Skip to content

Radius

Radius Setup

NumberDescription
1First, go to the Radius module in Mikrotik from the left sidebar menu.
2From the new window, create a new Radius Server by clicking on the plus button. A new window will appear as Radius Server for Radius Setups.
3Open it once the radius service is created.
4From the new Radius Server window, select the General tab from the top bar and select the PPP service for PPP auth request and accounting.
5From the new Radius Server window, select the General tab from the top bar and select the Hotspot service for Hotspot auth request and accounting.
6Enter your Radius Server IP address here. Mikrotik will send PPP and Hotspot requests to this Radius Server (Zal Pro) for Radius Auth and Accounting.
7Select Default Radius Protocol UDP.
8Insert your Radius Server NAS secret here. You must insert the same NAS secret as you inserted in Zal Pro Network -> NAS module. Warning: If you don't insert the same NAS secret, users will not connect at all. You can't use any special characters here; only plain text/letters/words/numbers will work. If you face any issues, like users not connecting or users being accepted in Zal Pro but not connecting in Mikrotik, or if the user's connection drops after a few seconds, recheck your Zal Pro NAS secret and this NAS secret. Both secrets must match. If you still face issues, set the secret to 123456, which will work for any NAS in your network.
9Set the Authentication port to 1812 for the Radius Server. Do not change these ports; use the default port as it is. If you want/need to change the port, then contact us.
10Set the Accounting port to 1813 for the Radius Server. Do not change these ports; use the default port as it is. If you want/need to change the port, then contact us.
11Very important radius timeout time, set Timeout to 3000 milliseconds. Do not set lower or higher than this.
12You must enable Radius Incoming requests from the Radius Server (Zal Pro) for CoA (Change of Authorization). Zal Pro uses this feature to change user bandwidth limits or to disconnect users from Mikrotik/NAS.
13You must set Radius Incoming port for CoA (Change of Authorization), and both CoA ports should match in Zal Pro NAS settings and here. The default is 3799. If CoA is not enabled, Zal Pro can't disconnect users from Mikrotik when needed. Zal Pro only sends disconnect and bandwidth changing requests to the user-connected NAS/IP/Mikrotik. You must set the correct NAS/Mikrotik/IP to the user in the user profile. If the connected user's IP does not match properly or if your Radius secret does not match with Zal Pro NAS Radius secret, you will see errors here as NAKS.

www.onezeroart.com