Skip to content

Revise 44Net Connect documentation for clarity and security - #235

Merged
jxmx merged 9 commits into
AllStarLink:mainfrom
Mason10198:44net_connect_cleanup
Jul 11, 2026
Merged

Revise 44Net Connect documentation for clarity and security#235
jxmx merged 9 commits into
AllStarLink:mainfrom
Mason10198:44net_connect_cleanup

Conversation

@Mason10198

Copy link
Copy Markdown
Contributor

This pull request significantly rewrites and expands the 44Net Connect documentation to emphasize firewall configuration and security best practices before enabling a public 44Net VPN tunnel. The new guide provides detailed, step-by-step instructions for both ASL3 Appliance and non-appliance systems, focusing on minimizing exposure of services and ensuring that only necessary ports are open to the Internet. The instructions are now organized into clear sections covering security risks, firewall setup, and VPN tunnel creation.

Security and Firewall Guidance:

  • Adds a new section on security risks, highlighting the importance of configuring a firewall before starting the VPN and warning against exposing unnecessary services to the Internet.
  • Provides detailed, system-specific firewall setup instructions for both ASL3 Appliance (using firewalld service definitions) and non-appliance Debian systems, including commands for creating a dedicated firewall zone and selectively enabling only required services like IAX2, EchoLink, and VOTER/RTCM.
  • Strongly discourages exposing management interfaces (e.g., SSH, Cockpit, AMI) to the public 44Net address, explaining the risks and omitting direct instructions for such exposure.

Step-by-Step Setup Instructions:

  • Reorganizes the guide to ensure users complete firewall configuration before creating or starting the VPN tunnel, with clear "Next" steps

…firewall setup instructions and service exposure guidelines.
@coderabbitai

coderabbitai Bot commented Jul 7, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 3c8c61a1-567a-4158-845a-637b2b71bc23

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mkmer mkmer left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Allan-N Allan-N left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This revised doc has lots of good information. But, the complexity of the page has also grown and I fear that we're moving away from the simple "do this and you're done" steps that fit on a single page. Would it make any sense to keep (or thin down) the "44Net Connect" page with just enough to get a node on the network and then have a more advanced page about firewalls and firewall configurations?

Comment thread docs/adv-topics/44net-connect.md Outdated
Comment thread docs/adv-topics/44net-connect.md Outdated
Comment thread docs/adv-topics/44net-connect.md Outdated
Comment thread docs/adv-topics/44net-connect.md Outdated
Comment thread docs/adv-topics/44net-connect.md Outdated
Comment thread docs/adv-topics/44net-connect.md Outdated
@Mason10198

Mason10198 commented Jul 7, 2026

Copy link
Copy Markdown
Contributor Author

@Allan-N My intention was to simplify the page and make it more beginner friendly, while also adding some additional necessary details.

The "additional details" are stuffed into collapsible blocks that only open up when intentionally clicked, keeping the page focused and straightforward (when rendered correctly). It sounds like it might not be rendering correctly for you?

Most of the bloat comes from showing step-by-step for two two different systems (appliance and non-appliance). The current page heavily leans on the assumption that the reader is using an Appliance installation.

IMO, firewall setup should absolutely be on the same page as the rest of the 44Net Connect setup. The average user would be more likely to skip it otherwise. Firewall configuration should, IMO, be configured before any VPN configuration is completed for security reasons.

Since the release of 44Net Connect, there have been a lot of ASL machines popping up on the public internet with little to no firewall protection. Most of the operators are just following guides or videos, and are not aware of the risks or additional firewall configuration that is needed.

Also IMO, this is the "bare minimum" information required to get 44Net Connect set up on an AllstarLink node safely.

As always, open to additional suggestions, but my main goal here was to:
a) add a little bit more detail about properly setting up a firewall
b) put the firewall configuration first, before the machine is exposed via a live 44Net Connect tunnel
c) make it easier to follow

@Allan-N

Allan-N commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

The "additional details" are stuffed into collapsible blocks that only open up when intentionally clicked, keeping the page focused and straightforward (when rendered correctly). It sounds like it might not be rendering correctly for you?

Possibly not. I was using Safari (on my Mac). Just tried Chrome and I'm seeing the same page. Oh ... the collapsible block is (way to) hard to see :

Screenshot 2026-07-07 at 5 34 15 PM

@Allan-N
Allan-N requested review from jxmx and ve7fet July 7, 2026 21:38
Comment thread docs/adv-topics/44net-connect.md Outdated
Comment thread docs/adv-topics/44net-connect.md
Comment thread docs/adv-topics/44net-connect.md Outdated
Comment thread docs/adv-topics/44net-connect.md
Comment thread docs/adv-topics/44net-connect.md Outdated
Comment thread docs/adv-topics/44net-connect.md Outdated
Comment thread docs/adv-topics/44net-connect.md Outdated
Comment thread docs/adv-topics/44net-connect.md Outdated
@jxmx
jxmx merged commit 083819b into AllStarLink:main Jul 11, 2026
2 checks passed
@Mason10198
Mason10198 deleted the 44net_connect_cleanup branch July 11, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants