The monitor
The monitor is the router’s web page for the NOC. It runs on the router itself, over HTTPS, on port 8881. It has four tabs:
- Console: every command the router sends to its OLTs, and the replies, live.
- OLT: the chassis, its ports, and every ONT with its customer.
- Alarms: the alarm register by area, with health readings.
- Settings: interfaces, VLANs, IP addresses and protection.
There is also the wall, a page for a screen in the support room.
Open it
Section titled “Open it”On the router:
dtvsol monitor DTVSOL - OLT monitor service: active https://XXX.XXX.XXX.10:8881/ users: 2 reachable only from the API allow-list (dtvsol protect list); self-signed certificateOpen that address in a browser. The certificate is generated by the router on its first start and is self-signed: accept it once.
Who can reach it
Section titled “Who can reach it”The monitor uses the same allow-list as the API. Add the networks your operators work from:
dtvsol protect listdtvsol protect add XXX.XXX.XXX.0/24 "NOC"Everything else is dropped before it reaches the login page.
Users and roles
Section titled “Users and roles”Every person has their own user. There are two roles:
- admin: sees everything and may change settings on the Settings tab.
- viewer: sees everything, changes nothing. This is the default.
dtvsol monitor user add alice admin # the password is asked twicedtvsol monitor user add bob # a viewerdtvsol monitor user role bob admindtvsol monitor user role alice viewerdtvsol monitor user passwd bobdtvsol monitor user del bobdtvsol monitor usersThe router checks the role on every change, not just in the page. A viewer who tries sees: only an admin may change settings.
The header shows who is signed in and the role, with a sign out link.
Sessions and logins
Section titled “Sessions and logins”- A login lasts 24 hours. Sessions survive a restart of the monitor.
- Passwords are stored only as salted hashes.
- After 5 failed logins from one address in 10 minutes, that address has to wait.
- Failed logins are written to
/opt/dtvsol/log/auth.log, where fail2ban bans repeat offenders.
Every change is logged
Section titled “Every change is logged”Every change made from the Settings tab is logged with the user’s name in
/opt/dtvsol/log/api.log, and in /opt/dtvsol/log/oltmon-settings.log with the time and the
browser’s address.
Light and dark
Section titled “Light and dark”The ☀ button in the header switches between light and dark.