Okey, problem is solved. It was my bad, because in Mikrotik RADIUS config there's field DOMAIN and I put there FQDN. I didn't know that this field is used by Mikrotik to forward auth to proper RADIUS server eg. when I log in as YYY\user, Mikrotik watches if there's RADIUS for domain YYY, and then pa...