Example: Configuring IPoE and PPPoE Subscribers on the Same Access Interface with Routing Services Support
This example describes how to support both IPoE and PPPoE subscribers on the same access interface when routing services are enabled for PPPoE subscribers.
Overview
You can enable support for both IPoE and PPPoE subscribers on the same access interface while using routing services for PPPoE subscriber sessions. In such deployments, auto-sensed VLANs automatically detect subscriber VLANs and create the corresponding subscriber interfaces when subscriber traffic is received on the access interface.
When you enable routing services for PPPoE subscribers, you must not include
family inet or family inet6 configuration in the
underlying dynamic VLAN profile. To support both IPoE and PPPoE subscribers on the same
access interface, configure separate dynamic VLAN profiles:
- A PPPoE VLAN profile that contains
routing-servicesconfiguration and only familypppoe - An IPoE VLAN profile that contains
family inetandfamily inet6configuration and does not containrouting-servicesconfiguration
When subscriber traffic arrives on an auto-sensed VLAN, the system creates a subscriber
VLAN interface by using the configured default VLAN profile. In this example, the
dvlan-pppoe profile serves as the default profile. IPoE subscribers
are then assigned to the dvlan-ipoe profile through domain-based
profile selection. With this configuration, PPPoE subscribers use the PPPoE VLAN profile
and receive routing-services support, while IPoE subscribers use the IPoE VLAN profile
and operate without routing services.
Before You Begin
This example uses PPPoE dynamic profiles, subscriber access profiles, domain-based profile assignment, auto-sensed VLANs, and DHCP subscriber access. For information about these features and the associated configuration procedures, review the following guides:
Configuration
Follow these steps to support IPoE and PPPoE subscribers on the same access interface while enabling routing services for PPPoE subscribers:
Configure a dynamic VLAN profile for PPPoE subscribers with routing services enabled. This profile defines the VLAN subscriber interface and references the PPPoE session profile (
ppp-dp-pp0) used to create the subscriber PPPoE session.[edit] set dynamic-profiles dvlan-pppoe interfaces demux0 unit "$junos-interface-unit" no-traps set dynamic-profiles dvlan-pppoe interfaces demux0 unit "$junos-interface-unit" routing-service enable set dynamic-profiles dvlan-pppoe interfaces demux0 unit "$junos-interface-unit" proxy-arp set dynamic-profiles dvlan-pppoe interfaces demux0 unit "$junos-interface-unit" vlan-id "$junos-vlan-id" set dynamic-profiles dvlan-pppoe interfaces demux0 unit "$junos-interface-unit" demux-options underlying-interface "$junos-underlying-interface" set dynamic-profiles dvlan-pppoe interfaces demux0 unit "$junos-interface-unit" family pppoe duplicate-protection set dynamic-profiles dvlan-pppoe interfaces demux0 unit "$junos-interface-unit" family pppoe dynamic-profile ppp-dp-pp0
Note: Do not configurefamily inetorfamily inet6statements in a dynamic VLAN profile that containsrouting-service enable.Configure a separate dynamic VLAN profile for IPoE subscribers. This profile defines the VLAN subscriber interface for IPoE sessions and includes
family inetandfamily inet6configuration. Unlike the PPPoE VLAN profile, this profile does not enable routing services.[edit] set dynamic-profiles dvlan-ipoe interfaces demux0 unit "$junos-interface-unit" no-traps set dynamic-profiles dvlan-ipoe interfaces demux0 unit "$junos-interface-unit" proxy-arp set dynamic-profiles dvlan-ipoe interfaces demux0 unit "$junos-interface-unit" vlan-id "$junos-vlan-id" set dynamic-profiles dvlan-ipoe interfaces demux0 unit "$junos-interface-unit" demux-options underlying-interface "$junos-underlying-interface" set dynamic-profiles dvlan-ipoe interfaces demux0 unit "$junos-interface-unit" family inet demux-source $junos-subscriber-ip-address set dynamic-profiles dvlan-ipoe interfaces demux0 unit "$junos-interface-unit" family inet unnumbered-address lo0.0 set dynamic-profiles dvlan-ipoe interfaces demux0 unit "$junos-interface-unit" family inet6 demux-source $junos-subscriber-ipv6-address set dynamic-profiles dvlan-ipoe interfaces demux0 unit "$junos-interface-unit" family inet6 unnumbered-address lo0.0
Configure an access profile with local authentication. This profile enables local subscriber authentication and is later applied to the auto-sensed VLAN configuration to process subscriber authentication requests.
[edit] set access profile ipoe authentication-order none
Configure a domain map entry that assigns IPoE subscribers to the IPoE VLAN profile. The domain map identifies subscribers based on their domain name and overrides the default VLAN profile assignment.
[edit] set access domain map ipoeuser.net dynamic-profile dvlan-ipoe
In this example, subscribers identified with the domain
ipoeuser.netare assigned thedvlan-ipoeprofile, overriding the defaultdvlan-pppoeprofile assignment.Configure auto-sensed VLANs and assign the PPPoE VLAN profile as the default profile. This configuration enables automatic VLAN creation on the access interface and uses
dvlan-pppoeas the default profile for newly discovered VLANs. DHCPv4 and DHCPv6 packets trigger subscriber authentication, allowing the domain map to assign IPoE subscribers to thedvlan-ipoeprofile.[edit] set interfaces ge-0/0/1 flexible-vlan-tagging set interfaces ge-0/0/1 auto-configure vlan-ranges dynamic-profile dvlan-pppoe accept any set interfaces ge-0/0/1 auto-configure vlan-ranges dynamic-profile dvlan-pppoe ranges any set interfaces ge-0/0/1 auto-configure vlan-ranges authentication packet-types dhcp-v4 set interfaces ge-0/0/1 auto-configure vlan-ranges authentication packet-types dhcp-v6 set interfaces ge-0/0/1 auto-configure vlan-ranges authentication username-include domain-name ipoeuser.net set interfaces ge-0/0/1 auto-configure vlan-ranges authentication username-include user-prefix user set interfaces ge-0/0/1 auto-configure vlan-ranges access-profile ipoe set interfaces ge-0/0/1 auto-configure remove-when-no-subscribers
Configure DHCP local server support for IPoE subscriber sessions. This configuration enables DHCP local server processing for IPoE subscribers and works with the access profile and domain map configuration to identify IPoE subscribers and assign the appropriate subscriber profile.
[edit] set system services dhcp-local-server traceoptions flag all set system services dhcp-local-server dhcpv6 group dhcpv6 authentication password vmxpswd set system services dhcp-local-server dhcpv6 group dhcpv6 authentication username-include user-prefix user set system services dhcp-local-server dhcpv6 group dhcpv6 interface demux0.0 set system services dhcp-local-server dynamic-profile client-dhcp-demux set system services dhcp-local-server group v4-grp authentication password vmxpswd set system services dhcp-local-server group v4-grp authentication username-include user-prefix user set system services dhcp-local-server group v4-grp interface demux0.0 set system services dhcp-local-server group v4-grp reauthenticate lease-renewal
This configuration restricts subscriber authorization triggers to DHCPv4 and DHCPv6 packets. PPPoE discovery packets do not participate in the local authorization workflow used to identify and assign IPoE subscribers to the
dvlan-ipoeprofile.
Verification
After completing the configuration:
- PPPoE subscribers are instantiated using the
dvlan-pppoeprofile and receive routing services support. - IPoE subscribers are instantiated using the
dvlan-ipoeprofile through domain-based profile selection. - Both subscriber types are supported concurrently on the same access interface.
Subscriber Verification
Verify that the PPPoE and IPoE subscribers are created successfully.
user@host> show subscribers Interface IP Address/VLAN ID User Name LS:RI demux0.3221225472 100 default:default pp0.3221225473 10.0.0.2 testuser default:default * 2001:db8:2222::100 demux0.3221225474 101 test_dhcp@ipoeuser.net default:default demux0.3221225475 10.0.0.3 test_dhcp default:default
In this output, the PPPoE subscriber session is established on VLAN 100 and the IPoE subscriber session is established on VLAN 101. The output also confirms that both subscriber types are active simultaneously on the same access interface.
VLAN Profile Verification
Verify that Junos OS assigns the correct dynamic VLAN profile to each subscriber type.
user@host> show subscribers detail Type: VLAN Logical System: default Routing Instance: default Interface: demux0.3221225472 Interface type: Dynamic Underlying Interface: ge-0/0/1 Dynamic Profile Name: dvlan-pppoe State: Active Session ID: 1 PFE Flow ID: 50 VLAN Id: 100 Login Time: 2026-08-12 11:30:39 IST Type: PPPoE User Name: testuser IP Address: 10.0.0.2 IP Netmask: 255.255.255.255 IPv6 Address: 2001:db8:2222::100 Logical System: default Routing Instance: default Interface: pp0.3221225473 Interface type: Dynamic Underlying Interface: demux0.3221225472 Dynamic Profile Name: ppp-dp-pp0 MAC Address: 00:10:94:00:00:02 State: Active Radius Accounting ID: 2 Session ID: 2 PFE Flow ID: 52 VLAN Id: 100 Login Time: 2026-08-12 11:30:39 IST Type: VLAN User Name: test_dhcp@ipoeuser.net Logical System: default Routing Instance: default Interface: demux0.3221225474 Interface type: Dynamic Underlying Interface: ge-0/0/1 Dynamic Profile Name: dvlan-ipoe State: Active Radius Accounting ID: 3 Session ID: 3 PFE Flow ID: 54 VLAN Id: 101 Login Time: 2026-08-12 11:32:11 IST Type: DHCP User Name: test_dhcp IP Address: 10.0.0.3 IP Netmask: 255.0.0.0 Logical System: default Routing Instance: default Interface: demux0.3221225475 Interface type: Dynamic Interface Set: test1 Underlying Interface: demux0.3221225474 Dynamic Profile Name: client-dhcp-demux MAC Address: 00:10:94:00:00:03 State: Active Radius Accounting ID: 4 Session ID: 4 PFE Flow ID: 56 VLAN Id: 101 Login Time: 2026-08-12 11:32:12 IST DHCP Options: len 41 35 01 01 39 02 02 40 3d 07 01 00 10 94 00 00 03 33 04 00 00 00 3c 0c 0a 62 61 6c 61 6d 5f 64 68 63 70 37 05 01 06 0f 21 2c DHCP Header: len 44 01 01 06 00 00 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 94 00 00 03 00 00 00 00 00 00 00 00 00 00
In this output, the VLAN subscriber interface on VLAN 100 is
instantiated by using the dvlan-pppoe dynamic VLAN profile,
and the corresponding PPPoE session is created by using the
ppp-dp-pp0 PPPoE session profile. The VLAN subscriber
interface on VLAN 101 is instantiated by using the
dvlan-ipoe dynamic VLAN profile through domain-based
profile selection, and the associated DHCP subscriber session is created
successfully. This confirms that Junos assigns the correct dynamic VLAN profile
to each subscriber type and supports both PPPoE and IPoE subscribers on the
same access interface.
Interface Verification
Verify that routing services are enabled for the PPPoE subscriber session.
user@host> show interfaces pp0.3221225473
Logical interface pp0.3221225473 (Index 536870964) (SNMP ifIndex 200000052)
Flags: Up Point-To-Point Encapsulation: PPPoE
PPPoE:
State: SessionUp, Session ID: 1,
Session AC name: vmx, Remote MAC address: 00:10:94:00:00:02,
Underlying interface: demux0.3221225472 (Index 536870962)
Ignore End-Of-List tag: Disable
Input packets : 0
Output packets: 0
LCP state: Opened
NCP state: inet: Opened, inet6: Not-configured, iso: Not-configured, mpls: Not-configured
CHAP state: Closed
PAP state: Success
Protocol inet, MTU: 1492
Max nh cache: 0, New hold nh limit: 0, Curr nh cnt: 0, Curr new hold cnt: 0, NH drop cnt: 0
Flags: None
Addresses, Flags: Is-Primary
Local: 172.16.0.1
Logical interface pp0.3221225473 (Index 388) (SNMP ifIndex 607)
Flags: Up Point-To-Point 0x4000 Encapsulation: PPPoE
PPPoE:
State: SessionUp, Session ID: 1,
Session AC name: None, Remote MAC address: 00:10:94:00:00:02,
Underlying interface: demux0.3221225472 (Index 387)
Ignore End-Of-List tag: Disable
PPP-Max-Payload tag: 1492
Bandwidth: 1Gbps
Input packets : 0
Output packets: 0
Keepalive settings: Interval 10 seconds, Up-count 1, Down-count 3
LCP state: Down
NCP state: inet: Opened, inet6: Opened, iso: Not-configured, mpls: Not-configured
CHAP state: Success
PAP state: Closed
Protocol inet, MTU: 1492
Max nh cache: 0, New hold nh limit: 0, Curr nh cnt: 0, Curr new hold cnt: 0, NH drop cnt: 0
Flags: None
Addresses, Flags: Is-Primary
Local: 16.0.0.1
Protocol inet6, MTU: 1492
Max nh cache: 0, New hold nh limit: 0, Curr nh cnt: 0, Curr new hold cnt: 0, NH drop cnt: 0
Flags: None
Addresses
Local: 2001:db8:5603::2ff:fe00:85f5
INET6 Address Flags: NoneIn this output, two logical instances of pp0.3221225473 are
displayed. The second logical interface is the portal interface created when routing
services are enabled for the PPPoE subscriber. The presence of this additional
logical interface confirms that routing services are active for the PPPoE subscriber
session.