MikroTik hotspot session-timeout, idle-timeout and keepalive-timeout
Last updated: 2 October 2026
Three timers decide when a hotspot session ends by itself. Set them too short and customers are asked to log in again all day. Leave them off and people who left hours ago still fill the active list.
The three timers
| Setting | Ends the session when | Default in a user profile |
|---|---|---|
session-timeout | the session has lasted this long, busy or not | not set |
idle-timeout | no traffic from the device has passed through the router for this long | none |
keepalive-timeout | the device has not answered the router's checks for this long, so it is switched off or out of range | 2m |
The difference between the last two: an idle device is still there but silent; a device that fails keepalive is gone.
Set them in the user profile
/ip hotspot user profile print
/ip hotspot user profile set 5M session-timeout=1d idle-timeout=15m keepalive-timeout=5mTo switch a timer off, set it to none (for session-timeout, 0s):
/ip hotspot user profile set 5M idle-timeout=none session-timeout=0sNew values apply to sessions that start after the change.
The second set, on the hotspot server
The hotspot server itself has timers with the same names. Those apply to devices that are connected but have not logged in, and they clear the host list:
/ip hotspot print
/ip hotspot set hotspot1 idle-timeout=5m keepalive-timeout=noneDo not confuse the two. Changing the server's timers does not log paying users out.
Session timeout is not a time package
session-timeout limits one session; the user can log straight back in. To sell an amount of time, use limit-uptime on the user, which counts all sessions together:
/ip hotspot user set [find name=guest1] limit-uptime=5hNeither is a calendar expiry. For that see hotspot user expiry.
See the timers at work
/ip hotspot active print detailEach session shows uptime, idle-time and, when a limit applies, session-time-left. Compare idle-time with your idle-timeout to see who is about to be logged out.
Users are logged out too often
- Idle timeout too short. A phone with its screen off sends little. With
idle-timeout=1mit is logged out in a pocket. Use 10 to 30 minutes. - Keepalive too short. Phones put Wi-Fi to sleep and miss the router's checks. Use 5 minutes or more instead of the default 2.
- Weak signal. A device at the edge of coverage drops off and fails keepalive. Timers will not fix that.
- No login cookie. With cookies on, a customer who was timed out is logged in again without typing. See hotspot login cookies.
- The package really ran out. Check
limit-uptimeandlimit-bytes-totalon the user, and the log.
/log print where topics~"hotspot"Users stay listed after they left
- Both timers are off. With
idle-timeout=noneandkeepalive-timeout=nonenothing ever ends the session. Set at least one. - Uptime keeps counting. A stale session uses up the customer's
limit-uptimewhile they are not there, and blocks their next login if shared-users is 1.
Remove a stale session by hand:
/ip hotspot active remove [find user="guest1"]Values that work for most sites
| Site | idle-timeout | keepalive-timeout |
|---|---|---|
| Café, short visits, time sold by the hour | 5m to 10m | 2m to 5m |
| Hostel, flats, long stays | 30m to 1h | 5m to 10m |
Where you sell connected time, shorter timers are fairer to the customer, because idle time stops being charged sooner.
With RADIUS
A RADIUS reply can carry Session-Timeout and Idle-Timeout for the session, and those take the place of the profile's values. See RADIUS attributes.
Where RadiusNest fits
With RadiusNest the time a customer has left comes from their package: time, end date and time-of-day hours are applied at each login, and the customer is disconnected when the package ends. The keepalive timer stays a router setting, and the advice above still applies to it.
Start the free trial See pricing
Questions and answers
What is the difference between idle-timeout and keepalive-timeout?
Idle timeout ends a session when the device is present but passes no traffic. Keepalive timeout ends it when the device no longer answers the router at all.
Does session-timeout stop a user from logging in again?
No. It ends the current session only. Use limit-uptime on the user to cap total time.
Why does the active list show users who left hours ago?
Idle and keepalive timeouts are both off in the user profile, so the router has no reason to end the session. Set at least one of them.