Looking for wired network router suggestions

chili_pepper

Acceleratti Incredibilis
Original poster
Supporting Member
Joined
Apr 27, 2023
Messages
6,242
Location
Murrland
I'm interested in upgrading my current network router, looking for some solid suggestions from the more tech-savvy members here.

Basic criteria:
  • table top unit or rack mount (1U) - I like the rack mount idea, cost dependent, functionality is more critical than physical format
  • robust hardware firewall functionality - not interested in nor do I use any shit M$ security software
  • at least 6 wired ethernet ports, preferably 8, more is fine
  • wifi capable, with good range but without needing a repeater - must be fully configurable and easily shut off
  • solid software interface with settings to control everything - not interested in any kind of smartphone app access or control, if that's a thing
  • must have the ability to block access to specific internet addresses, preferably with options for "by device" as well a "global"
  • logging of all traffic in both directions
  • ability to set and schedule access times for specific devices connected

I'm sure there's more but all I can think of at the moment.
 
  • Love
Reactions: Zorba
I'm interested in upgrading my current network router, looking for some solid suggestions from the more tech-savvy members here.

Basic criteria:
  • table top unit or rack mount (1U) - I like the rack mount idea, cost dependent, functionality is more critical than physical format
  • robust hardware firewall functionality - not interested in nor do I use any shit M$ security software
  • at least 6 wired ethernet ports, preferably 8, more is fine
  • wifi capable, with good range but without needing a repeater - must be fully configurable and easily shut off
  • solid software interface with settings to control everything - not interested in any kind of smartphone app access or control, if that's a thing
  • must have the ability to block access to specific internet addresses, preferably with options for "by device" as well a "global"
  • logging of all traffic in both directions
  • ability to set and schedule access times for specific devices connected

I'm sure there's more but all I can think of at the moment.

I'm in for this discussion, as my needs are similar and am tired of AT&T's braindead POS. I want professional level firewall rules, which must include "by domain" blocking.
 
  • Like
Reactions: chili_pepper
I'd think any commercial grade Cisco could do this - but they're PRICEY!

yeah if he wants that’s level of control and security, you want to minimize the blast radius. Edge device FW for IPS/IDS and north/south logging, then a decided LAN device, you could mix with your WiFi but not if you want real logical separation, and then you need something for east / west inspection, control, and logging so that’s potentially another FW device. Logs need to be stored, and then to be meaningful, you need event correlation and alerting.

If you don’t already know what your doing, easy to allow all or spend 50hrs trying to figure out why only 1 function of an app won’t work but every other one does.
 
Ubiquity makes excellent stuff and reasonably priced. I use two of their Amplifi routers. One as the wireless router and the other as a bridge in my pole barn. Then I have a CAT-6 cable between the two buildings for wireless backhaul. It makes a superb mesh network.

You can save some $$$ by adding a powered switch to the router. I have an 8-port on each end. Very cost effective.

For me, it was almost plug 'n play.
 
For some context, I've been dicking around with computer hardware and software for some 4+ decades now, and would consider myself to know enough to be dangerous (though my knowledge of newer OS's is lacking). No formal training, I do not do this in a professional capacity and never have. A bit of a hack, I suppose, but it has worked out for me thus far...

Currently running some flavor of Netgear router and have been for about 8 years now. Not a particular fan of the brand and not necessarily my preferred choice, but it's what I could get at the time and it was the closest to suiting the needs then on short notice. It does alright and actually includes a number of the features in my list above, but the software interface is a bit clunky and feels limited (possibly by design). It is physically limited to four wired connections, which has now become an issue. While I could expand by adding a switch to one of the existing wired ports, I'd rather not go this route. I feel like there should be something better out there.

Are you monitoring your kids internet access or hosting a public server

Neither, but I suppose I'm looking to apply similar logic to the connected machines. I'll do my best to outline and keep it orderly and coherent. May help, may not. Current network devices include:

Workstation #1 - used for "work work", needs internet access only, do not want it to see or access other network devices and vice versa. Aside from the physical power switch, I have little control over this device (I can change the desktop wallpaper! 😀), managed entirely by my employer.

Workstation #2 - new-ish, built by me a little over a year ago, runs Win 11 Pro. Rarely used at the moment, still in the process of killing off all the invasive M$ garbage on this one (what they're doing shouldn't be legal). Learning more about the group policy editor than I ever thought I would....

Workstation #3 - "demoted" about a year ago, still use this one daily and for most of my personal computing and design work, runs Win 8.1 Pro. Have been experiencing "forced obsolescence" through antivirus and browser software lately. Internet access is likely nearing an end for this one as a result. Upgrading the OS is not an option, partly because of the software running on it and partly because Microsoft sucks. No TPM, so no Win 11. Linux is not an option, either. The machine works, I'm not about to throw it way just because some M$ asshat says so.

Workstation #4 - older and less powerful than #3, this machine is in basically the same boat. In limbo at the moment, this one might get some flavor of Linux.

Laptop #1 - runs Win 10 Home (talk about a piece of shit! was purchased this way, preloaded...), handy when working on the vehicles in the garage or needing more portable design computing. Currently have to use this on Wifi only as it will automatically try updating to Win 11 if connected via hardwire - but not enough ports if I wanted to anyway. Suffers similar issues to the previous two running older software.

Laser Printer - currently on WiFi due to aforementioned port availability, has always been a bit glitchy with resolving IP addresses and occasionally needs a boot up it's ass. Assigning a static IP has helped, a wired connection would solve this. Should be accessible to all devices EXCEPT Workstation #1 - could never print properly to it anyway, thanks to my employers use of Citrix.

NAS - wired connection, accessible to all devices EXCEPT Workstation #1

3D Printer - connects via Wifi (in LAN only mode), no provisions for wired connectivity, access is only needed for my primary design computer, currently Workstation #3.

realistically you’re looking at multiple devices

That may be, though would prefer to do in one if possible.


After going over my posted list again, I cleaned it up a little and reordered based on feature importance (1,2 & 3 are tied for 1st)
  1. robust hardware firewall functionality - not interested in nor do I use any shit M$ security software
  2. solid software interface - not interested in any kind of smartphone app access or control, if that's a thing
  3. 6-8 wired Ethernet ports
  4. WiFi capable - must be fully configurable and easily shut off
  5. must have the ability to block access to specific internet addresses, preferably with options for "by device" as well a "global", though I'm fine if the "global" must be achieved with repeated "by device" setups. More than one way to skin a cat, assuming this would be tied to firewall functionality
  6. logging of all traffic in both directions - can be volatile logging, mostly would be used to verify that implemented controls are working
  7. ability to set and schedule access times for specific devices connected - or I can just power those devices down or pull the Ethernet cable...
  8. physical format - table top unit or rack mount (1U) - I like the rack mount idea but functionality is more critical than physical format
 
Last edited:
  • Like
Reactions: Zorba
For some context, I've been dicking around with computer hardware and software for some 4+ decades now, and would consider myself to know enough to be dangerous (though my knowledge of newer OS's is lacking). No formal training, I do not do this in a professional capacity and never have. A bit of a hack, I suppose, but it has worked out for me thus far...

Currently running some flavor of Netgear router and have been for about 8 years now. Not a particular fan of the brand and not necessarily my preferred choice, but it's what I could get at the time and it was the closest to suiting the needs then on short notice. It does alright and actually includes a number of the features in my list above, but the software interface is a bit clunky and feels limited (possibly by design). It is physically limited to four wired connections, which has now become an issue. While I could expand by adding a switch to one of the existing wired ports, I'd rather not go this route. I feel like there should be something better out there.



Neither, but I suppose I'm looking to apply similar logic to the connected machines. I'll do my best to outline and keep it orderly and coherent. May help, may not. Current network devices include:

Workstation #1 - used for "work work", needs internet access only, do not want it to see or access other network devices and vice versa. Aside from the physical power switch, I have little control over this device (I can change the desktop wallpaper! 😀), managed entirely by my employer.

Workstation #2 - new-ish, built by me a little over a year ago, runs Win 11 Pro. Rarely used at the moment, still in the process of killing off all the invasive M$ garbage on this one (what they're doing shouldn't be legal). Learning more about the group policy editor than I ever thought I would....

Workstation #3 - "demoted" about a year ago, still use this one daily and for most of my personal computing and design work, runs Win 8.1 Pro. Have been experiencing "forced obsolescence" through antivirus and browser software lately. Internet access is likely nearing an end for this one as a result. Upgrading the OS is not an option, partly because of the software running on it and partly because Microsoft sucks. No TPM, so no Win 11. Linux is not an option, either. The machine works, I'm not about to throw it way just because some M$ asshat says so.

Workstation #4 - older and less powerful than #3, this machine is in basically the same boat. In limbo at the moment, this one might get some flavor of Linux.

Laptop #1 - runs Win 10 Home (talk about a piece of shit! was purchased this way, preloaded...), handy when working on the vehicles in the garage or needing more portable design computing. Currently have to use this on Wifi only as it will automatically try updating to Win 11 if connected via hardwire - but not enough ports if I wanted to anyway. Suffers similar issues to the previous two running older software.

Laser Printer - currently on WiFi due to aforementioned port availability, has always been a bit glitchy with resolving IP addresses and occasionally needs a boot up it's ass. Assigning a static IP has helped, a wired connection would solve this. Should be accessible to all devices EXCEPT Workstation #1 - could never print properly to it anyway, thanks to my employers use of Citrix.

NAS - wired connection, accessible to all devices EXCEPT Workstation #1

3D Printer - connects via Wifi (in LAN only mode), no provisions for wired connectivity, access is only needed for my primary design computer, currently Workstation #3.



That may be, though would prefer to do in one if possible.


After going over my posted list again, I cleaned it up a little and reordered based on feature importance (1,2 & 3 are tied for 1st)
  1. robust hardware firewall functionality - not interested in nor do I use any shit M$ security software
  2. solid software interface - not interested in any kind of smartphone app access or control, if that's a thing
  3. 6-8 wired Ethernet ports
  4. WiFi capable - must be fully configurable and easily shut off
  5. must have the ability to block access to specific internet addresses, preferably with options for "by device" as well a "global", though I'm fine if the "global" must be achieved with repeated "by device" setups. More than one way to skin a cat, assuming this would be tied to firewall functionality
  6. logging of all traffic in both directions - can be volatile logging, mostly would be used to verify that implemented controls are working
  7. ability to set and schedule access times for specific devices connected - or I can just power those devices down or pull the Ethernet cable...
  8. physical format - table top unit or rack mount (1U) - I like the rack mount idea but functionality is more critical than physical format

That’s much more clear.

VLANs would give you the logical separation you want from your work computer, as well as keeping devices like your NAS off internet accessible network segments.

I focus more on the enterprise side, but PFSense, OpenWRT and ubiquity are generally well regarded in the consumer space, non subscription, and no crap app.
 
That’s much more clear.

Rather than dump all that initially, figured I'd dip a toe and see what came out in the replies. Plus I had to sit for a bit and write it out, which actually helped with the focus.

VLANs would give you the logical separation you want from your work computer, as well as keeping devices like your NAS off internet accessible network segments.

I focus more on the enterprise side, but PFSense, OpenWRT and ubiquity are generally well regarded in the consumer space, non subscription, and no crap app.

Sounds like I've got more homework to do. This isn't a necessarily time-sensitive decision, I've got time to figure things out, but I'd like to do it right and have something that will work for me into the future. I suppose the ultimate goal is taking back and keeping as much control as possible. I don't particularly care for the view companies like M$ have regarding the future of personal computing. I might not be able to stop an internet of things, but I guess I'd like to decide what things of mine, if any, are part of it, and who ultimately controls them.

Appreciate you offering up some reputable names, I honestly don't know when doing research other than I don't recognize any of them anymore.

non subscription, and no crap app.

Definitely what I'm looking for. (y)
 
  • Like
Reactions: red02tj
Any network performance penalty with this?

Nope, it’s layer 2 logical separation, been used for 20+ years in networking. Let’s you prevent network segments from communicating, it’s the “logical” vs physical approach to running dedicated hardware.

However there is management overhead, since you’ve now separated your networks, you need to plan for DNS/DHCP and other supporting services.


Unless this is a tinkering is fun project, you might be better off with

1 put your work computer on the guest WiFi. Most guest networks by default (easy to confirm with your router) block communication to other guest devices and back to your main network

2 RaspberryPi / Pihole DNS. This is the biggest leak for your ISP seeing what your do, it also gives you per domain blocking, it’s well community supported with curated DNS lists to block or allow content.

https://pi-hole.net/


2b - I had the above but it doesn’t solve for when your not at home, so ultimately I went with controld, it’s subscription (4$) a month but I got tired of managing more hardware and services.

Work computer on the guest network + Pihole should get you 80% of the way.
 
Last edited:
put your work computer on the guest WiFi

I'm afraid I can't do this one, it's wired and I have no say in the hardware they send me to use (wish I did, need more horsepower!).

Lately, they've been sending us these tiny, weakly appointed workstations. I assume their thinking is that, since everyone is essentially working directly off the corporate network via virtual machines (through the Citrix conduit), a minimal system is all that's needed. While that might work for most office employees, our design software requires serious graphics horsepower, something that doesn't translate so well with this configuration. Some days, it's downright painful to work, I just remind myself that I'm fortunate to work from home and I'm also paid by the hour... 😀
 
I can attest to PiHole's efficacy. Its not quite the same as a firewall, but it does stop a metric shit ton of crap. That's why Facefuck, TWITter, dreads, snapcat, whatsup, and maybe even soon to be Google are off my network, off my computers, and out of my life.

Don't knock your self-taught knowledge. My training was in microprocessor hardware, and a bit of software. Learned writing software on the job, and earned my living at it for about a decade. As I didn't have much networking knowledge, it took me awhile but I finally broke into IT. Six months after I started, my boss officially changed the job description of my position as I was able to do things that the IT guys were not (and vice versa). Just remember that its just software running on a Vonn Neumann machine - although I actually have a bit of experience with an early Harvard architecture as well. If you remember that Microsoft is a group of fools, and Apple is a group of idiots, you'll do fine as you'll be pissed off at both of them.

I know enough networking to be dangerous to myself. @red02tj 's advice about using a VLAN is spot on. I took a class in networking, learning all about the various discovery protocols. I told my boss, "You know that Internet thing? There's no way in Hell that will ever work!". He laughed, what a class-A kludge... I had some experience with ARCNet, a token ring setup which always made more sense to me than the collision avoidance of Ethernet - but I'm hardly an expert on the subject.

And good on you for insisting on hardware with a real interface, not PHOOOOOONNE bullshit. There is all too much PHOOOOOONNE bullshit in Wi-Fi routers and similar, I just can't see it with a decent firewall. If you get to anything by TP-Link, check it carefully. Most of their stuff is unavoidably "App" based. Why would anyone want to manage a damn network with a crippled smartphone is beyond me...
 
  • Like
Reactions: red02tj
I...our design software requires serious graphics horsepower, something that doesn't translate so well with this configuration. Some days, it's downright painful to work, I just remind myself that I'm fortunate to work from home and I'm also paid by the hour... 😀
Don't they make allowances for job function? We had a "standard" workstation configuration that most people were more than fine with - but you can rest assured that our SolidWorks people and other power users got something a bit more hefty. We had two levels of SolidWorks workstations, what I called "SolidWorks lite", for working with a part or two, and the heavy users who would load an entire large design in the thing - then rotate it. That was a $12K to $15K machine which got replaced every 3 years.

I once got a call from a "SolidWorks lite" user whose office mate had left the organization. He wanted to know if he could take over the ex's laptop as it would run SolidWorks better. "Shouldn't be a problem, but let me look...". The laptop in question was 8 or 9 years old, and nothing special. The employee's workstation was even older than that, and nothing special. Policy was every 3 years for everyone - needless to say a brand new "SolidWorks lite" workstation appeared on his desk post-haste!

On the other hand, another company I worked for was in the red for 10 or 11 years of the 13.5 that I worked for. So there wasn't any money for upgrades. I had a clone of the original IBM PC - and I had been trying to upgrade it for a couple or three years with what was called a "Baby AT motherboard" - that's what you did with those. Never any money, blah, blah, blah...

Until I was over in our other building, down in the basement talking to "Rich", the IT guy. There was a 6 foot high stack of 8MHZ AT clones in his lab - pretty much state of the art at the time. "Oh, those are nice - who's getting these?" The answer promptly pissed me off, "Bettina, Paulette, Cynthia, etc.".

So - I storm back across the street and into my boss's office. Casually brought up the Baby AT motherboard idea, and got the usual - and expected - answer. "If that's the case, can you tell me why Bettina and Paulette et al are getting BRAND NEW AT CLONES?!?!? I'm doing fucking software development on an antiquated machine and the damn secretaries are getting state of the art workstations!!"

Boss knew the game was up. So he told me to put together a new machine from our own product line (industrial computers, VERY expensive). So I did, I scrounged cards, found some down-rev sheet metal, and a prototype 286 processor card that I used for years as it ran faster than most 386s (when those came out). I scrounged everything except a hard drive. Boss wouldn't sign a stock transaction for the hard drive. I went back into my office absolutely steaming, getting myself worked up to go see the boss's boss and ask him WHAT THE EVERLOVING *FUCK*?

Suddenly, in my door walks the head of purchasing with not 1, not 2, but 3 30 megabyte Fuji hard drives! "Would I like one? How many? All 3? I'll have to charge you." He probably saved my job, I told him I didn't give a shit, gimme all 3 of them! Used those for years too.

Moral of the story: Secretaries ALWAYS get nice machines. Even when I was working IT years later, the secretaries always got nice machines. They weren't SolidWorks workstations, but they were damn nice all the same. And yes, I told my IT boss this story...
 
  • Like
Reactions: chili_pepper
Don't they make allowances for job function?

I like the concept, but that'd be a big old "NO". 😀

Honestly, you'd think it would be part of an assessment when configuring and purchasing equipment company-wide, but it clearly isn't. The one I currently have is literally 1/8 the size of the last, approx. 7" x 7" x 1.5". It runs hot to the touch and, as a bonus, because I work through a Citrix portal, the computer basically sees me as idle (as far as I can tell). At least once every workday (often twice), the built-in Windows antivirus and malware will run system scans, hogging all the resources and causing the thing to run even slower. It's mildly absurd.

The company I work for is great, probably the best I've ever worked for in terms of how they treat their employees overall. Now in my 11th year with the company, if I had one bone to pick, it would be their handling of technology. I don't call IT unless I absolutely have to, they aren't particularly helpful and I don't have 2 hours to waste.
 
And good on you for insisting on hardware with a real interface, not PHOOOOOONNE bullshit.

Yeah, getting harder and harder to avoid it, though. I'm not in the majority, I guess this is what people want.

To me, cell phones seem like incredibly insecure devices, not sure why anyone would use them for anything sensitive.
 
Last edited:
  • Like
Reactions: Zorba
At least once every workday (often twice), the built-in Windows antivirus and malware will run system scans, hogging all the resources and causing the thing to run even slower. It's mildly absurd.

I always said the fastest way to ruin a good computer is to install anti-virus on it. Windows pretty much requires it though.
 
Yeah, getting harder and harder to avoid it, though. I'm not in the majority, I guess this is what people want.

To me, cell phones seem like incredibly insecure devices, not sure why anyone would use them for anything sensitive.
It doesn't make any sense whatsoever to me - but you knew that. Little tiny screen, no keyboard = no fun. Never mind that not everyone has one. I'd much rather telnet into the thing and run a CLI program/command than anything to do with a PHOOOOOONNE. Amateur hour as far as I'm concerned.

I "finally" found some "smart plugs" that actually have some brains and don't require a control server to run the damn things - they have a built-in webpage to control them. They're not here yet, so I'll see when they get here. We have 3 fountains and a bunch of accent lights that I currently have on mechanical timers., about 10 of them. They long since lost any semblance of sync, and I've wanted to replace them with smart plugs but didn't want to go to the hassle of setting up a server to run them. Or use a PHOOOOOONNE.
 
  • Like
Reactions: chili_pepper
It doesn't make any sense whatsoever to me - but you knew that. Little tiny screen, no keyboard = no fun. Never mind that not everyone has one. I'd much rather telnet into the thing and run a CLI program/command than anything to do with a PHOOOOOONNE. Amateur hour as far as I'm concerned.

I "finally" found some "smart plugs" that actually have some brains and don't require a control server to run the damn things - they have a built-in webpage to control them. They're not here yet, so I'll see when they get here. We have 3 fountains and a bunch of accent lights that I currently have on mechanical timers., about 10 of them. They long since lost any semblance of sync, and I've wanted to replace them with smart plugs but didn't want to go to the hassle of setting up a server to run them. Or use a PHOOOOOONNE.

I hate smart plugs, especially the 2.4g only ones. I’ve started using

https://www.amazon.com/dp/B082TX3CV1?tag=wranglerorg-20
 
  • Like
Reactions: chili_pepper