Adding an ONT with trunk port to Huawei SmartAX MA5683T
Adding an ONT with a trunk port on Huawei SmartAX MA5683T means the ONT’s Ethernet output carries every VLAN tagged, instead of one VLAN untagged. This is useful behind a router or switch that reads the VLAN tags itself, rather than a plain home router that expects a single untagged connection. The example below uses a TP-Link GP110 in transparent mode with DHCP off; the same profiles work for most single-port Ethernet ONTs. See Huawei’s official SmartAX MA5683T support page for hardware and firmware details.
Create and tag the VLANs on the uplink port, build an ont-srvprofile with transparent enable, build an ont-lineprofile with one GEM port and VLAN mapping per VLAN, register the ONT with ont add, then add a service-port for each VLAN. The ONT’s Ethernet port then outputs every VLAN tagged.
Before you start
- The OLT is already configured and other ONTs are already online.
- The customer’s downstream device (router, switch, or access point) can read tagged VLANs on its WAN or trunk port — this setup will not work with a plain single-VLAN home router.
- The ONT is set to transparent/bridge mode with DHCP off. A TP-Link GP110 is used here; other single-port Ethernet ONTs are configured the same way.
How to add a trunk port ONT with tagged VLANs on Huawei MA5683T
Step 1 – Connect and enter configuration mode
enable configStep 2 – Create the VLANs and tag them on the uplink port
Every VLAN that will reach this ONT must be created on the OLT and tagged on the port it comes in on:
vlan 207 smart vlan 226 smart vlan 300 smart vlan 302 smart port vlan 207 0/8 0 port vlan 226 0/8 0 port vlan 300 0/8 0 port vlan 302 0/8 0Step 3 – Point user VLANs at the DHCP server (skip your management VLAN)
If billing/DHCP is reachable at an address like this:
dhcp-server 0 ip 192.168.1.1…then also enable it on each user VLAN interface, or those VLANs won’t hand out IP addresses:
interface vlanif226 dhcp-server 0 quit interface vlanif300 dhcp-server 0 quit interface vlanif302 dhcp-server 0 quitNote: VLAN 207 is skipped here because it’s used for management with static IPs. Skip DHCP relay on any VLAN you manage the same way.Step 4 – Create a DBA profile to limit outbound speed
dba-profile add profile-id 11 profile-name "dba-profile_11" type3 assure 1024 max 1000000Step 5 – Create the ONT service profile in transparent (trunk) mode
This is what makes the ONT pass every VLAN tagged instead of translating one VLAN to untagged:
ont-srvprofile gpon profile-name TAG ont-port eth 1 transparent enable multicast-forward untag multicast mode olt-control port vlan eth 1 transparent commit quitStep 6 – Create the ONT line profile with one GEM port per VLAN
ont-lineprofile gpon profile-name TEST tcont 4 dba-profile-id 11 gem add 1 eth tcont 4 gem add 2 eth tcont 4 gem add 3 eth tcont 4 gem add 4 eth tcont 4 gem mapping 1 1 vlan 207 gem mapping 2 1 vlan 226 gem mapping 3 1 vlan 300 gem mapping 4 1 vlan 302 commit quitStep 7 – Find the new ONT’s serial number
display ont autofind allStep 8 – Enter the GPON board’s interface and add the ONT
interface gpon 0/4 ont add 4 0 sn-auth "54504C47D8970FE8" omci ont-lineprofile-name TEST ont-srvprofile-name TAG desc TEST quitStep 9 – Add a service-port for each VLAN
service-port 450 vlan 207 gpon 0/4/4 ont 0 gemport 1 multi-service user-vlan 207 service-port 451 vlan 226 gpon 0/4/4 ont 0 gemport 2 multi-service user-vlan 226 service-port 452 vlan 300 gpon 0/4/4 ont 0 gemport 3 multi-service user-vlan 300 service-port 453 vlan 302 gpon 0/4/4 ont 0 gemport 4 multi-service user-vlan 302
ONT compatibility with multiple tagged VLANs
Not every ONT model handles many GEM ports and VLAN mappings the same way. On an Alcatel I-010G-V ONT, only 11 VLANs worked reliably — entries added from gem add 12 onward did not pass traffic. Switching to a TP-Link GP110 resolved it. If you need more than a handful of tagged VLANs on one trunk port, confirm your ONT model’s limit first.
Command reference
| Command | Purpose |
|---|---|
vlan <id> smart | Create a VLAN |
port vlan <id> <frame/slot> <port> | Tag a VLAN on the uplink port |
dhcp-server <id> ip <ip> | Point the OLT at a DHCP/billing server |
interface vlanif<id> / dhcp-server <id> | Enable DHCP relay on a VLAN interface |
dba-profile add profile-id <id> ... | Create a speed (DBA) profile |
ont-srvprofile gpon profile-name <name> + transparent enable | Create a service profile that passes all VLANs tagged |
ont-lineprofile gpon profile-name <name> | Create a line profile with one GEM port per VLAN |
display ont autofind all | Find an unregistered ONT’s serial number |
ont add <port> <id> sn-auth "<sn>" ... | Register the ONT with its profiles |
service-port <id> vlan <vlan> gpon <f/s/p> ont <id> gemport <gem> ... | Bind each VLAN to its GEM port |
Frequently asked questions
What is a trunk port ONT?
It’s an ONT configured so its Ethernet output carries multiple VLANs, all tagged, instead of one VLAN delivered untagged. The device connected to it (a router or switch) must be able to read those VLAN tags.
Why use transparent mode instead of VLAN translation?
transparent enable and port vlan eth 1 transparent make the ONT pass VLAN tags straight through rather than translating one VLAN to untagged traffic, which is what a trunk connection needs.
Do all VLANs need DHCP relay enabled?
No. Skip it on any VLAN you manage with static IPs, such as a management VLAN. Enable dhcp-server on each VLAN interface that should hand out addresses automatically.
Why did some VLANs stop working after VLAN 11 on my ONT?
Some ONT hardware has a limit on how many GEM ports and VLAN mappings it can handle. On an Alcatel I-010G-V, only 11 worked; switching to a TP-Link GP110 fixed it. Check your ONT model’s specifications if you need many tagged VLANs on one port.
Can other single-port Ethernet ONTs use this same setup?
Yes. The profiles and commands are the same; only the ONT’s own transparent/bridge mode setting needs to be confirmed in its own configuration interface.
