this post was submitted on 03 May 2026
53 points (94.9% liked)

Selfhosted

61070 readers
920 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

I'm trying to make my first server (Immich + Navidrome + Nextcloud running on Debian, will use WireguardVPN for remote access), but my crappy XFinity router (XB7) just won't port forward at all to my server machine. I've tried so many things to make it work, so the best thing I can do now is buy my own router so that I can just use the Xfinity router as a bridge. Do you guys have recommendations for a secure, customizable enough, and long-distance router good for 6 people?

all 40 comments
sorted by: hot top controversial new old
[–] turbowafflz@lemmy.world 33 points 2 months ago (2 children)

keep in mind it may not be your router's fault you can't accept incoming connections, you may be behind cgnat. if you are, you need a reverse proxy like cloudflare tunnels

[–] cravl@slrpnk.net 16 points 2 months ago (1 children)

Cloudflare tunnels is more than just a reverse proxy, but agreed. That might be the better option regardless. If you're Cloudflare-averse, you can use Tailscale funnels, or spin up your own rproxy+tunnel solution (there are plenty out there, such as Rathole, Zrok, or frp).

[–] paris@lemmy.blahaj.zone 1 points 2 months ago

I think rathole is unmaintained. It hasn't been updated in forever and basic features like proxy protocol are just sitting there waiting for a new release to make them available. I ended up replacing rathole with gost and I actually like it better. I can run an identical setup to rathole with straightforward command line parameters instead of a config file (though a config file can also be used).

[–] ranslite@pie.dasneuland.de 3 points 2 months ago

I am behind cgnat and my fritzbox buildin wireguard allows me to connect to my home network from outside.

[–] pulsewidth@lemmy.world 18 points 2 months ago (2 children)

I use very popular router by Gl.Inet called Flint 2 (GL-MT6000). Goes on special for about $125 USD. Great specs, solid device.

Fully supported by OpenWRT, and I recommend flashing to that so that you have completely FOSS software with no possibly hijinks from the manufacturer's OEM OS.

You'll need to read some guides or watch some vids to get you set up on OpenWRT, bit of a learning curve, but it has everything you could possibly need. Check it out.

[–] Nawor3565@lemmy.blahaj.zone 7 points 2 months ago

I also vouch for GL.inet routers, they also have a 5th gigabit port that was nice to have since all 4 of the ones on my old router were full.

[–] feannag@sh.itjust.works 3 points 2 months ago

I just bought the Flint 3 and love it so far! Been to lazy/haven't prioritized flashing it yet but it works great out the box.

[–] Shimitar@downonthestreet.eu 15 points 2 months ago* (last edited 2 months ago) (1 children)

Anything that supports OpenWRT I would say....

Or even better buy a mini PC with many net ports and install opnSense, but in this case you will need a separate wifi router and/or dedicated switch since any opnSense device will only work at perimeter level

[–] irmadlad@lemmy.world 2 points 2 months ago

Or even better buy a mini PC with many net ports and install opnSense, but in this case you will need a separate wifi router and/or dedicated switch since any opnSense device will only work at perimeter level

I went with this option except using pFsense in lieu of OpnSense. My own modem, router, and managed switches.

[–] xep@discuss.online 13 points 2 months ago (2 children)
[–] IsoKiero@sopuli.xyz 4 points 2 months ago
[–] tychosmoose@piefed.social 3 points 2 months ago

Same. Moved from OpenWRT through OPNsense to Mikrotik. The performance per watt and per dollar is great.

[–] HiTekRedNek@lemmy.world 12 points 2 months ago (1 children)

Used SFF PC: $40

Pcie 10gbe network card: $30

OPNsense: free

Done.

[–] dubyakay@lemmy.ca 7 points 2 months ago (1 children)

Where can I get SSF PC for $40? What am I looking for in particular?

[–] HiTekRedNek@lemmy.world 4 points 2 months ago* (last edited 2 months ago)

eBay, FB marketplace, craigslist. Basically any dell, hp, or Lenovo workstation big enough to have a pcie slot.

Intel is usually the most prevalent. 6th or 7th Gen i3 or better. 4 to 8G ram, at least a 64G SSD.

Here's one that's a little overkill on the ram. But you'll need a cheap small SSD if you get it.

https://ebay.us/m/RdCOjG

[–] utjebe@reddthat.com 11 points 2 months ago (1 children)

You can get dirt cheap routers on eBay (like $30, for Tp-Link) that have active support on OpenWrt. Great little devices to get you started and if it won't be enough you will know more / what you need to upgrade.

However if your XB7 isn't doing / allowing port forwarding, you will still needed that for things to work.

[–] grue@lemmy.world 9 points 2 months ago* (last edited 2 months ago) (1 children)

I second the recommendation for TP-Link running OpenWRT (that's the important part).

I've been using a few Archer C7s for going on a decade at this point. (So long that they went from "OpenWRT" to "LEDE" to back to "OpenWRT", LOL!) They've been working fine that whole time, and the only thing that annoys me about them is that they're a funny shape instead of being rack-mountable.

[–] eutampieri@feddit.it 7 points 2 months ago (1 children)

Beware! Now there’s a hardware revision for a TP-Link router (I think the C7) that is not supported by OpenWrt and never will

[–] adarza@lemmy.ca 3 points 2 months ago

we were looking awhile back for one, but none of the tplink models at walmart (the only retailer with routers within 50 miles) supported flashing with a third-party firmware and i didn't want to shop online for one.

we sorta lucked-out, though.. ended up just using the one from our old provider since they never asked for it back or charged us for it. it's dual band, has wpa3, guest ssid and vlan. enough for us for now. all we had to do is flip a setting from dsl uplink to wan uplink.

[–] Eldritch@piefed.world 9 points 2 months ago* (last edited 2 months ago)

OpenWRT. It's got a slight learning curve. But if you want something guaranteed to do what you want while still being upgradable. It's the solution for you. You can find pre-made Hardware that will run it. Or any old business waste computers that you can gut and rebuild any way you like to make a beast of a router if you want.

[–] Ferawyn@lemmy.world 8 points 2 months ago (1 children)

If you want a complete unit with custom hardware and tuned custom software, look at MikroTik. Solid hardware, dependable software, good support, good community.
If you want to build your own, grab any multi-ethernet micropc from aliexpress and install OPNsense. Cheap and flexible. But you'll be on your own once (not if) something fails.
Both of these are essentially pro-level options with lots of headroom to build up to advanced services. I'd stay away from OpenWRT which is essentially just an open source consumer grade wifi router image. You'd be replacing your crappy (but supported) router with the same thing just without support.
One other option I would mention if you like nice centralized web ui's, have a look at Ubiquiti's Unify. If you can afford to go all-in on a Unify router, backbone switch and wifi access points, the combined management is really a step above the competition.

[–] dubyakay@lemmy.ca 2 points 2 months ago (1 children)

How do you find those micropcs on Ali?

[–] nitrolife@hikki.team 2 points 2 months ago* (last edited 2 months ago) (1 children)

Just looking for "minipc pfsense"

[–] dubyakay@lemmy.ca 1 points 2 months ago (2 children)

Okay. Finally getting some results. I swear "micropc", sff etc did not yield results.

These ~C$150 devices will still need a Wi-Fi adapter connected to them though, right?

[–] nitrolife@hikki.team 1 points 2 months ago

If the seller doesn't have a WiFi bundle, then yes. If they do, you'll just need to pay extra.

I also recommend looking for a mini PC with Intel N100, N200, etc.

[–] eleitl@lemmy.zip 1 points 2 months ago

I would recommend to always use access points for that. A used (fanless) enterprise PoE switch comes handy to power several which are spread over the house.

[–] EncryptKeeper@lemmy.world 7 points 2 months ago

Do you live in the United States? If so the only reasonable option for a router at this exact point in time is to run your own using opnsense or PFsense. You can buy an x86 mini pc with with a couple high bandwidth NICs and it’ll do the job

[–] French75@slrpnk.net 4 points 2 months ago

I bought a minipc and put OPNsense on it. Its been just over a year now. Very flexible, very easy, and rock solid.

[–] Cyber@feddit.uk 2 points 2 months ago

If you're not wanting to customise too much, the Frtizbox equipment is good.

Plenty headroom for normal use.

However if you have 6 people all streaming 4k netflix and need 1mSec ping for gaming over a 10Gb link, you'll probably need to build something.

[–] CannedYeet@lemmy.world 2 points 2 months ago

I have an OpenWRT One. It comes with OpenWRT preinstalled (duh) and some proceeds go to fund the project.

[–] signalsayge@infosec.pub 1 points 2 months ago

If your router works for everything but that, I would recommend looking into Tailscale instead of a Wireguard VPN or run a Cloudflare tunnel as a service on the Debian host. Tailscale is free for personal use and is Wireguard under the hood with an orchestrator bolted on. I have done just about everything here has said at some point. I'm running a 10Gbps capable OPNSense firewall. For services outside my network I have several LXC containers with Cloudflare tunnels (broken out by service type) and I have Tailscale installed on one of my physical Debian hosts as an exit node.

If you just want access to everything while your out, Tailscale for your devices. If you want friends to be able to access, then Cloudflare tunnel. Neither require buying anything new.

[–] Decronym@lemmy.decronym.xyz 1 points 2 months ago* (last edited 2 months ago)

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:

Fewer Letters More Letters
LXC Linux Containers
PoE Power over Ethernet
SSD Solid State Drive mass storage
VPN Virtual Private Network

4 acronyms in this thread; the most compressed thread commented on today has 7 acronyms.

[Thread #276 for this comm, first seen 6th May 2026, 20:40] [FAQ] [Full list] [Contact] [Source code]