The use of portal hotspots as network authentication and enhancing wireless network security is commonly implemented by combining it with the Radius database (Remote Authentication Dial-In User Service) as a means of storing user credentials that can be accessed by network devices. Problems occur when a company that has an intranet network is geographically separated where the radius user database must be run on each intranet network, so that the same user registration process must be carried out repeatedly at branch companies. Kuningan University has branch campuses that are geographically located at different distances, so a centralized and secure technology is needed in exchanging data. In this study, the application of VPN (Virtual Private Network) technology was examined to combine two or more different networks with the application of security to data communications. The Radius database will be stored in a data center that uses a public IP so that it can be accessed by both sites connected using a VPN, so that the hotspot user data changes. The topology design was successfully simulated using the vmware and gns3 applications as a simulator for Mikrotik-based network devices according to the devices used in the research object. The results obtained, each site that is connected using remote vpn l2tp can be connected to each other to the radius database in the datacenter, and can be authenticated by a login hotspot that is activated on the Mikrotik router.