CodingBox Q&A Ask question

XG-7100 into a carrier ADVA FSP150CP demarc: link is up, nothing ever comes back, SFP LED red

Asked Active Viewed 102 Original language: English
1

Small office, one leased line, and the carrier terminated it on an ADVA FSP150CP screwed to the wall of the comms cupboard. My job is to get our own router onto that circuit instead of renting one from them, so the ix0 SFP+ port of a Netgate XG-7100 goes straight ino the ADVA access port.

  • Netgate XG-7100, WAN on ix0
  • ADVA FSP150CP demarcation box, installed and configured by the carrier, no login for us
  • three different 1G optics tried at the router end
  • LC patch cord left behind by the installers

The router is convinced it has a link. The demarc is not:

ix0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
        media: Ethernet autoselect
        status: active

# tcpdump -ni ix0
ARP, Request who-has <gateway> tell <wan address>, length 28
ARP, Request who-has <gateway> tell <wan address>, length 28

Output counters climb, input counters sit at zero, and the capture never contains anything we did not send ourselves. The SFP LED on the ADVA stays red with every module I put in the router.

Tried so far:

  • all three optics one after the other, no change to the red LED
  • swapped and cleaned the patch cord
  • carrier support say the circuit tests clean up to the demarc and that is where their job ends

Which module does this box actually want, and is a red SFP LED telling me my optic is wrong or that their port is provisioned for something else entirely?

Comments 6

Accepted answer

Your own counters have already told you which side of the fibre to look at, so start there rather than with a fourth module. Output climbing, input flat at zero, nothing in the capture except your own ARP going out. Nothing is arriving on your receive fibre at all. That is what a media mismatch looks like from the router side: your transmit disappears into the dark, the far end never answers, and the interface still reports active because the local side is happy with what it can see.

The access port on an FSP150CP is provisioned by the carrier for one media type - single mode fibre, multimode fibre or RJ45 - and the module in the router has to match that fibre type and wavelength. Red on the SFP LED is the box declining what it has been handed. When it does accept a module the Rate LED sits green at 1G, so those two lights together are your test result.

What this is not is a vendor whitelist. The router vendor's own people rebuilt this arrangement on a bench with an ADVA 0061003008 in the demarc and ordinary single mode 1000BASE-LX optics in the XG-7100, and it also came up with a Metrodata S12W1310S010C15C and with an FS SFP1G-LX-31. Third party 1G optics are not what is stopping you.

So the useful next move is not a fourth module. Get the carrier to state, in writing, what media type that access port is provisioned for, then match it. Fair warning though, this is exactly where these cases tend to stall: if they keep the box locked and will not tell you, you are buying optics and guessing, one at a time.

8 GermanywavesmithDE Original (English)

There's more than one lamp on that box worth reading, and you've only quoted one of them. When the FSP150CP is happy with a module and the port is running at a gig, the Rate LED goes green. Is yours green, amber or dark? Red on the SFP LED is the box saying the module and the way the port is set up don't agree, which isn't the same statment as your optic being broken.

Second question, and it's the one that actually decides this: what did the carrier provision that access port for? Single mode fibre, multimode fibre or RJ45 - and the router end has to be whichever of the three they gave you. Do you know which it is?

Also, what wavelength is each of the three optics you tried? The label normally says 850 nm or 1310 nm, and that matters a great deal more than the brand printed next to it.

1 IndiagigopsIN Original (English)

Asked them, and got most of the way to an answer by being refused.

The lights first, since that was the one thing I could check without their help. The Rate LED never comes on at all - dark, not amber - while the SFP LED sits red with every module. And I finally read the labels instead of the brands: all three optics are 1310 nm single mode, one of them a plain 1000BASE-LX. So I ran the same test three times and counted it as three tests, which is a lesson in itself.

The rest went nowhere. They won't release the configuration, they won't say what the access port is provisioned for, and when I asked them to enable the RJ45 port instead so we could take fibre out of the equation altogether, that was refused too. The box is theirs, the config is theirs, conversation over.

So the office is now up on a router rented from the carrier, which is precisely what I was trying to avoid, and the XG-7100 is on a shelf. Leaving this open in case somebody geets further with their own demarc than I managed to.

4 SpainoptictechES Original (English)

Same corner, different carrier box, if it's any comfort. XG-7100 again, fibre this time into an Adtran 5660 while a circuit was being moved from 100 Mbps up to a gig. The firewall side repoorted the port active and negotiated at 1000baseSX full duplex with a Ubiquiti UF-MM-1G in it. The Adtran just sat there at DOWN/DOWN.

Pinned the media instead of leaving it on autoselect:

ifconfig ix0 media 1000baseSX mediaopt full-duplex

No change. Rotated through Cisco and Ciena optics, no change. Went to a newer development build of the firewall image because somebody suggested it, no change. The same optic on the same fibre linked into a UniFi switch first time, so the module was never the fault, and the carrier's own support had nothing for us.

We gave up in the end and left a UniFi switch in the path, carrying the circuit across a VLAN between two of its ports so the Adtran only ever faces the switch. Direct firewall to CPE never came up and I still can't tell you why.

1 United Statestxnode67US Original (English)

Let me make the media point concrete, because "three different transceivers" is very often one test performed three times.

850 nm belongs to SR and to multimode glass; 1310 nm belongs to LR and to single mode. Both ends have to be the same kind, there is nothing to negotiate across that gap, and no amount of interface configuration changes which wavelength leaves the laser.

Those distance numbers are ceilings rather than floors, which catches people going the other way: LR modules at both ends of a three metre patch inside one rack are perfectly happy, they just want single mode cords. LR down multimode does occasionally produce a link over a couple of metres, but that is off-spec behaviour and not something to hang a paid circuit on.

Neatest example of this I have seen was a FortiGate that would not link to switches carrying Brocade and Extreme optics, and the whole discussion around it was about brand incompatibility. The Fortinet module was 10G SR, the far side was 10G LR. No whitelist, no vendor lock, just multimode staring at single mode.

4 KazakhstanrackhubKZ Original (English)

I wouldn't file that one under vendor lock either, and I'd be careful how the workaround gets read by anyone finding this later.

Putting a switch in the middle proves your optic, your fibre and your firewall port are all healthy. It says nothing whatsoever about why the CPE would not take the link directly - it moves the problem behind something the CPE is willing to talk to, and leaves it sitting there.

Pinning the media with ifconfig only changes how the local interface treats the link, too. It can't change what comes out of the optic, so it was never going to fix a media type mismatch at the far end. In both of tese cases the one thing nobody could see was how the carrier had provisioned their access port, and in both of them that is where the answer lives.

4 Ukrainerxnode71UA Original (English)
Log in to comment. Log in