Weird Network works with the routers you already have. This guide covers the four most common router families used by providers — MikroTik RouterOS, Ubiquiti UniFi, OpenWRT + CoovaChilli, and CoovaChilli standalone — with the exact steps to configure each for captive portal redirect, session tracking, and voucher authentication.
Compatibility Matrix
Quick reference for which routers are fully supported, partially supported, and what's required.
| Router | Portal Method | Auth Methods | Session Tracking | Hardware Req. | Status |
|---|---|---|---|---|---|
| MikroTik RouterOS | Built-in Hotspot | Form capture, Voucher | Via Weird Network session API | hEX S, hEX PoE, RB760iGS — any RouterOS 6.49+ | ✅ Supported |
| Ubiquiti UniFi | UniFi Guest Portal redirect | Form capture, Voucher | Via Weird Network session API | UDM, UDM-Pro, UDM-SE, UniFi Dream Router | ✅ Supported |
| OpenWRT + CoovaChilli | CoovaChilli splash page redirect | Form capture, Voucher, Social gate | Via CoovaChilli JSON interface + Weird Network API | Any OpenWRT-capable device (ath79, x86, ipq40xx) | ✅ Supported |
| OpenWRT (no CoovaChilli) | nodogsplash redirect | Form capture only | Limited — no real-time MAC tracking | Same as OpenWRT | ⚠️ Partial |
| CoovaChilli standalone | CoovaChilli UAM redirect | Form capture, Voucher | Full via RADIUS/JSON | Any Linux router or embedded device | ✅ Supported |
| Ubiquiti EdgeRouter | Built-in Hotspot redirect | Form capture | Via Weird Network session API | ER-X, ER-4, ER-6P, ER-12 | ✅ Supported |
Voucher support note: All fully-supported routers work with the Weird Network
voucher system — guests redeem codes via the captive portal, which calls
POST /api/vouchers/redeem and starts a session with auth_method=voucher.
Vouchers are generated in your provider dashboard and expire after 30 days.
Routers must also complete the pairing flow (pairing code from your dashboard) to appear
in router status and alert monitoring.
MikroTik RouterOS Setup
Software requirement: RouterOS 6.49+ or 7.x. Both branches are supported;
some CLI parameter names differ between versions (noted below).
Hardware requirement: hEX S recommended for small venues; hEX PoE for
AP-wired setups where the router also powers access points. Any device running RouterOS 6.49+
will work.
Open Winbox or WebFig, go to IP → Hotspot → Setup Wizard
Run the Hotspot Setup Wizard to initialize the hotspot service on your router. This creates the server profile and local DNS record automatically.
Select the guest-facing interface
Choose the interface that guests connect to — usually bridge-guest
or ether2 depending on your network layout. Do not select your WAN interface.
Set DNS name
Enter hotspot.yourdomain.com or leave the default. This is the hostname
the router uses for its local captive portal intercept page — it does not need to be
publicly resolvable.
Set Login Page URL to your Weird Network portal
Under Hotspot Server Profile → Login tab: enable HTTP PAP, then set Login Page URL
to https://weird-network.io/portal/<your-location-id>. In RouterOS 7.x,
you can also set this via terminal: /ip hotspot profile set login-page=<url>.
Configure Walled Garden
Under IP → Hotspot → Walled Garden, add weird-network.io and
weird-network.polsia.app so guests can reach the portal before authenticating.
Also add fonts.googleapis.com and fonts.gstatic.com for portal fonts.
Disable local RADIUS
In the Hotspot Server Profile → RADIUS tab, leave RADIUS disabled. Weird Network manages session state via the captive portal session API directly — no RADIUS server is required on your end.
Test the redirect
Connect a device to the guest network and try browsing. The router should intercept and redirect to your Weird Network portal. Confirm the portal loads, the location is correct, and submitting the form starts a session.
Troubleshooting MikroTik: If the portal redirect doesn't fire, check that the
guest interface is assigned to the hotspot server (IP → Hotspot → Servers) and that DNS is resolving
on the guest network. RouterOS 7.x changed the hotspot login page parameter name — use
/ip hotspot profile set login-page=<url> in the terminal if the WebFig field
doesn't save correctly.
Ubiquiti UniFi Setup
Software requirement: UniFi Network Application 7.x+; controller version ≥ 7.4
recommended for stable guest redirect behavior.
Hardware requirement: UDM, UDM-Pro, UDM-SE, or UniFi Dream Router acting as
the gateway. A standalone UniFi AP behind a third-party router will not handle the
redirect — the gateway must be a UniFi device and must be the DHCP server for the guest network.
Create or select a guest SSID
In UniFi Network app, go to Settings → WiFi. Create a new SSID or select an existing guest network. Guest SSIDs are isolated from the management network by default — confirm client isolation is enabled.
Enable Guest Hotspot
Under the SSID's Advanced settings, enable "Guest Hotspot." This activates UniFi's captive portal intercept for clients on this SSID.
Set Custom Portal URL
Under Portal Customization → Custom Portal URL, enter
https://weird-network.io/portal/<your-location-id>.
This is where UniFi redirects unauthenticated clients.
Add Pre-Authorization Access (Walled Garden)
Under Guest Control → Pre-Authorization Access, add: weird-network.io,
weird-network.polsia.app, fonts.googleapis.com,
fonts.gstatic.com. Without these, the portal page itself will fail to load
before the guest authenticates.
Configure session duration and bandwidth limits
Set session expiry and per-client bandwidth limits at the UniFi level as a baseline.
Weird Network will also enforce its own session policies via the
captive_portal_sessions table — the two can coexist without conflict.
Apply and test with a fresh device
Use a device that has never connected to this SSID (or forget the network first). Connect, confirm the portal appears and redirects correctly, and verify a session appears in your provider dashboard after authentication.
Troubleshooting UniFi: HTTPS interception is required for the redirect to work on modern browsers — UniFi's captive portal handles this by intercepting HTTP port 80 first. If clients see SSL errors on initial connection, verify the walled garden includes the full portal domain. UniFi requires the gateway (UDM/UDR) to be the DHCP server for the guest network; the redirect will not fire if a standalone AP is behind a third-party router.
OpenWRT + CoovaChilli Setup
Software requirement: OpenWRT 21.02+ with the coova-chilli package
(install via opkg). For partial support only, nodogsplash is an alternative
but does not support real-time MAC tracking or voucher auth.
Hardware requirement: Any 802.11ac or newer router with OpenWRT support,
≥ 64 MB RAM, ≥ 8 MB flash recommended. Works on ath79, x86, ipq40xx targets.
Install CoovaChilli via opkg
SSH into the router and run: opkg update && opkg install coova-chilli.
This installs the captive portal daemon and the UAM redirect engine.
Edit the CoovaChilli config file
Edit /etc/chilli/config (or /etc/config/chilli for UCI-based
installs). Set: HS_UAMUISSL (enable HTTPS UAM), HS_UAMUIPORT
(port for UAM interface), HS_NASID (your location ID), and point
HS_UAMSERVER to
https://weird-network.io/portal/<your-location-id>.
Set the UAM shared secret
Set HS_UAMSECRET to any shared secret string. Store this same secret in
your Weird Network provider dashboard under router config — the portal uses it to
validate the CoovaChilli challenge parameter for MAC binding.
Add walled garden entries
In HS_UAMALLOWED, add: weird-network.io weird-network.polsia.app
fonts.googleapis.com fonts.gstatic.com. Space-separated values in the config file.
Start and enable the service
Run: /etc/init.d/chilli enable && /etc/init.d/chilli start.
The daemon will start and insert iptables NAT rules for the guest-facing interface.
Test the redirect
Connect a device to the guest interface. CoovaChilli intercepts and redirects to the
UAM URL with a challenge parameter. The Weird Network portal reads this
for session MAC binding. Verify a session appears in your dashboard after authentication.
Troubleshooting OpenWRT + CoovaChilli: CoovaChilli requires the guest-facing
interface to be distinct from the WAN interface — typically br-guest on a separate
VLAN. If the service starts but clients aren't being redirected, check that
iptables -t nat -L shows the PREROUTING rules CoovaChilli inserts.
On OpenWRT with nftables (kernel 5.15+), CoovaChilli may require
kmod-compat-xtables to function.
CoovaChilli Standalone Setup
For operators running CoovaChilli on a dedicated Linux box — for example, a Raspberry Pi acting as the gateway for a guest network — the setup is nearly identical to the OpenWRT section above, with package installation handled by apt instead of opkg.
Install CoovaChilli via apt
Run: sudo apt update && sudo apt install coova-chilli.
The config file lands at /etc/chilli/config.
Configure the same parameters as OpenWRT
Set HS_UAMSERVER, HS_UAMSECRET, HS_NASID,
and HS_UAMALLOWED exactly as described in the OpenWRT section above.
From Weird Network's side, a standalone CoovaChilli host is indistinguishable from
an OpenWRT installation.
Enable and start via systemd
Run: sudo systemctl enable chilli && sudo systemctl start chilli.
Confirm the service is active with systemctl status chilli.
Verify guest interface routing
Confirm the Linux host is the default gateway for the guest network (acting as a NAT router), and that the guest-facing NIC is bound to CoovaChilli. Test the redirect with a connected device.
Common Troubleshooting
These are the most common issues providers encounter when connecting a new router to Weird Network.
-
Portal redirect not firing
Confirm the guest interface is in hotspot/captive-portal mode on the router, and that the walled garden includes
weird-network.io. On MikroTik, check IP → Hotspot → Servers to confirm the interface is bound. On UniFi, confirm the UDM/UDR is the DHCP server for the guest SSID. -
SSL certificate errors on redirect
The router must intercept HTTP (port 80) first — clients on HTTPS-only sites need an HTTP probe to trigger the captive portal notification. Modern iOS and Android send these probes automatically. If errors persist, check that the captive portal domain is in the walled garden so the portal page itself can load before auth.
-
Session not recorded in Weird Network dashboard
Confirm
POST /api/sessions/startreaches the server with the correctprovider_id,location_id, andmac_address. The portal JavaScript handles this on form submit — verify the portal URL contains the right location ID. Check your browser's network tab on a test device to confirm the API call fires and returns 200. -
Voucher codes not accepted
Vouchers are validated via
POST /api/vouchers/redeem. Confirm that you've generated vouchers in the provider dashboard and that their status isactive. Codes expire after 30 days and are rate-limited to 100 generated per provider per day. -
Router showing offline in dashboard
A router must be paired via the pairing-code flow (
POST /api/pairing-codefrom your dashboard) to appear in alert monitoring and online status. An unpaired router can still pass guest traffic, but won't send router-offline alerts or appear in the routers list.
Related Guides
More guides covering specific hardware and monetization strategies:
Need help with your router setup?
Drop your email and we'll send you a free WiFi audit — including which router configuration is best for your venue and what you might be leaving on the table.