4.1 KiB
Device Edge B2 public pilot runbook
Status: router/NAT is not configured by this document. It is a one-pilot, human-operated exposure gate for the already accepted Mini relay. It never changes Synology, Gelios, VPN, Device Plane command transport or device ownership.
Exact traffic path
ARUSNAVI B2 pilot
-> public IPv4 : TCP/9921
-> provider router : TCP/9921 -> 192.168.1.151:9921
-> Deco X55 : TCP/9921 -> 192.168.71.253:9921
-> Mini IPvlan relay
-> restricted private backhaul
-> Synology Gateway 127.0.0.1:9921
The observed Deco WAN is 192.168.1.151 with gateway 192.168.0.1; it is an
RFC1918 address. Therefore this is a double-NAT topology. A Deco rule alone
cannot make the tracker reachable from the internet.
Immutable safety boundary
- Forward TCP only, external and internal port
9921. - Deco target is exactly
192.168.71.253, never the Mini host192.168.68.54and never Synology. - Do not enable DMZ, UPnP, port ranges, UDP, 443 forwarding or any catch-all rule.
- Do not remove, replace or edit the Gelios monitoring route.
- The relay accepts connections only from a public IPv4 source, keeps quarantine-only discovery and has no command transport. A LAN client will intentionally be rejected; that is not a test failure.
- The rule must be deleted again if the single pilot is abandoned or the expected quarantine evidence is not obtained.
Gate 1 — DNS and public address
- Determine the actual public IPv4 on the provider-facing edge. Do not use
192.168.0.1,192.168.1.151,192.168.68.1or192.168.71.253as a DNS answer: all are private addresses. - Point
device.nodedc.ruto that public IPv4 only if the tracker UI accepts a hostname. Otherwise configure the public IPv4 directly. - If the provider router has no public WAN IPv4, or an internet check still cannot reach it after both rules below, stop. This is provider CGNAT/bridge territory: request a public IPv4 or a bridge/forwarding option from the provider. Do not introduce a VPS as an unreviewed workaround.
Gate 2 — provider router
On the upstream/provider router, create one port-forward rule:
| Field | Value |
|---|---|
| Name | NDC B2 pilot to Deco |
| Protocol | TCP |
| External port | 9921 |
| Target address | 192.168.1.151 |
| Target port | 9921 |
Save only that rule. It targets the Deco WAN address, not a service host.
Gate 3 — Deco X55
In the Deco mobile app: More → Advanced → NAT Forwarding → Port Forwarding → Add. Create exactly:
| Field | Value |
|---|---|
| Name | NDC B2 pilot |
| Protocol | TCP |
| External port | 9921 |
| Internal IP | 192.168.71.253 |
| Internal port | 9921 |
If the app forces a client selection, select the IPvlan relay only if its
address is shown as 192.168.71.253. Do not select the Mini host or any NAS.
If the UI will not accept the fixed IPvlan address, stop and record that fact;
do not substitute a DHCP address.
Gate 4 — ARUSNAVI B2 route
Use one known pilot B2 and one unused monitoring-server slot. Configure an
additional route with the documented INTERNAL protocol and the public
hostname/IP from Gate 1, TCP port 9921. Preserve the existing Gelios route in
its current slot. The ARUSNAVI account password stays in the operator surface;
it is not entered into Foundry, Device Plane or the relay.
The device IMEI observed in HEADER2 is a claimed identifier only. It becomes
a quarantine discovery, not an owned device and never a command target.
Acceptance and failure handling
The first valid HEADER/PACKAGE through the pilot route must produce a masked, quarantine-only discovery in Device Control Core and the existing Gelios map path must continue independently. Do not issue a device command.
On any unexpected behavior, remove the two NAT rules in reverse order:
- remove the Deco
NDC B2 pilotrule; - remove the provider-router
NDC B2 pilot to Decorule.
This ends external reachability while leaving the Mini, VPN, backhaul, Synology and Gelios unchanged. Do not use a LAN port probe as acceptance: the relay correctly rejects private source addresses.