RadiusNest › Guides

How to block tethering and re-sharing on a MikroTik hotspot

Last updated: 2 October 2026

A customer buys one login, then turns on the phone's own hotspot and shares it with five friends. The router sees one device. The TTL method blocks most of this with one rule, and it is worth knowing exactly where it stops working.

Why the router cannot see it

A phone that shares its connection hides the devices behind it, the same way your router hides your network from the internet. All their traffic reaches you from the phone's single address and MAC address. Counting devices or logins does not catch it, because there is only one.

What TTL is

Every packet carries a number called TTL that drops by one at each router it passes. A packet with TTL 1 can be received, but not passed on. A phone that shares its connection is acting as a router, so it must lower the TTL before handing a packet to the device behind it.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

The rule: send packets to customers with TTL 1

/ip firewall mangle add chain=postrouting out-interface=bridge-hotspot action=change-ttl new-ttl=set:1 passthrough=yes comment="no re-sharing"

Replace bridge-hotspot with your hotspot interface. Every packet going out to a customer now arrives with TTL 1. The customer's own phone uses it normally. When that phone tries to pass it on to a tethered laptop, the TTL reaches zero and the packet is dropped. The devices behind the phone connect to its Wi-Fi but nothing loads.

FastTrack must be off

Traffic handled by FastTrack skips mangle rules, so the TTL is not changed for it. If your firewall has a FastTrack rule, disable it:

/ip firewall filter disable [find action=fasttrack-connection]

A second check: drop what already passed through a device

Phones and most computers send their own packets with TTL 64 or 128. Packets that came through a sharing phone arrive one lower. Mark those on the way in and drop them:

/ip firewall mangle add chain=prerouting in-interface=bridge-hotspot ttl=equal:63 action=mark-packet new-packet-mark=reshared passthrough=yes
/ip firewall mangle add chain=prerouting in-interface=bridge-hotspot ttl=equal:127 action=mark-packet new-packet-mark=reshared passthrough=yes
/ip firewall filter add chain=forward packet-mark=reshared action=drop comment="re-shared traffic"

Put the filter rule above the rule that accepts established connections, or it never sees the packets. Use this as an addition to the first rule, not instead of it.

Test it

  1. Log a phone in to the hotspot and check that it browses normally.
  2. Turn on that phone's own hotspot and connect a laptop to it.
  3. The laptop should get Wi-Fi but no pages.
/ip firewall mangle print stats
/ip firewall filter print stats where comment="re-shared traffic"

The limits, honestly

  • It also blocks honest routers. A customer who plugs in their own Wi-Fi router is treated the same as a re-seller, because their router lowers the TTL too. If you sell to homes that use their own router, do not use this rule on that network; PPPoE suits them better.
  • It can be undone. A router or a modified phone can be set to rewrite the TTL of packets it passes on. Anyone who searches for it will find how. The method stops casual sharing, not a determined person.
  • Proxy and tunnel apps on the phone pass traffic on as the phone's own, so TTL does not show it.
  • The second check depends on usual TTL values. A device that starts from another value is not matched, and in rare cases a device you did not mean to block is. Watch the counters after turning it on.
  • These rules cover IPv4. If you hand out IPv6 to customers, they do not apply to it.

One device per login

TTL deals with sharing behind a device. Passing the password to another phone is a different matter, and that one is fully under your control:

/ip hotspot user profile set 5M shared-users=1

See shared users. You can also tie a user to one MAC address, with the caveat that phones use private addresses:

/ip hotspot user set [find name=guest1] mac-address=AA:BB:CC:DD:EE:FF

The part rules cannot do

Sharing pays when a fast, unlimited login is cheap. A data allowance and a sensible speed remove most of the reason: what the friends use comes off the buyer's own package. See hotspot data limits and user profiles.

Where RadiusNest fits

RadiusNest does not look inside traffic and does not replace the TTL rule; that stays on your router. What it does is the login side: each package has a "devices at the same time" number that is checked centrally across your routers, a data allowance that everything behind the customer's device uses up, and a live list of who is online where you can disconnect a session.

Start the free trial See pricing

Questions and answers

Does the TTL rule slow the hotspot down?

No. It changes one field in each packet. It does need FastTrack to be off, which raises processor load on busy routers.

Can customers get around the TTL block?

Yes, with a router or modified phone that rewrites TTL, or with a proxy app. It stops ordinary phone tethering, which is most cases.

Will the TTL rule break normal browsing?

Not for devices connected directly to your hotspot. It breaks internet for anything connected behind another router or a sharing phone, which is the purpose.

Related guides

Start the free trial See pricing