Say one lives in an apartment in an urban area. What would you suggest as the first security and performance upgrade to a setup that uses the provider's wifi router, hardwired to two separate wifi routers, one for my work and the other for the family stuff?
Literally can't keep my hands off my network. Just ordered a couple of pretty sweet upgrades for the #homelab. Pretty stoked about it. Come to Mama! :)
TP-Link TL-SG3428X-M2 | 24 Port Multi-Gigabit L2+ Managed Switch | 24 x 2.5 Gig Ethernet Ports, 4 x 10 Gig SFP+ Ports | 10 G Bandwidth | Support Omada SDN
https://i.nostr.build/KSsv2pljvj5n4hdh.webp





Note: The TL- name has been dropped with the new models as select Jetstream switches become Omada. It's the same device with a different brand and firmware numbers.
https://community.tp-link.com/en/business/forum/topic/649878
...And
Cable Matters Rackmount or Wall Mount 24-Port Shielded RJ45 Patch Panel with Jack Shutter
https://i.nostr.build/HWVQNKVBrmGuZsST.webp
https://i.nostr.build/fwlwJXWOC2rpcN08.webp
https://i.nostr.build/7Wrj4AQxvLTMOmlp.webp
https://i.nostr.build/omwBzeQ46jMwFjtH.webp
https://i.nostr.build/cEj0vHtFUGwM086R.webp
https://i.nostr.build/LNRABIDePbwAK1RM.webp
https://i.nostr.build/QYFCRmEBp2KFdBo9.webp
#ikitao #tech #networking
Discussion
I recommend a #Protectli Vault Pro VP2420 4x 2.5G with no WiFi module, coreboot pre-installed, running OPNsense (or pfSense; I prefer OPNsense).
It's a great hardware firewall/router for most home and small business networks. You can install an always-on VPN if you like, assign interfaces, silo networks, assign subnets and static IPs, and generally keep your network monitored and secure.
Put your ISP router in bridge mode, then use the Protectli as your firewall/router.
You can run all interfaces off the same LAN network or get more granular with security through isolation...
Example:
• LAN interface could be for your trusted devices like your computer, etc.
• Opt1 could be your NAS or storage (siloed from both networks).
• Opt2 could be your untrusted devices like IoT devices and for friends to connect to when they come over, etc.
You can then use OPNsense to set up rules for how these networks can and cannot interact with each other.
You can also run switches (large and small, managed or unmanaged) and/or WiFi routers (preferably running OpenWRT) in AP mode off of any of the three interfaces.
Why not an arm router with openwrt? Same result can be achieved with less money and resources.
Hardware firewalls running OPNsense on dedicated devices like Protectli offer superior security and advanced routing features. They're built for one job and do it well.
OpenWRT, primarily designed for Wi-Fi routers, provides flexibility but can struggle when tasked with complex firewall and routing functions.
While OpenWRT can be configured to do it all, it's not optimal for advanced security setups, similar to all-in-one ISP solutions that prioritize convenience over security.
Best practice involves separating network functions: use a dedicated hardware firewall/router (like OPNsense) for security and routing, and a separate device running OpenWRT or similar firmware for Wi-Fi.
This approach ensures each component performs its specialized task efficiently, avoiding the compromises inherent in all-in-one solutions.
I gotta do some digging. I just swapped my Unifi Security Gateway for OpnSense and am experiencing random internet drop offs. I can still connect to it via the webUI but can't ping out on the WAN, rebooting fixes it for a few hours/days but I need to figure it out. Are realtek ethernet ports as bad as Reddit makes it sound? According to then it's Intel or nothing...
what do you like about OPnsense over pfSense? I've been using pfSense since 2015. whenever I try to upgrade I always end up going back.
UI is so much better IMO, not to mention the questionable decisions/abuses of trust pfSense has made that has driven users to OPNsense. Both are good. I prefer OPNsense.
Thank you for this, much appreciated. I look forward to making this a weekend project in the very near future.