Frogfoot: seeing other customers' DHCP broadcasts on my WAN port, normal?

DStvNothingOn

Expert Member
Joined
May 21, 2011
Messages
1,755
Reaction score
1,735
Location
46°38'13.5"S 37°56'25.6"E
Was messing around with logging on my MikroTik's WAN drop rule tonight and noticed ether1 (straight off the Frogfoot ONT) is picking up a constant stream of DHCP discovers (0.0.0.0:68 -> 255.255.255.255:67) from MACs that aren't mine. So presumably other people's routers on the same segment looking for DHCP, and no port isolation on my segment at least.

Firewall drops it all, just surprised it's not isolated. Checked ARP and there's nothing from foreign MACs, so it looks limited to DHCP broadcast flooding rather than full L2 visibility. Anyone else on Frogfoot seeing this? Wondering if it's area specific or just how they run their segments. Also keen to hear if the Vumatel/Openserve guys see the same or if it's a Frogfoot thing.

Getting the usual port scans from Bulgaria and China in the same log but that's every public IP ever.
 
Yeah they should isolate and enable DHCP snooping per vlan.
 
Follow-up that makes this funnier: spent part of tonight trying to get into my own ONT (Calix) to read the light levels. Web UI dead, ping dead, wouldn't even answer ARP on its own segment with an address aliased onto the WAN port. Completely dark, FNO-managed via TR-069 only, nothing exposed to the subscriber at all.

So the ONT is bulletproof against the one person who owns the line, meanwhile the PON segment happily delivers every neighbour's DHCP discovers to my WAN port. Says something about the priorities though, keep the subscriber out of their own kit but the neighbours' broadcast noise is fine.
 
Same here basically. Neighbours are cgnatted along with me. Has it's good and bad - the bad is regular robot confirmations.
 
Follow-up that makes this funnier: spent part of tonight trying to get into my own ONT (Calix) to read the light levels. Web UI dead, ping dead, wouldn't even answer ARP on its own segment with an address aliased onto the WAN port. Completely dark, FNO-managed via TR-069 only, nothing exposed to the subscriber at all.

So the ONT is bulletproof against the one person who owns the line, meanwhile the PON segment happily delivers every neighbour's DHCP discovers to my WAN port. Says something about the priorities though, keep the subscriber out of their own kit but the neighbours' broadcast noise is fine.

I mean is it really so strange considering it’s their own controlled network?

It’s not really “public” as such. It’s really just a big LAN with fancier connections.
 
Top
Sign up to the MyBroadband newsletter
X