I wonder how Mikrotik Hotspot distinguish sessions after user is logged in? I mean when a user login to hotspot how mikrotik knows traffic is coming from his device?
I can’t think of anything other than MAC address matching as there is no cookie at network layer. If it’s the case, as MAC addresses are easily sniffable in a wireless network and easily changeable, Hotspot wont be so secure after all because one can impersonate someone else identity?