Site icon System Zone

MikroTik RouterOS User Authentication via RADIUS Server

MikroTik RouterOS has a strong local user database that is enough to manage a single MikroTik RouterOS user. But if your network has more than one MikroTik Routers, it is always better to use a RADIUS server to manage RouterOS user centrally. MikroTik User Manager RADIUS Server is a centralized user authentication and accounting application that gives the ISP Company or network administrator ability to manage not only RouterOS users but also PPP, Hotspot, DHCP and Wireless users. How to setup MikroTik User Manager RADIUS Server has been discussed in my previous article. If you are a new MikroTik user, feel free to study that article and then keep reading this article. In this article, I will show how to authenticate MikroTik local user via User Manager RADIUS Server.

MikroTik User Manager Package can be installed and configured either on physical RouterOS or on a dedicated physical server where MikroTik RouterOS is running. I always prefer to use RADIUS Server separately. For this, I have installed User Manager Package on a dedicated physical server where MikroTik RouterOS is installed. I have also a Physical RouterOS that will work as a RADIUS client.

MikroTik User Manager RADIUS Server Network

For this article, My User Manager RADIUS Server and Physical RouterOS contains below IP information.

This information is just my RND purpose only. Change this IP information according to your network configuration.

Complete configuration for MikroTik RouterOS user authentication via RADIUS Server can be divided into two parts.

Part 1: MikroTik User Manager RADIUS Server Configuration

In User Manager RADIUS Server, we will first add client router that will communicate with this RADIUS Server and then we will add user who will be authenticated. So, RADIUS Server configuration for RouterOS user authentication can be divided into two steps.

Step 1: Add Client Router in RADIUS Server Router List

Detail explanation about MikroTik User Manager RADIUS Server Routers has been discussed in my previous article. If you have any confusion about RADIUS Server Routers, first study that article and then follow below steps. The following steps will show you how to add client router in User Manager RADIUS Server.

Our client router has been added to our RADIUS Server. Now we will create user who will be authenticated by RADIUS Server.

Steps 2: Add User in User Manager RADIUS Server

Explanation about Users in User Manager RADIUS Server has been discussed in my previous article. If you feel any confusion about RADIUS user, study that article and then follow below section to add user in User Manager RADIUS Server.

Every user should have at least a user profile. So, we have to create user profile before creating a user. On the other hand, every profile may contain one or more limitations. So, before creating profile, we also need to create profile limitation. In my previous article MikroTik RouterOS User Management, I discussed that user permission level is defined by user group. In profile limitation, we will define user group that are available in Client RouterOS so that different user gets different permission level.

Create Profile Limitation in User Manager RADIUS Server

The following steps will show you how to create Profile Limitation in User Manager RADIUS Server.

Your first limitation has been created if you follow the above steps carefully. Similarly, you can create as many limitations as you want. You can also edit your created limitation using Edit menu from top menu bar.

Create User Profile in User Manager RADIUS Server

The following steps will show you how to create user profile in User Manager RADIUS Server.

You can add as many profiles as you want following the above steps carefully. After creating limitation and profile, we will now create users who will be authenticated to login to Client RouterOS.

Create User in User Manager RADIUS Server

The following steps will show you how to create users in User Manager RADIUS Server.

A user has been created successfully in User Manager RADIUS Server. You can create as many users as you want following the above steps carefully. Similarly, you can disable, enable, change or remove any user using Edit menu.

Our User Manager RADIUS Server configuration has been completed. Now we will configure Client Router that will use RADIUS Server for user authentication.

Part 2: MikroTik RouterOS Client Configuration

In MikroTik RouterOS Client, we will configure RADIUS client so that it can communicate with RADIUS Server as well as we will enable user authentication so that it finds user from RADIUS Server. So, RouterOS Client configuration can be divided into two steps.

Step 1: RADIUS Client Configuration in MikroTik RouterOS

The following steps will show you how to configure RADIUS client in MikroTik RouterOS.

RADIUS client configuration has been completed. Now we will enable user authentication via RADIUS Server.

Step 2: Enable RouterOS User Authentication via RADIUS Server

The following steps will show you how to enable RouterOS user authentication via RADIUS Server.

Your client RouterOS is now ready to authenticate user via RADIUS Server. Open winbox software and login to your Client MikroTik Router using RADIUS Server user credentials. If everything is OK, you are now able to login to your Client MikroTik Router via RADIUS Server user.

Following above steps properly, you are able to configure User Manager Radius Server and MiroTik RouterOS so that Radius user can login to MikroTik Router with his credentials. However, if you face any difficulty, watch my video about MikroTik RouterOS user authentication via Radius Server. I hope it will reduce your any confusion.

How to Authenticate MikroTik RouterOS User via RADIUS Server has been discussed in this article. I hope you are now able to configure your MikroTik RouterOS so that it can be able to authenticate login user via MikroTik User Manager RADIUS Server. However, if you face any confusion to configure your User Manager RADIUS Server and Client RouterOS, feel free to discuss in comment or contact with me from Contact page. I will try my best to keep you.

Exit mobile version