What's new

Need SSH-customizable security-oriented router with strong firmware, drivers, and kernel support

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

SDF07S

New Around Here
Hi,

I need a security-oriented WiFi 6E/7 router with 1/2.5/10Gbps Ethernet ports for home that meets the following criteria:
- Capable of creating Layer-2-Isolated VLAN's for 4+ LAN clients
- Capable of creating Layer-2-Isolated VLAN's for 4+ WLAN clients
- Allows for SSH-based cusotmizations, such as wiriting, saving, and applying custom IPTables, EBTables, and/or ARPTables
- Allows for SSH-based customizations to execute on boot via a script with assumption there is some guidance on how to do that
- Allows for disablement of sending any and all telemetry to router maker/manufacturer or whichever 3rd party, which should be each to accomplish with custom IPTables
- No in-bound traffic is to be allowed onto the router itself from WAN, which should be easy to accomplish with custom IPTables
- Continued strong support from router makers in regards to firmware, hardware drivers, and kernel
- Allow application of router firmware updates and router application updates manually via SSH
- Preferably follows strict secure design where each internal application runs in user mode and in its own container/sandbox
- Preferably can run DNSCrypt-Proxy, and/or OpenVPN, and/or WireGuard for all clients

I don't care for AI features, meshes, throughput-improveming traffic schedulers, and intrusion prevision systems because none of the clients host for LAN or WAN and each client exclusively uses OpenVPN and/or WireGuard VPN.

My threat model involves those who are able to get past any SNORT and/or SURICATA based intrusion system and prefer to exploit hardware via drivers and other low level methods, with which I am not familiar. That is why "Continued strong support from router makers in regards to hardware drivers and kernel" is very important to me.
 
Last edited:
Your question is phrased in such a way that it sounds like you're viewing this from an Asus owner's point of view, and you've posted it in the Asus forum. No Asus router will provide you with what you want. You should be looking at Linux/BSD based solutions (e.g. OPNsense, pfSense, etc. ) for the router together with separate access points for Wi-Fi.
 
I need a security-oriented WiFi 6E router

Posting this in ASUS Wireless forum - I'm afraid none from Asus, unless you want to play beta tester with Wi-Fi 7 products.

RT-AXE7800 - weak hardware, weak 2x2 Wi-Fi 6E radio, no Asuswrt 5.0 support, no 3rd party firmware support
GT-AXE11000 - old hardware, no Asuswrt 5.0 support, Asuswrt-Merlin on Asuswrt 4.0 base, will get EOL perhaps first
GT-AXE16000 - expensive with slow firmware support, no Asuswrt 5.0 support yet, Asuswrt-Merlin on Asuswrt 4.0 base
ZenWiFi Pro ET12 - expensive with slow firmware support, no Asuswrt 5.0 support yet, no 3rd party firmware support yet

With such requirements I would look at x86 hardware running pfSense with switching and access point whatever you prefer.
 
Last edited:
My threat model involves those who are able to get past any SNORT and/or SURICATA based intrusion system

It's basically anything encrypted Snort/Suricata can't see. Includes all HTTPS and VPN traffic. If you want to inspect SSL you need a proxy like Squid, but some surprises are waiting along the way. No home router can do it for Gigabit with the processing power and RAM available even in high-end models. It has to be fast enough x86 core CPU or multicore IPS/IDS on more power-efficient options. It won't be very user friendly nor cheap solution.
 
Last edited:
Yes, I thought ASUS could do the trick with some of their newer routers and ASUS Merlin firwmare support.

When I look at DD-WRT and OpenWRT, I see poor support in terms of drivers and firmware because router manufacturers are the ones holding keys to all the closed-source hardware components and unless they release firmware, projects like DD-WRT and OpenWRT are still mostly software-oriented. I thought it would be different with ASUS.
 
Asuswrt is also mostly closed source firmware with integrated proprietary components. Quite a few advertised firmware features require data sharing agreement with Trend Micro as well as Asus themselves for automatic firmware updates and built-in security features. About pfSense/OPNsense - hardware selection is the least problem. If you have no experience with either router OS - it will be steep learning curve. Your "pro" requirements suggest somewhat "pro" knowledge and experience. If this is not the case - your choices are limited to whatever is available on the consumer market.
 
I need a security-oriented WiFi 6E/7 router with 1/2.5/10Gbps Ethernet ports for home

With updated requirements:
One of Asuswrt-Merlin supported expensive "spider" models and... it is what it is. RT-BE96U or GT-BE98U Pro. There will be bugs, there will be beta testing period. Common for all new consumer products. Whatever is buggy in closed source components will stay this way until fixed by Asus upstream.
 

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top