Skip to content

Register a router (NAS)

A NAS is the router your subscribers connect through — in practice a MikroTik router. Every router that should authenticate subscribers against Farava is registered once in the panel and then configured on the router itself.

  1. Go to Network → NAS / Routers and select Register NAS.

  2. Fill in the form:

    Field Meaning
    Device name A name colleagues recognise, for example “Main router — Shahr-e Naw”.
    RADIUS source IP The address the router sends RADIUS packets from. Unique per router.
    Management IP Optional; the address staff use to manage the router.
    Shared secret The password the router and Farava use to recognise each other. Generate secret creates a strong one. 6 to 128 characters, no spaces or quotes.
    Interim accounting interval How often, in seconds, the router reports usage for active sessions. The default suits most networks.
  3. Under Advanced settings, if Farava should be able to disconnect sessions remotely (needed for suspension and quota exhaustion):

    • CoA / Disconnect address — the router address Farava sends disconnect requests to;
    • Port — usually 3799;
    • turn on Supports session disconnect;
    • turn on Supports live speed changes (CoA) only once you have tested it.
  4. Select Register NAS.

After registering, the NAS registered successfully page shows the values to enter on the router: RADIUS server, Authentication port (1812), Accounting port (1813), and CoA / Disconnect port. Use Copy settings and enter them on the router as described in MikroTik setup.

If you see RADIUS server address unavailable, the Farava server’s address for routers has not been set yet; contact the Farava team.

A new router is registered disabled, so no traffic is accepted from it before it is ready. Once the router is configured:

  1. Open the router under NAS / Routers.
  2. Under Security and availability, select Enable device.

From then on Farava accepts sign-in and accounting requests from this router.

On the router’s page, look at Live RADIUS status:

Status Meaning
LIVE RADIUS packets are arriving from this router.
STALE Packets used to arrive but none have for a while.
NEVER SEEN Nothing has arrived yet; check the router settings, address, or secret.

Last RADIUS activity shows the latest authentication, accounting start, interim update, and accounting stop separately. If you see authentication but no Accounting Start, accounting is turned off on the router — see MikroTik setup.

Disable device stops accepting RADIUS traffic from this router. Sessions in progress are not interrupted, but new sign-ins through this router are refused.

If the secret has leaked or been lost, under Security and availability select Rotate secret and generate a new one. Change the same secret on the router straight away — until both sides match, subscriber sign-ins through this router are rejected. Do this at a quiet time.