back
88 comments
If you don't want to do all that configuration, PFSense is a good alternative. https://www.pfsense.org/download/

PFSense is the same thing below the hood, but with a web front-end and plugins.

Most off the shelf wireless routers work fine as an access point, but are quite bad as a router. So you can just plug your old wireless router into this thing (with DHCP etc turned off), and your whole setup will be much better.

I'll echo the pfSense recommendation. One correction, though: pfSense is built upon FreeBSD, not linux.
IPFire is my choice if you prefer Linux.
I've been running pfsense for over 5 years now and never had an issue. And, it's only getting better. I highly recommend it.
I built a lan to wan router where the wan was a wifi link (couldn't run a cable in the building) using pfsense, it works really well.
Nth-ing pfSense. Straight-forward to configure, dead stable. Near-enterprise class features.
Ubiquiti's EdgeRouter Lite is a popular, fast, cheap (<$100), solution in this space.

People are running FreeBSD and Linux on it:

http://www.daemonology.net/blog/2016-01-10-FreeBSD-EdgeRoute...

https://wiki.gentoo.org/wiki/MIPS/ERLite-3

One note is that it's my understanding that running Linux or even FreeBSD will mean that you can't hit 1Mpps if that's important to what you're doing.
The driver for the network offload is proprietary, however the pre-installed OS is Debian Linux with a fork of Vyatta.
Can 2nd that its a very powerful and cheap router that could solve all my needs out of the box. Like routing my tv through a vpn etc.
So you go through all that trouble and end up with a terribly slow NIC, a "grownup" OS to maintain and the shitbox MIPS architecture to boot? What a pain. These MIPS boxes have their place, and that's squarely in the OpenWRT / system builder niche.

With the electricity prices the way they are in the US, no way I'd run something like that over a proper x86 as in the article that can saturate a 1Gbps and manage decent disk IO.

>>a proper x86 as in the article that can saturate a 1Gbps

"x86" covers a lot of ground. Certainly, in the "about $100" range, your choices in X86 land can't saturate 1Gbps either. The x86 box in the article was $280 total. About the same cost as the logical upgrade to the EdgeRouter Lite...their ER-8, which can saturate 1Gbps, and has 8 ports.

Here's a tutorial for doing the same thing with OpenBSD from a few years ago: http://www.bsdnow.tv/tutorials/openbsd-router
The OpenBSD site has an example as well.

http://www.openbsd.org/faq/pf/example1.html

As a point of comparison, the iptables syntax as shown in the Ars article is far harder to grok at first glance than either of the pf examples. For example:

    pass in on egress inet proto tcp from any to (egress) port { 80 443 } rdr-to <ipaddr>
vs:

    -A PREROUTING -p tcp -m tcp -i p4p1 --dport 80 -j DNAT --to-destination <ipaddr>:80
    -A FORWARD -p tcp -d <ipaddr> --dport 80 -j ACCEPT
Yeah, I've always found iptables to be a little hard to understand.

It also sounds like it's getting replaced[0]. My guess is that we will see iptables around for a long time after it's been deprecated. ifconfig, for example, is deprecated[1] yet it's still around and being used.

[0] https://lwn.net/Articles/564095/ [1] https://lists.debian.org/debian-devel/2009/03/msg00780.html

i would say that openbsd is the better tool for the job in my opinion. pf is just much nicer and simpler to set up and configure than linux iptables, and openbsd is hardened which is important for a machine that is always facing the internet.
Another thing that's nice about the BSDs is that they are whole systems, not different sets of kernel+utilities packed up by third parties.

Generally speaking, that means that there's one canonical way to do something instead of a bunch of different ways like in Linux (think 'ifconfig' vs 'ip'). Of course, FreeBSD ships with three different firewalls[0], so that's not always true.

There are downsides, of course. A freshly-installed BSD has a lot less stuff than a freshly-installed OpenSUSE/Ubuntu/Fedora/etc.

[0] https://www.freebsd.org/doc/handbook/firewalls.html

I'm sad they don't use dnsmasq in the article, it's a ton more easier to setup than bind and even commercial routers use it.
Yeah, plus it can also serve as DHCP server, one less package to install/maintain.
I wonder how well the Turris Omnia[1] will compare to a homebrew solution like this.

[1]https://omnia.turris.cz/en/

I cant wait for mine to arrive :)

I like those automatic security updates and network traffic analysis...

I had trouble getting a hold of one of those C1037U boxes from China. The seller would 'run out of stock' frequently if I found one for a decent price.

I ended up going with the APU2B4 board (an upgrade from the APU1D mentioned in the article.) I put pfSense on it, and it's been running perfect for a few weeks now.

Even that board is probably massive overkill for most people. I have 50/50 internet, and with full bandwidth used by torrents, a VPN and ssh session open to the router, and the web interface open, I'm still only getting about 10-15% CPU.

http://pcengines.ch/apu2b4.htm

Looks like the one listed in the article is both out of stock and going for ~$1400 (I'm guessing auto pricing?).

The APU boards are nice too; I thought about going for one when I was shopping for a better router and slapping OpenBSD on it. Ultimately I went with an Ubiquiti ERL, mostly because I didn't really want to buy an RS-232 cable, but the PC Engines boards are probably one of the best fully-DIY options you can get.

Interesting. I have been using such PCs in my Chinese office for about a year. They are made in a factory about 30 minutes from me. I was considering designing a better looking case and bundling a more reliable power supply to export these but I got busy with bigger business.

These Shenzhen factories are somehow getting these Intel CPUs for next to nothing. Factory price for the i5 model was about $100.

Could you please recommend accompanying parts if someone wanted to use that board with pfsense to end up with a home/office wireless router? I was looking for a packaged solution but the official pfsense two port appliance with the wireless option seemed fairly expensive.
Seems to be missing on of the most crucial parts: Keeping the software up to date to avoid being a victim to security issues.
During the "Linux-Setup" part of the article:

""" ...and whether you want automatic security upgrades. (Spoiler: Yes, you do.) """

This is also a nice simple and cheap device running OpenWRT ($25) with Wireless N, 2 100 mbit lan and USB: https://revspace.nl/GL-iNet - http://www.gl-inet.com/.

I've got a about 50 deployed, managing them with Ansible, super nice and cheap. USB powered as well.

If you like that, check out the Nexx WT3020H. Very similar specs but you can get them from China for about $13 USD.

Best of all, they're based around a MediaTek CPU, which doesn't have the same USB quirks as the Atheros AR9330 used in the GL-iNet.

I've personally upgraded my 3020H units from 8MB SPI to 16MB, but I've also heard that you can order them directly from the factory with 16MB if your order is large enough, or they're willing to customize.

At least in my setup, a small SSD means that a complete reboot for the router takes 22-24 seconds, and so TCP sessions will not drop.
Be careful when using a very small SSD or something like a CF card for a router. Enabling logging to disk can wear the flash memory out in a matter of weeks
1400 - 2400 usd for that small box? Is that worth it??
It was $250 before, a lot of sellers on aliexpress just jack the price when they're out of stock instead of delisting the item.
It is almost 4 years since World IPv6 Launch. I’m very disappointed that, other than a few randomly timed rants from Iljitsch van Beijnum, Ars Technica has made no visible movement to IPv6. No AAAA record for Arstechnica.com, no guides to installing IPv6, and now a tutorial for setting up routers spreading FUD about how difficult it is to install IPv6.
I have been running Linux boxes for 20 years as my home router, but just recently bought a Cisco RV325. Sort of got tired of maintaining it, and it took allot more power.

How will these smaller, embedded motherboards handle 1G Ethernet? Will be getting google fiber within next year.

Been using an APU board since they came out and I have a 1Gbps fibre connection. Unfortunately my measured speed comes to about 500/700Mbit but I belive that's due to either shitty equipment in the city wide fibre grid or my own switches/cables. I'm not really a network tech.

Either way the APU handles it fine for a home network and generates no noticeable heat.

Curious if the 120 GB SSD could be doubled as network storage acessible through WiFi?
Yep. Just install the samba/nfs/iscsi/other networking daemon and off you go. About the only thing to keep in mind is that you are going to need to configure the daemon before you use it to ensure that it's not listening on your WAN address, because you probably don't wanna have your files visible to all and sundry.
I'd like to play with Linux on this multi-nic board when I get some time and money http://www.banana-pi.org/r1.html
I use MikroTik for the nice hardware, low power, and RouterOS.
I bought MikroTik for the netflow feature, which can reveal active malware via hardware packet counters by endpoint.[0] The next cheapest router with netflow is in the thousands of dollars. MikroTik is $180 at Amazon.

[0] http://www.irongeek.com/i.php?page=videos/houseccon2015/t302...

Looks like he hasn't hit the ip_conntrack_tcp_be_liberal problem/setting yet. Good luck with streaming Netflix with that router...
Care to explain?
I have a lot of respect for those who know iptables well enough to make things like this. It looks so fascinating, but so complex.
Me too! As others in the thread have mentioned, OpenBSD and pf make for a (IMHO) much easier configuration. Not sure what kind of difference in performance one might expect. I suspect both Linux and OpenBSD are more than capable of keeping up with any traffic one might throw at such a router.
Going back to the first article: it was around $300. But as a project for my home, the lack of wifi is more frustrating.
Wtf. When I open the link or search alibaba, all of these mini computers is listed at $1300+ :S
realistically, what is the best option for adding wireless networking to this or any other setup based on a generic box? i assume one can build an access point with a typical wifi dongle but i am not aware of any of the software means required.
But this article is about building a router, not sure what wifi has to do with it.