RADIUS Explained: What It Is and How It Works for ISPs
By WISPGate: Built for Modern ISPs
RADIUS stands for Remote Authentication Dial-In User Service. It lets network access equipment exchange authentication and authorization information with a central server. A related accounting protocol carries session records. Together, these functions support AAA: authentication, authorization, and accounting. [1][2]
For an ISP, the practical questions are simple: should this subscriber connect, which service settings should apply, and what session information should be recorded?
Does your team manually update router accounts when customers pay, change packages, or need their service restored? When billing records and network settings are managed separately, keeping them aligned creates extra work. A properly integrated RADIUS setup can connect subscriber status to network access policies, reducing the need for repeated manual changes. [3][4][7]
What does RADIUS do?
Authentication: check the subscriber
In a PPPoE deployment configured to use RADIUS, the access router can send the subscriber’s authentication information to a RADIUS server rather than relying solely on locally stored accounts. MikroTik documents this capability for its PPP services, including PPPoE. [3]
Authorization: return the service settings
A successful RADIUS response can include attributes describing the service to provide. The network access server, or NAS, applies the supported settings. [1]
Capabilities depend on the equipment, access method, and configuration. For example, MikroTik documents attributes for rate limits, address pools, and session timeouts. VLAN assignment is also possible in supported deployments, including the IEEE 802.1X use described in RFC 3580. A commercial package must be translated into attributes or a profile the equipment understands. [4][5]
Accounting: collect session information
The access device sends accounting records to the server. These can contain a session identifier, duration, traffic counters, and termination cause. The information supports usage records and billing inputs; it does not create invoices or process payments. [2]
How does RADIUS work?
A simplified access exchange has four steps: [1]
- The access device sends an Access-Request. It includes information about the subscriber and connection.
- The server evaluates the request. Its configured authentication and authorization rules determine the result.
- The server replies. Access-Accept allows access, Access-Reject denies it, and Access-Challenge asks for further authentication information.
- The access device applies the accepted settings. Service attributes normally arrive inside Access-Accept; they are not a separate mandatory exchange.
The server’s back-end connections are implementation choices. For example, FreeRADIUS can use LDAP as a source of credentials and related information, or communicate with REST APIs to obtain decisions from an external system. The RADIUS protocol itself does not define an ISP’s CRM or payment workflow. [6][7]
Does RADIUS control internet speed?
RADIUS can supply a bandwidth policy; the network equipment enforces it. MikroTik’s Mikrotik-Rate-Limit is one vendor-specific example. The server must return attributes the receiving device supports, and that device must be configured to use them. [4]
For example, an ISP could map a 50 Mbps subscription to a corresponding rate-limit attribute. This describes a configured limit, not a promise that every speed test will achieve 50 Mbps.
How does RADIUS accounting work?
With accounting enabled, the NAS reports the session lifecycle: [2][8]
| Accounting status | Purpose |
|---|---|
| Start | Reports that service has begun |
| Interim-Update | Reports periodic session information while service continues |
| Stop | Reports that service has ended, with final session information |
These are status values carried in Accounting-Request packets. Interim updates can be scheduled using a supported Acct-Interim-Interval attribute or a NAS configuration. [2][8][9]
Accounting counters describe quantities such as transferred bytes and elapsed time. They do not identify every website a subscriber visited. A sudden NAS failure can also prevent a final Stop record from being generated, so an accounting record should not be treated as an infallible account of a session. [2]
Is RADIUS a billing system?
No. RADIUS handles AAA exchanges; billing software handles commercial records and payment workflows. Network equipment implements the resulting access policy. Connecting these responsibilities makes automation possible, but each integration must be configured and supported. [1][2][7][12]
For an ISP evaluating a solution, the useful questions are concrete: which access methods are supported, which attributes can the equipment enforce, how is accounting collected, and what happens to an active session when a customer pays, changes package, or is suspended?
How does RADIUS work with PPPoE and IPoE?
For PPPoE, the subscriber establishes a PPPoE connection to the access equipment; that equipment separately communicates with the RADIUS server for AAA. MikroTik’s PPP documentation describes the configuration needed to enable RADIUS authentication and accounting. [3]
RADIUS also participates in supported IPoE subscriber-management deployments. Juniper documents DHCP-based subscriber access with RADIUS and mechanisms for updating service settings through CoA or reauthentication. This is a different access process from PPPoE, so support and configuration must be checked for the particular gateway. [10][11]
Can RADIUS be automated for my subscribers?
Yes—when RADIUS is integrated with your subscriber management or billing system and supported network equipment. The practical benefit is that routine service changes can follow defined rules instead of requiring an engineer to update each account manually. [3][4][7]
For example, an integrated setup can:
- Authorize eligible subscribers: Use centrally managed account information when customers connect. [3][7]
- Apply the correct service settings: Return supported bandwidth limits or service profiles associated with the subscriber’s package. [4]
- Collect session information: Receive accounting records for usage tracking and troubleshooting. [2][8]
- Handle service changes: Request supported policy updates or disconnect an active session when required. [4][12]
If your team repeatedly handles these tasks by hand, these are useful workflows to evaluate for automation. The benefit depends on connecting the systems correctly: installing RADIUS alone does not automate payments, provisioning, or reconnection. [7][12]
Will RADIUS work with my billing software?
A billing integration connects commercial decisions to network authorization. FreeRADIUS’s REST module provides one way to connect external business logic to RADIUS processing. [7]
Consider this illustrative workflow:
- A customer pays for a subscription.
- The billing platform updates the account’s eligibility and package information.
- The RADIUS service uses that information when evaluating access.
- The access device applies the returned service settings.
The same integration could reject a future connection attempt after suspension. However, changing a database entry alone does not necessarily end an existing session. Active-session changes require an implemented mechanism, such as a supported CoA or Disconnect-Request. [12]
Automatic restoration after payment therefore depends on the billing integration, network capabilities, and reconnection process. It is not a feature that appears merely because a RADIUS server is installed. This example describes an architecture, not a verified claim about a specific product.
What is RADIUS CoA?
Change of Authorization (CoA) lets a system request changes to an existing session’s authorization. A Disconnect-Request is a separate message used to terminate a session. The receiving device acknowledges or rejects the request. [12]
The available changes vary by implementation. MikroTik, for example, documents support for changing rate limits and certain other attributes through CoA, but requires disconnection before changing an IP address, address pool, or routes. [4]
Which ports does RADIUS use?
For traditional RADIUS over UDP: [1][2][12]
| Function | Standard destination port |
|---|---|
| Authentication and authorization | UDP 1812 |
| Accounting | UDP 1813 |
| CoA and Disconnect requests | UDP 3799 |
Check the device configuration rather than assuming these values. For example, MikroTik documents a default incoming dynamic-authorization port of 1700. [4]
Can WISPGate help my ISP with RADIUS?
Still managing subscriber access separately from billing? Talk to the WISPGate team about your current setup and the tasks you want to automate.
Share which routers or access gateways you use, how subscribers connect, and what happens today when a customer pays, changes package, or is suspended. These details help identify the integrations and network capabilities your workflow requires.
Contact WISPGate to discuss RADIUS integration for your ISP.
Sources and further reading
- RFC 2865 – Remote Authentication Dial In User Service: Access exchanges, authorization attributes, and authentication port.
- RFC 2866 – RADIUS Accounting: Accounting packets, status values, counters, and accounting port.
- MikroTik – PPP AAA: PPP and PPPoE integration.
- MikroTik – RADIUS: Supported attributes, rate limits, CoA limitations, and incoming requests.
- RFC 3580 – IEEE 802.1X RADIUS Usage Guidelines: VLAN assignment attributes in applicable deployments.
- FreeRADIUS – Authentication with LDAP: LDAP as an authentication back end.
- FreeRADIUS – REST integration: Connecting external business logic. This documentation is for version 4.0.0; configuration details vary by release.
- RFC 2869 – RADIUS Extensions: Interim accounting and update intervals.
- RFC 5080 – Common RADIUS Implementation Issues and Suggested Fixes: Accounting clarifications and implementation behavior.
- Juniper – Dual-Stack Access Models in a DHCP Network: DHCP subscriber access and dynamic authorization.
- Juniper – RADIUS Reauthentication for DHCP Subscribers: Updating DHCP subscriber service settings.
- RFC 5176 – Dynamic Authorization Extensions to RADIUS: CoA, Disconnect requests, and UDP 3799.
Ready to Build a Smarter ISP?
Automate billing, streamline customer management, connect operational workflows, and gain greater visibility across your business.
Schedule a Live Demo →