FiberControl Manual
A practical guide to running your OLTs and ONUs from PlenoAgent: connecting and preparing an OLT, monitoring signal and inventory, authorizing ONUs for a subscription, linking them to billing, managing the subscriber's WiFi and diagnosing the most common problems.
1What FiberControl is and what you need
FiberControl connects PlenoAgent to the OLTs in your fiber network. It reads the ONU inventory and optical signal, authorizes new ONUs with the subscriber's configuration, applies suspensions and reactivations from billing, and lets you change the customer's WiFi without a site visit. Every change to an OLT goes through a queue with retries, is verified by reading the OLT back after writing, and is recorded in the audit log.
| Requirement | Why |
|---|---|
| FiberControl module active | Without it the page shows that the module is not active and subscriptions do not offer the fiber access block. |
| The company's VPN tunnel running | PlenoAgent reaches the OLT through your tunnel, using its private address. The OLT is never exposed to the internet. |
| OLT CLI username and password | FiberControl works through the OLT's command line (SSH or Telnet, depending on the model). Credentials are stored encrypted. |
| A compatible OLT model | Each model and firmware has a driver with certified capabilities. Anything not yet certified for your model is shown disabled, with the reason. If your OLT has no driver, see 2.2. |
FiberControl never "tries and sees" on a production OLT. If an action (authorizing, writing a static IP, creating profiles, managing WiFi) is not certified for your OLT's model and firmware, the button does not appear or the form explains that it is not available yet.
2Adding and preparing an OLT
On the OLTs tab, the Add OLT button opens the setup wizard. The wizard has five steps and writes nothing to the OLT until the last one.
Connect. Choose the Vendor and enter the name, private host (the OLT's management IP inside your network), port, transport, username and password. Use Detect model: PlenoAgent logs in to the OLT over the chosen transport, identifies the hardware and firmware, and confirms the credentials work. You can also pick the model from the list of compatible ones: when you do, the transport and port adjust to what that model uses (for example, Telnet on port 23 for older-firmware V-SOL units; see 2.3).
Read the OLT. PlenoAgent reads the OLT once: it confirms the connection, lists the ONUs and takes a configuration backup. The following steps work on that backup without touching the OLT again.
Network. Set the VLAN the OLT uses to carry subscriber traffic, and the gateway and mask each ONU receives. With From a billing router you pick the router the OLT hangs from, read its subnets, and choosing one fills these fields in. Here you also choose or create the line profile, the DBA profile and, if you want, a speed cap for the whole OLT.
ONU models. Each ONU model gets a service profile and the LAN ports it routes. An adaptive profile works for every model and avoids the profile mismatch warning. Tick only the ports the model actually has.
Review. You see exactly what PlenoAgent will create on the OLT. When you press Apply, it takes a fresh backup, creates only what is missing, verifies it, and saves the OLT's service template.
An OLT in Observe only is read-only: no ONUs are authorized, no profiles are created and no descriptions are written. It is the recommended mode to start with. When you want PlenoAgent to operate the OLT, turn it off when editing the OLT or with Allow changes on the wizard's last step.
2.1What PlenoAgent leaves alone
Profiles that already existed on the OLT are yours and are shown as External · read-only. PlenoAgent only creates and manages objects named PLENO_*, never modifies an operator's configuration, and stops the preparation if an ID it needs is already taken by a different definition: you will see the conflict and can choose another ID.
2.2Unidentified model
If your OLT is not on the compatible list, or detection does not recognize it, you can still register it as Unidentified model — no driver yet. It is saved without being polled or written to, and shows in the list as Awaiting driver. Test stays available to confirm PlenoAgent can reach it.
A model without a driver is not a "no". Contact us at [email protected] or on WhatsApp at +593 98 867 1418 with the OLT's brand, model and firmware. We build and certify the driver against your real hardware: reading first (inventory, signal, backups), then writing, one operation at a time (authorizing, static IP or PPPoE, suspending, WiFi). Each capability is enabled only once it has been verified on your OLT. What the failed detection captured already gives us a starting point.
2.3V-SOL: why it connects over Telnet
Many older-firmware V-SOL OLTs (V2.1 and V2.2) never release SSH sessions: every connection leaves a session occupied even when it is closed cleanly, until the table fills up. From then on the OLT accepts the username and password but refuses to open the session, and nobody (neither PlenoAgent nor your technicians) can log in over SSH until those sessions are released, which on some units only happens with a reboot. Over Telnet, the line is freed on logout.
That is why those models use Telnet on port 23 by default. Telnet travels inside your private VPN tunnel, never over the internet. If you prefer SSH on your OLT, you can change the transport when editing the OLT: it is a per-OLT setting.
V-SOL blocks Telnet until it is allowed in its login access list. If connecting fails with The OLT refused the connection on this port, log in to the OLT and allow Telnet for the address PlenoAgent connects from (the tunnel's). Also check that port 23 is not filtered on the router in between.
3A tour of the module
| Tab | What it is for |
|---|---|
| Overview | OLTs, PONs and ONUs online, synced bindings and open alarms, with the alarm queue to review and acknowledge them. |
| OLTs | Your OLTs with status, ONUs and inventory. Click the row to edit it; buttons to monitor, WiFi, test the connection and sync. |
| ONUs | Every ONU on every OLT, with search, filters and a shortcut to Unauthorized ONUs. Click the row to open its detail. |
| Provisioning | The queue of operations on the OLTs: authorizations, changes, suspensions, backups. Shows attempts and errors, and lets you retry. |
| Profiles | DBA, line, service and traffic profiles imported from each OLT, the service template and the setup wizard. |
| Backups | Configuration backups of each OLT with firmware, size, checksum and date. |
| Audit Logs | Every operation run on an OLT: who or what requested it, the result and the error code. |
The User manual button in the header opens this manual in the active language.
4Monitoring: inventory, signal and alarms
4.1What is read and how often
With Active monitoring on for the OLT, PlenoAgent records the ONUs' optical signal every 5 minutes and runs a full inventory (new and missing ONUs, model, PON port, distance and the MACs of the customer's equipment) every 15 minutes. Turning it off stops both; turning it back on immediately runs a connection test and an inventory.
The buttons on the OLT row force a read without waiting: Test opens a management session and confirms network, credentials and CLI; Sync queues an inventory.
4.2Signal quality
| RX power | Quality |
|---|---|
| -22 dBm or better | Good |
| Between -26 and -22 dBm | Warning |
| Worse than -26 dBm | Critical |
Each ONU's detail has its signal history (RX and TX) over 24 hours, 7 days or 30 days. Gaps in the chart are periods with no reading, not zero signal. Some OLTs cannot read an ONU's power before it is authorized; in that case the historical samples are kept.
4.3OLT monitoring
The Monitor button opens the optical telemetry of each physical PON port: TX power, temperature, voltage and TX bias over time. It helps you spot a degrading SFP module before subscribers notice.
4.4Alarms
The alarm queue on the Overview can be searched and filtered by status and severity. An Open alarm becomes Acknowledged with Acknowledge, so the team knows someone is on it, and Resolved on its own when the cause goes away. For example, ONU profile mismatch opens when the inventory sees an ONU whose physical capabilities do not match its service profile, and resolves on the first inventory after the fix.
5The ONU list
Search by serial, customer or model. Filters narrows by OLT, slot, PON, operational status, registration status, binding and signal range; ONUs with no reading are excluded when you set a signal limit. Each row shows up to four indicators:
- Operational status: online, offline, dying gasp (the ONU reported losing power) or unknown.
- Binding / synchronization with the subscription (table below).
- Profile mismatch: the ONU is online, but its ports do not match the assigned service profile.
- WiFi: whether WiFi management is being enabled, is enabled or failed on that ONU.
| Status | Meaning |
|---|---|
| Unlinked | The ONU is not associated with any subscription. |
| Linked | Associated with a subscription, with no changes pending on the OLT. |
| Pending / Applying | A change is queued or running on the OLT. |
| Synced | The OLT has exactly the state the subscription asks for. |
| Drifted / Failed | The OLT does not match what is expected, or the last change failed. Check Provisioning. |
The Unauthorized ONUs button counts the ONUs the OLT sees connected but that nobody has authorized yet: these are new installations waiting to be brought up.
6Authorizing an ONU: static IP, PPPoE or profiles
Open an unauthorized ONU from the list (the Unauthorized ONUs button filters them). There are two ways to bring it up, and the difference is who configures the subscriber's connection:
| Button | ONU mode | Who sets the IP or PPPoE |
|---|---|---|
| Authorize for subscription | Routed: the ONU is the subscriber's router. | PlenoAgent, from the OLT, using the subscription's data. The technician configures nothing. |
| Authorize (with profiles) | Bridge: the ONU only passes traffic through. | The customer's router behind the ONU. |
6.1Static IP or PPPoE from the OLT (Authorize for subscription)
The technician arrives, plugs in the ONU and leaves: the IP, gateway and DNS (or the PPPoE username and password) travel from the OLT to the ONU. Before you start, check three things:
- The subscription has its connection details. In Billing, in the subscription editor, the Connection Type must be Static IP with its IP assigned, or PPPoE with PPPoE Username and PPPoE Password.
- The OLT has a service template with mask, gateway, DNS, VLAN, routed LAN ports and a service profile for this ONU's model (see section 7).
- The OLT's driver has certified static IP or PPPoE writing. If not, the form says so and does not let you continue.
In the ONU detail, press Authorize for subscription.
Search for and choose the subscription. Only those with a static IP or a PPPoE account that are not yet linked to another ONU are offered.
Review What the OLT will receive. With a static IP: the address with its mask, the gateway and the DNS servers. With PPPoE: the subscription's username (the password comes from the subscription and is not shown). In both cases: VLAN, routed LAN ports, line profile, service profile for the model and traffic tables.
Press Authorize. The job enters the queue; the subscription is linked only once the OLT confirms the service. If something fails halfway, PlenoAgent undoes what it managed to write and the error shows up on Provisioning.
The form shows the reason: the OLT has no service template, it is in observe-only mode, the ONU's model has not been read yet (run Sync), the template has no service profile for that model, the subscription has neither a static IP nor a PPPoE username, or the driver does not yet have that writing certified.
The static IP comes from the subscription, not from the OLT. Before authorizing, confirm in Billing that it is correct and that no other device uses it: PlenoAgent does not check it against the OLT's configuration, and two subscribers with the same IP end in a site visit.
6.2Authorize with profiles (bridge)
Authorize registers the ONU with the line profile and service profile you choose. If comparable ONUs are already authorized, PlenoAgent proposes the same profiles. To also create the Internet VLAN and the service-port, turn on Provision Internet after authorization and enter the VLAN and the upstream and downstream traffic profiles. Without that option, the ONU is registered but has no service. In this mode the ONU is a bridge: the static IP or PPPoE is configured on the customer's router, and the ONU is linked to the subscription separately (section 8).
6.3Operating an authorized ONU
- Change profiles reassigns the line and service profile. It can interrupt service for a few seconds: FiberControl takes a backup first, verifies the new assignment and tries to restore the previous profiles if verification fails.
- Reboot restarts the ONU from the OLT.
- Deauthorize removes it from the OLT. It is destructive and cuts service, so it asks for confirmation.
- Sync description writes the customer's expected description to the OLT when it differs from the one on the ONU.
While an operation is running, the detail and the list show Authorizing… or Changing profiles… and the buttons are hidden so two changes are never queued on the same ONU.
7Profiles and service template
On Profiles you pick an OLT and see its DBA, line, service and traffic profiles. Import profiles reads them from the OLT again; if the OLT is busy with another operation, the import runs as soon as it is free and the list refreshes on its own.
The Service template defines how a subscriber is brought up on that OLT: VLAN, mask, gateway, DNS, LAN ports in routed mode, line profile and one service profile per ONU model. The IP comes from the subscription; everything else comes from the template.
Open Service template and use Propose from latest backup: PlenoAgent reads how the ONUs already on the OLT are configured, without connecting to it, and tells you how many follow that recipe.
Review the fields and add a service profile for each ONU model you install, written exactly as the OLT reports it. An ONU whose model is not on the list cannot be authorized for a subscription.
Save. From then on, Authorize for subscription appears on that OLT's unauthorized ONUs.
In the traffic profiles view, Billing plan mappings shows each plan's desired speed against the traffic table observed on the OLT and its sync status.
8Linking to billing
The ONU ↔ subscription link is what lets billing act on the OLT: knowing which ONU belongs to which customer, suspending it for non-payment and reactivating it on payment. If you authorized the ONU with Authorize for subscription, the link was created automatically. Otherwise there are two ways:
- From the ONU detail, in the Subscription block: press the pencil, search for the subscription and press Link subscription. It is a quick link: it identifies the customer, but RouterOS keeps doing the suspension and FiberControl does not control the speed.
- From the subscription editor in Billing, in the Fiber access block, where you also choose who controls what.
In the editor:
Turn on Manage access with FiberControl.
Choose the OLT and the ONU. The search accepts serial, description, PON port or MAC and only offers free ONUs. The Internet VLAN comes from the OLT's template and is not changed per subscription.
Decide who is the authority for each responsibility (table below) and save the subscription.
| Field | Options | What it decides |
|---|---|---|
| Bandwidth control | FiberControl · RouterOS · None | Who enforces the plan's speed. FiberControl is only offered if the OLT's driver has certified speed profiles. |
| Suspension control | FiberControl · RouterOS | Who cuts service for non-payment. With FiberControl, when the subscription is suspended the OLT suspends the service without deleting the ONU, and restores it on reactivation. |
| Authentication | RouterOS PPPoE · Pass-through | Whether the subscriber authenticates by PPPoE on the router or passes through transparently. |
8.1What happens on suspension and reactivation
The subscription changes status: the billing cycle suspends it for non-payment, someone blocks it by hand, or a payment, an extension or a balance adjustment reactivates it.
If Suspension control is FiberControl, PlenoAgent queues the change for the OLT: it suspends that ONU's service without deauthorizing it (the subscriber keeps their configuration) or restores it. The router leaves the customer active, so only the OLT does the cut-off.
The movement is recorded in the Subscription History (Service filter) as Service suspended or Service reactivated, with channel FiberControl and status Pending, Applied or Failed.
If the OLT does not answer (tunnel down, OLT busy), the job retries on its own. If it ends up Failed, the reason is on Provisioning; fix the cause and use Retry. If the FiberControl module is not active, the movement is marked Failed immediately: activate the module or switch the authority to RouterOS.
If Bandwidth control is FiberControl, the router queue is created without the plan's speeds and the OLT enforces the speed with its traffic table (see Billing plan mappings in section 7). Cancelling a subscription does not deauthorize the ONU: if it will no longer be used, deauthorize it from FiberControl.
If you choose FiberControl for speed or suspension, the router can keep authenticating PPPoE, but it must not duplicate the shaping or the cut-off. With two systems cutting the same customer, there is no way to tell which one took them offline.
Billing suspensions and reactivations go straight to the FiberControl queue. They do not use AI: they work the same even if the company runs out of credits.
9WiFi management (TR-069)
Lets you view and change each subscriber's WiFi name and password from PlenoAgent. The OLT tells each ONU where your ACS (the TR-069 server) is; it is exclusive to your company and only listens inside your VPN tunnel, so nothing is exposed to the internet. The WiFi button appears on the OLT row when its driver supports it.
9.1Enabling it on the OLT
Line profiles. An ONU only accepts an ACS if its line profile has TR-069 enabled. For each line profile you use, choose its copy with TR-069 enabled (PlenoAgent proposes the one it finds). If there is none, create it on the OLT and import the profiles again. Before writing anything, PlenoAgent compares both profiles on the OLT and rejects a copy that would change the subscriber's service.
Router rule. ONUs reach the ACS through your MikroTik, which must allow TCP 7547 to the ACS. With Let Pleno add the rule, PlenoAgent writes the
pleno-acsrule below the suspension rule, so suspended subscribers stay cut off. If you prefer to do it yourself, copy the rule shown.Press Enable on this OLT. It takes about a minute.
Enable management on the ONUs: all at once with Enable on N ONUs, or one by one from their detail. Each ONU reconnects for a few seconds as it moves to its TR-069 profile. New ONUs authorized with a routed WAN get it automatically.
9.2Changing a subscriber's WiFi
In the ONU detail, the WiFi section shows each network with its name, security, whether it is on and how many devices are connected. Edit the name (1 to 32 characters) or the password (8 to 63 characters, no accented characters; leave it empty to keep it) and press Save WiFi. Connected devices are disconnected and must rejoin with the new details.
If the ONU does not answer right away, the change stays under Waiting for the ONU and is applied when it reports in again, usually in under five minutes. You can cancel it while it is pending. Read again asks the ONU for its data once more.
The ONU must be authorized and have a routed WAN (static IP or PPPoE): in bridge mode it cannot reach the ACS. If the subscription is suspended, the router also blocks traffic to the ACS and changes are applied on reactivation.
9.3When it does not work
Always start from the ONU detail: the WiFi section shows that ONU's diagnosis and, if an attempt failed, the exact error. The most common cases:
| What you see | What it means | What to do |
|---|---|---|
| The ONU has not reported to the ACS yet | Management was enabled, but the ONU has not talked to your ACS yet. | Wait up to five minutes. If it does not arrive, check the router rule (TCP 7547) and that the ONU has a routed WAN. |
| The ONU stopped reporting to the ACS | It used to report and stopped; the data shown may be stale. | Check that the ONU is online, that the subscription is not suspended and that the router rule is still in place. |
| Your ACS is not running / Pleno could not reach your ACS | Your company's TR-069 server is stopped or not responding. | Open the OLT's WiFi and use Check and restart. If the VPN tunnel is down, the ACS cannot be reached either: check NetAdmin. |
| The ONU reports no WiFi networks | It is a model without WiFi, or it has not sent its networks yet. | Use Read again. |
| The subscription is suspended | The router blocks its traffic, including to the ACS. | Nothing: the change is applied on reactivation. |
| Pleno could not add the rule on … / The router rule is added by hand | The pleno-acs rule is missing on the router the ONU goes through. | Apply it again from the OLT's WiFi, or add it by hand with the text shown there. |
| Rejected by the ONU | The ONU received the change and rejected it (for example, a password its firmware does not accept). | Fix the value and save again: saving again clears the rejection and retries. |
| A change stuck in Waiting for the ONU | The ONU has not reported in again. | Check that it is online. If you no longer want to apply it, cancel it with the X. |
If enabling fails
- On the OLT: the OLT's WiFi window shows when the last attempt failed and why. Most often: a line profile copy that does not match its original or does not have TR-069 enabled (fix the mapping), or a
PLENO_ACSserver profile that already existed on the OLT with other data and is in use. - On an ONU: the detail shows the error and a Try again button. Typical causes: the ONU is a bridge (no routed WAN), its line profile has no TR-069 copy mapped in the OLT's WiFi, or the OLT did not confirm the change; in that last case the ONU is left as it was.
To go back on an ONU, use Disable WiFi management: it returns to its previous line profile, reconnects for a few seconds and keeps the WiFi name and password it had.
10Provisioning, backups and audit
Every change to an OLT is a job in the Provisioning queue. FiberControl runs one operation at a time on each OLT, because OLTs have few management sessions and one session too many can lock out your technicians.
| Status | Meaning |
|---|---|
| Pending / Running | Waiting its turn or running on the OLT. |
| Retrying | Failed for a transient reason (OLT busy, tunnel down) and will retry on its own. |
| Succeeded | Written and verified by reading the OLT back. |
| Failed | Ran out of attempts or the OLT rejected the change. The error explains why; fix the cause and use Retry. |
Retries are safe: repeating an authorization or suspension that was already applied does not duplicate anything.
On Backups, Create backup saves an OLT's full configuration with its checksum. PlenoAgent also takes an automatic backup before preparing an OLT or changing profiles. The Audit Logs record every operation on the OLT with its actor (a user or the system), result and error code.
11Troubleshooting and support
- "Cannot reach the OLT from the private network"
- Check in NetAdmin that the VPN tunnel is connected, that the private host is correct and that the router routes to the OLT's management network.
- "The OLT rejected the saved credentials"
- Edit the OLT and enter the username and password again. Leaving the password empty keeps the previous one.
- "The OLT has no free management sessions", or it closes the connection before authenticating
- The OLT has reached its CLI session limit. Close open sessions (PuTTY, the OLT's web interface, another management system) or wait for them to expire, then try again. Some OLTs do not release stuck sessions until they time out.
- A new ONU does not show up
- Use Sync on the OLT and check the Unauthorized ONUs filter. If the OLT has monitoring turned off, no automatic inventory runs.
- "Authorize for subscription" is missing
- The OLT has no service template. Set it up on Profiles.
- The ONU shows "Profile mismatch"
- Its model has different ports from the assigned service profile. Use an adaptive profile, or the right profile for that model, with Change profiles.
- A job ended up "Failed"
- Read the error on Provisioning. If it says the OLT is busy or unreachable, retry once it recovers; if it is a configuration conflict, fix it before retrying.
- The WiFi change is not applied
- The ONU detail explains the cause. The full table of messages and what to do is in 9.3.
- Connecting a V-SOL: "The OLT refused the connection on this port"
- Telnet is not allowed in the OLT's access list, or port 23 is filtered. See 2.3.
- A suspension did not cut the customer off
- Open the Subscription History and check the movement: the channel and status tell you who was supposed to cut and whether it succeeded. If the channel is FiberControl and it Failed, the reason is on Provisioning.
- My OLT model is not on the list
- Register it as an unidentified model and write to us: we build the driver with your hardware (see 2.2).
OLT name, model and firmware (shown in the list), ONU serial, approximate time, a screenshot of the error on Provisioning or of the window where it appeared, and whether anyone else had a session open on the OLT at that moment.