MikroTik + Subscriber Management: The Complete Integration Guide
17 March 2025 · 8 min read
MikroTik RouterOS is the backbone of most ISP networks in East Africa. It is powerful, affordable, and widely understood. But RouterOS alone is not a subscriber management system. When you have more than 50 clients, you need the two to talk.
What the integration enables
Once your MikroTik is connected to a billing platform:
- **Auto-suspend**: when a subscriber's account lapses, their PPPoE credentials are disabled or their IP is moved to a walled-garden hotspot automatically
- **Auto-reconnect**: the moment a payment clears, the account is reinstated -no human touch required
- **Bandwidth enforcement**: package changes are pushed to the router in real time using queue trees or simple queues
- **Usage monitoring**: session data (bytes in/out, session time) flows back to the billing system for reports and dashboards
API vs. Winbox scripting
There are two ways to integrate: the RouterOS API (port 8728/8729) or scripted Winbox/SSH commands.
The API approach is strongly preferred. It is faster, more reliable, and does not require leaving Winbox sessions open. All serious billing platforms use the API.
The API uses a binary protocol over TCP. Port 8728 is unencrypted; 8729 uses TLS. Always use 8729 when the billing platform is off-premises.
Required RouterOS configuration
On your MikroTik:
1. Create a dedicated API user with limited permissions (read + write on PPP and queues, no Winbox/SSH) 2. Enable the API service on port 8729 with TLS 3. Restrict the API user to the IP range of your billing platform 4. Test connectivity: telnet ROUTER_IP 8729 from the billing server should connect
PPPoE secrets management
Most ISPs use PPPoE for subscriber authentication. The billing platform manages the PPPoE secret table -creating a secret for each subscriber, updating the profile when the package changes, and disabling the secret when the account lapses.
A key configuration detail: set the PPPoE service to look up credentials in the "Local" database, not RADIUS, unless you are running a separate RADIUS server. Metron supports both local PPPoE secrets and RADIUS (FreeRADIUS / Radsec) depending on your infrastructure.
Multi-router deployments
ISPs with more than one site often have multiple MikroTik routers. Your billing platform needs to support connecting multiple routers, and it needs to know which subscriber is served by which router -otherwise suspend/reconnect commands go to the wrong device.
Metron supports unlimited routers per account, with per-subscriber router assignment managed in the subscriber profile.
Troubleshooting common issues
Reconnect command sent but subscriber stays suspended: check whether the API command succeeded (audit log in the billing platform) and whether the PPPoE secret was actually enabled. RouterOS sometimes has stale sessions that need to be flushed with: /ppp active remove [find]
Bandwidth profiles not updating: ensure the billing platform is pushing queue changes and that the MikroTik user has write permission on /queue.
API connections dropping: add a keepalive interval in your billing platform's router connection config. RouterOS closes idle API connections after a timeout.