44Net Connect: Difference between revisions
// via Wikitext Extension for VSCode |
mw push |
||
| (31 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
44Net Connect | {{DISPLAYTITLE:44Net Connect}} | ||
__NOTOC__ | |||
44Net Connect gives your device or network public IP addresses through a {{Term|WireGuard}} tunnel over your existing internet connection. ARDC operates the endpoint at the other end of the tunnel and routes traffic between your equipment and the Internet. | |||
You can use it to host services, reach station equipment remotely, or experiment with networking. | |||
== Before you start == | |||
You’ll need a [[Portal/Sign Up|Portal account]] with a [[Verification|verified amateur radio callsign]], an existing internet connection, and a device or router that can run WireGuard. | |||
You do not need to request addresses separately in the Portal. Connect assigns the device’s addresses when you create a tunnel. For a routed subnet, request a network in the Connect dashboard and attach it to your tunnel. | |||
Connect can work behind {{Term|NAT}} or {{Term|CGNAT}}, including on residential broadband, mobile, and satellite connections. Your connection must allow WireGuard traffic to reach the Connect endpoint. | |||
== What would you like to connect? == | |||
=== | |||
=== Single device === | |||
Run WireGuard on the device you want to connect, such as a Raspberry Pi, server, router, cellular hotspot, or laptop. When you create a tunnel, Connect issues an IPv4 address, an IPv6 address, and a configuration for that device. You don’t need to request a separate address assignment before creating the tunnel. | |||
This is a useful place to start if you want to connect one system. | |||
'' | '''[[44Net Connect/Quick Start|Set up a single device →]]''' | ||
See [[44Net Connect/Supported Platforms|device guides]] for platform-specific instructions, or read more about [[44Net Connect/Single Device Tunnel|single-device tunnels]]. | |||
=== Multiple devices or a network === | |||
You can either create a tunnel for each individual device, or run WireGuard on a router or gateway that connects a group of devices. The gateway handles the tunnel and routes traffic for the devices behind it. The individual devices do not need to run WireGuard themselves. | |||
This involves configuring addressing, routing, and firewall rules for the network as well as the tunnel. | |||
'''[[44Net Connect/Routed Subnet|Plan and set up a routed subnet →]]''' | |||
== What happens during setup? == | |||
You sign in to the [https://connect.44net.cloud Connect dashboard] using your Portal account, choose an endpoint, and create a tunnel. The dashboard supplies a WireGuard configuration to install on your device or gateway. The linked guides cover the steps for each setup. | |||
Your Portal account at [https://portal.ampr.org/ portal.ampr.org] holds your identity and callsign verification. The separate Connect dashboard at [https://connect.44net.cloud connect.44net.cloud] is where you manage tunnels and obtain their configurations. | |||
{{SectionFigure|file=44Net_Connect_overview.png|caption=Traffic between the Internet and your Connect addresses passes through a Connect endpoint and the WireGuard tunnel to your equipment.}} | |||
== Securing your connection == | |||
You decide which services to run and make accessible. Incoming connections depend on your service configuration and firewall rules. Take care: an active tunnel can unexpectedly make every service accessible to the public Internet, so check your firewall and service settings before you activate the tunnel. See [[Firewalling Basics|firewalling basics]] for guidance. | |||
Your routing configuration determines which outgoing traffic uses the tunnel. You can route all traffic through it, or select traffic by destination or source address. Replies from your Connect address to public Internet clients may also need to use the tunnel; selecting only destinations within 44Net does not cover those replies. The procedures depend on your system. | |||
You | ARDC operates the Connect endpoints. You maintain your device or gateway, its software, and its firewall. | ||
WireGuard encrypts traffic between your equipment and the Connect endpoint; it does not provide end-to-end encryption beyond that endpoint. Connect does not provide anonymity or attach your network to the [[IPIP Mesh]] or other community projects, which have separate participation and routing arrangements. | |||
If you’re ready to get started, see [[44Net_Connect/Quick_Start|Quick Start]]. For help with setup or operation, see [[Get Help]]. | |||
[[Category:Explanation]] | |||
[[Category:Participation Methods]] | |||
[[Category:44Net Connect]] | |||
Latest revision as of 22:33, 30 September 2026
44Net Connect gives your device or network public IP addresses through a WireGuard tunnel over your existing internet connection. ARDC operates the endpoint at the other end of the tunnel and routes traffic between your equipment and the Internet.
You can use it to host services, reach station equipment remotely, or experiment with networking.
Before you start
You’ll need a Portal account with a verified amateur radio callsign, an existing internet connection, and a device or router that can run WireGuard.
You do not need to request addresses separately in the Portal. Connect assigns the device’s addresses when you create a tunnel. For a routed subnet, request a network in the Connect dashboard and attach it to your tunnel.
Connect can work behind NAT or CGNAT, including on residential broadband, mobile, and satellite connections. Your connection must allow WireGuard traffic to reach the Connect endpoint.
What would you like to connect?
Single device
Run WireGuard on the device you want to connect, such as a Raspberry Pi, server, router, cellular hotspot, or laptop. When you create a tunnel, Connect issues an IPv4 address, an IPv6 address, and a configuration for that device. You don’t need to request a separate address assignment before creating the tunnel.
This is a useful place to start if you want to connect one system.
See device guides for platform-specific instructions, or read more about single-device tunnels.
Multiple devices or a network
You can either create a tunnel for each individual device, or run WireGuard on a router or gateway that connects a group of devices. The gateway handles the tunnel and routes traffic for the devices behind it. The individual devices do not need to run WireGuard themselves.
This involves configuring addressing, routing, and firewall rules for the network as well as the tunnel.
Plan and set up a routed subnet →
What happens during setup?
You sign in to the Connect dashboard using your Portal account, choose an endpoint, and create a tunnel. The dashboard supplies a WireGuard configuration to install on your device or gateway. The linked guides cover the steps for each setup.
Your Portal account at portal.ampr.org holds your identity and callsign verification. The separate Connect dashboard at connect.44net.cloud is where you manage tunnels and obtain their configurations.

Securing your connection
You decide which services to run and make accessible. Incoming connections depend on your service configuration and firewall rules. Take care: an active tunnel can unexpectedly make every service accessible to the public Internet, so check your firewall and service settings before you activate the tunnel. See firewalling basics for guidance.
Your routing configuration determines which outgoing traffic uses the tunnel. You can route all traffic through it, or select traffic by destination or source address. Replies from your Connect address to public Internet clients may also need to use the tunnel; selecting only destinations within 44Net does not cover those replies. The procedures depend on your system.
ARDC operates the Connect endpoints. You maintain your device or gateway, its software, and its firewall.
WireGuard encrypts traffic between your equipment and the Connect endpoint; it does not provide end-to-end encryption beyond that endpoint. Connect does not provide anonymity or attach your network to the IPIP Mesh or other community projects, which have separate participation and routing arrangements.
If you’re ready to get started, see Quick Start. For help with setup or operation, see Get Help.