44Net Connect

From 44Net Wiki
Revision as of 22:33, 30 September 2026 by KI5QKX (talk | contribs) (mw push)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)


44Net Connect gives your device or network public IP addresses through a WireGuard tunnel over your existing internet connection. ARDC operates the endpoint at the other end of the tunnel and routes traffic between your equipment and the Internet.

You can use it to host services, reach station equipment remotely, or experiment with networking.

Before you start

You’ll need a Portal account with a verified amateur radio callsign, an existing internet connection, and a device or router that can run WireGuard.

You do not need to request addresses separately in the Portal. Connect assigns the device’s addresses when you create a tunnel. For a routed subnet, request a network in the Connect dashboard and attach it to your tunnel.

Connect can work behind NAT or CGNAT, including on residential broadband, mobile, and satellite connections. Your connection must allow WireGuard traffic to reach the Connect endpoint.

What would you like to connect?

Single device

Run WireGuard on the device you want to connect, such as a Raspberry Pi, server, router, cellular hotspot, or laptop. When you create a tunnel, Connect issues an IPv4 address, an IPv6 address, and a configuration for that device. You don’t need to request a separate address assignment before creating the tunnel.

This is a useful place to start if you want to connect one system.

Set up a single device →

See device guides for platform-specific instructions, or read more about single-device tunnels.

Multiple devices or a network

You can either create a tunnel for each individual device, or run WireGuard on a router or gateway that connects a group of devices. The gateway handles the tunnel and routes traffic for the devices behind it. The individual devices do not need to run WireGuard themselves.

This involves configuring addressing, routing, and firewall rules for the network as well as the tunnel.

Plan and set up a routed subnet →

What happens during setup?

You sign in to the Connect dashboard using your Portal account, choose an endpoint, and create a tunnel. The dashboard supplies a WireGuard configuration to install on your device or gateway. The linked guides cover the steps for each setup.

Your Portal account at portal.ampr.org holds your identity and callsign verification. The separate Connect dashboard at connect.44net.cloud is where you manage tunnels and obtain their configurations.

Traffic between the Internet and your Connect addresses passes through a Connect endpoint and the WireGuard tunnel to your equipment.

Securing your connection

You decide which services to run and make accessible. Incoming connections depend on your service configuration and firewall rules. Take care: an active tunnel can unexpectedly make every service accessible to the public Internet, so check your firewall and service settings before you activate the tunnel. See firewalling basics for guidance.

Your routing configuration determines which outgoing traffic uses the tunnel. You can route all traffic through it, or select traffic by destination or source address. Replies from your Connect address to public Internet clients may also need to use the tunnel; selecting only destinations within 44Net does not cover those replies. The procedures depend on your system.

ARDC operates the Connect endpoints. You maintain your device or gateway, its software, and its firewall.

WireGuard encrypts traffic between your equipment and the Connect endpoint; it does not provide end-to-end encryption beyond that endpoint. Connect does not provide anonymity or attach your network to the IPIP Mesh or other community projects, which have separate participation and routing arrangements.

If you’re ready to get started, see Quick Start. For help with setup or operation, see Get Help.