Community discussions

just joined
Topic Author
Posts: 16
Joined: Mon Jul 09, 2007 9:50 am

Mikrotik & FreeRadius

Thu Feb 28, 2008 5:03 pm


I'm traying to use the MT Radius client & the FreeRadius Server for my customers accounting.

The problem is that the MT it's below a NAT System so the real address that arrive to the Radius Server is different from the NAS-IP-Address attribute sent from MT.

I know that some NAS (ex. CISCO) permits to change the NAS-IP-Address attribute before to send the request. It's possible make something similar with MT?
Or in alternative, anyone knows a way to change the attribute from the Raidius Server before the authentication?

Thanks in advance for any suggestions!
User avatar
Member Candidate
Member Candidate
Posts: 194
Joined: Fri Aug 17, 2007 9:06 am

Re: Mikrotik & FreeRadius

Sun Mar 02, 2008 6:43 pm

Why Do You need to change Nas-Ip-Address Attribute?
just joined
Posts: 21
Joined: Tue Aug 02, 2005 5:47 am

Re: Mikrotik & FreeRadius

Mon May 05, 2008 4:04 pm

I have the same problem.

I need mikrotik to send the public ip address and not the private address from behind the nat router.

This is what freeradius is seeing...

Currently - NAS-IP-Address =

What I need is NAS-IP-Address =

Posts: 940
Joined: Fri Jun 04, 2004 2:22 am
Location: St. Louis, MO

Re: Mikrotik & FreeRadius

Mon May 05, 2008 7:28 pm

This is not an issue. You will either have to SRCNAT your MT behind the NAT, that way it has its own public IP, or put in your PAT IP that your MTs are coming from. You can have 100 MTs behind a NAT, and just list one IP, however, they all have to have the same secret.
Dennis Burgess, MCTCE, MTCNA, MCTCTE, MTCWE, MTCNIE, A+, N+, MCP, MTCSE Mikrotik Certified Consultant / Trainer
Need Mikrotik Support: -- Link Technologies, Inc.
-- Author of "Learn RouterOS: Second Edition"
Frequent Visitor
Frequent Visitor
Posts: 56
Joined: Mon Jul 17, 2006 12:12 pm

Re: Mikrotik & FreeRadius

Tue May 06, 2008 11:10 pm

use pptp tunnel from border gw (where you use src-nat) to radius server, and you don't src-nat to the tunnel. I use this with mt -> debian and it works fine.
(interesting: debian is the pptp server and mt is the client, because i can't do for working reversal.) In radius don't remember to route inner ip addresses to the pptp tunnel.


Who is online

Users browsing this forum: MSN [Bot] and 94 guests