3 ms·
I recently switched to RouterOS. The learning curve was a bit high to me. I'm still tinkering with it but I got my main things working - vlans, default internet
by ThatMedicIsASpy 3y ago
I recently switched to RouterOS. The learning curve was a bit high to me. I'm still tinkering with it but I got my main things working - vlans, default internet access out via vpn, one port (internet accessible server) routed without vpn.
I learned a lot in the last 3 weeks it also helped me understand networking a lot more. Sure I had to do a lot of trial and error or figure out why things don't work but in the end it was worth it for me.
I came from 30€ OpenWRT routers with only 100mbit links which is why I upgraded.
The hAP ax³ were 140€ a piece (I use two) and the one 2.5Gb PoE port is actually nice since it powers the second router. It was a pricey upgrade compared to what was there before. I tried to buy another OpenWRT router but RouterOS seems to offer 10 times more compared to what OpenWRT can do.
I've looked at a lot of things even one of the more looked at super cheap thin client for this stuff (Fujitsu Futro S920).
At home I can't really justify a dedicated firewall.
- sgt 3y agoRouterOS has a steeper learning curve, but I find it very comforting that it is predictable/boring and I run it on hardware that is easily replacable. I have a cheap Mikrotik 1U unit.
- illiac786 3y agoMay I ask which VPN you are using? I have tried several and they are always blocked somewhere. I tried: Mullvad, IVPN, ProtonVPN. So far the only one which is never blocked is cloudflare’s WARP but I suspect it’s because it’s newish (the VPN functionality of WARP is at least, originally it was mostly about DNS). But it has severe performance problems when running on a router as far as I can tell, I suspect it has to do with MTU, but I couldn’t solve it so far. Next I was going to Google One’s VPN, but I don’t think it’s a candidate for me, I want to use a VPN for privacy, so google is probably not the best choice. The sites which are blocked are mostly enterprise login pages. As I work from home, it’s a no go for me. Secondly, I need to connect via VPN to some company network a couple of times a day and the performance of “VPN over VPN” is currently catastophic, it’s just unusable. Not sure if it’s also related to MTU…
- ThatMedicIsASpy 3y agoI use mullvad with the specific one being de-dus-wg-001 (Germany Düsseldorf Wireguard 001) most of the time. Sounds like an issue that could be solved by routing specific traffic/domains not over the VPN?
- illiac786 3y agoThat's possible??