Professional ISP Toolkit

Generate, manage, and deploy MikroTik configs

ISP Scripts helps WISP operators, small ISPs, and network technicians turn their known network values into a readable PPPoE + RADIUS starting configuration. Review it against your topology before importing — the tool is a baseline, not a substitute for a router backup or a production change plan.

  • Free, no signup
  • Runs 100% in your browser
  • Nothing you type is sent anywhere
  • Tested on RouterOS v7.x

Code Generator

    Live preview of pppoe-config.rsc. Edit the settings below and it updates as you type.

    MikroTik PPPoE + RADIUS config generator

    Presets only fill the form with editable examples. Always replace the interface names, IP ranges, RADIUS address, and secret with your real values before generating.

    Compatibility & deployment context

    The selector changes the review note in the generated file. It does not claim that every RouterOS feature or hardware model is interchangeable.

    Interfaces

    The WAN interface faces your uplink (satellite internet, fiber, upstream router). The subscriber-side interface faces your antennas or access points — they must be two different physical or virtual interfaces on the router.

    Subscriber addressing

    This pool is only used as a fallback if your RADIUS server doesn't return a Framed-IP-Address for a session — it should normally sit in the same subnet as the gateway IP above.

    RADIUS (SAS4 / any RFC-2865 server)

    Leave these blank and the script will contain placeholder text instead of a real address — safe to copy for review, but it won't authenticate anything until you fill these in.

    PPPoE service & default profile

    Use a plain number with an optional K/M/G suffix, e.g. 512k or 5M — these become the rx-rate/tx-rate RouterOS reads from the router's own perspective (upload here is what the subscriber sends).

    Hardening
    pppoe-config.rsc
    
            
    Before you import: export a backup from the router, confirm that WAN and subscriber interfaces are different, verify the gateway and pool are unused and in the intended subnet, confirm RADIUS ports and shared secret, then test the generated file on one reachable device before a wider rollout. A satellite/CGNAT uplink can prevent inbound access even when outbound NAT works.
    1. Export a backup before importing anything.
    2. Review the generated interfaces, IP ranges, and RADIUS values against your topology.
    3. Test on one reachable router first, then verify login, accounting, NAT, and management access.

    What this script sets up

    Five RouterOS building blocks, generated together so they actually reference each other correctly — the part that's easy to get wrong when copying commands from five different forum threads.

    01 · NAT

    A single masquerade rule on the WAN interface so every PPPoE client can reach the internet through one public IP.

    For beginners: your router has one public IP (or a private one behind CGNAT on some satellite connections), but dozens of subscribers behind it. NAT rewrites every outgoing packet so it looks like it came from the router, then rewrites the reply back to the right subscriber. Without this line, subscribers can't reach the internet at all.

    02 · RADIUS

    Registers your RADIUS server for PPP and turns on accounting with a 5-minute interim update — what billing platforms like SAS4 expect for live session data.

    For beginners: this block doesn't create subscriber accounts — it tells the router "ask this server when someone logs in." Usernames and passwords live on your RADIUS platform, not the router. Skip accounting=yes and logins still work, but your billing platform shows zero usage.

    03 · Profile

    A default PPP profile carrying your DNS servers and a rate-limit built from the upload/download fields — RouterOS reads this as rx-rate/tx-rate.

    For beginners: rx-rate/tx-rate is from the router's point of view, so rx (receive) is what the subscriber uploads, and tx (transmit) is what they download. If a subscriber's speeds look reversed, this is almost always why.

    04 · PPPoE server

    Binds the service to your subscriber-facing interface, one session per host, MTU/MRU tuned for PPPoE overhead.

    For beginners: this is the part that actually listens for login attempts on your antenna-side interface, not the WAN. "One session per host" stops a subscriber from opening multiple logins with the same credentials at once.

    05 · Firewall

    Baseline input/forward rules: drop invalid connections, and optionally close Winbox and Telnet to anyone sitting on the WAN side.

    For beginners: even after NAT works, an open router still answers management requests from anyone who can reach it. This closes Winbox and Telnet specifically on the WAN — your LAN-side access is untouched. See the router security guide for the full picture.

    Import

    Download the .rsc file, copy it to the router with Winbox's file manager, then run /import pppoe-config.rsc.

    Before you deploy: this is a starting template, not a certified fit for every topology. Review the pool range and gateway IP against your real addressing, and test on a router you can reach out-of-band before relying on it in production.

    Want the reasoning behind each line, not just the script? Read the full PPPoE + RADIUS setup guide — covers why WISPs use PPPoE over static IPs, how RADIUS accounting actually works, and the MTU/CGNAT issues that trip people up.

    Example output

    What the generator produces with the default values shown above — a full RouterOS PPPoE + RADIUS configuration, ready to import.

    pppoe-config.rsc — example
    # NAT — masquerade subscriber traffic out the WAN
    /ip firewall nat
    add chain=srcnat out-interface=ether1 action=masquerade comment="WAN masquerade"
    
    # RADIUS — authentication + accounting
    /radius
    add service=ppp address=192.168.88.10 secret=•••••••• authentication-port=1812 accounting-port=1813
    
    /ppp aaa
    set use-radius=yes accounting=yes interim-update=5m
    
    # Default profile — DNS + per-subscriber rate limit
    /ppp profile
    add name=default-radius local-address=10.10.10.1 dns-server=8.8.8.8,1.1.1.1 rate-limit=5M/10M only-one=yes
    
    # PPPoE server
    /interface pppoe-server server
    add service-name=isp-pppoe interface=ether2 default-profile=default-radius one-session-per-host=yes max-mtu=1480 max-mru=1480

    New planning tools for ISP operators

    The PPPoE generator is only one part of an ISP deployment. These tools cover the address plan, secure remote access, controlled exposure, subscriber shaping, and radio-link planning.

    WireGuard

    MikroTik WireGuard Generator creates RouterOS v7 interface, peer, address, firewall, and client-profile output for site-to-site and CGNAT deployments.

    dst-nat

    Port Forwarding Planner generates narrow dst-nat and forward rules, explains Hairpin NAT, and warns when the WAN address is in provider CGNAT space.

    VLSM

    IPv4 VLSM and overlap planning allocates different-size blocks from one pool and catches overlapping customer, tower, VLAN, and VPN networks.

    QoS

    QoS and Queue Calculator separates upload from download, generates PCQ-based Simple Queue or Queue Tree output, and explains packet-mark requirements.

    Wireless

    Wireless Link Budget calculates path loss, received level, fade margin, and first-Fresnel clearance before a WISP backhaul installation.

    New: What is MikroTik? explains how RouterOS, PPPoE, RADIUS, VLAN, QoS, VPN, and firewall tools fit together. See the complete tools collection for the assumptions, safe-use limits, and verification steps behind every output.

    Troubleshooting references

    When the generated baseline does not behave as expected, use a diagnostic sequence instead of changing several RouterOS settings at once.

    RADIUS

    RADIUS server not responding on RouterOS v7 separates discovery, routing, UDP, firewall, secret, authentication, and accounting problems.

    PPPoE

    PPPoE server configuration script guide explains how to run and verify each block before a wider rollout.

    Frequently asked questions

    How do I configure PPPoE on a MikroTik router?

    Fill in your WAN interface, subscriber-facing interface, and RADIUS server details in the form above — the generator builds the full /ip firewall nat, /radius, /ppp profile, and /interface pppoe-server server configuration for you. Download it as a .rsc file, copy it to the router, and run /import pppoe-config.rsc from the terminal. See the full setup guide for the reasoning behind each block.

    What's the difference between PPPoE and RADIUS on MikroTik?

    PPPoE is the connection protocol that authenticates a subscriber and hands them an IP address. RADIUS is a separate server your router asks "is this login valid, and what plan do they have?" — instead of storing every subscriber's password directly on the router. Most WISPs use both together: PPPoE for the connection, RADIUS for centralized authentication and usage billing.

    Why isn't my RADIUS accounting showing usage data?

    This almost always means accounting=yes is missing from /ppp aaa, or the RADIUS server isn't set up to log accounting packets on port 1813. The generator above sets this automatically with a 5-minute interim update, which is what platforms like SAS4 and GalaxyRAD expect.

    Can I use this generator for a full WISP setup, or just PPPoE?

    This page covers PPPoE + RADIUS specifically. For voucher/card-based access, use the Hotspot + RADIUS generator instead. For baseline NAT and firewall hardening on any MikroTik gateway — including ones that aren't running PPPoE or Hotspot at all — use the NAT + Firewall generator. Most WISPs end up using all three on the same router.

    Does this tool send my router's configuration anywhere?

    No. Everything runs in your browser with plain JavaScript — the interface names, IPs, and RADIUS secret you type in are never transmitted to any server. See the privacy policy for details.