2
AAli Bashirسأل · Jul 2, 2026, 01:15 PM
Trying to move off password auth to EAP-TLS for our PPPoE sessions. NMM's RADIUS speaks it fine in lab but I'm nervous about MikroTik RB4011 handling client-cert exchanges at scale (we have ~14k active sessions). Anyone tried this at 10k+? What's the CPU cost look like on the router side, and did you have to bump timeouts? Also curious if the AI Engine's cert-rotation playbook is worth turning on from day 1.
#radius#eap-tls#mikrotik#pppoe
ردّان·١٬٣٥٦ مشاهدة
0
JJamal Nasrأجاب · Jul 3, 2026, 04:20 PM
Running EAP-TLS across ~9k sessions on a pair of CCR2116-12G. CPU on the routers is fine — under 25% at peak. The bigger surprise was the RouterOS session log growth, which we now rotate hourly. Everything else was uneventful.
0
LLea Marinoأجاب · Jul 6, 2026, 10:11 AM
For cert rotation, definitely turn the AI Engine playbook on from day 1. Manual rotation for 14k clients would be a nightmare. It'll batch a rotation over 4 nights automatically.
سجّل الدخول للرد. هل أنت جديد؟ أنشئ حساباً أو تسجيل الدخول.
