• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Got Fiber, ONT Stick Options?

longblock454

2[H]4U
Joined
Nov 28, 2004
Messages
2,906
So I just got fiber, pretty lucky out in the sticks, provider is Joink, gig symmetrical. Only option from them is a Calix GS5229XG GigaSpire ONT router/wifi box thing (it does have a 10G ethernet port!) with no bridge mode. Though it does have a feature i've not seen before they call "DMZ Hosting", "DMZ hosting enables a LAN device to use the device WAN IP address as its own. DMZ places the LAN device outside the firewall." I've not played with it yet but I don't want to be double natted. My router is pfsense netgate hadware with SFP+, what options do I have for an ONT stick?

Provided ONT does not have the SFP module on the fiber, so I can't just clone it with an SFP Wizard and my hardware is not listed on the pon.wiki website.

Joink also said they have faster speeds in the works, so whatever I go with needs to be > than gig.
 
cant you just use a cat cable since its only 1g anyway? if you put your equipment into the dmz it should then handle everything. i think.
 
I'll test their DMZ feature and see what it does, but overall goal would be to eliminate the carrier ONT to simplify and remove that failure point. ONT sticks can't cost too much and I have the ONT MAC, was hoping for some suggestions, somebody here has to be experienced with them.

The Calix devices don't seem very popular and and there is several different technologies used on FTTH, not sure how to tell what flavor mine is. Google isn't helping much.

Another benefit is the ability to have a hot spare, not having to deal with the provider, especially on off hours.
 
Fiberstore. They are the place to go for any fiber optic transceiver needs. We use them all over at work (not their GPON stuff, their regular ethernet stuff) and I know a guy who works at a tier-1 ISP, they use them. Hell your ISP might even use them on the OLT side. The trick is that you have to get one that is in all ways compatible with the network you are on, and it may require cloning settings from your ONT. Generally you have to clone the MAC, but sometimes also the serial number and other pieces of info. This is something to research before you get in to it, and also if you are going to need one of their programmers to change the programming on it, or if you can change it all via web/ssh on the module itself (you probably can you don't usually need the programmer). Generally what you need to know:
  1. The kind of network you are on: GPON, XGPON, XGSPON, EPON, etc. This is the alpha and omega, as each are a different frequency, laser speed, etc so you have to have the right one to talk to the network. Also be aware they may change this later. The ONT/router you've listed says it is XGS-PON only so that would presumably be what your ISP is using.
  2. The PON serial number aka ONU ID aka FSAN. It will be 12 letter in total, given that this device is a Calix it should start with CXNK followed by 8 hexadecimal characters. You should try and find it in the web admin, if it is there (under system status or WAN status or something like that maybe) rather than on the box as sometimes the one on the box isn't correct.
  3. The MAC of the WAN side of the ONT. Again, should be able to get this in the web admin.
  4. The kind of login, IPoE, PPPoE, etc. If there's any credentials (using PPPoE), what are those?
Then it is a matter of setting up your ONU to patch the serial and MAC. That is basically what it takes to make it look just like the provided ONT to their equipment. You then need to configure your router to whatever they want. For IPoE that is just DHCP basically, for PPPoE you set that mode then give it the login credentials. If everything works, you are up and running, your router talks straight to the SFP which now is the ONU.

The big issue is that if it doesn't, you are on your own with forums and Claude for troubleshooting. Your ISP won't help you at all, and might even get mad at you. I can't really help you past this general info as I have no idea about your ISP or that ONT/router, this is just general info on how GPON works.

Couple other things of note: You need the ONU part, not the OLT part. OLT part is them, ONU is you. Also there are cheaper ones without the web interface, those MIGHT work, but only if your provider doesn't care about the MAC and serial. Some that use PPPoE don't, they just use the login and password. However I wouldn't count on it, most need those to be set correctly. I think you can program the cheaper ones to have the MAC and serial you want with the programmer I linked, but of course it is more costly so if you aren't programming multiple modules it doesn't make much sense.
 
Fiberstore. They are the place to go for any fiber optic transceiver needs. We use them all over at work (not their GPON stuff, their regular ethernet stuff) and I know a guy who works at a tier-1 ISP, they use them. Hell your ISP might even use them on the OLT side. The trick is that you have to get one that is in all ways compatible with the network you are on, and it may require cloning settings from your ONT. Generally you have to clone the MAC, but sometimes also the serial number and other pieces of info. This is something to research before you get in to it, and also if you are going to need one of their programmers to change the programming on it, or if you can change it all via web/ssh on the module itself (you probably can you don't usually need the programmer). Generally what you need to know:
  1. The kind of network you are on: GPON, XGPON, XGSPON, EPON, etc. This is the alpha and omega, as each are a different frequency, laser speed, etc so you have to have the right one to talk to the network. Also be aware they may change this later. The ONT/router you've listed says it is XGS-PON only so that would presumably be what your ISP is using.
  2. The PON serial number aka ONU ID aka FSAN. It will be 12 letter in total, given that this device is a Calix it should start with CXNK followed by 8 hexadecimal characters. You should try and find it in the web admin, if it is there (under system status or WAN status or something like that maybe) rather than on the box as sometimes the one on the box isn't correct.
  3. The MAC of the WAN side of the ONT. Again, should be able to get this in the web admin.
  4. The kind of login, IPoE, PPPoE, etc. If there's any credentials (using PPPoE), what are those?
Then it is a matter of setting up your ONU to patch the serial and MAC. That is basically what it takes to make it look just like the provided ONT to their equipment. You then need to configure your router to whatever they want. For IPoE that is just DHCP basically, for PPPoE you set that mode then give it the login credentials. If everything works, you are up and running, your router talks straight to the SFP which now is the ONU.

The big issue is that if it doesn't, you are on your own with forums and Claude for troubleshooting. Your ISP won't help you at all, and might even get mad at you. I can't really help you past this general info as I have no idea about your ISP or that ONT/router, this is just general info on how GPON works.

Couple other things of note: You need the ONU part, not the OLT part. OLT part is them, ONU is you. Also there are cheaper ones without the web interface, those MIGHT work, but only if your provider doesn't care about the MAC and serial. Some that use PPPoE don't, they just use the login and password. However I wouldn't count on it, most need those to be set correctly. I think you can program the cheaper ones to have the MAC and serial you want with the programmer I linked, but of course it is more costly so if you aren't programming multiple modules it doesn't make much sense.
Wow, with this level of complexity, I'd be trying the 'DMZ mode' first and see if it causes any use case issues versus going down this rabbit hole...
 
Wow, with this level of complexity, I'd be trying the 'DMZ mode' first and see if it causes any use case issues versus going down this rabbit hole...
I mean, you are literally trying to hook an unauthorized device up to their network. Ya it can be complex. It does depend on the ISP and how they do things though. If they use PPPoE (most don't anymore) then sometimes none of that is necessary, any generic GPON ONU will do and you just put in the login and password on your router, same as you'd have to do on their router. The issue is that if they don't use that, how do they authenticate who's who? The answer is the MAC and/or serial.

Something to remember with GPON and DOCSIS is they are PASSIVE networks, meaning that many devices are connected to passive splitters and then back to one connection on the OLT/CMTS. In GPON/XGS-PON you can have as many as 128 houses hooked to one OLT. That all comes down one fiber optic cable that then gets split passively to go to each house. So there are a whole bunch of devices talking on the same cable. It needs a way to know who's who.
 
Last edited:
The web interface doesn't tell me much, I do have the WAN MAC and the default SSID = CXNK01CAD9D3, which looks suspiciously like the serial number!
It could be. Also check the box and see if there's a serial like that anywhere on it.
 
I've reluctantly joined the 8311 Discord group, not much on the Calix side as it's rare, but a guy or two has bypass working with their own custom ONT stick firmware. I'm going to let this soak for a while then rip my ONT apart and dump a boot log, I'm a linux guy and have the ability to do the custom work, just want to make sure everything is stable before i tear into it.


Nothing further of interest or help on the box.
 
Back
Top