DIY ONT with GPON SFP stick and openWRT

Groudon

Member
Joined
May 4, 2013
Messages
341
Reaction score
99
Correct. We can not replace the ISP issued ONT/ONR here in Singapore.
I've actually had success using a GPON ONT SFP module with M1, and it was fairly straightforward. I believe it should be the same for StarHub too, or at least the telcos that are using Huawei OLTs. Unfortunately, the SFP module does run a little hot past my comfort level :)
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
31,691
Reaction score
9,035
I've actually had success using a GPON ONT SFP module with M1, and it was fairly straightforward. I believe it should be the same for StarHub too, or at least the telcos that are using Huawei OLTs. Unfortunately, the SFP module does run a little hot past my comfort level :)

Ah, that is very interesting to know. Thanks.

I though the ISPs are not given out the super admin password for the ONT so that it is difficult to replicate the settings in the GPON ONT SFP modules.
 

rockyleong

Senior Member
Joined
Sep 15, 2009
Messages
602
Reaction score
18
I've actually had success using a GPON ONT SFP module with M1, and it was fairly straightforward. I believe it should be the same for StarHub too, or at least the telcos that are using Huawei OLTs. Unfortunately, the SFP module does run a little hot past my comfort level :)
No extra stuff required? Mind sharing this over PM if its not comfortable?
 

Groudon

Member
Joined
May 4, 2013
Messages
341
Reaction score
99
No extra stuff required? Mind sharing this over PM if its not comfortable?
There's some minor settings required:
1) You need to clone the GPON_SN from old ONT. I did this with the V2801F chip, you can find guides on Lowyat and on Github (https://github.com/Anime4000/RTL960x). [surprisingly they are quite active in this area]
2) VLAN 1103, priority 1. On Mikrotik devices, you can refer to this guide: https://www.cflee.com/posts/routeros-tagged-m1-fibre/ ; please note that doing this type of manipulation will be done in software on the Mikrotik devices, so FastTrack won't work [i.e. hopefully you have a fast enough CPU in your device so you can still get full/near-to-full speeds. Probably not much of a concern for pfSense/opnSense devices].

I didn't explore the voice VLAN config for now, which I believe is VL1107, since M1 has already locked down their ONTs further which makes it difficult to retrieve the SIP settings.
 

BlonkBloink

Member
Joined
May 17, 2022
Messages
434
Reaction score
183
My ONT is Alcatel Lucent ONT from MR, what is the procudure? I cant even find thr managment page for the ONT
 

Groudon

Member
Joined
May 4, 2013
Messages
341
Reaction score
99
My ONT is Alcatel Lucent ONT from MR, what is the procudure? I cant even find thr managment page for the ONT
Alcatel's procedure would be much different, you probably will need to retrieve the SLID from the current ONT as well.
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,673
Reaction score
3,322
There's some minor settings required:
1) You need to clone the GPON_SN from old ONT. I did this with the V2801F chip, you can find guides on Lowyat and on Github (https://github.com/Anime4000/RTL960x). [surprisingly they are quite active in this area]
2) VLAN 1103, priority 1. On Mikrotik devices, you can refer to this guide: https://www.cflee.com/posts/routeros-tagged-m1-fibre/ ; please note that doing this type of manipulation will be done in software on the Mikrotik devices, so FastTrack won't work [i.e. hopefully you have a fast enough CPU in your device so you can still get full/near-to-full speeds. Probably not much of a concern for pfSense/opnSense devices].

I didn't explore the voice VLAN config for now, which I believe is VL1107, since M1 has already locked down their ONTs further which makes it difficult to retrieve the SIP settings.

The MikroTik export script looks pretty straight forward (bridge, vlan), just a BR-filter will do the trick. Such routing might not run on software firewall which uses NICs (I may be wrong) unless it is direct handover (from ISP upstream) to client side equipment. So may end up still need to deploy your firewall behind the router.

If you going all out MikroTik without the firewall, really worth a shot.​
 
Last edited:

Mach3.2

Great Supremacy Member
Joined
Apr 8, 2011
Messages
72,405
Reaction score
2,465
There's some minor settings required:
1) You need to clone the GPON_SN from old ONT. I did this with the V2801F chip, you can find guides on Lowyat and on Github (https://github.com/Anime4000/RTL960x). [surprisingly they are quite active in this area]
2) VLAN 1103, priority 1. On Mikrotik devices, you can refer to this guide: https://www.cflee.com/posts/routeros-tagged-m1-fibre/ ; please note that doing this type of manipulation will be done in software on the Mikrotik devices, so FastTrack won't work [i.e. hopefully you have a fast enough CPU in your device so you can still get full/near-to-full speeds. Probably not much of a concern for pfSense/opnSense devices].

I didn't explore the voice VLAN config for now, which I believe is VL1107, since M1 has already locked down their ONTs further which makes it difficult to retrieve the SIP settings.
Just the GPON_SN from the label on the ONT?

No need root the ONT to retrieve credentials ah? 🤔
 

Groudon

Member
Joined
May 4, 2013
Messages
341
Reaction score
99
The MikroTik export script looks pretty straight forward (bridge, vlan), just a BR-filter will do the trick. Such routing might not run on software firewall which uses NICs (I may be wrong) unless it is direct handover (from ISP upstream) to client side equipment. So may end up still need to deploy your firewall behind the router.

If you going all out MikroTik without the firewall, really worth a shot.​
yes, I believe you are right. Also, another issue is that these SFPs are not really very standard, and thus, not all devices accept it (so far no issues on an old Intel X520 NIC and plays well on the RB4011, but it won't work at all on the CCR1072 despite having both 10G/1.25G support).

Just the GPON_SN from the label on the ONT?

No need root the ONT to retrieve credentials ah? 🤔
Sent the commands from my end. Shouldn't be necessary.
 

BlonkBloink

Member
Joined
May 17, 2022
Messages
434
Reaction score
183

Im sure my SLID got sth wrong
Im on static, port 1 is WAN port 4 ins management, Im on the management interface
 

BlonkBloink

Member
Joined
May 17, 2022
Messages
434
Reaction score
183


SSH open, ran a ip addr to check if the management interface can access WAN, apparently not cos its in bridge mode
 

BlonkBloink

Member
Joined
May 17, 2022
Messages
434
Reaction score
183
aiyo wth MR so insecure. the management interface can access other peoples ONT and all is default creds
 

BlonkBloink

Member
Joined
May 17, 2022
Messages
434
Reaction score
183
also the ONT MR gave me was 2nd hand.... plastic all yellow and the seal was broken somemore.. anyone else experience this? cos last time singtel they give all relatively new one(ZTE/Huawei)
 

BlonkBloink

Member
Joined
May 17, 2022
Messages
434
Reaction score
183


This is veryyyyyyy bad..... those interfaces arent secure and can even reboot other peoples things... MR needs to actually do something. shld do vuln reporting but im sure they know and jsut dont care
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ. Forum members and moderators are responsible for their own posts.

Please refer to our Community Guidelines and Standards, Terms of Service and Member T&Cs for more information.
Top