5 ms·
This is very informative! What router would you suggest purchasing?
by markwaldron 9y ago
This is very informative! What router would you suggest purchasing?
- tortasaur 9y agoPlenty of routers can be flashed with open source third-party firmware like OpenWRT.
- jrcii 9y agoOpenBSD with CLI pf (not pfSense)
- alyandon 9y agoUsually, anything you can install a third party firmware on like openwrt, dd-wrt or tomato (shibby's version of tomato is the one I used the most). However, I gave up on consumer hardware and went with Ubiquiti for wifi AP and Mikrotik as my router. It was a bit of a pain to set up all my NAT rules in the Mikrotik router because unfortunately consumer devices do a lot of extra work behind that scenes (like setting up NAT reflection) to facilitate having NAT work painlessly. I'm perfectly content with the end result now though.
- a012 9y agoOpposite on me, I'm having a Mikrotik hAp ac and considering to use it as AP only then buy a Ubiquiti ER-X in front of it.
- alyandon 9y agoI did consider going with a pure Ubiquti solution but after borrowing a friends ER-Lite and comparing it to running RouterOS in a VM I decided that Mikrotik was a better overall fit for me from a technical standpoint. The RB3011 having a powerful cpu + the integrated 10 port (actually two different switches) switch helped push me that direction. There was something almost zen-like watching 300Mbps of traffic transiting my RB3011 and seeing it utilize 6% cpu. Ultimately, either is a fine solution and an ER-X is going to be a lot less fiddly to setup.
- swinglock 9y agoI would stay away from Ubnt routing. Which features that requires disabling packet processing off-loads and the performance impact is not well documented and varies between models and software versions. There appears to be many bugs related to off-loading as well. The below example is what finally made me decide not to consider Ubnt routers. It may be fixed now, maybe, but even if it was broken for way too long and shrouded in too much mystery, not even making it obvious which models are effected (the thread title was not always that specific either). I can't take Ubnt seriously, even for a home environment, after seeing how basic forwarding is that poor and it's not even their highest priority. The only good thing that this proves is that at least they don't censor their forums, trying to hide issues. https://community.ubnt.com/t5/EdgeMAX/UDP-packet-loss-on-Cavium-based-routers/td-p/1343012 https://community.ubnt.com/t5/EdgeMAX/UDP-packet-loss-on-Cav...
- justsomedood 9y agoI'm in the exact same scenario. Mikrotik Router and a Ubiquiti API. I do have an older 2011, the 3011's are much faster. The 3rd party firmwares aren't as powerful as mikrotik's RouterOS, and the Mikrotik hardware is really pretty cheap - though the UI is pretty bad for it. They're great once you get used to the UI
- Wheaties466 9y agoI'll never move on from a mikrotik router and UBNT wireless. also mikrotik routers comes with a standard config that comes with NAT w/ masquerade pre configured. But I agree there is a TON that is done behind the scenes. That level of granularity is what I am looking for.
- dsr_ 9y agoI built my own. These days, you can rely on Linux on fairly low-end CPUs to handle a gigabit of traffic, including IPv4 NAT, IPv6, firewalling, DHCP and DNS. For serious firepower, Jetway sells a 10 x 1 Gbit tiny fanless machine with a J1900 Celeron and up to 8GB of RAM, under $400 (without RAM or disk). All most people need is 2 gigabit ports and maybe a good WiFi interface -- although I prefer to scatter consumer WiFi boxes around my house in bridge mode.
- TheRealDunkirk 9y agoI built my own, several years ago, on a (fanless!) board like this: http://www.pcengines.ch/apu3a4.htm http://www.pcengines.ch/apu3a4.htm It has 3 NIC's, for inside, outside, and DMZ. You can also put a wifi radio on it, and make it an access point. I run a full Ubuntu on it, with local DNS, DHCP, Shorewall, etc.
- nerraga 9y agoI picked up a couple of these and I have to say I'm pretty impressed. They're pretty inexpensive little machines and they ship quick from pcengines. I have openbsd on one and ubuntu on the other. I'm using the openbsd one for dns, tftp, and a handful of projects. I was thinking about making the ubuntu one into an ap but I'm not sure about what kind of performance to expect vs my current off the shelf router. Have you used it as an access point?
- tinix 9y agoI have an older APU1C4 with two WLAN cards (WLE200NX) and it's hosting two physical APs and a few virtual ones (diff BSSID/subnet one running at 2.4 ghz other at 5). I just run vanilla Debian on it... The SD card has finally become corrupted over the years, however. When I reboot it, all my changes that were supposedly flushed to disk are lost. Thankfully I only reboot it occasionally when there are critical kernel updates. I just rsync over the filesystem in memory to facilitate restoring the previous configurations. Anyway, I run various services on it, aside from hostapd... It acts as my firewall, gateway, access point, and runs some other services like nginx to proxy some services from my LAN across subnets (like plex, etc) and motiond as a security camera monitor. I've used it as an SSH style VPN at times, in a pinch. When our WAN goes down I can simply plug my phone in to the APU via USB and tweak some iptables rules to use the LTE connection from the phone over USB network interface. I also have a newer APU2C4, along w/ an AC WLAN card and an msata drive... have had it for years just sitting there, grr. I really only got the newer one since it has AES-NI support on the processor and I can do much heavier VPN traffic, but the SD card issues have become annoying, so I think this post has encouraged me to finally set it up this weekend... Thanks :P Anyway, I wouldn't hesitate to pull the trigger on any of the pcengines stuff... Go for it! Just make sure the WLAN cards you use are well supported via hostapd. :)
- jimpudar 9y agoA very secure solution is building your own box to run OpenBSD. There are some good guides on how to set up OpenBSD as a typical NAT router / firewall here: https://www.openbsd.org/faq/pf/example1.html https://www.openbsd.org/faq/pf/example1.html I like PF a lot more than IPTables. I've found it to be far simpler to configure.
- user9182031 9y agoOnce you use PF, you can't really go back to iptables. The fact that you still can't create anchors or anything equivalent in iptables blows my mind. I can look at any of my older configurations from PF and understand what I was doing very quickly compared to iptables which is much harder to read and much less intuitive.
- phs2501 9y agoCan you briefly explain how a PF anchor is not equivalent to a iptables chain? From a very short perusal of the PF documentation it appears to be the same concept to me (i.e. a set of filtering rules you can branch to from another part of the ruleset...)
- woolvalley 9y agoUsually the issue in setting up a PC to do this kind of stuff is power consumption. Typically it's a minimum of 60W to run an idle PC, while an ARM router would run at 1-5W and have multiple ethernet ports.
- jimpudar 9y agoCorrect me if I'm wrong - I haven't tried it - but it looks like you should be able to run OpenBSD on ARM https://www.openbsd.org/armv7.html https://www.openbsd.org/armv7.html I'll check what the energy consumption on my router is. I'm using an AMD chip which I had lying around. You're probably right that it uses a bit more power than necessary. I was thinking about getting something like this: https://www.amazon.com/Firewall-Micro-Appliance-Gigabit-Barebone/dp/B01GIVQI3M/ref=sr_1_5?ie=UTF8&qid=1518825397&sr=8-5&keywords=pfsense+router https://www.amazon.com/Firewall-Micro-Appliance-Gigabit-Bare... which uses 10W. It should be easy to install *BSD on something similar.
- Mister_Snuggles 9y agoI've gone with a Ubiquiti UniFi Security Gateway. It's not too fancy (but getting fancier as updates are delivered) and does the job well. I wasn't satisfied with the VPN options, so I port-forward to an internal host and set up static routes as required.