Connection paths
A gateway at the site. A path to the right resource.
The gateway joins. The printer keeps its address.
- Approved teammateOutside the office→WireGuard
- Fibmesh routing nodePrivate network→WireGuard
- Office gatewayApproved LAN route→LAN
- Server / NAS / printerExisting local IP
Reach supported resources at the location without installing Fibmesh on each appliance.
Gateway enrollment does not individually enroll LAN equipment. Printer/scanner support depends on IP protocols and drivers; broadcast discovery and USB-only devices are not automatically carried across the network.
See device and gateway options →Forward selected ports to selected local services.
- External clientAssigned public IP and port→Service request
- Fibmesh public deliveryInbound firewall→WireGuard
- Site connector / gatewayTunnel and target mapping→LAN
- NVR or serverApproved LAN IP and port
A supported gateway deployment can map different public ports to different local targets. Replies to Fibmesh-delivered connections return through Fibmesh.
Ordinary LAN internet traffic keeps its ISP route unless routing is changed explicitly. The preconfigured Fibmesh Edge device approach has a customer POC; hardware remains development/pilot.
Explore Gateway IPs →Outgoing identity needs traffic to reach the gateway.
- Selected LAN devicesRoute via configured gateway→LAN route
- Customer router / gatewayExplicit traffic selection→WireGuard
- Fibmesh public sourceDelivery / exit location→Internet
- External serviceSees configured source
Give routed LAN traffic a stable public source for approved third-party access, using Public IPs or a suitable Outbound deployment.
Simply plugging a one-port connector into the LAN does not redirect the other devices’ outgoing traffic. Gateway placement, routes, return traffic and supported address families must be configured.
Explore traffic routing →Put it to work
Three different jobs for a site connection.
A shop may need shared billing, an office may need remote access to files, and a service team may need an equipment interface. A gateway can connect these resources without installing software on every one. The routing setup depends on which job it must do.
Reach resources privately
Approved staff can reach supported applications, storage and network peripherals through Networks. A site gateway provides the route to the selected local destinations.
Office resource access →Make a service reachable
Gateway IPs can deliver selected public traffic to a local server or appliance. Different public ports can map to different approved local targets where supported.
Public access to LAN services →Present a stable outgoing IP
Route selected LAN traffic through a suitable gateway and Fibmesh public source for third-party allowlisting. The rest can retain the existing ISP path under the chosen setup.
Plan the outgoing path →For an internet exit, LAN traffic must be routed to a supported gateway; current Outbound profiles use full tunnel. A Publish hostname only serves compatible web applications. Compare the connection options →

From a customer deployment
Shared billing across restaurant locations.
An anonymous restaurant-chain deployment used Public IPs with full tunnel for access to shared billing. It demonstrates that address-based arrangement; it does not establish a private branch mesh.
- Public IPs deployment
- Full-tunnel traffic arrangement
- Anonymous example; no performance figures claimed
A practical first deployment
Place the gateway for the job it must do.
Choose the targets
List local addresses and ports, site ranges and allowed users. Check overlapping addresses across offices, homes and clouds.
Plan both directions
For private access, provide a return route or supported source NAT. For public delivery, keep replies on Fibmesh. For outgoing identity, explicitly route the intended LAN traffic to the gateway.
Test with the site owner
Use the real client, verify the observed source and permitted ports, restart the connector, and retain a local recovery method. A powered-off gateway or failed ISP still affects reachability.
Questions, answered
Before you connect.
Does plugging in a connector change all the office’s internet traffic?
No. A connector can serve selected incoming targets without becoming the LAN’s default gateway. Outgoing routing needs explicit configuration; ordinary LAN traffic otherwise follows the existing ISP path.
What was demonstrated with the preconfigured Edge device?
A customer POC used a preconfigured device on the LAN to reach an NVR and server through remotely configured target mappings. The Fibmesh Edge device is a deployment option in development/pilot, not a generally released hardware product.
Can one site use both private access and public services?
Yes as a deployment design, with separate permissions, rules and supported routing. A private file server and a public application should not inherit each other’s exposure. Verify combined behavior on the chosen gateway.
Do branch printers and scanners just appear automatically?
No. Address-based protocols and appropriate drivers may work through an approved route. Broadcast discovery, USB-only equipment and local-only software need separate handling.
Start with one site and one useful service. Decide whether the gateway is providing access to a resource, routing outgoing traffic, or both.
Plan your first deployment →