Hardware Specifications
| Vendor/Brand | Vantiva (formerly Technicolor) |
| Model | AFM0002TIM/FWB/WND |
| ODM | HiSense |
| ODM Product Code | LTE3415-SCA+ |
| Chipset | Realtek RTL9601B |
| Flash | 32MB |
| RAM | 16MB |
| System | Linux (Luna SDK 1.9) |
| SFP interfaces | 1 Gbps only, no HSGMII |
| Optics | SC/APC |
| IP address | 192.168.2.1 / 169.0.0.1 |
| Web Gui | Can be enabled, user admin, password system |
| SSH | ✅ user admin, password system |
| Telnet | |
| Serial | ✅ |
| Serial baud | 115200 |
| Serial encoding | 8-N-1 |
| Form Factor | miniONT SFP |
| Multicast | ✅ |


Serial
The stick has a TTL 3.3v UART console (configured as 115200 8-N-1) that can be accessed from the top surface. To accept TX line commands, the GND of the TTL adapter should be attached to the stick's shield:

Note
Some USB TTL adapters label TX and RX pins the other way around: try to swap them if the connection doesn't work.
Hardware Revisions
- AFM0002TIM (IP address: 192.168.2.1)
- AFM0002FWB (IP address: 169.0.0.1)
- AFM0002WND (IP address: 169.0.0.1)
Info
The version used to obtain the info shown on this page is the AFM0002TIM
Warning
The AFM0002FWB can be transformed into AFM0002TIM. Usually AFM0002FWBs have older software.
List of software versions
- V1.7.6-170626 (FWB & WND)
- V1_7_8_180122
- V1_7_8_180725
- V1_7_8_181123
- V1_7_8_210412
- V1_7_8_210928
List of partitions
| dev | size | erasesize | name |
|---|---|---|---|
| mtd0 | 00040000 | 00001000 | "boot" |
| mtd1 | 00002000 | 00001000 | "env" |
| mtd2 | 00002000 | 00001000 | "env2" |
| mtd3 | 0003c000 | 00001000 | "config" |
| mtd4 | 00300000 | 00001000 | "k0" |
| mtd5 | 004c0000 | 00001000 | "r0" |
| mtd6 | 00300000 | 00001000 | "k1" |
| mtd7 | 004c0000 | 00001000 | "r1" |
| mtd8 | 00001000 | 00001000 | "Partition_008" |
| mtd9 | 00001000 | 00001000 | "Partition_009" |
| mtd10 | 00001000 | 00001000 | "Partition_010" |
| mtd11 | 00001000 | 00001000 | "Partition_011" |
| mtd12 | 00300000 | 00001000 | "linux" |
| mtd13 | 004c0000 | 00001000 | "rootfs" |
This stick supports dual boot.
k0 and r0 respectively contain kernel and firmware of the first image, while k1 and r1 contain kernel and firmware of the second one.
Useful files and binaries
Useful files
/var/config/lastgood.xml- Contains the user portion of the configuration/var/config/lastgood-hs.xml- Contains the "hardware" configuration (which should not be changed)/tmp/omcilog- OMCI messages logs (must be enabeled, see below)
Useful binaries
/etc/scripts/flash- Used to manipulate the config files in a somewhat safe mannerxmlconfig- Used for low-level manipulation of the XML config files. Called by/etc/scripts/flashnv- Used to manipulate nvram storage, including persistent config entries vianv setenv/nv getenvomcicli- Used to interact with the running OMCI daemonomci_app- The OMCI daemondiag- Used to run low-level diagnostics commands on the stick
GPON ONU status
Getting the operational status of the ONU
diag gpon get onu-stateQuerying a particular OMCI ME
# omcicli mib get MIB_IDXThe list of the MEs is in GPON MIB, and the most useful ones to check the provisioning received from the OLT are in Most useful MEs to check the provisioning.
To dump all the MEs at once[1]:
for ME in 2 5 6 7 11 24 45 47 49 50 52 78 79 83 84 89 130 131 133 134 136 137 148 157 158 171 240 244 245 248 249 250 253 255 256 257 262 263 264 266 267 268 272 273 274 277 278 280 281 284 287 296 298 307 308 309 310 311 312 321 322 329 330 334 340 341 65282 65294 65408 65527 65528 65529 65530 65531; do echo "MIB: $ME"; omcicli mib get $ME; doneTo dump the most useful MEs at once:
for ME in 6 7 11 84 131 171 256 257 262 263 264 277 309 329; do echo "MIB: $ME"; omcicli mib get $ME; doneGetting the GEM ports and the flows
# diag gpon show us-flow
============================================================
GPON ONU MAC U/S Flow Status
Flow ID | GEM Port | Type | TCont
0 | 263 | ETH | 0
1 | 264 | ETH | 1
64 | 2 | OMCI | 16
============================================================
# diag gpon show ds-flowGetting the VLANs bridged by the stick
The L2 table shows the learned MAC addresses with their VLAN (Vid): if the internet traffic arrives untagged on the router, this is a way to find which VLAN is used on the PON side[2].
# diag l2-table get entry address validOn the RTL9601D (e.g. ODI DFP-34X-2C2) the valid parameter is not available, the table has to be read entry by entry:
i=0
while [ $i -lt 2047 ]; do
diag l2-table get entry address $i | grep -q "LUT" && diag l2-table get entry address $i
i=$((i+1))
doneGetting the port status and the bandwidth limits
# diag port get status port all
Port Status Speed Duplex TX_FC RX_FC
---- ------ ----- ------ ----- -----
0 Up 1000M Full Dis Dis
2 Up 1000M Full Dis Dis
# diag bandwidth get egress port all
# diag bandwidth get ingress port allGPON/OMCI settings
Getting/Setting ONU GPON Serial Number
# /etc/scripts/flash get GPON_SN
GPON_SN=TMBB00000000
# /etc/scripts/flash set GPON_SN TMBB0A1B2C3DGetting/Setting ONU GPON PLOAM password
Info
The PLOAM password is stored in ASCII format
# /etc/scripts/flash get GPON_PLOAM_PASSWD
GPON_PLOAM_PASSWD=AAAAAAAAAA
# /etc/scripts/flash set GPON_PLOAM_PASSWD AAAAAAAAAAGetting/Setting OMCI software version (ME 7)
Note
This needs the /etc/scripts/flash modded
# /etc/scripts/flash get OMCI_SW_VER1
OMCI_SW_VER1=YOURFIRSTSWVER
# /etc/scripts/flash set OMCI_SW_VER1 YOURFIRSTSWVER
# /etc/scripts/flash get OMCI_SW_VER2
OMCI_SW_VER1=YOURSECONDSWVER
# /etc/scripts/flash set OMCI_SW_VER2 YOURSECONDSWVERGetting/Setting OMCI hardware version (ME 256)
Note
This needs the /etc/scripts/flash modded
# /etc/scripts/flash get HW_HWVER
HW_HWVER=V2.0
# /etc/scripts/flash set HW_HWVER MYHWVERSIONGetting/Setting OMCI vendor ID (ME 256)
Note
This needs the /etc/scripts/flash modded
# /etc/scripts/flash get PON_VENDOR_ID
PON_VENDOR_ID=ZTEG
# /etc/scripts/flash set PON_VENDOR_ID HWTCGetting/Setting OMCI equipment ID (ME 257)
Note
This needs the /etc/scripts/flash modded
# /etc/scripts/flash get GPON_ONU_MODEL
GPON_ONU_MODEL=DFP-34X-2C2
# /etc/scripts/flash set GPON_ONU_MODEL DFP-34X-XXXGetting/Setting OMCI OLT Mode and Fake OMCI
Configure how ONT Stick handle OMCI from OLT:
# /etc/scripts/flash get OMCI_OLT_MODE
OMCI_OLT_MODE=1
# /etc/scripts/flash set OMCI_OLT_MODE 2| Value | Note | OMCI Information |
|---|---|---|
| 0 | Default Mode | Stock setting, some values cannot be changed |
| 1 | Huawei OLT Mode | Huawei MA5671a |
| 2 | ZTE OLT Mode | ZTE |
| 3 | Customized Mode | Custom Software/Hardware Version, OMCC, etc... |
Some vendors/wholesale providers/ISPs have explicit LAN Port Number provisioning or proprietary OMCI that the stick cannot understand, this will make the stick reply OK to whatever the OLT sends it via OMCI.
0 = Disable, 1 = Enable, Default is 0
# /etc/scripts/flash get OMCI_FAKE_OK
OMCI_FAKE_OK=0
# /etc/scripts/flash set OMCI_FAKE_OK 1Advanced settings
Setting management IP
# /etc/scripts/flash get LAN_IP_ADDR
LAN_IP_ADDR=192.168.2.1
# /etc/scripts/flash set LAN_IP_ADDR 192.168.1.1Getting/Setting the L2 Bridge MTU
Note
Settings given via diag are not permanent after reboot
Getting/Setting the MTU of the L2 bridge
# diag switch get max-pkt-len port all
Port Speed
----------
0 1538
2 2031
# diag switch set max-pkt-len port all length 2000Checking the currently active image
# nv getenv sw_active
sw_active=1
# nv getenv sw_version0
sw_version0=V1_7_8_210412
# nv getenv sw_version1
sw_version1=V1_7_8_210412Booting to a different image
The firmware upgrade always writes the inactive image, so it is possible to go back to the previous firmware[3]:
# nv setenv sw_commit 0|1
# nv setenv sw_active 0|1
# rebootModifying the firmware
Warning
A wrong rootfs makes the image unbootable: always flash the inactive image, so that the stick can still boot the other one, and keep a backup of all the partitions.
Transferring files from/to the stick
Run md5sum on the source and on the destination to make sure that the file has not been corrupted.
Via SSH, from the stick to the PC and vice versa:
ssh admin@192.168.2.1 "cat /dev/mtd5" > mtd5.bin
cat rootfs.new | ssh admin@192.168.2.1 "cat > /tmp/rootfs.new"Via TFTP (a TFTP server must be running on the PC):
# tftp <PC IP>
tftp> get rootfs.new
tftp> put <filename> <directory>
tftp> qVia netcat (nc on the stick does not exit at the end of the transfer: stop it with CTRL+C)[4]:
# on the stick
nc -l -p 12345 > /tmp/rootfs.new
# on the PC
nc 192.168.2.1 12345 < rootfs.newInfo
On Windows run the commands from cmd (not PowerShell) and replace cat with type.
Extracting and repacking the rootfs
The rootfs is a SquashFS (LZMA) image: on the stick it is in r0 (/dev/mtd5) for the image 0 and in r1 (/dev/mtd7) for the image 1, while the kernel is in k0 (/dev/mtd4) and k1 (/dev/mtd6).
Warning
Run both commands as root, otherwise the rootfs image might be damaged.
# unsquashfs mtd5.bin
# mksquashfs squashfs-root rootfs.new -b 131072 -comp lzma -no-recoveryThe RTL960x emulator runs the extracted firmware in QEMU (qemu-user-static) to modify and test it before flashing it: any file in its custom folder is copied over squashfs-root when leaving the chroot, and the custom startup scripts go in /etc/init.d/rc35.
Flashing a new rootfs
Check which image is running (nv getenv sw_active): flash mtd6/mtd7 if the image 0 is running, mtd4/mtd5 if the image 1 is running. The following commands flash a new rootfs to the image 1 and boot it:
# flash_eraseall /dev/mtd7
# cat /tmp/rootfs.new > /dev/mtd7
# nv setenv sw_version1 NEW_SOFTWARE_VERSION
# nv setenv sw_commit 1
# rebootIf cat fails with cat: write error: Invalid Argument, write the image to the block device instead:
# flash_eraseall /dev/mtd7
# cat /tmp/rootfs.new > /dev/mtdblock7Repacking a firmware upgrade file
The firmware upgrade files of the ODM firmwares (e.g. V-SOL, T&W, ODI) are a tar containing the kernel (uImage), the rootfs, the fwu.sh upgrade script, the fwu_ver version file and the md5.txt checksums: after replacing the rootfs, update the checksums and repack it, then upload it from the Web GUI firmware upgrade page[4:1]:
tar -xf firmware.tar
mv rootfs.new rootfs
md5sum fwu.sh rootfs uImage fwu_ver > md5.txt
tar -cvf ../firmware-mod.tar *The Firmware_Mod folder of the RTL960x repository contains the community patches for the ODI DFP-34X-2C2, V-SOL V2801F and T&W TWCGPON657 (Bootstrap Web GUI, VLAN, speed and software version fixes).
Enabling the Web UI
# /bin/iptables -D INPUT -p tcp --dport 80 -j DROPCopying the configuration and the logs
The same commands of Transferring files from/to the stick work for the configuration and the logs:
# ssh admin@192.168.2.1 "cat /tmp/omcilog" > omcilog.log
# cat lastgood.xml | ssh admin@192.168.2.1 "cat > /var/config/lastgood.xml"Info
This section is based on the V1_7_8_210412 version of the stick's firmware
Adding support to configurable SW and HW versions, Vendor ID and equipment ID
/etc/scripts/flash can be modified in order to add support for some variables implemented in omci_app but removed from xmlconfig. The modified file is below.
flash set will still print an error but the change wil be persisted. You can check that by running the relative flash get command
#!/bin/ash
#
# usage: flash.sh [cmd] ...
#
DEFAULT_FILE="/etc/config_default.xml"
DEFAULT_HS_FILE="/etc/config_default_hs.xml"
LASTGOOD_FILE="/var/config/lastgood.xml"
LASTGOOD_HS_FILE="/var/config/lastgood_hs.xml"
# for array type in hw_setting
specific_mib_patten="(^HW(_|_WLAN0_|_WLAN1_)TX_POWER*)|(^HW_FON_KEYWORD$)"
rename_mib_patten="^HW_(NIC[0-1]|WLAN[0-1]_WLAN)_ADDR"
rename_mib_name="ELAN_MAC_ADDR"
hw_mib="^HW_|^SUPER_NAME$|^SUPER_PASSWORD$|^BOOT_MODE$|^ELAN_MAC_ADDR#|^WLAN_MAC_ADD$|^WAN_PHY_PORT$|^WIFI_SUPPORT$|^BYTE$|^WORD$|^DWORD$|^INT1$|^INT2$"
var=""
case "$1" in
"all")
# echo "------ [$1] Display all settings ------"
if [ $# -eq 1 ] || [ "$2" = "hs" ]; then
/bin/xmlconfig -os -hs
fi
if [ $# -eq 1 ] || [ "$2" = "cs" ]; then
/bin/xmlconfig -os
fi
exit 0
;;
"default")
# echo "------ [$1] Restore to default configurationg ------"
if [ "$2" = "cs" ]; then
/bin/xmlconfig -def_mib
/bin/xmlconfig -if $DEFAULT_FILE -nodef && /bin/xmlconfig -of $LASTGOOD_FILE
echo "Reset CS to default configuration success."
elif [ "$2" = "hs" ]; then
/bin/xmlconfig -def_mib -hs
/bin/xmlconfig -if $DEFAULT_HS_FILE -nodef && /bin/xmlconfig -of $LASTGOOD_HS_FILE
echo "Reset HS to default configuration success."
elif [ "$2" = "voip" ]; then
/bin/xmlconfig -def_voip_mib
/bin/xmlconfig -of $LASTGOOD_FILE
echo "Reset VoIP to default configuration success."
else
echo "Restore to default configurationg fail."
/bin/sh $0 -h
exit 1
fi
echo "Please reboot system."
exit 0
;;
"get" | "gethw")
# echo "------ [$1] Get a specific mib parameter from flash memory. ------"
if [ "$2" != "" ]; then
para=$2
if [ `echo $para | egrep $rename_mib_patten` ]; then
para=$rename_mib_name
fi
#echo "/bin/xmlconfig -g $para"
if [ `echo $para | egrep $specific_mib_patten` ]; then
/bin/xmlconfig -g $para | sed -r "s/$rename_mib_name+/$2/g" | sed -r "s/,+//g"
else
local_nv_getenv=`nv getenv $para`
if [ -z "${local_nv_getenv}" ]; then
/bin/xmlconfig -g $para | sed -r "s/$rename_mib_name+/$2/g"
else
echo "${local_nv_getenv}" | sed -r "s/$rename_mib_name+/$2/g"
fi
fi
if [ "$?" = "0" ]; then
exit 0
fi
else
/bin/sh $0 -h
exit 1
fi
;;
"set" | "sethw")
# echo "------ [$1] Set a specific mib parameter into flash memory. ------"
if [ "$2" != "" ] && [ "$3" != "" ]; then
para=$2
if [ `echo $para | egrep $rename_mib_patten` ]; then
$para=$rename_mib_name
fi
if [ $# -eq 3 ]; then
var=$3
else
while [ $# -ge 3 ]
do
# for multiple decimal values: dec2hex and concatenate all setting value
if [ "$3" = "08" ] || [ "$3" = "09" ]; then
# 08 & 09 are not invalid octal number
var=$var$3
else
var=$var`printf "%02x" $3`
fi
shift
if [ $# -ge 3 ]; then var=$var","; fi
done
fi
#echo "/bin/xmlconfig -s $para $var"
/bin/xmlconfig -s $para $var | egrep "[ERR]"
if [ $? == 0 ]; then
nv setenv $para $var
else
# Clear the ovveride from nv if it is there since we wrote it to xmlconfig
nv setenv $para
fi
if [ "`echo $2 | egrep $hw_mib`" = "" ]; then
/bin/xmlconfig -of $LASTGOOD_FILE
fi
/bin/xmlconfig -of -hs $LASTGOOD_HS_FILE && exit 0
else
/bin/sh $0 -h
exit 1
fi
;;
"-h")
echo 'Usage: flash.sh [cmd]'
echo 'cmd:'
echo ' all <cs/hs> : Show all settings.'
echo ' default <cs/hs> : Restore to default configuration.'
echo ' get MIB-NAME : get a specific mib parameter from flash memory.'
echo ' set MIB-NAME MIB-VALUE : set a specific mib parameter into flash memory.'
echo
echo ' Note: When set the MIB_ARRAY or MIB_VALUE overflowed,'
echo ' xmlconfig will truncate the redundant part.'
echo ' Take signed integer for example:'
echo ' 1. Set value=-6442450944(0xfffffffe80000000),'
echo ' and get value=-2147483648(0x80000000)'
echo ' 2. Set value=-2147483649(0xffffffff7fffffff),'
echo ' and get value=2147483647(0x7fffffff)'
echo ' 3. Set value=2147483648(0x80000000),'
echo ' and get value=-2147483648(0x80000000)'
echo ' 4. Set value=4294967296(0x100000000), and get value=0(0x0)'
echo
;;
*)
/bin/sh $0 -h
exit 1
;;
esacIncreasing the length of the software version from 13 to 14 characters
omci_app has a hard-coded limit of 13 characters for the software version, which is too low. We can binary patch it to increase it to 14 (or more, if you dare/need)
JVhEWjAwNCUAAAAIAAgACAAAAAAAAAAAAAAAAAAAAABvbWNpX2FwcG9tY2lfYXBwH4sIAAAAAAAA
AwMAAAAAAAAAAAAfiwgAAAAAAAADY2BoYGZgYFjh9Uq/aNcZQdXsOh3R5ktr/fd0sTEwcuTnJmfG
JxYUYJVlZGAA0gCHsMK2QQAAAAAAAEQlWERaMDA0JQ==Save it as omci_app.xdelta.base64, then run:
# base64 -d omci_app.xdelta.base64 > omci_app.xdelta
# xdelta patch omci_app.xdelta bin/omci_app bin/omci_app.new
# mv bin/omci_app.new bin/omci_appFor reference, the patch changes the follwing section of the omci_app:
-00408c24 24 05 00 0e li a1,0xe
+00408c24 24 05 00 0f li a1,0xf
-00408cf0 24 05 00 0f li a1,0xe
+00408cf0 24 05 00 0f li a1,0xf(It's inside the function referencing the string OMCI_SW_VER1)
The original file md5sum is: 4aea2f72bacc11256b7e2c1583d2ad4f The patched file md5sum is: da20327c4c002e4c27f82f6ee63dbc1a
Enabling PLOAM logging
/etc/scripts/flash set OMCI_DBGLVL 1
/etc/scripts/flash set OMCI_DBGLOGFILE 1
reboot
/bin/omcicli set logfile 1 ffffffff- The binary log will be placed inside:
/tmp/omcilog - You can convert it into a .pcap file using omcilog2pcap
- You can then open it with Wireshark by installing this OMCI plugin from GitHub
If you want to log everything since the stick boots, you can create a custom rootfs. Place the last command inside etc/runomci.sh as the last line of the file
Known Bugs
Miscellaneous Links
OMCI MIB, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/OMCI_CLI.md ↩︎
Diag, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/DIAG.md ↩︎
Firmware Partition, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/fw_part.md ↩︎
Modify firmware, Anime4000/RTL960x https://github.com/Anime4000/RTL960x/blob/main/Docs/Modify_Firmware.md ↩︎ ↩︎