Troubleshooting
Start with the doctor
Section titled “Start with the doctor”dtvsol doctor # the router, and the registered OLT against the router's recordsdtvsol doctor --no-olt # the router only (fast)The doctor only reads. It prints the findings grouped by area, worst first. Each finding has a severity (critical, warning, info), the problem, details and a fix.
| Area | What it checks |
|---|---|
dhcp |
the DHCP configuration and service, subnets for every served VLAN |
delegation |
IPv6 prefix delegation: pools and subnets that delegate nothing |
ipv6-gateway |
VLANs served by DHCPv6 without router advertisements (clients would get no IPv6 gateway) |
addressing |
network or broadcast addresses used as the router’s, two interfaces in one subnet |
vlans |
VLAN tags claimed twice, VLANs missing in the kernel |
routes, nat |
static routes and NAT pools against the kernel |
persistence |
addresses and VLANs recorded but not live, or live but not recorded (lost at the next reboot) |
boot |
boot-time problems that delay the VLANs, routes and DHCP |
clients |
clients pinned to interfaces or addresses that do not exist |
antispoof |
anti-spoofing rules against the configuration |
store, data |
the configuration database, and data files that do not parse |
backup |
the daily backup and its off-site copy |
ntp |
time for the OLTs |
olt |
the OLT registry, and the OLT against the router: S-VLAN, uplinks, Option 82, every service’s ONT and service-port |
If /opt/dtvsol/etc/config.php has an error, the API cannot start, and dtvsol doctor says so
first.
What is wrong right now
Section titled “What is wrong right now”dtvsol alarms # the alarm register, checked every minutedtvsol alerts # current conditionsdtvsol version # software version and the state of the main servicesdtvsol daemon status # API and DHCP statusAll in /opt/dtvsol/log/:
| File | What it holds |
|---|---|
api.log |
what the router did and changed, with who did it (the user’s name for changes from the monitor), and the backup’s lines |
auth.log |
failed logins: bad API keys and failed monitor logins (AUTH-FAIL <ip>), read by fail2ban |
cgnat-mappings.log |
every CGNAT block assignment and release |
olt-commands.jsonl |
every command sent to an OLT, with the reply (the monitor’s Console) |
oltmon-settings.log |
every settings change made in the monitor: time, address, user |
dtvsol daemon log # the last lines of api.logdtvsol daemon logf # follow itServices
Section titled “Services”| Unit | Role |
|---|---|
dtvsol-api |
the daemon dtvsold: the API on :8880 |
dtvsol-oltmon |
the web monitor on :8881 |
dtvsol-mkapi |
MK-api on :8728 |
dtvsol-vlans |
at boot: VLANs, routes, service interfaces, shaping, CGNAT, port forwards |
isc-dhcp-server, isc-dhcp-server6, radvd |
DHCP and IPv6 router advertisements |
fail2ban, snmpd, chrony |
bans, the SNMP agent, time |
dtvsol-olt-collect.timer |
the OLT collector, every 5 minutes |
dtvsol-olt-sync.timer |
plans onto the OLTs, every 15 minutes |
dtvsol-olt-maint.timer |
OLT saves and configuration backups |
dtvsol-backup.timer |
the daily router backup |
dtvsol-licence.timer |
the daily licence refresh |
dtvsol-antispoof.path, dtvsol-pd-routes.path |
follow the DHCP lease files |
systemctl status dtvsol-apijournalctl -u dtvsol-api -n 100journalctl -u dtvsol-oltmon -fjournalctl -u dtvsol-olt-collect -n 50systemctl list-timers 'dtvsol-*'Common problems
Section titled “Common problems”The monitor or the API does not answer from my PC. Your address is not on the allow-list, or fail2ban banned it. On the router:
dtvsol protect listdtvsol protect add XXX.XXX.XXX.0/24 "NOC"dtvsol fail2bandtvsol fail2ban unban XXX.XXX.XXX.23The monitor says “wait” at login.
Five failed logins from one address in 10 minutes. Wait, or use the right password. An admin can
reset it: dtvsol monitor user passwd <name>.
A network change came back by itself.
It was not confirmed within 120 seconds. Apply it again and confirm:
dtvsol netcfg apply, then dtvsol netcfg confirm.
POST /services answers 404.
The serial is not in the OLT’s autofind table: the ONU is not connected, not powered, not seen
yet, or already registered. Check with dtvsol service unregistered.
POST /services answers 502.
The OLT refused or could not be reached. The error carries the OLT’s own words. Nothing was
created. Look at the command in the monitor’s Console.
“vlandtvsol vlan add, 802.1Q,
id N, no address).
A subscriber gets no address.
Check dtvsol option82 (does the OLT insert Option 82?), dtvsol service get <id> (live state,
lease), and dtvsol antispoof log 1h.
Licence alarms.
dtvsol licence status, then sudo dtvsol licence refresh. The router must reach the DTVSOL
middleware over HTTPS. Without a valid licence the OLT drivers stop.
The doctor says something will not survive a reboot.
Follow its fix. For an address only in the kernel, add it properly with dtvsol ip add, or
store the running network with dtvsol netcfg import --save.