I recently switch over from m0nowall captive portal to mikrotik hotspot RB433 3.23. Her’s my problem hopefully somebody can assist me or point me in the correct direction.
Freeradius worked correctly when a user has reached its volume limits and with the interim update of 1min it will disconnect the user on m0nowall. Working 100%
however
With Mikrotik the freeradius attributes ( Rate limit etc )works perfectly but it do not disconnect the user if its past the limits. If the user is pass the limit and you disconnect him manually, and try to login, mikrotik prevent the login which is correct. Interrum update has been set and can see its is working on the stats page in freeradius.
I tried the following:
Switch on incoming raduis on port 3779 on Mikrotik.
Nothing hapens when the user goes past, everything is 0 in the icoming radius stats page.
if I run the follwoing command mikrotik disconnect the user and I can see ACK = 1 in the stats page.
Set Interrum Update in freeradius and in Mikrotik, still no go.
I see however in Freeradius 2.16 there is support fort originate-coa “Send-CoA-Request = No / Yes” do I need to upgrade.?
Does Mikrotik support Disconnect-Request like m0n0wall or is there something I am missing or can do in either Freeradius or Mikrotik to get the Disconnect-Request working, ether through a Disconnect-Request packet or CoA.
“RouterOS doesn’t support POD (Packet of Disconnect) the other RADIUS access request packet that performs a similar function as Disconnect Messages”
and
Change of Authorization
RADIUS disconnect and Change of Authorization (according to RFC3576) are supported as well. These attributes may be changed by a CoA request from the RADIUS server:
Mikrotik-Group
Mikrotik-Recv-Limit
Mikrotik-Xmit-Limit
Mikrotik-Rate-Limit
Ascend-Data-Rate (only if Mikrotik-Rate-Limit is not present)
Ascend-XMit-Rate (only if Mikrotik-Rate-Limit is not present)
Mikrotik-Mark-Id
Filter-Id
Mikrotik-Advertise-Url
Mikrotik-Advertise-Interval
Session-Timeout
Idle-Timeout
Port-Limit
What does this mean..?, what is the difference between packet of disconnect and radius disconnect. I think my problem more relates to POD, which is NOT supported by Router OS, which points to my problem, correct…?
I think what you are referring to is a CoA packet, and yes that works tested on my side. The question is how do one get Freeradius to send a CoA packet rather than a remote disconnect…?
What I have read so far is that Mikrotik will only support PoD if used wirh VSA attributes.
These ones are new and carries my interest, they are undocumented
I am using Mikrotik router OS 2.9, basic radius operations are working fine but while try to send a PoD and CoA request some it is not reaching to the router and some time it is marked as Bad request. I am new to Mikrotik router OS. Help to sort it out …
sorry for up date this post
I have a same problem for freeradius and Mikrotik-Total-Limit
When my users hit the qouta are not diconnect qutomatically but if diconnect manoly they are cannot connect to the server (Freeradius rejected).
I like to disconnect automaticaly after use the maximom tarffic like 1G