[c-nsp] PPPoE client answers PADI?

Andre Beck cisco-nsp at ibh.net
Wed Jun 29 08:00:51 EDT 2005


Hi,

when debugging a strange PPPoE problem in a wireless access infra-
structure for which we provide IP access, we finally found that a
client did not connect to our PPPoE server because it received more
than one PADO to its PADI request. The first one to answer won, and
now try to stay vertical: The box that answered the PADI with a PADO
wasn't some rogue PPPoE server deployed by evil persons but actually
one of our own deployed Cisco 831 PPPoE clients! This platform is
of course only configured to vpdn request-dialin and doesn't even
have a PPPoE server feature that would allow us to configure it for
allow-dialin. Yet it obviously answers any PADI it receives with a
PADO of its own, directing the client trying to initiate a session
into the void.

Anyone ever seen this? Bug Toolkit doesn't have anything about it,
neither seems Google, Usenet or this list. I wouldn't actually believe
it if I hadn't seen the "debug pppoe events" and "debug pppoe packets"
trace that clearly shows otherwise.

TIA,
Andre.
-- 
                  The _S_anta _C_laus _O_peration
  or "how to turn a complete illusion into a neverending money source"

-> Andre Beck    +++ ABP-RIPE +++    IBH Prof. Dr. Horn GmbH, Dresden <-


More information about the cisco-nsp mailing list