Mainline Linux on the MikroTik RB3011
earth.li
earth.li
Kudos to him though, it looks like it would be a popular device if it becomes easier to get Linux running well on it.
If by any chance that Jonathan is reading this, mainline Linux kernel that can be run on the cheap Banana Pi router (BPI-R64 price USD$64) will be very handy and useful [2].
Ah, yes, that makes sense. He started with Debian. But did do a lot of work with modules, drivers, device trees, the boot loader, etc.
The best results were using armbian kernel and userspace for this device. You should be able to build one in a less than an hour on modern pc.
I have a v7 device that I use with a sata drive. It has been stable so far.
Edit: forgot about needing a recent bootloader. This is also mentioned by armbian docs.
Having prepared embedded devices myself, it is quite common to patch the kernel you are working with to work around quirks in your hardware. However, it is much more pleasant to do so on a mainline kernel than on something that was already patched and never maintained.
Also note that the author mentions that he is currently in the process of getting his patches merged in Linux, and that most of the work should be included in 5.9. So perhaps not mainline yet, but future mainline definitely.
Instead, they're basically selling devices running a "proprietary" Linux and, IMO, leeching off of the kernel development community and others.
Fortunately, the OpenWRT community has, over the years, managed to get OpenWRT running on many of the MikroTik devices. (Occasionally, depending on the particular device, there's a "performance hit" due to hardware acceleration that doesn't work without binary blobs from the vendor, for example, but they've certainly managed to make these devices for those of us who would prefer to not touch RouterOS!)
Openwrt is really cool but it supports mostly wifi+4+1-port routers, and very few switches like the kind you'd run your lan with.
You do not need an ONT if you have an SFP slot available. Get a suitable SFP module for your fiber type, and you can plug the fiber directly into your router.
This safes you a little bit of power, latency and space. Overall I find it to be a more elegant solution.
And they have a point: the devices are not that compatible as they should be, and most of them will not work with their TRS069 system as the supplied CPE does.
As an aside, I do not have a SFP-capable router, but I have a few SFP slots on my managed switch. I've been toying with the idea of putting one in a dedicated VLAN with the WAN port of my router, with another ethernet cable connecting to the LAN port. I might also get away with using only one ethernet port if using tagged VLANs, but that would limit the bandwidth.
In my experience, Orange Slovakia refuses to do that; they have their Huawei OLTs, hand out Huawei ONTs and they only thing they were willing to do is switching the ONT to bridge mode.
That's not all: you cannot use any Huawei ONT, even if it is the same model as they use. You must use one provided by them. They are activated by serial numbers and they won't activate it if isn't their. So for a long time I had a router with SFP interface, but it was useless and I had to run the ONT next to it anyway.
On similar topic: how is IPTV done in France? Here, it looks like IGMP, the ONT does IGMP proxying and the upstream interface for the multicast subnet is a separate VLAN. (This is something, that many routers have problem with).
I've seen both, it might depend on the location, or other factors. Maybe you could ask explicitly?
See there: https://lafibre.info/orange-les-news/show-hello-2016/
That website also has a lot of information (in French) regarding ISP configs, and I think it would answer your question regarding IPTV. There is a whole section dedicated to replacing the box with a custom router: https://lafibre.info/remplacer-livebox/
It looks like there is a VLAN (840) for multicast TV, and another for VoD (838). There are a few vendor-specific field the DHCP server has to pass the decoder if you want that to work.
From one of the topics on that website, this English document is linked, which could be useful: https://docs.opnsense.org/manual/how-tos/orange_fr_tvf.html
If you can get config GPON OMCI strings from your router, maybe this will work for you.
I confirm they do. They have to support enterprise-lite setups on the same GPON as the standard consumer stuff.
Same here. I use the SFP module that came with the router from my ISP.
I was unhappy with the quality of the ISP supplied router, and the fact that it ran a 6 year old custom image which was vulnerable to the KRACK attack. Since my ISP does not allow upgrading the firmware, I decided to ditch their router completely. I plugged my ISP's SFP module into my own Ubiquity device and it works flawless.
That's what I'd like to do, but I haven't bothered to get a bi-directional SFP for my switch. Soon...
> I might also get away with using only one ethernet port ...
I would definitely avoid that at all costs! Exposing your internal network to your ISP's network is a really bad idea. With a managed switch, you'll want to disable as much of the "link-local" and other layer 2 "noise" as you can (e.g., CDP, LLDP, STP, etc.).
You may need to enable 802.1Q on your upstream-facing switchport anyways (and configure VLAN IDs, of course), but this would depend on your ISP's configuration. Either way, I'd still use a separate physical cable (between the router and switch) just for the "LAN side" -- if you weigh the pros and cons, it's a no-brainer!
On the switch side, I'd have put the SFP connector inside VLAN 42, untagged, and put every other port in VLAN 10, untagged.
There are probably a couple other ways to achieve this, and ISPs sometimes use tagged VLANs as well. But I think that could work (I have little experience with VLANs, so I might be wrong, feel free to point it out to me).
On the other hand, if I had gigabit fiber, a single cable would halve my bandwidth. And I'd pick the multiple cable option over the other as long as I can afford it (enough ports)!
Thanks for pointing out the layer 2 "noise". I wonder if my switch wouldn't support bridging together two ports, I think it runs Linux...
I have yet to see a single ISP that doesn't do it on their own side.
Having this exact issue in a place where I got stuck now.
GPON hardware makers are artificially limiting interoperability, while the underlying hardware is fully capable of that.
GPON has a out of band configuration protocol which is usually unavailable to the OS. Here they put their vendor ID block.
Huawei is a virtual monopoly in GPON, and they strike such deals where they block competitors in exchange for discount left, and right.
GePON is by far better in this regard as it had no technical provisions for anything like this to start with.
Not sure if I would ever try to install something else and loose hardware acceleration.
it has PoE input and output, and routerOS has enough features for me.
pfsense grade really. I have heard about vyos, but nothing more. Given that bpfilter & XDP is now in the kernel, i was wondering if there's something built on top of the latest and greatest.
The differences WRT kernel between various Linux distributions are likely not significant enough to matter for the overwhelming majority of users.
Unless you have "non-typical requirements", pretty much any of them will almost certainly be "good enough".
(Personally, my preferences are OpenBSD, FreeBSD, and OPNsense, in that order, but I'm weird. If I had to choose something built on Linux, OpenWRT would probably be the one that I'd reach for "by default".)
With a layer 3 switch you can avoid hops to the router and also get some hardware acceleration. Although the lines are increasingly blurred between switch and router with hardware acceleration becoming popular all around. Most consumer routers are router/switch combos.