Browse docs
Create and manage networks
Networks and access

Managing networks

Create, update, and monitor private network segments.

Section
Networks and access
Path
/ui/managing-networks

This guide covers the network lifecycle in the dashboard.

Create a network

  1. Open Networks.
  2. Click Create network.
  3. Enter name and CIDR block.
  4. Review Connection method. WireGuard is the supported production connection method today.
  5. Save and verify status.

GRE is not public production-ready. If legacy or internal GRE metadata appears, treat it as requested/default policy only and verify the effective protocol on runtime surfaces.

Connection method vs active connection

Connection method describes the supported method Nanami applies when planning new routes. It does not prove that a connection is currently active.

Nanami resolves the effective transport per tunnel or path from:

  • endpoint capability;
  • device type and gateway/server availability;
  • route or path policy;
  • runtime constraints observed by the connected client.

WireGuard is production available today. GRE remains hidden/disabled/internal and fail-closed for normal users until GRE-specific runtime support, endpoint modeling, product gating, and docs truth exist. If GRE metadata is present, Nanami must either report explicit GRE readiness for the path or show a safe unavailable reason. Runtime and tunnel views are the source of truth for the protocol actually in use.

Nanami prefers direct connectivity when safe and possible. Managed/shared gateways are used only when direct connectivity is unavailable and policy allows it, or when route policy explicitly requires a gateway. Gateway use may depend on plan, quota, capacity, fairness, and abuse controls.

Attach nodes and gateway paths

  • Enroll nodes through the guided add-node flow.
  • Let the network use an isolation-safe gateway assignment.
  • Validate that all endpoints report recent heartbeat.

Update policy safely

When changing access behavior:

  1. Apply minimal change first.
  2. Validate expected handshake updates.
  3. Expand rollout after verification.
  • CIDR ranges do not overlap unexpectedly.
  • Gateway health remains green after policy updates.
  • Effective tunnel/path protocol matches runtime truth after apply.
  • Audit trail captures who changed what and when.
Rollback

If connectivity drops after policy changes, revert to the last known-good policy version before making additional edits.

Continue

Choose the most useful continuation instead of a random article.