Routing & publishing
Subnet routes, exit nodes, mesh DNS and the Reverse Proxy.
Reaching things that are not on the mesh
- Subnet routes — One device advertises a LAN behind it, and the rest of the mesh reaches that range through it.
- Exit nodes — Send all internet traffic through a nominated device.
- Networks and Resources — Expose specific subnets or hosts, with routing peers and policy control, rather than the whole LAN.
- Mesh DNS — Reach a peer as devicename.mesh instead of remembering a tunnel address.
Publishing a service outward
The Reverse Proxy publishes an internal service on a public domain in three modes: HTTP, TLS passthrough, or raw TCP and UDP. Visitors can optionally be made to sign in first.
Reverse Proxy is complete and unit-tested on both server and client, but the full public-domain path has not been run against a live deployment. Treat it as unproven rather than finished.
When large transfers stall
Almost always the MTU. A tunnel adds header overhead, and a path that fragments or silently drops oversized packets shows up as small requests working perfectly and big ones hanging. The self-hosting guide has the specific numbers.