Raisecom
ISCOM2600G-HI (A) Series Configuration Guide
10 Security
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
447
Step
Command
Description
2
Raisecom(config)#pppoeagent enable
Enable global PPPoE+.
3
Raisecom(config)#interface
interface-type interface-number
Enter physical layer interface
configuration mode.
4
Raisecom(config-
gigaethernet1/1/1)#pppoeagent
enable
Enable interface PPPoE+.
Configuring PPPoE trusted interface
The PPPoE trusted interface can be used to prevent PPPoE server from being cheated and
avoid security problems because PPPoE packets are forwarded to other non-service interfaces.
Generally, the interface connected to the PPPoE server is configured to the trusted interface.
PPPoE packets from the PPPoE client to the PPPoE server are forwarded by the trusted
interface only. In addition, only PPPoE received from the trusted interface can be forwarded
to the PPPoE client.
Configure the PPPoE trusted interface for the ISCOM2600G-HI series switch as below.
Step
Command
Description
1
Raisecom#config
Enter global configuration mode.
2
Raisecom(config)#interface
interface-type interface-number
Enter physical layer interface
configuration mode.
3
Raisecom(config-
gigaethernet1/1/1)#pppoeagent
trust
Configure the PPPoE trusted
interface.
Because PPPoE+ is designed for the PPPoE client instead of the PPPoE server,
downlink interfaces of the device cannot receive the PADO and PADS packets. It
means that interfaces, where PPPoE+ is enabled, should not receive PADO and
PADS packet. If there interfaces receive these packets, it indicates that there are
error packets and the packets should be discarded. However, these interfaces can
forward PADO and PADS packets of trusted packet. In addition, PADI and PADR
packets are forwarded to the trusted interface only.
10.9.5 Configuring PPPoE+ packet information
PPPoE is used to process a specified Tag in PPPoE packets. This Tag contains Circuit ID and
Remote ID.
Circuit ID: is padded with the VLAN ID, interface number, and host name of request
packets at the RX client.
Remote ID: is padded with the MAC address of the client or the switch.