It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side)
Any suggestions? I believe we have Cox if that is any factor....
It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side)
Any suggestions? I believe we have Cox if that is any factor....
You'll get a great interface, frequent firmware updates with new features and security fixes, and you'll have a good strong signal at your neighbour's house if you're going for a visit.
That's cheaper than most all-in-one routers, and while you won't get the best single-client bandwidth, you will get much better management/configuration options.
It really isn't. There are plenty of consumer router+AP combos in the $75-90 range that offer equal or better performance to the ER-X + UAP-AC-Lite combination.
I've been looking for an excuse to go down the Ubiquiti route, but I really can't find one.
I'm personally using a TP-Link Archer C2600 that was on sale for $70 from Newegg in January.
In the end mucking with open source firmware, while interesting, just wasn’t worth it. I found the ubiquiti solution stable and the UniFi management software (especially their iOS app) are excellent for my needs. Plus mounting my AP in the ceiling means I can cover the entire house from one AP and at the same time keep the rest of my networking equipment stored away in the basement.
However, no router in that price point gives you the ability to easily expand past one AP, RADIUS VLAN support, the Unifi web interface and so forth.
My last setup was an ASUS N66 dedicated as the router with an Archer C7 as the WAP. Good performance but the configurability and stability (even with ddwrt on the asus) doesn’t compare to the ubiquiti combo I run now.
You must be assuming that the user insists on sticking with broken vendor software, instead of switching to OpenWRT. The only software benefit that you don't get just as easily from OpenWRT is centralized management of multiple APs. Adding and configuring APs one at a time is very easy and since home networks never require more than 2-3 APs the lack of centralized management is not a significant issue. RADIUS and VLANs are fully supported by OpenWRT, and the web interface is fine except for the aforementioned limitation that you're only managing one AP at a time.
I suspect your stability issues with the ASUS router were a consequence of you using DD-WRT hobbled by proprietary WiFi drivers, instead of an OpenWRT-supported router. The DD-WRT "project" is a mess compared to OpenWRT, which actually puts out stable releases and operates more like a proper Linux distribution. Third-party firmware distributions aren't all the same.
I used Merlin ddwrt which was supposed to be dedicated to ASUS hardware. At some point fiddling with wrt takes more time than the nonexistent price difference with the ubiquiti equipment :)
I didn’t use the ASUS for WiFi, just routing. My instability had to do with ipv6 issues - it would stop broadcasting RAs if I remember correctly causing intermittent connectivity issues. I would have to cycle power every so often (month or so?)
No such issues with the edgerouter. I’m sure OpenWRT works great for folks, I just found it wasn’t the right fit for me.
Usually the ISP router just sucks at wifi, but I have seen ISP routers which have only 100mbit/s uplink ports when the internet connection is higher. In that case you'd want a custom router also. Or if they ship some router with some features you dislike that you can't disable (like public hotspots, unpatchable insecure config interfaces, etc.)
I just want to extend the range without monkeying with the existing router or running cables. Ideally configuring the slaves to use the existing SSID/WPS config if that's possible.
I don't care (much) about the impact to latency or throughput, it seems like there's excess capacity now.
EDIT: downvoters please join the discussion, seems like an innocuous question to me.
But now, the ISP provides a single device that is where they terminate the DOCSIS connection and originate the Wifi router. And casual investigation leads me to believe that I "can't" replace this device. I don't want/need a DMZ or my own public servers. Also, I have less patience for tracking down my own breakage these days. The ISP's device works and performs spectacularly. I know of no public vulnerabilities for the provided router.
So IMO no I don't "really want to get rid of any kind of ISP provided router and Wifi".
They usually didn't advertise that though.
Their cloud management stuff is solid(and free with spare PC!) which is great if you help your family set anything up.
Ars did a great deep-dive a whole back[1], it's a pretty good read.
[1] https://arstechnica.com/information-technology/2018/07/enter...
The main security issue is that the vendors stop issuing security updates after they stop selling the router even though people are still using it, and the software that comes on it is usually crap to begin with. The solution to this is to get one you can install OpenWRT or Debian or whatever you prefer on it, do that as soon as you buy it and then it doesn't matter what the vendor does. But note that not all routers are supported by the software you want to use.
Also remember that a router is just a computer with multiple network ports on it. Adding another network port to your old laptop is a time-honored tradition. The hardware will be faster, the drivers are usually better, it has a built-in battery to survive power bumps, etc.
I wish there were $20-$30 PCI-E bridge cards of >2 1Gbit ethernet jacks but they don't exist.
Unless you actually need the ports to do some kind of network segmentation, one solution is to just plug the inside port into a five port switch (~$15). Which is how a lot of the consumer grade routers are implemented internally anyway.
You also can find quad port gigabit cards around those prices. Currently $22: https://www.amazon.com/HP-NC375T-Gigabit-Ethernet-539931-001...
There are scads of used quad port cards for even less on eBay.
Cost is not a primary concern, within reason. Wanting a consumer focused router is more about wanting to minimize set-up time and maintainence. Frankly, I’m not sure I have the time or trust myself to set up OpenWRT correctly/make sure it’s updating regularly/I’m installing the correct version etc.
As long as you're not going out of your way to install a nightly build of OpenWRT and you just stick with the stable releases, it's no more difficult than installing new firmware from the manufacturer and configuring it. The web interface for configuring OpenWRT is comparable to what most consumer routers provide, except that OpenWRT's UI is shared across all hardware platforms instead of being laden with vendor-specific branding and snake oil features.
These are trash too, full of closed code with backdoors. Buying small x86 mini PC and flashing it with OPNsense will take an hour. You get open source with GUI on FreeBSD, bulletproof.
Its documentation is however a bit lacking unfortunately.
Oh and it's openwrt under the hood, with lxc containers for things such as grafana.
Never had a better setup.
It blows any consumer router I've used out of the water in terms of stability, performance, flexibility, security, and user experience.
Getting emails for potential security issues, custom DNS domain for local network, fail2ban bruteforce prevention, QoS, alerting when WAN goes down, and so on, has all been a breeze to set up.
Cost | Purpose | What
$109 | Router | PCEngines apu2c2 http://pcengines.ch/apu2c2.htm
$10 | Router Case | http://pcengines.ch/case1d2blku.htm
$17 | Router Storage | http://pcengines.ch/msata16g.htm
$30 | Gigabit Switch | https://www.amazon.com/D-Link-Gigabit-Unmanaged-Desktop-DGS-108/dp/B000BCC0LO/
$80 | Wifi | Ubiquiti Unifi Lite https://www.amazon.com/Ubiquiti-Unifi-Ap-AC-Lite-UAPACLITEUS/dp/B015PR20GY/
With this setup, the router only does _routing_, so you also need a Wireless Access Point (WAP). Connect it like so: Modem->Router->Switch->WAP.Install pfSense on the router, configure the Unifi using Ubiquiti's Java app, and you're done. It's about $250 all together which _is_ more expensive than consumer routers, but IMHO it's worth the superior quality. The APU board is well-documented (PCEngines provides schematics!) and the firmware is based on Coreboot. The processor supports AES acceleration for faster encryption (great if you use VPNs!) PfSense is an enterprise-grade router/firewall with scads of graphs and features. And the Unifi has a great antenna with excellent range. Not to mention this setup leaves you with six spare ethernet ports on the switch.
My guess the if you get a wireless router, wifi signal strength is most important part, aside from that any mainstream router is probably OK.
That's because Ubiquiti Edgerouters and APs use the same processors and radios as consumer routers. If there's any truth to the memes about hardware quality, then the differences lie in things like the power supplies. Most of the perceived improvement in stability that Ubiquiti Edgerouters offer comes from having software that is actively maintained and not stuck on decade-old software branches. You can get all the same software benefits (more, really) by running OpenWRT on consumer hardware.
It's easy to set up and run multiple services (think XMPP, ssh, IP over DNS...).
Some time ago I decided to get a little more serious about security and put a mini-PC running pfsense between my home LAN and the Internet. Hopefully that is more secure though a similar search wouldn't prove that. Perusing some of the critical vulnerabilities at cvedetails.com seems to show that the only critical vulnerability for either of these is for versions of the software older than what I'm running. And I also see the flashing yellow "!" on the Asus management page that indicates an update is available.
That latter part is really a concern. I don't get a notification for an update unless I go look for it. Logging to either is not something I do every day.