You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Mikrotik路由器配置热点及Radius,为其他无线路由器提供账号密码?

Absolutely, you can use the built-in RADIUS server on your MikroTik RB-951G to handle user account authentication for your D-Link/TP-Link wireless routers scattered across your multi-story building. Let’s break down the setup process and key considerations to make this work smoothly:

1. First: Confirm Feasibility

MikroTik RB-951G comes with a native RADIUS server that supports standard authentication protocols like PAP and CHAP. Most modern D-Link and TP-Link small-business/home wireless routers support WPA2-Enterprise (802.1X) authentication, which relies on RADIUS for user validation. As long as your APs support this mode, the setup is fully achievable.

2. Step-by-Step MikroTik RADIUS Server Configuration

Enable & Configure the RADIUS Server

  1. Log into your MikroTik via Winbox or WebFig.
  2. Navigate to IP > RADIUS, then click the Settings tab.
    • Check the Enabled box to turn on the RADIUS server.
    • Under Clients, add the IP addresses (or entire subnet, e.g., 192.168.1.0/24) of all your wireless APs.
    • Set a Shared Secret (e.g., MySecureRadiusKey123) – this must match the secret you’ll configure on each AP.
    • Leave default ports (1812 for authentication, 1813 for accounting) unless you’ve modified them elsewhere.

Create User Accounts

  1. Still in IP > RADIUS, switch to the Users tab.
  2. Click the + button to add a new user:
    • Enter a Username and Password for the hotspot user.
    • Under Service, select wireless (this maps to 802.1X wireless authentication).
    • Repeat for all user accounts you need.

Optional: Enable Accounting (for Usage Tracking)

If you want to log user connection duration or data usage:

  • In the RADIUS Settings tab, check Accounting.
  • Ensure your APs also have RADIUS accounting enabled (we’ll cover this in the AP setup step).

You’ll need to repeat this process for every AP:

  1. Log into the AP’s web management interface.
  2. Navigate to Wireless Security settings.
  3. Select WPA2-Enterprise (802.1X) as the security mode (avoid WPA/WPA2 mixed mode for better compatibility).
  4. Input the following RADIUS details:
    • RADIUS Server IP: The LAN IP of your MikroTik RB-951G (e.g., 192.168.1.2).
    • Shared Secret: The same secret you set on the MikroTik RADIUS server.
    • Authentication Type: Choose PAP or CHAP (MikroTik supports both; PAP is more widely compatible with consumer APs).
  5. (Optional) Enable RADIUS Accounting if you turned it on in MikroTik, using port 1813.
  6. Save settings and reboot the AP to apply changes.
4. Key Troubleshooting & Best Practices
  • Network Connectivity: Ensure all APs can ping the MikroTik’s LAN IP. Check MikroTik’s firewall rules (IP > Firewall > Filter Rules) to allow UDP traffic on ports 1812 and 1813 from your AP subnet.
  • AP Compatibility: Older budget D-Link/TP-Link models may not support WPA2-Enterprise. Double-check your AP’s user manual or specs before proceeding.
  • Resource Limits: The RB-951G is a mid-range device – if you have 50+ concurrent users, monitor MikroTik’s CPU/memory usage (System > Resources) to avoid performance bottlenecks.
  • Test First: Validate the setup with one AP and one user account before rolling out to all devices. You can check active sessions in MikroTik’s IP > RADIUS > Active Sessions tab.

内容的提问来源于stack exchange,提问作者kabir

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:20:57