Get the most out of Hotspot Management
Hotspot Management turns a MikroTik router into a managed guest Wi-Fi service — a branded captive portal, per-guest speed and data limits, and an authentication record you can hand to an auditor. This guide walks the whole thing in order: what you do once at setup, what you do every day, and what your guests see on their own phones.
One system, three parts
You work in one place. Your guests see another. The router does what both of them decide.
1. The console
Where you work, on a computer. Guest accounts, speed and data plans, vouchers, the hotspot itself, reports and the authentication log.
2. The captive portal
What a guest sees when they join your Wi-Fi. Your logo, your terms, your colours — they accept, sign in, and they are online.
3. The router
Your MikroTik. Every account, plan and rule you set here is written to it, and what it reports back is what you see on screen.
Signing in lands you on the dashboard. It answers the questions you actually have first thing in the morning: who is online, did anything fail overnight, and is anything about to expire.
The dashboard — guests, live sessions, router health and 24 hours of login activity at a glance.
Further down: accounts about to expire, with a Renew button on each, and the busiest devices by MAC address.
First-time setup
Four things, once. After this the system runs on its own and you only come back to add guests and read reports.
Sign in to the console
Open http://your-server:3000/admin in a browser. Your username and first password come from whoever installed the system — the installer prints them once at the end, and a generated password must be changed the first time you use it.
The sign-in screen. Forgot your password? sends a six-digit code to the email address on your account.
Connect your router
Settings › Managed Router. Enter the router's name, its IP address, the API port (8728 by default) and an API username and password. Press Test Connection before saving — a successful test names the router back to you, which proves the credentials and the network path both work.
A connected router shows Reachable with the RouterOS version and board model it reported.
api policy. On the router, run
/user group print and check the group your API account belongs to. Without
that policy the login is refused no matter how correct the password is.
The router password is encrypted before it is stored and is never sent back out of the system — the field stays blank when you return, and leaving it blank keeps the password you already saved.
Put your name on the portal
Branding & Portal. This is not decoration — it is the first thing every guest sees. Set your company name, the portal title, the welcome line, your logo and your two brand colours, then write the terms and conditions guests must accept.
Branding — the name, logo and colours guests see on the captive portal.
Underneath, Portal Options decides which self-service links appear on the sign-in screen: password recovery, coupons, changing a password, and creating an account.
Each link is switched on here and under Self-Service — both are needed before it appears.
Changing the terms version puts the acceptance page back in front of every guest — which is exactly what you want when the wording changes for legal reasons.
Decide what a guest gets
Basic Setup › Service Plans. A plan is the answer to four questions: how fast, how much data, how long, and what happens when a limit is reached. Create one plan per class of guest — a standard room, a business floor, a conference hall, a day pass.
Four plans. Each row shows speed, daily quota, validity, any time-of-day rule, and what happens at the limit.
At limit is the important column. Throttle slows the guest down but keeps them online; Disconnect ends the session. Time rules let one plan behave differently at different hours — 20 Mbps during the day, 100 Mbps after six.
Guests & accounts
Creating accounts, finding them again, and acting on a hundred of them at once.
Add guests
Users & Access › Users. + Add User creates one account: username, password, full name, the group they belong to and the service plan they get. Bulk Upload takes a CSV when a coach party arrives and you need forty accounts at once.
Every guest, with their plan, live sessions, data used and last login. Actions sit on the row.
Each row carries its own actions — Edit, Disable, Suspend, Pass to reset a password, and Activity to open that guest's full history.
Find anyone in seconds
The search box takes a name, IP address, MAC address or group. When that is not enough, Advanced opens the full filter: by plan, by creation date, by last login, by expiry window, by session count, by data used — and combinations of them.
Advanced search. A filter you use often can be saved and reused from the dropdown.
Act on many at once
Tick the checkbox on any row and a bulk action bar appears. Enable or disable, change plan, extend expiry, send a notification, or export just the guests you picked.
Four selected. Select all matching this filter extends the action to every guest the search found, not just the page you can see.
One guest's whole story
Users & Access › User Activity. Type a username and you get every sign-in, every session, every device and every byte, merged into one timeline. This is the screen that answers "was someone else using my account?"
Sessions, data used, failed attempts, a chart over time, every device the account has been used from, and the timeline underneath.
Groups and who can do what
Users & Access › Groups & Roles. A group sorts guests — Rooms, Business Floor, Conference, Staff — and sets how many devices one account may use at the same time. A role is about your own staff: what a person signing in to this console is allowed to see and change.
Groups, their descriptions, the session limit each allows, and how many guests are assigned.
Vouchers & self-service
Two ways to hand out access without creating accounts one at a time.
Print vouchers for the front desk
Users & Access › Coupons. Generate Batch creates a run of codes tied to one service plan, with an expiry built in. Reception hands one to a walk-in guest; the guest types it into the portal and is online with that plan's speed and quota.
A batch of 60. Each code shows whether it is active, redeemed or expired, and who used it.
Print Unused produces a printable sheet of only the codes nobody has claimed — so a reprint never puts a live code on two pieces of paper.
Let guests help themselves
Users & Access › Self-Service. Decide how much guests can do without you: register their own account, recover a forgotten password, change a password they already know, and whether a new signup needs a verification code or your approval first.
Self-service. Codes waiting to be handed out and registrations awaiting approval appear below.
Self-registered guests can be given a plan and a group automatically, and you can limit how many accounts one device is allowed to create.
The hotspot
The router's own guest network — who is on it right now, and what is allowed through without signing in.
Check the hotspot server
Network › Hotspot › Servers. This is the router's guest network: which interface it runs on, which profile it uses and which address pool it hands out. Most sites have exactly one and never change it after setup.
One hotspot server, active on the guest bridge.
See who is online now
Active Users is the live list straight from the router: username, IP, MAC, how long they have been on and how much they have moved. Disconnect ends a session immediately; Bypass lets that device through without signing in again.
Live sessions on the router, with the data each has used this session.
Let some things through without a login
Access Control holds the two exceptions to "everyone must sign in".
Bindings and the walled garden — the two ways past the sign-in screen, on one page.
Bypass by MAC or IP
Walled garden
Router & addresses
What the router is doing, and the address and firewall settings behind it.
Watch it live
Live Monitoring polls the router every few seconds: throughput per interface, CPU, memory, uptime and which links are up or down. This is the page to open when someone says "the internet is slow".
Live monitoring, refreshing on its own. Red marks an interface that is down.
Interfaces, bridges and VLANs
Network › Interfaces lists every port with its state, bridge, IP addresses, MAC and MTU. The tabs above cover bridges, VLANs and IP addresses. You can enable or disable a port, or add an address, without opening Winbox.
Interfaces as the router reports them, with the guest bridge and its member ports.
Leases, and reserving an address
Network › DHCP › Leases & Reservations. Every address the router has handed out, searchable by MAC or IP. Reserve pins a device to the address it currently holds, so a printer or a till keeps the same one after a reboot.
Reserved addresses on top, live dynamic leases below, each with a one-click Reserve.
Firewall and NAT
Network › Firewall shows the router's filter rules and NAT rules on separate tabs, in the order the router evaluates them, with the traffic each has matched. Rules can be reordered by dragging, and enabled, disabled or cloned from the row.
Filter rules in evaluation order. NAT rules live on their own tab and are numbered separately by the router.
Reports & records
What you send upstairs, and what you keep for the auditor.
Run a report
Reports. Pick a report and a period, and it is drawn on screen first — totals, then charts, then the detail table. PDF and CSV download the same thing.
Totals first: attempts, successes, failures and unique devices for the period.
Attempts over time, why sign-ins failed, and the record-by-record table underneath.
The authentication log
Reports › Authentication Logs. Every sign-in, failure, session and terms acceptance, with the username, MAC address, IP and reason. Filter by status, event type and date range; Export CSV takes the filtered view, not the whole log.
The authentication record. Terms acceptances carry the guest's name on the same row once they sign in.
How long this is kept is set under Settings › Log Retention Policy — 180 days by default, and anything from 30 days to ten years if your regulator asks for something specific.
Trace a device or an account
Reports › MAC / User Tracking. Give it a MAC address or a username and it reconstructs the complete history for that device or account — every event and every session, in one chronological record, with the identities that device has been used under.
One device: 42 events, 20 successful logins, the account behind it and the full timeline.
Who changed what
Reports › Audit Trail records administrator actions rather than guest activity: who signed in to this console, what they changed, from which address and how long it took. Filter by administrator or by result.
Administrator actions, kept separately from the guest authentication log.
Security & email
Set these up once. Most of them only matter on the day something goes wrong.
Configure email
Policy › Email (SMTP). Enter your mail server, port, credentials and the address messages should come from, then press Test Connection and Send Test Email — the second one proves delivery, not just that the server answered.
SMTP. The password is encrypted before it is stored and never returned to the browser.
Set the security policy
Policy › Security. One page covering password strength and reuse history, lockout after repeated failures, how long an idle console session lasts, how often administrator passwords must change, and whether administrators need an emailed code as a second step at sign-in.
Password rules, lockout, session timeouts, and the expiry and grace behaviour for guest accounts.
Account Expiry & Grace is worth setting deliberately: how many days before expiry a guest is warned, how long a grace period lasts once they pass it, and the reduced speed they get during grace instead of being cut off outright.
Check your licence
Policy › Licence shows what you are licensed for, when it expires and which features are included. A new installation starts on a 15-day trial and licenses itself automatically as soon as it can reach the licence server.
Licence state, the installation ID Optimus Secure needs when you renew, and the features included.
Getting online
What your guest sees, in the order they see it. Worth knowing so reception can talk someone through it over the phone.
The terms, once
Joining the Wi-Fi opens the portal by itself on most phones. The first thing a guest sees is your terms and conditions. They tick the box, press Agree & Continue, and that acceptance is recorded against their device.
The terms screen, branded with your name and colours.
Sign in
Username and password, or a voucher code. The links underneath are the ones you switched on: recovering a forgotten password, redeeming a coupon, changing a password, and creating an account.
Sign-in. Every link here is one you chose to show.
Once they are in, the portal shows a connected page with their session details and a Logout button. Refreshing or reopening the page shows that same connected page — not the sign-in form again — for as long as the session is alive.
Change a password without calling reception
A guest who knows their current password can change it themselves. The rules their new password must satisfy are listed as they type, so they are not guessing.
Changing a password from the portal. The new one goes through the same rules as any other.
Quick reference
The words that appear on screen, and what each one means.
Account status
Expiry lifecycle
Voucher status
Hotspot bindings
At the plan limit
Router state
Getting help
The three things worth checking before you call, and where to call.
Guests cannot get online
Check Routers Reachable on the dashboard first. If the router is not answering, nothing else will work. If it is, look at Hotspot › Active Users to see whether sessions are being created at all.
A portal link is missing
Every self-service link is switched on in two places — under Self-Service for the feature, and under Branding & Portal for the link. The Branding page tells you when one is on and the other is off.
No email is arriving
Use Send Test Email under Policy › Email. It reports the mail server's actual answer, which is usually enough to identify the problem.
Still stuck?
Contact Optimus Secure at info@opsec.co.in. Quote your installation ID from Policy › Licence — it identifies your system precisely and saves a round of questions.