Hi all,
at the present, our "last mile" setup involves the use of Nv2 and OSPF to manage routing with CPEs (all of them are SXT); I'm a bit worried about the possibility of someone breaking into the CPE (they're at customers houses, not physically-secure), stealing our nv2 psk and begin fiddling with our routing. OSPF is active only on the wireless side of CPE, which, in turn, is unmanageable by the LAN side due to firewall; but - I learned - if you have physical access to the device it's possible to reset it, recover the configuration, and even get the passwords.
The network is already partitioned into several areas, typically one for each AP...the first thing I'm going to do, is to setup route-filters, in order to keep unwanted updates out of the backbone.
Now a couple of questions:
Is it possible to have, with nv2, per-customer psk ? It wouldn't solve the problem completely, but will allow a better manageability in the event of a...well, bad event
We thought about switching to PPPoE, to avoid CPEs talking OSPF with AP; this would also give us the possibility to disable client-forwarding, which is quite convenient. Is someone using it ? How well it performs in terms of overhead and CPU utilization ?
Best regards,
Simone.