Hacking-RTL960x-your-ISP-Fiber).
The RTL960x family[^rtl960x]:

| Chipset | Architecture | Type | Notes |
| --------- | ------------ | ------- | ----------------------------------------------------------- |
| RTL9601B | Lexra | SFU | First generation of GPON SFP ONTs, 1G only |
| RTL9601C1 | Lexra | SFU | Second generation of GPON SFP ONTs, 1G and partially 2.5G |
| RTL9601D | Lexra | SFU/HGU | Third generation of GPON SFP ONTs, stable 2.5G |
| RTL9602C | Lexra | SFU/HGU | Only in box ONTs |
| RTL9603C | MIPS | SFU/HGU | All-in-one, 1 core at 900 MHz |
| RTL9607C | MIPS | SFU/HGU | All-in-one, 2 cores at 1.15 GHz, USB and POTS |
| RTL9607DQ | ARM64 | SFU/HGU | All-in-one, 4 cores at 1 GHz, optional 2.5GbE and POTS |
| RTL9607F | ARM64 | SFU/HGU | All-in-one, 2 cores at 1 GHz, optional USB and POTS |

The most common RTL960x based SFP ONTs:

| Stick | Chipset | Flash | UNI | 4-port emulation | 2.5G |
| ------------------------------------------------------------ | --------- | ------ | ----------- | ---------------- | ------------------ |
| [V-SOL V2801F](/ont-vsol-v2801f) | RTL9601CI | 8 MB | VEIP & PPTP | ✅ | modded firmware |
| [T&W TWCGPON657](/ont-t-w-twcgpon657) | RTL9601CI | 16 MB | VEIP & PPTP | ✅ (V2801F fw) | modded firmware |
| [UFiber UF-Instant](/ont-ufiber-uf-instant) | RTL9601CI | 16 MB | PPTP | ❌ LAN 1 only | ❌ |
| [ODI DFP-34X-2C2 (Realtek)](/ont-odi-realtek-dfp-34x-2c2) | RTL9601D | 8 MB | VEIP & PPTP | ✅ SFU firmwares | ✅ |
| [Nokia G-010S-Q](/ont-nokia-g-010s-q) | RTL9601CI | 16 MB | PPTP | ❌ | ❌ |
| [LEOX LXT-010S-H](/ont-leox-lxt-010s-h) | RTL9601CI | 128 MB | | | ✅ |

Community guides for the RTL960x based sticks and ONTs (OMCI cloning, flash variables, 4-port emulation, 2.5G compatibility, firmwares and key generators): [Hacking RTL960x](https://github.com/Anime4000/RTL960x) by Anime4000 and its [forum](https://pururin.moe/viewtopic.php?t=7), and the [Hacking RTL960x your ISP Fiber](https://github.com/fernandothx/Hacking-RTL960x-your-ISP-Fiber) fork. The XGS-PON sticks based on the Realtek/Cortina CA8271x are documented in [CA8271x](https://github.com/YuukiJapanTech/CA8271x).

The useful commands for the Realtek sticks running the Luna SDK are in each device page, e.g. [ODI DFP-34X-2C2](/ont-odi-realtek-dfp-34x-2c2#gpon-onu-status).

::: warning End Of Life
Realtek announced that the RTL9601C and RTL9601CI will be End Of Life at the end of November 2026, and they will not get a replacement.
:::

## Cortina Chipsets

Cortina Access makes the 10G SoCs used by many XGS-PON and 10G-EPON ONTs and SFP+ sticks[^ca8271x]:

| Family | CPU | Applications |
| -------- | ------------------------- | --------------------------------------------------------------------------------------------------------- |
| CA8271 | MIPS R3000 | SFU ONTs and SFP+ sticks, with the minimum ports for a bridge and a low power CPU |
| CA8289 | AArch64 Cortex-A55, 4 cores | HGU ONTs, with multiple LAN PHYs, USB 3.0 and PCIe for the Wi-Fi |
| RTL9615C | AArch64 Cortex-A55, 2 cores | Low cost version of the CA8289 made by Realtek, with 2 XFI and 1 1G LAN, half the cores and memory channels |
| CA7774 | AArch64 Cortex-A53, 4 cores | HGU routers, like the CA8289 without the PON interface |

| SoC | Family | Code name | Applications |
| ---------- | ------ | --------- | -------------------------------------------------------------- |
| CA8271A | CA8271 | SATURN | PON SFU ONTs, cable TV RF |
| CA8271N | CA8271 | | PON SFU ONTs |
| CA8271NI | CA8271 | SATURN2 | PON SFU ONTs (e.g. [Nokia XS-010X-R](/xgs/ont-nokia-xs-010x-r)) |
| NLD0605APB | CA8271 | SATURN2 | CA8271NI made by NTT Electronics for the NTT 10G-EPON ONUs |
| CA8271S | CA8271 | SATURN | SFP+ sticks (e.g. [FS.com XGS-ONU-25-20NI](/xgs/ont-fs-XGS-ONU-25-20NI), [HiSense LTF7267-BHA+](/xgs/ont-hisense-ltf7267-bha+)) |
| CA8289 | CA8289 | VENUS | PON HGU ONTs |
| RTL9615C | CA8289 | TAURUS | Realtek XG-PON/XGS-PON ONTs |
| CA7774 | CA7774 | G3 | Routers without PON |

Some CA8271S sticks are the same hardware in an XGS-PON and in a 10G-EPON version, and can be switched between the two by replacing the firmware: CIG XG-99S ↔ [CIG XE-99S](/epon/CIG_XE-99S) and [HiSense LTF7267-BH+](/xgs/ont-hisense-ltf7267-bha+) ↔ [LTF7263-BH+](/epon/LTF7263-BH+). The community guides (root shell, `scfg.txt`, mtd dumps, SIEPON Package-A custom firmware) are in [Hacking CA8271x](https://github.com/YuukiJapanTech/CA8271x) by YuukiJapanTech.

## Lantiq Chipsets

Unfortunately Lantiq no longer exists as it has been bought out and dismembered by Intel. This purchase was a huge deal as at the time Lantiq was at the forefront of the GPON and xDSL chipset market.
Expand All @@ -101,3 +152,6 @@ Playing with ONTs can cause your serial number/PLOAM password to be banned and f
::: tip Tip
You can also help us with the content of this site, on each page you will find a button to edit on GitHub.
:::

[^rtl960x]: *Hacking RTL960x*, Anime4000/RTL960x https://github.com/Anime4000/RTL960x
[^ca8271x]: *Hacking CA8271x / CA8289x XGS-PON & 10G-EPON ONTs*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x
2 changes: 2 additions & 0 deletions ont-epon/CIG_XE-99S.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,6 +71,8 @@ The custom firmware is compatible with the following.
- Hisense LTF-7267-BH+ (GPON)
- Hisense LTF-7263-BH+

The stick is the same hardware of the CIG XG-99S (XGS-PON), and it can be switched to XGS-PON and back by replacing the firmware, see [Switching between XGS-PON and 10G-EPON](/xgs/ont-fs-XGS-ONU-25-20NI#switching-between-xgs-pon-and-10g-epon).

## Firmware versions
### Original firmware (SIEPON Package-C)
- CTC20220901
Expand Down
2 changes: 2 additions & 0 deletions ont-epon/LTF7263-BH+.md
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,8 @@ The custom firmware is compatible with the following.
- CIG XE-99S
- Hisense LTF-7263-BH+

The stick is the same hardware of the HiSense LTF7267-BH+ (XGS-PON), and it can be switched to XGS-PON and back by replacing the firmware, see [Switching between XGS-PON and 10G-EPON](/xgs/ont-hisense-ltf7267-bha+#switching-between-xgs-pon-and-10g-epon).

## Firmware versions
### Original firmware (SIEPON Package-C)
- 20210421024332
Expand Down
40 changes: 39 additions & 1 deletion ont-xgs/ont-fs-XGS-ONU-25-20NI.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ parent: FS.com
| Model | XGS-ONU-25-20NI |
| ODM | CIG |
| ODM Product Code | XG-99S |
| Chipset | Cortina CA8271A |
| Chipset | Cortina CA8271S |
| Flash | MX35LF1GE4AB 128MB |
| RAM | 128MB |
| CPU | Taroko V0.2 (MIPS) |
Expand Down Expand Up @@ -487,6 +487,8 @@ ERROR: can't get kernel image!
SATURN#
```

If the stick still boots, the uboot prompt can be reached while `Hit any key to stop autoboot` is displayed: on the old models any key works, while the new CIG models (XGS-ONU-25-20NI, XE-99S, ...) require to send the raw bytes `0x1b 0x1d 0x0f 0x0b`, e.g. with a Tera Term macro or PComm Terminal Emulator (found by [@rssor](https://github.com/rssor))[^ca8271x_mtd].

Download the stick's mtd dump from [GitHub.](https://github.com/YuukiJapanTech/CA8271x/tree/main/mtd)

Enable NAND with the following command:
Expand Down Expand Up @@ -536,11 +538,47 @@ SATURN# spi_nand write 0x81000000 0x000003b00000 0x2800000

When the stick turns back on, it will boot with the transferred kernel and rootfs.

## Switching between XGS-PON and 10G-EPON

The XG-99S (and its OEMs, like this stick) and the [CIG XE-99S](/epon/CIG_XE-99S) (10G-EPON) are the same hardware, so the stick can be switched between XGS-PON and 10G-EPON by replacing the firmware: changing only `scfg.txt` is not enough[^ca8271x_switch].

::: danger
Backup all the partitions first, and never remove the power while writing the partitions: a bricked stick can be repaired only via UART, see [Bricked stick Repair](#bricked-stick-repair).
:::

The following must be replaced, using the [images](https://github.com/YuukiJapanTech/CA8271x/tree/main/XG-XE_Switch) of the CA8271x repository (they contain the GPON serial number `GPON2350004b`, login password `UzwugGYT`, and the EPON MAC address `CC:CF:83:59:FF:F8`):

| Partition / item | Content |
| ------------------------- | --------------------------------------------------------------------------- |
| `mtd2` / `mtd5` | `dtb` |
| `mtd3` / `mtd6` | `kernel` |
| `mtd4` / `mtd7` | `rootfs` |
| `mtd9` / `mtd10` | `mfginfo` |
| `/userdata` | `userdata.tar.gz` (only when switching from XG-99S to XE-99S) |
| uboot `setpartlayout`, `more_args` | partition layout and boot partition (`rootfs` is `/dev/mtdblock12` for XGS-PON, `/dev/mtdblock11` for 10G-EPON) |

Each partition is written with:

```sh
# flash_eraseall /dev/mtd3
# flashcp -v kernel.bin /dev/mtd3
```

The full procedure, with the uboot environment for both directions, is in the [CA8271x repository](https://github.com/YuukiJapanTech/CA8271x/tree/main/XG-XE_Switch). The current mode is shown in the kernel log:

```sh
# grep "ca-pon: load PON_MAC_MODE:" /var/log/messages
Jan 1 00:00:13 saturn-sfpplus-eng user.warn kernel: [ 13.843922] ca-pon: load PON_MAC_MODE: XGSPON
```

# Known Bugs
- There is a bug in the `register_id` command in the `misc` CLI option that changes the value of `pon_passwd` (LOID Password) instead of `register_id` (PLOAM).


# Miscellaneous Links
- [GitHub - CA8271x](https://github.com/YuukiJapanTech/CA8271x)
- [FS.com XGS-ONU-25-20NI / CIG XG-99S Modification Utility](https://github.com/rssor/fs_xgspon_mod)

[^ca8271x_mtd]: *Dump images & Bricked Stick Repair*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x/tree/main/mtd
[^ca8271x_switch]: *Switch between XGS and 10GE*, YuukiJapanTech/CA8271x https://github.com/YuukiJapanTech/CA8271x/tree/main/XG-XE_Switch

Loading
Loading