Routers and Service DeliveryOperator runbook

Backup and Authenticator Settings

Configure customer authentication failover and copy customer credentials between RADIUS and a MikroTik router

Get help
What this guide covers

Configure customer authentication failover and copy customer credentials between RADIUS and a MikroTik router

On this page

This page configures authentication continuity for each Group Admin, Operator or Sub-Operator. It selects whether RADIUS or a chosen MikroTik Router is the primary authenticator and controls whether customer credentials are copied automatically or on request.

This page covers customer authentication continuity only; it is not a full-system backup page.

Before you begin

The target router must belong to the same Group Admin and have working API credentials. Confirm that customer records and RADIUS authentication are healthy before changing the primary authenticator.

Create an authenticator setting

  1. Open Routers & Packages → Customer Backup (the page is titled Customer Backup).
  2. Select New Setting.
  3. Choose the Operator whose customers the setting covers.
  4. Choose the fallback Router.
  5. Select the Primary Authenticator:
    • Radius — FreeRADIUS remains authoritative.
    • Router — the selected MikroTik router authenticates the copied local users.
  6. Select a Backup Type:
    • automatic — eligible customer changes are copied according to the configured workflow.
    • manual — use Backup Now when you want to create or refresh the copy.
  7. Select Submit.

Each Operator can have only one backup setting. Once an Operator has a setting, they no longer appear in the Operator dropdown on the create form — to point that Operator at a different router or change its authenticator, edit the existing setting instead of creating a new one. The system rejects any attempt to create a second setting for the same Operator.

What is copied

The customer backup job processes both PPPoE and Hotspot customers for the selected setting. When Router authentication is primary, related customer updates such as RADIUS password, username or framed-IP changes follow the router-authentication rules rather than assuming RADIUS is authoritative.

The page records each backup request and its status in the Backup activity table. Select Backup Now from a setting’s actions menu, then watch the request move through Queued → Running → Completed (a request that never runs to completion is marked Failed or Stale).

Only one active backup can run per setting at a time. If you press Backup Now again while a job is still processing, ISPbills coalesces the request rather than starting a duplicate and reports A backup job is already processing.

Each queued request is stamped with a fingerprint of its exact Operator, router and setting. If you edit the setting (for example, change its router) while a request is still queued, ISPbills marks the outdated request Stale instead of running it against the changed target — so a backup is never applied to the wrong tenant’s router.

Changing the primary authenticator

Changing Primary Authenticator dispatches a synchronization job. Treat this as a network change:

  1. Schedule it during a low-traffic period.
  2. Keep an active administrator session and router access available.
  3. Test one known subscriber after the job completes.
  4. Verify both new logins and reconnects before considering the change complete.

Selecting Router can make the chosen device responsible for subscriber authentication. Read the on-screen warning carefully; an unreachable router or incomplete local-user copy can interrupt service.

Troubleshooting

Symptom Check
Setting stays unchanged Retry the change and contact ISPbills support if it still does not apply.
Backup request never reaches Completed (stays Queued/Running, or shows Failed/Stale) Verify the selected router’s API address, username, password and port.
Duplicate Setting error A setting already exists for that Operator (only one is allowed per Operator). Edit the existing entry instead.
Subscribers cannot reconnect Restore the previous primary authenticator, verify RADIUS/router reachability, and test credential synchronization.
Router is missing from the list Confirm it belongs to the Group Admin and has valid API credentials.

For versioned MikroTik and OLT configuration snapshots, use Device Configuration Backup.

Need help applying this guide?Browse related guidance or ask the support team for help.