Connect a device, or connect a location
Install a supported app or agent on a device that should participate directly. Use a gateway when approved resources sit behind an existing router or cannot run Fibmesh software themselves. The current tunnel protocol is WireGuard; a manual WireGuard profile is the separate, more limited Compatibility Mode.
- Enrolled colleagueApproved private membership
- Fibmesh nodeEncrypted network path
- Site gatewayIts own enrollment and permissions
- LAN resourceFile server, printer, scanner or supported equipment
Policy: Approve the destination and return route. Downstream equipment does not automatically receive a Fibmesh device identity.
Return path: Use a known resource address or supported private name. Routed access does not carry every local broadcast or make automatic printer discovery work across sites.
Choose the method for your environment
| Method | Good fit | Check before deployment |
|---|---|---|
| Native desktop app | A person using a supported laptop or desktop | OS version, networking permissions and other VPNs |
| Headless agent | A supported server, VM or unattended compute host | Service ownership, updates, credentials and recovery access |
| Mobile app | A supported phone or tablet joining the private network or using supported outgoing routing | VPN lifecycle, background limits and platform exceptions |
| Gateway | Office, branch, cloud or LAN resources reached through one managed host | Approved destinations, forwarding, address overlap and return routes |
| Compatibility Mode | An assessed device using a manually handled WireGuard profile | Manual lifecycle, revocation, routing and reduced diagnostics |
Native platforms have different permissions and networking behaviour. A supported mobile client does not automatically make that phone a supported public application target. Initial public-ingress target scope excludes iOS and Android.
Join directly with an app or agent
The device enrols in the correct workspace and establishes its identity. Keys are generated locally; the backend receives the public key by default. The administrator grants the required access, and the native networking service applies the authorised policy. The visible app reports status rather than performing privileged route changes itself.
Enrollment does not automatically grant access to every resource or alter the default internet route. Check the product setup and supported release for the intended job.
Understand device and gateway enrollment →Reach resources through a gateway
The gateway needs legitimate access to the target network. Approve a destination or subnet, check for overlapping address ranges, and establish the return path. Its own enrollment does not give every downstream device a Fibmesh identity.
This can make a storage server, network printer or scanner reachable across locations. Application accounts, drivers and supported network protocols still matter. Broadcast-based discovery does not automatically cross a routed private network.
For public access through a gateway, assess forwarding rules and the replies separately. A gateway can also carry selected outgoing traffic or full-tunnel traffic when the product and release support that configuration. Fibmesh edge hardware remains a pilot/development deployment option.
Use Compatibility Mode deliberately
A manually managed profile has a smaller feature set than a native app. Do not expect dynamic policy refresh, complete route/DNS conflict handling or the same diagnostics. Follow the approved key-handling and removal procedure; never send an endpoint private key to the backend by default.
Choose the path separately from the method
Joining the workspace establishes identity. Network permissions decide reachability. Routing decides where packets travel. Current private connections use Fibmesh nodes; direct P2P is planned. Private IPv6 is in Networks scope, while automatic assignment needs release verification.
Before installation or automation
Confirm the exact package, supported OS, required privileges and removal procedure on Downloads. Product CLI & API guides distinguish implemented repository commands from proposed controls. Generated internal clients are not a supported public SDK.
