Skip to main content
Version: current

aaa


user/aaa​

Type: Settings Directory

AAA settings for management logins: authentication against a RADIUS server and RADIUS accounting of management sessions. See User for the full guide.

ArgumentTypeDescription
use-radiusboolAuthenticate management logins against a RADIUS server; a /radius entry with service=login must exist. The local user database is consulted first — RADIUS is used only for user names not found locally. A Mikrotik-Group attribute in the Access-Accept selects the local group. Password authentication over RADIUS for SSH logins uses MS-CHAPv2. Default: no.
accountingboolSend RADIUS accounting Start and Stop messages when a management session logs in and out. Management-session accounting carries no bandwidth counters. Default: yes.
interim-updatetimeInterval between Interim-Update accounting messages for active sessions. Default: 0s.
default-groupenumGroup assigned to RADIUS-authenticated users when the server sends no group, or when the sent group is listed in exclude-groups. Default: read.
exclude-groupsmulti { group: enum }Groups never accepted from the RADIUS server. If the server sends one of them, the user receives default-group instead; this protects against a rogue RADIUS server granting full rights. Default: none.