Skip to content

Quick Start

The 3 Things You Need to Know

  1. The AI runs in an isolated box — It's on a virtual machine on your Strato server, completely separated from everything else.
  2. You control the AI's internet access — Go to the "AI Access Level" tab and choose Locked, Minimal, Development, or Unrestricted.
  3. If something goes wrong, hit Emergency Stop — The red 🛑 button immediately cuts off all AI internet access.

Connecting via VPN

Step 1: Connect to the Admin VPN

Use NetworkManager or the command line:

# NetworkManager GUI: Activate "Strato VPS Host" connection
# Or manually:
sudo wg-quick up vpn_host

Step 2: Verify Connectivity

ping -c 2 10.0.0.1  # Strato host via VPN

Step 3: Access the Control Center

Open your browser and navigate to: https://firewall.clsxx.de

Login with BasicAuth credentials when prompted.

SSH Access

All SSH is VPN-only. No public SSH ports exist.

Target Command
Strato Host ssh -o IdentitiesOnly=yes -i ~/.ssh/openclaw_strato_key admin@10.0.0.1
Strato VM ssh -o IdentitiesOnly=yes -i ~/.ssh/openclaw_vm_strato_key admin@192.168.10.10
Local VM ssh -o IdentitiesOnly=yes -i ~/.ssh/openclaw_vm_key openclaw@192.168.1.200

Setting the AI's Access Level

  1. Go to the "AI Access Level" tab
  2. Click the desired level card
  3. Confirm the change in the modal dialog
  4. The firewall rules are applied immediately
Level What the AI Can Do
🔴 Locked Nothing — DNS lookups only
🟠 Minimal Browse websites (HTTPS)
🔵 Development Web + Git + SSH
🟢 Unrestricted Everything — no limits