Skip to content

Hardware Specifications

Vendor/Brand Zyxel
Model PMG3000-D20B
ODM T&W
ODM Product Code TW2362H-CDEL
Chipset Lantiq PEB98035
Flash 8 MB
RAM 64 MB
CPU MIPS 34Kc interAptiv
CPU Clock 400MHz
System eCoS
HSGMII Yes
Optics SC/APC
IP address 10.10.1.1
Web Gui ✅ username admin or guest, password 1234 or guest
SSH ✅ username admin, password admin. Not available in firmware V1.00(ABVJ.1)b1e
Telnet
Serial ✅
Serial baud 115200
Serial encoding 8-N-1
Form Factor miniONT SFP

Hardware Specifications ​

Vendor/BrandZyxel
ModelPMG3000-D20B
ODMT&W
ODM Product CodeTW2362H-CDEL
ChipsetLantiq PEB98035
Flash8 MB
RAM64 MB
CPUMIPS 34Kc interAptiv
CPU Clock400MHz
SystemeCoS
HSGMIIYes
OpticsSC/APC
IP address10.10.1.1
Web Gui✅ username admin or guest, password 1234 or guest
SSH✅ username admin, password admin. Not available in firmware V1.00(ABVJ.1)b1e
Telnet
Serial✅
Serial baud115200
Serial encoding8-N-1
Form FactorminiONT SFP
PMG3000-D20B
PMG3000-D20B
PMG3000-D20B Teardown
PMG3000-D20B Teardown
PMG3000-D20B Teardown
PMG3000-D20B Teardown
PMG3000-D20B Module comparison
PMG3000-D20B Module comparison

Once you access the stick via ssh you will be presented with a second tier login. The credentials to access the zyxel shell are: username: twmanu with password: twmanu or username: admin with password: 1234. From the Zyxel shell you can move to a standard Linux shell using the linuxshell command

Serial ​

The stick has a TTL 3.3v UART console (configured as 115200 8-N-1) that can be accessed from the top surface. It's near the SFP header. TX, RX and ground pads need to be connected to a USB2TTL adapter supporting 3V3 logic. Ground and power can be connected via the regular SFP pins.

PMG3000-D20B Serial Pinout
PMG3000-D20B Serial Pinout

Note

Some USB TTL adapters label TX and RX pins the other way around: try to swap them if the connection doesn't work.

Firmware is interchangeable with: ​

List of software versions ​

  • V1.00(ABVJ.0) (OpenWrt 12.09, with ssh)
    • V1.00(ABVJ.0)b3i (2020)
    • V1.00(ABVJ.0)b3s (2020-12-23)
    • V1.00(ABVJ.0)b3v (2021-05-08)
  • V1.00(ABVJ.1) (OpenWrt 12.09, without ssh)
    • V1.00(ABVJ.1)b1e (2023-07-26)
    • V1.00(ABVJ.1)b1i (2026-02-06)
    • V1.00(ABVJ.1)b1j (2026-05-27)
  • V2.50(ABVJ.1) (OpenWrt 14.07, with ssh)
    • V2.50(ABVJ.1)b1b (2022-08-10)
    • V2.50(ABVJ.1)b1d (2023-04-21)
    • V2.50(ABVJ.1)b1f (2023-07-14)

List of partitions ​

devsizeerasesizename
mtd00006000000010000"Boot"
mtd10001000000010000"Env"
mtd20039000000010000"ImageA"
mtd30039000000010000"ImageB"
mtd40006000000010000"Config"
mtd50001000000010000"SECTION_EGIS"
mtd60025000000010000"rootfs"
mtd70002000000010000"rootfs_data"

This stick supports dual boot, as visible from the presence of ImageA and ImageB, which contain the rootfs.

Useful files and binaries ​

Useful files ​

  • /var/config/ont.sys - Used to customize various settings on the stick. If you don't have it you can copy the stock one from /ont.sys

General Settings and Useful Commands ​

Note

All commands start from the twmanu shell.

GPON ONU status ​

Getting the operational status of the ONU ​

To check the connection status, use the following command:

linuxshell
onu ploamsg

curr_state=5 for O5 state, curr_state=1 for all other operational states.

Getting Speed LAN Mode ​

This SFP has HSGMII enabled by default: link_status=5 for HSGMII 2.5Gbit, link_status=4 for SGMII 1Gbit:

linuxshell
onu lanpsg 0

Setting Speed LAN Mode ​

Note

This command forces the speed to 2.5 and is instantaneous and permanent, use it only if your hardware supports HSGMII and is compatible (e.g. modified Broadcom 57810s NIC)

sh
hal
set speed 2.5g mode full

Querying a particular OMCI ME ​

Query via OMCI ME Class Name:

sh
omci
show me classname OmciClassName (e.g Ont2g)

Query via OMCI ME ID:

sh
omci
show me classid OmciClassId (e.g 7)

GPON/OMCI settings ​

Setting ONU GPON Serial Number ​

Note

The S/N is stored in the ASCII format.

sh
manufactory
set sn ALCLf0f0f0f0
exit
hal
set sn ALCLf0f0f0f0

Do not worry if one of the two commands results missing, the change is still applied with just one of them.

Setting ONU GPON PLOAM password ​

Note

The PLOAM password is stored in the ASCII format.

This can be done easily via the web UI. To do it via the shell use:

sh
hal
set password PLOAMPASS

Setting OMCI software version (ME 7) ​

Edit /var/config/ont.sys via vi directly on the stick itself. The file is CRLF terminated, one entry per line. The entries for the software version are:

SW_VER0:0xabcdef
SW_VER1:0xabcedf

Note

It's better to enter the software version in hex format, all lowercase precedeed by 0x.

Setting OMCI hardware version (ME 256) ​

sh
manufactory
set hardware version 3FE49165BFAA01

If the above command is missing you can edit /var/config/ont.sys via vi directly on the stick itself. The file is CRLF terminated, one entry per line. The entry for the hardware version is:

ONTG_VER:0x463630303556362e300000000000

The hardware version must be encoded in hex format and right padded to 28 characters with 0 (excluding the starting 0x) to avoid any spurious values.

Setting OMCI equipment ID (ME 257) ​

Note

Model number must not be longer than 20 characters in total.

sh
manufactory
set equipment id MYEQUIPMENTID
exit
omci
equipment id MYEQUIPMENTID

If any of the above commands is missing you can edit /var/config/ont.sys via vi directly on the stick itself. The file is CRLF terminated, one entry per line. The entry for the equipment id is:

ONTG_EQID:0x463630303556362E30000000000000000000000

The equipment id must be encoded in hex format and right padded to 39 characters with 0 (excluding the starting 0x) to avoid any spurious values.

Advanced settings ​

Resetting Web GUI admin credentials ​

Under certain circumstances, the Web GUI admin credentials might get changed from the default admin/1234 combination. To restore the default combination try following this method.

Creating a new rootfs ​

The stick has a tricky image packing method, fortunately it has been reverse engineered. A script to help you create a custom rootfs can be found here: https://github.com/hack-gpon/zyxel-pmg-3000-mod-kit

Flashing a new rootfs ​

Note

All commands start from the twmanu shell.

  • Transfer the new mtd on the stick via tftp:
linuxshell
tftp -gr mtd2.mod.bin TFTP_SERVER_IP
  • Flash it on the standby partition. You can use system and then show actimage to get the current active image. Check /proc/mtd for the right mtds. Usually:
  • if the currect active image is A, mtd2 is in use
  • If the current active image is B, mtd3 is in use
linuxshell
mtd -e /dev/mtd2 write /tmp/mtd2.mod.bin /dev/mtd2
  • Switch to the new image:
system
set actimage a
  • Reboot the ONT:
system
reboot

EEPROM (I2C slave simulated EEPROM) ​

The Zyxel PMG3000-D20B does not have a physical EEPROM, the Falcon SOC emulates an EEPROM by exposing it on the I2C interface as required by the SFF-8472 specification.

On the I2C interface, two memories of 256 bytes each will be available at the addresses 1010000X (A0h) and 1010001X (A2h).

The Zyxel PMG3000-D20B stores the content of the emulated EEPROM1 (A2h) in /tmp/config/sfp_eeprom1 to restore it after a reboot.

Info

The contents of EEPROM0 (A0h) are not stored anywhere and they're regenerated at each boot

EEPROM0 layout ​

addresssizenamedefault valuedescription
BASE ID FIELDS (SFF-8472)
01Identifier0x03 (SFP)Type of transceiver
11Ext identifier0x04 (MOD_DEF 4)Additional information about the transceiver
21Connector0x01 (SC)Type of media connector
3-108Transceiver0x04 0x40 0x00 0x02 0x12 0x10 0x00 0x80 (1X LX, 1310TX SMF, 1000BASE-LX, 1200 Mbps)Code for optical compatibility
111Encoding0x03 (8B/10B)High speed serial encoding algorithm
121Signaling Rate, Nominal0x0C (1Gbps)Nominal signaling rate
131Rate Identifier0x00 (Not used)Type of rate select functionality
141Length (SMF,km)0x14 (20 km)Link length supported for single-mode fiber, units of km
151Length (SMF)0xC8 (200 x 100m)Link length supported for single-mode fiber, units of 100 m
161Length (50 um, OM2)0xFF (No support)Link length supported for 50 um OM2 fiber, units of 10 m
171Length (62.5 um, OM1)0xFF (No support)Link length supported for 62.5 um OM1 fiber, units of 10 m
181Length copper cable0x00 (No support)Link length supported for copper or direct attach cable, units of m
191Length (50 um, OM3)0xFF (No support)Link length supported for 50 um OM3 fiber, units of 10 m
20-3516Vendor name0x4C 0x61 0x6E 0x74 0x69 0x71 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 (Lantiq)SFP vendor name (ASCII)
361Transceiver0x00 (No support)Code for optical compatibility
37-393Vendor OUI0x00 0x1C 0xADSFP vendor IEEE company ID
40-5516Vendor PN0x50 0x61 0x72 0x74 0x20 0x4E 0x75 0x6D 0x62 0x65 0x72 0x20 0x20 0x20 0x20 0x20 (Part Number)Part number provided by SFP vendor (ASCII)
56-594Vendor rev0x30 0x30 0x30 0x30 (0000)Revision level for part number provided by vendor (ASCII)
60-612Wavelength0x05 0x1E (1310nm TX)Laser wavelength
621Fibre Channel Speed 20xFF (No support)Transceiver's Fibre Channel speed capabilities
631CC_BASECheck code for Base ID Fields (addresses 0 to 62)
EXTENDED ID FIELDS (SFF-8472)
64-652Options0x00 0x1A (TX DISABLE, TX FAULT, RX LOS)Indicates which optional transceiver signals are implemented
661Signaling Rate, max0x00 (No specified)Upper signaling rate margin, units of %
671Signaling Rate, min0x00 (No specified)Lower signaling rate margin, units of %
68-8316Vendor SN0x6E 0x6F 0x20 0x73 0x65 0x72 0x69 0x61 0x6C 0x20 0x6E 0x75 0x6D 0x62 0x65 0x72 (no serial number)Serial number provided by vendor (ASCII)
84-918Date code0x31 0x33 0x30 0x31 0x30 0x31 0x20 0x20 (130101)Vendor's manufacturing date code
921Diagnostic Monitoring Type0x6C (Digital diagnostic, Internally calibrated, Received average power type, address change)Indicates which type of diagnostic monitoring is implemented
931Enhanced Options0xF0 (Alarm/warning flags, soft TX_DISABLE control, soft TX_FAULT monitoring, soft RX_LOS monitoring)Indicates which optional enhanced features are implemented
941SFF-8472 Compliance0x05 (Rev 11.0 of SFF-8472)Indicates which revision of SFF-8472 the transceiver complies with
951CC_EXTCheck code for the Extended ID Fields (addresses 64 to 94)
VENDOR SPECIFIC FIELDS
96-12732Vendor data0x20 0x20 0x20... (Not used)Vendor specifc data (ASCII)
128-255128Reserved0x00 0x00 0x00...Reserved

EEPROM1 layout ​

addresssizenamedefault valuedescription
DIAGNOSTIC AND CONTROL FIELDS
0-12Temp High Alarm0x64 0x00 (100℃)Value expressed in two's complement
2-32Temp Low Alarm0xCE 0x00 (-50℃)Value expressed in two's complement
4-52Temp High Warning0x55 0x00 (85℃)Value expressed in two's complement
6-72Temp Low Warning0xD8 0x00 (-40℃)Value expressed in two's complement
8-92Voltage High Alarm0x8C 0xA0 (3.6V)Value expressed in volt subunits[^subunit]
10-112Voltage Low Alarm0x75 0x30 (3.0V)Value expressed in volt subunits[^subunit]
12-132Voltage High Warning0x88 0xB8 (3.5V)Value expressed in volt subunits[^subunit]
14-152Voltage Low Warning0x79 0x18 (3.1V)Value expressed in volt subunits[^subunit]
16-172Bias High Alarm0xAF 0xC8 (90mA)Value expressed in milliampere subunits[^subunit]
18-192Bias Low Alarm0x00 0x00 (0mA)Value expressed in milliampere subunits[^subunit]
20-212Bias High Warning0x88 0xB8 (70mA)Value expressed in milliampere subunits[^subunit]
22-232Bias Low Warning0x00 0x00 (0mA)Value expressed in milliampere subunits[^subunit]
24-252TX Power High Alarm0x7B 0x86 (5dBm)Value expressed in watts subunits[^subunit]
26-272TX Power Low Alarm0x27 0x10 (0dBm)Value expressed in watts subunits[^subunit]
28-292TX Power High Warning0x6E 0x17 (4dBm)Value expressed in watts subunits[^subunit]
30-312TX Power Low Warning0x2B 0xD4 (0.1dBm)Value expressed in watts subunits[^subunit]
32-332RX Power High Alarm0x07 0xCB (-7dBm)Value expressed in watts subunits[^subunit]
34-352RX Power Low Alarm0x00 0x0F (-28dBm)Value expressed in watts subunits[^subunit]
36-372RX Power High Warning0x06 0x30 (-8dBm)Value expressed in watts subunits[^subunit]
38-392RX Power Low Warning0x00 0x14 (-27dBm)Value expressed in watts subunits[^subunit]
40-5516Reserved0x00 0x00 0x00...Contains the mac address of the SFP, it could also be empty
56-594RX_PWR(4) Calibration0x00 0x00 0x00 0x004th order RSSI calibration coefficient
60-634RX_PWR(3) Calibration0x00 0x00 0x00 0x003rd order RSSI calibration coefficient
64-674RX_PWR(2) Calibration0x00 0x00 0x00 0x002nd order RSSI calibration coefficient
68-714RX_PWR(1) Calibration0x00 0x00 0x00 0x001st order RSSI calibration coefficient
72-754RX_PWR(0) Calibration0x00 0x00 0x00 0x000th order RSSI calibration coefficient
76-772TX_I(Slope) Calibration0x00 0x00Slope for Bias calibration
78-792TX_I(Offset) Calibration0x00 0x00Offset for Bias calibration
80-812TX_PWR(Slope) Calibration0x00 0x00Slope for TX Power calibration
82-832TX_PWR(Offset) Calibration0x00 0x00Offset for TX Power calibration
84-852T(Slope) Calibration0x00 0x00Slope for Temperature calibration
86-872T(Offset) Calibration0x00 0x00Offset for Temperature calibration, in units of 256ths °C
88-892V(Slope) Calibration0x00 0x00Slope for VCC calibration
90-912V(Offset) Calibration0x00 0x00Offset for VCC calibration
92-943Reserved0x00 0x00 0x00Reserved
951CC_DMICheck code for Base Diagnostic Fields (addresses 0 to 94)
961Temperature MSBInternally measured module temperature
971Temperature LSB
981Vcc MSBInternally measured supply voltage in transceiver
991Vcc LSB
1001TX Bias MSBInternally measured TX Bias Current
1011TX Bias LSB
1021TX Power MSBMeasured TX output power
1031TX Power LSB
1041RX Power MSBMeasured RX input power
1051RX Power LSB
106-1094Optional Diagnostics0x00 0x00 0x00 0x00 (No support)Monitor Data for Optional Laser temperature and TEC current
1101Status/Control0x02 (Digital RX LOS)Optional Status and Control Bits
1111Reserved0x00Reserved
112-1132Alarm FlagsSupportedDiagnostic Alarm Flag Status Bits
1141Tx Input EQ control0x00 (No support)Tx Input equalization level control
1151Rx Out Emphasis control0x00 (No support)Rx Output emphasis level control
116-1172Warning FlagsSupportedDiagnostic Warning Flag Status Bits
118-1192Ext Status/Control0x00 0x00 (No support)Extended module control and status bytes
GENERAL USE FIELDS
120-1267Vendor Specific0x00 0x00 0x00 0x00 0x00 0x00 0x00Vendor specific memory addresses
1271Table Select0x00Optional Page Select
USER WRITABLE EEPROM
128-232105Reserved0x00 0x00 0x00...Reserved
233-2408GPON SNUnique in each SFPGPON Serial Number (ME 256)
241-2477Reserved0x00 0x00 0x00...Reserved
248-2558Vendor Control0x00 0x00 0x00... (Not used)Vendor specific control functions

Info

For more information, see the SFF-8472 Rev 11.0 specification.

Known Bugs ​

Miscellaneous Links ​

Copyright © 2022-2026. The documentation hereby found is distributed under the terms of the MIT License. Any external reference, link or software retains its original license and is not under the control of this website. Privacy Policy.