Skip to content

Comment on My Homelab Setupparent

Comments

Note: the latest OpenWrt on rack-grade routers is significantly more secure than proprietary, backdoored firewall appliances. I haven't really used Netgear/pfense but I reckon it wouldn't be much of improvement.

VLAN are perhaps the most important aspect of a network, and honestly I would start with it: tag the ports, bonding if necessary, and figure out IPv6-PD and resolve topology for it all, so that downstream DNS is easily configurable.

Do you mean pfsense/opnsense with "proprietary, backdoored firewall appliances"? I don't think so (if we are talking about OPNsense or the CE variant of pfsense).

Otherwise, I slightly agree that for the regular user, OpenWrt is simpler and less of a hassle than pfsense/opnsense, but still offers enough features. Personally, I enjoy having full control over all and every detail in my FW, which is only possible with the latter.

Thank you for the hint towards IPv6-PD/resolve topology - my migration to IPv6 is still on the ToDo list!

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.