Skip to content

The monitor

The monitor is the router’s web page for the NOC. It runs on the router itself, over HTTPS, on port 8881. It has four tabs:

  • Console: every command the router sends to its OLTs, and the replies, live.
  • OLT: the chassis, its ports, and every ONT with its customer.
  • Alarms: the alarm register by area, with health readings.
  • Settings: interfaces, VLANs, IP addresses and protection.

There is also the wall, a page for a screen in the support room.

On the router:

Terminal window
dtvsol monitor
DTVSOL - OLT monitor service: active
https://XXX.XXX.XXX.10:8881/
users: 2
reachable only from the API allow-list (dtvsol protect list); self-signed certificate

Open that address in a browser. The certificate is generated by the router on its first start and is self-signed: accept it once.

The monitor uses the same allow-list as the API. Add the networks your operators work from:

Terminal window
dtvsol protect list
dtvsol protect add XXX.XXX.XXX.0/24 "NOC"

Everything else is dropped before it reaches the login page.

Every person has their own user. There are two roles:

  • admin: sees everything and may change settings on the Settings tab.
  • viewer: sees everything, changes nothing. This is the default.
Terminal window
dtvsol monitor user add alice admin # the password is asked twice
dtvsol monitor user add bob # a viewer
dtvsol monitor user role bob admin
dtvsol monitor user role alice viewer
dtvsol monitor user passwd bob
dtvsol monitor user del bob
dtvsol monitor users

The router checks the role on every change, not just in the page. A viewer who tries sees: only an admin may change settings.

The header shows who is signed in and the role, with a sign out link.

  • A login lasts 24 hours. Sessions survive a restart of the monitor.
  • Passwords are stored only as salted hashes.
  • After 5 failed logins from one address in 10 minutes, that address has to wait.
  • Failed logins are written to /opt/dtvsol/log/auth.log, where fail2ban bans repeat offenders.

Every change made from the Settings tab is logged with the user’s name in /opt/dtvsol/log/api.log, and in /opt/dtvsol/log/oltmon-settings.log with the time and the browser’s address.

The ☀ button in the header switches between light and dark.