User Guide
User Guide
XPON ONT
HG1
www.tendacn.com
Document version: V1.0
Copyright Statement
© 2023 Shenzhen Tenda Technology Co., Ltd. All rights reserved.
is a registered trademark legally held by Shenzhen Tenda Technology Co., Ltd. Other
brand and product names mentioned herein are trademarks or registered trademarks of their
respective holders. Copyright of the whole product as integration, including its accessories and
software, belongs to Shenzhen Tenda Technology Co., Ltd. No part of this publication can be
reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language
in any form or by any means without the prior written permission of Shenzhen Tenda Technology
Co., Ltd.
Disclaimer
Pictures, images and product specifications herein are for references only. To improve internal
design, operational function, and/or reliability, Tenda reserves the right to make changes to the
products without obligation to notify any person or organization of such revisions or changes.
Tenda does not assume any liability that may occur due to the use or application of the product
described herein. Every effort has been made in the preparation of this document to ensure
accuracy of the contents, but all statements, information and recommendations in this document
do not constitute a warranty of any kind, express or implied.
Document version: V1.0
Preface
Thank you for choosing Tenda! This user guide walks you through all functions of the XPON ONT.
Conventions
The typographical elements that may be found in this document are defined as follows.
Item Presentation Example
The symbols that may be found in this document are defined as follows.
Symbol Meaning
This format is used to highlight a procedure that will save time or resources.
Technical support
Contact us if you need more help. We will be glad to assist you as soon as possible.
Website: www.tendacn.com
Revision history
Tenda is constantly searching for ways to improve its products and documentation. The following
table indicates any changes that might have been made since this guide was first published.
i
Document version: V1.0
Contents
1 Typical application scenarios................................................................................................... 1
3 Web UI ................................................................................................................................. 15
5 LAN ...................................................................................................................................... 23
6 WAN .................................................................................................................................... 24
ii
Document version: V1.0
7 Services ................................................................................................................................ 29
8 Advance ............................................................................................................................... 50
8.2.3 DHCPv6............................................................................................................................ 56
9 Diagnostics ........................................................................................................................... 59
10 Admin.................................................................................................................................. 63
iii
Document version: V1.0
10.4.2 Restore previous configuration of the ONT .................................................................. 66
10.7 ACL.......................................................................................................................................... 70
11 Statistics .............................................................................................................................. 74
Appendixes .............................................................................................................................. 75
iv
Document version: V1.0
1 Typical application
scenarios
1.1 Overview
The ONT type is divided into two main classes, including Single Family Unit (SFU) and
Home Gateway Unit (HGU).
1
Document version: V1.0
If you use the Ethernet cable to connect the LAN port of the ONT to the WAN of the router, determine
whether to configure the router according to the actual ONT type.
‒ HGU: You can access the internet without configuring the router.
‒ SFU: You can configure the router to dial-up with the related parameters provided by your ISP.
2
Document version: V1.0
‒ When the ONT is under bridge mode, you can only access the internet through the downstream
device used for setting up internet access.
‒ If you use the Ethernet cable to connect the LAN port of the ONT to the computer without the
router, you can access the internet without configuring the computer.
Under bridge mode, the ONT acts as a bridging device between your LAN and your ISP. The ONT
works under bridge mode by default.
When the ONT is set to the bridge mode, you can configure the related parameters of the ONT
according to your ISP and your own need.
---End
After the configuration is completed, you can configure a computer or a router to dial-up.
3
Document version: V1.0
Configure your computer to access the internet according to the parameters provided by your ISP.
PPPoE is used for illustration here.
4
Document version: V1.0
Step 7 Enter the PPPoE User name and Password provided by your ISP and click Connect.
---End
After the configuration is completed, you can access the internet on the computer.
◼ Configure internet access on a router
Assume that your ISP provides you with the PPPoE user name and password.
Step 1 Configure the ONT.
Step 2 Connect the WAN port of router to a LAN port of the ONT using an Ethernet cable.
Step 3 Refer to the quick installation guide or user guide of your router to configure the internet
access.
---End
After the configuration is completed, you can access the internet through the router.
5
Document version: V1.0
Step 5 Configure WAN IP Settings or/and IPv6 WAN Setting based on the IP protocol you choose.
− In the WAN IP Settings part, set Type to Fixed IP and configure other parameters as
required.
− In the IPv6 WAN Setting part, set Address Mode to Static and configure other
parameters as required.
6
Document version: V1.0
After the configuration is completed, you can access the internet through the LAN port of the ONT,
or by connecting a router (connection type: DHCP/dynamic IP) to a LAN port of the ONT.
7
Document version: V1.0
Step 5 Configure WAN IP Settings or/and IPv6 WAN Setting based on the IP protocol you choose.
− In the WAN IP Settings part, set Type to DHCP and configure other parameters as
required.
− In the IPv6 WAN Setting part, set Type to Slaac and configure other parameters as
required.
After the configuration is completed, you can access the internet through the LAN port of the ONT,
or by connecting a router (connection type: DHCP/dynamic IP) to a LAN port of the ONT.
8
Document version: V1.0
Step 6 Enter the PPPoE UserName and Password provided by your ISP in PPP Settings.
Step 7 (Optional) If you set IP Protocol to IPv6 or IPv4/IPv6, enter required parameters in IPv6
WAN Setting.
Step 8 Click Apply Changes.
---End
After the configuration is completed, you can access the internet through the LAN port of the ONT,
or by connecting a router (connection type: DHCP/dynamic IP) to a LAN port of the ONT.
9
Document version: V1.0
After the configuration is completed, you can access the internet through the router.
If you use the Ethernet cable to connect the LAN port of the ONT to the computer without the router,
you can refer to configure internet access on a computer (Skip step 1) to configure the computer to
dial-up.
10
Document version: V1.0
11
Document version: V1.0
2.2 Appearance
2.2.1 Indicators, ports, button and jack
◼ LED indicators
12
Document version: V1.0
Port/Button/Jack Description
Optical fiber port
PON
Used to connect to optical network through a fiber cord.
LAN port
LAN
Used to connect to a router, switch or computer.
Reset button
When the PWR LED indicator lights solid on, use an object with a spike to hold
RST the button down for longer than 10 seconds and release it. All LED indicators light
off several seconds later. When the PWR LED indicator lights solid on again, the
ONT is reset.
Power jack.
PWR
Use the included power adapter to connect the device to a power source.
Used to mount the device onto the wall.
Wall-mounting materials are self-prepared. Recommended specifications of the
expansion bolts and screws you may use are as follows:
Wall-mounting hole
[Expansion bolt] Inner diameter: 2.4 mm; Length: 26.4 mm.
[Screws] Quantity: 2; Thread diameter: 3 mm; Length: 14 mm; Head diameter:
5.2 mm.
13
Document version: V1.0
2.2.2 Label
The label is located on the bottom panel of the ONT. See the following figure for details.
14
Document version: V1.0
3 Web UI
3.1 Login
A maximum of three users can log in to the web UI at the same time.
Procedure:
Step 4 Power on the ONT using the included power adapter.
Step 5 Connect a computer to a LAN port of the ONT using an Ethernet cable.
Step 6 Start a web browser on a connected device and visit the IP address of the ONT
(192.168.1.1 by default). Enter your User Name and Password, and click Login.
----End
15
Document version: V1.0
If the above page does not appear, try the following solutions:
Ensure that the ONT is powered on properly.
If a wired device, such as a computer, is used for configuration, ensure that the wired device is
connected to a LAN port of the router properly, and is set to Obtain an IP address automatically
and Obtain DNS server address automatically.
Restore the ONT to factory settings and try again.
16
Document version: V1.0
3.2 Logout
The ONT logs you out when you:
− Click the Logout button on the upper-right corner of the web UI, or click Logout in
Admin > Logout.
− Perform no operation within 20 minutes.
17
Document version: V1.0
18
Document version: V1.0
4 Status
In this module, you can:
− View device status of the ONT.
− View IPv6 status of the ONT.
− View PON status of the ONT.
To access the page, log in to the web UI of the ONT and navigate to Status > Status > Device.
19
Document version: V1.0
Parameter description
Parameter Description
Specifies the basic system information of the ONT, including the device
System name, device type, uptime, software version, hardware version, magic
number, CPU usage, memory usage, and name servers.
Specifies the LAN IP address of the ONT, which is also the IP address used
IP Address
to log in to the web UI of the ONT.
LAN Subnet Mask Specifies the LAN subnet mask of the ONT.
Configuration
DHCP Server Specifies whether to enable the DHCP server of the ONT.
MAC Address Specifies the MAC address of the ONT’s LAN port.
WAN Protocol Specifies the channel mode used by the WAN port.
Configuration IP Address Specify the IP address and gateway address that the ONT obtains after
Gateway you set up a WAN connection successfully.
20
Document version: V1.0
Parameter description
Parameter Description
21
Document version: V1.0
Parameter description
Parameter Description
Vendor Name Specifies the vendor name of the ONT.
Temperature Specifies the current chip temperature of the ONT.
Voltage Specifies the current voltage of the optical module of the ONT.
PON Status
Tx Power Specify the transmitted and received optical power of the ONT over the
Rx Power PON port.
Bias Current Specifies the current bias current of the optical module of the ONT.
22
Document version: V1.0
5 LAN
In this module, you can configure the LAN IPv4 settings of the ONT.
To access the page, log in to the web UI and navigate to LAN > LAN > LAN Interface Settings.
Parameter description
Parameter Description
Specifies the IPv4 LAN address of the ONT, which is also the IPv4 address for logging in
IP Address
to the web UI of the ONT.
Subnet Mask Specifies the IPv4 LAN subnet mask of the ONT.
23
Document version: V1.0
6 WAN
After you have registered the ONT successfully, you can set up the WAN connection.
To access the configuration page, log in to the web UI of the ONT and navigate to WAN > WAN >
PON WAN. Required settings for WAN connections differ with the channel modes, connection
types and IP protocols that you choose.
Parameter description
Parameter Description
24
Document version: V1.0
Parameter Description
This parameter is available only when the Enable VLAN function is enabled. It specifies
802.1p_Mark the 802.1P priority. Data with a larger priority value takes a higher priority to be
processed.
Specifies the mode that you used to set up the WAN connection, including Bridged,
IPoE and PPPoE.
⚫ Bridged: Select this type when this device only serves as a modem, and you want to
set up a dial-up connection or enter other internet parameters directly on your
computer for internet access.
Channel Mode
⚫ IPoE: Select DHCP if your ISP does not provide any parameters to you for internet
access, and select Fixed IP if your ISP provides a static IP address and other related
information to you for internet access.
⚫ PPPoE: Select this type if your ISP provides a user name and password to you for
internet access.
Admin Status Specifies whether to enable this WAN connection.
25
Document version: V1.0
Parameter description
Parameter Description
Specifies the method used by the ONT to obtain WAN IP address information.
⚫ Fixed IP: You need to configure the local IP address, remote IP address (gateway
Type address) and other related information manually.
⚫ DHCP: The ONT obtains WAN IP address information automatically. Choose this type if
your ISP does not provide related parameters.
Local IP Address
If you select Fixed IP for Type, you should manually enter the IP address and related
Remote IP Address
information provided by your ISP.
Subnet Mask
IP Unnumbered Used to make multiple ports to share one IP address.
If the IP address is obtained through DHCP, you can select Request DNS to obtain the
Request DNS
DNS server address automatically.
If the IP address obtaining type is Fixed IP or Request DNS function is disabled when the
Primary DNS Server IP address obtaining type is DHCP, you should enter the DNS server address provided by
your ISP.
Secondary DNS
Server If the ISP only provides one DNS server address, you can leave the secondary DNS blank.
26
Document version: V1.0
Parameter description
Parameter Description
Specifies how the WAN IPv6 address of the ONT is obtained, including Slaac and Static.
⚫ Slaac: Stateless Address Autoconfiguration (SLAAC) is a dynamic allocation method of
Address Mode IPv6 address, which enables the ONT to auto-generate IPv6 addresses with local
information and those from the router advertisement.
⚫ Static: You need to enter parameters related to IPv6 address manually.
Specifies the IPv6 address and prefix length provided by your ISP when you select Static
IPv6 Address
for Address Mode.
Specifies the IPv6 gateway address of the ONT when you select Static for Address
IPv6 Gateway
Mode.
27
Document version: V1.0
Parameter description
Parameter Description
UserName
Specify the PPPoE user name and password for settings up the WAN connection.
Password
Specifies the PPPoE service name used by the PPPoE server to verify the legitimacy of
the ONT.
Service-Name
If your ISP did not provide a service name, leave this field blank. Otherwise, a dial failure
may occur.
28
Document version: V1.0
7 Services
7.1 Service
7.1.1 DHCP
Overview
The DHCP server can automatically assign IP addresses, subnet masks, gateway addresses and DNS
to LAN clients. When it is disabled, you need to manually configure the IP address information on
the LAN device to access the internet. Disable it only when necessary.
To access the configuration page, log in to the web UI of the ONT and navigate to Services >
Service > DHCP.
Parameter description
Parameter Description
Specifies the status of the DHCP server.
DHCP Mode ⚫ NONE: The DHCP server is disabled.
⚫ DHCP Server: The DHCP server is enabled.
Specifies the current LAN IP address of the ONT, which is also the IP address used to
LAN IP address
log in to the web UI of the ONT.
IP Pool Range Specifies the range of IP addresses that a DHCP server can assign to LAN clients.
29
Document version: V1.0
Parameter Description
Specifies the valid time of the IP addresses assigned by the DHCP server of the ONT
Max Lease Time
to the DHCP clients.
Specifies how the ONT assigns DNS server addresses to LAN clients.
⚫ Use DNS Relay: The ONT forwards the DNS query packets from LAN clients to an
DNS option external DNS server.
⚫ Set Manually: You need to set the DNS server address manually. You can set three
DNS servers at most, and at least one is required.
Used to assign fixed IP addresses to certain LAN clients based on their MAC
addresses. Devices with the MAC address connected to the ONT get the same IP
MAC-Based address every time.
Assignment
Please note the format of the MAC address. Use “-” to separate every two characters
in the MAC address.
Solution: You can reserve a fixed IP address for the FTP server to reach the goal.
Assume that:
− Fixed IP address reserved for the FTP server: 192.168.1.136
− MAC address of the FTP server host: D4:61:DA:1B:CD:89
Procedure:
Step 1 Log in to the web UI of the ONT.
Step 2 Navigate to Services > Service > DHCP.
Step 3 Click MAC-Based Assignment.
Step 4 Set MAC Address in the format of D4-61-DA-1B-CD-89.
Step 5 Enter 192.168.1.136 in Assigned IP Address.
30
Document version: V1.0
----End
Now you can access resources on the FTP server free from the influence of the dynamic IP address.
31
Document version: V1.0
Parameter description
Parameter Description
Enable Specifies whether the rule takes effect after being added.
Specifies the DDNS service provider. The ONT supports DynDNS.org, TZO and
NO-IP.
DDNS Provider You need to register and purchase services from one of these service
providers and use the parameters provided by the service provider to
configure the function on the ONT.
Hostname Specifies the hostname registered with the DDNS service.
Interface Specifies the WAN interface on which the dynamic DNS rule takes effect.
UserName Specify the user name and password registered on a DDNS service provider
for logging in to the DDNS service.
These fields are only available when the service provider is set to DynDNS.org
Password
and NO-IP.
Email Specify the Email and key you registered with the DDNS service provider.
Key These fields are only available when the service provider is set to TZO.
⚫ Add: It is used to add a new dynamic DNS rule.
Operation ⚫ Modify: It is used to modify existing dynamic DNS rules.
⚫ Remove: It is used to delete existing dynamic DNS rules.
Select Used to select existing rules to modify or remove them.
State Specifies the status of a rule, including Enable and Disable.
Service Specifies the DDNS service of the ONT.
Specifies the connection status of the DDNS, including Successfully updated,
Status
Connection error and Authentication failure.
Solution: You can configure the DDNS plus port forwarding functions to reach the goal.
Assume that the information of the FTP server includes:
− IP address: 192.168.1.136
− Service port: 21
The information of the registered DDNS service:
− Service provider: DynDNS.org
− User name: JohnDoe
32
Document version: V1.0
− Password: JohnDoe123456
− Domain name: o2849z7222.zicp.vip
Please ensure that the ONT obtains a public IP address. This function may not work on a host with an
IP address of a private network or an intranet IP address assigned by ISPs that start with 100. Common
IPv4 addresses are classified into class A, class B and class C. Private IP addresses of class A range from
10.0.0.0 to 10.255.255.255. Private IP addresses of class B range from 172.16.0.0 to 172.31.255.255.
Private IP addresses of class C range from 192.168.0.0 to 192.168.255.255.
Procedure:
Step 1 Log in to the web UI of the ONT.
Step 2 Add a Dynamic DNS rule.
1. Navigate to Services > Service > Dynamic DNS.
2. Select Enable.
3. Choose a service provider in DDNS Provider, which is DynDNS.org in this example.
4. Enter the Hostname, which is o2849z7222.zicp.vip in this example.
5. Select the WAN interface that the port forwarding rule applies to, which is ppp0 in this
example.
6. Enter the user name and password, which are JohnDoe and JohnDoe123456 in this
example.
7. Click Add.
33
Document version: V1.0
After the configuration is completed, users from the internet can access the FTP server by visiting
“Intranet service application layer protocol name://Domain name”. If the remote port number is
not the same as the default intranet service port number, the accessing address should be:
“Intranet service application layer protocol name://Domain name:Remote port number”.
Open the file explorer on a computer that can access the internet, and visit
ftp://o2849z7222.zicp.vip.
Enter the user name and password to access the resources on the FTP server.
34
Document version: V1.0
After the configuration is completed, if internet users still cannot access the FTP server, try the
following methods:
Ensure that the local port number configured in the port forwarding function is the same as the
intranet service port number set on the server.
Close the firewall, antivirus software and security guards on the host of the FTP server and try
again.
35
Document version: V1.0
7.2 Firewall
7.2.1 ALG
Application Layer Gateway (ALG) is a software component that manages specific application
protocols such as Session Initiation Protocol (SIP) and File Transfer Protocol (FTP). The ALG acts as
an intermediary between the internet and an application server and allows or denies traffic of
certain types to the application server. It does this by intercepting and analyzing the specified
traffic, allocating resources, and defining dynamic policies to allow traffic to pass through.
To access the configuration page, log in to the web UI of the ONT and navigate to Services >
Firewall > ALG.
Parameter description
Parameter Description
The File Transfer Protocol (FTP) is a standard network protocol used for the transfer of
ftp computer files between a client and server on a computer network.
The users on LAN can share resources on the FTP server on WAN only when it is selected.
The Layer Two Tunneling Protocol (L2TP) is an extension of the Point-to-Point Tunneling
Protocol (PPTP) used by an Internet Service Provider (ISP) to enable the operation of a Virtual
l2tp Private Network (VPN) over the Internet.
If you select L2TP protocol when you create a VPN connection on your computer in the LAN
of the ONT, it takes effect only when this function is enabled.
The Internet Protocol Security (IPsec) is a secure network protocol suite that authenticates
and encrypts the packets of data to provide secure encrypted communication between two
ipsec computers over an IP network. It is used in Virtual Private Networks (VPNs).
If you select IPsec protocol when you create a VPN connection on your computer in the LAN
of the ONT, it takes effect only when this function is enabled.
The Point-to-Point Tunneling Protocol (PPTP) is an obsolete method for implementing virtual
private networks. PPTP has many well-known security issues.
pptp
If you select the PPTP protocol when you create a VPN connection on your computer in the
LAN of the ONT, it takes effect only when this function is enabled.
The Trivial File Transfer Protocol (TFTP) is a simple file transfer protocol that allows a client to
tftp
get a file from or put a file onto a remote host.
36
Document version: V1.0
Parameter description
Parameter Description
Specify the default action for the outgoing (LAN -> WAN) or incoming (WAN ->
LAN) data.
⚫ Deny: By default, all incoming traffic is blocked. However, some traffic can
access by specific filtering rules. The incoming filtering rules allow traffic to
Default Action
pass in some conditions.
⚫ Allow: By default, all outgoing traffic from LAN is allowed, but some can be
blocked by specific filtering rules. Outgoing filtering rules can block outgoing
traffic under some conditions.
Specifies the protocol adopted by data to be filtered.
⚫ TCP: TCP protocol.
⚫ UDP: UDP protocol.
Protocol
⚫ ICMP: ICMP protocol.
⚫ TCP/UDP: TCP protocol and UDP protocol.
⚫ ANY: Any protocol.
37
Document version: V1.0
Parameter Description
Since the source port of the data packet is changeable, it is recommended that
the port be set to 1 to 65535 or left blank.
Specifies the destination IP address of the packets. The settings of Destination IP
Address and Subnet Mask determine which servers are affected by this rule.
⚫ When Filtering Direction is set to LAN→WAN, this parameter specifies the
Destination IP Address internet server’s IP address to be affected.
⚫ When Filtering Direction is set to WAN→LAN, this parameter specifies the
LAN server’s IP address to be affected.
⚫ When this parameter is left blank, all IP addresses are covered.
Specifies the subnet mask of the destination IP address. The settings of
Subnet Mask Destination IP Address and Subnet Mask determine which servers are affected
by this rule.
Specifies the destination port of the packets. Its setting determines which
Port services are affected by this rule.
The destination port is only for TCP and UDP protocol.
38
Document version: V1.0
To access the configuration page, log in to the web UI of the ONT and navigate to Services >
Firewall > MAC Filtering. The rule added is shown in Current Filter Table.
Parameter description
Parameter Description
Solution: You can configure the MAC address filter function to reach the goal.
Procedure:
Step 1 Log in to the web UI of the ONT.
Step 2 Navigate to Services > Firewall > MAC Filtering.
Step 3 Set MAC Filtering to Enable, and click Apply Changes.
Step 4 Set Mode to BlackList, and click Apply Changes.
Step 5 Set Source MAC Address to 8CEC4BB30493, and click Add.
39
Document version: V1.0
---End
In this example, after the configuration is completed, the device added cannot access the internet
through the ONT.
40
Document version: V1.0
Parameter description
Parameter Description
Local IP Specifies the IP address of the LAN host which runs the service to be accessed.
Local Port Specifies the port used for the LAN service.
Protocol Specifies the service protocol. Select Both if you are uncertain about the service type.
Specifies the IP address of the host which needs to access the local service.
Remote IP
When it is left blank, users with any IP address can access the local server.
Remote Port Specifies the port that internet users use to access the local service.
Interface Specifies the WAN interface through which internet users access the local service.
Goal: Open the FTP server to internet users and enable family members who are not at home to
access the resources of the FTP server from the internet.
Solution: You can configure the port forwarding function to reach the goal.
41
Document version: V1.0
Please ensure that the router obtains an IP address from the public network. This function may
not work on a host with an IP address of a private network or an intranet IP address assigned by
ISPs that start with 100. Common IPv4 addresses are classified into class A, class B and class C.
Private IP addresses of class A range from 10.0.0.0 to 10.255.255.255. Private IP addresses of class
B range from 172.16.0.0 to 172.31.255.255. Private IP addresses of class C range from 192.168.0.0
to 192.168.255.255.
ISPs may block unreported web services to be accessed with the default port number 80.
Therefore, when the default LAN port number is 80, please manually change it to an uncommon
port number (1024–65535), such as 9999.
The LAN port number can be different from the WAN port number.
FTP server
IP address: 192.168.1.136
Access using an IP address
Service port: 21
MAC address: D4:61:DA:1B:CD:89
WAN IP address:
102.33.66.88
Procedure:
Step 1 Log in to the web UI of the ONT.
Step 2 Add a port forwarding rule.
1. Navigate to Services > Firewall > Port Forwarding.
2. Set Port Forwarding to Enable, and click Apply Changes.
3. Select FTP Server from the Application drop-down list.
4. (Optional) Modify Comment for the rule, which is FTP Server in this example.
5. Set Local IP, which is 192.168.1.136 in this example, and leave Remote IP blank.
42
Document version: V1.0
Step 3 Assign a fixed IP address to the host where the server locates.
1. Navigate to Services > Service > DHCP.
2. Click MAC-Based Management.
3. Set MAC Address of the host of the server, which is D4-61-DA-1B-CD-89 in this example.
4. Set Assigned IP Address for the server host, which is 192.168.1.136 in this example.
After the configuration is completed, users from the internet can access the FTP server by visiting
“Intranet service application layer protocol name://WAN IP address of the ONT”. If the remote port
number is different from the default intranet service port number, the visiting address should be:
“Intranet service application layer protocol name://WAN IP address of the ONT:Remote port
number”. In this example, the address is “ftp://102.33.66.88”. You can find the WAN IP address of
the ONT in Device status.
To access the FTP server from the internet:
Open the file explorer on a computer that can access the internet, and visit ftp://102.33.66.88.
43
Document version: V1.0
Enter the user name and password to access the resources on the FTP server.
If you want to access the server within a LAN using a domain name, refer to the solution Dynamic
DNS + Port Forwarding.
After the configuration is completed, if internet users cannot access the FTP server, try the following
methods:
Ensure that the LAN port number configured in the port forwarding function is the same as the
service port number set on the server.
Close the firewall, antivirus software and security guards on the host of the FTP server and try
again.
44
Document version: V1.0
Parameter description
Parameter Description
URL Blocking Specifies whether to enable the URL blocking function.
Specifies the domain name that you want to block LAN clients from accessing.
FQDN An FQDN, sometimes also referred to as an absolute domain name, is a domain name that
specifies its exact location in the tree hierarchy of the Domain Name System (DNS). It
specifies all domain levels, including the top-level domain and the root zone.
---End
45
Document version: V1.0
After the configuration is completed, Facebook, Twitter and Instagram are not accessible through
the ONT.
7.2.6 DMZ
Overview
A DMZ host on a LAN is free from restrictions in communicating with the internet. It is useful for
getting better and smoother experiences in video conferences and online games. You can also set
the host of a server within the LAN as a DMZ host when in need of accessing the server from the
internet.
A DMZ host is not protected by the firewall of the router. Hackers may leverage the DMZ host to
attack your LAN. Therefore, enable the DMZ function only when necessary.
Hackers may leverage the DMZ host to attack the local network. Do not use the DMZ host
function randomly.
Security software, antivirus software and the built-in OS firewall of the computer may cause
DMZ function failures. Disable them when using the DMZ function. If the DMZ function is not
required, you are recommended to disable it and enable your firewall, security and antivirus
software.
To access the configuration page, log in to the web UI of the ONT and navigate to Services >
Firewall > DMZ.
Parameter description
Parameter Description
DMZ Host Specifies whether to enable the DMZ host function.
DMZ Host IP Address Specifies the IP address of the LAN host to be set as the DMZ host.
Solution: You can configure the DMZ host function to reach the goal.
Assume that the information of the FTP server includes:
− IP address: 192.168.1.136
− MAC address: D4:61:DA:1B:CD:89
46
Document version: V1.0
− Service port: 21
− WAN IP address of the router: 102.33.66.88
Please ensure that the router obtains a public IP address public. This function may not work on a host
with an IP address of a private network or an intranet IP address assigned by ISPs that start with 100.
Common IPv4 addresses are classified into class A, class B and class C. Private IP addresses of class A
range from 10.0.0.0 to 10.255.255.255. Private IP addresses of class B range from 172.16.0.0 to
172.31.255.255. Private IP addresses of class C range from 192.168.0.0 to 192.168.255.255.
FTP server
Access using an IP address
IP address: 192.168.1.136
Service port: 21
MAC address: D4:61:DA:1B:CD:89
WAN IP address:
102.33.66.88
Procedure:
Step 1 Log in to the web UI of the ONT.
Step 2 Set the server host as the DMZ host.
1. Navigate to Services > Firewall > DMZ.
2. Select Enable for DMZ Host.
3. Enter the IP address of the server host, which is 192.168.1.136 in this example.
4. Click Apply Changes.
Step 3 Assign a fixed IP address to the host where the server locates.
1. Navigate to Services > Service > DHCP.
2. Click MAC-Based Management.
3. Enter the MAC Address of the host of the server, which is D4-61-DA-1B-CD-89 in this
example.
4. Enter the assigned IP Address for the server host, which is 192.168.1.136 in this example.
47
Document version: V1.0
After the configuration is completed, users from the internet can access the FTP server by visiting
“Intranet service application layer protocol name://WAN IP address of the ONT”. If the intranet
service port number is not the default number, the accessing address should be: “Intranet service
application layer protocol name://WAN IP address of the ONT:Intranet service port number”.
If the default intranet service port number is 80, please change the service port number to an
uncommon one (1024–65535), such as 9999.
In this example, the address is “ftp://102.33.66.88”. You can find the WAN IP address of the ONT in
Device status.
Open the file explorer on a computer that can access the internet, and visit ftp://102.33.66.88.
48
Document version: V1.0
Enter the user name and password to access the resources on the FTP server.
If you want to access the server within a LAN using a domain name, refer to the solution DMZ +
Dynamic DNS.
After the configuration is completed, if internet users still cannot access the FTP server, close the
firewall, antivirus software and security guards on the host of the FTP server and try again.
49
Document version: V1.0
8 Advance
8.1 Advanced settings
8.1.1 ARP table
On this page, you can view the IP address and MAC address of devices connected to the ONT in a
wired manner.
To access the page, log in to the web UI of the ONT and choose Advance > Advance > ARP Table.
8.1.2 Routing
Overview
On this page, you can add, modify and delete static route rules. In addition, you can view the route
table of the ONT.
Routing is the act of choosing an optimal path to transfer data from a source address to a
destination address. A static route is a special route that is manually configured and has the
advantages of simplicity, efficiency and reliability. Proper static routing can reduce routing
problems and overload of routing data flow, and improve the forwarding speed of data packets.
After the static route is established, all data whose destination address is the destination network
of the static route are directly forwarded to the next hop through the static route interface.
To access the page, log in to the web UI of the ONT and navigate to Advance > Advance > Routing.
50
Document version: V1.0
Parameter description
Parameter Description
Enable Specifies whether to enable the static route function.
Destination Specifies the IP address of the destination network.
Specifies the priority of the routing rule. The smaller the number, the higher the priority.
Metric When the destination networks of two rules are the same, packets will be forwarded
according to the rule with smaller metric.
Interface Specifies the interface of the ONT that the packet exits from.
Add Route Used to add a new static route rule.
Update Used to update your modification to an existing rule.
51
Document version: V1.0
---End
After the configuration is completed, the static rule will be displayed in Static Route Table.
52
Document version: V1.0
After the configuration is completed, the updated parameters of the static rule will be displayed in
Static Route Table.
The route with 0.0.0.0 as both destination and subnet mask is the default route. When no
perfectly matched route is found for a packet, the packet will be forwarded through the default
route.
0.0.0.0 as the next hop indicates that the ONT is directly connected to the destination network.
53
Document version: V1.0
8.2.2 RADVD
The Router Advertisement Daemon (RADVD) is used by system administrators in stateless auto-
configuration methods of network hosts on IPv6 networks.
When IPv6 hosts configure their network interfaces, they broadcast Router Solicitation (RS)
requests onto the network to discover available devices. The RADVD software answers requests
with Router Advertisement (RA) messages. In addition, RADVD periodically broadcasts RA packets
to the attached link to update network hosts.
To access the page, log in to the web UI of the ONT and navigate to Advance > IPv6 > RADVD.
54
Document version: V1.0
Parameter description
Parameter Description
55
Document version: V1.0
Parameter Description
⚫ Manual: You need to set the prefix manually.
Prefix Specify the prefix information included in the RA message to hosts for generating
Prefix Length their IPv6 address.
AdvValidLifetime Specify the Advertisement Valid Lifetime and Advertisement Preferred Lifetime.
When the preferred lifetime expires, the use of the prefix is not encouraged, but not
prohibited. When the valid lifetime expires, the prefix becomes invalid.
AdvPreferredLifetime
The valid lifetime must be greater than or equal to the preferred lifetime.
AdvOnLink Specifies whether the router advertisement is on the link.
Specifies whether the prefix in the router advertisement can be used to generate IPv6
AdvAutonomous
address.
Specify the Recursive DNS Server (RDNSS) addresses assigned to IPv6 hosts for DNS
RDNSS 1/2
information configuration.
Specifies whether to enable the Unique Local Address (ULA).
Enable ULA The purpose of ULA resembles that of the private network address in IPv4. It is only
used within the private network and increases stability for the IPv6 host and its use of
services.
ULA Prefix Specify the ULA prefix information advertised by the ONT to hosts for generating
ULA Prefix Len unique local addresses. They are available only when Enable ULA is set to on.
Specify the valid lifetime and preferred lifetime of ULA prefix. They are available only
ULA Prefix Valid Time when Enable ULA is set to on.
When the preferred time expires, the use of the ULA prefix is not encouraged, but not
prohibited. When the valid time expires, the ULA prefix becomes invalid. It is available
only when Enable ULA is set to on.
ULA Prefix Preferred
Time
The valid time must be greater than or equal to the preferred time.
8.2.3 DHCPv6
IPv6 hosts may automatically generate IP addresses internally using Stateless Address
Autoconfiguration (SLAAC), or they may be assigned configuration with Dynamic Host
Configuration Protocol version 6 (DHCPv6). When the DHCPv6 server is enabled, the ONT can
assign IPv6 hosts with IP addresses, IP prefixes and other configurations required for IPv6 internet
access.
To access the page, log in to the web UI of the ONT and navigate to Advance > IPv6 > DHCPv6.
56
Document version: V1.0
Parameter description
Parameter Description
Specify the valid lifetime and preferred lifetime of the IPv6 address assigned to IPv6
Valid Lifetime hosts.
When the preferred lifetime expires, communication using the IPv6 address is not
Preferred Lifetime encouraged, but allowed. When the valid lifetime expires, the IPv6 address becomes
invalid.
57
Document version: V1.0
Parameter Description
Specifies the time before expiration when the host is expected to contact the DHCPv6
Renew Time server that did the assignment to renew the lifetimes of the addresses assigned to the
client.
Rebind Time Specifies the new valid time after the IPv6 address is renewed.
Client DUID The DUID is used by a client to get an IP address from a DHCPv6 server, and the server
compares the DUID with its database and delivers configuration data (such as the
address and DNS servers) to the client.
Domain Used to configure the domain.
58
Document version: V1.0
9 Diagnostics
9.1 Ping and Tracert
The ONT provides connectivity diagnosis tools, which include Ping and Tracert. You can use these
tools to test the connectivity to the internet, a certain IP address or domain name.
− Ping: It is a utility that helps to check if an IP address or domain name is accessible or
not. Ping works by sending a packet to the specified address and waits for the reply. It
also measures round trip time and reports errors.
− Tracert: It is a utility that traces a packet from your computer to the host, and will
also show the number of steps (hops) required to reach there, along with the time by
each step.
To access the page, log in to the web UI of the ONT and click Diagnostics. Both tools include IPv4
(Ping/Tracert) and IPv6 (Ping6/Tracert6) versions. The IPv4 version is used for illustration.
Ping
Parameter description
Parameter Description
Specifies the IP address or domain name whose connectivity with the ONT is to be
Host Address
diagnosed.
WAN Interface Specifies the WAN interface through which the packet for diagnosis is forwarded.
Tracert
59
Document version: V1.0
Parameter description
Parameter Description
Host Address Specifies the IP address or domain name of the tracert target.
Specifies the maximum number of times that the host tries to reach the host address.
NumberOfTries If all the attempts fail, it denotes network congestion and a reason for slow loading
web pages and dropped connections.
Max Hop Count When a packet cannot reach the destination and expires at an intermediate step, that
node returns the packet and identifies itself. It denotes network congestion and a
reason for slow loading web pages and dropped connections.
60
Document version: V1.0
61
Document version: V1.0
62
Document version: V1.0
10 Admin
10.1 GPON/EPON settings
On this page, you can register your ONT for internet access.
To access the page, log in to the web UI of the ONT and navigate to Admin > Admin > GPON
Settings (or EPON Settings). Enter the parameters provided by your ISP and click Apply Changes to
register the ONT.
You can view the registration status of the ONT on the PON status page.
63
Document version: V1.0
64
Document version: V1.0
10.3 Commit/Reboot
This page is used to commit any configuration changes you have made and reboot the ONT to put
the changes into effect. Click Commit and Reboot to save settings and reboot the ONT.
To access the page, log in to the web UI of the ONT and navigate to Admin > Admin >
Commit/Reboot.
65
Document version: V1.0
10.4 Backup/Restore
On this page, you can back up the configuration of the ONT, restore the configuration from a
backup file, and reset the ONT.
To access the page, log in to the web UI of the ONT and navigate to Admin > Admin >
Backup/Restore.
66
Document version: V1.0
Resetting the ONT will clear all previous personalized configurations. It is recommended to back up the
configuration of the ONT in advance.
Procedure:
Step 1 Log in to the web UI of the ONT.
Step 2 Navigate to Admin > Admin > Backup/Restore.
Step 3 Click Reset.
The ONT starts rebooting. Wait until it finishes rebooting, and then you can log in to the
ONT again and perform settings.
---End
67
Document version: V1.0
10.5 Password
On this page, you can change the login password for the ONT. The default login user name and
password are admin. You can only change the password, and the original password is required
during the process.
Procedure:
Step 1 Log in to the web UI of the ONT.
Step 2 Navigate to Admin > Admin > Password.
Step 3 Set UserName according to the actual permissions.
Step 4 Enter the original password in Old Password.
Step 5 Enter your new password in New Password and Confirmed Password.
Step 6 Click Apply Changes.
The following message is displayed, indicating that the password is changed successfully.
---End
68
Document version: V1.0
69
Document version: V1.0
10.7 ACL
Access Control List (ACL) is a collection of permitting and denying rules that ensure security by
blocking unauthorized users from and allowing authorized users to access ONT.
To access the page, log in to the web UI of the ONT and navigate to Admin > Admin > ACL.
Parameter description
Parameter Description
ACL Capability Specifies whether to enable the ACL function of the ONT.
Specifies the control mode of the rule.
⚫ When Enable is selected, traffic that meets the criteria of the rule can pass through the
Enable specified port of the ONT.
⚫ When Enable is deselected, traffic that meets the criteria of the rule is discarded at the
specified port of the ONT.
Specifies the interface that the access control rule applies to, including LAN and WAN.
⚫ LAN: The ONT checks traffic from the LAN side according to the rule and decides to pass
Interface it or discard it.
⚫ WAN: The ONT checks traffic from the WAN side according to the rule and decides to
pass it or discard it.
Start IP Address
Specify the IP address range or a certain IP address that is controlled by the rule.
End IP Address
70
Document version: V1.0
Parameter Description
Specifies the control mode of the rule. If you deselect Enable when setting an ACL rule,
State
the State shows Disable.
Interface Specifies the interface that the access control rule applies to, including LAN and WAN.
IP Address Specifies the IP address range or a certain IP address that is controlled by the rule.
Services Specifies the protocols adopted by the traffic, or the types of traffic.
Port Specifies the default ports adopted by the corresponding services.
71
Document version: V1.0
To access the page, log in to the web UI of the ONT and navigate to Admin > Admin > Time Zone.
Parameter description
Parameter Description
Current Time Specifies the current system time of the ONT. You can change it manually.
Time Zone Select Specifies the time zone where the ONT locates.
Daylight Saving Time (DST) is the practice of advancing clocks during warmer months so
that darkness falls later each day according to the clock.
Enable Daylight With it is enabled, the ONT sets the time forward by one hour in the spring ("spring
Saving Time forward") and sets the time back by one hour in autumn ("fall back") to return to standard
time. In other words, there is one 23-hour day in late winter or early spring and one 25-
hour day in the autumn.
72
Document version: V1.0
10.9 Logout
To access the page, navigate to Admin > Admin > Logout.
You can log out of the web UI of the ONT by clicking Logout on this page, or click Logout at the
upper-right corner of the web UI.
73
Document version: V1.0
11 Statistics
In this part, you can view the packet statistics of the ports and interfaces of the ONT.
Interface statistics
This page displays the received and transmitted packets statistics, including the received packets
(Rx pkt), received packets error (Rx err), dropped received packets (Rx drop), transmitted packets
(Tx pkt), transmitted packets error (Tx err), dropped transmitted packets (Tx drop).
To access the page, log in to the web UI of the ONT and navigate to Statistics > Statistics >
Interface.
PON statistics
The page displays the data statistics transmitted and received through the PON port.
To access the page, log in to the web UI of the ONT and navigate to Statistics > Statistics > PON
Statistics.
74
Document version: V1.0
Appendixes
A.1 Configure the computer to obtain an IPv4/IPv6
address automatically
Perform the configuration procedure in Windows 10, Windows 8 and Windows 7 as required. A
computer installed with a wired network adapter is used as an example to describe the procedure.
A.1.1 Windows 10
Step 1 Click in the bottom right corner of the desktop and choose Network settings.
75
Document version: V1.0
76
Document version: V1.0
Step 5 Select Obtain an IP address automatically and Obtain DNS server address automatically,
and click OK.
77
Document version: V1.0
A.1.2 Windows 8
Step 1 Right-click in the bottom right corner of the desktop and choose Open Network and
Sharing Center.
78
Document version: V1.0
Step 4 Select Obtain an IP address automatically and Obtain DNS server address automatically,
and click OK.
79
Document version: V1.0
A.1.3 Windows 7
Step 1 Click in the bottom right corner of the desktop and choose Open Network and
Sharing Center.
80
Document version: V1.0
Step 4 Select Obtain an IP address automatically and Obtain DNS server address automatically,
and click OK.
81
Document version: V1.0
IP Internet Protocol
82
Document version: V1.0
OS Operating system
RA Router Advertisement
RS Router Solicitation
UI User interface
83