Configuring Huawei SmartAX MA5683T /EA5800-X2

Huawei MA5683T configuration starts at the console port and ends with a working ONU that has a service-port. This guide covers the management IP, VLANs, DBA, line and service profiles, ONU registration, uplink setup, and the security and monitoring commands used on the Huawei SmartAX MA5683T / EA5800-X2 OLT.

Written by Madan Kc

Quick answer: Connect to the console (9600 8N1), set a management VLAN and IP, confirm the boards, then create the user VLAN, a DBA profile, a line profile and a service profile. Enable auto-find on the PON port, add the ONU with ont add, create a service-port for it, and run save.

Before you start

  • Console settings: baud rate 9600, 8 data bits, 1 stop bit, no flow control, terminal type VT100 or auto.
  • Example chassis: slots 0, 1, 4 and 5 hold GPBD boards, 6 and 7 hold SCUN control boards, 8 holds a GICF uplink board, 9 holds an X2CS board and 10 holds a PRTE board (slots 2 and 3 are empty). Slot numbers in the commands below follow this layout, so adjust them to your own chassis.
  • ONUs used with this setup include Huawei EchoLife HG8010, ZTE ZXA10 F601, Foxgate G2001R and Huawei EchoLife HG8245C (WiFi), among others.
  • All values in red are examples. Replace them with your own VLANs, IPs, slots and serial numbers.

Huawei MA5683T configuration step by step

  1. Connect to the console and set a management IP

    Connect to the CON port, then create a management VLAN (207 in this example) and give its VLAN interface an IP address. Use your own VLAN and addressing.

    enable
    config
    vlan 207 smart
    port vlan 207 0/8 0
    interface vlanif 207
    ip address 192.168.5.5 255.255.255.0
    quit

    Instead of an in-band VLAN interface you can use the dedicated management (meth) port, but that needs an extra cable to the OLT.

  2. Add a default route (optional)

    Add a default route if the management IP must be reachable from other networks.

    ip route-static 0.0.0.0 0.0.0.0 192.168.5.1
  3. Create a Telnet user

    In config mode, start the user wizard. It asks for a user name, a password, a password confirmation and a privilege level (1 = user, 2 = operator, 3 = admin).

    terminal user name
    Choose your own strong credentials and change any default password after the first login. For more on accounts, see Create and manage users on the Huawei SmartAX MA5683T.
  4. Confirm the new boards

    After inserting GPON, uplink or control boards, confirm them so the OLT brings them into service. Confirm slots one by one, or the whole frame at once, and check the result.

    board confirm 0/5
    board confirm 0/8
    board confirm 0/9
    display board
    board confirm 0
    display board 0

    To remove a board entry or restart a board:

    board remove 0/9
    board reset 0/5
    In the example chassis the boards were inserted while the OLT was powered on. Follow Huawei hardware guidance for hot insertion on your unit.
  5. Create the user VLAN and add it to the uplink

    Create a smart VLAN for subscribers (228 here) and attach it to the uplink port 0/8/0.

    vlan 228 smart
    port vlan 228 0/8 0
    display vlan 228

    To remove one VLAN, or a range, from a port:

    undo port vlan 228 0/8 0
    undo port vlan 228 to 240 0/8 0
  6. Create a DBA profile

    This example adds DBA profile 20 with an assured rate of 1024 and a maximum of 1000000 (values in kbit/s, so roughly a 1 Gbit/s upstream limit).

    dba-profile add profile-id 20 type3 assure 1024 max 1000000
    display dba-profile all

    Default profiles 1 to 9 exist and can be inspected and modified:

    display dba-profile profile-id 1
    dba-profile modify profile-id 1
    On this unit, DBA profile 1 could not be changed once ONTs were already registered on the OLT, whichever profile they used. Create a new profile instead.
  7. Create the ONT line profile

    The line profile maps the T-CONT and GEM port to the user VLAN.

    ont-lineprofile gpon profile-id 10
    tcont 4 dba-profile-id 20
    gem add 1 eth tcont 4
    mapping-mode vlan
    gem mapping 1 0 vlan 228
    commit
    quit
  8. Create the ONT service profile

    The service profile defines the ONT Ethernet port and its VLAN.

    ont-srvprofile gpon profile-id 10
    ont-port eth 1
    port vlan eth 1 228
    commit
    quit
  9. Find and add the ONU

    Open the GPON board interface, enable auto-find on the PON port, list the discovered ONUs, then add yours by serial number. In ont add, the two numbers are the PON port and the ONT ID.

    interface gpon 0/5
    port 0 ont-auto-find enable
    display ont autofind 0
    ont add 0 0 sn-auth SERIAL-NUMBER omci ont-lineprofile-id 10 ont-srvprofile-id 10 desc TEXT
    ont port native-vlan 0 0 eth 1 vlan 228
  10. Configure the uplink port

    Set the native VLAN and the network role on the uplink board (GIU interface 0/8 in this chassis), then check port state.

    interface giu 0/8
    native-vlan all vlan 228
    network-role 0 uplink
    display port state all
    display traffic-suppress
  11. Add a service-port for each ONU

    Every ONU needs its own service-port. Without it the ONU registers but passes no traffic.

    service-port 1 vlan 228 gpon 0/5/0 ont 0 gemport 1 multi-service user-vlan 228

    The service-port index also lets you look up the MAC addresses learned behind an ONU:

    display mac-address service-port 1
    display mac-address all | include e0cb-4ec3-7c44
    display mac-address port 0/4/3
    display mac-address
  12. Verify the ONU

    From the GPON interface, check registration, IP configuration, traffic, optical levels, firmware version and Ethernet counters.

    display ont info 0 0
    display ont ipconfig 0
    display ont traffic 0 0 1
    display ont optical-info 0 1
    display ont version 0 1
    display statistics ont-eth 0 1 ont-port 1
  13. Save the configuration

    Configuration changes are lost on reboot unless you save.

    save

    To review the running configuration, or only the lines that contain a keyword:

    display current-configuration
    display current-configuration | include TEXT

Optional: DHCP, SNMP and security settings

DHCP (only needed for Layer 3)

dhcp-server 0 ip 10.0.0.1
dhcp proxy enable
interface vlanif 228
dhcp-server 0

SNMP

snmp-agent community read TEXT
snmp-agent sys-info version v2c
snmp-agent sys-info contact TEXT
snmp-agent sys-info location TEXT

More detail: SNMP configuration on Huawei OLT.

Loop protection

ring check enable
ring check resume-interval 30

Anti-DoS protection

security anti-dos enable
security anti-dos control-packet policy deny
security anti-dos control-packet rate 0/5/0 default
display security anti-dos control-packet rate 0/5/0
display security dos-blacklist all

Other security features

security anti-icmpattack enable
security anti-ipattack enable
security anti-macduplicate enable
display log security
display security config
display security conflict

Monitoring, alarms and removing an ONU

Health and statistics:

display board 0/5
display cpu 0/5
display resource
display security config
display temperature
display gpon statistics ethernet 0/5 0
display igmp config global
display sysuptime

CPU overload control (default value 10):

display cpu-overload-control parameter
cpu-overload-control parameter adjustfactor 20

Alarms: show or hide alarm output in the console, and list active alarms (useful when a faulty SFP is plugged in):

alarm output all
undo alarm output all
display alarm active all

To remove an ONU, delete its service-port first, then the ONU itself:

undo service-port 1
interface gpon 0/5
ont delete 0 0
Clearing the configuration wipes the OLT. The draft shows the command below with “active/standby” as the target, so check the exact syntax on your firmware and back up first. Never run it on a live network.
erase flash data active/standby

Notes and compatibility

  • Commands, menus and defaults depend on the OLT firmware version and the boards installed. Check output on your own unit.
  • Reported default login is root / admin; other passwords seen on some units are huawei123, admin123 and Huawei@123. Change the password after first login.
  • The default management IP reported for this chassis is 10.11.104.2.
  • If a media converter is connected in place of an ONT on a PON branch, every ONT on that branch may stop working. A faulty ONT that constantly transmits at a high optical level can cause the same problem.
  • You do not have to type commands in full. Press TAB and the CLI completes them.
  • Official reference: Huawei SmartAX MA5600T series documentation on Huawei Enterprise Support (some downloads need an account).

Command reference

CommandWhat it does
board confirm 0/5Bring a newly inserted board into service
vlan 228 smartCreate a smart VLAN
port vlan 228 0/8 0Add a VLAN to an uplink port
dba-profile add profile-id 20 type3 ...Create a DBA profile
ont-lineprofile gpon profile-id 10Create an ONT line profile
ont-srvprofile gpon profile-id 10Create an ONT service profile
port 0 ont-auto-find enableEnable ONU auto-discovery on a PON port
display ont autofind 0List discovered ONUs
ont add 0 0 sn-auth ...Register an ONU by serial number
service-port 1 vlan 228 gpon 0/5/0 ont 0 ...Create the per-ONU service-port
display ont info 0 0Show ONU status
display mac-address service-port 1MAC addresses behind an ONU
undo service-port 1Delete a service-port (before deleting the ONU)
ont delete 0 0Delete an ONU
display alarm active allList active alarms
saveSave the configuration

Frequently asked questions

What is the default login for the Huawei MA5683T?

Many units use root with password admin, and some use huawei123, admin123 or Huawei@123. It depends on the firmware, so change the password after your first login.

What console settings does the MA5683T use?

Baud rate 9600, 8 data bits, 1 stop bit, no flow control, terminal type VT100 or auto.

Why does my ONU register but get no internet?

Each ONU needs its own service-port. Check that the VLAN in the service-port, the line profile mapping and the uplink port all match.

How do I delete an ONU on the MA5683T?

Delete its service-port first with undo service-port, then open the GPON interface and run ont delete with the port and ONT ID.

How do I bring a new board into service?

Run board confirm 0/5 for a single slot, or board confirm 0 for the whole frame, then check with display board.

Why can I not change DBA profile 1?

On this unit, DBA profile 1 could not be modified once ONTs were registered on the OLT, whichever profile they used. Create and use a new profile instead.

Related guides