Hotspot + Radius + Public Static IP's

I am attempting to convert an existing subnet that is currently static, to having it’s IP’s assigned by a rb750. I have both a public subnet and a private management subnet on the same interface. I do not want the Mikrotik to masquerade the traffic.

First I attempted to use a DHCP server with Radius and that would have worked, but then I found out that it didn’t do accounting. If you want accounting you have to use the hotspot server.

So now I have been fighting the hotspot server. I am running ROS 4.5. I have bypassed all of my static IP’s using /ip hotspot ip-binding. Then when I run the hotspot setup program everything seems to fall apart. I am not sure if I am supposed to set up the ip-bindings with the address and to-address filled out or to leave them blank in order to have my public IP’s not NATed. or do I fill them out with the same IP in address and to-address. Do I set the type to ‘bypassed’ or ‘regular’. I have different combination and nothing seems to work.

In order to migrate, I need to initially have the hotspot whitelist certain mac/public ips, with no NAT.
Then one by one, I want to go to each device and change the settings to DHCP and allow the hotspot server + Radius to manage the ip’s, with no NAT.

Is this possible or am I fighting a loosing battle?

When I have everything setup the way i think it should be, i keep getting the following in the log.

trying to log in by mac
logged out: host removed:
authorized client needs your ip.
logged in.

this happens over an over again in rapid succession for every ip that has been whitelisted in ip-bindings.

sorry if i bump this thread,

i have similiar case, i bind some gadget/notebook to 1 “to adress”, then i see log message “…authorized client need your IP”, why?
i need a user can use more than 1 device with 1 simple queue