44Net Connect
44Net Connect gives your device or network public IP addresses through a WireGuard tunnel over your existing internet connection. ARDC operates the endpoint at the other end of the tunnel and routes traffic between your equipment and the Internet.
You can use it to host services, reach station equipment remotely, or experiment with networking.
Before you start
You’ll need a Portal account with a verified amateur radio callsign, an existing internet connection, and a device or router that can run WireGuard.
You do not need to request addresses separately in the Portal. Connect assigns the device’s addresses when you create a tunnel. For a routed subnet, request a network in the Connect dashboard and attach it to your tunnel.
Connect can work behind NAT or CGNAT, including on residential broadband, mobile, and satellite connections. Your connection must allow WireGuard traffic to reach the Connect endpoint.
What would you like to connect?
Single device
Run WireGuard on the device you want to connect, such as a Raspberry Pi, server, router, cellular hotspot, or laptop. When you create a tunnel, Connect issues an IPv4 address, an IPv6 address, and a configuration for that device. You don’t need to request a separate address assignment before creating the tunnel.
This is a useful place to start if you want to connect one system.
See device guides for platform-specific instructions, or read more about single-device tunnels.
Multiple devices or a network
You can either create a tunnel for each individual device, or run WireGuard on a router or gateway that connects a group of devices. The gateway handles the tunnel and routes traffic for the devices behind it. The individual devices do not need to run WireGuard themselves.
This involves configuring addressing, routing, and firewall rules for the network as well as the tunnel.
Plan and set up a routed subnet →
What happens during setup?
You sign in to the Connect dashboard using your Portal account, choose an endpoint, and create a tunnel. The dashboard supplies a WireGuard configuration to install on your device or gateway. The linked guides cover the steps for each setup.
Your Portal account at portal.ampr.org holds your identity and callsign verification. The separate Connect dashboard at connect.44net.cloud is where you manage tunnels and obtain their configurations.

Securing your connection
You decide which services to run and make accessible. Incoming connections depend on your service configuration and firewall rules. Take care: an active tunnel can unexpectedly make every service accessible to the public Internet, so check your firewall and service settings before you activate the tunnel. See firewalling basics for guidance.
Your routing configuration determines which outgoing traffic uses the tunnel. You can route all traffic through it, or select traffic by destination or source address. Replies from your Connect address to public Internet clients may also need to use the tunnel; selecting only destinations within 44Net does not cover those replies. The procedures depend on your system.
ARDC operates the Connect endpoints. You maintain your device or gateway, its software, and its firewall.
WireGuard encrypts traffic between your equipment and the Connect endpoint; it does not provide end-to-end encryption beyond that endpoint. Connect does not provide anonymity or attach your network to the IPIP Mesh or other community projects, which have separate participation and routing arrangements.
If you’re ready to get started, see Quick Start. For help with setup or operation, see Get Help.