Connection documentation

MikroTik tunnel

The platform needs no public IP on the OLT and no port forwarding. The link is a WireGuard tunnel from your MikroTik to the hub vpn.olt.am (UDP 51820).

What the script does

  1. Creates the interface evx-olt and the hub peer; tunnel address 10.250.x.y/16.
  2. Forwards only two ports from the tunnel address to the OLT: telnet 23 and SNMP 161 (dst-nat + masquerade). Nothing else enters the provider's network.
  3. Lets the OLT/ONUs reply to the hub (ACS, NTP, traps) through the tunnel: masquerade towards evx-olt.
  4. All objects are marked comment="EVX-OLT …": the script is safe to run again and can be removed with one command.

How to run it

Copy the line from the workspace (wizard step 1) and paste it into New Terminal in WinBox/WebFig. The link is single-use and valid for 5 minutes. Check: /interface wireguard peers print : the peer will show last-handshake; in the workspace the tunnel status becomes “online”.

Several OLTs behind one MikroTik

Each OLT gets its own ports on the tunnel address (e.g. 2323/2161 for the second one). They are added from the same wizard: “Add OLT to tunnel”.

If it does not come up

  • No handshake: check that outgoing UDP 51820 is not blocked by a firewall and that the MikroTik clock is correct (WireGuard is sensitive to time).
  • Tunnel is up but the OLT does not reply: use “Check connection” in the workspace; it shows ping, telnet and SNMP separately. Most often it is a wrong OLT IP or telnet is disabled.