# One machine with a routable address, one publicly named but behind a household # connection, one stationary machine on that network, one that roams. # # Three unrelated public networks, routed to each other and never bridged — putting them # in one prefix would make ARP adjacency, non-decrementing TTL and crossing multicast # true in the lab and false in production. scenario: the-ordinary-shape segments: hosting: kind: public cidr: [192.0.2.0/24, "2001:db8:a::/48"] isp-home: kind: public cidr: [198.51.100.0/24, "2001:db8:b::/48"] isp-mobile: kind: public cidr: [203.0.113.0/24, "2001:db8:c::/48"] home: kind: private cidr: [10.99.1.0/24, "2001:db8:b:1::/64"] mtu: 1492 gateway: to: isp-home address: [198.51.100.7, "2001:db8:b::7"] nat: [v4] forwardable: true mapping_ttl: 120s devices: kind: private cidr: [192.168.30.0/24] gateway: to: isp-home address: [198.51.100.7] nat: [v4] forwardable: true mapping_ttl: 120s cafe: kind: private cidr: [10.50.0.0/16] mtu: 1400 gateway: to: isp-mobile address: [203.0.113.129] nat: [v4] forwardable: false mapping_ttl: 30s policy: - { from: devices, to: home, allow: false } - { from: home, to: devices, allow: true } machines: anchor: at: { segment: hosting, address: [192.0.2.10, "2001:db8:a::10"] } inbound: allow home-server: at: { segment: home, address: [10.99.1.135, "2001:db8:b:1::135"] } published: - { port: 443, on: home } inbound: allow workstation: at: { segment: home, address: [10.99.1.250, "2001:db8:b:1::250"] } inbound: deny laptop: at: { segment: home, address: [10.99.1.98, "2001:db8:b:1::98"] } inbound: deny # No `place:` yet. The node host it would place does not exist — this lab is being built to # develop it, and the lab refuses declarations it cannot materialise rather than raising a # mesh that silently lacks them. snapshot: raised