← All paths
Edge services: NAT, DHCP, and time
Put a LAN online through one public IP, publish a service, relay DHCP across subnets, and lock down time.
Put a whole private LAN online through a single public address with PAT.
Publish one inside service on one public port, and nothing else.
A subnet a hop away leases nothing. Relay the broadcast to the central server.
Relay is per-interface. Bring the second client subnet online too.
Close an open time service and require authenticated upstreams.