Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Ignoring DSL Forum VSAs from Directly Connected Devices

When CPE devices are directly connected to a BNG, you may want the router to ignore any DSL Forum VSAs that it receives in PPPoE control packets because the VSAs can be spoofed by malicious subscribers. Spoofing is particularly serious when the targeted VSAs are used to authenticate the subscriber, such as Agent-Circuit-Id [26-1] and Agent-Remote-ID [26-2]. You can include the direct-connect statement to ignore DSL Forum VSAs on static or dynamic PPPoE interfaces or PPPoE underlying interfaces.

To configure the router to ignore DSL Forum VSAs on specific PPPoE interfaces:

  1. Specify that you want to configure PPPoE-specific options on the interface:
    • For a PPPoE family in a dynamic profile for a VLAN demultiplexing (demux) logical interface:

    • For a PPPoE family in a dynamic profile:

    • For a PPPoE underlying interface in a dynamic profile:

    • For a PPPoE family on an underlying interface:

    • For an underlying interface with PPPoE encapsulation:

  2. Specify that the router ignores DSL forum VSAs received on a specific interface.

    or