Page 1 of 1
Limit on frequent PPPoE-session authentication failures?
Posted: Thu Jan 21, 2010 7:50 am
by archerfish
RouterOS v3.30 on x86.
We have some pppoe servers with radius-authentication. Sometimes, our customers tune their pppoe-clients to retry every second forever. For blocked (by billing) customers we offer so-called 'gray' pppoe-session (with ip 192.168.x.x), that have access only to a few corp sites. But some of them made errors in password, use invalid logins or do other mistakes. So our radius server takes a high load to process such useless frequent queries, while they (customers) sleeps or went away to job, and etc.
Is there any method to limit these negative pppoe-session creation requests?
Re: Limit on frequent PPPoE-session authentication failures?
Posted: Thu Jan 21, 2010 2:43 pm
by sergejs
There is nothing to do on PPPoE server, how do you know specific PPPoE connection is good or bad?
Educate your customer and create configuration guide for PPPoE client configuration to avoid bad username/password users.
Re: Limit on frequent PPPoE-session authentication failures?
Posted: Fri Jan 22, 2010 6:20 am
by archerfish
There is nothing to do on PPPoE server, how do you know specific PPPoE connection is good or bad?
We have frequent negative PAP-results on PPPoE sessions from one MAC-address (for ex more than 20-30 in one minute). Can it be the right description?
Educate your customer and create configuration guide for PPPoE client configuration to avoid bad username/password users.
Thank you, we will.
Re: Limit on frequent PPPoE-session authentication failures?
Posted: Thu Sep 01, 2016 2:40 pm
by asy
Hello.
I think it would be a useful feature.
Educate your customer and create configuration guide for PPPoE client configuration to avoid bad username/password users.
Great idea. But it from fantastic area.
Rate limit for authentication attempts in time window per MAC address is a great variant, I think.
Regards, Sergey.
[UPD] similar requests:
http://forum.mikrotik.com/viewtopic.php?t=18593
http://forum.mikrotik.com/viewtopic.php?f=2&t=43224
Re: Limit on frequent PPPoE-session authentication failures?
Posted: Mon Jan 02, 2017 12:01 pm
by asy
Educate your customer and create configuration guide for PPPoE client configuration to avoid bad username/password users.
Sometimes user's accounts disabled for non-payment. It is a lot every begin of month usually. This causes explosive growth in the number of attempts:
89172209 Jan 2 03:15 radiator.log.1.bz2
13945926 Jan 1 03:13 radiator.log.2.bz2
6846862 Dec 31 03:13 radiator.log.3.bz2
7216602 Dec 30 03:13 radiator.log.4.bz2