Learn · Lesson 7 of 7 · 6 min
Under the hood: how nodes connect
Your machines look for a direct connection. An encrypted relay carries traffic while they find a path—or when a direct path isn’t possible.
Introductions here. Traffic between peers.

Shares public keys, private addresses and network rules so nodes know about each other.
Carries your traffic directly between nodes or through a relay that cannot read it.
From the first packet to a direct path.
The first packet to an idle peer is dropped. That triggers local peer setup using information the node already has.
The relay carries encrypted traffic while the nodes look for a direct route.
Traffic moves to P2P without dropping the connection. Otherwise, the relay continues carrying it.
Start with outbound access.
No inbound ports need to be opened. The client needs these outbound connections:
UDP 42273Peer trafficTCP 443Control planeUse baseguard status to see whether a peer is reached through P2P, Relay or is Idle.
A few useful details
NAT behavior. Full-cone NAT usually permits a direct path. Restricted-cone NAT needs simultaneous traffic from both ends. Symmetric NAT may prevent a direct path, requiring a relay.
Encryption. WireGuard protects the peer traffic, including packets forwarded by a relay. Session keys rotate every two minutes.
Control plane state. It holds public keys, overlay addresses and rules, and forwards end-to-end encrypted ICE signaling. It does not hold private WireGuard keys or receive your peer traffic.
Retrying direct paths. The client continues probing in the background when a relay is in use.
Connect your machines, define their access, and keep the configuration easy to understand.