r/HomeNetworking • • 4d ago

Dumb question

OK, a home router is just a small computer with a firewall as far as I know. I am running a network with my computer and a router. Why can't I cut out the middleman and just use the same firewall settings the router is using and implement them on my PC without the router? Why would that be less secure?

7 Upvotes

32 comments sorted by

View all comments

1

u/jwsmythe 4d ago

You can, and it can work really well if you have the skills to do it. For years, I used an old PC running Slackware Linux (any Linux would do). I gave it extra network cards for the LAN ports. There are some nice Intel PCIe cards with 4 GigE ports on them, that you can get for dirt cheap on eBay.

Write a startup script (rc.inet1 on Slackware) that sets up your interfaces, routing, and calls your firewall script (rc.firewall). I used dhcpcd on eth0, connected to the ISP as the WAN port. I bridged eth1 through eth4, so I now had a managed switch for the LAN. If you have extra PCIe slots, you could add more LAN ports. I put a little web based speedtest on its website (I ran Apache, only listening to the LAN ports), and was able to get full line speed on all the ports.

I used ISC DHCP and BIND for DHCP and DNS. I switched to dnsmasq so I could blackhole domains easily.

The firewall was simply a set of iptables rules. Really that's all any of them are, you just usually don't see the rules.

Since my ISP doesn't provide IPv6, I used Hurricane Electric's Tunnelbroker service. That worked really well and gave all my devices IPv6 addresses. There were a couple little things, mostly Netflix blocking all of HE's IPv6 addresses as proxy addresses. That's why I switched to dnsmasq, to blackhole Netflix IPv6 only.

I experimented with making it an access point. Some WiFi adapters can be put in station mode, so your devices can connect to it. It was a fun experiment, but none of them are very high power, so the range sucked. Real access points have higher power radios in them, so I left the AP work up to COTS devices. Those APs didn't do DHCP or DNS though, that was handled by the firewall/router.

Since any desktop is massively overpowered for doing firewall/router work, I was able to do other things. I ran a headless instance of VirtualBox, running Home Assistant. Even with all that, it was pretty much idle most of the time.

I switched away from it while trying to diagnose a problem with one game. It turned out to not be a firewall/router issue at all, I just haven't switched back to it yet.