Complete Modules Guide
Every ISP Boost module, explained in plain language with step-by-step instructions - written for someone using it for the first time. The panel screens are identical between editions, so this one guide covers both Self-Hosted and Cloud.
1. First login & Dashboard
- Log in with the admin account created during setup (Self-Hosted: the setup wizard; Cloud: your signup email/password).
- You land on the Dashboard - a live snapshot: total/online/active/expired users, a status donut, top profiles by subscriber count, a 24h online-users chart, 7-day signups/revenue sparklines, wallet balance and outstanding debts, and (Admins only) server health gauges.
- Top-right Customize toggle lets you turn dashboard cards on/off - saved to your browser, so each operator can have their own layout.
- For a drag-and-drop custom dashboard instead of the built-in one, use Advanced → Dashboards admin.
2. Profiles (service packages)
A Profile is the package you sell: speed, price, validity. Create your packages before you create customers.
- Profiles → New profile.
- Basic information: name, description, Type -
prepaid/postpaidfor PPPoE customers,hotspotfor voucher-based wifi - price, Enabled. - Bandwidth: download/upload rate in bps (e.g.
6000000= 6 Mbps). This becomes the RADIUSMikrotik-Rate-Limitattribute automatically. - Expiration: amount + unit (hours/days/weeks/months) after activation.
- Optional cards you can leave at defaults for now: Burst (MikroTik queue burst), MikroTik specifics (queue priority, address-list tag), Billing cycle (monthly reset day), Reward points, Traffic rules (FUP multiplier, daily reset, carry-over), Pricing & visibility (max reseller/portal price), Hotspot & vendor specifics (separate session, IP-pool mode, Cisco QoS).
- Save. Once saved (edit mode), three more tables appear: FUP notifications (alert at a usage threshold via SMS/Email/Telegram/Webhook), Add-on packs (extra days/traffic users can buy without switching plan), Time-of-day policies (throttle/boost at set hours), and Per-reseller pricing (override cost/price per manager).
3. NAS, PPPoE & Hotspot (the router side)
This is the one part of ISP Boost that touches your MikroTik router directly, so it has its own full Winbox-and-CLI walkthrough rather than being repeated here:
- Self-Hosted edition: Device setup → NAS → RADIUS client → PPPoE → Hotspot (Winbox + CLI, step by step)
- Cloud edition: Device setup → NAS → RADIUS client → PPPoE → Hotspot (Winbox + CLI, step by step)
In short, once that's done: adding a NAS in ISP Boost is NAS → New NAS (IP, shared secret, type); after any NAS change click Reload FreeRADIUS or nothing will authenticate. The NAS list also shows live Online/RTT/Loss/Status per router, a per-NAS live RADIUS console (desktop icon on a row) for debugging, and a bulk CSV import.
4. Subscribers (Users)
This is your customer list - one row per PPPoE/Hotspot/prepaid subscriber.
4.1 Create a subscriber
- Users → New user.
- Minimum required: username, password, and a profile. That's genuinely enough - saving writes the RADIUS
radcheck/radreplyrows automatically and the customer can authenticate immediately. - Optional but common: name/contact info, Parent (owner manager) for tenancy, MAC lock, Credit user (auto-renews on the owning manager's balance), Auto renew, and Advanced/RADIUS overrides (static IP, simultaneous sessions, MikroTik overrides).
- You can also scan a CNIC/ID card photo - on-device OCR auto-fills name, ID number, DOB, gender and address.
4.2 Day-to-day operations (on a subscriber's detail page)
Click any user to open their detail page - the icon-tile grid is your one-click workflow:
- Activate - the main "sell service" dialog: units, payment method (manager/user balance/free), money collected, new expiration.
- Issue Invoice, Change Profile, Schedule Change (future-dated profile switch), Disconnect (RADIUS CoA kick), Deposit/Withdraw, Reset Traffic, Payment link, Change username.
- Tabs: Overview, Edit, Traffic, Sessions (live/past connections), Invoices/Payments/Journal, RADIUS (raw radcheck/radreply for debugging), History, Documents/FreeZone/Quota.
4.3 List-level tools
- Filters drawer and a Managers tree drawer to scope by reseller subtree; a 28-column show/hide picker for the table itself.
- Bulk actions (select rows): Activate all, Extend/Compensate days, Change profile, Change password, Enable/Disable, Disconnect, Cancel service, Deposit/Withdraw, Delete.
- CSV Import/Export - Import needs at minimum
username+password; download the Sample CSV first to see every optional column.
5. Cards & vouchers (build Hotspot + issue cards)
This is exactly how you run a walk-up/voucher-based Hotspot business. Two card types exist: Refill (a PIN that tops up an existing subscriber's balance - they keep their current plan) and User (a self-contained login baked into the card that activates a specific profile the moment it's redeemed - this is what Hotspot vouchers use).
5.1 Set up a print template (optional but recommended)
- Cards → Templates (top-right, or
/card-templates). - New template: pick a layout (e.g.
10up_a4- 10 vouchers per A4 sheet), set brand name/header/footer/terms text, colors, logo, PIN font size, and which fields to print (username/price/expiry/serial). - Preview PDF to check it, then mark it Default so new voucher batches use it automatically.
5.2 Generate a batch of Hotspot vouchers
- Cards → Generate batch.
- Type = User (for Hotspot walk-up wifi).
- Quantity (1-10,000), Target profile = the
Hotspot-type profile you created in section 2, Prefix (optional label on the codes), PIN length (6-40 characters - shorter is easier to type on a phone, but weigh that against brute-force risk on a public wifi login). - Generate. A job appears under "Recent generation jobs" - once its status flips to
done, a PDF download icon appears next to it. That PDF is your printable voucher sheet using the template from 5.1. - Print, cut, and sell/hand out the vouchers. A customer connects to your wifi, gets redirected to the ISP Boost Hotspot login page (see section 3 for the router-side wiring), and types the PIN to get online instantly.
5.3 Other card operations
- Redeem card (manual) - if a customer calls in instead of using the portal, enter their PIN + username yourself to credit/activate on their behalf.
- Transfer batch - move an unused range of cards to a reseller's stock.
- The Cards table at the bottom shows every card's state:
available/used/suspended. - For Refill cards (top-ups instead of walk-up logins): same Generate batch flow, but Type = Refill with a fixed refill value instead of a target profile.
6. Support tickets
- Tickets → New ticket to log a customer issue, or customers raise one themselves from the self-service portal (section 9).
- Tickets route to a Department (defined under HR, see section 8) and optionally a specific employee within it - leave the employee blank for "anyone in that department."
- Lifecycle:
open→ (operator replies)pending→resolved→closed. A closed ticket's new replies open a fresh ticket rather than reopening it. - Replying: toggle Internal note to keep a reply staff-only - it never reaches the customer or fires the reply webhook. Regular replies do both.
7. Customer self-service portal
This is what your subscribers see when they log into their own account (separate from your admin panel).
- Header cards: Account (plan + expiry), Balance (with a Pay/top-up button), Status (online/offline + unpaid-invoice badge).
- Usage tab: month-to-date download/upload/online-time + a per-session table.
- Invoices tab: pay outstanding invoices via your configured gateway, or download PDFs.
- Support tab: open/track their own tickets.
Enable/configure self-service under Settings → Customer portal (UCP) - signup, password recovery, captcha, auto-activate.
8. Managers & resellers
A "Manager" is anyone with panel access - your own staff, or resellers you sell bulk service to who then resell to their own customers.
8.1 Create a reseller
- Managers → New manager.
- Minimum: username, password, security group/role. Set a Parent to nest them under another reseller, or leave blank for top-level.
- For resellers specifically, set a Debt limit (so they can't overspend what they owe you) and Max users (cap on subscribers they can create).
- Assign which Profiles they can sell and at what cost/price on the manager's Profiles tab (per-manager pricing).
8.2 Running the relationship
- Deposit/Withdraw on the manager's detail page to credit or debit their wallet - this is the balance they spend from when activating their own customers.
- Login as (sign-in icon on the Managers list) impersonates that manager, useful for support.
- Managers → Tree view shows the full reseller hierarchy as a collapsible org chart.
- Roles & permissions (under Settings → Organization) controls exactly what each role can see/do - keep "Users · index all" off for reseller roles so each one stays scoped to their own subtree.
- Branding (button on a manager's detail page) lets a reseller have their own logo/colors/login page when reached via their custom domain (see section 14).
9. Inventory
Track physical stock - routers, ONUs, cables, anything you hand out or sell.
- Inventory → Categories - set up your item categories first (e.g. "Routers", "Cables").
- Inventory → Warehouses - add your stock location(s).
- Inventory → Items - create each SKU, its min-stock threshold, and whether to track individual serial numbers.
- Record stock movements: Receive (stock in), Issue (stock out, e.g. handed to a customer), Transfer (between warehouses), Adjustment (correct a count with a reason). Every movement is logged in the read-only Movements tab.
- Check the Low stock tab periodically for items at/below their threshold.
10. HR
- HR → Departments - set up your org structure first (this also feeds ticket routing in section 6).
- HR → Employees - add staff records (distinct from Manager panel logins).
- Attendance tab - manual clock in/out with status (present/absent/leave/half day/holiday).
- Leave tab - employees request time off, you approve/reject (rejecting requires a reason).
- Payroll tab - New payroll run auto-creates entries for every active salaried employee; lifecycle draft → finalized → paid, editable while draft.
11. Assets
For anything that depreciates and needs tracking - company laptops, deployed CPE, vehicles.
- Assets → Categories - set a default useful life per category (drives depreciation).
- Assets → Locations - add your physical sites.
- Add an asset, assign category/location. Depreciation (monthly, accumulated, book value) is computed automatically - no schedule to run.
- Open an asset's detail drawer for its QR label (print or download SVG for physical labeling) and to log/schedule Maintenance (recurring, "every N days", with a due-soon/overdue view on the Maintenance tab).
12. Reports
All financial reporting lives here, sharing one From/To date range (defaults to this month) with an Apply button.
- Revenue - invoiced/collected/outstanding totals + top profiles by revenue, with a daily CSV export.
- P&L - revenue vs expenses (payroll, inventory cost, asset maintenance) → net + margin %.
- Aging - outstanding receivables bucketed Current / 0-30 / 31-60 / 61-90 / 90+ days.
- Churn - monthly new/expired/net-change/active-at-end over up to 24 months.
- Audit log - the same audit trail as section 13, embedded here for convenience.
13. Settings hub
The configuration landing page - a grid of tiles, each opening a key-value editor. A few categories live under their own hubs instead of this grid: Email/SMS/notifications → Notifications hub; Backup/advanced → Server hub.
- Portals: Admin portal (hostnames/session behaviour), Customer portal/UCP (signup, recovery, captcha), FreeZone (section 14), Announcements (section 17).
- Organization: Roles & permissions, Manager groups, User groups (tag subscribers: Residential/Business/Hotspot/VIP), Form fields (add custom KYC-style fields to any form), Custom domains (section 14).
14. Notifications (Email / SMS / Webhooks)
Notifications hub is a card grid, one card per channel:
- Email templates + Email (SMTP) - your outbound mail server + the wording for welcome/expiry/invoice/receipt emails.
- SMS templates, SMS provider (pick provider, API key, sender name), and SMS queue (outbound jobs, drained every 2 min, with retry-failed).
- Notification rules - when emails/SMS actually fire (expiry warnings, activation alerts, Telegram bot, dashboard banners).
- Alert routing - route operator-facing alerts (NAS up/down, backup failures, new tickets, subscriber online/offline/expiry) to Email/SMS/Push per event.
Webhooks (developer integrations)
- Webhooks → Add endpoint: label, URL, a secret (auto-generated if left blank), and which events to subscribe to (blank = all events).
- Every delivery is signed - verify the
X-H3R-Signatureheader ashmac_sha256(rawBody, secret)against the raw POST body. - Use Send test ping to fire one delivery immediately, and check the Recent queue (last 100 deliveries, attempts + last response) if something isn't arriving.
15. Payment gateways
- Settings → Payment gateways. One tile per provider: Stripe, AbhiPay, JazzCash, Easypaisa.
- Click a tile → toggle Enabled, pick Test/Live mode, set currency, and paste in the provider's credentials (Stripe: publishable + secret key + webhook signing secret; JazzCash: merchant ID + password + integrity salt; Easypaisa: store ID + hash key).
- Copy the read-only Webhook URL shown on the tile into that provider's own dashboard so payment confirmations reach ISP Boost automatically.
- Every transaction (checkout, webhook, return, refund) logs to the Transaction log below, filterable by gateway/status/operation - your first stop if a payment "didn't show up."
16. Branding
- Settings → Branding & Theme for the global look: app title, footer text, logo/favicon, primary color, theme (Light/Dark/Light-Dark/Auto), and login-page headline/tagline/background.
- Color and theme preview live as you pick them; other changes apply on Save.
- For a reseller's own branded panel/domain instead of the global look: open that reseller under Managers → Branding button. Blank fields there fall through to the global settings above.
17. IP pools & FreeZone
IP pools
Named buckets of IPs RADIUS hands out via Framed-IP-Address, global or scoped to one NAS.
- Settings → IP pools → New pool: name, description, NAS (blank = global).
- Add IP for a single address, or Add range (Start..End, up to 1024 at once) to bulk-populate it.
- Each entry shows which subscriber (if any) currently holds it, or "available."
FreeZone (zero-rated traffic)
Define network ranges whose traffic doesn't count against a subscriber's FUP - e.g. your own CDN, peering partners, MikroTik's update servers.
- Settings → FreeZone → Add network.
- Set the Ratio:
0= fully free (doesn't count at all),1-99= counts as that percentage of actual bytes,100= normal accounting (same as no rule). - An external NetFlow/sFlow collector populates actual per-subscriber usage against these rules - this page just defines them.
18. Custom domains (branded reseller URLs)
- Settings → Custom domains → Add. Enter the hostname (lowercase, no scheme, subdomains OK) and optionally the reseller it belongs to (blank = a global alias for your own panel).
- Have the reseller point an A record for that hostname at your server's IP.
- Click Verify DNS - badge turns
verifiedonce it resolves correctly (ormismatchwith the actual IP shown, if it's wrong). - Click Provision SSL - runs Let's Encrypt/certbot. Badge shows
provisioning…thenvalid; renews automatically roughly every 60 days. - Toggle Apply branding so requests on that hostname get the reseller's own look from section 16.
19. 2FA & audit log
Two-factor authentication
- Your own account: top-right profile menu → Enable 2FA → scan the QR with an authenticator app (Google Authenticator, Authy, 1Password) or type the secret manually → enter the 6-digit code to confirm.
- Save the 10 recovery codes shown right after - each is single-use, for when you lose the authenticator. They're not shown again.
- To require it for a specific manager: on their form, tick Requires 2FA under Advanced information.
Audit log
Every create/update/delete on subscribers, managers, profiles, NAS, settings etc. is logged with actor, before/after diff, IP and user-agent. Filter by subject type, action, and date range; Diff on a row shows the before/after table; Export CSV for compliance records.
20. License
(Self-Hosted primarily - Cloud licensing is handled by your subscription plan instead, see Plans & billing.)
- The status card shows State/Plan, in-use users vs your licensed limit, expiry, and hardware-binding info (domain/UDID/MAC fingerprint).
- Check for updates asks the license server if a newer app version is out. Refresh re-validates now (also runs nightly automatically).
- Activate / Change key to paste a new key - takes effect immediately, no restart needed.
- If a fresh install shows unactivated, Start Free plan gives you 50 users for 3 months to get going.
21. Server, backup & tools
Server monitoring
Live vitals: CPU/RAM/disk gauges, per-service health (web, MySQL, Redis, queue, scheduler, FreeRADIUS), system info, and live per-interface network bandwidth. Auto-refreshes every 60s (network table every 3s).
Backup & Restore
- Create backup now for an on-demand snapshot, or configure the automatic schedule/retention under Settings → Backups.
- Download any snapshot to keep offline, or Upload an existing dump to bring it into the list.
- Restore overwrites the current database with the chosen snapshot - a safety snapshot of the current state is taken first automatically, and you'll likely need to sign in again afterward.
Tools (diagnostics)
Five tabs, run from the server itself: Ping (is a NAS/CPE reachable?), RADIUS test (send a real Access-Request to a NAS using its stored secret), MAC lookup (OUI vendor lookup), SNMP walk, SMS test (send one SMS synchronously to verify gateway credentials without waiting for the queue).
22. Announcements
- Settings → Announcements → New. Goes live immediately as a ribbon at the top of every operator's panel on their next page load.
- Each operator dismisses it individually (their browser only) - colleagues still see it until they dismiss too.
- Archive retires it for everyone; the trash icon deletes the record permanently.
- Typical uses: maintenance windows, billing reminders to resellers, urgent ops notes.