I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....
Since this thread is about security: Google WiFi. It has secure boot and it auto-updates (although there seem to be few updates released lately).
Security Begins at the Home Router
111–120 of 177 posts
Re: Security Begins at the Home Router
#112Have a DOCSIS3 / DOCSIS3.1 modem that is a dumb L2 bridge. TP-Link makes decent ones that are compatible with Comcast. You can find them and their reviews on Amazon.
Use something like a Ubiquiti ER-X (Edgerouter X) for your WAN-to-LAN interface and NAT. The Ubiquiti EdgeOS is developed by a team of people they hired away from vyattta when vyatta was sold to Brocade. It's a fork of Vyatta with a decent UI on top of it, and full SSH access. Which is of course based on Debian.
Have no wifi functions in your router!!!
And then something like a set of ubiquiti UAP-AC-LITE or UAP-AC-PRO access point(s), as needed. You can set up the ubiquiti unifi controller inside of a debian VM in virtualbox. The controller does not need to run persistently , just once to provision the APs, if you're doing basic WPA2-presharedkey authentication for your home. Bring up the VM again in the future on your laptop if you need to make changes.
This is a pretty low budget but highly effective solution ($65 cablemodem + $48 router + $78 wifi AP).
If you prefer Mikrotik to ubnt, there are a lot of small, similarly sized things you could replace the ER-X with that are in the $45 to $80 price range that will perform similarly.
Re: Security Begins at the Home Router
#113Earlier quoted context omitted.
Solid firmwares like OpenWRT run on a lot of routers already. It should be possible to have some amount of regular updates, if not automatic.
Do you realize that OpenWrt is not very secure and DD-Wrt is even worse?
Re: Security Begins at the Home Router
#114I'd like explore making a small ecosystem of open security plugins built on top of OpenWrt. The goal is to make firewalling and controlling network traffic really easy. The UI should be so easy a parent could perform difficult tasks such as limiting an iot devices traffic to local net or maybe just one ip using just an app. Or detecting unusual patterns of traffic from a device or IP addresses. The apis exist I can't…
It's impenetrable to anyone that doesn't want to invest months into the scene and develop expertise in it. Much like phones we really need a PC equivalent in this space.
Re: Security Begins at the Home Router
#115Just install OPNSense (or its less modern forebear: PFSense). It works great, has a ton of features (e.g. packet filter from FreeBSD, OpenVPN, etc, etc), and it gets security updates. I run mine in a VM, with the WAN adapter passed through to it to make it unavailable to the host.
Second OPNsense. And there are nice fanless x86 mini PCs, router size on aliexpress
Re: Security Begins at the Home Router
#116I'd like explore making a small ecosystem of open security plugins built on top of OpenWrt. The goal is to make firewalling and controlling network traffic really easy. The UI should be so easy a parent could perform difficult tasks such as limiting an iot devices traffic to local net or maybe just one ip using just an app. Or detecting unusual patterns of traffic from a device or IP addresses. The apis exist I can't…
Re: Security Begins at the Home Router
#117Earlier quoted context omitted.
Cox (Orange County) and Verizon Fios (Los Angeles) delivered routers with good-looking, seemingly randomly generated passwords printed on a label. It's been this way with Cox for at least six years.
I have Fios in NYC and the password is also available on the account page on Verizon's website, which I find a bit unsettling.
For that reason alone it’s best to have your own equipment not tied to the ISP, IMO. The ISP can already see all of my plaintext traffic, DNS requests, and MITM all my sessions if they wish. I’d rather not give them full access to my private network on top of that.
Re: Security Begins at the Home Router
#118Earlier quoted context omitted.
You can get the EdgeRouter X for ~$50 and that will scale to symmetric gigabit connections, if your needs are simple (ie. you're just doing basic routing & firewalling, not trying to do traffic shaping, etc). Budget AP option then is a UAP-AC-Lite which you can buy off Amazon for ~$80, bringing your total to $130 all said and done. That's cheaper than most all-in-one routers, and while you won't get the best single-c…
> That's cheaper than most all-in-one routers, It really isn't. There are plenty of consumer router+AP combos in the $75-90 range that offer equal or better performance to the ER-X + UAP-AC-Lite combination.
However, no router in that price point gives you the ability to easily expand past one AP, RADIUS VLAN support, the Unifi web interface and so forth.
My last setup was an ASUS N66 dedicated as the router with an Archer C7 as the WAP. Good performance but the configurability and stability (even with ddwrt on the asus) doesn’t compare to the ubiquiti combo I run now.
Re: Security Begins at the Home Router
#119Earlier quoted context omitted.
> That's cheaper than most all-in-one routers, It really isn't. There are plenty of consumer router+AP combos in the $75-90 range that offer equal or better performance to the ER-X + UAP-AC-Lite combination.
I explicitly mentioned that you could beat single stream performance with high end all-in-one routers. However, no router in that price point gives you the ability to easily expand past one AP, RADIUS VLAN support, the Unifi web interface and so forth. My last setup was an ASUS N66 dedicated as the router with an Archer C7 as the WAP. Good performance but the configurability and stability (even with ddwrt on the asus…
You must be assuming that the user insists on sticking with broken vendor software, instead of switching to OpenWRT. The only software benefit that you don't get just as easily from OpenWRT is centralized management of multiple APs. Adding and configuring APs one at a time is very easy and since home networks never require more than 2-3 APs the lack of centralized management is not a significant issue. RADIUS and VLANs are fully supported by OpenWRT, and the web interface is fine except for the aforementioned limitation that you're only managing one AP at a time.
I suspect your stability issues with the ASUS router were a consequence of you using DD-WRT hobbled by proprietary WiFi drivers, instead of an OpenWRT-supported router. The DD-WRT "project" is a mess compared to OpenWRT, which actually puts out stable releases and operates more like a proper Linux distribution. Third-party firmware distributions aren't all the same.
Re: Security Begins at the Home Router
#120I'd like explore making a small ecosystem of open security plugins built on top of OpenWrt. The goal is to make firewalling and controlling network traffic really easy. The UI should be so easy a parent could perform difficult tasks such as limiting an iot devices traffic to local net or maybe just one ip using just an app. Or detecting unusual patterns of traffic from a device or IP addresses. The apis exist I can't…
The biggest barrier to entry I've found with this stuff is the hardware, I can't walk into a store and buy something with OpenWrt pre installed and for various reasons online isn't a a good option. I've looked at various possibilities and the whole scene is a mess similar to phone ROMs where you have to trawl through random forums, pull down random ROMs, trawl through more forums to find out why x doesn't work in $co…
That's describing pretty much all the alternative firmware distributions, except OpenWRT, which is actually well-organized and delivers real stable releases. If you're digging through forums to find forks and builds made by some anonymous individual, it's almost certainly because you got fooled into buying hardware that requires closed-source drivers. (Or else you bought something that is just too new and not yet supported by OpenWRT.)