# Two things production has and a flat lab cannot show. # # `devices` and `home` sit behind ONE router — identical gateway declarations — with a # policy allowing home→devices and denying the reverse. That is an ordinary segmented # household router, and the asymmetry is the normal case. # # `cafe` sits behind a gateway we do not control. Outbound works; nothing initiates # inward, and nothing can be published there at all. scenario: segmented-and-unforwardable segments: hosting: kind: public cidr: [192.0.2.0/24] home: kind: private cidr: [192.168.1.0/24] gateway: to: hosting address: [192.0.2.50] nat: [v4] forwardable: true mapping_ttl: 120s devices: kind: private cidr: [192.168.30.0/24] gateway: to: hosting address: [192.0.2.50] # identical → the SAME router nat: [v4] forwardable: true mapping_ttl: 120s cafe: kind: private cidr: [10.50.0.0/16] gateway: to: hosting address: [192.0.2.80] nat: [v4] forwardable: false # carrier-grade NAT, or simply not ours mapping_ttl: 30s policy: - { from: devices, to: home, allow: false } - { from: home, to: devices, allow: true } machines: anchor: at: { segment: hosting, address: [192.0.2.10] } inbound: allow home-server: at: { segment: home, address: [192.168.1.135] } inbound: allow thermostat: at: { segment: devices, address: [192.168.30.20] } inbound: allow roamer: at: { segment: cafe, address: [10.50.3.23] } inbound: allow