MikroTik RADIUS attributes: rate limit, data and time limits
Last updated: 2 October 2026
When a MikroTik router asks a RADIUS server about a login, the reply can carry the limits for that session. These are the attributes that matter for hotspot and PPPoE, and what each does.
The attributes you will use
| Attribute | Effect on the router |
|---|---|
Mikrotik-Rate-Limit | Speed for the session, in the same form as a profile rate-limit, for example 2M/5M (upload/download). |
Session-Timeout | Seconds until the session is closed. Used for time left and for validity. |
Idle-Timeout | Seconds without traffic before the session is closed. |
Mikrotik-Total-Limit | Total bytes (up plus down) the session may use. With Mikrotik-Total-Limit-Gigawords for more than 4 GB. |
Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit | Byte limits per direction. |
Framed-IP-Address | A fixed address for this user. |
Framed-Pool | The router pool to take the address from. |
Mikrotik-Address-List | Adds the user's address to a firewall address list while online. |
Mikrotik-Group | The hotspot user profile or PPP profile to apply. |
Acct-Interim-Interval | How often the router reports usage during a session. |
Mikrotik-Rate-Limit in full
2M/5M 3M/8M 1500k/4M 10/10 8 1M/2MIn order: speed, burst speed, burst threshold, burst time, priority, guaranteed minimum. Only the first part is required. The first number of each pair is the direction from the customer to the router (upload).
Data limits above 4 GB
The byte attributes are 32-bit, so they stop at about 4.29 GB. For more, the server sends the matching Gigawords attribute as well: each unit of Gigawords adds 4,294,967,296 bytes.
Accounting
The router reports each session's start, updates and stop, with bytes and seconds. Turn it on in the hotspot profile and for PPP:
/ip hotspot profile set [find] use-radius=yes radius-accounting=yes radius-interim-update=5m
/ppp aaa set use-radius=yes accounting=yes interim-update=5mDisconnecting a user from the server
For the server to end a session (for example when a package runs out), the router must accept its requests:
/radius incoming set accept=yes port=3799See what the router received
/system logging add topics=radius,debug
/log print where topics~"radius"Remove the logging rule when you are done; it is noisy.
Where RadiusNest fits
You do not have to work with attributes yourself. In RadiusNest you fill in a package (speed, data, time, validity) and the right replies are sent for each login, including data limits above 4 GB and disconnecting a user whose package has ended.
Start the free trial See pricing
Questions and answers
Which attribute sets the speed on MikroTik?
Mikrotik-Rate-Limit, a vendor-specific attribute. Its value has the same form as a rate-limit in a profile.
Why is my data limit ignored above 4 GB?
The limit attribute is 32-bit. The server must also send the Gigawords attribute for larger values.
Does a RADIUS reply override the user profile on the router?
Values sent by RADIUS apply to that session and take the place of the profile's settings for the same thing.