Need help choosing a Router for this large but simple network

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

Michael Stora

New Member
Aug 11, 2023
23
6
3
I'm looking for the cheapest most compact (and preferably fanless) router (but a fan is not a deal breaker) which will never be a bottleneck for ~150-300Mbps internet (Starlink--I'm rural)--Basically I want more than adequate hardware but not overkill. I want to run the router on bare metal (no virtualization). I'm not sure if I should run OpenWRT, pfsense, or something else. I'm open to <=1L desktops, mini towers, ZimaBoard, etc. A third port for OOB management would be preferable. I'm open to referb computers as well.

Other than that my requirements are quite limited:
  • Failover WAN to Cellular Modem (USB connection)
    • Need TTL Mangling
  • VPN
  • Firewall
  • DHCP Server (DHCP and Static DHCP for nearly add devices except those assigned by the wireless APs running OpenWRT).
  • Externally exposed services and DMZ. Starlink currently does not give you that option because they do not have enough unique IPv4 adresses but that is supposed to change with IPv6. I used to run quire a few services before I moved.
  • Limited LV3 routing between VLANs. I have my 10Gbps NAS and CUPS printer server on their own untaged trunk lines for LV2 sharing. For LV3 routing I will only need the following:
    • Limited SMB sharing between computers on Office VLAN (10Gbps clients), Trusted VLAN (mostly 2.5Gbps), and Work VLAN (2.5Ggps), so 2.5GBase-T or SPF+ on LAN side would be preferable but 1000Base-T is acceptable. I'll use the NAS if I want to move big files from PC to PC. Also my main switch has the ability the turn over exactly one bridge to the hardware.
    • Share wireless printers (I have 2) that are on the Trusted VLAN with Office and Work VLANs which have no wireless presence.
    • Ports needed by games?
Here are my VLANs:
  1. Office (my personal computers, and servers--mostly 10Gbps). No WiFi presence.
  2. Work (an employer-managed laptop that needs to run employer's VPN). No WiFi presence.
  3. Trusted (the family's computers, devices that need connectivity to phones and tablets, etc. Fire TV, Firestick, smart TVs)
  4. Guest (self explanatory)
  5. IoT (untrusted): Thermostats, Cameras, Smart Bulbs, the Alexa my parents got me to talk to their granddaughter.
And finally my large (but I think simple) network in picture form attached. Thanks in advance for any feedback.
 

Attachments

louie1961

Active Member
May 15, 2023
166
63
28
I have one of these running pfSense, but I think there are similar devices in the same price range with better processors now. https://www.amazon.com/gp/product/B09WYQKHZV/ref=ppx_yo_dt_b_search_asin_title?ie=UTF8&th=1

I run 6 VLANs: trusted devices, internet facing devices, IOT devices, Televisions, a guest network and a VLAN dedicated to managing my switch, my Proxmox servers and my WAP. I am running three NAS boxes, a Proxmox server with 15 different apps on it, 4 TVs, a bunch of ring cameras, and 5 PCs. My internet is rated for 300mbps. My pfSense firewall device has never slowed me down. I use Cloudlfare tunnels to expose my Wordpress, Nextcloud, and Grocy (grocery/recipe app) to the internet. I have a 2.5gbe managed switch, and my network is mostly 2.5gbe except for my WAP which connects with a gigabit port. I am totally happy with the performance.
 
  • Like
Reactions: Michael Stora

Michael Stora

New Member
Aug 11, 2023
23
6
3
a mikrotik, maybe L009UiGS-RM
That is a great product that appears to have averything on my wish list and will free up enough ports to save me one switch. Now I just have to be able to find one for sale.
If I go with the L009UiGS-2HaxD-IN for just $10 more I can save one Wireless AP.
 

MrGuvernment

Member
Nov 16, 2020
39
7
8
pcengines if you can get one, but may not check all boxes.

Personally, a lot of those amazon / aliexpress boxes I do question, often made by companies you can find no information on (while the parts may be known, not all in it are..., all built 100% in China, and with all of the current spying going on and what is being found in infrastructure and gear....
 
  • Like
Reactions: Michael Stora

coxhaus

Active Member
Jul 7, 2020
109
36
28
I like Cisco small business switches running L3 for home. I also run 3 Cisco 150ax wireless APs. This feeds a pfsense router running a low watt i3.