On MikroTik devices, the “Radius” tab within a “Server Profile” has a very specific and essential function to integrate external authentication services into your network.
This configuration is mainly used to link your MikroTik with a RADIUS (Remote Authentication Dial-In User Service) server.
We explain more about its usefulness and configuration:
Main Functions of the Radius Tab in Server Profile
- Authentication: Integration with a RADIUS server allows MikroTik devices to authenticate users using this external protocol. This is common in networks that use PPP (Point-to-Point Protocol), Hotspot, or VPN services, where user authentication is not managed locally but through a centralized server that manages credentials and access policies.
- Accounting: In addition to authentication, RADIUS can also manage accounting, which records users' resource usage, such as connection time, amount of data transferred, and other network usage details. This information is crucial for network administration, billing, or compliance with usage policies.
- Content: RADIUS also allows the configuration of specific attributes for each user session, such as time limits, special permissions, and dynamically assigned VLAN configurations, among others.
Configuring Radius in Server Profile in MikroTik
To configure RADIUS on a MikroTik, follow these basic steps:
- Access RouterOS: Use WinBox, WebFig, or SSH to access your MikroTik device.
- Navigate to Radius: go to
Radius
in the main menu to configure the RADIUS servers you want to use. - Add a RADIUS server: Click the plus sign (+) to add a new server. Here you must enter the IP address of the RADIUS server, the port (default is 1812 for authentication and 1813 for accounting), and the shared secret key that matches the configuration on your RADIUS server.
- Configure Server Profile:
- In the corresponding section (PPP, Hotspot, etc.), create or edit a “Server Profile”.
- In the “Radius” tab, activate the “Use Radius” options for authentication and, if necessary, for accounting.
- Make sure you select the correct RADIUS server for each service you are configuring.
This configuration is essential for managing large networks, especially in enterprise or service provider environments where centralized user management and accounting are necessary for efficient and secure operation. In addition, it helps comply with security policies by centralizing authentication and having better control over who accesses the network.
There are no tags for this post.