Penetrating Private RFC1918 Networks Without Firewall Holes: Lory Mesh | Lorikeet Security Skip to main content
Back to Blog

Penetrating Private RFC1918 Networks Without Firewall Holes: Lory Mesh

Lorikeet Security Infrastructure Team September 23, 2026 10 min read Network Security & Lory Mesh

One of the greatest logistical headaches in penetration testing is assessing private corporate infrastructure. When a compliance standard (like SOC 2 CC7.1 or PCI DSS Requirement 11.4) mandates an internal network assessment, organizations are traditionally forced to:

Lorikeet Security eliminated this friction with Lory Mesh (mesh/README.md), an asynchronous Layer-3 overlay network that connects cloud-based autonomous testing engines to private RFC1918 subnets (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) using outbound-only mutual TLS.

Zero Inbound Firewall Holes: The Lory Mesh connector initiates an outbound TLS 1.3 tunnel over standard TCP port 51820 to the AWS Mesh Gateway. No inbound ports are ever opened, and internal IPs remain completely invisible to the public internet.

How Lory Mesh Works Under the Hood

Setting up an internal assessment takes less than 60 seconds. A network engineer runs a single enrollment command on any machine inside the target network:

curl -fsSL 'https://lorikeetsecurity.com/mesh/get?os=linux' | sudo LORY_ENROLL=<token> sh

Behind the scenes, the connector daemon (lory-meshd.py):

  1. Auto-Detects Local Subnets: Scans local network interfaces to identify active RFC1918 CIDR blocks.
  2. Configures a Virtual TUN Adapter: Creates a virtual network interface (lory0 on Linux, Wintun on Windows) in the 100.100.0.0/16 overlay range.
  3. Establishes Outbound mTLS: Connects to mesh.lorikeetsecurity.com:51820 using unique client certificates minted by the Lorikeet Mesh Certificate Authority.
  4. Enables Stateful SNAT: Applies local kernel packet masquerading so packets routed from Lory's cloud scanner pod reach internal hosts and return seamlessly.

Strict Multi-Tenant Isolation (CompanyResolver)

When testing internal networks in a multi-tenant cloud environment, security isolation is paramount. The Lory Mesh Gateway pod features a dedicated CompanyResolver engine that validates every packet against active engagement scopes stored in the database.

Traffic originating from an engagement can only reach the specific connector and approved CIDRs registered to that organization, completely preventing cross-tenant packet leakage.

Assess Your Internal Network in Minutes with Lory Mesh

No hardware shipments. No inbound firewall holes. Schedule an internal network penetration test powered by Lory Mesh and Lorikeet Security.

-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!