Revise 44Net Connect documentation for clarity and security - #235
Conversation
…firewall setup instructions and service exposure guidelines.
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Allan-N
left a comment
There was a problem hiding this comment.
This revised doc has lots of good information. But, the complexity of the page has also grown and I fear that we're moving away from the simple "do this and you're done" steps that fit on a single page. Would it make any sense to keep (or thin down) the "44Net Connect" page with just enough to get a node on the network and then have a more advanced page about firewalls and firewall configurations?
|
@Allan-N My intention was to simplify the page and make it more beginner friendly, while also adding some additional necessary details. The "additional details" are stuffed into collapsible blocks that only open up when intentionally clicked, keeping the page focused and straightforward (when rendered correctly). It sounds like it might not be rendering correctly for you? Most of the bloat comes from showing step-by-step for two two different systems (appliance and non-appliance). The current page heavily leans on the assumption that the reader is using an Appliance installation. IMO, firewall setup should absolutely be on the same page as the rest of the 44Net Connect setup. The average user would be more likely to skip it otherwise. Firewall configuration should, IMO, be configured before any VPN configuration is completed for security reasons. Since the release of 44Net Connect, there have been a lot of ASL machines popping up on the public internet with little to no firewall protection. Most of the operators are just following guides or videos, and are not aware of the risks or additional firewall configuration that is needed. Also IMO, this is the "bare minimum" information required to get 44Net Connect set up on an AllstarLink node safely. As always, open to additional suggestions, but my main goal here was to: |

This pull request significantly rewrites and expands the 44Net Connect documentation to emphasize firewall configuration and security best practices before enabling a public 44Net VPN tunnel. The new guide provides detailed, step-by-step instructions for both ASL3 Appliance and non-appliance systems, focusing on minimizing exposure of services and ensuring that only necessary ports are open to the Internet. The instructions are now organized into clear sections covering security risks, firewall setup, and VPN tunnel creation.
Security and Firewall Guidance:
firewalldservice definitions) and non-appliance Debian systems, including commands for creating a dedicated firewall zone and selectively enabling only required services like IAX2, EchoLink, and VOTER/RTCM.Step-by-Step Setup Instructions: