MikroTik RouterOS v7 stable released
mikrotik.com
mikrotik.com
The only problem is the availability: they are not stable as a Cisco/Juniper, but you can add several layers of redundancy with a fraction of the costs. Also the support is very basic.
Edit: Thanks for all the answers, from me and anyone else who was looking! I have some good ideas from the below comments and hopefully this thread helps some others as well.
I use mine with a Mikrotik RB4011. A very stable and reliable combination.
Also note that in unpatched hostapd channel bonding (40MHz and more channels) does not really work. There is a check whether neighboring channel is crowded (which always is due to overcrowded spectrum) that disables channel bonding. AFAIK Openwrt has patch that allows to override this check, but Debian does not.
As a result, i get consistently higher wifi speeds from commercial wifi APs than from my Alix router.
I have on order a mikrotik rb5009UG+S+, which has nine gigabit ethernet ports, one 2.5 gigabit ethernet port, and a 10g sfp+ cage. It has zero fans and benchmarks show it capable of 10 gigabit routing. It costs less than $200.
I love vyos, and I would definitely prefer an open source router. But people I talk to love their mikrotik products. It doesn't seem like the old ones are being abandoned.
Nope, don't trust them to do that after https://community.ui.com/questions/Ubiquiti-ignoring-auto-up...
They have dozens of products which they update constantly, picking one bug at one time as malice and blacklisting a company is not correct. If you go that route you won't have any company left to buy from.
I also just find the UDMs interface an absolute shit show to navigate and find things.
It says it supports a gateway mode, but as a power user I want a bit more control than what I would expect a WAP to offer. I use an EdgeRouter-4 running whatever the latest official release is. Having separate boxes grants me freedom to do things like mess with Wi-Fi settings while my SO watches a show on Apple TV connected via Ethernet. It's the little things.
I often think of a pfSense build, but then I remember how happy I am with the performance and efficiency of a dedicated box.
A dumber switch would be just fine, but I wanted something with 802.1at POE and good VLAN support because I like to break things up a bit.
OPNsense is darned handy, and I like that it does more than an EdgeRouter would, like terminate a Wireguard VPN. The R610 works wonderfully, and the switch... well... it's a switch. Once configured it's kinda transparent.
Moving houses soon, so I got a second R610 to fill in signal on what I perceive will be dead spots due to plaster+lathe construction, and in testing thus far it all seems to Just Work. And like you appreciate, since it's all modular it's a lot easier to maintain than the UniFi stuff when things go sideways.
Very, very happy with this setup.
Interesting, thanks. Looks similar to one I'm considering to purchase when I'm moving next year. I'd be using OpnSense too.
I think that any slim/passive box will work well. So long as it has enough NICs and they have quality drivers for hardware offload and whatnot it'll work great.
Eventually I picked the Asus ZenWifi system, and honestly it works great (I have no affiliation with Asus). There's no cloud account to create when you install it. The app is acceptable. There are various security things you can turn on which seem to require cloud assistance, but the core product seems to work very nicely. Any time you try to turn on something which might cause the system to share extra data, a popup appears to explain that to you.
It's so powerful, Wifi-wise, that I bought three nodes and only deployed two. I use it with Ethernet backhaul but it has a dedicated radio for wireless backhaul. It has ethernet LAN ports on each node, and each node is identical to every other node (i.e. there is no "base" and "satellite"). I went from spotty Wifi throughout my 2,000 sq ft house to very strong Wifi throughout. I wrung my hands for a long time because I gave up VLANs and some other things I wanted, and then said the heck with it.
The last time they had a pay per device per month service it started at $1/device/month and then they bumped it to $10/device/month. Somehow they thought the one time cost of a device should become an annual cost and that people would adopt it. Obviously that flopped.
Now think of the same scenario, but everyone's gotten complacent and are getting dependent on their devices that are linked back to ui.com. They might not blatantly flip the switch, but now that they have a hook for licensing checks they can start shifting development so new features are licensed for a monthly fee rather than getting them free forever when you buy a device.
IMO as soon as the all-in-one devices that perform management (ex: UDM Pro) while being linked to a ui.com account get enough adoption they'll shift to some kind of feature licensing or simply release new devices / revisions that require "cloud licensing" or something similar.
They're also very flippant when it comes to breaking devices in a way that prevents a connection to the controller. They think SSHing into broken devices to fix them is reasonable and it's not if you have to deal with many sites / devices.
Not exactly what I want to see in the device that can literally compromise all of my other devices. Am I missing something -- did this turn out to be nothing, or did folks decide that Ubiquiti has bounced back? This seemed really really serious at the time and turned me completely off from ever purchasing one of their products.
https://krebsonsecurity.com/2021/12/ubiquiti-developer-charg...
Not great - but more classic insider attack, then security breach.
Any links or reference. Cant find anything with a quick Google Search.
This is no longer the case. Some devices (albeit not too many) now have working 802.11ax [0].
I know most about the Linksys E8450, which does require a newer snapshot of OpenWRT (it's not yet in a stable release).
[0] https://openwrt.org/toh/views/toh_available_16128_ax-wifi
Would like to hear ideas about Apple's airports running custom NetBSD ... are you guys still running those as edge/internet routers with wifi or have you pushed them to the inside of the network and promoted some other box to the firewall role? I'm kinda stuck in the conundrum "it's unix with PF, it can handle itself" and "it's does not get updates anymore".
There are two choices, the way I see it:
1. Invest in a decent router (probably $150-200 at least) and throw openwrt on it. You'll need something with serious CPU beef because openwrt relies more on software than hardware, and most routers use hardware for QoS etc., hence the price tag. You'll also need to actually understand the multitude of settings offered by openwrt if you care at all about security or performance -- this is nontrivial if you aren't already a network engineer.
2. Buy a used Apple Airport router. The last generation support AC wifi, which is... basically as fast as the best things out there right now, barring wifi 6E. On the plus side: this comes with mostly sane defaults and good performance, I easily get 600+ mbps up/down on my gigabit internet. On the downside... I think you can only configure airport routers through macOS (and a mostly-dead iOS app), and they don't let you configure all the settings you might want. A fair tradeoff for good, non-footgun defaults IMO, but YMMV.
There's also the third option of creating some bespoke raspberry pi + wifi hardware solution for yourself, but that's likely to get you punched by your flatmates when it inevitably reboots incorrectly during a power outage or overheats or whatever and suddenly you need to spend 2 hours debugging problems without a working wireless connection and everyone else is pissed they can't use the internet. Unless, of course, you're a brilliant network engineer who would never make a silly mistake or have a bug in their custom router solution.
Which I guess is why most people use Google or Amazon spyware for internet in their homes.
The biggest reason I don't use a Google router or something of that ilk is exactly what you mentioned in this comment: I don't want basic functionality like port forwarding locked behind some cloud account that I might have to pay for monthly eventually (or might get shut down). At least my current hardware will likely work perfectly until the hardware fails.
The way it was written your statement sounded like a Apple shill really.
Why not OPNsense on an old x86 box?
> but that's likely to get you punched by your flatmates when it inevitably reboots incorrectly during a power outage or overheats or whatever and suddenly you need to spend 2 hours debugging problems without a working wireless connection and everyone else is pissed they can't use the internet.
I thought for a couple of years that my OPNsense setup would pass the Family Acceptance Factor, but one day (a few months back!) it spontaneously wiped itself of its settings — requiring me to plug in a monitor, reconfigure it to boot, and restore my settings from a backup.
My (very annoyed) family had to ask why we had to jump through hoops, and not use a simple consumer router like everyone else.
I'd imagine that OpenWrt would be the same, or worse.
In the worst case, stock firmware would require a hard reset (power cycle) every few weeks. I've had OpenWRT firmware running without interruption (on UPS) for years at a time.
Given that I'd likely keep my next router for 5+ years, I'm hoping for 2.5gbit (if not 10gbit), 4 ports, IPv6 aware (I get a /60 from my ISP), VLANs (so I can keep the random consumer crap segregated off), etc. I had settled on the hardkernel with 6x2.5 Gbit ports, but it's discontinued.
My Ubiquiti 6xp does a great job, I can keep the config file in git, I can assign a IPv6 /64 per port, run custom firewall rules to redirect all DNS to my DNS server (allowing blocking youtube, web games, etc), etc. I block all remote access to my router and from the consumer crap VLAN with watches, TVs, AV receivers, game consoles, etc.
Here's hoping someone ships similar, have my eye on the Mirotek RB5009UG+S+IN, has 1 10G, 1 2.5G, and a bunch of 1G. I'd need a second vlan capable switch with a 10G uplink for my uses, but it's workable. Hoping for similar with a few more faster ports. Even just 2x10G would make a big difference.
And before anyone else jumps in with old information,as of the latest firmware, it does not require cloud access. And the PPoE performance problem has been fixed.
It was a bumpy transition for a bit because they moved off of Vyatta to generic Linux for the routers.
They also are introducing full VLAN support in DSM 1.3 which should be out soon if you're a power user. Honestly if they supported PoE for their extenders I probably would have switched out to it. The extenders will mesh wired or wireless which is nice.
https://kb.synology.com/en-global/SRM/help/SRM/NetworkCenter...
I personally like that because I can safely remotely access the routers I've deployed for others if I ever have a reason to. They just need to check a box to turn it on or off in the GUI.
They also have an "experience improvement" program that sends home telemetry that can also be disabled. As far as I know there's no "phone home" that you can't turn off if you don't want it.
Maybe for routers it’s different, but this service is not secure for NAS.
Was going to go all in on Ubiquiti but was put off when reading about the reliability issues, plus was way more expensive.
Pleased with my router + access point + PoE switch + hardware controller :)
The major benefit of this setup is that you don't depend on some manufacturer for updates. Given Ubiquiti's and Netgate's recently hostile actions towards users and open source, this provides a great peace of mind. The other benefit is that you're free to upgrade your hardware as needed, which particularly for WiFi cards is great to have. Right now I'm sticking with WiFi 5 because of the costs, but in the future upgrading to 6E would just be a matter of changing the cards (assuming they're supported by the OS).
Speaking of cards, I went with Compex WLE1216V5-20, which have an Atheros chip and are thus much better supported on Linux than Broadcom, etc.
With pfSense, the issue was primarily two-fold. First was the fact that all the firewall rules and such did not support dynamic prefixes. Major PITA right there.
Second was the DNS server, that is, when using pfSense as a DNS server I couldn't figure out how to prevent it from sending the public IPv6 address to clients. Thus when the (public) prefix changed, DNS stopped working on the clients.
Some of this might have improved since I last used it, but I switched to OpenWRT and haven't looked back for a second.
I've had intermittent LAN dropouts on the SG3100 that I couldn't explain from the logs. That in addition to Netgate's hostility towards open source with how they're handling pfSense, and the whole pfSense+ product, just puts a bad taste in my mouth when it comes to supporting the company. For the hardware and software stack they provide, the devices are very overpriced IMO. Same with Ubiquiti, though at least with Ubiquiti you're paying for a set-it-and-forget-it network, as long as you're willing to fully invest in their ecosystem. They're the Apple of network prosumer equipment.
But my main interest in abandoning both is investing in devices that I can upgrade and maintain independently and at my own pace. It will also be cheaper in the long run, though it does require some tinkering to setup.
I guess it will depend on how much I like OpenWrt :) I don't have any experience with it.
In tunables you need:
hw.ibrs_disable="1"
hw.mds_disable="0"
vm.pmap.pti="0"
It's sad that everyone only wants to accept huge amounts of cash these days. Take VyOS as an example. The smallest licensing option they have is $6k per year for unlimited installs. That makes it completely unobtainable for a person that I build firewalls for, so we don't even evaluate it.
In terms of percentages, we could probably add about 15% to every firewall sold and that could be passed along to a software vendor. If we had a self serve portal where we could download LTS releases and generate lifetime licenses we'd send them 15% of our firewall (sales) revenue and they'd basically never hear from us.
In real numbers that would be about $1-1.5k a year as long as we could pay per device as we sell/install them. Using pfSense as an example it'd be in the range of $10k since we started using pfSense and, in the last 5 years, I think I've only had 1 issue I couldn't figure out on my own where I had to go ask on their forum.
https://danosproject.atlassian.net/wiki/spaces/DAN/pages/819...
Some instructions here: https://boratory.net/pfsense-firewall-futro-s900/ https://forums.servethehome.com/index.php?resources/introduc...
I'd suggest using old consumer routers as access points.
RouterOS is a bit clunky for a Linux user. They kind of mimick Cisco UX, which is a big mess for everyone except professional network engineers.
I wish to declare that I'm a Mikrotik fanboy. My hardware is ten years old, doesn't break, and Mikrotik supports it on the latest versions, apparently without plans to ever sunset the support. Ooh aah.
Works great, the interfaces are a little basic, but they are extremely fast and absolutely work flawlessly.
Rolled out a 10gbit / 25gbit network at home. My biggest complaints are:
* Wireless is really difficult to get “decent speeds”. I also have my ISP’s router and a Draytek at home, these easily do 500mbit, and it’s nearly impossible to get my router board to do the same. When asking support there’s mainly a lot of hand-waving “you’ll never get better than 100mbit anywhere anyway”, etc. Even if other router vendors use hacks / cheats to achieve what they do, I would want an explanation what exactly it is they’re doing, and why Mikrotik can’t do that.
* I know their Linux Kernel supports certain features, I would really like an “escape hatch” so I can just run traffic shaping commands manually. Eg if I want to use RED with ECN, the lack of a UI checkbox shouldn’t be the limiting factor;
* Upgrades while being in their development branch has been a big pain, many times losing crucial configurations; I guess this is fair game when I’m on the beta channel.
* Hardware is a bit underpowered for my needs, but I guess that’s why enterprise equipment is 10x - 50x as expensive. Doing traffic shaping on anything more than 1gbit is pretty much impossible; probably the best solution is to use some dedicated hardware with a whole bunch of network cards inside.
10/25 feels like a CCR2004? Or are you just talking switching.
If routing remember it isn't full bandwidth - the 170gbit of ports is squished into 2x25 before hitting the CPU[0]. Not sure how much is offloaded to the PIPE.
[0] https://i.mt.lv/cdn/product_files/CCR2004-1G-12Splus2XS_2004...
That’s exactly right. Thanks for the tip that things get squished into 2x25gbit before reaching the CPU; this effectively means that anything that isn’t offloaded to the hardware is limited by “just” 2x25GBit. Is my understanding also correct that this would be the case for when traffic needs to go from the SFP+ ports to the SFP28 ones?
Regardless, what I really wanted to do (mostly as an experiment) is use QoS to prioritize iSCSI and others; the problem I’m running into is that the CPUs are just not able to do that that fast.
I think the only solution to this problem would be to use an x86 machine with a bunch of Mellanox cards in it.
The hardware is underpowered because they optimise for people who deploy a hundred routers on mountaintops, with excellent lines of sight but poor access for replacement. Underclocking severely helps reliability.
https://openwrt.org/toh/mikrotik/common
Standalone wireless on Mikrotik is bad. CapsMan is even worse as it seems to hobble some of the standalone settings. Mikrotik are good at engineering routers but bad at engineering Wifi drivers.
I tried every which way to get Mikrotik wifi to work well, at reasonable speed, without dropping packets when roaming. No dice.
Now I have three HAP AC running OpenWRT, connected to a CCR for switching and a HEX S for routing, the latter two still running RouterOS 6. 5 VLANs, PoE, queues, several forwarded services, Solid as a rock.
(I've said it now... massive network wobble likely on the way).
I don't think I have ever seen anything along those lines out there.
Im actually happy with my unifi setup - but there are some things (like multiple load balanced WAN ports) that should be easy to do, but instead are impossible.
I wish router for personal use were as "easily" programmable as an OpenFlow compatible equipment with a external controller. Even if you need some extra tooling to reach all the feature of RouterOS, like a compute node for the DNS. I don't know if this kind of evolution will ever reach the consumer space.
Some nice features you may not realise exist on RouterOS 7 are built-in support for Wireguard VPN and ZeroTier client support.
Is it easy for a noob to setup things like port forwarding and vlans on a router/ap box?
I've managed cisco amd juniper routers. And I can't make heads nor tails of it.
As soon as you wonder off the default track, you're expected to understand deep level networking terminology abstracted in a UI tailored for experts.
Mikrotik's SwOS is alright and has most of the options you'd expect from a switch, but is missing the ability to have a human readable text config. I've got a Netgear switch as well, and I'd label its obtuseness on par with RouterOS. At the end of the day it seems every network vendor has their own bespoke proprietary UI that you have to suffer through.
In general I'm much more at home with Linux's iproute2/bridge-utils/nft. What I really want is some low power switches that can run OpenFlow or the like so I can centralize all the config back to my Linux router. On a home network, most devices shouldn't be talking directly among themselves anyway!
Another thing I really want is for network switches to have an RGB LED on each port that can indicate what VLAN it's configured for.
If you want to set ether 3, 4 and 5 to untagged vlan called "Alf" with ID 11, ether 6 to untablled vlan "Bob" (id 12), and ether 7 and 8 to a trunk of both Alf and Bob, you can do
1) Create a bridge for Alf, and a bridge for Bob
2) Assign IPs for them (assuming your mikrotik is the router), and maybe dhcp pools, server etc
3) add ether3, 4 and 5 as bridge ports for Alf, and ether6 for Bob
4) Create a vlan interface on ether7 for Alf with vlanid=11, add to bridge Alf
5) Create a vlan interface on ether8 for Alf with vlanid=11, add to bridge Alf
6) Create a vlan interface on ether7 for Bob with vlanid=21, add to bridge Bob
7) Create a vlan interface on ether8 for Bob with vlanid=21, add to bridge Bob
But the killer is there are two different recommended ways to do it depending on the hardware.
/interface bridge port
add bridge=_bridge interface=sfp-sfpplus1
add bridge=_bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=sfp2 pvid=10
But then I also have to define the VLAN ID for the bridge (for egress, I believe) - /interface bridge vlan
add bridge=_bridge tagged=sfp-sfpplus1,_bridge, untagged=sfp2 vlan-ids=10
The device is a CRS328-4C-20S-4S+RM. It seems like I am using the other recommended way. Which would make sense because I'm not really using the "router" part of the software, but rather configuring the built in switch chip to do its thing.Looking at the text config now it seems quite sensible, and isn't far from SwOS, Linux CLI, or switch chip datasheets. But I remember getting to that point in the WebUI being somewhat confusing, perhaps due to the alternative in-CPU way you described.
- you need to enable hardware offloading for it
- different models have different limits on number of hardware offloaded bridges
- if it's not hardware offloaded, you run all traffic through cpu and kill throughput
you can go on fiverr and upwork and get someone to remotely configure/manage it for you.
I'm not quite sure what you mean here. Everyone from banks to small shops use IT configuration services.
Most people will supply you a resume, contact details and sign a NDA. That's quite good enough.
Anyone posting on HN will likely be able to figure out the basics, but it is definitely much less polished than other prosumer products such as Ubiquiti and the documentation can be a little rough around the edges.
On the other hand, I'm not sure "unintuitive" is the correct word here. Having had the (dis)pleasure of setting up complex topologies on other manufactures like Cisco I found MikroTik to be considerably more intuitive (or perhaps "less unintuitive" would be more appropriate), possibly because Cisco has been built on for many decades and new features were constantly added on top of existing systems for compatibility purposes instead of redoing the CLI from scratch to make a more consistent user experience.
everything more or less maps directly onto raw Linux functionality
Having said that - if you know network setup very well, then Mikrotiks are very powerful and allow for network setups that are much more flexible than consumer equipment.
(Also configuring IPv6 correctly is also a special hell that's far away from clicking "enable IPv6" on my previous ASUS)
The criticism on their firewall might as well be a criticism on iptables (which IMO is completely valid, even after years I still have doubts about what a certain rules structure is going to do).
iptables itself is extremely unintuitive (although extremely powerful and flexible), but their GUI makes it more manageable.
When compared to consumer router devices, then no.
When compared to configuring enterprise networking kit using the CLI ... well ... perhaps. Mikrotik does have some short cuts / UI features. But if you want to do anything vaguely complex, you're going to need to put some serious time into getting your head around the way the system processes packets.
If getting to grips with how packets flow through different subsystems in your router doesn't really appeal (check out https://wiki.mikrotik.com/wiki/Manual:Packet_Flow) then there are better, simpler options which are still powerful.
Wireguard is a must for us now! I've been using professionally on MikroTik, too, almost everything worked as expected!
(only some issue with being able to export settings... I hope it's solved now)
Then one day, when I was away from home and actually needed the VPN, it absolutely melted. Basically everything on the router stopped working, and I suspect it was Wireguard since the router went haywire when I was actually using it extensively. Needed a hard power cycle, which I couldn't actually do.
These days I just leave my router to do its basic duties and have a Raspberry Pi dedicated to nothing but Wireguard. Haven't had issues since. The Pi 2 Model B also performs better for Wireguard and I imagine that the Pi 4 could saturate my 100 Mb/s upload.
Granted, it's been a hot minute since I've last tried WG on EdgeRouters.
I love my mikrotik devices, but they can be a bit iffy around the edges
(e.g. if my pppoe connection reconnects the ipsec stops working until the interface is bounced)
Many of them have ITX size PC or motherboard with Atom CPU and over 8 of 1G NIC plus 2 10G SFP+
I.e. among people where I know what kind of stuff they have, anybody vaguely technical might have an Ubiquiti AP for their WiFi, whereas the people that love to tinker with networking stuff have some mikrotik device somewhere to play with.
I don't deal much with IXPs, but I did hear somewhere that there were a shockingly high number of mikrotik peers at one exchange point (10%+)
You could potentially build a Linux PC to do some of the more basic stuff that most ISPs require at a similar price, such as PPPoE concentrators, but it's still a lot more hands-on work for no clear benefit.
I can't find right now what the market share of peering routers is in Rio's IX, but i feel like it's significantly higher than 10% (probably between 20 to 30%).
Unifi really does unify the entire ecosystem, it's basically the Apple of network gear down the quality of packging. I love it.
I heard good things about Mikrotik but their product line feels scattered and unorganized.
Still seems to be missing certain features - like showing what routes you're advertising to a BGP peer, so certainly not ready for use. Of course the way that routeros is developed, it relies on users to do the testing and debugging.
Release candidates for 7.1 had container support which opens worlds of possibilities for the switch. But unfortunately was removed for the final version pending updates.
Edit: Container support was introduced in rc3 and removed in rc5.
Your script is probably going to break due to the new syntaxes in v7, but no significant added new features on that matter that I'm aware.
I'm hoping they switched to chrony but I don't know.
ASIC router: 10 Tbps for $10K
And the efficiency also scales down; ASICs should be faster for any budget above $2K.
To my knowledge, the only viable open-source project is that one Linksys router/AP combo, and that doesn't necessarily fit the features someone might be looking for.
While it's nice to think everything could be open source, in the hardware/firmware world it's just not common.