Use a Mikrotik as Your Home Router (2017)
blog.ligos.net
blog.ligos.net
Their devices run Linux so you can ssh directly into them if you want to change something. All config options are also available via the command line interface.
If you want a consistent UI experience, choose one of their several "lines" and stick with it for all your hardware, i.e. use a Unifi Security Gateway + a Unifi Switch instead of the EdgeRouter X. This will allow you to control all your devices from the same interface. I went with the heterogenuous combination because it suited my needs.
The remote management tools are really nice if you have multiple sites (parents house, vacation home, etc) to manage. 1% problem for sure, but for a little bit more than a crapbox integrated router you can get an enterprise-grade modular managed solution.
As a geek with more complex networking needs -- multi-WAN, site-to-site VPN tunnels, lots of port forwards -- EdgeRouters are the way to go. UNMS gives me some centralized management and insights into what's happening with my EdgeOS (and AirMax) gear. Rest of my network is UniFi APs and switches.
When last I checked, you could not compile your own kernel for Ubiquiti devices and get something that worked the same way as before -- the switch ports, IIRC, and probably other stuff.
My firewall runs actual Debian Stable, gets updates to everything including the kernel, and happily handles the gigabit that VZ claims to be delivering to my house. (Actual speeds tested vary from 700-950Mb/s.)
Nothing is as small as custom non-PC hardware. However, I think mine is reasonably small and you can go to a NUC size for 2 gigabit ports.
I'm glad they're in compliance with the GPL now, anyway. They were remarkably resistant.
The ER-X is actually a little Debian box with a decent GUI.
Unless you have >600 Mbps symmetric gigabit home internet, an ER-X is more than fast enough for routing, firewall/NAT functions for the average residential user.
It is also a really good way to economically separate the functions of router and wifi. Have a router that is a wired 1000BaseT router with no wifi. Buy one or two of the 802.11ac Unifi dual band access points, priced anywhere from $75/ea to $200/ea depending if you want 2x2 MIMO or 3x3 MIMO, or wave2 functionality.
Set up the unifi controller as a virtualbox VM on your laptop that you use to provision it and make changes. The controller does not need to remain persistently on the LAN once the APs are configured.
Short answer: EdgeRouter 4 ($199) or EdgeRouter Lite ($99).
Long Answer: It depends.
The ER-X / ER-X-SFP are architected as a switch with a router hanging off an internal 1Gb/s full-duplex link. Every routed packet crosses that link twice -- once in, once out -- so they can only do 1Gb/s of combined routing.
For most purposes, traffic patterns are heavily asymmetrical so this isn't a meaningful limitation, but to get > 400-500 Mb/s symmetrical performance you need any of their other models.
The ERLite-3 and ER-4 are the next best models for home use. Both are fanless, low-power, and capable of line-rate symmetrical routing across all ports simultaneously. ER-4 doubles the RAM, has twice as many faster CPU cores, adds a dedicated SFP port, has an internal PSU, and an optional rackmount kit.
ERPoe-5 is an ERLite-3 with one port replaced by a 3-port switch and 24v/48v PoE (early units shipped with a 24v PSU, buyer beware if you need 48v PoE).
ER-8 / ERPro-8 have 8 routed ports, are rackmount-only, and have fans that aren't suitable for living / work spaces. The Pro adds 2 SFP combo ports and a slightly higher clocked CPU. The newer ER-4 is much more powerful and costs less.
ER-6P is an ER-4 with two more copper ports, an external PSU, and 24v PoE (standard PoE is 48v).
Note that the ER-X, ER-X-SFP, and ERPoe-5 are the only models with switched ports. You can bridge routed ports to emulate a switch, but that forces traffic out of the hardware offload engine and seriously compromises performance. Buy an external switch or a model with switched ports if you need switched ports. For the money, the ER-X makes an excellent compact managed switch with a much nicer UI than typical cheap web-managed switches.
On the UniFi side, the USG is equivalent to the ERLite-3 and the USG-PRO-4 is an ERPro-8 with half the ports. An updated model based on the ER-4 / ER-6P platform is expected but not any time soon.
This way you get the best of both worlds. Especially since the EdgeRouter line is absolutely one of the best on the market when it comes to network throughput (which you really want if you have 1000mbps+ fiber behind it)
1: https://wiki.mikrotik.com/wiki/Manual:Webfig
2: https://wiki.mikrotik.com/wiki/Manual:Winbox
1: https://mikrotik.com/product/RB962UiGS-5HacT2HnT
As far as the RCE, is SMB even enabled by default? It's an important catch and I'm not clear yet how exploitable via JS in a browser, but I can't imagine that SMB is open to the world in any router's default configuration.
I can't say i disagree.
The recent bug about being able to download the user database was less cool though. But it was patches very fast after it was discovered.
Then again the above bug is only exploitable if you allow incoming connections from WAN on the management port, which isn't good practice (but i and many other people do it anyways because it's simple).
These days a blank non responsive void is the only thing that makes sense for an office.
0: https://dyn.com/blog/longer-is-not-better/, previous discussion https://news.ycombinator.com/item?id=490924
You never hear about MTU failures in the media :(
Would you mind describing your setup/config? Is it just the apu2 plus a ubiquiti AP? Which AP?
from pcengines, I got:
https://www.pcengines.ch/apu2c4.htm https://www.pcengines.ch/case1d2redu.htm https://www.pcengines.ch/msata16f.htm https://www.pcengines.ch/ac12vus2.htm
put that together and installed pfSense per their instructions:
http://pcengines.ch/howto.htm#OS_installation
You could get their wifi modules:
https://www.pcengines.ch/wle200nx.htm https://www.pcengines.ch/wle600vx.htm
but I advise against it if you want to run pfSense, since driver support on pfSense for these might be sketchy/difficult to get working. Linux might be a better choice for a router OS if you're going to get those modules. My personal recommendation is to avoid getting wifi onboard the apu2 and stick with this instead:
https://www.ubnt.com/airmax/nanostationm/
or if you want 802.11ac:
https://www.ubnt.com/airmax/nanostation-ac/
and just take up one of the three ports available on the apu2 permanently for your Nanostation.
Set this up, and you'll be happy for years. I consider it the ultimate DIY home router setup and I've experimented with many. This one takes the cake. The only thing I wish for is an extra RJ-45 port on the pcengines APU2 for some of the devices that are close by it (e.g. a mac mini I use as HTPC), but since everything or nearly everything has wifi nowadays, you don't get to notice this much. Worst case, if you need extra ports, hit amazon and type only "pfsense" in the box - there's a vendor called ProtectLi (https://protectli.com/) which sells 4 and 6 port boxes similar to the APU2, but with Intel instead of AMD (I'm kind of partial to AMD plus PCEngines is run by Americans/Swiss :). Those will work just as well though you're looking at spending more $$$. If that's no objective, then just get the 4 or 6 port ProtectLi.
Reply here let me know how it works out once you've got it setup the way you want.
I ended up switching to Opnsense instead. It was a good medium between dd-wrt and Mikrotik in terms of usability / exposed features.
Mikrotik is for those who want to do traffic manipulation at very low levels - it's not for the faint of heart if you're not a network pro.
I also didn't like that I had to pay for a new license if I had to change the hardware in my box.
Strongly suggest just throwing OpenBSD on a flash disk (possibly with the help of flashrd) and going from there. Once you get a taste of the solidness of pf & the openbsd network configuration tools/documentation, you'll miss it every time you use another free OS.
No vendor's products won't have RCEs; what's important is turnaround time to deployable fix, and MikroTik's pretty fast.
I have used it to teach an introductory course in computer networking and it could perform well many net protocols (DHCP, NAT, etc.) and even some advanced routing configurations (with RIP/OSPF).
UI was a little rough on the edges but after a while you get used to.
[0] https://nvd.nist.gov/vuln/detail/CVE-2018-7445
[1] https://forum.mikrotik.com/viewtopic.php?t=133533#p656301
I don't think a manufacturer should be judged too harshly based on if they have vulnerabilities or not, since all software does, but rather on how they respond to and patch those vulnerabilities.
MikroTik fixed both of the issues you referenced, just as Asus fixed the issue I referenced. So I see no specific reason not to use either a MikroTik or a Asus device (and keep both up to date).
The only major thing I'd consider is:
- Does the manufacturer respond constructively?
- Is the device still receiving security updates/has no outstanding holes?
It's very bad, but they responded quickly and resolved the issue.
One thing i'd say is worth mentioning is that they're still keeping "all" (all i know off) RouterBoard devices updated. We've had customers with gear many many years old, still updated with feature and security upgrades.
(they even ship their rootfs with proprietary kernel modules that are marked as license: GPL so that they don't taint the kernel, ie for their bandwidth test)
Bottom line, great routers, packed with features, not simple to configure.