Redoing all my home networking
blog.jessfraz.com
blog.jessfraz.com
42u IBM-branded cabinet
Cisco ASA 5510 firewall
Dell R610 running ESXi
Old Dell 2950 full of 2TB drives running FreeNAS
Cisco 'Small Business' 50 port managed switch
A couple of 4U server cases containing the guts of obsolete gaming systems, repurposed as assorted servers
If you've got the space and can deal with the noise, I can't say too many good things about the R610s - available dirt cheap, and though they're about four generations old at this point, still perform decently since Intel/AMD have, until recently, pretty much stagnated on CPU performance.
Luckily I have a basement.
Do you know how many watts you consume? Are alternatives to old enterprise gear from eBay going to be cheaper from an electricity point of view?
-Cisco ASA 5510 firewall - 100W
-Dell R610 running ESXi - 400W
-Old Dell 2950 full of 2TB drives running FreeNAS - 400W
-Cisco 'Small Business' 50 port managed switch - 100W
-A couple of 4U server cases containing the guts of obsolete gaming systems, repurposed as assorted -servers - 2 x 300W
So, maybe 1600W under medium load? A 15A circuit can deliver 1800W max., so it would be occupying one whole circuit.
Hardly worth it, considering the noise, heat, space, and power. Old enterprise hardware gets given away for a reason.
Apart from that, places like www.weirdstuff.com might exist in your area, and have stuff like this laying around for pennies on the dollar.
A few years ago, they sold 4 pallets of Extreme 10/100 switches for $20! The catch is they sell lots and you have to pick them up at one time.
What do you think of that?
I am trying to put together a render farm where I need a lot of parallel CPUs to run Unreal Engine Swarm [0] but I just don't have the time or experience to execute on it. My goal is 16 Xeon chips across maybe 8 'boxes' to get to around 64/128 cores.
Anyone know where I could look to find someone I could contract to put something like this together?
These days, one dual-socket server can give you that, for a pretty reasonable cost compared to the time, expense, and power usage of running a rack full of systems.
If you had to put together a copy of the Amazon X1 instance https://aws.amazon.com/ec2/instance-types/x1/ any recommendation on a mobo/memory/case to use?
Only fear is that the time/cost it takes to spool up/down would not let us iterate as fast as ideally possible if we owned the hardware and had it running 24/7 for dedicated just in time use.
So rather than rent an X1 instance indefinitely we might just pony up the $ upfront and buy our own.
"Each X1 instance is powered by four Intel® Xeon® E7 8880 v3 (codenamed Haswell) processors and offers up to 128 vCPUs."
Anyone know if the X1 instance is 1 motherboard with 4 sockets or 2 separate mobos with 2?
IMO, if your core competency isn't sourcing and buying hardware in order to build render farms, you shouldn't do it. It's just not worth it. AWS brings a lot of value to the table, not the least of which is the fact that you won't have to maintain/fix hardware when you're just trying to render something. If the instance is broken, you can just kill it and spin up a new one.
Seriously, this will make your life so much easier.
> Anyone know if the X1 instance is 1 motherboard with 4 sockets or 2 separate mobos with 2?
This shouldn't matter. It's abstracted away from you by design.
Or dual epyc for a single box 64/128 system?
https://www.newegg.com/Product/Product.aspx?Item=N82E1681911...
From that thread: "Definitely not the threadripper - there were some benchmarks scattered around in other topics and it's actually slower at compiling and lighting builds than my 7820X, while costing more to build a system with."
But not sure if I should trust those opinions from the dev community as the benchmarks aren't too sophisticated.
I'll continue doing more research on those thank you! I think dual epyc could be interesting for the cost.
As for contracting, there's lots of options, but everything depends heavily on your usage model. Let's say your render jobs take the shape of "press button, enqueue 10,000 CPU-minutes of work". How often do you press the button? How valuable are low completion times? How penalizing are high completion times? Are there ever times when there is no work?
Cloud computing is a good fit for some problems: you can press a button, run your code on 10,000 CPUs, and finish the job in a minute. Cloud computing is expensive for other problems: in terms of hardware, the $1500 machine above compares favorably versus a cc2.8xlarge instance which costs about $1500/month at on-demand pricing. Server hardware is not the only cost -- you still need space and power and disks and network and time for setup and ongoing maintenance -- but there's definitely a break-even point.
PaaS, IaaS, dedicated servers, colocation, and in-house datacenters all make sense for users seeking different tradeoffs. It's difficult to give useful advice without knowing more about the tradeoffs you want to make and the relative values you place on setup time versus run time versus money.
I agree with you that they are great value but I find the noise and power consumption of that generation a bit much so just built my own boxes
Absolutely this. No need to run enterprise level hardware at home. You can easily run a huge environment with 128gb of ram and an 8-core Ryzen processor. If you want to get crazy you could even get an Epyc CPU with a SuperMicro motherboard, put it into a eATX whitebox case and run silent fans with a huge heatsink and still barely use any power. You can even run all the networking OS's in VM's, either with PFSense or some other vm template or use GNS3. No need to purchase a ton of hardware.
It really makes no sense to me why people drop all this money on R710's and make their house sound like the Hartsfield-Jackson Delta Terminal.
Anyway, the ZFS approach is to inherently trust the data that's in RAM over the data on the drive if there's a discrepancy, so ECC RAM is required to maintain the integrity of data on RAM.
That ZFS needs ECC moreso than other filesystems is an often repeated misconception. It's just that ZFS (and e.g. Btrfs) is often run on file servers, on which ECC is recommended.
This is absurd. Please read up (and understand) this before talking about it again. The benefits of ZFS and the benefits of ECC are orthogonal, though if your fileserver has both, it's a pretty darn robust system with respect to integrity -- assuming that (for example) the disk controllers don't lie about something being synced.
Definitely agree on using other cast-off hardware, though.
In contrast, I paid around $120 for a PCEngines APU2 (running PFSense), and it uses around 8W of power (measured).
Old servers are the same -- the amount of power they use for the performance makes them expensive to run 24x7.
I've been wiring up 10G throughout the house, and managed to get a ER-8-XG (beta version) on this site for under $500. (8 10-gig SFP+). Wife made me get rid of it because it was too loud. :( Got a Dell T1700 (they're like giving them away on EBay). Quad core Xeon E3, plenty of headroom to do firewall/routing in software.
OpenBSD makes it so dead simple to setup the basics that (unlike with my NAS) I've never been tempted to try a GUI distribution such as pfSense, yet it also gives you the flexibility to do more esoteric things like forwarding DNS using DNSCrypt, or allowing UPnP, but only to the PlayStation on a VLAN that can't talk to your main network. And the PC Engines gear works perfectly with OpenBSD.
Example of a basic separated setup:
DOCSIS 3.0 cablemodem that is a dumb layer 2 bridge: https://www.amazon.com/TP-Link-Download-Certified-Spectrum-T...
router good for up to a 150-200 Mbps class cablemodem connection, $50: https://www.amazon.com/Ubiquiti-Networks-ER-X-Router/dp/B014...
if you want to mess around with stuff from the CLI, a ubiquiti edgerouter is actually a very tiny debian system. their edgerouter OS is a fork of vyatta and is developed by a team of people they hired away from vyatta when brocade acquired them.
802.11ac 2x2 MIMO dual band WAP: https://www.amazon.com/Ubiquiti-Unifi-Ap-AC-Lite-UAPACLITEUS...
or go for the more expensive 3x3 MIMO and 802.11ac wave2 WAPs if you really feel the need for it.
set up the unifi controller in a virtualbox VM that runs on your laptop and use it to do the initial setup/provisioning. bring up the VM whenever you need to make changes.
Also for homelabbers the https://www.supermicro.com/products/system/Mini-ITX/SYS-E300... is like the "ultra-NUC", really small but 2x10 gbe NICS built in, plus IPMI.
The difference with IPMI tho is you can safely put them in the attic or wherever.
Now, for the most part I do general IT support and a ton of web development for company, without a ton of oversight.
We've got a nice guest wireless network for our clients with token based auth and a really reliable and consistent office network.
I recently bought a Mikrotik HAPlite for home which has also been great, I can VPN in and check my security cams without any horrifying cloud service getting a livestream of my home.
I like the fact everything is included, ospf, bgp, pim, mpls/vpls, you name it it's there (aside from decent user management). I used to run bgp at home but moved to ospf recently
Why do you need bgp/ospf for your home network? Are you just experimenting?
I used to manage the network of my school campus, we connected about 1000 persons, and ospf was working great! We didn't use mikrotik though, we used extremenetworks routers
OSPF makes it far easier to manage those, but I did used to run BGP as it made more sense to me when I learned about routing protocols and was more forgiving of wireless issues (which could have been me using the wrong OSPF mode to be honest)
In addition to the normal fixed infrastructure, I have a cluster of 5 cheap mikrotiks that I use for a little experimentation with things like failover time, but that's mainly for work purposes.
When I switched to CAPsMAN, I ended up using VPLS for my wireless backbone, thus giving me proper layer 2 isolation, without fragmentation (MPLS not being limited by the L3 MTU).
The CLI is nice in ways Cisco IOS isn’t, like a safe mode, auto-complete and in-line tab suggestions.
As if the feature parity between UIs wasn’t huge, the feature-set itself is major. RouterOS runs on PCs, there is a VM version as well, but you can get a an performant SOHO Routerboard unit for stupid cheap and they even have the actual Routerboard hardware available in bare PCB form-factor for OEM integration.
The Ubiquiti hardware generally seems much higher performance and is also low cost. But on the other hand, I do know some guys who really like the Mikrotik stuff so maybe it's just me...
If you want to do anything more than very basic single AP home scenario, you have to be willing to get your hands dirty. BUT they are very configurable, make for great learning experiences, and (from my experience) are very reliable, both hardware and data-plane software.
That said, the configuration software DOES have bugs from time to time, but MT is decently responsive.
Does anyone have suggestions for beginner friendly guides to home networking? My home setup is pretty hacky, and I'd love to setup something more secure as well as improving my understanding. Right now I have an ASUS RT-AC66U router with asuswrt-merlin, and it runs an OpenVPN server, so I can remotely access my home network.
How do people setup their home network domain name and device hostnames? I have the router set to update a public DDNS entry each time it connects to the internet, and a LAN DHCP Server with manually assigned IP and hostname for each known MAC address. This works alright for home devices, but it gets awkward for mobile devices and laptops. How do you restrict sharing functionality to VPN connections? Should your hostname remain the same regardless of what network you're connected to, or should it vary?
Do you use IPv6? My ISP supports IPv6, and I had enabled it on my router for a few months, but eventually ended up turning it off since I felt uncertain that everything was configured securely. Am I just being paranoid?
Is it ever worth setting up a RADIUS Server for WPA2-Enterprise wireless security? I kinda like the idea of having a centralized location for handling authN/authZ, but the relationship between the different technologies (Kerberos, LDAP, ActiveDirectory, etc) is pretty confusing, and nobody seems to do a good job at explaining how it all ties together. Right now I just generate an SSH key per device, and I import it to each device which should allow connections. But that increases the friction of deploying home services, which gets a bit demotivating.
What monitoring tools do people setup for their home network? Do you handle updates manually or do you have that process automated? Every time I consider setting up a network monitoring tool, I kinda end up going down the rabbit hole and getting overwhelmed by the huge number of options. Many of these tools kinda assume that the user is already familiarized with best practices and that they know exactly what they want, which couldn't be further from the truth in my case.
Want to know if IPv6 is secure? Do research to find out. Then you will know for sure.
I would say you will have a hard time figuring anything out for yourself when your infrastructure uses business-class solutions and is cross vendor.
If you're uncomfortable with IPv6, you are right to turn it off. Learn it, become comfortable, then configure it properly. This advice holds for everything.
Is it worth setting up RADIUS? Only if you want the experience. One of the possible functions of a home lab is to gain experience.
It sounds like you want to learn how to do operations. It's always advisable to start by gathering requirements, generating threat models, listing resources, and then trying to construct a plan. None of this needs to be fixed in stone - as you research one thing, you should learn of alternatives with different trade-offs. Keep track of all that. There is never just one set of "best practices".
You can clear sign an authorized_keys file with "gpg --clearsign <authorized_keys>", then just pass the resulting *.asc file to this script. It will verify the signature and 'import' it by copying it to ~/.ssh.
The main advantage is following the UNIX philosophy (albeit in a limited manner). The security gateway does NAT, VPN and firewalling, the APs do wireless and the switches switch packets. The CPUs can't get overloaded with other tasks.
I don't think I'm anything like an average user though. I have over 20 devices on my home network continually and 100Mbit fibre to my home - though with my new gear I could increase that to 800Mbit.
By separating the router and wireless APs you also get the ability to place multiple APs throughout your home for improved signal.
My Mikrotik and Netgear both regularly shut down when I max out my Internet connection. I've had days where I've had to manually restart them numerous times trying to push large docker images to AWS.
They both have spotty upnp implementations, which I need to work because there are game consoles in this apartment and upnp is necessary to get them online reliably. The Mikrotik's AP is pretty terrible. Doesn't even span a small 1BR in Seattle.
Netgear's models are notorious for being vulnerable to stupid exploits even after numerous hacky patchy series.
The most handwavey one: I find consumer routers just sorta need to be replaced every few years.
I spent less doing the whole Unifi thing recently than I've spent on routers and such in the last 6 years. I don't think I'll be needing to replace this gear any time soon, and Unifi isn't really custom hardware at all. They non-rack mount stuff is relatively affordable if you're willing to make a moderate investment.
Which AP do you have? They sell many, which vary greatly in transmit power. Some (like the RB951G-2HnD) support up to the legal maximum of 30 dBm, but most (like the cAP lite) run at 20 dBm. The notorious RB951-2n (my first) ran at only 15 dBm, which is underpowered.
The 20 dBm models are designed to be used in a multiple-AP scenario, e.g. one AP per room. They definitely won't span multiple rooms, by design. (This is for several reasons, both to properly segregate client devices onto separate APs, and to ensure TX power parity between the AP and devices, which often operate in the 17 dBm range.)
I've run exclusively MT for years and never had one lock up under load. What model do you have and what sort of bandwidth are you talking about? I regularly run 200+ Mbps transfers to/from my NAS (across a wAP ac) and never have trouble. (I did once own a hAP ac that would – after an electrical event that destroyed some other equipment of mine – reboot occasionally.)
for me it was because
- it could not max out my connection: it was maxing out a 70Mb/s on a 100Mb/s connection
- those off the shelf routers do not support vlans, and I like so segment my home lan in stuff I trust, and stuff I don't trust.
The Unifi product is getting better, but I sometimes wish I had gone with their EdgeRouter line instead of Unifi for routing and switching.
I would say it’s certainly good enough for home, but I’d hesitate to use it in a lab environment where configs might get a little more unique.
(I have both and my EdgeRouter X feels definitely in “maintenance mode”).
Software wise, the UniFi line does seem a little more actively developed, but new EdgeRouter products are and have been coming out (like the 10Gbit EdgeRouter Infinity a little while ago, and the new EdgeRouter 4 etc.). I think a lot of the software slowness might have been that some of the devs on the EdgeMax team left (judging by the staff posting on the forums), so it's probably been taking a while for the new devs to get up to speed.
It's certainly not rocket science, but I don't know too many junior sysadmins who could do it without hours of research and pain. Whereas making a change on an EdgeRouter is more legacy - find, apply, save. Done.
o Zotac dual nic with pfsense o netgear 24 port switch with vlans (no PoE, too expensive) o i5 NUC o quadcore atom ZFS storage box o 2x unifi AC APs o Many raspberry pis for environmental sensors/control and the like
There are a number of VLANs some for public things like cheapy chinese CCTV (don't want that seeing the internal network) media and the spouse(s)
Everything was controlled with puppet, now migrated to ansible. I was tempted to replace most of it with an old HP z600, but that would blow the power budget (all the compute when on consumes < 45watts) a z600 with dual CPU pulls about 100-130.
There is an hosted Atom box that provide website, VPN and backup coordination.
In my case, the default wifi-router that came from the provider sits unplugged and idle.
The network was pretty tightly integrated into the boat, a mix of Seatalkng, RS485 and RS232. All connected to my PC through wifi. Sadly, my homelab suffered from saltwater exposure and high humidity. My Mikrotik router and LR wifi antenna stayed with me. Since coming back stateside I've replaced most of my gear with Azure, IFTTT, and Alexa. 3 things we didn't have access to while sailing.
Very few of the job functions we rely on in my space can be reasonably handled in 45 minutes. Resultantly, every interview question is indirect. We either reduce problems to what we hope are aggregate indicators (e.g. coding questions) with little to no certainty that we've correctly aggregated the skillset, use fast-search limit test questions that can spook candidates, or resort to fuzzy indicators that end up serving as pet questions.
For me, I check for things like accurate self assessment and subtle asshole cues, but largely indirectly, since everybody lies...
“Tell me about your home network” is one of the odder proxy questions I’ve seen, having spent a lot of time looking at this problem.
What I’ve recommended for years is to replace technical interviews with take home work sample tests. Those also have their downsides and have recently gotten a bad name because of how poorly many people execute them, but replacing your interview process with them almost always leads to better results in my experience.
Maybe it's useful for 'can this person describe something complex they worked on' with lots of places to dig into 'how much low level networking knowledge does this person have,' but a large number of my peers use the WiFi that comes with the modem from their ISP, and don't even realize they're doing everything wrong.
Particularly, it is discriminatory in that it penalizes people based on their home situation, both from a time and financial perspective. People with children, especially single parents, are often not in positions to actively maintain a home lab or complex home network, due to time constraints.
Others just might not have the inclination, and it doesn't say anything at all about their ability to perform the job.
Even if you're not going to take the lack of a home lab as a negative, it can throw a candidate off - candidates are very conditioned to feel that a hard no to an interview questions is going to be taken as a mark against them, and this is going to effect their ability to answer other questions as effectively.
A much better question is to ask how someone approaches learning new technologies or keeping up with the changes in technology in general. For some people that will be work related, for some it will be home labs, and is an important skill regardless of how much time you have available. People with home labs will almost universally talk about it, and you can get the same discussion with them, without risking discriminating against people that have to keep their skills sharp through other methods. It's also more likely to be directly relevant to the skills related to the job, rather than random projects that might be tech related but not relevant to the position being interviewed for.
You should focus on the things required for the job. Not what people do in their free time.
We do know that diversity increases the effectiveness and problem solving ability of a team - at worst, getting a bunch of people that have home labs is actively detrimental to this, and at best does nothing to improve it.
There's limited time available in interviews, and you're probably better suited asking relevant questions.
(And from a personal perspective, asking about home lab details would benefit me. I've got ten gig fiber throughout the house and close to a terabyte of RAM consumed by my VMs... But none of that is realistically making me a better employee)
I agree that competency testing, especially project based, is better. The only reason I'd ask about their off time is to get a sense of what they like and better getting to know what kinds of projects they might gravitate to, given the choice.
However they were reasonably promising on the test, so as part of the "getting to know you" part of the interview we went over where they got their knowledge. Home labs, ebay, second had stuff. Do I expect _everyone_ to have a home lab? fuck no. Do I explicitly ask about them? no.
I must take issue with discriminatory, the whole point of an interview is to discriminate against people who are not capable of the job role.
What you are talking about is social bias, and that frankly has nothing really to do with home labs, and a lot to do with people being arseholes.
Identified the author immediately by the opening sentence. The "overengineered" CoreOS deskop was great, I wish it became an actual project.
I admit I haven't had any performance issues with the router (although I'm not running any complicated routing rules), and out of the box it was setup to run as a NAT router, so it was just plug and play. However once I started digging into it I started reaching the limitations. As others have said the documentation is pretty bad, and the only way to tell if something is supported by your hardware is usually to try it and see what happens (or read a 40 page thread in the forums). Here are a few things I had issues with:
- Using a USB LTE dongle as a backup WAN connection. At first the device wasn't recognised, I then connected it through a powered USB hub and it worked, but then after rebooting it wasn't recognised again, but if I physically reconnected it then it worked - but for a 'backup' that kind of sucked (this was later fixed in a software update).
- VLANs. I wanted some ports to be tagged on a certain vlan, no matter what the device was sending (I want to have a 'media' VLAN), after I while I found out the hardware doesn't support that though, so I gave up on that idea. I setup the AP to have a guest network running on a separate vlan, and wanted that to have no access to my network, after trying for a few hours (and usually locking myself and having to factory reset the router each time) I gave up. This was only a stop-gap anyway, as I'd planned to get a managed PoE switch.
- VPNs. I wanted to setup an outgoing OpenVPN client, and route some traffic through it based on IP (Netflix). I also wanted to setup an incoming OpenVPN server, so I could access my network from the outside. RouterOS has built in support for OpenVPN, but the features are somewhat limited, for example as a client it doesn't support certificate authentication (but as a server it does).
The Unifi was a breeze in comparison, like the Apple of networking gear, but in the same way the options are somewhat limited (and having to install an application to configure networking gear feels weird). To be honest I liked OpenWRT better than both of these... the documentation, ease of use, and being a developer I feel right at home editing configuration files. I assume PFSense would be a good choice too.
It probably took me weeks to get a working guest network setup on my MT. That is one thing I wish they'd automate. I don't regret it, as I'm partly into MT so I can learn more about networking, but it makes it hard to recommend to others who want a basic home router.
(CAPsMAN helps a little, in that you can direct it to isolate all clients on a given SSID from each other, even across APs, but that still leaves you with configuring routing. It also has a packet fragmentation problem in that mode…)
I had my own VLAN fun when I tried to configure VLANs through the switch menu. Turns out that doing so overrides port master/slave configuration with no warning. I ended up bridging my WAN and LAN ports for a few days… (Now MT is thankfully starting to move away from direct configuration of the switch chip and instead using it to transparently accelerate bridges.)
EDIT: Tried following the linked instructions but nassh just hung while trying to connect, with no prompt from Smart Card Connector :( Oh well, at least it's possible in principle.
https://chromium.googlesource.com/apps/libapps/+/master/nass...
The simple approach is to make a list of your physical media collection, stow it away for backup purposes, and download the collection over time. Then eventually you can even move towards torrenting the rest of your media and drop that netflix subscription that's supporting the destruction of net neutrality!
If the author is in the united states, torrenting the videos would violate copyright (when you torrent (if you don't have uploading disabled somehow), you redistribute without authorization). Transcoding DVDs you've already bought is not distribution.
I find I can do a better job (at least to my eyes) than most 4.7/8GB movie rips, and the standards for x265 aren't set yet.
Ripping your own media gives you a lot more flexibility.
Main issue is that dvd covers are ugly as sin, and there's no archive of the disk image that isn't a literal photo of the disk (but the case covers are scanned on http://www.cdcovers.cc/), so I've been creating my own,
and dvd authoring is a pain in the ass if you want soft-coded subs, and multiple audio tracks
But since my target player is ps3, which apparently supports avi w/ xsubs and mpeg4, I'm planning to switch out to that: video quality is much better for the disk size between mpeg2 and mpeg4 (kunaki only produces cd and dvd5, so a blue-ray archive is out)
I don't like caring about individual copies though, so having a way to recreate them cheaply on lost/damage/borrowed-but-never-returned is pretty useful imo. I get to treat it both digitally and physically on preference.
Ofc, all the stuff I haven't watched, like but wouldn't recommend, etc will never leave digital. The ideal scenario is just that I can pull a dvd off a shelf when I recommend it, instead of scrambling for a usb or mega or scp; if its possible, physical sharing is a lot nicer than digital
1) PoE wired backhaul.
2) Way more management and configuration control.
3) Separability of routing, switching, and wireless.
4) Simple L2TP VPN endpoint support.
I'm very happy with my choice, and I just installed AP's only at my folks' place over Thanksgiving. Simple remote management may be Overkill, but I'm willing to wager that the lifecycle in this gear will be much better than the once-every-18-months dance that they've been doing with extenders, routers, etc.
I have a 1930s solid brick built house, and a 50 meter garden with a "work shed" at the other end.
with two I have the entire house, garden and shed covered at a decent speed.
"I love writing opinionated blog posts that make dudes go all ape shit and territorial if I didn’t do it the same way as them. Think for yourselves :) there can be more than one way ya doofuses it’s all about what your personal tradeoffs are."
Is this the kind of response you want to have to people sharing their opinions on a public forum; having a productive discussion that you started.
I'm considering buying a CompuLab fitlet 2 to give pfSense a permanent home but may end up leaving it on my workstation. The increase in power consumption over leaving my workstation on 24/7 is probably neglible. But the fitlet2 seems simpler.
I've got 3 Unifi APs , a 24-port switch and a security gateway.
Personally I like managed kit 'cause it provides some insight into whats happening on your network. If you see a slowdown what's causing it, what devices do I have connected etc.
Additionally, Ubiquiti has a nice manager interface which makes updating the firmware pretty easy, which is nice security patches are needed and making those easy to apply is a good thing.
https://help.ubnt.com/hc/en-us/articles/115013737328-Ubiquit...
When I move to a bigger place I'll probably put the router behind a big PoE switch and buy some of the 48v PoE compatible APs. We use them in work and they've been very good so far.
Rock solid reliability. I have never had to reboot my ER-X or UAP-AC-PROs except for firmware updates. You'll also get updates for a long time compared to consumer gear.
You can also use one NIC and VLANs.
http://www.virten.net/2016/06/additional-usb-nic-for-intel-n...
The only NUCs that are worth it are the i5/i7s but they are rather warm and need a fan. (I have a first gen i5, its fucking awesome though.)
There are a lot of reasons to not use pfsense. Basically no SQM (eg: fq_codel), everything is a giant php script running as root, tons of simple features (eg: backup) have to be implemented as plugins unless you pay for the commercial support, and the most important of all: because it's not a normal freebsd system, you don't know exactly where to look when something breaks; you don't just have to find the broken config file, you have to find the script responsible for generating that broken config file. I am not a fan of pfsense.
It's more likely that she'd go with a simple linux system considering the projects she's worked on, but I think it's cool that she didn't do that, either. There's something to be said for not having a bunch of different systems to maintain. Ubiquiti equipment is a bargain. You pay a one-time fee for equipment that is probably twice marked up from what it costs to make, and in result you get immediate patching of things like that recent WPA2 bug, great throughput via hardware acceleration, advanced features, etc., for a very long time. Set it and forget it.