Standards-based AAA reading directly from Postgres. Managed FreeRADIUS 3.x on hardened Ubuntu. Ruckus, MikroTik, Cisco, Huawei — anything speaking RFC 2865. Endpoints and shared secrets are issued during onboarding, never in public docs.
| USER | FRAMED IP | NAS | DOWN | UP | DUR |
|---|---|---|---|---|---|
| ahmed.almansoori | 10.44.12.108 | MikroTik-01 | 4.8 GB | 312 MB | 3h 41m |
| yousef.ibrahim | 10.44.12.204 | MikroTik-01 | 1.2 GB | 88 MB | 1h 12m |
| V-MCF-2841 | 10.99.4.17 | Ruckus SZ | 340 MB | 42 MB | 28m |
| noora.ali | 10.44.14.9 | MikroTik-01 | 18.4 GB | 2.1 GB | 14h 03m |
| khalid.rashid | 10.44.20.44 | Cisco BNG | 6.8 GB | 418 MB | 4h 55m |
PPPoE, IPoE, MAC, hotspot. Credentials read directly from radcheck — no ORM layer, no cache lag.
Framed-IP-Address, session-timeout, class attributes. Speed limits enforced by NAS via Vendor-Specific Attributes.
Start / interim / stop packets written to radacct. Live sessions and usage counters populated in real time.
Change of Authorization to bounce a session on plan change. Disconnect-Request to force-off a suspended user.
Assign from tenant-scoped pools. Recycle on session end. Static reservations for business subscribers.
WaaS layer routes by Called-Station-Id and sets tenant control attributes for downstream authorization.
Hardened Ubuntu. Systemd-supervised. Endpoints and shared secrets issued to your NOC during onboarding — never in public documentation.
Deliberately off the standard 1812/1813 pair — zero interference with any monitoring you already have. Actual port numbers scoped to your account.
Session-pooled. FreeRADIUS-SQL. Row-level security enforces tenant isolation at the query layer, not at the app layer.
We'll walk your MikroTik or Ruckus config live on a demo call.