Example: Configuring IPoE and PPPoE Subscribers on the Same Access Interface with Routing Services Support

This example describes how to support both IPoE and PPPoE subscribers on the same access interface when routing services are enabled for PPPoE subscribers.

Overview

You can enable support for both IPoE and PPPoE subscribers on the same access interface while using routing services for PPPoE subscriber sessions. In such deployments, auto-sensed VLANs automatically detect subscriber VLANs and create the corresponding subscriber interfaces when subscriber traffic is received on the access interface.

When you enable routing services for PPPoE subscribers, you must not include family inet or family inet6 configuration in the underlying dynamic VLAN profile. To support both IPoE and PPPoE subscribers on the same access interface, configure separate dynamic VLAN profiles:

  • A PPPoE VLAN profile that contains routing-services configuration and only family pppoe
  • An IPoE VLAN profile that contains family inet and family inet6 configuration and does not contain routing-services configuration

When subscriber traffic arrives on an auto-sensed VLAN, the system creates a subscriber VLAN interface by using the configured default VLAN profile. In this example, the dvlan-pppoe profile serves as the default profile. IPoE subscribers are then assigned to the dvlan-ipoe profile through domain-based profile selection. With this configuration, PPPoE subscribers use the PPPoE VLAN profile and receive routing-services support, while IPoE subscribers use the IPoE VLAN profile and operate without routing services.

Before You Begin

This example uses PPPoE dynamic profiles, subscriber access profiles, domain-based profile assignment, auto-sensed VLANs, and DHCP subscriber access. For information about these features and the associated configuration procedures, review the following guides:

Configuration

Follow these steps to support IPoE and PPPoE subscribers on the same access interface while enabling routing services for PPPoE subscribers:

  1. Configure a dynamic VLAN profile for PPPoE subscribers with routing services enabled. This profile defines the VLAN subscriber interface and references the PPPoE session profile (ppp-dp-pp0) used to create the subscriber PPPoE session.

    Note: Do not configure family inet or family inet6 statements in a dynamic VLAN profile that contains routing-service enable.
  2. Configure a separate dynamic VLAN profile for IPoE subscribers. This profile defines the VLAN subscriber interface for IPoE sessions and includes family inet and family inet6 configuration. Unlike the PPPoE VLAN profile, this profile does not enable routing services.

  3. Configure an access profile with local authentication. This profile enables local subscriber authentication and is later applied to the auto-sensed VLAN configuration to process subscriber authentication requests.

  4. Configure a domain map entry that assigns IPoE subscribers to the IPoE VLAN profile. The domain map identifies subscribers based on their domain name and overrides the default VLAN profile assignment.

    In this example, subscribers identified with the domain ipoeuser.net are assigned the dvlan-ipoe profile, overriding the default dvlan-pppoe profile assignment.

  5. Configure auto-sensed VLANs and assign the PPPoE VLAN profile as the default profile. This configuration enables automatic VLAN creation on the access interface and uses dvlan-pppoe as the default profile for newly discovered VLANs. DHCPv4 and DHCPv6 packets trigger subscriber authentication, allowing the domain map to assign IPoE subscribers to the dvlan-ipoe profile.

  6. Configure DHCP local server support for IPoE subscriber sessions. This configuration enables DHCP local server processing for IPoE subscribers and works with the access profile and domain map configuration to identify IPoE subscribers and assign the appropriate subscriber profile.

    This configuration restricts subscriber authorization triggers to DHCPv4 and DHCPv6 packets. PPPoE discovery packets do not participate in the local authorization workflow used to identify and assign IPoE subscribers to the dvlan-ipoe profile.

Verification

After completing the configuration:

  • PPPoE subscribers are instantiated using the dvlan-pppoe profile and receive routing services support.
  • IPoE subscribers are instantiated using the dvlan-ipoe profile through domain-based profile selection.
  • Both subscriber types are supported concurrently on the same access interface.

Subscriber Verification

Verify that the PPPoE and IPoE subscribers are created successfully.

In this output, the PPPoE subscriber session is established on VLAN 100 and the IPoE subscriber session is established on VLAN 101. The output also confirms that both subscriber types are active simultaneously on the same access interface.

VLAN Profile Verification

Verify that Junos OS assigns the correct dynamic VLAN profile to each subscriber type.

In this output, the VLAN subscriber interface on VLAN 100 is instantiated by using the dvlan-pppoe dynamic VLAN profile, and the corresponding PPPoE session is created by using the ppp-dp-pp0 PPPoE session profile. The VLAN subscriber interface on VLAN 101 is instantiated by using the dvlan-ipoe dynamic VLAN profile through domain-based profile selection, and the associated DHCP subscriber session is created successfully. This confirms that Junos assigns the correct dynamic VLAN profile to each subscriber type and supports both PPPoE and IPoE subscribers on the same access interface.

Interface Verification

Verify that routing services are enabled for the PPPoE subscriber session.

In this output, two logical instances of pp0.3221225473 are displayed. The second logical interface is the portal interface created when routing services are enabled for the PPPoE subscriber. The presence of this additional logical interface confirms that routing services are active for the PPPoE subscriber session.