How to give a PPPoE customer a static IP on MikroTik
Last updated: 2 October 2026
Most PPPoE customers take whatever address the pool gives them. Some need the same address every time: a shop with cameras, an office with a server, a customer who pays for a public IP. On MikroTik that is one setting on the customer's secret.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
Set the address on the secret
/ppp secret set [find name=customer1] remote-address=10.10.10.200Or when creating the customer:
/ppp secret add name=customer1 password=StrongPass1 service=pppoe profile=5M remote-address=10.10.10.200The address on the secret is used instead of the pool named in the profile. Everything else, including the speed, still comes from the profile. The customer gets the new address at the next login, so end the open session:
/ppp active remove [find name=customer1]
/ppp active print where name=customer1Keep fixed addresses outside the pool
If 10.10.10.200 is also inside the pool, the router may hand it to another customer first. Your fixed customer is then refused until that address is free. Reserve a part of the range for fixed addresses and shrink the pool to the rest:
/ip pool set [find name=pppoe-pool] ranges=10.10.10.2-10.10.10.199Now .2 to .199 are handed out automatically and .200 to .254 are yours to assign by hand. Write the customer's name in the secret's comment, and never give the same address to two secrets: the second one to log in fails.
Private or public?
| Fixed private address | Fixed public address | |
|---|---|---|
| Example | 10.10.10.200 | An address from a block your upstream provider routes to you |
| Good for | Finding the customer in your own network, firewall rules, port forwarding to them | A customer who must be reachable from the internet directly |
| NAT | Still behind your NAT | Must not be masqueraded |
Giving a public address
You can only hand out public addresses that your upstream provider routes to your router. Ask them for a routed block; an address you invent will not work. Then:
- Set it as
remote-addresson the secret, as above. The router adds the route to the customer by itself when the session comes up. - Make sure your NAT rule only covers the private range, so the public customer is not hidden behind your own address:
/ip firewall nat print
/ip firewall nat add chain=srcnat src-address=10.10.10.0/24 out-interface=ether1 action=masqueradeA masquerade rule with no src-address would also catch the public customer; replace it with one like the above.
- Check your forward firewall. The usual rule that drops new connections from the internet also drops them for this customer. Allow traffic to the public address if the customer is meant to be reachable, and remember that they are then exposed and need their own firewall. See basic firewall.
The cheaper alternative: forward a port
If the customer only needs one camera recorder reachable from outside, a fixed private address plus a port forwarding rule on your router does the job without a public address per customer.
With RADIUS
When logins are checked by a RADIUS server, secrets on the router are not used. The server sends the fixed address in its reply with the Framed-IP-Address attribute, and the router gives the session that address. A pool can be named the same way with Framed-Pool. See MikroTik RADIUS attributes.
/ppp aaa set use-radius=yesThe rule about the pool still applies: the fixed addresses must be outside the range the router hands out by itself.
Where RadiusNest fits
In RadiusNest a customer can be given a static IP address taken from a pool you define per router, and that address is sent to the router at each login. The routed public block, the NAT rule and the firewall remain your own work on the router; RadiusNest does not change them.
Start the free trial See pricing
Questions and answers
Does a static IP customer still get the profile speed?
Yes. Only the address comes from the secret. The speed and other settings still come from the PPP profile.
Why can my static IP customer not connect?
Most often the address is in use by someone else because it is still inside the pool, or two secrets were given the same address.
Can I give a customer a whole public address without NAT?
Yes, if your upstream provider routes that address to you. Set it as remote-address and make sure your masquerade rule does not cover it.