RadiusNest › Guides

How to disconnect a MikroTik hotspot user and keep them out

Last updated: 2 October 2026

Removing a hotspot user from the active list takes one command. Keeping them off takes two or three more, because the router remembers the device in other places. This is the full sequence.

Find the session

/ip hotspot active print
/ip hotspot active print where user="ali"

Note the username and the MAC address. One username can have several sessions if its profile allows more than one device.

1. End the session

/ip hotspot active remove [find user="ali"]

By device instead of by name:

/ip hotspot active remove [find mac-address=AA:BB:CC:DD:EE:FF]

In Winbox: IP → Hotspot → Active, select the line and press the minus button. The customer is offline at once and sees the login page on the next request.

Why they come straight back

Ending the session does not take away the right to log in. One of these lets the device in again within seconds:

  • A login cookie. The browser or the router still holds one. See hotspot cookies.
  • MAC login. The device is logged in by its address as soon as it is seen. See MAC authentication.
  • The user still works. The customer simply types the password again, or the phone does it for them.
  • A bypass. A device with a bypassed IP binding was never a session in the first place.
/ip hotspot cookie remove [find user="ali"]

Now the device has to log in by hand. If the kick was only to clear a stuck session or to make a new speed apply, stop here: the customer logs in again and gets the current settings.

3. Stop the user logging in

/ip hotspot user set [find name="ali"] disabled=yes

Disable before you remove the session, or the device may log in again in between. To let them back later:

/ip hotspot user set [find name="ali"] disabled=no

4. Clear the host entry

The host list holds every device the hotspot has seen, logged in or not. Removing the entry makes the router start fresh with that device, which helps when a device is stuck with an old address:

/ip hotspot host remove [find mac-address=AA:BB:CC:DD:EE:FF]

The device reappears as a new host as soon as it sends anything.

Keep a device off completely

To refuse a device whatever username it tries, block its MAC address. It will not even see the login page:

/ip hotspot ip-binding add mac-address=AA:BB:CC:DD:EE:FF type=blocked comment="blocked"

A phone can come back with a different private MAC address, so this stops a device, not a person. More in IP binding.

Everything for one user in one go

/ip hotspot user set [find name="ali"] disabled=yes
/ip hotspot cookie remove [find user="ali"]
/ip hotspot active remove [find user="ali"]

By script

A named script that kicks one user, with the name in one place:

/system script add name=kick-user source={
  :local u "ali"
  /ip hotspot cookie remove [find user=$u]
  /ip hotspot active remove [find user=$u]
  :log info ("hotspot: kicked " . $u)
}
/system script run kick-user

Log everyone out, for example before maintenance:

/ip hotspot active remove [find]

To do that every night, put the line in a scheduler; see scheduler and scripts. Customers with a valid cookie are back the moment they use the internet, which is usually what you want.

When users are checked by RADIUS

A RADIUS user is not in the router's user list, so there is nothing to disable on the router. Removing the session and the cookie works the same way, but the lasting block has to be made on the server, which then refuses the next login. For the server to end a session by itself, the router must accept its requests:

/radius incoming set accept=yes port=3799

See RADIUS attributes.

Where RadiusNest fits

RadiusNest has a live list of who is online on all your connected routers, with a disconnect button on each session, so staff do not need the router password to kick someone. A customer whose package has ended is disconnected automatically and refused at the next login. A cookie on the router does not let them back in, because every login is checked again.

Start the free trial See pricing

Questions and answers

Why does a hotspot user reconnect right after I remove them?

The device still has a login cookie or is logged in by MAC address, or the user is still enabled. Remove the cookie and disable the user as well as the session.

How do I disconnect all hotspot users at once?

Run /ip hotspot active remove [find]. Everyone is logged out; those with a valid cookie are logged in again on their next request.

Does removing a user from the active list delete the account?

No. It only ends the current session. The user, its password and its limits stay as they were.

Related guides

Start the free trial See pricing