Offices and branches

Keep the resources on site. Bring them within reach.

Bring selected office servers, storage and equipment within reach through a supported gateway. Choose private access, public delivery or a stable outgoing source.

Connection paths

A gateway at the site. A path to the right resource.

Follow the connectionIllustrative connection paths

The gateway joins. The printer keeps its address.

  1. Approved teammateOutside the officeWireGuard
  2. Fibmesh routing nodePrivate networkWireGuard
  3. Office gatewayApproved LAN routeLAN
  4. Server / NAS / printerExisting local IP

Reach supported resources at the location without installing Fibmesh on each appliance.

Gateway enrollment does not individually enroll LAN equipment. Printer/scanner support depends on IP protocols and drivers; broadcast discovery and USB-only devices are not automatically carried across the network.

See device and gateway options →

Forward selected ports to selected local services.

  1. External clientAssigned public IP and portService request
  2. Fibmesh public deliveryInbound firewallWireGuard
  3. Site connector / gatewayTunnel and target mappingLAN
  4. NVR or serverApproved LAN IP and port

A supported gateway deployment can map different public ports to different local targets. Replies to Fibmesh-delivered connections return through Fibmesh.

Ordinary LAN internet traffic keeps its ISP route unless routing is changed explicitly. The preconfigured Fibmesh Edge device approach has a customer POC; hardware remains development/pilot.

Explore Gateway IPs →

Outgoing identity needs traffic to reach the gateway.

  1. Selected LAN devicesRoute via configured gatewayLAN route
  2. Customer router / gatewayExplicit traffic selectionWireGuard
  3. Fibmesh public sourceDelivery / exit locationInternet
  4. External serviceSees configured source

Give routed LAN traffic a stable public source for approved third-party access, using Public IPs or a suitable Outbound deployment.

Simply plugging a one-port connector into the LAN does not redirect the other devices’ outgoing traffic. Gateway placement, routes, return traffic and supported address families must be configured.

Explore traffic routing →

Put it to work

Three different jobs for a site connection.

A shop may need shared billing, an office may need remote access to files, and a service team may need an equipment interface. A gateway can connect these resources without installing software on every one. The routing setup depends on which job it must do.

Reach resources privately

Approved staff can reach supported applications, storage and network peripherals through Networks. A site gateway provides the route to the selected local destinations.

Office resource access →

Make a service reachable

Gateway IPs can deliver selected public traffic to a local server or appliance. Different public ports can map to different approved local targets where supported.

Public access to LAN services →

Present a stable outgoing IP

Route selected LAN traffic through a suitable gateway and Fibmesh public source for third-party allowlisting. The rest can retain the existing ISP path under the chosen setup.

Plan the outgoing path →

For an internet exit, LAN traffic must be routed to a supported gateway; current Outbound profiles use full tunnel. A Publish hostname only serves compatible web applications. Compare the connection options →

Illustrative restaurant setting
Illustrative photography · not a photograph of the described customer or deployment.

From a customer deployment

Shared billing across restaurant locations.

An anonymous restaurant-chain deployment used Public IPs with full tunnel for access to shared billing. It demonstrates that address-based arrangement; it does not establish a private branch mesh.

  • Public IPs deployment
  • Full-tunnel traffic arrangement
  • Anonymous example; no performance figures claimed
Read the shared billing example →

A practical first deployment

Place the gateway for the job it must do.

  1. Choose the targets

    List local addresses and ports, site ranges and allowed users. Check overlapping addresses across offices, homes and clouds.

  2. Plan both directions

    For private access, provide a return route or supported source NAT. For public delivery, keep replies on Fibmesh. For outgoing identity, explicitly route the intended LAN traffic to the gateway.

  3. Test with the site owner

    Use the real client, verify the observed source and permitted ports, restart the connector, and retain a local recovery method. A powered-off gateway or failed ISP still affects reachability.

Questions, answered

Before you connect.

Does plugging in a connector change all the office’s internet traffic?

No. A connector can serve selected incoming targets without becoming the LAN’s default gateway. Outgoing routing needs explicit configuration; ordinary LAN traffic otherwise follows the existing ISP path.

What was demonstrated with the preconfigured Edge device?

A customer POC used a preconfigured device on the LAN to reach an NVR and server through remotely configured target mappings. The Fibmesh Edge device is a deployment option in development/pilot, not a generally released hardware product.

Can one site use both private access and public services?

Yes as a deployment design, with separate permissions, rules and supported routing. A private file server and a public application should not inherit each other’s exposure. Verify combined behavior on the chosen gateway.

Do branch printers and scanners just appear automatically?

No. Address-based protocols and appropriate drivers may work through an approved route. Broadcast discovery, USB-only equipment and local-only software need separate handling.

Start with one site and one useful service. Decide whether the gateway is providing access to a resource, routing outgoing traffic, or both.

Plan your first deployment →