# A machine on a routable address, and a machine behind a household connection. # # This is the case that only exists in production today: the second machine is reachable # from the first only through a forwarded port, at the GATEWAY's address, never its own. scenario: behind-nat segments: hosting: kind: public cidr: [192.0.2.0/24] home: kind: private cidr: [192.168.1.0/24] gateway: to: hosting address: [192.0.2.50] # what the world sees the household as nat: [v4] forwardable: true mapping_ttl: 120s machines: anchor: at: { segment: hosting, address: [192.0.2.10] } inbound: allow home-server: # a dash in the name, on purpose at: { segment: home, address: [192.168.1.135] } published: - { port: 8080, on: home } inbound: allow