It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda CloudGen Firewall

This Firmware Version Is End-Of-Support

Documentation for this product is no longer updated. Please see for further information on our EoS policy.

How to Configure an ISP with xDSL using PPPoE

  • Last updated on

Point-to-Point Protocol over Ethernet (PPPoE) provides an easy solution for high-speed access services by using broadband modems. Configure an xDSL connection using PPPoE that uses the configuration parameters supplied by your ISP. PPPoE requires no special configuration to the access network. Each PPP session learns the Ethernet address of the remote peer and creates a unique session identification (ID).

In this article:

Before you Begin

Connect the Ethernet port of the ISP modem to a free port of your Barracuda NG Firewall. Depending on the modem, a standard Ethernet cable or a crossover cable must be used. Contact the ISP or vendor of the xDSL modem for more information.

Step 1. Configure Link Properties

Specify the properties for the DHCP link and define the transport protocol for PPP.

  1. Go to CONFIGURATION > Configuration Tree > Box > Network.
  2. In the left menu, select xDSL/DHCP/ISDN.
  3. Click Lock.
  4. Set xDSL Enabled to Yes.
  5. In the XDSL Links table, click + to add an entry.
  6. Enter a name for the xDSL link (no special characters) and click OK. The xDSL Links window opens.
  7. Select the Connection Type to specify the transport protocol for PPP.
  8. (optional) Enter the Static Local and Gateway IP address if your ISP does not assign it automatically.
  9. Select the Ethernet Interface the xDSL modem is attached to.

PPPoA and PPPoE and Bridged Ethernet are only useable with a legacy-integrated ADSL modem.

Step 3. Configure Authentication

Most ISPs require authentication information to connect. These configuration settings are provided by your ISP. If no authentication is required, set Authentication Method to NONE.

  1. In the Authentication section, select the Authentication Method. Default: PAP_or_CHAP
  2. Enter the User Access ID (PPP username) assigned by your ISP.
  3. If provided by your ISP, enter the User Access Sub-ID. The # and @ symbols are generated automatically.
  4. The complete user ID is formatted as follows: [user_id]#[access_sub_id]@[provider_name], e.g.,
  5. Enter the Access Password assigned by your ISP.
  6. If you want to use your ISPs DNS servers, select Use ProviderDNS.
  7. To use dynamic DNS, select Use Dynamic DNS and click Set. The Dynamic DNS Params window opens.
    1. Select a dynamic DNS Service Type. For information on DynDNS service types, see
    2. Enter the Dyn DNS Name that was registered on
    3. Enter the User Access ID and Password for accessing the service.
  8. Click OK.

Step 4. Configure Routing Settings

Configure whether to create a default route, dynamic routing, and the route metric.  

  1. Set Create Default Route to YES to automatically create a default route via this xDSL connection.
  2. If you are using dynamic routing protocols like OSPF/RIP/BGP, enable Advertise Route.
  3. Enter a Route Metric if multiple dynamic links are available. The link with the lowest route metric is automatically chosen if more than one default route is available.  

Step 5. Configure Connection Monitoring

Configure log settings and define target IP addresses that will be regularly pinged to monitor the availability of the connection. Each target IP address is pinged every 20 seconds (2 ICMP packets each). If there is no response, the link is re-established.

  1. In the Connection Monitoring section, select the Monitoring method:
    • LCP – If ping fails, the dial-in daemon is probed directly via LCP.
    • ICMP – The Barracuda NG Firewall probes the Reachable IPs and, if there is no response, the gateway.
    • StrictLCP – No ICMP probing occurs.
  2. Enter one or more Reachable IPs to monitor the availability of the connection. The target IP addresses should only be accessible via the xDSL connection.
  3. Select the Unreachable Action to be taken if the connection cannot be established. The following options are available:
    • Restart – Restarts the xDSL connection.
    • Increase-Metric – Changes the preference for xDSL routes until the probe succeeds.
  4. Click OK.
  5. Click Send Changes and Activate.

Step 6. Activate Network Changes

You must activate the network changes to bring up the xDSL connection.

  1. Go to CONTROL > Box.
  2. In the left menu, expand the Network section and click Activate new network configuration.
  3. Select Failsafe. The 'Failsafe Activation Succeeded' message is displayed after your new network configurations have been successfully activated.

Your xDSL connection is now active and the IP address assigned by your ISP is visible on the CONTROL > Network page. All status icons next to the ppp1 interface are green, indicating an active connection. If the xDSL connection is your primary Internet connection, the default route pointing to the ppp1 interface is also created. If more than one default route is present, the connection with the lowest route metric is used.

Operating a xDSL Link in Standby Mode

If required, e.g., for maintenance purposes, you can enable Standby Mode in the link configuration. In standby mode, the activation and subsequent monitoring of the link must be triggered externally. Standby mode also lets you combine HA setups for HA xDSL connections. In standby mode,

  1. The involved routes are set to pending state, and it is not checked whether they are established.
  2. The configuration is completely run through, but the connection is not yet established. 

Connecting is handled from the Command-Line Interface via a server-side script that is used for starting and stopping the connection with corresponding command lines:

  • Start all xDSL connections - /etc/phion/dynconf/network/openxdsl start &
  • Stop all xDSL connections - /etc/phion/dynconf/network/openxdsl stop & 
  • Start an explicit xDSL connection - /etc/phion/dynconf/network/openxdsl start & 
  • Stop an explicit xDSL connections - /etc/phion/dynconf/network/openxdsl stop &

is the name of the configuration entry in the xDSL Links list: 



In some cases, especially in combination with PPPoE acceleration, the segment size of the packets going into the tunnel might be too big. Set the MSS (Maximum Segment Size) to 1350 and clear DF bit to yes in the Advanced Settings tab for all access rules handling incoming and outgoing traffic for the PPPoE connection.

Last updated on