Install
The installer is install.sh. It is idempotent: you can run it again after an update to
refresh the units, timers and packages.
1. Put the software in /opt/dtvsol
Section titled “1. Put the software in /opt/dtvsol”From a release tarball:
sudo mkdir -p /opt/dtvsolsudo tar xzf dtvsol-router-<rev>.tar.gz -C /opt/dtvsolOr from the repository you were given access to:
sudo git clone <repository-url> /opt/dtvsolCopy the licensed binaries you received into /opt/dtvsol/bin/: dtvsold and the OLT driver
dtvsol-olt-<vendor>.
2. Run the installer
Section titled “2. Run the installer”cd /opt/dtvsolsudo ./install.shIf the server has no IPv4 address with a default route yet, the installer lists the ports (name, MAC, link) and asks for the interface, the address, the gateway and the DNS servers. You can also give them on the command line:
sudo ./install.sh --iface eno1 --ip XXX.XXX.XXX.10/24 --gw XXX.XXX.XXX.1 --dns XXX.XXX.XXX.53,XXX.XXX.XXX.54The installer then:
- Installs the Ubuntu packages.
- Places the files in
/opt/dtvsoland putsdtvsolon thePATH. - Turns on IPv4 and IPv6 forwarding and loads the
8021qandifbkernel modules. - Writes a base DHCP configuration (only if none exists).
- Installs the systemd units, the timers, the cron jobs, the fail2ban filter and jail, and Tab
completion for
dtvsol. - Generates a random API key and prints it once. Keep it: your billing needs it.
- Creates the system user
dtvsol(a sudo login for operators). - Moves the configuration into the database
data/dtvsol.db, stores the router’s own network configuration, and starts the services. - Sets up chrony so the router can serve time to its OLTs.
At the end it prints the next steps.
3. Secure the box
Section titled “3. Secure the box”Set your own password for the dtvsol user:
sudo passwd dtvsolAdd your management networks to fail2ban’s ignoreip, so an operator who mistypes a password
is not locked out:
sudo nano /etc/fail2ban/jail.d/dtvsol.confsudo systemctl restart fail2banAllow your NOC to reach the API (port 8880) and the monitor (port 8881). Only localhost is allowed until you add a network:
dtvsol protect add XXX.XXX.XXX.0/24 "NOC"dtvsol protect list4. Enrol the licence
Section titled “4. Enrol the licence”Use the router id and the token DTVSOL gave you. Give the token as - to type it instead of
leaving it in the shell history:
dtvsol licence enrol <router-id> -dtvsol licence statusThe licence is refreshed by a daily timer. See Troubleshooting if it reports a problem.
5. Check the network configuration
Section titled “5. Check the network configuration”The router keeps its own network (ports, bonds, their addresses, the default route and DNS) in the database and writes the netplan file from it. The installer stored what it found. Check it:
dtvsol netcfg showdtvsol netcfg diffIf the server already had a network configured by hand, read it in once:
dtvsol netcfg import # shows what would be stored, key by keydtvsol netcfg import --saveSee Network changes before you change anything here.
6. Create the first monitor user
Section titled “6. Create the first monitor user”The first user should be an admin. You are asked for the password twice:
dtvsol monitor user add alice admindtvsol monitordtvsol monitor prints the address to open, for example https://XXX.XXX.XXX.10:8881/. The
certificate is self-signed: accept it once in the browser. See
the monitor.
7. Optional settings
Section titled “7. Optional settings”If your billing provisions MikroTik routers, set the MK-api login. The installer stores a placeholder password that you must change:
dtvsol mkapi set user billing password '<a-strong-password>'If you monitor with an NMS over SNMP:
dtvsol snmp set community '<secret>' location "POP 1" contact "noc@example.net"8. Check the result
Section titled “8. Check the result”dtvsol versiondtvsol doctor --no-oltdtvsol doctor should report no critical findings. Continue with
First steps.
Updating
Section titled “Updating”Replace the files in /opt/dtvsol with the new release (or git pull), then run the installer
again:
cd /opt/dtvsolsudo ./install.shYour configuration in data/ and your logs in log/ are kept.