Because Everyone (Still) Needs a Router
codinghorror.com
codinghorror.com
Avoid any ASUS routers unless you're flashing a new firmware. Awful experience. My last one was the N15. It wouldn't even give out a DHCP lease to two different computers and four different NICs.
And, as for:
"Ever sat in an internet shop, a hotel room or lobby, a local hotspot, and wondered why you can't access your email? Unknown to you, the guy in the next room or at the next table is hogging the internet bandwidth to download the Lord Of The Rings Special Extended Edition in 1080p HDTV format."
Nmap is your friend. Find the offending port and flood it. Since the local connection is always quicker than the Internet connection, it's easy to do. I've done this countless times, and only to those torrenting. At one cafe I use to frequent I would just start scanning whenever this one guy came in. I wonder if he ever developed a negative Pavlovian response to seeing me at the cafe and his torrenting success.
Do I feel guilty about basically DoS? Really, no. If someone tries to take control of a limited resource... shit is going to happen.
I'm assuming you find someone with a high random port open, but I have no idea where to go from there.
How would you go about flooding that connection? Are you relying on a card in passive mode to gather data and replay it? What do you use to replay?
The above combined with the offending computer usually being a Mac and it's named something like "Bob Smith's Computer" is enough to common-sense narrow it down within a minute or two without having to use passive mode.
(Also with the repeat offender I kept his MAC handy.)
Then just initiate as many TCP connections as you can a la Python or whatever is handy.
(of course your mileage may vary with this approach such as when clients are isolated from communicating with each other.)
Or is the idea just to spam multiple connections?
That said ... considering these are Macs, they probably have mDNS open to IPv6 link-local traffic. It might make more sense to flood the offending machine with valid, unicasted mDNS packets. I don't know how well the Apple mDNS daemon copes with high traffic volume, but in my experience Avahi (on an Atom-powered netbook, admittedly) can regularly use over 50% CPU on a wireless network with an oversized local subnet. Hypothetically, deliberately flooding an OS X system with complex but valid mDNS announcements could have interesting results...
I should probably point out that Windows systems tend to be protected from this. Firstly, iTunes or Bonjour must be installed separately. Secondly, Windows Firewall tends to kick in with its "Public" profile, blocking inbound traffic by default. Thirdly, Windows machines tend to use mDNS over IPv4 multicast instead of IPv6 unless an auto-configured external address exists. This further reduces the traffic seen, although this last point is no protection from deliberate floods.
There are Tomato variants that offer per-user bandwidth caps. Check the Toastman build: http://en.wikipedia.org/wiki/Tomato_(firmware)
Good to know, thanks, thought that was what the entire article was about - buy a commodity router (or hardware in general) and flash it with new and better firmware.
Also, check out the reviews on smallnetbuilder etc, they have excellent ratings for these two routers, with the most high recommendations for both.
There's no need to rubbish the whole range of ASUS routers :)
I sometimes use the shared wifi on trains and overhear people who are confused as to why they can view webpages but 1080p video doesn't seem to stream very well.
Does that include a friendly chat with them?
http://news.ycombinator.com/item?id=1160585
What surprised me was the number of responses along the lines of "you don't need this -- just install DD-WRT, OpenWRT, whatever and configure the foo,bar, and baz features as such." I'm likely in the 99th percentile of the US population in my ability to do such a thing, and I still have to spend a bunch of time Googling. Worse yet, I don't have the certainty at the end that I've done it right.
[We do sell this but] We limit the number of offices in a minimum order to 10. This was a hard lesson. We started off dreamy-eyed with onesies and twosies but were rapidly buried under a sea of "and it also has to...".
Pretty much says it all.
Also over here in the UK you get a free wi-fi router when you sign up for broadband from the major providers. No QoS, but auto-updating. Do you not get that where you are? If they do, where's the market? The router shelf space in local stores has already dwindled down to a single dusty shelf from the aisles it used to dominate.
I'm currently on Qwest (formerly anyway, now acquired by CenturyLink) DSL. Qwest provided an excellent modem/wifi router for free, but I have no idea if CenturyLink would do the same now - I kind of suspect the giant teleco would probably provide inferior equipment and/or charge for it.
Hm. I'm kind of amazed leasing a router from TW wasn't written into the contract.
http://www.buffalotech.com/products/wireless/wireless-router...
I'm using the 'stock' DD-WRT firmware on mine, and it handles its duty as a VPN endpoint, a Tunnelbroker endpoint, and does significant QoS'ing without a problem.
http://news.ycombinator.com/item?id=4082351
The part of Tomato I like best is its simple DNS interface that lets you have one hosts file that is shared across all the machines connected to it. This is where I define my local dev domains so that I can test across devices that don't allow local host file changes (namely non-jailbroken iOS devices).
[0] http://www.thekelleys.org.uk/dnsmasq/docs/dnsmasq-man.html
Check out http://wiki.mikrotik.com/wiki/Manual:RouterOS_features if you're interested. You can download the OS and run it in a VM if you want to give it a try before purchasing.
FTA: (...) a combination of commodity hardware and open-source firmware.
It's OK that you suggest RouterOS, I'm just saying OP is not supposed to mention it.
However, I'd argue that the use of open source firmware in this case is a means to an end, since proprietary firmware generally sucks. But since this is an article about how to have a quality Internet connection, rather than how to get started in router OS development, it might be more than suitable for many of his readers.
The feature list is very impressive and on par with professional-grade gear (Cisco etc.). Only downside is that it's not open source, but it's updated about every month or so. [1]
Or I want to have two access points which route traffic between eachother, but also local clients can connect to either one. ap-bridge mode with wireless distribution system (WDS) can do this, but only with WEP encryption since for some reason one of the wireless cards must be in "station" mode for the WPA key exchange to function properly. In station mode the wireless card is not an access point, it is a client only and can not accept the local connections from laptops.
The support is surly and unapologetic. If your bug is fixed, in the next major release you have to pay to upgrade your license, but probably that release has some other bug as well. read the changelogs, the users are the beta testers. mikrotik are accused of being GPL violators as well, openWRT has not been able to support recent hardware. you get what you pay for.
If I had to deploy more wireless networks, I would use the ubiquity access point products, they've come a long way. Maybe I'd still use mikrotik for a router.
I'm not a network engineer, I just want a static IP to be assigned to the router and simple switching on the other ports, but damn if I couldn't figure that out in 15 minutes.
In the end I had other things to do so I put it aside, but be warned that you need to be willing to invest the time to make these work. (or already have a networking background)
With my Verizon FIOS's router, if I try to torrent anything it gets throttled down to less than 10KB/s, and on my old Linksys, attempting to torrent would make browsing the internet nearly impossible.
What I've ended up doing is hooking up the ASUS router via LAN to the FIOS router and connecting all my devices to the ASUS. Every single complain is fixed going this route.
http://www.dd-wrt.com/wiki/index.php/Verizon_FIOS_setup_with...
Bittorrent tends to create several entries in the state-table (since you're typically connected to hundred of seeds/leeches), which are each stored in memory, and uses up CPU resources to setup/maintain/teardown.
So if you were downloading a file via, say, Rapidshare, there'd be probably 1 TCP (you can configure your browser to use more) connection for your router to track, and do the necessary TCP handshakes, acknowledgments, RWIN scaling etc. Multiply all that's necessary for 1 TCP connection by N, where N is the number of peers you're connected to, and the limited resources on a $60 router get used up fast.
Early models of the now-famous Linksys WRT54G could reliably be crashed by torrenting while using stock firmware. A power-cycle was necessary to get it running again. Fun times.
However, all this only applies if you're running the router in NAT mode, which means the router takes the IP address from your ISP, and acts as the endpoint on behalf of your computer. If the router is running in bridged mode, then your computer acts as the endpoint, as much more equipped to handle large numbers of TCP connections.
Edit: Formatting, Grammar.
> Early models of the now-famous Linksys WRT54G could
> reliably be crashed by torrenting while using stock
> firmware. A power-cycle was necessary to get it
> running again. Fun times.
I had an older Linksys model, but it would get into a state where the max bandwidth it would allow would be 32kB/s.There are ways to mitigate that kind of thing. the simplest being keeping upstream bandwidth levels limited to slightly less than your upstream connection speed. Traffic prioritization schemes also exist letting you have some say in the buffer order ( always putting acks, icmp, and ssh first in line for instance ).
Perhaps I should blog about the setup as some point.
If you're outside of the US (I'm guessing, based on the speed of your link), some products are export-restricted. You'd have to check on support for your locale. Another option if you're in a DIY mood is making a custom Linux box using split access features of iptables [3].
[1] http://www.newegg.com/Product/Product.aspx?Item=N82E16833124...
My home router/server is a MicroATX box with an Atom D525, 4GB RAM, 2 x 1TB RAID-1, and 2 x Gigabit NIC. Cost a few hundred dollars to build, draws ~16W idle, and is almost silent. DNS, SSH, FTP, SMB, POP/IMAP, SMTP, QoS, PPTP/OpenVPN/IPsec, and dmcrypt are included. The Atom chip is fine for home use, move up to an Athlon if you're pushing a lot of SSH traffic.
[1] http://www.clearfoundation.com/Software/overview.html [2] http://www.clearcenter.com/support/documentation/clearos_ent...
Then you have to get or guess the configs for both WAN links, possibly with unhelpful residential support techs.
Cisco 2600 class routers are power hungry and loud too, so no win there. Soekris is smaller and more efficient, and runs BSD, so it's awesome in other ways...but it is a pain in the neck to set up. Several hours of prep plus work for your first time.
But if you are most concerned about DNS, I can think of two quick options: put your own router (ideally running Tomato or DD-WRT) behind your existing mess and serve DHCP from there to your network(s), or take DHCP from your provider, but hardcode the DNS settings on each host.
Edit: and Aside: less than a minute after posting this, I decided to check google to see if Soekris supported cable modem cards, and my post (this comment) came up on the first page of results. I had no idea google could turn crawls into results that quickly.
But it appears that Soekris does not support cable modem cards, from a cursory investigation.
Or if you're lucky enough for your provided devices to support real bridge, put both of your devices in dumb mode and plug that as ethernet into your dual-wan device. That's still hardware present but management is kept to the absolute minimum. Plus sometimes you don't really have a choice to use the provided devices...
BTW, do yourself a favor and don't get a Zyxel device.
You just bond the two public facing nics together with ifenslave, setup pppoe and write an iptables script.
Also, IIRC (been a while since I did it), normal bonding only gives you round robbin i.e. your max speed is limited to the bandwidth of whichever external link your connection is forwarded through at the time (unless you use an ISP that can do MLPPP - which is rare). If you want to combine the bandwidth of both connections into one fat virtual pipe, you could get a cheap VPS and then run an Open VPN link over the bonded virtual interface on your linux box at home to the VPS box (I think! I last played with this 4 yrs ago and details are hazy...).
http://www.netgear.com/business/products/security/wired-VPN-...
It's not as sexy as the FOSS solutions on this thread, but it has the advantage of working just by plugging in power and two Ethernet cables.
The older ASUS routers are stuck on Linux 2.4.x permanently in OpenWRT (which DD-WRT and Tomato are derived from) because of proprietary Wifi or Ethernet drivers or firmware blobs and poor CPU support.
I haven't tried either of the Buffalo routers, but my budget ASUS has been rocksolid and works very well.
A word of advice about tomato though, the development has stalled somewhat and led to the continuing development of a number of "modifications"(1) developed by different people, where each goes its own ways (e.g. Shibby, Toastman etc.). They can be found via the sub-forum and continuously add new features, improve existing ones and also fix some bugs etc.
(I am using Toastman's tomato no-usb mod)
I haven't yet taken the time to tweak it to perfection, and unlike Jeff Atwood haven't benched its wireless performace compared to others. While it works well for me, I'd be curious about comparison info.
Since I know this happens reproducibly on two different devices, I am certain it is the software. And unfortunately without QoS the Tomato firmware loses much of its appeal.
Unfortunately this is one of those "unreportable" bugs: there is no way to properly report it, much less have it debugged by original developers.
Can you imagine your electricity or water outlet at home being constrained like bandwidth is? Those issues were solved a century ago, they'll get fixed for bandwidth too within our lifetime.
In any case, I'm not sure if we'll ever have a large enough pipe for everyone; our current pipes are more than enough for our needs five years ago, but our needs grew, and will in the future.
Power has remained relatively constant at about 1.3MWh per capita. In the last thirty years, it has grown only 300KWh.
Internet bandwidth, on the other hand, went from 9.6-14.4kbit/s modems in fax machines in the 80s to 28.8-56.6kbit/s modems in the 90s to the megabit/s range in the 00s to the 15-100Mbps you can get in a residence today.
If the bandwidth issue is to get solved, the growth in consumption will need to peak.
And you're right - it's estimated to have dropped 13-15% in the past 30 years.
http://www.awwa.org/files/Resources/Waterwiser/JAW0211rockaw...
More relevant to the point though, would be to compare it with the growth in internet usage a decade or two from now: as technologies mature it would would seem reasonable to expect that the growth tails off and QoS on the internet last mile will become just as useful as QoS on water pipes.
I've been running Tomato and Tomato USB with QoS enabled for 4+ years. Routers were usually WRT54G or compatible Asus models installed into multiple homes or SOHO businesses. Tomato has been rock solid for me over that time period. Uptime was months or years depending on how often the router was moved or power went out.
However I have had a few issues with Tomato USB, which is a 3rd party fork. Switching back to original Tomato fixed my problems.
All I'm gaining by reading the article is some knowledge on some consumer electronics that will probably no longer be valid in a couple weeks, which IMO is not HN-material. These types of articles are best served by Google results when I'm actually looking for a new router, not on my HN feed.
What's next, "how to build a computer?"
https://forum.openwrt.org/viewtopic.php?id=37069
By the way, I think most TP-Link products are using an Atheros chipset. Very affordable and really well supported by OpenWrt.
Also, I don't know if SpeedMod has been merged back into mainline Tomato or not, but it's worked flawlessly on my WRT54GL for almost a year now.
I completely agree with Jeff's conclusion as well - commodity hardware + FOSS = potentially unbeatable. FOSS that has had a chance to literally evolve on the same platform for almost a decade, assuming it hasn't been abandoned, can really demonstrate the power of software evolution, for lack of better term.
1. http://www.newegg.com/Product/Product.aspx?Item=N82E16833124...
2. http://www.amazon.com/Cisco-Linksys-WRT54GL-Wireless-G-Broad...
3. http://touristinparadise.blogspot.com/2008/04/linksys-wrt54g...
I'm using the MultiSSID functionality (so I have my home wireless network, and a heavily throttled guest network), QoS (basically what Jeff wrote about), VPN (so I can be assured of a secure connection while on the road, and have effective LAN access via TAP), as well as all the standard stuff. It tickles me a bit that I'm getting a featureset for $80 that you'd have to pay several hundred for to get it out of the box.
Pros:
- Hard to brick, easy to revert an f'ed up flash
- 5-6mo uptimes (most stable consumer router I've owned at least)
- Tracks network usage, attractive graphs
- Easy to add local DNS entries for your systems
- Improves DNS performance with a transparent DNS proxy (dnsmasq) (e.g. you can have it query all servers at once, and return record from the first server to respond)
- Easy to use port forwarding rules
- Attach a USB HD to it to act as a NAS (smb/ftp/dlna, nfs possible with unfsd)
- Setup a full pxeboot enviroment with it, including a shared nfs root!
- Run tcpdump to troubleshoot network issues!
- Runs most openwrt packages
Cons:
- Sensitive to heat (90f days will cause it to crash, only reason I've had to reboot it though)
- Doesn't always mount my USB thumb drive at boot (poor USB connection?)
- Not fast enough to stream 1024p HD over wifi
- Limited internal flash, I store my utils (e.g. tcpdump, nmap) on my USB thumb drive
- TomatoUSB doesn't appear to be maintained anymore :(
I recently switched to Toastman (http://www.linksysinfo.org/index.php?threads/toastman-releas...) which: is based on TomatoUSB; has better QoS rules; and is updated more frequently. I currently use it on a RT-N16 and a WRT54G.
Free (a ISP) started in 2002. It's a home-made modem router, who also does TV and Phone. Since that almost all others French ISP have created their *box (Livebox, BBox, AliceBox, Neufbox, …).
I hadn't heard the term QoS until today.
It looks like Airports lack it: http://forums.macrumors.com/showthread.php?t=1115580
Which is sad. We've got 5-10 devices connected at any one time and have had really terrible problems in terms of getting a consistently fast connection.
It seems like my internet connection has gotten worse over the past 4 years living in San Francisco and it's hard to pinpoint the cause because of the lack of innovation in routers. It would be nice to see someone come out with something really innovative here that shows easily what type of traffic you are getting and what is causing slowdowns.
I ended up chosing dd-wrt. I had some security concerns (such a technical forum stores passwords in plain text!! Does this imply anything the security of the project?) which I voiced on their forum.
Their responses shocked me: http://www.dd-wrt.com/phpBB2/viewtopic.php?p=681593
I'm probably not going to install dd-wrt.
Some people share their LANs with more disruptive users than others, so QoS on that LAN can be useful. But the article was not clear at all.
The routers can enable WRED to mitigate some congestion problems, though it is not the silver bullet and works on a per-flow basis. Some new solutions to solve the buffer bloat problems is to install the experimental CeroWRT firmware in your routers (http://www.bufferbloat.net/projects/cerowrt), however, this is also a work in progress.
But what I dont understand is why hardware manufactures go out of there way to prevent external software from being installed.
Point is that I want to avoid adding yet another box to my home -- especially if the box is plastic rather than metal and requires its own external AC adapter like the first of the OP's buying recommendations does.
I'd like to be able to configure a VPN at the router, and not have to think about whether the software is compatible with, installed in and used by all the software on my devices. Any suggestions?
I got fed up of all that and decided to do something about it. Routers have 8, 16mb of RAM? My worst computer that's lying around has 256mb. Slap another ethernet card in, install iptables, it's one day's work tops and your router will never crash and never forget anything again. My personal best is 7,000 torrents all going at once with the internet still being fairly usable.
A future project I have in mind is to do the same thing but with ultra low power components, e.g. Intel Atom or something along those lines. I aim to get under 10W draw from the wall.
- Limit dw/up by ip/mac
- QoS
- VPN (with Open VPN)
- Web sniffer (i can see url history)
and much more...
[1]: http://en.wikipedia.org/wiki/Tomato_(firmware)#Feature_compa...
For example, if you read the datasheets of the internal components of the DLink DIR300, you can notice that by setting a few registers here and there you can achieve 802.1Q VLAN Tagging on the device's 4 port switch.
Very fun times.
Installed OpenWRT, no bug. Posted on their (the company, ubiquity) forum, reply is "we don't support that and if you install it, you're on your own, we won't fix bugs!"
Oh the irony. Whoever wrote that probably didn't even realize what he just did.
Now to find the best place to buy one of these Asus routers in Australia...
Check http://en.wikipedia.org/wiki/Tomato_(firmware) for a nice matrix.
These patches were specific to the ar71xx hardware and unneeded on most other devices.
Given that core components of what we were trying to do (BQL and the codel and fq_codel qdiscs) have only just landed in the mainline linux kernels, doing comprehensive benchmarks would have been misleading.
Secondly - cerowrt's intent is a research project - everything that works we try to get into openwrt - so while the qos implementations differ, both are using fq_codel now.
It's my hope that tomato and gargoyle and dd-wrt - indeed as many router distros - adopt fq_codel or something like it as their underlying qdisc.
http://queue.acm.org/detail.cfm?id=2209336
thirdly - for the kinds of things we are trying to fix (bufferbloat, mesh networks, dns, ipv6) not a lot of good benchmarks exist.
http://www.teklibre.com/~d/bloat/pfifo_fast_vs_sfq_qfq_log.p...
openwrt is very open and community-like (with actual VCS, package building scripts, package manager, and so on), easy to tinker and so on. But there's no neat and simple UI. Command line or uhm, "half decent UIs that u have to install and setup"
tomato has a very good UI, is open source, but isn't really all that easy to tinker with (none of the openwrt niceties)
I generally go with openwrt because, i like command line anyway, and i like being able to make my router do absolutely everything. for example, patching my openvpn and installing the package took 5min with openwrt.
Basically, if you're not into tinkering i'd just go with tomato. If you are, i'd go with openwrt. If somehow tomato doesn't work for you, dd-wrt.
Does the support of devices (e.g. different chips) affect the choice of which one to use?