this post was submitted on 11 Aug 2023
6 points (100.0% liked)
networking
2811 readers
1 users here now
Community for discussing enterprise networks and the ensuing chaos that comes after inheriting or building one.
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Memory normally isn't the bottleneck. When you say "moderately complex firewall" does that include policy-based routing? What speeds do you get between a wireguard client and a wireless client?
PBR is in use and different LAN clients use different Wireguard VPNs or bypass the VPNs entirely. Download speeds are limited by remote server uplink speeds to about 100Mbps. Just ran a test and at full VPN utilization the router's loafing along at 22% CPU. No matter how complex I've made the config this cheap router has been able to easily handle it.
What VPN speeds were you running that maxed out your router CPU? Were you running Wireguard or OpenVPN?
I'm talking about 1gbps between multiple clients on LAN and VPN. I don't think there are any 802.11ax routers with a support that can handle gigabit speeds without any performance loss when you get the cpu involved in routing.
But I'm also saying most people will be fine with just an openwrt router. The features you get are usually worth the slight performance loss, and buying a separate firewall to squeeze an extra 100mbps out of your connection when you're already getting >850mbps doesn't always make sense.
In your response to the OP's question where you said "most wifi routers aren’t fast enough to run complicated firewall rules, VPNs, etc. at full speed" were you also "talking about 1gbps between multiple clients on LAN and VPN"?
OP: "use case: small home network 2-3 users. some internal self hosting and maybe one day external self hosting."
From their comments they don't even have a gigabit Internet connection, much less anything that would stress even a moderately priced router.
Openwrt isn't capable of providing enterprise level performance either but that's not what's being discussed. A high end router running Openwrt (and even cheaper hardware) should be able to handle OP's stated use case without breaking a sweat.
Yes, that's what I was talking about. And yes, OP has said in other comments that they have gigabit upstream. OP's original question was about why some people use openwrt as just an AP and use a separate machine for a firewall. I gave a common reason.
Personally, I'm building a NAS with 8 SAS drives controlled with an enterprise RAID controller and 2.5gbps ethernet. Total cost is under $300 (including drives) since it's all used hardware. Enterprises have moved past 1g/2.5g ethernet and SAS 2 a while ago, so lightly used hardware is cheap.