You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 5 Next »

Overview

User Manager is RADIUS server implementation in RouterOS which provides centralized user authentication and authorization to a certain service. Having a central user database allows better track of system users and customers. As a separate package, User Manager is available on all architectures including SMIPS, however care must be taken due to limited free space available. It supports many different authentication methods including PAP, CHAP, MS-CHAP, MS-CHAPv2, EAP-TLS, EAP-TTLS and EAP-PEAP. In RouterOS, DHCP, Dot1x, Hotspot, IPsec, PPP, Wireless are features that benefit from User Manager the most. Each user can see their account statistics and manage available profiles using WEB interface. Additionally, users are able buy their own data plans (profiles) using the most popular payment gateway - PayPal making it a great system for service providers. Customized reports can be generated to ease processing by billing department. User Manager works according to RADIUS standard defined in RFC2865 and RFC3579.

Attributes

RADIUS attributes are defined authorization, information and configuration parameters that are passed between the RADIUS server and client. User Manager allows sending customized attributes defined in "attributes" menu.

#AttributeData typePacket typeRFCDescription
1User-Name
Access-AcceptRFC2865
6Service-Type
Access-AcceptRFC2865
7Framed-Protocol
Access-AcceptRFC2865
8

Framed-IP-Address


Access-AcceptRFC2865
9

Framed-IP-Netmask


Access-AcceptRFC2865
10

Framed-Routing


Access-AcceptRFC2865
11

Filter-Id


Access-AcceptRFC2865
12

Framed-MTU


Access-AcceptRFC2865
13

Framed-Compression


Access-AcceptRFC2865
14

Login-IP-Host


Access-AcceptRFC2865
15

Login-Service


Access-AcceptRFC2865
16

Login-TCP-Port


Access-AcceptRFC2865
18

Reply-Message


Access-Accept, Access-ChallengeRFC2865
19

Callback-Number


Access-AcceptRFC2865
20

Callback-Id


Access-AcceptRFC2865
22

Framed-Route


Access-AcceptRFC2865
23

Framed-IPX-Network


Access-AcceptRFC2865
24

State


Access-Accept, Access-ChallengeRFC2865
25

Class


Access-AcceptRFC2865
26

Vendor-Specific


Access-Accept, Access-ChallengeRFC2865
27

Session-Timeout


Access-Accept, Access-ChallengeRFC2865
28

Idle-Timeout


Access-Accept, Access-ChallengeRFC2865
29

Termination-Action


Access-AcceptRFC2865
33

Proxy-State


Access-Accept, Access-ChallengeRFC2865
34

Login-LAT-Service


Access-AcceptRFC2865
35

Login-LAT-Node


Access-AcceptRFC2865
36

Login-LAT-Group


Access-AcceptRFC2865
37

Framed-AppleTalk-Link


Access-AcceptRFC2865
38

Framed-AppleTalk-Network


Access-AcceptRFC2865
39

Framed-AppleTalk-Zone


Access-AcceptRFC2865
56

Egress-VLANID


Access-AcceptRFC4675
57

Ingress-Filters


Access-AcceptRFC4675
58

Egress-VLAN-Name


Access-AcceptRFC4675
59

User-Priority-Table


Access-AcceptRFC4675
62

Port-Limit


Access-AcceptRFC2865
63

Login-LAT-Port


Access-AcceptRFC2865






Database

User limitation

WEB user interface

Reports

Payment gateway

  • No labels