1 of 20

How to build a Router

Jesse Campbell�

jcamp@gmx.com

jbcse.com

New Jersey Linux User Group (NJLUG) - 6/28/2023 Meetup -

Presentation URL: tinyurl.com/diyrouter

2 of 20

Why?

  • Greater control over what the router does
    • Make certain devices LAN only (no internet access)
  • Plug-ins, more features
    • VPN (Virtual Private Network)
      • Access LAN remotely
    • Advanced networking
      • Detection, filtering, debugging
  • Better analytical data, logs
    • Top talkers (most data sent/received)
    • DHCP lease times (new and old devices)
    • Connection percentages
    • Utilization statistics

3 of 20

How? Method 1: Reprogram existing router

  1. Reprogram existing router
    1. Middle to high end routers from:
      1. Netgear
      2. Linksys
      3. TP-Link
      4. ASUS

Can run 3rd party firmware (embedded Linux)

Firmware such as:

        • OpenWRT
        • DD-WRT
        • Tomato
        • Merlin
    • Can be found on ebay for $50+
    • Check compatibility list on firmware websites before buying

4 of 20

How? Method 2: Build from scratch

  • Choose your hardware
    • Usually requires amd64 (x86 for older OS) type of CPU, such as Intel or AMD
      • Some experimental builds are customized for ARM such as single-board computers like Raspberry Pi or similar
    • pfSense Netgate sells the hardware with pfSense OS (Poll: Users of pfSense?)
    • Recommended
      • 8GB+ of RAM
      • 2+ core amd64 CPU
      • 32GB+ SSD
      • USB stick to backup your config file
    • Requires 2 or more ethernet ports to route Internet traffic

Either use your own computer, or buy an all-in-one device from Aliexpress

5 of 20

Example hardware (6x 1gbit ports, ~$150 shipped)

2.5gbit 6x device costs about $200 to $300 on aliexpress, search keywords: pfsense or opnsense

Fanless Pfsense Router Industrial Mini PC Intel Core i5 7267U i3 7167U 3865U Firewall PC 6 Lans 2*RS232 HD 4G/3G WiFi

6 of 20

How? Method 2: Build from scratch

2. Choose your OS

FreeBSD

pfSense Community Edition

OPNsense OS (fork)

Unix-like (Multi-user concurrent server, free, open source)

GNU/Linux

7 of 20

8 of 20

Devil in the Details

  • OPNsense doesn’t work well with:
    • USB ethernet adapters or Wifi cards (yet)�
  • If your SSD dies, you have to start over
    • Make backup config files and save to USB stick�
  • Higher learning curve
    • Such as, bridging several ports to use as a switch

9 of 20

Install instructions

  1. Download ISO of pfSense or OPNsense�
  2. Boot ISO using USB stick (Recommended: Ventoy)�
  3. Boots to default login (root/opnsense, or installer/opnsense)�
  4. Numbered list of selections�

FreeBSD, pfSense, and OPNsense �

    • Live OSes you test out by specifying which port is for LAN and which is WAN
    • Also can be tested using VMWare Player (free)

10 of 20

11 of 20

12 of 20

Configuration

  • If you wish to install on OPNsense
    • log in w/ username “installer” and password “opnsense
  • Use the HTTP address to log into the router configuration page
    • Username: root
    • Default Password: opnsense
  • Configure like you would any network router
  • Update the OS using built-in updater (optional)
  • Optional: Select plugins (optional)
    • Recommended: ntopng for traffic analysis
    • Adblock and anti-tracking filters�
  • If you need WiFi, use a separate Access Point or a WiFi router in AP mode�
  • Always make a backup of your config file after making changes
    • In case your SSD stops working, you can rebuild everything from a backup config file

13 of 20

14 of 20

15 of 20

Working Router Demo

16 of 20

Working Router Demo (firewall live view)

17 of 20

Working Router Demo (plugin: ntopng)

Show demo

18 of 20

Updates

19 of 20

20 of 20

Conclusion

Questions / Comments?���Jesse Campbell

jcamp@gmx.com

Jbcse.com

New Jersey Linux User Group (NJLUG)��6/28/2023 Meetup�

Presentation URL: tinyurl.com/diyrouter