How to Block Hotspot Sharing/Tethering on MikroTik RouterOS
How AROFi prevents a single paid login from being shared across multiple devices via Wi-Fi hotspot sharing, USB tethering, or Bluetooth sharing.
1. Why Block Hotspot Sharing?
A common problem: a customer buys one voucher or session, then shares it to several other devices via their phone's hotspot/tethering feature.
This causes bandwidth congestion, slows the connection for paying customers, and reduces your revenue per device actually using the network.
AROFi's provisioning script enforces a one-device-per-login rule automatically — you don't need to configure the items below by hand, but it helps to understand what's already active so you don't accidentally undo it.
2. Single session per login
Every login is limited to one active device at a time automatically — nothing to configure.
If you ever see this setting in WinBox, leave the keepalive timeout alone: it's deliberately set long so a phone's screen locking or going briefly idle doesn't get mistaken for the customer leaving the network and disconnected by mistake.
3. Anti-tethering protection
Even with one device per login enforced, a customer could still try to share their connection using their phone's own hotspot or tethering feature.
AROFi blocks this automatically for every hotspot it provisions — a shared/tethered device simply can't get a working connection, without needing any app or setup on the customer's side.
4. Testing
1. Log in to the hotspot on your phone using a voucher or live billing.
2. Turn on your phone's hotspot/tethering feature.
3. Connect a second device (e.g. a laptop) to your phone's shared hotspot.
4. Try to load a website from the second device — it should fail or time out, while your phone stays fully connected.
