OMCI Wireshark and PCAP tools
The OMCI (ONT Management and Control Interface, ITU-T G.984.4 / G.988) messages exchanged between the OLT and the ONT contain the whole provisioning of the line: managed entities, VLAN rules, T-CONTs, GEM ports and the values the OLT expects from the ONT. Capturing them is the best way to understand why an ONT does not work, or to clone the configuration of the ISP ONT.
The workflow is:
- enable the OMCI log on the ONT and copy the log to the PC;
- convert the log to a
.pcapfile with omcilog2pcap; - open the
.pcapfile in Wireshark with the OMCI Wireshark dissector; - optionally, analyze large captures with omcipcap.
omcilog2pcap
omcilog2pcap converts the OMCI logs of the ONTs into .pcap files. The format of the log is detected automatically:
| Log | Detected by |
|---|---|
Lantiq based chips (e.g. Huawei MA5671A), omcid log | [omcid] lines |
| Sagemcom devices (e.g. the TIM F@st 5684S) | :omci capture: lines |
Cortina Access devices: merge the pkt_rx and pkt_tx logs into a single file, the packets are re-ordered automatically | debug: lines |
| Huawei devices (e.g. OptiXstar S800E, B450) | OLT->ONT / ONT->OLT blocks |
| Realtek based chips (e.g. Technicolor AFM0002TIM): one OMCI message in hex per line | any other text log |
The default version is the .NET one (native AOT), in the C# branch. Download the executable for your OS from the releases, or build it from src/ with the .NET SDK.
To convert a log, drag and drop it on the executable, or pass it as argument:
omcilog2pcap omci_log.txtThe .pcap file is written in the current directory with the same name as the log (omci_log.pcap). Each OMCI message is wrapped in a fake Ethernet frame with EtherType 0x88B5 (OLT MAC 08:87:01:70:17:01, ONT MAC 08:87:88:00:00:00), which is the EtherType the dissector is registered on.
WARNING
The js branch contains an experimental JavaScript port (ALPHA) that has never been tested: use the C# version.
Getting the OMCI log on Realtek based sticks
On the Realtek (Luna SDK) based sticks the OMCI daemon can write a binary log to /tmp/omcilog:
/etc/scripts/flash set OMCI_DBGLVL 1
/etc/scripts/flash set OMCI_DBGLOGFILE 1
reboot
/bin/omcicli set logfile 1 ffffffffThen copy the log to the PC, for example:
ssh admin@192.168.2.1 "cat /tmp/omcilog" > omcilog.logTo log the messages since the boot of the stick, add the last command at the end of etc/runomci.sh in a custom rootfs. See the Technicolor AFM0002 page for the details.
OMCI Wireshark dissector
The OMCI Wireshark dissector is a Lua plugin that decodes the OMCI messages in Wireshark. It requires Wireshark 1.4.3 or newer with Lua 5.1 or newer (check it in Help > About).
To install it, copy both omci.lua and BinDecHex.lua in the Wireshark personal plugins folder:
| OS | Folder |
|---|---|
| Linux/*nix | $HOME/.config/wireshark/plugins |
| Windows | %APPDATA%\Wireshark\plugins |
| macOS | $HOME/.config/wireshark/plugins |
Restart Wireshark and open omci-example.pcap from the repository to check that the dissector works. Use the omci display filter to show only the OMCI messages.
The dissector is a fork of 0liv1er/omci-wireshark-dissector, originally published on Google Code.
omcipcap
omcipcap is an open-source GPON/XGS-PON OMCI semantic analysis framework for .pcap and .pcapng files. It complements packet-level inspection tools such as Wireshark by reconstructing protocol-level engineering information from OMCI traffic:
- Detect OMCI provisioning failures and error responses
- Build and compare MIB snapshots
- Analyze Extended VLAN Tagging Operation Configuration Data (ME 171)
- Reconstruct T-CONT, GEM Port and Priority Queue relationships
- Generate OMCI topology information
- Produce structured JSON and Markdown output for automation and AI-assisted analysis
- Support vendor-specific Managed Entity definitions and semantic extensions
It is available on GitHub and PyPI.