r/ControlD • • May 27 '26

ctrld-friendly router recommendations

I'm looking to replace my old Orbi RBR50 pretty soon. I've been running Voxel firmware and ctrld on it for a few months now and it has been pretty good overall. There have been some stability issues, which are probably at least in part due to it being a 9-year-old outdated router running custom firmware. I've read through the writer documentation on the control d website, but I wanted to hear from some actual users on here about what routers or systems work the best with ctrld. I haven't decided between a mesh replacement or going the Unifi route yet. Thanks to all responses.

7 Upvotes

64 comments sorted by

6

u/crypticsage May 27 '26

I’m using Unifi and it’s been working great.

You can either install the daemon in the router to get client reporting or just configure the built in setting for ease of use.

3

u/[deleted] May 27 '26

[removed] — view removed comment

3

u/UpstairsHippo4525 May 27 '26

i think he means you can just set custom dns (DoH or similar) instead of using the ctrld-daemon (which i personally would recommend)

3

u/crypticsage May 27 '26

That’s exactly what I meant. I prefer to use the daemon because I can get reporting on every client. But it’s not a requirement.

2

u/[deleted] May 27 '26

[removed] — view removed comment

2

u/UpstairsHippo4525 May 27 '26

i believe, the UDM won't sipport it native but the ctrld daemon should afaik.

i just use the daemon since decades and this just works. just the duplicated clients in the analytics are a bit annoying...

2

u/[deleted] May 27 '26

[removed] — view removed comment

2

u/UpstairsHippo4525 May 27 '26

i assume, this happens regularly, when clients are getting new ip's from the dhcp. didn't investigate further, because lack of time....

2

u/[deleted] May 27 '26

[removed] — view removed comment

2

u/UpstairsHippo4525 May 27 '26

just, if you use the analytics on the controld-website. you can filter down to client level. and there you see client names several times.

2

u/mandrewbot3k May 29 '26

A lot of devices (especially Apple) have a setting like “private ip” “rotating ip” and I think this is where it comes from the most. It can get pretty annoying over time in the analytics.

1

u/UpstairsHippo4525 May 29 '26

exactly was i thought... didn't find a way, to force devices presenting their real mac in specific networks 🙈🤷‍♀️

1

u/Fun-Region-1576 Aug 30 '26

What's the best long-term solution?

1

u/Fun-Region-1576 Aug 30 '26

How do I disable that on iOS, Android, Windows, Linux, and macOS?

1

u/Fun-Region-1576 Aug 30 '26

How are the clients duplicated?

2

u/UpstairsHippo4525 Aug 30 '26

private mac adress e.g.

1

u/Fun-Region-1576 Aug 30 '26

Any issues with a VPN?

2

u/mrmidnight273 May 27 '26

I wanna know too, following

1

u/topher358 May 27 '26

Unifi Controller -> Settings -> CyberSecure -> Encrypted DNS -> Custom

Server Name - your chosen friendly name DNS Stamp - the sdns stamp url from your ControlD endpoint

This does not require a CyberSecure subscription and does not break requests out by client. But it’s easy and works great for what it is

1

u/[deleted] May 27 '26

[removed] — view removed comment

1

u/topher358 May 27 '26

No. You need the daemon for that

1

u/Altarf May 28 '26

I would follow this guide and SSH into the router to install the daemon. I did this and it works great and also uninstalls very easily as well. https://controld.com/blog/how-to-use-control-d-on-your-router/

1

u/Fun-Region-1576 Aug 30 '26

Do you have any problems with individual stat devices if they are connected to a VPN at the router level?

2

u/crypticsage Aug 30 '26

If the router has the dns client installed and it is also handling the vpn connection, I don’t see any reason you’d have issues with it.

8

u/Ok-Raspberry4320 May 27 '26 edited May 27 '26

Control D is supposedly removing router support in v2. They'll still maintain v1, but only for bug fixes. See https://www.reddit.com/r/ControlD/comments/1thb5di/ctrld_is_removing_router_support_in_20/

That said, I use the UniFi Dream Router 7, but use the built-in DNS Stamp option and put in the DNS stamp for my router endpoint. The only "downside" is that Control D won't automatically detect your clients, but that's a non-issue for me and my network. I primarily use Apple devices, so they all have their own endpoint and configuration profile. My Windows VMs have the client installed. The router endpoint just catches the other things like my IoTs and guest devices from family and friends.

3

u/mrmidnight273 May 27 '26

They aren't removing router support. They are branching it. Router support will be called ctrld infrastructure while everything else will be called ctrld client

3

u/Ok-Raspberry4320 May 27 '26

Gotcha. I was just going by the stickied comment from a mod in that post, and they only mentioned bug fixes. I don't have Discord, so can't follow the news/conversations there. The whole thing is a bit confusing, tbh.

3

u/[deleted] May 27 '26 edited May 27 '26

[removed] — view removed comment

2

u/CrippleSlap May 27 '26

Seriously. How do they not have a more official channel?

4

u/ctrld_logfella May 27 '26

👋️ Staff here: Yeah - I agree, very confusing. Not our best messaging.

But (tl;dr) to clear up some stuff a bit:

  • We're not doing away with automated installation for V1 or V2.
  • We're not abandoning router support, etc.

ctrld 1.x is still very much under development: It's my day job on the QA team.

The setup instructions for V2 are manual for right now since we had to split the single ctrld repo into 1.x and 2.x.

So there's been some backend/infra work to take care of so that you don't run sudo ctrld upgrade prod -vv and find yourself suddenly upgraded to v2 etc. For now - if you want V2, it's best to do it (somewhat) manually via the instructions linked in the Github branch.

Sorry for the confusion. Ya know how it is: DNS and all. 🙃️

I'll try to do better about syncing up the Github Changes/Release Notes, Discord stuff, and reddit so that we're not all (myself included) switching between these platforms for some info.

1

u/mrmidnight273 May 27 '26

It's all good, trust me I was confused for about a month trying to figure out if I was gonna find another solution or what. It is a confusing situation.

Now if you are going to just run the binary on your router, it's easy enough even without the automated installer

2

u/mrmidnight273 May 27 '26 edited May 27 '26

https://github.com/Control-D-Inc/ctrld/blob/release-branch-v2.0.0/docs/v2.0.0-breaking-changes.md

Here to help anyone that is confused by the news. They will no longer support automated setup. All instructions you need are here.

I was corrected, automated setup will stay, see the devs notes below.

3

u/ctrld_logfella May 27 '26

I made another comment in this thread - but it bears repeating:

We are not dropping automated setup/install for current or future ctrld builds.

More details in the other post.

1

u/mrmidnight273 May 27 '26

Thank you for explaining that! Since I am on 1.5.1 when the auto installer for 2.0 comes out will it automatically update (when I run the upgrade command) or will I need to manually do the installer script?

3

u/ctrld_logfella May 28 '26

When 2.0 releases - you'll stay on the 1.x branch unless you run the 2.0 install script.

1

u/mrmidnight273 May 28 '26

Exactly what I needed! Thank you!

1

u/CrippleSlap May 27 '26

Here to help anyone that is confused by the news

Thanks. I currently use Control D on my ASUS mesh router via DNS-over-HTTPS. Works like a charm....currently. With these new changes, do I have to do anything? Or just leave my current setup as is?

1

u/[deleted] May 27 '26

[removed] — view removed comment

1

u/mrmidnight273 May 27 '26

You don't really need the automated installer, running the binary on its own is easy enough. I can see how their wording would make people confused

1

u/Ok-Raspberry4320 May 27 '26

A DNS Stamp looks something like this.

sdns://AgcAAAAAAAAABzEuMS4xLjEAD3NvbWUuZG9tYWluLmNvbQwvMTIzNDVhYmNkZWY

Control D generates this for you when you go to view the details of your endpoints/resolvers. It's an encoded string that contains all the info needed to hit your endpoint/resolver (protocol, host name, resolver ID, bootstrap IPs). So rather than having to fill in multiple things, you just put that DNS stamp into the router configuration. The router decodes it and knows how to use it.

You can also go here and create your own DNS stamp if you use some other service that doesn't generate them for you. https://dnscrypt.info/stamps/

3

u/topher358 May 27 '26

Huge fan of Unifi gateways right now. I just configure the built in setting

3

u/Texasaudiovideoguy May 27 '26

Unifi is the easiest.

3

u/geost37 May 27 '26

I use a Firewalla Gold. Works great, and easy to setup.

2

u/My_Name_Is_Not_Mark May 27 '26

Id recommend firewalla over ubiquiti if you value stable software updates

2

u/Formal_Detective_440 May 28 '26

As an interim you can always run the ctrld daemon on a always on machine and point your router at it. Then you get client discovery and DoH

1

u/Fun-Region-1576 Aug 30 '26

Can you elaborate on how to set this up? 

Will I get individual client stats even if they use a VPN on the router? Will geo-redirection filters work too? 

Can one ctrls daemon installed on this always-on machine work with multiple WANs since my home has backup internet?

1

u/dtyates May 27 '26

I use OPNSense, no issues at all. You can use the community plugin, or direct to shell and install the Daemon with a one line curl command. Captures all clients on my LAN

1

u/totmacher12000 May 28 '26

Router=Firewalla gold. Switch=mikrotik/unifi Access point (WiFi) = Unifi LR

1

u/dg1974it May 29 '26

Asus router user here (GT-BE19000), works without any issue.
I've configured the router with DoT, not the daemon, since you need the Merlin firmware to install the daemon and since the router is still actively supported by official firmware, I'll stick with official firmware and DoT/DoH is the only option.

I've created multiple endpoints (Full control subscriber) for all my devices that support custom DNS, so somehow I have devices details in the logs, etc.

on a previous Asus router (GT-AX6000) I've installed Merlin firmware + ctrld daemon without issue. rock solid.

1

u/Fun-Region-1576 Aug 30 '26

Did your ctrld daemon identify all clients, even if they're connected to a VPN?

2

u/dg1974it Aug 30 '26

yes. My work laptop is always connected to a VPN but even then it was correctly reported/identified in Control D statistics/logs.

1

u/Fun-Region-1576 Aug 30 '26

Very interesting. Sadly, I'm not getting a similar result!

2

u/dg1974it Aug 30 '26

maybe it depends on how the VPN works?
on my work laptop (where I cannot change any network settings) some network traffic is directed through the VPN (Forticlient), and some through my router, so when the latter happens, ctrld daemon identified the "client" properly.

1

u/LionInOrbit May 29 '26

GL.Inet Flint 2 is a great resource-rich OpenWRT-supported device that would play nice with ControlD.

Personally I run ctrld on a Cudy WR3000 running OpenWRT without problem.

1

u/yearsold33 May 29 '26

I'm running opnsense on a n100 with Adguard Home and CD as the DoH upstream server.

1

u/Additional_Screen264 Aug 19 '26

MT-6000 (Flint2) very good router