# What router are you using?

**URL:** https://discuss.privacyguides.net/t/what-router-are-you-using/31059
**Category:** Questions
**Created:** 2025-09-12T14:30:22Z
**Posts:** 38

## Post 1 by @djkilla — 2025-09-12T14:30:22Z

Just curious to know what routers users are using. I currently use an Asus RT-AX86U but I’m in the market for an updated router. Currently the Ubiquiti UniFi Dream Router 7 ( **UDR7** ) has my full attention but I wanted to check what others had to say before making the purchase.

By the way, the reason I’m looking at the UDR7 router is because you’re able to create VLANs, the Zone firewall and the new object oriented networking. This will be a router replacement for me with no other purchase to expand, meaning no additional equipment will be added to the router such as more switches, wifi extender to create a mesh network, etc.. Just looking for a good, quality, reliable router that’s got some great security features built in.

---

## Post 2 by @anon57862721 — 2025-09-12T14:32:23Z

I personally would buy the Banana Pi Open WRT router if I were in the market for one. Its FOSS and highly customizable. But seems like you know what you want and why but do check this one out as it may serve your purposes too.

---

## Post 3 by @anon63378630 — 2025-09-12T14:38:10Z

> [@djkilla](#):
>
> UDR7 router

that thing has a weird port choice: it has 10g sfp+ but the rest are 2.5g?  
like what consumer ISP offers sfp+ (without an ont mod) or why would you want a nas via 10g but clients at 2.5g?

---

## Post 4 by @dngray — 2025-09-12T14:45:20Z

Personally i wouldn’t go all in on ubiquiti unless you like really want to be tied to their ecosystem. Some of their products used to be better in the past.

You could also consider opnsense. I have one of their appliances and it’s rock solid with the features I need. It also works on any platform, if i wanted to use some old server I could do that too.

Would also be checking whatever you choose has enough features to do ip policy matching on the firewall, like say you want a VPN running on your router and want to direct one of your VLANs to tunnel traffic into it.

---

## Post 5 by @anon92357554 — 2025-09-12T14:50:07Z

OpenWrt on a [Google WiFi Puck](https://openwrt.org/toh/google/wifi)

---

## Post 6 by @djkilla — 2025-09-12T14:55:51Z

@ [JG Johnny Gossamer](https://discuss.privacyguides.net/u/jg) - Interesting, but for me that would make for an interesting future project going the Banana route.

@ [SkewedZeppelin](https://discuss.privacyguides.net/u/skewedzeppelin) - You’re right. The router is more for a small business but I’m looking to use it as a home router. The SFP+ can be converted with a SFP+ to RJ45 10GbE adapter but anything above 2.5gbe would be capped to due to the other 4 ports being 2.5gbe. I’m aware of this but the security features is what really has my attention.

Forgot to mention that my budget is around $500. The router is for a small apartment. I’m also looking at a two mesh system (TP-Link Deco BE63) which would probably be overkill for a small apartment but the security features may not be comparable to the UDR7. I guess I would be willing to sacrafice as long as there’s VLAN capability to seperate devices from each other along with some decent rules to go a little further.

---

## Post 7 by @djkilla — 2025-09-12T15:05:47Z

@ [dngray](https://discuss.privacyguides.net/u/dngray) - quoted “Would also be checking whatever you choose has enough features to do ip policy matching on the firewall, like say you want a VPN running on your router and want to direct one of your VLANs to tunnel traffic into it.”

I like this idea. I’m currently using Mullvad VPN and ControlD DNS using the Hagezi’s DNS - Normal configuration. Also Firefox with a more hardened fork of Arkenfox. Specifically Narsil’s user.js: [Narsil/desktop\_user.js: user.js file for configuring and hardening Firefox privacy and security.- - Forgejo](https://git.nixnet.services/Narsil/desktop_user.js)

---

## Post 8 by @anon63378630 — 2025-09-12T15:21:03Z

> [@djkilla](#):
>
> Also Firefox with a more hardened fork of Arkenfox. Specifically Narsil’s user.js

If you want Arkenfox, please just use Arkenfox.

---

## Post 9 by @jonah — 2025-09-12T15:53:07Z

> [@djkilla](#):
>
> Just curious to know what routers users are using.

Mine is from Ubiquiti. You have to realize they are very cloud integrated though.

> [@anon63378630](#):
>
> like what consumer ISP offers sfp+

Mine does on their 10G plan lol, but you’d never use a router as underpowered as this on it.

> [@anon63378630](#):
>
> why would you want a nas via 10g but clients at 2.5g?

This is probably the normal use-case for 10G, using it on central servers to support more lower bandwidth clients concurrently…

> [@djkilla](#):
>
> Ubiquiti UniFi Dream Router 7

If you want to go with Ubiquiti, my choice would be the UniFi Express 7.

---

## Post 10 by @Laitinlok — 2025-09-12T16:07:45Z

I use x86 router and installed OpenWRT

---

## Post 11 by @djkilla — 2025-09-12T16:55:21Z

Sooooo, after thinking about it. I should have titled the subject differently.

New question, if you could buy a new router today, what would it be (if you had $500)?

Any must have features?

Any web sites you would trust to get reliable info on choosing a router? For example: [The 3 Best Wi-Fi Routers of 2025 - RTINGS.com](https://www.rtings.com/router/reviews/best/wifi-router)

---

## Post 12 by @anon63378630 — 2025-09-12T17:00:40Z

> [@djkilla](#):
>
> what would it be

a sff optiplex with some dual or quad 10g or 25g port nics and slap opnsense or openwrt on it  
would be well under $200

example (unaffiliated):

- $50 [Dell OptiPlex 5040 SFF i5-6500 @3.20GHz | No Drive | 8GB RAM | No OS | eBay](https://www.ebay.com/itm/297601875941)
- $45 [OEM Mellanox MCX4121C Dual Port 25GbE SFP28 ConnectX-4 Ethernet Card Low | eBay](https://www.ebay.com/itm/356935356328)
- and a icx7250 (8x10g+48x1g poe) for good measure: [Brocade ICX7250-48P-2X10G Managed Switch-Same Day Shipping | eBay](https://www.ebay.com/itm/256902823900)

---

## Post 13 by @Bhaelros — 2025-09-12T18:39:31Z

Using Fritzbox 7690 :slight_smile: I have a Netgear XR500 flashed with OpenWRT but it is failing too frequently, so Fritz is my main device.

---

## Post 14 by @Tux — 2025-09-12T21:56:57Z

I would avoid anything made by Ubiquiti, and second the suggestion of an OpenWrt One for an affordable home router that respects your privacy and freedom out of the box. Also consider various GL.inet routers as a second best option.

As for what I personally use: a retired gaming PC with a dual SFP28 NIC and a Mediatek WiFi card used in AP mode, running Linux.

---

## Post 15 by @djkilla — 2025-09-13T03:21:15Z

I’m a little shocked at the answers I’ve gotten. I didn’t expect to see the OpenWRT One, the Banana version and the Fritzbox to be so popular. I’ve taken another deeper look at these products and they are interesting. Are they really that good? How’s the UI when using these, are the settings easy to navigate around or does it use terminal commands to set up? Any cons?

I’m still looking at some other commercial routers and researching more. Seems like I always find a con as in wifi range, buggy software, the hardware itself is way too big and spider-like. I do like the TP-Link BE550 and the Asus RT-BE92U but still keep coming back to the Unifi Dream Router 7 (UDR7). Is it really that bad of a router? Reviews are good for a stand alone router. Like I said, I’m not looking to expand beyond the router itself since it’s for a small house. I also don’t plan to go beyond a 2gb internet connection anytime soon.

---

## Post 16 by @anxioustotem — 2025-09-13T06:49:35Z

i bought an off-lease lenovo sff intel desktop with a four port Fujitsu intel NIC. It uses very little energy and runs smoothly with my gigabit connection you really want to make sure you get a legit NIC because ebay is flooded with weird knockoffs. the manufacturer branded ones like HP, or Fujitsu are not faked as far as I can tell

---

## Post 17 by @Securely0845 — 2025-09-13T12:49:17Z

With a little network knowledge, the Unifi equipment is easy to set up and maintain, they are slightly more expensive than most of the other suggestions here, but the UDM options are really geared towards enterprise/SOHO, so you pay a premium for that.

They don’t have a bad reputation for privacy, but your management pane is cloud based and while the company doesn’t have direct access to it, through their tools they can gain access, so it has the potential to not be as private as building your own with opnsense or openwrt.

I’ve been running two UDMPs for the last 4-5 years with zero issues and no downtime on either one, the second one has been a life saver a few times as it’s at a family members house and I can remote manage it for them the few times their ISP went out, or the PiHole stopped worked for some reason.

---

## Post 18 by @username0990 — 2025-09-13T14:52:01Z

I guess this setup consumes more power than a typical household router, right?

---

## Post 19 by @dngray — 2025-09-13T15:00:37Z

> [@djkilla](#):
>
> OpenWRT One, the Banana version and the Fritzbox to be so popular

Well if you use opnsense you can use any x86 or generic arm, or even a VM. Be mindful that if you actually intend to flash a openwrt on a device its probably easier to use something like the turris etc. I wouldn’t bother buying hardware not designed to run open firmware on it, seems more effort than it is worth.

Also consider bandwidth and whether a banana pi will meet your needs, if you have fast internet this may not be sufficient, especially if you want it to do vpn routing as well.

---

## Post 20 by @anon63378630 — 2025-09-13T15:03:23Z

> [@username0990](#):
>
> this setup consumes more power

power at the wall for an optiplex like that would be 30-40w and the icx7250 draws about 50w  
you can get the 24 port non-poe variant of the 7250 and that supposedly only draws 30w

but the gain is you can basically get 10g on everything you’d need in a home environment along with an excellent management interface and support for advanced features/acls

otherwise there are fairly cheap 8 and 16 port 2.5g switches these days that’ll draw \<15w

---

## Post 21 by @anon48875053 — 2025-09-13T15:47:36Z

I’m using the Flint 2 from GL.iNet with vanilla OpenWrt. Works very well, but Flint 3 now exists.

---

## Post 22 by @djkilla — 2025-09-13T17:04:59Z

Well, spent the last day checking out the OpenWRT One. There’s tons of firmware to load up and get additional settings or access to whatever you need. Installing add-ons requires a bit of command line but for me overall, I would probably stay with the already installed firmware that comes with the unit as a starting point. I still don’t know how many square feet the radios are capable of covering. I saw you can create VLANs which is good. I still would prefer wifi 7 with beefier hardware and that’s where the new OpenWRT2 comes in. I don’t think it’s out yet but will include wifi 7 along with a 5gb/10gb WAN ports and beefier hardware. I still would need a switch to directly connect 4-5 devices. I like how you can buy two of these and create a mesh network for coverage.

@ [Securely0845](https://discuss.privacyguides.net/u/securely0845) - Thanks for that info! Looks like I’ll end up getting the UDR7 after really diving into reviews, comments and ratings on router comparisons. I see you can actually skip creating a cloud account and remain local with access to all the settings without missing much of anything. Quality, size, features, reliable updates check all the boxes with me. I don’t mind the occasional hiccups, if any, since all routers experience a glitch from updates every once in a while.

I’ll probably also purchase the OpenWRT2 when available as something to tinker with experiment on since it’s so cheap around $89 (Cheap to me at least). It shouldn’t go to waste as I’ll probably set it up as an access point creating a mesh network. Or sell it to a friend or keep it as it could become useful in so many ways.

---

## Post 23 by @bitsondatadev — 2025-09-13T17:05:51Z

I’m using a [Firewalla Gold Plus](https://firewalla.com/products/firewalla-gold-plus) and loving it. My next move will be more DIY but this is something that is time consuming and easy to mess up if you rush it, so this was my in between. Also, I love their features and those give me inspiration for what I want and don’t want to for my own setup.

---

## Post 24 by @anon83428815 — 2025-09-13T18:23:08Z

Router: [NanoPi R4S](https://openwrt.org/toh/friendlyarm/nanopi_r4s_v1) using OpenWrt.

APs: [ZyXEL NWA50AX Pro](https://openwrt.org/toh/zyxel/nwa50ax_pro) using OpenWrt.

Switch: [HPE 1920-24G](https://openwrt.org/toh/hpe/1920-24g_jg924a) using OpenWrt.

---

## Post 25 by @Tux — 2025-09-15T02:51:50Z

You can’t go wrong the OpenWrt One, it’s far more robust and feature complete than comparably priced plastic boxes from Asus and the like. It’s also under YOUR control, and not backdoored like the Ubiquity stuff. A router shouldn’t phone home, period.

---

## Post 26 by @bsd — 2025-09-15T09:40:38Z

I use the following:

[Firewalla Gold Pro(10Gig)](https://firewalla.com/products/firewalla-gold-pro)

- This is my main Router/Firewall.
- 2x10gig and 2x 2.5gig ports.
- My main Desktop is plugged directly into it.

[Firewalla Access Point 7](https://firewalla.com/collections/firewalla-ap7/products/firewalla-ap7)

- Wireless Access Point, plugged into the FGP
- All of my IoT devices are connected to this on a separate VLAN(VLAN30) with rules that block them from accessing my devices on the Personal VLAN10 and VLAN20.

[TP-Link TL-SG2210MP](https://www.tp-link.com/us/business-networking/smart-switch/tl-sg2210mp/)

- 1 gigabit switch.
- Plugged into the FGP as well(VLAN20).
- My two homelab servers are plugged into this(VLAN20). Cannot access devices on VLAN10 or VLAN30.

---

## Post 27 by @bitsondatadev — 2025-12-08T15:24:54Z

You have the newer version of my setup…jealousville population: me

I did recently add a relatively cheap refurbed tplink TL-SG2428P 28-Port Gb Switch 24 being PoE+. This was to connect my basement floor to my second floor.

I highly recommend running larger conduit on the outside of your house and use junction boxes you can open to make upgrading cables easier.

That all said, it’s become super easy to do line drops in my house.

 ![IMG_20250910_194506_850](https://forum-uploads.privacyguidesusercontent.com/original/3X/3/e/3e50fb492cedd7f0e9bb631d286cb67ad8c55044.jpeg)

 ![IMG_20250906_125531_035](https://forum-uploads.privacyguidesusercontent.com/original/3X/5/7/57ab77c6d43a945073f912e584c698d8d20a3938.jpeg)

 ![IMG_20251006_114102_728](https://forum-uploads.privacyguidesusercontent.com/original/3X/e/c/ec2be5d1094ab1c1272e08b60bd1bd955b5a9e6e.jpeg)

 ![IMG_20251026_162052_069](https://forum-uploads.privacyguidesusercontent.com/original/3X/4/2/42d36740d1d937178b2c00ff42374f83bf228ba2.jpeg)

Oh, hire a contractor to install the PVC if you’re installing near your water, electric, and HVAC lines like I did. You’ll notice the bottom part where all the other pipes are going in. This is also where my ISP line comes in, water lines and power for HVAC and from that power grid. All SUPER dangerous so get a contractor you trust. Plus drilling a hole in your wall to the outside needs to be sealed properly so pests or cold don’t enter. I always prefer small local contractors I’ve worked with over some less dangerous jobs to get a feel for how they solve problems.

I did this because the previous owner finished the basement and made everything inaccessible, and I just opened up some big holes so all of that wall would be accessible for future work. That and I just like having consistency.

---

## Post 28 by @anonymous484 — 2025-12-08T16:07:02Z

from the links @bsd provides that is like $1,200+ of equipment for a home network. What kind of workloads / activities are you using it for?

---

## Post 29 by @bitsondatadev — 2025-12-16T02:58:10Z

Running my own datacenter for my family so we can quit this tech dominated economy.

Trying to think how to open and standardize my installation and then make a small business model so I never have to work for anyone else but myself and my family. Then hopefully others can build their biz on it for their local communities and so on…

---

## Post 30 by @anonymous484 — 2025-12-16T03:17:44Z

Very cool. Sounds similar to what [Jake (formerly of LTT) is doing](https://www.youtube.com/watch?v=vpTZWyOw_Uo)..

---

## Post 31 by @Honolumbus — 2026-01-10T20:52:52Z

> [@jonah](#):
>
> ![](https://forum-cdn.privacyguides.net/letter_avatar_proxy/v4/letter/a/c0322f/48.png) anon63378630:
> 
> > why would you want a nas via 10g but clients at 2.5g?
> 
> This is probably the normal use-case for 10G, using it on central servers to support more lower bandwidth clients concurrently…

It can also be used as a trunk port to connect a switch. Enterprise switches often have two of these to connect all vertically in a rack. Routers look like they only need one since the other end’s the internet normally.

---

## Post 32 by @U53R — 2026-01-10T23:51:49Z

Gl.iNet one. They have super neat feature to randomize BSSID.

See

> [@GL.iNet adding random BSSID to fight mapping](https://discuss.privacyguides.net/t/gl-inet-adding-random-bssid-to-fight-mapping/19296):
>
> I can only say “thanks goddess”. Apple and Google tracks BSSIDs to fill their own maps. I don’t want to be a product when I don’t even use Google crap, just because all housemates use Google crap.

Also they have LuCi interface to add more advanced config. And they one from not-so-many manufacturers that have HTTPS in admin panel.

Yes, they have so much more to do but we’ll, who doesn’t?

They even moved to NTS instead of NTP (who else did that?):

> 2025-11-18: Use chrony instead of ntpd

> **[GL.iNet download center](https://dl.gl-inet.com/release/router/snapshot/be9300/4.8.4)**

Plus their support super helpful. They even helped me to write script!

---

## Post 33 by @Onscreen5341 — 2026-01-11T00:19:45Z

For now sadly some shitty ZTE router from my ISP and as APs TP-Link Deco M4s.

I try to switch from Deco M4 to the Ubiquiti UniFi 7 Pro.

---

## Post 34 by @Boris — 2026-01-11T03:25:56Z

I use an N100 mini PC from AliExpress with OPNsense as the router, and two gl.iNet Flint 2s as dumb APs.

---

## Post 35 by @Tux — 2026-01-11T20:27:29Z

Yes this is one of the best solutions for power users, although I personally prefer Linux over BSD because I am more familiar with it and don’t need or want a GUI.

---

## Post 36 by @Vico — 2026-01-13T13:43:18Z

I use the router Flint 2 from GL.iNet. I upgraded to the mainline OpenWrt version immediately after purchase, because I prefer that to GL.iNet’s own version. I’m very satisfied, you can’t compare it in any way with the router I got from the provider.

---

## Post 37 by @bullfrog423990 — 2026-07-16T07:17:09Z

I’m also looking for a new router and trying to choose between Firewalla gold SE, UCG Ultra, or OPNSense.

Any special reason you moved from your firewalla gold to ubiquiti?  
Also on your Ubiquiti devices do you do anything to block or reduce data collection telemetry?

---

## Post 38 by @john.982387487 — 2026-07-16T07:25:47Z

OpenWRT on Netgear WAX206 for 1 wireless client + managed switch for 4 wired clients (1 with double line)
