Configuring Authentication Parameters
Context
An OLT needs to authenticate validity and identity of each ONU to prevent access from unauthorized ONUs. A GPON system supports the following ONU authentication modes:
Authentication Mode |
Description |
Advantage |
Disadvantage |
Usage Scenario |
---|---|---|---|---|
SN authentication |
The OLT authenticates an ONU by checking the SN of the ONU. The SN of each ONU is a globally unique string of 13 characters. The first four characters represent the manufacturer. The SN of a Huawei ONU starts with hwhw. |
This mode does not require any manual configuration and has a high reliability. |
When an ONU fails and needs to be replaced by a new one, the SN of the new ONU must be added to the OLT, so this mode is not flexible. |
It is applicable to all scenarios because the device supports this mode by default. |
Password authentication |
The OLT authenticates an ONU by checking whether the password sent by the ONU is the same as that configured locally. |
It is simple to configure and you do not need to configure new passwords when users change their physical locations. This mode implements flexible access. |
When two ONUs use the same password, the OLT allows the one that passes the authentication earlier to go online. Therefore, if an unauthorized ONU has gone online by using the password of an authorized ONU, the authorized ONU cannot go online. |
It is applicable to networks requiring flexible access. |
The device supports the SN authentication mode by default.
A GPON system supports the following ONU authentication modes: only by serial number (SN), only by password, or by SN and password. When a GPON system authenticates the ONU by checking the password or checking SN and password, you must run the gpon-password command to configure a password for the GPON.
All the authentication parameters are pre-configured on the OLT and cannot be modified on the ONU. If the authentication parameters are not pre-configured, the ONU cannot be authenticated.