2
AAli Bashirasked · Jul 2, 2026, 01:15 PM
Trying to move off password auth to EAP-TLS for our PPPoE sessions. NMM's RADIUS speaks it fine in lab but I'm nervous about MikroTik RB4011 handling client-cert exchanges at scale (we have ~14k active sessions). Anyone tried this at 10k+? What's the CPU cost look like on the router side, and did you have to bump timeouts? Also curious if the AI Engine's cert-rotation playbook is worth turning on from day 1.
#radius#eap-tls#mikrotik#pppoe
2 replies·1350 views
0
JJamal Nasrreplied · Jul 3, 2026, 04:20 PM
Running EAP-TLS across ~9k sessions on a pair of CCR2116-12G. CPU on the routers is fine — under 25% at peak. The bigger surprise was the RouterOS session log growth, which we now rotate hourly. Everything else was uneventful.
0
LLea Marinoreplied · Jul 6, 2026, 10:11 AM
For cert rotation, definitely turn the AI Engine playbook on from day 1. Manual rotation for 14k clients would be a nightmare. It'll batch a rotation over 4 nights automatically.
Sign in to reply. New here? Create an account or sign in.
