Implementation guide

MikroTik FreeRADIUS Integration for ISP Networks

This integration depends on agreement between RouterOS and RADIUS: client identity, shared secret, services, attributes, accounting intervals and CoA path must all match.

Use the interface and documentation together.

The capture below shows the related ISPbills product area. Follow the linked documentation for current fields and prerequisites, then validate the exact device, provider, software version, failure path and rollback before production use.

ISPbills RADIUS interface for network access and session operations
RADIUS operations view for configured AAA environments.

Plan the complete path, not one isolated setting.

Configure and validate MikroTik as a FreeRADIUS NAS for PPPoE or Hotspot authentication, accounting and session control. Confirm the exact device, software version, provider contract and failure behavior in a representative environment before production rollout.

01

Establish the NAS relationship

Register the MikroTik source address and configure the same protected secret on both sides.

02

Enable only intended services

Select PPP, Hotspot or other supported RADIUS services deliberately.

03

Test full AAA behavior

Verify accept, reject, returned policy, accounting and session control—not login alone.

Prove the boundaries before automating them.

Record expected results, failure signals, the person who can approve a change, and the rollback path. Product support depends on the deployed architecture and integration version.

  1. RouterOS source addressTest this requirement with representative data and retain the result in the implementation plan.
  2. Authentication and accounting portsTest this requirement with representative data and retain the result in the implementation plan.
  3. Interim update intervalTest this requirement with representative data and retain the result in the implementation plan.
  4. CoA or disconnect clientTest this requirement with representative data and retain the result in the implementation plan.

Implementation answers

Why does RADIUS say unknown client?

The request source does not match a registered NAS address. Check routing, NAT and the RouterOS source address.

What causes an invalid authenticator?

A mismatched shared secret is a common cause; rotate and verify it securely on both systems.

Can RouterOS fall back locally?

RouterOS service settings determine fallback behavior. Define it deliberately and test a RADIUS outage.

Validate with your own environment

Bring the actual routers, access design, billing rules and failure cases.

Explore the online workspace or ask ISPbills to review compatibility and migration scope.

Open online demoDiscuss your deployment