Skip to content

Guide for ISPs

How to automatically suspend internet customers when their package expires

Ask any ISP owner what eats their evening and expiry is near the top: checking who has not paid, logging in to the router, disabling them, and then enabling them again the moment they pay. All of it can run by itself, as long as you understand one detail about how PPPoE sessions behave.

· 5 min read · ISPOpera

The manual way, and why it breaks

With customers stored as local secrets on the MikroTik, suspending someone means finding them, disabling the secret and removing their active session. Do that for thirty customers on the first of the month and mistakes are guaranteed: someone who paid gets cut, someone who did not stays online for weeks.

How automatic suspension works

When customers authenticate through RADIUS, the billing system decides who is allowed in. Every customer has a subscription end date. When it passes and no payment has been recorded, the system marks them expired and removes their permission on the RADIUS server. From that point their router cannot log in again.

  • Nobody has to remember who is due.
  • The decision is based on the same dates the invoices use, so billing and the network never disagree.
  • Paying customers are never touched.

The detail that confuses everyone: running sessions

RADIUS is asked when a session starts. A customer who is already connected when they expire keeps that session until it ends: when their router restarts, the power goes out, or you disconnect them. That is why an expired customer can still be browsing the next morning.

You have two simple ways to deal with it:

  • Disconnect the session on the MikroTik, so the router has to dial again and is refused: /ppp active remove [find name="USERNAME"].
  • Set a session timeout on the PPP profile so every session re-authenticates at least once a day, for example /ppp profile set default session-timeout=1d. Expired customers then drop within a day at most. The trade-off is a brief reconnect for every customer once a day.

Grace periods and payments under review

Customers who pay by bank transfer, JazzCash or Easypaisa often pay on the last day and send a slip. Cutting them off while you have not checked the slip yet causes angry calls. A good setup leaves a customer connected while their payment proof is under review, and only expires them if nothing is pending.

Reactivation

When the payment is recorded, the customer is made active on RADIUS again and their router can connect straight away. If it gave up retrying while they were expired, a router restart brings it back.

Fewer expiries in the first place

The cheapest disconnection is the one that never happens. Reminders a week before expiry and on the last few days, on the customer’s phone, turn most expiries into early payments.

How ISPOpera handles it

  • Every night at 12:00 AM Pakistan time, customers whose subscription has ended are marked expired and taken off RADIUS.
  • Customers with a payment slip under review are not expired until you decide.
  • Expiry reminders go out 7, 5, 4, 3, 2 and 1 days before the end date and on the day itself.
  • Approving a payment or recording one makes the customer active again, with the new period shown before you confirm.