MikroTik PPPoE speed limit with PPP profiles
Last updated: 2 October 2026
On a MikroTik PPPoE server the speed of a customer comes from the PPP profile the customer is in. Make one profile per plan, put each customer in the right one, and the router builds the speed limit by itself at every login.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
One profile per plan
/ppp profile add name=5M local-address=10.10.10.1 remote-address=pppoe-pool rate-limit=2M/5M only-one=yes
/ppp profile add name=10M local-address=10.10.10.1 remote-address=pppoe-pool rate-limit=5M/10M only-one=yes
/ppp profile add name=20M local-address=10.10.10.1 remote-address=pppoe-pool rate-limit=10M/20M only-one=yesThe pool pppoe-pool and the server itself are made in PPPoE server setup. Name the profile after the plan so the customer list is easy to read.
Which figure is download?
The rate-limit is written rx/tx from the router's point of view. The first figure is what the router receives from the customer, so it is the customer's upload. The second is what the router sends to the customer, so it is the download.
| rate-limit | Customer upload | Customer download |
|---|---|---|
2M/5M | 2 Mbps | 5 Mbps |
5M/10M | 5 Mbps | 10 Mbps |
512k/1M | 512 kbps | 1 Mbps |
Getting the order backwards is the most common mistake: the customer then has a fast upload and a slow download.
Put the customer in a profile
/ppp secret add name=customer1 password=StrongPass1 service=pppoe profile=5MThe queue the router makes
When the customer connects, the router adds a dynamic simple queue for that session. It is named after the session, for example <pppoe-customer1>, it is marked D (dynamic), and it disappears when the customer disconnects. You do not create or edit it.
/queue simple print where dynamic
/queue simple print statsIf the queue is there but the customer still gets full speed, FastTrack is skipping it. See speed limit not working.
Change a customer's plan
Move the secret to the other profile, then end the open session. The new speed is applied at the next login, and the customer's router reconnects within a few seconds.
/ppp secret set [find name=customer1] profile=10M
/ppp active remove [find name=customer1]The same is true when you edit the rate-limit of a profile: sessions that are already open keep the old speed until they reconnect.
A plan with burst
The rate-limit can carry burst values after the normal speed: burst speed, burst threshold and burst time.
/ppp profile set [find name=5M] rate-limit="2M/5M 4M/10M 1500k/4M 16/16"What those figures do, and how long the burst really lasts, is worked through in burst explained.
Good to know
- A profile has a speed but no end date. A secret stays valid until you disable it. See what to do with unpaid customers.
- A static simple queue that sits above the dynamic one and matches the same address is used instead of it. Keep hand-made queues away from the PPPoE address range.
- Many sessions mean many queues. Watch the processor load as the customer count grows.
Where RadiusNest fits
With RadiusNest the speed is part of the customer's package rather than of a profile on each router. At login the router is told the speed, and the optional burst, for that customer and builds the same dynamic queue. Change the package and the new speed applies at the customer's next login; the router still does the limiting.
Start the free trial See pricing
Questions and answers
Which number in a PPP profile rate-limit is download?
The second. rate-limit=2M/5M gives the customer 2 Mbps upload and 5 Mbps download, because the figures are written from the router's side.
Why did the speed not change after I edited the profile?
Open sessions keep the limit they got at login. Remove the active session and the customer reconnects with the new speed.
Can two customers in the same profile share one limit?
No. Each session gets its own queue with the full speed of the profile. A shared limit for a group needs a parent queue or PCQ.