Need help with hotspot configurations

Hello

I'm having a problem with the hotspot.

Despite all the configurations I've made on my antennas, the custom captive portal only appears intermittently for clients. How can I resolve this issue?

What's the first thing you would do if a person asked you the same question?

I'd say he probably forgot a confirmation; I've checked it countless times, which is why I'm here in case someone else has had this problem so we can try and exchange information.

But I don't see any information in your post, absolutely nothing.

So, if they pointed out the same thing to you, what would be your basis for a solution?

That all the customer's devices are broken?
And why would this assumption be wrong, given that there's no concrete basis to the contrary?

Bonjour voici la configuration de mon routeur

2026-08-21 09:06:53 by RouterOS 7.22.2

software id = Q7RG-SCHD

model = CCR1009-7G-1C-1S+

serial number = E3200E9FE928

/interface bridge
add name=HOTSPOT port-cost-mode=short
add name=LAN port-cost-mode=short
add name=WAN port-cost-mode=short
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] http-cookie-lifetime=6h
add dns-name=ob-wifi.free hotspot-address=192.168.12.254
http-cookie-lifetime=1h login-by=mac,cookie,http-chap,http-pap,mac-cookie
mac-auth-mode=mac-as-username-and-password name=hsprof1
radius-default-domain=ob-wifi.free use-radius=yes
/ip hotspot user profile
set [ find default=yes ] mac-cookie-timeout=4w2d open-status-page=http-login
session-timeout=4w2d transparent-proxy=yes
/ip pool
add name=hs-pool-11 ranges=192.168.12.1-192.168.12.253
/ip dhcp-server
add address-pool=hs-pool-11 interface=HOTSPOT name=dhcp1
/port
set 0 baud-rate=auto
set 1 baud-rate=auto
/interface bridge port
add bridge=WAN ingress-filtering=no interface=ether1 internal-path-cost=10
path-cost=10
add bridge=HOTSPOT ingress-filtering=no interface=ether3 internal-path-cost=
10 path-cost=10
add bridge=HOTSPOT ingress-filtering=no interface=ether4 internal-path-cost=
10 path-cost=10
add bridge=HOTSPOT ingress-filtering=no interface=ether5 internal-path-cost=
10 path-cost=10
add bridge=HOTSPOT ingress-filtering=no interface=ether6 internal-path-cost=
10 path-cost=10
add bridge=HOTSPOT ingress-filtering=no interface=ether7 internal-path-cost=
10 path-cost=10
add bridge=LAN ingress-filtering=no interface=ether2 internal-path-cost=10
path-cost=10
/ip firewall connection tracking
set udp-timeout=10s
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/ip settings
set max-neighbor-entries=8192
/ipv6 settings
set disable-ipv6=yes max-neighbor-entries=8192 soft-max-neighbor-entries=8191
/interface ovpn-server server
add auth=sha1,md5 mac-address=FE:A4:DB:32:98:5D name=ovpn-server1
/ip address
add address=192.168.10.254/24 interface=LAN network=192.168.10.0
add address=192.168.12.254/24 interface=HOTSPOT network=192.168.12.0
/ip dhcp-client
add interface=WAN name=client1
/ip dhcp-server network
add address=192.168.12.0/24 comment="hotspot network" gateway=192.168.12.254
/ip firewall filter
add action=passthrough chain=unused-hs-chain comment=
"place hotspot rules here" disabled=yes
/ip firewall nat
add action=passthrough chain=unused-hs-chain comment=
"place hotspot rules here" disabled=yes
add action=masquerade chain=srcnat comment="masquerade hotspot network"
src-address=192.168.12.0/24
/ip hotspot
add address-pool=hs-pool-11 disabled=no idle-timeout=none interface=HOTSPOT
keepalive-timeout=2m login-timeout=1m name=hotspot1 profile=hsprof1
/ip hotspot user
add name=admin
/ip hotspot walled-garden
add comment="place hotspot rules here" disabled=yes
/ip hotspot walled-garden ip
add action=accept disabled=no dst-address=161.97.106.192 !dst-address-list
!dst-port !protocol !src-address !src-address-list
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/radius
add address=161.97.106.192 service=login,hotspot timeout=7s
/routing bfd configuration
add disabled=no interfaces=all min-rx=200ms min-tx=200ms multiplier=5
/system clock
set time-zone-name=Africa/Douala
/system identity
set name="MikroTik Gros Blanc"
/system routerboard settings
set auto-upgrade=yes
/system scheduler
add name=schedule1 on-event="/ip hotspot user profile set pekos \\r
\n idle-timeout=0 \\r
\n keepalive-timeout=2m \\r
\n session-timeout=30d \\r
\n mac-cookie-timeout=30d\r
\n" policy=
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon
start-date=2026-08-17 start-time=20:56:40

mon problème est que les clients connectés par faisceau hertzien de temps en temps se retrouvent obligé de se reconnecter via le portail captif

merci pour l'intérêt que vous portez a ma préoccupation

I don't see anything strange about it, maybe some colleagues...

I think it depends on the fact that the system relies too much on MAC authentication,
since the devices use a different MAC address at each access point, and they change it over time.
Disconnections are commonplace in this case.


Je n'y vois rien d'étrange, peut-être que certains collègues…

Je pense que cela vient du fait que le système repose trop sur l'authentification MAC, car les appareils utilisent une adresse MAC différente à chaque point d'accès, et cette adresse change régulièrement.
Les déconnexions sont fréquentes dans ce cas.

Merci vraiment pour l'intérêt.

S'il y a une proposition stp il ne faut pas hésiter je serai ravis au cas où.
Est si un collègue peut nous apporter son expertise ce serait idéal.

Nous avons essayé de copier le modèle de payement des opérateur réseau.