如何在Mikrotik路由器配置热点及Radius,为其他无线路由器提供账号密码?
Absolutely, you can use the built-in RADIUS server on your MikroTik RB-951G to handle user account authentication for your D-Link/TP-Link wireless routers scattered across your multi-story building. Let’s break down the setup process and key considerations to make this work smoothly:
MikroTik RB-951G comes with a native RADIUS server that supports standard authentication protocols like PAP and CHAP. Most modern D-Link and TP-Link small-business/home wireless routers support WPA2-Enterprise (802.1X) authentication, which relies on RADIUS for user validation. As long as your APs support this mode, the setup is fully achievable.
Enable & Configure the RADIUS Server
- Log into your MikroTik via Winbox or WebFig.
- Navigate to
IP > RADIUS, then click the Settings tab.- Check the Enabled box to turn on the RADIUS server.
- Under Clients, add the IP addresses (or entire subnet, e.g.,
192.168.1.0/24) of all your wireless APs. - Set a Shared Secret (e.g.,
MySecureRadiusKey123) – this must match the secret you’ll configure on each AP. - Leave default ports (
1812for authentication,1813for accounting) unless you’ve modified them elsewhere.
Create User Accounts
- Still in
IP > RADIUS, switch to the Users tab. - Click the
+button to add a new user:- Enter a Username and Password for the hotspot user.
- Under Service, select
wireless(this maps to 802.1X wireless authentication). - Repeat for all user accounts you need.
Optional: Enable Accounting (for Usage Tracking)
If you want to log user connection duration or data usage:
- In the RADIUS Settings tab, check Accounting.
- Ensure your APs also have RADIUS accounting enabled (we’ll cover this in the AP setup step).
You’ll need to repeat this process for every AP:
- Log into the AP’s web management interface.
- Navigate to Wireless Security settings.
- Select WPA2-Enterprise (802.1X) as the security mode (avoid WPA/WPA2 mixed mode for better compatibility).
- Input the following RADIUS details:
- RADIUS Server IP: The LAN IP of your MikroTik RB-951G (e.g.,
192.168.1.2). - Shared Secret: The same secret you set on the MikroTik RADIUS server.
- Authentication Type: Choose PAP or CHAP (MikroTik supports both; PAP is more widely compatible with consumer APs).
- RADIUS Server IP: The LAN IP of your MikroTik RB-951G (e.g.,
- (Optional) Enable RADIUS Accounting if you turned it on in MikroTik, using port
1813. - Save settings and reboot the AP to apply changes.
- Network Connectivity: Ensure all APs can ping the MikroTik’s LAN IP. Check MikroTik’s firewall rules (
IP > Firewall > Filter Rules) to allow UDP traffic on ports1812and1813from your AP subnet. - AP Compatibility: Older budget D-Link/TP-Link models may not support WPA2-Enterprise. Double-check your AP’s user manual or specs before proceeding.
- Resource Limits: The RB-951G is a mid-range device – if you have 50+ concurrent users, monitor MikroTik’s CPU/memory usage (
System > Resources) to avoid performance bottlenecks. - Test First: Validate the setup with one AP and one user account before rolling out to all devices. You can check active sessions in MikroTik’s
IP > RADIUS > Active Sessionstab.
内容的提问来源于stack exchange,提问作者kabir

