Reaching computers on other networks
For administrators: connecting BeeBEEP across subnets and VPNs such as Tailscale with a beehosts.ini file, the ports to open, and Wi-Fi isolation.
For: administrators · From BeeBEEP 6.0.0 · Updated on
BeeBEEP finds the users of a local network by itself. A computer on another network -- another subnet of your office, a VPN such as Tailscale, a network that does not pass broadcast -- has to be named once, by its address or by its host name. This page is for whoever runs the network: how to name many computers at once with one file, what the network must let through, and what a Wi-Fi with client isolation does. How a user adds one person by hand is in finding the people you want to reach.
Why some computers are not found
BeeBEEP announces itself with broadcast and multicast packets, which never leave the network they are sent on. A router between two subnets stops them, and a VPN carries only packets sent to one address: Tailscale, for one, carries no broadcast or multicast at all. The computers can still reach each other; they only need to know where to look.
Once two users are connected, everything works as on one network: chats, groups and files.
BeeBEEP also tries by itself on a network that drops broadcast: at every start and at every search it sends its announcement straight to the addresses where it last met other users, and to the addresses of its own network (what BeeBEEP tries by itself). Beyond its own network it needs the list below.
Which network interfaces BeeBEEP uses
A computer often has more network interfaces than networks a person works on: bridges for containers and virtual machines, VPN tunnels. BeeBEEP sends its broadcast announcements, and asks whether a network is private or public, only on interfaces that can lead to other people:
- up and running, not the loopback, and not reported by the system as virtual;
- not a bridge for containers or virtual machines: on Linux and macOS, names that start with
docker,veth,virbr,br-,vboxnetorvmnet; - not a point-to-point tunnel:
tun, and on macOSutun; - on macOS, not AirDrop's radios,
awdlandllw.
A TAP adapter -- a VPN that bridges the computer onto a remote local network -- counts as a network like any other: BeeBEEP announces itself there and finds the people of that network.
This list only decides where BeeBEEP announces itself by broadcast and which networks it asks you about. A computer named by its address, under Add a user by address or in beehosts.ini, is reached through whichever interface the system chooses, a tunnel included: that is how BeeBEEP works over Tailscale.
Connect a whole group with beehosts.ini
For more than a couple of computers, write them all in one file and copy it to every computer of the group. The file is beehosts.ini, in the data folder (see the data folder); BeeBEEP reads it at every start. An administrator can also place one beside the policy file (see the policy file): that one always applies, and yours adds to it.
# The computers of the office, one per line
office-pc.tailnet-name.ts.net
laptop-anna.tailnet-name.ts.net
192.168.3.32
server.example.com tcp
# A whole network of the office
10.0.5.0/24
Each BeeBEEP recognizes its own name and addresses in the list and skips them, so the same file works on every computer. Whichever computer starts later reaches the others, and when a computer's network changes, BeeBEEP contacts the list again.
How a line is written
A line is host[:port] [udp|tcp]: an address or a host name, then a port if it is not the default one, then how BeeBEEP makes the first contact. Spaces around the words do not matter, nor the case of udp and tcp.
| Way | Default port | What BeeBEEP does |
|---|---|---|
udp, or nothing | 36475 | sends its announcement straight to that computer; the other BeeBEEP answers and connects back; a computer that is switched off costs nothing |
tcp | 6475 | connects to that computer's listening port at start, and sends its announcement to port 36475 at the same time, so the other side can connect back if the connection does not get through |
Write udp (or nothing) for most computers. Write tcp for a computer whose network lets only the listening port through.
A file written for BeeBEEP 5.x reads the same way: its lines name hosts to contact over udp. A line BeeBEEP cannot read is skipped with a warning in the log, without stopping the rest of the file.
A whole network
A line a.b.c.d/n names a network: BeeBEEP sends its announcement to every address of it, at start, when its own network changes and when you search. 10.0.5.255, the way BeeBEEP 5.x wrote it, means 10.0.5.0/24. Only announcements are sent, never a connection, at the pace of the search above.
A network larger than 256 addresses is covered in blocks of 256, and all the network lines of the file together cover at most 16 such blocks (about 4 000 addresses); BeeBEEP writes to the log what it left out. Such a line takes no port and no tcp, and an IPv6 network is never covered address by address: these lines are skipped with a warning.
A line that starts with ! blocks an address instead (see hosts to block).
What the network must let through
Between the computers, allow:
| Port | Protocol | Used for |
|---|---|---|
6475 | TCP | the connection itself (the Listening port) |
36475 | UDP | the announcement that asks the other side to connect |
On a computer whose firewall asks, allow BeeBEEP on the network the VPN creates, not only on the local one. If the computers use a network password (Settings > Network > Use network password), they all need the same one: an announcement under another password is not read.
Tailscale
With MagicDNS on, each computer of the tailnet has a name such as office-pc.tailnet-name.ts.net, shown in the Tailscale admin console. Use those names in the field or in beehosts.ini: they keep working when Tailscale gives a computer a new address. If your tailnet's access rules restrict ports, allow TCP 6475 and UDP 36475 between the computers that use BeeBEEP.
A Tailscale name usually resolves to an IPv4 and an IPv6 address; BeeBEEP uses the IPv4 one unless Prefer IPv6 over IPv4 is on.
Wi-Fi with client isolation
A Wi-Fi with client isolation -- guest networks, most public hotspots, some office access points -- drops every packet between two wireless devices, broadcast and direct connections alike: no file and no list of addresses connects them. If BeeBEEP is meant to work on your Wi-Fi, give its users a network without client isolation, or allow traffic between their devices; where isolation has to stay, a computer on the cable running BeeBEEP lets the wireless devices talk through it. Wi-Fi networks that keep devices apart explains it for the users.