Live data from Hacker News

MikroTik RouterOS v7 stable released

mikrotik.com

141–150 of 188 posts

Re: MikroTik RouterOS v7 stable released

#142
post #76

Earlier quoted context omitted.

Thanks for that, it is what I figured. I have a really old, nice, router running one of the WRT-like OSes and I really, really don't want to do that anymore. I have a small family and do not want to mess with this stuff. I might just bite the bullet and hook up a few more of the Google routers. I hate using Google, and don't trust them, but I probably trust them more than most other brands in this space. Also, I can'…

Yeah, I've been frustrated with the router space for a while recently so I figured you might benefit from my research (and likely bias as well). Too bad others in this thread downvoted me without responding, though -- if anybody can recommend a decent answer to this question that I didn't cover or explain why I'm wrong, I'm happy to admit that. I would really like there to be a decent router out there for my use case…

I think the reason why you got downvoted is because you made broad sweeping statements without anything to back it up. It also does not reflect my experience, the amount of routers running open source systems that one can buy is much larger than it has ever been (I pointed out some options further up the thread), ASUS uses dd-wrt IIRC and others. Also the openwrt/pfsense/opnsense solutions are not really slower than commercial offerings, many offerings now are capable of running OpenVPN at reasonable speeds, in particular if your CPU has AES-NI support.

The way it was written your statement sounded like a Apple shill really.

Re: MikroTik RouterOS v7 stable released

#143
post #132
post #127

Earlier quoted context omitted.

I'm currently in the process of moving my home network from Ubiquiti to an open solution with a few Mikrotik RBM11Gs to serve as APs, and will probably also replace my Netgate SG-3100 with pfSense with likely a PC Engines machine. All will probably be running OpenWrt, though if that's too limiting / buggy, I'll just use plain Linux or OpenBSD on them. The major benefit of this setup is that you don't depend on some m…

I've been considering replacing my EdgeRouter with a pfsense box (probably the Netgate 6100), have you been dissatisfied with your Netgate?

Unless something radical has changed in the last half year or so, pfSense will be a giant PITA if you have "residential" IPv6. That is, anything but a completely static prefix.

Re: MikroTik RouterOS v7 stable released

#144
post #132
post #127

Earlier quoted context omitted.

I'm currently in the process of moving my home network from Ubiquiti to an open solution with a few Mikrotik RBM11Gs to serve as APs, and will probably also replace my Netgate SG-3100 with pfSense with likely a PC Engines machine. All will probably be running OpenWrt, though if that's too limiting / buggy, I'll just use plain Linux or OpenBSD on them. The major benefit of this setup is that you don't depend on some m…

I've been considering replacing my EdgeRouter with a pfsense box (probably the Netgate 6100), have you been dissatisfied with your Netgate?

I also have an EdgeRouter, but will probably replace that last since it works fine and doesn't require any of the Ubiquiti Controller / Cloud shenanigans.

I've had intermittent LAN dropouts on the SG3100 that I couldn't explain from the logs. That in addition to Netgate's hostility towards open source with how they're handling pfSense, and the whole pfSense+ product, just puts a bad taste in my mouth when it comes to supporting the company. For the hardware and software stack they provide, the devices are very overpriced IMO. Same with Ubiquiti, though at least with Ubiquiti you're paying for a set-it-and-forget-it network, as long as you're willing to fully invest in their ecosystem. They're the Apple of network prosumer equipment.

But my main interest in abandoning both is investing in devices that I can upgrade and maintain independently and at my own pace. It will also be cheaper in the long run, though it does require some tinkering to setup.

Re: MikroTik RouterOS v7 stable released

#145

Earlier quoted context omitted.

yes. but more importantly, they are extremely popular - big ecosystem of freelancers. you can go on fiverr and upwork and get someone to remotely configure/manage it for you.

Curious, would you trust someone to do that? For me when it comes to network, my paranoia level is sky high. I would definitely not allow some random person to configure my network...

It's no different than devops.

I'm not quite sure what you mean here. Everyone from banks to small shops use IT configuration services.

Most people will supply you a resume, contact details and sign a NDA. That's quite good enough.

Re: MikroTik RouterOS v7 stable released

#146
post #27

So, what's the best wifi gateway with extra access points for a home that I don't have to screw with and doesn't spy on me or have cloud crap? My ISP sent a Google wifi thing but I'd rather pay a few hundred than use that for 10 bucks a month to rent that thing, and I don't trust Google. Edit: Thanks for all the answers, from me and anyone else who was looking! I have some good ideas from the below comments and hopef…

I heard good things about PCengines APU products (e.g. see here https://teklager.se/en/products/routers/apu3d4-open-source-r... I'm not affiliated). You essentially run openwrt or pfsense on your own hardware. Alternatively, many people are now putting pfsense/opnsense on their own hardware. In particular thin-clients are very capable and some can be easily be retrofitted with multiple ethernet ports (however, prices…

> The one thing you need to be careful with is wifi hardware compatibility.

I'd suggest using old consumer routers as access points.

Re: MikroTik RouterOS v7 stable released

#147
post #27

So, what's the best wifi gateway with extra access points for a home that I don't have to screw with and doesn't spy on me or have cloud crap? My ISP sent a Google wifi thing but I'd rather pay a few hundred than use that for 10 bucks a month to rent that thing, and I don't trust Google. Edit: Thanks for all the answers, from me and anyone else who was looking! I have some good ideas from the below comments and hopef…

Hot take: All routers completely suck right now, and most of them are built to spy on your network at worst and accidentally expose you to cyberattacks at best. There are two choices, the way I see it: 1. Invest in a decent router (probably $150-200 at least) and throw openwrt on it. You'll need something with serious CPU beef because openwrt relies more on software than hardware, and most routers use hardware for Qo…

> 1. Invest in a decent router (probably $150-200 at least) and throw openwrt on it. You'll need something with serious CPU beef because openwrt relies more on software than hardware, and most routers use hardware for QoS etc., hence the price tag. You'll also need to actually understand the multitude of settings offered by openwrt if you care at all about security or performance -- this is nontrivial if you aren't already a network engineer.

Why not OPNsense on an old x86 box?

> but that's likely to get you punched by your flatmates when it inevitably reboots incorrectly during a power outage or overheats or whatever and suddenly you need to spend 2 hours debugging problems without a working wireless connection and everyone else is pissed they can't use the internet.

I thought for a couple of years that my OPNsense setup would pass the Family Acceptance Factor, but one day (a few months back!) it spontaneously wiped itself of its settings — requiring me to plug in a monitor, reconfigure it to boot, and restore my settings from a backup.

My (very annoyed) family had to ask why we had to jump through hoops, and not use a simple consumer router like everyone else.

I'd imagine that OpenWrt would be the same, or worse.

Re: MikroTik RouterOS v7 stable released

#148
post #54

I've been thinking about going with Mikrotik at least twice but never pulled the trigger because I am sort of a chicken shit. Is it easy for a noob to setup things like port forwarding and vlans on a router/ap box?

Nope, it's really not for noobs. Basics things you can get via click on other SoHo routers like sane default firewall configuration, NAT loopback or simple VPN setup do not exist here. Setting up a Mikrotik is more akin to setting up a DSL connection on 1992 Linux - it's all "technically" available in the UI, but the UI is just a clickable version of all the CLI complexity and you need to know network terminology to…

But once you know that you need a NAT loopback, you can quickly follow instructions on internet to create that rule.

Re: MikroTik RouterOS v7 stable released

#149
post #27

So, what's the best wifi gateway with extra access points for a home that I don't have to screw with and doesn't spy on me or have cloud crap? My ISP sent a Google wifi thing but I'd rather pay a few hundred than use that for 10 bucks a month to rent that thing, and I don't trust Google. Edit: Thanks for all the answers, from me and anyone else who was looking! I have some good ideas from the below comments and hopef…

Ubiquiti amplifi hd. I use the mesh stuff.

Re: MikroTik RouterOS v7 stable released

#150
post #127
post #27

So, what's the best wifi gateway with extra access points for a home that I don't have to screw with and doesn't spy on me or have cloud crap? My ISP sent a Google wifi thing but I'd rather pay a few hundred than use that for 10 bucks a month to rent that thing, and I don't trust Google. Edit: Thanks for all the answers, from me and anyone else who was looking! I have some good ideas from the below comments and hopef…

I'm currently in the process of moving my home network from Ubiquiti to an open solution with a few Mikrotik RBM11Gs to serve as APs, and will probably also replace my Netgate SG-3100 with pfSense with likely a PC Engines machine. All will probably be running OpenWrt, though if that's too limiting / buggy, I'll just use plain Linux or OpenBSD on them. The major benefit of this setup is that you don't depend on some m…

Have you ever looked at VyOS (https://vyos.io/)? IIRC EdgeOS was a fork of Vyatta and Vyatta became VyOS. Their LTS pricing doesn't work for small businesses, but the rolling release might be an option for home use.

It's sad that everyone only wants to accept huge amounts of cash these days. Take VyOS as an example. The smallest licensing option they have is $6k per year for unlimited installs. That makes it completely unobtainable for a person that I build firewalls for, so we don't even evaluate it.

In terms of percentages, we could probably add about 15% to every firewall sold and that could be passed along to a software vendor. If we had a self serve portal where we could download LTS releases and generate lifetime licenses we'd send them 15% of our firewall (sales) revenue and they'd basically never hear from us.

In real numbers that would be about $1-1.5k a year as long as we could pay per device as we sell/install them. Using pfSense as an example it'd be in the range of $10k since we started using pfSense and, in the last 5 years, I think I've only had 1 issue I couldn't figure out on my own where I had to go ask on their forum.

Post reply on HN