跳到内容
NOS 1.2 · Aurora 现已发布——支持 24 种语言的对话式 NOCCore X100 旗舰——面向 500,000+ 用户的集群安装程序Field Engineer 伴侣应用——工单、GIS 和现场测试Netxol One 套件——NMM · CRM · ERP 统一身份部署案例·单台 Core X20 支撑 82,000 用户
Netxol
NMM

RADIUS EAP-TLS with MikroTik — anyone running this in production?

2
AAli Bashir提问 · Jul 2, 2026, 01:15 PM
Trying to move off password auth to EAP-TLS for our PPPoE sessions. NMM's RADIUS speaks it fine in lab but I'm nervous about MikroTik RB4011 handling client-cert exchanges at scale (we have ~14k active sessions). Anyone tried this at 10k+? What's the CPU cost look like on the router side, and did you have to bump timeouts? Also curious if the AI Engine's cert-rotation playbook is worth turning on from day 1.
#radius#eap-tls#mikrotik#pppoe
2 条回复·1,381 次浏览
0
JJamal Nasr回复 · Jul 3, 2026, 04:20 PM
Running EAP-TLS across ~9k sessions on a pair of CCR2116-12G. CPU on the routers is fine — under 25% at peak. The bigger surprise was the RouterOS session log growth, which we now rotate hourly. Everything else was uneventful.
0
LLea Marino回复 · Jul 6, 2026, 10:11 AM
For cert rotation, definitely turn the AI Engine playbook on from day 1. Manual rotation for 14k clients would be a nightmare. It'll batch a rotation over 4 nights automatically.
登录后回复。 初次来访? 创建账户登录