For a while I have been planning to switch from an all-in-one wifi router to having separate devices because that way they can be upgraded piece by piece instead of having to replace the whole thing.

I am confused about the role of the firewall.

If I have a router running OpenWRT, does it have a firewall included? Either by default or by installing certain packages?

Or is it required to have a separate firewall running opnsense/pfsense?

If not required, what would be the benefits that would lean in favour of separate firewall?

use case: small home network 2-3 users. some internal self hosting and maybe one day external self hosting.

ETA: The best internet I could subscribe to where I’m at is 1024 Mbps down, 50 Mbps up. So don’t worry about wasting fibre speeds. :(

My assembled components so far are: router, WAPs, switches, ethernet cable and cable modem.

Thanks for any advice.

You are viewing a single thread.
View all comments View context
2 points

Openwrt includes a firewall, but most wifi routers aren’t fast enough to run complicated firewall rules, VPNs, etc. at full speed.

Not my experience. Right now I’m running 2 Wireguard VPNs and a moderately complex firewall on a single core 775Mhz Atheros TP-Link router and it’s not even breaking a sweat. More than 60% of memory is available, and even when transferring a huge file the utilization doesn’t exceed 50%.

permalink
report
parent
reply
2 points

Memory normally isn’t the bottleneck. When you say “moderately complex firewall” does that include policy-based routing? What speeds do you get between a wireguard client and a wireless client?

permalink
report
parent
reply
2 points

PBR is in use and different LAN clients use different Wireguard VPNs or bypass the VPNs entirely. Download speeds are limited by remote server uplink speeds to about 100Mbps. Just ran a test and at full VPN utilization the router’s loafing along at 22% CPU. No matter how complex I’ve made the config this cheap router has been able to easily handle it.

What VPN speeds were you running that maxed out your router CPU? Were you running Wireguard or OpenVPN?

permalink
report
parent
reply
1 point

I’m talking about 1gbps between multiple clients on LAN and VPN. I don’t think there are any 802.11ax routers with a support that can handle gigabit speeds without any performance loss when you get the cpu involved in routing.

But I’m also saying most people will be fine with just an openwrt router. The features you get are usually worth the slight performance loss, and buying a separate firewall to squeeze an extra 100mbps out of your connection when you’re already getting >850mbps doesn’t always make sense.

permalink
report
parent
reply

networking

!networking@sh.itjust.works

Create post

Community for discussing enterprise networks and the ensuing chaos that comes after inheriting or building one.

Community stats

  • 80

    Monthly active users

  • 121

    Posts

  • 794

    Comments