LazyRemote.
Download MarkdownNetwork review

PROJECT-OWNED SAMPLE · 9 SEPTEMBER 2026

Network Fit
Review.

A worked example for one Linux workstation behind CGNAT, one existing relay, and two owner-operated clients.

This is not a customer result. The names, addresses, ports, and findings are synthetic. The structure shows the report a buyer receives; it contains no private fleet data.

DECISION

Conditional go.

The route is a reasonable fit if every reverse listener remains on relay loopback, the tunnel and jump roles use separate restricted identities, host keys are pinned, and an independent administrator path survives the test. Do not deploy if any of those gates cannot be met.

Need

Reach a home Linux workstation from a laptop and phone for SSH and a private browser viewer. The home connection is behind CGNAT, so it cannot accept a normal inbound port forward.

Existing pieces

One owner-controlled relay with public SSH, one workstation that can make outbound SSH connections, and two owner-controlled client devices. No hardware purchase or relay hosting is part of the review.

Laptop / phoneowner-controlled client
Relay SSHpublic, patched, authenticated
Relay loopbackreverse listener, never wildcard
Workstation loopbackSSH or private viewer

The route is end-to-end SSH through reviewed identities. A successful carrier alone does not authorize a user, and a browser viewer does not become public merely because the relay is public.

BoundaryIntended bindWho can reach itDecision
Relay SSHReviewed public addressApproved SSH clientsConditional
Reverse listener127.0.0.1 on relayRelay-local jump path onlyRequired
Endpoint controller127.0.0.1 on workstationLocal app or declared forwardRequired
Private browser viewer127.0.0.1 on workstationIts dedicated reviewed forwardRequired
Raw VNC / RDPNo public listenerNo Internet sourceStop if exposed

Illustrative labels only. The paid report records the buyer’s observed bind addresses and listener owners without copying secrets.

A

Relay administrator

Independent recovery only. It is not the everyday jump or tunnel identity.

B

Tunnel identity

No shell, TTY, X11, agent forwarding, wildcard listener, or arbitrary target.

C

Jump identity

Separate client key and a pinned relay host key; access ends at declared loopback routes.

D

Endpoint identity

Separate host identity and permissions for each enrolled computer.

Stop

Wildcard reverse listening

If the relay shows a reverse listener on 0.0.0.0 or ::, stop the candidate and correct the SSH policy before any client test.

Required

Role separation

Do not reuse the relay administrator key for the persistent carrier or for everyday client access.

Required

Host verification

Pin the relay and endpoint host identities. A changed fingerprint fails closed and requires an independent check.

Open

Reboot recovery

A running service is not reboot evidence. Prove one controlled restart and one authorized reboot before calling persistence verified.

Rollback order

  1. Close the client session.
  2. Stop only the candidate carrier.
  3. Confirm its relay loopback listener is gone.
  4. Restore the reviewed prior unit or configuration.
  5. Re-probe the existing path.

Answer before payment

  • Who owns the relay and network policy?
  • Which operating systems are in scope?
  • Which exact SSH, noVNC, or private-web path is needed?
  • Is there an independent recovery route?
  • What must continue working during the change?

FREE FIT CHECK FIRST

Bring the shape of the network,
not its secrets.

Send the endpoint operating systems, whether a reachable relay already exists, the NAT or port constraint, and the intended access path. Do not attach passwords, private keys, access codes, or unredacted configuration.

Review the fixed scope