Configuring Huawei MA5608T / EA5800-X2

Configuring Huawei MA5608T / EA5800-X2: Initial OLT Setup Guide

Last updated: September 2026

Applies to: Huawei SmartAX MA5608T and EA5800-X2. Most commands also work on the MA5600T, MA5683T, and MA5800 series; prompts and defaults can differ slightly between firmware versions.

TL;DR: Log in over console at 9600 baud, confirm your boards, set a management VLAN + IP, create a separate admin user, restrict SSH/Telnet/SNMP access, then build your user VLAN and DBA/line/service profiles. Register each customer with ont add + service-port, and finish with save.

This guide uses the Huawei MA5608T as the example device. Every step below is copy-ready — change only the red values to match your network.

Values in red (usernames, passwords, IPs, VLAN IDs, serial numbers) are examples — replace them with your own.

Step 1 – Connect and Log In

Connect to the OLT with a console cable at a speed of 9600. The standard login is root with password admin or admin123 (newer firmware usually uses admin123). More login methods and default credentials for every model are in the Huawei OLT Complete Setup Guide.

Once logged in, go into privileged and configuration mode:

enable config

Step 2 – View the Current Configuration

Show the full running configuration:

display current-configuration

Filter the output to lines containing a keyword:

display current-configuration | include TEXT

Step 3 – Change the Root Password and Create an Admin User

Change the password of the root user (enter root when asked for the user name):

terminal user password

Create a second administrator. This lets you and a colleague stay logged in at the same time (one as root, one under the new account), and keeps your actions separate from the shared root login:

terminal user name

The OLT then asks for these values (type them at each prompt — this block is for reference, not for pasting):

User Name(length<6,15>):madankc User Password(length<6,15>):******** Confirm Password(length<6,15>):******** User profile name(<=15 chars)[root]: User's Level: 1. Common User 2. Operator 3. Administrator:3 Permitted Reenter Number(0--4):4 User's Appended Info(<=30 chars): Adding user successfully Repeat this operation? (y/n)[n]:n

Tip: Press Enter to accept the default profile name and to leave the appended info blank. Level 3 is Administrator, and 4 is the highest number of simultaneous sessions this account may hold. Want a recognizable hostname on the OLT too? See How to Rename Your Huawei OLT.

Step 4 – Check and Confirm Installed Boards

See which boards are installed and check the device health:

display board 0 display board 0/0 display board 0/2 display board 0/4 display version display patch all display io-packetfile information display temperature 0/0 display temperature 0/2 display cpu 0/0 display cpu 0/2

Example output of display board 0:

------------------------------------------------------------------------- SlotID BoardName Status SubType0 SubType1 Online/Offline ------------------------------------------------------------------------- 0 H805GPBD Normal 1 2 H801MCUD Active_normal CPCA 3 4 H801MPWC Normal 5 -------------------------------------------------------------------------

By the way, the H801MCUD control board has 4 ports of 1 Gb/s, while the H801MCUD1 has 2 ports of 10 Gb/s and 2 ports of 1 Gb/s. Pick the one that matches your uplink.

If a board is installed but not listed as added, confirm it:

board confirm 0/0 board confirm 0/4

If necessary, restart the GPON board:

board reset 0/0

Heads up: Resetting a GPON board interrupts service for every ONT connected to it. An unconfirmed board can look healthy (LEDs normal) while its service ports don’t work — always run board confirm for new boards.

Step 5 – Management VLAN, IP Address, and Default Route

If you don’t need it, delete the standard IP address from the meth port:

interface meth0 undo ip address quit

Create a VLAN for management, pass it to the uplink port, and assign the OLT’s IP address:

vlan 208 smart port vlan 208 0/2 0 interface vlanif208 ip address 192.168.2.5 255.255.255.0 quit

Specify the default gateway so the OLT’s IP address is reachable from other networks:

ip route-static 0.0.0.0 0.0.0.0 192.168.2.1

Note: 0/2 0 means uplink port 0 on the control board in slot 2. Adjust it if your uplink is on a different port or slot.

Step 6 – Restrict SSH, Telnet, and SNMP Access

Specify the IP addresses that are allowed to connect to the device. Each command takes a start and an end IP — use the same address twice for a single host:

SSH:

sysman ip-access ssh 192.168.5.5 192.168.5.5 sysman ip-access ssh 192.168.1.1 192.168.1.2 sysman firewall ssh enable

Telnet:

sysman ip-access telnet 192.168.5.5 192.168.5.5 sysman ip-access telnet 192.168.1.1 192.168.1.2 sysman firewall telnet enable

SNMP:

sysman ip-access snmp 192.168.5.5 192.168.5.5 sysman ip-access snmp 192.168.1.1 192.168.1.2 sysman firewall snmp enable

Don’t lock yourself out: Add your own management PC’s IP before running the firewall ... enable lines. Once the firewall is on, any address not in the list is blocked (the console cable always still works). Prefer SSH over Telnet where you can, since Telnet sends passwords in clear text.

Step 7 – Configure SNMP and SNMP Traps

Set the community strings and device information:

snmp-agent community write WRITE_COMMUNITY snmp-agent community read READ_COMMUNITY snmp-agent sys-info contact madankc snmp-agent sys-info location madankc snmp-agent sys-info version v2c

Send traps to your NMS (for example a Huawei U2000 server):

snmp-agent target-host trap-hostname U2000SERVER address 192.168.5.3 udp-port 162 trap-paramsname NMS snmp-agent target-host trap-paramsname NMS v2C securityname NMS snmp-agent trap enable standard

Security: Use different strings for the read and write communities, and never reuse a username or a guessable word. SNMP v2c sends community strings in clear text, which is why the SNMP access list in Step 6 matters.

Step 8 – Configure Time Zone and NTP

Set the time zone, daylight saving (if your country uses it), and the NTP server:

timezone GMT+ 02:00 time dst start 04-01 00:00:00 end 10-28 00:00:00 adjust 01:00 ntp-service unicast-server 192.168.2.7 source-interface vlanif208

Nepal: use timezone GMT+ 05:45 and skip the time dst line — Nepal doesn’t observe daylight saving. The source-interface must be the management interface you created in Step 5.

Step 9 – Create the User VLAN

Create the VLAN your subscribers will use, pass it to the uplink port, and verify it:

vlan 944 smart port vlan 944 0/2 0 display vlan 944

Step 10 – Create DBA, Service, and Line Profiles

Next, create a 1 Gb/s speed profile, plus profiles for a single-port ONT and the client VLAN.

DBA (speed) profile:

display dba-profile all dba-profile add profile-id 15 profile-name "dba-profile_15" type3 assure 1024 max 1000000

ONT service profile (single Ethernet port, VLAN translation):

display ont-srvprofile gpon all ont-srvprofile gpon profile-id 10 profile-name "vlan 944" ont-port eth 1 port vlan eth 1 translation 944 user-vlan 944 commit quit

ONT line profile (T-CONT, GEM port, and VLAN mapping):

display ont-lineprofile gpon all ont-lineprofile gpon profile-id 10 profile-name "vlan 944" tcont 4 dba-profile-id 15 gem add 1 eth tcont 4 gem mapping 1 0 vlan 944 commit quit

Note: In the DBA profile, assure 1024 and max 1000000 are in kbps — roughly 1 Mb/s guaranteed and about 1 Gb/s maximum. Run the display ... all commands first so your profile IDs don’t collide with existing ones.

Step 11 – Enable Loop Protection and ONT Autofind

Turn on loop protection:

ring check enable ring check resume-interval 30

Enable ONT autofind on the GPON port (harmless if it’s already on):

interface gpon 0/0 port 0 ont-auto-find enable quit

Step 12 – Add the First ONT

This example adds the first ONT on the first GPON port (port 0 — numbering starts at 0). The serial number comes from the autofind list, and ont add 0 0 means GPON port 0, ONT ID 0.

display ont autofind all interface gpon 0/0 display ont autofind 0 ont add 0 0 sn-auth "414C434CF2A40000" omci ont-lineprofile-id 10 ont-srvprofile-id 10 desc "madankc.com.np" ont port native-vlan 0 0 eth 1 vlan 944 priority 0 quit service-port 1 vlan 944 gpon 0/0/0 ont 0 gemport 1 multi-service user-vlan 944

Learn more: Step-by-step ONT registration with screenshots is covered in Adding ONU to Huawei SmartAX MA5683T, and the ont port native-vlan command is explained in Huawei 5680 OLT Native VLAN Configuration Method.

Step 13 – View, Troubleshoot, and Remove an ONT

View information about an ONT (port 0, ONT ID 0):

interface gpon 0/0 display ont info 0 0 display ont optical-info 0 0 display ont version 0 0 display statistics ont-eth 0 0 ont-port 1 quit

View the client’s MAC address by its service-port:

display mac-address service-port 1

Remove an ONT — always delete its service-port first:

undo service-port 1 interface gpon 0/0 ont delete 0 0 quit

Find ONTs with an erroneous configuration:

diagnose display ont failed-configuration 0/0/0 all quit

Step 14 – Save the Configuration and Run Health Checks

Save the configuration (the OLT does not save it automatically unless you set up auto-save):

save

Find out which SFP module is in a PON port (for example C+ or C++):

interface gpon 0/0 display port state 0 quit

If there are two control cards, check the synchronization status:

display data sync state

View environment monitoring (EMU) information:

interface emu 0 display fan environment info display fan system parameter quit

Add and inspect an ESC environment unit:

emu add 1 H801esc 0 0 "GERM4815T" display emu display emu baudrate interface emu 1 display esc system parameter display esc environment info quit

Command Reference

CommandPurpose
display current-configurationShow the running configuration
terminal user nameCreate a new user (interactive prompts)
terminal user passwordChange a user’s password, for example root
display board 0List installed boards and their status
board confirm 0/0Confirm (add) an installed board
board reset 0/0Restart a board (interrupts service)
vlan <id> smartCreate a VLAN
port vlan <id> 0/2 0Pass a VLAN to the uplink port
ip route-static 0.0.0.0 0.0.0.0 <gateway>Set the default route
sysman ip-access ssh|telnet|snmp <start> <end>Allow an IP range to manage the OLT
snmp-agent community read|write <name>Set SNMP community strings
ntp-service unicast-server <ip> source-interface vlanif<id>Sync time from an NTP server
dba-profile add ...Create a DBA (speed) profile
ont-srvprofile gpon ...Create an ONT service profile
ont-lineprofile gpon ...Create an ONT line profile
ring check enableTurn on loop protection
display ont autofind allList ONTs waiting to be registered
ont add <port> <id> sn-auth "<SN>" ...Register an ONT by serial number
service-port <id> vlan <vlan> gpon 0/0/0 ont <id> ...Bind the ONT to a VLAN and GEM port
display ont info <port> <id>View ONT status (in interface gpon mode)
display mac-address service-port <id>View the client’s MAC address
undo service-port <id>Remove a service-port (do this before ont delete)
ont delete <port> <id>Delete an ONT
display ont failed-configuration 0/0/0 allFind ONTs with configuration errors (in diagnose mode)
display port state <port>Check the SFP class (C+ / C++) of a PON port
display data sync stateCheck control-card synchronization
saveSave the configuration

FAQ

What is the default login for the MA5608T and EA5800-X2?
Connect by console at 9600 baud and log in as root. The password is admin on older firmware and admin123 on newer firmware. Change it right away with terminal user password. Defaults for other models are listed in the Huawei OLT Complete Setup Guide.
Why create a separate admin user instead of using root?
A dedicated account lets two administrators be logged in at the same time (one as root, one under the new name) and makes it easier to tell who ran which command. It also means you can lock down or change the root password without disrupting daily work.
What is the difference between the H801MCUD and H801MCUD1 control boards?
The H801MCUD has 4 ports of 1 Gb/s. The H801MCUD1 has 2 ports of 10 Gb/s and 2 ports of 1 Gb/s, so choose it when your uplink is 10G.
How do I register a new ONT on the OLT?
Run display ont autofind all to get the serial number, add it with ont add inside interface gpon, set the native VLAN with ont port native-vlan, then bind it with service-port (see Step 12). A full walkthrough is in Adding ONU to Huawei SmartAX MA5683T.
How do I delete an ONT safely?
Remove its service-port first with undo service-port <id>, then go into interface gpon 0/0 and run ont delete <port> <id>. Deleting in the reverse order leaves an orphaned service-port behind.
How can I tell whether a PON port uses a C+ or C++ SFP module?
Enter interface gpon 0/0 and run display port state 0. The output shows the optical module class installed in that port.

Read Also