Map
Fetch and verify the signed relay inventory.
Nexus Atlas does not bolt a separate tunnel migrator onto its data plane. Relay and direct connectivity enter the same link scheduler, so upgrading or falling back does not rebuild the secure Atlas tunnel.
The relay provides immediate rendezvous and reachability. Direct-path discovery happens after communication already works.
Fetch and verify the signed relay inventory.
Open outbound authenticated sessions to the selected relay set.
Run STUN from the same socket that carries Atlas data.
Exchange candidates and attempt the same ordered paths together.
Measure every working path and apply the chosen traffic policy.
Both nodes initiate outbound sessions to an authenticated relay. CGNAT normally permits that traffic, so rendezvous and tunneled communication can begin without an inbound rule or public address.
Nodes exchange server-reflexive and local candidates through their existing relay session. They try the same candidate order together. When a response returns, the direct path becomes alive with a real measured RTT.
Direct and relay paths are ordinary Atlas scheduler inputs. If cellular routing makes the relay faster, or if the direct mapping disappears, policy can move traffic without invoking traversal logic again.
A change in path availability changes scheduler inputs. Applications keep using the same Atlas interface and addresses.
| Network condition | Direct path | Relay path | Atlas behaviour |
|---|---|---|---|
| Endpoint-independent mapping | Likely available | Warm | Direct usually wins on measured delivery time. |
| Endpoint-dependent CGNAT | Unavailable | Active | Relay continues carrying the tunnel. |
| Mobile address changes | Re-evaluated | Authenticated roaming | New valid sources are adopted per path. |
| Direct degradation | Score worsens | Already measured | Traffic shifts according to policy. |
| Primary relay failure | Unaffected if live | Secondary elected | Configured relay redundancy remains available. |
Both ends are Nexus Atlas, so interoperability machinery intended for unrelated clients can be replaced by simpler product-native components.
RFC-compatible address discovery and mapping classification. Atlas relays provide the observation points.
An Atlas-native forwarder carries opaque encrypted frames without allocation and channel-binding complexity.
Relay rendezvous discovers candidates; the existing Atlas probes and scheduler decide how every live path is used.
Apply as a pilot partner if you have a deployment ready to test, or start evaluating Nexus Atlas Traversal as a future customer. Tell us enough to understand the endpoints, carriers, regions, and operational constraints involved.
Run an early deployment with direct engineering contact and help shape priorities through real-world feedback.
Research architecture, security, deployment options, and commercial fit before committing to a pilot.