Net2Net-Local-RADIUS-Manager

Docker app from Chris Nortje's Repository

Overview

Local, per-WISP MikroTik PPPoE RADIUS manager. Stores data inside the mapped appdata folder. Exposes the web portal on 8080 and RADIUS authentication/accounting on UDP 1812/1813.

Net2Net Local RADIUS Manager

Standalone, per-WISP RADIUS management software for MikroTik PPPoE networks. It replaces MikroTik User Manager, integrates with the WISP's local UISP CRM, and provides branded portals for Net2Net, WISP staff, and customers.

Current milestone

The first working scaffold includes:

  • FastAPI service with health, bootstrap, dashboard, package, subscriber, router and IP-pool endpoints
  • PostgreSQL-first schema designed to coexist with the standard FreeRADIUS SQL tables
  • React/Vite web dashboard with permanent Net2Net sub-branding
  • Windows + WSL2 bootstrap scripts (no Docker)
  • Explicit boundaries for UISP sync, MikroTik API, CoA and User Manager import work

Docker / Unraid beta

The container runs the web portal, management API and RADIUS authentication/accounting service in one local WISP appliance. It persists all operational data under /data.

Ports:

  • 8080/tcp — administrator and client portal
  • 1812/udp — RADIUS authentication
  • 1813/udp — RADIUS accounting

Before starting a production container, set unique values for APP_SECRET (32+ characters), BOOTSTRAP_SUPERADMIN_PASSWORD, BOOTSTRAP_WISPADMIN_PASSWORD, and RADIUS_SHARED_SECRET. The initial administrator passwords are used only if the database is empty. Include the mapped /data directory in the Unraid backup schedule.

For a local Docker test:

Copy-Item .env.example .env
# Replace every secret in .env first.
docker compose up --build

Open http://SERVER-IP:8080. The manual Unraid import template is unraid/net2net-local-radius.xml. It is intentionally a beta template until an image registry and final public repository URL are selected.

The Super Admin can create and download consistent SQLite backups through the protected /api/system/backups endpoint. The container retains the latest 14 backups by default.

Run the development build

Web interface

cd apps/web
npm install
npm run dev

Open http://localhost:5173.

API (Windows preview)

cd apps/api
python -m venv .venv
.venv\Scripts\Activate.ps1
pip install -e ".[dev]"
Copy-Item ..\..\.env.example ..\..\.env
uvicorn app.main:app --reload --port 8000

The API uses in-memory preview data until DATABASE_URL is connected in the next milestone. Open http://localhost:8000/docs.

WSL2 services

Run PowerShell as Administrator:

.\scripts\install-windows.ps1

The installer enables WSL2/Ubuntu when needed and then installs PostgreSQL, FreeRADIUS, its PostgreSQL driver, Redis, Python and supporting tools inside Ubuntu. It intentionally does not alter any MikroTik router.

Operating model

  • One isolated installation per WISP
  • WISP-specific branding with permanent "Powered by Net2Net Local RADIUS Manager"
  • UISP is the CRM and billing source of truth
  • A confirmed UISP customer can own multiple PPPoE services
  • UISP suspension throttles every linked PPPoE service to 8k/8k
  • Packages show advertised rates while storing separate provisioned rates (for example 5/5 displayed, 6/6 provisioned)
  • Private and public address pools allocate the next available address
  • Routers are registered manually by OSPF loopback IP and use the internal RouterOS API

See docs/architecture.md for the working architecture and delivery stages.

Install Net2Net-Local-RADIUS-Manager on Unraid in a few clicks.

Find Net2Net-Local-RADIUS-Manager in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.

Open the Apps tab on your Unraid server Search Community Apps for Net2Net-Local-RADIUS-Manager Review the template variables and paths Click Install

Download Statistics

50
Total Downloads

Related apps

Details

Repository
botchris/net2netradius:latest
Last Updated2026-09-17
First Seen2026-09-17

Runtime arguments

Web UI
http://[IP]:[PORT:8080]
Network
bridge
Shell
sh
Privileged
false

Template configuration

Web portalPorttcp

Administrator and customer portal.

Target
8080
Default
8080
Value
8080
RADIUS authenticationPortudp

MikroTik RADIUS authentication port.

Target
1812
Default
1812
Value
1812
RADIUS accountingPortudp

MikroTik RADIUS accounting port.

Target
1813
Default
1813
Value
1813
Application dataPathrw

Persistent database, branding, and backups. Include this folder in Unraid backups.

Target
/data
Default
/mnt/user/appdata/net2net-radius
Value
/mnt/user/appdata/net2net-radius
Application secretVariable

A unique random value, at least 32 characters. Never reuse it between WISPs.

Target
APP_SECRET
Initial Super Admin passwordVariable

Used only on the first start, when the database is empty.

Target
BOOTSTRAP_SUPERADMIN_PASSWORD
Initial WISP Admin passwordVariable

Used only on the first start, when the database is empty.

Target
BOOTSTRAP_WISPADMIN_PASSWORD
RADIUS shared secretVariable

Must match every MikroTik /radius secret. Use a unique long value per WISP.

Target
RADIUS_SHARED_SECRET
UISP / UNMS server URLVariable

Optional UISP server address, for example https://uisp.example.net.

Target
UISP_BASE_URL
UISP / UNMS API tokenVariable

Optional UISP API token for CRM synchronisation. Leave blank when UISP is not used.

Target
UISP_API_TOKEN
Private RADIUS client networkVariable

Optional private CIDR allowed to source RADIUS requests, for example 10.10.0.0/16. Leave blank to permit only registered router addresses.

Target
RADIUS_CLIENT_NETWORK
Hide lab recordsVariable

Keep false in production.

Target
SHOW_LAB_DATA
Default
false
Value
false