Security problem in PPPoE connection

Joe Maimon jmaimon at ttec.com
Sun Mar 12 19:40:40 UTC 2006




Joe Shen wrote:

> Hi,
> 
> We are facing problem with PPPoE in ethernet access
> network. 
> 
> To provide high speed access, 10Mbps/100Mbps ethernet
> is used as access method. But, we found some guy
> 'steal' some other's account by listening to
> broadcasting packets, and they also set up 'phishing'
> PPPoE server to catch those PPPoE authentication
> packets. 
> 

Well you need to do a few things

-- Terminate access to the miscreants
-- Implement features like private-vlans
-- Otherwise prevent ports from communicating between eachothers except 
through your authorized PPPoE server. MAC access lists may provide some 
help with that. You will need to examine exactly what your L2 switches 
support.





More information about the NANOG mailing list