44Net Connect/Quick Start/Fedora: Difference between revisions
Wrote install dependencies section |
Updated automatic start instructions to use automatically generated systemd unit |
||
| (One intermediate revision by the same user not shown) | |||
| Line 22: | Line 22: | ||
The third line, beginning with "Active," should indicate that the unit is active (running). | The third line, beginning with "Active," should indicate that the unit is active (running). | ||
If it's not, run <code>systemctl start systemd-resolved</code> to start the unit. This will ensure that the unit is currently running. | If it's not, run <code>systemctl start systemd-resolved</code> to start the unit. This will ensure that the unit is currently running. | ||
== Configure your WireGuard client == | |||
* Create a new file for your WireGuard configuration in <code>/etc/wireguard/</code>, for example <code>/etc/wireguard/wg0.conf</code>. | |||
* You can name this file however you want, but this file name will become the name of your WireGuard interface. | |||
* Paste the configuration text in from 44Net Connect, or if you prefer to use the file that was emailed to you, upload that one. | |||
[[File:wireguard_tunnel_config.png|500px]] | |||
The first time you create your tunnel, the private key will be present in the config for you to copy. Every subsequent time you view the config in the portal, the private key will not be shown. Saving a backup of the private key in a secure place is recommended. | |||
After creating your config file, set its permissions so that only the owner has read or write permissions. This can be done with the command <code>sudo chmod 600 /etc/wireguard/wg0.conf</code>. (Replace <code>wg0</code> with the name of your file.) | |||
== Activate and connect == | |||
=== Activate your tunnel === | |||
Run the command <code>wg-quick up wg0</code> (replace <code>wg0</code> with the name of your configuration file if different). | |||
=== Confirm Connection in the Connect dashboard === | |||
* Your tunnel status should show as "Active" with a green indicator. | |||
[[File:wireguard_tunnel_connected.png|500px]] | |||
* The <code>Endpoint</code> field should show the IP address your device is connecting from, as well as the port it's using. This is not the 44Net IP from which your device is publicly accessible. | |||
=== Other Ways to Confirm Connection === | |||
* Visit https://connect.44net.cloud/myip in your browser, or query it from the command line using <code>curl https://connect.44net.cloud/myip</code> | |||
* Use <code>traceroute</code> to inspect the path between you and some other device, such as <code>traceroute 1.1.1.1</code>. When the tunnel is working, the first hop will be through a 44Net gateway, so its IP will be in the <code>44.0.0.0/9</code> or <code>44.128.0.0/10</code> subnet. | |||
== Starting the Tunnel Automatically == | |||
* On Linux distributions that use <code>systemd</code>, using the <code>systemd</code> unit automatically generated by <code>wg-quick</code> is the recommended way to automatically start the tunnel. These are automatically created for any config file in <code>/etc/wireguard</code>. | |||
* The automatically created unit is called <code>wg-quick@<config file name>.service</code>, so a file <code>/etc/wireguard/wg0.conf</code> would make <code>wg-quick@wg0.service</code>. | |||
* Enable and start the service by running <code>sudo systemctl enable --now wg-quick@<config file></code>, where <code><config file></code> is replaced with the name of your config file without the extension. | |||
* Verify that the service has started by running <code>systemctl status wg-quick@<config file></code> and checking that it says enabled and active, the same way we previously checked that systemd-resolved was working. | |||
[[Category:Tutorial]] | |||
[[Category:How-To]] | |||
[[Category:Participation Methods]] | |||
[[Category:44Net Connect]] | |||
[[Category:Getting Started]] | |||
Latest revision as of 17:42, 20 August 2026
What you need
- A 44Net Portal account
- A verified amateur radio callsign
- A configuration file from 44Net Connect
- A device running Fedora Linux
- Some sort of Internet access
If you haven't set up your Portal account or verified your callsign yet, see 44Net: Get Started for instructions. If you haven't obtained a WireGuard tunnel configuration file from 44Net Connect, get one using the the 44Net Connect quick start guide
Install Dependencies
Step 1: Ensure your OS is up to date
Update your system packages using either your GUI tool of choice, or by opening
a terminal and running sudo dnf update && sudo dnf upgrade.
Step 2: Install wireguard
Run sudo dnf install wireguard-tools.
Step 3: Verify that systemd-resolved is enabled
systemd-resolved comes installed by default on Fedora. Ensure that it's running by executing systemctl status systemd-resolved in your terminal. If the unit is running without issues, there will be a green circle at the top left. The second line, beginning with "Loaded," should indicate that the unit is enabled. If it's not, run systemctl enable systemd-resolved to enable the unit. This will ensure that the unit starts automatically when your Fedora machine boots from now on.
The third line, beginning with "Active," should indicate that the unit is active (running).
If it's not, run systemctl start systemd-resolved to start the unit. This will ensure that the unit is currently running.
Configure your WireGuard client
- Create a new file for your WireGuard configuration in
/etc/wireguard/, for example/etc/wireguard/wg0.conf. - You can name this file however you want, but this file name will become the name of your WireGuard interface.
- Paste the configuration text in from 44Net Connect, or if you prefer to use the file that was emailed to you, upload that one.
The first time you create your tunnel, the private key will be present in the config for you to copy. Every subsequent time you view the config in the portal, the private key will not be shown. Saving a backup of the private key in a secure place is recommended.
After creating your config file, set its permissions so that only the owner has read or write permissions. This can be done with the command sudo chmod 600 /etc/wireguard/wg0.conf. (Replace wg0 with the name of your file.)
Activate and connect
Activate your tunnel
Run the command wg-quick up wg0 (replace wg0 with the name of your configuration file if different).
Confirm Connection in the Connect dashboard
- Your tunnel status should show as "Active" with a green indicator.
- The
Endpointfield should show the IP address your device is connecting from, as well as the port it's using. This is not the 44Net IP from which your device is publicly accessible.
Other Ways to Confirm Connection
- Visit https://connect.44net.cloud/myip in your browser, or query it from the command line using
curl https://connect.44net.cloud/myip - Use
tracerouteto inspect the path between you and some other device, such astraceroute 1.1.1.1. When the tunnel is working, the first hop will be through a 44Net gateway, so its IP will be in the44.0.0.0/9or44.128.0.0/10subnet.
Starting the Tunnel Automatically
- On Linux distributions that use
systemd, using thesystemdunit automatically generated bywg-quickis the recommended way to automatically start the tunnel. These are automatically created for any config file in/etc/wireguard. - The automatically created unit is called
wg-quick@<config file name>.service, so a file/etc/wireguard/wg0.confwould makewg-quick@wg0.service. - Enable and start the service by running
sudo systemctl enable --now wg-quick@<config file>, where<config file>is replaced with the name of your config file without the extension. - Verify that the service has started by running
systemctl status wg-quick@<config file>and checking that it says enabled and active, the same way we previously checked that systemd-resolved was working.