17 ms·
Hidden Networks in TP-Link Routers
- chana_masala 5y agoAny recommendations for an ethernet only router? I do know I could use the Pi to do that, but it seems like a waste.
- jagger27 5y agoMikrotik has a ton of options for that.
- orev 5y agoQotom boxes seem to work well and can run OpenWRT, opnsense, pfsense, etc.
- adambatkin 5y agoMikrotik!
- rootusrootus 5y agoDepends on what you want from it. I've other things I hack on so I don't really have the time to hack together my own router, so I use a Ubiquiti USG. Before that I had an EdgeRouter Lite (more or less identical) for years.
- chana_masala 5y agoI thought Ubiquiti was in the news recently for something very unsavory?
- winddude 5y agoWorse still almost all new routers and mesh systems, don't have the admin interface on the device, you have to sign up and manage it through a cloud account controlled by the manufacture. If anyone can recommend a good wifi mesh system that supports wifi 6 and doesn't require signing up for a manufacture cloud account, please let me know.
- hn_throwaway_69 5y agoUbiquiti access points support meshing and you can run the controller yourself. I have AP Lite 6.
- 2ion 5y agoThey also used to be able to be set up standalone without controller (have one AP lite as well) but they removed that from their "apps" a while back (already set up APs keep working in standalone mode). This has caused me to make new AP deployments around the house using TP-Link Omada APs w/ OpenWRT firmware instead. Ubiquity is no longer worth the premium if they keep messing with the software side of things (although their hardware keeps working well).
- hn_throwaway_69 5y agoIt's still possible to setup standalone UniFi access points. I just tested it. The AP Lite 6 on the latest firmware can be set up in standalone mode with the latest Android app. You click the + icon in the top right, wait, then click other setup options -> standalone UniFi access point.
- deleted 5y ago[deleted]
- zokier 5y ago> I had to move away from Asus as they didn't provide a good hardware solution for 4G Surely a 4G USB dongle would work fine in a linux router such as those from Asus?
- petre 5y agoOh come on, a dongle? In 2021, really? Most dongles on the market are Huawei anyway and they do NAT, no bridge or modem mode. You have to pull down some pin to ground and reflash them to get actual modem functionality. I've got one in my drawer. Plus when they get hot they'll start causing issues.
- aivisol 5y agoMikrotik SXT LTE6 works for me as I am in a very remote place. RouterOS is really great piece of software, you have web based GUI, you have fully featured CLI with all things you need from router: NAT, firewall, port forward, I cannot name them all, I believe I barely use few % of what is inside. Ubiquiti UAP-AC as an AP.
- R0b0t1 5y agoI dislike the mikrotik devices because they lock the functionality of the device. I was unable to set up a pair of repeaters as anything else because of this. It was not really advertised and it's totally artificial.
- deleted 5y ago[deleted]
- SavantIdiot 5y agoHuawei AX3 does something similar. As does any Xfinity router (but I think you can turn that off) but the Xfinity mesh is actually pretty decent if you have a subscription. Similarly, in Vietnam HCMC you can connect to wifi anywhere in the city because every telco/isp router creates a mesh like Xfinity. It's not a bad idea: having wifi network everywhere, but I suspect 5G will obviate this need. Wouldn't surprise me if home routers became a thing of the past in some areas if 5G delivers. FYI: `airodump-ng` is a great way to see whats going on with any new router since it hops channels.
- treesknees 5y agoThe public hotspot systems are actually much "worse" in terms of the overheads the author wrote about. With a couple of unused SSIDs, they're just sending out a simple 802.11 beacon frame every so often and that's it. The energy cost and disruption to surrounding networks/channels must be minimal. With a hotspot, not only do you have regular network traffic flowing and causing more potential interference, your router/modem is also using more power to process the traffic and modulate that signal into the wireline side. At least one estimate I found would be around $23/year of 24/7 use of the hotspot network (it may be less with newer hardware, article is from 2014) https://www.extremetech.com/computing/185560-new-report-illustrates-how-comcasts-public-xfinity-wifi-program-actually-costs-you-money https://www.extremetech.com/computing/185560-new-report-illu...
- amenghra 5y agoToo bad fon/fonera didn’t span out. The idea was to share your access point (in a secure way) and earn credits for doing so.
- dariosalvi78 5y agoI still own a couple of foneras, I liked the model..
- deleted 5y ago[deleted]
- avidiax 5y agoThe security model for this doesn't look utterly broken. Seems that you need to go into the main router and "add" the mesh nodes. They obviously appear there by attaching to these hidden networks. But since this is configuration-free, that suggests that the mesh devices store a single static key for these networks and can join any such network. Whatever protocols exposed on that interface better not have any security problems, or you'll have a backdoor. You could make this somewhat secure by having a TPM in the mesh device that signs a challenge-response to get the hidden network key by MAC-address, but that seems too complicated. They could simply having the mesh endpoints broadcast a proprietary AP, and 'adding' by joining that network from the primary device and setting configuration. https://www.tp-link.com/us/support/faq/2532/ https://www.tp-link.com/us/support/faq/2532/
- sebow 5y agoUnrelated but kind of related: I stopped looking at TP-Link routers(and other cheap chinese routers) as soon as their android app required registration: obviously for legal reasons due to all the "good-faith telemetry"[surely not shady at all], etc. Disgusting.. ended up paying more for an asus router(related to the article: not needing 4g/5g), not perfect or made in the west nor enterprise-tier but good enough for home usage, also pretty decently supported by open firmware solutions.
- formerly_proven 5y agoSo after the Ubiquiti debacle I went out and looked for a similar combination (solid hardware + not-too-annoying software). After briefly considering Mikrotik (which has issues with ac (wifi 5) and no ax (wifi 6) support) I settled on Grandstream for now. They don't just make phones but a small set of fairly nicely featured wifi APs for ok prices. Hardware seems solid, Software not annoying. I've bought a few pieces from TP-Link when I was a poor student, not too bad as far as datasheet-specs per dollar goes, but the firmware was always exactly the kind of trashfire you'd expect and the hardware exactly what you paid for (not much). Definitely the kind of device you have to try real hard to fake your surprise when you find dozens of unpatched CVEs and no firmware updates.
- andrewxdiamond 5y ago> So after the Ubiquiti debacle… I was in this same boat, but did you know that data breach was completely fabricated by a disgruntled employee? They didn’t actually leak any data or had any real breach. It’s still not great that this was doable, but at some level, someone has to have the keys to the kingdom. https://news.ycombinator.com/item?id=29411775 https://news.ycombinator.com/item?id=29411775 I think Ubiquiti makes really nice gear for prosumers, and it is completely unfair that their good reputation has suffered so much over this incident.
- bpye 5y agoThere was more to the debacle, for example, putting ads for their other products in the controller UI.
- sgarman 5y agoOr the new version of their controller software missing huge chunks of functionality causing you to keep switching from new UI to old UI depending on what you needed to get done.
- universenz 5y ago
- aquafox 5y agoI'm the one who made the original observation of the hidden network in the TP-link forum: https://community.tp-link.com/en/home/forum/topic/170160 https://community.tp-link.com/en/home/forum/topic/170160 Took a long time until TP-Link offered a firmware update to disable the mesh functionality. Happy to see the issue mentioned here.
- aetherspawn 5y agoI have been more than happy with both my tp-link AX50 and tp-link AX11000. The most stable routers and best router firmware that I’ve owned.
- louloulou 5y agoNot sure what they mean by "build my own router", it's easy enough to flash open firmware on a lot of tp-link models. https://download1.dd-wrt.com/dd-wrtv2/downloads/betas/2021/12-20-2021-r47900/ https://download1.dd-wrt.com/dd-wrtv2/downloads/betas/2021/1...
- aquafox 5y agoTried it, but Wifi speed on the Archer C7 was significantly reduced.
- gsich 5y agoOpenWrt probably has to do everything through the CPU. Not hardware accelerated like in the stock firmware.
- wtallis 5y agoUsually a lack of hardware acceleration support is a problem on the wired side, where a lot of consumer routers rely on NAT offload in the Ethernet switch, without which a cheap MIPS core cannot offer good WAN to LAN throughput. WiFi NICs are quite self-contained these days with their own complicated firmware, to the extent that it is often hard to move enough of the processing back to the CPU even when you want to (such as to do smarter airtime scheduling than the proprietary firmware that runs on the NIC).
- louloulou 5y agoDo you know the reason? In my case I just had to boost the power for the wifi a bit in the settings to improve the speed. But I never ran it with the original firmware, so have no point of comparison.
- tannr 5y agoit sounds interesting, however manufacturer claims it can stop functioning if you install "wrong" locale (whatever that means) while I cannot get how hardware can die from install different "driver" warnings like that put me off from using tp-links. Perhaps I'll buy a cheap tp-link and give it a try just as experiment to see how far I can get
- mhitza 5y agoThis type of whackery is (the primary reason) why I try to buy computing devices on which I can flash a clean OS (OpenWrt/DD-WRT for routers)[1]. It sucks because it limits my choices down to a few, but at the same time I feel like I don't throw out money at abandonware. [1] don't even get me started on TP-Link releasing routers with the same name but v2/v3/2020/2021 update where it's hard to even know if I'm buying the one that supports the custom OS flash.
- azinman2 5y agoThe author touched on right of repair. I’d love to see a law requiring all devices to either be supported, or if being sunset, being required by law to provide tools/source/schematics to take over the device and extend its utility beyond the manufacturer’s willingness. Particularly a last firmware that disables anything requiring phoning home to continue to function. We saw that with OnHub recently, when after only 6 years Google decided to render a lot of devices e-waste. The least they could do is recycle them for you at their own cost.
- msla 5y ago"Right of repair" being focused on hardware is a neat little trick to enforce the illusion that changing software is beyond your rights as a consumer. Yes, you can fix the antenna when it breaks, and focus on how hard the fight was to get the right to fix the hardware you own... which you don't own as long as the company uses software to control what the hardware can and cannot do. But you sure physically own those mostly-useless atoms real good!
- R0b0t1 5y agoI had no idea it was focused on hardware. It applies to software too.
- tablespoon 5y ago> "Right of repair" being focused on hardware is a neat little trick to enforce the illusion that changing software is beyond your rights as a consumer. Is it a trick, or just limited imagination? My impression is that "right of repair" came from mechanically-minded people seeking to maintain their traditional ability to repair physical devices in the face of corporate hostility (e.g. farmers vs. John Deere). > Yes, you can fix the antenna when it breaks, and focus on how hard the fight was to get the right to fix the hardware you own... which you don't own as long as the company uses software to control what the hardware can and cannot do. But you sure physically own those mostly-useless atoms real good! This seems more of software-centric Free Software attitude, which is not a place someone with mechanical skills but not very strong software skills is likely to arrive at themselves.
- howdydoo 5y agoIf you have a home router, do yourself a favor and install OpenWrt. You won't have to worry about the UI lying to you.
- encryptluks2 5y agoMany TP-Link products are absolutely terrible. Their Mesh products at Costco, you have to use an app on your phone to manage them and they are tied to an online account so presumably they are shipping your network info back to China. They won't even let you change your login email address once you've registered.
- orangepurple 5y agoCheap $20 TP-Link Wireless AC routers are capable of reliably running latest builds of DD-WRT if you turn the link power down. I run my TP-Link TX power at the minimum allowable setting. You can count on a reliable 866 mbps!
- 3np 5y agoThat last point was so infuriating. Was home visiting family a while back and helped them set up their new TP-Link network. Reluctantly installed the management app on a device of mine, and made my family member admin with full permissions (or so I thought). Only after I left town did we realize I'd have to hand them my account to actually give them the admin rights.
- throwaway180118 5y agoNot only does their Deco mesh force you to use their cloud app, but there's no 2FA.
- tannr 5y agohaving exactly same expirience with tp-link, firmware is always outdated and I find it at every flat for rent (long-term or airbnb), hotels small coffee-shops etc. So much space to have fun :\ I've moved to Mikrotik and don't know all disadvantages I have, but I am super happy about configuration options they provide. Happy to find alternatives here in the thread
- chronogram 5y agoLast week I bought a TP-Link AX55 and went through the settings and enabled all the neat things and disabled all the regular consumer ease of access things (WPS, meshing things), and the only hidden networks in my area with the same app are several decibel away with a different MAC address. Either it’s not around in the newer models or it’s part of one of the regular consumer ease of access things.
- estaseuropano 5y agoWhy disable mesh? I thought that will ensure the devices work together rather than compete (looking at fritzbox, but it seems they are all compatible).
- wtallis 5y agoA mesh network is entirely different from and inferior to a network with multiple access points each with a wired connection. If you've built your network to be the latter, you don't want anything to start acting as a wireless repeater and wasting lots of airtime.
- fomine3 5y agoSome people use term "wired backhaul mesh". It seems that it's just a seamless roaming but that's what I want.
- chronogram 5y agoExcuse me for the late response. I logged into the router and it’s called their trademarked “TP-Link OneMesh”, it’s likely useful if you buy more TP-Link products and want easy integration, however it’s unnecessary for my home. You’re lucky with your Fritzbox, my area has no competition in the ISP market which means I’m stuck with overpriced low quality, from the copper to the modem to the customer service.
- latchkey 5y agoI just got the AX55 as well. Fast modern router for the price. Pretty happy with the purchase, despite the lack of openness.
- lordnacho 5y agoI had a related problem with their PowerLine TPA-4220 devices yesterday. It turns out there's a DHCP server on it that you can't turn off! It's supposed to be smart and know when there's another DHCP server on the network, but it appears that this sometimes doesn't work. So I found that my laptop sometimes ends up configured on the wrong subnet, which of course kills the internet connection. The thing is, the web interface does not have a setting to shut off the rogue server. If I hadn't done a CCNA I don't think I would have ever figured this out. I don't know what ordinary people do when this happens to them.
- ceejayoz 5y agoI had a similar experience with my Netgear Orbi; they have a dual 2.4/5 GHz network on the same SSID, but certain devices just cannot handle it (including apparently Facebook's Oculus and quite a few smart home devices). Turns out you can split them up into separate SSIDs, but only by telnetting into your base station and each satellite and running some cryptic commands on each. It used to be possible via the web UI, but they just... dropped it.
- easton 5y agoOur network at home has both 2.4 and 5 on the same SSID, with no issues (and I have an oculus). Is this just a Netgear thing?
- ceejayoz 5y agoNo clue. Very possible it's specific to the Orbi, or possibly the spots in our house the Oculus and LG washer/dryer are located - perhaps the signal strength is just iffy enough they hop between the two frequencies sometimes. A full restart of the devices helps, but usually only for 15-30 mins.
- icebergonfire 5y ago> A full restart of the devices helps, but usually only for 15-30 mins. This rings a bell. Do you have an Orbi mesh by any chance? I used to experience this with specific cheap IoT devices that were constantly hopping to different Orbi satellites. There is an option somewhere in the UI to bind a device to one specific access point, and you can tag a device as IoT or smart speakers which (based on feeling) seems to change the steering heuristics to something that stops this from happening.
- 3np 5y agoA bit of a tangent, but I recently discovered GL.iNet[0] and ordered a couple of routers and hotspots. HK vendor for network devices running forked OpenWRT with a bunch of extras and customization. I haven't had the time to dive deep enough into all of the code yet, but so far I'm very optimistic. Not perfect; some of the more interesting functionality (like site-to-site VPN) is tied to a proprietary closed SaaS with associated telemetry (and maybe even backdoors, intentional or otherwise). The Wireguard setup is for some reason (legacy?) not using the OpenWRT WG-interfaces but set up using custom init scripts. And getting anything else than OpenWRT/LEDE running on them with full hardware support will probably be a significant effort. I'm a bit wary of using the stock OS without compiling it myself because, well, you know. Still, the sources are provided (including instructions on how to customize and compile your own OS/firmware). The locked-away functionality can be ported/unlocked if you're up for it. They fully support users hacking their devices all they want - and stuff like this[1] shows some hacker DNA. Out of the box the hotspot is by far the best I've found in the price-class. The mudi's pretty cool; pocket wifi with swappable miniPCIe 4G/WiFi cards and a small dongle for Ethernet. So one could make it into a fully customized road-warrior bridge for any WiFi/Ethernet devices, or whatever other shenanigans you can imagine with that. I really hope they steer course on the right track and don't fall to the same fate as Ubiquity. As mentioned I haven't battle-tested them extensively yet but so far I can warmly recommend them. [0]: https://www.gl-inet.com/ https://www.gl-inet.com/ [1]: https://github.com/gl-inet/portal-detection https://github.com/gl-inet/portal-detection
- TechBro8615 5y agoI’ve got one of those, it’s pretty nice. Last I checked (multiple years ago) it phoned home to a .cn address by default. I don’t remember the details – please verify for yourself.
- 3np 5y agoI will! Without the cloud stuff, the only thing I found so far was stuff like this, which I remove myself but is fully understandable - if you want to do zeroconf connectivity-checking on devices used in Mainland China you don't have much options otherwise. 8.8.8.8 certainly won't work. https://github.com/gl-inet/gli-pub/blob/326341dc5c14a256562e47c186135100c3ef7d70/mwan3/files/etc/config/mwan3#L9 https://github.com/gl-inet/gli-pub/blob/326341dc5c14a256562e...
- synergy20 5y agoBuy routers that can work with Openwrt, period. TP-Link actually has quite a few(not the newest models though, but the not-newest-model should work for 95% of the customers) that runs openwrt well. All my routers are running non-vendor firmware(e.g. openwrt) for the last 15 years, never had any troubles.
- jorvi 5y agoSadly OpenWRT doesn’t support band steering.
- jjulius 5y agohttps://forum.openwrt.org/t/dawn-band-steering/71767 https://forum.openwrt.org/t/dawn-band-steering/71767
- mlyle 5y agoYou can install DAWN and get band-steering and controlled migration between multiple APs.
- paavoova 5y agoIf you set the SSID and password identical for both bands, the clients should prefer to negotiate the optimal band. I just checked and all clients save for some legacy devices on my OpenWRT router are on 5GHz. So I'm now wondering for which cases is band-steering helpful?
- kiwijamo 5y agoClients don't always do this automatically. My Arch Linux laptop would often select 2.4GHz in places where 5GHz offered a much better experience. Generally it will start on 5GHz when it is close to the router, fall back to 2.4GHz when it moves far away, and (sadly) it doesn't go back to 5GHZ when it moves back closer to the router. Apple devices were pretty good, automatically choosing and switching to the best bands at all times with behaviour much similar to that seen on mobile phones. For this reason I prefer the AP to manage the band steering as it means all devices are connected to the best band. Leaving it to the clients results in a hit and miss experience depending on how well the decide operates. I live with other people who own all sort of different devices so it's not possible for me to say "OK this network is only for Apple devices", I have to ensure thr WiFi works for all sorts of different devices.
- radicaldreamer 5y agoEero seems like a company which makes simple, plug and play mesh routers and doesn't seem to pull anything funny with their equipment.
- yjftsjthsd-h 5y agoEero is owned by Amazon now, so I'm not sure how far I'd trust that. Like, I trust them to be technically competent, but not to act in my interests.
- stordoff 5y agoThe main issue for me has been forced updates, which can fire off at inopportune times. They have been very stable though.
- submeta 5y agoI aggree that the situation the author describes is unacceptable. But I am wondering why the author does not value his personal time. I can‘t help but think of opportunity costs. He spends a lot of time writing this article, reverse engineering backups and whatnot instead of shelling a hundred dollars to get a new device? I see this pattern so often in the tech world.
- subhro 5y ago> But I am wondering why the author does not value his personal time. Maybe, because it is fun reverse engineering stuff?
- submeta 5y agoI agree. I like tinkering myself. But then why mention avoiding spending a hundred dollars for a new device, but spending a couple of hours as if those hours are worth less than said amount of money.
- adamauckland 5y agoI'm not sure if you're trying to be funny for jokes, but we all know you don't get paid for hours which you can't bill, so...
- yjftsjthsd-h 5y ago"Time you enjoy wasting is not wasted time."
- rgj 5y agoOut of principle maybe?
- A_non_e-moose 5y agoShould customers of a product be forced to either spend 100$ for a new product and generate more ewaste, or tinker with their device leaving it in an unsupported perhaps even out of warranty state? Maybe some people are happy with either option, but it sure is unethical to force that choice, especially when all the effort it could have taken from the manufacturer was to add a boolean flag. I'd complain too, not everyone is in the same situation, and this is dodgy behavior anyway regardless of me liking the workarounds or not, simply having to workaround is bad enough in principle.
- cbdumas 5y agoWhile we're talking routers I'll plug Mikrotik. Some basic knowledge of the Linux networking stack is required so they're not great for a general user, but for ~$50 I got a device that handles my setup with ease (Ipv4 over PPPoE and IPv6 over 6rd) and I'm seeing throughput significantly higher than my previous router which was a Zotac mini computer running pfsense. If you are more toward the power user / networking nerd end of the spectrum I'd recommend Mikrotik.
- blibble 5y agoyeah their stuff is pretty good but as you say it's a pretty thin layer on top of the Linux stack (e.g. you have to understand iptables else you'll get nowhere)
- zamadatix 5y agoThey also make a great 16 port SFP+ 10G switch (CRS317-1G-16S+RM) usually available for ~$350 which is nice for a prosumer setup. They also have a 10/100/1000/2500/5000/10000 RJ45 transceiver which is nice because it lets you migrate things over without having to upgrade everything or buy a separate multirate gigabit switch. I do my actual routing on a Ubiquiti EdgeRouter though I've used MikroTik there as well in the past. I avoid most other Ubiquiti products though, particularly the UniFi line. In both cases HW accelerated NAT and routing greatly outperforms an unaccelerated ARM/x86 Linux/BSD PC. Particularly when it comes to new session latencies not just saturating the bandwidth.
- discardedrefuse 5y agoAT&T has been doing something similar for years. https://forums.att.com/conversations/att-fiber-equipment/possible-vulnerability-pace-5268ac-leaves-wifi-radio-on-with-no-security-even-when-is-set-to-off/5defd50fbad5f2f6062df285 https://forums.att.com/conversations/att-fiber-equipment/pos...
- clajiness 5y agoHard to beat OPNsense on Protectli machines with your favorite flavor of networking hardware (Unifi, Microtik, etc).
- xanaxagoras 5y agoI did this during COVID and it took a lot of time and learning, but now I feel like the God of my network and I can do cool stuff that wasn't possible on my old gear. I've read that Protecli boxes are re-branded Qotom machines and I'm sure you can get the same setup for a few hundred less but I'm glad I went with them for the support and coreboot OOTB.
- clajiness 5y agoTotally on board with the US-based support. I’ve called them once and they were fantastic. As soon as they offer a model with 10Gb NICs, I’ll buy one of those, too. As for god mode, I agree. Super customizable and everything works properly. I grew tired of the nonsense routing ubiquiti kept releasing, went to pfsense, and right to opnsense.
- protectli 5y ago
- robocat 5y agoMy solution is to buy a reliable WiFi Access Point and plug that into the router, and just disable the router’s WiFi. That way I can choose a router for the features I need (or use a small PC if I wanted to do something tricky or needed high performance). I think that would fix the problem with the TP-Link (albeit costing far more). I use Unifi UAP-AC-LR for the AP, because they are easy to set up from an Android phone, are not expensive, are not flakey, can be mounted in a location to optimise WiFi reception (powered from Ethernet cable by included DC injector), can be easily moved to new ISP or house, don’t require a controller, and they just keep working. Ubiquiti have made some dick moves, but their AP and point-to-point hardware has been solidly reliable and relatively simple to configure.
- m45t3r 5y agoNot trying to defend TP-Link or anything, but I recently bought a pair of mesh router from them and they work very well. BTW, this hidden network probably uses another protocol (for the OneMesh). It is the 802.11s (https://en.wikipedia.org/wiki/IEEE_802.11s https://en.wikipedia.org/wiki/IEEE_802.11s), that uses its own encryption method based on Simultaneous Authentication of Equals (SAE) (yeah, that is the same as WPA3, however it came before it). It shows as hidden network on Wi-Fi Analyzer, but the network is not actually hidden in the same sense of a hidden Wi-Fi network: this simple happens because 802.11s has no concept of SSID. The authentication of new devices happens when you pair a new router using the application available on Android/iOS (it has a web interface too but AFAIK it doesn't allow adding new mesh routers to the network). So it seems pretty secure for me, at least sans some security bugs that I am sure that the device should have. Doesn't bother me too much considering that most bugs that I saw on those consumer routers generally comes from the security from things like administration pages and not the Wi-Fi network itself (unless it is something like KRACK that affects all devices implementing the protocol). Yeah, it is still pretty sh*t that they enable this by default, but if the router from the author of blog post is from one of their lines of mesh routers I do think this is kinda of made by purpose, because using multiple routers devices is kinda of the idea of a mesh network.
- ignitionmonkey 5y agoThanks for the info. That makes sense given the "11s" configuration I found for those SSIDs. The router is not in their mesh line AFAIK, though most of their home products now support OneMesh, so that line is a bit blurry. To clarify, I like TP-Link products too. Their PowerLAN products so far have been the most reliable for me and the router's been solid too. It's just really disappointing that an almost (for me) perfect product has this very simple software flaw without any solution other than to hope the manufacturer decides to fix it at some point. I had the same issue with Asus routers, but they were smart enough to open source their software and let others fix pretty much everything for them.
- ignitionmonkey 5y agoJust to correct myself, "11i" is actually what I saw in the configuration and it's the "Beacon Type". WiFi Analyzer shows them as 11n (2.4Hz) and 11ac (5GHz). https://jahed.dev/2021/12/20/editing-tp-link-router-backups/ https://jahed.dev/2021/12/20/editing-tp-link-router-backups/
- tomxor 5y ago> they didn't provide a good hardware solution for 4G. That's right, my street doesn't have fibre despite being in the tech startup heart of London. So here I am with a TP-Link router. Same situation, another UK city center, without fiber, and with an incredibly noisy, effectively useless 1Mbit ADSL line. I really wanted something running an open firmware, but for LTE you really need something >= Cat10 for reliable home broadband, and there isn't a lot of choice at this end excluding crazy expensive commercial stuff - It's either Netgear or Huawie. After learning way too much about LTE, I ultimately settled on a Netgear M2 (MR2100) and a couple of magnetic MIMO antennas out the window, which has worked very well, and the firmware isn't terrible. I was initially repelled by the high price ~£400, but you really need the 5x carrier aggregation of Cat10 to get something reliable, the cheapo Cat4/6 TP link stuff is not worth the time IMO. [edit] At the time there was one industrial LTE router manufacturer that caught my eye "Teltonika" which ship with OpenWRT as the official firmware! but at the time they only had a Cat6 modem. They now appear to have added a Cat12 one! "RUTX12 and it's price is not dissimilar to the Netgear M2: https://teltonika-networks.com/product/rutx14/ https://teltonika-networks.com/product/rutx14/ If I was buying again id give this a shot.
- ddtaylor 5y ago> I had to move away from Asus as they didn't provide a good hardware solution for 4G. That's right, my street doesn't have fibre despite being in the tech startup heart of London. So here I am with a TP-Link router, spamming unwanted waves. Do I really have to drop another £100 on new hardware just because TP-Link doesn't want to offer a boolean flag? What a waste. Maybe it's finally time to build my own router. I'm pretty sure building your own router is going to cost more than $100.
- deleted 5y ago[deleted]
- AtNightWeCode 5y agoMy ASUS router has enabled remote access after updates at multiple occasions. So much for ASUS. Is there a tech brand that only sells stuff with no bs? I would gladly by a "pure" router with no branded features. Would also gladly buy a TV without any of the "smart" stuff.
- globular-toast 5y agoI was running a TP-link access point (not router) and was surprised to notice the "hidden" networks. I thought I was misinterpreting the readings at first, but the installed that beta firmware and it allowed me to disable them. This improved connectivity with some devices. I shortly after switched to a Ubiquiti access point which has been a lot better. I think it's really important for people to know the difference between routers, switches, access points and modems. I've noticed that even geeks these days seem to have forgotten or maybe never knew. This has nothing to do with routers whatsoever. You can pick and choose the best from each category. No need to go "all in" on one device and accept tons of compromises.
- r1ch 5y agoFor those curious about the "Wi-Fi spam" comment: even though nothing is connected to the network and it's a hidden SSID, it still has to broadcast beacons every 100ms. The 802.11 standard says beacons must be sent at the lowest rate the AP supports, so your ~350 byte beacon at 1mbps (2.4 GHz) uses around 5% of the frequency. It doesn't take many SSIDs on the same 2.4 GHz channel to make the throughput fall through the floor. Beacon spam is one of the reasons why 2.4 GHz is practically unusable in dense environments these days. Thankfully for 5 GHz this isn't as bad since the lowest rate is 6mbps and the signal penetrates less. Some routers have the option to disable 802.11b which raises the minimum 2.4 GHz beacon to 6mbps as well, but unless everyone does this it won't make much difference.
- londons_explore 5y agoWould there have been a better way to do design beacons? The general problem is a device needing to advertise itself for other devices to connect to, other devices which might not be capable of any faster rate... Beacons being 350 bytes is pretty stupid though... They could have been 20 bytes long, saying "I'm a device with mac address XXX, plz contact me to know what services I have on offer".
- r1ch 5y agoIn retrospect, definitely. But a huge part of why Wi-Fi is so successful is the wide compatibility, so we're stuck with a design that is 20+ years old. Beacons also serve to do power saving wake-ups and various other things these days, and there's room to optimize them if the Wi-Fi alliance were stricter - some vendors are broadcasting their manufacturer and model (and sometimes serial number!) every 100ms as well as lots of other unnecessary information elements.
- tradertef 5y agoThere is out-of-band discovery for devices that support multiple bands. That should help in 6 GHz band but it looks more and more that 2.4 GHz will be only for discovery in the future.. https://www.extremenetworks.com/extreme-networks-blog/the-off-road-trail-to-6-ghz-ap-discovery/ https://www.extremenetworks.com/extreme-networks-blog/the-of...
- hnlmorg 5y agoI'm not at all surprised by this article because I recently purchased a new TP-Link router (Archer something IIRC) and it's quite honestly the worst router I've ever run. I goes down several times a day, dropping all network traffic that isn't TCP. Thus DHCP, UDP DNS and ICMP echo all fail. My old router is > 5 years old Asus (possibly as much as 10 years old!!) and literally held together with electricians tape. I've had an array of physical failures due to age from the antenna no longer standing up to the power button no longer functioning and I've used electricians tape to fix all of them. But for the stuff that matters it still works extraordinary well. So I figured it was only a matter of time before that router died completely and I'd need a new one. And I figured it has been so many years since I last upgraded that my new device should be amazing in comparison. But man was I wrong. After getting kicked out of an important Zoom call last week (and weeks of issues and debugging too) I finally lost my temper, unhooked the router and went full on Office Space[1] on it. I'm now back to running the old router. A router that's older than both of my kids. A router that had earned its retirement. I'm going to replace it with a Draytek device in the new year. Given I'm mostly working from home these days I want something reliable. But I'm also thinking Draytek will last me another ~10 years so it will work out cheaper than the TP-Link crap. In fact I'll never buy another TP-Link device again. [1] For those who haven't seen Office Space: https://youtu.be/fjsSr3z5nVk https://youtu.be/fjsSr3z5nVk (also definitely watch the movie. It's great!)
- ei8ths 5y agotp-link is pretty solid but i recently went back to asus for their mesh and UI, its just incredibly better with more features. I never saw hidden networks on my tp-link ax 3000, what i did see is lack of firmware updates, it seems like my model was abandoned.
- deleted 5y ago[deleted]
- mastazi 5y ago> Maybe it's finally time to build my own router Can anyone link a good "getting started" guide for this? I have experience managing servers but not managing network appliances, so I'm looking for a relatively gentle intro... Edit: I'm not asking about how to install OpenWRT on an existing router, I'm looking for a guide on how to build a router from general purpose hardware - in the same way that you can build your own NAS etc.
- mshockwave 5y ago+1 on the same question. I actually saw some posts about x86_64 based router the other day (didn't mention how to build it though), wondered if that's a viable solution.
- mastazi 5y agoI saw a similar one for a Raspberry PI based router, but I don't know if that's a good start or not, I would still like to hear from someone with experience: https://www.seeedstudio.com/blog/2021/06/11/how-to-build-a-raspberry-pi-router-step-by-step-tutorial/ https://www.seeedstudio.com/blog/2021/06/11/how-to-build-a-r...
- kube-system 5y agoOPNsense installs quite nicely on most x86 hardware. I have had a very good experience running it on a repurposed low-powered used 1U server appliance with a couple of good quality networking interfaces. It's so easy, all you need to do is install from media, and configure one interface as LAN and the other as WAN. Plug in your internet into one interface and your LAN into the other. Configure it like you normally would configure a router, and you're done. I'm running mine on a very old dual-core i5 with 4G of RAM and a 16GB SSD, and even this is overkill.
- mastazi 5y agothank you! Years ago I remember looking into pfSense which appears to be related to OPNsense. Looking into it now!
- Namidairo 5y agoI've found similar networks when inspecting other brands of router. It's not an uncommon sight these days with vendors and their 50 different proprietary mesh negotiation protocols. While I did wonder how they generated the SSID (In this case it was 128-bit hash, underscore then the vendor name), I didn't really look too hard into it as my goal was wiping out the vendor's firmware anyway. I did spot some features like configuration sync that made my "this'll be written properly..." senses go off though. I do note that there is a Wifi Alliance spec for this kind of thing now though. It's called Wi-Fi EasyMesh. I can't imagine anyone apart from actual SoC vendors taking the effort to implement it though, as it's a 163 page specification, available only on request or by alliance members. (Well the vast majority of chipset manufacturers are members, and the specifications have leaked anyway) Edit: Scratch that, there were actually 3 different hidden SSIDs. The one mentioned above was a hidden IoT SSID, the other two were VendorMesh_hash and VendorMesh_WPS. :S
- lsc36 5y agoI once bought a TP-Link Wifi router as it was pretty high-speced at the time and people recommended it. I was happy with it until it hijacked my HTTP connection to tell me there's a firmware update. Will never consider their products again.
- hda2 5y agoWe had the misfortune of having a large number of tp-link devices being installed in our network (a large residential building) and those devices have been nothing but a source of trouble ever since they were installed. They seem to be talking with each other and overriding their configuration to the point where I had to segregate them in their own little NATs (with the complete blessings of the building manager). Only then did the shenanigans stop. That, in addition to their ever-dwindling configuration options, is why I refuse to buy from them anymore. There (much) older devices were fantastic though.
- thegototechguy 5y agowow. i just noticed when i debugged the settings. Thanks for giving this insight
- hatware 5y agoIf you've never tried a prosumer router, TP-Link is a great intro. I recommend a standalone router with a standalone access point, rather than a combo like we see so often on the consumer side. I'm so glad I got an ER605 to tinker with while waiting for my Mikrotik to come in.
- dbeley 5y agoI've had very good experience with Gl-iNet products. They have good hardware, very good openWRT support (the official firmware is based on openWRT) and are beefy enough to be used as home routers even if they are marketed as travel routers.
- southerntofu 5y agoDo all GL-iNet products support mainline OpenWRT? or is there exceptions?
- dbeley 5y agoBy comparing https://www.gl-inet.com/products/ https://www.gl-inet.com/products/ with https://openwrt.org/toh/start?dataflt%5BBrand*%7E%5D=inet https://openwrt.org/toh/start?dataflt%5BBrand*%7E%5D=inet the OpenWRT support doesn't seem to be 100% but almost all of them are. I personally own an AR750S and a MT300.
- southerntofu 5y agoThanks! In your experience, are they reliable with OpenWRT? My experience with commercial routers and access points (consumer grade) is that they need rebooting about every month because they start failing silently (eg. lights still on but wifi cannot be detected by clients).
- dbeley 5y agoYes very! I use the AR750S as my home router and I never had to reboot it manually in any situation. Though the updating process can be more streamlined, I had to redo all my configuration when updating from openWRT 19 to latest 21 (could have been my own mistake during flashing, at least I have firmware updates).
- windex 5y agoI have a box full of old consumer wireless routers. I am not sure why most of these devices are so flaky. These days I separate the packet routing from the wifi part and that has made things a little more sane.
- KETpXDDzR 5y agoI can highly recommend looking at the router database of OpenWRT. I had bad experiences with DD-WRT. Mostly stability issues. According to my research, OpenWRT doesn't have as much functionality or router support. But, it's very stable. My favorite feature is both is that you can easily add virtual APs. E.g., I have one virtual AP with net isolation (no access to other networks, Internet only) and clients can't see each other.