A tiny PC as a router
blog.liw.fi
blog.liw.fi
In my day, a router was a Intel Pentium @90MHz with 4M of RAM. No HDD, only a FDD with Linux. Granted, it probably would have problems today with speeds we're all used to and WLAN, but, man, strip it down, strip it all down to Megs. You don't need X running on that. You don't need all these services. Fonts. Libraries. Default pictures. That's all bloat. Throw out the SDD. A 1G usb thumb drive is enough. I/O speed concerns? You got 8 gigs of ram, dude, you could fit your whole "factory" image in it and have enough space for the second one. Ramdisk the shit out the system. Dude...
And, just out of curiosity, how does using iptables make that not a real firewall (even if you're using iptables in an indirect manner)?
Agreed, though if you do, you have to be careful with writes. I literally had to reflash my drive every time the power went out (I don't have an UPS). My solution was to move every writable directory to a tmpfs, then mount the root fs as readonly. Logs get shipped by a cron job over ssh. It's been rock-solid ever since.
If you want to upgrade or reconfigure without reflashing, you can still remount with rw, do your thing and then remount with ro again.
It didn't cost too much and it's flexible - running Ubuntu server I can stick some Docker containers on it, run a/v for the network, Nagios, anything really. It's a good learning exercise too when you consider anything that impacts my son accessing XBox Live is essentially mission-critical in this house.
When I replaced my ISP supplied router with it (BT Home Hub 5) I immediately saw better performance and less latency. Unfortunately I forgot they deliver their premium sport channels over IPTV/Multicast so it was a couple of days learning that but i've acquired a new skill for my CV, so hey-ho.
BTW if the processor is like mine the 2.4ghz thing is the burst clock, it normally idles are 800mhz, which is important as the box is fanless.
All those things should be on separate machines.
To me a non-production system is one I can turn off for indeterminate periods of time without loss of any service I actually need to use in daily life.
No, pretty much everything is.
> Anything else is disposable, a convenience.
Fine, we'll your definition: If it causes an inconvenience if it goes down it is a production machine.
The OS on my gateway only goes down on kernel updates, and I can crontab them (unlike with the ISP supplied box).
My son and his mates can put any old malware infested phone on his SSID, but they can't get to my LAN. I can run my gitlab etc without affecting him, apart from QoS - any the latter is something the ISP gateway doesn't even offer.
Anybody sufficiently experienced can segregate services on a single box without any worry.
The wifi my partner and childs kit is connected to = VLANd off, goes straight out through a DMZ via its own interface.
The stuff i'm testing doesn't touch this and I can do what I like through those interfaces without affecting their stuff. Unlike the ISP supplied router if something crashes, I can restart the service rather than pull the power. It doesn't crash anyway, unlike the ISP kit which is temperamental at best.
ISP routers already have wifi. Shouldn't the wifi be separate, as rebooting the router will bring it down otherwise? Where do you draw the line?
Can you pull the power on your testing machine without affecting the wifi ? The point is not that you can usually do it without affecting any other services, the point is that even if you fuck up in the most spectacular way possible and literally fry all the hardware in that box it should not affect any other service than the one you were tinkering with. (Note that in a corporate setting that would not be acceptable either and you'd want failover and no single points of failure).
> unlike the ISP supplied router if something crashes, I can restart the service rather than pull the power. It doesn't crash anyway, unlike the ISP kit which is temperamental at best.
I'm not saying you should use the ISP-provided router, on the contrary, you should definitely build your own. But build a second machine for your experiments, and third for your fileserver, and a fourth for your torrents, and a fifth for.. etc. etc.
> ISP routers already have wifi. Shouldn't the wifi be separate, as rebooting the router will bring it down otherwise?
Yes it should certainly be separate. And it is, at least in my house. Router is a simple server-grade machine (IPMI, ECC, etc.) that ONLY does network routing. I use Ubiquiti access points for the WiFi.
> Where do you draw the line?
Functionally separate services on separate boxes.
No, seriously... Usually these kind of devices end up doing a lot more, like file serving, backups, code repository duties, music playing services, SMTP relay or even build machine tasks. If it's accessible by a technical person, it will get some serious use and abuse.
No complaints yet, except pfSense is not that great with Wifi. It's probably best to do wifi separately if you want to run a BSD flavour on it. I haven't tried installing Linux on it yet, since WiFi is functioning well enough, albeit sub-optimally.
[1] Available e.g. here: http://www.newegg.com/Product/Product.aspx?Item=0XP-000A-000...
See https://help.ubnt.com/hc/en-us/categories/200321064-EdgeMAX
I don't use WiFi much, but when I do, I use a separate box. Separation of function.
Having said that, the Qotom is absolutely perfect for 1000Base-T to 1000Base-T routing. It's got plenty of CPU (unlike the commercial crap is hopelessly lacking), and plenty of RAM so it won't overflow its NAT tables.
That would be because numerically, the majority of routers are tiny boxes sold for home use with three NICs: external ethernet, internal ethernet (often connected directly to a mini-switch), and internal WiFi. They also serve as firewalls, DHCP servers, NTP servers, and DNS relays, none of which are technically routing.
For most home users, routing Wifi to their provider's ethernet handoff is exactly what they need a router for.
I initially intended to build my own router when I got Gigabit internet. After some research, I settled on a SOHO solution that seemed hard to beat in bang-for-buck: Ubiquiti EdgeRouter LITE-3. It does roughly 933Mbps for WAN->LAN, which means I don't lose much speed in that transition. For prebuilt solutions, the only way to one-up that is to move to 10Gbps hardware which is cost prohibitive.
All that said, the Ubiquiti router runs a custom version of Debian and I'd prefer to work with something that could work with Ansible or the like and is a little more open.
I'm a huge fan of pfSense which wraps a nice UI and some great tools (proxy, AV, analysis, etc.) into one big package. Worth a look. I used to run my home router on a little Qotom computer, but virtualized it to get rid of wires and boxes; works great. I'm running three pfSense boxes in various environments and can't say enough good things about 'em.
£25 and two minutes to flash it, and away. It amazes me what OpenWRT and ROOter have crammed into 4MB. 4MB!
After using IPCop for roughly 4 years, I have now moved to Sophos UTM Home [1], and couldn't be happier. Much easier to use, and supports upnp.
[1]: https://www.sophos.com/en-us/products/free-tools/sophos-utm-...
2 vendors have already made preliminary announcements:
* http://www.asrock.com/ipc/overview.asp?Model=IMB-157 * https://www.asus.com/Motherboards/J3455M-E/
It's not more expensive than a high end consumer router and significantly more capable.
It's been running for several months now but gets relatively warm due to passive cooling. I wonder how long it will last.
They are both good.
Why not using anything with a GUI like pfsense or Sophos UTM?