In August 2026, 81% of Brazil's 57.9 million fixed broadband connections were fiber, according to the access dashboard published by Anatel, Brazil's telecom regulator. At a regional ISP, the typical CPE in the subscriber base is an ONT, and it almost never comes from a single vendor. The OLT is from one manufacturer, last year's batch came from another, and this month's is whatever the distributor had in stock.
In a network like that, the TR-069 question support hears most often is how to configure a third-party ONT so it points to the ACS and shows up there. The recipe that works with an ONU from the OLT's own vendor fails with the rest, and the technician can't tell whether the problem is in the OLT, the ONT or the server. How the protocol works is covered in Unraveling TR-069. During rollout, what almost always gets stuck is getting the device to point at the ACS.
Why a third-party ONT won't bring up TR-069 through the OLT
Between the OLT and the ONU, management runs over OMCI, standardized by the ITU-T in Recommendation G.988. That's how the OLT creates services and VLANs and, in many cases, hands the ONU the TR-069 server details. The standard is shared by everyone, but it reserves room for proprietary management entities, and each vendor fills that room its own way. When the OLT sends the WAN and TR-069 configuration through its own extensions, a third-party ONT drops whatever it doesn't understand and comes up with what it managed to build. Routing ONTs (HGUs) make this harder, because the router side is usually configured through TR-069 itself, so the OLT has to get the ONU to create a WAN with the right service before TR-069 has any way out.
The classic symptom is the ONT's WAN coming up with the INTERNET service and without INTERNET_TR069. PPPoE authenticates, the subscriber browses, and the device never appears in the ACS, because the ONT's CWMP client has no outbound interface enabled for it. According to the CWMP configuration page in the IXC ACS Help Center, that service has to be enabled on the WAN, and the CWMP screen differs from vendor to vendor because not all of them follow the Broadband Forum standard to the letter. On some models, such as the TP-Link XX530v, the documented fix is to delete the WAN and create a new one with both TR069 and INTERNET checked.
Three ways to point CPEs at the ACS in a multi-vendor network
The first is the one everybody tries. The OLT pushes the WAN profile with TR069 along with the ONU authorization. With an ONT from the OLT's vendor, or from a brand the OLT vendor has already tested, it's the cleanest path, and the ONU shows up in the ACS without anyone touching it. With a different brand, test one unit before you count on it.
The second is ACS discovery via DHCP, defined in the Broadband Forum's TR-069 specification. The CPE asks the DHCP server for the ACS address in a vendor-specific option, and the ISP answers with the URL. In a mixed fleet, a common design uses two WANs on the ONT, one for internet over PPPoE and another for management over IPoE on its own VLAN, with DHCP handing out the URL, so pointing no longer depends on the OLT. The catch is that support for that option varies by model and firmware. Some ONTs request it and apply it, some ignore it, and testing is the only way to find out.
The third is to write the ACS URL into the device before it goes out to the field or, better still, ask the supplier to ship the batch with your ACS URL in the factory defaults. Typing it in unit by unit through the web interface has the limits we discussed in TR-069 vs Web Interface, and a setting entered that way is gone after the first factory reset. A factory template scales and survives a reset. For upcoming batches, that's where we would put the effort, because it removes the dependence on the OLT and on how each firmware behaves with DHCP.
TR-069 configuration: getting the URL and credentials right
Whichever path you choose, what reaches the ONT is a URL and a few username and password pairs. The URL has four parts (scheme, host, port and path), as in http://acs.example.com:7547/tr069, and every one of them matters. The address you type in the browser to open the ACS dashboard usually won't work, because that's only the domain.
Point by domain name, never by IP. A fleet pointed at an IP stops talking to the ACS the day the server changes address, and then the re-pointing has to be done on the device, the OLT or the provisioning profile, because the ACS can't reach devices that can't reach it.
With credentials, the confusion comes from similar names. The ACS username and password are what the CPE uses to authenticate to the server. The Connection Request credential goes the other way, and it's what the ACS uses to ask the CPE for an immediate session. The web interface admin login plays no part in pointing. Since these fields sit on the same screen, one below the other, that's exactly where they get swapped. The IXC ACS Help Center has a page on TR-069 pointing credentials that lists what each vendor calls each field.
The ONU isn't showing up in the ACS. What should I check?
With the configuration done and nothing arriving, work from the most likely and cheapest check to the rarest, in the order of the Help Center guide for devices that don't appear in IXC ACS.
- Confirm the URL is complete, with scheme, a colon before the port, and path. Copy and paste the field saved on the device to compare it instead of reading it by eye.
- Test the ACS port from a machine on the subscriber network, because from the server itself it always answers. An immediate refusal points to the wrong port or a stopped service, and a timeout points to a firewall somewhere in the path.
- Check that the domain resolves to the right server. This tends to break after a server migration or an IP change.
- Search for the device by serial number. A newly arrived ONU isn't linked to a customer yet, so it won't appear in a search by login.
- Review the credentials, keeping in mind that wrong credentials rarely stop a device from appearing. Their typical symptom is a device that shows up but doesn't respond to commands right away.
- See whether the model is certified. An uncertified model still shows up and displays the basics, so if nothing appears at all, the cause is in the items above.
CGNAT usually gets the blame and is almost never the reason. The Inform goes from the CPE to the ACS, and NAT doesn't block outbound connections, so a device behind CGNAT shows up normally. What it gets in the way of is the Connection Request, which travels from the ACS to the CPE, and the immediate command waits in the queue until the next Inform. In IXC ACS, the CPE CWMP Port indicator in the header of the device screen shows whether that port is open, closed or filtered.
Once it's up: standardizing a multi-vendor fleet
With the ONT showing up, the job becomes getting different models configured the same way. In IXC ACS, Device Pre-configuration defines parameters such as WAN and LAN DNS, NTP, web access and the Wi-Fi regulatory domain, which are sent to every new device that reaches the ACS. Each model applies what it supports, and the screen itself shows what each one doesn't. When a device goes back to factory defaults, automatic preset-based reconfiguration detects the reset and reapplies the settings.
Frequently asked questions
Which port does TR-069 use? 7547 is the registered CWMP port and the one most CPEs use to receive Connection Requests. The port where the ACS listens for Informs depends on the installation, so confirm yours instead of copying it from a manual.
What Inform interval should I use? In IXC ACS, a new installation ships with 1,200 seconds (20 minutes), and the system won't accept anything below 300. Start with the default and only lower it for a reason, because a short interval multiplies sessions and server load without bringing in new information at the same rate.
Next steps for your ISP
In a multi-vendor network, ACS pointing that holds up doesn't depend on a technician's memory or on the OLT getting along with another vendor's ONT. For upcoming batches, decide before you buy between a management WAN with DHCP and a factory template, and write down for the team the URL that already works in your fleet.
If you'd like to see how this works with the models you have in the field, click the button below to talk to our team.