📶 User Guide

Get the most out of Hotspot Management

Hotspot Management turns a MikroTik router into a managed guest Wi-Fi service — a branded captive portal, per-guest speed and data limits, and an authentication record you can hand to an auditor. This guide walks the whole thing in order: what you do once at setup, what you do every day, and what your guests see on their own phones.

Product
Hotspot Management
Prepared by
Optimus Secure
Version
1.0 — August 2026
Overview

One system, three parts

You work in one place. Your guests see another. The router does what both of them decide.

💻

1. The console

Where you work, on a computer. Guest accounts, speed and data plans, vouchers, the hotspot itself, reports and the authentication log.

📱

2. The captive portal

What a guest sees when they join your Wi-Fi. Your logo, your terms, your colours — they accept, sign in, and they are online.

📡

3. The router

Your MikroTik. Every account, plan and rule you set here is written to it, and what it reports back is what you see on screen.

Signing in lands you on the dashboard. It answers the questions you actually have first thing in the morning: who is online, did anything fail overnight, and is anything about to expire.

The dashboard, showing guest counts, live sessions, router reachability and login activity

The dashboard — guests, live sessions, router health and 24 hours of login activity at a glance.

Lower half of the dashboard showing accounts expiring soon and the most active devices

Further down: accounts about to expire, with a Renew button on each, and the busiest devices by MAC address.

Read the tiles left to right. The Routers Reachable tile is the one to check first — if it does not read 1/1, nothing else on the page is current, because the router is not answering.
Getting Started

First-time setup

Four things, once. After this the system runs on its own and you only come back to add guests and read reports.

1

Sign in to the console

Open http://your-server:3000/admin in a browser. Your username and first password come from whoever installed the system — the installer prints them once at the end, and a generated password must be changed the first time you use it.

The administrator sign-in screen with username and password entered

The sign-in screen. Forgot your password? sends a six-digit code to the email address on your account.

⚠️ Password recovery needs email. The code can only be sent once SMTP is configured (step 23) and your account has an email address on it. Set both up before you need them.
2

Connect your router

Settings › Managed Router. Enter the router's name, its IP address, the API port (8728 by default) and an API username and password. Press Test Connection before saving — a successful test names the router back to you, which proves the credentials and the network path both work.

The Managed Router settings page showing a connected router and the log retention policy

A connected router shows Reachable with the RouterOS version and board model it reported.

⚠️ The API user needs the api policy. On the router, run /user group print and check the group your API account belongs to. Without that policy the login is refused no matter how correct the password is.

The router password is encrypted before it is stored and is never sent back out of the system — the field stays blank when you return, and leaving it blank keeps the password you already saved.

3

Put your name on the portal

Branding & Portal. This is not decoration — it is the first thing every guest sees. Set your company name, the portal title, the welcome line, your logo and your two brand colours, then write the terms and conditions guests must accept.

The branding page with company name, logo upload, colours and portal title

Branding — the name, logo and colours guests see on the captive portal.

Underneath, Portal Options decides which self-service links appear on the sign-in screen: password recovery, coupons, changing a password, and creating an account.

Portal options checkboxes and the terms and conditions editor

Each link is switched on here and under Self-Service — both are needed before it appears.

Two switches, on purpose. The box here decides whether guests are shown the link; the matching box under Self-Service decides whether the feature is on at all. If a link is ticked here but the feature is off, this page tells you so directly.

Changing the terms version puts the acceptance page back in front of every guest — which is exactly what you want when the wording changes for legal reasons.

4

Decide what a guest gets

Basic Setup › Service Plans. A plan is the answer to four questions: how fast, how much data, how long, and what happens when a limit is reached. Create one plan per class of guest — a standard room, a business floor, a conference hall, a day pass.

Service plans with speed, daily quota, validity, time rules and the action taken at the limit

Four plans. Each row shows speed, daily quota, validity, any time-of-day rule, and what happens at the limit.

⏱️ Speed limit 📊 Daily data cap 🕒 Time-of-day rules 🐢 Throttle at limit 🔌 Disconnect at limit

At limit is the important column. Throttle slows the guest down but keeps them online; Disconnect ends the session. Time rules let one plan behave differently at different hours — 20 Mbps during the day, 100 Mbps after six.

Preview before you commit. Preview Enforcement shows which guests a change would affect and what would happen to them, without touching anyone. Enforce Now then applies it.
Day to Day

Guests & accounts

Creating accounts, finding them again, and acting on a hundred of them at once.

5

Add guests

Users & Access › Users. + Add User creates one account: username, password, full name, the group they belong to and the service plan they get. Bulk Upload takes a CSV when a coach party arrives and you need forty accounts at once.

The user list with plan, sessions, data used, last login, status and per-row actions

Every guest, with their plan, live sessions, data used and last login. Actions sit on the row.

Each row carries its own actions — Edit, Disable, Suspend, Pass to reset a password, and Activity to open that guest's full history.

6

Find anyone in seconds

The search box takes a name, IP address, MAC address or group. When that is not enough, Advanced opens the full filter: by plan, by creation date, by last login, by expiry window, by session count, by data used — and combinations of them.

The advanced search panel with plan, date, session count and data filters

Advanced search. A filter you use often can be saved and reused from the dropdown.

Save the searches you repeat. "Expiring within 7 days" or "never logged in" are worth saving once and clicking thereafter.
7

Act on many at once

Tick the checkbox on any row and a bulk action bar appears. Enable or disable, change plan, extend expiry, send a notification, or export just the guests you picked.

Four guests selected with the bulk action bar showing the available actions

Four selected. Select all matching this filter extends the action to every guest the search found, not just the page you can see.

⚠️ Check the count before you apply. The bar tells you how many accounts are selected. With "select all matching" that can be far more than the rows on screen — which is the point, but worth a glance first.
8

One guest's whole story

Users & Access › User Activity. Type a username and you get every sign-in, every session, every device and every byte, merged into one timeline. This is the screen that answers "was someone else using my account?"

One guest's activity: sessions, data used, devices seen and a chronological timeline

Sessions, data used, failed attempts, a chart over time, every device the account has been used from, and the timeline underneath.

9

Groups and who can do what

Users & Access › Groups & Roles. A group sorts guests — Rooms, Business Floor, Conference, Staff — and sets how many devices one account may use at the same time. A role is about your own staff: what a person signing in to this console is allowed to see and change.

User groups with member counts and maximum simultaneous sessions

Groups, their descriptions, the session limit each allows, and how many guests are assigned.

Give reception the least they need. A support role can look up a guest and reset a password without being able to change plans, firewall rules or anyone's permissions.
Day to Day

Vouchers & self-service

Two ways to hand out access without creating accounts one at a time.

10

Print vouchers for the front desk

Users & Access › Coupons. Generate Batch creates a run of codes tied to one service plan, with an expiry built in. Reception hands one to a walk-in guest; the guest types it into the portal and is online with that plan's speed and quota.

A voucher batch and its codes, each showing status, who redeemed it and when it expires

A batch of 60. Each code shows whether it is active, redeemed or expired, and who used it.

Print Unused produces a printable sheet of only the codes nobody has claimed — so a reprint never puts a live code on two pieces of paper.

Expiry stops the drawer problem. Codes age out on their own, so a forgotten stack at reception stops being usable rather than staying valid forever.
11

Let guests help themselves

Users & Access › Self-Service. Decide how much guests can do without you: register their own account, recover a forgotten password, change a password they already know, and whether a new signup needs a verification code or your approval first.

Self-service settings with registration, verification, approval and password options

Self-service. Codes waiting to be handed out and registrations awaiting approval appear below.

Self-registered guests can be given a plan and a group automatically, and you can limit how many accounts one device is allowed to create.

⚠️ Each option is switched on in two places. Here, and again under Branding & Portal where you decide whether guests are shown the link. If something is not appearing on the portal, check both.
Day to Day

The hotspot

The router's own guest network — who is on it right now, and what is allowed through without signing in.

12

Check the hotspot server

Network › Hotspot › Servers. This is the router's guest network: which interface it runs on, which profile it uses and which address pool it hands out. Most sites have exactly one and never change it after setup.

The hotspot server list showing interface, profile, pool and status

One hotspot server, active on the guest bridge.

13

See who is online now

Active Users is the live list straight from the router: username, IP, MAC, how long they have been on and how much they have moved. Disconnect ends a session immediately; Bypass lets that device through without signing in again.

Active hotspot users with address, MAC, uptime, bytes in and out, and disconnect and bypass actions

Live sessions on the router, with the data each has used this session.

14

Let some things through without a login

Access Control holds the two exceptions to "everyone must sign in".

Access control: MAC cookies, IP bindings for bypassed and blocked devices, and the walled garden

Bindings and the walled garden — the two ways past the sign-in screen, on one page.

Bypass by MAC or IP

BypassedThe device skips the portal entirely — a lobby printer, a till, a smart TV, a reception iPad.
BlockedThe device is refused, whatever credentials it offers.
RegularNormal — must sign in like any guest.

Walled garden

By hostnameSites reachable before signing in — your own website, a payment gateway.
By IP rangeThe same, for services that do not present a clean hostname.
Automatic login by MAC remembers a device so a returning guest is not asked again. The cookie has a lifetime, and Clear all forgets every remembered device at once.
⚠️ Bypass is an exception, not a shortcut. A bypassed device is not authenticated, so its traffic is not attributable to a guest in your logs. Use it for equipment you own, not for people.
The Network

Router & addresses

What the router is doing, and the address and firewall settings behind it.

15

Watch it live

Live Monitoring polls the router every few seconds: throughput per interface, CPU, memory, uptime and which links are up or down. This is the page to open when someone says "the internet is slow".

Live monitoring with interface counts, CPU and memory load, uptime and per-interface throughput

Live monitoring, refreshing on its own. Red marks an interface that is down.

16

Interfaces, bridges and VLANs

Network › Interfaces lists every port with its state, bridge, IP addresses, MAC and MTU. The tabs above cover bridges, VLANs and IP addresses. You can enable or disable a port, or add an address, without opening Winbox.

The interface list with state, bridge membership, IP addresses, MAC and MTU

Interfaces as the router reports them, with the guest bridge and its member ports.

17

Leases, and reserving an address

Network › DHCP › Leases & Reservations. Every address the router has handed out, searchable by MAC or IP. Reserve pins a device to the address it currently holds, so a printer or a till keeps the same one after a reboot.

DHCP leases split into reserved static entries and current dynamic leases, each with a reserve action

Reserved addresses on top, live dynamic leases below, each with a one-click Reserve.

Reserve, then bypass. For equipment that should never see the portal, reserve its address here and add it as a bypassed binding under Hotspot › Access Control.
18

Firewall and NAT

Network › Firewall shows the router's filter rules and NAT rules on separate tabs, in the order the router evaluates them, with the traffic each has matched. Rules can be reordered by dragging, and enabled, disabled or cloned from the row.

Firewall filter rules with chain, action, source, destination, port and matched traffic

Filter rules in evaluation order. NAT rules live on their own tab and are numbered separately by the router.

⚠️ Order matters, and so does the tab. The router keeps filter and NAT rules in separate tables with their own numbering — rule 3 in one is unrelated to rule 3 in the other.
Oversight

Reports & records

What you send upstairs, and what you keep for the auditor.

19

Run a report

Reports. Pick a report and a period, and it is drawn on screen first — totals, then charts, then the detail table. PDF and CSV download the same thing.

The report page with totals for attempts, successes, failures and unique devices

Totals first: attempts, successes, failures and unique devices for the period.

Report charts showing login attempts over time and the reasons sign-ins failed, above the detail table

Attempts over time, why sign-ins failed, and the record-by-record table underneath.

Have it sent to you instead. Schedule emails any report daily, weekly or monthly to a list of addresses — the usual way compliance reporting gets done without anyone remembering to do it.
20

The authentication log

Reports › Authentication Logs. Every sign-in, failure, session and terms acceptance, with the username, MAC address, IP and reason. Filter by status, event type and date range; Export CSV takes the filtered view, not the whole log.

The authentication log with time, user, MAC, IP, event, status and reason

The authentication record. Terms acceptances carry the guest's name on the same row once they sign in.

How long this is kept is set under Settings › Log Retention Policy — 180 days by default, and anything from 30 days to ten years if your regulator asks for something specific.

21

Trace a device or an account

Reports › MAC / User Tracking. Give it a MAC address or a username and it reconstructs the complete history for that device or account — every event and every session, in one chronological record, with the identities that device has been used under.

A MAC address traced to one guest, with totals, identities and a full event timeline

One device: 42 events, 20 successful logins, the account behind it and the full timeline.

This is the answer to a police or regulator request. One MAC address in, a complete dated record out, exportable as CSV.
22

Who changed what

Reports › Audit Trail records administrator actions rather than guest activity: who signed in to this console, what they changed, from which address and how long it took. Filter by administrator or by result.

The administrative audit trail showing time, admin, role, action, resource, result and source address

Administrator actions, kept separately from the guest authentication log.

Oversight

Security & email

Set these up once. Most of them only matter on the day something goes wrong.

23

Configure email

Policy › Email (SMTP). Enter your mail server, port, credentials and the address messages should come from, then press Test Connection and Send Test Email — the second one proves delivery, not just that the server answered.

SMTP settings with host, port, credentials, from name and address, and test buttons

SMTP. The password is encrypted before it is stored and never returned to the browser.

⚠️ Three features depend on this. Administrator sign-in codes, administrator password recovery and scheduled reports all need working email. Without it they simply cannot be delivered.
24

Set the security policy

Policy › Security. One page covering password strength and reuse history, lockout after repeated failures, how long an idle console session lasts, how often administrator passwords must change, and whether administrators need an emailed code as a second step at sign-in.

Security policy: password rules, brute-force lockout, session timeouts and account expiry with grace

Password rules, lockout, session timeouts, and the expiry and grace behaviour for guest accounts.

Account Expiry & Grace is worth setting deliberately: how many days before expiry a guest is warned, how long a grace period lasts once they pass it, and the reduced speed they get during grace instead of being cut off outright.

🔑 Password rules 🚫 Lockout ⏲️ Idle sign-out 📧 Sign-in codes 📅 Expiry & grace
25

Check your licence

Policy › Licence shows what you are licensed for, when it expires and which features are included. A new installation starts on a 15-day trial and licenses itself automatically as soon as it can reach the licence server.

The licence page showing plan, expiry, installation ID and included features

Licence state, the installation ID Optimus Secure needs when you renew, and the features included.

The captive portal keeps working regardless. If a licence lapses, the console is what stops — guests already online are not thrown off.
For Guests

Getting online

What your guest sees, in the order they see it. Worth knowing so reception can talk someone through it over the phone.

26

The terms, once

Joining the Wi-Fi opens the portal by itself on most phones. The first thing a guest sees is your terms and conditions. They tick the box, press Agree & Continue, and that acceptance is recorded against their device.

The captive portal terms and conditions screen with an acceptance checkbox

The terms screen, branded with your name and colours.

Only once per device. A guest who has already agreed goes straight to sign-in next time. Publishing a new version of the terms puts the page back in front of everybody.
27

Sign in

Username and password, or a voucher code. The links underneath are the ones you switched on: recovering a forgotten password, redeeming a coupon, changing a password, and creating an account.

The guest sign-in screen with links for password recovery, coupons, password change and registration

Sign-in. Every link here is one you chose to show.

Once they are in, the portal shows a connected page with their session details and a Logout button. Refreshing or reopening the page shows that same connected page — not the sign-in form again — for as long as the session is alive.

28

Change a password without calling reception

A guest who knows their current password can change it themselves. The rules their new password must satisfy are listed as they type, so they are not guessing.

The guest change-password form listing the password rules that must be met

Changing a password from the portal. The new one goes through the same rules as any other.

⚠️ This is off until you switch it on — under Self-Service, and shown on the portal by the matching box under Branding & Portal.
Reference

Quick reference

The words that appear on screen, and what each one means.

Account status

ActiveCan sign in and use the network.
DisabledSwitched off by an administrator. Cannot sign in.
SuspendedHeld, usually for non-payment or misuse. Cannot sign in.
PendingSelf-registered and waiting for a code or approval.
ExpiredPast its expiry date. Renew or extend to restore access.

Expiry lifecycle

ActiveWell inside its validity.
WarningExpiry is close. The guest is notified if email is set up.
GracePast expiry but still online, at the reduced grace speed.
ExpiredGrace is over. Access has stopped.

Voucher status

ActivePrinted and not yet used.
RedeemedA guest has claimed it. Shows who and when.
ExpiredAged out before anyone used it.

Hotspot bindings

BypassedSkips the portal completely.
BlockedRefused, whatever it presents.
RegularMust sign in like any guest.

At the plan limit

ThrottleSlowed to the reduced speed, stays online.
DisconnectSession ends.
No actionCounted only. Nothing is enforced.

Router state

ReachableAnswering on the API. Everything on screen is current.
UnreachableNot answering. Live pages will be empty or stale.
Out of syncA plan or policy has not been written to the router yet.
Support

Getting help

The three things worth checking before you call, and where to call.

📡

Guests cannot get online

Check Routers Reachable on the dashboard first. If the router is not answering, nothing else will work. If it is, look at Hotspot › Active Users to see whether sessions are being created at all.

🔗

A portal link is missing

Every self-service link is switched on in two places — under Self-Service for the feature, and under Branding & Portal for the link. The Branding page tells you when one is on and the other is off.

📧

No email is arriving

Use Send Test Email under Policy › Email. It reports the mail server's actual answer, which is usually enough to identify the problem.

Still stuck?

Contact Optimus Secure at info@opsec.co.in. Quote your installation ID from Policy › Licence — it identifies your system precisely and saves a round of questions.