Deploy CanMe

Stand up your network.

Boot the image, tell it what to be, repeat. Three steps to a working network.

The short path

Three steps to a working network

Pick a step for what it involves.

You → CoreMesh ↔ CoreUsers → MeshYour laptopNot an applianceCoreAlways requiredMeshAlways requiredYour usersNot an appliance
Other parts of the picture

Tap a component for its sizing and rules, or a link for what rides on it.

Name your network and pick where it runs.

You host CanMe, so you choose this.

Fill these in once the machines have addresses.

Where it will run

Same image either way. This just decides which link you need.

The image

Download the image

CanMe Core runs as a virtual machine in your cloud, or from the CAN Live ISO on your own hardware. The rollout steps after boot are identical either way — the launch links below are pulled live from our downloads server, so they are always the current release.

Launch the CanMe AMI in the AWS Console, then continue with the Core rollout below.

Version1.0.6
Regioneu-central-1
Image ID
ami-0c0e6b36af010f25a

Your users don't need any of this

Once the network is up, employees and guests just install the client and sign in. Send them to the join page.

See the join page

Admin questions

How many machines do I need to start?

Two. A Core (4 CPU, 16 GB RAM, 80 GB disk) and one Mesh (2 CPU, 8 GB, 60 GB). That is the whole of steps 1 to 3 — everything after it is more of the same.

Is it really the same image for Core, Mesh and Gate?

Yes. One ISO, one cloud image. You boot it and choose what that machine becomes on its rollout page, so there is nothing to pick correctly at download time.

Do I need a Mesh and a Gate?

One Core, and at least one Mesh — your everyday users connect through a Mesh, so without one nobody can reach the network. Add more Meshes for capacity or extra sites. A Gate is the only optional part, and only for devices that cannot run a client themselves: printers, PLCs, legacy servers, whole subnets.

Which ports do I need to open?

Every part carries its own list — select it in the diagram above for its inbound and outbound rules. In short: the Core listens on 80, 443, 8440, 8443 and 9000, a Mesh reaches the Core on 8440, and outbound each appliance needs DNS and 443 for licensing, updates and certificates.

What is the Rollout Page at :8443?

A temporary, secure setup interface exposed on port 8443 before Cansole exists. You use it once to install Core (or to enroll a Mesh/Gate with a token); it disables itself automatically when the rollout completes.

The rollout page or Cansole won't load. What's wrong?

Almost always one of three things on your own laptop: the Cannector client is not installed, an SSL/TLS-inspecting proxy is breaking the connection, or another VPN is still connected. Also check that the DNS record from step 1 actually resolves before you type an address anywhere.

What happens if I lose the break-glass account?

It is shown exactly once, at the end of the Core install, and cannot be retrieved again — put it in your password manager the moment you see it. Use your own account for day-to-day work and keep the break-glass credentials sealed for emergencies.

How do updates work?

Everything is driven from Cansole — no manual work, no USB sticks. As soon as a new update is available, you roll it out across every component, ring by ring.

What do my users have to install?

The Cannector client, and nothing else. Send them to the join page for your network; they install it, sign in, and they are on. Client-less devices behind a Gate change nothing at all.

Do I need a license key up front?

You need one to complete the Core install. If you do not have it yet, write to hello@canme.cloud and we will send you one.