PFCONNECT DEPLOYMENT GUIDE

Center ต้องทำอะไร
Station ต้องทำอะไร

คู่มือหน้าเดียวสำหรับทบทวนการติดตั้ง การเชื่อมต่อครั้งแรก และการตรวจสอบระบบ PFCONNECT

01 • OVERVIEW

ภาพรวมการทำงาน

Center บริหารข้อมูลและสร้าง Runtime Configuration ส่วน Station รับค่า ตรวจสอบ และ Apply ลงบนระบบจริง

C

PFCONNECT Center

จัดการ Customer, Site, Network, Peer, Permission และ Runtime Revision

S

PFCONNECT Station

ติดตั้ง Agent, เชื่อม NetBird, รับ Desired State และ Apply WireGuard, Route และ VXLAN

02 • CENTER SIDE

ฝั่ง Center ต้องทำอะไรบ้าง

01

เตรียม Center

ติดตั้ง Center, Runtime Center และ Dashboard พร้อมตรวจสอบ Service

02

สร้าง Customer

กำหนด Customer Code, Master Site, WG Network และค่าพื้นฐาน

03

สร้างหรือ Register Site

เพิ่ม Site ID, Site Name, NetBird IP, Local LAN และ Sync Key

04

กำหนด Permission

ระบุว่า Site ใดเข้าถึง Network ใด เช่น Branch ไป ERP Server

05

Generate Runtime

สร้าง Peer, Allowed IP, Route, Revision และ Desired State

06

ตรวจสอบสถานะ

ตรวจ Site, Peer, Route, Last Sync และสถานะ Agent จาก Dashboard

Center ไม่ต้อง Apply Route ให้ Station เอง

Center สร้าง Desired State ส่วน Station Agent เป็นผู้สร้าง Interface, Peer, Route และ VXLAN

03 • STATION SIDE

ฝั่ง Station ต้องทำอะไรบ้าง

01

เตรียมระบบ

ติดตั้ง Linux/OpenWrt เปิด IPv4 Forwarding และตรวจ ip, wg และ vxlan

02

ติดตั้ง NetBird

เชื่อม Station เข้า NetBird และตรวจสอบว่า wt0 มีสถานะ UP

03

ติดตั้ง Agent

กำหนด Center URL, Customer, Site ID และ Sync Key

04

Register / Sync

ลงทะเบียน Site หรือใช้ Sync Key จาก Center แล้วดึง Runtime

05

Apply Configuration

Agent สร้าง pfwg0, Peer, Allowed IP, Route และ VXLAN

06

ตรวจสอบผล

ตรวจ wt0, pfwg0, Handshake, Route และการเข้าถึง LAN ปลายทาง

Station ไม่ควรแก้ Runtime ด้วยมือเป็นหลัก

หากแก้ Route หรือ WireGuard ด้วยมือ Agent อาจคืนค่าตาม Desired State ในรอบ Sync ถัดไป

04 • FIRST CONNECTION

ลำดับการเชื่อมต่อครั้งแรก

1

Center: สร้าง Site

กำหนด Site ID, Local LAN, NetBird IP และสร้าง Sync Key

2

Station: เชื่อม NetBird

ตรวจสอบว่า wt0 UP และมองเห็น NetBird Network

3

Station: ตั้งค่า Agent

กำหนด Center, Customer Code, Site ID และ Sync Key

4

Center: กำหนด Permission

เลือก Network ที่ Site นี้เข้าถึงได้ และ Generate Runtime

5

Station: Run Sync

Agent ดึง Runtime แล้ว Apply pfwg0, Peer และ Route

6

ทดสอบการเชื่อมต่อ

ตรวจ Handshake, Ping Tunnel IP และทดสอบ LAN ปลายทาง

05 • DAILY OPERATION

การทำงานประจำวัน

Centerแก้ Site / Network / Permission
Runtime Engineสร้าง Revision และ Desired State
Station AgentSync, Compare และ Apply
NetworkWireGuard / Route / VXLAN พร้อมใช้
06 • CHECKLIST

Checklist ก่อนใช้งานจริง

Center Checklist

  • Center Service ทำงาน
  • Runtime Center ทำงาน
  • Customer และ Site ถูกต้อง
  • Site มี Sync Key
  • Local LAN ไม่ชนกัน
  • Permission ถูกต้อง
  • Runtime Revision ถูก Generate

Station Checklist

  • NetBird Connected
  • wt0 มี IP และสถานะ UP
  • IPv4 Forwarding เปิด
  • pfagent config ถูกต้อง
  • pfagent doctor ผ่าน
  • pfwg0 ถูกสร้าง
  • WireGuard Handshake สำเร็จ
  • Route ไป Remote LAN ถูกสร้าง
07 • VERIFY COMMANDS

คำสั่งตรวจสอบที่ใช้บ่อย

ฝั่ง Station

pfagent status
pfagent doctor
pfagent-runtime status
pfagent-runtime sync
ip link show wt0
ip link show pfwg0
wg show
ip route

ฝั่ง Center

pfconnect-site list
systemctl status pfconnect-center
systemctl status pfconnect-runtime-center
curl -s http://127.0.0.1:9443/health
curl -s http://127.0.0.1:9444/health
หมายเหตุ

ชื่อคำสั่งอาจต่างตาม Version แต่หลักการคือ Center ต้องสร้าง Runtime ได้ และ Station ต้อง Sync/Apply ได้ครบ