Identity and access
| Term | Meaning |
|---|---|
| Workspace | The organisation’s scope for members, resources and policy. |
| Enrollment | The process that gives a device or gateway an identity in a workspace. |
| Device ID | An identifier for an enrolled resource. It is not a password or proof of authorisation by itself. |
| Access group | A way to organise private membership and permissions. Joining more groups does not create a new device address for each group. |
| Private address | An address used within the private network rather than as a public internet destination. |
| CGNAT range | Shared IPv4 address space, 100.64.0.0/10, used for Networks private addressing. Using this range does not itself mean all Fibmesh services perform NAT. |
| Private IPv6 | IPv6 addressing for private network participation, distinct from a publicly routed IPv6 allocation. |
| Private DNS | Names for authorised private resources. Resolving a name does not grant network or application access. |
Devices and delivery
| Term | Meaning |
|---|---|
| Endpoint | A participating laptop, phone, server or other supported device. |
| Agent | Software that handles enrollment, policy and status on a supported host. |
| Gateway | A resource that carries approved traffic between network boundaries, for example into an office LAN. |
| Connector | In Publish, the customer-side software that reaches the app and connects it to the Fibmesh gateway through a tunnel. |
| Node / exit | Fibmesh infrastructure used to carry a connection or deliver traffic to the internet. |
| WireGuard | The currently supported tunnel protocol. It encrypts traffic between its tunnel endpoints, not every later hop to an internet service. |
| Compatibility Mode | A manually managed WireGuard profile with fewer lifecycle and diagnostic features than native enrollment. |
| P2P | A direct peer-to-peer path between participants. Planned for Networks; current paths use Fibmesh nodes. |
Addresses and traffic
| Term | Meaning |
|---|---|
| Inbound | A connection started by the other side, such as an internet visitor opening your server. |
| Outbound | A connection started by your device. “Outbound” is also the name of Fibmesh’s internet-routing product. |
| Return path | The route used for replies. Inbound-only access still needs its responses to return correctly. |
| Selected outbound | A Public IP routing choice: selected destinations use Fibmesh; unrelated destinations use the existing ISP. |
| Full tunnel | Eligible internet traffic follows the chosen tunnel. Local routes, OS exceptions, DNS and unsupported address families need explicit handling. |
| NAT | Address translation. A gateway can translate traffic for LAN devices; direct routed Public IP delivery does not require that same translation model. |
| Routed subnet | A block of public addresses delivered to a supported gateway, from which workloads can use separate addresses. |
| Prefix length | The number after the slash in an address block. For IPv6, /48 is a larger block than /64. Fibmesh Routed Subnets supports separately allocated IPv6 prefixes from /48 through /64. |
| Dual stack | Both IPv4 and IPv6. An IPv6-only allocation does not automatically provide IPv4 connectivity. |
| Allowlist | A list of permitted sources or destinations. Source-IP approval does not replace an application login. |
Configuration and status
| Term | Meaning |
|---|---|
| Policy | The approved rules describing what a resource should be able to do. |
| Desired state | The configuration the backend intends the resource to apply. |
| Observed state | The configuration or result the resource last reported. |
| Latest Sync | The recent exchange of intended policy and reported results. Check its time and outcome. |
| Control plane | The systems that manage identity, policy and configuration. |
| Data plane | The path carrying application traffic. Policy governs this path; it is not an extra physical hop. |
| Revocation | Removal of an identity’s permission or credentials. Verify that affected resources have applied the change. |
