ISP Radius: profiles, accounts, and connectivity control
Configure the integrated Radius engine, connect accounts to services, inspect authentication/session data, and provide protected customer options.
Last updated: 2026-08-20
When to use ISP Radius
ISP Radius is the integrated connector for managing Radius credentials, profiles, and connectivity state within ISP Billing’s customer, service, and billing lifecycle. Select it as provider only for the intended access.
Do not overlap it with ISP Radius 2.0, Radius Manager, WimeRadius, or BlissRadius on the same circuit unless a controlled migration defines the authoritative account, switchover, and rollback.
Initial configuration
Open Settings → ISP Radius and enter the parameters required by the installed server. Use a dedicated least-privilege technical account and keep database or management interfaces off the public Internet.
Connector authentication, database reachability, and the NAS ability to query Radius are separate checks. Prove each one before creating production accounts.
Profiles and Radius attributes
Create profiles before accounts. Each profile contains an internal name, default option, supported Radius attributes, and a description visible in Customer Area. Permanent = yes leaves suspension and reactivation under ISP Billing’s commercial lifecycle; port limits restrict simultaneous authentication.
Session timeout, MikroTik rates, DNS, and DHCP pool attributes must match the NAS dictionary and implementation. Duplicate rows are resolved by the last occurrence, so remove ambiguity and test a pilot account.
Additional options and parental control
A profile can provide several options, each with its own attributes and customer description. For filtered DNS, copy the normal connectivity attributes and change only the DNS values or other explicitly supported policy fields.
Explain effect, limitations, expected reconnection, and opt-out. Parental-control DNS reduces selected exposure but is not a complete security guarantee.
Create the account
From Accounts, select New account and associate the correct customer and installation address. Enter unique username and password, profile, option, optional public or static IP information, state, and only necessary internal notes.
States are Active, Suspended, and Terminated. An account linked to a service cannot be deleted until the association is resolved. Verify the remote account and a controlled authentication after saving.
Service link and billing
On the customer service select ISP Radius and link the intended account. The commercial service can then govern suspension and reactivation according to configured rules.
Use Unbilled services to find technical access that remains active without the expected commercial service or document. Reconcile customer, account, service, period, and billing rather than deleting evidence of the mismatch.
Authentication, sessions, and diagnosis
Authentication Requests shows accepted and rejected attempts; Sessions provides start, stop, duration, traffic, NAS, and addresses. Service detail can refresh PPPoE state and the last observed IP.
Diagnose in order: commercial service state, account state, credentials, option and profile, Radius reply, current session, and NAS. Change one layer at a time so the cause remains attributable.
Customer Area and protected changes
Customer Area can show account, state, active option, and descriptions of permitted alternatives. An option change requires an OTP sent to the registered recipient and disconnects the account so the next authentication receives new attributes.
Verify identity, contact, commercial effect, and modem reconnection instructions before enabling self-service. Never expose passwords, internal attributes, or management endpoints.
Pre-launch controls
- Test connector access and least-privilege permissions.
- Create a pilot profile and validate every attribute on the NAS.
- Create one account linked to the correct customer, address, and service.
- Verify authentication, accounting, session termination, suspension, and reactivation.
- Test OTP-protected option change and reconnection in Customer Area.
- Review unbilled accounts and services periodically.