Command Reference · WISP

MikroTik RouterOS PPPoE Server Commands

PPPoE server is how most WISPs authenticate and manage subscriber connections. It also happens to be exactly what your RouterOS license’s tunnel-count limit governs — here’s how it’s configured.

What It Does

A PPPoE server accepts PPPoE connection requests from customer equipment (a router or modem in bridge mode) over a given interface, authenticates each subscriber, and assigns them an IP address, turning each active session into its own PPPoE “tunnel.” This is the standard access model for a huge share of WISP and fixed-wireless ISP deployments.

Basic Syntax

Create a PPP profile
/ppp/profile/add name=subscribers local-address=10.10.0.1 remote-address=subscriber-pool

A profile defines what addressing and settings apply to sessions using it — local-address is the router’s own address for these sessions, remote-address references an IP pool subscribers get addresses from.

Add PPPoE server instance
/interface/pppoe-server/server/add service-name=isp-service interface=ether2 default-profile=subscribers disabled=no

This starts a PPPoE server listening on ether2, using the profile created above by default for connecting sessions.

Add a subscriber (secret)
/ppp/secret/add name=customer001 password=strongpassword service=pppoe profile=subscribers

A “secret” is one subscriber’s username/password credential. For larger deployments, RADIUS authentication (via /radius) replaces individually managed secrets — see our Command Reference hub as we expand coverage of RADIUS specifically.

Practical Example: Subscriber Setup

Terminal
/ip/pool/add name=subscriber-pool ranges=10.10.0.10-10.10.0.250
/ppp/profile/add name=subscribers local-address=10.10.0.1 remote-address=subscriber-pool
/interface/pppoe-server/server/add service-name=isp-service interface=ether2 default-profile=subscribers disabled=no
/ppp/secret/add name=customer001 password=strongpassword service=pppoe profile=subscribers

This gives you a working PPPoE server on ether2, issuing addresses from a defined pool, with one subscriber credential ready to authenticate.

How This Connects to Your License Level

Each active PPPoE session counts as one tunnel against your RouterOS license’s tunnel limit. Level 4 supports 200 concurrent PPPoE/PPTP/L2TP/OVPN tunnels combined, Level 5 supports 500, and Level 6 is unlimited — see our License Comparison for the exact numbers per level. If you’re running a PPPoE server as a WISP and approaching your subscriber count limit, that’s the specific number to check against.

Troubleshooting

  • Subscribers can’t connect at all — confirm the PPPoE server instance isn’t disabled=yes, and that the interface it’s bound to is actually up.
  • Connects but no internet access — check the profile’s remote-address pool isn’t exhausted, and that NAT/routing is configured for the subscriber address range, separately from the PPPoE server config itself.
  • Hitting the tunnel limit — run /ppp/active/print to see current session count against your license level’s ceiling; this is a licensing limit, not a configuration bug, and requires a higher license level to raise — see our License Upgrade guide.

⚠ Removing a profile or secret disconnects active subscribers

Editing or removing a /ppp/profile or /ppp/secret entry that’s currently in use will affect subscribers using it — potentially disconnecting active sessions. Make changes to production subscriber profiles during a maintenance window where practical.

RouterOS v6/v7 Differences

PPPoE server configuration is structurally unchanged between v6 and v7 — the same /interface/pppoe-server, /ppp/profile, and /ppp/secret menus apply in both. This is one of the areas the v7 routing redesign (covered in our v7 Upgrade Guide) does not materially affect, since PPPoE server sits in the PPP stack rather than the routing protocol stack that changed.

Technical reference

MikroTik RouterOS documentation — Command Line Interface. This page is an independent, original explanation written by our team, not an official MikroTik publication.