Community discussions

MikroTik App
 
brainy
Member Candidate
Member Candidate
Topic Author
Posts: 155
Joined: Fri Sep 29, 2006 3:08 pm
Location: Unterschleissheim, Germany
Contact:

PPPoE Flooding

Wed Oct 17, 2007 12:57 pm

Hi there,

we have a customer that has some kind of broken PPPoE-Client.

The problem is, that his router is flooding our MT Box with several PPPoE-Login/Logout's Sessions.

There are about 10 new Sessions per Second, resulting in 100% CPU usage and a lot of memory usage.

Can i somehow add a delay in PPPoE-Server?

Or anything else i can do to prevent that.

I already have "One session per host" active.
 
ropebih
Member Candidate
Member Candidate
Posts: 113
Joined: Tue May 22, 2007 5:35 pm

Re: PPPoE Flooding

Wed Oct 17, 2007 5:40 pm

I have some problem...
 
ropebih
Member Candidate
Member Candidate
Posts: 113
Joined: Tue May 22, 2007 5:35 pm

Re: PPPoE Flooding

Thu Oct 18, 2007 3:06 pm

Can someone from mikrotik explain this. Is it something that can be done for prevention? Only reboot helps after this and that's not good.

Image
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: PPPoE Flooding

Thu Oct 18, 2007 3:21 pm

You can use 3.0rc6 there is improved pppoe server functionality that will help in your case.
 
brainy
Member Candidate
Member Candidate
Topic Author
Posts: 155
Joined: Fri Sep 29, 2006 3:08 pm
Location: Unterschleissheim, Germany
Contact:

Re: PPPoE Flooding

Wed Nov 21, 2007 9:21 pm

So where is this function to prevent this kind of flood? I installed rc10 on a testmachine and didnt find anything.
 
UniKyrn
Member Candidate
Member Candidate
Posts: 245
Joined: Fri Dec 24, 2004 9:27 pm
Location: Spokane, WA

Re: PPPoE Flooding

Wed Nov 21, 2007 9:36 pm

Why not add a firewall rule to throw away the PPPoE frames from his routers MAC address?
 
ropebih
Member Candidate
Member Candidate
Posts: 113
Joined: Tue May 22, 2007 5:35 pm

Re: PPPoE Flooding

Sat Jan 12, 2008 4:33 pm

up...

any solutions for this problem?
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: PPPoE Flooding

Sat Jan 12, 2008 9:31 pm

You can run PPPOE server on bridge interface. This will allow you to use bridge filters where you can successfully drop or limit pppoe discovery packets.
 
ropebih
Member Candidate
Member Candidate
Posts: 113
Joined: Tue May 22, 2007 5:35 pm

Re: PPPoE Flooding

Sat Feb 09, 2008 12:38 am

You can run PPPOE server on bridge interface. This will allow you to use bridge filters where you can successfully drop or limit pppoe discovery packets.
Can you explain me how could I imitate number of PPPoE connections in bridge filter?

Thanks
 
User avatar
gmsmstr
Trainer
Trainer
Posts: 982
Joined: Fri Jun 04, 2004 2:22 am
Location: St. Louis, MO
Contact:

Re: PPPoE Flooding

Sun Feb 10, 2008 2:38 am

As posted, add the interface to a bridge, then use the bridge filters to limit the PPPoE discovery packets

Second, v3 should only allow 50 attempts at any given time. This is a OS feature, not a "software" swtich that you can change in v3.

Who is online

Users browsing this forum: billyerasmus101, Majestic-12 [Bot], nl2024, r0nzzibb and 211 guests