Anda di halaman 1dari 2

DUDAS MikroTik

My pppoe server service uses default profile (at the moment I do NOT want to use defaultencryption profile). AAA server is active. In the client side, my pppoe client has user/pass and default profile. This scenario without encryption works fine. I am trying to encrypt my PPPoE Sessions using radius attributes. I want to see in Active connections, in encoding field=MPPE128 stateless. I read http://freeradius.org/rfc/rfc2548.html and search in MT database and google. I tried lot of configuration and with several radius attribute: MS-MPPE-Encryption-Policy, MSMPPE-Encryption-Types,MS-MPPE-Recv-Key, MS-MPPE-Send-Key. For example in my radreply table in freeradius, username| attribute| op | value NTV;MS-MPPE-Encryption-Policy;:=;0x00000002 NTV;MS-MPPE-Encryption-Types;:=;0x0000000e NTV;MS-MPPE-Recv-Key;:=;0x74bbb154bacd94c95e6e2e069d1b48df NTV;MS-MPPE-Send-Key;:=;0x468129c1b70123e815d71a891595a860 these values cause an error 'encryption negotiation rejected'. What are the correct values to see in encoding MPPE128 stateless? I do not use the default-encryption because I have to differentiate user types. Some of my customers have an old-fashioned device which not supports encryption. All my PPPoE users are in a RADIUS server accounts. So I can distinguish if I use or not use encryption in the RADIUS account. Can I configure theses parameters in a RADIUS account?

I am doing the integration with Nintendo in order to all his Nintendo3DS can authenticate in my MikroTik hotspots. The new Nintendo 3DS firmware implements a WISPr client to connect to Internet. However, it fails. Nintendo people and we analyze the problem and we realize that Mikrotik access points sends a 200 OK response before sending the 302 with WISPr spec. Because it sends the 200 OK, the device thinks that it has an open connection to the internet and does not proceed with the

login process. We verify this with a wireless packet capture (attached .pcap files). In the pcap file you can see this behavior (http 200/OK request). I would want to know if there is a solution or an updated firmware that resolves this.

I have a problem with some of my PPPoE servers. The pppoe server profile has a ip pool in the <remote address> attribute in the profile. This IP pool has several public IP's. It happens the PPPoE server works fine until the ip pool is run out. I check the PPP active connections and the number of registers is lower than the number of IP's in the ip pool. I know a MAC (pppoe client) has two ip's. May be it is a bug? My main problem is I cannot release the ip's assigned by a pppoe server. Is there any method to achieve?

1. Funcionamiento y valores de MTU/MRU en encapsulaciones de tneles L2TP(EoIP(PPPoE))) 2. Limitacin del ancho de banda de PPPoE causado por un valor bajo en el buffer de paquetes del sistema de colas. Es normal? 3. PPPoE Relay vs Filtrado en bridges.

Anda mungkin juga menyukai