Any recommendations for (DIY) internet routers?

I moved from our ISP router to a Unifi UDR which was a good way to get access to more advanced networking and multiple WiFi options to split up our smart components with firewalls to keep the resulting VLANs in their own lane.

However, with the UDR in place my internet speed is taking a massive hit.

We’re lucky enough have gigabit internet here and while the UDR says it’s seeing 850mb down, if I run a speed test on a PC, it returns a low 600mb/s result with PoE disconnected and all threat protection off.

If I bypass the UDR and gett the ISP router out of modem mode and back into duty, a speedtest on the same PC will give us about 950mb/s down.
I wouldn’t mind a bit of a hit for the features and keeping it in the Unifi ecosystem, but 30% loss is too much.

I’d spoken to Ubiquiti support already and their answer was pretty much “That’s the way it is. It’s an entry level router” My wallet disagrees with their statement and I noticed that they’ve revised their UDR online pages adding a couple of asterisks for * (1) GbE RJ45 WAN port**
**Internet speeds up to 700 Mbps
.:frowning:

So now we’re looking to replace it with an alternative router with Gb+ throughput, is low-powered and still keeps us secure.

Currently we have 2 Unifi AP and 2 switches which should still be able to be managed with Unifi Controller in docker, so that should still be able to handle most of the LAN networking and internal firewalling … assuming it plays nice with a 3rd party gateway(?)

I guess all we need is something to handle external threat detection and port forwarding to my reverse-proxy. Prob something that can run opnSense or suchlike.

Anyone have any recommendations or “I did this and it’s great?”

Hi, OPNsense or pfSense ?

Cannot really say that they are great as I don’t have one :wink: but my next router will most likely be from teklager. They install opnsense or what you want on what looks like a decent low power routerboard.

They are based in Europe, so if you’re in the US shipping is probably ridiculous.

Apparently there is a speed issue with the latest opnsense release not reaching Gbit speeds, but as it was possible in older releases it should be a question of finding the right tunables