Edit: forgot to mention that I’m based in Europe, which might be relevant for which devices are easily available.
Hi, I am a newbie looking for a new router, one where I can block ads and tracking (with AdGuard, PiHole or something similar), I can choose my own DNS, and hopefully tinker more once I learn more about routers and networks. I have a home server currently running only locally and would like to access it from outside my home, but I’m afraid of letting the door open to bots, hackers, etc.
I am currently using the router provided by my ISP, which has poor customization options and is also failing a lot lately (it loses internet connection at least once a week and needs restarting).
I have searched a bit around and I think something where I can install OpenWRT or other open source firmware would be good. On the OpenWRT forum I have seen recommended the GL·INet Flint 2 GL-MT6000 https://openwrt.org/toh/gl.inet/gl-mt6000. I also looked a bit more on GL·INet’s website and saw the GL·INet 3e (GL-BE6500) which has WiFi 7, and wondered if that could be a good upgrade, but seems it doesn’t support (yet) installing official OpenWRT.
As for me and my use case: I am comfortable with the Linux command line, my personal computer runs Linux and I have a home server running OpenMediaVault with a couple of services on Docker (Jellyfin, Navidrome, Radicale, Trilium, Calibre-Web, Wanderer), but I barely know anything about routers and networks. The router will serve to connect that server via Ethernet and use several devices (laptops, desktop PC, phones, tablets, AndroidTV…) via WiFi.
I wonder what the thoughts of people who know about routers and networks are.
- Are these good options for a first non-ISP router?
- Is the 3e (GL-BE6500) worth the update for WiFi 7 or is it overkill for my use-case? Maybe even a bad idea if it doesn’t support the official OpenWRT?
- Anything else I missed and should take into account?
In addition to the physical router recommendation, I have 2 more questions:
-
from what I have read in other threads I believe I might need to keep my ISP’s router, or get another device to use as a modem before the router (I don’t know how to do that). Is that correct or can I just replace my ISP’s router with a router running OpenWRT (or similar) and be set?
-
does anyone have any good resources to learn more about networks, modems, routers, etc.? for a newbie who is comfortable with the Linux command line but otherwise knows nothing about the topic.
I use the Flint 2 with openwrt (vanilla, not stock). I installed Unbound for a recursive DNS and dnscrypt (or whatever its called). The router has been amazing and handles the recursive DNS with no issues.
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:
Fewer Letters More Letters AP WiFi Access Point DNS Domain Name Service/System HASS Home Assistant automation software ISP Internet Service Provider IoT Internet of Things for device controllers NAT Network Address Translation NUC Next Unit of Computing brand of Intel small computers PoE Power over Ethernet VPN Virtual Private Network
[Thread #89 for this comm, first seen 27th Aug 2026, 15:50] [FAQ] [Full list] [Contact] [Source code]
A Gl.inet router is easy to use with it’s stock firmware. I recommend getting one and keeping it stock at least for awhile. You can still use Luci to get more in-depth while also having a simple to understand interface as a backup. It has Adguard built in as well as other things like VPNs and Tailscale and packet inspection. Of course through Luci you can install all sorts of stuff. The Flint 2 has good hardware to be able to run lots of addons
I went the Flint 2 route, I do not currently need wifi 7 but I did flash it with vanilla Openwrt. With the clean vanilla OpenWRT I have added 2 VPNs, I am considering adding a third (one is personal, one is to show off to friends, and the third one will be for my off site back up). I have a poop load of vLANs (IoT stuff, home lab stuff, my personal stuff, guest stuff, child safe vLAN, Personal VPN vLAN, guest VPN vLAN). I have a bunch of wifi APs, (personal, guest, kiddo safe, IoT, and a few because I am an asshole and believe all them waves belongth to me!).
My plan was to host my own email server but this girl loves her hair and did not want to pull it all out, so I just continued on using a third party for that, this is why I got a firewall I controlled because I needed static IP addresses for email but I would recommend getting one if you are adding your own firewall just to by pass everything your ISP is doing, I have fibre but even when I had DSL my ISP had to keep their modem in there, port 1 is just a dumb switch that goes to my firewall.
Originally I had a VPN running on a pi zero 2 (do not do this it is not that great to do it), but now my Flint 2 takes care of it and I do not notice any slow downs when I am away from the LAN. As a Canadian my PM just recently said we are at war with the US, sure it is a trade war not a pew pew boom war but war non the less and as an ex-Apple fan girl I was already slowly moving my stuff away from Apple things and use a pi 4 for HA I have a pi 5 running a bunch of services including pihole, would highly recommend, I have another pi 5 running stuff, and a pi zero 2 running my secondary pihole. I would highly recommend pihole to anyone who is just starting home labbing or been at it for a while, there is some disagreement with people who use other ad blockers but I found pihole first and feel in love with it. You will be so glad to have a VPN with whatever ad blocker you choose (pihole). But getting a static IP is a good idea, sure there are hacks to get things working with things like duckdns.org, your own domain, or whatever else.
You mention hackers and bots, I have crowdsec running on my firewall with things going to all my other devices and a honey pot on my pi zero 2, but my suggestion is if you do not want to set up crowdsec and just rely on the firewall make sure you use strong passwords, I have vaultwarden for those, and change your ssh ports on your devices and while you are at it do not use anything in the 8080 port range.
That glinet 3e will never get openwrt due to the chip used on it, I’m being told, which makes it a no go imo
YMMV but I managed to get a Netgear Nighthawk, one or two generations old, for $10 from a thrift store nearby when my router was starting to crap out. It might be my area but I found at least a couple dozen of those same routers over the years.
I nabbed it, flashed Fresh Tomato on it, and it has been performing excellent for two years.
Sounds like a hardware flipping opportunity to me!
at least for me, I would be interest in buying one and paying shipping if you find another.
I want a Flint2, but they are a bit pricey for me atm.
I’ll keep an eye out for a good deal, mate!
From the US if that matters.
I am in Ohio so that should make it easier
Unless you have fiber from your ISP you need a modem to translate from the TV or phone cable to Ethernet.
I’m not a fan of openWRT. I’d recommend you go look at NUC-style x86 mini PCs with multiple network ports instead and install OPNsense. I find the web interface much more intuitive than LuCI
This, some PoE switches, some grand stream APs, and it’s off to fully owning your network and never looking back.
I am looking at PoE switches, some PoE Access Points, and cameras actually.
A group near me does hardware auctions and has tons of Extreme Network APs that I think are PoE supported, but they keep dodging my requests.
Good luck. I hope you can get those on the cheap. I ended up wiring everything I could in the house, including streaming devices, consoles PCs, etc. The APs are basically only handling phones, tablets and some wifi IoT switches (matter over WiFi) to my home Assistant. Everything else is wired. I could not be happier. 11 PoE cameras, my wife almost had a heart attack when she saw that invoice 🤣
ipfire is a good alternative to opensense because its simpler to use imo.
If you have cable, you need a modem. You might be able to put the ISP’s modem into passthrough mode. If not, get one of your own, from the ISP’s supported models list.
Thanks for your answer. I wasn’t sure what “you have cable” exactly meant, but after seeing BrightCandle’s comment I looked at my ISP contract and it mentions VDSL 50, so I guess I don’t need a separate modem then.
If you want to cut out your ISP device entirely, you will need to know exactly what setup your ISP has given to you, and then match that with your own hardware. The https://pon.wiki/ and servethehome forums are a great place to start for this.
If your ISP device has a passthrough mode that you are happy with using, practically any device with two gigabit ports will work for a 1gbps internet connection. I use a https://friendlyelec.com/ device, because they come with friendlywrt preinstalled, but your choice of router software is basically entirely preference based.
I’m also a noob with tech anymore. My old faithful router started dropping this year, replaced it with the Flint 2 earlier this year because I also wanted OpenWRT. It comes with OpenWRT installed, but I don’t think it’s the plain old vanilla OpenWRT, so when I hooked it up and started setting it up, it needs a firmware update anyway, so I installed the actual OpenWRT from their site. It’s been great since, totally happy with it.
I have 2 x Flint 2, the second one is in “extender” mode for better coverage in our house. I’ve found it to be a great router.
I’ve tried to figure out setting up VLAN on the Flint 2 but as yet I’ve failed. I’ll try again at some point.
Flint 4 will support VLAN out of the box though I’m waiting to see more about OpenWRT implementation on it.
Take a look at OPNsense which is open source or pfSense which is more commercial but still has a community version. Good documentation and will run on really old hardware as long as you have two Ethernet ports in the computer. Until last year my router was a 2007 dual core dell PC. I upgraded to a fifth generation I5.
I run the licensed version of pfSense on all the routers in my org. I have full tunnels between each location along with full blocking of malicious sites including all adult content. It may look complicated but if you want to learn how netowrking works you can do a lot worse.
I found the Cisco free networking courses really helpful when trying to figure out my network stack. Some of the earlier stuff you probably know but you can skip through quickly, especially if you don’t care about getting the “qualification”. https://www.cisco.com/site/us/en/learn/training-certifications/training/netacad/index.html
I would personally recommend keeping the router and adguard/pihole server separate. If you mess something up, it’s easier to quickly switch the router DNS to a public one whilst you try to fix it, especially if you have anybody else at home who won’t appreciate losing their internet because you messed up something (which will happen but let’s you learn)! It’s also a good idea to keep this separate from your main server for this very same point. You might accidentally use up the entire hard drive or have some messed up update on one software take all the RAM, making everything else unusable (both happened to me at different times, and one was overnight before I was working from home which was not fun to try and fix first thing in the morning!). It’s not always clear which device is causing and what went wrong so can take some time to fix but gives you flexibility to fix in your own time.
That’s why I would recommend getting a used thin client for £30ish (GBP) from eBay or somewhere like that. I have my pihole and home assistant on there to be clean and separate in case my server goes down. Then the internet still works, the lights still work, and things like nextcloud and jellyfin just have to wait a bit.
It also allows you to upgrade devices separately (e.g. when my internet provide unexpectedly upgraded to 2.5G I chose to buy a new router and one of the switches, and upgrade the Ethernet socket on my home server) but kept my existing WiFi access point and pihole/HASS server which still work fine after years of use. Most of my clients at home can’t handle higher speeds so no point upgrading the rest of the network until they can (if ever). I have separated my WiFi access point and router because of the location of my incoming wires and home layout, which you could also think about doing. I’ve always thought getting seperate devices focusing on one thing they do best makes sense, and can actually be cheaper to buy.
Not sure about routers themselves but have heard good things about openwrt. I do NOT recommend the TP Link Omada series!
My current router is an ancient laptop running NixOS. Ethernet in via the Ethernet port, and out via a USB converter. It probably could serve as a WiFi AP too, but currently I have a dumb OpenWRT in bridge mode for that.
The same laptop also selfhosts Prosody, coturn, LiveKit and stuff.
I don’t really see how a proper router would be better than that.
I have seen recommended the GL·INet Flint 2 GL-MT6000 https://openwrt.org/toh/gl.inet/gl-mt6000
I’ve used a Flint 2 GL-MT6000. Works fine for me. If you want a high-spec new OpenWRT machine, it’s near the top end, from my skim. It may be overkill if you don’t intend to do anything elaborate.
and is also failing a lot lately (it loses internet connection at least once a week and needs restarting).
So, you’re still going to need to have a cable modem or DSL modem or whatever, if you have cable or DSL service, and it (or some other hardware, if you can get that working) going to be necessary for that bit. There are three pieces to this equation: a modem or whatever translates your satellite/long-range-wireless/cable/DSL/etc link to your ISP to Ethernet. A wireless access point, to provide WiFi. A router, to NAT connections, do things like setting up what traffic goes where, what’s blocked, etc. The Flint 2 will act as a wireless access point and as a router. But it doesn’t have a modem built in.
You can turn off a lot of functionality on your ISP-provided router, but you’re going to keep it in the loop (with the Flint 2 plugged into it) unless you have the ability to use an alternative modem. It may be possible to replace it with a different modem, depending upon your particular situation; I believe that some ISPs may embed authentication information in the modem specifically to keep people from using alternatives.
Thus, if the ISP-provided router keeps failing in that configuration, this isn’t going to fix your problem. You can reduce the functionality that the thing uses, like, maybe throw it into bridge mode (which just passes traffic through, doesn’t NAT anything) and let the Flint 2 act as a router. That’ll reduce what the ISP-provided router does, and if that’s triggering some bug on the thing, that might resolve your problem.
If the existing router is honestly failing in some way—like, once it has problems, it never comes back without a reboot, isn’t just connectivity problems—you might request a replacement.
If none of the above fixes your problem (i.e. the ISP-provided router, stays in the loop and keeps failing and only a reboot fixes things) a mitigation, albeit not a fix, would be to set something up on your network to ping the outside world and then power-cycle the router automatically if it fails for a certain amount of time.
I second the Flint 2. It’s the best router I’ve ever used.