Guide for ISPs
How to connect MikroTik to a RADIUS billing system for PPPoE customers
Most ISPs start with customers saved as PPP secrets on the MikroTik itself. That works for fifty customers and falls apart at five hundred: every expiry, speed change and new connection means logging in to the router. Moving authentication to RADIUS puts all of it in one place, where your billing system can control it.
· 7 min read · ISPOpera
What RADIUS changes
With RADIUS, the MikroTik stops deciding who may connect. When a customer’s router dials PPPoE, the MikroTik asks the RADIUS server whether the username and password are valid and what speed to give. The server answers with an accept or a reject, plus attributes such as the rate limit. Your billing system keeps the RADIUS server up to date, so a customer who has not paid simply gets a reject the next time they connect.
- One customer list for every router you run, instead of a separate secret list on each one.
- Speeds that follow the package the customer is billed for.
- Expiry handled by the billing system instead of by hand.
- Accounting records (session time, data used) collected centrally.
What you need before you start
- A MikroTik running RouterOS with a working PPPoE server (or one you are about to set up).
- The RADIUS server’s IP address, the shared secret, and the ports. The standard ports are 1812 for authentication and 1813 for accounting.
- Your router’s public IP registered on the RADIUS server as a client. The server only answers routers it knows.
- Access to the router through Winbox or SSH, and a test customer you can safely disconnect.
Step 1: Add the RADIUS server to the MikroTik
Open New Terminal in Winbox and add the server as a RADIUS client for the PPP service. Replace the capitalised values with the ones you were given.
/radius add service=ppp address=RADIUS_SERVER_IP secret=SHARED_SECRET authentication-port=1812 accounting-port=1813 timeout=3sThe default timeout is very short. When the RADIUS server is reached over the internet rather than your own LAN, a few seconds avoids false failures on a slow moment.
Step 2: Tell PPP to use RADIUS
/ppp aaa set use-radius=yes accounting=yes interim-update=5muse-radius sends logins to the server. accounting reports when sessions start and stop, and interim-update sends a usage update every five minutes while a session is running, which is what keeps live usage and online status accurate.
Step 3: Check the PPPoE server and profile
If you already run PPPoE, keep your server as it is. If not, create one on the interface that faces your customers (the example uses ether2).
/interface pppoe-server server add service-name=internet interface=ether2 default-profile=default one-session-per-host=yes disabled=noThe PPP profile the server uses must give customers addresses: a local address for the router side and a remote address, usually an IP pool. Make sure your NAT (masquerade) rule covers that pool, or customers will connect but have no internet.
Step 4: Remove the old local PPP secrets
This is the step most ISPs miss. The MikroTik checks its own PPP secrets before it asks RADIUS. If a customer still has a local secret, the router logs them in by itself and never sends the request to RADIUS, so expiry, speed changes and usage tracking silently do nothing for that customer.
enable if you need to roll back):/ppp secret print
/ppp secret disable [find name="USERNAME"]Disable rather than delete while you are testing. Once a customer is confirmed working through RADIUS, remove their local secret for good.
Step 5: Test with one customer
- Pick a test customer who exists on the RADIUS side and has no local secret.
- Disconnect their current session so they dial again:
/ppp active remove [find name="USERNAME"]. - Watch the session come back in
/ppp active print. A session authenticated by RADIUS is marked with the R flag. - If it does not connect, look at
/log print where topics~"radius"and/radius monitor 0to see whether requests are sent, answered or timing out.
How speeds reach the router
MikroTik reads the speed from the Mikrotik-Rate-Limit attribute in the RADIUS reply, written as rx/tx, for example 10M/10M. From the router’s point of view rx is what the customer uploads and tx is what they download. A new speed is applied when the customer’s session starts, so after changing a package the customer gets the new speed on their next connection.
Common problems
- Every login rejected: the shared secret differs between the router and the server, or the router’s public IP is not registered as a client.
- Requests time out: UDP 1812 and 1813 are blocked by a firewall on either side, or the timeout is too short.
- One customer ignores every change: they still have a local PPP secret.
- Connected but no internet: the address pool is not covered by your NAT rule.
- Everyone drops at once: the router lost its connection to the RADIUS server. New logins fail until it is back.
How ISPOpera uses this
ISPOpera runs the RADIUS server for you. Each package’s speed is sent to the router as Mikrotik-Rate-Limit and its name as Mikrotik-Group. Adding a customer creates their RADIUS account, expiry takes them off RADIUS at midnight, and approving a payment makes them active again. ISPOpera also checks every five minutes that your router is still talking to RADIUS and alerts you if it stops.
Read next on ISPOpera