Skip to main content

ArcNet

ArcNet is the encrypted tunnel layer of the EmberNet fabric: the point-to-point IP tunnels between the central platform and every remote site, giving nodes plain Layer 3 reachability to each other for agent check-ins and storage replication.

Where Flux is an identity-based application overlay, ArcNet is a straightforward encrypted IP tunnel.

Flux is the primary path, and ArcNet is the one that needs the network's permission. ArcNet is UDP and wants a reachable port, which is the first thing an industrial network filters; Flux rides outbound TCP/443, which is the egress those sites allow. An endpoint that reports ArcNet as its active path has lost Flux and is degraded, not optimized.

At sites where Flux is the only thing that gets out, ArcNet does not stop working. It is carried over Flux, so the site still gets its Layer 3 tunnel without needing UDP to traverse the plant firewall. That is the normal configuration, not a fallback.

Where it sits​

The fabric uses different layers for different jobs:

LayerCarried byWhat rides on it
Layer 3 (IP routing)ArcNetNode-to-node IP reachability and storage replication between nodes
Layer 4+ (application overlay)FluxThe cluster API, cross-site app interfaces, device proxying, remote access
Layer 2 (Ethernet bridging)WeldLegacy protocols that need a broadcast domain, such as EtherNet/IP and PROFINET discovery

Most deployments only use the first two. Weld is operator-toggled and exists for equipment that cannot work any other way.

The cluster API is on Flux, not ArcNet. Nodes reach their own cluster API through a Flux service address rather than a node IP, which is what lets a site keep a working control plane when its ArcNet tunnel is down or was never permitted. Do not design around the assumption that losing ArcNet costs you the control plane; it does not.

Addressing​

ArcNet is a hub-and-spoke topology built on RFC 6598 carrier-grade NAT space, 100.64.0.0/10, with the hub at 100.64.0.1. Each organization gets its own /24 inside that block, and its peers are addressed from it.

PropertyValue
TransportUDP
Address space100.64.0.0/10 (RFC 6598)
TopologyHub-and-spoke
Per organizationOne /24
Available addresses4,194,304

RFC 6598 rather than RFC 1918 is a deliberate choice. Factory networks are full of 10.x and 192.168.x addressing, and a management tunnel that collides with plant addressing is a management tunnel you cannot use during an incident. The 100.64.0.0/10 block is non-routable on the public internet, distinct from RFC 1918 space, and large enough that no deployment will exhaust it.

Tunnel status and peers​

ArcNet is managed by Fireball platform staff from the ArcNet tab of the Flux Console in Global Command. From there they create, rename, enable, disable, and delete peers, assign each peer to an organization, and hand out its configuration or enrollment QR code.

A peer counts as connected when its last handshake completed within the last two minutes. A handshake older than that does not always mean the tunnel is broken. ArcNet is quiet when there is nothing to send, so a genuinely idle peer can drift out of connected and recover the moment traffic resumes.

Tenant users do not manage ArcNet peers. A peer is tied to an organization by the tag platform staff give it, so a peer with no tag belongs to no organization.

Relationship to the rest of the platform​

  • Flux is the primary path and carries application traffic and the cluster API; ArcNet gives nodes Layer 3 IP reachability to each other. They are complementary, not alternatives, and on most sites ArcNet is carried over Flux rather than running beside it.
  • Network Devices reaches managed network equipment over ArcNet tunnels.
  • Ops deploys to clusters that are reachable over ArcNet.
  • Cinder replicates storage between nodes across it.

Next steps​