4 ms·
Right, it was more trouble and not as cheap as a commodity router, if you paid the same for a commodity router you'd be getting much more modern wifi like 11ax.
by outsomnia 6y ago
Right, it was more trouble and not as cheap as a commodity router, if you paid the same for a commodity router you'd be getting much more modern wifi like 11ax. However for people who considered OpenWRT, there are few equivalents... pfsense but it seemed I would have just moved sideways and the lesson of the CVE was to align with desktop type distros that have infrastructure teams and more eyes.
This has two mini PCI cards for wifi, one for 2.4GHz and one for 5GHz, they don't reach comparable speeds but it is very reliable. It also has 128GB msata SSD mini PCI.
Once Linux was installed, I was surprised nmcli + firewalld is really powerful now, I could set up a multizone AP with two mini PCI cards and Ethernet routing in a couple of hours googling, and it worked stably and just how I intended. For anything else, it's a normal Linux box with the kind of normal storage and packages you don't get on commodity routers.
- champtar 6y agoI use Fedora on my VPS and up to date Firewalld is really limited compared to OpenWrt firewall3 config. Inter zone forwarding rules are still not a thing, MSS Clamping not sure, and not sure if there are anything close to OpenWrt mwan3. SFC is just legal representation, and joining it will not change anything to the development. As pointed by others, RCE (or equivalent) in package managers affected all of them, so this issue alone to switch seems an overreaction to me.
- outsomnia 6y ago> SFC is just legal representation No, as the article says >> Conservancy will help OpenWrt continue to thrive and grow as its new fiscal sponsor. That's what I think they need, to resolve their security and testing issues. > Inter zone forwarding rules are still not a thing I can believe that firewalld is not there on some things, but for what I wanted to do, including VPN service, it worked out great. I was expecting it to be a much harder ride, it would have been a few years ago. > so this issue alone to switch seems an overreaction to me. When I realized for 3 years there had been no package security on my own box I had thought was in better defensible shape than running manufacturer firmware, I realized I had been living in a fantasy. You're free to make up your own mind.