AllStarLink: Difference between revisions

From 44Net Wiki
KN6DWI (talk | contribs)
Instruct users to read the AllStarLink sign up documentation
KN6DWI (talk | contribs)
Discuss special considerations for split tunnel
 
(9 intermediate revisions by the same user not shown)
Line 2: Line 2:


== Step 1: Sign up for AllStarLink ==
== Step 1: Sign up for AllStarLink ==
Follow AllStarLink's [instructions for the sign up process](https://allstarlink.github.io/basics/portal/). They'll guide you through signing up for an account, registering a server, and registering a node. This will allocate a node number to you, or a set of node numbers if you choose to immediately extend your node number as suggested.  
Follow AllStarLink's [https://allstarlink.github.io/basics/portal/ instructions for the sign up process]. They'll guide you through signing up for an account, registering a server, and registering a node. This will allocate a node number to you, or a set of node numbers if you choose to immediately extend your node number as suggested.  


During registration, United States amateur radio operators will need an '''official copy''' of their license, obtained by [https://wireless2.fcc.gov/UlsEntry/licManager/login.jsp logging in to the FCC website] with their FRN. The publicly available reference copy is not sufficient. After signing up, wait for your account to be verified, which should take at most 24 hours.
During registration, United States amateur radio operators will need an '''official copy''' of their license, obtained by [https://wireless2.fcc.gov/UlsEntry/licManager/login.jsp logging in to the FCC website] with their FRN. The publicly available reference copy is not sufficient. After signing up, wait for your account to be verified, which should take at most 24 hours.


Take note of the IAX port you select when creating your server. This can be changed later, but the portal setting must line up with your firewall settings later.
Take note of the IAX port you select when creating your server. This can be changed later, but the portal setting must line up with your firewall settings later. The default is <code>4569</code>.


== Step 2: Create a server ==
== Step 2: Install AllStarLink ==
== Step 3: Create a node ==
AllStarLink3 can be installed on Debian or Raspberry Pi OS. The <code>asl3-appliance</code> package is available for Debian 13 (trixie). It includes Asterisk, app_rpt, and Allmon3. The <code>asl3-appliance-pc</code> package includes the same, and additional functionality for mDNS broadcasts and swapfile management. The ASL3 appliance for Raspberry Pi OS can be installed with the Raspberry Pi Imager for ease of installation, which lets you preload Wi-Fi configuration. It also supports managing the Pi's serial port at <code>/dev/serial0</code>, as well as using the GPIO pins for PTT triggering. The Pi image keeps logs and temp files only in memory to reduce writes to the SD card.
== Step 4: Install AllStarLink ==
 
== Step 5: Configure firewall ==
=== Raspberry Pi Appliance ===
== Step 6: Enable 44Net Connect tunnel ==
To install the Raspberry Pi ASL3 appliance, see the [https://allstarlink.github.io/install/pi-appliance/pi-detailed/ ASL3 guide to setting up the Pi appliance.] This guide is primarily for flashing a fresh image on your Pi. If you want to add an ASL3 appliance to an existing Pi, follow the steps for the Debian appliance.
 
=== Debian PC or Appliance ===
To install ASL3 on Debian, via any of <code>asl3-appliance</code>, <code>asl3-appliance-pc</code>, or a non-appliance Debian install (<code>asl3</code>), follow [https://allstarlink.github.io/install/debian/install/ the ASL3 Debian install guide.] It covers all three methods, and notes each point where the installation methods diverge.
 
== Step 3: Configure firewall ==
=== firewalld ===
{{Info|Warn|When using a 44Net Connect tunnel with AllStarLink and <code>firewalld</code>, don't put the 44Net WireGuard interface in the <code>allstarlink</code> zone provided by the appliance. This will make your web management interface publicly available on the internet. Instead, create a 44Net zone, and add the requisite services to that zone.}}
 
For security, the firewall should be configured before bringing up the VPN tunnel. The AllStarLink manual has [https://allstarlink.github.io/adv-topics/44net-connect/ a page about 44Net Connect] with recommendations for firewall configuration. If you installed one of the appliance packages, it comes with custom <code>firewalld</code> service definitions. Your 44Net Connect zone must have the <code>iax2</code> service added for AllStar to function. If you're accepting EchoLink connections, the <code>echolink</code> service must also be added. That can be done with the following commands:
 
'''IAX2:'''<code>sudo firewall-cmd --zone <your zone here> --add-service iax2 --permanent</code>
 
'''Echolink:''' <code>sudo firewall-cmd --zone <your zone here> --add-service echolink --permanent</code>
 
 
Users of the non-appliance version should open <code>UDP 4560-4580</code> for IAX2, and <code>5198-5199</code> for EchoLink.
 
'''IAX2:''' <code>sudo firewall-cmd --zone <your zone here> --add-port 4560-4580/udp --permanent </code>
 
'''Echolink:''' <code>sudo firewall-cmd --zone <your zone here> --add-port 5189-5199/udp --permanent</code>
 
 
Once you've added your services or ports, don't forget to reload your firewall:
 
<code>sudo firewall-cmd --reload</code>
 
=== ufw ===
{{Info|Note|<code>firewalld</code> is the recommended firewall software for devices with 44Net Connect software, because its abstraction of zones makes secure configuration easier to set up and understand. <code>ufw</code> can still be used, but it will be more involved due to lacking zones. }}
 
 
<code>ufw</code> rules allowing IAX2 and EchoLink can be entered as follows:
 
'''IAX2:''' <code>sudo ufw allow in on <44net wireguard interface> to any port 4560-4580 proto udp</code>
 
'''Echolink:''' <code>sudo ufw allow in on <44net wireguard interface> to any port 5189-5199 proto udp</code>
 
These rules can be entered before the 44Net Connect WireGuard interface is actually created, but they won't work until a WireGuard interface is created with exactly the same name. The WireGuard interface will be named after the config file used to create it, so <code>wg0.conf</code> would create the interface <code>wg0</code>.
 
== Step 4: Enable 44Net Connect tunnel ==
Go to the [https://wiki.ampr.org/wiki/44Net_Connect/Single_Device_Tunnel Single Device Tunnel tutorials list], and follow the quick start tutorial for your distribution.
 
=== Optional: Split Tunnel ===
There are special considerations for operating a split tunnel on a device with AllStarLink. Nodes register with the central coordination server and report statistics by contacting <code>register.allstarlink.org</code> and <code>stats.allstarlink.org</code>. For the node to be registered with your static 44Net IP, these communications must go out through your VPN tunnel, which by by default they will not. These domains don't have static IPs, so you'll need to deploy a watchdog service to create and update routing rules based on the DNS records.


[[Category:Use Cases]]
[[Category:Use Cases]]
[[Category:How-To]]
[[Category:How-To]]

Latest revision as of 00:02, 2 October 2026

AllStarLink is an open source[1] internet repeater linking system that uses the Asterisk PBX software internally, and provides a web interface for management. It can be used both for connecting repeaters to the internet and for creating reflectors that internet-linked repeaters can connect to. An AllStarLink installation consists of multiple pieces of software: The Asterisk PBX, the app_rpt application made by AllStarLink, and the Allmon3 web interface.

Step 1: Sign up for AllStarLink

Follow AllStarLink's instructions for the sign up process. They'll guide you through signing up for an account, registering a server, and registering a node. This will allocate a node number to you, or a set of node numbers if you choose to immediately extend your node number as suggested.

During registration, United States amateur radio operators will need an official copy of their license, obtained by logging in to the FCC website with their FRN. The publicly available reference copy is not sufficient. After signing up, wait for your account to be verified, which should take at most 24 hours.

Take note of the IAX port you select when creating your server. This can be changed later, but the portal setting must line up with your firewall settings later. The default is 4569.

Step 2: Install AllStarLink

AllStarLink3 can be installed on Debian or Raspberry Pi OS. The asl3-appliance package is available for Debian 13 (trixie). It includes Asterisk, app_rpt, and Allmon3. The asl3-appliance-pc package includes the same, and additional functionality for mDNS broadcasts and swapfile management. The ASL3 appliance for Raspberry Pi OS can be installed with the Raspberry Pi Imager for ease of installation, which lets you preload Wi-Fi configuration. It also supports managing the Pi's serial port at /dev/serial0, as well as using the GPIO pins for PTT triggering. The Pi image keeps logs and temp files only in memory to reduce writes to the SD card.

Raspberry Pi Appliance

To install the Raspberry Pi ASL3 appliance, see the ASL3 guide to setting up the Pi appliance. This guide is primarily for flashing a fresh image on your Pi. If you want to add an ASL3 appliance to an existing Pi, follow the steps for the Debian appliance.

Debian PC or Appliance

To install ASL3 on Debian, via any of asl3-appliance, asl3-appliance-pc, or a non-appliance Debian install (asl3), follow the ASL3 Debian install guide. It covers all three methods, and notes each point where the installation methods diverge.

Step 3: Configure firewall

firewalld

Warning
When using a 44Net Connect tunnel with AllStarLink and firewalld, don't put the 44Net WireGuard interface in the allstarlink zone provided by the appliance. This will make your web management interface publicly available on the internet. Instead, create a 44Net zone, and add the requisite services to that zone.

For security, the firewall should be configured before bringing up the VPN tunnel. The AllStarLink manual has a page about 44Net Connect with recommendations for firewall configuration. If you installed one of the appliance packages, it comes with custom firewalld service definitions. Your 44Net Connect zone must have the iax2 service added for AllStar to function. If you're accepting EchoLink connections, the echolink service must also be added. That can be done with the following commands:

IAX2:sudo firewall-cmd --zone <your zone here> --add-service iax2 --permanent

Echolink: sudo firewall-cmd --zone <your zone here> --add-service echolink --permanent


Users of the non-appliance version should open UDP 4560-4580 for IAX2, and 5198-5199 for EchoLink.

IAX2: sudo firewall-cmd --zone <your zone here> --add-port 4560-4580/udp --permanent

Echolink: sudo firewall-cmd --zone <your zone here> --add-port 5189-5199/udp --permanent


Once you've added your services or ports, don't forget to reload your firewall:

sudo firewall-cmd --reload

ufw

Note
firewalld is the recommended firewall software for devices with 44Net Connect software, because its abstraction of zones makes secure configuration easier to set up and understand. ufw can still be used, but it will be more involved due to lacking zones.


ufw rules allowing IAX2 and EchoLink can be entered as follows:

IAX2: sudo ufw allow in on <44net wireguard interface> to any port 4560-4580 proto udp

Echolink: sudo ufw allow in on <44net wireguard interface> to any port 5189-5199 proto udp

These rules can be entered before the 44Net Connect WireGuard interface is actually created, but they won't work until a WireGuard interface is created with exactly the same name. The WireGuard interface will be named after the config file used to create it, so wg0.conf would create the interface wg0.

Step 4: Enable 44Net Connect tunnel

Go to the Single Device Tunnel tutorials list, and follow the quick start tutorial for your distribution.

Optional: Split Tunnel

There are special considerations for operating a split tunnel on a device with AllStarLink. Nodes register with the central coordination server and report statistics by contacting register.allstarlink.org and stats.allstarlink.org. For the node to be registered with your static 44Net IP, these communications must go out through your VPN tunnel, which by by default they will not. These domains don't have static IPs, so you'll need to deploy a watchdog service to create and update routing rules based on the DNS records.

  1. ↑ The ASL3 source is available on GitHub, though installing from source is not recommended.