I've got a lot of cash to spend and I want to go full retard with a router. Which router is the best one in the market?

I've got a lot of cash to spend and I want to go full retard with a router. Which router is the best one in the market?

Attached: Archer-C5400X-01_normal_1517297872202y.jpg (590x590, 97K)

Other urls found in this thread:

security.stackexchange.com/questions/129382/how-effective-is-mac-whitelisting-on-a-wireless-access-point
gigawave.com/2016/05/10/techtip-802-11w-protected-management-frames/
twitter.com/NSFWRedditVideo

More expensive is NOT better.
A midrange one from Walmart and disable WPS because it's stupidly unsecure.
Do you really want to broadcast your SSID to the whole neighborhood with that monster pictured?!

Edge router x + unfi aps

>disable WPS
what? and just leave it without password? also I intend to use a MAC filter

Ubiquiti?

The REAL question is, when the fuck are we getting a good cheap RJ45 10GbE switch.

WPS (Wi-fi Protected Setup) is the thing you use to push a button or enter a PIN to connect to a wi-fi network, instead of picking out the network and punching in a password (which had better be long and very un-memorable if its to be secure). You should disable it because it's a big security hole. Same for upnp, which is the thing that lets you avoid having to learn how to forward ports manually.

Really no consumer wi-fi router is any good, they're all the same cheap, low-powered, chink shit inside, with the same slipshod barely-updated software on top.

shit, my bad, I was thinking WPA instead of WPS

>upnp, which is the thing that lets you avoid having to learn how to forward ports manually.

I thought what did that was DMZ

The DMZ feature (which isn't actually a real DMZ in networking terms, but never mind all that) is basically just a "forward EVERY port to this one machine" button. If you're smart enough to set up a machine to safely withstand that, you're smart enough to not need that feature.

Upnp is a way for devices to say "hey router, open and forward a port for me would ya?" If you hear that and think "gee, I bet malicious software could use that..." then you'd be right.

god dammit, I just wanted to play Age of Empires 2 on Voobly

>avoid having to learn how to forward ports manually.
It's not about 'learning' how to do it. It's just a pain in the ass to manually forward every port some special snowflake program needs. It's extremely tedious, especially if you have a multitude of devices connected to your network or have family members who share that connection.

Also with upnp, the port is only open when a service on YOUR network is listening to that port. When you manually forward a port, that port stays open permanently, leaving it wide open to port scanners. With any decent modern router, enabling upnp should pose no security risk. Manually port forwarding is fucking autistic.

Everybody on youtube say Ubiquiti UniFi makes the best home and office wifi.

this, if you have they money go for a cavium +3mil pps version with poe and sfp. wifi wise an ac lite will suffice.

If your neighbors kid went through the storm to get your wpa2/3 password, MAC filtering isn't going to slow him down any. You're better off just using a stupid long password and maybe having a guest network with a qr code to auto correct for family

good luck guessing a MAC address in my acl since every packet that reaches the lan interface from an unknown mac gets dropped. can't ping, can't arp, no dhcp no nothing.

any retard kid running kali linux can find out what your mac address is and spoof it. mac address whitelisting is completely useless.

security.stackexchange.com/questions/129382/how-effective-is-mac-whitelisting-on-a-wireless-access-point

>no nothing
>Broadcasting isn't a thing
Even if acl somehow hid connected devices from airodump, I can just look at broadcasts from unconnected devices looking for your network. It's as easy as spoofing the address and sending a few deauth packets to grab the rest when they ultimately drop and reconnect

Let's be honest - unless you really pissed off some nerd with no hobbies, it's unlikely someone will try to get into your network.

They'll probably just jump on your stupid neighbor's network with their shitty wifi router from the ISP & their shitty WEP password.

>it's unlikely someone will try to get into your network.
Chinese/Russians have massive botnets that try to run all types of nasty shit on every IP. The best protection is an updated router, preferably custom flashed to something like DDWRT + strong WPA2 password. If possible, only use ethernet for your desktop + smart tv's, and keep Wifi open only for your phone or other devices which cannot use ethernet.

If you've ever ran a server before, you'll see first hand how much shit tries to connect to your devices.

>what is 802.11w
it's implemented on ubiquimeme APs

You're a fucking retard.

>airodump-ng
>see your shit connected to the network

Source: OSWP, which is overkill for your retarded ass.

you're an oxygen thief, dipshit
>gigawave.com/2016/05/10/techtip-802-11w-protected-management-frames/