Backup and Authenticator Settings
Configure customer authentication failover and copy customer credentials between RADIUS and a MikroTik router
On this page
This page configures authentication continuity for each Group Admin, Operator or Sub-Operator. It selects whether RADIUS or a chosen MikroTik Router is the primary authenticator and controls whether customer credentials are copied automatically or on request.
This page covers customer authentication continuity only; it is not a full-system backup page.
Before you begin
The target router must belong to the same Group Admin and have working API credentials. Confirm that customer records and RADIUS authentication are healthy before changing the primary authenticator.
Create an authenticator setting
- Open Network → Backups or Routers & Packages → Backup Settings.
- Select New Setting.
- Choose the Operator whose customers the setting covers.
- Choose the fallback Router.
- Select the Primary Authenticator:
- Radius — FreeRADIUS remains authoritative.
- Router — the selected MikroTik router authenticates the copied local users.
- Select a Backup Type:
- automatic — eligible customer changes are copied according to the configured workflow.
- manual — use Backup Now when you want to create or refresh the copy.
- Select Submit.
Only one identical Operator/router setting can exist. The system rejects duplicate combinations.
What is copied
The customer backup job processes both PPPoE and Hotspot customers for the selected setting. When Router authentication is primary, related customer updates such as RADIUS password, username or framed-IP changes follow the router-authentication rules rather than assuming RADIUS is authoritative.
The page records each manual backup request and its status. Select Backup Now, then review Manual Backup History to confirm that it reaches Done.
Changing the primary authenticator
Changing Primary Authenticator dispatches a synchronization job. Treat this as a network change:
- Schedule it during a low-traffic period.
- Keep an active administrator session and router access available.
- Test one known subscriber after the job completes.
- Verify both new logins and reconnects before considering the change complete.
Selecting Router can make the chosen device responsible for subscriber authentication. Read the on-screen warning carefully; an unreachable router or incomplete local-user copy can interrupt service.
Troubleshooting
| Symptom | Check |
|---|---|
| Setting stays unchanged | Retry the change and contact ISPbills support if it still does not apply. |
| Backup request never reaches Done | Verify the selected router’s API address, username, password and port. |
| Duplicate Setting error | An entry already exists for the same Operator and router. Edit that entry instead. |
| Subscribers cannot reconnect | Restore the previous primary authenticator, verify RADIUS/router reachability, and test credential synchronization. |
| Router is missing from the list | Confirm it belongs to the Group Admin and has valid API credentials. |
For versioned MikroTik and OLT configuration snapshots, use Device Configuration Backup.