![MikroTik RouterOS v2.9 Reference Manual Download Page 542](http://html1.mh-extra.com/html/mikrotik/routeros-v2-9/routeros-v2-9_reference-manual_1794644542.webp)
Local HotSpot user database non-fatal errors:
• invalid username or password - self-explanatory
• user $(username) is not allowed to log in from this MAC address - trying to log in from a
MAC address different from specified in user database. Solution: log in from the correct MAC
address or take out the limitation
• user $(username) has reached uptime limit - self-explanatory
• user $(username) has reached traffic limit - either limit-bytes-in or limit-bytes-out limit is
reached
• no more sessions are allowed for user $(username) - the shared-users limit for the user's
profile is reached. Solution: wait until someone with this username logs out, use different login
name or extend the shared-users limit
RADIUS client non-fatal errors:
• invalid username or password - RADIUS server has rejected the username and password sent
to it without specifying a reason. Cause: either wrong username and/or password, or other error.
Solution: should be clarified in RADIUS server's log files
• <error_message_sent_by_radius_server> - this may be any message (any text string) sent
back by RADIUS server. Consult with your RADIUS server's documentation for further
information
RADIUS client fatal errors:
• RADIUS server is not responding - user is being authenticated by RADIUS server, but no
response is received from it. Solution: check whether the RADIUS server is running and is
reachable from the HotSpot router
HotSpot How-to's
Description
This section will focus on some simple examples of how to use your HotSpot system, as well as
give some useful ideas.
Setting up https authorization
At first certificate must be present with decrypted private key:
Then we can use that certificate for hotspot:
After that we can see, that HTTPS is running on hotspot interface:
Bypass hotspot for some devices in hotspot network
All IP binding entries with type property set to bypassed, will not be asked to authorize - it means
that they will have login-free access:
If all fields has been filled in the ip-binding table and type has been set to bypassed, then the IP
address of this entry will be accessible from public interfaces immediately:
Page 528 of 695
Copyright 1999-2007, MikroTik. All rights reserved. Mikrotik, RouterOS and RouterBOARD are trademarks of Mikrotikls SIA.
Other trademarks and registred trademarks mentioned herein are properties of their respective owners.