Anti-virus on router level

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
32,474
Reaction score
9,468
I have provided some links about ISP and Router vendor provided security offerings in the following thread.
https://forums.hardwarezone.com.sg/threads/isp-and-router-vendor-security-related-offerings.6938654/
ISP offering will have monthly subscription.

Comsumer Router based offerings may have both free and paid option.

Consumer Router vendors also partnered with security vendors.

1) Asus AIProtection powered by Trend Micro
Free bundle with Asus rotuers (AIProtection Classic and AIprotection Pro)
https://www.asus.com/content/aiprotection/
2) TP-Link HomeCare, free with a few TP-Link Routers, powered by Trend Micro
https://www.tp-link.com/sg/homecare/
3) TP-Link Homeshield (free) and Homeshield Pro (one month free trial, S$8.98 per month) for newer AX models and Deco models, powered by Avira
https://www.tp-link.com/sg/homeshield/
4) Netgear Armor, powered by BitDefender (unlimited devices, include BitDefender Security and BifDefender VPN), S$99.99 annual subscription
https://www.netgear.com/sg/home/services/armor/
5) Linksys does not see to have such offerings
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
32,474
Reaction score
9,468
For newer Asus AX routers, I will recommend typical users to turn on AIprotection. I checked it on Asus RT-AX82U (my previous main router with lower end BCM6750 CPU) and RT-AX86U (my current router with higher end BCM4908 CPU), and it is running okay without slowing down the router. This is unlike Adaptive QoS which will significantly slow down the network speed.

I am not using AIprotection myself with my Asus RT-AX86U -- I use Pi-hole or Adguard Home instead (as LxC containers on another machine in the home network). I also use uBlockOrigin browser extension with Google Chrome which is my main browser to use under Windows/Linux/macOS.

Under Windows, I am also using the built-in Windows Security functions. I do not really use anit-virus under Linux and macOS.

With all these protection, I will still say users need to be careful and it is good to learn some basic knowledge about Cyber Cecurity.

CSA Singapore (a government agency) has some tips for the general public.
https://www.csa.gov.sg/information-for/general-public
 
Last edited:

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
32,474
Reaction score
9,468

Hafi

Arch-Supremacy Member
Joined
Mar 30, 2003
Messages
15,380
Reaction score
5,360
I see that nowadays, anti virus are on router which block malicious links, etc.

Did anyone turn them on?

why and why not?


Sent from A universe Where pink PWNED everything
Privacy issue... if the AV bundled on the router is free so who is the product?

If you are ok with the AV scanning (ahem... collecting data) whatever on your network is transmitting/receiving then no issue with that.
 

iduncheckmail

Supremacy Member
Joined
Nov 24, 2002
Messages
5,934
Reaction score
2,475
no point la.
I tried the asus one , but the network like slowed down and sites this cannot load that cannot load.
use internet until wana vomit blood
 

yusoffb01

Arch-Supremacy Member
Joined
Jun 17, 2008
Messages
16,594
Reaction score
1,658
I see that nowadays, anti virus are on router which block malicious links, etc.

Did anyone turn them on?

why and why not?


Sent from A universe Where pink PWNED everything

The ones in router is not real antivirus, its just a list maintained by the antivirus company to known malware sites.

Sign up for adguard and add your blocklists, especially osid which blocks: Ads, (Mobile) App Ads, Phishing, Malvertising, Malware, Spyware, Ransomware, CryptoJacking, Scam ... Telemetry/Analytics/Tracking
uAibdlj.png


set the timeout of block to be 1800s instead of default 10s so it is more responsive. then set your router dns to the custom one in your account.

the free tier of 300k is enough for one month. if it burst, you can set your secondary dns on router to adguard default https://adguard-dns.io/kb/general/dns-providers/
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
32,474
Reaction score
9,468
The ones in router is not real antivirus, its just a list maintained by the antivirus company to known malware sites.

Sign up for adguard and add your blocklists, especially osid which blocks: Ads, (Mobile) App Ads, Phishing, Malvertising, Malware, Spyware, Ransomware, CryptoJacking, Scam ... Telemetry/Analytics/Tracking
uAibdlj.png


set the timeout of block to be 1800s instead of default 10s so it is more responsive. then set your router dns to the custom one in your account.

the free tier of 300k is enough for one month. if it burst, you can set your secondary dns on router to adguard default https://adguard-dns.io/kb/general/dns-providers/

This Adguard DNS is a bit slow in Singapore. Good to know you have a work-around and that free tier is good enough.
https://adguard-dns.io/en/license.html

NextDNS may be a bit more popular as it offers free tier earlier.
https://nextdns.io/pricing

ControlD does not offer free tier, but it is quite a bit faster than Adguard. It does provide free public DNS server (quite some options) like Adguard public DNS servers.
https://controld.com/plans?step=plans

Cisco OpenDNS provides free OpenDNS Home and paid OpenDNS Home VIP.
https://www.opendns.com/home-internet-security/
 

yusoffb01

Arch-Supremacy Member
Joined
Jun 17, 2008
Messages
16,594
Reaction score
1,658
This Adguard DNS is a bit slow in Singapore. Good to know you have a work-around and that free tier is good enough.
https://adguard-dns.io/en/license.html

NextDNS may be a bit more popular as it offers free tier earlier.
https://nextdns.io/pricing

ControlD does not offer free tier, but it is quite a bit faster than Adguard. It does provide free public DNS server (quite some options) like Adguard public DNS servers.
https://controld.com/plans?step=plans

Cisco OpenDNS provides free OpenDNS Home and paid OpenDNS Home VIP.
https://www.opendns.com/home-internet-security/
didnt know adguard was slow. been using a few months.

cisco is another good one for secondary dns. Block page look so atas.

i stopped the google pihole which worked well for years. then when they change free tier, i couldnt get the 10c per month even after configuring.

also have opnsense but didnt bother to configure dns.
 

BradenHeat

Supremacy Member
Joined
Apr 4, 2005
Messages
7,314
Reaction score
1,610
if something cheap and expandable , do take a look at [ gl-inet's axt1800 ] , am using it daily, either work testing or as a DHCP router



As its base on Openwrt, and its modular [ Adguard as its main selling point ] , LuCI advance setting to load up more security



to answer, the inbuilt is VERY BARE minimum, unlike to prevent malicious attachements or spreading of virus much .

but if more than required for ease of mind, what xiaofan mentioned about pfsense, or [ firewalla ] or [ ubiquity ] may help abit more with their own proprietary IDS/IPS [ Intrustion Detection System / Intrustion Prevention System ]

next level, above pro-sumer mentioned, would be all out NGFW with endpoint clients per devices

p.s i would avoid TP link, as there is no guarantees what kind of information might be transmitted or data logging .

they come pre-bundled because its free money for them to track sites and user profile in general
 

Hafi

Arch-Supremacy Member
Joined
Mar 30, 2003
Messages
15,380
Reaction score
5,360
if something cheap and expandable , do take a look at [ gl-inet's axt1800 ] , am using it daily, either work testing or as a DHCP router

p.s i would avoid TP link, as there is no guarantees what kind of information might be transmitted or data logging .

they come pre-bundled because its free money for them to track sites and user profile in general
just FYI which maybe you didn't know

gl-inet is also chinese based company (operation from HK), if you do like to use gl-inet devices, I would recommend you avoid their Goodcloud service.
 

BradenHeat

Supremacy Member
Joined
Apr 4, 2005
Messages
7,314
Reaction score
1,610
nah
just FYI which maybe you didn't know

gl-inet is also chinese based company (operation from HK), if you do like to use gl-inet devices, I would recommend you avoid their Goodcloud service.
i do know theyre semi-china base.

only openwrt + adguard drew me, to the conclusion recommending

still MUCH better than TP link or Xiaomi routers, in default os

Comparatively speaking, ive used a range of routers and brands, think Gl-iNet is a clear winner for me, as i can get [ vlan, adguard, wireguard, hardened wireless , virtual enhanced firewall etc ] all for that price

the closest to get most bang for buck, is Firewalla with its dockers
both HK companies, but using semi-open-sourced base

and out of the box experiences, still much easier AND secure


i can easily ask a non tech person, buy gl-inet slate ax , talk through video call, and get it done with adguard and other smaller software packages done within 1hrs


Asus with custom firmware merlin ? not a chance.

Pfsense and other inbetweens ? i would become a free labour ,

Ubuqity, ive not been pushing, due to their nonsense subscription bs recently, and if they have been toying with the idea, i cannot in all likely hood, risk my extended family

no shiating on your post, Hafi, just throwing this info out for those looking to secure their home, without splurging too much or diving TOO MUCH GOD DANG TIME on dockers and terminal / ssh putty asus

i used to be that [ mesh is KING !] to [ GAMING Router FTW !] phrase :s13: :s13: :s22: :s22: =:p:o:o:s34:
 

Hafi

Arch-Supremacy Member
Joined
Mar 30, 2003
Messages
15,380
Reaction score
5,360
nah

i do know theyre semi-china base.

only openwrt + adguard drew me, to the conclusion recommending

still MUCH better than TP link or Xiaomi routers, in default os

Comparatively speaking, ive used a range of routers and brands, think Gl-iNet is a clear winner for me, as i can get [ vlan, adguard, wireguard, hardened wireless , virtual enhanced firewall etc ] all for that price

the closest to get most bang for buck, is Firewalla with its dockers
both HK companies, but using semi-open-sourced base

and out of the box experiences, still much easier AND secure


i can easily ask a non tech person, buy gl-inet slate ax , talk through video call, and get it done with adguard and other smaller software packages done within 1hrs


Asus with custom firmware merlin ? not a chance.

Pfsense and other inbetweens ? i would become a free labour ,

Ubuqity, ive not been pushing, due to their nonsense subscription bs recently, and if they have been toying with the idea, i cannot in all likely hood, risk my extended family

no shiating on your post, Hafi, just throwing this info out for those looking to secure their home, without splurging too much or diving TOO MUCH GOD DANG TIME on dockers and terminal / ssh putty asus

i used to be that [ mesh is KING !] to [ GAMING Router FTW !] phrase :s13: :s13: :s22: :s22: =:p:o:o:s34:
yea I get what you sayin... no need to get too sexcited. :ROFLMAO:

I personally using gl-inet BRUME2 as my DHCP router and twin Asus AX92U (merlin fork) as an AP and a mesh node.
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
32,474
Reaction score
9,468
Comparatively speaking, ive used a range of routers and brands, think Gl-iNet is a clear winner for me, as i can get [ vlan, adguard, wireguard, hardened wireless , virtual enhanced firewall etc ] all for that price

the closest to get most bang for buck, is Firewalla with its dockers
both HK companies, but using semi-open-sourced base

and out of the box experiences, still much easier AND secure

Hmm, I think Firewalla is not a Hong Kong company, rather it is a US company based in San Jose (California).

GL.iNet is headquarted in Hong Kong.

Firewalla: GNU Affero General Public License v3.0
https://github.com/firewalla/firewalla

GL.iNet licence: GNU General Public License 2.0 as it is based on an older version of OpenWRT.
https://github.com/gl-inet/openwrt

The reason I do not like GL.iNet is precisely because it is not based on main line of OpenWRT but rather an old version. They make good HW and as of now nice customization. But I am not so sure if they can really keep up a few years down the road.

I prefer to use mainline OpenWRT myself and I would not really recommend GL.iNet as the main router for home network, even though it is very good as a travel router.
 
Last edited:

cstanhwz

Master Member
Joined
Dec 31, 2005
Messages
3,335
Reaction score
234
I leave the AiProtection Pro "on" on my Asus XT8.

And I have Norton 360 installed on my PC too.

Sometime, accessing some websites, my Norton will pop up with the message saying a malicious attached had been blocked.

So the AiProtection Pro on the XT8 is not blocking all attacks.

But I still leave it "on".
 

BradenHeat

Supremacy Member
Joined
Apr 4, 2005
Messages
7,314
Reaction score
1,610
Hmm, I think Firewalla is not a Hong Kong company, rather it is a US company based in San Jose (California).

GL.iNet is headquarted in Hong Kong.

Firewalla: GNU Affero General Public License v3.0
https://github.com/firewalla/firewalla

GL.iNet licence: GNU General Public License 2.0 as it is based on an older version of OpenWRT.
https://github.com/gl-inet/openwrt

The reason I do not like GL.iNet is precisely because it is not based on main line of OpenWRT but rather an old version. They make good HW and as of now nice customization. But I am not so sure if they can really keep up a few years down the road.

I prefer to use mainline OpenWRT myself and I would not really recommend GL.iNet as the main router for home network, even though it is very good as a travel router.
Still much easier to recommend out of the box

for starters

firewalla was ex engineers from Cisco
But their forum support and people there are abysmal

there’s one dude ranting how he is desk top support and firewalla products should not fail

which made me cringe to wonder why his current company at that time still have him on payroll :s22::spin::s22:

as for openwrt being back a gen, still much better than Hua Wei / dlink/ tp link routers
 

BradenHeat

Supremacy Member
Joined
Apr 4, 2005
Messages
7,314
Reaction score
1,610
I leave the AiProtection Pro "on" on my Asus XT8.

And I have Norton 360 installed on my PC too.

Sometime, accessing some websites, my Norton will pop up with the message saying a malicious attached had been blocked.

So the AiProtection Pro on the XT8 is not blocking all attacks.

But I still leave it "on".

rather you just have common sense web surfing habits with strengthened windows group policies with inbuilt defender

360 barely can keep up with todays attacks without consuming tons of system resources to be honest
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
32,474
Reaction score
9,468
as for openwrt being back a gen, still much better than Hua Wei / dlink/ tp link routers

Hmm, it is like two generations behind.

It is based on 19.07 as per github (if they keep up with GPL license requirement, this repo should be the latest from GL.iNet), which is EOLed by OpenWRT project.
https://github.com/gl-inet/openwrt

OpenWRT release: current stable release version 22.03, old stable release 21.03. Version 19.07 is EOLed.
https://openwrt.org/releases/start
 

BradenHeat

Supremacy Member
Joined
Apr 4, 2005
Messages
7,314
Reaction score
1,610
Firmware VersionOpenWrt 21.02-SNAPSHOT r16399+159-c67509efd7 / LuCI openwrt-22.03 branch git-21.284.67084-e4d24f0

explains why they reply slowly on requests, some years behind
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
32,474
Reaction score
9,468
Firmware VersionOpenWrt 21.02-SNAPSHOT r16399+159-c67509efd7 / LuCI openwrt-22.03 branch git-21.284.67084-e4d24f0

explains why they reply slowly on requests, some years behind

This is better, only one generation behind.

That means their github site is kind of outdated.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ. Forum members and moderators are responsible for their own posts.

Please refer to our Community Guidelines and Standards, Terms of Service and Member T&Cs for more information.
Top