Hello everyone.
I am troubleshooting a strange issue on a MikroTik RB750Gr3 (RouterOS 6.48.6) running a PPPoE WISP network.
Some time ago, an unusual and abnormally high traffic/usage pattern started appearing, apparently related to one or a few specific clients.
This behavior did not exist before, and now it generates traffic patterns that are difficult to explain.
What makes this confusing is that I have already tested multiple scenarios:
-
Different network layouts
-
Network isolation using VLANs
-
Monitoring with Torch
-
Packet captures (tcpdump / Wireshark)
-
MAC/IP observation and traffic correlation
However, I still cannot find a clear protocol, destination, or traffic pattern explaining the behavior.
In captures, some devices show more activity than others, plus expected multicast/broadcast traffic, but nothing that clearly identifies the source of the abnormal usage.
Environment:
-
MikroTik RB750Gr3
-
RouterOS 6.48.6
-
PPPoE clients
-
WISP environment
-
Some client environments include routers, TVs, streaming devices, etc.
At this point I am trying to determine whether this could realistically be caused by:
-
Client-generated abnormal traffic
(Smart TV, Android TV, router, internal LAN device, IPTV/streaming app, malware, cloud sync, misbehaving application, etc.) -
Physical / external hardware issue
(Bad switch, damaged Ethernet cable, faulty port, defective PoE injector/power supply, negotiation problem, Layer-2 loop, broadcast storm, etc.) -
Specific MikroTik / PPPoE behavior
Something that may only appear under certain traffic conditions or with particular devices.
An additional challenge is that packet captures do not show an obvious smoking gun explaining the amount of traffic observed.
Has anyone experienced something similar in a PPPoE/WISP environment?
What would you investigate next to distinguish between:
-
client/application behavior
-
Layer-2 physical problems
-
MikroTik/PPPoE related causes
Any ideas or similar experiences would be appreciated.
