For my home, using Ubiquiti products has worked well. I have the EdgeRouter Lite and UAP-AC-PRO access points which support POE. It's been nice using products designed for professionals, and it's nice to be able to administer and upgrade the router independently from the access point. These products just work, and there's none of this dodgy "reboot the router" nonsense.
I hear a lot of good things about the many mesh networking setups (often combined routers/APs) now on the market but haven't tried any. They're almost certainly a better fit for a consumer who doesn't want to be a network admin. Ubiquiti has one (the "Alien"), and the Eero (now owned by Amazon) is often recommended.
My parents have Eero, and it's definitely a really nice system that Just Works. Exactly as you described it, perfect for a consumer that wants quality without having to be a network admin.
It's a shame that there aren't more "pro-sumer" products like this out there. A common warning I read when researching Ubiquity products was that they're not for people who aren't tech/networking professionals. I don't know where that came from, because setting it all up was a breeze. It was way easier than dealing with Asus's terrible "setup wizard".
There's still a lot of weirdness in Ubiquiti, even in their UniFi line, that'll throw the average user, but it's definitely a lot more user friendly than the EdgeMax line. I often find UniFi tries to be so friendly that it ends up making things harder. I had an auto-discovery issue that I spent a lot of time troubleshooting, mostly because I can't just tell it "this device with this MAC address is here now", it has to find it for itself.
The UDMP does a really good job just being "the central core of your network you plug stuff into", but it's also confusing because it has the device firmware itself and then the software for each function on it, including the firewall software, which is all very convoluted.
Mikrotik is another company that has a good pro-sumer to pro ecosystem. Routers, APs, adapters, long-range point-to-point radio stuff. Most of their gear runs on variations of their RouterBOARD hardware and Linux-based RouterOS, and can be collectively managed through CAPsMAN, which can either run on one of their routers or on a desktop PC.
The configuration side is definitely less slick than what you get with Unifi, on the other hand you can configure everything in detail. You get an astounding amount of possibilities for your money, if you can accept the late-90s/early-2000s style web interface or just use the terminal interface instead.
The only thing I've found lacking is that they don't have any 4x4 or 802.11ax access points yet, but if you go modular (separate router, switch and AP), you can upgrade piecemeal when you need to.
The EdgeRouter OS is essentially a Debian build and can run openconnect and other VPN software if you need something that is not included in the base install.
I would recommend the ERs to anyone with a bit of networking skill.
What are you doing to it? Mine ran at 950 down, 450 up just fine. Are you going faster?
https://www.michaelhorowitz.com/second.router.for.wfh.php
and here:
>Can the wireless network(s) be scheduled to turn off at night and then back on in the morning?
This seems almost tin-foil hat level security. Nobody is wardriving at 3am and hacking into your wifi.
>Is it limited to one logon at a time? It should be. The router should not allow multiple computers to logon at the same time using the same userid.
How does this improve security? I guess you can use it to catch an attacker on the rare chance that they get access at the same time you're on the admin page, but that's not really worth considering.
>Can the userid for the web interface be changed? Every router lets you change the password, a few let you also change the userid. This is most important when using Remote Administration. An October 2016 study of 12,000 home routers by ESET found that "admin" was the userid "in most cases."
What's wrong with "admin" with a secure password?
I do think "one logon at a time" might be a good idea, just not for security reasons. I suspect these routers don't do well with concurrent updates.
Changing the admin id would have the benefit of culling out noise. An unsuccessful login attempt to "myuniqueadmin" catches your attention as something meaningful.
Now why the author calls this out is anyone's guess. Sometimes someone sees a product like what I work on, sees single-user, assumes "aha! Better security!" No, we're just lazy. If there's any additional security, that's gravy and not a design decision.
* Pepwave Surf SOHO
* Amped Wireless RTA1750
* Synology RT1900ac
[0] https://routersecurity.org/checklist.phpSo yeah, it's pretty expensive on an ongoing basis to convert an old desktop to a router.
I must confess, I run an OpenBSD firewall on an old Dell server. Fortunately the Intel CPU doesn't need to do much. So I'm only drawing about 70 W continuous. I keep meaning to replace it with something more power efficient but haven't.
Not saying it wasn’t worth it - it’s a huge step up in reliability from what I had, but I kinda feel like an EdgeRouter is a gateway into the wider Ubiquiti ecosystem.
Glancing at their documentation, it seems that they've only EOLed the three early 802.11ac access points they released. Of course that doesn't help you or make your concern any less valid, but it's not like they're in the business of just willy-nilly cutting off support for their products. The one you bought just happened to fall into an unfortunate minority.
As for what DIY OS/dist, I have used VyOS, IPFire, pfSense, OPNSense, and a handful of various xx-WRT derivatives. OpenWrt is still my recommendation without a doubt. I'm still not at all a fan of the update and package management of OpenWRT, but it's the best out there unless you configure a vanilla debian install yourself.
Keep WiFi APs as separate devices, regardless of if you mesh or not.
Of course it wouldn't be complete without hacking up your own, custom Linux system calls[1], or hacking up SquashFS to be big-endian for no reason and storing your own data structures in the compressor options[2].
[1] https://twitter.com/RichFelker/status/1357733309737021444