Welcome Guest ( Log In | Register )

3 Pages  1 2 3 >Bottom

Outline · [ Standard ] · Linear+

Home Networking Ditch ONU, use GPON SFP on Business Grade Router, 2.5G ONU for Unifi & Maxis, NO NEED VLAN

views
     
miloaisdino
post Jun 25 2020, 03:44 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Doraku @ Jun 25 2020, 03:28 PM)
This is kinda super late, but i did ask this kinda question before.

Here a answer from soonwai
https://forum.lowyat.net/index.php?showtopi...post&p=89527265
*
iirc tm doesnt do auth based on gpon sn anymore. as long as the password is correct it should work

This post has been edited by miloaisdino: Jun 25 2020, 03:45 PM
miloaisdino
post Jun 26 2020, 12:10 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(amirsubhi @ Jun 26 2020, 11:00 AM)
as long as Mikrotik GPON SFP/Huawei support OMCI required by TM than it may work,

I haven't try it though for mikrotik.
*
https://blog.csdn.net/zhidc/article/details...Pai2-4.nonecase
Some gpon sticks are actually full fledged onts, even come with web interface. omci might work then
miloaisdino
post Jun 26 2020, 04:34 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Jun 26 2020, 04:24 PM)
This stick is ONU, might can work?
https://s.lazada.com.my/s.bI2ov
*
it might.. but some gpon sticks come without user interface with "locked loid and password" so you cant really use it unless someone has access to the olt side for whitelisting.. bummer
miloaisdino
post Jun 26 2020, 09:46 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(thankyou @ Jun 26 2020, 08:10 PM)
I don't think they ever authenticate with GPON SN or MAC as long as the password is correct. I've replace the ONU since 2012 and it was working all the while...
*
It's like some gpon sticks have their passwords locked to 123456780 so the only way is loid/sn auth but we know thats not what tm does.
miloaisdino
post Jun 27 2020, 01:17 AM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Jun 26 2020, 10:32 PM)
See feedback that, they show have WebUI to configure ONT Authentication
Since you have ER-12, test if that works.
Also, if possible, try override OLT OMCI command or manual OMCI, try remove/adjust Hardware Speed Capping, I like to remove speed cap VLAN 621 to achieve A+ Anti Bufferbloat. let PPPoE based speed limit.

SSH Log OLT of HG8240H5, OLT Provisioning:
CODE
1981-01-01 00:01:43 [Critical][Config-Log] Terminal:OLT(-),Result:Success,Type:Set,Msg:Me[11] Inst[257] Att[5] Val[0]
1981-01-01 00:01:43 [Critical][Config-Log] Terminal:OLT(-),Result:Success,Type:Set,Msg:Me[11] Inst[258] Att[5] Val[0]
1981-01-01 00:01:43 [Critical][Config-Log] Terminal:OLT(-),Result:Success,Type:Set,Msg:Me[11] Inst[259] Att[5] Val[0]
1981-01-01 00:01:43 [Critical][Config-Log] Terminal:OLT(-),Result:Success,Type:Set,Msg:Me[11] Inst[260] Att[5] Val[0]

I also have change TM to TIME ONT, what I do simply put my ONT Authentication Password.
Maybe TM OLT have list or SN check, between new HG8240 and HG8240H5, both have same "48575443" (HWTC) SN at first 8 HEX digit,
*
nice. looking at the ui screenshots from the reviews, it is an unlocked rebranded zte onu stick!
edit: it seems to be quite beefy, with 600mhz cpu and 256mb of ram. heck i wonder if it can hardware nat too!

also i used RED qos algorithm to improve bufferbloat on my mikrotik. needs quite a bit of tuning tho

This post has been edited by miloaisdino: Jun 27 2020, 01:27 AM
miloaisdino
post Jun 27 2020, 12:44 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Jun 27 2020, 03:32 AM)
Oh! I didn't know that was unlocked rebranded ZTE ONU stick.
I plan to have ER-X-SFP or ER-12, if that stick works, currently I using ER-X.

ER-X have "offload hwnat" to offload NAT to Hardware Level.
[attachmentid=10524476]

However, enable Smart QoS will make "hwnat" render useless,
plus very taxing CPU cycle and strain 12V 1A adapter.
I simply enable Smart QoS at Upload:
[attachmentid=10524477]

I saw some Maxis Fibre user able to get more speed than advertised, removing/increasing ONT Speed Limit help eliminate Bufferbloat, and no need QoS to be enable, and reduce router CPU usage!
*
sounds good that omci can be bypassed just by using a 3rd party onu. hopefully the huawei olt wont know how to provision the hard cap on the zte onu stick doh.gif (actually the maxis issued btu should be tm property, maybe the hard cap is tm's way of unfairly limiting maxis bw?)

any idea what brand of onu that maxis user used?

This post has been edited by miloaisdino: Jun 27 2020, 01:23 PM
miloaisdino
post Jun 28 2020, 07:27 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Jun 28 2020, 05:48 PM)
This what I hope for, just wanted a fair speed and better latency
Yes, my 300Mbps become 280Mbps in real world, same with upload become 42Mbps, and worst like streamyx, high jitter and lags,
I choose maxis because of routing to SG and no port get block, like TCP 6667, game will run perfectly with better NAT status.
I got HG8240H5 as TM gave me.
I remember when I press "reset" button, and internet speed become 4mbps, this show speed is capped on ONT, not OLT. even tho I put correct password.

---

I kind give up on Hacking Huawei HG8240H5, didn't find any exploit.
if thankyou manage to get ONU SFP stick to work on EdgeRouter 12, I will follow the same, and money well spend  biggrin.gif
*
ah that makes sense. at first when you connect without pppoe login your line will be capped to 4mbps (probably for hypptv stb), then upon pppoe login the olt will retroactively increase the speed cap of the ont by omci.

i wonder having 2 pppoe dialers behind the ont to different accounts can confuse the olt doh.gif

edit: maybe thats the key, omci configures a speed limit for port 2 on the huawei onu for maxis, but if the onu can be hacked for maxis to be on eg port 3 instead maybe omci will fail to speed cap?

This post has been edited by miloaisdino: Jun 28 2020, 07:32 PM
miloaisdino
post Jun 28 2020, 10:18 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Jun 28 2020, 09:01 PM)
SFP stick is more to universal version
No, it was under my PPPoE and get 4mbps ONT default settings
I have tried, not working, the ONT speed is shared.
If can hack and override, we have custom OMCI settings.

I thinking, upgrade to 500Mbps for a week and downgrade back 300Mbps, will ONT speed remain cap at 500?
Need call 123 for this.
*
i meant there will be a time lag between pppoe login and increase of speed cap.. all the onts in the same area share the same pw so i guess the speed cap is by detecting your account on pppoe?

taken from tm alcatel ont provisioning guide online:
Service Provisioning – Sample Service Configuration
7.1 Create ONT Infrastructure
Create ONTs using SLID Password.
configure equipment ont interface 1/1/5/1/10 sw-ver-pland AUTO
sernum ALCL:00000000 subslocid 0000000001 voip-allowed enable enable-aes enable

so any match for alcl sn or huawei sn ont will be allowed as long the pw (replaced by 0000000001) is correct for any speed

miloaisdino
post Sep 21 2020, 12:07 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 21 2020, 11:37 AM)
LTE Dongle detected, can view dongle WebUI, I think Maxis limit, I try put SIM to my phone, straight no line!

I guess, put dongle at Maxis Router serve via LAN
*
is the dongle even receiving an ip address from maxis? if no maybe it could be an apn issue, or might need to clone the imei of the maxis router onto the dongle. if ip address received but still cant access internet, might need to mangle the TTL setting for requests through the dongle on the mikrotik
miloaisdino
post Sep 21 2020, 12:32 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 21 2020, 12:25 PM)
Dongle I use is from Maxis, ZTE brand.

Mikrotik got dongle IP from "lte" Interface, 192.168.0.199
I can access dongle WebUI via 192.168.0.1
Dongle have IP 100.64.0.0/10
APN is fine, since can do nslookup through 192.168.0.1, other traffic is blocked.

Mangle TTL?
*
i suspect this is a TTL issue! its similar to how people used TTL changers to bypass tethering caps. try incrementing/decrementing the ttl of traffic destined to the dongle under "mangle" in mikrotik until it works
miloaisdino
post Sep 21 2020, 11:36 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 21 2020, 11:00 PM)
need find pfSense box with SFP~ x86 can handle gigabit easily biggrin.gif
I have test ping ttl under Maxis TP-Link - ZTE Dongle

CODE
TTL:
Address         PC          TP-Link > ZTE Dongle
------------------------------------------------
1.1.1.1         53          54
google.com      112         113
facebook.com    49          50


PC:
[attachmentid=10592982]

TP-Link Router with ZTE Dongle Attached:
[attachmentid=10592983]

53 < 54 is decrease by 1,

So, I do test Firewall Mangle on pppoe-out1:
CODE
Chain: prerouting
In. Interface: pppoe-out1

Action: change TTL
TTL Action: decrement by 1

it's worked! so I change pppoe-out1 to lte1, not working!

I wonder why not work on lte1, maybe dongle detect by MAC Address?
*
hmm so currently:
dongle +sim works when connected to pc --> maxis tplink
dongle doesnt work on mikrotik, sim doesnt work on phone

maxis detects ttl via Outgoing packets to their gateway, so Out Interface should be used instead of In Interface for mangle
https://forum.mikrotik.com/viewtopic.php?t=144140 (example of working for mikrotik dongle).

https://answers.microsoft.com/en-us/windows...3e-92fa5ca0bd16 the ttl from the ping is actually the "final" decremented ttl at the destination and is not what maxis receives! what i suspected was that the "original source" ttl value when dongle is connected to tplink is different from when dongle/sim is plugged anywhere else, so we need to "offset" the ttl somehow...

maybe can try connecting dongle by usb directly into pc instead then ping? that might rule out dongle detect mac address or other problems?

This post has been edited by miloaisdino: Sep 21 2020, 11:43 PM
miloaisdino
post Sep 22 2020, 12:27 AM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 22 2020, 12:24 AM)
Yeah,
PC > Maxis TP-Link + 4G Dongle = Works
PC > Mikrotik + 4G Dongle = Not Working, only "nslookup" works
I been thinking the same, I want to know what TTL is set in Maxis TP-Link,
If have tool to crack USB Ethernet between Dongle and Router, inspect packet that way?

Or crack TP-Link router?

I managed to open since I have extra during PKP, put UART header and putty serial console, I stuck at Login, dont know what username and password  doh.gif
» Click to show Spoiler - click again to hide... «

Plugging Maxis ZTE 4G Dongle into PC is same like plugging into Mikrotik, only "nslookup" works
[attachmentid=10593029]
[attachmentid=10593030]

I try follow that guide carefully, and do one by one finding, make Mikrotik ALL in One rclxm9.gif
*
haha. maybe try static ttl first, easier than cracking tplink (there are only 255 combinations to try! (much fewer since ttl 1-35 will pretty much kill lots of websites)try near 64, 128, 255 +- or other common ttl maybe?)


This post has been edited by miloaisdino: Sep 22 2020, 12:32 AM
miloaisdino
post Sep 22 2020, 12:35 AM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 22 2020, 12:34 AM)
Do I need to disable FastTrack Connection?
*
for traffic destined to the dongle only, yes! anyway 4g isnt that fast shouldn't have any bottlenecks doh.gif
QUOTE(calvin1688 @ Apr 16 2019, 04:05 PM)
from the photo indicate you must insert the modem into the pc.FYi although you can plug your usb dongle into your pc & the usb dongle can shown blue light but due to maxis had lock the usb dongle thus the usb dongle will only work when you plug into the maxis tp-link router.
*
QUOTE(G K Lai @ Apr 16 2019, 11:09 PM)
Yup! You are right, I plug it to PC just for testing purpose.
Because it can't seems to work on Maxis' TP-Link router so I try it on PC.
That was last night when Maxis Fibre were down for many people, so I have to try hard for this backup SIM to work.
There was once when I plug it to PC, it seems so have connection, then it ask new software is available and if I would like to update.
I clicked [Yes] then... never get it to work again since then... bangwall.gif
The update should came from either Maxis or ZTE, I can't tell when the message simply pops-up just like that.   sad.gif
*
hmm could be mac address? maybe clone the tplink mac onto mikrotik too?!
https://wiki.mikrotik.com/wiki/Manual:Interface/LTE

QUOTE(trix @ May 28 2019, 02:08 PM)
for those with dongle that has been updated and unable to connect anymore, try these steps:

1. browse to the dongle IP address using firefox
2. go to Settings -> Dial-up settings
3. right click in the page -> Inspect Element
4. search for #auto_mode, double click on disabled="" on the highlighted line, delete it, press enter
old value =
CODE
<input type="radio" name="modeGroup" id="auto_mode" value="auto_dial" data-bind="checked: selectMode, enable: false" disabled="">

new value =
CODE
<input type="radio" name="modeGroup" id="auto_mode" value="auto_dial" data-bind="checked: selectMode, enable: false" >

5. Automatic radio button is now enabled, click on it
6. search for apply, delete disabled="" as well
old value =
CODE
<input type="button" class="btn-1" data-bind="click: save, enable: false" trans="apply" disabled="" value="Apply">

new value =
CODE
<input type="button" class="btn-1" data-bind="click: save, enable: false" trans="apply" value="Apply">

7. Apply button is now enabled, click on it, you should receive success message

Now, the dongle should be usable again with maxis router archer c5v and should auto connect if fiber connection is down.
*
QUOTE(Connexiionz @ Oct 24 2019, 01:52 AM)
Pls note that there is a mac address lock in place... The dongle will only work properly with c5v with firmware 190304 because of dhcp addressing issue... BTW 190304 is the latest version of the routers firmware.
With the mac address lock... U will not be able to use the dongle anywhere else besides ur router.

Latest news.

The sim will not work on anything other than maxis routers or dongle. You maybe the lucky few whose sim is not locked to the maxis devices...
*
confirm mac address!! not TTL!! mac address for maxis usb should be maxis router mac +- a few digits on the last octet!

This post has been edited by miloaisdino: Sep 22 2020, 12:46 AM
miloaisdino
post Sep 22 2020, 11:05 AM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 22 2020, 01:57 AM)
No wonder, I type TTL value from 1 until 255 no luck doh.gif

some digging:
[attachmentid=10593106]
in maxis router show some list mac address

[attachmentid=10593107]
when 4G backup plug into PC, this mac address kind static across connect-disconnect

[attachmentid=10593108]
[attachmentid=10593109]
[attachmentid=10593110]
the Dongle MAC address will generate randomly every USB plugged

Question is, can Mikrotik act like TP-Link? fool ZTE Dongle, or TP-Router has "special" driver for dongle hmm.gif
*
maybe the dongle sees the mac address of the tplink/mikrotik and decides whether to block the connection. so maybe try using /interface on mikrotik to set the mac address of the maxis router facing the dongle to "fool" the dongle? arp -a shows the mac address of the dongle itself after every reboot (not the pc)

or maybe theres a hidden mac address filtering page on the dongle webui itself that can be found by inspect element. then we can just disable it!

This post has been edited by miloaisdino: Sep 22 2020, 11:23 AM
miloaisdino
post Sep 23 2020, 04:49 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 23 2020, 04:28 PM)
I have tried this, and not working. bridge > lte1
You mean: bridge > bridgeLTE---lte1 ?
I create bridgeLTE and add a port, the lte1 interface are not exist sad.gif
*
https://forum.mikrotik.com/viewtopic.php?t=113569#p614298
this might be helpful!
miloaisdino
post Sep 24 2020, 09:57 AM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 24 2020, 02:49 AM)
tried, lte1 passthrough to bridge adapter not work:
[attachmentid=10594902]

I guess, time to UART console for some iptables:
[attachmentid=10594903]
WebGUI login not work in UART console, I dont know what is the valid login
UART log here: https://gist.github.com/Anime4000/4dd729dc4...7eec36121184992
*
can't switch usb device
sd 0:0:0:1: [sda] we have tried 10 times, but the USB device is still not ready, just return here!
sd 0:0:0:1: [sda] media is not present, wait for 0.5 seconds
getConfigFromMergeFile 150 decrypt mode_switch.conf successfully

and

usbcore: registered new interface driver cdc_ether
usbcore: registered new interface driver rndis_host
Failed to to open /proc/tty/driver/usbserial

clue from here onwards

and maybe the uart password can be found from router backup config file (downloaded from webui)?

This post has been edited by miloaisdino: Sep 24 2020, 10:09 AM
miloaisdino
post Sep 24 2020, 08:59 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 24 2020, 08:55 PM)
I tried run nmap scan, none sad.gif
router backup config is encrypted, cannot see inside, unless I extract router flash and binwalk it, find shadow file and run password crack?
*
https://github.com/JackDoan/TP-Link-ArcherC5-RCE
looks useful! worth a shot
miloaisdino
post Sep 24 2020, 11:30 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 24 2020, 10:14 PM)
it works half way, some can be read
[attachmentid=10596323]
*
now thats some weird encoding :/
anyways the config looks like the "TR069 xml IGD style" of config, probably because customised for maxis

This post has been edited by miloaisdino: Sep 24 2020, 11:30 PM
miloaisdino
post Sep 25 2020, 01:18 AM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 25 2020, 12:53 AM)
plug directly, so I it can print randomized device MAC Address
it appear XML type.
I trying in my Linux Box:
[attachmentid=10596339]
It works!!! I love you pcat miloaisdin!!! XD

I found something inside XML:
CODE
       <User instance=2 >
         <Level val=2 />
         <Username val=MaxSysAdm />
         <Password val=Ng88Mxs@2019! />
         <Allowed_LA_Protocols val=HTTP,HTTPS />
       </User>


Login with "administrator" & "SN" as password:
[attachmentid=10596345]
admin

Login with "MaxSysAdm" & "Ng88Mxs@2019!" as password:
[attachmentid=10596352]
root

With root, now can set "Full Cone NAT" for Xbox and PlayStation! no need UPNP or Port Forward, since automatic incoming 1:1 NAT
[attachmentid=10596359]

I made a quick guide here: https://hitoha.ga/hack-stock-maxis-router-t...ink-archer-c5v/

Since I have extra Archer C5v, I going to sacrifice this for Research! I going to share conf.xml file while 4G Dongle attached!
*
wow nice that fullcone works. but ive seen routers that dont support hw nat when fullcone is enabled, might have performance penalty for faster connections,wonder if tplink is liddat

and the packet capture filename that u blurred, was that yr mac address? quite disturbing if the router is made to silently packet capture traffic for no reason...

This post has been edited by miloaisdino: Sep 25 2020, 01:23 AM
miloaisdino
post Sep 25 2020, 01:28 AM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 25 2020, 01:23 AM)
during UART Serial sessions, I notice this router have 4 core @ 900MHz CPU
*
i suspect its actually dual core (2 physical core) but presented as 4 logical core in linux (not 100% sure), anyway most regular ac routers max out at about 700+ mbps without hw nat, should not be an issue unless >800mbps package!

edit: good to disable tr069 and vlan 821 in case maxis releases a fw update to change the password and hash the password entry in the config file!!

This post has been edited by miloaisdino: Sep 25 2020, 01:31 AM

3 Pages  1 2 3 >Top
 

Change to:
| Lo-Fi Version
0.0663sec    0.92    7 queries    GZIP Disabled
Time is now: 5th December 2025 - 10:52 AM