help! discovered authentication bypass

Hi!

Im using my CCRs PPPoE to authenticate users and give them access to the network according to the user profiles. we’ve found that if someone puts in the IP of the CCR and uses that as a gateway on a windows PC, they can access the internet without having to authenticate with the CCR. how can I prevent this?

sorry for the very basic question

Export your configuration and post here.