When Herotel needed RADIUS authentication that could survive South Africa's power grid and scale past a million subscribers, three engineering firsts came with it.
Herotel is a South African fibre and fixed-wireless ISP, built by acquiring more than 30 independent regional providers over several years. Each one arrived with its own RADIUS server, its own subscriber database, and its own way of authenticating customers. Connecting the network authentication together resulted in a complicated patchwork of servers.
By 2023, that patchwork had become the hard limit on Herotel's growth. The company needed a single platform that could scale past a million subscribers, survive South Africa's unreliable power grid, and support a new business model that was impossible with legacy systems.
It found that platform with InkBridge Networks, the company that created and maintains FreeRADIUS, the open-source RADIUS server that underpins most of the world's network authentication.
Thirty ISPs, all with different RADIUS systems
Each of the ISPs Herotel acquired had built or bought its own authentication stack, and none of them talked to each other. A customer could not move from one Herotel company to another without a new account being created from scratch. Herotel had rolled out a standard set of applications across the group a few years earlier, but under the surface, every regional business still ran its own RADIUS system and its own database.
That structure had a ceiling. Each legacy instance could handle roughly 40,000 to 50,000 customers before it ran out of headroom, and Herotel's ambitions were an order of magnitude larger. The product catalogue told the same story: hundreds of overlapping data packages had accumulated across those 30-plus acquisitions, each one a separate thing to configure, support, and reconcile.
South Africa's power grid made the problem worse. Frequent, widespread outages meant that when electricity came back online, an entire neighbourhood, suburb, or town would try to re-authenticate at once, a traffic spike the legacy servers were not designed to absorb. According to Imel Rautenbach, Herotel's IT Executive, those spikes hit as often as ten times a day across the network.
"We used to lose customers because they couldn't get back online after a power outage," Rautenbach said. "Everyone tried to reconnect at once and our old systems couldn't handle the spike. Thousands of customers would wait up to half an hour just to re-authenticate."
A single platform, built by the people who wrote FreeRADIUS
Herotel was already running its own FreeRADIUS-based solution and trusted the software. But its in-house team did not have the depth of RADIUS expertise needed to rebuild that solution for scale. So the ISP turned to InkBridge Networks, reasoning that the safest hands for a FreeRADIUS rebuild belonged to the people who wrote the code in the first place.
InkBridge replaced Herotel's 30-plus standalone instances with a single, cloud-hosted authentication platform on Google Cloud Platform (GCP). The new system was deployed in 2024 and has been fully operational since mid-2025, consolidating every regional business onto one database and one set of FreeRADIUS policies for the first time in Herotel's history.
Three new pieces of engineering for a unique set of demands
Herotel's deployment required InkBridge to solve three problems that go beyond what most RADIUS installations ever have to handle. All three solutions come from having built FreeRADIUS itself: InkBridge could design new authentication behaviour at the protocol level, rather than working around the limits of a closed product.
The first was credential sharing. When a household's login gets passed around a neighbourhood the way a shared streaming password does, capacity and revenue both suffer. The standard fix, disconnecting the suspected duplicate session, creates a new problem: both users fight to reconnect, and the session cycles rapidly back and forth.
InkBridge built something different. Before a new session is admitted, the platform sends a Change of Authorisation request to probe whether the existing session is genuinely still active. If it has ended, the new user connects without friction. If it has not, the new attempt is rejected, and the active session stays untouched. As far as InkBridge can determine, this is the first production deployment of CoA-based simultaneous-use detection at operator scale.
The second was failover. South Africa's power and physical infrastructure problems do not just cause re-authentication spikes; they also cut entire sites off from the internet, including from Herotel's cloud-hosted FreeRADIUS servers. InkBridge's answer was a hybrid architecture: small on-premises appliances that mirror the cloud servers and advertise the same RADIUS IP addresses via anycast. Under normal conditions, BGP AS-path prepending keeps traffic routing to the cloud. The moment that connectivity drops, whether from a fibre cut or a regional outage, the on-premises boxes take over automatically and subscribers stay online without anyone touching a keyboard.
How anycast failover keeps Herotel subscribers online during power and fibre outages
The third was distance. Herotel service runs in two GCP regions, Johannesburg and Doha, separated by roughly 150 milliseconds of network latency, and the business had legacy applications tying it to MySQL as its database. Standard synchronous MySQL calls turn that latency directly into lost throughput, because the server waits for a response before it can do anything else. InkBridge built an asynchronous I/O module for the MySQL client that decouples request handling from the round trip, so throughput no longer depends on how far apart the two sites are.
The resulting platform runs on approximately eight CPU cores in GCP, a fraction of the hardware that comparable proprietary RADIUS deployments typically require at this scale.
The prepaid model that became possible with a new platform
Herotel's engineering choices, guided by InkBridge expertise, changed what the company could sell.
Now that the platform could absorb high volumes of short-lived sessions without strain, Herotel launched a prepaid Wi-Fi product: R199 (about $11) for a router and professional installation, with no contract or credit check. Customers then buy access vouchers in 7, 14, 28, or 31-day increments, either online or at a grocery store pay point. Every voucher activation and expiry generates a RADIUS transaction, at a volume the old systems could never have supported.
"Our market is very price-sensitive," Rautenbach said. "Prepaid lets people pay for a week or a month when they're able to, and that's opened up access to communities we couldn't reach before with traditional contracts. Now it's probably our largest growth area and at least half our customer base."
Prepaid access is reaching customers in smaller towns, peri-urban areas, and townships where contract-based broadband has typically been harder to access, extending fibre-grade connectivity to communities that the old business model excluded.
Worth subscribing to.
Worth reading.
Our weekly newsletter covers network authentication tips, how-tos, security vulnerabilities, free resources, standards updates, and industry news. (All stuff you should stay up to date on!)
What changed for Herotel’s business
The clearest measure of the new platform is what happens during a power outage now. Reconnection after an outage has dropped from as long as 30 minutes to about 2 minutes on average.
"Now, when power is restored, almost everyone is back online immediately," Rautenbach said. "Maybe a hundred people wait a minute or two, and the rest don't even notice there was an issue."
The business results followed. Herotel has grown from roughly 200,000 to more than 350,000 active customers, adding around 10,000 new subscribers a month, and the platform is architected to scale well beyond a million.
The product catalogue has been simplified from hundreds of overlapping packages down to a few tens, standardised across every regional business for the first time.
The manual intervention that used to consume Herotel's support team during every outage is largely gone, freeing staff to work on network expansion instead of firefighting.
Herotel is now South Africa's largest retail fibre-to-the-home ISP by connected homes, operating across more than 500 towns. That growth was not available to the company on its old architecture.
The takeaway for other operators
Multi-brand operators built through acquisition tend to inherit exactly this kind of fragmented authentication estate, and unreliable power or connectivity is not unique to South Africa.
The specific innovations here (CoA-based session detection, anycast failover, and asynchronous multi-site I/O) are reusable wherever an operator runs FreeRADIUS and hits the same limits.
Building those capabilities was only possible because InkBridge controls FreeRADIUS's full request lifecycle, rather than working around the limits of someone else's implementation.
Need more help?
If your ISP is wrestling with a legacy RADIUS estate that will not scale, an outage pattern that keeps repeating, or a business model your current authentication platform cannot support, we can help. InkBridge Networks has 25 years of expertise. We wrote the standards, maintain FreeRADIUS, and have seen every failure mode there is. Reach out to request a quote.
Related Articles
RADIUS design for internet service providers (ISPs)
Internet service providers (ISPs) must deliver fast, reliable connectivity. Downtime can disrupt operations, while slow speeds drive customers elsewhere. Multiple levels of network redundancy are essential to maintaining stable, uninterrupted service.
ISPs/Telcos
InkBridge Networks helps ISPs and telecom providers build scalable, highly available RADIUS systems with flexible licensing and multi-site management.