TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Building My Perfect Router

32 pointsby oneowlabout 6 years ago

2 comments

tya99about 6 years ago
I did a similar thing in order to implement network segregation via VLANs and VPN routing.<p>Personally I think Alpine Linux is one of the better distributions to use for routers because it uses musl which is ultra small. <a href="https:&#x2F;&#x2F;www.etalabs.net&#x2F;compare_libcs.html" rel="nofollow">https:&#x2F;&#x2F;www.etalabs.net&#x2F;compare_libcs.html</a><p>I have separate VLANs:<p>• VLAN 1: Management (no tag, null route)<p>• VLAN 2: Untrusted (routes direct to ISP via ppp0)<p>• VLAN 3: Trusted (routes direct to ISP via ppp0)<p>• VLAN 4: Trusted (routes via tun0 - VPN connection for private browsing etc)<p>• VLAN 5: Null route for devices that do not require internet access of any kind, desk phones printers etc.<p>(Doesn&#x27;t have to be a Raspberry Pi, you can use anything that Alpine Linux runs on which is x86_64, x86, ppc64le, s390x, armhf, aarch64 (ARM8 like Raspberry Pi 3), armv7 (Raspberry Pi 2, and friends).[1]<p>[0] <a href="https:&#x2F;&#x2F;wiki.alpinelinux.org&#x2F;wiki&#x2F;Linux_Router_with_VPN_on_a_Raspberry_Pi_(IPv6)" rel="nofollow">https:&#x2F;&#x2F;wiki.alpinelinux.org&#x2F;wiki&#x2F;Linux_Router_with_VPN_on_a...</a><p>[1] <a href="https:&#x2F;&#x2F;alpinelinux.org&#x2F;downloads&#x2F;" rel="nofollow">https:&#x2F;&#x2F;alpinelinux.org&#x2F;downloads&#x2F;</a><p>The idea is that anything on VLAN2 is completely segregated at the switch and router level from the rest of my network.
评论 #19664185 未加载
virgakwolfwabout 6 years ago
I update the router about once a month, just to ensure all the relevant packages are kept current with upstream. So far the only breakages have been in kernel incompatibilities with the ipt-netflow module, but I think that’s only happened once so far - any Arch updates to shorewall, dnsmasq, etc. have been stable.