44Net Connect: Difference between revisions

From 44Net Wiki
// via Wikitext Extension for VSCode
mw push
 
(26 intermediate revisions by the same user not shown)
Line 1: Line 1:
44Net Connect is the quickest way to start participating in 44Net.
{{DISPLAYTITLE:44Net Connect}}
__NOTOC__


Instead of setting up BGP routing or IPIP Mesh, Connect establishes a WireGuard tunnel between your device and a Connect endpoint node. With the tunnel active, your system operates as a native 44Net host with its own address on the public Internet.
44Net Connect gives your device or network public IP addresses through a {{Term|WireGuard}} tunnel over your existing internet connection. ARDC operates the endpoint at the other end of the tunnel and routes traffic between your equipment and the Internet.


Your laptop, Raspberry Pi, router, cloud instance, or small lab can appear on 44Net even from behind residential NAT, CGNAT, mobile networks, or satellite links.
You can use it to host services, reach station equipment remotely, or experiment with networking.


Connect uses WireGuard as transport, but it is not a privacy VPN. You are not logging in to a service; you are connecting your system to the public Internet. The purpose of the tunnel is to carry your traffic to a point of presence so your system can participate as a public network host.
== Before you start ==
You’ll need a [[Portal/Sign Up|Portal account]] with a [[Verification|verified amateur radio callsign]], an existing internet connection, and a device or router that can run WireGuard.


== Get Started with 44Net Connect ==
You do not need to request addresses separately in the Portal. Connect assigns the device’s addresses when you create a tunnel. For a routed subnet, request a network in the Connect dashboard and attach it to your tunnel.
{{Section|class=mw-section--brief|1=
=== Step 1: Sign in to the Connect dashboard ===
{{SectionAside|
{{SectionFigure|file=Connect Welcome Screen.png|width=300px|alt=44Net Connect welcome screen|class=align-right}}
}}
* Visit [https://connect.44net.cloud The 44Net Connect dashboard].
* Click the “Log In to Get Started” button.
* Sign in with your 44Net Portal account credentials.


''New to the Portal? See [[GetStarted]] to sign up and get your callsign verified. You must have a verified callsign to use Connect. If you have a callsign but haven't completed verification, please do so before proceeding.''
Connect can work behind {{Term|NAT}} or {{Term|CGNAT}}, including on residential broadband, mobile, and satellite connections. Your connection must allow WireGuard traffic to reach the Connect endpoint.
}}


{{SectionLayout|min=99%|gap=0.75rem|
== What would you like to connect? ==
{{SectionCard|
=== Step 2: Create your first tunnel ===
* On the dashboard page, click the “Create Tunnel” button.
* Select an endpoint region and node.
* Enter a name for your tunnel, click the “Create Tunnel” button, and confirm.


''Don’t worry too much about the endpoint selection. You can change it later if needed, and you can have multiple tunnels to different endpoints if you want. The tunnel name is just for your reference.''
=== Single device ===
}}
Run WireGuard on the device you want to connect, such as a Raspberry Pi, server, router, cellular hotspot, or laptop. When you create a tunnel, Connect issues an IPv4 address, an IPv6 address, and a configuration for that device. You don’t need to request a separate address assignment before creating the tunnel.


{{SectionCard|
This is a useful place to start if you want to connect one system.
=== Step 3: Get your WireGuard configuration ===
* Scroll down to find your tunnel configuration.
* Click the “Copy to Clipboard” button to copy the configuration text.
* Paste the configuration into your WireGuard client (Windows, macOS), or save it as a configuration file (e.g. <code>wg0.conf</code> on Linux, cloud instances, etc.).


''The configuration includes your public and private keys, an automatically-assigned 44Net address, and the endpoint information. It’s a standard WireGuard config that you can use with any compatible client or device.''
'''[[44Net Connect/Quick Start|Set up a single device →]]'''
}}


{{SectionCard|
See [[44Net Connect/Supported Platforms|device guides]] for platform-specific instructions, or read more about [[44Net Connect/Single Device Tunnel|single-device tunnels]].
=== Step 4: Activate your tunnel ===
* Start the WireGuard tunnel (“Activate” in the client, or <code>wg-quick up wg0</code> on Linux).


''Once the tunnel is active, your system operates as a native 44Net host. Inbound and outbound traffic is routed through the Connect endpoint, giving your device a direct connection to the Internet.''
=== Multiple devices or a network ===
}}
You can either create a tunnel for each individual device, or run WireGuard on a router or gateway that connects a group of devices. The gateway handles the tunnel and routes traffic for the devices behind it. The individual devices do not need to run WireGuard themselves.
}}
}}


[[File:44net-connect-overview.svg|center|800px|alt=Diagram showing a device connecting via WireGuard to a 44Net Connect endpoint and participating as a native 44Net host|'''How 44Net Connect works:''' your device establishes a WireGuard tunnel to a Connect endpoint node, which routes traffic to and from your assigned 44Net address.]]
This involves configuring addressing, routing, and firewall rules for the network as well as the tunnel.


== What 44Net Connect Provides ==
'''[[44Net Connect/Routed Subnet|Plan and set up a routed subnet →]]'''


* A WireGuard tunnel to a Connect endpoint node
== What happens during setup? ==
* A usable 44Net IP address
You sign in to the [https://connect.44net.cloud Connect dashboard] using your Portal account, choose an endpoint, and create a tunnel. The dashboard supplies a WireGuard configuration to install on your device or gateway. The linked guides cover the steps for each setup.
* Optional routed subnet assignments
* Participation in 44Net without running BGP routing


== How Connect Works ==
Your Portal account at [https://portal.ampr.org/ portal.ampr.org] holds your identity and callsign verification. The separate Connect dashboard at [https://connect.44net.cloud connect.44net.cloud] is where you manage tunnels and obtain their configurations.


# You authenticate to your Connect dashboard using your Portal account.
{{SectionFigure|file=44Net_Connect_overview.png|caption=Traffic between the Internet and your Connect addresses passes through a Connect endpoint and the WireGuard tunnel to your equipment.}}
# The Connect dashboard generates a WireGuard configuration.
# Your device establishes a secure tunnel to a Connect endpoint node.
# The endpoint routes traffic between your system and the Internet.
# Your device participates on the Internet as a normal routed system.


The WireGuard tunnel provides transport only. It is not designed for privacy or anonymity, and it does not replace your internet connection.
== Securing your connection ==
You decide which services to run and make accessible. Incoming connections depend on your service configuration and firewall rules. Take care: an active tunnel can unexpectedly make every service accessible to the public Internet, so check your firewall and service settings before you activate the tunnel. See [[Firewalling Basics|firewalling basics]] for guidance.


== Requirements ==
Your routing configuration determines which outgoing traffic uses the tunnel. You can route all traffic through it, or select traffic by destination or source address. Replies from your Connect address to public Internet clients may also need to use the tunnel; selecting only destinations within 44Net does not cover those replies. The procedures depend on your system.


You will need:
ARDC operates the Connect endpoints. You maintain your device or gateway, its software, and its firewall.


* A 44Net Portal account
WireGuard encrypts traffic between your equipment and the Connect endpoint; it does not provide end-to-end encryption beyond that endpoint. Connect does not provide anonymity or attach your network to the [[IPIP Mesh]] or other community projects, which have separate participation and routing arrangements.
* A verified amateur radio callsign
* A device capable of running WireGuard
* Some sort of Internet access, even if it's behind NAT or CGNAT


Common supported platforms include:
If you’re ready to get started, see [[44Net_Connect/Quick_Start|Quick Start]]. For help with setup or operation, see [[Get Help]].


* Linux, macOS, and Windows systems
[[Category:Explanation]]
* Raspberry Pi and similar single-board computers
[[Category:Participation Methods]]
* Many home and commercial routers
[[Category:44Net Connect]]
* Cloud instances and virtual machines
* Some mobile hotspots and embedded networking devices
 
A continuously running device is supported if you plan to host services.
 
== Connect Endpoint Nodes ==
 
44Net Connect uses multiple endpoint nodes operated within the 44Net infrastructure.
 
* Endpoint nodes are hosted by ARDC in multiple locations.
* Traffic entering through these nodes is routed to participating systems.
* Capacity and geographic diversity continue to expand.
* Future development includes support for volunteer-operated endpoint nodes.
 
Connect is designed as a distributed system rather than a single gateway.
 
== What Connect Is Not ==
 
44Net Connect is '''not''':
 
* A commercial VPN service
* An anonymity or privacy tool
* A replacement for internet access
* Required for participants who already operate routed subnets or BGP connectivity
 
== Typical Use Cases ==
 
* Personal stations reachable on 44Net
* Remote access to home or lab systems
* Temporary or portable applications
* Linking or accessing remote repeaters
* Learning about WireGuard and networking
* Development of applications and services on 44Net
* Remote monitoring or control systems
* Exploring and experimenting with 44Net
 
== Relationship to Other Participation Methods ==
 
{| class="wikitable"
! Method !! Best For
|-
| '''44Net Connect''' || Individuals and small systems
|-
| Routed Subnets || Established networks and organizations
|-
| RF / Mesh Networks || Local and regional wireless communities
|}
 
== Future Development ==
 
Ongoing work includes:
 
* Additional endpoint regions
* Volunteer-hosted nodes
* Improved onboarding and automation
* Deeper integration with Portal services
 
== Related Pages ==
 
* [[Portal]]
* [[Address Allocations]]
* [[Routing 44Net]]
* [[Mesh Networking]]
* [[Getting Started with 44Net]]

Latest revision as of 22:33, 30 September 2026


44Net Connect gives your device or network public IP addresses through a WireGuard tunnel over your existing internet connection. ARDC operates the endpoint at the other end of the tunnel and routes traffic between your equipment and the Internet.

You can use it to host services, reach station equipment remotely, or experiment with networking.

Before you start

You’ll need a Portal account with a verified amateur radio callsign, an existing internet connection, and a device or router that can run WireGuard.

You do not need to request addresses separately in the Portal. Connect assigns the device’s addresses when you create a tunnel. For a routed subnet, request a network in the Connect dashboard and attach it to your tunnel.

Connect can work behind NAT or CGNAT, including on residential broadband, mobile, and satellite connections. Your connection must allow WireGuard traffic to reach the Connect endpoint.

What would you like to connect?

Single device

Run WireGuard on the device you want to connect, such as a Raspberry Pi, server, router, cellular hotspot, or laptop. When you create a tunnel, Connect issues an IPv4 address, an IPv6 address, and a configuration for that device. You don’t need to request a separate address assignment before creating the tunnel.

This is a useful place to start if you want to connect one system.

Set up a single device →

See device guides for platform-specific instructions, or read more about single-device tunnels.

Multiple devices or a network

You can either create a tunnel for each individual device, or run WireGuard on a router or gateway that connects a group of devices. The gateway handles the tunnel and routes traffic for the devices behind it. The individual devices do not need to run WireGuard themselves.

This involves configuring addressing, routing, and firewall rules for the network as well as the tunnel.

Plan and set up a routed subnet →

What happens during setup?

You sign in to the Connect dashboard using your Portal account, choose an endpoint, and create a tunnel. The dashboard supplies a WireGuard configuration to install on your device or gateway. The linked guides cover the steps for each setup.

Your Portal account at portal.ampr.org holds your identity and callsign verification. The separate Connect dashboard at connect.44net.cloud is where you manage tunnels and obtain their configurations.

Traffic between the Internet and your Connect addresses passes through a Connect endpoint and the WireGuard tunnel to your equipment.

Securing your connection

You decide which services to run and make accessible. Incoming connections depend on your service configuration and firewall rules. Take care: an active tunnel can unexpectedly make every service accessible to the public Internet, so check your firewall and service settings before you activate the tunnel. See firewalling basics for guidance.

Your routing configuration determines which outgoing traffic uses the tunnel. You can route all traffic through it, or select traffic by destination or source address. Replies from your Connect address to public Internet clients may also need to use the tunnel; selecting only destinations within 44Net does not cover those replies. The procedures depend on your system.

ARDC operates the Connect endpoints. You maintain your device or gateway, its software, and its firewall.

WireGuard encrypts traffic between your equipment and the Connect endpoint; it does not provide end-to-end encryption beyond that endpoint. Connect does not provide anonymity or attach your network to the IPIP Mesh or other community projects, which have separate participation and routing arrangements.

If you’re ready to get started, see Quick Start. For help with setup or operation, see Get Help.