1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
|
:lastproofread: 2022-09-17
.. _pppoe-server:
############
PPPoE Server
############
VyOS utilizes `accel-ppp`_ to provide PPPoE server functionality. It can
be used with local authentication or a connected RADIUS server.
.. note:: Please be aware, due to an upstream bug, config
changes/commits will restart the ppp daemon and will reset existing
PPPoE connections from connected users, in order to become effective.
Configuration
=============
First steps
-----------
.. cfgcmd:: set service pppoe-server access-concentrator <name>
Use this command to set a name for this PPPoE-server access
concentrator.
.. cfgcmd:: set service pppoe-server authentication mode <local | radius>
Use this command to define whether your PPPoE clients will locally
authenticate in your VyOS system or in RADIUS server.
.. cfgcmd:: set service pppoe-server authentication local-users username
<name> password <password>
Use this command to configure the username and the password of a
locally configured user.
.. cfgcmd:: set service pppoe-server interface <interface>
Use this command to define the interface the PPPoE server will use to
listen for PPPoE clients.
.. cfgcmd:: set service pppoe-server gateway-address <address>
Use this command to configure the local gateway IP address.
.. cfgcmd:: set service pppoe-server name-server <address>
Use this command to set the IPv4 or IPv6 address of every Doman Name
Server you want to configure. They will be propagated to PPPoE
clients.
Client Address Pools
--------------------
To automatically assign the client an IP address as tunnel endpoint, a
client IP pool is needed. The source can be either RADIUS or a
named pool. There is possibility to create multiple named pools.
Each named pool can include only one address range. To use multiple
address ranges configure ``next-pool`` option.
**Client IP address via IP range definition**
.. cfgcmd:: set service pppoe-server client-ip-pool <POOL-NAME> range <x.x.x.x-x.x.x.x | x.x.x.x/x>
Use this command to define the IP address range to be given
to PPPoE clients. If notation ``x.x.x.x-x.x.x.x``,
it must be within a /24 subnet. If notation ``x.x.x.x/x`` is
used there is possibility to set host/netmask.
.. cfgcmd:: set service pppoe-server client-ip-pool <POOL-NAME> next-pool <NEXT-POOL-NAME>
Use this command to define the next address pool name.
.. cfgcmd:: set service pppoe-server default-pool <POOL-NAME>
Use this command to define default address pool name.
.. code-block:: none
set service pppoe-server client-ip-pool IP-POOL next-pool 'IP-POOL2'
set service pppoe-server client-ip-pool IP-POOL range '10.0.10.5/24'
set service pppoe-server client-ip-pool IP-POOL2 range '10.0.0.10-10.0.0.12'
set service pppoe-server default-pool 'IP-POOL'
**RADIUS based IP pools (Framed-IP-Address)**
To use a radius server, you need to switch to authentication mode RADIUS
and then configure it.
.. cfgcmd:: set service pppoe-server authentication radius server <address>
key <secret>
Use this command to configure the IP address and the shared secret
key of your RADIUS server. You can have multiple RADIUS servers
configured if you wish to achieve redundancy.
.. code-block:: none
set service pppoe-server access-concentrator 'ACN'
set service pppoe-server authentication mode 'radius'
set service pppoe-server authentication radius server 10.1.100.1 key 'secret'
set service pppoe-server interface 'eth1'
set service pppoe-server gateway-address '10.1.1.2'
RADIUS provides the IP addresses in the example above via
Framed-IP-Address.
**RADIUS sessions management DM/CoA**
.. cfgcmd:: set service pppoe-server authentication radius dynamic-author
<key | port | server>
Use this command to configure Dynamic Authorization Extensions to
RADIUS so that you can remotely disconnect sessions and change some
authentication parameters.
.. code-block:: none
set service pppoe-server authentication radius dynamic-author key 'secret123'
set service pppoe-server authentication radius dynamic-author port '3799'
set service pppoe-server authentication radius dynamic-author server '10.1.1.2'
Example, from radius-server send command for disconnect client with
username test
.. code-block:: none
root@radius-server:~# echo "User-Name=test" | radclient -x 10.1.1.2:3799
disconnect secret123
You can also use another attributes for identify client for disconnect,
like Framed-IP-Address, Acct-Session-Id, etc. Result commands appears in
log.
.. code-block:: none
show log | match Disconnect*
Example for changing rate-limit via RADIUS CoA.
.. code-block:: none
echo "User-Name=test,Filter-Id=5000/4000" | radclient 10.1.1.2:3799 coa
secret123
Filter-Id=5000/4000 (means 5000Kbit down-stream rate and 4000Kbit
up-stream rate) If attribute Filter-Id redefined, replace it in RADIUS
CoA request.
Automatic VLAN Creation
-----------------------
.. cfgcmd:: set service pppoe-server interface <interface> vlan <id | range>
VLAN's can be created by Accel-ppp on the fly via the use of a Kernel module
named `vlan_mon`, which is monitoring incoming vlans and creates the
necessary VLAN if required and allowed. VyOS supports the use of either
VLAN ID's or entire ranges, both values can be defined at the same time for
an interface.
When configured, PPPoE will create the necessary VLANs when required. Once
the user session has been cancelled and the VLAN is not needed anymore, VyOS
will remove it again.
.. code-block:: none
set service pppoe-server interface eth3 vlan 100
set service pppoe-server interface eth3 vlan 200
set service pppoe-server interface eth3 vlan 500-1000
set service pppoe-server interface eth3 vlan 2000-3000
Bandwidth Shaping
-----------------
Bandwidth rate limits can be set for local users or RADIUS based
attributes.
For Local Users
^^^^^^^^^^^^^^^
.. cfgcmd:: set service pppoe-server authentication local-users username <name>
rate-limit <download | upload>
Use this command to configure a data-rate limit to PPPOoE clients for
traffic download or upload. The rate-limit is set in kbit/sec.
.. code-block:: none
set service pppoe-server access-concentrator 'ACN'
set service pppoe-server authentication local-users username foo password 'bar'
set service pppoe-server authentication local-users username foo rate-limit download '20480'
set service pppoe-server authentication local-users username foo rate-limit upload '10240'
set service pppoe-server authentication mode 'local'
set service pppoe-server client-ip-pool IP-POOL range '10.1.1.100/24'
set service pppoe-server default-pool 'IP-POOL'
set service pppoe-server name-server '10.100.100.1'
set service pppoe-server name-server '10.100.200.1'
set service pppoe-server interface 'eth1'
set service pppoe-server gateway-address '10.1.1.2'
Once the user is connected, the user session is using the set limits and
can be displayed via 'show pppoe-server sessions'.
.. code-block:: none
show pppoe-server sessions
ifname | username | ip | calling-sid | rate-limit | state | uptime | rx-bytes | tx-bytes
-------+----------+------------+-------------------+-------------+--------+----------+----------+----------
ppp0 | foo | 10.1.1.100 | 00:53:00:ba:db:15 | 20480/10240 | active | 00:00:11 | 214 B | 76 B
For RADIUS users
^^^^^^^^^^^^^^^^
The current attribute 'Filter-Id' is being used as default and can be
setup within RADIUS:
Filter-Id=2000/3000 (means 2000Kbit down-stream rate and 3000Kbit
up-stream rate)
The command below enables it, assuming the RADIUS connection has been
setup and is working.
.. cfgcmd:: set service pppoe-server authentication radius rate-limit enable
Use this command to enable bandwidth shaping via RADIUS.
Other attributes can be used, but they have to be in one of the
dictionaries in */usr/share/accel-ppp/radius*.
Load Balancing
--------------
.. cfgcmd:: set service pppoe-server pado-delay <number-of-ms>
sessions <number-of-sessions>
Use this command to enable the delay of PADO (PPPoE Active Discovery
Offer) packets, which can be used as a session balancing mechanism
with other PPPoE servers.
.. code-block:: none
set service pppoe-server pado-delay 50 sessions '500'
set service pppoe-server pado-delay 100 sessions '1000'
set service pppoe-server pado-delay 300 sessions '3000'
In the example above, the first 499 sessions connect without delay. PADO
packets will be delayed 50 ms for connection from 500 to 999, this trick
allows other PPPoE servers send PADO faster and clients will connect to
other servers. Last command says that this PPPoE server can serve only
3000 clients.
IPv6
----
IPv6 client's prefix
^^^^^^^^^^^^^^^^^^^^
.. cfgcmd:: set service pppoe-server client-ipv6-pool <IPv6-POOL-NAME>
prefix <address> mask <number-of-bits>
Use this comand to set the IPv6 address pool from which a PPPoE
client will get an IPv6 prefix of your defined length (mask) to
terminate the PPPoE endpoint at their side. The mask length can be
set from 48 to 128 bit long, the default value is 64.
IPv6 Prefix Delegation
^^^^^^^^^^^^^^^^^^^^^^
.. cfgcmd:: set service pppoe-server client-ipv6-pool <IPv6-POOL-NAME>
delegate <address> delegation-prefix <number-of-bits>
Use this command to configure DHCPv6 Prefix Delegation (RFC3633). You
will have to set your IPv6 pool and the length of the delegation
prefix. From the defined IPv6 pool you will be handing out networks
of the defined length (delegation-prefix). The length of the
delegation prefix can be set from 32 to 64 bit long.
IPv6 default client's pool assignment
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
.. cfgcmd:: set service pppoe-server default-ipv6-pool <POOL-NAME>
Use this command to define default IPv6 address pool name.
Maintenance mode
================
.. opcmd:: set pppoe-server maintenance-mode <enable | disable>
For network maintenance, it's a good idea to direct users to a backup
server so that the primary server can be safely taken out of service.
It's possible to switch your PPPoE server to maintenance mode where
it maintains already established connections, but refuses new
connection attempts.
Checking connections
====================
.. opcmd:: show pppoe-server sessions
Use this command to locally check the active sessions in the PPPoE
server.
.. code-block:: none
show pppoe-server sessions
ifname | username | ip | calling-sid | rate-limit | state | uptime | rx-bytes | tx-bytes
-------+----------+------------+-------------------+-------------+--------+----------+----------+----------
ppp0 | foo | 10.1.1.100 | 00:53:00:ba:db:15 | 20480/10240 | active | 00:00:11 | 214 B | 76 B
Per default the user session is being replaced if a second
authentication request succeeds. Such session requests can be either
denied or allowed entirely, which would allow multiple sessions for a
user in the latter case. If it is denied, the second session is being
rejected even if the authentication succeeds, the user has to terminate
its first session and can then authentication again.
.. code-block:: none
vyos@# set service pppoe-server session-control
Possible completions:
disable Disables session control
deny Deny second session authorization
Examples
========
IPv4
----
The example below uses ACN as access-concentrator name, assigns an
address from the pool 10.1.1.100-111, terminates at the local endpoint
10.1.1.1 and serves requests only on eth1.
.. code-block:: none
set service pppoe-server access-concentrator 'ACN'
set service pppoe-server authentication local-users username foo password 'bar'
set service pppoe-server authentication mode 'local'
set service pppoe-server client-ip-pool IP-POOL range '10.1.1.100-10.1.1.111'
set service pppoe-server default-pool 'IP-POOL'
set service pppoe-server interface eth1
set service pppoe-server gateway-address '10.1.1.2'
set service pppoe-server name-server '10.100.100.1'
set service pppoe-server name-server '10.100.200.1'
Dual-Stack IPv4/IPv6 provisioning with Prefix Delegation
--------------------------------------------------------
The example below covers a dual-stack configuration via pppoe-server.
.. code-block:: none
set service pppoe-server authentication local-users username test password 'test'
set service pppoe-server authentication mode 'local'
set service pppoe-server client-ip-pool IP-POOL range '192.168.0.1/24'
set service pppoe-server default-pool 'IP-POOL'
set service pppoe-server client-ipv6-pool IPv6-POOL delegate '2001:db8:8003::/48' delegation-prefix '56'
set service pppoe-server client-ipv6-pool IPV6-POOL prefix '2001:db8:8002::/48' mask '64'
set service pppoe-server default-ipv6-pool IPv6-POOL
set service pppoe-server ppp-options ipv6 allow
set service pppoe-server name-server '10.1.1.1'
set service pppoe-server name-server '2001:db8:4860::8888'
set service pppoe-server interface 'eth2'
set service pppoe-server gateway-address '10.100.100.1'
The client, once successfully authenticated, will receive an IPv4 and an
IPv6 /64 address to terminate the pppoe endpoint on the client side and
a /56 subnet for the clients internal use.
.. code-block:: none
vyos@pppoe-server:~$ sh pppoe-server sessions
ifname | username | ip | ip6 | ip6-dp | calling-sid | rate-limit | state | uptime | rx-bytes | tx-bytes
--------+----------+-------------+--------------------------+---------------------+-------------------+------------+--------+----------+----------+----------
ppp0 | test | 192.168.0.1 | 2001:db8:8002:0:200::/64 | 2001:db8:8003::1/56 | 00:53:00:12:42:eb | | active | 00:00:49 | 875 B | 2.1 KiB
.. include:: /_include/common-references.txt
|