44Net Connect: Difference between revisions

From 44Net Wiki
// via Wikitext Extension for VSCode
mw push
 
(16 intermediate revisions by the same user not shown)
Line 1: Line 1:
44Net Connect is the quickest way to start participating in 44Net.
{{DISPLAYTITLE:44Net Connect}}
__NOTOC__


Instead of setting up BGP routing or IPIP Mesh, Connect establishes a WireGuard tunnel between your device and a Connect endpoint node. With the tunnel active, your system operates as a native 44Net host with its own address on the public Internet.
44Net Connect gives your device or network public IP addresses through a {{Term|WireGuard}} tunnel over your existing internet connection. ARDC operates the endpoint at the other end of the tunnel and routes traffic between your equipment and the Internet.


Your laptop, Raspberry Pi, router, cloud instance, or small lab can appear on 44Net even from behind residential NAT, CGNAT, mobile networks, or satellite links.
You can use it to host services, reach station equipment remotely, or experiment with networking.


Connect uses WireGuard as transport, but it is not a privacy VPN. You are not logging in to a service; you are connecting your system to the public Internet. The purpose of the tunnel is to carry your traffic to a point of presence so your system can participate as a public network host.
== Before you start ==
You’ll need a [[Portal/Sign Up|Portal account]] with a [[Verification|verified amateur radio callsign]], an existing internet connection, and a device or router that can run WireGuard.


{{Section|
You do not need to request addresses separately in the Portal. Connect assigns the device’s addresses when you create a tunnel. For a routed subnet, request a network in the Connect dashboard and attach it to your tunnel.
{{SectionCard|
==Start Using 44Net Connect==
New to Connect? Jump straight to the step‑by‑step setup guide:


[[44Net Connect/Quick Start|→ 44Net Connect Quick Start]]
Connect can work behind {{Term|NAT}} or {{Term|CGNAT}}, including on residential broadband, mobile, and satellite connections. Your connection must allow WireGuard traffic to reach the Connect endpoint.


You can return here later to learn how Connect works in more detail.
== What would you like to connect? ==
}}
}}


[[File:44net-connect-overview.svg|center|800px|alt=Diagram showing a device connecting via WireGuard to a 44Net Connect endpoint and participating as a native 44Net host|'''How 44Net Connect works:''' your device establishes a WireGuard tunnel to a Connect endpoint node, which routes traffic to and from your assigned 44Net address.]]
=== Single device ===
Run WireGuard on the device you want to connect, such as a Raspberry Pi, server, router, cellular hotspot, or laptop. When you create a tunnel, Connect issues an IPv4 address, an IPv6 address, and a configuration for that device. You don’t need to request a separate address assignment before creating the tunnel.


If you prefer to follow a guided setup instead of reading the overview first, see [[44Net Connect Quick Start]].
This is a useful place to start if you want to connect one system.


== What 44Net Connect Provides ==
'''[[44Net Connect/Quick Start|Set up a single device →]]'''


* A WireGuard tunnel to a Connect endpoint node
See [[44Net Connect/Supported Platforms|device guides]] for platform-specific instructions, or read more about [[44Net Connect/Single Device Tunnel|single-device tunnels]].
* A usable 44Net IP address
* Optional routed subnet assignments
* Participation in 44Net without running BGP routing


== How Connect Works ==
=== Multiple devices or a network ===
You can either create a tunnel for each individual device, or run WireGuard on a router or gateway that connects a group of devices. The gateway handles the tunnel and routes traffic for the devices behind it. The individual devices do not need to run WireGuard themselves.


# You authenticate to your Connect dashboard using your Portal account.
This involves configuring addressing, routing, and firewall rules for the network as well as the tunnel.
# The Connect dashboard generates a WireGuard configuration.
# Your device establishes a secure tunnel to a Connect endpoint node.
# The endpoint routes traffic between your system and the Internet.
# Your device participates on the Internet as a normal routed system.


The WireGuard tunnel provides transport only. It is not designed for privacy or anonymity, and it does not replace your internet connection.
'''[[44Net Connect/Routed Subnet|Plan and set up a routed subnet →]]'''


== Requirements ==
== What happens during setup? ==
You sign in to the [https://connect.44net.cloud Connect dashboard] using your Portal account, choose an endpoint, and create a tunnel. The dashboard supplies a WireGuard configuration to install on your device or gateway. The linked guides cover the steps for each setup.


You will need:
Your Portal account at [https://portal.ampr.org/ portal.ampr.org] holds your identity and callsign verification. The separate Connect dashboard at [https://connect.44net.cloud connect.44net.cloud] is where you manage tunnels and obtain their configurations.


* A 44Net Portal account
{{SectionFigure|file=44Net_Connect_overview.png|caption=Traffic between the Internet and your Connect addresses passes through a Connect endpoint and the WireGuard tunnel to your equipment.}}
* A verified amateur radio callsign
* A device capable of running WireGuard
* Some sort of Internet access, even if it's behind NAT or CGNAT


Common supported platforms include:
== Securing your connection ==
You decide which services to run and make accessible. Incoming connections depend on your service configuration and firewall rules. Take care: an active tunnel can unexpectedly make every service accessible to the public Internet, so check your firewall and service settings before you activate the tunnel. See [[Firewalling Basics|firewalling basics]] for guidance.


* Linux, macOS, and Windows systems
Your routing configuration determines which outgoing traffic uses the tunnel. You can route all traffic through it, or select traffic by destination or source address. Replies from your Connect address to public Internet clients may also need to use the tunnel; selecting only destinations within 44Net does not cover those replies. The procedures depend on your system.
* Raspberry Pi and similar single-board computers
* Many home and commercial routers
* Cloud instances and virtual machines
* Some mobile hotspots and embedded networking devices


A continuously running device is supported if you plan to host services.
ARDC operates the Connect endpoints. You maintain your device or gateway, its software, and its firewall.


== Connect Endpoint Nodes ==
WireGuard encrypts traffic between your equipment and the Connect endpoint; it does not provide end-to-end encryption beyond that endpoint. Connect does not provide anonymity or attach your network to the [[IPIP Mesh]] or other community projects, which have separate participation and routing arrangements.


44Net Connect uses multiple endpoint nodes operated within the 44Net infrastructure.
If you’re ready to get started, see [[44Net_Connect/Quick_Start|Quick Start]]. For help with setup or operation, see [[Get Help]].


* Endpoint nodes are hosted by ARDC in multiple locations.
[[Category:Explanation]]
* Traffic entering through these nodes is routed to participating systems.
[[Category:Participation Methods]]
* Capacity and geographic diversity continue to expand.
[[Category:44Net Connect]]
* Future development includes support for volunteer-operated endpoint nodes.
 
Connect is designed as a distributed system rather than a single gateway.
 
== What Connect Is Not ==
 
44Net Connect is '''not''':
 
* A commercial VPN service
* An anonymity or privacy tool
* A replacement for internet access
* Required for participants who already operate routed subnets or BGP connectivity
 
== Typical Use Cases ==
 
* Personal stations reachable on 44Net
* Remote access to home or lab systems
* Temporary or portable applications
* Linking or accessing remote repeaters
* Learning about WireGuard and networking
* Development of applications and services on 44Net
* Remote monitoring or control systems
* Exploring and experimenting with 44Net
 
== Relationship to Other Participation Methods ==
 
{| class="wikitable"
! Method !! Best For
|-
| '''44Net Connect''' || Individuals and small systems
|-
| Routed Subnets || Established networks and organizations
|-
| RF / Mesh Networks || Local and regional wireless communities
|}
 
== Future Development ==
 
Ongoing work includes:
 
* Additional endpoint regions
* Volunteer-hosted nodes
* Improved onboarding and automation
* Deeper integration with Portal services
 
== Ready to Try It? ==
 
You can set up a working 44Net connection in just a few minutes:
 
* [[44Net Connect Quick Start|Start the Quick Start Guide]]
 
== Related Pages ==
 
* [[Portal]]
* [[Address Allocations]]
* [[Routing 44Net]]
* [[Mesh Networking]]
* [[Getting Started with 44Net]]

Latest revision as of 22:33, 30 September 2026


44Net Connect gives your device or network public IP addresses through a WireGuard tunnel over your existing internet connection. ARDC operates the endpoint at the other end of the tunnel and routes traffic between your equipment and the Internet.

You can use it to host services, reach station equipment remotely, or experiment with networking.

Before you start

You’ll need a Portal account with a verified amateur radio callsign, an existing internet connection, and a device or router that can run WireGuard.

You do not need to request addresses separately in the Portal. Connect assigns the device’s addresses when you create a tunnel. For a routed subnet, request a network in the Connect dashboard and attach it to your tunnel.

Connect can work behind NAT or CGNAT, including on residential broadband, mobile, and satellite connections. Your connection must allow WireGuard traffic to reach the Connect endpoint.

What would you like to connect?

Single device

Run WireGuard on the device you want to connect, such as a Raspberry Pi, server, router, cellular hotspot, or laptop. When you create a tunnel, Connect issues an IPv4 address, an IPv6 address, and a configuration for that device. You don’t need to request a separate address assignment before creating the tunnel.

This is a useful place to start if you want to connect one system.

Set up a single device →

See device guides for platform-specific instructions, or read more about single-device tunnels.

Multiple devices or a network

You can either create a tunnel for each individual device, or run WireGuard on a router or gateway that connects a group of devices. The gateway handles the tunnel and routes traffic for the devices behind it. The individual devices do not need to run WireGuard themselves.

This involves configuring addressing, routing, and firewall rules for the network as well as the tunnel.

Plan and set up a routed subnet →

What happens during setup?

You sign in to the Connect dashboard using your Portal account, choose an endpoint, and create a tunnel. The dashboard supplies a WireGuard configuration to install on your device or gateway. The linked guides cover the steps for each setup.

Your Portal account at portal.ampr.org holds your identity and callsign verification. The separate Connect dashboard at connect.44net.cloud is where you manage tunnels and obtain their configurations.

Traffic between the Internet and your Connect addresses passes through a Connect endpoint and the WireGuard tunnel to your equipment.

Securing your connection

You decide which services to run and make accessible. Incoming connections depend on your service configuration and firewall rules. Take care: an active tunnel can unexpectedly make every service accessible to the public Internet, so check your firewall and service settings before you activate the tunnel. See firewalling basics for guidance.

Your routing configuration determines which outgoing traffic uses the tunnel. You can route all traffic through it, or select traffic by destination or source address. Replies from your Connect address to public Internet clients may also need to use the tunnel; selecting only destinations within 44Net does not cover those replies. The procedures depend on your system.

ARDC operates the Connect endpoints. You maintain your device or gateway, its software, and its firewall.

WireGuard encrypts traffic between your equipment and the Connect endpoint; it does not provide end-to-end encryption beyond that endpoint. Connect does not provide anonymity or attach your network to the IPIP Mesh or other community projects, which have separate participation and routing arrangements.

If you’re ready to get started, see Quick Start. For help with setup or operation, see Get Help.