Adding an ONT with trunk port to Huawei SmartAX MA5683T

Adding an ONT with a trunk port on Huawei SmartAX MA5683T means the ONT’s Ethernet output carries every VLAN tagged, instead of one VLAN untagged. This is useful behind a router or switch that reads the VLAN tags itself, rather than a plain home router that expects a single untagged connection. The example below uses a TP-Link GP110 in transparent mode with DHCP off; the same profiles work for most single-port Ethernet ONTs. See Huawei’s official SmartAX MA5683T support page for hardware and firmware details.

Written by Madan Kc

Quick answer

Create and tag the VLANs on the uplink port, build an ont-srvprofile with transparent enable, build an ont-lineprofile with one GEM port and VLAN mapping per VLAN, register the ONT with ont add, then add a service-port for each VLAN. The ONT’s Ethernet port then outputs every VLAN tagged.

Before you start

  • The OLT is already configured and other ONTs are already online.
  • The customer’s downstream device (router, switch, or access point) can read tagged VLANs on its WAN or trunk port — this setup will not work with a plain single-VLAN home router.
  • The ONT is set to transparent/bridge mode with DHCP off. A TP-Link GP110 is used here; other single-port Ethernet ONTs are configured the same way.

How to add a trunk port ONT with tagged VLANs on Huawei MA5683T

  1. Step 1 – Connect and enter configuration mode

    enable
    config
  2. Step 2 – Create the VLANs and tag them on the uplink port

    Every VLAN that will reach this ONT must be created on the OLT and tagged on the port it comes in on:

    vlan 207 smart
    vlan 226 smart
    vlan 300 smart
    vlan 302 smart
    port vlan 207 0/8 0
    port vlan 226 0/8 0
    port vlan 300 0/8 0
    port vlan 302 0/8 0
  3. Step 3 – Point user VLANs at the DHCP server (skip your management VLAN)

    If billing/DHCP is reachable at an address like this:

    dhcp-server 0 ip 192.168.1.1

    …then also enable it on each user VLAN interface, or those VLANs won’t hand out IP addresses:

    interface vlanif226
    dhcp-server 0
    quit
    interface vlanif300
    dhcp-server 0
    quit
    interface vlanif302
    dhcp-server 0
    quit
    Note: VLAN 207 is skipped here because it’s used for management with static IPs. Skip DHCP relay on any VLAN you manage the same way.
  4. Step 4 – Create a DBA profile to limit outbound speed

    dba-profile add profile-id 11 profile-name "dba-profile_11" type3 assure 1024 max 1000000
  5. Step 5 – Create the ONT service profile in transparent (trunk) mode

    This is what makes the ONT pass every VLAN tagged instead of translating one VLAN to untagged:

    ont-srvprofile gpon profile-name TAG
    ont-port eth 1
    transparent enable
    multicast-forward untag
    multicast mode olt-control
    port vlan eth 1 transparent
    commit
    quit
  6. Step 6 – Create the ONT line profile with one GEM port per VLAN

    ont-lineprofile gpon profile-name TEST
    tcont 4 dba-profile-id 11
    gem add 1 eth tcont 4
    gem add 2 eth tcont 4
    gem add 3 eth tcont 4
    gem add 4 eth tcont 4
    gem mapping 1 1 vlan 207
    gem mapping 2 1 vlan 226
    gem mapping 3 1 vlan 300
    gem mapping 4 1 vlan 302
    commit
    quit
  7. Step 7 – Find the new ONT’s serial number

    display ont autofind all
  8. Step 8 – Enter the GPON board’s interface and add the ONT

    interface gpon 0/4
    ont add 4 0 sn-auth "54504C47D8970FE8" omci ont-lineprofile-name TEST ont-srvprofile-name TAG desc TEST
    quit
  9. Step 9 – Add a service-port for each VLAN

    service-port 450 vlan 207 gpon 0/4/4 ont 0 gemport 1 multi-service user-vlan 207
    service-port 451 vlan 226 gpon 0/4/4 ont 0 gemport 2 multi-service user-vlan 226
    service-port 452 vlan 300 gpon 0/4/4 ont 0 gemport 3 multi-service user-vlan 300
    service-port 453 vlan 302 gpon 0/4/4 ont 0 gemport 4 multi-service user-vlan 302

ONT compatibility with multiple tagged VLANs

Not every ONT model handles many GEM ports and VLAN mappings the same way. On an Alcatel I-010G-V ONT, only 11 VLANs worked reliably — entries added from gem add 12 onward did not pass traffic. Switching to a TP-Link GP110 resolved it. If you need more than a handful of tagged VLANs on one trunk port, confirm your ONT model’s limit first.

Command reference

CommandPurpose
vlan <id> smartCreate a VLAN
port vlan <id> <frame/slot> <port>Tag a VLAN on the uplink port
dhcp-server <id> ip <ip>Point the OLT at a DHCP/billing server
interface vlanif<id> / dhcp-server <id>Enable DHCP relay on a VLAN interface
dba-profile add profile-id <id> ...Create a speed (DBA) profile
ont-srvprofile gpon profile-name <name> + transparent enableCreate a service profile that passes all VLANs tagged
ont-lineprofile gpon profile-name <name>Create a line profile with one GEM port per VLAN
display ont autofind allFind an unregistered ONT’s serial number
ont add <port> <id> sn-auth "<sn>" ...Register the ONT with its profiles
service-port <id> vlan <vlan> gpon <f/s/p> ont <id> gemport <gem> ...Bind each VLAN to its GEM port

Frequently asked questions

What is a trunk port ONT?

It’s an ONT configured so its Ethernet output carries multiple VLANs, all tagged, instead of one VLAN delivered untagged. The device connected to it (a router or switch) must be able to read those VLAN tags.

Why use transparent mode instead of VLAN translation?

transparent enable and port vlan eth 1 transparent make the ONT pass VLAN tags straight through rather than translating one VLAN to untagged traffic, which is what a trunk connection needs.

Do all VLANs need DHCP relay enabled?

No. Skip it on any VLAN you manage with static IPs, such as a management VLAN. Enable dhcp-server on each VLAN interface that should hand out addresses automatically.

Why did some VLANs stop working after VLAN 11 on my ONT?

Some ONT hardware has a limit on how many GEM ports and VLAN mappings it can handle. On an Alcatel I-010G-V, only 11 worked; switching to a TP-Link GP110 fixed it. Check your ONT model’s specifications if you need many tagged VLANs on one port.

Can other single-port Ethernet ONTs use this same setup?

Yes. The profiles and commands are the same; only the ONT’s own transparent/bridge mode setting needs to be confirmed in its own configuration interface.

Related guides