×

Warning

JUser: :_load: Unable to load user with ID: 43

JUser: :_load: Unable to load user with ID: 40

Mikrotik Login

 

If you have bought the RADIUS module, activated it and set it properly, you can use the Mikrotik login function. If you do not know whether the RADIUS module in your application is active or not, you can check it out in Clients Home.

 

If you decide to use it, you will not have to set up special accounts for technicians (with corresponding rights) on each router. Also, when a technician leaves your company, it will not be necessary for you to remove their accounts on all routers. Access to the RADIUS server is automatically configured, which enables MikroTik login for technicians (through WinBox, SSH etc., depending on the rights settings). Manual configuration of all routers is thus unnecessary, which speeds up the whole process.

 

To activate the management of technicians’ access rights to routers, you have to set the service_mikrotik_login key to 1 in Settings Syst. settings Mikrotik. By doing this, you activate the MikroTik login through RADIUS feature on all routers in the system.

 

By default, a given administrator has access to all routers.

 

If you do not want anyone to have access to a certain router (for example: main gateway or CORE router), then you can uncheck the Login of technicians to Mikrotiks via Radius box in the settings of a given router in Hardware Routers All. If this box is not checked, it is not possible to log in through any account created in Settings Administrators Mikrotik Login.

 

If everything is set correctly and you start RADIUS, the system automatically activates communication with the RADIUS server on all routers, sets up relevant access groups (information about individual groups’ rights must be saved directly to routers) and allows technicians to log in according to their authorization.

 

alert icon ATTENTION alert icon

 

If you want to use this function, it is necessary to check the setting of the server_ip key in Settings Syst. settings General. You have to enter here the IP address of the ISPadmin server that is accessible from all routers. This IP address will be set as the IP address of the RADIUS server on all routers. If you set it incorrectly, access to routers through RADIUS will not be possible because of a non-existent RADIUS server.

 

The MikroTik login through RADIUS feature is functional only if the RADIUS module in the ISPadmin system is activated. If it is not activated, the feature is not functional.

 

You can easily check whether and how the function works by having a technician connect to one of the routers or through WinBox - in the Radius menu and in the System / Users / Groups menu.

 

 

On this page, you can define in detail the rights of individual groups that will be used for the management of technicians’ access to routers. Then you assign individual users (technicians) to the groups you have created. You may create as many groups with various rights as possible.

 

A new group can be added by clicking on . On the page that appears, enter the name of a given group and set the individual rights the way you want. You can also modify the settings in the overview of existing groups. There is a list of rights for each group along with information about how you have configured them (icon check ok / icon check ko). You can change the configuration by clicking on individual icons. 

 

You can set the following rights:

 

local A given group of technicians is / is not allowed to log in through a local console.
telnet A given group of technicians is / is not allowed to log in through telnet.
ssh A given group of technicians is / is not allowed to log in through SSH.
ftp A given group of technicians is / is not allowed to log in through FTP. Such technicians can read, write and delete.
reboot A given group of technicians is / is not allowed to reboot a router.
read A given group of technicians is only allowed to read. No configuration changes are possible.
write A given group of technicians is / is not allowed to modify configurations (with the exception of user management - setting up further user accounts for access to routers). If you want to allow this group to read as well, you have to modify the read item accordingly.
policy A given group of technicians is / is not allowed to set up further administrator accounts for access to routers.
test A given group of technicians is / is not allowed to carry out the following tests: ping, traceroute, bandwidth-test, wireless scan, sniffer a snooper.
web A given group of technicians is / is not allowed to log in through the web interface.
winbox A given group of technicians is / is not allowed to log in through WinBox.
password A given group of technicians is / is not allowed to change passwords to individual user accounts.
sensitive A given group of technicians is / is not allowed to see sensitive data, such as passwords, wireless keys etc.
api A given group of technicians is / is not allowed to log in through API.
sniff A given group of technicians is / is not allowed to use a sniffer utility.

 

You can edit a particular group by clicking on icon edit.

You can delete a particular group by clicking on icon check ko grey.

 

 

You can add a new user (technician) by clicking on . Enter the login name and password of a given technician on the page that appears. Since every single user has to belong to a certain group (with a given set of rights), assign this technician to a particular group. Furthermore, you can add a note to them. Finish the process by clicking on Save.

 

The overview of users contains the following details: user, group and note.

 

You can edit a particular user by clicking on the icon edit icon.

You can delete a particular user by clicking on the icon check ko grey icon.

 

Creating a standalone invoice

Read more ... (index.php?option=com_content&view=article&id=1159&...

Removing records from ISPadmin

Delete client Deleted client is not deleted from the system, instead its rec...

Add new / Edit existing Service

If you have added a new client, it just a contact which is not linked to any ac...

System Variables

Read more ... (index.php?option=com_content&view=article&id=1380&...

Accepting Cash Payment

overpayments (index.php?option=com_content view=article id=1088:overpaymen...

Edit invoice

Modify an invoice changing the following: Title Item description ...

No permission for adding overpayment into client´s credit

If you are trying to add overpayment, and see Permission denied message you h...

Limited data consumed / Traffic graphs are high

If you experience one/both of the following problems Limited data gets consum...

Suspension of service

The function of suspending a client serves to temporarily block the service with...

How to display client portal login credentials on an invoice

In Invoicing Settings Invoice Groups, while adding a new group (+ Add new group)...

Creation of client number

While adding a new contact to the system, you will be offered first unused clien...

Add New Contact

a requested service in Client card (index.php?option=com_content view=article...

Return of overpayment

Bulk order (index.php?option=com_content view=article id=628:returned catid=488:...

Send invoices by email

Invoices get sent in PDF automatically upon their issuing. Sending via both, reg...

Entering an address

You have the following options to enter address: Fill in respective fields: S...

More than 1 item in email or phone number fields

You will be able to add more items in every field in the system designed for ema...

PING to client does not work

PING to client function is off by default. It is to reduce network load which in...

Charging clients for tariff changes

You might want to charge clients, for example, when they decide to change to ...

One-time invoice for a service provided in a certain time period

If you want to issue a one-time invoice for a certain service that is provide...

How to give a discount

Options for discount of regular service rate are as follows: Tariff rate dis...

VAT missing on a cash receipt

If the client pays for the invoice in cash, VAT tax is not stated on the cash re...

How to send a client an email containing all of their unpaid invoices

If you want to send a particular client an email containing all of their unpaid ...

How to issue an expenditure cash slip

The system issues an expenditure cash slip when overpayments are refunded in ...

How to assign an IP address pool to a client

When editing/adding the Internet service (index.php?option=com_content view=arti...

Filtering clients base on their invoicing

Invoicing is related to services, not clients. A client can have e.g. 2 active s...

Displaced invoice margin

If invoice margins are printed incorrectly you have to check print settings of P...

Use of IP address

To find out, which client used a certain IP address in specified time, go to ...

Lookup by phone number

You can use http://ISPadmindomain.com/new/www/find-client-by-phone-number/?numbe...

How to increase internet speed in off-peak hours

If you want to increase a client’s Internet speed in off-peak hours...

Is it possible to set an installation fee discount anywhere in the system?

No, it is not. You cannot enter such a discount to the system at the moment. ...

How to add a NAT IP address

A NAT IP address can be added in the Client card. When you are editing the In...

Suspension of the internet service at the client's request

If your client contacts you and wants you to temporarily suspend the Internet...

Is it possible to set a specific speed for IPTV service?

No, it is not possible. You cannot set up special speed profiles for the IPTV...

How to add supplementary information to contact emails and phone numbers

If you need to add supplementary information to a client's email address and ...

Is it possible to export/print out all the contracts of a client at once?

No, it is not possible. Each contract is unique. It is a single file and it i...

«
»

CONTACT

NET service solution, s.r.o.
Žerotínova 3056/81a
787 01 Šumperk
Czech Republic