RadiusNest › Guides

MikroTik RADIUS attributes: rate limit, data and time limits

Last updated: 2 October 2026

When a MikroTik router asks a RADIUS server about a login, the reply can carry the limits for that session. These are the attributes that matter for hotspot and PPPoE, and what each does.

The attributes you will use

AttributeEffect on the router
Mikrotik-Rate-LimitSpeed for the session, in the same form as a profile rate-limit, for example 2M/5M (upload/download).
Session-TimeoutSeconds until the session is closed. Used for time left and for validity.
Idle-TimeoutSeconds without traffic before the session is closed.
Mikrotik-Total-LimitTotal bytes (up plus down) the session may use. With Mikrotik-Total-Limit-Gigawords for more than 4 GB.
Mikrotik-Recv-Limit, Mikrotik-Xmit-LimitByte limits per direction.
Framed-IP-AddressA fixed address for this user.
Framed-PoolThe router pool to take the address from.
Mikrotik-Address-ListAdds the user's address to a firewall address list while online.
Mikrotik-GroupThe hotspot user profile or PPP profile to apply.
Acct-Interim-IntervalHow often the router reports usage during a session.

Mikrotik-Rate-Limit in full

2M/5M 3M/8M 1500k/4M 10/10 8 1M/2M

In order: speed, burst speed, burst threshold, burst time, priority, guaranteed minimum. Only the first part is required. The first number of each pair is the direction from the customer to the router (upload).

Data limits above 4 GB

The byte attributes are 32-bit, so they stop at about 4.29 GB. For more, the server sends the matching Gigawords attribute as well: each unit of Gigawords adds 4,294,967,296 bytes.

Accounting

The router reports each session's start, updates and stop, with bytes and seconds. Turn it on in the hotspot profile and for PPP:

/ip hotspot profile set [find] use-radius=yes radius-accounting=yes radius-interim-update=5m
/ppp aaa set use-radius=yes accounting=yes interim-update=5m

Disconnecting a user from the server

For the server to end a session (for example when a package runs out), the router must accept its requests:

/radius incoming set accept=yes port=3799

See what the router received

/system logging add topics=radius,debug
/log print where topics~"radius"

Remove the logging rule when you are done; it is noisy.

Where RadiusNest fits

You do not have to work with attributes yourself. In RadiusNest you fill in a package (speed, data, time, validity) and the right replies are sent for each login, including data limits above 4 GB and disconnecting a user whose package has ended.

Start the free trial See pricing

Questions and answers

Which attribute sets the speed on MikroTik?

Mikrotik-Rate-Limit, a vendor-specific attribute. Its value has the same form as a rate-limit in a profile.

Why is my data limit ignored above 4 GB?

The limit attribute is 32-bit. The server must also send the Gigawords attribute for larger values.

Does a RADIUS reply override the user profile on the router?

Values sent by RADIUS apply to that session and take the place of the profile's settings for the same thing.

Related guides

Start the free trial See pricing