Generate, manage, and deploy MikroTik configs
ISP Scripts helps WISP operators, small ISPs, and network technicians turn their known network values into a readable PPPoE + RADIUS starting configuration. Review it against your topology before importing — the tool is a baseline, not a substitute for a router backup or a production change plan.
Live preview of pppoe-config.rsc. Edit the settings below and it updates as you type.
Five RouterOS building blocks, generated together so they actually reference each other correctly — the part that's easy to get wrong when copying commands from five different forum threads.
A single masquerade rule on the WAN interface so every PPPoE client can reach the internet through one public IP.
For beginners: your router has one public IP (or a private one behind CGNAT on some satellite connections), but dozens of subscribers behind it. NAT rewrites every outgoing packet so it looks like it came from the router, then rewrites the reply back to the right subscriber. Without this line, subscribers can't reach the internet at all.
Registers your RADIUS server for PPP and turns on accounting with a 5-minute interim update — what billing platforms like SAS4 expect for live session data.
For beginners: this block doesn't create subscriber accounts — it tells the router "ask this server when someone logs in." Usernames and passwords live on your RADIUS platform, not the router. Skip accounting=yes and logins still work, but your billing platform shows zero usage.
A default PPP profile carrying your DNS servers and a rate-limit built from the upload/download fields — RouterOS reads this as rx-rate/tx-rate.
For beginners: rx-rate/tx-rate is from the router's point of view, so rx (receive) is what the subscriber uploads, and tx (transmit) is what they download. If a subscriber's speeds look reversed, this is almost always why.
Binds the service to your subscriber-facing interface, one session per host, MTU/MRU tuned for PPPoE overhead.
For beginners: this is the part that actually listens for login attempts on your antenna-side interface, not the WAN. "One session per host" stops a subscriber from opening multiple logins with the same credentials at once.
Baseline input/forward rules: drop invalid connections, and optionally close Winbox and Telnet to anyone sitting on the WAN side.
For beginners: even after NAT works, an open router still answers management requests from anyone who can reach it. This closes Winbox and Telnet specifically on the WAN — your LAN-side access is untouched. See the router security guide for the full picture.
Download the .rsc file, copy it to the router with Winbox's file manager, then run /import pppoe-config.rsc.
Want the reasoning behind each line, not just the script? Read the full PPPoE + RADIUS setup guide — covers why WISPs use PPPoE over static IPs, how RADIUS accounting actually works, and the MTU/CGNAT issues that trip people up.
What the generator produces with the default values shown above — a full RouterOS PPPoE + RADIUS configuration, ready to import.
# NAT — masquerade subscriber traffic out the WAN /ip firewall nat add chain=srcnat out-interface=ether1 action=masquerade comment="WAN masquerade" # RADIUS — authentication + accounting /radius add service=ppp address=192.168.88.10 secret=•••••••• authentication-port=1812 accounting-port=1813 /ppp aaa set use-radius=yes accounting=yes interim-update=5m # Default profile — DNS + per-subscriber rate limit /ppp profile add name=default-radius local-address=10.10.10.1 dns-server=8.8.8.8,1.1.1.1 rate-limit=5M/10M only-one=yes # PPPoE server /interface pppoe-server server add service-name=isp-pppoe interface=ether2 default-profile=default-radius one-session-per-host=yes max-mtu=1480 max-mru=1480
The PPPoE generator is only one part of an ISP deployment. These tools cover the address plan, secure remote access, controlled exposure, subscriber shaping, and radio-link planning.
MikroTik WireGuard Generator creates RouterOS v7 interface, peer, address, firewall, and client-profile output for site-to-site and CGNAT deployments.
Port Forwarding Planner generates narrow dst-nat and forward rules, explains Hairpin NAT, and warns when the WAN address is in provider CGNAT space.
IPv4 VLSM and overlap planning allocates different-size blocks from one pool and catches overlapping customer, tower, VLAN, and VPN networks.
QoS and Queue Calculator separates upload from download, generates PCQ-based Simple Queue or Queue Tree output, and explains packet-mark requirements.
Wireless Link Budget calculates path loss, received level, fade margin, and first-Fresnel clearance before a WISP backhaul installation.
New: What is MikroTik? explains how RouterOS, PPPoE, RADIUS, VLAN, QoS, VPN, and firewall tools fit together. See the complete tools collection for the assumptions, safe-use limits, and verification steps behind every output.
When the generated baseline does not behave as expected, use a diagnostic sequence instead of changing several RouterOS settings at once.
RADIUS server not responding on RouterOS v7 separates discovery, routing, UDP, firewall, secret, authentication, and accounting problems.
PPPoE server configuration script guide explains how to run and verify each block before a wider rollout.
Fill in your WAN interface, subscriber-facing interface, and RADIUS server details in the form above — the generator builds the full /ip firewall nat, /radius, /ppp profile, and /interface pppoe-server server configuration for you. Download it as a .rsc file, copy it to the router, and run /import pppoe-config.rsc from the terminal. See the full setup guide for the reasoning behind each block.
PPPoE is the connection protocol that authenticates a subscriber and hands them an IP address. RADIUS is a separate server your router asks "is this login valid, and what plan do they have?" — instead of storing every subscriber's password directly on the router. Most WISPs use both together: PPPoE for the connection, RADIUS for centralized authentication and usage billing.
This almost always means accounting=yes is missing from /ppp aaa, or the RADIUS server isn't set up to log accounting packets on port 1813. The generator above sets this automatically with a 5-minute interim update, which is what platforms like SAS4 and GalaxyRAD expect.
This page covers PPPoE + RADIUS specifically. For voucher/card-based access, use the Hotspot + RADIUS generator instead. For baseline NAT and firewall hardening on any MikroTik gateway — including ones that aren't running PPPoE or Hotspot at all — use the NAT + Firewall generator. Most WISPs end up using all three on the same router.
No. Everything runs in your browser with plain JavaScript — the interface names, IPs, and RADIUS secret you type in are never transmitted to any server. See the privacy policy for details.