Configuring Layer 2 Interoperation Service Ports on OLT

Configuring Layer 2 interoperation service ports on a Huawei OLT lets ONTs in the same VLAN exchange traffic directly, which is useful when you need to network two offices over one ISP link. This guide creates a VLAN, adds a service-port per ONT, and enables user-bridging and protocol tunnelling in a VLAN service profile. It is based on a computer networking setup with two ONTs on one OLT.

Written by Madan Kc, who runs DG Link Network, a fiber internet provider in Nepal

Quick answer: Create a smart VLAN and add it to the uplink, create a service-port for each ONT in that VLAN, then make a VLAN service profile with user-bridging enable (plus any tunnel options you need) and bind it to the VLAN with vlan bind service-profile.

Before you start

  • Console or Telnet access to the OLT, in config mode.
  • Two ONTs already registered on the OLT. Their slots, ports and IDs go in the service-port commands.
  • Values in red are examples; use your own VLAN, ports and IDs.
  • Commands can vary by OLT model and firmware. The syntax here matches the Huawei MA5600 series style.

How to configure Layer 2 interoperation service ports on a Huawei OLT

  1. Create the VLAN

    Create a smart VLAN that will carry the traffic between the two ONTs (300 in this example).

    vlan 300 smart
  2. Add the VLAN to the uplink port

    Attach the VLAN to the OLT uplink port.

    port vlan 300 0/19 0
  3. Create a service-port for each ONT

    Create one service-port per ONT, both in the same VLAN. Here ONT 1 is on port 0/3/1 and ONT 2 is on port 0/4/1.

    service-port 301 vlan 300 gpon 0/3/1 ont 1 gemport 12 multi-service user-vlan 300
    service-port 302 vlan 300 gpon 0/4/1 ont 2 gemport 12 multi-service user-vlan 300
    The ONTs must already be registered, and the GEM port used here must exist in their line profile. See Adding ONU to Huawei SmartAX MA5683T.
  4. Create the VLAN service profile and enable user-bridging

    user-bridging enable is the mandatory line: it allows traffic between users in the VLAN. The tunnel lines let the named protocol packets pass through the VLAN transparently.

    vlan service-profile profile-id 1
    user-bridging enable
    bpdu tunnel enable
    ospf tunnel enable
    rip tunnel enable
    vtp-cdp tunnel enable
    commit
    quit
    Enable only the tunnel options your customer equipment needs. user-bridging enable is the one you must have.
  5. Bind the service profile to the VLAN

    Attach the profile to the VLAN so the settings take effect.

    vlan bind service-profile 300 profile-id 1

Verify the configuration

Check the profile and VLAN

display vlan service-profile profile-id 1
display vlan 300

Notes

Good to know

Command reference

CommandWhat it does
vlan 300 smartCreate the smart VLAN
port vlan 300 0/19 0Add the VLAN to the uplink port
service-port 301 vlan 300 gpon ...Create a service-port for an ONT
vlan service-profile profile-id 1Create the VLAN service profile
user-bridging enableAllow traffic between users in the VLAN
bpdu tunnel enablePass BPDU packets through the VLAN
vlan bind service-profile 300 profile-id 1Bind the profile to the VLAN

Frequently asked questions

What is Layer 2 interoperation between ONTs on a Huawei OLT?

It lets ONTs in the same VLAN exchange Layer 2 traffic with each other, for example to link two offices in one network. By default traffic between ONUs in a smart VLAN is blocked.

What does user-bridging enable do?

It is set in the VLAN service profile and allows traffic between users in that VLAN. In this configuration it is mandatory.

When do I need the tunnel commands?

The bpdu, ospf, rip and vtp-cdp tunnel options let those protocol packets pass through the VLAN. Enable only the ones your customer equipment uses.

Do I need this if the ONTs are in different subnets?

No. If clients use different subnets and gateways, traffic can pass through the router. Enable proxy ARP on the core router instead.

Related guides

#l2networking