STEP_033G_SOURCE_NAT_DISCOVERY PASS_SOURCE_NAT_DISCOVERY timestamp: 20260708-111923 Validation: - vm100_masq_lines: 2 - vm100_nat_10_200_related_lines: 6 - nat_inference: LIKELY_VM100_NATS_TOWARD_VM101 - canary_absent_lines: 1 - fwmark_rule203_lines: 1 - table200_default_vpn1_lines: 1 - table203_default_vpn3_lines: 1 - uci_pending_lines: 0 Remote changes: - none, read-only inventory Interpretation: - If VM100 NATs LAN clients toward VM101 as 10.200.0.1, VM101-side canary by source 10.200.0.1 is too broad. - In that case the next safe canary must be done before NAT on VM100, or VM100 NAT must be selectively adjusted in a separate staged plan.