New to Powerlynx hotspots? To understand what a hotspot controller is and how it fits with Powerlynx, start with the Hotspots documentation.
One of the most common questions we get from new operators is simply: “What hardware do I need to run a Powerlynx hotspot?” This post answers that at the level of what has to be true of your equipment, rather than handing you a single shopping list — then shares the devices we and our users have had good results with, from a single café router up to a stadium-scale core.
In short, every Powerlynx hotspot has one device that matters most: the hotspot controller (NAS), the router on your site that Powerlynx talks to. It must run a captive portal that redirects to Powerlynx’s external splash page, authenticate against Powerlynx over RADIUS, and be reachable from Powerlynx over a VPN (WireGuard / OpenVPN / IPsec) or a public IP. The switches and access points behind it simply forward client traffic and stay invisible to Powerlynx — and Powerlynx handles sign-in and policy only, so your Internet still comes from your ISP. The Hotspots documentation explains all of this — and the full controller requirements — in detail; below we focus on the hardware.
Our position on hardware recommendations
Before we name any specific devices, one important disclaimer.
It is not our policy to recommend specific hardware. The best-suited devices for a given site depend on many factors — the coverage area, the number of devices on site, the number of simultaneous connections you expect, the kinds of client devices your guests use, and more. Choosing and sizing that equipment is ultimately the customer’s responsibility.
For anything beyond a simple single-router setup, we strongly recommend consulting a dedicated network engineer or system administrator. The models and tiers below are shared as practical guidance and as examples that have worked well — not as a guarantee that a given device is right for your particular site.
That said, we’re glad to help. If you need a hand with your NAS configuration or reconfiguration, or want initial-setup recommendations for the other devices in your network, our support team can assist. And if you already have network equipment you’re thinking of using with Powerlynx, reach out and we’ll help you figure out whether it fits — just email support@powerlynx.app.
Recommended NAS devices
MikroTik — our top recommendation
If you want the smoothest experience, MikroTik is strongly recommended. It gives you full control through RouterOS and its API, and the range scales cleanly from a tiny café router all the way to a carrier-grade core, so you can standardize on one vendor across every site size.
A quick note on honesty before the tables: MikroTik does not publish an official “maximum concurrent hotspot users” figure for any of its routers. The tiers below are engineering guidance based on each device’s CPU and RAM headroom for hotspot and RADIUS work — not a vendor specification. Treat them as sensible starting points, and size up if in doubt.
Tier 1 — up to ~100 concurrent online users (SOHO, with built-in Wi-Fi):
| Model | Notes |
|---|---|
| hAP ax³ (C53UiG+5HPaxD2HPaxD) | Recommended — especially with switches/APs behind it. Quad-core IPQ-6010 up to 1800 MHz, 1 GB RAM, 4×1G + 1×2.5G, Wi-Fi 6 (AX1800), PoE in/out, USB 3.0. |
| hAP ax² (C52iG-5HaxD2HaxD-TC) | Same 1 GB RAM and Wi-Fi 6 (AX1800), quad-core IPQ-6010 @864 MHz, 5×1G. Great for a standalone single-box site. |
| hAP ac³ (RBD53iG) | 256 MB RAM, 5×1G, Wi-Fi 5. |
Both hAP ax models share 1 GB of RAM and the same AX1800 Wi-Fi 6 radios — the difference that matters here is routing capacity, not wireless. The ax³ runs the same quad-core chip at up to 1800 MHz (against the ax²’s 864 MHz) and adds a 2.5GbE port, so when it’s acting as a controller with switches and access points behind it — aggregating every downstream client’s RADIUS, NAT, firewall and per-user-queue work, over an uplink that isn’t capped at 1 Gbit/s — it’s the better pick. The ax² is perfectly good for a standalone single-box small site. Either way, prefer these over the older hAP ac², whose 128 MB of RAM is tight for hotspot work.
Tier 2 — up to ~500 concurrent online users (wired core, no built-in Wi-Fi):
| Model | Notes |
|---|---|
| RB5009UG+S+IN | Recommended, current. 4-core ARM64 @1.4 GHz, 1 GB DDR4, 7×1G + 1×2.5G + SFP+ (10G). |
| L009UiGS-RM | 2-core @800 MHz, 512 MB RAM, 8×1G + SFP (2.5G). |
| RB4011iGS+5HacQ2HnD-IN | 4-core, 1 GB RAM, 10×1G + SFP+ (10G), Wi-Fi 5. Still sold; the RB5009 is the newer, more capable pick. |
Tier 3 — 500+ concurrent online users (Cloud Core Routers):
| Model | Notes |
|---|---|
| CCR2004-16G-2S+ | 4-core @1.7 GHz, 4 GB RAM, 16×1G RJ45 + 2×SFP+ (10G). Best when you uplink many APs/switches over copper. |
| CCR2004-1G-12S+2XS | 4-core @1.7 GHz, 4 GB ECC RAM, 12×SFP+ (10G) + 2×SFP28 (25G). For fibre-dense sites. |
| CCR2116-12G-4S+ | 16-core @2.0 GHz, 16 GB RAM, 13×1G + 4×SFP+ (10G). Top tier. |
The two CCR2004 variants share the same quad-core engine and differ mainly in port mix — copper (16G) versus fibre (12S+2XS); the 16-core CCR2116 is the step up for the largest sites. At this scale the limiting factor is CPU per session and per RADIUS transaction, not raw throughput — which is exactly why the multi-core CCRs earn their place here.
A few EOL notes so you don’t buy something discontinued: the old RB3011UiAS-RM is discontinued — use the L009UiGS-RM or RB5009UG+S+IN instead. The CCR1009 is discontinued (its Tilera platform is end-of-life) — use the CCR2004 or RB5009 instead.
Tested SOHO devices (all real, all validated): hAP ac lite (RB952Ui-5ac2nD, 64 MB RAM and 100 M ports — only for the very smallest setups), hAP ac² (legacy, superseded by the ax²), hAP ac³, hAP ax², hAP ax³.
And a few MikroTik-specific caveats worth knowing up front:
- FastTrack and hotspot don’t mix. A broad FastTrack firewall rule bypasses connection tracking, the firewall, queues and the hotspot handler — which means with the hotspot active it can skip authentication and byte-accounting entirely. Keep FastTrack away from hotspot client traffic.
- Know your Wi-Fi package. The
ac-generation devices use the legacywirelesspackage (Wi-Fi 5); theax-generation devices use the newerwifipackage (Wave 2 / Wi-Fi 6, more capable). Thewifi/Wave2 package is ARM-only and needs at least 256 MB of RAM. (The-TCsuffix just means a tower-case enclosure — same electronics inside.) - WireGuard needs RouterOS v7. WireGuard is our recommended tunnel, and it’s only available on RouterOS v7 and later, so your controller must run ROS v7+.
Prefer a virtual machine? Consider CHR. You don’t have to run RouterOS on a physical box. MikroTik’s Cloud Hosted Router (CHR) is RouterOS packaged as a virtual machine, so you can run your controller on a cloud provider (AWS, Hetzner, Google Cloud, Vultr…) or on your own on-premise Linux/hypervisor host (KVM/Proxmox, VMware, Hyper-V). Because it’s a VM, you size its CPU, RAM and disk to your needs and scale with the host, and it runs the same RouterOS v7 hotspot + RADIUS + WireGuard feature set — so a CHR instance can be your Powerlynx NAS. It has no radios of its own, so your access points and switches sit behind it on the network. One thing to plan for: the free CHR licence is throttled to 1 Mbit/s per interface — fine for testing, but a production hotspot needs a paid tier (P1 lifts that to 1 Gbit/s per interface, with higher tiers above). See MikroTik’s official documentation: Cloud Hosted Router, CHR - RouterOS - MikroTik Documentation
Other supported NAS vendors
MikroTik is our recommendation, but if you prefer another supported vendor, that’s fine — just choose a device with similar capabilities (external portal + third-party RADIUS + a VPN or public-IP path to Powerlynx). Here are examples for each, with the one key caveat to watch:
- Cambium — there’s no single-box router NAS here; a Cambium hotspot is built from cnPilot APs plus an external portal and external RADIUS via cnMaestro (cloud or on-prem). Examples: cnPilot e410 (indoor, Wi-Fi 5), e510 / e600 (outdoor). Note that cnMatrix is a switch, not a NAS. Cambium connects to Powerlynx over a Public IP only. Caveat: it’s an AP/controller-based design rather than a router, and it configures RADIUS + splash per-WLAN with a cnMaestro external-portal hook. Also be aware that the Cambium preset can store the upload/download accounting figures swapped — worth checking your usage direction.
- Teltonika — RutOS has a Hotspot service (installed via the Package Manager) that works with external RADIUS. Examples: RUT240 / RUT241 (entry-level LTE, 2.4 GHz only — small sites only), RUT955 / RUT956 (industrial LTE with hotspot + RADIUS and Hotspot 2.0 — small-to-mid sites). Caveat: these are small cellular routers, not built for hundreds of concurrent users; make sure you’re on the latest RutOS with the Hotspot package installed.
- Cudy — for small networks only, and it’s firmware-gated. Powerlynx documents the WR1300 on firmware ≥ 2.2.3; the WR3000 has also gained a captive portal per Cudy, but it isn’t named in Powerlynx’s own guide — for other Cudy models, check with support@powerlynx.app first. Cudy reaches Powerlynx over WireGuard.
- Ruckus — Ruckus is AP-first, so the “controller” is what acts as the NAS: Unleashed (a master AP, the simplest option), ZoneDirector (a hardware controller — needs NBI + WISPr + walled garden), or SmartZone (a virtual, enterprise-grade controller). Caveat: a lone standalone-firmware AP has only limited portal features; use Unleashed, ZoneDirector or SmartZone.
- TP-Link (Omada) — integrated through the Omada controller (the Omada Software Controller on a host, an OC200/OC300 hardware controller, or the cloud controller); your Omada gateway (e.g. ER605, ER7206, or the all-in-one Wi-Fi 6 ER706W) and EAP access points register to it. Caveat: a standalone EAP on its own isn’t a controller — you need an Omada controller for the RADIUS + captive-portal integration. Full steps: TP-Link Omada setup guide.
The switches and access points behind the controller
Everything below the controller — your switches and access points — has just two things to get right: it must be compatible with your controller, and its job is simply to forward client traffic to the NAS.
Third-party access points from vendors like UniFi, TP-Link, Ruijie, Ubiquiti, Cambium or Teltonika all work happily as plain access points (running in AP mode, often carried over VLANs) behind a supported controller. What they can’t do is act as a standalone Powerlynx controller themselves — the controller role always belongs to the NAS. So if you already own APs from one of these vendors, keep them: put them in AP mode behind your MikroTik (or other supported) controller and they’ll do their job.
A word on CAPsMAN. If your controller and APs are all MikroTik, CAPsMAN is MikroTik’s own feature for centrally managing MikroTik CAP access points from one place. It’s genuinely useful for large MikroTik fleets — but it’s a MikroTik convenience, not a Powerlynx requirement. Powerlynx neither needs nor knows about CAPsMAN; it’s completely orthogonal to your hotspot setup. Use it if it makes managing your APs easier, but don’t treat it as a Powerlynx step. If you do want to run it with a Powerlynx hotspot, here’s a step-by-step walkthrough: Powerlynx Hotspot with CAPsMAN (Simple Setup).
Closing
The short version: your controller is the device that matters — get a NAS that meets the requirements above, size it to your expected number of concurrent users, and put whatever compatible switches and APs you need behind it. When in doubt about coverage, capacity or which model fits your site, talk to a network engineer.
Setup guides
When you’re ready to configure, these per-vendor manuals walk you through the actual setup:
- MikroTik Hotspot — How to connect your Mikrotik with Powerlynx (Advanced setup): | Powerlynx
- Cambium Hotspot — Connect Cambium hotspot with Powerlynx | Powerlynx
- Teltonika Hotspot — Connect Teltonika hotspot with Powerlynx | Powerlynx
- Cudy Hotspot — Connect Cudy hotspot with Powerlynx | Powerlynx
- Ruckus Hotspot — Connecting the Ruckus Hotspot to Powerlynx | Powerlynx
- TP-Link Omada hotspot — Connecting TP-Link Omada to Powerlynx (self-hosted RADIUS captive portal) | Powerlynx
- MikroTik CAPsMAN (multi-AP) hotspot — Powerlynx Hotspot with CAPsMAN (Simple Setup)
- OpenVPN connection — OpenVPN | Powerlynx
- IPSec VPN connection — IPSec VPN | Powerlynx
Got a setup of your own, or a question about whether a particular device will work? Reply below — tell us what you’re running and we’re happy to help you figure it out.