12 ms·
The Ars guide to building a Linux router from scratch
- dsr_ 10y agoAt least in my setup, a small SSD means that a complete reboot for the router takes 22-24 seconds, and so TCP sessions will not drop.
- bluedino 10y agoBe careful when using a very small SSD or something like a CF card for a router. Enabling logging to disk can wear the flash memory out in a matter of weeks
- dsr_ 10y agoI have a 64GB SSD and a little over 4.5GB used in the last year. I don't think that flash exhaustion is likely in the near future... but I also have a 32GB USB stick plugged in, which gets a backup copy once a week. The great thing about building your own router is that you can easily replace parts.
- bcook 10y agoI have been using a non-commercial, 8GB CompactFlash card with my pfSense install for 2 years with no problems, and I run the full pfSense rather than the NanoBSD version. I do not run extra services like Squid or Snort, so most of my "writes" are probably within my massive 1GB of RAM.
- satysin 10y agoWith modern SSD that isn't going to be a concern. You can write to them at full speed constantly for months and real world tests have shown them to last just fine and you are not going to max out 500MB/s writes to an SSD with log files :)
- goda90 10y agoI wonder how well the Turris Omnia[1] will compare to a homebrew solution like this. [1]https://omnia.turris.cz/en/ https://omnia.turris.cz/en/
- urza 10y agoI cant wait for mine to arrive :) I like those automatic security updates and network traffic analysis...
- Mister_Snuggles 10y agoHere's a tutorial for doing the same thing with OpenBSD from a few years ago: http://www.bsdnow.tv/tutorials/openbsd-router http://www.bsdnow.tv/tutorials/openbsd-router
- zdw 10y agoThe OpenBSD site has an example as well. http://www.openbsd.org/faq/pf/example1.html http://www.openbsd.org/faq/pf/example1.html As a point of comparison, the iptables syntax as shown in the Ars article is far harder to grok at first glance than either of the pf examples. For example: pass in on egress inet proto tcp from any to (egress) port { 80 443 } rdr-to <ipaddr> vs: -A PREROUTING -p tcp -m tcp -i p4p1 --dport 80 -j DNAT --to-destination <ipaddr>:80 -A FORWARD -p tcp -d <ipaddr> --dport 80 -j ACCEPT
- Mister_Snuggles 10y agoYeah, I've always found iptables to be a little hard to understand. It also sounds like it's getting replaced[0]. My guess is that we will see iptables around for a long time after it's been deprecated. ifconfig, for example, is deprecated[1] yet it's still around and being used. [0] https://lwn.net/Articles/564095/ https://lwn.net/Articles/564095/ [1] https://lists.debian.org/debian-devel/2009/03/msg00780.html https://lists.debian.org/debian-devel/2009/03/msg00780.html
- zdw 10y agoifconfig is BSD derived and standard across more Unix variants, whereas ip and friends are Linux only. See also dladm in illumos as another variation on a theme.
- Decade 10y agoifconfig is still used on BSD and, most importantly, MacOS X. Also, the Linux replacement for ifconfig is ip from iproute2, and that was made by the guy who did Linux QoS. He sort of sucks at usability. For example, `ifconfig eth0 down` becomes `ip link set dev eth0 down` and `ifconfig eth0 192.168.1.2` becomes `ip add add 192.168.1.2/24 brd + dev eth0`; I had to look these up to make sure I had the correct syntax. Okay, the actual command is `ip address add` and not `ip add add`, but it allows extreme abbreviation at the expense of discoverability.
- danielrhodes 10y agoIf you don't want to do all that configuration, PFSense is a good alternative. https://www.pfsense.org/download/ https://www.pfsense.org/download/ PFSense is the same thing below the hood, but with a web front-end and plugins. Most off the shelf wireless routers work fine as an access point, but are quite bad as a router. So you can just plug your old wireless router into this thing (with DHCP etc turned off), and your whole setup will be much better.
- anderiv 10y agoI'll echo the pfSense recommendation. One correction, though: pfSense is built upon FreeBSD, not linux.
- bcook 10y agoIPFire is my choice if you prefer Linux.
- deelowe 10y agoI've been running pfsense for over 5 years now and never had an issue. And, it's only getting better. I highly recommend it.
- lightlyused 10y agoI built a lan to wan router where the wan was a wifi link (couldn't run a cable in the building) using pfsense, it works really well.
- kjs3 10y agoNth-ing pfSense. Straight-forward to configure, dead stable. Near-enterprise class features.
- tyingq 10y agoUbiquiti's EdgeRouter Lite is a popular, fast, cheap (<$100), solution in this space. People are running FreeBSD and Linux on it: http://www.daemonology.net/blog/2016-01-10-FreeBSD-EdgeRouter-Lite.html http://www.daemonology.net/blog/2016-01-10-FreeBSD-EdgeRoute... https://wiki.gentoo.org/wiki/MIPS/ERLite-3 https://wiki.gentoo.org/wiki/MIPS/ERLite-3
- vostok 10y agoOne note is that it's my understanding that running Linux or even FreeBSD will mean that you can't hit 1Mpps if that's important to what you're doing.
- revelation 10y agoSo you go through all that trouble and end up with a terribly slow NIC, a "grownup" OS to maintain and the shitbox MIPS architecture to boot? What a pain. These MIPS boxes have their place, and that's squarely in the OpenWRT / system builder niche. With the electricity prices the way they are in the US, no way I'd run something like that over a proper x86 as in the article that can saturate a 1Gbps and manage decent disk IO.
- tyingq 10y ago>>a proper x86 as in the article that can saturate a 1Gbps "x86" covers a lot of ground. Certainly, in the "about $100" range, your choices in X86 land can't saturate 1Gbps either. The x86 box in the article was $280 total. About the same cost as the logical upgrade to the EdgeRouter Lite...their ER-8, which can saturate 1Gbps, and has 8 ports.
- mynewtb 10y agoSeems to be missing on of the most crucial parts: Keeping the software up to date to avoid being a victim to security issues.
- cnvogel 10y agoDuring the "Linux-Setup" part of the article: """ ...and whether you want automatic security upgrades. (Spoiler: Yes, you do.) """
- briHass 10y agoI had trouble getting a hold of one of those C1037U boxes from China. The seller would 'run out of stock' frequently if I found one for a decent price. I ended up going with the APU2B4 board (an upgrade from the APU1D mentioned in the article.) I put pfSense on it, and it's been running perfect for a few weeks now. Even that board is probably massive overkill for most people. I have 50/50 internet, and with full bandwidth used by torrents, a VPN and ssh session open to the router, and the web interface open, I'm still only getting about 10-15% CPU. http://pcengines.ch/apu2b4.htm http://pcengines.ch/apu2b4.htm
- gh02t 10y agoLooks like the one listed in the article is both out of stock and going for ~$1400 (I'm guessing auto pricing?). The APU boards are nice too; I thought about going for one when I was shopping for a better router and slapping OpenBSD on it. Ultimately I went with an Ubiquiti ERL, mostly because I didn't really want to buy an RS-232 cable, but the PC Engines boards are probably one of the best fully-DIY options you can get.
- shimon_e 10y agoInteresting. I have been using such PCs in my Chinese office for about a year. They are made in a factory about 30 minutes from me. I was considering designing a better looking case and bundling a more reliable power supply to export these but I got busy with bigger business. These Shenzhen factories are somehow getting these Intel CPUs for next to nothing. Factory price for the i5 model was about $100.
- aroch 10y agoAt least in the past, I've heard of people getting lots of low binned / questionable QC'd intel chips for dollars per chip. They basically go for auction to the highest bidder. If you're willing to deal with a high defect rate (Either extensive QC yourself or just don't give a shit), it is a pretty good deal.
- avtar 10y agoCould you please recommend accompanying parts if someone wanted to use that board with pfsense to end up with a home/office wireless router? I was looking for a packaged solution but the official pfsense two port appliance with the wireless option seemed fairly expensive.
- x0 10y agoI have a lot of respect for those who know iptables well enough to make things like this. It looks so fascinating, but so complex.
- peatmoss 10y agoMe too! As others in the thread have mentioned, OpenBSD and pf make for a (IMHO) much easier configuration. Not sure what kind of difference in performance one might expect. I suspect both Linux and OpenBSD are more than capable of keeping up with any traffic one might throw at such a router.
- wtallis 10y agoBSD is at a huge disadvantage in QoS capability, to the point that it really shouldn't be recommended as the OS for the gateway on a typical low-speed bufferbloated residential ADSL or DOCSIS connection.
- zxv 10y agoI don't see any disadvantages of BSD for QoS. I believe the syntax for writing QoS on FreeBSD and OpenBSD provides very good expressive capability [1]. By using tagging [2], one can assign QoS priority to anything that a firewall rule can define. Having used FreeBSD QoS on dial-up, ISDN, DSL and cable over the years, it is this expressiveness that is one of the reasons I prefer the pf packet filter and thus BSD. Here's an example for bandwidth limited wan. Interactive ssh sessions get a queue with a minimum bandwidth; scp and sftp bulk transfers go to a separate queue. queue rootq on em0 bandwidth 100M max 100M queue ssh parent rootq bandwidth 20M queue ssh_interactive parent ssh bandwidth 10M min 5M queue ssh_bulk parent ssh bandwidth 10M queue std parent rootq bandwidth 20M default block return out on em0 inet all set queue std pass out on em0 inet proto tcp from any to any port 22 set queue(ssh_bulk, ssh_interactive) [1] PF - Packet Queueing and Prioritization http://www.openbsd.org/faq/pf/queueing.html http://www.openbsd.org/faq/pf/queueing.html [2] PF - Packet Tagging (Policy Filtering) http://www.openbsd.org/faq/pf/tagging.html http://www.openbsd.org/faq/pf/tagging.html
- pcunite 10y agoI use MikroTik for the nice hardware, low power, and RouterOS.
- tacon 10y agoI bought MikroTik for the netflow feature, which can reveal active malware via hardware packet counters by endpoint.[0] The next cheapest router with netflow is in the thousands of dollars. MikroTik is $180 at Amazon. [0] http://www.irongeek.com/i.php?page=videos/houseccon2015/t302-the-fox-is-in-the-henhouse-detecting-a-breach-before-the-damage-is-done-josh-sokol http://www.irongeek.com/i.php?page=videos/houseccon2015/t302...
- lvillani 10y agoWhich one do you have? Mine is an RB751U-2HnD and it is plagued with problems, to the point that I set-up an automatic reboot every other day and I'm thinking about switching to Ubiquiti gear...
- nier 10y agoA client of mine has a RouterBOARD 1100 X2 AH that I also decided to reboot daily for stability reasons. A RouterBOARD 951G 2HnD used in a branch office lost all IPSec configuration and hangs when viewing the settings on the command line. Certified MikroTik technician says the thing has to be reformatted and set up from scratch. My first experience with MikroTik products. Not good.
- jlgaddis 10y agoJust to chime in with another anecdote, I've got several MikroTik RB493G's acting as PPPoE access concentrators that are stable as hell and have been in service for a couple of years with no issues. In general, I've had better luck with the lower end of their product line.
- tacon 10y agoI bought this one: MikroTik - CRS125-24G-1S-RM http://www.amazon.com/MikroTik-CRS125-24G-1S-RM-rackmount-enclosure-manageable/dp/B00I4QJSIM http://www.amazon.com/MikroTik-CRS125-24G-1S-RM-rackmount-en... I haven't pushed it much, as RouterOS is very powerful but has rather a steep learning curve. I've never had to reboot it in the five months I've had it.
- madengr 10y agoI have been running Linux boxes for 20 years as my home router, but just recently bought a Cisco RV325. Sort of got tired of maintaining it, and it took allot more power. How will these smaller, embedded motherboards handle 1G Ethernet? Will be getting google fiber within next year.
- INTPenis 10y agoBeen using an APU board since they came out and I have a 1Gbps fibre connection. Unfortunately my measured speed comes to about 500/700Mbit but I belive that's due to either shitty equipment in the city wide fibre grid or my own switches/cables. I'm not really a network tech. Either way the APU handles it fine for a home network and generates no noticeable heat.
- pronoiac 10y agoGoing back to the first article: it was around $300. But as a project for my home, the lack of wifi is more frustrating.
- Aaargh20318 10y agoBut this article is about building a router, not sure what wifi has to do with it.
- cnvogel 10y agoI guess most people, when they hear the word Router, they think of their DSL-box. And those commonly have a WiFi access-point built in. (commonly also called CPE (customer premises equipment) by the telephone companies). $ ip route default via x.x.x.1 dev eno1 proto dhcp src x.x.x.x metric 1024 x.x.x.x/nn dev eno0 proto kernel scope link src x.x.x.x 192.168.2.0/24 dev br0 proto kernel scope link src 192.168.2.114 192.168.2.1 dev br0 proto dhcp scope link src 192.168.2.114 metric 1024 $ ip link (...) 2: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> (...) Network guys, when hearing the word Router think of something that holds a full BGP view... BGP router identifier 213.200.87.253, local AS number 65534 BGP table version is 7863026, main routing table version 7863026 578096 network entries using 58387696 bytes of memory 578096 path entries using 27748608 bytes of memory 344077 BGP path attribute entries using 20645160 bytes of memory 129723 BGP AS-PATH entries using 3908750 bytes of memory 1054 BGP community entries using 58126 bytes of memory 4 BGP extended community entries using 96 bytes of memory 0 BGP route-map cache entries using 0 bytes of memory 0 BGP filter-list cache entries using 0 bytes of memory BGP using 110748436 total bytes of memory Dampening enabled. 145 history paths, 277 dampened paths BGP activity 730922/149406 prefixes, 731552/150036 paths, scan interval 60 secs Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 213.200.64.93 4 3257 2823796 74946 7863002 0 0 3w5d 577951 Woodworkers, when hearing the word Router think of something that can effortlessly carve a groove into wood. So, who's right?
- chris_wot 10y ago
- shekhar101 10y agoCurious if the 120 GB SSD could be doubled as network storage acessible through WiFi?
- Sanddancer 10y agoYep. Just install the samba/nfs/iscsi/other networking daemon and off you go. About the only thing to keep in mind is that you are going to need to configure the daemon before you use it to ensure that it's not listening on your WAN address, because you probably don't wanna have your files visible to all and sundry.
- INTPenis 10y agoI'm sad they don't use dnsmasq in the article, it's a ton more easier to setup than bind and even commercial routers use it.
- tdkl 10y agoYeah, plus it can also serve as DHCP server, one less package to install/maintain.
- mdewinter 10y agoThis is also a nice simple and cheap device running OpenWRT ($25) with Wireless N, 2 100 mbit lan and USB: https://revspace.nl/GL-iNet https://revspace.nl/GL-iNet - http://www.gl-inet.com/ http://www.gl-inet.com/. I've got a about 50 deployed, managing them with Ansible, super nice and cheap. USB powered as well.
- kogepathic 10y agoIf you like that, check out the Nexx WT3020H. Very similar specs but you can get them from China for about $13 USD. Best of all, they're based around a MediaTek CPU, which doesn't have the same USB quirks as the Atheros AR9330 used in the GL-iNet. I've personally upgraded my 3020H units from 8MB SPI to 16MB, but I've also heard that you can order them directly from the factory with 16MB if your order is large enough, or they're willing to customize.
- skinowski 10y agoLooks like he hasn't hit the ip_conntrack_tcp_be_liberal problem/setting yet. Good luck with streaming Netflix with that router...
- lightlyused 10y agoCare to explain?
- skinowski 10y agoHere we go: https://www.pitt-pladdy.com/blog/_20091125-185551_0000_Linux_Netfilter_and_Window_Scaling/ https://www.pitt-pladdy.com/blog/_20091125-185551_0000_Linux...
- lightlyused 10y agoAnything recent? That is from 2009.
- skinowski 10y agoip_conntrack_tcp_be_liberal is still in kernel sources and it is enabled in distributions like openwrt. The author does not mention this, so very likely that his/her custom router will drop traffic. Recently I ran into the issue with Netflix traffic which seemed to use window scaling. In my case I did not disable scaling, but had to enable this option on arch Linux.
- Nux 10y agoI'd like to play with Linux on this multi-nic board when I get some time and money http://www.banana-pi.org/r1.html http://www.banana-pi.org/r1.html
- 35bge57dtjku 10y ago1400 - 2400 usd for that small box? Is that worth it??
- song 10y agoIt was $250 before, a lot of sellers on aliexpress just jack the price when they're out of stock instead of delisting the item.
- Decade 10y agoIt is almost 4 years since World IPv6 Launch. I’m very disappointed that, other than a few randomly timed rants from Iljitsch van Beijnum, Ars Technica has made no visible movement to IPv6. No AAAA record for Arstechnica.com, no guides to installing IPv6, and now a tutorial for setting up routers spreading FUD about how difficult it is to install IPv6.