Hello 44Net,
For those of you who are interested in our 2021 audited financials, they
are now posted and available for your perusal:
https://www.ampr.org/about/legal.
More information and context for the financials can be found in this
blog post:
https://www.ampr.org/2021-audited-990-pf-tax-return-financial-statements/
Happy perusing, and please don't hesitate to reach out with any questions.
Many thanks,
Rosy
--
Rosy Schechter - KJ7RYV
Executive Director
Amateur Radio Digital Communications (ARDC)
ampr.org
All,
This is the updated dynamic firewall script for OpenWrt 22.03 >= 22.03. This script will not reload firewall counters upon processing new endpoints into the set.
Please be advised - a firewall bug on the release version will not recognize empty or missing files - and hence keeps this from working without an upgrade of the firewall. The script posted in the original email (attached below), contains the script that will work without the patch.
You may run the following to patch OpenWrt and use this:
opkg update; opkg upgrade firewall4reboot
Reference: https://forum.openwrt.org/t/re-22-03-translate-extra-raw-firewall-rules/140…
--
73,
-LynwoodKB3VWG--
#########################!/bin/sh# load encap.txt into ipipfilter list
PATH="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
cd /tmp || exit 1
###########################
rm /tmp/ipip_filter.txt echo 169.228.34.84 >> /tmp/ipip_filter.txt
grep addprivate /var/lib/ampr-ripd/encap.txt | sed -e 's/.*encap //' | sort -u | while read ipdo echo $ip >> /tmp/ipip_filter.txtdone
fw4 reload-sets
exit 0
######################3
-------- Original message --------From: lleachii(a)aol.com Date: 10/4/22 19:15 (GMT-05:00) To: AMPRNet Working Group <44net(a)mailman.ampr.org> Subject: Re: [44net] Re: [FYI] OpenWrt Nodes - 22.03.0 with dynamic firewall
Old comments removed:
#!/bin/sh# load encap.txt into ipipfilter list
PATH="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
cd /var/lib/ampr-ripd || exit 1
nft flush set inet fw4 ipipfilter
nft add element inet fw4 ipipfilter { 169.228.34.84 }
grep addprivate encap.txt | sed -e 's/.*encap //' | sort -u | while read ipdo nft add element inet fw4 ipipfilter { $ip }done
All,
I'm not sure to whom to direct this question. I'm trying to research who informed me (likely the late Brian Kantor WB6CYT, SK) - that an NTP server exists at 44.0.0.1 (gw.ampr.org).
Just doing some usual testing and updating of my node, I observed that there's no longer a NTP response from that IP. Is this by design, another issue, etc?
I just wanted to ask, especially since AMPRGW is listed on the Wiki as an available NTP server. I wanted to update that information if the service no longer operates on that IP.
--
73,
- LynwoodKB3VWG
Hi, all:
We are now accepting applications from those wishing to serve on our Technical Advisory Committee (TAC) in 2023. These are volunteer positions, with a term of one year (January to December). Please submit applications by Nov. 12, 2022!
About the TAC
The primary role of the TAC is to advise on 44Net technology, architecture, and policy. In 2022, the committee worked on providing feedback on a survey released to 44Net users, which garnered over 1700 responses from all over the world. Additionally, they developed a feature requirements document <https://www.ampr.org/wp-content/uploads/2022-09-Portal-Features-Requirement…> for an updated portal, which we use for 44Net address space allocations.
2023 Goals & Time Commitment
In 2023, the TAC will continue its work on refining 44Net use-cases and standards. Goals include further development of the portal mentioned above, researching and developing a proposal for Points for Presence (PoPs) based on existing use cases and best practices, and conversations with the 44Net community about IPv6. Note that though there may be some prototyping and development, the majority of the work may be document-focused.
The TAC usually meets once or twice a month for at least an hour. Additional time may be spent working on or taking meetings related to the projects mentioned above.
How to Apply
If you are interested in joining the TAC, please send a resume and brief cover letter to contact(a)ardc.net <mailto:contact@ardc.net> by November 12, 2022. In your cover letter, which can be brief, please outline:
Your experience with 44Net, networking, development, and/or amateur radio,
Your experience working with networking and similar technologies, and
What you could see yourself contributing in 2023.
Please submit applications by Nov. 12, 2022!
We’ll review all applications and seek to make a determination by December 7, 2022. Meetings will begin mid-January.
For more information about the roles and duties of these committees, you can read the Advisory Committee Policy in full here. <https://www.ampr.org/advisory-committee-policy/>
Please direct any questions to contact(a)ardc.net <mailto:contact@ardc.net>.
We’re looking forward to reading your application!
73,
Dan KB6NU
I'm trying to use the instructions at https://wiki.ampr.org/wiki/Setting_up_a_gateway_on_Ubiquiti_EdgeRouter and I thought everything was working but I'm having and issues.
eth0 is my internet at 50.93.51.24
eth1 is my 192.168.1.x network
eth2 is my 44.135.148.129
switch0 is 192.168.1.1/24
tun44 was setup using the instructions (used 44 instead of 0)
I added the protocols (changed next-hop to tun44)
Added all the firewall modifications (keeping table 1)
I have setup in the portal my gateway at 50.93.51.24 (Did this yesterday).
My linux box has two network cards. One on 192.168.1.110 and the other is set to 44.135.148.130/27.
My problem is I can't ping from the outside world to my linux box on the 44 network. On my linux box when I try and ping any 44 network (like 44.60.44.10) none of the packets make it through. I tried pinging 44.60.44.10 from the Edgerouter command line and it won't make it either. I'm sure I missed something but I don't know what it might be. Any help would be appreciated.
Stephen Atkins
VE6CPU/VE6STA/VE6SU
Sent with [Proton Mail](https://proton.me/) secure email.
Hi 44Net,
At long last, I'm pleased to share with you that ARDC has hired a new
Director of Technology, Jon Kemper.
In his role, Jon will be working with the foundation, volunteers and
community members to lead the assessment, development, and
implementation of new technology initiatives, manage open source
projects, and improve the operational efficiency of both 44Net and the
grantmaking side of the house.
Jon brings a wealth of experience managing global engineering teams
using software development methodologies. Notable projects include:
remotely-operated vehicles (including underwater vehicles), Internet of
things (IoT) sensors, and embedded control systems. His amateur radio
activities include the building of 70 cm repeaters that link together
via RF and VoIP and design of a flat audio board used to equalize and
route discriminator audio.
Jon holds an Amateur Extra Class amateur radio license and a commercial
General Radiotelephone Operator License (GROL). He studied computer
science and physics at California State University San Marcos and has an
AA Degree from Palomar College. Jon is a lifelong learner in the field
of technology and has been awarded 4 U.S. patents, including one for an
automotive security device and one for a device that measures
temperature and converts that measurement into a color.
Jon was introduced to radio and electronics by his grandfather, Guy A.
Kemper, who founded Kemper Radio Laboratories in Los Angeles. At ARDC,
Jon will be carrying on the family tradition of helping future
generations become interested in science and technology.
We are thrilled to have Jon on board and look forward to evolving and
improving our technology under his direction.
If you want to share the news with your friends off 44Net, the above is
also available in blog post form here:
https://www.ampr.org/ardc-welcomes-technical-director-jon-kemper-ka6nvy/
Also, Jon is cc'd here. Feel free to say hi to him on or off list.
Onwards and 73,
Rosy
--
Rosy Schechter - KJ7RYV
Executive Director
Amateur Radio Digital Communications (ARDC)
ampr.org
I'm trying to follow the instructions on https://wiki.ampr.org/wiki/Installing_ampr-ripd_on_a_Ubiquiti_EdgeRouter_or… but I'm not getting it and I've reset back to the default settings. I've got the router setup and working as a gateway with external IP of 75.158.135.117 which was given by DHCP from my ISP and is on eth0. On eth1 is set as my internal network as 192.168.1.1/24. I have two ethernet adapters on my computer. One is going to eth1 on the router. The other is on eth2 on the router which is currently not configured. I was thinking eth2 would be my 44 net. I have setup a DMZ so everything that comes in to eth0 goes to my computer (I have a lot of servers running on that machine so if you scan it you will get lots of hits. Have fun until I lock it down).
I'm hitting a snag on the very first part of router prep. Where it says to edit the WAN_LOCAL rule set. Under which do I add these? Under source NAT rule or destination NAT rule?
BTW I'm running ER3 Lite 1.10.11 on my router. Once I figure out a few of these things I can take some snap shots of my setup to add to the wiki page to help future setups.
Stephen Atkins
VE6CPU/VE6STA/VE6SU
Sent with [Proton Mail](https://proton.me/) secure email.
David,
- I opted for the WAX202 after seeing this discussion: https://forum.openwrt.org/t/wax202-30-at-us-staples/138622/31 - regarding the other models, I don't see any other WAX models supported in the OpenWrt Table of hardware - https://openwrt.org/toh/start
- To my understanding, the Netgear firmware only produces an Access Point, as I need a router, C++ libraries to run ampr-ripd, snmp, NetFlow, firewall, etc., I've switched to OpenWrt already. I rarely run OEM firmware.
- While MAC filtering is not suggested as a security feature, yes - OpenWrt does support it. I'm not aware of any limits. See the macfilter WiFi config here: https://openwrt.org/docs/guide-user/network/wifi/basic#common_options1
I am considering WiFi 6E; but I currently have no devices possessing a 6 GHz chip. This will definitely be a consideration for my next device purchase
Also, I found another sale at Office Depot: https://www.officedepot.com/a/products/3002477/Netgear-Desktop-Wireless-Acc…
--
- KB3VWG
I'm finally getting my 44net router going. I've got an ipip tunnel going. I havent done any ping tests through it yet as I need to run another network cable. But I'm trying to figure out how to get the routing table loaded. I must be blind or to tired to find the instructions. Can someone point me in the right direction? After that I just need to get an ampr domain set.
Thanks
Stephen Atkins
VE6CPU/VE6STA/VE6SU
Sent from Proton Mail mobile
Alrighty everyone.
So I know my gateway is happy being part of the AmprNet, ( My tunl0 interface is working) because I get the correct IP address of my 1 and only host (for now) on my local AmprNet network when using Rob’s http://44.60.44.10/whatismyip/
Woo Hoo. The biggest part of this is done.
But my only problem now is…
I can resolve, ping, and get ping responses using hostnames such as Bob’s linux.ve3mch.ampr.org and every other hostname’s he has, on my Gateway machines terminal but NOT from the 1 and only host(for now). BUT!! I can
ping their IP addresses.
I know this is a DNS issue but what DNS entry should I be using on my AmprNet host to resolve domain names to their IP addresses on the AmprNet? Should I be running my own? Not really sure where to attack this issue.
After this, I believe I’ll be ready to pitch my services to the MESH network guys here in the Valley to see what interest I can spun up in joining at least a couple of nodes for now onto the AmprNet itself. Also ill work on returning my
packet node to service after a few years and have it available on the AmprNet.
Thanks all. I have faith in this. LOL
Harold
K7ILO
From: Lee D Bengston <kilo5dat(a)gmail.com>
Date: Thursday, October 13, 2022 at 11:15 AM
To: Harold Kinchelow <k7ilo(a)outlook.com>
Subject: Re: [44net] Testing 1 2 3 4
Update - it turned out the problem with my access to the portal was just a web browser issue. I changed web browsers and was able to log in.
Here is what is in the portal for my gateway. Both subnets are listed, but indeed only the first one is in the encap.txt file.
[cid:ii_l97dnxsc0]
Evidently the subnet that is not in encap.txt is being advertised via RIP44 because various people are able to communicate with my IP's in 44.92.0.64/28<http://44.92.0.64/28>.
73,
Lee K5DAT
On Wed, Oct 12, 2022 at 9:18 PM Lee D Bengston <kilo5dat(a)gmail.com<mailto:kilo5dat@gmail.com>> wrote:
Harold,
Nothing has been down on my end. I think most people use ampr-ripd these days to get the routes, so not being in the encap.txt file would not affect them. I have 8 or 9 AXIP links between my packet node and others over amprnet, and all of them are up and have been for weeks. It does look like my password expired on the portal, so I need to address that. I would think if I didn't log in to the portal often enough, and they wanted to suspend my allocation, then the routes for my allocation would disappear from the ampr-ripd broadcast AND the encap.txt file. I seem to recall when I first started playing with amprnet that there were routes missing in encap.txt.
Thanks,
Lee K5DAT
On Wed, Oct 12, 2022 at 8:45 PM Harold Kinchelow <k7ilo(a)outlook.com<mailto:k7ilo@outlook.com>> wrote:
Hey Lee
I was going to try to ping you again and see that your route (subnet) is not in the encap.txt file.
Im assuming when this happens, your system is down?
Thanks
Harold
K7IO
From: Lee D Bengston <kilo5dat(a)gmail.com<mailto:kilo5dat@gmail.com>>
Date: Tuesday, October 11, 2022 at 6:40 AM
To: Harold Kinchelow <k7ilo(a)outlook.com<mailto:k7ilo@outlook.com>>
Subject: Re: [44net] Testing 1 2 3 4
Hello Harold,
Sorry I was insanely busy yesterday at work. Today I am not able to ping any of the 3, but maybe you have made some changes. I did try pinging some other amprnet addresses and still could.
73,
Lee
On Mon, Oct 10, 2022 at 2:54 PM Harold Kinchelow <k7ilo(a)outlook.com<mailto:k7ilo@outlook.com>> wrote:
Ok Lee
Try now.
I added a route to my startup script to see what happnens.
Let me know.
Thanks.
Harold
From: Lee D Bengston <kilo5dat(a)gmail.com<mailto:kilo5dat@gmail.com>>
Date: Monday, October 10, 2022 at 9:39 AM
To: Harold Kinchelow <k7ilo(a)outlook.com<mailto:k7ilo@outlook.com>>
Subject: Re: [44net] Testing 1 2 3 4
Fyi I can ping .193 and .194 but not .195
Lee K5DAT
On Mon, Oct 10, 2022 at 12:39 AM Harold Kinchelow <k7ilo(a)outlook.com<mailto:k7ilo@outlook.com>> wrote:
I figured that’s what you meant. LOL
Do me a favor and see if you get a ping response from 44.63.63.193, 194 and 195
Thanks
Harold
From: Lee D Bengston <kilo5dat(a)gmail.com<mailto:kilo5dat@gmail.com>>
Date: Sunday, October 9, 2022 at 3:18 PM
To: Harold Kinchelow <k7ilo(a)outlook.com<mailto:k7ilo@outlook.com>>
Subject: Re: [44net] Testing 1 2 3 4
OK, meant to say trace to .66 should go thru .65, but I think you got the gist. Glad to hear things are working.
73,
Lee K5DAT
On Sun, Oct 9, 2022 at 3:28 PM Harold Kinchelow <k7ilo(a)outlook.com<mailto:k7ilo@outlook.com>> wrote:
Lee
Ping and traceroute as expected.
Thanks
Harold
K7ILO
From: Lee D Bengston <kilo5dat(a)gmail.com<mailto:kilo5dat@gmail.com>>
Date: Sunday, October 9, 2022 at 6:52 AM
To: Harold Kinchelow <k7ilo(a)outlook.com<mailto:k7ilo@outlook.com>>
Subject: Re: [44net] Testing 1 2 3 4
Hello Harold,
Feel free to try 44.92.0.65 & 44.92.9.66. Also if you traceroute to .65 it should go through .65.
73,
Lee K5DAT
On Sat, Oct 8, 2022 at 9:24 PM Harold Kinchelow via 44net <44net(a)mailman.ampr.org<mailto:44net@mailman.ampr.org>> wrote:
Hey gang.
Are there a couple of ip’s I can use the do a ping test from my network?
Trying to test to make sure Im heading in the right direction.
Thanks
Harold
K7ILo
_______________________________________________
44net mailing list -- 44net(a)mailman.ampr.org<mailto:44net@mailman.ampr.org>
To unsubscribe send an email to 44net-leave(a)mailman.ampr.org<mailto:44net-leave@mailman.ampr.org>