Openwrt is good as perimeter router, to protect against bugs

Just found from cvedetails that openwrt only got handful of bugs each year and usually got patched.
Last week I still use a TP1ink C2, which have a large hole before wannacry (2017), and
Still no update after wannacry! Even another D1ink 842, there are updates but
Seems don’t address the large hole. (both are code execution holes!)

So my opinion is openwrt good as outer router.

But I will still use an inner router, because that old buggy TP1ink C2 got MUCH
Better parental control. You can go see in TP1ink's website, the emulator.
It let you choose device(by mac/ip), target site(by url/ip), schedule time PLAN,
And then choose combination. Openwrt only choose device(mac/ip), target (by ip, no URL), exact time slot, And need enter all again for each entry. Openwrt can block URL by adblock but NO timing can be chosen.

Many people are against "double NAT", so far I am ok with it. And
Indeed I hope it provide further security to my PC.


Not true.

TP-LINK firmware is based on a very old version of OpenWRT so it's better to use the latest OpenWRT of you want to protect the router from known exploits.

but your method is like "block URL".
and cant set "block URL at a specific time range".

it's better than using adblock to block URL, as adblock will block for ALL device.

You can combine the block URL with time schedule.

pls show me,

using tp1ink, i just click click click is ok.

on openwrt, it really is not easy.

ps I grad-ed from university already, but a layman, not in IT

Visit the previous link I posted and create the rules with the url ipsets.
Then visit this link and append to the rule the time limit.

let me digest and reply within a week or so, thanks
hope it works.

unless those 2 pages are made into a GUI (even it's a webpage for clicking).
that's too much to "type" for a layman.

You can just copy-paste the whole code block.

tp1ink c2 use this way:

choose device by mac/ip
choose target by url/ip
choose a timetable

then allow you make rules base on above. (allow/deny).

I really dont think that table is as easy as tp1link's.
the table is not easy to understand.