For voucher and card-based access — captive portal login instead of PPPoE dial-in. Fill in your network and RADIUS details on the left, get a ready-to-import script on the right.
Hotspot login is a different access model from PPPoE — clients get a DHCP lease first, then get redirected to a login page before they're allowed out. Six pieces, wired together correctly.
A DHCP server on the hotspot interface — clients need an IP before they can even see the login page.
For beginners: this is the step before authentication. A hotspot client gets an IP the moment it connects to your wireless network — the login page only appears when it tries to browse. No DHCP server here means no IP, and no client ever reaches the login screen at all.
The address range handed out to connecting devices, shared between DHCP and the hotspot server.
For beginners: size this range for how many devices could realistically be connected at once, not just active subscribers — phones and routers often hold a lease even when idle.
Registered with service=hotspot (not ppp) — authentication and accounting for voucher logins.
For beginners: this is the same RADIUS server concept as the PPPoE generator, but tagged for hotspot traffic specifically. Voucher codes themselves live on your RADIUS platform — this script only tells the router where to check them.
Carries the login page hostname and turns on RADIUS with a 5-minute interim update for live usage data.
For beginners: the hostname here is what shows in the subscriber's browser address bar during login — it doesn't need to be a real registered domain, just something consistent you can reference in support.
Optional — lets a specific domain (like a payment page) load before the subscriber logs in.
For beginners: without a walled garden entry, a subscriber can't even reach your payment page to buy a voucher, because the router blocks everything until login — this is the one deliberate exception.
Same WAN-side Winbox/Telnet hardening as the PPPoE generator.
For beginners: this closes router management ports to the public internet, not to your hotspot clients — see the router security guide for the full reasoning.
What the generator produces with the default values shown above — a full RouterOS Hotspot + RADIUS configuration, ready to import.
# IP pool — handed out to connecting clients /ip pool add name=hs-pool ranges=10.20.20.10-10.20.20.254 # DHCP server on the hotspot interface /ip dhcp-server add interface=ether3 address-pool=hs-pool name=hs-dhcp disabled=no /ip dhcp-server network add address=10.20.20.0/24 gateway=10.20.20.1 dns-server=8.8.8.8,1.1.1.1 # RADIUS — authentication + accounting for hotspot service /radius add service=hotspot address=192.168.88.10 secret=•••••••• authentication-port=1812 accounting-port=1813 # Hotspot profile — login page + RADIUS /ip hotspot profile add name=hs-profile hotspot-address=10.20.20.1 dns-name=login.mynetwork.com login-by=http-chap,http-pap use-radius=yes radius-interim-update=5m
Fill in your hotspot interface, network, and RADIUS server details in the generator on this page. It builds the DHCP server, IP pool, RADIUS registration, and hotspot profile together, ready to download as a .rsc file. Voucher codes themselves are created on your RADIUS platform (SAS4, GalaxyRAD, etc.) — this script only tells the router where to check them. See the full setup guide for how captive portal login actually works.
A walled garden lets a specific domain — usually a payment page — load before a subscriber logs in. Without it, a subscriber can't reach your payment page at all, since the router blocks everything until login. Only fill this in if you're selling vouchers online.
Hotspot suits walk-up, voucher-based, or public access where subscribers don't have fixed accounts. PPPoE suits fixed monthly subscribers with a dedicated login. See the full PPPoE vs Hotspot comparison for a detailed breakdown.
No. Everything runs in the browser with plain JavaScript — nothing typed into this form is transmitted to any server. See the privacy policy for details.