Multiple hotspots on one MikroTik router: one per VLAN or bridge
Last updated: 2 October 2026
One router can run several hotspots at once: guests and staff, two buildings, or two brands on the same equipment. Each hotspot needs its own interface, its own address range and its own profile.
The rule: one hotspot per interface
A hotspot server is attached to one interface, and that interface must be a separate network: a VLAN interface, a bridge, or a single port that is not inside a bridge. For each hotspot you create the same five things as in a normal hotspot setup: address, pool, DHCP server, hotspot profile and hotspot server.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
1. Create the VLANs
In this example ether2 carries tagged traffic to a switch or to access points that put each Wi-Fi name in its own VLAN: 10 for the first hotspot, 20 for the second.
/interface vlan add name=vlan10-cafe interface=ether2 vlan-id=10
/interface vlan add name=vlan20-rooms interface=ether2 vlan-id=20If the networks arrive on separate ports instead, skip this step and use the ports, or one bridge per network, in place of the VLAN interfaces below.
2. The first hotspot
/ip address add address=10.5.10.1/24 interface=vlan10-cafe
/ip pool add name=pool-cafe ranges=10.5.10.2-10.5.10.254
/ip dhcp-server add name=dhcp-cafe interface=vlan10-cafe address-pool=pool-cafe disabled=no
/ip dhcp-server network add address=10.5.10.0/24 gateway=10.5.10.1 dns-server=10.5.10.1
/ip hotspot profile add name=prof-cafe hotspot-address=10.5.10.1 dns-name=cafe.wifi html-directory=hotspot
/ip hotspot add name=hs-cafe interface=vlan10-cafe address-pool=pool-cafe profile=prof-cafe disabled=no3. The second hotspot
/ip address add address=10.5.20.1/24 interface=vlan20-rooms
/ip pool add name=pool-rooms ranges=10.5.20.2-10.5.20.254
/ip dhcp-server add name=dhcp-rooms interface=vlan20-rooms address-pool=pool-rooms disabled=no
/ip dhcp-server network add address=10.5.20.0/24 gateway=10.5.20.1 dns-server=10.5.20.1
/ip hotspot profile add name=prof-rooms hotspot-address=10.5.20.1 dns-name=rooms.wifi html-directory=hotspot-rooms
/ip hotspot add name=hs-rooms interface=vlan20-rooms address-pool=pool-rooms profile=prof-rooms disabled=noEach profile has a different hotspot-address and a different dns-name. Reusing one name for two hotspots sends customers to the wrong login page.
4. Internet and DNS for both
/ip dns set allow-remote-requests=yes
/ip firewall nat add chain=srcnat src-address=10.5.10.0/24 action=masquerade
/ip firewall nat add chain=srcnat src-address=10.5.20.0/24 action=masquerade5. A login page for each
The second profile points at a folder named hotspot-rooms. In Winbox Files, download the hotspot folder, rename the copy on your computer, change the logo and text, and upload it under the new name. The details are in customizing the login page. If both hotspots may look the same, leave both profiles on html-directory=hotspot.
Users: shared or separate
Users stored on the router can log in on any of its hotspots. To tie a user to one of them, set the server on the user:
/ip hotspot user add name=room204 password=5521 server=hs-rooms profile=5M
/ip hotspot user add name=guest7 password=9034 server=hs-cafe profile=5MRADIUS is switched on per profile, so one hotspot can use router users while the other uses RADIUS:
/ip hotspot profile set prof-rooms use-radius=yesKeep the networks apart
The router routes between its own networks unless told otherwise. Stop the two hotspots reaching each other:
/ip firewall filter add chain=forward src-address=10.5.10.0/24 dst-address=10.5.20.0/24 action=drop
/ip firewall filter add chain=forward src-address=10.5.20.0/24 dst-address=10.5.10.0/24 action=dropCheck
/ip hotspot print
/ip hotspot active print
/ip hotspot host printThe active list has a server column that shows which hotspot each customer is on.
What usually goes wrong
- No address on the second network. The switch or access point does not tag the VLAN, or tags a different number. Check with
/ip dhcp-server lease print. - The hotspot shows as invalid. Its interface is a port inside a bridge. Use the bridge, or take the port out.
- Both hotspots show the same page. Both profiles point at the same
html-directory, or the phone cached the old page. - The login page of one hotspot does not open. Its
dns-nameis the same as the other's. See login page not opening.
Where RadiusNest fits
RadiusNest does not create VLANs or hotspots; those stay on your router as set up above. Once the profiles use RADIUS, the logins of every hotspot, on one router or several, are checked in one place, with the same packages, vouchers and sales report for all of them.
Start the free trial See pricing
Questions and answers
How many hotspots can one MikroTik router run?
There is no fixed small number. Each needs its own interface and address range, and the practical limit is the router's processor and memory under your traffic.
Can two hotspots share the same users?
Yes. Router users work on every hotspot of that router unless you set server= on the user. Users checked by RADIUS work wherever the profile has use-radius=yes.
Do I need VLANs for a second hotspot?
No. A separate port or a separate bridge works the same way. VLANs are only the usual way to carry two networks over one cable.