Jump to content

Template:Networking rutos manual hotspot: Difference between revisions

From Teltonika Networks Wiki
No edit summary
No edit summary
(35 intermediate revisions by 5 users not shown)
Line 1: Line 1:
{{Template: Networking_device_manual_fw_disclosure
{{Template: Networking_rutos_manual_fw_disclosure
| series = {{{series}}}
| fw_version ={{Template: Networking_rutos_manual_latest_fw
| name  = {{{name}}}
| fw_version ={{Template: Networking_device_manual_latest_fw
  | series = {{{series}}}
  | series = {{{series}}}
  | name  = {{{name}}}
  | name  = {{{name}}}
  }}
  }}
}}
}}
{{#ifeq: {{{series}}} | RUT9 |<br><i><b>Note</b>: <b>[[{{{name}}} Hotspot (legacy WebUI)|click here]]</b> for the old style WebUI (FW version {{Template: Networking_device_manual_latest_fw | series = RUT9XX}} and earlier) user manual page.</i>|}}
{{#ifeq: {{{series}}} | RUT9 |<br><i><b>Note</b>: <b>[[{{{name}}} Hotspot (legacy WebUI)|click here]]</b> for the old style WebUI (FW version {{Template: Networking_rutos_manual_latest_fw | series = RUT9XX}} and earlier) user manual page.</i>|}}
{{#ifeq: {{{series}}} | RUT2 |<br><i><b>Note</b>: <b>[[{{{name}}} Hotspot (legacy WebUI)|click here]]</b> for the old style WebUI (FW version {{Template: Networking_device_manual_latest_fw | series = RUT2XX}} and earlier) user manual page.</i>|}}
{{#ifeq: {{{series}}} | RUT2 |<br><i><b>Note</b>: <b>[[{{{name}}} Hotspot (legacy WebUI)|click here]]</b> for the old style WebUI (FW version {{Template: Networking_rutos_manual_latest_fw | series = RUT2XX}} and earlier) user manual page.</i>|}}
==Summary==
==Summary==


On Teltonika Networks devices a <b>Hotspot</b> is a service that provides authentication, authorization and accounting for a network. This chapter is an overview of the Hotspot section for {{{name}}} devices.
On Teltonika Networks devices a <b>Hotspot</b> is a service that provides authentication, authorization and accounting for a network. This chapter is an overview of the Hotspot section for {{{name}}} devices.
{{#switch: {{{series}}}
  | #default =
  | RUT36X|RUT9|TCR1|RUT2|RUT2M|RUT9M|TRB1|TRB2|TRB5 =
<u><b>


<u><b>Note:</b> Hotspot is additional software on some devices that can be installed from the <b>System → [[{{{name}}} Package Manager|Package Manager]]</b> page.</u>
Note:</b> Hotspot is additional software that can be installed from the <b>System → [[{{{name}}} Package Manager|Package Manager]]</b> page.</u>
}}


==General==
==General==
Line 26: Line 29:
</ol>
</ol>


[[File:Networking_rutos_manual_hotspot_hotspot_instances_add_button_edit_buton_wifi.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_hotspot_instances_add_button_edit_buton_wifi_{{{wifi}}}.png|border|class=tlt-border]]


After this, a new Hotspot configuration window will appear.
After this, a new Hotspot configuration window will appear.
{{#switch: {{{series}}} | RUTX | RUTM | RUTC = <b>Note:</b> Devices that have hotspot in core can support up to 5 hotspot instances.}}


====General Settings====
====General Settings====
Line 39: Line 40:
----
----
{{#switch: {{{series}}}
{{#switch: {{{series}}}
   | #default = [[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_general_v3.png|border|class=tlt-border]]
   | #default = [[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_general_v2.png|border|class=tlt-border]]
   | TRB1 | TRB5 | TRB16 = [[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_general_trb_v1.png|border|class=tlt-border]]}}
   | TRB1 | TRB2 | TRB5 = [[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_general_trb.png|border|class=tlt-border]]}}


<table class="nd-mantable">
<table class="nd-mantable">
Line 50: Line 51:
     <tr>
     <tr>
<td>Configuration profile</td>
<td>Configuration profile</td>
<td>Cloud4wi | Default | Hotspotsystems | Purple portal; default: <b>Default</b></td>
<td>Cloud4wi | Default | Hotspotsystems; default: <b>Default</b></td>
<td>Pre-configures Hotspot settings according to the selected service provider.</td>
<td>Pre-configures Hotspot settings according to the selected service provider.</td>
     </tr>
     </tr>
Line 60: Line 61:
     <tr>
     <tr>
<td>Hotspot Network</td>
<td>Hotspot Network</td>
<td>ip/netmask; default: <b>{{#switch: {{{series}}} | #default = 192.168.2.0/24 | TRB1 | TRB2 | TRB5 | TRB2M |TRB16 = 192.168.3.0/24}}</b></td>
<td>ip/netmask; default: <b>{{#switch: {{{series}}} | #default = 192.168.2.0/24 | TRB1 | TRB2 | TRB5 = 192.168.3.0/24}}</b></td>
<td>IP address and subnet of the Hotspot network. Netmask must be from 16 to 30.</td>
<td>IP address and subnet of the Hotspot network.</td>
     </tr>
     </tr>
     <tr>
     <tr>
<td>IP Address</td>
<td>IP Address</td>
<td>ip; default: '''{{#switch: {{{series}}} | #default = 192.168.2.254 | TRB1 | TRB2 | TRB5 | TRB2M | TRB16 = 192.168.3.254}}'''</td>
<td>ip; default: '''{{#switch: {{{series}}} | #default = 192.168.2.254 | TRB1 | TRB2 | TRB5 = 192.168.3.254}}'''</td>
<td>Defines the IP address of your Hotspot router in network.</td>
<td>Defines the IP address of your Hotspot router in network.</td>
     </tr>
     </tr>
     <tr>
     <tr>
<td>Authentication mode</td>
<td>Authentication mode</td>
<td>Local users | Radius | MAC authentication | Single sign-on{{#ifeq:{{{mobile}}}|1| {{!}} SMS OTP}}; default: <b>Local users</b></td>
<td>Radius | Local user | {{#ifeq:{{{mobile}}}|1|SMS OTP <nowiki>|</nowiki> |}}MAC auth ; default: <b>Local users</b></td>
<td>Authentication mode defines how users will connect to the Hotspot.</td>
<td>Authentication mode defines how users will connect to the Hotspot.</td>
     </tr>
     </tr>
     <tr>
     <tr>
<td>Local users: Allow signup</td>
<td>Allow signup</td>
<td>off | <span style="color: #20C0D7;"><b>on</b></span>; default: <b>off</b></td>
<td>off | <span style="color: #20C0D7;"><b>on</b></span>; default: <b>off</b></td>
<td>Allows users to sign up to hotspot via landing page.</td>
<td>Allows users to sign up to hotspot via landing page.</td>
     </tr>
     </tr>
     <tr>
     <tr>
<td>Local users: <span style="color: #20C0D7;">Expiration time</span></td>
<td><span style="color: #20C0D7;">Expiration time</span></td>
<td>integer; default: <b>0</b></td>
<td>integer; default: <b>0</b></td>
<td>User credential expiration time. Applies to users who signed up via landing page.</td>
<td>User credential expiration time. Applies to users who signed up via landing page.</td>
     </tr>
     </tr>
     <tr>
     <tr>
<td>Local users: <span style="color: #20C0D7;">Users group</span></td>
<td><span style="color: #20C0D7;">Users group</span></td>
<td>user group; default: <b>default</b></td>
<td>user group; default: <b>default</b></td>
<td>The user group to which users signed up via landing page should be assigned to.</td>
<td>The user group to which users signed up via landing page should be assigned to.</td>
     </tr>
     </tr>
    <tr>
<td>Radius {{#ifeq:{{{mobile}}}|1| / SMS OTP}}: Enable MAC authentication</td>
<td>off | on; default: <b>off</b></td>
<td>Enable MAC address authentication.</td>
    </tr>
    <tr>
<td>MAC authentication: Require password</td>
<td>off | <span style="color:brown">on</span>; default: <b>off</b></td>
<td>Enables password requirement for MAC authentication.</td>
    </tr>
    <tr>
<td>MAC authentication: <span style="color:brown">MAC auth password</span></td>
<td>string; default: <b>none</b></td>
<td>Password for MAC authentication.</td>
    </tr>
    <tr>
<td>MAC authentication / Single sign-on {{#ifeq:{{{mobile}}}|1| / SMS OTP}}: User group</td>
<td>select; default: <b>default</b></td>
<td>Specifies the group of dynamically created users.</td>
    </tr>{{#ifeq:{{{mobile}}}|1|
    <tr>
<td>SMS OTP: Allow password duplicates</td>
<td>off {{!}} on; default: <b>off</b></td>
<td>Allows more than one user to login with a same password.</td>
    </tr>
    <tr>
<td>SMS OTP: Expiration time</td>
<td>unsingned integer; default: <b>0</b></td>
<td>User expiration time in sec (0 means unlimited).</td>
    </tr>|}}
     <tr>
     <tr>
<td>Landing Page</td>
<td>Landing Page</td>
<td>Internal | <span style="color: #f43b1a;">External</span>; default: <b>Internal</b></td>
<td>Internal | <span style="color: #f43b1a;">External</span>; default: <b>Internal</b></td>
<td>Location of the landing page.</td>
<td>If external Landing Page is chosen, new section, to enter website address, will appear, e.g., <i><nowiki>http://www.example.com</nowiki></i></td>
     </tr>
     </tr>
     <tr>
     <tr>
Line 127: Line 98:
<td>integer; default: <b>3990</b></td>
<td>integer; default: <b>3990</b></td>
<td>Port to bind for authenticating clients.</td>
<td>Port to bind for authenticating clients.</td>
    </tr>
    <tr>
<td><span style="color: #f43b1a;">Password encoding</span></td>
<td>off {{!}} on; default: <b>none</b></td>
<td>Password encoding with the challenge.</td>
    </tr>
    <tr>
<td><span style="color: #f43b1a;">Landing page address</span></td>
<td>url; default: <b>none</b></td>
<td>External landing page address (http://www.example.com).</td>
     </tr>
     </tr>
     <tr>
     <tr>
Line 145: Line 106:
     <tr>
     <tr>
<td>Success page</td>
<td>Success page</td>
<td>Success Page | Original URL | <span style="color:blue">Custom</span>; default: <b>Success page</b></td>
<td>Success Page | Original URL | Custom; default: <b>Success page</b></td>
<td>Location to return to after successful authentication.</td>
<td>Location to return to after successful authentication.</td>
    </tr>
    <tr>
<td><span style="color:blue">Custom</span></td>
<td>url; default: <b>none</b></td>
<td>Address must contain protocol (http://www.example.com).</td>
     </tr>
     </tr>
</table>
</table>
Line 157: Line 113:
=====Advanced=====
=====Advanced=====
----
----
[[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_advanced_v1.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_advanced.png|border|class=tlt-border]]


<table class="nd-mantable">
<table class="nd-mantable">
Line 168: Line 124:
<td>Additional interfaces</td>
<td>Additional interfaces</td>
<td>Available interfaces; default: '''none'''</td>
<td>Available interfaces; default: '''none'''</td>
<td>Choose additional the interfaces you want to attach to this hotspot instance.</td>
<td>Shows additional interfaces that can be attached to hotspot instance.</td>
    </tr>
    <tr>
<td>Enable MAC blocking</td>
<td>off {{!}} on; default: off</td>
<td>Blocks access to MAC addresses that have reached set amount of failed login attempts.</td>
     </tr>
     </tr>
     <tr>
     <tr>
<td>Logout address</td>
<td>Logout address</td>
<td>ip; default: '''1.0.0.0'''</td>
<td>ip; default: '''1.0.0.0'''</td>
<td>IP address to instantly logout a client accessing it.</td>
<td>An address that can be used by users to logout from the Hotspot session.</td>
     </tr>
     </tr>
     <tr>
     <tr>
<td>Protocol</td>
<td>Protocol</td>
<td>HTTP | <span style="color: #20C0D7;">HTTPS</span>; default: <b>HTTP</b></td>
<td>HTTP | HTTPS; default: <b>HTTP</b></td>
<td>Protocol to be used for landing page.</td>
<td>Protocol to be used for landing page.</td>
     </tr>
     </tr>
Line 196: Line 147:
     </tr>
     </tr>
     <tr>
     <tr>
<td><span style="color: #f43b1a;">Group</span></td>
<td><span style="color: #f43b1a;">Trial access</span>: Group</td>
<td>User group; default: <b>default</b></td>
<td>User group; default: <b>default</b></td>
<td>Specifies the group of trial users.</td>
<td>Group of trial users.</td>
    </tr>
    <tr>
<td>Subdomain</td>
<td>string; default: <b>none</b></td>
<td>Combined with Domain to make a DNS alias for the Hotspot IP address.</td>
    </tr>
    <tr>
<td>Domain</td>
<td>string; default: <b>none</b></td>
<td>Combined with Subdomain to make a DNS alias for the Hotspot IP address.</td>
     </tr>
     </tr>
     <tr>
     <tr>
Line 231: Line 172:
     </tr>
     </tr>
     <tr>
     <tr>
<td>Primary DNS server</td>
<td>DNS server 1</td>
<td>ip; default: <b>8.8.8.8</b></td>
<td>ip; default: <b>8.8.8.8</b></td>
<td>Additional DNS servers that are to be used by the Hotspot.</td>
<td>Additional DNS servers that are to be used by the Hotspot.</td>
     </tr>
     </tr>
     <tr>
     <tr>
<td>Secondary DNS server</td>
<td>DNS server 2</td>
<td>ip; default: <b>8.8.4.4</b></td>
<td>ip; default: <b>8.8.4.4</b></td>
<td>Additional DNS servers that are to be used by the Hotspot.</td>
<td>Additional DNS servers that are to be used by the Hotspot.</td>
Line 244: Line 185:
=====Radius=====
=====Radius=====
----
----
<b>Radius</b> authentication mode uses an external RADIUS server, to which you have to provide an address to, instead of using the router's Local Authentication. If you are using Local authentication, this section is not visible.
</b>Radius</b> authentication mode uses an external RADIUS server, to which you have to provide an address to, instead of using the router's Local Authentication. If you are using Local authentication, this section is not visible.


[[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_radius_v2.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_radius.png|border|class=tlt-border]]


<table class="nd-mantable">
<table class="nd-mantable">
Line 253: Line 194:
<th>Value</th>
<th>Value</th>
<th>Description</th>
<th>Description</th>
    </tr>
    <tr>
<td>Require Message-Authenticator</td>
<td>off {{!}} on; default: <b>on</b></td>
<td>Require and validate Message-Authenticator RADIUS attribute on Access-Request replies.</td>
     </tr>
     </tr>
     <tr>
     <tr>
Line 313: Line 249:
Format of address is <b>website.com</b> (does not include https://www).
Format of address is <b>website.com</b> (does not include https://www).


[[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_walled_garden_v2.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_walled_garden.png|border|class=tlt-border]]
 
<table class="nd-mantable">
    <tr>
<th>Field</th>
<th>Value</th>
<th>Description</th>
    </tr>
    <tr>
<td>Mode</td>
<td>Allowlist {{!}} Blocklist; default: <b>Allowlist</b></td>
<td>Select mode for blocking.</td>
    </tr>
    <tr>
<td>Address list</td>
<td>domain names (one record per line); default: <b>none</b></td>
<td>List of addresses the client can access without first authenticating. One record per line. See placeholder for accepted formats. Some domains require both 'www' and non-'www' versions to be entered to ensure proper blocking.</td>
    </tr>
</table>


=====URL Parameters=====
=====URL Parameters=====
Line 337: Line 255:
The <b>URL parameters</b> section becomes visible when <b>Landing page</b> is selected as <b>External</b> in [[{{{name}}}_Hotspot#General_2|General settings]] section.
The <b>URL parameters</b> section becomes visible when <b>Landing page</b> is selected as <b>External</b> in [[{{{name}}}_Hotspot#General_2|General settings]] section.


[[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_urlparams_v1.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_urlparams.png|border|class=tlt-border]]


<table class="nd-mantable">
<table class="nd-mantable">
Line 364: Line 282:
<td>string; default: <b>none</b></td>
<td>string; default: <b>none</b></td>
<td>The MAC address of the client trying to gain Internet access.</td>
<td>The MAC address of the client trying to gain Internet access.</td>
    </tr>
    <tr>
<td>IP</td>
<td>ip default: <b>none</b></td>
<td>The IP Address of the client trying to gain Internet access.</td>
     </tr>
     </tr>
     <tr>
     <tr>
Line 416: Line 329:
In this section you can add custom <b>Scripts</b> that will be executed after a session is authorized in the <b>Session up</b> section, after session has moved from authorized state to unauthorized in the <b>Session down</b> section and after a new user has been signed up in the <b>User signup</b> section.
In this section you can add custom <b>Scripts</b> that will be executed after a session is authorized in the <b>Session up</b> section, after session has moved from authorized state to unauthorized in the <b>Session down</b> section and after a new user has been signed up in the <b>User signup</b> section.


[[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_user_scripts_v2.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_general_hotspot_instances_general_settings_user_scripts.png|border|class=tlt-border]]
 
<table class="nd-mantable">
    <tr>
<th>Field</th>
<th>Value</th>
<th>Description</th>
    </tr>
    <tr>
<td>Session up</td>
<td>bash script; default: <b>none</b></td>
<td>Script executed after a session is authorized. Executed with the environment variables (Please refer to the wiki).</td>
    </tr>
    <tr>
<td>Session down</td>
<td>bash script; default: <b>none</b></td>
<td>Script executed after a session has moved from authorized state to unauthorized. Executed with the environment variables (Please refer to the wiki).</td>
    </tr>
    <tr>
<td>User signup</td>
<td>bash script; default: <b>none</b></td>
<td>Script executed after a new user has been created during signup process. Executed with the environment variables (Please refer to the wiki).</td>
    </tr>
</table>


==Local Users==
==Local Users==
Line 452: Line 342:
</ol>
</ol>


[[File:Networking_rutos_manual_hotspot_local_users_add_button_edit_button_v1.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_local_users_add_button_edit_button.png|border|class=tlt-border]]


==Landing Page==
==Landing Page==


This section is used to define how your Hotspot's <b>Landing Page</b> will look like to connecting users.
This section is used to define how your Hotspot's <b>Landing Page</b> will look like to connecting users.
{{#switch: {{{series}}}
  | #default =  <b>Note:</b> since Hotspot supports unauthenticated users, they will be using different IPs. Basically IP will incremented based on the prefix provided. So for example if Hotspot network is 192.168.2.0/24 third octet will be incremented. So for IP 192.168.2.254 would increment to 192.168.3.254. If the network is 172.16.0.0/16 it will increment second octet. So for IP 172.16.255.254 it would increment to 172.17.255.254 and so on. After successful authentication, Hotspot will be using network that is set in Hotspot settings > General settings.
  |TCR1|TRB1|TRB5|TRB16 = <b>Note:</b> since Hotspot supports unauthenticated users, they will be using different IPs. Basically IP will incremented. So for example if Hotspot network is 192.168.2.0/24 third octet will be incremented. So for IP 192.168.2.254 would increment to 192.168.4.254. If the network is 172.16.0.0/16 it will increment second octet. So for IP 172.16.255.254 it would increment to 172.17.255.254 and so on. After successful authentication, Hotspot will be using network that is set in Hotspot settings > General settings.
}}


===General Settings===
===General Settings===
Line 467: Line 352:
<b>General Settings</b> section lets you choose the authentication protocol and theme that will be used in the Landing Page. You can download more themes using the [[{{{name}}}_Package_Manager|Package Manager]]
<b>General Settings</b> section lets you choose the authentication protocol and theme that will be used in the Landing Page. You can download more themes using the [[{{{name}}}_Package_Manager|Package Manager]]


[[File:Networking_rutos_manual_hotspot_landing_page_general_settings_v1.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_landing_page_general_settings.png|border|class=tlt-border]]


===Themes===
===Themes===
Line 473: Line 358:
The <b>Themes</b> section displays all available Landing Page themes. In order to download a theme, click the 'Download' button, in order to edit a theme, click the 'Edit' button next to it.
The <b>Themes</b> section displays all available Landing Page themes. In order to download a theme, click the 'Download' button, in order to edit a theme, click the 'Edit' button next to it.


[[File:Networking_rutos_manual_hotspot_landing_page_themes_download_edit_button_v1.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_landing_page_themes__download_edit_button.png|border|class=tlt-border]]


====Images====
====Images====
Line 479: Line 364:
The <b>Images</b> section allows you to upload custom images to different objects.
The <b>Images</b> section allows you to upload custom images to different objects.


[[File:Networking_rutos_manual_hotspot_landing_page_themes_images_v2.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_landing_page_themes_images.png|border|class=tlt-border]]


====Style Settings====
====Style Settings====
----
----


Pressing 'Edit' button next to style settings lets you edit how your
Pressing edit button [[File:Networking rutx manual edit button v1.png]] next to style settings lets you edit how your
landing page will look visually using CSS syntax.
landing page will look visually using CSS syntax.


[[File:Networking_rutos_manual_hotspot_landing_page_themes_style_settings_v1.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_landing_page_themes_style_settings.png|border|class=tlt-border]]


====View Settings====
====View Settings====
Line 493: Line 378:
In <b>View Settings</b> you can access and modify default templates for various parts of landing page and edit their HTML code.
In <b>View Settings</b> you can access and modify default templates for various parts of landing page and edit their HTML code.


[[File:Networking_rutos_manual_hotspot_landing_page_themes_view_settings_v1.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_landing_page_themes_view_settings.png|border|class=tlt-border]]


====Custom Theme====
====Custom Theme====
----
----
To use custom theme you can download default theme and edit it's content. Then use 'Browse' button to upload it.
To use custom theme you can download default theme and edit it's content. Then use upload button to upload it.


[[File:Networking rutos manual hotspot landing page themes upload custom v2.png|border|class=tlt-border]]
[[File:Networking rutos manual hotspot landing page themes upload custom v1.png|border|class=tlt-border]]


==User Groups==
==User Groups==
Line 510: Line 395:
</ol>
</ol>


[[File:Networking_rutos_manual_hotspot_user_groups_edit_button_v1.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_user_groups_edit_button.png|border|class=tlt-border]]


A group's settings page will look similar to this:
A group's settings page will look similar to this:


[[File:Networking_rutos_manual_hotspot_user_groups_group_default_settings_v3.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_user_groups_group_default_settings_v2.png|border|class=tlt-border]]


<table class="nd-mantable">
<table class="nd-mantable">
Line 576: Line 461:
==User Management==
==User Management==


The <b>User sessions</b> tab displays the status and session statistics of currently logged in users. You can also "kick" (deauthenticate) a user by clicking the 'Logout' button next to it.
The <b>Current Hotspot Users</b> tab displays the status and session statistics of currently logged in users. You can also "kick" (deauthenticate) a user by clicking the 'Logout' button next to it.


[[File:Networking_rutos_manual_hotspot_user_management_current_hotspot_users_v1.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_user_management_current_hotspot_users.png|border|class=tlt-border]]




The <b>Registered Hotspot Users</b> tab displays the data of unique users that have registered to the hotspot before.  
The <b>Registered Hotspot Users</b> tab displays the data of unique users that have registered to the hotspot before.  


[[File:Networking_rutos_manual_hotspot_user_management_registered_hotspot_users_v1.png|border|class=tlt-border]]
[[File:Networking_rutos_manual_hotspot_user_management_registered_hotspot_users.png|border|class=tlt-border]]
 
{{#switch: {{{series}}} | TRB1 | TRB2 | TRB5 | RUT30X | OTD140 | TRB2M | RUT301 | TRB16 | OTD500 | TRB501 =
| RUTX | RUTM | RUT36X | TCR1 | RUT9 | RUT9M | RUT2 | RUT2M | RUT361 | TAP100 | TAP200 | #default = {{#switch: {{{name}}} | RUTX08 | RUTX09 | RUTM08 | RUTM09 | RUTM59 = | #default =
{{Template:Networking_rutos_manual_hotspot_2.0
| series = {{{series}}}
| name = {{{name}}}
| wifi = {{{wifi}}}
}}}}}}


[[Category:{{{name}}} Services section]]
[[Category:{{{name}}} Services section]]

Revision as of 13:23, 3 October 2023

Template:Networking rutos manual fw disclosure


Summary

On Teltonika Networks devices a Hotspot is a service that provides authentication, authorization and accounting for a network. This chapter is an overview of the Hotspot section for {{{name}}} devices.


General

Hotspot Instances


The Hotspot Instances section displays the main parameters of your Hotspot. By default, a Hotspot instance does not exist on the device. To create a new instance and begin configuration:

  1. select an 'Interface';
  2. click the 'Add' button;

[[File:Networking_rutos_manual_hotspot_hotspot_instances_add_button_edit_buton_wifi_{{{wifi}}}.png|border|class=tlt-border]]

After this, a new Hotspot configuration window will appear.

General Settings


The General Settings window is where most of the Hotspot configuration takes place. Look to the sub-sections below for information on configuration fields found in the General Settings sections.

General

Field Value Description
Configuration profile Cloud4wi | Default | Hotspotsystems; default: Default Pre-configures Hotspot settings according to the selected service provider.
Enable off | on; default: on Turns the Hotspot instance on or off.
Hotspot Network ip/netmask; default: 192.168.2.0/24 IP address and subnet of the Hotspot network.
IP Address ip; default: 192.168.2.254 Defines the IP address of your Hotspot router in network.
Authentication mode Radius | Local user | MAC auth ; default: Local users Authentication mode defines how users will connect to the Hotspot.
Allow signup off | on; default: off Allows users to sign up to hotspot via landing page.
Expiration time integer; default: 0 User credential expiration time. Applies to users who signed up via landing page.
Users group user group; default: default The user group to which users signed up via landing page should be assigned to.
Landing Page Internal | External; default: Internal If external Landing Page is chosen, new section, to enter website address, will appear, e.g., http://www.example.com
UAM Port integer; default: 3990 Port to bind for authenticating clients.
UAM Secret string; default: none Shared secret between uamserver and hotspot.
Success page Success Page | Original URL | Custom; default: Success page Location to return to after successful authentication.
Advanced

Field Value Description
Additional interfaces Available interfaces; default: none Shows additional interfaces that can be attached to hotspot instance.
Logout address ip; default: 1.0.0.0 An address that can be used by users to logout from the Hotspot session.
Protocol HTTP | HTTPS; default: HTTP Protocol to be used for landing page.
Enable TOS off | on; default: off Enables Terms of Service (ToS) requirement. Client device will be able to access the Internet only after agreeing ToS.
Trial access off | on; default: off Enables trial internet access for a specific group.
Trial access: Group User group; default: default Group of trial users.
HTTPS to landing page redirect off | on; default: off Redirect initial pre-landing page HTTPS requests to hotspot landing page.
Certificate files from device off | on; default: off Specified whether to upload key & certificate files from computer or to use files generated on this device via the System → Administration → [[{{{name}}} Administration#Certificates|Certificates]] page.
SSL key file key file; default: none Upload/select SSL key.
SSL certificate file certificate file; default: none Upload/select SSL certificate.
DNS server 1 ip; default: 8.8.8.8 Additional DNS servers that are to be used by the Hotspot.
DNS server 2 ip; default: 8.8.4.4 Additional DNS servers that are to be used by the Hotspot.
Radius

Radius authentication mode uses an external RADIUS server, to which you have to provide an address to, instead of using the router's Local Authentication. If you are using Local authentication, this section is not visible.

Field Value Description
RADIUS server #1 ip; default: none The IP address of the RADIUS server #1 that is to be used for Authenticating your wireless clients.
RADIUS server #2 ip; default: none The IP address of the RADIUS server #2 that is to be used for Authenticating your wireless clients.
Authentication port integer [0..65535]; default: 1812 RADIUS server authentication port.
Accounting port integer [0..65535]; default: 1813 RADIUS server accounting port.
NAS identifier string; default: none NAS-Identifier is one of the basic RADIUS attributes.
Radius secret key string; default: none The secret key is a password used for authentication with the RADIUS server.
Swap octets off | on; default: off Swaps the meaning of input octets and output as it relates to RADIUS attributes.
Location name string; default: none Custom location name for your Hotspot.
Location ID string; default: none Custom location ID for your Hotspot.
Walled Garden

You can add a list of addresses that users connected to the Hotspot will be able to reach without any authentication. By default this list is empty. Simply write addresses into the Address List.

Format of address is website.com (does not include https://www).

URL Parameters

The URL parameters section becomes visible when Landing page is selected as External in [[{{{name}}}_Hotspot#General_2|General settings]] section.

Field Value Description
UAM IP string; default: none The IP Address of the Captive Portal gateway.
UAM port string; default: none The port on which the Captive Portal will serve web content.
Called string; default: none The MAC address of the IP Address of the Captive Portal gateway.
MAC string; default: none The MAC address of the client trying to gain Internet access.
NAS id string; default: none An identification for the Captive Portal used in the RADIUS request.
Session id string; default: none The unique identifer for session.
User url string; default: none The URL which the user tried to access before he were redirected to the Captive Portal's URL's pages.
Challenge string; default: none A challenge that should be used together with the user's password to create an encrypted phrase used to log on.
Custom 1 string; default: none Add custom name and custom value which will be displayed in url parameters.
- SSID | Hostname | FW version | --Custom--; default: SSID -
Custom 2 string; default: none Add custom name and custom value which will be displayed in url parameters.
- SSID | Hostname | FW version | --Custom--; default: SSID -
User Scripts

In this section you can add custom Scripts that will be executed after a session is authorized in the Session up section, after session has moved from authorized state to unauthorized in the Session down section and after a new user has been signed up in the User signup section.

Local Users

The Local Users section is used to create and manage users that can connect to the Hotspot. The elements comprising the Local Users page are explained in the list and figure below.

  1. Entering a Username, Password and clicking the 'Add' button creates a new user.
  2. The 'Group' dropdown menu assigns a user to another group.
  3. The 'Edit' button lets you change a user's password or assign the user to another group.
  4. The 'Delete[X]' button deletes a user.

Landing Page

This section is used to define how your Hotspot's Landing Page will look like to connecting users.

General Settings


General Settings section lets you choose the authentication protocol and theme that will be used in the Landing Page. You can download more themes using the [[{{{name}}}_Package_Manager|Package Manager]]

Themes


The Themes section displays all available Landing Page themes. In order to download a theme, click the 'Download' button, in order to edit a theme, click the 'Edit' button next to it.

Images


The Images section allows you to upload custom images to different objects.

Style Settings


Pressing edit button next to style settings lets you edit how your landing page will look visually using CSS syntax.

View Settings


In View Settings you can access and modify default templates for various parts of landing page and edit their HTML code.

Custom Theme


To use custom theme you can download default theme and edit it's content. Then use upload button to upload it.

User Groups

User Groups provides the possibility to set different connection limits for different users. A group called 'default' is already created and does not have any limitations set by default. You can

  1. create a new group by entering a custom Name and clicking 'Add'
  2. or configure the existing rule by clicking the 'Edit' button next to it.

A group's settings page will look similar to this:

Field Value Description
Idle timeout integer; default: none A timeout in seconds after which idle users are automatically disconnected from the Hotspot. (0 means unlimited.)
Time limit integer; default: none Disables hotspot user after time limit in sec is reached. (0, meaning unlimited)
Download bandwidth integer; default: none Maximum download bandwidth that the users assigned to this template can achieve. Bandwidth can be specified in Mbit/s.
Upload bandwidth integer; default: none Maximum upload bandwidth that the users assigned to this template can achieve. Bandwidth can be specified in Mbit/s.
Download limit integer; default: none A received data limit that the users assigned to this template can reach. After the data limit is reached, the user will lose data connection. Download limit is specified in MB.
Upload limit integer; default: none A sent data limit that the users assigned to this template can reach. After the data limit is reached, the user will lose data connection. Upload limit is specified in MB.
Warning integer; default: none Send an SMS warning to hotspot user after warning value of download or upload data in MB is reached. Only works with SMS OTP authentication.
Period Month | Week | Day; default: Month The beginning of the period during which the restriction specified in this section will apply. After the period is over, all specified limits are reset.
Start day integer [1..31] | Monday..Sunday | integer [1..24]; default: 1 Choices changes depending on what 'Period' was chosen. Specifies which day of the month, week or hour of the day the limits will be reset.

User Management

The Current Hotspot Users tab displays the status and session statistics of currently logged in users. You can also "kick" (deauthenticate) a user by clicking the 'Logout' button next to it.


The Registered Hotspot Users tab displays the data of unique users that have registered to the hotspot before.

[[Category:{{{name}}} Services section]]