back
185 comments
I'm a staunch defender of OpenWRT. Having used just about every "router distro" folks care to name (remember SmoothWall?) for the last 20~ years, OpenWRT is built like a tank and just keeps trundling along

I hope their experiments with the "OpenWRT One" keep going. I'd love to see OpenWRT take a (deserved) bite out of the "SMB firewall vendors" like Netgate or OPNsense. Or just undercutting Wi-Fi vendors like Ubiquiti who base their work on OpenWRT anyway

Something I'm excited to try myself in future is running "OpenWISP" [1] to manage a small fleet (three) OpenWRT devices in parallel for a deployment in a shared workshop. This seems to also be something that OpenWRT could be better at integrating, but it's nice to see "a vendor" tackling it

[1] https://openwisp.org/

Ease of managing multiple OpenWRT devices is still its weakest link. OpenWRT is device centric, but I don't want to managed devices, I want to manage a network.

Modern mesh WiFi systems I've seen do that so well. I know in theory that I could create a VLAN + SSID on my OpenWRT router and APs just for iot devices to only access the internet. But setting that up on a TP-Link mesh was a couple of taps in their app. Doing it on my OpenWRT devices would be quite a bit more hassle.

At home, I built an OPNsense box to evaluate (using Sophos XG135 Rev 3 hardware, along with an OpenWrt nice Netgear WiFi AP on POE), but then went back to a plastic OpenWrt all-in-one box.

OPNsense (and pfSense) are neat, but I personally don't need an IDS/IPS right now, and I like to be able to run the router fanless.

One thing that OpenWrt could use immediately, for basic home WiFi router functionality, is easier ways to add guest-like VLANs from the Luci Web-based admin UI. (I currently have a guest VLAN config that I partly cargo-culted with numerous steps in Luci years ago, largely based on a blog post, and that would be a pain to reconstruct on a new install.)

For techies whose households include non-techies, a little IDS/IPS could help keep some nasty traffic off your home Internet pipe, and I suppose that could now run alongside OpenWrt on some of the more powerful plastic boxes, or on a PC with the right WiFi devices/APs. (In addition to use of VLANs and routing to minimize damage from all the malware-infested devices, and also thinking "zero trust" for the techie stuff you run.)

I definitely believe people underestimate the potential of OpenWRT as an app platform. Before getting sidelined with work I did some proof of concept WebRTC SFU on it https://github.com/atomirex/umbrella which worked surprisingly well.

Was also surprised, then not surprised, to learn it's used as the front end on many of the new generation of 3D printers.

> I hope their experiments with the "OpenWRT One" keep going.

OpenWRT Two is scheduled for late 2025 from GL.iNet and should go for ~$250.

https://news.ycombinator.com/item?id=43512495

OpenWISP states in its docs that you should be running at least 20 devices to make it worth it. [1] So it's not supposed to be a easy way to manage a few devices for home users.

> However, OpenWISP may not be the best fit for very small networks (fewer than 20 devices), organizations lacking IT expertise, or enterprises seeking open-source alternatives solely for cost-saving purposes.

1: https://openwisp.org/faq/#suitable

"Or just undercutting Wi-Fi vendors like Ubiquiti who basse their work on OpenWRT anyway."

Not sure about today, but this company used to sell hardware whose capabilities were IIRC only "fully enabled" if the buyer used the company's closed source OS. An open source OS might work with the hardware but the buyer would not get the same performance.

At the time, the HN comments continuously supported this company. It appeared that for these commmenters, this was a worthwhile sacrifice. They would just keep recommending Ubiquiti. (Unsolicted recommendations)

We once delivered a totally not router box running openwrt, just because it was very simple and bastardising openwrt was easier than yocto.
Related, I used to love going to the monowall website gallery to see all the labgore. It's still there like a time capsule: https://m0n0.ch/wall/gallery.php
I went smallwall after m0n0wall was shutdown. I recall the smallwall & smoothwall maintainers briefly considered joining forces.
>I'd love to see OpenWRT take a (deserved) bite out of the "SMB firewall vendors" like Netgate or OPNsense. Or just undercutting Wi-Fi vendors like Ubiquiti who base their work on OpenWRT anyway

Why? You don't want competition in the space?

>Or just undercutting Wi-Fi vendors like Ubiquiti who base their work on OpenWRT anyway

Huh? The older edgerouters were based on vyatta. The newer ones on a custom linux distro, neither of which are OpenWRT. They hired the original author of pfsense to build them a firewall based on Debian from scratch when they realized vyatta wasn't going to meet their needs. The UDM kernel is very much not OpenWRT

https://github.com/fabianishere/udm-kernel

Being excited about OpenWRT is great but spreading bad information and for reasons I can't fathom hoping for the downfall of other players in the market, not so much.

> vendors like Ubiquiti who base their work on OpenWRT anyway

I thought Ubiquity’s firmwares were all based on Debian. Is this no longer the case?

> I'd love to see OpenWRT take a (deserved) bite out of the "SMB firewall vendors" like Netgate

I'll just leave this here: https://www.netgate.com/blog/pfsense-software-embraces-chang...

OPNsense are unlikely to be able to make this transition, as they can't even reliably work on the FreeBSD kernel.

I hope OpenWrt doesn't turn too commercial (like Netgate or opnsense) because that leads just to subscriptions, enshittification, feature gates, and drama. It is now in a good place as a solid platform to build upon, I hope it stays that way.
OpenWrt is what I use. I picked my routers specifically to be well supported by OpenWrt, immediately wiped whatever the original firmware and installed OpenWrt and that was about ten years ago. Then when I replaced the hardware I also looked for a compatible model with OpenWrt and did the same.

I never had any issue with OpenWrt which I couldn't solve and it just works. Its uptime is pretty much the uptime since when the power goes out due to storms and such.

Same. Been running OpenWrt for years now. I select hardware that runs OpenWrt and never (well, only once, truely) have had to reboot a device due crashing. That old "reboot your router" is just not a thing (touch wood).

I'm sure it helps that all my infrastructure is on a UPS. I've found that even Raspberry Pis can be long-term reliable servers, running ubuntu server and on the UPS.

Another thing that seems to help. I separate function. One box functions only as the router. The wifi boxes only provide wifi endpoints - they do not do routing. And so on.

I have my fibre ont and the wifi router on a cheap battery backup. It has always continued to work even during extended power outages.
What hardware did you go with? I was thinking of getting the second most recent glinet to run openwrt, but haven't convinced myself it's worth it since my current tplink is still pretty new and is just be getting it to tinker (I don't currently even run any vlans or anything fancy)
Seconding all this. Ever since I had weird problems with the vendor firmware on a router, I just pick hardware I can put OpenWrt on right away. Works great.
OpenWRT is such a good os for a router - simple but configurable UI, works reliably, I wish router companies would just ship it by default
But then you get annoying firmware providers like Broadcom who refuse to write OSS drivers for linux and a lot of work is being spent on the reverse engineering
There are some low-cost routers on amazon that do.

also, I think the linksys wrt1900 supported openwrt when it came out. (not perfectly, but they tried)

I love OpenWrt.

But I wished there was something similar but for "big" (in a relative sense) devices. I feel lot of the constraints OpenWrt is based on are not really that applicable when you have hundreds of megabytes of flash and RAM, and that is starting to become a common thing for routers these days. Even their own OpenWrt One router has 256M flash and a full gigabyte of RAM. That is not all that resource constrained anymore. What I would love is to have something that would be closer to "normal" linux distro while getting the networking goodies and ease of configuration from OpenWrt.

I have the opposite complaint. I wish OpenWRT ran on low-resource routers like those really cheap TP-link ones. DD-WRT does support a few of it, and my personal opinion is that it is better optimised than OpenWRT. By the way, you should explore OpenBSD ( https://openbsdrouterguide.net/ ).
Strongly agreed. I'd rather be running a Debian, with systemd, and boring regular utilities, than the bespoke environment openwrt has crafted together.

I'm super glad openwrt exists, and their uci config predates systemd's attempt to build a cohesive consistent whole system configuration pattern & is epic, but given the capabilities of these systems it feels so worthwhile to de-specialize the environment, to make it more boring.

What I really want is Kubernetes oriented tools that can manage hostapd & something like dawn or openert's usteer for band/ap steering. And some other ancillary wifi tools. Maybe maybe a setup for radius/enterprise, instead of just psk. You can do so much more with it, but at its core openwrt is 90% packaging for openwrt. It's not even particularly super well tuned hostapd: theres so much wireless config one can go try & enable that really is just additional 802.11 specs hostapd supports, they may improve your openwrt wifi experience.

I do find it sad/ironic/interesting to note that the router that started it all is no longer supported.

Not to bell the cat, but some sort of symbolic build for the WRT54G(L) should still be possible… right?

Been a fan for a long time and use it on my Archer C7, but I had to disable hardware switching in order to use SQM, and now the switching performance is <200mbps. Having recently upgraded to home fiber, I'm probably going to get a native Unifi router.
I used DD-WRT forever, but holy crap was it buggy. Once I tried OpenWRT, there was no going back. Shit just works, and works well.
I'm a huge fan of OpenWrt. When I got 10 Gbit internet at home I had to replace my old Ubiquiti USG3 on the cheap so I built a router out of a $80 Lenovo ThinkCentre Tiny.

I tried OPNsense and pfSense on advice but they could never crack around 5 Gbps throughput even with a bunch of tweaking, but OpenWrt gave me the full 10 gbps out of the box with no hassles.

I also replaced the Ubiquiti firmware on an EdgeRouter with OpenWrt and it boosted the throughput from around 1.3 Gbps to 1.7 Gbps.

The OpenWrt UI for configuring the firewall is probably one of my favorite firewall UIs of all time. Before OpenWrt I could never wrap my head around those "local" etc ruleset names in more traditional routers, I had to look them up again every time I edited the config. Just being able to say "I have these networks, let this one do this to that one" is very easy to understand.

Openwrt is amazing. I had a wrt54gs, and then latter got a Netgear wgt634u with an astounding USB2 port! Served as a great office shoutcast playing server for the office, a decade before Sonos (for example) existed.

The hardware situation has felt very tenuous for years now. Qualcomm support has felt so so bodged in. It feels perpetually like "this new chipset will finally get us past all the horrible half working hacks of the last barely working chipset" on and on, usually sort of working but only barely. I did finally get my IPQ8074A based router going (rax120) but it took so long, and needs an older wifi firmware (their 2.7) to work. But it feels like maybe slowly it could be getting better, maybe perhaps support will be more mainline less hacked next time.

One very recent example that's lovely to see is Qualcomm starting to mainline their Packet Processing Engine, for the IPQ9574 at least. Link and example hardware below. There have been various forks of openwrt that bundle in cobbled together versions of the software to use hardware offload/accelerators, lots of these. But it's been far from problemfree and are hard to maintain, especially trying to maintain kernel compatibility. https://www.phoronix.com/news/Qualcomm-PPE-Driver-Linux-6.18 https://www.524wifi.com/index.php/embedded-cpu-boards/dual-r... https://forum.openwrt.org/t/ipq806x-nss-build-netgear-r7800-...

It's good to see MediaTek present in openwrt space. One of the only other highly present chipsets available. The price is often quite good for pretty new wifi standard supporting routers. The anec-data I've heard is that driver maturity is not great, but at least there's motion & movement within the kernel, which springs hope eternal.

A lot of companies were built on this.
All my accesspoints and routers run OpenWRT. Love it.

At some point I even ported OpenWRT to my unsupported tplink device. IIRC I hacked together a devicetree and made some small modifications to the tplink loader code.

Funnily enough when I made a PR on github it was basically ignored after I implemented the feedback. I proceed to instead send the patch to the mailinglist and it was merged the same day without comment. That must be some kind of skill filter...

I just started using OpenWrt on Incus via LXC and it works really well. The most difficult part was just learning the config file. It looks like upgrading OpenWrt (esp. on LXC) is the tricky part though so not looking forward to that. I considered moving it to a VM so upgrading it is easier but it runs so smooth on Incus.
Big fan of it. Allows you to create experimental software for OpenWrt, like I did: https://github.com/ro31337/big-internet-button?tab=readme-ov...

> In our hyper-connected world, we've become slaves to the endless scroll. Social media, news, videos - the algorithm-driven content feeds are designed to capture and hold our attention indefinitely. We tell ourselves "just 5 more minutes" but hours disappear. Our brains are being rewired for constant stimulation, making us less capable of deep thought, genuine connection, and meaningful work.

> The Big Internet Button breaks this cycle by introducing friction back into your internet consumption.

Installed it on a TP-Link to replace my ISP router a couple days ago. I'm super impressed with how it needed almost no config (except to manually activate the Wifi and to set a password).

I'd recommend downloading the Material theme for anyone complaining about the barebones look.

Is the router only available on AliExpress?

No EU vendor?

Apparently the firmware is shipped without the GUI (LUCI). And only 900 units have been sold in 10 months. Something fishy is going on.

https://www.reddit.com/r/openwrt/comments/1h0pkbw/openwrt_on...

Unfortunately, they use Busybox under the hood with its plethora of unfixed bugs and security issues and a bug tracker that is almost always down. I cannot trust this project anymore and stopped using systems based on it.
I switched from an ARM version of Openwrt on my Linkstar H68K to a Beelink EQI12 powered Proxmox instance running Openwrt on a VM. Used ChatGPT to debug it and set up multi-wan failover for it. Works excellently.
Fond memories of PirateBox. Actually, fondness is directly proportional to which router I was hacking - Thumbs down for TP-Link - Many thumbs up for the GLI AR150, the sweetest of spots (hugging face emoji)
OpenWRT is really cool. I recently figured out it has an "attended upgrade" feature which makes updating it very easy.
Can anyone recommend a guide on the firewall?
all my routers run TOMATO
Another option (depending on your requirements) is to use normal "workstation" Linux distro like Debian on an regular x86 PC equipped with two NICs. I added an SFP28 dual NIC to an old gaming PC and now use it as a router/home server and can saturate the link (25Gbps). I get north of 4Gbps through Wireguard too. Routing and the firewall are built into the kernel so you don't really need a specific distro. I just added a DNS server (Unbound in recursive mode) and a DHCP server. For WiFi I use hostapd, but an external AP would be a better solution for most people.
Openwrt still has some strange footguns (imo) and the upgrade process is painful. I personally just prefer running general-purpose distros for my routing and firewalling needs. I realize the learning curve for this for someone who just wants a home router is unrealistic though :)

But out of all the router/firewall distros, OpenWRT it is by far the best.

An easy-to-setup OpenWrt-based plugin to sell internet for satoshis: https://tollgate.me/
I've been following OpenWRT for years, and finally made the jump.

This was after using DD-WRT and various flavors of Tomato (especially Shibby and FreshTomato) for two decades on probably ~100 routers in various locations. Some of those locations were business production environments, with the routers providing VPN connecting sites across the continent as a backbone for VOIP telephony, remote user access, etc. (before the likes of Tailscale).

It's an important project and I have a great appreciation for all the work the developers have put into it. But I have to admit, I was underwhelmed. LuCI wasn't as robust as I expected (the "queue all your changes as a batch of commands" approach is a great idea, but its implementation has some rough edges that simply don't work - IIRC, where the UI isn't aware of conflicting config changes you've already queued). And I found in practice getting it to do things that are easy and reliable on FreshTomato, was frustratingly unintuitive, taking more steps than I'd expect, some seeming brittle/error-prone. I'm not averse to scripting, having written short novels of commands for previous OS's, and even custom-compiled binaries (e.g. to install iPerf, before it was bundled with the OS) and a whole custom FreshTomato build that added some admin pages for long-term bandwidth/latency graphing. So I'm open to learning new things, I just felt like I was doing more fighting with the OS than should be necessary.

One small example was configuring a Let's Encrypt certificate. This feels like it should be a near one-click operation. In my case it took a bit of testing and tweaking to get right - I wound up contributing my short solution back to a SuperUser answer: https://superuser.com/a/1904844/75522

Properly disabling IPv6 took more than just a checkbox. I had "No default route present, overriding ra_lifetime to 0!" messages logged, until I added "net.ipv6.conf.all.disable_ipv6=1" to /etc/sysctl.conf.

Maybe I'm just getting snagged by doing things in 'weird' ways. e.g. My inaugural router on it is a MikroTik wAP ac. Turns out you don't get a WAN interface out of the box when flashed on that device, and I had to manually create it. There wasn't really any documentation warning about that, and it took a while before I realized life would go better if I used a lowercase rather than uppercase convention (for better integration with built-in stuff that relies on its existence).

A lingering issue I haven't figured out yet is how to make a reliable "toggle switch" to turn on and off access to the internet for one device on my network (by IP or MAC address). I set up a firewall rule, but wind up having to manually run "/etc/init.d/firewall reload" and "conntrack -D ..." each time to kill any established connections. On FreshTomato it was just a checkbox you turn on/off. If anyone has advice on this I'd be grateful.

One last tip for anyone else using it on a router plugged into a Starlink endpoint that's in bypass mode (i.e. you want to be able to port forward). You'll get messages in syslog every 5 minutes due to short-lived Starlink IP:

  daemon.notice netifd: wan (####): udhcpc: sending renew to server
  daemon.notice netifd: wan (####): udhcpc: lease of ###.###.###.# obtained from ###.###.###.#, lease time 300
You can suppress them by appending "-l 1" (without quotes) to the "procd_set_param command /sbin/netifd" line in /etc/init.d/network, then reboot the router (in my case running "/etc/init.d/network reload" didn't quite do it). On the plus side, the Dynamic DNS package is working well in my setup. (And yes, I understand the implications of using Let's Encrypt on a DDNS IP).

I'm not here to whine, just to suggest that anyone else thinking of making the switch manage your expectations and leave yourself some time to perfect things and get used to the new platform.

What’s new with OpenWrt?
RIP Cucumber Tony.
Couldn’t developers of OpenWRT come up with a better UI?

It’s not user friendly at all.