IPIP Mesh

From 44Net Wiki


The IPIP Mesh connects participating amateur radio networks through tunnels over the Internet. You operate a gateway that exchanges traffic between your 44Net network and other participants’ gateways serving their 44Net networks. These may be single systems, home or club LANs, or larger networks.

You can use the Mesh to reach other participants’ services, share your own, and generally experiment with networking.

ARDC supports the project and operates a gateway that provides connectivity between the Mesh and the Internet. Each participant is responsible for their own gateway and its operation.

Before you start

You’ll need a Portal account with a verified amateur radio callsign, and a computer or router that supports IPIP and can maintain Mesh routes. Raspberry Pis, Linux servers, and cloud instances are common choices.

Your gateway also needs a reachable public IPv4 endpoint on your existing internet connection. Your ISP, router, and firewall must allow IP protocol 4 (IP-in-IP). If you use RIP route updates, your gateway must also accept those updates on UDP port 520 inside the IPIP tunnel; this does not require opening UDP port 520 on your public Internet connection. Check the Internet requirements for IPIP Mesh before choosing equipment or requesting an assignment.

The public endpoint is for carrying the tunnels between gateways. The 44Net Mesh addresses identify the systems you connect to, through the gateways.

What can you connect to?

The Mesh connects you to other networks on the Mesh. Each gateway uses a shared directory of subnets and endpoints to send traffic directly to the destination gateway. The services you can use depend on what their operators make available and permit through their firewalls.

A 44Net address alone does not make a system part of the Mesh. 44Net Connect and independently routed networks have their own connection arrangements. Joining the Mesh does not automatically give you access to them, and joining them does not give you access to the Mesh.

Limited access from the public Internet is available through Amprgw, the shared Internet gateway. Inbound traffic requires the destination host’s Mesh address to be registered in ampr.org DNS.

The Mesh does not provide general-purpose Internet access. Your gateway should route traffic to registered Mesh subnets through the Mesh and other traffic through your existing Internet connection.

How will you participate?

Operate your own gateway

Use a computer or router to handle the tunnels and routes for your Mesh subnet. You configure it as a gateway, assign addresses to your systems, and arrange for their Mesh traffic and replies to pass through it.

Find a gateway setup guide →

See how Mesh gateways connect for more about the arrangement.

Participate through an existing network

Some amateur networks participate in the Mesh, and their operators may help you connect through existing infrastructure. Ask the network’s operators what they provide and what you would need to run. Explore independently operated networks and projects to find one that interests you.

What happens during setup?

For your own gateway, the main steps are:

  1. Request an address assignment for IPIP Mesh use.
  2. Register your gateway’s public endpoint and associate your Mesh subnet with it in the Portal, so other gateways can learn how to reach you.
  3. Configure IPIP and a way to maintain routes to other Mesh networks, following a guide for your platform.
  4. Configure addressing, routing, and firewall rules for your local systems, then check communication with another participant.

Once you’re connected

Keep your gateway’s software, routes, and Portal endpoint information current. You decide which systems and services to expose, and maintain the firewall rules that allow access to them.

IPIP does not encrypt traffic. Use encrypted application protocols where needed. See Mesh firewall guidance for more about controlling traffic, and Get Help for setup or operating questions.

Guides and reference

These pages cover mesh gateways, setup, and routing. Some guides describe older systems and have not been revalidated.

Gateways

Platform guides

For other connection methods, see device and platform guides.

Routing references and tools

Historical services