My network home setup v3.0
giuliomagnifico.blog
giuliomagnifico.blog
Never rebooted - uptimes in months and they are on battery backup.
It is amazing how much the stock firmware shipped by the likes of Broadcom/Realtek sucks so much - it is not like Mikrotik/Ubiquiti makes their own SOC's to make it more realizable.
I think the mixed reviews are from HN where people are complaining about their security posture (for good reason).
I believe they did something like force cloud-login with some software update a few years back.
They also apparently were downplaying a major security incident, and sued Brian Krebs for reporting on it: https://arstechnica.com/tech-policy/2022/03/ubiquiti-sues-jo....
I have some Ubiquiti stuff, and it works fine, but I've been meaning to look deeper into all this, but I just haven't had the time. I just stopped updating the controller software (none of their gear is external-facing, and IIRC it's only needed for configuration/management) because cloud login is an absolute dealbreaker for me.
No, what they did was update the software to prefer cloud-login and push you to set it up during onboarding for new products because they use cloud-login for remote management and anti-theft/device tracking.
It's always been entirely optional. I just set up a new network because I moved and gifted my previous network to the buyer's of my prior home. I'm still using local accounts only with no remote management, and it works perfectly fine on the latest generation of Ubiquiti gear with the latest firmwares. The only thing I login to my UI account for is to use the store and buy hardware.
The other thing with Brian Krebs was a faked security incident by an insider who was trying to extort money from Ubiquiti and Brian Krebs played the fool by assisting them.
Granted, there are /many/ issues I have with Ubiquiti, but generally speaking if you use local accounts and keep the firmware updated it is no worse than any other edge networking device exposed to the Internet.
Was that all? Did they add telemetry or something else? I had read that I'd need to edit some text config file or something to opt-out of something I didn't want, because they provided no option in the UI.
I believe this might be what I was thinking of: https://www.reddit.com/r/Ubiquiti/comments/fhlowt/where_is_t....
I took a wait and see before I sorted it all out (since none of their stuff is external facing on my network), and haven't gotten around to it.
Even the local login, from a device on the network, can be set up to require two-factor auth. That alone makes it more secure than a lot of consumer-grade stuff which only requires a password, which is often never changed from the default.
I'm happy with my Unifi Dream Machine as a one-device home network. I thought about getting rid of it a while back when some bad press about Unifi security was published, but it turns out it was fake news and Brian Krebs has lost all credibility in my eyes for continuing to promote it even after it was debunked.
Yeah. Updates used to be a nightmare. I had to worry about Windows updates, Java updates, and of course Unifi updates.
Then I started to use the Docker container at https://github.com/jacobalberty/unifi-docker No worries about cloud login...
I have 21 APs all controlled by the container on a Raspberry Pi 4. It's not even breaking a sweat. When I want to upgrade the Unifi application, I stop the container, and re-run the command to use the newer Unifi version. Three minutes later, it's back on the air.
> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies.
It has shaken a lot of people's confidence in Ubiquiti's internal security practices.
Then, a few years in a firmware upgrade to the switch (their 250W PoE switch) caused it to start isolating my Google WiFi APs because it would do some loop detection. An hour on the phone with their support (which in that instance was really good) resulted in a a prognosis of "This particular loop detection can't be turned off." So I had to drop a dumb switch in front of the Ubiquiti for the Google APs. I was considering replacing them with Ubiquiti, but needed to run some more wire throughout the house to get what I needed.
Then I ran into a firmware upgrade that bricked 3 of my 4 cameras. After going back and forth with their support and getting nowhere, I just gave up. I had replaced the controller with the CloudKey G2 at one point because the old one was no longer supported, and it seemed to help with but not totally resolve the days of rebooting cameras situation.
Honestly, having the cameras bricked was a relief, because of all the consternation that the firmware updates had been causing. I just couldn't bring myself to buy new Ubiquiti cameras.
I ended up pulling out all the Ubiquiti hardware, replacing it with $200 4K very low light cameras that are just amazing (rebranded HIK Vision, "Montavue"). I'm using BlueIris for the camera controller, which is fine. Still using the Google WiFi, which continues to work great. I have 4 APs (one in router role, 3 spread around the house).
Security wise it is not great, but I don't think it is worse than other consumer products (tplink, netgear...etc). At least ubiquiti patches vulnerabilities reasonably fast.
Their cloud infra sucks and the whole data breach / lawsuit drama people constantly bring up was all because (I think?) a former employee had a static AWS access key with admin level access. Small companies are usually not good at dealing with internal threats. I don't use the cloud service anyways and self-host the network controller.
Now my biggest complain is that I have to manage a mongodb 3.x cluster for the controller...
I need it to be an external cluster with some redundancy, so that I can easily backup the database, fix file corruption, and deal with other database errors.
If you have questions where you think I can help, drop me an email.
I picked up a couple of Grandstream Wifi 6 APs to try and other than the gawdawful update process (that has thankfully improved - but you still have to get past the ridiculous initial firmware) they are wicked fast and so far a lot more stable/consistent than the Unifi counterparts. The unifi controller is indeed very slick/pretty to look at, but over the years I've come to realize that the "stats" it reports aren't very accurate so I'm back to librenms to gather/report on my network statistics.
I still think Ubiquity rots from the head and whether they mismanage teams in one country or another should not reflect on the country the people are working from.
Me and some other colleagues worked for a US based company from Hungary. The company payed us well according to Hungarian standards, but wee where cheap according to US standards. (The payed US junior salaries for senior people). The people in the team were very knowledgeable, efficient and we delivered a lot of great stuff. It worked well for a couple of years, but then the company got greedy. They hired people from another outsourcing company from Ukraine (I think) and this time they went for the cheapest. The people we got only had little work experience and they paid by the delivered story point. The code quality suffered as they wanted to merge everything ASAP. I left shortly after for a different reason, but as I heard from previous colleagues the company went downhill after that.
So outsourcing can be a turning point, but for a different reason than you think.
I even said so by pointing out that I think they rot from the head and do mismanagement as you described too.
So in that light I would ask how did you understood me thinking something different?
https://store.ui.com/collections/unifi-network-wireless/prod...
I'd like to see something with 6e but these are still incredible:
- Fast
- Wide compatibility across devices
- PoE
- Put it wherever you want, doesn't have to be in some closet near your modem/router/etc
- Just works. Really. I've run Ubiquity APs for years. Throw devices at it, literally never worry about Wi-Fi again. Say goodbye to it flaking out, slowing down for whatever reason, the occasional reboot, etc.
- Need more coverage? Plug in another AP, couple of clicks, done.
I run a local controller in an LXC container (VM, docker, local, etc available too) with all local login and none of that cloud and phone home stuff enabled.
However, I wonder if this is true in either repeated or multi-ap setups ? That is, if I configure an AP and then one of those wall-mounted directional ubiquity repeaters with another AP on the other end … shared SSID … can that configuration run with no controller?
I would think it could but .. I have not tried…
The older one finally asked me "do you think the WiFi is just super-good at our house?!"
There is hope, though, they recently started to speed test the networks they are in and mine is so far winning.
All this does not matter, really, as having 40 vs 200 Mbps on a phone did not matter much.
People are surprised that I have the smallest fiber package (150Mb/150Mb and it's more than enough) and I have "better" internet than their gigabit cable.
As for packet loss, this would be a problem as it means hw issues or misconfiguration somewhere.
they are on battery backup
Is this useful?My understanding is that when there is a power failure in the neighborhood, the broadband provider's equipment is usually offline as well.
Of course, the answer is probably: "it depends on your broadband provider's local hardware setup." But I would be interested to hear peoples' thoughts.
My house is brick/mortar so I need 2 AP's to cover the entire house - the AP is one kids bedroom - she insisted a wired LAN connection for her PS5 (online gaming and ping/lag) so I needed to power both a small switch and the AP - got a 12V battery system for that.
I had a friend with a generator who got the opportunity to test this due to an extended power outage. Although I agree, it probably depends largely on how well your local ISP has their act together. He found that Comcast (consumer-grade Internet) in his neighborhood was actually able to keep Internet service running for a little over 24 hours. His generator evidently outlasted Comcast's generator and he lost Internet on the second day.
I'd love to see neighborhood-to-neighborhood, ISP-to-ISP comparisons of Internet connectivity longevity in the event of power outages.
Many devices also operate less efficiently in high heat. If the AC unit is on a circuit with other devices, it is possible that the influx current when starting the AC unit trips the breaker. One might even be able to get away with 2 AC units on a 15A breaker as long as both compressors never start at the exact same time, but cause a trip when then kick in together.
After several years of use, I can say that Ubiquiti software and support are trash. Their configuration app (I used the iOS version) almost never works, meaning that it almost always fails to find the AP that is one foot away from the phone. It also suffers from unprofessional UI-layout defects. Their Mac app won't run until you manually strip quarantine flags from it because it isn't even signed... then it won't run because it relies on Java 8, and Mac OS hasn't shipped with Java in a decade. And if you jump through enough hoops to get it to launch, it fails to detect any Ubiquiti devices.
Once I somehow tricked their iOS app into communicating with the AP and got it working, it did work for years and has pretty good range.
But now (and this appears to be a somewhat common problem), the AP randomly stops sending data on 2.4 gHz. Here's one of several posts about it: https://community.ui.com/questions/AP-AC-Pro-problems-with-2... And it appears to afflict multiple products.
This can last from minutes to days. Although you're connected to it, you can't even hit the router. Ubiquiti support is utterly useless; it's as if they do everything possible to drag out interactions until you go away, providing vague, terse, one-sentence answers every couple of days that contain no specifics.
My impression is that Ubiquiti is just hanging on, coasting on existing technology and doesn't even have support staff that knows how it works.
I don't think Amplifi is getting enough love in the consumer market today. I know anecdotally when walking my parents through the Amplifi purchases I had to ask a Best Buy employee to leave and stop confusing my parents because he didn't understand why anyone would want the "weird new" Amplifi brand and not "the better brands" Google Home or Netgear Orbi. I didn't feel like explaining Ubiquiti's decades in Enterprise to the kid.
It doesn't help that Ubiquiti has had some recent troubles, and I'm still not sure even Ubiquiti knows what the long term horizon looks like for Amplifi products. But I appreciate that they are trying to make headway in the consumer space, and that from what I can tell the consumer products do show the experience from Enterprise products.
It would be nice to have a less complex app/frontend management interface for less tech-savvy end users -- if you could use the Amplifi app to see status and do basic troubleshooting on an Unifi network for instance--
The upgrade pick would be the RB5009 with SFP+, 2.5GBe and 8GBe ports, much-much more CPU. The availability of this is pretty bad tho, I have the PoE version on order.
So yes, the difference is like this: https://i.redd.it/slaeayro0o061.png But in the end, it is worth it.
this can be both a pro and a con :)
The wired buffer bloat screenshot seems quite high to me at 53 ms. Not sure if it's router or something else related. Have you tried connecting directly through the modem?
In my setup, FTTH of the GPON variety (1000/400), I get around 5 ms latency on the buffer bloat page. My old FTTC setup (1000/60, fiber to the curve + COAX through the building) was around 8.
My setup is GPON box -> managed switch -> Router (virtualized on KVM with pass-through NICs) -> managed switch (again) -> 2nd managed switch -> PC.
There’re already the fiber cables on the street, I’m waiting for the vertical lines to my home.
This was in an apartment building in Paris, not a detached house. It was a quite common setup when fiber started rolling out: it would arrive in the basement and apartments would be connected through the existing coax (TV) cables.
Checking Wikipedia, maybe FTTB is a more appropriate term.
Now it's mostly GPON FTTH.
---
edit: regarding the latency, your setup adds around 30 ms of latency, which to me seems rather high.
Ping time from router to AP
root@R4S:~# ping 192.168.1.3
PING 192.168.1.3 (192.168.1.3): 56 data bytes
64 bytes from 192.168.1.3: seq=0 ttl=64 time=1.150 ms64 bytes from 192.168.1.3: seq=1 ttl=64 time=1.252 ms64 bytes from 192.168.1.3: seq=2 ttl=64 time=1.117 ms64 bytes from 192.168.1.3: seq=3 ttl=64 time=1.170 ms64 bytes from 192.168.1.3: seq=4 ttl=64 time=1.210 ms64 bytes from 192.168.1.3: seq=5 ttl=64 time=1.204 ms64 bytes from 192.168.1.3: seq=6 ttl=64 time=1.232 ms64 bytes from 192.168.1.3: seq=7 ttl=64 time=1.190 ms64 bytes from 192.168.1.3: seq=8 ttl=64 time=1.207 ms^C
--- 192.168.1.3 ping statistics ---
9 packets transmitted, 9 packets received, 0% packet loss
round-trip min/avg/max = 1.117/1.192/1.252 ms PING 192.168.1.3 (192.168.1.3): 56 data bytes
64 bytes from 192.168.1.3: seq=0 ttl=64 time=1.150 ms
64 bytes from 192.168.1.3: seq=1 ttl=64 time=1.252 ms
64 bytes from 192.168.1.3: seq=2 ttl=64 time=1.117 ms
64 bytes from 192.168.1.3: seq=3 ttl=64 time=1.170 ms
64 bytes from 192.168.1.3: seq=4 ttl=64 time=1.210 ms
64 bytes from 192.168.1.3: seq=5 ttl=64 time=1.204 ms
64 bytes from 192.168.1.3: seq=6 ttl=64 time=1.232 ms
64 bytes from 192.168.1.3: seq=7 ttl=64 time=1.190 ms
64 bytes from 192.168.1.3: seq=8 ttl=64 time=1.207 ms
^C
--- 192.168.1.3 ping statistics --- 9 packets transmitted, 9 packets received, 0% packet loss
round-trip min/avg/max = 1.117/1.192/1.252 msSFP is a plus though, and software support is pretty weak on R4S side - only getting openwrt official support in the upcoming 22.03 release...about a year after you could buy the device
[0] https://www.cpubenchmark.net/compare/Rockchip-RK3399-vs-Medi...
Hex S can route gigabit; barely, but still. See https://mikrotik.com/product/hex_s#fndtn-testresults For a 6W device, that's pretty neat.
I'm in this situation.. But I have the fiber line coming directly into my gear with the ISP provided modem into another port on the switch. I use an EAP proxy to forward the authentication packets to modem, and all other traffic skips the modem entirely.
I did ask my install guy to give me the separate fiber transceiver (not integrated with the modem), because I didn't have an SFP cage to use the fiber line directly.
1. had the UDM for about a year, then at some point found out that some firmware update had completely trashed 2.4GHz wifi. Like you can connect to it but if you transfer more than 1MB or so it just hangs, reconnect works but basically unusable, 5GHz works fine but in my house the office just did not get good enough coverage. Like, dude, you had ONE JOB!
2. Bought a Ruckus AP and an Mikrotik hEX S to do routing. Wifi is better but office still did not have good enough coverage.
3. Finally gave up and just ran some CAT 6A from the router to my office. Night and day.
From my research Ruckus gear is really good and requires no controller nor cloud connectivity whatsoever but expensive. Mikrotik is nice for wired stuff, but mostly quite dated for wireless, also they still carry a lot of their previous generation gear .. a lot of it has really wimpy CPU's, so do some research. Also the configuration can be a bit involved, tho lot of internet advice on a decent setup.
The original cloud key is quite slow but totally usable; there's a docker container and running on anything faster than a Pi its quite fast and snappy.
It is more complex, you have to get used to Winbox, but after that, there's no way back to Unifi. There are no dashboards that look nice in screenshots, but on the other hand, the stats provided make sense.
But wrt firmware issues, Mikrotik also has occasional one.
After the security incident a few years ago, Ubiquiti pushed an update that let's you login to it via a local credential rather than their cloud identity server.
I don't see anything in UDM Pro's Unifi that is dependent on their cloud (other than checking for updates)
They don't have this attitude and never have. You can use local accounts, have always been able to use local accounts.
The only thing out there that's better than Ubiquiti is actual enterprise gear, all of which now requires subscription licensing. Unfortunately if you want a buy once / cry once solution for prosumer usage, Ubiquiti is the best option. I hunted for alternatives several times, and nobody is competitive. Microtik is the next closest option, but it's frankly garbage and with bigger security issues.
Ubiquiti is the least smelly networking solution in a room full of really smelly options. They are not consumer friendly like they used to be.
Agreed entirely. Unfortunately this is a market that's not well served because there's a lot more money to be made just shoveling consumer garbage out or putting small businesses over the barrel with subscriptions rather than offering a proper prosumer product.
https://community.ui.com/questions/BUG-USG-PPPoE-or-Static-I...
Surprisingly Cisco, with their small business line, has one of the better looking contenders. No subscription - and I didn't need anything (not even an email) to download firmware updates or the controller (!!) Not your fathers Cisco! Their controller lags Unifi, but not by much. I scored a router and switch off of ebay just to dabble and it was pretty promising. I haven't looked at it for a while; I probably need to fire it back up and see if it's matured any. In the end for firewall I went back to OpnSense. Unifi switches are OK but their one year hardware warranty, frankly, sucks. If I were to by new switches I'd probably just go back to netgear. Their lifetime warranty is pretty hard to beat. I've had them replace 10 year old switches with nary a blink of the eye so it's not just lip service.
Not only software-level, but "hardware" e.g. best location, enclosure, cabling, etc.
If you have a strong 2.4GHz wireless network already (a proper mesh system in your home), look into having your smart stuff run over wireless, no point in having zigbee. If you don't have a strong wireless network, first consider getting one, else look into zigbee devices.
Run home assistant, doesn't matter what devices you want to have on your network, home assistant is a must for a decent smart home experience. You can run it on a raspberry pi 3b+ or a spare server in a docker container. Spare server is faster but the pi can handle it.
Setup all your devices to talk to home assistant, then make home assistant expose the devices to Google Home or Alexa, instead of directly exposing the devices to the cloud services.
Smart TVs are not good, my experience with LG and Samsung has been of ADs and abandoned software, instead get a good TV (image quality, etc..) and plug a Mi Box or Roku or Amazon Firestick into it.
CCTV is a mixed topic, you can go the closed circuit camera option (NVRs and suff) or you can go with ip cameras. Just don't use wireless cameras, everything wired for this.
If you want some hardware brands and comparisons, check out The Hook Up on youtube for the specific topic. I can vouch for Sonoff, Shelly, Reolink, etc..
However, we have a few ZigBee remotes/portable buttons and sensors (motion and temperature/humidity), which are a great addition. I already know where to put another ZigBee router to finally make that floor reliable. But I can only do so once my SO&I agree on what fixture to put there, and that's complicated ;-)
Maybe look at the nVidia Shield as a more privacy-friendly alternative to FireTV et al. (at least that's what Mozilla says). Sadly it's pretty expensive.
Can't say anything about NVR.
The remainder I can totally agree with. If I unplug my modem, only thing lost are weather report and mower bot control.
I've been meaning to try the newer 700 series hub for better penetration.
The other issue is that despite zwave being low power, all the devices are still $50-$100
I have a home network powered by Asus routers, but that's only after years of trial-and-error with other brands (Netgear, Linksys, TP-Link). The fact that Asus is the "crappy inconsistent B-minus grade devices" company normally and that's way above average in routers is a massive step forwards.
The extended features are a joke and I have to reset the routers maybe once a year at worst but they're the first solid home internet connection I've ever had.
If I have to go through the mayhem again, I'll be cribbing from guides like this, but I'll be really really angry about it.
How do normies live?
Part of the problem is, most consumer-grade routers use CPUs that can kind of get by most of the time on passive cooling. Then when the weather is hot or your usage is above-average, it has problems.
Most people want to avoid active cooling on a router, because you've got it out in the open for line-of-sight / signal propagation purposes, and there's kind of a reliability argument for avoiding moving parts.
I'm not trying to say the only advantage of a pro setup is having fans on it, but it's definitely one of the advantages.
I think the phrase 'ignorance is bliss' explains this
How do the normies live? Quite easily.
I use my Internet carrier's WiFi 6 router/modem combination. It works fine. It's free, and I don't get a discount for bringing my own equipment. I spent zero time configuring anything.
I have Internet. I haven't noticed any problems making Zoom calls or playing games online. What I don't know about my bufferbloat score doesn't really hurt me.
Anything I host is in a VPS so I don't need any advanced routing or VLANs.
I’ve explained my setup at the beginning of the post, there’s also the “temperatures alerts” in my previous blog post. Also if the temperature raise too much, the A/C above the wooden cabinet turns on and cools down all the hardware. During the night thishappened various times during this hot summer!
> I'd recommend keeping all that in a metal enclosure in a utility room where the hardware can catch fire without setting the entire house ablaze
Yes but you cannot agree with me that the metal racks are terrible/ugly =] I want to have my network things inside my house, possibly where I can see them, and I don’t want to have a metal rack inside my living room, see my first post with all the house rooms (http://giuliomagnifico.blog/networking/2022/01/14/my-home-se...).
Anyway I can’t say that the fire risk is concrete, as always with electrical things. But I prefer to monitor this risk with sensors and maintenance instead of “move the risk in the garage/car park or cellar” (I also have a fire extinguisher hidden inside a wardrobe, just in case…)
The A/C starting if things get too hot is great, especially if it doesn't depend on any of said things not being out of order (say because it shut down because of the heat).
I can also call my parents or neighbors to ask if they are seeing smoke out of my house =] that’s the most efficient alarm!
Most of these appliances don't actually have flammable materials right next to the active components that can catch fire. A circuit board can catch fire but it'll likely self-extinguish because it's in a metal enclosure away from anything flammable.
In this case, you'll very quickly get a self-sustaining fire (thanks to all that firewood around it) and will need to actively extinguish it - turning the power off or starting the AC will not save you.
The best solution, short of an active fire suppression system such as sprinklers (which obviously come with their own problems) is to put the hardware in a place where you can have a device catch fire and be confident that the fire won't spread or get out of hand.
I understand what you say, unfortunately! I hope that nothing will ever happen…
From the manual "• Provide 5 cm clearance on top and sides for adequate airflow around the unit."
My network gear runs 24/7, even if I'm away from home for multiple days at a time. I usually only turn it off when I leave for longer (>1 week) holidays.
Most cheap hardware does not have X or Y safety class capacitors so if there's any exposed conductor you're probably marginally safer on an insulator like wood.
Not great and I personally wouldn't put equipment in cabinets, but I'd expect most failures to occur when the equipment is actively being used & under stress, not during standby.
"Name Brand" products with legitimate UL listings almost entirely use Class X or Y caps where safety regulations require them and would be immune to this problem due to internal construction differences. "No name gray market off aliexpress" would be an unwise choice.
It's surprising how few fires we have from household electronics. The odds are it'll be fine.
It looks like a branded generic Supermicro machine but seems convenient to get it out of the box and the price doesn’t seem bad considering what’s in it.
1. https://shop.netgate.com/collections/rack-appliances/product...
Could put in a PCIe dual x 10GBe card into an old PC and if that's not enough ports buy a vlan capable switch with a 10GBe uplink and enough 2.5gbe/1gbe ports for your needs.
From what I've been able to tell, at 10G speeds, you pretty much have to build your own. Currently, I'm planning to get a SFFPC, stick a quad port 10G card in it, maybe run ESXi, router OS TBD: VyOS, DANOS, OpenWRT?
Wireless is fine if it's only half of your loop. For example, suppose you want to stream a game from your powerful computer/console to your phone/tablet. There's a perceptible difference between having just the receiver wireless and having the sender and receiver both wireless.
Am I being silly? I'm concerned about what could happen if there's a failure when I'm not home to maintain everything, since I'm the only person who can or wants to work with this equipment.
I'd love to reduce my buffer bloat to improve the quality of my my video and audio calls. But I'm not sure it's worth it. Or if the results in this post demonstrate an average use case with a crappy ISP.
Bonus is OpenWRT also seems to be much more stable than manufacturer hardware as long as your hardware is well supported. Plus you don't have to worry about your manufacturer no longer supporting firmware on your model and OpenWRT is much faster to respond to the occasional security issue, etc.
OpenWRT has gotten some flak over the years by leaving devices behind when they no longer have enough flash and/or RAM. That said OpenWRT is likely going to support your hardware longer than the manufacturer will.
OpenWRT didn't even support the CPU by default, and when I managed to get OpenWRT on there, I had serious QoS problems because the CPU wasn't up to snuff. I liked OpenWRT a lot but it was a really frustrating experience.
Anyway I leave alone but With a VPN you can manage your home LAN from everywhere. I’ve done a similar setup for my parents, when they call me saying “we don’t have internet” I can simply check what’s going on, I wrote a post here: http://giuliomagnifico.blog/networking/2022/07/21/setting-up...
https://community.ui.com/questions/Wireless-LAN-Roaming-FAQ/...
It all works very nicely.
Internet -> Modem -> router -> managed switch - access point ?
Anyway, thanks for sharing the setup. I love how everybody here has a different takeaway from this. For me, it was nanoPi. I just ordered R4SE for my tinkering with OpenWrt.
I have a symmetric fiber gig connection that is quite stable but I’m thinking about getting a secondary connection from a different provider. My “dream” is to have HA (active/passive) routers that can fall back on the backup (slower) line and back when there’s need. The rest of my HW is small and spread out throughout a house than not a single failure will severely affect my home.
Yes, also. depends if you are in download or upload =) be careful with the R4SE (the model with inside eMMC storage), I don't know if the R4S OpenWrt build will run also in the R4SE.
Currently I'm using: ATT fiber modem, Mikrotik CRS354-48P-4S+2Q+RM for PoE+, tplink deco axe5300
https://www.amazon.com/gp/product/B087X7KNWS
https://www.amazon.com/TP-Link-AXE5300-Tri-Band-Whole-Home-S...
I'm not familiar with any of OP's components, but it's absolutely possible to have a silent setup.
In my case, I have an HP EliteDesk (salvage from work) that does the routing, etc, which is dead quiet, and it's connected to a fanless Brocade (Ruckus) switch. There's no coil while or anything. The most annoying parts are the blinking lights, which I fixed with some red tape.