OpenWrt 19.07
openwrt.org
openwrt.org
I have an End-Of-Life'd SG-1000 from PFsense developer NetGate https://www.netgate.com/solutions/pfsense/sg-1000.html
The thing no longer gets updates as of October 2019 and was never particularly well supported, but feels like an absolutely perfect OpenWRT target
I've poked at it on and off with regard to getting Linux running, as it seems to be heavily based off a standard, old Ti SoC "evaluation board" and it /mostly/ works
The problem I've run into though with the upstream kernel is the ethernet NIC's appear to be linked. If you unplug either interface, they both stop responding until they are both reconnected to active devices. I'm not well-versed enough with ARM DeviceTree to figure out what the issue is, nor do I want to buy the Ti hardware SDK to test it with
The old 4.4.3-yocto files Netgate sent me do appear to work with it, and the DeviceTree even works up to 4.19-LTS with minimal modification https://intelminer.com/pflin.zip
(I have no idea if OpenWRT in particular is like this, but there’s enough out there that people don’t make them their first port of call.)
I have ported three different devices to OpenWRT/LEDE over the years. In the first instance, it was pretty easy and they just accepted it.
In the second case they gave me the runaround and bullshitted until I just said I gave up. I used an alternate email address/alias to get it accepted. They took it with almost no changes just because they thought I was another person. They would have never accepted it had they known.
In the third case I was given a hard time again and just gave up, but never went back to get the device accepted and just don't care.
There are people like Kresin and Crispin and a few other toxic jerks who will fuck around with you for reasons I don't completely understand. There's a lot of smoke-filled-room bullshit that goes on in IRC channels that nobody ever gets to see in the OpenWRT community and so the decision making is super opaque and you have no idea what the real reason is they won't accept your patch while they pretend there's something else wrong with it on the mailing list (sudden onset application of policy that doesn't exist or they will just ask you to explain something begin and then pretend they don't understand).
It's not all bad over there. jow and Felix Fietkau are awesome, but they either don't have the power or don't care to make the org better.
The whole LEDE/OpenWRT fork thing will tell you a lot about the organization.
Oh yea, I almost forgot. How did OP here know about the new release of OpenWRT? They have no end-user mailing list. They don't have a twitter feed. They don't do facebook. They seem to hate their userbase because they have NO MECHANISM to alert end-users that there's a new release of the operating system. The update the wiki, maybe do a forum post if you are lucky, and that's it. Pure word-of-mouth.
Yea OpenWRT has problems.
RSS/Atom is alive and well, mainly because it's built into every CMS and blog engine by default, but requires some digging through the HEAD of a page to get it into a reader now that most browsers don't treat is as a first class format.
Mozilla corporate BSed their way out of RSS. Their source for their claim that "nobody uses RSS" comes from their telemetry. Not one thought was given to the idea that maybe RSS users simply disable that more often?
This is not a complaint - the wiki is big, the lede/openwrt division very likely incurred a cost that the project still has to recover from. Actually a openwrt-announce mailinglist exists, but nothing is send there yet. "Announcements" has been one of the topics in a recent meeting - https://openwrt.org/meetings/20191121
A couple more (less intense) experiences like this and bullshit reasons for refusing patches and nowadays whenever I improve or extend some open source stuff I just quietly do so in a fork on github and that's it. Maybe the original maintainers discover it one day. Also saves me the hassle of trying to adhere to any coding guidelines etc. for no reason.
That is assuming they use GitHub or a moral equivalent and it isn’t instead buried in sourceforge or god help you some dusty SVN repo.
The nice thing about GitHub is it dramatically lowers the barriers to contributing to open source projects. I remember before pull requests you’d have to generate patches using arcane commands you’d copy and paste from some website. Then you’d email the diff to some mailing list and hope for the best.
Pull requests are perhaps the best thing that happened to open source.
/me: Bug in the build system. This is how to reproduce.
/they: Bug in Linux kernel. Not our problem.
/they: Bug is closed, upstream issue.
/me: No, toolchain bug. Here is proof.
/they: need logs
/me: here's logs
/me: here's a clumsy fix
/they: that's so stupid
/they: and your linux installation is broken
/me: no it's not, see here, working as intended
/they: you don't understand cross-compiling
/me: look here, you are setting up the cross-compilation all wrong
/they: kernel bug, fixed upstream
/me: not that again
/me: here's build logs, cross-compilation issue
/they: you are stupid, your linux installation is broken
/me: linux installation is just fine, but you are relying on a debian-ism
/me: here's patch
/they: ok, send to mailing list for review
/they: IRC says patch stupid
/they: we've merged our patch
They really need to work on being not hostile and clannish. Never had any issue on other mailing lists, and those weren't the Kumbaya-required kind with a code of conduct.
Maybe something like survival of the fittest (Darwinian). Each build attempt runs the gauntlet. Only variations which survive get promoted.
I recently learned about "Test Into Prod", a seemingly effective methodology for mitigating the PR-based workflow bottlenecks.
So sorry, but I can't quickly refind the conference talks. (New laptop doesn't have my old browser history.) The speaker had previously done a fashion startup. Glib? Gilb? Argh. Sorry.
Then have the workflow look more like (1) anon q public submits repro file & issue description, (2) auto-test system runs and validates repro file, (3) issue auto-logged, (4) issue cannot be manually unlogged without fix (if upstream, move to side filter, pending upstream fix)
The human triage stage usually seems the most adversarial. So having an automated system take it to "Yup, this is a bug" would be a good start.
This happened to me, but with a different project.. laughed off the mailing list for a dumb patch only to be included in a near term update. I seriously walked away from large open source projects for almost 6 years because of this attitude.
As always, back up your config, and make a note of your working firmware before upgrading. I’m going to sit this one out for a bit :).
> Get one for my parents, flash it with OpenWRT - 200mbps down - not crazy but enough for them
> One year later, update with an "optimized" version - 600mbps down - amazed
> One year later, update with latest - down to 200mbps and can't find the build I've used previously!
You won't regret it.
I have a Moto G2 a.k.a. "Titan" (2014), flashed it to LineageOS, bricked it three years ago, got another phone, recently checked it out again, and couldn't download LineageOS for it anymore.
Luckily, MicroG still had a ROM for it, and now it works fine, but I'd've preferred the pure LOS version, as it runs Android 7, on which Google Play Services is not an absolute necessity (with Android 8, you need it to get push notifications).
I believe I can still get the source code for it and compile it myself, but I've never done that for an Android ROM before, and I'm not particularly keen on trying that out now.
My point being: Your devices could, in theory, live forever, but the files for it (ROMs and drivers) may not always be available, and knowing the internet, won't.
In my field (industrial IT), it's not uncommon to still have PCs running on Intel Core2 systems, but more and more vendors are dropping the product pages and driver files for them. Pentium 4s are also still being used, but good luck finding drivers for them.
Comcast was more than happy to charge me for a half gigabit for several years. All the while the modem I was renting from them only supported like 200mbit.
5GHz is okay but flashing anything other than official firmware breaks the 2.4GHz.
Suddenly all of my ESP8266 are disconnected. My Brother printer also cannot reach the WiFi.
I had to test it on my (deprecated) Netgear EX2700 and could confirm the exact same problem. Other than the lack of configuration persistence, 19.07 performs just great and I was pleased with many of the new features and changes. Unfortunately I'll have to stick with 18.06.6 as I have power outtages every now and then.
Images for some device became too big to support a persistent overlay, causing such models to lose configuration after a reboot. If you experience this problem, please report the affected device in the forum and consider downgrading to OpenWrt 18.06 or using the Image Builder to pack a smaller custom image.
If you are confident building your own image, try to inverse the button state here and test it out / send a patch: https://github.com/openwrt/openwrt/blob/master/target/linux/...
This release brings all devices up to the same (mostly) unpatched Linux kernel, 4.14.
For the popular Tp-link Archer C7 routers (and family?) you finally get soft off-loading with the new ath79 device-tree, meaning the device can now handle routing 600mbps+ where it before would only route 350mbps+. That’s massive!
The new client-side GUI is noticeably snappier on slow routers.
I’ve already upgraded all the 5 units I have in my home network, and I’m feeling it. I’ve kept settings despite recommendations against doing so, and I’ve had zero problems. Super-smooth!
Props to the team and everyone involved. Despite their modesty this was quite a release!
The C7 was fine for a while but in the end got extremely unreliable, even in partial roles as only a router (with wifi disabled) and then later as only a an AP (with the DHCP server disabled). Currently it's unplugged because any time it was turned on, devices would roam to it and get stuck there with no connectivity.
I should try upgrading it to the latest OpenWRT and see if things are any better.
What about say configuring my own OpenBSD server to act as a router? I am out of my intellectual depth here but I feel like that would be more secure than Linux in general if we are going for max security.
As governments and private equity groups continue to buy out whatever hosting provider, VPN, Registrar, etc they can find...I feel like Open Source is a pretty soft target in the grand scheme of things. I am trying to become somewhat ruthless in analyzing my dependencies when it comes to software.
NOTE: another commenter mentioned a TP-Link product. Those devices are absolutely insecure to the core of their firmware for the time being. 7 days ago I discovered their completely open production Elasticsearch API server for their entire camera and IOT platform in the United States. It has now been remediated but that event puts under suspicion anything else the company deals with via the TP-Link brand out of Shenzhen.
A Google Wifi setup (with it's automatic updates) is probably better for privacy and security than the TP-Link. Better still would be pfsense, vyatta. Personally, I use an ER-X running a minor vyatta fork and it's rock solid.
That may have been me.
> Those devices are absolutely insecure to the core of their firmware for the time being.
Which is why you replace that firmware with OpenWRT, right?
I really can't stress enough how good the documentation is; in the Linux world I'm used to googling and wikis and whatnot because most man pages for the components of a distro are either nonexistent or incomplete, but with OpenBSD, you'll do fine with just man and apropos. It's considered a bug if the documentation is missing something.
OpenBSD is a fantastic OS for learning about all kinds of UNIX and networking stuff if you're not opposed to spending some time reading good quality documentation.
I installed OpenBSD on an APU2C4 and it has been rock solid for the last year and a bit.
In terms of cost you will be hard pressed to find a x86 SOC with 4 I tel NICs and a serial port at a cheaper price.
I'm unaware of someone having put that together for OpenBSD, but think it should run on similar hardware. If so, then their Website is buggy for listing long obsolete devkits/boards only.
The non-x86 alternatives I don't have much experience in save for an Ubiquiti EdgeRouter Lite, which works fine, but is a bit of a pain to operate because there's no syspatch support.
If you just want a secure router at a low price, OpenWRT on a well-supported platform probably gets closest to that; I have an old TP-Link router in the closet somewhere that's over 10 years old now and could still run the latest version of OpenWRT.
If you can't use OpenWrt then buy enterprise-grade equipment. Personally I'm using a combination of a Mikrotik router at the edge and then consumer-grade powerline access points with OpenWrt (not strictly needed for security as they're behind the firewall already, this was more for functionality to support 802.11r for Wi-Fi).
All that said, I'm not sure how misconfigured TP-Link infrastructure would lead one to declare all their device firmware is bad.
This strikes me as both very difficult and very wise, in the way that choosing to run Linux on your desktop was 20 years ago.
I would not run Tomato? on a router in 2020 it runs with old Kernels and old packages.
Disclaimer: I am not a OpenWrt dev I just help out around the place like on Twitter forums PS if any one needs help pleas come to the forums we will help out as best as we can. Some people think that OpenWrt has devs that are not very tolerant. I can tell you that this is not true. there was a bug in LUCI the webinterface that made it hard to use with my screen reader I asked about it on irc and it was fixt in 3 hours.
From the internet, nothing should be exposed - or maybe OpenVPN port or ssh?
From outside, usually you would see WPA2-PSK network. I know there are some attacks on WPA2, but I don't know if they're practical. I also know that WPS (that PIN thing) is very insecure, but that is hopefully disabled on most networks.
From inside the network, things get more difficult, because the router has to have a lot of services exposed - DNS, DHCP, whatever the thing that supports UPnP is, the admin web interface, ssh, etc.
This makes me think, that unless the manufacturer sneaks in a backdoor, things should be relatively secure from outside (both internet and physically). Am I missing something?
- It's so much easier if you keep it simple as possible. If it's your router/FW, don't run your web server, file server, streaming media server, etc. on it. I mean, you can, but that's just a lot of things that can go wrong.
- PF, the firewall in OpenBSD, is usually configured via CLI + conf txt files. The syntax is shall we say terse, but it's well documented and there are lots of examples. Yes, I know there are some 'PF GUIs' out there; I've never tried them on OpenBSD and don't know anyone who has. If that's a deal-breaker, then maybe look at pfSense (FreeBSD based).
- Pay close attention to the hardware compatibility list; not all WLAN chipsets are well supported.
- Read the documentation. Seriously. The community is at best 'difficult'; if you drop into their world asking questions that are in the doco expect active hostility. And OpenBSD is not Linux despite the superficial similarities. Don't expect everything to work like it does on Linux.
Not the process, not the remote host, not the monthly agreggate, but which connected device wifi or lan is using what, total or by host.
(use case; figuring out whose phone/laptop/tablet/tv/whatever is suddenly eating all the bandwidth in my home from time to time)
I'm using 18.06.05. A nice view in LuCI would be perfect but something that need to ssh is fine too.
But I have long searched for something similar. The answers were mostly useless e.g. most if not all were for the combined bandwidth.
I now run ntopng on another x86 device and use port mirroring to capture the traffic that goes through the OpenWrt device.
What kind of resource needs are we talking about here ? The router I use at home is a R6220 (OpenWrt description "It comes with a large 128 MB NAND ROM with space for many packages and a single core (dual thread) MIPS CPU powered by 128 MB RAM"), do you reckon there is a chance for it to run there ?
line-display: one-line-sent
hide-source: yes
dns-resolution: yes
show-totals: yes
show-bars: yes
use-bytes: yes
sort: 10s
downside is: iftop as far as I know can't filter multiple interfaces, so you'd need to check them separately with -i eth0 / -i wlan0.
If you're mainly concerned about latency, give the package "sqm-scripts" a try. You're sacrificing a bit of bandwith for active queue management. So a VoIP session is not affected by a download.Already using sqm (and I love it) but it's for use cases like when a laptop that hasn't been used in a while is started by someone to charge before watching a movie and steam/dropbox/windows on said laptop start hogging everything. In a residential area where we're still depending on ~10 Mbps adsl, identifying the device can be a need.
> downside is: iftop as far as I know can't filter multiple interfaces, so you'd need to check them separately with -i eth0 / -i wlan0.
Since I care only about lan <=> wan, doesn't that mean I just need to check on wan ? And all clients would be there, no matter if they're connected to the router through lan or by wifi ?
Otherwise there is documentation on all other possible tools you can use:
https://openwrt.org/docs/guide-user/services/network_monitor... https://openwrt.org/docs/guide-user/network/wan/wwan/bandwit...
Finally I splurged for a UniFi Dream Machine a couple of months ago and I could not be happier.
Nothing against the OpenWrt folks of course, but the reason these projects exist is the router vendors just suck. I won’t give them any more of my $ (Linksys, Netgear, ASUS in my case.)
I was impressed because of how clean and workable the stock web UI is, as well as how many features it has. They have some of the more obscure normal things like IGMP proxying (with a very user-friendly UI for configuring it) but what really impressed me was that it even had WireGuard support as an official installable package.
I'll stick with my UBNT gear at home but still, for a consumer brand Keenetic is pretty nice.
All router firmware is terrible in some ways, and has been for decades -_-
I just upgraded, and went with a device intended to be a commercial AP, but since it has two Ethernet jacks, it makes a great router under Openwrt. So far, it seems pretty good, but I'll be happier if I see uptimes of more than a year.
I've been using ASUS based routers for the last ~10 years (with Openwrt) and a few months ago decided to upgrade to something else.
After researching what routers are out there, I ended up getting a Turris Omnia [~320 eur]. It's running a fork of Openwrt. Can probably run vanilla Openwrt without too many issues.
There's also Turris Mox - a modular design from the same people, but I ended up getting Turris Omnia, since they pack 2gb of RAM into that router and it has 3 miniPCIe slots on it.
Not sure how much it's still the case, but for a long time there were a bunch that worked just fine with OpenWRT as long as it was the forked 3 generation old version that was the official firmware.
Edit: ...or does VDSL2 run with the ethernet protocol and just needs a standard nic? The VLAN ID tag makes me think so, but the GDMT993.5 (Vectoring) tells me it could be something more...
ADSL could only encapsulate ATM frames (hence using PPPoA), VDSL includes a new mode called PTM that can encapsulate ethernet frames. This may be what you were reading about.
The only PCI-E VDSL2 card I've seen is the Draytek VigorNIC 132. (Which, BTW, should really also have a low-profile backplate. :/ )
I can't deny I'd be curious to play around with it on an x86 OpenWRT system, but at about 200€, it's a bit pricy...
My current setup has a latency of 8ms, of which I'd speculate that at most 2ms are due to the router+modem? Could an x86 "monster" router+modem bring that down to 0ms?
You should also look into buffer bloat, and see if that's affecting your latency.
I'm honestly curious: why do you guys use OpenWRT, dd-wrt, tomato etc.? Re-using old hardware? Flashing bugged cheap routers that work bad with official firmware (that's never going to be fixed probably)? Need a specific feature not normally available on home net devices? Just enthusiast about the project or simply enjoying the hacking?
(1) I spent a few euros more on it than the typical home network appliances but I gained them back in quality, reliability, active support and development: no crappy hardware, no bugged software and zero issue with my 15+ WiFi devices in my house in a year.
I still use OpenWRT/DD-WRT on a few standalone access points, because I'd rather have a standard webui than dealing with manufacturer idiosyncrasies. Although when it's upgrade time I'll be tempted to move further in the amd64/hostapd direction.
1. DNS over HTTPS to cloudflare so that my DNS doesn't leak.
2. Hurricane Electric's tunnelbroker, so that I can access the IPv6 web.
3. Dynamic DNS so that I can address my home connection anywhere, even if my IP changes.
4. Wiregaurd so that I can access everything on my home network.
I tend to agree that most people should just buy Ubiquiti SOHO gear and be done with it, but at least for me, this is cheaper and a bit more fun.
but anything else goes, especially #4 WireGuard.
That they are considered as one of the better options just shows how crappy the market in general is.
And therefore alternatives like OpenWrt are needed!
2) It doesn't come with the source, so it fundamentally cannot be trusted. A router that can't be trusted isn't very useful, and so proprietary router firmwares are simply unacceptable on their face.
I should know ; I have a HW accelerated NIC too. Works wonder until the max speed of my optic fiber.
At the same time as this they have attempted to slip a call home function in unnoticed and stopped living up to their obligation to provide source code under the GPL.
Edit: I checked after posting this comment and Ubiquity is once again making the GPL source archive available. It had disappeared for quite a while and there was a bit of an outcry regarding it.
- targets labeled "ar71xx" can only use the old driver, and will probably not be supported in future releases. Consider replacing such equipment.
- targets labeled "ath79" have already been ported (or started out?) with the new driver, and owners may ignore the whole topic.
- targets labeled "ar71xx-to-ath79" have a commitment for support for the new driver, so that all future releases should work with this hardware (even though this latest release still uses the old driver).
Can somebody confirm whether this is an accurate understanding?
I have tp-link AC1750v5 routers, identified with the third bullet above. Can I ignore this, or do I have to do something to switch it to the new driver?
The "ar71xx-ath79" target is used in the wiki for devices that are supported both in ar71xx and ath79, there should be 19.07.0 images for both.
In any case, use ath79 for new devices, and migrate from ar71xx to ath79 on existing devices.
There is a guide here: https://openwrt.org/docs/guide-user/installation/ar71xx.to.a...
So, when you install the new boot image, you choose which, and if you choose the ath79 one, then when you restore the configuration, something runs to translate it for the new names. Presumably, then, if everything seems to work, you make a new backup with the new settings, and everybody can forget the old names.
Some of my specific issues were addressed, if I had simply bothered to read the release notes carefully. Instead, I found my update file, and updated. When WPA3 didn’t show up, I poked around forums for workarounds and finally found some answers that helped. Now my other clients couldn’t connect/stay connected, even to the WPA2. These notes clearly mention this, as well as the libup issue I solved via - -force-upgrading
I really appreciate the effort the OpenWRT folks have put in to collecting useful snippets of documentation for odd cases and uses. Sure it might could be better organized but it's there at least.
What about the FreeWRT fork? Is it alive / lively / up-to-date / running ahead?