Brutkey

Matthew Garrett
@mjg59@nondeterministic.computer
Matthew Garrett
@mjg59@nondeterministic.computer

…oh wait there's no actual reason my IPv6 gateway has to be the same as my IPv4 one, is there? Something else on my network can terminate the tunnel and RA

Matthew Garrett
@mjg59@nondeterministic.computer

Sigh nope clamping the ethernet interfaces to 1480 doesn't help

Matthew Garrett
@mjg59@nondeterministic.computer

Nope echo 1 >/proc/mt7621/hw_nat and immediately anything going via the IPv6 tunnel ends up with missing fragments. Hmm. Maybe I can try something awful.

Matthew Garrett
@mjg59@nondeterministic.computer

Oh wait hang on Ubiquiti released their first firmware update for this in two years last week let me try that first

Matthew Garrett
@mjg59@nondeterministic.computer

Ok fuck this I've worked around enough misfeatures on this thing. I need a router that:
* Has no wifi. No, I don't want to just turn it off. No wifi.
* Runs off PoE.
* Gigabit copper, no SFP, I do not need 2.5GBps.
* Handles ipsec and GRE tunneling. I need no other VPN support.
* Ideally at least 4 ethernet ports, otherwise I'm going to need to buy another switch.
* Can sustain bidirectional gigabit either without relying on hardware offload or with offload that works in all the above cases

Matthew Garrett
@mjg59@nondeterministic.computer

* Small. If it's rack-mountable it's way too big.
* No fan.
* An actual product, I do not want to have to build it myself.
* I'm sure I'll find arbitrary ways to decide that whatever you suggest doesn't fit my arbitrary criteria but please suggest anyway

Matthew Garrett
@mjg59@nondeterministic.computer

Ok fuck this I've worked around enough misfeatures on this thing. I need a router that:
* Has no wifi. No, I don't want to just turn it off. No wifi.
* Runs off PoE.
* Gigabit copper, no SFP, I do not need 2.5GBps.
* Handles ipsec and GRE tunneling. I need no other VPN support.
* Ideally at least 4 ethernet ports, otherwise I'm going to need to buy another switch.
* Can sustain bidirectional gigabit either without relying on hardware offload or with offload that works in all the above cases