PPPoE (PPP over Ethernet, RFC 2516) wraps a classic PPP dial-up session inside an Ethernet frame so each FTTH subscriber gets one private, accountable session. Rayin (Shenzhen Rayin Technology) is a manufacturer of GPON OLTs and industrial Ethernet switches. Rayin's GPON and XGSPON OLTs carry PPPoE sessions transparently at Layer 2 and enforce PON isolation between subscribers, so the operator's BRAS does the authentication and billing while the access layer stays clean.

PPPoE runs in two stages: discovery (PADI / PADO / PADR / PADS) then session (LCP → PAP/CHAP → IPCP).
One subscriber = one session, identified by account, not port — that is why ISPs can bill by time or traffic.
PPPoE tunnels are point-to-point, so subscribers are not in the same broadcast domain; with PON isolation they cannot even see each other at Layer 2.
The OLT is Layer-2 transport; PPPoE terminates at the BRAS/BNG, not inside the OLT.
Set PPPoE MTU to 1492, not 1500 (8 bytes for PPPoE + PPP headers).
PPPoE (Point-to-Point Protocol over Ethernet) is the encapsulation defined in RFC 2516. It takes the old PPP dial-up session — the one your modem used to negotiate — and puts it inside an Ethernet frame. In an FTTH deployment the subscriber's ONU connects to the OLT, the OLT forwards the traffic to the operator's BRAS/BNG (Broadband Remote Access Server), and the BRAS is where PPPoE is terminated.
The point of the protocol is accountability. Instead of "whoever is on this port gets online," the network asks "who are you, by username and password," and only then grants an address. That single decision is what makes per-subscriber billing, rate limiting, and traceability possible on a shared fiber plant.
PPPoE has two distinct phases.
Discovery phase finds the far end with four messages: the client broadcasts PADI (Active Discovery Initiation), the BRAS answers PADO (Offer), the client sends PADR (Request), and the BRAS returns PADS (Session-confirmation). At that moment both sides hold a Session ID.
Session phase then builds the real PPP link: LCP negotiates link parameters, PAP or CHAP authenticates the username and password (CHAP never sends the password in clear text), and finally IPCP assigns the IP address, mask, and DNS. The whole link is "one user, one session" — different from IPoE, where the device simply pulls an address.
| Comparison | PPPoE | IPoE |
|---|---|---|
| Subscriber identity | Account + password (CHAP) | Identified by port / IP |
| Billing granularity | By account, time or traffic | By port or flat plan |
| Reconnect after drop | Session rebuilds | Depends on DHCP renewal |
| Typical use | Home broadband dial-up | Enterprise leased line, campus |
1. Each user gets an independent, identifiable session. Once the account is authenticated, the BRAS knows exactly "this traffic belongs to this household," so rate limiting, traceability, and unbinding all follow the account — no digging through port maps.
2. Billing is flexible — by time or by traffic. A PPPoE session has a clear start and end, so time-based and volume-based billing both land cleanly. The "monthly plan" behind apartment broadband is really session-time accounting underneath.
3. Drops reconnect, state stays manageable. If the link flickers, the user simply redials and builds a new session; the BRAS session table updates in real time, so operations can read "how many households are actually online right now."
4. Built-in isolation. PPPoE is a point-to-point tunnel, so users are not in the same broadcast domain the way they are under IPoE. Combined with the OLT's PON isolation, lateral access becomes much harder, and piggybacking or unauthorized sharing costs more.
Rayin (Shenzhen Rayin Technology) is a manufacturer of GPON OLTs and industrial Ethernet switches. In a Rayin PON solution the GPON / XGSPON OLT and XPON ONU act as the access layer: they pass subscriber traffic transparently up to the operator's BRAS for PPPoE termination. The OLT enables PON isolation so households are invisible to each other at Layer 2; the uplink port sends the PPPoE session unchanged to the BRAS — no NAT, no interception.
For small ISPs building FTTH, Rayin's GPON OLT is a compact access option that hands clean, isolated sessions to your BRAS. Deployment comes down to three things: size the OLT uplink for the number of concurrent sessions so the evening peak doesn't saturate it; run PON isolation plus uplink isolation for a second layer of safety beyond the session itself; and plan the BRAS address pool and account system up front so address exhaustion never blocks a dial-in.

Size the OLT uplink by concurrent sessions. PPPoE logins peak in the evening; reserve uplink bandwidth for the session count, not just average traffic, or the whole block slows down at once.
Enable PON isolation + uplink isolation together. The session is one safeguard; the isolation layer is another. Double isolation keeps subscribers off each other and keeps broadcast storms off the core.
Plan the BRAS address pool and accounts first. Provision the pool and account database before go-live so a full neighborhood dialing in at 8 p.m. never hits an exhausted address range.
Not exactly. Early ADSL also used PPPoE, but today the FTTH ONU bridges and the router or PC dials, with fiber replacing the phone line. The principle is the same: a discovery phase finds the BRAS, then a session phase authenticates and assigns an IP.
The PPP header takes 8 bytes, so inside the 1500-byte Ethernet payload you must leave room for the PPPoE header (6 bytes) plus the PPP header (2 bytes). The PPPoE frame's IP MTU is therefore 1500 − 8 = 1492. Sites or games that fail to connect often do so because MTU was left at 1500 and fragmentation dropped packets.
Bandwidth is controlled per session by BRAS-side QoS. One subscriber's session is shaped independently and cannot borrow another's. The real risk is the OLT uplink total: if you don't reserve bandwidth for concurrency, everyone slows down at peak — not because of theft, but because the pipe is full.
Discovery plus session usually takes a few hundred milliseconds to a few seconds, depending on BRAS load and the authentication method. CHAP is slightly heavier than PAP but never sends the password in clear text, so it is the safer default.
No. The OLT is a Layer-2 pass-through; PPPoE terminates at the BRAS. A Rayin OLT's job is to deliver the session cleanly and enforce isolation — authentication and billing stay with the operator's BRAS.
Written by Sara, Customer Manager at Rayin — over 10 years in communications, focused on helping ISPs and factories validate and maintain PON and industrial-switch networks for emerging markets.
About Rayin → https://www.szrayin.com/Profile/