TanodTools
EN

MikroTik PPPoE server generator

Set the customer interface, address pool and speed plans, and get a complete RouterOS PPPoE server with profiles, a secrets template and optional RADIUS.

Runs in your browser; nothing you type leaves your device

Server
Authentication
Speed plans (profiles)
    The first plan is the server's default profile and the one the generated accounts use.
    Accounts and options

    Generates RouterOS v7 syntax (also valid on v6). Secrets get placeholder passwords on purpose; the page never asks for real ones. IPv4 only; IPv6 prefix delegation for PPPoE is not covered. MikroTik and RouterOS are trademarks of SIA Mikrotīkls. This tool is independent and not affiliated with or endorsed by MikroTik.

    How to set up a PPPoE server on MikroTik

    1. Enter the customer-facing interface (an Ethernet port, a bridge or a VLAN) and a service name.
    2. Give the customer address pool as a network, the DNS servers, and one profile per speed plan with its upload and download rate.
    3. Choose authentication, RADIUS and NAT, set how many placeholder accounts to create, and copy or download the script. Replace every CHANGE_ME before customers connect.

    Anatomy of a RouterOS PPPoE server

    A PPPoE server on RouterOS is four pieces. An IP pool holds the customer addresses. PPP profiles describe each plan: the router's local address on every session, the pool to take remote addresses from, the DNS servers to hand out and the rate-limit that becomes the customer's queue. The PPPoE server itself listens for discovery requests on the customer-facing interface. Secrets, or a RADIUS server, decide who may log in and with which profile.

    Each session is a point-to-point link, so customers don't need a subnet of their own: the router uses one local address for all sessions and each customer gets a single address from the pool. That is why the customer interface needs no IP address and no DHCP server; on a bridge or VLAN shared with other services, keep PPPoE and IP traffic apart.

    Tips

    • Want plans with burst? Work out the values with the burst calculator; it prints the full rate-limit string for a profile or RADIUS.
    • Customers behind separate VLANs per tower or building? Create the VLANs with the VLAN generator and run one PPPoE server per VLAN, or a bridge over them.
    • Protect the router itself with the firewall generator: customer-facing interfaces should not reach WinBox or SSH.

    Questions

    How do the rates in a PPP profile work?

    The profile's rate-limit is written rx/tx from the router's point of view: rx is what the router receives from the customer (their upload) and tx is what it sends (their download). When a session comes up, RouterOS creates a dynamic simple queue with those limits. RADIUS can override it per customer with the Mikrotik-Rate-Limit attribute.

    Why are the passwords CHANGE_ME?

    Customer passwords are secrets, and a configuration generator has no business knowing them. The script creates the accounts with obvious placeholders so the structure is ready; set real passwords on the router, import them from your billing system, or let a RADIUS server handle authentication.

    What do only-one and one-session-per-host do?

    only-one on the profile stops the same username from having two sessions at once. one-session-per-host on the server stops one MAC address from opening several sessions. Together they prevent most account sharing.

    Why is the MTU 1480?

    PPPoE adds an 8-byte header inside the Ethernet frame, so the most a session can carry over a standard 1500-byte link is 1492. RouterOS defaults to 1480, which leaves room for VLAN tags and odd CPE behaviour; change-tcp-mss in the profile then clamps TCP so large packets don't get fragmented.

    Which authentication methods should I allow?

    CHAP and MS-CHAPv2 don't send the password in clear text. PAP does, and is only worth enabling for old CPEs that support nothing else. RADIUS works with all of them, though some RADIUS backends need PAP to check hashed passwords.

    Is any of this sent anywhere?

    No. The script is generated in your browser.