Home port/Platform/Cross-network sharin'

Screen sharin' across guest Wi-Fi, VLANs, an' segmented networks.

Subnets, VLANs, guest Wi-Fi, LTE, the buildin' across town: one workspace, no VPN, no UC call, no cables. This be the capability that sets Polaris apart from the rest o' the fleet.

Polaris sessions on a rotating wireframe globe An orthographic wireframe Earth, drawn as a coastline and a fifteen-degree graticule, which can be dragged to rotate. Marked on it are sharing devices, meeting-room displays and Polaris Cloud signaling regions. Sessions play in a loop: both ends of a share open an outbound connection to a signaling region, the region introduces them, and the content itself then travels along a single direct arc between the two endpoints while the signaling links go idle. In the last session of the loop the two ends sit behind a network that will not allow a direct path, the direct arc breaks at a marked obstruction, and the encrypted content instead takes one extra hop through a relay before reaching the display. EU WESTDENVERLONDON
Every session here crosses a network, aye

A guest on LTE in London shares to a Denver boardroom. Both ends dial out; the media sails direct.

signallin' — outbound TLS 443, both ends dial out media — direct between the two endpoints relayed media — the fallback, one extra hop along the way a NAT no direct path can cross, savvy
GUEST DEVICEguest Wi-Fi / LTEPOLARIS CLOUDsignaling brokerPOLARIS PODdisplay · AV VLAN1 · DIAL OUT · TLS 4431 · DIAL OUT · TLS 443both connections start inside the network: no inbound rules, no open ports2 · SCREEN KEY · K7RM2XKEY RESOLVES TO THIS ROOM3 · SDP · ICE EXCHANGED3 · SDP · ICE EXCHANGEDeach side learns a direct path to the other4 · DIRECT MEDIA · ENCRYPTED · DTLS-SRTPEPHEMERAL UDP · PEER-TO-PEER · SOLICITED FLOW PASSES THE STATEFUL FWCLOUD IDLE · OUT OF THE MEDIA PATH5 · UNSOLICITED PACKET✕DROPPED · NO RULE MATCHESSTATEFUL FW · OUTBOUND ONLYSTATEFUL FW · OUTBOUND ONLYCNX-01 · CROSS-NETWORK DATA PATH · TIME RUNS DOWNWARD · CLOUD = SIGNALING ONLYSHEET 1/1 · REV C1 · NO ROUTEGuest Wi-Fi and the display’s VLANhave no route between them.DISPLAY · AV VLANGUEST DEVICE✕2 · THE HANDSHAKEBoth sides dial out to Polaris Cloud:TLS 443, signaling only.POLARIS CLOUDSDP · ICE3 · DIRECT MEDIAThe cloud introduces them, then steps away.Media flows device-to-device, encrypted.CLOUD · OUT OF THE MEDIA PATHENCRYPTED · P2P
1. A guest on LTE tries to reach the display directly. No route exists, an' none will be charted.2. The share leaves their browser instead: outbound TLS signalin' on TCP 443 to webrtc.mersive.com.3. The cloud introduces the two endpoints; they negotiate a direct, encrypted WebRTC connection between 'em. Nothin' routes through Mersive; nothin' bridges.4. Content sails device-to-display over that direct connection. Signalin' be outbound-only on both sides: no inbound firewall rules, not a single hole in the hull.
thin dashes: signalin' to the cloud, outbound TLSbold lines: media, direct between the endpointsthe guest shares from the browser, no app neededhatched walls: routes that never exist; openings: negotiated flows only, savvy
The fallback, the whole tale

When no direct path can be charted, the media takes one relayed hop.

The globe above ends one session in four this way. This be that hop, message by message — what the relay be asked fer, what it be allowed to forward, an' what it can spy.

SHARING DEVICEbehind symmetric NATTURN RELAYpublic address, no NATPOLARIS PODdisplay · AV VLAN1 · SYMMETRIC NAT · A DIFFERENT EXTERNAL PORT FOR EVERY DESTINATIONoutbound, succeeds — mapped to 203.0.113.7:51000the display answers to 203.0.113.7:51000✕that mapping is valid only for traffic to the region that opened it — so the check is dropped, and no candidate pair succeeds2 · ALLOCATE · THE DEVICE ASKS THE RELAY FOR AN ADDRESS OF ITS OWNAllocate401 Unauthorized · realm + nonceAllocate · USERNAME · MESSAGE-INTEGRITYSuccess · XOR-RELAYED-ADDRESS · LIFETIME 600 s198.51.100.20:49200a public address that belongs to the device but lives on the relay. One NAT mapping, one destination — which is the thing symmetric NAT does not break3 · CREATEPERMISSION · THE RELAY IS TOLD WHO MAY REACH ITCreatePermission · XOR-PEER-ADDRESS · 300 sthe relay forwards from that one peer address and drops everything else — it is an allocation, not an open reflector4 · CHANNELBIND · 36 BYTES OF PER-PACKET OVERHEAD BECOME 4ChannelBind · channel number · 600 s5 · RELAYED MEDIA · ENCRYPTED · ONE EXTRA HOPDTLS-SRTP END TO END · THE RELAY FORWARDS CIPHERTEXT IT HOLDS NO KEY FORSYMMETRIC NATSTATEFUL FWCNX-02 · RELAYED FALLBACK · TIME RUNS DOWNWARD · RFC 8656 MECHANICS · RFC 5737 ADDRESSESSHEET 1/1 · REV A1 · NO DIRECT PATHA symmetric NAT uses a differentexternal port for every destination.DEVICEDISPLAY✕2 · ALLOCATEThe device asks a relay for a publicaddress of its own, and authenticates.TURN RELAY198.51.100.20:49200LIFETIME 600 s · ONE PEER PERMITTED3 · RELAYED MEDIAOne extra hop. The relay forwardsciphertext it holds no key for.DTLS-SRTP · END TO END

A symmetric NAT hands every destination a different external port, so the address the display was given be not the address the packets would arrive from.

the device an' its NATrelay control messages, then the relayed mediaencryption the relay sits outside ofhatched walls: the NAT an' the firewall, neither o' which be opened
Where this saves the voyage

Three rooms that run a LAN-local system aground.

The visitin' presenter

A board member strolls in on LTE. No guest Wi-Fi sign-up, no VPN token, no dongle. They join the workspace from a browser an' present in under a minute, with zero access to yer network.

Try it in yer boardroom →

Yer segmented enterprise

Corp, guest, AV, an' OT networks that must never route to each other, by policy. Polaris keeps the isolation intact an' still lands every source on the same display.

The enterprise tale →

The multi-buildin' campus

Engineerin' in Building C shares to the war room in Building A, across VLANs an' fiber, without hoistin' a UC call just to move pixels.

Campus scale →
How cross-network signalin' works

Where yer content actually sails

Polaris Cloud introduces the two ends of a share. It does not carry 'em.

When a source an' a display sit on different networks, the signalin' service at webrtc.mersive.com exchanges connection details between the sharin' device an' the display, an' the two negotiate a direct, encrypted WebRTC connection between themselves. Yer content travels from the device to the display. It does not pass through Mersive.

  • What reaches our cloud: session signalin', the connection details the two endpoints need to find each other. Not yer screen.
  • What stays on yer network: when a source an' a display be already on the same network, the connection be negotiated with local addresses only an' never leaves the LAN.
  • What never happens: no inbound firewall rules, no bridgin' of yer networks. All cloud traffic be outbound TLS on TCP 443 from both sides. A guest device gets zero access to yer network; the workspace be the only shared surface.
The short o' it

The combination o' cross-network capability without a VPN, the workspace, an' meetin' parity with a composited workspace available in a web browser sets Polaris apart from the rest o' the fleet.

✓ No VPN✓ No UC call✓ No inbound holes in the hull✓ Guest gets zero network access✓ Every Polaris tier, aye

Check the matrix, matey → The security read →

See the platform live, matey.

Hardware trials set sail fer every product, straight from Mersive. When the rooms prove it, we introduce yer regional partner fer the rollout.

Start yer trial Spy it on YouTube ↗