Jump to content

RUT301 Hotspot

From Teltonika Networks Wiki
Main Page > RUT Routers > RUT301 > RUT301 Manual > RUT301 WebUI > RUT301 Services section > RUT301 Hotspot

The information in this page is updated in accordance with firmware version RUT301_R_00.07.24.2.


Summary

On Teltonika Networks devices a Hotspot is a service that provides authentication, authorization and accounting for a network. This chapter is an overview of the Hotspot section for RUT301 devices.

Note: Hotspot is additional software on some devices that can be installed from the System → Package Manager page.

General

Hotspot Instances


The Hotspot Instances section displays the main parameters of your Hotspot. By default, a Hotspot instance does not exist on the device. To create a new instance click the 'Add' button:

After this, a new Hotspot configuration window will appear.

Note: Devices that have hotspot in core can support up to 5 hotspot instances.

Instance Configuration


The Instance Configuration window is where most of the Hotspot configuration takes place. Look to the sub-sections below for information on configuration fields found in tis sections.

Field Value Description
Enable off | on; default: on Enable hotspot functionality.
Name string; default: hotspot1 Hotspot name.
Configuration profile Cloud4wi | Default | Hotspotsystems | Purple portal; default: Default Pre-configures Hotspot settings according to the selected service provider.
Authentication mode Local users | Radius | MAC authentication | Single sign-on; default: Local users Authentication mode defines how users will connect to the Hotspot. For improved security it is advised to avoid MAC authentication.
Interface None | Wireless interfaces: None Interface to be used for hotspot.
Hotspot Network ip/netmask; default: 192.168.2.0/24 IP address and subnet of the Hotspot network. Netmask must be from 16 to 30.
Success page Success Page | Original URL | Custom; default: Success page Location to return to after successful authentication.
Custom URL url; default: none Address must contain protocol (http://www.example.com).
Additional interfaces Available interfaces; default: none Choose additional the interfaces you want to attach to this hotspot instance.
Enable MAC blocking off | on; default: off Blocks access to MAC addresses that have reached set amount of failed login attempts. For improved security it is advised to enable MAC blocking.
Logout address ip; default: 1.0.0.0 IP address to instantly logout a client accessing it.
Enable TOS off | on; default: off Enables Terms of Service (ToS) requirement. Client device will be able to access the Internet only after agreeing ToS.
Trial access off | on; default: off Enables trial internet access for a specific group.
Group User group; default: default Specifies the group of trial users.
Primary DNS server ip; default: 8.8.8.8 Additional DNS servers that are to be used by the Hotspot.
Secondary DNS server ip; default: 8.8.4.4 Additional DNS servers that are to be used by the Hotspot.
Isolate clients off | on; default: on Disable client to client communication.
Authentication mode: Radius

Radius authentication mode uses an external RADIUS server, to which you have to provide an address to, instead of using the router's Local Authentication. If you are using Local authentication, this section is not visible.

Field Value Description
Require Message-Authenticator off | on; default: on Require and validate Message-Authenticator RADIUS attribute on Access-Request replies. For improved security it is advised to enable Message-Authenticator option.
RADIUS main server ip; default: none The IP address of the RADIUS server #1 that is to be used for Authenticating your wireless clients.
RADIUS backup server ip; default: none The IP address of the RADIUS server #2 that is to be used for Authenticating your wireless clients.
Ports Authenticator port and Accounting port; default: 1812 and 1813 RADIUS server accounting port and authentication port.
NAS identifier string; default: none NAS-Identifier is one of the basic RADIUS attributes.
Radius secret key string; default: none The secret key is a password used for authentication with the RADIUS server.
Swap octets off | on; default: off Swaps the meaning of input octets and output as it relates to RADIUS attributes.
Location name string; default: none Custom location name for your Hotspot.
Location ID string; default: none Custom location ID for your Hotspot.
Enable MAC authentication off | on; default: off Enable MAC address authentication.
MAC case Upper | Lower; default: Upper
MAC delimiter None | Dash | Colon; default: Dash
Authentication mode: MAC authentication

Field Value Description
Require password off | on; default: off Enables password requirement for MAC authentication. For improved security it is advised to enable password requirement.
MAC authentication: MAC auth password string; default: none Password for MAC authentication.
Users group user group; default: default Specifies the group of dynamically created users.
Authentication mode: Single Sign-On

Field Value Description
OpenID Connect metadata document URL; default: none URL that points to the provider’s metadata.
OpenID Connect client ID string; default: admin Unique identifier assigned to your application by the identity provider.
OpenID Connect client secret string; default: none Confidential key used together with the client ID to authenticate your application with the identity provider.
OpenID Connect redirect URI string; default: http://192.168.2.254:3990/ssocallback The URL where the identity provider will send the user after successful authentication.
Users group user group; default: default Specifies the group of dynamically created users.


Landing page


Field Value Description
Password encoding off | on; default: on Password encoding with the challenge. For improved security it is advised to turn on password encoding.
Landing Page Internal | External; default: Internal Location of the landing page.
UAM Secret string; default: none Shared secret between uamserver and hotspot. For improved security it is advised to use UAM secret.
Protocol HTTP | HTTPS; default: HTTP Protocol to be used for landing page. For improved security it is advised to use HTTPS.
Subdomain string; default: none Combined with Domain to make a DNS alias for the Hotspot IP address.
Landing page address url; default: none External landing page address (http://www.example.com).
Domain string; default: none Combined with Subdomain to make a DNS alias for the Hotspot IP address.
HTTPS to redirect to landing page off | on; default: off Redirect initial pre-landing page HTTPS requests to hotspot landing page. For improved security it is advised to enable this option.
Assign to theme themes; default: default Hotspot landing page theme.
Certificate files from device off | on; default: off Specified whether to upload key & certificate files from computer or to use files generated on this device via the System → Administration → Certificates page.
SSL key file key file; default: none Upload/select SSL key.
SSL certificate file certificate file; default: none Upload/select SSL certificate.
SSL CA certificate file certificate file; default: none Upload/select SSL certificate.
UAM Port integer; default: 3990 Port to bind for authenticating clients.
Allow signup (available with Authentication: Local users) off | on; default: off Allows users to sign up to hotspot via landing page.
Users group user group; default: default Specifies the group of dynamically created users.
URL Parameters

The URL parameters section becomes visible when Landing page is selected as External in Landing page section.

Field Value Description
Called string; default: none The MAC address of the IP Address of the Captive Portal gateway.
UAM port string; default: none The port on which the Captive Portal will serve web content.
MAC string; default: none The MAC address of the client trying to gain Internet access.
IP ip default: none The IP Address of the client trying to gain Internet access.
NAS id string; default: none An identification for the Captive Portal used in the RADIUS request.
Session id string; default: none The unique identifer for session.
User url string; default: none The URL which the user tried to access before he were redirected to the Captive Portal's URL's pages.
Challenge string; default: none A challenge that should be used together with the user's password to create an encrypted phrase used to log on.
Custom 1 string; default: none Add custom name and custom value which will be displayed in url parameters.
- SSID | Hostname | FW version | --Custom--; default: SSID -
Custom 2 string; default: none Add custom name and custom value which will be displayed in url parameters.
- SSID | Hostname | FW version | --Custom--; default: SSID -

Walled Garden


You can add a list of addresses that users connected to the Hotspot will be able to reach without any authentication. By default this list is empty. Simply write addresses into the Address List.

Format of address is website.com (does not include https://www).

Field Value Description
Mode Allowlist | Blocklist; default: Allowlist Select mode for blocking. For improved security it is advised to use Allowlist.
Address list domain names (one record per line); default: none List of addresses the client can access without first authenticating. One record per line. See placeholder for accepted formats. Some domains require both 'www' and non-'www' versions to be entered to ensure proper blocking. For improved security it is not advised to allow accessing domains without authenticating first.

User Scripts


In this section you can add custom Scripts that will be executed after a session is authorized in the Session up section, after session has moved from authorized state to unauthorized in the Session down section and after a new user has been signed up in the User signup section.

Field Value Description
Session up bash script; default: none Script executed after a session is authorized. Executed with the environment variables (Please refer to the wiki).
Session down bash script; default: none Script executed after a session has moved from authorized state to unauthorized. Executed with the environment variables (Please refer to the wiki).
User signup bash script; default: none Script executed after a new user has been created during signup process. Executed with the environment variables (Please refer to the wiki).

Landing Page

Overview


The Landing Page page, found under Services > Hotspot, allows administrators to manage the customizable landing/login pages (captive portal themes) that users see when connecting to a hotspot network.

Layout & Features


Header actions

  • Upload – upload a new landing page theme (e.g., a custom HTML/asset package).
  • Create new theme – build a new landing page theme from scratch.
  • Visible columns (3 of 3) – toggle which table columns are displayed.

Bulk actions bar

  • Shows the count of selected rows (0 selected by default).
  • Download – export the selected theme(s).
  • Remove – delete the selected theme(s).
  • Both actions are disabled until at least one theme is selected.

Theme table columns

Column Description
Checkbox Select individual themes for bulk actions
Theme name Name of the landing page theme (e.g., "Default theme")
Assigned to instance Which hotspot instance the theme is currently applied to (e.g., "hotspot1")
Actions Per-row actions: Edit, Customize, Duplicate

Per-theme actions

  • Edit – modify the theme's name and assings theme to instance.
  • Customize – adjust visual settings (branding, colors, layout) without editing raw code.
  • Duplicate – create a copy of the theme as a starting point for a new one.

Save & Apply: A primary button at the bottom-right confirms and applies any pending changes to the landing page configuration.

Edit (actions)


Clicking Edit on a theme opens the "<Theme Name>" theme configuration panel (breadcrumb: Services > Hotspot > Landing page > Configuration).

Field Value Description
Name text; required The display name of the theme (e.g., "Default theme").
Instances multi-select; default: none Hotspot instance(s) assigned to this theme (e.g., "hotspot1"). Instances can be added or removed using the x next to each tag or via the dropdown arrow.

Customize (Actions)


Clicking Customize on a theme opens the "<Theme Name>" theme preview panel (breadcrumb: Services > Hotspot > Landing page > Configuration), which allows previewing and styling the theme.

Theme Preview

Field Value Description
Page of preview dropdown; default: Login page Selects which page of the theme to preview (e.g., login page).
Preview theme link Opens the selected page in a new tab to preview the current theme styling.
Theme Configuration

The Theme configuration section is split into two tabs: Style settings and Texts.

Style settings tab:

Field Value Description
Fav icon file file upload; e.g. favicon.png Icon displayed in the browser tab for the landing page. Can be removed with the x.
Background radio: Image / Color fill Selects whether the page background uses an uploaded image or a solid color fill.
Background file file upload; e.g. background.webp Image file used as the page background when "Image" is selected. Can be removed with the x.
Form logo file upload; e.g. logo.svg Logo image displayed on the login/signup form. Can be removed with the x.
Form background color hex color; required; default: #ffffff Background color of the login/signup form container.
Banner Font size (px) / Font color (hex); required Font size and color used for the banner text on the landing page.
Form input Fill color / Border color (hex); required Fill and border colors used for input fields on the form.
Font of titles dropdown; e.g. Oswald Font family used for titles throughout the theme.
Font sizes Titles / Subtitles / Body text / Inputs and labels (px); required Font size settings for different text elements: titles, subtitles, body text, and input/label text.
Button colors Background / Text (hex); required Background and text colors used for buttons on the landing page.
Text colors Primary / Secondary (hex); required Primary and secondary text colors used throughout the theme.

Texts tab: Allows customization of the text labels and titles displayed across the landing page theme, such as the browser tab title, background/form headers, and page titles for Login, Register, and etc. Each field comes pre-filled with a default value that can be edited to match the desired branding or language.

User Management

Overview

The User Management section, found under Services > Hotspot, allows administrators to monitor active hotspot sessions and manage hotspot users and groups. The page is organized into three tabs: Sessions, Users, and Groups.

Sessions Tab

The Sessions tab (labeled "User sessions") displays a real-time list of currently connected hotspot clients.

Header actions:

  • Visible columns (9 of 9) – toggle which table columns are displayed.
  • Search – search/filter the session list.
  • Day / Week / Month / Year – time range filter toggle for viewing session data.

Bulk actions bar:

  • Shows the count of selected rows (0 selected by default).
  • Logout – forcibly logs out the selected session(s). Disabled until at least one session is selected.

Table columns:

Field Value Description
Hostname text; e.g. Hostname of the connected client device. Shown as "-" if unavailable (e.g., unauthenticated clients).
Name text; e.g. user1 Username associated with the session. Shown as "-" for unauthenticated sessions.
instance text; e.g. hotspot1 Hotspot instance the session belongs to.
Status text; e.g. Active (green) / Unauthenticated (orange) Current authentication/connection status of the session.
Session time text; e.g. 17s Duration the session has been active. Shown as "-" if not applicable.
IP address text; e.g. 192.168.2.2 IP address assigned to the connected client.
MAC address mac address; e.g. MAC address of the connected client's network interface.
Download data; e.g. 50.35 KB Total data downloaded by the client during the session.
Upload data; e.g. 37.57 KB Total data uploaded by the client during the session.

If no clients are connected, the table displays: "No users currently connected".

Users Tab

The Users tab (labeled "All users") displays a list of all hotspot user accounts and allows administrators to add, edit, enable/disable, or delete users.

Header actions:

  • Visible columns (8 of 10) – toggle which table columns are displayed.
  • Search – search/filter the user list.

Table columns:

Field Value Description
Name text; e.g. user1 Username of the hotspot account.
Type text; e.g. Local user Type of user account (e.g., local user).
Instance text; e.g. hotspot1 Hotspot instance the user is associated with.
Group text; e.g. default User group the account belongs to.
Expires in text; e.g. Does not expire Expiration setting for the user account.
Registration date date; e.g. 2026-08-18 Date the user account was registered/created.
Enabled toggle; default: on Enables or disables the user account.
Actions links: Edit / Delete Per-row actions to edit the user's details or delete the account.

Bottom actions:

  • Add user – opens a form to create a new hotspot user account.
  • Save & Apply – saves and applies any pending changes.

Add User / Edit

Clicking Add user or Edit on a user opens the "<User Name>" Local user configuration panel (breadcrumb: Services > Hotspot > User Management > Users).

Fields:

Field Value Description
User profile enable off |; default: off Enables or disables the user account.
Name text; required; e.g. user2 Username used for user login.
Type text; default: Local user Indicates the account type (read-only for local users).
Email address text; default: none Email address of the user.
Password password field; default: none Password used for user login. Leaving this field empty will keep the current password.
Assign to all instances off | on; default: on Automatically assign the user to all current and future hotspot instances.
Assigned to instance instances; default: none Select the hotspot instances to which this user will be assigned.
User group dropdown; default: default Select the hotspot group to which this user will belong.

Groups Tab

The Groups tab (labeled "User groups") displays a list of user groups used to organize hotspot users and apply shared bandwidth/time restrictions.

Header actions:

  • Visible columns (7 of 7) – toggle which table columns are displayed.
  • Search – search/filter the group list.

Table columns:

Field Value Description
Name text; e.g. default Name of the user group.
Download bandwidth text; default: Unlimited Maximum download bandwidth allowed for users in this group.
Upload bandwidth text; default: Unlimited Maximum upload bandwidth allowed for users in this group.
Download limit text; default: Unlimited Maximum total download data allowed for users in this group.
Upload limit text; default: Unlimited Maximum total upload data allowed for users in this group.
Time limit text; default: Unlimited Maximum session/connection time allowed for users in this group.
Actions links: Edit / Delete Per-row actions to edit or delete the group. The default group cannot be deleted.

Bottom actions:

  • Add – opens a form to create a new user group.

Add/Edit (Actions)

Clicking Edit on a group opens the "<Group Name>" group configuration panel (breadcrumb: Services > Hotspot > User Management > User groups > Configuration).

Fields:

Field Value Description
Name text; required; e.g. default Name of the user group.
Idle timeout seconds; default: none (e.g., 0) If the idle timeout is not configured or is set to '0', it indicates that no timeout is applied, and the session duration is unlimited.
Time limit seconds; default: none (e.g., 1) The set time limit disables hotspot user after time limit in sec is reached. '0' or empty value is equal to unlimited.
Bandwidth limit Download / Upload (Mb); default: none (e.g., 1000 Mb / 500 Mb) The max allowed download and upload speed, in megabits.
Data limit Download / Upload (MB); default: none (e.g., 10000 MB / 10000 MB) Disable hotspot user after download or upload limit value in MB is reached.
Period radio: Day / Week / Month; default: Day Period for which hotspot data limiting should apply. After the period is over, all specified limits are reset.
Start hour/Start day dropdown; default: 1 Specifies which day of the month, week or hour of the day the limits will be reset.
Expiration time seconds; default: none User expiration time in sec. Set to 0 for unlimited session duration.