Differentiating Radius authentication usernames on service

I would like to implement Radius authentication for multiple services on the same RouterOS device. In the past some devices client provided an automated prefix for the username based upon the type of service making the request (ppp-user, pptp-user, l2tp-user, login-user). I don’t see any mechanism in RouterOS and I haven’t see any other way to restrict usernames based upon service.

Without some mechanism to identify and restrict authentication per username based upon service, the pptp users are able to login with ssh/winbox…

Have I completely overlooked something?

Tim

Interesting point of view.. But.. There is not possible to authenticate from
A radius server sending what you can see in user/groups?

Its strange that you can’t do this. I only user AAA to a radius with hotspot and login to the router, not for a specific service like ssh.