Another option would be your own hardware with pfsense (bsd) or ipfire(linux).
Even further would be your own hardware with linux and write your own nftables or bpf.
Another option would be your own hardware with pfsense (bsd) or ipfire(linux).
Even further would be your own hardware with linux and write your own nftables or bpf.
The best option in my opinion is something Intel based running a well known Linux distro with automated security updates that is fully in your control. Shorewall can do everything needed for a home router. This option is a lot more expensive though.
(Sadly my home internet connection is too slow to make hardware offloading on the edge router matter...)
Interesting, do you have any more about this?
Got an ER-PoE that intermittently loses packets and have never got to the bottom of why (I gave up and bought a non-Ubnt router, just haven’t got around to configuring it yet).
I was one of the people involved in some of the measurements on there.
I avoid ubnt networking gear in general after that experience (although ER-X seems good and I use one at home as a smart switch). Their specialty is in APs, which work really great.
In any case, you can load it onto some fairly low cost hardware for your typical home user. It's fantastic.
I am not a huge fan of the Ubiquiti routers. They required loading a config onto them just to get DHCP enabled and NAT setup for a typical 1 WAN and 1 LAN environment. Why on earth they would ship without that config on them when 99.9999% of environments are like that is bewildering to me.
Don't know if it's changed since then but I haven't gone back to mess with them since.
As a Linux guy I have to admit PFSense and similar products (NAS4Free etc) interface is the best I have ever seen around wrt functionality and ease of use, sadly OpenWRT web interface simply doesn't stand a chance, and I'm not referring to aesthetics as I'm aware OpenWRT is aimed at hardware with orders of magnitude less resources, but pure functionality - in fact I have never been able to configure a small tp-link mr3020 router to use it as a WiFi bridge for my networked but not wireless printer. Yes it can be done and there is a HOWTO on that task, but it doesn't work and low level iptables scripts aren't exactly my strong point. It would be trivial doing that with PFSense, but sadly it cannot fit into that device. /Rant
[1] https://www.openbsd.org/octeon.html
[2] https://news.ycombinator.com/item?id=10079210
[3] https://an.undulating.space/post/180411-erl-openbsd-upgrade/
Unfortunately I was wrong and the post is just for cryptography acceleration. Will have to check the commits to see if any other work has been done.
They're basically the same hardware.
For whatever braindead reason, they told me that they wouldn't give me an RMA because they don't "support" 3rd party SFP modules. They wouldn't loan me one to fix the problem, they wouldn't agree to reimburse me if it didn't fix the problem, nothing. Buy their module or deal with broken equipment.
I bought one of their SFP modules and to nobody's surprise the problem persisted. At the same time I bought a Mikrotik hAP and again to nobody's surprise, all the SFP modules that "failed" worked with zero problems.
At that point Ubiquiti finally granted me an RMA but at that point I went and got a refund instead.
After that support experience, I'll never buy Ubiquiti or recommend it again.
I'd much rather recommend PC-Engines: https://www.pcengines.ch/. They're x86 based so you can run whatever on them, cheap and have really good performance.