Thanks for Davids build. Bought 3200ACM as the best router existing (especially because of the desktop processing power) and tuned it properly to finally act like OpenVPN client for the whole network and "NAS" server. LEDE is absolutely horrible in configuration, everything needs to be tweaked on the command line. Doesn't hold a candle to ASUS Merlin in UI. Spent a month of two tunning, using mke2fs, bonnie, hdparm, tune2fs, dumpe2fs, smartctls, fdisk, cryptsetup, openssl, ssh, iptables tools and got what wanted:
- only SSH via keyfile & password and then sudo password to access root from outside
- IP restricted access from WAN to stupid clients (VPN bypass is so difficult, using "OpenVPN/WAN Policy-Based Routing" plugin but it works for domains only, so need to script iptables)
- HTTPS UI only from inside (LEDE user root to log in to UI - what??)
- blazing VPN speeds for all clients utilizing 90% of ISP speed (130Mbps), no need for i5/i7 Pro desktops to do the job anymore.. also mobile phones, while pretty fast, would othewise suffer speed degradation (cca -50%)
- *blazing NAS speeds for USB3 and eSATAp (yup, it's powered so a chinese 4$ cable is enough to connect a drive), using a single 2.5" 4TB RAID0 Seagate drive (reason: each spinning drive is -50% slower at the end, my setup guarantees 110MB/s samba speed *everywhere*)
- blazing multiple encrypted drives speeds on OpenVPN-grade encryption
- antivirus, adblocker, dnscrypt etc running
- custom scripts to monitor status of connected drives, internet connectivity and auto fix it, report this activity by changing LED diodes (color, graphic effect) in realtime (cute feature of Linksys)
- boosted WiFi signals, custom antennas etc etc
Looks good. Looks better than Asus GT router.
*Some guys wrote Samba slows down, not possible. Samba is bad in network discovery, bad in client interpretation (no thumbnails often), bad in failover (can get stuck, and confused by deleted files), but it uses full network link capacity. That's why i can enjoy perfect 90MB/s on SHA256 drive via Samba. And with journal. Toughest conditions only. 110-115MB/s on public drive. You get basically what you see in "openssl bench". No other router can do.
Other explanation can be: USB2, poor drive, poor filesystem driver (NTFS3G is a horrid crippled driver, you need a full version from Tuxera/Paragon, as in the stock firmware, but but.. they don't sell it separately). It can be investigated on router with available packages bwm-ng or bonnie.
Now all this happiness was followed by disappointment when i realized cannot save my configuration. So im not updating. I will wait for some magic build with NEON and final mwlwifi and go through the horror once again. Every little set up action matters, including every little file permission set, every init or hotplug script set, and this firmware just can't save the configuration. Sad! ASUS Merlin never ever disabled a single setting, and it's close to updating itself alone. LEDE, meanwhile, left me with corrupted upgrade I had to quit by tripple power off.
Thanks!