RadiusNest › Guides

MikroTik PPPoE: what to do with expired and unpaid customers

Last updated: 2 October 2026

A PPPoE secret has no end date, so a customer who has not paid stays online until you act. There are two ways to act: switch the account off, or let it connect into a closed corner of your network where only a notice page opens.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

The simple way: disable the secret

/ppp secret disable [find name=customer1]
/ppp active remove [find name=customer1]

The second line matters. Disabling a secret stops the next login, but a session that is already open carries on until it is removed. After payment:

/ppp secret enable [find name=customer1]

The drawback: the customer's router just shows "authentication failed". They cannot tell an unpaid bill from a fault, so they phone you.

The friendlier way: an expired profile

Here the customer still connects, but gets an address from a separate range that can reach nothing except DNS and one notice page. The examples use 10.20.0.0/24 for expired customers and a small web server of your own at 192.168.100.10 that shows the notice and how to pay.

1. Pool and profile

/ip pool add name=expired-pool ranges=10.20.0.2-10.20.0.254
/ppp profile add name=expired local-address=10.20.0.1 remote-address=expired-pool address-list=expired rate-limit=256k/256k dns-server=10.20.0.1 only-one=yes

address-list=expired puts each such customer's address into a firewall address list while they are online. The DNS server here is the router itself, so it must answer DNS:

/ip dns set allow-remote-requests=yes

2. Firewall: DNS and the notice page only

/ip firewall filter
add chain=forward src-address-list=expired dst-address=192.168.100.10 action=accept comment="expired: notice page"
add chain=forward src-address-list=expired protocol=udp dst-port=53 action=accept comment="expired: dns"
add chain=forward src-address-list=expired protocol=tcp dst-port=53 action=accept comment="expired: dns"
add chain=forward src-address-list=expired action=drop comment="expired: no internet"

New rules are added at the bottom. In Winbox, drag these four to the top of the forward rules and keep them in this order, so no earlier accept rule lets the traffic through.

3. Send web pages to the notice

/ip firewall nat add chain=dstnat src-address-list=expired protocol=tcp dst-port=80 action=dst-nat to-addresses=192.168.100.10 to-ports=80 comment="expired: notice"

4. Move the customer

/ppp secret set [find name=customer1] profile=expired
/ppp active remove [find name=customer1]

After payment, set the profile back to the customer's plan and remove the active session again so they reconnect with normal access.

What to expect

  • Only plain http:// pages are redirected. Nearly every site is HTTPS, and an HTTPS page cannot be swapped for yours; it simply fails to load. Phones and computers often notice this themselves and open the notice in a sign-in window, but not always.
  • Tell customers another way too: a message before the due date saves more calls than the notice page.
  • You must run the notice page on a server or a small computer in your network. Put your payment details and phone number on it.
  • Still manual. Someone has to move each customer on the right day, or a script has to. See scheduler and scripts for the pitfalls.

Which to use

Disable the secretExpired profile
Work to set upNonePool, profile, firewall rules and a notice page
What the customer seesA login errorA notice, when they open a plain web page
Uses an address and a sessionNoYes

For how billing fits around this, see PPPoE billing with automatic expiry.

Where RadiusNest fits

RadiusNest handles the part that is easy to forget: every customer has an end date, and when the package ends the customer is disconnected and further logins are refused automatically, on every router, until you renew. It does not provide a notice page for unpaid customers. Customers can check their own balance and end date on their account page or in the Telegram bot before they run out.

Start the free trial See pricing

Questions and answers

Why is a disabled PPPoE customer still online?

Disabling the secret only stops new logins. Remove the open session with /ppp active remove and the customer cannot reconnect.

Can I redirect HTTPS sites to my payment notice?

No. The browser expects the real site's certificate, so the page fails instead of showing your notice. Only plain http pages can be redirected.

Do expired customers still use an address from my pool?

With an expired profile they use an address from the separate expired pool. With a disabled secret they use none.

Related guides

Start the free trial See pricing