Bird – Internet Routing Daemon
bird.network.cz
bird.network.cz
The recently announced Mozilla WebThings gateway also runs on the Turris:
https://news.ycombinator.com/item?id=20532763
The BIRD Internet Routing Daemon, a BGP routing service you can run yourself, is included in the available OpenWRT packages:
https://openwrt.org/packages/pkgdata/bird4
No, I don't run BIRD myself, though it could be fun to play with.
A ubnt edgerouter-x is good for up to about 800Mbps of NAT and runs an os derived from Debian and vyatta. Or something like a mikrotik rb4011.
Then buy a dedicated purpose wifi ap like a ubnt uap pro that does dual band 802.11ac.
A router should be a thing that has 1000baseT ports on it, maybe an sfp or sfp+ cage and no wireless. A wifi ap should be a thing with no routing functionality that serves the purpose to bridge a wifi client device at layer 2 onto some specific section of Ethernet fabric.
Why?
If you need a media converter, router, and wireless access point anyway, there are obvious space and power advantages to combining these functions into a single device.
I could see a concern about performance, but from scanning online reviews, it seems like the Turris Omnia performs just fine.
> A router should ... > A wifi ap should ...
Instead of just stating your beliefs as if their truth is self-evident, please offer some rationale.
In my field, "toy" is anything that costs under 500 bucks. If we want a wireless interface for OOB, we'll add an opengear LTE gateway device.
The router I mentioned in the earlier post consumes 5W of power and is the size of a pack of cigarettes. It looks like a toy, and is under $50, basically disposable, but is much more stable and bug free than home routers you can buy from $85-275 at Best buy which integrate wifi capability.
The consumer market for cool looking multi band $200 routers with spiky antennas coming out of the top is, in my opinion, ridiculous.
As for the dedicated wifi side, ask any professional who uses (on the cheap side, ubnt) or xirrus, ruckus APs in environments with thousands of clients whether wifi aps should also be routers. They'll have a good laugh at the idea.
Personally, I was thinking to configure network with ER-X for myself, but I quickly started to reconsider to take ER-4/ER-6 or Omnia, which seems to be few magnitudes better. Omnia is great SOHO router, it has better transfer over the air (5GHz on Turris it's between 900-950 [0]) than ER-X in eth-eth (700-800 [1]). If you aren't scarred of having a all-in-one device[6], then it might a great choice if you would like more possibilities, e.g. to setup few more services directly on Turris (i.e. PiHole, Syncthing) with mSATA disk, instead of using RaspberryPi with SD card (:scream:) for this purpose. In terms of pricing (for EU customers) pricing does not sound that bad (if you also looking to have a WLAN network), because ubnt ER-4/RaspberryPi 3B+/UAP Lite (note, it's slower MIMO 2x2) [2][3][4] is about 260+ pounds, for Omnia 270+ pounds.
[0]: https://bluegadgettooth.com/best-openwrt-router/
[1]: https://www.mbreviews.com/ubiquiti-edgerouter-x-review/
[2]: https://skinflint.co.uk/ubiquiti-edgerouter-4-er-4-a1749252.... (~160)
[3]: https://skinflint.co.uk/raspberry-pi-3-model-b-a1785657.html (~30)
[4]: https://skinflint.co.uk/ubiquiti-unifi-ap-ac-lite-uap-ac-lit... (~70)
[5]: https://skinflint.co.uk/turris-omnia-2gb-a1520592.html (~270)
[6]: I have heard following rule of thumb, that networks should be organized to have dedicated devices per given resposibility instead of having such router-switch-nas-godzillas, because of easier replacement in case of failure, maintenance, etc. etc. (just like in microservices architecture).
Just curious, why? (You just mentioned "shoulds" and "dos", not "whys")
Have a router supporting weird configurations like CenturyLink gigabit gpon service, which if you don't want to use their terrible gateway device, requires a unique vlan tag on the wan interface.
Ability to have a router that is Debian under the hood.
That 800Mbps won't do much for a 10 Mbps ADSL circuit, or even 100 Mbps cable. Though if you can saturate that, props to you.
Well yeah, they also have a little side business managing the .cz TLD and coordinating Czech ISPs /wrt infrastructure roll-outs, security incidents, etc...
For most of the HN crowd, the Turris / OpenWRT angle likelely has more immediate "what does this mean for me / what can I do with this" significance.
Good routers are built for reliability, and most of them seem to opt for slowish CPUs and a fast-path for routing that doesn't involve the CPU at all. The CPU is there to update the routing table and do other supporting chores.
[0]: https://www.ui.com/edgemax/comparison/
[1]: https://help.ubnt.com/hc/en-us/articles/115006567467-EdgeRou...
The number one flaw of commercial routers/security devices is that they don't get updated or can't get updated.
If you don't want an Omnia, I would strongly advise building a low power computer that runs a mainstream Linux distro with excellent security support -- Debian is an excellent choice -- and spending a few days setting it up properly.
As you mention, Turris updates automatically. For stock OpenWRT you've got to manage upgrades (and add'l pckg install and configs) yourself. The generous storage means you can add additional OpenWRT packages and apps as desired.
Auto-updating a plain OpenWRT installation is not hard to implement and allows you to stay up-to-date.
That said, the Omnia's hardware is pretty great and the fact that you can plug eMMC storage to run LXC containers is absolutely fantastic.
You can also install plain OpenWRT on it these days.
A major set of problems are:
- Minuscule rewriteable storage on consumer networking kit.
- The need to create a firmware image, and not merely select and configure packages on disk.
- Bootloader fuckwittedness.
None of these are OpenWRT's fault. They do define the operating theatre, however. Unfortunately, in light of this, OpenWRTs tools and documentation are not up to the task. Yes, free software, volunteer project, etc., etc. I'm hoping my criticisms may be useful.
Many consumer devices (my ADSL modem comes to mind) have nanoscopic writable storage: 8 MB is not atypical.
OpenWRT's other upgrade opions are ... neither clearly stated nor readily achieved.
One of the higher-ranked HN OpenWRT submissions concerns why there is no autoupdate:
https://web.archive.org/web/20160206204329/http://prpl.works... (https://news.ycombinator.com/item?id=10870294)
The OpenWRT user guide does not clearly address system upgrades, though there's otherwise good coverage of many topics:
https://openwrt.org/docs/guide-user/start
The most applicable section appears to be "Installing Additional Software", with sections:
- Beginners guide to building your own firmware
- Extroot configuration
- Managing packages
- Opkg Package Manager
- Saving firmware space
- Show available package upgrades after SSH login
- Using the Image Builder
Only the last directly addresses upgrading. A dedicated "System UpgradinG" document would be extremely useful.
The sysupgrade docs are not in the user guide but the technical reference:
https://openwrt.org/docs/techref/sysupgrade
I've tried compiling from source. There's a hell of a lot of menuconfig, and my build failed after 9+ hours. Not newbie-friendly at all. (FWIW I don't consideer mysef a newbie.)
I've not yet tried the imagebuilder.
I'm very familiar (20+ years) with Febian, and both the familiarity and its APT package management make the process highly predictable (with much help from ample storage and open bootloader standards). OpenWRTx is a long way from that, yet.
If you've any illumination or advice to add beyond "Auto-updating a plain OpenWRT installation is not hard to implement and allows you to stay up-to-date", I'm all ears.
Both VPNs and proxies are supported. "VPN proxying" isn't a familiar term.
Generally, Turris has any OpenWRT capability. Possibly helpful:
https://openwrt.org/docs/guide-user/services/vpn/openvpn/cli...
https://openwrt.org/docs/guide-user/services/tor/create-tor-...
For example it’s used by Netflix for “sharing network topology from ISP networks to Netflix control system in AWS” [2].
[1] https://joinup.ec.europa.eu/collection/open-source-observato...
It’s now sitting in my closet with a burnt out chip. Long story short, I put the same network cards in it all the enthusiasts were. Those slots were meant to be user upgradeable. It starts smoking, I open it up and send some pics to the company. They don’t get back to me. Two weeks later I do what anyone does in this position and post on their forums. That gets their attention, they write me back. Immediately they’re on the defensive and after another week of bartering agree to take a look at it only if I ship it to them at my expense and pay for the repairs. At this point I’ve already sunk 5 hundred dollars into it so I agree and ask for a shipping address. They never get back to me. Over the next month I send them follow up emails literally begging to pay them to fix my router. I never got a response.
Between CZ.nic and Purism, I’ve sworn off small hardware shops. It’s been my experience they often don’t stand behind their products when they fail or simply lack the customer service bigger firms can afford.
I ended up buying a few mesh routers from Synology which have been purring away ever since.
having to deploy whole zebra to just be able to announce local docker routes is a bit too much for my liking
I don't really get what dynamic IP routing is, or what this project means to solve at internet scale?
BGP can also be used inside an AS and some container networking solutions (e.g. kube-router for kubernetes) also use it.
A routing daemon speaks one or more routing protocol to build a table of routes. That can be used for various purposes, including programming the host's own routing table (bird runs on UNIX-like OSes) or other implementations can update a special kind of memory called a CAM (think something like a hashtable in silicon) an ASIC on a router/route switch uses.
Check wikipedia for BGP and peering and you should have what you desire.
Often in a setup where the aggregation router has dual links to a pair of big core routers. The cores only speak bgp within their own AS.
Or in a particularly big POP, a twin pair of agg routers connected in a X shaped topology to a pair of core routers.
[0] https://bird.network.cz/?get_doc&v=20&f=bird-1.html#ss1.1
this is primarily accomplished by running a routing protocol which allows ‘adjacent’ routers to exchange routing information, f.e rip, ospf, bgp etc.
with static routing, a more ‘hands on’ approach is required...