1. Current Location: Home >  Router Encyclopedia >  Why is remote access sometimes connected directly and sometimes relayed? The speed is ten times faster. I drew a diagram of the NAT hole drilling principle

Why is remote access sometimes connected directly and sometimes relayed? The speed is ten times faster. I drew a diagram of the NAT hole drilling principle

NAT hole punching principle diagram: STUN asking for directions, exchanging notes, shooting and drilling the entire process; the symmetrical NAT failure is compared to the relay's bottom cover

the Feiniu FN Connect , I left a tail note: transferring files from the company WiFi to the home NAS, 500KB/s, and grinding a 2GB material package for over an hour; At night, my wife used her phone data to browse the NAS album at home, and the photos swiped at lightning speed, running right up to 50MB right next to our home. The same NAS, same account, can make a tenfold difference. Later, I checked the connection states on both sides and finally understood—her line was a direct device-to-device connection, while mine was a server-around relay. The decision on which path to take is one thing: NAT the hole is or not. This isn't just FN Connect; Tencent Meeting, WeChat Video, Tailscale, and gaming multiplayer all share the same underlying system.

spent a minute reviewing the NAT level first

the devices at home use internal network addresses like 192.168 or 31.x, which do not exist on the public network. When the packet goes out, the router changes the source address to the public IP of the WAN port, and casually records it on its mapping table: internal network 192.168.31.10:54321, external 117.136.x.x:56789 after leaving. The return packet is forwarded back to the corresponding device according to this table. In my NAT , I discussed it from the perspective of online gaming, emphasizing only one thing related to the hole: the hole that is dug out, outsiders only get a public IP and port number. As for who can enter through this opening, the rules are set by each router .

some routers are generous—if they open the opening, anyone can pass through; Some are picky, but only those you've reached out to are acceptable; Others are the most cunning, changing their approach every time they contact a new target. This difference in temperament directly determines the success or failure of the drilling.

NAT has four temperaments; the success or failure of drilling depends on it

textbooks divide NAT into four types, with names containing "cone" sounding intimidating. Using a community parcel collection point as an analogy makes it clear:

types rules collection points for example
is completely conical with an opening so any external address can enter your name is posted on the shelf, and anyone who posts it is forwarded
restricting the cone only allowing IPs you have actively contacted. No matter the port only accepts shipments from the store you ordered
port restrictions are conicalIP and port must match the one you contacted only recognize the rider from that store
symmetrical every time you change destinations you get a new shelf number and each store gets a new shelf number, and the old account becomes obsolete

most home routers use the first three types (collectively called conical). Once the port is drilled, the destination is the same map. The firewalls exported by companies and some carriers' CGNAT are symmetrical—this is a serious issue behind the scenes. As long as both sides of the NAT are conical, drilling holes is basically possible; As long as one side is symmetrical, there's basically no chance.

The entire process of making holes: asking for directions, exchanging points, firing

two devices behind the NAT want to connect directly, neither knows the other's public network address numbers, so you have to follow the button in three steps.

first step is to ask for directions. A and B each send a UDP package to a STUN server. What does STUN do? It's like a mirror—you send a contract to it, and it replies: "From the outside, I see you as 117.136.x.x:56789." This address is the address mapped by NAT. The standard port for STUN servers is 3478, and there are plenty of free ones on the public web—Google and Tencent have them.

second step: exchange. both sides exchanged the house numbers they asked for through a third-party channel. This channel is the work done by the login servers of FN Connect, Tencent Meeting, and Tailscale—it only delivers notes, never touches the data. So when those apps are disconnected and you can't log into the server, you can't even connect, and there's nowhere to deliver the notes.

third step of firing. A outsource to B's address, and B simultaneously outsource to A's address. The clever part is in timing: before B's packet reaches A's NAT, A happens to actively send a packet to B. The record on A's NAT mapping table is still hot, and when B's packet arrives, it hits the table entry and lets it pass. The reverse is also true. The two openings were chiseled open to each other, and the hole was opened. The whole process usually takes several hundred milliseconds to a few seconds. When you see the app spinning "Connected," it's usually the shooter.

Why did both video conferencing and remote networking start with UDP? Because UDP has no connection status, the packet can leave at will, making it ideal for this kind of "simultaneous mutual shooting" work. TCP and UDP mentioned that TCP requires a handshake first, and the timing on both sides is misaligned, making drilling holes an order of magnitude higher, so it's usually just used as a backup.

Why is

symmetric NAT hopeless, and how is the relay backed up

The weak point of symmetrical NAT lies here: When A asks STUN for directions, it uses Hole 1, but when it turns to contact B, NAT switches it to Hole 2. B received a note with the address of Kou Zi 1, which was sent over. A's NAT checked the form—there was no record of it, so he threw it away. The door number on the note was expired, and no matter how he tried, he couldn't make it. As long as one side is symmetrical, the direct connection to this road is basically sealed.

then it's the relay's turn to appear, called a TURN: both sides pass data to one server, and the server passes it to the other. Throughout the process, the speed limit you see is the "bandwidth allocated to you by the server" and "the distance between you and the server." FN Connect free relay test ranges from 500KB/s to 1MB/s, with further discounts during evening peak hours; I tested the temperament of Synology QuickConnect relays in QuickConnect , and it also capped at a few MB/s. Why is it generally slow? Server bandwidth is real money, free speed limits are the norm, Tailscale's DERP and game accelerator's "dedicated line" are essentially all about this.

know if you're a direct connection or a relay

the worst part of this is that hole drilling fails without errors, the software silently downgrades to the relay . You can't see anything on the interface. You might think it's your internet connection or your NAS isn't working, but actually, you're just taking the wrong path. So he had to be the referee himself.

the first referee is speed. Running uplink at home (mine has 50MB uplink and about 5MB/s file transfers) is direct connection; If the device is consistently stuck between 500KB/s and 1MB/s, stationary and not affected by time periods, it's probably a relay. Relay has a characteristic of slow relay—it's consistently slow, unlike bandwidth congestion where nighttime is worse than daytime.

second judge was the software explaining itself. In Tencent Meeting's settings, you can view network statistics. The sending and receiving speed doesn't increase, but the latency is okay—it's a relay phase. Tailscale is more practical. On the backend management page, every connection is labeled as Direct or Derp (the name of its main relay), making it clear at a glance. That's why I recommend it as a testing tool—after connecting, just look at the labels and you'll see the quality of your path. For FN Connect and other systems that don't reveal their status, they use speed to deduce backwards. That's how I judged the 1190 article.

By the way, the same person switching networks can get different results: my home WiFi is direct connection, my company's WiFi is relay, and mobile data is direct connection. So when investigating, don't just focus on the one side at home and look at both sides.

the reality at home: CGNAT, IPv6, and the speed boost order

falls on their own broadband, these two realities are the most crucial. One is CGNAT: WAN ports with addresses starting with 100.64 mean the operator is cramming you and hundreds of households behind the same public IP address, creating a huge NAT layer. Many regions still have symmetrical attitudes, worsening the success rate of hole drilling. The method to determine this is about checking public IPs. Check the WAN port address and then compare your phone's data to the outbound IP to get the answer. Another bad news is that China Mobile and some newly installed telecom broadband providers come with this treatment by default. If you can get a public network V4 for calls, try to get it.

other is IPv6, which is the cure for the entire hole-punching game. each device gets the world's only V6 address there's no such thing as "hiding behind the internal network"—the door is open, and you knock directly. Both ends have V6, and remote networking apps automatically switch to V6 direct connection. My wife's phone can fill up data thanks to this—V6 coverage for cellular networks has long been standard. What I need to do at home is to sort out the V6. The router switch and the optical modem are two separate levels. Xiaomi routers have a switch in version 31.1, which I before. The optical modem side has its own issues, bridging and routing modes are different

As for my company's relay route, how was it ultimately saved: the access side had no V6, the outlet was symmetrical, and the software layer couldn't be saved. I simply configured my home side with a public IP and high-level port, and VPN to go home or directly map the port . With access to one side of the public network, the other party doesn't need to dig a hole and goes straight to your door, skipping the whole luck-based process.

as usual, here's the order: from free to paid money:

cost of every step
1 checking IPv6 on both ends, try mobile data first (if you have V6, it's likely to be a direct connection) 0 yuan
2 Calling 10,000 at home costs IP0 yuan for public networks, but depending on luck
3 public IP+port mapping or VPN, going 0 home can cost tens of yuan
4 is no good; the relay either endures or moves to the paid tier monthly fee

next time remote access gets stuck on a PowerPoint slide, don't rush to blame the NAS for not working—see which path you're on before deciding which end to treat.

Read More


Copyright Notice Scan to read on mobile
All Rights Reserved: 《SHUNOT》 => 《Why is remote access sometimes connected directly and sometimes relayed? The speed is ten times faster. I drew a diagram of the NAT hole drilling principle》
Article URL: https://www.shunot.com/en/lybk/1207.html
Unless otherwise stated, all articles are original by 《SHUNOT》. Reposting is welcome! Please indicate the original URL when reposting, thank you.

Contact Us

Online Consultation: Click here to send me a message

WeChat ID: master_135

Scan to follow