Documentation

The network terms, in plain language.

A short reference for the words used across Fibmesh setup guides, product explanations and connection status.

Read the platform overview ↗

Identity and access

Term Meaning
Workspace The organisation’s scope for members, resources and policy.
Enrollment The process that gives a device or gateway an identity in a workspace.
Device ID An identifier for an enrolled resource. It is not a password or proof of authorisation by itself.
Access group A way to organise private membership and permissions. Joining more groups does not create a new device address for each group.
Private address An address used within the private network rather than as a public internet destination.
CGNAT range Shared IPv4 address space, 100.64.0.0/10, used for Networks private addressing. Using this range does not itself mean all Fibmesh services perform NAT.
Private IPv6 IPv6 addressing for private network participation, distinct from a publicly routed IPv6 allocation.
Private DNS Names for authorised private resources. Resolving a name does not grant network or application access.

Devices and delivery

Term Meaning
Endpoint A participating laptop, phone, server or other supported device.
Agent Software that handles enrollment, policy and status on a supported host.
Gateway A resource that carries approved traffic between network boundaries, for example into an office LAN.
Connector In Publish, the customer-side software that reaches the app and connects it to the Fibmesh gateway through a tunnel.
Node / exit Fibmesh infrastructure used to carry a connection or deliver traffic to the internet.
WireGuard The currently supported tunnel protocol. It encrypts traffic between its tunnel endpoints, not every later hop to an internet service.
Compatibility Mode A manually managed WireGuard profile with fewer lifecycle and diagnostic features than native enrollment.
P2P A direct peer-to-peer path between participants. Planned for Networks; current paths use Fibmesh nodes.

Addresses and traffic

Term Meaning
Inbound A connection started by the other side, such as an internet visitor opening your server.
Outbound A connection started by your device. “Outbound” is also the name of Fibmesh’s internet-routing product.
Return path The route used for replies. Inbound-only access still needs its responses to return correctly.
Selected outbound A Public IP routing choice: selected destinations use Fibmesh; unrelated destinations use the existing ISP.
Full tunnel Eligible internet traffic follows the chosen tunnel. Local routes, OS exceptions, DNS and unsupported address families need explicit handling.
NAT Address translation. A gateway can translate traffic for LAN devices; direct routed Public IP delivery does not require that same translation model.
Routed subnet A block of public addresses delivered to a supported gateway, from which workloads can use separate addresses.
Prefix length The number after the slash in an address block. For IPv6, /48 is a larger block than /64. Fibmesh Routed Subnets supports separately allocated IPv6 prefixes from /48 through /64.
Dual stack Both IPv4 and IPv6. An IPv6-only allocation does not automatically provide IPv4 connectivity.
Allowlist A list of permitted sources or destinations. Source-IP approval does not replace an application login.

Configuration and status

Term Meaning
Policy The approved rules describing what a resource should be able to do.
Desired state The configuration the backend intends the resource to apply.
Observed state The configuration or result the resource last reported.
Latest Sync The recent exchange of intended policy and reported results. Check its time and outcome.
Control plane The systems that manage identity, policy and configuration.
Data plane The path carrying application traffic. Policy governs this path; it is not an extra physical hop.
Revocation Removal of an identity’s permission or credentials. Verify that affected resources have applied the change.
See how these pieces fit together →