283
people found this helpful, as of 2023
ranked #93,404 most helpful
out of 571,544,897 reviews
★★★★☆
Good performance, but worrisome pattern of firmware updates and nervousness about security
I am currently happily using this WiFi router, but my concerns about its security caused me leave my previous router between it and the Internet.
PRELIMINARIES:
0. Recognize that Amazon has mixed together reviews for a range of different models in this product family -- models that have very different performance, design, features, ... So check that the review is for the model you are considering.
1. Recognize that many of the earlier reviews here contain obsolete information -- problems that have been addressed by firmware upgrades. The 2013-March-19 upgrade added Guest Networking and fixed some other problems. The previous upgrade of 2012-Dec-25 fixed many bugs and performance problems. Having seen the earlier reviews and being a curious techie, I tried the original firmware found that that the _sample_ of reported problems that I could easily test were indeed fixed by the 2012-12-25 firmware.
If you get this device, do NOT disregard these updates thinking that they are only optional (that is, only for those having identifiable problems).
2. (update) Don't stop at the firmware upgrade of 2013-March-19--it has a major vulnerability that is being actively exploited (eg, Web search for CSRF and "router hijack"). There is a subsequent firmware upgrade (2013-06-17) whose description makes it seem innocuous and unnecessary for most users, that update seems to block the version of this exploit that I have access to.
3. The pattern of firmware updates is worrisome. Some of the problems fixed are to be expected: performance problems/enhancements and compatibility problems with certain other network devices. For these, I applaud the manufacturer for putting out fixes on a 3-4 month time scale. HOWEVER some of the other problems are things they should have been correct in the initial release, and consequently I worry about undetected/unfixed problems that remain, especially those related to security since that is a critical function of this device (more below).
In this review, _Security_ comes at the very end for compositional reasons, not because it is low priority.
----
My Background: I evaluate home WiFi Routers on three basic criteria: Security, Performance, and Features, and in that order. I place "Features" last because most home users, and me currently, will not need or use most of the more advanced features. I worked in computer/network security in the 1990s and early 2000s and computer networking starting in the 1980s. Being retired, I now have too small a set of devices to evaluate this router for more sophisticated or demanding settings.
Because friends and neighbors ask for help in setting up/fixing their network problems, I am also exposed to the perspective and choices of the typical home user. This review contains elements of interest to different groups: experts, mass-market consumers,... I have tried to structure the review to simplify your quickly ID'ing and skipping elements that are irrelevant to your interest/experience (not needed, too complicated, too trivial, ...).
----
Features: Summary: The features are as expected for this class of device.
This is unsurprising because this is largely dictated by the chipsets used, and there is relatively modest variability across the competing chipsets at any given time. Because the landscape is ever changing -- what the newest chipsets provide and what device is using which generation of chipset -- my advice is that you use web search to try to find the chipsets used by the various models of router you are considering and if successful look at the reviews of those chipsets as a precursor for comparing the overall router.
The software used in many brands of routers also comes from common software code bases (via different paths) but many manufacturers try to obscure this. And there are various combinations of components, versions-used and customizations-make. While the manual available for download is only minimally out-of-sync with the firmware, the documentation of some of the features is underspecified and can be resolved only through experimentation. But this is quite common for this class of device (not just this model or brand).
The USB printer port worked for my printers -- a Canon MFP and 2 different models of Samsungs. This was only a brief test because the primary printer and the MFP also have Ethernet interfaces (preferred). The utility program was easy to use and worked well.
The USB storage sharing feature also worked, although I don't expect to be using it -- no current need and concerns about the security of the implementation.
----
WiFi Performance: Good
Background: This is replacing a six year-old Buffalo Airstation WHR-G54S with its omnidirectional 2.2dBm antenna replaced by a Hawking Directional 15dB Corner Antenna (Model HAI15SC). I live in an old house that was extended and remodeled several times by previous owners. There are enough perplexing weak/dead spots in my house that I cannot project performance to more conventionally constructed houses.
I tested locations in and just outside my house using the (free) inSSIDer software tool with both routers within 3 feet of each other. In the 2.4 GHz band, the signal strength was equal or slightly better than that of the (enhanced) previous one. Of course, the difference between G and N protocols and 40MHz wide channels improved throughput considerably. For the 5 GHz band, I had no comparables.
I got about 8 Mbps speeds when connecting from across the street -- about 140 ft with some intervening tree foliage. The router is in a front room, but not near a window and my computer was just inside the neighbor's front window.
In the month of use, I have had no problems with the WiFi. No freezing. No unusual patterns of delays or larger latencies. My primary computer is in a separate room, through an open door but well out of line-of-sight, about 30 feet straight line distance.
----
WiFi antenna geometry and separation:
This device has detachable antennas, allowing those that understand optimization of antenna geometry to do so.
Additional spec: Antenna separation: 85 mm (left to center), 98 mm (center to right), 183 mm (left to right).
FYI: For the 2.4Ghz band, the wavelength is roughly 120-125mm; for the 5.0Ghz band, it is roughly 51-58mm.
Background: For a multiple antenna system (such as this), the geometry and separation of the antennas can have significant effect, but I don't know what scheme(s) this device uses and I am too out-of-date to judge whether this device has antennas that are positioned for performance or for manufacturing convenience. Example, one long-established multi-antenna scheme, "Diversity", benefits from having its two antennas separated by one wavelength.
----
Temperature: This device stays cool -- very close to ambient temperature. I have it in a fairly typical location: an out-of-the-way location on a table top that gets somewhat below-average air circulation. Explanation: Heat is a concern because it shortens the lifespan of electronics.
----
Auto-selection of WiFi channel and channel width: This is relevant primarily to a WiFi router that might have another such device placed close to it, such as in neighboring apartments or companies or departments in a suite of offices. Or not, depending on the nature of the walls in between. I live in a dense suburban setting, with my immediate neighbors' WiFi routers about 50 feet from mine, and we have yet to see any signs of interference (unsurprising based on the literature and my measurement of their signal strength as less than half of mine).
Auto-selection was designed for situations where good-enough could be achieved without _careful_ coordination, or where such coordination was impractical (difficult neighbors, rapidly changing environment,...) In these situations, a common practice is to periodically check for _significant_ channel selection conflicts and make appropriate adjustments (manual selection, coordination, increase distance of router from conflicts,...)
I experimented using my previous WiFi-G router to create conflicts, manually setting its channel to the three non-overlapping channels (1, 6, 11) to see how this device responded.
The auto-selection of channels seems to occur only when the router is booted. This is expected because many WiFi adapters (clients) have difficulties or failures if the channel is changed while connected. Usually, it made a non-conflicting choice, but twice it auto-selected channel 6 when the WiFi-G router in the same room was already on that channel, but without any transmissions with its client beyond keep-alives. When the WiFi-G router was on channel 6, this router would predominantly choose channel 11 although I couldn't detect any reason for it to prefer 11 to channel 1.
With auto-selection of channel width, I observed the width change a few times (using the inSSIDer tool) but I don't have the tools for a meaningful test.
----
Utility programs: Download the updated versions.
The EasySetupAssistant utility was fatally and opaquely confused because I connected the new router to a second Ethernet interface on my computer. It seems to do little other than prompt for basic configuration, minus the critical step of changing the default administrative account and password. My recommendation is to start with Web browser interface.
----
Mounting:
Although most people will have this device sitting horizontally, there are slots in the bottom to allow it to be mounted vertically (eg a wall), but there is no stand. The slots are designed to force nose-down or nose-up mounting because of the multi-antenna system. There is a very slight tilt to the indicator panel (on the front), but not enough to enable _easy_ reading when mounted vertically -- while I can see the _presence_ of the lights, I have to put my head close to the vertical surface, or use a mirror, to identify the icons.
----
User Interface and documentation:
The Web browser interface has a panel on the right providing a significant amount of documentation of features being configured, and typically is close to what is in the manual. While this is good for the UI, it represents a deficiency for the manual. The documentation goes beyond simply providing a few words to disambiguate the labels in the setting panels, but routinely falls short of giving the user enough information to make informed decisions. Examples:
1. On selecting what protocols to use, it says that if all your devices use "N", you can select "N only". It fails to mention that selecting "N only" is likely to improve performance. Consequently, the user is likely to unnecessarily leave the default+recommended setting of supporting all protocols on that band.
2. The router provides SW and HW NAT, but doesn't say why you might want to turn off HW NAT (Answer: There are some some devices/apps, particularly older ones, that don't conform to the assumptions built into HW NAT. If such are having problems connecting out to the Internet, try turning off HW NAT to see if that fixes the problem. Otherwise, leave it enabled).
3. "IP & MAC Binding": The explanation in the UI fails to distinguish this from "Address Resolution" under "DHCP". Most users will want the latter, but since it is buried one-step down whereas the former is in the LHS tabs, it is easy to pick the wrong one (a confusion that can be seen with web search). Furthermore, this name is ambiguous, covering a range of capabilities. One use involves preventing ARP spoofing. Another simply improves efficiency.
In most places, the UI does a very good job of providing error messages and warnings (eg need to reboot before settings take effect) and of indicating why a selection isn't available (need to enable X). However, there is no warning that when you install new firmware, all your settings will be lost (so first you need to back them up, then restore after the upgrade).
The quality of the writing in the documentation -- grammar, spelling and content -- was significantly better than I have come to expect for this type of product. The few passages that struck me as "bad" were in fact typical of what I encounter in many similar products (from China) -- awkward, but not unmanageable.
----
UI Annoyances:
The layout assumes that the browser window will be very wide, with things such as excessive space between columns obscuring that you need to scroll to find additional columns with important settings.
Significant amounts of the available status information is not under the "Status" tab, but under the tabs for the associated settings.
MAC addresses have to be in the hyphen-separator format whereas most of my MAC addresses used colons, thereby inhibiting cut-and-paste. I did a cut-and-paste of those addresses into a TXT file, then a search-and-replace, and then a cut-and-paste into the UI.
Some of the log files have Internet addresses in hex rather than dot notation (a0b0c12 for 10.11.12.18).
Lack of inheritance. For example, for entering addresses on the LAN, rather than providing the subnet address and having you enter just the host component, the UI has you enter the full address and (correctly) gives you an error message when you make the inevitable typos.
No uploading of tables: There are tables of data (address mappings, rules) that need to be entered manually that I would like to be able to upload from a TXT file. If you are trying to manage multiple routers, having such makes it much easier to keep all properly updated (no missing entries, no typos from manual entry).
************
SECURITY ISSUES
1. There is no provision for signing off from the administrative interface despite it being a basic security practice to absolutely minimize such connections. There has been a long, long string of exploits that hijack such connections. Of most relevance to the current home user, there is a class of malware that you unknowingly download from an infected web site and if this malware finds an open connection to your router, it modifies the configuration to let the miscreants take over your network.
ADVICE: Do not enable automatic supplying of account or password. The session is _not_ ended by a soft reboot (needed for many setting changes) nor by closing the tab in the browser (tested: Chrome, Firefox, IE10). You need to do a full restart of the browser or, better yet, power cycle the router.
2. Administrative account name and password need to be changed immediately. Both are well-known and are the first ones guessed. If the malware cited in (1) does not find an open connection, it tries to open one and the defaults make it trivial. Other malware that gets on your network will often try the same.
2a. The EasySetupAssistant does not prompt you to change these.
2b. To change this, you need to open the last tab "System Tools" and select "Password" (seventh entry).
3. The USB storage feature comes with an administrative account with the same first-guessed username and password, and with read-write access (shudder). As part of this, you can enable the router to be an FTP server, and make that FTP server accessible over the Internet. I RECOMMEND _AGAINST_ THIS -- see Appendix.
4. Protection from Denial-of-Service (DoS) attacks is turned off by default (under tab Security, under Advanced Security) and requires that you also turn on "System Tools" -> "Statistics" (there is a reminder in red of this). I do not understand why this wasn't enabled by default: My router logs show a set of ICMP/TCP/UDP flood attacks every day or two (much reduced frequency from several years ago) and NMAP probes (the documentation is silent on this).
5. The TFTP ALG (Application Layer Gateway) is enabled. TFTP is a badly obsolete protocol -- it lacks authentication and was designed for devices with miniscule amounts of memory and processing power. For at least 20 years, the widely accepted firewall rules haven't allowed TFTP except on the LAN. This makes me very nervous about all the invisible security decisions embedded in this product.
6. I could not find documentation of what firewall capabilities this router provides, leaving me to make inferences from similar products and the details of how to loosen the firewall security. I don't like having to make inferences because they can too easily be wrong.
7. The description of the 2013-March-19 firmware update includes "6. Fixed some vulnerabilities and improved security". For a device that has a crucial security function in my network, I want to be _notified_ of fixes and not have to periodically check the manufacturer's website to see if there are new releases. I couldn't even find where to register my purchase to enable them to send such notifications. Unfortunately, this failing is common in this category of devices.
And more questionable default settings (this review is intended to give you a sense of the product, not a tutorial).
---- Appendix: Security issues of an Internet-accessible FTP server on a router ----
The USB connectors on this router can be used for USB disks (Flash drive, HDD). The router can be configured to allow access from the WAN (referred to as the "Internet"). Do _NOT_ enable this unless you fully understand your situation and the serious risks (for example, the WAN port is connected to a LAN you control and/or trust). For virtually every use, collaborative storage in the Cloud (Google Drive, Microsoft's SkyDrive,...) is a better alternative.
1. Do you trust the implementation of the server? Among FTP server implementations, there is a long history of exploits that allowed miscreants to:
1a. break out of the FTP directories and modify system file and take over the whole system (your router).
1b. override access controls -- add or modify files when they should have read-only access. If you must do this, at least use a USB Flash Drive that has a physical read-only switch.
2. Do you trust your ability to select account names and passwords that will stand up to a concerted attack? If so, the empirical evidence is that you are fooling yourself. Realize that large sites protect against these attacks with additional software (Intrusion Detection Systems).
3. Do you think that because you have a home network of 1-3 computers, the miscreants won't find you or bother with you? Wrong. They have automated "bots" (software robots) constantly looking for precisely this situation because of the higher chance of success.
Why worry about someone out there on the Internet storing files on your FTP server without your knowledge/authorization? Think child porn. Law Enforcement Organizations (LEOs) in their ignorance and enthusiasm still routinely fail to consider other options for how such files might wind up on your computer. This is not "simply" a matter of time in jail and huge legal bills before the matter is sorted out, or of lingering damage to your reputation. During raids, the LEOs have a tradition of administering "rough justice", including things like allegedly throwing the handcuffed suspect head-first down stairs (the traditional "He tripped") -- this is a famous, widely-used motivational/cautionary story from WiFi hacking, but equally applicable to FTP servers.
-- Douglas B. Moran
May 2013 · Electronics