RadiusNest › Guides

MikroTik PPPoE customer cannot connect: causes and fixes

Last updated: 2 October 2026

A customer calls: the internet light is off and their router shows an error. PPPoE failures fall into two groups, and the error on the customer side tells you which one you have. Then the router log tells you the exact reason.

Two kinds of failure

Customer seesMeaningLook at
Error 691, "authentication failed", "wrong username or password"The server answered and refused the loginThe secret, its profile and the address pool
Error 651 or 678, "no response", "server not found", stuck on "connecting"The customer's router never heard from the serverCable, link, interface, bridge, service name

Read the log first

/log print where topics~"ppp"

If the customer's attempts appear in the log, the two sides can hear each other and the problem is the login. If nothing appears when the customer retries, the request is not reaching the server.

For more detail, turn on debug logging while the customer tries again:

/system logging add topics=pppoe,debug
/system logging add topics=ppp,debug
/log print follow where topics~"ppp"

Remove the two logging rules afterwards (System → Logging in Winbox). They fill the log quickly.

Login refused (error 691)

/ppp secret print where name=customer1
/ppp active print where name=customer1
  • Wrong password or username. Names are case sensitive and a space at the end counts. Set the password again and have the customer retype it: /ppp secret set [find name=customer1] password=NewPass1
  • The secret is disabled. It shows an X in the list.
  • Wrong service. The secret's service must be pppoe or any.
  • Locked to another device. If caller-id holds a MAC address, only that device may log in. After the customer replaces their router, clear it: /ppp secret set [find name=customer1] caller-id=""
  • Already online. With only-one=yes in the profile an account holds one session. A second device using the same login, or a stale session, gets in the way. Remove the old session with /ppp active remove [find name=customer1].
  • The profile is missing or wrong. A secret that points to a profile with no addresses cannot finish connecting.
  • The pool is empty. When every address is in use, new customers are refused while old ones stay online.
/ppp profile print
/ip pool print
/ip pool used print

Widen the pool range if it is full. A customer with a fixed address needs that address to be free: see static IP for a PPPoE customer.

No answer from the server (error 651 or 678)

/interface pppoe-server server print
/interface bridge port print
/interface print
  • The server is disabled or was removed.
  • Wrong interface. If the customer port is inside a bridge, the PPPoE server must run on the bridge, not on the port.
  • Service name. If the customer's router has a service name filled in, it must match the server's service-name. An empty service name on the customer side matches any server.
  • The link is down. Check that the port shows as running, and the cable, the wireless link or the switch in between. A managed switch with the wrong VLAN blocks PPPoE silently.
  • The customer's WAN is not set to PPPoE, or the cable is in a LAN port. See PPPoE client setup.

Connects, then drops or will not browse

  • Drops every few minutes: a poor link, or two devices fighting over one account.
  • Connected but some sites hang: packet size. See PPPoE MTU and MSS.
  • Connected but nothing opens: the NAT rule does not cover the customer's address, or the profile has no DNS server.

Where RadiusNest fits

With RadiusNest the login is checked centrally, so the reason for a refusal is in one place for all your routers: wrong password, package ended, data used up or already online. The live list shows who is connected and lets you disconnect a stuck session. It does not fix cables, bridges or service names; those stay on the router.

Start the free trial See pricing

Questions and answers

What does error 691 mean on a PPPoE connection?

The server refused the login. Usually the username or password is wrong, the account is disabled or expired, or the same account is already online elsewhere.

What does error 651 or 678 mean?

The customer's device got no answer from a PPPoE server. Look at the cable or link, the interface the server runs on and the service name.

How do I see why a PPPoE login failed on MikroTik?

Run /log print where topics~"ppp". For more detail add logging rules for the pppoe and ppp topics with debug, and remove them when done.

Related guides

Start the free trial See pricing