RB941 hAP lite cocok untuk hotspot skala kecil: cafe, warung, kos-kosan, atau RT/RW Net awal. Kapasitas ideal
10-20 user concurrent. Untuk hotspot >30 user, pertimbangkan upgrade ke hAP ac^2 atau CCR series.
CPU
AR9344 - 650MHz
RAM
32 MB DDR2
STORAGE
16 MB FLASH
ETHERNET
4x 10/100 Mbps
WIRELESS
2.4GHz b/g/n
HOTSPOT
BUILT-IN
USER MAX
~20 CONCURRENT
VOUCHER
UNLIMITED
POWER
5V DC / USB
OS
RouterOS v6 L4
DIMENSI
113 x 89 x 28mm
BERAT
160 gram
LIMITASI HOTSPOT RB941: RAM 32MB terbatas untuk banyak user + Layer7. Hindari L7 protocol + hotspot bersamaan. Batasi max 20-30 concurrent user. Jika butuh lebih, upgrade hardware.
TOPOLOGI HOTSPOT
SCHEMA
// TOPOLOGI HOTSPOT SERVER + CAPTIVE PORTAL //[ INTERNET / ISP ]
|
| kabel UTP
v
+--------------------------------------+
| MikroTik RB941 |
| HOTSPOT SERVER + CAPTIVE PORTAL |
| |
| ether1 = WAN (IP dari ISP) |
| |
| bridge1 (LAN Gateway) |
| |- ether2 (LAN) |
| |- ether3 (LAN) |
| |- ether4 (LAN) |
| |- wlan1 (WIFI) SSID: CAFE-WIFI |
| |
| IP Gateway: 10.5.50.1/24 |
| HOTSPOT = aktif di bridge |
| LOGIN PAGE = http://10.5.50.1/login |
| USER PROFILE = 1jam, 3jam, 1hari |
| VOUCHER = user/pass auto-generate |
| WALLED GARDEN = WhatsApp, IG, dll |
+--------------------------------------+
| | |
v v v
[ TAMU ][ TAMU ][ TAMU ]connect WiFilogin pageinput voucher-> browse-> voucher-> internet
ALUR HOTSPOT: (1) Tamu connect WiFi, (2) Buka browser -> redirect ke login page, (3) Input username & password (voucher), (4) Router verifikasi, (5) Jika valid -> akses internet sesuai limit profile, (6) Setelah limit habis -> otomatis logout.
ANIMASI CAPTIVE PORTAL FLOW
LIVE FLOW
Visualisasi captive portal: tamu connect WiFi, traffic diblokir (merah), di-redirect ke login page,
setelah login berhasil -> traffic lolos (hijau) ke internet.
Belum Login (Blocked)
Login Page (Captive)
Sudah Login (Passed)
Wireless Link
Response Packet
CAPTIVE PORTAL: Router memblokir semua traffic HTTP/HTTPS dari client yang belum login, lalu redirect ke login page. Setelah autentikasi berhasil, IP/MAC client di-whitelist dan traffic diizinkan sesuai limit profile.
KONSEP DASAR HOTSPOT
FUNDAMENTAL
Hotspot di MikroTik adalah fitur captive portal yang memaksa client untuk login
sebelum dapat akses internet. Berbeda dengan WiFi password biasa, hotspot memberikan kontrol penuh: limit bandwidth,
limit waktu, limit kuota, voucher, walled garden, dan monitoring.
KOMPONEN HOTSPOT
KOMPONEN
FUNGSI
CONTOH
Hotspot Server
Service utama yang aktif di interface
hotspot1 di bridge
User Profile
Template: limit bandwidth, waktu, shared-user
1jam-2Mbps, 1hari-10Mbps
User
Voucher: username & password
v001 / abc123
IP Binding
Bypass/Block berdasarkan MAC/IP
Bypass admin, block device
Walled Garden
Situs yang bisa diakses tanpa login
WhatsApp, Instagram, login page
Login Page
Halaman HTML untuk input voucher
Custom HTML/CSS/JS
MAC Cookie
Auto-login berdasarkan MAC address
Device familiar tidak perlu login ulang
ALUR HOTSPOT
1
CLIENT CONNECT WIFI
Tamu connect ke SSID hotspot (open network, tanpa password WiFi). DHCP beri IP address.
2
CAPTIVE PORTAL INTERCEPT
Router intercept semua HTTP request, redirect ke login page (http://10.5.50.1/login). HTTPS juga di-redirect via SSL redirect.
Router cek username & password di database user. Jika valid -> IP/MAC client di-whitelist.
5
AKSES INTERNET
Client dapat akses internet sesuai limit profile (bandwidth, waktu, kuota). Queue otomatis dibuat.
6
AUTO LOGOUT
Saat limit waktu/kuota habis, atau idle timeout tercapai, router otomatis logout client. IP dikembalikan ke pool.
HOTSPOT vs WIFI PASSWORD
ASPEK
HOTSPOT
WIFI PASSWORD
Autentikasi
Username & password (voucher)
Password WiFi saja
Limit bandwidth
Per user (via profile)
Tidak bisa
Limit waktu
Per user (uptime limit)
Tidak bisa
Limit kuota
Per user (bytes limit)
Tidak bisa
Monitoring
Detail per user
Hanya per device
Voucher
Bisa jual voucher
Tidak bisa
Walled garden
Bisa
Tidak bisa
Kompleksitas
Lebih kompleks
Simpel
Use case
Cafe, hotel, RT/RW Net
Rumah, kantor private
KAPAN PAKAI HOTSPOT? Jika Anda butuh: (1) kontrol akses per user, (2) limit bandwidth/waktu/kuota, (3) jual voucher, (4) monitoring detail, (5) walled garden. Untuk rumah/kantor private yang tidak butuh fitur ini, WiFi password biasa sudah cukup.
PERSIAPAN SEBELUM KONFIGURASI
STEP 01
Siapkan hal-hal berikut agar proses konfigurasi hotspot berjalan lancar.
YANG HARUS DISIAPKAN
ITEM
KETERANGAN
CATATAN
Router RB941
Sudah terpasang adaptor 5V
LED PWR harus menyala
Kabel UTP
Minimal 2 buah (straight)
1 untuk WAN, 1 untuk PC
PC/Laptop
Dengan port ethernet
Untuk akses awal via kabel
WinBox
Download dari mikrotik.com
Atau pakai browser (WebFig)
Info ISP
Jenis koneksi: DHCP/PPPoE/Static
Tanya ISP jika tidak tahu
Skema IP Hotspot
Subnet untuk hotspot
Contoh: 10.5.50.0/24
Nama SSID
Nama WiFi hotspot
Contoh: CAFE-WIFI
Rencana Voucher
Paket voucher yang akan dijual
1jam, 3jam, 1hari, dll
SKEMA IP HOTSPOT
KOMPONEN
IP ADDRESS
KETERANGAN
Gateway Hotspot
10.5.50.1/24
IP router di hotspot network
Subnet
10.5.50.0/24
Range: .0 - .255
DHCP Pool
10.5.50.2 - 10.5.50.254
253 IP untuk client hotspot
Login Page
http://10.5.50.1/login
URL login page hotspot
RENCANA VOUCHER
Rp 2.000
1 JAM
Bandwidth2M / 5M
Uptime1 jam
Shared1 user
Rp 5.000
3 JAM
Bandwidth3M / 7M
Uptime3 jam
Shared1 user
Rp 10.000
1 HARI
Bandwidth5M / 10M
Uptime24 jam
Shared2 user
Rp 50.000
1 MINGGU
Bandwidth10M / 20M
Uptime7 hari
Shared3 user
TIPS: Sesuaikan harga voucher dengan bandwidth ISP dan target pasar. Untuk cafe/warung, voucher 1-3 jam paling laku. Untuk kos-kosan, voucher harian/mingguan lebih cocok.
RESET & AKSES ROUTER
STEP 02
Reset router ke factory default, lalu akses via WinBox atau browser.
VIA HARDWARE
1
Cabut power router
2
Tekan tombol RESET dengan pin
3
Colok power sambil tekan RESET
4
Tunggu ~5 detik sampai LED ACT berkedip
5
Lepas tombol, router reboot
6
Tunggu 1-2 menit sampai fully boot
VIA CLI
# Reset dengan default config[admin@MikroTik] > /system reset-configurationDo you really want to resetconfiguration? [y/N]y# Reset tanpa default config[admin@MikroTik] > /system reset-configurationno-defaults=yes skip-backup=yes! WARNING: semua konfigurasi terhapus
AKSES ROUTER
VIA WINBOX (RECOMMENDED)
1
Colok kabel UTP dari PC ke ether2
2
Buka WinBox
3
Tab Neighbors, tunggu router muncul
4
Klik MAC address router
5
Login: admin | Password: (kosong)
6
Klik Connect
VIA WEBFIG (BROWSER)
1
Colok kabel UTP dari PC ke ether2
2
Buka browser
3
Ketik: http://192.168.88.1
4
Login: admin | Password: (kosong)
5
Masuk ke WebFig
PENTING: Selalu connect via MAC address di WinBox. Jika IP berubah atau salah konfigurasi, Anda masih bisa akses via MAC.
IDENTITY & GANTI PASSWORD
STEP 03
Beri nama router dan GANTI PASSWORD ADMIN. WAJIB sebelum router terhubung internet.
VIA CLI
# 1. Set identity[admin@MikroTik] > /system identityset name="HOTSPOT-CAFE"[admin@HOTSPOT-CAFE] > # 2. Ganti password admin (WAJIB!)[admin@HOTSPOT-CAFE] > /user set adminpassword="Rozak@Hotspot2024!"# 3. Cek list user[admin@HOTSPOT-CAFE] > /user print # NAME GROUP 0 admin full
VIA WINBOX
1
Menu: System -> Identity
2
Name: HOTSPOT-CAFE
3
Klik OK
4
Menu: System -> Users
5
Double-click admin -> tombol Password
6
Password baru (min 12 karakter)
7
Klik OK -> OK
KRITIS: Password admin harus KUAT. Minimal 12 karakter, kombinasi huruf besar, kecil, angka, dan simbol. CATAT di tempat aman. Jika lupa, harus reset fisik router.
CEK & NAMA INTERFACE
STEP 04
Cek interface, beri nama yang jelas. ether1 = WAN, ether2-4 = LAN, wlan1 = WIFI.
VIA CLI
# 1. Cek interface[admin@HOTSPOT-CAFE] > /interface print # NAME TYPE MTU 0 ether1 ether 1500 1 ether2 ether 1500 2 ether3 ether 1500 3 ether4 ether 1500 4 wlan1 wlan 1500 5 bridge1 bridge 1500# 2. Rename interface[admin@HOTSPOT-CAFE] > /interface set ether1 name="WAN"[admin@HOTSPOT-CAFE] > /interface set ether2 name="LAN1"[admin@HOTSPOT-CAFE] > /interface set ether3 name="LAN2"[admin@HOTSPOT-CAFE] > /interface set ether4 name="LAN3"
VIA WINBOX
1
Menu: Interfaces
2
Double-click ether1 -> Name: WAN
3
Ulangi untuk ether2-4: LAN1, LAN2, LAN3
4
Klik Apply -> OK
BRIDGE SETUP
STEP 05
Bridge menyatukan LAN (ether2-4) dan WiFi (wlan1) menjadi satu jaringan. Hotspot akan aktif di bridge ini.
VIA CLI
# 1. Cek bridge port default[admin@HOTSPOT-CAFE] > /interface bridge port print # INTERFACE BRIDGE PVID 0 ether2 bridge1 1 1 ether3 bridge1 1 2 ether4 bridge1 1 3 wlan1 bridge1 1# 2. Optimasi bridge[admin@HOTSPOT-CAFE] > /interface bridge set bridge1protocol-mode=none fast-forward=yes# protocol-mode=none untuk hotspot# (RSTP bisa konflik dengan hotspot)
VIA WINBOX
1
Menu: Bridge
2
Tab Ports: cek ether2-4, wlan1 sudah ada
3
Double-click bridge1
4
Tab Advanced: Protocol Mode: none
5
Tab HW: centang Fast Forward
6
Klik Apply -> OK
PENTING: Untuk hotspot, set protocol-mode=none. RSTP bisa menyebabkan masalah dengan hotspot captive portal. Jangan masukkan ether1 (WAN) ke bridge!
IP ADDRESS GATEWAY HOTSPOT
STEP 06
Setup IP address untuk bridge. IP ini akan jadi gateway untuk semua client hotspot dan jadi URL login page.
VIA CLI
# 1. Ganti IP gateway hotspot[admin@HOTSPOT-CAFE] > /ip address set[find interface=bridge]address=10.5.50.1/24# 2. Verifikasi[admin@HOTSPOT-CAFE] > /ip address print # ADDRESS NETWORK INTERFACE 0 10.5.50.1/24 10.5.50.0 bridge! Setelah ganti IP, akses router! via IP baru: 10.5.50.1! Login page: http://10.5.50.1/login
VIA WINBOX
1
Menu: IP -> Addresses
2
Double-click entry bridge
3
Address: 10.5.50.1/24
4
Interface: bridge
5
Klik Apply -> OK
6
Akses router via 10.5.50.1
TIPS: IP gateway ini akan jadi URL login page: http://10.5.50.1/login. Pilih IP yang mudah diingat atau sesuai skema network Anda.
DHCP CLIENT (WAN)
STEP 07
Setup DHCP client di WAN agar router dapat IP dari ISP.
VIA CLI
# Setup DHCP client di WAN[admin@HOTSPOT-CAFE] > /ip dhcp-client addinterface=ether1disabled=nouse-peer-dns=yesuse-peer-ntp=noadd-default-route=yes# Cek status - harus "bound"[admin@HOTSPOT-CAFE] > /ip dhcp-client print # INTERFACE STATUS ADDRESS 0 ether1 bound 10.10.10.5/24
VIA WINBOX
1
Menu: IP -> DHCP Client
2
+ Add: Interface: ether1
3
Add Default Route: yes
4
Use Peer DNS: yes
5
Klik OK
6
Status harus bound
NAT MASQUERADE
STEP 08
NAT masquerade WAJIB agar client hotspot bisa akses internet.
PENTING: NTP WAJIB untuk hotspot. Jika waktu router salah, uptime limit voucher tidak akurat. User bisa dapat waktu lebih banyak atau lebih sedikit dari yang seharusnya.
PENTING: Urutan rule firewall SANGAT PENTING. Rule accept established HARUS di paling atas. Hotspot akan otomatis tambahkan rule-nya sendiri (hs-auth, hs-unauth) - JANGAN dihapus.
WIRELESS SETUP (OPEN NETWORK)
STEP 12
Setup WiFi sebagai open network (tanpa password WiFi). Autentikasi dilakukan via login page hotspot, bukan WiFi password.
VIA CLI
# 1. Set mode AP, SSID[admin@HOTSPOT-CAFE] > /interface wireless set wlan1mode=ap-bridgessid="CAFE-WIFI"country=indonesiafrequency-mode=regulatory-domain# 2. Set channel[admin@HOTSPOT-CAFE] > /interface wireless set wlan1channel=6band=2ghz-b/g/n# 3. OPEN NETWORK (no security)[admin@HOTSPOT-CAFE] > /interface wireless security-profilesset [find default=yes]mode=noneauthentication-types=""# 4. Set tx-power[admin@HOTSPOT-CAFE] > /interface wireless set wlan1tx-power-mode=all-rates-fixedtx-power=17# 5. Verifikasi[admin@HOTSPOT-CAFE] > /interface wireless print
VIA WINBOX
1
Menu: Wireless
2
Double-click wlan1
3
Tab Wireless: Mode: ap-bridge
4
SSID: CAFE-WIFI
5
Band: 2GHz-B/G/N, Channel: 6
6
Tab Security Profiles -> edit default
7
Mode: none (OPEN NETWORK)
8
Authentication Types: (kosongkan)
9
Klik OK -> Apply -> OK
KENAPA OPEN NETWORK? Hotspot butuh open network agar captive portal bisa bekerja. Jika WiFi pakai password, client tidak bisa connect tanpa password dulu, sehingga tidak bisa di-redirect ke login page. Autentikasi dilakukan via login page, bukan WiFi password.
HOTSPOT SERVER SETUP
HOTSPOT CORE
Aktifkan hotspot server di interface bridge. Ini adalah inti dari captive portal. Setelah setup, semua client yang connect akan di-redirect ke login page.
# 1. Connect HP/Laptop ke SSID "CAFE-WIFI"# 2. HP dapat IP 10.5.50.x dari DHCP# 3. Buka browser, akses http://google.com# 4. Akan di-redirect ke login page:# http://10.5.50.1/login# 5. Login dengan:# Username: admin# Password: admin123# 6. Jika berhasil -> dapat akses internet# Cek user aktif[admin@HOTSPOT-CAFE] > /ip hotspot active print # SERVER USER ADDRESS UPTIME 0 hotspot1 admin 10.5.50.100 2m 15s
PENTING: Setelah hotspot setup, JANGAN hapus rule firewall hs-auth, hs-unauth, hotspot. Rule ini yang mengontrol captive portal. Jika dihapus, hotspot tidak bekerja.
HOTSPOT USER PROFILE
HOTSPOT CORE
User Profile adalah template untuk voucher. Di sini kita set limit bandwidth, limit waktu, shared users, dll. Satu profile bisa dipakai banyak user.
VIA CLI
# 1. Profile 1 JAM - Rp 2.000[admin@HOTSPOT-CAFE] > /ip hotspot user profile addname="1jam-2Mbps"rate-limit="2M/5M"idle-timeout=10mkeepalive-timeout=30sshared-users=1status-autorefresh=1m# 2. Profile 3 JAM - Rp 5.000[admin@HOTSPOT-CAFE] > /ip hotspot user profile addname="3jam-3Mbps"rate-limit="3M/7M"idle-timeout=15mshared-users=1# 3. Profile 1 HARI - Rp 10.000[admin@HOTSPOT-CAFE] > /ip hotspot user profile addname="1hari-5Mbps"rate-limit="5M/10M"idle-timeout=30mshared-users=2# 4. Profile 1 MINGGU - Rp 50.000[admin@HOTSPOT-CAFE] > /ip hotspot user profile addname="1minggu-10Mbps"rate-limit="10M/20M"idle-timeout=1hshared-users=3# 5. Verifikasi[admin@HOTSPOT-CAFE] > /ip hotspot user profile print # NAME RATE-LIMIT SHARED-USERS 0 default 1 1jam-2Mbps 5M/2M 1 2 3jam-3Mbps 7M/3M 1 3 1hari-5Mbps 10M/5M 2 4 1minggu-10Mbps 20M/10M 3
VIA WINBOX
1
Menu: IP -> Hotspot
2
Tab User Profiles
3
+ Add profile baru
4
Tab General: Name: 1jam-2Mbps
5
Tab Limits:
6
Rate Limit: 2M/5M (up/down)
7
Idle Timeout: 10m
8
Shared Users: 1
9
Klik OK
10
Ulangi untuk profile lain
PARAMETER USER PROFILE
PARAMETER
FUNGSI
CONTOH
name
Nama profile
1jam-2Mbps
rate-limit
Limit bandwidth (up/down)
2M/5M (upload 2M, download 5M)
idle-timeout
Logout jika tidak aktif
10m (10 menit)
keepalive-timeout
Interval ping ke client
30s (30 detik)
shared-users
Jumlah device yang bisa login bersamaan
1 (1 device saja)
status-autorefresh
Interval refresh status page
1m (1 menit)
login-by
Metode login
http-chap, http-pap, cookie, mac
on-login
Script saat login
Untuk logging, notifikasi
on-logout
Script saat logout
Untuk logging
TIPS RATE-LIMIT
FORMAT: UP/DOWN
Rate-limit selalu format upload/download. Contoh: 2M/5M = upload 2Mbps, download 5Mbps.
DOWNLOAD > UPLOAD
Download biasanya 2-3x upload. User lebih banyak download (browsing, streaming) daripada upload.
SHARED USERS
1 = 1 device saja (voucher pribadi). 2-3 = bisa dipakai beberapa device (voucher keluarga/kantor).
IDLE TIMEOUT
Logout otomatis jika tidak ada aktivitas. Hemat bandwidth. 10-30 menit cocok untuk voucher singkat.
TIPS: Profile "default" yang dibuat saat setup hotspot bisa dihapus atau dimodifikasi. Buat profile baru sesuai paket voucher yang akan dijual.
USER & VOUCHER
HOTSPOT CORE
User adalah voucher yang akan diberikan ke tamu. Setiap user punya username, password, profile, dan limit uptime.
VIA CLI
# 1. Voucher 1 JAM[admin@HOTSPOT-CAFE] > /ip hotspot user addname="v001"password="abc123"profile="1jam-2Mbps"limit-uptime=1hcomment="Voucher 1 Jam - Rp 2000"# 2. Voucher 3 JAM[admin@HOTSPOT-CAFE] > /ip hotspot user addname="v002"password="xyz789"profile="3jam-3Mbps"limit-uptime=3hcomment="Voucher 3 Jam - Rp 5000"# 3. Voucher 1 HARI[admin@HOTSPOT-CAFE] > /ip hotspot user addname="v003"password="daily2024"profile="1hari-5Mbps"limit-uptime=1dcomment="Voucher 1 Hari - Rp 10000"# 4. Voucher 1 MINGGU[admin@HOTSPOT-CAFE] > /ip hotspot user addname="v004"password="weekly2024"profile="1minggu-10Mbps"limit-uptime=7dcomment="Voucher 1 Minggu - Rp 50000"# 5. Voucher dengan limit kuota[admin@HOTSPOT-CAFE] > /ip hotspot user addname="v005"password="quota1gb"profile="1hari-5Mbps"limit-bytes-total=1Gcomment="Voucher 1GB - Rp 10000"# 6. Verifikasi[admin@HOTSPOT-CAFE] > /ip hotspot user print # NAME PROFILE UPTIME LIMIT-UPTIME 0 admin default 1 v001 1jam-2Mbps 0s 1h 2 v002 3jam-3Mbps 0s 3h 3 v003 1hari-5Mbps 0s 1d 4 v004 1minggu-10Mbps 0s 7d 5 v005 1hari-5Mbps 0s -
VIA WINBOX
1
Menu: IP -> Hotspot
2
Tab Users
3
+ Add user baru
4
Tab General:
5
Name: v001 (username)
6
Password: abc123
7
Profile: 1jam-2Mbps
8
Tab Limits:
9
Uptime: 1h (limit waktu)
10
Comment: Voucher 1 Jam - Rp 2000
11
Klik OK
12
Ulangi untuk voucher lain
CONTOH VOUCHER
v001 / abc123
1 JAM - Rp 2.000
Profile1jam-2Mbps
Bandwidth2M / 5M
Uptime1 jam
Shared1 user
v002 / xyz789
3 JAM - Rp 5.000
Profile3jam-3Mbps
Bandwidth3M / 7M
Uptime3 jam
Shared1 user
v003 / daily2024
1 HARI - Rp 10.000
Profile1hari-5Mbps
Bandwidth5M / 10M
Uptime24 jam
Shared2 user
v005 / quota1gb
1 GB - Rp 10.000
Profile1hari-5Mbps
Bandwidth5M / 10M
Quota1 GB
Shared1 user
LIMIT UPTIME FORMAT
FORMAT
ARTI
CONTOH
30s
30 detik
Trial singkat
10m
10 menit
Trial
1h
1 jam
Voucher 1 jam
3h
3 jam
Voucher 3 jam
1d
1 hari (24 jam)
Voucher harian
7d
7 hari
Voucher mingguan
30d
30 hari
Voucher bulanan
LIMIT BYTES (KUOTA)
# limit-bytes-total = total upload + download# limit-bytes-in = download saja# limit-bytes-out = upload saja# Format:# 100M = 100 MB# 1G = 1 GB# 5G = 5 GB# Contoh: voucher 1GB[admin@HOTSPOT-CAFE] > /ip hotspot user addname="v005"password="quota1gb"profile="1hari-5Mbps"limit-bytes-total=1G# Saat total upload+download mencapai 1GB,# user otomatis logout.
TIPS: Username & password case-sensitive. "abc123" berbeda dengan "ABC123". Buat username yang mudah diingat tapi tidak mudah ditebak. Jangan pakai nama umum seperti "admin", "user", "test".
AUTO GENERATOR VOUCHER
HOTSPOT ADVANCED
Buat script untuk generate voucher otomatis. Lebih cepat daripada buat manual satu per satu. Bisa generate 10-100 voucher dalam hitungan detik.
# Export voucher ke format yang bisa dicetak[admin@HOTSPOT-CAFE] > /ip hotspot user print where comment="Auto-generated" # NAME PASSWORD PROFILE UPTIME 0 v1h001 a3k8m2 1jam-2Mbps 1h 1 v1h002 b4l9n3 1jam-2Mbps 1h 2 v1h003 c5m0p4 1jam-2Mbps 1h# Export ke file[admin@HOTSPOT-CAFE] > /ip hotspot user print file="voucher-list"# Download file via WinBox:# Menu Files -> drag file voucher-list.txt ke desktop# Print file tersebut untuk jadi voucher fisik# ATAU pakai tool external:# - Mikhmon (web-based hotspot manager)# - UserManager (MikroTik official)# - Script Python untuk generate + print
TIPS AUTO GENERATOR
PASSWORD RANDOM
Pakai karakter random untuk password. Hindari password yang mudah ditebak. 6-8 karakter cukup untuk voucher.
USERNAME SEQUENTIAL
Username dengan prefix + nomor: v1h001, v1h002, dst. Mudah di-track dan di-manage.
PAKAI COMMENT
Beri comment untuk setiap voucher: "Auto-generated", "Voucher 1 Jam", dll. Memudahkan filtering.
SCHEDULER
Bisa jadwalkan script generator otomatis tiap hari/minggu untuk stok voucher baru.
TIPS: Untuk produksi, pertimbangkan pakai Mikhmon atau tool external yang lebih lengkap: generate voucher, print voucher, monitoring, reporting, dll. Script di atas hanya contoh dasar.
WALLED GARDEN
HOTSPOT ADVANCED
Walled Garden memungkinkan client akses situs tertentu TANPA login hotspot. Berguna untuk: WhatsApp, Instagram, situs pembayaran, situs internal, dll.
WhatsApp, Instagram, Facebook. User bisa tetap chat/browse tanpa harus login dulu.
SITUS PEMBAYARAN
Bank, e-wallet, payment gateway. User bisa bayar voucher tanpa login hotspot.
SITUS INTERNAL
Server internal, printer network, dll. Akses tanpa perlu login.
JANGAN ABUSE
Jangan masukkan semua situs ke walled garden. Nanti user tidak perlu login sama sekali.
CATATAN: Walled garden hanya bekerja untuk HTTP. Untuk HTTPS, perlu tambahan walled-garden-IP atau walled-garden-IP6. Beberapa aplikasi modern (WhatsApp, Instagram) pakai HTTPS, jadi perlu tambahkan IP address-nya juga.
IP BINDING
HOTSPOT ADVANCED
IP Binding untuk bypass atau block client berdasarkan MAC address. Berguna untuk: admin bypass (tidak perlu login), block device tertentu, atau fix IP untuk device tertentu.
VIA CLI
# 1. BYPASS: Admin tidak perlu login[admin@HOTSPOT-CAFE] > /ip hotspot ip-binding addmac-address="A1:B2:C3:D4:E5:F6"type=bypassedcomment="Admin Laptop"# 2. BYPASS: Printer tidak perlu login[admin@HOTSPOT-CAFE] > /ip hotspot ip-binding addmac-address="B2:C3:D4:E5:F6:01"type=bypassedcomment="Printer"# 3. BLOCK: Device tidak boleh connect[admin@HOTSPOT-CAFE] > /ip hotspot ip-binding addmac-address="XX:XX:XX:XX:XX:XX"type=blockedcomment="Device Blocked"# 4. REGULAR: Fix IP untuk device[admin@HOTSPOT-CAFE] > /ip hotspot ip-binding addmac-address="C3:D4:E5:F6:01:02"address=10.5.50.50type=regularcomment="NAS Server"# 5. Verifikasi[admin@HOTSPOT-CAFE] > /ip hotspot ip-binding print # MAC-ADDRESS ADDRESS TYPE 0 A1:B2:C3:D4:E5:F6 bypassed 1 B2:C3:D4:E5:F6:01 bypassed 2 XX:XX:XX:XX:XX:XX blocked 3 C3:D4:E5:F6:01:02 10.5.50.50 regular
VIA WINBOX
1
Menu: IP -> Hotspot
2
Tab IP Binding
3
+ Add binding baru
4
MAC Address: A1:B2:C3:D4:E5:F6
5
Type: bypassed
6
Comment: Admin Laptop
7
Klik OK
8
Ulangi untuk device lain
TIPE IP BINDING
TYPE
FUNGSI
KEGUNAAN
regular
Fix IP untuk MAC tertentu
Device selalu dapat IP yang sama
bypassed
Bypass hotspot (tidak perlu login)
Admin, printer, server internal
blocked
Block device (tidak dapat IP)
Device tidak diinginkan
KASUS PENGGUNAAN
ADMIN BYPASS
Laptop admin tidak perlu login setiap kali connect. Pakai type=bypassed.
PRINTER / SERVER
Device yang butuh IP tetap dan tidak perlu login. Pakai type=bypassed atau regular.
BLOCK DEVICE
Block device yang tidak diinginkan (misal device bekas karyawan). Pakai type=blocked.
FIX IP
Device selalu dapat IP yang sama (seperti static lease DHCP). Pakai type=regular + address.
TIPS: Untuk lihat MAC address client yang sedang connect, cek di /ip hotspot active print atau /ip dhcp-server lease print. Catat MAC address device yang ingin di-bypass/block.
CUSTOM LOGIN PAGE
HOTSPOT ADVANCED
Ganti tampilan login page default dengan design custom. Bisa pakai HTML, CSS, JavaScript. Tambahkan logo, info voucher, harga, dll.
PREVIEW LOGIN PAGE CUSTOM
CAFE WIFI
FREE INTERNET HOTSPOT
Username: v001
Password: ********
STRUKTUR FILE HOTSPOT
# File login page ada di folder /hotspot//hotspot/ |- login.html <- Halaman login utama |- a.html <- Halaman setelah login sukses |- rlogin.html <- Redirect setelah login |- status.html <- Halaman status user aktif |- logout.html <- Halaman setelah logout |- error.html <- Halaman error |- css/ <- Folder CSS |- img/ <- Folder gambar |- js/ <- Folder JavaScript# Edit file login.html untuk custom design# Upload via WinBox: Menu Files -> /hotspot/ -> drag file
Tambahkan logo cafe/warung. Upload gambar ke folder /hotspot/img/. Pakai di HTML.
RESPONSIVE DESIGN
Pastikan login page tampil bagus di HP dan tablet. Pakai CSS responsive (media query).
INFO VOUCHER
Tampilkan daftar harga voucher di login page. User tahu pilihan yang tersedia.
MULTI LANGUAGE
Bisa buat login page multi bahasa (ID/EN) dengan JavaScript atau multiple file.
TIPS: Backup file login.html default sebelum dimodifikasi. Jika ada masalah, bisa restore ke default. Test login page di browser incognito untuk hindari cache.
MAC COOKIE
HOTSPOT ADVANCED
MAC Cookie memungkinkan device yang sudah pernah login tidak perlu login ulang dalam periode tertentu. Berguna untuk user tetap yang sering datang.
User login dengan voucher. Router simpan MAC address + timestamp di database cookie.
2
USER LOGOUT / LIMIT HABIS
User logout otomatis atau manual. MAC cookie masih tersimpan di router.
3
USER CONNECT KEMBALI
User connect WiFi lagi. Router cek MAC cookie - jika masih valid (< timeout), auto-login tanpa perlu input voucher.
4
COOKIE EXPIRE
Setelah timeout (misal 3 hari), cookie expire. User harus login ulang dengan voucher baru.
REKOMENDASI TIMEOUT
SKENARIO
TIMEOUT
ALASAN
Cafe/Warung
1d - 3d
Tamu sering kembali dalam 1-3 hari
Kos-kosan
7d - 30d
Penghuni tetap, jarang ganti device
Kantor
7d - 30d
Karyawan tetap, device tetap
Event
3h - 1d
Peserta event, durasi singkat
Hotel
1d - 7d
Sesuai durasi menginap
TIPS MAC COOKIE
USER EXPERIENCE
MAC cookie meningkatkan UX. User tidak perlu login berulang. Cocok untuk user tetap.
JANGAN TERLALU PANJANG
Timeout terlalu panjang = voucher tidak laku. User bisa pakai voucher lama terus.
CLEAR COOKIE PERIODIC
Bersihkan MAC cookie secara berkala (misal tiap minggu) agar user beli voucher baru.
MAC ADDRESS BISA DI-SPOOF
User advanced bisa spoof MAC address untuk bypass. Untuk keamanan tinggi, pertimbangkan metode lain.
TIPS: MAC cookie cocok untuk cafe/warung dengan pelanggan tetap. Untuk hotspot yang murni jual voucher (tanpa pelanggan tetap), disable MAC cookie agar user harus beli voucher setiap kali.
HOTSPOT + QUEUE TREE (QOS)
HOTSPOT ADVANCED
Hotspot otomatis buat simple queue per user berdasarkan rate-limit di profile. Untuk QOS lebih advanced, bisa integrasi dengan queue tree.
VIA CLI
# Hotspot otomatis buat simple queue# saat user login[admin@HOTSPOT-CAFE] > /queue simple print # NAME TARGET MAX-LIMIT 0 hs-v001 10.5.50.100 5M/2M 1 hs-v002 10.5.50.101 7M/3M 2 hs-v003 10.5.50.102 10M/5M# Queue otomatis dihapus saat user logout# Untuk total bandwidth hotspot:[admin@HOTSPOT-CAFE] > /queue simple addname="total-hotspot"target="10.5.50.0/24"max-limit="45M/48M"queue="pcq-upload-default/pcq-download-default"comment="Total Hotspot Bandwidth"# Cek queue aktif[admin@HOTSPOT-CAFE] > /queue simple print
VIA WINBOX
1
Menu: Queues
2
Lihat queue otomatis dari hotspot (hs-*)
3
+ Add queue baru untuk total
4
Name: total-hotspot
5
Target: 10.5.50.0/24
6
Max Limit: 45M/48M
7
Queue: pcq-upload-default/pcq-download-default
8
Klik OK
STRATEGI QOS HOTSPOT
STRATEGI
CARA
KEGUNAAN
Per User (otomatis)
Rate-limit di profile
Limit bandwidth per voucher
Total Hotspot
Simple queue untuk subnet
Limit total bandwidth hotspot
PCQ
Queue type PCQ
Fair sharing antar user
Priority
Queue priority
Prioritas jenis traffic
TIPS: Untuk hotspot sederhana, rate-limit di profile sudah cukup. Untuk hotspot dengan banyak user, tambahkan total queue + PCQ agar bandwidth terdistribusi adil.
MONITORING HOTSPOT
HOTSPOT MONITOR
Monitor performa hotspot: user aktif, bandwidth, voucher terpakai, log, dll.
VIA CLI
# 1. Cek user aktif[admin@HOTSPOT-CAFE] > /ip hotspot active print # SERVER USER ADDRESS UPTIME BYTES 0 hotspot1 v001 10.5.50.100 15m 32s 45MB/120MB 1 hotspot1 v002 10.5.50.101 2h 15m 120MB/450MB# 2. Cek semua user (aktif + tidak aktif)[admin@HOTSPOT-CAFE] > /ip hotspot user print # NAME PROFILE UPTIME LIMIT-UPTIME 0 admin default 1 v001 1jam-2Mbps 15m 32s 1h 2 v002 3jam-3Mbps 2h 15m 3h 3 v003 1hari-5Mbps 0s 1d# 3. Cek hit (berapa kali user login)[admin@HOTSPOT-CAFE] > /ip hotspot user print detail 1 name="v001" profile="1jam-2Mbps" uptime=15m 32s bytes-in=45MB bytes-out=120MB limit-uptime=1h hits=1# 4. Cek log hotspot[admin@HOTSPOT-CAFE] > /log print where topics="hotspot"# 5. Monitor real-time[admin@HOTSPOT-CAFE] > /log print follow where topics="hotspot"# 6. Cek statistik server[admin@HOTSPOT-CAFE] > /ip hotspot print stats
VIA WINBOX
1
Menu: IP -> Hotspot
2
Tab Active: lihat user yang sedang online
3
Tab Users: lihat semua user + status
4
Tab Hosts: lihat semua device yang connect
5
Menu: Queues: lihat bandwidth per user
6
Menu: Log: filter topic hotspot
7
Menu: Tools -> Graphing: grafik bandwidth
METRIK YANG PERLU DIMONITOR
METRIK
CARA CEK
KETERANGAN
User aktif
/ip hotspot active print
Berapa user yang sedang online
Bandwidth per user
/queue simple print
Berapa bandwidth yang dipakai
Uptime user
/ip hotspot user print
Berapa lama user sudah online
Bytes in/out
/ip hotspot user print detail
Total download/upload per user
Hits
/ip hotspot user print detail
Berapa kali user login
Log login/logout
/log print where topics="hotspot"
Log aktivitas user
CPU load
/system resource print
Pastikan CPU tidak overload
TIPS MONITORING
GRAPHING
Aktifkan graphing untuk lihat grafik bandwidth historis. Berguna untuk analisis pola penggunaan.
LOGGING
Log semua aktivitas login/logout. Berguna untuk troubleshooting dan audit.
NOTIFIKASI
Script untuk notifikasi jika ada user login, atau jika CPU overload. Bisa kirim email/Telegram.
MIKHMON / USERMANAGER
Tool external untuk monitoring lebih lengkap: dashboard, reporting, user management, dll.
TIPS: Monitor hotspot secara rutin, terutama saat ramai. Jika CPU >80% atau banyak user complaint lambat, pertimbangkan upgrade hardware atau limit user concurrent.
TRIAL ACCESS
HOTSPOT ADVANCED
Berikan akses trial gratis untuk menarik pelanggan. User bisa coba internet gratis beberapa menit sebelum memutuskan beli voucher.
VIA CLI
# 1. Buat profile trial[admin@HOTSPOT-CAFE] > /ip hotspot user profile addname="trial-15min"rate-limit="1M/2M"idle-timeout=5mshared-users=1# 2. Buat user trial[admin@HOTSPOT-CAFE] > /ip hotspot user addname="trial"password="trial"profile="trial-15min"limit-uptime=15mcomment="Free Trial 15 Menit"# 3. Test trial# Username: trial# Password: trial# Dapat 15 menit gratis# 4. ALTERNATIF: MAC-based trial# Setiap MAC dapat 1x trial# Butuh script custom untuk implementasi
VIA WINBOX
1
Menu: IP -> Hotspot -> User Profiles
2
+ Add: Name: trial-15min
3
Rate Limit: 1M/2M
4
Idle Timeout: 5m
5
Shared Users: 1
6
Klik OK
7
Tab Users -> + Add
8
Name: trial, Password: trial
9
Profile: trial-15min, Uptime: 15m
10
Klik OK
STRATEGI TRIAL
DURASI PENDEK
15-30 menit cukup untuk coba kecepatan. Tidak terlalu panjang agar user tetap beli voucher.
BANDWIDTH TERBATAS
Limit bandwidth trial lebih rendah dari voucher berbayar. User merasa butuh upgrade.
1x PER DEVICE
Batasi trial 1x per MAC address. Butuh script custom atau tool external.
PROMOSI DI LOGIN PAGE
Tampilkan info trial di login page. "Coba gratis 15 menit! Username: trial, Password: trial".
TIPS: Trial efektif untuk menarik pelanggan baru. Tapi jangan terlalu generous - nanti user tidak mau beli voucher. Trial 15 menit dengan bandwidth terbatas sudah cukup untuk demo.
TROUBLESHOOTING HOTSPOT
SUPPORT
Masalah umum hotspot dan solusinya.
CLIENT TIDAK DIREDIRECT KE LOGIN PAGE
KEMUNGKINAN PENYEBAB:
1. Hotspot tidak aktif: /ip hotspot print
2. NAT redirect tidak ada: /ip firewall nat print
3. Client pakai HTTPS (hotspot hanya redirect HTTP)
4. Client sudah login (cek /ip hotspot active print)
5. DNS client tidak resolve ke hotspot IP SOLUSI: Cek hotspot aktif, NAT redirect ada. Test akses http://10.5.50.1 langsung. Clear browser cache.
LOGIN GAGAL / USERNAME PASSWORD SALAH
KEMUNGKINAN PENYEBAB:
1. Username/password salah (case-sensitive)
2. User tidak ada: /ip hotspot user print
3. User disabled: cek kolom disabled
4. Uptime sudah habis (limit-uptime tercapai)
5. Shared users penuh (device lain sudah login)
6. Profile tidak ada: /ip hotspot user profile print SOLUSI: Cek user ada & enabled. Reset uptime jika perlu. Cek shared users.
LOGIN BERHASIL TAPI TIDAK BISA INTERNET
KEMUNGKINAN PENYEBAB:
1. NAT masquerade tidak ada: /ip firewall nat print
2. Default route tidak ada: /ip route print
3. DNS tidak aktif: /ip dns print
4. Firewall block: /ip firewall filter print
5. Router tidak dapat IP dari ISP: /ip dhcp-client print SOLUSI: Cek NAT, route, DNS. Test ping dari router ke 8.8.8.8.
HOTSPOT LAMBAT / CPU OVERLOAD
KEMUNGKINAN PENYEBAB:
1. Terlalu banyak user concurrent (>20 untuk RB941)
2. Layer7 protocol aktif (berat CPU)
3. Banyak walled garden rules
4. RAM penuh (32MB terbatas)
5. Bandwidth terlalu tinggi SOLUSI: Cek CPU: /system resource print. Disable L7. Kurangi user. Upgrade hardware jika perlu.
USER TIDAK AUTO LOGOUT SAAT LIMIT HABIS
KEMUNGKINAN PENYEBAB:
1. NTP tidak sinkron (waktu router salah)
2. Keepalive timeout tidak aktif
3. Client tidak respond ke keepalive
4. Bug di RouterOS version SOLUSI: Cek NTP: /system ntp client print. Set keepalive-timeout=30s. Update RouterOS.
WALLED GARDEN TIDAK BEKERJA
KEMUNGKINAN PENYEBAB:
1. Host pattern salah (pakai wildcard *.domain.com)
2. Aplikasi pakai HTTPS (butuh walled-garden-IP)
3. DNS tidak resolve domain
4. Rule walled garden disabled SOLUSI: Cek pattern. Untuk HTTPS, tambahkan IP address di walled-garden-IP. Test di browser incognito.
DIAGNOSTIC COMMANDS
# Cek semua komponen hotspot> /ip hotspot print> /ip hotspot active print> /ip hotspot user print> /ip hotspot user profile print> /ip hotspot ip-binding print> /ip hotspot walled-garden print# Cek firewall & NAT> /ip firewall nat print> /ip firewall filter print# Cek DHCP> /ip dhcp-server print> /ip dhcp-server lease print# Cek log> /log print where topics="hotspot"> /log print follow where topics="hotspot"# Test connectivity> /ping 8.8.8.8> /ping google.com
BEST PRACTICE HOTSPOT
TIPS
PASSWORD VOUCHER KUAT
Jangan pakai password mudah ditebak (123456, password). Pakai random string 6-8 karakter.
NTP WAJIB
NTP wajib untuk uptime limit akurat. Jika waktu router salah, voucher tidak akurat.