RUT301 Hotspot
The information in this page is updated in accordance with firmware version RUT301_R_00.07.24.2.
Summary
On Teltonika Networks devices a Hotspot is a service that provides authentication, authorization and accounting for a network. This chapter is an overview of the Hotspot section for RUT301 devices.
Note: Hotspot is additional software on some devices that can be installed from the System → Package Manager page.
General
Hotspot Instances
The Hotspot Instances section displays the main parameters of your Hotspot. By default, a Hotspot instance does not exist on the device. To create a new instance click the 'Add' button:
After this, a new Hotspot configuration window will appear.
Note: Devices that have hotspot in core can support up to 5 hotspot instances.
Instance Configuration
The Instance Configuration window is where most of the Hotspot configuration takes place. Look to the sub-sections below for information on configuration fields found in tis sections.
| Field | Value | Description |
|---|---|---|
| Enable | off | on; default: on | Enable hotspot functionality. |
| Name | string; default: hotspot1 | Hotspot name. |
| Configuration profile | Cloud4wi | Default | Hotspotsystems | Purple portal; default: Default | Pre-configures Hotspot settings according to the selected service provider. |
| Authentication mode | Local users | Radius | MAC authentication | Single sign-on; default: Local users | Authentication mode defines how users will connect to the Hotspot. For improved security it is advised to avoid MAC authentication. |
| Interface | None | Wireless interfaces: None | Interface to be used for hotspot. |
| Hotspot Network | ip/netmask; default: 192.168.2.0/24 | IP address and subnet of the Hotspot network. Netmask must be from 16 to 30. |
| Success page | Success Page | Original URL | Custom; default: Success page | Location to return to after successful authentication. |
| Custom URL | url; default: none | Address must contain protocol (http://www.example.com). |
| Additional interfaces | Available interfaces; default: none | Choose additional the interfaces you want to attach to this hotspot instance. |
| Enable MAC blocking | off | on; default: off | Blocks access to MAC addresses that have reached set amount of failed login attempts. For improved security it is advised to enable MAC blocking. |
| Logout address | ip; default: 1.0.0.0 | IP address to instantly logout a client accessing it. |
| Enable TOS | off | on; default: off | Enables Terms of Service (ToS) requirement. Client device will be able to access the Internet only after agreeing ToS. |
| Trial access | off | on; default: off | Enables trial internet access for a specific group. |
| Group | User group; default: default | Specifies the group of trial users. |
| Primary DNS server | ip; default: 8.8.8.8 | Additional DNS servers that are to be used by the Hotspot. |
| Secondary DNS server | ip; default: 8.8.4.4 | Additional DNS servers that are to be used by the Hotspot. |
| Isolate clients | off | on; default: on | Disable client to client communication. |
Authentication mode: Radius
Radius authentication mode uses an external RADIUS server, to which you have to provide an address to, instead of using the router's Local Authentication. If you are using Local authentication, this section is not visible.
| Field | Value | Description |
|---|---|---|
| Require Message-Authenticator | off | on; default: on | Require and validate Message-Authenticator RADIUS attribute on Access-Request replies. For improved security it is advised to enable Message-Authenticator option. |
| RADIUS main server | ip; default: none | The IP address of the RADIUS server #1 that is to be used for Authenticating your wireless clients. |
| RADIUS backup server | ip; default: none | The IP address of the RADIUS server #2 that is to be used for Authenticating your wireless clients. |
| Ports | Authenticator port and Accounting port; default: 1812 and 1813 | RADIUS server accounting port and authentication port. |
| NAS identifier | string; default: none | NAS-Identifier is one of the basic RADIUS attributes. |
| Radius secret key | string; default: none | The secret key is a password used for authentication with the RADIUS server. |
| Swap octets | off | on; default: off | Swaps the meaning of input octets and output as it relates to RADIUS attributes. |
| Location name | string; default: none | Custom location name for your Hotspot. |
| Location ID | string; default: none | Custom location ID for your Hotspot. |
| Enable MAC authentication | off | on; default: off | Enable MAC address authentication. |
| MAC case | Upper | Lower; default: Upper | |
| MAC delimiter | None | Dash | Colon; default: Dash |
Authentication mode: MAC authentication
| Field | Value | Description |
|---|---|---|
| Require password | off | on; default: off | Enables password requirement for MAC authentication. For improved security it is advised to enable password requirement. |
| MAC authentication: MAC auth password | string; default: none | Password for MAC authentication. |
| Users group | user group; default: default | Specifies the group of dynamically created users. |
Authentication mode: Single Sign-On
| Field | Value | Description |
|---|---|---|
| OpenID Connect metadata document | URL; default: none | URL that points to the provider’s metadata. |
| OpenID Connect client ID | string; default: admin | Unique identifier assigned to your application by the identity provider. |
| OpenID Connect client secret | string; default: none | Confidential key used together with the client ID to authenticate your application with the identity provider. |
| OpenID Connect redirect URI | string; default: http://192.168.2.254:3990/ssocallback | The URL where the identity provider will send the user after successful authentication. |
| Users group | user group; default: default | Specifies the group of dynamically created users. |
Landing page
| Field | Value | Description |
|---|---|---|
| Password encoding | off | on; default: on | Password encoding with the challenge. For improved security it is advised to turn on password encoding. |
| Landing Page | Internal | External; default: Internal | Location of the landing page. |
| UAM Secret | string; default: none | Shared secret between uamserver and hotspot. For improved security it is advised to use UAM secret. |
| Protocol | HTTP | HTTPS; default: HTTP | Protocol to be used for landing page. For improved security it is advised to use HTTPS. |
| Subdomain | string; default: none | Combined with Domain to make a DNS alias for the Hotspot IP address. |
| Landing page address | url; default: none | External landing page address (http://www.example.com). |
| Domain | string; default: none | Combined with Subdomain to make a DNS alias for the Hotspot IP address. |
| HTTPS to redirect to landing page | off | on; default: off | Redirect initial pre-landing page HTTPS requests to hotspot landing page. For improved security it is advised to enable this option. |
| Assign to theme | themes; default: default | Hotspot landing page theme. |
| Certificate files from device | off | on; default: off | Specified whether to upload key & certificate files from computer or to use files generated on this device via the System → Administration → Certificates page. |
| SSL key file | key file; default: none | Upload/select SSL key. |
| SSL certificate file | certificate file; default: none | Upload/select SSL certificate. |
| SSL CA certificate file | certificate file; default: none | Upload/select SSL certificate. |
| UAM Port | integer; default: 3990 | Port to bind for authenticating clients. |
| Allow signup (available with Authentication: Local users) | off | on; default: off | Allows users to sign up to hotspot via landing page. |
| Users group | user group; default: default | Specifies the group of dynamically created users. |
URL Parameters
The URL parameters section becomes visible when Landing page is selected as External in Landing page section.
| Field | Value | Description |
|---|---|---|
| Called | string; default: none | The MAC address of the IP Address of the Captive Portal gateway. |
| UAM port | string; default: none | The port on which the Captive Portal will serve web content. |
| MAC | string; default: none | The MAC address of the client trying to gain Internet access. |
| IP | ip default: none | The IP Address of the client trying to gain Internet access. |
| NAS id | string; default: none | An identification for the Captive Portal used in the RADIUS request. |
| Session id | string; default: none | The unique identifer for session. |
| User url | string; default: none | The URL which the user tried to access before he were redirected to the Captive Portal's URL's pages. |
| Challenge | string; default: none | A challenge that should be used together with the user's password to create an encrypted phrase used to log on. |
| Custom 1 | string; default: none | Add custom name and custom value which will be displayed in url parameters. |
| - | SSID | Hostname | FW version | --Custom--; default: SSID | - |
| Custom 2 | string; default: none | Add custom name and custom value which will be displayed in url parameters. |
| - | SSID | Hostname | FW version | --Custom--; default: SSID | - |
Walled Garden
You can add a list of addresses that users connected to the Hotspot will be able to reach without any authentication. By default this list is empty. Simply write addresses into the Address List.
Format of address is website.com (does not include https://www).
| Field | Value | Description |
|---|---|---|
| Mode | Allowlist | Blocklist; default: Allowlist | Select mode for blocking. For improved security it is advised to use Allowlist. |
| Address list | domain names (one record per line); default: none | List of addresses the client can access without first authenticating. One record per line. See placeholder for accepted formats. Some domains require both 'www' and non-'www' versions to be entered to ensure proper blocking. For improved security it is not advised to allow accessing domains without authenticating first. |
User Scripts
In this section you can add custom Scripts that will be executed after a session is authorized in the Session up section, after session has moved from authorized state to unauthorized in the Session down section and after a new user has been signed up in the User signup section.
| Field | Value | Description |
|---|---|---|
| Session up | bash script; default: none | Script executed after a session is authorized. Executed with the environment variables (Please refer to the wiki). |
| Session down | bash script; default: none | Script executed after a session has moved from authorized state to unauthorized. Executed with the environment variables (Please refer to the wiki). |
| User signup | bash script; default: none | Script executed after a new user has been created during signup process. Executed with the environment variables (Please refer to the wiki). |
Landing Page
Overview
The Landing Page page, found under Services > Hotspot, allows administrators to manage the customizable landing/login pages (captive portal themes) that users see when connecting to a hotspot network.
Layout & Features
Header actions
- Upload – upload a new landing page theme (e.g., a custom HTML/asset package).
- Create new theme – build a new landing page theme from scratch.
- Visible columns (3 of 3) – toggle which table columns are displayed.
Bulk actions bar
- Shows the count of selected rows (0 selected by default).
- Download – export the selected theme(s).
- Remove – delete the selected theme(s).
- Both actions are disabled until at least one theme is selected.
Theme table columns
| Column | Description |
|---|---|
| Checkbox | Select individual themes for bulk actions |
| Theme name | Name of the landing page theme (e.g., "Default theme") |
| Assigned to instance | Which hotspot instance the theme is currently applied to (e.g., "hotspot1") |
| Actions | Per-row actions: Edit, Customize, Duplicate |
Per-theme actions
- Edit – modify the theme's name and assings theme to instance.
- Customize – adjust visual settings (branding, colors, layout) without editing raw code.
- Duplicate – create a copy of the theme as a starting point for a new one.
Save & Apply: A primary button at the bottom-right confirms and applies any pending changes to the landing page configuration.
Edit (actions)
Clicking Edit on a theme opens the "<Theme Name>" theme configuration panel (breadcrumb: Services > Hotspot > Landing page > Configuration).
| Field | Value | Description |
|---|---|---|
| Name | text; required | The display name of the theme (e.g., "Default theme"). |
| Instances | multi-select; default: none | Hotspot instance(s) assigned to this theme (e.g., "hotspot1"). Instances can be added or removed using the x next to each tag or via the dropdown arrow. |
Customize (Actions)
Clicking Customize on a theme opens the "<Theme Name>" theme preview panel (breadcrumb: Services > Hotspot > Landing page > Configuration), which allows previewing and styling the theme.
Theme Preview
| Field | Value | Description |
|---|---|---|
| Page of preview | dropdown; default: Login page | Selects which page of the theme to preview (e.g., login page). |
| Preview theme | link | Opens the selected page in a new tab to preview the current theme styling. |
Theme Configuration
The Theme configuration section is split into two tabs: Style settings and Texts.
Style settings tab:
| Field | Value | Description |
|---|---|---|
| Fav icon file | file upload; e.g. favicon.png | Icon displayed in the browser tab for the landing page. Can be removed with the x. |
| Background | radio: Image / Color fill | Selects whether the page background uses an uploaded image or a solid color fill. |
| Background file | file upload; e.g. background.webp | Image file used as the page background when "Image" is selected. Can be removed with the x. |
| Form logo | file upload; e.g. logo.svg | Logo image displayed on the login/signup form. Can be removed with the x. |
| Form background color | hex color; required; default: #ffffff | Background color of the login/signup form container. |
| Banner | Font size (px) / Font color (hex); required | Font size and color used for the banner text on the landing page. |
| Form input | Fill color / Border color (hex); required | Fill and border colors used for input fields on the form. |
| Font of titles | dropdown; e.g. Oswald | Font family used for titles throughout the theme. |
| Font sizes | Titles / Subtitles / Body text / Inputs and labels (px); required | Font size settings for different text elements: titles, subtitles, body text, and input/label text. |
| Button colors | Background / Text (hex); required | Background and text colors used for buttons on the landing page. |
| Text colors | Primary / Secondary (hex); required | Primary and secondary text colors used throughout the theme. |
Texts tab: Allows customization of the text labels and titles displayed across the landing page theme, such as the browser tab title, background/form headers, and page titles for Login, Register, and etc. Each field comes pre-filled with a default value that can be edited to match the desired branding or language.
User Management
Overview
The User Management section, found under Services > Hotspot, allows administrators to monitor active hotspot sessions and manage hotspot users and groups. The page is organized into three tabs: Sessions, Users, and Groups.
Sessions Tab
The Sessions tab (labeled "User sessions") displays a real-time list of currently connected hotspot clients.
Header actions:
- Visible columns (9 of 9) – toggle which table columns are displayed.
- Search – search/filter the session list.
- Day / Week / Month / Year – time range filter toggle for viewing session data.
Bulk actions bar:
- Shows the count of selected rows (0 selected by default).
- Logout – forcibly logs out the selected session(s). Disabled until at least one session is selected.
Table columns:
| Field | Value | Description |
|---|---|---|
| Hostname | text; e.g. | Hostname of the connected client device. Shown as "-" if unavailable (e.g., unauthenticated clients). |
| Name | text; e.g. user1 | Username associated with the session. Shown as "-" for unauthenticated sessions. |
| instance | text; e.g. hotspot1 | Hotspot instance the session belongs to. |
| Status | text; e.g. Active (green) / Unauthenticated (orange) | Current authentication/connection status of the session. |
| Session time | text; e.g. 17s | Duration the session has been active. Shown as "-" if not applicable. |
| IP address | text; e.g. 192.168.2.2 | IP address assigned to the connected client. |
| MAC address | mac address; e.g. | MAC address of the connected client's network interface. |
| Download | data; e.g. 50.35 KB | Total data downloaded by the client during the session. |
| Upload | data; e.g. 37.57 KB | Total data uploaded by the client during the session. |
If no clients are connected, the table displays: "No users currently connected".
Users Tab
The Users tab (labeled "All users") displays a list of all hotspot user accounts and allows administrators to add, edit, enable/disable, or delete users.
Header actions:
- Visible columns (8 of 10) – toggle which table columns are displayed.
- Search – search/filter the user list.
Table columns:
| Field | Value | Description |
|---|---|---|
| Name | text; e.g. user1 | Username of the hotspot account. |
| Type | text; e.g. Local user | Type of user account (e.g., local user). |
| Instance | text; e.g. hotspot1 | Hotspot instance the user is associated with. |
| Group | text; e.g. default | User group the account belongs to. |
| Expires in | text; e.g. Does not expire | Expiration setting for the user account. |
| Registration date | date; e.g. 2026-08-18 | Date the user account was registered/created. |
| Enabled | toggle; default: on | Enables or disables the user account. |
| Actions | links: Edit / Delete | Per-row actions to edit the user's details or delete the account. |
Bottom actions:
- Add user – opens a form to create a new hotspot user account.
- Save & Apply – saves and applies any pending changes.
Add User / Edit
Clicking Add user or Edit on a user opens the "<User Name>" Local user configuration panel (breadcrumb: Services > Hotspot > User Management > Users).
Fields:
| Field | Value | Description |
|---|---|---|
| User profile enable | off |; default: off | Enables or disables the user account. |
| Name | text; required; e.g. user2 | Username used for user login. |
| Type | text; default: Local user | Indicates the account type (read-only for local users). |
| Email address | text; default: none | Email address of the user. |
| Password | password field; default: none | Password used for user login. Leaving this field empty will keep the current password. |
| Assign to all instances | off | on; default: on | Automatically assign the user to all current and future hotspot instances. |
| Assigned to instance | instances; default: none | Select the hotspot instances to which this user will be assigned. |
| User group | dropdown; default: default | Select the hotspot group to which this user will belong. |
Groups Tab
The Groups tab (labeled "User groups") displays a list of user groups used to organize hotspot users and apply shared bandwidth/time restrictions.
Header actions:
- Visible columns (7 of 7) – toggle which table columns are displayed.
- Search – search/filter the group list.
Table columns:
| Field | Value | Description |
|---|---|---|
| Name | text; e.g. default | Name of the user group. |
| Download bandwidth | text; default: Unlimited | Maximum download bandwidth allowed for users in this group. |
| Upload bandwidth | text; default: Unlimited | Maximum upload bandwidth allowed for users in this group. |
| Download limit | text; default: Unlimited | Maximum total download data allowed for users in this group. |
| Upload limit | text; default: Unlimited | Maximum total upload data allowed for users in this group. |
| Time limit | text; default: Unlimited | Maximum session/connection time allowed for users in this group. |
| Actions | links: Edit / Delete | Per-row actions to edit or delete the group. The default group cannot be deleted. |
Bottom actions:
- Add – opens a form to create a new user group.
Add/Edit (Actions)
Clicking Edit on a group opens the "<Group Name>" group configuration panel (breadcrumb: Services > Hotspot > User Management > User groups > Configuration).
Fields:
| Field | Value | Description |
|---|---|---|
| Name | text; required; e.g. default | Name of the user group. |
| Idle timeout | seconds; default: none (e.g., 0) | If the idle timeout is not configured or is set to '0', it indicates that no timeout is applied, and the session duration is unlimited. |
| Time limit | seconds; default: none (e.g., 1) | The set time limit disables hotspot user after time limit in sec is reached. '0' or empty value is equal to unlimited. |
| Bandwidth limit | Download / Upload (Mb); default: none (e.g., 1000 Mb / 500 Mb) | The max allowed download and upload speed, in megabits. |
| Data limit | Download / Upload (MB); default: none (e.g., 10000 MB / 10000 MB) | Disable hotspot user after download or upload limit value in MB is reached. |
| Period | radio: Day / Week / Month; default: Day | Period for which hotspot data limiting should apply. After the period is over, all specified limits are reset. |
| Start hour/Start day | dropdown; default: 1 | Specifies which day of the month, week or hour of the day the limits will be reset. |
| Expiration time | seconds; default: none | User expiration time in sec. Set to 0 for unlimited session duration. |

















