Skip to content

Hardware Specifications

Vendor/Brand T&W
Model TWC GPON657
ODM ✅
Chipset Realtek RTL9601CI
Flash 16 MB
RAM 64 MB
System Linux (Luna SDK)
SFP interfaces HSGMII
Optics SC/APC
IP address
Web Gui ✅ user admin, password system
SSH ✅ user admin, password system
Telnet
Serial
Form Factor miniONT SFP

Hardware Specifications ​

Vendor/BrandT&W
ModelTWC GPON657
ODM✅
ChipsetRealtek RTL9601CI
Flash16 MB
RAM64 MB
SystemLinux (Luna SDK)
SFP interfacesHSGMII
OpticsSC/APC
IP address
Web Gui✅ user admin, password system
SSH✅ user admin, password system
Telnet
Serial
Form FactorminiONT SFP

Firmware is interchangeable with: ​

Enabling telnet ​

Telnet must be enabled from the Web GUI before the configuration[1]:

StateURL
Enablehttp://192.168.1.1/bd/telnet_open.asp
Disablehttp://192.168.1.1/bd/telnet_close.asp

List of firmwares and files ​

FirmwareNotes
C00R657V00B12_20191121.tarStock B12
C00R657V00B13_20191024.tarStock B13
C00R657V00B13_20191205.tarStock B13
C00R657V00B13_20200507.tarStock B13
C00R657V00B15_20201222.tarStock B15
C00R657V2801F_V1.9.0-220404.tarV2801F firmware for the TWCGPON657
TWCGPON657_V1.9.0-240204.tarV2801F firmware for the TWCGPON657, 4-port emulation

The recommended version is TWCGPON657_V1.9.0-240204.tar (or C00R657V2801F_V1.9.0-220404.tar), the V2801F firmware for the T&W TWC GPON657: it supports both VEIP and PPTP, and the 240204 also the 4-port emulation.

Flashing the V2801F firmware ​

The V2801F firmware checks the VS_AUTH_KEY license key, which does not exist on the stock firmware: without a valid key the stick reboots in a loop, see V-SOL V2801F[2].

  1. If the stock firmware is newer than B13, downgrade it to B13 or older;
  2. Via telnet, set the stick to 1000BASE-X and to the Ethernet mode, which prevents the reboot loop:
    sh
    # flash set LAN_SDS_MODE 1
    # flash set PON_MODE 3
  3. Upload the V2801F firmware from the Web GUI and wait;
  4. Set a MAC address, hardware version and key that match:
    sh
    # flash set ELAN_MAC_ADDR 6CEFC6000000
    # flash set HW_HWVER RTL960x
    # flash set VS_AUTH_KEY 00CF646955CCBDB88AB3B68922DB810F
  5. Set PON_MODE back to 1 (GPON) or 2 (EPON) and reboot.

Useful files and binaries ​

Useful files ​

  • /var/config/lastgood.xml - Contains the user portion of the configuration

  • /tmp/omcilog - OMCI messages logs (must be enabeled, see below)

Useful binaries ​

  • flash - Used to manipulate the config files in a somewhat safe manner
  • xmlconfig - Used for low-level manipulation of the XML config files. Called by flash
  • nv - Used to manipulate nvram storage, including persistent config entries via nv setenv/nv getenv
  • omcicli - Used to interact with the running OMCI daemon
  • omci_app - The OMCI daemon
  • diag - Used to run low-level diagnostics commands on the stick

GPON ONU status ​

Getting the operational status of the ONU ​

sh
diag gpon get onu-state

Querying a particular OMCI ME ​

sh
# omcicli mib get MIB_IDX

The list of the MEs is in GPON MIB, and the most useful ones to check the provisioning received from the OLT are in Most useful MEs to check the provisioning.

To dump all the MEs at once[3]:

sh
for ME in 2 5 6 7 11 24 45 47 49 50 52 78 79 83 84 89 130 131 133 134 136 137 148 157 158 171 240 244 245 248 249 250 253 255 256 257 262 263 264 266 267 268 272 273 274 277 278 280 281 284 287 296 298 307 308 309 310 311 312 321 322 329 330 334 340 341 65282 65294 65408 65527 65528 65529 65530 65531; do echo "MIB: $ME"; omcicli mib get $ME; done

To dump the most useful MEs at once:

sh
for ME in 6 7 11 84 131 171 256 257 262 263 264 277 309 329; do echo "MIB: $ME"; omcicli mib get $ME; done

Getting the GEM ports and the flows ​

sh
# diag gpon show us-flow
============================================================
    GPON ONU MAC U/S Flow Status
Flow ID | GEM Port | Type | TCont
      0 |      263 |  ETH |     0
      1 |      264 |  ETH |     1
     64 |        2 | OMCI |    16
============================================================
# diag gpon show ds-flow

Getting the VLANs bridged by the stick ​

The L2 table shows the learned MAC addresses with their VLAN (Vid): if the internet traffic arrives untagged on the router, this is a way to find which VLAN is used on the PON side[4].

sh
# diag l2-table get entry address valid

On the RTL9601D (e.g. ODI DFP-34X-2C2) the valid parameter is not available, the table has to be read entry by entry:

sh
i=0
while [ $i -lt 2047 ]; do
    diag l2-table get entry address $i | grep -q "LUT" && diag l2-table get entry address $i
    i=$((i+1))
done

Getting the port status and the bandwidth limits ​

sh
# diag port get status port all
Port Status Speed    Duplex TX_FC RX_FC
---- ------ -----    ------ ----- -----
0    Up     1000M    Full   Dis   Dis
2    Up     1000M    Full   Dis   Dis
# diag bandwidth get egress port all
# diag bandwidth get ingress port all

Getting/Setting Speed LAN Mode ​

Note

Please use recommended version TWCGPON657_V1.9.0-240204.tar. It is not guaranteed that any value for LAN_SDS_MODE other than 1 will work with other firmware versions. Before editing the sync speed settings make sure your hardware supports it.

To change the link mode use this command:

sh
# flash get LAN_SDS_MODE
LAN_SDS_MODE=0
# flash set LAN_SDS_MODE 1
Valuecat /proc/kmsgModeBehavior
1<4>change mode to 1(Fiber 1G)FIBER1GbaseX with auto-neg on
2<4>change mode to 2(SGMII PHY)TP MII1Gb PHY
3<4>change mode to 3(SGMII MAC)MII1Gb MAC
4<4>change mode to 4(HiSGMII PHY)TP MII2.5Gb PHY
5<4>change mode to 5(HiSGMII MAC)MII2.5Gb MAC
6<4>change mode to 6(2500BaseX)FIBER2500baseX with auto-neg on

The default value on this stick is 2.

The 2.5G modes are 4 (HiSGMII PHY), 5 (HiSGMII MAC) and 6 (2500BASE-X): most of the hosts that support 2.5G work with the mode 6 and the port forced to 2500BASE-X, see the SFP standard page and the 2.5G compatibility list[5].

WARNING

A LAN_SDS_MODE not supported by the host makes the stick unreachable: the only way to restore it is the serial console.

GPON/OMCI settings ​

Getting/Setting ONU GPON Serial Number ​

sh
# flash get GPON_SN
GPON_SN=TMBB00000000
# flash set GPON_SN TMBB0A1B2C3D

Getting/Setting ONU GPON PLOAM password ​

Info

The PLOAM password is stored in ASCII format

sh
# flash get GPON_PLOAM_PASSWD
GPON_PLOAM_PASSWD=AAAAAAAAAA
# flash set GPON_PLOAM_PASSWD AAAAAAAAAA

Getting/Setting OMCI software version (ME 7) ​

sh
# nv setenv sw_custom_version0 YOURFIRSTSWVER
# nv setenv sw_custom_version1 YOURSECONDSWVER

Getting/Setting OMCI hardware version (ME 256) ​

sh
# flash get HW_HWVER
HW_HWVER=V2.0
# flash set HW_HWVER MYHWVERSION

Getting/Setting OMCI vendor ID (ME 256) ​

sh
# flash get PON_VENDOR_ID  
PON_VENDOR_ID=ZTEG
# flash set PON_VENDOR_ID HWTC

Getting/Setting OMCI equipment ID (ME 257) ​

sh
# flash get GPON_ONU_MODEL
GPON_ONU_MODEL=DFP-34X-2C2
# flash set GPON_ONU_MODEL DFP-34X-XXX

Getting/Setting OMCI OLT Mode and Fake OMCI ​

Configure how ONT Stick handle OMCI from OLT:

sh
# flash get OMCI_OLT_MODE
OMCI_OLT_MODE=1
# flash set OMCI_OLT_MODE 2
ValueNoteOMCI Information
0Default ModeStock setting, some values cannot be changed
1Huawei OLT ModeHuawei MA5671a
2ZTE OLT ModeZTE
3Customized ModeCustom Software/Hardware Version, OMCC, etc...

Some vendors/wholesale providers/ISPs have explicit LAN Port Number provisioning or proprietary OMCI that the stick cannot understand, this will make the stick reply OK to whatever the OLT sends it via OMCI.

0 = Disable, 1 = Enable, Default is 0

sh
# flash get OMCI_FAKE_OK
OMCI_FAKE_OK=0
# flash set OMCI_FAKE_OK 1

Getting/Setting the OMCC version ​

The OMCC version (ME 257) advertised to the OLT, e.g. 128 (0x80) or 160 (0xA0):

sh
# flash get OMCC_VER
OMCC_VER=128
# flash set OMCC_VER 160

Getting/Setting the OMCI traffic management option ​

How the OLT manages the upstream bandwidth (ME 256 Traffic management option): if the upload speed is lower than expected, try the other values[6].

sh
# flash get OMCI_TM_OPT
OMCI_TM_OPT=2
# flash set OMCI_TM_OPT 0
ValueMode
0Priority controlled
1Rate controlled
2Priority and rate controlled

Getting/Setting the VEIP slot ID ​

Some OLTs expect the VEIP (ME 329) with the same Entity ID of the original ONT, usually 0x0e01. The slot ID is the most significant byte of the Entity ID (0x0e = 14), and it is applied only if the bit 0x100 (cf_apply_customized_veip_slot_id) of OMCI_CUSTOM_ME is set: the default value on the SFU firmwares is 65536 (0x10000), so it must be set to 65792 (0x10100)[7].

sh
# flash set OMCI_VEIP_SLOT_ID 14
# flash set OMCI_CUSTOM_ME 65792

The other feature bits of OMCI_CUSTOM_ME have been documented by @rajkosto.

Getting/Setting the other identity values ​

Some OLTs (mostly the ones that accept any ONU, e.g. Fiberhome and Calix) also check other values of the original ONT[1:1]:

VariableDescriptionExample
OUIOrganizationally Unique Identifier of the original MAC address875773
HW_SERIAL_NOHardware serial number (not the GPON serial number)UONHUWH12341234123
ELAN_MAC_ADDRMAC address of the stick, required by EPON781735000000
HW_CWMP_MANUFACTURERTR-069 manufacturerHuawei Technologies Co., Ltd
HW_CWMP_PRODUCTCLASSTR-069 product classHG8240H
LOID, LOID_PASSWDLogical ONU ID and password, used by EPON and some GPON ISPs
sh
# flash set OUI 875773
# flash set HW_CWMP_MANUFACTURER 'Huawei Technologies Co., Ltd'

WARNING

Changing ELAN_MAC_ADDR or HW_HWVER requires a new VS_AUTH_KEY, see VS_AUTH_KEY.

Getting/Setting the PON mode, device type and VLAN mode ​

VariableValues
PON_MODE1 GPON (default), 2 EPON, 3 Ethernet (the PON side works as an Ethernet fiber transceiver)
DEVICE_TYPE0 bridge, 1 router, 2 hybrid
VLAN_CFG_TYPE0 auto (from OMCI), 1 manual (uses VLAN_MANU_MODE)
VLAN_MANU_MODE0 transparent, 1 tagging (Q-in-Q, the outer tag is removed), 2 remote access, 3 special case

Every flash set requires a reboot to be applied[8].

Advanced settings ​

Setting management IP ​

sh
# flash get LAN_IP_ADDR
LAN_IP_ADDR=192.168.2.1
# flash set LAN_IP_ADDR 192.168.1.1

Getting/Setting the L2 Bridge MTU ​

Note

Settings given via diag are not permanent after reboot

Getting/Setting the MTU of the L2 bridge

sh
# diag switch get max-pkt-len port all 
Port Speed 
---------- 
0 1538 
2 2031 
# diag switch set max-pkt-len port all length 2000

Checking the currently active image ​

sh
# nv getenv sw_active
sw_active=1
# nv getenv sw_version0
sw_version0=V1_7_8_210412
# nv getenv sw_version1
sw_version1=V1_7_8_210412

Booting to a different image ​

The firmware upgrade always writes the inactive image, so it is possible to go back to the previous firmware[9]:

sh
# nv setenv sw_commit 0|1
# nv setenv sw_active 0|1
# reboot

Factory reset ​

DANGER

Make a backup of the env, env2 and config partitions (see this guide) and write down ELAN_MAC_ADDR and the license key (VS_AUTH_KEY) before the reset: after it the stick uses the default MAC address, and a wrong key prevents the authentication to the OLT.

The configuration is stored in the config partition (/dev/mtd3), erasing it restores the default settings[10]:

sh
# flash_eraseall /dev/mtd3
# reboot

If the stick reboots in a loop, the reset-config-partition.sh script keeps trying until it can erase the partition via SSH.

Modifying the firmware ​

Warning

A wrong rootfs makes the image unbootable: always flash the inactive image, so that the stick can still boot the other one, and keep a backup of all the partitions.

Transferring files from/to the stick ​

Run md5sum on the source and on the destination to make sure that the file has not been corrupted.

Via SSH, from the stick to the PC and vice versa:

sh
ssh admin@192.168.1.1 "cat /dev/mtd5" > mtd5.bin
cat rootfs.new | ssh admin@192.168.1.1 "cat > /tmp/rootfs.new"

Via TFTP (a TFTP server must be running on the PC):

sh
# tftp <PC IP>
tftp> get rootfs.new
tftp> put <filename> <directory>
tftp> q

Via netcat (nc on the stick does not exit at the end of the transfer: stop it with CTRL+C)[11]:

sh
# on the stick
nc -l -p 12345 > /tmp/rootfs.new
# on the PC
nc 192.168.1.1 12345 < rootfs.new

Info

On Windows run the commands from cmd (not PowerShell) and replace cat with type.

Extracting and repacking the rootfs ​

The rootfs is a SquashFS (LZMA) image: on the stick it is in r0 (/dev/mtd5) for the image 0 and in r1 (/dev/mtd7) for the image 1, while the kernel is in k0 (/dev/mtd4) and k1 (/dev/mtd6).

Warning

Run both commands as root, otherwise the rootfs image might be damaged.

sh
# unsquashfs mtd5.bin
# mksquashfs squashfs-root rootfs.new -b 131072 -comp lzma -no-recovery

The RTL960x emulator runs the extracted firmware in QEMU (qemu-user-static) to modify and test it before flashing it: any file in its custom folder is copied over squashfs-root when leaving the chroot, and the custom startup scripts go in /etc/init.d/rc35.

Flashing a new rootfs ​

Check which image is running (nv getenv sw_active): flash mtd6/mtd7 if the image 0 is running, mtd4/mtd5 if the image 1 is running. The following commands flash a new rootfs to the image 1 and boot it:

sh
# flash_eraseall /dev/mtd7
# cat /tmp/rootfs.new > /dev/mtd7
# nv setenv sw_version1 NEW_SOFTWARE_VERSION
# nv setenv sw_commit 1
# reboot

If cat fails with cat: write error: Invalid Argument, write the image to the block device instead:

sh
# flash_eraseall /dev/mtd7
# cat /tmp/rootfs.new > /dev/mtdblock7

Repacking a firmware upgrade file ​

The firmware upgrade files of the ODM firmwares (e.g. V-SOL, T&W, ODI) are a tar containing the kernel (uImage), the rootfs, the fwu.sh upgrade script, the fwu_ver version file and the md5.txt checksums: after replacing the rootfs, update the checksums and repack it, then upload it from the Web GUI firmware upgrade page[11:1]:

sh
tar -xf firmware.tar
mv rootfs.new rootfs
md5sum fwu.sh rootfs uImage fwu_ver > md5.txt
tar -cvf ../firmware-mod.tar *

The Firmware_Mod folder of the RTL960x repository contains the community patches for the ODI DFP-34X-2C2, V-SOL V2801F and T&W TWCGPON657 (Bootstrap Web GUI, VLAN, speed and software version fixes).

Known Bugs ​

VLAN swap issue (MEID 171), auto-sensing mode to switch between SGMII/HiSGMII

You should use the VID/VLAN shown by executing the command omcicli mib get 84 via telnet to bring up PPPoE

Miscellaneous Links ​


  1. RTL960x SFP xPON ONU Configuration Guide, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/StickSetup.md â†Šī¸Ž â†Šī¸Ž

  2. TWCGPON657 firmware, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/tree/main/Firmware/TWCGPON657 â†Šī¸Ž

  3. OMCI MIB, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/OMCI_CLI.md â†Šī¸Ž

  4. Diag, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/DIAG.md â†Šī¸Ž

  5. 2.5Gb Compatibility, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/2.5Gb.md â†Šī¸Ž

  6. Slow Upload Speed, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/SlowUploadSpeed.md â†Šī¸Ž

  7. OMCI_VEIP_SLOT_ID, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/VEIP.md â†Šī¸Ž

  8. flash get, flash set, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/FLASH_GETSET_INFO.md â†Šī¸Ž

  9. Firmware Partition, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/fw_part.md â†Šī¸Ž

  10. Factory Reset, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/factory_reset.md â†Šī¸Ž

  11. Modify firmware, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/Modify_Firmware.md â†Šī¸Ž â†Šī¸Ž

Copyright Š 2022-2026. The documentation hereby found is distributed under the terms of the MIT License. Any external reference, link or software retains its original license and is not under the control of this website. Privacy Policy.