Skip to content

Hardware Specifications

Vendor/Brand FS.com
Model GPON-ONU-34-20BI
ODM SourcePhotonics
ODM Product Code SPS-34-24T-HP-TDFO
Chipset Lantiq PEB98035
CPU MIPS 34Kc interAptiv
CPU Clock 400MHz
Flash 16 MB
RAM 64 MB
Bootloader U-Boot 2011.12-lantiq-gpon-1.2.24
System OpenWRT 14.07_ltq (Kernel 3.10.49)
Load addr 0x80800000
HSGMII Yes
Optics SC/APC
IP address 192.168.1.10
Web Gui
SSH ✅ user ONTUSER, password 7sp!lwUBz1
Telnet
Serial ✅ on SFP
Serial baud 115200
Serial encoding 8-N-1
Form Factor miniONT SFP

Hardware Specifications ​

Vendor/BrandFS.com
ModelGPON-ONU-34-20BI
ODMSourcePhotonics
ODM Product CodeSPS-34-24T-HP-TDFO
ChipsetLantiq PEB98035
CPUMIPS 34Kc interAptiv
CPU Clock400MHz
Flash16 MB
RAM64 MB
BootloaderU-Boot 2011.12-lantiq-gpon-1.2.24
SystemOpenWRT 14.07_ltq (Kernel 3.10.49)
Load addr0x80800000
HSGMIIYes
OpticsSC/APC
IP address192.168.1.10
Web Gui
SSH✅ user ONTUSER, password 7sp!lwUBz1
Telnet
Serial✅ on SFP
Serial baud115200
Serial encoding8-N-1
Form FactorminiONT SFP
FS.com GPON ONU
FS.com GPON ONU
FS.com GPON ONU in the box
FS.com GPON ONU in the box

Possible clones ​

  • FS.com GPON-SFP-ONT-MAC-I (SKU 133619)
  • SourcePhotonics SPS-34-24T-HP-TDFO

Warning

The GPON-SFP-ONT-MAC-I is sold as multiple SKUs; the 133619 SKU is identical to the GPON-ONU-34-20BI, but other SKUs are not the same hardware. The 133619 SKU is now no longer sold.

Firmware is interchangeable with: ​

Serial ​

The stick has a TTL 3.3v UART console (configured as 115200 8-N-1) that can be accessed from the SFP connector.

USB TTL(UART) AdapterSFP 20pins Molex connector
3.3Vpin #15 and #16
TXpin #2
RXpin #7
GNDpin #14

Note

Some USB TTL adapters label TX and RX pins the other way around: try to swap them if the connection doesn't work.

List of software versions ​

  • 6BA1896SPLQA13 (Dec 16 2016)
  • 6BA1896SPLQA41
  • 6BA1896SPLQA42 (Sep 18 2021)

List of partitions ​

Partition layouts change depending on which image is booted, in particular:

When booting image0:

mtd2 ---> image0 (linux)
mtd5 --> image1
mtd3 --> rootfs
mtd4 --> rootfs_data

When booting image0:

mtd2 ---> image0
mtd3 --> image1 (linux)
mtd4 --> rootfs
mtd5 --> rootfs_data

For more info XPONos partition layout.

When booting from image0 ​

devsizeerasesizename
mtd00004000000010000"uboot"
mtd10008000000010000"uboot_env"
mtd20074000000010000"linux"
mtd30061eedc00010000"rootfs"
mtd40037000000010000"rootfs_data"
mtd50080000000010000"image1"

When booting from image1 ​

devsizeerasesizename
mtd00004000000010000"uboot"
mtd10008000000010000"uboot_env"
mtd20074000000010000"image0"
mtd30080000000010000"linux"
mtd4006d807700010000"rootfs"
mtd50041000000010000"rootfs_data"

List of firmwares and files ​

Unlock the device ​

Note

The following commands are to be used on version 6BA1896SPLQA42, to get the commands for version 6BA1896SPLQA41 please check the following page: Carlito Firmware.

Bootloader unlock from shell ​

Warning

It is strongly recommended that you unlock the bootloader before making any major changes to the firmware.

sh
fw_setenv bootdelay 5
fw_setenv asc0 0
fw_setenv preboot "gpio set 3;gpio input 2;gpio input 105;gpio input 106;gpio input 107;gpio input 108"

Emergency bootloader unlock via TTL serial ​

Warning

This is not necessary if you have already unlocked the bootloader from the shell as specified above.

If for some reason you are in the situation where you do not have a bootable firmware on your SFP stick you can do an emergency unlock via TTL serial.

To perform the emergency unlock, the following hardware is required:

  • TTL-USB adapter,
  • SFP adapter to connect the TTL-USB cables to the SFP stick.

The electrical connections are the same as those of the Huawei MA5671A; see the Huawei root guide for accurate details on how to connect the TTL-USB to the SFP adapter.

When you are ready with everything plugged in you need to press the button below. A window will open to execute the emergency unlock.

GPON ONU status ​

Getting the operational status of the ONU ​

shell
onu ploamsg

Querying a particular OMCI ME ​

sh
omci_pipe.sh meg MIB_IDX ME_IN

Where MIB_IDX is the MIB ID and the ME_IN is the ME instance number

Getting/Setting Speed LAN Mode ​

To get the LAN Mode:

sh
onu lanpsg 0

The link_status variable tells the current speed

Value (for sgmii_mode and link_status)Speed
31 Gbps / SGMII with auto-neg on
41 Gbps / SGMII with auto-neg off
52.5 Gbps / HSGMII with auto-neg on

To change the default lan mode value you can use fw_setenv sgmii_mode. The firmware already has the value set to 5 by default and there should not be any need to change it.

GPON/OMCI settings ​

Setting ONU GPON Serial Number ​

sh
set_serial_number ABCD12345678

Or:

sh
sfp_i2c -i8 -s "ABCD12345678"

Getting ONU GPON Serial Number ​

sh
fw_printenv | grep nSerial

Or:

sh
sfp_i2c -g

Setting ONU GPON PLOAM password ​

sh
sfp_i2c -i11 -s "1234567890"

Setting ONU GPON LOID and LOID password ​

sh
sfp_i2c -i9 -s "1234567890"
sfp_i2c -i10 -s "password01"

Setting OMCI equipment ID (ME 257) ​

sh
sfp_i2c -i6 -s "YOUR_EQUIPMENT_ID"

Setting OMCI Vendor ID (ME 256) ​

sh
sfp_i2c -i7 -s "YOUR_VENDOR_ID"

Setting OMCI hardware version (ME 256) ​

sh
sed 's/256 0 HWTC 0000000000000/256 0 HWTC YOUR_ONU_VERSION/' /rom/etc/mibs/data_1g_8q.ini > /etc/mibs/data_1g_8q.ini

Restoring the default ONU hardware version (ME 256) ​

sh
cat /rom/etc/mibs/data_1g_8q.ini > /etc/mibs/data_1g_8q.ini

Setting OMCI software version (ME 7) ​

Info

The patch below is only compatible with the firmware version 6BA1896SPLQA42

The image version normally can't be changed because it is hard-coded into the /opt/lantiq/bin/omcid binary, so the binary has to be modified with the following hex patch which removes the hardcoded version.

< 000084c0: 9a43 931f f760 d840 9b64 f760 d864 1a00  .C...`.@.d.`.d..
< 000084d0: 1acf 6500 1a20 2268 940a 2205 b468 1a00  ..e.. "h.."..h..
---
> 000084c0: 9a43 931f f760 d840 9b64 f760 d864 6500  .C...`.@.d.`.de.
> 000084d0: 6500 6500 1a20 2268 940a 2205 b468 1a00  e.e.. "h.."..h..

Info

Proceed only if your md5sum /opt/lantiq/bin/omcid has the correct checksum 7e97163e24c9cb39439589c65b438168

This is the patch, encoded in base64

QlNESUZGNDA1AAAAAAAAAD4AAAAAAAAA2C8JAAAAAABCWmg5MUFZJlNZYqnvBwAACFBSQWAAAMAA
AAgAQCAAMQwIIwjImgDOdMvi7kinChIMVT3g4EJaaDkxQVkmU1lrJSbUAACFTAjAACAAAAiCAAAI
IABQYAFKQ01INxUgd6Soj2JURm8pUR8XckU4UJBrJSbUQlpoORdyRThQkAAAAAA=

Save it on your computer (not on the stick) as omcid_patch.base64, then run:

sh
base64 -d omcid_patch.base64 > omcid.bspatch
bspatch <your_original_omcid> omcid omcid.bspatch

Info

If you don't have bspatch installed, most distributions include it in the bsdiff package

After patching the resulting patched omcid should have an md5 checksum of 525139425009c4138e92766645dad7d0. If that is also correct, continue by making a backup copy of your original omcid on the stick.

sh
cd /opt/lantiq/bin
cp omcid omcid.original

Now, SCP has to be used to copy the modified omcid binary in /opt/lantiq/bin/omcid. Before restarting the stick and applying changes, make sure omcid has its execution bit set, then reboot the stick and change the image version with the following command:

sh
chmod ugo+x /opt/lantiq/bin/omcid

Is also a good time to set the image0/image1_version: crashes have been reported if they are not set correctly before reboot.

sh
fw_setenv image0_version YOUR_IMAGE0_VERSION
fw_setenv image1_version YOUR_IMAGE1_VERSION

Now the stick can be rebooted.

Info

Be aware that sometimes omcid can rewrite the two variables when run in its non-patched state. After reboot, double check the set values are still correct.

Advanced settings ​

Setting data_1g_8q_us1280_ds512.ini OMCI MIB file for 2500 Mbps profiles ​

Info

The patch provided below is only compatible with the firmware version 6BA1896SPLQA42

Info

If you need to set the ONU version remember that you will have to do it using the MIB file /etc/mibs/data_1g_8q_us1280_ds512.ini instead of /etc/mibs/data_1g_8q.ini

The MIB file data_1g_8q_us1280_ds512.ini is very useful to avoid performance problems in situations where 2500 Mbps speed profiles are used. To enable it, run this command:

sh
fw_setenv mib_file data_1g_8q_us1280_ds512.ini

Setting custom OMCI MIB file ​

Info

If you need to set the ONU version, remember that you will have to do it using your custom MIB file instead of /etc/mibs/data_1g_8q.ini

Copy the MIB file to /etc/mibs, then run this command:

sh
fw_setenv mib_file YOUR_MIB_FILENAME

Setting management MAC ​

sh
uci set network.lct.macaddr=00:06:B5:07:D6:04
uci set network.host.macaddr=00:06:B5:07:D8:04
uci commit network.lct.macaddr=00:06:B5:07:D6:04
uci commit network.host.macaddr=00:06:B5:07:D8:04

Setting management IP ​

sh
fw_setenv ipaddr 192.168.20.60
fw_setenv gatewayip 192.168.20.1

Rebooting the ONU ​

sh
reboot

Disable RX_LOS status ​

Info

The patch provided below is only compatible with the firmware version 6BA1896SPLQA42

Some switches/routers (e.g. Mikrotik) do not allow access to the magament interface without the fiber being connected because the SFP reports RX_LOS status It is possible to fix this by modifying the mod_optic.ko driver to spoof non RX_LOS status by setting PIN 8 (RX_LOS) to be always low.

This is the change to be made, in hex format:

< 00013740: 2404 0003 2405 0001 0c00 0000 ac43 0980  $...$........C..
---
> 00013740: 2404 0003 2405 0000 0c00 0000 ac43 0980  $...$........C..

Info

Proceed only if your md5sum /lib/modules/3.10.49/mod_optic.ko has the correct checksum 7c718c3410c4120fe98fa7a9a5c6c407

This is the patch, encoded in base64:

QlNESUZGNDA2AAAAAAAAADYAAAAAAAAAXEEFAAAAAABCWmg5MUFZJlNZ5TTrjgAAB+ZARjAEACAA
AARAACAAMQZMQRppiFkgKGTeXi7kinChIcpp1xxCWmg5MUFZJlNZcaVLvQABOOCAwAAAAQAIAAig
ACClRgZoMhUf9JKbgIk3hdyRThQkHGlS70BCWmg5F3JFOFCQAAAAAA==

Save it on your computer (not on the stick) as mod_optic.base64, then run:

sh
base64 -d mod_optic.base64 > mod_optic.bspatch
bspatch <your_original_mod_optic.ko> mod_optic.ko mod_optic.bspatch

Info

If you don't have bspatch installed, most distributions include it in the bsdiff package

After patching the resulting mod_optic.ko should have an md5 checksum of e14a5a70b023873853afe920870f076e. If that is also correct, continue by making a backup copy of your original mod_optic.ko on the stick.

sh
cd /lib/modules/3.10.49/
cp mod_optic.ko mod_optic.ko.original

Now use SCP to copy the modified mod_optic.ko kernel module in /lib/modules/3.10.49/mod_optic.ko.

TX Fault / Serial ​

The stick will remain in a perpetual "TX Fault" state as the same SFP pin is used for both serial and TX Fault signaling. If this causes you issues (normally it shouldn't), you can issue the commands below to disable it. Note that this will disable both the TX Fault signal and Serial on the stick after boot.

sh
fw_setenv asc0 1
fw_setenv preboot "gpio set 3;gpio input 100;gpio input 105;gpio input 106;gpio input 107;gpio input 108"

In case you need to re-enable it, issue the following commands from the bootloader (FALCON)

sh
FALCON => setenv asc0 0
FALCON => saveenv

SFP EEPROM settings ​

Reading all EEPROM ​

sh
sfp_i2c -r

Getting Firmware version ​

sh
strings /opt/lantiq/bin/omcid | grep ^software_Version | awk -F[=,] '{print $2}'

Getting Firmware build time ​

sh
strings /opt/lantiq/bin/omcid | grep compiled

EEPROM (I2C slave simulated EEPROM) ​

The FS GPON-ONU-34-20BI stick does not have a physical EEPROM, the Falcon SOC emulates an EEPROM by exposing it on the I2C interface as required by the SFF-8472 specification.

On the I2C interface, two memories of 256 bytes each will be available at the addresses 1010000X (A0h) and 1010001X (A2h), however the actual available memory from the emulated EEPROM will be 640 bytes each, but only the first 256 bytes will be exposed in the I2C interface.

The FS stick stores the content of the emulated EEPROM in U-Boot env variables to restore it after a reboot:

  • EEPROM0 (A0h) stored in U-Boot env variable sfp_a0_low_128
  • EEPROM1 (A2h) stored in U-Boot env variable sfp_a2_info

EEPROM0 layout ​

addresssizenamedefault valuedescription
BASE ID FIELDS (SFF-8472)
01Identifier0x03 (SFP)Type of transceiver
11Ext identifier0x04 (MOD_DEF 4)Additional information about the transceiver
21Connector0x01 (SC)Type of media connector
3-108Transceiver0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00Code for optical compatibility
111Encoding0x03 (NRZ)High speed serial encoding algorithm
121Signaling Rate, Nominal0x0C (1.244Gbps)Nominal signaling rate
131Rate Identifier0x00 (Not used)Type of rate select functionality
141Length (SMF,km)0x14 (20 km)Link length supported for single-mode fiber, units of km
151Length (SMF)0xC8 (200 x 100m)Link length supported for single-mode fiber, units of 100 m
161Length (50 um, OM2)0x00 (No support)Link length supported for 50 um OM2 fiber, units of 10 m
171Length (62.5 um, OM1)0x00 (No support)Link length supported for 62.5 um OM1 fiber, units of 10 m
181Length copper cable0x00 (No support)Link length supported for copper or direct attach cable, units of m
191Length (50 um, OM3)0x00 (No support)Link length supported for 50 um OM3 fiber, units of 10 m
20-3516Vendor name0x46 0x53 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 (FS)SFP vendor name (ASCII)
361Transceiver0x00 (No support)Code for optical compatibility
37-393Vendor OUI0x00 0x00 0x00 (No specified)SFP vendor IEEE company ID
40-5516Vendor PN0x47 0x50 0x4F 0x4E 0x2D 0x4F 0x4E 0x55 0x2D 0x33 0x34 0x2D 0x32 0x30 0x42 0x49 (GPON-ONU-34-20BI)Part number provided by SFP vendor (ASCII)
56-594Vendor rev0x30 0x31 0x20 0x20 (01)Revision level for part number provided by vendor (ASCII)
60-612Wavelength0x05 0x1E (1310nm TX)Laser wavelength
621Fibre Channel Speed 20x00 (No support)Transceiver's Fibre Channel speed capabilities
631CC_BASECheck code for Base ID Fields (addresses 0 to 62)
EXTENDED ID FIELDS (SFF-8472)
64-652Options0x00 0x1A (TX DISABLE, TX FAULT, RX LOS)Indicates which optional transceiver signals are implemented
661Signaling Rate, max0x00 (No specified)Upper signaling rate margin, units of %
671Signaling Rate, min0x00 (No specified)Lower signaling rate margin, units of %
68-8316Vendor SNUnique in each SFPSerial number provided by vendor (ASCII)
84-918Date codeUnique in each SFPVendor's manufacturing date code
921Diagnostic Monitoring Type0x68 (Digital diagnostic, Internally calibrated, Received average power type)Indicates which type of diagnostic monitoring is implemented
931Enhanced Options0xF0 (Alarm/warning flags, soft TX_DISABLE control, soft TX_FAULT monitoring, soft RX_LOS monitoring)Indicates which optional enhanced features are implemented
941SFF-8472 Compliance0x05 (Rev 11.0 of SFF-8472)Indicates which revision of SFF-8472 the transceiver complies with
951CC_EXTCheck code for the Extended ID Fields (addresses 64 to 94)
VENDOR SPECIFIC FIELDS
96-12732Vendor data0x20 0x20 0x20... (Not used)Vendor specifc data (ASCII)
128-255128Reserved0x00 0x00 0x00...Reserved
EXTRA EEPROM FIELDSNot exposed to I2C interface
256-639384Reserved0x00 0x00 0x00...Reserved

EEPROM1 layout ​

addresssizenamedefault valuedescription
DIAGNOSTIC AND CONTROL FIELDS
0-12Temp High Alarm0x5F 0x00 (95℃)Value expressed in two's complement
2-32Temp Low Alarm0xCE 0x00 (-50℃)Value expressed in two's complement
4-52Temp High Warning0x5A 0x00 (90℃)Value expressed in two's complement
6-72Temp Low Warning0xD3 0x00 (-45℃)Value expressed in two's complement
8-92Voltage High Alarm0x8C 0xA0 (3.6V)Value expressed in volt subunits[1]
10-112Voltage Low Alarm0x75 0x30 (3.0V)Value expressed in volt subunits[1:1]
12-132Voltage High Warning0x88 0xB8 (3.5V)Value expressed in volt subunits[1:2]
14-152Voltage Low Warning0x79 0x18 (3.1V)Value expressed in milliampere subunits[1:3]
16-172Bias High Alarm0xAF 0xC8 (90mA)Value expressed in milliampere subunits[1:4]
18-192Bias Low Alarm0x00 0x00 (0mA)Value expressed in milliampere subunits[1:5]
20-212Bias High Warning0x88 0xB8 (70mA)Value expressed in milliampere subunits[1:6]
22-232Bias Low Warning0x00 0x00 (0mA)Value expressed in milliampere subunits[1:7]
24-252TX Power High Alarm0xF6 0x77 (8dBm)Value expressed in watts subunits[1:8]
26-272TX Power Low Alarm0x15 0xF7 (-2.5dBm)Value expressed in watts subunits[1:9]
28-292TX Power High Warning0xC3 0xC6 (7dBm)Value expressed in watts subunits[1:10]
30-312TX Power Low Warning0x1B 0xA7 (-1.5dBm)Value expressed in watts subunits[1:11]
32-332RX Power High Alarm0x0C 0x5A (-5dBm)Value expressed in watts subunits[1:12]
34-352RX Power Low Alarm0x00 0x08 (-31dBm)Value expressed in watts subunits[1:13]
36-372RX Power High Warning0x09 0xCF (-6dBm)Value expressed in watts subunits[1:14]
38-392RX Power Low Warning0x00 0x0A (-30dBm)Value expressed in watts subunits[1:15]
40-456MAC addressUnique in each SFPContains the mac address of the SFP, it could also be empty
46-5510Reserved0x00 0x00 0x00...Reserved
56-594RX_PWR(4) Calibration0x00 0x00 0x00 0x004th order RSSI calibration coefficient
60-634RX_PWR(3) Calibration0x00 0x00 0x00 0x003rd order RSSI calibration coefficient
64-674RX_PWR(2) Calibration0x00 0x00 0x00 0x002nd order RSSI calibration coefficient
68-714RX_PWR(1) Calibration0x3F 0x80 0x00 0x001st order RSSI calibration coefficient
72-754RX_PWR(0) Calibration0x00 0x00 0x00 0x000th order RSSI calibration coefficient
76-772TX_I(Slope) Calibration0x01 0x00Slope for Bias calibration
78-792TX_I(Offset) Calibration0x00 0x00Offset for Bias calibration
80-812TX_PWR(Slope) Calibration0x01 0x00Slope for TX Power calibration
82-832TX_PWR(Offset) Calibration0x00 0x00Offset for TX Power calibration
84-852T(Slope) Calibration0x01 0x00Slope for Temperature calibration
86-872T(Offset) Calibration0x00 0x00Offset for Temperature calibration, in units of 256ths °C
88-892V(Slope) Calibration0x01 0x00Slope for VCC calibration
90-912V(Offset) Calibration0x00 0x00Offset for VCC calibration
92-943Reserved0x00 0x00 0x00Reserved
951CC_DMICheck code for Base Diagnostic Fields (addresses 0 to 94)
961Temperature MSBInternally measured module temperature
971Temperature LSB
981Vcc MSBInternally measured supply voltage in transceiver
991Vcc LSB
1001TX Bias MSBInternally measured TX Bias Current
1011TX Bias LSB
1021TX Power MSBMeasured TX output power
1031TX Power LSB
1041RX Power MSBMeasured RX input power
1051RX Power LSB
106-1094Optional Diagnostics0xFF 0xFF 0xFF 0xFF (No support)Monitor Data for Optional Laser temperature and TEC current
1101Status/Control0x82 (Soft TX disable, disable laser, digital TX fault, digital RX LOS, power&data ready)Optional Status and Control Bits
1111Reserved0x00Reserved
112-1132Alarm FlagsSupportedDiagnostic Alarm Flag Status Bits
1141Tx Input EQ control0xFF (No support)Tx Input equalization level control
1151Rx Out Emphasis control0xFF (No support)Rx Output emphasis level control
116-1172Warning FlagsSupportedDiagnostic Warning Flag Status Bits
118-1192Ext Status/Control0x00 0x00 (No support)Extended module control and status bytes
GENERAL USE FIELDS
120-1267Vendor Specific0x70 0x00 0x00 0x00 0x00 0x00 0x00Vendor specific memory addresses
1271Table Select0x00Optional Page Select
USER WRITABLE EEPROM
128-19063Reserved0xFF 0xFF 0xFF...Reserved
191-21424GPON LOID or PLOAMDepends on the configuration of the SFPGPON Logical ONU ID or PLOAM, depends on GPON LOID/PLOAM switch
215-23117GPON LPWDDepends on the configuration of the SFPGPON Logical Password
2321GPON LOID/PLOAM switchDepends on the configuration of the SFP0x01 to enable LOID, 0x02 to enable PLOAM
233-2408GPON SNUnique in each SFPGPON Serial Number (ME 256)
241-2477Reserved0xFF 0xFF 0xFF...Reserved
248-2558Vendor Control0xFF 0xFF 0xFF... (Not used)Vendor specific control functions
EXTRA EEPROM FIELDSNot exposed to I2C interface
256-511256Unknown vendor specificProbably not used in current SFPs
512-53120GPON Equipment IDGPON Equipment ID (ME 257), may not work in some firmwares
532-5354GPON Vendor IDGPON Vendor ID (ME 256 and more), may not work in some firmware
536-639104ReservedReserved

Info

For more information, see the SFF-8472 Rev 11.0 specification.

Miscellaneous Links ​



  1. The subunit are 10000 times smaller than the specified unit ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

Copyright © 2022-2026. The documentation hereby found is distributed under the terms of the MIT License. Any external reference, link or software retains its original license and is not under the control of this website. Privacy Policy.