OpenWRT turns 20; wants to launch their "first upstream supported" design
lwn.net
lwn.net
https://www.friendlyelec.com/index.php?route=product/product...
On the other hand, they would sell it with direct support for real OpenWrt, while many other manufacturers, including FriendlyElec, often publish franken-Linux distros that force users to resort to others such as Armbian and DietPi to be sure their OS doesn't become obsolete and unsupported in a few years.
I have been looking for an open source replacement for the Elecom WRH-583BK2-S is there anything in there? It's a W65 x D35 x H20.5 (mm), dual LAN, 802.11ac router.
I'm guessing it will also be a tag from `git.openwrt.org`, from the same development and release process that continues to support numerous other consumer devices, and keep them up to date.
It might be good to clarify this, since people who've seen a lot of open source projects can imagine ways this could go bad.
I have a very favorable impression of the OpenWrt project, and I'm looking forward to this being a good thing.
Also, I think the configuration file is already robust enough; you can edit them using a text editor like vim or edit them using the UI or edit them using the CLI tool. I cannot think of anything to make the configuration file even more robust.
At least on the hardware I've owned, OpenWRT has to be reconfigured after version upgrade or else it becomes unstable.
Thankfully all the config files are plain text and can be manipulated however you like. It is usually not too difficult to take working config while fixing or disusing problematic files.
the turris devices are tinker friendly, feature rich and high quality - and not cheap.
truth be told, the aio router-server embedded thing seems very difficult because peoples expectations vary widely and the whole ids/dpi and media-server stuff gets somewhat more demanding at gigabit speeds than what unoptimized stacks can accomplish with commodity low-power hardware.
As a result, it's capable of 99% of jobs, but it's only the best choice for about 2% of them. For most things, the Omnia is tremendous overkill and nowhere near cost effective. Therefore it suffers low sales volume, and the price never comes down.
This new box might only be capable of 75% of jobs, but it should be a good cost-effective choice for quite a lot of them. It still won't be the cheapest, but it'll be reasonable, and they should sell truckloads of them.
I associate openwrt with router firmware/software, so I would expect a lot of ethernet ports (more than two). Or use it as a wifi router/access point, when I only need one port. If I would want to do any networking tricks, I would fall back to a rpi/banana pi, which wouldn't do routing or wifi.
I'm only curious. I have two rpi's in my drawer doing nothing.
Longer answer:
1) providing basic networking (default gateway, connection to upstream provider)
2) basic security: firewalling + natting
3) basic network daemons, and "daemons": DNS, DHCP, IPv6 autoconf, and a nice new one: 802.11s ("network mesh": keep wifi at 5 bars by kicking people off their access point if another access point can provide a better connection)
4) more advanced networking stuff: VPN (l3vpn, l2ptp, l2ptmp, mesh vpn), cloud connections/vpns, WAN connections, redundancy (downstream and upstream, l2 and l3, ...)
5) more advanced security stuff: 802.1x, stateful firewalls, inspecting firewalls, IDS, ...
6) server networking stuff: proxy, reverse proxy, statefull firewalling, load balancing, ...
7) more advanced daemons (on network devices it's mostly proxying for redundancy and/or load balancing): File sharing, SMTP, WebDAV, Active Directory, payment protocols, ...
Now a lot of these OpenWRT can't provide, but you'd be surprised and their support for new things goes up every year.
For a router, you can feasibly use an off the shelf prosumer device like Unifi, or, more compellingly, an actual robust OS like OpnSense, PfSense, Sophos or Untangle.
As for access point capability, that should really be segmented, and any off the shelf Ruckus, Aruba, Unifi etc. will always outperform the drivers available to OpenWRT. I'm a staunch advocate of an eBay ruckus 510 or 610, which will be very little in terms of cost and also your best home access point ever.
It's nice that it's open source and all, but in terms of raw performance or value-add, I don't see it. Open source for the sake of open source is... well, another discussion.
You probably don't see it because you are used to spending big bucks on your networking equipment whereas most people will spend $50 and then install OpenWRT to wring the most value out of it.
It's not a package deal, but router hardware for Pfsense or OpnSense, or even a Tp link or Unifi device isn't exactly breaking the bank.
It's also vastly superior enough for the Open WRT to not be worth it.
Does OpenWRT appeal to people with a low degree of knowledge, time or skill? Heck no.
The most applicable scenario I can think of is someone who is very knowledgeable and has a lot of time but very little money, but OpenWRT exclusively as a device for people who live in India or Brazil is again not super compelling to *me* as a technological package.
Though I respect conceptually that other people might have different perspectives, I live in a country with an average living standard, so I can't really share it.
Yup. That was me as a high school student. Or rather, I wanted to be very knowledge, and did have a lot of time and very little money. OpenWRT was perfect to get started with tinkering with networking.
This. Your comments about open source are relevant but IMO these days with work from home, tons of devices, larger/more well constructed homes, increased traffic for anything/everything, etc managed APs are just the way to go.
I'm a big advocate of OpenWRT but many years ago I got sick of fiddling with basic connectivity on a regular basis and dropped a few hundred dollars on a standard Unifi setup. I haven't touched or thought of my "pipes" since - to me there's nothing worse than being deep flow into a project and then having to fiddle with some router or access point because it's being flaky, dropping packets, negotiating slower link speeds, etc. It's much better than factory firmware in most cases but that's a pretty low bar.
Ubiquiti has had some controversies with data access, cloud stuff, etc but I just can't be bothered to care. For $100 x $NUM APs and a docker container to run the controller it just works.
Unifi has been truly game changing for me in terms of making wifi ethernet level reliable, predictable, and consistent - everywhere without needing to take on yet another level of deep expertise in Wifi.
To replace it, I saw that Asus routers use a custom wwrt by default. And if you want to truly control it, there's an open source project that lets you adjust it more (Merlin).
I bought an Asus router and haven't looked back.
Back then I didn't really understand routing etc. and just used OpenWRT as plug and play. But is it actually a good alternative to the above component-based setup when just a single device is desired?
2. Mediatek might not be willing to provide their WiFi SoC if you are not using their compute SoC, and Rockchip doesn't have any WiFi chips.
The rk3588 is frankly a non-starter.
There are some China-only ZTE devices that do this, but they obviously have a different order volume and scale that makes it possible. (The main SoC is replaced with a ZXIC one, a ZTE subsidiary)
* >1G internet in a mostly or exclusively wifi home
* <=1G internet + a 2.5G LAN, so that ethernet <=> wifi and ethernet<=>SSD transfers are faster
The second scenario could actually fit me right now, but my ISP is expecting to roll out multi-gigabit options later this year year.
At any rate, I agree with everyone else, I would prefer two 2.5G ports.
Seems to really limit the audience and shorten the useful life of a router to penny pinch. How about a $88 NanoPi with dual 2.5G, 4GB ram, 32GB eMMC, and wifi? Is it really worth $10 to have 1/4th the ram, 1/256th the storage, 1G instead of 2.5G and less CPU[0]?
I got similar with the faster RK3588, 8GB ram, dual 2.5 and 1G, and metal case for $120. I've been quite impressed, it's about half as fast as my xeon E3-1230 from years ago.
WiFi is always a problem with flashing random devices. If they can build a device that has stable WiFi with external antennas, it would be a game changer.
There isn't a wide consensus anymore, like there was with the buffalo model.
Integrated modem would be nice, but it is very difficult to find it.
edit: available in EU; Linksys E8450/Belkin RT3200 aren't available on Italy it seems.
I’m looking as well. Although now it seems like I should just buy this BPi when it is available. I would like to go back to ARM on my router… just nothing Broadcom!
Updates are as easy as other device (press button on web interface or use openwrt cli)
IMO, owrt runs best on x86 (it’s your usual Linux kernel after all) and you get the best support and performance. You also avoid a lot of all the bugs related to embedded development with custom SoC, internal switch, vlans, flash layout, possibility of brick, bootloader stuff, etc.
You could download the CSV dump of the hardware table [1] and filter in e.g. LibreOffice Calc.
https://store-eu.gl-inet.com/en-jp/products/flint-2-gl-mt600...
https://openwrt.org/toh/mercusys/mr90x_v1
Anything with the MT7986B chipset is a good choice, they support Wifi6, have a 2.5G ethernet port, have decent amounts of RAM/flash and mostl importantly have a fast enough CPU to do high speed WAN to LAN routing and firewalling.
If they're able to deliver what's in the email I'll be picking one up.
* USB (device, console): Holtek HT42B534-2 UART to USB (USB-C port)
* Power: USB-PD-12V on USB-C port
Does that mean dual USB-C ports, or will the console host also need to supply power?OpenWRT-based cheap travel routers have been a life-saver for me during my trips, specially to countries behind Iron Curtain firewalls.
I'll buy at least one as soon as it comes out.
(Asking out of total ignorance)
https://wireless.wiki.kernel.org/en/users/Documentation/mode...
That's unlikely to be what was meant. It's probably m.2 2242, a shortish but "normal" drive size in the embedded space.
Notice no 20 mm width is allowed as part of the M.2 standard. The device specs are likely a typo.
As others have said, it was probably supposed to read "m.2 2242" which is physically in-between the size of the 2230 drives that the Steam Deck uses and the 2280 ones that most modern desktops and laptops use.
Looks like there is some progress now for running OpenWRT on Asus RT-AX89X.
Please post the links!
https://forum.openwrt.org/t/whats-your-favourite-cheap-lede-...
https://forum.openwrt.org/t/whats-your-favorite-enthusiast-l...
Best of both worlds.
Compared to an ordinary router:
1) There's a bit more powerful CPU, barely enough for TOR or wireguard VPN. Doesn't say anything about hardware crypto.
2) There's 1 GB RAM, way too much for basic routing, barely enough for TOR, barely enough to run a webserver, but not both.
3) There's NVME storage as an option, but NVME is too small, too expensive, and MUCH too fast for a NAS with that kind of networking, and there's no USB3 or eSATA to connect external storage such as a large HDD or a DAS.
4) I assume that the wifi chip (only one?) is soldered. If the driver ever becomes unmaintained, like it happend with mwlwifi, you throw the router into the garbage.
5) It doesn't even have a network switch.
6) They plan to load it with various features (serial, USB debug, JTAG (ffs! why??)) that only devs will ever use, and only until they get it booting. No use for all that once it boots reliably.
7) Modbus? Who uses that!? I want mPCIe, GPIOs, I2c, SPI, serial (other than the debug port), RS485, you know... actually useful stuff!
8) And there's RTC on a device that 99.9999% of users will connect to the internet. Why? For the rare situations when it boots after a power failure before the ISP network is up? If it had SPI/I2c out, there are Raspberry Pi RTC modules that could be added for $1.
9) The price: 100$ is waaaay to much for something that's only a micro-router. GL-MT3000 is in the same price category and has USB3.
My ideal router would have:
- 2 GHz 4 core armv8 CPU, or at least 2 core armv7+vfpv3
- working frequency scaling and idle
- hardware crypto (wireguard, openvpn, TOR), hardware CRC32 (for btfs), hardware XOR (for MD RAID)
- RAM as SODIMM memory modules (even better if sold without them - recycle my own, upgrade any time)
- at least 3 mPCIe slots for wifi 2.4G, 5G, and WWAN modem (even better if sold without them - recycle my own, upgrade any time)
- 8 port switch with management
- WAN port separate from the switch
- eSATA with port multiplier support
- USB3 with UAS support
- GPIO identical to RPi, maybe one more serial port
- mounting holes that fit an ordinary GPU cooler
- temperature sensor on a wire
- PWM LEDs
- no GPU, no HDMI, no other video outputs
Unfortunately, no such device exists.
8: RTC is SURPRISINGLY very important for E.G. Initial TLS / HTTPS connections and bootstrapping secure connections. It's also a serious quality of life aspect that doesn't cost that much to add. Surely you've seen the hell caused by Microsoft's attempts to fix this problem wreaking havoc with connection failures.
5: I suspect that was more to fit the form factor of an existing off the shelf case, and dangling a dumb-switch off the internal port is a reasonable option. This is annoying but I understand the reasons and tradeoffs.
I see using this device as a router for E.G. grandma's / friend / other family. Where someone tech literate buys the thing that does 99.9% of the desired work for a lot less headache and that you know will see updates because it's supported from day 0 by OpenWRT / the community.
Wifi 6E, with the upper band frequencies, might be enough to convince me to get it too.
8: I'm not aware of any problems. Why would TLS and HTTPS not work? AFAIK, when NTP is not yet up, OpenWrt sets system time to the timestamp of the most recent saved file. That is good enough not to run into "certificate not yet valid" situations. And what HTTPS and TLS are you talking about? DNS over <something> won't work until WAN is up. When WAN is up, NTP is up too.
5: I don't. What good is a slow cheap router if I need another device next to it? Might as well put an old laptop/desktop as router instead.
Lots of routers are supported by OpenWrt, until they aren't. I already mentioned mwlwifi - they were the best routers, most recommended, until that driver was abandoned. Soldered wifi from another manufacturer won't change the situation. Works today; crashes tomorrow.
I've been using (and previously contributing) to OpenWrt for almost 10 years, it's an excellent project and deserves some spotlight, I really hope this gains some traction.
I'm a big fan of OpenWRT. I switched to it after running pfSense for a lot of years. Anyone can donate to the project here: https://openwrt.org/donate
That being said, a huge portion of the consumer-oriented router brands are based on openwrt/buildroot today, so they're far from the only group guilty of benefitting from openwrt without contributing things back.
https://downloads.openwrt.org/releases/23.05.2/targets/media...
https://downloads.openwrt.org/releases/23.05.2/targets/media...
https://forum.openwrt.org/t/trouble-flashing-vanilla-openwrt...
gee_one
December 12, 2023, 2:36am 4
I just got one of these. It is certainly supported! I am now running my own homebrewed build of openwrt 23.05.2I updated the gl-inet firmware to the latest 4.4.6, and then flashed vanilla openwrt 23.05.2 through the luci web interface.
I played around with the uboot flasher which takes an img file. I haven't played around enough with it yet to unpack the images to see if they are different formats or not.
It sounds like you are doing the right things. I guess check the hashes to make sure the files are intact? I haven't tested other versions or snapshots.
cameroncc
December 12, 2023, 4:07am 5
Did you just use the sysupgrade image from the firmware selector? How long did it take to fully flash? gee_one
December 12, 2023, 5:30am 6
Yes, for the vanilla firmware, I used the sysupgrade version from the firmware selector, 23.05.2.I don't remember how long it took, but it wasn't very long. I think about 5 mins or less. I had a serial console as well, so it was easy to see that some activity was going on.
cameroncc
December 15, 2023, 4:13am 11
Well, I just reflashed the GL.iNet image from uboot and then flashed the OpenWrt sysupgrade image from luci again just like before so I could try to ssh and read dmesg before messing with UART and it just... worked... no idea whyI realize that 23.05 is supported on the device, but my point is that it was entirely done by individual contributors from outside of GL.iNet, not contributed by the company itself. It sucks because GL.iNet sort of built a reputation off of being the openwrt router brand, and used to be in relatively good standing, but have shifted their approach since. Now they benefit off the reputation they built previously, because of people like me who assume they're still doing that before making purchases.
Not sure I understand why this would not be exactly what one would want. (Namely, people outside the company being able to get the hardware to work with an open source OS.^1) Who wants to be stuck with a proprietary vendor OS on a router, something like Ubiquiti (a company recommended countless times on HN), where the only way to get the full features is to use their OS instead of choice of Linux/BSD installed by the buyer.
AFAICT, GL.inet software is generally no better than OpenWRT or other open source projects. It's probably terrible. Why would anyone expect otherwise. Good reason to compile OpenWRT for oneself.
The GL.inet software is probably getting worse. FWIW, one can still buy the older models. The pre-installed bootloader can be replaced. For newer models, might have to contact GL.inet. It's not clear if you are suggesting one cannot get the source to the bootloader for the router you bought, i.e., you asked GL.inet and they said no or did not respond. If that's the case, then I am interested to know.
AFAIK, people bought the older models for the hardware, e.g., GB ethernet, small form factor, and being supported by OpenWRT. GL.inet is a hardware company that lets the buyer replace the pre-installed OS with their own version; this is anticipated. That is more than many companies selling similar products.
There may be better travel router hardware available today. But being known to work with OpenWRT is an important factor for some buyers. For _some_ GL.inet models, the hardware is known to work with OpenWRT and u-boot compiled and installed by the buyer. AFAICT, the models with the Mediatek 7981 SoC are not a problem. If this is wrong, please do tell.
1. For example,
https://forum.openwrt.org/t/how-do-gl-inet-devices-become-su...
daniel March 7, 2023, 5:38pm 33
fakemanhk:
while their MT2500/MT3000 using Mediatek chipset I might go for it since it has higher chance to get vanilla OpenWrt on it.
MT2500 and MT3000 will definitely get vanilla OpenWrt on them. I'm working on this. gl.inet has provided hardware and all necessary documentation (schematics, ...) to do this. Would of course be nicer if they'd even do that themselves, but that's too much to ask, I guess. It's quite different case from the SiFlower SoC where there isn't even any sourcecode for most drivers. For MT7981 everything relevant is available in sourcecode, just needed some work to go to upstream Linux and will land in OpenWrt very soon.This is certainly true. SoC vendors often base their SDK on a fixed version of OpenWrt and then add proprietary patches on top. Then sell the SoC + SDK to a device vendor that adds additional proprietary patches and sells the device.
The issue with this is that the only way to fix security issues is to back-port them to the exact kernel version the SoC used as a base, and after a year or two, they completely drop support and you're left with a device that has known security vulnerabilities you can do nothing about.
How many old routers are still in use that are used as part of a botnet?
See for example the audited financials of projects hosted by the Software in the Public Interest (SPI), where many do have tens or hundreds of thousands of dollars already https://www.spi-inc.org/treasurer/reports/202311/#index4h3
I would totally buy this device if they make it happen. My current router is about four years old and runs OpenWRT.
Are they complying with the license terms? I guess I don't understand why it would be considered a negative for them to build a product based on OpenWRT.
They do seem to be complying with the license terms, and the free portions of the software can be downloaded from the Gl.iNet website.
Most of the negatives have been covered in other comments here.
If they really want to focus on hardware and base everything on top of OpenWrt, it would be easier for them to upstream as much as possible and let the community handle updates. Even donating would be less expensive. It would be somewhat of a win-win situation IMO.
Would you care to go into why you chose it over pf/Opn Sense? Considering that you have to reinstall so it's not automatic, what makes it enough better to make the change worth your while?
I'm currently running OpnSense for my personal routing and firewalling needs, and considered OpenWRT a few weeks ago (for linux driver support, but that's another story). In the end, I changed my nic and kept opnsense.
Also, while exploring other options, I found that OpenWRT provided much higher bandwidth on the same processor/memory footprint. I was able to reduce the VM CPU and memory allocations after switching.
Finally, there were a number of features I needed that pfSense just did not support. One was IGMP snooping, another was IPv6 using a provider tunnel.
I hope OpenWRT pulls off having their own device. That would definitely be an upgrade from GL.iNet. But compared to getting a completely non-open firmware like every other GL.iNet competitor, even their versions of OpenWRT are a major step up.
There are a few of their devices that have upstream support in OpenWRT. But it is like buying any other device for running stock OpenWRT in that regard - you have to do your homework to make sure you get something compatible.
I still have OpenWRT running on a RPi4 'router' and 3 TP-Link routers as APs on my network. But still wish I could get GL.iNet's Wireguard management in Luci...
I have had a fiber line connected during the whole time and it has served me well (I haven't done much customizing on it though, I have to admit. It's just the router for my home network).
Second, why would you need something different that what routers are already doing? They are just trying to sell their own openWRT routers, the hardware has existed for a decade at or below $100, why would it be difficult for them to meet that?
"that this router isabeautiful (sic) example of excellent GPL/LGPL compliance"
I think about Meego/Jolla phone and tablet, Ubuntu Phone, Kobol Helios and tons of other projects that have either failed or are struggling due to market size and ecosystem.
I've been running a Turris Omnia for the last few years, which I've been fairly happy with. Network performance is about average and the platform as a whole is certainly due for an update, but stability has been great, it receives regular upgrades, and I'm happy to pay more for a project that has an open mindset. Not sure many feel the same way about commodity network hardware though.
https://www.amazon.com/NETGEAR-AC1750-Smart-Router-Gigabit/d... https://openwrt.org/toh/netgear/r6350
Here is a new router for $30 with 5 gigabit ports and usb 3.0 https://www.amazon.com/dp/B082HH24YY/
With something like a rpi that sells millions of units, that can be spread over way more units than something like this that (optimistically) gets sold to a few thousand nerds and that's it.
1. They ship an excellent device. I mean, if they ship what they're describing, I'd buy it.
2. The commercial side of things corrupts and ruins the FOSS+community side of the project (see: CyanogenMod).
Hope the first one happens and the second one doesn't.
You can probably run the whole thing for $100/year of unavoidable costs (eg. Domain registration).
I think you're significantly underestimating the kind of resources a project like OpenWRT needs.
(Source: involved with CI/CD pipelines for other, smaller, FOSS projects, and those already need much more.)
Also the USB-C UART and recovery read-only bootloader is a nice touch. Really looking forward to it.
One concern is just misplaced anger because some users misunderstand what this means for OpenWRT going forward, but I hope they'll be in the minority.
> The OpenWrt project does not pay its developers,
This is actually surprising to me, but I guess the donation money isn't enough to pay developers. Would the surplus if infrastructure costs are covered go to developers or is it all going to a rainy day fund?
Prolific devs could setup a Patreon/Librepay if they'd like, but that opens up its own can of worms like false expectations/entitlement of some donators. They might prefer not to do that for that reason alone.
(1) https://www.buffalotech.com/products/airstation-highpower-n3...
I have one of these myself, they're handy devices, but I wouldn't go and recommend them as good OpenWRT devices.
It is also the platform I personally use for OpenWRT development work.
I'd expect it to be some mass-produced cheap router.
Since the demise of Soekris and PC Engines, I don't know of good alternatives. I'd like to be excited about newer ARM-based, power sipping routers- but which ones aren't so cheaply made? The aformentioned companies hit that sweet spot- a 2-3x cost premium for industrial quality and an open approach. They were devoted to hardware and wasted no energy on branded forks of OpenWRT.
I'm curious to try some Teltonika products like the RUT series. They seem sparsely documented on the OpenWRT wiki, though.
Curious to hear any Soekris/PC Engines fans experience with newer stuff.
For instance, I can imagine them holding all specs constant except that they ship a new wifi radio every 2-3 years.
This would allow other open source projects to target it and be rock solid. For instance, my pc engines openbsd router is something like 8 years old and has never crashed.
I’d happily pay a $50-100 premium to get a brand new board that’s fast enough, but that had all the bugs worked out the last few years.
That's the part I'd suggest swapping out every few years. That might mean people are stuck with older bluetooth or a low performance WiFi radio or whatever on the SoC, but that won't impact performance much. (In the worst case, they could just disable the SoC radios to prevent RF interference with the "real" radio.)
https://www.cnx-software.com/2021/10/06/mediatek-unveils-fil...
I'm reasonably sure this line of chips is designed to be the only active radio in an access point:
> Filogic 830 packs a wide variety of features into a compact, ultra-low power 12nm SoC, allowing customers to design differentiated solutions for routers, access points and mesh systems. The SoC integrates four Arm Cortex-A53 processors operating at up to 2GHz per core for up to +18,000 DMIPs processing power, dual 4x4 Wi-Fi 6/6E for up to 6Gbps connectivity, two 2.5 Gigabit Ethernet interfaces and a host of peripheral interfaces. Filogic 830’s built-in hardware acceleration engines for Wi-Fi offloading and networking enable faster and more reliable connectivity. In addition, the chipset also supports MediaTek FastPath™ technology for low latency applications such as gaming and AR/VR.
My reading of that is that the ARMs are there for software defined networking tasks, and not to run the router OS. I could be wrong. However, the OpenWRT spec lists this chip as a network adapter, not as the main SoC.