The Ars guide to building a Linux router from scratch
arstechnica.com
arstechnica.com
PFSense is the same thing below the hood, but with a web front-end and plugins.
Most off the shelf wireless routers work fine as an access point, but are quite bad as a router. So you can just plug your old wireless router into this thing (with DHCP etc turned off), and your whole setup will be much better.
People are running FreeBSD and Linux on it:
http://www.daemonology.net/blog/2016-01-10-FreeBSD-EdgeRoute...
With the electricity prices the way they are in the US, no way I'd run something like that over a proper x86 as in the article that can saturate a 1Gbps and manage decent disk IO.
"x86" covers a lot of ground. Certainly, in the "about $100" range, your choices in X86 land can't saturate 1Gbps either. The x86 box in the article was $280 total. About the same cost as the logical upgrade to the EdgeRouter Lite...their ER-8, which can saturate 1Gbps, and has 8 ports.
http://www.openbsd.org/faq/pf/example1.html
As a point of comparison, the iptables syntax as shown in the Ars article is far harder to grok at first glance than either of the pf examples. For example:
pass in on egress inet proto tcp from any to (egress) port { 80 443 } rdr-to <ipaddr>
vs: -A PREROUTING -p tcp -m tcp -i p4p1 --dport 80 -j DNAT --to-destination <ipaddr>:80
-A FORWARD -p tcp -d <ipaddr> --dport 80 -j ACCEPTIt also sounds like it's getting replaced[0]. My guess is that we will see iptables around for a long time after it's been deprecated. ifconfig, for example, is deprecated[1] yet it's still around and being used.
[0] https://lwn.net/Articles/564095/ [1] https://lists.debian.org/debian-devel/2009/03/msg00780.html
See also dladm in illumos as another variation on a theme.
For example, `ifconfig eth0 down` becomes `ip link set dev eth0 down` and `ifconfig eth0 192.168.1.2` becomes `ip add add 192.168.1.2/24 brd + dev eth0`; I had to look these up to make sure I had the correct syntax.
Okay, the actual command is `ip address add` and not `ip add add`, but it allows extreme abbreviation at the expense of discoverability.
Generally speaking, that means that there's one canonical way to do something instead of a bunch of different ways like in Linux (think 'ifconfig' vs 'ip'). Of course, FreeBSD ships with three different firewalls[0], so that's not always true.
There are downsides, of course. A freshly-installed BSD has a lot less stuff than a freshly-installed OpenSUSE/Ubuntu/Fedora/etc.
I like those automatic security updates and network traffic analysis...
I ended up going with the APU2B4 board (an upgrade from the APU1D mentioned in the article.) I put pfSense on it, and it's been running perfect for a few weeks now.
Even that board is probably massive overkill for most people. I have 50/50 internet, and with full bandwidth used by torrents, a VPN and ssh session open to the router, and the web interface open, I'm still only getting about 10-15% CPU.
The APU boards are nice too; I thought about going for one when I was shopping for a better router and slapping OpenBSD on it. Ultimately I went with an Ubiquiti ERL, mostly because I didn't really want to buy an RS-232 cable, but the PC Engines boards are probably one of the best fully-DIY options you can get.
These Shenzhen factories are somehow getting these Intel CPUs for next to nothing. Factory price for the i5 model was about $100.
APU2C4 http://pcengines.ch/apu2c4.htm
case1d2blku http://pcengines.ch/case1d2blku.htm (black cases run cooler)
http://pcengines.ch/ac12vus2.htm (power plug)
db9cab1 http://pcengines.ch/db9cab1.htm (serial null modem)
I already had a USB->Serial adapter. For storage I used a 32GB Class 10 microSD card in a SD adapter, which I found acceptably fast (and faster than my usb sticks.) Note, if you want to run Snort or Squid, you might want a small SSD, but for a router-only it is overkill.
I assembled the board+case, wrote the 4gb nano-bsd image of pfSense to the SD card, and booted right up.
Total cost was < $200 USD.
edit: I noticed you mentioned wireless...I've heard the wireless support in pfSense using PC Engines boards is better than it was, but I prefer to use (multiple) separate APs for wifi. One of the APs I'm using is: http://www.amazon.com/TP-LINK-TL-WA801ND-Wireless-300Mbps-Re..., which I've had no issues with. I prefer the ability to upgrade/replace my APs without messing with the router, and my router is in the basement, while the APs are on other floors.
I'll probably move to 5GHz wireless later this year, and this separation allows that.
""" ...and whether you want automatic security upgrades. (Spoiler: Yes, you do.) """
I've got a about 50 deployed, managing them with Ansible, super nice and cheap. USB powered as well.
Best of all, they're based around a MediaTek CPU, which doesn't have the same USB quirks as the Atheros AR9330 used in the GL-iNet.
I've personally upgraded my 3020H units from 8MB SPI to 16MB, but I've also heard that you can order them directly from the factory with 16MB if your order is large enough, or they're willing to customize.
I do not run extra services like Squid or Snort, so most of my "writes" are probably within my massive 1GB of RAM.
How will these smaller, embedded motherboards handle 1G Ethernet? Will be getting google fiber within next year.
Either way the APU handles it fine for a home network and generates no noticeable heat.
[0] http://www.irongeek.com/i.php?page=videos/houseccon2015/t302...
My first experience with MikroTik products. Not good.
In general, I've had better luck with the lower end of their product line.
MikroTik - CRS125-24G-1S-RM
http://www.amazon.com/MikroTik-CRS125-24G-1S-RM-rackmount-en...
I haven't pushed it much, as RouterOS is very powerful but has rather a steep learning curve. I've never had to reboot it in the five months I've had it.
I believe the syntax for writing QoS on FreeBSD and OpenBSD provides very good expressive capability [1]. By using tagging [2], one can assign QoS priority to anything that a firewall rule can define.
Having used FreeBSD QoS on dial-up, ISDN, DSL and cable over the years, it is this expressiveness that is one of the reasons I prefer the pf packet filter and thus BSD.
Here's an example for bandwidth limited wan. Interactive ssh sessions get a queue with a minimum bandwidth; scp and sftp bulk transfers go to a separate queue.
queue rootq on em0 bandwidth 100M max 100M
queue ssh parent rootq bandwidth 20M
queue ssh_interactive parent ssh bandwidth 10M min 5M
queue ssh_bulk parent ssh bandwidth 10M
queue std parent rootq bandwidth 20M default
block return out on em0 inet all set queue std
pass out on em0 inet proto tcp from any to any port 22 set queue(ssh_bulk, ssh_interactive)
[1] PF - Packet Queueing and Prioritization
http://www.openbsd.org/faq/pf/queueing.html[2] PF - Packet Tagging (Policy Filtering) http://www.openbsd.org/faq/pf/tagging.html
I just wish tc had an interface understandable by your average sysadmin. I have to dig into the source to figure out what anything does, but not many users will have the ability/desire to do that.
A hierarchy of dumb FIFO queues does not make a real QoS system. It can produce reasonable-looking benchmark numbers when the prioritization rules and benchmark are contrived to match, but in the face of real-world traffic that uses HTTP to carry vastly different kinds of traffic over links that don't have constant bandwidth and latency, OpenBSD is hopeless. Even the rate-limiting capability that OpenBSD has is rudimentary and lacks the ability to account for per-packet overhead and framing overhead, which is necessary for accurate traffic shaping on common service types like ADSL.
If you say you don't see any disadvantages for OpenBSD on QoS, then your idea of QoS is twenty years out of date.
You're right, OpenBSD no longer has ECN, and my comments regarding OpenBSD were out of date.
And yes, ECN is far more effective because it provides feedback to the sender.
All of the BSDs are still way behind; the best by only a few years, while others are stuck in the 1990s.
$ ip route
default via x.x.x.1 dev eno1 proto dhcp src x.x.x.x metric 1024
x.x.x.x/nn dev eno0 proto kernel scope link src x.x.x.x
192.168.2.0/24 dev br0 proto kernel scope link src 192.168.2.114
192.168.2.1 dev br0 proto dhcp scope link src 192.168.2.114 metric 1024
$ ip link
(...)
2: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> (...)
Network guys, when hearing the word Router think of something that holds a full BGP view... BGP router identifier 213.200.87.253, local AS number 65534
BGP table version is 7863026, main routing table version 7863026
578096 network entries using 58387696 bytes of memory
578096 path entries using 27748608 bytes of memory
344077 BGP path attribute entries using 20645160 bytes of memory
129723 BGP AS-PATH entries using 3908750 bytes of memory
1054 BGP community entries using 58126 bytes of memory
4 BGP extended community entries using 96 bytes of memory
0 BGP route-map cache entries using 0 bytes of memory
0 BGP filter-list cache entries using 0 bytes of memory
BGP using 110748436 total bytes of memory
Dampening enabled. 145 history paths, 277 dampened paths
BGP activity 730922/149406 prefixes, 731552/150036 paths, scan interval 60 secs
Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd
213.200.64.93 4 3257 2823796 74946 7863002 0 0 3w5d 577951
Woodworkers, when hearing the word Router think of something that can effortlessly carve a groove into wood.So, who's right?
__________
________ \
\ \
\ \
| |
| |
\ \___
\_____Think of where you want to place your router ? (Usually in your server closet or close to where the fiber enters your house) Now think of where you want your access-point to be. Preferably somewhere central in your house, where it will give you the best coverage.
So the best place to put an AP is usually a shitty place to put a router and vice-versa. They have no business being in the same box.
You can add WiFi to a generic box, but the Ars Technica staff are promoting a consensus that it’s better to use a separate access point that is designed to be good as an access point.
http://arstechnica.com/gadgets/2015/10/review-ubiquiti-unifi...