← Back to Blog

MikroTik RADIUS Authentication: Setup & Best Practices

May 28, 2025 · 10 min read · By Veloxiom Team

RADIUS (Remote Authentication Dial-In User Service) is the backbone of subscriber management for ISPs using MikroTik routers. This guide covers everything you need to set up and optimize RADIUS authentication for PPPoE and DHCP environments.

Why RADIUS for ISP Management?

RADIUS provides centralized authentication, authorization, and accounting (AAA) for your subscriber base. Instead of managing users on each individual router, RADIUS gives you:

MikroTik RADIUS Configuration

Setting up RADIUS on MikroTik RouterOS involves three main steps:

1. RADIUS Server Configuration

First, configure your FreeRADIUS server with the appropriate NAS (Network Access Server) entries for each MikroTik router. Each router needs a shared secret and the correct authentication port configuration.

2. MikroTik Router Setup

On each MikroTik router, configure the RADIUS client to point to your RADIUS server. Key settings include:

3. User Profile Management

Create service plans that map to RADIUS attributes: bandwidth limits (rate-limit), IP pool assignments, session timeouts, and traffic quotas.

Best Practices

Simplifying RADIUS with Veloxiom

Veloxiom eliminates the complexity of manual RADIUS configuration. Connect your MikroTik routers via the RouterOS API, and Veloxiom handles RADIUS configuration, user provisioning, and session monitoring automatically.

Try Veloxiom Free Demo