ISP Radius Hotspot: gateways, portals and vouchers
Manage MikroTik gateways, profiles, portals, accounts, vouchers and sessions.
Last updated: 2026-10-07
Hotspot plans and gateway quota
Lite is free and allows 2 gateways. Start includes 8 gateways in total for €10 per month plus VAT; Pro includes 20 gateways in total for €20 per month plus VAT. The module exclusively manages MikroTik gateways running RouterOS; routers from other manufacturers cannot be registered as gateways. Activation with an automatic certificate requires RouterOS 7.22 or later within series 7, stable or long-term. All plans have the same module features; the gateway quota changes. External services retain their own pricing.
A full administrator can activate Lite from Settings, using the existing free-module procedure. The Info e abbonamenti tab, next to Portali, compares Lite, Start and Pro and shows the active subscription, registered gateways and how many gateways can still be added. All registered gateways count, including those awaiting connection, offline or revoked, until deleted. At quota, adding gateways is blocked; existing gateways remain available for viewing and editing according to permissions.
To increase the quota, a full administrator with Hotspot write permission opens Info e abbonamenti → Richiedi upgrade, selects a higher plan, confirms the request and price, then submits. The request follows the commercial process used for licence and storage upgrades; the quota increases after approval. While Upgrade richiesto is shown, wait for the outcome without submitting duplicates. The plan quota is a total, not additional gateways.
ISPs managed by a Master request the change through their Master. Existing enabled ISPs may show Piano esistente with their retained quota and commercial terms. For capacity beyond the available plans, agree commercial terms before adding sites.
API catalogue
The API catalogue for ISP integrations contains no dedicated Hotspot entries. Manage the module through the Gateway, Portals, accounts and sessions pages.
Delete a gateway, including after failed activation
For a paired gateway, open Gestione avanzata and select Revoca collegamento. The Elimina gateway button appears at the top after revocation is requested, including when revocation is still pending. It stays hidden while the gateway is paired, even if temporarily unreachable. It is directly available when initial connection or reconnection has not been completed. Hotspot write permission is required.
Deletion confirmation invalidates the installation script and management credentials and requests remote connection deactivation. Once complete, you return to the list and the gateway page is no longer available.
If remote deactivation is not confirmed, cancel and retry or confirm a second time to delete only the gateway page. In this case the guest network may remain active: check the connection on the concentrator. Cancelling the second confirmation keeps the gateway page available with management already revoked.
Guest accounts, portals and connection history are retained. Deletion does not reset the MikroTik or close existing guest sessions.
Getting started
Open Settings → ISP Radius Hotspot → Gateway. Manage site devices, guest accounts, access profiles and vouchers. Complete the guest network configuration and try a real login before distributing credentials.
At the top of configuration pages, Torna alla dashboard Hotspot opens the module overview; Torna alle impostazioni opens general settings.
Guided gateway management is a preview available on enabled installations. It includes connection to ISP Billing, network preparation and first installation on a MikroTik, including an existing customer router when free guest interfaces and prerequisites are available. Test the service before using it at customer sites.
Permissions and manual gateways
Hotspot read permission allows viewing the list, details and guest network draft. Hotspot write permission is required to create, edit, generate an installation script, update configuration, request an interface reading, save the draft, request activation and restoration or revoke a gateway. Each ISP can access only its own gateways.
The manual management button is hidden from the Gateway list. Existing installations are retained and are not automatically imported into guided management.
In manual management, incomplete service configuration prevents saving: contact support. If «Gateway salvato» appears with an update error, the details have already been saved: do not create a second gateway and contact support before retrying. Confirmation that the service restarted does not replace a guest login test.
Gateway dashboard
The page groups Impostazioni Hotspot and Apri WebFig beside the gateway name. Connection and last contact are separate from the configuration reading date. Collegato means recent contact: test guest login and browsing to verify the service.
Four compact indicators show authenticated sessions, CPU, memory and uptime. Zero means zero reported sessions; a dash means a missing value. Configurazione sulla MikroTik shows the reading date and status. With write permission, when values are missing or outdated, the page requests an update and displays them when available. Use Aggiorna dalla MikroTik to request another reading; Hotspot write permission is required.
Rete rilevata shows the device bridge, ports, VLANs, Wi-Fi and addresses. Links open the relevant settings directly. Portale ospiti groups portal selection with the site’s Walled Garden and MAC bypass permissions. Every change requires review and confirmation.
Expand RouterOS e manutenzione to review the installed version and updates. Name, site and advanced management remain in expandable sections. Read-only permission allows viewing values; the page preserves unsaved fields when new data arrives.
Configura Hotspot: read interfaces
Open the gateway and select Configure hotspot. The steps are Device, Internet, Bridge and VLAN, Ports and Wi-Fi, Addresses, Portal and access, Review.
In Device select Detect / update device and keep the MikroTik powered on and connected. During a new reading, the previous settings remain on hold; the form opens when the reading is complete. A failure explains which information is unavailable and the next action. You do not need to reinstall the connection.
Device distinguishes interfaces available without VLAN from ports and bridges usable for VLAN transport. Requirements to complete before applying are in a separate section and repeated in Review. With available ports and an identified Internet connection, you can prepare and save a draft while requirements remain outstanding. On an existing customer router, Internet and the customer configuration are retained. Activation automatically prepares DNS for guests, RADIUS disconnection and the name required for the certificate. Local management retains access from the customer network and excludes guests. Existing DNS servers and Internet access are retained. Normal discovery selections, including those that exclude dynamic interfaces, are retained while excluding guests. A conflict with an already active service requires review before applying. Saving keeps a draft without changing the MikroTik; device information is read again before applying.
Existing Hotspot on the router
If Device detects an existing Hotspot, it shows its name and interface and stops the new activation. The procedure does not delete it. Before replacing it, review users, services and management access, keep a configuration copy and deliberately remove it from the MikroTik. Then select Detect / update device and review the prerequisites. A disabled service or a previous Hotspot RADIUS configuration also requires review.
Guest ports and management access
In Internet review the observed connection, address and mode: DHCP, PPPoE including VLAN, or static IP. The existing connection and its underlying physical interfaces remain excluded from guests. A network that cannot be identified confidently requires technical review and another reading.
The guest-port table without VLAN shows only interfaces that can join the bridge directly, with state and connection. VLAN transport ports are selected separately in Bridge e VLAN. Open Excluded interfaces and reasons to review the others separately. Local management permissions alone do not make a free port occupied; the future guest network is automatically excluded from local management during application. For new activations, ports already assigned to customer bridges, addresses, services, groups or rules remain occupied even when unplugged. Enabled radios, CAPsMAN, virtual radios and Internet interfaces are protected. Disabled, disconnected local radios without other assignments can be selected and configured as access points.
For each selected radio choose SSID, country and open access or WPA2. Confirm enabling disabled interfaces. Previously applied installations keep their settings; retain management access and test every update.
VLAN ports and initial Wi-Fi configuration
The Porte e bridge che trasportano la VLAN table shows observed Ethernet ports and bridges, with their state and availability. You can select an enabled existing bridge without VLAN filtering, including one carrying the private network and Internet. The guest VLAN is created on that bridge; its ports, addresses and services are retained. Unavailable ports remain visible with the reason. If a port already belongs to a bridge, select the available bridge as the VLAN parent. The port retains its membership. Internet ports remain protected. Availability refers to the indicated reading; request a new reading after manual changes.
During first activation, the legacy Wi-Fi radios selected for guests are reset and configured with the confirmed SSID, country and security. The Wi-Fi panel and summary identify the radios that will be reset. Previous settings are retained for restoration. Radios serving other Wi-Fi networks require review before selection. Saving a draft does not reset radios.
If a step fails, the message distinguishes reset, channel, country, access point mode, network name and security. Wait for the restoration result and share the message with support. Later Hotspot setting changes apply only the confirmed choices.
Network, portal and draft review
In Bridge e VLAN, choose whether to create Hotspot on a VLAN. The guest bridge is automatic. For example, choose Yes, enter 50 and select ether8. You can also select RetePrivata: VLAN 50 on that bridge joins the guest bridge, where Hotspot runs. RetePrivata retains its existing network. In the following step you can also add, for example, ether4 without VLAN to the same guest bridge. An existing VLAN is reused only if available and compatible; a VLAN assigned to other services requires review first. Connected switches and access points must carry the same VLAN. In the next step, Altre porte ospiti senza VLAN lets you add normal ports or Wi-Fi, or continue without additional interfaces. Without VLAN, select at least one available port or radio. Turning VLAN off requires a new port choice and does not automatically convert its transport port. Active networks are edited in Hotspot settings using observed device values.
Enter a private IPv4 network from /16 to /28, gateway and DHCP range. For new activations existing DNS servers are displayed read-only and retained. If the DNS service for devices is off, it is protected and enabled automatically when applying; previously managed installations keep the choice of one or two IPv4 DNS servers. Recognized overlaps, addresses outside the network and ranges containing the gateway are rejected. New activations do not move ports out of the customer network; previous installations retain their management-access requirements.
In Portale e accesso, choose a published portal and a Hotspot profile belonging to your ISP. Each profile appears once, even when it contains multiple attributes. This choice concerns initial installation; for an active site use the dedicated portal choice and confirm its summary. The profile is retained with the final save. Access mode follows the published portal.
The selected Wi-Fi country is adapted to the format required by the radio. After a compatibility correction, retry the saved configuration without entering the SSID and country again.
The MikroTik name needed for the certificate is prepared automatically on the device. The certificate requires RouterOS 7.22 or later within series 7, stable or long-term. Confirm the choice, review the Riepilogo and select Salva e registra gateway. Choices are saved and the gateway is registered for authentication. If requirements remain outstanding, the button becomes Save draft and only saves your choices: complete the listed requirements and update the reading before registration and application. Initial registration updates the Hotspot service and may briefly interrupt new logins. From the gateway page, review the summary and select Applica configurazione salvata to apply the network, portal and certificate. No interface is enabled while moving through the steps.
Create and associate a gateway
Select Aggiungi gateway and read the requirements shown above the form: a MikroTik already connected to the Internet, with interfaces available for guests, with working name resolution and correct date and time; a stable RouterOS 7 release, version 7.16 or later; and WinBox access with configuration permissions. Check the installed version under System → Resources → Version and complete any updates and restarts before running the script.
Enter a name and site, add optional notes and select Crea gateway e continua. For example: site “Central Cafe”, gateway “Main entrance”. Creating the gateway opens its details, where you can prepare the script.
When first opening Configura hotspot, Recupero dei dati dalla MikroTik appears with an animated loading indicator: please allow a few minutes. The message distinguishes waiting for data from receiving it. Keep the MikroTik powered on and connected to the Internet: configuration opens automatically once ports, Wi-Fi and network settings are available. If loading fails, select Riprova verifica.
Open its details, select Genera script di attivazione and Copia script. Run the script in the WinBox Terminal within 15 minutes. The script contains a private credential: never publish it or share it with guests, including in exports or logs that contain its source. If the connection fails, send support only the Terminal line beginning with “ISP Billing: collegamento non completato”. If the Terminal reports an incompatible RouterOS version, update to stable RouterOS 7.16 or later within the 7 series and repeat installation. RouterOS 6 is not supported. The “script installed” message does not yet confirm connectivity: wait for Collegato in ISP Billing. Before the first association, generating another script invalidates the previous one. After running it, select Aggiorna stato.
Automatic connection recovery
After you paste the new script, the MikroTik retrieves its updated management program from ISP Billing and retries the connection after temporary interruptions. Keep it powered on and connected to the Internet. The new script also prepares the certificates needed for a secure connection, without a separate manual import. If all DNS settings are absent, it can use the servers prepared by support; existing DNS and DoH settings are retained. Correct an Internet or DNS problem instead of resetting the gateway again.
The Terminal distinguishes script installato, collegamento da completare (script installed, connection pending) from script installato e contatto riuscito (script installed, contact successful). In both cases select Aggiorna stato and wait for Collegato in the gateway page: installation alone does not prove that guests can browse. If the credential expires before the first association, generate another script. For a previously associated device that was reset, use Gestione avanzata → Ricollega o sostituisci MikroTik on the same page.
Program updates are retrieved automatically when the gateway can communicate with ISP Billing. An older script blocked before making contact cannot receive them: after support updates the service, paste the new script once. Applying saved Hotspot settings still requires your confirmation.
Reuse a MikroTik after a failed connection
If the initial connection failed and you want to use a new gateway page for the same MikroTik, revoke or delete the old gateway first. From the new gateway, select Genera script di attivazione and run the script within 15 minutes: it replaces the recognized previous ISP Billing connection while retaining Internet access. Wait for Collegato, then complete the Hotspot configuration from the new gateway.
If the MikroTik already has a Hotspot or a previous guest configuration, replacement stops with a message: use recovery from the old gateway page or share the message with support. Shared, customized or unrecognized connections require support. This feature does not transfer the guest network to the new gateway.
To use the new automatic recovery, generate a new script after support updates ISP Billing. Reachable gateways retrieve program updates; devices blocked before making contact require the new script.
HTTPS certificate and retries
The certificate obtained for the gateway is retained even after restoring the network. Later attempts reuse it if it belongs to the gateway, matches the portal name and is usable. Renewal remains automatic on the MikroTik, which must stay connected to the Internet. If the gateway certificate no longer exists, a new activation can request it again after checking that it belonged to the gateway and that the portal name is unchanged. A renamed certificate is retained and requires checking its name in System → Certificates. A certificate belonging to another configuration or with mismatched details requires support.
Messages distinguish an incomplete request, failed issuance, an expired waiting period and an unusable certificate. If its status cannot be read, share the message with support: this error may occur even when the certificate has already been issued. After the correction, select Applica configurazione salvata to check the retained certificate again. If only the waiting period expires, wait a few minutes and retry: the existing certificate request is checked again. If issuance fails or a request limit is reported, contact support before retrying activation. The certificate is retained for diagnosis. Do not delete it manually or reinstall the connection to address this error.
Configuration preparation or transfer incomplete
If a configuration limit message appears, share it with support before changing the selected ports. Your saved choices remain available.
If the transfer does not finish, check that the gateway is connected and refresh its status. When Applica configurazione salvata is available, retry from the gateway page. If restoration needs verification, wait for a technician before continuing. You do not need to create another gateway.
Network configuration incomplete
If activation stops while configuring the network, the message identifies the step that could not be completed, such as creating the Hotspot service, ordering protection rules, bridge, DHCP, Wi-Fi or enabling ports. For the Hotspot profile, the message also distinguishes the portal directory, certificate, login method and RADIUS settings. Share the message with support before retrying. Configurazione precedente ripristinata confirms restoration of the previous settings; Ripristino da verificare requires a technician.
If an earlier attempt shows only a generic network error and restoration is confirmed, retry Applica configurazione salvata to obtain the detail. You do not need to reinstall the connection script or create another gateway.
If an error is reported while setting HTTPS redirection in the profile, wait for the correction provided by support. Once restoration is confirmed, retry Applica configurazione salvata; the retained certificate is checked again and login continues to use HTTPS.
Update RouterOS from the gateway
The gateway page presents status and actions in compact blocks. Expand RouterOS e manutenzione to see the installed version and compatibility. Select Verifica aggiornamenti and wait for the MikroTik response. The check looks for a newer compatible release on the stable channel and installs nothing.
When a version is offered, keep a backup and select Aggiorna RouterOS. Confirmation shows the installed and proposed versions and warns about the restart: connections will be temporarily interrupted. Keep the gateway powered on. Completion appears only after the MikroTik reports the new version. You can then apply the saved Hotspot configuration.
Hotspot write permission and a connected RouterOS 7 gateway are required. If device permissions are missing, open Abilita il riavvio da ISP Billing and follow the WinBox instructions using an administrator account. Do not start other network changes during an update. If the result cannot be confirmed, inspect the device before checking again; installation is never repeated automatically. Upgrade RouterOS 6 through WinBox before connecting it. A compatible long-term release already allows Hotspot activation.
Activate and restore Hotspot
After saving and registration, open the gateway page, review the summary and select Applica configurazione salvata. Read the confirmation: selected ports become guest ports and affected connections may be interrupted. Keep management access to the MikroTik. Hotspot write permission, a connected device and RouterOS 7.22 or later in series 7, stable or long-term, are required. First installation requires a dedicated device without an existing Hotspot.
Verifica apparato in corso means the system reads the MikroTik and checks that saved ports, network, Wi-Fi, profile and portal are usable. Compatible settings are applied as soon as the complete reading is available, including after a reset or with an older reading. If reading fails, the message identifies the settings not received and the next action; there is no need to wait for verification to expire. You may leave the page during the operation. Elapsed time alone does not require recreating the configuration. If Scelte da rivedere appears, read the reason, open Modifica configurazione, correct the choices and save. Unavailable saved interfaces remain visible until you remove them from the selection. Retry with Applica configurazione salvata (Apply saved configuration). If verification does not complete within ten minutes, check connectivity and retry.
Credentials, voucher and passwordless portals are supported. For passwordless access, guests enter their name, email and mobile number, accept the terms and select Accedi. No SMS, password entry or code is required. Contact details are collected without verification. The profile selected on the gateway provides the access limits. The automatic certificate uses a MikroTik name and requires Internet connectivity and a correct clock. Devices receive the gateway as DNS; selected DNS servers are used for Internet. Credentials and vouchers use the limits of their assigned account profile; selecting a wizard profile does not modify existing accounts.
Keep the gateway powered on and select Aggiorna stato after a few minutes. Configurazione applicata confirms the device network, portal and certificate; still test portal opening, login and browsing from a guest device. If preparation stops, the message identifies the requirement to correct, such as RouterOS version, Hotspot capability, guest network, profile or portal. Follow the suggested action and retry Applica configurazione salvata. Unexpected problems identify the phase: if repeated, share the message with support. Initial MikroTik checks also distinguish a condition preventing activation from a check the device cannot complete. If a check cannot be completed, the message explains the recognised problem and the next useful action. When the precise cause is unavailable, this is stated without blaming existing rules. Earlier attempts without details require a new attempt to obtain the reason. An uncertain result requires restoring connectivity and reading the status again, without creating another gateway.
When available during first installation, Richiedi ripristino removes this activation and restores the settings it changed, interrupting guest access. Wait for confirmation before reviewing and saving the wizard again. Avoid manual device changes between activation and restoration. Contact a technician when restoration requires verification. Failed activation attempts trigger restoration; its result still needs confirmation.
Understand activation errors
For some errors without an identified cause, ISPINO automatically adds one or two suggested checks from official MikroTik documentation below the message. The source links can be opened directly. No additional button is needed. The suggestion does not confirm the cause or change the MikroTik; if unavailable, the original message remains.
The error message directly explains the detected problem and the next useful action. When the MikroTik identifies insufficient permissions, exhausted memory, a missing item, a rejected value or an unsupported command, the corresponding guidance is shown. If the precise cause is unavailable, the page says so and does not suggest deleting rules without an identified conflict.
When a new authorization is not confirmed, the message identifies the site and HTTP/HTTPS port, MAC or affected firewall permission and indicates where to check. It distinguishes a missing rule, duplicate rules and an existing rule with different settings. For a site, verification checks the domain, HTTP or HTTPS port, TCP protocol, site Hotspot, allow action and enabled state of the rule together. Firewall verification also checks return traffic towards the guest network for the allowed connections. To confirm a firewall authorization, its rule must be enabled, unique for that authorization and have all required values. Multiple rules for the same authorization are duplicates even when their settings differ. When retrying application, check the latest result date to distinguish the new attempt from the previous one. If authorization verification stops because a command is not recognized, that message does not identify which rules are correct or should be removed. If the number of rules created by the attempt differs, the available counts are shown. This result does not prove that old rules remain: do not delete other rules without an identified conflict. The detail describes the failed attempt; its rules may already have been undone by restoration. If the previous result is generic, once restoration is confirmed, retry Applica configurazione salvata (Apply saved configuration) to obtain the detail of a new attempt.
After manually deleting an old Hotspot, enabled rules may remain in IP → Hotspot → Walled Garden IP with Server referring to the deleted service. First activation reports them before applying the network. Identify the rules of that server and remove only remnants of the old installation; preserve rules with Server=all and rules needed by other services. Then select Rileva / aggiorna apparato (Read / refresh device) and retry activation.
After an error during application, check restoration status first. Configurazione precedente ripristinata (Previous configuration restored) allows reviewing choices and retrying. With Ripristino da verificare (Restoration needs checking), inspect the MikroTik and complete restoration before another activation.
Gateway registration and errors
The Registrazione del gateway panel shows the result and latest confirmation time. Registrazione confermata means the gateway was registered for authentication and the service acknowledged its update; guest networking must still be activated and a real login tested.
If registration does not finish, the saved draft remains available. Use Riprova registrazione to resume from that draft; do not create another gateway. Save any new changes first. An address already used with different details requires support. Saving an unchanged, confirmed registration again does not restart the service; retrying an uncertain result may repeat the update.
If Registrazione non disponibile appears, contact support. Hotspot write permission is required; read permission allows viewing the result. Manage guided gateways from their own page rather than the legacy manual screens.
Edit an active Hotspot network
Open the gateway → Impostazioni Hotspot. Available sections are Portal, Ports and VLANs, Wi-Fi, Addresses, and Walled Garden and MAC bypass. Values come from the MikroTik: manual changes appear after a new reading. Portal also shows the address, page directory, login methods and RADIUS usage observed on the device. Reading retains the MikroTik configuration and also shows changes made in WebFig.
When opening the page with write permission, missing or outdated values trigger a reading. Later readings arrive in the background: the page does not reload, and entered fields, position, filters and table page stay in place. If values are identical, only the date changes. If they change, Nuovi valori disponibili (New values available) appears: select Mostra nuovi valori when ready. Unsaved edits are replaced only after confirmation. Use Aggiorna dalla MikroTik to request another reading. Date, status and message show the outcome. The page resumes reading after a temporary interruption and indicates when new values are available. If the MikroTik stops sending values, the reading button becomes available again; when known, the message identifies the section that could not be read. The latest complete values retain their own date. Last contact identifies connectivity, Last reading identifies the received configuration, and Latest confirmed result identifies application or restoration: their times may differ. Once complete values exist, you can continue entering changes during a reading. Before the summary, values are checked for freshness and the displayed configuration must still be valid. Wait for a reading when needed; if configuration has changed or verification cannot finish, entered fields remain on the page. Editing stays disabled until the first complete reading.
Open a section, edit only the required values and select Rivedi e applica modifica. Check and confirm the summary. Changing the portal affects the page and any access settings listed in the summary. Ports and VLANs can disable a managed member, change a managed VLAN number or its parent port/bridge or add a free port with an optional VLAN. An existing bridge can only be selected as a VLAN parent; it is never added directly to the guest network. Manual VLAN parent changes appear after the next reading. Wi-Fi can change the guest network name. Addresses can change DHCP, guest DNS, pool or guest network addresses. Customer rules marked as view-only remain managed on the device.
Your choice is checked again before application. If an affected value changes meanwhile, read again and confirm the new summary. A manual change in another area is preserved. Avoid simultaneous MikroTik edits while a request is running; address or port changes may interrupt guest connections.
The page follows device confirmation and the final reading. An offline gateway completes the request when available. With Ripristino da verificare, contact support before more changes. Write permission is required to request readings and apply changes; read-only access allows viewing the latest available values. Initial installation keeps its guided procedure.
Update gateway configuration
For an associated gateway that has not been revoked, open its details, expand Gestione avanzata and select Aggiorna collegamento. Hotspot write permission is required. Read and confirm the request: the connection may briefly be interrupted. Leave the MikroTik powered on and connected to the Internet; it will receive the available settings at its next contact, without reinstalling the script.
Select Aggiorna stato and wait for Collegamento configurato. If the gateway is offline, the request remains pending. A message distinguishes an already confirmed configuration from one awaiting confirmation. If the new settings require support, contact support before proceeding. This action updates the connection. Use Applica configurazione salvata to apply the first guest network configuration.
Understand the status
Da attivare: saved, awaiting setup. In attesa di attivazione: script generated. Attivazione scaduta: generate a new script. Collegamento in preparazione: leave the device powered on and wait. Collegato: recent contact with ISP Billing. Non raggiungibile: check power and Internet access.
Details show the model, RouterOS version, last contact and connection configuration confirmation. “Collegato” does not certify guest Internet access: verify it separately. Follow any error message or contact support. If the page has expired, reload it before repeating an action.
Retry automatic activation
To retry an incomplete activation, select Applica configurazione salvata. The device reading is refreshed automatically; you do not need to request a manual reading first. If the same comparison error returns without changes to the device, share the message with support. When Scelte da rivedere is shown, review and save the indicated settings before retrying.
Revoke or replace a device
Under Gestione avanzata, Revoca collegamento stops remote gateway management. Read the confirmation before proceeding. If Revoca da completare appears, repeat the action when the service is available; the operation is complete only when Revocato is displayed.
For a reset or replacement MikroTik, use Ricollega o sostituisci MikroTik on the same gateway page, including after revocation. Hotspot write permission is required. Disconnect the previous device from the site network when replacing it, then read and confirm the consequences: its connection is disabled and pending operations are cancelled. The name, site, portal and saved configuration are retained. The gateway name is also assigned to the MikroTik; after saving a new name, the device receives it on its next connection.
Once the new script is ready, paste it into the WinBox Terminal of the dedicated MikroTik, already connected to the Internet, within 15 minutes. Select Aggiorna stato; after reconnection, choose Applica configurazione salvata (Apply saved configuration) or Modifica configurazione (Edit configuration). Applying checks compatibility with the MikroTik automatically and proceeds when valid; missing ports or incompatible networks are reported for correction. Editing opens the retained settings with freely accessible Internet, port and Wi-Fi sections. If device information is missing, the reading starts automatically and the settings open when ready. If the device does not respond, use Riprova verifica (Retry check). Reconnecting alone does not activate guest access. If Ricollegamento da completare appears, use Riprova ricollegamento: the script becomes available only after removal of the old connection is confirmed. If the script is lost or expires before pairing, reload the page and generate a new one. Revoking the connection does not close existing guest sessions or terminate a commercial service.
Profiles and portals
If the phone does not open the portal automatically, reconnect to the guest network and open the gateway’s HTTP address shown on the site page. If the portal appears, test login and Internet access; otherwise check the gateway connection and configuration.
Profiles define speed, duration, simultaneous access and other conditions supported by the network. A change may affect every associated account. Separate portal settings exist for credentials, password-free access and vouchers, including colours, logo, background and content. In the Portal library, the profile is selected only at the gateway and applies to new registrations after configuration is applied; existing accounts keep their profile.
The module navigation shows Generali, Profili, Gateway and Portali. Walled Garden and MAC bypass are managed on each gateway page. The three older Captive Portal links are hidden from this navigation; their pages and settings remain available at their existing addresses for existing installations. The Portali section lets you prepare independent designs for different sites. The portal is installed when the gateway configuration is activated.
The portal chooser also shows the actual access mode: the portal name does not determine its mode. Rimuovi scelta immediately opens the list to choose again. To change the mode of a portal in use, duplicate it, select the mode on the copy, publish it and assign it to the gateway. Review and save changes, then apply the saved configuration.
Portal library: create and edit
Open Settings → ISP Radius Hotspot → Portali and choose Crea portale or open an existing portal. Read permission allows viewing and previews; write permission allows saving and publishing.
The editor has five tabs: Accesso e registrazione (access and registration), Grafica e immagini (design and images), Testi e struttura (text and venue), Consensi e rubrica (consent and contacts), and Pubblicazione e gateway (publication and gateways). The first four show the preview alongside settings; the fifth brings versions and associated sites together. Save actions and draft status are in the bottom bar.
The portal defines access mode, text and design. Select the profile only in gateway configuration: sites can share one portal with different speeds and limits. New registrations use the profile applied at the site; existing accounts retain their assigned profile.
Preview, publish and restore
The preview follows your edits. Choose Telefono (phone) or Computer: the whole screen is shown at scale, with its dimensions and percentage. Scroll inside it when content exceeds the screen. Choose Accesso (login) or Registrazione (registration) when available, and compare draft, published and previous versions. Fields and buttons are demonstrations.
Salva solo bozza keeps work without showing it to guests. Salva e pubblica updates all associated sites; review the confirmation and affected sites. Under Pubblicazione e gateway, publish a draft, duplicate a portal or restore its previous version. To change a single site, duplicate the portal and assign the copy to that gateway.
Guest pages use compact logos and images. The portal image field displays one photo; the background stays separate and no image selectors are shown. Service operator information appears in the footer outside the card.
Opening the Wi-Fi login page
Join the guest network and wait for the login page. Automatic opening also depends on the phone: if the page does not appear, open the Wi-Fi network details and select its login option when available. If the delay recurs, report the phone model and gateway.
To update the login pages of an already configured gateway, open Modifica configurazione, review your choices, save again and select Aggiorna adesso. Wait for Configurazione applicata, then test with a device that has not yet authenticated. Connections may be interrupted during the update. Publishing text and images updates the online portal content; updating the gateway login pages requires this one-time step.
Portal link
Copy the Link del portale from the portal page. The address contains a long random code and remains stable when saving or publishing content; a duplicate gets a different address. Always use the displayed link instead of constructing it from portal numbers.
For credentials portals, opening it outside Wi-Fi shows the personal area protected by mobile number or username and password. Opening the link alone does not grant Internet access. When replacing an older numeric address, update shared links and QR codes: the old address may no longer be available.
Choose a portal for a site
For an active Hotspot, open the gateway → Cambia portale. Choose a published portal, select Rivedi e applica modifica and confirm the summary. The choice takes effect after device confirmation. Each gateway uses one portal; several sites may share it.
Publishing text and images for an already online portal updates content on the next opening or reload. To change access mode, duplicate the portal, choose the mode on the copy, publish and confirm it for the site. Moving a local portal online requires the same explicit choice.
Before activation, choose the portal in the guided procedure with other initial settings. Hotspot write permission is required.
Library states and errors
Bozza: never published. Pubblicato: the draft matches the published version. Modifiche in bozza: a published version exists and the draft contains unpublished changes. Use name and state filters and the last modified date to find a portal.
If the portal or its associations changed in another page, the operation stops: reload and review before confirming. Reload an expired page. For rejected images, check format, dimensions and file integrity. Contact support if the library is unavailable. Before publishing, check both preview sizes, associated sites and the version to use.
Registration and password recovery
Under Generali → Messaggi agli ospiti, configure the sending service. In Portali → Accesso e registrazione, enable account creation and choose whether to verify the mobile number with a code. Select the new guest profile in gateway configuration; changes take effect after application and do not reassign existing accounts.
Existing guests enter mobile number or username and password. Choose the dial code from the list with flags. The phone field supports the phone’s contact suggestions and accepts a complete international number. Errors appear centrally with actions to retry, recover the password or create an account.
Crea account asks for name, mobile number and a password chosen by the guest. Email and city may remain blank. Verify a code when configured; credentials and Collegati appear after creation. An existing number does not create a second account. Recupera password sends the existing account password to its mobile number.
After login or new registration, the same device at the same venue can show Bentornato for 24 hours: select Accedi or Usa un altro account to enter different credentials. Switching accounts clears quick return. The browser must retain recognition; clearing its data or changing the device’s private address requires login again. Opening this page does not automatically authenticate the personal area. The form discourages password saving, but the browser makes the final decision.
Mobile number in account details
When creating or editing an account, choose the country from the flag beside the mobile field and enter the number. The contact is saved with + and the international dial code, including new portal registrations. An administrative contact may remain blank. The login username retains its format and is not changed by the dial-code selection.
Service conditions and offers
To collect newsletter subscriptions, enable collection and specify the controller and sender, HTTPS privacy notice and channels. A separate unchecked Acconsento a ricevere novità e offerte — leggi checkbox appears. Consent remains voluntary and does not block Wi-Fi. Its dialog explains the controller, channels, privacy notice and unsubscribe option.
In passwordless mode, new guests enter name and mobile number; email and city may remain blank. They accept the conditions and may opt into communications. Returning from the same device shows Accedi without repeating details or consent.
Venue and welcome email
Under Testi e struttura, enter the venue name and contacts. Blank fields are hidden. The website is used by Naviga after login; it opens in a new tab when supported by the browser. ISP information appears outside the card.
In General settings choose the guest email sender. New registration sends a welcome email with credentials and a personal link only when the guest entered an email address. It is separate from newsletter enrollment and needs no confirmation. The portal shows only the confirmation page with credentials: select Collegati to access the Internet. Registration confirmation also shows the sending result. If sending fails, the account remains valid: keep the displayed credentials and select Collegati. If sending succeeds but the message is missing, also check the spam folder.
Guest personal area
Guests can open the portal link outside Wi-Fi and sign in with mobile number or username and password to view and edit name, email and city. The mobile number remains the login identity. They can change password by entering the current one, view observed sessions and request disconnection. Deletion requires password and explicit confirmation.
Signing out of the personal area does not stop Wi-Fi browsing. Connection status may be unavailable; a reachable site must confirm disconnection requests.
Recognized devices
When device recognition is available, on mobile number and password portals each account can associate up to two devices for 24 hours after their first login. Reconnection within this period can be automatic; credentials are required again after expiry. Any shorter profile limits still apply.
For a third device, choose replacement, verify the mobile number by SMS and select the device to remove. Wait for confirmation before continuing. A device that changes its private address may be recognized as new. Voluntary logout may require entering the password again.
Walled Garden and MAC bypass by site
Open the gateway → Modifica autorizzazioni. Before activation, save lists for initial configuration. For an active Hotspot, the page shows observed rules and lists managed for this site.
Select Modifica gli elenchi di questa sede. Enter up to 50 exact domains, one per line, such as www.example.org. Add required subdomains, without paths, IP addresses or wildcards. HTTP and HTTPS are supported. Required portal destinations are retained.
Enter up to 50 unicast MAC addresses, one per line, such as 02:11:22:33:44:55. These devices browse without authentication at this site, without a RADIUS account profile or limits. Use the MAC shown for this network; bypass cannot recognise it if it changes. Use account-authorised devices to retain account limits.
To revoke access, remove the domain or MAC from its list. Select Rivedi e applica modifica and confirm the listed additions and revocations. Customer rules are view-only. Conflicts with manual rules require review before adding bypass. Manually deleted or disabled rules stay as observed; a new permission must be requested and confirmed.
Check the result and test websites and devices without an active login. Changed devices may need to reconnect. Incomplete sites may require extra domains; sites sharing an IP may share permission. Hotspot write permission is required; read-only users can view values.
Accounts and provider identifier
Under Generali, the provider identifier is read-only. You do not need to enter it. Hotspot write permission is required to save other settings.
The same mobile number can be registered with different ISPs, using separate accounts and passwords. Guests select the international calling code and enter their mobile number and password; they can also enter the full number starting with +. Voucher users enter the code they received. No additional identifier is required.
The dashboard shows numbers, codes and profile names without the provider suffix. Accounts registered through previous portals retain their credentials. If a historical account is not recognized, contact support before changing it.
The new portal installed on the MikroTik provides login with existing accounts and vouchers. For mobile number and password portals, password recovery is available even when registration is disabled, after SMS service setup. Save and publish changes to update online portals. Online portals show the current publication. Older local portals must first be connected to the online service.
Accounts and vouchers
Under Account list → New Hotspot access, choose Username and password or Named voucher. Enter the account holder and profile; email, mobile number and city complete the record. A voucher generates a code in the va-12345678 format when saved and displays it in the account page. For credentials, enter a password or generate a six-digit password.
No expiry sets no end date; Duration in days accepts 1 to 3650 days. New manually created accesses start their duration when saved. Editing keeps the displayed start date; unused batch vouchers keep their first-use start. Profile limits still apply. Leave the new password empty to keep the current password.
An existing account retains its access type. You can change its holder, contacts, profile, validity, status and notes. Groups still generate voucher batches and PDF printouts. Verify login and expiry with a test account before distributing access. Creation and editing require Hotspot write permission.
RADIUS disconnect requests
Initial Hotspot configuration enables incoming RADIUS disconnect requests from the designated server. For an older gateway where this service is disabled, request a specific support review. Portal and permission changes preserve this setting.
Disconnect requests and session counts are separate checks: this setting does not close old session records left open on the server.
Hotspot dashboard: network and guests
Open DashBoard Radius from the Radius HotSpot menu. The page shows managed gateways, connected gateways, observed guest connections and gateways needing attention. The chart separates connected, unreachable, pending and revoked gateways; bars show up to five sites with recent readings, ranked by connection count, including sites with zero guests. Sessioni RADIUS opens records without a closing confirmation, whose count may differ from guests observed on gateways. The list shows the last update and marks records Da verificare after 15 minutes without recent data; it does not automatically close sessions.
Each gateway shows site, model, last contact, guest count and Hotspot status. Collegato means recent communication; Hotspot configurato means confirmed configuration, which alone does not verify guest Internet access. Use the Gateway, Site and Connection column filters to find sites or issues. The standard paginated table includes all gateways; choose Apri to take action.
Data refreshes every minute while the page is visible, or with Aggiorna. Refresh also updates the gateway table while preserving its filters and selected page. On the Gateway list, Aggiorna elenco reloads the current page. Readings are considered recent for four minutes. A dash means no reliable count is available, rather than zero guests. The total states how many gateways have recent readings and counts connections, not unique people. Revoked gateways do not contribute to online guests. If refresh fails, a warning retains the previous data and its timestamp.
Viewing requires module access and read permission. The overview covers up to 1,000 gateways; a notice links to the complete list when the limit is reached.
Open MikroTik WebFig
An account with Radius HotSpot write permission finds Apri WebFig on an associated gateway detail and in the Gateway and Dashboard lists. Press it to open a new window directly, then enter the MikroTik username and password. If the browser blocks the window, allow new windows for ISP Billing and try again.
To enable an operator, open Account admin → Ruoli (Admin accounts → Roles), edit their role and select MODIFICHE nel Modulo Radius HotSpot (Radius HotSpot write permission). Keep VISUALIZZAZIONE (read permission) to access the module pages. Full administrator status is not required. Read permission alone does not enable WebFig. Removing write permission also revokes authorization for that account’s existing WebFig access.
When the gateway is already ready, WebFig opens directly. If the first access needs preparation, ISP Billing handles it and opens WebFig once the MikroTik confirms: leave the window open, with no additional manual steps. Once access is ready, that same window automatically moves to WebFig. The prepared service and access permissions remain configured after a MikroTik reboot. If the gateway does not respond or has incompatible custom settings, a message is shown; try again or contact support.
Each access lasts one hour and extends automatically during use. It may end after a period of inactivity. Reloading a page from an ended access shows Riconnetti (Reconnect) and Torna a ISP Billing (Return to ISP Billing): Reconnect reopens WebFig in the same tab. If your ISP Billing session has ended, sign in again before continuing. You may need to enter your MikroTik credentials again. Opening a new one automatically closes your previous access on the same gateway. Other administrators retain their access, within the total limit of three per gateway. On the WebFig page, use Chiudi accessi WebFig to end your own access. Closing it does not disconnect guests.
Before activation, the link stays visible but the page shows WebFig da attivare with disabled actions. WebFig provides the operations allowed to the MikroTik user you enter, including functions beyond Hotspot. Changes take effect directly on the device. Use Hotspot settings for guided guest operations and refresh the reading after manual changes. WebFig availability does not confirm guest Internet access.
Daily use and customer services
Dashboards summarize access. Consult Utenti Online, authentication requests and session history to investigate errors, times and usage. Check the date and time of the information before drawing conclusions.
Hotspot accounts can be linked to customer services. The Customer Area and service details show permitted information; unbilled services remain in their dedicated checks. The new gateway record does not automatically change billing or account status.
Operating practices
Use dedicated devices and recognizable site names. Limit operator access, protect installation scripts and keep a private copy of device configuration. Try changes on a lab gateway before using them at customer sites. Do not deliver a hotspot based solely on its connected status.
Checklist
- Check service availability and permissions
- Create a gateway with a name and site
- Prepare MikroTik Internet access and clock
- Run the script before it expires
- Check last contact and configuration confirmation
- Have the technician complete guest networking, authentication and portal setup
- Test login, browsing, limits and logout
- Distribute only verified credentials and vouchers
- Confirm any revocation is complete