CCR-1036-12G-4S rebooting after pptp users auth fail

I use CCR-1036-12G-4S as pptp server. Users auth by radius server, and after a lot of attempts unsuccess authorization (bad password or radius responce timeout) router go to reboot.

I have ROS version 6.32.3

Crash log:

10:43:10 radius,debug     Framed-Protocol = 1 
10:43:10 radius,debug     NAS-Port = 15733943 
10:43:10 radius,debug     NAS-Port-Type = 5 
10:43:10 radius,debug     User-Name = "test" 
10:43:10 radius,debug     Calling-Station-Id = "10.108.95.203" 
10:43:10 radius,debug     Called-Station-Id = "10.64.0.12" 
10:43:10 radius,debug     MS-CHAP-Challenge = 0x59dbb41a908c85f1 
10:43:10 radius,debug     MS-CHAP-Response = 0x01010000000000000000000000000000 
10:43:10 radius,debug       000000000000000000000d2579187376 
10:43:10 radius,debug       06a127027949b0230f4dfdee3eda92c4 
10:43:10 radius,debug       b56d 
10:43:10 radius,debug     NAS-Identifier = "Str29.VPN" 
10:43:10 radius,debug     NAS-IP-Address = 10.128.255.18 
10:43:11 radius,debug received Access-Reject with id 195 from 10.50.3.10:1812 
10:43:11 radius,debug     Signature = 0xc45da105070562b06bebaebeaf67e412 
10:43:11 radius received reply for 1b:1dec 
10:43:11 radius,debug received Access-Accept with id 192 from 10.50.3.10:1812 
10:43:11 radius,debug     Signature = 0x9f921e622c26566c85dcf0ab8b0cb45e 
10:43:11 radius,debug     MS-CHAP-MPPE-Keys = 0x63715394b41717d107afb5d29551880a 
10:43:11 radius,debug       513d3b67bae64f9c31be67cee98a50d5 
10:43:11 radius,debug     MS-MPPE-Encryption-Policy = 1 
10:43:11 radius,debug     MS-MPPE-Encryption-Type = 6 
10:43:11 radius,debug     Service-Type = 2 
10:43:11 radius,debug     Framed-Protocol = 1 
10:43:11 radius,debug     Acct-Interim-Interval = 0 
10:43:11 radius,debug     Framed-IP-Address = 10.10.5.135 
10:43:11 radius,debug     MT-Rate-Limit = "100k" 
10:43:11 radius,debug     Unknown-Attribute(type=230) = 0x00000064 
10:43:11 radius,debug     Unknown-Attribute(type=232) = 0x00000064 
10:43:11 radius,debug     Unknown-Attribute(type=231) = 0x0000000a 
10:43:11 radius,debug     Unknown-Attribute(type=233) = 0x00000064 
10:43:11 radius,debug     Session-Timeout = 600 
10:43:11 radius received reply for 1b:1de9 
10:43:11 radius,debug received Access-Accept with id 193 from 10.50.3.10:1812 
10:43:11 radius,debug     Signature = 0x8f4e1147105a3947dd0c524af015e461 
10:43:11 radius,debug     MS-CHAP-MPPE-Keys = 0x2dcc8ee711839996dab518f8c8a40d0a 
10:43:11 radius,debug       480ec04cf97d1d8ebb86c0fe14897b14 
10:43:11 radius,debug     MS-MPPE-Encryption-Policy = 1 
10:43:11 radius,debug     MS-MPPE-Encryption-Type = 6 
10:43:11 radius,debug     Service-Type = 2 
10:43:11 radius,debug     Framed-Protocol = 1 
10:43:11 radius,debug     Acct-Interim-Interval = 0 
10:43:11 radius,debug     MT-Rate-Limit = "60000k" 
10:43:11 radius,debug     Unknown-Attribute(type=230) = 0x0000ea60 
10:43:11 radius,debug     Unknown-Attribute(type=232) = 0x00000064 
10:43:11 radius,debug     Unknown-Attribute(type=231) = 0x00001770 
10:43:11 radius,debug     Unknown-Attribute(type=233) = 0x00000064 
10:43:11 radius,debug     Session-Timeout = 86430 
10:43:11 radius received reply for 1b:1dea 
10:43:13 radius,debug received Access-Accept with id 194 from 10.50.3.10:1812 
10:43:13 radius,debug     Signature = 0x7187708078d922166a2ca31f02674ed2 
10:43:13 radius,debug     MS-CHAP-MPPE-Keys = 0x274f93294f776401bbe4fe0bd8cd7284 
10:43:13 radius,debug       a762b84913fd152074096a5d115fe3fc 
10:43:13 radius,debug     MS-MPPE-Encryption-Policy = 1 
10:43:13 radius,debug     MS-MPPE-Encryption-Type = 6 
10:43:13 radius,debug     Service-Type = 2 
10:43:13 radius,debug     Framed-Protocol = 1 
10:43:13 radius,debug     Acct-Interim-Interval = 0 
10:43:13 radius,debug     MT-Rate-Limit = "120000k" 
10:43:13 radius,debug     Unknown-Attribute(type=230) = 0x0001d4c0 
10:43:13 radius,debug     Unknown-Attribute(type=232) = 0x00000064 
10:43:13 radius,debug     Unknown-Attribute(type=231) = 0x00002ee0 
10:43:13 radius,debug     Unknown-Attribute(type=233) = 0x00000064 
10:43:13 radius,debug     Session-Timeout = 86430 
10:43:13 radius received reply for 1b:1deb 
10:00:59 system,error,critical System rebooted because of kernel failure 
10:00:59 system,error,critical router was rebooted without proper shutdown, probably kernel failure 
10:12:47 ppp,error,critical 2654: Encryption got out of sync - disabling



/export 
# jan/01/2002 23:28:37 by RouterOS 6.32.3
# software id = X4X4-FCYC
#
/interface vlan
add interface=sfp1 l2mtu=1576 name=vlan2 vlan-id=2
add interface=sfp1 l2mtu=1576 name=vlan100 vlan-id=100
add interface=sfp1 l2mtu=1576 name=vlan155 vlan-id=155
add interface=sfp2 l2mtu=1576 name=vlan250 vlan-id=250
add interface=sfp2 l2mtu=1576 name=vlan251 vlan-id=251
add interface=sfp2 l2mtu=1576 name=vlan252 vlan-id=252
add interface=sfp2 l2mtu=1576 name=vlan253 vlan-id=253
add interface=sfp2 l2mtu=1576 name=vlan254 vlan-id=254
add interface=sfp2 l2mtu=1576 name=vlan255 vlan-id=255
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=vpn-pptp ranges=93.157.16.1-93.157.19.254
/ppp profile
add change-tcp-mss=yes dns-server=193.111.3.1 local-address=10.64.0.12 name=pptp-server only-one=yes remote-address=vpn-pptp session-timeout=1d use-compression=no use-encryption=no use-ipv6=no use-mpls=no
/tool user-manager customer
set admin access=own-routers,own-users,own-profiles,own-limits,config-payment-gw
/interface pptp-server server
set authentication=pap,chap default-profile=pptp-server enabled=yes
/ip address
add address=10.128.0.9/21 interface=vlan100 network=10.128.0.0
add address=192.168.88.1/24 interface=ether1 network=192.168.88.0
add address=10.128.255.18/30 interface=vlan155 network=10.128.255.16
add address=10.128.64.21/29 interface=vlan251 network=10.128.64.16
add address=10.40.0.1/24 interface=vlan2 network=10.40.0.0
add address=10.64.0.12/27 interface=vlan2 network=10.64.0.0
add address=10.64.0.14/27 interface=vlan2 network=10.64.0.0
add address=10.128.64.29/29 interface=vlan252 network=10.128.64.24
add address=10.128.64.37/29 interface=vlan253 network=10.128.64.32
add address=10.128.64.45/29 interface=vlan254 network=10.128.64.40
add address=10.128.64.134/29 interface=vlan255 network=10.128.64.128
add address=10.128.64.13/29 interface=vlan250 network=10.128.64.8
/ip firewall filter
add action=drop chain=input src-address=10.105.24.43
add action=drop chain=input src-address=10.108.34.93
add action=drop chain=input src-address=10.105.42.28
add action=drop chain=input src-address=10.107.0.186
add action=drop chain=input src-address=10.108.95.203
/ip route
add distance=1 gateway=10.128.255.17
add distance=1 dst-address=10.10.90.16/29 gateway=10.128.64.25
add distance=1 dst-address=10.33.17.0/24 gateway=10.128.64.17
add distance=1 dst-address=10.60.16.0/21 gateway=10.128.64.33
add distance=1 dst-address=10.60.24.0/21 gateway=10.128.64.25
add distance=1 dst-address=10.60.32.0/21 gateway=10.128.64.17
add distance=1 dst-address=10.65.0.0/16 gateway=10.128.64.9
add distance=1 dst-address=10.66.0.0/18 gateway=10.128.64.17
add distance=1 dst-address=10.67.0.0/18 gateway=10.128.64.17
add distance=1 dst-address=10.68.0.0/16 gateway=10.128.64.33
add distance=1 dst-address=10.69.0.0/16 gateway=10.128.64.9
add distance=1 dst-address=10.70.0.0/16 gateway=10.128.64.9
add distance=1 dst-address=10.70.5.0/24 gateway=10.128.64.41
add distance=1 dst-address=10.70.15.0/24 gateway=10.128.64.41
add distance=1 dst-address=10.71.0.0/18 gateway=10.128.64.25
add distance=1 dst-address=10.71.21.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.71.23.0/24 gateway=10.128.64.41
add distance=1 dst-address=10.72.0.0/16 gateway=10.128.64.25
add distance=1 dst-address=10.72.2.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.3.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.4.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.10.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.11.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.13.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.14.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.15.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.20.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.25.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.27.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.28.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.29.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.72.30.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.73.0.0/16 gateway=10.128.64.41
add distance=1 dst-address=10.73.30.0/24 gateway=10.128.64.33
add distance=1 dst-address=10.74.0.0/18 gateway=10.128.64.25
add distance=1 dst-address=10.77.0.0/16 gateway=10.128.64.33
add distance=1 dst-address=10.78.0.0/16 gateway=10.128.64.33
add distance=1 dst-address=10.79.0.0/18 gateway=10.128.64.17
add distance=1 dst-address=10.80.0.0/21 gateway=10.128.64.33
add distance=1 dst-address=10.81.0.0/16 gateway=10.128.64.129
add distance=1 dst-address=10.89.1.0/24 gateway=10.128.64.41
add distance=1 dst-address=10.105.0.0/16 gateway=10.128.64.9
add distance=1 dst-address=10.106.0.0/16 gateway=10.128.64.17
add distance=1 dst-address=10.107.0.0/16 gateway=10.128.64.25
add distance=1 dst-address=10.108.0.0/16 gateway=10.128.64.33
add distance=1 dst-address=10.109.0.0/16 gateway=10.128.64.41
add distance=1 dst-address=10.110.0.0/16 gateway=10.128.64.129
add distance=1 dst-address=192.168.34.0/24 gateway=10.128.64.33
add distance=1 dst-address=192.168.35.0/24 gateway=10.128.64.17
add distance=1 dst-address=192.168.80.152/29 gateway=10.128.64.33
add distance=1 dst-address=192.168.83.0/24 gateway=10.128.64.25
add distance=1 dst-address=192.168.87.0/24 gateway=10.128.64.41
add distance=1 dst-address=192.168.129.0/24 gateway=10.128.64.9
add distance=1 dst-address=192.168.130.0/24 gateway=10.128.64.9
add distance=1 dst-address=192.168.250.0/24 gateway=10.128.64.25
/ppp aaa
set use-radius=yes
/radius
add address=10.50.3.10 secret=**** service=ppp src-address=10.128.255.18 timeout=10s
/system identity
set name=Str29.VPN
/system logging
add action=echo disabled=yes topics=pptp,debug,radius
add action=echo disabled=yes topics=pptp,debug
add action=disk topics=critical
add action=disk topics=warning
/system note
set note=str29.vpn
/system routerboard settings
set cpu-frequency=1200MHz memory-frequency=1066DDR
/tool user-manager database
set db-path=user-manager

I think there is problem with auth spamming requests by users with incorrect login/password pair.
Now I have been testing it after disabled ms-chap auth method.