Checks and common problems
Checks
- Tunnel: “Tunnels” menu — “● online”; the “Check” button shows the tunnel, telnet and SNMP to the OLT separately. On the MikroTik: /interface wireguard peers print — the hub peer has a last-handshake.
- OLT: the OLT page shows boards, PON ports and the ONU count; “Poll OLT” refreshes the data immediately.
- TR-069: the ONU card shows the ACS as “online”; after the “TR-069 script” changes from the card apply within seconds.
The tunnel does not come up
- Outgoing UDP 51820 is blocked — check the firewall of the MikroTik and the upstream network.
- Wrong time on the MikroTik — WireGuard is sensitive to the clock; enable the NTP client.
- The add-on script or the “TR-069 script” stopped with “This router has another EVX-OLT tunnel” — the script belongs to another tunnel. Take the script of the tunnel that runs on this router.
OLT not responding
- Wrong OLT IP — you need the OLT management address as the MikroTik sees it (check with ping from the MikroTik).
- Telnet or SNMP is disabled on the OLT, or an ACL on the OLT blocks the MikroTik address.
- Wrong telnet login or password, or the user lacks rights.
The ONU does not reach TR-069
- There is no Mgmt VLAN with DHCP for ONUs, or the pool is not set in the OLT settings.
- There is no route from the ONU Mgmt network to the ACS via the MikroTik.
- Changes apply only after a few minutes — run the “TR-069 script”.
Security
- Nothing is opened to the outside on the MikroTik: the router connects to the hub itself.
- Only telnet 23 and SNMP 161 to the OLT pass from the tunnel into the ISP network, and after the “TR-069 script” — TCP 58000 and 7547 to the ONU Mgmt pools.
- OLT passwords are stored encrypted; every command on the OLT is in the portal log.
- On the OLT page you can restrict OLT access (ACL) to the MikroTik address — the platform checks the login and rolls back the change if access is lost.
Contact
Write to us via the form on olt.am or your manager — we will connect together.