All, I recently stood up a ac2 for a tunnel server to 44net and a ac3 as a node being linked by a transit tunnel. Now this setup is perfectly acceptable from what I read and standard. It works. I started thinking about how all this ties together and had a novel idea. Standing all this up in a mini pc using proxmox. Has anyone done or tried this. The cost would be about the same as running 3 pieces of hardware.
The general idea.
I sit behind CGNAT as a cable modem user. So the first lxc would be a ultra light Linux container to run the wireguard tunnel to 44net. Eth0 on the machine bridged into the wan port and lan would be a vbridge0 out.
The next VM would be provisioned to be a supernode wan would be the vbridge0 and dtd out vbr1
the next VM would be a AREDN node wan also feed by vbr0 and lan dtd vbr1 to link to the super, last but not least add one more lan out to eth2 on the machine. Creating a whole routing environment virtually. Leaving the lan port for a dtd radio or direct lan link to the node. This could also host AREDN wireguard tunnels into the mesh as intended.
This would also have the advantage of leveraging faster hardware and more ram for the supernode. Backups would all be handled in proxmox so it could be directly replicated in other locations, or cloud servers. The faster speeds of the intel processors would eat tunnels for breakfast and the total system shouldn't even break a sweat at 50-100 node routings. If my internet could handle that. But say you have a served agency that has incredible internet this would smoke any current hardware specs.
Have any of you tried setting up a whole network in this fashion? Is it worth trying and seeing what it could do? Is this just an exercise in futility?
I wanted to move my local mesh island routing thru a super node to still link to the world but not advertise everything on our network unless others meant to get there.
Again thanks in advance for any ideas or pitfalls.
KM6TFY - Daniel.
The general idea.
I sit behind CGNAT as a cable modem user. So the first lxc would be a ultra light Linux container to run the wireguard tunnel to 44net. Eth0 on the machine bridged into the wan port and lan would be a vbridge0 out.
The next VM would be provisioned to be a supernode wan would be the vbridge0 and dtd out vbr1
the next VM would be a AREDN node wan also feed by vbr0 and lan dtd vbr1 to link to the super, last but not least add one more lan out to eth2 on the machine. Creating a whole routing environment virtually. Leaving the lan port for a dtd radio or direct lan link to the node. This could also host AREDN wireguard tunnels into the mesh as intended.
This would also have the advantage of leveraging faster hardware and more ram for the supernode. Backups would all be handled in proxmox so it could be directly replicated in other locations, or cloud servers. The faster speeds of the intel processors would eat tunnels for breakfast and the total system shouldn't even break a sweat at 50-100 node routings. If my internet could handle that. But say you have a served agency that has incredible internet this would smoke any current hardware specs.
Have any of you tried setting up a whole network in this fashion? Is it worth trying and seeing what it could do? Is this just an exercise in futility?
I wanted to move my local mesh island routing thru a super node to still link to the world but not advertise everything on our network unless others meant to get there.
Again thanks in advance for any ideas or pitfalls.
KM6TFY - Daniel.
