MikroTik setup
This page shows the MikroTik settings needed to work with Farava. First register the router in the panel so you have the server address and shared secret. Each step is shown in WinBox and as a terminal command.
1. Add Farava as the RADIUS server
Section titled “1. Add Farava as the RADIUS server”In WinBox, go to Radius and add a new entry:
| WinBox field | Value |
|---|---|
| Service | ppp (and hotspot for Hotspot) |
| Address | The Farava RADIUS server address (from the NAS registration page) |
| Secret | The same shared secret registered in Farava |
| Authentication Port | 1812 |
| Accounting Port | 1813 |
| Src. Address | The same RADIUS source IP you registered in Farava |
/radius add service=ppp address=FARAVA_SERVER_IP secret="SHARED_SECRET" \ authentication-port=1812 accounting-port=1813 src-address=NAS_SOURCE_IP2. Turn on accounting
Section titled “2. Turn on accounting”In PPP → Secrets → PPP Authentication&Accounting (or PPP → AAA):
- turn on Use Radius;
- turn on Accounting;
- set Interim Update to
5m.
/ppp aaa set use-radius=yes accounting=yes interim-update=5mAlso make sure there is no local PPP Secret on the router for the subscriber’s username; otherwise the router answers by itself and never asks Farava.
3. Accept disconnects from Farava
Section titled “3. Accept disconnects from Farava”For suspension and quota exhaustion to close an active session, the router must accept Disconnect/CoA requests from Farava.
In WinBox: Radius → Incoming, turn on Accept and set Port to
3799.
/radius incoming set accept=yes port=3799Enter the same port in Farava under the router’s Advanced settings as the CoA / Disconnect port, and turn on Supports session disconnect.
4. Restrict the firewall
Section titled “4. Restrict the firewall”In IP → Firewall → Filter Rules, add a rule in the input chain before
the general drop rule so port 3799 is open only to the Farava server:
/ip firewall filter add chain=input action=accept protocol=udp \ src-address=FARAVA_SERVER_IP dst-port=3799 \ comment="Allow Farava RADIUS Disconnect"Never open port 3799 to the whole internet. If there is NAT between Farava and the router, use the address the router actually sees.
5. Test it
Section titled “5. Test it”- Enable the router in Farava.
- Connect with a test subscriber.
- See the subscriber online in PPP → Active Connections on the router and in Network → Sessions in Farava.
- On the router’s page in Farava, Live RADIUS status should be LIVE.
- Suspend the test subscriber’s service and check that they disappear from Active Connections a few seconds later. (This only happens in enforce mode.)
- Resume the service.
Where does the speed limit come from?
Section titled “Where does the speed limit come from?”Farava does not create queues on the router and never connects to the router
API. When a subscriber signs in, Farava sends the plan speed in the RADIUS
reply and MikroTik itself creates a dynamic queue for that session. See
the queues under Queues → Simple Queues or with /queue simple print. If
no queue is created, the system is probably still in
observe mode.