[RP-PPPoE] PADT Flood?
Christian Costa
christian at eol.co.nz
Sun Aug 15 17:11:19 EDT 2010
Hi there,
We run a PPPoE server that has an average of 800-900 clients connected
to it.
It seems that every so often lots of clients are dropped off and I find
the following in the log files:
Aug 16 08:20:44 apollo pppoe-server[16156]: PADT for session 2935
received from 00:25:9C:0D:20:F1; should be from 00:16:B6:8F:34:73
Aug 16 08:20:44 apollo pppoe-server[16156]: PADT for session 2185
received from 00:25:9C:0B:8F:9F; should be from 00:19:CB:F9:7B:7B
Aug 16 08:20:44 apollo pppoe-server[16156]: PADT for session 221
received from 00:25:9C:0D:20:F1; should be from 00:15:6D:DC:27:8D
...
By analyzing it further I found out that 8 different devices seem to be
causing it. I say causing it because that's where the packets come from.
It seems 8 devices are flooding the server with PADT messages for all
the other MAC addresses on the network.
Has anyone one come across something like that before? I did lots of
research but couldn't find anything about it other than the same question.
Any help would be appreciated.
Kind regards,
Christian
More information about the RP-PPPoE
mailing list