[RP-PPPoE] PADT Flood?

Christian Costa christian at eol.co.nz
Sun Aug 15 17:11:19 EDT 2010


  Hi there,

We run a PPPoE server that has an average of 800-900 clients connected 
to it.
It seems that every so often lots of clients are dropped off and I find 
the following in the log files:



Aug 16 08:20:44 apollo pppoe-server[16156]: PADT for session 2935 
received from 00:25:9C:0D:20:F1; should be from 00:16:B6:8F:34:73
Aug 16 08:20:44 apollo pppoe-server[16156]: PADT for session 2185 
received from 00:25:9C:0B:8F:9F; should be from 00:19:CB:F9:7B:7B
Aug 16 08:20:44 apollo pppoe-server[16156]: PADT for session 221 
received from 00:25:9C:0D:20:F1; should be from 00:15:6D:DC:27:8D
...

By analyzing it further I found out that 8 different devices seem to be 
causing it. I say causing it because that's where the packets come from. 
It seems 8 devices are flooding the server with PADT messages for all 
the other MAC addresses on the network.
Has anyone one come across something like that before? I did lots of 
research but couldn't find anything about it other than the same question.
Any help would be appreciated.

Kind regards,

Christian





More information about the RP-PPPoE mailing list