Another option would be your own hardware with pfsense (bsd) or ipfire(linux).
Even further would be your own hardware with linux and write your own nftables or bpf.
The best option in my opinion is something Intel based running a well known Linux distro with automated security updates that is fully in your control. Shorewall can do everything needed for a home router. This option is a lot more expensive though.
(Sadly my home internet connection is too slow to make hardware offloading on the edge router matter...)
Interesting, do you have any more about this?
Got an ER-PoE that intermittently loses packets and have never got to the bottom of why (I gave up and bought a non-Ubnt router, just haven’t got around to configuring it yet).
I was one of the people involved in some of the measurements on there.
I avoid ubnt networking gear in general after that experience (although ER-X seems good and I use one at home as a smart switch). Their specialty is in APs, which work really great.
[1] https://www.openbsd.org/octeon.html
[2] https://news.ycombinator.com/item?id=10079210
[3] https://an.undulating.space/post/180411-erl-openbsd-upgrade/
Unfortunately I was wrong and the post is just for cryptography acceleration. Will have to check the commits to see if any other work has been done.
They're basically the same hardware.
In any case, you can load it onto some fairly low cost hardware for your typical home user. It's fantastic.
I am not a huge fan of the Ubiquiti routers. They required loading a config onto them just to get DHCP enabled and NAT setup for a typical 1 WAN and 1 LAN environment. Why on earth they would ship without that config on them when 99.9999% of environments are like that is bewildering to me.
Don't know if it's changed since then but I haven't gone back to mess with them since.
As a Linux guy I have to admit PFSense and similar products (NAS4Free etc) interface is the best I have ever seen around wrt functionality and ease of use, sadly OpenWRT web interface simply doesn't stand a chance, and I'm not referring to aesthetics as I'm aware OpenWRT is aimed at hardware with orders of magnitude less resources, but pure functionality - in fact I have never been able to configure a small tp-link mr3020 router to use it as a WiFi bridge for my networked but not wireless printer. Yes it can be done and there is a HOWTO on that task, but it doesn't work and low level iptables scripts aren't exactly my strong point. It would be trivial doing that with PFSense, but sadly it cannot fit into that device. /Rant
For whatever braindead reason, they told me that they wouldn't give me an RMA because they don't "support" 3rd party SFP modules. They wouldn't loan me one to fix the problem, they wouldn't agree to reimburse me if it didn't fix the problem, nothing. Buy their module or deal with broken equipment.
I bought one of their SFP modules and to nobody's surprise the problem persisted. At the same time I bought a Mikrotik hAP and again to nobody's surprise, all the SFP modules that "failed" worked with zero problems.
At that point Ubiquiti finally granted me an RMA but at that point I went and got a refund instead.
After that support experience, I'll never buy Ubiquiti or recommend it again.
I'd much rather recommend PC-Engines: https://www.pcengines.ch/. They're x86 based so you can run whatever on them, cheap and have really good performance.
The other option I've heard good things about are the PCEngines devices. They don't, as far as I'm aware, have hardware offload, so make sure their performance suits, but they use OSS U-Boot and you install the OS of your choice. It's one of the most open devices in a router form factor I've come across.
Depending on the number of ports you need, you could also use one of the Jetway devices. They make them with varying numbers of ports as SBCs in a case and you add RAM/M.2 SSD. I got a Celeron one with 2 ports and run it as a Suricata IPS. It performed just fine with my 100M pipe.
So speeds are kind a slow, around 50-90 megabits (i have gigabit fiber, that the er-x otherwise can fill out completely).
It can sustain 500mbit/s with no issue. As this is my internet connection speed, I don't know if it can go any higher.
My one complaint about this approach is that there are so many interactions happening at the software level that any time I set up a network stack, I always feel as though the whole thing is very fragile and only works because everything is precisely configured. Since I like to tinker, I want a system that feels more reliable, and so I go for the router-in-a-box approach of pfsense or opnsense. I wish it was easy to get a network configuration that "just works".
Specifically, the best deals can be had on the oldest model, the R6700v3, from an Amazon warehouse deal for $70. This is what I use, and it works without issue with dd-wrt. You'll need to flash it 3 times.
The best device is probably the R7800 model. It uses a very fast, non-Broadcom (OpenWRT-supported), modern chip. The only way this matters in practice is if (1) you have a gigabit Internet connection and (2) if you need QoS turned on for scoring an A+ in "bufferbloat" on speedtest.net--i.e., you play games.
If you don't use QoS, you will be able to serve 1 gigabit with dd-wrt's "Shortcut Forwarding Engine," which is an accelerated "in-Linux-kernel IP packet forwarding engine." If you don't have a gigabit connection, the typical Linux routing stuff that dd-wrt uses is fine.
With regards to model roulette, you can always buy it off eBay for the specific model. These routers are so common I see listing for them in Craigslist in the Bay Area right now.
I would argue the two main reasons to do this are for improved security/stability and QoS. If you're not interested in these features, buy something that Wirecutter recommends in your price range. But compared to $70, I believe a truly decent router can be had for $50 (the Archer series others have mentioned) that is also truly ancient.
The Apple Airport devices run ARM NetBSD and you can SSH into them. The last generation ran NetBSD 7 and executed binaries from NetBSD userspace when compiled statically.
OpenWRT does not ship closed-source Broadcom drivers, so it tends to have worse support across the board. I don't think their OSS-related reasons for doing so are material to you.
It's one of the only WiFi routers I've ever worked with that has a fallback flash mode in the bootloader, and the only one that I know you can buy today. This is invaluable when you're not sure if something you're doing could make it fail to boot, like installing an upgrade without knowing whether it uses the same partition layout as you had. When it does you can just try again. (I've needed this once already.)
I retired them mostly because the Ubiquiti management is much easier and that hardware also affordable (though the software is not open, so not a fit for your use case).
(I'm not disputing your experience, but don't want other readers to conclude that 5GHz doesn't work on any of them.)
It's absolutely not all roses on the UBNT side of things. They are exhibiting some of classic signs of expanding too fast and stretching themselves a bit too thin. In particular their hardware lineup is starting to get overly broad and they aren't being aggressive about retiring older products and keeping the matrix simple, which of course in turn represents an increasing maintenance burden. And some of their hardware which was disruptively priced and fantastic value at launch is now getting very old in the tooth. The UniFi controller UI can be shallow for more then simple usage of things like DNS/DHCP/RADIUS, granted a lot of HN types may have their own separate appliances/servers for that. Their USG has always been a bit of an orphan and only recently has really started getting the serious attention it needs. They've got some features on high end hardware that while niche still haven't been fleshed out. Their EdgeRouter hardware is keeping up better though.
That said the update process has continued to be pleasant and solid, and their support even for old devices has been excellent. There are no required ties to any external services. The hardware itself has been very reliable, and even the RMA process for when something burned out on us was decent (2 minute wait to online chat on a Sunday morning and immediate RMA approval). They've been quite good on security updates for a number of the major issues that have come up over the last year, and have had no major snafus (that MikroTik one storing passwords as plain text was painful/disturbing to see). While enterprises will have more advanced needs for SoHo situations even if they're not open source I think UBNT is worth consideration, particularly for those wearing plenty of hats already who are ready to cut down on cognitive load a bit.
I've been running UniFi APs for years, but recently switched from my pfSense appliances to USG routers. I lost a lot of flexibility (especially for things like VPN configuration), but the simplicity and seamless management have been a huge time-saver.
I am puzzled by some of their new offerings—do they really expect any serious commercial customers to install lighting powered by PoE? Perhaps they're onto something innovative, but it seems like a distraction from their core business.
Yes, although I want to emphasize again that while they made a new hire specifically for the USG and it's seen dramatic improvements in the last year [1] it was still a kind of orphan child for a while and I still need to drop down to the shell sometimes for initial setup. Rock solid after that and simple and good integration with the overall site sure but it hasn't always been clear for someone starting from scratch how to get it up the first time in common SoHo situations. Also for those with gigabit links who want to run Suricata IDS/IPS (which requires turning off hardware offload), Ubiquiti just doesn't offer anything even remotely SoHo priced with the muscle for that right now. The low end USG "3P" (~$110) maxes out around 150 Mbps with IPS after the most recent update (an improvement from 85 Mbps before that) while the Pro (~$300) maxes out around 430-450. Only the XG can handle a gigabit or higher but that's $2500 and built with 8x 10G links, it's ludicrous overkill for those who don't want its other features and routing. Granted gigabit fiber links are far from the norm but they're gradually increasing and the HN crowd may be more likely to go for them then many, and the hardware in the USG 3P and USG Pro is just old now.
>I am puzzled by some of their new offerings—do they really expect any serious commercial customers to install lighting powered by PoE? Perhaps they're onto something innovative, but it seems like a distraction from their core business.
I definitely agree about distractions, though at the same time we should recognize that of course different divisions and people can be doing different things at the same time, development and engineering talent isn't necessarily fungible there. Still, they aren't a megacorp, overall resources and management bandwidth isn't unlimited either.
On the other hand at one point Ubiquiti had a real effort in the IOT space called MFi, but due to a lot of internal technical debt issues there (IIRC there) it essentially got canned, and they planned to eventually resurrect it on top of their more advanced foundations but haven't had the bandwidth. Maybe the lighting and their efforts to improve their security offerings are some first baby steps towards getting back into that? In fairness IOT has some of the same properties in terms of suckage that have made their networking efforts successful, and could also be a major market. Updates are often a pain or non-existent, the security story is awful, and much of it insists on using 3rd party cloud dependencies. There could be a real valuable hole there for Ubiquiti to fill were they to execute well enough, though I'd feel better about it if their core felt more tightly managed and foundations a bit steadier. We'll see I guess, and at least lighting should have been a pretty low R&D way experiment with it?
---
1: And for better or worse, the very fact of a piece of cheaper networking gear seeing years of support and improvements is depressingly unusual in the industry.
[1] DD-WRT struggled with 100Mbps to WAN - hardware NAT
x86, can run OpenWRT.
Later today (if all goes well) I'll be adding wifi to it!
At one point I had an 802.11n card in my older ALIX2D router, but there were stability and performance issues so now I always use a separate access point, most recently a Unifi AC-PRO which has some quirks but works well in general.
I've been happy enough with the x86 routing strategy that when it came time to replace my older Cisco 100mbps switch, I decided to do that with x86 hardware as well. All of the smaller/cheaper gigabit switches either didn't support VLANs, made way too much heat, or had reliability issues, and the ones that were suitable were quite expensive and had reliability issues of their own.
So, I found a Supermicro Atom C2000 board (A1SRM-LN7F[1]) on sale for $90, which has 7 Intel NIC gigabit ports built-in and supports ECC ram. I put it in a Supermicro 1U[2] enclosure along with an Intel PCIe 4x gigabit NIC, for a total of 11 gigabit ports on the switch. I installed Debian on it and set up open-vswitch, which worked but was soon replaced by "vlan-aware" Linux bridging.
It's easily capable of switching gigabit traffic between multiple machines at the same time, ping shows an average latency of 0.310ms, has very low power usage and makes very little heat.
Note that those C2000 Atoms do have a "sudden death" hardware flaw, but Supermicro should have fixed it on more recent inventory, and they will send a "patched" board to replace any that are affected before they fail. The Atom C3000 doesn't have that issue, but I don't think Supermicro (or anyone, really) make any C3000 boards with that many built-in gigabit ports.
[1] http://www.supermicro.com/products/motherboard/Atom/X10/A1SR...
[2] http://www.supermicro.com/products/chassis/1U/510/SC510T-203...
Take a look e.g. at OpenWrt's list of devices "Ideal for OpenWrt": https://openwrt.org/toh/views/toh_available_864
Consider TP-Link Archer C7, for instance. It is an older one, but has reasonably fast hardware, supports IEEE 802.11ac and is available on Amazon. New costs ~75 USD, a "certified refurbished" version costs ~50 USD.
I have performed some simple tests using `iperf` tool on Archer C7 with OpenWrt and it was able to sustain wired network speeds of around 750 Mb/s and wireless speeds (IEEE 802.11ac) of around 300 Mb/s (maybe even more, but I do not remember exactly).
[0] https://www.aliexpress.com/item/Wifi-Router-NEXX-WT3020H-300...
There are many brands and models that are compatible with OpenWRT. I have good experience with tp-link wr1043nd, wdr3600 but they are a bit old by now. I just ordered ZyXEL NBG6617 to test out.
If you really need a small / low power usage appliance then some Ubiquiti devices run OpenBSD as I mentioned in another reply below.
Anecdotally OpenBSD also supports wireguard if that's a concern.
Otherwise, get an edgerouter.
(2) If you get the wrong router, just return it and get another.
(3) Buy a router at a brick and mortar store so you know what you're getting.
If you're flashing your own images of OpenWRT, there are a few conveniences which are a bit more uncommon in the hardware which are useful if you ever need to debrick - eg easily openable case, UART header comes pre-installed (you don't need to solder your own), etc.
TP-Link, the former manufacturer of my choice, unfortunately has become a version roulette it seems.
If power consumption does not bother you, maybe banana pi? Or something atom based?
I would assume that they are easy to flash and high compatible.
If I am not mistaken FRITZ!OS is a Linux distribution.
Edit: actually, it is possible at least for some MT hardware : https://wiki.openwrt.org/toh/mikrotik/common
What’s your reason for suggesting friends buy a modem/router beyond the cost?