You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Next »

Overview

User Manager is RADIUS server implementation in RouterOS which provides centralized user authentication and authorization to a certain service. Having a central user database allows better track of system users and customers. As a separate package, User Manager is available on all architectures including SMIPS, however care must be taken due to limited free space available. It supports many different authentication methods including PAP, CHAP, MS-CHAP, MS-CHAPv2, EAP-TLS, EAP-TTLS and EAP-PEAP. In RouterOS, DHCP, Dot1x, Hotspot, IPsec, PPP, Wireless are features that benefit from User Manager the most. Each user can see their account statistics and manage available profiles using WEB interface. Additionally, users are able buy their own data plans (profiles) using the most popular payment gateway - PayPal making it a great system for service providers. Customized reports can be generated to ease processing by billing department. User Manager works according to RADIUS standard defined in RFC2865 and RFC3579.

Attributes

RADIUS attributes are defined authorization, information and configuration parameters that are passed between the RADIUS server and client. User Manager allows sending customized attributes defined in "attributes" menu.

#AttributePacket typeDescription
1User-NameAccess-Accept
6Service-TypeAccess-Accept
7Framed-ProtocolAccess-Accept
8

Framed-IP-Address

Access-Accept
9

Framed-IP-Netmask

Access-Accept
10

Framed-Routing

Access-Accept
11

Filter-Id

Access-Accept
12

Framed-MTU

Access-Accept
13

Framed-Compression

Access-Accept
14

Login-IP-Host

Access-Accept
15

Login-Service

Access-Accept
16

Login-TCP-Port

Access-Accept
18

Reply-Message

Access-Accept, Access-Challenge
19

Callback-Number

Access-Accept
20

Callback-Id

Access-Accept
22

Framed-Route

Access-Accept
23

Framed-IPX-Network

Access-Accept
24

State

Access-Accept, Access-Challenge
25

Class

Access-Accept
26

Vendor-Specific

Access-Accept, Access-Challenge
27

Session-Timeout

Access-Accept, Access-Challenge
28

Idle-Timeout

Access-Accept, Access-Challenge
29

Termination-Action

Access-Accept
33

Proxy-State

Access-Accept, Access-Challenge
34

Login-LAT-Service

Access-Accept
35

Login-LAT-Node

Access-Accept
36

Login-LAT-Group

Access-Accept
37

Framed-AppleTalk-Link

Access-Accept
38

Framed-AppleTalk-Network

Access-Accept
39

Framed-AppleTalk-Zone

Access-Accept
62

Port-Limit

Access-Accept
63

Login-LAT-Port

Access-Accept

Database

User limitation

WEB user interface

Reports

Payment gateway

  • No labels