All docs/Connect machines and private services
USE

Connect machines and private services

Use identity-gated private addresses for existing applications without opening public ports.

July 2026

The access model

AgentNet assigns private 10.86.x.x addresses and discovers a direct path when possible, with relay fallback when networks cannot connect directly. Friendship is the first trust boundary; service policy remains a separate explicit decision.

  • No public IP or router port-forwarding is required.
  • Unknown identities cannot assume route access.
  • Existing SSH, HTTP, RDP, TCP, and UDP software can keep its normal protocol.
  • Revoking a relationship removes the identity-level path without redesigning both networks.

Basic workflow

01
Install on both machines

Use the platform guide and verify `agentnet doctor`.

02
Exchange identities

Send and accept a friend request.

03
Inspect routes

Use Desktop or the CLI to find the peer private address.

04
Reach the intended service

Connect with the existing client only after the service and access policy are configured.

Smart regional proxy

The local proxy can send selected region-classified destinations through an approved exit while leaving other traffic direct. The default install uses China split routing; full-tunnel behavior is an explicit mode, not the default.

# local proxy endpoint
127.0.0.1:8889
Next guideAgentNet for agents and automation