EMZETT.
Login

PPP

In short: Point-to-Point Protocol — a protocol for establishing a direct connection between two network nodes, classically used for dial-up connections (DSL, ISDN).

In more detail: PPP takes care of connection setup, authentication (e.g. via PAP/CHAP) and packaging IP packets for transmission over the physical line. Today mostly used as PPPoE (PPP over Ethernet) in DSL routers.

In Depth

PPP emerged in the early 1990s as the successor to the older SLIP protocol and was for a long time THE standard protocol for dial-up connections via analogue modems and later ISDN. It takes on several tasks at once: connection setup and configuration (which network parameters are used), authentication of the dialling-in user (via PAP — password in plain text — or the more secure CHAP with a challenge-response procedure) and the actual encapsulation of IP packets for serial transmission over the physical line.

In modern DSL connections, PPP mostly runs as PPPoE (PPP over Ethernet) — although the physical connection has long run over Ethernet technology, the classic PPP protocol is “tunnelled” over it, mainly because internet providers can continue to handle user-based authentication (credentials for the internet connection) and billing through it — a legacy of the dial-up era that has survived technically to this day.

PAP versus CHAP

The two classic PPP authentication methods differ significantly in their security: PAP (Password Authentication Protocol) transmits the user name and password in plain text over the line — considered insecure today, but still partly supported for compatibility reasons. CHAP (Challenge Handshake Authentication Protocol) never sends the password itself over the line: the server sends a random “challenge”, the client uses its password to calculate a hash value from it and only sends this back — the server also knows the password and can calculate the expected hash value itself to compare. An eavesdropper on the line thus never sees the actual password, only a calculation derived from it that’s valid for this one session.

Why PPPoE has survived to this day

From a purely technical point of view, PPPoE would no longer be strictly necessary for most modern fibre and cable connections — Ethernet alone is enough to transport data packets. The real reason it persists is commercial: internet providers use PPP authentication to assign each customer connection a unique, individual public IP address and to manage credentials per contract, without having to introduce more elaborate alternatives such as 802.1X. That’s why routers still have to know the PPPoE credentials provided by the provider in order to be able to dial into the internet at all.

See also: Authentication