Administrator Manual
Adding or Editing HGWs, PAEGWs and PGWs

To add a gateway, select the data tab, press the context properties button of the domain in which insert a gateway and select “ Add gateway”. While, to modify a gateway, always in the data tab, press the context button on the gateway and select “ Edit”. In both cases, a page appears that allows you to manage the contents of the following fields:

General Data

It is important to enter the GPS coordinates (latitude and longitude fields) eventually derived automatically from the address. They are used to display the map of the gateways and for the geo-referenced “ Advertising Campaigns“.

Field Description
ID ID of the record. Auto-assigned Identifier of the record. It can be used to use the API or external integrations.

It is displayed during the editing phase of existing data and not during the insertion of a new record.

Created on Date and time of the creation of the gateway.
Gateway Name Name assigned to the gateway.

Editable only if the user has permission to manage the data of the gateway. 

Gateway MAC Address

If the gateway also acts as an access point and therefore has a WiFi interface, define the MAC address(es) of the WiFi interfaces by separating them with a comma. This is used to recognise the correct domain and gateway for the WiFi connection and radius login. It must be defined in order to obtain connection statistics, the count of connected devices, the duration of the session, and the traffic per access point with its Heatmap.

If not defined, you will not get WiFi statistics.If the radius cannot recognize the gateway from which the login request originates, in the “System Log” it will be reported an ”info“ that also defines the “Calling Station ID” passed in. In this case, define the gateway name with the value corresponding to the “Calling Station ID” or assign the value in this field.

For non-Mirotik gateways, if you want to activate the Syslog, it must be defined.

Network Name

Name of the network displayed in the login App and in the sidebar of the Welcome Portal.

You need to specify it if any virtual gateways have been added.

To offer multiple authentication methods to users, follow these steps:

  • Enter the multilingual title to be displayed for the method represented by this gateway;
  • Add a new domain, parameterising it as needed;
  • Add a new virtual gateway to the previous gateway by entering the following minimum values:
Field Description
Virtual Gateway Type With multiple authentication methods
Network Name Multilingual title to assign to this second authentication method.
Reference Domain Select the new domain just entered.

This configuration will display two options in the sidebar under “Available Networks”, allowing users to choose which network to use.

Convenient cases for using multiple authentication methods include:

  • Schools, where the same infrastructure is used for both teachers and students, but with different authentication and performance methods.
  • Hospitals, cruise ships, hotels, resorts, camp sites, etc. where guests and staff require distinct access methods.
Address Address where the gateway is installed. Used to calculate the GPS coordinates.
ZIP Code ZIP code.
City City where the gateway is installed.
Country Country where the gateway is installed.
Phone Telephone number of the person in charge.
Mobile Phone Mobile number of the person in charge.
Activate Logs

Enables the registration of logs for the gateway. 
To enable this feature, it is necessary that IP address of the connection must be static, i.e. it does not change for each ADSL reconnection of the manager. If it changes, the logs will not be registered because the IP is not recognised.

Possible options are:

  • Disabled: the logs for this gateway are not saved;
  • Enabled: SysLog data are saved in a general file;
  • Enabled with saving in separate file: SysLog data are saved in a separate file so that it can be easily identified.

Editable only if the user has permission to manage the data of the gateway. 

Internet Connection IP Address or DynDNS Name  Defines the IP address or DynDNS name with which the gateway will contact the HSNM. 
Mandatory if: you active the syslog filter in the system settings; if you want to to permit the disconnection of users from the backend from the page “ Connected devices”; if from the frontend of the user profile’s App it is allowed to disconnect the device.

Editable only if the user has permission to manage the data of the gateway.

URL or IP to Access the Management Web URL or IP to access the web management of the gateway

If the backend is in HTTPS and the web management access of the device is in HTTP, it will open a new browser tab. In other cases, it will open a new tab on the HSNM backend.

Hardware Type Hardware type of the gateway.

Warning! Ubiquiti UniFi Controller/Dream Machine does not support or has errors in accounting radius. The data are correct only if the system is able to reach the UniFi Controller (usually with NAT or VPN rules) and compensate directly for deficiencies by enabling the various parameters of the panel “Fields for Gateway Configuration” and under panel “Radius”. If it is not possible, it is recommended to use this type of gateway only for user authentication. The user data rate can not be parameterised by the products but can only be defined in the controller.

Editable only if the user has permission to manage the data of the gateway.

Gateway RouterOS Version RouterOS version.

Visible only if in the “Hardware type” field, you have selected “MikroTik”.

Editable only if the user has permission to manage the data of the gateway.

Uptime Updatime, active time of the gateway.

The field contains a value only if the gateway’s scripts are updated to version 6 and later.

Visible only if in the field “Hardware Type” has been selected MikroTik.

Welcome Portal Template Declares the template to use for this gateway that parameterises the contents and the graphic unit interface of the Welcome Portal or login page. 

If you enable the “Use domain settings” option, it will use the template defined in the domain.

Advertising Defines the type of advertising, derived from “Advertising Campaigns“, that can be displayed to users.
Possible values are:

  • Enabled: enable the inclusion of advertisement:
  • Only for campaign on this gateway: enables the inclusion of advertising only for specific campaigns for this gateway (they must have defined the field gateway).
  • Disabled: does not display advertisement. 
  • Editable only if the user has permission to manage the data of the gateway and if advertising has not been disabled in the domain.

If in the domain, you have defined not to display advertising, this value is not considered in this field.

Surveys, Quizzes or Tests Enables the request for surveys, quizzes or tests.
Possible values are:

  • Use domain definition.
  • Enable, one at a time. Enables the request to fill in the surveys but at maximum one at a time.
  • Enable, all those provided. If the current context provides for more surveys, it requires them all.
  • Disable. No surveys are required.

Editable only if the user has permission to manage the domain data.

Web Management or/and Access to the APIs

It allows you to specify parameters to access the admin interfaced and APIs of specific gateway types (such as MikroTik, Ubiquiti, etc.):

Field Description
URL or IP to Access

URL or IP address to access the gateway configuration (or/and API) via the web, complete with protocol and port if applicable.

The field is required when the hardware type selected is “Ubiquiti UniFi Network Server/Dream Machine”.

E.g. https://GatewayDomainOrIP:GatewayPort.

Username

Username to access the gateway configuration via the APIs.

The field is required when the hardware type selected is “Ubiquiti UniFi Network Server/Dream Machine”.

Password

Password to access the gateway configuration via the APIs.

Geolocation and Tracking

Allows defining the parameters for the gateway’s geolocation and tracking.

Field Description
Latitudine

GPS coordinates of the gateway: latitude.

If left blank, latitude is set based on the address.

GPS coordinates are re-calculated automatically if not defined or if you change the address, city or country. To manually set coordinates, first define the address, city, and country, save, then enter the desired coordinates and save again.

Longitudine GPS coordinates of the getaway: longitude. 

If left blank, longitude is set based on the address.

GPS coordinates are re-calculated automatically if not defined or if you change the address, city or country. To manually set coordinates, first define the address, city, and country, save, then enter the desired coordinates and save again.

Update GPS Coordinates

Enable automatic updating of coordinates based on GPS location.

Visible only with MikroTik hardware types.

Not visible with “PAEGW”-gateway type.

The tracking of the gateway’s GPS coordinates requires a GPS detector compatible and to be connected to the MikroTik. Moreover, on the MikroTik RouterOS there must be installed and enabled the GPS package.

Update IP Address

Enable automatic updating of the IP address from which the GPS coordinates are obtained.

This feature can be used, for example, in buses or taxis where the IP address changes according to the cell to which the gateway is connected, automatically updating the configuration of the Family DNS and accepting requests from the current IP address.

Vehicle

Define the reference vehicle.

To define the vehicle, you need to purchase the “Fleet GPS Tracking & Telemetry” module.

Vehicle Code

It allows you to define the alphanumeric vehicle code (or in some applications called ‘vehicle ID’) associated with the gateway to automatically update GPS coordinates with systems that send data in TAIP (Trimble ASCII Interface Protocol) format with ‘LN’ (Long Navigation Message) messages and complete these messages with the vehicle ID.

Required if you want to display the gateway location in the ‘Route’ app of the Welcome Portal.

This is unnecessary if you use the ‘GPS Tracking and Telemetry’ module and define a value in the ‘Vehicle’ field. In this case, the vehicle ID will be specified in the vehicle itself and not in the gateway.

The vehicle ID is unique for the entire system. Multiple operators cannot have the same vehicle ID.

Activation Scheduler

Using the parameters in this section, you can set the times and the months of the gateway activation.
You can then create systems functioning based on the opening hours, days or months of the companies who offer the services.

Field Description
Timezone

Defines the timezone of the gateway.

The value entered affects the gateway’s activation times and the calculation of the speed modulation of products of guests.
Using this value, it is possible to parameterise international gateways with different time zones than the one set in the system, reseller or manager.

If you select “Use default”, it will consider the Timezone defined in the manager.

Operating Hours Defines the operating hours of the gateway. The gateway will be active during the highlighted hours.Timetables depend on the selected Timezone.
Operating Days Defines the operating days of the gateway. The gateway will be active on the highlighted days.
Operating Months Defines the operating months of the gateway. The gateway will be active during the months that are highlighted, partially active in the months not highlighted or disabled in the months that are not highlighted.
The gateway can be partially active in the non-highlighted months if in the manager or reseller has defined a percentage in the “Reduce the Maximum Number of Users of the Gateway to” field. If the percentage is equal to zero, the system is disabled in the months that are not highlighted.
With these options, it is then possible to define seasons or gateways with seasonal peaks.

Custom App

Field Description
App to Load List of system Apps to upload for this gateway. 
To select the Apps, open the list by clicking in the field and make the selection. To remove an App already selected, click the button of the App already uploaded.
In addition to the Apps specific for the domain (press the button of the domain properties then select “ Custom app”) and for the gateway (press the button of the gateway properties then select “ Custom app”), it uploads also the system Apps defined in this field. To see the system Apps, press the button of the properties on “ System” and select “ Custom app”.

External Authentications

After authentication through social login, you can ask the user, depending on the used social networks, to press “I like”, “Follow” or “Circle”. 
In order to do this, you have to indicate the URL of the page or the ID of the user who can be “liked” or to “follow”. 
For a description on how you can create the pages, please refer to the section “enable social login” in this manual.

The values entered in the gateway are considered more important and specific than those of the domain. Therefore, if the same field is definable in both the gateway and the domain and you have entered the values into both levels, it will consider the ones of the gateway. If you do not enter them into the gateway, it adopts the ones of the domain.

Not visible with “PAEGW”-gateway type.

Field Description
URL or Page ID for “I Follow” Defines the complete URL (without HTTP://) or the Facebook page ID which the user can press “Follow”.

CNA

Warning! If you have chosen the “QR Code & connect. No registration, no password” authentication type the CNA properties are always considered “Disabled”.

If you print cards with the QR Code, to facilitate the access, we suggest you to disable the CNA.

Not visible with “PAEGW”-gateway type.

Field Description
Disable the Apple CNA If enabled, disables the Apple mini browser (Captive Network Assistant) which has several limitations (e.g. it does not display YouTube videos). The user must manually open the browser after having been connected to Wi-Fi.
The option will be active from the next update of “ Walled Garden

Not available if you have selected “Ruckus Access point”, “Ruckus Zone Director” or CISCO Meraki in the hardware type. In this case, you have to manually enter the Walled gardens in the configuration of the appliances. For the list of the Walled gardens to open, please refer to the “ Walled Garden” paragraph.

Disable the Android CNA If enabled, disables the Android mini browser Android (Captive Network Assistant) which has several limitations (e.g. it does not display the YouTube videos). The user must manually open the browser after having been connected to Wi-Fi.
The option will be active from the next update of “ Walled Garden“.

Not available if you have selected “Ruckus Access point”, “Ruckus Zone Director” or CISCO Meraki in the hardware type. In this case, you have to manually enter the Walled gardens in the configuration of the appliances. For the list of the Walled gardens to open, please refer to the “ Walled Garden” paragraph.

Warning! The usage of Android CNA has several limitations: In some versions, it does not display YouTube videos; after the login, the CNA closes automatically and therefore user is no more inside the Welcome Portal and cannot be redirected to a Custom URL; pressing the Facebook button “I Like” on Android 6, it displays a blank white page and closes the Welcome Portal; etc.

Redirect to Browser if CNA Appears

Whether CNA appears, it prompts users to open the standard browser and enter the provided URL.

Full-Screen Advertising

If the “Advertising Module” is active, you can use this panel to specify whether and when to display advertising campaigns in full screen. Full-screen AD campaigns are triggered by defined events and can block user actions for the seconds you specify.

If multiple campaigns are active and the same event is defined multiple times, multiple campaigns will be displayed.

If you define events for full-screen advertising in both the domain and the gateway, the events will accumulate.

These events only take effect if you have defined campaigns with “Full Screen” content type.

Field Description
Active Enable full-screen advertising.
Event The event that triggers the advertising.
Other Event Additional events that can trigger the advertising.

Analytics e Marketing

Field

Description

Enable Google Analytics

Enable the Google Analytics service.

Google Analytics is a service that Google makes available to users to monitor their website or web service. Analytics is a real dashboard that shows statistics and data related to user access.

Google Analytics ID

Enter the Google Analytics ID (Es. UA-NNNNNNNN-NN).

Enable Facebook Pixel

Enable the Facebook Pixel service.

Facebook Pixel ID

Enter the Facebook Pixel ID (i.e. NNNNNNNNNNNNNNN).

Facebook Pixel tracks users’ passage, allowing you to measure actions and create more targeted advertising.

Syslog

Field

Description

Activate Logs

Enable the registration of logs for the gateway.
To enable this feature, it is necessary that the IP address of the connection must be static, i.e. it does not change for each ADSL reconnection of the manager. If it changes, the logs will not be registered because the IP is not recognized.

The possible options are:

  • Disabled: the logs for this gateway are not saved;
  • Enabled: SysLog data are saved in a general file;
  • Enabled with saving in a separate file: SysLog data are saved in a separate file so that it can be easily identified.

Editable only if the system user has permission to manage the data of the gateway.

Server Syslog

Define the server to send the data to.

The possible options are:

  • Internal: Data is processed directly by the device.
  • Remote: If you enable this option you can specify the IP address and the port to send the data to.

Visible only if you have selected “Enabled” or “Enabled with separate recording” in “Activate Logs”.

IP Address

IP address to send the data to.

Visible only if you have selected “Remote” in “Server Syslog”.

Port

Remote port to send data to.

Visible only if you have selected “Remote” in “Server Syslog”.

Options

Field Description
Maximum Number of Users

Maximum number of users connected to the gateway. Once this number is reached, other users will no longer be able to connect unless there are disconnections. To indicate that the number of users is not limited, edit a zero value.

It is used to create a multi-tenant system.

If in the reseller and/or in the manager, you have specified a maximum value of users, then the minimum value in this field is equal to five.

The maximum value that you can edit depends: on the “Maximum Number of Users per Gateway” defined in the reseller and/or in the manager, on the concurrent users defined in the “Maximum Number of Users” in the manager or reseller and on how many gateways you have already inserted.

To not stress the system, the count of the current number of connected users is not done at every access to the Welcome Portal but every minute. In some special cases and on systems with lots of users, it may happen that the maximum number of defined users is exceeded.

Editable only if the user has permissions to manage the data of the gateway.

Maximum Number of Views per minute

The sum of the maximum number of views per minute, you need to enter in the manager’s gateways cannot exceed the value defined in the manager.
A value of zero indicates that no limit has been set.

It is used to create a multi-tenant system. It allows limiting the access to the Welcome Portal. When several devices try to view the Welcome Portal in the same minute and their number exceeds the defined value, the user will see a message that the system is busy and to wait for X seconds.

Editable only if the user has permission to administrate the reseller’s data.

Maximum Number of Source IPs

The maximum number of source IPs from which the NAS authentication requests arrive. 

Warning! A value greater than one consumes additional licenses. As a matter of fact, if you define three, it means you insert three gateways.

If the number of IPs making requests is higher than the number indicated, the gateway will be automatically blocked, and the PPPoE routers will no longer be able to authenticate.

For PPPoE gateways (NAS) of Mikrotik type, the maximum number of IPs from which requests can be received is set to three.

Available only for PPPoE domains with hardware type “Other” and if the user has permission to manage the data of the gateway.

Enable Notification

Enables sending notifications for gateway monitoring.

Available only for MikroTik and Cradlepoint gateways.

Verify Internet Connection

This option, typically set to ‘Yes’, activates the verification of internet connectivity when users log in.

If not activated, the login procedure is faster but the user is not notified when the internet becomes available

Show Wizard

Show a notification on the dashboard inviting the user to run the initial setup wizard to configure the gateway.

The value will be automatically disabled when the wizard runs and completes.

Gateway Blocked If enabled, it blocks the logins to all users of the gateway.

Available only if the user has permissions to manage the data of the gateway.

Notes for the Gateway Enter possible notes for the gateway.

Available only if the user has permission to manage the data of the gateway.

Fields for Configuring the Gateway

After you have entered and saved this information by pressing the button on the gateway properties in sidebar and choosing “ Download Gateway Config Files“, you can download a .zip file containing all the files necessary to configure a gateway and compatible based on MikroTik RouterOS.

This entire section is available only if the user has the permissions to manage the data of the gateway.

Visible only if the type of gateway is MikroTik.

Authentication Options

Visible only if the type of gateway is MikroTik and not “PAEGW”.

Field Description
Authentication via MAC Address If enabled, it is possible to create users with a username and password equal to the MAC address of the device. This avoids the Welcome Portal and consequently the manual registration and authentication phase.

Enable this option only if really necessary otherwise an authentication request will be sent to the Wifi connection of any device.

Wireless

Field Description
Enable the WiFi Interface

If enabled, you declare that the gateway provides WiFi access. For MikroTik, it allows you to generate the configuration script inclusive of the settings for wireless (Wlan1)If enabled, the commands for configuring the wireless card (WLAN1) will be added to the configuration script of the gateway and the hotspot service will be configured on this interface.
If disabled, no wireless card will be configured and the hotspot service will be configured on the Ether2.

SSID Enter the SSID of the wireless network that you want to be displayed by the users who connect to this gateway.

It appears only if “Enable the WiFi Interface” is enabled.

Radius

Field Description
Force Disconnections Not editable and always enabled to avoid having open connections already expired. Connections not receiving updates from the gateway during the double of the time defined in the ‘Interim Update’ of the Product Policy are automatically closed.
Send Disconnection Requests to the Gateway In addition to forcing disconnections, it also sends a radius request for disconnection to the gateway. Some types of gateways (i.e. Ubiquiti) may not send the stop to the radius and consider the device always active. If enabled, the gateway must be reachable via the port indicated with UDP protocol.

For Ubiquiti UniFi Controller/Dream Machine, we recommend you to enable this option. For MikroTik it is not available.

Port for Disconnection Requests Port used by the gateway to accept the disconnection requests. Port 3799 is commonly used but it depends on the type of gateway.

For Ubiquiti UniFi Controller/Dream Machine, we recommend you enable this option. For MikroTik it is not available.

Verify User Consumption If the gateway does not support all the necessary radius attributes and the device is able to send the disconnection requests, the system periodically verifies the consumption of the connected users and in case they reach the time/traffic limits or at the expiration, it disconnects the user
Wan.

For Ubiquiti UniFi Controller/Dream Machine, we recommend you enable this option. For MikroTik it is not available.

Secret for Radius

Password to be used when configuring the radius.
For MikroTik-type gateways, the password is automatically added to the file you can download for the automatic configuration or when using the Upload Configuration option.

Radius Ip Addresses

IP addresses to use for Radius configuration.
IP addresses displayed:

  • The IP addresses defined in the network and in the “Round robin hosts”.
  • IP addresses derived from the resolution of the domain name assigned to HSNM and the domains of the “round robin hosts”. They can be useful if the gateway is not networked with HSNM.

WAN

Visible only if the type of gateway is MikroTik.

Field

Description

WAN Configuration Type

Allows choosing how to configure the WAN.
The possible options are:

  • Enter Parameters. The user needs to complete the parameters displayed as to generate the configuration automatically;
  • Manual Configuration of the Gateway. It does not generate the configuration of the WAN part, leaving complete autonomy on configuring directly the gateway. You have to define the route and the NAT or Masquerading rule. It is useful to add the service on pre-existing and already configured MikroTik-type gateways.

If you choose “Manual Configuration of the Gateway”, all subsequent parameters of this section will be hidden.

Same Network of the Appliance

Enable it if the gateway is on the same network (physical and IP) of HSNM.

If enabled, in the configuration script of the gateway, it will add the commands to define, in the DNS configuration, a static host that associates the domain name, defined in “System Setting”, to the IP address (generally private) of HSNM.

Warning! If not enabled and the gateway is on the same network in NAT with the platform, the gateway may fail to contact the HSNM.

Addressing Mode

Type of network addressing
The possible values are:

  • Static IP or DHCP;
  • PPPoE Client;
  • USB Modem;
  • LTE.

“PPPoE Client”, “USB Modem” and LTE are not available for domains with PPPoE authentication type.

Interface

Select the WAN interface.
Possible values are: 

  • Ether1; 
  • Ether2;
  • Ether3;
  • Ether4;
  • Ether5;
  • Ether6;
  • Ether7;
  • Ether8;
  • Ether9;
  • Ether10;
  • Ether11;
  • Ether12;
  • WLAN2;

“WLAN2”is not available for domains with “PPPoE” as authentication type.

Some (EtherX) interfaces are not in the list if they had been already used in the Hotspot Interfaces of the virtual gateways.

Use a VLAN

Enables or disables the use of a VLAN for the WAN interface.

Visible only if you have selected “Ether1” or “WLAN 2” in the interface type.

VLAN ID

ID for the VLAN. It allows numeric values between 2 and 4095.

Visible only if “Use a VLAN” is enabled.

Visible only if you have selected “Ether1” or “WLAN 2” in the interface type and you have enabled “Use a VLAN”.

Use DHCP client for the WAN

Enables or disables the DHCP client for the WAN interface. 

If enabled, in the configuration script of the gateway it will add the commands to define a DHCP client in the network interface of the hotspot service that will be connected to the corporate network of the manager. 

If disabled, it will display the fields for the definition of IP address, subnet mask and gateway. These fields will be automatically added to the commands of the configuration script to define the IP address of the network interface of the gateway that will be connected to corporate network of the manager.

Visible only if you have selected “Ether1” or “WLAN 2” in the interface type.

WAN IP Address

IP address that you want to assign to the WAN interface.

Visible only if “Use DHCP Client for the WAN” is not enabled and if you have selected “Ether1” or “WLAN 2” in the interface type.

WAN Network Mask

Network mask that you want to assign to the WAN interface.

Visible only if “Use DHCP Client for the WAN” is not enabled and if you have selected “Ether1” or “WLAN 2” in the interface type.

WAN Gateway

IP address of the gateway for the WAN interface. It should coincide with the private IP address assigned to the router of the internet connection of the manager.

Visible only if “Use DHCP Client for the WAN” is enabled and if you have selected “Ether1” or “WLAN 2” in the interface type.

Primary DNS

Primary DNS used by the gateway for the WAN interface.

Visible only if “Use DHCP client for WAN” is not enabled and if “Static IP or DHCP” has been selected in the type of network addressing.

Secondary DNS

Secondary DNS used by the gateway for the WAN interface.

Visible only if “Use DHCP client for WAN” is not enabled, “Static IP or DHCP” has been selected as type of network addressing, and the Family DNS is not active.

Allow Remote Requests to DNS

If enabled, use the gateway as a DNS server.

Visible only if “Use DHCP client for WAN” is not enabled, “Static IP or DHCP” has been selected as type of network addressing, and the Family DNS is not active.

PPPoE Client Username

PPPoE client’s username.

Visible only if you have selected “PPPoE Client” as type of network addressing.

PPPoE Client Password

PPPoE client’s password.

Visible only if in the type of network addressing you have selected “PPPoE Client”.

Dial on Demand PPPoE Client

If enabled, it connects to the PPPoE server only when internet traffic is generated.

Visible only if in the type of network addressing you have selected “PPPoE Client”.

MTU PPPoE Client

Defines MTU of the PPPoE Client’s interface. If it is defined to zero the MTU will not be set.

Visible only if in the type of network addressing you have selected “PPPoE Client”.

APN

Enter the APN provided by the operator of the SIM card.

Visible only if you have selected “USB Modem or LTE in the Addressing Mode.

Authentication

Enable SIM card authentication.

Activation allows you to view the “Usermane” and “Password” fields.

With some operators it is not necessary to enable it.

Visible only if you have selected “USB Modem” or “LTE” in the Addressing Mode.

Username

Enter the username provided by the operator of the SIM card. 

Visible only if you have selected “PPPoE Client”, “USB Modem”or “LTE” in the Addressing Mode.

Password

Enter the password provided by the operator of the SIM card. 

Visible only if you have selected “PPPoE Client”, “USB Modem” or “LTE” in the Addressing Mode.

Modem Initialization AT Command

Enter the AT command to use to initialise the modem.

Visible only if you have selected “USB Modem in the Addressing Mode.

Dial AT Command

Enter the AT command to use to make the call. 

Generally ATDT.

Visible only if you have selected “USB Modem in the Addressing Mode.

USB Port

Select the USB port of the MikroTik gateway where the USB modem is connected.

Visible only if you have selected “USB Modem in the Addressing Mode.

Dial Out Phone Number

Enter the phone number provided by the SIM card operator in order to dial out.

Visible only if you have selected “USB Modem in the Addressing Mode.

Guest Interfaces

Visible only if the type of gateway is MikroTik.

Field Description
SSL Certificate Select thwe SSL certificate to use.

The list shows the “Non-private” certificates entered at the system, reseller and manager level.

Editing this field or changing the certificate to “SSL Certificate” involves the automatic installation or update of the certificate installed in the gateways. When the certificate expires, then you simply have to change the certificate to “SSL Certificates”.

For the “PAEGW” gateway types it can be defined for any Hotspot virtual gateway types.

Domain Name (Hotspot DNS Name) Domain name used by the Hotspot service to load the login page.

It must correspond to the domain of the certificate selected in the “SSL Certificate” field.

If the domain name you edited is not compatible with the certificate, the system will automatically suggest a valid name.

Not visible for “PAEGW” gateway types.

Add EtherX to the Guest Bridge

If activated, it adds the gateway ethernet X to the bridge in order to activate the (Hotspot, WPA Enterprise or PPPoE) service even on the ethernet. To activate only if the gateway that you are configuring, has 2 or more network cards.

If you are using the ethernet in the WAN, it will not appear in the list.

Guest Network

Visible only if the type of gateway is MikroTik.

Field Description
Keep-Alive timeout Defines the Keep-Alive timeout to check the accessibility of the client. If clients are no more reachable, for example for the loss of the WiFi connection, after the defined time they are disconnected automatically.
For example, if you want to keep a user logged for any length of time without forcing him to relog even when he switches off his device, you have to define a sufficiently high time.

The value is dynamically updated every five minutes in the gateways.

Warning, disconnection can be caused also by the Timeout Idle and the Timeout Session defined in the product policy.

If “Not Defined”, the client remains connected even if, for example, disconnects from the WiFi network or the gateway no longer reaches the HSNM. Any disconnection will be caused by the values defined in the policy of the products (“Session Timeout” and “Timeout for Idle”) or in the products (time or/and traffic credit or expiration).

IP Address IP address to assign to the interface (WLAN1 or Ether2, depending if you have enabled the “Enable the WiFi Interface” field) on which you will activate the hotspot service.
Network Mask Enter the network mask that you want to assign to the interface (WLAN1 or Ether2 depending on if you have enabled the “Enable the WiFi Interface” field) on which you will activate the hotspot service.
DNS IP Addresses Enter the IP addresses of the DNS servers (separated by commas) that you want to assign to the gateway. It is very important that the inserted DNS is operating, otherwise, the users accessing the service may have problems viewing pages.
First IP Address for the DHCP Address Pool Enter the first IP address of the pool of addresses that will be assigned by the DHCP server that is configured on the interface where the hotspot service will be activated on. 
The IP addresses of the pool will be assigned to the devices that connect.
Last IP Address for the DHCP Address Pool Enter the last IP address of the pool of addresses that will be assigned by the DHCP server that is configured on the interface where the hotspot service will be activated on.
The IP addresses of the pool will be assigned to the devices that connect.
DHCP Lease Time Specify the lease time, expressed in hours, for the IP address assignment of the connected devices

Warning! Set a value equal to or greater than the maximum time for inactivity is defined in the product policy used in the domain. 

Use a VLAN Enables or disables using a VLAN for the bridge interface of the hotspot.
VLAN ID ID of the VLAN. The numeric values allowed are from 2 to 4095

Visible only if “Use a VLAN” is enabled.

GPS

Visible only if the gateway type is MikroTik and not “PAEGW”.

Field Description
GPS Available Activate if the gateway supports GPS.
GPS Type GPS type. If you use the integrated GPS (for example in the LtAP mini 4G Kit, LtAP mini, LtAP mini LTE kit, LtAP mini LTE kit-US models) it is advisable to connect an external GPS antenna.
The possible options are:
USB;
Integrated.
USB Port for the GPS Antenna USB port where the GPS antenna is connected.

Visible only if “USB” has been selected on “GPS type”.

VPN

Visible only if the gateway type is MikroTik.

Field Description
Use VPN

Enable or disable the VPN configuration in the gateway. It can be useful if you want that, the hotspots managed by HSNM are on the same IP network of HSNM so you can e.g. activate the sending of LOGs also for hotspots connected to xDSL connection with dynamic IP. 

Available options are:

  • No: VPN not activated
  • Yes, use PPTP: Set up a PPTP VPN.
  • Yes, use SSTP: Set up a SSTP VPN.
  • Yes, use L2TP: Set up a L2TP VPN.
Server Name The host name or IP address of the VPN server to which the gateway will connect to establish a VPN.

Displayed only if “Use VPN” is enabled.

Username The username for the VPN connection.

Displayed only if “Use VPN” is enabled.

Password The password for the VPN connection.

Displayed only if “Use VPN” is enabled.

Secret

The secret for the VPN connection (optional). 

It is displayed only if “Use VPN” is enabled with “Yes, use L2TP”

Scheduler

Visible only if the gateway type is MikroTik.

Field Description
Minutes for the Update

Defines the auto-update interval (in minutes) of the “ Walled Garden” (free URL) and of the IPs or MAC address to bypass or block for the gateway.

The minimum value is 5 minutes.

Not visible for “PAEGW”-type gateways.

Monitoring Interval Defines the interval (in minutes) for monitoring the status of the gateway and the access point.

MikroTik Router OS

Visible only if the gateway type is MikroTik.

Field Description
Custom Commands Custom commands in addition to the standard ones to be included in the script generated for configuring the gateway.

Options

Visible only if the gateway type is MikroTik.

Field Description
Upgrade Script If enabled, it upgrades the gateway scripts. After the upgrade the check is disabled in order to perform the upgrade once

Reboot the Gateway

If enabled, this will reboot the gateway. Possible values are:

  • No
  • Yes, only once
  • Yes, always if the number of ‘Simple Queues’ exceeds the number of ‘Hotspot Active Users’
Warning: The reboot option, which allows a reboot if the number of “Simple Queues” exceeds the number of Hotspot Active Users, has been introduced to mitigate a RouterOS bug that remains unresolved in version 7.16.
Upgrade Config If enabled, updates, reconfigures and automatically reboots the gateway (this feature is only available for the gateway configured from version 2.0.137 and later ones). 
After the update, the check is disabled in order to perform the update only once. 

Warning! If the data entered are incorrect, the gateway may not be any more accessible!

Import Users If enabled, imports users from “MikroTik HotSpot users” generated by printers or external tools.

Command Bar

In the upper-righ corner of the command bar, if you are editing a gateway, the following buttons are displayed:

Button Description

Show Gateway Setup Wizard

By clicking the button, you close the current page and show the setup wizard for configuring the gateway.

Upload Configuration It allows you to perform the automatic configuration of the MikroTik gateway type.
For further information, please refer to the “Upload MikroTik Configuration” paragraph described below.

Visible only if you have chosen MikroTik as hardware type.

Upload MikroTik Configuration

Thanks to this feature it is possible to configure in a simple and automatic way the MikroTik gateway type.
When pressing the “Upload Configuration” button in the command bar, the following fields will be displayed:

Field Description
IP Address Assigned to the Gateway

IP address assigned to the gateway. In order to upload the configuration, it must be reachable from the system. If you have not assigned it yet, log in to the router using WinBox and assign one to the IP/Addresses session.

If you wish to use a specific port (the default one is 8728), define it after the IP address by separating it from the colon in the form “IP:Port”.

Username to Log In Username to log in the MikroTik gateway.
Password to Log In Password to log in the MikroTik gateway. On new devices, the password is empty

By pressing the “Run” button, the gateway configuration will be performed.

At the end of the operation, a confirmation message or any will appear. If the upload has been successfully performed, the gateway will be automatically restarted.