Add access device configuration in Toughradius
RouterOS device information must be configured in the Toughradius system, otherwise all authentication messages will be discarded.
650) this.width=650; "src=" Http://docs.toughradius.net/imgs/ros_basconfig.png "style=" Border:0px;font-size: Inherit; "/>
RouterOS RADIUS Configuration
Note that to make the Force downline function effective, it is important to start the authorization function and open the 3799 port to Radius.
650) this.width=650; "src=" Http://docs.toughradius.net/imgs/ros_radiusconfig.png "style=" Border:0px;font-size: Inherit; "/>
For the billing interval, if it is a monthly type package, the billing interval should be set a little longer, can effectively alleviate the RADIUS server burden, if you want to get more accounting data, appropriate adjustments required accounting interval.
650) this.width=650; "src=" Http://docs.toughradius.net/imgs/ros_accounting.png "style=" Border:0px;font-size: Inherit; "/>
According to the actual situation, configure the address pool, PPPoE authentication interface, encryption options, usually do not consider MSCHAPV1
650) this.width=650; "src=" Http://docs.toughradius.net/imgs/ros_pppoeconfig.png "style=" Border:0px;font-size: Inherit; "/>
RouterOS Docking Extension
Through the Toughradius tariff policy mechanism, you can increase the function extension for RouterOS.
650) this.width=650; "src=" Http://docs.toughradius.net/imgs/ros_radius_ext.png "style=" Border:0px;font-size: Inherit; "/>
Partial Radius extension properties supported by RouterOS
mikrotik-recv-limit receives a total packet byte limit from the client, which can be used to charge based on the traffic. The mikrotik-xmit-limit sends the client a limit on the total number of bytes of packets that can be used based on the traffic charge. The mikrotik-group user group, which can be used when managing users with RADIUS authentication Mikrotik to return whether the user belongs to the full group or another group .mikrotik-wireless-forward When RADIUS returns the property value =0 to Mikrotik, the frame of the Mikrotik wireless client is not forwarded to the infrastructuremikrotik-rate-limit customer's rate limit. String representation, formatted as rx-rate[/tx-rate] [rx-burst-rate[/tx-burst-rate] [rx-burst-threshold[/ Tx-burst-threshold] [rx-burst-time[/tx-burst-time] [priority] [rx-rate-min[/tx-rate-min] []] where the content in [] is optional. "Rx" represents the customer's upload rate, the "TX" customer's download rate. Burst-rate burst rate, Burst-threshold burst threshold, Burst-time burst duration. Mikrotik-Realm account name suffix. mikrotik-host-ip hotspot Client The most initial IP address Mikrotik-Mark-Id firewall Magle chain name. Only for hotspot. Mikrotik-Advertise-URL Notification page address (URL). Generally used for Hotspotmikrotik-advertise-interval url notification interval mikrotik-ascend-client-gateway hotspot application, The gateway address of the client in the DHCP address pool. Mikrotik-Ascend-Data-Rate similar to Rate-limit but this property is Rate-liMIT ignores mikrotik-ascend-xmit-rate download rate limit But this property is Rate-limit ignored
This article is from the "toughstruct" blog, make sure to keep this source http://jamiesun.blog.51cto.com/7142358/1767642
Toughradius and RouterOS Docking guide