Building Blue Canoe · 1 of 2
Pre-Tik and Post-Tik: The Router That Unblocked Everything
How replacing a constrained ISP router unlocked Blue Canoe's wider DNSSEC, mail and network programme.

Originally published on LinkedIn on 12 August 2026. This is the permanent Blue Canoe edition, with dated technical updates where the work subsequently progressed.
Update, 25 August 2026: The dependency chain described here has since been completed. Authoritative DNS is operational across all 22 managed zones, with all 11 expected DNSSEC chains validating successfully. The replacement three-node mail platform and DANE are deployed and operational; the latest mail production rerun passed all 31 routine checks.
The headline reason for replacing our router was simple: the fibre connection was being upgraded to 8Gb, and the ISP-supplied Arris was only useful up to about 2.5Gb. The more important reason was DNS.
I wanted DANE for the mail platform. DANE required DNSSEC. DNSSEC meant taking proper control of authoritative DNS. The Arris could not support the DNS architecture I needed, and its backplane and internal limitations were already making it unsuitable for a server environment that had grown well beyond 1Gb.
That gave the build order a fairly unforgiving dependency chain: fix the edge first, then DNS and DNSSEC, then mail, with DANE added once the live endpoints and certificates were settled. There was no point starting further up the stack while the foundation prevented it.
Choosing the replacement
We looked at a lot of routers. I was not trying to join a vendor religion; I wanted the right balance of performance, control, price and simplicity. On that basis the MikroTik RB4011s won hands down.
The design was deliberately modular. The primary RB4011 connects directly to the ONT over its 10Gb SFP+ interface and carries aggregate north/south traffic. The servers retain 1Gb interfaces for ordinary service traffic, while a separate 10Gb switching fabric provides the fast east/west path for replication, migrations, logging, repositories, backups and other machine-to-machine work. A second RB4011 handles the separate 1Gb backup line.
Wi-Fi was deliberately kept out of the routing decision. An Omada access point now provides the radio layer and the MikroTik remains the router. It is a mixed-vendor setup, and it has been rock solid end to end. I increasingly think of infrastructure as Lego: each component should have a clear job and bolt cleanly onto the next.
I expected a trial
I was prepared for this to take a month. Plans rarely survive first contact with real infrastructure unchanged, and replacing the edge of a live network is an excellent place to discover what you did not know.
In reality we were live in two days.
The moment that mattered was the first successful test through the MikroTik. Until then the design was still a plan. Seeing real traffic pass through it was a considerable relief. From there the build moved quickly.
That speed was not because we skipped the thinking. Quite the opposite. A lot of the work had already happened before the first production change: comparing hardware, mapping dependencies, deciding where 10Gb actually mattered, preserving rollback paths and working out what had to remain boring.
Control was the real upgrade
The 8Gb headline is useful, but bandwidth turned out not to be the biggest win. The important change was that the edge stopped being something I had to work around.
We gained explicit control of routing and of our public /28. We gained visibility into interface state, traffic, errors and thermals. We could build a DNS architecture that the old router had prevented. Later, adding things such as WireGuard became a small, understandable extension rather than another workaround.
The router moved from being a recurring concern in the back of my mind to something I hardly think about.
Pre-Tik and post-Tik
There is now a very definite pre-Tik and post-Tik period in this network.
Before it, the edge constrained what came next. After it, the question changed from “can the router cope with this?” to “what should we build next?”
The MikroTik did not finish the infrastructure project. It made the rest of it possible. DNS came next, then DNSSEC and the mail platform. DANE would follow once the live mail endpoints and certificates were settled. The router was the key that unlocked the dependency chain.
The best compliment I can give it is also the least exciting: most days, it just sits there doing its job. On a network, boring is good.