Reference

System Requirements

What you need to run One Access Panel.

System Requirements

One Access Panel connects to your MikroTik router over API-SSL. Your router handles the hotspot sessions; the dashboard watches it remotely. You need a router powerful enough for the number of users you plan to serve.


Minimum Specs

For small deployments up to 20 concurrent hotspot users.

SpecValue
RouterMikroTik hAP lite (RB941) or equivalent
CPU650 MHz single-core
RAM32 MB
RouterOS7.x
Concurrent usersUp to 20
NetworkSingle WAN, router reachable from dashboard server

Recommended Specs

For large deployments up to 500+ concurrent hotspot users.

SpecValue
RouterMikroTik RB4011, CCR1009, or hAP ac2 and above
CPU1.4 GHz quad-core or better
RAM256 MB+
RouterOS7.13+ (faster polling, more stable session stats)
Concurrent usersUp to 500+
NetworkDual WAN recommended for redundancy

Router Setup Requirements

  • API-SSL service enabled on port 8729 (use the API-SSL Setup tool under 1Config to enable it)
  • A router user in a group holding ftp, reboot, read, write, policy, test, password, sniff, sensitive, romon, api. Managing the expiry scheduler needs read, write, policy and test, so Kick & Delete, Kick & Disable and Enable/Disable return "permission not allowed" without them.
  • Dashboard server must reach the router on the API-SSL port (firewall allows it)

### Expiry scheduler permissions

Each time-limited voucher gets an expiry scheduler that removes the user when its time runs out. RouterOS only lets a router user disable or delete an object whose policies that user also holds. The current One Access Script creates schedulers with read, write, policy and test, so a router user with those policies can manage them. A scheduler created by an earlier script carries a wider set; recreate it with the current One Access Script, or add the missing policies to the router user's group.


Dual WAN (ECMP)

If the router balances traffic across two or more WAN links, pin the dashboard's WireGuard endpoint with one `/32` host route per WAN. Without it the tunnel handshakes leave by different links and the connection flaps. Each gateway can be a next-hop IP, a PPPoE or other interface, or `IP%interface` when the links share a gateway. Generate the routes with the Multi-WAN WireGuard Routes Fix tool under Tools > 1Config. Do not disable ECMP.


Browser Requirements

BrowserMinimum Version
Chrome90+
Firefox90+
Safari15+
Edge90+

JavaScript must be enabled. The dashboard uses Server-Sent Events for live data. All modern browsers support this natively.