Live data from Hacker News

HomeLab #1: MikroTik as a Home Router

justsomebody.dev

111–120 of 151 posts

Re: HomeLab #1: MikroTik as a Home Router

#111
post #75
post #3

For me, the era of MikroTik is sort of... now. Don't get me wrong, they make powerful and feature-complete stuff, but their UI sort of assumes you really know what you're doing. I don't know what I'm doing. But my LLM does. I've been able to set up site-to-site VPNs with Mikrotik in fifteen minutes now, rather than the day-long exercise of googling and praying.

Related they let you download the entire documentation in an LLM friendly format. https://manual.mikrotik.com/llms-full.txt Their front page documentation specifically mentions it: https://manual.mikrotik.com/docs/introduction#machine-readab...

> LLM friendly format

Is that not just markdown? is there a specific way of formatting docs that's "friendly" to LLMs now?

Re: HomeLab #1: MikroTik as a Home Router

#112

MikroTik is a nightmare from what I have heard, companies who invested hundreds of thousands of dollars cannot wait for the contract to expire to replace everything. For homelab, you are far better served buying a second hand Sophos baremetal/server rack mounted, and installing OPNSense in it. I have a 2nd hand Sophos SG210 Rev3 from eBay, replaced the Celeron CPU with an i7 one, 16GB, new SSD, dual 10G NIC, it had b…

Another option is to just buy some used enterprise mini PC (google project tinyminimicro) with PCIE slot, and use that. Probably lower power consumption than a full rack mounted server, definitely takes much less space (unless you already have the rack).

Re: HomeLab #1: MikroTik as a Home Router

#113
post #75

Earlier quoted context omitted.

Related they let you download the entire documentation in an LLM friendly format. https://manual.mikrotik.com/llms-full.txt Their front page documentation specifically mentions it: https://manual.mikrotik.com/docs/introduction#machine-readab...

> LLM friendly format Is that not just markdown? is there a specific way of formatting docs that's "friendly" to LLMs now?

I did not know about it, but it's actually linked in the LLM friendly doc [1]. Seems like some rules around being able to use parsing tools such as regex, and general formatting.

[1]: https://llmstxt.org/

Re: HomeLab #1: MikroTik as a Home Router

#114
One thing that frustrates me about MikroTik and OpenWRT too, is a lot of things require multiple steps to set up, like adding a port forward with hairpin isn't just one click, adding a VLAN requires adding stuff in like 5+ different places.

I really liked using Opnsense before I switched to Openwrt and I always want to go back, because it was just so much more streamlined and easy to configure from a 'geek but not a network engineer' perspective.

Re: HomeLab #1: MikroTik as a Home Router

#115
I use tp-link everything. I have all of them connected to self-hosted Omada controller in docker. Works like a breeze, including notifications. Used MikroTik before but "the dude" or whatever is called now was hit and miss. Probably you don't need it anymore if get llm to configure it.

Re: HomeLab #1: MikroTik as a Home Router

#116
post #3

For me, the era of MikroTik is sort of... now. Don't get me wrong, they make powerful and feature-complete stuff, but their UI sort of assumes you really know what you're doing. I don't know what I'm doing. But my LLM does. I've been able to set up site-to-site VPNs with Mikrotik in fifteen minutes now, rather than the day-long exercise of googling and praying.

> I don't know what I'm doing.

That's also my problem. My colleague tells me that it's very easy to setup, but he's a network engineer and knows what things are.

Mikrotik seems to operate in an interesting area between high-end home-labing and the SME market. Without preexisting networking knowledge at a certain level, their documentation isn't all that helpful. I'm sure you can learn from the documentation, YouTube videos and trial and error, but if like me you get a few hours once in a while to take down your home network and get it back up it's going to take a while to gain the required knowledge. I really want an addition internet connection so I can play with this stuff.

On the negative, I'd say it's pretty clear that Mikrotik want you do buy training. It feels like some information is withheld by those with the certifications and Mikrotik and the UI isn't helping you much to figure out stuff on your own.

Re: HomeLab #1: MikroTik as a Home Router

#117
post #114

One thing that frustrates me about MikroTik and OpenWRT too, is a lot of things require multiple steps to set up, like adding a port forward with hairpin isn't just one click, adding a VLAN requires adding stuff in like 5+ different places. I really liked using Opnsense before I switched to Openwrt and I always want to go back, because it was just so much more streamlined and easy to configure from a 'geek but not a…

I use a mikrotik at home, and I always get a review from Claude after making config changes.

I actually used to be a network engineer (many decades and career reinventions ago), and I appreciate that Mikrotik exposes all of the layers and connections between them.

But damn if Claude doesn’t always find something I got wrong in the config.

Re: HomeLab #1: MikroTik as a Home Router

#118

Earlier quoted context omitted.

They have an increasingly capable "simple" UI for casual users. It seems like improving it is on their roadmap, as they've been delivering vast improvements in functionality with each major release. Also, shipping winbox on all platforms has been a huge QoL improvement

I configure it by copy pasting the pages to chatgpt and asking questions. Dumb? Maybe but seems to work.

If you use codex or Claude code or similar you can just have it ssh in.

Re: HomeLab #1: MikroTik as a Home Router

#119
post #104
post #7

Switched to Ubiquiti, I'm quite happy except for their lack of a sane MCP.

How is the ipv6 situation these days? I left Ubiquiti 2 years ago because I needed to be able to configure the /56 I got from my isp. The unifi controller was pathetic in what it could do.

I'm new to Ubiquiti routers, but I had no problem dividing the /60 I got from my ISP and assign /64s to VLANs.

You might be interested in https://www.youtube.com/watch?v=KZpJvpm1Ris (title: Does UniFi FINALLY support IPv6 Properly? State of IPv6 with Unifi Network v9). The video is about a year old, but from the looks it's not terribly outdated.

Re: HomeLab #1: MikroTik as a Home Router

#120

Just use linux! Why use someone else's non FOSS, locked down linux, when you could truly own your router? It's a great educational experience I would recommend to anyone interested in networking. Grab debian, grab a system with 2 NICs, make it your router/firewall/gateway.

Bingo. I use Mikrotik for my switches. They were the first I found that had 10Gb uplinks, inexpensively and with low power usage. L2 configuration is janky (like every other switch) but workable. I use both SwOS and ROS, but moving towards ROS for dot1x (unfortunately inescapable to have that functionality on the switch).

But the actual router? That lives on NixOS in a virtual machine on a generic amd64 machine that also runs NixOS. I'd rather design / perfect my config once in terms of iproute2/nftables and know I can swap in any hardware. I've got a full policy routing setup that let's me define for each device what Internet horizon it can see (along with what other local devices it can access).

I also find the sibling comment mentioning routing speed to be funny. I've found that unencrypted gigabit WAN is easily handled by most amd64 computers. 10Gb LAN->LAN hairpin routing seems fine. But the big thing is doing gigabit OpenVPN/wireguard, which off the shelf hardware-accelerated routers just don't really do unless you spend a lot. (coupled with the above policy routing, I can configure things like this particular web browsing VM goes out a data center IP that rotates every day).

Wireless APs are similarly handled by hostapd on NixOS, driving (mostly) Mikrotik MiniPCIe Wifi cards. I don't really need the latest and greatest wifi gen, rather I just need them to work and be as maintenance-free as possible.

Post reply on HN