RadiusNest › Guides

MikroTik hotspot session-timeout, idle-timeout and keepalive-timeout

Last updated: 2 October 2026

Three timers decide when a hotspot session ends by itself. Set them too short and customers are asked to log in again all day. Leave them off and people who left hours ago still fill the active list.

The three timers

SettingEnds the session whenDefault in a user profile
session-timeoutthe session has lasted this long, busy or notnot set
idle-timeoutno traffic from the device has passed through the router for this longnone
keepalive-timeoutthe device has not answered the router's checks for this long, so it is switched off or out of range2m

The difference between the last two: an idle device is still there but silent; a device that fails keepalive is gone.

Set them in the user profile

/ip hotspot user profile print
/ip hotspot user profile set 5M session-timeout=1d idle-timeout=15m keepalive-timeout=5m

To switch a timer off, set it to none (for session-timeout, 0s):

/ip hotspot user profile set 5M idle-timeout=none session-timeout=0s

New values apply to sessions that start after the change.

The second set, on the hotspot server

The hotspot server itself has timers with the same names. Those apply to devices that are connected but have not logged in, and they clear the host list:

/ip hotspot print
/ip hotspot set hotspot1 idle-timeout=5m keepalive-timeout=none

Do not confuse the two. Changing the server's timers does not log paying users out.

Session timeout is not a time package

session-timeout limits one session; the user can log straight back in. To sell an amount of time, use limit-uptime on the user, which counts all sessions together:

/ip hotspot user set [find name=guest1] limit-uptime=5h

Neither is a calendar expiry. For that see hotspot user expiry.

See the timers at work

/ip hotspot active print detail

Each session shows uptime, idle-time and, when a limit applies, session-time-left. Compare idle-time with your idle-timeout to see who is about to be logged out.

Users are logged out too often

  • Idle timeout too short. A phone with its screen off sends little. With idle-timeout=1m it is logged out in a pocket. Use 10 to 30 minutes.
  • Keepalive too short. Phones put Wi-Fi to sleep and miss the router's checks. Use 5 minutes or more instead of the default 2.
  • Weak signal. A device at the edge of coverage drops off and fails keepalive. Timers will not fix that.
  • No login cookie. With cookies on, a customer who was timed out is logged in again without typing. See hotspot login cookies.
  • The package really ran out. Check limit-uptime and limit-bytes-total on the user, and the log.
/log print where topics~"hotspot"

Users stay listed after they left

  • Both timers are off. With idle-timeout=none and keepalive-timeout=none nothing ever ends the session. Set at least one.
  • Uptime keeps counting. A stale session uses up the customer's limit-uptime while they are not there, and blocks their next login if shared-users is 1.

Remove a stale session by hand:

/ip hotspot active remove [find user="guest1"]

Values that work for most sites

Siteidle-timeoutkeepalive-timeout
Café, short visits, time sold by the hour5m to 10m2m to 5m
Hostel, flats, long stays30m to 1h5m to 10m

Where you sell connected time, shorter timers are fairer to the customer, because idle time stops being charged sooner.

With RADIUS

A RADIUS reply can carry Session-Timeout and Idle-Timeout for the session, and those take the place of the profile's values. See RADIUS attributes.

Where RadiusNest fits

With RadiusNest the time a customer has left comes from their package: time, end date and time-of-day hours are applied at each login, and the customer is disconnected when the package ends. The keepalive timer stays a router setting, and the advice above still applies to it.

Start the free trial See pricing

Questions and answers

What is the difference between idle-timeout and keepalive-timeout?

Idle timeout ends a session when the device is present but passes no traffic. Keepalive timeout ends it when the device no longer answers the router at all.

Does session-timeout stop a user from logging in again?

No. It ends the current session only. Use limit-uptime on the user to cap total time.

Why does the active list show users who left hours ago?

Idle and keepalive timeouts are both off in the user profile, so the router has no reason to end the session. Set at least one of them.

Related guides

Start the free trial See pricing