Register a router (NAS)
A NAS is the router your subscribers connect through — in practice a MikroTik router. Every router that should authenticate subscribers against Farava is registered once in the panel and then configured on the router itself.
1. Register the router in the panel
Section titled “1. Register the router in the panel”-
Go to Network → NAS / Routers and select Register NAS.
-
Fill in the form:
Field Meaning Device name A name colleagues recognise, for example “Main router — Shahr-e Naw”. RADIUS source IP The address the router sends RADIUS packets from. Unique per router. Management IP Optional; the address staff use to manage the router. Shared secret The password the router and Farava use to recognise each other. Generate secret creates a strong one. 6 to 128 characters, no spaces or quotes. Interim accounting interval How often, in seconds, the router reports usage for active sessions. The default suits most networks. -
Under Advanced settings, if Farava should be able to disconnect sessions remotely (needed for suspension and quota exhaustion):
- CoA / Disconnect address — the router address Farava sends disconnect requests to;
- Port — usually
3799; - turn on Supports session disconnect;
- turn on Supports live speed changes (CoA) only once you have tested it.
-
Select Register NAS.
2. Configure the router
Section titled “2. Configure the router”After registering, the NAS registered successfully page shows the values to enter on the router: RADIUS server, Authentication port (1812), Accounting port (1813), and CoA / Disconnect port. Use Copy settings and enter them on the router as described in MikroTik setup.
If you see RADIUS server address unavailable, the Farava server’s address for routers has not been set yet; contact the Farava team.
3. Enable the router
Section titled “3. Enable the router”A new router is registered disabled, so no traffic is accepted from it before it is ready. Once the router is configured:
- Open the router under NAS / Routers.
- Under Security and availability, select Enable device.
From then on Farava accepts sign-in and accounting requests from this router.
4. Check that it works
Section titled “4. Check that it works”On the router’s page, look at Live RADIUS status:
| Status | Meaning |
|---|---|
| LIVE | RADIUS packets are arriving from this router. |
| STALE | Packets used to arrive but none have for a while. |
| NEVER SEEN | Nothing has arrived yet; check the router settings, address, or secret. |
Last RADIUS activity shows the latest authentication, accounting start, interim update, and accounting stop separately. If you see authentication but no Accounting Start, accounting is turned off on the router — see MikroTik setup.
Disable a router
Section titled “Disable a router”Disable device stops accepting RADIUS traffic from this router. Sessions in progress are not interrupted, but new sign-ins through this router are refused.
Rotate the shared secret
Section titled “Rotate the shared secret”If the secret has leaked or been lost, under Security and availability select Rotate secret and generate a new one. Change the same secret on the router straight away — until both sides match, subscriber sign-ins through this router are rejected. Do this at a quiet time.