Reference
System Requirements
What you need to run One Access Panel.
System Requirements
One Access Panel connects to your MikroTik router over API-SSL. Your router handles the hotspot sessions; the dashboard watches it remotely. You need a router powerful enough for the number of users you plan to serve.
Minimum Specs
For small deployments up to 20 concurrent hotspot users.
| Spec | Value |
|---|---|
| Router | MikroTik hAP lite (RB941) or equivalent |
| CPU | 650 MHz single-core |
| RAM | 32 MB |
| RouterOS | 7.x |
| Concurrent users | Up to 20 |
| Network | Single WAN, router reachable from dashboard server |
Recommended Specs
For large deployments up to 500+ concurrent hotspot users.
| Spec | Value |
|---|---|
| Router | MikroTik RB4011, CCR1009, or hAP ac2 and above |
| CPU | 1.4 GHz quad-core or better |
| RAM | 256 MB+ |
| RouterOS | 7.13+ (faster polling, more stable session stats) |
| Concurrent users | Up to 500+ |
| Network | Dual WAN recommended for redundancy |
Router Setup Requirements
- API-SSL service enabled on port 8729 (use the API-SSL Setup tool under 1Config to enable it)
- A router user in a group holding ftp, reboot, read, write, policy, test, password, sniff, sensitive, romon, api. Managing the expiry scheduler needs read, write, policy and test, so Kick & Delete, Kick & Disable and Enable/Disable return "permission not allowed" without them.
- Dashboard server must reach the router on the API-SSL port (firewall allows it)
### Expiry scheduler permissions
Each time-limited voucher gets an expiry scheduler that removes the user when its time runs out. RouterOS only lets a router user disable or delete an object whose policies that user also holds. The current One Access Script creates schedulers with read, write, policy and test, so a router user with those policies can manage them. A scheduler created by an earlier script carries a wider set; recreate it with the current One Access Script, or add the missing policies to the router user's group.
Dual WAN (ECMP)
If the router balances traffic across two or more WAN links, pin the dashboard's WireGuard endpoint with one `/32` host route per WAN. Without it the tunnel handshakes leave by different links and the connection flaps. Each gateway can be a next-hop IP, a PPPoE or other interface, or `IP%interface` when the links share a gateway. Generate the routes with the Multi-WAN WireGuard Routes Fix tool under Tools > 1Config. Do not disable ECMP.
Browser Requirements
| Browser | Minimum Version |
|---|---|
| Chrome | 90+ |
| Firefox | 90+ |
| Safari | 15+ |
| Edge | 90+ |
JavaScript must be enabled. The dashboard uses Server-Sent Events for live data. All modern browsers support this natively.